Setting an Impact Tolerance for CBS-2 Currency Management enables Brunei Darussalam Central Bank (BDCB) to define the maximum disruption that may be allowed before the consequences become unacceptable to the public, financial institutions, government stakeholders, the integrity of the national currency, or the wider financial system.
The tolerance must be based on the harm resulting from disruption rather than solely on how quickly an individual system, facility, or operational process can be recovered.
Impact Tolerance is therefore an end-to-end service boundary. It considers whether BDCB can continue providing an adequate, secure, and trustworthy supply of banknotes and coins across Brunei Darussalam despite disruption to forecasting, production, storage, distribution, authentication, accounting, security, or supporting technology.
The BCM Institute methodology similarly describes Impact Tolerance as the maximum tolerable level of disruption to a critical business service and recommends expressing it through measurable outcomes such as duration, data loss, financial impact, and customer effect.
The assessment must consider all 15 Sub-Critical Business Services because a failure originating in one process may propagate across the currency lifecycle.
For example, corrupted inventory data may initially affect vault reconciliation but subsequently prevent authorised currency release, delay replenishment to financial institutions, impair management reporting, and reduce confidence in the accuracy of currency-in-circulation records.
Cyber and ICT risks are integrated throughout this assessment rather than treated as a separate technology exercise. Ransomware, unauthorised access, database corruption, network failure, failed technology changes, processing-equipment outages, loss of surveillance, and third-party ICT disruption can directly affect BDCB’s ability to safeguard, account for, process, and distribute currency.
The Impact Tolerance must therefore measure the resulting service harm regardless of whether the originating cause is physical, operational, technological, cyber-related, or external.
For this assessment, the five harm levels are interpreted as follows:
This expanded scale is consistent with the underlying principle that organisations should distinguish inconvenience, material harm, and intolerable harm when setting Impact Tolerances.
Table 1: Impact Tolerance Assessment
|
Sub-CBS Code |
Name of Sub-CBS |
Potential Disruption |
Potential Harm |
Level of Harm |
Key Harm Indicators |
|
CBS-2.1 |
Currency Demand Forecasting |
Forecasting data becomes unavailable, incomplete, corrupted, or materially inaccurate; demand models fail to reflect seasonal, institutional, or emergency requirements. |
BDCB may underestimate denomination and reserve-stock requirements, causing later shortages, emergency procurement, inefficient inventory allocation, or inability to meet exceptional cash demand. Overestimation may create unnecessary production, storage, insurance, and custody exposure. Harm is generally delayed rather than immediate but can become serious if the error remains undetected. |
Medium under short-term disruption; High where inaccurate forecasts affect a major production or replenishment cycle. |
Duration of forecasting outage; age and completeness of source data; forecast variance against actual demand; number of denominations affected; projected reserve-stock shortfall; number of institutions whose projected demand cannot be met; time remaining before production or procurement decisions. |
|
CBS-2.2 |
Currency Production Planning |
Production schedules cannot be completed, approved, amended, or communicated; denomination requirements or contingency reserves are incorrectly planned. |
Production may be initiated too late, in the wrong quantities, or with an unsuitable denomination mix. Extended disruption could reduce strategic currency reserves and increase reliance on existing stock, emergency procurement, or accelerated external manufacturing. |
Medium, escalating to High where reserve levels approach minimum thresholds or a scheduled production window is missed. |
Duration of planning delay; production decision deadlines missed; percentage reduction in projected reserve coverage; denominations below approved stock thresholds; number of unresolved production approvals; estimated lead-time extension. |
|
CBS-2.3 |
Currency Procurement and Manufacturing Oversight |
Currency production, secure procurement, quality inspection, acceptance, or shipment is delayed or interrupted by manufacturer failure, geopolitical restrictions, quality defects, cyberattack, transport disruption, or loss of production records. |
BDCB may be unable to replenish strategic reserves or introduce required currency stock. Defective or non-compliant notes or coins may be accepted, while prolonged supply interruption could ultimately constrain national currency availability. |
High, becoming Very High when reserve stock is insufficient to absorb the manufacturing or delivery delay. |
Production milestone slippage; percentage of order delayed or rejected; number of denominations affected; remaining reserve-stock coverage; quality failure rate; secure shipment delays; supplier recovery estimate; availability of alternate manufacturing arrangements. |
|
CBS-2.4 |
Currency Inventory and Vault Management |
Vault access is lost; inventory records are unavailable or inconsistent; physical stock cannot be located, released, received, reconciled, or securely controlled. |
