Chapter 7
Establishing Organisational Goals for Operational Resilience for GCash
Introduction
The purpose of this chapter is to define the organisational goals that should guide GCash in developing, implementing and sustaining its Operational Resilience programme.
Organisational goals provide strategic direction by translating regulatory expectations, business priorities and resilience principles into measurable outcomes that management can govern and monitor.
For GCash, these goals should reflect the characteristics of a highly digital financial services organisation whose Critical Operations depend on technology, telecommunications, customer authentication, financial institutions, merchants, third-party service providers, data integrity, and rapid incident response.
Under ISO 22316, organisational resilience requires leadership, shared purpose, awareness of changing conditions, adaptive capacity, effective relationships, and continual learning.
These principles should be converted into goals that help GCash remain capable of delivering important financial services despite significant disruption.
This chapter also aligns the proposed goals with the requirements of Bangko Sentral ng Pilipinas Circular No. 1203, Series of 2024 – Guidelines on Operational Resilience.
BSP requires supervised financial institutions to establish an Operational Resilience Framework that is integrated with governance and risk management; identify Critical Operations; define Tolerance for Disruption; map interconnections and interdependencies; consider Severe but Plausible Scenarios; test resilience capabilities; maintain effective response and recovery arrangements; and improve resilience continuously.
The objective of this chapter is therefore to provide GCash with a clear set of enterprise-level Operational Resilience goals that can be translated into policies, programmes,
Key Risk Indicators, Key Performance Indicators, investment priorities and management actions.
By the end of the chapter, the reader should understand what GCash aims to achieve through Operational Resilience and how these goals support customer protection, regulatory compliance, continuity of financial services, and long-term organisational resilience.
Why Organisational Goals Matter
Operational Resilience goals define the outcomes that an organisation intends to achieve before, during and after disruption.
Without clearly established goals, Operational Resilience can become a collection of disconnected activities such as:
- Business Continuity planning;
- disaster recovery testing;
- cyber exercises;
- vendor reviews;
- incident management;
- risk assessments; and
- regulatory reporting.
Although each of these activities is important, they should contribute to common enterprise outcomes.
For GCash, the central question should be:
What resilience outcomes must the organisation achieve to ensure that its Critical Operations remain available, secure and recoverable during severe disruption?
The organisational goals provide the answer.
Goal 1 – Maintain Delivery of Critical Operations Through Disruption
The first and most important organisational goal should be:
GCash shall maintain the delivery of identified Critical Operations through significant operational disruption within its approved Tolerance for Disruption.
This is the core outcome expected under BSP Circular No. 1203.
For GCash, Critical Operations may include functions associated with:
- Digital Wallet Operations;
- Payment Transaction Processing;
- Funds Transfer;
- Wallet Funding;
- Merchant Payments;
- Transaction Authorisation;
- Customer Account Access;
- Financial Reconciliation; and
- Service Recovery.
The goal should not require that every supporting component remain fully available at all times.
Instead, it requires that the overall Critical Operation continue at a level sufficient to avoid intolerable disruption.
This distinction is essential.
Operational Resilience does not mean:
"Nothing may ever fail."
It means:
"Failure must not prevent GCash from delivering its most important operations beyond acceptable disruption limits."
Goal 2 – Protect Customers from Material Harm
A second major goal should be:
GCash shall minimise the risk of material customer harm resulting from operational disruption.
Customer harm may arise where users experience:
- inability to access funds;
- failed payments;
- delayed transfers;
- duplicate transactions;
- incorrect balances;
- unavailable merchant payments;
- inability to pay essential bills;
- loss of transaction information; or
- exposure to fraud during a disruption.
This goal should influence how GCash:
- identifies Critical Operations;
- defines Tolerance for Disruption;
- prioritises recovery;
- communicates during incidents;
- manages transaction integrity; and
- designs alternate service arrangements.
For a digital financial platform, customer impact should be one of the principal measures of resilience.
Goal 3 – Establish Clear Tolerance for Disruption
GCash should establish the goal:
Every identified Critical Operation shall have a Board-approved or appropriately governed Tolerance for Disruption supported by measurable indicators.
Tolerance for Disruption establishes the boundary between manageable disruption and unacceptable consequences.
