.

Strengthening Operational Resilience at GCash: An Enterprise Implementation Guide
BB OR [C] 10

[OR] [GCash] [E1] [C7] Establishing Organisational Goals for Operational Resilience

[OR] [GCash] [Full Banner] Strengthening Operational Resilience at GCash

The purpose of this chapter is to define the organisational goals that should guide GCash in developing, implementing and sustaining its Operational Resilience programme.

Organisational goals provide strategic direction by translating regulatory expectations, business priorities and resilience principles into measurable outcomes that management can govern and monitor.

For GCash, these goals should reflect the characteristics of a highly digital financial services organisation whose Critical Operations depend on technology, telecommunications, customer authentication, financial institutions, merchants, third-party service providers, data integrity, and rapid incident response.

Under ISO 22316, organisational resilience requires leadership, shared purpose, awareness of changing conditions, adaptive capacity, effective relationships, and continual learning. These principles should be converted into goals that help GCash remain capable of delivering important financial services despite significant disruption.

This chapter also aligns the proposed goals with the requirements of Bangko Sentral ng Pilipinas Circular No. 1203, Series of 2024 – Guidelines on Operational Resilience.

New call-to-action

Moh Heng Goh
Operational Resilience Certified Planner-Specialist-Expert

[OR] [GCash] [Disclaimer] Legal Disclaimers and Usage of eBook Banner

Chapter 7

New call-to-action

Establishing Organisational Goals for Operational Resilience for GCash

Introduction

[OR] [GCash] [E1] [C7] Establishing Organisational GoalsThe purpose of this chapter is to define the organisational goals that should guide GCash in developing, implementing and sustaining its Operational Resilience programme.

Organisational goals provide strategic direction by translating regulatory expectations, business priorities and resilience principles into measurable outcomes that management can govern and monitor.

For GCash, these goals should reflect the characteristics of a highly digital financial services organisation whose Critical Operations depend on technology, telecommunications, customer authentication, financial institutions, merchants, third-party service providers, data integrity, and rapid incident response.

Under ISO 22316, organisational resilience requires leadership, shared purpose, awareness of changing conditions, adaptive capacity, effective relationships, and continual learning.

These principles should be converted into goals that help GCash remain capable of delivering important financial services despite significant disruption.

This chapter also aligns the proposed goals with the requirements of Bangko Sentral ng Pilipinas Circular No. 1203, Series of 2024 – Guidelines on Operational Resilience.

BSP requires supervised financial institutions to establish an Operational Resilience Framework that is integrated with governance and risk management; identify Critical Operations; define Tolerance for Disruption; map interconnections and interdependencies; consider Severe but Plausible Scenarios; test resilience capabilities; maintain effective response and recovery arrangements; and improve resilience continuously.

The objective of this chapter is therefore to provide GCash with a clear set of enterprise-level Operational Resilience goals that can be translated into policies, programmes,

Key Risk Indicators, Key Performance Indicators, investment priorities and management actions.

By the end of the chapter, the reader should understand what GCash aims to achieve through Operational Resilience and how these goals support customer protection, regulatory compliance, continuity of financial services, and long-term organisational resilience.

 

Why Organisational Goals Matter

Operational Resilience goals define the outcomes that an organisation intends to achieve before, during and after disruption.

Without clearly established goals, Operational Resilience can become a collection of disconnected activities such as:

  • Business Continuity planning;
  • disaster recovery testing;
  • cyber exercises;
  • vendor reviews;
  • incident management;
  • risk assessments; and
  • regulatory reporting.

Although each of these activities is important, they should contribute to common enterprise outcomes.

For GCash, the central question should be:

What resilience outcomes must the organisation achieve to ensure that its Critical Operations remain available, secure and recoverable during severe disruption?

The organisational goals provide the answer.

 

Goal 1 – Maintain Delivery of Critical Operations Through Disruption

The first and most important organisational goal should be:

GCash shall maintain the delivery of identified Critical Operations through significant operational disruption within its approved Tolerance for Disruption.

This is the core outcome expected under BSP Circular No. 1203.

