While the earlier Plan phase establishes governance, maturity, priorities, and risk appetite, the Implement phase applies those foundations to the operations that matter most to customers and the organisation.
For GCash, this means identifying the operations that must remain resilient, understanding the people, processes, technology, information, and third parties that support them, defining how much disruption can be tolerated, testing those operations against Severe but Plausible Scenarios, and using the results to continuously strengthen resilience.
Because GCash operates within a highly digital and interconnected financial services environment, this phase should focus on end-to-end service delivery rather than on isolated systems, departments, or recovery plans.
The purpose of this chapter is to introduce the reader to the Implement phase of GCash’s Operational Resilience Planning Methodology and explain how its five stages convert strategic resilience intent into operational capability.
The Implement phase is where GCash identifies the operations whose disruption could create material customer or organisational consequences, maps the resources and dependencies needed to deliver them, establishes measurable disruption thresholds, validates resilience through scenario testing and converts identified weaknesses into practical improvements.
This phase therefore provides the bridge between planning and demonstrated resilience capability.
By the end of this chapter, the reader should understand the purpose and sequence of the five Implement stages, and how the output from each stage serves as input to the next.
The reader should also recognise how these activities should be applied to GCash’s digital operating environment, where financial transactions depend on applications, telecommunications, cybersecurity, data, financial institutions, merchants and third-party service providers.
Together, the five stages enable GCash to move from understanding what should be resilient to demonstrating whether its Critical Operations can actually remain within acceptable disruption limits under severe operational stress.
The Implement phase answers five practical questions:
These questions correspond to five stages:
For alignment with BSP terminology, GCash should interpret Critical Business Services as the methodology equivalent of Critical Operations, and Impact Tolerance as the maximum tolerable level of disruption for those operations.
This allows the methodology to remain consistent while respecting the terminology used by the Bangko Sentral ng Pilipinas.
The objective of the Implement phase is to establish and validate the resilience of GCash’s most important end-to-end operations.
This phase should produce a practical understanding of:
The Implement phase therefore turns the Operational Resilience programme from a governance framework into an operating capability.
The first stage is to identify Critical Business Services.
For GCash, this means identifying the customer-facing or operational outcomes whose prolonged disruption could result in material harm to customers, the organisation or relevant participants in the financial ecosystem.
Under the methodology, a Critical Business Service should be defined at an outcome level rather than as an individual application, department or process.
For GCash, potential candidates might include:
These examples would require formal assessment before being designated as Critical Operations.
The identification process should consider:
Suppose GCash evaluates Digital Wallet Operations.
The assessment may determine that prolonged unavailability would prevent customers from:
Because these outcomes are central to the customer experience, Digital Wallet Operations may be identified as a Critical Operation.
The primary output should be a:
Critical Business Service / Critical Operation Register
This should include:
Once a Critical Operation has been identified, GCash should determine how to deliver it end-to-end.
The purpose of Map Interconnections and Interdependencies is to identify all important resources and dependencies required to deliver the Critical Operation.
These may include:
The mapping should not stop at organisational boundaries.
For GCash, a simplified Digital Wallet mapping may resemble:
Customer
↓
GCash Mobile Application
↓
Authentication
↓
Wallet Platform
↓
Transaction Engine
↓
Database / Ledger
↓
Bank / Payment Interface
↓
Merchant or Recipient
↓
Settlement and Reconciliation
↓
Customer Notification
The purpose of the mapping is to understand where disruption can enter and how it may propagate through the service.
For Payment Transaction Processing, GCash may identify dependencies such as:
If one of these dependencies has no practical alternative, it may represent a significant vulnerability to resilience.
The key outputs should include:
Once the Critical Operation and its dependencies are understood, GCash should define the maximum level of disruption it can tolerate.
The purpose of Set Impact Tolerance is to establish the boundary beyond which disruption would create unacceptable consequences.
For GCash, useful measures may include:
Impact Tolerance should be established from the perspective of customer and business harm rather than from existing recovery capability alone.
The question should not be:
“How quickly can the system recover?”
It should be:
“How long can this Critical Operation be disrupted before the consequences become unacceptable?”
For Payment Transaction Processing, GCash might determine that the operation should not be unavailable for more than a defined period during peak customer activity.
It may also set complementary measures such as:
These thresholds would then guide:
The principal output should be an:
Impact Tolerance / Tolerance for Disruption Statement
for each Critical Operation.
Once the Critical Operation, dependencies and Impact Tolerance are defined, GCash should validate its resilience.
The purpose of Conduct Scenario Testing is to expose the Critical Operation to Severe but Plausible Scenarios and assess whether it can remain within its Impact Tolerance.
Scenarios should be:
Possible GCash scenarios could include:
Scenario testing should challenge:
People + Process + Technology + Data + Third Parties + External Dependencies
rather than testing one system in isolation.
GCash may test Digital Wallet Operations using a Severe but Plausible Scenario involving:
The test would assess:
The outputs should include:
The final stage of the Implement phase is to Improve Lessons Learnt.
Operational Resilience testing has limited value if identified weaknesses are documented but not addressed.
The purpose of this stage is to convert findings from:
into measurable resilience improvement.
The process should follow a clear cycle:
Incident or Test
↓
Lesson Identified
↓
Root Cause
↓
Risk Assessment
↓
Remediation
↓
Owner and Deadline
↓
Validation
↓
Closure
↓
Framework Improvement
The goal should be to improve both the Critical Operation itself and the wider Operational Resilience programme.
