.

Implementing Operational Resilience for Bank of Nova Scotia: An Enterprise Implementation Guide
BB OR 2

[OR] [BNS] [E1] [C5] Identifying Critical Business Services

[OR] [BNS] [Full Banner] Implementing Operational Resilience for Bank of Nova Scotia

Operational resilience is founded on an organisation's ability to continue delivering its most important services despite severe disruptions.

For a large international financial institution such as Bank of Nova Scotia (BNS), identifying Critical Business Services (CBS) is one of the most important activities when establishing an enterprise operational resilience programme.

Rather than focusing solely on internal departments or business functions, operational resilience considers the services that customers, counterparties, regulators, and financial markets rely upon every day.

The identification of CBS enables BNS to determine which services require the highest level of protection, establish impact tolerances, understand operational dependencies, conduct scenario testing, and prioritise investment in resilience capabilities.

This service-oriented perspective provides a common foundation for governance, operational risk management, business continuity management, cyber resilience, technology resilience, third-party risk management, and crisis management.

As a global banking institution operating across multiple jurisdictions, BNS must ensure that disruptions do not cause intolerable harm to customers or threaten confidence in the financial system.

New call-to-action

Moh Heng Goh
Operational Resilience Certified Planner-Specialist-Expert

[OR] [BNS] Legal Disclaimer Banner

eBook 1: Chapter 5

New call-to-action

What are the Critical Business Services (CBS) of Bank of Nova Scotia?

 

Introduction

[OR] [GEN] [E1] [C5] Identifying Critical Business Services

Operational resilience is founded on an organisation's ability to continue delivering its most important services despite severe disruptions.

For a large international financial institution such as Bank of Nova Scotia (BNS), identifying Critical Business Services (CBS) is one of the most important activities when establishing an enterprise operational resilience programme.

Rather than focusing solely on internal departments or business functions, operational resilience considers the services that customers, counterparties, regulators, and financial markets rely upon every day.

The identification of CBS enables BNS to determine which services require the highest level of protection, establish impact tolerances, understand operational dependencies, conduct scenario testing, and prioritise investment in resilience capabilities.

This service-oriented perspective provides a common foundation for governance, operational risk management, business continuity management, cyber resilience, technology resilience, third-party risk management, and crisis management.

As a global banking institution operating across multiple jurisdictions, BNS must ensure that disruptions do not cause intolerable harm to customers or threaten confidence in the financial system.

 

What is a Critical Business Service (CBS)?

OR Critical Business Services BCMPediaA Critical Business Service (CBS) is a service delivered by an organisation to its customers or market participants that, if disrupted, could cause significant customer harm, threaten financial stability, create regulatory concerns, or materially affect the organisation's safety, soundness, or reputation.

Operational resilience, therefore, shifts the focus from protecting internal business functions to ensuring the continuous delivery of essential customer-facing services.

Unlike traditional Business Continuity Management (BCM), which primarily identifies Critical Business Functions (CBF), Operational Resilience adopts an end-to-end service perspective.

Each CBS encompasses the complete chain of people, processes, technology, facilities, data, and third-party providers required to deliver a service successfully. This broader perspective enables organisations to understand the full range of interconnections and dependencies supporting service delivery.

Once CBS has been identified, BNS can proceed to:

  • Establish impact tolerances for each critical service.
  • Map supporting business processes and operational dependencies.
  • Identify vulnerabilities and concentration risks.
  • Conduct severe but plausible scenario testing.
  • Prioritise resilience investments based on customer impact.
  • Demonstrate compliance with applicable operational resilience regulatory expectations.

 

Key Considerations for Identifying CBS at Bank of Nova Scotia

Although the precise list of CBS should be determined through an enterprise-wide assessment involving business leaders, operational risk specialists, technology teams, and senior management, several guiding principles should be applied.

Customer Harm

The primary consideration is whether disruption would create unacceptable consequences for retail, commercial, corporate, institutional, or wealth management customers.

Financial Stability

Services supporting payment systems, financial markets, liquidity, clearing, settlement, or wholesale banking may have broader systemic implications beyond BNS itself.

Regulatory Obligations

Services subject to banking regulations, anti-money laundering obligations, financial reporting requirements, consumer protection, and prudential supervision warrant careful consideration due to potential legal and supervisory consequences.

Revenue and Franchise Value

Services that generate significant revenue or support long-term customer relationships should receive heightened attention to resilience.