For GCash, Critical Operations may include functions associated with:

  • Digital Wallet Operations;
  • Payment Transaction Processing;
  • Funds Transfer;
  • Wallet Funding;
  • Merchant Payments;
  • Transaction Authorisation;
  • Customer Account Access;
  • Financial Reconciliation; and
  • Service Recovery.

The goal should not require that every supporting component remain fully available at all times.

Instead, it requires that the overall Critical Operation continue at a level sufficient to avoid intolerable disruption.

This distinction is essential.

Operational Resilience does not mean:

"Nothing may ever fail."

It means:

"Failure must not prevent GCash from delivering its most important operations beyond acceptable disruption limits."

 

Goal 2 – Protect Customers from Material Harm

A second major goal should be:

GCash shall minimise the risk of material customer harm resulting from operational disruption.

Customer harm may arise where users experience:

  • inability to access funds;
  • failed payments;
  • delayed transfers;
  • duplicate transactions;
  • incorrect balances;
  • unavailable merchant payments;
  • inability to pay essential bills;
  • loss of transaction information; or
  • exposure to fraud during a disruption.

This goal should influence how GCash:

  • identifies Critical Operations;
  • defines Tolerance for Disruption;
  • prioritises recovery;
  • communicates during incidents;
  • manages transaction integrity; and
  • designs alternate service arrangements.

For a digital financial platform, customer impact should be one of the principal measures of resilience.

 

Goal 3 – Establish Clear Tolerance for Disruption

GCash should establish the goal:

Every identified Critical Operation shall have a Board-approved or appropriately governed Tolerance for Disruption supported by measurable indicators.

Tolerance for Disruption establishes the boundary between manageable disruption and unacceptable consequences.

Possible measures may include:

  • maximum duration of service interruption;
  • maximum number of affected customers;
  • maximum transaction volume affected;
  • maximum transaction value affected;
  • maximum backlog;
  • maximum service degradation;
  • maximum data-loss threshold; and
  • customer-impact thresholds.

For example, GCash may determine that a particular payment operation must not remain unavailable for more than a specified period or affect more than a defined number of active customers.

These thresholds should be challenging, measurable and aligned with customer and financial-system consequences.

 

Goal 4 – Understand End-to-End Dependencies

A major organisational goal should be:

GCash shall maintain current end-to-end maps of the people, processes, technology, information, facilities, third parties, and external organisations that support every Critical Operation.

Dependency mapping enables management to identify:

  • single points of failure;
  • concentration risks;
  • critical vendors;
  • technology bottlenecks;
  • key-person dependencies;
  • external financial connections;
  • telecommunications dependencies; and
  • public-infrastructure dependencies.

The goal should extend beyond internal organisational charts.

For example:

Digital Wallet Operation

Application

Authentication

Transaction Processing

Database

Telecommunications

Partner Bank

Settlement

Customer Notification

 

Each component should be understood in terms of its contribution to the Critical Operation.

 

Goal 5 – Strengthen Technology Resilience

Because GCash is highly dependent on digital infrastructure, an important organisational goal should be:

GCash shall maintain technology capabilities that support Critical Operations within established Tolerance for Disruption under severe but plausible conditions.

This may require:

  • resilient architecture;
  • infrastructure redundancy;
  • automated failover;
  • geographic separation;
  • backup and restoration;
  • capacity management;
  • network resilience;
  • monitoring;
  • database resilience;
  • application recovery; and
  • disaster recovery.

Technology recovery objectives should be aligned with Operational Resilience outcomes.

A system may technically meet its recovery time objective but still fail to support the Critical Operation within its Tolerance for Disruption.

Therefore:

Technology Recovery Objective ≤ Critical Operation Tolerance for Disruption

should be treated as a key planning principle.

 

Goal 6 – Strengthen Cyber Resilience

GCash should establish the goal:

GCash shall prevent, detect, respond to, recover from and adapt to cyber incidents affecting Critical Operations.

Cybersecurity alone focuses heavily on preventing compromise.

Operational Resilience also asks whether the organisation can continue to function after cyber controls fail.

