Chapter 4
Composing the Operational Resilience Team for GCash
Introduction
The purpose of this chapter is to establish the recommended governance and organisational structure for implementing and sustaining Operational Resilience at GCash.
Operational Resilience is not the responsibility of a single department such as Business Continuity, Operational Risk, Technology, Cybersecurity or Compliance.
It requires coordinated participation across the organisation because the ability to deliver Critical Operations through disruption depends upon people, processes, technology, information, facilities, third parties and external interconnections working together.
BSP Circular No. 1203 explicitly requires that Operational Resilience be integrated into the institution's existing governance structure and related risk management processes, rather than being treated as a stand-alone programme.
The Circular also establishes clear responsibilities for the Board of Directors, senior management and the three lines of defence in developing, approving, implementing, reviewing and enhancing the Operational Resilience Framework.
This chapter therefore provides a practical recommended team structure for GCash that translates these regulatory expectations into an operational model.
By the end of the chapter, the reader should understand how responsibilities should be distributed from the Board and executive-management level through an Operational Resilience Steering Committee, programme leadership, Critical Operations owners, Business Continuity, Operational Risk, Technology, Cybersecurity, Third-Party Risk, Compliance and Internal Audit.
The objective is to establish clear accountability, avoid fragmented resilience activities, enable coordinated decision-making and ensure that information on Critical Operations, Tolerance for Disruption, vulnerabilities, scenario-testing results and remediation actions reaches the appropriate governance level.
This structure should enable GCash to demonstrate that Operational Resilience is embedded into enterprise governance and day-to-day risk management rather than maintained as a separate compliance exercise.
Why an Operational Resilience Team Is Required
Operational Resilience differs from traditional Business Continuity Management because its focus extends across the end-to-end delivery of Critical Operations.
BSP defines Operational Resilience as the ability of a BSP-Supervised Financial Institution to deliver its Critical Operations through significant operational disruption.
Critical Operations may rely upon people, technology, information, facilities, internal processes, clearing and settlement arrangements, outsourced services and other supporting assets.
For GCash, this means resilience cannot be managed effectively by a single specialised team acting independently.
For example, the resilience of a digital wallet transaction could involve:
Business Operations → Technology → Cybersecurity → Telecommunications → Authentication → Transaction Processing → Partner Bank or Payment Infrastructure → Merchant or Recipient → Customer Communication → Reconciliation
Each component may have different owners, controls, and recovery arrangements.
The Operational Resilience team therefore needs to act as the integrating governance mechanism that connects these functions to the continued delivery of GCash's Critical Operations.
BSP Governance Expectations
BSP Circular No. 1203 provides an important basis for the proposed GCash structure.
The Circular requires BSFIs to use their existing governance structure to establish, oversee and implement an effective Operational Resilience approach.
This governance arrangement should define the roles and responsibilities of the Board of Directors and senior management across the development, approval, implementation, ongoing review and enhancement of the Operational Resilience Framework.
BSP assigns the Board of Directors primary responsibility for oversight and approval of the Operational Resilience Framework, including the roles of the three lines of defence.
The three lines identified by BSP are:
- First Line: Business units and internal controls;
- Second Line: Risk Management and Compliance; and
- Third Line: Internal Audit.
Senior management, meanwhile, is expected to lead the implementation of the Operational Resilience Framework, assess the institution's resilience capability, and communicate the required remedial actions to the Board.
This establishes an important principle for GCash:
Operational Resilience should be governed at the enterprise level but executed across the organisation.
Proposed Operational Resilience Governance Structure for GCash
A recommended governance structure for GCash is shown below.
Board of Directors / Board Risk Committee
↓
President / CEO and Executive Management
↓
Operational Resilience Steering Committee
↓
Operational Resilience Programme Lead
↓
Critical Operation Owners
↓
Cross-Functional Operational Resilience Working Group
Supporting functions:
Business Operations | Operational Risk | BCM | Crisis Management | Technology | ICT Risk | Cybersecurity | Third-Party Risk | Compliance | Legal | Data | Finance | Customer Operations | Corporate Communications | Human Resources
Independent assurance:
Internal Audit
This structure is a recommended implementation model, not a prescribed BSP organisational chart.
