Ebook

[BCM] [Damanat] [E1] [C8] Implementing the BCM Planning Methodology

Written by Moh Heng Goh | Jul 24, 2026 7:16:53 AM

eBook 1: Chapter 8

Business Continuity Management Planning Methodology for The Saudi Mortgage Guarantees Services Company (Damanat)

 

 

Introduction

A Business Continuity Management (BCM) programme is most effective when implemented using a structured, repeatable, and well-governed methodology.

Rather than developing Business Continuity Plans in isolation, organisations should adopt a systematic approach that progressively builds organisational resilience through a series of interrelated activities.

Each phase produces outputs that become essential inputs to the next phase, ensuring that continuity planning is evidence-based, risk-informed, and aligned with business priorities.

For the Saudi Mortgage Guarantees Services Company (Damanat), the BCM Planning Methodology provides a practical roadmap for establishing, implementing, maintaining, and continually improving the organisation's continuity capability.

The methodology translates the strategic direction established in this chapter into a structured implementation programme that supports Damanat's operational responsibilities, regulatory obligations, and organisational resilience objectives.

The methodology presented in this eBook consists of seven integrated phases:

  1. Project Management
  2. Risk Analysis and Review (RAR)
  3. Business Impact Analysis (BIA)
  4. Business Continuity Strategy (BCS)
  5. Plan Development (PD)
  6. Testing and Exercising (T&E)
  7. Programme Management (PgM)

Each phase has a distinct purpose while remaining closely connected to the preceding and subsequent phases. Collectively, they establish a continual improvement cycle that enables Damanat to maintain effective continuity capabilities as its operating environment evolves.

 

Principles of the BCM Planning Methodology

The proposed methodology is designed around several fundamental principles:

Business-Driven

Business continuity requirements should be determined by Damanat's operational priorities rather than by technology capabilities alone.

Recovery decisions should focus on maintaining Critical Business Functions (CBFs) that support the organisation's mandate.

Risk-Informed

Planning should be guided by an understanding of credible threats, vulnerabilities, existing controls, and potential business consequences.

Resources should be directed toward areas of greatest operational significance.

Impact-Based

Recovery priorities should be determined through Business Impact Analysis, ensuring that functions with the greatest operational, regulatory, financial, and reputational consequences receive appropriate attention.

Integrated

BCM should operate as an enterprise programme that complements Enterprise Risk Management, Operational Risk Management, Crisis Management, ICT Disaster Recovery, Cybersecurity, and Operational Resilience.

Scalable

The methodology should be sufficiently flexible to accommodate changes in organisational structure, business priorities, regulatory expectations, and emerging risks without requiring fundamental redesign.

Continually Improved

Business Continuity Management is an ongoing management discipline. Every exercise, incident, audit, management review, and organisational change provides opportunities to strengthen resilience and improve recovery capability.

 

The Seven-Phase BCM Planning Methodology

Phase 1: Project Management (PjM)

Purpose

To establish the governance, leadership, scope, resources, and implementation structure required for BCM.

Key Activities
  • Obtain executive sponsorship.
  • Establish BCM governance.
  • Define programme scope.
  • Appoint the BCM Programme Manager.
  • Form the BCM Steering Committee.
  • Develop the implementation roadmap.
  • Allocate resources.
  • Establish document control.
  • Define reporting arrangements.
  • Communicate the programme.
Main Inputs
  • Organisational strategy.
  • Executive direction.
  • Regulatory expectations.
  • BCM Policy.
  • Available resources.
Main Outputs
  • Approved BCM project charter.
  • Governance structure.
  • Implementation roadmap.
  • Communication plan.
  • Project schedule.
  • Resource plan.
Responsible Roles
  • Senior Management.
  • BCM Steering Committee.
  • BCM Programme Manager.
Connection to the Next Phase

A properly governed project provides the organisational framework required to perform the Risk Analysis and Review in a consistent and coordinated manner.

 

Phase 2: Risk Analysis and Review (RAR)

Purpose

Risk Analysis and Review identifies the threats that may disrupt Damanat's operations, evaluates vulnerabilities, reviews existing controls, and establishes the organisation's disruption risk profile.

