Beyond seismic zones: Rethinking banking data resilience
Banking regulators need to rethink what “different seismic zones” should mean for data centres and disaster recovery sites, moving beyond building codes to focus on data continuity and operational resilience
ICT governance frameworks of central banks require financial institutions to have robust, sophisticated and manageable ICT infrastructure and application systems.
As an essential component, the regulatory body requires these institutions to have a Data Centre (DC) and Disaster Recovery Site (DRS) in different seismic zones.
My exchanges with AI in this note began last night as I tried to figure out what these seismic zones might be.
I shall outline the exchanges briefly to convey two messages:
- Regulators need to avoid parroting and critically examine terms and concepts that are operationalised to ensure compliance; and
- What a meaningful way to define seismic zones could be. I will deal with the latter, while the first will indirectly be unveiled.
The exchange began with a naive question: "How many seismic zones are there in Bangladesh?"
AI: Bangladesh is divided into four seismic zones — low, moderate, medium-high and highest risk zones.
Those were from the Bangladesh National Building Code (BNBC), meant to capture seismic risks to buildings. It did not take me long to figure out that conventional discourse refers to a seismic zone as a specific geographic region that shares a similar frequency and intensity of earthquakes, classified by its level of geological hazard.
But data centres would have to be built in low-risk areas, not in all "seismic zones" as defined above.
Thus, I asked AI, "Why do you give scales of hazards rather than seismic zones that have high risks?"
Interesting responses came, suggesting that "engineers needed numbers, risk involves people, hazard involves nature", among other things.
Finally, I realised the need to be more precise, and we eventually engaged in an exchange on approaches to define "seismic zones" for the purpose of storing large volumes of data.
Defining "seismic zones" requires shifting from standard structural building codes to a data continuity and operational resilience framework. Standard codes focus on preventing building collapse to save lives, whereas data centre zoning focuses on preventing a nanosecond of downtime or hardware destruction
Defining "seismic zones" requires shifting from standard structural building codes to a data continuity and operational resilience framework. Standard codes focus on preventing building collapse to save lives, whereas data centre zoning focuses on preventing a nanosecond of downtime or hardware destruction, AI suggested.
AI picked up the "paradigm shift" and suggested creating a meaningful seismic zoning map for data storage using a combination of the following specialised criteria:
Peak ground acceleration (PGA) and spectral acceleration (Sa)
The likelihood of the ground accelerating horizontally and vertically at specific frequencies is relevant for assessing potential damage due to mechanical head crashes in hard drives, disruptions in solid-state arrays and fibre-optic alignments, even if the building itself remains perfectly intact.
Microzonation (Soil liquefaction and amplification)
Impacts vary across soft soil and solid bedrock.
Critical infrastructure proximity (The "secondary hazard" zone)
Distance from fault lines crossing power grids, water lines and fibre backbones is relevant because of the centrality of power — grid electricity or fuel-generated.
Non-structural component vulnerability
When AI again produced a green, yellow, orange and red matrix, I insisted on moving away from such hazard colour scales.
Finally, a proposal was made to implement precise risk reduction for data storage: "must abandon hazard colour scales entirely and zone by Failure Domains, Latency Boundaries and Infrastructure Interdependencies."
Instead of mapping how hard the ground shakes, meaningful data zoning maps how far a failure can travel and where data can safely replicate in real time.
Thus, seismic zones are defined based strictly on data engineering and business continuity metrics. Moving away from "Green to Red" risk scales, a data architect zones by recovery objectives.
By now, AI was too keen to develop architecture specific to target recovery point objectives or recovery time objectives — how many minutes of data loss or downtime can your organisation survive? I chose not to pursue this since I had no such parameters specific to an organisation.
However, I asked AI to map the three functional data zones directly onto Bangladesh's geological structures and fibre-grid infrastructure. By overlaying data resilience requirements onto the country's physical geography, the proposal was to split Bangladesh into three distinct data storage zones.
I avoided reproducing the technical details for general readership. Given the current stock of training data, moving from traditional geographic hazard maps to functional data infrastructure boundaries was a major "paradigm shift" for AI.
The above is an exercise by a non-technical person and may be considered a preliminary attempt to operationalise the concept of "seismic zone" to protect data flows and storage, so vital for banking operations.
Initial responses to an attempt by the author to get clear views on interpreting "different seismic zones" were frustrating. Decisions on the choice of sites among operators as well as regulators may be biased by BNBC (building codes).
Such decisions may be better informed if assistance from AI is obtained by asking the right questions and then critically using the responses in conjunction with prior knowledge to make decisions.
Sajjad Zohir is the executive director of the Economic Research Group (ERG).
Disclaimer: The views and opinions expressed in this article are those of the author and do not necessarily reflect the opinions and views of The Business Standard.
