Skip to main content
Dark green background, "Weak Application Security Can Cost You Millions," 3 slanted images of fingers pointing to digital locks, and a "Learn the Basics" button
Category: Business Continuity & Resilience

Critical Function

Also known as: Critical Business Function, Mission Critical Function
Simply put

A critical function is a service, process, or task that an organization must keep running because interrupting it would seriously harm its operations or its mission. These functions are identified so they can be prioritized and protected when a disruption occurs. What counts as critical depends on the organization's context and objectives.

Formal definition

A critical function is a specific service, procedure, task, or decision deemed essential to sustaining an organization's mission or operations, such that it must continue without interruption, or be restored within defined timeframes, following a disruption. In resilience and continuity practice, critical functions are typically identified and prioritized through criticality analysis or functional decomposition, which maps functions and supporting components to mission outcomes and evaluates the impact of their loss. The threshold and scope of criticality are context-dependent, varying by organization, sector, and objectives; in certain regulatory contexts, such as the FSB's guidance on identifying critical functions, the term also extends to functions whose discontinuation could disrupt the broader economy or financial system. This definition addresses the general concept and does not resolve jurisdiction-specific or sector-specific criteria, which should be verified against the applicable framework or authority.

Why it matters

Identifying critical functions is foundational to operational resilience and business continuity planning because not every process an organization performs carries equal consequence if disrupted. By determining which services, procedures, tasks, or decisions are essential to sustaining the mission, an organization can prioritize where to concentrate protective measures, recovery resources, and management attention when a disruption occurs. Without this prioritization, response efforts risk being spread indiscriminately across activities of varying importance, potentially leaving the functions whose loss would cause the most serious harm inadequately protected.

The concept also carries weight beyond the boundaries of a single organization in certain regulatory contexts. The Financial Stability Board's 2013 guidance on identifying critical functions, for example, addresses functions that firms provide to the real economy, reflecting a concern that the discontinuation of some functions could disrupt the broader economy or financial system, not merely the firm performing them. This wider framing illustrates that criticality can be assessed against different objectives, from an individual entity's mission to systemic stability, and that the applicable threshold depends on the framework or authority in question.

Because what counts as critical is context-dependent, varying by organization, sector, and objectives, the exercise of defining critical functions is itself a governance and risk-management judgment rather than a fixed determination. Organizations that do not periodically revisit these determinations may find that functions once considered peripheral have become essential, or that recovery timeframes no longer reflect operational reality.

Who it's relevant to

Business Continuity and Resilience Professionals
Those responsible for continuity and operational resilience rely on the identification of critical functions to prioritize protective measures and set recovery timeframes. Criticality analysis and functional decomposition give them a structured basis for deciding which services must continue without interruption and which can be restored within defined windows after a disruption.
Risk Managers
Risk managers use critical function determinations to focus assessment and treatment efforts on the processes whose loss would most seriously harm operations or the mission. Because criticality is context-dependent, they play a role in ensuring these determinations reflect the organization's current objectives and are revisited as circumstances change.
Governance Bodies and Senior Management
Because designating a function as critical is ultimately a judgment about what is essential to the organization's mission, senior management and governance bodies have an interest in overseeing how these determinations are made, prioritized, and resourced. This oversight is part of directing and controlling how the organization prepares for and responds to disruption.
Compliance Officers in Regulated Sectors
In sectors where authorities set criteria for criticality, such as financial services, where the FSB's guidance addresses functions provided to the real economy, compliance officers must ensure that the organization's identification of critical functions aligns with applicable regulatory expectations. The specific criteria should be verified against the relevant framework or authority, as they vary by jurisdiction and sector.

Inside Critical Function

Function or Service Definition
A critical function is typically an activity, service, or operation whose disruption could materially affect the organization, its customers, the market, or, in some sectors, broader financial or operational stability. The precise scope of what counts as 'critical' is usually determined by the organization against defined criteria rather than being universally fixed.
Criticality Criteria
The basis for designating a function as critical, which often includes factors such as the potential impact of disruption, the availability of substitutes, interdependencies with other functions, and, in regulated sectors, the effect on customers or markets. These criteria vary by jurisdiction, sector, and organization size.
Impact and Interdependency Assessment
An evaluation of how the loss or degradation of the function would affect objectives, connected processes, and third parties. This commonly draws on business impact analysis and mapping of dependencies, including supporting people, processes, technology, and suppliers.
Tolerances and Objectives
Parameters such as acceptable disruption thresholds or recovery expectations that are often associated with critical functions in operational resilience and business continuity contexts. The specific terminology and thresholds depend on the applicable framework or regulatory regime.
Regulatory and Framework Context
In certain sectors, notably financial services, the concept of critical or important functions appears within recovery, resolution, and operational resilience regimes. The exact meaning, obligations, and terminology differ across jurisdictions and frameworks, and specifics should be verified against the applicable primary source.

