Operational resilience moves from concept to reality when an organisation begins applying its framework to the business services that matter most.
Understanding the organisation, establishing an Operational Resilience (OR) Planning Methodology, defining governance arrangements, and identifying Critical Business Services (CBSs) provide the foundation.
The next step is to translate that foundation into practical implementation.
This third and final eBook in the Operational Resilience in Action: The MBSB Approach series focuses on that transition.
Titled Starting Your OR Implementation, this eBook provides a structured approach for MBSB to commence the practical implementation of operational resilience across its identified Critical Business Services.
It brings together the implementation submissions prepared by the respective business units and provides a consistent basis for documenting, reviewing, challenging, and improving the resilience of these services.
The emphasis is practical. Rather than explaining operational resilience only as a concept, the eBook demonstrates how MBSB can progressively develop the information required to understand how its Critical Business Services are delivered, what they depend upon, how much disruption can be tolerated, what could seriously disrupt them, and whether existing resilience arrangements are capable of keeping disruption within acceptable limits.
The first two eBooks therefore serve as pre-reading and implementation guidance for this final eBook.
The progression can be viewed simply as:
This third eBook is where the outputs developed during the earlier stages begin to be translated into detailed, service-level resilience information.
Each Critical Business Service should be examined consistently so that MBSB can progressively develop an end-to-end understanding of how the service operates and how it could withstand disruption.
The eBook therefore provides a common implementation structure for business units to document their respective Critical Business Services and supporting arrangements.
The resulting submissions should enable MBSB to:
The objective is not simply to produce documentation. The information generated should support decision-making, prioritisation, investment, scenario testing, remediation, and ongoing management of operational resilience.
For this implementation, the following Critical Business Services form the working CBS catalogue for MBSB:
|
CBS |
Critical Business Service |
|
CBS-1 |
Customer Deposit and Account Access Services |
|
CBS-2 |
Domestic Funds Transfer and Payment Services |
|
CBS-3 |
Digital Banking Services |
|
CBS-4 |
Cash Access and Cash Transaction Services |
|
CBS-5 |
Financing Account Servicing and Repayment Services |
|
CBS-6 |
Corporate Payment and Bulk Transaction Services |
|
CBS-7 |
High-Value and Interbank Payment Services |
|
CBS-8 |
Customer Transaction Authentication and Authorisation Services |
|
CBS-9 |
Customer Support and Assistance During Banking Disruptions |
The catalogue should not be regarded as static.
As MBSB's products, delivery channels, technologies, outsourcing arrangements, customer expectations, and regulatory obligations evolve, the organisation should periodically review whether the services identified as critical remain appropriate.
The implementation is organised around five sequential and interconnected stages.
The first stage develops a detailed understanding of how each Critical Business Service is delivered end-to-end.
A Critical Business Service may appear straightforward when viewed from the customer's perspective, but its delivery can involve numerous processes, systems, business units, people, facilities, data flows, third parties, and supporting activities.
The Detailed Processes [DP] stage breaks the CBS into its constituent processes and activities.
For example, the delivery of a payment service may involve customer initiation, authentication, transaction validation, processing, fraud screening, payment routing, settlement, confirmation, exception handling, and customer support.
Documenting these processes establishes the foundation for the subsequent resilience analysis.
Key question:
Once the detailed processes are understood, MBSB needs to identify the resources, relationships, and dependencies supporting them.
The Map Interconnections and Interdependencies [MII] stage develops an end-to-end view of the people, processes, technology, information, facilities, third parties, infrastructure, and other resources that the Critical Business Service depends on.
This stage should also consider dependencies between Critical Business Services.
For example, Digital Banking Services may depend upon Customer Transaction Authentication and Authorisation Services. Payment services may rely on common technology platforms, telecommunications infrastructure, external payment networks, data centres, cloud services, or third-party providers.
Understanding these relationships helps identify:
Key question:
Operational resilience recognises that disruptions cannot always be prevented.
The organisation must therefore determine the maximum level of disruption it can tolerate before the consequences become unacceptable.
The Establish Impact Tolerances [iTo] stage defines this boundary for each Critical Business Service.
Impact tolerances should be informed by the potential consequences of disruption, including impacts on customers, financial position, operations, regulatory obligations, reputation, counterparties, and the broader financial ecosystem where relevant.
Depending upon the service, an impact tolerance may incorporate measures such as:
The impact tolerance subsequently becomes an important reference point for scenario design and testing.
Key question:
Once dependencies and impact tolerances have been established, MBSB can consider the circumstances that could severely disrupt each Critical Business Service.
The Identify Severe but Plausible Scenarios [SbPS] stage focuses on credible events that are sufficiently severe to challenge existing resilience arrangements.
These scenarios should not be limited to historical incidents. They should consider circumstances that could reasonably occur even if MBSB has not previously experienced them.
Examples may include:
Scenario selection should be informed by the characteristics and dependencies of the CBS rather than applying identical scenarios to every service.
Key question:
The final stage converts the preceding analysis into practical resilience validation.
Scenario Testing [ST] evaluates whether MBSB can continue delivering, recover, or otherwise manage a Critical Business Service during a severe but plausible disruption without exceeding its established impact tolerance.
