Digitalisation, interconnected financial infrastructure, reliance on third-party service providers, cyber threats, technology concentration, changing customer expectations, and increasingly complex operating models mean that disruptions can propagate rapidly across an organisation and potentially the wider financial system.
For a financial institution such as MBSB Bank Berhad (MBSB Bank), operational resilience is therefore broader than maintaining conventional business continuity arrangements.
It requires the organisation to understand which services are most important, how those services are delivered, the resources and dependencies that support them, how much disruption it can tolerate, and whether it can continue delivering those services during severe but plausible disruptions.
MBSB Bank is a full-fledged Islamic banking institution regulated by Bank Negara Malaysia (BNM). Its banking activities serve retail, SME and corporate customers through physical and increasingly digital delivery channels.
This combination of banking operations, digital channels, payment infrastructure, customer-facing services, technology platforms and external dependencies provides an appropriate setting for examining Operational Resilience (OR) in practice.
BNM has emphasised robust operational risk management, resilient technology and cyber capabilities, governance and accountability, and the ability of financial institutions to withstand disruption while continuing to deliver financial services.
This case study applies these principles to MBSB as a practical example. It does not represent MBSB's actual internal Operational Resilience framework unless information is publicly available.
Where internal arrangements are not publicly known, reasonable assumptions are made based on banking industry practices and BNM's emerging expectations.
The purpose of this chapter is to establish the organisational context required before developing an Operational Resilience programme for MBSB.
Operational resilience should not begin with technology solutions, recovery plans or scenario exercises. It should begin with an understanding of the organisation and the outcomes that need to be protected.
For MBSB, this means answering several fundamental questions:
These questions create the foundation for the later stages of the Operational Resilience Planning Methodology.
The chapter therefore establishes an initial organisational profile, operating environment, proposed OR team structure, preliminary view of Critical Business Services (CBSs), organisational characteristics and Operational Resilience goals.
Understanding the organisation is one of the most important prerequisites for Operational Resilience.
A financial institution cannot determine what must remain resilient without first understanding what it delivers, who depends upon those services and what consequences could arise if those services become unavailable.
MBSB Bank operates as an Islamic banking institution in Malaysia and provides Shariah-compliant financial solutions to retail, SME and corporate customers. Its operating model combines conventional customer touchpoints with digital banking and payment capabilities.
Examples of customer-facing capabilities include individual and corporate online banking, fund transfers, DuitNow, JomPAY, financing payments, foreign fund transfers, account enquiries and other transactional services. Corporate banking capabilities also connect customers with payment mechanisms, including RENTAS and SWIFT.
From an Operational Resilience perspective, this means that MBSB should not be viewed simply as a collection of departments or systems.
It should be viewed as a network of services.
For example:
A disruption at any point in this chain may affect the customer's ability to complete the required banking activity.
This service-oriented perspective is fundamental to Operational Resilience.
MBSB operates within a highly regulated financial services environment where the availability, integrity and security of banking services can directly affect customers, businesses and confidence in the financial system.
The primary regulator considered for this case study is Bank Negara Malaysia.
represents an important development in Malaysia's approach to Operational Resilience. It considers lessons from operational disruptions, international developments, existing Malaysian regulatory requirements and the governance and accountability arrangements needed to strengthen resilience across financial institutions.
BNM's subsequent assessment of operational risk developments has highlighted practical resilience concerns, including:
These considerations provide useful reference points for the MBSB case study.
Banking has become increasingly dependent upon technology.
MBSB provides digital banking capabilities for individual and corporate customers. Its corporate services include payment and transfer capabilities such as DuitNow, IBG, RENTAS and SWIFT, while its retail services similarly depend on electronic channels and interconnected financial infrastructure.
This creates a resilience challenge.
A customer may perceive a service as simple—for example, transferring money—but delivery may depend on:
Consequently, resilience cannot be assessed only at the application or departmental level.
Modern banks rely upon external organisations for technology, telecommunications, cloud services, payment processing, software, security, facilities and specialist services.
The failure of a third party can therefore become an operational disruption for MBSB even where MBSB's own infrastructure remains operational.
