2026-01-06 | BM 1225

Added · Updated

Business Continuity Management Framework (Annexure to Circular No BM – 1225)

This framework mandates that licensed domestic banks, finance and leasing companies, and their subsidiaries establish a comprehensive Business Continuity Management system covering governance, policy, strategy, and recovery planning. It requires the Board of Directors to approve the BCM policy and Tier-1 critical service impact tolerances, while senior management must define Service Recovery Time Objectives and maintain a dedicated BCM Committee meeting at least quarterly. The document further obligates entities to conduct regular Business Impact Analyses, integrate BCM into enterprise risk management, and perform annual testing and independent audits to ensure operational resilience against disruptions.

Central Bank of Oman logo

Oman

Central Bank of Oman

Click to view thumbnail

BUSINESS CONTINUITY MANAGEMENT FRAMEWORK (Annexure to Circular No BM – 1225, dated January 6, 2026)

Page 2 of 48 Contents Glossary of Terms.....................................................................................................................................4 Acronyms...................................................................................................................................................7

  1. Introduction.......................................................................................................................................8
  2. Applicability of the Framework...................................................................................................9
  3. Scope ...............................................................................................................................................10 3.1 BCM and Its Purpose............................................................................................................10
  4. BCM Governance Principle........................................................................................................11 4.1 Key governance elements ................................................................................................11
  5. Business Continuity Policy...........................................................................................................14 5.1 Key Components of the BCM Policy...............................................................................14
  6. BCM Strategy..................................................................................................................................17
  7. Business Impact Analysis (BIA) and Recovery Objectives ...............................................20 7.1 BIA Methodology..................................................................................................................20 7.2 Scenario Assessment...........................................................................................................22 7.3 BIA Updates and Review:...................................................................................................23 7.4 Recovery Strategy and Objectives .................................................................................23
  8. Business Continuity and Recovery plans................................................................................26 8.1 Purpose....................................................................................................................................26 8.2 Scope.......................................................................................................................................26 8.3 Principles.................................................................................................................................26 8.4 Business Continuity Plan (BCP)..........................................................................................26 8.5 IT Disaster Recovery Plan (DRP)........................................................................................29 8.6 Cyber Resilience...................................................................................................................30 8.7 Communication....................................................................................................................32 8.8 Cross border Communication ..........................................................................................34 8.9 Crisis Management Plan (CMP) .......................................................................................34 8.10 Integration and Linkages ...................................................................................................35 8.11 Updates, Review and Approval Process: ......................................................................35
  9. Testing...............................................................................................................................................37 9.1 General Testing Guidelines ...............................................................................................37 9.2 Reporting and Documentation of Test Results..............................................................38

Page 3 of 48 9.3 Frequency of Testing ...........................................................................................................38 10. Training and Awareness..........................................................................................................40 10.1 Training and Awareness Requirements..........................................................................40 11 Audit and Assurance...............................................................................................................41 11.1 Responsibilities of Internal Audit.......................................................................................41 12 Reporting.....................................................................................................................................42 12.1 Reporting and Disclosures .................................................................................................42 13 Annexures...................................................................................................................................43 Annexure – 1: Initial Incident Report ............................................................................................43 Annexure – 2: Comprehensive Incident Report.......................................................................45 Annexure – 3: Test Report BCM.....................................................................................................47

Page 4 of 48 Glossary of Terms Terminology Definitions Alternate Site A site held in readiness for use during a business continuity event to maintain an organisation’s business continuity. The term applies equally to work space or technology requirements. Organisations may have more than one alternate site. In some cases, an alternate site may involve facilities that are used for normal day-to-day operations but which are able to accommodate additional business functions when a primary location becomes inoperable. Business Continuity Management Business continuity management is a whole-of-business approach that includes policies, standards, and procedures for ensuring that specified operations can be maintained or recovered in a timely fashion in the event of a disruption. Its purpose is to minimise the operational, financial, legal, reputational and other material consequences arising from a disruption. Business Continuity Plan (BCP) A business continuity plan is a comprehensive written plan of action that sets out the procedures and establishes the processes and systems necessary to continue or restore the operation of an organisation in the event of a disruption. Business continuity plans establish the roles and allocate responsibilities for managing operational disruptions and provide clear guidance regarding the succession of authority in the event of a disruption that disables key personnel. They also clearly set out the decision-making authority and define the triggers for invoking the organisation’s business continuity plan. Business Impact Analysis Business impact analysis is the process of measuring (quantitatively and qualitatively) the business impact or loss of business processes in the event of a disruption. It is a dynamic process for identifying critical operations and services, key internal and external dependencies and appropriate resilience levels. It is used to identify

Page 5 of 48 recovery priorities, recovery resource requirements, and essential staff and to help shape a business continuity plan. Critical business services Critical business services are activities whose disruption would cause intolerable harm to customers or threaten financial stability or whose disruption would significantly affect the operation of the organization or the broader financial system. For example, data center operations, large-value payment processing, transaction clearing, and settlement, as well as supporting systems like funding and reconciliation services, are typically considered critical. Dependency Mapping A process to identify and understand the internal and external dependencies on people, processes, technology, and other resources (including those involving third parties) for each critical business service. IT Disaster Recovery IT Disaster recovery (IT DR) is part of BCM which includes policies, standards, procedures and processes pertaining to resilience, recovery or continuation of technology infrastructure supporting critical business processes. Maximum Acceptable Outage (MAO) Maximum Acceptable Outage (MAO) is defined as the time that would take for adverse impacts which might arise because of not providing a product/service or performing an activity, to become unacceptable. Recovery Level Recovery level is the target level of service that will be provided in respect of a specific business operation after a disruption. Recovery Strategy A recovery strategy sets out recovery objectives and priorities that are based on the business impact analysis. Among other things, it establishes targets for the level of service the organisation would seek to deliver in the event of a disruption and the framework for ultimately resuming business operations.

Page 6 of 48 Recovery Time Recovery time is the target duration of time to recover a specific business operation. A recovery time has two components: the duration of time from the disruption to the activation of a business continuity plan; and, the duration of time from the activation of the business continuity plan to the recovery of the specific business operation. Recovery Time Objective Recovery Time Objective (RTO) is defined as the period following an incident (time incident occurred/point of disruption) within which, products or services must be resumed, activity must be resumed, or resources must be recovered. Red-Team Exercise A controlled, intelligence-led simulation of sophisticated cyberattacks conducted by authorized testers to assess the institution’s ability to detect, respond to, and recover from real-world threats, in accordance with recognized standards. Service Recovery Time Objective (SRTO) Target duration of time to restore a specific business service from the point of disruption to the point when the specific business service is recovered to a level sufficient to meet business obligations.

