← All sectors
Resilience Rulebook · By sector

Financial Market Utilities (FMUs)

The operational-resilience, BCDR, and crisis-handling obligations that most likely apply to financial market utilities (fmus) — by regulator, domain, and compliance status. Filter and search the full set below.

A WSquare Advisory analysis In partnership with Resilis
Profile fmu · 146 likely-applicable · 0 excluded by asset size
Disclaimer. Applicability is determined entity by entity, based on each firm's specific facts and circumstances — charter, registrations, activities, asset/AUM size, and more. These profiles are an automated first-pass filter to help triage what likely applies; they are NOT a legal determination and NOT legal advice. Confirm applicability for your specific entity with qualified counsel or compliance.
WITHIN THE RESILIENCE CORPUS — 146 obligations · Financial market utility / clearing agency pure continuity / DR / crisis (neither): 88 Cybersecurity 31 total · 26 only Third-party 32 total · 27 only 5 both
Within this corpus, cybersecurity (31) and third-party (32) overlap (5) and each keeps its own space (26 cyber-only, 27 third-party-only); 88 are pure continuity / DR / crisis. This is a thematic split of the resilience body — not the entirety of either theme.
The wider picture — cyber & third-party are far larger than resilience
US financial-sector final rules, Federal Register, since 2015 · as of 2026-06-24 (federal proxy; excludes state/EU/UK/Canada)
Cybersecurity19 of 62 rules touch resilience (31%) · 43 outside scope
Third-party33 of 416 rules touch resilience (8%) · 383 outside scope
Most cyber and (especially) third-party rulemaking does not touch resilience and is intentionally out of this corpus. The Venn above is a thematic split within the resilience body, not the whole of either theme.
Applicable rules by regulator
CA_OSFI: 48 (33%)CA_OSFI48UK_PRA: 24 (16%)UK_PRA24EU_ESA: 23 (16%)EU_ESA23FRB: 22 (15%)FRB22SEC: 15 (10%)SEC15OCC: 14 (10%)OCC14

Resilience sub-themes in scope

How this persona’s 146 applicable obligations distribute across cross-cutting themes. For the full lens (what each requires), run python3 -m regwatch.theme <theme> --persona fmu.

ThemeObligationsof which proposed
Third-Party / Vendor Risk Management32
Cybersecurity × Resilience31
Incident Reporting & Notification78
Resilience Testing & Exercises34

Likely applicable (146)


Country:
Domain:
Regulator:
IDCountryRegulatorDomainSize triggerObligation (with source quote)CitationStatusSuggested evidence to comply
OBL-00731United StatesFRBbusiness continuityEstablish a board-approved robust operational risk management framework that identifies and mitigates plausible sources of operational risk, ensures high security and reliability, and provides for rapid recovery of critical operations.
“manage its operational risks by establishing a robust operational risk-management framework that is approved by its board of directors”
12 CFR 234.3(a)(17)finalBoard-approved written operational risk management framework; documented risk-tolerance policy; evidence of board approval and periodic review.
OBL-00732United StatesFRBbusiness continuityMaintain a business continuity plan incorporating a secondary site with a distinct risk profile from the primary site.
“business continuity plan that (1) incorporates the use of a secondary site at a location with a distinct risk profile from the primary site”
12 CFR 234.3(a)(17)(vii)finalWritten BCP with documented secondary site; site risk profile analysis showing distinct risk profile; evidence of operational readiness of secondary site.
OBL-00733United StatesFRBbusiness continuityMaintain a BCP designed to enable critical systems to recover and resume operations no later than two hours following disruptive events.
“is designed to enable critical systems to recover and resume operations no later than two hours following disruptive events”
12 CFR 234.3(a)(17)(vii)finalBCP with documented 2-hour RTO for critical systems; test results demonstrating achievement of 2-hour recovery target.
OBL-00734United StatesFRBbusiness continuityMaintain a BCP designed to enable completion of settlement by the end of the day of disruption, even in extreme circumstances.
“is designed to enable it to complete settlement by the end of the day of the disruption, even in case of extreme circumstances”
12 CFR 234.3(a)(17)(vii)finalBCP with same-day settlement completion objective; scenario test results including extreme disruption scenarios confirming end-of-day settlement capability.
OBL-00735United StatesFRBbusiness continuityTest the business continuity plan at least annually.
“is tested at least annually”
12 CFR 234.3(a)(17)(vii)finalAnnual BCP test records including date, scope, participants, results, and identified gaps; evidence of participant involvement in testing.
OBL-00736United StatesFRBbusiness continuityConduct tests of systems, policies, procedures, and controls in accordance with a documented testing framework that addresses at minimum scope, frequency, participation, interdependencies, and reporting.
“conduct tests of its systems, policies, procedures, and controls in accordance with a documented testing framework”
12 CFR 234.3(a)(17)(i)(A)(1)finalWritten testing framework document covering scope, frequency, participation, interdependencies, and reporting; test logs and results.
OBL-00737United StatesFRBbusiness continuityEnsure testing assesses whether systems, policies, procedures, or controls function as intended.
“a designated FMU's testing assess whether its systems, policies, procedures, or controls function as intended”
12 CFR 234.3(a)(17)(i)(A)(2)finalTest plans with defined expected outcomes; test results comparing actual vs. intended performance; remediation records for gaps.
OBL-00738United StatesFRBbusiness continuityConduct review of design, implementation, and testing of affected and similar systems, policies, procedures, and controls after any material operational incident.
“conduct a review of the design, implementation, and testing of systems, policies, procedures, and controls after the designated FMU experienced any material operational incidents”
12 CFR 234.3(a)(17)(i)(B)finalPost-incident review reports documenting affected and similar systems reviewed; findings and remediation actions; governance sign-off.
OBL-00739United StatesFRBbusiness continuityConduct review of affected and similar systems, policies, procedures, and controls when a change to the operating environment could significantly affect plausible sources or mitigants of operational risk.
“review the design, implementation, and testing of systems, policies, procedures, and controls after significant changes to the environment in which it operates”
12 CFR 234.3(a)(17)(i)(B)finalChange management records identifying operational risk impact; post-change review reports; governance approval documentation.
OBL-00740United StatesFRBbusiness continuityRemediate deficiencies identified during tests and reviews as soon as possible, following established governance processes, including risk analysis, prioritization, and validation.
“remediate, as soon as possible and following established governance processes, any deficiencies identified during tests and reviews”
12 CFR 234.3(a)(17)(i)(C)finalDeficiency tracking log; governance-approved remediation plans with target dates; evidence of completion or documented risk acceptance; validation records.
OBL-00741United StatesFRBbusiness continuityEstablish a documented framework for incident management providing for prompt detection, analysis, and escalation of incidents; appropriate response procedures; and incorporation of lessons learned.
“establish a documented framework for incident management that provides for the prompt detection, analysis, and escalation of an incident; appropriate procedures for addressing an incident; and incorporation of lessons learned following an incident”
12 CFR 234.3(a)(17)(vi)finalWritten incident management framework document; evidence of lessons-learned reviews; escalation procedures; after-action reports.
OBL-00742United StatesFRBbusiness continuityInclude within the incident management framework a plan for notification and communication of material operational incidents identifying entities to be notified, including non-participants that could be affected.
“include a plan for notification and communication of material operational incidents. This plan, among other things, would need to identify the entities that would be notified of operational incidents, including non-participants”
12 CFR 234.3(a)(17)(vi)finalWritten notification and communication plan listing all entity types to be notified; contact lists including non-participants and industry fora.
OBL-00743United StatesFRBbusiness continuityImmediately notify the Board when the designated FMU activates its business continuity plan or has a reasonable basis to conclude there is an actual or likely disruption or material degradation to critical operations, services, or ability to fulfill obligations on time.
“notify the Board immediately when it activated its business continuity plan or had a reasonable basis to conclude that (1) there was an actual or likely disruption, or material degradation, to any of its critical operations or services”
12 CFR 234.3(a)(17)(vi)(A)(1)finalIncident notification log with timestamps; Board notification records; documented notification process aligned with Board-established process.
OBL-00744United StatesFRBbusiness continuityImmediately notify the Board when the designated FMU has a reasonable basis to conclude there is an unauthorized entry, or a vulnerability that could allow unauthorized entry, into its computer/network/electronic systems that affects or could affect critical operations or services.
“unauthorized entry or a vulnerability that could allow unauthorized entry, into the designated FMU's computer, network, electronic, technical, automated, or similar systems that affects or has the potential to affect its critical operations or services”
12 CFR 234.3(a)(17)(vi)(A)(2)finalCyber incident and vulnerability log; Board notification records with timestamps; evidence of reasonable-basis assessment criteria.
OBL-00745United StatesFRBbusiness continuityNotify the Board of incidents in accordance with the process established by the Board. [adjacent]
“a designated FMU must notify the Board of incidents 'in accordance with the process established by the Board'”
12 CFR 234.3(a)(17)(vi)(A)finalWritten notification procedure referencing Board-established process; evidence of communication with Board supervisory team to confirm contact details and methods.
OBL-00746United StatesFRBbusiness continuityEstablish criteria and processes for timely communication and responsible disclosure of material operational incidents to participants or other relevant entities, including appropriate communication methods.
“establish criteria and processes, including the appropriate methods of communication, to provide for timely communication and responsible disclosure of material operational incidents to its participants or other relevant entities”
12 CFR 234.3(a)(17)(vi)(B)finalDocumented disclosure criteria; communication procedures; contact lists; sample notifications; records of participant communications during past incidents.