BSP establishes governance responsibilities and three-lines-of-defence expectations, while the institution determines how these responsibilities are embedded within its organisational structure.
Level 1 – Board of Directors / Board Risk Committee
The highest level of Operational Resilience governance should reside with the Board of Directors, potentially supported by the Board Risk Committee or another appropriate Board-level committee.
Under BSP Circular No. 1203, the Board is primarily responsible for overseeing and approving the Operational Resilience Framework.
For GCash, recommended Board responsibilities include:
- approving the Operational Resilience Framework;
- approving or overseeing the criteria for identifying Critical Operations;
- reviewing the institution's overall resilience posture;
- reviewing material resilience vulnerabilities;
- overseeing significant Tolerance for Disruption decisions;
- reviewing severe but plausible scenario-testing results;
- overseeing major remediation programmes;
- ensuring appropriate resilience investment;
- challenging management where Critical Operations cannot remain within approved tolerance levels; and
- ensuring that the three lines of defence discharge their Operational Resilience responsibilities.
The Board should receive sufficient information to assess whether GCash could continue to deliver its most important operations during significant disruption.
The Board should therefore receive decision-oriented resilience information, rather than detailed operational data alone.
Recommended Board Operational Resilience Dashboard
The Board or Board Risk Committee could receive periodic reporting covering:
|
Reporting Area |
Example Board Information |
|
Critical Operations |
Approved Critical Operations and significant changes |
|
Tolerance for Disruption |
Approved tolerance levels and emerging concerns |
|
Resilience Status |
Overall resilience assessment by Critical Operation |
|
Major Vulnerabilities |
Significant weaknesses or single points of failure |
|
Scenario Testing |
Key test outcomes and tolerance breaches |
|
Major Incidents |
Material disruption affecting Critical Operations |
|
Third-Party Risk |
Critical provider vulnerabilities and concentration risk |
|
Technology Resilience |
Significant ICT resilience concerns |
|
Cyber Resilience |
Material cyber scenarios affecting Critical Operations |
|
Remediation |
Overdue or high-priority resilience actions |
|
Regulatory Compliance |
Material BSP Operational Resilience gaps |
|
Investment |
Significant resilience capabilities requiring funding |
This enables the Board to exercise meaningful oversight rather than simply receive confirmation that resilience exercises have been completed.
Level 2 – President / CEO and Executive Management
Senior management should translate Board direction into operational execution.
BSP states that senior management should lead the implementation of the Operational Resilience Framework, assess the institution's Operational Resilience capabilities, and communicate necessary remedial actions to the Board.
For GCash, the President/CEO and executive management should therefore:
- sponsor Operational Resilience at enterprise level;
- establish management accountability;
- approve resources and priorities;
- resolve conflicts between business and resilience objectives;
- ensure Critical Operation owners are formally appointed;
- oversee implementation of the Operational Resilience roadmap;
- ensure material vulnerabilities are remediated;
- review significant scenario-testing results;
- ensure incidents are escalated appropriately;
- support cross-functional collaboration; and
- provide the Board with accurate information regarding resilience capability.
Senior management should particularly ensure that Operational Resilience does not become confined to a risk, BCM or technology team.
Level 3 – Operational Resilience Steering Committee
GCash should establish an Operational Resilience Steering Committee as the principal management forum for coordinating resilience activities across the organisation.
The Committee should ideally be chaired by an executive with sufficient authority to resolve cross-functional issues.
A possible Chair could be:
Chief Risk Officer
with participation from other key executives.
The Steering Committee should provide management-level oversight between the Board/executive level and the Operational Resilience working teams.
Recommended Membership
The Steering Committee could include representatives from:
- Executive Management;
- Operational Risk;
- Business Operations;
- Technology;
- Cybersecurity;
- Business Continuity;
- Crisis Management;
- Third-Party Risk;
- Compliance;
- Legal;
- Finance;
- Customer Operations;
- Data and Information Management;
- Corporate Communications; and
- Human Resources.
Critical Operations owners should participate where matters affecting their operations are discussed.
