Guide

South Africa Business Continuity & Operational Resilience Guide

A practical South Africa BCM guide connecting ISO 22301 with SARB Prudential Authority and Basel operational-resilience expectations for banks.

South African organisations can use ISO 22301 as an international BCMS baseline, while regulated sectors add local requirements. For banks, the South African Reserve Bank (SARB) Prudential Authority has explicitly directed banks to consider the adequacy and robustness of their operational-resilience practices against the Basel Committee’s Principles for Operational Resilience. Government contingency-planning guidance also exists, but applicability and authority should be checked for the organisation concerned.

South Africa BCM reference map

ReferenceScope / audienceContinuity emphasis
ISO 22301:2019Voluntary/contractual/certification baseline across sectorsBCMS governance, BIA, strategy, plans, exercises and improvement
SARB Prudential Authority Directive D10/2021Banks, branches of foreign institutions and controlling companies within the directiveEnterprise-wide operational resilience and alignment to Basel operational-resilience principles
Basel Principles for Operational ResilienceInternational banking-prudential reference used by SARB PA directiveGovernance, operational risk, BCP/testing, mapping, third-party dependencies, incident management, resilient ICT
South African government contingency-planning guidanceRelevant public-sector / contingency-planning contextsStructured contingency planning and arrangements; confirm current applicability for the entity
Sector regulators / critical infrastructure obligationsOrganisation-specificAdditional obligations can apply; maintain an applicability register

Banking operational resilience: move from plans to core business services

SARB PA Directive D10/2021 highlights that complex and interconnected business models expose banks to evolving operational risks and requires an enterprise-wide, systematic approach to operational resilience so core business services can be sustained. For BCM practitioners, that means evidence should connect business services to critical operations, technology, people, facilities and third parties; plans and DR tests alone are not enough if the organisation cannot explain the service outcome under disruption.

Basel operational-resilience principles translated into BCM records

Principle areaBCM implementation record
GovernanceBoard/senior accountability, tolerance/risk decisions, unresolved vulnerability reporting
Operational risk managementDisruption scenarios and controls integrated with wider operational risk
Business continuity planning and testingCurrent plans, exercises, actual incident lessons and measured recovery outcomes
Mapping interconnections/interdependenciesCore service → process → people → technology → facilities → information → third parties
Third-party dependency managementCritical supplier inventory, concentration, resilience evidence, exit/contingency
Incident managementClassification, escalation, response structure, communication and lessons learned
ICT including cyber securityResilient architecture, backup/recovery, cyber response, tested restoration and data integrity

South Africa continuity evidence pack

  • Inventory of core/critical business services and accountable owners.
  • BIA evidence showing impact over time, recovery requirements and minimum service.
  • Dependency maps with people, technology, site, information and third-party concentration.
  • BCPs with activation authority, degraded-service design, communications and return to normal.
  • DR evidence with measured recovery time/point and business validation.
  • Severe-but-plausible exercises that include supplier, technology, site and people failure modes.
  • Operational resilience vulnerabilities and remediation tracked to closure.
  • Management reporting focused on capability gaps, not only percentage of plans marked “current.”

Worked South Africa banking example

A bank identifies a core digital-payment service and maps it to customer channels, authentication, fraud decisioning, payment processing, telecom connectivity, operations staff and two external providers. A scenario removes the primary data centre and creates telecom congestion. Technology recovery meets the application RTO, but customers in one region cannot authenticate reliably. The finding is an operational-resilience vulnerability because the service outcome remains degraded despite the successful DR metric. Remediation therefore targets telecom/authentication diversity and an alternate customer route, followed by an integrated retest.

South Africa practitioner checklist

  • For banks, review the SARB Prudential Authority operational-resilience directive and Basel principles in the institution’s current supervisory context.
  • Identify core business services/outcomes and connect them to BIA, BCP, DR and third-party evidence.
  • Do not copy banking-specific expectations into unrelated industries without confirming applicability.
  • Use ISO 22301 where an international BCMS control framework is appropriate.
  • Integrate cyber resilience and supplier concentration into continuity scenarios.
  • Measure actual service outcomes during exercises; system recovery alone is insufficient.
  • Maintain local legal/regulatory references by entity and review them when rules change.

Official references and further reading

SARB / Basel: operational resilience evidence for banks

SARB Prudential Authority Directive D10/2021 directs banks in scope to consider the adequacy and robustness of their operational-resilience practices against the Basel Committee principles. The principles cover governance, operational risk management, business continuity planning/testing, mapping interconnections and interdependencies of critical operations, third-party dependency management, incident management, and resilient ICT including cyber security.

Basel principle areaBCM evidence question
GovernanceWho is accountable for resilience of core/critical operations and unresolved weaknesses?
Operational riskHow do disruption scenarios and controls connect with operational-risk management?
BCP and testingCan the bank demonstrate recovery/continuity through exercises rather than plan currency only?
MappingAre people, technology, processes, information, facilities and third parties mapped to critical operations at useful granularity?
Third partiesAre critical dependency, concentration and recovery assumptions known and tested?
Incident managementAre severity, escalation, communications, decisions and lessons integrated with continuity plans?
ICT/cyberCan critical operations withstand technology/cyber disruption and recover trusted services/data?

South Africa banking scenario

A digital banking service depends on mobile channels, identity, fraud controls, core banking, telecom connectivity and two third parties. A DR test recovers the core application within target but a telecom dependency prevents a material customer segment from authenticating. An application-level RTO dashboard could show green, while an operational-resilience view remains red because the core service outcome is not being delivered. The corrective action therefore targets dependency diversity and customer fallback, then retests the end-to-end service.

Operational resilience review pack for a South African bank

Review areaEvidence to challenge
Core service scopeDefinition, accountable owner, customer/market outcome and why disruption matters
Tolerance / recovery requirementMaximum disruption and service-level recovery assumptions linked to business impact
Dependency mappingPeople, processes, technology, information, facilities, utilities and third parties at enough detail to find common-mode failures
Scenario testingSevere operational scenarios that combine technology, cyber, supplier and workforce constraints rather than testing one component only
Third-party resilienceService-specific recovery evidence, concentration and substitution/exit constraints
Incident responseEscalation, crisis communications, decision logging and handover into recovery
ICT resilienceArchitecture, backup, identity, network and cyber recovery evidence connected to the service
RemediationMaterial vulnerabilities have owner, funding, due date and retest evidence

For organisations outside banking, the SARB/BCBS material can still be educational, but it should not be presented as a binding requirement unless the entity is actually in scope. A general ISO 22301 BCMS or other sector-specific framework may be more appropriate.