Possible measures may include:
- maximum duration of service interruption;
- maximum number of affected customers;
- maximum transaction volume affected;
- maximum transaction value affected;
- maximum backlog;
- maximum service degradation;
- maximum data-loss threshold; and
- customer-impact thresholds.
For example, GCash may determine that a particular payment operation must not remain unavailable for more than a specified period or affect more than a defined number of active customers.
These thresholds should be challenging, measurable and aligned with customer and financial-system consequences.
Goal 4 – Understand End-to-End Dependencies
A major organisational goal should be:
GCash shall maintain current end-to-end maps of the people, processes, technology, information, facilities, third parties, and external organisations that support every Critical Operation.
Dependency mapping enables management to identify:
- single points of failure;
- concentration risks;
- critical vendors;
- technology bottlenecks;
- key-person dependencies;
- external financial connections;
- telecommunications dependencies; and
- public-infrastructure dependencies.
The goal should extend beyond internal organisational charts.
For example:
Digital Wallet Operation
↓
Application
↓
Authentication
↓
Transaction Processing
↓
Database
↓
Telecommunications
↓
Partner Bank
↓
Settlement
↓
Customer Notification
Each component should be understood in terms of its contribution to the Critical Operation.
Goal 5 – Strengthen Technology Resilience
Because GCash is highly dependent on digital infrastructure, an important organisational goal should be:
GCash shall maintain technology capabilities that support Critical Operations within established Tolerance for Disruption under severe but plausible conditions.
This may require:
- resilient architecture;
- infrastructure redundancy;
- automated failover;
- geographic separation;
- backup and restoration;
- capacity management;
- network resilience;
- monitoring;
- database resilience;
- application recovery; and
- disaster recovery.
Technology recovery objectives should be aligned with Operational Resilience outcomes.
A system may technically meet its recovery time objective but still fail to support the Critical Operation within its Tolerance for Disruption.
Therefore:
Technology Recovery Objective ≤ Critical Operation Tolerance for Disruption
should be treated as a key planning principle.
Goal 6 – Strengthen Cyber Resilience
GCash should establish the goal:
GCash shall prevent, detect, respond to, recover from and adapt to cyber incidents affecting Critical Operations.
Cybersecurity alone focuses heavily on preventing compromise.
Operational Resilience also asks whether the organisation can continue to function after cyber controls fail.
The goal should therefore integrate:
- threat intelligence;
- protective controls;
- security monitoring;
- incident response;
- ransomware preparedness;
- cyber recovery;
- data-integrity restoration;
- identity and authentication resilience;
- cyber scenario testing; and
- communication during cyber incidents.
A severe cyberattack should form part of Operational Resilience testing rather than being managed solely as a cybersecurity issue.
Goal 7 – Manage Third-Party Resilience
GCash should establish the goal:
Critical third-party providers supporting Critical Operations shall maintain resilience capabilities consistent with GCash's Tolerance for Disruption.
This is particularly important where operations depend upon:
- cloud providers;
- telecommunications companies;
- software providers;
- payment processors;
- banks;
- identity-verification providers;
- messaging services;
- cybersecurity providers; and
- financial-service partners.
This goal should include:
- identification of critical providers;
- contractual resilience requirements;
- service-level requirements;
- recovery capability assessment;
- provider scenario participation;
- concentration-risk assessment;
- contingency arrangements;
- substitute providers; and
- exit strategies.
GCash should avoid assuming that contractual service levels automatically guarantee Operational Resilience.
Goal 8 – Integrate BCM with Operational Resilience
An organisational goal should be:
GCash shall align its Business Continuity Management programme with Critical Operations and Tolerance for Disruption.
BCM provides a major foundation for Operational Resilience.
The programme should support:
- Business Impact Analysis;
- continuity strategies;
- alternate arrangements;
- recovery procedures;
- crisis management;
- exercises;
- communications;
- workforce resilience; and
- lessons identified.
However, BCM should be aligned with the end-to-end Critical Operation.
The planning sequence should increasingly become:
Critical Operation
↓
Tolerance for Disruption
↓
Dependencies
↓
Business Impact Analysis
↓
Continuity Strategy
↓
Recovery Plan
↓
Scenario Testing
This strengthens the connection between BCM and Operational Resilience.