The goal should therefore integrate:

  • threat intelligence;
  • protective controls;
  • security monitoring;
  • incident response;
  • ransomware preparedness;
  • cyber recovery;
  • data-integrity restoration;
  • identity and authentication resilience;
  • cyber scenario testing; and
  • communication during cyber incidents.

A severe cyberattack should form part of Operational Resilience testing rather than being managed solely as a cybersecurity issue.

 

Goal 7 – Manage Third-Party Resilience

GCash should establish the goal:

Critical third-party providers supporting Critical Operations shall maintain resilience capabilities consistent with GCash's Tolerance for Disruption.

This is particularly important where operations depend upon:

  • cloud providers;
  • telecommunications companies;
  • software providers;
  • payment processors;
  • banks;
  • identity-verification providers;
  • messaging services;
  • cybersecurity providers; and
  • financial-service partners.

This goal should include:

  • identification of critical providers;
  • contractual resilience requirements;
  • service-level requirements;
  • recovery capability assessment;
  • provider scenario participation;
  • concentration-risk assessment;
  • contingency arrangements;
  • substitute providers; and
  • exit strategies.

GCash should avoid assuming that contractual service levels automatically guarantee Operational Resilience.

 

Goal 8 – Integrate BCM with Operational Resilience

An organisational goal should be:

GCash shall align its Business Continuity Management programme with Critical Operations and Tolerance for Disruption.

BCM provides a major foundation for Operational Resilience.

The programme should support:

  • Business Impact Analysis;
  • continuity strategies;
  • alternate arrangements;
  • recovery procedures;
  • crisis management;
  • exercises;
  • communications;
  • workforce resilience; and
  • lessons identified.

However, BCM should be aligned with the end-to-end Critical Operation.

The planning sequence should increasingly become:

 

Critical Operation

Tolerance for Disruption

Dependencies

Business Impact Analysis

Continuity Strategy

Recovery Plan

Scenario Testing

 

This strengthens the connection between BCM and Operational Resilience.

 

Goal 9 – Strengthen Crisis and Incident Response

GCash should establish the goal:

GCash shall maintain coordinated incident and crisis management capabilities that enable timely escalation, decision-making, communication, and recovery of Critical Operations.

This requires clear:

  • incident classifications;
  • escalation thresholds;
  • decision authority;
  • succession arrangements;
  • Crisis Management Team roles;
  • Critical Operation owners;
  • technology response teams;
  • customer communication processes;
  • regulatory communication processes; and
  • recovery priorities.

The objective should be to reduce the time between:

Detection

Assessment

Escalation

Decision

Response

Recovery

A technically recoverable incident may still cause severe harm if decision-making is slow or poorly coordinated.

 

Goal 10 – Maintain Transaction and Data Integrity

GCash should establish the goal:

Financial and customer data supporting Critical Operations shall remain accurate, complete, secure, and recoverable throughout disruption and restoration.

Data integrity is particularly important for:

  • wallet balances;
  • payment transactions;
  • transfers;
  • customer records;
  • merchant transactions;
  • reconciliation;
  • financial reporting; and
  • regulatory reporting.

Recovery should therefore include:

  • transaction validation;
  • reconciliation;
  • duplicate detection;
  • data-integrity verification;
  • balance confirmation;
  • exception management; and
  • audit trails.

Restoring system availability without confirming transaction integrity would not represent successful Operational Resilience.

 

Goal 11 – Test Against Severe but Plausible Scenarios

GCash should establish the goal:

All Critical Operations shall be periodically tested against Severe but Plausible Scenarios to determine whether they can remain within Tolerance for Disruption.

Scenario testing should be realistic and challenging.

Possible scenarios may include:

  • prolonged application outage;
  • major ransomware incident;
  • telecommunications failure;
  • critical cloud-provider outage;
  • payment-network disruption;
  • data corruption;
  • simultaneous production and recovery failure;
  • loss of key personnel;
  • significant natural disaster; and
  • cascading failure across multiple providers.

Tests should challenge:

People + Process + Technology + Data + Third Parties + External Infrastructure

rather than isolated systems.

 

Goal 12 – Identify and Remediate Resilience Vulnerabilities

Another important organisational goal should be:

Material vulnerabilities affecting Critical Operations shall be identified, prioritised, assigned and remediated within approved timelines.

