Appearance
Resilience Assessments
Where to find it: Operational Resilience, then BCM & Resilience (/bcm), then Resilience.
A Resilience Assessment (RES-YYYY-NNNN) evaluates a business service's overall resilience posture across six transparent dimensions.
The six dimensions
| # | Dimension | Question |
|---|---|---|
| 1 | Criticality and impact tolerance | How important is this service, and what disruption can be tolerated? |
| 2 | BIA currency and approval | Is there an active, approved BIA within its review validity window? |
| 3 | Plan coverage and currency | Are there approved, current continuity and DR plans with real procedures and contacts? |
| 4 | Tested recovery capability | What did the most recent exercise achieve, and did it meet the objectives? |
| 5 | Scope dependency health | Do the assets, systems, vendors and organisational units the service depends on carry unmitigated single points of failure? |
| 6 | Open findings and overdue remediation | What deficiencies are outstanding, and what is overdue? |
Each dimension is assessed and reported separately. The overall posture is derived from them — and never by averaging.
The critical-failure override
A critical failure in any dimension pulls the overall posture to Vulnerable
A breached RTO, or a compromised single point of failure with no mitigation, deterministically drives the overall posture to Vulnerable — overriding positive scores in every other dimension, with no numerical dilution.
This is the same principle as mandatory indicator gating in continuous assurance, applied to resilience. Five strong dimensions and one critical failure is not "83% resilient". A service that cannot recover within its tolerance is not resilient, whatever else is in good order.
Dependency health and single points of failure
Dependencies are resolved through the Scope Registry: the assets, systems, third-party engagements and organisational units the service relies on.
The assessment looks for unmitigated single points of failure — a dependency whose loss would prevent recovery, with no alternative path.
This is where third-party concentration becomes visible. When four important business services all depend on the same engagement, the dependency links say so, and the loss of that provider is a single point of failure across four services rather than one.
Not tested and not assessed
Where a service has not been exercised or assessed, its status reports not tested or not assessed. It is never assumed resilient.
| Reading | Meaning | What to do |
|---|---|---|
| Not assessed | No resilience assessment exists | Assess it |
| Not tested | No completed exercise | Exercise it |
| Vulnerable | A critical failure in at least one dimension | Remediate and retest |
The first two are information gaps; the third is a known problem. Presenting them as the same colour would be a mistake.
What an assessment records
| Field | Purpose |
|---|---|
| Business reference | RES-YYYY-NNNN |
| Business service | The subject |
| Criticality tier | From the BIA and service classification |
| Tested capability status | The state of dimension 4 |
| RTO and RPO conformance | Whether the last exercise met the objectives |
| Dependency health | The state of dimension 5 |
| Open finding count | The state of dimension 6 |
| Overall resilience status | The derived posture |
| Owner and status | Governance |
Approval
Assess resilience profile, then resilience review and sign-off, then approved or rejected.
Segregation of duties: the assessor cannot sign off their own assessment. Requires bcm.resilience_assess to assess and the sign-off role to approve.
Permissions
| Action | Permission |
|---|---|
| View resilience status | bcm.read |
| Assess service resilience, impact tolerances, dependency vulnerabilities and gap posture | bcm.resilience_assess |
| Generate advisory AI gap analyses | bcm.ai_assist |
Requires the bcm_resilience entitlement.
Example
Assessment RES-2026-0005 — Retail Payments Service, Q2.
| # | Dimension | Assessment |
|---|---|---|
| 1 | Criticality and impact tolerance | Strong. Important business service; impact tolerance defined at 4 hours, board approved |
| 2 | BIA currency and approval | Strong. BIA-2026-0003 approved, within review window |
| 3 | Plan coverage and currency | Adequate. BCP-2026-0004 v2.1 approved and current; contact details found stale during exercise |
| 4 | Tested recovery capability | Critical failure. EXE-2026-0009 breached RTO at 312 minutes against a 240-minute target |
| 5 | Scope dependency health | Attention. ENG-2026-0041 core hosting is a single point of failure shared with two other important services; mitigation is contractual, not architectural |
| 6 | Open findings and overdue remediation | Adequate. 2 open findings from the exercise; neither overdue |
Overall posture: Vulnerable.
Four of six dimensions are strong or adequate. The overall posture is Vulnerable because dimension 4 is a critical failure. No averaging is applied.
Q3 reassessment, after the successful retest:
| # | Dimension | Assessment |
|---|---|---|
| 4 | Tested recovery capability | Strong. EXE-2026-0014 achieved 198 minutes against a 240-minute target |
| 5 | Scope dependency health | Attention. Unchanged |
Overall posture: Adequate with attention — the dependency concentration remains, and is now the leading concern rather than being hidden behind the recovery failure.
The override does not hide the other dimensions
The Q2 assessment reported all six dimensions with their reasoning. The override determined the headline, not the content. A reader could see immediately that the problem was recovery capability, not planning or governance.
Troubleshooting
"Overall posture is Vulnerable but most dimensions are fine." A critical failure in one dimension overrides. Read the dimension detail to find it.
"A service shows not tested despite a scheduled exercise." Scheduled is not completed.
"Dependency health flags a vendor we consider low risk." Dependency health assesses recoverability, not vendor risk. A low-risk vendor can still be a single point of failure.
"I cannot sign off my own assessment." Segregation of duties.