Governance is the backbone of any operational resilience framework. In the “Develop and Embed Governance” stage of the “Plan” phase of AmBank Malaysia’s Operational Resilience Planning Methodology, the focus is on establishing clear structures, roles, responsibilities, and policies to ensure resilience is integrated into the bank’s operations.
Effective governance provides strategic direction, oversight, and accountability for resilience efforts, ensuring that the bank can anticipate, prepare for, and respond to disruptions.
This article outlines the implementation steps for embedding governance within AmBank’s operational resilience framework, along with practical examples.
Objective: Define clear accountability and decision-making authority for resilience management across the bank.
Actions:
Example:
AmBank’s Board Risk Management Committee (BRMC) oversees the operational resilience strategy, while the Operational Resilience Steering Committee (ORSC) ensures policies and frameworks are executed effectively at the business unit level.
Objective: Establish a policy framework that aligns with regulatory expectations and best practices.
Actions:
Example:
AmBank’s Operational Resilience Policy mandates that all critical business services must have defined impact tolerances and undergo annual resilience testing to ensure they can withstand disruptions.
Objective: Ensure key stakeholders understand their responsibilities in resilience governance.
Actions:
Example:
Objective: Implement monitoring frameworks to track resilience performance and compliance.
Actions:
Example:
AmBank’s Resilience Dashboard provides real-time visibility into critical system performance, cyber threats, and third-party risks. This enables senior management to take proactive measures to mitigate disruptions.
Objective: Make resilience a core part of business strategy, risk management, and operational decision-making.
Actions:
Example:
Before launching a new digital banking service, AmBank’s risk management team assesses its resilience by conducting cyber resilience testing and validating cloud service providers’ ability to meet the bank’s impact tolerances.
Developing and embedding governance in operational resilience ensures that AmBank Malaysia can proactively manage risks, protect critical business services, and maintain financial stability.
By implementing a structured governance approach with clear policies, accountability, monitoring, and a strong risk culture, the bank strengthens its ability to withstand disruptions while maintaining customer trust and regulatory compliance.
| Operational Resilience Framework: A Case Study of AmBank Malaysia | |||||
| "Plan" Phase of the Operational Resilience Planning Methodology | |||||
| C2 | C3 | C4 | C5 | C6 | C7 |
To learn more about the course and schedule, click the buttons below for the OR-300 Operational Resilience Implementer course and the OR-5000 Operational Resilience Expert Implementer course.
|
If you have any questions, click to contact us. |
||
|
|