.

Strengthening Operational Resilience at GCash: An Enterprise Implementation Guide
BB OR [B] 11

[OR] [GCash] [E2] [P1] [C2] Five Stages of the "Plan" Phase

[OR] [GCash] [Full Banner] Strengthening Operational Resilience at GCash

Operational Resilience at GCash should be implemented through a structured methodology that enables the organisation to understand its existing resilience capabilities, identify gaps, define improvement priorities, align resilience with enterprise risk appetite, and establish the governance required to sustain the programme.

x eBook Cover [OR] [GCash] [E2] [2D]New call-to-action

The Plan phase of the Operational Resilience Planning Methodology provides the foundation for this work by ensuring that GCash does not proceed directly into implementation activities without first establishing its current position, target state, strategic priorities, acceptable risk boundaries and governance model.

Plan Phase

Moh Heng Goh
Operational Resilience Certified Planner-Specialist-Expert

[OR] [GCash] [Disclaimer] Legal Disclaimers and Usage of eBook Banner

Plan Phase

Introduction to GCash’s “Plan” Phase of the Operational Resilience Planning Methodology

Introduction
New call-to-action

[OR] [GCash] [E2] [P1] [S1-S5] [C2] Five Stages of the Plan PhaseOperational Resilience at GCash should be implemented through a structured methodology that enables the organisation to understand its existing resilience capabilities, identify gaps, define improvement priorities, align resilience with enterprise risk appetite, and establish the governance required to sustain the programme.

For a highly digital financial-services organisation operating in the Philippines, this planning discipline is especially important because resilience depends on the coordinated performance of people, processes, technology, information, telecommunications, third-party providers, financial institutions and external infrastructure.

The Plan phase of the Operational Resilience Planning Methodology provides the foundation for this work by ensuring that GCash does not proceed directly into implementation activities without first establishing its current position, target state, strategic priorities, acceptable risk boundaries and governance model.

 

Purpose of the Chapter

The purpose of this chapter is to introduce the reader to the Plan phase of GCash’s Operational Resilience Planning Methodology and explain how its five stages provide the foundation for a structured and sustainable resilience programme.

Before GCash identifies and tests Critical Operations, establishes Tolerance for Disruption or develops detailed resilience improvements, management should first understand the organisation’s existing capability and maturity, determine where gaps exist, decide how those gaps will be addressed, confirm the level of operational risk it is prepared to accept, and establish the governance required to oversee implementation.

By the end of this chapter, the reader should understand the purpose and sequence of the five stages within the Plan phase and how each stage contributes to GCash’s broader Operational Resilience objectives.

The reader should also be able to recognise how the outputs from one stage provide inputs to the next, creating a logical progression from current-state assessment to governance and implementation readiness.

Together, these stages enable GCash to move from a fragmented collection of resilience activities to an integrated enterprise programme that aligns Operational Resilience with business priorities, customer protection, regulatory expectations, and organisational decision-making.

 

Introduction to GCash’s Operational Resilience Planning Methodology

New call-to-actionA practical Operational Resilience methodology should provide a clear sequence for designing, implementing and sustaining resilience capabilities.

For GCash, the planning methodology can be organised around a broader lifecycle that begins with Plan, followed by implementation and ongoing sustainment activities.

The Plan phase answers five fundamental questions:

  • Where are we now?
  • What is missing?
  • Where do we need to go?
  • How much risk are we prepared to accept?
  • Who is accountable for ensuring we get there?

These questions correspond to the five stages of the Plan phase

The five stages should be treated as connected activities rather than separate exercises.

For example, GCash cannot develop a credible Operational Resilience roadmap unless it first understands its current capabilities and gaps.

Similarly, management cannot effectively prioritise resilience investments without understanding both the identified weaknesses and the organisation’s accepted risk appetite.

 

Phase 1: Plan

The objective of the Plan phase is to establish the strategic, governance and capability foundation required for Operational Resilience.

