---
title: [OR] [PIDM] [E1] [C1] Introducing OR Case Study
description: [OR] [PIDM] [E1] [C1] Introducing OR Case Study
image: https://blog.bcm-institute.org/hubfs/PIDM%20Graphic%20Folder/PIDM%20Morepost/%5BOR%5D%20%5BPIDM%5D%20%5BE1%5D%20%5BC1%5D%20Introducing%20OR%20Case%20Study.jpg
---

.

[![BCMIWhiteLogo.png](https://blog.bcm-institute.org/hs-fs/hubfs/Blog%20Testing/BCMIWhiteLogo.png?width=556&name=BCMIWhiteLogo.png "BCMIWhiteLogo.png")](http://www.bcm-institute.org/)

- [Home](https://www.bcm-institute.org/)
- [About Us](https://www.bcm-institute.org/about-us-3/) 
    - [A President’s Perspective](https://www.bcm-institute.org/about-us/a-presidents-perspective/)
    - [Our History](https://www.bcm-institute.org/about-us/our-history/)
    - [Our Advisory Council](https://www.bcm-institute.org/about-us/our-advisory-council/)
    - [Customers’ Testimonials](https://www.bcm-institute.org/about-us/customers-testimonials/)
    - [Credential Verification](https://www.bcm-institute.org/about-us/credential-verification/)
- [Courses](https://blog.bcm-institute.org/blog/course-fees-for-blended-learning-courses-master-catalog) 
    - [ISO 22301 Business Continuity Management System Audit](https://blog.bcm-institute.org/audit/business-continuity-management-audit-courses)
    - [ISO 22301 Business Continuity Management](https://blog.bcm-institute.org/bcm/business-continuity-management-courses)
    - [Crisis Communication](https://blog.bcm-institute.org/crisis-communication/crisis-communication-courses)
    - [Crisis Management](https://blog.bcm-institute.org/en/crisis-management/courses)
    - [IT Disaster Recovery](https://blog.bcm-institute.org/it-disaster-recovery/courses)
    - [Operational Resilience](https://blog.bcm-institute.org/operational-resilience/courses)
    - [Operational Resilience Audit](https://blog.bcm-institute.org/operational-resilience-audit/courses)
- [Certification](https://blog.bcm-institute.org/certification/types-of-certifications-offered) 
    - [ISO 22301 BCMS Audit Certification](https://blog.bcm-institute.org/certification/business-continuity-management-audit-certification)
    - [ISO22301 Business Continuity Management Certification](https://blog.bcm-institute.org/bcm/business-continuity-management-certification)
    - [Crisis Communication Certification](https://blog.bcm-institute.org/crisis-communication/crisis-communication-certification)
    - [Crisis Management Certification](https://blog.bcm-institute.org/en/crisis-management/crisis-management-certification)
    - [IT Disaster Recovery Planning Certification](https://blog.bcm-institute.org/it-disaster-recovery/it-disaster-recovery-certification)
    - [Operational Resilience Certification](https://blog.bcm-institute.org/operational-resilience/operational-resilience-certification)
    - [Operational Resilience Audit Certification](https://blog.bcm-institute.org/operational-resilience-audit)
- [Seminars](https://blog.bcm-institute.org/meet-the-expert/mte-webinar-mainpage)
- [Store](https://www.bcm-institute.org/store-2/)
- [Contact Us](http://www.bcm-institute.org/about-us/contact-us/)

- <https://www.facebook.com/BCMInstitute/>
- <https://www.linkedin.com/company/business-continuity-management-institute-bcm-institute>

###### Building Operational Resilience at PIDM: A Strategic Implementation Guide

![BB OR \[D\] 1](https://blog.bcm-institute.org/hs-fs/hubfs/OR%20picture/OR%20Pictures%20A/BB%20OR%20Folder%20D/BB%20OR%20%5BD%5D%201.jpg?width=2000&height=1333&name=BB%20OR%20%5BD%5D%201.jpg "BB OR [D] 1")

# \[OR\] \[PIDM\] \[E1\] \[C1\] Introducing OR Case Study

[![New call-to-action](https://no-cache.hubspot.com/cta/default/3893111/7a6f5c32-e8ae-42c9-acb3-ba7f4b3f4998.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/7a6f5c32-e8ae-42c9-acb3-ba7f4b3f4998)

[![eBook Cover \[OR\] \[PIDM\] \[E1\] \[2D\] ](https://no-cache.hubspot.com/cta/default/3893111/6dd47adf-d0be-42c1-9f8c-27b4a9421256.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/6dd47adf-d0be-42c1-9f8c-27b4a9421256)

Operational Resilience (OR) concerns an organisation's ability to continue delivering its Critical Business Services (CBS) during severe operational disruption without causing unacceptable harm.

It requires an organisation to understand which services matter most, how they are delivered, what resources and external parties they depend on, and whether those services can withstand significant disruption.

For Perbadanan Insurans Deposit Malaysia (PIDM), this assessment must be considered in the context of its role in Malaysia's financial protection and resolution framework.

PIDM's operational responsibilities involve deposit insurance, takaful and insurance benefits protection, preparedness for member institution failure, resolution-related activities, and communication with affected stakeholders.

Disruption to these responsibilities may have consequences extending beyond PIDM's internal operations.

Depending on the circumstances, it could affect the availability of protection information, the timely fulfilment of protection obligations, coordination with member institutions, and confidence in financial protection arrangements.

