For a large international financial institution such as Bank of Nova Scotia (BNS), this methodology provides a disciplined approach for protecting the delivery of critical banking services while meeting regulatory expectations and supporting strategic business objectives.
The methodology aligns Operational Resilience with enterprise risk management, business continuity management, cyber resilience, technology resilience, third-party risk management, and crisis management, ensuring that resilience becomes an integral part of the bank's day-to-day operations rather than a standalone initiative.
The purpose of this chapter is to provide readers with a comprehensive overview of the Operational Resilience Planning Methodology that will be used throughout this eBook. Before examining each stage in detail, readers should understand how the fifteen stages fit together to form a structured implementation roadmap.
This understanding will enable readers to follow the remaining chapters with a clear appreciation of how each activity contributes to building and maintaining Operational Resilience across the enterprise.
The Operational Resilience Planning Methodology consists of three sequential phases:
Each phase builds upon the outcomes of the previous phase, creating a continuous improvement cycle rather than a one-time implementation project.
|
Phase |
Purpose |
|
Phase 1 – Plan |
Assess the organisation, define strategy, establish governance, and prepare for implementation. |
|
Phase 2 – Implement |
Identify Critical Business Services, understand dependencies, establish impact tolerances, and validate resilience through testing. |
|
Phase 3 – Sustain |
Embed Operational Resilience into organisational culture through communication, training, assurance, and continual improvement. |
The Plan phase establishes the strategic and governance foundations for Operational Resilience.
It enables BNS to understand its current maturity, identify opportunities for improvement, define its resilience strategy, clarify its risk appetite, and establish governance structures to support successful implementation.
The first stage evaluates BNS's current Operational Resilience capabilities across governance, risk management, business continuity, cyber resilience, technology resilience, third-party management, and incident response.
The assessment provides a baseline against which future improvements can be measured.
Example – BNS:
BNS conducts an enterprise-wide maturity assessment to determine how consistently Operational Resilience practices are implemented across its Canadian retail banking, international banking, capital markets, and wealth management businesses.
The assessment identifies varying levels of maturity between business units and highlights opportunities to standardise resilience practices.
Once the current capability has been assessed, the bank compares existing practices with internal objectives and applicable regulatory expectations to identify areas requiring enhancement.
Example – BNS:
A gap analysis identifies that while cyber resilience testing is well established, dependency mapping for Critical Business Services is inconsistent across international operations.
The findings become prioritised improvement initiatives within the implementation programme.
The Operational Resilience Strategy establishes the programme's long-term direction, while the implementation roadmap defines the sequence of activities, milestones, responsibilities, and resource requirements.
Example – BNS:
BNS develops a three-year Operational Resilience roadmap that prioritises identifying Critical Business Services, mapping enterprise dependencies, conducting scenario testing, and enhancing governance across its domestic and international operations.
Operational Resilience decisions should reflect the level of operational risk that the Board and Senior Management are prepared to accept while continuing to deliver critical banking services.
Example – BNS:
The Board confirms acceptable disruption thresholds for payment processing, digital banking availability, and customer access to banking services, ensuring that resilience investments align with the bank's overall risk appetite.
Governance establishes accountability, reporting structures, oversight mechanisms, policies, and decision-making processes for Operational Resilience.
Example – BNS:
BNS establishes an Operational Resilience Steering Committee comprising representatives from Operational Risk, Technology, Cybersecurity, Business Continuity, Compliance, Treasury, and Business Units, with regular reporting to Senior Management and the Board Risk Committee.
The Implement phase translates strategy into operational capability. During this phase, BNS identifies Critical Business Services, understands supporting dependencies, defines acceptable disruption levels, validates resilience through testing, and continuously improves its capabilities.
Example – BNS:
Critical Business Services include Retail Deposit Services, Digital Banking, Payment and Funds Transfer Services, Commercial Banking, Treasury Operations, Wealth Management, and Fraud Detection Services.
This stage identifies the people, processes, technology, applications, facilities, information, and third-party providers supporting each Critical Business Service.
Example – BNS:
For Digital Banking Services, BNS maps mobile banking platforms, authentication services, cloud infrastructure, payment gateways, telecommunications providers, cybersecurity controls, and customer support functions to identify operational dependencies and potential single points of failure.
Impact tolerances define the maximum acceptable level of disruption before customer harm or unacceptable business impact occurs.
Example – BNS:
BNS establishes measurable tolerances for online banking availability, payment processing times, ATM services, and customer contact centre response times to guide recovery priorities during major disruptions.