Currency may be physically available but operationally unusable. BDCB could be unable to meet withdrawal requests, accept returned currency, confirm stock availability, or demonstrate custody integrity. A security or reconciliation failure could create financial loss, investigation requirements, and serious loss of confidence. |
Very High where authorised access, stock integrity, or nationwide release capability is materially affected. |
Duration of vault inaccessibility; value and denominations inaccessible; percentage of national operational stock affected; reconciliation variance; number of delayed releases; number of affected financial institutions; security-control status; ability to activate an alternate vault or manual register. |
|
CBS-2.5 |
Currency Distribution and Replenishment |
Currency orders cannot be received or fulfilled; dispatch scheduling, secure transportation, hand-over, or confirmation fails; access to distribution facilities or routes is disrupted. |
Financial institutions may be unable to replenish cash holdings, potentially affecting branches, cash points, businesses, government payments, and public access to physical currency. Widespread or prolonged disruption may affect confidence and economic activity. |
Very High where disruption is nationwide, affects multiple institutions, or occurs during peak or emergency demand. |
Duration of distribution suspension; number and proportion of financial institutions affected; geographic areas affected; value and denomination of unfulfilled orders; backlog age; number of missed dispatches; projected cash depletion at receiving institutions; availability of alternate routes and transport capacity. |
|
CBS-2.6 |
Currency Receipt and Return Processing |
Returned currency cannot be received, registered, counted, reconciled, or transferred for authentication and sorting. |
Returned notes and coins may accumulate at financial institutions or receiving facilities. Processing congestion can reduce reusable stock, delay detection of counterfeit or damaged currency, create custody exposure, and eventually constrain the circulation cycle. |
Medium, escalating to High when backlogs obstruct secure receipt capacity or reduce currency available for recirculation. |
Duration of receipt suspension; volume and value awaiting processing; backlog age; percentage of receiving capacity consumed; number of institutions unable to return currency; unreconciled consignments; effect on available fit-currency inventory. |
|
CBS-2.7 |
Currency Authentication and Quality Verification |
Authentication equipment, reference data, specialist capability, or examination facilities become unavailable; counterfeit detection or quality verification is degraded. |
Suspected counterfeit or unsuitable currency may not be identified promptly. Legitimate returned currency may also be withheld unnecessarily, reducing available stock. A prolonged control failure could weaken confidence in the authenticity and quality of currency in circulation. |
High, becoming Very High if counterfeit currency is released, material authenticity uncertainty exists, or national confidence is threatened. |
Duration of authentication outage; volume awaiting verification; number and value of suspected counterfeits; false acceptance or rejection rate; percentage of verification capacity unavailable; number of institutions affected; age of counterfeit alerts; volume released under exceptional procedures. |
|
CBS-2.8 |
Currency Fitness Sorting and Recirculation Management |
Sorting machines, processing software, classification criteria, or operators become unavailable; fit and unfit currency cannot be separated accurately. |
Fit currency may not be returned to circulation, increasing dependence on new stock. Unfit notes may remain in circulation, lowering currency quality. Incorrect sorting could send usable currency for destruction or unsuitable currency for redistribution. |
High where disruption materially reduces recirculation capacity or sorting accuracy. |
Sorting capacity unavailable; volume and value of unsorted currency; backlog age; fit-note yield; sorting error rate; recirculation shortfall; denomination availability; percentage reliance on new stock; machine recovery time. |
|
CBS-2.9 |
Counterfeit Currency Investigation and Reporting |
Case records, forensic analysis, intelligence exchange, specialist investigators, or reporting channels are unavailable or compromised. |
Counterfeit trends may not be identified or communicated promptly. Financial institutions and law-enforcement bodies may lack actionable information, enabling continued circulation and weakening confidence in national currency integrity. |
High, escalating to Very High during a widespread or sophisticated counterfeit event. |
Number and value of uninvestigated cases; age of outstanding alerts; institutions awaiting guidance; geographic spread; repeat counterfeit patterns; reporting delay; suspected organised-crime involvement; number of unresolved forensic examinations. |
|
CBS-2.10 |
Currency Destruction and Disposal Management |
Destruction equipment, approvals, witnessed controls, reconciliation records, or secure disposal arrangements become unavailable. |
Unfit currency accumulates in secure storage, consuming vault capacity and increasing custody, security, and accounting exposure. Incorrect or unauthorised destruction could create irrecoverable financial and evidential consequences. |
Medium for a controlled short-term postponement; Very High where destruction integrity, authorisation, or reconciliation is compromised. |
