The assessment must begin with the harm arising from loss or severe degradation of the end-to-end service rather than with the recovery capabilities of individual systems.
For Policy Issuance and Underwriting, unacceptable harm may arise when customers cannot obtain necessary insurance protection, underwriting decisions are materially delayed or incorrect, policies are issued using corrupted or incomplete information, regulatory screening is bypassed, or customers are uncertain whether coverage is valid.
The assessment must consequently consider all 14 Sub-CBS processes, from application intake through underwriting, pricing, policy issuance, record administration, quality assurance, incident response, and service restoration.
Cyberattack, ransomware, unauthorised access, application failure, database corruption, infrastructure outage, failed change, network disruption, or third-party ICT failure may interrupt several Sub-CBS processes simultaneously and accelerate the point at which customer harm becomes intolerable.
For this assessment, the following five-level scale is used:
This five-level scale expands the broader distinction between inconvenience, harm, and intolerable harm described in the reference methodology.
Table 1: Impact Tolerance Harm Assessment
|
Sub-CBS Code |
Name of Sub-CBS |
Potential Disruption |
Potential Harm |
Level of Harm |
Key Harm Indicators |
|
CBS-1.1 |
Customer Application Intake |
Digital application channels, intermediary submissions, branch intake, or contact-centre registration become unavailable or materially degraded. Applications may not be received, acknowledged, timestamped, or entered into the underwriting workflow. |
Prospective customers may be unable to apply for insurance protection, time-sensitive applications may be delayed, and intermediaries may resort to uncontrolled manual channels. Harm increases where applicants reasonably expect cover to commence within a defined period or where an application relates to imminent financial, medical, or contractual needs. |
High. A brief channel outage may cause inconvenience, but prolonged multi-channel disruption creates a growing backlog and prevents the entire service lifecycle from starting. |
Duration of intake outage; percentage of unavailable submission channels; number of unregistered applications; application backlog; percentage of affected applicants; failed or abandoned submissions; geographic spread; complaints; applications approaching validity or quotation-expiry dates. |
|
CBS-1.2 |
Application Validation and Completeness Review |
Applications cannot be checked for completeness, authenticity, mandatory fields, supporting documents, or identity information. Validation queues may accumulate or applications may proceed without required evidence. |
Customers may experience repeated requests for information, extended processing times, inconsistent treatment, or rejection caused by missing documentation. Allowing incomplete applications to proceed may create underwriting, conduct, fraud, and regulatory risks. |
High. The process is a key control gate. Prolonged disruption may either stop underwriting or result in uncontrolled processing using incomplete information. |
Number and age of unvalidated applications; incomplete-document rate; percentage processed manually; validation error rate; cases advanced without required evidence; customer resubmissions; complaints; control exceptions; backlog-clearance time. |
|
CBS-1.3 |
Customer Risk Profiling |
Customer, occupational, lifestyle, insurance-history, financial, or other relevant information cannot be consolidated or assessed. Risk-profiling rules may be unavailable or generate incomplete results. |
Applicants may be incorrectly classified, resulting in unsuitable underwriting pathways, inconsistent evidence requirements, inaccurate premiums, or inappropriate acceptance or rejection. Harm may not be immediately visible and could emerge after policy issuance or during claims assessment. |
High. Errors at this stage can propagate through underwriting, pricing, policy issuance, and future claims decisions. |
Percentage of profiles incomplete or manually produced; profiling error rate; volume of cases awaiting risk classification; override frequency; retrospective corrections; inconsistent classifications; customer disputes; policies requiring post-issuance review. |
|
CBS-1.4 |
Medical and Financial Underwriting Assessment |
Underwriters cannot access medical evidence, financial information, underwriting rules, case histories, or specialist advice. Assessment capacity may also be reduced by loss of specialist personnel or third-party medical services. |
Applications requiring medical or financial underwriting may remain undecided. Incorrect assessments could expose customers to inappropriate exclusions or loadings, expose MCIS to risks outside appetite, or result in disputes over disclosure and coverage. Vulnerable or time-sensitive applicants may face significant detriment. |
Very High. This is a central decision-forming process. Severe disruption can stop a substantial portion of policy issuance or produce materially defective underwriting outcomes. |
