. .

Strengthening Operational Resilience at GCash: An Enterprise Implementation Guide
BB OR [A] 18

[OR] [GCash] [E3] [CBS] [1] [ITo] Establish Impact Tolerances

[OR] [GCash] [Full Banner] Strengthening Operational Resilience at GCash

Impact Tolerance represents the maximum level of disruption that GCash can tolerate for CO-1 Digital Wallet Operations before the disruption results in unacceptable harm to customers, the organisation, the Philippine financial system, or regulatory obligations.

Unlike Recovery Time Objectives (RTOs), Recovery Point Objectives (RPOs), Maximum Tolerable Periods of Disruption (MTPDs), or Service Level Agreements (SLAs), Impact Tolerance is measured from the perspective of harm caused by service disruption rather than the recovery capability of individual systems or business processes.

For Digital Wallet Operations, Impact Tolerance must be assessed across the complete end-to-end service lifecycle, taking into consideration every Sub-Critical Business Service (Sub-CBS) that contributes to service delivery.

A disruption affecting a single Sub-CBS may have cascading consequences across payment processing, customer access, merchant transactions, settlement activities, regulatory compliance, and customer confidence.

New call-to-action

Dr Goh Moh Heng
Operational Resilience Planner-Specialist-Expert

[OR] [GCash] [Disclaimer] Legal Disclaimers and Usage of eBook Banner

New call-to-actionChapter: Setting Impact Tolerance for CO-1 Digital Wallet Operations

Introduction

[OR] [GCash] [PH] [E3] [CO] [1] [ITo] Digital Wallet Operations

Impact Tolerance represents the maximum level of disruption that GCash can tolerate for CO-1 Digital Wallet Operations before the disruption results in unacceptable harm to customers, the organisation, the Philippine financial system, or regulatory obligations.

Unlike Recovery Time Objectives (RTOs), Recovery Point Objectives (RPOs), Maximum Tolerable Periods of Disruption (MTPDs), or Service Level Agreements (SLAs), Impact Tolerance is measured from the perspective of harm caused by service disruption rather than the recovery capability of individual systems or business processes.

BCMPedia_BSP_Tolerance for DisruptionFor Digital Wallet Operations, Impact Tolerance must be assessed across the complete end-to-end service lifecycle, taking into consideration every Sub-Critical Business Service (Sub-CBS) that contributes to service delivery.

A disruption affecting a single Sub-CBS may have cascading consequences across payment processing, customer access, merchant transactions, settlement activities, regulatory compliance, and customer confidence.

Consequently, understanding the relative importance of each Sub-CBS enables GCash to identify where resilience capabilities should be strengthened to prevent unacceptable harm.

Cybersecurity and ICT risks are integral to this assessment because Digital Wallet Operations depend extensively on digital platforms, cloud infrastructure, telecommunications networks, payment gateways, application programming interfaces (APIs), databases, and external financial institutions.

Cyberattacks, infrastructure failures, technology concentration risks, and third-party ICT disruptions can all contribute to breaches of the defined Impact Tolerance. Accordingly, cyber and ICT considerations are embedded throughout the assessment rather than being treated as separate risk categories.

Banner [Table] [OR] [E3] Establish Impact Tolerance

Table 1: Impact Tolerance Assessment

Sub-CBS Code

Name of Sub-CBS

Potential Disruption

Potential Harm

Level of Harm

Key Harm Indicators

CO-1.1

Digital Wallet Registration and Provisioning

Customer onboarding platform unavailable

New customers unable to register or activate wallets, reducing service accessibility and delaying financial inclusion.

Medium

Number of failed registrations, onboarding delays, customer complaints, duration of disruption

CO-1.2

Customer Identity Verification and Account Validation

Identity verification service unavailable or degraded

Customers cannot complete KYC verification, preventing wallet activation and creating regulatory compliance risks.

High

Verification failure rate, onboarding backlog, regulatory exceptions

CO-1.3

Wallet Funding and Value Loading

Cash-in channels unavailable

Customers cannot add funds, limiting wallet usability and reducing transaction activity.

