CBS-1 Deposit Insurance Protection Administration
Introduction
![[OR] [PIDM] [E3] [CBS] [1] [ITo] Deposit Insurance Protection Administration](https://no-cache.hubspot.com/cta/default/3893111/33e29914-7a30-4f21-8b0d-dd3cba3c255a.png)
Setting an Impact Tolerance for CBS-1: Deposit Insurance Protection Administration establishes the maximum disruption level that Perbadanan Insurans Deposit Malaysia (PIDM) can tolerate before the interruption causes unacceptable harm to depositors, member banks, the organisation, or Malaysia's financial system.
The assessment must be based on the consequences of disruption rather than the recovery capabilities of individual business processes or technology systems.
For PIDM, the principal concern is whether deposit insurance protection can continue to be administered accurately, consistently, and reliably, particularly when financial stress or a member bank failure increases the importance of dependable protection information.
The assessment must therefore examine the complete service delivery chain.
This includes membership administration, coverage determination, deposit information management, premium assessment, compliance monitoring, protection communication, exception handling, and service restoration.
A failure affecting one Sub-Critical Business Service (Sub-CBS) may propagate through several downstream processes. For example, corruption of deposit information could prevent validation of total insured deposits, delay premium assessment, and compromise information needed for reimbursement preparedness.
This analysis must integrate cybersecurity and information and communications technology (ICT) risks. Ransomware, unauthorised access, database corruption, network failures, cloud outages, and technology concentration risks can simultaneously affect several processes and prevent PIDM from delivering CBS-1 within acceptable limits.
This chapter assesses the potential harm associated with each of the 18 identified Sub-CBS processes, examines relevant cyber and ICT risk exposures, proposes proactive risk management measures, and establishes an illustrative service-level Impact Tolerance for management consideration.
Catalogue clarification: The quality-control instructions refer to 20 Sub-CBS processes, but the supplied catalogue contains 18, numbered CBS-1.1 through CBS-1.18. This assessment covers all 18 supplied processes without inventing two additional processes.
Establishing the Impact Tolerance Assessment Framework
Definition of Impact Tolerance
Impact Tolerance is the maximum level of disruption to a Critical Business Service that an organisation can accept before the resulting harm becomes unacceptable.
Define it from the perspective of the service outcome and the stakeholders who depend on that outcome.
For PIDM, this means determining how much disruption to deposit insurance administration can be accepted before it materially compromises protection accuracy, statutory responsibilities, member bank obligations, or depositor confidence.
The assessment should consider both the duration and the severity of disruption.
A prolonged interruption to a routine administrative activity may be manageable outside a critical reporting period.
However, a short-lived incident that corrupts authoritative coverage records or produces materially incorrect protection information may cause unacceptable harm much earlier.
Impact Tolerance should therefore be multidimensional.
Distinguishing Impact Tolerance from Other Recovery Measures
|
Measure |
Purpose |
Relationship to Impact Tolerance |
|
Impact Tolerance |
Defines the maximum acceptable disruption to the end-to-end CBS before unacceptable harm occurs. |
Establishes the overarching service-level boundary. |
|
Recovery Time Objective (RTO) |
Defines the target time for restoring a process, system, or resource. |
Must be sufficiently demanding to support the CBS tolerance. |
|
Recovery Point Objective (RPO) |
Defines the maximum targeted period of data loss measured backwards from disruption. |
Supports the information integrity and recovery requirements of the CBS. |
|
Maximum Tolerable Period of Disruption (MTPD) |
Establishes the time beyond which disruption to an activity becomes unacceptable. |
May inform service-level analysis, but does not replace an end-to-end, multidimensional tolerance. |
|
System availability target |
Measures the expected availability of a technology component. |
Provides supporting performance evidence but does not establish whether the service outcome is achieved. |
|
Service Level Agreement (SLA) |
Defines agreed service performance commitments. |
Provides contractual or operational support but may not reflect the maximum harm threshold. |
A reimbursement-related information repository, for example, may be restored within its RTO while CBS-1 remains impaired because the recovered records are corrupted or inconsistent.
The service should not be considered restored until it can deliver the required administrative outcomes accurately and reliably.
Harm Assessment Dimensions
The assessment should consider the following dimensions.
|
Harm dimension |
Application to CBS-1 |
|
Depositor harm |
Incorrect coverage information, uncertainty about protection, or inability to obtain authoritative information. |
|
Member bank harm |
Delayed classifications, reporting difficulties, disputed premium assessments, or unresolved obligations. |
|
Statutory and regulatory harm |
Failure to meet applicable legal obligations or authorised administrative requirements. |
|
Financial harm |
Incorrect premium calculations, delayed collection, or unreliable financial records. |
|
Financial stability harm |
Protection uncertainty during financial stress or a member bank failure could contribute to wider confidence concerns. |
|
Information integrity harm |
Corrupted, incomplete, inaccurate, or unauthorised changes to authoritative records. |
|
Organisational harm |
Prolonged service disruption, significant remediation costs, loss of confidence, or impaired ability to fulfil statutory responsibilities. |
The significance of each dimension depends on the timing, scale, and circumstances of disruption.
Assess financial stability consequences particularly carefully during periods of member institution distress. A routine administrative outage should not automatically be assumed to cause systemic harm.
Proposed five-level harm classification
The classifications in Table 1 represent the potential severity of a credible prolonged or severe disruption, assuming relevant controls or alternative arrangements are insufficient.
They are not assessments of incident probability or assertions about PIDM's existing control effectiveness.
