For a highly digital financial-services organisation operating in the Philippines, this planning discipline is especially important because resilience depends on the coordinated performance of people, processes, technology, information, telecommunications, third-party providers, financial institutions and external infrastructure.
The Plan phase of the Operational Resilience Planning Methodology provides the foundation for this work by ensuring that GCash does not proceed directly into implementation activities without first establishing its current position, target state, strategic priorities, acceptable risk boundaries and governance model.
The purpose of this chapter is to introduce the reader to the Plan phase of GCash’s Operational Resilience Planning Methodology and explain how its five stages provide the foundation for a structured and sustainable resilience programme.
Before GCash identifies and tests Critical Operations, establishes Tolerance for Disruption or develops detailed resilience improvements, management should first understand the organisation’s existing capability and maturity, determine where gaps exist, decide how those gaps will be addressed, confirm the level of operational risk it is prepared to accept, and establish the governance required to oversee implementation.
By the end of this chapter, the reader should understand the purpose and sequence of the five stages within the Plan phase and how each stage contributes to GCash’s broader Operational Resilience objectives.
The reader should also be able to recognise how the outputs from one stage provide inputs to the next, creating a logical progression from current-state assessment to governance and implementation readiness.
Together, these stages enable GCash to move from a fragmented collection of resilience activities to an integrated enterprise programme that aligns Operational Resilience with business priorities, customer protection, regulatory expectations, and organisational decision-making.
For GCash, the planning methodology can be organised around a broader lifecycle that begins with Plan, followed by implementation and ongoing sustainment activities.
The Plan phase answers five fundamental questions:
These questions correspond to the five stages of the Plan phase
The five stages should be treated as connected activities rather than separate exercises.
For example, GCash cannot develop a credible Operational Resilience roadmap unless it first understands its current capabilities and gaps.
Similarly, management cannot effectively prioritise resilience investments without understanding both the identified weaknesses and the organisation’s accepted risk appetite.
The objective of the Plan phase is to establish the strategic, governance and capability foundation required for Operational Resilience.
It enables GCash to determine:
This phase should therefore be completed before large-scale implementation begins.
The outputs from the Plan phase become important inputs into subsequent activities involving:
The first stage is to Assess Capability and Maturity.
The purpose of this stage is to determine how effectively GCash currently manages Operational Resilience and the maturity of its existing capabilities across relevant disciplines.
The assessment should examine areas such as:
The maturity assessment should not focus solely on the existence of policies or plans.
It should also determine whether those capabilities are:
A useful maturity scale could include:
Initial → Developing → Defined → Managed → Optimised
GCash may already have mature capabilities in Business Continuity, disaster recovery, cybersecurity, and incident management.
However, an Operational Resilience maturity assessment might identify that these capabilities are primarily managed by individual functions.
For example:
The maturity assessment may determine that these activities are individually strong but not yet fully integrated around the end-to-end delivery of Critical Operations.
This would indicate that GCash possesses valuable resilience capabilities but requires greater integration.
The principal output should be an:
Operational Resilience Capability and Maturity Assessment Report
This should establish the baseline against which subsequent improvements are measured.
Once the current capability and maturity level has been assessed, GCash should perform a structured Gap Analysis.
The purpose of this stage is to compare:
Current State
with
Required or Target State
The gap analysis should identify where GCash’s existing capabilities do not fully meet its intended Operational Resilience objectives, internal requirements or applicable regulatory expectations.
Potential gaps may relate to:
The analysis should classify gaps according to:
Suppose the Stage 1 maturity assessment determines that GCash has detailed technology dependency maps, but they are organised by application rather than by Critical Operation
The gap may therefore be described as:
Current State:
Technology dependencies are documented at system level.
Target State:
Dependencies should be mapped end-to-end across people, processes, technology, information, and third parties for each Critical Operation.
Identified Gap:
Existing technology mapping does not provide complete visibility into Critical Operations.
Required Improvement:
Develop integrated dependency maps linking systems to customer-facing Critical Operations.
The key output should be an:
Operational Resilience Gap Register
The register should identify:
Once the gaps are understood, GCash should determine how to address them.
The purpose of the Develop Strategy and Roadmap stage is to translate the findings from the maturity assessment and gap analysis into a structured improvement programme.
The Operational Resilience strategy should define:
The roadmap should convert the strategy into practical activities over defined time horizons.
A possible structure may be:
Immediate Priorities – 0 to 6 months
Medium-Term Priorities – 6 to 18 months
Longer-Term Priorities – 18 to 36 months
The roadmap should prioritise the most significant resilience vulnerabilities rather than attempting to address every gap simultaneously.
An Operational Resilience roadmap for GCash might prioritise:
0–6 Months
6–18 Months
18–36 Months
This gives management a realistic path from current-state capability to target-state maturity.
The principal outputs should include:
Operational Resilience Strategy
and
Operational Resilience Implementation Roadmap
The fourth stage is to Confirm Risk Appetite.
appetite defines the amount and type of risk that GCash is prepared to accept while pursuing its objectives.
Operational Resilience should therefore be aligned with the organisation’s broader Enterprise Risk Management framework.
The purpose of this stage is to determine whether existing risk-appetite statements adequately address Operational Resilience and whether additional measures or thresholds are required.
Relevant areas may include:
Risk appetite provides management with a framework for prioritising resilience investment.
Not every risk can be eliminated.