High

Failed funding transactions, affected customers, transaction volume reduction

CO-1.4

Wallet Balance Management

Ledger corruption or balance synchronisation failure

Incorrect balances may prevent payments, create financial discrepancies and generate customer disputes.

Very High

Data integrity failures, balance inconsistencies, reconciliation exceptions

CO-1.5

Payment Transaction Processing

Payment processing unavailable

Customers and merchants cannot complete transactions, causing widespread disruption to commerce.

Very High

Transaction failure rate, merchant impact, payment backlog, service outage duration

CO-1.6

Funds Transfer and Settlement Processing

Settlement delays or transfer failures

Delayed fund transfers affect liquidity, customer confidence and financial obligations.

Very High

Settlement backlog, delayed transfers, failed interbank transactions

CO-1.7

Transaction Authorisation and Risk Controls

Authentication or fraud detection unavailable

Legitimate transactions rejected or fraudulent transactions approved, exposing customers and GCash to financial loss.

Very High

Authentication failures, fraud alerts, false approvals, fraud losses

CO-1.8

Merchant Payment Enablement

Merchant payment connectivity disrupted

Merchants cannot accept wallet payments, affecting commercial transactions and customer confidence.

High

Number of affected merchants, failed merchant transactions, payment success rate

CO-1.9

Digital Wallet Service Integration Management

API or integration platform failure

Multiple downstream services fail simultaneously because critical integrations are unavailable.

Very High

API failure rates, integration outages, number of dependent services affected

CO-1.10

Customer Transaction Notification and Communication

Notification services unavailable

Customers lose transaction visibility, increasing enquiries, disputes and fraud concerns.

Medium

Notification delivery failures, contact centre volumes, customer complaints

CO-1.11

Transaction Monitoring and Operational Surveillance

Monitoring systems unavailable

Operational issues remain undetected, increasing disruption duration and delaying incident response.

High

Monitoring blind spots, delayed incident detection, system availability metrics

CO-1.12

Exception Handling and Transaction Resolution

Investigation capability degraded

Failed transactions remain unresolved, increasing operational risk and customer dissatisfaction.

High

Case backlog, dispute resolution time, unresolved transaction volume

CO-1.13

Financial Reconciliation and Operational Reporting

Reconciliation processing unavailable

Financial discrepancies accumulate, affecting accounting accuracy and regulatory reporting.

High

Outstanding reconciliation items, reporting delays, financial variances

CO-1.14

Operational Incident Management

Incident coordination capability unavailable

Delayed escalation and ineffective response increase outage duration and operational losses.

High

Incident response times, escalation delays, recovery coordination issues

CO-1.15

Service Recovery and Operational Restoration

Disaster recovery capability unavailable

Digital Wallet Operations cannot be restored within acceptable operational limits following a major disruption.

Very High

Recovery duration, service availability, recovery test failures, customer impact

 

Table 2: Cyber and ICT Risk Linkage

Sub-CBS Code

Name of Sub-CBS

Cyber and ICT Risk Linkage

Contribution to Impact Tolerance Breach

Proactive Risk Management Action

Evidence of Proactive Risk Management

CO-1.1

Digital Wallet Registration and Provisioning

Identity management compromise, customer onboarding platform outage, API failure, denial-of-service attack

Large numbers of customers cannot register or activate wallets, delaying access to essential financial services and increasing customer dissatisfaction.

Implement multi-layer identity verification, resilient onboarding architecture, DDoS protection, API redundancy and continuous platform monitoring.

Identity verification control assessments, vulnerability assessment reports, API resilience testing, onboarding platform failover test reports.

CO-1.2

Customer Identity Verification and Account Validation

KYC platform outage, privileged access compromise, identity database corruption, third-party identity verification failure

Regulatory onboarding requirements cannot be completed, preventing wallet activation and creating compliance exposure.

Deploy redundant KYC services, privileged access management, continuous monitoring of identity verification services and third-party assurance reviews.

