Operational resilience requires more than the ability to recover technology, restore facilities, or activate a business continuity plan.
It requires an organisation to understand which services are most important to its customers, determine how much disruption can be tolerated, test whether those services can remain within acceptable limits, and continuously strengthen the capabilities that support them.
For MCIS Insurance Bhd (MCIS), operational resilience is particularly important because policyholders depend on the organisation to provide financial protection, process claims, maintain policy records, collect premiums, administer benefits, and deliver timely customer support.
Disruption to these services may create financial hardship, customer harm, regulatory concerns, reputational damage, and loss of confidence.
Each phase contains five stages. Together, the 15 stages provide a practical roadmap for establishing, implementing, evaluating, and continually improving operational resilience across the organisation.
The methodology is designed to move MCIS from understanding its current resilience position to embedding resilience as an enduring organisational capability.
It connects governance, risk appetite, Critical Business Services, dependency mapping, impact tolerance, scenario testing, organisational culture, training, assurance, and continuous improvement within a single enterprise framework.
The purpose of this chapter is to introduce the reader to the structure, logic, and intended outcomes of MCIS’s Operational Resilience Planning Methodology before the individual stages are examined in greater detail.
By reading this chapter, the reader should understand:
This chapter provides a high-level orientation rather than detailed operating procedures. Its objective is to give readers a clear understanding of the complete methodology so that subsequent chapters can focus on the implementation requirements, tools, decisions, responsibilities, and deliverables associated with each stage.
MCIS’s Operational Resilience Planning Methodology is organised into three phases that represent the lifecycle of an enterprise resilience programme.
|
Phase |
Primary Focus |
Intended Outcome |
|
Phase 1: Plan |
Establish direction, assess readiness, identify gaps, and create governance |
A clearly defined and adequately sponsored Operational Resilience programme |
|
Phase 2: Implement |
Identify important services, map dependencies, establish tolerances, test capabilities, and improve resilience |
Critical Business Services that can remain within acceptable disruption limits |
|
Phase 3: Sustain |
Embed resilience into culture, communication, training, assessment, and independent assurance |
A mature and continuously improving Operational Resilience capability |
The phases should not be treated as isolated projects. They form a connected and recurring management cycle.
The Plan Phase establishes the organisational direction and management foundation. The Implement Phase applies that direction to Critical Business Services and their supporting resources. The Sustain Phase embeds resilience into routine organisational behaviour and assures that the programme remains effective.
As MCIS’s operating environment, technology, customer expectations, products, outsourcing arrangements, and risks evolve, the methodology should be repeated and refined. Operational resilience is therefore not a one-time implementation exercise. It is an ongoing management discipline.
The Plan Phase establishes the strategic and organisational foundation for operational resilience. It enables MCIS to understand its current capabilities, determine what must be improved, define its intended direction, confirm its tolerance for operational disruption, and establish effective governance.
The five stages of the Plan Phase are:
Plan Phase – Stage 1
The first stage evaluates MCIS’s existing ability to prevent, respond to, recover from, and adapt to operational disruption.
The assessment should examine the extent to which resilience is already supported by:
The objective is not merely to confirm whether individual programmes exist. MCIS should assess whether these capabilities operate collectively to protect important customer services.
A maturity assessment may examine:
MCIS may use a maturity scale ranging from an initial or informal capability to an optimised and integrated capability.
Example for MCIS
MCIS may determine that it has established business continuity plans, technology recovery procedures, cyber incident response arrangements, and crisis management protocols. However, the maturity assessment may reveal that these capabilities are managed separately and are not consistently linked to end-to-end customer services.
For example, individual departments may be able to recover their own processes, but management may not have a consolidated view of whether the entire claims settlement service can remain operational during a prolonged core insurance system outage.
The assessment would therefore identify the need to move from function-based recovery planning towards service-based operational resilience.
Key Output
The principal output is an Operational Resilience Capability and Maturity Assessment Report, supported by maturity scores, observations, strengths, weaknesses, and initial improvement priorities.
