Resource center · Operational Resilience

UK operational resilience: important business services and impact tolerances.

The United Kingdom regime asks a different question from DORA. Not “who supplies you” but “what would harm your clients if it stopped, and for how long can it stop”. Firms subject to both need to answer both.

Guide UK operational resilience · United Kingdom · outcomes-based regime

The shape of the regime

The United Kingdom regime is outcomes-based. There is no standard template and no periodic file submitted to a supervisor. What a firm must be able to produce, on request, is a coherent account: the services it considers important, the tolerances it has set, the resources those services depend on, the testing it has done, and the vulnerabilities that testing exposed.

That difference in shape is the reason firms subject to both regimes cannot simply extend one to cover the other. A complete DORA register does not demonstrate that a firm can remain within an impact tolerance, and a thorough impact-tolerance exercise does not produce the register.

Identifying important business services

An important business service is one whose disruption could cause intolerable harm to clients, or pose a risk to the soundness, stability or resilience of the financial system or the orderly operation of markets.

  • Services, not business lines. The regulator’s framing distinguishes a specific service a client receives from a collection of services described at product level. Accessing an account online and doing the same by telephone can be two services, while “lending” is a collection.
  • Harm to clients and to markets are separate tests. A service can qualify on either.
  • Lack of substitutability increases criticality but its presence does not justify excluding a service — firms should not assume other providers would step in.
  • Impacts are assessed before mitigation. Existing controls do not remove a service from the population.

Setting an impact tolerance

A tolerance is set for each important business service and expressed by reference to a duration; other metrics can be used, but alongside duration rather than instead of it. The factors to weigh include the nature of the client base and any vulnerability that makes clients more susceptible to harm, potential financial loss, potential reputational damage, and the aggregate effect of several services failing together where they share common resources identified in mapping.

A tolerance is a limit, not a target. It states the point beyond which harm becomes intolerable. Setting it at current recovery capability inverts the exercise — the tolerance is derived from harm to clients, and the gap to current capability is the finding.

Mapping and third parties

Mapping identifies the people, processes, technology, facilities and information each important business service relies on, in enough detail to identify vulnerabilities and to see where services share resources. Third parties appear here as dependencies of a service rather than as a population in their own right — which is precisely the inverse of the DORA register’s orientation, and the reason the two datasets are related but not interchangeable.

Scenario testing and self-assessment

Firms test their ability to remain within each tolerance under a range of severe but plausible disruption scenarios, and keep a written self-assessment covering the services, the tolerances, the mapping, the testing performed, lessons learned and remedial action. Compliance is kept under review and reconsidered when the business changes materially.

Running this alongside DORA

Two regimes, compared
DimensionUnited KingdomDORA
Organising unitThe important business serviceThe contractual arrangement
Central artefactSelf-assessment, held and produced on requestRegister of Information, reported at least yearly
PrescriptionOutcomes-based; no standard templateFixed templates, coded values, machine validation
Third partiesAs dependencies surfaced by mappingAs a population in their own right, with supply chain
Test appliedIntolerable harm to clients or to market integrityCritical or important function

The economical approach for a group operating across both is one dependency dataset serving two views: the arrangement-oriented register, and the service-oriented mapping. The determinations stay separate — a function that is critical or important is not automatically an important business service, and the reverse holds too.

Official sources

Primary instruments only. Each is named in full so the reference remains traceable even if a link moves.

  1. Financial Conduct Authority Handbook — SYSC 15A, Operational resilienceFCA Handbook · identification, impact tolerances, mapping, testing and self-assessment
  2. Prudential Regulation Authority — Operational resilience: impact tolerances for important business servicesBank of England · parallel expectations for firms within the prudential regulator’s scope
  3. Regulation (EU) 2022/2554 (DORA)EUR-Lex · Regulation · for the comparison in this record

REGREP is an independent software provider. This record explains a reporting framework in plain language and is not legal, tax or regulatory advice. Confirm scope, thresholds and submission dates with your competent authority before you file.

Keep reading

More on this framework, and the module that produces the filing.

All operational resilience resources

Two regimes, one dependency dataset.

United Kingdom operational resilience runs as a scoped engagement, sized to whether you also carry a European register.