洞察
Scott Graham / Unsplash — board packs and operational evidence
REGULATORY

HKMA OR-2: the evidence pack your board needs before May 2026

A pragmatic checklist for banks and their outsourced data-center providers — mapped to severe-but-plausible scenarios, tolerance for disruption, and third-party dependency mapping.

ReliDC Reliability Desk24 Jun 20268 min read

With less than a year to the HKMA's OR-2 effective date, most Hong Kong-authorised institutions we speak to have a policy document — but not an evidence pack. The distinction matters: examiners will ask to see the assets, the scenarios, and the recovery telemetry, not the intent.

OR-2 is not another annual attestation exercise. It expects continuous, evidenced mapping of critical operations to the facilities that support them — including third-party data halls — and severe-but-plausible scenario testing against measurable impact tolerances.

We recommend structuring the pack around four artefacts. First, a critical-operations register that names each operation and links it to the underlying facility assets (hall, power train, cooling plant, interconnect). Second, a tolerance-for-disruption statement per operation with measurable recovery objectives — not qualitative adjectives. Third, a severe-but-plausible scenario library covering cooling loss, utility loss, concurrent maintenance failure, and interconnect loss. Fourth, a third-party dependency map that names the specific data hall, not just the vendor brand.

The last item is where most banks stall. Naming 'Provider X, HK' is not sufficient. OR-2 expects the specific hall, the specific UPS bus, and the concentration risk if two critical operations share a single point of failure.

For colo providers serving bank tenants, the commercial implication is clear: screenshot dashboards will not clear a review. Tenants will ask for living asset models, FMEA-ranked risk registers, and scenario evidence packs they can put in front of their board.

Start with one hall. Produce the four artefacts. Stress-test them with your CRO and facilities lead. Then scale across the campus. That sequence beats a last-minute binder every time.

重點
  • Policy documents are not evidence packs — examiners want assets, scenarios, and telemetry.
  • Name halls and power trains, not just vendor brands.
  • Include interconnect / DCI loss in severe-but-plausible scenarios where fabric is shared.
  • One-hall pilot packs scale faster than enterprise-wide paper exercises.
下一步

想把這套分析套用到您的設施?

預約固定範圍的可靠性評估——一間機房或一個園區,約四至八週。

預約評估 →