Responsibilities of the Operational Resilience Steering Committee
The Steering Committee should:
- oversee implementation of the Operational Resilience Framework;
- recommend Critical Operations for approval;
- review proposed Tolerance for Disruption;
- review dependency-mapping results;
- identify cross-functional vulnerabilities;
- review severe but plausible scenarios;
- approve the annual scenario-testing programme;
- monitor test outcomes;
- prioritise remediation actions;
- resolve cross-functional resilience issues;
- monitor third-party resilience concerns;
- review significant incidents;
- oversee lessons identified;
- monitor Operational Resilience programme maturity;
- escalate material concerns to executive management and the Board; and
- ensure alignment between Operational Resilience and existing risk-management disciplines.
The Committee should meet regularly and more frequently where major incidents or significant resilience concerns arise.
Level 4 – Operational Resilience Programme Lead
A designated Operational Resilience Programme Lead should coordinate implementation across the organisation.
This role does not replace the accountability of Critical Operation owners or other functions.
Rather, the Programme Lead acts as the central integrator.
Recommended responsibilities include:
- maintaining the Operational Resilience Framework;
- coordinating Critical Operation identification;
- developing methodologies and templates;
- coordinating Tolerance for Disruption assessments;
- managing dependency-mapping activities;
- facilitating severe but plausible scenario development;
- coordinating scenario-testing programmes;
- monitoring remediation actions;
- facilitating Operational Resilience governance meetings;
- coordinating regulatory submissions and evidence;
- maintaining the Operational Resilience roadmap;
- coordinating awareness and training;
- maintaining programme documentation; and
- preparing management and Board reporting.
The Programme Lead should have sufficient organisational authority and access to senior management to challenge gaps and escalate unresolved resilience issues.
Critical Operation Owners
One of the most important roles in the proposed GCash structure is the Critical Operation Owner.
Each identified Critical Operation should have a senior business owner accountable for its end-to-end resilience.
This is important because BSP's Operational Resilience approach focuses on the continued delivery of Critical Operations rather than individual departments, processes or systems. Critical Operations may cut across many organisational functions and supporting assets.
For example, if Digital Wallet Operations were identified as a Critical Operation, responsibility should not reside solely with Technology.
Its resilience may depend on:
- wallet operations;
- customer authentication;
- transaction processing;
- technology platforms;
- cybersecurity;
- telecommunications;
- financial counterparties;
- customer communications;
- reconciliation;
- service providers; and
- recovery processes.
The Critical Operation Owner should therefore take responsibility for the resilience outcome across this complete chain.
Responsibilities of a Critical Operation Owner
Recommended responsibilities include:
- confirming the scope of the Critical Operation;
- identifying supporting processes and resources;
- reviewing interconnections and interdependencies;
- proposing Tolerance for Disruption;
- identifying vulnerabilities;
- participating in scenario development;
- approving scenario-testing objectives;
- participating in exercises;
- reviewing test results;
- accepting or escalating identified risks;
- ensuring remediation actions are completed; and
- reporting resilience status to the Steering Committee.
The Critical Operation Owner should not be expected to personally control every dependency.
Instead, the role is responsible for ensuring that the operation's end-to-end resilience is understood and appropriately managed.
Cross-Functional Operational Resilience Working Group
Below the Steering Committee, GCash should establish a Cross-Functional Operational Resilience Working Group.
This group performs much of the detailed analytical and implementation work.
Recommended members may include:
|
Function |
Primary Operational Resilience Contribution |
|
Business Operations |
Process ownership and operational knowledge |
|
Operational Risk |
Risk identification, assessment and treatment |
|
Business Continuity |
BIA, continuity strategies and recovery planning |
|
Crisis Management |
Strategic incident coordination |
|
Technology |
Application and infrastructure resilience |
|
ICT Risk |
Technology-risk challenge and oversight |
|
Cybersecurity |
Cyber threat and response capabilities |
|
Third-Party Risk |
Supplier and outsourcing dependencies |
|
Compliance |
Regulatory interpretation and compliance monitoring |
|
Legal |
Contractual and legal considerations |
|
Customer Operations |
Customer-impact assessment |
|
Finance |
Financial and liquidity consequences |
|
Data Management |
Data integrity, availability and recovery |
|
Communications |
Customer, regulator and stakeholder communications |
|
Human Resources |
Workforce and key-person resilience |
This structure reflects BSP's expectation that Operational Resilience should leverage existing risk-management frameworks rather than operate in a silo.