A Very High classification does not automatically mean that any interruption to the process breaches the CBS impact tolerance. The actual breach depends on the resulting end-to-end service harm and the approved tolerance conditions.
Table 1: Sub-CBS Impact Tolerance and Harm Assessment
The following table evaluates each of the 18 Sub-CBS processes against a credible severe or prolonged disruption.
The harm ratings are indicative assessments of potential consequences, not verified PIDM risk ratings.
They assume that existing controls or alternative arrangements are insufficient and that the disruption occurs during a relevant operating period.
The assessment considers both direct harm and cascading consequences for the overall CBS.
|
Sub-CBS Code |
Name of Sub-CBS |
Potential Disruption |
Potential Harm |
Level of Harm |
Key Harm Indicators |
|
CBS-1.1 |
Administer Member Bank Participation |
Membership records become unavailable or inaccurate following a system outage or unauthorised modification. |
Incorrect membership status could affect protection administration, member obligations and public information. During institutional distress, uncertainty may complicate protection-related decisions. |
High — authoritative membership status underpins several downstream processes. |
Duration of unavailable membership records; number of affected banks; incorrect status records; delayed membership updates; unresolved discrepancies. |
|
CBS-1.2 |
Maintain Deposit Insurance Coverage Framework |
Approved coverage rules become inaccessible, outdated, or incorrectly modified. |
Incorrect application of protection requirements could affect product classification, depositor information, and subsequent reimbursement determinations. |
Very High — material errors in authoritative coverage rules could propagate across multiple services. |
Number of incorrect rules; affected products; duration of inaccurate guidance; number of consequential decisions; material statutory inconsistencies. |
|
CBS-1.3 |
Assess Deposit Product Insurability |
Product assessments cannot be completed or classifications are incorrect. |
Member banks and depositors may receive delayed or inaccurate information about whether particular deposit products are protected. |
High — incorrect determinations may affect protection expectations and require extensive correction. |
Number of delayed assessments; affected products and banks, assessment backlog, incorrect classifications, and duration of unresolved determinations. |
|
CBS-1.4 |
Administer Deposit Product Coverage Records |
Coverage records are corrupted, deleted or unavailable. |
Approved classifications cannot be reliably retrieved, potentially causing inconsistent disclosures and protection decisions. |
Very High — loss of authoritative coverage integrity could affect multiple downstream processes. |
Number of corrupted records; proportion of unavailable classifications; duration of record unavailability; conflicting coverage information. |
|
CBS-1.5 |
Administer Member Bank Deposit Information Requirements |
Reporting specifications cannot be distributed or incorrect specifications are issued. |
Member banks may submit incompatible information, causing validation failures and delays in deposit insurance administration. |
Medium — normally manageable through clarification, but severity increases during critical submission periods. |
Number of affected banks, specification errors, submission delays, volume of rejected files, and missed applicable deadlines. |
|
CBS-1.6 |
Receive and Validate Deposit Insurance Information |
The information submission platform becomes unavailable or accepts corrupted submissions. |
PIDM may be unable to obtain reliable information for deposit insurance administration, premium assessment, and relevant preparedness activities. |
Very High — widespread data integrity failure could affect multiple critical processes. |
Number of failed submissions; affected banks; validation error rate; information latency; volume of unverified records; outage duration. |
|
CBS-1.7 |
Maintain Insured Deposit Information and Records |
Authoritative information is lost, encrypted, corrupted, or inaccessible. |
Administrative decisions may rely on unreliable records; premium assessments and reimbursement preparedness may be impaired. |
Very High — authoritative record loss or undetected corruption could create substantial downstream harm. |
Lost or corrupted records; data age; recovery duration; reconciliation discrepancies; affected banks; availability of verified backups. |
|
CBS-1.8 |
Validate Total Insured Deposits |
Validation processes fail or produce inaccurate insured deposit totals. |
Premium assessments may be incorrect, and relevant deposit insurance information may become unreliable. |
Highly inaccurate totals could materially affect premium administration and require corrective action. |
Value of discrepancies; number of affected banks; delayed validations; percentage of unverified totals; missed assessment deadlines. |
|
CBS-1.9 |
Assess Member Bank Premium Classification |
Classification information is unavailable or incorrectly calculated. |
Member banks may receive incorrect premium classifications, resulting in disputed assessments or retrospective adjustments. |
High errors affecting multiple banks could create material financial and compliance consequences. |
Incorrect classifications; affected banks; premium adjustment value; unresolved disputes; classification delay. |
|
CBS-1.10 |
Calculate and Assess Deposit Insurance Premiums |
The premium calculation platform fails or produces erroneous assessments. |
Premium obligations may be delayed or misstated, affecting collection, financial reporting, and member bank obligations. |
High material calculation errors could affect the integrity of the premium administration cycle. |
Incorrect assessments, delayed invoices, affected banks, assessment backlog, and reconciliation differences. |