An effective OR programme should consequently extend dependency analysis beyond the organisational boundary.
Cyber incidents represent another important operating consideration.
Ransomware, distributed denial-of-service attacks, credential compromise, data breaches, malicious insiders and attacks against service providers can affect the confidentiality, integrity or availability of banking services.
Operational Resilience therefore, asks a different question from cybersecurity alone:
If a successful cyberattack occurs despite preventive controls, can MBSB continue delivering its most important services within acceptable limits?
That distinction is important. Operational Resilience assumes that not every disruption can be prevented.
Operational Resilience should not be owned exclusively by Business Continuity Management, Operational Risk or Technology.
It is inherently cross-functional.
For this case study, MBSB should establish an Operational Resilience Steering Committee, supported by an Operational Resilience Working Team.
|
Function |
Primary OR Responsibility |
|
Senior Management Sponsor |
Executive sponsorship and strategic direction |
|
Operational Risk |
Risk framework integration and challenge |
|
Business Continuity Management |
Continuity and recovery capability |
|
Technology / IT |
Technology resilience and recovery |
|
Cybersecurity |
Cyber resilience and incident preparedness |
|
Business Service Owners |
Accountability for CBS resilience |
|
Operations |
Process and operational dependency analysis |
|
Enterprise Risk Management |
Integration with enterprise risks |
|
Third-Party / Vendor Management |
External dependency resilience |
|
Compliance |
Regulatory alignment |
|
Shariah-related governance functions |
Consider relevant Shariah governance implications |
|
Legal |
Legal and contractual considerations |
|
Customer Service |
Customer impact and disruption management |
|
Corporate Communications |
Internal and external crisis communications |
|
Human Resources |
Workforce resilience and competency |
|
Facilities / Security |
Workplace and physical resilience |
|
Data Management |
Data availability, integrity and recovery |
The purpose of this structure is not to create another isolated resilience function.
Its purpose is to connect existing capabilities around the delivery of critical services.
This reflects the direction highlighted by BNM, particularly the importance of governance, accountability and coordinated resilience across increasingly complex dependencies.
Traditional BCM programmes frequently begin with departments, processes or applications.
Operational Resilience begins with the outcome delivered to the customer or another important stakeholder.
The IT Department is a function.
Core Banking System is a technology resource.
DuitNow is a payment mechanism.
But:
Enabling customers to access and transfer funds may represent a customer-facing business service.
This distinction becomes important when identifying MBSB's Critical Business Services.
The following represents an initial case-study view rather than MBSB's formally approved CBS inventory.
|
Potential Critical Business Service |
Why It May Be Important |
|
Access to customer deposits and accounts |
Customers depend upon access to their funds and account information |
|
Domestic funds transfer |
Customers and businesses depend upon the timely movement of funds |
|
Digital banking services |
Significant customer transactions increasingly depend upon digital access |
|
Cash withdrawal and deposit services |
Provides customers with access to and placement of physical cash |
|
Financing, servicing and repayment |
Supports customers' ongoing financing obligations |
|
Corporate payment services |
Businesses depend upon payment, payroll and treasury transactions |
|
Interbank and high-value payment services |
Supports transactions involving other financial institutions and financial infrastructure |
|
Customer authentication and transaction authorisation |
Enables secure access to multiple customer-facing services |
MBSB's actual CBS determination would require a formal assessment.
Relevant criteria could include:
How many customers could be affected?
Could customers lose access to funds or suffer significant financial loss?
How quickly would disruption become unacceptable?
Could disruption affect other institutions or financial infrastructure?
Would prolonged disruption interfere with regulatory obligations?
Could disruption materially reduce customer confidence?
Could disruption propagate beyond MBSB?
This approach is consistent with the broader emphasis in BNM's Operational Resilience direction on maintaining the continued delivery of important financial services during disruption.
Several organisational characteristics should influence the design of MBSB's Operational Resilience programme.
MBSB Bank operates as an Islamic banking institution.
Resilience arrangements, therefore, need to recognise both conventional banking operational requirements and relevant Shariah governance considerations.
