eBook OR

[OR] [MBSB] [E2] [P3] [C14] Five Stages of the "Sustain" Phase

Written by Moh Heng Goh | Aug 26, 2026, 10:12:02 AM

Introduction to MBSB’s “Sustain” Phase of the Operational Resilience Planning Methodology

Introduction

Operational resilience is not achieved simply because MBSB has identified its Critical Business Services, mapped their interconnections and interdependencies, established Impact Tolerances, and completed scenario testing.

These activities create an important operational resilience capability, but that capability can weaken over time if it is not embedded, maintained, reviewed and improved.

The Sustain Phase of MBSB’s Operational Resilience Planning Methodology is therefore concerned with ensuring that operational resilience becomes a continuing organisational capability rather than a one-time implementation initiative.

For MBSB, this means embedding resilience into organisational behaviour, management communication, staff competencies, ongoing assessment and independent assurance. It also means ensuring that operational resilience keeps pace with changes in business services, technology, outsourcing arrangements, customer expectations, emerging threats and regulatory developments.

This direction is strongly aligned with Bank Negara Malaysia’s 2025 Discussion Paper on Operational Resilience.

BNM states that operational resilience is not a one-off exercise but a continuous journey that requires financial institutions to learn from disruptions and near misses, periodically update testing, and improve their processes, architecture, and governance structures as the operating environment evolves.

BNM also places leadership and organisational culture at the centre of operational resilience, noting that Boards and Senior Management should take ownership of resilience outcomes and ensure that critical services are understood, adequately resourced and supported by effective oversight across technology, operations and risk.

MBSB’s Sustain Phase consists of five stages:

Together, these stages ensure that the operational resilience capabilities created through the Plan and Implement phases remain relevant, effective and embedded within MBSB’s business-as-usual activities.

 

The purpose of this chapter is to introduce the reader to the Sustain Phase and explain why operational resilience must continue after the initial implementation of processes, controls and testing arrangements.

The chapter prepares the reader to understand how MBSB can transition operational resilience from a programme of implementation into an established organisational capability.

This distinction is important because resilience can deteriorate without active maintenance. Critical Business Services may change. New applications may be introduced. Existing systems may migrate to new technology platforms.

Third-party providers may change. Business processes may be redesigned. New cyber threats may emerge.

Employees with key resilience responsibilities may move to different roles. Impact Tolerances and dependency maps that were valid when first developed may therefore no longer reflect the organisation’s current operating environment.

BNM recognises this challenge by emphasising that periodic reviews, updated testing and improvements are required to ensure operational resilience keeps pace with a changing environment.

By the end of this chapter, the reader should be able to:

  • explain the purpose of MBSB’s Sustain Phase;
  • understand the five stages and how they work together;
  • recognise why cultural change is necessary to embed operational resilience;
  • understand the role of internal and external communication in resilience;
  • determine how training and awareness should be tailored to different organisational roles;
  • understand how self-assessment enables MBSB to periodically evaluate its own operational resilience capability;
  • recognise the role of independent quality review in providing objective challenge and assurance; and
  • understand how the Sustain Phase creates a continuous improvement loop back into planning and implementation.

The intended outcome is that operational resilience becomes part of how MBSB operates, governs, changes and makes decisions, rather than remaining a specialist activity owned by a limited group of resilience practitioners.

 

The Sustain Phase

The Sustain Phase focuses on maintaining MBSB’s operational resilience capability over time.

The five stages address five fundamental questions:

 

Sustain Stage

Key Question for MBSB

1. Introduce Cultural Change

Are resilience considerations reflected in organisational behaviour and decision-making?

2. Develop Communication Strategy

Can relevant stakeholders receive the right information before, during and after disruption?

3. Implement Training and Awareness

Do people understand their responsibilities and possess the capability to perform them?

4. Provide Self-assessment

Can MBSB determine whether its resilience arrangements remain effective?

5. Conduct Independent Quality Review

Is there objective challenge and assurance over the operational resilience framework?

The Sustain Phase therefore moves operational resilience from implementation into institutionalisation.

BNM recognises that stronger operational resilience requires organisational alignment, long-term commitment and sustained momentum.

The Discussion Paper also acknowledges that institutions face competing pressures involving cost, innovation, efficiency, customer experience and risk, making strong governance and organisational commitment essential for sustained improvement.

For MBSB, this means resilience considerations should eventually become part of normal business decisions involving technology investment, product development, outsourcing, business change, operational risk, budgeting and strategic planning.

