Chapter: Perform Scenario Testing for CO-1 Digital Wallet Operations
Introduction
Scenario Testing is one of the most important validation activities within an Operational Resilience programme because it provides objective evidence of whether a Critical Operation can continue to operate within its defined Impact Tolerance when exposed to Severe but Plausible Scenarios.
Rather than focusing solely on technology recovery or business continuity plans, Scenario Testing evaluates the coordinated response of people, processes, technology, information, facilities, third parties, and governance across the complete end-to-end service.
For GCash's CO-1 Digital Wallet Operations, the previously identified Severe but Plausible Scenarios provide the foundation for designing realistic Scenario Tests. Each test is mapped to a specific Sub-Critical Business Service (Sub-CBS), while also assessing how disruption propagates across interconnected business processes and supporting capabilities.
The recommended testing programme integrates Cyber and ICT Risks throughout every scenario. Cyberattacks, cloud outages, API failures, telecommunications disruptions, data integrity failures, and third-party service interruptions are treated as embedded components of operational disruption rather than isolated technology events.
This integrated approach enables GCash to assess its ability to maintain Digital Wallet Operations within its approved Impact Tolerance while identifying resilience gaps, validating governance, and supporting continuous improvement.
The uploaded prompt specifies that the programme should include end-to-end testing, integrated cyber and ICT risk considerations, measurable objectives, auditable evidence, and regulatory alignment with BSP Circular No. 1203 (Series of 2024).
Table 1 (Part 1): Scenario Testing Programme
|
Sub-CBS Code |
Name of Sub-CBS |
Severe but Plausible Scenario |
Recommended Scenario Test |
Testing Method |
Scenario Testing Objective |
Key Scenario Injects / Disruption Conditions |
Interconnections and Interdependencies Tested |
|
CO-1.1 |
Digital Wallet Registration and Provisioning |
DDoS attack on onboarding platform |
Customer onboarding resilience test |
Cyber incident simulation with API resilience testing |
Validate the ability to continue onboarding customers during sustained cyber disruption. |
Customer registration failures, API latency, surge in onboarding requests |
Customer onboarding, identity verification, CRM integration, network infrastructure |
|
CO-1.2 |
Customer Identity Verification and Account Validation |
National identity verification service outage |
Identity verification continuity exercise |
Third-party disruption exercise with tabletop escalation |
Assess continuity of customer verification when external identity services become unavailable. |
External KYC service unavailable, communications delays, manual verification activation |
Identity providers, compliance operations, fraud management, customer onboarding |
|
CO-1.3 |
Wallet Funding and Value Loading |
Banking connectivity failure |
Payment channel resilience test |
Integrated business and technology simulation |
Validate continued customer funding using alternative banking channels. |
Primary banking interface unavailable, payment gateway degradation, increased transaction retries |
Banking interfaces, payment gateways, treasury operations, settlement services |
|
CO-1.4 |
Wallet Balance Management |
Ledger database corruption |
Data integrity validation exercise |
Data integrity and reconciliation test |
Demonstrate the ability to detect, isolate and restore accurate wallet balances. |
Database corruption, inconsistent balances, recovery from replicated database |
Transaction processing, reconciliation, customer account management |
|
CO-1.5 |
Payment Transaction Processing |
Ransomware affecting payment processing |
Integrated payment resilience exercise |
Cyber incident simulation combined with disaster recovery test |
Validate end-to-end payment continuity during a major cyber incident. |
Payment processing failure, ransomware encryption, failover activation |
Merchant ecosystem, fraud controls, banking connectivity, customer services |
|
CO-1.6 |
Funds Transfer and Settlement Processing |
National payment settlement disruption |
Settlement continuity exercise |
Integrated business and technology simulation |
Assess settlement capability when external clearing services are unavailable. |
Settlement delays, banking network outage, liquidity management decisions |
Banking institutions, clearing houses, treasury, reconciliation |
|
CO-1.7 |
Transaction Authorisation and Risk Controls |