BSP specifically identifies operational risk, business continuity, third-party risk and information and technology risk as relevant interconnected disciplines.
Role of Business Continuity Management
Business Continuity Management should remain a major contributor to Operational Resilience.
BSP states that BCM is an essential component of Operational Resilience and recognises the complementary relationship between the two.
BCM tends to address specific failure points, while Operational Resilience examines the end-to-end delivery of Critical Operations.
Within the GCash Operational Resilience Team, BCM should contribute:
- Business Impact Analysis;
- recovery requirements;
- continuity strategies;
- Business Continuity Plans;
- recovery procedures;
- business continuity exercises;
- alternate work arrangements;
- crisis management integration;
- recovery coordination; and
- lessons identified.
BCM, therefore, provides essential recovery capabilities, while Operational Resilience provides the broader end-to-end framework.
Role of Operational Risk Management
Operational Risk should provide the risk-management foundation for the programme.
BSP describes Operational Resilience as closely linked to Operational Risk Management but broader in focus, as it considers whether disruptions prevent the continued delivery of Critical Operations and the harm they may cause to customers and the wider financial system.
Operational Risk should support:
- risk identification;
- control assessments;
- emerging-risk monitoring;
- operational-risk event analysis;
- risk appetite alignment;
- vulnerability assessment;
- scenario assessment;
- remediation monitoring; and
- risk reporting.
Operational Risk should also provide independent second-line challenge to resilience assessments performed by the business.
Role of Technology and ICT Risk
Technology teams should be responsible for building and maintaining the technical capabilities required to support Critical Operations.
Relevant responsibilities include:
- infrastructure resilience;
- application availability;
- architecture resilience;
- capacity management;
- disaster recovery;
- system redundancy;
- backup and recovery;
- monitoring;
- failover;
- data restoration; and
- technical incident response.
ICT Risk should provide independent assessment and challenge of technology-related resilience exposure.
For GCash, this relationship is particularly important because the delivery of financial services is highly dependent on digital technology.
Role of Cybersecurity
Cybersecurity should be integrated into the Operational Resilience Team because cyber incidents can create significant operational disruption.
BSP emphasises the relationship between cybersecurity and Operational Resilience and expects institutions to understand the evolving cyber threat landscape and to strengthen their cyber resilience capabilities.
The Cybersecurity function should contribute:
- threat intelligence;
- cyber-risk assessments;
- preventive controls;
- security monitoring;
- incident detection;
- cyber incident response;
- forensic capability;
- cyber recovery;
- ransomware preparedness;
- penetration testing; and
- cyber scenario exercises.
Operational Resilience should then evaluate whether these capabilities collectively allow GCash to continue delivering Critical Operations within its Tolerance for Disruption.
Role of Third-Party Risk Management
Third-party providers may support important components of GCash's Critical Operations.
BSP states that third-party service providers supporting processes feeding into Critical Operations should maintain an appropriate level of Operational Resilience consistent with the requirements established by the BSFI.
The Third-Party Risk function should therefore:
- identify critical suppliers;
- map suppliers to Critical Operations;
- assess concentration risk;
- review resilience capabilities;
- evaluate contingency arrangements;
- assess exit strategies;
- participate in scenario tests involving suppliers;
- monitor service performance;
- review contractual resilience obligations; and
- monitor significant provider incidents.
This allows GCash to understand resilience beyond its organisational boundary.
Role of Compliance
Compliance should provide second-line regulatory oversight.
Its responsibilities should include:
- interpreting BSP Operational Resilience requirements;
- monitoring compliance with Circular No. 1203;
- reviewing policies and procedures;
- assessing regulatory gaps;
- supporting regulatory reporting;
- reviewing governance evidence;
- monitoring regulatory developments; and
- escalating material compliance issues.
Compliance should not own the Operational Resilience programme itself.
Instead, it should independently assess whether implementation meets regulatory expectations.
Role of Internal Audit
Internal Audit represents the third line of defence.
BSP specifically identifies Internal Audit as the third line within the Operational Resilience governance structure.
