The structure and the designated list
Does the structure agree with our important business services list?
A bank designates its important business services by customer harm: what customers would lose if the service stopped. That is the list the regulation is built on.
The platform makes a second reading, from the model, not from anyone's list. Nobody tells the model which elements are structurally critical. It asks questions such as: what would cut the most paths into the important business services, and what would hit the rest of the network hardest if it were disrupted?
In Sudo Bank, 42 elements would stress the network more than Cross-border Operations, the lowest-ranked of the twelve important business services, and are not on the list. They include Backup & Disaster Recovery, Encryption & Key Management, Cybersecurity Operations, Cloud Infrastructure, Network Infrastructure, Internal Audit, Identity Management Systems and Legacy Core Banking.
Most of these are resources, not services, so they do not belong on the list. But they carry more structural weight than a service that is on it, and mapping and scenario testing should give them that weight. Where the two readings diverge, the structure shows what the designated list leaves out.
Seen in: Sudo Bank, a synthetic UK retail and commercial bank.
To see it, ask us for a guest login.
A guest login lets you explore the demonstration models yourself.
Ask for a guest loginNext finding
What a service stands on
What does a service stand on, and where will trouble arrive from?
Read
