Under ISO 22316, an organisation should understand its context, relationships, dependencies, changing conditions and sources of uncertainty so that it can anticipate, respond and adapt effectively to disruption.
For GCash, this means looking beyond the mobile application itself and examining the wider environment that enables the continuous delivery of digital wallet, payment, transfer and related financial services.
This environment includes customers, merchants, banks and financial institutions, telecommunications networks, technology platforms, cybersecurity capabilities, employees, third-party service providers, regulators, public infrastructure and the broader Philippine financial ecosystem.
GCash's mobile wallet operations are handled by G-Xchange, Inc. (GXI), which states that it is regulated by the Bangko Sentral ng Pilipinas (BSP), while the organisation operates a broad digital financial ecosystem covering transfers, payments, bills, cash-in and cash-out, and services provided through affiliated and third-party partners.
This chapter also helps readers understand how changes and disruptions in GCash's operating environment affect its ability to meet the operational resilience expectations set forth in BSP Circular No. 1203, Series of 2024 – Guidelines on Operational Resilience.
BSP requires supervised financial institutions to consider their own operating environment when identifying critical operations, determining severe but plausible scenarios, mapping interconnections and interdependencies, managing risks and conducting business continuity exercises.
In particular, BSP requires scenarios to be based on realistic assumptions specific to the institution and its operating environment.
By the end of this chapter, the reader should be able to identify the major internal and external factors affecting GCash, understand how these factors create dependencies and vulnerabilities, and recognise how changes in the operating environment should influence Critical Operation identification, Tolerance for Disruption, risk assessment, scenario testing, BCM arrangements and resilience improvement.
The operating environment represents the combination of internal and external conditions within which an organisation conducts its activities and delivers products and services.
For operational resilience, understanding the operating environment is particularly important because disruption often originates outside the organisation's boundaries.
GCash operates within a highly interconnected digital financial ecosystem.
Its ability to deliver services depends not only on its internal resources but also on networks of financial institutions, telecommunications providers, technology services, merchants, billers, payment networks, external service providers and customers.
GCash currently provides or facilitates services including payments, fund transfers, cash-in, cash-out, bill payments, cards, QR payments, and other digital financial services.
A number of additional products are delivered through affiliates or third-party partners, including savings, lending, investment, insurance and other financial services.
Consequently, GCash's resilience cannot be assessed solely by determining whether the GCash mobile application is operational. It must be assessed from an end-to-end service delivery perspective.
A disruption affecting a telecommunications network, financial institution, cloud platform, identity-verification provider, merchant-acquiring arrangement, or payment-processing interface can ultimately affect the service experienced by the GCash customer, even if the originating disruption occurs outside GCash itself.
The internal operating environment consists of the capabilities, structures and resources controlled or managed by GCash that contribute to the delivery of its operations.
For operational resilience purposes, important internal considerations may include:
These elements should not be examined independently. A Critical Operation normally relies upon several of them simultaneously.
For example, the ability to process a customer payment could require:
Customer request → authentication → transaction authorisation → wallet/ledger processing → connectivity to external systems → merchant or recipient confirmation → reconciliation → customer notification.
Failure anywhere along this chain may affect successful delivery of the operation.
GCash also operates in an external environment that can change rapidly and pose risks beyond the organisation's direct control.
Major external considerations include the following.
As a BSP-regulated institution, GCash operates under the regulatory framework governing electronic money issuers and other BSP-supervised financial institutions.
Its own terms state that G-Xchange, Inc. is registered, licensed, and regulated by the BSP, and that the GCash Wallet is a reloadable electronic money instrument subject to applicable BSP rules and regulations.
Changes in regulations may therefore affect areas such as:
Regulatory change itself should therefore be treated as an important element of the operating environment.
GCash depends on interactions with other entities within the Philippine and international financial ecosystems.
These may include:
GCash currently supports transfers to numerous partner banks and delivers a range of financial products through both its own platform and partnerships.
Disruption involving one of these connections may therefore affect the end-to-end delivery of a GCash service.
GCash operates primarily through digital channels. Its resilience is consequently highly dependent on the reliability, scalability and security of its information and communications technology environment.
Relevant factors include:
BSP explicitly recognises technology and security as critical components of a safe and resilient operating environment.
The Circular expects BSFIs to adopt risk-based strategies that address confidentiality, integrity, and availability, and to regularly test ICT protection, detection, response, and recovery capabilities under increasingly complex disruption scenarios.
For GCash, therefore, ICT resilience and operational resilience are closely interconnected.
Mobile financial services inherently depend upon telecommunications and supporting public infrastructure.
For GCash, relevant dependencies may include:
BSP Circular No. 1203 specifically requires BSFIs to assess dependencies on public infrastructure, such as telecommunications, transportation, and energy, in terms of their potential impact on Critical Operations and the established Tolerance for Disruption.
This has direct relevance to GCash.
For example, a prolonged telecommunications disruption could affect:
Operational resilience, therefore, requires management to consider not only failures within GCash's direct control but also failures in the infrastructure on which GCash depends.
