2026-01-06 | BM 1225Added · Updated
This framework mandates that licensed domestic banks, finance and leasing companies, and their subsidiaries establish a comprehensive Business Continuity Management system covering governance, policy, strategy, and recovery planning. It requires the Board of Directors to approve the BCM policy and Tier-1 critical service impact tolerances, while senior management must define Service Recovery Time Objectives and maintain a dedicated BCM Committee meeting at least quarterly. The document further obligates entities to conduct regular Business Impact Analyses, integrate BCM into enterprise risk management, and perform annual testing and independent audits to ensure operational resilience against disruptions.
Get CBO alerts — same-day email on every new publication.
BUSINESS
CONTINUITY
MANAGEMENT
FRAMEWORK
(Annexure to Circular No BM – 1225, dated January 6, 2026)
Contents
Glossary of Terms.....................................................................................................................................4
Acronyms...................................................................................................................................................7
9.3 Frequency of Testing ...........................................................................................................38
10. Training and Awareness..........................................................................................................40
10.1 Training and Awareness Requirements..........................................................................40
11 Audit and Assurance...............................................................................................................41
11.1 Responsibilities of Internal Audit.......................................................................................41
12 Reporting.....................................................................................................................................42
12.1 Reporting and Disclosures .................................................................................................42
13 Annexures...................................................................................................................................43
Annexure – 1: Initial Incident Report ............................................................................................43
Annexure – 2: Comprehensive Incident Report.......................................................................45
Annexure – 3: Test Report BCM.....................................................................................................47
Glossary of Terms
Terminology Definitions
Alternate Site A site held in readiness for use during a business continuity event to maintain an organisation’s business continuity. The term applies equally to work space or technology requirements. Organisations may have more than one alternate site. In some cases, an alternate site may involve facilities that are used for normal day-to-day operations but which are able to accommodate additional business functions when a primary location becomes inoperable. Business Continuity Management Business continuity management is a whole-of-business approach that includes policies, standards, and procedures for ensuring that specified operations can be maintained or recovered in a timely fashion in the event of a disruption. Its purpose is to minimise the operational, financial, legal, reputational and other material consequences arising from a disruption. Business Continuity Plan (BCP) A business continuity plan is a comprehensive written plan of action that sets out the procedures and establishes the processes and systems necessary to continue or restore the operation of an organisation in the event of a disruption. Business continuity plans establish the roles and allocate responsibilities for managing operational disruptions and provide clear guidance regarding the succession of authority in the event of a disruption that disables key personnel. They also clearly set out the decision-making authority and define the triggers for invoking the organisation’s business continuity plan. Business Impact Analysis Business impact analysis is the process of measuring (quantitatively and qualitatively) the business impact or loss of business processes in the event of a disruption. It is a dynamic process for identifying critical operations and services, key internal and external dependencies and appropriate resilience levels. It is used to identify
recovery priorities, recovery resource requirements, and essential staff and to help shape a business continuity plan. Critical business services Critical business services are activities whose disruption would cause intolerable harm to customers or threaten financial stability or whose disruption would significantly affect the operation of the organization or the broader financial system. For example, data center operations, large-value payment processing, transaction clearing, and settlement, as well as supporting systems like funding and reconciliation services, are typically considered critical. Dependency Mapping A process to identify and understand the internal and external dependencies on people, processes, technology, and other resources (including those involving third parties) for each critical business service. IT Disaster Recovery IT Disaster recovery (IT DR) is part of BCM which includes policies, standards, procedures and processes pertaining to resilience, recovery or continuation of technology infrastructure supporting critical business processes. Maximum Acceptable Outage (MAO) Maximum Acceptable Outage (MAO) is defined as the time that would take for adverse impacts which might arise because of not providing a product/service or performing an activity, to become unacceptable. Recovery Level Recovery level is the target level of service that will be provided in respect of a specific business operation after a disruption. Recovery Strategy A recovery strategy sets out recovery objectives and priorities that are based on the business impact analysis. Among other things, it establishes targets for the level of service the organisation would seek to deliver in the event of a disruption and the framework for ultimately resuming business operations.
Recovery Time Recovery time is the target duration of time to recover a specific business operation. A recovery time has two components: the duration of time from the disruption to the activation of a business continuity plan; and, the duration of time from the activation of the business continuity plan to the recovery of the specific business operation. Recovery Time Objective Recovery Time Objective (RTO) is defined as the period following an incident (time incident occurred/point of disruption) within which, products or services must be resumed, activity must be resumed, or resources must be recovered. Red-Team Exercise A controlled, intelligence-led simulation of sophisticated cyberattacks conducted by authorized testers to assess the institution’s ability to detect, respond to, and recover from real-world threats, in accordance with recognized standards. Service Recovery Time Objective (SRTO) Target duration of time to restore a specific business service from the point of disruption to the point when the specific business service is recovered to a level sufficient to meet business obligations.
Acronyms
1 Banks Banks licensed by the Central Bank of Oman 2 BCM Business Continuity Management 3 BCP Business Continuity Plans 4 BCRPs Business Continuity and Recovery Plans 5 BIA Business Impact Analysis 6 CBO Central Bank of Oman 7 CBS Critical Business Services (CBS) 8 CFSBS Chief Financial Stability & Banks Supervision 9 CMP Crisis Management Plan 10 CMT Crisis Management Team 11 CRP Cyber Resilience Plan 12 DR Disaster Recovery 13 DRP Disaster Recovery Plan 14 ERM Enterprise-wide Risk Management 15 ICT Information and Communication technologies 16 FLCs Finance and Leasing Companies licensed by the Central Bank of Oman 17 RPO Recovery Point Objectives 18 RTO Recovery Time Objective 19 SD Surveillance Department 20 SRTO Service Recovery Time Objective 21 TLPT Threat-Led Penetration Testing
Introduction
1.1. Operational disruptions present numerous challenges due to pandemic,
rapid technological advancements and a more hostile cyber landscape. The situation becomes even more complicated when banks operate across borders or depend heavily on third-party service providers. Although banks and FLCs may take extensive measures to enhance operational resilience, disruptions are still possible, often due to factors beyond their control. As such, an effective Business Continuity Management (BCM) framework is essential to minimize the impact of such disruptions and ensuring the continuity of financial services.
