Operational Resilience is not the responsibility of a single department such as Business Continuity, Operational Risk, Technology, Cybersecurity or Compliance.
It requires coordinated participation across the organisation because the ability to deliver Critical Operations through disruption depends upon people, processes, technology, information, facilities, third parties and external interconnections working together.
BSP Circular No. 1203 explicitly requires that Operational Resilience be integrated into the institution's existing governance structure and related risk management processes, rather than being treated as a stand-alone programme.
The Circular also establishes clear responsibilities for the Board of Directors, senior management and the three lines of defence in developing, approving, implementing, reviewing and enhancing the Operational Resilience Framework.
This chapter therefore provides a practical recommended team structure for GCash that translates these regulatory expectations into an operational model.
By the end of the chapter, the reader should understand how responsibilities should be distributed from the Board and executive-management level through an Operational Resilience Steering Committee, programme leadership, Critical Operations owners, Business Continuity, Operational Risk, Technology, Cybersecurity, Third-Party Risk, Compliance and Internal Audit.
The objective is to establish clear accountability, avoid fragmented resilience activities, enable coordinated decision-making and ensure that information on Critical Operations, Tolerance for Disruption, vulnerabilities, scenario-testing results and remediation actions reaches the appropriate governance level.
This structure should enable GCash to demonstrate that Operational Resilience is embedded into enterprise governance and day-to-day risk management rather than maintained as a separate compliance exercise.
Operational Resilience differs from traditional Business Continuity Management because its focus extends across the end-to-end delivery of Critical Operations.
BSP defines Operational Resilience as the ability of a BSP-Supervised Financial Institution to deliver its Critical Operations through significant operational disruption.
Critical Operations may rely upon people, technology, information, facilities, internal processes, clearing and settlement arrangements, outsourced services and other supporting assets.
For GCash, this means resilience cannot be managed effectively by a single specialised team acting independently.
For example, the resilience of a digital wallet transaction could involve:
Each component may have different owners, controls, and recovery arrangements.
The Operational Resilience team therefore needs to act as the integrating governance mechanism that connects these functions to the continued delivery of GCash's Critical Operations.
BSP Circular No. 1203 provides an important basis for the proposed GCash structure.
The Circular requires BSFIs to use their existing governance structure to establish, oversee and implement an effective Operational Resilience approach.
This governance arrangement should define the roles and responsibilities of the Board of Directors and senior management across the development, approval, implementation, ongoing review and enhancement of the Operational Resilience Framework.
BSP assigns the Board of Directors primary responsibility for oversight and approval of the Operational Resilience Framework, including the roles of the three lines of defence.
The three lines identified by BSP are:
Senior management, meanwhile, is expected to lead the implementation of the Operational Resilience Framework, assess the institution's resilience capability, and communicate the required remedial actions to the Board.
This establishes an important principle for GCash:
Operational Resilience should be governed at the enterprise level but executed across the organisation.
A recommended governance structure for GCash is shown below.
Board of Directors / Board Risk Committee
↓
President / CEO and Executive Management
↓
Operational Resilience Steering Committee
↓
Operational Resilience Programme Lead
↓
Critical Operation Owners
↓
Cross-Functional Operational Resilience Working Group
Supporting functions:
Business Operations | Operational Risk | BCM | Crisis Management | Technology | ICT Risk | Cybersecurity | Third-Party Risk | Compliance | Legal | Data | Finance | Customer Operations | Corporate Communications | Human Resources
Independent assurance:
Internal Audit
This structure is a recommended implementation model, not a prescribed BSP organisational chart.
BSP establishes governance responsibilities and three-lines-of-defence expectations, while the institution determines how these responsibilities are embedded within its organisational structure.
The highest level of Operational Resilience governance should reside with the Board of Directors, potentially supported by the Board Risk Committee or another appropriate Board-level committee.
Under BSP Circular No. 1203, the Board is primarily responsible for overseeing and approving the Operational Resilience Framework.
For GCash, recommended Board responsibilities include:
The Board should receive sufficient information to assess whether GCash could continue to deliver its most important operations during significant disruption.
The Board should therefore receive decision-oriented resilience information, rather than detailed operational data alone.
