Skip to main content
Category: Business Continuity

Important Business Service

Also known as: IBS, Important Business Services
Simply put

An important business service is a service a firm provides to a customer or user outside the organization that delivers a specific, identifiable outcome. It is distinguished from internal processes or support functions, which serve the firm itself rather than an external user. Firms typically identify these services so they can focus on keeping them running even during disruption.

Formal definition

In the context of operational resilience, an Important Business Service (IBS) is a service that delivers a specific outcome to an identifiable user external to the firm, as opposed to an internal process, support function, or internal activity. Identifying IBS is a foundational step in operational resilience work: firms map the processes and resources required to deliver each IBS in order to test resilience and identify risks that could prevent delivery of the service. The concept is used in operational resilience regimes for the financial sector, and the precise scope, thresholds, and expectations may vary by jurisdiction, regulator, and firm; this entry does not cover implementation specifics such as impact tolerance setting or regulatory reporting requirements.

Why it matters

The concept of an Important Business Service sits at the foundation of operational resilience work in the financial sector. By defining resilience around services delivered to external users rather than around internal systems or organizational units, regulators and firms shift the focus from asset-level continuity toward the outcomes that customers and the wider market actually depend on. This distinction matters because a firm can have healthy internal processes while still failing the people who rely on it if the end-to-end service is disrupted.

Identifying IBS correctly is consequential because it scopes the rest of a firm's resilience programme. Services that are classified as important attract mapping, testing, and resilience measures, so an overly narrow identification risks leaving genuinely critical services unprotected, while an overly broad one can dilute attention and resources. Because the concept is used in operational resilience regimes for the financial sector, the precise scope, thresholds, and expectations may vary by jurisdiction, regulator, and firm, and firms should treat identification as a judgement exercise rather than a mechanical one.

The Bank of England has framed operational resilience work in terms of documenting a firm's resilience journey and identifying the risks that could prevent delivery of important business services. Anchoring resilience to external outcomes helps ensure that internal support functions and activities are assessed for how they contribute to those outcomes, rather than being treated as ends in themselves.

Who it's relevant to

Operational resilience and business continuity teams
These teams own the identification and mapping of Important Business Services, tracing the processes and resources needed to deliver each service so that resilience can be tested and delivery risks surfaced.
Risk managers
Risk professionals use the IBS lens to focus assessment on the services whose disruption would affect external users, identifying and treating risks that could prevent a firm from delivering those services.
Governance and senior management
Those responsible for direction and oversight rely on a clear IBS inventory to make decisions about where resilience investment and attention should be concentrated, since the classification scopes much of the resilience programme.
Compliance and regulatory specialists in financial firms
Because the concept is embedded in operational resilience regimes for the financial sector, compliance staff track how their jurisdiction and regulator expect IBS to be defined and evidenced, recognizing that scope, thresholds, and expectations may differ across regimes and firms.
Internal auditors and assurance functions
Independent assurance providers evaluate whether the firm's identification and mapping of Important Business Services is sound and complete, without themselves owning or performing the underlying management activity.

Inside IBS

Service-Based Definition
An Important Business Service is typically defined as a service that a firm provides to an external end user or participant, rather than an internal function or activity. The focus is on the outcome delivered to clients or the market, not on the underlying processes or systems in isolation.
Materiality and Impact Criteria
Firms commonly identify a service as important where its disruption could cause intolerable harm to clients, pose a risk to market integrity, or threaten the firm's safety and soundness. The specific criteria depend on the applicable regulatory regime and the firm's sector and scale.
Impact Tolerance
For each Important Business Service, firms are often expected to set a maximum tolerable level of disruption, frequently expressed in terms of duration, volume, or other measurable parameters. This defines the boundary beyond which disruption is considered intolerable.
Mapping of Supporting Resources
Delivery of an Important Business Service typically depends on a chain of underlying resources, which may include people, processes, technology, facilities, data, and third-party providers. Mapping these dependencies supports identification of vulnerabilities.
Operational Resilience Linkage
The concept commonly sits within an operational resilience framework, connecting governance oversight, risk identification, scenario testing, and continuity planning. It spans governance and risk management pillars and may carry compliance obligations where a regulator mandates its identification.

Common questions

Answers to the questions practitioners most commonly ask about IBS.