1.2. The BCM framework comprise of following seven interrelated components,
arranged in a hierarchical sequence:
1.2.1. Governance & Oversight
1.2.2. BCM Policy
1.2.3. BCM Strategy
1.2.4. Business Impact Analysis (BIA) and Scenario Assessment
1.2.5. Plans (BCP, Recovery Plans, IT-DRP, Cyber Resilience, Crisis Management)
1.2.6. Testing, Exercising and Validation
1.2.7. Monitoring, Reporting and Continuous Improvement
Applicability of the Framework
2.1 This framework is applicable to all licensed domestic banks and FLCs
including their subsidiaries, foreign branches and representative offices.
2.2 Licensed foreign banks and their overseas entities who provide the services
to the foreign branches operating in the Sultanate of Oman.
2.3 The requirements under the framework extend to all activities of the bank
and FLCs, whether performed internally or delivered through outsourcing and third-party arrangements.
2.4 Banks and FLCs should ensure that the contractual provisions and
governance arrangements with service providers are adequate to comply with the requirements stipulated in the framework.
Scope
BCM framework covers the entire lifecycle of BCM, from initiation and implementation to maintenance, monitoring, and improvement. The BCM framework provide principles and best practices to help banks and FLCs establish, implement, maintain, monitor, and continuously improve their BCM frameworks. Ultimately, Banks and FLCs bear the responsibility for ensuring their preparedness for business continuity and for effectively recovering from operational disruptions. To this end, banks and FLCs should develop and implement policies, plans, and procedures that enable the rapid restoration of critical services and functions following any disruption.
3.1 BCM and Its Purpose
3.1.1 BCM framework is an enterprise-wide approach designed to ensure that
critical business processes can continue or be quickly restored in the event of significant internal or external operational disruptions. One of its primary objectives is to minimize the financial, legal, and reputational consequences of such disruptions.
3.1.2 The extent and degree to which a Bank and FLCs implements the BCM
framework should be commensurate with the nature, size, risk profile and complexity of its business operations. Banks and FLCs shall adapt the framework as necessary, taking into consideration the diverse activities they engage in, and the different markets in which they operate and conduct transactions.
3.1.3 The Basel Committee on Banking Supervision's Joint Forum published seven
high-level Principles for BCM in August 2006, which remain relevant even today. Banks are encouraged to refer to these principles when developing and refining their own BCM frameworks.
BCM Governance Principle
As outlined in Principle 1 of the High-Level Principles for Business Continuity published by the Basel Committee on Banking Supervision, the board of directors and senior management of a Banks are ultimately accountable for the organization’s business continuity. In particular, senior management, with the approval of the board of directors, defines the relationship between themselves and the crisis management structure (BCM Committee). Additionally, the board and senior management must recognize that outsourcing business operations does not transfer the responsibility for business continuity. The responsibility remains with the Bank and FLCs, regardless of outsourcing arrangements.
4.1 Key governance elements
4.1.1 Accountability for Risk Management: The board of directors and senior
management are responsible for identifying, assessing, prioritizing, managing, and controlling all risks related to business continuity.
4.1.2 Approval and Oversight of the BCM Framework: The BCM framework should
be defined, approved, implemented, and maintained, with final approval from the board of directors and ongoing monitoring by senior management.
4.1.3 Policy and Plans Development: Senior management is responsible to
develop policies, plans, procedures and processes for business continuity. Policies must be approved by the board of directors while plans, procedures and processes must be approved by the senior management for locally incorporated Banks and FLCs or by the head office for branches of foreign Banks.
4.1.4 Sufficient Budget Allocation: The board of directors should ensure that an
adequate budget is allocated to support all necessary BCM activities.
4.1.5 Communication and Structure: The business continuity structure including
Committee must be clearly defined and communicated to all relevant employees and third parties. BCM Committee, mandated by the board of directors, should be established.
4.1.6 Establishment of BCM Committee and its composition: A senior
management committee should be established and should have
representations from Business, Risk, Compliance, Information Technology, Information Security, Operations, BCM Manager, and other relevant departments.
4.1.7 BCM Committee Charter: A BCM Committee charter should be developed,
outlining the following:
i. Committee objectives.
ii. Roles and responsibilities.
iii. Minimum participant numbers.
iv. Meeting frequency (at least quarterly).
v. Documentation of meeting minutes for audit purposes.
4.1.8 BCM Manager Appointment: A BCM Manager/Head should be appointed
who has:
i. Sufficient authority to oversee and manage the BCM program.
ii. The necessary qualifications, experience, skills, and competencies to
implement and maintain the BCM program within the organization.
4.1.9 Adequate Staffing: The BCM function should be adequately staffed with
qualified team members to effectively manage the BCM program.