Scenario testing evaluates whether Critical Business Services remain within established impact tolerances during severe but plausible disruption events.
Example – BNS:
The bank conducts enterprise exercises involving ransomware attacks, cloud service provider outages, telecommunications failures, insider threats, and prolonged data centre disruptions to assess the resilience of payment services and digital banking.
Lessons learned from incidents, exercises, audits, and reviews are analysed and incorporated into continuous improvement activities.
Example – BNS:
Following a simulation involving a regional technology outage, BNS updates dependency maps, improves executive escalation procedures, strengthens third-party communication protocols, and enhances recovery playbooks for customer-facing services.
The Sustain phase embeds Operational Resilience into organisational culture and governance. It ensures resilience capabilities remain effective as technologies, business models, regulations, and threat landscapes evolve.
Operational Resilience becomes effective only when resilience thinking is embedded throughout the organisation rather than confined to specialist teams.
Example – BNS:
Senior leaders communicate the importance of Operational Resilience as a shared organisational responsibility, encouraging all employees to recognise their role in protecting Critical Business Services and responding effectively during disruptions.
An effective communication strategy supports stakeholder awareness before, during, and after operational disruption.
Example – BNS:
The bank develops communication plans for employees, customers, regulators, investors, third-party providers, and the media, ensuring consistent messaging during significant operational incidents.
Training ensures employees understand Operational Resilience principles, governance responsibilities, escalation procedures, and incident response expectations.
Example – BNS:
Targeted training programmes are delivered to executives, business managers, operational teams, technology personnel, and customer-facing employees, supported by role-based exercises and awareness campaigns.
Business units periodically assess the effectiveness of their Operational Resilience capabilities against established policies, standards, and performance indicators.
Example – BNS:
Each business division completes an annual self-assessment covering Critical Business Services, dependency mapping, scenario testing outcomes, governance effectiveness, and compliance with Operational Resilience requirements.
Independent reviews provide objective assurance that the Operational Resilience programme remains effective, appropriately governed, and aligned with regulatory expectations.
Example – BNS:
Internal Audit, or an independent assurance function, reviews governance, scenario testing, impact tolerances, dependency mapping, and resilience reporting, and provides recommendations for continuous improvement and Board oversight.
Operational Resilience is a continuous journey that requires structured planning, disciplined implementation, and sustained organisational commitment.
The three-phase Planning Methodology presented in this chapter provides the Bank of Nova Scotia with a practical framework for strengthening its ability to anticipate, withstand, respond to, recover from, and adapt to operational disruptions while maintaining the delivery of Critical Business Services.
By progressing systematically through the fifteen stages, BNS can integrate resilience into governance, risk management, technology, business continuity, cyber resilience, and day-to-day operations.
The chapters that follow explore each stage of the methodology in detail, providing practical guidance, implementation techniques, examples, and recommended deliverables.
Readers will gain the knowledge required to develop an Operational Resilience programme aligned with regulatory expectations, supporting informed decision-making and enhancing the long-term resilience of Bank of Nova Scotia's critical banking operations.
Blogs marked [x] are under construction
| C1 [x] | C2 [x] | C8 [x] | C14 [x] | |||
| eBook 2: Implementing Operational Resilience for Bank of Nova Scotia | ||||||
| eBook 1 | eBook 2 | eBook 3 | C20 [x] | C21 [x] | ||
| "Plan" Phase of the Operational Resilience Planning Methodology |
||||||
| C2 [x] | C3 [x] | C4 [x] | C5 [x] | C6 [x] | C7 [x] | |
| "Implement" Phase of the Operational Resilience Planning Methodology | ||||||
| C8 [x] | C9 [x] | C10 [x] | C11 [x] | C12 [x] | C13 [x] | |
| "Sustain" Phase of the Operational Resilience Planning Methodology | ||||||
| C14 [x] | C15 [x] | C16 [x] | C17 [x] | C18 [x] | C19 [x] | |
For organisations looking to accelerate their journey, BCM Institute’s training and certification programs, including the OR-5000 Operational Resilience Expert Implementer course, provide in-depth insights and practical toolkits for effectively embedding this model.
Gain Competency: For organisations looking to accelerate their journey, BCM Institute’s training and certification programs, including the OR-5000 Operational Resilience Expert Implementer course, provide in-depth insights and practical toolkits for effectively embedding this model.
To learn more about the course and schedule, click the buttons below for the OR-300 Operational Resilience Implementer course and the OR-5000 Operational Resilience Expert Implementer course.
|
If you have any questions, click to contact us. |
||
|
|