Principal Activities
  • Identify threats.
  • Assess vulnerabilities.
  • Review existing controls.
  • Evaluate likelihood.
  • Assess consequences.
  • Document risks.
  • Recommend treatment options.
Main Inputs
  • Organisational context.
  • Operating environment analysis.
  • Historical incidents.
  • Threat intelligence.
  • Regulatory guidance.
Main Outputs
  • Threat Register.
  • Risk Register.
  • Control assessment.
  • Risk treatment recommendations.
  • Residual risk profile.
Responsible Roles
  • Enterprise Risk Management.
  • BCM Programme Manager.
  • Business Unit Representatives.
Connection to the Next Phase

The identified threats provide the disruption scenarios that will be analysed during the Business Impact Analysis.

 

 

Phase 3: Business Impact Analysis (BIA)

Purpose

The Business Impact Analysis determines which business functions are critical and establishes recovery priorities based on the consequences of disruption.

Principal Activities
  • Identify Critical Business Functions.
  • Assess operational impacts.
  • Determine financial impacts.
  • Assess regulatory consequences.
  • Evaluate stakeholder impacts.
  • Identify resource dependencies.
  • Determine recovery requirements.
Main Inputs
  • Approved organisational context.
  • Threat information.
  • Business process information.
  • Management interviews.
Main Outputs
  • Business Impact Analysis Report.
  • Critical Business Function Catalogue.
  • Recovery priorities.
  • Resource dependency maps.
  • Recovery requirements.
Responsible Roles
  • BCM Programme Manager.
  • CBF Owners.
  • Business Unit Coordinators.
Connection to the Next Phase

Recovery requirements established during the BIA form the basis for selecting appropriate Business Continuity Strategies.

 

Phase 4: Business Continuity Strategy (BCS)

Purpose

Business Continuity Strategy identifies practical measures that enable Damanat to maintain or restore Critical Business Functions within acceptable operational limits.

Principal Activities
  • Evaluate continuity options.
  • Assess alternative workplaces.
  • Determine technology recovery approaches.
  • Review supplier resilience.
  • Identify staffing arrangements.
  • Confirm information recovery methods.
  • Recommend recovery strategies.
Main Inputs
  • Business Impact Analysis.
  • Resource requirements.
  • Organisational constraints.
  • Risk assessment results.
Main Outputs
  • Approved Business Continuity Strategies.
  • Resource plans.
  • Technology recovery approach.
  • Alternate workplace arrangements.
  • Supplier continuity strategies.
Responsible Roles
  • BCM Steering Committee.
  • Business Unit Heads.
  • ICT.
  • Facilities.
  • Procurement.
Connection to the Next Phase

Approved strategies provide the operational framework used to develop Business Continuity Plans.

 

Phase 5: Plan Development (PD)

Purpose

Plan Development documents the procedures that will be followed before, during, and after a disruptive incident.

Principal Activities
  • Prepare Business Continuity Plans.
  • Develop departmental recovery procedures.
  • Establish contact lists.
  • Document recovery actions.
  • Develop escalation procedures.
  • Prepare communication templates.
  • Establish document control.
Main Inputs
  • Approved Business Continuity Strategies.
  • Recovery requirements.
  • Organisational policies.
Main Outputs
  • Business Continuity Plans.
  • Department recovery procedures.
  • Crisis support documentation.
  • Contact directories.
  • Resource inventories.
Responsible Roles
  • BCM Programme Manager.
  • Business Unit Coordinators.
  • Critical Business Function Owners.
Connection to the Next Phase

Completed plans are validated through structured Testing and Exercising activities.

 

Phase 6: Testing and Exercising (TE)

Purpose

Testing and Exercising confirms that Business Continuity Plans are practical, accurate, and capable of supporting effective recovery.

Principal Activities
  • Conduct document reviews.
  • Facilitate walkthrough exercises.
  • Perform tabletop simulations.
  • Execute functional exercises.
  • Test ICT Disaster Recovery.
  • Validate communication procedures.
  • Record lessons learned.
Main Inputs
  • Business Continuity Plans.
  • Crisis scenarios.
  • Exercise objectives.
Main Outputs
  • Exercise reports.
  • Improvement recommendations.
  • Corrective action plans.
  • Updated continuity documentation.
Responsible Roles
  • BCM Programme Manager.
  • Crisis Management Team.
  • Business Units.
  • ICT Disaster Recovery Team.
Connection to the Next Phase

Lessons learned from testing become key inputs to the Programme Management phase.

 

Phase 7: Programme Management (PgM)

Purpose

Programme Management ensures that BCM remains effective throughout the organisation's lifecycle through governance, monitoring, maintenance, and continual improvement.

