Organisational goals provide strategic direction by translating regulatory expectations, business priorities and resilience principles into measurable outcomes that management can govern and monitor.
For GCash, these goals should reflect the characteristics of a highly digital financial services organisation whose Critical Operations depend on technology, telecommunications, customer authentication, financial institutions, merchants, third-party service providers, data integrity, and rapid incident response.
Under ISO 22316, organisational resilience requires leadership, shared purpose, awareness of changing conditions, adaptive capacity, effective relationships, and continual learning.
These principles should be converted into goals that help GCash remain capable of delivering important financial services despite significant disruption.
This chapter also aligns the proposed goals with the requirements of Bangko Sentral ng Pilipinas Circular No. 1203, Series of 2024 – Guidelines on Operational Resilience.
BSP requires supervised financial institutions to establish an Operational Resilience Framework that is integrated with governance and risk management; identify Critical Operations; define Tolerance for Disruption; map interconnections and interdependencies; consider Severe but Plausible Scenarios; test resilience capabilities; maintain effective response and recovery arrangements; and improve resilience continuously.
The objective of this chapter is therefore to provide GCash with a clear set of enterprise-level Operational Resilience goals that can be translated into policies, programmes,
Key Risk Indicators, Key Performance Indicators, investment priorities and management actions.
By the end of the chapter, the reader should understand what GCash aims to achieve through Operational Resilience and how these goals support customer protection, regulatory compliance, continuity of financial services, and long-term organisational resilience.
Operational Resilience goals define the outcomes that an organisation intends to achieve before, during and after disruption.
Without clearly established goals, Operational Resilience can become a collection of disconnected activities such as:
Although each of these activities is important, they should contribute to common enterprise outcomes.
For GCash, the central question should be:
What resilience outcomes must the organisation achieve to ensure that its Critical Operations remain available, secure and recoverable during severe disruption?
The organisational goals provide the answer.
The first and most important organisational goal should be:
GCash shall maintain the delivery of identified Critical Operations through significant operational disruption within its approved Tolerance for Disruption.
This is the core outcome expected under BSP Circular No. 1203.
For GCash, Critical Operations may include functions associated with:
The goal should not require that every supporting component remain fully available at all times.
Instead, it requires that the overall Critical Operation continue at a level sufficient to avoid intolerable disruption.
This distinction is essential.
Operational Resilience does not mean:
"Nothing may ever fail."
It means:
"Failure must not prevent GCash from delivering its most important operations beyond acceptable disruption limits."
A second major goal should be:
GCash shall minimise the risk of material customer harm resulting from operational disruption.
Customer harm may arise where users experience:
This goal should influence how GCash:
For a digital financial platform, customer impact should be one of the principal measures of resilience.
GCash should establish the goal:
Every identified Critical Operation shall have a Board-approved or appropriately governed Tolerance for Disruption supported by measurable indicators.
Tolerance for Disruption establishes the boundary between manageable disruption and unacceptable consequences.
Possible measures may include:
For example, GCash may determine that a particular payment operation must not remain unavailable for more than a specified period or affect more than a defined number of active customers.
These thresholds should be challenging, measurable and aligned with customer and financial-system consequences.
A major organisational goal should be:
GCash shall maintain current end-to-end maps of the people, processes, technology, information, facilities, third parties, and external organisations that support every Critical Operation.
Dependency mapping enables management to identify:
The goal should extend beyond internal organisational charts.
For example:
Digital Wallet Operation
↓
Application
↓
Authentication
↓
Transaction Processing
↓
Database
↓
Telecommunications
↓
Partner Bank
↓
Settlement
↓
Customer Notification
Each component should be understood in terms of its contribution to the Critical Operation.
Because GCash is highly dependent on digital infrastructure, an important organisational goal should be:
GCash shall maintain technology capabilities that support Critical Operations within established Tolerance for Disruption under severe but plausible conditions.
This may require:
Technology recovery objectives should be aligned with Operational Resilience outcomes.
A system may technically meet its recovery time objective but still fail to support the Critical Operation within its Tolerance for Disruption.
Therefore:
Technology Recovery Objective ≤ Critical Operation Tolerance for Disruption
should be treated as a key planning principle.
GCash should establish the goal:
GCash shall prevent, detect, respond to, recover from and adapt to cyber incidents affecting Critical Operations.
Cybersecurity alone focuses heavily on preventing compromise.
Operational Resilience also asks whether the organisation can continue to function after cyber controls fail.
The goal should therefore integrate:
A severe cyberattack should form part of Operational Resilience testing rather than being managed solely as a cybersecurity issue.
GCash should establish the goal:
Critical third-party providers supporting Critical Operations shall maintain resilience capabilities consistent with GCash's Tolerance for Disruption.
This is particularly important where operations depend upon:
This goal should include:
GCash should avoid assuming that contractual service levels automatically guarantee Operational Resilience.
