Resilience Assurance: Are You Really Resilient, or Just Checking the Box?
My perspective on readiness and resilience was shaped long before I entered the corporate world.
I came from a military environment where the standards were exceptionally high. You didn’t simply tell someone you were ready. You had to demonstrate it. More importantly, you didn’t prepare for readiness once a year because an inspection was coming. You had to be consistently prepared to respond when called upon.
Anything less wasn’t acceptable.
That mindset has stayed with me throughout more than 20 years of working with organizations on crisis management, business continuity, emergency preparedness, and operational resilience. It has also shaped the way I think about assessments and exercises.
One thing I’ve learned is that there can be a significant difference between believing you are resilient and being able to demonstrate it.
I’ve seen organizations with excellent plans, detailed business impact analyses, impressive dashboards, and carefully documented recovery strategies. On paper, everything looks good. Then we run an exercise, and the assumptions start to unravel.
The person with authority to make a critical decision isn’t available. A recovery strategy depends on a third party that hasn’t been included in the exercise. Two teams interpret the escalation process differently. A workaround that appeared perfectly reasonable on paper takes significantly longer when people actually try to use it. A recovery time reported to leadership for several years turns out never to have been properly tested.
None of this necessarily means that the organization has a bad resilience program. In fact, discovering these issues is precisely what a good resilience program should do.
The problem comes when an organization assesses itself, gives itself a maturity score, and assumes the job is finished.
That is why I believe the next evolution in organizational resilience needs to be about independent assurance.
From Having a Plan to Demonstrating a Capability
For many years, resilience programs have understandably focused on plans, policies and processes. Organizations needed business continuity plans, crisis management plans, disaster recovery plans, emergency response procedures and risk assessments.
Those things remain important. But regulators are increasingly interested in something beyond the existence of documentation: Can the organization actually continue delivering its important services when something goes wrong?
We can see this very clearly in the United Kingdom. Under the FCA’s operational resilience framework, in-scope firms must identify their important business services, set impact tolerances, understand the people, processes, technology, facilities, information, and third parties that support those services, and test whether they can remain within those tolerances during severe but plausible disruption.
Importantly, the requirement doesn’t stop at conducting an exercise. Firms are expected to learn from scenario testing, identify vulnerabilities, make improvements, and test again. FCA guidance specifically says that improvements made following previous testing should themselves trigger further scenario testing.
The FCA’s March 2026 observations reinforce this. It highlighted the importance of documented assumptions, recovery times, workarounds, third-party dependencies, and testing outcomes that boards can understand and challenge. It also pointed to scenario testing and real-world incidents being used to validate impact tolerances, with testing outcomes integrated into remediation and governance reporting.
That is an important distinction. The objective isn’t simply to demonstrate that an exercise took place. The objective is to produce evidence about whether the organization can perform.
Europe Is Moving in the Same Direction
The EU’s Digital Operational Resilience Act (DORA) provides another good example. For covered financial entities, DORA requires a digital operational resilience testing program designed to identify weaknesses, deficiencies, and gaps and to support corrective action.
DORA includes a range of potential testing methods, including vulnerability assessments, physical security reviews, scenario-based testing, performance testing, end-to-end testing and penetration testing. It also requires entities within the scope of those provisions to test ICT systems and applications supporting critical functions at least annually.
One aspect of DORA that I find particularly interesting is its focus on independence. The regulation states that tests should be undertaken by independent parties, whether internal or external, with appropriate measures to avoid conflicts of interest when internal testers are used. It also requires procedures to prioritize, classify, and remediate issues identified through testing and validation to ensure identified weaknesses are addressed.
Again, the direction is clear: assess, test, identify weaknesses, remediate and validate.
Related: Why Manufacturing Companies Can’t Afford to Guess at Resilience
What About the United States?
The U.S. does not have a single operational resilience regulatory framework directly equivalent to the UK’s regime or DORA across all industries. The regulatory landscape is more fragmented and sector-specific.
However, I think it would be a mistake to interpret that as meaning the United States isn’t moving in the same general direction.
Look at financial services.