OBL-00747United StatesFRBbusiness continuityImmediately notify affected participants in the event of actual disruptions or material degradation to critical operations or services or to the ability to fulfill obligations on time.
“notify affected participants immediately in the event of actual disruptions or material degradation to its critical operations or services or to its ability to fulfill its obligations on time”
12 CFR 234.3(a)(17)(vi)(B)(1)finalParticipant notification logs with timestamps; incident records; evidence of identification of affected participants and immediate outreach.
OBL-00748United StatesFRBbusiness continuityNotify all participants and other relevant entities in a timely and responsible manner of all other material operational incidents that require immediate Board notification.
“notify all participants and other relevant entities in a timely and responsible manner of all other material operational incidents that require immediate notification to the Board”
12 CFR 234.3(a)(17)(vi)(B)(2)finalAll-participant notification records; disclosure timing log; documented responsible disclosure criteria; evidence of notifications to non-participant relevant entities.
OBL-00749United StatesFRBbusiness continuityIdentify and mitigate plausible sources of operational risk (internal and external) through appropriate systems, policies, procedures, and controls that are reviewed, audited, and tested periodically and after major changes.
“identify the plausible sources of operational risk, both internal and external, and mitigate their impact through the use of appropriate systems, policies, procedures, and controls that are reviewed, audited, and tested periodically and after major changes”
12 CFR 234.3(a)(17)(i)finalOperational risk register; audit reports; testing records; change management logs triggering post-change reviews.
OBL-00750United StatesFRBbusiness continuityIdentify, monitor, and manage operational risks the designated FMU may pose to other FMUs and trade repositories. [adjacent]
“identify, monitor, and manage the operational risks it may pose to other FMUs and trade repositories”
12 CFR 234.3(a)(17)finalInterdependency risk assessments; monitoring procedures for risks transmitted to connected FMUs and trade repositories; documented escalation procedures.
OBL-00751United StatesFRBbusiness continuityEnsure adequate, scalable capacity to handle increasing stress volumes.
“have adequate, scalable capacity to handle increasing stress volumes”
12 CFR 234.3(a)(17)finalCapacity planning documentation; stress/volume test results; capacity monitoring reports; evidence of scalability mechanisms.
OBL-00752United StatesFRBbusiness continuityAddress potential and evolving vulnerabilities and threats to operational risk, including supply chain and ransomware threats, through systems, policies, procedures, and controls.
“address potential and evolving vulnerabilities and threats”
12 CFR 234.3(a)(17)finalThreat intelligence program documentation; vulnerability management policy; evidence of supply chain and ransomware scenario planning; updated risk assessments.
OBL-00755United StatesSECcybersecurityDevelop, implement, and maintain written policies and procedures for an incident response program reasonably designed to detect, respond to, and recover from unauthorized access to or use of customer information.
“require covered institutions to develop, implement, and maintain written policies and procedures for an incident response program that is reasonably designed to detect, respond to, and recover from unauthorized access to or use of customer information”
17 CFR 248.30(a)(3)finalWritten incident response program policies and procedures; version history; board/senior management approval documentation
OBL-00756United StatesSECcybersecurityInclude in the incident response program procedures to assess the nature and scope of any incident and identify customer information systems and types of customer information that may have been accessed or used without authorization.
“Assess the nature and scope of any incident involving unauthorized access to or use of customer information and identify the customer information systems and types of customer information that may have been accessed or used without authorization”
17 CFR 248.30(a)(3)(i)finalWritten assessment procedures within IRP; completed incident assessment records; logs identifying affected systems and data types
OBL-00757United StatesSECcybersecurityInclude in the incident response program procedures to take appropriate steps to contain and control an incident to prevent further unauthorized access to or use of customer information.
“Take appropriate steps to contain and control the incident to prevent further unauthorized access to or use of customer information”
17 CFR 248.30(a)(3)(ii)finalWritten containment and control procedures within IRP; incident records showing containment actions taken; periodic review documentation
OBL-00761United StatesSECcybersecurityInclude incident response program procedures for notifying affected individuals whose sensitive customer information was, or is reasonably likely to have been, accessed or used without authorization. [adjacent]
“Notify each affected individual whose sensitive customer information was, or is reasonably likely to have been, accessed or used without authorization in accordance with the notification obligations discussed below”
17 CFR 248.30(a)(3)(iii)finalWritten notification procedures within IRP; notification decision trees; records of notifications issued per incident
OBL-00762United StatesSECcybersecurityEstablish, maintain, and enforce written policies and procedures for oversight of service providers, including due diligence and monitoring, to ensure service providers safeguard customer information and that affected individuals receive required notices. [adjacent]
“covered institutions will be required to establish, maintain, and enforce written policies and procedures reasonably designed to require oversight, including through due diligence and monitoring of service providers, including to ensure that affected individuals receive any required notices”
17 CFR 248.30(a)(5)finalWritten vendor oversight policies; due diligence records; service provider contracts with security/notification obligations; monitoring logs
OBL-00763United StatesSECcybersecurityRequire service providers to notify the covered institution of a breach as soon as possible, but no later than 72 hours after the service provider becomes aware that an applicable breach has occurred.
“the final amendments require covered institutions to ensure that their service providers provide notification as soon as possible, but no later than 72 hours after becoming aware that an applicable breach has occurred”
17 CFR 248.30(a)(5)(i)finalVendor contracts containing 72-hour breach notification clauses; records of notifications received from service providers; breach intake logs
OBL-00765United StatesSECcybersecurityAdopt written policies and procedures with administrative, technical, and physical safeguards to protect customer records and information (safeguards rule), now extended to transfer agents. [adjacent]
“The safeguards rule requires brokers, dealers, investment companies, and registered investment advisers to adopt written policies and procedures that address administrative, technical, and physical safeguards to protect customer records and information”
17 CFR 248.30(a)finalWritten safeguards policy covering administrative, technical, and physical controls; evidence of transfer agent compliance; periodic review records
OBL-00768United StatesSECcybersecurityPeriodically review and update incident response assessment and containment procedures to ensure they remain reasonably designed.
“covered institutions generally should consider reviewing and updating the assessment procedures periodically to ensure that the procedures remain reasonably designed”
17 CFR 248.30(a)(3)finalDocumented periodic review cycle for IRP; change logs showing updates; board or senior management approval of updated procedures
OBL-00769United StatesSECcybersecurityDelay customer notification only upon receiving a written request from the Attorney General that notification poses a substantial risk to national security or public safety, consistent with the Public Company Cybersecurity Rules framework. [adjacent]
“the final amendments will permit covered institutions to delay providing notice after the Commission receives a written request from the Attorney General that this notice poses a substantial risk to national security or public safety”
17 CFR 248.30(a)(4)finalProcedures for handling Attorney General delay requests; records of any delay requests received and actions taken
OBL-00885European UnionEU_ESAbusiness continuityEstablish and maintain a sound, comprehensive and well-documented ICT risk management framework as part of the overall risk management system.
“Financial entities shall have in place a sound, comprehensive and well-documented ICT risk management framework as part of their overall risk management system”
Art. 6(1) Regulation (EU) 2022/2554finalBoard-approved ICT risk management framework document; annual review records; integration evidence within overall risk management system
OBL-00886European UnionEU_ESAbusiness continuityIdentify, classify and document all ICT-supported business functions, roles, dependencies, assets and information assets critical to operations.
“Financial entities shall identify, classify and adequately document all ICT supported business functions, roles and responsibilities, the information assets and ICT assets supporting those functions”
Art. 8(1) Regulation (EU) 2022/2554finalAsset inventory and classification register; mapping of ICT assets to critical business functions; documented dependencies
OBL-00887European UnionEU_ESAbusiness continuityContinuously monitor and manage all sources of ICT risk, including risks posed by third-party ICT service providers, and implement protection and prevention measures.
“Financial entities shall continuously monitor and control the security and functioning of ICT systems and tools and shall minimise the impact of ICT risk”
Art. 9(1)-(2) Regulation (EU) 2022/2554finalContinuous monitoring logs; vulnerability management records; evidence of preventive controls; third-party risk monitoring reports
OBL-00888European UnionEU_ESAbusiness continuityImplement ICT business continuity policy and plans to ensure continuity of critical or important functions through ICT disruptions.
“As part of the ICT risk management framework referred to in Article 6(1), financial entities shall put in place a comprehensive ICT business continuity policy”
Art. 11(1) Regulation (EU) 2022/2554finalBoard-approved ICT BCP document; list of critical functions covered; activation criteria; defined RTO/RPO; annual review records
OBL-00891European UnionEU_ESAbusiness continuityDevelop and implement crisis communication plans to ensure effective communication to staff, stakeholders and public during ICT-related crises.
“Financial entities shall have in place crisis communication plans enabling a responsible disclosure of, at least, major ICT-related incidents or vulnerabilities to clients, counterparts and the public”
Art. 14(1) Regulation (EU) 2022/2554finalDocumented crisis communication plan; defined roles and spokespersons; internal/external notification templates; activation records
OBL-00892European UnionEU_ESAbusiness continuityDesignate a crisis communication manager responsible for managing communications during ICT-related incidents.
“Financial entities shall designate a person responsible for implementing the communication strategy for ICT-related incidents and fulfil the public and media function for that purpose”
Art. 14(2) Regulation (EU) 2022/2554finalNamed crisis communication manager; role description; evidence of appointment; escalation pathway documentation
OBL-00893European UnionEU_ESAbusiness continuityEstablish and maintain an ICT-related incident management process to detect, manage and notify major ICT-related incidents, including classification criteria.
