Operational Resilience
DETAIL

Basel Committee on Banking Supervision – Principles for Operational Resilience (March 2021)

SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting.
Framework text may require a separate license unless explicitly provided.

Overview

The Principles for Operational Resilience, published by the Basel Committee on Banking Supervision on 31 March 2021, set out seven principles for strengthening banks' ability to deliver critical operations through disruption. The Committee defines operational resilience as the ability of a bank to deliver critical operations through disruption, which requires it to identify and protect itself from threats and potential failures, respond and adapt to them, and recover and learn from disruptive events.

The BCBS, hosted by the Bank for International Settlements, issued the principles together with revisions to its Principles for the Sound Management of Operational Risk (PSMOR), which it first published in 2003 and revised in 2011. The principles are addressed to internationally active banks and their supervisors; member jurisdictions implement them through national rules and supervisory expectations rather than by direct legal effect.

Banks implement the principles by using existing governance to set an operational resilience approach, identifying critical operations and the tolerance for disruption to each, mapping the internal and external interconnections that support them, managing third-party dependencies, maintaining and testing business continuity plans, running incident management and ICT and cyber security programs, and reporting to the board. The revised PSMOR supplies the operational risk management framework on which this work rests.

Why it Matters

The principles are the international reference point that national regulators, including the PRA, the FCA, and APRA, drew on for their own operational resilience regimes, and supervisors of internationally active banks assess against them. They shift the question from whether individual risks are controlled to whether a bank can keep its critical operations running when something goes wrong.

Key benefits include:

  • An international baseline

One set of principles gives banking groups a consistent foundation across the jurisdictions in which they operate.

  • Focus on critical operations

Resilience is organized around the operations whose disruption would harm the bank, its customers, or financial stability.

  • Built on operational risk management

The principles use existing governance and operational risk functions rather than creating a parallel structure.

  • Coverage of modern dependencies

Third-party relationships, interconnections, and ICT and cyber security are addressed explicitly.

  • Alignment with national regimes

Meeting the principles supports compliance with PRA SS1/21, FCA SYSC 15A, EU DORA, and similar rules.

How it Works

The document explains the Committee's definition of operational resilience, its relationship to operational risk management, and then states seven principles: governance; operational risk management; business continuity planning and testing; mapping interconnections and interdependencies; third-party dependency management; incident management; and ICT including cyber security. Each principle is followed by explanatory paragraphs on what the Committee expects and cross-references to the corresponding principles in the revised PSMOR, which itself contains twelve principles covering the board, senior management, the risk management environment, ICT, business continuity, and disclosure.

Banks apply the principles by having the board approve an operational resilience approach and a tolerance for disruption to critical operations, identifying those operations and mapping the people, technology, information, facilities, and third parties that deliver them, testing business continuity plans against severe but plausible scenarios, managing third-party and intra-group dependencies, maintaining incident response and recovery plans, and running ICT and cyber security programs that protect, detect, respond, and recover. Supervisors review the approach as part of their assessment of the bank's operational risk management.

Within SmartSuite, teams record critical operations and the tolerance for disruption to each, map interconnections and third parties, manage business continuity plans and tests, track incidents and lessons learned, and report resilience status to the board against each of the seven principles.

Key Elements

  • Governance

Banks use their existing governance structure to establish, oversee, and implement an effective operational resilience approach approved by the board.

  • Operational risk management

Banks leverage their operational risk management functions to identify external and internal threats and potential failures in people, processes, and systems, and to assess and manage them.

  • Business continuity planning and testing

Banks maintain business continuity plans and conduct exercises against a range of severe but plausible scenarios.

  • Mapping interconnections and interdependencies

Once critical operations are identified, banks map the internal and external interconnections and interdependencies needed to deliver them.

  • Third-party dependency management

Banks manage their dependencies on third parties and intra-group entities that support critical operations.

  • Incident management

Banks develop and implement response and recovery plans to manage incidents that could disrupt critical operations, and learn from them.

  • ICT including cyber security

Banks ensure resilient ICT, including cyber security, subject to protection, detection, response, and recovery programs that are tested and reviewed.

