.

Operational Resilience in Action: The MBSB Approach
BB OR [C] 4

[OR] [MBSB] [E1] [C4] Composing the OR Team

[OR] [MBSB] [Full Banner] Operational Resilience in Action The MBSB Bank's Approach

Operational Resilience cannot be implemented effectively by a single department.

For MBSB Bank (MBSB), the ability to continue delivering Critical Business Services during disruption depends upon coordinated decisions across business operations, risk management, technology, cybersecurity, Business Continuity Management (BCM), third-party management, customer service, crisis management and other supporting functions.

This cross-functional requirement is reinforced by Bank Negara Malaysia's (BNM) 2025 Discussion Paper on Operational Resilience.

BNM states that Operational Resilience spans technology, risk management, operations, business, outsourcing and cybersecurity, and warns that siloed working arrangements can create organisational blind spots and weaken integrated oversight.

BNM also identifies strong Board oversight and timely decision-making within a cross-functional and integrated structure as an important differentiator between financial institutions that withstand disruption and those that struggle.

For MBSB, composing the Operational Resilience team is therefore not simply an administrative exercise.

It is a governance decision that determines who owns resilience outcomes, who coordinates the programme, who provides specialist expertise, who challenges decisions and who is accountable when weaknesses are identified.

New call-to-action

Moh Heng Goh
Operational Resilience Certified Planner-Specialist-Expert

x [OR] [MBSB] Legal Disclaimer Banner

Chapter 4

New call-to-action

Composing the Operational Resilience Team for MBSB Bank

Introduction

[OR] [MBSB] [E1] [C4] Composing the OR Team

Operational Resilience cannot be implemented effectively by a single department. For MBSB Bank (MBSB), the ability to continue delivering Critical Business Services during disruption depends upon coordinated decisions across business operations, risk management, technology, cybersecurity, Business Continuity Management (BCM), third-party management, customer service, crisis management and other supporting functions.

This cross-functional requirement is reinforced by Bank Negara Malaysia's (BNM) 2025 Discussion Paper on Operational Resilience. BNM states that Operational Resilience spans technology, risk management, operations, business, outsourcing and cybersecurity, and warns that siloed working arrangements can create organisational blind spots and weaken integrated oversight.

BNM also identifies strong Board oversight and timely decision-making within a cross-functional and integrated structure as an important differentiator between financial institutions that withstand disruption and those that struggle.

For MBSB, composing the Operational Resilience team is therefore not simply an administrative exercise. It is a governance decision that determines who owns resilience outcomes, who coordinates the programme, who provides specialist expertise, who challenges decisions and who is accountable when weaknesses are identified.

 

New call-to-action

The purpose of this chapter is to establish a practical Operational Resilience governance and team structure for MBSB Bank.

The rationale for developing this structure early is that Operational Resilience cuts across organisational boundaries and cannot be delivered effectively if ownership remains fragmented among BCM, Operational Risk, Technology, Cybersecurity and individual business units.

BNM's emerging direction places Operational Resilience at the Board level and expects clear accountability, integrated decision-making and cross-functional coordination.

It also identifies Board responsibilities such as approving critical operations and/or services, setting impact tolerances, reviewing resilience-testing outcomes and holding Senior Management accountable for resilience outcomes.

By the end of this chapter, the reader should understand the proposed governance hierarchy for MBSB, the responsibilities of the Board, Senior Management, an Operational Resilience Steering Committee, an Operational Resilience programme function, Critical Business Service Owners and supporting specialists.

The reader should also understand how MBSB can apply the Three Lines Model so that ownership, oversight, challenge and assurance remain distinct while still supporting a common resilience objective.

The intended outcome is a structure capable of making Operational Resilience an enterprise-wide capability rather than another standalone risk-management programme.

 

Why MBSB Needs a Cross-Functional Operational Resilience Team

A Critical Business Service may depend upon multiple organisational functions simultaneously.

Consider CBS-2: Domestic Funds Transfer and Payment Services.

Its delivery could require:

Business Operations

Digital Banking

Authentication

Core Banking

Payment Processing

Cybersecurity Controls

Telecommunications

External Payment Infrastructure

Customer Support

 

No single function owns every component.

