It requires a structured, repeatable methodology that enables an organisation to progressively build, implement, and continuously strengthen its resilience capabilities.
For a digital financial platform such as GCash, whose operations support millions of customers and businesses across the Philippines, operational resilience must be embedded into governance, operational processes, technology, risk management, and organisational culture.
The methodology reflects internationally recognised Operational Resilience principles and aligns with the expectations of the Bangko Sentral ng Pilipinas (BSP) under Circular No. 1203 (Series of 2024) – Guidelines on Operational Resilience.
Rather than treating Operational Resilience as a one-time project, the methodology establishes a continuous improvement cycle that enables GCash to anticipate, withstand, respond to, recover from, and adapt to operational disruptions while continuing to perform its Critical Operations.
This chapter introduces the overall Operational Resilience Planning Methodology used throughout this implementation guide.
Before undertaking detailed resilience activities, readers need to understand how the programme is structured, why each phase is important, and how the individual stages build upon one another to create a comprehensive Operational Resilience capability.
By the end of this chapter, readers will be able to:
Understand the three phases of the Operational Resilience Planning Methodology.
Recognise the purpose of each stage within the methodology.
Appreciate how the phases collectively support continual improvement in resilience.
Understand how the methodology aligns with BSP Operational Resilience expectations.
Visualise how the methodology can be applied within GCash's operational environment.
This understanding provides the roadmap for the remainder of the implementation guide.
Phase 1 – Plan
Phase 2 – Implement
Phase 3 – Sustain
Each phase addresses a different aspect of Operational Resilience maturity. Together, they form a continuous lifecycle that enables GCash to improve resilience capabilities while responding to changing business, technology, regulatory, and threat environments.
During this phase, GCash evaluates its current state, identifies opportunities for improvement, defines its resilience strategy, determines acceptable levels of operational risk, and establishes governance arrangements to support programme implementation.
The first activity is to evaluate GCash's existing Operational Resilience capability across governance, operational risk management, technology resilience, business continuity, cyber resilience, crisis management, third-party risk management, and organisational preparedness.
Example – GCash
GCash performs an enterprise-wide maturity assessment to determine whether existing operational risk, business continuity, cyber resilience, and technology resilience capabilities adequately support the continuity of its digital wallet operations and payment ecosystem.
The current maturity assessment is compared against regulatory expectations, recognised good practices, and organisational objectives to identify capability gaps.
Example – GCash
The assessment identifies limited dependency mapping across third-party payment providers and insufficient scenario testing for cloud infrastructure disruptions.
Based on the gap analysis, GCash develops a multi-year Operational Resilience Strategy and implementation roadmap.
The roadmap should define priorities, responsibilities, resource requirements, implementation timelines, and measurable outcomes.
Example – GCash
Management approves a three-year roadmap focused on identifying Critical Operations, mapping dependencies, developing impact tolerance, enhancing cyber resilience, and conducting enterprise-wide scenario testing.
Senior management establishes the level of operational disruption the organisation is prepared to tolerate while remaining within acceptable risk limits.
Risk appetite provides strategic direction for resilience investment decisions and operational priorities.
Example – GCash
The Board confirms that payment processing interruptions affecting nationwide customer transactions that exceed defined tolerance levels are unacceptable and require the highest investment priority in resilience.
Appropriate governance structures ensure accountability, oversight, reporting, and continuous management of Operational Resilience.
Governance should define executive ownership, committee responsibilities, reporting mechanisms, and decision-making authority.
Example – GCash
An Operational Resilience Steering Committee is established with representatives from Operations, Technology, Cybersecurity, Operational Risk, Business Continuity, Compliance, Legal, and Internal Audit.
The Implement phase converts strategic planning into operational capability.
It identifies Critical Operations, analyses supporting dependencies, establishes impact tolerances, validates resilience through testing, and improves resilience using lessons learned.
The organisation identifies those operational activities whose disruption would result in unacceptable customer, regulatory, financial, or systemic harm.
Example – GCash
Critical Operations include Digital Wallet Operations, Digital Payment and Funds Transfer Operations, Customer Identity and Authentication Operations, Fraud Detection Operations, and Digital Platform Operations.
Each Critical Operation is mapped to identify its supporting:
Example – GCash
Digital Payment Operations are mapped to payment gateways, cloud infrastructure, API services, telecommunications providers, banking partners, fraud detection platforms, and customer authentication systems.
GCash establishes the maximum acceptable level of disruption for each Critical Operation before unacceptable harm occurs.
Impact tolerances provide measurable resilience objectives.