Number and value of pending assessments; longest outstanding case; percentage requiring specialist review; unavailable medical reports; decision-error rate; manual-assessment volume; high-sum-assured cases delayed; complaints; policies issued subject to later correction. |
|
CBS-1.5 |
Fraud Screening and Compliance Verification |
Fraud analytics, identity checks, sanctions screening, AML controls, duplicate-policy checks, or compliance-review capabilities become unavailable, inaccurate, or bypassed. |
MCIS may issue policies to prohibited, fraudulent, impersonated, or otherwise unsuitable applicants. Alternatively, legitimate customers may be incorrectly rejected or delayed. The disruption could lead to regulatory breaches, financial crime exposure, reputational damage, and remediation costs. |
Very High. A loss of screening integrity may create immediate regulatory and financial-crime concerns even where customer-facing service appears operational. |
Number of unscreened or partially screened applications; screening-system downtime; sanctions or watchlist age; false-positive and false-negative rates; manual overrides; cases issued under temporary risk acceptance; confirmed fraud cases; regulatory notifications; control-breach duration. |
|
CBS-1.6 |
Underwriting Decision Management |
Decision workflows, approval authorities, underwriting rules, referral routing, or decision records become unavailable or unreliable. Decisions may be delayed, duplicated, lost, or made outside delegated authority. |
Applicants may not receive timely or defensible decisions. Inconsistent acceptance, rejection, postponement, exclusions, or premium loadings may result in customer detriment and legal or conduct risk. A decision-integrity failure could lead to policies being issued without valid approval. |
Very High. The process converts assessments into binding underwriting outcomes and is a major control and accountability point. |
Number of undecided applications; age of decision backlog; decisions outside authority limits; duplicate or missing decisions; exception volume; percentage processed manually; decision reversals; customer complaints; unauthorised approvals. |
|
CBS-1.7 |
Premium Calculation and Pricing Confirmation |
Pricing engines, actuarial tables, product rules, underwriting loadings, discounts, tax calculations, or premium interfaces fail or produce incorrect results. |
Customers may be overcharged, undercharged, quoted inconsistent premiums, or issued policies on incorrect financial terms. MCIS may incur financial loss, require large-scale recalculation, or face conduct and regulatory concerns. |
Very High. Data-integrity or calculation errors can affect many policies before detection and may create binding contractual and financial consequences. |
Number and value of incorrect quotations; pricing variance from approved rules; affected product lines; calculation-error rate; retrospective premium adjustments; complaints; revenue leakage; policies suspended from issuance; duration of pricing uncertainty. |
|
CBS-1.8 |
Policy Documentation Preparation |
Policy schedules, certificates, benefit illustrations, exclusions, endorsements, terms, or disclosure documents cannot be generated or contain inaccurate information. |
Customers may not receive clear and accurate evidence of the cover offered. Incorrect documents may create uncertainty over benefits, exclusions, commencement dates, premiums, or contractual obligations. Policy issuance may have to be suspended even where underwriting has been completed. |
High. Short interruptions may be managed through controlled alternatives, but prolonged or integrity-related disruption creates contractual and customer-harm concerns. |
Number of documents not generated; document-error rate; missing clauses or schedules; affected products; reissued documents; customers awaiting policy packs; manual-document volume; printing or delivery backlog; complaints concerning policy terms. |
|
CBS-1.9 |
Policy Approval and Issuance |
Final approval, policy-number generation, policy activation, effective-date recording, or issuance confirmation fails. Policies may remain in an uncertain state between approval and activation. |
Customers may believe they are insured when no valid policy has been issued, or may be unable to demonstrate coverage. MCIS may face disputes where an insured event occurs during the interruption. Premium collection, administration, and downstream servicing may also be prevented. |
Very High. This is the point at which the underwriting outcome becomes an effective insurance contract. Uncertainty over coverage can rapidly become intolerable. |
Number of approved but unissued policies; issuance outage duration; customers without policy confirmation; policies with uncertain effective dates; duplicate policy numbers; activation failures; insured events occurring during the delay; backlog value; regulatory complaints. |
|
CBS-1.10 |
Customer and Distribution Notification |
Customers, agents, brokers, or other distribution partners cannot receive decisions, policy documents, premium instructions, special terms, or requests for further information. |
