69 terms in plain language with links to the guides that unpack them. Definitions written to be used, not recited.
Who is accountable for what, and to whom.
Accountability
The obligation to answer for an outcome. Accountability sits with one person and cannot be delegated, unlike the work itself.
Responsibility
The duty to carry out the work. Responsibility can be delegated and shared; accountability for the result cannot.
The Board
The governing body that carries ultimate accountability for the organisation, including its resilience. The board sets appetite, oversees management and answers to shareholders and regulators. See BCM for the board.
Audit Committee
The board committee that oversees financial reporting, internal control and audit. Resilience assurance reports often land here.
CEO · Chief Executive Officer
The most senior executive, accountable to the board for running the organisation, including the resilience capability that protects it.
CRO · Chief Risk Officer
The executive who leads the risk function: frameworks, appetite proposals, reporting and challenge. In many groups the CRO also carries operational resilience.
Management
The executives who run the organisation day to day and implement the direction the board sets. The contrast between oversight and management is the foundation of governance.
Internal Audit
The independent function that assures the board that risk management and controls actually work. The third line of the three lines model.
The Three Lines
The IIA model that separates roles: management owns and manages risk, the risk and compliance functions support and challenge, and internal audit gives independent assurance. See three lines of defence.
Oversight
The board's work of directing, questioning and verifying what management does, without doing it. Distinct from supervision, which is what a regulator does.
Corporate Governance
The system of rules and relationships by which a company is directed and controlled: the board, shareholders, management and their accountabilities.
Corporate Governance Code
A published set of governance principles that listed companies apply or explain against. Many codes now expect the board to oversee resilience explicitly.
Resilience Governance
The board-level direction and oversight of resilience: appetite, accountability, reporting and assurance. Governance means oversight by the board, not day-to-day management.
Risk Owner
The named manager accountable for a specific risk and for the controls that treat it. Every risk on the register needs one owner, not a committee.
The core of the method: what we protect and how fast it comes back.
Business Continuity
The capability of an organisation to keep delivering its products and services at acceptable levels through a disruption. It is the outcome that plans, teams and exercises exist to protect. See business continuity.
Business Continuity Management (BCM)
The management discipline that identifies threats to critical activities and builds the capability to keep them running. It covers analysis, planning, exercising and continual improvement.
Business Continuity Management System (BCMS)
The formal system of policies, roles, processes and records through which an organisation runs business continuity, as defined by ISO 22301. Certification against the standard assesses this system.
BCP · Business Continuity Plan
The documented procedures that guide the organisation through a disruption: who acts, in what order, with what resources, toward which targets. See the continuity plan.
DRP · Disaster Recovery Plan
The technical plan for restoring IT systems and data after a disruption, built to meet the RTO and RPO of the services they support. See the recovery plan.
Business Impact Analysis (BIA)
The analysis that identifies critical processes, measures the impact of their interruption over time, and produces recovery targets such as MAO, RTO and RPO. See business impact analysis.
Critical Process
A process whose interruption quickly threatens the organisation's objectives, obligations or revenue. Critical processes get recovery targets and priority in continuity plans. See the process register.
Recovery Time Objective (RTO)
The target time for restoring a process or service after a disruption. The RTO must be shorter than the MAO, with margin.
Recovery Point Objective (RPO)
The maximum acceptable data loss measured in time: how far back the last usable copy may be. The RPO drives backup frequency.
Maximum Acceptable Outage (MAO)
The longest period a process can be interrupted before the harm becomes unacceptable. Recovery targets must fit inside the MAO.
Maximum Tolerable Period of Disruption (MTPD)
The ISO 22301 term for the time after which the impact of a disruption becomes unacceptable. In practice it names the same limit as MAO.
Minimum Business Continuity Objective (MBCO)
The minimum level of products or services the organisation commits to deliver during a disruption, agreed in advance.
Recovery
The return of processes and services to agreed levels after a disruption, through the recovery targets and in the order the BIA established.
Downtime
The period during which a service or process is unavailable. Downtime describes time only; the harm it causes is measured separately.
Cost of One Day of Downtime
The calculated loss the organisation suffers for each day a process stands still. The number that turns continuity from a policy debate into an investment case. See the cost of downtime.
Disruption
Any event that interrupts the normal delivery of products, services or operations, whatever its cause. The single term the profession uses for outages, incidents and interruptions of every kind.
Resilience
The ability of an organisation to absorb shocks, adapt and keep pursuing its objectives in a changing environment. It is broader than continuity: it covers strategy, culture and governance as well as plans.
The client's view of the service and the limits of disruption.
Operational Resilience
The ability to keep important business services within impact tolerances through disruption. The concept anchors the regimes of the Bank of England, the FCA and CBUAE. See operational resilience.
Important Business Service
A service whose failure could cause intolerable harm to customers or threaten market stability. The unit of analysis in the operational resilience regimes of the FCA and CBUAE.
Impact Tolerance
The maximum acceptable level of disruption to an important business service, set as a clear limit in time or another measure. A term from the Bank of England SS1/21 and the FCA rules.
