Operational Resilience is no longer viewed as a standalone risk management initiative but as an enterprise-wide management discipline that enables financial institutions to continue delivering their most important business services during disruption.
As financial services become increasingly digital, interconnected, and dependent upon complex internal and external ecosystems, organisations must adopt a structured methodology that systematically develops, implements, and continuously improves resilience capabilities.
For an organisation such as AIA Bhd, Operational Resilience extends beyond recovering from operational incidents.
It focuses on anticipating disruption, protecting critical business services, minimising harm to customers, maintaining regulatory compliance, and continuously adapting to an evolving threat landscape.
This chapter introduces the Operational Resilience Planning Methodology used throughout this eBook series. Although developed using AIA Bhd as the case study, the methodology represents a practical implementation framework that can be adapted by any regulated financial institution.
The methodology comprises three progressive phases—Plan, Implement, and Sustain—containing fifteen structured stages that collectively establish, operationalise, and continually strengthen Operational Resilience capabilities.
Before beginning an Operational Resilience programme, practitioners must understand not only what activities need to be completed, but also why they are performed, when they should occur, and how they relate to one another.
Without a structured methodology, organisations often implement isolated resilience initiatives that lack strategic alignment, resulting in duplicated effort, governance gaps, and inconsistent outcomes.
The purpose of this chapter is to introduce the complete Operational Resilience Planning Methodology that will guide the reader throughout this implementation guide. It explains the rationale behind the three implementation phases and describes the objectives of each of the fifteen stages.
By understanding the methodology at the outset, readers will appreciate how each subsequent chapter contributes to building a comprehensive Operational Resilience capability rather than a collection of independent activities.
Upon completing this chapter, readers should be able to:
The Operational Resilience Planning Methodology provides a structured roadmap for designing, implementing, and continuously improving resilience capabilities across the organisation.
The methodology is organised into three integrated phases:
Each phase builds upon the previous one. The planning activities establish strategic direction, implementation converts strategy into operational capability, while the sustain phase embeds resilience into organisational culture and governance to ensure long-term effectiveness.
Rather than treating Operational Resilience as a one-off compliance exercise, this methodology promotes continual improvement through governance, learning, assessment, and independent assurance.
The Plan phase establishes the strategic foundation for the entire Operational Resilience programme.
During this phase, AIA Bhd evaluates its current capabilities, identifies improvement opportunities, develops an implementation strategy, aligns resilience objectives with organisational risk appetite, and establishes governance structures that support long-term programme success.
The first stage evaluates the organisation's current Operational Resilience capabilities.
The assessment examines governance, policies, processes, technology, business continuity, operational risk management, cyber resilience, third-party management, crisis management, and organisational readiness.
Understanding the current maturity enables management to prioritise investments and identify realistic improvement objectives.
Illustrative example for AIA Bhd
AIA Bhd conducts an enterprise-wide maturity assessment to determine how effectively its insurance operations, digital customer platforms, claims services, technology functions, and supporting business units currently manage operational disruptions.
The assessment reveals strengths in Business Continuity Management while identifying opportunities to strengthen dependency mapping across digital services and third-party providers.
Following the maturity assessment, identified capabilities are compared against regulatory expectations, industry good practices, and organisational objectives.
Gap analysis enables management to determine where additional controls, governance, resources, or processes are required before implementation proceeds.
Illustrative example for AIA Bhd
Following its maturity assessment, AIA Bhd identifies that while cyber resilience capabilities are well established, formal impact tolerance definitions for critical insurance services have not yet been developed.
This gap becomes a priority within the implementation roadmap.
The strategy defines how the organisation intends to achieve Operational Resilience, while the roadmap establishes implementation priorities, timelines, responsibilities, milestones, and resource allocation.
The roadmap transforms strategic intent into a manageable implementation programme.
Illustrative example for AIA Bhd
AIA Bhd develops a three-year Operational Resilience roadmap that prioritises customer-facing digital services, claims processing, policy administration, and supporting technology platforms before progressively expanding resilience capabilities across other corporate functions.
Operational Resilience decisions should align with the organisation's overall risk appetite.
Senior management defines the level of operational disruption that can be tolerated before unacceptable harm occurs to customers, regulators, reputation, or financial stability.
The risk appetite provides guidance when determining resilience priorities and investment decisions.
Illustrative example for AIA Bhd
Executive management determines that prolonged disruption affecting digital policy servicing or claims settlement would exceed the organisation's acceptable risk tolerance due to potential customer harm and regulatory implications.
Governance establishes accountability, decision-making authority, reporting structures, oversight responsibilities, and programme ownership.
Strong governance ensures Operational Resilience remains integrated with enterprise risk management rather than operating independently.
Illustrative example for AIA Bhd
AIA Bhd establishes an Operational Resilience Steering Committee comprising representatives from Operations, Information Technology, Risk Management, Business Continuity, Cybersecurity, Compliance, Customer Services, and Internal Audit to oversee programme implementation and continuous improvement.
The Implement phase transforms strategic planning into operational capability.
It identifies the organisation's most important services, analyses their dependencies, establishes resilience targets, validates preparedness through scenario testing, and continuously improves resilience based on operational experience.
Critical Business Services are those whose disruption would cause unacceptable harm to customers, regulatory objectives, or market confidence.
These services become the primary focus of Operational Resilience planning.
Illustrative example for AIA Bhd
AIA Bhd identifies claims processing, policy administration, premium collection, digital customer services, and policy issuance as Critical Business Services requiring enhanced resilience planning.
Once Critical Business Services have been identified, planners map the people, technology, facilities, information, suppliers, and supporting business processes required to deliver each service.
Dependency mapping identifies potential single points of failure and critical operational interdependencies.
