South African organisations can use ISO 22301 as an international BCMS baseline, while regulated sectors add local requirements. For banks, the South African Reserve Bank (SARB) Prudential Authority has explicitly directed banks to consider the adequacy and robustness of their operational-resilience practices against the Basel Committee’s Principles for Operational Resilience. Government contingency-planning guidance also exists, but applicability and authority should be checked for the organisation concerned.
South Africa BCM reference map
| Reference | Scope / audience | Continuity emphasis |
|---|---|---|
| ISO 22301:2019 | Voluntary/contractual/certification baseline across sectors | BCMS governance, BIA, strategy, plans, exercises and improvement |
| SARB Prudential Authority Directive D10/2021 | Banks, branches of foreign institutions and controlling companies within the directive | Enterprise-wide operational resilience and alignment to Basel operational-resilience principles |
| Basel Principles for Operational Resilience | International banking-prudential reference used by SARB PA directive | Governance, operational risk, BCP/testing, mapping, third-party dependencies, incident management, resilient ICT |
| South African government contingency-planning guidance | Relevant public-sector / contingency-planning contexts | Structured contingency planning and arrangements; confirm current applicability for the entity |
| Sector regulators / critical infrastructure obligations | Organisation-specific | Additional obligations can apply; maintain an applicability register |
Banking operational resilience: move from plans to core business services
SARB PA Directive D10/2021 highlights that complex and interconnected business models expose banks to evolving operational risks and requires an enterprise-wide, systematic approach to operational resilience so core business services can be sustained. For BCM practitioners, that means evidence should connect business services to critical operations, technology, people, facilities and third parties; plans and DR tests alone are not enough if the organisation cannot explain the service outcome under disruption.
Basel operational-resilience principles translated into BCM records
| Principle area | BCM implementation record |
|---|---|
| Governance | Board/senior accountability, tolerance/risk decisions, unresolved vulnerability reporting |
| Operational risk management | Disruption scenarios and controls integrated with wider operational risk |
| Business continuity planning and testing | Current plans, exercises, actual incident lessons and measured recovery outcomes |
| Mapping interconnections/interdependencies | Core service → process → people → technology → facilities → information → third parties |
| Third-party dependency management | Critical supplier inventory, concentration, resilience evidence, exit/contingency |
| Incident management | Classification, escalation, response structure, communication and lessons learned |
| ICT including cyber security | Resilient architecture, backup/recovery, cyber response, tested restoration and data integrity |
South Africa continuity evidence pack
- Inventory of core/critical business services and accountable owners.
- BIA evidence showing impact over time, recovery requirements and minimum service.
- Dependency maps with people, technology, site, information and third-party concentration.
- BCPs with activation authority, degraded-service design, communications and return to normal.
- DR evidence with measured recovery time/point and business validation.
- Severe-but-plausible exercises that include supplier, technology, site and people failure modes.
- Operational resilience vulnerabilities and remediation tracked to closure.
- Management reporting focused on capability gaps, not only percentage of plans marked “current.”
Worked South Africa banking example
A bank identifies a core digital-payment service and maps it to customer channels, authentication, fraud decisioning, payment processing, telecom connectivity, operations staff and two external providers. A scenario removes the primary data centre and creates telecom congestion. Technology recovery meets the application RTO, but customers in one region cannot authenticate reliably. The finding is an operational-resilience vulnerability because the service outcome remains degraded despite the successful DR metric. Remediation therefore targets telecom/authentication diversity and an alternate customer route, followed by an integrated retest.
South Africa practitioner checklist
- For banks, review the SARB Prudential Authority operational-resilience directive and Basel principles in the institution’s current supervisory context.
- Identify core business services/outcomes and connect them to BIA, BCP, DR and third-party evidence.
- Do not copy banking-specific expectations into unrelated industries without confirming applicability.
- Use ISO 22301 where an international BCMS control framework is appropriate.
- Integrate cyber resilience and supplier concentration into continuity scenarios.
- Measure actual service outcomes during exercises; system recovery alone is insufficient.
- Maintain local legal/regulatory references by entity and review them when rules change.
Official references and further reading
- SARB Prudential Authority Directive D10/2021 — Directive on operational resilience for South African banks.
- Basel Principles for Operational Resilience — International banking principles referenced by the SARB PA directive.
- South African Government contingency planning guideline — Government-published contingency-planning guideline; verify relevance/applicability for the entity.
- ISO 22301:2019 — International BCMS requirements baseline.
SARB / Basel: operational resilience evidence for banks
SARB Prudential Authority Directive D10/2021 directs banks in scope to consider the adequacy and robustness of their operational-resilience practices against the Basel Committee principles. The principles cover governance, operational risk management, business continuity planning/testing, mapping interconnections and interdependencies of critical operations, third-party dependency management, incident management, and resilient ICT including cyber security.
| Basel principle area | BCM evidence question |
|---|---|
| Governance | Who is accountable for resilience of core/critical operations and unresolved weaknesses? |
| Operational risk | How do disruption scenarios and controls connect with operational-risk management? |
| BCP and testing | Can the bank demonstrate recovery/continuity through exercises rather than plan currency only? |
| Mapping | Are people, technology, processes, information, facilities and third parties mapped to critical operations at useful granularity? |
| Third parties | Are critical dependency, concentration and recovery assumptions known and tested? |
| Incident management | Are severity, escalation, communications, decisions and lessons integrated with continuity plans? |
| ICT/cyber | Can critical operations withstand technology/cyber disruption and recover trusted services/data? |
South Africa banking scenario
A digital banking service depends on mobile channels, identity, fraud controls, core banking, telecom connectivity and two third parties. A DR test recovers the core application within target but a telecom dependency prevents a material customer segment from authenticating. An application-level RTO dashboard could show green, while an operational-resilience view remains red because the core service outcome is not being delivered. The corrective action therefore targets dependency diversity and customer fallback, then retests the end-to-end service.
Operational resilience review pack for a South African bank
| Review area | Evidence to challenge |
|---|---|
| Core service scope | Definition, accountable owner, customer/market outcome and why disruption matters |
| Tolerance / recovery requirement | Maximum disruption and service-level recovery assumptions linked to business impact |
| Dependency mapping | People, processes, technology, information, facilities, utilities and third parties at enough detail to find common-mode failures |
| Scenario testing | Severe operational scenarios that combine technology, cyber, supplier and workforce constraints rather than testing one component only |
| Third-party resilience | Service-specific recovery evidence, concentration and substitution/exit constraints |
| Incident response | Escalation, crisis communications, decision logging and handover into recovery |
| ICT resilience | Architecture, backup, identity, network and cyber recovery evidence connected to the service |
| Remediation | Material vulnerabilities have owner, funding, due date and retest evidence |
For organisations outside banking, the SARB/BCBS material can still be educational, but it should not be presented as a binding requirement unless the entity is actually in scope. A general ISO 22301 BCMS or other sector-specific framework may be more appropriate.