 

Stage 1: Introduce Cultural Change

[Sustain Phase – Stage 1]
Embedding Resilience into Organisational Behaviour

The first stage of the Sustain Phase is to establish an organisational culture that supports operational resilience.

Operational resilience is not sustained solely through policies, procedures and technical controls. It also depends upon how people behave when risks, weaknesses and disruptions emerge.

An appropriate resilience culture should encourage employees and management to:

  • identify vulnerabilities early;
  • escalate concerns promptly;
  • report near misses;
  • challenge assumptions;
  • consider resilience implications when making decisions;
  • recognise the importance of critical service continuity;
  • avoid accepting unnecessary single points of failure; and
  • learn openly from operational disruption.

BNM identifies leadership and culture as central to operational resilience. It also warns that incentives focused excessively on cost efficiency, delivery speed or incident minimisation can unintentionally discourage transparency, early escalation and investment in preventive controls.

This has important implications for MBSB. A strong resilience culture is not one in which operational incidents never occur.

Rather, it is one in which employees identify weaknesses early, escalate them transparently and take timely action to prevent a weakness from becoming a major disruption.

MBSB Example

Suppose a technology team identifies that a key system supporting a Critical Business Service is approaching capacity limits during peak transaction periods.

In a weak resilience culture, the issue might be deferred because no major outage has yet occurred and additional infrastructure expenditure may compete with other priorities.

In a resilience-oriented culture, the potential vulnerability would be escalated based on its possible impact on the Critical Business Service. Business, Technology, Risk and Finance stakeholders could then collectively determine whether mitigation or investment is required.

Similarly, if an employee identifies a near miss involving a third-party service interruption, the organisational response should encourage reporting and analysis rather than discourage escalation, even if the customer ultimately experienced no visible disruption.

This behaviour reflects the BNM emphasis on transparency, early escalation and timely remediation of identified weaknesses.

Cultural Change as an Ongoing Process

Cultural change should not be treated as an awareness campaign with a defined completion date.

MBSB should reinforce expected behaviours through:

  • leadership messages;
  • governance discussions;
  • performance objectives;
  • risk and control assessments;
  • incident reviews;
  • scenario exercises;
  • management decision-making;
  • change approval processes; and
  • recognition of appropriate resilience behaviours.

The practical objective is for employees to ask:

“What could this decision mean for the resilience of our Critical Business Services?”

as part of normal business activity.

 

Stage 2: Develop Communication Strategy

[Sustain Phase – Stage 2]
Ensuring Timely and Effective Resilience Communication

Operational resilience depends heavily upon communication.

During disruption, uncertainty can be as damaging as the underlying operational failure. Incomplete, delayed or inconsistent communication may affect customers, employees, regulators, counterparties and third-party providers.

MBSB should therefore develop a structured Operational Resilience Communication Strategy covering communication:

  • before disruption, to establish awareness and preparedness;

  • during disruption, to support coordinated response and informed decision-making; and

  • after disruption, to communicate recovery status, findings and improvement actions where appropriate.

BNM’s 2025 Discussion Paper identifies improved incident communication outcomes as one area that may warrant further regulatory development as operational resilience practices evolve.

Stakeholder Groups

MBSB’s communication arrangements should consider different stakeholder groups, including:

  • Board and Senior Management;
  • Critical Business Service owners;
  • operational teams;
  • Technology and Cybersecurity;
  • BCM and Crisis Management teams;
  • Risk and Compliance;
  • customers;
  • third-party service providers;
  • relevant financial infrastructure participants; and
  • BNM and other authorities that require notification.

Each audience requires different information.

Senior Management may require information on the extent of disruption, customer impact, whether Impact Tolerance is at risk of being breached, and decisions requiring escalation.

Operational teams require specific information regarding response actions and priorities.

Customers require timely, clear and understandable information on service availability, alternatives and expected restoration.

MBSB Example

Consider an outage affecting a Critical Business Service that enables customers to perform digital banking transactions.

MBSB’s communication strategy could define:

Operational escalation

Technology and operations teams immediately escalate the disruption through established incident management arrangements.

Management communication

Senior Management receives information about affected services, expected customer impact, restoration options and proximity to the approved Impact Tolerance.

Customer communication

Customers receive clear information through appropriate channels regarding the affected service and available alternatives.

Regulatory communication

Where regulatory reporting thresholds apply, the appropriate MBSB function coordinates timely notification to BNM.