4.1.10 Integration with Enterprise-wide Risk Management (ERM): The BCM
framework should form an integral part of the bank’s and FLC’s overall ERM system, to ensure that BCM is not treated as a stand-alone activity but as a core component of the bank’s and FLC’s risk management and strategic decision-making. The key methodologies include the following:
i. Continuity risks should be identified, assessed, and monitored
alongside other operational risks in the risk register, with clearly assigned ownership.
ii. Material disruption scenarios should be included in the bank’s and
FLC’s risk appetite framework, stress testing, and capital and liquidity planning processes.
iii. Key continuity indicators and test results should be reported through
the same governance and risk-reporting channels that serve the board’s risk oversight function.
4.1.11 Cross-Functional Collaboration: Cross-functional teams, including strategic,
tactical, and operational members, should contribute to the implementation and maintenance of business continuity and disaster recovery plans. By following these principles, Banks and FLCs can ensure strong governance over their business continuity efforts, fostering resilience across the organization.
e. Provisions for training, awareness, and testing. f. Requirements for third-party participation. g. Document control, review, and approval procedures.
5.1.3 The minimum requirements under Governance Structure and Framework
for Impact tolerances are as under:
i. Governance Structure and roles: Effective governance of the business
continuity policy requires:
a. Regular Review and Approval: The policy shall be reviewed and approved periodically (at least once in three years) by the Board of Directors. b. Senior Management and Leadership Involvement: Senior management and business unit leaders must be actively involved in the implementation, oversight and monitoring of compliance of the BCM policy as well as annual assessment of effectiveness of implementation of BCM Policy.
c. Commitment from the First and Second Lines of Defense: The first and
second lines of defense should be committed to the design and execution of the business continuity policy. d. Independent Review by the Third Line of Defense: The third line of defense shall conduct independent evaluations of the business continuity policy’s implementation and effectiveness.
ii. Framework for setting Impact Tolerances and SRTO/RTO/RPO:
a. The BCM Policy shall stipulate the process for identifying important/critical business in a tiered approach, and defining ‘Impact Tolerances’ for such businesses in alignment with the risk appetite of the bank and FLC. b. The Board should approve at least the Tier -1 services and the ‘impact tolerances’ for such services, leaving the rest to be determined by senior management.
c. The Policy shall require the senior management to determine,
maintain and periodically review:
6.4.4 Reporting, Communication, and Training: Define clear reporting structures,
communication protocols, and training requirements to ensure effective implementation and awareness of the BCM strategy.
6.4.5 Contents of BCM Strategy: The BCM Strategy, at a minimum, shall include
the following:
i. Impact-Tolerance-Driven Design
a. Licensed Banks and FLCs shall define impact tolerances for critical businesses, stating the maximum acceptable level of disruption in measurable terms (time, volume, customer detriment). b. Recovery and resilience capabilities shall be engineered around these tolerances, not merely around RTO/RPO metrics.
c. The Strategy shall demonstrate that design of technology, staffing,
intra-group and third-party arrangements collectively maintain operations within these tolerances.
ii. Continuity Architecture
a. The Bank and FLCs shall implement a multi-layered continuity architecture, selecting recovery models consistent with impact tolerances. b. Redundancy shall be embedded at all layers of network, power, data, and personnel.
c. Single points of failure shall be identified, documented, and
eliminated through design remediation. d. The Bank and FLCs shall adopt resilience-by-design principles, ensuring new systems undergo resilience impact assessments prior to production release.
iii. Cyber and ICT Resilience Integration
a. The BCM Strategy shall incorporate ICT continuity measures consistent with international standards and the requirements under CBO Cybersecurity & Resilience Framework issued vide BM – 1194.
b. Banks and FLCs shall maintain appropriate backups (“cyber vaults”) for critical data and test data-integrity validation after recovery.
c. Critical systems shall undergo Threat-Led Penetration Testing (TLPT) or
equivalent red-team exercises at least once every three years. d. Results of TLPT shall inform refinement of recovery architecture and incident-response procedures.
iv. Testing and Validation of the Strategy
a. The effectiveness of the BCM Strategy shall be verified through integrated testing (business, IT, third-party service providers). b. Gaps identified during tests shall be addressed within agreed remediation timelines and re-tested for closure.
c. Independent validation by internal audit shall occur at least once
every three years.
as well as supporting systems like funding and reconciliation services, are typically considered critical.
ii. The Banks and FLCs shall maintain CBS Register recording for each
service:
a. Service description and responsible owner; b. Customer segments and volumes served;
c. Identification of both internal and external interdependencies
(systems, intra-group entities, third-party service providers, facilities, data, people); d. Applicable impact tolerance; and e. Criticality rating (high/medium/low).
iii. The CBS Register shall be reviewed semi-annually.
7.1.3 Dependency Mapping
i. The Bank and FLC shall create end-to-end dependency maps for each
CBS, identifying all supporting assets and interconnections.
ii. Maps shall include data-flows, upstream and downstream
dependencies, and cross-border linkages.
iii. Technology tools such as service-mapping software may be used for
accuracy and auditability.
iv. Dependencies shall be validated during testing to ensure completeness.
7.1.4 Impact Dimensions
i. BIAs shall measure potential impact across multiple dimensions on each
CBS:
a. Customer harm or financial loss; b. Regulatory or legal breach;
c. Market or payment-system disruption;
d. Reputational damage; and
e. Safety or operational-integrity risk.
ii. Quantitative thresholds shall be established where possible (e.g.,
transaction volumes delayed, customers affected).
7.1.5 Impact Tolerance and RTO/ RPO
i. For each CBS, the Bank and FLC shall specify:
a. Impact Tolerance – maximum tolerable disruption; b. RTO – target restoration time;
c. RPO – maximum data-loss period; and
d. Resource requirements to meet these objectives.
ii. Tolerances shall be approved by the board/ senior management, as the
case may be, and linked to the Bank’s and FLC’s risk appetite.
iii. Where tolerances are breached during testing or incidents, corrective
measures shall be initiated immediately and recorded.
