Criticality Assessment

Sets the criticality tier of a single third-party arrangement and ties it to the firm's important business service, recovery time and recovery point objectives, customer impact, regulatory impact, operational substitutability, and concentration considerations. Produces the upstream record that vendor-diligence, contract-gap-review, exit-plan, concentration-risk-review, and dora-register-builder consume. Audience: head of TPRM, head of operational resilience, business owner. Best for: - A new arrangement is being proposed and the firm needs the tier set before kicking off vendor-diligence. - An annual third-party portfolio review where tiers are stale or inconsistently applied. - A DORA preparation cycle that requires a critical-or-important-function flag for every ICT arrangement. - A material change to the service or to the firm's important-business-service map triggers a re-tier. Not the right tool when: - The firm has not yet defined the important business service the arrangement supports (the criticality

anotb Updated

File contents

anotb/second-line-financial-services/tree/main/plugins/capability-plugins/third-party-operational-resilience/skills/criticality-assessment commit c187c96949

Frequently asked questions

npx skillmds@latest add anotb/criticality-assessment