Chapter: Setting Impact Tolerance for CO-1 Digital Wallet Operations
Introduction
Impact Tolerance represents the maximum level of disruption that GCash can tolerate for CO-1 Digital Wallet Operations before the disruption results in unacceptable harm to customers, the organisation, the Philippine financial system, or regulatory obligations.
Unlike Recovery Time Objectives (RTOs), Recovery Point Objectives (RPOs), Maximum Tolerable Periods of Disruption (MTPDs), or Service Level Agreements (SLAs), Impact Tolerance is measured from the perspective of harm caused by service disruption rather than the recovery capability of individual systems or business processes.
For Digital Wallet Operations, Impact Tolerance must be assessed across the complete end-to-end service lifecycle, taking into consideration every Sub-Critical Business Service (Sub-CBS) that contributes to service delivery.
A disruption affecting a single Sub-CBS may have cascading consequences across payment processing, customer access, merchant transactions, settlement activities, regulatory compliance, and customer confidence.
Consequently, understanding the relative importance of each Sub-CBS enables GCash to identify where resilience capabilities should be strengthened to prevent unacceptable harm.
Cybersecurity and ICT risks are integral to this assessment because Digital Wallet Operations depend extensively on digital platforms, cloud infrastructure, telecommunications networks, payment gateways, application programming interfaces (APIs), databases, and external financial institutions.
Cyberattacks, infrastructure failures, technology concentration risks, and third-party ICT disruptions can all contribute to breaches of the defined Impact Tolerance. Accordingly, cyber and ICT considerations are embedded throughout the assessment rather than being treated as separate risk categories.
Table 1: Impact Tolerance Assessment
|
Sub-CBS Code |
Name of Sub-CBS |
Potential Disruption |
Potential Harm |
Level of Harm |
Key Harm Indicators |
|
CO-1.1 |
Digital Wallet Registration and Provisioning |
Customer onboarding platform unavailable |
New customers unable to register or activate wallets, reducing service accessibility and delaying financial inclusion. |
Medium |
Number of failed registrations, onboarding delays, customer complaints, duration of disruption |
|
CO-1.2 |
Customer Identity Verification and Account Validation |
Identity verification service unavailable or degraded |
Customers cannot complete KYC verification, preventing wallet activation and creating regulatory compliance risks. |
High |
Verification failure rate, onboarding backlog, regulatory exceptions |
|
CO-1.3 |
Wallet Funding and Value Loading |
Cash-in channels unavailable |
Customers cannot add funds, limiting wallet usability and reducing transaction activity. |
High |
Failed funding transactions, affected customers, transaction volume reduction |
|
CO-1.4 |
Wallet Balance Management |
Ledger corruption or balance synchronisation failure |
Incorrect balances may prevent payments, create financial discrepancies and generate customer disputes. |
Very High |
Data integrity failures, balance inconsistencies, reconciliation exceptions |
|
CO-1.5 |
Payment Transaction Processing |
Payment processing unavailable |
Customers and merchants cannot complete transactions, causing widespread disruption to commerce. |
Very High |
Transaction failure rate, merchant impact, payment backlog, service outage duration |
|
CO-1.6 |
Funds Transfer and Settlement Processing |
Settlement delays or transfer failures |
Delayed fund transfers affect liquidity, customer confidence and financial obligations. |
Very High |
Settlement backlog, delayed transfers, failed interbank transactions |
|
CO-1.7 |
Transaction Authorisation and Risk Controls |
Authentication or fraud detection unavailable |
Legitimate transactions rejected or fraudulent transactions approved, exposing customers and GCash to financial loss. |
Very High |
Authentication failures, fraud alerts, false approvals, fraud losses |
|
CO-1.8 |
Merchant Payment Enablement |
Merchant payment connectivity disrupted |
Merchants cannot accept wallet payments, affecting commercial transactions and customer confidence. |
High |
Number of affected merchants, failed merchant transactions, payment success rate |
|
CO-1.9 |
Digital Wallet Service Integration Management |
API or integration platform failure |
Multiple downstream services fail simultaneously because critical integrations are unavailable. |
Very High |
API failure rates, integration outages, number of dependent services affected |
|
CO-1.10 |
Customer Transaction Notification and Communication |
Notification services unavailable |
Customers lose transaction visibility, increasing enquiries, disputes and fraud concerns. |
Medium |
Notification delivery failures, contact centre volumes, customer complaints |
|
CO-1.11 |
Transaction Monitoring and Operational Surveillance |
Monitoring systems unavailable |
Operational issues remain undetected, increasing disruption duration and delaying incident response. |
High |