7.1.6 Third-party service providers and Supplier Capability Assessment Banks
and FLCs must assess the capability of third-party service providers, suppliers, and service providers to maintain service levels during a disruption, especially for CBS.
7.2 Scenario Assessment
7.2.1 The Bank and FLC shall design and maintain a catalogue of severe-butplausible scenarios derived from threat assessment and historical data.
These scenarios should be assessed quantitatively and qualitatively for financial, operational, legal, and reputational impacts.
7.2.2 Scenarios shall include single-event and multi-event combinations such as:
i. Data-center outage coinciding with cyberattack;
ii. Regional natural disaster affecting multiple branches;
iii. Critical third-party service providers insolvency;
iv. Widespread telecom failure; or
v. Systemic liquidity crisis with concurrent operational disruption.
7.2.3 Each scenario shall specify trigger points, escalation paths, and expected
recovery performance against tolerances.
7.2.4 Scenario outcomes shall be documented and incorporated into BCM
Strategy reviews.
7.2.5 Use of Data and Analytical Tools
i. Banks and FLCs are encouraged to use quantitative modelling,
simulation, and scenario-analytics platforms to enhance accuracy of impact estimation.
ii. Sensitivity analysis shall be performed to evaluate effects of prolonged
or cascading events.
iii. Data from incidents, near-misses, and industry stress exercises shall be
incorporated into scenario design.
7.3 BIA Updates and Review:
The BIA should be reviewed and updated as follows:
7.3.1 Annually by all Banks and FLCs to ensure ongoing relevance.
7.3.2 Post-major Disruptions within three months of any major operational
disruption.
7.3.3 When Major Changes Occur (within three months), including changes to
organizational structure, people, processes, technology, suppliers, locations or regulatory requirements.
7.4 Recovery Strategy and Objectives
7.4.1 A recovery strategy outlines the recovery objectives and priorities that are
derived from the BIA. It sets clear targets for the level of service; an organization aims to maintain during a disruption and provides a structured framework for resuming business operations as quickly as possible. The purpose of the recovery strategy is to ensure that recovery efforts are executed in a systematic and predefined manner, minimizing disruption and financial loss.
7.4.2 When establishing recovery strategies, Banks and FLCs should take an endto-end view of the critical business services and their dependencies. This
means considering not only the recovery of individual processes but also the complete set of interconnected processes that support the delivery of each service. This holistic approach minimizes the impact of disruptions, safeguards customer interests, and preserves the safety and soundness of the Bank and FLC.
7.4.3 Recovery Objectives
i. Recovery objectives are predefined goals for restoring CBS to a
specified level of service (recovery level) within a defined period (recovery time) after a disruption. In alignment with Principle 3 of the High-Level Principles for Business Continuity published by the Basel Committee on Banking Supervision, Banks should set recovery objectives that are proportionate to the risk posed by the disruption to the operation of the financial system.
ii. While the senior management hold ultimate accountability for recovery
objectives, these objectives are often developed by, or in consultation with, business line management, particularly at the level of individual business functions.
iii. Banks and FLCs must identify and document appropriate recovery
objectives and strategies based on the results of the BIA and lessons learnt from the previous incidents, considering the risk profile, nature, size, and complexity of the institution’s business and structure.
7.4.4 Recovery Objectives for Critical Resources
As a minimum, the following business recovery options must be defined to address the loss of the following critical resources:
i. Staff
ii. Buildings
iii. IT Systems and Infrastructure (including Payment and Settlement
systems as well as communications systems)
iv. External Service Providers, intra group entities and suppliers (including
outsourcing partners and information providers)
The recovery objectives should be formally documented and cover the recovery options for these critical resources. These objectives should be updated regularly to ensure their relevance.
7.4.5 Minimum Operational Resources: Determining the minimal resources
required to achieve the desired recovery level, including personnel, IT/data, buildings, and external service providers.
7.4.6 Prioritization of Recovery Efforts
Banks and FLCs must prioritize recovery efforts based on the criticality of each service and function, determining recovery strategies and resource allocation accordingly.
7.4.7 Frequency of Updates
Recovery objectives should be reviewed and updated:
i. Annually by all Banks and FLCs.
ii. Post-Major Operational Disruptions, within three months of the event.
from disruptive events while maintaining service delivery and meeting client expectations, even under constrained conditions.
8.4.2 The BCP outlines the institution's critical functions, identifies the systems and
processes that need to be maintained, and details the strategies required to ensure continuity. The plan provides actionable steps for recovery and highlights the importance of staff safety as the foremost consideration during any disruption.
8.4.3 Key Components of Business Continuity Plan
i. Critical Resources: The BCP should identify critical resources, including
people, technology, processes, data, equipment, facilities, and their interconnections and interdependencies that support the Bank’s and FLC’s critical services essential for business continuity.
ii. People Resources: It shall include:
a) Details of key individuals in DR site and remote access support. b) Coordinator details (Assigned to operationalize the recovery site) c) Details about Salvage team (Tasked with restoring the primary site to full operational capacity)
iii. Roles and Responsibilities: The BCP must allocate roles and
responsibilities for managing operational disruptions, establishing clear guidance on the succession of authority when key personnel become unavailable.
iv. Decision-Making Authority: The plan should clearly define decisionmaking authority and outline triggers for activating the BCP.
v. Activation Criteria: The BCP should include criteria for activation in the
event of partial disruption to critical business services, ensuring timely and decisive action before the situation worsens.