Illustrative example for AIA Bhd
For digital claims processing, AIA Bhd maps customer portals, claims management applications, cloud infrastructure, payment gateways, customer service teams, document management systems, telecommunications providers, and third-party medical assessment partners.
Impact tolerance defines the maximum acceptable disruption before unacceptable harm occurs.
Unlike recovery objectives, impact tolerance focuses on customer outcomes rather than technical system recovery.
Illustrative example for AIA Bhd
Management determines that prolonged disruption to digital claims submission beyond an agreed tolerance could significantly affect customer confidence and therefore requires enhanced resilience controls and recovery capabilities.
Scenario testing validates whether resilience capabilities can successfully maintain Critical Business Services during severe but plausible disruptions.
Testing provides objective evidence that resilience arrangements are effective.
Illustrative example for AIA Bhd
AIA Bhd conducts an enterprise-wide exercise simulating simultaneous cyber disruption affecting customer portals and cloud-hosted policy administration systems while increased customer enquiries place additional pressure on contact centre operations.
Every disruption, exercise, or incident provides opportunities for improvement.
Lessons learned should be documented, analysed, prioritised, and incorporated into future resilience improvements.
Operational Resilience therefore becomes a continuous learning process rather than a static programme.
Illustrative example for AIA Bhd
Following a resilience exercise, AIA Bhd identifies opportunities to improve communications between technology teams, claims operations, customer service representatives, and external service providers, leading to revised incident response procedures.
The Sustain phase embeds Operational Resilience into everyday organisational behaviour.
It ensures resilience capabilities continue evolving through leadership, communication, education, self-assessment, and independent assurance.
Operational Resilience succeeds only when employees understand their role in protecting critical business services.
Building a resilience culture encourages proactive risk awareness and accountability across the organisation.
Illustrative example for AIA Bhd
Senior management incorporates resilience objectives into leadership messaging and encourages business units to consider operational resilience during strategic planning, technology changes, and new product development.
Effective communication ensures stakeholders understand resilience objectives, governance arrangements, responsibilities, and incident response expectations.
Communication also strengthens awareness among employees, regulators, customers, and business partners.
Illustrative example for AIA Bhd
AIA Bhd develops an internal communication programme explaining Operational Resilience objectives, implementation progress, employee responsibilities, and governance updates across business units.
Training equips employees with the knowledge and practical skills required to support resilience objectives.
Different stakeholder groups require different levels of resilience education.
Illustrative example for AIA Bhd
Claims officers, customer service representatives, technology teams, senior executives, and third-party coordinators participate in role-specific Operational Resilience training aligned with their operational responsibilities.
Business units periodically assess their own resilience capabilities to identify improvement opportunities before formal reviews occur.
Self-assessment encourages ownership and continuous monitoring.
Illustrative example for AIA Bhd
Each business unit annually reviews its resilience arrangements using a structured maturity assessment covering governance, dependencies, incident response, testing, and continuous improvement.
Independent reviews provide objective assurance that Operational Resilience capabilities remain effective, compliant, and aligned with organisational objectives.
These reviews may be performed by Internal Audit or independent external specialists.
Illustrative example for AIA Bhd
Internal Audit conducts an independent review of AIA Bhd's Operational Resilience programme to evaluate governance effectiveness, testing outcomes, regulatory alignment, and implementation progress, providing recommendations for further enhancement.
Operational Resilience is not achieved through a single project or compliance exercise; it is established through a structured, disciplined, and continually evolving implementation programme.
The three-phase Operational Resilience Planning Methodology presented in this chapter provides AIA Bhd with a comprehensive framework for building, implementing, and sustaining resilience across its critical business services.
The Plan phase establishes the strategic direction, governance, and organisational readiness required for success.
The Implement phase translates strategy into operational capability by identifying Critical Business Services, understanding dependencies, setting impact tolerances, validating resilience through scenario testing, and driving continual improvement.
Finally, the Sustain phase embeds Operational Resilience into the organisation's culture through communication, training, self-assessment, and independent assurance, ensuring that resilience remains an integral part of day-to-day operations rather than a one-time initiative.
The chapters that follow examine each of these fifteen stages in greater depth, providing practical guidance, implementation techniques, examples, templates, and recommended practices to help AIA Bhd—and organisations with similar operational profiles—develop a mature, sustainable, and regulator-aligned Operational Resilience capability.
Blogs marked [x] are under construction
| C1 | C2 [x] | C8 [x] | C14 [x] | |||
| BNM OR Policy | eBook 1 | eBook 2 | eBook 3 | C20 [x] | C21 [x] | |
| |
||||||
| "Plan" Phase of the Operational Resilience Planning Methodology |
||||||
| C2 [x] | C3 [x] | C4 [x] | C5 [x] | C6 [x] | C7 [x] | |
| "Implement" Phase of the Operational Resilience Planning Methodology | ||||||
| C8 [x] | C9 [x] | C10 [x] | C11 [x] | C12 [x] | C13 [x] | |
| "Sustain" Phase of the Operational Resilience Planning Methodology | ||||||
| C14 [x] | C15 [x] | C16 [x] | C17 [x] | C18 [x] | C19 [x] | |
For organisations looking to accelerate their journey, BCM Institute’s training and certification programs, including the OR-5000 Operational Resilience Expert Implementer course, provide in-depth insights and practical toolkits for effectively embedding this model.
Gain Competency: For organisations looking to accelerate their journey, BCM Institute’s training and certification programs, including the OR-5000 Operational Resilience Expert Implementer course, provide in-depth insights and practical toolkits for effectively embedding this model.
To learn more about the course and schedule, click the buttons below for the OR-300 Operational Resilience Implementer course and the OR-5000 Operational Resilience Expert Implementer course.
|
If you have any questions, click to contact us. |
||
|
|