[![New call-to-action](https://no-cache.hubspot.com/cta/default/3893111/82999100-d8aa-47ed-b3b7-b418c3698d2a.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/82999100-d8aa-47ed-b3b7-b418c3698d2a)

[Moh Heng Goh](https://blog.bcm-institute.org/ebook-or/author/moh-heng-goh) Sep 23, 2026

###### Operational Resilience Certified Planner-Specialist-Expert

### [![New call-to-action](https://no-cache.hubspot.com/cta/default/3893111/52e8419c-3654-4d2f-815d-aa9dca0619a5.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/52e8419c-3654-4d2f-815d-aa9dca0619a5)

### eBook 1: Chapter 1

### [![New call-to-action](https://no-cache.hubspot.com/cta/default/3893111/82999100-d8aa-47ed-b3b7-b418c3698d2a.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/82999100-d8aa-47ed-b3b7-b418c3698d2a)

### **Operational Resilience Case Study for PIDM**

[![\[OR\] \[PIDM\] \[E1\] \[C1\] Introducing OR Case Study](https://no-cache.hubspot.com/cta/default/3893111/e3c0c51a-9a45-4f10-bc1c-0d55c1312940.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/e3c0c51a-9a45-4f10-bc1c-0d55c1312940)[![eBook Cover \[OR\] \[PIDM\] \[E1\] \[2D\] ](https://no-cache.hubspot.com/cta/default/3893111/6dd47adf-d0be-42c1-9f8c-27b4a9421256.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/6dd47adf-d0be-42c1-9f8c-27b4a9421256)Operational Resilience (OR) concerns an organisation's ability to continue delivering its Critical Business Services (CBS) during severe operational disruption without causing unacceptable harm.

It requires an organisation to understand which services matter most, how they are delivered, what resources and external parties they depend on, and whether those services can withstand significant disruption.

For Perbadanan Insurans Deposit Malaysia (PIDM), this assessment must be considered in the context of its role in Malaysia's financial protection and resolution framework.

PIDM's operational responsibilities include deposit insurance, takaful, and insurance benefits protection; preparedness for member institution failure; resolution-related activities; and communication with affected stakeholders.

Disruption to these responsibilities may have consequences extending beyond PIDM's internal operations. Depending on the circumstances, it could affect the availability of protection information, the timely fulfilment of protection obligations, coordination with member institutions, and confidence in financial protection arrangements.

PIDM's Operational Resilience programme should therefore focus on continuing to deliver critical outcomes rather than recovering individual systems or departments alone.

This chapter introduces PIDM as the subject of a practical implementation case study. It establishes the organisational context, preliminary assumptions, proposed governance structure, potential Critical Business Services, and strategic objectives needed to begin developing an enterprise-wide Operational Resilience programme.

This chapter provides a foundation for subsequent assessments. It does not represent a verified description of PIDM's internal operating arrangements or an approved PIDM Operational Resilience policy.

#### **Purpose and Scope of the Chapter**

This chapter establishes a common understanding of PIDM before detailed Operational Resilience planning begins.

The assessment addresses eight interconnected areas:

1. PIDM's organisational context and the importance of its protection and resolution responsibilities.
2. The purpose and intended outcomes of an Operational Resilience programme.
3. The organisation's operating environment and relevant Malaysian regulatory considerations.
4. The proposed structure and responsibilities of an Operational Resilience implementation team.
5. The identification and preliminary assessment of Critical Business Services.
6. The characteristics that influence PIDM's resilience requirements.
7. The organisational goals and objectives that should guide implementation.
8. The assumptions and initial risks that require validation during subsequent stages.

The chapter provides a preliminary implementation framework.

Detailed process decomposition, dependency mapping, Impact Tolerance assessment, and scenario testing should be undertaken only after PIDM has validated the relevant organisational information and established appropriate governance.

##### **Expected Chapter Outcomes**

By the end of this chapter, readers should be able to explain PIDM's operational context, identify the principal areas requiring resilience protection, propose an appropriate implementation team, and establish initial goals for the Operational Resilience programme.

They should also understand which assumptions require confirmation before the case study can be converted into a formal organisational assessment.

 

#### **[![New call-to-action](https://no-cache.hubspot.com/cta/default/3893111/6d07484c-bfdd-4a00-983b-8d2c54bad8e4.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/6d07484c-bfdd-4a00-983b-8d2c54bad8e4)Understanding Your Organisation: PIDM**

##### **Organisational Mandate and Resilience Context**

PIDM is Malaysia's deposit insurer and administers protection arrangements for eligible deposits and takaful and insurance benefits.

Its role also encompasses preparedness and responsibilities associated with member institution failures and resolution.

These functions give PIDM a distinctive operating profile. Unlike a commercial bank, PIDM does not primarily deliver everyday deposit-taking, lending, or payment services.

Its critical outcomes concern administering protection arrangements and acting effectively when circumstances require protection or resolution mechanisms to be activated.

Operational Resilience should consequently be assessed in two operating states:

 

| Operating state | Characteristics | Resilience implications |
| --- | --- | --- |
| Business-as-usual | Routine administration, information collection, premium-related activities, monitoring, preparedness and stakeholder communication. | Maintain accurate records, reliable information exchanges, compliance with applicable obligations, and readiness to respond to emerging events. |
| Heightened stress or member institution failure | Urgent demand for verified information, protection or resolution decisions, coordinated action, and potentially large-scale stakeholder communication. | Maintain critical capabilities under increased workload, compressed decision timeframes, heightened public scrutiny, and disruption affecting multiple institutions simultaneously. |

A service that can tolerate a short interruption during routine operations may require substantially greater availability during an institutional distress event.

