
If you run continuity at a financial firm, three sets of supervisors are now asking you the same question in different accents. Which services can you not afford to lose? How long could you stand to lose them? Can you show, with evidence, that you would get them back inside that window?
Brussels asks through a regulation centered on technology. London asks through rules built around services and tolerances. Washington asks mostly through guidance and the examination handbook. The vocabulary differs enough to cause real confusion in firms that operate in more than one of these places, and the overlap is large enough that running three separate programs would be a waste. What follows is a plain map of each regime and what it means for a mid-size firm's continuity program.
The EU: DORA
The Digital Operational Resilience Act, Regulation (EU) 2022/2554, has applied since 17 January 2025. Because it is a regulation rather than a directive, it applies directly across the EU without national transposition, filled out by detailed technical standards from the European supervisory authorities. The scope is wide: banks, investment firms, insurers, payment and e-money institutions, crypto-asset service providers, trading venues, central counterparties and others, about twenty categories of financial entity in all. EIOPA's overview of DORA is a reasonable starting point.
DORA is about ICT risk, not all operational risk. That sounds narrower than it is, since almost every critical process at a financial firm now runs on technology. Its requirements fall into five areas:
- ICT risk management. A documented framework for which the management body carries ultimate responsibility. It includes an ICT business continuity policy, response and recovery plans, backup and restoration procedures, and recovery objectives.
- Incident management and reporting. Firms classify ICT incidents against set criteria and report major ones to their competent authority in stages (an initial notification, an intermediate report and a final report) on tight clocks.
- Digital operational resilience testing. A testing program covering the ICT systems that support critical or important functions, plus threat-led penetration testing at least every three years for the firms supervisors select.
- ICT third-party risk. Mandatory contract clauses, exit strategies, and a structured, standardized record of every ICT third-party arrangement that supervisors can collect.
- Information sharing. Voluntary arrangements to exchange cyber threat intelligence among financial entities.
Alongside these, DORA creates direct EU oversight of ICT providers designated as critical to the financial sector, which in practice means the large cloud and technology vendors.
For continuity managers, the change is that the business continuity plan is no longer a document the examiner skims. Under DORA it is one component of an ICT risk framework that has to be tested, reported on and tied to how incidents are classified.
The UK: important business services and impact tolerances
The PRA and FCA published their operational resilience policies in March 2021, and the Bank of England applied parallel requirements to financial market infrastructures. The rules took effect on 31 March 2022, by which point firms had to have identified their important business services, set impact tolerances, and started mapping and testing. By 31 March 2025, firms had to be able to remain within those tolerances in severe but plausible scenarios.
The method has four moving parts:
- Important business services. Services provided to external end users or market participants whose disruption could cause intolerable harm to consumers or market integrity (the FCA's lens) or threaten a firm's safety and soundness or financial stability (the PRA's lens). "Make a payment" qualifies. "Run the general ledger" usually does not, because it is internal, although it may support a service that does.
- Impact tolerances. The maximum tolerable level of disruption to each important business service, expressed with at least one time-based metric. The board sets it, and it is a statement about harm, not about systems.
- Mapping. Documenting the people, processes, technology, facilities and information that deliver each service, in enough detail to find vulnerabilities.
- Scenario testing. Checking whether the firm can stay within tolerance under severe but plausible scenarios, and recording what it will do about any it cannot meet.
All of this comes together in a self-assessment document that the board approves and supervisors can request. Third parties are covered by separate PRA expectations on outsourcing and third-party risk, and the Financial Services and Markets Act 2023 added a critical third parties regime under which HM Treasury can designate key providers for direct oversight by the regulators. The PRA and FCA also consulted in late 2024 on more prescriptive incident and third-party reporting.
The UK approach is the most explicit about starting from the customer and working backward. That is its main lesson for firms that will never have to comply with it.
The US: guidance, the handbook, and a few hard rules
The US has no single operational resilience rule. In October 2020 the Federal Reserve, the OCC and the FDIC issued an interagency paper, Sound Practices to Strengthen Operational Resilience. It is aimed at the largest banking organizations and states that it does not change existing rules or guidance. Instead, it organizes them around one goal: delivering critical operations and core business lines through a disruption, within the firm's tolerance for disruption. It groups sound practices into seven areas: governance, operational risk management, business continuity management, third-party risk management, scenario analysis, secure and resilient information systems, and surveillance and reporting.
For everyone else, the reference text is the FFIEC Business Continuity Management booklet, issued in November 2019 as part of the IT Examination Handbook. It replaced the older business continuity planning booklet and moved the emphasis from IT recovery plans to enterprise-wide continuity management: board and senior management oversight, business impact analysis, risk assessment, third-party dependencies, exercises and testing, and keeping the program current. Examiners use it at institutions of every size.
A few binding requirements sit around this guidance. Since 2022, banking organizations have had to notify their primary federal regulator within 36 hours of determining that a qualifying computer-security incident has occurred. The 2023 interagency guidance on third-party relationships sets out life-cycle expectations for vendor risk. Broker-dealers have FINRA Rule 4370, which requires a written business continuity plan reviewed annually, and certain market infrastructure falls under the SEC's Regulation SCI.