KYC audit reports, privileged access reviews, penetration testing reports, supplier assurance reports, compliance monitoring records.

CO-1.3

Wallet Funding and Value Loading

Banking gateway outage, payment API disruption, network failure, cloud infrastructure outage

Customers are unable to load funds, reducing wallet usability and affecting downstream payment services.

Establish multiple banking connectivity paths, API resilience testing, network redundancy, transaction monitoring and capacity management.

Banking connectivity test reports, API monitoring dashboards, network resilience tests, transaction processing reports.

CO-1.4

Wallet Balance Management

Database corruption, storage failure, ransomware, data synchronisation failure

Inaccurate wallet balances may result in failed transactions, financial losses and loss of customer confidence, rapidly breaching the Impact Tolerance.

Implement database replication, immutable backups, integrity validation, real-time replication monitoring and disaster recovery procedures.

Database integrity reports, backup restoration tests, disaster recovery exercises, reconciliation reports.

CO-1.5

Payment Transaction Processing

Payment engine failure, DDoS attack, application failure, API gateway disruption

Large-scale payment failures immediately affect customers and merchants and represent one of the fastest paths to breaching the Impact Tolerance.

Deploy high-availability payment platforms, active-active processing, DDoS protection, transaction throttling and continuous health monitoring.

High-availability test results, transaction performance reports, DDoS simulation exercises, operational monitoring records.

CO-1.6

Funds Transfer and Settlement Processing

Settlement engine outage, network latency, third-party banking connectivity failure

Delayed or failed settlements create liquidity, financial and customer impacts that may extend beyond GCash to the wider payment ecosystem.

Maintain redundant settlement channels, automated reconciliation, contingency settlement procedures and continuous banking interface monitoring.

Settlement testing reports, reconciliation evidence, banking interface monitoring reports, contingency exercise records.

CO-1.7

Transaction Authorisation and Risk Controls

Authentication service outage, fraud detection failure, privileged account compromise, cyber intrusion

Fraud prevention capability deteriorates, increasing financial crime exposure while simultaneously affecting legitimate customer transactions.

Implement adaptive authentication, security monitoring, behavioural analytics, privileged access management and continuous fraud model validation.

Security Operations Centre (SOC) monitoring reports, penetration testing, fraud model validation reports, authentication resilience tests.

CO-1.8

Merchant Payment Enablement

Merchant API failure, QR payment platform disruption, third-party payment gateway outage

Merchant acceptance of digital wallet payments is significantly reduced, affecting commercial activity and customer confidence.

Diversify payment connectivity, implement resilient API gateways, monitor merchant connectivity and maintain contingency routing capabilities.

Merchant connectivity dashboards, API performance reports, third-party assurance reports, resilience testing results.

CO-1.9

Digital Wallet Service Integration Management

API gateway failure, middleware outage, cloud integration platform failure, technology concentration risk

Multiple interconnected Sub-CBS processes fail simultaneously, creating one of the highest risks of breaching the overall Impact Tolerance.

Implement resilient integration architecture, API redundancy, cloud resilience, technology diversification and continuous interface monitoring.

Integration resilience testing, cloud resilience assessments, API failover tests, architecture review reports.

CO-1.10

Customer Transaction Notification and Communication

SMS gateway outage, push notification failure, telecommunications disruption

Customers lose transaction visibility, delaying fraud detection and increasing customer enquiries, although core financial processing may continue.

Use multiple communication channels, redundant messaging platforms and continuous delivery monitoring.

Notification delivery reports, telecommunications resilience testing, communication platform monitoring records.

CO-1.11

Transaction Monitoring and Operational Surveillance

Monitoring platform failure, log collection failure, security event monitoring disruption

Operational incidents remain undetected, extending disruption duration and increasing the likelihood of exceeding the Impact Tolerance.

Implement redundant monitoring platforms, centralised logging, automated alerting and continuous SOC operations.

Monitoring coverage reports, SOC dashboards, incident detection metrics, monitoring resilience tests.