vi. Recovery Objectives: A clear process for maintaining critical activities
within predefined recovery objectives (e.g., Recovery Time Objectives [RTO], Recovery Point Objectives [RPO], and Maximum Acceptable Outage [MAO]) should be incorporated.
vii. Business-as-Usual Resumption: The BCP should outline a process for
returning to normal operations once the disruption has been resolved. viii.Consideration of Pandemic and Extended Disruptions: While BCPs were traditionally focused on short-term disruptions, such as those lasting a few hours to a week, the COVID-19 pandemic highlighted the need for plans addressing longer-term disruptions. Banks and FLCs should consider multiple time frames for BCPs, such as immediate, short-term, medium-term, and long-term scenarios (ranging from hours to more than six months). Furthermore, Banks and FLCs should account for new risks introduced by alternative work arrangements, technological challenges with remote work, and increased cybersecurity threats during extended disruptions.
ix. Contingency Planning for Third Party Service Providers: Banks and FLCs
should develop comprehensive contingency plans, including exit strategies, to maintain resilience in the event of disruptions at third-party service providers. This includes considering alternatives such as substituting third-party services (e.g., data centers, telecom providers) or bringing services back in-house.
x. Legal Considerations for Third-Party Agreements: Given the disruptions
experienced during the pandemic, Banks and FLCs should formalize agreements with third-party providers to ensure continued provision of critical services during operational interruptions. These agreements should guarantee operational resilience, regardless of the duration of a disruption. Legal agreements should be comprehensive covering all aspects to ensure continued provision of critical services and shall include minimum the following:
a) Clear allocation of responsibilities between the Banks/ FLCs and the third-party service providers to ensure continued provision of critical services during operational interruptions. b) Bank’s and FLC’s right to inspect third-party service providers BCM framework and assess their effectiveness during the test exercise of BCPs. c) CBO’s access directly or via Bank and FLC to inspect the third-party service providers BCM framework.
8.5 IT Disaster Recovery Plan (DRP)
8.5.1 Banks and FLCs must ensure their IT infrastructure remains resilient and
capable of recovering from disruptions while maintaining the security and integrity of their critical operations. Banks and FLCs must define, approve, implement, and maintain an IT Disaster Recovery Plan (DRP) for their critical activities and related technology infrastructure. The IT DRP should cover the following key areas:
i. Recovery and Restoration of Technology Services: IT DRP should
clearly define, approve, implement, and maintain procedures to recover and restore critical technology services and infrastructure components, including data, systems, networks, services, and applications. These procedures should align with the BIA.
ii. Cyber Attack Resilience and Business Continuity: The DRP should be
designed to enable rapid recovery from cyberattacks and ensure safe restoration of business operations while safeguarding security processes, data, and information. Banks and FLCs shall refer to the CBO Cybersecurity & Resilience Framework issued vide BM 1194 for comprehensive guidance on cybersecurity and resilience matters, including reporting requirements to the CBO.
iii. Alternative Data Center: Banks and FLCs must establish an alternative
data center at a geographically distinct location that mitigates the risks faced by the primary data center (e.g., geographical threats) with following features:
a) The alternative data center should commensurate with the configurations and capacities of the primary data center, ensuring that the systems, networks, applications, and data can be fully supported in the event of a disaster. b) The same logical, physical, environmental, and cybersecurity controls implemented in the primary data center should also be applied to the alternative data center.
iv. Backup and Recovery Process: Banks and FLCs must define and
implement a robust backup and recovery process to ensure the integrity and availability of critical data and systems during a disaster.
v. Disaster Recovery Testing: Disaster recovery tests must be conducted
at least annually to validate the effectiveness of the DRP and its arrangements.
vi. Ongoing Evaluation and Updates: The effectiveness of the IT DRP
should be measured, reviewed, and updated at least once a year to ensure it remains relevant and effective.
8.6 Cyber Resilience
8.6.1 The malicious use of information and communication technologies (ICT)
poses a significant risk to financial services that are crucial to both national and international financial systems. Such threats can undermine security, erode public confidence, and jeopardize financial stability. As Banks and FLCs increasingly rely on technology, automation, and integration with third-party providers and customers, their attack surface continues to expand. This broader exposure invites cyber-adversaries to enhance their capabilities, making it essential for Banks and FLCs to strengthen their cyber resilience.
8.6.2 With the growing reliance on third-party providers, particularly in cloud
services and shared service models, the perimeter of interest for financial regulators has widened. These developments necessitate a new approach for Banks and FLCs to build and maintain robust cyber resilience, particularly in collaboration with third parties.
8.6.3 The Impact of Pandemic and Emerging Cyber Risks
i. The COVID-19 pandemic has introduced new challenges and risks that
can affect Banks and FLCs rapidly and extensively. The shift to remote work, reliance on digital services, and increased cyber threats such as ransomware attacks and phishing have amplified operational risks. These disruptions have affected various aspects of operations, including data, systems, personnel, facilities, and relationships with external service providers.
ii. The pandemic has also heightened concerns about the operational
risks associated with remote work. It is crucial for Banks and FLCs to assess whether emerging risks can be effectively managed and whether they have procedures in place to identify, analyze, and mitigate these risks as their work models evolve. Banks and FLCs need
to consider how these risks impact their overall risk profiles, particularly in a hybrid working environment.
