Skip to content
RiskTemplates · The Daily Brief Saturday, July 25, 2026
Wire FinCEN's Student Aid Fraud Alert: The ACH Refund Pattern Banks Need to Tune Now JUL 23

Feature Business Continuity

FFIEC BCM Section III.B Risk Assessment: Turn Threats Into Continuity Strategies

Build an FFIEC BCM Section III.B risk assessment that traces threats, controls, gaps, continuity strategies, tests, and remediation.

Table of Contents

TL;DR

  • The BIA tells you what must recover and by when. The FFIEC BCM Section III.B risk assessment tells you what can break it, where controls are weak, and which continuity strategy is justified.
  • Build a traceable chain: critical service → dependency → threat → control evidence → residual gap → strategy → test → remediation.
  • A heat map is not the deliverable. The useful output is a set of decisions: what to prevent, what to recover, what to work around, what to accept, and what must stop safely.

A continuity risk assessment fails the moment it becomes a list of disasters with red, amber, and green boxes.

The FFIEC business continuity management Section III.B risk assessment is supposed to drive continuity strategy. That means a reviewer should be able to start with a critical service—ACH processing, card authorization, online banking, fraud monitoring—and follow the analysis all the way to a tested recovery decision. If the workbook ends at “cyberattack: high,” it has described anxiety, not managed risk.

The FFIEC Business Continuity Management booklet separates the business impact analysis from the risk assessment for a reason. The BIA establishes impacts and recovery priorities. Section III.B evaluates specific threats, vulnerabilities, and controls. The next step, continuity strategy, should be the consequence of that analysis rather than a menu copied from last year’s plan.

What is the FFIEC BCM Section III.B risk assessment actually for?

Its practical job is to answer five questions:

  1. Which credible threats can disrupt each critical service?
  2. Which people, facilities, technology, data, utilities, and third parties sit in the failure path?
  3. Which preventive or detective controls genuinely reduce the exposure?
  4. What residual gap remains if those controls fail or the event exceeds their design?
  5. Which continuity strategy closes that gap within the BIA’s recovery objective?

That last question is where weak assessments disappear into the BCP. They score a ransomware event as high, list backups as a control, and never determine whether restoration can meet the four-hour RTO. Or they rate a telecom outage moderate because a branch has two circuits, without checking whether both enter through the same conduit.

The FFIEC Section III.B page is the regulatory anchor. For implementation detail, NIST’s Contingency Planning Guide for Federal Information Systems, SP 800-34 Rev. 1 provides a complementary system-contingency process covering BIA, preventive controls, recovery strategies, plan development, testing, and maintenance. NIST is not a substitute for FFIEC examination guidance, but the lifecycle is useful when Technology owns part of the evidence.

Keep the BIA and risk assessment separate—but connected

The fastest way to confuse both artifacts is to ask business owners to score threats while they are still defining impacts.

ArtifactCore questionTypical evidenceOutput
BIAWhat happens if this service is unavailable, regardless of cause?Transaction volumes, customer obligations, cutoff times, financial and legal impacts, dependenciesCriticality, RTO, RPO, maximum tolerable downtime
Risk assessmentWhat could interrupt the service, and how exposed are we?Architecture, facility and utility maps, incidents, vendor evidence, control tests, threat informationInherent risk, control effectiveness, residual gap
Continuity strategyHow will we continue or recover within the approved objective?Capacity analysis, contracts, manual procedures, alternate arrangements, recovery estimatesSelected strategy, owner, funding, activation criteria
Exercise or testDoes the strategy work under realistic conditions?Test script, timestamps, system output, reconciliation, participant observationsActual recovery result, exceptions, remediation

If your BIA needs repair first, use the BIA versus risk assessment guide before combining workshops. One practical aside: business owners usually want to discuss the outage they remember. Let them. Capture that event as evidence, then return to the structured dependency and threat review so one memorable incident does not become the whole assessment.

Build the traceability table before the heat map

A workable register needs enough structure to preserve the decision trail. Start with these fields:

FieldWhat to recordExample entry
Critical serviceBIA service ID and namePAY-01 — ACH origination
Recovery objectiveApproved RTO/RPORTO 4 hours; RPO 30 minutes
DependencySpecific asset or partyCore file generation service; SFTP gateway; operations approver
Threat scenarioEvent plus failure mechanismIdentity provider outage blocks privileged access to file transmission
Inherent exposureImpact and likelihood before controlsHigh impact / possible likelihood
Existing controlPrecise control activityBreak-glass account tested quarterly; credential held in vault
EvidenceRecord and dateIAM-Q2-2026-017; successful test 2026-06-14
Vulnerability or gapWhat still failsBackup approver has not completed production access test
Residual riskRating after evidenced controlsHigh until alternate approver test passes
Strategy decisionAvoid, reduce, transfer, recover, work around, accept, or stop safelyUse break-glass access plus dual-controlled manual release
ValidationHow the strategy will be testedTimed access and file-release exercise; no production payment
Owner and due dateNamed accountable rolePayments Operations Director; 2026-08-15

Notice what is missing: a generic “mitigation” cell containing “BCP.” A plan is not a control merely because it exists. The control is the specific capability—an alternate circuit, immutable backup, manual queue, delegated authority, spare device pool—and the evidence that capability works.

Score controls from evidence, not confidence

Use a simple control scale if it helps consistency:

  • Effective: designed for this failure mode, operating evidence is current, and the observed result met the objective.
  • Partially effective: the control exists but testing found a capacity, timing, access, documentation, or dependency gap.
  • Ineffective: the control failed, has no usable evidence, or does not address the stated threat.
  • Not tested: do not quietly treat this as effective. Carry the uncertainty into residual risk.

