8.7 Important Business Services and Impact Tolerances
An important business service is a service to outside clients whose disruption could cause intolerable harm. Its impact tolerance is the longest disruption that is acceptable, measured in time. Systems coming back is not the end of the problem, because a backlog keeps clients waiting after that. So the recovery time must be much shorter than the tolerance.
Why it matters: The clock runs until clients are served again, not until the systems restart.
Summary: An important business service is a service to outside clients whose disruption could cause intolerable harm, and its impact tolerance is the maximum tolerable disruption, measured in time. Because backlogs keep clients waiting after systems return, the recovery time must be far shorter than the tolerance.
- Name services from the client’s side (“make payments”), never as systems or departments.
- Worked example: with arrivals of 2,000 an hour and capacity of 2,500, total disruption is five times the outage, so a 24-hour tolerance allows only a 4.8-hour outage.
- Surge capacity is the other lever: at 3,000 an hour the survivable outage rises to 8 hours.
- Set tolerances from the harm analysis, not from what the firm can already achieve.
- Knight Capital lost more than $460 million in about 45 minutes: for trading services the tolerance is minutes.

An important business service is a service to an outside client or market participant whose disruption could cause intolerable harm or threaten the firm’s soundness or market stability, named from the outside in: “make payments for clients”, not “the payments engine”. An impact tolerance is “the maximum tolerable level of disruption to an important business service, as measured by a length of time” (FCA Glossary). Firms must stay within it “in the event of a severe but plausible disruption” (SYSC 15A.2.9R), tested across scenarios “of varying nature, severity and duration” (SYSC 15A.5.4R). Risk appetite limits how likely a failure is; an impact tolerance assumes it has happened and limits how long clients feel it.
Illustrative: client payments, tolerance 24 hours. Payments arrive at 2,000 an hour; after recovery the system clears 2,500 an hour, so the queue shrinks by 500 an hour. An outage of t hours queues 2,000t payments, which take 2,000t ÷ 500 = 4t hours to clear: total disruption t + 4t = 5t.
| Outage | Backlog | Hours to clear | Total disruption |
|---|---|---|---|
| 4 hours | 8,000 | 16 | 20 hours: within |
| 4.8 hours | 9,600 | 19.2 | 24 hours: at the limit |
| 6 hours | 12,000 | 24 | 30 hours: breached by 6 |
Flip point: 5t = 24, so t = 4.8 hours, a fifth of the tolerance. Surge capacity is the other lever: at 3,000 an hour, disruption is 3t and the longest survivable outage 24 ÷ 3 = 8 hours. Service is restored only when reconciliations (Part 8.3: The Reconciliation Sequence — Why Order Matters) confirm no payment was lost or sent twice.
Autopsy: Knight Capital, August 1, 2012. A technician did not copy new order-routing code to one of eight servers, no second technician reviewed the deployment, and 97 automated error emails before the open were not acted on. In about 45 minutes Knight lost more than $460 million (SEC, 2013; SEC order; Part 5.6: How High-Frequency Trading Actually Captures Its Edge). A software release is a severe but plausible scenario, and for a trading service the tolerance is minutes, so only an automated kill switch keeps the firm inside it.
For each service, maximum outage = tolerance ÷ (1 + arrival rate ÷ spare clearing capacity). If tested recovery is longer, shorten recovery or add surge capacity; never lengthen the tolerance unless the harm analysis supports it. Where clients cannot submit work during the outage, there is no backlog and the outage itself is measured against the tolerance.
Setting the tolerance at what the firm can already achieve. A firm whose tested outage is 6 hours could set a 30-hour tolerance and pass every test while clients waiting beyond 24 hours are harmed. The 30 − 24 = 6-hour gap is a vulnerability to record and fix (SYSC 15A.6.1R).
What is an important business service?
A service to an outside client or market participant, such as making payments or settling trades, whose disruption could cause intolerable harm or threaten the firm’s soundness or market stability. It is named from the client’s view, never as a system or department.
How is an impact tolerance different from a recovery time objective?
An impact tolerance limits how long clients go without a service; a recovery time objective limits how long one system is down. Backlogs keep clients waiting after systems return, so recovery must be far shorter than the tolerance: under a fifth of it in the worked example.
What counts as a severe but plausible scenario?
A disruption extreme enough to stress the service yet credible for the firm: losing a data center or key supplier, a cyber attack, corrupted data, a failed software release. Firms test a range of them and may find that some extremes would breach tolerance.