An organisational goal should be:
GCash shall align its Business Continuity Management programme with Critical Operations and Tolerance for Disruption.
BCM provides a major foundation for Operational Resilience.
The programme should support:
However, BCM should be aligned with the end-to-end Critical Operation.
The planning sequence should increasingly become:
Critical Operation
↓
Tolerance for Disruption
↓
Dependencies
↓
Business Impact Analysis
↓
Continuity Strategy
↓
Recovery Plan
↓
Scenario Testing
This strengthens the connection between BCM and Operational Resilience.
GCash should establish the goal:
GCash shall maintain coordinated incident and crisis management capabilities that enable timely escalation, decision-making, communication, and recovery of Critical Operations.
This requires clear:
The objective should be to reduce the time between:
Detection
→ Assessment
→ Escalation
→ Decision
→ Response
→ Recovery
A technically recoverable incident may still cause severe harm if decision-making is slow or poorly coordinated.
GCash should establish the goal:
Financial and customer data supporting Critical Operations shall remain accurate, complete, secure, and recoverable throughout disruption and restoration.
Data integrity is particularly important for:
Recovery should therefore include:
Restoring system availability without confirming transaction integrity would not represent successful Operational Resilience.
GCash should establish the goal:
All Critical Operations shall be periodically tested against Severe but Plausible Scenarios to determine whether they can remain within Tolerance for Disruption.
Scenario testing should be realistic and challenging.
Possible scenarios may include:
Tests should challenge:
People + Process + Technology + Data + Third Parties + External Infrastructure
rather than isolated systems.
Another important organisational goal should be:
Material vulnerabilities affecting Critical Operations shall be identified, prioritised, assigned and remediated within approved timelines.
Typical vulnerabilities may include:
Every significant vulnerability should have:
Operational Resilience testing should therefore result in measurable improvement.
GCash should establish the goal:
Operational Resilience shall be governed through clear Board oversight, senior management accountability and defined ownership of Critical Operations.
Governance should include:
This goal supports BSP's requirement that Operational Resilience be integrated with existing governance rather than managed as a separate programme.
ISO 22316 places importance on culture, leadership and shared organisational purpose.
GCash should therefore establish the goal:
Operational Resilience responsibilities and behaviours shall be embedded across the organisation.
A resilience culture means that employees understand:
This requires:
Operational Resilience should become part of normal operations rather than an annual exercise.
GCash should establish the goal:
Customers, regulators, employees, partners and other relevant stakeholders shall receive timely, accurate and coordinated information during significant disruption.
Customer communication should address:
Internal communication should ensure that:
Communication quality can significantly affect the overall consequence of an incident.
A further goal should be:
GCash shall meet all applicable BSP Operational Resilience notification, reporting and evidence requirements during and following significant disruptions.
The organisation should have predefined processes covering:
Regulatory reporting should be incorporated into incident-management procedures rather than treated as an administrative afterthought.
Operational Resilience should be forward-looking.
GCash should establish the goal:
GCash shall continuously assess emerging threats and changes that may affect the resilience of Critical Operations.
These may include:
The results should feed into:
GCash should establish the goal:
Operational Resilience shall be continuously improved using lessons from incidents, exercises, near misses, audits, regulatory reviews and organisational change.
Sources of learning should include:
Each lesson should be evaluated and translated into action where appropriate.
The improvement cycle should be:
Experience
↓
Lesson Identified
↓
Root Cause
↓
Remediation
↓
Validation
↓
Closure
↓
Framework Improvement
This aligns directly with the adaptive principles of ISO 22316.
The recommended enterprise goals can be summarised as follows:
|
No. |
Organisational Goal |
Desired Outcome |
|
1 |
Maintain Critical Operations |
Critical Operations remain within Tolerance for Disruption |
|
2 |
Protect Customers |
Minimise material customer harm |
|
3 |
Establish Tolerance for Disruption |
Clear measurable resilience boundaries |
|
4 |
Map Dependencies |
Complete end-to-end operational visibility |
|
5 |
Strengthen Technology Resilience |
Technology supports Critical Operations under stress |
|
6 |
Strengthen Cyber Resilience |
Cyber incidents do not create intolerable disruption |
|
7 |
Manage Third Parties |
Critical suppliers meet resilience expectations |
|
8 |
Integrate BCM |
BCM supports end-to-end resilience outcomes |
|
9 |
Strengthen Incident Management |
Rapid escalation and coordinated response |
|
10 |
Protect Data Integrity |
Transactions and balances remain accurate |
|
11 |
Perform Scenario Testing |
Resilience capabilities are validated |
|
12 |
Remediate Vulnerabilities |
Material resilience weaknesses are addressed |
|
13 |
Strengthen Governance |
Clear accountability and oversight |
|
14 |
Build Resilience Culture |
Employees understand and support resilience |
|
15 |
Communicate Effectively |
Stakeholders receive timely information |
|
16 |
Meet Regulatory Requirements |
BSP reporting obligations are achieved |
|
17 |
Monitor Emerging Threats |
Resilience remains forward-looking |
|
18 |
Continuously Improve |
Lessons translate into measurable improvement |
Organisational goals should be supported by measurable objectives.