Suppose a scenario test reveals that GCash can restore its payment platform within the required time, but transaction reconciliation after failover takes significantly longer than expected.
The lesson identified may therefore be:
Technical recovery meets the target, but reconciliation delays could cause the Critical Operation to exceed its Impact Tolerance.
The improvement action may include:
This demonstrates why successful system recovery does not automatically mean that the Critical Operation is resilient.
The outputs should include:
The five Implement stages form a continuous sequence.
Stage 1
Identify Critical Business Services
Determines what must be resilient.
↓
Stage 2
Map Processes and Resources
Determines what the service depends upon.
↓
Stage 3
Set Impact Tolerance
Determines how much disruption can be accepted.
↓
Stage 4
Conduct Scenario Testing
Determines whether resilience actually works.
↓
Stage 5
Improve Lessons Learnt
Determines how resilience will be strengthened.
Together, these stages create a closed-loop resilience implementation process.
|
Implement Stage |
Core Question |
Example Application to GCash |
Key Output |
|
Stage 1 – Identify Critical Business Services |
What must remain resilient? |
Identify Digital Wallet Operations or Payment Transaction Processing as candidate Critical Operations |
Critical Operation Register |
|
Stage 2 – Map Processes and Resources |
What supports the service? |
Map application, authentication, transaction processing, banks, telecoms and third parties |
Dependency Map |
|
Stage 3 – Set Impact Tolerance |
How much disruption can be accepted? |
Establish maximum disruption duration and customer/transaction thresholds |
Impact Tolerance Statement |
|
Stage 4 – Conduct Scenario Testing |
Can the service remain resilient under stress? |
Test cyber, technology, telecom and third-party failures |
Scenario Test Report |
|
Stage 5 – Improve Lessons Learnt |
What must be improved? |
Convert test findings into remediation and retesting |
Lessons and Remediation Register |
The Implement phase should not operate independently from the Plan and Sustain phases.
The relationship can be represented as:
The Plan phase provides direction. The Implement phase demonstrates capability. Together they form the foundation of a mature Operational Resilience programme.
The Implement phase should build upon GCash’s existing BCM capabilities.
For example:
|
Operational Resilience Activity |
Supporting BCM Capability |
|
Identify Critical Operations |
Business Impact Analysis |
|
Map Processes and Resources |
Dependency analysis |
|
Set Impact Tolerance |
Recovery objectives and impact assessment |
|
Scenario Testing |
BCM exercises and simulations |
|
Lessons Learned |
Post-exercise and post-incident improvement |
The important difference is that Operational Resilience focuses on end-to-end Critical Operations and acceptable limits of disruption, rather than on individual business-unit recovery alone.
For GCash, the Implement phase should be closely integrated with Technology and Cybersecurity.
Digital financial services may rely on:
Technology and cyber teams should therefore participate directly in:
Operational Resilience provides the business outcome against which those technical capabilities are assessed.
Critical Operations may depend substantially on external service providers.
GCash should therefore ensure that the Implement phase considers:
A Critical Operation cannot be considered resilient if a critical external dependency fails to meet the required Impact Tolerance.
At completion of the Implement phase, GCash should have a structured set of resilience deliverables.
These should include:
Together, these provide evidence that Operational Resilience has moved beyond planning into implementation.
Several principles should guide the Implement phase.
Assess the complete Critical Operation rather than isolated processes.
Measure resilience according to the effect of disruption on customers.
Understand both internal and external dependencies.
Evaluate performance against defined disruption thresholds.
Test conditions that genuinely challenge existing capabilities.
Business, Technology, Cybersecurity, Risk, BCM, and third parties should participate.
Use measurable test evidence rather than assumptions.
Every disruption or exercise should strengthen future resilience.
The Implement phase is where GCash converts Operational Resilience planning into demonstrable capability.
Its five stages—Identify Critical Business Services, Map Processes and Resources, Set Impact Tolerance, Conduct Scenario Testing, and Improve Lessons Learnt—create a structured pathway from determining what matters most to validating whether those operations can continue through severe disruption.
Each stage builds on the previous one: Critical Operations establish the focus, mapping establishes the dependency picture, Impact Tolerance establishes the resilience boundary, scenario testing validates capability, and lessons identified drive improvement.
For GCash, this phase is particularly important because digital financial services depend on tightly interconnected technology, telecommunications, data, financial institutions and third-party providers.
Resilience therefore cannot be demonstrated through isolated disaster recovery or BCM exercises alone. It must be demonstrated at the end-to-end Critical Operation level and measured against the organisation’s accepted disruption boundaries.
When these five stages are implemented as a continuous cycle, GCash can progressively strengthen its ability to withstand disruptions, protect customers, address vulnerabilities, and improve resilience across its financial services ecosystem.
Blogs marked [x] are under construction
| C1 | C2 | C8 | C14 | |||
"Implement" Phase of the Operational Resilience Planning Methodology |
|||||
| C8 [x] | C9 [x] | C10 [x] | C11 [x] | C12 [x] | C13 [x] |
To learn more about the course and schedule, click the buttons below for the OR-300 Operational Resilience Implementer course and the OR-5000 Operational Resilience Expert Implementer course.
|
If you have any questions, click to contact us. |
||
|
|