Important business services are named from the client’s side and each has an impact tolerance measured in time. Backlogs mean total disruption exceeds the outage, so the maximum outage equals the tolerance divided by one plus arrivals over spare capacity, 4.8 hours against a 24-hour tolerance in the worked example.
Six questions on this chapter. Decide on your answer first, then click “Reveal Answer.”
1. Work arrives at 1,000 items an hour, the system clears 1,500 an hour after recovery, and the impact tolerance is 12 hours. What is the longest outage that keeps total disruption within tolerance?
- 8 hours
- 6 hours
- 12 hours
- 4 hours
Reveal Answer
Answer: D. Maximum outage = tolerance ÷ (1 + arrivals ÷ spare capacity) = 12 ÷ (1 + 1,000 ÷ 500) = 12 ÷ 3 = 4 hours.
2. Which of these is correctly named as an important business service?
- Making payments for clients
- The firm’s main data center
- The core banking platform
- The payments operations team
Reveal Answer
Answer: A. Important business services are defined from the client’s side; systems, sites and departments are resources mapped behind them.
3. A firm’s tested outage for a service is 6 hours and its harm analysis points to 24 hours. Which response matches the rules?
- Raise the tolerance to 30 hours so the test passes
- Keep 24 hours and log the gap as a vulnerability to fix
- Drop the service from the important business services list
- Replace the tolerance with the system’s recovery time objective
Reveal Answer
Answer: B. The tolerance comes from the point of intolerable harm; a failure to meet it is a vulnerability to record and fix under the self-assessment rules.
4. What does the Knight Capital loss of August 2012 teach about impact tolerances for trading services?
- An annual board review of the testing plan would have caught it
- Disaster recovery sites restored within four hours prevent such losses
- Its tolerance is minutes, so automated kill switches matter
- Trading services should carry longer tolerances than payment services
Reveal Answer
Answer: C. Knight lost more than $460 million in about 45 minutes after a faulty deployment; only automated controls act fast enough to keep such a service within tolerance.
5. Worked problem: Arrivals are 2,000 an hour and capacity is 2,500. After a 3-hour outage, how long to clear the backlog and what is the total disruption?
Reveal Answer
Answer: Backlog = 3 × 2,000 = 6,000. Clearing rate = 2,500 − 2,000 = 500 an hour, so 12 hours. Total disruption = 3 + 12 = 15 hours, five times the outage.
6. Worked problem: With a 24-hour impact tolerance, what is the longest outage the service can absorb?
Reveal Answer
Answer: Total = 5 × outage ≤ 24, so the outage may be at most 4.8 hours.
8.8 Bringing It Together — Reconciliation as the Operational Proof of Governance
Governance is only words until it is proven. The Three Lines say who is accountable. The client asset rules say what must be true. Daily reconciliation shows that it is true. Tools like RCSAs, the risk register, key risk indicators, loss events and, in the US, SOX 404 connect each break to the board.
Why it matters: A break on the reconciliation screen is a governance signal that can reach the board.
Summary: Reconciliation is how governance is proven: the Three Lines say who is accountable, client asset rules say what must be true, and daily reconciliation shows it is. RCSAs, the risk register, KRIs, loss events and, in the US, SOX 404 connect each break to the board.
- A worked break log shows 91.1% of open value aged past five days, one red KRI and one reclassified “timing” break.
- A recall not yet received is a receivable, not a recovery, so the loss event stands until the money returns.
- SOX 404(a) requires management’s yearly assessment; 404(b) auditor attestation applies to larger listed companies.
- Experts disagree on using loss history for capital; the EU and UK set the ILM to 1 and the US re-proposal drops it.
- Citi–Revlon: three approvers read the same screen and $894 million went out instead of $7.8 million.

Part 8: Operational Risk Governance & Reconciliation closes a circle opened in Volume II’s Part 9: the Three Lines of Defense say who is accountable, client asset rules say what must be true (Part 8.1: Reconciliation as a Regulatory Control, Not Just Operational Hygiene), reconciliation is how that truth is proven daily, and operational resilience asks whether it survives a shock (Parts 8.6 and 8.7).
