US interagency examination guidance for resilience, continuity, disaster recovery, testing and third-party dependencies.
TL;DR:
- US interagency examination guidance for resilience, continuity, disaster recovery, testing and third-party dependencies.
- Apply enterprise-wide resilience governance, impact analysis, recovery strategies, testing and continuous improvement.
- Document tests, incidents, remediation and board oversight for examination.
Summary
US interagency examination guidance for resilience, continuity, disaster recovery, testing and third-party dependencies. Its scope covers critical financial and payment operations.
The main requirements are to apply enterprise-wide resilience governance, impact analysis, recovery strategies, testing and continuous improvement.
Operational resilience focuses on the continued delivery of important services through disruption. Technology availability is one input, alongside people, processes, data, facilities and third parties. Mapping those dependencies exposes situations in which an apparently healthy component still cannot deliver the end-to-end service that customers or other institutions rely on.
Risk management seeks to prevent failures; continuity and recovery planning deal with failures that still occur. Scenario testing examines whether those arrangements work under severe but plausible conditions, including the loss of an important supplier or a shared dependency. Recovery objectives, communication and decision-making responsibilities need to be connected to the affected service rather than considered only as technical system settings.
For payment activity, disruption can affect initiation, authentication, processing, settlement support and access to funds in different ways. Evidence from incidents and tests helps identify weaknesses and track remediation. The instrument's scope determines which institutions or infrastructures are covered and how its governance, reporting and assurance expectations interact with other financial-sector rules.
The instrument also addresses reporting and evidence: document tests, incidents, remediation and board oversight for examination.
Keywords
- FFIEC Business Continuity Management
- FFIEC BCM
- FFIEC IT Examination Handbook — Business Continuity Management
- FFIEC Business Continuity Management summary
- FFIEC Business Continuity Management requirements
- FFIEC Business Continuity Management compliance
- United States payment regulation
- United States financial regulation
- Federal Financial Institutions Examination Council regulation
- operational resilience