Internal Audit should independently assess:
- governance effectiveness;
- framework design;
- Critical Operation identification;
- Tolerance for Disruption methodology;
- dependency mapping;
- scenario-testing quality;
- remediation governance;
- regulatory compliance;
- reliability of management reporting; and
- effectiveness of the three-lines-of-defence arrangement.
Internal Audit should remain independent from programme design and operational implementation.
Three Lines of Defence for GCash Operational Resilience
A recommended structure is shown below.
|
Line of Defence |
Participants |
Main Responsibility |
|
First Line |
Critical Operation Owners, Business Units, Technology Operations, Customer Operations and supporting operational teams |
Own and manage resilience risks; maintain Critical Operations |
|
Second Line |
Operational Risk, ICT Risk, Compliance, Third-Party Risk and relevant control functions |
Establish frameworks, monitor, challenge and provide oversight |
|
Third Line |
Internal Audit |
Provide independent assurance |
The Board oversees the effectiveness of all three lines, while senior management leads implementation.
This directly reflects the governance principles contained in BSP Circular No. 1203.
Proposed GCash Operational Resilience Organisation
The desired Operational Resilience governance structure for GCash can therefore be represented as follows:
Board of Directors / Board Risk Committee
Strategic oversight and approval
↓
President / CEO and Executive Management
Executive accountability and sponsorship
↓
Operational Resilience Steering Committee
Cross-enterprise governance and decision-making
↓
Operational Resilience Programme Lead
Programme coordination and integration
↓
Critical Operation Owners
End-to-end resilience accountability
↓
Operational Resilience Working Group
Business OperationsOperational Risk
BCM
Crisis Management
Technology
ICT Risk
Cybersecurity
Third-Party Risk
Compliance
Legal
Data
Finance
Customer Operations
Human Resources
Corporate Communications
↓
Supporting Operational Teams and Critical Third Parties
Alongside this structure:
Internal Audit → Independent Third-Line Assurance
Example Responsibility Matrix
|
Operational Resilience Activity |
Board |
Senior Management |
OR Steering Committee |
OR Programme Lead |
Critical Operation Owner |
Risk / Compliance |
Internal Audit |
|
Approve OR Framework |
A |
R |
C |
C |
I |
C |
I |
|
Implement OR Framework |
I |
A |
R |
R |
C |
C |
I |
|
Identify Critical Operations |
A |
C |
R |
R |
R |
C |
I |
|
Set Tolerance for Disruption |
A |
C |
R |
C |
R |
C |
I |
|
Dependency Mapping |
I |
I |
C |
R |
A/R |
C |
I |
|
Identify Severe but Plausible Scenarios |
I |
C |
A |
R |
R |
C |
I |
|
Scenario Testing |
I |
C |
A |
R |
R |
C |
I |
|
Remediation |
I |
A |
R |
C |
R |
C |
I |
|
Regulatory Compliance |
I |
A |
C |
C |
C |
R |
I |
|
Independent Assurance |
I |
I |
I |
I |
I |
I |
A/R |
Key: A – Accountable; R – Responsible; C – Consulted; I – Informed
The precise RACI should be adjusted to reflect GCash's approved corporate governance structure.
Team Responsibilities During a Major Disruption
The Operational Resilience governance structure must also work during actual disruption.
BSP expects institutions to define roles, responsibilities, and succession of authority as part of their response and recovery capabilities.
Incident-response plans should identify key officers and personnel, internal and external resources, event classification, response and recovery procedures, and communication arrangements.
For GCash, the governance structure during disruption could transition as follows:
Operational Incident
↓
Incident Management Team
↓
Crisis Management Team
↓
Critical Operation Owner
↓
Operational Resilience / BCM Coordination
↓
Executive Management
↓
Board Notification where Material
↓
BSP Notification where Regulatory Thresholds Apply
This structure should be predetermined rather than designed during the incident.
Regulatory Incident Reporting Responsibilities
The Operational Resilience Team should also establish clear responsibility for regulatory notification.
Under BSP Circular No. 1203, a BSFI must notify the appropriate BSP supervising department within 24 hours from activation of the incident response plan for Critical Operations.
Information should include, where applicable, the nature and duration of the disruption, affected Critical Operations, whether Tolerance for Disruption has been breached, and actions management has taken or intends to take to continue delivery.
