Operational Resilience as an Investment Thesis: What Investors Should Examine Beyond the Balance Sheet


By Korosh Farazad - Founder & CEO of Farazad Investments, which advises founders, boards, and institutional investors on structured finance and cross-border transactions from Switzerland.
A company can report strong revenue growth, healthy margins, and an attractive balance sheet while remaining surprisingly fragile. A single technology failure, the loss of a critical supplier, the departure of a key executive, or a breakdown in regulatory controls can impair cash flow and enterprise value far faster than a conventional financial model suggests.
This is why operational resilience deserves a more prominent place in investment analysis. It is broader than business continuity and broader than cybersecurity. It describes an organization’s ability to keep delivering its most important products and services when conditions are disrupted, to recover within an acceptable timeframe, and to learn from what happened.
What operational resilience means for investors
The US Interagency Paper on Sound Practices to Strengthen Operational Resilience, published in October 2020, connects continuity of critical operations with the resources needed to prepare for, withstand, recover from, and learn from disruption. Written for the largest US banking organizations, its underlying idea travels well beyond banking.
The key investor question is whether management understands its critical dependencies, has defined its tolerance for disruption, and has the resources and decision-making discipline to keep functioning when a major assumption fails.
Why the balance sheet is not enough
Traditional financial analysis remains essential. Historical statements, however, largely record what has already happened. Two companies with similar financial profiles can carry very different risk. One may have diversified suppliers, tested recovery plans, redundant systems, and a deep management bench. The other may depend on one supplier, one cloud environment, or one founder whose knowledge is not documented.
Operational resilience does not replace financial analysis. It tells you how reliable the financial model is likely to be under stress.
The regulatory lens is now European as much as American
For cross-border investors, the European and Swiss frameworks are frequently relevant reference points. The Basel Committee’s Principles for Operational Resilience, published in March 2021, established an international baseline. Its concept of a tolerance for disruption asks how much disruption to a service the organisation can accept before the consequences become unacceptable.
Under the UK’s PRA and FCA rules, firms must identify important business services, set impact tolerances, and demonstrate they can remain within them during severe but plausible scenarios. The EU’s Digital Operational Resilience Act, or DORA, has applied since January 2025, covering ICT risk management, incident reporting, resilience testing, and oversight of critical third-party technology providers.
Switzerland addresses operational risks and resilience for banks through FINMA Circular 2023/1, in force since the beginning of 2024. For investors structuring cross-border transactions from Switzerland, the practical question is whether a target understands which regimes reach it through customer and supplier relationships, rather than only through its own domicile.
Seven areas investors should examine
1. Critical operations and business dependencies
The starting point is to identify activities essential to revenue, customer service, compliance, and cash generation. Then map their dependencies: people, facilities, technology, data, logistics, intellectual property, licenses, payment systems, and external providers.
If this process stopped tomorrow, what would fail first, how quickly would the impact spread, and who has the authority to respond?
2. Supply-chain concentration and substitution risk
Supplier concentration is often visible in procurement data but not fully reflected in an investment case. A business may appear diversified by customer or geography while depending on a single manufacturer, component, data provider, or logistics route.
Examine contractual protections, lead times, inventory policy, alternative sources, and the cost and time required to qualify a substitute. Some single-source relationships are commercially rational. What matters is knowing which dependencies are deliberate, which are accidental, and which could threaten the investment thesis.
3. Technology, data, and cyber resilience
Technology architecture should be reviewed as a business asset and a business risk. Investors should examine:
Privileged-access controls and identity management
Backup integrity, and whether backups have been restored rather than merely taken
Recovery time objectives and recovery point objectives, and whether they are documented per service
Incident response ownership, escalation, and rehearsal history
Patching cadence and known unremediated vulnerabilities
Software dependencies, including open-source components and end-of-life systems
Data classification and where regulated data physically resides
Third-party platform concentration, particularly single-cloud dependency
A written policy demonstrates intent. A completed test demonstrates capability. The NIST Cybersecurity Framework 2.0 reinforces the governance question through its Govern function: does anyone with authority own the controls?
4. Management depth and key-person risk
A company may have excellent procedures and still depend heavily on one individual. Founder dependence, undocumented commercial relationships, concentrated technical knowledge, and thin succession coverage can create hidden operational liabilities.
Investors should assess whether responsibilities and decisions are documented, more than one person understands each critical process, and leadership has operated effectively under stress. The review should extend beyond the chief executive to finance, operations, technology, compliance, sales, and customer relationships.