8.6.4 Ensuring Resilient IT Infrastructure
i. The reliability and security of IT services are vital to ensure that operations
can continue remotely, particularly during widespread disruptions like the pandemic. As hybrid working arrangements become more common, maintaining strong cybersecurity and protecting against threats like cyber-attacks and data breaches is critical. Banks and FLCs must continually monitor and enhance their IT infrastructure to defend against cyber risks and ensure the continuity of critical operations.
ii. The challenges faced during a pandemic may be compounded by
other disruptive events, such as natural disasters, cyber-attacks, and terrorism. The likelihood of simultaneous disruptive events increases over time, and certain risks such as power outages, key personnel unavailability, or cyber-attacks may be more likely due to circumstances brought about by the pandemic. This makes it essential for Banks and FLCs to design flexible BCP that account not only for individual risks but also for the potential combination of multiple threats occurring simultaneously.
8.6.5 Cyber Resilience Programs
i. Banks and FLCs should implement comprehensive cyber resilience
programs that cover protection, detection, response, and recovery. These programs should be regularly tested to ensure they remain effective in mitigating risks and responding to disruptions. Additionally, Banks and FLCs must maintain situational awareness and provide relevant, timely information to support risk management and decisionmaking processes, enabling the continued delivery of critical operations.
ii. All infrastructure and software changes that support critical services,
business functions, and processes must undergo thorough risk assessments to ensure they meet the institution’s requirements for availability and recovery. This ensures that Banks and FLCs can maintain operational continuity in the face of cyber threats and other disruptions.
8.6.6 Compliance with Cybersecurity & Resilience Framework:
Banks and FLCs shall refer to the CBO Cybersecurity & Resilience Framework (BM – 1194) for comprehensive guidance on cybersecurity and resilience matters, including reporting requirements to the CBO. This framework provides essential standards for managing and enhancing cyber resilience in Banks and FLCs, ensuring they are prepared for evolving cyber threats and operational challenges.
8.7 Communication
8.7.1 Effective communication is crucial in crisis management during major
operational disruptions. Banks and FLCs must devote special attention to developing comprehensive communication plans that cover both internal and external communication during operational disruptions. The ability to communicate clearly and efficiently with both internal teams and external stakeholders during major operational disruptions is vital to an institution's ability to respond, recover, and maintain public confidence.
8.7.2 Banks and FLCs should incorporate clear procedures and methods for
communication within their organization and with relevant external parties as part of their BCP. These procedures should ensure that all parties involved are kept informed of the situation and can make well-informed decisions to support the recovery process.
8.7.3 Key Considerations for Communication:
i. Timely and Effective Communication: Early communication is critical to
assess the impact of a disruption on both internal operations and the broader financial system. It is essential to quickly determine the severity of the disruption and decide whether to activate the BCP. As the crisis progresses, providing timely and accurate information to stakeholders is key to the recovery process and helps restore normal operations across the financial system.
ii. Maintaining Public Confidence: Clear, consistent communication
throughout the duration of a major operational disruption is necessary to maintain public confidence in the Bank and FLC and the broader financial system. Regular updates help ensure transparency and support effective decision-making. However, Banks and FLCs shall seek prior permission from CBO when communicating with the media in case of major operational disruption.
iii. Lines of Reporting and Succession: Each key function should have
clearly defined reporting lines and succession plans, particularly for key managerial and operational staff. Up-to-date contact lists for all critical personnel, including crisis management team members, authorities, and infrastructure providers, should be readily available at both primary and backup locations. The lists should also include details of all internal and external stakeholders who need to be notified immediately when a critical business service is disrupted.
iv. Communication Channels and Alternatives: A communication plan
should identify the primary communication channels, including mainstream and social media, and outline procedures for alternative channels in the event that primary channels are unavailable. Banks and FLCs must be prepared to effectively communicate with external parties (e.g., regulators, service providers) and within their organization, using predefined channels and protocols.
v. Emergency Communication Protocols: Banks and FLCs should
establish emergency communication procedures and designate individuals or teams responsible for communication with staff and external stakeholders. This group may include senior management, public relations staff, legal and compliance advisors, and business continuity coordinators. This communication team should be capable of reaching personnel located at remote sites, across multiple locations, or working off-site.
vi. Contingency-Based Communication Plans: Banks and FLCs should
consider specific communication plans based on the use of tools like call trees or mass notification systems. These plans should be supported by technological tools that enable rapid communication with staff during a disruption. Satellite communication equipment may be provided to key personnel responsible for managing operational continuity, ensuring they can communicate even in the event of widespread infrastructure failure.
vii. Lessons Learnt from Pandemic and other High-Impact Scenarios: The
COVID-19 pandemic has reinforced the importance of adaptable and effective communication strategies during crisis events. Banks and FLCs should review and improve their communication frameworks to address high-impact scenarios, such as cyber-attacks (often arising from remote work), natural disasters like earthquakes, and other crises.
These strategies should include identifying target audiences, determining the appropriate types of messages, and selecting best communication channels for each situation.
8.8 Cross border Communication
8.8.1 Banks should establish communication procedures that specifically address
interactions with financial authorities in other jurisdictions during major operational disruptions with cross-border implications.
8.8.2 As Banks become more interconnected across global markets, the impact
of a significant operational disruption is likely to extend beyond national borders. Managing disruptions that affect multiple jurisdictions introduces additional complexity, which requires careful planning and coordination. While domestic communication procedures are generally well-defined within Bank's BCP, disruptions with international reach demand additional focus and preparation.
8.8.3 Banks should recognize the possibility that a disruption in one jurisdiction
could affect the operations of significant subsidiaries, branches, or otherwise impact the broader financial system in other regions. In such cases, Banks must ensure that their communication protocols include clear guidelines for when and how to contact relevant financial authorities in other jurisdictions.
