Operational Resilience Planning Methodology: The Five Stages of the “Plan” Phase for AmBank Malaysia
Introduction

Operational resilience is a crucial aspect of financial institutions, enabling them to withstand disruptions and maintain essential services.
At AmBank Malaysia, the “Plan” phase of the Operational Resilience Planning Methodology consists of five structured stages:
- Assess Capability and Maturity
- Analyse Gap
- Develop Strategy and Roadmap
- Confirm Risk Appetite
- Develop and Embed Governance
Each stage plays a vital role in shaping AmBank Malaysia’s resilience framework, aligning with regulatory expectations and industry best practices.
Below is a summary of the implementation process for each stage, along with practical examples.
Stage 1: Assess Capability and Maturity
[Plan Phase – Stage 1]
Objective:
Evaluate the bank’s current operational resilience capabilities, maturity level, and preparedness against regulatory and industry benchmarks.
Implementation Process:
- Conduct a Resilience Maturity Assessment using a structured framework (e.g., Basel Committee on Banking Supervision, Bank Negara Malaysia’s Operational Resilience Guidelines).
- Assess critical business services, their interdependencies, and existing resilience measures.
- Identify strengths in resilience and areas that require improvement.
- Engage key stakeholders, including risk management, IT, and business continuity teams, to provide insights.
Example:
AmBank Malaysia utilizes a Resilience Maturity Model to assess its preparedness, ranging from Level 1 (Basic) to Level 5 (Optimised). The assessment highlights gaps in third-party risk management and IT disaster recovery planning, prompting further analysis.
Stage 2: Analyse Gap
[Plan Phase – Stage 2]
Objective:
Identify gaps between the bank’s current resilience capabilities and the target state based on regulatory and business requirements.
Implementation Process:
- Compare findings from the capability assessment against regulatory guidelines (e.g., Bank Negara Malaysia’s Resilience Framework).
- Conduct a Business Impact Analysis (BIA) to evaluate vulnerabilities in key operational areas.
- Review past incidents and stress test results to identify areas of resilience weakness.
- Prioritise identified gaps based on potential risk exposure and business impact.
Example:
A gap analysis reveals that while AmBank has robust cybersecurity measures, its incident response plans lack integration with third-party service providers, which could delay recovery in the event of a major cyberattack.
Stage 3: Develop Strategy and Roadmap
[Plan Phase – Stage 3]
Objective:
Formulate a strategic approach and an implementation roadmap to enhance AmBank’s operational resilience over time.
Implementation Process:
- Define short-term (1 year), medium-term (3 years), and long-term (5 years) resilience goals.
- Develop an implementation roadmap outlining key initiatives, milestones, and required investments.
- Align resilience strategy with broader risk management and digital transformation goals.
- Identify key performance indicators (KPIs) and metrics for tracking progress.
Example:
AmBank has developed a three-year Operational Resilience Roadmap, focusing on:
- Year 1: Enhancing cyber resilience and third-party risk management.
- Year 2: Strengthening cloud-based disaster recovery and crisis communication protocols.
- Year 3: Achieving full operational resilience automation with AI-driven threat detection.
Stage 4: Confirm Risk Appetite
[Plan Phase – Stage 4]
Objective:
Define and validate the bank’s operational resilience risk appetite, ensuring alignment with business strategy and regulatory expectations.
Implementation Process:
- Establish risk appetite thresholds for service downtime, data loss, and financial losses due to disruptions.
- Conduct scenario analysis to assess potential resilience risks and their financial impact.
- Obtain approval from senior management and board committees.
- Ensure risk appetite statements are embedded into business and risk management processes.
Example:
AmBank determines that for critical payment processing systems, the acceptable maximum downtime is 30 minutes, and data loss should not exceed 5 minutes of transaction records. These thresholds guide resilience investments and incident response strategies.
Stage 5: Develop and Embed Governance
[Plan Phase – Stage 5]
Objective:
Establish a governance structure to ensure ongoing oversight of resilience, accountability, and compliance with regulations.
Implementation Process:
- Define roles and responsibilities for operational resilience at various levels (e.g., Board, Risk Committees, Operational Resilience Teams).
- Integrate resilience governance within Enterprise Risk Management (ERM) and IT governance frameworks.
- Implement regular resilience testing, including penetration testing, tabletop exercises, and full-scale simulations.
- Establish a continuous monitoring mechanism to track and report resilience performance.
Example:
AmBank creates an Operational Resilience Committee chaired by the Chief Risk Officer (CRO). The committee reviews resilience metrics quarterly, conducts annual scenario exercises, and reports directly to the Board Risk Committee.
AmBank Malaysia’s five-stage “Plan” phase provides a structured and strategic approach to operational resilience. By assessing current capabilities, identifying gaps, developing a strategic roadmap, confirming risk appetite, and embedding governance, the bank ensures its ability to withstand disruptions while meeting regulatory expectations.
This proactive approach strengthens AmBank’s resilience posture, safeguards critical financial services, and reinforces trust among customers, regulators, and stakeholders.
| Operational Resilience Framework: A Case Study of AmBank Malaysia | |||||
| "Plan" Phase of the Operational Resilience Planning Methodology | |||||
| C2 | C3 | C4 | C5 | C6 | C7 |
![]() |
![]() |
![]() |
![]() |
![]() |
![]() |
Gain Competency: For organisations looking to accelerate their journey, BCM Institute’s training and certification programs, including the OR-5000 Operational Resilience Expert Implementer course, provide in-depth insights and practical toolkits for effectively embedding this model.

