.

Implementing Business Continuity Management for The Saudi Mortgage Guarantees Services Company: An Enterprise Implementation Guide
BB BCM CGC_with Cert Logo_v1-12

[BCM] [Damanat] [E2] [C1] Business Continuity Management Planning Methodology

[BCM] [Damanat] [Full Banner] Implementing BCM for The Saudi Mortgage Guarantees Services Company

A successful Business Continuity Management (BCM) programme requires a structured, repeatable methodology that guides the organisation through planning, implementation, validation, maintenance, and continual improvement.x eBook Cover [BCM] [Damanat] [E2] [2D]

This chapter introduces the Business Continuity Management Planning Methodology for Damanat, which provides the implementation framework for the subsequent chapters of this eBook.

The methodology is aligned with the management-system principles of ISO 22301 – Security and resilience — Business continuity management systems — Requirements and is structured to support the Saudi Arabian regulatory environment in which Damanat operates.

The methodology consists of seven interconnected phases:

    1.ProjectManagement(PM)BCM Planning Methodology
    2. Risk Analysis and Review (RAR)
    3. Business Impact Analysis (BIA)
    4. Business Continuity Strategy (BCS)
    5. Plan Development (PD)
    6. Testing and Exercising (TE)
    7. Program Management (PgM)

Together, these phases establish a lifecycle for developing, implementing, validating, maintaining, and continually improving BCM within Damanat.

New call-to-action

Dr Goh Moh Heng
Business Continuity Management Certified Planner-Specialist-Expert

Damanat Legal Disclaimer Banner

eBook 2: Chapter 1

New call-to-action

Business Continuity Management Planning Methodology for The Saudi Mortgage Guarantees Services Company

 

 

Introduction

x eBook Cover [BCM] [Damanat] [E2] [2D][BCM] [Damanat] [E2] [C1] Business Continuity Management Planning MethodologyThis chapter introduces the Business Continuity Management Planning Methodology for Damanat, which provides the implementation framework for the subsequent chapters of this eBook.

The methodology is aligned with the management-system principles of ISO 22301 – Security and resilience — Business continuity management systems — Requirements and is structured to support the Saudi Arabian regulatory environment in which Damanat operates.
New call-to-action

The methodology consists of seven interconnected phases:

    1. Project Management (PM)
    2. Risk Analysis and Review (RAR)
    3. Business Impact Analysis (BIA)
    4. Business Continuity Strategy (BCS)
    5. Plan Development (PD)
    6. Testing and Exercising (TE)
    7. Program Management (PgM)

Together, these phases establish a lifecycle for developing, implementing, validating, maintaining, and continually improving BCM within Damanat.

 

BCM Planning Methodology

The BCM Planning Methodology provides Damanat with a consistent approach for translating organisational, operational, regulatory, and resilience requirements into practical continuity capabilities.

The methodology should be applied across the organisation and should involve business functions, technology, risk management, compliance, facilities, human resources, communications, third-party management, and other relevant supporting functions.

The seven phases should not be treated as isolated activities. Outputs from one phase become important inputs into subsequent phases.

For example, the Risk Analysis and Review identifies threats that could disrupt Damanat, while the Business Impact Analysis establishes which activities require priority recovery. These findings subsequently influence the selection of continuity strategies and the development of Business Continuity Plans.

Testing and Exercising then validates whether these arrangements can operate under realistic disruption conditions, while Program Management ensures that the entire BCM capability remains current and effective.

Seven Phases of the BCM Planning Methodology

Phase

BCM Phase

Primary Purpose

Key Outcomes for Damanat

1

Project Management (PM)

Establish and manage the BCM implementation project

Scope, governance, responsibilities, project schedule, resources and implementation oversight

2

Risk Analysis and Review (RAR)

Identify and assess disruption threats

Threat register, risk assessment, existing controls, vulnerabilities and treatment requirements

3

Business Impact Analysis (BIA)

Determine the consequences of disruption and recovery priorities

Critical business functions, recovery requirements, dependencies, MBCO, RTO and resource requirements

4

Business Continuity Strategy (BCS)

Determine how critical activities will be recovered

People, premises, technology, information, supplier and operational recovery strategies

5

Plan Development (PD)

Document response and recovery arrangements

Business Continuity Plans, procedures, activation arrangements, escalation and recovery actions

6

Testing and Exercising (TE)

Validate plans, strategies and organisational readiness

Exercise results, capability gaps, lessons learned and corrective actions

7

Program Management (PgM)

Maintain and continually improve BCM

Governance, training, awareness, reviews, audits, maintenance and continual improvement

 

The Seven-Phase BCM Planning Methodology

New call-to-actionPhase 1: Project Management (PM)

[BCM] [Damanat] [E2] [C2] Project ManagementProject Management establishes the foundation for implementing BCM across Damanat.

