eBook OR

[OR] [MCIS] [E2] [C1] OR Planning Methodology

Written by Moh Heng Goh | Jul 23, 2026 8:09:46 AM



Introduction to MCIS Insurance Bhd’s Operational Resilience Planning Methodology

Introduction

Operational resilience requires more than the ability to recover technology, restore facilities, or activate a business continuity plan.

It requires an organisation to understand which services are most important to its customers, determine how much disruption can be tolerated, test whether those services can remain within acceptable limits, and continuously strengthen the capabilities that support them.

For MCIS Insurance Bhd (MCIS), operational resilience is particularly important because policyholders depend on the organisation to provide financial protection, process claims, maintain policy records, collect premiums, administer benefits, and deliver timely customer support.

Disruption to these services may create financial hardship, customer harm, regulatory concerns, reputational damage, and loss of confidence.

To manage these risks systematically, MCIS can adopt a structured Operational Resilience Planning Methodology comprising three integrated phases:

  • Plan
  • Implement
  • Sustain

Each phase contains five stages. Together, the 15 stages provide a practical roadmap for establishing, implementing, evaluating, and continually improving operational resilience across the organisation.

The methodology is designed to move MCIS from understanding its current resilience position to embedding resilience as an enduring organisational capability.

It connects governance, risk appetite, Critical Business Services, dependency mapping, impact tolerance, scenario testing, organisational culture, training, assurance, and continuous improvement within a single enterprise framework.

Purpose of the Chapter

The purpose of this chapter is to introduce the reader to the structure, logic, and intended outcomes of MCIS’s Operational Resilience Planning Methodology before the individual stages are examined in greater detail.

By reading this chapter, the reader should understand:

  • Why MCIS requires a structured Operational Resilience Planning Methodology.
  • How the Plan, Implement, and Sustain phases are connected.
  • The purpose of each of the 15 stages.
  • The principal activities undertaken at each stage.
  • The expected deliverables and management outcomes.
  • How each stage may be applied within the operating context of an insurance company.
  • How the methodology supports the protection of policyholders and other stakeholders.
  • How operational resilience can be integrated with risk management, business continuity, crisis management, technology resilience, cybersecurity, outsourcing, and regulatory compliance.

This chapter provides a high-level orientation rather than detailed operating procedures. Its objective is to give readers a clear understanding of the complete methodology so that subsequent chapters can focus on the implementation requirements, tools, decisions, responsibilities, and deliverables associated with each stage.

Overview of MCIS’s Operational Resilience Planning Methodology

MCIS’s Operational Resilience Planning Methodology is organised into three phases that represent the lifecycle of an enterprise resilience programme.

 

Phase

Primary Focus

Intended Outcome

Phase 1: Plan

Establish direction, assess readiness, identify gaps, and create governance

A clearly defined and adequately sponsored Operational Resilience programme

Phase 2: Implement

Identify important services, map dependencies, establish tolerances, test capabilities, and improve resilience

Critical Business Services that can remain within acceptable disruption limits

Phase 3: Sustain

Embed resilience into culture, communication, training, assessment, and independent assurance

A mature and continuously improving Operational Resilience capability

The phases should not be treated as isolated projects. They form a connected and recurring management cycle.

The Plan Phase establishes the organisational direction and management foundation. The Implement Phase applies that direction to Critical Business Services and their supporting resources. The Sustain Phase embeds resilience into routine organisational behaviour and assures that the programme remains effective.

As MCIS’s operating environment, technology, customer expectations, products, outsourcing arrangements, and risks evolve, the methodology should be repeated and refined. Operational resilience is therefore not a one-time implementation exercise. It is an ongoing management discipline.

 

Phase 1: Plan

The Plan Phase establishes the strategic and organisational foundation for operational resilience. It enables MCIS to understand its current capabilities, determine what must be improved, define its intended direction, confirm its tolerance for operational disruption, and establish effective governance.

The five stages of the Plan Phase are:

  1. Assess Capability and Maturity
  2. Analyse Gap
  3. Develop Strategy and Roadmap
  4. Confirm Risk Appetite
  5. Develop and Embed Governance
Assess Capability and Maturity

Plan Phase – Stage 1

The first stage evaluates MCIS’s existing ability to prevent, respond to, recover from, and adapt to operational disruption.