Customers may be unaware that an application was accepted, declined, postponed, or subject to exclusions or loadings. They may miss payment or acceptance deadlines, incorrectly assume coverage exists, or be unable to exercise cancellation and review rights. |
High. The underlying policy may exist, but failure to communicate its status and terms can cause significant customer misunderstanding and conduct risk. |
Undelivered communications; percentage of affected customers and intermediaries; notification delay; failed email, SMS, portal, or postal delivery; unread critical notices; missed acceptance or payment deadlines; complaints; duplicate contacts; manual-calling backlog. |
|
CBS-1.11 |
Policy Record Administration |
Policy master records, underwriting evidence, decision histories, documents, audit trails, or customer records cannot be created, updated, reconciled, or retrieved. |
Policy servicing, billing, claims processing, regulatory reporting, customer enquiries, and future underwriting may rely on incomplete or inconsistent records. Data loss or corruption could create widespread uncertainty over policy terms and status. |
Very High. Record integrity is essential not only to CBS-1 but also to downstream services throughout the policy lifecycle. |
Number of records unavailable or unreconciled; data-loss interval; database-integrity exceptions; policies missing audit trails; record-reconciliation backlog; downstream service failures; claims or billing cases affected; unauthorised record changes; restoration accuracy. |
|
CBS-1.12 |
Exception and Referral Management |
Complex, high-risk, high-value, unusual, or policy-exception cases cannot be routed to specialist underwriters, medical advisers, legal specialists, compliance officers, or approval authorities. |
Applicants with non-standard circumstances may face lengthy delays or inconsistent decisions. Pressure to bypass referrals could result in unauthorised risk acceptance, inappropriate exclusions, or customer unfairness. Concentration on a small number of specialists may amplify the disruption. |
High. The overall volume may be smaller, but individual cases may carry substantial customer, financial, legal, or reputational consequences. |
Number and value of pending referrals; age of oldest case; unavailable specialists; percentage of cases awaiting external evidence; cases processed outside referral rules; high-sum-assured exposure; temporary risk acceptances; decision reversals. |
|
CBS-1.13 |
Underwriting Quality Assurance and Compliance Monitoring |
Quality reviews, control monitoring, exception reporting, management information, or compliance surveillance become unavailable or are materially delayed. Defective decisions may therefore remain undetected. |
Systematic underwriting, pricing, documentation, or compliance errors may continue across a growing population of applications. Management may lack evidence that the service remains within risk appetite and regulatory requirements. |
High. The immediate customer-facing disruption may be limited, but prolonged loss of assurance increases the likelihood and scale of undetected harm. |
QA-review backlog; percentage of cases not reviewed; overdue compliance checks; unresolved findings; repeat exceptions; management reports unavailable; control-failure detection time; affected policy population; remediation backlog. |
|
CBS-1.14 |
Underwriting Incident and Service Recovery Management |
Incident detection, escalation, command, communications, business continuity arrangements, cyber response, technology recovery, or service-restoration coordination fails during a disruption. |
The original incident may continue for longer, spread across additional Sub-CBS processes, or be recovered inconsistently. Customers and intermediaries may receive inaccurate information, backlogs may grow, and the overall service may exceed its Impact Tolerance. |
Very High. Failure of coordinated incident and recovery management directly increases the duration, scope, and severity of harm across the complete CBS. |
Time to detect, declare, and escalate; time to activate continuity arrangements; number of Sub-CBS affected; recovery-progress variance; backlog growth; percentage of staff or channels restored; communication accuracy; recovery test performance; duration beyond tolerance. |
Table 2: Cyber and ICT Risk Integration and Proactive Risk Management
|
Sub-CBS Code |
Name of Sub-CBS |
Cyber and ICT Risk Linkage |
Contribution to Impact Tolerance Breach |
Proactive Risk Management Action |
Evidence of Proactive Risk Management |
|
CBS-1.1 |
Customer Application Intake |
Distributed denial-of-service attacks, portal or API failure, network outage, bot activity, ransomware, failed digital-channel change, identity-service outage, or capacity exhaustion could prevent or distort application submissions. |
Simultaneous loss of digital, intermediary, and branch-assisted channels would prevent new applications from entering the service. The resulting backlog and customer exclusion could cause the CBS to exceed its permitted duration or affected-customer threshold. |
