SlideShare a Scribd company logo
MEASURING OPERATIONAL
RESILIENCE
50,000
GLOBALLY
CERTIFICATES 90
TRANSPARENT
INTRODUCTION
Any threat to operational resilience is also a risk to
business viability and continuity. The role in which
governance and managerial entities play in controlling
operational risk is directly linked to financial performance
and reduction of losses through ensuring continuity of
business services.
Operational resilience is the ability to alter operations in
the face of changing business conditions. It is the ability
to quickly ramp up or slow down with quick and local
process modification.
An operationally resilient organisation is operating within
the Plan Do Check Act cycle. It is continuously:
• 
Finding and assessing its vulnerabilities and its supply
chain vulnerabilities
• 
Reducing the likelihood of disruption with planning,
controls, flexibility and redundancies
• 
Detecting disruption in itself and supply chains
• 
Measuring its operational resilience
METHOD
There are various methods for measuring operational
resilience, some of which are complex, protracted and
involve various disciplines. Yet often the best way is the
simplest way. This method is one of those, and the only
requirement is that you know what you know and what
you don’t know about your organisation.
The method is explained using an example which is
entirely customizable – you can change all the weighting
values, scores, numbers and structures of the objectives
and tasks. The important thing to note is that whatever
you do, make sure it’s repeatable so you can carry out
before and after measurements as part of your internal
governance processes.
It is often best achieved by a group of people from within
the organisation.
BENEFITS
• 
Demonstrates continuous improvement towards
objectives, and can help drive internal audit
planning
• 
Quick and requires no expertise, just knowledge
of the performance of your organisation and key
suppliers
• 
A powerful presentational tool for top
management
• Customizable
• 
Used to measure other business functions or
capabilities, such as security or procurement
STEP BY STEP
Overall
Objective
Objectives
Tasks
Activities
OPERATIONAL RESILIENCE
Overall
Objective
Objectives
Measuring your organisation’s operational resilience is the overall objective.
This comprises 3 main objectives (or whatever you choose):
• Perform a risk analysis of the organisation
• Implement controls
• Test and maintain the controls
STEP 1
1. Functionally decompose the objectives into tasks
2. Functionally decompose the tasks into activities
STEP 2
Understand
organisation
Vulnerability
assesment
Strategy
selection
Business
objectives
Internal
resources
Business
impact analysis
Understanding
strategies
Test
Strategic
External
resources
Risk
assesment
Strategy
selection
Maintenance
Operational
Business
continuity plans
Test and
maintenance
OPERATIONAL RESILIENCE
Risk analysis
Risk analysis Implementation
Test and
maintenance
Communication
Leadership
Generic risk
control
Implementation
of risk
treatment
BCM
embedded
Training Risk transfer
Cultural
aspects
Supplier
management
Prevention
Incident
reporting
Human
resource
Physical
resource
Implementation
Overall
Objective
Objectives
Tasks
1. Assign a weighting to each objective. The sum of the weightings must be 1.
2. Assign a weighting to each task. The sum of each objective group of tasks must be 1.
STEP 3
Overall
Objective
Objectives
Tasks
Activities
1. Assign a weighting to each activity, so that for each parent task, they add up to 1.
STEP 4
0.323
Risk analysis
0.588
Implementation
0.089
Test and
maintenance
0.250
Understand