Authentication platform compromise |
Fraud and authentication resilience exercise |
Cyber incident simulation |
Validate secure customer authentication while maintaining fraud prevention capability. |
Authentication failures, privileged account compromise, fraud alerts |
Identity management, fraud monitoring, cybersecurity operations |
|
CO-1.8 |
Merchant Payment Enablement |
Merchant platform capacity exhaustion |
Merchant payment stress exercise |
Capacity and stress test |
Validate payment performance during sustained peak transaction demand. |
Transaction surge, API congestion, merchant payment delays |
Merchant platforms, acquiring partners, payment APIs |
Table 1 (Part 2): Scenario Testing Programme
|
Sub-CBS Code |
Name of Sub-CBS |
Severe but Plausible Scenario |
Recommended Scenario Test |
Testing Method |
Scenario Testing Objective |
Key Scenario Injects / Disruption Conditions |
Interconnections and Interdependencies Tested |
|
CO-1.9 |
Digital Wallet Service Integration Management |
Enterprise API Gateway Failure combined with Cloud Connectivity Degradation |
Enterprise Integration Resilience Exercise |
API resilience test combined with integrated business and technology simulation |
Validate that Digital Wallet Operations continue despite failure of multiple API services and cloud-hosted integration components. |
API gateway failure, cloud latency, multiple external interface failures, degraded middleware performance |
Banking APIs, merchant systems, payment gateways, settlement platforms, cloud infrastructure |
|
CO-1.10 |
Customer Transaction Notification and Communication |
Nationwide Telecommunications Service Disruption |
Customer Communication Continuity Exercise |
Walk-through combined with third-party disruption exercise |
Assess GCash's ability to communicate with customers using alternative channels during telecommunications disruption. |
SMS gateway outage, mobile network degradation, delayed push notifications |
Telecommunications providers, notification platforms, customer support, fraud alert services |
|
CO-1.11 |
Transaction Monitoring and Operational Surveillance |
Failure of Monitoring Platform and Security Event Collection |
Operational Monitoring Validation Exercise |
Technical recovery test with cyber incident simulation |
Validate detection capability when monitoring systems become unavailable while operational incidents continue to develop. |
SIEM failure, monitoring dashboard outage, delayed operational alerts, loss of security logging |
SOC, operational monitoring, technology operations, cybersecurity monitoring |
|
CO-1.12 |
Exception Handling and Transaction Resolution |
Large-scale Failed Transaction Backlog |
Customer Resolution Surge Exercise |
Integrated business simulation |
Assess operational capability to manage high volumes of failed transactions while maintaining acceptable customer service levels. |
Surge of failed transactions, duplicate payments, high complaint volumes, manual investigation workload |
Customer service, payment operations, reconciliation teams, fraud management |
|
CO-1.13 |
Financial Reconciliation and Operational Reporting |
Data Integrity Failure during End-of-Day Reconciliation |
Financial Integrity Recovery Exercise |
Data integrity and reconciliation test |
Validate the organisation's ability to restore accurate financial records following data corruption. |
Corrupted settlement files, reconciliation mismatches, delayed reporting deadlines |
Finance, accounting, settlement services, regulatory reporting |
|
CO-1.14 |
Operational Incident Management |
Major Cyber Incident with Escalation Failure |
Crisis Coordination Exercise |
Crisis management exercise integrated with cyber incident simulation |
Assess executive decision-making, governance effectiveness and cross-functional coordination during a major cyber crisis. |
Ransomware attack, communication failures, delayed escalation, executive decision points |
Crisis Management Team, Executive Management, Technology Operations, Cybersecurity, Communications |
|
CO-1.15 |
Service Recovery and Operational Restoration |
Simultaneous Failure of Primary and Disaster Recovery Environments |
End-to-End Service Recovery Exercise |
Disaster recovery test combined with end-to-end Critical Operation scenario test |
Validate recovery of Digital Wallet Operations within the approved Impact Tolerance following catastrophic infrastructure failure. |
Primary site unavailable, disaster recovery replication failure, regional infrastructure disruption, prolonged service outage |
Disaster Recovery infrastructure, cloud services, network providers, business operations, customer services |