“Financial entities shall define, establish and implement an ICT-related incident management process to detect, manage and notify ICT-related incidents”
Art. 17(1) Regulation (EU) 2022/2554finalIncident management process documentation; classification criteria; incident log; escalation procedures; evidence of regular review
OBL-00894European UnionEU_ESAbusiness continuityClassify ICT incidents and cyber threats using prescribed criteria (clients affected, duration, data loss, criticality, economic impact) and report major incidents to competent authorities.
“Financial entities shall classify ICT-related incidents and shall determine their impact based on the following criteria: the number of clients, counterparts or financial transactions affected”
Art. 18(1) Regulation (EU) 2022/2554finalClassification methodology aligned to RTS criteria; incident registers with classification evidence; major incident reports submitted to authorities
OBL-00895European UnionEU_ESAbusiness continuitySubmit initial, intermediate and final reports on major ICT-related incidents to the relevant competent authority within prescribed timeframes.
“Financial entities shall submit: an initial notification; an intermediate report after the initial notification, as soon as the status of the original incident has changed significantly; a final report”
Art. 19(3) Regulation (EU) 2022/2554finalTemplates for initial/intermediate/final reports; submission records with timestamps; evidence of authority acknowledgement
OBL-00896European UnionEU_ESAbusiness continuityPerform a basic digital operational resilience testing programme annually, covering ICT tools, systems and processes supporting critical or important functions.
“Financial entities shall establish, maintain and review a sound and comprehensive digital operational resilience testing programme as an integral part of the ICT risk management framework”
Art. 25(1) Regulation (EU) 2022/2554finalAnnual resilience testing plan and results; coverage of critical/important functions; gap remediation records; sign-off by management
OBL-00897European UnionEU_ESAbusiness continuityConduct threat-led penetration testing (TLPT) at least every three years on critical or important live production systems.
“Financial entities shall carry out at least every 3 years advanced testing by means of TLPT. Based on the risk profile of the financial entity and taking into account operational circumstances”
Art. 26(1) Regulation (EU) 2022/2554finalTLPT scope documentation; testers' credentials (TIBER or equivalent); test results and remediation plans; authority notification records
OBL-00898European UnionEU_ESAbusiness continuityAdopt a strategy on ICT third-party risk, including a policy for use of ICT services supporting critical or important functions, and review it annually.
“As part of their ICT risk management framework, financial entities shall adopt and regularly review a strategy on ICT third-party risk, taking into account the multi-vendor strategy”
Art. 28(1) Regulation (EU) 2022/2554finalBoard-approved third-party ICT risk strategy; annual review records; multi-vendor strategy documentation; concentration risk assessment
OBL-00899European UnionEU_ESAbusiness continuityBefore entering into ICT third-party arrangements for critical or important functions, assess concentration risk and risks of ICT service provider failure or unavailability.
“Prior to entering into a contractual arrangement on the use of ICT services, financial entities shall: identify and assess all relevant risks in relation to the ICT third-party service provider”
Art. 28(4) Regulation (EU) 2022/2554finalPre-contract due diligence reports; concentration risk analysis; risk registers; sign-off documentation before contract execution
OBL-00900European UnionEU_ESAbusiness continuityMaintain and update a register of all contractual arrangements with ICT third-party service providers and report it to competent authorities upon request.
“Financial entities shall maintain and update at entity level, at sub-consolidated and at consolidated level, a register of information in relation to all contractual arrangements on the use of ICT services”
Art. 28(3) Regulation (EU) 2022/2554finalCentralised ICT third-party contract register; evidence of regular updates; submission records to competent authority
OBL-00901European UnionEU_ESAbusiness continuityEnsure contractual arrangements with ICT third-party providers for critical/important functions include mandatory clauses on business continuity, availability, recovery and exit strategies.
“Contractual arrangements on the use of ICT services shall include at minimum: the description of full service levels including updates and revisions thereof; the obligations of the ICT third-party service provider to provide assistance at no additional cost”
Art. 30(2) Regulation (EU) 2022/2554finalContract clauses checklist aligned to Art. 30 requirements; contract review records; evidence of remediated legacy contracts
OBL-00902European UnionEU_ESAbusiness continuityEstablish exit strategies for ICT third-party arrangements on critical or important functions to ensure continuity if a provider fails or is discontinued.
“Financial entities shall, taking into account the specificities of the ICT services to be provided, have exit strategies in order to be able to terminate, without detriment to their regulated activities, the relevant contractual arrangements”
Art. 28(8) Regulation (EU) 2022/2554finalDocumented exit strategies per critical provider; portability assessments; alternative provider lists; transition plan templates
OBL-00903European UnionEU_ESAbusiness continuityInclude in ICT contracts with providers of critical/important functions rights to audit, access data, and require participation in incident response and recovery activities.
“Contractual arrangements for the provision of ICT services supporting critical or important functions shall include: full cooperation of the ICT third-party service provider with the competent authorities and the resolution authorities of the financial entity”
Art. 30(3) Regulation (EU) 2022/2554finalContract audit-right and cooperation clauses; evidence of audit execution; incident response cooperation records from providers
OBL-00904European UnionEU_ESAbusiness continuityImplement protection measures including data integrity, encryption and access controls to safeguard ICT assets and ensure resilience of ICT infrastructure.
“Financial entities shall develop, document and implement a policy on ICT security giving formal mandate to protect confidentiality, integrity, and availability of data”
Art. 9(3) Regulation (EU) 2022/2554finalICT security policy; encryption and access control standards; evidence of implementation; penetration test results; periodic review records
OBL-00905European UnionEU_ESAbusiness continuityMaintain backup systems and data restore procedures tested regularly, with backup systems physically and logically separate from primary systems.
“Financial entities shall put in place backup policies and procedures. Financial entities shall have backup systems that can be activated without undue delay”
Art. 12(1) Regulation (EU) 2022/2554finalBackup policy; evidence of physical/logical separation; restore test records and success metrics; RTO/RPO alignment documentation
OBL-00906European UnionEU_ESAbusiness continuityDetect anomalous activity, identify potential single points of failure, and implement measures to address ICT concentration risk in own infrastructure.
“Financial entities shall identify all sources of ICT risk and shall assess cyber threats and ICT vulnerabilities relevant to their ICT supported business functions, information assets and ICT assets”
Art. 8(4) Regulation (EU) 2022/2554finalICT risk assessment reports; single point of failure analysis; concentration risk register; remediation plans with target dates
OBL-00907European UnionEU_ESAbusiness continuityEnsure the management body defines, approves, oversees and is accountable for the ICT risk management framework and digital operational resilience strategy.
“The management body of the financial entity shall define, approve, oversee and be accountable for the implementation of all arrangements related to the ICT risk management framework”
Art. 5(1) Regulation (EU) 2022/2554finalBoard resolution approving ICT risk framework; board-level oversight records; assigned accountability documentation; training completion records
OBL-00908European UnionEU_ESAbusiness continuityConduct post-incident reviews after major ICT incidents to identify root causes and implement corrective actions to prevent recurrence.
“After a major ICT-related incident, financial entities shall perform a post-incident review to determine the root causes of disruptions and identify improvements to be applied to the ICT operations”
Art. 17(6) Regulation (EU) 2022/2554finalPost-incident review reports with root-cause analysis; corrective action plans with owners and deadlines; evidence of implementation
OBL-00909European UnionEU_ESAbusiness continuityShare cyber threat intelligence and information on ICT vulnerabilities and incidents with other financial entities under appropriate confidentiality arrangements. [adjacent]
“Financial entities may exchange amongst themselves cyber threat information and intelligence, including indicators of compromise, tactics, techniques, and procedures, cyber alerts and configuration tools”
Art. 45(1) Regulation (EU) 2022/2554finalInformation-sharing agreements; records of threat intelligence shared/received; confidentiality controls; participation in sector ISACs
OBL-00982CanadaCA_OSFIbusiness continuityEstablish and maintain an Enterprise Disaster Recovery Program (EDRP) to support ability to deliver technology services through disruption and operate within risk tolerance.
“FRFIs should establish and maintain an Enterprise Disaster Recovery Program (EDRP) to support its ability to deliver technology services through disruption and operate within its risk tolerance.”
OSFI B-13, Section 2.9, Principle 12finalBoard/Senior Management approved EDRP document; RTO/RPO definitions; accountability matrix; data backup/recovery policy; evidence of alignment with BCM program.
OBL-00984CanadaCA_OSFIbusiness continuityAlign the disaster recovery program with the business continuity management program.
“FRFIs should align the disaster recovery program with its business continuity management program.”
OSFI B-13, Section 2.9.1finalDocumentation cross-referencing EDRP and BCM program; shared dependency analysis; integrated test plans; governance records showing joint oversight.
OBL-00985CanadaCA_OSFIbusiness continuityManage key EDRP dependencies including data security/storage requirements, locations of backup sites, service provider locations relative to primary data centres, and other critical technology assets.
“FRFIs should manage key dependencies required to support the EDRP, such as: Information security requirements for data security and storage (e.g., encryption); and, Location of technology asset centres, backup sites, service provider locations and proximity to primary data centres.”
OSFI B-13, Section 2.9.2finalDependency register with geographic/proximity analysis; encryption standards for backup data; inventory of backup and recovery sites; third-party location mapping.
OBL-00986CanadaCA_OSFIbusiness continuityRegularly perform scenario testing on disaster recovery capabilities against severe but plausible scenarios to validate recovery strategies and confirm ability to meet pre-defined requirements.