CO-1.12

Exception Handling and Transaction Resolution

Case management platform outage, transaction investigation database failure

Failed transactions remain unresolved, increasing operational backlog and customer dissatisfaction during prolonged disruptions.

Maintain resilient case management systems, automated workflow recovery, backup investigation capabilities and operational contingency procedures.

Case management recovery tests, operational audit findings, workflow resilience reports, service quality metrics.

CO-1.13

Financial Reconciliation and Operational Reporting

Financial reporting platform outage, database corruption, batch processing failure

Financial discrepancies accumulate, delaying regulatory reporting and increasing financial control risks.

Automate reconciliation validation, implement redundant reporting systems, integrity monitoring and backup reporting processes.

Reconciliation audit reports, financial control testing, regulatory reporting validation records, backup reporting exercises.

CO-1.14

Operational Incident Management

Incident management platform outage, communication platform disruption, cyberattack during incident response

Incident coordination becomes ineffective, extending recovery time and increasing the probability of breaching the Impact Tolerance.

Implement resilient incident management platforms, alternative communication channels, crisis management exercises and incident playbooks.

Crisis exercise reports, incident response testing, communication resilience exercises, management review minutes.

CO-1.15

Service Recovery and Operational Restoration

Disaster Recovery platform failure, backup corruption, cloud recovery failure, infrastructure outage

Failure to restore Digital Wallet Operations within acceptable limits results in prolonged customer harm and failure to remain within the defined Impact Tolerance.

Conduct regular disaster recovery testing, infrastructure resilience assessments, backup validation, cloud recovery exercises and recovery governance reviews.

Disaster recovery test reports, failover exercise reports, backup verification records, infrastructure resilience assessments, independent assurance reviews.

 

Recommended Impact Tolerance for CO-1 Digital Wallet Operations

The following Impact Tolerance is an illustrative implementation recommendation for CO-1 Digital Wallet Operations. It is intended to demonstrate a practical approach to Operational Resilience implementation and must be validated by GCash's Senior Management, Critical Operation Owner, Operational Risk Management, Technology Services, Cybersecurity, Business Continuity Management, and other relevant governance bodies, taking into account BSP regulatory expectations and the organisation's operational context.

 

Assessment Area

Illustrative Recommendation

Critical Operation

CO-1 Digital Wallet Operations

Impact Tolerance Objective

Maintain the continuous availability and integrity of Digital Wallet Operations so that disruption does not result in unacceptable harm to customers, financial stability, regulatory obligations, or market confidence.

Illustrative Maximum Tolerable Service Disruption

Up to 2 hours for complete end-to-end service outage under severe but plausible scenarios. Longer disruptions should trigger executive escalation and crisis management.

Illustrative Service Availability Threshold

Maintain availability above 99.9% during normal operations. Temporary degradation may be tolerated only if essential payment and wallet functions remain available.

Illustrative Customer Impact Threshold

Significant disruption affecting more than 20% of active customers or critical merchant ecosystems should be considered approaching unacceptable harm and require executive intervention.

Illustrative Transaction Processing Threshold

Critical payment processing should maintain a transaction success rate above 99% under normal operating conditions. Sustained degradation below this level should initiate incident escalation and resilience response.

Illustrative Data Integrity Threshold

No material loss, corruption, or unauthorised alteration of customer wallet balances or transaction records is acceptable. Any confirmed integrity compromise should be treated as a potential breach of the Impact Tolerance regardless of outage duration.

Illustrative Regulatory Threshold

Any disruption resulting in regulatory notification requirements, significant compliance breaches, or systemic payment disruption should be considered a potential Impact Tolerance breach.

Point of Unacceptable Harm

Unacceptable harm occurs when customers lose sustained access to essential wallet services, widespread payment failures occur, financial records cannot be trusted, or disruption materially affects confidence in GCash or the broader Philippine payment ecosystem.

Rationale

The recommended Impact Tolerance reflects the critical role that Digital Wallet Operations plays within the Philippine digital financial ecosystem. Unlike traditional recovery metrics such as RTO or SLA, this recommendation focuses on the point at which disruption causes unacceptable harm to customers, merchants, financial institutions, and regulatory objectives.

