Quarterly ExCo Pack — Operational Resilience, DORA Readiness & Climate Risk Integration
This quarterly Executive Committee cadence pack provides the CEO and executive team with an integrated view of operational resilience, DORA implementation progress, critical third-party dependency risk, and the integration of climate-related financial risks into strategic decision-making. It is designed to meet the expectations set out in PRA/FCA PS6/21 on operational resilience, the DORA regulation (including the final RTS on incident classification), and PRA SS3/19 on managing climate-related financial risks. ExCo is the appropriate forum for these topics on a quarterly rhythm because they cross the boundaries of Technology, Operations, Risk, Finance, and Strategy — no single functional committee can resolve trade-offs on impact tolerances, third-party exit strategies, or transition planning without executive alignment. The pack ties tactical remediation progress to strategic capital and investment decisions, and produces the executive narrative that feeds upward into the quarterly Board Risk Committee cycle. It also ensures the firm can evidence Senior Manager accountability under SMCR for these prescribed responsibilities.
8
Required Materials
6
Key Questions
3
Related Themes
- Operational Resilience Self-Assessment Update
- Important Business Services (IBS) Impact Tolerance Testing Results
- DORA Gap Analysis & Implementation Roadmap
- Critical Third-Party (CTP) Concentration & Substitutability Report
- ICT Incident Register & Classification Summary
- Climate Risk Scenario Analysis Executive Summary
- Transition Plan Progress Report
- Cyber Threat Landscape Executive Briefing
- Can we evidence remaining within impact tolerance for every Important Business Service under severe but plausible scenarios?
- Where are our most acute concentrations on critical ICT third parties, and are exit or substitution strategies genuinely executable?
- Are we on track to meet DORA obligations, and where are the residual gaps against the final RTS on incident classification?
- How are climate scenario results (including the PRA Biennial Exploratory Scenario) informing pricing, credit appetite, and capital planning?
- Is our transition plan credible to investors, regulators, and NGOs, and adequately resourced?
- Do recent cyber incidents — internal or peer — indicate control gaps we should escalate to the Board Risk Committee?