Monitoring blind spots, delayed incident detection, system availability metrics |
|
CO-1.12 |
Exception Handling and Transaction Resolution |
Investigation capability degraded |
Failed transactions remain unresolved, increasing operational risk and customer dissatisfaction. |
High |
Case backlog, dispute resolution time, unresolved transaction volume |
|
CO-1.13 |
Financial Reconciliation and Operational Reporting |
Reconciliation processing unavailable |
Financial discrepancies accumulate, affecting accounting accuracy and regulatory reporting. |
High |
Outstanding reconciliation items, reporting delays, financial variances |
|
CO-1.14 |
Operational Incident Management |
Incident coordination capability unavailable |
Delayed escalation and ineffective response increase outage duration and operational losses. |
High |
Incident response times, escalation delays, recovery coordination issues |
|
CO-1.15 |
Service Recovery and Operational Restoration |
Disaster recovery capability unavailable |
Digital Wallet Operations cannot be restored within acceptable operational limits following a major disruption. |
Very High |
Recovery duration, service availability, recovery test failures, customer impact |
Table 2: Cyber and ICT Risk Linkage
|
Sub-CBS Code |
Name of Sub-CBS |
Cyber and ICT Risk Linkage |
Contribution to Impact Tolerance Breach |
Proactive Risk Management Action |
Evidence of Proactive Risk Management |
|
CO-1.1 |
Digital Wallet Registration and Provisioning |
Identity management compromise, customer onboarding platform outage, API failure, denial-of-service attack |
Large numbers of customers cannot register or activate wallets, delaying access to essential financial services and increasing customer dissatisfaction. |
Implement multi-layer identity verification, resilient onboarding architecture, DDoS protection, API redundancy and continuous platform monitoring. |
Identity verification control assessments, vulnerability assessment reports, API resilience testing, onboarding platform failover test reports. |
|
CO-1.2 |
Customer Identity Verification and Account Validation |
KYC platform outage, privileged access compromise, identity database corruption, third-party identity verification failure |
Regulatory onboarding requirements cannot be completed, preventing wallet activation and creating compliance exposure. |
Deploy redundant KYC services, privileged access management, continuous monitoring of identity verification services and third-party assurance reviews. |
KYC audit reports, privileged access reviews, penetration testing reports, supplier assurance reports, compliance monitoring records. |
|
CO-1.3 |
Wallet Funding and Value Loading |
Banking gateway outage, payment API disruption, network failure, cloud infrastructure outage |
Customers are unable to load funds, reducing wallet usability and affecting downstream payment services. |
Establish multiple banking connectivity paths, API resilience testing, network redundancy, transaction monitoring and capacity management. |
Banking connectivity test reports, API monitoring dashboards, network resilience tests, transaction processing reports. |
|
CO-1.4 |
Wallet Balance Management |
Database corruption, storage failure, ransomware, data synchronisation failure |
Inaccurate wallet balances may result in failed transactions, financial losses and loss of customer confidence, rapidly breaching the Impact Tolerance. |
Implement database replication, immutable backups, integrity validation, real-time replication monitoring and disaster recovery procedures. |
Database integrity reports, backup restoration tests, disaster recovery exercises, reconciliation reports. |
|
CO-1.5 |
Payment Transaction Processing |
Payment engine failure, DDoS attack, application failure, API gateway disruption |
Large-scale payment failures immediately affect customers and merchants and represent one of the fastest paths to breaching the Impact Tolerance. |
Deploy high-availability payment platforms, active-active processing, DDoS protection, transaction throttling and continuous health monitoring. |
High-availability test results, transaction performance reports, DDoS simulation exercises, operational monitoring records. |
|
CO-1.6 |
Funds Transfer and Settlement Processing |
Settlement engine outage, network latency, third-party banking connectivity failure |
Delayed or failed settlements create liquidity, financial and customer impacts that may extend beyond GCash to the wider payment ecosystem. |
Maintain redundant settlement channels, automated reconciliation, contingency settlement procedures and continuous banking interface monitoring. |
Settlement testing reports, reconciliation evidence, banking interface monitoring reports, contingency exercise records. |
|
CO-1.7 |
Transaction Authorisation and Risk Controls |
Authentication service outage, fraud detection failure, privileged account compromise, cyber intrusion |
Fraud prevention capability deteriorates, increasing financial crime exposure while simultaneously affecting legitimate customer transactions. |
Implement adaptive authentication, security monitoring, behavioural analytics, privileged access management and continuous fraud model validation. |