The assessment should examine the extent to which resilience is already supported by:

  • Enterprise risk management.
  • Operational risk management.
  • Business continuity management.
  • Crisis management.
  • Technology disaster recovery.
  • Cybersecurity.
  • Information security.
  • Incident management.
  • Outsourcing and third-party risk management.
  • Emergency response.
  • Regulatory compliance.
  • Internal audit and assurance.

The objective is not merely to confirm whether individual programmes exist. MCIS should assess whether these capabilities operate collectively to protect important customer services.

A maturity assessment may examine:

  • Governance and senior management oversight.
  • Policies, standards, and procedures.
  • Roles and accountability.
  • Identification of important services.
  • Mapping of processes and dependencies.
  • Tolerance-setting practices.
  • Testing and exercising.
  • Incident escalation and communication.
  • Third-party resilience.
  • Management information and reporting.
  • Organisational culture.
  • Assurance and continuous improvement.

MCIS may use a maturity scale ranging from an initial or informal capability to an optimised and integrated capability.

Example for MCIS

MCIS may determine that it has established business continuity plans, technology recovery procedures, cyber incident response arrangements, and crisis management protocols. However, the maturity assessment may reveal that these capabilities are managed separately and are not consistently linked to end-to-end customer services.

For example, individual departments may be able to recover their own processes, but management may not have a consolidated view of whether the entire claims settlement service can remain operational during a prolonged core insurance system outage.

The assessment would therefore identify the need to move from function-based recovery planning towards service-based operational resilience.

Key Output

The principal output is an Operational Resilience Capability and Maturity Assessment Report, supported by maturity scores, observations, strengths, weaknesses, and initial improvement priorities.

Analyse Gap

Plan Phase – Stage 2

The gap analysis compares MCIS’s current resilience capability against its desired future state.

While the maturity assessment establishes where the organisation is currently positioned, the gap analysis determines what is missing and what must change.

The analysis should consider gaps relating to:

  • Governance.
  • Policy and methodology.
  • Service ownership.
  • Critical Business Service identification.
  • Dependency mapping.
  • Impact tolerance.
  • Scenario testing.
  • Third-party resilience.
  • Technology resilience.
  • Management reporting.
  • Skills and competency.
  • Culture and awareness.
  • Assurance.
  • Documentation.
  • Regulatory alignment.

Each gap should be evaluated based on:

  • Potential customer harm.
  • Regulatory significance.
  • Business impact.
  • Urgency.
  • Implementation complexity.
  • Cost.
  • Resource requirements.
  • Dependency on other initiatives.

Example for MCIS

MCIS may identify that its business continuity programme assigns recovery time objectives to business processes but does not establish impact tolerances for end-to-end Critical Business Services.

A further gap may be that critical third parties are assessed individually through procurement reviews, but the organisation does not fully understand how multiple third-party failures could collectively affect claims payment or premium collection.

Another gap may be that scenario testing focuses primarily on technology recovery and does not test the full customer journey across business units, applications, suppliers, payment channels, and communication arrangements.

Key Output

The principal output is an Operational Resilience Gap Analysis Report containing:

  • Identified gaps.
  • Root causes.
  • Risk implications.
  • Recommended corrective actions.
  • Priority ratings.
  • Proposed owners.
  • Target completion periods.
Develop Strategy and Roadmap

Plan Phase – Stage 3

The Operational Resilience Strategy defines what MCIS intends to achieve and how resilience will support the organisation’s wider business, customer, risk, and regulatory objectives.

The strategy should establish:

  • The organisation’s resilience vision.
  • Strategic objectives.
  • Scope of the programme.
  • Guiding principles.
  • Target operating model.
  • Governance arrangements.
  • Implementation priorities.
  • Resource requirements.
  • Measures of success.
  • Reporting expectations.

The roadmap converts the strategy into a sequenced implementation plan.

It should define:

  • Workstreams.
  • Deliverables.
  • Milestones.
  • Dependencies.
  • Accountable owners.
  • Required resources.
  • Budget considerations.
  • Target completion dates.
  • Performance indicators.
  • Assurance activities.

The roadmap should be realistic and risk-based. MCIS does not need to address every weakness simultaneously. Priority should be given to gaps that expose policyholders or the organisation to the greatest potential harm.

