Operational resilience
Competent authorities should form a holistic view on the ability of the institution to deliver critical or important functions through disruption (level of operational resilience), an outcome that benefits from the effective management of operational risk, taking into account the institution’s size, business model and overall risk profile. For this purpose, competent authorities should leverage on their existing assessments on operational risk management, business continuity, change management capabilities, third-party services and the ICT upon which the institution relies to holistically evaluate whether these elements collectively support the institution’s operational resilience. Competent authorities should also consider whether the institution implements its risk management framework, business continuity plans, third-party management (already assessed in the context of DORA and EBA Guidelines issued pursuant to Article 74(3) of Directive 2013/36/EU on internal governance arrangements, processes and mechanisms) and recovery and resolution frameworks in a consistent and coordinated manner. Moreover, competent authorities should consider whether the institution has sufficiently mapped the internal and external interconnections and interdependencies that are needed to deliver its critical or important functions.
Competent authorities should consider the attention given by the management body and senior management on the institution’s ability to respond to and recover from disruptions under the assumption that failures will occur. For this purpose, competent authorities should consider whether:
the management body takes an active role in establishing a broad understanding of the operational resilience approach across the institution and in monitoring the effectiveness of the institution’s operational resilience approach;
timely reporting on the institution’s ongoing operational resilience is provided in support of the management body’s oversight, particularly when major identified deficiencies could affect the delivery of the institution’s critical or important functions.