Kuala Lumpur · Malaysia
Prepared for review
Business Proposal

A volunteer management
platform, built to grow
with every hour logged.

A phased, MVP-first plan for a corporate volunteering system that gives your CSR team one place to run programmes, and your leadership team a clear, auditable record of impact — built with Malaysian data governance in mind from day one.

Prepared for
Public Bank, Malaysia
Prepared by
Green Growth Asia Foundation
Document date
17 August 2026
Version
Proposal v1.0 — MVP scope
01
Overview

Executive summary

Today, employee volunteering across most Malaysian banks runs on spreadsheets, email threads, and department-level goodwill. It works, but it doesn't scale, and it leaves CSR teams unable to answer a simple question with confidence: how many hours did we actually contribute this year, and where?

We propose building a purpose-built Volunteer Management Platform for Public Bank — starting with a lean, fully-functional MVP that replaces manual tracking with a single system of record, and growing in later phases into a full engagement and ESG-reporting engine.

01

One system of record

Every opportunity, sign-up, and logged hour lives in one auditable place — no more chasing spreadsheets across branches.

02

Reporting your CSR team can trust

Exportable participation and impact data, structured to feed directly into your sustainability and ESG disclosures.

03

Built for a bank, from day one

SSO, role-based access, and a data-handling approach aligned to PDPA 2010 and BNM's technology risk expectations.

Why now

Bursa Malaysia's enhanced sustainability reporting requirements and growing investor attention to ESG performance are pushing CSR and community-investment data out of spreadsheets and into board-level reporting. A platform that produces clean, structured volunteering data isn't a nice-to-have anymore — it's becoming part of how listed financial institutions demonstrate their social impact commitments.

02
Why this matters

The business case

Where things stand today

Based on how volunteering programmes typically run inside large Malaysian corporates, we expect the current state looks something like this:

  • Opportunities are announced over email or intranet posts, with sign-ups tracked in shared spreadsheets or forms per branch or department.
  • Hours are self-reported, inconsistently, with no standard proof of participation.
  • CSR teams spend a disproportionate amount of time consolidating data manually ahead of quarterly or annual reporting.
  • Leadership has limited real-time visibility into participation trends across branches, regions, or departments.
  • There's no consistent way to tie volunteering activity back to the bank's broader ESG or Value-Based Intermediation (VBI) commitments.

What this costs the organisation

Administrative drag

Manual consolidation across branches typically consumes days of CSR staff time per reporting cycle — time better spent designing programmes than chasing data.

Reporting risk

Self-reported, unverified hours are hard to defend in an audit or sustainability assurance review — a growing concern as ESG disclosures face more scrutiny.

Low engagement visibility

Without a central view, it's difficult to tell which branches or departments are disengaged, or which causes resonate most with staff.

Missed storytelling

Great volunteering moments go undocumented and unshared, weakening the internal case for continued CSR investment.

Why now, specifically for a Malaysian bank

Sustainability reporting expectations under Bursa Malaysia's listing framework, growing regulatory attention to community and social impact from Bank Negara Malaysia, and rising employee expectations around purpose-driven work are converging. A structured platform turns volunteering from a goodwill initiative into a measurable, reportable business function.

03
The idea

Proposed solution overview

A single web platform with three connected views — one for employees, one for CSR administrators, and one for leadership reporting — built around one straightforward loop.

Step 1Admin publishes

CSR team creates a volunteering opportunity — cause, date, location, capacity, whether it's virtual or in-person.

Step 2Employee signs up

Staff browse opportunities, RSVP in one click, and the event syncs to their Outlook or Google calendar automatically.

Step 3Hours are logged

After the activity, hours are recorded — self-logged with lightweight proof, or confirmed by an event organiser.

Step 4Impact is reported

Admins and leadership see consolidated participation data, exportable for internal reporting and sustainability disclosures.

Design principle

We are deliberately not proposing a full enterprise CSR suite on day one. The goal of the MVP is to prove this loop works end to end, replaces your current manual process, and gives you real data — before we invest in the more advanced engagement and integration features described in the roadmap.

04
Phase 1

MVP scope

Everything below is what we propose building and delivering in the initial engagement. Nothing here depends on features from later phases.