Plan Phase – Stage 2
The gap analysis compares MCIS’s current resilience capability against its desired future state.
While the maturity assessment establishes where the organisation is currently positioned, the gap analysis determines what is missing and what must change.
The analysis should consider gaps relating to:
Each gap should be evaluated based on:
Example for MCIS
MCIS may identify that its business continuity programme assigns recovery time objectives to business processes but does not establish impact tolerances for end-to-end Critical Business Services.
A further gap may be that critical third parties are assessed individually through procurement reviews, but the organisation does not fully understand how multiple third-party failures could collectively affect claims payment or premium collection.
Another gap may be that scenario testing focuses primarily on technology recovery and does not test the full customer journey across business units, applications, suppliers, payment channels, and communication arrangements.
Key Output
The principal output is an Operational Resilience Gap Analysis Report containing:
Plan Phase – Stage 3
The Operational Resilience Strategy defines what MCIS intends to achieve and how resilience will support the organisation’s wider business, customer, risk, and regulatory objectives.
The strategy should establish:
The roadmap converts the strategy into a sequenced implementation plan.
It should define:
The roadmap should be realistic and risk-based. MCIS does not need to address every weakness simultaneously. Priority should be given to gaps that expose policyholders or the organisation to the greatest potential harm.
Example for MCIS
MCIS may develop a three-year Operational Resilience roadmap.
The first year may focus on:
The second year may focus on:
The third year may focus on:
The roadmap may prioritise services such as claims management and settlement because disruption could cause immediate financial and emotional harm to policyholders and beneficiaries.
Key Output
The principal outputs are an approved:
Plan Phase – Stage 4
Risk appetite defines the nature and level of operational risk MCIS is prepared to accept in pursuit of its objectives.
Operational resilience does not assume that every disruption can be prevented. Instead, it requires management to determine how much disruption may be accepted before customer harm or organisational impact becomes intolerable.
The organisation’s operational resilience risk appetite should address matters such as:
Risk appetite should guide the later establishment of impact tolerances for individual Critical Business Services.
The relationship between risk appetite and impact tolerance should be clearly understood:
Example for MCIS
MCIS may determine that it has a very low appetite for disruptions that prevent eligible policyholders or beneficiaries from receiving approved claim payments.
It may also have a low appetite for:
These risk appetite statements would influence investment decisions, resilience controls, service tolerances, and escalation thresholds.
Key Output
The principal output is an approved set of Operational Resilience Risk Appetite Statements, Metrics, Thresholds, and Escalation Requirements.
Plan Phase – Stage 5
Governance provides the authority, accountability, oversight, and decision-making structure required to implement operational resilience effectively.
The governance model should define responsibilities for:
Effective governance requires more than the creation of committees. Operational resilience responsibilities should be embedded into:
Example for MCIS
MCIS may assign executive accountability for Operational Resilience to a designated senior executive, while individual Critical Business Service owners remain accountable for the resilience of their respective services.
The owner of Claims Management and Settlement, for example, would be responsible for:
A management-level Operational Resilience Committee may oversee programme progress, approve methodologies, review testing results, monitor remediation, and escalate material risks to the appropriate board committee.
Key Output
The principal outputs include:
The Implement Phase applies the strategic direction established during the Plan Phase to MCIS’s actual services and operating arrangements.
Its objective is to identify the services that matter most, understand how they are delivered, determine how much disruption can be tolerated, test the organisation’s ability to remain within those tolerances, and address identified weaknesses.
The five stages of the Implement Phase are:
Implement Phase – Stage 1
A Critical Business Service is a service delivered to customers or external stakeholders whose disruption could cause intolerable harm.
The identification process should focus on service outcomes rather than internal departments or isolated business processes.
MCIS should assess potential services against criteria such as:
Potential Critical Business Services for MCIS may include:
The final list should be proportionate and focused. If too many services are classified as critical, resources may become diluted and management attention may be weakened.