New call-to-action

It enables GCash to determine:

  • its existing level of resilience capability;
  • areas requiring improvement;
  • target-state resilience objectives;
  • investment priorities;
  • acceptable operational risk boundaries;
  • management accountability;
  • governance arrangements; and
  • implementation priorities.

This phase should therefore be completed before large-scale implementation begins.

The outputs from the Plan phase become important inputs into subsequent activities involving:

  • identification of Critical Operations
  • mapping of interconnections and interdependencies;
  • establishment of Tolerance for Disruption;
  • development of Severe but Plausible Scenarios;
  • scenario testing;
  • remediation;
  • training and awareness; and
  • continuous improvement.

New call-to-actionStage 1: Assess Capability and Maturity

[Plan Phase – Stage 1]

The first stage is to Assess Capability and Maturity.

The purpose of this stage is to determine how effectively GCash currently manages Operational Resilience and the maturity of its existing capabilities across relevant disciplines.

The assessment should examine areas such as:

  • Operational Resilience governance;
  • Operational Risk Management;
  • Business Continuity Management;
  • Crisis Management;
  • ICT resilience;
  • cyber resilience;
  • Third-Party Risk Management;
  • incident management;
  • dependency mapping;
  • Critical Operation identification;
  • Tolerance for Disruption;
  • scenario testing;
  • resilience culture;
  • management reporting; and
  • continuous improvement.

The maturity assessment should not focus solely on the existence of policies or plans.

It should also determine whether those capabilities are:

  • implemented;
  • integrated;
  • tested;
  • understood;
  • governed;
  • measured; and
  • continuously improved.

A useful maturity scale could include:

Initial → Developing → Defined → Managed → Optimised

Example for GCash

GCash may already have mature capabilities in Business Continuity, disaster recovery, cybersecurity, and incident management.

However, an Operational Resilience maturity assessment might identify that these capabilities are primarily managed by individual functions.

For example:

  • Technology may conduct disaster recovery testing;
  • Cybersecurity may conduct cyber simulations;
  • Business Continuity may conduct continuity exercises; and
  • Third-Party Risk may assess critical suppliers.

The maturity assessment may determine that these activities are individually strong but not yet fully integrated around the end-to-end delivery of Critical Operations.

This would indicate that GCash possesses valuable resilience capabilities but requires greater integration.

Key Output

The principal output should be an:

Operational Resilience Capability and Maturity Assessment Report

This should establish the baseline against which subsequent improvements are measured.

New call-to-actionStage 2: Analyse Gap

[Plan Phase – Stage 2]

Once the current capability and maturity level has been assessed, GCash should perform a structured Gap Analysis.

The purpose of this stage is to compare:

Current State

with

Required or Target State

The gap analysis should identify where GCash’s existing capabilities do not fully meet its intended Operational Resilience objectives, internal requirements or applicable regulatory expectations.

Potential gaps may relate to:

  • governance;
  • Critical Operation identification;
  • Tolerance for Disruption;
  • dependency mapping;
  • scenario testing;
  • third-party resilience;
  • cyber recovery;
  • management reporting;
  • resilience metrics;
  • business continuity integration;
  • training;
  • incident escalation; or
  • evidence of resilience capability.

The analysis should classify gaps according to:

  • significance;
  • urgency;
  • regulatory relevance;
  • customer impact;
  • operational impact;
  • implementation complexity; and
  • remediation priority.
Example for GCash

Suppose the Stage 1 maturity assessment determines that GCash has detailed technology dependency maps, but they are organised by application rather than by Critical Operation

The gap may therefore be described as:

Current State:

  • Technology dependencies are documented at system level.

Target State:

  • Dependencies should be mapped end-to-end across people, processes, technology, information, and third parties for each Critical Operation.

Identified Gap:

  • Existing technology mapping does not provide complete visibility into Critical Operations.

Required Improvement:

  • Develop integrated dependency maps linking systems to customer-facing Critical Operations.

Key Output

The key output should be an:

Operational Resilience Gap Register

The register should identify:

  • gap;
  • current state;
  • target state;
  • risk implication;
  • priority;
  • owner; and
  • proposed treatment.