Consequently, assigning Operational Resilience solely to BCM would be insufficient. Assigning it solely to Technology would be equally problematic. Operational Risk may provide governance and challenge, but it does not directly operate the services.

MBSB therefore requires a governance structure in which:

  • The Board provides oversight and challenge;
  • Senior Management owns Operational Resilience outcomes;
  • a designated senior executive provides central accountability;
  • Critical Business Service Owners remain accountable for the resilience of their services;
  • specialist functions contribute resilience capabilities;
  • Risk provides independent oversight and challenge; and
  • Internal Audit provides independent assurance.

This allows Operational Resilience to become an integrated management capability.

 

BNM's Governance Direction for Operational Resilience

BNM dedicates a specific section of its 2025 Discussion Paper to governance and accountability structures for Operational Resilience.

BNM states that Operational Resilience should be treated as a Board-level priority because disruptions can cause intolerable customer harm and threaten financial stability. The Board's role includes approving critical operations or services, setting impact tolerances, reviewing resilience testing and holding Senior Management accountable.

BNM further states that the cross-functional nature of Operational Resilience requires a holistic approach across areas such as:

  • technology;
  • risk management;
  • operations;
  • business;
  • outsourcing; and
  • cybersecurity.

Of particular importance for MBSB is BNM's reference to the Responsibility Mapping policy document. According to the Discussion Paper, the policy requires financial institutions to designate a member of Senior Management with a direct reporting line to the Chief Executive Officer as responsible for implementing the Operational Resilience framework.

BNM expects one person to be ultimately accountable for Operational Resilience outcomes, while other members of Senior Management retain responsibility for resilience within their respective domains.

Examples specifically cited by BNM include:

  • CTO for technology resilience;
  • CISO for cyber resilience;
  • COO for process resilience;
  • CRO for risk appetite; and
  • heads of business units for critical services.

These principles provide the basis for the proposed MBSB governance structure in this chapter.

 

Proposed Operational Resilience Governance Structure for MBSB

A practical structure for MBSB can be represented as follows:

 

Board of Directors / Board Risk Committee

Chief Executive Officer and Senior Management / Management Risk Committee

Senior Executive Accountable for Operational Resilience

Operational Resilience Steering Committee

Operational Resilience Programme Office / Coordination Function

Critical Business Service Owners

Supporting Resource and Functional Owners

Operational Resilience Working Groups

 

This structure establishes both vertical accountability and horizontal coordination.

Vertical accountability ensures that material Operational Resilience matters can be escalated from service level to Senior Management and ultimately to the Board.

Horizontal coordination ensures that business, technology, risk, cybersecurity, BCM, third-party management and other functions work together around the resilience of the same Critical Business Services.

 

Board of Directors / Board Risk Committee

The Board should provide the highest level of governance for MBSB's Operational Resilience programme.

BNM expects Boards to play a direct role in overseeing resilience, including approving critical operations or services, impact tolerances and resilience-testing outcomes. Boards are also expected to challenge Senior Management and integrate resilience considerations into strategy and resource allocation.

For MBSB, the Board or an appropriately mandated Board Risk Committee should therefore:

  • approve the Operational Resilience policy and framework;
  • approve the overall Operational Resilience strategy;
  • approve the Critical Business Service inventory;
  • approve or endorse Impact Tolerances;
  • review material scenario-testing results;
  • challenge significant vulnerabilities and remediation delays;
  • consider Operational Resilience when approving major transformation programmes;
  • consider resilience implications of critical outsourcing arrangements;
  • review significant operational incidents and lessons learned;
  • monitor the overall resilience posture; and
  • hold Senior Management accountable for agreed resilience outcomes.

The Board should not manage day-to-day Operational Resilience activities.

Its role is oversight, challenge and accountability.

 

Chief Executive Officer and Senior Management

Senior Management translates Board expectations into organisational action.

The CEO should ensure that Operational Resilience receives sufficient authority, resources and organisational priority.

For MBSB, Senior Management responsibilities should include:

  • implementing the Board-approved Operational Resilience strategy;
  • determining programme priorities;
  • resolving cross-functional conflicts;
  • approving significant resilience investments;
  • ensuring resilience considerations are incorporated into strategic decisions;
  • monitoring material vulnerabilities;
  • ensuring remediation actions are completed;
  • reviewing service-level resilience performance; and
  • escalating significant resilience matters to the Board.