organisation
0.425
Vulnerability
assesment
0.250
Strategy
selection
0.400
Leadership
0.400
Generic risk
control
0.200
Implementation
of risk treatment
0.075
Business
objectives
OPERATIONAL RESILIENCE
0.323
Risk analysis
0.588
Implementation
0.089
Test and
maintenance
0.250
Understand
organisation
0.425
Vulnerability
assesment
0.250
Strategy
selection
0.400
Leadership
0.400
Generic risk
control
0.200
Implementation
of risk
treatment
0.075
Business
objectives
0.500
Internal
resources
0.500
Business
impact analysis
0.118
Understanding
strategies
0.667
BCM
embedded
0.141
Training
0.066
Risk transfer
0.250
Test
0.167
Strategic
0.500
External
resources
0.500
Risk
assesment
0.268
Strategy
selection
0.333
Cultural
aspects
0.263
Supplier
management
0.249
Prevention
0.750
Maintenance
0.833
Operational
0.614
Business
continuity plans
0.141
Incident
reporting
0.312
Human
resource
0.455
Communication
0.373
Physical
resource
OPERATIONAL RESILIENCE
Assign a score from between 0 and 1 to each activity
(shown in brown).
This is a subjective assessment of how optimal the
task is, although if you have data to support your
assessment then all the better. The score reflects
your confidence in the task, and if you don’t know
then give it a low score.
This is deliberately subjective; it should be a quick
debate.
Some organisations define criteria for scoring e.g.
what good and bad is.
STEP 5 0.118 0.90
Understanding strategies
0.268 0.91
Strategy selection
0.614 1.00
Business continuity plans
Multiply the score by the weighting.
The product is shown in green.
STEP 6 0.105
Understanding strategies
0.244
Strategy selection
0.614
Business continuity plans
1. 
The sum of the products is the score for the parent
task (shown in pink).
2. 
Multiply the sum by the weighting to give the
weighted score (shown in blue).
STEP 7
0.105
Understanding strategies
0.244
Strategy selection
0.241
Strategy selection
0.250 0.963
0.614
Business continuity plans
*as taken from above
OPERATIONAL RESILIENCE
www.nqa.com
Overall
Objective
Objectives
Tasks
Activities
Risk analysis Implementation
Test and
maintenance
Understand
organisation
Vulnerability
assesment
Strategy
selection
Leadership
Generic risk
control
Implementation
of risk
treatment
Business
objectives
Test
Maintenance
1. 
For each objective group of tasks, add up the task’s weighted scores
(sum shown in pink).
2. 
Multiply the sum by the objective’s weighting (product shown in purple).
3. 
Add up the products to give the overall operational resilience assessment score
(shown in red).
STEP 8
0.842
0.004
0.089 0.053
0.518
0.588 0.882
0.320
0.323 0.991
0.250 0.00
0.075 0.250 0.425 0.241 0.400 0.395 0.087
0.750 0.07
ASSESSMENT SCORE
The example assessment score doesn’t say the organisation is 86% operationally resilient. It is measure by which
a higher score is almost certainly better than a lower score. But more importantly, it quickly identifies strengths,
weaknesses or a lack of knowledge in certain areas.
By applying criteria to the assessment it can be represented as a heat map for presentation purposes.
Objectives Risk Analysis Implementation Test and Maintenance
Tasks
Risk
Analysis
Understand
Organisation
Vulnerability
Assesment
Strategy
selection
Leadership
Generic risk
control
Implementation
of risk
treatment
Activities
Strategic Internal BIA Understand
BCM
Embedded
Training Transfer Test Maintenance
Operational External Risk Select BCM Culture Suppliers Prevent
Incidents
Human
resources
Comms
Physical
resources
BCP
NQA, Warwick House, Houghton Hall Park, Houghton Regis,
Dunstable, Bedfordshire LU5 5ZX, United Kingdom
T: 0800 052 2424 E: info@nqa.com @nqaglobal