Duration of destruction suspension; value and volume awaiting destruction; storage capacity consumed; unreconciled destruction batches; security incidents; control exceptions; witness or approval gaps; variances between destruction and accounting records. |
|
CBS-2.11 |
Currency Accounting and Reconciliation |
General ledger interfaces, inventory records, transaction journals, reconciliation tools, or source data become unavailable, corrupted, or inconsistent. |
BDCB may be unable to confirm currency issued, held, returned, destroyed, or in circulation. Unresolved differences could prevent further physical movements, compromise financial reporting, conceal loss or fraud, and weaken accountability. |
Very High where material balances cannot be verified or currency movements continue without reliable reconciliation. |
Duration of reconciliation outage; value and number of unreconciled movements; ledger-to-physical variance; data-loss period; number of interfaces unavailable; age of outstanding breaks; manual entries awaiting verification; reporting deadlines at risk. |
|
CBS-2.12 |
Currency Security and Custody Management |
Physical security, access control, surveillance, alarm monitoring, dual-control arrangements, secure transport protection, or custody records fail or are compromised. |
Currency assets, personnel, facilities, and sensitive information may be exposed to theft, sabotage, fraud, unauthorised access, or loss. Failure may require immediate suspension of vault, processing, or distribution operations and can affect nearly every Currency Management process. |
Very High because security and custody are pervasive dependencies across the service. |
Security systems unavailable; unauthorised-access attempts; number of facilities affected; surveillance coverage lost; duration of dual-control failure; custody exceptions; transport movements suspended; value of currency exposed; confirmed or suspected loss. |
|
CBS-2.13 |
Currency Information and Operational Monitoring |
Monitoring dashboards, stock alerts, operational reports, performance data, or incident-detection mechanisms become unavailable or inaccurate. |
Management may not identify emerging shortages, processing backlogs, control failures, or service degradation in time to intervene. Delayed escalation could allow an otherwise manageable incident to develop into an Impact Tolerance breach. |
High where BDCB loses end-to-end situational awareness across multiple Sub-CBS processes. |
Duration of monitoring loss; number of unavailable data feeds; age of last verified position; percentage of processes operating without current status; alerts missed; management reports delayed; discrepancies between local and central monitoring; unresolved threshold breaches. |
|
CBS-2.14 |
Currency Incident Management and Service Recovery |
Incident command, crisis communications, escalation, continuity procedures, recovery coordination, decision-making, or alternate-site activation fails. |
BDCB may respond inconsistently or too slowly to a disruption, causing avoidable delays, duplicated actions, poor stakeholder communication, and cascading failure across Currency Management. The originating incident may therefore remain unresolved beyond the service tolerance. |
Very High, particularly when multiple processes, facilities, institutions, or cyber and physical threats are involved. |
Time to detect, declare, and escalate; time to activate response teams; number of unfilled critical roles; recovery milestones missed; stakeholder notification delay; decisions awaiting approval; effectiveness of manual workarounds; estimated time to service stabilisation. |
|
CBS-2.15 |
Regulatory Reporting and Continuous Service Improvement |
Incident, risk, control, audit, performance, and remediation information cannot be consolidated, reported, or acted upon. |
Immediate currency delivery may continue, but unresolved weaknesses may recur or worsen. Material incidents may not be reported accurately or promptly, management may lack assurance, and remediation investment may be delayed. |
Medium for short-term reporting delay; High where significant incidents, control deficiencies, or overdue remediation remain undisclosed or unmanaged. |
Reporting deadlines missed; number of incomplete incident reports; overdue remediation actions; repeat findings; unresolved risk acceptances; age of management information; audit issues overdue; number of lessons not incorporated into procedures or tests. |
The highest-harm processes are those that directly control the physical availability, integrity, security, and release of currency:
These processes form the immediate operational chain through which currency is held, authorised, moved, validated, protected, accounted for, monitored, and restored. Failure in any one of them may prevent BDCB from using otherwise available physical stock.
Processes such as demand forecasting, production planning, procurement, and manufacturing oversight generally have longer disruption horizons because currency reserves and existing circulation provide some buffer. Nevertheless, their harm can become very high when disruption persists, coincides with increased demand, affects a critical denomination, or exhausts existing reserves.
The assessment therefore demonstrates why the tolerance cannot be expressed only as a single system-recovery deadline. Some failures create immediate unacceptable harm, particularly loss of security or data integrity. Others become intolerable through duration, geographic spread, backlog accumulation, reserve depletion, or the number of institutions affected.
