Operational Resilience for Financial Institutions (BNM)
Bank Negara Malaysia issued a Discussion Paper on Operational Resilience on 19 December 2025, with comments closing on 30 April 2026. It is not yet a policy document, but its direction is clear. Financial institutions are expected to identify their critical operations and services, map the people, processes, technology and third parties they depend on, set a tolerance for how long and how badly each can be disrupted before customers or markets are harmed, and test their ability to stay within it under severe but plausible scenarios. One piece is already in force: under the Responsibility Mapping policy document, effective 1 January 2026, banks and insurers must designate a member of senior management reporting directly to the CEO as responsible for implementing the operational resilience framework.
This two-day course is for operational risk, business continuity, technology, outsourcing and resilience teams, and the senior managers now accountable for resilience, in banks, Islamic banks, insurers and takaful operators. It separates clearly what is required today from what the discussion paper proposes, so institutions can build ahead of the final policy without over-committing. It connects resilience to existing work under RMiT, outsourcing and business continuity, and pairs with ISO 22301 Business Continuity for the continuity programme itself.
HRD Corp SBL-Khas Claimable
Programme Agenda
Day 1, 9:00 AM - 9:15 AM
Welcome and Programme Overview
Introduction to the session, objectives, and housekeeping.
Day 1, 9:15 AM - 10:15 AM
Where Operational Resilience Stands in Malaysia
The December 2025 discussion paper and its status, the Responsibility Mapping requirement in force since 1 January 2026, and how resilience relates to existing policy documents on operational risk, RMiT, outsourcing and business continuity.
Day 1, 10:15 AM - 10:30 AM
Break
Day 1, 10:30 AM - 11:30 AM
Identifying Critical Operations and Services
Choosing the services whose disruption would harm customers, the institution or the financial system, and the level of granularity that makes mapping useful rather than exhausting.
Day 1, 11:30 AM - 12:30 PM
Mapping Dependencies
Mapping people, processes, technology, facilities, data and third parties behind each critical service, including service providers beyond your own organisation such as third-party administrators and distribution partners, and finding single points of failure.
Day 1, 12:30 PM - 1:30 PM
Lunch
Day 1, 1:30 PM - 3:15 PM
Setting Tolerances for Disruption
Defining how long a critical service can be disrupted, how much impact is acceptable, and the minimum level of service to maintain, from the customer's and the market's point of view.
Day 1, 3:15 PM - 3:30 PM
Break
Day 1, 3:30 PM - 4:45 PM
Severe but Plausible Scenario Testing
Designing scenarios severe enough to reveal weaknesses yet credible, multi-layered failures, cyber and third-party outages, and using results to recalibrate tolerances and investment.
Day 1, 4:45 PM - 5:00 PM
Day 1 Close
Recap and what to review before day two.
Day 2, 9:00 AM - 9:15 AM
Day 1 Review
Recap of day one and the questions it left open.
Day 2, 9:15 AM - 10:15 AM
Third Parties and Concentration Risk
Contingency and alternative arrangements for critical third-party services, cloud concentration, exit planning and what to test with key providers.
Day 2, 10:15 AM - 10:30 AM
Break
Day 2, 10:30 AM - 12:30 PM
Accountability Under Responsibility Mapping
The designated senior manager's role, how other senior managers share responsibility for resilience in their domains, board oversight, and the reporting the board should receive.
Day 2, 12:30 PM - 1:30 PM
Lunch
Day 2, 1:30 PM - 3:15 PM
Customer-Centric Disruption Management
Communicating with customers during disruptions, workarounds that protect vulnerable customers, and learning from incidents.
Day 2, 3:15 PM - 3:30 PM
Break
Day 2, 3:30 PM - 4:45 PM
Workshop: One Critical Service End to End
Teams select a critical service for a case institution, map its dependencies, set an impact tolerance, design a scenario test, and draft the board summary.
Day 2, 4:45 PM - 5:00 PM
Wrap-Up and Q&A
Key takeaways, next steps, and close.
Key Outcomes
- Distinguish current requirements from the proposals in BNM's discussion paper
- Identify critical operations and services and map their dependencies
- Set defensible tolerances for disruption
- Design severe but plausible scenario tests and use the results
- Manage third-party and concentration risk for critical services
- Meet the Responsibility Mapping expectations for resilience accountability
Training Mode Physical / Online / Hybrid / e-learning
HRD Corp SBL-Khas Claimable
Level Intermediate. For operational risk, business continuity, technology, outsourcing and resilience teams, and accountable senior managers, in banks, Islamic banks, insurers and takaful operators.
Duration 2 Days (16 Hours) | 9:00 AM to 5:00 PM daily
Venue In-house at the client's premises, or delivered via the client's preferred platform (Microsoft Teams, Zoom, or equivalent)
Assessment A mapped critical service with tolerance, scenario test and board summary, plus a written knowledge check
Certificate Certificate of Completion issued to all participants upon full attendance