| Guidelines This chapter sets out principles for improving banks’ operational resilience. It covers the following areas: (i) governance; (ii) operational risk management; (iii) business continuity planning and testing; (iv) mapping of interconnections and interdependencies of critical operations; (v) third-party dependency management; and (vi) incident management; and resilient information and communication technology (ICT), including cyber security. The contents of this chapter are based on:
|
| Related standards |
| Related guidelines |
| Other related publications
|
Operational risk-related events, such as pandemics, cyber incidents, technology failures and natural disasters, can cause significant operational failures or wide-scale disruptions in financial markets.
The Covid-19 pandemic underscored the importance of operational resilience, as banks rapidly adapted their operational posture in response to new hazards or changes in existing hazards that occurred in different parts of their organisation. Pandemic-related disruptions affected information systems, personnel, facilities and relationships with third-party service providers and customers. In parallel, there was a notable spike in cyber threats (ransomware attacks, phishing, etc.), alongside an increased potential for operational risk events caused by people, failed processes and systems as a result of greater reliance on virtual working arrangements.
While the application of technology to financial services has benefited banks and their customers, it has also introduced new risks. These risks resulted from vulnerabilities related to the rapid adoption of and increased dependency on technology infrastructure for the provision of financial services and intermediation, as well as the sector's growing reliance on technology-based services provided by third parties.
Operational resilience is an outcome that benefits from the effective management of operational risk. Activities such as risk identification and assessment, risk mitigation (including the implementation of controls) and the monitoring of risks and control effectiveness work together to minimise operational disruptions and their effects. In addition, management's focus on the bank's ability to respond to and recover from disruptions, assuming failures will occur, will support operational resilience. An operationally resilient bank is less prone to incur untimely lapses in its operations and losses from disruptions, thus lessening incident impact on critical operations and related services, functions and systems. While it may not be possible to avoid certain operational risks, such as a pandemic, it is possible to improve the resilience of a bank's operations to such events.
The following terms are used throughout this chapter and have the meaning given below:
The Committee seeks to promote a principles-based approach to improving operational resilience. These principles are to be applied on a consolidated basis to banks consistent with the scope of the Basel Framework. When implementing the Principles, banks should take account of the nature, size, complexity and risk profile of their activities.
Recognising that a range of potential hazards cannot be prevented, the Committee believes that a pragmatic, flexible approach to operational resilience can enhance the ability of banks to withstand, adapt to and recover from potential hazards and thereby mitigate potentially severe adverse impacts.
In addition, business continuity, third-party dependency management and resilient ICT including cyber security are important factors for banks to consider when strengthening their operational resilience. It is essential for banks to ensure that existing risk management frameworks, business continuity plans and third-party dependency management are implemented consistently within the organisation. Banks should consider whether their operational resilience approach is appropriately harmonised with the stated actions, organisational mappings, and definitions of critical functions and critical shared services contained in their recovery and resolution plans as specified in the Financial Stability Board's (FSB's) Recovery and Resolution Planning framework, as appropriate.2
| 2 | See FSB, Key Attributes of Effective Resolution Regimes for Financial Institutions, April 2024; relevant supporting guidance in Recovery and resolution planning for systemically important financial institutions: guidance on identification of critical functions and critical shared services, July 2013; and Guidance on arrangements to support operational continuity in resolution, August 2016. |
The practices described below should not be viewed in isolation, but rather as integral parts of a bank's forward-looking operational resilience approach in line with its operational risk appetite and tolerance for disruption.
Banks should utilise their existing governance structure to establish, oversee and implement an effective operational resilience approach that enables them to respond and adapt to, as well as recover and learn from, disruptive events in order to minimise their impact on delivering critical operations through disruption.
The board of directors should review and approve the bank's operational resilience approach considering the bank's risk appetite and tolerance for disruption to its critical operations. In formulating the bank's tolerance for disruption, the board of directors should consider the bank's operational capabilities given a broad range of severe but plausible scenarios that would affect its critical operations. The board of directors should ensure that the bank's policies effectively address instances where the bank's capabilities are insufficient to meet its stated tolerance for disruption.
