Operational Resilience cannot be implemented effectively by a single department. For MBSB Bank (MBSB), the ability to continue delivering Critical Business Services during disruption depends upon coordinated decisions across business operations, risk management, technology, cybersecurity, Business Continuity Management (BCM), third-party management, customer service, crisis management and other supporting functions.
This cross-functional requirement is reinforced by Bank Negara Malaysia's (BNM) 2025 Discussion Paper on Operational Resilience. BNM states that Operational Resilience spans technology, risk management, operations, business, outsourcing and cybersecurity, and warns that siloed working arrangements can create organisational blind spots and weaken integrated oversight.
BNM also identifies strong Board oversight and timely decision-making within a cross-functional and integrated structure as an important differentiator between financial institutions that withstand disruption and those that struggle.
For MBSB, composing the Operational Resilience team is therefore not simply an administrative exercise. It is a governance decision that determines who owns resilience outcomes, who coordinates the programme, who provides specialist expertise, who challenges decisions and who is accountable when weaknesses are identified.
The purpose of this chapter is to establish a practical Operational Resilience governance and team structure for MBSB Bank.
The rationale for developing this structure early is that Operational Resilience cuts across organisational boundaries and cannot be delivered effectively if ownership remains fragmented among BCM, Operational Risk, Technology, Cybersecurity and individual business units.
BNM's emerging direction places Operational Resilience at the Board level and expects clear accountability, integrated decision-making and cross-functional coordination.
It also identifies Board responsibilities such as approving critical operations and/or services, setting impact tolerances, reviewing resilience-testing outcomes and holding Senior Management accountable for resilience outcomes.
By the end of this chapter, the reader should understand the proposed governance hierarchy for MBSB, the responsibilities of the Board, Senior Management, an Operational Resilience Steering Committee, an Operational Resilience programme function, Critical Business Service Owners and supporting specialists.
The reader should also understand how MBSB can apply the Three Lines Model so that ownership, oversight, challenge and assurance remain distinct while still supporting a common resilience objective.
The intended outcome is a structure capable of making Operational Resilience an enterprise-wide capability rather than another standalone risk-management programme.
A Critical Business Service may depend upon multiple organisational functions simultaneously.
Consider CBS-2: Domestic Funds Transfer and Payment Services.
Its delivery could require:
Business Operations
↓
Digital Banking
↓
Authentication
↓
Core Banking
↓
Payment Processing
↓
Cybersecurity Controls
↓
Telecommunications
↓
External Payment Infrastructure
↓
Customer Support
No single function owns every component.
Consequently, assigning Operational Resilience solely to BCM would be insufficient. Assigning it solely to Technology would be equally problematic. Operational Risk may provide governance and challenge, but it does not directly operate the services.
MBSB therefore requires a governance structure in which:
This allows Operational Resilience to become an integrated management capability.
BNM dedicates a specific section of its 2025 Discussion Paper to governance and accountability structures for Operational Resilience.
BNM states that Operational Resilience should be treated as a Board-level priority because disruptions can cause intolerable customer harm and threaten financial stability. The Board's role includes approving critical operations or services, setting impact tolerances, reviewing resilience testing and holding Senior Management accountable.
BNM further states that the cross-functional nature of Operational Resilience requires a holistic approach across areas such as:
Of particular importance for MBSB is BNM's reference to the Responsibility Mapping policy document. According to the Discussion Paper, the policy requires financial institutions to designate a member of Senior Management with a direct reporting line to the Chief Executive Officer as responsible for implementing the Operational Resilience framework.
BNM expects one person to be ultimately accountable for Operational Resilience outcomes, while other members of Senior Management retain responsibility for resilience within their respective domains.
Examples specifically cited by BNM include:
These principles provide the basis for the proposed MBSB governance structure in this chapter.
A practical structure for MBSB can be represented as follows:
Board of Directors / Board Risk Committee
↓
Chief Executive Officer and Senior Management / Management Risk Committee
↓
Senior Executive Accountable for Operational Resilience
↓
Operational Resilience Steering Committee
↓
Operational Resilience Programme Office / Coordination Function
↓
Critical Business Service Owners
↓
Supporting Resource and Functional Owners
↓
Operational Resilience Working Groups
This structure establishes both vertical accountability and horizontal coordination.
Vertical accountability ensures that material Operational Resilience matters can be escalated from service level to Senior Management and ultimately to the Board.
Horizontal coordination ensures that business, technology, risk, cybersecurity, BCM, third-party management and other functions work together around the resilience of the same Critical Business Services.
The Board should provide the highest level of governance for MBSB's Operational Resilience programme.