Table 2: Cyber and ICT Risk Integration, Proactive Controls and Evidence
|
Sub-CBS Code |
Name of Sub-CBS |
Cyber and ICT Risk Linkage |
Contribution to Impact Tolerance Breach |
Proactive Risk Management Action |
Evidence of Proactive Risk Management |
|
CBS-2.1 |
Currency Demand Forecasting |
Data-feed interruption, model corruption, unauthorised alteration of assumptions, database failure, ransomware, failed analytical-platform change, or loss of source-system interfaces could produce incomplete or inaccurate forecasts. |
A compromised forecast may not cause immediate service failure but can create a future reserve shortfall, unsuitable denomination mix, or inability to respond to peak demand. Undetected data-integrity failure is more serious than a visible outage because decisions may continue using false information. |
Validate source data against independent records; apply model governance and version control; restrict privileged access; maintain offline forecast templates; retain historical datasets; perform reasonableness checks and forecast back-testing; establish manual demand-estimation procedures. |
Approved model-risk assessments; access reviews; change records; data-quality reports; forecast-variance analysis; backup-restoration tests; manual-workaround exercises; management approval of key assumptions. |
|
CBS-2.2 |
Currency Production Planning |
Planning application failure, workflow outage, document corruption, loss of approval records, unauthorised schedule changes, or network failure affecting communication with procurement and production stakeholders. |
Delayed or manipulated production plans can cause missed manufacturing windows or inadequate reserve replenishment. A prolonged outage becomes material as decision deadlines and supplier lead times are exhausted. |
Maintain controlled offline copies of approved plans; implement multi-level authorisation; digitally verify plan changes; test alternate communication channels; define planning decision deadlines and escalation triggers; back up production specifications and schedules. |
Approval logs; segregation-of-duties reviews; workflow audit trails; backup test results; alternate-communications exercises; change-management records; planning contingency procedure tests. |
|
CBS-2.3 |
Currency Procurement and Manufacturing Oversight |
Third-party cyberattack, supplier ICT outage, compromise of currency specifications, secure-file-transfer failure, production-system disruption, data leakage, or technology concentration at a single manufacturer. |
A supplier outage may delay production or delivery beyond reserve coverage. Compromised specifications or quality records could also affect the security and authenticity of newly manufactured currency. |
Conduct supplier cyber and operational resilience due diligence; require incident notification and recovery commitments; secure and encrypt specification exchanges; maintain independent specification verification; assess alternate production sources; monitor milestone and concentration risk. |
Third-party risk assessments; contractual resilience clauses; supplier assurance reports; independent quality-test records; secure-transfer logs; business continuity test evidence; concentration-risk reviews; supplier remediation reports. |
|
CBS-2.4 |
Currency Inventory and Vault Management |
Inventory database failure, access-control compromise, privileged-access abuse, ransomware, surveillance outage, network failure, time-synchronisation failure, or corruption of stock records. |
Loss of reliable inventory or secure vault access can immediately prevent currency release and receipt. If physical and digital records cannot be reconciled, operations may need to stop even when currency remains available. |
Use highly available inventory platforms; maintain immutable transaction logs; implement strong privileged-access management and multifactor authentication; retain controlled manual vault registers; provide redundant surveillance and access systems; perform regular physical-to-system reconciliation; test alternate-vault operations. |
Failover reports; physical inventory counts; reconciliation results; privileged-access reviews; CCTV and access-control test records; cyber monitoring logs; penetration-test findings; alternate-vault exercise reports; exception investigations. |
|
CBS-2.5 |
Currency Distribution and Replenishment |
Order-management failure, network outage, denial-of-service attack, dispatch-system failure, interface disruption with financial institutions, mobile communications loss, or compromise of transport schedules. |
BDCB may be unable to receive, prioritise, authorise, or dispatch replenishment requests. Compromised routing or order data could create security exposure or send incorrect denominations and quantities. A multi-institution outage could breach the tolerance rapidly. |
Establish authenticated alternate order channels; maintain offline dispatch procedures; provide redundant communications; validate high-value orders through independent confirmation; separate sensitive transport information; maintain alternate routing and transport arrangements; test manual order fulfilment. |
Distribution continuity-test reports; alternate-channel tests; transport-provider assurance; dispatch audit trails; communication-resilience tests; order-reconciliation results; scenario tests involving widespread bank demand. |
|
CBS-2.6 |
Currency Receipt and Return Processing |
Receipt-registration failure, barcode or tracking-system outage, counting-equipment failure, interface disruption, ransomware, or corruption of consignment records. |
Returned currency may become untraceable or remain unprocessed. Accumulating backlog can consume secure storage and reduce currency available for authentication and recirculation, eventually affecting supply. |
Maintain manual consignment registers and pre-numbered custody records; provide equipment redundancy; isolate processing equipment where appropriate; reconcile all received items at hand-offs; prioritise high-value and high-risk returns; monitor backlog thresholds. |
Equipment-maintenance records; manual-processing test results; custody reconciliations; backlog dashboards; restoration tests; incident logs; exception reports; periodic end-to-end consignment tracing. |
|
CBS-2.7 |
Currency Authentication and Quality Verification |
Authentication-device compromise, malware, obsolete detection software, reference-database corruption, failed software updates, loss of connectivity, or manipulation of detection thresholds. |
Counterfeit or unsuitable currency could be incorrectly accepted, while genuine currency could be rejected and withheld. A common technology defect across all devices creates a major concentration risk. |
