Operational Resilience for Financial Institutions (BNM)

Bank Negara Malaysia issued a Discussion Paper on Operational Resilience on 19 December 2025, with comments closing on 30 April 2026. It is not yet a policy document, but its direction is clear. Financial institutions are expected to identify their critical operations and services, map the people, processes, technology and third parties they depend on, set a tolerance for how long and how badly each can be disrupted before customers or markets are harmed, and test their ability to stay within it under severe but plausible scenarios. One piece is already in force: under the Responsibility Mapping policy document, effective 1 January 2026, banks and insurers must designate a member of senior management reporting directly to the CEO as responsible for implementing the operational resilience framework.

This two-day course is for operational risk, business continuity, technology, outsourcing and resilience teams, and the senior managers now accountable for resilience, in banks, Islamic banks, insurers and takaful operators. It separates clearly what is required today from what the discussion paper proposes, so institutions can build ahead of the final policy without over-committing. It connects resilience to existing work under RMiT, outsourcing and business continuity, and pairs with ISO 22301 Business Continuity for the continuity programme itself.

HRD Corp Training Provider Malaysia HRD Corp SBL-Khas Claimable

Programme Agenda

01

Day 1, 9:00 AM - 9:15 AM

Welcome and Programme Overview

Introduction to the session, objectives, and housekeeping.

02

Day 1, 9:15 AM - 10:15 AM

Where Operational Resilience Stands in Malaysia

The December 2025 discussion paper and its status, the Responsibility Mapping requirement in force since 1 January 2026, and how resilience relates to existing policy documents on operational risk, RMiT, outsourcing and business continuity.

03

Day 1, 10:15 AM - 10:30 AM

Break

04

Day 1, 10:30 AM - 11:30 AM

Identifying Critical Operations and Services

Choosing the services whose disruption would harm customers, the institution or the financial system, and the level of granularity that makes mapping useful rather than exhausting.

05

Day 1, 11:30 AM - 12:30 PM

Mapping Dependencies

Mapping people, processes, technology, facilities, data and third parties behind each critical service, including service providers beyond your own organisation such as third-party administrators and distribution partners, and finding single points of failure.

06

Day 1, 12:30 PM - 1:30 PM

Lunch

07

Day 1, 1:30 PM - 3:15 PM

Setting Tolerances for Disruption

Defining how long a critical service can be disrupted, how much impact is acceptable, and the minimum level of service to maintain, from the customer's and the market's point of view.

08

Day 1, 3:15 PM - 3:30 PM

Break

09

Day 1, 3:30 PM - 4:45 PM

Severe but Plausible Scenario Testing

Designing scenarios severe enough to reveal weaknesses yet credible, multi-layered failures, cyber and third-party outages, and using results to recalibrate tolerances and investment.

10

Day 1, 4:45 PM - 5:00 PM

Day 1 Close

Recap and what to review before day two.

11

Day 2, 9:00 AM - 9:15 AM

Day 1 Review

Recap of day one and the questions it left open.

12

Day 2, 9:15 AM - 10:15 AM

Third Parties and Concentration Risk

Contingency and alternative arrangements for critical third-party services, cloud concentration, exit planning and what to test with key providers.

13

Day 2, 10:15 AM - 10:30 AM

Break

14

Day 2, 10:30 AM - 12:30 PM

Accountability Under Responsibility Mapping

The designated senior manager's role, how other senior managers share responsibility for resilience in their domains, board oversight, and the reporting the board should receive.

15

Day 2, 12:30 PM - 1:30 PM

Lunch

16

Day 2, 1:30 PM - 3:15 PM

Customer-Centric Disruption Management

Communicating with customers during disruptions, workarounds that protect vulnerable customers, and learning from incidents.

17

Day 2, 3:15 PM - 3:30 PM

Break

18

Day 2, 3:30 PM - 4:45 PM

Workshop: One Critical Service End to End

Teams select a critical service for a case institution, map its dependencies, set an impact tolerance, design a scenario test, and draft the board summary.

19

Day 2, 4:45 PM - 5:00 PM

Wrap-Up and Q&A

Key takeaways, next steps, and close.

Key Outcomes

  • Distinguish current requirements from the proposals in BNM's discussion paper
  • Identify critical operations and services and map their dependencies
  • Set defensible tolerances for disruption
  • Design severe but plausible scenario tests and use the results
  • Manage third-party and concentration risk for critical services
  • Meet the Responsibility Mapping expectations for resilience accountability

Training Mode   Physical / Online / Hybrid / e-learning

HRD Corp   SBL-Khas Claimable

Level   Intermediate. For operational risk, business continuity, technology, outsourcing and resilience teams, and accountable senior managers, in banks, Islamic banks, insurers and takaful operators.

Duration   2 Days (16 Hours)  |  9:00 AM to 5:00 PM daily

Venue   In-house at the client's premises, or delivered via the client's preferred platform (Microsoft Teams, Zoom, or equivalent)

Assessment   A mapped critical service with tolerance, scenario test and board summary, plus a written knowledge check

Certificate   Certificate of Completion issued to all participants upon full attendance

Enquiries   Contact us to register or discuss scheduling

Frequently Asked Questions

Yes. Operational Resilience for Financial Institutions (BNM) is HRD Corp SBL-Khas claimable. Employers registered with HRD Corp (PSMB) can claim the training fee against their levy, as Orbix Tech Sdn Bhd is an HRD Corp certified training provider. Submit the SBL-Khas application before the session date.

Operational Resilience for Financial Institutions (BNM) runs for 2 days (16 hours) | 9:00 AM to 5:00 PM daily. It is delivered as an in-house closed group session, so the schedule can be adjusted to fit your team's working hours.

Yes. Delivery options are physical, online, hybrid, e-learning. In-house sessions run at your premises anywhere in Malaysia, online sessions run live over video conference, and hybrid combines both for teams split across sites.

Certificate of Completion issued to all participants upon full attendance. Each certificate carries a certificate number that can be checked at orbixtech.my/certificate-verify.

Level: Intermediate. For operational risk, business continuity, technology, outsourcing and resilience teams, and accountable senior managers, in banks, Islamic banks, insurers and takaful operators. The session is built around worked examples and group exercises rather than theory, so participants apply the material to their own organisation during the session.

Half-day and full-day sessions are quoted per session for a closed group, from RM 800 and RM 1,750 respectively. Advanced 2-day programmes are quoted per participant, from RM 4,000. All figures are before any HRD Corp levy claim.