eBook OR

[OR] [MBSB] [E2] [P2] [C8] Five Stages of the "Implement" Phase

Written by Moh Heng Goh | Aug 26, 2026, 9:54:37 AM

Introduction to MBSB’s “Implement” Phase of the Operational Resilience Planning Methodology

Introduction


The Implement Phase is where MBSB translates the foundations established during the Plan Phase into practical operational resilience capabilities.

Having assessed its current maturity, identified gaps, developed its strategy and roadmap, confirmed its risk appetite, and established governance arrangements, MBSB must now apply these foundations to the business services that matter most to its customers and stakeholders.

For MBSB, this means moving beyond a predominantly function-based or system-based view of continuity towards an end-to-end service perspective.

The central question is no longer limited to whether an individual department, application or technology platform can recover after disruption.

The broader question is whether MBSB can continue to deliver its critical business services at an acceptable level of disruption when faced with severe but plausible events.

This direction is consistent with Bank Negara Malaysia's 2025 Discussion Paper on Operational Resilience, which identifies several foundational capabilities for financial institutions: preserving the continuity of critical operations and services; mapping internal and external interdependencies; managing third-party dependencies; setting tolerances for disruption; and assessing capabilities under severe but plausible scenarios.

BNM also emphasises continuous improvement and organisational learning from incidents and near misses.

The five stages within MBSB's Implement Phase are:

These five stages form a logical sequence. MBSB first determines what must remain resilient, then understands what those services depend upon, determines how much disruption can be tolerated, tests whether the service can remain within that tolerance, and finally addresses weaknesses identified through testing and actual disruptions.

 

The purpose of this chapter is to provide the reader with an overview of the Implement Phase before the detailed implementation activities for each stage are addressed in subsequent chapters.

Understanding this phase as an integrated sequence is important because its individual activities are mutually dependent.

MBSB cannot establish meaningful impact tolerances without first determining which services are critical.

Scenario testing will be incomplete if the organisation does not understand the people, processes, technology, data, facilities, and third parties that support those services.

Similarly, identifying vulnerabilities through testing achieves little unless lessons are converted into remediation and sustained improvements.

BNM's Discussion Paper reflects this interconnected approach. It notes that financial institutions cannot protect critical operations and services without understanding what they rely upon and how failures can propagate through people, processes, data, technology, facilities, business units and external service providers.

By the end of this chapter, the reader should be able to:

  • explain the purpose of MBSB's Implement Phase;
  • understand the five stages and their relationship to one another;
  • recognise how MBSB can identify and prioritise critical business services;
  • understand the importance of mapping interconnections and interdependencies from an end-to-end service perspective;
  • distinguish impact tolerance from traditional recovery measures such as MTD and RTO;
  • understand how severe but plausible scenario testing challenges MBSB's resilience capability; and
  • recognise how lessons from tests, disruptions, and near misses should result in measurable improvements in resilience.

The intended outcome is a clear understanding of how MBSB can progress from designing an operational resilience framework to implementing and validating resilience at the critical business service level.

 

The Implement Phase

The Implement Phase focuses operational resilience activities around the services that MBSB needs to protect from intolerable disruption.

This represents an important development from traditional continuity approaches. MBSB may already have recovery strategies for business functions, technology systems and facilities.

These remain important. However, the resilience of a critical business service is determined by whether the complete chain of resources and dependencies supporting that service can collectively operate through disruption.

BNM observes that Malaysian financial institutions already operate under complementary requirements covering BCM, technology risk, outsourcing, operational risk and governance.

The emerging direction toward operational resilience is not intended to displace these arrangements. Instead, BNM considers how they can be organised around a more explicit outcome: the ability to sustain critical operations and services despite disruption.

For MBSB, the Implement Phase can therefore be expressed as five connected questions:

 

Implement Stage

Key Question for MBSB

1. Identify Critical Business Services

Which services must MBSB prioritise for resilience?

2. Map Interconnections and Interdependencies

What does each critical service depend upon?