Framework Scope

The principles are addressed to internationally active banks and their supervisors and are implemented by member jurisdictions of the Basel Committee through their own rules and supervisory expectations. They cover the delivery of a bank's critical operations through disruption from any source, including pandemics, cyber incidents, technology failures, and natural disasters, and the governance, risk management, continuity, mapping, third-party, incident, and ICT arrangements that support it; they do not set capital requirements, which are addressed in the Basel III framework.

Framework Objectives

The Committee's objective is to promote a principles-based approach to improving operational resilience so that banks can withstand and recover from severe disruptions.

Give banks and supervisors a common definition of operational resilience centered on critical operations.

Ensure boards own an operational resilience approach and a tolerance for disruption.

Make banks understand the interconnections, interdependencies, and third parties behind their critical operations.

Require tested business continuity, incident response, and recovery capabilities.

Strengthen ICT and cyber security as an integral part of resilience.

Align the principles with the revised Principles for the Sound Management of Operational Risk so both are implemented together.

Framework in Context

The principles were issued alongside the revised Principles for the Sound Management of Operational Risk and build on earlier Committee guidance on corporate governance, outsourcing, business continuity, and operational risk. National regimes published in the same month, including PRA SS1/21 and FCA SYSC 15A in the United Kingdom, apply the same ideas of critical operations or important business services and tolerances for disruption, and EU DORA and APRA CPS 230 do so for the EU and Australia. ISO 22301 provides a management system for the business continuity elements, and the Basel III framework sets the capital standards that sit alongside the principles.

Common Framework Mappings

The BCBS Principles for Operational Resilience are commonly mapped to the national operational resilience regimes that implement them and to the continuity and capital standards that sit alongside them.

Mapped frameworks include:

PRA SS1/21

FCA SYSC 15A (PS21/3)

EU DORA

ISO 22301

Basel III

APRA CPS 230

At a Glance
Basel Committee on Banking Supervision – Principles for Operational Resilience (March 2021)
  • Classification
    Category
    Operational Resilience
    Domain
    Operational Resilience
    Framework Family
    Other
  • Regulatory Context
    Type
    Guidance
    Legal Instrument
    Supervisory Principles
    Sector
    Financial Sector
    Industry
    Financial Services
  • Region / Publisher
    Region
    Global
    Region Detail
    Global (Basel Committee)
    Publisher
    Basel Committee on Banking Supervision (BCBS)
  • Versioning
    Version
    March 2021
    Effective Date
    March 31, 2021
    Issue Date
    March 31, 2021
  • Adoption
    Adoption Model
    Regulatory Compliance
    Implementation Complexity
    High
  • Official Reference
License Information

License included / downloadable: Yes

The principles are published free of charge by the Bank for International Settlements, and the seven principles and the revised PSMOR are included with the platform as a requirement set.

Framework text is licensed by its publisher and is included only where stated above.

Official Resources
Principles for operational resilience (BIS)
The Basel Committee publication page for the March 2021 principles, with summary and download.
Principles for operational resilience (PDF)
The full text of the seven principles with the Committee's definition of operational resilience and explanatory paragraphs.
Revisions to the principles for the sound management of operational risk (BIS)
The companion March 2021 publication that revises the twelve PSMOR principles on which the resilience principles build.
Basel Committee on Banking Supervision
The BIS overview of the Committee, its membership, and its role as the primary global standard setter for the prudential regulation of banks.
SMARTSUITE

How SmartSuite Supports BCBS Operational Resilience Principles

SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting.

For the BCBS principles, SmartSuite records critical operations and their tolerance for disruption, maps interconnections and third parties, manages business continuity plans, tests, and incidents, and reports resilience status to the board against each of the seven principles.

Principles and Critical Operations Library

Hold the seven principles, the twelve PSMOR principles, and the bank's critical operations with their tolerance for disruption in one structured record set.

Ownership, Cadence, and Accountability

Assign owners for each principle and critical operation, set review cycles, and track board approval of the resilience approach.