Goal 9 – Strengthen Crisis and Incident Response
GCash should establish the goal:
GCash shall maintain coordinated incident and crisis management capabilities that enable timely escalation, decision-making, communication, and recovery of Critical Operations.
This requires clear:
- incident classifications;
- escalation thresholds;
- decision authority;
- succession arrangements;
- Crisis Management Team roles;
- Critical Operation owners;
- technology response teams;
- customer communication processes;
- regulatory communication processes; and
- recovery priorities.
The objective should be to reduce the time between:
Detection
→ Assessment
→ Escalation
→ Decision
→ Response
→ Recovery
A technically recoverable incident may still cause severe harm if decision-making is slow or poorly coordinated.
Goal 10 – Maintain Transaction and Data Integrity
GCash should establish the goal:
Financial and customer data supporting Critical Operations shall remain accurate, complete, secure, and recoverable throughout disruption and restoration.
Data integrity is particularly important for:
- wallet balances;
- payment transactions;
- transfers;
- customer records;
- merchant transactions;
- reconciliation;
- financial reporting; and
- regulatory reporting.
Recovery should therefore include:
- transaction validation;
- reconciliation;
- duplicate detection;
- data-integrity verification;
- balance confirmation;
- exception management; and
- audit trails.
Restoring system availability without confirming transaction integrity would not represent successful Operational Resilience.
Goal 11 – Test Against Severe but Plausible Scenarios
GCash should establish the goal:
All Critical Operations shall be periodically tested against Severe but Plausible Scenarios to determine whether they can remain within Tolerance for Disruption.
Scenario testing should be realistic and challenging.
Possible scenarios may include:
- prolonged application outage;
- major ransomware incident;
- telecommunications failure;
- critical cloud-provider outage;
- payment-network disruption;
- data corruption;
- simultaneous production and recovery failure;
- loss of key personnel;
- significant natural disaster; and
- cascading failure across multiple providers.
Tests should challenge:
People + Process + Technology + Data + Third Parties + External Infrastructure
rather than isolated systems.
Goal 12 – Identify and Remediate Resilience Vulnerabilities
Another important organisational goal should be:
Material vulnerabilities affecting Critical Operations shall be identified, prioritised, assigned and remediated within approved timelines.
Typical vulnerabilities may include:
- single points of failure;
- unsupported systems;
- inadequate capacity;
- untested recovery procedures;
- dependency on one provider;
- lack of alternative communications;
- excessive recovery times;
- key-person dependency;
- inadequate cyber recovery;
- weak data restoration; and
- unclear escalation authority.
Every significant vulnerability should have:
- risk rating;
- accountable owner;
- remediation action;
- target completion date;
- funding decision;
- status; and
- evidence of closure.
Operational Resilience testing should therefore result in measurable improvement.
Goal 13 – Maintain Effective Governance and Accountability
GCash should establish the goal:
Operational Resilience shall be governed through clear Board oversight, senior management accountability and defined ownership of Critical Operations.
Governance should include:
- Board or Board Risk Committee oversight;
- Executive Management sponsorship;
- Operational Resilience Steering Committee;
- Operational Resilience Programme Lead;
- Critical Operation Owners;
- first-line responsibilities;
- second-line oversight; and
- third-line independent assurance.
This goal supports BSP's requirement that Operational Resilience be integrated with existing governance rather than managed as a separate programme.
Goal 14 – Establish a Strong Resilience Culture
ISO 22316 places importance on culture, leadership and shared organisational purpose.
GCash should therefore establish the goal:
Operational Resilience responsibilities and behaviours shall be embedded across the organisation.
A resilience culture means that employees understand:
- the Critical Operations they support;
- their role during disruption;
- escalation requirements;
- continuity arrangements;
- cyber responsibilities;
- customer-impact consequences; and
- the importance of reporting weaknesses.
This requires:
- awareness programmes;
- training;
- role-specific exercises;
- leadership communication;
- lessons-sharing;
- resilience metrics; and
- recognition of resilience responsibilities.
Operational Resilience should become part of normal operations rather than an annual exercise.
Goal 15 – Strengthen Customer and Stakeholder Communication
GCash should establish the goal:
Customers, regulators, employees, partners and other relevant stakeholders shall receive timely, accurate and coordinated information during significant disruption.