BNM expects Boards to play a direct role in overseeing resilience, including approving critical operations or services, impact tolerances and resilience-testing outcomes. Boards are also expected to challenge Senior Management and integrate resilience considerations into strategy and resource allocation.
For MBSB, the Board or an appropriately mandated Board Risk Committee should therefore:
The Board should not manage day-to-day Operational Resilience activities.
Its role is oversight, challenge and accountability.
Senior Management translates Board expectations into organisational action.
The CEO should ensure that Operational Resilience receives sufficient authority, resources and organisational priority.
For MBSB, Senior Management responsibilities should include:
BNM identifies centralised accountability as important because it supports stronger cross-functional coordination, integration of resilience into strategic and outsourcing decisions, effective management of trade-offs, timely remediation, structured reporting and more effective crisis management.
MBSB should designate a single member of Senior Management as ultimately accountable for Operational Resilience outcomes.
This individual should have sufficient authority, organisational standing and direct access to the CEO.
The precise title does not need to be prescribed solely for Operational Resilience. Depending upon MBSB's organisational design, accountability could potentially sit with an existing senior executive whose responsibilities enable enterprise-wide coordination.
BNM explicitly avoids prescribing a single organisational configuration and instead focuses on roles, responsibilities and decision-making effectiveness. Its Discussion Paper notes that governance-related requirements are deliberately more principle-based because structural arrangements should reflect the institution's circumstances.
The designated accountable executive should therefore:
However, central accountability must not remove responsibility from other executives.
Operational Resilience remains a shared Senior Management responsibility.
MBSB should establish an Operational Resilience Steering Committee (ORSC) as the principal cross-functional management forum for the Operational Resilience programme.
Its purpose should be to coordinate decisions that cannot be managed effectively by individual departments.
The ORSC could include representatives such as:
|
Proposed Member |
Primary Contribution |
|
Senior Executive Accountable for OR |
Chairmanship and overall accountability |
|
Chief Operating Officer / Operations Representative |
Process and operational resilience |
|
Chief Risk Officer / Operational Risk |
Risk oversight, appetite and challenge |
|
Chief Technology Officer / CIO |
Technology resilience |
|
Chief Information Security Officer |
Cyber resilience |
|
Head of Business Continuity Management |
Continuity and recovery integration |
|
Business / CBS Owners |
Service-level accountability |
|
Third-Party / Outsourcing Risk |
External dependency resilience |
|
Customer Service |
Customer impact and disruption management |
|
Compliance |
Regulatory alignment |
|
Data Management |
Data availability, integrity and recovery |
|
Crisis Management |
Disruption command and escalation |
|
Corporate Communications |
Customer and stakeholder communications |
|
Facilities / Physical Security |
Site and physical resilience |
|
Finance |
Investment and financial impact considerations |
|
Legal |
Contractual and legal considerations |
Membership should remain sufficiently senior that decisions can be made rather than merely discussed.
The ORSC should provide the primary management-level coordination mechanism.
Its responsibilities should include:
Although Operational Resilience should be enterprise-wide, MBSB should have a small central function responsible for coordinating the programme.
This may be a dedicated Operational Resilience team or an appropriately structured function within an existing organisational area.
The role should be to coordinate rather than own every resilience activity.
Its responsibilities could include:
The central OR function should not become the owner of each CBS.
That accountability should remain with the respective business service owner.
Each Critical Business Service should have a clearly identified CBS Owner.
For MBSB's proposed catalogue, this would include ownership for services such as:
The CBS Owner should be sufficiently senior to influence the business, technology and operational resources supporting the service.
Responsibilities should include:
This is an important shift from traditional BCM.
The CBS Owner is accountable for the resilience of the service outcome, not merely the recovery of a department.
Critical Business Services depend on resources owned by different functions.
These supporting resource owners may include:
Human Resources, operational management and specialist-team leaders.
Business operations and process owners.
Technology application owners, infrastructure owners and architecture teams.
Identity, security monitoring, incident response and security engineering.
Data owners, data custodians and information-management teams.
Facilities management, physical security and site operations.
Vendor owners, outsourcing management and procurement.
The resource owner should understand which CBSs depend upon the resource under their control.
For example, the same authentication platform may support:
CBS-2 Domestic Funds Transfer and Payment Services
CBS-3 Digital Banking Services
CBS-6 Corporate Payment and Bulk Transaction Services
CBS-8 Customer Transaction Authentication and Authorisation Services
This visibility allows MBSB to detect concentration risk.
Below the ORSC, MBSB should establish temporary or standing Operational Resilience Working Groups to perform detailed implementation activities.
These could include:
CBS Identification Working Group
Supports service definition and criticality assessment.
Mapping Working Group
Develops detailed process, resource, interconnection and dependency maps.
