Executive boardroom overlooking the Toronto skyline

Insights · Industry Analysis

Insurance operational resilience: building the next maturity step

Most insurers have continuity plans. Fewer can say how long a claims operation can be disrupted before the harm becomes unacceptable — and prove they have tested it.

01

From recovering systems to sustaining outcomes

Traditional continuity planning is asset-centric: identify systems, set recovery time objectives, arrange alternate sites. Operational resilience inverts the question. It starts with the outcomes the insurer must sustain — claims paid, policies administered, obligations reported — and works backwards to everything those outcomes depend on, including people, processes, technology, data, facilities and third parties.

That inversion matters because the dependencies that break an outcome are rarely the ones on the recovery list. A claims operation can survive the loss of a data centre and fail because a single adjudication vendor is unavailable.

02

Map critical operations end to end

  • Identify critical operations in policyholder-outcome terms, not by department
  • Map the full dependency chain: applications, data, people, locations, third parties
  • Identify single points of failure and their realistic substitution time
  • Record data flows and processing locations, including subcontracted processing
  • Keep the mapping current through change management rather than annual refresh

03

Set tolerances the board is willing to defend

A tolerance states the maximum disruption the insurer will accept before harm becomes unacceptable — for example, a defined maximum period during which claims payments cannot be issued. Setting it is a board judgement about policyholder harm, not a technical estimate of recovery capability.

The discipline comes from the gap. Where current capability cannot meet the tolerance, the difference becomes a funded remediation plan with a date, or an explicitly accepted risk. Tolerances set to match existing capability provide no information and no pressure to improve.

04

Test scenarios that assume failure has occurred

Severe-but-plausible testing is where mapping and tolerances are validated. Useful scenarios are specific, uncomfortable and cross-functional: extended unavailability of a policy administration provider, a ransomware event affecting claims data integrity, the loss of a key operational site during a catastrophe response, or the simultaneous failure of a provider used by several business lines.

The output should be a short list of concrete gaps — a missing manual workaround, an untested data restore, an unreachable third-party contact — each with an owner and a date.

05

Third parties and concentration in the insurance chain

Insurance operations depend heavily on external parties: managing general agents, third-party administrators, brokers, adjusters, restoration networks, reinsurers and cloud platforms. Resilience work should reconcile directly with the third-party risk framework so that criticality, tolerances and exit plans use one consistent view rather than two competing inventories.

06

Where insurers are focusing next

  • Data integrity and recoverability, not just system availability
  • Manual and degraded-mode workarounds documented and periodically exercised
  • Consolidated dependency mapping shared across resilience, technology and vendor teams
  • Scenario testing extended to include third-party and concentration failures
  • Board reporting that pairs tolerance breaches with funded remediation

What good looks like

  • A short, board-approved list of critical operations defined by policyholder outcome
  • Current end-to-end dependency maps maintained through change management
  • Tolerances set on harm, with the capability gap funded or formally accepted
  • An annual programme of severe-but-plausible tests with documented gaps and owners
  • One reconciled view of critical third parties across resilience and vendor programs
  • Reporting that shows whether the insurer can stay within tolerance today

This article summarizes publicly available Canadian regulatory expectations, including OSFI Guideline E-21, and common industry practice. Requirements vary by regulator, charter and risk profile — confirm with counsel and your principal regulator.

Frequently asked questions

What is a critical operation for an insurer?

+

An activity whose disruption would materially harm policyholders, counterparties, market integrity or the insurer's financial condition — commonly claims intake and payment, policy administration and renewals, premium collection, reinsurance recoveries, actuarial valuation and regulatory reporting.

What is a tolerance for disruption?

+

The maximum acceptable level and duration of disruption to a critical operation, expressed in outcome terms such as time, volume or client impact. It is set by the board, tested through scenarios, and used to prioritize investment.

How does OSFI E-21 relate to business continuity planning?

+

Business continuity planning focuses on recovering assets, sites and systems. Operational resilience starts from the outcome the policyholder experiences and asks whether the critical operation can continue through disruption by any means, including manual workarounds and alternative providers.

What does severe-but-plausible testing involve?

+

Scenarios that assume a control has already failed — for example, a prolonged outage at a critical administrator, a ransomware event affecting policy data, or the loss of a key claims location — and testing whether the operation stays within tolerance. The value is in the gaps identified and remediated, not the pass or fail.

How do provincial regulators fit in?

+

Federally regulated insurers look to OSFI guidance, while provincially regulated insurers and intermediaries are supervised by bodies such as the AMF in Quebec and FSRA in Ontario. Many provincially regulated entities adopt equivalent resilience practices as a proportionate benchmark.

Ready when you are

Bring clarity, control and confidence to your risk and compliance program.

Explore Our Services