|
CBS-1.11 |
Administer Premium Collection and Reconciliation |
Payment information is unavailable, or premium receipts cannot be reconciled. |
PIDM may be unable to establish whether premium obligations have been fulfilled, potentially affecting financial records and compliance monitoring. |
High material or prolonged reconciliation failures may create financial uncertainty and unresolved obligations. |
Unreconciled premium value; overdue payments; unmatched transactions; reconciliation backlog; duration of unavailable payment information. |
|
CBS-1.12 |
Monitor Member Bank Compliance with Deposit Insurance Requirements |
Compliance monitoring becomes unavailable or fails to detect material breaches. |
Reporting, premium, or disclosure non-compliance may remain unresolved, weakening the effectiveness of deposit insurance administration. |
High — prolonged failure could allow material obligations to remain unaddressed. |
Number of overdue compliance cases; material unresolved breaches; delayed corrective actions; affected banks; reporting delays. |
|
CBS-1.13 |
Administer Deposit Insurance Disclosure Requirements |
Incorrect disclosure requirements are distributed, or disclosure monitoring fails. |
Depositors may receive misleading protection information, particularly concerning product eligibility or coverage. |
Very High — widespread inaccurate disclosure during financial stress could create significant depositor harm and confidence concerns. |
Number of affected banks and products; duration of incorrect disclosures; estimated affected depositors; material complaints; correction time. |
|
CBS-1.14 |
Provide Deposit Insurance Protection Information |
PIDM's information channels become unavailable or publish inaccurate coverage information. |
Depositors may be unable to obtain authoritative information, potentially increasing uncertainty during financial stress. |
Very High — widespread unavailability or misinformation during a bank failure could have significant consequences. |
Duration of unavailable channels; number of affected enquiries; incorrect published statements; affected depositor population; time to correct. |
|
CBS-1.15 |
Manage Deposit Insurance Administrative Exceptions |
Exception management fails or critical cases remain unresolved. |
Coverage disputes, information errors and premium discrepancies may accumulate and affect downstream decisions. |
High — unresolved material exceptions could compromise service integrity. |
Number of unresolved critical cases; age of exceptions; affected banks; value of disputed assessments; overdue escalations. |
|
CBS-1.16 |
Monitor Deposit Insurance Service Performance |
Monitoring systems fail, or performance reports are incomplete. |
Service deterioration may remain undetected, allowing processing backlogs and control failures to develop into significant disruption. |
High — loss of monitoring could delay intervention across multiple processes. |
Monitoring outage duration; undetected incidents; backlog growth; missed escalation thresholds; unavailable performance indicators. |
|
CBS-1.17 |
Manage Deposit Insurance Service Disruptions |
Incident coordination fails because of unavailable personnel, communications or response arrangements. |
PIDM may be unable to prioritise essential activities, activate continuity measures or coordinate recovery effectively. |
Very High — ineffective response could allow a contained incident to develop into prolonged service-wide disruption. |
Incident detection-to-escalation time; response activation delay; affected processes; duration of unavailable essential services; missed tolerance thresholds. |
|
CBS-1.18 |
Restore and Reconcile Deposit Insurance Administration |
Recovery systems fail or restored records contain undetected discrepancies. |
CBS-1 may remain unavailable or operate using inaccurate information despite apparent technology restoration. |
Very High — incomplete recovery could prolong disruption and compromise the integrity of resumed operations. |
Recovery duration; reconciliation completion; outstanding transactions; data discrepancies; backlog clearance; verified restoration status. |
Interpretation of the Harm Assessment
The assessment identifies several processes whose disruption could create particularly significant consequences for CBS-1.
Coverage rules and records, deposit information validation, authoritative information repositories, disclosure, public information, disruption management and restoration have been assigned Very High potential harm classifications.
These processes can influence multiple downstream activities or determine whether PIDM can maintain the accuracy and reliability of deposit insurance administration.
However, the classifications should not be interpreted as an automatic recovery priority ranking.
For example, premium calculation may become exceptionally time-sensitive during a statutory assessment deadline, while public communication may become more important during member bank distress.
PIDM should therefore assess criticality against operating conditions, service dependencies and the time at which harm becomes unacceptable.
Table 2: Integrated Cyber and ICT Risk Assessment
Assess cyber and ICT risks as potential causes of disruption to the same Sub-CBS processes examined in Table 1.
They should not be treated as an independent technology exercise disconnected from service outcomes.
For each process, the assessment should establish how a cyber incident or ICT failure could affect its delivery, whether the resulting consequences could contribute to an impact tolerance breach, and which controls would provide demonstrable protection.
The controls below are proposed measures, not claims that PIDM has already implemented them. The evidence column specifies records that management should obtain and retain to demonstrate implementation and effectiveness.
