. .

Operational Resilience in Action: The MBSB Approach
BB OR [A] 18

[OR] [MBSB] [E3] [CBS] [1] [ITo] Establish Impact Tolerances

[OR] [MBSB] [Full Banner] Operational Resilience in Action The MBSB Bank's Approach

Setting an Impact Tolerance for CBS-1 Customer Deposit and Account Access Services establishes the boundary beyond which service disruption would cause an unacceptable level of harm to MBSB's customers, the organisation, connected financial institutions, or, in sufficiently severe circumstances, the wider financial system.

The Impact Tolerance should therefore be established from the perspective of the end-to-end customer outcome rather than from the recovery capability of an individual application, department or infrastructure component.

BCM Institute's Operational Resilience methodology similarly defines Impact Tolerance around the maximum tolerable disruption to a Critical Business Service and distinguishes it from conventional recovery objectives.

New call-to-action

Dr Goh Moh Heng
Operational Resilience Certified Planner-Specialist-Expert

x [OR] [MBSB] Legal Disclaimer Banner

New call-to-actionCBS-1 Customer Deposit and Account Services

Introduction

[OR] [MBSB] [E3] [CBS] [1] [ITo] Customer Deposit and Account Access Services

Setting an Impact Tolerance for CBS-1 Customer Deposit and Account Access Services establishes the boundary beyond which service disruption would cause an unacceptable level of harm to MBSB's customers, the organisation, connected financial institutions, or, in sufficiently severe circumstances, the wider financial system.

The Impact Tolerance should therefore be established from the perspective of the end-to-end customer outcome rather than from the recovery capability of an individual application, department or infrastructure component.

BCM Institute's Operational Resilience methodology similarly defines Impact Tolerance around the maximum tolerable disruption to a Critical Business Service and distinguishes it from conventional recovery objectives.

For CBS-1, this distinction is particularly important. A core account platform may technically be available, yet customers remain unable to access their accounts because authentication, digital channels, telecommunications, account information, or another shared dependency has failed.

Conversely, an individual process may be unavailable without immediately making the entire Critical Business Service unavailable where MBSB has effective alternative arrangements.

Accordingly, the assessment considers all 18 Sub-CBS processes previously identified for CBS-1. All 18 are included below.

Cyber and ICT risks are integrated directly into this assessment rather than treated as a separate technology exercise.

This is consistent with the direction of BNM's recent resilience work: BNM has stated that increased use of digital technology and shared systems raises the risk of disruption from cyber incidents and technical failures, and its updated technology-risk requirements seek to strengthen resilience against cyber threats, outages and data breaches.

 

Impact Tolerance Assessment Approach

For this implementation assessment, the following five-level scale is used to provide greater differentiation across the Sub-CBS processes:

 

Level

Interpretation for CBS-1

Very Low

Localised inconvenience with negligible effect on customers' ability to access deposits or account information.

Low

Limited degradation affecting a small customer population or non-essential service component, with readily available alternatives.

Medium

Material service degradation affecting customers or operations, but manageable through alternative arrangements before significant harm develops.

High

Serious disruption affecting customer access to funds, account information or essential account processing, with significant potential for financial, regulatory or reputational harm.

Very High

Widespread, prolonged or integrity-related disruption capable of causing severe customer harm, significant regulatory concern, loss of confidence or broader financial-system consequences.

This five-level implementation scale expands the underlying BCM Institute concept of distinguishing between inconvenience, harm, and intolerable harm, enabling MBSB to prioritise its processes and controls more precisely.

BCM Institute's methodology identifies the transition to intolerable harm as the critical boundary for Impact Tolerance.

Banner [Table] [OR] [E3] Establish Impact Tolerance

Table P4: Establish Impact Tolerance for CBS-1

Sub-CBS Code

Name of Sub-CBS

Potential Disruption

Potential Harm

Level of Harm

Key Harm Indicators

CBS-1.1

Deposit Account Establishment and Activation

Account-opening or activation capability becomes unavailable or materially degraded, preventing new accounts from being established or activated.

New customers may be unable to commence banking activity or access newly deposited funds. Backlogs may develop, but existing customers' account access would generally remain available.

Medium — material if prolonged, but normally less immediately harmful than loss of access to existing deposits.

Duration; number of accounts awaiting activation; backlog growth; customers unable to access newly funded accounts; geographic/channel scope; complaints.

CBS-1.2

Customer and Account Information Maintenance

Customer or account records cannot be amended, or updates are delayed, lost or incorrectly applied.

Customers may be unable to update details or mandates, resulting in authentication problems, misdirected information or inability to complete account servicing.

Medium — usually manageable temporarily, but harm increases where incorrect information prevents account access.

