eBook OR

[OR] [BNS] [E1] [C1] Introducing OR Case Study

Written by Moh Heng Goh | Jul 11, 2026 12:49:16 PM

eBook 1: Chapter 1

Understanding the Organisation

 

Introduction

 

Operational Resilience begins with a thorough understanding of the organisation it is intended to protect.

Before identifying critical business services, mapping operational dependencies, or conducting scenario testing, an organisation must first understand its business model, operating environment, strategic objectives, governance structure, and stakeholder expectations.

This foundational understanding ensures that resilience efforts are aligned with business priorities and regulatory requirements rather than implemented as isolated operational initiatives.

This chapter introduces Bank of Nova Scotia (BNS) as the case study organisation for this eBook. It provides an overview of the bank's operating context, organisational characteristics, and the environment in which it delivers financial services. It also outlines the composition of an Operational Resilience implementation team, introduces the concept of Critical Business Services (CBS), and establishes the organisational goals that will guide the Operational Resilience programme throughout this implementation guide.

 

Understanding Your Organisation: Bank of Nova Scotia

Bank of Nova Scotia (BNS), commonly known as Scotiabank, is one of Canada's largest international banking institutions.

Founded in 1832, the bank has grown into a diversified financial services organisation serving millions of customers across Canada, North America, Latin America, the Caribbean, Europe, and Asia-Pacific.

Its operations encompass retail banking, commercial banking, corporate banking, wealth management, capital markets, treasury services, and international banking.

As a systemically important financial institution, BNS plays a critical role in supporting economic activity by providing essential financial services.

Customers rely upon the bank to safeguard deposits, process payments, facilitate lending, manage investments, execute foreign exchange transactions, and provide access to digital banking services around the clock.

The continuity of these services is essential not only for customers but also for businesses, financial markets, payment systems, and the wider economy.

Given its global footprint and interconnected operations, BNS operates within a complex ecosystem involving customers, regulators, payment networks, financial market infrastructures, technology providers, cloud service providers, outsourcing partners, and third-party vendors.

This interconnected environment requires the bank to adopt an enterprise-wide Operational Resilience approach capable of anticipating, withstanding, responding to, recovering from, and adapting to operational disruptions.

Operational Resilience therefore extends beyond traditional Business Continuity Management or disaster recovery planning.

It integrates governance, operational risk management, cyber resilience, technology resilience, third-party risk management, crisis management, and business continuity into a coordinated framework that focuses on maintaining the delivery of Critical Business Services during severe but plausible disruption events.

 

Bank of Nova Scotia's Operating Environment

Financial institutions operate in one of the most highly regulated and interconnected sectors of the global economy.

BNS must continuously balance customer expectations, regulatory compliance, technological innovation, operational efficiency, and emerging risks while maintaining uninterrupted service delivery.

Several characteristics define the bank's operating environment.

Highly Regulated Industry

BNS is subject to prudential supervision by the Office of the Superintendent of Financial Institutions (OSFI) in Canada, together with regulatory requirements in the many jurisdictions where it operates.

These regulations establish expectations for operational risk management, governance, cyber resilience, outsourcing, business continuity, data protection, and operational resilience.

Digital Transformation

Customers increasingly expect banking services to be available anytime and anywhere through digital channels.

Mobile banking, online banking, digital payments, artificial intelligence, cloud computing, and open banking initiatives have transformed customer expectations while increasing technology dependencies.

Interconnected Financial Ecosystem

Banking services depend upon extensive relationships with payment networks, clearing and settlement systems, telecommunications providers, cloud service providers, financial market infrastructures, correspondent banks, fintech partners, and outsourced service providers.

Disruptions affecting any of these dependencies may impact multiple banking services simultaneously.

Increasing Cyber Threats

Cybersecurity continues to represent one of the most significant operational risks facing financial institutions.

Ransomware, phishing campaigns, insider threats, software supply chain attacks, and sophisticated nation-state cyber activities can disrupt critical banking operations and undermine customer confidence.

Evolving Customer Expectations

Customers expect continuous service availability, rapid transaction processing, secure digital experiences, and timely communication during incidents.

Service disruptions can quickly affect customer trust, reputation, and competitive positioning.

Geopolitical and Environmental Risks

Global banking operations are increasingly exposed to geopolitical tensions, sanctions, extreme weather events, pandemics, supply chain disruptions, and infrastructure failures.

These risks reinforce the need for resilient operational capabilities across international operations.

 

Composition of an Operational Resilience Team for Bank of Nova Scotia

Implementing Operational Resilience requires collaboration across multiple business and support functions.

Rather than assigning responsibility to a single department, BNS should establish a cross-functional governance structure that reflects enterprise-wide ownership of resilience.

An example of an Operational Resilience implementation team is shown below.