The Board or Board Risk Committee could receive periodic reporting covering:
|
Reporting Area |
Example Board Information |
|
Critical Operations |
Approved Critical Operations and significant changes |
|
Tolerance for Disruption |
Approved tolerance levels and emerging concerns |
|
Resilience Status |
Overall resilience assessment by Critical Operation |
|
Major Vulnerabilities |
Significant weaknesses or single points of failure |
|
Scenario Testing |
Key test outcomes and tolerance breaches |
|
Major Incidents |
Material disruption affecting Critical Operations |
|
Third-Party Risk |
Critical provider vulnerabilities and concentration risk |
|
Technology Resilience |
Significant ICT resilience concerns |
|
Cyber Resilience |
Material cyber scenarios affecting Critical Operations |
|
Remediation |
Overdue or high-priority resilience actions |
|
Regulatory Compliance |
Material BSP Operational Resilience gaps |
|
Investment |
Significant resilience capabilities requiring funding |
This enables the Board to exercise meaningful oversight rather than simply receive confirmation that resilience exercises have been completed.
Senior management should translate Board direction into operational execution.
BSP states that senior management should lead the implementation of the Operational Resilience Framework, assess the institution's Operational Resilience capabilities, and communicate necessary remedial actions to the Board.
For GCash, the President/CEO and executive management should therefore:
Senior management should particularly ensure that Operational Resilience does not become confined to a risk, BCM or technology team.
GCash should establish an Operational Resilience Steering Committee as the principal management forum for coordinating resilience activities across the organisation.
The Committee should ideally be chaired by an executive with sufficient authority to resolve cross-functional issues.
A possible Chair could be:
with participation from other key executives.
The Steering Committee should provide management-level oversight between the Board/executive level and the Operational Resilience working teams.
The Steering Committee could include representatives from:
Critical Operations owners should participate where matters affecting their operations are discussed.
The Steering Committee should:
The Committee should meet regularly and more frequently where major incidents or significant resilience concerns arise.
A designated Operational Resilience Programme Lead should coordinate implementation across the organisation.
This role does not replace the accountability of Critical Operation owners or other functions.
Rather, the Programme Lead acts as the central integrator.
Recommended responsibilities include:
The Programme Lead should have sufficient organisational authority and access to senior management to challenge gaps and escalate unresolved resilience issues.
One of the most important roles in the proposed GCash structure is the Critical Operation Owner.
Each identified Critical Operation should have a senior business owner accountable for its end-to-end resilience.
This is important because BSP's Operational Resilience approach focuses on the continued delivery of Critical Operations rather than individual departments, processes or systems. Critical Operations may cut across many organisational functions and supporting assets.
For example, if Digital Wallet Operations were identified as a Critical Operation, responsibility should not reside solely with Technology.
Its resilience may depend on:
The Critical Operation Owner should therefore take responsibility for the resilience outcome across this complete chain.
Recommended responsibilities include:
The Critical Operation Owner should not be expected to personally control every dependency.
Instead, the role is responsible for ensuring that the operation's end-to-end resilience is understood and appropriately managed.
Below the Steering Committee, GCash should establish a Cross-Functional Operational Resilience Working Group.
This group performs much of the detailed analytical and implementation work.
Recommended members may include:
|
Function |
Primary Operational Resilience Contribution |
|
Business Operations |
Process ownership and operational knowledge |
|
Operational Risk |
Risk identification, assessment and treatment |
|
Business Continuity |
BIA, continuity strategies and recovery planning |
|
Crisis Management |
Strategic incident coordination |
|
Technology |
Application and infrastructure resilience |
|
ICT Risk |
Technology-risk challenge and oversight |
|
Cybersecurity |
Cyber threat and response capabilities |
|
Third-Party Risk |
Supplier and outsourcing dependencies |
|
Compliance |
Regulatory interpretation and compliance monitoring |
|
Legal |
Contractual and legal considerations |
|
Customer Operations |
Customer-impact assessment |
|
Finance |
Financial and liquidity consequences |
|
Data Management |
Data integrity, availability and recovery |
|
Communications |
Customer, regulator and stakeholder communications |
|
Human Resources |
Workforce and key-person resilience |
This structure reflects BSP's expectation that Operational Resilience should leverage existing risk-management frameworks rather than operate in a silo.
BSP specifically identifies operational risk, business continuity, third-party risk and information and technology risk as relevant interconnected disciplines.
Business Continuity Management should remain a major contributor to Operational Resilience.
BSP states that BCM is an essential component of Operational Resilience and recognises the complementary relationship between the two.