Example for MCIS

MCIS may develop a three-year Operational Resilience roadmap.

The first year may focus on:

  • Establishing governance.
  • Approving the methodology.
  • Identifying Critical Business Services.
  • Assigning service owners.
  • Mapping selected priority services.

The second year may focus on:

  • Setting impact tolerances.
  • Conducting scenario tests.
  • Addressing major technology and third-party vulnerabilities.
  • Improving management reporting.

The third year may focus on:

  • Expanding testing.
  • Integrating resilience into change management.
  • Strengthening culture.
  • Conducting independent reviews.
  • Embedding continuous improvement.

The roadmap may prioritise services such as claims management and settlement because disruption could cause immediate financial and emotional harm to policyholders and beneficiaries.

Key Output

The principal outputs are an approved:

  • Operational Resilience Strategy; and
  • Operational Resilience Implementation Roadmap.
Confirm Risk Appetite

Plan Phase – Stage 4

Risk appetite defines the nature and level of operational risk MCIS is prepared to accept in pursuit of its objectives.

Operational resilience does not assume that every disruption can be prevented. Instead, it requires management to determine how much disruption may be accepted before customer harm or organisational impact becomes intolerable.

The organisation’s operational resilience risk appetite should address matters such as:

  • Maximum acceptable service disruption.
  • Customer harm.
  • Claims payment delays.
  • Data loss or corruption.
  • Technology unavailability.
  • Cyber incidents.
  • Third-party concentration risk.
  • Manual processing capacity.
  • Regulatory breaches.
  • Financial loss.
  • Reputational impact.

Risk appetite should guide the later establishment of impact tolerances for individual Critical Business Services.

The relationship between risk appetite and impact tolerance should be clearly understood:

  • Risk appetite operates at the enterprise or risk-category level.
  • Impact tolerance applies to the maximum acceptable disruption of a specific Critical Business Service.

Example for MCIS

MCIS may determine that it has a very low appetite for disruptions that prevent eligible policyholders or beneficiaries from receiving approved claim payments.

It may also have a low appetite for:

  • Loss of sensitive policyholder information.
  • Prolonged unavailability of core policy records.
  • Incorrect premium allocation.
  • Unauthorised changes to policy information.
  • Failure to meet regulatory notification obligations.

These risk appetite statements would influence investment decisions, resilience controls, service tolerances, and escalation thresholds.

Key Output

The principal output is an approved set of Operational Resilience Risk Appetite Statements, Metrics, Thresholds, and Escalation Requirements.

Develop and Embed Governance

Plan Phase – Stage 5

Governance provides the authority, accountability, oversight, and decision-making structure required to implement operational resilience effectively.

The governance model should define responsibilities for:

  • The Board of Directors.
  • Board or management risk committees.
  • Senior management.
  • The Chief Risk Officer.
  • Operational Resilience programme leadership.
  • Critical Business Service owners.
  • Business units.
  • Technology.
  • Cybersecurity.
  • Business continuity.
  • Crisis management.
  • Procurement and vendor management.
  • Compliance.
  • Internal audit.

Effective governance requires more than the creation of committees. Operational resilience responsibilities should be embedded into:

  • Job descriptions.
  • Committee terms of reference.
  • Policies.
  • Risk acceptance processes.
  • Project governance.
  • Change management.
  • Product approval.
  • Outsourcing decisions.
  • Performance objectives.
  • Management reporting.
  • Escalation procedures.

Example for MCIS

MCIS may assign executive accountability for Operational Resilience to a designated senior executive, while individual Critical Business Service owners remain accountable for the resilience of their respective services.

The owner of Claims Management and Settlement, for example, would be responsible for:

  • Confirming the scope of the service.
  • Validating mapped dependencies.
  • Recommending impact tolerances.
  • Participating in scenario testing.
  • Monitoring vulnerabilities.
  • Sponsoring remediation.
  • Reporting significant resilience risks.

A management-level Operational Resilience Committee may oversee programme progress, approve methodologies, review testing results, monitor remediation, and escalate material risks to the appropriate board committee.

Key Output

The principal outputs include:

  • An approved Operational Resilience Governance Framework.
  • Defined roles and responsibilities.
  • Committee terms of reference.
  • Service ownership arrangements.
  • Reporting and escalation protocols.

