Skip to main content
green gradient background, "The Future of Application Security Is Already Here." and a read the report button.
Category: Business Continuity & Resilience

Important Business Service

Also known as: IBS, Important Business Services
Simply put

An important business service is a service that a firm provides to an external user or customer, delivering a specific, identifiable outcome, rather than an internal process or support function. In operational resilience regimes, firms are typically expected to identify these services because disruption to them could cause harm to customers or, in the financial sector, to wider market or financial stability. Identifying them is a starting point for mapping the people, processes, and resources needed to deliver each service and for testing how resilient it is to disruption.

Formal definition

In operational resilience frameworks, an Important Business Service (IBS) is commonly defined as a service delivered by a firm to an identifiable user external to the firm that results in a specific outcome, as distinct from internal processes, support functions, or activities that do not directly serve external clients. Under supervisory approaches such as those referenced by the Bank of England, firms typically identify their IBS as a foundational step in the resilience lifecycle, then map the processes and underlying resources (for example people, technology, facilities, and third parties) required to deliver each service, and assess the risks and vulnerabilities that could prevent delivery. The specific criteria for designating a service as "important", and thresholds such as impact tolerances applied to it, are set by applicable regulatory regimes and vary by jurisdiction and sector; firms should verify the precise definition and obligations against the relevant primary source and regulator guidance. This definition addresses the operational resilience usage of the term and does not cover jurisdiction-specific designation criteria or matters requiring legal interpretation.

Why it matters

The concept of an important business service reframes operational resilience around the outcomes that customers and markets actually depend on, rather than around the internal systems or organizational units a firm happens to have. This shift matters because a firm can suffer a technology outage or a failed process that has little external effect, while a comparatively minor internal disruption can cascade into significant harm if it sits on the delivery path of a service that external users rely on. By identifying important business services first, firms direct their resilience efforts toward what could cause harm to customers or, in the financial sector, to wider market or financial stability.

In supervisory approaches such as those referenced by the Bank of England, identifying important business services is described as the foundation of a firm's resilience journey: it is the starting point for documenting risks that could prevent delivery of those services and for demonstrating to regulators that resilience work is focused on the right priorities. Getting this identification wrong, by scoping too narrowly, mislabeling an internal support function as a customer service, or overlooking a genuinely important service, can undermine everything built on top of it, including mapping, impact tolerance setting, and scenario testing.

Because the specific criteria for designating a service as "important," and any thresholds such as impact tolerances applied to it, are set by applicable regulatory regimes and vary by jurisdiction and sector, firms cannot treat identification as a purely mechanical exercise. It requires judgment about who the external users are, what outcome each service delivers, and what level of disruption would be tolerable, and firms should verify the precise obligations against the relevant primary source and regulator guidance.

Who it's relevant to

Operational resilience and business continuity teams
These teams are typically responsible for identifying important business services, mapping the processes and resources that deliver them, and testing resilience to disruption. The IBS concept defines the scope of their work and helps them focus effort on services whose disruption could harm external users.
Compliance officers and regulatory affairs functions
In regulated sectors, identifying important business services and meeting associated obligations can be a supervisory expectation. Compliance staff need to confirm the precise designation criteria and any thresholds against the relevant regulatory regime, since these vary by jurisdiction and sector and may require legal interpretation.
Risk managers
Once important business services are identified and mapped, risk managers assess the risks and vulnerabilities that could prevent their delivery. The IBS framing helps prioritize risk assessment around outcomes that matter to customers or, in the financial sector, to market and financial stability.
Senior management and boards
Directing and controlling resilience efforts requires leadership to agree on which services are important and to oversee the documentation of the firm's resilience journey. Because identification underpins subsequent mapping and testing, board-level judgment about scope and priorities carries governance significance.
Third-party and technology managers
Because delivery of an important business service often depends on people, technology, facilities, and third parties, those managing supplier relationships and technology infrastructure need to understand which services their resources support and where vulnerabilities in the delivery chain could disrupt an external-facing outcome.

Inside IBS

Service to an external party
An Important Business Service is typically understood as a service delivered by a firm to an end user or client outside the organization, rather than an internal process or function that supports the firm's own operations.
Potential for harm on disruption
The concept centers on the consequences of disruption. A service is often designated 'important' where its interruption could cause intolerable harm to clients or consumers, or pose a risk to market integrity or the stability of the wider financial system, depending on the applicable regulatory context.
Impact tolerance
In many operational resilience regimes, each Important Business Service is associated with an impact tolerance, typically the maximum tolerable level of disruption expressed as a metric such as duration. Note that the precise definition and required metrics vary by jurisdiction and regulator, and specifics should be verified against the primary source.
Underlying resources and dependencies
Delivery of an Important Business Service generally relies on a chain of supporting resources, which may include people, processes, technology, facilities, data, and third-party or intra-group providers. Mapping these dependencies is commonly part of identifying and managing the service.
Board and governance ownership
Identification and oversight of Important Business Services often sits within the governance pillar, with senior management or the board typically responsible for approving the list of services and their impact tolerances, though allocation of responsibility varies by framework and organization.