Examples include:
|
Goal |
Example Measure |
|
Maintain Critical Operations |
Percentage of Critical Operations tested within Tolerance for Disruption |
|
Protect Customers |
Maximum customers affected during tested scenarios |
|
Dependency Mapping |
Percentage of Critical Operations with current dependency maps |
|
Technology Resilience |
Percentage of critical systems meeting resilience requirements |
|
Third-Party Resilience |
Percentage of critical providers independently assessed |
|
Scenario Testing |
Percentage of annual testing programme completed |
|
Vulnerability Management |
Percentage of high-risk findings remediated on time |
|
Training |
Percentage of designated resilience personnel trained |
|
Incident Response |
Time from detection to escalation |
|
Recovery |
Time from disruption to restoration |
|
Data Integrity |
Percentage of recovery tests completing successful reconciliation |
|
Governance |
Percentage of required Board resilience reviews completed |
This makes Operational Resilience measurable and governable.
The proposed organisational goals directly support major elements of BSP's Operational Resilience framework.
|
BSP Requirement |
Corresponding GCash Organisational Goal |
|
Governance |
Strengthen governance and accountability |
|
Critical Operations |
Maintain delivery of Critical Operations |
|
Tolerance for Disruption |
Establish measurable tolerance |
|
Mapping |
Understand end-to-end dependencies |
|
Severe but Plausible Scenarios |
Perform scenario-based resilience testing |
|
Operational Risk |
Identify and remediate vulnerabilities |
|
ICT and Cyber Risk |
Strengthen technology and cyber resilience |
|
Third-Party Risk |
Manage critical provider resilience |
|
BCM |
Integrate BCM with Operational Resilience |
|
Response and Recovery |
Strengthen incident and crisis response |
|
Regulatory Reporting |
Meet BSP reporting requirements |
|
Continuous Improvement |
Learn and improve continuously |
This demonstrates that Operational Resilience goals should not sit separately from regulation.
They should translate regulatory expectations into organisational outcomes.
The proposed goals also support the broader principles of ISO 22316.
ISO 22316 emphasises characteristics such as:
For GCash, these principles can be expressed operationally as:
Understand what is critical
↓
Understand what it depends upon
↓
Prepare for severe disruption
↓
Respond effectively
↓
Maintain service
↓
Recover
↓
Learn
↓
Adapt
This provides the connection between organisational resilience and financial-sector Operational Resilience.
GCash could consolidate the organisational goals into an overarching enterprise statement such as:
GCash seeks to maintain the safe and reliable delivery of its Critical Operations through significant operational disruption by protecting customers, maintaining Critical Operations within approved Tolerance for Disruption, strengthening technology and cyber resilience, managing critical interconnections and third-party dependencies, maintaining effective response and recovery capabilities, and continuously improving resilience through testing, learning and adaptation.
This statement can form the basis for:
Establishing clear organisational goals is essential for transforming Operational Resilience from a collection of risk-management activities into an enterprise capability at GCash.
These goals define the outcomes that management, business owners and supporting functions should collectively achieve: maintaining Critical Operations within Tolerance for Disruption, protecting customers, preserving transaction and data integrity, understanding dependencies, strengthening technology and cyber resilience, managing third parties, integrating BCM, responding effectively to incidents, and continuously identifying and remediating vulnerabilities.
The goals also provide a common direction for governance, investment, scenario testing, training and performance measurement.
For GCash, these organisational goals should be directly aligned with the Operational Resilience expectations set out in Bangko Sentral ng Pilipinas Circular No. 1203 and the broader organisational resilience principles of ISO 22316.
The ultimate measure of success is not the number of continuity plans, recovery tests or risk assessments completed, but whether GCash can continue delivering its most important financial operations during severe disruption without exceeding acceptable levels of customer and financial-system impact.
By converting resilience principles into clear, measurable and governed organisational goals, GCash can create a stronger foundation for Critical Operation identification, Tolerance for Disruption, dependency mapping, Severe but Plausible Scenario development, scenario testing, remediation and continuous resilience improvement.
Understanding Your Organisation
|
|
|
||||
| C1 | C2 | C3 | C4 | C5 | ||
| C6 | C7 | C8 | C9 | eBook Cover | ||
To learn more about the course and schedule, click the buttons below for the OR-300 Operational Resilience Implementer course and the OR-5000 Operational Resilience Expert Implementer course.
|
If you have any questions, click to contact us. |
||
|
|