PIDM should therefore avoid assuming that normal workload, normal staffing or routine recovery priorities adequately represent its most demanding operating conditions.

##### **Stakeholders**

Consider the following stakeholder groups when identifying potential harm and determining resilience priorities.

 

| Stakeholder | Principal interest | Potential consequence of disruption |
| --- | --- | --- |
| Eligible depositors | Accurate protection information and timely reimbursement when applicable. | Uncertainty, delayed access to protected funds, and financial hardship. |
| Eligible takaful and insurance beneficiaries | Accurate protection information and fulfilment of applicable protected benefits. | Delayed benefits, uncertainty, and possible financial hardship. |
| Member banks and insurer members | Clear obligations, accurate information exchange, and effective coordination. | Administrative uncertainty, processing delays, and difficulty fulfilling protection-related responsibilities. |
| Bank Negara Malaysia and relevant authorities | Timely coordination and reliable information within their respective mandates. | Delayed decisions, incomplete situational awareness, or ineffective coordination. |
| Financial system participants | Orderly protection and resolution arrangements. | Reduced confidence or disruption propagation in a significant institutional event. |
| PIDM's Board and senior management | Effective delivery of statutory responsibilities and informed risk decisions. | Inadequate oversight, delayed response, and failure to achieve critical organisational outcomes. |
| PIDM employees and critical service providers | Clear responsibilities, dependable resources, and workable continuity arrangements. | Inability to perform essential activities or support recovery. |

Stakeholder analysis should distinguish direct service recipients from parties that support delivery or may experience secondary consequences.

##### **Proposed organisational assumptions**

The following assumptions are suitable for initiating the case study but require PIDM confirmation.

 

| Assumption | Implementation implication | Validation required |
| --- | --- | --- |
| Essential protection and resolution activities depend on accurate information received from member institutions. | Information integrity, secure exchange, and validation should receive significant attention. | Confirm actual information sources, submission arrangements, and ownership. |
| Several CBS share specialist personnel, technology, and external communication capabilities. | Mapping should identify common-cause failures and competing recovery priorities. | Validate the enterprise dependency map. |
| Some services become more time-critical during institutional distress. | Impact Tolerances may need to account for changing operating conditions. | Confirm event-driven obligations and harm thresholds. |
| Cyber or ICT disruption could affect authoritative information and recovery arrangements at the same time. | Testing should address integrity and clean recovery as well as availability. | Review actual architecture, access controls, and backup arrangements. |
| External coordination is necessary for some protection and resolution activities. | Scenario testing should challenge external information exchange and decision-making. | Confirm relevant authorities, member institutions, providers, and communication protocols. |

Record these assumptions in a controlled register with named owners and target validation dates.

 

#### **[![New call-to-action](https://no-cache.hubspot.com/cta/default/3893111/c7280eb9-276d-4026-b846-5d0bbf497159.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/c7280eb9-276d-4026-b846-5d0bbf497159)**

#### **PIDM's Operating Environment in Malaysia**

PIDM operates within a financial ecosystem shaped by statutory protection responsibilities, interconnected financial institutions, technology dependence, evolving cyber threats and expectations concerning the continuity of essential financial services.

Understanding this environment is necessary because a disruption originating outside PIDM may affect its ability to deliver a critical outcome.

##### **Regulatory and Statutory Environment**

PIDM's own governing legislation and applicable statutory instruments should form the starting point for identifying its obligations.

Bank Negara Malaysia is an important institution within Malaysia's financial regulatory framework and a relevant coordination stakeholder for PIDM.

However, PIDM should not automatically be classified as a BNM-regulated commercial financial institution or assumed to be subject to every BNM policy applicable to banks, insurers, or payment operators.

BNM's Operational Resilience Discussion Paper, issued on 19 December 2025, describes an emerging direction for strengthening the continuity of critical financial services.

Its stated population covers specified banking institutions, insurers, takaful operators, prescribed development financial institutions, designated payment system operators and eligible electronic money issuers; PIDM is not expressly included in that definition.

The paper should therefore be treated here as a Malaysian methodological reference, not proof of a directly binding obligation on PIDM.

For implementation, PIDM should maintain a regulatory applicability register that distinguishes its own statutory duties, applicable regulatory requirements, relevant supervisory or coordination expectations, and voluntarily adopted good practices.

##### **External Operating Pressures**

BNM's Discussion Paper identifies technology failures, cyber incidents, third-party outages, compromised information and power failures as sources of disruption.

It also highlights risks arising from shared telecommunications, cloud infrastructure, concentrated providers and physical events.

These themes provide a useful basis for PIDM's initial environmental assessment.

 

| Environmental factor | Illustrative exposure for PIDM | Initial resilience consideration |
| --- | --- | --- |
| Cyber threats | Ransomware, unauthorised access or corruption of protection-related information. | Protect authoritative records, detect compromise and verify recovered data. |
| Technology dependence | Failure of applications, databases, identity services or infrastructure supporting multiple CBS. | Identify common technology dependencies and test service-level recovery. |
| Member institution interconnections | Delayed, inaccurate or unavailable information from affected institutions. | Establish validated information requirements and secure alternatives. |
| Third-party concentration | Several services relying on one provider, facility or communications capability. | Assess substitutability and common failure domains. |
| Physical and environmental disruption | Loss of premises, utilities or access to critical personnel. | Test alternative working arrangements and crisis coordination. |
| Financial-sector stress | Simultaneous demand for protection information, reimbursement readiness and resolution coordination. | Establish priorities for scarce resources and heightened-stress operating arrangements. |
| Information integrity | Incorrect records or classifications influencing protection-related decisions. | Apply independent validation, reconciliation and controlled publication. |

PIDM must establish the presence and severity of each exposure through actual risk assessments and dependency mapping.

