Board Resilience Assurance Orchestrator
Builds a traceable view of important-service resilience, third-party exposure and unresolved risk.
Reconciles service tolerances, dependencies, critical vendors, concentration, tests, incidents, exit readiness and actions into a board-level narrative that separates activity from assurance. It highlights services without current evidence, recurring failures and risk accepted beyond appetite, with every statement linked to source.
Authority
Prepare
Team role
Coordinates the work
Handoffs
Named collaborators
The role
What it owns and where its authority ends
Desk
Recovery, Lessons & Board Assurance
Desk workflow
Controlled restoration, then business validation, then independent post-incident review, then remediation verification, then committee and board assurance.
Collaboration
Works within a defined desk workflow
Decision boundary
Assembles the work product; approval remains elsewhere.
Systems and capabilities involved
Business service and dependency graph
TPRM, testing, incident and action records
Metric and appetite registry
Board-paper generator
Handoffs
What this role gives and receives
Capabilities offered
Build a resilience assurance report
Reconcile service, third-party, testing, incident and action evidence against appetite.
- Receives:
- Reporting period, service population, evidence records and risk appetite
- Returns:
- Cited committee or board pack with gaps, breaches, trends and actions
Delegates
Certify current concentration measures and correlated failure exposure. Trigger: Every reporting close Returns: Concentration results, breaches and material movements.
Delegates
Reconcile ICT relationship population and register completeness. Trigger: Every reporting close for regulated ICT relationships Returns: Population, validation errors, attestations and submission status.
Delegates
Provide overdue, repeated and independently closed action status. Trigger: Every reporting close Returns: Action aging, extensions, recurrence and closure evidence.
Handoff to
Receives from
Receives from
External handoff
Chief risk officer
External handoff
Operational resilience committee
Context
What the role needs to do the work
- Current work
- Reporting period, service population, metric ledger, material movements and open attestations.
- Prior interactions
- Prior packs, board questions, restatements and committed actions.
- Policies and reference
- Risk appetite, impact tolerances, committee mandate and metric definitions.
- Working method
- Population reconciliation, attestation, narrative and restatement rules.
Illustrative workflow
How the work moves
Starting point
Quarter-end board risk pack closes after a material vendor outage.
- 01
Reconcile important services, critical relationships, concentrations, tests, incidents and actions.
- 02
Commission source attestations and investigate appetite breaches and metric changes.
- 03
Draft a cited narrative and route it through CRO, legal and the resilience committee.
Result
A board pack with one concentration breach, one service outside tolerance and accountable actions.
Checks and boundaries
What must be tested or reviewed
- 01Reports services without a current scenario test as evidence gaps, not zero failures.
- 02Separates incident frequency from customer impact and time outside tolerance.
- 03Restates a metric visibly when the important-service population changes.
Human authority
- Service and risk owners attest metrics
- CRO and legal approve board or external narrative
Keep exploring