Use layered authentication methods; validate device software and signature updates; retain specialist manual examination capability; segregate devices from unnecessary networks; test sample accuracy; maintain equipment from more than one operational pool where feasible; preserve offline reference materials. |
Device-certification records; calibration results; software-integrity checks; vulnerability assessments; false-acceptance and rejection reports; manual-examination competency records; independent sample-test results; equipment failover exercises. |
|
CBS-2.8 |
Currency Fitness Sorting and Recirculation Management |
Sorting-machine failure, capacity degradation, control-software defect, malicious code, database corruption, failed configuration change, or common-component failure across processing machines. |
Recirculation capacity may fall below demand and create a growing backlog. Incorrect classification can reduce currency quality or destroy usable stock. Common technology concentration may disable the entire sorting operation. |
Maintain redundant processing capacity; control and test configuration changes; monitor throughput and error rates; retain manual or semi-automated fallback procedures; hold critical spare parts; establish preventive maintenance and alternate processing arrangements. |
Capacity reports; machine-availability logs; maintenance records; change-test results; sorting-quality reports; spare-parts inventory; recovery exercises; throughput stress-test results. |
|
CBS-2.9 |
Counterfeit Currency Investigation and Reporting |
Case-management outage, theft of sensitive intelligence, unauthorised case alteration, forensic-tool failure, malware, loss of secure communications, or third-party information-sharing disruption. |
Counterfeit intelligence may be delayed, incomplete, or exposed. Failure to detect patterns or warn financial institutions can allow wider circulation and increase public and market harm. |
Encrypt case data; restrict access by role and need; maintain secure alternate communication with relevant authorities; preserve forensic evidence offline; back up case records; test information-sharing procedures; monitor for unauthorised access and data exfiltration. |
Access logs; data-loss-prevention alerts; backup-restoration tests; case-file audits; secure communication tests; incident-response records; forensic chain-of-custody reviews; inter-agency exercise reports. |
|
CBS-2.10 |
Currency Destruction and Disposal Management |
Destruction-control software failure, manipulation of batch records, loss of video evidence, access-control compromise, sensor failure, ransomware, or corruption of destruction certificates. |
BDCB may be unable to prove that authorised currency was destroyed completely and accurately. Unauthorised or unreconciled destruction is irreversible and can create severe financial, security, legal, and reputational consequences. |
Enforce dual authorisation and witnessed destruction; reconcile pre- and post-destruction quantities independently; retain immutable evidence; separate destruction control from accounting approval; maintain manual shutdown and safety procedures; test security and surveillance continuity. |
Destruction certificates; independent reconciliation reports; surveillance-retention logs; access records; control-test results; witnessed sample reviews; incident reports; internal audit findings. |
|
CBS-2.11 |
Currency Accounting and Reconciliation |
Ledger outage, interface failure, data corruption, ransomware, unauthorised journal entries, time-sequence failure, database loss, or unsuccessful system change. |
BDCB may lose the authoritative record of currency balances and movements. Operations may need to be suspended until integrity is restored, and continued processing could increase unquantified exposure. |
Use resilient ledger and reconciliation architecture; maintain immutable source journals; enforce maker-checker controls; reconcile critical movements promptly; define a near-zero data-loss objective for confirmed movements; test point-in-time recovery; monitor interfaces and unusual entries. |
Disaster-recovery reports; restoration and data-integrity tests; reconciliation break reports; journal-access reviews; interface-monitoring records; database backup evidence; independent assurance; management review of material variances. |
|
CBS-2.12 |
Currency Security and Custody Management |
Cyber compromise of access control, surveillance, alarms, identity platforms, communications, or transport-tracking systems; privileged-access abuse; coordinated cyber-physical attack; infrastructure or power failure. |
A cyber event could create physical access, disable monitoring, reveal sensitive movement details, or force suspension of vault and transport operations. Because the security capability supports most Sub-CBS processes, disruption can cause a rapid service-wide breach. |
Segregate physical-security networks; implement defence-in-depth and independent alarm channels; restrict privileged access; provide backup power and communications; maintain manual guards and physical controls; test coordinated cyber-physical incident response; protect transport data. |
Security penetration-test reports; access recertification; alarm and backup-power tests; cyber-physical exercise reports; surveillance availability records; privileged-session monitoring; physical-security inspections; remediation tracking. |
|
CBS-2.13 |
Currency Information and Operational Monitoring |
Monitoring-platform outage, corrupted dashboards, data-feed interruption, alert suppression, denial-of-service attack, capacity overload, or common identity-service failure. |
Management may operate with an inaccurate service picture and fail to recognise that stock, processing, distribution, or security thresholds are deteriorating. This can delay intervention until the Impact Tolerance is exceeded. |
Implement independent monitoring paths for critical indicators; verify dashboard data against source records; maintain manual status-reporting templates; provide redundant communications; prioritise alerts; define escalation thresholds; test monitoring during system and network outages. |
Monitoring-availability reports; alert-test records; data-reconciliation reports; capacity tests; manual situation-report exercises; incident-detection metrics; network-resilience tests; management review records. |
|
CBS-2.14 |
Currency Incident Management and Service Recovery |
Incident-management platform failure, communications outage, ransomware affecting crisis records, loss of staff contact information, unavailable recovery documentation, or inaccessible emergency facilities. |
Response teams may be unable to coordinate decisions, communicate with financial institutions, prioritise scarce currency, or activate alternate arrangements. Delayed recovery directly increases the likelihood that service disruption exceeds tolerance. |