##### **Regulatory lessons for the case study**

BNM's Discussion Paper identifies five foundational operational resilience themes: continuity of critical services, mapping internal and external dependencies, managing third-party dependencies, disruption tolerances, and assessment under severe but plausible scenarios. It also discusses leadership, oversight and continuous improvement.

For this case study, those themes can be translated into a practical sequence:

##### Identify critical outcomes → Understand delivery dependencies → Define unacceptable harm → Test severe disruptions → Address weaknesses

This sequence is an implementation recommendation for PIDM, not a regulatory instruction directly imposed on PIDM by the Discussion Paper.

 

#### **[![New call-to-action](https://no-cache.hubspot.com/cta/default/3893111/cce97ee9-af23-4c1c-a7e7-1270d2d7da56.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/cce97ee9-af23-4c1c-a7e7-1270d2d7da56)**

#### **Composition of an Operational Resilience Team for PIDM**

Operational Resilience requires an enterprise-wide approach because critical services are delivered through multiple business functions and shared resources.

PIDM should establish an implementation team with clear accountability, decision-making authority and access to relevant expertise.

The structure below is proposed for the case study. Align it with PIDM's actual organisational structure and governance arrangements before adoption.

##### **Proposed Governance Structure**

**![\[OR\] \[PM\] Proposed Governance Structure](https://blog.bcm-institute.org/hs-fs/hubfs/%5BOR%5D%20%5BPM%5D%20Diagram/%5BOR%5D%20%5BPM%5D%20Proposed%20Governance%20Structure.png?width=788&height=551&name=%5BOR%5D%20%5BPM%5D%20Proposed%20Governance%20Structure.png)**

##### **Proposed Roles and Responsibilities**

 

| Role | Key responsibilities |
| --- | --- |
| Board or relevant Board committee | Oversee material resilience exposures, challenge management's assessments and review significant unresolved weaknesses. |
| Senior management | Sponsor the programme, approve resources, establish accountability and make decisions within delegated authority. |
| OR Steering Committee | Resolve cross-functional issues, review implementation progress and coordinate enterprise priorities. |
| OR programme lead | Establish methodology, templates, quality criteria, schedules and consolidated reporting. |
| CBS owners | Define service boundaries, validate dependencies, propose Impact Tolerances and assess end-to-end resilience. |
| Business process owners | Document detailed processes, operational resources, alternative arrangements and disruption consequences. |
| BCM and crisis management specialists | Integrate continuity, incident escalation, crisis coordination and recovery arrangements. |
| Operational risk specialists | Assess vulnerabilities, challenge assumptions and support risk treatment. |
| Technology and ICT Risk specialists | Validate infrastructure, application dependencies, architecture and technical recovery capabilities. |
| Cybersecurity specialists | Assess cyber threats, monitoring, incident containment, information compromise and clean recovery. |
| Legal and compliance specialists | Identify applicable obligations, decision authorities and legal consequences of disruption. |
| Third-party relationship owners | Validate external dependencies, provider capabilities and contractual or alternative arrangements. |
| Internal Audit | Provide independent assurance under its approved mandate without assuming management's implementation responsibilities. |

##### **Working Principles**

The team should operate according to four principles.

Service accountability: Each CBS must have a clearly identified owner accountable for the overall service assessment, even when other functions control critical resources.

Cross-functional participation: Business, technology, cyber, risk, and external dependency specialists must collaborate. No single function can establish end-to-end resilience independently.

Evidence-based assessment: Conclusions should be supported by validated records, tests, approvals and documented assumptions.

Management escalation: Escalate material tolerance breaches, unresolved concentration risks, and significant resource conflicts through established governance channels.

 

[![New call-to-action](https://no-cache.hubspot.com/cta/default/3893111/166119c4-828b-4bdc-89ed-fb335170f89c.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/166119c4-828b-4bdc-89ed-fb335170f89c)

#### **Critical Business Services: Key Considerations for Operational Resilience**

A Critical Business Service is an end-to-end service whose disruption could cause unacceptable harm to relevant stakeholders, the organisation or the wider financial system.

Identifying a CBS requires focusing on service outcomes rather than organisational departments, applications, or individual business functions.

For PIDM, the initial catalogue should reflect its protection, reimbursement, resolution, financial resource and stakeholder coordination responsibilities.

##### **Proposed Critical Business Service Catalogue**

The following ten services are proposed for the case study and should be validated by PIDM before formal adoption.

 

| Code | Critical Business Service | Principal resilience consideration |
| --- | --- | --- |
| CBS-1 | Deposit Insurance Protection Administration | Accuracy and continuity of deposit insurance administration, coverage information and related obligations. |
| CBS-2 | Insured Deposit Reimbursement | Ability to execute eligible depositor reimbursement accurately and within applicable requirements following a triggering event. |
| CBS-3 | Takaful and Insurance Benefits Protection Administration | Accurate administration of protection arrangements and information concerning eligible takaful and insurance benefits. |
| CBS-4 | Protected Takaful and Insurance Benefits Fulfilment | Ability to fulfil protected benefits accurately and in a timely manner when required. |
| CBS-5 | Member Institution Resolution Execution | Continuity of essential decision-making, coordination and execution capabilities during resolution activities. |
| CBS-6 | Member Institution Failure Preparedness and Resolution Readiness | Availability of plans, information, personnel and resources needed for effective failure preparedness. |
| CBS-7 | Member Institution Membership and Protection Obligations Administration | Accuracy of membership status, records and protection-related administrative obligations. |
| CBS-8 | Financial Resources Availability for Protection and Resolution | Availability of financial resources required to support protection and resolution responsibilities. |
| CBS-9 | Critical Depositor, Policy Owner and Public Communication | Delivery of timely, accurate and authoritative information during disruption or institutional distress. |
| CBS-10 | Critical Member Institution Information and Coordination | Reliable information exchange and coordination with member institutions and relevant external stakeholders. |

This catalogue is a starting point for analysis. It is not represented as PIDM's officially approved internal CBS register.