Page 7 of 48 Acronyms 1 Banks Banks licensed by the Central Bank of Oman 2 BCM Business Continuity Management 3 BCP Business Continuity Plans 4 BCRPs Business Continuity and Recovery Plans 5 BIA Business Impact Analysis 6 CBO Central Bank of Oman 7 CBS Critical Business Services (CBS) 8 CFSBS Chief Financial Stability & Banks Supervision 9 CMP Crisis Management Plan 10 CMT Crisis Management Team 11 CRP Cyber Resilience Plan 12 DR Disaster Recovery 13 DRP Disaster Recovery Plan 14 ERM Enterprise-wide Risk Management 15 ICT Information and Communication technologies 16 FLCs Finance and Leasing Companies licensed by the Central Bank of Oman 17 RPO Recovery Point Objectives 18 RTO Recovery Time Objective 19 SD Surveillance Department 20 SRTO Service Recovery Time Objective 21 TLPT Threat-Led Penetration Testing

Page 8 of 48

  1. Introduction 1.1. Operational disruptions present numerous challenges due to pandemic, rapid technological advancements and a more hostile cyber landscape. The situation becomes even more complicated when banks operate across borders or depend heavily on third-party service providers. Although banks and FLCs may take extensive measures to enhance operational resilience, disruptions are still possible, often due to factors beyond their control. As such, an effective Business Continuity Management (BCM) framework is essential to minimize the impact of such disruptions and ensuring the continuity of financial services. 1.2. The BCM framework comprise of following seven interrelated components, arranged in a hierarchical sequence: 1.2.1. Governance & Oversight 1.2.2. BCM Policy 1.2.3. BCM Strategy 1.2.4. Business Impact Analysis (BIA) and Scenario Assessment 1.2.5. Plans (BCP, Recovery Plans, IT-DRP, Cyber Resilience, Crisis Management) 1.2.6. Testing, Exercising and Validation 1.2.7. Monitoring, Reporting and Continuous Improvement

Page 9 of 48 2. Applicability of the Framework 2.1 This framework is applicable to all licensed domestic banks and FLCs including their subsidiaries, foreign branches and representative offices. 2.2 Licensed foreign banks and their overseas entities who provide the services to the foreign branches operating in the Sultanate of Oman. 2.3 The requirements under the framework extend to all activities of the bank and FLCs, whether performed internally or delivered through outsourcing and third-party arrangements. 2.4 Banks and FLCs should ensure that the contractual provisions and governance arrangements with service providers are adequate to comply with the requirements stipulated in the framework.

Page 10 of 48 3. Scope BCM framework covers the entire lifecycle of BCM, from initiation and implementation to maintenance, monitoring, and improvement. The BCM framework provide principles and best practices to help banks and FLCs establish, implement, maintain, monitor, and continuously improve their BCM frameworks. Ultimately, Banks and FLCs bear the responsibility for ensuring their preparedness for business continuity and for effectively recovering from operational disruptions. To this end, banks and FLCs should develop and implement policies, plans, and procedures that enable the rapid restoration of critical services and functions following any disruption. 3.1 BCM and Its Purpose 3.1.1 BCM framework is an enterprise-wide approach designed to ensure that critical business processes can continue or be quickly restored in the event of significant internal or external operational disruptions. One of its primary objectives is to minimize the financial, legal, and reputational consequences of such disruptions. 3.1.2 The extent and degree to which a Bank and FLCs implements the BCM framework should be commensurate with the nature, size, risk profile and complexity of its business operations. Banks and FLCs shall adapt the framework as necessary, taking into consideration the diverse activities they engage in, and the different markets in which they operate and conduct transactions. 3.1.3 The Basel Committee on Banking Supervision's Joint Forum published seven high-level Principles for BCM in August 2006, which remain relevant even today. Banks are encouraged to refer to these principles when developing and refining their own BCM frameworks.

Page 11 of 48 4. BCM Governance Principle As outlined in Principle 1 of the High-Level Principles for Business Continuity published by the Basel Committee on Banking Supervision, the board of directors and senior management of a Banks are ultimately accountable for the organization’s business continuity. In particular, senior management, with the approval of the board of directors, defines the relationship between themselves and the crisis management structure (BCM Committee). Additionally, the board and senior management must recognize that outsourcing business operations does not transfer the responsibility for business continuity. The responsibility remains with the Bank and FLCs, regardless of outsourcing arrangements. 4.1 Key governance elements 4.1.1 Accountability for Risk Management: The board of directors and senior management are responsible for identifying, assessing, prioritizing, managing, and controlling all risks related to business continuity. 4.1.2 Approval and Oversight of the BCM Framework: The BCM framework should be defined, approved, implemented, and maintained, with final approval from the board of directors and ongoing monitoring by senior management. 4.1.3 Policy and Plans Development: Senior management is responsible to develop policies, plans, procedures and processes for business continuity. Policies must be approved by the board of directors while plans, procedures and processes must be approved by the senior management for locally incorporated Banks and FLCs or by the head office for branches of foreign Banks. 4.1.4 Sufficient Budget Allocation: The board of directors should ensure that an adequate budget is allocated to support all necessary BCM activities. 4.1.5 Communication and Structure: The business continuity structure including Committee must be clearly defined and communicated to all relevant employees and third parties. BCM Committee, mandated by the board of directors, should be established. 4.1.6 Establishment of BCM Committee and its composition: A senior management committee should be established and should have

Page 12 of 48 representations from Business, Risk, Compliance, Information Technology, Information Security, Operations, BCM Manager, and other relevant departments. 4.1.7 BCM Committee Charter: A BCM Committee charter should be developed, outlining the following: i. Committee objectives. ii. Roles and responsibilities. iii. Minimum participant numbers. iv. Meeting frequency (at least quarterly). v. Documentation of meeting minutes for audit purposes. 4.1.8 BCM Manager Appointment: A BCM Manager/Head should be appointed who has: i. Sufficient authority to oversee and manage the BCM program. ii. The necessary qualifications, experience, skills, and competencies to implement and maintain the BCM program within the organization. 4.1.9 Adequate Staffing: The BCM function should be adequately staffed with qualified team members to effectively manage the BCM program. 4.1.10 Integration with Enterprise-wide Risk Management (ERM): The BCM framework should form an integral part of the bank’s and FLC’s overall ERM system, to ensure that BCM is not treated as a stand-alone activity but as a core component of the bank’s and FLC’s risk management and strategic decision-making. The key methodologies include the following: i. Continuity risks should be identified, assessed, and monitored alongside other operational risks in the risk register, with clearly assigned ownership. ii. Material disruption scenarios should be included in the bank’s and FLC’s risk appetite framework, stress testing, and capital and liquidity planning processes.

Page 13 of 48 iii. Key continuity indicators and test results should be reported through the same governance and risk-reporting channels that serve the board’s risk oversight function. 4.1.11 Cross-Functional Collaboration: Cross-functional teams, including strategic, tactical, and operational members, should contribute to the implementation and maintenance of business continuity and disaster recovery plans. By following these principles, Banks and FLCs can ensure strong governance over their business continuity efforts, fostering resilience across the organization.