BNM identifies centralised accountability as important because it supports stronger cross-functional coordination, integration of resilience into strategic and outsourcing decisions, effective management of trade-offs, timely remediation, structured reporting and more effective crisis management.

 

Senior Executive Accountable for Operational Resilience

MBSB should designate a single member of Senior Management as ultimately accountable for Operational Resilience outcomes.

This individual should have sufficient authority, organisational standing and direct access to the CEO.

The precise title does not need to be prescribed solely for Operational Resilience. Depending upon MBSB's organisational design, accountability could potentially sit with an existing senior executive whose responsibilities enable enterprise-wide coordination.

BNM explicitly avoids prescribing a single organisational configuration and instead focuses on roles, responsibilities and decision-making effectiveness. Its Discussion Paper notes that governance-related requirements are deliberately more principle-based because structural arrangements should reflect the institution's circumstances.

The designated accountable executive should therefore:

  • oversee implementation of MBSB's Operational Resilience framework;
  • chair or sponsor the Operational Resilience Steering Committee;
  • ensure CBS ownership is assigned;
  • coordinate resilience responsibilities across Senior Management;
  • escalate significant vulnerabilities;
  • ensure unresolved resilience issues receive management attention;
  • arbitrate competing priorities;
  • ensure resilience considerations influence strategic investment;
  • provide consolidated reporting to the CEO and Board; and
  • remain ultimately accountable for implementation effectiveness.

However, central accountability must not remove responsibility from other executives.

Operational Resilience remains a shared Senior Management responsibility.

 

Operational Resilience Steering Committee

MBSB should establish an Operational Resilience Steering Committee (ORSC) as the principal cross-functional management forum for the Operational Resilience programme.

Its purpose should be to coordinate decisions that cannot be managed effectively by individual departments.

Proposed Membership

The ORSC could include representatives such as:

 

Proposed Member

Primary Contribution

Senior Executive Accountable for OR

Chairmanship and overall accountability

Chief Operating Officer / Operations Representative

Process and operational resilience

Chief Risk Officer / Operational Risk

Risk oversight, appetite and challenge

Chief Technology Officer / CIO

Technology resilience

Chief Information Security Officer

Cyber resilience

Head of Business Continuity Management

Continuity and recovery integration

Business / CBS Owners

Service-level accountability

Third-Party / Outsourcing Risk

External dependency resilience

Customer Service

Customer impact and disruption management

Compliance

Regulatory alignment

Data Management

Data availability, integrity and recovery

Crisis Management

Disruption command and escalation

Corporate Communications

Customer and stakeholder communications

Facilities / Physical Security

Site and physical resilience

Finance

Investment and financial impact considerations

Legal

Contractual and legal considerations

 

Membership should remain sufficiently senior that decisions can be made rather than merely discussed.

 

Responsibilities of the Operational Resilience Steering Committee

The ORSC should provide the primary management-level coordination mechanism.

Its responsibilities should include:

Governance
  • maintain the Operational Resilience framework;
  • recommend CBSs for approval;
  • recommend Impact Tolerances;
  • establish resilience standards;
  • monitor policy compliance.
Dependency Management
  • ensure end-to-end service mapping is completed;
  • identify concentrations and common points of failure;
  • review critical third-party dependencies;
  • challenge assumptions regarding alternative arrangements.
Scenario Testing
  • approve severe but plausible scenarios;
  • review scenario-testing outcomes;
  • ensure testing addresses end-to-end service delivery;
  • challenge weaknesses revealed by exercises.
Vulnerability Management
  • maintain visibility of material resilience vulnerabilities;
  • prioritise remediation;
  • escalate overdue actions;
  • assess residual risks.
Investment
  • recommend resilience investments;
  • challenge trade-offs between cost and resilience;
  • ensure resources are directed toward material vulnerabilities.
Reporting
  • maintain resilience Key Risk Indicators and Key Performance Indicators;
  • provide consolidated reporting to Senior Management;
  • escalate significant breaches of Impact Tolerance;
  • track progress against the resilience roadmap.