MBSB serves retail, SME and corporate customers.
Different customer groups may experience disruption differently.
For example, temporary unavailability of corporate payment services could affect payroll or supplier payments, while retail banking disruption could prevent individuals from accessing funds.
Digital banking increases convenience but also concentrates dependency upon technology, telecommunications, cybersecurity and data.
Digital resilience, therefore, becomes inseparable from Operational Resilience.
Services involving DuitNow, IBG, RENTAS, SWIFT and other payment mechanisms illustrate the interconnected nature of banking operations.
Resilience consequently depends not only upon MBSB but upon external financial infrastructure and participating institutions.
Customers may interact with the bank through branches, digital banking, self-service banking and other channels. MBSB's self-service facilities, for example, support withdrawals, deposits, balance enquiries, financing payments, bill payments and transfers.
Channel diversity can improve resilience where genuine alternatives exist, but only when the alternative channel does not depend upon the same underlying point of failure.
As a regulated financial institution, MBSB must align resilience capabilities with BNM's evolving expectations and related requirements concerning BCM, technology risk, operational risk and financial services.
Operational Resilience should therefore complement existing regulatory programmes rather than create an entirely separate control environment.
An Operational Resilience programme requires clearly defined organisational goals.
The goal should not simply be:
That is neither realistic nor consistent with the fundamental concept of Operational Resilience.
The objective is to ensure that the organisation can anticipate, withstand, respond to, recover from and learn from disruption while protecting the continued delivery of its most important services.
For this case study, MBSB could establish the following overarching goal:
This can be translated into eight supporting objectives.
Establish a consistent methodology for identifying the services whose disruption could create unacceptable consequences.
Map the people, processes, technology, information, facilities, and third parties supporting each CBS.
Determine the maximum level of disruption that MBSB is prepared to tolerate for each CBS before the consequences become unacceptable.
Use service mapping and risk analysis to identify:
Conduct severe but plausible scenarios that challenge the end-to-end delivery of CBSs.
Examples could include:
Scenario A — Major Cyberattack
Ransomware compromises critical technology supporting digital banking.
Scenario B — Core Banking Failure
A technology failure prevents customers from accessing accounts and completing transactions.
Scenario C — Payment Infrastructure Disruption
Connectivity with an important payment infrastructure becomes unavailable.
Scenario D — Critical Third-Party Failure
A major service provider suffers an extended outage.
Scenario E — Telecommunications Failure
Connectivity affecting branches, customer channels or data centres is disrupted.
Scenario F — Major Data Integrity Incident
Transaction or account information becomes unavailable or unreliable.
These examples also reflect concerns identified in BNM's observations concerning cyber threats, critical IT failures, power outages, third-party dependencies and single points of failure. (Bank Negara Malaysia)
Assign clear accountability for the resilience of Critical Business Services and establish appropriate escalation and reporting mechanisms.
Operational Resilience should integrate rather than replace:
The common point of integration should be the Critical Business Service.
Lessons from incidents, exercises, near misses, risk assessments and regulatory reviews should be converted into measurable resilience improvements.
Before proceeding with detailed analysis, several working assumptions are useful for this case study.
These assumptions will be validated or refined as the Operational Resilience programme progresses.
|
Assumption |
OR Implication |
|
Digital banking will continue to increase in importance |
Technology and cyber resilience become critical |
|
Customers increasingly expect continuous access to banking services |
Service availability expectations will remain high |
|
MBSB depends upon external service providers |
Third-party resilience must form part of CBS assessment |
|
Critical services depend upon interconnected systems |
End-to-end mapping is necessary |
|
Not all disruptions can be prevented |
Recovery and adaptation capabilities must be developed |
|
Some disruptions may affect several services simultaneously |
Scenario testing should consider correlated failures |
|
Customer impact increases with disruption duration |
Impact tolerance should incorporate time |
|
Alternative channels may share common infrastructure |
Substitution arrangements must be validated rather than assumed |
|
Regulatory expectations will continue to develop |
The OR framework should be adaptable |
These assumptions encourage MBSB to move from a recovery-centric mindset toward a service-resilience mindset.