Principal Activities
  • Monitor programme performance.
  • Conduct management reviews.
  • Coordinate audits.
  • Update documentation.
  • Monitor organisational change.
  • Review lessons learned.
  • Improve programme maturity.
Main Inputs
  • Exercise reports.
  • Incident reports.
  • Audit findings.
  • Management reviews.
  • Organisational changes.
Main Outputs
  • Updated BCM documentation.
  • Performance reports.
  • Improvement plans.
  • Management review reports.
  • Revised implementation roadmap.
Responsible Roles
  • BCM Steering Committee.
  • BCM Programme Manager.
  • Senior Management.

Connection to the Next Cycle

Programme Management feeds continuous improvements back into Project Management whenever significant organisational, technological, or regulatory changes occur, creating a continual improvement cycle.

Table 1.8: BCM Planning Methodology for The Saudi Mortgage Guarantees Services Company (Damanat)

 

BCM Phase

Purpose

Key Activities

Main Deliverables

Primary Owner

Management Approval

Project Management

Establish governance and implementation framework

Governance, scope, planning, resource allocation

BCM Charter, Project Plan, Governance Structure

BCM Programme Manager

Senior Management

Risk Analysis and Review

Identify threats and evaluate risks

Threat identification, control assessment, risk evaluation

Threat Register, Risk Register

Enterprise Risk Management

BCM Steering Committee

Business Impact Analysis

Determine business impacts and recovery priorities

Impact assessment, dependency analysis, recovery requirements

BIA Report, CBF Catalogue

BCM Programme Manager

Business Unit Heads

Business Continuity Strategy

Select appropriate continuity solutions

Strategy evaluation, resource planning, recovery options

Business Continuity Strategy Report

BCM Steering Committee

Senior Management

Plan Development

Develop documented recovery procedures

BCP development, contact lists, recovery documentation

Business Continuity Plans

CBF Owners

Business Unit Heads

Testing and Exercising

Validate recovery capability

Exercises, simulations, ICT testing, lessons learned

Exercise Reports, Improvement Actions

BCM Programme Manager

BCM Steering Committee

Programme Management

Sustain and continually improve BCM

Reviews, audits, maintenance, reporting, continual improvement

Management Review Reports, Updated Documentation

BCM Steering Committee

Senior Management

 

Characteristics of an Effective BCM Planning Methodology

For Damanat, the BCM Planning Methodology should exhibit the following characteristics:

  • Scalable: Adaptable to organisational growth, restructuring, and changes in business priorities.
  • Risk-informed: Guided by credible threats, vulnerabilities, and business risks.
  • Impact-driven: Prioritises recovery based on the consequences of disruption rather than organisational hierarchy.
  • Integrated: Aligns with Enterprise Risk Management, Crisis Management, ICT Disaster Recovery, Cybersecurity, and Operational Resilience.
  • Supported by documented information: Ensures that policies, procedures, assessments, and plans remain controlled, accessible, and current.
  • Subject to regular review: Reflects organisational changes, regulatory developments, and lessons learned.
  • Continuously improved: Incorporates findings from exercises, incidents, audits, and management reviews to enhance resilience over time.

 

Relationship to eBooks 2 and 3

This chapter introduces the overall BCM Planning Methodology at a conceptual level. eBook 2 expands each of the seven phases in detail, providing implementation guidance, recommended practices, and practical considerations for Damanat's BCM programme.

eBook 3 translates the methodology into organisation-specific outputs, including completed templates, assessments, recovery strategies, Business Continuity Plans, testing documentation, and programme management artefacts.

Together, the three eBooks provide a structured progression from understanding the organisational context, through methodology design, to practical implementation, enabling Damanat to establish a sustainable and continually improving Business Continuity Management programme.

 

The BCM Planning Methodology provides Damanat with a structured and repeatable approach for implementing Business Continuity Management through seven integrated phases, from project initiation to continual programme improvement.

This methodology ensures that planning activities are logically sequenced, evidence-based, and aligned with organisational priorities and regulatory expectations.

With the implementation framework established, attention now turns to understanding the threats and risks that could affect Damanat's operations.

Assessing these risks enables the organisation to prioritise continuity planning and develop appropriate recovery strategies based on credible disruption scenarios.

 

eBook 1: Understanding Your Organisation
C1 C2 C3 C4 C5 C6
C7 C8 C9 C10 C11 C12
 

More Information About Business Continuity Management Courses

 

To learn more about the course and schedule, click the buttons below for BCM-300 Business Continuity Management Implementer [BCM-3] and BCM-5000 Business Continuity Management Expert Implementer [BCM-5].

Please feel free to send us a note if you have any questions.