From process to service
The observation that triggered everything
Between 2015 and 2020, several major banking outages followed the same pattern: every department had its continuity plan, every plan was current, every plan had been tested — and the client was left without account access for days.
The reason is structural. A continuity plan is written by a department, for its own perimeter. The service delivered to the client crosses six departments, four applications and three suppliers. Nobody was accountable for the whole chain.
The reframing
Regulators changed the unit of analysis. The question is no longer "what are your critical processes?" but "what services do you deliver, and at what point does their disruption become intolerable for your clients?"
The difference is considerable in practice:
| Process approach | Service approach |
|---|---|
| "Payment processing" | "A client can make a payment" |
| Scope: one division | Scope: the whole chain, third parties included |
| Objective: resource RTO | Objective: service impact tolerance |
| Owner: the department head | Owner: a designated service owner |
| Test: the resource restarts | Test: the client is served despite the outage |
The fourth change is the most important
In the service approach you must designate an owner for each important service — a person accountable for the end-to-end chain, including links they do not control hierarchically.
That point is what makes the exercise hard, and also what makes it effective. A service owner facing a dependency they do not control escalates it; a department head optimises their own perimeter.
What it does not replace
Operational resilience does not repeal business continuity: it sits above it. The BIA, strategies, plans and exercises remain necessary — they become the means of holding a tolerance, instead of being an end in themselves.
An organisation can be perfectly ISO 22301 conformant and still fail an operational resilience review, simply because it has never looked at its services end to end.
Key takeaways
- A service is defined from the client's viewpoint, not the org chart
- You start from harm suffered, not from the resource lost
- A service cuts across divisions: that is the point