Maintain diverse intake channels; protect internet-facing services with DDoS controls; test capacity and rate limiting; implement secure offline or deferred-capture procedures; monitor failed submissions; provide controlled channel switching; include intake services in cyber and disaster-recovery exercises. |
DDoS-test results; channel-failover reports; capacity-monitoring dashboards; application-availability reports; vulnerability and penetration-test results; continuity procedure approvals; scenario-test records; remediation logs. |
|
CBS-1.2 |
Application Validation and Completeness Review |
Document-management failure, malware-infected uploads, optical or automated validation errors, identity-verification API failure, unauthorised alteration, or database outage may prevent reliable validation. |
Applications may accumulate or proceed without required evidence. A prolonged loss of validation controls may force MCIS to stop processing, while uncontrolled workarounds could increase fraud, privacy, and compliance exposure. |
Apply secure file scanning and validation; maintain integrity checks and document versioning; provide controlled manual-validation procedures; reconcile deferred validations; monitor interface failures; segregate validation approvals; test restoration of document repositories. |
Secure-upload logs; malware-detection records; access-control reviews; document-repository recovery tests; validation exception reports; manual-control testing; reconciliation evidence; risk-acceptance records. |
|
CBS-1.3 |
Customer Risk Profiling |
Data corruption, unauthorised changes to profiling rules, failed system integration, inaccurate customer-history retrieval, privileged-access compromise, or analytics-model failure may create incorrect profiles. |
Incorrect profiles may pass unnoticed into underwriting and pricing, producing widespread decision errors. The service may technically remain available while breaching data-integrity and customer-harm thresholds. |
Implement rule-change governance; maintain source-to-profile reconciliation; monitor anomalous overrides and classifications; restrict privileged access; validate profiling logic after changes; retain traceable source data; conduct retrospective sampling. |
Approved change records; user-access recertification; profiling-model validation; reconciliation reports; anomaly-monitoring records; QA sampling results; privileged-access logs; post-implementation review findings. |
|
CBS-1.4 |
Medical and Financial Underwriting Assessment |
Underwriting-platform failure, ransomware, medical-information interface outage, unauthorised access to sensitive records, database latency, remote-access failure, or third-party medical-system disruption could stop assessments. |
A prolonged outage would halt cases requiring specialist assessment and may expose sensitive personal or medical data. Loss of confidentiality, integrity, or availability could independently create unacceptable harm. |
Segment and protect underwriting environments; encrypt sensitive data; apply least-privilege access; maintain secure alternative access to essential evidence; cross-train underwriters; establish manual-assessment thresholds; test recovery with third-party medical providers. |
Access reviews; encryption-control tests; cyber-monitoring alerts; underwriting-platform recovery tests; third-party assurance reports; cross-training records; tabletop and simulation reports; data-restoration validation. |
|
CBS-1.5 |
Fraud Screening and Compliance Verification |
Screening-platform outage, sanctions-data interruption, cyber manipulation of screening rules, API failure, stale watchlists, privileged compromise, or false-result generation could undermine the control. |
A large volume of applications may remain unscreened, or prohibited applicants may be issued policies. Because integrity is critical, even a relatively short disruption could breach the tolerance where screening cannot be completed retrospectively before issuance. |
Use fail-secure processing rules; suspend issuance where mandatory checks cannot be completed; maintain alternative screening capability; monitor watchlist currency; independently validate screening changes; apply dual approval for overrides; reconcile all deferred checks. |
Watchlist-update reports; screening uptime records; override logs; dual-approval evidence; change-test results; deferred-screening reconciliation; financial-crime control assessments; incident-response records. |
|
CBS-1.6 |
Underwriting Decision Management |
Workflow-engine failure, decision-record corruption, unauthorised approval, identity and access-management failure, failed rule deployment, or queue-routing defects may prevent or invalidate decisions. |
Applications may remain undecided or be approved outside authority. A loss of decision integrity can create policies that cannot be demonstrated as validly authorised, accelerating regulatory and contractual harm. |