Duration; maintenance backlog; failed updates; percentage of affected accounts; incorrect records; complaints; access failures attributable to stale data.

CBS-1.3

Account Status and Access Administration

Account statuses, holds, restrictions, or reactivation instructions cannot be processed correctly.

Legitimate customers may be prevented from accessing funds, while incorrect removal of controls could expose accounts to unauthorised activity.

High — directly influences whether customers can access accounts safely.

Accounts incorrectly restricted; duration of restrictions; failed reactivations; customers denied access; control exceptions; unauthorised access events.

CBS-1.4

Deposit Receipt and Account Credit Processing

Incoming deposits or credits cannot be posted or are materially delayed.

Customers may not receive expected funds and could be unable to meet payment or liquidity needs. Reconciliation and complaints may increase.

High — prolonged delay can cause direct financial harm to customers.

Delayed credits; transaction value and volume; posting backlog; duration; affected customers; reconciliation breaks; complaints.

CBS-1.5

Account Balance and Transaction Record Processing

Core balance or transaction processing becomes unavailable, delayed or unreliable.

Customers may see incorrect balances, lose visibility of transactions or be unable to transact safely. Multiple interconnected services may also be affected.

Very High — central concentration point whose failure can impair the entire CBS and several other CBSs.

Duration; affected accounts; unavailable/incorrect balances; transaction backlog; data-integrity exceptions; channels affected; financial exposure.

CBS-1.6

Customer Account Enquiry and Information Access

Customers cannot view balances, transactions or account status through normal channels.

Customers cannot determine whether funds are available or whether transactions have completed, potentially affecting financial decisions and confidence.

High — severity rises rapidly if all enquiry channels are simultaneously unavailable.

Duration; percentage of customers affected; channels unavailable; enquiry failure rate; contact-centre demand; complaints.

CBS-1.7

Account Statement and Transaction Information Provision

Statements or historical transaction information become unavailable or delayed.

Customers may experience difficulties with reconciliation, financial administration, disputes or evidence requirements, although immediate access to funds may remain unaffected.

Medium — usually tolerable for a limited period if current account access remains available.

Statement delays; number of customers affected; historical data unavailable; backlog; complaints; statutory or regulatory reporting implications.

CBS-1.8

Account Access Request and Instruction Processing

Customer instructions cannot be received, routed or processed.

Customers may technically have active accounts but be unable to initiate permitted account activities, resulting in an effective loss of service.

High — directly affects practical customer use of the account.

Failed instructions; duration; percentage of requests rejected/unprocessed; channels affected; transaction backlog; customer complaints.

CBS-1.9

Account Access Validation and Control

Authentication, authorisation, or account control validation fails or becomes unavailable.

Legitimate customers may be denied access or, conversely, inappropriate access may occur. Failure can affect multiple access channels simultaneously.

Very High — combines availability and security consequences and may represent a common-mode dependency.

Authentication failure rate; customers locked out; unauthorised attempts accepted; channels affected; fraud/security events; duration.

CBS-1.10

Account Access Exception and Rejection Management

Failed access attempts and rejected instructions cannot be diagnosed or resolved.

Customers remain unable to access their accounts after the initial failure; unresolved cases accumulate, potentially masking a broader systemic problem.

Medium — potentially High where exceptions become widespread or prolonged.

Exception backlog; ageing cases; repeat failures; unresolved customer cases; escalation volumes; complaint trends.

CBS-1.11

Account Restriction and Access Restoration

Restrictions cannot be removed following a legitimate resolution, or are removed incorrectly.

Customers may remain unable to access funds unnecessarily, while premature restoration may expose accounts to security or compliance risks.

High — an extended lockout can cause significant harm to individual customers.

Number of restricted accounts; restriction duration; failed restoration; inappropriate releases; customer hardship cases; complaints.

CBS-1.12

Deposit Account Reconciliation and Integrity Management

MBSB cannot reconcile account postings or establish the accuracy of balances following processing errors or disruption.

Customer balances and transaction histories may become unreliable. MBSB may need to restrict account activity until integrity is established.

Very High — uncertainty over customer balances can make nominally available services unsafe to use.

Unreconciled items; value of discrepancies; number of affected accounts; reconciliation duration; incorrect balances; duplicate/missing postings.

CBS-1.13

Account Access Service Monitoring and Exception Escalation

Service degradation or systemic access failures are not promptly detected or escalated.

An initially manageable disruption may continue undetected, increasing the number of affected customers and reducing remaining time before the Impact Tolerance is breached.

High — monitoring failure magnifies other disruptions rather than necessarily creating the original failure.

Detection time; escalation time; missed alerts; error rates; backlog growth; customer reports preceding internal detection.