These are assessment labels, not universal regulatory ratings. Define them in your methodology and calibrate them against your own exercise records. An anti-gaming check helps: every “effective” rating should map to a test record, production monitoring record, contract commitment, or independently reviewed operating artifact.

Work a threat all the way into a strategy

Realistic hypothetical: a community bank’s wire operations service has a four-hour RTO. Staff work from headquarters, but the wire application is remotely accessible. The assessment identifies a regional power and telecom event.

At first glance, remote access looks like the strategy. The dependency review changes the answer:

  • Headquarters and the designated alternate workspace use different power utilities.
  • Both locations rely on the same identity provider and the same telecom carrier.
  • The backup approver has a laptop but has not authenticated from the alternate workspace.
  • Call-back verification procedures exist only on the headquarters shared drive.
  • The wire platform vendor’s status page is public, but the escalation contact is six months out of date.

The resulting strategy is not “work remotely.” It is a control package:

  1. maintain an offline copy of the current wire procedure and call-back directory;
  2. test backup approver access from the alternate workspace;
  3. confirm the carrier paths do not share an unrecognized local failure point;
  4. establish the vendor’s authenticated escalation route;
  5. define a safe-stop rule when dual control or call-back verification is unavailable; and
  6. run a timed exercise that measures access, approval, release, and reconciliation.

That is the link from threat to continuity strategy. It also exposes where ownership gets messy: Technology owns connectivity, Operations owns the manual procedure, Security owns emergency access, and Vendor Management owns provider evidence. The BCM owner should coordinate the record, not pretend to own every control.

For deeper dependency mapping, use the third-party dependency depth guide. It is especially useful when two “different” vendors share one cloud region, identity provider, telecom route, or subcontractor.

Turn residual gaps into test objectives

The FFIEC continuity-strategy section becomes operational when every material residual gap has one of four dispositions:

  • Strategy funded and implemented. Record the owner, activation rule, capacity assumption, and evidence.
  • Strategy approved but incomplete. Track the missing action and interim control as an issue.
  • Risk accepted. Name the acceptance authority, rationale, scope, expiry, and reassessment trigger.
  • Service restricted or stopped safely. Define who can make that decision and how customer, counterparty, and regulatory obligations are handled.

Then convert the uncertainty into a test objective. “Run ransomware tabletop” is too broad. “Demonstrate that Payments can retrieve the offline ACH release procedure, establish dual control, produce a balanced file, and document held items within four hours while primary identity services are unavailable” is testable.

The business continuity testing documentation guide explains the evidence package. At minimum, retain the scenario, assumptions, participants, timestamps, observed results, exceptions, owner decisions, and proof that remediation was later validated.

The examiner-ready evidence bundle

For one sampled critical service, be ready to produce:

  • current BIA record and approved recovery objectives;
  • dependency map with business, technology, facility, data, personnel, and third-party dependencies;
  • threat-and-control assessment with methodology and evidence references;
  • continuity strategy decision and approval;
  • procedure or runbook implementing that strategy;
  • latest exercise or test record with actual timing;
  • unresolved exceptions, risk acceptances, and remediation status; and
  • evidence that material changes triggered reassessment.

The full NIST SP 800-34 Rev. 1 PDF is useful for Technology teams building system-level contingency evidence. The bank-level record still needs to explain the business service and regulatory consequence. A clean server recovery test does not prove that Operations can reconcile queued payments or that Customer Support can communicate accurately during the outage.

So what?

Pick one service with a short RTO this week. Start at its BIA row and try to trace one realistic threat through dependencies, control evidence, residual risk, strategy, test result, and remediation. Every broken link is a concrete work item. That one-service trace will tell you more about the quality of the program than a perfectly colored enterprise heat map.

If the underlying artifacts are missing, the Business Continuity & Disaster Recovery Kit includes BIA, risk assessment, dependency mapping, recovery procedure, testing, and action-tracking templates built to work as one evidence chain.

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What does FFIEC BCM Section III.B require from a risk assessment?
The assessment should identify realistic threats to critical operations, evaluate the likelihood and impact of disruption, consider existing controls and vulnerabilities, and support the selection of continuity strategies. A useful assessment preserves the trace from each critical service and dependency to the threat, control gap, strategy, test, and remediation owner.
Is a business impact analysis the same as a business continuity risk assessment?
No. The BIA identifies critical services, impacts, dependencies, and recovery objectives without assuming a specific cause. The risk assessment evaluates specific threats and vulnerabilities that could disrupt those services. The two artifacts should connect, but one should not be relabeled as the other.
Should the assessment score inherent and residual continuity risk?
That is a practical way to show what the threat looks like before controls and what remains after considering tested controls. The scoring scale should be documented, and a strong control should not reduce residual risk unless operating evidence supports the rating.
How does the risk assessment connect to continuity testing?
Material threat-and-strategy pairs should become test objectives. If a strategy depends on manual processing, an alternate site, a backup telecom path, or a vendor recovery capability, the exercise should test that dependency and record observed recovery time, exceptions, and corrective actions.
How often should the FFIEC business continuity risk assessment be updated?
Use a documented periodic review plus event-driven updates after material product, technology, facility, staffing, vendor, threat, or dependency changes. The trigger matters more than treating an annual date change as evidence of a real reassessment.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

Business Continuity & Disaster Recovery (BCP/DR) Kit

BCP and DR templates with BIA, recovery procedures, and a standalone tabletop exercise kit.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.