Security Operations Centre (SOC) monitoring reports, penetration testing, fraud model validation reports, authentication resilience tests. |
|
CO-1.8 |
Merchant Payment Enablement |
Merchant API failure, QR payment platform disruption, third-party payment gateway outage |
Merchant acceptance of digital wallet payments is significantly reduced, affecting commercial activity and customer confidence. |
Diversify payment connectivity, implement resilient API gateways, monitor merchant connectivity and maintain contingency routing capabilities. |
Merchant connectivity dashboards, API performance reports, third-party assurance reports, resilience testing results. |
|
CO-1.9 |
Digital Wallet Service Integration Management |
API gateway failure, middleware outage, cloud integration platform failure, technology concentration risk |
Multiple interconnected Sub-CBS processes fail simultaneously, creating one of the highest risks of breaching the overall Impact Tolerance. |
Implement resilient integration architecture, API redundancy, cloud resilience, technology diversification and continuous interface monitoring. |
Integration resilience testing, cloud resilience assessments, API failover tests, architecture review reports. |
|
CO-1.10 |
Customer Transaction Notification and Communication |
SMS gateway outage, push notification failure, telecommunications disruption |
Customers lose transaction visibility, delaying fraud detection and increasing customer enquiries, although core financial processing may continue. |
Use multiple communication channels, redundant messaging platforms and continuous delivery monitoring. |
Notification delivery reports, telecommunications resilience testing, communication platform monitoring records. |
|
CO-1.11 |
Transaction Monitoring and Operational Surveillance |
Monitoring platform failure, log collection failure, security event monitoring disruption |
Operational incidents remain undetected, extending disruption duration and increasing the likelihood of exceeding the Impact Tolerance. |
Implement redundant monitoring platforms, centralised logging, automated alerting and continuous SOC operations. |
Monitoring coverage reports, SOC dashboards, incident detection metrics, monitoring resilience tests. |
|
CO-1.12 |
Exception Handling and Transaction Resolution |
Case management platform outage, transaction investigation database failure |
Failed transactions remain unresolved, increasing operational backlog and customer dissatisfaction during prolonged disruptions. |
Maintain resilient case management systems, automated workflow recovery, backup investigation capabilities and operational contingency procedures. |
Case management recovery tests, operational audit findings, workflow resilience reports, service quality metrics. |
|
CO-1.13 |
Financial Reconciliation and Operational Reporting |
Financial reporting platform outage, database corruption, batch processing failure |
Financial discrepancies accumulate, delaying regulatory reporting and increasing financial control risks. |
Automate reconciliation validation, implement redundant reporting systems, integrity monitoring and backup reporting processes. |
Reconciliation audit reports, financial control testing, regulatory reporting validation records, backup reporting exercises. |
|
CO-1.14 |
Operational Incident Management |
Incident management platform outage, communication platform disruption, cyberattack during incident response |
Incident coordination becomes ineffective, extending recovery time and increasing the probability of breaching the Impact Tolerance. |
Implement resilient incident management platforms, alternative communication channels, crisis management exercises and incident playbooks. |
Crisis exercise reports, incident response testing, communication resilience exercises, management review minutes. |
|
CO-1.15 |
Service Recovery and Operational Restoration |
Disaster Recovery platform failure, backup corruption, cloud recovery failure, infrastructure outage |
Failure to restore Digital Wallet Operations within acceptable limits results in prolonged customer harm and failure to remain within the defined Impact Tolerance. |
Conduct regular disaster recovery testing, infrastructure resilience assessments, backup validation, cloud recovery exercises and recovery governance reviews. |
Disaster recovery test reports, failover exercise reports, backup verification records, infrastructure resilience assessments, independent assurance reviews. |
Recommended Impact Tolerance for CO-1 Digital Wallet Operations
The following Impact Tolerance is an illustrative implementation recommendation for CO-1 Digital Wallet Operations. It is intended to demonstrate a practical approach to Operational Resilience implementation and must be validated by GCash's Senior Management, Critical Operation Owner, Operational Risk Management, Technology Services, Cybersecurity, Business Continuity Management, and other relevant governance bodies, taking into account BSP regulatory expectations and the organisation's operational context.