Enforce role-based and delegated-authority controls; use strong authentication; maintain immutable decision audit trails; test workflow changes; reconcile pending and completed cases; establish controlled manual approval procedures; monitor unusual decision patterns. |
Delegated-authority matrices; access recertification; authentication logs; workflow-control testing; audit-trail reviews; decision-reconciliation reports; change-approval records; exception-monitoring dashboards. |
|
CBS-1.7 |
Premium Calculation and Pricing Confirmation |
Pricing-engine defects, corrupted actuarial tables, unauthorised rule changes, failed deployment, interface errors, rounding or tax-calculation defects, and database failure could generate inaccurate premiums. |
A single technology defect may affect a high volume of quotations and policies. Incorrect pricing may create widespread customer remediation, financial loss, or suspension of affected products, thereby breaching integrity and scope thresholds. |
Apply independent pricing-model validation; segregate development and approval; use automated regression testing; monitor price outliers; maintain version-controlled tables; provide rapid rollback; reconcile issued premiums against approved parameters. |
Pricing-model approvals; regression-test evidence; change and rollback records; outlier-monitoring reports; actuarial sign-off; premium-reconciliation results; post-release reviews; remediation tracking. |
|
CBS-1.8 |
Policy Documentation Preparation |
Document-generation failure, template corruption, unauthorised clause changes, print-service outage, malware, data-merging errors, or storage failure may prevent accurate policy documents from being produced. |
Incorrect or unavailable documents may force issuance to stop or result in customers receiving defective contractual information. A template defect could affect an entire product population before discovery. |
Control document templates; require legal, compliance, and business approval; verify data-to-document mapping; maintain alternative secure generation capability; monitor template changes; reconcile generated documents; test document recovery and reissuance. |
Approved-template register; change logs; sample-document testing; mapping-validation results; document-generation availability reports; reissuance procedures; access reviews; recovery-test reports. |
|
CBS-1.9 |
Policy Approval and Issuance |
Policy-administration failure, database outage, duplicate-number generation, privileged-access compromise, failed batch processing, infrastructure outage, or time-synchronisation error may prevent or corrupt issuance. |
Customers may have uncertain coverage status, conflicting effective dates, or duplicate policies. Because the process creates the policy contract, disruption or integrity failure can breach tolerance rapidly, particularly if an insured event occurs during the outage. |
Design resilient issuance architecture; maintain database replication and tested recovery; protect policy-number generation; synchronise system time; use transaction-integrity controls; reconcile approved-to-issued populations; define emergency evidence-of-cover arrangements subject to legal approval. |
High-availability test results; database failover reports; recovery-point validation; time-synchronisation monitoring; policy-number reconciliation; privileged-access logs; emergency procedure approvals; scenario-test outcomes. |
|
CBS-1.10 |
Customer and Distribution Notification |
Email, SMS, portal, telephony, print, or intermediary interfaces may fail because of network outage, cyberattack, provider disruption, domain compromise, or incorrect contact-data extraction. |
Customers may remain unaware of policy status or material terms. Multi-channel concentration or compromise could cause a large-scale notification failure and contribute to customer misunderstanding beyond tolerance. |
Maintain channel diversity; authenticate outbound communications; monitor delivery failures; establish priority-calling and intermediary-notification procedures; validate contact-data extracts; test alternative communications; assess external communications providers. |
Delivery dashboards; failed-message reports; alternative-channel tests; provider assurance reports; phishing-control records; communication exercise reports; contact-data reconciliation; incident logs. |
|
CBS-1.11 |
Policy Record Administration |
Ransomware, database corruption, unauthorised changes, backup failure, replication error, cloud or infrastructure outage, excessive access, or failed data migration could damage policy records. |
Loss or corruption of policy records may affect underwriting, billing, servicing, claims, reporting, and customer confirmation simultaneously. The breadth and persistence of harm could cause an immediate or prolonged Impact Tolerance breach. |
Maintain immutable and offline backups; implement database-integrity monitoring; restrict and monitor privileged access; test point-in-time restoration; reconcile master and downstream records; segment critical data stores; establish cyber-recovery environments and clean-room procedures. |
