Skip to content

MAS Guidelines on Business Continuity Management and Operational Resilience

Back to Technology & Cyber

Previous Next


Overview

MAS has established comprehensive expectations for operational resilience in financial institutions through its Guidelines on Business Continuity Management (BCM) and the broader operational resilience framework. These guidelines require FIs to identify critical business services, set impact tolerances, and ensure they can continue to deliver essential services during severe disruptions -- whether from pandemics, cyberattacks, technology failures, or natural disasters.

Applicable to: All financial institutions regulated by MAS, including banks, insurers, capital markets intermediaries, financial holding companies, and payment service providers.

Legal basis: MAS Guidelines on Business Continuity Management (BCM-G01), MAS Notice on Technology Risk Management, MAS Information Paper on Operational Resilience (2022).

Key milestones: Original BCM Guidelines issued in 2003; revised in 2022 to incorporate operational resilience concepts aligned with international standards (Basel Committee BCBS d515, FSB guidance).


1. Business Continuity Management Framework

1.1 Board and Senior Management Responsibilities

  • Board oversight: The board should approve the BCM policy and framework, set the FI's risk appetite for operational disruptions, and receive regular reports on BCM readiness.
  • Senior management accountability: Senior management should establish and maintain the BCM framework, allocate adequate resources, and ensure regular testing.
  • BCM governance: Designate a senior officer responsible for BCM coordination across the organization.
  • BCM committee: Establish a BCM committee or equivalent governance body with representation from key business and support functions.

1.2 BCM Policy

FIs should establish a BCM policy that covers:

  • Scope and objectives of the BCM program
  • Roles and responsibilities for BCM activities
  • Risk appetite for operational disruptions
  • Integration with enterprise risk management
  • Testing and review frequency
  • Training and awareness requirements
  • Reporting and escalation procedures

1.3 Business Impact Analysis (BIA)

FIs must conduct regular BIAs to:

  • Identify critical business functions and services
  • Assess the impact of disruptions (financial, regulatory, reputational, customer)
  • Determine maximum tolerable downtime for each critical function
  • Identify dependencies (technology, people, facilities, third parties)
  • Establish recovery priorities and resource requirements
  • Update BIA at least annually or when significant changes occur

2. Critical Business Services

2.1 Identification

FIs should identify critical business services based on:

  • Customer impact: Services whose disruption would significantly impact customers' ability to access their funds, make payments, or manage their financial affairs.
  • Financial system impact: Services whose disruption could affect the stability or functioning of the broader financial system.
  • Regulatory obligations: Services required to meet regulatory reporting and compliance obligations.
  • Contractual obligations: Services subject to contractual service level commitments.

2.2 Examples of Critical Business Services

For different types of FIs, critical business services typically include:

Banks: - Deposit-taking and withdrawals - Payment processing (domestic and cross-border) - Lending and credit facilities - Treasury and market operations - Trade finance processing

Capital markets intermediaries: - Securities trading and execution - Clearing and settlement - Custody services - Client account management - Regulatory reporting

Insurers: - Claims processing and payment - Policy administration - Underwriting - Reinsurance operations - Premium collection

2.3 Service Mapping

For each critical business service, FIs should map:

  • People: Key roles and personnel required to deliver the service
  • Processes: End-to-end process flows and decision points
  • Technology: Applications, infrastructure, and data required
  • Facilities: Physical locations and workspaces
  • Third parties: External dependencies including service providers and counterparties
  • Information: Critical data and documentation required

3. Impact Tolerance

3.1 Setting Impact Tolerances

MAS expects FIs to set impact tolerances for their critical business services:

  • Definition: The maximum tolerable level of disruption to a critical business service, expressed in terms of duration, volume of transactions affected, or other relevant metrics.
  • Calibration: Impact tolerances should be set by the board or senior management, informed by the BIA and considering the needs of customers, counterparties, and the broader financial system.
  • Severe but plausible scenarios: Impact tolerances should be tested against severe but plausible disruption scenarios, not just the most likely scenarios.