 

Phase 2: Implement

The Implement Phase applies the strategic direction established during the Plan Phase to MCIS’s actual services and operating arrangements.

Its objective is to identify the services that matter most, understand how they are delivered, determine how much disruption can be tolerated, test the organisation’s ability to remain within those tolerances, and address identified weaknesses.

The five stages of the Implement Phase are:

  1. Identify Critical Business Services
  2. Map Processes and Resources
  3. Set Impact Tolerance
  4. Conduct Scenario Testing
  5. Improve Lessons Learnt
Identify Critical Business Services

Implement Phase – Stage 1

A Critical Business Service is a service delivered to customers or external stakeholders whose disruption could cause intolerable harm.

The identification process should focus on service outcomes rather than internal departments or isolated business processes.

MCIS should assess potential services against criteria such as:

  • Potential harm to policyholders.
  • Financial hardship.
  • Number and vulnerability of affected customers.
  • Regulatory impact.
  • Legal obligations.
  • Reputational consequences.
  • Time sensitivity.
  • Market confidence.
  • Dependency on other financial institutions.
  • Availability of substitutes or workarounds.

Potential Critical Business Services for MCIS may include:

  • Insurance application and policy issuance.
  • Premium collection and allocation.
  • Claims management and settlement.
  • Customer policy administration.
  • Digital policyholder servicing.
  • Customer assistance and complaint management.
  • Policy benefit and maturity payment.
  • Investment-linked policy administration.

The final list should be proportionate and focused. If too many services are classified as critical, resources may become diluted and management attention may be weakened.

Example for MCIS

MCIS may identify Claims Management and Settlement as a Critical Business Service because its prolonged disruption could prevent policyholders or beneficiaries from receiving funds during illness, disability, hospitalisation, death, or other insured events.

Although many internal functions support claims settlement, the CBS should be defined as an end-to-end customer service rather than as separate claims registration, assessment, approval, and payment departments.

Key Output

The principal output is an approved Critical Business Services Register, including:

  • Service definitions.
  • Service owners.
  • Customers and stakeholders.
  • Rationale for criticality.
  • Service boundaries.
  • Regulatory relevance.
Map Interconnections and Interdependencies

Implement Phase – Stage 2

Once a Critical Business Service has been identified, MCIS must understand how the service is delivered from end to end.

Dependency mapping identifies the people, processes, technology, data, facilities, and third parties required to deliver the service.

The mapping should include:

  • Business processes.
  • Supporting activities.
  • Employees and specialist roles.
  • Core applications.
  • Infrastructure.
  • Databases.
  • Information and records.
  • Premises.
  • Telecommunications.
  • Payment channels.
  • Outsourced service providers.
  • Cloud providers.
  • Banks.
  • Medical service providers.
  • Distribution partners.
  • Interdependencies with other services.

The objective is not to create process maps solely for documentation. The mapping should reveal vulnerabilities, concentrations, single points of failure, and dependencies that may prevent the service from remaining within its impact tolerance.

Example for MCIS

For the Claims Management and Settlement service, MCIS may map dependencies such as:

  • Claims intake channels.
  • Claims assessors.
  • Policy administration systems.
  • Document management systems.
  • Medical reports.
  • Healthcare providers.
  • Fraud detection tools.
  • Approval authorities.
  • Finance systems.
  • Banking partners.
  • Payment platforms.
  • Customer communication channels.
  • External claims investigators.

The mapping may reveal that both claims assessment and payment depend on a single core platform or that a manual workaround can support only a small percentage of normal transaction volume.

Key Output

The principal output is an End-to-End Dependency Map for each Critical Business Service, supported by a dependency inventory and vulnerability observations.

Set Impact Tolerance

Implement Phase – Stage 3

Impact tolerance defines the maximum level of disruption that MCIS is willing to accept for a Critical Business Service before the resulting harm becomes intolerable.

An impact tolerance may include:

  • Maximum duration of disruption.
  • Maximum number of affected customers.
  • Maximum transaction backlog.
  • Maximum financial exposure.
  • Maximum delay in customer outcomes.
  • Maximum level of data loss.
  • Maximum level of service degradation.

Impact tolerance differs from traditional recovery objectives.

A recovery time objective generally applies to the restoration of a system, process, or activity. An impact tolerance applies to the maximum acceptable disruption of the entire customer-facing service.