Typical vulnerabilities may include:

  • single points of failure;
  • unsupported systems;
  • inadequate capacity;
  • untested recovery procedures;
  • dependency on one provider;
  • lack of alternative communications;
  • excessive recovery times;
  • key-person dependency;
  • inadequate cyber recovery;
  • weak data restoration; and
  • unclear escalation authority.

Every significant vulnerability should have:

  • risk rating;
  • accountable owner;
  • remediation action;
  • target completion date;
  • funding decision;
  • status; and
  • evidence of closure.

Operational Resilience testing should therefore result in measurable improvement.

 

Goal 13 – Maintain Effective Governance and Accountability

GCash should establish the goal:

Operational Resilience shall be governed through clear Board oversight, senior management accountability and defined ownership of Critical Operations.

Governance should include:

  • Board or Board Risk Committee oversight;
  • Executive Management sponsorship;
  • Operational Resilience Steering Committee;
  • Operational Resilience Programme Lead;
  • Critical Operation Owners;
  • first-line responsibilities;
  • second-line oversight; and
  • third-line independent assurance.

This goal supports BSP's requirement that Operational Resilience be integrated with existing governance rather than managed as a separate programme.

 

Goal 14 – Establish a Strong Resilience Culture

ISO 22316 places importance on culture, leadership and shared organisational purpose.

GCash should therefore establish the goal:

Operational Resilience responsibilities and behaviours shall be embedded across the organisation.

A resilience culture means that employees understand:

  • the Critical Operations they support;
  • their role during disruption;
  • escalation requirements;
  • continuity arrangements;
  • cyber responsibilities;
  • customer-impact consequences; and
  • the importance of reporting weaknesses.

This requires:

  • awareness programmes;
  • training;
  • role-specific exercises;
  • leadership communication;
  • lessons-sharing;
  • resilience metrics; and
  • recognition of resilience responsibilities.

Operational Resilience should become part of normal operations rather than an annual exercise.

 

Goal 15 – Strengthen Customer and Stakeholder Communication

GCash should establish the goal:

Customers, regulators, employees, partners and other relevant stakeholders shall receive timely, accurate and coordinated information during significant disruption.

Customer communication should address:

  • affected services;
  • transaction status;
  • alternative arrangements;
  • expected restoration;
  • customer precautions;
  • fraud warnings; and
  • service restoration.

Internal communication should ensure that:

  • management receives reliable incident information;
  • recovery teams understand priorities;
  • customer service receives approved messages; and
  • decision-makers receive timely updates.

Communication quality can significantly affect the overall consequence of an incident.

 

Goal 16 – Comply with Regulatory Reporting Requirements

A further goal should be:

GCash shall meet all applicable BSP Operational Resilience notification, reporting and evidence requirements during and following significant disruptions.

The organisation should have predefined processes covering:

  • event classification;
  • regulatory-reporting thresholds;
  • escalation to Compliance;
  • management approval;
  • preparation of notifications;
  • submission to BSP;
  • follow-up reporting; and
  • retention of evidence.

Regulatory reporting should be incorporated into incident-management procedures rather than treated as an administrative afterthought.

 

Goal 17 – Continuously Monitor Emerging Threats

Operational Resilience should be forward-looking.

GCash should establish the goal:

GCash shall continuously assess emerging threats and changes that may affect the resilience of Critical Operations.

These may include:

  • evolving cyber threats;
  • new technology dependencies;
  • cloud concentration;
  • regulatory changes;
  • geopolitical events;
  • climate risks;
  • telecommunications vulnerabilities;
  • new fraud patterns;
  • supplier changes;
  • artificial-intelligence risks;
  • new products; and
  • significant organisational changes.

The results should feed into:

Risk Assessment
Dependency Mapping
Scenario Catalogue
Testing Programme
Resilience Investment

 

Goal 18 – Support Continuous Improvement

GCash should establish the goal:

Operational Resilience shall be continuously improved using lessons from incidents, exercises, near misses, audits, regulatory reviews and organisational change.