Page 14 of 48 5. Business Continuity Policy A business continuity policy, encompassing the scope, roles and taxonomy, should provide a foundation for setting business continuity objectives and shall be properly documented. 5.1 Key Components of the BCM Policy 5.1.1 Policy Definition, Approval, and Communication: The business continuity policy shall be approved by the Board of Directors, and communicated to all stakeholders involved in the business continuity process. 5.1.2 Minimum Policy Requirements: The policy shall, at a minimum, include the following elements: i. Objectives: Clear, concise and measurable business continuity objectives. ii. Risk Appetite: BCM Risk Appetite statement covering the residual risk that Banks and FLCs are willing to accept. It should also be closely aligned with risk appetite of the banks and FLCs. iii. Scope: The scope of the BCM policy shall include applicable business functions, branches, intra-group, outsourcing and third-party arrangements, processes, technical standards, third-party service providers, cyber resilience coverage, impact tolerances, etc. In addition, the BCM Policy should also explicitly link with other key internal policies of the banks and FLCs, such as operational risk management framework, outsourcing policy, information security policy and cybersecurity policy. iv. Contents: The BCM Policy shall include, at a minimum, the following elements: a. Governance structure and roles (Board, Senior Management, BCM Committee). b. BCM principles and objectives. c. Methodology for identification of critical services and framework for setting and reviewing impact tolerances and SRTO/RTO/RPO. d. Integration of BCM with risk management and business planning.

Page 15 of 48 e. Provisions for training, awareness, and testing. f. Requirements for third-party participation. g. Document control, review, and approval procedures. 5.1.3 The minimum requirements under Governance Structure and Framework for Impact tolerances are as under: i. Governance Structure and roles: Effective governance of the business continuity policy requires: a. Regular Review and Approval: The policy shall be reviewed and approved periodically (at least once in three years) by the Board of Directors. b. Senior Management and Leadership Involvement: Senior management and business unit leaders must be actively involved in the implementation, oversight and monitoring of compliance of the BCM policy as well as annual assessment of effectiveness of implementation of BCM Policy. c. Commitment from the First and Second Lines of Defense: The first and second lines of defense should be committed to the design and execution of the business continuity policy. d. Independent Review by the Third Line of Defense: The third line of defense shall conduct independent evaluations of the business continuity policy’s implementation and effectiveness. ii. Framework for setting Impact Tolerances and SRTO/RTO/RPO: a. The BCM Policy shall stipulate the process for identifying important/critical business in a tiered approach, and defining ‘Impact Tolerances’ for such businesses in alignment with the risk appetite of the bank and FLC. b. The Board should approve at least the Tier -1 services and the ‘impact tolerances’ for such services, leaving the rest to be determined by senior management. c. The Policy shall require the senior management to determine, maintain and periodically review:

Page 16 of 48 ▪ the Impact tolerances (other than under Board Delegation) and ▪ the supporting Service Recovery Time Objectives (SRTO), Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO) based on the outcomes of Business Impact Analysis and Scenario Testing. d. Impact Tolerances shall be reviewed annually and recalibrated following material changes in business model, infrastructure, processes or regulatory requirements. 5.1.4 Scope Exclusions: Any exclusions from the scope of the BCM policy, if applicable, shall be documented and evaluated on a regular basis. Justifications for these exclusions must be formally approved by the Board of Directors.

Page 17 of 48 6. BCM Strategy 6.1 The Board of Directors of licensed banks and FLCs shall establish and maintain a documented BCM Strategy, which is developed in pursuant to the BCM Policy. The BCM Strategy should define how the bank and FLC will maintain or restore critical operations within the board-approved impact tolerances under all severe but plausible conditions. 6.2 The Strategy shall serve as the link between policy intent and operational execution through ‘Recovery Plans’, aligning continuity objectives with the institution’s risk appetite, technology design, outsourcing model, and crisis￾management structure. 6.3 Senior management, in turn, is accountable for implementing and maintaining the strategy. The BCM strategy should be integrated into the Bank’s and FLC’s overall strategic objectives and serve as a part of sound management practices within the organization. The Board is responsible for monitoring the Bank's and FLC’s compliance with the documented BCM strategy. 6.4 The following areas should be addressed in the BCM strategy: 6.4.1 Strategic Objectives: The BCM Strategy shall articulate how the Banks and FLCs will: i. Safeguard life, assets, data, and reputation; ii. Continue delivery of Critical function within set Impact tolerances; iii. Preserve financial stability and stakeholder confidence; and iv. Integrate continuity planning with enterprise-risk, technology, and outsourcing frameworks. 6.4.2 Scope: The BCM Strategy shall apply enterprise-wide, covering head office, intra-group, branches, customer-facing digital channels, data centers, critical third parties, and market infrastructures relied upon for settlement and payments. 6.4.3 Ongoing Review and Alignment: Establish processes for the continuous review and validation of the BCM strategy to ensure its alignment with the Bank’s and FLC’s strategic goals.

Page 18 of 48 6.4.4 Reporting, Communication, and Training: Define clear reporting structures, communication protocols, and training requirements to ensure effective implementation and awareness of the BCM strategy. 6.4.5 Contents of BCM Strategy: The BCM Strategy, at a minimum, shall include the following: i. Impact-Tolerance-Driven Design a. Licensed Banks and FLCs shall define impact tolerances for critical businesses, stating the maximum acceptable level of disruption in measurable terms (time, volume, customer detriment). b. Recovery and resilience capabilities shall be engineered around these tolerances, not merely around RTO/RPO metrics. c. The Strategy shall demonstrate that design of technology, staffing, intra-group and third-party arrangements collectively maintain operations within these tolerances. ii. Continuity Architecture a. The Bank and FLCs shall implement a multi-layered continuity architecture, selecting recovery models consistent with impact tolerances. b. Redundancy shall be embedded at all layers of network, power, data, and personnel. c. Single points of failure shall be identified, documented, and eliminated through design remediation. d. The Bank and FLCs shall adopt resilience-by-design principles, ensuring new systems undergo resilience impact assessments prior to production release. iii. Cyber and ICT Resilience Integration a. The BCM Strategy shall incorporate ICT continuity measures consistent with international standards and the requirements under CBO Cybersecurity & Resilience Framework issued vide BM – 1194.

Page 19 of 48 b. Banks and FLCs shall maintain appropriate backups (“cyber vaults”) for critical data and test data-integrity validation after recovery. c. Critical systems shall undergo Threat-Led Penetration Testing (TLPT) or equivalent red-team exercises at least once every three years. d. Results of TLPT shall inform refinement of recovery architecture and incident-response procedures. iv. Testing and Validation of the Strategy a. The effectiveness of the BCM Strategy shall be verified through integrated testing (business, IT, third-party service providers). b. Gaps identified during tests shall be addressed within agreed remediation timelines and re-tested for closure. c. Independent validation by internal audit shall occur at least once every three years.

