Banks now required to come up with disaster preparedness plan

MANILA, Philippines - The Bangko Sentral ng Pilipinas (BSP) has issued the guidelines for the business continuity management (BCM) plan for banks and other financial institutions.

BSP officer-in-charge Ma. Almasara Cyd Tuaño-Amador said BSP-supervised financial institutions (BSFIs) are required to come up with a comprehensive business continuity management process as part of their operational risk management system.

“A well-designed BCM process enables BSFIs to resume critical operations swiftly and minimize operational, financial, legal, reputational   and other material risks arising from a disruption. This also helps mitigate systemic risks as well as maintain public trust and confidence in the financial system,” she said.

Banks and financial institutions could be adversely affected by disruption of critical operations due to internal and external threats that may be natural, manmade or technical in origin.

“Extreme events may cause major disruptions whose impact are very broad in scope, duration or both and can pose a substantial risk to the continued operation of BSFls,” Tuaño-Amador said.

Tuaño-Amador pointed out it is important to ensure that their operations of BSFIs should withstand major disruptions since they play a crucial role in the financial system and economy as a whole.

The BSP said the cyclical, process-oriented BCM framework of BSFIs should include business impact analysis and risk assessment; strategy formulation, plan development; plan testing; as well as personnel training and plan maintenance.

She explained pandemic planning, cyber resilience, information security, interdependencies, liquidity risk management, project management, event or problem management, outsourcing and insurance should be integrated into the BCM process.

The BSP said cyber-threats and attacks against the financial services industry have become increasingly widespread, sophisticated and coordinated.

It added recent cyber-attacks worldwide highlight, not only the degree of disruption to a BSFI’s operations but also the extent of reputational damage that could undermine public trust and confidence.

“As such, the BSFI should consider the potential impact of these cyber events into its BCM process and institute adequate cyber resilience capabilities. Given the unique characteristics of cyber-threats and attacks, traditional back-up and recovery arrangements adopted by the BSFI may no longer be sufficient and even increase the damage to the BSFIs’ network, operations and critical information assets,” the central bank said.

Show comments