Operational Resilience becomes effective only when an organisation translates its understanding of the business, operating environment, Critical Business Services and key dependencies into clear organisational goals and measurable resilience objectives.
For MBSB Bank (MBSB), these goals should define what the bank intends to protect, what level of disruption it is prepared to withstand, how responsibilities should be assigned and how resilience should influence investment and management decision-making.
This is particularly important in the Malaysian financial services environment. Bank Negara Malaysia (BNM) issued its Discussion Paper on Operational Resilience in December 2025 to set out emerging regulatory considerations for strengthening financial institutions' ability to withstand disruption and maintain the continued delivery of financial services.
BNM's subsequent assessment of operational risk also highlights cyber risk, IT disruption, organisational risk, human error and increasing reliance on external service providers among the operational concerns facing financial institutions.
MBSB's Operational Resilience goals should therefore extend beyond conventional objectives such as maintaining system availability or recovering within predefined Recovery Time Objectives.
The goals should focus ultimately on the continued delivery of Critical Business Services within acceptable levels of disruption, while minimising customer harm and protecting the bank and the wider financial ecosystem.
The purpose of this chapter is to establish a practical set of organisational goals and supporting objectives for MBSB Bank's Operational Resilience programme.
The rationale for defining these goals at this stage is that the previous organisational analysis has already established what MBSB does, the environment in which it operates, how Operational Resilience should be governed, which services may be critical and which organisational characteristics influence its resilience profile.
These findings now need to be translated into a common direction that can guide the subsequent planning, implementation, testing and continual improvement of Operational Resilience. BNM's emerging direction reinforces the importance of continued service delivery and stronger resilience practices across financial institutions.
By the end of this chapter, the reader should be able to define an overarching Operational Resilience goal for MBSB and translate it into specific objectives covering Critical Business Services, dependency mapping, Impact Tolerances, scenario testing, governance, third-party resilience, technology and cyber resilience, customer protection, learning and continuous improvement.
These goals should provide a practical decision-making framework rather than simply a statement of intent. This is consistent with ISO 22316:2017, which recognises that organisational resilience objectives and initiatives should be tailored to the individual organisation rather than applied uniformly.
Without clearly defined goals, Operational Resilience can easily become a collection of disconnected activities.
For example, MBSB may already undertake:
Each activity contributes to resilience.
However, unless these capabilities are connected to a common organisational objective, they may remain focused on individual departments, systems or risk disciplines.
Operational Resilience provides that common objective.
A practical question for MBSB is:
What outcome should all resilience-related capabilities collectively achieve?
The answer should be centred on the delivery of MBSB's most important services.
A suitable overarching goal for MBSB could be:
To strengthen MBSB Bank's ability to anticipate, withstand, respond to, recover from and learn from operational disruption while continuing to deliver its Critical Business Services within established Impact Tolerances, minimising harm to customers and supporting the safety, soundness and confidence of the Malaysian financial system.
This goal combines several important principles.
It recognises that disruption cannot always be prevented.
It focuses on services rather than individual resources.
It recognises customer harm as an important measure of disruption.
It establishes Impact Tolerance as the boundary for acceptable disruption.
It recognises that recovery is only one part of resilience.
It also incorporates learning and improvement.
The overarching goal should be translated into specific objectives.
For MBSB, these objectives can be organised around the following ten areas:
1. Critical Business Services
2. Customer and Stakeholder Protection
3. Interconnections and Interdependencies
4. Impact Tolerance
5. Severe but Plausible Scenario Testing
6. Vulnerability Reduction
7. Technology, Cyber and Data Resilience
8. Third-Party Resilience
9. Governance and Accountability
10. Learning and Continuous Improvement
Together, these objectives create a practical Operational Resilience agenda.
The first organisational goal should be to ensure that MBSB clearly identifies and prioritises the business services whose disruption could cause unacceptable consequences.
