CBS-12 Third-Party / Outsourced Service Management
Scenario testing for CBS-12 focuses on validating Metrobank’s ability to maintain critical business services when faced with severe but plausible disruptions.
These tests are designed to simulate real-world operational challenges, including cyber threats, vendor failures, and regulatory compliance issues, to ensure response and recovery measures can sustain services within approved impact tolerances.
Integrating cyber and ICT risk considerations is critical, as these risks often amplify third-party dependencies and service continuity challenges.
Table P6: Perform Scenario Testing for CBS-12
|
Sub-CBS Code |
Sub-CBS |
Recommended Scenario Test Themes |
Impact/Effect |
Evidence of Proactive Risk Management Action |
|
12.1 |
Vendor Risk Management |
Vendor insolvency, supply chain disruption, and a cybersecurity breach at the vendor |
Service delays, financial losses, and reputational damage |
Vendor audits, risk scoring, regular performance reviews, and contractual risk clauses |
|
12.2 |
Third-Party Contract Management |
Contract non-compliance, legal disputes, and regulatory audit failure |
Service disruption, regulatory fines, operational penalties |
Periodic contract review, SLA monitoring, and legal advisory integration |
|
12.3 |
Outsourced Service Monitoring |
System downtime at the outsourced provider, inadequate incident reporting |
Service unavailability, data loss, and operational bottlenecks |
Continuous monitoring tools, KPIs, escalation protocols |
|
12.4 |
Service Continuity Planning |
Vendor business interruption, natural disaster impacting service |
Critical service outage, breach of impact tolerance, customer dissatisfaction |
Business continuity plans, backup vendors, and regular continuity drills |
|
12.5 |
Compliance and Regulatory Assurance |
Non-compliance with regulatory requirements, data privacy breach |
Regulatory sanctions, reputational damage, and financial penalties |
Compliance audits, automated reporting, and staff training programs |
|
12.6 |
Incident Management and Response |
Multi-vendor incident, ransomware attack, critical system failure |
Delayed response, extended downtime, financial and reputational impact |
Incident response plan, tabletop exercises, cyber resilience drills |
By systematically conducting scenario testing, Metrobank can confidently assess the resilience of its third-party and outsourced service arrangements.
These exercises provide insights into vulnerabilities, enhance incident response, and ensure that services operate within defined impact tolerances.
Evidence collected from proactive risk management actions enables continuous improvement and strengthens integration of cyber and ICT risk considerations into the overall operational resilience strategy.
Gain Competency: For organisations looking to accelerate their journey, BCM Institute’s training and certification programs, including the OR-5000 Operational Resilience Expert Implementer course, provide in-depth insights and practical toolkits for effectively embedding this model.





![Banner [Table] [OR] [E3] Perform Scenario Testing](https://no-cache.hubspot.com/cta/default/3893111/a45e9708-7139-4f4e-8e0e-41179f5cacc3.png)
![Banner [Summing] [OR] [E3] Perform Scenario Testing](https://no-cache.hubspot.com/cta/default/3893111/11895c06-91e9-4cec-acb6-4356741952e4.png)
![[OR] [MBT] [E3] [CBS] [12] [DP] Third-Party Outsourced Service Management](https://no-cache.hubspot.com/cta/default/3893111/7c07a042-eb9c-4f76-bf19-10435fa89d38.png)
![[OR] [MBT] [E3] [CBS] [12] [MD] Map Dependency](https://no-cache.hubspot.com/cta/default/3893111/f3043f5e-a02d-4463-94db-25e2488c9c8a.png)
![[OR] [MBT] [E3] [CBS] [12] [MPR] Map Processes and Resources](https://no-cache.hubspot.com/cta/default/3893111/6e3d60b9-54c5-47d4-9b44-5c842a90a2e7.png)
![[OR] [MBT] [E3] [CBS] [12] [ITo] Establish Impact Tolerances](https://no-cache.hubspot.com/cta/default/3893111/437dedd1-0563-4237-ab7b-4f8cc85522ba.png)
![[OR] [MBT] [E3] [CBS] [12] [SuPS] Identify Severe but Plausible Scenarios](https://no-cache.hubspot.com/cta/default/3893111/6de9bd0a-8756-40ae-9112-e8a3d5f8999e.png)





![[BL-OR] [3-4-5] View Schedule](https://no-cache.hubspot.com/cta/default/3893111/d0d733a1-16c0-4b68-a26d-adbfd4fc6069.png)
![[BL-OR] [3] FAQ OR-300](https://no-cache.hubspot.com/cta/default/3893111/f20c71b4-f5e8-4aa5-8056-c374ca33a091.png)
![Email to Sales Team [BCM Institute]](https://no-cache.hubspot.com/cta/default/3893111/3c53daeb-2836-4843-b0e0-645baee2ab9e.png)