BCM tends to address specific failure points, while Operational Resilience examines the end-to-end delivery of Critical Operations.
Within the GCash Operational Resilience Team, BCM should contribute:
BCM, therefore, provides essential recovery capabilities, while Operational Resilience provides the broader end-to-end framework.
Operational Risk should provide the risk-management foundation for the programme.
BSP describes Operational Resilience as closely linked to Operational Risk Management but broader in focus, as it considers whether disruptions prevent the continued delivery of Critical Operations and the harm they may cause to customers and the wider financial system.
Operational Risk should support:
Operational Risk should also provide independent second-line challenge to resilience assessments performed by the business.
Technology teams should be responsible for building and maintaining the technical capabilities required to support Critical Operations.
Relevant responsibilities include:
ICT Risk should provide independent assessment and challenge of technology-related resilience exposure.
For GCash, this relationship is particularly important because the delivery of financial services is highly dependent on digital technology.
Cybersecurity should be integrated into the Operational Resilience Team because cyber incidents can create significant operational disruption.
BSP emphasises the relationship between cybersecurity and Operational Resilience and expects institutions to understand the evolving cyber threat landscape and to strengthen their cyber resilience capabilities.
The Cybersecurity function should contribute:
Operational Resilience should then evaluate whether these capabilities collectively allow GCash to continue delivering Critical Operations within its Tolerance for Disruption.
Third-party providers may support important components of GCash's Critical Operations.
BSP states that third-party service providers supporting processes feeding into Critical Operations should maintain an appropriate level of Operational Resilience consistent with the requirements established by the BSFI.
The Third-Party Risk function should therefore:
This allows GCash to understand resilience beyond its organisational boundary.
Compliance should provide second-line regulatory oversight.
Its responsibilities should include:
Compliance should not own the Operational Resilience programme itself.
Instead, it should independently assess whether implementation meets regulatory expectations.
Internal Audit represents the third line of defence.
BSP specifically identifies Internal Audit as the third line within the Operational Resilience governance structure.
Internal Audit should independently assess:
Internal Audit should remain independent from programme design and operational implementation.
A recommended structure is shown below.
|
Line of Defence |
Participants |
Main Responsibility |
|
First Line |
Critical Operation Owners, Business Units, Technology Operations, Customer Operations and supporting operational teams |
Own and manage resilience risks; maintain Critical Operations |
|
Second Line |
Operational Risk, ICT Risk, Compliance, Third-Party Risk and relevant control functions |
Establish frameworks, monitor, challenge and provide oversight |
|
Third Line |
Internal Audit |
Provide independent assurance |
The Board oversees the effectiveness of all three lines, while senior management leads implementation.
This directly reflects the governance principles contained in BSP Circular No. 1203.
The desired Operational Resilience governance structure for GCash can therefore be represented as follows:
Board of Directors / Board Risk Committee
Strategic oversight and approval
↓
President / CEO and Executive Management
Executive accountability and sponsorship
↓
Operational Resilience Steering Committee
Cross-enterprise governance and decision-making
↓
Operational Resilience Programme Lead
Programme coordination and integration
↓
Critical Operation Owners
End-to-end resilience accountability
↓
Operational Resilience Working Group
Business Operations↓
Supporting Operational Teams and Critical Third Parties
Alongside this structure:
Internal Audit → Independent Third-Line Assurance
|
Operational Resilience Activity |
Board |
Senior Management |
OR Steering Committee |
OR Programme Lead |
Critical Operation Owner |
Risk / Compliance |
Internal Audit |
|
Approve OR Framework |
A |
R |
C |
C |
I |
C |
I |
|
Implement OR Framework |
I |
A |
R |
R |
C |
C |
I |
|
Identify Critical Operations |
A |
C |
R |
R |
R |
C |
I |
|
Set Tolerance for Disruption |
A |
C |
R |
C |
R |
C |
I |
|
Dependency Mapping |
I |
I |
C |
R |
A/R |
C |
I |
|
Identify Severe but Plausible Scenarios |
I |
C |
A |
R |
R |
C |
I |
|
Scenario Testing |
I |
C |
A |
R |
R |
C |
I |
|
Remediation |
I |
A |
R |
C |
R |
C |
I |
|
Regulatory Compliance |
I |
A |
C |
C |
C |
R |
I |
|
Independent Assurance |
I |
I |
I |
I |
I |
I |
A/R |
Key: A – Accountable; R – Responsible; C – Consulted; I – Informed
The precise RACI should be adjusted to reflect GCash's approved corporate governance structure.