CBS-1.14

Customer Account Access Incident Management

Incident coordination, decision-making or cross-functional response fails during material disruption.

Recovery actions may be delayed or conflicting; customer impact increases and alternative arrangements may not be invoked in time.

Very High — ineffective incident management can convert a recoverable event into an Impact Tolerance breach.

Incident declaration time; decision delays; recovery milestones missed; customer population affected; unresolved actions; escalation to crisis level.

CBS-1.15

Disrupted Account Access Customer Assistance

Customers cannot obtain accurate information or assistance during a widespread disruption.

Customers may be unable to understand account status or alternative access arrangements. Vulnerable customers may experience greater financial harm.

High — customer harm may escalate even if technical recovery remains on schedule.

Contact-centre abandonment; wait times; complaints; unanswered enquiries; vulnerable-customer cases; inconsistent communications.

CBS-1.16

Alternative Account Access and Continuity Processing

Alternative channels, workarounds or continuity procedures fail when primary service is unavailable.

MBSB loses its principal means of limiting customer harm during disruptions, increasing the likelihood that CBS-1 will exceed its Impact Tolerance.

Very High — failure removes an important layer of resilience during an already severe incident.

Alternative capacity; percentage of normal demand supported; failed workaround transactions; customer coverage; activation time; shared dependency failures.

CBS-1.17

Deposit Account Processing Recovery and Reconciliation

Technology recovery fails, recovered data is incomplete, or transaction queues cannot be reconciled.

Outage duration extends, and restoration may introduce missing, duplicated, or inaccurate account transactions.

Very High — failed recovery can directly cause the Impact Tolerance to be exceeded.

Recovery elapsed time; failed recovery steps; RPO/data-loss position; unreconciled transactions; backlog; integrity exceptions.

CBS-1.18

Account Access Service Restoration and Validation

Service is restored technically but end-to-end validation is incomplete or instability persists.

Customers may encounter repeated outages, inaccurate balances, or failed transactions after declared restoration.

Very High — premature or incomplete restoration can compound harm and undermine confidence in recovered service.

Service stability; repeat incidents; error rates; reconciled accounts; transaction backlog; channels validated; customer complaints after restoration.

 

Principal Sub-CBS Affecting the Impact Tolerance

Although all 18 Sub-CBS contribute to CBS-1, several warrant particular attention because their disruption can rapidly affect the end-to-end customer outcome:

  • CBS-1.5 Account Balance and Transaction Record Processing — central source of authoritative account and transaction information.

  • CBS-1.9 Account Access Validation and Control — determines whether customers can safely gain access.

  • CBS-1.12 Deposit Account Reconciliation and Integrity Management — determines whether restored account information can be trusted.

  • CBS-1.14 Customer Account Access Incident Management — coordinates containment, continuity and recovery during severe disruption.

  • CBS-1.16 Alternative Account Access and Continuity Processing — provides the principal resilience mechanism when normal access is unavailable.

  • CBS-1.17 Deposit Account Processing Recovery and Reconciliation — determines whether processing can be restored before intolerable harm develops.

  • CBS-1.18 Account Access Service Restoration and Validation — establishes whether CBS-1 has actually returned to stable end-to-end operation.

These processes should therefore receive heightened attention when MBSB calibrates its resilience investment, scenario-testing programme and recovery capabilities.

Table 2: Cyber and ICT Risk Integration for CBS-1

Sub-CBS Code

Name of Sub-CBS

Cyber and ICT Risk Linkage

Contribution to Impact Tolerance Breach

Proactive Risk Management Action

Evidence of Proactive Risk Management

CBS-1.1

Deposit Account Establishment and Activation

Onboarding application failure; API disruption; identity-service outage; ransomware; failed technology change; data corruption

Prevents account creation/activation and can create sustained onboarding backlog.

Resilient onboarding architecture; controlled changes; API monitoring; secure backups; alternate onboarding procedures; cyber hardening.

Change test results; vulnerability assessments; API monitoring records; backup tests; continuity exercise records; remediation tracker.

CBS-1.2

Customer and Account Information Maintenance

Database failure; unauthorised modification; privileged-access compromise; application outage; data corruption

Incorrect or unavailable customer records may cause subsequent access or authentication failures.

Role-based access; privileged-access controls; database resilience; audit logging; integrity checks; backup and recovery testing.

Access reviews; privileged access logs; database failover reports; audit log reviews; control testing; restoration tests.

CBS-1.3

Account Status and Access Administration

Privileged-account compromise; application failure; unauthorised status change; integration failure

An incorrect account status may lock out customers or allow access contrary to controls.

Segregation of duties; maker-checker controls; privileged-access monitoring; automated reconciliation of status changes; resilient workflow.

