Management Summary
- Purpose / Background: Following the successful conclusion of the HKMA’s "1+3 year" journey (under SPM OR-2), which saw all AIs establish operational resilience frameworks by May 31, 2026, the HKMA is shifting its focus to sustaining and uplifting these capabilities as "business as usual" (BAU).
- One-line conclusion: AIs must transition operational resilience from a project-based initiative to an embedded, BAU process that proactively evolves with the changing risk landscape.
- Key Changes:
- Transitioning governance from project-based structures to permanent, staff-empowered operational ownership.
- Requirement to regularly review and potentially compress "tolerances for disruption" to demonstrate maturity.
- Shift toward higher granularity in mapping and increased severity in scenario testing.
- Integration of automation (e.g., auto-refreshing third-party dependency maps) to improve agility.
- Explicit focus on emerging risks, specifically AI-empowered cyber threats and third-party risk management.
- Key Dates / Deadlines: Immediate (as of June 1, 2026, the post-OR-2 implementation phase is active).
- Applicability / Impact scope: All Authorized Institutions (AIs) in Hong Kong.
- Recommended management actions:
- Perform a gap analysis between current project-based resilience teams and permanent BAU operating models.
- Review and validate critical operations and disruption tolerances to ensure they reflect current business profiles.
- Formalize training programs to empower all staff to take ownership of operational resilience duties.
- Update risk management and incident response frameworks to specifically account for AI-driven cyber threats.
- Enhance technical infrastructure to automate mapping processes for new services and third-party providers.
Detailed Summary
- Document overview: This circular marks the end of the initial implementation period for SPM module OR-2. It serves as a regulatory directive for AIs to maintain and mature their existing operational resilience frameworks.
- Main requirements:
- Governance: "Tone from the top" remains mandatory; boards must ensure that operational resilience is not siloed in project teams but embedded in daily business functions.
- Parameter Reviews: Consistent with OR-2, the Board must review the criteria for critical operations, the actual list of operations, and disruption tolerances at least annually or upon major changes.
- Proactive Management: AIs are required to maintain a risk-based framework for prioritizing remediation, especially concerning evolving threats like AI-enabled cyber risks.
- Key changes:
- From Project to BAU: Shifting from "1+3 year" project management structures to integrated BAU ownership.
- Maturity Goal: Moving beyond compliance to active "compression" of disruption tolerances where possible.
- Tech-Enabled Resilience: Expectation to move toward automated mapping tools that update in real-time as service ecosystems change.
- Increased Rigor: Testing scenarios should evolve to be increasingly severe compared to initial benchmarks.
- Important dates & transition:
- June 1, 2026: Post-OR-2 monitoring begins. AIs are now in the "sustaining and uplifting" phase.
- Impact and risks:
- Operational: Increased burden to integrate resilience into staff KPIs and training.
- IT/Data: Requirement to increase mapping granularity and automate dependency tracking.
- Compliance: Heightened scrutiny on third-party management and the ability to mitigate AI-powered cyber risks.
- Compliance action checklist:
- [ ] Appoint permanent departmental owners for resilience tasks previously held by project teams.
- [ ] Update staff training curriculum to reflect BAU resilience responsibilities.
- [ ] Re-calibrate scenario testing to include "increasingly severe" disruption events.
- [ ] Review current ICT and cyber security frameworks to address AI-specific threat vectors.
- [ ] Conduct annual board review of critical operation parameters as per OR-2.
- Appendices/attachments summary:
- (N/A) The document contains no separate attachments; references are made to previously issued good practice circulars (Jan 2025/April 2026) and Whole Industry Simulation Exercise reports (2023/2025), which serve as foundational guidance for ongoing maturity.