Operational resilience is a critical component of financial institutions, ensuring that essential business services can withstand and recover from disruptions.
The financial industry, including banks like AmBank Malaysia, operates in an increasingly complex and interconnected environment where threats such as cyberattacks, IT failures, third-party service disruptions, and regulatory changes can pose significant risks.
Ensuring resilience is no longer just about recovery after an incident—it is about proactively defining the boundaries within which a business can operate before experiencing an unacceptable level of harm.
In the Implement phase of AmBank Malaysia’s Operational Resilience Planning Methodology, one of the key stages is Establishing Impact Tolerance.
This stage involves defining the maximum acceptable level of disruption that a critical business service can endure before it causes intolerable harm to customers, market integrity, or financial stability.
By setting clear impact tolerances, AmBank ensures that it can maintain financial stability, regulatory compliance, and customer trust, even in the face of unexpected disruptions.
The process involves identifying critical business services, assessing risks, defining acceptable disruption limits, conducting stress testing, and continuously improving resilience measures.
Before setting impact tolerances, AmBank must first determine which business services are critical. A critical business service is one that, if disrupted, would have a significant impact on customers or the financial system.
Example:
For each critical service, AmBank must define a threshold beyond which the disruption becomes unacceptable. This threshold could be measured in terms of time, volume, or service capacity.
Example:
AmBank must analyze different disruption scenarios and their potential impact on business services, customers, and market confidence. These scenarios should be based on past incidents, industry trends, and regulatory expectations.
Example:
To validate the established impact tolerances, AmBank must conduct stress testing and simulation exercises. These tests assess whether the bank’s existing controls and mitigation strategies can keep disruptions within acceptable limits.
Example:
Once impact tolerances are validated, they must be integrated into AmBank’s incident response, crisis management, and recovery planning processes. Clear escalation protocols and decision-making frameworks should be established to ensure that the bank can act swiftly when an incident occurs.
Example:
Impact tolerances should not be static; they must evolve based on changing business environments, regulatory updates, and emerging risks. AmBank should establish a regular review cycle to reassess and refine its impact tolerances.
Example:
To facilitate a structured review process, AmBank Malaysia’s management can utilise the following template to document impact tolerances across all critical business services:
|
Critical Business Service |
Maximum Allowable Downtime |
Key Risks Identified |
Mitigation Strategies |
Testing & Validation Results |
Review Frequency |
|
Online Banking Services |
4 hours |
Cyberattacks, IT failure |
Redundant servers, cybersecurity enhancements |
Passed stress test in Q1 |
Quarterly |
|
Corporate Treasury Operations |
2 hours |
Liquidity risks, system outages |
Backup processing systems |
Pending re-evaluation |
Semi-Annual |
|
Cheque Clearing Services |
1 business day |
Third-party failure, processing delays |
Alternative clearinghouse partnerships |
Successful test in Q2 |
Annual |
|
ATM Network Availability |
3 hours |
Power failure, software issues |
Generator backups, real-time monitoring |
Passed the emergency drill |
Quarterly |
|
Card Payment Processing |
2 hours |
Third-party service provider outage |
Multi-provider failover system |
Partial failure in Q3 test |
Monthly |
By establishing well-defined impact tolerances, AmBank Malaysia ensures that its critical business services remain resilient, even in the face of operational disruptions.
This proactive approach strengthens financial stability, regulatory compliance, and customer trust, ensuring that the bank can respond swiftly and effectively to any crisis.
The process of defining impact tolerances is not a one-time activity but an ongoing effort that requires continuous assessment, scenario planning, and adaptation to emerging risks.
As financial institutions face an increasingly complex risk landscape, operational resilience must be embedded into the core of business continuity and risk management frameworks.
AmBank’s commitment to refining its impact tolerance methodology ensures that it remains at the forefront of resilience planning, safeguarding its reputation and the financial well-being of its customers.
By continuously improving and stress testing its operational resilience framework, AmBank Malaysia can confidently navigate disruptions and maintain its role as a trusted financial institution in Malaysia’s banking sector.
Operational Resilience Framework: A Case Study of AmBank Malaysia |
|||||
"Implement" Phase of the Operational Resilience Planning Methodology |
|||||
| C8 | C9 | C10 | C11 | C12 | C13 |
To learn more about the course and schedule, click the buttons below for the OR-300 Operational Resilience Implementer course and the OR-5000 Operational Resilience Expert Implementer course.
|
If you have any questions, click to contact us. |
||
|
|