Side by side
| EU: DORA | UK: PRA/FCA regime | US: Sound Practices and FFIEC | |
|---|---|---|---|
| Legal form | Directly applicable regulation plus technical standards | Binding rules with supervisory statements | Supervisory guidance and exam handbook, plus a few separate rules |
| Key dates | Applies from 17 Jan 2025 | In force 31 Mar 2022; within tolerance by 31 Mar 2025 | FFIEC booklet Nov 2019; Sound Practices Oct 2020 |
| Who is in scope | About twenty types of EU financial entity; oversight of critical ICT providers | UK banks, building societies, insurers, larger investment firms, payment and e-money firms, exchanges | Sound Practices: largest banks. Booklet: all FFIEC-supervised institutions |
| Starting point | ICT systems supporting critical or important functions | Important business services to external users | Critical operations and core business lines |
| Tolerance idea | Recovery objectives; incident classification thresholds | Board-set impact tolerance with a time metric | Tolerance for disruption linked to risk appetite |
| Testing | Regular testing of key systems; threat-led penetration tests every three years for selected firms | Severe but plausible scenario testing against tolerances | Exercises and scenario analysis proportionate to risk |
| Third parties | Mandatory contract terms, exit plans, standardized contract records | Outsourcing expectations plus critical third parties regime | 2023 interagency third-party guidance |
| Incident reporting | Staged reporting of major ICT incidents | Existing notification duties; new rules proposed in 2024 | 36-hour notification rule for banking organizations |
| Board role | Management body ultimately responsible for ICT risk | Board approves services, tolerances and self-assessment | Board oversight and approval of risk appetite |
Where the differences actually matter
The unit of analysis. A traditional BIA works at the level of internal processes. The UK starts one level up, at the service a customer experiences. DORA starts at the critical or important function and the technology beneath it. The Sound Practices paper uses critical operations and core business lines, terms familiar to anyone who has worked on resolution planning. None of these replaces the BIA, but each needs a layer above it.
Tolerance is not an RTO. An RTO is an internal recovery target for a process or system. An impact tolerance is the point at which harm to customers or markets becomes intolerable, and it should be set without reference to what IT can currently deliver. If every tolerance happens to equal an existing RTO, a supervisor will reasonably suspect the firm worked backward.
Testing to the edge. Traditional continuity tests prove a plan works. The UK regime expects some scenarios severe enough that the firm may not stay within tolerance, because the point is to find the edge. DORA adds technical depth through threat-led testing. US examiners increasingly ask whether tests covered realistic, combined failures rather than a single site outage.
Third-party detail. DORA is far more prescriptive about contracts than the other two. Even firms with no EU presence are feeling it, because large vendors have rewritten their standard terms to meet it.
What this means for a mid-size firm
Picture a US bank or broker-dealer with assets in the tens of billions, a small UK subsidiary and perhaps an EU investment firm. Most of the work is the same whichever regime bites.
- Keep one program and present three views. One BIA, one dependency map, one scenario library, one third-party inventory. Produce the UK self-assessment, the DORA documentation and the US exam package as views of the same data. Firms that build three programs end up with three conflicting answers.
- Add a service layer above the BIA. Name the handful of services clients would notice losing, and map processes to them. A US-only firm benefits too, because it gives the board something comprehensible to set tolerances against.
- Have the board set tolerances in business terms. "Client payments delayed no more than one business day" is a tolerance. "Payment hub RTO of four hours" is an engineering target that should follow from it.
- Build a scenario library that goes past site loss. Loss of a major cloud region, a faulty software update pushed to every endpoint (the CrowdStrike outage of 19 July 2024 is the obvious reference), ransomware at a core processor, and a regional power failure on the scale of the 2003 Northeast blackout.
- Write an incident classification matrix with the clocks on it. DORA's staged reports, the US 36-hour rule and UK notification duties have different triggers. The incident commander should not be working them out at 2 a.m.
- Check the skills. Operational resilience sits between continuity, technology risk and vendor management. Traditional credentials cover part of it, and our comparison of business continuity certifications shows where the gaps are. It is also becoming a distinct specialty on business continuity career paths, which changes how firms hire for it.
Whichever regime applies, the evidence matters as much as the capability. Our briefing on surviving a BCM audit or regulatory examination covers what examiners ask to see and how to have it ready.
A decision rule for the next twelve months
Ask five questions of your own program, in order, and stop at the first "no":
- Can we name, in one sentence each, the services our clients would notice losing within a day?
- Has the board approved a tolerance for each, stated in terms of harm and time?
- Can we trace each service to the people, systems, sites, data and vendors behind it?
- Have we tested at least one scenario per service that was severe enough to fail?
- Does each gap from those tests have an owner, a date and a budget line?
The first "no" is next quarter's project. A firm that can answer all five with evidence is in good shape under any of the three regimes. One that cannot will find the same weaknesses exposed, whichever supervisor asks first.