Backup-success reports; immutable-backup tests; cyber-recovery exercises; restoration and reconciliation evidence; privileged-access reviews; database-integrity alerts; penetration-test findings; independent assurance reports. |
|
CBS-1.12 |
Exception and Referral Management |
Workflow or collaboration-platform failure, secure file-transfer outage, loss of remote access, specialist directory failure, third-party portal outage, or cyber compromise of referral information may interrupt complex cases. |
High-value or unusual applications may remain unresolved, while attempts to bypass referrals could create unauthorised risk acceptance. Concentration in individual specialists or a single collaboration platform may accelerate the backlog. |
Identify specialist concentration risks; maintain deputies and succession arrangements; establish secure alternative referral methods; protect sensitive case information; define manual referral registers; monitor aging cases; test specialist unavailability scenarios. |
Skills and deputy matrices; access-control results; manual-referral test records; aging reports; third-party assurance; secure-transfer logs; scenario-test results; management review minutes. |
|
CBS-1.13 |
Underwriting Quality Assurance and Compliance Monitoring |
Reporting-platform outage, incomplete data feeds, logging failure, tampering with assurance records, analytics defects, or delayed batch processing may obscure control failures. |
Defective underwriting or pricing may continue undetected until the affected population becomes large enough to exceed customer, financial, or regulatory thresholds. |
Maintain independent data sources; reconcile assurance populations to production; protect logs from alteration; monitor data-feed completeness; define manual sampling during outages; prioritise high-risk cases; test monitoring-platform recovery. |
Data-completeness reports; log-integrity controls; QA reconciliation; manual-review records; monitoring-system recovery tests; overdue-review dashboards; compliance committee minutes; independent-review findings. |
|
CBS-1.14 |
Underwriting Incident and Service Recovery Management |
Incident-management tools, security monitoring, backup communications, recovery environments, identity services, network connectivity, or crisis-coordination platforms may fail during a major event. Technology concentration may cause production and recovery capabilities to fail together. |
Delayed detection, escalation, containment, decision-making, or recovery would extend the disruption across multiple Sub-CBS processes. Failure at this stage is highly likely to cause the overall CBS to exceed its permitted time, scope, and integrity thresholds. |
Maintain integrated cyber, ICT, business continuity, crisis-management, and operational-resilience arrangements; establish out-of-band communications; test clean recovery; define service-prioritised recovery sequencing; conduct severe but plausible scenarios; maintain executive escalation and regulatory-notification procedures. |
Integrated response plans; incident-command records; crisis exercises; cyber-recovery test reports; recovery-sequencing documentation; call-tree tests; regulatory-notification exercises; management committee minutes; lessons-learned and remediation reports. |
The following is an illustrative implementation recommendation and should be validated and formally approved by MCIS senior management, the CBS owner, Operational Resilience and Operational Risk functions, underwriting leadership, actuarial and compliance functions, technology and cybersecurity owners, legal advisers, and relevant governance committees.
It should also be reviewed against applicable Bank Negara Malaysia requirements and MCIS's actual customer volumes, product commitments, risk appetite, contractual obligations, technology architecture, and historical performance.
MCIS should be able to continue or restore CBS-1 Policy Issuance and Underwriting so that no widespread uncertainty exists regarding whether insurance coverage has been validly approved or issued; no material population of customers is exposed to incorrect underwriting, pricing, screening, policy terms, or effective dates; and no more than 10% of the normal daily application volume remains unable to progress through controlled service channels for longer than 24 hours.
The outer maximum tolerable duration for complete loss of new-policy issuance should be 24 hours. Critical control and data-integrity failures affecting identity verification, fraud and compliance screening, underwriting decisions, premium calculations, policy approval, policy effective dates, or policy records should have a tolerance approaching zero for unverified processing: affected transactions should be stopped, isolated, or subjected to approved compensating controls rather than allowed to continue with uncertain integrity.
Where service is degraded rather than fully unavailable, MCIS should retain the ability to receive and securely register at least 90% of normal daily application volume, prioritise urgent and vulnerable-customer cases, communicate the status of affected applications, and prevent the backlog from exceeding one normal business day's processing capacity.