Example for MCIS
MCIS may identify Claims Management and Settlement as a Critical Business Service because its prolonged disruption could prevent policyholders or beneficiaries from receiving funds during illness, disability, hospitalisation, death, or other insured events.
Although many internal functions support claims settlement, the CBS should be defined as an end-to-end customer service rather than as separate claims registration, assessment, approval, and payment departments.
Key Output
The principal output is an approved Critical Business Services Register, including:
Implement Phase – Stage 2
Once a Critical Business Service has been identified, MCIS must understand how the service is delivered from end to end.
Dependency mapping identifies the people, processes, technology, data, facilities, and third parties required to deliver the service.
The mapping should include:
The objective is not to create process maps solely for documentation. The mapping should reveal vulnerabilities, concentrations, single points of failure, and dependencies that may prevent the service from remaining within its impact tolerance.
Example for MCIS
For the Claims Management and Settlement service, MCIS may map dependencies such as:
The mapping may reveal that both claims assessment and payment depend on a single core platform or that a manual workaround can support only a small percentage of normal transaction volume.
Key Output
The principal output is an End-to-End Dependency Map for each Critical Business Service, supported by a dependency inventory and vulnerability observations.
Implement Phase – Stage 3
Impact tolerance defines the maximum level of disruption that MCIS is willing to accept for a Critical Business Service before the resulting harm becomes intolerable.
An impact tolerance may include:
Impact tolerance differs from traditional recovery objectives.
A recovery time objective generally applies to the restoration of a system, process, or activity. An impact tolerance applies to the maximum acceptable disruption of the entire customer-facing service.
MCIS should set tolerances based on evidence and consider:
Example for MCIS
For Claims Management and Settlement, MCIS may determine that urgent claims involving hospitalisation, death benefits, or severe financial hardship require a more stringent tolerance than routine claims.
The impact tolerance may state that MCIS must not allow disruption to prevent priority claims from being assessed and paid beyond a defined maximum period.
Supporting measures may include:
The tolerance should be approved by an appropriately authorised governance body and supported by clear rationale.
Key Output
The principal output is an approved Impact Tolerance Statement and Supporting Metrics for each Critical Business Service.
Implement Phase – Stage 4
Scenario testing evaluates whether MCIS can continue delivering a Critical Business Service within its approved impact tolerance during severe but plausible disruption.
Testing should examine end-to-end service delivery rather than individual plans or systems in isolation.
Potential scenarios may include:
Scenario testing should challenge assumptions and examine:
Example for MCIS
MCIS may test a scenario in which ransomware makes the core policy administration and claims platforms unavailable for several days.
The exercise may assess whether MCIS can:
The test may reveal that systems can technically be recovered within the required period, but manual claims prioritisation and customer communication are insufficient. This would indicate that technology recovery alone does not provide complete service resilience.
Key Output
The principal output is a Scenario Testing Report documenting:
Implement Phase – Stage 5
Operational resilience testing has limited value unless findings are translated into measurable improvements.
Lessons should be obtained from:
MCIS should distinguish between:
Each improvement action should have:
The organisation should also determine whether a finding affects other services. A weakness identified in claims processing may also exist in policy issuance, premium collection, or customer servicing.
Example for MCIS
A ransomware scenario test may reveal that MCIS can recover its claims platform within the required period but cannot rapidly obtain an accurate list of urgent claims received immediately before the outage.
The resulting improvement actions may include:
Key Output
The principal output is an Operational Resilience Improvement Plan and Lessons-Learnt Register, supported by tracked actions and evidence of closure.
The Sustain Phase ensures that Operational Resilience becomes an enduring organisational capability rather than a temporary project.
It focuses on culture, communication, competence, self-assessment, and independent assurance.
The five stages of the Sustain Phase are:
Sustain Phase – Stage 1
Operational resilience depends on how people think, behave, make decisions, and respond under pressure.
