.

Operational Resilience in Practice: The Brunei Darussalam Central Bank Approach
OR BB FI MY Gen-20

[OR] [BDCB] [E3] [CBS] [2] [ITo] Establish Impact Tolerances

[OR] [BDCB] [Full Banner] Operational Resilience at BDCB A Strategic Implementation Guide

Setting an Impact Tolerance for CBS-2 Currency Management enables Brunei Darussalam Central Bank (BDCB) to define the maximum disruption that may be allowed before the consequences become unacceptable to the public, financial institutions, government stakeholders, the integrity of the national currency, or the wider financial system.

The tolerance must be based on the harm resulting from disruption rather than solely on how quickly an individual system, facility, or operational process can be recovered.

Impact Tolerance is therefore an end-to-end service boundary. It considers whether BDCB can continue providing an adequate, secure, and trustworthy supply of banknotes and coins across Brunei Darussalam despite disruption to forecasting, production, storage, distribution, authentication, accounting, security, or supporting technology.

The BCM Institute methodology similarly describes Impact Tolerance as the maximum tolerable level of disruption to a critical business service and recommends expressing it through measurable outcomes such as duration, data loss, financial impact, and customer effect.

New call-to-action

Dr Goh Moh Heng
Operational Resilience Certified Planner-Specialist-Expert
New call-to-action

New call-to-action

CBS-2 Currency Management

Introduction


New call-to-action[OR] [BDCB] [E3] [CBS] [2] [ITo] Loan and Financing Operations

Setting an Impact Tolerance for CBS-2 Currency Management enables Brunei Darussalam Central Bank (BDCB) to define the maximum disruption that may be allowed before the consequences become unacceptable to the public, financial institutions, government stakeholders, the integrity of the national currency, or the wider financial system.

The tolerance must be based on the harm resulting from disruption rather than solely on how quickly an individual system, facility, or operational process can be recovered.

New call-to-action

New call-to-action

Impact Tolerance is therefore an end-to-end service boundary. It considers whether BDCB can continue providing an adequate, secure, and trustworthy supply of banknotes and coins across Brunei Darussalam despite disruption to forecasting, production, storage, distribution, authentication, accounting, security, or supporting technology.

The BCM Institute methodology similarly describes Impact Tolerance as the maximum tolerable level of disruption to a critical business service and recommends expressing it through measurable outcomes such as duration, data loss, financial impact, and customer effect.

The assessment must consider all 15 Sub-Critical Business Services because a failure originating in one process may propagate across the currency lifecycle.

For example, corrupted inventory data may initially affect vault reconciliation but subsequently prevent authorised currency release, delay replenishment to financial institutions, impair management reporting, and reduce confidence in the accuracy of currency-in-circulation records.

Cyber and ICT risks are integrated throughout this assessment rather than treated as a separate technology exercise. Ransomware, unauthorised access, database corruption, network failure, failed technology changes, processing-equipment outages, loss of surveillance, and third-party ICT disruption can directly affect BDCB’s ability to safeguard, account for, process, and distribute currency.

The Impact Tolerance must therefore measure the resulting service harm regardless of whether the originating cause is physical, operational, technological, cyber-related, or external.

For this assessment, the five harm levels are interpreted as follows:

  • Very Low: Minor internal inconvenience with no material effect on currency availability, integrity, or stakeholders.
  • Low: Limited service degradation that can be managed through normal procedures without material external impact.
  • Medium: Noticeable operational disruption affecting some institutions, processes, or service channels, but with effective workarounds available.
  • High: Material disruption affecting currency availability, service integrity, multiple institutions, or important obligations, with limited remaining workarounds.
  • Very High: Disruption that creates or is close to creating unacceptable harm, including widespread cash shortages, loss of currency integrity, significant security compromise, systemic financial-sector effects, or serious loss of public confidence.

This expanded scale is consistent with the underlying principle that organisations should distinguish inconvenience, material harm, and intolerable harm when setting Impact Tolerances.

Banner [Table] [OR] [E3] Establish Impact Tolerance

Table 1: Impact Tolerance Assessment

Sub-CBS Code

Name of Sub-CBS

Potential Disruption

Potential Harm

Level of Harm

Key Harm Indicators

CBS-2.1

Currency Demand Forecasting

Forecasting data becomes unavailable, incomplete, corrupted, or materially inaccurate; demand models fail to reflect seasonal, institutional, or emergency requirements.

BDCB may underestimate denomination and reserve-stock requirements, causing later shortages, emergency procurement, inefficient inventory allocation, or inability to meet exceptional cash demand. Overestimation may create unnecessary production, storage, insurance, and custody exposure. Harm is generally delayed rather than immediate but can become serious if the error remains undetected.

Medium under short-term disruption; High where inaccurate forecasts affect a major production or replenishment cycle.

Duration of forecasting outage; age and completeness of source data; forecast variance against actual demand; number of denominations affected; projected reserve-stock shortfall; number of institutions whose projected demand cannot be met; time remaining before production or procurement decisions.

CBS-2.2

Currency Production Planning

Production schedules cannot be completed, approved, amended, or communicated; denomination requirements or contingency reserves are incorrectly planned.

Production may be initiated too late, in the wrong quantities, or with an unsuitable denomination mix. Extended disruption could reduce strategic currency reserves and increase reliance on existing stock, emergency procurement, or accelerated external manufacturing.

Medium, escalating to High where reserve levels approach minimum thresholds or a scheduled production window is missed.

Duration of planning delay; production decision deadlines missed; percentage reduction in projected reserve coverage; denominations below approved stock thresholds; number of unresolved production approvals; estimated lead-time extension.