Common questions

Answers to the questions practitioners most commonly ask about Critical Function.

Is a critical function the same as any important business activity?
Not necessarily. While the terms are sometimes used loosely, a critical function typically refers to an activity whose disruption would have a significant impact on the organization, its stakeholders, or, in some regulated sectors, on the broader market or financial system. Many activities are important to daily operations without meeting the threshold of criticality. The distinction usually depends on the impact and tolerance criteria an organization or its regulator has defined, so what counts as critical varies by context and should be assessed against those criteria rather than assumed.
Does designating a function as critical guarantee it will keep running during a disruption?
No. Identifying a function as critical is an analytical and prioritization step; it does not by itself ensure continuity. Designation typically informs where an organization concentrates resilience measures, controls, and recovery planning, but no control or plan eliminates the possibility of disruption. Whether a critical function actually continues depends on the effectiveness of the associated arrangements, testing, and the nature of the event, and residual risk generally remains even after treatment.
How do organizations typically identify which functions are critical?
A common approach involves assessing the potential impact of a function's disruption against defined criteria, often through methods such as a business impact analysis. Factors frequently considered include the severity and speed of harm to stakeholders, financial and operational consequences, legal or regulatory implications, and interdependencies with other functions. In some regulated sectors, supervisory expectations or specific criteria may shape which functions must be treated as critical. The precise method and thresholds vary by organization, sector, and applicable requirements.
Who is usually responsible for designating and overseeing critical functions?
Responsibility is often shared across governance and management layers. Senior management and, in many organizations, the board or a designated committee typically approve the criteria and the resulting designations, consistent with their role in directing and controlling the organization. Operational and risk or continuity functions frequently perform the underlying analysis and maintain the supporting arrangements. The specific allocation of roles and decision rights depends on the organization's governance structure and any applicable regulatory expectations.
How should critical functions be documented and kept current?
Organizations commonly maintain records that identify each critical function, its supporting resources and dependencies, and the rationale for its designation. Because business models, systems, and third-party relationships change, such designations are typically reviewed on a periodic basis and after significant changes or events. Keeping documentation current helps ensure that resilience and recovery planning continues to reflect the functions that actually matter most. The appropriate frequency and depth of review depend on the organization's context and any relevant requirements.
How do critical functions relate to risk management and continuity planning?
Identifying critical functions often serves as an input to broader risk management and business continuity or operational resilience activities. Once critical functions are known, organizations typically assess the risks that could disrupt them, evaluate existing controls, and plan recovery and continuity arrangements accordingly. This links the concept across pillars: it supports risk assessment and treatment, informs governance-level prioritization, and, where continuity relates to regulatory expectations, may touch compliance. The specific integration approach varies by framework and organization.

Common misconceptions

A critical function is the same as a high-risk function.
Criticality reflects the consequence of disruption to the function itself, whereas risk concerns the likelihood and effect of potential events. A function may be critical yet well-controlled with low residual risk, and a high-risk activity is not necessarily critical. The two concepts inform each other but are distinct.
The list of critical functions is defined uniformly by regulation and is fixed once set.
Designation typically depends on organization-specific criteria and context, and applicability varies by jurisdiction, sector, and size. What qualifies as critical often changes as the business, its dependencies, and the external environment evolve, so the designation generally requires periodic review.
Identifying critical functions and putting continuity plans in place guarantees the function will not fail.
Controls, continuity arrangements, and resilience measures modify risk but do not eliminate it or guarantee an outcome. Identification supports preparedness and prioritization, yet residual risk of disruption typically remains.

Best practices

Establish documented, agreed criteria for what makes a function critical, and apply them consistently rather than relying on ad hoc judgment.
Map each critical function to its supporting people, processes, technology, and third-party dependencies to reveal interdependencies and potential single points of failure.
Distinguish criticality assessments from risk assessments, using each to inform the other while keeping the concepts separate in analysis and reporting.
Review and revalidate critical function designations periodically and after significant organizational, technological, or regulatory change.
Where operating in a regulated sector, verify the applicable definitions, terminology, and obligations against the relevant primary regulatory source and seek professional advice on jurisdiction-specific interpretation.
Communicate criticality designations to relevant governance, risk, and continuity stakeholders so that resource prioritization and resilience planning reflect a shared understanding.
Application Security Isn’t Optional Anymore.