3. Set Impact Tolerance

How much disruption can MBSB tolerate before unacceptable harm occurs?

4. Conduct Scenario Testing

Can MBSB remain within tolerance during severe but plausible disruption?

5. Improve Lessons Learned

What must MBSB change after weaknesses are identified?

Together, these stages convert operational resilience from a framework into a practical service-level management capability.

 

Stage 1: Identify Critical Business Services

[Implement Phase – Stage 1]
Determining What MBSB Must Protect

The first stage is to identify MBSB's Critical Business Services (CBSs).

Not every business activity requires the same level of resilience. Some activities can experience temporary interruption with manageable consequences, while disruption to others may rapidly result in significant customer harm, financial loss, regulatory consequences, reputational damage or wider disruption to the financial ecosystem.

BNM similarly emphasises that financial institutions need to identify which operations and services are critical to consumers and markets and preserve their continuity.

Its Discussion Paper recognises that not all services are equally significant and that resilience efforts should prioritise what is essential for customers and stakeholders.

For MBSB, a critical business service should be described from the customer or stakeholder outcome perspective rather than solely in terms of the internal department performing the work.

For example:

  • Internal function: Payment Operations

  • Technology: Core Banking System

  • Customer-facing service: Customer Funds Transfer Service

The critical business service should describe what the customer or stakeholder receives, rather than merely the resources producing that outcome.

Considerations for MBSB

MBSB could evaluate candidate services using factors such as:

  • number and type of customers affected;
  • customers' ability to access their funds;
  • financial consequences;
  • potential regulatory impact;
  • duration of disruption;
  • availability of alternative channels;
  • impact on vulnerable customers;
  • potential contagion or wider financial system implications;
  • reputational consequences; and
  • timing of disruption, including peak transaction periods.

BNM specifically observes that customer expectations for uninterrupted access are particularly high for services affecting access to funds, including mobile and online banking and real-time payments.

MBSB Example

MBSB may determine that Customer Funds Transfer Service is a Critical Business Service.

The rationale could be that an extended disruption would prevent retail and business customers from transferring funds, potentially affecting essential payments, commercial obligations and customers' immediate access to financial resources.

MBSB may similarly evaluate services associated with customer deposits, financing-related transactions or other essential banking outcomes. However, inclusion should be based on clearly defined criticality criteria rather than assuming that every customer-facing activity is automatically critical.

The principal output from this stage should be an approved inventory of Critical Business Services, together with clear descriptions, service boundaries, ownership and documented justification for their inclusion.

Stage 2: Map Interconnections and Interdependencies

[Implement Phase – Stage 2]
Understanding How Critical Business Services Are Delivered

Once MBSB knows which services are critical, it must understand how each service is delivered from end to end.

A critical service rarely depends on a single department or application. It usually relies on an interconnected chain involving:

  • people;
  • processes;
  • technology;
  • applications;
  • infrastructure;
  • data;
  • facilities;
  • internal business units;
  • telecommunications;
  • third-party providers;
  • outsourced arrangements;
  • payment or industry infrastructures; and
  • other supporting services.

BNM identifies this visibility into dependencies as a core operational resilience capability. The Discussion Paper explains that disruptions can propagate through complex networks of people, processes, data, technology, facilities and external providers, and that mapping is necessary to identify vulnerabilities, concentrations and critical points of failure.

BNM's existing BCM expectations also require financial institutions to identify and assess internal and external interdependencies, including people, processes, and technologies, and to incorporate outsourcing arrangements supporting critical activities into continuity planning.

The purpose of mapping is therefore not simply to produce a process diagram. It is to enable MBSB to understand how disruption at one component could propagate through the chain and ultimately affect delivery of the Critical Business Service.

MBSB Example

For the Customer Funds Transfer Service, an illustrative dependency chain could be:

This service may additionally depend upon:

  • cybersecurity monitoring;
  • data centre infrastructure;
  • telecommunications providers;
  • network connectivity;
  • databases;
  • cloud or technology service providers;
  • operations personnel;
  • fraud monitoring;
  • customer support; and
  • external payment or switching arrangements.

