Skip to main content
Category: Business Continuity

Severe but Plausible Scenario

Also known as: Severe but Plausible Disruption Scenario, Severe but Plausible Event
Simply put

A severe but plausible scenario is a serious but realistic disruption that an organisation uses to test whether it can keep delivering its most important services. The idea is to imagine an event that is demanding enough to stretch the organisation's defences, yet still credible rather than far-fetched. Firms use these scenarios to check whether they can stay within acceptable limits on the harm a disruption could cause.

Formal definition

In operational resilience practice, a severe but plausible scenario is a hypothesised disruption, calibrated to be both credible and materially stressful, used in scenario testing to assess an organisation's ability to remain within its impact tolerances for important business services. The 'severe' dimension requires the scenario to test resilience arrangements meaningfully, while the 'plausible' dimension constrains it to disruptions that could realistically occur, distinguishing it from purely extreme or theoretical worst-case events. Such scenarios are typically applied within regulatory operational resilience regimes, for example, as reflected in UK Financial Conduct Authority guidance, to evaluate recovery plans and identify vulnerabilities; specific requirements, calibration methods, and applicability vary by jurisdiction, sector, and firm. This entry does not cover implementation specifics, scenario construction methodologies, or the setting of impact tolerances themselves.

Why it matters

Operational resilience regimes increasingly ask organisations not merely to plan for disruption in the abstract, but to demonstrate, through testing, that they can continue delivering their most important services when something goes seriously wrong. Severe but plausible scenarios are the mechanism through which this demonstration occurs. Without a credible yet demanding scenario against which to test, a firm's recovery arrangements may look robust on paper while remaining unproven in practice. The 'severe but plausible' calibration matters because it forces a genuine stress on resilience arrangements without collapsing into implausible worst-case events that offer little practical learning.

For firms operating within regulatory operational resilience frameworks, such as those reflected in UK Financial Conduct Authority guidance, exercising and testing recovery plans against these scenarios is treated as a fundamental part of understanding whether the organisation can remain within its impact tolerances for important business services. The scenario is the bridge between a theoretical tolerance and evidence that the tolerance can actually be met. Where testing reveals that a firm cannot stay within tolerance, it surfaces vulnerabilities that would otherwise remain hidden until a real disruption exposed them.

The practice also supports shared learning across the sector. Collaborative efforts, such as the severe but plausible scenario library compiled by industry working groups, illustrate how firms pool views and experience to inform the scenarios they use. Calibration, applicable requirements, and construction methods nonetheless vary by jurisdiction, sector, and firm, so a scenario appropriate for one organisation is not automatically appropriate for another.

Who it's relevant to

Operational resilience and business continuity teams
These teams design and run scenario tests, selecting or calibrating severe but plausible scenarios that stress important business services and then assessing whether the firm remains within its impact tolerances. The results feed directly into the identification of vulnerabilities and the refinement of recovery arrangements.
Risk managers
Risk professionals use these scenarios to evaluate whether recovery plans hold up under credible but demanding disruption, connecting the testing outcomes to the organisation's broader assessment of operational risk. The scenarios help translate an impact tolerance from a stated limit into tested evidence.
Compliance and regulatory specialists
Within regimes such as those reflected in UK FCA guidance, specialists rely on severe but plausible scenario testing to demonstrate that recovery plans have been exercised and that the firm can remain within tolerance. They should note that specific requirements and applicability vary by jurisdiction, sector, and firm.
Internal auditors and assurance providers
Assurance functions may review whether scenario testing is being conducted appropriately and whether its findings are acted upon. Consistent with the independence of assurance activities, their role is to evaluate the adequacy of the testing process rather than to design or run the scenarios themselves.
Governance bodies and senior management
Boards and executives responsible for oversight of operational resilience use the outcomes of severe but plausible scenario testing to understand whether the organisation can continue delivering important business services under stress, and to direct remediation where tolerances cannot be met.

Inside Severe but Plausible Scenario

Scenario Narrative
A structured description of a hypothetical adverse event or combination of events that is severe in impact yet remains within the realm of possibility, distinguishing it from both routine stress and implausible worst-case fantasy.
Severity Calibration
The dimension defining how damaging the scenario is, typically set toward the tail of the impact distribution to test resilience under significant strain rather than under everyday conditions.
Plausibility Anchor
The reasoning or evidence, such as historical analogues, expert judgment, or causal logic, used to justify that the scenario could credibly occur, keeping it defensible rather than arbitrary.
Assumptions and Drivers
The explicit conditions, triggers, and causal factors assumed within the scenario, which practitioners commonly document so the analysis can be understood, challenged, and updated.
Impact Assessment
The evaluation of consequences across relevant dimensions (for example financial, operational, or reputational), used to test whether the organization's capacity and responses would hold under the modeled stress.
Application Context
The purpose for which the scenario is used, commonly operational resilience testing, stress testing, or risk assessment, which shapes how severity and plausibility are framed.

