MARSAD
Methodology/ OpRes lifecycle

Identify, map, test, declare, evidence, and start again.

Operational resilience is not a project. It is a recurring cycle that the bank ought to be able to walk a regulator through at any moment.

What it is

The OpRes lifecycle is the spine SAMA's framework expects. Five recurring stages, each producing artefacts that feed the next:

Why it matters

SAMA's framework asks for a posture, not a one-off study. The lifecycle is the loop that keeps that posture honest. A bank that can produce a six-month-old declaration but no recent test, or recent tests but no traceable findings, has gaps a regulator will notice quickly.

The bank's own benefit is comparable. If the cycle is operating, the next BCM exercise, the next vendor incident, the next SAMA inspection don't all start from a blank page.

How MARSAD frames it

MARSAD organises the work around four governance pillars, each producing artefacts the lifecycle consumes:

Findings & actions Periodic attestations Resilience tests Third parties

The pillars are wired to each other so the lifecycle is one coherent loop rather than four parallel streams. A failed resilience test, for example, opens a finding automatically and threads its remediation through the right workflow. A third-party incident that affects an IBS lands as evidence on that service's record. The OpRes scorecard rolls all of this up by IBS, by outcome category, and against MVB scope so you can see where the cycle is healthy and where it has stalled.

Design note. The lifecycle is deliberately circular, not linear. There is no "we're done" state for operational resilience, only a more or less recent set of artefacts. MARSAD's role is to make the loop traceable.

What customers see

Related methodology