Employee-facing features
FeatureWhat it does
Opportunity browserSearch and filter volunteering opportunities by cause, date, location, and format (virtual or in-person).
One-click sign-upRSVP to an opportunity directly from the listing, with automatic capacity tracking.
Personal dashboardA staff member's own history — hours logged, opportunities joined, upcoming commitments.
Manual hour loggingLog hours after an activity with a simple proof attachment (photo or organiser confirmation).
NotificationsEmail and in-app reminders ahead of upcoming sign-ups and deadlines.
CSR administrator features
FeatureWhat it does
Opportunity managementCreate, edit, publish, and close volunteering opportunities.
Sign-up & hours approvalReview and approve sign-ups and submitted hour logs.
Admin dashboardLive view of total hours, active participants, and opportunities currently open.
Reporting exportCSV/Excel export of participation and hours data for internal and CSR reporting.
Access, security & platform
FeatureWhat it does
Single sign-onLogin via your corporate identity provider (Azure AD / Okta), no separate credentials.
Role-based accessTwo roles at MVP stage — Employee and Administrator — each seeing only what they need.
Data protection baselineEncryption at rest and in transit, access logging, aligned to PDPA 2010 handling principles.
Web platformFully responsive web application — works on desktop and mobile browsers; no native app at this stage.
Calendar syncAdd-to-calendar on RSVP, compatible with Outlook and Google Calendar.
Explicitly out of scope for MVP

Gamification and leaderboards, the NGO/partner self-service portal, native mobile apps, HRIS/payroll integration, and ESG-framework-aligned report generation are all real, valuable features — and they're exactly what Phase 2 and Phase 3 are for. We've kept them out of the MVP so the first release stays fast to build, easy to test, and low-risk to approve.

05
What comes next

Roadmap — future phases

The MVP is designed to be extended, not replaced. Phase 2 and Phase 3 are presented here to show the full trajectory of the platform, and to inform architecture decisions we make now.

Phase 2 — Engagement & scale Phase 2

  • Gamification — badges, points, and milestone recognition
  • Recognition features — Volunteer of the Month, leadership shout-outs
  • Team and branch-level group sign-ups
  • NGO / community partner portal for submitting opportunity requests
  • Advanced analytics — trends by department, branch, and region
  • Push notifications and Microsoft Teams integration
  • Recurring volunteering commitments (e.g. weekly mentoring)
  • Manager approval workflow for Volunteer Time Off (VTO) requests

Phase 3 — Enterprise & strategic depth Phase 3

  • HRIS/payroll integration for automated VTO sync and headcount mapping
  • Matching-gift and payroll donation programmes tied to volunteering hours
  • Grant and fund disbursement tracking to NGO partners
  • ESG/sustainability report generation, structured for GRI and Bursa Malaysia disclosure formats
  • AI-based opportunity recommendations based on employee interests
  • Native mobile application
  • Multi-language support (Bahasa Malaysia, English, Mandarin)
  • Disaster-response rapid mobilisation mode
  • Background-check tracking for programmes involving vulnerable groups
06
How it's built

Technical architecture

Hosting model

Cloud-hosted (AWS or Azure), with data residency configured to your requirements. We will confirm whether in-country hosting in Malaysia is required before finalising this, given BNM's expectations for regulated financial institutions.

Application stack

A standard, well-supported web stack — a modern JavaScript frontend, a REST API backend, and a managed relational database. Nothing exotic; chosen for long-term maintainability, not novelty.

Identity & access

SSO via SAML/OAuth 2.0 against your corporate identity provider. No parallel password system for your staff to manage.

Integration approach

Calendar sync via standard Outlook/Google APIs at MVP; HRIS and Teams integrations scoped for Phase 2/3 via documented REST APIs.

Scalability

The MVP is architected to comfortably support your full employee base from day one, with headroom for concurrent usage spikes around large seasonal campaigns (e.g. flood relief drives, Financial Literacy Month). We size infrastructure for your actual headcount once confirmed during discovery.

07
Non-negotiable for a bank

Security & data privacy

This platform will hold employee personal data. We treat that with the same seriousness your organisation applies to any system touching staff records — not with the lighter posture sometimes given to "CSR tools."

AreaOur approach
EncryptionTLS 1.2+ in transit; AES-256 at rest for all stored personal data.
AuthenticationSSO via your identity provider; MFA enforced at the IdP level, not bypassed by the platform.
Access controlRole-based access control (RBAC), least-privilege by default, full access logging.
Data residencyConfigurable hosting region; in-country Malaysian hosting available if required by your vendor risk policy.
PDPA alignmentData collection, consent language, and retention practices aligned to the Personal Data Protection Act 2010.
Retention & deletionDefined retention schedule with documented deletion process for departed employees, on request.
TestingIndependent penetration testing prior to go-live, with findings shared and remediated before launch.
On certifications

We want to be direct: as this is a newly-scoped software engagement, formal certifications such as ISO 27001 or SOC 2 for this specific platform will be pursued as part of the engagement roadmap rather than already in place. We are fully prepared to complete your vendor security questionnaire and welcome an early security review with your IT/InfoSec team — we'd rather surface any gaps during discovery than at go-live.