Table 2: Expected Resilience Outcomes and Evidence
|
Sub-CBS Code |
Name of Sub-CBS |
Cyber and ICT Risk Linkage |
Impact Tolerance Boundary Tested |
Expected Resilience Outcome |
Evidence to be Collected |
Proactive Risk Management Action |
Evidence of Proactive Risk Management |
|
CO-1.1 |
Digital Wallet Registration and Provisioning |
DDoS attack, API disruption |
Ability to maintain customer onboarding within acceptable service levels |
Customer onboarding continues using resilient infrastructure with minimal disruption. |
Test plans, API monitoring logs, DDoS mitigation reports, onboarding performance metrics |
Strengthen DDoS protection, API redundancy and onboarding scalability |
DDoS testing reports, API resilience testing, capacity assessments |
|
CO-1.2 |
Customer Identity Verification and Account Validation |
Third-party ICT outage |
Maximum acceptable onboarding delay |
Customer verification continues using contingency verification procedures. |
Third-party outage records, KYC processing times, manual verification logs |
Diversify identity verification providers and strengthen contingency arrangements |
Supplier assurance reports, resilience testing results |
|
CO-1.3 |
Wallet Funding and Value Loading |
Banking gateway failure |
Maximum disruption to customer funding capability |
Alternative banking channels restore funding capability before Impact Tolerance is exceeded. |
Banking interface logs, transaction completion rates, failover timing |
Enhance payment routing resilience and banking redundancy |
Banking connectivity testing, failover exercise reports |
|
CO-1.4 |
Wallet Balance Management |
Database corruption, ransomware |
Financial data integrity |
Accurate wallet balances restored without material customer impact. |
Database recovery logs, reconciliation reports, integrity validation results |
Implement immutable backups and continuous integrity monitoring |
Backup restoration reports, integrity testing results |
|
CO-1.5 |
Payment Transaction Processing |
Cyberattack, ransomware, application failure |
End-to-end payment processing continuity |
Critical payment processing remains within approved Impact Tolerance. |
Transaction success rates, recovery times, cyber incident logs |
Improve cyber resilience, active-active processing and automated failover |
Cyber exercise reports, disaster recovery tests, penetration testing |
|
CO-1.6 |
Funds Transfer and Settlement Processing |
Settlement platform outage |
Maximum settlement delay |
Settlement processing resumes without systemic financial disruption. |
Settlement backlog reports, recovery metrics, reconciliation records |
Improve settlement contingency arrangements and liquidity planning |
Settlement testing reports, contingency exercise documentation |
|
CO-1.7 |
Transaction Authorisation and Risk Controls |
Authentication compromise |
Customer authentication availability and fraud prevention effectiveness |
Legitimate customer access maintained while preventing fraudulent transactions. |
Authentication success rates, fraud monitoring reports, SOC logs |
Enhance privileged access management and adaptive authentication |
Identity management reviews, cyber simulation reports |
|
CO-1.8 |
Merchant Payment Enablement |
Capacity exhaustion, API overload |
Merchant transaction availability |
Merchant payment services remain operational despite high transaction volumes. |
Transaction latency reports, API utilisation metrics, merchant availability reports |
Improve capacity planning, auto-scaling and merchant API resilience |
Capacity testing reports, infrastructure monitoring |
|
CO-1.9 |
Digital Wallet Service Integration Management |
API gateway failure, cloud outage |
End-to-end integration continuity |
Critical interfaces recover automatically or fail over with minimal customer impact. |
API performance reports, failover timing, cloud monitoring dashboards |
Strengthen integration resilience and diversify technology concentration |
Cloud resilience assessments, architecture reviews, API failover testing |
|
CO-1.10 |
Customer Transaction Notification and Communication |
Telecommunications disruption |
Timeliness of customer communications |
Customers continue receiving essential notifications through alternative channels. |
Notification delivery reports, customer communication logs |
Implement multi-channel communications and resilient messaging platforms |
Communication resilience testing, third-party service reviews |
|
CO-1.11 |
Transaction Monitoring and Operational Surveillance |
Monitoring platform failure |
Time to detect operational degradation |
Critical incidents remain detectable through redundant monitoring capabilities. |