Maintain offline response plans and contact lists; provide out-of-band communications; pre-authorise emergency decisions; establish alternate command facilities; cross-train critical roles; conduct integrated cyber, facility, logistics, and currency-shortage exercises; track recovery against tolerance milestones. |
Exercise reports; call-tree tests; alternate-site activation records; incident-response metrics; crisis-communication tests; role-training records; lessons-learned reports; management committee minutes; remediation status. |
|
CBS-2.15 |
Regulatory Reporting and Continuous Service Improvement |
Reporting-platform failure, incomplete incident data, document-management outage, unauthorised report alteration, loss of evidence, or cyber disruption affecting remediation tracking. |
BDCB may not identify recurring weaknesses or demonstrate that severe incidents and control deficiencies are being managed. Delayed remediation can leave known vulnerabilities capable of causing a future tolerance breach. |
Maintain controlled evidence repositories; protect report integrity through access and version controls; reconcile reporting data to source systems; track remediation with accountable owners and deadlines; escalate overdue high-risk actions; retain offline copies of critical reports. |
Approved reports; version histories; committee minutes; risk acceptance records; remediation dashboards; audit trails; independent review findings; closure evidence; follow-up scenario-test results. |
An indicative Impact Tolerance for CBS-2 Currency Management should be expressed as a combination of time, service availability, geographic scope, institutional impact, physical currency availability, data integrity, and security outcomes.
Illustrative implementation recommendation
BDCB should remain capable of authorising and releasing essential currency to the financial system throughout a disruption and should restore any material interruption to core vault access, currency release, receipt, authentication, accounting, security, and distribution capabilities within four hours of confirmed service impact.
No disruption should result in an unverified loss of currency, release of unauthenticated currency, material corruption of currency inventory or accounting records, or loss of custody integrity.
A disruption should not prevent more than 25% of participating financial institutions from obtaining essential currency replenishment for longer than four hours during the applicable operating period, and nationwide essential replenishment capability should not be unavailable for more than two hours without activation of approved contingency arrangements.
This tolerance is deliberately multi-dimensional. A time measure alone would not address an immediate integrity or security failure, while a scope measure alone would not capture a prolonged disruption affecting one critical geographic area or institution.
|
Tolerance Dimension |
Indicative Boundary |
|
Core service disruption duration |
No more than four hours of material disruption to essential vault access, currency release, receipt, authentication, reconciliation, security, or distribution capability. |
|
Nationwide distribution capability |
No more than two hours without an operational method for receiving, prioritising, authorising, and initiating essential replenishment requests, including contingency channels. |
|
Emergency currency release |
BDCB should be capable of initiating an authorised emergency currency release within two hours of approval and commencing physical dispatch within four hours, subject to security and transport conditions. |
|
Institutional scope |
No more than 25% of participating financial institutions should be unable to access essential replenishment beyond four hours. No critical institution or geographic area should be left without an agreed contingency route where cash depletion is imminent. |
|
Geographic scope |
A localised disruption should not become a nationwide inability to distribute currency. Alternate routes or facilities should be available before local stock depletion creates public harm. |
|
Currency availability |
Essential denominations should remain available above management-approved minimum operational and contingency stock levels. No denomination should fall below its emergency distribution threshold without escalation and controlled allocation. |
|
Processing degradation |
Authentication, sorting, receipt, and return processing may operate at reduced capacity temporarily, but the backlog should not exceed secure storage capacity or reduce fit-currency availability below the emergency replenishment requirement. |
|
Data latency |
Critical stock, vault, dispatch, receipt, and reconciliation positions should not remain unverified for more than one hour during active currency movements. Management should receive a validated service position at least hourly during a material incident. |
|
Data loss |
No permanent loss of confirmed currency-movement, custody, destruction, or accounting records should be accepted. Any reconstructed records must be independently verified before normal processing resumes. |
|
Data integrity |
Any material uncertainty about physical stock, custody, authenticity, or accounting balances should trigger controlled suspension of affected movements until integrity is established. There should be no tolerance for knowingly releasing currency using materially corrupted or unverified records. |
|
Security and custody |
There should be zero tolerance for uncontrolled vault access, unaccounted currency loss, unauthorised destruction, or release without required custody controls. A security-control failure may require immediate service restriction even before the time threshold is reached. |
|
Counterfeit and authenticity control |
No material volume of currency should be released where authentication integrity is uncertain. Suspected systemic compromise of authentication capability should be treated as an immediate potential tolerance breach. |
|
Regulatory and statutory effect |
No disruption should cause a material inability to fulfil BDCB’s currency responsibilities, conceal a significant incident, compromise required records, or prevent timely escalation to the appropriate governance authority. |
|
Public and financial-system harm |
The tolerance is breached before cash shortages become widespread, public access to essential cash is materially restricted, currency authenticity is reasonably questioned, or financial institutions are forced to curtail critical cash services. |
The Impact Tolerance should be considered breached when one or more of the following conditions occur:
Currency Management differs from continuously available digital services because physical currency is held in reserves, already exists in circulation, and is distributed through multiple financial institutions.