Customer communication should address:
- affected services;
- transaction status;
- alternative arrangements;
- expected restoration;
- customer precautions;
- fraud warnings; and
- service restoration.
Internal communication should ensure that:
- management receives reliable incident information;
- recovery teams understand priorities;
- customer service receives approved messages; and
- decision-makers receive timely updates.
Communication quality can significantly affect the overall consequence of an incident.
Goal 16 – Comply with Regulatory Reporting Requirements
A further goal should be:
GCash shall meet all applicable BSP Operational Resilience notification, reporting and evidence requirements during and following significant disruptions.
The organisation should have predefined processes covering:
- event classification;
- regulatory-reporting thresholds;
- escalation to Compliance;
- management approval;
- preparation of notifications;
- submission to BSP;
- follow-up reporting; and
- retention of evidence.
Regulatory reporting should be incorporated into incident-management procedures rather than treated as an administrative afterthought.
Goal 17 – Continuously Monitor Emerging Threats
Operational Resilience should be forward-looking.
GCash should establish the goal:
GCash shall continuously assess emerging threats and changes that may affect the resilience of Critical Operations.
These may include:
- evolving cyber threats;
- new technology dependencies;
- cloud concentration;
- regulatory changes;
- geopolitical events;
- climate risks;
- telecommunications vulnerabilities;
- new fraud patterns;
- supplier changes;
- artificial-intelligence risks;
- new products; and
- significant organisational changes.
The results should feed into:
Risk Assessment
→ Dependency Mapping
→ Scenario Catalogue
→ Testing Programme
→ Resilience Investment
Goal 18 – Support Continuous Improvement
GCash should establish the goal:
Operational Resilience shall be continuously improved using lessons from incidents, exercises, near misses, audits, regulatory reviews and organisational change.
Sources of learning should include:
- actual disruptions;
- scenario tests;
- disaster recovery tests;
- cyber exercises;
- supplier failures;
- near misses;
- internal audit findings;
- external assurance;
- regulatory feedback; and
- customer complaints.
Each lesson should be evaluated and translated into action where appropriate.
The improvement cycle should be:
Experience
↓
Lesson Identified
↓
Root Cause
↓
Remediation
↓
Validation
↓
Closure
↓
Framework Improvement
This aligns directly with the adaptive principles of ISO 22316.
Proposed Organisational Goals for GCash Operational Resilience
The recommended enterprise goals can be summarised as follows:
|
No. |
Organisational Goal |
Desired Outcome |
|
1 |
Maintain Critical Operations |
Critical Operations remain within Tolerance for Disruption |
|
2 |
Protect Customers |
Minimise material customer harm |
|
3 |
Establish Tolerance for Disruption |
Clear measurable resilience boundaries |
|
4 |
Map Dependencies |
Complete end-to-end operational visibility |
|
5 |
Strengthen Technology Resilience |
Technology supports Critical Operations under stress |
|
6 |
Strengthen Cyber Resilience |
Cyber incidents do not create intolerable disruption |
|
7 |
Manage Third Parties |
Critical suppliers meet resilience expectations |
|
8 |
Integrate BCM |
BCM supports end-to-end resilience outcomes |
|
9 |
Strengthen Incident Management |
Rapid escalation and coordinated response |
|
10 |
Protect Data Integrity |
Transactions and balances remain accurate |
|
11 |
Perform Scenario Testing |
Resilience capabilities are validated |
|
12 |
Remediate Vulnerabilities |
Material resilience weaknesses are addressed |
|
13 |
Strengthen Governance |
Clear accountability and oversight |
|
14 |
Build Resilience Culture |
Employees understand and support resilience |
|
15 |
Communicate Effectively |
Stakeholders receive timely information |
|
16 |
Meet Regulatory Requirements |
BSP reporting obligations are achieved |
|
17 |
Monitor Emerging Threats |
Resilience remains forward-looking |
|
18 |
Continuously Improve |
Lessons translate into measurable improvement |
Translating Goals into Measurable Objectives
Organisational goals should be supported by measurable objectives.
