Operational Resilience Series
BGBann_Playbook_Crisis Management

[OR] [P2-S1] What is Critical Business Services in Operational Resilience?

Critical Business Service is a service provided by an organisation, or by another person on behalf of the organisation, to one or more clients which, if disrupted, could:

  • cause intolerable harm to any one or more of the organisation’s clients or
  • pose a risk to the soundness, stability or resilience of the industry, such as the financial industry, its system or the orderly operation of the markets.

This is the introductory blog [OR-P2-S1] to Stage 1 of the "IMPLEMENT" phase of the OR Planning Methodology.  It is a pre-reading for participants attending the Operational Resilience Implementer/ Expert Implementer course.

Moh Heng Goh
Operational Resilience Certified Planner-Specialist-Expert

New call-to-action[Implement] What is a Critical Business Service?

Critical Business Service is a service provided by an organisation, or by another person on behalf of the organisation, to one or more clients which, if disrupted, could:

  1. Cause intolerable harm to any one or more of the organisation’s clients or
  2. Pose a risk to the soundness, stability or resilience of the industry, such as the financial industry, its system or the orderly operation of the markets.

How Does an Organisation Identify Business Services?

When considering what business services an organisation provides, looking at the customer journey in the financial industry or manufacturing the production and distribution processes is a good starting point.

Other sources of information to leverage when identifying services include but are not limited to:

  • Risk registers
  • Critical asset and third-party supplier lists and risk assessments
  • Business continuity and recovery plans

It is essential for the OR implementer first to identify Critical Business Services or CBS, sometimes referred to as Important Business Services or Critical Operations, across different organisations operating globally. 

Viewing from the lens of these business operations or services, set tolerance for disruption (will be explained as "impact tolerance" in the next stage), secure resources, and verify the appropriateness of the framework.

Differing from the current risk management framework, risk in operational resilience is viewed from an end-to-end service.

What is and is not a Business Service?

To have a detailed but not complicated presentation of each identified important business service (critical business service or critical operation), it is essential to understand that only business services will be documented once identified as important or critical. 

Other related documentation, such as "underpinning services" and "internal services," will not be presented to the regulators as it would result in a very "complicated" view of a business service.

 

Business Service Underpinning Services Internal Services
OR Business Services BCMPedia OR Underpinning Services BCMPedia New call-to-action
Document Not presented as part of Business Services (to the regulator)

 

New call-to-actionHow to Identify Critical Business Services?

Identifying critical business services is a crucial step in operational resilience planning. These services are essential for the organisation's operations, revenue generation, regulatory compliance, and customer satisfaction. The following steps outline the process:

Define the Scope and Objectives
  • Define the scope and objectives of the operational resilience implementation. 
  • Identify the areas, functions, and processes that must be assessed for criticality.
    • This includes core banking services, payment processing, customer support, risk management, regulatory compliance, and other critical business functions.
Conduct Business (Services) Impact Analysis
  • OR Business Services BCMPediaPerform a Business (Services) Impact Analysis to assess the potential impacts of disruptions on various business processes and services.
    • Note that the scope is broader than the typical "critical business function."
  • Identify dependencies, interconnections, and criticality of each service.
  • Identify the critical inputs, processes, and outputs associated with each service.
  • Determine their recovery time objectives (RTO) and recovery point objectives (RPO).
  • Consider service disruptions and financial, operational, reputational, and regulatory consequences.
Engage Relevant Stakeholders
  • Collaborate with business unit leaders, department heads, risk managers, and subject matter experts to gather insights on the importance of specific services and their interdependencies. 
  • Ensure representation from different areas of the institution to capture diverse perspectives.
  • Engage relevant stakeholders across the organisation to comprehensively understand the business services and their criticality. 
Prioritise Services
  • Prioritize the identified business services based on the BIA findings and stakeholder input.
  • Assign a level of criticality to each service based on its impact on the institution's overall operations, regulatory compliance, customer experience, and financial stability. 
  • Use consistent and objective criteria to rank the services in order of importance.
Document Critical Business Services
  • Create a comprehensive inventory of critical business services, including their dependencies, associated risks, and recovery requirements.
  • Maintain this inventory as a living document and update it regularly.
  • Document the identified critical business services in a structured manner. 
  • Include detailed information such as service descriptions, key inputs and outputs, dependencies, recovery objectives, and any regulatory requirements specific to each service.
  • Maintain documentation as it will serve as a reference for future resilience planning and resource allocation.
Validate and Review
  • Validate and review the identification of critical business services regularly to ensure their ongoing relevance and alignment with organizational goals and strategies.
Additional Explanatory Note 

  Terminology Explanation See Definition  
  Critical Business Service is a business service that, if disrupted, is likely to impact the FSI’s safety and soundness significantly, as well as its customers or other FSI that depend on the business service. OR Critical Business Services BCMPedia  
  Important Business Service is a business service provided by an organisation, or by another person on behalf of the organisation, to one or more clients which, if disrupted, could:
  • cause intolerable harm to any one or more of the organisation’s clients or
  • pose a risk to the soundness, stability or resilience of the financial system or the orderly operation of the financial markets.
New call-to-action  
  Critical Operations is defined as an output to a business service that, if interrupted during the operational period, will cause financial loss, damage, or interruption to the delivery of goods or services essential to the organization’s continued operation or success. OR Critical Operations  
  Harm The impact of the level of harm to the customer when the organisation providing critical business services is disrupted. There are three levels of harm:
  • Intolerable harm
  • Harm
  • Inconvenience
OR Levels of Harm BCMPedia  
  Business Services (Banking)

Banking Examples

  • Cash transactions
  • Lending
  • Deposit-taking
  • Treasury
  • Private banking and wealth management
  • Investment banking
  • Corporate finance
  • Trade services

New call-to-action

 
  Business Services (Insurance)

Insurance Examples

  • Claims servicing
  • Policy renewal and servicing
  • Policy inception
New call-to-action  
         
 
"Implement" Phase of the OR Planning Methodology

 

Identify Important Business Services Map Processes and Resources

Set Impact Tolerance

Conduct Scenario Testing Improve Lesson Learnt  
New call-to-action New call-to-action New call-to-action New call-to-action New call-to-action  

 

This is not part of the implementation methodology as it is an ongoing activity before and after the implementation.

  Implementation Activities Definition
  Prior "Develop and Embed Governance" must be completed before the implementation as part of the initial assessment when embarking on the operational resilience journey. OR Governance BCMPedia
  Post Post-implementation will require reporting and the ability to "Provide Self-assessment". New call-to-action

 

Exam Preparation for OR BoK 6 New call-to-action New call-to-action New call-to-action
       

More Information About Blended Learning OR-5000 [BL-OR-5] or OR-300 [BL-OR-3]

To learn more about the course and schedule, click the buttons below for the OR-3 Blended Learning OR-300 Operational Resilience Implementer course and the OR-5 Blended Learning OR-5000 Operational Resilience Expert Implementer course.

BL-OR-3 Register Now BL-OR-3_Tell Me More BL-OR-3_View Schedule
BL-OR-5_Register Now BL-OR-5_Tell Me More  [BL-OR] [3-4-5] View Schedule
[BL-OR] [3] FAQ OR-300

If you have any questions, click to contact us.Email to Sales Team [BCM Institute]

FAQ BL-OR-5 OR-5000
[BL-OR] [3] What is BL-OR-3 Course?

New call-to-action

[BL-OR] [3-4-5] What is BL-OR-5 Course?

Comments

 

More Posts

New Call-to-action