Access certification; control-testing results; security monitoring records; exception reports; audit findings.

CBS-1.4

Deposit Receipt and Account Credit Processing

Interface/API failure; payment connectivity outage; transaction queue failure; data corruption; third-party ICT disruption

Credits cannot reach customer accounts, increasing customer financial harm as disruption persists.

Resilient interfaces; transaction queuing; duplicate controls; end-to-end monitoring; reconciliation; alternate connectivity.

Interface monitoring; failover tests; reconciliation reports; third-party assurance; incident exercises; capacity reports.

CBS-1.5

Account Balance and Transaction Record Processing

Core application failure; database outage; ransomware; data corruption; infrastructure outage; capacity degradation; technology concentration

Common failure may simultaneously remove balance information and transaction processing across several channels and interconnected CBSs.

High-availability architecture; tested disaster recovery; immutable/secured backups; database replication; capacity management; cyber segmentation; recovery rehearsals.

DR test reports; failover results; capacity reports; penetration tests; backup restoration evidence; cyber exercise results; management risk review.

CBS-1.6

Customer Account Enquiry and Information Access

DDoS; web/mobile outage; API failure; network disruption; authentication outage; infrastructure failure

Customers lose visibility of account balances and transactions, potentially across all digital channels.

DDoS protection; multi-channel capability; network resilience; API monitoring; capacity testing; alternate customer enquiry arrangements.

DDoS test/monitoring records; capacity tests; availability reports; channel failover tests; incident simulations.

CBS-1.7

Account Statement and Transaction Information Provision

Statement-generation failure; document repository outage; data corruption; digital-delivery failure

Customers lose formal account records; prolonged failure may create regulatory or customer servicing issues.

Resilient document repository; backup statement-generation capability; data-integrity controls; recovery procedures.

Recovery test results; data-quality reports; backup tests; service monitoring; remediation reports.

CBS-1.8

Account Access Request and Instruction Processing

API/middleware outage; channel application failure; network failure; failed software release; capacity overload

Customer instructions cannot reach the processing systems, even though the underlying accounts remain operational.

Resilient middleware; API redundancy; transaction queuing; controlled deployment; performance and capacity monitoring.

Change-management evidence; API availability reports; performance tests; failover tests; transaction-queue monitoring.

CBS-1.9

Account Access Validation and Control

Authentication outage; cyberattack; DDoS; identity-platform failure; credential compromise; privileged-access compromise

Widespread authentication failures can block legitimate customers across multiple channels; a security control failure may expose accounts to fraud.

Resilient authentication architecture; MFA controls; DDoS resilience; privileged-access management; alternative authentication procedures; continuous security monitoring.

Authentication availability reports; penetration tests; access reviews; SOC monitoring; cyber exercises; failover test results.

CBS-1.10

Account Access Exception and Rejection Management

Case-management outage; diagnostic monitoring failure; integration disruption

Failed cases cannot be investigated, allowing access problems to accumulate and potentially concealing systemic failure.

Resilient case management; exception dashboards; manual fallback procedures; escalation thresholds; monitoring integration.

Exception reports; continuity tests; incident records; monitoring and control tests; backlog reports.

CBS-1.11

Account Restriction and Access Restoration

Access-control failure; compromised administrator credentials; workflow outage; data synchronisation failure

Customers remain incorrectly restricted or unauthorised restoration occurs; widespread failure can materially increase harm.

Strong privileged-access controls; dual authorisation; synchronisation monitoring; restoration procedures; access reconciliation.

Privileged-access reviews; approval logs; exception reports; control tests; security monitoring records.

CBS-1.12

Deposit Account Reconciliation and Integrity Management

Data corruption; database inconsistency; missing transaction feeds; ransomware; recovery-data mismatch

MBSB cannot establish trustworthy balances, potentially requiring continued service restriction even after systems recover.

Automated reconciliation; integrity controls; immutable transaction logs; recovery-point validation; independent data verification.

Reconciliation reports; data-integrity testing; recovery tests; backup validation; exception logs; independent review findings.

CBS-1.13

Account Access Service Monitoring and Exception Escalation

Monitoring-platform outage; telemetry loss; security-monitoring failure; alert misconfiguration

Delayed detection consumes available tolerance and allows customer impact to expand before response begins.

Redundant monitoring; end-to-end service metrics; synthetic transaction monitoring; alert testing; independent monitoring paths.

Alert-test records; monitoring availability reports; incident detection metrics; SOC records; control testing.

CBS-1.14

Customer Account Access Incident Management

Collaboration-platform outage; cyberattack affecting incident tools; loss of communications; inaccurate ICT situational awareness

A delayed or ineffective response extends service disruption and may cause MBSB to exceed the tolerance boundary.

