. .
Bangko Sentral Ng Pilipinas (BSP) Operational Resilience Guidelines Series
BB OR 5

[OR] [BSP] Integrating Operational Resilience with Key Risk Management Processes

The Bangko Sentral ng Pilipinas (BSP) emphasises the importance of operational resilience for BSP-supervised financial institutions (BSFIs). This resilience is vital for ensuring the continuity of critical operations during significant disruptions, thereby safeguarding the institutions’ viability and the integrity of the financial system. 

Operational resilience is viewed as an end-state wherein a BSFI showcases its capability to sustain critical operations despite adverse events. BSFIs must conduct proactive assessments, devise strategic response plans, and weave operational resilience into their overall risk management structures to reach this goal.

This involves a comprehensive governance approach encompassing key processes, including operational risk management, business continuity management (BCM), cybersecurity, outsourcing frameworks, and recovery planning. These elements are crucial in strengthening the institution’s resilience against diverse threats.

Moh Heng Goh
Operational Resilience Audit-Specialist-Expert

Operational Resilience and Its Integration with Related Processes

[OR][BSP Guidelines] Integrate with RM FunctionsThe Bangko Sentral ng Pilipinas (BSP) emphasises that operational resilience is an essential outcome for BSFIs (BSP-supervised financial institutions).

Bangko Sentral ng Pilipinas official at a monetary policy meetingIt ensures the continuity of critical operations during significant disruptions while safeguarding the institution's viability and the financial system.

Achieving operational resilience requires integrating various risk management functions into a cohesive framework.

This section outlines the interaction of operational resilience with critical processes such as operational risk management, business continuity management, cybersecurity, outsourcing, and recovery planning.

Operational Resilience as an End-State

OR Core ComponentOperational resilience is the ultimate goal where a BSFI demonstrates the ability to maintain its critical operations during disruptions.

This resilience strengthens the BSFI's viability and reinforces the financial system's stability.

Acknowledging that disruptions will occur, BSFIs must conduct forward-looking assessments, carefully plan responses, and integrate operational resilience into their risk management frameworks.

It is not a stand-alone goal but part of a broader governance structure that includes operational risk management, business continuity, cybersecurity, outsourcing, and recovery planning.

Operational Risk Management

New call-to-actionOperational resilience is deeply connected to operational risk management, though their focuses differ.

While operational risk management deals with reducing the risk of losses due to failed internal processes, systems, or external events, operational resilience focuses on the ability to maintain critical operations despite such failures.

Operational resilience aims to minimise the impact of disruptions on customers, market integrity, and the financial system rather than merely preventing loss. This broader focus ensures that critical services remain available even during adverse events.

Business Continuity Management (BCM)

New call-to-actionBusiness continuity management (BCM) and operational resilience complement each other. BCM traditionally addresses individual points of failure, ensuring continuous operation during disruptions.

Operational resilience, however, extends this focus by ensuring the end-to-end delivery of critical services across a broader range of potential disruptions.

While BCM may be triggered during a crisis, operational resilience covers a broader spectrum of capabilities, including crisis management, to ensure the delivery of critical operations through varying scenarios.

Cybersecurity

New call-to-actionCybersecurity is crucial for protecting a BSFI’s information assets, customers, and third parties from cyberattacks. BSFIs must continuously assess their cyber environment as cyber threats evolve and adapt their defences accordingly.

Integrating cyber resilience with operational resilience involves identifying critical operations, setting tolerances for disruption, and aligning cybersecurity priorities with the broader resilience framework.

This holistic approach ensures that BSFIs can withstand cyber threats while maintaining critical functions.

Outsourcing Framework

New call-to-actionOutsourcing has become common in the financial industry, particularly for critical operations. However, outsourcing adds complexity and can expose BSFIs to additional vulnerabilities.

BSFIs must ensure that their third-party service providers have the same operational resilience level as the institution.

This includes maintaining resilience during both routine operations and potential disruptions. Adequate oversight and controls are essential to ensure third-party partners meet these standards.

Recovery Plan

The recovery plan is another critical component of operational resilience. It enables BSFIs to take pre-emptive measures to avoid breaching regulatory requirements and maintain financial resilience.

BSFIs should align their recovery plans with the operational resilience framework, mainly the critical functions and services identified.

This ensures that recovery from non-financial risks is fully integrated into the BSFI’s overall approach to maintaining critical operations during disruptions.

Summing Up...

The BSP’s operational resilience framework encompasses a wide-ranging, integrated approach beyond isolated risk management strategies.

BSFIs are expected to embed resilience into their governance structures, ensuring they can continue providing critical operations during disruptions. This will support the stability of the financial system and the broader economy.

 

BSP Operational Resilience Guidelines
 
 
[OR][BSP Guidelines] Key Implementation and Components [OR][BSP Guidelines] Key OR Definition [OR][BSP Guidelines] Integrate with RM Functions [OR][BSP Guidelines] Key OR Elements [OR][BSP Guidelines] Reporting, Notification and Supervisory Requirements    
[OR][BSP Framework] Summary Self-Assessment Questionnaire [OR][BSP Framework] Self-Assessment Questionnaire [OR][BSP Framework] SAQ Part 1 & 2 [OR][BSP] Guidelines on Operational Resilience BCMPedia Operational Resilience    

More Information About Blended Learning OR-5000 [OR-5] or OR-300 [OR-3]

To learn more about the course and schedule, click the buttons below for the OR-3 Blended Learning OR-300 Operational Resilience Implementer course and the OR-5 Blended Learning OR-5000 Operational Resilience Expert Implementer course.

BL-OR-3 Register Now BL-OR-3_Tell Me More BL-OR-3_View Schedule
BL-OR-5_Register Now BL-OR-5_Tell Me More  [BL-OR] [3-4-5] View Schedule
[BL-OR] [3] FAQ OR-300

If you have any questions, click to contact us.Email to Sales Team [BCM Institute]

FAQ BL-OR-5 OR-5000
 

 

 
OR Implementer Landing Page

New call-to-action

New call-to-action

Comments:

 

More Posts

New Call-to-action