In a risk and control self-assessment (RCSA), each business unit periodically rates its risks for likelihood and impact and rates the controls against them. The results feed the risk register, the firm’s single list of risks, owners, controls and actions. KRIs (Part 8.4: STP Rate, Tolerance, and Matching) watch those risks between assessments, and loss events and near misses (Part 8.5: Aged Breaks — The Audit and Risk Flag) test the ratings: a reconciliation rated “effective” that sits behind three write-offs this quarter was rated wrong.
A US broker-dealer’s cash and nostro reconciliation, illustrative report date Friday, November 6, 2026; ages in business days, policy as in Part 8.5: Aged Breaks — The Audit and Risk Flag.
| Break | Age | Amount | Root cause | Outcome |
|---|---|---|---|---|
| B-201 | 1 | $2,450 | Timing (T+1 receipt) | Preparer; clears Monday |
| B-202 | 4 | $18,600 | Data: fee missing from table | Team lead; fee booked |
| B-203 | 7 | $64,000 | Counterparty: coupon unpaid | Head of operations; claim |
| B-204 | 10 | $142,000 | System: payment sent twice | Up one level; red KRI; recall |
| B-206 | 13 | $9,300 | Labeled timing | Reclassified as real discrepancy |
| B-205 | 17 | $740 | Unknown bank charge | Write-off proposed; awaiting approval |
Open value = 2,450 + 18,600 + 64,000 + 142,000 + 9,300 + 740 = $237,090. Aged (over 5 days): 4 of 6 breaks, 64,000 + 142,000 + 9,300 + 740 = $216,040, or 216,040 ÷ 237,090 = 91.1% of value; B-204 alone is 142,000 ÷ 216,040 = 65.7% of it. B-204 is logged now as a $142,000 execution, delivery and process management loss event, because a recall not yet received is a receivable, not a recovery.
In the US the same reconciliations are internal control over financial reporting (ICFR) under Sarbanes-Oxley section 404: management assesses ICFR yearly (404(a)) and, for larger listed companies, the auditor attests (404(b)); smaller reporting companies with revenue under $100 million are exempt only from the attestation. A reconciliation not performed, reviewed or evidenced is a control deficiency. A May 2026 SEC proposal would exempt companies below $2 billion of public float from 404(b).
In Part 8.5: Aged Breaks — The Audit and Risk Flag‘s example, banks with €80 million and €200 million of average losses hold €1.59 billion and €2.08 billion with the ILM, but €1.77 billion each when it is set to 1. For loss history: Federal Reserve economists Curti and Migueis found “past operational losses are informative of future losses, even after controlling for a wide range of financial characteristics” (FEDS, 2023). Against: AFME argues past events are not an accurate predictor, their information value fades after about three years, and history cannot see new risks such as cyber (AFME). Regulators chose simplicity: the EU and UK set the ILM to 1, and the US re-proposal drops it. The evidence that losses predict losses is stronger than the case for any particular formula, so where capital ignores loss history, a firm’s own risk assessment should not.
Treat a reconciliation as evidence of control only if it is complete (every account in scope ran), independent (the external record came from the third party), timely (breaks aged with owners) and reviewed by a second person. If any test fails, the control failed even if no break appeared (Part 8.4: STP Rate, Tolerance, and Matching); report it through the RCSA.
Three approvers reading the same misleading screen. On August 11, 2020, Citibank, as agent on a Revlon loan, meant to pay about $7.8 million of interest. Under its “six-eye” procedure three people approved the payment, all believing that setting only the principal field to an internal account would suppress the principal; Citibank paid out $894 million of principal, about 894 ÷ 7.8 ≈ 115 times the intended amount. Lenders who received roughly $500 million refused to return it; a district court let them keep it in 2021, and Citibank’s claim was restored only on appeal on September 8, 2022 (opinion; Torys). Add an independent check: no payment above the amount due without separate approval.
What is an RCSA in operational risk?
A risk and control self-assessment: a business unit periodically rates its own risks for likelihood and impact and rates the controls against them. Results feed the risk register and are challenged by the second line, by KRIs and by actual loss events and near misses.
How does SOX 404 apply to reconciliations?
Account reconciliations are key controls over financial reporting. Management assesses them yearly under section 404(a), and larger listed companies’ auditors attest under 404(b). A reconciliation that was not performed, reviewed or evidenced is a control deficiency even if the balances were right.
Why is reconciliation called the proof of governance?
Because it turns governance claims into daily evidence. Segregation, accountability and controls stay claims until two independent records are compared and every difference is explained, owned and closed. Aged breaks, write-offs and missed reconciliations are where those gaps show first.