|
Sub-CBS Code |
Name of Sub-CBS |
Cyber and ICT Risk Linkage |
Contribution to Impact Tolerance Breach |
Proactive Risk Management Action |
Evidence of Proactive Risk Management |
|
CBS-1.1 |
Administer Member Bank Participation |
Unauthorised changes to membership records; identity compromise; database failure; failed application changes. |
Incorrect membership status may propagate to premium, compliance and communication processes. Widespread undetected changes could contribute to a breach. |
Enforce role-based access, privileged access controls, dual authorisation for material changes, change monitoring and recoverable membership records. |
Approved access matrix; privileged access reviews; change logs; database recovery test; exception reports. |
|
CBS-1.2 |
Maintain Deposit Insurance Coverage Framework |
Unauthorised modification of coverage rules; compromised document repository; failed publication; ransomware. |
Corrupted rules could generate incorrect protection decisions across multiple processes, potentially breaching integrity conditions before a prolonged outage occurs. |
Maintain authoritative, version-controlled rules with dual approval, immutable historical copies, integrity verification, and controlled distribution. |
Approved rule versions; change approvals; repository audit logs; integrity checks; restoration test results. |
|
CBS-1.3 |
Assess Deposit Product Insurability |
Assessment application outage; compromised product submissions; phishing; unauthorised alteration of determinations. |
Incorrect or delayed classifications could affect multiple products and produce widespread inaccurate protection information. |
Authenticate submissions, verify source documents, segregate assessment and approval duties, maintain alternative assessment procedures and review abnormal changes. |
Submission validation records; approval logs; access reviews; alternative processing exercise; assessment quality reviews. |
|
CBS-1.4 |
Administer Deposit Product Coverage Records |
Database corruption; ransomware; unauthorised changes; backup failure; failed data migration. |
Loss of authoritative classifications could prevent reliable disclosure and coverage decisions, directly threatening the proposed integrity boundary. |
Implement access restrictions, database integrity checks, protected backups, controlled change management and independent restoration verification. |
Database audit trails; backup reports; restore test results; reconciliation records; approved change documentation. |
|
CBS-1.5 |
Administer Member Bank Deposit Information Requirements |
Communication platform outage; compromised specifications; unauthorised document changes; network failure. |
Incorrect specifications could generate widespread submission errors and prevent downstream processing during a critical reporting period. |
Maintain controlled specifications, authenticated distribution, change approval, alternate communication channels and member acknowledgement procedures. |
Approved specifications; distribution records; change logs; communication tests; acknowledgement records. |
|
CBS-1.6 |
Receive and Validate Deposit Insurance Information |
Ransomware; malicious files; API or secure transfer failures; denial-of-service attacks; validation engine malfunctions. |
Widespread submission interruption or undetected corrupted information could prevent accurate downstream administration and contribute directly to a breach. |
Secure transfer channels, malware scanning, input validation, segregated processing, capacity monitoring, alternative submission arrangements and data integrity controls. |
Vulnerability assessments; penetration test reports; malware monitoring; validation test results; failover exercises; alternate submission test records. |
|
CBS-1.7 |
Maintain Insured Deposit Information and Records |
Ransomware; privileged access compromise; database corruption; cloud outage; backup compromise; replication errors. |
Loss of authoritative records or restoration of corrupted information could prevent essential administration and undermine downstream protection activities. |
Protect privileged access, maintain immutable or isolated backups, monitor database integrity, test restoration, segregate recovery infrastructure and establish recovery-point controls. |
Privileged access reviews; backup integrity reports; disaster recovery tests; reconciliation evidence; cyber incident exercises; independent assurance findings. |
|
CBS-1.8 |
Validate Total Insured Deposits |
Calculation logic corruption; data feed interruption; application failure; unauthorised modification of validation rules. |
Incorrect insured deposit totals could produce material premium errors and compromise the reliability of administrative information. |
Apply independent calculation checks, controlled rule changes, source-to-output reconciliation, anomaly detection and alternative validation procedures. |
Calculation verification reports; reconciliation records; change approvals; exception logs; alternative processing test results. |
|
CBS-1.9 |
Assess Member Bank Premium Classification |
Compromised classification inputs; unauthorised rule changes; application failure; loss of specialist access. |
Incorrect classifications affecting multiple banks could generate material assessment errors and disputes. |
Implement controlled classification rules, dual approval, access monitoring, independent review and tested manual classification procedures. |
Classification approvals; access logs; rule validation results; quality assurance reports; manual processing exercise records. |
|
CBS-1.10 |
Calculate and Assess Deposit Insurance Premiums |
Calculation engine defect; failed technology change; database corruption; ransomware; performance degradation. |
Inaccurate or unavailable premium assessments during a critical cycle could exceed acceptable processing and financial integrity limits. |
Use independently verified calculation logic, pre-production testing, reconciliation, rollback capability, alternative calculation arrangements and capacity testing. |
Calculation test results; change approvals; rollback test reports; reconciliation records; capacity monitoring; business continuity exercises. |
|
CBS-1.11 |
Administer Premium Collection and Reconciliation |
Payment interface failure; fraudulent payment instruction; compromised bank information; reconciliation platform outage. |
Material unreconciled receipts or incorrect financial records could breach financial integrity conditions and delay confirmation of member obligations. |
Authenticate payment information, segregate payment duties, independently verify bank details, reconcile daily where applicable, and maintain alternative bank statement access. |
Payment control testing; reconciliation reports; bank confirmation records; fraud monitoring; alternative access tests; finance approvals. |
|
CBS-1.12 |
Monitor Member Bank Compliance with Deposit Insurance Requirements |
Monitoring platform failure; incomplete data feeds; unauthorised closure of compliance cases; compromised evidence. |
Material breaches may remain undetected or unresolved, potentially causing prolonged failure to meet applicable obligations. |
Maintain complete compliance data feeds, exception alerts, protected case histories, supervisory review and alternative compliance tracking. |
Monitoring reports; case audit trails; access reviews; compliance testing; escalation records; alternative tracking exercise. |
|
CBS-1.13 |
Administer Deposit Insurance Disclosure Requirements |
Compromised disclosure templates; unauthorised content changes; publication system failure; outdated replicated information. |
Incorrect disclosures affecting many depositors could breach the service's information integrity conditions, especially during financial stress. |
Establish authoritative content, legal approval, version control, publication monitoring, rapid correction procedures and member bank verification. |
Approved disclosure templates; publication logs; content integrity checks; member verification records; correction exercises. |
