Guide

United Kingdom Business Continuity & Operational Resilience Guide

A practical UK guide connecting BS EN ISO 22301, Civil Contingencies guidance, BCI practice and FCA/PRA important-business-service operational resilience.

UK business continuity combines an international/UK-adopted management-system standard with public-sector civil-contingencies duties and, in financial services, a distinct operational-resilience regime focused on important business services and customer/market harm. These frameworks are related but not interchangeable. A firm should first identify whether it is pursuing BS EN ISO 22301 conformity, subject to statutory responder duties, within FCA/PRA operational-resilience scope, or using good practice voluntarily.

United Kingdom BCM reference map

ReferenceScope / audienceKey BCM idea
BS EN ISO 22301:2019+A1:2024Organisations using the UK adoption of ISO 22301BCMS requirements plus the 2024 climate-action amendment
Cabinet Office Emergency Preparedness – Chapter 6Civil Contingencies Act responder contextBusiness continuity arrangements for Category 1 responders and support for resilience duties
FCA SYSC 15AIn-scope FCA firmsIdentify important business services, set impact tolerances, map resources and perform severe-but-plausible scenario testing
PRA SS1/21Relevant PRA-regulated firmsOperational resilience and impact-tolerance expectations for important business services
BCI Good Practice Guidelines 7.0Practitioners globally; BCI based in UKSix professional practices covering BCMS establishment through validation

Important business service and impact tolerance are not just new names for process and RTO

Under FCA operational-resilience rules, an in-scope firm identifies distinct important business services and sets an impact tolerance for each. The firm must be able to remain within that tolerance during severe but plausible disruption. FCA guidance asks firms to consider factors such as client vulnerability, number of clients, financial loss, market confidence, loss of functionality, data confidentiality/integrity/availability and knock-on effects. This is an outcome-and-harm lens. A process RTO can support the service, but it is not automatically the impact tolerance.

Mapping: build the service chain

FCA mapping requires in-scope firms to identify and document the people, processes, technology, facilities and information needed to deliver each important business service, sufficiently to identify vulnerabilities and remediate them. Third parties supporting the service are part of that understanding. A useful implementation adds owner, location, minimum capacity, recovery capability and evidence to each dependency so the map drives action rather than becoming a static diagram.

LayerExample fieldsTest question
Service outcomeImportant service, customers, harm, impact toleranceCan we continue the outcome within tolerance?
ProcessActivities, handoffs, cut-offs, manual alternativesWhich step becomes the bottleneck first?
PeopleRole, minimum staff, location, access, alternateCan the service operate with severe absenteeism?
Technology / informationApp, data, RTO/RPO, identity, integrationDoes end-to-end recovery fit inside the service tolerance?
FacilitiesSite, seats, equipment, access, utilitiesIs alternate capacity real under a regional scenario?
Third partiesService, subcontractor, commitment, escalation, exitCan a common supplier failure break multiple services?

Scenario testing: severe but plausible

FCA rules require scenario testing for in-scope firms to assess whether important services can remain within impact tolerances. Scenarios can include unavailability of facilities or key people, critical third-party failure, disruption to market participants, or loss/reduction of technology. Test the end-to-end service, not only one system. Measure customer/service outcomes and identify vulnerabilities that need remediation.

Civil Contingencies Act context

Cabinet Office Emergency Preparedness guidance includes a dedicated business-continuity chapter. For Category 1 responders, the framework includes a duty to maintain plans so they can continue to perform functions during emergencies so far as reasonably practicable. Organisations outside that statutory responder scope may still find the public guidance useful, but should not describe themselves as subject to those duties without confirming applicability.

UK evidence pack for financial operational resilience

EvidenceWhat good looks like
Important business service inventoryDistinct services, rationale, review date and accountable owner
Impact tolerance recordApproved tolerance with harm rationale and peak-demand consideration
MappingPeople/process/technology/facilities/information and third-party dependencies with vulnerabilities
Testing planScenario portfolio, objectives, coverage, frequency rationale and progression
Scenario resultsObserved service outcome, breach/near-breach, assumptions, lessons and remediation
Self-assessment / governanceManagement/board-level understanding of approach, vulnerabilities, decisions and evidence
BCM/DR linkProcess/system RTO/RPO/MBCO and recovery tests traceable to important service needs

Worked UK example: digital payment service

An in-scope firm identifies “allow retail customers to make time-critical outbound payments” as an important business service. It defines an impact tolerance using customer harm and market/operational considerations, then maps the service through mobile/web channels, fraud controls, identity, payment engine, network, data, operations staff and a third-party provider. A scenario removes the primary cloud region and then degrades the third-party fraud service. The payment engine itself recovers inside its RTO, but the service remains outside acceptable capacity because fraud decisions cannot be processed. The resulting action targets the end-to-end dependency, not the already-green application recovery metric.

Official references and further reading

UK operational resilience: impact tolerance is not just an RTO

For firms within the FCA/PRA operational-resilience scope, the important business service is considered from the external outcome/harm perspective. The firm identifies the service, sets an impact tolerance for the maximum tolerable disruption, maps resources needed to deliver it, tests severe-but-plausible scenarios and remediates vulnerabilities. A system RTO is one input; it does not by itself show that the firm can remain within the service impact tolerance.

QuestionBCM / RTO viewOperational-resilience view
What is the object?Process, application or service recovery targetImportant business service and harm from disruption
What is the limit?Target time to recover / maximum tolerable disruptionImpact tolerance: maximum tolerable disruption in terms of harm, often with time metric
What must be mapped?Dependencies needed for recoveryPeople, processes, technology, facilities, information and third parties needed to deliver the service
What proves capability?BCP/DR exercise meets targetSevere-but-plausible scenario testing shows service can remain within impact tolerance
What happens to gaps?Corrective action / risk acceptanceVulnerabilities prioritised, funded, governed and retested

UK self-assessment evidence questions

  • Why is this an important business service?
  • How was the impact tolerance set and what harm metrics support it?
  • What mapping depth is necessary to identify vulnerabilities?
  • Which third parties are material and what happens if they fail?
  • Which severe-but-plausible scenarios were tested?
  • What vulnerabilities were discovered and how are they funded/remediated?
  • What has management/board governance challenged or approved?
  • How are lessons from real incidents and near misses fed back into testing?

Civil Contingencies Act BCM context

UK Cabinet Office emergency-preparedness guidance includes a dedicated chapter on Business Continuity Management in the Civil Contingencies Act framework. Public-sector and responder organisations should read the relevant statutory guidance in their own context rather than assuming private-sector ISO implementation is equivalent to public-sector duties.