For Heads-of · Practitioner
Important business service impact-tolerance mapping
A maintained map of where AI systems sit within important business services, with an AI-specific impact tolerance defined for each.
- directive
- operational-resilience
- mapping
- policy
What it does
Extends the organisation's operational resilience mapping and impact-tolerance work to explicitly include AI components, with a defined tolerable duration and severity for AI-specific disruption.
Where it fits
Mitigates ai-not-mapped-to-important-business-services and no-impact-tolerance-for-ai-dependent-services directly.
Risks this mitigates
The risks this control addresses, ranked by effectiveness.
Untested AI failure scenarios
No scenario testing exists for AI-specific disruption modes against the organisation's impact tolerances.
No impact tolerance for AI-dependent services
A business service that depends on an AI system has no defined impact tolerance for AI-specific disruption.
AI not mapped to important business services
AI components embedded in an important business service haven't been identified or mapped, so an AI failure isn't accounted for in the service's impact tolerance.
Framework and clause references
| Framework | Clause | Title |
|---|---|---|
| SS1/21: Operational Resilience | Impact tolerances | Impact tolerances |
| SS1/21: Operational Resilience | Mapping | Mapping |
| SS1/23: Model Risk Management Principles for Banks | Principle 2 | Model risk governance |