In the financial sector, defining and confirming risk appetite is a crucial step in ensuring an effective operational resilience strategy.
For AmBank Malaysia, confirming risk appetite within the “Plan” phase of its Operational Resilience Planning Methodology establishes clear boundaries for risk-taking while aligning resilience efforts with the bank’s business objectives and regulatory expectations.
The “Confirm Risk Appetite” stage helps AmBank Malaysia determine the level of operational disruption it can withstand, ensuring that critical business services remain available even under adverse conditions.
This article outlines the key implementation steps for confirming risk appetite, supplemented with examples relevant to the bank’s operational environment.
Objective:
To set the boundaries for risk-taking across critical business services, functions, and supporting infrastructure.
Actions:
Example:
AmBank Malaysia determines that its real-time gross settlement (RTGS) system must recover within one hour in the event of a cyberattack, ensuring uninterrupted high-value transactions.
Objective:
To ensure the bank’s operational resilience, the risk appetite is consistent with Bank Negara Malaysia (BNM) regulatory guidelines and AmBank’s overall risk management framework.
Actions:
Example:
AmBank Malaysia aligns its risk appetite for digital banking downtime with BNM’s expectations by setting a maximum allowable disruption time of 30 minutes for its online banking services, ensuring compliance with digital banking resilience standards.
Objective:
To define quantifiable risk appetite statements and set specific risk tolerance thresholds.
Actions:
Example:
AmBank Malaysia implements a real-time monitoring system for its ATM network. If the transaction failure rate exceeds 1%, an automatic escalation process is triggered for immediate investigation and remediation.
Objective:
To test the practicality of risk appetite thresholds under various operational disruption scenarios.
Actions:
Example:
AmBank Malaysia runs a cyber resilience stress test where its digital banking platform is subjected to a simulated ransomware attack. The test reveals that customer login failures exceed the bank’s acceptable threshold of 0.5%, prompting adjustments in cybersecurity investment and incident response protocols.
Objective:
To ensure all stakeholders understand and adhere to the bank’s operational resilience risk appetite.
Actions:
Example:
AmBank Malaysia formally includes its risk appetite for digital payment processing in its ERM policy, ensuring that the IT and payments operations teams proactively monitor and mitigate risks that could exceed defined tolerance levels.
Confirming risk appetite is a critical component of AmBank Malaysia’s operational resilience planning. By defining clear risk tolerance thresholds, aligning with regulatory requirements, implementing quantifiable risk metrics, conducting stress testing, and ensuring organization-wide communication, AmBank strengthens its ability to withstand operational disruptions.
A well-defined risk appetite enables the bank to balance risk-taking with resilience, ensuring uninterrupted financial services for its customers while meeting regulatory and strategic objectives.
| Operational Resilience Framework: A Case Study of AmBank Malaysia | |||||
| "Plan" Phase of the Operational Resilience Planning Methodology | |||||
| C2 | C3 | C4 | C5 | C6 | C7 |
To learn more about the course and schedule, click the buttons below for the OR-300 Operational Resilience Implementer course and the OR-5000 Operational Resilience Expert Implementer course.
|
If you have any questions, click to contact us. |
||
|
|