SOC dashboards, incident detection timelines, monitoring logs |
Implement redundant monitoring infrastructure and independent alerting |
Monitoring resilience tests, SOC exercise reports |
|
CO-1.12 |
Exception Handling and Transaction Resolution |
Operational overload |
Customer dispute resolution within acceptable timeframes |
High transaction exception volumes managed without exceeding customer service thresholds. |
Case resolution statistics, operational dashboards, customer service reports |
Improve automation, surge staffing and workflow prioritisation |
Operational readiness reviews, workflow testing results |
|
CO-1.13 |
Financial Reconciliation and Operational Reporting |
Data corruption |
Financial reporting integrity |
Accurate reconciliation completed within regulatory reporting timelines. |
Reconciliation reports, audit trails, reporting validation |
Strengthen automated reconciliation and integrity controls |
Financial control testing, audit reports |
|
CO-1.14 |
Operational Incident Management |
Cyberattack and communication failure |
Executive response and crisis coordination effectiveness |
Effective governance, rapid escalation and coordinated decision-making maintained throughout the incident. |
Crisis decision logs, executive briefings, incident timelines |
Strengthen crisis governance, communication resilience and executive exercises |
Crisis management exercise reports, governance reviews |
|
CO-1.15 |
Service Recovery and Operational Restoration |
Disaster Recovery failure, regional infrastructure outage |
Overall Impact Tolerance for CO-1 Digital Wallet Operations |
Full restoration achieved within approved Impact Tolerance using resilient recovery arrangements. |
Disaster recovery results, service restoration timelines, customer impact assessments |
Enhance recovery architecture, recovery automation and resilience governance |
Disaster recovery exercises, independent assurance reports, recovery capability assessments |
Regulatory Considerations for Scenario Testing by a Philippine Banking Financial Services Institution (BFSI)
For a Philippine BFSI such as GCash, BSP Circular No. 1203 (Series of 2024) establishes the expectation that Operational Resilience arrangements should include the identification of Critical Operations, the establishment of Impact Tolerances, the mapping of important interconnections and interdependencies, and the use of Severe but Plausible Scenarios to validate resilience capabilities.
The Circular emphasises that scenario testing should provide management with assurance regarding the institution's ability to continue delivering Critical Operations during significant disruption while identifying vulnerabilities requiring remediation.
From an implementation perspective, GCash should design a structured Scenario Testing programme that:
- Tests the end-to-end delivery of Digital Wallet Operations rather than individual systems or business units.
- Incorporates operational, cyber, ICT, third-party, and crisis management scenarios that reflect realistic threats.
- Defines measurable Impact Tolerance thresholds and success criteria before each exercise.
- Involves cross-functional participation from business operations, technology, cybersecurity, risk management, business continuity, crisis management, compliance, internal audit, and critical external service providers where appropriate.
- Collects comprehensive evidence, including decision logs, recovery metrics, customer impact assessments, system performance data, and lessons identified.
- Uses post-exercise findings to update resilience strategies, technology architecture, business continuity plans, cyber response procedures, governance arrangements, and future investment priorities.
Scenario Testing provides the practical mechanism through which GCash can validate the resilience of CO-1 Digital Wallet Operations under realistic and demanding operating conditions. By using Severe but Plausible Scenarios as the foundation for testing, the organisation moves beyond verifying individual recovery plans to assessing whether the entire Critical Operation can continue delivering services within its defined Impact Tolerance.
Testing each Sub-Critical Business Service while simultaneously challenging the interconnections between people, processes, technology, information, facilities, and third-party providers provides a comprehensive understanding of end-to-end operational resilience.
The integration of Cyber and ICT Risks throughout the testing programme further reflects the dependence of Digital Wallet Operations on digital infrastructure, cloud services, payment networks, telecommunications, and external ecosystem partners.