Before detailed BCM analysis begins, Damanat should establish the scope, objectives, governance arrangements, responsibilities, resources, deliverables, implementation schedule, and reporting mechanisms for the BCM initiative.

The project should identify the business functions and supporting activities included within the BCM scope and determine the individuals responsible for providing operational information and approving BCM outputs.

Particular attention should be given to establishing clear ownership between the central BCM function and business-function representatives.

Key activities should include:
  • defining BCM project objectives and scope;
  • establishing BCM governance and sponsorship;
  • appointing the BCM project team;
  • identifying Business Continuity Coordinators;
  • defining roles and responsibilities;
  • establishing project milestones and deliverables;
  • identifying documentation requirements;
  • establishing management reporting arrangements;
  • conducting stakeholder briefings and workshops; and
  • monitoring implementation progress.

The output from this phase provides the organisational structure through which the remaining BCM phases can be implemented.

 

New call-to-action

Phase 2: Risk Analysis and Review (RAR)

[BCM] [Damanat] [E2] [C3] Risk Analysis and Review Risk Analysis and Review identifies the threats and vulnerabilities that could cause significant disruption to Damanat's operations.

The objective is not merely to produce a general enterprise risk register.

The RAR should specifically examine business continuity risks—events and circumstances that can interrupt critical business functions, supporting resources, technology, facilities, personnel, information, or external dependencies.

Potential disruption scenarios may include technology failures, cyber incidents, telecommunications outages, loss of premises, utility disruption, loss of critical personnel, third-party failure, physical security incidents, natural hazards, infrastructure disruption, and other operational events relevant to Damanat.

For each identified threat, Damanat should assess:

  • likelihood of occurrence;
  • potential disruption impact;
  • existing preventive and mitigating controls;
  • vulnerabilities and single points of failure;
  • residual exposure;
  • adequacy of existing controls; and
  • additional treatment measures where required.

The resulting Threat and Risk Register provides an important input into continuity strategy development and scenario design for subsequent BCM exercises.

 

New call-to-action

Phase 3: Business Impact Analysis (BIA)

The Business Impact Analysis determines which activities are most important to Damanat and establishes their recovery requirements following disruption.

Rather than asking only what could go wrong, the BIA asks:

What would happen if a particular business function or activity could no longer be performed?

[BCM] [Damanat] [E2] [C4] Business Impact AnalysisThe BIA should examine how the consequences of disruption increase over time and determine when those consequences become unacceptable.

For Damanat, impact assessment should consider relevant categories such as:

  • financial impact;
  • operational impact;
  • customer and beneficiary impact;
  • legal and contractual impact;
  • regulatory impact;
  • reputational impact; and
  • strategic impact.

The BIA should establish appropriate recovery requirements, including where applicable:

  • Maximum Acceptable Outage (MAO);
  • Maximum Business Continuity Objective (MBCO);
  • Recovery Time Objective (RTO);
  • Recovery Point Objective (RPO);
  • minimum staffing requirements;
  • technology requirements;
  • information and data requirements;
  • premises requirements;
  • internal dependencies;
  • external dependencies; and
  • critical supplier and service-provider dependencies.

The results allow Damanat to prioritise recovery based on business impact rather than attempting to recover every activity simultaneously.

 

New call-to-action

Phase 4: Business Continuity Strategy (BCS)

[BCM] [Damanat] [E2] [C5] Business Continuity StrategyOnce Damanat understands its disruption risks and recovery priorities, appropriate Business Continuity Strategies must be developed.

The purpose of this phase is to determine how Damanat will continue or recover priority activities within the recovery requirements established by the BIA.

Strategies should be practical, proportionate, technically achievable, financially justified, and consistent with approved recovery objectives.

Strategy development should consider:

People

Alternative staffing, cross-training, succession arrangements, remote-working capability, workforce relocation, and availability of specialist personnel.

Premises

Alternative workplaces, reciprocal arrangements, remote operations, distributed working, and recovery-site requirements.

Technology

System resilience, redundancy, disaster recovery, alternative connectivity, backup arrangements, recovery infrastructure, and manual workarounds.

Information

Protection, accessibility, backup, restoration, integrity, and availability of critical records and operational information.

Suppliers and External Parties

Alternative suppliers, contractual continuity requirements, service-level expectations, concentration risks, contingency arrangements, and supplier recovery capabilities.

Business Processes

Alternative processing arrangements, temporary procedures, workarounds, prioritisation mechanisms, and reduced-service operating models.

Selected strategies should demonstrate that Damanat can achieve the recovery requirements established through the BIA.

 

New call-to-action

Phase 5: Plan Development (PD)

[BCM] [Damanat] [E2] [C6] BCM Plan DevelopmentPlan Development converts approved continuity strategies into documented procedures that can be activated during an actual disruption.

