A reset of Oman's business continuity expectations
On 6 January 2026, the Central Bank of Oman issued Circular BM 1225, introducing a new Business Continuity Management Framework for all licensed banks and finance and leasing companies operating in Oman. Institutions were directed to prepare and finalise their frameworks by 30 June 2026 and implement the requirements promptly.
BM 1225 replaces guidance dating from 2010. That matters because the operating environment has changed substantially. Financial services now depend on digital channels, shared infrastructure, cloud technology, outsourced operations and concentrated service providers in ways that older continuity plans were not designed to address.
The CBO's direction is clear: continuity should be organised around the delivery of critical financial services, not only the recovery of individual systems or locations.
The disruption landscape is broader
The circular identifies a wide range of threats, including cyber incidents, technology and third-party outages, physical events, geopolitical developments, pandemic-related disruption and climate-related risks. It also highlights compound scenarios in which several failures occur at the same time.
This is a realistic view of operational disruption. A technology outage can coincide with loss of connectivity, reduced staff availability or failure at a shared provider. A recovery plan that assumes every other dependency remains available may look complete on paper but fail under the conditions in which it is actually needed.
For Omani institutions, concentration in payment systems, telecommunications networks and service providers makes dependency risk particularly important. Resilience therefore requires an end-to-end understanding of how services are delivered across internal functions and external organisations.
A service-centric approach changes the work
The framework asks institutions to identify critical services, understand their end-to-end dependencies and establish recovery arrangements that can maintain essential banking and financial services through severe but plausible disruption.
This should lead institutions to connect information that often sits in separate inventories. Business impact assessments, application registers, infrastructure maps, vendor records, staffing dependencies, facilities plans and disaster recovery documentation should collectively explain how each critical service operates and where it could fail.
The resulting map should be detailed enough to support decisions. Management should be able to identify single points of failure, concentrations, manual workarounds, recovery dependencies and the sequence in which components must be restored. It should also show where recovery assumptions depend on a third party or on infrastructure shared across the financial sector.
Boards set tolerance; management proves capability
BM 1225 places direct emphasis on the Board and senior management. Boards are expected to set clear expectations, approve appropriate tolerance levels for service disruption and ensure that management allocates resources proportionate to the institution's size, complexity and systemic importance.
Senior management is responsible for turning those expectations into effective strategies, plans and recovery capabilities that are tested regularly. This makes tolerance more than a policy statement. It needs to inform recovery design, technology investment, third-party arrangements, scenario selection and escalation.
Useful management information should show whether each critical service can remain within its approved tolerance, what testing has demonstrated, which vulnerabilities remain unresolved and when remediation will be completed. Where the evidence is weak, the response should be a decision on risk reduction or formal risk acceptance at the right level.
Testing must reflect how disruption happens
Testing should move beyond isolated technical failover. Severe but plausible exercises need to challenge the whole service, including decision-making, communications, staffing, data, facilities and external dependencies. Compound events should be included where they are relevant to the institution's risk profile.
Third-party participation is particularly important. An institution cannot demonstrate resilience for an outsourced critical dependency solely through a contract or a provider's assurance report. It needs evidence that notification, recovery, data access, capacity and escalation arrangements work for the institution's own services and tolerances.
Testing should produce clear findings, accountable actions and retesting where material weaknesses are identified. Independent assurance can then assess whether the programme covers the right services, uses credible scenarios and closes issues effectively, without taking ownership away from the business and technology teams responsible for continuity.
Implementation priorities
Priorities should include completing critical-service and dependency mapping, calibrating disruption tolerances, aligning business and technology recovery plans, reviewing concentration in third-party and shared infrastructure, and conducting end-to-end scenario tests. The framework should also be maintained as services, systems, suppliers and operating models change.
BM 1225 gives Oman a more current basis for business continuity oversight. Its practical value will depend on whether institutions use it to improve the resilience of services in operation, rather than treating completion of the framework as the final outcome.