The Federal Reserve, FDIC, and OCC have issued joint sound practices for strengthening operational resilience at large and complex U.S. banking organizations. They define operational resilience around an organization’s ability to prepare, adapt, withstand, and recover from disruption while continuing to deliver critical operations and core business lines.
Their guidance brings together governance, operational risk, business continuity, third-party risk, cybersecurity, and recovery planning. More importantly for this discussion, it includes practical expectations around testing.
Among the practices identified are:
- Regularly reviewing, testing and updating controls supporting critical operations.
- Incorporating testing, training and awareness into business continuity management.
- Testing business continuity plans and incorporating lessons learned.
- Including third-party dependencies in exercises and, where possible, testing alongside critical third parties.
- Using scenario analysis to understand disruption.
- Having independent internal or external audit provide review and challenge of operational risk management and the organization’s tolerance for disruption. (Federal Reserve)
The Federal Reserve has separately emphasized that more work remains to ensure banks can withstand operational disruptions from all hazards, including severe but plausible cyber incidents. (Federal Reserve)
The FFIEC has also shifted its business continuity guidance toward a broader resilience perspective, emphasizing enterprise-wide approaches covering technology, business operations, testing, and communications rather than treating continuity as simply an IT recovery issue. (FFIEC)
So while the regulatory structures differ, there is a common theme emerging across the U.S., UK and Europe:
Organizations increasingly need to demonstrate resilience, not simply document it.
The Problem With Self-Assessment
I strongly believe in resilience assessments. A well-designed assessment gives an organization a structured way to understand its current capabilities, identify gaps, benchmark maturity, and establish priorities.
But there is an inherent limitation.
Most assessments rely, at least initially, on what the organization says it does. Someone confirms a crisis management process exists. Someone reports that a business continuity plan exists. Someone states that critical suppliers have contingency arrangements. Someone provides a recovery time for an important process.
None of those answers need to be intentionally misleading to be inaccurate.
Organizations naturally develop assumptions about their own capabilities:
- “We have a plan.”
- “We’ve trained the team.”
- “Our supplier has redundancy.”
- “IT can recover the system within four hours.”
- “We can operate manually.”
- “Our executives know what to do.”
- “We’ve tested this before.”
The question I always come back to is: How do we know?
Those statements might all be correct, but until evidence supports them and, where appropriate, they’re tested under realistic conditions, they remain assumptions.
Moving From Assessment to Assurance
This is where I believe independent resilience assurance becomes increasingly important.
A mature assurance approach should connect four things: assessment, evidence, testing, and remediation.
1. Assess the capability
Start by understanding the organization’s current resilience maturity and capabilities. Depending on the organization, this could examine governance, crisis management, business continuity, emergency management, technology resilience, crisis communications, third-party dependencies, training, exercising, and continuous improvement.
An assessment provides the baseline. But it shouldn’t automatically provide the assurance.
2. Validate the evidence
If an organization states that a capability exists, it should have appropriate evidence to support that assertion.
If there is a crisis management plan, review it. If executives receive crisis leadership training, understand what that training involves. If an important service has a four-hour recovery requirement, understand how that number was set and whether the supporting dependencies have been considered. If a critical supplier provides an essential component of the recovery strategy, determine what evidence exists about that supplier’s ability to perform during the same disruption.
This changes the question from “Do you have it?” to “Show me how you know it will work.”
3. Test the capability
This is where exercises become extremely powerful.
A properly designed simulation can remove key people, make technology unavailable, introduce conflicting information, simulate a critical supplier failure, generate media and stakeholder pressure, compress decision-making timelines and force leaders to make decisions with incomplete information.
More importantly, the exercise can be specifically designed around assumptions and vulnerabilities identified during the assessment.
That creates a direct connection between assessment and testing rather than treating them as two unrelated compliance activities.
4. Remediate and retest
Finding the problem isn’t enough.
Organizations need a mechanism to turn findings into improvements, assign owners, set deadlines, and track remediation. Significant weaknesses should then be retested.
The assurance cycle therefore becomes:
Assess → Validate → Test → Identify Gaps → Remediate → Retest → Assure
Then repeat it.
That last point matters because resilience is not a project with an end date. It is a capability that needs continual validation.