More Related Content

PDF
NQA ISO 22301 Transition Gap Guide
PDF
NQA ISO 22301 Business Continuity Checklist
PDF
NQA ISO 9001 to ISO 27001 Gap Guide
PPTX
HSE Training Presentation for ISO 14001, ISO 45001 Integration
PDF
NQA ISO 13485 Gap Guide – what’s changed?
PPTX
Annex SL Training for ISO 9001:2015. & ISO 14001:2015.
PDF
NQA - 10 Steps to IMS Guide
PDF
Outline of ISO 22301:2019 Documentation and Training kit
NQA ISO 22301 Transition Gap Guide
NQA ISO 22301 Business Continuity Checklist
NQA ISO 9001 to ISO 27001 Gap Guide
HSE Training Presentation for ISO 14001, ISO 45001 Integration
NQA ISO 13485 Gap Guide – what’s changed?
Annex SL Training for ISO 9001:2015. & ISO 14001:2015.
NQA - 10 Steps to IMS Guide
Outline of ISO 22301:2019 Documentation and Training kit

What's hot (18)

PDF
Iso 22301 Checklist
PPTX
Internal auditor 9001 day 1
PDF
Integrated Management System Manual Template (Preview)
PPTX
Integrated management systems
PDF
Why Audit? What Is the Difference Between Regulatory Auditing and ISO 14001 o...
PPT
3d 3 Todays Internal Auditor
PDF
NQA - ISO 13485 Transition Checklist
PDF
Integrated Management Systems
PDF
ISO 9001, 14001, 45001 (IMS) basics training material
PDF
NQA ISO 45001 Gap Guide
PDF
NQA ISO 22000 Food Safety Transition Gap Guide
PDF
NQA - ISO 45001 Implementation Guide
PDF
NQA ISO 45001 Implementation Guide
PDF
18001 audit-checklist
PDF
ISO 900:2015
PDF
ISO/DIS 45001:2017 OH&S manual (preview)
PDF
Achieving Superior Energy Performance (SEP) - U.S. DOE
PDF
Iso 9001 transition checklist
Iso 22301 Checklist
Internal auditor 9001 day 1
Integrated Management System Manual Template (Preview)
Integrated management systems
Why Audit? What Is the Difference Between Regulatory Auditing and ISO 14001 o...
3d 3 Todays Internal Auditor
NQA - ISO 13485 Transition Checklist
Integrated Management Systems
ISO 9001, 14001, 45001 (IMS) basics training material
NQA ISO 45001 Gap Guide
NQA ISO 22000 Food Safety Transition Gap Guide
NQA - ISO 45001 Implementation Guide
NQA ISO 45001 Implementation Guide
18001 audit-checklist
ISO 900:2015
ISO/DIS 45001:2017 OH&S manual (preview)
Achieving Superior Energy Performance (SEP) - U.S. DOE
Iso 9001 transition checklist
Ad

Similar to NQA Measuring Operational Resilience Guide (20)

PDF
Operational Risk Management: Standard Requirements
PDF
Business Continuity Management - Operational & Cyber Resilience Part 1 (whi...
PPTX
360Resilience @ BESA Conference 2018
PPT
Operational risk & business continuity management
PDF
Operational resilience presentation 1 (1)
PPTX
Managing Risks in Uncertainty - Building your Organizational Resilience
PDF
Impower's resilience framework self scoring sheet
PPTX
Operational Resilience
PDF
Strengthening Operational Resilience in Financial Services by Migrating to Go...
PDF
Ensure Preparedness with Operational Resilience - Article
PDF
Org-Resilience-WP-Nov-2015
PDF
Bci NeBe conf 2017 keynote - making sense of resilience - james crask - sd
PDF
The State of Enterprise Resilience - Resilience Survey 2015
PPT
Assessing measuring oprisksama-khan011805
PPT
Assessing & measuring operational risk
PPTX
Improving BCM through Measurement and Benchmarking
PPTX
BUSINESS CONTINUITY PLANNING AND RISK MANAGEMENT
PPT
Six sigma
PDF
Bank of England Operational Resilience
PDF
Risk Management Best Practices for Enhancing Organisational Resilience
Operational Risk Management: Standard Requirements
Business Continuity Management - Operational & Cyber Resilience Part 1 (whi...
360Resilience @ BESA Conference 2018
Operational risk & business continuity management
Operational resilience presentation 1 (1)
Managing Risks in Uncertainty - Building your Organizational Resilience
Impower's resilience framework self scoring sheet
Operational Resilience
Strengthening Operational Resilience in Financial Services by Migrating to Go...
Ensure Preparedness with Operational Resilience - Article
Org-Resilience-WP-Nov-2015
Bci NeBe conf 2017 keynote - making sense of resilience - james crask - sd
The State of Enterprise Resilience - Resilience Survey 2015
Assessing measuring oprisksama-khan011805
Assessing & measuring operational risk
Improving BCM through Measurement and Benchmarking
BUSINESS CONTINUITY PLANNING AND RISK MANAGEMENT
Six sigma
Bank of England Operational Resilience
Risk Management Best Practices for Enhancing Organisational Resilience
Ad