 

Operational Resilience Programme Office / Coordination Function

Although Operational Resilience should be enterprise-wide, MBSB should have a small central function responsible for coordinating the programme.

This may be a dedicated Operational Resilience team or an appropriately structured function within an existing organisational area.

The role should be to coordinate rather than own every resilience activity.

Its responsibilities could include:

  • maintaining the OR methodology;
  • coordinating CBS identification;
  • maintaining the CBS register;
  • facilitating dependency mapping;
  • coordinating Impact Tolerance assessments;
  • developing scenario-testing standards;
  • maintaining the resilience-testing calendar;
  • tracking vulnerabilities and remediation;
  • producing management dashboards;
  • facilitating OR Steering Committee meetings;
  • coordinating awareness and training;
  • supporting periodic self-assessments; and
  • maintaining documentation and regulatory evidence.

The central OR function should not become the owner of each CBS.

That accountability should remain with the respective business service owner.

 

Critical Business Service Owners

Each Critical Business Service should have a clearly identified CBS Owner.

For MBSB's proposed catalogue, this would include ownership for services such as:

  • CBS-1 Customer Deposit and Account Access Services;
  • CBS-2 Domestic Funds Transfer and Payment Services;
  • CBS-3 Digital Banking Services;
  • CBS-4 Cash Access and Cash Transaction Services;
  • CBS-5 Financing Account Servicing and Repayment Services;
  • CBS-6 Corporate Payment and Bulk Transaction Services;
  • CBS-7 High-Value and Interbank Payment Services;
  • CBS-8 Customer Transaction Authentication and Authorisation Services; and
  • CBS-9 Customer Support and Assistance During Banking Disruptions.

The CBS Owner should be sufficiently senior to influence the business, technology and operational resources supporting the service.

Responsibilities should include:

  • defining the service;
  • understanding customer outcomes;
  • validating the end-to-end dependency map;
  • proposing Impact Tolerances;
  • understanding major vulnerabilities;
  • participating in scenario testing;
  • accepting or escalating identified risks;
  • sponsoring remediation;
  • ensuring service changes are reflected in resilience documentation; and
  • reporting service-level resilience to the ORSC.

This is an important shift from traditional BCM.

The CBS Owner is accountable for the resilience of the service outcome, not merely the recovery of a department.

 

Supporting Resource Owners

Critical Business Services depend on resources owned by different functions.

These supporting resource owners may include:

People

Human Resources, operational management and specialist-team leaders.

Processes

Business operations and process owners.

Technology

Technology application owners, infrastructure owners and architecture teams.

Cybersecurity

Identity, security monitoring, incident response and security engineering.

Information

Data owners, data custodians and information-management teams.

Facilities

Facilities management, physical security and site operations.

Third Parties

Vendor owners, outsourcing management and procurement.

 

The resource owner should understand which CBSs depend upon the resource under their control.

For example, the same authentication platform may support:

  • CBS-2 Domestic Funds Transfer and Payment Services

  • CBS-3 Digital Banking Services

  • CBS-6 Corporate Payment and Bulk Transaction Services

  • CBS-8 Customer Transaction Authentication and Authorisation Services

This visibility allows MBSB to detect concentration risk.

 

Operational Resilience Working Groups

 

Below the ORSC, MBSB should establish temporary or standing Operational Resilience Working Groups to perform detailed implementation activities.

These could include:

CBS Identification Working Group

Supports service definition and criticality assessment.

Mapping Working Group

Develops detailed process, resource, interconnection and dependency maps.

Impact Tolerance Working Group

Develops service-level tolerance proposals and supporting rationale.

Scenario Testing Working Group

Designs and conducts severe but plausible tests.

Third-Party Resilience Working Group

Reviews critical external dependencies and alternative arrangements.

Vulnerability and Remediation Working Group

Tracks corrective actions and investment priorities.

These groups should not create separate governance layers.

They should perform detailed work and report findings to the ORSC.

