Reference

The Resilience Operating Discipline

A standing practice for keeping a critical service inside its stated tolerance, and for holding the evidence that it did.

Under stress, an institution runs the practice it already had.

Supervisors in six jurisdictions now ask institutions to demonstrate that a critical service holds inside a stated tolerance while it is failing. That proof comes from a practice the institution was already running: named owners, declared tolerances, mapped dependencies, tested recovery, and evidence produced on a schedule. The Resilience Operating Discipline sets out that practice, and the conditions under which an institution can honestly claim to have it.

What the expectation actually says

JurisdictionInstrumentWhat it requires
European UnionDORA, Regulation (EU) 2022/2554, applying January 2025ICT risk management and testing, including threat-led penetration testing for designated entities.
United KingdomPRA and FCA operational resilience policy, PS21/3, full compliance March 2025Important business services identified, impact tolerances set, and staying within them tested.
AustraliaAPRA CPS 230, effective July 2025Tolerance levels for critical operations, on disruption period, minimum service, and data loss.
CanadaOSFI Guideline E-21, published August 2024, full adherence expected 1 September 2026Operational risk management and resilience, including business continuity and crisis management. Guideline B-13 covers technology and cyber risk.
SingaporeMAS technology risk and business continuity requirementsRecovery and service-availability expectations for regulated financial institutions.
United StatesRegulation S-K Item 106, adopted July 2023Disclosure of cybersecurity risk-management processes and board oversight. Presently disclosure-led rather than tolerance-led.

The instruments differ, and the term of art differs with them. Impact tolerance is a United Kingdom construct. CPS 230 sets tolerance levels on separate axes. DORA does not use the term at all. What the six share is the shift from describing a control to demonstrating an outcome.

The distinction the discipline rests on

Compliance asks whether a control was designed and operating on the day it was examined. Resilience asks whether the service stayed inside its tolerance on the day it broke.

The second question is answerable only with evidence that existed before anyone asked for it. That is the whole of the difference, and it is the reason the discipline is a practice an institution maintains rather than a document it produces.

The practice

Six operations, and the order they run in.

The order matters. Every operation after the second depends on a tolerance having been set, and setting one is where implementations stall. None of them is finished once. Each has a cadence, and each produces something an outsider can be shown.

01
GovernanceStanding

Fix who decides

Named owners, decision rights, and a reporting line that reaches the board. Resilience fails at the seam between functions, so the discipline begins by settling who decides what before an incident rather than during one.

In practice that means one accountable executive per critical service, and a standing board agenda item. The common failure is a committee with shared executive accountability and no individual answer to the question of who calls it.

Produces a named owner for each critical service, and a standing item on the board agenda.

02
Impact tolerancesSet once

Set the tolerance

A stated maximum, set before anything breaks: how long a service may be unavailable, how degraded it may run, how much data may be lost.

This is the hardest part of the discipline and the part that creates most of its value, because it forces an institution to say in advance what it is prepared to survive. Almost every implementation that stalls, stalls here. A tolerance that no business owner will sign is a sign the service was never really understood, and the honest response is to go back to mapping.

Produces a stated maximum for each critical service, signed by the business owner who carries it and revisited on material change.

03
MappingContinuous

Map the dependencies

Which services are critical, what they depend on, and where those dependencies concentrate. Mapping records complexity. It does not remove it, and the output is a register that keeps changing rather than a diagram that hangs on a wall.

Produces a dependency register that changes when the estate changes.

04
TestingScheduled

Run it to the breaking point

Severe but plausible scenarios run against the mapped dependencies, far enough to find the breaking point. A test that everything passes has told the institution nothing it did not already believe.

Produces test results, including the ones that failed, with the breaking point named.

05
RecoveryDemonstrated

Demonstrate the recovery

The demonstrated ability to restore a critical service inside its tolerance. A recovery plan and a recovery capability are different objects, and only one of them is evidence.

Produces a recovery performed inside tolerance, and the time it actually took.

06
MeasurementContinuous

Produce the evidence

Test results, tolerance breaches, dependency changes, and recovery times, produced on a schedule and retained. Supervision is increasingly evidence-led, and evidence assembled after a request arrives is worth less than evidence that was already on the shelf.

Produces a retained record a supervisor can be shown without preparation.

Service availability against impact tolerance during a disruption Two recovery curves after the same disruption. Without the practice, availability falls below the stated impact tolerance and stays outside it for a long interval before recovering. With mapping, testing and rehearsed recovery, the curve turns above the tolerance line and the breach never occurs. The red line is the rehearsed practice and the gray line is the paper plan. Mapped, tested, rehearsed Plan on paper Service Impact tolerance The tolerance holds. Disruption Time Time outside tolerance, plan on paper.
The disruption still happens. A firm on a paper plan learns the width of that bracket during the incident.
The discipline moves where the curve turns, and it produces the record of the turn.

Provenance

Where the discipline came from.

It was written out of operating practice rather than research, which is also the limit of what it claims.

Oritse J. Uku built Citigroup’s first cloud incident-response program and authored the bank’s third-party incident-response playbook and its major incident-response runbook, working across fusion-center teams in New York, Budapest, and Singapore. He later served as board-appointed CISO of two Northwestern Mutual subsidiaries: a federally chartered savings association, and a registered broker-dealer, reporting to a subsidiary board in each. The six parts above are the portions of that work that transferred between institutions without being rebuilt.

Why Resilience Is The New Compliance An early statement of the argument. Forbes Technology Council, 16 January 2026.

Operational Resilience Is Becoming the Global Regulatory Baseline The regulatory frame the discipline is built against. Essay, January 2026.

Evidence of Resilience How continuity is demonstrated to a board rather than asserted. Essay, December 2025.

The full background Where these arguments came from, and what they are built on.

Limits

What the discipline does not do.

Stated here because a practice that claims no limits is asking to be taken on faith.

It does not prevent disruption.

An institution running the discipline well will still have incidents. What changes is whether the service stays inside its tolerance and whether anyone can show that it did.

It does not produce a certification.

There is no conformity scheme behind it, no assessor to appoint, and no badge at the end. It is a practice, and the only evidence of it is the evidence it generates.

It does not replace DORA, CPS 230, or an existing control framework.

It organizes them into one operating rhythm so their outputs become comparable, which is a smaller claim than a new standard and a more useful one.

It does not work without a stated tolerance.

An institution unwilling to name what it is prepared to survive cannot run the discipline, and should not claim to.

Briefings

Discussing this with a board.

I work with boards and executive teams on resilience architecture, supervisory expectations, and the operating-model implications of the discipline. Inquiries go to media@oritseuku.com.

Media and speaking →

Colophon

Resilience Operating Discipline, version 1. First published in 2025 under the title Resilience Is the New Compliance. The framework was renamed in May 2026. The substantive position is unchanged, and the discipline frame names what the work always was: a practice an institution maintains, audits, and improves.

Regulatory instruments and dates in force were checked on 30 August 2026. This page is reviewed twice a year. Last reviewed 30 August 2026.