More from NQA (20)

PDF
NQA ISO 27001 27017 27018 27701 Mapping
PDF
NQA ISO 13485 Introduction Guide
PDF
NQA Ten Tips for Planning and Preparing
PDF
NQA ISO 13485 Implementation Guide
PDF
NQA Your Risk Assurance Partner
PDF
NQA Your Complete Guide to ISO 27001
PDF
NQA ISO 50001 Implementation Guide
PDF
NQA ISO 27701 Implementation Guide
PDF
NQA ISO 27001 Implementation Guide
PDF
NQA ISO 22000 Implementation Guide
PDF
NQA ISO 14001 Implementation Guide
PDF
NQA ISO 9001 Implementation Guide
PDF
NQA Journey to Certification
PDF
NQA 10 Steps to IMS Guide
PPTX
Certification Body Approach to ISO 9001:2015 by NQA
PDF
Implementing ISO 50001 at the London School of Economics
PDF
ISO 45001 Current Status of Development from ISO
PPTX
NQA ISO 14001:2015 – Accredited Certification Transition Webinar Slides
PDF
Oxford Brookes Case Study - ISO 14001 (Environmental Management)
PDF
Nairns Case Study - ISO 14001 (Environmental Management)
NQA ISO 27001 27017 27018 27701 Mapping
NQA ISO 13485 Introduction Guide
NQA Ten Tips for Planning and Preparing
NQA ISO 13485 Implementation Guide
NQA Your Risk Assurance Partner
NQA Your Complete Guide to ISO 27001
NQA ISO 50001 Implementation Guide
NQA ISO 27701 Implementation Guide
NQA ISO 27001 Implementation Guide
NQA ISO 22000 Implementation Guide
NQA ISO 14001 Implementation Guide
NQA ISO 9001 Implementation Guide
NQA Journey to Certification
NQA 10 Steps to IMS Guide
Certification Body Approach to ISO 9001:2015 by NQA
Implementing ISO 50001 at the London School of Economics
ISO 45001 Current Status of Development from ISO
NQA ISO 14001:2015 – Accredited Certification Transition Webinar Slides
Oxford Brookes Case Study - ISO 14001 (Environmental Management)
Nairns Case Study - ISO 14001 (Environmental Management)

Recently uploaded (20)

