Board Checklist: Is It Critical?

·

Before accepting the word critical, ask for evidence.

If management cannot answer the questions below, the board has not received a criticality assessment. It has received an adjective.

Critical is not a compliment. It is a claim that failure would cause unacceptable harm—to people, essential services, regulated obligations, core operations, or the organisation’s survival—and that the organisation cannot simply continue as normal. The desired output of the conversation is not “high / medium / low.” It is a decision about resilience objectives, ownership, investment, testing and escalation.

The CRITICAL Test

C — Consequence. Would failure threaten life, essential services, regulated obligations, material assets, trusted data or organisational survival? If the honest answer is inconvenience, reputational irritation, or a missed internal deadline, stop. You are looking at importance, possibly urgency. You are not looking at criticality.

R — Recovery window. How long can the capability be unavailable before the impact becomes unacceptable? Minutes and days are different species. A number with no owner and no test is a wish.

I — Integrity. Could corrupted or manipulated output cause serious decisions or transactions? A system that is “up” while lying can be more dangerous than a system that is down.

T — Tolerance. What level of disruption, data loss or degradation has the board formally accepted? If the board has never accepted a number, management is improvising under the label of policy.

I — Interdependence. Which internal systems, suppliers, people, facilities and identities support it? Criticality lives in the chain, not in the box with the biggest logo.

C — Contingency. Is there a safe, tested workaround? Untested heroics are not a contingency plan. They are a story you tell after the fact.

A — Affected parties. How many customers, employees, markets or authorities could be affected? Scale does not create criticality by itself, but it changes the duty to know.

L — Legal obligations. Could failure trigger mandatory action, reporting or breach of authorisation conditions?

For regulated financial entities, DORA connects critical or important functions to material impairment of authorisation conditions, financial performance, or continuity of services and activities. That is the legal version of the same test: not “do we like this system,” but “what breaks in the licence, the money, or the service if it fails.”

What to Do With the Answers

If the answers are crisp, you have a candidate for different controls: stronger resilience, tested recovery, named escalation, fewer unknown dependencies.

If the answers are fog, do not let the fog wear a red badge. Demote the language until the evidence arrives. An urgent client request can still be handled today. It does not get to borrow the word you will need at 02:13.

Board action: Select one allegedly critical service and request evidence for every line of this checklist.


Relevant Sources

  1. Regulation (EU) 2022/2554 (DORA), Article 3 — EUR-Lex — https://eur-lex.europa.eu/eli/reg/2022/2554/oj
  2. Cybersecurity Incident — NIST CSRC Glossary — https://csrc.nist.gov/glossary/term/cybersecurity_incident
  3. Emergency Preparedness and Response: Getting Started — OSHA — https://www.osha.gov/emergency-preparedness

If you want this checklist used on a live service—not as a slide, as an evidence request—that is a working session I run with boards and GCs. Contact me.