![BB OR [C] 11 BB OR [C] 11](https://blog.bcm-institute.org/hs-fs/hubfs/BB%20OR%20%5BAi%20Gen%20Blog%20Photo%5D/OR%20Pictures%20A/BB%20OR%20Folder%20C/BB%20OR%20%5BC%5D%2011.jpg?width=2000&height=1333&name=BB%20OR%20%5BC%5D%2011.jpg)


![x [OR] [AmB] Legal Disclaimer Banner](https://no-cache.hubspot.com/cta/default/3893111/c17ea734-ce39-46d1-9b00-ce39367ccfc1.png)
![[Banner] [Summing] [OR] [E2] [C2] Five Stages of the _Plan_ Phase](https://no-cache.hubspot.com/cta/default/3893111/94252783-48b0-4534-9233-532e841f581d.png)
![[OR] [AmB] [P1 to P3] [C1] OR Planning Methodology](https://no-cache.hubspot.com/cta/default/3893111/4272283c-1b31-42b2-9ffb-6dec1486ef07.png)
![[OR] [AmB] [P2] [S1-S5] [C8] Five Stages of the _Implement_ Phase](https://no-cache.hubspot.com/cta/default/3893111/28d33a62-1830-447f-85f9-0136fa6c0368.png)
![[OR] [AmB] [P3] [S1-S5] [C14] Five Stages of the Sustain Phase](https://no-cache.hubspot.com/cta/default/3893111/4d2a8252-c383-4cd7-82bb-2c64bf0143a6.png)
![[OR] [AmB] [E2] [P1] [S1] [C3] Assessing Capability and Maturity](https://no-cache.hubspot.com/cta/default/3893111/fa566c3f-d706-4cf6-82eb-8c994905ed23.png)
![[OR] [AmB] [E2] [P1] [S2] [C4] Analysing Gaps](https://no-cache.hubspot.com/cta/default/3893111/756b2d4c-674f-43a9-b5b3-c1dab5a00db3.png)
![[OR] [AmB] [E2] [P1] [S3] [C5] Developing Strategy and Roadmap](https://no-cache.hubspot.com/cta/default/3893111/f243b851-ff78-4975-9015-f50e66e5bf40.png)
![[OR] [AmB] [E2] [P1] [S4] [C6] Confirming Risk Appetite](https://no-cache.hubspot.com/cta/default/3893111/1a2599aa-80c2-4b29-b583-40d84faca3a4.png)
![[OR] [AmB] [E2] [P1] [S5] [C7] Developing and Embedding Governance](https://no-cache.hubspot.com/cta/default/3893111/b352e6f5-94ee-4370-a13c-d09222bcf7f0.png)





![[BL-OR] [3-4-5] View Schedule](https://no-cache.hubspot.com/cta/default/3893111/d0d733a1-16c0-4b68-a26d-adbfd4fc6069.png)
![[BL-OR] [3] FAQ OR-300](https://no-cache.hubspot.com/cta/default/3893111/f20c71b4-f5e8-4aa5-8056-c374ca33a091.png)
![Email to Sales Team [BCM Institute]](https://no-cache.hubspot.com/cta/default/3893111/3c53daeb-2836-4843-b0e0-645baee2ab9e.png)









