Operational Resilience FCA PS21/3 and PRA PS6/21 … Why ...

文章推薦指數: 80 %
投票人數:10人

Operational Resilience, FCA PS21/3 and PRA PS6/21…Why it is not just BI. Paul Greenhalgh and Robert Simpson January 6, 2022. operational resilience fca. Home>Blog>OperationalResilience,FCAPS21/3andPRAPS6/21…WhyitisnotjustBI Blog OperationalResilience,FCAPS21/3andPRAPS6/21…WhyitisnotjustBI PaulGreenhalghandRobertSimpson January6,2022 Somefirmsmistakenlyconcludethatreportingontheirbusinesscontinuityactivitiesusingtheregulator’sparlanceissufficient.Itisnot. Inreality,theobligationsthatthepolicystatementsdescribeareconsiderablyfurtherreaching,detailingthenecessityforastep-changeinafirm’sapproachtoensuringoperationalresilience.Theyexplaintheneedtotranslatethefiveinterventionstepsdescribedinthepolicystatements(prepare,detect,respond,recoverandadapt)tosolutiondesignprinciplesandthenidentifyareasofstrategicandoperationalimportanceforfutureinvestmentandimprovement.Servicesneedtobeidentifiedandmappedtoprocessesandresources.Customer,firmandmarketimpacttolerancesneedtobesetandplausibledisruptionscenariosdefinedandtested. Toachievealloftheseaviewofthefirm’swiderresourceecosystemisneeded.Itisessentialthatanup-to-dateholisticviewofthefirmsoveralloperationalresiliencehealthisreadilyaccessibletoallkeystakeholders,allofthetime.Improvedoversightoftheentirerangeofresourcetypesandthetimelydetectionofresourcevulnerabilitiesiskeytomakingsurethatthoseresponsibleforensuringtheoperationalresilienceofimportantbusinessserviceshavethedatatheyneed. Traditionalbusinessintelligenceanddatavisualisationtoolsdoagreatjobofretroactivelyreportingontrendsandhelpingdiscoverpatternsofpastbehaviour.TheyareanessentialpartofafirmsreportingcapabilityandITecosystembuttheydonotdelivertheactionableinsightrequired,nordotheysupporttheworkflowsandprocessesrequired,tocontinuallyassureafirm’soperationalresilience. Reportingthatincludesthedocumentationofworkflows,thedecision-makingprocessesandthecurationofevidenceisanotherareainwhichBItoolssimplyarenotabletoprovidethefunctionalityrequired.Theregulatorsmakeitclearthatafirmisexpectedtoshowevidenceofprocessessuchas: Whyaserviceisconsideredtobeimportantorisnot? Whyimpacttoleranceshavebeensetwheretheyhave? Whichcriteriahavebeenused,why,andhowoftenhaveimportantservicesbeentestedagainstplausiblebusinessscenarios;inadditiontotheresultsofthetesting. TheIBSreassessments,thelogicused;opinionsofstakeholders;justificationsandtheindividualsresponsible. Whyinvestmentdecisionshavebeentaken,whyandwhattheywilldelivertowardstheaimofimprovingthefirm’soperatingresilience. TheFCA’sandPRA’sBuildingOperationalResiliencePolicyStatements21/3&6/21describetheneedforfirmsto: Identifyimportantbusinessservicesanddetermineappropriateimpacttolerances. Identifyanddocumentthenecessarypeople,processes,technology,facilitiesandresourcesrequiredtodelivertheimportantbusinessservices. Usescenariosandlearningtodetermineifservicesareresilientagainstdefinedimpacttolerances. AsolutionwiththeFCA/PRA’spolicystatement/satitsheartisneeded,ratherthantryingtoretrofittherequirementsandrepurposingexistingBIsolutions.ThesolutionneedstobefocusedontranslationofthefiveinterventionstepsdescribedinBuildingOperationalResiliencePS21/3and6/21tokeysolutiondesignprinciples.Thiswillallowfirmstobetterprioritiseareasofstrategicandoperationalimportanceforinvestment.Itmustbecomprehensiveandallowfirmstoidentifyandmapallservices,processesandresources.Customer,firmandmarketimpacttolerancesthenneedtobesetandplausibledisruptionscenariosdefinedandtested.Thesolutionmustsupportalloftheseelements,endtoend.Finally,thesolutionmustbeconnectedasitmustintegratewiththewiderITecosystemtoenablethedetectionofresourcevulnerabilitiesanddelivertheholisticoversightofafirm’soperationalresiliencethatisdemanded. CorporaterOperationalResilienceSolution Corporater’sOperationalResiliencesoftwaresolution’soutoftheboxfunctionalityallowsfirmstoprepare,detect,respond,recoverandadapttodisruptionstoimportantbusinessservices. FormoreinformationseeCorporaterOperationalResilienceSolution. Interestedtoseeademo?Contactus. OperationalResilienceintheUKfinancialsector:FrequentlyAskedQuestions LearnmoreaboutOperationalResilienceintheUKfinancialsector.ClickheretoaccessOperationalResilienceFAQsansweredbyourspecialistsontheimplications,practiceandimplementationoftheoperationalresilienceframeworkintheUK. PopularBlogs AdvantagesvsBenefitsofRiskManagement Readmore> TenBenefitsOfUsingTechnologyinStrategyManagement Readmore> WhatisGRC(Governance,RiskandCompliance)? Readmore> KPIismorethananumber.ItisaStory! Readmore> OperationalResiliencevsBusinessContinuity:AComparison Readmore> Tags BusinessContinuityManagement BusinessIntelligence ComplianceManagement OperationalResilience PerformanceManagement



請為這篇文章評分?