MCIS should set tolerances based on evidence and consider:

  • Customer vulnerability.
  • Product obligations.
  • Claims urgency.
  • Regulatory expectations.
  • Normal and peak transaction volumes.
  • Manual workaround capacity.
  • Dependencies.
  • Potential cumulative impact.
  • Availability of alternative channels.

Example for MCIS

For Claims Management and Settlement, MCIS may determine that urgent claims involving hospitalisation, death benefits, or severe financial hardship require a more stringent tolerance than routine claims.

The impact tolerance may state that MCIS must not allow disruption to prevent priority claims from being assessed and paid beyond a defined maximum period.

Supporting measures may include:

  • Maximum number of priority claims delayed.
  • Maximum backlog.
  • Minimum processing capacity during disruption.
  • Maximum duration for loss of access to essential policy records.

The tolerance should be approved by an appropriately authorised governance body and supported by clear rationale.

Key Output

The principal output is an approved Impact Tolerance Statement and Supporting Metrics for each Critical Business Service.

Conduct Scenario Testing

Implement Phase – Stage 4

Scenario testing evaluates whether MCIS can continue delivering a Critical Business Service within its approved impact tolerance during severe but plausible disruption.

Testing should examine end-to-end service delivery rather than individual plans or systems in isolation.

Potential scenarios may include:

  • Ransomware affecting core insurance platforms.
  • Prolonged cloud or data centre failure.
  • Telecommunications disruption.
  • Payment network outage.
  • Loss of a critical third-party provider.
  • Major data corruption.
  • Cyberattack combined with customer misinformation.
  • Flooding affecting operational premises.
  • Widespread workforce unavailability.
  • Simultaneous technology and supplier failure.
  • Failure during a peak claims period.
  • Loss of key personnel and specialist expertise.

Scenario testing should challenge assumptions and examine:

  • Detection.
  • Escalation.
  • Decision-making.
  • Communication.
  • Manual workarounds.
  • Alternative channels.
  • Customer prioritisation.
  • Third-party response.
  • Technology recovery.
  • Data availability.
  • Backlog management.
  • Regulatory notification.
  • Ability to remain within impact tolerance.

Example for MCIS

MCIS may test a scenario in which ransomware makes the core policy administration and claims platforms unavailable for several days.

The exercise may assess whether MCIS can:

  • Access essential policyholder information through alternative means.
  • Identify urgent claims.
  • Receive claim notifications.
  • Validate policy coverage.
  • Apply emergency approval procedures.
  • Initiate manual or alternative payments.
  • Communicate with affected customers.
  • Coordinate with banks and service providers.
  • Report the incident to management and regulators.
  • Prevent the claims service from exceeding its approved impact tolerance.

The test may reveal that systems can technically be recovered within the required period, but manual claims prioritisation and customer communication are insufficient. This would indicate that technology recovery alone does not provide complete service resilience.

Key Output

The principal output is a Scenario Testing Report documenting:

  • Scenario design.
  • Participants.
  • Assumptions.
  • Test results.
  • Tolerance performance.
  • Identified vulnerabilities.
  • Management decisions.
  • Required remediation.
Improve Lessons Learnt

Implement Phase – Stage 5

Operational resilience testing has limited value unless findings are translated into measurable improvements.

Lessons should be obtained from:

  • Scenario tests.
  • Actual incidents.
  • Business continuity exercises.
  • Technology recovery tests.
  • Cyber incidents.
  • Customer complaints.
  • Supplier outages.
  • Internal audits.
  • Regulatory reviews.
  • Near misses.
  • Industry events.

MCIS should distinguish between:

  • Observations.
  • Lessons identified.
  • Lessons formally accepted.
  • Corrective actions.
  • Completed improvements.
  • Verified closure.

Each improvement action should have:

  • A clear owner.
  • A target completion date.
  • A priority.
  • Required resources.
  • Defined success criteria.
  • Governance oversight.
  • Closure evidence.

The organisation should also determine whether a finding affects other services. A weakness identified in claims processing may also exist in policy issuance, premium collection, or customer servicing.

Example for MCIS

A ransomware scenario test may reveal that MCIS can recover its claims platform within the required period but cannot rapidly obtain an accurate list of urgent claims received immediately before the outage.

