Skip to content

Resilience Assessments

Where to find it: Operational Resilience, then BCM & Resilience (/bcm), then Resilience.

A Resilience Assessment (RES-YYYY-NNNN) evaluates a business service's overall resilience posture across six transparent dimensions.


The six dimensions

#DimensionQuestion
1Criticality and impact toleranceHow important is this service, and what disruption can be tolerated?
2BIA currency and approvalIs there an active, approved BIA within its review validity window?
3Plan coverage and currencyAre there approved, current continuity and DR plans with real procedures and contacts?
4Tested recovery capabilityWhat did the most recent exercise achieve, and did it meet the objectives?
5Scope dependency healthDo the assets, systems, vendors and organisational units the service depends on carry unmitigated single points of failure?
6Open findings and overdue remediationWhat deficiencies are outstanding, and what is overdue?

Each dimension is assessed and reported separately. The overall posture is derived from them — and never by averaging.


The critical-failure override

A critical failure in any dimension pulls the overall posture to Vulnerable

A breached RTO, or a compromised single point of failure with no mitigation, deterministically drives the overall posture to Vulnerable — overriding positive scores in every other dimension, with no numerical dilution.

This is the same principle as mandatory indicator gating in continuous assurance, applied to resilience. Five strong dimensions and one critical failure is not "83% resilient". A service that cannot recover within its tolerance is not resilient, whatever else is in good order.


Dependency health and single points of failure

Dependencies are resolved through the Scope Registry: the assets, systems, third-party engagements and organisational units the service relies on.

The assessment looks for unmitigated single points of failure — a dependency whose loss would prevent recovery, with no alternative path.

This is where third-party concentration becomes visible. When four important business services all depend on the same engagement, the dependency links say so, and the loss of that provider is a single point of failure across four services rather than one.


Not tested and not assessed

Where a service has not been exercised or assessed, its status reports not tested or not assessed. It is never assumed resilient.

ReadingMeaningWhat to do
Not assessedNo resilience assessment existsAssess it
Not testedNo completed exerciseExercise it
VulnerableA critical failure in at least one dimensionRemediate and retest

The first two are information gaps; the third is a known problem. Presenting them as the same colour would be a mistake.


What an assessment records

FieldPurpose
Business referenceRES-YYYY-NNNN
Business serviceThe subject
Criticality tierFrom the BIA and service classification
Tested capability statusThe state of dimension 4
RTO and RPO conformanceWhether the last exercise met the objectives
Dependency healthThe state of dimension 5
Open finding countThe state of dimension 6
Overall resilience statusThe derived posture
Owner and statusGovernance

Approval

Assess resilience profile, then resilience review and sign-off, then approved or rejected.

Segregation of duties: the assessor cannot sign off their own assessment. Requires bcm.resilience_assess to assess and the sign-off role to approve.


Permissions

ActionPermission
View resilience statusbcm.read
Assess service resilience, impact tolerances, dependency vulnerabilities and gap posturebcm.resilience_assess
Generate advisory AI gap analysesbcm.ai_assist

Requires the bcm_resilience entitlement.


Example

Assessment RES-2026-0005 — Retail Payments Service, Q2.

#DimensionAssessment
1Criticality and impact toleranceStrong. Important business service; impact tolerance defined at 4 hours, board approved
2BIA currency and approvalStrong. BIA-2026-0003 approved, within review window
3Plan coverage and currencyAdequate. BCP-2026-0004 v2.1 approved and current; contact details found stale during exercise
4Tested recovery capabilityCritical failure. EXE-2026-0009 breached RTO at 312 minutes against a 240-minute target
5Scope dependency healthAttention. ENG-2026-0041 core hosting is a single point of failure shared with two other important services; mitigation is contractual, not architectural
6Open findings and overdue remediationAdequate. 2 open findings from the exercise; neither overdue

Overall posture: Vulnerable.

Four of six dimensions are strong or adequate. The overall posture is Vulnerable because dimension 4 is a critical failure. No averaging is applied.

Q3 reassessment, after the successful retest:

#DimensionAssessment
4Tested recovery capabilityStrong. EXE-2026-0014 achieved 198 minutes against a 240-minute target
5Scope dependency healthAttention. Unchanged

Overall posture: Adequate with attention — the dependency concentration remains, and is now the leading concern rather than being hidden behind the recovery failure.

The override does not hide the other dimensions

The Q2 assessment reported all six dimensions with their reasoning. The override determined the headline, not the content. A reader could see immediately that the problem was recovery capability, not planning or governance.


Troubleshooting

"Overall posture is Vulnerable but most dimensions are fine." A critical failure in one dimension overrides. Read the dimension detail to find it.

"A service shows not tested despite a scheduled exercise." Scheduled is not completed.

"Dependency health flags a vendor we consider low risk." Dependency health assesses recoverability, not vendor risk. A low-risk vendor can still be a single point of failure.

"I cannot sign off my own assessment." Segregation of duties.


OrviQ Enterprise Governance, Risk & Compliance Platform