 

Proposed MBSB Operational Resilience Team Structure

The overall structure can be summarised as follows:

 

Governance Level

Proposed MBSB Structure

Primary Responsibility

Level 1

Board / Board Risk Committee

Oversight, challenge, approval and accountability

Level 2

CEO / Senior Management / Management Risk Committee

Executive ownership, resource allocation and decision-making

Level 3

Senior Executive Accountable for Operational Resilience

Enterprise-wide accountability and coordination

Level 4

Operational Resilience Steering Committee

Cross-functional governance and programme oversight

Level 5

Operational Resilience Programme Function

Methodology, coordination, reporting and programme management

Level 6

Critical Business Service Owners

Accountability for service resilience

Level 7

Resource / Functional Owners

Resilience of supporting people, process, technology, data, facilities and third parties

Level 8

Operational Resilience Working Groups

Detailed analysis, mapping, testing and remediation

This model is deliberately designed around outcomes and accountability rather than organisational hierarchy alone.

 

Integrating the Three Lines Model

MBSB should preserve independence and effective challenge while developing its cross-functional Operational Resilience structure.

A practical Three Lines Model could be applied as follows.

 

Line

MBSB Functions

Operational Resilience Role

First Line

Business units, Operations, Technology, Cybersecurity, service owners and resource owners

Own and manage Operational Resilience risks and controls

Second Line

Operational Risk, Enterprise Risk, Compliance and relevant oversight functions

Establish framework, provide challenge and monitor adherence

Third Line

Internal Audit

Provide independent assurance over framework design and operating effectiveness

The distinction is important.

The cross-functional nature of OR does not mean risk ownership and independent challenge should be blurred.

For example:

Business Service Owner

owns the resilience of the CBS.

Operational Risk

challenges whether resilience risks have been properly assessed.

Internal Audit

independently evaluates whether the governance framework operates effectively.

 

Role of Business Continuity Management

BCM should remain an important part of MBSB's Operational Resilience structure.

BCM brings established capabilities including:

  • Business Impact Analysis;
  • recovery requirements;
  • Business Continuity Plans;
  • alternate arrangements;
  • exercising;
  • incident preparedness;
  • crisis response; and
  • recovery coordination.

However, BCM should not be expected to own Operational Resilience independently.

Operational Resilience expands the focus from:

"Can the affected function recover?"

to:

"Can the Critical Business Service remain within its Impact Tolerance when one or more supporting resources fail?"

BCM therefore becomes one of the essential capabilities supporting CBS resilience.

 

Role of Technology and Cybersecurity

Technology and cybersecurity will have especially important roles within MBSB because many banking services depend upon digital platforms.

BNM notes that technology and third-party risk requirements are comparatively more prescriptive because technology failures and cyber incidents can propagate quickly through the financial ecosystem.

It specifically highlights system availability, security controls, recovery capability and failover arrangements as fundamental to continuity.

Technology representatives should therefore contribute:

  • architecture analysis;
  • application dependencies;
  • infrastructure resilience;
  • capacity management;
  • disaster recovery;
  • failover arrangements;
  • technical debt analysis; and
  • technology concentration assessment.

Cybersecurity should contribute:

  • cyber-risk scenarios;
  • identity and access resilience;
  • ransomware readiness;
  • security monitoring;
  • data-integrity risks;
  • cyber incident response; and
  • recovery from compromised environments.

 

Role of Third-Party and Outsourcing Management

MBSB's OR team should include strong third-party representation because service resilience may depend on providers outside its direct control.

BNM's existing Outsourcing and RMiT requirements already require risk assessment, due diligence, contractual provisions, contingency arrangements and continuous oversight for relevant third-party and technology arrangements.

Within Operational Resilience, MBSB should extend this analysis by asking:

  • Which CBSs depend upon the provider?
  • Is the provider substitutable?
  • How quickly could substitution occur?
  • Does the provider depend upon another critical provider?
  • Are alternative arrangements genuinely independent?
  • Has the provider participated in scenario testing?
  • Can MBSB obtain timely information during a disruption?
  • Would the provider's failure cause several CBSs to fail simultaneously?

These questions should be considered by the ORSC rather than left solely to procurement or vendor management.

 

Role of Crisis Management and Communications

Operational Resilience is not only about maintaining systems.

When disruption occurs, effective decision-making and communication can materially reduce customer harm.