Don’t Exercise to Prove Your Plan Works
I’ve said this many times when designing and facilitating exercises: don’t design an exercise to prove your plan works.
Design it to discover where it doesn’t.
The two approaches differ significantly.
If an exercise lets everyone comfortably walk through the existing plan, it can easily become another compliance activity. Everyone attends, everyone talks, the exercise finishes, an After Action Report is produced and the box gets checked.
But what did we actually learn?
A good exercise creates enough pressure, uncertainty and complexity to expose assumptions, dependencies and decision-making challenges that might otherwise remain hidden. That doesn’t mean every exercise needs to be impossibly difficult or designed to make participants fail. It means the scenario needs to provide enough challenge to generate meaningful evidence about capability.
The UK’s regulatory approach is particularly explicit about this. The FCA requires firms to test against severe but plausible scenarios and use those tests to understand vulnerabilities that could prevent them from remaining within their impact tolerances. Its guidance specifically recognizes simulations and live-system testing alongside other testing approaches. (FCA)
Why Independence Matters
Another question organizations should consider is: Who is validating our assessment of ourselves?
Internal teams understand their organizations better than anyone. Their knowledge is invaluable. But familiarity can also create blind spots.
If the same group creates the framework, completes the assessment, interprets the answers, determines the maturity level and ultimately decides whether the organization has achieved the required standard, assumptions may never be sufficiently challenged.
Independent assurance provides another layer of challenge. It can examine the evidence behind an answer, question assumptions, compare stated capability with observed capability and identify inconsistencies between plans, teams and dependencies.
That doesn’t mean an external organization owns resilience. Management remains responsible for building and maintaining the capability.
Independent assurance provides confidence that the capability being reported to leadership reflects reality.
Boards Need More Than a Score
Imagine presenting a resilience dashboard to a board showing that the organization has achieved an 85% maturity score.
My first question would be: What does 85% actually mean?
Does it mean 85% of assessment questions received positive answers? Does it mean 85% of the required documentation exists? Does it mean controls have been independently reviewed? Or does it mean the organization has demonstrated that its critical services can continue through severe disruption?
Those are very different things.
A maturity score can be extremely useful for benchmarking, prioritizing investment and measuring progress. But it becomes much more powerful when supported by evidence and testing.
Instead of telling leadership, “Our crisis management capability is mature,” imagine being able to report that the capability has been independently assessed, supporting evidence reviewed, the leadership team tested through a severe but plausible scenario, vulnerabilities identified, remediation completed and key improvements subsequently retested.
That tells me far more about resilience than a score alone.
Moving From Compliance to Confidence
There will always be compliance requirements. Organizations will continue to need policies, plans, assessments, records and documentation.
But I believe organizations that genuinely take resilience seriously should be asking themselves a different question.
Not simply: “Are we compliant?”
But: “Are we confident this will work when we need it?”
That requires organizations to challenge assumptions, produce evidence, conduct realistic exercises, remediate weaknesses, and accept that discovering problems during testing is a positive outcome.
It may also mean introducing greater independent challenge and assurance into the resilience program.
My military experience taught me something very simple about readiness. You didn’t become ready because an assessment said you were ready. You demonstrated readiness through training, testing, exercising and consistently maintaining the standards expected of you.
Corporate resilience is obviously a very different environment, but I believe the underlying principle still applies.
Readiness has to be demonstrated.
If I were sitting on a board today and being presented with an annual resilience assessment, the question I would keep asking is:
How do we know?
If we’re told that critical services can be recovered within defined tolerances, how do we know? If we’re told the leadership team can manage a major crisis, how do we know? If we’re told critical suppliers can continue supporting us, how do we know? If we’re told our communications, technology recovery and business continuity arrangements are effective, what evidence supports those statements?
The answer shouldn’t simply be, “Because the assessment says so.”
It should be supported by evidence, independent challenge and, wherever possible, meaningful testing.
That’s the difference between checking the box and building genuine confidence in resilience.
I think this version is much closer to your voice and your experience. The military opening also gives us a theme we can carry through the article—readiness has to be demonstrated—rather than making independent assurance sound like another consulting methodology.

Add your first comment to this post