3.2 Recovery Objectives

For each critical business service, FIs should define:

  • Recovery Time Objective (RTO): The maximum acceptable time to restore the service after a disruption.
  • Recovery Point Objective (RPO): The maximum acceptable data loss measured in time (how current must recovered data be).
  • Minimum Business Continuity Objective (MBCO): The minimum level of service that must be maintained during a disruption.
  • Maximum Tolerable Period of Disruption (MTPD): The absolute maximum time the service can be unavailable before unacceptable consequences occur.

3.3 Typical Recovery Objectives

Service Category RTO RPO
Payment systems 2-4 hours Near-zero
Trading systems 2 hours Near-zero
Customer-facing services 4-8 hours 1-4 hours
Regulatory reporting 24 hours 4-24 hours
Back-office processing 24-48 hours 24 hours
Support functions 48-72 hours 24 hours

4. Third-Party Dependency Management

4.1 Identification and Assessment

FIs must identify and assess third-party dependencies that could affect critical business services:

  • Critical third parties: Service providers whose disruption could impair the FI's ability to deliver critical business services.
  • Concentration risk: Assessment of reliance on single or small number of service providers for critical functions.
  • Substitutability: Evaluation of the FI's ability to switch to alternative providers in case of disruption.
  • Geographic risk: Consideration of geographic concentration in third-party service delivery locations.

4.2 Contractual Requirements

Contracts with critical service providers should include:

  • Defined service levels with measurable metrics
  • BCM and disaster recovery obligations of the service provider
  • Right to audit the service provider's BCM arrangements
  • Incident notification requirements and response timelines
  • Termination provisions and transition assistance
  • Data backup and recovery commitments
  • MAS access rights for examination purposes

4.3 Ongoing Monitoring

  • Regular assessment of service provider BCM capabilities
  • Participation in or review of service provider DR testing results
  • Monitoring of service provider financial health and operational stability
  • Review of service provider's own third-party dependencies (fourth-party risk)
  • Contingency plans for service provider failure or withdrawal

5. Business Continuity Plans

5.1 Plan Components

BCPs should address:

  • Activation criteria: Clear triggers for BCP activation based on incident severity
  • Command structure: Incident management team roles, responsibilities, and authority
  • Communication plan: Internal communication (staff), external communication (customers, regulators, media), and escalation procedures
  • Recovery procedures: Step-by-step procedures for restoring critical services
  • Alternate arrangements: Backup facilities, remote working capabilities, manual procedures
  • Resource requirements: Personnel, technology, and facilities needed for recovery
  • Stand-down procedures: Criteria and process for returning to normal operations

5.2 Pandemic Preparedness

Following the COVID-19 experience, MAS expects FIs to maintain pandemic-specific BCM capabilities:

  • Split-site operations to reduce single-point-of-failure risks
  • Remote working infrastructure and policies
  • Succession planning for key personnel
  • Health and safety protocols for essential workers
  • Communication strategies for extended disruptions

5.3 Cyber Resilience

BCPs should specifically address cyber incident scenarios:

  • Ransomware attack response and recovery
  • Data breach containment and notification
  • System compromise and forensic investigation
  • Customer communication during cyber incidents
  • Coordination with law enforcement and regulators
  • Offline or degraded-mode operations during system recovery

6. Testing and Exercises

6.1 Testing Requirements

MAS requires regular testing of BCM arrangements:

  • Frequency: At least annually for critical business services; more frequently for highest-priority services.
  • Scope: Testing should cover all critical business services over a rolling cycle.
  • Scenarios: Tests should use a range of scenarios, including severe but plausible disruptions.
  • Realism: Tests should be as realistic as practicable, including unannounced exercises.

6.2 Types of Testing

  • Tabletop exercises: Discussion-based exercises to review plans and decision-making processes.
  • Walkthrough tests: Step-by-step review of BCP procedures to verify accuracy and completeness.
  • Simulation exercises: Simulated disruption scenarios requiring activation of recovery procedures.
  • Full-scale DR tests: Actual failover to backup systems and facilities to verify recovery capabilities.
  • Third-party tests: Joint testing with critical service providers and counterparties.