Intolerable Harm
The level of harm to customers or the market that the firm must never cause, however severe the disruption. The FCA and CBUAE regimes are anchored on it.
How risk is described, measured and owned.
Risk Management
The coordinated activities that direct an organisation with regard to risk: identify, assess, treat, monitor. ISO 31000 is the reference framework. See the risk management system.
Enterprise Risk Management (ERM)
Risk management applied across the whole enterprise under one framework, one appetite and one reporting line to the board, rather than in silos.
Risk Assessment
The process of identifying risks, analysing their likelihood and impact, and evaluating them against appetite to decide treatment. See the risk matrix.
Risk Register
The living record of identified risks with their owners, assessments, controls and treatment actions. A management tool, not a filing exercise.
Risk Appetite
The amount and type of risk the board is willing to take in pursuit of objectives. Appetite is set at the top and cascades into limits and thresholds, with tolerance as its counterpart. See risk appetite.
Appetite Cascade
The translation of board appetite into concrete limits, tolerances and targets at every level below, so that daily decisions stay inside the board's intent.
Residual Risk
The risk that remains after controls are applied. Residual risk is what the board actually accepts, so it must be compared with appetite.
Risk Concentration
Dependence of many activities on one supplier, site, system or person, so that a single failure hits several services at once. See single points of failure.
Key Risk Indicator (KRI)
A measurable early signal that a risk is rising toward its threshold. Good KRIs trigger action before the loss, not after it. See KRI vs KPI.
Indicator
A measured value that shows the state of a risk, a process or a capability. Indicators feed dashboards and board reports.
Threshold
The agreed value at which a signal changes status and triggers escalation or action. Thresholds turn appetite into daily practice.
Assumption
A condition taken as true when a plan or an analysis is built. Assumptions must be written down and tested, because a failed assumption breaks the plan silently.
Scenario
A structured description of a plausible disruption used to test plans, tolerances and decisions. Regulators expect severe but plausible scenarios.
What happens in the acute phase and how you prepare for it.
Crisis Management
The organised response to events that threaten the organisation's operations, reputation or existence: structures, decisions and communication under pressure.
Crisis Team
The named group of executives that assembles when a crisis is declared, with the authority to decide, spend and communicate. See the crisis plan.
Crisis Communication
The planned communication with staff, customers, regulators and media during a disruption. Prepared messages and named spokespeople protect trust when time is short. See crisis communications.
Escalation
The pre-agreed path by which an incident moves to higher authority when it crosses a threshold. Clear escalation replaces hesitation with procedure.
Exercise
A planned rehearsal of plans, teams and decisions against a scenario. Exercises validate capability; an unexercised plan is a hypothesis. See exercises.
Tabletop Exercise
A discussion-based exercise in which the team walks through a scenario at the table, testing decisions and roles without touching live operations. See cyber exercises.
Lessons Learned
The structured findings after an exercise or a real disruption, turned into owned actions with deadlines. The loop that makes the capability improve.
Dependencies the company does not control directly.
Supplier
An external party that provides goods or services the organisation depends on. Critical suppliers are assessed, contracted and exercised for continuity. See losing a supplier.
Supply Chain
The network of suppliers, logistics and services the organisation depends on to deliver. Continuity extends to this chain, not just to the organisation's own walls.
Requirements, evidence and maturity.
Regulator
The public authority that sets binding requirements for a sector and holds firms to them, such as CBUAE, the FCA or NCEMA.
Supervisor
The authority that monitors regulated firms day to day: reviews, inspections, findings. The word describes the regulator's watch, never the board's.
Regulatory Requirement
A binding obligation issued by a regulator. Requirements define the minimum; appetite and strategy decide how far beyond it the firm goes. See regulatory continuity requirements.
Mandatory Regime
A set of rules firms must follow by law or licence, with sanctions for failure. NCEMA 7000 is mandatory for UAE government entities and critical infrastructure.
Voluntary Standard
A standard an organisation adopts by choice, such as ISO 22301, often to prove capability to clients and partners through certification. See ISO 22301.
Compliance
Conformity with the requirements that apply to the organisation, demonstrated with evidence. Compliance proves the minimum; resilience is the goal beyond it.
Certification
Independent confirmation that a management system conforms to a standard, issued after audit by an accredited body.
Certificate
The document that records a person has completed a programme and passed its assessment. In ERGP it carries a unique number and public verification.
Assurance
Independent confirmation to the board that resilience actually works: evidence, testing and audit rather than management's own word.
Reporting
The regular flow of structured information to management, the board and regulators: indicators, incidents, exercises and progress against appetite.
Maturity
The degree to which a capability is established, repeatable and improving, measured against a defined model rather than by impression.
Maturity Level
A defined step on a maturity scale, from initial to optimised. Levels let the board set a target and track movement toward it. See measuring resilience.
Nothing found. Try another word or see the full list.
13 вопросов, 5 минут, бесплатно — результат сразу на экране и на почту.