Third-party communication

Critical external providers are engaged through established escalation channels to support diagnosis and recovery.

The communication strategy should establish responsibilities, approval authorities, communication channels and escalation thresholds before disruption occurs.

 

Stage 3: Implement Training and Awareness

[Sustain Phase – Stage 3]
Building Organisational Capability

People cannot fulfil operational resilience responsibilities effectively unless they understand what is expected of them.

Training and awareness should therefore be designed according to the responsibilities of different stakeholder groups rather than relying on a single generic programme.

BNM emphasises the importance of Board and Senior Management capability, noting that effective oversight requires sufficient understanding to challenge architectural decisions, interpret resilience indicators, assess third-party dependencies, and evaluate whether scenario testing genuinely validates end-to-end resilience.

For MBSB, operational resilience learning can therefore be structured according to role.

Board and Senior Management

Training should provide sufficient understanding to:

  • oversee the Operational Resilience Framework;
  • approve or challenge Critical Business Services;
  • understand Impact Tolerances;
  • interpret scenario-testing outcomes;
  • evaluate major vulnerabilities;
  • make informed resilience investment decisions; and
  • hold accountable executives responsible for remediation.

BNM specifically describes Board responsibilities as including oversight of operational resilience, approval of critical operations or services, setting Impact Tolerances, reviewing resilience-testing results and holding Senior Management accountable for outcomes.

Critical Business Service Owners

Service owners should understand:

  • service boundaries;
  • interconnections and dependencies;
  • Impact Tolerances;
  • vulnerabilities;
  • scenario-testing responsibilities;
  • remediation requirements; and
  • escalation arrangements.
Technology, Cybersecurity and Operations Teams

Training could focus on:

  • the connection between individual systems and Critical Business Services;
  • shared dependencies;
  • recovery priorities;
  • minimum service levels;
  • incident escalation; and
  • consequences of exceeding Impact Tolerance.
General Employees

Awareness should help employees understand:

  • what operational resilience means;
  • why disruption cannot always be prevented;
  • their responsibility to report incidents and weaknesses;
  • business continuity and escalation arrangements; and
  • the importance of maintaining customer services.
MBSB Example

MBSB could implement an annual operational resilience learning programme consisting of:

  • Board and Senior Management briefings;
  • service-owner workshops;
  • targeted training for BCM, Risk, Technology and operational teams;
  • scenario-based exercises; and
  • organisation-wide awareness communications.

Rather than measuring success solely by training completion rates, MBSB should consider whether participants can apply the knowledge during exercises and actual disruptions.

 

Stage 4: Provide Self-Assessment

[Sustain Phase – Stage 4]
Periodically Evaluating MBSB’s Own Resilience

The fourth stage requires MBSB to periodically assess whether its operational resilience arrangements remain appropriate and effective.

Self-assessment provides a structured opportunity to step away from routine operational activities and examine the organisation’s overall resilience position.

The assessment should not simply ask:

“Have the required documents been completed?”

It should ask:

“Can MBSB demonstrate that its Critical Business Services remain resilient within approved Impact Tolerances?”

 

This outcome-focused approach is consistent with BNM’s emerging direction, which is anchored on critical services, dependency visibility, strong governance, realistic scenario testing and continuous improvement.

Areas for Self-assessment

MBSB could assess whether:

  • the Critical Business Service inventory remains current;
  • service boundaries remain appropriate;
  • service ownership is clear;
  • dependency maps accurately reflect current arrangements;
  • third-party dependencies remain adequately managed;
  • Impact Tolerances remain appropriate;
  • testing covers sufficiently severe but plausible scenarios;
  • scenario findings have been remediated;
  • identified weaknesses are being escalated appropriately;
  • staff training remains current;
  • governance reporting provides adequate information; and
  • significant business or technology changes have altered the resilience profile.
MBSB Example

Assume MBSB has implemented a major technology change affecting a Critical Business Service during the year.

As part of its self-assessment, the service owner may identify that the underlying technology architecture has changed, but the service dependency map still reflects the previous environment.

The self-assessment would flag the mapping as outdated and require it to be revised.

MBSB may then determine that the architecture change also affects the assumptions supporting its scenario testing and possibly its Impact Tolerance.

The resulting action could require:

Update dependency map → Review resilience assumptions → Reassess vulnerabilities → Update scenario → Re-test

In this way, self-assessment becomes a mechanism for maintaining the accuracy of the entire operational resilience framework.