Because the service is highly dependent on interconnected technology platforms, third-party providers, payment networks, and cyber resilience capabilities, maintaining the proposed Impact Tolerance requires coordinated governance, robust ICT resilience, effective cyber controls, and regular scenario testing across the entire end-to-end operating model.

Banner [Summing] [OR] [E3] Establish Impact Tolerance

Setting an Impact Tolerance for CO-1 Digital Wallet Operations establishes a clear boundary between acceptable operational disruption and unacceptable harm. By assessing each Sub-Critical Business Service individually and understanding its contribution to the end-to-end delivery of the Critical Operation, GCash gains a structured basis for identifying where resilience capabilities must be strengthened to protect customers and maintain confidence in its digital financial services.

The integration of Cyber and ICT risks into the assessment recognises that operational resilience is inseparable from technology resilience.

Cyberattacks, infrastructure failures, cloud outages, API disruptions, and third-party ICT failures all have the potential to propagate rapidly across interconnected processes and contribute directly to an Impact Tolerance breach.

Embedding these risks within each Sub-CBS assessment ensures that resilience measures address the operational consequences of technology failures rather than treating cyber resilience as a standalone discipline.

The proactive risk management actions and supporting evidence identified throughout this chapter provide management with demonstrable assurance that resilience capabilities are being implemented, monitored, and continuously improved.

Evidence such as control testing results, penetration tests, disaster recovery exercises, scenario testing outcomes, third-party assurance reports, and governance committee reviews enables GCash to demonstrate resilience preparedness to internal stakeholders and the Bangko Sentral ng Pilipinas.

Finally, the recommended Impact Tolerance should serve as the benchmark for future severe-but-plausible scenario testing, resilience investment decisions, remediation programmes, and continuous improvement activities.

As Digital Wallet Operations evolve, technology architectures change, customer usage patterns increase, or regulatory expectations develop, the Impact Tolerance should be periodically reviewed and recalibrated to ensure it continues to reflect the level of disruption that GCash can tolerate before unacceptable harm occurs. This ongoing validation process is fundamental to sustaining a mature and effective Operational Resilience programme.

 

[OR] [GCash] [3/4 Banner] Strengthening Operational Resilience at GCash

eBook 3: Starting Your OR Implementation
CBS-1 Insurance Policy Application and Issuance
CBS-1 DP CBS-1 MII CBS-1 ITo CBS-1 SbPS CBS-1 ST
[OR] [GCash] [PH] [E3] [CO] [1] [DP] Digital Wallet Operations [OR] [GCash] [PH] [E3] [CO] [1] [MD] Digital Wallet Operations [OR] [GCash] [PH] [E3] [CO] [1] [ITo] Digital Wallet Operations New call-to-action [OR] [GCash] [PH] [E3] [CO] [1] [ST] Digital Wallet Operations

New call-to-actionNew call-to-action

Gain Competency: For organisations looking to accelerate their journey, BCM Institute’s training and certification programs, including the OR-5000 Operational Resilience Expert Implementer course, provide in-depth insights and practical toolkits for effectively embedding this model.

 

More Information About OR-5000 [OR-5] or OR-300 [OR-3]

To learn more about the course and schedule, click the buttons below for the OR-300 Operational Resilience Implementer course and the OR-5000 Operational Resilience Expert Implementer course.

BL-OR-3 Register Now BL-OR-3_Tell Me More BL-OR-3_View Schedule
BL-OR-5_Register Now BL-OR-5_Tell Me More  [BL-OR] [3-4-5] View Schedule
[BL-OR] [3] FAQ OR-300

If you have any questions, click to contact us.Email to Sales Team [BCM Institute]

FAQ BL-OR-5 OR-5000
OR Implementer Landing Page

New call-to-action

New call-to-action

 

Your Comments Here:

 

CTA Banner_OR

CTA Banner_ORA

CTA Banner_BCM

CTA Banner_ITDR

CTA Banner_CM