For the purposes of this case study, the proposed MBSB CBS catalogue consists of:
|
Code |
Critical Business Service |
|
CBS-1 |
Customer Deposit and Account Access Services |
|
CBS-2 |
Domestic Funds Transfer and Payment Services |
|
CBS-3 |
Digital Banking Services |
|
CBS-4 |
Cash Access and Cash Transaction Services |
|
CBS-5 |
Financing Account Servicing and Repayment Services |
|
CBS-6 |
Corporate Payment and Bulk Transaction Services |
|
CBS-7 |
High-Value and Interbank Payment Services |
|
CBS-8 |
Customer Transaction Authentication and Authorisation Services |
|
CBS-9 |
Customer Support and Assistance During Banking Disruptions |
The organisational objective should be:
Every approved Critical Business Service should have a clearly defined service scope, accountable owner, mapped dependencies, established Impact Tolerance and evidence that its resilience has been tested.
This turns the CBS inventory from a classification exercise into an active management framework.
Operational Resilience should be customer-oriented.
For MBSB, a service may technically continue operating while customers experience unacceptable consequences.
For example, Digital Banking Services might remain partially available while customers cannot:
The organisational objective should therefore be:
Assess disruption according to the outcome experienced by the customer, not merely the status of MBSB's internal systems.
MBSB should consider factors such as:
BNM's operational-risk assessment specifically notes the importance of financial institutions' ability to withstand disruption and maintain the continued delivery of financial services. (Bank Negara Malaysia)
A Critical Business Service cannot be resilient unless MBSB understands what supports it.
The organisational objective should therefore be:
Maintain sufficient end-to-end visibility of the people, processes, technology, information, facilities, third parties and financial infrastructure required to deliver each Critical Business Service.
For example:
CBS-2 Domestic Funds Transfer and Payment Services
may depend on:
Customer Channel
↓
Authentication
↓
Core Banking
↓
Payment Application
↓
Telecommunications
↓
Payment Network
↓
Other Financial Institutions
MBSB should be able to identify:
The purpose of mapping is therefore not simply to produce diagrams.
It is to identify where service failure could originate and propagate.
Traditional BCM typically relies upon recovery metrics such as Recovery Time Objective and Maximum Tolerable Downtime.
These remain important, but Operational Resilience requires a broader service-level perspective.
MBSB should establish an organisational objective that:
Every Critical Business Service has a clearly defined and approved Impact Tolerance representing the maximum level of disruption that can be tolerated before customer or stakeholder consequences become unacceptable.
Impact Tolerance could incorporate dimensions such as:
For example, the tolerance for Customer Deposit and Account Access Services might differ significantly from the tolerance for another service because customers may rapidly experience harm when access to funds is lost.
Impact Tolerance should therefore be service-specific.
MBSB should not assume that documented continuity and recovery arrangements will perform as intended during a real event.
An organisational goal should therefore be:
Regularly test whether Critical Business Services can remain within established Impact Tolerances during severe but plausible disruption scenarios.
Illustrative scenarios could include:
Scenario testing should focus on the end-to-end service, rather than merely whether an individual recovery plan has been executed successfully.
A successful technology recovery test does not necessarily demonstrate service resilience.
The question is:
Was the Critical Business Service maintained or restored without exceeding its Impact Tolerance?
Scenario testing, dependency mapping, incidents and risk assessments will identify weaknesses.
MBSB should establish a specific organisational goal that:
Material vulnerabilities affecting Critical Business Services are identified, prioritised, assigned to accountable owners and remediated within agreed timeframes.
Examples may include:
The important principle is:
Operational Resilience testing should lead to resilience improvement.
A repeated vulnerability that remains unresolved after successive exercises indicates a governance problem, not merely a testing finding.
Technology is central to MBSB's service delivery.
BNM's current regulatory landscape includes its revised Risk Management in Technology (RMiT) policy document issued in November 2025, while BNM's operational-risk assessment identifies cyber risk and IT disruption among major operational risks. (Bank Negara Malaysia)
MBSB's organisational objective should therefore be:
Ensure that critical technology, cyber and information capabilities support the continued delivery and safe recovery of Critical Business Services.
This requires more than availability.
MBSB should consider:
Availability
Can the service be accessed?
Integrity
Can the information be trusted?
Confidentiality
Is sensitive information protected?
Capacity
Can systems support required volumes during disruption?