Common questions

Answers to the questions practitioners most commonly ask about IBS.

Is an important business service the same as a critical IT system or application?
No. An important business service is defined by the service delivered to an external end user or the market, not by the underlying technology that supports it. IT systems, applications, and infrastructure are typically resources or assets that enable a service, but the service itself is framed in terms of an outcome to customers or the wider financial system. Conflating the two is a common error; a single important business service often depends on many systems, and a single system may support several services. The distinction matters because impact tolerances and mapping exercises are generally applied at the service level rather than the asset level.
Does classifying a service as 'important' mean it must never suffer any disruption?
Not in most operational resilience frameworks. Designating a service as important does not imply an expectation of zero disruption; rather, it typically triggers a requirement to identify the point beyond which disruption would cause intolerable harm and to remain within that impact tolerance. The concept generally accepts that some disruption may occur and focuses on the severity, duration, and consequences an organization can absorb without unacceptable harm to clients, the market, or the firm's viability. Framing it as a guarantee of continuous availability misstates the purpose, which is to manage rather than eliminate the effects of disruption.
How does an organization decide which of its services qualify as important business services?
Identification usually rests on assessing the potential harm that disruption to a service would cause, commonly considering impact on clients or end users, on the safety and soundness of the firm, and, in some regulatory contexts, on the integrity or stability of the wider market. Approaches vary by jurisdiction, sector, and organization, so the specific criteria and thresholds should be verified against the applicable regulatory expectations. Governance bodies typically own and periodically review this determination, and the rationale for including or excluding a service is often expected to be documented and defensible.
What is involved in mapping the resources that support an important business service?
Mapping generally means identifying and documenting the people, processes, technology, facilities, data, and third parties that a service relies on to be delivered. The aim is to reveal dependencies, concentrations, and potential points of failure so that vulnerabilities can be assessed against the service's impact tolerance. The depth of mapping expected can vary, and organizations often describe a phased approach that becomes more granular over time. Mapping is typically treated as a living exercise rather than a one-time task, since dependencies change as the organization and its suppliers evolve.
How do impact tolerances relate to important business services?
In many operational resilience frameworks, an impact tolerance expresses the maximum level of disruption to an important business service that an organization considers acceptable, often described in terms of duration and severity of harm. Setting impact tolerances is usually distinct from setting internal recovery time objectives, because the former reflects the outer limit of tolerable harm to end users or the market rather than an internal operational target. Organizations then test whether they can stay within these tolerances under a range of severe but plausible scenarios. The specific metrics and how they are expressed can differ across regimes and should be aligned with applicable requirements.
Who within an organization is typically accountable for important business services?
Accountability commonly sits with senior management and the board or an equivalent governing body, reflecting the governance principle that responsibility for direction and oversight rests at the top. Day-to-day management of a service may be delegated to service or business owners, while risk, compliance, and internal audit functions often provide independent challenge and assurance. Clear allocation of roles and decision rights is generally regarded as important, and some regulatory regimes assign specific individual accountabilities. Exact expectations vary by jurisdiction and sector, so accountability arrangements should be confirmed against the relevant rules and, where needed, appropriate professional advice.

Common misconceptions

An Important Business Service is the same as a critical internal function or process.
The two are frequently conflated but are generally treated as distinct. An Important Business Service is typically framed around the service delivered to an external client or the market, whereas an internal function or process is one of the underlying resources that supports delivery. This distinction can vary by regulatory framework.
Setting an impact tolerance guarantees the service will not be disrupted beyond that point.
An impact tolerance expresses the maximum level of disruption an organization judges tolerable; it is a target and planning benchmark, not a control that eliminates the possibility of exceeding it. Firms typically still need to test their ability to remain within tolerance, and no measure ensures disruption is prevented.
Every important-sounding activity in the firm must be designated an Important Business Service.
Designation typically turns on the potential for harm to clients, market integrity, or financial stability if the service is disrupted, rather than on internal significance alone. Scope, thresholds, and applicability differ by jurisdiction, sector, and firm size, so criteria should be confirmed against the relevant regulatory source.

Best practices

Define each Important Business Service from the perspective of the external end user or client, and document the rationale for why disruption could cause intolerable harm to clients, market integrity, or financial stability.
Map the full chain of supporting resources for each service, including people, processes, technology, facilities, data, and third-party or intra-group dependencies, so that vulnerabilities can be identified.
Set and document an impact tolerance for each service using measurable criteria, and treat it as a benchmark to be tested rather than an assurance that disruption will be prevented.
Verify the identification criteria, required metrics, and any prescribed definitions against the applicable regulator's primary source, recognizing that requirements vary by jurisdiction, sector, and firm size.
Assign clear governance ownership so that senior management or the board approves the list of Important Business Services and their impact tolerances, and periodically reviews them.
Conduct scenario-based testing to assess whether the organization can remain within impact tolerances under plausible severe disruptions, and use the results to prioritize remediation of identified weaknesses.
Application Security Isn’t Optional Anymore.