The resulting improvement actions may include:

  • Establishing a secure secondary claims register.
  • Improving data replication.
  • Defining criteria for priority claims.
  • Training claims staff in manual processing.
  • Pre-agreeing emergency payment arrangements.
  • Updating customer communication templates.
  • Retesting the service after remediation.

Key Output

The principal output is an Operational Resilience Improvement Plan and Lessons-Learnt Register, supported by tracked actions and evidence of closure.

 

Phase 3: Sustain

The Sustain Phase ensures that Operational Resilience becomes an enduring organisational capability rather than a temporary project.

It focuses on culture, communication, competence, self-assessment, and independent assurance.

The five stages of the Sustain Phase are:

  1. Introduce Cultural Change
  2. Develop Communication Strategy
  3. Implement Training and Awareness
  4. Provide Self-Assessment
  5. Conduct Independent Quality Review
Introduce Cultural Change

Sustain Phase – Stage 1

Operational resilience depends on how people think, behave, make decisions, and respond under pressure.

A resilience culture encourages employees to:

  • Understand the importance of customer service.
  • Recognise operational vulnerabilities.
  • Escalate concerns promptly.
  • Challenge unrealistic assumptions.
  • Consider resilience when making business decisions.
  • Learn from disruptions and near misses.
  • Take accountability for service outcomes.
  • Collaborate across organisational boundaries.

Cultural change requires visible senior management commitment. Resilience should be reflected in leadership messages, performance objectives, project decisions, risk discussions, and investment priorities.

Example for MCIS

MCIS may introduce a requirement for business and technology teams to consider the effect of proposed changes on Critical Business Services.

When a new digital claims feature is introduced, project teams would not evaluate only cost, delivery schedule, and functionality. They would also assess:

  • Additional dependencies.
  • Failure modes.
  • Supplier concentration.
  • Recovery arrangements.
  • Manual alternatives.
  • Impact on the claims service tolerance.

This demonstrates that resilience has become part of routine decision-making.

Key Output

The principal output is an Operational Resilience Cultural Change Plan, supported by leadership actions, behavioural expectations, and measures of cultural adoption.

Develop Communication Strategy

Sustain Phase – Stage 2

A communication strategy ensures that employees, management, service providers, customers, and other stakeholders receive appropriate information about operational resilience.

The strategy should address communication:

  • Before disruptions.
  • During incidents.
  • During service recovery.
  • After incidents.
  • During testing and exercises.
  • When major resilience changes are introduced.

Internal communication should explain:

  • Why operational resilience matters.
  • Which services are critical.
  • Who is accountable.
  • How incidents should be escalated.
  • What employees are expected to do.
  • What has been learned from testing and incidents.

External communication arrangements should support:

  • Policyholder updates.
  • Agent and intermediary communication.
  • Service-provider coordination.
  • Regulatory notification.
  • Media response.
  • Public statements.
  • Complaint handling.

Example for MCIS

During a disruption to digital policy servicing, MCIS may need to communicate differently with:

  • Policyholders.
  • Insurance agents.
  • Contact centre employees.
  • Senior management.
  • Technology vendors.
  • Bank Negara Malaysia.
  • Media representatives.

The communication strategy should establish approved channels, decision rights, message owners, escalation triggers, and pre-drafted templates.

Key Output

The principal output is an Operational Resilience Communication Strategy and Stakeholder Communication Framework.

Implement Training and Awareness

Sustain Phase – Stage 3

Training and awareness ensure that individuals understand their resilience responsibilities and possess the competence required to perform them.

Training should be role-based.

Board and senior management training may cover:

  • Governance.
  • Accountability.
  • Risk appetite.
  • Impact tolerance.
  • Scenario-testing results.
  • Major vulnerabilities.
  • Regulatory expectations.

Critical Business Service owners may require training on:

  • Service identification.
  • Dependency mapping.
  • Tolerance setting.
  • Scenario design.
  • Vulnerability management.
  • Reporting.

Operational employees may require training on:

  • Incident escalation.
  • Manual workarounds.
  • Customer prioritisation.
  • Alternative systems.
  • Communication.
  • Recovery procedures.

Awareness activities may include:

  • Briefings.
  • E-learning.
  • Workshops.
  • Simulations.
  • Tabletop exercises.
  • Campaigns.
  • Induction programmes.
  • Lessons-learned sessions.