Under the oversight of the board of directors, senior management should implement the bank's operational resilience approach and ensure that financial, technical and other resources are appropriately allocated to support the bank's overall operational resilience approach.
Senior management should provide timely reports on the ongoing operational resilience of the bank's business units in support of the board's oversight, particularly when significant deficiencies could affect the delivery of the bank's critical operations.
The board of directors should take an active role in establishing a broad understanding of the bank's operational resilience approach, through clear communication of its objectives to all relevant parties, including bank personnel, third parties and intragroup entities.
Banks should leverage their respective functions for the management of operational risk to identify external and internal threats and potential failures in people, processes and systems on an ongoing basis, promptly assess the vulnerabilities of critical operations and manage the resulting risks in accordance with their operational resilience approach.
The bank’s operational risk management function should work alongside other relevant functions to manage and address any risks that threaten the delivery of critical operations. Banks should coordinate their business continuity planning, third-party dependency management, recovery and resolution planning and other relevant risk management frameworks to strengthen operational resilience across the bank.
Banks should have sufficient controls and procedures, consistent with and conducted alongside the risk identification process, to identify and assess threats and vulnerabilities, and more generally their operational risk, in a timely manner and, to the extent possible, prevent them from affecting critical operations delivery. The respective functions should regularly assess the effectiveness of the implemented controls and procedures. These assessments should also be conducted in the event of changes to any underlying components of the critical operations, as well as after incidents to consider lessons learned and new threats and vulnerabilities that caused the incident.
Banks should leverage change management capabilities in accordance with the change management processes under the overall management of operational risk as a way to assess potential effects on the delivery of critical operations and on their interconnections and interdependencies.
Banks should have business continuity plans in place and conduct business continuity exercises under a range of severe but plausible scenarios in order to test their ability to deliver critical operations through disruption.
An effective business continuity plan should be forward-looking when assessing the impact of potential disruptions. Business continuity exercises should be conducted and validated for a range of severe but plausible scenarios that incorporate disruptive events and incidents.
An effective business continuity plan should identify critical operations, and key internal and external dependencies to assess the risks and potential impact of various disruption scenarios on critical operations. These plans should incorporate business impact analyses and recovery strategies as well as testing programmes, training and awareness programmes, and communication and crisis management programmes.
Business continuity plans should develop, implement and maintain a regular business continuity exercise encompassing critical operations and their interconnections and interdependencies, including those through relationships with, but not limited to, third parties and intragroup entities. Among other business continuity goals, business continuity exercises should support staff's operational resilience awareness including training of staff, so that they can effectively adapt and respond to incidents.
Business continuity plans should provide detailed guidance for implementing the bank's disaster recovery framework. These plans should establish the roles and responsibilities for managing operational disruptions and provide clear guidance regarding the succession of authority in the event of a disruption that impacts key personnel. Additionally, these plans should clearly set out the internal decision-making process and define the triggers for invoking the bank's business continuity plan.
Banks’ business continuity plans for the delivery of critical operations and critical third-party services contained in their recovery and resolution plans should be consistent with their operational resilience approaches.
Once a bank has identified its critical operations, the bank should map the internal and external interconnections and interdependencies that are necessary for the delivery of critical operations consistent with its approach to operational resilience.
The respective functions should map (ie identify and document) the people, technology, processes, information, facilities, and the interconnections and interdependencies among them as needed to deliver the bank's critical operations, including those dependent upon, but not limited to, third parties or intragroup arrangements.
Banks may leverage their recovery and resolution plans, as appropriate, for definitions of critical operations and should consider whether their operational resilience approaches are appropriately harmonised with the organisational mappings of critical operations and critical third-party services contained in their recovery and resolution plans.
The approach and level of granularity of mapping should be sufficient for banks to identify vulnerabilities and to support testing of their ability to deliver critical operations through disruption, as described in Principle 3, considering the bank's risk appetite and tolerance for disruption.
Banks should manage their dependencies on relationships, including those of, but not limited to, third parties or intragroup entities, for the delivery of critical operations.