The evidence collected from Scenario Testing—including recovery performance metrics, cyber event logs, decision records, customer impact assessments, and after-action reviews—provides management and the Board with demonstrable assurance that resilience capabilities are functioning as intended or highlights where improvements are required.
These findings should be translated into targeted remediation actions, governance enhancements, technology investments, updated response procedures, and continuous improvement initiatives, ensuring that GCash's Operational Resilience programme remains effective, adaptive, and aligned with evolving business risks and regulatory expectations.
| eBook 3: Starting Your OR Implementation |
||||
| CBS-1 Insurance Policy Application and Issuance | ||||
| CBS-1 DP | CBS-1 MII | CBS-1 ITo | CBS-1 SbPS | CBS-1 ST |
![]() |
![]() |
![]() |
![]() |
![]() |
Gain Competency: For organisations looking to accelerate their journey, BCM Institute’s training and certification programs, including the OR-5000 Operational Resilience Expert Implementer course, provide in-depth insights and practical toolkits for effectively embedding this model.

![BB OR [B] 13 BB OR [B] 13](https://blog.bcm-institute.org/hs-fs/hubfs/OR%20picture/OR%20Pictures%20A/BB%20OR%20Folder%20B/BB%20OR%20%5BB%5D%2013.jpg?width=2000&height=1333&name=BB%20OR%20%5BB%5D%2013.jpg)
![[OR] [GCash] [Full Banner] Strengthening Operational Resilience at GCash](https://no-cache.hubspot.com/cta/default/3893111/3a39ca09-f7ed-4e75-858f-941c41224c31.png)
![[OR] [GCash] [Disclaimer] Legal Disclaimers and Usage of eBook Banner](https://no-cache.hubspot.com/cta/default/3893111/454a0c6c-3084-45f4-b724-65b4ca4eb6d1.png)

![[OR] [GCash] [PH] [E3] [CO] [1] [ST] Digital Wallet Operations](https://no-cache.hubspot.com/cta/default/3893111/482a8d4c-a87b-4de2-9825-0982a35464d4.png)
![Banner [Table] [OR] [E3] Perform Scenario Testing](https://no-cache.hubspot.com/cta/default/3893111/a45e9708-7139-4f4e-8e0e-41179f5cacc3.png)
![Banner [Summing] [OR] [E3] Perform Scenario Testing](https://no-cache.hubspot.com/cta/default/3893111/11895c06-91e9-4cec-acb6-4356741952e4.png)
![[OR] [GCash] [3/4 Banner] Strengthening Operational Resilience at GCash](https://no-cache.hubspot.com/cta/default/3893111/f32c765b-c3ba-4ed6-bd15-6dc928547f19.png)
![[OR] [GCash] [PH] [E3] [CO] [1] [DP] Digital Wallet Operations](https://no-cache.hubspot.com/cta/default/3893111/62adb964-d08b-4996-9d00-dca98439cdd7.png)
![[OR] [GCash] [PH] [E3] [CO] [1] [MD] Digital Wallet Operations](https://no-cache.hubspot.com/cta/default/3893111/4cab1d04-4396-4674-8d6e-547dcef28e10.png)
![[OR] [GCash] [PH] [E3] [CO] [1] [ITo] Digital Wallet Operations](https://no-cache.hubspot.com/cta/default/3893111/c463e973-5d22-4fdc-b88c-8837e49be150.png)








![[BL-OR] [3-4-5] View Schedule](https://no-cache.hubspot.com/cta/default/3893111/d0d733a1-16c0-4b68-a26d-adbfd4fc6069.png)
![[BL-OR] [3] FAQ OR-300](https://no-cache.hubspot.com/cta/default/3893111/f20c71b4-f5e8-4aa5-8056-c374ca33a091.png)
![Email to Sales Team [BCM Institute]](https://no-cache.hubspot.com/cta/default/3893111/3c53daeb-2836-4843-b0e0-645baee2ab9e.png)