A resilience culture encourages employees to:
Cultural change requires visible senior management commitment. Resilience should be reflected in leadership messages, performance objectives, project decisions, risk discussions, and investment priorities.
Example for MCIS
MCIS may introduce a requirement for business and technology teams to consider the effect of proposed changes on Critical Business Services.
When a new digital claims feature is introduced, project teams would not evaluate only cost, delivery schedule, and functionality. They would also assess:
This demonstrates that resilience has become part of routine decision-making.
Key Output
The principal output is an Operational Resilience Cultural Change Plan, supported by leadership actions, behavioural expectations, and measures of cultural adoption.
Sustain Phase – Stage 2
A communication strategy ensures that employees, management, service providers, customers, and other stakeholders receive appropriate information about operational resilience.
The strategy should address communication:
Internal communication should explain:
External communication arrangements should support:
Example for MCIS
During a disruption to digital policy servicing, MCIS may need to communicate differently with:
The communication strategy should establish approved channels, decision rights, message owners, escalation triggers, and pre-drafted templates.
Key Output
The principal output is an Operational Resilience Communication Strategy and Stakeholder Communication Framework.
Sustain Phase – Stage 3
Training and awareness ensure that individuals understand their resilience responsibilities and possess the competence required to perform them.
Training should be role-based.
Board and senior management training may cover:
Critical Business Service owners may require training on:
Operational employees may require training on:
Awareness activities may include:
Example for MCIS
Claims employees may receive practical training on how to process urgent claims when the primary claims platform is unavailable.
The training may include:
Key Output
The principal output is an Operational Resilience Training and Awareness Programme, including competency requirements, training records, and effectiveness measures.
Sustain Phase – Stage 4
Self-assessment enables MCIS to evaluate whether its Operational Resilience programme remains complete, effective, and aligned with approved requirements.
The self-assessment should consider:
The assessment should be evidence-based and should not rely solely on subjective declarations.
It should identify:
Example for MCIS
During its annual self-assessment, MCIS may identify that a major change to its digital customer platform introduced a new cloud service provider and additional application interfaces.
Although the platform was approved through normal project governance, the Critical Business Service dependency map may not yet reflect these changes.
The self-assessment would require the service owner to update the dependency map, review concentration risk, confirm recovery arrangements, and determine whether additional scenario testing is necessary.
Key Output
The principal output is an Operational Resilience Self-Assessment Report, supported by evidence, management attestations, identified exceptions, and improvement actions.
Sustain Phase – Stage 5
An Independent Quality Review provides objective assurance that MCIS’s Operational Resilience programme is appropriately designed, implemented, and maintained.
The review may be conducted by:
The review should assess:
Independent review should challenge whether management conclusions are supported by adequate evidence.
Example for MCIS
An independent reviewer may examine the Claims Management and Settlement service and determine that its impact tolerance is well documented but has been tested only against a technology outage.
The reviewer may recommend additional tests involving:
This challenge would improve confidence that the service can remain resilient under a sufficiently broad range of severe but plausible scenarios.
Key Output
The principal output is an Independent Operational Resilience Quality Review Report, including findings, ratings, recommendations, management responses, and agreed corrective actions.
The three phases of MCIS’s Operational Resilience Planning Methodology are mutually dependent.
The Plan Phase establishes direction, but it cannot demonstrate resilience unless the organisation implements service-based activities.
The Implement Phase produces maps, tolerances, tests, and improvements, but these capabilities will deteriorate unless they are sustained through culture, training, assessment, and assurance.
The Sustain Phase maintains programme effectiveness, but its findings may require MCIS to revisit its strategy, governance, risk appetite, service inventory, or testing approach.
The methodology should therefore operate as a continuous cycle:
Plan the capability, implement resilience around important services, sustain the capability, and use lessons and assurance findings to improve the next planning cycle.