New call-to-actionStage 3: Develop Strategy and Roadmap

[Plan Phase – Stage 3]

Once the gaps are understood, GCash should determine how to address them.

The purpose of the Develop Strategy and Roadmap stage is to translate the findings from the maturity assessment and gap analysis into a structured improvement programme.

The Operational Resilience strategy should define:

  • strategic objectives;
  • target maturity;
  • implementation priorities;
  • required capabilities;
  • investment priorities;
  • programme sequencing;
  • responsibilities;
  • performance measures; and
  • expected outcomes.

The roadmap should convert the strategy into practical activities over defined time horizons.

A possible structure may be:

  • Immediate Priorities – 0 to 6 months

  • Medium-Term Priorities – 6 to 18 months

  • Longer-Term Priorities – 18 to 36 months

The roadmap should prioritise the most significant resilience vulnerabilities rather than attempting to address every gap simultaneously.

Example for GCash

An Operational Resilience roadmap for GCash might prioritise:

0–6 Months

  • establish governance;
  • approve methodology;
  • identify initial Critical Operations;
  • define ownership;
  • establish Tolerance for Disruption methodology.

6–18 Months

  • complete dependency mapping;
  • strengthen third-party resilience assessments;
  • develop Severe but Plausible Scenarios;
  • conduct initial end-to-end scenario testing.

18–36 Months

  • automate resilience monitoring;
  • integrate resilience indicators into management dashboards;
  • mature cross-organisation scenario testing;
  • conduct independent resilience assurance.

This gives management a realistic path from current-state capability to target-state maturity.

Key Output

The principal outputs should include:

Operational Resilience Strategy

and

Operational Resilience Implementation Roadmap

New call-to-actionStage 4: Confirm Risk Appetite

[Plan Phase – Stage 4]

The fourth stage is to Confirm Risk Appetite.

appetite defines the amount and type of risk that GCash is prepared to accept while pursuing its objectives.

Operational Resilience should therefore be aligned with the organisation’s broader Enterprise Risk Management framework.

The purpose of this stage is to determine whether existing risk-appetite statements adequately address Operational Resilience and whether additional measures or thresholds are required.

Relevant areas may include:

  • service availability;
  • technology outages;
  • cyber incidents;
  • customer harm;
  • transaction disruption;
  • third-party failures;
  • data loss;
  • financial loss;
  • regulatory impact; and
  • reputational impact.

Risk appetite provides management with a framework for prioritising resilience investment.

Not every risk can be eliminated.

The organisation must therefore determine:

  • which risks must be reduced;
  • which risks may be tolerated;
  • which risks require escalation; and
  • which risks require immediate treatment.
Risk Appetite and Tolerance for Disruption

Risk appetite and Tolerance for Disruption are related but distinct.

Risk Appetite

defines the level of risk the organisation is willing to accept.

Tolerance for Disruption

defines the maximum level of disruption that can be accepted for a particular Critical Operation.

For example:

Enterprise Risk Appetite

Operational Resilience Risk Appetite

Critical Operation Tolerance for Disruption

This creates a clear hierarchy between enterprise risk governance and operational resilience thresholds.

Example for GCash

GCash may establish an Operational Resilience risk-appetite statement such as:

GCash has a low appetite for operational disruptions that prevent customers from accessing funds, completing essential payment transactions, or maintaining confidence in their account balances.

This statement can then inform more specific Tolerance for Disruption measures for relevant Critical Operations.

Key Output

The outputs should include:

  • approved Operational Resilience risk-appetite statements;
  • resilience risk thresholds;
  • escalation criteria; and
  • linkage between risk appetite and Critical Operation tolerance.

New call-to-actionStage 5: Develop and Embed Governance

[Plan Phase – Stage 5]

The final stage of the Plan phase is to Develop and Embed Governance.

Operational Resilience cannot be successfully implemented without clear accountability.