Example – GCash
Management establishes recovery objectives for Digital Wallet Operations based on customer impact, transaction volumes, regulatory obligations, and financial stability considerations.
The organisation validates resilience through realistic severe but plausible disruption scenarios.
Testing evaluates whether Critical Operations remain within established impact tolerances.
Example – GCash
Scenario exercises simulate ransomware attacks, nationwide telecommunications outages, cloud service failures, payment gateway disruptions, and simultaneous cyber and operational incidents.
Following testing or actual incidents, lessons are analysed and incorporated into governance, technology, operational processes, recovery strategies, and resilience planning.
Example – GCash
Following a major technology simulation exercise, GCash enhances cloud failover procedures, strengthens third-party monitoring, and updates crisis communication protocols.
Operational Resilience is not static. The Sustain phase ensures resilience capabilities remain effective as business operations, technology, customer expectations, threats, and regulatory requirements evolve.
Operational Resilience becomes embedded within organisational values, behaviours, and decision-making.
Example – GCash
Business leaders incorporate resilience objectives into operational planning, project governance, and performance management.
Internal and external communication supports resilience awareness before, during, and after operational disruptions.
Example – GCash
Communication procedures define stakeholder engagement with customers, regulators, banking partners, merchants, media, and employees during significant operational incidents.
Personnel receive appropriate education, exercises, and awareness programmes to support resilience responsibilities.
Example – GCash
Operations, Technology, Cybersecurity, Customer Support, and Executive Management participate in annual Operational Resilience workshops and scenario exercises.
Business units periodically evaluate the effectiveness of resilience controls and identify opportunities for continuous improvement.
Example – GCash
Operational departments complete annual self-assessments measuring compliance with Operational Resilience standards and programme objectives.
Independent reviews provide assurance that the Operational Resilience Programme remains effective, compliant, and aligned with organisational objectives.
Reviews may be performed by Internal Audit, Risk Assurance, or independent external specialists.
Example – GCash
Internal Audit evaluates governance effectiveness, dependency mapping quality, scenario testing results, and compliance with BSP Operational Resilience expectations.
The three phases form a continuous Operational Resilience lifecycle.
Rather than progressing through the methodology only once, GCash should continually revisit each phase as business models, technologies, customer expectations, regulations, and threat landscapes evolve. This cyclical approach enables the organisation to maintain resilience maturity over the long term.
A structured Operational Resilience Planning Methodology provides GCash with a practical roadmap for developing and maintaining enterprise-wide resilience capabilities.
By progressing through the Plan, Implement, and Sustain phases, the organisation can systematically assess its current capability, establish governance, identify and strengthen Critical Operations, validate resilience through testing, and embed resilience into everyday business practices.
Each stage builds upon the previous one, creating an integrated programme that supports operational continuity, protects customers, and enhances confidence in GCash's ability to operate during severe but plausible disruptions.
The chapters that follow examine each stage of the methodology in greater detail.
Beginning with the Plan phase, readers will learn how to assess current Operational Resilience capability and maturity, identify opportunities for improvement, and establish the strategic foundations necessary for a successful Operational Resilience Programme at GCash.
Blogs marked [x] are under construction
| C1 | C2 [x] | C8 [x] | C14 [x] | |||
| eBook 2: Implementing Operational Resilience for XX | ||||||
| BSP OR Policy | eBook 1 | eBook 2 | eBook 3 | C20 [x] | C21 [x] | |
| |
||||||
| "Plan" Phase of the Operational Resilience Planning Methodology |
||||||
| C2 [x] | C3 [x] | C4 [x] | C5 [x] | C6 [x] | C7 [x] | |
| "Implement" Phase of the Operational Resilience Planning Methodology | ||||||
| C8 [x] | C9 [x] | C10 [x] | C11 [x] | C12 [x] | C13 [x] | |
| "Sustain" Phase of the Operational Resilience Planning Methodology | ||||||
| C14 [x] | C15 [x] | C16 [x] | C17 [x] | C18 [x] | C19 [x] | |
For organisations looking to accelerate their journey, BCM Institute’s training and certification programs, including the OR-5000 Operational Resilience Expert Implementer course, provide in-depth insights and practical toolkits for effectively embedding this model.
Gain Competency: For organisations looking to accelerate their journey, BCM Institute’s training and certification programs, including the OR-5000 Operational Resilience Expert Implementer course, provide in-depth insights and practical toolkits for effectively embedding this model.
To learn more about the course and schedule, click the buttons below for the OR-300 Operational Resilience Implementer course and the OR-5000 Operational Resilience Expert Implementer course.
|
If you have any questions, click to contact us. |
||
|
|