CBS-2.3

Currency Procurement and Manufacturing Oversight

Currency production, secure procurement, quality inspection, acceptance, or shipment is delayed or interrupted by manufacturer failure, geopolitical restrictions, quality defects, cyberattack, transport disruption, or loss of production records.

BDCB may be unable to replenish strategic reserves or introduce required currency stock. Defective or non-compliant notes or coins may be accepted, while prolonged supply interruption could ultimately constrain national currency availability.

High, becoming Very High when reserve stock is insufficient to absorb the manufacturing or delivery delay.

Production milestone slippage; percentage of order delayed or rejected; number of denominations affected; remaining reserve-stock coverage; quality failure rate; secure shipment delays; supplier recovery estimate; availability of alternate manufacturing arrangements.

CBS-2.4

Currency Inventory and Vault Management

Vault access is lost; inventory records are unavailable or inconsistent; physical stock cannot be located, released, received, reconciled, or securely controlled.

Currency may be physically available but operationally unusable. BDCB could be unable to meet withdrawal requests, accept returned currency, confirm stock availability, or demonstrate custody integrity. A security or reconciliation failure could create financial loss, investigation requirements, and serious loss of confidence.

Very High where authorised access, stock integrity, or nationwide release capability is materially affected.

Duration of vault inaccessibility; value and denominations inaccessible; percentage of national operational stock affected; reconciliation variance; number of delayed releases; number of affected financial institutions; security-control status; ability to activate an alternate vault or manual register.

CBS-2.5

Currency Distribution and Replenishment

Currency orders cannot be received or fulfilled; dispatch scheduling, secure transportation, hand-over, or confirmation fails; access to distribution facilities or routes is disrupted.

Financial institutions may be unable to replenish cash holdings, potentially affecting branches, cash points, businesses, government payments, and public access to physical currency. Widespread or prolonged disruption may affect confidence and economic activity.

Very High where disruption is nationwide, affects multiple institutions, or occurs during peak or emergency demand.

Duration of distribution suspension; number and proportion of financial institutions affected; geographic areas affected; value and denomination of unfulfilled orders; backlog age; number of missed dispatches; projected cash depletion at receiving institutions; availability of alternate routes and transport capacity.

CBS-2.6

Currency Receipt and Return Processing

Returned currency cannot be received, registered, counted, reconciled, or transferred for authentication and sorting.

Returned notes and coins may accumulate at financial institutions or receiving facilities. Processing congestion can reduce reusable stock, delay detection of counterfeit or damaged currency, create custody exposure, and eventually constrain the circulation cycle.

Medium, escalating to High when backlogs obstruct secure receipt capacity or reduce currency available for recirculation.

Duration of receipt suspension; volume and value awaiting processing; backlog age; percentage of receiving capacity consumed; number of institutions unable to return currency; unreconciled consignments; effect on available fit-currency inventory.

CBS-2.7

Currency Authentication and Quality Verification

Authentication equipment, reference data, specialist capability, or examination facilities become unavailable; counterfeit detection or quality verification is degraded.

Suspected counterfeit or unsuitable currency may not be identified promptly. Legitimate returned currency may also be withheld unnecessarily, reducing available stock. A prolonged control failure could weaken confidence in the authenticity and quality of currency in circulation.

High, becoming Very High if counterfeit currency is released, material authenticity uncertainty exists, or national confidence is threatened.

Duration of authentication outage; volume awaiting verification; number and value of suspected counterfeits; false acceptance or rejection rate; percentage of verification capacity unavailable; number of institutions affected; age of counterfeit alerts; volume released under exceptional procedures.

CBS-2.8

Currency Fitness Sorting and Recirculation Management

Sorting machines, processing software, classification criteria, or operators become unavailable; fit and unfit currency cannot be separated accurately.

Fit currency may not be returned to circulation, increasing dependence on new stock. Unfit notes may remain in circulation, lowering currency quality. Incorrect sorting could send usable currency for destruction or unsuitable currency for redistribution.

High where disruption materially reduces recirculation capacity or sorting accuracy.

Sorting capacity unavailable; volume and value of unsorted currency; backlog age; fit-note yield; sorting error rate; recirculation shortfall; denomination availability; percentage reliance on new stock; machine recovery time.

CBS-2.9

Counterfeit Currency Investigation and Reporting

Case records, forensic analysis, intelligence exchange, specialist investigators, or reporting channels are unavailable or compromised.

Counterfeit trends may not be identified or communicated promptly. Financial institutions and law-enforcement bodies may lack actionable information, enabling continued circulation and weakening confidence in national currency integrity.

High, escalating to Very High during a widespread or sophisticated counterfeit event.

Number and value of uninvestigated cases; age of outstanding alerts; institutions awaiting guidance; geographic spread; repeat counterfeit patterns; reporting delay; suspected organised-crime involvement; number of unresolved forensic examinations.

CBS-2.10

Currency Destruction and Disposal Management

Destruction equipment, approvals, witnessed controls, reconciliation records, or secure disposal arrangements become unavailable.

Unfit currency accumulates in secure storage, consuming vault capacity and increasing custody, security, and accounting exposure. Incorrect or unauthorised destruction could create irrecoverable financial and evidential consequences.

Medium for a controlled short-term postponement; Very High where destruction integrity, authorisation, or reconciliation is compromised.

Duration of destruction suspension; value and volume awaiting destruction; storage capacity consumed; unreconciled destruction batches; security incidents; control exceptions; witness or approval gaps; variances between destruction and accounting records.

CBS-2.11

Currency Accounting and Reconciliation

General ledger interfaces, inventory records, transaction journals, reconciliation tools, or source data become unavailable, corrupted, or inconsistent.