Suppose the mapping reveals that two apparently independent digital channels depend on the same authentication platform. MBSB may initially believe that one channel provides an alternative if the other fails. The mapping demonstrates that both share a common point of failure.

This is precisely the type of vulnerability that operational resilience mapping is intended to expose.

 
Mapping Beyond Direct Dependencies

MBSB should also consider dependencies behind dependencies.

A technology service provider may itself rely upon:

Cloud Infrastructure → Telecommunications Provider → Data Centre → Specialist Software Provider

BNM highlights the risks arising from opaque supply chains and concentration among specialised providers where substitution during an outage may be difficult.

The principal output of this stage should therefore be an end-to-end Critical Business Service dependency map that provides sufficient visibility to support impact tolerance setting, vulnerability assessment and scenario testing.

 

Stage 3: Set Impact Tolerance

[Implement Phase – Stage 3]
Defining the Boundary of Unacceptable Disruption

Once MBSB understands its Critical Business Services and their dependencies, it can determine the maximum level of disruption it can tolerate before the resulting impact becomes unacceptable.

This threshold is the Impact Tolerance.

BNM describes tolerance for disruption as establishing a clear boundary between what is acceptable and unacceptable, including consideration of how long a critical operation or service can be unavailable, how much impact can occur before customers or markets experience harm, and what minimum service level should be maintained during disruption.

Impact tolerance should therefore be established primarily from the perspective of the service's outcome and the harm arising from its disruption.

This distinguishes it from traditional recovery metrics.

Impact Tolerance versus MTD and RTO

MBSB may already use:

Maximum Tolerable Downtime (MTD) – the maximum duration for which a business function can be unavailable before its consequences become unacceptable.

Recovery Time Objective (RTO) – the target period within which a resource, system or activity should be restored.

These remain valuable.

However, BNM observes that internal recovery metrics such as MTD and RTO may not be sufficient on their own, as operational resilience should also account for the external consequences of disruption, particularly the impact on customers and stakeholders.

Impact tolerance therefore provides the service-level boundary, while RTO and other recovery metrics help individual supporting components operate within that boundary.

MBSB Example

Assume MBSB establishes an illustrative impact tolerance for its Customer Funds Transfer Service based upon:

The maximum duration and scale of disruption that can occur before customers' inability to transfer funds creates unacceptable harm.

The supporting assessment could consider:

  • duration of service unavailability;
  • number of customers affected;
  • transaction volumes;
  • value of transactions delayed;
  • customer groups affected;
  • availability of alternative channels;
  • time of day or payment cycle;
  • complaints and customer harm;
  • regulatory implications; and
  • possible impact on counterparties or other market participants.

A disruption of thirty minutes during a low-volume period may have very different consequences from thirty minutes during salary crediting, a major payment period or another high-volume event.

BNM similarly notes that even relatively short disruptions may have disproportionate consequences for customers during peak periods.

The principal output of this stage should be approved and clearly justified Impact Tolerances for each Critical Business Service, supported by appropriate metrics and escalation thresholds.

 

Stage 4: Conduct Scenario Testing

[Implement Phase – Stage 4]
Testing Whether MBSB Can Remain Within Impact Tolerance

Once impact tolerance has been established, MBSB must determine whether its existing resilience arrangements can maintain the Critical Business Service within that tolerance.

This is achieved through Scenario Testing.

BNM emphasises that testing isolated failures is no longer sufficient. Scenarios should be severe enough to reveal deficiencies while remaining reasonably plausible and should challenge assumptions through concurrent or multi-layered failures.

Scenario testing therefore differs from an exercise designed merely to demonstrate that a plan works.

Its purpose is to find vulnerabilities before an actual disruption exposes them.