MBSB's Crisis Management and Communications representatives should therefore contribute to:

  • escalation criteria;
  • crisis activation;
  • decision authority;
  • customer communication;
  • regulatory notification;
  • media and stakeholder communication;
  • alternative service instructions;
  • service restoration communication; and
  • post-incident lessons learned.

This becomes particularly important when a service approaches or exceeds its Impact Tolerance.

 

Governance During Business-as-Usual and Crisis Conditions

MBSB's Operational Resilience structure should work in both:

Business-as-Usual

and

Disruption / Crisis Conditions

 

Under business-as-usual conditions, the governance structure should:

  • identify services;
  • map dependencies;
  • review vulnerabilities;
  • establish tolerances;
  • test scenarios;
  • monitor indicators; and
  • improve resilience.

During disruption, the same accountability model should support:

  • rapid escalation;
  • service prioritisation;
  • activation of alternatives;
  • allocation of scarce resources;
  • customer communication;
  • regulatory reporting;
  • decisions about degraded service levels; and
  • restoration priorities.

BNM identifies stronger cross-functional coordination during both business-as-usual and crisis conditions as one of the benefits of centralised accountability.

 

Decision Rights and Escalation

A well-designed OR team is ineffective if decision rights are unclear.

MBSB should therefore define:

  • Who can declare that a CBS is materially disrupted?

  • Who determines that an Impact Tolerance is likely to be breached?

  • Who authorises degraded service operation?

  • Who approves the activation of alternative arrangements?

  • Who decides whether resilience investment is required?

  • Who accepts residual resilience risk?

  • Who escalates unresolved vulnerabilities to the Board?

These authorities should be documented before a disruption occurs.

 

Operational Resilience Reporting

The OR team should develop a consolidated resilience dashboard for Senior Management and the Board.

Illustrative reporting could include:

 

Reporting Area

Examples

CBS Status

Number of approved CBSs and ownership status

Impact Tolerance

Approved tolerance and breaches

Dependency Mapping

Mapping completeness and identifying concentration risks

Scenario Testing

Tests completed, findings and tolerance performance

Vulnerabilities

Open, overdue and high-risk vulnerabilities

Third Parties

Critical provider resilience issues

Technology Resilience

Availability, failover and recovery concerns

Incidents

Material disruptions and near misses

Remediation

Progress against corrective actions

Investment

Major resilience initiatives and funding decisions

Continuous Improvement

Lessons learned from incidents and testing

The purpose of reporting should be to support decision-making, not merely produce additional metrics.

 

Avoiding Common Governance Weaknesses

MBSB should avoid several common implementation weaknesses.

Treating OR as a BCM Project

This limits ownership and may isolate technology, cyber and business leaders.

Treating OR as an IT Resilience Programme

Technology is critical, but service resilience also depends upon people, processes, data, facilities and third parties.

Creating a Committee Without Decision Authority

The ORSC should be capable of making or escalating substantive decisions.

Assigning CBS Ownership Too Low in the Organisation

CBS owners should have sufficient authority to influence resources and remediation.

Allowing Second-Line Functions to Own First-Line Risks

Risk functions should challenge rather than replace business accountability.

Overlooking Third Parties

External providers may represent some of the most important service dependencies.

Focusing Only on Governance Meetings

Operational Resilience must ultimately improve service capability, not merely produce governance documentation.

 

Regulatory Alignment for MBSB

The proposed structure aligns with several themes identified by BNM.

 

BNM Direction

Proposed MBSB Response

Operational Resilience as Board-level priority

Board / Board Risk Committee oversight

Single Senior Management accountability

Designated accountable senior executive

Shared responsibility across Senior Management

COO, CTO/CIO, CISO, CRO and business leadership responsibilities

Cross-functional integration

Operational Resilience Steering Committee

Critical-service ownership

Designated CBS Owners

Dependency visibility

Resource owners and mapping working groups

Timely remediation

ORSC vulnerability tracking and escalation

Structured reporting

Consolidated Operational Resilience dashboard

Effective crisis management

Integration with Crisis Management and Communications

Continuous learning

Formal lessons-learned and remediation process

 

BNM's Discussion Paper also makes clear that the regulatory direction is not intended to replace existing frameworks.