Recoverability
Can systems and data be restored within required service tolerances?
Security
Can service restoration occur without exposing customers or the bank to unacceptable cyber risk?
A technically available but corrupted banking platform is not resilient.
MBSB's CBSs will depend partly on organisations beyond its direct control.
The objective should therefore be:
Understand and actively manage critical third-party dependencies supporting MBSB's Critical Business Services, including the resilience implications of provider concentration and substitutability.
MBSB should determine:
The objective is not to eliminate third-party dependency.
It is to ensure that MBSB understands and manages the service-level consequences of that dependency.
Operational Resilience should have clear ownership from Board level through to individual CBS and resource owners.
The organisational goal should therefore be:
Establish governance arrangements in which Operational Resilience is centrally coordinated, appropriately challenged and clearly owned across MBSB.
The governance pathway could be:
Board / Board Risk Committee
↓
Senior Management / Management Risk Committee
↓
Senior Executive Accountable for Operational Resilience
↓
Operational Resilience Steering Committee
↓
Critical Business Service Owners
↓
Supporting Resource Owners
MBSB should avoid a structure where everyone contributes but nobody is ultimately accountable.
Governance should clearly identify:
Operational Resilience should not replace MBSB's existing risk and resilience capabilities.
Instead, an important organisational goal should be:
Integrate existing management disciplines around the continued delivery of Critical Business Services.
This can be represented as:
Operational Risk
Business Continuity Management
IT Disaster Recovery
Cybersecurity
Crisis Management
Incident Management
Third-Party Risk Management
Data Management
↓
Critical Business Service Resilience
The Critical Business Service becomes the common organising point.
For example, different functions may separately assess the same service:
Operational Resilience asks whether those controls collectively enable the service outcome to remain within tolerance.
Operational Resilience requires more than following predefined plans.
Severe disruption may develop differently from assumptions used when the plan was written.
MBSB therefore needs an organisational objective to:
Develop the capacity to adapt during disruption when normal operating and recovery assumptions no longer apply.
This may require:
This aligns with the broader concept of organisational resilience in ISO 22316. ISO describes organisational resilience as applicable to organisations of all types and notes that specific objectives and initiatives should be tailored to individual organisational needs. (ISO)
Operational Resilience cannot depend solely on policies and technology.
The organisation must understand its resilience responsibilities.
An objective for MBSB should therefore be:
Embed awareness of Critical Business Services and resilience responsibilities into normal organisational decision-making and behaviour.
Employees and management should understand:
ISO's guidance on organisational resilience emphasises the importance of resilient culture, shared values, awareness of changing contexts and strong leadership. (ISO)
Operational Resilience should not be something MBSB evaluates only after systems and processes have been implemented.
A further organisational objective should be:
Incorporate Operational Resilience considerations into material business, technology, outsourcing and transformation decisions before new vulnerabilities are introduced.
For example, when adopting a new technology platform, MBSB should ask:
This approach is more effective than attempting to remediate resilience weaknesses after implementation.
Operational Resilience should evolve as MBSB changes.
An organisational objective should therefore be:
Continuously improve resilience using lessons from incidents, scenario tests, near misses, audits, regulatory reviews and changes in the operating environment.
The improvement cycle can be represented as:
Disruption / Test
↓
Observe Performance
↓
Identify Weaknesses
↓
Determine Root Causes
↓
Prioritise Corrective Actions
↓
Implement Improvements
↓
Retest
↓
Update Resilience Assessment
This turns incidents and exercises into sources of organisational learning.