BDCB may be unable to confirm currency issued, held, returned, destroyed, or in circulation. Unresolved differences could prevent further physical movements, compromise financial reporting, conceal loss or fraud, and weaken accountability.

Very High where material balances cannot be verified or currency movements continue without reliable reconciliation.

Duration of reconciliation outage; value and number of unreconciled movements; ledger-to-physical variance; data-loss period; number of interfaces unavailable; age of outstanding breaks; manual entries awaiting verification; reporting deadlines at risk.

CBS-2.12

Currency Security and Custody Management

Physical security, access control, surveillance, alarm monitoring, dual-control arrangements, secure transport protection, or custody records fail or are compromised.

Currency assets, personnel, facilities, and sensitive information may be exposed to theft, sabotage, fraud, unauthorised access, or loss. Failure may require immediate suspension of vault, processing, or distribution operations and can affect nearly every Currency Management process.

Very High because security and custody are pervasive dependencies across the service.

Security systems unavailable; unauthorised-access attempts; number of facilities affected; surveillance coverage lost; duration of dual-control failure; custody exceptions; transport movements suspended; value of currency exposed; confirmed or suspected loss.

CBS-2.13

Currency Information and Operational Monitoring

Monitoring dashboards, stock alerts, operational reports, performance data, or incident-detection mechanisms become unavailable or inaccurate.

Management may not identify emerging shortages, processing backlogs, control failures, or service degradation in time to intervene. Delayed escalation could allow an otherwise manageable incident to develop into an Impact Tolerance breach.

High where BDCB loses end-to-end situational awareness across multiple Sub-CBS processes.

Duration of monitoring loss; number of unavailable data feeds; age of last verified position; percentage of processes operating without current status; alerts missed; management reports delayed; discrepancies between local and central monitoring; unresolved threshold breaches.

CBS-2.14

Currency Incident Management and Service Recovery

Incident command, crisis communications, escalation, continuity procedures, recovery coordination, decision-making, or alternate-site activation fails.

BDCB may respond inconsistently or too slowly to a disruption, causing avoidable delays, duplicated actions, poor stakeholder communication, and cascading failure across Currency Management. The originating incident may therefore remain unresolved beyond the service tolerance.

Very High, particularly when multiple processes, facilities, institutions, or cyber and physical threats are involved.

Time to detect, declare, and escalate; time to activate response teams; number of unfilled critical roles; recovery milestones missed; stakeholder notification delay; decisions awaiting approval; effectiveness of manual workarounds; estimated time to service stabilisation.

CBS-2.15

Regulatory Reporting and Continuous Service Improvement

Incident, risk, control, audit, performance, and remediation information cannot be consolidated, reported, or acted upon.

Immediate currency delivery may continue, but unresolved weaknesses may recur or worsen. Material incidents may not be reported accurately or promptly, management may lack assurance, and remediation investment may be delayed.

Medium for short-term reporting delay; High where significant incidents, control deficiencies, or overdue remediation remain undisclosed or unmanaged.

Reporting deadlines missed; number of incomplete incident reports; overdue remediation actions; repeat findings; unresolved risk acceptances; age of management information; audit issues overdue; number of lessons not incorporated into procedures or tests.

Observations from the Harm Assessment

The highest-harm processes are those that directly control the physical availability, integrity, security, and release of currency:

  • CBS-2.4 Currency Inventory and Vault Management
  • CBS-2.5 Currency Distribution and Replenishment
  • CBS-2.7 Currency Authentication and Quality Verification
  • CBS-2.11 Currency Accounting and Reconciliation
  • CBS-2.12 Currency Security and Custody Management
  • CBS-2.13 Currency Information and Operational Monitoring
  • CBS-2.14 Currency Incident Management and Service Recovery

These processes form the immediate operational chain through which currency is held, authorised, moved, validated, protected, accounted for, monitored, and restored. Failure in any one of them may prevent BDCB from using otherwise available physical stock.

Processes such as demand forecasting, production planning, procurement, and manufacturing oversight generally have longer disruption horizons because currency reserves and existing circulation provide some buffer. Nevertheless, their harm can become very high when disruption persists, coincides with increased demand, affects a critical denomination, or exhausts existing reserves.

The assessment therefore demonstrates why the tolerance cannot be expressed only as a single system-recovery deadline. Some failures create immediate unacceptable harm, particularly loss of security or data integrity. Others become intolerable through duration, geographic spread, backlog accumulation, reserve depletion, or the number of institutions affected.

Table 2: Cyber and ICT Risk Integration, Proactive Controls and Evidence

Sub-CBS Code

Name of Sub-CBS

Cyber and ICT Risk Linkage

Contribution to Impact Tolerance Breach

Proactive Risk Management Action

Evidence of Proactive Risk Management

CBS-2.1

Currency Demand Forecasting

Data-feed interruption, model corruption, unauthorised alteration of assumptions, database failure, ransomware, failed analytical-platform change, or loss of source-system interfaces could produce incomplete or inaccurate forecasts.

A compromised forecast may not cause immediate service failure but can create a future reserve shortfall, unsuitable denomination mix, or inability to respond to peak demand. Undetected data-integrity failure is more serious than a visible outage because decisions may continue using false information.

Validate source data against independent records; apply model governance and version control; restrict privileged access; maintain offline forecast templates; retain historical datasets; perform reasonableness checks and forecast back-testing; establish manual demand-estimation procedures.

Approved model-risk assessments; access reviews; change records; data-quality reports; forecast-variance analysis; backup-restoration tests; manual-workaround exercises; management approval of key assumptions.

CBS-2.2

Currency Production Planning

Planning application failure, workflow outage, document corruption, loss of approval records, unauthorised schedule changes, or network failure affecting communication with procurement and production stakeholders.