CBS-1 and CBS-7 may overlap in membership administration, while CBS-9 and CBS-10 may share communication capabilities. Clarify their boundaries and primary process ownership during validation.

##### **Criteria for identifying and validating a CBS**

PIDM should evaluate each candidate service against the following considerations:

- **Stakeholder harm:** Could disruption adversely affect depositors, policy owners, beneficiaries or member institutions?
- **Financial-system consequences:** Could failure impair confidence, protection arrangements or orderly institutional resolution?
- **Statutory obligations:** Could disruption prevent PIDM from meeting applicable legal duties or deadlines?
- **Time criticality:** How quickly could disruption become unacceptable under normal and heightened-stress conditions?
- **Information integrity:** Could incorrect data cause harmful protection, reimbursement or resolution decisions?
- **Interconnectedness:** Could failure propagate to other critical services or external institutions?
- **Substitutability:** Are viable alternative processes, resources and service channels available?

Criticality should be determined by potential harm, not simply by transaction volume, staffing levels or technology expenditure.

An event-driven service such as reimbursement may have limited routine activity but become exceptionally important when a member institution fails.

##### **Initial Dependency Considerations**

Assess the ten services collectively because they may depend on common information, technology, specialist personnel, communications channels, and external organisations.

For example, membership and coverage information may support reimbursement preparation, while financial resources and member institution coordination may be essential during resolution execution.

These are proposed relationships for investigation, not verified descriptions of PIDM's internal architecture.

The next implementation stages should confirm the actual relationships and identify shared dependencies that could cause multiple services to fail simultaneously.

 

#### **[![New call-to-action](https://no-cache.hubspot.com/cta/default/3893111/e12b7140-d40d-4b7f-a231-17b3e65f28ef.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/e12b7140-d40d-4b7f-a231-17b3e65f28ef)**

#### **Key Characteristics of PIDM**

Understanding PIDM's organisational characteristics helps determine how to design its Operational Resilience programme.

The following characteristics are relevant to the case study.

##### **Table 1.1: Organisational Characteristics and Resilience Implications**

 

| Characteristic | Relevance to PIDM | Operational Resilience implication |
| --- | --- | --- |
| Statutory protection mandate | Protection and resolution activities are linked to public-interest responsibilities. | Resilience priorities should reflect statutory outcomes and stakeholder harm, not commercial service targets alone. |
| Event-driven critical activities | Reimbursement and resolution responsibilities may become urgent following member institution failure. | Impact Tolerances and testing should consider heightened-stress conditions, not only routine operations. |
| Information-intensive operations | Accurate membership, coverage, deposit and benefits information may be essential to decisions. | Data integrity, validation, secure exchange and reconciliation require particular attention. |
| Financial-system interconnections | Effective delivery may depend on member institutions, authorities and external service providers. | Dependency mapping should extend beyond PIDM's organisational boundaries. |
| Specialist decision-making | Critical decisions may require legal, protection, resolution, and financial expertise. | Assess deputisation, knowledge retention, and decision authority. |
| Public confidence considerations | Disruption may generate uncertainty among protected stakeholders. | Maintain authoritative communication and consistent information during crisis conditions. |
| Shared enterprise resources | Multiple CBS may rely on common technology, facilities and personnel. | Identify concentration risks and competing recovery priorities. |
| Sensitive information | Protection and institutional information may require confidentiality, accuracy and controlled access. | Integrate cybersecurity, access governance, and trusted recovery into resilience planning. |

##### **Implications for programme design**

These characteristics indicate that PIDM's programme should address three interconnected dimensions.

Operational continuity: Maintain the people, processes and alternative arrangements needed to deliver essential outcomes.

Information trustworthiness: Ensure that authoritative information remains accurate, complete, protected and recoverable.

Enterprise coordination: Enable rapid decisions and effective collaboration across CBS owners, support functions and external stakeholders.

A programme focused solely on restoring technology would not adequately address these dimensions.

 

#### **[![New call-to-action](https://no-cache.hubspot.com/cta/default/3893111/02078ee0-af93-4873-9644-67d0094f384f.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/02078ee0-af93-4873-9644-67d0094f384f)**

#### **Establishing Organisational Goals for PIDM's Operational Resilience**

Organisational goals should define what PIDM intends to achieve through its Operational Resilience programme.

They should align with the organisation's mandate and translate into measurable objectives, assigned responsibilities, and documented evidence.

##### **Proposed Overarching Goal**

To strengthen PIDM's ability to continue delivering its Critical Business Services during severe but plausible disruption, within approved limits of acceptable harm, while maintaining the integrity of protection-related information and supporting effective financial protection and resolution outcomes.

This is a proposed programme goal for the case study and requires management validation.