|
CBS-1.14 |
Provide Deposit Insurance Protection Information |
Distributed denial-of-service attack; website compromise; telephony outage; misinformation; cloud or content platform failure. |
Loss of authoritative information channels or publication of incorrect information during a bank failure could rapidly create unacceptable depositor harm. |
Deploy denial-of-service protection, content integrity monitoring, alternative channels, verified crisis messages, communication capacity testing and rapid correction arrangements. |
Website resilience tests; security monitoring; communication exercises; alternative channel tests; content approvals; incident response records. |
|
CBS-1.15 |
Manage Deposit Insurance Administrative Exceptions |
Case management outage; lost evidence; unauthorised case closure; compromised workflow; access-control failure. |
Critical exceptions may remain unresolved and propagate inaccurate decisions into other processes, contributing to a breach. |
Maintain protected case records, escalation thresholds, dual approval for material closures, alternate case tracking and periodic backlog reviews. |
Case audit logs; escalation records; access reviews; backlog reports; alternate processing test results. |
|
CBS-1.16 |
Monitor Deposit Insurance Service Performance |
Platform outages; corrupted telemetry; alert suppression; time synchronisation failure; incomplete system feeds. |
Failure to detect service degradation could delay intervention until duration, scope or integrity thresholds are exceeded. |
Establish independent monitoring, alert validation, synchronised time sources, manual reporting, escalation triggers and monitoring continuity tests. |
Monitoring coverage reports; alert testing; time synchronisation checks; escalation exercises; management dashboard records. |
|
CBS-1.17 |
Manage Deposit Insurance Service Disruptions |
Ransomware affecting incident tools; communications failure; identity infrastructure outage; cyberattack on recovery coordination systems. |
Delayed detection, decision-making or continuity activation could allow a contained incident to become a service-wide tolerance breach. |
Maintain out-of-band communications, offline continuity plans, delegated authority, alternate command arrangements, cyber crisis exercises and coordinated third-party response procedures. |
Crisis exercise reports; communication tests; delegation records; incident response plans; third-party exercise evidence; management minutes. |
|
CBS-1.18 |
Restore and Reconcile Deposit Insurance Administration |
Backup corruption; compromised recovery environment; failed failover; malware replication; unavailable recovery specialists. |
Incomplete or inaccurate restoration could extend disruption beyond the maximum duration or violate the service's integrity conditions. |
Maintain isolated recovery capabilities, verify backup integrity, test failover, perform independent reconciliation, validate restored data and establish formal return-to-service approval. |
Disaster recovery reports; failover test results; backup verification; reconciliation sign-offs; recovery acceptance records; remediation tracking. |
Cyber and ICT Risks that Could Affect Multiple Sub-CBS
The table identifies several risks that could affect CBS-1 through common dependencies rather than isolated process failures.
These risks should be assessed against the validated dependency map rather than assumed to exist in PIDM's current technology environment.
BNM's 2025 financial stability reporting highlights cyber resilience, technology failures, single points of failure and coordinated testing with critical technology providers as important operational risk considerations for Malaysian financial institutions.
For PIDM, these considerations provide useful risk assessment benchmarks. The direct applicability of particular BNM requirements must be established separately.
Recommended Impact Tolerance for CBS-1: Deposit Insurance Protection Administration
Proposed Service-level Tolerance
The recommended approach is to establish a multidimensional Impact Tolerance that combines maximum disruption duration, minimum service capacity, information integrity, stakeholder impact and the circumstances in which the service is operating.
A single time-based threshold would be insufficient because some disruptions, particularly the publication of materially incorrect coverage information, may cause unacceptable harm before the maximum disruption duration is reached.
![[OR] [PM] [PIDM] Illustrative management proposal](https://blog.bcm-institute.org/hs-fs/hubfs/%5BOR%5D%20%5BPM%5D%20Diagram/%5BOR%5D%20%5BPM%5D%20%5BPIDM%5D%20Illustrative%20management%20proposal.png?width=780&height=512&name=%5BOR%5D%20%5BPM%5D%20%5BPIDM%5D%20Illustrative%20management%20proposal.png)
The proposed duration thresholds should be understood as provisional values for assessment and scenario design. They should not be adopted merely because they appear operationally achievable.
PIDM must first determine whether unacceptable harm would arise earlier, particularly during member institution distress, critical reporting deadlines or significant public uncertainty.
Detailed Proposed Tolerance Dimensions
|
Tolerance dimension |
Indicative threshold |
Breach condition |
|
Essential administration — normal conditions |
Maximum 24 hours of continuous disruption. |
Essential CBS-1 outcomes remain unavailable beyond 24 hours, or another harm threshold is reached earlier. |
|
Essential administration — heightened stress |
Maximum 4 hours for essential protection information and administrative capabilities. |
Essential capabilities remain unavailable beyond 4 hours during a qualifying stress event, or unacceptable harm occurs earlier. |
|
Minimum service capacity |
Maintain at least 50% of the required essential administrative workload during disruption, subject to validation. |
Sustained capacity falls below the approved minimum and causes unacceptable backlog or stakeholder consequences. |
|
Information latency |
Essential membership and coverage changes should be available to authorised users within 4 hours of approval during heightened stress. |
Materially outdated information causes incorrect decisions or exceeds the approved information currency threshold. |
|
Authoritative information integrity |
Zero knowingly released material coverage errors; unresolved suspect records must be quarantined. |
Materially incorrect protection information is issued or used in an authoritative decision. |
|
Member bank impact |
No member bank should lose access to all essential protection administration channels beyond the applicable duration threshold without an effective alternative. |
The approved scope or duration of institutional disruption is exceeded. |
|
Depositor communication |
At least one verified authoritative information channel should remain available during heightened stress, with alternative channels activated promptly. |
No effective channel remains available, or materially incorrect information is disseminated. |
|
Statutory obligations |
Meet applicable legal deadlines and requirements, or use authorised contingency arrangements where legally permissible. |
A material statutory obligation is breached, irrespective of the general time threshold. |
|
Cross-CBS consequences |
CBS-1 disruption must not cause another CBS to exceed its own approved impact tolerance. |
A material dependency failure causes an approved tolerance breach in CBS-2, CBS-5, CBS-6 or another connected CBS. |
|
Recovery completeness |
Essential records and transactions must be verified and reconciled before unrestricted return to normal operations. |
Service is declared restored despite material unresolved integrity or reconciliation failures. |
The proposed 50% capacity threshold is a starting hypothesis, not an established minimum. PIDM should calculate the actual capacity required to prevent unacceptable backlog accumulation during relevant operating cycles.