Alternate communication capability; cyber/ICT incident playbooks; crisis escalation criteria; regular integrated exercises; service-level dashboards.

Exercise reports; incident playbooks; lessons-learned reports; management committee minutes; action trackers.

CBS-1.15

Disrupted Account Access Customer Assistance

Contact-centre outage; telephony failure; CRM outage; DDoS on customer information channels

Customers cannot receive assistance while account access is disrupted, thereby magnifying harm and increasing pressure on the remaining channels.

Multi-channel communications; alternate contact-centre capability; surge-capacity planning; pre-approved disruption communications.

Contact-centre continuity tests; capacity exercises; communications exercises; call-volume monitoring; management review.

CBS-1.16

Alternative Account Access and Continuity Processing

Recovery environment shares failed infrastructure; network failure; alternative channel capacity exhaustion; authentication dependency

Apparent alternative arrangements fail simultaneously with primary services, removing MBSB's ability to contain customer harm.

Dependency-diverse recovery design; capacity testing; alternative network paths; independent authentication/recovery options where feasible; continuity rehearsals.

Architecture reviews; dependency assessments; capacity tests; failover reports; scenario-testing results; risk acceptance records.

CBS-1.17

Deposit Account Processing Recovery and Reconciliation

DR failure; backup corruption; ransomware persistence; replication failure; failed failover; network outage

Recovery exceeds planned duration or produces unreliable data, directly threatening the CBS Impact Tolerance.

Regular end-to-end DR testing; clean recovery capability; immutable backups; replication monitoring; recovery sequencing; cyber recovery exercises.

DR test reports; backup restore evidence; replication reports; cyber recovery exercise records; remediation tracking; management sign-off.

CBS-1.18

Account Access Service Restoration and Validation

Premature system restoration; residual malware; unresolved data corruption; interface instability; capacity degradation

Service may appear restored but remain unreliable, potentially causing repeated disruption or incorrect customer account information.

Formal restoration criteria; security validation; reconciliation sign-off; stability monitoring; phased restoration; post-recovery control checks.

Restoration checklist; security clearance; reconciliation sign-off; monitoring reports; post-incident review; management acceptance.

 

Cyber and ICT Risk as an End-to-End Resilience Issue

Cyber and ICT risks should not be viewed merely as risks to technology assets. For CBS-1, they are potential causes of customer harm.

BNM has recognised that greater dependence on digital technology and shared systems increases exposure to cyber incidents, outages and data breaches. Its recent work on technology risk and Operational Resilience reflects the need for financial institutions to continue delivering critical services despite severe operational disruption.

For MBSB, the most significant Cyber and ICT pathways to an Impact Tolerance breach include:

[OR] [PM] [E3] ITo] [CBF] Cyber and ICT Risk as an End-to-End Resilience IssueThe relevant question is therefore not simply, "Was the technology restored within its RTO?"

The more important Operational Resilience question is:

Did MBSB maintain or restore CBS-1 before disruption caused unacceptable harm to customers and other stakeholders?

 

Relationship Between Impact Tolerance and Traditional Recovery Metrics

Impact Tolerance should not replace MBSB's existing BCM and ICT recovery metrics. Those measures remain important, but they perform different roles.

 

Measure

Primary Purpose

Relationship to CBS-1 Impact Tolerance

Impact Tolerance

Defines the boundary beyond which disruption to CBS-1 causes unacceptable harm.

The overarching service-level resilience boundary.

RTO

Specifies the targeted time for recovering a process, application or technology component.

Should be set sufficiently inside the Impact Tolerance to allow integration, reconciliation and service validation before intolerable harm occurs.

RPO

Specifies the acceptable data-loss position following recovery.

Must support the data-integrity conditions of CBS-1; meeting a time tolerance while losing unacceptable account data would not constitute successful resilience.

MTPD

Identifies the maximum period a business activity can remain disrupted before unacceptable organisational impact develops.

Provides BCM input but may be process-oriented rather than focused on the external customer outcome of the CBS.

SLA

Establishes agreed performance commitments for internal or third-party services.

Supplier SLAs should support MBSB's Impact Tolerance but cannot determine it. A contractual target does not define the amount of customer harm MBSB can tolerate.

 

BCM Institute's guidance similarly distinguishes Impact Tolerance from RTO and other conventional time-based recovery measures.

A practical design principle is therefore:

Component RTOs, integration recovery, reconciliation, validation, and customer-channel restoration must collectively fit comfortably within the CBS Impact Tolerance.