8.8.4 These communication protocols should:
i. Identify the specific circumstances under which cross-border
communication is necessary.
ii. Establish predefined contact points with financial authorities,
regulators, and other stakeholders in affected jurisdictions.
iii. Ensure that communication is timely, accurate, and consistent across
all jurisdictions to mitigate the potential impact on the financial system and maintain regulatory compliance.
8.9 Crisis Management Plan (CMP)
8.9.1 The CMP shall describe governance and command structure during major
disruptions.
8.9.2 A Crisis Management Team (CMT) shall be chaired by a senior executive
empowered to make binding decisions.
8.9.3 The CMP shall specify:
i. Activation criteria and escalation process;
ii. Roles and responsibilities within the CMT;
iii. Decision-rights hierarchy and delegation of authority;
iv. Media, customer, and regulator communication protocols; and
v. Stakeholder coordination with government and market infrastructure
entities
8.9.4 Banks and FLCs shall maintain pre-approved communication templates
and ensure 24/7 contact accessibility for CMT members.
8.9.5 The CMP shall be tested through simulation exercises and updated based
on lessons learned.
8.9.6 The CMP shall manage all incidents impacting the Bank and FLC, including
those attributable to dependencies on, but not limited to, third parties and intragroup entities.
8.10 Integration and Linkages
8.10.1 The BCP, DRP, CRP, and CMP shall be integrated into a single Business
Continuity Framework with consistent governance, version control, and escalation triggers.
8.10.2 Interdependencies among the plans shall be mapped and periodically
validated during testing.
8.10.3 Documentation shall clearly state linkages to the BCM Policy and
Strategy.
8.11 Updates, Review and Approval Process:
8.11.1 Annual Review: Banks and FLCs should review and update their BCP
annually to ensure its relevance and effectiveness.
8.11.2 Post-Disruption Review: The plan should be reviewed and updated within
three months following any major operational disruption.
8.11.3 Plans shall be approved by Senior Management and acknowledged by
functional heads.
8.11.4 Material revisions shall be communicated to the Board’s Risk Committee
and the Central Bank upon request.
8.11.5 Compliance Monitoring: Regular monitoring of compliance with all the
plans are essential. BCM Manger shall ensure that critical service providers, including third parties, have plans in place and tested on yearly basis.
vii. Integrated BCM Testing: Banks and FLCs should conduct an integrated
BCP test that covers all critical services, business processes, and functions to assess the overall coordination and effectiveness of the BCM framework.
9.2 Reporting and Documentation of Test Results
9.2.1 All test results should be reported to the BCM committee, senior
management, and the board of directors. These results will help identify areas for improvement within the BCP and the broader BCM framework. An independent party, such as internal audit, should assess the testing process, review results, and report findings to senior management and the board. Any identified gaps or shortcomings must be addressed timely with comprehensive action plan.
9.2.2 Detailed documentation of all exercises and tests should be maintained for
audit purposes, and the results should include:
i. Confirmation of whether the objectives of the test were met.
ii. Confirmation of the capabilities and readiness of recovery
resources.
iii. Documentation of lessons learned and areas requiring
improvement.
iv. In the case of failure, identification of the root cause and the
tracking of remediation actions to resolution. Re-testing should be conducted within three months after failure.
9.3 Frequency of Testing
9.3.1 Testing should be conducted at least once per year, or within three months
after the Bank and FLC resuming normal operations following invocation of the BCP due to a major operational disruption. Detailed test reports related to business continuity and disaster recovery should be submitted to Surveillance Department (SD) - CBO within six weeks after the test. Based on the test results, Banks and FLCs should develop an improvement action plan, which must be approved by senior management. The action plan should be submitted to SD – CBO within three months of the test result submission.
9.3.2 Banks and FLCs should consider a risk-based approach to build up capacity
to conduct test exercises and DR drills during business hours on working
days. Banks and FLCs shall communicate to relevant stakeholders related to the date and timings of the test exercise. By following these testing protocols, Banks and FLCs can ensure their BCPs are robust, effective, and capable of responding to a wide range of disruptions, ensuring operational resilience and continuity.
11 Audit and Assurance
11.1 Responsibilities of Internal Audit
11.1.1 Bank’s and FLC’s BCM framework should be subject to review by an
independent party, such as internal or external audit, and significant findings should be reported to the board and senior management on a timely basis.
11.1.2 Conducting a BCM audit is a crucial method for providing an
independent evaluation of the adequacy and effectiveness of the BCM framework’s implementation. The Bank and FLC should ensure that its audit program adequately covers the assessment of BCM preparedness based on the level of operational risks that it is exposed to.
11.1.3 The Internal Audit Department of Banks and FLCs should perform a
comprehensive review of the BCM framework at least once a year to assess whether the BCM framework and BCP is practical as per changing environment and have incorporated all desired changes. The audit should pay particular attention to higher risk areas identified from the Bank’s and FLC’s risk assessment, previous audit findings, and relevant incidents. Internal Audit should observe the business continuity and disaster recovery testing activities as an independent observer in order to provide a reasonable assurance on the executed activities, test results and verifying that the tests align with the Bank’s and FLC’s overall BCP objectives. The audit report should identify any gaps in the BCM framework and document these for review by the external auditor and CBO examiners.
11.1.4 The BCM framework will undergo an external audit at least once every
three years. Therefore, the scope of the external audit should be aligned to encompass the entire BCM framework.
11.1.5 The Banks and FLCs should establish processes to track and monitor the
implementation of remedial actions in response to the audit findings. Audit reports should be communicated to and reviewed by senior management and the Board of Directors to ensure the BCM framework remains practical and effective in addressing potential operational disruptions.