GCash should therefore predetermine:
- who determines whether the reporting threshold has been met;
- who prepares the notification;
- who approves it;
- who submits it to BSP;
- who maintains communication with the regulator; and
- who ensures subsequent information is provided where requested.
This should involve Operations, Risk, Compliance, Legal, Incident Management and senior management as appropriate.
Competencies Required of the Operational Resilience Team
The effectiveness of the team will depend not merely on organisational titles but on appropriate competencies.
Collectively, the GCash Operational Resilience Team should understand:
- Operational Resilience concepts;
- BSP Circular No. 1203;
- GCash's operating model;
- Critical Operations;
- Operational Risk;
- BCM;
- Crisis Management;
- ICT resilience;
- Cybersecurity;
- third-party risk;
- dependency mapping;
- Tolerance for Disruption;
- scenario development;
- scenario testing;
- incident response;
- regulatory reporting; and
- continuous improvement.
Cross-functional awareness is especially important.
-
Technology staff need to understand business impact.
-
Business owners need to understand technology dependencies.
-
Risk specialists need to understand end-to-end operations.
-
Senior leaders need to understand the consequences of breaches of Tolerance for Disruption.
Operational Resilience Team Deliverables
The team should collectively produce and maintain a defined set of Operational Resilience deliverables.
These should include:
- Operational Resilience Policy;
- Operational Resilience Framework;
- governance structure;
- Critical Operation inventory;
- Critical Operation ownership register;
- Tolerance for Disruption statements;
- dependency maps;
- vulnerability assessments;
- Severe but Plausible Scenario catalogue;
- scenario-testing programme;
- scenario-testing reports;
- BCM and recovery strategies;
- Critical Third-Party register;
- remediation register;
- incident-response arrangements;
- regulatory-notification procedures;
- awareness and training records;
- Operational Resilience management reports; and
- Board reporting.
Together, these demonstrate that Operational Resilience is being actively managed rather than merely documented.
Continuous Review of the Team Structure
The Operational Resilience organisation should not remain static.
BSP requires the Operational Resilience Framework to be periodically reviewed, refined and updated so that it remains aligned with the institution's risk appetite, Tolerance for Disruption, business model and complexity.
Reviews should also occur when material changes arise in operations or business activities.
GCash should therefore review its Operational Resilience team structure when there are significant changes involving:
- organisational restructuring;
- new Critical Operations;
- new products;
- major technology changes;
- new third-party arrangements;
- regulatory changes;
- acquisitions or partnerships;
- major incidents;
- significant test findings; or
- changes in business scale or complexity.
Governance should evolve together with the organisation.
Composing the Operational Resilience Team is a foundational step in strengthening Operational Resilience at GCash.
The programme requires more than appointing an Operational Resilience Manager or assigning responsibility to Business Continuity.
Because Critical Operations depend upon interconnected business processes, people, technology, data, third parties, and external financial infrastructure, effective resilience requires coordinated accountability across the enterprise.
BSP Circular No. 1203 reinforces this principle by requiring Operational Resilience to operate through existing governance structures, with the Board primarily responsible for oversight and approval, senior management responsible for leading implementation, the first line responsible for managing resilience within the business, the second line providing risk and compliance oversight, and Internal Audit providing independent third-line assurance.
For GCash, the recommended structure therefore combines Board oversight, executive sponsorship, an Operational Resilience Steering Committee, a central Operational Resilience Programme Lead, accountable Critical Operation Owners and a cross-functional Operational Resilience Working Group, supported by independent second- and third-line challenge.
The purpose of this structure is not to create another organisational silo, but to integrate existing capabilities around the end-to-end delivery of Critical Operations.
When clearly defined responsibilities, escalation paths, decision rights, competencies and reporting mechanisms are established, GCash will be better positioned to identify vulnerabilities, establish Tolerance for Disruption, coordinate scenario testing, respond to major incidents, complete remediation and demonstrate to the Bangko Sentral ng Pilipinas that Operational Resilience is embedded within its governance and risk-management system.
The proposed organisation chart and RACI are recommended implementation structures, not structures explicitly prescribed by BSP. Circular No. 1203 prescribes the governance responsibilities and three-lines-of-defence expectations, while giving the institution flexibility to embed them within its existing governance structure.