Common questions

Answers to the questions practitioners most commonly ask about Severe but Plausible Scenario.

Is a severe but plausible scenario the same as a worst-case scenario?
No. A severe but plausible scenario is deliberately bounded by plausibility: it depicts a stress that is serious yet credible given the organization's environment and risk profile. A worst-case scenario, by contrast, may extend to extreme or near-impossible outcomes that strain believability. The plausibility constraint is what makes the scenario useful for planning and decision-making, because management can act on outcomes it accepts as genuinely possible. Removing that constraint tends to produce results that stakeholders discount.
Does labelling a scenario 'severe but plausible' mean it is a prediction of what will happen?
No. Such a scenario is an analytical construct used to test resilience, not a forecast or an assertion of likelihood. It describes a coherent set of conditions that could occur so that the organization can assess how its objectives, controls, and financial or operational position would fare. Treating it as a prediction misreads its purpose; it is intended to explore vulnerability under stress rather than to state what is expected.
How do we set the severity level so a scenario is stressful without becoming implausible?
Severity is commonly calibrated by anchoring to observable references such as historical stress events, conditions experienced by comparable organizations, and the specific exposures in the risk profile, then adjusting to a level that meaningfully challenges the organization. The aim is a scenario that pressures assumptions, controls, and capacity while remaining defensible to informed reviewers. Documenting the rationale and the reference points supports the plausibility judgement and helps stakeholders accept the calibration. Practices for calibration vary across frameworks, jurisdictions, and sectors.
Who should be involved in developing and reviewing these scenarios?
Scenario development typically draws on input from business and operational areas that understand the exposures, from risk management functions that structure and challenge the analysis, and often from subject-matter specialists relevant to the stress being modelled. In many governance arrangements, oversight bodies or senior management review and endorse the scenarios and the assumptions behind them. Independent assurance functions may separately evaluate the process, but their role is to assess rather than to construct the scenarios, preserving the distinction between management and assurance activities.
How often should severe but plausible scenarios be reviewed or refreshed?
Scenarios are commonly revisited on a periodic cycle and also when material changes occur, such as shifts in the risk profile, the operating environment, the strategy, or the external landscape. The intent is to keep the scenarios current so they continue to represent conditions that are both severe and credible; a scenario that no longer reflects present exposures may lose its relevance. Specific review frequencies depend on the organization, its sector, and any applicable regulatory expectations, which vary across jurisdictions.
How should the results of scenario analysis feed into decision-making?
Outputs are typically used to inform judgements about resilience, capacity, and the adequacy of controls and contingency arrangements, and they may highlight vulnerabilities that warrant treatment. Results are commonly reported to management and relevant oversight bodies to support decisions on risk treatment, planning, and resource allocation. Because a scenario explores possible rather than expected conditions, its findings inform rather than dictate decisions, and they do not guarantee outcomes. This entry does not address specific tooling, quantitative modelling techniques, or legal advice.

Common misconceptions

A severe but plausible scenario is the same as a worst-case scenario.
The two differ deliberately. A worst-case scenario may extend to extreme or improbable outcomes, whereas a severe but plausible scenario is constrained by a plausibility anchor, so it is demanding yet remains a credible event the organization could realistically face.
Producing severe but plausible scenarios is primarily a risk management exercise with no governance role.
Scenario design and calibration involve decision rights and oversight. Governance bodies commonly set or challenge the severity and plausibility parameters, while risk management performs the assessment, so the concept can span more than one GRC pillar depending on how an organization assigns responsibilities.
If an organization withstands a severe but plausible scenario, its resilience is assured.
A scenario tests preparedness against a specific modeled set of assumptions; it does not guarantee resilience against events outside those assumptions. Outcomes depend on the quality of the assumptions and drivers, which may not capture every plausible pathway.

Best practices

Document the plausibility anchor explicitly, citing the historical analogues, expert judgment, or causal reasoning that justify why the scenario could credibly occur.
Record all assumptions, triggers, and drivers so the scenario can be reviewed, challenged, and refreshed as conditions change.
Calibrate severity deliberately toward the tail of the impact distribution rather than to everyday conditions, while keeping it distinct from implausible worst-case extremes.
Align the scenario's framing to its intended purpose, whether operational resilience testing, stress testing, or broader risk assessment, since purpose shapes appropriate severity and plausibility.
Subject scenario parameters to appropriate governance oversight or challenge, keeping the roles of those who set parameters and those who perform the assessment clear.
Assess impact across the relevant dimensions and treat the results as indicative of preparedness against the modeled assumptions, not as an assurance of resilience against all possible events.
Promotional banner graphic asking if you are ready for PCI DSS 4.0 with a call-to-action to get the guide