Designing MBSB Scenarios

Scenario design could consider combinations of:

  • major application failure;
  • cyberattack or ransomware;
  • data corruption;
  • telecommunications outage;
  • cloud service disruption;
  • critical third-party failure;
  • loss of key personnel;
  • unavailability of premises;
  • regional power outage;
  • infrastructure failure;
  • concurrent supplier and internal system disruption; or
  • major disruption during peak transaction periods.

The scenario should be related to a specific Critical Business Service and should challenge the end-to-end dependency chain mapped in the preceding stage.

MBSB Example

For the Customer Funds Transfer Service, MBSB could test the following severe but plausible scenario:

A cyber incident causes the primary payment processing environment to become unavailable during a high-volume period. At the same time, degradation at a telecommunications provider affects connectivity to an alternative processing environment.

The test could evaluate:

  • how quickly the incident is detected;
  • whether escalation is timely;
  • whether alternative processing arrangements remain available;
  • whether shared dependencies undermine redundancy;
  • whether MBSB can maintain minimum service levels;
  • how customers are informed;
  • how critical third parties respond;
  • whether management can make decisions with incomplete information;
  • whether the service exceeds its Impact Tolerance; and
  • what additional controls or investment may be necessary.

The critical question is not simply:

“Did MBSB recover the affected system?”

The operational resilience question is:

“Did MBSB continue or restore the Critical Business Service before disruption exceeded its approved Impact Tolerance?”

This service-level perspective makes scenario testing a meaningful validation of resilience rather than simply a technical recovery exercise.

 

Stage 5: Improve Lessons Learnt

[Implement Phase – Stage 5]
Converting Findings into Greater Resilience

Scenario testing, incidents and near misses will inevitably reveal weaknesses.

The final stage of the Implement Phase is therefore to ensure that these findings result in measurable improvements.

BNM explicitly identifies continuous improvement and learning as a core lesson from operational disruptions.

Financial institutions are expected to establish structured processes for incorporating insights from disruptions into future planning and to periodically update testing, processes, architecture and governance as risks evolve.

For MBSB, lessons learned should extend beyond the production of an after-action report.

Each significant finding should be considered in terms of:

MBSB Example

Suppose scenario testing identifies that the fallback arrangements for the Customer Funds Transfer Service depend upon the same telecommunications infrastructure as the primary environment.

The test has therefore revealed a common dependency that could undermine both primary and recovery arrangements.

MBSB could respond by:

  • assessing alternative network connectivity;
  • introducing greater provider diversity;
  • improving failover architecture;
  • strengthening contingency procedures;
  • revising the dependency map;
  • reassessing the relevant technology RTO;
  • repeating the scenario following remediation; and
  • reporting the vulnerability and remediation progress through operational resilience governance.

A lesson should only be considered properly addressed when the underlying weakness has been remediated or formally accepted within MBSB's risk governance framework.

Connecting the Five Implement Stages

The Implement Phase should operate as a single analytical and management sequence rather than five independent exercises.

The relationship can be represented as:

If MBSB identifies Critical Business Services but does not map their dependencies, it cannot fully understand their vulnerabilities.

If it maps dependencies but does not establish Impact Tolerances, it lacks a clear service-level boundary against which resilience can be assessed.

If it establishes Impact Tolerances but does not conduct sufficiently challenging testing, those tolerances remain largely theoretical.

If it conducts scenario testing without addressing identified vulnerabilities, the testing becomes a procedural exercise rather than a mechanism for improving resilience.

The value of the methodology therefore comes from the integration of all five stages.

 

Relationship with Existing MBSB Resilience Capabilities

The Implement Phase should not require MBSB to discard its established BCM, technology risk, operational risk or third-party risk arrangements.

Instead, it provides an organising framework for bringing these capabilities together to focus on critical service outcomes.