08
Working within your framework

Compliance & governance

  • Audit trail: every sign-up, hour submission, and approval is logged with a timestamp and actor, and retrievable for audit purposes.
  • Role-based access control: Employee and Administrator roles at MVP, with clear separation of what each can view or change.
  • Vendor risk process: we expect to complete your standard vendor onboarding and technology risk assessment, and we'll build our project timeline around that review rather than around it.
  • ESG/sustainability alignment: the data model captures hours, causes, and participation in a structure that can later feed GRI-aligned or Bursa Malaysia sustainability disclosures, even though report generation itself is a Phase 3 feature.
09
From kickoff to launch

Implementation timeline

Phase ADiscoveryWeeks 1–2

Requirements workshops with your CSR and IT teams, confirmation of SSO provider, hosting/data residency requirements, and existing branch/department structure.

Phase BDesignWeeks 3–4

UX flows and visual design for all three views (employee, admin, reporting), reviewed and signed off with you before development begins.

Phase CDevelopmentWeeks 5–10

Build in two-week sprints, with a working demo shared at the end of each sprint.

Phase DUATWeeks 11–12

Structured user acceptance testing with a nominated group from your CSR team, tracked against a formal sign-off checklist.

Phase ELaunch & hypercareWeeks 13–14

Go-live, staff communications support, and two weeks of hypercare with priority response to any issues.

Total indicative timeline: ~14 weeks from discovery kickoff to go-live, subject to confirmation during Phase A and your vendor risk review process.

10
Who's behind this

Team & credentials

Green Growth Asia Foundation is a not-for-profit organisation incorporated in Malaysia, dedicated to supporting strong, inclusive, and sustainable economic growth across emerging economies in Asia — with a long-standing focus on climate action, ESG practice, and community empowerment.

Our work has centred on programme design and delivery rather than commercial software development — but running large-scale community and sustainability programmes across the region for many years has required exactly the kind of operational infrastructure this proposal describes. Over that time, we've built an internal technical team capable of specifying, managing, and delivering software projects of this scale, and this platform reflects how we believe a corporate volunteering system should actually work in practice, having run programmes like it ourselves.

A note on this section

We're keeping formal staff bios, past client references, and detailed team CVs out of this initial proposal. A fuller team and credentials profile — including our technical delivery lead, project management approach, and relevant programme case studies — will follow once there's mutual interest in proceeding to a detailed scoping conversation.

11
Investment

Commercial model

ItemBasisIndicative
MVP buildFixed-price, scoped against Section 445K to 50K
Hosting & infrastructureMonthly, cloud usage-basedas per the prefered deployment platform
Support & maintenanceMonthly retainer, post-warrantyincluded for first 3 months
Phase 2 (indicative)Scoped separately post-MVPTo be scoped
Phase 3 (indicative)Scoped separately post-MVPTo be scoped

Figures above are placeholders pending a detailed scoping conversation on headcount, branch count, and integration requirements — we'd rather price this precisely against confirmed requirements than offer a number that shifts later.

Payment milestones

  • Milestone 1 — on signing: project kickoff and discovery
  • Milestone 2 — on design sign-off
  • Milestone 3 — on UAT sign-off
  • Milestone 4 — on go-live
12
After launch

Support & SLA

Warranty period

30 days post-launch, all defects fixed at no additional cost.

Ongoing support

Monthly retainer covering maintenance, minor enhancements, and platform monitoring.

Response targets

Critical issues: same business day. Standard issues: within 3 business days.

A full SLA document — including uptime commitment, escalation matrix, and named support contacts — will be issued alongside the final contract.

13
Being upfront

Risks & mitigations

RiskSeverityMitigation
Vendor security review extends timelineHighWe build the review into Phase A rather than treating it as a gate at the end; early InfoSec involvement.
Low initial staff adoptionMediumLaunch communications plan, pilot with 1–2 branches before org-wide rollout.
SSO/IdP integration delaysMediumConfirm IdP details and test access in Week 1 of discovery, not at development handoff.
Scope creep into Phase 2 featuresLowMVP scope is fixed at contract signing; new requests are logged for Phase 2, not folded in mid-build.
Data residency requirement identified lateMediumConfirmed explicitly during Phase A before infrastructure is provisioned.
14
What we'll need from you

Assumptions & dependencies

  • Timely access to a nominated CSR and IT stakeholder for discovery and UAT sign-off.
  • Access to a test/sandbox environment for your identity provider (Azure AD / Okta) during development.
  • Content for initial volunteering opportunities to populate the platform ahead of launch.
  • Confirmation of employee headcount and branch structure for infrastructure sizing.
  • Reasonable availability of your vendor risk/InfoSec team during Phase A to avoid downstream delays.
  • Scope is fixed to Section 4 (MVP); requests outside this scope are logged for future phases rather than absorbed into the current build.
15
Moving forward

Next steps

Let's confirm scope and get a discovery workshop on the calendar.

We'd suggest a 60–90 minute session with your CSR and IT/InfoSec stakeholders to walk through this proposal, confirm the MVP feature list against your actual needs, and align on your vendor risk process upfront — before any commercial terms are finalised.

Step 1
Review this proposal internally
Step 2
Schedule a discovery workshop
Step 3
Confirm MVP scope & commercial terms