 

Recommended Impact Tolerance for CBS-1 Customer Deposit and Account Access Services

Illustrative Recommendation

For implementation and scenario-design purposes, the following illustrative Impact Tolerance is recommended for MBSB:

MBSB should be capable of maintaining or restoring a minimum acceptable level of Customer Deposit and Account Access Services within four hours of a severe but plausible disruption, without widespread loss of customer access to deposited funds, material uncertainty over account balances or transaction integrity, or unacceptable customer, regulatory or financial-system harm.

The proposed four-hour boundary should not be interpreted as an RTO. It is the proposed outer customer-harm boundary for the Critical Business Service.

Supporting systems and processes should normally recover materially earlier than this threshold to provide sufficient time for reconciliation, end-to-end validation and controlled service restoration.

Proposed Impact Tolerance Dimensions

 

Impact Dimension

Illustrative Tolerance for CBS-1

Maximum disruption duration

4 hours before widespread loss of essential customer deposit/account access is considered potentially intolerable.

Essential service availability

At least one viable means of obtaining essential account information and accessing funds should be maintained or restored within the tolerance where reasonably practicable.

Customer scope

MBSB should avoid simultaneous inability of a material proportion of active customers to access their deposit accounts across all principal channels. As an initial implementation trigger, disruption affecting 10% or more of active customers, or a smaller population that involves significant harm to vulnerable customers, should require immediate escalation and management assessment.

Channel scope

Failure of one channel may remain tolerable where genuinely independent alternatives remain available and capable of absorbing demand. Simultaneous failure of all principal access channels should be treated as approaching the intolerance boundary significantly earlier.

Service degradation

Degraded operation may be tolerated where customers retain reliable access to essential services. Severe performance degradation that makes the service practically unusable should be treated as service unavailability.

Transaction backlog

Backlogs must remain at a level that can be reconciled and cleared without causing prolonged customer harm, duplicate processing, or unacceptable downstream impact.

Data latency

Temporary delayed account information may be tolerable where clearly controlled; prolonged presentation of materially stale balances should not be treated as acceptable service availability.

Data integrity

No tolerance for known material corruption of customer balances, unauthorised alteration or unreconciled loss of material customer transaction data. Where integrity cannot be established, the service should not be considered fully restored.

Authentication/security

Restoration must not bypass essential security or authorisation controls merely to achieve the time threshold.

Regulatory considerations

Disruption must remain manageable without causing material breach of applicable legal, regulatory, customer-protection or notification obligations.

Financial-system considerations

The tolerance should be reconsidered downward where disruption could propagate into interconnected payment, cash or interbank services or create broader confidence concerns.

 

Rationale for the Four-Hour Illustrative Tolerance

A relatively short tolerance is appropriate because CBS-1 concerns customers' ability to access their own deposit accounts and account information.

Customer harm may increase rapidly where people cannot:

  • determine whether funds are available;
  • access money required for essential expenditure;
  • confirm whether transactions have completed;
  • receive expected credits;
  • use alternative payment or cash-access channels; or
  • obtain reliable information about their account.

The impact may be greater for vulnerable customers, customers experiencing financial stress, businesses dependent on account liquidity, or customers affected during periods of elevated demand.

The four-hour proposal should therefore be treated as an implementation hypothesis to be tested, not a predetermined regulatory requirement.

MBSB should validate it using:

  • customer-impact analysis;
  • transaction and account-access volumes;
  • peak-period analysis;
  • vulnerable-customer considerations;
  • channel substitution capability;
  • incident history;
  • dependency mapping;
  • technology recovery capabilities;
  • third-party recovery commitments;
  • cyber recovery capabilities;
  • payment-system interconnections;
  • scenario-testing results; and
  • applicable BNM requirements.

If analysis demonstrates that intolerable customer harm could arise before four hours under particular circumstances, the tolerance should be shortened or supplemented by more stringent secondary thresholds.

 

Escalating Harm Across the Tolerance Window

The proposed tolerance can be operationalised through an escalation model.

0–1 Hour — Controlled Disruption

The primary objective is rapid detection, containment and activation of alternative arrangements.

A disruption may remain within the Low-to-Medium harm range where alternative channels remain available, and customer access is largely maintained.

1–2 Hours — Material Customer Impact

Management attention should increase as the number of affected customers and transaction backlogs grow.

Disruption affecting several channels, authentication capability or account information should be considered High harm even if the four-hour outer boundary has not yet been reached.

2–4 Hours — Approaching the Intolerance Boundary

CBS-level incident governance should focus on protecting the remaining tolerance.

Executive escalation should consider:

  • customer harm;
  • vulnerable customers;
  • alternative channel capacity;
  • transaction backlog;
  • account-data integrity;
  • recovery confidence;
  • interconnected CBS impacts; and
  • regulatory notification requirements.
Beyond 4 Hours — Presumed Intolerable Unless Evidence Demonstrates Otherwise

Widespread inability to access deposit accounts extending beyond the proposed tolerance should be treated as a potential Impact Tolerance breach and escalated accordingly.