For example:

 

Existing Capability

Contribution to Operational Resilience

Business Continuity Management

Identifies critical business functions and establishes continuity and recovery arrangements

Technology and Disaster Recovery

Supports availability and recovery of critical systems and infrastructure

Operational Risk Management

Identifies and manages risks arising from people, processes, systems and external events

Cybersecurity

Protects critical services against cyber disruption

Third-party Risk Management

Manages dependencies on external providers

Crisis and Incident Management

Supports coordinated response and management decision-making

Operational Resilience

Integrates these capabilities around the continued delivery of Critical Business Services within Impact Tolerance

This reflects BNM's emerging approach.

The Discussion Paper states that operational resilience is not intended to displace existing requirements. Rather, framing existing capabilities around clearly defined resilience outcomes can provide greater structure and coherence.

For MBSB, the practical implication is important: operational resilience should connect existing capabilities rather than create another organisational silo.

 

Expected Outputs from the Implement Phase

When the five stages have been implemented effectively, MBSB should have a defined set of operational resilience outputs.

These should include:

Collectively, these outputs should enable Senior Management to answer five fundamental questions:

  • What services matter most?
  • What do they depend upon?
  • How much disruption can MBSB tolerate?
  • Can MBSB remain within those tolerances?
  • What is MBSB doing about known vulnerabilities?

 

From Implement to Sustain

Completion of the Implement Phase does not mean that MBSB has permanently achieved operational resilience.

Business services change. Technology architectures evolve.

New providers are introduced. Customer expectations increase. Threats emerge. Organisational structures change. Previously acceptable assumptions may therefore become obsolete.

BNM stresses that operational resilience is not a one-off exercise but a continuous journey that requires institutions to learn from disruptions and near misses, update testing, and improve processes, architecture, and governance as the operating environment changes.

The capabilities established during the Implement Phase must therefore transition into the Sustain Phase, where MBSB embeds operational resilience through:

The transition from Implement to Sustain changes the question from:

“Have we built the required operational resilience capabilities?”

to:

“How do we ensure those capabilities remain effective as MBSB changes?”

The Implement Phase represents the practical core of MBSB's Operational Resilience Planning Methodology.

It converts the strategic foundations established during the Plan Phase into measurable resilience capabilities centred on the continued delivery of Critical Business Services.

Through Identify Critical Business Services, MBSB determines which service outcomes require priority protection.

Through Map Interconnections and Interdependencies, it develops an end-to-end understanding of the people, processes, technology, data, facilities, and external providers that support those services.

Set Impact Tolerance establishes the boundary between acceptable and unacceptable disruption.

Conduct Scenario Testing determines whether MBSB can remain within that boundary under severe but plausible conditions. Finally, Improve Lessons Learnt ensures that vulnerabilities revealed through testing, incidents and near misses lead to corrective action and stronger resilience.

This five-stage approach closely reflects the direction articulated by BNM in its 2025 Discussion Paper, particularly its emphasis on critical services, dependency visibility, disruption tolerances, severe-but-plausible testing and continuous improvement.

BNM's broader direction also reinforces the importance of moving from a primarily recovery-focused model towards a more forward-looking, resilience-first approach within Malaysia's increasingly digital and interconnected financial environment.

For MBSB, the Implement Phase therefore provides the bridge between understanding operational resilience and demonstrating operational resilience in practice.

Its effectiveness will ultimately be determined not by the volume of plans, maps, or test reports produced, but by whether MBSB can continue to deliver its most critical business services during significant disruption.

Blogs marked [x] are under construction

C1 C2 C8 C14
"Implement" Phase of the Operational Resilience Planning Methodology
C8 [x] C9 [x] C10 [x] C11 [x] C12 [x] C13 [x]

 

Gain Competency: For organisations looking to accelerate their journey, BCM Institute’s training and certification programs, including the OR-5000 Operational Resilience Expert Implementer course, provide in-depth insights and practical toolkits for effectively embedding this model.

 

More Information About OR-5000 [OR-5] or OR-300 [OR-3]

To learn more about the course and schedule, click the buttons below for the OR-300 Operational Resilience Implementer course and the OR-5000 Operational Resilience Expert Implementer course.

If you have any questions, click to contact us.