UK business continuity combines an international/UK-adopted management-system standard with public-sector civil-contingencies duties and, in financial services, a distinct operational-resilience regime focused on important business services and customer/market harm. These frameworks are related but not interchangeable. A firm should first identify whether it is pursuing BS EN ISO 22301 conformity, subject to statutory responder duties, within FCA/PRA operational-resilience scope, or using good practice voluntarily.
United Kingdom BCM reference map
| Reference | Scope / audience | Key BCM idea |
|---|---|---|
| BS EN ISO 22301:2019+A1:2024 | Organisations using the UK adoption of ISO 22301 | BCMS requirements plus the 2024 climate-action amendment |
| Cabinet Office Emergency Preparedness – Chapter 6 | Civil Contingencies Act responder context | Business continuity arrangements for Category 1 responders and support for resilience duties |
| FCA SYSC 15A | In-scope FCA firms | Identify important business services, set impact tolerances, map resources and perform severe-but-plausible scenario testing |
| PRA SS1/21 | Relevant PRA-regulated firms | Operational resilience and impact-tolerance expectations for important business services |
| BCI Good Practice Guidelines 7.0 | Practitioners globally; BCI based in UK | Six professional practices covering BCMS establishment through validation |
Important business service and impact tolerance are not just new names for process and RTO
Under FCA operational-resilience rules, an in-scope firm identifies distinct important business services and sets an impact tolerance for each. The firm must be able to remain within that tolerance during severe but plausible disruption. FCA guidance asks firms to consider factors such as client vulnerability, number of clients, financial loss, market confidence, loss of functionality, data confidentiality/integrity/availability and knock-on effects. This is an outcome-and-harm lens. A process RTO can support the service, but it is not automatically the impact tolerance.
Mapping: build the service chain
FCA mapping requires in-scope firms to identify and document the people, processes, technology, facilities and information needed to deliver each important business service, sufficiently to identify vulnerabilities and remediate them. Third parties supporting the service are part of that understanding. A useful implementation adds owner, location, minimum capacity, recovery capability and evidence to each dependency so the map drives action rather than becoming a static diagram.
| Layer | Example fields | Test question |
|---|---|---|
| Service outcome | Important service, customers, harm, impact tolerance | Can we continue the outcome within tolerance? |
| Process | Activities, handoffs, cut-offs, manual alternatives | Which step becomes the bottleneck first? |
| People | Role, minimum staff, location, access, alternate | Can the service operate with severe absenteeism? |
| Technology / information | App, data, RTO/RPO, identity, integration | Does end-to-end recovery fit inside the service tolerance? |
| Facilities | Site, seats, equipment, access, utilities | Is alternate capacity real under a regional scenario? |
| Third parties | Service, subcontractor, commitment, escalation, exit | Can a common supplier failure break multiple services? |
Scenario testing: severe but plausible
FCA rules require scenario testing for in-scope firms to assess whether important services can remain within impact tolerances. Scenarios can include unavailability of facilities or key people, critical third-party failure, disruption to market participants, or loss/reduction of technology. Test the end-to-end service, not only one system. Measure customer/service outcomes and identify vulnerabilities that need remediation.
Civil Contingencies Act context
Cabinet Office Emergency Preparedness guidance includes a dedicated business-continuity chapter. For Category 1 responders, the framework includes a duty to maintain plans so they can continue to perform functions during emergencies so far as reasonably practicable. Organisations outside that statutory responder scope may still find the public guidance useful, but should not describe themselves as subject to those duties without confirming applicability.
UK evidence pack for financial operational resilience
| Evidence | What good looks like |
|---|---|
| Important business service inventory | Distinct services, rationale, review date and accountable owner |
| Impact tolerance record | Approved tolerance with harm rationale and peak-demand consideration |
| Mapping | People/process/technology/facilities/information and third-party dependencies with vulnerabilities |
| Testing plan | Scenario portfolio, objectives, coverage, frequency rationale and progression |
| Scenario results | Observed service outcome, breach/near-breach, assumptions, lessons and remediation |
| Self-assessment / governance | Management/board-level understanding of approach, vulnerabilities, decisions and evidence |
| BCM/DR link | Process/system RTO/RPO/MBCO and recovery tests traceable to important service needs |
Worked UK example: digital payment service
An in-scope firm identifies “allow retail customers to make time-critical outbound payments” as an important business service. It defines an impact tolerance using customer harm and market/operational considerations, then maps the service through mobile/web channels, fraud controls, identity, payment engine, network, data, operations staff and a third-party provider. A scenario removes the primary cloud region and then degrades the third-party fraud service. The payment engine itself recovers inside its RTO, but the service remains outside acceptable capacity because fraud decisions cannot be processed. The resulting action targets the end-to-end dependency, not the already-green application recovery metric.
Official references and further reading
- BSI BS EN ISO 22301:2019+A1:2024 — UK adoption/listing of ISO 22301 with Amendment 1:2024.
- GOV.UK Emergency Preparedness — Includes Chapter 6 on Business Continuity Management.
- FCA SYSC 15A — Operational resilience requirements for in-scope firms.
- PRA SS1/21 — PRA expectations for important business services and impact tolerances.
- BCI GPG 7.0 — Practitioner good practice framework.
UK operational resilience: impact tolerance is not just an RTO
For firms within the FCA/PRA operational-resilience scope, the important business service is considered from the external outcome/harm perspective. The firm identifies the service, sets an impact tolerance for the maximum tolerable disruption, maps resources needed to deliver it, tests severe-but-plausible scenarios and remediates vulnerabilities. A system RTO is one input; it does not by itself show that the firm can remain within the service impact tolerance.
| Question | BCM / RTO view | Operational-resilience view |
|---|---|---|
| What is the object? | Process, application or service recovery target | Important business service and harm from disruption |
| What is the limit? | Target time to recover / maximum tolerable disruption | Impact tolerance: maximum tolerable disruption in terms of harm, often with time metric |
| What must be mapped? | Dependencies needed for recovery | People, processes, technology, facilities, information and third parties needed to deliver the service |
| What proves capability? | BCP/DR exercise meets target | Severe-but-plausible scenario testing shows service can remain within impact tolerance |
| What happens to gaps? | Corrective action / risk acceptance | Vulnerabilities prioritised, funded, governed and retested |
UK self-assessment evidence questions
- Why is this an important business service?
- How was the impact tolerance set and what harm metrics support it?
- What mapping depth is necessary to identify vulnerabilities?
- Which third parties are material and what happens if they fail?
- Which severe-but-plausible scenarios were tested?
- What vulnerabilities were discovered and how are they funded/remediated?
- What has management/board governance challenged or approved?
- How are lessons from real incidents and near misses fed back into testing?
Civil Contingencies Act BCM context
UK Cabinet Office emergency-preparedness guidance includes a dedicated chapter on Business Continuity Management in the Civil Contingencies Act framework. Public-sector and responder organisations should read the relevant statutory guidance in their own context rather than assuming private-sector ISO implementation is equivalent to public-sector duties.