Reporting the Self-assessment

Significant findings should be reported through MBSB’s governance arrangements.

Senior Management should be able to understand:

  • areas of resilience strength;
  • significant weaknesses;
  • overdue remediation;
  • emerging vulnerabilities;
  • areas approaching or exceeding risk tolerance; and
  • actions requiring management attention.

This supports the forward-looking reporting approach highlighted by BNM. The Discussion Paper notes that centralised accountability should facilitate timely escalation, remediation and consistent, structured reporting on operational resilience risks.

 

Stage 5: Conduct an Independent Quality Review

[Sustain Phase – Stage 5]
Providing Objective Challenge and Assurance

Self-assessment is valuable, but it cannot provide the same level of independence as an objective quality review.

The final stage of the Sustain Phase therefore introduces Independent Quality Review.

The purpose is to determine whether MBSB’s operational resilience framework is:

  • appropriately designed;
  • consistently implemented;
  • supported by adequate evidence;
  • aligned with governance expectations;
  • capable of meeting its intended outcomes; and
  • subject to effective remediation where weaknesses exist.

The independent review should challenge assumptions rather than simply confirm the existence of documentation.

Independence of Review

Depending on MBSB’s governance model, the review may be conducted by an appropriately independent assurance function or competent external party.

The key principle is that reviewers should be sufficiently independent of those responsible for designing and operating the resilience arrangements being assessed.

BNM’s Discussion Paper recognises the value of independent assurance mechanisms in the broader operational resilience ecosystem and cites approaches such as independent third-party audits among possible assurance mechanisms.

MBSB Example

An independent reviewer could select MBSB’s Customer Funds Transfer Service and assess the complete resilience chain.

The review might examine:

Critical Business Service Identification

Is there clear justification for why the service is considered critical?

Interconnection and Interdependency Mapping

Are internal and external dependencies complete and current?

Impact Tolerance

Is the tolerance supported by clear customer, financial, regulatory and service considerations?

Scenario Testing

Are scenarios genuinely severe but plausible, or have they been designed primarily to produce successful outcomes?

Remediation

Have weaknesses identified through testing and incidents been addressed within agreed timelines?

Governance

Does Senior Management receive sufficient information to challenge the service’s resilience posture?

 

If the review identifies weaknesses, these should be documented, assigned to accountable owners, prioritised according to risk and monitored through MBSB’s governance arrangements.

Independent Quality Review therefore closes the assurance loop by providing objective challenge over both the design and effectiveness of operational resilience.

 

How the Five Sustain Stages Work Together

The five Sustain stages should operate as an integrated lifecycle.

A dependency map can technically remain on file for several years, but it may no longer be useful if MBSB changes its technology architecture.

A scenario-testing programme can continue annually, but it may provide little value if the scenarios no longer reflect emerging threats.

Training can be completed, but employees may still be unable to perform effectively under disruption.

The Sustain Phase is therefore designed to test whether operational resilience remains current, understood, embedded and effective.

 

Role of Governance in Sustaining Operational Resilience

Governance runs through all five Sustain stages.

BNM’s 2025 Discussion Paper states that operational resilience should be a Board-level priority, with Boards playing a role in approving critical services, setting Impact Tolerances, reviewing resilience-testing results and holding Senior Management accountable for resilience outcomes.

BNM further notes that operational resilience crosses multiple domains, including technology, risk management, operations, business, outsourcing and cybersecurity. Working in silos can therefore create organisational blind spots and weaken integrated oversight.

For MBSB, sustained governance should therefore ensure that:

  • resilience responsibilities remain clearly assigned;
  • Critical Business Service owners remain accountable;
  • significant vulnerabilities receive appropriate escalation;
  • overdue remediation is visible to management;
  • resilience implications are incorporated into strategic and investment decisions;
  • scenario-testing results receive appropriate challenge; and
  • changes in the operating environment trigger reassessment where required.

BNM also identifies the importance of assigning ultimate accountability for operational resilience while recognising that other senior executives retain responsibilities within their respective areas, such as technology, cyber resilience, operations, risk appetite and critical business services.

Operational resilience therefore requires both central accountability and distributed responsibility.

 

Integrating Operational Resilience into Business-as-Usual Activities

The long-term objective of the Sustain Phase is for operational resilience considerations to become part of MBSB’s normal management processes.