Third-party dependencies are another significant feature of GCash's operating environment.
GCash's published service catalogue indicates that some services are provided directly by GXI, while others are provided through Fuse Financing or external partners.
Such an operating model provides significant business capability but also introduces dependencies.
Examples may include:
BSP Circular No. 1203 places particular emphasis on third-party arrangements supporting Critical Operations.
Where such arrangements affect Critical Operations, they should address how the operation will continue during a disruption or establish appropriate exit arrangements in the event the provider can no longer deliver the service.
The institution is also expected to consider alternatives, including substitute providers or, where feasible, bringing services back in-house.
For GCash, this means third-party resilience should be evaluated from the perspective of the Critical Operation being supported, rather than solely through conventional vendor management assessments.
Customer expectations are also an important part of the operating environment.
Customers using a digital financial service typically expect near-continuous access to:
GCash reports that millions of Filipinos use its services and that its ecosystem includes millions of merchants and social sellers.
The scale of customer reliance increases the potential consequence of operational disruption.
A prolonged disruption could potentially create:
These considerations are important in determining whether an operation should be classified as a Critical Operation.
Cyber risk represents an important external and internal operating-environment factor for a digital financial organisation.
Relevant threats may include:
Operational resilience differs from traditional cybersecurity in that it assumes preventive controls may sometimes fail.
The resilience question is therefore not only:
"Can GCash prevent the cyberattack?"
It must also ask:
"If the cyberattack succeeds, can GCash continue delivering its Critical Operations within the approved Tolerance for Disruption?"
This distinction aligns with the BSP expectation that ICT protection, detection, response and recovery arrangements should be tested against severe but plausible scenarios.
An operational resilience framework should not be based on a static picture of the organisation.
GCash's operating environment may change because of:
BSP Circular No. 1203 specifically requires the identification of Critical Operations to remain dynamic and to account for changes in operational components, lessons learned from disruptions, and emerging threats or vulnerabilities.
The Circular similarly expects change-management processes to evaluate how significant changes may affect both the delivery of Critical Operations and their interconnections and interdependencies.
For GCash, an operational resilience assessment should therefore be updated whenever significant changes occur.
BSP Circular No. 1203 explicitly links an institution's operating environment to operational resilience testing.
The Circular requires periodic business continuity exercises covering Critical Operations, interconnections and key dependencies.
These exercises should use a range of severe yet plausible scenarios grounded in realistic assumptions specific to the BSFI and its operating environment.
This requirement is particularly important.
A generic scenario such as "system outage" may provide limited insight into resilience.
A scenario designed around GCash's actual operating environment might instead consider:
A prolonged disruption affecting a major telecommunications service simultaneously impacts customer connectivity, transaction authentication, and selected external payment interfaces during a period of high transaction demand.
Such a scenario examines several dependencies simultaneously and provides a more realistic test of organisational resilience.
Other implementation scenarios that may be appropriate for consideration include:
These examples represent practical considerations for scenario design and should not be interpreted as individually prescribed BSP scenarios.
Examining the operating environment directly supports the identification of GCash's Critical Operations.
BSP Circular No. 1203 requires BSFIs to use board-approved criteria when identifying and prioritising Critical Operations. The assessment should consider potential disruption impacts on:
Importantly, the identification process should cover the end-to-end activities necessary to deliver the Critical Operation, rather than focusing solely on individual people, processes or systems.
For GCash, candidate Critical Operations could therefore include activities associated with:
These are implementation examples requiring formal assessment and should not be interpreted as predetermined BSP classifications.
Understanding the operating environment provides the information needed to perform dependency mapping.
BSP requires BSFIs to map the chains of activities necessary to deliver Critical Operations, particularly those involving internal and external interconnections and service-provider dependencies.
For GCash, a simplified dependency structure could be represented as:
Critical Operation
↓
Business Processes
↓
People
↓
Applications and Technology
↓
Data
↓
Telecommunications
↓
Financial Institutions
↓
Third Parties
↓
Public Infrastructure
↓
Customer / Merchant Outcome
Mapping these relationships allows GCash to identify:
BSP also expects mapping activities for operational resilience to be harmonised with related risk management disciplines, including operational risk, third-party risk, BCM, and ICT risk.
At a minimum, this should include a time-based measure that identifies how long delivery of a Critical Operation may be disrupted before material risk arises.
Other metrics may include the maximum number of customers affected or the transaction volumes and values affected.
The operating environment is important because the consequence of disruption may vary depending on circumstances.
For example, the impact of a two-hour payment outage could differ considerably depending on whether it occurs:
Operational resilience testing should therefore challenge the Tolerance for Disruption under conditions representative of GCash's actual operating environment.
BSP Circular No. 1203 makes it clear that BCM should be an integral part of the operational resilience framework.
The BCM programme should be aligned with the institution's risk appetite and Tolerance for Disruption and should take a forward-looking view of how potential disruptions affect Critical Operations.
For GCash, the BCM programme should therefore support:
The significant difference is that BCM activities should increasingly be viewed through the lens of Critical Operations and Tolerance for Disruption.
