Skip to content

FRM Exam Part II · Digital Resilience and Financial Stability: The Quest for Policy Tools in the Financial Sector

Digital Resilience Frameworks and Regulation for FRM Part II

Updated 11 October 2026 · Fact-checked

Digital resilience frameworks require financial firms to keep critical services running through ICT disruption, not just to prevent losses. DORA, the Basel operational resilience principles and FSB incident guidance share one logic: identify critical operations, set tolerances, test severe scenarios, manage third parties, respond and recover, then learn.

Understand Digital Resilience Frameworks and Regulation

Operational risk asks how much you may lose when processes, people, systems or external events fail. Operational resilience asks a different question: can you keep delivering critical services, and recover quickly, when something fails anyway? Risk management tries to reduce the chance of failure. Resilience assumes failure will happen and limits its impact on customers and markets.

Three bodies shape the topic. The Basel Committee issued principles for operational resilience. They are supervisory principles for banks, not a capital formula. They cover governance, operational risk management, business continuity planning and testing, mapping interconnections and dependencies, third-party dependency management, incident management, and ICT and cyber security resilience.

The EU Digital Operational Resilience Act (DORA) is binding EU regulation for financial entities and their critical ICT third-party providers. Its main pillars are ICT risk management, ICT-related incident management and reporting, digital operational resilience testing (including threat-led penetration testing for certain entities), management of ICT third-party risk, and information sharing. Providers designated as critical come under EU-level oversight.

The FSB works at the international level. Its cyber incident response and recovery toolkit sets out effective practices for firms. They cover governance, planning and preparation, analysis, mitigation, restoring operations, coordination and communication, and improvement. The FSB also works on common incident reporting formats to cut fragmentation across jurisdictions.

Common concepts run through all three. Identify critical operations or important functions. Set an impact tolerance (Basel calls it tolerance for disruption), meaning the maximum disruption you will accept. Map people, processes, technology and third parties behind each service. Test against severe but plausible scenarios. Manage concentration in cloud and ICT providers. The board owns the outcome.

Key formulas to remember

Resilience logic
Critical operations → map dependencies → set tolerance → test severe but plausible scenarios → respond and recover → learn
This sequence is the backbone of Basel, DORA and FSB material. Use it to place any answer option.
Operational risk vs operational resilience
Risk: reduce likelihood and loss. Resilience: limit disruption to critical services and recover within tolerance.
Resilience is outcome focused and service focused, not loss focused.
DORA pillars
ICT risk management; incident reporting; resilience testing; third-party risk; information sharing
Five pillars. Threat-led penetration testing sits under testing.
Tolerance check
Actual recovery time ≤ impact tolerance (maximum tolerable disruption)
A breach means the firm failed its own tolerance, even if no capital loss occurred.

How to solve Digital Resilience Frameworks and Regulation questions

Use this method for any question on digital resilience regulation, whether it asks for a definition, a framework match or a case judgement.

  1. 1Identify the framework or concept being tested: Basel principles, DORA or FSB toolkit.
  2. 2Decide if the question is about risk (losses, capital) or resilience (service continuity, recovery, tolerance).
  3. 3Find the critical service or function at stake and ask what it depends on, including third parties.
  4. 4Match the issue to the lifecycle stage: governance, mapping, tolerance, testing, third-party management, incident response, recovery or learning.
  5. 5Check who is responsible: the board and senior management own resilience; the first line runs it; supervisors set expectations.
  6. 6Eliminate options that treat resilience as only prevention, only capital, or only IT recovery.
  7. 7Pick the option that is service focused, tested under severe but plausible scenarios and tied to a tolerance.

Quickest way: Three-question filter

When to use it: Use when time is short and the options mix terms from several frameworks.

  1. Ask: is this about continuing critical services or about loss amounts? Services means resilience.
  2. Ask: is it binding EU law with named pillars (DORA) or international principles and effective practices (Basel, FSB)?
  3. Ask: which stage of the lifecycle does the scenario show? Pick the option for that stage, usually testing, third-party or incident handling.

Common mistakes in Digital Resilience Frameworks and Regulation

  • Treating operational resilience as the same as operational risk management.

    Both deal with failures of systems and processes.

    Fix: Remember the difference: risk reduces likelihood and loss; resilience keeps critical services within tolerance when failure occurs.