An overview of the complete methodology is presented below.
|
Phase |
Stage |
Primary Question |
|
Plan |
Assess Capability and Maturity |
Where is MCIS today? |
|
Plan |
Analyse Gap |
What is missing or inadequate? |
|
Plan |
Develop Strategy and Roadmap |
What will MCIS achieve, and how? |
|
Plan |
Confirm Risk Appetite |
What level of operational risk is acceptable? |
|
Plan |
Develop and Embed Governance |
Who is accountable, and how will decisions be made? |
|
Implement |
Identify Critical Business Services |
Which services must be protected from intolerable disruption? |
|
Implement |
Map Processes and Resources |
What is required to deliver each service? |
|
Implement |
Set Impact Tolerance |
How much disruption can MCIS accept? |
|
Implement |
Conduct Scenario Testing |
Can the service remain within tolerance during severe disruption? |
|
Implement |
Improve Lessons Learnt |
What weaknesses must be corrected? |
|
Sustain |
Introduce Cultural Change |
Are resilience behaviours embedded in the organisation? |
|
Sustain |
Develop Communication Strategy |
Are stakeholders informed before, during, and after disruption? |
|
Sustain |
Implement Training and Awareness |
Do people possess the required knowledge and competence? |
|
Sustain |
Provide Self-Assessment |
Is the programme operating as intended? |
|
Sustain |
Conduct Independent Quality Review |
Is there objective assurance over programme effectiveness? |
Applying the methodology should enable MCIS to:
The methodology also provides a common language that can be used across MCIS by senior management, risk teams, business units, technology teams, service owners, auditors, and external stakeholders.
MCIS Insurance Bhd’s Operational Resilience Planning Methodology provides a structured enterprise approach for protecting the services that are most important to policyholders and other stakeholders. Its three phases—Plan, Implement, and Sustain—guide the organisation from initial capability assessment through service identification, dependency mapping, tolerance setting, scenario testing, cultural integration, self-assessment, and independent assurance.
The Plan Phase establishes the direction, priorities, risk boundaries, and governance required to manage resilience. The Implement Phase applies these foundations to Critical Business Services and tests whether they can remain within acceptable disruption limits. The Sustain Phase ensures that resilience becomes embedded in organisational culture, communication, competence, assessment, and assurance.
The methodology should not be regarded as a one-time compliance project. It is a continuous management cycle that enables MCIS to learn from disruption, respond to emerging risks, adapt to organisational change, and progressively strengthen its ability to protect customers.
The next chapter will build upon this overview by examining the first stage of the Plan Phase: Assessing MCIS Insurance Bhd’s Operational Resilience Capability and Maturity. This assessment will establish the organisation’s current position, identify existing strengths, and provide the evidence required for subsequent gap analysis, strategy development, and programme prioritisation.
Blogs marked [x] are under construction
| C1 | C2 [x] | C8 [x] | C14 [x] | |||
| BSP OR Policy | eBook 1 | eBook 2 | eBook 3 | C20 [x] | C21 [x] | |
| |
||||||
| "Plan" Phase of the Operational Resilience Planning Methodology |
||||||
| C2 [x] | C3 [x] | C4 [x] | C5 [x] | C6 [x] | C7 [x] | |
| "Implement" Phase of the Operational Resilience Planning Methodology | ||||||
| C8 [x] | C9 [x] | C10 [x] | C11 [x] | C12 [x] | C13 [x] | |
| "Sustain" Phase of the Operational Resilience Planning Methodology | ||||||
| C14 [x] | C15 [x] | C16 [x] | C17 [x] | C18 [x] | C19 [x] | |
Gain Competency: For organisations looking to accelerate their journey, BCM Institute’s training and certification programs, including the OR-5000 Operational Resilience Expert Implementer course, provide in-depth insights and practical toolkits for effectively embedding this model.
To learn more about the course and schedule, click the buttons below for the OR-300 Operational Resilience Implementer course and the OR-5000 Operational Resilience Expert Implementer course.
|
If you have any questions, click to contact us. |
||
|
|