Instead of asking only:
"Can the business process be recovered?"
GCash should also ask:
"Can the end-to-end Critical Operation remain within its Tolerance for Disruption?"
The following table illustrates how examining GCash's operating environment supports compliance with BSP Circular No. 1203.
|
Operating Environment Area |
BSP Operational Resilience Expectation |
Example Application to GCash |
|
Critical Operations |
Identify and prioritise Critical Operations using board-approved criteria. |
Assess digital wallet, payments, transfers and other significant operations based on customer and financial-system impact. |
|
Operating Environment |
Severe but plausible scenarios should reflect the BSFI's distinctive operating environment. |
Develop GCash-specific disruption scenarios that reflect digital, telecommunications, cyber, and third-party dependencies. |
|
Interconnections |
Map activities and resources supporting Critical Operations. |
Map applications, people, transaction-processing components, banks, telecommunications and external providers. |
|
Third Parties |
Identify and manage service provider dependencies that affect Critical Operations. |
Assess whether critical service providers can maintain support during disruption and identify alternatives. |
|
Public Infrastructure |
Assess dependency on telecommunications, transport and energy. |
Determine how telecom or power disruption could affect wallet and payment availability. |
|
ICT and Security |
Protect confidentiality, integrity, and availability, and regularly test protection, detection, response, and recovery. |
Integrate cybersecurity and technology-resilience testing into Critical Operations exercises. |
|
Change Management |
Assess effects of significant changes on Critical Operations and dependencies. |
Include an operational resilience impact assessment for major system, vendor, and product changes. |
|
BCM |
Integrate BCM and BCP into the operational resilience framework. |
Align BIA, recovery strategies and continuity exercises with Critical Operations and Tolerance for Disruption. |
|
Scenario Testing |
Conduct periodic exercises using severe but plausible scenarios. |
Test prolonged digital outages, cyber disruption and major dependency failures. |
|
Response and Recovery |
Maintain or restore Critical Operations within Tolerance for Disruption. |
Establish alternative channels, recovery options and clear incident escalation arrangements. |
|
Governance |
Board oversight should apply to Critical Operations and tolerance-setting. |
Provide management and board reporting on resilience vulnerabilities, testing and remediation. |
|
Continuous Improvement |
Update resilience arrangements to reflect changes, lessons, and new threats. |
Use incidents, near misses, testing and technology changes to update resilience controls. |
These requirements reflect the broader objective of BSP Circular No. 1203: to strengthen BSFIs' ability to manage disruptions affecting Critical Operations and to maintain the continued delivery of financial services.
ISO 22316 emphasises that organisational resilience depends upon an organisation's ability to anticipate and respond to change.
Examining the operating environment therefore supports several organisational-resilience principles, including:
For GCash, ISO 22316 provides a broader organisational resilience perspective, while BSP Circular No. 1203 sets out more specific operational resilience expectations for financial institutions.
The two perspectives are complementary.
ISO 22316 asks whether the organisation can adapt and thrive in a changing environment.
BSP operational resilience asks whether the institution can continue to deliver its Critical Operations during disruptions within acceptable tolerance levels.
Together, they create a comprehensive basis for resilience management.
Examining the operating environment is fundamental to understanding how resilience should be developed at GCash.
As a highly digital BSP-regulated financial services organisation, GCash operates within an interconnected ecosystem involving customers, merchants, financial institutions, telecommunications networks, technology infrastructure, third-party providers, public infrastructure, and regulatory authorities.
Disruption to any one of these components may affect the end-to-end delivery of a Critical Operation. Understanding these relationships enables GCash to move beyond individual-system recovery and adopt an enterprise-wide perspective on operational resilience.
BSP Circular No. 1203 reinforces this requirement by linking Critical Operation identification, Tolerance for Disruption, dependency mapping, risk management, technology resilience, BCM, and scenario testing directly to the institution's operating environment.
BSP expects scenarios to reflect realistic conditions distinctive to each BSFI and requires periodic resilience and business continuity exercises to encompass Critical Operations and their important dependencies.
When combined with ISO 22316, this approach enables GCash to understand where it operates, what it depends upon, what may change, where vulnerabilities exist and how disruption could affect customers and the wider financial ecosystem.
This operating-environment analysis therefore provides an essential foundation for the subsequent identification of Critical Operations, mapping of interconnections and interdependencies, establishment of Tolerance for Disruption, development of severe but plausible scenarios, scenario testing and continuous strengthening of operational resilience.
Note from Author: I have deliberately used “Critical Operations” and “Tolerance for Disruption”, rather than the UK-style terms “Critical Business Services” and “Impact Tolerance”, when referring specifically to BSP Circular No. 1203, because those are the regulatory terms used by BSP.
Understanding Your Organisation
|
|
|
||||
| C1 | C2 | C3 | C4 | C5 | ||
| C6 | C7 | C8 | C9 | eBook Cover | ||
To learn more about the course and schedule, click the buttons below for the OR-300 Operational Resilience Implementer course and the OR-5000 Operational Resilience Expert Implementer course.
|
If you have any questions, click to contact us. |
||
|
|