“FRFIs should regularly validate and report on their disaster recovery strategies, plans and/or capabilities against severe but plausible scenarios...The FRFI's backup and recovery capabilities and processes to validate resiliency strategies, plans and actions, and confirm the organization's ability ”
OSFI B-13, Section 2.9.3, Principle 13finalDR test schedule; scenario descriptions; test results and gap analysis reports; evidence of senior management reporting on test outcomes.
OBL-00987CanadaCA_OSFIbusiness continuityDR scenario testing must include critical third-party technologies and integration points with upstream/downstream dependencies, both on- and off-premises.
“Critical third-party technologies and integration points with upstream and downstream dependencies, including both on- and off-premises technology.”
OSFI B-13, Section 2.9.3finalDR test scope documentation listing third-party systems tested; test results for third-party recovery; evidence of joint testing with critical service providers.
OBL-00988CanadaCA_OSFIbusiness continuityDR scenarios must be forward-looking and consider new/emerging risks, material changes to business/technology, situations causing prolonged outage, and prior incident history.
“These scenarios should be forward-looking and consider, where appropriate: New and emerging risks or threats; Material changes to business objectives or technologies; Situations that can lead to prolonged outage; and, Previous incident history and known technology complexities or weaknesses.”
OSFI B-13, Section 2.9.3finalScenario library with documented rationale; threat intelligence inputs; post-incident review records used as scenario inputs; refresh log.
OBL-00989CanadaCA_OSFIbusiness continuityDefine standards and implement incident/problem management processes including governance structure for timely identification, escalation, system restoration/recovery, and root cause investigation.
“FRFIs should define standards and implement processes for incident and problem management. Standards should provide an appropriate governance structure for timely identification and escalation of incidents, restoration and/or recovery of an affected system, and investigation and resolution of incide”
OSFI B-13, Section 2.7.1finalIncident management standard/policy; escalation matrix; restoration procedures; RCA process documentation; incident logs.
OBL-00990CanadaCA_OSFIbusiness continuityImplement incident response procedures including internal/external communication with escalation/notification triggers, and establish and periodically test incident management processes with third parties.
“Developing and implementing incident response procedures that mitigate the impacts of incidents, including internal and external communication actions that contain escalation and notification triggers and processes...Establishing and periodically testing incident management processes with third part”
OSFI B-13, Section 2.7.2finalIncident response playbooks; communication plans with notification thresholds; third-party incident management agreements; joint test records.
OBL-00991CanadaCA_OSFIbusiness continuityConduct periodic exercises and testing of incident management processes, playbooks, and response tools to validate and maintain their effectiveness.
“Performing periodic testing and exercises using plausible scenarios in order to identify and remedy gaps in incident response actions and capabilities; Conducting periodic exercises and testing of incident management process, playbooks, and other response tools (e.g., coordination and communication)”
OSFI B-13, Section 2.7.2finalExercise schedule and after-action reports; playbook review logs; gap remediation tracking; evidence of lessons-learned integration.
OBL-00992CanadaCA_OSFIbusiness continuityDevelop problem management processes for detection, categorization, investigation and resolution of incident causes, including post-incident reviews and root cause/impact diagnostics to improve incident management.
“FRFIs should develop problem management processes that provide for the detection, categorization, investigation and resolution of suspected incident cause(s). Processes should include post-incident reviews, root cause and impact diagnostics and identification of trends or patterns in incidents.”
OSFI B-13, Section 2.7.3finalProblem management process documentation; post-incident review records; trend analysis reports; evidence of process improvements driven by findings.
OBL-00993CanadaCA_OSFIbusiness continuityDesign and implement technology architecture using Resilience-by-Design and Availability-by-Design principles, commensurate with business needs.
“Using a risk-based approach, systems and associated infrastructure should be designed and implemented to achieve availability, scalability, security (Secure-by-Design) and resilience (Resilience-by-Design), commensurate with business needs.”
OSFI B-13, Section 2.1.2finalArchitecture framework documentation; design standards referencing resilience/availability requirements; architecture review records; sign-off on new systems against resilience criteria.
OBL-00994CanadaCA_OSFIbusiness continuityMaintain a current comprehensive asset inventory cataloguing technology assets throughout their lifecycle, including documented interdependencies between critical assets to assist in response to security and operational incidents.
“Documented interdependencies between critical technology assets, where appropriate, to enable proper change and configuration management processes, and to assist in response to security and operational incidents, including cyber attacks.”
OSFI B-13, Section 2.2.2finalAsset inventory system with criticality classification; interdependency maps; process for keeping inventory current; evidence of use during incident response.
OBL-00995CanadaCA_OSFIbusiness continuityContinuously monitor technology currency and proactively implement plans to mitigate risks from unpatched, outdated, or unsupported assets; replace/upgrade assets before maintenance ceases.
“FRFIs should continuously monitor the currency of software and hardware assets...It should proactively implement plans to mitigate and manage risks stemming from unpatched, outdated or unsupported assets and replace or upgrade assets before maintenance ceases.”
OSFI B-13, Section 2.2.5finalTechnology currency monitoring reports; end-of-life asset register; remediation/upgrade plans with timelines; evidence of executive oversight.
OBL-00996CanadaCA_OSFIbusiness continuityEnsure changes to technology assets in production are documented, assessed, tested, approved, implemented and verified in a controlled manner, with defined emergency change controls. [adjacent]
“FRFIs should ensure that changes to technology assets in the production environment are documented, assessed, tested, approved, implemented and verified in a controlled manner...The standard should also define emergency change and control requirements to ensure that such changes are implemented in a”
OSFI B-13, Section 2.5.1finalChange management policy/standard; change logs; emergency change procedures; post-implementation review records.
OBL-00997CanadaCA_OSFIbusiness continuityDefine technology service management standards with performance indicators/service targets and remediation processes to ensure technology services support business continuity.
“FRFIs should establish technology service management standards with defined performance indicators and/or service targets that can be used to measure and monitor the delivery of technology services. Processes should also provide for remediation where targets are not being met.”
OSFI B-13, Section 2.8.1finalService management standards; KPI/SLA dashboards; remediation tracking logs; management reporting on service performance.
OBL-00998CanadaCA_OSFIbusiness continuityDefine and continuously monitor performance and capacity requirements with thresholds on infrastructure utilisation to ensure technology supports current and future business needs.
“FRFIs should define performance and capacity requirements with thresholds on infrastructure utilization. These requirements should be continuously monitored against defined thresholds to ensure technology performance and capacity support current and future business needs.”
OSFI B-13, Section 2.8.2finalCapacity management plan; utilisation threshold documentation; monitoring tool outputs; alerts and breach records; capacity planning reports.
OBL-00999CanadaCA_OSFIbusiness continuityEstablish cyber incident response capabilities (team, tools, playbooks) available on a continuous basis to rapidly respond, contain and recover from cyber security events materially impacting technology assets.
“FRFIs should establish a cyber incident response team with tools and capabilities available on a continuous basis to rapidly respond, contain and recover from cyber security events and incidents that could materially impact the FRFI's technology assets, customers and other stakeholders.”
OSFI B-13, Section 3.4.4finalCyber incident response team charter; on-call rosters; tooling inventory; playbooks; 24/7 availability evidence; test exercise records.
OBL-01000CanadaCA_OSFIbusiness continuityMaintain cyber security incident management process and playbooks to enable timely and effective management of cyber security incidents.
“FRFIs should maintain a cyber security incident management process and playbooks to enable timely and effective management of cyber security incidents.”
OSFI B-13, Section 3.4.3finalCurrent cyber incident management process documentation; scenario-specific playbooks; version control records; evidence of regular review and update.
OBL-01001CanadaCA_OSFIbusiness continuityAlign and integrate cyber security, technology, crisis management and communication protocols, including capabilities for timely escalation and stakeholder coordination during major cyber events.
“FRFIs should ensure the alignment and integration between their cyber security, technology, crisis management and communication protocols. This should include capabilities to enable comprehensive and timely escalation and stakeholder coordination (internal and external) in response to a major cyber ”
OSFI B-13, Section 3.4.1finalIntegrated cyber-crisis management framework; escalation matrix linking cyber, technology and crisis teams; communication protocols; joint exercise records.
OBL-01002CanadaCA_OSFIbusiness continuityConduct forensic investigation for incidents where technology assets may have been materially exposed; perform detailed post-incident assessment including RCA for high-severity incidents.
“FRFIs should conduct a forensic investigation for incidents where technology assets may have been materially exposed. For high-severity incidents, the FRFI should conduct a detailed post-incident assessment of direct and indirect impacts...including a root cause analysis to identify remediation acti”
OSFI B-13, Section 3.4.5finalForensic investigation reports; post-incident assessment reports; RCA documentation; remediation action plans; tracking of lessons learned.
OBL-01003CanadaCA_OSFIbusiness continuityMaintain continuous security logging for technology assets and defence layers; implement minimum log retention periods; ensure logs support timely forensic investigation of cyber events. [adjacent]
“FRFIs should ensure continuous security logging for technology assets and different layers of defence tools...FRFIs should implement minimum security log retention periods and maintain cyber security event logs to facilitate a thorough and unimpeded forensic investigation of cyber security events.”
OSFI B-13, Section 3.3.1finalLog management policy with defined retention periods; SIEM configuration; log completeness audit results; evidence that logs were available and usable in recent incidents.
OBL-01004CanadaCA_OSFIbusiness continuityProactively identify, defend, detect, respond and recover from cyber security threats and incidents to maintain confidentiality, integrity and availability of technology assets.