Examples include incorporating resilience into:

Change Management

Material changes affecting Critical Business Services should trigger review of dependencies, Impact Tolerances, and testing requirements.

New Product and Service Development

Resilience should be considered when designing new customer services rather than added after deployment.

Technology Investment

Architecture decisions should consider common dependencies, redundancy, failover capability and end-to-end service impact.

Third-party Management

New and existing providers should be assessed according to the critical services they support and the consequences of provider failure.

Risk Management

Operational resilience vulnerabilities should feed into MBSB’s operational risk processes and risk reporting.

Strategic Planning

Major transformation programmes should consider their impact on Critical Business Services.

Incident and Crisis Management

Response priorities should be informed by service criticality and Impact Tolerance.

This integration is consistent with BNM’s view that operational resilience should provide structure and coherence to capabilities that financial institutions already maintain through BCM, technology governance, third-party management, operational risk and governance.

 

Expected Outputs from the Sustain Phase

Effective implementation of the Sustain Phase should produce a set of practical outputs for MBSB.

These could include:

 

Sustain Stage

Illustrative Output

Introduce Cultural Change

Operational Resilience Culture and Change Programme

Develop Communication Strategy

Operational Resilience Communication Strategy and Escalation Protocol

Implement Training and Awareness

Role-based Training and Awareness Programme

Provide Self-assessment

Periodic Operational Resilience Self-assessment Report

Conduct Independent Quality Review

Independent Operational Resilience Quality Review Report and Remediation Plan

These outputs should not exist merely to demonstrate completion of the methodology.

Their value lies in whether they provide MBSB with reliable mechanisms to identify deterioration, emerging risk and improvement opportunities before these result in intolerable disruption.

 

Completing the Operational Resilience Lifecycle

The Sustain Phase completes MBSB’s three-phase Operational Resilience Planning Methodology:

Operational resilience should operate as a continuous management cycle, not a three-phase project with a fixed end date.

Findings from self-assessment, independent review, actual incidents, emerging risks or regulatory developments may reveal that MBSB needs to reassess its maturity, analyse new gaps or revise its Operational Resilience Strategy and Roadmap.

Similarly, a significant business acquisition, a new digital service, a technology transformation, or a material outsourcing arrangement could change MBSB’s Critical Business Services and dependencies sufficiently to require parts of the Implement Phase to be revisited.

This continuous loop reflects BNM’s stated future direction, which describes an outcome-focused approach anchored on critical operations and services, deep dependency visibility, strong governance, realistic scenario testing and continuous improvement.

 

The Sustain Phase ensures that the operational resilience capability developed by MBSB through the Plan and Implement phases remains effective as the organisation and its operating environment change.

Through Introduce Cultural Change, MBSB seeks to embed resilience into behaviours and decision-making.

Develop a Communication Strategy to ensure that relevant stakeholders receive accurate and timely information before, during, and after disruption.

Implement Training and Awareness to build the knowledge and competencies required at the Board, management, service-owner, and employee levels.

Provide self-assessment, enabling MBSB to periodically evaluate whether its Critical Business Services and supporting resilience arrangements remain fit for purpose.

Finally, Conduct Independent Quality Review provides objective challenge and assurance that the Operational Resilience Framework is appropriately designed, implemented and maintained.

The significance of the Sustain Phase is reinforced by BNM’s view that operational resilience requires long-term commitment, organisational alignment and continuous improvement.

BNM identifies leadership, culture, governance, and accountability as central to resilience and expects financial institutions to continually learn from disruptions and near misses, while updating testing, processes, architecture, and governance as circumstances evolve.

For MBSB, the Sustain Phase therefore changes operational resilience from something the organisation implements into something the organisation continually practises.

When the three phases operate together, operational resilience becomes a recurring cycle:

 

Blogs marked [x] are under construction

C1 C2 C8 C14
"Sustain" Phase of the Operational Resilience Planning Methodology
C14 [x] C15 [x] C16 [x] C17 [x] C18 [x] C19 [x]

Gain Competency: For organisations looking to accelerate their journey, BCM Institute’s training and certification programs, including the OR-5000 Operational Resilience Expert Implementer course, provide in-depth insights and practical toolkits for effectively embedding this model.

 

More Information About OR-5000 [OR-5] or OR-300 [OR-3]

To learn more about the course and schedule, click the buttons below for the OR-300 Operational Resilience Implementer course and the OR-5000 Operational Resilience Expert Implementer course.

If you have any questions, click to contact us.