Sources of learning should include:

  • actual disruptions;
  • scenario tests;
  • disaster recovery tests;
  • cyber exercises;
  • supplier failures;
  • near misses;
  • internal audit findings;
  • external assurance;
  • regulatory feedback; and
  • customer complaints.

Each lesson should be evaluated and translated into action where appropriate.

The improvement cycle should be:

Experience

Lesson Identified

Root Cause

Remediation

Validation

Closure

Framework Improvement

This aligns directly with the adaptive principles of ISO 22316.

 

Proposed Organisational Goals for GCash Operational Resilience

The recommended enterprise goals can be summarised as follows:

 

No.

Organisational Goal

Desired Outcome

1

Maintain Critical Operations

Critical Operations remain within Tolerance for Disruption

2

Protect Customers

Minimise material customer harm

3

Establish Tolerance for Disruption

Clear measurable resilience boundaries

4

Map Dependencies

Complete end-to-end operational visibility

5

Strengthen Technology Resilience

Technology supports Critical Operations under stress

6

Strengthen Cyber Resilience

Cyber incidents do not create intolerable disruption

7

Manage Third Parties

Critical suppliers meet resilience expectations

8

Integrate BCM

BCM supports end-to-end resilience outcomes

9

Strengthen Incident Management

Rapid escalation and coordinated response

10

Protect Data Integrity

Transactions and balances remain accurate

11

Perform Scenario Testing

Resilience capabilities are validated

12

Remediate Vulnerabilities

Material resilience weaknesses are addressed

13

Strengthen Governance

Clear accountability and oversight

14

Build Resilience Culture

Employees understand and support resilience

15

Communicate Effectively

Stakeholders receive timely information

16

Meet Regulatory Requirements

BSP reporting obligations are achieved

17

Monitor Emerging Threats

Resilience remains forward-looking

18

Continuously Improve

Lessons translate into measurable improvement

 

Translating Goals into Measurable Objectives

Organisational goals should be supported by measurable objectives.

Examples include:

 

Goal

Example Measure

Maintain Critical Operations

Percentage of Critical Operations tested within Tolerance for Disruption

Protect Customers

Maximum customers affected during tested scenarios

Dependency Mapping

Percentage of Critical Operations with current dependency maps

Technology Resilience

Percentage of critical systems meeting resilience requirements

Third-Party Resilience

Percentage of critical providers independently assessed

Scenario Testing

Percentage of annual testing programme completed

Vulnerability Management

Percentage of high-risk findings remediated on time

Training

Percentage of designated resilience personnel trained

Incident Response

Time from detection to escalation

Recovery

Time from disruption to restoration

Data Integrity

Percentage of recovery tests completing successful reconciliation

Governance

Percentage of required Board resilience reviews completed

This makes Operational Resilience measurable and governable.

 

Aligning Goals with BSP Circular No. 1203

The proposed organisational goals directly support major elements of BSP's Operational Resilience framework.

 

BSP Requirement

Corresponding GCash Organisational Goal

Governance

Strengthen governance and accountability

Critical Operations

Maintain delivery of Critical Operations

Tolerance for Disruption

Establish measurable tolerance

Mapping

Understand end-to-end dependencies

Severe but Plausible Scenarios

Perform scenario-based resilience testing

Operational Risk

Identify and remediate vulnerabilities

ICT and Cyber Risk

Strengthen technology and cyber resilience

Third-Party Risk

Manage critical provider resilience

BCM

Integrate BCM with Operational Resilience

Response and Recovery

Strengthen incident and crisis response

Regulatory Reporting

Meet BSP reporting requirements

Continuous Improvement

Learn and improve continuously

This demonstrates that Operational Resilience goals should not sit separately from regulation.

They should translate regulatory expectations into organisational outcomes.

 

Aligning Goals with ISO 22316

The proposed goals also support the broader principles of ISO 22316.

ISO 22316 emphasises characteristics such as:

  • shared vision and purpose;
  • understanding organisational context;
  • effective leadership;
  • resilience culture;
  • shared information;
  • availability of resources;
  • relationships and networks;
  • continual improvement; and
  • ability to anticipate and manage change.