12 Reporting
12.1 Reporting and Disclosures
12.1.1 Chief Financial Stability & Banks Supervision (CFSBS) will appoint the focal
person and the same shall be conveyed to Banks and FLCs within four weeks of publication of this Framework. In case of any change, same will be communicated immediately.
12.1.2 Banks and FLCs should notify immediately but not later than two hours to
focal person or CFSBS, after discovering any incidents that could severely disrupt business operations or trigger the activation of the BCP. An initial report, based on the attached specimen as Annexure – 1 shall be shared within 24 hours of major operational disruption.
12.1.3 A post-incident report including root causes of major operational
disruption as per specimen attached as Annexure – 2 should be submitted to the focal person or CFSBS, CBO within one month of the Bank and FLCs resuming normal operations, following the initial report.
12.1.4 Banks and FLCs shall seek permission from focal person or CFSBS, CBO
when communicating with the media in case of major operational disruption.
12.1.5 Detailed report from business continuity and disaster recovery tests with
specimen attached as Annexure – 3 should be submitted to the SD, CBO through FTP folder within six weeks after the test. Following this, an action plan, based on the test results, should be submitted to the SD, CBO within three months after approval from senior management.
12.1.6 Incidents invoking BCP due to cyber-attacks shall be reported both as per
Cybersecurity & Resilience Framework BM – 1194 and as per format attached with this framework.
13 Annexures
Annexure – 1: Initial Incident Report
To be Reported within 24 Hours of the Incident
Section A: General Information
Incident Report Number (Unique
Identifier)
Name of the Licensed Institution
Section B: Incident Information
Date and Time of Incident
Date and Time of Report to CBO
Description of Incident
Type of the Incident (e.g., System
Outage, Cyber Attack, Natural Disaster, Supply Chain Disruption) Location(s) Affected: [Specify regions, departments, or systems] Date and time of detection of the incident Date: Time:
The incident was detected by (e.g. employees, third-party service providers, customers) Impact Assessment: [Immediate operational impact and effect on services, customers, or business continuity] Description of the incident (System Outage, Cyber Attack, Natural Disaster, Supply Chain Disruption).
Details of the critical system(s) or network(s) that is/are impacted by the incident (This should include location, purpose of this system, make/model, etc.) running on the system/networks, etc. The Probable impacts/risks of the incident (For Example: customer service delivery, loss of sensitive Information, Public Confidence and Reputation) Sequential Order of Events Date of Incident, Start Time, Duration The Immediate Steps Taken by the Bank/ FLC Name of Stakeholders Notified/Involved Communication Channels used (e.g. email, internet, press release, website Notice, etc.) Justifications on the Decision/Activation of BCP and/or DR
Annexure – 2: Comprehensive Incident Report To be Reported within One Month of the Normal Operation Resumption Root Cause Analysis (RCA) Incident's Causal Factors Causes of experienced incident (Identify and elaborate on the root causes of the disruption, whether they were internal, external, or a combination of both. For example (Technical Failure, Hardware Malfunction, Natural Disaster)) Primary Cause: (for Example IT system failure, human error, environmental factors) Secondary Causes: (Any contributing factors) Underlying Issues: (Potential systemic weaknesses or vulnerabilities identified) Mitigation Steps Immediate Mitigation steps taken to contain the incident and to prevent the spread of the situation
Mitigation Steps/Efforts:
Steps identified or to be taken to address the problem in the longer term. List the remedial measures/corrections effected (one-time measure) and/or corrective actions taken to prevent future occurrences of similar types of incidents Response Actions Initiated Initial Response Communication with Internal and External Stake holders Recovery Actions Third Party Involvement Date of Resolution Date Time Business Impact Operational Impact Financial Impact Reputational Impact Additional Information Any other information that needs to be reported to CBO
Annexure – 3: Test Report BCM
To be Reported within Six weeks of Test
Section A: General Information
Test Report Number (Unique Identifier)
Name of the Licensed Institution
Section B: Test Information
Date and Time of Start of Test Date: Time:
Date and Time of End of Test Date: Time:
Date of Report to CBO
Test Scope and Methodology
Test Scenarios (e.g., Simulated disruptions including IT system failures, power outages, financial transaction disruptions, and third-party service failures) Testing Approach (Scenario-based testing, tabletop exercises, live recovery drills, performance metrics based on RTOs and RPOs, and stakeholder interviews) Key Areas Tested (IT and Data Recovery, Critical Financial Services, Third-Party Service Providers, Communication Systems, Resource Availability) Test Results Critical Financial Services Scenario (Disruption to core banking services, including online transactions) Outcome (RTO exceeded by 1.5 hours)
IT and Data Recovery Scenario (Data center outage) Outcome (RTO met) Third-Party Service Providers Scenario (Failure of critical third-party financial data provider) Outcome (RTO exceeded 2 hours from agreed upon RTO) Communication Systems Scenario (Disruption of communication channels) Outcome (RTO exceeded 4 hours) Resource Availability Scenario (Shortage of critical financial operations staff due to illness or travel disruption) Outcome (RTO exceeded 4 hours due to delay in identification of technical staff) Alternate Site and Recovery Arrangements Scenario Outcome Cybersecurity Scenarios Scenario Outcome All Areas that shall be tested as per BCM Framework Scenario Outcome Over Test Result Passed Partially Passed Failed Key Findings and Recommendations Key Findings including Technical Observations (Dependency on Main Data Centre with justification) Key Recommendations Internal Audit Observations Action Plan (Within three months after the approval from the Board of Directors)
Read the rest free
Source: Central Bank of Oman — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works
More like this from CBO
We email you every new CBO publication the day it's published.