eBook OR

[OR] [GCash] [E1] [C3] Examining Operating Environment

Written by Moh Heng Goh | Aug 18, 2026, 9:00:39 AM

Chapter 3

Introduction

The purpose of this chapter is to examine the operating environment in which GCash delivers its financial services and to explain why understanding this environment is fundamental to organisational and operational resilience.

Under ISO 22316, an organisation should understand its context, relationships, dependencies, changing conditions and sources of uncertainty so that it can anticipate, respond and adapt effectively to disruption.

For GCash, this means looking beyond the mobile application itself and examining the wider environment that enables the continuous delivery of digital wallet, payment, transfer and related financial services.

This environment includes customers, merchants, banks and financial institutions, telecommunications networks, technology platforms, cybersecurity capabilities, employees, third-party service providers, regulators, public infrastructure and the broader Philippine financial ecosystem.

GCash's mobile wallet operations are handled by G-Xchange, Inc. (GXI), which states that it is regulated by the Bangko Sentral ng Pilipinas (BSP), while the organisation operates a broad digital financial ecosystem covering transfers, payments, bills, cash-in and cash-out, and services provided through affiliated and third-party partners. 

This chapter also helps readers understand how changes and disruptions in GCash's operating environment affect its ability to meet the operational resilience expectations set forth in BSP Circular No. 1203, Series of 2024 – Guidelines on Operational Resilience.

BSP requires supervised financial institutions to consider their own operating environment when identifying critical operations, determining severe but plausible scenarios, mapping interconnections and interdependencies, managing risks and conducting business continuity exercises.

In particular, BSP requires scenarios to be based on realistic assumptions specific to the institution and its operating environment.

By the end of this chapter, the reader should be able to identify the major internal and external factors affecting GCash, understand how these factors create dependencies and vulnerabilities, and recognise how changes in the operating environment should influence Critical Operation identification, Tolerance for Disruption, risk assessment, scenario testing, BCM arrangements and resilience improvement.

 

Understanding the Operating Environment

The operating environment represents the combination of internal and external conditions within which an organisation conducts its activities and delivers products and services.

For operational resilience, understanding the operating environment is particularly important because disruption often originates outside the organisation's boundaries.

GCash operates within a highly interconnected digital financial ecosystem.

Its ability to deliver services depends not only on its internal resources but also on networks of financial institutions, telecommunications providers, technology services, merchants, billers, payment networks, external service providers and customers.

GCash currently provides or facilitates services including payments, fund transfers, cash-in, cash-out, bill payments, cards, QR payments, and other digital financial services.

A number of additional products are delivered through affiliates or third-party partners, including savings, lending, investment, insurance and other financial services. 

Consequently, GCash's resilience cannot be assessed solely by determining whether the GCash mobile application is operational. It must be assessed from an end-to-end service delivery perspective.

A disruption affecting a telecommunications network, financial institution, cloud platform, identity-verification provider, merchant-acquiring arrangement, or payment-processing interface can ultimately affect the service experienced by the GCash customer, even if the originating disruption occurs outside GCash itself.

 

Internal Operating Environment

The internal operating environment consists of the capabilities, structures and resources controlled or managed by GCash that contribute to the delivery of its operations.

For operational resilience purposes, important internal considerations may include:

  • organisational governance and management oversight;
  • business and operational processes;
  • people and specialist competencies;
  • technology platforms and applications;
  • cybersecurity capabilities;
  • information and data;
  • operational risk management;
  • business continuity management;
  • incident and crisis management;
  • facilities and workplaces;
  • financial resources;
  • organisational culture;
  • change management;
  • communications and escalation arrangements; and
  • recovery and restoration capabilities.

These elements should not be examined independently. A Critical Operation normally relies upon several of them simultaneously.

For example, the ability to process a customer payment could require:

Customer request → authentication → transaction authorisation → wallet/ledger processing → connectivity to external systems → merchant or recipient confirmation → reconciliation → customer notification.

Failure anywhere along this chain may affect successful delivery of the operation.

 

External Operating Environment

GCash also operates in an external environment that can change rapidly and pose risks beyond the organisation's direct control.

Major external considerations include the following.