Key-person risk is rarely a reason to walk away. It is a reason to price the risk and put knowledge transfer and succession on the investment agenda.
5. Governance, escalation, and decision speed
Resilience also depends on decisions under pressure. Who can declare an incident, approve emergency expenditure, communicate with customers and regulators, and inform the board? Test management through scenarios:
What happens if the main operating site is unavailable for two weeks?
What happens if a core system is encrypted and the backups are three days old?
What happens if a key supplier fails during the busiest quarter?
What happens if a senior executive becomes suddenly unavailable?
The purpose is to observe whether management thinks in terms of priorities, trade-offs, escalation, and accountability. The board should independently challenge spending, risk acceptance, and whether reporting rests on evidence rather than confidence.
6. Financial capacity to absorb disruption
Operational and financial resilience reinforce each other. Insufficient liquidity can prevent a company from maintaining payroll, securing alternative suppliers, funding recovery, or retaining employees.
Stress-test liquidity under operational scenarios, including emergency procurement, expedited logistics, system restoration, customer remediation, regulatory costs, and delayed receivables. Review debt documents, minimum liquidity requirements, covenant headroom, insurance, and contingent funding in the same frame.
How much financial capacity does the business need to remain credible while its operating model is under pressure?
7. Learning culture and remediation follow-through
Learning is often skipped in diligence. Ask for post-incident reviews, remediation trackers, and internal audit findings across several cycles. Repeat findings are a governance signal: they reveal whether management closes what it opens. A company that documents near misses, assigns owners, and evidences closure demonstrates a capability that no single incident record can show.
An investor’s operational-resilience scorecard
A consistent scorecard turns a broad qualitative subject into a structured investment discussion. The weighting should vary by sector.
Area | Questions to Test | Evidence to Request |
Critical operations | Which activities are essential to revenue, customers, and compliance? | Process map, dependency map, service priorities |
Supply chain | Where are the single points of failure and how quickly can substitutes be activated? | Supplier concentration, contracts, lead times, substitution plan |
Technology and cyber | Can critical systems and data be restored within an acceptable timeframe? | Recovery tests, incident history, access controls, backup evidence |
People and leadership | Is the business dependent on a small number of individuals? | Organization chart, succession coverage, documented procedures |
Governance | Who decides, escalates, communicates, and spends during disruption? | Incident playbook, board reporting, escalation matrix |
Financial capacity | Can the company fund continuity and recovery without destabilizing its capital structure? | Liquidity forecast, covenant headroom, insurance, stress cases |
Learning culture | Does the organization improve after incidents and near misses? | Post-incident reviews, remediation tracking, audit findings |
Case Study: The Hidden Critical Dependency
During the acquisition of a mid-market European logistics operator, financial diligence reflected robust EBITDA margins and expanding customer contracts. Operational resilience screening, however, revealed that 80% of fleet dispatching relied on proprietary legacy software managed entirely by a single external contractor, with no source-code escrow or internal redundancy.
The deal team introduced a €2.5M holdback contingent on transitioning to an enterprise cloud platform and executing key-person retention agreements prior to closing. Operational insight didn't break the deal; it protected enterprise value and redefined the post-acquisition CapEx strategy.
The scorecard identifies where the investment thesis is robust, where it rests on unproven assumptions, and where targeted investment could create value.
Turning resilience into a value-creation plan
Operational resilience belongs in the value-creation plan. Priorities may include supplier diversification, modernizing core systems, documenting processes, improving working-capital visibility, strengthening management, or clearer board reporting.
Track recovery-test performance, critical supplier coverage, system availability, incident closure times, staff cross-training, and documented owners and backups for key processes. These measures help distinguish resilience activity from resilience capability. A resilient company may also be able to accept contracts, enter markets, or integrate acquisitions that weaker competitors cannot support.
Common mistakes in resilience diligence
Investors should avoid four mistakes: treating resilience as synonymous with cybersecurity; accepting policies as proof of preparedness; ignoring critical third parties; and assuming every activity must continue at all times. In a serious disruption, management must know which services to protect first and what can be paused, simplified, or rebuilt later.
The investment conclusion
Operational resilience is the quality of a company’s response when its plan meets reality. Invulnerability is not the standard. Understanding your vulnerabilities and demonstrating that you can manage them is.
The balance sheet tells an investor what a business has accumulated. Operational resilience helps reveal whether it can continue to create value when conditions become difficult. That capability is part of the investment case itself.
For further insights on execution, speed, and deal discipline, explore Korosh Farazad’s latest book: Full Disclosure: Time is Money, How to Get Things Done.



Comments