 

Role

Primary Responsibilities

Executive Sponsor

Provides strategic direction, resources, and executive oversight

Operational Resilience Programme Manager

Leads programme implementation and coordinates activities

Operational Risk Management

Integrates resilience with enterprise operational risk management

Business Unit Representatives

Identify Critical Business Services and business requirements

Technology Services

Assess infrastructure resilience and technology dependencies

Cybersecurity

Evaluate cyber resilience and security controls

Business Continuity Management

Align continuity planning with resilience objectives

Crisis Management Team

Coordinate strategic response during major disruptions

Third-Party Risk Management

Assess the resilience of outsourced providers and suppliers

Legal and Compliance

Ensure regulatory compliance across jurisdictions

Human Resources

Support workforce resilience and succession planning

Corporate Communications

Manage internal and external communications during disruptions

Internal Audit

Provide independent assurance over programme effectiveness

This multidisciplinary team enables resilience decisions to be made from an enterprise perspective while ensuring that operational, technological, regulatory, and customer considerations are incorporated into programme implementation.

Critical Business Services of Bank of Nova Scotia: Key Considerations for Operational Resilience

Operational Resilience focuses on protecting the delivery of services that are critical to customers and the financial system rather than protecting organisational departments or individual technologies.

When identifying Critical Business Services (CBS), BNS should consider several important factors.

  • Services that are essential to customers and financial markets.
  • Services whose disruption would cause significant customer harm.
  • Services required to maintain financial stability.
  • Services supporting regulatory obligations.
  • Services with significant operational or technology dependencies.
  • Services that rely heavily upon third-party providers.
  • Services whose disruption would significantly impact the bank's reputation or financial performance.
  • Services requiring rapid recovery due to contractual or regulatory expectations.

Examples of likely Critical Business Services include:

  • Retail Deposit Services
  • Payment and Funds Transfer Services
  • Digital Banking
  • Commercial Banking
  • Corporate Banking
  • Treasury Operations
  • Wealth Management
  • Foreign Exchange Services
  • Lending Services
  • Fraud Detection and Financial Crime Monitoring

These services will be examined in greater detail in subsequent chapters where dependency mapping, impact tolerances, and scenario testing are introduced.

 

Key Characteristics of Bank of Nova Scotia

Understanding the organisation's characteristics enables resilience planning to be tailored appropriately.

 

Characteristic

Operational Resilience Consideration

International Banking Group

Requires coordination across multiple jurisdictions

Systemically Important Financial Institution

High expectations for operational resilience and continuity

Customer-Centric Service Model

Protection of customer-facing services is paramount

Highly Digital Operations

Significant reliance on technology and cyber resilience

Extensive Third-Party Ecosystem

Strong third-party risk management is required

Large Workforce

Effective governance, communication, and training essential

Complex Regulatory Environment

Compliance with multiple national regulatory frameworks

Continuous Service Delivery

Critical banking services are expected to operate with minimal disruption

These characteristics influence how resilience capabilities should be designed, implemented, monitored, and continuously improved.

 

Establishing Organisational Goals for Operational Resilience

The Operational Resilience programme should align with BNS's broader business strategy while supporting regulatory expectations and customer outcomes.

The following organisational goals provide a practical foundation for implementation.

Goal

Purpose

Protect Critical Business Services

Maintain delivery of essential banking services during disruptions

Reduce Customer Harm

Minimise financial, operational, and reputational impacts on customers

Strengthen Enterprise Resilience

Improve the organisation's ability to withstand and recover from disruptions

Support Regulatory Compliance

Meet operational resilience expectations across all applicable jurisdictions

Enhance Operational Risk Management

Integrate resilience into enterprise risk management practices

Improve Technology and Cyber Resilience

Strengthen the resilience of critical technology and digital services

Increase Third-Party Resilience

Manage dependencies on external service providers

Improve Incident Response

Enhance coordinated response to operational disruptions

Promote Continuous Improvement

Use lessons learned to strengthen resilience capabilities over time

Protect Stakeholder Confidence

Maintain trust among customers, regulators, investors, and employees

Measurable objectives, governance arrangements, resilience metrics, and regular reporting to Senior Management and the Board should support these goals.

 

Understanding the organisation is the first and most important step in implementing an effective Operational Resilience programme.

For Bank of Nova Scotia, this involves recognising its role as a globally connected financial institution, understanding its operating environment, establishing an enterprise-wide governance structure, and identifying the strategic goals that will guide resilience activities.

It also requires an appreciation of the bank's operational complexity, regulatory obligations, technology dependencies, and the critical services upon which customers and the financial system depend.

The concepts introduced in this chapter provide the foundation for the remainder of this implementation guide. With a clear understanding of the organisation's context, the next chapter will examine the principles of Operational Resilience in greater detail, including its objectives, core components, governance requirements, and how it differs from traditional Business Continuity Management.

This progression establishes the framework for identifying Critical Business Services, mapping operational dependencies, defining impact tolerances, and implementing a resilient operating model across the Bank of Nova Scotia.

Blogs marked [x] are under construction

Understanding Your Organisation
 
 
C1 C2 (X) C3 (X) C4 (X) C5    
   
C6 (X) C7 (X) C8 (X) C9 (X) eBook Cover    
   
     

 

Gain Competency: For organisations looking to accelerate their journey, BCM Institute’s training and certification programs, including the OR-5000 Operational Resilience Expert Implementer course, provide in-depth insights and practical toolkits for effectively embedding this model.

 

More Information About OR-5000 [OR-5] or OR-300 [OR-3]

To learn more about the course and schedule, click the buttons below for the OR-300 Operational Resilience Implementer course and the OR-5000 Operational Resilience Expert Implementer course.

If you have any questions, click to contact us.