For GCash, these principles can be expressed operationally as:

Understand what is critical

Understand what it depends upon

Prepare for severe disruption

Respond effectively

Maintain service

Recover

Learn

Adapt

This provides the connection between organisational resilience and financial-sector Operational Resilience.

 

Proposed Enterprise Operational Resilience Goal Statement

GCash could consolidate the organisational goals into an overarching enterprise statement such as:

GCash seeks to maintain the safe and reliable delivery of its Critical Operations through significant operational disruption by protecting customers, maintaining Critical Operations within approved Tolerance for Disruption, strengthening technology and cyber resilience, managing critical interconnections and third-party dependencies, maintaining effective response and recovery capabilities, and continuously improving resilience through testing, learning and adaptation.

This statement can form the basis for:

  • Operational Resilience Policy;
  • management objectives;
  • Board reporting;
  • programme roadmaps;
  • resilience investment;
  • training;
  • business-unit objectives; and
  • regulatory evidence.

 

Banner [Summing] [OR] [E1] [C7] Establishing Organisational Goals for Operational Resilience

Establishing clear organisational goals is essential for transforming Operational Resilience from a collection of risk-management activities into an enterprise capability at GCash.

These goals define the outcomes that management, business owners and supporting functions should collectively achieve: maintaining Critical Operations within Tolerance for Disruption, protecting customers, preserving transaction and data integrity, understanding dependencies, strengthening technology and cyber resilience, managing third parties, integrating BCM, responding effectively to incidents, and continuously identifying and remediating vulnerabilities.

The goals also provide a common direction for governance, investment, scenario testing, training and performance measurement.

For GCash, these organisational goals should be directly aligned with the Operational Resilience expectations set out in Bangko Sentral ng Pilipinas Circular No. 1203 and the broader organisational resilience principles of ISO 22316.

The ultimate measure of success is not the number of continuity plans, recovery tests or risk assessments completed, but whether GCash can continue delivering its most important financial operations during severe disruption without exceeding acceptable levels of customer and financial-system impact.

By converting resilience principles into clear, measurable and governed organisational goals, GCash can create a stronger foundation for Critical Operation identification, Tolerance for Disruption, dependency mapping, Severe but Plausible Scenario development, scenario testing, remediation and continuous resilience improvement.

 

[OR] [GCash] [3/4 Banner] Strengthening Operational Resilience at GCash

Understanding Your Organisation
 
 
C1 C2 C3 C4 C5    
[OR] [GCash] [E1] [C1] Introducing OR Case Study [OR] [GCash] [E1] [C2] Understanding Your Organisation [OR] [GCash] [E1] [C3] Examining Operating Environment [OR] [GCash] [E1] [C4] Composing the OR Team [OR] [GCash] [E1] [C5] Identifying Critical Business Services    
C6 C7 C8 C9 eBook Cover    
[OR] [GCash] [E1] [C6] Analysing Key Characteristics [OR] [GCash] [E1] [C7] Establishing Organisational Goals [OR] [GCash] [E1] [C8] Summary [OR] [GCash] [E1] [C9] Back Cover x eBook Cover [OR] [GCash] [E1] [2D]    
     

 

New call-to-actionGain Competency: For organisations looking to accelerate their journey, BCM Institute’s training and certification programs, including the OR-5000 Operational Resilience Expert Implementer course, provide in-depth insights and practical toolkits for effectively embedding this model.

 

More Information About OR-5000 [OR-5] or OR-300 [OR-3]

To learn more about the course and schedule, click the buttons below for the OR-300 Operational Resilience Implementer course and the OR-5000 Operational Resilience Expert Implementer course.

BL-OR-3 Register Now BL-OR-3_Tell Me More BL-OR-3_View Schedule
BL-OR-5_Register Now BL-OR-5_Tell Me More  [BL-OR] [3-4-5] View Schedule
[BL-OR] [3] FAQ OR-300

If you have any questions, click to contact us.Email to Sales Team [BCM Institute]

FAQ BL-OR-5 OR-5000
OR Implementer Landing Page

New call-to-action

New call-to-action

 

Comments

 

CTA Banner_OR

CTA Banner_ORA

CTA Banner_BCM

CTA Banner_ITDR

CTA Banner_CM