Banks should perform a risk assessment and due diligence before entering into arrangements including those of, but not limited to, third parties or intragroup entities, consistent with the bank's operational risk management framework, outsourcing/third-party risk management policy and operational resilience approach. Prior to the bank entering into such an arrangement, the bank should verify whether the third party, including, if relevant, the intragroup entity to these arrangements, has at least equivalent level of operational resilience to safeguard the bank's critical operations in both normal circumstances and in the event of disruption.
Banks should develop appropriate business continuity and contingency planning procedures and exit strategies to maintain their operational resilience in the event of a failure or disruption at a third party impacting the provision of critical operations. Scenarios under the bank's business continuity plans should assess the substitutability of third parties that provide services to the bank's critical operations, and other viable alternatives that may facilitate operational resilience in the event of an outage at a third party, such as bringing the service back in-house.
Banks should develop and implement response and recovery plans to manage incidents that could disrupt the delivery of critical operations in line with the bank's risk appetite and tolerance for disruption. Banks should continuously improve their incident response and recovery plans by incorporating the lessons learned from previous incidents.
Banks should maintain an inventory of incident response and recovery, internal and third-party resources to support the bank's response and recovery capabilities.
Incident management is the process of identifying, analysing, rectifying and learning from an incident and preventing recurrences or mitigating the severity thereof. The goal of incident management is to limit the disruption and restore critical operations in line with the bank’s risk appetite and tolerance for disruption.3
| 3 | For examples of detailed response and recovery practices, see FSB, Effective Practices for Cyber Incident Response and Recovery, October 2020. |
The scope of incident management should capture the life cycle of an incident,4 typically including, but not limited to:
| 4 | Recognising that the life cycle on an incident could span multiple measures of time that could range from hours to weeks to months. |
Incident response and recovery procedures should be periodically reviewed, tested and updated. Banks should identify and address the root causes of incidents to prevent or minimise serial recurrence.
Lessons learned from previous incidents, including incidents experienced by others, should be duly reflected when updating the incident management programme. A bank's incident management programme should manage all incidents impacting the bank, including those attributable to dependencies on, but not limited to, third parties and intragroup entities.
| 5 | Cyber security as defined in FSB, Cyber Lexicon, April 2023. |
Banks should ensure resilient ICT, including cyber security, that is subject to protection, detection, response and recovery programmes that are regularly tested, incorporate appropriate situational awareness and convey relevant, timely information for risk management and decision-making processes to fully support and facilitate the delivery of the bank's critical operations.
Banks should have a documented ICT policy, including cyber security, which stipulates governance and oversight requirements, risk ownership and accountability, ICT security measures (eg access controls, critical information asset protection, identity management), periodic evaluation and monitoring of cyber security controls, and incident response, as well as business continuity and disaster recovery plans.
Banks should identify their critical information assets and the infrastructure upon which they depend. Banks should also prioritise their cyber security efforts based on their ICT risk assessment and on the significance of the critical information assets to the bank's critical operations, while observing all pertinent legal and regulatory requirements relating to data protection and confidentiality. Banks should develop plans and implement controls to maintain the integrity of critical information in the event of a cyber event, such as secure storage and offline backup on immutable media of data supporting critical operations. Banks should regularly evaluate the threat profile of their critical information assets, test for vulnerabilities and ensure their resilience to ICT-related risks.
This module describes expectations to combat money laundering and terrorist financing.
This module describes expectations and practices relating to capital adequacy.
This module describes expectations for corporate governance.
This module describes expectations for credit risk and counterparty credit risk management.
This module describes expectations for external audit and sets out references related to public disclosure.
This module describes expectations for banks’ internal audit and compliance functions.
This module describes expectations for liquidity risk management.
This module sets out references related to market risk and interest rate risk.
This module describes expectations for the management of operational risk and operational resilience.
This module describes expectations for the management of problem assets and expected credit losses.
This module describes the application of proportionality in prudential regulation and supervision.
This module describes expectations for risk management.
This module describes the nature and application of prudential supervision.