Delayed or manipulated production plans can cause missed manufacturing windows or inadequate reserve replenishment. A prolonged outage becomes material as decision deadlines and supplier lead times are exhausted.

Maintain controlled offline copies of approved plans; implement multi-level authorisation; digitally verify plan changes; test alternate communication channels; define planning decision deadlines and escalation triggers; back up production specifications and schedules.

Approval logs; segregation-of-duties reviews; workflow audit trails; backup test results; alternate-communications exercises; change-management records; planning contingency procedure tests.

CBS-2.3

Currency Procurement and Manufacturing Oversight

Third-party cyberattack, supplier ICT outage, compromise of currency specifications, secure-file-transfer failure, production-system disruption, data leakage, or technology concentration at a single manufacturer.

A supplier outage may delay production or delivery beyond reserve coverage. Compromised specifications or quality records could also affect the security and authenticity of newly manufactured currency.

Conduct supplier cyber and operational resilience due diligence; require incident notification and recovery commitments; secure and encrypt specification exchanges; maintain independent specification verification; assess alternate production sources; monitor milestone and concentration risk.

Third-party risk assessments; contractual resilience clauses; supplier assurance reports; independent quality-test records; secure-transfer logs; business continuity test evidence; concentration-risk reviews; supplier remediation reports.

CBS-2.4

Currency Inventory and Vault Management

Inventory database failure, access-control compromise, privileged-access abuse, ransomware, surveillance outage, network failure, time-synchronisation failure, or corruption of stock records.

Loss of reliable inventory or secure vault access can immediately prevent currency release and receipt. If physical and digital records cannot be reconciled, operations may need to stop even when currency remains available.

Use highly available inventory platforms; maintain immutable transaction logs; implement strong privileged-access management and multifactor authentication; retain controlled manual vault registers; provide redundant surveillance and access systems; perform regular physical-to-system reconciliation; test alternate-vault operations.

Failover reports; physical inventory counts; reconciliation results; privileged-access reviews; CCTV and access-control test records; cyber monitoring logs; penetration-test findings; alternate-vault exercise reports; exception investigations.

CBS-2.5

Currency Distribution and Replenishment

Order-management failure, network outage, denial-of-service attack, dispatch-system failure, interface disruption with financial institutions, mobile communications loss, or compromise of transport schedules.

BDCB may be unable to receive, prioritise, authorise, or dispatch replenishment requests. Compromised routing or order data could create security exposure or send incorrect denominations and quantities. A multi-institution outage could breach the tolerance rapidly.

Establish authenticated alternate order channels; maintain offline dispatch procedures; provide redundant communications; validate high-value orders through independent confirmation; separate sensitive transport information; maintain alternate routing and transport arrangements; test manual order fulfilment.

Distribution continuity-test reports; alternate-channel tests; transport-provider assurance; dispatch audit trails; communication-resilience tests; order-reconciliation results; scenario tests involving widespread bank demand.

CBS-2.6

Currency Receipt and Return Processing

Receipt-registration failure, barcode or tracking-system outage, counting-equipment failure, interface disruption, ransomware, or corruption of consignment records.

Returned currency may become untraceable or remain unprocessed. Accumulating backlog can consume secure storage and reduce currency available for authentication and recirculation, eventually affecting supply.

Maintain manual consignment registers and pre-numbered custody records; provide equipment redundancy; isolate processing equipment where appropriate; reconcile all received items at hand-offs; prioritise high-value and high-risk returns; monitor backlog thresholds.

Equipment-maintenance records; manual-processing test results; custody reconciliations; backlog dashboards; restoration tests; incident logs; exception reports; periodic end-to-end consignment tracing.

CBS-2.7

Currency Authentication and Quality Verification

Authentication-device compromise, malware, obsolete detection software, reference-database corruption, failed software updates, loss of connectivity, or manipulation of detection thresholds.

Counterfeit or unsuitable currency could be incorrectly accepted, while genuine currency could be rejected and withheld. A common technology defect across all devices creates a major concentration risk.

Use layered authentication methods; validate device software and signature updates; retain specialist manual examination capability; segregate devices from unnecessary networks; test sample accuracy; maintain equipment from more than one operational pool where feasible; preserve offline reference materials.

Device-certification records; calibration results; software-integrity checks; vulnerability assessments; false-acceptance and rejection reports; manual-examination competency records; independent sample-test results; equipment failover exercises.

CBS-2.8

Currency Fitness Sorting and Recirculation Management

Sorting-machine failure, capacity degradation, control-software defect, malicious code, database corruption, failed configuration change, or common-component failure across processing machines.

Recirculation capacity may fall below demand and create a growing backlog. Incorrect classification can reduce currency quality or destroy usable stock. Common technology concentration may disable the entire sorting operation.

Maintain redundant processing capacity; control and test configuration changes; monitor throughput and error rates; retain manual or semi-automated fallback procedures; hold critical spare parts; establish preventive maintenance and alternate processing arrangements.

Capacity reports; machine-availability logs; maintenance records; change-test results; sorting-quality reports; spare-parts inventory; recovery exercises; throughput stress-test results.

CBS-2.9

Counterfeit Currency Investigation and Reporting

Case-management outage, theft of sensitive intelligence, unauthorised case alteration, forensic-tool failure, malware, loss of secure communications, or third-party information-sharing disruption.

Counterfeit intelligence may be delayed, incomplete, or exposed. Failure to detect patterns or warn financial institutions can allow wider circulation and increase public and market harm.

Encrypt case data; restrict access by role and need; maintain secure alternate communication with relevant authorities; preserve forensic evidence offline; back up case records; test information-sharing procedures; monitor for unauthorised access and data exfiltration.