Testing should examine more than whether an existing continuity or recovery plan can be activated. It should evaluate the service from an end-to-end operational resilience perspective.
This may include assessing:
The outcome should identify both demonstrated resilience capabilities and areas requiring improvement.
Key question:
The five stages are deliberately connected:
Each stage provides information required by the next.
Detailed process information enables the identification of dependencies. Dependency mapping reveals potential vulnerabilities and informs the setting of meaningful impact tolerances.
Impact tolerances establish the boundary against which severe but plausible scenarios can be considered. Those scenarios then provide the basis for scenario testing.
The result is an implementation process that moves from understanding the service to demonstrating its resilience.
Operational resilience cannot be implemented effectively by a central OR, BCM, or Risk function acting alone.
Business units responsible for Critical Business Services play an important role because they possess the operational knowledge needed to explain how those services function.
Their submissions should therefore reflect practical operating knowledge rather than merely reproduce policies, procedures, or existing continuity documentation.
Business units should be able to explain:
How the service operates → What supports it → What could disrupt it → How much disruption is tolerable → Whether MBSB can remain within that tolerance
Central OR, BCM, Risk, Technology, Cybersecurity, Third-Party Risk, and other relevant functions can provide methodology, facilitation, review, challenge, and specialist input.
This combination of business ownership and specialist challenge is important for developing credible operational resilience assessments.
As a Malaysian financial services institution, MBSB operates within the regulatory environment established by Bank Negara Malaysia (BNM).
Accordingly, the implementation approach should be considered alongside applicable BNM requirements and supervisory expectations relating to areas such as business continuity, technology risk, operational risk, outsourcing and third-party arrangements, cyber resilience, incident management, and broader operational resilience.
The implementation should not be treated as an isolated compliance exercise.
Instead, operational resilience should bring together relevant capabilities across MBSB, enabling the organisation to develop a service-centred understanding of its ability to withstand disruption.
This eBook therefore provides an implementation structure through which MBSB's existing risk management and resilience capabilities can be connected around the continued delivery of its Critical Business Services.
This eBook forms part of the value-added implementation support provided to organisations undertaking BCM Institute's training-led operational resilience implementation approach.
Under this approach, participants not only learn the OR methodology during certification or competency-based training. They progressively apply the methodology to their own organisation.
Training provides knowledge and implementation guidance, while project submissions offer the opportunity to apply that knowledge to real-world Critical Business Services.
The approach can be summarised as:
This helps bridge the gap between professional education and organisational implementation.
For MBSB, the submissions developed through the five stages can progressively contribute to a practical body of operational resilience information that can be reviewed, challenged, updated, and used as the OR programme matures.
After the five stages, the submission for each Critical Business Service should provide a coherent resilience story.
It should enable management and reviewers to understand:
|
Implementation Question |
Expected Output |
|
How is the CBS delivered? |
Detailed Processes [DP] |
|
What supports and connects the CBS? |
Interconnects and Interdependencies [MII] |
|
How much disruption is acceptable? |
Impact Tolerance [iTo] |
|
What could severely disrupt the CBS? |
Severe but Plausible Scenarios [SbPS] |
|
Can the CBS withstand the disruption? |
Scenario Testing [ST] |
|
What weaknesses remain? |
Findings, gaps and vulnerabilities |
|
What needs to improve? |
Remediation and resilience improvement actions |
This creates traceability from service delivery through to resilience validation and improvement.
Operational resilience becomes meaningful when an organisation can demonstrate that it understands its critical services and has taken practical steps to ensure they can withstand disruption.
For MBSB, the nine identified Critical Business Services provide the focal point for this implementation.
The work begins by understanding each service in detail. It then progressively examines dependencies, tolerance for disruption, credible threats to service delivery, and the effectiveness of MBSB's existing resilience arrangements.
The implementation journey can therefore be expressed as:
The chapters that follow compile and structure the submissions from the respective business units across the five implementation stages.
Together, these submissions provide the basis for moving MBSB's Operational Resilience programme from methodology and planning into practical implementation, validation, and continuous improvement.
The ultimate objective is not to demonstrate that disruption will never occur.
It is to develop sufficient understanding, preparedness, and resilience so that, when disruption occurs, MBSB is better positioned to protect the continued delivery of the Critical Business Services that matter to its customers, stakeholders, and the wider financial system.
Blogs marked [x] are under construction
| eBook 3: Starting Your OR Implementation |
| CBS-1 | CBS-2 [x] | CBS-3 [x] | CBS-4 [x] | CBS-5 [x] | List of CBS |
| |
|||||
| CBF-6 [x] | CBS-7 [x] | CBS-8 [x] | eBook 1 | eBook 2 | eBook 3 |
| |
|
||||
| Consolidated Report (CR) | |||||
| DP [x] | MD [x] | MPR [x] | ITo [x] | SuPS [x] | ST [x] |
Gain Competency: For organisations looking to accelerate their journey, BCM Institute’s training and certification programs, including the OR-5000 Operational Resilience Expert Implementer course, provide in-depth insights and practical toolkits for effectively embedding this model.
To learn more about the course and schedule, click the buttons below for the [OR-3] OR-300 Operational Resilience Implementer course and the [OR-5] OR-5000 Operational Resilience Expert Implementer course.
|
If you have any questions, click to contact us. |
||
|
|