Importantly, MBSB should not wait four hours to declare that harm has become intolerable where other thresholds have already been exceeded.

For example:

Material corruption of customer balances could constitute intolerable harm immediately, irrespective of elapsed time.

This illustrates why Impact Tolerance should be multi-dimensional rather than purely time-based.

 

Proactive Risk Management and Management Oversight

The objective of Operational Resilience is not simply to document the tolerance. MBSB should demonstrate that it actively manages the risk of breaching it.

Key proactive actions should include:

  • identifying single points of failure across CBS-1;
  • aligning component RTOs with the CBS tolerance;
  • testing authentication resilience across multiple customer channels;
  • verifying that alternative channels do not share critical common dependencies;
  • performing regular end-to-end disaster recovery tests;
  • testing recovery from cyberattack and ransomware;
  • maintaining recoverable and integrity-protected account data;
  • monitoring capacity against peak and stressed demand;
  • testing transaction reconciliation after technology recovery;
  • assessing third-party recovery capabilities against MBSB's tolerance;
  • monitoring dependency concentration;
  • exercising customer communications and surge arrangements;
  • validating continuity procedures with actual business users;
  • performing severe but plausible scenario tests; and
  • tracking resilience weaknesses to closure.

Evidence should be retained to demonstrate that these activities are operating rather than merely documented.

A suitable management evidence pack could include:

Approved CBS Impact Tolerance → Dependency Map → Risk Assessment → Control Test Results → DR/Cyber Recovery Tests → Scenario Testing → Identified Gaps → Remediation Plan → Management Review → Risk Acceptance/Closure

This provides traceability from the resilience requirement to management action.

 

Application to Severe but Plausible Scenario Testing

The proposed Impact Tolerance should become the principal benchmark for the next stage: Identify Severe but Plausible Scenarios [SbPS] and subsequently Perform Scenario Testing [ST].

Tests should deliberately challenge the assumptions underlying the four-hour tolerance.

Examples include:

Scenario 1 — Core Account Platform Failure

Core account processing becomes unavailable during a peak transaction period and primary failover does not complete as planned.

Scenario 2 — Authentication Common-Mode Failure

CBS-8 becomes unavailable, preventing authentication across digital and assisted account-access channels despite healthy account-processing infrastructure.

Scenario 3 — Ransomware and Data Integrity

A cyberattack requires isolation of account-processing environments while MBSB determines whether transaction data has been compromised.

Scenario 4 — Simultaneous Digital and Contact-Centre Disruption

Digital banking becomes unavailable, and customer demand overwhelms the contact centre, severely reducing alternative access and assistance.

Scenario 5 — Third-Party Technology Failure

A critical external ICT dependency experiences prolonged disruption that exceeds its expected recovery commitment.

Scenario 6 — Failed Disaster Recovery

The primary platform fails, and the designated recovery environment cannot assume production processing.

Scenario 7 — Data Corruption Without System Outage

Systems remain technically available, but MBSB cannot verify the accuracy of the displayed customer balances.

 

The key test question should remain:

Can MBSB continue to deliver CBS-1 within the established Impact Tolerance despite the severe yet plausible disruption?

If the answer is no, the scenario has identified a resilience gap requiring management action.

 

Management Validation of the Proposed Impact Tolerance

The proposed Impact Tolerance is an illustrative implementation recommendation and should not be interpreted as an established MBSB limit or a prescribed BNM threshold.

Before adoption, it should be validated by:

  • CBS-1 business owner;
  • Operational Resilience function;
  • Business Continuity Management;
  • Operational Risk Management;
  • Technology and ICT Risk;
  • Cybersecurity;
  • customer-service leadership;
  • Compliance and Legal, where appropriate;
  • third-party risk management;
  • senior management; and
  • the appropriate Board or management governance forum under MBSB's OR governance arrangements.

The validation should specifically confirm that:

  1. the harm assumptions are credible;
  2. the four-hour threshold occurs before intolerable harm;
  3. component recovery objectives provide adequate contingency inside the tolerance;
  4. alternative customer-access arrangements are realistic;
  5. data-integrity thresholds are appropriate;
  6. customer-scope thresholds reflect MBSB's actual customer population;
  7. vulnerable-customer considerations have been incorporated;
  8. interconnected CBS implications have been assessed;
  9. third-party arrangements support the tolerance; and
  10. applicable BNM requirements and supervisory expectations have been considered.

Formal approval and the supporting rationale should be retained as part of MBSB's Operational Resilience documentation.