Page 20 of 48 7. Business Impact Analysis (BIA) and Recovery Objectives The Business Impact Analysis (BIA) is a critical process for identifying and evaluating the potential impacts both quantitative and qualitative that disruptions may have on business operations. The BIA is the foundation for understanding an organization’s critical operations, key dependencies, and the required resilience levels. It helps assess the risks of various disruption scenarios and their effects on the organization’s operations and reputation. The BIA assists in identifying which business functions are critical to the organization’s survival and which could be temporarily disrupted without significant consequences. During a major disruption, access to necessary recovery resources may be limited. Therefore, the BIA helps prioritize the recovery of critical functions and establishes appropriate recovery objectives. 7.1 BIA Methodology 7.1.1 The Senior Management/ BCM committee of the Licensed Banks and FLCs shall defined methodology for conducting and implementing BIA at least annually, which should be validated by internal audit periodically. The methodology shall: i. Define criteria for identifying critical businesses and functions; ii. Quantify financial, operational, legal, and reputational impacts of disruption; iii. Determine RTO, RPO, and impact tolerances values; and iv. Map dependencies across people, process, technology, data, premises and third parties in order to determine the minimal resources required to achieve the desired recovery levels. 7.1.2 Identification of Critical Business Services (CBS) i. Critical business services are activities whose disruption would cause intolerable harm to customers or threaten financial stability or whose disruption would significantly affect the operation of the organization or the broader financial system. For example, data center operations, large-value payment processing, transaction clearing, and settlement,

Page 21 of 48 as well as supporting systems like funding and reconciliation services, are typically considered critical. ii. The Banks and FLCs shall maintain CBS Register recording for each service: a. Service description and responsible owner; b. Customer segments and volumes served; c. Identification of both internal and external interdependencies (systems, intra-group entities, third-party service providers, facilities, data, people); d. Applicable impact tolerance; and e. Criticality rating (high/medium/low). iii. The CBS Register shall be reviewed semi-annually. 7.1.3 Dependency Mapping i. The Bank and FLC shall create end-to-end dependency maps for each CBS, identifying all supporting assets and interconnections. ii. Maps shall include data-flows, upstream and downstream dependencies, and cross-border linkages. iii. Technology tools such as service-mapping software may be used for accuracy and auditability. iv. Dependencies shall be validated during testing to ensure completeness. 7.1.4 Impact Dimensions i. BIAs shall measure potential impact across multiple dimensions on each CBS: a. Customer harm or financial loss; b. Regulatory or legal breach; c. Market or payment-system disruption; d. Reputational damage; and

Page 22 of 48 e. Safety or operational-integrity risk. ii. Quantitative thresholds shall be established where possible (e.g., transaction volumes delayed, customers affected). 7.1.5 Impact Tolerance and RTO/ RPO i. For each CBS, the Bank and FLC shall specify: a. Impact Tolerance – maximum tolerable disruption; b. RTO – target restoration time; c. RPO – maximum data-loss period; and d. Resource requirements to meet these objectives. ii. Tolerances shall be approved by the board/ senior management, as the case may be, and linked to the Bank’s and FLC’s risk appetite. iii. Where tolerances are breached during testing or incidents, corrective measures shall be initiated immediately and recorded. 7.1.6 Third-party service providers and Supplier Capability Assessment Banks and FLCs must assess the capability of third-party service providers, suppliers, and service providers to maintain service levels during a disruption, especially for CBS. 7.2 Scenario Assessment 7.2.1 The Bank and FLC shall design and maintain a catalogue of severe-but￾plausible scenarios derived from threat assessment and historical data. These scenarios should be assessed quantitatively and qualitatively for financial, operational, legal, and reputational impacts. 7.2.2 Scenarios shall include single-event and multi-event combinations such as: i. Data-center outage coinciding with cyberattack; ii. Regional natural disaster affecting multiple branches; iii. Critical third-party service providers insolvency; iv. Widespread telecom failure; or

Page 23 of 48 v. Systemic liquidity crisis with concurrent operational disruption. 7.2.3 Each scenario shall specify trigger points, escalation paths, and expected recovery performance against tolerances. 7.2.4 Scenario outcomes shall be documented and incorporated into BCM Strategy reviews. 7.2.5 Use of Data and Analytical Tools i. Banks and FLCs are encouraged to use quantitative modelling, simulation, and scenario-analytics platforms to enhance accuracy of impact estimation. ii. Sensitivity analysis shall be performed to evaluate effects of prolonged or cascading events. iii. Data from incidents, near-misses, and industry stress exercises shall be incorporated into scenario design. 7.3 BIA Updates and Review: The BIA should be reviewed and updated as follows: 7.3.1 Annually by all Banks and FLCs to ensure ongoing relevance. 7.3.2 Post-major Disruptions within three months of any major operational disruption. 7.3.3 When Major Changes Occur (within three months), including changes to organizational structure, people, processes, technology, suppliers, locations or regulatory requirements. 7.4 Recovery Strategy and Objectives 7.4.1 A recovery strategy outlines the recovery objectives and priorities that are derived from the BIA. It sets clear targets for the level of service; an organization aims to maintain during a disruption and provides a structured framework for resuming business operations as quickly as possible. The purpose of the recovery strategy is to ensure that recovery efforts are executed in a systematic and predefined manner, minimizing disruption and financial loss.

Page 24 of 48 7.4.2 When establishing recovery strategies, Banks and FLCs should take an end￾to-end view of the critical business services and their dependencies. This means considering not only the recovery of individual processes but also the complete set of interconnected processes that support the delivery of each service. This holistic approach minimizes the impact of disruptions, safeguards customer interests, and preserves the safety and soundness of the Bank and FLC. 7.4.3 Recovery Objectives i. Recovery objectives are predefined goals for restoring CBS to a specified level of service (recovery level) within a defined period (recovery time) after a disruption. In alignment with Principle 3 of the High-Level Principles for Business Continuity published by the Basel Committee on Banking Supervision, Banks should set recovery objectives that are proportionate to the risk posed by the disruption to the operation of the financial system. ii. While the senior management hold ultimate accountability for recovery objectives, these objectives are often developed by, or in consultation with, business line management, particularly at the level of individual business functions. iii. Banks and FLCs must identify and document appropriate recovery objectives and strategies based on the results of the BIA and lessons learnt from the previous incidents, considering the risk profile, nature, size, and complexity of the institution’s business and structure. 7.4.4 Recovery Objectives for Critical Resources As a minimum, the following business recovery options must be defined to address the loss of the following critical resources: i. Staff ii. Buildings iii. IT Systems and Infrastructure (including Payment and Settlement systems as well as communications systems) iv. External Service Providers, intra group entities and suppliers (including outsourcing partners and information providers)

Page 25 of 48 The recovery objectives should be formally documented and cover the recovery options for these critical resources. These objectives should be updated regularly to ensure their relevance. 7.4.5 Minimum Operational Resources: Determining the minimal resources required to achieve the desired recovery level, including personnel, IT/data, buildings, and external service providers. 7.4.6 Prioritization of Recovery Efforts Banks and FLCs must prioritize recovery efforts based on the criticality of each service and function, determining recovery strategies and resource allocation accordingly. 7.4.7 Frequency of Updates Recovery objectives should be reviewed and updated: i. Annually by all Banks and FLCs. ii. Post-Major Operational Disruptions, within three months of the event.