6.3 Testing Outcomes

  • Document test results, including recovery times achieved versus objectives
  • Identify gaps and weaknesses in BCM arrangements
  • Track remediation actions with defined owners and timelines
  • Report test results to senior management and the board
  • Incorporate lessons learned into plan updates

7. Incident Management

7.1 Incident Response Framework

FIs should maintain an incident management framework:

  • Detection: Automated monitoring and alerting for operational disruptions
  • Assessment: Rapid assessment of incident severity and potential impact on critical business services
  • Escalation: Clear escalation paths based on incident severity
  • Response: Coordinated response actions including BCP activation if warranted
  • Communication: Timely communication to stakeholders (customers, staff, regulators, media)
  • Recovery: Restoration of services within defined recovery objectives
  • Review: Post-incident review and lessons learned

7.2 MAS Notification

FIs must notify MAS of significant operational disruptions:

  • Notification trigger: Disruptions that materially affect the FI's ability to deliver critical business services to customers or meet regulatory obligations.
  • Timeline: As soon as practicable, and no later than 1 hour from discovery.
  • Content: Nature of the disruption, services affected, estimated impact, and recovery actions underway.
  • Follow-up: Root cause analysis within 14 calendar days of the incident.

8. Operational Resilience -- Evolved Framework

8.1 From BCM to Operational Resilience

MAS's operational resilience framework represents an evolution beyond traditional BCM:

  • BCM focus: Recovery from specific disruptions to restore normal operations.
  • Operational resilience focus: Ability to prevent, adapt, respond to, recover from, and learn from disruptions to continue delivering critical business services within impact tolerances.

8.2 Key Differences

Aspect Traditional BCM Operational Resilience
Starting point Internal processes and systems Critical business services to customers
Scope Specific disruption scenarios All types of disruptions
Objective Recover to normal operations Maintain service within impact tolerances
Testing Plan verification Scenario testing against impact tolerances
Third parties Contractual obligations End-to-end service delivery view
Governance BCM committee Board-level risk appetite

8.3 Self-Assessment

MAS expects FIs to conduct periodic self-assessments of operational resilience:

  • Map critical business services and their dependencies
  • Set and validate impact tolerances
  • Identify vulnerabilities through scenario testing
  • Remediate identified gaps within defined timelines
  • Report self-assessment findings to the board
  • Develop a multi-year roadmap for operational resilience improvement

9. Cloud and Technology Resilience

9.1 Cloud Service Resilience

For FIs using cloud services for critical business services:

  • Multi-availability zone deployment for critical workloads
  • Multi-region or multi-cloud strategies for highest-priority services
  • Regular failover testing of cloud-based services
  • Data backup and recovery verification
  • Monitoring of cloud service provider service levels and incidents
  • Exit planning for cloud service provider migration

9.2 Technology Recovery

  • Documented disaster recovery procedures for all critical IT systems
  • Regular backup verification and restoration testing
  • Defined recovery architecture (hot standby, warm standby, cold standby)
  • Network resilience with redundant connectivity
  • Cyber recovery capabilities separate from primary disaster recovery

10. Regulatory Reporting and Compliance

10.1 Ongoing Obligations

FIs should maintain:

  • Up-to-date BCM documentation accessible to relevant staff
  • Annual review and update of BIA, BCPs, and impact tolerances
  • Regular reporting to the board on BCM and operational resilience posture
  • Evidence of testing, including test results and remediation tracking
  • Staff training and awareness records

10.2 MAS Examination

MAS may examine FIs' operational resilience through:

  • Thematic reviews across the industry
  • Individual institution inspections
  • Self-assessment requests
  • Stress testing exercises
  • Incident response reviews following actual disruptions

Compliance Relevance for Regnify

As a SaaS platform supporting compliance workflows, Regnify must address operational resilience considerations:

  • Service availability: Regnify is part of the compliance workflow for representative onboarding; downtime could delay MAS submissions and regulatory compliance.
  • Data resilience: Declaration data, approval workflows, and audit trails must be recoverable within defined RPO/RTO targets.
  • Third-party dependency: FIs using Regnify must include it in their third-party dependency mapping for critical business services.
  • Incident notification: Platform incidents affecting FI compliance operations may trigger MAS notification obligations for the FI.
  • Testing support: Regnify should support FI customers' BCM testing by providing availability and recovery SLAs and participating in customer DR exercises.
  • Cloud resilience: Kubernetes-based infrastructure should be deployed across multiple availability zones with automated failover capabilities.

Previous Next

Back to Technology & Cyber