The goals developed in this chapter can be consolidated as follows:
|
No. |
MBSB Operational Resilience Goal |
Intended Outcome |
|
OR-G1 |
Protect Critical Business Services |
Critical services continue within acceptable disruption levels |
|
OR-G2 |
Minimise Customer and Stakeholder Harm |
Disruption consequences remain within agreed tolerances |
|
OR-G3 |
Understand End-to-End Dependencies |
Critical dependencies and concentrations are visible |
|
OR-G4 |
Establish Impact Tolerances |
Clear boundaries exist for unacceptable disruption |
|
OR-G5 |
Test Severe but Plausible Scenarios |
Resilience is demonstrated rather than assumed |
|
OR-G6 |
Reduce Material Vulnerabilities |
Weaknesses are prioritised and remediated |
|
OR-G7 |
Strengthen Technology, Cyber and Data Resilience |
Digital services remain available, secure and recoverable |
|
OR-G8 |
Strengthen Third-Party Resilience |
External dependency risks are understood and managed |
|
OR-G9 |
Establish Governance and Accountability |
Resilience responsibilities and decision rights are clear |
|
OR-G10 |
Integrate Existing Resilience Disciplines |
BCM, risk, cyber, technology and other capabilities operate around CBS outcomes |
|
OR-G11 |
Develop Organisational Adaptability |
MBSB can respond effectively beyond predefined plans |
|
OR-G12 |
Build a Resilience-Supporting Culture |
Resilience becomes part of everyday decision-making |
|
OR-G13 |
Embed Resilience into Change |
New products and transformations do not introduce unmanaged vulnerabilities |
|
OR-G14 |
Continuously Learn and Improve |
Incidents and testing produce measurable resilience improvements |
These goals provide a structured bridge between strategic intent and implementation.
Goals are most useful when their achievement can be assessed.
MBSB could therefore establish measures such as:
|
Goal Area |
Illustrative Measure |
|
CBS Governance |
Percentage of CBSs with approved owners |
|
Dependency Mapping |
Percentage of CBSs with validated end-to-end maps |
|
Impact Tolerance |
Percentage of CBSs with approved Impact Tolerances |
|
Scenario Testing |
Percentage of CBSs tested against approved severe but plausible scenarios |
|
Tolerance Performance |
Number of scenario tests or incidents resulting in tolerance breach |
|
Vulnerability Management |
Number and age of unresolved material vulnerabilities |
|
Third-Party Resilience |
Percentage of critical providers assessed against CBS requirements |
|
Technology Resilience |
Percentage of critical technology dependencies meeting CBS recovery requirements |
|
Remediation |
Percentage of resilience actions completed within agreed dates |
|
Training |
Percentage of relevant personnel completing OR awareness or role-based training |
|
Lessons Learned |
Percentage of material incident or testing actions implemented |
|
Governance |
Frequency and timeliness of resilience reporting to Senior Management and Board |
Metrics should remain decision-oriented.
The purpose is not to create the largest possible dashboard.
It is to provide management with enough information to answer:
Is MBSB becoming more resilient, and where does material vulnerability remain?
MBSB can translate each organisational goal into a target state.
For example:
Target outcome: All CBSs are formally identified, approved and assigned to accountable owners.
Target outcome: MBSB can trace the end-to-end resources and external dependencies required to deliver every CBS.
Target outcome: Senior Management and the Board understand the point at which disruption to each CBS becomes unacceptable.
Target outcome: MBSB has evidence that CBSs can operate within tolerance under severe but plausible disruption or has documented remediation where they cannot.
Target outcome: Material weaknesses are visible, prioritised and subject to accountable remediation.
Target outcome: Material Operational Resilience decisions can be escalated rapidly to the appropriate management level.
Target outcome: Lessons from disruption consistently result in changes to controls, processes, architecture or preparedness.
This allows MBSB to measure progress from current state toward desired resilience state.
ISO 22316:2017 remains the published international standard on organisational resilience as of August 2026, although ISO indicates that a second edition is under development. (ISO)
ISO 22316 is particularly relevant because it does not prescribe uniform resilience objectives. Instead, organisational initiatives should be tailored to the organisation's needs. (ISO)
This principle is directly applicable to MBSB.
Its OR goals should reflect:
The objective is therefore not to copy another financial institution's resilience goals.
It is to establish goals appropriate to MBSB's own organisational context.
Operational Resilience goals should guide the programme through a clear chain:
Organisational Context
↓
Operational Resilience Goals
↓
Operational Resilience Strategy
↓
Roadmap
↓
Critical Business Services
↓
Impact Tolerances
↓
Scenario Testing
↓
Remediation and Investment
↓
Continuous Improvement
The goals define what MBSB wants to achieve.