  • Saying the Basel operational resilience principles set a capital charge.

    Basel is mostly associated with capital rules.

    Fix: These are supervisory principles on governance, mapping, testing, third parties and incident management. Operational risk capital is a separate framework.

  • Calling DORA a set of voluntary guidelines.

    It is confused with international guidance from the FSB and Basel.

    Fix: DORA is binding EU regulation with specific requirements, including oversight of critical ICT third-party providers.

  • Setting tolerance by expected loss or probability.

    Candidates carry over VaR-style thinking.

    Fix: Impact tolerance is the maximum disruption to a critical service, usually expressed as time or volume, that the firm will accept.

  • Assuming outsourcing transfers the responsibility for resilience.

    Contracts and service level agreements look like a transfer of risk.

    Fix: The firm stays accountable. It must manage third-party and concentration risk, plan exits and test dependencies.

  • Testing only for likely events or only recovery of data.

    Tests are designed to pass.

    Fix: Frameworks expect severe but plausible scenarios, testing of the whole service and learning from results.

Worked examples

Example 1

A bank's payments service depends on a single cloud provider. An outage lasts 9 hours. The board had set an impact tolerance of 4 hours for the service. No customer funds were lost. Which assessment is most consistent with operational resilience frameworks?
A. No issue, because no financial loss occurred
B. Tolerance was breached; the bank should review mapping, concentration risk, exit and testing
C. Only the cloud provider is accountable
D. The bank should raise operational risk capital by 9 hours of revenue

Show the solution
  1. Compare actual disruption with tolerance: 9 hours exceeds 4 hours, so tolerance was breached.
  2. Resilience is judged by service continuity, so absence of loss does not remove the breach. A is wrong.
  3. Third-party dependency does not transfer accountability. C is wrong.
  4. Resilience principles are not a capital formula, and capital is not scaled by hours of revenue. D is wrong.
  5. The expected response is to review dependency mapping, concentration in one provider, exit and contingency plans, and scenario testing.

Answer: B

Example 2

Which feature distinguishes DORA from the Basel operational resilience principles and the FSB cyber toolkit?
A. It covers incident response
B. It is binding EU regulation that also brings critical ICT third-party providers under EU-level oversight
C. It requires board involvement
D. It addresses testing

Show the solution
  1. Incident response, board involvement and testing appear in all three sources, so A, C and D do not distinguish DORA.
  2. Basel principles and FSB toolkit are international supervisory principles and effective practices, not directly binding law.
  3. DORA is binding in the EU and sets an oversight regime for designated critical ICT third-party providers.
  4. Therefore B is the distinguishing feature.

Answer: B

Exam tips

  • Expect case-style stems: an outage, a vendor failure or a cyber incident. Decide first whether the question tests tolerance, third parties, testing or response.
  • Know the five DORA pillars by name and that threat-led penetration testing falls under testing.
  • Be precise on legal status: DORA is binding EU regulation; Basel principles and FSB toolkit are international guidance.
  • Wrong options often confuse resilience with capital, loss estimates or pure disaster recovery. Reject them.
  • Link this topic to concentration risk in cloud and ICT providers, as it also appears in the Current Issues readings on digital resilience.

Practice questions from Digital Resilience and Financial Stability: The Quest for Policy Tools in the Financial Sector

Digital Resilience Frameworks and Regulation: frequently asked questions

What is the difference between operational risk and operational resilience?

Operational risk is the risk of loss from failed processes, people, systems or external events. Operational resilience is the ability to keep delivering critical services and recover within a set tolerance when disruption happens. Resilience is service focused, while operational risk is loss focused.

What does DORA require in summary?

DORA requires EU financial entities to manage ICT risk, report major ICT incidents, test their digital resilience, and manage ICT third-party risk. It also encourages information sharing and places designated critical ICT providers under EU-level oversight.

Do the Basel operational resilience principles add capital requirements?

No. They are supervisory principles covering governance, risk management, continuity, mapping, third parties, incident management and ICT resilience. Operational risk capital is handled by a separate Basel framework.

What is the FSB cyber incident response and recovery toolkit?

It is a set of effective practices that help firms prepare for, respond to and recover from cyber incidents. It covers governance, planning, analysis, mitigation, restoration, coordination, communication and improvement after the event.