A payments platform goes down for six hours. Two people get paged.

The first asks: did we recover inside the recovery time objective? The second asks: at what hour did customers start getting hurt, and did we stay under that line? Same outage, same war room. Two different questions, and in most banks now, two different jobs with different reporting lines, different audiences and different ceilings.

If you work in business continuity, you've probably noticed the resilience postings multiplying and wondered whether they're your job with a new title. Partly. Here's where the two actually split, which one the market is building senior seats around, and what a hiring panel checks when a continuity professional applies for a resilience role.

Where The Split Came From

Regulators changed the question. Business continuity has long had its own standards: ISO 22301 for continuity management systems, and in the US the FFIEC's Business Continuity Management booklet (2019). Those frameworks ask whether you've planned and exercised your recovery.

From 2020 onward, supervisors started asking something harder.

UK: the PRA (SS1/21) and FCA (PS21/3), both March 2021, required firms to identify their important business services, set an impact tolerance for each, and map and test them against severe but plausible scenarios. Rules applied from 31 March 2022, and firms had until 31 March 2025 to be able to stay within tolerance.

US: the Fed, OCC and FDIC published Sound Practices to Strengthen Operational Resilience in October 2020 (the Fed's SR 20-24).

Global and EU: the Basel Committee issued its Principles for Operational Resilience in March 2021, and the EU's Digital Operational Resilience Act (DORA) has applied since 17 January 2025.

Canada: OSFI's final Guideline E-21, Operational Risk Management and Resilience, was published in August 2024, with full adherence expected by 1 September 2026. That deadline has just passed, so Canadian banks and insurers are hiring for it right now.

Notice what E-21 does: business continuity appears inside it, as one of the capabilities that support resilience. The regulator itself places continuity under the resilience umbrella. That's the whole career question in one sentence.

The Side-By-Side

What you analyse. Continuity works system by system, site by site, process by process. Resilience starts from the service a customer or market actually receives, then traces everything that service depends on: people, technology, facilities, data and third parties.

What you measure. Continuity sets recovery time and recovery point objectives, usually driven by a business impact analysis. Resilience sets an impact tolerance: the point at which disruption would cause intolerable harm to customers or market integrity. One is about getting a system back. The other is about harm to someone outside the building.

What you assume. Continuity plans for disruption scenarios. Resilience assumes disruption will happen and asks whether you stay inside tolerance when it does, including under severe scenarios that the plan was never written for.

Who signs off. Continuity plans are typically owned by business and technology owners. Under the UK regime, the board approves important business services, impact tolerances and the firm's self-assessment. That changes who you present to.

What third parties look like. In continuity, usually a vendor questionnaire and a contract clause. In resilience, an actual dependency on the map, including the vendor's own suppliers, and a scenario where that vendor fails.

What a good year looks like. Continuity: plans current, exercises completed, recovery met. Resilience: a test that found something uncomfortable, and evidence it got fixed.

Which One Pays More

You'll find confident salary numbers for both online. We haven't found a reliable public source that splits pay cleanly between the two, so we won't quote one. Titles overlap too much, and the same work carries different titles at different banks.

What we can say is how the money is decided, because that's structural. Pay follows three things: whose budget funds the seat, which line of defense it sits in, and how senior the audience is. Resilience seats more often report into operational risk or the COO's office and produce material that goes to the board. Continuity seats more often sit in operations or technology and report to the owners of the systems they recover. The seat with the more senior audience tends to carry the more senior title band.

That also means a resilience role in the first line and one in the second line can pay differently for similar work, because pay and promotion are funded and decided differently in each line. Ask which line the seat is in before you compare offers.

Where Each Seat Sits, And Why The Panel Changes

Resilience roles land in at least four places: inside operational risk, inside business continuity (often renamed), inside technology risk, or as a standalone team reporting to the COO. Internal audit then reviews all of it.

Where the seat sits decides what the panel weighs most. Inside operational risk, they'll test how you aggregate and report risk and how you challenge the business's own assessment. Inside technology risk, they'll push on infrastructure and vendor dependencies. Reporting to the COO, they'll test whether you can turn a dependency finding into a decision an executive can act on.

In second line resilience seats, one skill carries more weight than people expect: holding a tolerance when the business wants a softer number. That's effective challenge, the skill that separates a Manager from a Director, applied to a service map.

What A Panel Probes When A Continuity Pro Applies

From the hiring side, resilience panels have now seen a lot of continuity resumes with the title changed. They've learned three questions that separate the two quickly.

1. "Walk me through one service you mapped end to end. What did you find that wasn't in the business impact analysis?" They want the dependency nobody had documented: a shared database two services both relied on, a vendor's own cloud provider, a single team that was the only one who knew a manual workaround.