“FRFIs should proactively identify, defend, detect, respond and recover from external and insider cyber security threats, events and incidents to maintain the confidentiality, integrity and availability of its technology assets.”
OSFI B-13, Section 3.0finalCyber resilience framework documentation; threat assessment records; detection tool evidence; response/recovery playbooks; post-incident recovery evidence.
OBL-01005CanadaCA_OSFIbusiness continuityImplement enhanced controls to rapidly contain cyber threats, defend critical technology assets, and remain resilient against cyber attacks, including designing application controls to limit cyber attack impact.
“FRFIs should employ enhanced controls and functionality to rapidly contain cyber security threats, defend its critical technology assets and remain resilient against cyber attacks...Designing application controls to contain and limit the impact of a cyber attack.”
OSFI B-13, Section 3.2.3finalCritical asset register with associated enhanced controls; containment control documentation; security hardening baselines; control testing results.
OBL-01006CanadaCA_OSFIbusiness continuityEstablish technology and cyber risk management framework including risk appetite, tolerance levels, and processes for identifying, assessing, managing and reporting technology/cyber risks including emerging threats. [adjacent]
“Technology and cyber risk appetite and measurement (e.g., limits, thresholds and tolerance levels)...Management of unique risks posed by emerging threats and technologies...Reporting to Senior Management on technology and cyber risk appetite measures, exposures and trends.”
OSFI B-13, Section 1.3.2finalApproved RMF with risk appetite statements; tolerance thresholds; risk reporting dashboards; emerging risk process documentation; board/senior management reporting records.
OBL-01207United KingdomUK_PRAbusiness continuityIdentify and document important business services (IBS) — those whose disruption could pose risk to safety and soundness, financial stability, or policyholder protection.
“firms must identify their important business services...defined as the services a firm provides which, if disrupted, could pose a risk to a firm's safety and soundness or...the financial stability of the UK.”
Operational Resilience 2.1; SS1/21 §2.2finalBoard-approved written list of IBS with documented rationale referencing safety/soundness, financial stability and policyholder protection criteria; reviewed annually.
OBL-01208United KingdomUK_PRAbusiness continuitySet an impact tolerance (including a mandatory time-based metric) for each identified important business service.
“firms to set an impact tolerance for each of their important business services...An impact tolerance must, in all cases, include a time-based metric to measure the tolerable level of disruption.”
Operational Resilience 2.2, 2.4; SS1/21 §3.1, §3.6finalDocumented impact tolerances per IBS with time-based metric (and supplementary metrics where applicable); board approval evidenced in board minutes.
OBL-01209United KingdomUK_PRAbusiness continuitySet impact tolerances at the point beyond which further disruption would pose a risk to safety and soundness, financial stability, or policyholder protection.
“require firms to set their impact tolerances at the point at which any further disruption to the important business service would pose a risk to the firm's safety and soundness...policyholder protection...financial stability of the UK.”
Operational Resilience 2.3; SS1/21 §3.2finalWritten rationale for each tolerance threshold referencing quantitative/qualitative indicators per SS1/21 §3.8.
OBL-01210United KingdomUK_PRAbusiness continuityEnsure ability to deliver each IBS within its impact tolerance in severe but plausible scenarios by 31 March 2025.
“firms to ensure they are able to deliver their important business services within impact tolerances in severe but plausible scenarios...no later than Monday 31 March 2025.”
Operational Resilience 2.5, 2.6; SS1/21 §4.1, §4.14finalPrioritised remediation plan showing milestones; evidence of plan execution; scenario test results confirming IBS delivery within tolerance by 31 March 2025.
OBL-01211United KingdomUK_PRAbusiness continuityDevelop and implement effective remediation plans for IBS that cannot remain within impact tolerances, with timing proportionate to disruption impact.
“firms to develop and implement effective remediation plans for the important business services that would not be able to remain within their impact tolerance...speed at which vulnerabilities are remediated should be commensurate with the potential impact.”
SS1/21 §4.3, §4.15finalWritten remediation plans per at-risk IBS with timelines; progress tracking records; evidence of senior management ownership.
OBL-01212United KingdomUK_PRAbusiness continuityMap the people, processes, technology, facilities, and information resources required to deliver each IBS, including resources provided by third parties.
“require firms to identify and document the necessary people, processes, technology, facilities, and information...required to deliver each of their important business services...irrespective of whether the resources are being provided wholly or in part by a third party.”
Operational Resilience 4.1; SS1/21 §5.1, §5.5finalDocumented mapping artefacts per IBS showing all resource dependencies including third-party/intragroup; updated annually or on material change.
OBL-01213United KingdomUK_PRAbusiness continuityUpdate IBS mapping at least annually, or sooner following a significant change.
“The PRA expects firms to update their mapping annually at a minimum, or following significant change if sooner.”
SS1/21 §5.9finalVersion-controlled mapping documents with dated review records; change-triggered update log.
OBL-01214United KingdomUK_PRAbusiness continuityRegularly test ability to remain within impact tolerances using severe but plausible disruption scenarios, with testing focused on recovery and response.
“require firms to test regularly their ability to remain within impact tolerances in severe but plausible disruption scenarios...The PRA expects firms to focus on recovery and response arrangements.”
Operational Resilience 5.1; SS1/21 §6.1finalWritten testing plan; scenario test reports; evidence of increasing scenario severity over time; lessons-learned log.
OBL-01215United KingdomUK_PRAbusiness continuityDevelop a written testing plan specifying scenario types, frequency, IBS coverage, and availability/integrity testing, proportionate to potential disruption impact.
“firms to develop a testing plan that details how they will gain assurance that they can remain within impact tolerances...nature and frequency of a firm's testing should be proportionate to the potential impact that disruption could cause.”
SS1/21 §6.6finalDocumented testing plan covering scenario types, frequency, IBS prioritisation, availability/integrity scenarios; board or senior management approval.
OBL-01217United KingdomUK_PRAbusiness continuityEnsure ability to remain within impact tolerances irrespective of third-party use; effectively manage third parties so they do not cause tolerance breaches.
“firms to be able to remain within impact tolerances for important business services, irrespective of whether or not they use third parties in the delivery of these services...effectively manage their use of third parties to ensure they can meet the required standard.”
SS1/21 §4.5finalThird-party contracts with resilience obligations; third-party assurance reports; evidence that third-party SLAs align with impact tolerance requirements.
OBL-01218United KingdomUK_PRAbusiness continuityUnderstand and manage sub-outsourcing dependencies that may threaten operational resilience and IBS delivery.
“Firms should understand the reliance placed on sub-outsourcing arrangements and if these arrangements pose a threat to their operational resilience.”
SS1/21 §5.6finalSub-outsourcing register; materiality assessment; evidence that primary service providers maintain oversight of sub-contractors' resilience capability.
OBL-01219United KingdomUK_PRAbusiness continuityInclude third-party failure/disruption scenarios (including supply chain) as severe but plausible scenarios in operational resilience testing.
“one of the severe but plausible scenarios that firms may select for this testing could involve a failure or disruption at a third party, or their supply chain, based on previous incidents or near misses.”
SS1/21 §6.13finalTesting plans and reports that include at least one third-party/supply-chain failure scenario per material outsourced IBS.
OBL-01220United KingdomUK_PRAbusiness continuityRequire contractual agreements for material outsourcing to include obligations for both parties to implement and test business contingency plans aligned to impact tolerances.
“contractual agreements for material outsourcing arrangements to include 'requirements for both parties to implement and test business contingency plans. For the firm, these should take account of firms' impact tolerances for important business services.'”
SS1/21 §6.13finalMaterial outsourcing contracts containing explicit BCP testing obligations; evidence of joint or coordinated testing with third parties.
OBL-01221United KingdomUK_PRAbusiness continuityDevelop communication strategies for internal and external stakeholders as part of operational disruption response planning, including escalation paths and decision-maker identification.
“firms to develop communication strategies for both internal and external stakeholders as part of their planning for responding to operational disruptions...plans should include the escalation paths they would use to manage communications during an incident.”
SS1/21 §4.7finalWritten communications plan per IBS covering escalation paths, key contact lists (regulators, suppliers, operational staff), and decision-maker identification.
OBL-01222United KingdomUK_PRAbusiness continuityReview IBS list at least annually, or sooner on significant change, to determine whether additions or removals are required.
“The PRA expects firms to review their important business services annually at a minimum, or sooner if a significant change occurs, and to determine whether any changes are required to their list of important business services.”
SS1/21 §2.10finalAnnual review records with board/senior management sign-off; change log documenting trigger-based reviews.
OBL-01223United KingdomUK_PRAbusiness continuityBoard must approve and regularly review: IBS list, impact tolerances, and written self-assessment, including scenario analyses of ability to remain within tolerances.
“a firm's board must approve and regularly review the firm's important business services, impact tolerances, and written self-assessment...boards must regularly review assessments...and the scenario analyses of its ability to remain within the impact tolerance.”
Operational Resilience 7; SS1/21 §7.1finalBoard meeting minutes evidencing approval and review of IBS, tolerances, self-assessment and scenario results; board MI packs.
OBL-01224United KingdomUK_PRAbusiness continuityAssign overall responsibility for implementing operational resilience policies to the Chief Operations SMF24 (where it exists) with reporting to the board.
“the Chief Operations Senior Management Function (SMF) 24 should hold overall responsibility for implementing operational resilience policies and reporting to the board.”
SS1/21 §7.4finalSMF24 appointment documentation; SMCR responsibilities map attributing operational resilience to SMF24; board reporting records.