Examples include:
|
Goal |
Example Measure |
|
Maintain Critical Operations |
Percentage of Critical Operations tested within Tolerance for Disruption |
|
Protect Customers |
Maximum customers affected during tested scenarios |
|
Dependency Mapping |
Percentage of Critical Operations with current dependency maps |
|
Technology Resilience |
Percentage of critical systems meeting resilience requirements |
|
Third-Party Resilience |
Percentage of critical providers independently assessed |
|
Scenario Testing |
Percentage of annual testing programme completed |
|
Vulnerability Management |
Percentage of high-risk findings remediated on time |
|
Training |
Percentage of designated resilience personnel trained |
|
Incident Response |
Time from detection to escalation |
|
Recovery |
Time from disruption to restoration |
|
Data Integrity |
Percentage of recovery tests completing successful reconciliation |
|
Governance |
Percentage of required Board resilience reviews completed |
This makes Operational Resilience measurable and governable.
Aligning Goals with BSP Circular No. 1203
The proposed organisational goals directly support major elements of BSP's Operational Resilience framework.
|
BSP Requirement |
Corresponding GCash Organisational Goal |
|
Governance |
Strengthen governance and accountability |
|
Critical Operations |
Maintain delivery of Critical Operations |
|
Tolerance for Disruption |
Establish measurable tolerance |
|
Mapping |
Understand end-to-end dependencies |
|
Severe but Plausible Scenarios |
Perform scenario-based resilience testing |
|
Operational Risk |
Identify and remediate vulnerabilities |
|
ICT and Cyber Risk |
Strengthen technology and cyber resilience |
|
Third-Party Risk |
Manage critical provider resilience |
|
BCM |
Integrate BCM with Operational Resilience |
|
Response and Recovery |
Strengthen incident and crisis response |
|
Regulatory Reporting |
Meet BSP reporting requirements |
|
Continuous Improvement |
Learn and improve continuously |
This demonstrates that Operational Resilience goals should not sit separately from regulation.
They should translate regulatory expectations into organisational outcomes.
Aligning Goals with ISO 22316
The proposed goals also support the broader principles of ISO 22316.
ISO 22316 emphasises characteristics such as:
- shared vision and purpose;
- understanding organisational context;
- effective leadership;
- resilience culture;
- shared information;
- availability of resources;
- relationships and networks;
- continual improvement; and
- ability to anticipate and manage change.
For GCash, these principles can be expressed operationally as:
Understand what is critical
↓
Understand what it depends upon
↓
Prepare for severe disruption
↓
Respond effectively
↓
Maintain service
↓
Recover
↓
Learn
↓
Adapt
This provides the connection between organisational resilience and financial-sector Operational Resilience.
Proposed Enterprise Operational Resilience Goal Statement
GCash could consolidate the organisational goals into an overarching enterprise statement such as:
GCash seeks to maintain the safe and reliable delivery of its Critical Operations through significant operational disruption by protecting customers, maintaining Critical Operations within approved Tolerance for Disruption, strengthening technology and cyber resilience, managing critical interconnections and third-party dependencies, maintaining effective response and recovery capabilities, and continuously improving resilience through testing, learning and adaptation.
This statement can form the basis for:
- Operational Resilience Policy;
- management objectives;
- Board reporting;
- programme roadmaps;
- resilience investment;
- training;
- business-unit objectives; and
- regulatory evidence.
Establishing clear organisational goals is essential for transforming Operational Resilience from a collection of risk-management activities into an enterprise capability at GCash.
These goals define the outcomes that management, business owners and supporting functions should collectively achieve: maintaining Critical Operations within Tolerance for Disruption, protecting customers, preserving transaction and data integrity, understanding dependencies, strengthening technology and cyber resilience, managing third parties, integrating BCM, responding effectively to incidents, and continuously identifying and remediating vulnerabilities.
The goals also provide a common direction for governance, investment, scenario testing, training and performance measurement.
For GCash, these organisational goals should be directly aligned with the Operational Resilience expectations set out in Bangko Sentral ng Pilipinas Circular No. 1203 and the broader organisational resilience principles of ISO 22316.
The ultimate measure of success is not the number of continuity plans, recovery tests or risk assessments completed, but whether GCash can continue delivering its most important financial operations during severe disruption without exceeding acceptable levels of customer and financial-system impact.
By converting resilience principles into clear, measurable and governed organisational goals, GCash can create a stronger foundation for Critical Operation identification, Tolerance for Disruption, dependency mapping, Severe but Plausible Scenario development, scenario testing, remediation and continuous resilience improvement.
