Basel Committee on Banking Supervision – Principles for Operational Resilience (March 2021)

SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting. Framework text may require a separate license unless explicitly provided.
Overview
The Principles for Operational Resilience, published by the Basel Committee on Banking Supervision on 31 March 2021, set out seven principles for strengthening banks' ability to deliver critical operations through disruption. The Committee defines operational resilience as the ability of a bank to deliver critical operations through disruption, which requires it to identify and protect itself from threats and potential failures, respond and adapt to them, and recover and learn from disruptive events.
The BCBS, hosted by the Bank for International Settlements, issued the principles together with revisions to its Principles for the Sound Management of Operational Risk (PSMOR), which it first published in 2003 and revised in 2011. The principles are addressed to internationally active banks and their supervisors; member jurisdictions implement them through national rules and supervisory expectations rather than by direct legal effect.
Banks implement the principles by using existing governance to set an operational resilience approach, identifying critical operations and the tolerance for disruption to each, mapping the internal and external interconnections that support them, managing third-party dependencies, maintaining and testing business continuity plans, running incident management and ICT and cyber security programs, and reporting to the board. The revised PSMOR supplies the operational risk management framework on which this work rests.
Why it Matters
The principles are the international reference point that national regulators, including the PRA, the FCA, and APRA, drew on for their own operational resilience regimes, and supervisors of internationally active banks assess against them. They shift the question from whether individual risks are controlled to whether a bank can keep its critical operations running when something goes wrong.
Key benefits include:
- An international baseline
One set of principles gives banking groups a consistent foundation across the jurisdictions in which they operate.
- Focus on critical operations
Resilience is organized around the operations whose disruption would harm the bank, its customers, or financial stability.
- Built on operational risk management
The principles use existing governance and operational risk functions rather than creating a parallel structure.
- Coverage of modern dependencies
Third-party relationships, interconnections, and ICT and cyber security are addressed explicitly.
- Alignment with national regimes
Meeting the principles supports compliance with PRA SS1/21, FCA SYSC 15A, EU DORA, and similar rules.
How it Works
The document explains the Committee's definition of operational resilience, its relationship to operational risk management, and then states seven principles: governance; operational risk management; business continuity planning and testing; mapping interconnections and interdependencies; third-party dependency management; incident management; and ICT including cyber security. Each principle is followed by explanatory paragraphs on what the Committee expects and cross-references to the corresponding principles in the revised PSMOR, which itself contains twelve principles covering the board, senior management, the risk management environment, ICT, business continuity, and disclosure.
Banks apply the principles by having the board approve an operational resilience approach and a tolerance for disruption to critical operations, identifying those operations and mapping the people, technology, information, facilities, and third parties that deliver them, testing business continuity plans against severe but plausible scenarios, managing third-party and intra-group dependencies, maintaining incident response and recovery plans, and running ICT and cyber security programs that protect, detect, respond, and recover. Supervisors review the approach as part of their assessment of the bank's operational risk management.
Within SmartSuite, teams record critical operations and the tolerance for disruption to each, map interconnections and third parties, manage business continuity plans and tests, track incidents and lessons learned, and report resilience status to the board against each of the seven principles.
Key Elements
- Governance
Banks use their existing governance structure to establish, oversee, and implement an effective operational resilience approach approved by the board.
- Operational risk management
Banks leverage their operational risk management functions to identify external and internal threats and potential failures in people, processes, and systems, and to assess and manage them.
- Business continuity planning and testing
Banks maintain business continuity plans and conduct exercises against a range of severe but plausible scenarios.
- Mapping interconnections and interdependencies
Once critical operations are identified, banks map the internal and external interconnections and interdependencies needed to deliver them.
- Third-party dependency management
Banks manage their dependencies on third parties and intra-group entities that support critical operations.
- Incident management
Banks develop and implement response and recovery plans to manage incidents that could disrupt critical operations, and learn from them.
- ICT including cyber security
Banks ensure resilient ICT, including cyber security, subject to protection, detection, response, and recovery programs that are tested and reviewed.
Framework Scope
The principles are addressed to internationally active banks and their supervisors and are implemented by member jurisdictions of the Basel Committee through their own rules and supervisory expectations. They cover the delivery of a bank's critical operations through disruption from any source, including pandemics, cyber incidents, technology failures, and natural disasters, and the governance, risk management, continuity, mapping, third-party, incident, and ICT arrangements that support it; they do not set capital requirements, which are addressed in the Basel III framework.
Framework Objectives
The Committee's objective is to promote a principles-based approach to improving operational resilience so that banks can withstand and recover from severe disruptions.
Give banks and supervisors a common definition of operational resilience centered on critical operations.
Ensure boards own an operational resilience approach and a tolerance for disruption.
Make banks understand the interconnections, interdependencies, and third parties behind their critical operations.
Require tested business continuity, incident response, and recovery capabilities.
Strengthen ICT and cyber security as an integral part of resilience.
Align the principles with the revised Principles for the Sound Management of Operational Risk so both are implemented together.
Framework in Context
The principles were issued alongside the revised Principles for the Sound Management of Operational Risk and build on earlier Committee guidance on corporate governance, outsourcing, business continuity, and operational risk. National regimes published in the same month, including PRA SS1/21 and FCA SYSC 15A in the United Kingdom, apply the same ideas of critical operations or important business services and tolerances for disruption, and EU DORA and APRA CPS 230 do so for the EU and Australia. ISO 22301 provides a management system for the business continuity elements, and the Basel III framework sets the capital standards that sit alongside the principles.
Common Framework Mappings
The BCBS Principles for Operational Resilience are commonly mapped to the national operational resilience regimes that implement them and to the continuity and capital standards that sit alongside them.
Mapped frameworks include:
PRA SS1/21
FCA SYSC 15A (PS21/3)
EU DORA
ISO 22301
Basel III
APRA CPS 230
- ClassificationCategoryOperational ResilienceDomainOperational ResilienceFramework FamilyOther
- Regulatory ContextTypeGuidanceLegal InstrumentSupervisory PrinciplesSectorFinancial SectorIndustryFinancial Services
- Region / PublisherRegionGlobalRegion DetailGlobal (Basel Committee)PublisherBasel Committee on Banking Supervision (BCBS)
- VersioningVersionMarch 2021Effective DateMarch 31, 2021Issue DateMarch 31, 2021
- AdoptionAdoption ModelRegulatory ComplianceImplementation ComplexityHigh
- Official ReferenceOpen Link in New TabSource
License included / downloadable: Yes
The principles are published free of charge by the Bank for International Settlements, and the seven principles and the revised PSMOR are included with the platform as a requirement set.
Framework text is licensed by its publisher and is included only where stated above.
How SmartSuite Supports BCBS Operational Resilience Principles
SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting.
For the BCBS principles, SmartSuite records critical operations and their tolerance for disruption, maps interconnections and third parties, manages business continuity plans, tests, and incidents, and reports resilience status to the board against each of the seven principles.
Principles and Critical Operations Library
Hold the seven principles, the twelve PSMOR principles, and the bank's critical operations with their tolerance for disruption in one structured record set.
Ownership, Cadence, and Accountability
Assign owners for each principle and critical operation, set review cycles, and track board approval of the resilience approach.
Evidence Collection and Audit Trail
Attach mapping outputs, continuity test results, and incident reviews with timestamps and reviewers for supervisory review.
Continuity Testing and Incident Management
Plan exercises against severe but plausible scenarios, log incidents and recovery, and record lessons learned.
Third-Party and Interconnection Mapping
Link internal functions, intra-group entities, and external providers to the critical operations they support.
Board and Supervisory Reporting
Produce dashboards and reports showing resilience status, open vulnerabilities, and remediation by principle.
Related frameworks