OBL-01225United KingdomUK_PRAbusiness continuityProduce and maintain a written self-assessment documenting compliance with the Operational Resilience Parts, approved by the board.
“require firms to document a self-assessment of their compliance with the Operational Resilience Part...Firms' boards are accountable for and should approve the information provided in these documents.”
Operational Resilience 6; SS1/21 §8.1finalBoard-approved written self-assessment document; version history; board approval minute.
OBL-01226United KingdomUK_PRAbusiness continuitySelf-assessment must document IBS list with rationale, impact tolerances with rationale, mapping methodology, testing strategy and scenarios, lessons learned, identified vulnerabilities with remediation plans, and group-related risks.
“list their important business services...specify the impact tolerances...detail their approach to mapping...describe their strategy for testing...identify any lessons learned...identify the vulnerabilities that threaten their ability...identify any additional risks...from elsewhere in their group.”
Operational Resilience 6; SS1/21 §8.3finalSelf-assessment containing all enumerated sections; board approval minute; evidence of annual updates.
OBL-01227United KingdomUK_PRAbusiness continuitySet recovery time objectives and recovery point objectives for resources underpinning IBS so that the IBS can be delivered within its impact tolerance.
“requirements might include capacity specifications, recovery time objectives, and recovery point objectives. These requirements should be set to enable the firm to deliver the important business service within its impact tolerance.”
SS1/21 §3.14finalDocumented RTO/RPO per resource/system supporting each IBS; evidence RTO/RPO align to and are tested against impact tolerances.
OBL-01228United KingdomUK_PRAbusiness continuityCRR consolidation entities and insurers must identify important group business services and set impact tolerances at group level to capture risks from non-individually-regulated group members.
“CRR consolidation entities...or an insurer...to identify a proportionate number of important group business services and respective impact tolerances at the level of the group.”
Operational Resilience 8.6–8.13; SS1/21 §9.1finalGroup-level IBS list with impact tolerances; board approval at group level; group self-assessment including subsidiaries outside the UK.
OBL-01229United KingdomUK_PRAbusiness continuityCRR consolidation entities must maintain regular dialogue with group members so CRR firms can account for additional risks to safety and soundness when assessing ability to remain within impact tolerances. [adjacent]
“the CRR consolidation entity would have regular dialogue with other members of its group so the CRR firm (or CRR firms) can take account of any additional risks to their safety and soundness when assessing their ability to remain within impact tolerance.”
Operational Resilience 8.8; SS1/21 §9.4finalRecords of regular group resilience dialogue (e.g. meeting minutes); group risk reporting mechanisms feeding into individual firm self-assessments.
OBL-01230United KingdomUK_PRAbusiness continuityManage risks from intragroup third-party arrangements with the same rigour as external third parties to ensure ability to remain within impact tolerances.
“firms to manage risk and make appropriate arrangements to be able to remain within impact tolerance, whether using third parties that are other entities within their group or external providers.”
SS1/21 §4.6finalIntragroup SLAs/contracts with resilience obligations; assurance evidence (audits, test results) for intragroup providers equivalent to external third-party oversight.
OBL-01231United KingdomUK_PRAbusiness continuityHave a prioritised plan in place by 31 March 2022 setting out how the firm will achieve full within-tolerance capability, with the plan already being executed by that date.
“Firms are expected to have a prioritised plan which sets out how they will comply with the requirement to be able to remain within their impact tolerances within a reasonable time...firms must have started putting the plan into effect by Thursday 31 March 2022.”
SS1/21 §4.14finalDated, board-approved prioritised remediation/implementation plan; evidence of programme initiation (e.g. project kick-off, resource allocation) by 31 March 2022.
OBL-01237CanadaCA_OSFIbusiness continuityIdentify critical operations and assess their ability to withstand disruptions; map all internal and external dependencies end to end, covering people, technology, processes, information, facilities, and third parties.
“Critical operations should be identified and assessed for their ability to withstand disruptions... Once identified, critical operations should be mapped for internal and external dependencies.”
Guideline E-21, Section 3.1finalWritten inventory of critical operations; dependency maps reviewed and updated regularly; documented financial-loss estimates for disruption scenarios.
OBL-01238CanadaCA_OSFIbusiness continuityEstablish tolerances for disruption for each critical operation, setting the maximum level of disruption the institution can withstand across a range of severe but plausible scenarios.
“Tolerances for disruption should set out the maximum level of disruption a financial institution can withstand across a range of severe but plausible scenarios.”
Guideline E-21, Section 3.2finalBoard/senior-management-approved tolerance statements per critical operation; documentation showing tolerances exceed risk appetite limits; periodic review records.
OBL-01239CanadaCA_OSFIbusiness continuityConduct regular scenario testing of critical operations against severe-but-plausible disruptions, using tabletop exercises, simulations, and live-systems testing, to assess whether operations can persist within tolerances for disruption.
“Regular scenario testing improves understanding of when tolerances for disruption would be breached... a variety of testing methodologies should be used, including table-top exercises, simulations, and live-systems testing.”
Guideline E-21, Section 3.3finalScenario testing schedule; test plans and results; gap analyses; board/senior-management reporting of results; iterative improvement records.
OBL-01240CanadaCA_OSFIbusiness continuityConduct business impact analyses to assess risks and potential impacts of disruptive events, identify the impact of disruptions, and establish maximum recovery objectives; review and update the analyses regularly.
“A business impact analysis assesses the risks and potential impacts of a range of disruptive events on operations. It should identify and measure: The impact of disruptions. The maximum limits on recovery objectives before severe consequences or losses occur.”
Guideline E-21, Section 4.1.1finalCurrent BIA documentation with RTO/RPO thresholds; evidence of periodic review; linkage to BCP and scenario-testing programme.
OBL-01241CanadaCA_OSFIbusiness continuityDevelop business continuity plans (BCPs) covering response and recovery actions for a range of threats, including protocols for plan invocation, roles and responsibilities, backup personnel, staff safety, recovery targets, workarounds, and internal/external communication plans.
“Business continuity plans set out the response and recovery actions for a range of potential threats... This should include: Establishing protocols for invoking the plan... Defining roles and responsibilities... Setting targets for recovery levels and times.”
Guideline E-21, Section 4.1.2finalDocumented BCPs per critical operation/business unit; invocation protocols; communication templates; staff training records.
OBL-01242CanadaCA_OSFIbusiness continuityRegularly test business continuity plans using scenarios that include long-duration and simultaneous disruptions involving critical third parties; address gaps identified and maintain contingency plans for critical third parties.
“Business continuity plan tests should provide reasonable assurance that plans are effective... Tests should consider a range of severe but plausible circumstances, including scenarios with disruptions that: Are long in duration. Are simultaneous in nature. Involve critical third parties.”
Guideline E-21, Section 4.1.3finalBCP test schedule and results; after-action reports; gap-remediation tracking; evidence critical third parties demonstrated BCP robustness.
OBL-01244CanadaCA_OSFIbusiness continuityEstablish a crisis management plan with escalation protocols to senior management and the board, plan invocation criteria, internal and external communications protocols, and conduct regular testing and lessons-learned exercises.
“A crisis management plan should be established that ensures effective, coordinated, and timely responses to potential crises... It should include: Protocols for escalation to senior management and the board. Criteria for invoking the plan. Internal and external communications protocols.”
Guideline E-21, Section 4.3finalDocumented crisis management plan; escalation matrix; communications templates; test records; lessons-learned reports incorporated into plan updates.
OBL-01245CanadaCA_OSFIbusiness continuityMaintain a senior-level crisis management team responsible for decision-making, coordination, and oversight of strategies to address crises affecting operations.
“A crisis management team can help ensure effective communication, expedited recovery, and an effective response to the crisis.”
Guideline E-21, Section A5 (definition) and Section 4.3finalTerms of reference for crisis management team; membership list with seniority documented; records of activation and decision logs during incidents.
OBL-01246CanadaCA_OSFIbusiness continuityIntegrate business continuity risk management with operational resilience, evolving its focus from business processes to critical operations end to end, and including business impact analyses and tested BCPs.
“Business continuity risk management is the process of planning for, and recovering from, disruptions to operations. It should be integrated with and strengthen operational resilience. Over time, its focus should evolve from business processes to critical operations end to end.”
Guideline E-21, Section 4.1finalEvidence of BCP integration with operational resilience programme; roadmap showing evolution toward end-to-end critical operations coverage.
OBL-01247CanadaCA_OSFIbusiness continuityProvide staff with training on business continuity plans, including plan activation and management of operations during disruption.
“Staff should be provided with training on business continuity plans, including their activation and how operations will be managed during disruption.”
Guideline E-21, Section 4.1.2finalTraining completion records; training materials covering BCP activation; periodic refresher training schedule.
OBL-01248CanadaCA_OSFIbusiness continuityObtain sufficient information about critical third parties to assess their resilience, and coordinate with them to conduct broader resilience exercises where possible.
“Where a third party is identified as critical, sufficient information should be obtained to assess its resilience... The financial institution should also coordinate with critical third parties, where possible, to conduct broader exercises.”
Guideline E-21, Sections 3.1 and 3.3finalThird-party resilience assessments; evidence of information gathered (e.g., audit reports, questionnaires); joint exercise records with critical third parties.
OBL-01249CanadaCA_OSFIbusiness continuityRequire critical third parties to demonstrate robustness in their own business continuity plans and testing, and maintain contingency plans for critical third-party failures.