Evidence Collection and Audit Trail

Attach mapping outputs, continuity test results, and incident reviews with timestamps and reviewers for supervisory review.

Continuity Testing and Incident Management

Plan exercises against severe but plausible scenarios, log incidents and recovery, and record lessons learned.

Third-Party and Interconnection Mapping

Link internal functions, intra-group entities, and external providers to the critical operations they support.

Board and Supervisory Reporting

Produce dashboards and reports showing resilience status, open vulnerabilities, and remediation by principle.

Related frameworks

PRA SS1/21

PRA SS1/21 sets the Prudential Regulation Authority's expectations for how UK banks and insurers identify important business services, set impact tolerances, and stay within them.

FCA SYSC 15A (PS21/3)

FCA PS21/3 and SYSC 15A require UK-regulated firms to identify important business services, set impact tolerances, map and test their resilience, and self-assess against them.

EU DORA

DORA is an EU regulation requiring financial firms to manage ICT risks, report incidents, test security, and oversee third-party providers.

ISO 22301

ISO 22301 is a business continuity management standard helping organizations prepare for, respond to, and recover from disruptions.

Basel III

Basel III is an international banking regulation framework that strengthens banks' capital, liquidity, and risk management to reduce systemic risk.

APRA CPS 230

CPS 230 is an APRA standard requiring banks, insurers, and superannuation funds to manage operational risks and ensure resilience.

NIS2 (EU 2022/2555)

NIS2 establishes mandatory cybersecurity and incident-reporting requirements to strengthen resilience across essential and important EU organizations.

ONBOARDING FAQS

Frequently Asked Questions For BCBS Operational Resilience Principles

What are the BCBS Principles for Operational Resilience?

They are seven principles published by the Basel Committee on Banking Supervision on 31 March 2021 to strengthen banks' ability to deliver critical operations through disruption. They cover governance, operational risk management, business continuity, mapping interconnections, third-party dependencies, incident management, and ICT including cyber security. They were issued together with revisions to the Principles for the Sound Management of Operational Risk.

How does the Basel Committee define operational resilience?

The Committee defines it as the ability of a bank to deliver critical operations through disruption. That ability lets a bank identify and protect itself from threats and potential failures, respond and adapt to them, and recover and learn from disruptive events to minimize their impact. Operational resilience is treated as an outcome of effective operational risk management.

Are the principles legally binding?

No. The Basel Committee has no legal authority, and its standards and guidelines are implemented by member jurisdictions through national rules and supervisory expectations. Regimes such as PRA SS1/21, FCA SYSC 15A, and EU DORA give the same ideas legal effect. Supervisors of internationally active banks assess against the principles.

What is the relationship to the revised PSMOR?

The Principles for the Sound Management of Operational Risk, first issued in 2003 and revised in 2011 and again in March 2021, set out twelve principles for managing operational risk. The resilience principles build on them and cross-reference them, for example on change management, ICT, and business continuity. The Committee expects banks to implement both together.

What is a critical operation?

Critical operations are the activities, processes, services, and their supporting assets whose disruption would be material to the continued operation of the bank or its role in the financial system. Banks identify them, set a tolerance for disruption to each, and map the interconnections and third parties that deliver them. The concept parallels important business services in the UK regimes.

How do the principles relate to PRA SS1/21, FCA SYSC 15A, and DORA?

The UK regimes were published in the same month and apply the same concepts of critical services, tolerances for disruption, mapping, testing, and governance with legal force for UK firms. EU DORA does the same for EU financial entities with a focus on ICT risk. Banks that meet the Basel principles have most of the foundation those rules require.

How does SmartSuite support the BCBS principles?

SmartSuite records critical operations and their tolerance for disruption, maps interconnections and third parties, and manages business continuity plans, tests, and incidents. Each principle has an owner, a review cadence, and linked evidence, and dashboards show resilience status and remediation progress for the board and supervisors.

Operationalize BCBS Operational Resilience Principles with Connected Workflows

Manage controls, risks, evidence, and audits in one platform designed for modern governance, risk, and compliance.