PDF
NAV to Microsoft Dynamics 365 Business Central Upgrade in London UK (1).pdf
PDF
Why Should Call Centers Use Inbound Call Tracking in 2025.pdf
PDF
Sustainable Fire Safety How AMCs Contribute to a Greener Future.pdf
PPTX
Task 2_ portfolio PP-Food collection drive purpose
PPTX
Precision Mapping with Scan to BIM Services
PDF
Choosing the Right SIRA-Approved Access Control Systems for Your Dubai Busine...
PDF
The Rise of ICOs in Environmental and Sustainability Projects (2).pdf
PPTX
How After-School Art Classes Enhance Social Skills.pptx
PDF
Blush & Brown Modern Minimalist eBook Workbook.pdf
PDF
Defi Smart Contract Developmkent Infographics.pdf
PDF
Optimize Freight, Fleet, and Fulfillment with Scalable Logistics Solutions.pdf
PPTX
Why Outsourcing Debt Collection Saves Time and Money.pptx
PDF
The Impact of Lighting on Paint Colours.pdf
PDF
Management Colleges In Delhi Ncr | Galgotias University
PDF
Threat Intelligence Services in Abu Dhabi
PDF
Xinzex: A Complete Web Development Guide for Beginners
PDF
Top 7 Cybersecurity Companies in Abu Dhabi
PDF
Choosing an Entrepreneurial Path Based on Your Personality.pdf
PPTX
Expert Tree Pruning & Maintenance Services in Sydney
PDF
Why Infotrench Stands Out as the Best SEO Agency in Noida.pdf
NAV to Microsoft Dynamics 365 Business Central Upgrade in London UK (1).pdf
Why Should Call Centers Use Inbound Call Tracking in 2025.pdf
Sustainable Fire Safety How AMCs Contribute to a Greener Future.pdf
Task 2_ portfolio PP-Food collection drive purpose
Precision Mapping with Scan to BIM Services
Choosing the Right SIRA-Approved Access Control Systems for Your Dubai Busine...
The Rise of ICOs in Environmental and Sustainability Projects (2).pdf
How After-School Art Classes Enhance Social Skills.pptx
Blush & Brown Modern Minimalist eBook Workbook.pdf
Defi Smart Contract Developmkent Infographics.pdf
Optimize Freight, Fleet, and Fulfillment with Scalable Logistics Solutions.pdf
Why Outsourcing Debt Collection Saves Time and Money.pptx
The Impact of Lighting on Paint Colours.pdf
Management Colleges In Delhi Ncr | Galgotias University
Threat Intelligence Services in Abu Dhabi
Xinzex: A Complete Web Development Guide for Beginners
Top 7 Cybersecurity Companies in Abu Dhabi
Choosing an Entrepreneurial Path Based on Your Personality.pdf
Expert Tree Pruning & Maintenance Services in Sydney
Why Infotrench Stands Out as the Best SEO Agency in Noida.pdf

