The Art of CTO STAMP Framework assesses operational resilience across five dimensions — Services, Tolerances, Architecture, Monitoring, and Proof — aligned to FCA and DORA regulatory requirements.
How resilient are our critical services, really?
A resilience score across Services, Tolerances, Architecture, Monitoring and Proof, aligned to FCA and DORA.
About 20 min · Assessment · Free
About this toolWhy it matters, common mistakes, FAQ
Would Your Critical Services Actually Hold?
Resilience is usually assessed component by component, but outages come from interactions — a retry storm, a shared dependency, a control that behaves differently under load. Availability targets you cannot trace to a control are aspirations.
Teams reason about failure as things breaking one at a time. Most serious incidents are several safe-looking behaviours combining, which is precisely what component-level review is blind to.
Questions CTOs ask
- What is the STAMP operational resilience framework?
- STAMP stands for Services, Tolerances, Architecture, Monitoring, and Proof — five dimensions for assessing operational resilience. It helps organizations identify their important business services, set impact tolerances for disruption, ensure their architecture supports those tolerances, implement monitoring to detect breaches, and gather evidence to prove resilience to regulators. The framework aligns with both FCA (UK) and DORA (EU) regulatory requirements.
- What are impact tolerances in operational resilience?
- Impact tolerances define the maximum acceptable level of disruption to an important business service, measured in terms like downtime duration, transaction volume affected, or data loss. For example, a payment processing service might have an impact tolerance of "no more than 4 hours of complete outage." Regulators expect organizations to set these tolerances based on consumer harm analysis, then test and prove they can stay within them under severe but plausible scenarios.
Related Reading
STAMP Framework for Resilience: A Practical Operational Resilience Assessment Guide for FCA and DORA
STAMP framework for resilience: an operational resilience assessment tool guide for FCA and DORA
guidesVendor Risk Assessment Template for Series A CTOs: A Practical Third-Party Risk Management Tool
Vendor risk assessment template for Series A CTOs: a practical third-party risk management tool
insightsGeopolitics and Regulation Are Now Architecture Requirements (Not Just Legal Reviews)
CTOs are entering an era where “compliance” isn’t a separate function: geopolitical exposure and fast-moving tech regulation are directly shaping cloud/AI architecture, third-party vendor strategy,...