Governance, risk and compliance

SmartSuite for the Resilience Testing Lead

The Resilience Testing Lead plans and runs the scenario testing and exercise programme: severe-but-plausible scenarios, tabletop and live exercises, impact tolerance tests and the evidence regulators expect. They turn results into corrective actions and track them to closure.

What you own

  • Design the annual testing and exercise programme
  • Develop severe-but-plausible scenarios for important business services
  • Facilitate tabletop and live exercises
  • Test impact tolerances and document outcomes
  • Convert findings into corrective actions and track closure
  • Report test results and lessons learned to the resilience lead and regulators

Where the role sits

Each name opens that role's page.

Reports to

Head of Operational Resilience

Head of Operational Resilience

See the role

Direct reports

Works closely with

Business Continuity Manager

Business Continuity Manager

See the role
IT Disaster Recovery Lead

IT Disaster Recovery Lead

See the role
Crisis Management Lead

Crisis Management Lead

See the role
Business Continuity Analyst

Business Continuity Analyst

See the role

GRC processes

The shared GRC process map, highlighted for this role.

Owns

accountable for the process

resilience

Touches

contributes or approves

issues-actions, reporting

Depends on

consumes its output

risk, third-party

How SmartSuite helps, suite by suite

Each card is the persona record from that suite's Users tab.

No items found.

Suites that serve this role

How SmartSuite supports this role

Operational resilience. Schedules exercises, captures results and scores impact tolerance tests against each important business service.

Issues and actions. Converts exercise findings into corrective actions with owners and tracks them to closure.

Reporting. Produces regulator-ready testing evidence and lessons-learned reports.

Industry reference

ISO 22301:2019 clause 8.5 requires an exercise and test programme; the UK PRA's SS1/21 and the FCA's rules require firms to test important business services against severe-but-plausible scenarios and evidence they stay within impact tolerance. DORA Articles 24 to 27 require a digital operational resilience testing programme, with threat-led penetration testing for significant entities, built on TIBER-EU and CBEST.

Other sectors prescribe the cadence: CMS requires hospitals to run two exercises a year; FEMA's HSEEP methodology governs public sector exercises; SOC 2 and ISO 27001 auditors look for tested recovery plans at technology providers.

In their words

Related roles

Head of Operational Resilience

Head of Operational Resilience

See the role

See SmartSuite for your role

Start a free trial, or book a demo and we will walk through your role's workflows in SmartSuite.