PRA SS1/21 sets the Prudential Regulation Authority's expectations for how UK banks and insurers identify important business services, set impact tolerances, and stay within them.

FCA PS21/3 and SYSC 15A require UK-regulated firms to identify important business services, set impact tolerances, map and test their resilience, and self-assess against them.

DORA is an EU regulation requiring financial firms to manage ICT risks, report incidents, test security, and oversee third-party providers.

ISO 22301 is a business continuity management standard helping organizations prepare for, respond to, and recover from disruptions.

Basel III is an international banking regulation framework that strengthens banks' capital, liquidity, and risk management to reduce systemic risk.
Frequently Asked Questions For BCBS Operational Resilience Principles
They are seven principles published by the Basel Committee on Banking Supervision on 31 March 2021 to strengthen banks' ability to deliver critical operations through disruption. They cover governance, operational risk management, business continuity, mapping interconnections, third-party dependencies, incident management, and ICT including cyber security. They were issued together with revisions to the Principles for the Sound Management of Operational Risk.
The Committee defines it as the ability of a bank to deliver critical operations through disruption. That ability lets a bank identify and protect itself from threats and potential failures, respond and adapt to them, and recover and learn from disruptive events to minimize their impact. Operational resilience is treated as an outcome of effective operational risk management.
No. The Basel Committee has no legal authority, and its standards and guidelines are implemented by member jurisdictions through national rules and supervisory expectations. Regimes such as PRA SS1/21, FCA SYSC 15A, and EU DORA give the same ideas legal effect. Supervisors of internationally active banks assess against the principles.
The Principles for the Sound Management of Operational Risk, first issued in 2003 and revised in 2011 and again in March 2021, set out twelve principles for managing operational risk. The resilience principles build on them and cross-reference them, for example on change management, ICT, and business continuity. The Committee expects banks to implement both together.
Critical operations are the activities, processes, services, and their supporting assets whose disruption would be material to the continued operation of the bank or its role in the financial system. Banks identify them, set a tolerance for disruption to each, and map the interconnections and third parties that deliver them. The concept parallels important business services in the UK regimes.
The UK regimes were published in the same month and apply the same concepts of critical services, tolerances for disruption, mapping, testing, and governance with legal force for UK firms. EU DORA does the same for EU financial entities with a focus on ICT risk. Banks that meet the Basel principles have most of the foundation those rules require.
SmartSuite records critical operations and their tolerance for disruption, maps interconnections and third parties, and manages business continuity plans, tests, and incidents. Each principle has an owner, a review cadence, and linked evidence, and dashboards show resilience status and remediation progress for the board and supervisors.
Manage controls, risks, evidence, and audits in one platform designed for modern governance, risk, and compliance.