Example for MCIS

Claims employees may receive practical training on how to process urgent claims when the primary claims platform is unavailable.

The training may include:

  • Accessing authorised alternative records.
  • Applying manual verification controls.
  • Prioritising vulnerable customers.
  • Escalating exceptions.
  • Initiating emergency payment procedures.
  • Recording transactions for later reconciliation.

Key Output

The principal output is an Operational Resilience Training and Awareness Programme, including competency requirements, training records, and effectiveness measures.

Provide Self-Assessment

Sustain Phase – Stage 4

Self-assessment enables MCIS to evaluate whether its Operational Resilience programme remains complete, effective, and aligned with approved requirements.

The self-assessment should consider:

  • Governance effectiveness.
  • Completeness of the CBS inventory.
  • Accuracy of dependency maps.
  • Adequacy of impact tolerances.
  • Scenario-testing coverage.
  • Status of remediation.
  • Third-party resilience.
  • Training completion.
  • Incident lessons.
  • Emerging risks.
  • Material business and technology changes.
  • Compliance with policy requirements.

The assessment should be evidence-based and should not rely solely on subjective declarations.

It should identify:

  • Effective practices.
  • Weaknesses.
  • Overdue actions.
  • Changes in risk exposure.
  • Exceptions.
  • Areas requiring management attention.

Example for MCIS

During its annual self-assessment, MCIS may identify that a major change to its digital customer platform introduced a new cloud service provider and additional application interfaces.

Although the platform was approved through normal project governance, the Critical Business Service dependency map may not yet reflect these changes.

The self-assessment would require the service owner to update the dependency map, review concentration risk, confirm recovery arrangements, and determine whether additional scenario testing is necessary.

Key Output

The principal output is an Operational Resilience Self-Assessment Report, supported by evidence, management attestations, identified exceptions, and improvement actions.

Conduct Independent Quality Review

Sustain Phase – Stage 5

An Independent Quality Review provides objective assurance that MCIS’s Operational Resilience programme is appropriately designed, implemented, and maintained.

The review may be conducted by:

  • Internal audit.
  • An independent risk assurance function.
  • External specialists.
  • Other suitably qualified reviewers without direct responsibility for programme implementation.

The review should assess:

  • Governance.
  • Methodology.
  • Regulatory alignment.
  • Service identification.
  • Mapping quality.
  • Impact tolerance rationale.
  • Scenario-testing rigour.
  • Remediation.
  • Third-party coverage.
  • Data quality.
  • Reporting.
  • Culture.
  • Sustainability.

Independent review should challenge whether management conclusions are supported by adequate evidence.

Example for MCIS

An independent reviewer may examine the Claims Management and Settlement service and determine that its impact tolerance is well documented but has been tested only against a technology outage.

The reviewer may recommend additional tests involving:

  • Workforce unavailability.
  • Payment provider failure.
  • Data corruption.
  • Third-party medical assessor disruption.
  • Simultaneous cyber and communication failures.

This challenge would improve confidence that the service can remain resilient under a sufficiently broad range of severe but plausible scenarios.

Key Output

The principal output is an Independent Operational Resilience Quality Review Report, including findings, ratings, recommendations, management responses, and agreed corrective actions.

Integration of the Three Phases

The three phases of MCIS’s Operational Resilience Planning Methodology are mutually dependent.

The Plan Phase establishes direction, but it cannot demonstrate resilience unless the organisation implements service-based activities.

The Implement Phase produces maps, tolerances, tests, and improvements, but these capabilities will deteriorate unless they are sustained through culture, training, assessment, and assurance.

The Sustain Phase maintains programme effectiveness, but its findings may require MCIS to revisit its strategy, governance, risk appetite, service inventory, or testing approach.

The methodology should therefore operate as a continuous cycle:

Plan the capability, implement resilience around important services, sustain the capability, and use lessons and assurance findings to improve the next planning cycle.

An overview of the complete methodology is presented below.

Phase

Stage

Primary Question

Plan

Assess Capability and Maturity

Where is MCIS today?

Plan

Analyse Gap

What is missing or inadequate?

Plan

Develop Strategy and Roadmap

What will MCIS achieve, and how?

Plan

Confirm Risk Appetite

What level of operational risk is acceptable?

