Operational resilience is the ability of financial institutions to continue to operate effectively and provide essential services in the event of a disruption. This includes disruptions caused by natural disasters, cyber attacks, IT outages, or human error.
There are many different definitions of operational resilience, but they all share the same basic idea: the ability to withstand and recover from disruptions. The following are some examples of definitions from UK subject matter experts:
Technology resilience is a key component of operational resilience. It refers to the ability of technology systems to withstand and recover from disruptions. This includes disruptions caused by hardware failures, software bugs, or network outages.
There are many different aspects of technology resilience that financial institutions need to consider, including:
The regulatory landscape for operational resilience is constantly evolving. In the US, the Securities and Exchange Commission (SEC) and the Federal Deposit Insurance Corporation (FDIC) have both issued guidance on operational resilience. In the UK, the FCA has published a number of policies and guidance on operational resilience, including PS21/3: Building Operational Resilience.
In the EU, the European Banking Authority (EBA) has published a number of guidelines on operational resilience, including EBA/GL/2021/05: Guidelines on Operational Resilience. And in Asia, the Monetary Authority of Singapore (MAS) has published a number of guidelines on operational resilience, including MAS Notice 654: Guidelines on Technology Risk Management for Financial Institutions.
The following table summarizes the key regulators, regulations, and timescales for implementation for operational resilience in the US, UK, EU, and Asia:
Region | Regulator | Regulation | Timescale for implementation |
US | SEC | SR-FINREG-2022-001: Operational Resilience Rule | 1 January 2023 |
UK | FCA | PS21/3: Building Operational Resilience | 31 March 2023 |
EU | EBA | EBA/GL/2021/05: Guidelines on Operational Resilience | 31 December 2022 |
Asia | MAS | MAS Notice 654: Guidelines on Technology Risk Management for Financial Institutions | 31 December 2022 |
Operational resilience is an important topic for financial institutions of all sizes. By understanding the risks to their operational resilience and implementing appropriate controls, financial institutions can help to protect their customers, their reputation, and their financial stability.
References