##### **Proposed Goals and Objectives**

 

| Goal | Supporting objective | Illustrative measure of achievement |
| --- | --- | --- |
| 1. Establish service visibility | Identify and approve the enterprise CBS catalogue and accountable owners. | Approved CBS register with documented service boundaries and ownership. |
| 2. Understand end-to-end delivery | Document detailed processes and material internal and external dependencies. | Validated process catalogues and dependency maps for all approved CBS. |
| 3. Define acceptable disruption | Establish service-level Impact Tolerances based on unacceptable harm. | Approved tolerance statements supported by documented harm assessments. |
| 4. Strengthen operational and technology resilience | Identify vulnerabilities affecting people, processes, data, technology, facilities and third parties. | Risk assessments, control improvements and documented alternative arrangements. |
| 5. Demonstrate resilience capability | Conduct severe but plausible scenario testing against approved tolerances. | Test results showing actual service performance and clearly identified gaps. |
| 6. Improve crisis coordination | Establish effective escalation, decision-making and communication arrangements. | Exercised crisis procedures, decision logs and communication test results. |
| 7. Strengthen management oversight | Provide management with clear information on resilience capability and material weaknesses. | Periodic reporting, documented decisions and remediation tracking. |
| 8. Sustain continuous improvement | Incorporate lessons from incidents, near misses, tests and organisational changes. | Updated assessments, completed remediation and successful retesting. |

##### **Goal-setting Principles**

PIDM should ensure each goal links to an identifiable service outcome, is assigned to an accountable owner, and is supported by evidence.

Measures should distinguish activities from results. Completing a dependency map is an implementation milestone; demonstrating that the mapped dependencies can withstand disruption is a resilience outcome.

Similarly, conducting an exercise does not prove resilience unless the test establishes whether the CBS remained within its approved Impact Tolerance.

#### **Initial Operational Resilience Risk Understanding**

Before undertaking detailed risk assessments, PIDM should establish a preliminary view of the disruption threats that could affect its Critical Business Services.

This initial assessment should guide further investigation rather than be treated as a verified enterprise risk register.

##### **Table 1.2: Preliminary Operational Resilience Risk Register**

 

| Risk category | Illustrative disruption | Potential consequence | Initial assessment action |
| --- | --- | --- | --- |
| Cybersecurity | Ransomware compromises administrative records and recovery environments. | Unavailable or untrustworthy protection information. | Assess cyber dependencies, privileged access, backup protection and clean recovery. |
| ICT infrastructure | Shared infrastructure or identity services become unavailable. | Simultaneous disruption across multiple CBS. | Identify common failure domains and test recovery arrangements. |
| Data integrity | Incorrect member institution or protection information propagates between processes. | Erroneous decisions, delayed fulfilment and stakeholder harm. | Establish data ownership, validation and reconciliation controls. |
| External dependency | A member institution or critical provider cannot supply essential information or services. | Delayed administration, reimbursement or resolution readiness. | Map external dependencies and validate alternatives. |
| People and expertise | Critical specialists are unavailable during an urgent event. | Delayed decisions and inadequate processing capability. | Assess succession, deputisation and knowledge transfer. |
| Facilities and utilities | Primary premises or supporting infrastructure become inaccessible. | Loss of coordination and operational capacity. | Assess alternative facilities and remote working arrangements. |
| Crisis management | Escalation is delayed or responsibilities are unclear. | Prolonged disruption and inconsistent decisions. | Review activation criteria, delegated authority and crisis exercises. |
| Cross-CBS concentration | Multiple services depend on the same technology, team or external party. | Cascading failure and competing recovery priorities. | Consolidate dependency maps and assess enterprise concentration. |
| Stakeholder communication | Authoritative channels fail during a protection event. | Misinformation, uncertainty and potential confidence effects. | Assess communication capacity, alternative channels and message approval. |

Each risk should then be assessed for its relevance, existing controls, potential harm, ownership, and treatment requirements.

Cyber and ICT risks should not be confined to a separate technical assessment. Trace their consequences through the processes and dependencies that deliver each CBS.

#### **Case Study Implementation Roadmap**

The findings from this introductory chapter provide the foundation for a structured implementation journey.

 

| Implementation activity | Purpose | Principal deliverable |
| --- | --- | --- |
| Understand PIDM | Establish organisational context, mandate, stakeholders and operating environment. | Organisational profile and validated assumptions. |
| Establish direction | Define resilience goals, governance, accountability and programme scope. | Approved objectives and implementation arrangements. |
| Identify CBS | Determine which end-to-end services require resilience protection. | Approved CBS catalogue. |
| Outline detailed processes | Identify the constituent processes supporting each CBS. | Sub-CBS process catalogues. |
| Map dependencies | Establish how people, processes, data, technology, facilities and external parties support delivery. | Dependency maps and concentration risk assessment. |
| Set Impact Tolerances | Define the maximum disruption permitted before unacceptable harm occurs. | Approved tolerance statements. |
| Identify scenarios | Develop severe but plausible disruptions that challenge the service. | Scenario catalogue. |
| Perform testing | Assess actual capability against the tolerance and identify weaknesses. | Test reports, lessons and remediation plans. |
| Sustain improvement | Maintain assessments and address changes, incidents and identified weaknesses. | Updated programme records and management reporting. |

This roadmap connects the organisational understanding developed in eBook 1 with the methodology and implementation activities addressed in the subsequent eBooks.

 

### **[![Banner \[Summing\] \[OR\] \[E1\] \[C1\] Introducing OR Case Study](https://no-cache.hubspot.com/cta/default/3893111/d2e2c339-9a7d-496d-924a-d75107cf7afe.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/d2e2c339-9a7d-496d-924a-d75107cf7afe)**

This chapter has established the foundation for PIDM's Operational Resilience case study by examining its organisational context, operating environment, stakeholders, proposed governance structure, Critical Business Services, defining characteristics and preliminary risks.