The purpose of governance is to define:

  • who owns Operational Resilience;
  • who approves the framework;
  • who owns Critical Operations;
  • who challenges resilience assessments;
  • who monitors implementation;
  • who reviews scenario-testing results;
  • who approves remediation;
  • who receives reporting; and
  • who provides independent assurance.

A practical governance structure for GCash may include:

 

Board of Directors / Board Risk Committee

Executive Management

Operational Resilience Steering Committee

Operational Resilience Programme Lead

Critical Operation Owners

Cross-Functional Operational Resilience Working Group

 

Supporting functions may include:

  • Business Operations;
  • Operational Risk;
  • BCM;
  • Crisis Management;
  • Technology;
  • ICT Risk;
  • Cybersecurity;
  • Third-Party Risk;
  • Compliance;
  • Legal;
  • Finance;
  • Customer Operations; and
  • Corporate Communications.

Internal Audit should provide independent assurance.

Example for GCash

GCash may designate senior business executives as Critical Operation Owners for major areas such as Digital Wallet Operations or Payment Transaction Processing.

The Critical Operation Owner would then be accountable for ensuring that:

  • dependencies are identified;
  • Tolerance for Disruption is defined;
  • vulnerabilities are addressed;
  • scenarios are tested; and
  • remediation actions are completed.

The owner would not personally manage every system or third party supporting the operation.

Instead, the role would provide end-to-end accountability.

Key Output

The main outputs should include:

  • Operational Resilience Governance Framework;
  • Committee structure;
  • RACI matrix;
  • Critical Operation ownership register;
  • Escalation arrangements; and
  • Board and management reporting requirements.

 

How the Five Stages Work Together

The five Plan stages form a logical sequence.

Stage 1

Assess Capability and Maturity

Determines where GCash is today.

Stage 2

Analyse Gap

Determines what is missing.

Stage 3

Develop Strategy and Roadmap

Determines how GCash will improve.

Stage 4

Confirm Risk Appetite

Determines how much risk GCash is prepared to accept.

Stage 5

Develop and Embed Governance

Determines who is responsible for ensuring implementation succeeds.

 

Together, these stages establish the management foundation for the remainder of the Operational Resilience lifecycle.

 

Example Plan Phase for GCash

The overall Plan phase may be summarised as follows:

Plan Stage

Core Question

Example Application to GCash

Key Output

Stage 1 – Assess Capability and Maturity

Where are we now?

Assess BCM, cyber, ICT, risk, third-party and governance capabilities

Capability and Maturity Assessment

Stage 2 – Analyse Gap

What is missing?

Identify weaknesses in Critical Operation mapping, tolerance and testing

Gap Register

Stage 3 – Develop Strategy and Roadmap

How will we improve?

Prioritise governance, mapping, testing and technology resilience improvements

Strategy and Roadmap

Stage 4 – Confirm Risk Appetite

How much risk can we accept?

Align customer, service and technology disruption thresholds with enterprise risk appetite

OR Risk Appetite

Stage 5 – Develop and Embed Governance

Who is accountable?

Establish Board oversight, Critical Operation ownership and cross-functional governance

Governance Framework

 

Key Deliverables from the Plan Phase

At completion of the Plan phase, GCash should have a coherent package of Operational Resilience planning outputs.

These should include:

  • Capability and Maturity Assessment;
  • Gap Analysis;
  • Operational Resilience Gap Register;
  • target maturity profile;
  • Operational Resilience Strategy;
  • implementation roadmap;
  • resilience investment priorities;
  • Operational Resilience risk-appetite statement;
  • governance structure;
  • RACI matrix;
  • management reporting arrangements; and
  • Critical Operation ownership framework.

These outputs provide the foundation for the next phase of implementation.

 

Planning Principles for Gcash

Several principles should guide the Plan phase.

Enterprise-wide rather than siloed

Operational Resilience should connect existing disciplines rather than create another isolated programme.

Outcome-oriented rather than document-oriented

The objective is to strengthen the ability to deliver Critical Operations rather than simply produce policies and templates.

