SmartSuite for the Head of Operational Resilience
The Head of Operational Resilience leads the enterprise resilience programme: business impact analyses, important business service mapping, impact tolerances, continuity plans, testing and crisis management. They ensure every business unit maintains, tests and improves its plans.
What you own
- Own the resilience framework, policy and programme plan
- Identify important business services and set impact tolerances
- Coordinate business impact analyses with stakeholders
- Approve continuity and recovery plans across departments
- Manage the testing and exercising schedule and drive corrective actions
- Oversee crisis management escalation and communication
- Report readiness, RTOs and maturity to executives and the board
Where the role sits
Each name opens that role's page.
Reports to
Direct reports
Works closely with
GRC processes
The shared GRC process map, highlighted for this role.
Owns
accountable for the process
Touches
contributes or approves
Depends on
consumes its output
How SmartSuite helps, suite by suite
Each card is the persona record from that suite's Users tab.
How they use the Operational Resilience & Business Continuity suite
BIA execution
Coordinates BIAs with stakeholders.
Crisis response
Oversees escalations and communication.
Exercise planning
Tracks preparedness across teams.
How they use SmartSuite
Continuity Plan Management
Creates, reviews, and approves recovery plans across departments.
Testing & Exercising
Manages test schedules, captures results, and drives corrective actions.
Program Dashboards
Visualizes organizational RTOs, MTTRs, readiness levels, and overall maturity.
Suites that serve this role
How SmartSuite supports this role
Operational resilience. Structures BIAs, service mapping, continuity plans and exercise logs in one workspace so the programme runs on a schedule with automated reminders.
Risk management. Links important business services and their tolerances to the risks and controls that protect them.
Third-party risk. Maps critical vendors to the services that depend on them so concentration risk is visible.
Issues and actions. Captures corrective actions from tests and incidents and tracks them to closure.
Reporting. Visualises organisational RTOs, readiness levels and maturity for executive and board reporting.
Industry reference
ISO 22301:2019 provides the management system; the UK PRA's SS1/21 and FCA rules (fully in force March 2025) define the regulatory model of important business services, impact tolerances and scenario testing; the EU's DORA (from January 2025) applies it to ICT risk across financial entities; the Basel Committee's Principles for Operational Resilience (2021) set the international baseline.
Other sectors have their own anchors: CMS emergency preparedness rules (42 CFR 482.15) for healthcare providers, FEMA's continuity directives and NIST SP 800-34 for public bodies, and NIS2 and SOC 2 availability commitments for technology providers. The BCI Good Practice Guidelines cover the practice.
In their words
Related roles
See SmartSuite for your role
Start a free trial, or book a demo and we will walk through your role's workflows in SmartSuite.