The assessment highlights the importance of treating Operational Resilience as an enterprise-wide capability focused on critical service outcomes.

PIDM must consider not only whether its internal systems and departments can recover, but also whether its protection, reimbursement, resolution and coordination responsibilities can continue during severe disruption without unacceptable harm.

The proposed ten-service catalogue provides an initial framework for identifying the services that require resilience protection. Its boundaries, ownership and criticality must be validated before formal adoption.

The chapter also establishes preliminary organisational goals and a proposed implementation team to support accountability, cross-functional collaboration and evidence-based assessment.

BNM's December 2025 Discussion Paper provides relevant methodological considerations for Malaysia's financial sector, particularly concerning critical service continuity, dependency mapping, disruption tolerances, severe but plausible testing and management oversight.

These considerations should be applied to PIDM with due regard to the document's discussion-paper status and the actual regulatory requirements applicable to the organisation.

The next chapter will examine PIDM's organisational mandate, principal functions, and stakeholder relationships in greater detail.

This will provide the organisational understanding required to validate the proposed Critical Business Services and develop an implementation programme that reflects PIDM's actual operating environment.

 

[![BL-OR-3-5 Blog Under Construction](https://no-cache.hubspot.com/cta/default/3893111/3aefb2d2-3110-47c1-ad4f-d3e6e5381066.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/3aefb2d2-3110-47c1-ad4f-d3e6e5381066)

Blogs marked \[x\] are under construction

[![New call-to-action](https://no-cache.hubspot.com/cta/default/3893111/56090723-e91a-4dcf-bae2-9a0dfc3808b0.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/56090723-e91a-4dcf-bae2-9a0dfc3808b0)

| ##### Understanding Your Organisation |  |  |  |  |  |  |
| --- | --- | --- | --- | --- | --- | --- |
| **C1** | **C2 \[x\]** | **C3 \[x\]** | **C4 \[x\]** | **C5** |   |   |
| [![\[OR\] \[PIDM\] \[E1\] \[C1\] Introducing OR Case Study](https://no-cache.hubspot.com/cta/default/3893111/e3c0c51a-9a45-4f10-bc1c-0d55c1312940.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/e3c0c51a-9a45-4f10-bc1c-0d55c1312940) | [![\[OR\] \[GEN\] \[E1\] \[C2\] Understanding Your Organisation](https://no-cache.hubspot.com/cta/default/3893111/ced1bdb4-c85e-4ebe-8878-082aea79ef6a.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/ced1bdb4-c85e-4ebe-8878-082aea79ef6a) | [![\[OR\] \[GEN\] \[E1\] \[C3\] Examining Operating Environment](https://no-cache.hubspot.com/cta/default/3893111/cc870a30-329c-416c-bda9-ffd799be3d62.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/cc870a30-329c-416c-bda9-ffd799be3d62) | [![\[OR\] \[GEN\] \[E1\] \[C4\] Composing the OR Team](https://no-cache.hubspot.com/cta/default/3893111/695d257f-c746-48a6-a463-26b3b6a8a7d1.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/695d257f-c746-48a6-a463-26b3b6a8a7d1) | [![New call-to-action](https://no-cache.hubspot.com/cta/default/3893111/e1edad86-0c49-4fd4-8885-0d7c7e6e0eb2.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/e1edad86-0c49-4fd4-8885-0d7c7e6e0eb2) |   |   |
| **C6 \[x\]** | **C7 \[x\]** | **C8 \[x\]** | **C9 \[x\]** | **eBook Cover** |   |   |
| [![\[OR\] \[GEN\] \[E1\] \[C6\] Analysing Key Characteristics](https://no-cache.hubspot.com/cta/default/3893111/312be1e5-fa5e-40cd-ae3b-55f729092d4a.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/312be1e5-fa5e-40cd-ae3b-55f729092d4a) | [![\[OR\] \[GEN\] \[E1\] \[C7\] Establishing Organisational Goals for Operational Resilience](https://no-cache.hubspot.com/cta/default/3893111/36ee9cb1-b726-4615-ad89-cfdebc4ecbf4.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/36ee9cb1-b726-4615-ad89-cfdebc4ecbf4) | [![\[OR\] \[GEN\] \[E1\] \[C8\] Summary](https://no-cache.hubspot.com/cta/default/3893111/24dde137-e587-4125-ac61-a0b0577d1f61.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/24dde137-e587-4125-ac61-a0b0577d1f61) | [![\[OR\] \[GEN\] \[E1\] \[C9\] \[Back Cover\] OR](https://no-cache.hubspot.com/cta/default/3893111/e234eb57-ece8-484b-8ab0-96f336d8396d.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/e234eb57-ece8-484b-8ab0-96f336d8396d) | [![eBook Cover \[OR\] \[PIDM\] \[E1\] \[2D\] ](https://no-cache.hubspot.com/cta/default/3893111/6dd47adf-d0be-42c1-9f8c-27b4a9421256.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/6dd47adf-d0be-42c1-9f8c-27b4a9421256) |   |   |
|   |   |   |  |  |  |  |

[![New call-to-action](https://no-cache.hubspot.com/cta/default/3893111/084e620a-46c5-419a-82ed-6a681d15c0b6.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/084e620a-46c5-419a-82ed-6a681d15c0b6)[![New call-to-action](https://no-cache.hubspot.com/cta/default/3893111/309c3a80-4c3c-4eb9-811d-bd401ccb1610.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/309c3a80-4c3c-4eb9-811d-bd401ccb1610)Gain Competency: For organisations looking to accelerate their journey, BCM Institute’s training and certification programs, including the OR-5000 Operational Resilience Expert Implementer course, offer in-depth insights and practical toolkits to embed this model effectively.

