eBook OR

[OR] [BNS] [E2] [C1] Overview of Operational Resilience Planning Methodology

Written by Moh Heng Goh | Jul 11, 2026 12:49:51 PM

eBook 2: Chapter 1

Introduction


Operational Resilience is not achieved through a single project or technology investment. It is developed through a structured, repeatable methodology that enables an organisation to understand its current resilience capabilities, implement improvements systematically, and sustain those capabilities as the organisation evolves.

For a large international financial institution such as Bank of Nova Scotia (BNS), this methodology provides a disciplined approach for protecting the delivery of critical banking services while meeting regulatory expectations and supporting strategic business objectives.

This implementation guide adopts a three-phase Operational Resilience Planning Methodology consisting of Plan, Implement, and Sustain. Collectively, these phases comprise fifteen interrelated stages that guide BNS from initial capability assessment through governance, implementation, testing, organisational embedding, and continual improvement.

The methodology aligns Operational Resilience with enterprise risk management, business continuity management, cyber resilience, technology resilience, third-party risk management, and crisis management, ensuring that resilience becomes an integral part of the bank's day-to-day operations rather than a standalone initiative.

 

Purpose of the Chapter

The purpose of this chapter is to provide readers with a comprehensive overview of the Operational Resilience Planning Methodology that will be used throughout this eBook. Before examining each stage in detail, readers should understand how the fifteen stages fit together to form a structured implementation roadmap.

Upon completing this chapter, readers should be able to:

  • Understand the three phases of the Operational Resilience Planning Methodology.
  • Recognise the objectives of each implementation stage.
  • Appreciate how each stage contributes to the protection of Critical Business Services.
  • Understand how governance, operational risk management, business continuity, cyber resilience, and technology resilience are integrated throughout the methodology.
  • Relate each implementation stage to the operational environment of the Bank of Nova Scotia.

This understanding will enable readers to follow the remaining chapters with a clear appreciation of how each activity contributes to building and maintaining Operational Resilience across the enterprise.

 

Overview of the Operational Resilience Planning Methodology

The Operational Resilience Planning Methodology consists of three sequential phases:

  • Phase 1 – Plan
  • Phase 2 – Implement
  • Phase 3 – Sustain

Each phase builds upon the outcomes of the previous phase, creating a continuous improvement cycle rather than a one-time implementation project.

 

Phase

Purpose

Phase 1 – Plan

Assess the organisation, define strategy, establish governance, and prepare for implementation.

Phase 2 – Implement

Identify Critical Business Services, understand dependencies, establish impact tolerances, and validate resilience through testing.

Phase 3 – Sustain

Embed Operational Resilience into organisational culture through communication, training, assurance, and continual improvement.

 

Phase 1: Plan – Laying the Foundation for Resilience

 

The Plan phase establishes the strategic and governance foundations for Operational Resilience.

It enables BNS to understand its current maturity, identify opportunities for improvement, define its resilience strategy, clarify its risk appetite, and establish governance structures to support successful implementation.

 
Assess Capability and Maturity (Plan Phase - Stage 1)

The first stage evaluates BNS's current Operational Resilience capabilities across governance, risk management, business continuity, cyber resilience, technology resilience, third-party management, and incident response.

The assessment provides a baseline against which future improvements can be measured.

Example – BNS:

BNS conducts an enterprise-wide maturity assessment to determine how consistently Operational Resilience practices are implemented across its Canadian retail banking, international banking, capital markets, and wealth management businesses.

The assessment identifies varying levels of maturity between business units and highlights opportunities to standardise resilience practices.

Analyse Gap (Plan Phase - Stage 2)

Once the current capability has been assessed, the bank compares existing practices with internal objectives and applicable regulatory expectations to identify areas requiring enhancement.

Example – BNS:

A gap analysis identifies that while cyber resilience testing is well established, dependency mapping for Critical Business Services is inconsistent across international operations.

The findings become prioritised improvement initiatives within the implementation programme.

Develop Strategy and Roadmap (Plan Phase - Stage 3)

The Operational Resilience Strategy establishes the programme's long-term direction, while the implementation roadmap defines the sequence of activities, milestones, responsibilities, and resource requirements.

Example – BNS:

BNS develops a three-year Operational Resilience roadmap that prioritises identifying Critical Business Services, mapping enterprise dependencies, conducting scenario testing, and enhancing governance across its domestic and international operations.

Confirm Risk Appetite (Plan Phase - Stage 4)

Operational Resilience decisions should reflect the level of operational risk that the Board and Senior Management are prepared to accept while continuing to deliver critical banking services.

Example – BNS:

The Board confirms acceptable disruption thresholds for payment processing, digital banking availability, and customer access to banking services, ensuring that resilience investments align with the bank's overall risk appetite.

 

Develop and Embed Governance (Plan Phase - Stage 5)

Governance establishes accountability, reporting structures, oversight mechanisms, policies, and decision-making processes for Operational Resilience.

Example – BNS:

BNS establishes an Operational Resilience Steering Committee comprising representatives from Operational Risk, Technology, Cybersecurity, Business Continuity, Compliance, Treasury, and Business Units, with regular reporting to Senior Management and the Board Risk Committee.

 

Phase 2: Implement – Bringing the Strategy to Life

 

The Implement phase translates strategy into operational capability. During this phase, BNS identifies Critical Business Services, understands supporting dependencies, defines acceptable disruption levels, validates resilience through testing, and continuously improves its capabilities.

Identify Critical Business Services (Implement Phase - Stage 1)

The bank identifies customer-facing services whose disruption would cause significant customer harm, regulatory concern, or financial instability.

Example – BNS:

Critical Business Services include Retail Deposit Services, Digital Banking, Payment and Funds Transfer Services, Commercial Banking, Treasury Operations, Wealth Management, and Fraud Detection Services.