Regulatory Environment

As a BSP-regulated institution, GCash operates under the regulatory framework governing electronic money issuers and other BSP-supervised financial institutions.

Its own terms state that G-Xchange, Inc. is registered, licensed, and regulated by the BSP, and that the GCash Wallet is a reloadable electronic money instrument subject to applicable BSP rules and regulations. 

Changes in regulations may therefore affect areas such as:

  • operational resilience;
  • electronic money;
  • operational risk;
  • technology risk;
  • cybersecurity;
  • outsourcing;
  • consumer protection;
  • anti-money laundering;
  • data protection;
  • payments;
  • business continuity; and
  • incident reporting.

Regulatory change itself should therefore be treated as an important element of the operating environment.

Financial Ecosystem

GCash depends on interactions with other entities within the Philippine and international financial ecosystems.

These may include:

  • banks;
  • electronic money issuers;
  • payment networks;
  • clearing and settlement arrangements;
  • remittance organisations;
  • financial-service partners;
  • merchants;
  • billers; and
  • other payment counterparties.

GCash currently supports transfers to numerous partner banks and delivers a range of financial products through both its own platform and partnerships. 

Disruption involving one of these connections may therefore affect the end-to-end delivery of a GCash service.

Technology Environment

GCash operates primarily through digital channels. Its resilience is consequently highly dependent on the reliability, scalability and security of its information and communications technology environment.

Relevant factors include:

  • application availability;
  • cloud or data-centre services;
  • database availability;
  • transaction processing;
  • network connectivity;
  • telecommunications;
  • APIs;
  • authentication services;
  • cybersecurity controls;
  • monitoring systems;
  • backup and recovery;
  • infrastructure capacity; and
  • software changes.

BSP explicitly recognises technology and security as critical components of a safe and resilient operating environment.

The Circular expects BSFIs to adopt risk-based strategies that address confidentiality, integrity, and availability, and to regularly test ICT protection, detection, response, and recovery capabilities under increasingly complex disruption scenarios.

For GCash, therefore, ICT resilience and operational resilience are closely interconnected.

 

Telecommunications and Public Infrastructure

Mobile financial services inherently depend upon telecommunications and supporting public infrastructure.

For GCash, relevant dependencies may include:

  • mobile telecommunications networks;
  • internet connectivity;
  • electricity;
  • transport infrastructure;
  • data centres;
  • cloud infrastructure; and
  • other national digital infrastructure.

BSP Circular No. 1203 specifically requires BSFIs to assess dependencies on public infrastructure, such as telecommunications, transportation, and energy, in terms of their potential impact on Critical Operations and the established Tolerance for Disruption.

This has direct relevance to GCash.

For example, a prolonged telecommunications disruption could affect:

  • customer access to the GCash application;
  • OTP delivery;
  • payment confirmation;
  • merchant transactions;
  • account authentication;
  • customer support;
  • employee communications; and
  • incident coordination.

Operational resilience, therefore, requires management to consider not only failures within GCash's direct control but also failures in the infrastructure on which GCash depends.

 

Third-Party and Partner Environment

Third-party dependencies are another significant feature of GCash's operating environment.

GCash's published service catalogue indicates that some services are provided directly by GXI, while others are provided through Fuse Financing or external partners. 

Such an operating model provides significant business capability but also introduces dependencies.

Examples may include:

  • cloud service providers;
  • telecommunications providers;
  • banks;
  • identity verification providers;
  • cybersecurity services;
  • payment-processing providers;
  • merchant networks;
  • customer communication platforms;
  • infrastructure providers; and
  • financial-product partners.

BSP Circular No. 1203 places particular emphasis on third-party arrangements supporting Critical Operations.

Where such arrangements affect Critical Operations, they should address how the operation will continue during a disruption or establish appropriate exit arrangements in the event the provider can no longer deliver the service.

The institution is also expected to consider alternatives, including substitute providers or, where feasible, bringing services back in-house.

For GCash, this means third-party resilience should be evaluated from the perspective of the Critical Operation being supported, rather than solely through conventional vendor management assessments.

 

Customer and Market Environment

Customer expectations are also an important part of the operating environment.

Customers using a digital financial service typically expect near-continuous access to:

  • their wallets;
  • payments;
  • fund transfers;
  • transaction information;
  • merchant payments;
  • bill payments; and
  • account-management capabilities.