NQA Measuring Operational Resilience Guide

  • 2. INTRODUCTION Any threat to operational resilience is also a risk to business viability and continuity. The role in which governance and managerial entities play in controlling operational risk is directly linked to financial performance and reduction of losses through ensuring continuity of business services. Operational resilience is the ability to alter operations in the face of changing business conditions. It is the ability to quickly ramp up or slow down with quick and local process modification. An operationally resilient organisation is operating within the Plan Do Check Act cycle. It is continuously: • Finding and assessing its vulnerabilities and its supply chain vulnerabilities • Reducing the likelihood of disruption with planning, controls, flexibility and redundancies • Detecting disruption in itself and supply chains • Measuring its operational resilience METHOD There are various methods for measuring operational resilience, some of which are complex, protracted and involve various disciplines. Yet often the best way is the simplest way. This method is one of those, and the only requirement is that you know what you know and what you don’t know about your organisation. The method is explained using an example which is entirely customizable – you can change all the weighting values, scores, numbers and structures of the objectives and tasks. The important thing to note is that whatever you do, make sure it’s repeatable so you can carry out before and after measurements as part of your internal governance processes. It is often best achieved by a group of people from within the organisation. BENEFITS • Demonstrates continuous improvement towards objectives, and can help drive internal audit planning • Quick and requires no expertise, just knowledge of the performance of your organisation and key suppliers • A powerful presentational tool for top management • Customizable • Used to measure other business functions or capabilities, such as security or procurement
  • 3. STEP BY STEP Overall Objective Objectives Tasks Activities OPERATIONAL RESILIENCE Overall Objective Objectives Measuring your organisation’s operational resilience is the overall objective. This comprises 3 main objectives (or whatever you choose): • Perform a risk analysis of the organisation • Implement controls • Test and maintain the controls STEP 1 1. Functionally decompose the objectives into tasks 2. Functionally decompose the tasks into activities STEP 2 Understand organisation Vulnerability assesment Strategy selection Business objectives Internal resources Business impact analysis Understanding strategies Test Strategic External resources Risk assesment Strategy selection Maintenance Operational Business continuity plans Test and maintenance OPERATIONAL RESILIENCE Risk analysis Risk analysis Implementation Test and maintenance Communication Leadership Generic risk control Implementation of risk treatment BCM embedded Training Risk transfer Cultural aspects Supplier management Prevention Incident reporting Human resource Physical resource Implementation
  • 4. Overall Objective Objectives Tasks 1. Assign a weighting to each objective. The sum of the weightings must be 1. 2. Assign a weighting to each task. The sum of each objective group of tasks must be 1. STEP 3 Overall Objective Objectives Tasks Activities 1. Assign a weighting to each activity, so that for each parent task, they add up to 1. STEP 4 0.323 Risk analysis 0.588 Implementation 0.089 Test and maintenance 0.250 Understand organisation 0.425 Vulnerability assesment 0.250 Strategy selection 0.400 Leadership 0.400 Generic risk control 0.200 Implementation of risk treatment 0.075 Business objectives OPERATIONAL RESILIENCE 0.323 Risk analysis 0.588 Implementation 0.089 Test and maintenance 0.250 Understand organisation 0.425 Vulnerability assesment 0.250 Strategy selection 0.400 Leadership 0.400 Generic risk control 0.200 Implementation of risk treatment 0.075 Business objectives 0.500 Internal resources 0.500 Business impact analysis 0.118 Understanding strategies 0.667 BCM embedded 0.141 Training 0.066 Risk transfer 0.250 Test 0.167 Strategic 0.500 External resources 0.500 Risk assesment 0.268 Strategy selection 0.333 Cultural aspects 0.263 Supplier management 0.249 Prevention 0.750 Maintenance 0.833 Operational 0.614 Business continuity plans 0.141 Incident reporting 0.312 Human resource 0.455 Communication 0.373 Physical resource OPERATIONAL RESILIENCE
  • 5. Assign a score from between 0 and 1 to each activity (shown in brown). This is a subjective assessment of how optimal the task is, although if you have data to support your assessment then all the better. The score reflects your confidence in the task, and if you don’t know then give it a low score. This is deliberately subjective; it should be a quick debate. Some organisations define criteria for scoring e.g. what good and bad is. STEP 5 0.118 0.90 Understanding strategies 0.268 0.91 Strategy selection 0.614 1.00 Business continuity plans Multiply the score by the weighting. The product is shown in green. STEP 6 0.105 Understanding strategies 0.244 Strategy selection 0.614 Business continuity plans 1. The sum of the products is the score for the parent task (shown in pink). 2. Multiply the sum by the weighting to give the weighted score (shown in blue). STEP 7 0.105 Understanding strategies 0.244 Strategy selection 0.241 Strategy selection 0.250 0.963 0.614 Business continuity plans *as taken from above
  • 6. OPERATIONAL RESILIENCE www.nqa.com Overall Objective Objectives Tasks Activities Risk analysis Implementation Test and maintenance Understand organisation Vulnerability assesment Strategy selection Leadership Generic risk control Implementation of risk treatment Business objectives Test Maintenance 1. For each objective group of tasks, add up the task’s weighted scores (sum shown in pink). 2. Multiply the sum by the objective’s weighting (product shown in purple). 3. Add up the products to give the overall operational resilience assessment score (shown in red). STEP 8 0.842 0.004 0.089 0.053 0.518 0.588 0.882 0.320 0.323 0.991 0.250 0.00 0.075 0.250 0.425 0.241 0.400 0.395 0.087 0.750 0.07 ASSESSMENT SCORE The example assessment score doesn’t say the organisation is 86% operationally resilient. It is measure by which a higher score is almost certainly better than a lower score. But more importantly, it quickly identifies strengths, weaknesses or a lack of knowledge in certain areas. By applying criteria to the assessment it can be represented as a heat map for presentation purposes. Objectives Risk Analysis Implementation Test and Maintenance Tasks Risk Analysis Understand Organisation Vulnerability Assesment Strategy selection Leadership Generic risk control Implementation of risk treatment Activities Strategic Internal BIA Understand BCM Embedded Training Transfer Test Maintenance Operational External Risk Select BCM Culture Suppliers Prevent Incidents Human resources Comms Physical resources BCP NQA, Warwick House, Houghton Hall Park, Houghton Regis, Dunstable, Bedfordshire LU5 5ZX, United Kingdom T: 0800 052 2424 E: info@nqa.com @nqaglobal