|
Dimension |
Illustrative Threshold |
|
Maximum complete service interruption |
No more than 24 hours for complete inability to approve and issue new policies through all controlled channels. |
|
Priority service restoration |
Customer application receipt, compliance screening, underwriting decision controls, policy approval, issuance-status confirmation, and policy-record integrity should receive the highest recovery priority. |
|
Customer scope |
No more than 10% of normal daily applicants should remain unable to submit or progress an application through any controlled channel for longer than 24 hours. |
|
Channel scope |
Loss of one channel may be tolerated where other controlled channels remain available and have sufficient capacity. Simultaneous loss of all material intake or communication channels should not continue beyond the 24-hour outer limit. |
|
Minimum degraded-service capacity |
MCIS should seek to retain or restore at least 90% of normal daily intake capability, or an approved minimum capacity sufficient to prevent backlog growth beyond one normal business day's workload. |
|
Application backlog |
The unresolved backlog attributable to the disruption should not exceed one normal business day's application volume without executive escalation, customer communication, and an approved recovery plan. |
|
Urgent and vulnerable customers |
Applications identified as urgent, time-sensitive, or involving potentially vulnerable customers should be triaged and progressed through controlled alternative arrangements within four hours of classification, where sufficient information and legal authority exist. |
|
Underwriting and decision integrity |
Zero tolerance for knowingly issuing policies without required underwriting approval, mandatory compliance screening, authorised pricing, or validated policy terms. |
|
Pricing and policy-document accuracy |
No material policy population should be issued using unvalidated premium calculations, corrupted product rules, inaccurate exclusions, or defective contractual documents. Affected issuance should be suspended until integrity is confirmed. |
|
Policy-status certainty |
No customer should be left with unresolved uncertainty concerning whether coverage is effective for longer than four hours after MCIS identifies the ambiguity, particularly where an insured event may occur. |
|
Data loss and recovery |
Policy, underwriting, approval, screening, pricing, and issuance records should be recoverable to a validated point that prevents loss of committed policy decisions or unauthorised reconstruction. Any potential data loss should be reconciled before further processing. |
|
Data latency |
Customer, underwriting, screening, pricing, and issuance data used for decisions should be current and validated. Stale or delayed information should not be used where it could materially alter eligibility, screening, pricing, or policy terms. |
|
Regulatory-control threshold |
Mandatory regulatory, sanctions, AML, fraud, privacy, delegated-authority, and recordkeeping controls should not be bypassed solely to maintain processing volumes. Processing should be paused or managed under formally approved compensating controls. |
|
Geographic scope |
A local site or channel disruption may remain within tolerance where services can be transferred to another location or remote arrangement. A nationwide loss of controlled application and issuance capability would represent a severe condition requiring immediate executive escalation. |
|
Third-party disruption |
Dependence on medical providers, intermediaries, hosting services, telecommunications providers, or communications channels should not prevent MCIS from maintaining minimum controlled service or communicating the status of applications within the proposed tolerance. |
|
Point of intolerable harm |
Harm becomes intolerable when disruption exceeds 24 hours across the service, when a material customer population cannot obtain or confirm coverage, when policy or pricing integrity cannot be established, when mandatory screening is bypassed, or when corrupted records create uncertainty that cannot be rapidly contained and reconciled. |
A 24-hour outer limit is appropriate as an initial implementation assumption because Policy Issuance and Underwriting is important to customers but is not generally a real-time transaction service comparable with immediate access to deposits or emergency payment processing.
A short delay may therefore constitute inconvenience rather than intolerable harm. However, the harm profile can escalate rapidly where:
The tolerance should therefore combine duration, affected-customer scope, service capacity, backlog, decision integrity, data integrity, and regulatory-control thresholds. Time alone would be insufficient.
A service could be restored within 24 hours but still cause unacceptable harm if incorrect premiums, exclusions, effective dates, screening results, or policy records were produced during the incident.
The proposed 24-hour boundary is not an RTO. The supporting RTOs for critical applications and operational processes should be set materially inside that boundary to allow time for incident detection, technical recovery, data validation, business reconciliation, backlog management, customer communication, and controlled restoration.
For example, MCIS may determine that the Policy Administration System requires a four-hour RTO and a tightly controlled RPO to support the 24-hour CBS Impact Tolerance.
These technical targets contribute to the service outcome but do not replace the service-level tolerance.
Similarly:
Although every Sub-CBS contributes to CBS-1, the following processes require particular attention because their failure can rapidly produce unacceptable harm or propagate disruption across the service:
CBS-1.5 Fraud Screening and Compliance Verification
The service should not continue through uncontrolled bypass of mandatory screening. Availability can be restored through alternative controls, but the integrity of compliance decisions must remain protected.