#### More Information About OR-5000 \[OR-5\] or OR-300 \[OR-3\]

To learn more about the course and schedule, click the buttons below for the OR-300 Operational Resilience Implementer course and the OR-5000 Operational Resilience Expert Implementer course.

| [![BL-OR-3 Register Now](https://no-cache.hubspot.com/cta/default/3893111/3530eccb-515d-401e-afc2-3469e26d7fbf.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/3530eccb-515d-401e-afc2-3469e26d7fbf) | [![BL-OR-3\_Tell Me More](https://no-cache.hubspot.com/cta/default/3893111/fdd4fa9c-ed69-40c1-925f-4eb6a1c5c255.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/fdd4fa9c-ed69-40c1-925f-4eb6a1c5c255) | [![BL-OR-3\_View Schedule](https://no-cache.hubspot.com/cta/default/3893111/77a34b84-0a6d-44f8-b8d6-6ab04cdf5edd.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/77a34b84-0a6d-44f8-b8d6-6ab04cdf5edd) |
| --- | --- | --- |
| [![BL-OR-5\_Register Now](https://no-cache.hubspot.com/cta/default/3893111/6e5c0cda-39b9-4bbd-b3d4-4cf46a790b14.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/6e5c0cda-39b9-4bbd-b3d4-4cf46a790b14) | [![BL-OR-5\_Tell Me More](https://no-cache.hubspot.com/cta/default/3893111/a68a08aa-36d3-4216-9551-202c9fde06ea.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/a68a08aa-36d3-4216-9551-202c9fde06ea) | [![ \[BL-OR\] \[3-4-5\] View Schedule](https://no-cache.hubspot.com/cta/default/3893111/d0d733a1-16c0-4b68-a26d-adbfd4fc6069.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/d0d733a1-16c0-4b68-a26d-adbfd4fc6069) |
| [![\[BL-OR\] \[3\] FAQ OR-300](https://no-cache.hubspot.com/cta/default/3893111/f20c71b4-f5e8-4aa5-8056-c374ca33a091.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/f20c71b4-f5e8-4aa5-8056-c374ca33a091) | If you have any questions, click to contact us.[![Email to Sales Team \[BCM Institute\]](https://no-cache.hubspot.com/cta/default/3893111/3c53daeb-2836-4843-b0e0-645baee2ab9e.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/3c53daeb-2836-4843-b0e0-645baee2ab9e) | [![FAQ BL-OR-5 OR-5000](https://no-cache.hubspot.com/cta/default/3893111/7f2718a4-ea80-4f84-a319-dc2d4df37a46.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/7f2718a4-ea80-4f84-a319-dc2d4df37a46) |
| [![OR Implementer Landing Page](https://no-cache.hubspot.com/cta/default/3893111/74b1e556-8cd2-4a74-8821-db1804534955.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/74b1e556-8cd2-4a74-8821-db1804534955) | [![New call-to-action](https://no-cache.hubspot.com/cta/default/3893111/f2bd8eb1-32d2-4732-9267-ea53223cf58f.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/f2bd8eb1-32d2-4732-9267-ea53223cf58f) | [![New call-to-action](https://no-cache.hubspot.com/cta/default/3893111/084e620a-46c5-419a-82ed-6a681d15c0b6.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/084e620a-46c5-419a-82ed-6a681d15c0b6) |

 

#### **Comments**

 

![CTA Banner\_OR](https://blog.bcm-institute.org/hubfs/CTA%20Banner%20for%20Blog/CTA%20Banner_OR.jpg "CTA Banner_OR")

---

![CTA Banner\_ORA](https://blog.bcm-institute.org/hubfs/CTA%20Banner%20for%20Blog/CTA%20Banner_ORA.jpg "CTA Banner_ORA")

---

![CTA Banner\_BCM](https://blog.bcm-institute.org/hubfs/CTA%20Banner%20for%20Blog/CTA%20Banner_BCM.jpg "CTA Banner_BCM")

---

![CTA Banner\_ITDR](https://blog.bcm-institute.org/hubfs/CTA%20Banner%20for%20Blog/CTA%20Banner_ITDR.jpg "CTA Banner_ITDR")

---

![CTA Banner\_CM](https://blog.bcm-institute.org/hubfs/CTA%20Banner%20for%20Blog/CTA%20Banner_CM.jpg "CTA Banner_CM")

![BCMIWhiteLogoSmall.png](https://blog.bcm-institute.org/hs-fs/hubfs/Blog%20Testing/BCMIWhiteLogoSmall.png?width=72&name=BCMIWhiteLogoSmall.png "BCMIWhiteLogoSmall.png")

All rights reserved. Copyright 2026

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Moh Heng Goh",
    "url" : "https://blog.bcm-institute.org/ebook-or/author/moh-heng-goh"
  },
  "dateModified" : "2026-09-23T11:12:29.766Z",
  "datePublished" : "2026-09-23T07:42:56.000Z",
  "headline" : "[OR] [PIDM] [E1] [C1] Introducing OR Case Study",
  "mainEntityOfPage" : {
    "@id" : "https://blog.bcm-institute.org/ebook-or/or-pidm-e1-c1-introducing-or-case-study",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://blog.bcm-institute.org/hubfs/BCMI%20Logo.png"
    },
    "name" : "BCMI Pte Ltd"
  }
}
```