Rather, Operational Resilience provides a more coherent, outcome-oriented way of connecting existing BCM, technology governance, third-party management, Operational Risk and governance requirements.

 

From Team Composition to Critical Business Services

Once MBSB has established the governance and team structure, it can proceed with greater clarity into the implementation work.

The sequence becomes:

Board and Senior Management Oversight

Appoint Accountable Senior Executive

Establish OR Steering Committee

Assign OR Coordination Function

Identify Critical Business Services

Assign CBS Owners

Map Supporting Resources

Set Impact Tolerances

Conduct Scenario Testing

Remediate and Continuously Improve

 

The composition of the team therefore directly influences the quality of every subsequent Operational Resilience activity.

 

Banner [Summing] [OR] [E1] [C4] Composing the OR Team

Composing the Operational Resilience team is a foundational governance activity for MBSB Bank.

Operational Resilience crosses the boundaries of business operations, technology, cybersecurity, Operational Risk, BCM, third-party management, customer service and crisis management.

No single function possesses sufficient authority, information or capability to deliver it independently.

BNM's 2025 Discussion Paper reinforces this conclusion by making Operational Resilience a Board-level concern and emphasising strong oversight, central accountability and cross-functional coordination.

It expects Boards to oversee critical services, Impact Tolerances and resilience testing, while a designated Senior Management member should provide ultimate accountability for implementation, and other executives remain responsible for resilience outcomes within their domains.

For MBSB, the proposed structure therefore consists of Board oversight, Senior Management ownership, a designated accountable executive, an Operational Resilience Steering Committee, a central coordination function, Critical Business Service Owners, resource owners and specialist working groups.

The structure should operate within an appropriate Three Lines Model so that ownership, oversight and independent assurance remain clear.

The key principle is:

Operational Resilience should be centrally coordinated but collectively owned.

The central OR function may provide the methodology and coordination, but the resilience of MBSB's Critical Business Services ultimately depends on the business leaders and supporting functions responsible for delivering those services.

With the governance structure established, MBSB can move to the next essential question:

Which business services are sufficiently important that they must be prioritised for resilience?

The next chapter, therefore, focuses on identifying MBSB's Critical Business Services, providing the service catalogue around which dependency mapping, Impact Tolerance setting, scenario testing and resilience improvement can subsequently be organised.

 

 

 

[OR] [MBSB] [3/4 Banner] Operational Resilience in Action The MBSB Bank's Approach

eBook 1: Understanding Your Organisation: MBSB Bank
C1 C2 C3 C4
[OR] [MBSB] [E1] [C1] Introducing OR Case Study [OR] [MBSB] [E1] [C2] Understanding Your Organisation [OR] [MBSB] [E1] [C3] Examining Operating Environment [OR] [MBSB] [E1] [C4] Composing the OR Team
C5 C6 C7 C8
[OR] [MBSB] [E1] [C5] Identifying Critical Business Services [OR] [MBSB] [E1] [C6] Analysing Key Characteristics [OR] [MBSB] [E1] [C7] Establishing Organisational Goals [OR] [MBSB] [E1] [C8] Summary
 

New call-to-actionNew call-to-action

For organisations looking to accelerate their journey, BCM Institute’s training and certification programs, including the OR-5000 Operational Resilience Expert Implementer course, provide in-depth insights and practical toolkits for effectively embedding this model.

 

More Information About OR-5000 [OR-5] or OR-300 [OR-3]

To learn more about the course and schedule, click the buttons below for the OR-300 Operational Resilience Implementer course and the OR-5000 Operational Resilience Expert Implementer course.

BL-OR-3 Register Now BL-OR-3_Tell Me More BL-OR-3_View Schedule
BL-OR-5_Register Now BL-OR-5_Tell Me More  [BL-OR] [3-4-5] View Schedule
[BL-OR] [3] FAQ OR-300

If you have any questions, click to contact us.Email to Sales Team [BCM Institute]

FAQ BL-OR-5 OR-5000
OR Implementer Landing Page

New call-to-action

New call-to-action

 

Comments

 

CTA Banner_OR

CTA Banner_ORA

CTA Banner_BCM

CTA Banner_ITDR

CTA Banner_CM