Understanding Your Organisation
|
|
|
||||
| C1 | C2 | C3 | C4 | C5 | ||
![]() |
![]() |
![]() |
![]() |
![]() |
||
| C6 | C7 | C8 | C9 | eBook Cover | ||
![]() |
![]() |
![]() |
![]() |
![]() |
||
Gain Competency: For organisations looking to accelerate their journey, BCM Institute’s training and certification programs, including the OR-5000 Operational Resilience Expert Implementer course, provide in-depth insights and practical toolkits for effectively embedding this model.

![BB OR [C] 4 BB OR [C] 4](https://blog.bcm-institute.org/hs-fs/hubfs/OR%20picture/OR%20Pictures%20A/BB%20OR%20Folder%20C/BB%20OR%20%5BC%5D%204.jpg?width=2000&height=1333&name=BB%20OR%20%5BC%5D%204.jpg)
![[OR] [GCash] [Full Banner] Strengthening Operational Resilience at GCash](https://no-cache.hubspot.com/cta/default/3893111/3a39ca09-f7ed-4e75-858f-941c41224c31.png)

![[OR] [GCash] [Disclaimer] Legal Disclaimers and Usage of eBook Banner](https://no-cache.hubspot.com/cta/default/3893111/454a0c6c-3084-45f4-b724-65b4ca4eb6d1.png)
![Banner [Summing] [OR] [E1] [C4] Composing the OR Team](https://no-cache.hubspot.com/cta/default/3893111/1686cd9b-8dc6-4e4b-ac68-9cbab48d9225.png)
![[OR] [GCash] [3/4 Banner] Strengthening Operational Resilience at GCash](https://no-cache.hubspot.com/cta/default/3893111/f32c765b-c3ba-4ed6-bd15-6dc928547f19.png)
![[OR] [GCash] [E1] [C1] Introducing OR Case Study](https://no-cache.hubspot.com/cta/default/3893111/49375b92-7717-4d7f-82a3-f5ca7b4c5ca4.png)
![[OR] [GCash] [E1] [C2] Understanding Your Organisation](https://no-cache.hubspot.com/cta/default/3893111/eb990ab7-3dbf-4f68-b9cb-e4116375e810.png)
![[OR] [GCash] [E1] [C3] Examining Operating Environment](https://no-cache.hubspot.com/cta/default/3893111/e60a4256-bfe8-4290-94ed-f179c7ada080.png)
![[OR] [GCash] [E1] [C5] Identifying Critical Business Services](https://no-cache.hubspot.com/cta/default/3893111/d6eaf971-de08-4db7-b16d-d8dcd953210b.png)
![[OR] [GCash] [E1] [C6] Analysing Key Characteristics](https://no-cache.hubspot.com/cta/default/3893111/f46b1de5-6d77-4fca-b7a6-c57f0adf20da.png)
![[OR] [GCash] [E1] [C7] Establishing Organisational Goals](https://no-cache.hubspot.com/cta/default/3893111/45763717-cdcc-4b7b-b83d-d21494bbfdc9.png)
![[OR] [GCash] [E1] [C8] Summary](https://no-cache.hubspot.com/cta/default/3893111/5b0ed315-15e9-46c7-82f4-09c1a1d17139.png)
![[OR] [GCash] [E1] [C9] Back Cover](https://no-cache.hubspot.com/cta/default/3893111/015a1be7-2368-4cbd-978a-f15eecfbd6f9.png)
![x eBook Cover [OR] [GCash] [E1] [2D]](https://no-cache.hubspot.com/cta/default/3893111/6be54ccc-e74c-4dc1-9dca-7f943817ad55.png)





![[BL-OR] [3-4-5] View Schedule](https://no-cache.hubspot.com/cta/default/3893111/d0d733a1-16c0-4b68-a26d-adbfd4fc6069.png)
![[BL-OR] [3] FAQ OR-300](https://no-cache.hubspot.com/cta/default/3893111/f20c71b4-f5e8-4aa5-8056-c374ca33a091.png)
![Email to Sales Team [BCM Institute]](https://no-cache.hubspot.com/cta/default/3893111/3c53daeb-2836-4843-b0e0-645baee2ab9e.png)