Access logs; data-loss-prevention alerts; backup-restoration tests; case-file audits; secure communication tests; incident-response records; forensic chain-of-custody reviews; inter-agency exercise reports.

CBS-2.10

Currency Destruction and Disposal Management

Destruction-control software failure, manipulation of batch records, loss of video evidence, access-control compromise, sensor failure, ransomware, or corruption of destruction certificates.

BDCB may be unable to prove that authorised currency was destroyed completely and accurately. Unauthorised or unreconciled destruction is irreversible and can create severe financial, security, legal, and reputational consequences.

Enforce dual authorisation and witnessed destruction; reconcile pre- and post-destruction quantities independently; retain immutable evidence; separate destruction control from accounting approval; maintain manual shutdown and safety procedures; test security and surveillance continuity.

Destruction certificates; independent reconciliation reports; surveillance-retention logs; access records; control-test results; witnessed sample reviews; incident reports; internal audit findings.

CBS-2.11

Currency Accounting and Reconciliation

Ledger outage, interface failure, data corruption, ransomware, unauthorised journal entries, time-sequence failure, database loss, or unsuccessful system change.

BDCB may lose the authoritative record of currency balances and movements. Operations may need to be suspended until integrity is restored, and continued processing could increase unquantified exposure.

Use resilient ledger and reconciliation architecture; maintain immutable source journals; enforce maker-checker controls; reconcile critical movements promptly; define a near-zero data-loss objective for confirmed movements; test point-in-time recovery; monitor interfaces and unusual entries.

Disaster-recovery reports; restoration and data-integrity tests; reconciliation break reports; journal-access reviews; interface-monitoring records; database backup evidence; independent assurance; management review of material variances.

CBS-2.12

Currency Security and Custody Management

Cyber compromise of access control, surveillance, alarms, identity platforms, communications, or transport-tracking systems; privileged-access abuse; coordinated cyber-physical attack; infrastructure or power failure.

A cyber event could create physical access, disable monitoring, reveal sensitive movement details, or force suspension of vault and transport operations. Because the security capability supports most Sub-CBS processes, disruption can cause a rapid service-wide breach.

Segregate physical-security networks; implement defence-in-depth and independent alarm channels; restrict privileged access; provide backup power and communications; maintain manual guards and physical controls; test coordinated cyber-physical incident response; protect transport data.

Security penetration-test reports; access recertification; alarm and backup-power tests; cyber-physical exercise reports; surveillance availability records; privileged-session monitoring; physical-security inspections; remediation tracking.

CBS-2.13

Currency Information and Operational Monitoring

Monitoring-platform outage, corrupted dashboards, data-feed interruption, alert suppression, denial-of-service attack, capacity overload, or common identity-service failure.

Management may operate with an inaccurate service picture and fail to recognise that stock, processing, distribution, or security thresholds are deteriorating. This can delay intervention until the Impact Tolerance is exceeded.

Implement independent monitoring paths for critical indicators; verify dashboard data against source records; maintain manual status-reporting templates; provide redundant communications; prioritise alerts; define escalation thresholds; test monitoring during system and network outages.

Monitoring-availability reports; alert-test records; data-reconciliation reports; capacity tests; manual situation-report exercises; incident-detection metrics; network-resilience tests; management review records.

CBS-2.14

Currency Incident Management and Service Recovery

Incident-management platform failure, communications outage, ransomware affecting crisis records, loss of staff contact information, unavailable recovery documentation, or inaccessible emergency facilities.

Response teams may be unable to coordinate decisions, communicate with financial institutions, prioritise scarce currency, or activate alternate arrangements. Delayed recovery directly increases the likelihood that service disruption exceeds tolerance.

Maintain offline response plans and contact lists; provide out-of-band communications; pre-authorise emergency decisions; establish alternate command facilities; cross-train critical roles; conduct integrated cyber, facility, logistics, and currency-shortage exercises; track recovery against tolerance milestones.

Exercise reports; call-tree tests; alternate-site activation records; incident-response metrics; crisis-communication tests; role-training records; lessons-learned reports; management committee minutes; remediation status.

CBS-2.15

Regulatory Reporting and Continuous Service Improvement

Reporting-platform failure, incomplete incident data, document-management outage, unauthorised report alteration, loss of evidence, or cyber disruption affecting remediation tracking.

BDCB may not identify recurring weaknesses or demonstrate that severe incidents and control deficiencies are being managed. Delayed remediation can leave known vulnerabilities capable of causing a future tolerance breach.

Maintain controlled evidence repositories; protect report integrity through access and version controls; reconcile reporting data to source systems; track remediation with accountable owners and deadlines; escalate overdue high-risk actions; retain offline copies of critical reports.

Approved reports; version histories; committee minutes; risk acceptance records; remediation dashboards; audit trails; independent review findings; closure evidence; follow-up scenario-test results.

 

Recommended Impact Tolerance for CBS-2 Currency Management

Proposed Overall Tolerance

An indicative Impact Tolerance for CBS-2 Currency Management should be expressed as a combination of time, service availability, geographic scope, institutional impact, physical currency availability, data integrity, and security outcomes.

Illustrative implementation recommendation

BDCB should remain capable of authorising and releasing essential currency to the financial system throughout a disruption and should restore any material interruption to core vault access, currency release, receipt, authentication, accounting, security, and distribution capabilities within four hours of confirmed service impact.

No disruption should result in an unverified loss of currency, release of unauthenticated currency, material corruption of currency inventory or accounting records, or loss of custody integrity.