Page 26 of 48 8. Business Continuity and Recovery plans 8.1 Purpose To ensure that Licensed Banks and FLCs maintain documented, practical, and tested plans capable of restoring critical operations and information systems within approved impact tolerances during any disruption. 8.2 Scope Business Continuity and Recovery Plans (BCRPs) shall include the following categories: 8.2.1 Business Continuity Plan (BCP) to ensure essential business processes continue under disruption. 8.2.2 IT Disaster Recovery Plan (DRP) to restore technology infrastructure, systems, and data within approved impact tolerances. 8.2.3 Cyber Resilience Plan (CRP) to detect, contain, and recover from cyber incidents within approved impact tolerances. 8.2.4 Crisis Management Plan (CMP) to govern decision-making, communications, and leadership coordination during crises. 8.3 Principles 8.3.1 BCRPs shall be aligned with impact tolerances established under the BCM Strategy. 8.3.2 Plans shall be actionable, clearly assigned to responsible personnel, and accessible during disruptions. 8.3.3 Plans shall ensure end-to-end recovery, including restoration of customer￾facing and internal support functions within approved impact tolerances. 8.4 Business Continuity Plan (BCP) 8.4.1 Business continuity plan (BCP) is the process of developing a plan to prevent, respond to, and recover from potential severe disruptions. The primary goal is to ensure the protection of processes, assets, and human resources while enabling the institution to quickly resume operations following a disruption. BCP is a crucial element of operational resilience, which is the ability of Banks and FLCs to prevent, adapt, recover, and learn

Page 27 of 48 from disruptive events while maintaining service delivery and meeting client expectations, even under constrained conditions. 8.4.2 The BCP outlines the institution's critical functions, identifies the systems and processes that need to be maintained, and details the strategies required to ensure continuity. The plan provides actionable steps for recovery and highlights the importance of staff safety as the foremost consideration during any disruption. 8.4.3 Key Components of Business Continuity Plan i. Critical Resources: The BCP should identify critical resources, including people, technology, processes, data, equipment, facilities, and their interconnections and interdependencies that support the Bank’s and FLC’s critical services essential for business continuity. ii. People Resources: It shall include: a) Details of key individuals in DR site and remote access support. b) Coordinator details (Assigned to operationalize the recovery site) c) Details about Salvage team (Tasked with restoring the primary site to full operational capacity) iii. Roles and Responsibilities: The BCP must allocate roles and responsibilities for managing operational disruptions, establishing clear guidance on the succession of authority when key personnel become unavailable. iv. Decision-Making Authority: The plan should clearly define decision￾making authority and outline triggers for activating the BCP. v. Activation Criteria: The BCP should include criteria for activation in the event of partial disruption to critical business services, ensuring timely and decisive action before the situation worsens. vi. Recovery Objectives: A clear process for maintaining critical activities within predefined recovery objectives (e.g., Recovery Time Objectives [RTO], Recovery Point Objectives [RPO], and Maximum Acceptable Outage [MAO]) should be incorporated.

Page 28 of 48 vii. Business-as-Usual Resumption: The BCP should outline a process for returning to normal operations once the disruption has been resolved. viii.Consideration of Pandemic and Extended Disruptions: While BCPs were traditionally focused on short-term disruptions, such as those lasting a few hours to a week, the COVID-19 pandemic highlighted the need for plans addressing longer-term disruptions. Banks and FLCs should consider multiple time frames for BCPs, such as immediate, short-term, medium-term, and long-term scenarios (ranging from hours to more than six months). Furthermore, Banks and FLCs should account for new risks introduced by alternative work arrangements, technological challenges with remote work, and increased cybersecurity threats during extended disruptions. ix. Contingency Planning for Third Party Service Providers: Banks and FLCs should develop comprehensive contingency plans, including exit strategies, to maintain resilience in the event of disruptions at third-party service providers. This includes considering alternatives such as substituting third-party services (e.g., data centers, telecom providers) or bringing services back in-house. x. Legal Considerations for Third-Party Agreements: Given the disruptions experienced during the pandemic, Banks and FLCs should formalize agreements with third-party providers to ensure continued provision of critical services during operational interruptions. These agreements should guarantee operational resilience, regardless of the duration of a disruption. Legal agreements should be comprehensive covering all aspects to ensure continued provision of critical services and shall include minimum the following: a) Clear allocation of responsibilities between the Banks/ FLCs and the third-party service providers to ensure continued provision of critical services during operational interruptions. b) Bank’s and FLC’s right to inspect third-party service providers BCM framework and assess their effectiveness during the test exercise of BCPs. c) CBO’s access directly or via Bank and FLC to inspect the third-party service providers BCM framework.

Page 29 of 48 8.5 IT Disaster Recovery Plan (DRP) 8.5.1 Banks and FLCs must ensure their IT infrastructure remains resilient and capable of recovering from disruptions while maintaining the security and integrity of their critical operations. Banks and FLCs must define, approve, implement, and maintain an IT Disaster Recovery Plan (DRP) for their critical activities and related technology infrastructure. The IT DRP should cover the following key areas: i. Recovery and Restoration of Technology Services: IT DRP should clearly define, approve, implement, and maintain procedures to recover and restore critical technology services and infrastructure components, including data, systems, networks, services, and applications. These procedures should align with the BIA. ii. Cyber Attack Resilience and Business Continuity: The DRP should be designed to enable rapid recovery from cyberattacks and ensure safe restoration of business operations while safeguarding security processes, data, and information. Banks and FLCs shall refer to the CBO Cybersecurity & Resilience Framework issued vide BM 1194 for comprehensive guidance on cybersecurity and resilience matters, including reporting requirements to the CBO. iii. Alternative Data Center: Banks and FLCs must establish an alternative data center at a geographically distinct location that mitigates the risks faced by the primary data center (e.g., geographical threats) with following features: a) The alternative data center should commensurate with the configurations and capacities of the primary data center, ensuring that the systems, networks, applications, and data can be fully supported in the event of a disaster. b) The same logical, physical, environmental, and cybersecurity controls implemented in the primary data center should also be applied to the alternative data center. iv. Backup and Recovery Process: Banks and FLCs must define and implement a robust backup and recovery process to ensure the integrity and availability of critical data and systems during a disaster.