|
Assessment Area |
Illustrative Recommendation |
|
Critical Operation |
CO-1 Digital Wallet Operations |
|
Impact Tolerance Objective |
Maintain the continuous availability and integrity of Digital Wallet Operations so that disruption does not result in unacceptable harm to customers, financial stability, regulatory obligations, or market confidence. |
|
Illustrative Maximum Tolerable Service Disruption |
Up to 2 hours for complete end-to-end service outage under severe but plausible scenarios. Longer disruptions should trigger executive escalation and crisis management. |
|
Illustrative Service Availability Threshold |
Maintain availability above 99.9% during normal operations. Temporary degradation may be tolerated only if essential payment and wallet functions remain available. |
|
Illustrative Customer Impact Threshold |
Significant disruption affecting more than 20% of active customers or critical merchant ecosystems should be considered approaching unacceptable harm and require executive intervention. |
|
Illustrative Transaction Processing Threshold |
Critical payment processing should maintain a transaction success rate above 99% under normal operating conditions. Sustained degradation below this level should initiate incident escalation and resilience response. |
|
Illustrative Data Integrity Threshold |
No material loss, corruption, or unauthorised alteration of customer wallet balances or transaction records is acceptable. Any confirmed integrity compromise should be treated as a potential breach of the Impact Tolerance regardless of outage duration. |
|
Illustrative Regulatory Threshold |
Any disruption resulting in regulatory notification requirements, significant compliance breaches, or systemic payment disruption should be considered a potential Impact Tolerance breach. |
|
Point of Unacceptable Harm |
Unacceptable harm occurs when customers lose sustained access to essential wallet services, widespread payment failures occur, financial records cannot be trusted, or disruption materially affects confidence in GCash or the broader Philippine payment ecosystem. |
Rationale
The recommended Impact Tolerance reflects the critical role that Digital Wallet Operations plays within the Philippine digital financial ecosystem. Unlike traditional recovery metrics such as RTO or SLA, this recommendation focuses on the point at which disruption causes unacceptable harm to customers, merchants, financial institutions, and regulatory objectives.
Because the service is highly dependent on interconnected technology platforms, third-party providers, payment networks, and cyber resilience capabilities, maintaining the proposed Impact Tolerance requires coordinated governance, robust ICT resilience, effective cyber controls, and regular scenario testing across the entire end-to-end operating model.
Setting an Impact Tolerance for CO-1 Digital Wallet Operations establishes a clear boundary between acceptable operational disruption and unacceptable harm. By assessing each Sub-Critical Business Service individually and understanding its contribution to the end-to-end delivery of the Critical Operation, GCash gains a structured basis for identifying where resilience capabilities must be strengthened to protect customers and maintain confidence in its digital financial services.
The integration of Cyber and ICT risks into the assessment recognises that operational resilience is inseparable from technology resilience.
Cyberattacks, infrastructure failures, cloud outages, API disruptions, and third-party ICT failures all have the potential to propagate rapidly across interconnected processes and contribute directly to an Impact Tolerance breach.
Embedding these risks within each Sub-CBS assessment ensures that resilience measures address the operational consequences of technology failures rather than treating cyber resilience as a standalone discipline.
The proactive risk management actions and supporting evidence identified throughout this chapter provide management with demonstrable assurance that resilience capabilities are being implemented, monitored, and continuously improved.