A disruption should not prevent more than 25% of participating financial institutions from obtaining essential currency replenishment for longer than four hours during the applicable operating period, and nationwide essential replenishment capability should not be unavailable for more than two hours without activation of approved contingency arrangements.

This tolerance is deliberately multi-dimensional. A time measure alone would not address an immediate integrity or security failure, while a scope measure alone would not capture a prolonged disruption affecting one critical geographic area or institution.

Supporting Tolerance Dimensions

Tolerance Dimension

Indicative Boundary

Core service disruption duration

No more than four hours of material disruption to essential vault access, currency release, receipt, authentication, reconciliation, security, or distribution capability.

Nationwide distribution capability

No more than two hours without an operational method for receiving, prioritising, authorising, and initiating essential replenishment requests, including contingency channels.

Emergency currency release

BDCB should be capable of initiating an authorised emergency currency release within two hours of approval and commencing physical dispatch within four hours, subject to security and transport conditions.

Institutional scope

No more than 25% of participating financial institutions should be unable to access essential replenishment beyond four hours. No critical institution or geographic area should be left without an agreed contingency route where cash depletion is imminent.

Geographic scope

A localised disruption should not become a nationwide inability to distribute currency. Alternate routes or facilities should be available before local stock depletion creates public harm.

Currency availability

Essential denominations should remain available above management-approved minimum operational and contingency stock levels. No denomination should fall below its emergency distribution threshold without escalation and controlled allocation.

Processing degradation

Authentication, sorting, receipt, and return processing may operate at reduced capacity temporarily, but the backlog should not exceed secure storage capacity or reduce fit-currency availability below the emergency replenishment requirement.

Data latency

Critical stock, vault, dispatch, receipt, and reconciliation positions should not remain unverified for more than one hour during active currency movements. Management should receive a validated service position at least hourly during a material incident.

Data loss

No permanent loss of confirmed currency-movement, custody, destruction, or accounting records should be accepted. Any reconstructed records must be independently verified before normal processing resumes.

Data integrity

Any material uncertainty about physical stock, custody, authenticity, or accounting balances should trigger controlled suspension of affected movements until integrity is established. There should be no tolerance for knowingly releasing currency using materially corrupted or unverified records.

Security and custody

There should be zero tolerance for uncontrolled vault access, unaccounted currency loss, unauthorised destruction, or release without required custody controls. A security-control failure may require immediate service restriction even before the time threshold is reached.

Counterfeit and authenticity control

No material volume of currency should be released where authentication integrity is uncertain. Suspected systemic compromise of authentication capability should be treated as an immediate potential tolerance breach.

Regulatory and statutory effect

No disruption should cause a material inability to fulfil BDCB’s currency responsibilities, conceal a significant incident, compromise required records, or prevent timely escalation to the appropriate governance authority.

Public and financial-system harm

The tolerance is breached before cash shortages become widespread, public access to essential cash is materially restricted, currency authenticity is reasonably questioned, or financial institutions are forced to curtail critical cash services.

 

Point at Which Harm Becomes Severe or Intolerable

The Impact Tolerance should be considered breached when one or more of the following conditions occur:

  • BDCB cannot authorise or release essential currency within the four-hour service boundary.
  • Nationwide currency-replenishment initiation is unavailable for more than two hours without a viable contingency method.
  • More than 25% of participating financial institutions cannot obtain essential replenishment beyond four hours.
  • A significant geographic area is approaching cash depletion without an executable replenishment route.
  • Physical inventory cannot be reconciled reliably to custody and accounting records.
  • Currency has been lost, stolen, released without required authority, or destroyed without complete reconciliation.
  • Authentication integrity is compromised and potentially counterfeit or unsuitable currency may have entered circulation.
  • A security failure prevents safe continuation of vault, processing, or transport operations.
  • Corrupted data prevents BDCB from establishing a trusted currency position.
  • Disruption creates widespread cash shortages, threatens currency integrity, materially affects financial-sector operations, or risks serious loss of public confidence.
  • Management cannot obtain an accurate end-to-end service position or coordinate effective recovery before other thresholds are exceeded.
Rationale for the Proposed Impact Tolerance

Currency Management differs from continuously available digital services because physical currency is held in reserves, already exists in circulation, and is distributed through multiple financial institutions.

These characteristics provide limited buffering against a short central operational disruption. However, this buffer does not eliminate the need for a demanding tolerance.

A relatively short tolerance is appropriate for vault access, authorisation, accounting, security, and emergency distribution because failure in these areas can prevent BDCB from using the physically available currency stock. The tolerance must also be stricter during:

  • Peak public-demand periods;
  • Major holidays or salary-payment periods;
  • Natural hazards or national emergencies;
  • Disruption to electronic payment channels;
  • Exceptional withdrawals by financial institutions;
  • A counterfeit or security event;
  • Concurrent failure of transport, facilities, or communications; or
  • Cyber incidents affecting multiple Currency Management processes.

The recommended thresholds are intended to establish the point before operational degradation causes unacceptable external harm. They are not statements of existing BDCB

capability or public commitments.

Relationship to RTO, RPO, MTPD and SLA

The proposed Impact Tolerance must not be treated as interchangeable with supporting recovery and performance measures.

Recovery Time Objective

An RTO defines the targeted time for recovering a particular system, process, facility, or resource. Several RTOs may support the four-hour Currency Management Impact Tolerance. For example, the inventory platform may require a shorter RTO because staff needs time after recovery to validate data, reconcile stock, approve releases, and commence distribution.

A system recovered at the four-hour boundary would not demonstrate compliance if the overall Currency Management service remained unavailable beyond that point.

