Bank business continuity and supplier risk management system
The responsible team sees which systems and suppliers the banking services depend on. The results of the incidents and continuity tests help plan specific improvements.
The dependence of a business service on systems, suppliers and their common links is not tied to a realistically tested recovery. During the disruption, an unreasonably expected alternative or a restored technical system is supported by a running service.
How the solution works
- The team describes what action the customer must be able to perform even during a malfunction and how long the service disruption would be acceptable.
- Systems, data, teams and supplier links to the same service.
- The selected playback or output script is checked for its actual purpose.
- The test or incident provides the actual effect of the service and unresolved gaps.
- Designated personnel correct the deficiencies, and a retest shows whether the service is operating under the intended conditions.
Key challenges
- Risk of technological suppliers fragmented
Solution capabilities
Service dependencies
Provides a link between the business process, systems, data and significant supplier links.
Supplier, Contract and Obligations
The contractual service, the importance of the function, and the known common dependencies retain the responsibility of its renewal.
Continuity scenario
The intended alternative is checked against the availability of data and operations, employee capabilities, and actual load demand.
Service Recovery Test
Verifying the completion of a client action, matching stalled operations, and remaining constraint.
Output capability
The switching evaluates how the data will be transferred and the functions dependent on its services. The exit conditions provided for in the contract are checked together with the technical possibilities of relocation.
Closing the Gaps
The conclusion of the test or incident is linked to a responsible correction and requires re-checking.
Business context
- Risk of technological suppliers fragmented
- The dependence of a business service on systems, suppliers and their common links is not tied to a realistically tested recovery. During the disruption, an unreasonably expected alternative or a restored technical system is supported by a running service.
- Continuity of service is important to customer confidence
- For a business customer, bank disruption can interfere with the execution of payments or obtaining the necessary information. Clear vendor dependencies and verified recovery actions help the team prepare for such situations. It is important for the customer to receive confirmed information about the availability of the service and the required follow-up actions.
Core features
- Service dependencies
- Supplier, Contract and Obligations
- Continuity scenario
- Service Recovery Test
- Output capability
- Closing the Gaps
Key integrations
- Registers of technological services and assets
- Relevant function, system and data dependency.
- Contracts and supplier management
- Scope of service, important links and accepted contractual basis.
- The course of incidents and tests
- The impact of the incident, the result of the restoration of the service and the deficiencies eliminated.
- Change and Action Plan
- Designated repair and proof of re-checking.
Potential impact (%)
The ranges indicate an illustrative relative change in the metric under the stated assumptions. Results depend on the starting position and actual use of the solution. Percentages for different metrics must not be added together.
Work on determining the impact of an incident business
12–36%Decreasing
This illustrative scenario assumes that 30-60% of manual data entry and handover work can be addressed. That share is assumed to fall by 40-60%. Company data is needed to verify both the addressable workload and the resulting change.
Active exposure volume reconciliation for a similar incident scenario is measured.
Critical gaps not re-verified
2–12%Decreasing
This illustrative scenario assumes that the controls described can address 10-30% of discrepancies. That share is assumed to fall by 20-40%. Company data is needed to verify both the addressable share and the resulting change.
Significant deficiencies have been calculated, with a deadline for elimination, but their correction has not yet been confirmed by re-checking.
Conditional calculation scenarios. The assumptions have not been validated against client measurements.
When this solution is relevant
- The restoration of the service needs to be confirmed by the execution of customer operations, but the team only sees the technical state of the systems.
- Critical services depend on multiple suppliers and their overall infrastructure and replacement options are not clearly assessed.
Implementation requirements
The bank links important services to the technologies used and supplier commitments. Incident and supplier registers are supplemented with recovery procedures, responsible staff and inspection results to allow the team to assess readiness for the disruption.
Further development options
- Screening additional services and common upstream scenarios
- Review of Service Concentrations by Common Dependencies Actually Identified