These characteristics provide limited buffering against a short central operational disruption. However, this buffer does not eliminate the need for a demanding tolerance.
A relatively short tolerance is appropriate for vault access, authorisation, accounting, security, and emergency distribution because failure in these areas can prevent BDCB from using the physically available currency stock. The tolerance must also be stricter during:
The recommended thresholds are intended to establish the point before operational degradation causes unacceptable external harm. They are not statements of existing BDCB
capability or public commitments.
The proposed Impact Tolerance must not be treated as interchangeable with supporting recovery and performance measures.
Recovery Time Objective
An RTO defines the targeted time for recovering a particular system, process, facility, or resource. Several RTOs may support the four-hour Currency Management Impact Tolerance. For example, the inventory platform may require a shorter RTO because staff needs time after recovery to validate data, reconcile stock, approve releases, and commence distribution.
A system recovered at the four-hour boundary would not demonstrate compliance if the overall Currency Management service remained unavailable beyond that point.
Recovery Point Objective
An RPO defines the maximum targeted period of data that may be lost following an incident. For confirmed currency movements, custody transfers, destruction records, and accounting entries, BDCB should adopt an extremely low or near-zero data-loss position supported by journals, replication, immutable logs, and manual source records.
Meeting an RPO does not itself demonstrate that the service remains within Impact Tolerance. Restored data must also be accurate, complete, reconciled, and usable.
Maximum Tolerable Period of Disruption
An MTPD normally identifies the maximum period for which an activity can remain disrupted before its viability or objectives are seriously affected. It can help determine process recovery priorities but may focus more narrowly on individual activities or organisational consequences.
The Impact Tolerance is set from the perspective of harm caused by disruption to the end-to-end Critical Business Service. It may therefore be shorter than the MTPD of some supporting processes.
Service Level Agreement
An SLA establishes expected performance between service providers and recipients. A supplier might comply with a contractual SLA while BDCB still breaches its Currency Management Impact Tolerance because several providers, processes, or facilities fail concurrently.
Supplier recovery commitments should therefore be calibrated to leave BDCB sufficient time to complete its own verification, decision-making, processing, and service-restoration activities.
Although every Sub-CBS supports Currency Management, the following require particularly strong recovery and resilience arrangements:
CBS-2.4 Currency Inventory and Vault Management
This is the control point for physical availability. Inventory records, authorised access, custody controls, and alternate storage arrangements must remain reliable during disruption.
CBS-2.5 Currency Distribution and Replenishment
This is the primary delivery mechanism to financial institutions. Alternate ordering channels, secure transport capacity, prioritisation criteria, and emergency distribution arrangements are essential.
CBS-2.7 Currency Authentication and Quality Verification
Currency should not be recirculated when authenticity or quality cannot be established. BDCB needs both technology-based and specialist manual verification capability.
CBS-2.11 Currency Accounting and Reconciliation
Currency movements cannot continue safely without trusted records. Recovery arrangements must preserve transaction sequence, evidence, approval, and physical-to-ledger reconciliation.
CBS-2.12 Currency Security and Custody Management
Security failure can force the suspension of multiple operational processes. Resilience must cover physical, cyber, personnel, communications, surveillance, and transport controls.
CBS-2.13 Currency Information and Operational Monitoring
Management needs timely and accurate information to detect deterioration, allocate scarce stock, invoke contingency arrangements, and prevent an incident from exceeding tolerance.
CBS-2.14 Currency Incident Management and Service Recovery
Effective command, escalation, communication, and recovery coordination determine whether disruption is contained within the tolerance. Scenario testing is intended to assess whether a critical business service can remain within its approved tolerance under severe but plausible conditions.