Map Processes and Resources (Implement Phase - Stage 2)

This stage identifies the people, processes, technology, applications, facilities, information, and third-party providers supporting each Critical Business Service.

Example – BNS:

For Digital Banking Services, BNS maps mobile banking platforms, authentication services, cloud infrastructure, payment gateways, telecommunications providers, cybersecurity controls, and customer support functions to identify operational dependencies and potential single points of failure.

Set Impact Tolerance (Implement Phase - Stage 3)

Impact tolerances define the maximum acceptable level of disruption before customer harm or unacceptable business impact occurs.

Example – BNS:

BNS establishes measurable tolerances for online banking availability, payment processing times, ATM services, and customer contact centre response times to guide recovery priorities during major disruptions.

Conduct Scenario Testing (Implement Phase - Stage 4)

Scenario testing evaluates whether Critical Business Services remain within established impact tolerances during severe but plausible disruption events.

Example – BNS:

The bank conducts enterprise exercises involving ransomware attacks, cloud service provider outages, telecommunications failures, insider threats, and prolonged data centre disruptions to assess the resilience of payment services and digital banking.

Improve Lessons Learned (Implement Phase - Stage 5)

Lessons learned from incidents, exercises, audits, and reviews are analysed and incorporated into continuous improvement activities.

Example – BNS:

Following a simulation involving a regional technology outage, BNS updates dependency maps, improves executive escalation procedures, strengthens third-party communication protocols, and enhances recovery playbooks for customer-facing services.

 

Phase 3: Sustain – Ensuring Long-term Resilience

 

The Sustain phase embeds Operational Resilience into organisational culture and governance. It ensures resilience capabilities remain effective as technologies, business models, regulations, and threat landscapes evolve.

Introduce Cultural Change (Sustain Phase - Stage 1)

Operational Resilience becomes effective only when resilience thinking is embedded throughout the organisation rather than confined to specialist teams.

Example – BNS:

Senior leaders communicate the importance of Operational Resilience as a shared organisational responsibility, encouraging all employees to recognise their role in protecting Critical Business Services and responding effectively during disruptions.

Develop Communication Strategy (Sustain Phase - Stage 2)

An effective communication strategy supports stakeholder awareness before, during, and after operational disruption.

Example – BNS:

The bank develops communication plans for employees, customers, regulators, investors, third-party providers, and the media, ensuring consistent messaging during significant operational incidents.

Implement Training and Awareness (Sustain Phase - Stage 3)

Training ensures employees understand Operational Resilience principles, governance responsibilities, escalation procedures, and incident response expectations.

Example – BNS:

Targeted training programmes are delivered to executives, business managers, operational teams, technology personnel, and customer-facing employees, supported by role-based exercises and awareness campaigns.

Provide Self-assessment (Sustain Phase - Stage 4)

Business units periodically assess the effectiveness of their Operational Resilience capabilities against established policies, standards, and performance indicators.

Example – BNS:

Each business division completes an annual self-assessment covering Critical Business Services, dependency mapping, scenario testing outcomes, governance effectiveness, and compliance with Operational Resilience requirements.

Conduct Independent Quality Review (Sustain Phase - Stage 5)

Independent reviews provide objective assurance that the Operational Resilience programme remains effective, appropriately governed, and aligned with regulatory expectations.

Example – BNS:

Internal Audit, or an independent assurance function, reviews governance, scenario testing, impact tolerances, dependency mapping, and resilience reporting, and provides recommendations for continuous improvement and Board oversight.

 

Operational Resilience is a continuous journey that requires structured planning, disciplined implementation, and sustained organisational commitment.

The three-phase Planning Methodology presented in this chapter provides the Bank of Nova Scotia with a practical framework for strengthening its ability to anticipate, withstand, respond to, recover from, and adapt to operational disruptions while maintaining the delivery of Critical Business Services.

By progressing systematically through the fifteen stages, BNS can integrate resilience into governance, risk management, technology, business continuity, cyber resilience, and day-to-day operations.

The chapters that follow explore each stage of the methodology in detail, providing practical guidance, implementation techniques, examples, and recommended deliverables.

Readers will gain the knowledge required to develop an Operational Resilience programme aligned with regulatory expectations, supporting informed decision-making and enhancing the long-term resilience of Bank of Nova Scotia's critical banking operations.

Blogs marked [x] are under construction

C1 [x] C2 [x] C8 [x]  C14 [x]      

 

  eBook 2: Implementing Operational Resilience for Bank of Nova Scotia
    eBook 1 eBook 2 eBook 3   C20 [x] C21 [x] 
   
  "Plan" Phase of the Operational Resilience Planning Methodology
  C2 [x] C3 [x] C4 [x] C5 [x] C6 [x] C7 [x]
  "Implement" Phase of the Operational Resilience Planning Methodology
  C8 [x] C9 [x] C10 [x] C11 [x] C12 [x] C13 [x]
 
  "Sustain" Phase of the Operational Resilience Planning Methodology
  C14 [x] C15 [x] C16 [x] C17 [x] C18 [x] C19 [x]
 


For organisations looking to accelerate their journey, BCM Institute’s training and certification programs, including the OR-5000 Operational Resilience Expert Implementer course, provide in-depth insights and practical toolkits for effectively embedding this model.

 

More Information About OR-5000 [OR-5] or OR-300 [OR-3]

Gain Competency: For organisations looking to accelerate their journey, BCM Institute’s training and certification programs, including the OR-5000 Operational Resilience Expert Implementer course, provide in-depth insights and practical toolkits for effectively embedding this model.

To learn more about the course and schedule, click the buttons below for the OR-300 Operational Resilience Implementer course and the OR-5000 Operational Resilience Expert Implementer course.

If you have any questions, click to contact us.