2. "How was the tolerance set, and who pushed back?" A tolerance nobody argued about usually wasn't tested hard. They want to hear the negotiation and how you held or moved the number.

3. "Tell me about a scenario test that went badly." A program where every test passed reads as a program that tested easy scenarios. Name the breach, what it exposed and what changed.

Candidates who can only describe the framework in textbook order (services, tolerances, mapping, testing, governance) are describing the paperwork layer, which panels assume you can learn. It's a good example of what an interview panel is actually scoring: evidence you did the hard part, not that you know its name.

Making The Move From Continuity To Resilience

Rewrite the record around services, not plans. Here's an illustration. "Maintained business continuity plans for 30 business units" describes volume. "Mapped the retail payments service end to end and found an undocumented dependency on a single vendor data centre, which went into the scenario test plan" describes resilience. Same person, same job, different read. Generic volume lines are exactly what the hiring panel sees when your resume lands and skims past.

Build one mapping example before you apply. If your employer doesn't have a formal resilience program, pick one service your team supports and map it yourself: who, what systems, what data, which vendors, and what happens if each fails. One real example, with one surprise in it, beats any certificate.

Learn the regulator's words for your market. UK: important business services and impact tolerances. Canada: E-21's critical operations and tolerances for disruption. EU: DORA's ICT risk and third-party register. US: the 2020 sound practices. Using the right terms tells the panel you've read the source, not a vendor's summary.

Keep confidential details confidential. You don't need to name the system or the vendor to show the finding. How to show impact when your work is confidential covers how to keep the substance and lose the specifics.

Who Else Is Competing For These Seats

Continuity professionals aren't the only applicants. Operational risk people who've investigated real incidents bring the dependency-tracing habit. Technology and IT disaster recovery people bring the infrastructure map but often need to learn to talk about harm to customers instead of recovery times. Program managers who've coordinated work across teams that didn't report to them bring the coordination the job depends on.

Internal auditors who've audited a resilience program see these frameworks from the outside and often move across well. It's also a strong way to build Director evidence inside audit, which is why it shows up in what actually gets an internal auditor promoted to Director. Each background has to tell a slightly different story, and the reframing mistakes are similar to the ones in the risk-to-compliance and audit-to-compliance pivot playbook: leading with the old function instead of the new job.

When Staying In Continuity Is The Right Call

This isn't "continuity is dying." Every framework above still requires business continuity and crisis management. E-21 names them explicitly, and someone still has to make recovery actually work at 3 a.m. Specialists who run crisis response well are hard to find.

The question is where you want your ceiling. If you want to lead the function that reports to the board on whether the institution can stay inside tolerance, that seat is increasingly titled resilience. If you want to be the person who makes recovery happen, continuity is a real career. Choose it on purpose rather than drifting into whichever title your current team uses.

Continuity asks how fast you get it back. Resilience asks how much harm you can tolerate before you do.

What To Take From This

  • Business continuity measures recovery of systems and processes. Operational resilience measures harm to customers and markets, per important business service, against a board-approved tolerance.
  • The regulators drove the split: PRA SS1/21 and FCA PS21/3 (UK), the 2020 US interagency sound practices, Basel's 2021 principles, DORA (EU) and OSFI E-21 (Canada, full adherence by 1 September 2026).
  • Pay follows the seat's line of defense, budget and audience. Resilience seats more often face the board, which is why they tend to carry the senior titles.
  • Panels test three things: a service you mapped end to end, a tolerance someone pushed back on, and a test that went badly. Build one real example before you apply.

Questions People Actually Ask

What is the difference between operational resilience and business continuity?

Business continuity plans how systems and processes recover, usually against recovery time objectives. Operational resilience starts from the services customers and markets rely on and tests whether the firm can stay within a tolerance for harm during severe but plausible disruption.

Is business continuity part of operational resilience?

In most current frameworks, yes. OSFI's Guideline E-21, for example, includes business continuity and crisis management as capabilities that support operational resilience, rather than treating them as a separate discipline.

Can a business continuity manager move into operational resilience?

Yes, and many do. The gap panels probe is end-to-end service mapping, setting impact tolerances under challenge and scenario testing that finds real problems. One concrete example of each makes the move far easier.

Does operational resilience pay more than business continuity?

There's no reliable public data splitting the two cleanly. Pay follows the seat: which line of defense it sits in, whose budget funds it and how senior the audience is. Resilience roles more often report to the board, which tends to carry more senior titles.

Do I need a certification to get an operational resilience job?

It helps as a signal that you know the vocabulary, but it works as a tiebreaker. A candidate with one real mapping and testing story consistently beats a certified candidate who can only describe the framework.