Similarly, the four-hour information latency threshold should be validated against the timing of coverage decisions, member bank changes and other critical administrative requirements.
Defining the Point of Intolerable Harm
The Impact Tolerance is breached when any approved service-level threshold is exceeded.
This means that PIDM should not wait until the maximum disruption duration expires if another form of unacceptable harm occurs earlier.
For example, a material coverage information error affecting a large depositor population could breach the tolerance immediately upon authoritative publication, even if the underlying system is restored within one hour.
A service outage affecting premium assessment might remain within tolerance for several hours under normal conditions but become unacceptable if it causes a material statutory deadline to be missed.
The service-level tolerance should therefore operate as a set of binding conditions rather than an average performance score.
Proposed breach rule: A breach occurs when any approved duration, integrity, stakeholder harm, statutory or cross-service condition is exceeded. Meeting one threshold cannot compensate for breaching another.
Rationale for the Proposed Tolerance
The proposed 24-hour normal operating threshold recognises that CBS-1 is primarily an ongoing administrative service rather than a continuous payment-processing service.
Some activities may be temporarily deferred or performed through controlled alternatives without immediately causing unacceptable harm.
However, this assumption must be tested against PIDM's actual operating cycles and statutory obligations.
The proposed four-hour heightened-stress threshold reflects the greater importance of authoritative protection information and administrative readiness during member institution distress.
The integrity requirement is deliberately stricter than the availability requirement.
An unavailable system may be managed through alternative procedures. An available system producing materially incorrect protection information may create more serious harm because the error can propagate into decisions, disclosures and other critical services.
For this reason, PIDM should prioritise verified information and controlled processing over restoring normal transaction volumes prematurely.
Identifying Sub-CBS Processes Critical to Remaining Within Tolerance
The harm assessment should be combined with the interdependency map to identify processes whose disruption could cause the parent service to exceed its tolerance.
This is a proposed prioritisation for further validation, not an assertion about PIDM's existing recovery arrangements.
Critical Integrity Dependencies
The following processes require particularly strong information integrity controls:
- CBS-1.2 Maintain Deposit Insurance Coverage Framework.
- CBS-1.4 Administer Deposit Product Coverage Records.
- CBS-1.6 Receive and Validate Deposit Insurance Information.
- CBS-1.7 Maintain Insured Deposit Information and Records.
- CBS-1.8 Validate Total Insured Deposits.
These processes establish or preserve information used by other administrative activities.
Corruption or unauthorised modification may propagate into downstream decisions even when the relevant applications remain available.
Critical Communication Dependencies
CBS-1.13 and CBS-1.14 become particularly important during financial stress.
PIDM should maintain the ability to provide verified coverage information through at least one effective channel and ensure that materially inaccurate information can be withdrawn or corrected promptly.
These capabilities should be coordinated with CBS-9: Critical Depositor, Policy Owner and Public Communication.
Critical Response and Restoration Dependencies
CBS-1.16, CBS-1.17 and CBS-1.18 provide the monitoring, response and restoration capabilities required across the entire service.
If these processes fail, PIDM may be unable to detect disruption, activate alternative arrangements or confirm that service delivery has been safely restored.
Therefore, assess their effectiveness through end-to-end exercises.
Time-sensitive Premium Administration
CBS-1.9, CBS-1.10 and CBS-1.11 may become particularly important during premium assessment and collection periods.
PIDM should determine whether a separate operating-cycle condition is required within the overall impact tolerance.
For example, the tolerance may need to specify that a disruption cannot cause a material premium assessment or collection obligation to miss an applicable deadline.
This condition should be based on actual statutory and administrative requirements rather than an arbitrary recovery target.
Proactive Risk Management to Prevent Impact Tolerance Breaches
The proposed impact tolerance should guide PIDM's preventive, detective, response and recovery arrangements.
The objective is to reduce the likelihood of disruption, limit its consequences and maintain essential service outcomes when preventive controls fail.
Preventive Controls
PIDM should identify and reduce vulnerabilities that could affect several Sub-CBS processes simultaneously.
Measures should include privileged access management, secure system configuration, vulnerability remediation, controlled technology changes, segregation of duties, information validation and third-party resilience assessments.
Pay particular attention to shared infrastructure and authoritative information repositories.
Detective Controls
Monitoring should identify both technology failures and deterioration in service outcomes.
Relevant indicators include failed submissions, unusual record changes, growing processing backlogs, premium calculation anomalies, unavailable communication channels and delayed exception resolution.
Alerts should link to escalation thresholds that allow management to intervene before impact tolerance is breached.
Response Controls
PIDM should establish clear decision-making arrangements for incidents affecting CBS-1.
These should include incident classification, continuity activation, prioritisation of essential processes, stakeholder communication and coordination with affected member banks or service providers.
Response arrangements should remain executable when normal communication or identity management systems are unavailable.