Evidence such as control testing results, penetration tests, disaster recovery exercises, scenario testing outcomes, third-party assurance reports, and governance committee reviews enables GCash to demonstrate resilience preparedness to internal stakeholders and the Bangko Sentral ng Pilipinas.
Finally, the recommended Impact Tolerance should serve as the benchmark for future severe-but-plausible scenario testing, resilience investment decisions, remediation programmes, and continuous improvement activities.
As Digital Wallet Operations evolve, technology architectures change, customer usage patterns increase, or regulatory expectations develop, the Impact Tolerance should be periodically reviewed and recalibrated to ensure it continues to reflect the level of disruption that GCash can tolerate before unacceptable harm occurs. This ongoing validation process is fundamental to sustaining a mature and effective Operational Resilience programme.
| eBook 3: Starting Your OR Implementation |
||||
| CBS-1 Insurance Policy Application and Issuance | ||||
| CBS-1 DP | CBS-1 MII | CBS-1 ITo | CBS-1 SbPS | CBS-1 ST |
![]() |
![]() |
![]() |
![]() |
![]() |
Gain Competency: For organisations looking to accelerate their journey, BCM Institute’s training and certification programs, including the OR-5000 Operational Resilience Expert Implementer course, provide in-depth insights and practical toolkits for effectively embedding this model.

![BB OR [A] 18 BB OR [A] 18](https://blog.bcm-institute.org/hs-fs/hubfs/OR%20picture/OR%20Pictures%20A/BB%20OR%20Folder%20A/BB%20OR%20%5BA%5D%2018.jpg?width=2000&height=1333&name=BB%20OR%20%5BA%5D%2018.jpg)
![[OR] [GCash] [Full Banner] Strengthening Operational Resilience at GCash](https://no-cache.hubspot.com/cta/default/3893111/3a39ca09-f7ed-4e75-858f-941c41224c31.png)
![[OR] [GCash] [Disclaimer] Legal Disclaimers and Usage of eBook Banner](https://no-cache.hubspot.com/cta/default/3893111/454a0c6c-3084-45f4-b724-65b4ca4eb6d1.png)
![[OR] [GCash] [PH] [E3] [CO] [1] [ITo] Digital Wallet Operations](https://no-cache.hubspot.com/cta/default/3893111/c463e973-5d22-4fdc-b88c-8837e49be150.png)
![Banner [Table] [OR] [E3] Establish Impact Tolerance](https://no-cache.hubspot.com/cta/default/3893111/627c33a8-714d-40af-9a2b-0d7957fb8afa.png)
![Banner [Summing] [OR] [E3] Establish Impact Tolerance](https://no-cache.hubspot.com/cta/default/3893111/5e80e50f-5e3e-44ea-8c43-16bf42d4f3b5.png)
![[OR] [GCash] [3/4 Banner] Strengthening Operational Resilience at GCash](https://no-cache.hubspot.com/cta/default/3893111/f32c765b-c3ba-4ed6-bd15-6dc928547f19.png)
![[OR] [GCash] [PH] [E3] [CO] [1] [DP] Digital Wallet Operations](https://no-cache.hubspot.com/cta/default/3893111/62adb964-d08b-4996-9d00-dca98439cdd7.png)
![[OR] [GCash] [PH] [E3] [CO] [1] [MD] Digital Wallet Operations](https://no-cache.hubspot.com/cta/default/3893111/4cab1d04-4396-4674-8d6e-547dcef28e10.png)

![[OR] [GCash] [PH] [E3] [CO] [1] [ST] Digital Wallet Operations](https://no-cache.hubspot.com/cta/default/3893111/482a8d4c-a87b-4de2-9825-0982a35464d4.png)







![[BL-OR] [3-4-5] View Schedule](https://no-cache.hubspot.com/cta/default/3893111/d0d733a1-16c0-4b68-a26d-adbfd4fc6069.png)
![[BL-OR] [3] FAQ OR-300](https://no-cache.hubspot.com/cta/default/3893111/f20c71b4-f5e8-4aa5-8056-c374ca33a091.png)
![Email to Sales Team [BCM Institute]](https://no-cache.hubspot.com/cta/default/3893111/3c53daeb-2836-4843-b0e0-645baee2ab9e.png)