Understanding Your Organisation
|
|
|
||||
| C1 | C2 | C3 | C4 | C5 | ||
![]() |
![]() |
![]() |
![]() |
![]() |
||
| C6 | C7 | C8 | C9 | eBook Cover | ||
![]() |
![]() |
![]() |
![]() |
![]() |
||
Gain Competency: For organisations looking to accelerate their journey, BCM Institute’s training and certification programs, including the OR-5000 Operational Resilience Expert Implementer course, provide in-depth insights and practical toolkits for effectively embedding this model.

![BB OR [C] 10 BB OR [C] 10](https://blog.bcm-institute.org/hs-fs/hubfs/OR%20picture/OR%20Pictures%20A/BB%20OR%20Folder%20C/BB%20OR%20%5BC%5D%2010.jpg?width=2000&height=1333&name=BB%20OR%20%5BC%5D%2010.jpg)
![[OR] [GCash] [Full Banner] Strengthening Operational Resilience at GCash](https://no-cache.hubspot.com/cta/default/3893111/3a39ca09-f7ed-4e75-858f-941c41224c31.png)

![[OR] [GCash] [Disclaimer] Legal Disclaimers and Usage of eBook Banner](https://no-cache.hubspot.com/cta/default/3893111/454a0c6c-3084-45f4-b724-65b4ca4eb6d1.png)
![Banner [Summing] [OR] [E1] [C7] Establishing Organisational Goals for Operational Resilience](https://no-cache.hubspot.com/cta/default/3893111/f0efd50b-0d39-45a9-a7aa-252eca58e85a.png)
![[OR] [GCash] [3/4 Banner] Strengthening Operational Resilience at GCash](https://no-cache.hubspot.com/cta/default/3893111/f32c765b-c3ba-4ed6-bd15-6dc928547f19.png)
![[OR] [GCash] [E1] [C1] Introducing OR Case Study](https://no-cache.hubspot.com/cta/default/3893111/49375b92-7717-4d7f-82a3-f5ca7b4c5ca4.png)
![[OR] [GCash] [E1] [C2] Understanding Your Organisation](https://no-cache.hubspot.com/cta/default/3893111/eb990ab7-3dbf-4f68-b9cb-e4116375e810.png)
![[OR] [GCash] [E1] [C3] Examining Operating Environment](https://no-cache.hubspot.com/cta/default/3893111/e60a4256-bfe8-4290-94ed-f179c7ada080.png)
![[OR] [GCash] [E1] [C4] Composing the OR Team](https://no-cache.hubspot.com/cta/default/3893111/b6d68856-f047-4039-b59e-70477d278ac9.png)
![[OR] [GCash] [E1] [C5] Identifying Critical Business Services](https://no-cache.hubspot.com/cta/default/3893111/d6eaf971-de08-4db7-b16d-d8dcd953210b.png)
![[OR] [GCash] [E1] [C6] Analysing Key Characteristics](https://no-cache.hubspot.com/cta/default/3893111/f46b1de5-6d77-4fca-b7a6-c57f0adf20da.png)
![[OR] [GCash] [E1] [C8] Summary](https://no-cache.hubspot.com/cta/default/3893111/5b0ed315-15e9-46c7-82f4-09c1a1d17139.png)
![[OR] [GCash] [E1] [C9] Back Cover](https://no-cache.hubspot.com/cta/default/3893111/015a1be7-2368-4cbd-978a-f15eecfbd6f9.png)
![x eBook Cover [OR] [GCash] [E1] [2D]](https://no-cache.hubspot.com/cta/default/3893111/6be54ccc-e74c-4dc1-9dca-7f943817ad55.png)





![[BL-OR] [3-4-5] View Schedule](https://no-cache.hubspot.com/cta/default/3893111/d0d733a1-16c0-4b68-a26d-adbfd4fc6069.png)
![[BL-OR] [3] FAQ OR-300](https://no-cache.hubspot.com/cta/default/3893111/f20c71b4-f5e8-4aa5-8056-c374ca33a091.png)
![Email to Sales Team [BCM Institute]](https://no-cache.hubspot.com/cta/default/3893111/3c53daeb-2836-4843-b0e0-645baee2ab9e.png)