Recovery Controls
Recovery arrangements should address both availability and information integrity.
Restoring an application is insufficient if the recovered information is outdated, corrupted or incomplete.
PIDM should verify recovered records, reconcile outstanding transactions, assess residual exceptions and obtain appropriate approval before returning to normal operations.
Management Oversight and Evidence
Management should require evidence demonstrating that controls operate effectively.
Examples include completed recovery tests, verified backup restoration, vulnerability remediation records, scenario testing results, third-party assurance findings and management-approved corrective actions.
A control documented in a policy should not be considered effective solely because the policy exists.
The evidence should demonstrate that the control can operate under conditions relevant to severe but plausible disruption.
Validating the Impact Tolerance Through Scenario Testing
Management must test the proposed tolerance against severe but plausible scenarios before approval.
Scenario testing should establish whether PIDM can maintain CBS-1 within the proposed duration, integrity, capacity and stakeholder harm boundaries.
Table 3: Recommended Impact Tolerance Validation Scenarios
|
Scenario |
Sub-CBS affected |
Tolerance dimensions tested |
Expected validation evidence |
|
Ransomware corrupts the deposit information repository during a premium assessment cycle. |
CBS-1.6–1.8, CBS-1.10, CBS-1.17–1.18 |
Information integrity, disruption duration, processing capacity and recovery completeness. |
Recovery test results, data reconciliation, backlog measurements and actual service restoration time. |
|
Privileged access compromise alters deposit product coverage records. |
CBS-1.2–1.4, CBS-1.13–1.15 |
Zero material coverage errors, detection time and correction capability. |
Access logs, integrity verification, incident records and corrected publication evidence. |
|
Member bank information exchange fails across multiple institutions. |
CBS-1.5–1.8, CBS-1.12 |
Information latency, affected member banks, processing backlog and minimum capacity. |
Alternative submission results, affected institution counts and backlog clearance records. |
|
Premium assessment platform fails immediately before a critical deadline. |
CBS-1.8–1.11 |
Duration, statutory obligations, financial integrity and processing capacity. |
Alternative calculation results, reconciliation records and evidence of deadline compliance. |
|
Website and telephony services fail during a member bank distress event. |
CBS-1.13–1.14, CBS-1.17 |
Four-hour heightened-stress threshold, information availability and stakeholder harm. |
Alternative channel activation, communication timestamps, enquiry volumes and approved messages. |
|
Shared identity management fails across production and recovery environments. |
Multiple Sub-CBS |
Common-cause failure, duration, minimum service capacity and recovery independence. |
Emergency access test, continuity exercise and verified service performance. |
|
Recovery systems restore outdated or corrupted administrative records. |
CBS-1.7, CBS-1.15–1.18 |
Information integrity, recovery completeness and duration. |
Backup verification, transaction reconciliation and formal restoration approval. |
Testing Methodology
Each scenario should define the disruption trigger, affected dependencies, operating conditions, assumptions and expected service outcomes.
Testing should measure actual performance against the proposed impact tolerance.
For example, a scenario involving the loss of the deposit information repository should establish whether alternative information can be obtained, whether essential administration can continue and whether recovered records can be independently verified.
The test should also assess the consequences for connected services, particularly insured deposit reimbursement and resolution preparedness.
Assessing Test Outcomes
PIDM should classify test outcomes by whether the service remained within tolerance, approached the tolerance boundary, or exceeded it.
A test that restores all systems but fails to reconcile material information discrepancies should not be recorded as successful service restoration.
Similarly, a test that meets the duration threshold but releases materially inaccurate protection information should be treated as a tolerance breach.
Remediation and Retesting
Where a test identifies a potential breach, the responsible service owner should document the root cause, proposed remediation, accountable owner and completion date.
Remediation may involve technology changes, additional capacity, alternative communication channels, improved information validation or stronger third-party arrangements.
Retest material improvements to confirm they reduce the risk of exceeding the impact tolerance.
Governance, Approval and Regulatory Alignment
Approval of the Impact Tolerance
PIDM should establish a formal approval process for CBS-1's Impact Tolerance.
The CBS owner should develop the proposed tolerance with input from operational resilience, BCM, operational risk, technology, cybersecurity, legal, compliance and relevant business functions.
The proposal should be supported by documented evidence demonstrating:
- The nature and severity of potential harm.
- The rationale for each proposed threshold.
- The operational conditions under which tighter thresholds apply.
- The relationship between the tolerance and applicable statutory obligations.
- The ability of existing or proposed arrangements to maintain the service within tolerance.
- The results of scenario testing and any material unresolved vulnerabilities.
Senior management should challenge the proposed thresholds and submit them for approval through PIDM's established governance arrangements.
Where a proposed threshold cannot currently be achieved, management should document the capability gap, associated risk, remediation plan and interim controls. The threshold should not simply be relaxed to match existing recovery capabilities.
Regulatory Alignment
BNM issued its Discussion Paper on Operational Resilience on 19 December 2025.
The paper addresses the development of resilience capabilities, including identifying critical services, mapping dependencies, setting disruption tolerances, and testing severe but plausible scenarios.
BNM's subsequent financial stability reporting also highlights the importance of cyber resilience, managing technology dependencies, identifying single points of failure and conducting coordinated testing with critical technology service providers.
These considerations provide useful benchmarks for PIDM's methodology.
However, the December 2025 document is a discussion paper, and PIDM should establish its direct applicability separately.
BNM does not prescribe the thresholds proposed in this chapter, and PIDM should not present them as regulatory requirements.