Plan

Develop and Embed Governance

Who is accountable, and how will decisions be made?

Implement

Identify Critical Business Services

Which services must be protected from intolerable disruption?

Implement

Map Processes and Resources

What is required to deliver each service?

Implement

Set Impact Tolerance

How much disruption can MCIS accept?

Implement

Conduct Scenario Testing

Can the service remain within tolerance during severe disruption?

Implement

Improve Lessons Learnt

What weaknesses must be corrected?

Sustain

Introduce Cultural Change

Are resilience behaviours embedded in the organisation?

Sustain

Develop Communication Strategy

Are stakeholders informed before, during, and after disruption?

Sustain

Implement Training and Awareness

Do people possess the required knowledge and competence?

Sustain

Provide Self-Assessment

Is the programme operating as intended?

Sustain

Conduct Independent Quality Review

Is there objective assurance over programme effectiveness?

 

Expected Benefits for MCIS

Applying the methodology should enable MCIS to:

  • Focus resilience efforts on services that matter most to policyholders.
  • Establish clear accountability for end-to-end service resilience.
  • Understand critical operational and third-party dependencies.
  • Identify single points of failure and concentration risks.
  • Define measurable disruption limits.
  • Improve the quality of scenario testing.
  • Strengthen business and technology coordination.
  • Prioritise resilience investment based on customer harm.
  • Improve crisis and incident decision-making.
  • Demonstrate structured governance and assurance.
  • Integrate operational resilience with existing risk and continuity capabilities.
  • Continuously adapt to changes in technology, products, suppliers, threats, and customer expectations.

The methodology also provides a common language that can be used across MCIS by senior management, risk teams, business units, technology teams, service owners, auditors, and external stakeholders.

 

MCIS Insurance Bhd’s Operational Resilience Planning Methodology provides a structured enterprise approach for protecting the services that are most important to policyholders and other stakeholders. Its three phases—Plan, Implement, and Sustain—guide the organisation from initial capability assessment through service identification, dependency mapping, tolerance setting, scenario testing, cultural integration, self-assessment, and independent assurance.

The Plan Phase establishes the direction, priorities, risk boundaries, and governance required to manage resilience. The Implement Phase applies these foundations to Critical Business Services and tests whether they can remain within acceptable disruption limits. The Sustain Phase ensures that resilience becomes embedded in organisational culture, communication, competence, assessment, and assurance.

The methodology should not be regarded as a one-time compliance project. It is a continuous management cycle that enables MCIS to learn from disruption, respond to emerging risks, adapt to organisational change, and progressively strengthen its ability to protect customers.

The next chapter will build upon this overview by examining the first stage of the Plan Phase: Assessing MCIS Insurance Bhd’s Operational Resilience Capability and Maturity. This assessment will establish the organisation’s current position, identify existing strengths, and provide the evidence required for subsequent gap analysis, strategy development, and programme prioritisation.

Blogs marked [x] are under construction

C1 C2 [x] C8 [x]  C14 [x]      

   BSP OR Policy eBook 1 eBook 2 eBook 3   C20 [x] C21 [x] 
   
  "Plan" Phase of the Operational Resilience Planning Methodology
  C2 [x] C3 [x] C4 [x] C5 [x] C6 [x] C7 [x]
  "Implement" Phase of the Operational Resilience Planning Methodology
  C8 [x] C9 [x] C10 [x] C11 [x] C12 [x] C13 [x]
 
  "Sustain" Phase of the Operational Resilience Planning Methodology
  C14 [x] C15 [x] C16 [x] C17 [x] C18 [x] C19 [x]
 


For organisations looking to accelerate their journey, BCM Institute’s training and certification programs, including the OR-5000 Operational Resilience Expert Implementer course, provide in-depth insights and practical toolkits for effectively embedding this model.

 

More Information About OR-5000 [OR-5] or OR-300 [OR-3]

Gain Competency: For organisations looking to accelerate their journey, BCM Institute’s training and certification programs, including the OR-5000 Operational Resilience Expert Implementer course, provide in-depth insights and practical toolkits for effectively embedding this model.

To learn more about the course and schedule, click the buttons below for the OR-300 Operational Resilience Implementer course and the OR-5000 Operational Resilience Expert Implementer course.

If you have any questions, click to contact us.