concept

Operational Resilience Requirement

A supervisory expectation that a firm can continue delivering critical business services through disruption, expressed as an impact tolerance it must evidence.

Financial regulators have moved from asking whether systems are available to asking whether the business service continues — and requiring the firm to state, for each important service, the maximum tolerable disruption before intolerable harm occurs.

That reframing has architectural consequences. The unit of analysis is a service such as "make a payment" or "access funds", not an application, so the mapping from service to every supporting system, third party and person has to exist. The tolerance is a stated number the firm must be able to demonstrate it can meet, under severe but plausible scenarios, with evidence from testing rather than design intent.

Three things follow that ordinary availability engineering does not require. Severe but plausible scenario testing — a full region loss, a critical vendor failure, a ransomware event — exercised rather than modelled. Substitutability for critical third parties, meaning an assessed and rehearsed alternative rather than a clause in a contract. And the ability to operate in a degraded mode, because continuing to deliver a reduced service is frequently the realistic answer where full restoration within tolerance is not achievable.

Impact tolerance is therefore a design input of the same weight as an SLO, and usually a stricter one.