Is an important business service the same as an internal IT system or application?
No. An important business service is defined by the outcome it delivers to external parties, such as customers or the wider market, not by the underlying technology that supports it. IT systems, applications, and infrastructure are resources that enable a service, but they are not themselves the service. Conflating the two is a common error; a single important business service typically depends on multiple systems, people, processes, facilities, and third parties, and one system may support several services.
Does every service or business line an organization runs count as an important business service?
No. The designation is deliberately selective. In many operational resilience frameworks the term is reserved for services whose disruption could cause intolerable harm to clients, threaten the firm's viability, or pose a risk to the stability or integrity of the relevant market or financial system. Services that do not meet such thresholds may still matter to the business but would not typically be classified as important business services. The specific criteria and terminology vary by jurisdiction, regulator, and sector.
How does an organization go about identifying its important business services?
Identification commonly starts from the perspective of the external party receiving the service and considers the potential harm if the service were disrupted. Organizations typically assess candidate services against criteria such as impact on customers, market integrity, and the firm's own safety and soundness. The process often involves input from business, risk, and compliance functions and governance sign-off. The exact methodology and the population of services will differ across firms and jurisdictions, so this describes a general approach rather than a prescribed procedure.
What is the relationship between an important business service and impact tolerance?
In several operational resilience regimes, an impact tolerance is set for each important business service to express the maximum tolerable level or duration of disruption to that service. The important business service is the unit of analysis, and the impact tolerance is the boundary against which resilience is tested and measured. The precise definition, metrics, and expectations for setting impact tolerances vary by regulator and jurisdiction, and this entry does not cover the specific calculation methods.
Who within an organization is typically accountable for important business services?
Accountability commonly sits with senior management and the board or an equivalent governing body, consistent with the governance pillar's focus on decision rights and oversight. Day-to-day management of the service and its supporting resources is generally a first line responsibility, while risk and compliance functions may provide challenge and oversight, and internal audit may provide independent assurance. Specific role allocations depend on the organization's structure and any applicable individual accountability regimes, which differ by jurisdiction.
How do important business services relate to mapping and scenario testing?
Once identified, an important business service is typically mapped to the people, processes, technology, facilities, and third parties that support its delivery, in order to locate vulnerabilities and dependencies. Scenario testing is then commonly used to assess whether the service can remain within its impact tolerance under severe but plausible disruption. The depth of mapping and the design of scenarios vary by organization and regulatory expectation; this entry does not address specific tooling or test design.

Common misconceptions

An Important Business Service is the same as a critical internal process or IT system.
The term is generally oriented toward services delivered to external end users or the market, whereas internal processes and systems are typically treated as supporting resources that enable delivery. Conflating the two can lead firms to map dependencies incorrectly and to set tolerances against the wrong object.
The designation and its associated requirements are universal across all firms and jurisdictions.
Whether a firm must identify Important Business Services, and the criteria used, depend on the applicable regulatory regime, sector, and organization size. The concept is prominent in certain operational resilience regimes and may not apply, or may apply differently, elsewhere. It should not be presented as a global mandatory standard.
Setting an impact tolerance guarantees that disruption will remain within acceptable limits.
An impact tolerance defines the level of disruption a firm considers tolerable; it is a target and boundary for planning and testing, not an assurance that actual disruptions will stay within it. Achieving resilience depends on the effectiveness of supporting controls and continuity arrangements.

Best practices

Distinguish clearly between the Important Business Service delivered to end users and the underlying resources that support it, and document the relationship rather than treating them interchangeably.
Confirm the applicable regulatory expectations for your jurisdiction, sector, and firm size before assuming that identification of Important Business Services or specific criteria apply.
Set and document an impact tolerance for each identified service using measurable parameters, and revisit these tolerances as the business and its dependencies change.
Maintain an up-to-date mapping of the people, processes, technology, facilities, data, and third parties on which each service depends, so that vulnerabilities can be identified.
Test resilience against plausible severe-but-realistic disruption scenarios to assess whether services can be kept within their impact tolerances, and treat gaps as findings for remediation.
Keep management ownership of resilience arrangements distinct from independent assurance over them, so that the effectiveness of controls is reviewed objectively rather than self-assessed.
Promotional banner graphic asking if you are ready for PCI DSS 4.0 with a call-to-action to get the guide