Business Risk and Resilience

Navigating non-financial risk to build resilience and achieve strategic goals.

As organisations face increasing operational complexity, regulatory scrutiny and business disruption, effective risk and resilience practices are essential to protecting organisational value. Amstelveen helps organisations identify, assess and manage non-financial risks while strengthening their ability to respond, recover and adapt. We combine strategic risk insight, regulatory knowledge and practical delivery capability to embed scalable risk and resilience practices across the business.

How we help

Our team comprises experienced risk and resilience professionals, including ISO 22301 certified specialists, who help organisations transform reactive crisis management into proactive, structured approaches that protect assets and ensure the continuity and recovery of operations. We are independent experts who identify vulnerabilities and design practical strategies to strengthen resilience and withstand business disruption.

Strategic Risk

We support organisations to identify and manage emerging risks impacting strategy and operations.
Through horizon scanning and scenario analysis, we assess geopolitical shifts, technology disruption and regulatory change, embedding risk into strategic
planning and governance to align growth with risk appetite and strengthen decision making.

Operational Risk

We partner with Boards, Executives, and frontline risk owners to embed practical risk management into daily operations. This includes designing risk appetite statements, developing control libraries and strengthening incident responses to position
operational risk as a strategic capability that protects business value and supports sustainable growth.

Business Continuity Management

We manage end-to-end BCM uplift programs, including assessment of existing capabilities, execution of Business Impact Analysis (BIA), development of tailored Business Continuity Plans (BCPs) and facilitation of crisis simulation exercises. This enables organisations to enhance preparedness, respond effectively to disruptions and strengthen resilience.

Third-Party Risk Management

We design and implement third-party risk management frameworks to strengthen governance and manage supply chain risk. This includes vendor due diligence, ongoing assessments and supply chain mapping and concentration analysis, improving visibility across the vendor ecosystem and supporting risk informed decision making and regulatory alignment.

Risk in Change

We support organisations in managing risk throughout major change initiatives by conducting delivery and delivered risk assessments, business readiness and transition assurance, and post implementation reviews to assess outcomes and risk effectiveness, helping clients deliver change with confidence.

Augmented Risk and Resilience Support

We provide experienced professionals to strengthen and scale risk and resilience capabilities, supporting both short-term projects and longer-term initiatives to deliver sustained outcomes.

Our services are designed to address the key non-financial risks that can impact organisational performance, resilience and long-term sustainability.

Business Continuity Management

We support clients across the BCM lifecycle, including Business Impact Analysis (BIA), business continuity planning, crisis management exercises, BCM reviews and BCM uplift programs. Our approach helps organisations prepare for disruptions and strengthen organisational resilience.

Learn more

Third-Party Risk Management

We design and embed practical TPRM frameworks that improve visibility of supplier risk, strengthen governance and enhance oversight of critical service providers. We support organisations across the third-party risk management lifecycle from identification and assessment through ongoing monitoring and offboarding.

Learn more

Our Experience

Major Multinational Financial Services Group

CPS 230 Project Implementation and Change Management

Amstelveen supported a Line 1 risk function within a major Australian bank to implement CPS230 Operational Risk Management requirements and prepare for APRA visitation. This included completing CPS230 gap assessments at Stage Gate Reviews, followed by delivery of uplift activities across business continuity, service provider and operational risk capabilities. Amstelveen facilitated process mapping for critical operations management, uplifted Business Continuity Plans, and supported the identification and governance of material service providers relevant to critical operations. They also planned and executed the Change Management program, encompassing training sessions, website updates, in-person events and readiness assessment across the management level through to the C-suite. The engagement strengthened alignment between operational risk, business continuity, and regulatory expectations under CPS230.

Australian Financial Technology Company

Crisis Scenario Design and Simulation

The client is a financial services organisation delivering payments and banking-related services and subject to APRA CPS 230 operational resilience requirements. Amstelveen was engaged to support the uplift of Business Continuity capabilities through the identification and development of plausible disruption scenarios aligned to critical operations and third-party dependencies. This included reviewing existing resilience artefacts, developing a scenario library, and assessing the potential impact of severe but plausible events. Amstelveen designed and facilitated an executive-level crisis simulation, focused on a critical service provider outage impacting payments, to test response effectiveness, decision-making, and communication protocols. The engagement resulted in documented observations and recommendations to enhance crisis response, recovery strategies, and operational resilience maturity.

Major Medical Indemnity Insurer

Third Party Risk Management Managed Service

Amstelveen is engaged by the client to establish and deliver an ongoing Third Party Risk Management (TPRM) managed service to support compliance with CPS 234 Information Security requirements. The engagement involves designing the end-to-end third-party risk assessment framework, including the development of assessment criteria, policies, procedures, and governance processes aligned with CPS 234 and information security obligations. As part of the managed service, Amstelveen conducts risk assessments for both new and existing service providers, evaluating information security controls and identifying areas requiring remediation or enhanced oversight. Amstelveen continues to manage the third-party risk assessment lifecycle on behalf of the client, providing ongoing assurance that material service providers are assessed consistently and in alignment with regulatory expectations and information security requirements.

Major Australian Not-for-Profit

Crisis Management and Business Continuity Management Uplift

The client is a major Australian not-for-profit organisation operating in a complex and evolving risk environment, with increasing cyber threats and operational complexity. Amstelveen was engaged to uplift crisis preparedness through the development of a Crisis Management Plan (CMP) and supporting governance framework. This included defining processes for crisis identification, escalation, and response, alongside the development of tailored response playbooks. The engagement also involved designing and facilitating a cyber crisis simulation, enabling the Executive Leadership Team to exercise decision-making under pressure and test coordination across business units. The exercise assessed crisis communications, stakeholder mobilisation, and operational response, resulting in targeted recommendations to strengthen organisational resilience and continuity capability.

Major Australian Airline

Security Supplier Risk Management

Amstelveen was seconded as part of a Major Australian Airline’s Cyber Security Team to uplift and maintain their Security Supplier Risk Management standards, processes and reporting. This involved developing relevant Standards, Frameworks and redesigning dashboards and metrics for consumption by Executive Management. Additionally, the existing supplier questionnaires were reviewed and uplifted, with a focus on the inclusion of attestations for vulnerability management and data encryption. The team was also responsible for directly managing and training an external managed services provider, who were responsible for liaising with third parties for the triage and completion of security questionnaires.

"Organisations need to understand not only what could go wrong but also how they will respond, recover and adapt when disruption occurs. We help clients build practical risk and resilience capabilities that strengthen decision making, protect critical operations and support long-term organisational success."

Romana Bizjak, Partner - Business Risk and Resilience

Build stronger risk and resilience capabilities

Whether you're uplifting operational risk practices, strengthening business continuity capabilities, improving third-party risk management or delivering major change initiatives, our team can help design and embed practical solutions that enhance resilience and support better decision making.