Impact Tolerance Working Group
Develops service-level tolerance proposals and supporting rationale.
Scenario Testing Working Group
Designs and conducts severe but plausible tests.
Third-Party Resilience Working Group
Reviews critical external dependencies and alternative arrangements.
Vulnerability and Remediation Working Group
Tracks corrective actions and investment priorities.
These groups should not create separate governance layers.
They should perform detailed work and report findings to the ORSC.
The overall structure can be summarised as follows:
|
Governance Level |
Proposed MBSB Structure |
Primary Responsibility |
|
Level 1 |
Board / Board Risk Committee |
Oversight, challenge, approval and accountability |
|
Level 2 |
CEO / Senior Management / Management Risk Committee |
Executive ownership, resource allocation and decision-making |
|
Level 3 |
Senior Executive Accountable for Operational Resilience |
Enterprise-wide accountability and coordination |
|
Level 4 |
Operational Resilience Steering Committee |
Cross-functional governance and programme oversight |
|
Level 5 |
Operational Resilience Programme Function |
Methodology, coordination, reporting and programme management |
|
Level 6 |
Critical Business Service Owners |
Accountability for service resilience |
|
Level 7 |
Resource / Functional Owners |
Resilience of supporting people, process, technology, data, facilities and third parties |
|
Level 8 |
Operational Resilience Working Groups |
Detailed analysis, mapping, testing and remediation |
This model is deliberately designed around outcomes and accountability rather than organisational hierarchy alone.
MBSB should preserve independence and effective challenge while developing its cross-functional Operational Resilience structure.
A practical Three Lines Model could be applied as follows.
|
Line |
MBSB Functions |
Operational Resilience Role |
|
First Line |
Business units, Operations, Technology, Cybersecurity, service owners and resource owners |
Own and manage Operational Resilience risks and controls |
|
Second Line |
Operational Risk, Enterprise Risk, Compliance and relevant oversight functions |
Establish framework, provide challenge and monitor adherence |
|
Third Line |
Internal Audit |
Provide independent assurance over framework design and operating effectiveness |
The distinction is important.
The cross-functional nature of OR does not mean risk ownership and independent challenge should be blurred.
For example:
owns the resilience of the CBS.
challenges whether resilience risks have been properly assessed.
independently evaluates whether the governance framework operates effectively.
BCM should remain an important part of MBSB's Operational Resilience structure.
BCM brings established capabilities including:
However, BCM should not be expected to own Operational Resilience independently.
Operational Resilience expands the focus from:
to:
BCM therefore becomes one of the essential capabilities supporting CBS resilience.
Technology and cybersecurity will have especially important roles within MBSB because many banking services depend upon digital platforms.
BNM notes that technology and third-party risk requirements are comparatively more prescriptive because technology failures and cyber incidents can propagate quickly through the financial ecosystem.
It specifically highlights system availability, security controls, recovery capability and failover arrangements as fundamental to continuity.
Technology representatives should therefore contribute:
Cybersecurity should contribute:
MBSB's OR team should include strong third-party representation because service resilience may depend on providers outside its direct control.
BNM's existing Outsourcing and RMiT requirements already require risk assessment, due diligence, contractual provisions, contingency arrangements and continuous oversight for relevant third-party and technology arrangements.
Within Operational Resilience, MBSB should extend this analysis by asking:
These questions should be considered by the ORSC rather than left solely to procurement or vendor management.
Operational Resilience is not only about maintaining systems.
When disruption occurs, effective decision-making and communication can materially reduce customer harm.
MBSB's Crisis Management and Communications representatives should therefore contribute to:
This becomes particularly important when a service approaches or exceeds its Impact Tolerance.
MBSB's Operational Resilience structure should work in both:
and
Under business-as-usual conditions, the governance structure should:
During disruption, the same accountability model should support:
BNM identifies stronger cross-functional coordination during both business-as-usual and crisis conditions as one of the benefits of centralised accountability.
A well-designed OR team is ineffective if decision rights are unclear.
MBSB should therefore define:
Who can declare that a CBS is materially disrupted?
Who determines that an Impact Tolerance is likely to be breached?
Who authorises degraded service operation?
Who approves the activation of alternative arrangements?
Who decides whether resilience investment is required?
Who accepts residual resilience risk?
Who escalates unresolved vulnerabilities to the Board?
These authorities should be documented before a disruption occurs.
The OR team should develop a consolidated resilience dashboard for Senior Management and the Board.