GCash reports that millions of Filipinos use its services and that its ecosystem includes millions of merchants and social sellers.

The scale of customer reliance increases the potential consequence of operational disruption.

A prolonged disruption could potentially create:

  • inability to access funds;
  • failed transactions;
  • delayed merchant payments;
  • inability to pay essential bills;
  • customer complaints;
  • reputational impact;
  • liquidity or reconciliation challenges;
  • regulatory concern; and
  • wider impacts across interconnected participants.

These considerations are important in determining whether an operation should be classified as a Critical Operation.

 

Cyber Threat Environment

Cyber risk represents an important external and internal operating-environment factor for a digital financial organisation.

Relevant threats may include:

  • ransomware;
  • distributed denial-of-service attacks;
  • credential theft;
  • account takeover;
  • malware;
  • API attacks;
  • data breaches;
  • phishing;
  • insider threats;
  • fraudulent transactions;
  • compromise of third-party systems; and
  • attacks targeting financial infrastructure.

Operational resilience differs from traditional cybersecurity in that it assumes preventive controls may sometimes fail.

The resilience question is therefore not only:

"Can GCash prevent the cyberattack?"

It must also ask:

"If the cyberattack succeeds, can GCash continue delivering its Critical Operations within the approved Tolerance for Disruption?"

This distinction aligns with the BSP expectation that ICT protection, detection, response and recovery arrangements should be tested against severe but plausible scenarios.

 

Changes in the Operating Environment

An operational resilience framework should not be based on a static picture of the organisation.

GCash's operating environment may change because of:

  • new products;
  • new customer segments;
  • changes in transaction volumes;
  • new technology platforms;
  • cloud migrations;
  • acquisitions or partnerships;
  • introduction of new payment channels;
  • new vendors;
  • regulatory changes;
  • cybersecurity developments;
  • organisational restructuring;
  • major technology releases;
  • changes in public infrastructure; and
  • emerging threats.

BSP Circular No. 1203 specifically requires the identification of Critical Operations to remain dynamic and to account for changes in operational components, lessons learned from disruptions, and emerging threats or vulnerabilities.

The Circular similarly expects change-management processes to evaluate how significant changes may affect both the delivery of Critical Operations and their interconnections and interdependencies.

For GCash, an operational resilience assessment should therefore be updated whenever significant changes occur.

 

BSP Requirement to Consider the Operating Environment

BSP Circular No. 1203 explicitly links an institution's operating environment to operational resilience testing.

The Circular requires periodic business continuity exercises covering Critical Operations, interconnections and key dependencies.

These exercises should use a range of severe yet plausible scenarios grounded in realistic assumptions specific to the BSFI and its operating environment.

This requirement is particularly important.

  • A generic scenario such as "system outage" may provide limited insight into resilience.

  • A scenario designed around GCash's actual operating environment might instead consider:

  • A prolonged disruption affecting a major telecommunications service simultaneously impacts customer connectivity, transaction authentication, and selected external payment interfaces during a period of high transaction demand.

Such a scenario examines several dependencies simultaneously and provides a more realistic test of organisational resilience.

Other implementation scenarios that may be appropriate for consideration include:

  • prolonged mobile application disruption;
  • failure of a critical payment-processing component;
  • widespread telecommunications outage;
  • cyberattack compromising several customer channels;
  • outage of a critical cloud or technology provider;
  • disruption involving a major financial-institution partner;
  • corruption or loss of transaction data;
  • simultaneous primary and recovery-environment failure;
  • major third-party service failure; and
  • cascading disruption across several interconnected operations.

These examples represent practical considerations for scenario design and should not be interpreted as individually prescribed BSP scenarios.

 

Connecting the Operating Environment to Critical Operations

Examining the operating environment directly supports the identification of GCash's Critical Operations.

BSP Circular No. 1203 requires BSFIs to use board-approved criteria when identifying and prioritising Critical Operations. The assessment should consider potential disruption impacts on:

  • the institution's viability;
  • customers; and
  • the institution's role within the financial system.

Importantly, the identification process should cover the end-to-end activities necessary to deliver the Critical Operation, rather than focusing solely on individual people, processes or systems.

