Confirming Risk Appetite in the Plan Phase of Operational Resilience Planning for AmBank Malaysia
(Part of the “Plan” Phase in Operational Resilience for Metrobank)
Introduction
In the financial sector, defining and confirming risk appetite is a crucial step in ensuring an effective operational resilience strategy.
For AmBank Malaysia, confirming risk appetite within the “Plan” phase of its Operational Resilience Planning Methodology establishes clear boundaries for risk-taking while aligning resilience efforts with the bank’s business objectives and regulatory expectations.
The “Confirm Risk Appetite” stage helps AmBank Malaysia determine the level of operational disruption it can withstand, ensuring that critical business services remain available even under adverse conditions.
This article outlines the key implementation steps for confirming risk appetite, supplemented with examples relevant to the bank’s operational environment.
Implementation Steps for Confirming Risk Appetite
Step 1: Define the Scope of Risk Appetite for Operational Resilience
Objective:
To set the boundaries for risk-taking across critical business services, functions, and supporting infrastructure.
Actions:
- Identify critical business services that require resilience planning, such as retail banking operations, digital banking platforms, treasury operations, and payments processing.
- Define key operational risks, including cybersecurity threats, third-party service failures, IT disruptions, and regulatory non-compliance.
- Establish acceptable thresholds for operational disruption, such as maximum allowable downtime (MAD) and recovery time objectives (RTO) for core services.
Example:
AmBank Malaysia determines that its real-time gross settlement (RTGS) system must recover within one hour in the event of a cyberattack, ensuring uninterrupted high-value transactions.
Step 2: Align Risk Appetite with Regulatory and Strategic Objectives
Objective:
To ensure the bank’s operational resilience, the risk appetite is consistent with Bank Negara Malaysia (BNM) regulatory guidelines and AmBank’s overall risk management framework.
Actions:
- Review BNM’s Operational Risk and Resilience Guidelines to align risk appetite with compliance requirements.
- Ensure risk appetite aligns with AmBank’s corporate strategy, such as the expansion of its digital banking services and financial inclusion initiatives.
- Consult key stakeholders, including the Board of Directors, Risk Management Committee, and business unit leaders, to validate alignment.
Example:
AmBank Malaysia aligns its risk appetite for digital banking downtime with BNM’s expectations by setting a maximum allowable disruption time of 30 minutes for its online banking services, ensuring compliance with digital banking resilience standards.
Step 3: Establish Risk Metrics and Tolerance Levels
Objective:
To define quantifiable risk appetite statements and set specific risk tolerance thresholds.
Actions:
- Develop risk appetite statements that outline acceptable risk levels for different types of disruptions.
- Identify key risk indicators (KRIs) that measure adherence to risk appetite, such as:
- System uptime percentage (e.g., 99.9% availability for digital banking).
- Transaction failure rate (e.g., less than 0.5% of digital transactions fail).
- Third-party service recovery time (e.g., critical vendors must restore services within two hours).
- Define action triggers when risk metrics approach tolerance limits.
Example:
AmBank Malaysia implements a real-time monitoring system for its ATM network. If the transaction failure rate exceeds 1%, an automatic escalation process is triggered for immediate investigation and remediation.
Step 4: Conduct Stress Testing and Scenario Analysis
Objective:
To test the practicality of risk appetite thresholds under various operational disruption scenarios.
Actions:
- Develop resilience scenarios, such as cyberattacks, IT system failures, third-party disruptions, and natural disasters.
- Simulate worst-case operational disruptions and evaluate whether AmBank’s risk appetite tolerances are realistic.
- Adjust risk appetite statements based on test results, ensuring that business services can recover within the defined limits.
Example:
AmBank Malaysia runs a cyber resilience stress test where its digital banking platform is subjected to a simulated ransomware attack. The test reveals that customer login failures exceed the bank’s acceptable threshold of 0.5%, prompting adjustments in cybersecurity investment and incident response protocols.
Step 5: Formalise and Communicate Risk Appetite Statements
Objective:
To ensure all stakeholders understand and adhere to the bank’s operational resilience risk appetite.
Actions:
- Document and approve the Operational Resilience Risk Appetite Statement as part of the bank’s enterprise risk management (ERM) framework.
- Communicate risk appetite levels to all relevant teams, including risk management, IT, operations, and third-party service providers.
- Integrate risk appetite statements into business continuity and incident response plans for seamless execution during disruptions.
Example:
AmBank Malaysia formally includes its risk appetite for digital payment processing in its ERM policy, ensuring that the IT and payments operations teams proactively monitor and mitigate risks that could exceed defined tolerance levels.
Confirming risk appetite is a critical component of AmBank Malaysia’s operational resilience planning. By defining clear risk tolerance thresholds, aligning with regulatory requirements, implementing quantifiable risk metrics, conducting stress testing, and ensuring organization-wide communication, AmBank strengthens its ability to withstand operational disruptions.
A well-defined risk appetite enables the bank to balance risk-taking with resilience, ensuring uninterrupted financial services for its customers while meeting regulatory and strategic objectives.
| Operational Resilience Framework: A Case Study of AmBank Malaysia | |||||
| "Plan" Phase of the Operational Resilience Planning Methodology | |||||
| C2 | C3 | C4 | C5 | C6 | C7 |
![]() |
![]() |
![]() |
![]() |
![]() |
![]() |
Gain Competency: For organisations looking to accelerate their journey, BCM Institute’s training and certification programs, including the OR-5000 Operational Resilience Expert Implementer course, provide in-depth insights and practical toolkits for effectively embedding this model.