Recovery Point Objective

An RPO defines the maximum targeted period of data that may be lost following an incident. For confirmed currency movements, custody transfers, destruction records, and accounting entries, BDCB should adopt an extremely low or near-zero data-loss position supported by journals, replication, immutable logs, and manual source records.

Meeting an RPO does not itself demonstrate that the service remains within Impact Tolerance. Restored data must also be accurate, complete, reconciled, and usable.

Maximum Tolerable Period of Disruption

An MTPD normally identifies the maximum period for which an activity can remain disrupted before its viability or objectives are seriously affected. It can help determine process recovery priorities but may focus more narrowly on individual activities or organisational consequences.

The Impact Tolerance is set from the perspective of harm caused by disruption to the end-to-end Critical Business Service. It may therefore be shorter than the MTPD of some supporting processes.

Service Level Agreement

An SLA establishes expected performance between service providers and recipients. A supplier might comply with a contractual SLA while BDCB still breaches its Currency Management Impact Tolerance because several providers, processes, or facilities fail concurrently.

Supplier recovery commitments should therefore be calibrated to leave BDCB sufficient time to complete its own verification, decision-making, processing, and service-restoration activities.

Critical Sub-CBS for Remaining Within Tolerance

Although every Sub-CBS supports Currency Management, the following require particularly strong recovery and resilience arrangements:

CBS-2.4 Currency Inventory and Vault Management

This is the control point for physical availability. Inventory records, authorised access, custody controls, and alternate storage arrangements must remain reliable during disruption.

CBS-2.5 Currency Distribution and Replenishment

This is the primary delivery mechanism to financial institutions. Alternate ordering channels, secure transport capacity, prioritisation criteria, and emergency distribution arrangements are essential.

CBS-2.7 Currency Authentication and Quality Verification

Currency should not be recirculated when authenticity or quality cannot be established. BDCB needs both technology-based and specialist manual verification capability.

CBS-2.11 Currency Accounting and Reconciliation

Currency movements cannot continue safely without trusted records. Recovery arrangements must preserve transaction sequence, evidence, approval, and physical-to-ledger reconciliation.

CBS-2.12 Currency Security and Custody Management

Security failure can force the suspension of multiple operational processes. Resilience must cover physical, cyber, personnel, communications, surveillance, and transport controls.

CBS-2.13 Currency Information and Operational Monitoring

Management needs timely and accurate information to detect deterioration, allocate scarce stock, invoke contingency arrangements, and prevent an incident from exceeding tolerance.

CBS-2.14 Currency Incident Management and Service Recovery

Effective command, escalation, communication, and recovery coordination determine whether disruption is contained within the tolerance. Scenario testing is intended to assess whether a critical business service can remain within its approved tolerance under severe but plausible conditions.

Proactive Risk Management Priorities

To reduce the probability and impact of an Impact Tolerance breach, BDCB should implement a coordinated programme covering prevention, detection, response, recovery, and adaptation.

Establish Minimum Currency Stock and Capacity Triggers

BDCB should define minimum operational, contingency, and strategic reserve thresholds by denomination. Triggers should account for normal demand, peak periods, electronic-payment disruption, delayed manufacturing, and emergency distribution requirements.

Evidence should include approved threshold methodologies, regular stock reports, exception escalations, and management decisions when reserves approach tolerance limits.

Reduce Facility and Technology Concentration

The assessment should identify whether a single vault, processing location, inventory platform, network, identity service, authentication technology, or transport arrangement could disable several Sub-CBS processes simultaneously.

Where concentration cannot be removed, BDCB should establish alternate facilities, manual procedures, spare capacity, diverse communications, protected equipment, and pre-approved contingency arrangements.

Protect Currency Data Integrity

Stock balances, movements, custody changes, authentication results, destruction records, and accounting entries should be protected by strong access controls, immutable logging, reconciliation, backup, and independent verification.

Data-integrity restoration should be tested rather than assuming that a technically successful backup restoration produces a trusted operational position.

Strengthen Cyber-Physical Resilience

Currency operations rely on the interaction of physical and digital controls. Scenario testing should therefore include attacks that disable access control, surveillance, communications, inventory systems, or transport information while physical operations are continuing.

Tests should evaluate whether BDCB can maintain secure custody, activate manual controls, identify unauthorised access, and restore trusted records.

Maintain Operational Workarounds

Manual procedures should exist for:

  • Receiving and authenticating emergency replenishment requests;
  • Recording vault withdrawals and deposits;
  • Maintaining custody hand-offs;
  • Prioritising financial institutions;
  • Tracking consignments;
  • Reconciling currency movements;
  • Reporting the operational position; and
  • Coordinating incident response.

Workarounds should be time-limited, controlled, adequately staffed, and tested at realistic transaction volumes.

Strengthen Third-Party and External-Entity Preparedness

Currency manufacturers, secure transport providers, specialist maintenance services, financial institutions, and relevant government or enforcement bodies should be included in resilience planning where their participation is necessary.

BDCB should understand their recovery capabilities, notification arrangements, capacity constraints, technology dependencies, and ability to support concurrent or nationwide disruption.

Conduct Integrated Scenario Testing

Scenarios should assume that disruption has occurred and examine whether BDCB can continue or restore Currency Management before the approved tolerance is exceeded. This approach focuses on response and recovery capability rather than relying only on preventive controls. (BCM Institute Blog)

Relevant severe-but-plausible scenarios include:

  • Simultaneous loss of the primary vault and inventory platform;
  • Ransomware affecting inventory, accounting, and operational monitoring;
  • Failure of secure distribution during a surge in public cash demand;
  • Extended manufacturer disruption combined with low reserve stock;
  • Compromise of authentication technology during a counterfeit campaign;
  • Coordinated cyber-physical attack on access control and surveillance;
  • Data corruption creating uncertainty over currency balances;
  • Loss of the primary processing centre and specialist personnel;
  • Widespread electronic-payment disruption driving exceptional currency demand;
  • Insider compromise of custody, destruction, or inventory records; and
  • Prolonged power, network, or telecommunications failure affecting multiple sites.