The strategy determines how it intends to achieve it.
The roadmap determines when and in what sequence the work will occur.
The implementation methodology then delivers the required capabilities.
This distinction is important because a resilience programme without clear goals can become activity-driven rather than outcome-driven.
Before approving MBSB's Operational Resilience goals, leadership should consider questions such as:
These questions move Operational Resilience from a technical programme to an enterprise-management discipline.
For use in MBSB's Operational Resilience framework, a concise organisational statement could be:
MBSB Bank will strengthen its Operational Resilience capability to ensure that Critical Business Services can continue to be delivered within approved Impact Tolerances during severe but plausible operational disruptions. MBSB will achieve this by understanding end-to-end dependencies, protecting customers, strengthening technology and third-party resilience, establishing clear accountability, testing resilience capabilities and continuously addressing identified vulnerabilities.
This statement can provide a common point of reference for:
This chapter completes an important part of understanding MBSB.
The progression across this eBook has established:
Understand MBSB Bank
↓
Examine Its Operating Environment
↓
Establish the Operational Resilience Team
↓
Identify Critical Business Services
↓
Understand MBSB's Key Characteristics
↓
Establish Organisational Operational Resilience Goals
The next stage is to convert these foundations into structured implementation.
This can be achieved through the Operational Resilience Planning Methodology:
Establish the organisational foundation, governance, strategy, risk boundaries and implementation roadmap.
Identify Critical Business Services, map their interconnections and interdependencies, establish Impact Tolerances, conduct scenario testing and improve resilience based on lessons learned.
Embed Operational Resilience within culture, communications, training, self-assessment and independent review.
The organisational goals established in this chapter provide the strategic anchor connecting all three phases.
Establishing organisational goals converts MBSB Bank's understanding of Operational Resilience into a clear statement of intended outcomes. Without these goals, activities such as dependency mapping, Impact Tolerance setting, scenario testing, technology recovery and third-party assessment can remain disconnected.
With clearly defined goals, each activity contributes to a common purpose: maintaining the continued delivery of MBSB's Critical Business Services within acceptable levels of disruption.
BNM's December 2025 Discussion Paper and subsequent operational-risk observations reinforce the importance of strengthening financial institutions' ability to withstand disruption and maintain financial-service delivery. Cyber threats, technology disruption, organisational change and increasing reliance on external providers make resilience an ongoing management concern rather than a one-time compliance exercise.
For MBSB, the overarching objective can therefore be summarised as:
Protect the continued delivery of Critical Business Services, minimise customer harm and strengthen MBSB's ability to withstand, adapt to and recover from severe operational disruption.
Achieving this objective requires MBSB to understand its dependencies, establish meaningful Impact Tolerances, test severe but plausible scenarios, remediate vulnerabilities, strengthen technology and third-party resilience, maintain clear accountability and continuously learn from incidents and exercises.
ISO 22316 supports this organisation-specific approach by recognising that resilience objectives should reflect the individual organisation's circumstances rather than follow a uniform model. (ISO)
The key takeaway from this chapter is therefore:
Operational Resilience goals define the outcomes MBSB intends to protect; the Operational Resilience Planning Methodology provides the structured pathway for achieving them.
With the organisational context, operating environment, governance structure, Critical Business Services, organisational characteristics and resilience goals now established, MBSB has the foundation needed to begin its structured Operational Resilience implementation journey.
The subsequent eBooks in Operational Resilience in Action: The MBSB Approach can build upon this foundation by moving from understanding the organisation to planning, implementing, testing and sustaining its Operational Resilience capabilities.
| eBook 1: Understanding Your Organisation: MBSB Bank | |||
| C1 | C2 | C3 | C4 |
| C5 | C6 | C7 | C8 |
For organisations looking to accelerate their journey, BCM Institute’s training and certification programs, including the OR-5000 Operational Resilience Expert Implementer course, provide in-depth insights and practical toolkits for effectively embedding this model.
To learn more about the course and schedule, click the buttons below for the OR-300 Operational Resilience Implementer course and the OR-5000 Operational Resilience Expert Implementer course.
|
If you have any questions, click to contact us. |
||
|
|