Identify important business services based on the harm their disruption would cause to customers or markets.
Operational Resilience Mapping and Impact Tolerance Testing in Financial Services
Map important business services, set impact tolerances and design severe-but-plausible scenario tests to meet operational resilience regulatory requirements.
Course Overview
Operational resilience regulation has shifted supervisory attention from preventing every disruption to proving a firm can stay within tolerable limits when disruption inevitably happens, and firms that treat this as a documentation exercise discover the gap the first time a real incident forces them to test their assumptions live. This course walks through the operational resilience lifecycle: identifying important business services whose disruption would cause intolerable harm to customers or market integrity, mapping the people, processes, technology, facilities and third parties each service depends on, and setting impact tolerances that define the maximum tolerable duration and extent of disruption. Participants then design severe-but-plausible scenario tests, covering cyber-attack, third-party failure and facilities loss, and learn to evaluate whether the firm can remain within its stated tolerances under each scenario rather than simply confirming a plan exists on paper. The course covers the self-assessment document supervisors expect, the governance and board reporting operational resilience requires, and the remediation planning needed when testing reveals a firm cannot meet a stated tolerance. Participants leave able to build or strengthen a programme that would withstand supervisory scrutiny and a genuine operational crisis.
Expected Learning Outcomes
Map the people, process, technology, facility and third-party dependencies underpinning each important business service.
Set impact tolerances defining the maximum tolerable duration and extent of service disruption.
Design severe-but-plausible scenario tests covering cyber, third-party and facilities disruption.
Evaluate testing results to determine whether a firm can remain within its stated impact tolerances.
Prepare the operational resilience self-assessment document expected by supervisors.
Build remediation plans addressing vulnerabilities identified through scenario testing.
Who Should Attend
Operational resilience programme leads and heads of business continuity in regulated firms.
Chief operating officers responsible for important business service delivery.
Risk management staff mapping third-party and technology dependencies.
Regulatory affairs specialists preparing operational resilience supervisory submissions.
Board members and senior managers accountable for operational resilience oversight.
Third-party and vendor risk managers assessing dependency mapping requirements.
Course Modules
Select any module to see its sessions and points.
01Identifying Important Business Services
2 sessions · 8 points
Session 1Defining and Prioritising Important Business Services
- Apply harm-based criteria to identify which business services qualify as important business services.
- Assess the customer and market integrity impact of disruption to each candidate service.
- Prioritise important business services based on the severity and breadth of potential harm.
- Document the rationale for including or excluding a service from the important business service list.
Session 2Governance and Ownership Structures
- Assign named service owners accountable for each important business service's resilience.
- Establish a governance forum overseeing operational resilience across all important business services.
- Define escalation paths from service owners to senior management during a live disruption.
- Align operational resilience governance with existing risk and business continuity committees.
02Dependency Mapping and Impact Tolerance
2 sessions · 8 points
Session 1Mapping Underlying Dependencies
- Map the people, processes and technology systems each important business service depends on.
- Identify facilities and physical infrastructure dependencies supporting service delivery.
- Map third-party and outsourced provider dependencies, including fourth-party concentration risk.
- Build a dependency register that is kept current as systems and providers change over time.
Session 2Setting and Justifying Impact Tolerances
- Set impact tolerances defining the maximum tolerable disruption duration for each important business service.
- Justify tolerance levels using customer harm analysis and historical incident data.
- Calibrate tolerances that are neither unrealistically tight nor so loose they provide no real constraint.
- Document tolerance-setting rationale in a form defensible to supervisors and internal audit.
03Severe-but-Plausible Scenario Testing
2 sessions · 8 points
Session 1Designing Scenario Tests
- Design cyber-attack scenarios testing the firm's ability to maintain a service within its impact tolerance.
- Build third-party failure scenarios simulating loss of a critical outsourced provider.
- Construct facilities loss scenarios covering data centre or key site unavailability.
- Combine scenario elements to test compounding disruption affecting multiple dependencies simultaneously.
Session 2Evaluating and Documenting Test Results
- Evaluate whether test results demonstrate the firm remaining within its stated impact tolerance.
- Identify vulnerabilities exposed during testing that require remediation investment.
- Compare test outcomes against previous testing cycles to track resilience improvement over time.
- Document testing methodology and results in a form suitable for supervisory review.
04Self-Assessment, Reporting and Remediation
2 sessions · 8 points
Session 1Preparing the Self-Assessment Document
- Compile the self-assessment document covering important business services, tolerances and test results.
- Present the self-assessment for board review and formal sign-off before submission.
- Address common supervisory feedback themes on self-assessment completeness and evidence quality.
- Update the self-assessment on a defined cycle reflecting material business or technology changes.
Session 2Remediation Planning and Continuous Improvement
- Build remediation plans addressing each vulnerability identified through scenario testing.
- Prioritise remediation investment based on the severity of the resilience gap identified.
- Track remediation progress against milestones reported to the operational resilience governance forum.
- Embed lessons from testing and real incidents into the next cycle of scenario design.
What the participant receives
4 course modules
A structured syllabus
8 training sessions
across 5 days
32 detailed points
Applied, detailed content
Accredited attendance certificate
On completing the programme
Complete your registration
We will contact you within one business day to confirm.
Ready to start?
Reserve your seat and start building the skill.