Risk-based

Investment should focus on the vulnerabilities that create the greatest customer, operational and regulatory consequences.

Proportionate

The programme should reflect GCash’s scale, digital operating model and complexity.

Customer-focused

Customer harm should remain a central consideration.

Forward-looking

Planning should consider emerging threats, technology change and increasing interdependence.

Evidence-based

Management decisions should be supported by assessments, testing and measurable indicators

Continuously improving

The Plan phase should be revisited as the organisation and its operating environment evolve

 

[Banner] [Summing] [OR] [E2] [C2] Five Stages of the _Plan_ Phase

The Plan phase establishes the strategic and governance foundation for Operational Resilience at GCash.

Rather than beginning with isolated recovery plans or scenario tests, GCash should first determine its existing resilience capability, identify gaps, establish an improvement strategy, confirm its acceptable level of operational risk and embed appropriate governance.

The five stages—Assess Capability and Maturity, Analyse Gap, Develop Strategy and Roadmap, Confirm Risk Appetite, and Develop and Embed Governance—provide a structured progression from understanding the current state to establishing an organisation that is ready to implement Operational Resilience systematically.

For GCash, this planning discipline is especially important because Critical Operations depend upon complex combinations of technology, customer processes, financial institutions, telecommunications, data and third-party services.

A strong Plan phase ensures that these dependencies are addressed within a coordinated enterprise programme rather than through fragmented resilience activities.

Once completed, the Plan phase provides the direction, accountability, priorities and risk boundaries needed for the subsequent implementation of Critical Operation identification, dependency mapping, Tolerance for Disruption, Severe but Plausible Scenario development, scenario testing and continuous resilience improvement.

BL-OR-3-5 Blog Under Construction

Blogs marked [x] are under construction

[OR] [GCash] [3/4 Banner] Strengthening Operational Resilience at GCash

C1 C2 C8 C14      
[OR] [GCash] [E2] [C1] OR Planning Methodology [OR] [GCash] [E2] [P1] [S1-S5] [C2] Five Stages of the Plan Phase [OR] [GCash] [E2] [P1] [S1-S5] [C8] Five Stages of the Implement Phase [OR] [GCash] [E2] [P1] [S1-S5] [C14] Five Stages of the Sustain Phase
"Plan" Phase of the Operational Resilience Planning Methodology
C2 [x] C3 [x] C4 [x] C5 [x] C6 [x] C7 [x]
[OR] [GEN] [P1] [S1-S5] [C2] Five Stages of the _Plan_ Phase [OR] [GEN] [E2] [P1] [S1] [C3] Assessing Capability and Maturity [OR] [GEN] [E2] [P1] [S2] [C4] Analysing Gaps [OR] [GEN] [E2] [P1] [S3] [C5] Developing Strategy and Roadmap [OR] [GEN] [E2] [P1] [S4] [C6] Confirming Risk Appetite [OR] [GEN] [E2] [P1] [S5] [C7] Developing and Embedding Governance
 

New call-to-actionGain Competency: For organisations looking to accelerate their journey, BCM Institute’s training and certification programs, including the OR-5000 Operational Resilience Expert Implementer course, provide in-depth insights and practical toolkits for effectively embedding this model.

 

More Information About OR-5000 [OR-5] or OR-300 [OR-3]

To learn more about the course and schedule, click the buttons below for the OR-300 Operational Resilience Implementer course and the OR-5000 Operational Resilience Expert Implementer course.

BL-OR-3 Register Now BL-OR-3_Tell Me More BL-OR-3_View Schedule
BL-OR-5_Register Now BL-OR-5_Tell Me More  [BL-OR] [3-4-5] View Schedule
[BL-OR] [3] FAQ OR-300

If you have any questions, click to contact us.Email to Sales Team [BCM Institute]

FAQ BL-OR-5 OR-5000
OR Implementer Landing Page

New call-to-action

New call-to-action

 

Comments

 

CTA Banner_OR

CTA Banner_ORA

CTA Banner_BCM

CTA Banner_ITDR

CTA Banner_CM