The organisation must therefore determine:
Risk appetite and Tolerance for Disruption are related but distinct.
defines the level of risk the organisation is willing to accept.
defines the maximum level of disruption that can be accepted for a particular Critical Operation.
For example:
Enterprise Risk Appetite
↓
Operational Resilience Risk Appetite
↓
Critical Operation Tolerance for Disruption
This creates a clear hierarchy between enterprise risk governance and operational resilience thresholds.
GCash may establish an Operational Resilience risk-appetite statement such as:
GCash has a low appetite for operational disruptions that prevent customers from accessing funds, completing essential payment transactions, or maintaining confidence in their account balances.
This statement can then inform more specific Tolerance for Disruption measures for relevant Critical Operations.
The outputs should include:
The final stage of the Plan phase is to Develop and Embed Governance.
Operational Resilience cannot be successfully implemented without clear accountability.
The purpose of governance is to define:
A practical governance structure for GCash may include:
Board of Directors / Board Risk Committee
↓
Executive Management
↓
Operational Resilience Steering Committee
↓
Operational Resilience Programme Lead
↓
Critical Operation Owners
↓
Cross-Functional Operational Resilience Working Group
Supporting functions may include:
Internal Audit should provide independent assurance.
GCash may designate senior business executives as Critical Operation Owners for major areas such as Digital Wallet Operations or Payment Transaction Processing.
The Critical Operation Owner would then be accountable for ensuring that:
The owner would not personally manage every system or third party supporting the operation.
Instead, the role would provide end-to-end accountability.
The main outputs should include:
The five Plan stages form a logical sequence.
Stage 1
Assess Capability and Maturity
Determines where GCash is today.
↓
Stage 2
Analyse Gap
Determines what is missing.
↓
Stage 3
Develop Strategy and Roadmap
Determines how GCash will improve.
↓
Stage 4
Confirm Risk Appetite
Determines how much risk GCash is prepared to accept.
↓
Stage 5
Develop and Embed Governance
Determines who is responsible for ensuring implementation succeeds.
Together, these stages establish the management foundation for the remainder of the Operational Resilience lifecycle.
The overall Plan phase may be summarised as follows:
|
Plan Stage |
Core Question |
Example Application to GCash |
Key Output |
|
Stage 1 – Assess Capability and Maturity |
Where are we now? |
Assess BCM, cyber, ICT, risk, third-party and governance capabilities |
Capability and Maturity Assessment |
|
Stage 2 – Analyse Gap |
What is missing? |
Identify weaknesses in Critical Operation mapping, tolerance and testing |
Gap Register |
|
Stage 3 – Develop Strategy and Roadmap |
How will we improve? |
Prioritise governance, mapping, testing and technology resilience improvements |
Strategy and Roadmap |
|
Stage 4 – Confirm Risk Appetite |
How much risk can we accept? |
Align customer, service and technology disruption thresholds with enterprise risk appetite |
OR Risk Appetite |
|
Stage 5 – Develop and Embed Governance |
Who is accountable? |
Establish Board oversight, Critical Operation ownership and cross-functional governance |
Governance Framework |
At completion of the Plan phase, GCash should have a coherent package of Operational Resilience planning outputs.
These should include:
These outputs provide the foundation for the next phase of implementation.
Several principles should guide the Plan phase.
Operational Resilience should connect existing disciplines rather than create another isolated programme.
The objective is to strengthen the ability to deliver Critical Operations rather than simply produce policies and templates.
Investment should focus on the vulnerabilities that create the greatest customer, operational and regulatory consequences.
The programme should reflect GCash’s scale, digital operating model and complexity.
Customer harm should remain a central consideration.
Planning should consider emerging threats, technology change and increasing interdependence.
Management decisions should be supported by assessments, testing and measurable indicators
The Plan phase should be revisited as the organisation and its operating environment evolve
The Plan phase establishes the strategic and governance foundation for Operational Resilience at GCash.
Rather than beginning with isolated recovery plans or scenario tests, GCash should first determine its existing resilience capability, identify gaps, establish an improvement strategy, confirm its acceptable level of operational risk and embed appropriate governance.
The five stages—Assess Capability and Maturity, Analyse Gap, Develop Strategy and Roadmap, Confirm Risk Appetite, and Develop and Embed Governance—provide a structured progression from understanding the current state to establishing an organisation that is ready to implement Operational Resilience systematically.
For GCash, this planning discipline is especially important because Critical Operations depend upon complex combinations of technology, customer processes, financial institutions, telecommunications, data and third-party services.
A strong Plan phase ensures that these dependencies are addressed within a coordinated enterprise programme rather than through fragmented resilience activities.
Once completed, the Plan phase provides the direction, accountability, priorities and risk boundaries needed for the subsequent implementation of Critical Operation identification, dependency mapping, Tolerance for Disruption, Severe but Plausible Scenario development, scenario testing and continuous resilience improvement.
Blogs marked [x] are under construction
| C1 | C2 | C8 | C14 | |||
| "Plan" Phase of the Operational Resilience Planning Methodology | |||||
| C2 [x] | C3 [x] | C4 [x] | C5 [x] | C6 [x] | C7 [x] |
To learn more about the course and schedule, click the buttons below for the OR-300 Operational Resilience Implementer course and the OR-5000 Operational Resilience Expert Implementer course.
|
If you have any questions, click to contact us. |
||
|
|