Business Continuity Plans should therefore be operational documents rather than theoretical descriptions of BCM arrangements.

Plans should enable responsible personnel to understand:

  • when the plan should be activated;
  • who has authority to activate it;
  • who must be notified;
  • where the recovery team should operate;
  • what actions must be performed;
  • which activities must be recovered first;
  • which resources are required;
  • which external parties must be contacted; and
  • how operations will progressively return to normal.

Damanat's BCM documentation should establish appropriate links between incident management, crisis management, business continuity, technology disaster recovery, communications, and other organisational response arrangements.

Plans should also contain escalation criteria, contact arrangements, recovery procedures, resource requirements, dependencies, and procedures for returning from continuity operations to normal business operations.

 

New call-to-action

Phase 6: Testing and Exercising (TE)

[BCM] [Damanat] [E2] [C7] Testing and ExercisingA Business Continuity Plan cannot be considered reliable simply because it has been documented and approved.

Damanat should establish a structured Testing and Exercising programme to validate whether strategies, plans, personnel, technologies, facilities, suppliers, and decision-making arrangements can perform as expected during disruption.

Exercises may progressively include:

  • walkthroughs;
  • call-tree and notification tests;
  • tabletop exercises;
  • functional exercises;
  • technology recovery tests;
  • alternative-site tests;
  • supplier participation exercises;
  • crisis simulations; and
  • integrated exercises involving multiple business functions.

Exercise objectives and success criteria should be established before each exercise.

Following completion, Damanat should document observations, deficiencies, lessons learned, corrective actions, responsible owners, and target completion dates.

Where significant deficiencies are identified, the affected arrangements should be corrected and revalidated.

Testing and exercising therefore creates the feedback mechanism through which documented BCM arrangements become demonstrated organisational capabilities.

 

New call-to-action

Phase 7: Program Management (PgM)

[BCM] [Damanat] [E2] [C8] Program ManagementBusiness Continuity Management does not end when plans have been written and exercised.

Program Management establishes the ongoing governance required to maintain and improve Damanat's BCM capability.

The BCM program should ensure that continuity arrangements remain aligned with changes affecting:

  • organisational structure;
  • products and services;
  • business processes;
  • personnel;
  • technology;
  • premises;
  • suppliers;
  • regulatory requirements;
  • operating environments; and
  • emerging disruption risks.

Program Management should include:

  • BCM governance and management oversight;
  • periodic BIA and risk assessment reviews;
  • plan maintenance;
  • training and competency development;
  • awareness programmes;
  • exercise scheduling;
  • corrective-action tracking;
  • internal review and audit;
  • management reporting;
  • document control;
  • performance monitoring; and
  • continual improvement.

This phase converts BCM from a one-time implementation project into an embedded organisational management discipline.

 

[BCM] [Damanat] [3/4 Banner] Implementing BCM for The Saudi Mortgage Guarantees Services CompanySpecific BCM Requirements for Damanat

Damanat operates within Saudi Arabia's financial-services ecosystem; therefore, its BCM methodology should reflect both ISO 22301 and applicable Saudi regulatory expectations.

The Saudi Central Bank's Business Continuity Management Framework states that its requirements draw on international standards including ISO 22301 and require applicable member organisations to formally integrate BCM into their programmes.

The framework addresses governance, BCM strategy and policy, BIA and risk assessment, continuity planning, testing, awareness, document review and independent assurance.

Of particular relevance to Damanat, the SAMA framework requires a defined and maintained methodology for BIA and risk assessment.

It calls for identification of internal and external threats and single points of failure across people, process, technology and premises; prioritisation of activities through BIA; identification of internal and external dependencies; determination of recovery resources; and establishment of measures including RTO, RPO and MAO.

It also specifies annual BIA and risk-assessment updates and updates following major organisational, process, technology, supplier or location changes.

Governance is equally important. The SAMA framework places ultimate BCM responsibility with the board or an appropriately delegated executive, requires sufficient resources, calls for a BCM Committee and BCM function, and expects cross-functional participation in implementation and maintenance of continuity and disaster-recovery arrangements.

Accordingly, a specific requirement for Damanat should be:

Damanat shall establish, document, implement, maintain and continually improve an enterprise BCM program covering its critical business functions and the people, processes, technology, premises, information, suppliers and external dependencies required to deliver them.

The program shall establish approved recovery requirements through BIA and disruption-risk assessment; implement appropriate continuity and recovery strategies; maintain actionable Business Continuity Plans; periodically exercise those arrangements; and ensure that identified deficiencies are assigned, tracked and resolved through formal BCM governance.