Illustrative reporting could include:
|
Reporting Area |
Examples |
|
CBS Status |
Number of approved CBSs and ownership status |
|
Impact Tolerance |
Approved tolerance and breaches |
|
Dependency Mapping |
Mapping completeness and identifying concentration risks |
|
Scenario Testing |
Tests completed, findings and tolerance performance |
|
Vulnerabilities |
Open, overdue and high-risk vulnerabilities |
|
Third Parties |
Critical provider resilience issues |
|
Technology Resilience |
Availability, failover and recovery concerns |
|
Incidents |
Material disruptions and near misses |
|
Remediation |
Progress against corrective actions |
|
Investment |
Major resilience initiatives and funding decisions |
|
Continuous Improvement |
Lessons learned from incidents and testing |
The purpose of reporting should be to support decision-making, not merely produce additional metrics.
MBSB should avoid several common implementation weaknesses.
This limits ownership and may isolate technology, cyber and business leaders.
Technology is critical, but service resilience also depends upon people, processes, data, facilities and third parties.
The ORSC should be capable of making or escalating substantive decisions.
CBS owners should have sufficient authority to influence resources and remediation.
Risk functions should challenge rather than replace business accountability.
External providers may represent some of the most important service dependencies.
Operational Resilience must ultimately improve service capability, not merely produce governance documentation.
The proposed structure aligns with several themes identified by BNM.
|
BNM Direction |
Proposed MBSB Response |
|
Operational Resilience as Board-level priority |
Board / Board Risk Committee oversight |
|
Single Senior Management accountability |
Designated accountable senior executive |
|
Shared responsibility across Senior Management |
COO, CTO/CIO, CISO, CRO and business leadership responsibilities |
|
Cross-functional integration |
Operational Resilience Steering Committee |
|
Critical-service ownership |
Designated CBS Owners |
|
Dependency visibility |
Resource owners and mapping working groups |
|
Timely remediation |
ORSC vulnerability tracking and escalation |
|
Structured reporting |
Consolidated Operational Resilience dashboard |
|
Effective crisis management |
Integration with Crisis Management and Communications |
|
Continuous learning |
Formal lessons-learned and remediation process |
BNM's Discussion Paper also makes clear that the regulatory direction is not intended to replace existing frameworks.
Rather, Operational Resilience provides a more coherent, outcome-oriented way of connecting existing BCM, technology governance, third-party management, Operational Risk and governance requirements.
Once MBSB has established the governance and team structure, it can proceed with greater clarity into the implementation work.
The sequence becomes:
Board and Senior Management Oversight
↓
Appoint Accountable Senior Executive
↓
Establish OR Steering Committee
↓
Assign OR Coordination Function
↓
Identify Critical Business Services
↓
Assign CBS Owners
↓
Map Supporting Resources
↓
Set Impact Tolerances
↓
Conduct Scenario Testing
↓
Remediate and Continuously Improve
The composition of the team therefore directly influences the quality of every subsequent Operational Resilience activity.
Composing the Operational Resilience team is a foundational governance activity for MBSB Bank.
Operational Resilience crosses the boundaries of business operations, technology, cybersecurity, Operational Risk, BCM, third-party management, customer service and crisis management.
No single function possesses sufficient authority, information or capability to deliver it independently.
BNM's 2025 Discussion Paper reinforces this conclusion by making Operational Resilience a Board-level concern and emphasising strong oversight, central accountability and cross-functional coordination.
It expects Boards to oversee critical services, Impact Tolerances and resilience testing, while a designated Senior Management member should provide ultimate accountability for implementation, and other executives remain responsible for resilience outcomes within their domains.
For MBSB, the proposed structure therefore consists of Board oversight, Senior Management ownership, a designated accountable executive, an Operational Resilience Steering Committee, a central coordination function, Critical Business Service Owners, resource owners and specialist working groups.
The structure should operate within an appropriate Three Lines Model so that ownership, oversight and independent assurance remain clear.
The key principle is:
The central OR function may provide the methodology and coordination, but the resilience of MBSB's Critical Business Services ultimately depends on the business leaders and supporting functions responsible for delivering those services.
With the governance structure established, MBSB can move to the next essential question:
The next chapter, therefore, focuses on identifying MBSB's Critical Business Services, providing the service catalogue around which dependency mapping, Impact Tolerance setting, scenario testing and resilience improvement can subsequently be organised.
| eBook 1: Understanding Your Organisation: MBSB Bank | |||
| C1 | C2 | C3 | C4 |
| C5 | C6 | C7 | C8 |
For organisations looking to accelerate their journey, BCM Institute’s training and certification programs, including the OR-5000 Operational Resilience Expert Implementer course, provide in-depth insights and practical toolkits for effectively embedding this model.
To learn more about the course and schedule, click the buttons below for the OR-300 Operational Resilience Implementer course and the OR-5000 Operational Resilience Expert Implementer course.
|
If you have any questions, click to contact us. |
||
|
|