Page 30 of 48 v. Disaster Recovery Testing: Disaster recovery tests must be conducted at least annually to validate the effectiveness of the DRP and its arrangements. vi. Ongoing Evaluation and Updates: The effectiveness of the IT DRP should be measured, reviewed, and updated at least once a year to ensure it remains relevant and effective. 8.6 Cyber Resilience 8.6.1 The malicious use of information and communication technologies (ICT) poses a significant risk to financial services that are crucial to both national and international financial systems. Such threats can undermine security, erode public confidence, and jeopardize financial stability. As Banks and FLCs increasingly rely on technology, automation, and integration with third-party providers and customers, their attack surface continues to expand. This broader exposure invites cyber-adversaries to enhance their capabilities, making it essential for Banks and FLCs to strengthen their cyber resilience. 8.6.2 With the growing reliance on third-party providers, particularly in cloud services and shared service models, the perimeter of interest for financial regulators has widened. These developments necessitate a new approach for Banks and FLCs to build and maintain robust cyber resilience, particularly in collaboration with third parties. 8.6.3 The Impact of Pandemic and Emerging Cyber Risks i. The COVID-19 pandemic has introduced new challenges and risks that can affect Banks and FLCs rapidly and extensively. The shift to remote work, reliance on digital services, and increased cyber threats such as ransomware attacks and phishing have amplified operational risks. These disruptions have affected various aspects of operations, including data, systems, personnel, facilities, and relationships with external service providers. ii. The pandemic has also heightened concerns about the operational risks associated with remote work. It is crucial for Banks and FLCs to assess whether emerging risks can be effectively managed and whether they have procedures in place to identify, analyze, and mitigate these risks as their work models evolve. Banks and FLCs need

Page 31 of 48 to consider how these risks impact their overall risk profiles, particularly in a hybrid working environment. 8.6.4 Ensuring Resilient IT Infrastructure i. The reliability and security of IT services are vital to ensure that operations can continue remotely, particularly during widespread disruptions like the pandemic. As hybrid working arrangements become more common, maintaining strong cybersecurity and protecting against threats like cyber-attacks and data breaches is critical. Banks and FLCs must continually monitor and enhance their IT infrastructure to defend against cyber risks and ensure the continuity of critical operations. ii. The challenges faced during a pandemic may be compounded by other disruptive events, such as natural disasters, cyber-attacks, and terrorism. The likelihood of simultaneous disruptive events increases over time, and certain risks such as power outages, key personnel unavailability, or cyber-attacks may be more likely due to circumstances brought about by the pandemic. This makes it essential for Banks and FLCs to design flexible BCP that account not only for individual risks but also for the potential combination of multiple threats occurring simultaneously. 8.6.5 Cyber Resilience Programs i. Banks and FLCs should implement comprehensive cyber resilience programs that cover protection, detection, response, and recovery. These programs should be regularly tested to ensure they remain effective in mitigating risks and responding to disruptions. Additionally, Banks and FLCs must maintain situational awareness and provide relevant, timely information to support risk management and decision￾making processes, enabling the continued delivery of critical operations. ii. All infrastructure and software changes that support critical services, business functions, and processes must undergo thorough risk assessments to ensure they meet the institution’s requirements for availability and recovery. This ensures that Banks and FLCs can maintain operational continuity in the face of cyber threats and other disruptions.

Page 32 of 48 8.6.6 Compliance with Cybersecurity & Resilience Framework: Banks and FLCs shall refer to the CBO Cybersecurity & Resilience Framework (BM – 1194) for comprehensive guidance on cybersecurity and resilience matters, including reporting requirements to the CBO. This framework provides essential standards for managing and enhancing cyber resilience in Banks and FLCs, ensuring they are prepared for evolving cyber threats and operational challenges. 8.7 Communication 8.7.1 Effective communication is crucial in crisis management during major operational disruptions. Banks and FLCs must devote special attention to developing comprehensive communication plans that cover both internal and external communication during operational disruptions. The ability to communicate clearly and efficiently with both internal teams and external stakeholders during major operational disruptions is vital to an institution's ability to respond, recover, and maintain public confidence. 8.7.2 Banks and FLCs should incorporate clear procedures and methods for communication within their organization and with relevant external parties as part of their BCP. These procedures should ensure that all parties involved are kept informed of the situation and can make well-informed decisions to support the recovery process. 8.7.3 Key Considerations for Communication: i. Timely and Effective Communication: Early communication is critical to assess the impact of a disruption on both internal operations and the broader financial system. It is essential to quickly determine the severity of the disruption and decide whether to activate the BCP. As the crisis progresses, providing timely and accurate information to stakeholders is key to the recovery process and helps restore normal operations across the financial system. ii. Maintaining Public Confidence: Clear, consistent communication throughout the duration of a major operational disruption is necessary to maintain public confidence in the Bank and FLC and the broader financial system. Regular updates help ensure transparency and support effective decision-making. However, Banks and FLCs shall seek prior permission from CBO when communicating with the media in case of major operational disruption.

Page 33 of 48 iii. Lines of Reporting and Succession: Each key function should have clearly defined reporting lines and succession plans, particularly for key managerial and operational staff. Up-to-date contact lists for all critical personnel, including crisis management team members, authorities, and infrastructure providers, should be readily available at both primary and backup locations. The lists should also include details of all internal and external stakeholders who need to be notified immediately when a critical business service is disrupted. iv. Communication Channels and Alternatives: A communication plan should identify the primary communication channels, including mainstream and social media, and outline procedures for alternative channels in the event that primary channels are unavailable. Banks and FLCs must be prepared to effectively communicate with external parties (e.g., regulators, service providers) and within their organization, using predefined channels and protocols. v. Emergency Communication Protocols: Banks and FLCs should establish emergency communication procedures and designate individuals or teams responsible for communication with staff and external stakeholders. This group may include senior management, public relations staff, legal and compliance advisors, and business continuity coordinators. This communication team should be capable of reaching personnel located at remote sites, across multiple locations, or working off-site. vi. Contingency-Based Communication Plans: Banks and FLCs should consider specific communication plans based on the use of tools like call trees or mass notification systems. These plans should be supported by technological tools that enable rapid communication with staff during a disruption. Satellite communication equipment may be provided to key personnel responsible for managing operational continuity, ensuring they can communicate even in the event of widespread infrastructure failure. vii. Lessons Learnt from Pandemic and other High-Impact Scenarios: The COVID-19 pandemic has reinforced the importance of adaptable and effective communication strategies during crisis events. Banks and FLCs should review and improve their communication frameworks to address high-impact scenarios, such as cyber-attacks (often arising from remote work), natural disasters like earthquakes, and other crises.

Page 34 of 48 These strategies should include identifying target audiences, determining the appropriate types of messages, and selecting best communication channels for each situation. 8.8 Cross border Communication 8.8.1 Banks should establish communication procedures that specifically address interactions with financial authorities in other jurisdictions during major operational disruptions with cross-border implications. 8.8.2 As Banks become more interconnected across global markets, the impact of a significant operational disruption is likely to extend beyond national borders. Managing disruptions that affect multiple jurisdictions introduces additional complexity, which requires careful planning and coordination. While domestic communication procedures are generally well-defined within Bank's BCP, disruptions with international reach demand additional focus and preparation. 8.8.3 Banks should recognize the possibility that a disruption in one jurisdiction could affect the operations of significant subsidiaries, branches, or otherwise impact the broader financial system in other regions. In such cases, Banks must ensure that their communication protocols include clear guidelines for when and how to contact relevant financial authorities in other jurisdictions. 8.8.4 These communication protocols should: i. Identify the specific circumstances under which cross-border communication is necessary. ii. Establish predefined contact points with financial authorities, regulators, and other stakeholders in affected jurisdictions. iii. Ensure that communication is timely, accurate, and consistent across all jurisdictions to mitigate the potential impact on the financial system and maintain regulatory compliance. 8.9 Crisis Management Plan (CMP) 8.9.1 The CMP shall describe governance and command structure during major disruptions.

