Reference
The Resilience Operating Discipline
A standing practice for keeping a critical service inside its stated tolerance, and for holding the evidence that it did.
Under stress, an institution runs the practice it already had.
Supervisors in six jurisdictions now ask institutions to demonstrate that a critical service holds inside a stated tolerance while it is failing. That proof comes from a practice the institution was already running: named owners, declared tolerances, mapped dependencies, tested recovery, and evidence produced on a schedule. The Resilience Operating Discipline sets out that practice, and the conditions under which an institution can honestly claim to have it.
What the expectation actually says
| Jurisdiction | Instrument | What it requires |
|---|---|---|
| European Union | DORA, Regulation (EU) 2022/2554, applying January 2025 | ICT risk management and testing, including threat-led penetration testing for designated entities. |
| United Kingdom | PRA and FCA operational resilience policy, PS21/3, full compliance March 2025 | Important business services identified, impact tolerances set, and staying within them tested. |
| Australia | APRA CPS 230, effective July 2025 | Tolerance levels for critical operations, on disruption period, minimum service, and data loss. |
| Canada | OSFI Guideline E-21, published August 2024, full adherence expected 1 September 2026 | Operational risk management and resilience, including business continuity and crisis management. Guideline B-13 covers technology and cyber risk. |
| Singapore | MAS technology risk and business continuity requirements | Recovery and service-availability expectations for regulated financial institutions. |
| United States | Regulation S-K Item 106, adopted July 2023 | Disclosure of cybersecurity risk-management processes and board oversight. Presently disclosure-led rather than tolerance-led. |
The instruments differ, and the term of art differs with them. Impact tolerance is a United Kingdom construct. CPS 230 sets tolerance levels on separate axes. DORA does not use the term at all. What the six share is the shift from describing a control to demonstrating an outcome.
The distinction the discipline rests on
Compliance asks whether a control was designed and operating on the day it was examined. Resilience asks whether the service stayed inside its tolerance on the day it broke.
The second question is answerable only with evidence that existed before anyone asked for it. That is the whole of the difference, and it is the reason the discipline is a practice an institution maintains rather than a document it produces.
The practice
Six operations, and the order they run in.
The order matters. Every operation after the second depends on a tolerance having been set, and setting one is where implementations stall. None of them is finished once. Each has a cadence, and each produces something an outsider can be shown.
Fix who decides
Named owners, decision rights, and a reporting line that reaches the board. Resilience fails at the seam between functions, so the discipline begins by settling who decides what before an incident rather than during one.
In practice that means one accountable executive per critical service, and a standing board agenda item. The common failure is a committee with shared executive accountability and no individual answer to the question of who calls it.
Produces a named owner for each critical service, and a standing item on the board agenda.
Set the tolerance
A stated maximum, set before anything breaks: how long a service may be unavailable, how degraded it may run, how much data may be lost.
This is the hardest part of the discipline and the part that creates most of its value, because it forces an institution to say in advance what it is prepared to survive. Almost every implementation that stalls, stalls here. A tolerance that no business owner will sign is a sign the service was never really understood, and the honest response is to go back to mapping.
Produces a stated maximum for each critical service, signed by the business owner who carries it and revisited on material change.
Map the dependencies
Which services are critical, what they depend on, and where those dependencies concentrate. Mapping records complexity. It does not remove it, and the output is a register that keeps changing rather than a diagram that hangs on a wall.
Produces a dependency register that changes when the estate changes.
Run it to the breaking point
Severe but plausible scenarios run against the mapped dependencies, far enough to find the breaking point. A test that everything passes has told the institution nothing it did not already believe.
Produces test results, including the ones that failed, with the breaking point named.
Demonstrate the recovery
The demonstrated ability to restore a critical service inside its tolerance. A recovery plan and a recovery capability are different objects, and only one of them is evidence.
Produces a recovery performed inside tolerance, and the time it actually took.
Produce the evidence
Test results, tolerance breaches, dependency changes, and recovery times, produced on a schedule and retained. Supervision is increasingly evidence-led, and evidence assembled after a request arrives is worth less than evidence that was already on the shelf.
Produces a retained record a supervisor can be shown without preparation.
The discipline moves where the curve turns, and it produces the record of the turn.
Provenance
Where the discipline came from.
It was written out of operating practice rather than research, which is also the limit of what it claims.
Oritse J. Uku built Citigroup’s first cloud incident-response program and authored the bank’s third-party incident-response playbook and its major incident-response runbook, working across fusion-center teams in New York, Budapest, and Singapore. He later served as board-appointed CISO of two Northwestern Mutual subsidiaries: a federally chartered savings association, and a registered broker-dealer, reporting to a subsidiary board in each. The six parts above are the portions of that work that transferred between institutions without being rebuilt.
Why Resilience Is The New Compliance An early statement of the argument. Forbes Technology Council, 16 January 2026.
Operational Resilience Is Becoming the Global Regulatory Baseline The regulatory frame the discipline is built against. Essay, January 2026.
Evidence of Resilience How continuity is demonstrated to a board rather than asserted. Essay, December 2025.
The full background Where these arguments came from, and what they are built on.
Limits
What the discipline does not do.
Stated here because a practice that claims no limits is asking to be taken on faith.
An institution running the discipline well will still have incidents. What changes is whether the service stays inside its tolerance and whether anyone can show that it did.
There is no conformity scheme behind it, no assessor to appoint, and no badge at the end. It is a practice, and the only evidence of it is the evidence it generates.
It organizes them into one operating rhythm so their outputs become comparable, which is a smaller claim than a new standard and a more useful one.
An institution unwilling to name what it is prepared to survive cannot run the discipline, and should not claim to.
Briefings
Discussing this with a board.
I work with boards and executive teams on resilience architecture, supervisory expectations, and the operating-model implications of the discipline. Inquiries go to media@oritseuku.com.
Media and speaking →Colophon
Resilience Operating Discipline, version 1. First published in 2025 under the title Resilience Is the New Compliance. The framework was renamed in May 2026. The substantive position is unchanged, and the discipline frame names what the work always was: a practice an institution maintains, audits, and improves.
Regulatory instruments and dates in force were checked on 30 August 2026. This page is reviewed twice a year. Last reviewed 30 August 2026.