Operational resilience, in the PRA’s rules, is a firm’s ability to remain within its impact tolerance for each important business service through a severe but plausible disruption.
A firm must identify its important business services, the services which, if disrupted, could threaten its safety and soundness or, for systemically important firms, UK financial stability. It must set an impact tolerance for each, the maximum tolerable disruption measured as a length of time, and be able to stay within it. The board approves both and reviews the self-assessment. The head of operational resilience runs that cycle: the map behind each service, the scenario testing, the self-assessment and the board paper.
Who they report to is the first thing we settle in a brief. The PRA expects the Chief Operations function, SMF24, to hold overall responsibility for implementing operational resilience policies and reporting to the board, shared by no more than three people where it is shared at all. So the head either owns the programme in the first line for the chief operating officer, or challenges it from the second line for the chief risk officer, whose function the Risk Control Part requires to be independent from the operational functions. Either works; a firm that has not chosen does not, and candidates at this level ask which it is before they ask about money.
Sources: PRA Rulebook, Operational Resilience Part, chapters 1, 2 and 7, Senior Management Functions Part, rule 3.8, and Risk Control Part, rule 3.4; PRA SS1/21, March 2022, paragraphs 3.1 and 7.4.