Page 35 of 48 8.9.2 A Crisis Management Team (CMT) shall be chaired by a senior executive empowered to make binding decisions. 8.9.3 The CMP shall specify: i. Activation criteria and escalation process; ii. Roles and responsibilities within the CMT; iii. Decision-rights hierarchy and delegation of authority; iv. Media, customer, and regulator communication protocols; and v. Stakeholder coordination with government and market infrastructure entities 8.9.4 Banks and FLCs shall maintain pre-approved communication templates and ensure 24/7 contact accessibility for CMT members. 8.9.5 The CMP shall be tested through simulation exercises and updated based on lessons learned. 8.9.6 The CMP shall manage all incidents impacting the Bank and FLC, including those attributable to dependencies on, but not limited to, third parties and intragroup entities. 8.10 Integration and Linkages 8.10.1 The BCP, DRP, CRP, and CMP shall be integrated into a single Business Continuity Framework with consistent governance, version control, and escalation triggers. 8.10.2 Interdependencies among the plans shall be mapped and periodically validated during testing. 8.10.3 Documentation shall clearly state linkages to the BCM Policy and Strategy. 8.11 Updates, Review and Approval Process: 8.11.1 Annual Review: Banks and FLCs should review and update their BCP annually to ensure its relevance and effectiveness.

Page 36 of 48 8.11.2 Post-Disruption Review: The plan should be reviewed and updated within three months following any major operational disruption. 8.11.3 Plans shall be approved by Senior Management and acknowledged by functional heads. 8.11.4 Material revisions shall be communicated to the Board’s Risk Committee and the Central Bank upon request. 8.11.5 Compliance Monitoring: Regular monitoring of compliance with all the plans are essential. BCM Manger shall ensure that critical service providers, including third parties, have plans in place and tested on yearly basis.

Page 37 of 48 9. Testing 9.1 General Testing Guidelines Banks and FLCs should regularly test their BCPs to assess their effectiveness and ensure readiness. Testing is an essential component of an effective BCM framework, as it helps verify the institution’s ability to recover critical operations and respond effectively during disruptions. Testing should occur annually or within three months after the Banks and FLCs resuming normal operations following invocation of the BCP. 9.1.1 The following key areas should be covered in BCP testing: i. Scenario Planning and Objectives: Tests should include carefully planned plausible scenarios, such as disturbances in payment and settlement systems, with clearly defined objectives for each critical function, service, process, location, and worst-case situations. ii. Alternate Site and Recovery Arrangements: Test scenarios must evaluate how alternate sites and recovery arrangements will be operated, ensuring that coordination is smooth and that plans are executed seamlessly. iii. Stress Testing: Stress tests should be conducted using severe but plausible scenarios to challenge current planning assumptions, assess the relevance of BCPs, and ensure they effectively mitigate the impact of major disruptions. Tests should also verify that the SRTOs for critical business services and the RTOs for critical business functions can be achieved through the established recovery objectives. iv. IT Disaster Recovery Testing: Banks and FLCs should evaluate the effectiveness of IT DR testing for the infrastructure that supports critical systems. This ensures that the IT recovery capability is in place to resume business operations after major disasters or disruptions. v. Cybersecurity Scenarios: Cybersecurity-related scenarios, such as cyber-attacks, should be included to test the Bank’s and FLC’s response and recovery procedures in the context of evolving cyber threats. vi. BCP Team Activation: Test scenarios should also cover the activation of the BCP team, ensuring the team’s involvement and coordination during a crisis.

Page 38 of 48 vii. Integrated BCM Testing: Banks and FLCs should conduct an integrated BCP test that covers all critical services, business processes, and functions to assess the overall coordination and effectiveness of the BCM framework. 9.2 Reporting and Documentation of Test Results 9.2.1 All test results should be reported to the BCM committee, senior management, and the board of directors. These results will help identify areas for improvement within the BCP and the broader BCM framework. An independent party, such as internal audit, should assess the testing process, review results, and report findings to senior management and the board. Any identified gaps or shortcomings must be addressed timely with comprehensive action plan. 9.2.2 Detailed documentation of all exercises and tests should be maintained for audit purposes, and the results should include: i. Confirmation of whether the objectives of the test were met. ii. Confirmation of the capabilities and readiness of recovery resources. iii. Documentation of lessons learned and areas requiring improvement. iv. In the case of failure, identification of the root cause and the tracking of remediation actions to resolution. Re-testing should be conducted within three months after failure. 9.3 Frequency of Testing 9.3.1 Testing should be conducted at least once per year, or within three months after the Bank and FLC resuming normal operations following invocation of the BCP due to a major operational disruption. Detailed test reports related to business continuity and disaster recovery should be submitted to Surveillance Department (SD) - CBO within six weeks after the test. Based on the test results, Banks and FLCs should develop an improvement action plan, which must be approved by senior management. The action plan should be submitted to SD – CBO within three months of the test result submission. 9.3.2 Banks and FLCs should consider a risk-based approach to build up capacity to conduct test exercises and DR drills during business hours on working

Page 39 of 48 days. Banks and FLCs shall communicate to relevant stakeholders related to the date and timings of the test exercise. By following these testing protocols, Banks and FLCs can ensure their BCPs are robust, effective, and capable of responding to a wide range of disruptions, ensuring operational resilience and continuity.

Page 40 of 48 10. Training and Awareness 10.1 Training and Awareness Requirements 10.1.1 Banks and FLCs should establish, implement, and maintain a comprehensive training and awareness program to support their BCM objectives. This program should focus on developing the necessary competencies among staff to effectively carry out BCM-related responsibilities. 10.1.2 Training should be provided to both new employees and existing staff through regular refresher sessions, ensuring all staff are equipped with a clear understanding of their roles, duties, and responsibilities in relation to BCM activities. Particular attention should be given to the training of individuals within the crisis management organization, ensuring they are well-prepared to respond to incidents effectively. 10.1.3 To reinforce the significance of BCM, Banks and FLCs should implement an ongoing awareness program that consistently informs all employees about the importance of BCM and their role within the framework. 10.1.4 At a minimum, Banks and FLCs should provide annual training to employees involved in BCM to ensure they possess the required experience, skills, and competencies. Additionally, the effectiveness of the training and awareness program should be periodically assessed and updated as necessary. 10.1.5 Third party service providers should also conduct annual training about BCM related to the continued provision of critical services during operational interruptions as mentioned in the agreement.