Impact Tolerance Approval Record
PIDM should maintain a controlled approval record containing the following information.
|
Approval field |
Required information |
|
CBS |
CBS-1: Deposit Insurance Protection Administration |
|
Accountable owner |
PIDM-designated CBS owner |
|
Proposed tolerance |
24 hours under normal conditions; four hours for specified essential capabilities during heightened stress |
|
Additional conditions |
Approved integrity, capacity, information latency, stakeholder and statutory thresholds |
|
Harm assessment |
Documented justification for the proposed boundaries |
|
Supporting evidence |
Sub-CBS assessment, dependency maps, impact analysis and scenario testing results |
|
Review and challenge |
Business, risk, technology, cybersecurity, legal and compliance review |
|
Approval authority |
Appropriate authority under PIDM's governance framework |
|
Review triggers |
Material service changes, incidents, test failures, regulatory developments and changes in dependencies |
|
Approval status |
Pending validation and formal approval |
The approval record should identify the version of the tolerance statement, approval date, accountable owner and next review date.
Setting an Impact Tolerance for CBS-1: Deposit Insurance Protection Administration establishes a clear boundary between disruption that PIDM can manage and disruption that creates unacceptable harm.
The assessment of all 18 Sub-CBS processes shows that the consequences of disruption differ by the nature of the affected activity, its dependencies, operating conditions, and the potential for harm to propagate across the service.
Information integrity, authoritative coverage decisions, member bank information, public communication and effective recovery arrangements are particularly important to maintaining the service within acceptable limits.
Integrating cyber and ICT risks into the assessment strengthens PIDM's understanding of how ransomware, unauthorised access, data corruption, infrastructure outages and shared technology dependencies could compromise end-to-end service delivery.
The proposed Impact Tolerance combines duration, service capacity, information integrity, stakeholder impact and statutory obligations. Its numerical thresholds are illustrative and must be validated against PIDM's actual operating environment and evidence of unacceptable harm.
Proactive risk management should be supported by auditable evidence demonstrating the effectiveness of preventive controls, monitoring, incident response, recovery and reconciliation arrangements.
Once approved, the Impact Tolerance should guide scenario testing, recovery priorities, remediation decisions and resilience investment. It should also be reviewed whenever significant changes occur to CBS-1, its supporting processes, technology, third parties or operating environment.
The next implementation activity is to conduct severe but plausible scenario testing to determine whether PIDM can maintain Deposit Insurance Protection Administration within its approved Impact Tolerance and identify improvements where existing capabilities are insufficient.
Gain Competency: For organisations looking to accelerate their journey, BCM Institute’s training and certification programs, including the OR-5000 Operational Resilience Expert Implementer course, provide in-depth insights and practical toolkits for effectively embedding this model.

![BB OR [A] 18 BB OR [A] 18](https://blog.bcm-institute.org/hs-fs/hubfs/OR%20picture/OR%20Pictures%20A/BB%20OR%20Folder%20A/BB%20OR%20%5BA%5D%2018.jpg?width=2000&height=1333&name=BB%20OR%20%5BA%5D%2018.jpg)


![[OR] [PM] [PIDM] Proposed five level harm classification](https://blog.bcm-institute.org/hs-fs/hubfs/%5BOR%5D%20%5BPM%5D%20Diagram/%5BOR%5D%20%5BPM%5D%20%5BPIDM%5D%20Proposed%20five%20level%20harm%20classification.png?width=788&height=462&name=%5BOR%5D%20%5BPM%5D%20%5BPIDM%5D%20Proposed%20five%20level%20harm%20classification.png)
![Banner [Table] [OR] [E3] Establish Impact Tolerance](https://no-cache.hubspot.com/cta/default/3893111/627c33a8-714d-40af-9a2b-0d7957fb8afa.png)

![Banner [Summing] [OR] [E3] Establish Impact Tolerance](https://no-cache.hubspot.com/cta/default/3893111/5e80e50f-5e3e-44ea-8c43-16bf42d4f3b5.png)

![[OR] [PIDM] [E3] [CBS] [1] [DP] Deposit Insurance Protection Administration](https://no-cache.hubspot.com/cta/default/3893111/fcc1a03b-1f2c-41e4-a510-b733d153c6b0.png)
![[OR] [PIDM] [E3] [CBS] [1] [MII] Deposit Insurance Protection Administration](https://no-cache.hubspot.com/cta/default/3893111/2d1258ae-8671-46c3-8185-b57fa19bfad8.png)
![[OR] [PIDM] [E3] [CBS] [1] [SbPS] Deposit Insurance Protection Administration](https://no-cache.hubspot.com/cta/default/3893111/8572ef1b-f502-4dfb-912a-e57072c9b7b4.png)
![[OR] [PIDM] [E3] [CBS] [1] [ST] Deposit Insurance Protection Administration](https://no-cache.hubspot.com/cta/default/3893111/d72c17a8-a9f9-4aeb-8593-32cb40696ad9.png)







![[BL-OR] [3-4-5] View Schedule](https://no-cache.hubspot.com/cta/default/3893111/d0d733a1-16c0-4b68-a26d-adbfd4fc6069.png)
![[BL-OR] [3] FAQ OR-300](https://no-cache.hubspot.com/cta/default/3893111/f20c71b4-f5e8-4aa5-8056-c374ca33a091.png)
![Email to Sales Team [BCM Institute]](https://no-cache.hubspot.com/cta/default/3893111/3c53daeb-2836-4843-b0e0-645baee2ab9e.png)








