Organizational resilience is more than business continuity
Many organizations already believe they are resilient because they have business continuity plans, disaster recovery procedures, insurance coverage, and crisis communication templates. These items are important, but they do not automatically create resilience. A plan that has not been tested under realistic conditions may fail when it is needed. A recovery time objective that was never aligned to business impact may create false confidence. A supplier continuity questionnaire may not reveal whether a critical third party can perform during a regional disruption. A crisis management team may exist on paper but lack the authority or information needed to make timely decisions. Even insurance policies can fail when management has not taken sufficient steps to ensure resilience.
The IIA Topical Requirement for Organizational Resilience pushes internal audit to evaluate resilience more holistically. The guide asks whether resilience is governed, risk-assessed, controlled, tested, and whether management is committed to improvement. Resilience is not owned by one department. It cuts across operations, technology, finance, legal, compliance, human resources, procurement, communications, and executive leadership.
Organizational disruption has become more interconnected. For example, a cyberattack can lead to an operational outage. An operational outage can become a customer service issue. A customer service issue can become a regulatory or reputational problem. A third-party failure can affect financial reporting, customer commitments, product delivery, and compliance obligations at the same time.
When resilience fails, it is usually because the organization did not understand its critical dependencies, did not escalate information quickly enough, did not test realistic scenarios, or did not assign clear ownership for decisions that had to be made under pressure.
Governance: Resilience must be owned before the crisis
The first area organizations should focus on is governance. Effective resilience starts with defining who is responsible for setting expectations, approving priorities, monitoring readiness, and responding when disruption occurs. Boards and senior leaders do not need to manage every operational detail, but they do need visibility into the organization’s most critical services, the risks that could disrupt them, and the level of disruption the organization is willing or able to tolerate.
Many organizations will find that resilience governance is fragmented. Business continuity may sit in operations. Disaster recovery may sit in IT. Third-party risk may sit in procurement or compliance. Cyber resilience may sit with the CISO. Crisis communications may sit with legal or public relations. Enterprise risk management may maintain a risk register, but that register may not connect directly to operational recovery capability.
Each function may be doing reasonable work within its own lane, but no one may be looking across the full resilience picture. Internal audit can add value by testing whether governance structures connect these efforts. The IIA Topical Requirement for Organizational Resilience also emphasizes the need for a formal organizational strategy that addresses a unified approach to resilience.
Resilience reporting should be presented in risk terms to help leadership understand where the organization is prepared, where it remains exposed, and where residual risk exceeds appetite. Reporting should connect resilience objectives to critical business activities, known vulnerabilities, unresolved remediation items, testing results, resource needs, and emerging threats. A board does not need every operational detail, but it does need a clear view of whether management’s resilience capability matches the organization’s risk profile.
Internal audit should evaluate whether the board receives enough information to provide effective oversight. A mature organization should be able to explain which services are most critical, which dependencies support those services, how recovery capabilities have been tested, what gaps remain, and what decisions require board or executive attention.
Risk management: Resilience depends on understanding what matters most
Organizational resilience depends on understanding what must be protected, what can fail, and how failure would affect the organization’s objectives. Risk management’s traditional assessments may not go far enough because they often evaluate risks by category rather than by operational dependency.
A resilience-focused assessment should identify critical business services, supporting processes, technology platforms, data flows, facilities, people, suppliers, and regulatory obligations. It is not enough to know that a system is important. The organization must understand what service relies on that system, what upstream and downstream processes are affected, what manual alternatives exist, and how long the business can operate without it.
Internal audit should expect challenges in this area because dependency mapping is difficult. Many organizations do not have a complete view of how processes, systems, data, and third parties connect. Documentation may be outdated. Business owners may understand their own workflows but not the technology or suppliers that support them. IT may understand infrastructure but not the business impact of downtime. Procurement may maintain contracts but not operational recovery details.
Internal audit can help by assessing whether resilience risks are periodically identified, assessed, managed, and mapped to strategic objectives. The organization should be able to show how resilience risks are evaluated across operations, technology, supply chain, facilities, human resources, finance, legal, compliance, and other relevant areas. The process should also include clear accountability for monitoring risk levels and escalating issues when risk exceeds tolerance.
Control processes must be operationally credible
The next area is control processes. Resilience controls include the policies, procedures, systems, tests, monitoring activities, and corrective actions that allow the organization to prepare for and respond to disruption. These controls may include business continuity plans, disaster recovery plans, backup processes, incident response procedures, crisis management protocols, emergency communication tools, supplier contingency plans, manual workaround procedures, training programs, and post-incident review processes.
The challenge for internal audit is to evaluate whether these controls are operationally credible. A control should not be considered effective simply because a document exists. Internal audit should assess whether plans are current, approved, accessible, aligned to business impact analyses, and tested. Testing should go beyond tabletop conversations that confirm everyone knows the plan. Mature organizations test decision-making, handoffs, data recovery, alternate processing, communication channels, and third-party dependencies through live simulation. They also track issues identified during exercises and confirm that corrective actions are completed.