“Critical third parties should also demonstrate robustness in their own business continuity plans and testing. There should be processes to address gaps identified during testing, as well as contingency plans for critical third parties.”
Guideline E-21, Section 4.1.3finalContractual BCP requirements for critical third parties; evidence of third-party BCP review/testing attestations; documented contingency/exit plans per critical third party.
OBL-01250CanadaCA_OSFIbusiness continuityImplement a data risk management framework including a strategy and programme covering data governance, architecture, classification, integrity/availability controls, and processes for escalating and responding to data breaches and data-related incidents. [adjacent]
“It should also comprise a specific data risk management framework that includes a data risk management strategy and program... Processes for escalating and responding to data breaches and other data-related incidents.”
Guideline E-21, Section 4.7finalDocumented data risk management framework; data governance policy with roles; data architecture documentation; incident-response procedures for data breaches; training records.
OBL-01251CanadaCA_OSFIbusiness continuityEnsure data supporting critical operations is accurate, complete, timely, secure, and protected, using methodologies that maintain integrity, adaptability, confidentiality, and availability throughout the data lifecycle.
“Effective data risk management ensures that data is accurate, complete, timely, secure, and protected... Methodologies for ensuring the integrity, adaptability, confidentiality, and availability of data throughout its lifecycle.”
Guideline E-21, Section 4.7finalData quality and availability metrics; documented lifecycle management controls; classification and protection policies; testing evidence for data availability under disruption scenarios.
OBL-01252CanadaCA_OSFIbusiness continuityEmbed effective technology and cyber risk management as a foundation of operational resilience, aligned with Guideline B-13, to prevent wide-scale operational disruption from technology failure, infiltration, or data loss.
“A critical technology failure, infiltration, or loss of data can result in wide-scale disruption impacting operations. Sound technology and cyber risk management is fundamental to bolstering operational resilience.”
Guideline E-21, Section 4.5finalTechnology and cyber risk management programme aligned with B-13; cyber incident response plans; resilience controls documentation; testing records.
OBL-01253CanadaCA_OSFIbusiness continuityManage third-party operational resilience risks (including disruption at a third party or loss/corruption of critical data) as part of operational resilience, aligned with Guideline B-10.
“Threats to operational resilience can arise from critical third-party arrangements, including disruption at the third party or the loss or corruption of critical data. Accordingly, effective third-party risk management is an important contributor to operational resilience.”
Guideline E-21, Section 4.6finalThird-party risk register identifying critical arrangements; resilience due-diligence records; concentration risk analysis; B-10-aligned oversight documentation.
OBL-01254CanadaCA_OSFIbusiness continuityConduct scenario analysis at both business-unit and enterprise-wide levels using a range of severe but plausible scenarios; use results to inform operational resilience scenario testing.
“Scenario analysis should be conducted using appropriate techniques at both the business unit and enterprise-wide levels and incorporate a range of severe but plausible scenarios... Scenario analysis results may be used to inform operational resilience scenario testing.”
Guideline E-21, Section 2.3.4finalDocumented scenario analysis results; evidence of business-unit and enterprise-wide coverage; linkage records showing how results fed into Section 3.3 scenario testing.
OBL-01255CanadaCA_OSFIbusiness continuityEnsure senior management and the board receive timely reports on operational resilience scenario testing results, including analysis of deficiencies, assessment of whether critical operations can be maintained within tolerances, and plans to address shortcomings.
“Senior management and the board of directors should also receive the results of scenario analysis... and scenario testing... This should include: Analysis of deficiencies. An assessment of operational resilience, and whether critical operations can be maintained within established tolerances for dis”
Guideline E-21, Section 2.4.2finalBoard and senior-management reporting templates; documented scenario testing reports presented to board; remediation tracking logs.
OBL-01256CanadaCA_OSFIbusiness continuityEnsure breaches of tolerances for disruption are appropriately escalated to senior management and addressed in a timely and sustainable manner.
“Ensuring breaches of tolerances for disruption are appropriately escalated and addressed.”
Guideline E-21, Section 1.1finalEscalation policy and procedures; log of tolerance breaches with escalation records; evidence of corrective actions taken and closed.
OBL-01257CanadaCA_OSFIbusiness continuityPerform change management assessments for significant operational changes (new products, acquisitions, new tech systems, process changes), including deploying tested contingency plans if a change fails and testing changes before implementation.
“Deploy tested contingency plans in the event a change fails. Test the change on systems and processes before introducing it.”
Guideline E-21, Section 4.4finalChange management policy; operational risk assessments for significant changes; tested contingency/rollback plans; pre-implementation test results; post-implementation effectiveness metrics.
OBL-01258CanadaCA_OSFIbusiness continuityConduct ongoing monitoring of adherence to tolerances for disruption and operational risk limits, using comprehensive metrics; ensure key risk indicators include escalation protocols when risk levels approach or exceed limits.
“Ongoing monitoring should be conducted to help prepare for, and respond to, changes in operational risks. It should assess adherence to the operational risk appetite statement and operational risk limits, as well as tolerances for disruption.”
Guideline E-21, Sections 2.4.1 and 2.3.2finalKRI dashboard including tolerance-for-disruption metrics; documented escalation thresholds; monitoring reports; records of management actions taken when thresholds breached.
OBL-01259CanadaCA_OSFIbusiness continuityCapture and analyse operational risk event data (actual, potential, and near-misses) to determine root causes, contributing risk categories, and corrective measures; use findings to strengthen resilience controls.
“Operational risk event data exceeding established limits should be captured to assess: What the root cause of the operational risk event is... What corrective measures ought to be taken to address deficiencies or control failures.”
Guideline E-21, Section 2.3.3finalOperational risk event database including near-misses; root-cause analysis records; corrective action logs; trend reporting to senior management.
OBL-01260CanadaCA_OSFIbusiness continuityEnsure independent risk and compliance functions oversee and challenge resilience activities, including escalation channels for significant issues, and that internal audit provides independent assurance on operational risk management controls and systems.
“The independent risk and compliance functions oversee and challenge the risk and resilience activities... Internal audit or a similar function should provide independent assurance to senior management and the board of directors that operational risk management controls, policies and procedures, and ”
Guideline E-21, Sections 1.3 and 1.4finalInternal audit plan covering ORM and resilience; audit reports; issue-tracking logs; documented escalation channels; second-line challenge records.
OBL-01261CanadaCA_OSFIbusiness continuityConduct lessons-learned exercises following a crisis and incorporate findings into the crisis management plan; share the plan with relevant business units and impacted external parties.
“Lessons-learned exercises should be undertaken following a crisis and incorporated into the plan. The crisis management plan should be regularly tested and shared with the relevant business units in the financial institution and any impacted external parties, as appropriate.”
Guideline E-21, Section 4.3finalPost-crisis lessons-learned reports; evidence of plan updates; distribution records showing plan shared with business units and external parties; test schedules and results.
OBL-01262United StatesOCCcrisis managementBanking organizations must notify their primary Federal regulator of any computer-security incident that rises to the level of a notification incident as soon as possible and no later than 36 hours after determining the incident occurred.
“a banking organization must notify its primary Federal regulator of any computer-security incident that rises to the level of a notification incident as soon as possible and no later than 36 hours after the banking organization determines that a notification incident has occurred.”
12 CFR Part 53 (OCC); 12 CFR Part 225 (Board); 12 CFR Part 304 (FDIC) — Final Rule Section III.AfinalWritten incident response procedure with 36-hour notification SLA; incident log with timestamps of determination and notification; sample notifications to primary Federal regulator; after-action reports.
OBL-01263United StatesOCCcrisis managementBank service providers must notify at least one bank-designated point of contact at each affected banking organization customer as soon as possible when the bank service provider determines it has experienced a computer-security incident that has materially disrupted or degraded, or is reasonably likely to materially disrupt or degrade, c
“the final rule requires a bank service provider to notify at least one bank-designated point of contact at each affected banking organization customer as soon as possible when the bank service provider determines it has experienced a computer-security incident that has caused, or is reasonably likel”
12 CFR Part 53 (OCC); 12 CFR Part 225 (Board); 12 CFR Part 304 (FDIC) — Final Rule Section III.AfinalNotification procedures referencing bank-designated contacts; incident logs with determination timestamps; evidence of as-soon-as-possible notifications to banking organization customers; service agreements identifying points of contact.
OBL-01264United StatesOCCcrisis managementBanking organizations must have sufficient understanding of their lines of business to determine which business lines, upon failure, would result in a material loss of revenue, profit, or franchise value, in order to identify notification incidents. [adjacent]
“all banking organizations must have a sufficient understanding of their lines of business to be able to determine which business lines would, upon failure, result in a material loss of revenue, profit, or franchise value to the banking organization, so that they can meet their notification obligatio”
12 CFR Part 53 (OCC); 12 CFR Part 225 (Board); 12 CFR Part 304 (FDIC) — Final Rule Section III.B.ivfinalDocumented inventory of core business lines with materiality assessments; board or senior management approval; mapping of business lines to notification incident thresholds.
OBL-01266United StatesOCCcrisis managementBanking organizations must apply a 'reasonably likely' materiality standard when determining whether a computer-security incident constitutes a notification incident requiring regulator notification, covering incidents that have materially disrupted or degraded or are reasonably likely to do so.
“a banking organization will be required to notify its primary Federal regulator when it has suffered a computer-security incident that has a reasonable likelihood of materially disrupting or degrading the banking organization or its operations.”