Testing should document assumptions, actual performance, tolerance consumption, management decisions, control failures, unresolved risks, and required investments. Board and senior management attention is particularly important where testing identifies scenarios in which the organisation cannot remain within tolerance. (BCM Institute Blog)

Governance and Validation

The proposed Impact Tolerance is an illustrative implementation recommendation. It should not be interpreted as a confirmed BDCB requirement, existing operating capability, or publicly committed service standard.

Before approval, it should be validated by:

  • Senior management;
  • The Currency Management service owner;
  • Operational Resilience and Business Continuity functions;
  • Operational Risk Management;
  • Technology and ICT Risk owners;
  • Cybersecurity;
  • Physical Security;
  • Finance and Accounting;
  • Procurement and Third-Party Risk Management;
  • Compliance and Legal functions;
  • Relevant financial-sector stakeholders; and
  • Any applicable statutory, policy, audit, or supervisory requirements.

Validation should confirm that:

  1. The selected harm indicators are measurable.
  2. Data sources are reliable and available during incidents.
  3. Alert thresholds provide sufficient time for action.
  4. Supporting process and system RTOs are shorter than the overall tolerance.
  5. Third-party commitments allow BDCB to meet its service boundary.
  6. Manual workarounds can operate at the required scale.
  7. Scenario tests demonstrate credible performance under severe conditions.
  8. Known vulnerabilities and concentration risks are subject to funded remediation.
  9. Senior management understands the residual risk where the tolerance cannot yet be met.
  10. The tolerance remains appropriate as demand patterns, technology, threats, and operating arrangements change.

Banner [Summing] [OR] [E3] Establish Impact Tolerance

The Impact Tolerance for CBS-2 Currency Management establishes a clear boundary between manageable disruption and unacceptable harm. It directs attention away from the recovery of isolated systems and towards BDCB’s ability to continue safeguarding, accounting for, processing, and supplying physical currency across the financial system.

Analysis of the 15 Sub-CBS processes demonstrates how different disruptions consume the tolerance in different ways. Some create immediate danger through loss of security, custody, authentication, or data integrity. Others become harmful as backlogs accumulate, reserve stocks decline, institutions are unable to replenish currency, or disruption spreads geographically.

Integrating Cyber and ICT Risk into every Sub-CBS assessment strengthens the tolerance by recognising that technology failure can directly prevent physical currency operations. It also highlights technology concentration, data corruption, privileged-access compromise, infrastructure failure, third-party ICT disruption, and cyber-physical attack as potential causes of end-to-end service failure.

Auditable evidence—including risk assessments, control-test results, failover reports, reconciliation records, cyber monitoring, third-party assurance, exercise findings, committee minutes, and remediation reports—allows management and reviewers to determine whether stated resilience capabilities exist in practice.

Once validated, the Impact Tolerance should guide scenario design, recovery priorities, control enhancement, technology and facility investment, third-party requirements, management escalation, and remediation planning. It should be reviewed whenever there are material changes to currency demand, processes, facilities, technology, suppliers, threats, regulations, or the wider financial operating environment. Through regular validation and severe-but-plausible scenario testing, BDCB can use the tolerance as a practical management boundary for protecting the continuity, security, integrity, and trustworthiness of Brunei Darussalam’s Currency Management service.

[OR] [BDCB] [3/4 Banner] Operational Resilience at BDCB A Strategic Implementation Guide

eBook 3: Starting Your OR Implementation
CBS-2 Currency Management
CBS-2 DP CBS-2 MII CBS-2 ITo CBS-2 SbPS CBS-2 ST
[OR] [BDCB] [E3] [CBS] [2] [DP] Loan and Financing Operations [OR] [BDCB] [E3] [CBS] [2] [MII] Loan and Financing Operations [OR] [BDCB] [E3] [CBS] [2] [ITo] Loan and Financing Operations [OR] [BDCB] [E3] [CBS] [2] [SbPS] Loan and Financing Operations [OR] [BDCB] [E3] [CBS] [2] [ST] Loan and Financing Operations


New call-to-actionFor organisations looking to accelerate their journey, BCM Institute’s training and certification programs, including the OR-5000 Operational Resilience Expert Implementer course, provide in-depth insights and practical toolkits for effectively embedding this model.

 

More Information About OR-5000 [OR-5] or OR-300 [OR-3]

Gain Competency: For organisations looking to accelerate their journey, BCM Institute’s training and certification programs, including the OR-5000 Operational Resilience Expert Implementer course, provide in-depth insights and practical toolkits for effectively embedding this model.

To learn more about the course and schedule, click the buttons below for the [OR-3] OR-300 Operational Resilience Implementer course and the [OR-5] OR-5000 Operational Resilience Expert Implementer course.

BL-OR-3 Register Now BL-OR-3_Tell Me More BL-OR-3_View Schedule
BL-OR-5_Register Now BL-OR-5_Tell Me More  [BL-OR] [3-4-5] View Schedule
[BL-OR] [3] FAQ OR-300

If you have any questions, click to contact us.Email to Sales Team [BCM Institute]

FAQ BL-OR-5 OR-5000
OR Implementer Landing Page

New call-to-action

New call-to-action

 

Your Comments Here:

 

CTA Banner_OR

CTA Banner_ORA

CTA Banner_BCM

CTA Banner_ITDR

CTA Banner_CM