Operational Dependencies

Each service should be evaluated based on its dependence upon:

  • People
  • Business processes
  • Technology platforms
  • Applications
  • Data
  • Facilities
  • Communication networks
  • Cloud services
  • Third-party service providers
  • External financial market infrastructures
Interconnected Services

Many banking services depend upon one another. Understanding upstream and downstream dependencies enables BNS to identify single points of failure and systemic vulnerabilities before disruption occurs.

 

Critical Business Services of Bank of Nova Scotia

The following table presents a proposed set of Critical Business Services that would typically support an enterprise operational resilience programme for a diversified international banking institution. The final CBS inventory should be validated through governance workshops and approved by senior management.

 

No.

Proposed Critical Business Service

Purpose

Primary Customers

1

Retail Deposit and Account Services

Maintain customer deposits, savings, and current accounts

Retail customers

2

Retail Payments and Funds Transfer

Process domestic and international payments

Individuals and businesses

3

Digital Banking Services

Deliver online and mobile banking capabilities

Retail and commercial customers

4

ATM and Card Services

Provide cash withdrawal and card payment capabilities

Retail customers

5

Commercial Banking Services

Support lending, deposits, and transaction banking

Commercial clients

6

Corporate and Institutional Banking

Provide financing, treasury, and banking services

Large corporations and institutions

7

Treasury and Liquidity Management

Maintain liquidity, funding, and capital operations

Enterprise-wide

8

Foreign Exchange and International Payments

Facilitate cross-border financial transactions

Retail, corporate, and institutional clients

9

Wealth Management Services

Support investment advisory and portfolio management

Wealth management clients

10

Securities Custody and Investment Services

Safeguard investment assets and settlement activities

Institutional and wealth clients

11

Credit and Lending Services

Process consumer, commercial, and mortgage lending

Retail and commercial customers

12

Fraud Detection and Financial Crime Monitoring

Protect customers and comply with financial crime regulations

Enterprise-wide

13

Customer Contact Centre Services

Deliver customer support and incident handling

All customers

14

Regulatory Reporting and Compliance Services

Fulfil prudential and regulatory reporting obligations

Regulators

15

Cybersecurity and Identity Management Services

Protect digital banking platforms and customer identities

Enterprise-wide

 

Example: Severe but Plausible Scenarios Affecting the Bank of Nova Scotia CBS

Operational resilience programmes should evaluate how CBS perform during severe but plausible disruption scenarios.

These scenarios extend beyond traditional disaster recovery assumptions and assess whether critical services can continue operating within established impact tolerances.

 

Scenario

Potential Impacted CBS

Enterprise-wide ransomware attack

Digital Banking, Payments, Treasury, Customer Contact Centre

Major cloud service provider outage

Digital Banking, Wealth Management, Customer Services

Core banking system failure

Deposit Services, Lending, Payments, ATM Services

Cyberattack on payment infrastructure

Payments, International Transfers, Treasury

Telecommunications network outage

Contact Centre, Digital Banking, Card Authorisation

Third-party payment processor failure

Card Services, Merchant Payments

Insider threat causing data corruption

Customer Accounts, Lending, Regulatory Reporting

Pandemic causing workforce shortages

Contact Centre, Operations, Treasury, Compliance

Data centre outage

Multiple technology-dependent CBS

Cross-border geopolitical disruption

International Payments, Foreign Exchange, Trade Finance

 

Regulatory Alignment for Bank of Nova Scotia

As a federally regulated financial institution in Canada, Bank of Nova Scotia (BNS) is subject to the expectations of the Office of the Superintendent of Financial Institutions (OSFI), particularly Guideline E-21: Operational Risk Management and Resilience.

The guideline establishes that operational resilience is an outcome of effective operational risk management and requires financial institutions to develop the capability to continue delivering critical operations through severe disruptions.

Rather than viewing operational resilience as a standalone programme, OSFI expects it to be integrated into the institution's overall governance, risk management, business continuity, technology, cyber resilience, crisis management, data management, and third-party risk management frameworks.

Under Guideline E-21, BNS should identify and assess its critical operations—referred to in this eBook as Critical Business Services (CBS)—based on the potential impact that a disruption would have on the bank's continued operations, safety and soundness, customers, other financial institutions, and the stability of the Canadian financial system.

The assessment should adopt an end-to-end view of each service and consider both internal and external dependencies, recognising that operational resilience extends beyond technology recovery to encompass people, processes, information, facilities, third-party providers, and supporting infrastructure.

