Self-Assessment Questionnaire on Operational Resilience
The evolving regulatory landscape requires financial institutions to continually strengthen their operational resilience (OR) frameworks.
In this context, the Self-Assessment Questionnaire (SAQ) provides a structured tool to help BSP-supervised financial institutions (BSFIs) evaluate their preparedness for operational disruptions.
This article explains the SAQ's key objectives, structure, and timeline and is a practical example for professionals navigating their institution's OR journey.
Objectives of the Self-Assessment Questionnaire
- Evaluate OR Capabilities. The SAQ offers an overview of the BSFI's current OR capabilities and pinpoints areas for further development.
- Support Leadership and Supervision. It aids the Board, senior management, and bank supervisors understand the organisation's operational resilience readiness.
- Capture the OR Journey. The SAQ documents the institution's progress toward achieving operational resilience, serving as a benchmark and a roadmap for future enhancements.
Timeline for Compliance
BSFIs must submit a transition plan, comprising a gap analysis and action plan, to the BSP's supervising department within one year of the Circular’s effectivity.
The SAQ forms the basis of this submission.
Critical Elements of the Self-Assessment Questionnaire
The SAQ comprises multiple sections designed to guide financial institutions through a systematic evaluation of their operational resilience framework.
Part I: Gap Analysis
For the detailed guided questions, refer to Appendix II, "Self-Assessment Questionnaire (SAQ) on the Operational Resilience Framework. "
The Gap Analysis focuses on assessing compliance with the BSP's circular and identifying areas that need improvement. It involves three key steps:
- Assessment of Compliance. The institution evaluates whether it is entirely, partially, or non-compliant with the requirements.
- Identifying Gaps. This step pinpoints the areas where the institution falls short of the requirements.
- Action Plans. The institution proposes specific measures to address the identified gaps and enhance its OR capabilities.
A. Governance Structure
Critical questions for this section include:
- Does the BSFI have a dedicated Board-level committee overseeing the integration of operational resilience?
- Have roles and responsibilities for operational resilience been defined for senior management, business units, and risk management functions?
- For foreign banks, has the head office implemented an OR framework applicable to the Philippine branch?
Actionable Insight. A strong governance structure is essential for implementing a robust OR framework. Financial institutions must establish apparent leadership oversight and articulate roles and responsibilities across different departments.
B. Vital Elements of Operational Resilience
Identify Critical Operations
- Has the institution identified and gained Board approval for critical operations?
- Have changes been made to the business model or processes following the identification of these operations?
Set Tolerance for Disruption
- What is the institution’s tolerance for disruption, and how is it set?
- Which personnel are responsible for ensuring that operations remain within the set tolerance levels?
Determine Severe but Plausible Scenarios
- Has the institution identified scenarios that could significantly impact critical operations?
- Are “severe and plausible” scenarios included, such as coordinated cyberattacks or natural disasters like the "Big One"?
Map Interconnections and Interdependencies
- Has the institution mapped the interconnections and interdependencies of critical operations?
- Are vulnerabilities identified during the mapping process? What action plans are in place to address them?
Plan for and Manage Risks
- Have disruptions or vulnerabilities been identified that could affect critical operations?
- What measures are in place to ensure that critical operations can continue throughout a disruption?
Business Continuity Management (BCM) and Testing
- Is BCM integrated into the institution’s operational resilience framework?
- Has the institution conducted business continuity exercises for severe and plausible scenarios, ensuring alignment with identified critical operations?
Respond to and Recover from Disruptive Events
- How will response and recovery strategies mitigate harm to customers and the financial system?
- Are internal and external communication plans in place for operational disruptions?
Review, Refine, and Update the OR Framework
- Does the institution maintain a database of disruptions affecting critical operations?
- How often does the institution review and update its OR framework, and who is responsible?
Action Steps for BSFIs
BSFIs should leverage the SAQ to:
- Engage Leadership. Ensure active involvement of the Board and senior management in overseeing operational resilience efforts.
- Identify Critical Gaps. Use the gap analysis to highlight weaknesses and non-compliance with the regulatory requirements.
- Develop Action Plans. Proactively develop and implement measures to address governance, operational processes, and risk management gaps.
- Test Continuity Plans. Regularly test business continuity and recovery plans against severe scenarios to ensure operational resilience.
Summing Up...
The Self-Assessment Questionnaire offers a comprehensive framework for BSFIs to assess and enhance their operational resilience capabilities.
By systematically addressing governance structures, identifying critical operations, and preparing for severe but plausible scenarios, financial institutions can ensure they are well-prepared to navigate operational disruptions.
The SAQ is a regulatory requirement and a vital tool in the institution’s broader risk management strategy.
More Information About Blended Learning OR-5000 [OR-5] or OR-300 [OR-3]
To learn more about the course and schedule, click the buttons below for the OR-3 Blended Learning OR-300 Operational Resilience Implementer course and the OR-5 Blended Learning OR-5000 Operational Resilience Expert Implementer course.
![]() |
![]() |
![]() |
![]() |
![]() |
![]() |
![]() |
![]() |
|
|
||
![]() |
![]() |