CBS-1.6 Underwriting Decision Management
Underwriting decisions must be properly authorised, recorded, and traceable. A technically available service that produces unauthorised or inconsistent decisions cannot be considered resilient.
CBS-1.7 Premium Calculation and Pricing Confirmation
Pricing errors can affect large populations before detection. Preventive validation, rapid rollback, and population-level reconciliation are therefore essential.
CBS-1.9 Policy Approval and Issuance
This process determines whether a valid policy exists. Uncertainty at this point can create immediate contractual and customer harm, especially where an insured event occurs during disruption.
CBS-1.11 Policy Record Administration
Reliable policy and underwriting records are essential to billing, servicing, claims management, customer communication, and regulatory evidence. Data corruption may therefore affect multiple Critical Business Services.
CBS-1.14 Underwriting Incident and Service Recovery Management
Incident and recovery coordination determines whether the original disruption remains contained or expands beyond the Impact Tolerance. Recovery must be prioritised according to customer and service outcomes rather than technical convenience.
A breach of the CBS-1 Impact Tolerance may affect or be amplified by disruption to other MCIS Critical Business Services, including:
The final Impact Tolerance should therefore be tested not only against a standalone underwriting outage but also against compound scenarios in which one or more connected services are disrupted simultaneously.
MCIS should validate the proposed Impact Tolerance using scenarios that test both availability and integrity, including:
Each scenario should determine whether MCIS can maintain the minimum service outcome, prevent invalid processing, protect data integrity, communicate with affected customers, and recover before the 24-hour outer limit or other defined harm thresholds are exceeded.
Senior management and the responsible governance committees should receive evidence demonstrating that the Impact Tolerance is supported by practical capabilities rather than existing only as a policy statement.
Evidence should include:
The Impact Tolerance for CBS-1 Policy Issuance and Underwriting establishes a clear boundary between manageable disruption and unacceptable harm.
It directs MCIS to preserve the customer and regulatory outcomes of the service rather than focusing only on whether individual systems have been restored.
The analysis of all 14 Sub-CBS processes demonstrates how an interruption can propagate from application intake through risk assessment, compliance screening, underwriting decisions, pricing, policy issuance, communication, and policy-record administration.
Integrating Cyber and ICT Risks strengthens the assessment by recognising that service availability alone is not sufficient.
A service cannot be considered resilient where underwriting decisions, premiums, policy documents, effective dates, or customer records are inaccurate, corrupted, unauthorised, or incapable of being validated.
Preventive, detective, response, recovery, and resilience controls must therefore protect the confidentiality, integrity, availability, and recoverability of the complete service.
The proposed 24-hour outer limit, affected-customer threshold, minimum degraded-service capacity, backlog boundary, and near-zero tolerance for unverified processing provide an initial basis for management consideration.
They should be calibrated against MCIS's actual application volumes, customer profiles, product characteristics, contractual commitments, historical incidents, dependency architecture, risk appetite, and applicable regulatory expectations.
Once approved, the Impact Tolerance should guide scenario design, technology and third-party resilience requirements, recovery priorities, control testing, remediation decisions, investment planning, incident escalation, and management reporting.
It should be reviewed whenever MCIS changes its products, processes, distribution channels, technology platforms, data architecture, outsourcing arrangements, customer commitments, or operating environment.
Through regular validation and evidence-based testing, the Impact Tolerance can remain a practical management boundary that supports sustained delivery of Policy Issuance and Underwriting during severe but plausible disruption.
| eBook 3: Starting Your OR Implementation |
||||
| CBS-1 Policy Issuance and Underwriting | ||||
| CBS-1 DP | CBS-1 MII | CBS-1 ITo | CBS-1 SbPS | CBS-1 ST |
Gain Competency: For organisations looking to accelerate their journey, BCM Institute’s training and certification programs, including the OR-5000 Operational Resilience Expert Implementer course, provide in-depth insights and practical toolkits for effectively embedding this model.
To learn more about the course and schedule, click the buttons below for the OR-300 Operational Resilience Implementer course and the OR-5000 Operational Resilience Expert Implementer course.
|
If you have any questions, click to contact us. |
||
|
|