The identification of CBS provides the foundation for several key operational resilience activities expected by OSFI, including:

  • Identifying and assessing critical operations through a risk-based, enterprise-wide approach.
  • Mapping end-to-end operational dependencies, including people, technology, processes, information, facilities, third parties, and interconnected services.
  • Establishing and monitoring tolerances for disruption that define the maximum acceptable level of service disruption.
  • Conducting regular scenario analysis and testing of severe but plausible disruptions at both the business unit and enterprise levels.
  • Identifying operational vulnerabilities, concentration risks, and single points of failure across critical operations.
  • Escalating breaches of disruption tolerances and ensuring timely remediation of identified deficiencies.
  • Integrating operational resilience into governance, operational risk management, business continuity, technology risk, cyber resilience, third-party risk management, change management, data risk management, and crisis management programmes.
  • Promoting continuous improvement through lessons learned, periodic reassessment, and regular reporting to Senior Management and the Board.

Guideline E-21 also places strong emphasis on governance and accountability.

Senior Management is responsible for implementing and maintaining an effective operational risk management framework and operational resilience programme, while the Board provides oversight of the institution's resilience capabilities.

BNS should therefore ensure that governance arrangements clearly define responsibilities, allocate sufficient resources, establish reporting mechanisms, and promote a culture that supports effective operational resilience across all business lines.

By aligning its operational resilience programme with OSFI Guideline E-21, BNS can strengthen its ability to anticipate, withstand, respond to, recover from, and adapt to operational disruptions while continuing to deliver its critical banking services within established disruption tolerances.

This approach not only supports regulatory compliance but also reinforces customer confidence, financial stability, and the institution's long-term safety and soundness.

 

Banner [Summing] [OR] [E1] [C5] Identifying Critical Business Services

Identifying Critical Business Services is the cornerstone of an effective operational resilience programme.

It enables the Bank of Nova Scotia to focus resilience efforts on the services that matter most to customers, financial markets, regulators, and the wider economy.

By adopting a service-centric perspective, BNS can better understand the complex network of people, processes, technology, facilities, information, and third-party providers that underpins service delivery.

The proposed CBS presented in this chapter provides a practical starting point for implementing operational resilience.

In practice, these services should be validated through structured business workshops, dependency mapping, and executive governance to establish an enterprise-wide CBS inventory.

This inventory becomes the foundation for defining impact tolerances, analysing interdependencies, conducting scenario testing, and continually strengthening the bank's ability to withstand, respond to, recover from, and adapt to future disruptions while maintaining confidence in its critical banking services.

BL-OR-3-5 Blog Under Construction

Blogs marked [X] are under construction

[OR] [BNS] [3/4 Banner] Implementing Operational Resilience for Bank of Nova Scotia

Understanding Your Organisation
 
 
C1 C2 (X) C3 (X) C4 (X) C5    
[OR] [GEN] [E1] [C1] Introducing OR Case Study [OR] [GEN] [E1] [C2] Understanding Your Organisation [OR] [GEN] [E1] [C3] Examining Operating Environment [OR] [GEN] [E1] [C4] Composing the OR Team [OR] [BNS] [E1] [C5] Identifying Critical Business Services    
C6 (X) C7 (X) C8 (X) C9 (X) eBook Cover    
[OR] [GEN] [E1] [C6] Analysing Key Characteristics [OR] [GEN] [E1] [C7] Establishing Organisational Goals for Operational Resilience [OR] [GEN] [E1] [C8] Summary [OR] [GEN] [E1] [C9] [Back Cover] OR eBook Cover [OR] [BNS] [E1] [2D]    
     

 

New call-to-actionGain Competency: For organisations looking to accelerate their journey, BCM Institute’s training and certification programs, including the OR-5000 Operational Resilience Expert Implementer course, provide in-depth insights and practical toolkits for effectively embedding this model.

 

More Information About OR-5000 [OR-5] or OR-300 [OR-3]

To learn more about the course and schedule, click the buttons below for the OR-300 Operational Resilience Implementer and OR-5000 Operational Resilience Expert Implementer courses.

BL-OR-3 Register Now BL-OR-3_Tell Me More BL-OR-3_View Schedule
BL-OR-5_Register Now BL-OR-5_Tell Me More  [BL-OR] [3-4-5] View Schedule
[BL-OR] [3] FAQ OR-300

If you have any questions, click to contact us.Email to Sales Team [BCM Institute]

FAQ BL-OR-5 OR-5000
OR Implementer Landing Page

New call-to-action

New call-to-action

 

Comments

 

CTA Banner_OR

CTA Banner_ORA

CTA Banner_BCM

CTA Banner_ITDR

CTA Banner_CM