 

Banner [Summing] [OR] [E3] Establish Impact Tolerance

The Impact Tolerance for CBS-1 Customer Deposit and Account Access Services provides MBSB with a clear boundary between a manageable disruption and one that creates unacceptable harm.

The assessment demonstrates why that boundary cannot be determined solely from the RTO of the core banking platform.

CBS-1 depends upon an interconnected service chain involving account processing, customer information, transaction records, authentication, customer channels, monitoring, incident response, continuity arrangements, reconciliation and recovery.

Analysis of the 18 Sub-CBS processes identifies where disruption is most likely to threaten the overall tolerance. In particular, account balance and transaction processing, authentication, data integrity, incident management, alternative access, technology recovery and final service validation represent critical resilience capabilities.

Integrating Cyber and ICT Risk strengthens this assessment by identifying how cyberattacks, ransomware, DDoS attacks, application and database failures, network outages, data corruption, failed technology changes, third-party disruptions, and technology concentration could directly translate into customer harm.

BNM's current direction recognises the increased resilience risks associated with digital technology, shared systems, cyber incidents and technical failures.

For implementation purposes, an indicative four-hour maximum disruption tolerance is proposed, supplemented by customer-scope, channel-availability, service-degradation and data-integrity thresholds.

The recommendation is deliberately multi-dimensional because some events—particularly material account data corruption or widespread unauthorised access—could cause intolerable harm before the time threshold is reached.

The implementation sequence should therefore be:

[OR] [PM] [E3] [ITo] [CBF] Implementation Sequence

Impact Tolerance should ultimately function as a management decision boundary.

It provides MBSB with a measurable basis for determining how resilient CBS-1 needs to be, where investment should be prioritised, which weaknesses require remediation and whether severe but plausible disruptions can be absorbed without causing unacceptable harm.

As CBS-1, its technology architecture, customer channels, third-party dependencies and threat environment evolve, the Impact Tolerance and its underlying assumptions should be periodically reviewed and revalidated.

In this way, Impact Tolerance becomes not merely a regulatory artefact but a practical mechanism for ensuring that MBSB's resilience capability remains aligned with the continued protection of its customers and the safe delivery of critical banking services.

 

Methodological and Regulatory References

BCM Institute's guidance on Impact Tolerance emphasises establishing the maximum tolerable disruption to a Critical Business Service and distinguishing the resulting boundary from conventional RTO and BCM recovery measures.

Its Levels of Harm methodology further provides a basis for distinguishing inconvenience, significant harm and intolerable harm when assessing the consequences of service disruption.

Bank Negara Malaysia's 2025 reporting identifies increased cyber and technology risks arising from greater dependence on digital technology and shared systems and notes both the strengthening of technology-risk requirements and the issuance of its Operational Resilience Discussion Paper

 

[OR] [MBSB] [3/4 Banner] Operational Resilience in Action The MBSB Bank's Approach

eBook 3: Starting Your OR Implementation
CBS-1 Customer Deposit and Account Access Services
CBS-1 DP CBS-1 MII CBS-1 ITo CBS-1 SbPS CBS-1 ST
[OR] [MBSB] [E3] [CBS] [1] [DP] Customer Deposit and Account Access Services [OR] [MBSB] [E3] [CBS] [1] [MII] Customer Deposit and Account Access Services [OR] [MBSB] [E3] [CBS] [1] [ITo] Customer Deposit and Account Access Services [OR] [MBSB] [E3] [CBS] [1] [SbPS] Customer Deposit and Account Access Services [OR] [MBSB] [E3] [CBS] [1] [ST] Customer Deposit and Account Access Services

New call-to-actionNew call-to-action

For organisations looking to accelerate their journey, BCM Institute’s training and certification programs, including the OR-5000 Operational Resilience Expert Implementer course, provide in-depth insights and practical toolkits for effectively embedding this model.

 

 

More Information About OR-5000 [OR-5] or OR-300 [OR-3]

To learn more about the course and schedule, click the buttons below for the OR-300 Operational Resilience Implementer course and the OR-5000 Operational Resilience Expert Implementer course.

BL-OR-3 Register Now BL-OR-3_Tell Me More BL-OR-3_View Schedule
BL-OR-5_Register Now BL-OR-5_Tell Me More  [BL-OR] [3-4-5] View Schedule
[BL-OR] [3] FAQ OR-300

If you have any questions, click to contact us.Email to Sales Team [BCM Institute]

FAQ BL-OR-5 OR-5000
OR Implementer Landing Page

New call-to-action

New call-to-action

 

Your Comments Here:

 

CTA Banner_OR

CTA Banner_ORA

CTA Banner_BCM

CTA Banner_ITDR

CTA Banner_CM