12 CFR Part 53 (OCC); 12 CFR Part 225 (Board); 12 CFR Part 304 (FDIC) — Final Rule Section III.B.ivfinalWritten decision criteria/playbook defining 'reasonably likely' threshold; documented incident classification rationale; training records for staff making notification determinations.
OBL-01267United StatesOCCcrisis managementBanking organizations must evaluate whether a material loss of revenue, profit, or franchise value resulting from a computer-security incident is material on an enterprise-wide basis when assessing notification incident status under the second prong of the definition.
“a banking organization should evaluate whether the loss is material to the organization as a whole.”
12 CFR Part 53 (OCC); 12 CFR Part 225 (Board); 12 CFR Part 304 (FDIC) — Final Rule Section III.B.ivfinalEnterprise-wide materiality assessment methodology; documented incident evaluations referencing enterprise-level impact; internal policies on materiality thresholds.
OBL-01268United StatesOCCcrisis managementBank service providers must ensure their notification to banking organization customers is directed to a bank-designated point of contact rather than an arbitrary individual, requiring coordination with banking organization customers to establish and maintain those contact designations.
“requiring that notice be provided to a bank-designated point of contact, rather than to at least two individuals at each banking organization customer.”
12 CFR Part 53 (OCC); 12 CFR Part 225 (Board); 12 CFR Part 304 (FDIC) — Final Rule Section III.A and III.D.iiifinalMaintained and current list of bank-designated notification contacts per customer; contractual or operational records reflecting designated contacts; notification test records.
OBL-01269United StatesOCCcrisis managementBanking organizations and bank service providers must determine whether a computer-security incident has occurred based on a determination standard (not a subjective good-faith belief), requiring documented incident assessment processes.
“the agencies are replacing the 'good faith belief' standard with a banking organization's determination. The agencies agree with commenters who criticized the proposed 'believes in good faith' standard as too subjective and imprecise.”
12 CFR Part 53 (OCC); 12 CFR Part 225 (Board); 12 CFR Part 304 (FDIC) — Final Rule Section III.B.ivfinalDocumented incident determination procedures; records of each determination with supporting evidence; audit trail showing when determination was made and by whom.
OBL-01270United StatesOCCcrisis managementBanking organizations must be capable of identifying computer-security incidents that materially disrupt or degrade (or are reasonably likely to do so) their ability to carry out banking operations or deliver products/services to a material portion of their customer base in the ordinary course of business.
“Ability to carry out banking operations, activities, or processes, or deliver banking products and services to a material portion of its customer base, in the ordinary course of business.”
12 CFR Part 53 (OCC); 12 CFR Part 225 (Board); 12 CFR Part 304 (FDIC) — Final Rule Section III.B.ivfinalIncident classification framework with defined thresholds for customer-base impact; customer access monitoring tools; documented escalation procedures for customer-facing service disruptions.
OBL-01271United StatesOCCcrisis managementBanking organizations must be capable of identifying notification incidents that impact operations whose failure or discontinuance would pose a threat to the financial stability of the United States (the third prong of the notification incident definition).
“operations, including associated services, functions and support, as applicable, the failure or discontinuance of which would pose a threat to the financial stability of the United States.”
12 CFR Part 53 (OCC); 12 CFR Part 225 (Board); 12 CFR Part 304 (FDIC) — Final Rule Section III.B.ivfinalDocumented identification of systemically important operations; impact analysis; linkage to resolution plan critical operations where applicable; board-approved classification.
OBL-01272United StatesOCCcrisis managementBanking organizations that provide sector-critical services and currently notify their primary Federal regulator of computer-security incidents on a same-day basis are encouraged to continue doing so (supervisory expectation).
“the agencies would encourage those banking organizations providing sector-critical services that currently notify their primary Federal regulator of these types of incidents on a same-day basis to continue to do so.”
12 CFR Part 53 (OCC); 12 CFR Part 225 (Board); 12 CFR Part 304 (FDIC) — Final Rule Section III.A (footnote 19)finalIncident response policy documenting same-day notification expectation for sector-critical service providers; notification logs demonstrating same-day practice.
OBL-01273United StatesOCCcrisis managementBank service providers must have procedures to determine when a computer-security incident has materially disrupted or degraded, or is reasonably likely to materially disrupt or degrade, covered services to banking organization customers for four or more hours, triggering the notification obligation.
“when the bank service provider determines it has experienced a computer-security incident that has caused, or is reasonably likely to cause, a material service disruption or degradation for four or more hours.”
12 CFR Part 53 (OCC); 12 CFR Part 225 (Board); 12 CFR Part 304 (FDIC) — Final Rule Section III.D.iifinalDocumented incident response procedures with four-hour service degradation trigger; service monitoring and duration-tracking tools; incident classification logs; sample notifications.
OBL-01274United StatesOCCcrisis managementBanking organizations must assess whether a computer-security incident at a bank service provider has or is reasonably likely to have a material impact on the banking organization, potentially triggering the banking organization's own notification requirement to its regulator.
“prompt notification will allow the banking organization to assess whether the incident has or is reasonably likely to have a material impact on the banking organization and thus trigger the banking organization's own notification requirement.”
12 CFR Part 53 (OCC); 12 CFR Part 225 (Board); 12 CFR Part 304 (FDIC) — Final Rule, Introduction and Section III.D.ifinalThird-party incident intake and assessment procedure; documented escalation criteria; records of assessments following receipt of bank service provider notifications.
OBL-01275United StatesOCCcrisis managementBanking organizations and bank service providers must ensure that contracts with bank service providers address notification provisions consistent with the final rule, so that banking organizations receive prompt notification of computer-security incidents affecting covered services.
“while the agencies agree that incident notification is generally addressed by contract, we believe that this issue is important enough to warrant an independent regulatory requirement that ensures consistency and enforceability, without the necessity of revising contractual provisions.”
12 CFR Part 53 (OCC); 12 CFR Part 225 (Board); 12 CFR Part 304 (FDIC) — Final Rule Section III.D.ivfinalContract inventory with review of notification provisions; updated contract templates meeting final rule standards; evidence of renegotiation or addenda for non-compliant contracts.
OBL-01276United StatesOCCcrisis managementBanking organizations must identify and monitor their critical dependence on bank service providers for essential services and ensure operational resilience by receiving timely notification of computer-security incidents at those providers that could disrupt covered services.
“banking organizations have become increasingly reliant on third parties to provide essential services. Such third parties may also experience computer-security incidents that could disrupt or degrade the provision of services to their banking organization customers.”
12 CFR Part 53 (OCC); 12 CFR Part 225 (Board); 12 CFR Part 304 (FDIC) — Final Rule Section III.D.ifinalInventory of critical bank service providers and covered services; third-party risk monitoring program; documented escalation procedures upon receipt of service provider incident notifications.
OBL-01336United StatesSECcybersecurityDisclose any material cybersecurity incident on Form 8-K Item 1.05 within four business days of determining the incident is material, describing nature, scope, timing, and impact. [adjacent]
“An Item 1.05 Form 8-K must be filed within four business days of determining an incident was material.”
17 CFR 249.308, Form 8-K Item 1.05; 17 CFR 240.13a-11finalFiled Form 8-K Item 1.05; internal materiality determination memo; incident log with determination date; description of nature, scope, timing, and impact
OBL-01337United StatesSECcybersecurityMake a materiality determination regarding a cybersecurity incident as soon as reasonably practicable after discovery of the incident. [adjacent]
“a registrant shall make a materiality determination regarding a cybersecurity incident as soon as reasonably practicable after discovery of the incident.”
Form 8-K Item 1.05, Instruction 1finalWritten incident response procedure specifying materiality assessment timeline; dated materiality determination records for each incident
OBL-01339United StatesSECcybersecurityDisclose in periodic reports (Form 10-K / Form 20-F) the registrant's processes for assessing, identifying, and managing material risks from cybersecurity threats. [adjacent]
“Registrants must describe their processes, if any, for the assessment, identification, and management of material risks from cybersecurity threats.”
17 CFR 229.106(b)finalAnnual report Item 106(b) disclosure; documented risk management framework; evidence of third-party assessor engagement if applicable
OBL-01342United StatesSECcybersecurityDisclose in periodic reports the board of directors' oversight of risks from cybersecurity threats. [adjacent]
“Describe the board's oversight of risks from cybersecurity threats.”
17 CFR 229.106(c); Form 20-FfinalAnnual report board oversight disclosure; board committee charters; board meeting minutes referencing cybersecurity oversight activities
OBL-01344United StatesSECcybersecurityForeign Private Issuers must describe in Form 20-F management's role in assessing and managing material cybersecurity risks. [adjacent]
“FPIs must: Describe management's role in assessing and managing material risks from cybersecurity threats.”
17 CFR 249.220f; Form 20-FfinalForm 20-F annual report cybersecurity governance section; management role descriptions; supporting internal governance documentation
OBL-01347United StatesSECcybersecurityA registrant may delay an Item 1.05 Form 8-K filing only where the U.S. Attorney General determines that immediate disclosure would pose a substantial risk to national security or public safety. [adjacent]
“A registrant may delay filing as described below, if the United States Attorney General determines immediate disclosure would pose a substantial risk to national security or public safety.”
Form 8-K Item 1.05; 17 CFR 240.13a-11finalWritten Attorney General determination on file; documented delay justification; record of filing date relative to AG determination receipt

Turning this into an operating plan?

Knowing which rules bind you is step one. WSquare Advisory builds the operating capability behind compliance — the continuity, third-party, and recovery disciplines these regimes expect. If that's your challenge, let's talk.

Start with an Operating Survey · $5,000 →