Page 41 of 48 11 Audit and Assurance 11.1 Responsibilities of Internal Audit 11.1.1 Bank’s and FLC’s BCM framework should be subject to review by an independent party, such as internal or external audit, and significant findings should be reported to the board and senior management on a timely basis. 11.1.2 Conducting a BCM audit is a crucial method for providing an independent evaluation of the adequacy and effectiveness of the BCM framework’s implementation. The Bank and FLC should ensure that its audit program adequately covers the assessment of BCM preparedness based on the level of operational risks that it is exposed to. 11.1.3 The Internal Audit Department of Banks and FLCs should perform a comprehensive review of the BCM framework at least once a year to assess whether the BCM framework and BCP is practical as per changing environment and have incorporated all desired changes. The audit should pay particular attention to higher risk areas identified from the Bank’s and FLC’s risk assessment, previous audit findings, and relevant incidents. Internal Audit should observe the business continuity and disaster recovery testing activities as an independent observer in order to provide a reasonable assurance on the executed activities, test results and verifying that the tests align with the Bank’s and FLC’s overall BCP objectives. The audit report should identify any gaps in the BCM framework and document these for review by the external auditor and CBO examiners. 11.1.4 The BCM framework will undergo an external audit at least once every three years. Therefore, the scope of the external audit should be aligned to encompass the entire BCM framework. 11.1.5 The Banks and FLCs should establish processes to track and monitor the implementation of remedial actions in response to the audit findings. Audit reports should be communicated to and reviewed by senior management and the Board of Directors to ensure the BCM framework remains practical and effective in addressing potential operational disruptions.

Page 42 of 48 12 Reporting 12.1 Reporting and Disclosures 12.1.1 Chief Financial Stability & Banks Supervision (CFSBS) will appoint the focal person and the same shall be conveyed to Banks and FLCs within four weeks of publication of this Framework. In case of any change, same will be communicated immediately. 12.1.2 Banks and FLCs should notify immediately but not later than two hours to focal person or CFSBS, after discovering any incidents that could severely disrupt business operations or trigger the activation of the BCP. An initial report, based on the attached specimen as Annexure – 1 shall be shared within 24 hours of major operational disruption. 12.1.3 A post-incident report including root causes of major operational disruption as per specimen attached as Annexure – 2 should be submitted to the focal person or CFSBS, CBO within one month of the Bank and FLCs resuming normal operations, following the initial report. 12.1.4 Banks and FLCs shall seek permission from focal person or CFSBS, CBO when communicating with the media in case of major operational disruption. 12.1.5 Detailed report from business continuity and disaster recovery tests with specimen attached as Annexure – 3 should be submitted to the SD, CBO through FTP folder within six weeks after the test. Following this, an action plan, based on the test results, should be submitted to the SD, CBO within three months after approval from senior management. 12.1.6 Incidents invoking BCP due to cyber-attacks shall be reported both as per Cybersecurity & Resilience Framework BM – 1194 and as per format attached with this framework.

Page 43 of 48 13 Annexures Annexure – 1: Initial Incident Report To be Reported within 24 Hours of the Incident Section A: General Information Incident Report Number (Unique Identifier) Name of the Licensed Institution Section B: Incident Information Date and Time of Incident Date and Time of Report to CBO Description of Incident Type of the Incident (e.g., System Outage, Cyber Attack, Natural Disaster, Supply Chain Disruption) Location(s) Affected: [Specify regions, departments, or systems] Date and time of detection of the incident Date: Time: The incident was detected by (e.g. employees, third-party service providers, customers) Impact Assessment: [Immediate operational impact and effect on services, customers, or business continuity] Description of the incident (System Outage, Cyber Attack, Natural Disaster, Supply Chain Disruption).

Page 44 of 48 Details of the critical system(s) or network(s) that is/are impacted by the incident (This should include location, purpose of this system, make/model, etc.) running on the system/networks, etc. The Probable impacts/risks of the incident (For Example: customer service delivery, loss of sensitive Information, Public Confidence and Reputation) Sequential Order of Events Date of Incident, Start Time, Duration The Immediate Steps Taken by the Bank/ FLC Name of Stakeholders Notified/Involved Communication Channels used (e.g. email, internet, press release, website Notice, etc.) Justifications on the Decision/Activation of BCP and/or DR

Page 45 of 48 Annexure – 2: Comprehensive Incident Report To be Reported within One Month of the Normal Operation Resumption Root Cause Analysis (RCA) Incident's Causal Factors Causes of experienced incident (Identify and elaborate on the root causes of the disruption, whether they were internal, external, or a combination of both. For example (Technical Failure, Hardware Malfunction, Natural Disaster)) Primary Cause: (for Example IT system failure, human error, environmental factors) Secondary Causes: (Any contributing factors) Underlying Issues: (Potential systemic weaknesses or vulnerabilities identified) Mitigation Steps Immediate Mitigation steps taken to contain the incident and to prevent the spread of the situation

Page 46 of 48 Mitigation Steps/Efforts: Steps identified or to be taken to address the problem in the longer term. List the remedial measures/corrections effected (one-time measure) and/or corrective actions taken to prevent future occurrences of similar types of incidents Response Actions Initiated Initial Response Communication with Internal and External Stake holders Recovery Actions Third Party Involvement Date of Resolution Date Time Business Impact Operational Impact Financial Impact Reputational Impact Additional Information Any other information that needs to be reported to CBO

Page 47 of 48 Annexure – 3: Test Report BCM To be Reported within Six weeks of Test Section A: General Information Test Report Number (Unique Identifier) Name of the Licensed Institution Section B: Test Information Date and Time of Start of Test Date: Time: Date and Time of End of Test Date: Time: Date of Report to CBO Test Scope and Methodology Test Scenarios (e.g., Simulated disruptions including IT system failures, power outages, financial transaction disruptions, and third-party service failures) Testing Approach (Scenario-based testing, tabletop exercises, live recovery drills, performance metrics based on RTOs and RPOs, and stakeholder interviews) Key Areas Tested (IT and Data Recovery, Critical Financial Services, Third-Party Service Providers, Communication Systems, Resource Availability) Test Results Critical Financial Services Scenario (Disruption to core banking services, including online transactions) Outcome (RTO exceeded by 1.5 hours)

Page 48 of 48 IT and Data Recovery Scenario (Data center outage) Outcome (RTO met) Third-Party Service Providers Scenario (Failure of critical third-party financial data provider) Outcome (RTO exceeded 2 hours from agreed upon RTO) Communication Systems Scenario (Disruption of communication channels) Outcome (RTO exceeded 4 hours) Resource Availability Scenario (Shortage of critical financial operations staff due to illness or travel disruption) Outcome (RTO exceeded 4 hours due to delay in identification of technical staff) Alternate Site and Recovery Arrangements Scenario Outcome Cybersecurity Scenarios Scenario Outcome All Areas that shall be tested as per BCM Framework Scenario Outcome Over Test Result Passed Partially Passed Failed Key Findings and Recommendations Key Findings including Technical Observations (Dependency on Main Data Centre with justification) Key Recommendations Internal Audit Observations Action Plan (Within three months after the approval from the Board of Directors)