MBSB would not be starting its resilience journey from zero.
Like other regulated Malaysian financial institutions, existing capabilities in areas such as BCM, technology risk, cybersecurity, incident management and operational risk provide important foundations.
Operational Resilience builds upon these capabilities.
A useful distinction is:
This shifts attention from organisational components to service outcomes.
Consider a hypothetical MBSB digital banking disruption.
Recovering the application server within the documented Recovery Time Objective would not necessarily demonstrate resilience if customers remained unable to transact because authentication, telecommunications, or an external payment connection remained unavailable.
Operational Resilience, therefore, requires an end-to-end perspective.
This is particularly relevant given BNM's observations concerning dependency complexity and single points of failure affecting channels such as online banking, ATMs and call centres.
The initial foundation established in this chapter can be summarised as follows:
|
Foundation Element |
MBSB Case Study Position |
|
Organisation |
MBSB Bank Berhad |
|
Sector |
Financial Services / Islamic Banking |
|
Jurisdiction |
Malaysia |
|
Primary Regulator |
Bank Negara Malaysia |
|
Primary Stakeholders |
Retail, SME and corporate customers |
|
Resilience Focus |
Continued delivery of Critical Business Services |
|
Primary Drivers |
Customer protection, regulatory expectations, digital dependency and financial-system confidence |
|
Governance |
Board and Senior Management oversight with cross-functional OR governance |
|
Core OR Unit of Analysis |
Critical Business Service |
|
Primary Dependencies |
People, process, technology, information, facilities and third parties |
|
Key Threat Areas |
Cyberattack, technology failure, third-party disruption, payment-system disruption, telecommunications failure and operational failure |
|
Existing Capabilities to Integrate |
BCM, Operational Risk, Technology Risk, Cybersecurity, Crisis Management, Incident Management and Third-Party Risk |
|
Desired Outcome |
Critical services remain within defined impact tolerances during severe but plausible disruptions |
This chapter has established the organisational foundation for the MBSB Operational Resilience case study.
MBSB operates within an increasingly digital and interconnected Malaysian financial services environment.
Its ability to provide banking services depends upon combinations of people, processes, technology, data, facilities, payment infrastructure and third-party organisations.
This complexity means that resilience cannot be achieved by managing individual risks or recovery plans independently.
The focus must move toward the continued delivery of Critical Business Services.
The 2025 BNM Discussion Paper reinforces this direction by positioning Operational Resilience around the ability of financial institutions to withstand disruption, supported by strong operational risk management, technology and cyber resilience, governance and accountability.
BNM's subsequent observations also highlight practical priorities such as recovery capability, single points of failure and joint testing with critical third-party service providers.
For MBSB, this chapter establishes four important foundations:
First, Operational Resilience should be governed as an enterprise-wide responsibility rather than as an isolated BCM or technology initiative.
Second, MBSB should identify its Critical Business Services from the perspective of outcomes delivered to customers and other stakeholders.
Third, resilience should be assessed across the entire service delivery chain, including internal and external dependencies.
Fourth, the objective is not to eliminate every disruption. The objective is to ensure that disruption does not exceed the organisation's ability to continue delivering its most important services within acceptable limits.
With the organisational context established, the next step is to examine MBSB's operating environment in greater depth—including its internal and external context, stakeholder expectations, regulatory drivers, technology dependencies, third-party ecosystem and the disruption landscape that could affect the delivery of its Critical Business Services.
This understanding will provide the basis for developing a structured and organisation-specific Operational Resilience programme for MBSB.
| eBook 1: Understanding Your Organisation: MBSB Bank | |||
| C1 | C2 | C3 | C4 |
| C5 | C6 | C7 | C8 |
For organisations looking to accelerate their journey, BCM Institute’s training and certification programs, including the OR-5000 Operational Resilience Expert Implementer course, provide in-depth insights and practical toolkits for effectively embedding this model.
To learn more about the course and schedule, click the buttons below for the OR-300 Operational Resilience Implementer course and the OR-5000 Operational Resilience Expert Implementer course.
|
If you have any questions, click to contact us. |
||
|
|