For GCash, candidate Critical Operations could therefore include activities associated with:

  • Digital Wallet Operations;
  • Payment Transaction Processing;
  • Funds Transfer Operations;
  • Merchant Payment Operations;
  • Customer Account Access;
  • Cash-In and Cash-Out Operations;
  • Transaction Authorisation;
  • Financial Reconciliation; and
  • Service Recovery.

These are implementation examples requiring formal assessment and should not be interpreted as predetermined BSP classifications.

 

Mapping Interconnections and Interdependencies

Understanding the operating environment provides the information needed to perform dependency mapping.

BSP requires BSFIs to map the chains of activities necessary to deliver Critical Operations, particularly those involving internal and external interconnections and service-provider dependencies.

For GCash, a simplified dependency structure could be represented as:

Critical Operation

Business Processes

People

Applications and Technology

Data

Telecommunications

Financial Institutions

Third Parties

Public Infrastructure

Customer / Merchant Outcome

Mapping these relationships allows GCash to identify:

  • single points of failure;
  • concentrated dependencies;
  • capacity constraints;
  • key-person dependencies;
  • technology vulnerabilities;
  • third-party risks;
  • public-infrastructure dependencies; and
  • cascading effects across multiple Critical Operations.

BSP also expects mapping activities for operational resilience to be harmonised with related risk management disciplines, including operational risk, third-party risk, BCM, and ICT risk.

 

Tolerance for Disruption and Environmental Conditions

Once Critical Operations have been identified, BSP requires institutions to establish a clearly defined Tolerance for Disruption.

At a minimum, this should include a time-based measure that identifies how long delivery of a Critical Operation may be disrupted before material risk arises.

Other metrics may include the maximum number of customers affected or the transaction volumes and values affected.

The operating environment is important because the consequence of disruption may vary depending on circumstances.

For example, the impact of a two-hour payment outage could differ considerably depending on whether it occurs:

  • during normal transaction volumes;
  • during payroll periods;
  • during major shopping campaigns;
  • during holidays;
  • during a natural disaster;
  • while another financial institution is already experiencing disruption; or
  • during simultaneous telecommunications instability.

Operational resilience testing should therefore challenge the Tolerance for Disruption under conditions representative of GCash's actual operating environment.

 

Integration with Business Continuity Management

BSP Circular No. 1203 makes it clear that BCM should be an integral part of the operational resilience framework.

The BCM programme should be aligned with the institution's risk appetite and Tolerance for Disruption and should take a forward-looking view of how potential disruptions affect Critical Operations.

For GCash, the BCM programme should therefore support:

  • Business Impact Analysis;
  • recovery strategies;
  • incident recovery arrangements;
  • roles and responsibilities;
  • succession of authority;
  • crisis communications;
  • awareness and training;
  • scenario exercises; and
  • continuous improvement.

The significant difference is that BCM activities should increasingly be viewed through the lens of Critical Operations and Tolerance for Disruption.

Instead of asking only:

"Can the business process be recovered?"

GCash should also ask:

"Can the end-to-end Critical Operation remain within its Tolerance for Disruption?"

 

Example Compliance Considerations for GCash

The following table illustrates how examining GCash's operating environment supports compliance with BSP Circular No. 1203.

 

Operating Environment Area

BSP Operational Resilience Expectation

Example Application to GCash

Critical Operations

Identify and prioritise Critical Operations using board-approved criteria.

Assess digital wallet, payments, transfers and other significant operations based on customer and financial-system impact.

Operating Environment

Severe but plausible scenarios should reflect the BSFI's distinctive operating environment.

Develop GCash-specific disruption scenarios that reflect digital, telecommunications, cyber, and third-party dependencies.

Interconnections

Map activities and resources supporting Critical Operations.

Map applications, people, transaction-processing components, banks, telecommunications and external providers.

Third Parties

Identify and manage service provider dependencies that affect Critical Operations.

Assess whether critical service providers can maintain support during disruption and identify alternatives.

Public Infrastructure

Assess dependency on telecommunications, transport and energy.

Determine how telecom or power disruption could affect wallet and payment availability.

ICT and Security

Protect confidentiality, integrity, and availability, and regularly test protection, detection, response, and recovery.