The Operational Resilience governance structure must also work during actual disruption.
BSP expects institutions to define roles, responsibilities, and succession of authority as part of their response and recovery capabilities.
Incident-response plans should identify key officers and personnel, internal and external resources, event classification, response and recovery procedures, and communication arrangements.
For GCash, the governance structure during disruption could transition as follows:
Operational Incident
↓
Incident Management Team
↓
Crisis Management Team
↓
Critical Operation Owner
↓
Operational Resilience / BCM Coordination
↓
Executive Management
↓
Board Notification where Material
↓
BSP Notification where Regulatory Thresholds Apply
This structure should be predetermined rather than designed during the incident.
The Operational Resilience Team should also establish clear responsibility for regulatory notification.
Under BSP Circular No. 1203, a BSFI must notify the appropriate BSP supervising department within 24 hours from activation of the incident response plan for Critical Operations.
Information should include, where applicable, the nature and duration of the disruption, affected Critical Operations, whether Tolerance for Disruption has been breached, and actions management has taken or intends to take to continue delivery.
GCash should therefore predetermine:
This should involve Operations, Risk, Compliance, Legal, Incident Management and senior management as appropriate.
The effectiveness of the team will depend not merely on organisational titles but on appropriate competencies.
Collectively, the GCash Operational Resilience Team should understand:
Cross-functional awareness is especially important.
Technology staff need to understand business impact.
Business owners need to understand technology dependencies.
Risk specialists need to understand end-to-end operations.
Senior leaders need to understand the consequences of breaches of Tolerance for Disruption.
The team should collectively produce and maintain a defined set of Operational Resilience deliverables.
These should include:
Together, these demonstrate that Operational Resilience is being actively managed rather than merely documented.
The Operational Resilience organisation should not remain static.
BSP requires the Operational Resilience Framework to be periodically reviewed, refined and updated so that it remains aligned with the institution's risk appetite, Tolerance for Disruption, business model and complexity.
Reviews should also occur when material changes arise in operations or business activities.
GCash should therefore review its Operational Resilience team structure when there are significant changes involving:
Governance should evolve together with the organisation.
Composing the Operational Resilience Team is a foundational step in strengthening Operational Resilience at GCash.
The programme requires more than appointing an Operational Resilience Manager or assigning responsibility to Business Continuity.
Because Critical Operations depend upon interconnected business processes, people, technology, data, third parties, and external financial infrastructure, effective resilience requires coordinated accountability across the enterprise.
BSP Circular No. 1203 reinforces this principle by requiring Operational Resilience to operate through existing governance structures, with the Board primarily responsible for oversight and approval, senior management responsible for leading implementation, the first line responsible for managing resilience within the business, the second line providing risk and compliance oversight, and Internal Audit providing independent third-line assurance.
For GCash, the recommended structure therefore combines Board oversight, executive sponsorship, an Operational Resilience Steering Committee, a central Operational Resilience Programme Lead, accountable Critical Operation Owners and a cross-functional Operational Resilience Working Group, supported by independent second- and third-line challenge.
The purpose of this structure is not to create another organisational silo, but to integrate existing capabilities around the end-to-end delivery of Critical Operations.
When clearly defined responsibilities, escalation paths, decision rights, competencies and reporting mechanisms are established, GCash will be better positioned to identify vulnerabilities, establish Tolerance for Disruption, coordinate scenario testing, respond to major incidents, complete remediation and demonstrate to the Bangko Sentral ng Pilipinas that Operational Resilience is embedded within its governance and risk-management system.
The proposed organisation chart and RACI are recommended implementation structures, not structures explicitly prescribed by BSP. Circular No. 1203 prescribes the governance responsibilities and three-lines-of-defence expectations, while giving the institution flexibility to embed them within its existing governance structure.
Understanding Your Organisation
|
|
|
||||
| C1 | C2 | C3 | C4 | C5 | ||
| C6 | C7 | C8 | C9 | eBook Cover | ||
To learn more about the course and schedule, click the buttons below for the OR-300 Operational Resilience Implementer course and the OR-5000 Operational Resilience Expert Implementer course.
|
If you have any questions, click to contact us. |
||
|
|