![BB OR [D] 3 BB OR [D] 3](https://blog.bcm-institute.org/hs-fs/hubfs/BB%20OR%20%5BAi%20Gen%20Blog%20Photo%5D/OR%20Pictures%20A/BB%20OR%20Folder%20D/BB%20OR%20%5BD%5D%203.jpg?width=2000&height=1333&name=BB%20OR%20%5BD%5D%203.jpg)

![[E2] [C6] [P1] [S4] Confirming Risk Appetite](https://no-cache.hubspot.com/cta/default/3893111/36bc08e8-54f0-4b0b-b402-6d96c72dc3bb.png)
![x [OR] [AmB] Legal Disclaimer Banner](https://no-cache.hubspot.com/cta/default/3893111/c17ea734-ce39-46d1-9b00-ce39367ccfc1.png)
![[Banner] [Summing] [OR] [E2] [C6] Confirming Risk Appetite](https://no-cache.hubspot.com/cta/default/3893111/c13a1d8c-3234-4a1a-a30b-393e264dd957.png)
![[OR] [AmB] [P1] [S1-S5] [C2] Five Stages of the _Plan_ Phase](https://no-cache.hubspot.com/cta/default/3893111/7713cc8c-f0f2-4c0b-90ca-577cb08e33af.png)
![[OR] [AmB] [E2] [P1] [S1] [C3] Assessing Capability and Maturity](https://no-cache.hubspot.com/cta/default/3893111/fa566c3f-d706-4cf6-82eb-8c994905ed23.png)
![[OR] [AmB] [E2] [P1] [S2] [C4] Analysing Gaps](https://no-cache.hubspot.com/cta/default/3893111/756b2d4c-674f-43a9-b5b3-c1dab5a00db3.png)
![[OR] [AmB] [E2] [P1] [S3] [C5] Developing Strategy and Roadmap](https://no-cache.hubspot.com/cta/default/3893111/f243b851-ff78-4975-9015-f50e66e5bf40.png)
![[OR] [AmB] [E2] [P1] [S5] [C7] Developing and Embedding Governance](https://no-cache.hubspot.com/cta/default/3893111/b352e6f5-94ee-4370-a13c-d09222bcf7f0.png)





![[BL-OR] [3-4-5] View Schedule](https://no-cache.hubspot.com/cta/default/3893111/d0d733a1-16c0-4b68-a26d-adbfd4fc6069.png)
![[BL-OR] [3] FAQ OR-300](https://no-cache.hubspot.com/cta/default/3893111/f20c71b4-f5e8-4aa5-8056-c374ca33a091.png)
![Email to Sales Team [BCM Institute]](https://no-cache.hubspot.com/cta/default/3893111/3c53daeb-2836-4843-b0e0-645baee2ab9e.png)