Integrate cybersecurity and technology-resilience testing into Critical Operations exercises.

Change Management

Assess effects of significant changes on Critical Operations and dependencies.

Include an operational resilience impact assessment for major system, vendor, and product changes.

BCM

Integrate BCM and BCP into the operational resilience framework.

Align BIA, recovery strategies and continuity exercises with Critical Operations and Tolerance for Disruption.

Scenario Testing

Conduct periodic exercises using severe but plausible scenarios.

Test prolonged digital outages, cyber disruption and major dependency failures.

Response and Recovery

Maintain or restore Critical Operations within Tolerance for Disruption.

Establish alternative channels, recovery options and clear incident escalation arrangements.

Governance

Board oversight should apply to Critical Operations and tolerance-setting.

Provide management and board reporting on resilience vulnerabilities, testing and remediation.

Continuous Improvement

Update resilience arrangements to reflect changes, lessons, and new threats.

Use incidents, near misses, testing and technology changes to update resilience controls.

These requirements reflect the broader objective of BSP Circular No. 1203: to strengthen BSFIs' ability to manage disruptions affecting Critical Operations and to maintain the continued delivery of financial services. 

 

Relationship with ISO 22316

ISO 22316 emphasises that organisational resilience depends upon an organisation's ability to anticipate and respond to change.

Examining the operating environment therefore supports several organisational-resilience principles, including:

  • understanding organisational context;
  • shared purpose and direction;
  • awareness of changing conditions;
  • effective relationships and networks;
  • availability of resources;
  • organisational learning;
  • innovation and adaptability; and
  • coordinated decision-making.

For GCash, ISO 22316 provides a broader organisational resilience perspective, while BSP Circular No. 1203 sets out more specific operational resilience expectations for financial institutions.

The two perspectives are complementary.

  • ISO 22316 asks whether the organisation can adapt and thrive in a changing environment.

  • BSP operational resilience asks whether the institution can continue to deliver its Critical Operations during disruptions within acceptable tolerance levels.

Together, they create a comprehensive basis for resilience management.

 

Examining the operating environment is fundamental to understanding how resilience should be developed at GCash.

As a highly digital BSP-regulated financial services organisation, GCash operates within an interconnected ecosystem involving customers, merchants, financial institutions, telecommunications networks, technology infrastructure, third-party providers, public infrastructure, and regulatory authorities.

Disruption to any one of these components may affect the end-to-end delivery of a Critical Operation. Understanding these relationships enables GCash to move beyond individual-system recovery and adopt an enterprise-wide perspective on operational resilience.

BSP Circular No. 1203 reinforces this requirement by linking Critical Operation identification, Tolerance for Disruption, dependency mapping, risk management, technology resilience, BCM, and scenario testing directly to the institution's operating environment.

BSP expects scenarios to reflect realistic conditions distinctive to each BSFI and requires periodic resilience and business continuity exercises to encompass Critical Operations and their important dependencies.

When combined with ISO 22316, this approach enables GCash to understand where it operates, what it depends upon, what may change, where vulnerabilities exist and how disruption could affect customers and the wider financial ecosystem.

This operating-environment analysis therefore provides an essential foundation for the subsequent identification of Critical Operations, mapping of interconnections and interdependencies, establishment of Tolerance for Disruption, development of severe but plausible scenarios, scenario testing and continuous strengthening of operational resilience.

Note from Author: I have deliberately used Critical Operationsand Tolerance for Disruption, rather than the UK-style terms “Critical Business Services” and “Impact Tolerance”, when referring specifically to BSP Circular No. 1203, because those are the regulatory terms used by BSP.

 

Understanding Your Organisation
 
 
C1 C2 C3 C4 C5    
   
C6 C7 C8 C9 eBook Cover    
   
     

 

Gain Competency: For organisations looking to accelerate their journey, BCM Institute’s training and certification programs, including the OR-5000 Operational Resilience Expert Implementer course, provide in-depth insights and practical toolkits for effectively embedding this model.

 

More Information About OR-5000 [OR-5] or OR-300 [OR-3]

To learn more about the course and schedule, click the buttons below for the OR-300 Operational Resilience Implementer course and the OR-5000 Operational Resilience Expert Implementer course.

If you have any questions, click to contact us.