CRO Operational Resilience Planning 3 — Questions and Answers
Question 1: Which element is NOT typically included in an operational resilience self-assessment?
- Identification of important business services
- Mapping of people, processes, and technology dependencies
- Competitor benchmarking of resilience capabilities (Correct answer)
- Testing of ability to remain within impact tolerances
Correct answer: Competitor benchmarking of resilience capabilities
Self-assessments focus on a firm's own capabilities, dependencies, and tolerance thresholds — not competitor comparisons.
Question 2: How does operational resilience differ fundamentally from traditional business continuity management (BCM)?
- BCM focuses on outcomes for customers; resilience focuses on internal processes
- Resilience focuses on maintaining important business services and customer outcomes; BCM focuses on restoring internal processes (Correct answer)
- Resilience applies only to technology; BCM covers all operations
- BCM is a regulatory requirement; resilience is optional best practice
Correct answer: Resilience focuses on maintaining important business services and customer outcomes; BCM focuses on restoring internal processes
Operational resilience is outcome-focused on services delivered to customers, whereas traditional BCM centers on restoring internal processes.
Question 3: A financial firm's payment processing service experiences a cyberattack. Under operational resilience principles, what is the firm's primary obligation?
- Report to law enforcement within one hour
- Remain within pre-set impact tolerances while managing the incident (Correct answer)
- Shut down all digital services as a precaution
- Communicate to shareholders before customers
Correct answer: Remain within pre-set impact tolerances while managing the incident
The firm must manage the incident while staying within defined impact tolerances to prevent intolerable harm to customers and markets.
Question 4: In the context of operational resilience, 'important business services' are defined by:
- Revenue contribution alone
- The potential for harm to customers, counterparties, or market integrity if disrupted (Correct answer)
- Internal management priorities
- Services covered by existing insurance policies
Correct answer: The potential for harm to customers, counterparties, or market integrity if disrupted
Important business services are those whose disruption could cause intolerable harm to customers, counterparties, or financial market integrity.
Question 5: What role does board governance play in operational resilience planning?
- Delegating all resilience decisions to the CRO without oversight
- Setting and approving impact tolerances and overseeing testing outcomes (Correct answer)
- Approving only technology-related resilience investments
- Reviewing resilience only after a major incident occurs
Correct answer: Setting and approving impact tolerances and overseeing testing outcomes
The board must approve impact tolerances and hold management accountable for testing and maintaining resilience capabilities.
Question 6: A firm discovers that its data backup restoration takes 72 hours but its impact tolerance for data recovery is 4 hours. The correct response is to:
- Extend the impact tolerance to match the current capability
- Invest in improving recovery capabilities to meet the 4-hour tolerance (Correct answer)
- Accept the gap as immaterial if the scenario is unlikely
- Document the gap and revisit it during the next annual review
Correct answer: Invest in improving recovery capabilities to meet the 4-hour tolerance
When actual recovery capabilities fall short of impact tolerances, the firm must close the gap through investment and process improvement.
Question 7: Which regulatory framework specifically introduced 'impact tolerance' as a core concept for UK financial services firms?
- Basel III operational risk framework
- PRA/FCA Operational Resilience Policy (PS6/21 and PS7/21) (Correct answer)
- ISO 22301 Business Continuity standard
- DORA (Digital Operational Resilience Act)
Correct answer: PRA/FCA Operational Resilience Policy (PS6/21 and PS7/21)
The UK PRA and FCA introduced impact tolerance as a central concept in their 2021 operational resilience policy statements (PS6/21 and PS7/21).
Which element is NOT typically included in an operational resilience self-assessment?