Karvy Stock Broking used clients’ powers of attorney to move their securities into a demat account of its own, never disclosed to the exchanges, and pledged them to lenders. NSE found about ₹2,300 crore of securities of more than 95,000 clients there; SEBI’s interim order of November 22, 2019, stopped it, and in April 2023 SEBI barred Karvy and its promoter for seven years (SEBI order, Dec 2019; Business Standard, 2023). A location record missing one account cannot balance against ownership (Part 8.2: The Six Reconciliation Types).
SEBI then closed the cash route: under its client-fund upstreaming framework (circular of June 8, 2023, in force from July 1, 2023; some clauses were deferred to September 1, 2023, and a revised framework followed on December 12, 2023), brokers pass all client funds to clearing corporations as cash, a lien on fixed deposits or pledged overnight-fund units, so no client money stays with the broker at end of day. Unlike CASS 7’s daily-reconciled trust, India removes the money overnight. The RBI’s April 30, 2024, Guidance Note on operational resilience asks banks and NBFCs for a “tolerance for disruption” for critical operations, the counterpart of impact tolerances.
Reconciliation turns the Three Lines of Defense and client asset rules into daily evidence, connected to the board through RCSAs, the risk register, KRIs, loss events and, in the US, SOX 404. A reconciliation counts as a control only if it is complete, independent, timely and reviewed, and an independent preventive check would have stopped the Citi–Revlon payment.
Six questions on this chapter. Decide on your answer first, then click “Reveal Answer.”
1. A break log shows three open breaks: $10,000 aged 2 days, $50,000 aged 7 days and $40,000 aged 12 days. What share of open value is aged past five business days?
- 90%
- 50%
- 40%
- 60%
Reveal Answer
Answer: A. Aged value = 50,000 + 40,000 = 90,000; open value = 100,000; 90,000 ÷ 100,000 = 90%.
2. Why did Citibank’s “six-eye” approval fail to stop the Revlon payment in 2020?
- The lenders’ systems misreported the amount received
- All three relied on the same screen and the same belief
- The payment bypassed the firm’s maker-checker procedure
- Only one employee approved the payment before release
Reveal Answer
Answer: B. Three people approved it, each believing that setting only the principal field to an internal account suppressed the principal; their checks were not independent.
3. What does section 404(b) of the Sarbanes-Oxley Act require?
- A daily reconciliation of customer reserve bank accounts
- An auditor’s opinion on the fair value of all reported assets
- Management’s own yearly assessment of its internal controls
- An auditor’s attestation on management’s control assessment
Reveal Answer
Answer: D. Section 404(a) requires management’s assessment; 404(b) adds the auditor’s attestation for larger listed companies.
4. How have regulators treated Basel’s internal loss multiplier (ILM)?
- The US applies it fully, while the EU and UK set it to 1
- All major jurisdictions apply the Basel formula as written
- The EU and UK set it to 1, and the US re-proposal removes it
- Only the UK sets it to 1, as part of its 2025 resilience deadline
Reveal Answer
Answer: C. The EU (from 2025) and UK (from 2027) set the ILM to 1, and the March 2026 US re-proposal drops it, so capital rests on the size-based BIC.
5. Worked problem: Open breaks total $3.2m. 40% are older than five days and one KRI is red. How much is aged?
Reveal Answer
Answer: 40% × $3.2m = $1.28m.
6. Worked problem: A $90,000 break is aged and the escalation threshold is $100,000. Does it move up a level, and what if it grows to $110,000?
Reveal Answer
Answer: $90,000 does not; $110,000 does.
- SEC order in the matter of Knight Capital Americas (Oct 2013) — One of eight servers, no second review, 97 emails, over $460 million
- FCA Handbook SYSC 15A.2, 15A.5 and 15A.6 — Remain within tolerance (15A.2.9R), scenario testing (15A.5.4R), third parties (15A.5.5G), self-assessment and six-year retention (15A.6)
- FCA Glossary
- SEC, 2013
- Curti and Migueis, The Information Value of Past Losses in Operational Risk (FEDS, Jan 2023) — Evidence that past losses predict future losses (8.8 Disagree)
- SEC: accelerated filer definitions and Section 404 — 404(a), 404(b) and the $100 million revenue exemption
- RBI (April 2024)
- SEBI (June 8, 2023)