For Damanat specifically, this means the BCM methodology should address disruption not only within Damanat itself but also across the dependencies supporting the delivery of mortgage guarantee services.

These may include participating financial institutions, technology and telecommunications providers, data and information services, outsourced service providers, government or regulatory interfaces, payment or settlement dependencies, and other parties required to originate, administer and support mortgage guarantees.

Supplier and service-provider resilience should therefore form an explicit part of the RAR, BIA, BCS and TE phases.

SAMA's framework specifically requires assessment, at least annually, of vendors', suppliers' and service providers' capability to support prioritised activities during disruptive incidents.

The seven-phase methodology therefore provides Damanat with a practical mechanism for translating ISO 22301 and relevant regulatory expectations into an operational BCM capability.

 

Integrating the Seven Phases

The strength of the methodology comes from the relationship between its seven phases.

  • New call-to-actionProject Management establishes what must be implemented and who is responsible.

  • Risk Analysis and Review determines what could disrupt Damanat.

  • Business Impact Analysis determines what must be recovered and how quickly.

  • Business Continuity Strategy determines how recovery requirements will be achieved.

  • Plan Development documents how Damanat will respond and recover.

  • Testing and Exercising determines whether those arrangements actually work.

  • Program Management ensures that the capability remains current, governed, tested and continually improved.

The resulting lifecycle can therefore be represented as:

PM → RAR → BIA → BCS → PD → TE → PgM → Review and Continual Improvement

Importantly, the completion of Program Management does not represent the end of BCM. Changes in Damanat's operating environment, technology, business model, regulatory obligations, suppliers or risk landscape should trigger reassessment and, where necessary, another iteration through the relevant phases.

 

x [Banner] [Summing] [OR] [E2] [C1] Overview of Operational Resilience Planning Methodology

 The Business Continuity Management Planning Methodology establishes the implementation architecture for BCM within The Saudi Mortgage Guarantees Services Company.

By structuring implementation around Project Management, Risk Analysis and Review, Business Impact Analysis, Business Continuity Strategy, Plan Development, Testing and Exercising, and Program Management, Damanat can progress systematically from understanding its disruption exposure to establishing and demonstrating practical recovery capability.

More importantly, the methodology establishes traceability across the BCM lifecycle. Threats identified during RAR influence the scenarios for which Damanat must prepare. Recovery priorities established through the BIA determine the capabilities required from continuity strategies.

Those strategies are translated into operational procedures through Plan Development.

Testing and exercising validate whether those procedures and resources can meet the intended recovery objectives.

Program Management then ensures that lessons learned, organisational changes and emerging risks are incorporated into the BCM programme.

This lifecycle approach supports the intent of ISO 22301 while providing a practical structure through which Damanat can address applicable Saudi regulatory expectations and its own operational requirements.

For Damanat, successful BCM implementation ultimately depends on moving beyond the production of continuity documents toward the establishment of a demonstrable organisational capability—one in which management, employees, technology teams, business functions and critical external parties understand their responsibilities and can work collectively to maintain or restore priority activities when disruption occurs.

The subsequent chapters of this eBook will progressively apply the seven-phase methodology, beginning with the establishment and management of the BCM implementation project and continuing through risk assessment, business impact analysis, strategy development, plan development, exercising and ongoing programme management.

 

[BCM] [Damanat] [3/4 Banner] Implementing BCM for The Saudi Mortgage Guarantees Services Company

eBook 2: Implementing Business Continuity Management
C1 C2 C3 C4 C5
[BCM] [Damanat] [E2] [C1] Business Continuity Management Planning Methodology [BCM] [Damanat] [E2] [C2] Project Management [BCM] [Damanat] [E2] [C3] Risk Analysis and Review [BCM] [Damanat] [E2] [C4] Business Impact Analysis [BCM] [Damanat] [E2] [C5] Business Continuity Strategy
C6 C7 C8 C9 C10
[BCM] [Damanat] [E2] [C6] BCM Plan Development [BCM] [Damanat] [E2] [C7] Testing and Exercising [BCM] [Damanat] [E2] [C8] Program Management [BCM] [Damanat] [E2] [C9] Summary [BCM] [Damanat] [E2] [C10] Back Cover
 

More Information About Business Continuity Management Courses

To learn more about the course and schedule, click the buttons below for BCM-300 Business Continuity Management Implementer [BCM-3] and BCM-5000 Business Continuity Management Expert Implementer [BCM-5]

New call-to-action New call-to-action Register [BL-B-3]*
New call-to-action New call-to-action New call-to-action
FAQ [BL-B-3]

Please feel free to send us a note if you have any questions.

Email to Sales Team [BCM Institute]

 FAQ BL-B-5 BCM-5000
New call-to-action New call-to-action New call-to-action
 
 

Your Comments Here:

 

More Posts

New Call-to-action