To reduce the probability and impact of an Impact Tolerance breach, BDCB should implement a coordinated programme covering prevention, detection, response, recovery, and adaptation.
BDCB should define minimum operational, contingency, and strategic reserve thresholds by denomination. Triggers should account for normal demand, peak periods, electronic-payment disruption, delayed manufacturing, and emergency distribution requirements.
Evidence should include approved threshold methodologies, regular stock reports, exception escalations, and management decisions when reserves approach tolerance limits.
The assessment should identify whether a single vault, processing location, inventory platform, network, identity service, authentication technology, or transport arrangement could disable several Sub-CBS processes simultaneously.
Where concentration cannot be removed, BDCB should establish alternate facilities, manual procedures, spare capacity, diverse communications, protected equipment, and pre-approved contingency arrangements.
Stock balances, movements, custody changes, authentication results, destruction records, and accounting entries should be protected by strong access controls, immutable logging, reconciliation, backup, and independent verification.
Data-integrity restoration should be tested rather than assuming that a technically successful backup restoration produces a trusted operational position.
Currency operations rely on the interaction of physical and digital controls. Scenario testing should therefore include attacks that disable access control, surveillance, communications, inventory systems, or transport information while physical operations are continuing.
Tests should evaluate whether BDCB can maintain secure custody, activate manual controls, identify unauthorised access, and restore trusted records.
Manual procedures should exist for:
Workarounds should be time-limited, controlled, adequately staffed, and tested at realistic transaction volumes.
Currency manufacturers, secure transport providers, specialist maintenance services, financial institutions, and relevant government or enforcement bodies should be included in resilience planning where their participation is necessary.
BDCB should understand their recovery capabilities, notification arrangements, capacity constraints, technology dependencies, and ability to support concurrent or nationwide disruption.
Scenarios should assume that disruption has occurred and examine whether BDCB can continue or restore Currency Management before the approved tolerance is exceeded. This approach focuses on response and recovery capability rather than relying only on preventive controls. (BCM Institute Blog)
Relevant severe-but-plausible scenarios include:
Testing should document assumptions, actual performance, tolerance consumption, management decisions, control failures, unresolved risks, and required investments. Board and senior management attention is particularly important where testing identifies scenarios in which the organisation cannot remain within tolerance. (BCM Institute Blog)
The proposed Impact Tolerance is an illustrative implementation recommendation. It should not be interpreted as a confirmed BDCB requirement, existing operating capability, or publicly committed service standard.
Before approval, it should be validated by:
Validation should confirm that:
The Impact Tolerance for CBS-2 Currency Management establishes a clear boundary between manageable disruption and unacceptable harm. It directs attention away from the recovery of isolated systems and towards BDCB’s ability to continue safeguarding, accounting for, processing, and supplying physical currency across the financial system.
Analysis of the 15 Sub-CBS processes demonstrates how different disruptions consume the tolerance in different ways. Some create immediate danger through loss of security, custody, authentication, or data integrity. Others become harmful as backlogs accumulate, reserve stocks decline, institutions are unable to replenish currency, or disruption spreads geographically.
Integrating Cyber and ICT Risk into every Sub-CBS assessment strengthens the tolerance by recognising that technology failure can directly prevent physical currency operations. It also highlights technology concentration, data corruption, privileged-access compromise, infrastructure failure, third-party ICT disruption, and cyber-physical attack as potential causes of end-to-end service failure.
Auditable evidence—including risk assessments, control-test results, failover reports, reconciliation records, cyber monitoring, third-party assurance, exercise findings, committee minutes, and remediation reports—allows management and reviewers to determine whether stated resilience capabilities exist in practice.
Once validated, the Impact Tolerance should guide scenario design, recovery priorities, control enhancement, technology and facility investment, third-party requirements, management escalation, and remediation planning. It should be reviewed whenever there are material changes to currency demand, processes, facilities, technology, suppliers, threats, regulations, or the wider financial operating environment. Through regular validation and severe-but-plausible scenario testing, BDCB can use the tolerance as a practical management boundary for protecting the continuity, security, integrity, and trustworthiness of Brunei Darussalam’s Currency Management service.
| eBook 3: Starting Your OR Implementation |
||||
| CBS-2 Currency Management | ||||
| CBS-2 DP | CBS-2 MII | CBS-2 ITo | CBS-2 SbPS | CBS-2 ST |
Gain Competency: For organisations looking to accelerate their journey, BCM Institute’s training and certification programs, including the OR-5000 Operational Resilience Expert Implementer course, provide in-depth insights and practical toolkits for effectively embedding this model.
To learn more about the course and schedule, click the buttons below for the [OR-3] OR-300 Operational Resilience Implementer course and the [OR-5] OR-5000 Operational Resilience Expert Implementer course.
|
If you have any questions, click to contact us. |
||
|
|