The methodology is aligned with the management-system principles of ISO 22301 – Security and resilience — Business continuity management systems — Requirements and is structured to support the Saudi Arabian regulatory environment in which Damanat operates.
The methodology consists of seven interconnected phases:
1. Project Management (PM)
2. Risk Analysis and Review (RAR)
3. Business Impact Analysis (BIA)
4. Business Continuity Strategy (BCS)
5. Plan Development (PD)
6. Testing and Exercising (TE)
7. Program Management (PgM)
Together, these phases establish a lifecycle for developing, implementing, validating, maintaining, and continually improving BCM within Damanat.
The BCM Planning Methodology provides Damanat with a consistent approach for translating organisational, operational, regulatory, and resilience requirements into practical continuity capabilities.
The methodology should be applied across the organisation and should involve business functions, technology, risk management, compliance, facilities, human resources, communications, third-party management, and other relevant supporting functions.
The seven phases should not be treated as isolated activities. Outputs from one phase become important inputs into subsequent phases.
For example, the Risk Analysis and Review identifies threats that could disrupt Damanat, while the Business Impact Analysis establishes which activities require priority recovery. These findings subsequently influence the selection of continuity strategies and the development of Business Continuity Plans.
Testing and Exercising then validates whether these arrangements can operate under realistic disruption conditions, while Program Management ensures that the entire BCM capability remains current and effective.
|
Phase |
BCM Phase |
Primary Purpose |
Key Outcomes for Damanat |
|
1 |
Project Management (PM) |
Establish and manage the BCM implementation project |
Scope, governance, responsibilities, project schedule, resources and implementation oversight |
|
2 |
Risk Analysis and Review (RAR) |
Identify and assess disruption threats |
Threat register, risk assessment, existing controls, vulnerabilities and treatment requirements |
|
3 |
Business Impact Analysis (BIA) |
Determine the consequences of disruption and recovery priorities |
Critical business functions, recovery requirements, dependencies, MBCO, RTO and resource requirements |
|
4 |
Business Continuity Strategy (BCS) |
Determine how critical activities will be recovered |
People, premises, technology, information, supplier and operational recovery strategies |
|
5 |
Plan Development (PD) |
Document response and recovery arrangements |
Business Continuity Plans, procedures, activation arrangements, escalation and recovery actions |
|
6 |
Testing and Exercising (TE) |
Validate plans, strategies and organisational readiness |
Exercise results, capability gaps, lessons learned and corrective actions |
|
7 |
Program Management (PgM) |
Maintain and continually improve BCM |
Governance, training, awareness, reviews, audits, maintenance and continual improvement |
Before detailed BCM analysis begins, Damanat should establish the scope, objectives, governance arrangements, responsibilities, resources, deliverables, implementation schedule, and reporting mechanisms for the BCM initiative.
The project should identify the business functions and supporting activities included within the BCM scope and determine the individuals responsible for providing operational information and approving BCM outputs.
Particular attention should be given to establishing clear ownership between the central BCM function and business-function representatives.
The output from this phase provides the organisational structure through which the remaining BCM phases can be implemented.
The objective is not merely to produce a general enterprise risk register.
The RAR should specifically examine business continuity risks—events and circumstances that can interrupt critical business functions, supporting resources, technology, facilities, personnel, information, or external dependencies.
Potential disruption scenarios may include technology failures, cyber incidents, telecommunications outages, loss of premises, utility disruption, loss of critical personnel, third-party failure, physical security incidents, natural hazards, infrastructure disruption, and other operational events relevant to Damanat.
For each identified threat, Damanat should assess:
The resulting Threat and Risk Register provides an important input into continuity strategy development and scenario design for subsequent BCM exercises.
The Business Impact Analysis determines which activities are most important to Damanat and establishes their recovery requirements following disruption.
Rather than asking only what could go wrong, the BIA asks:
For Damanat, impact assessment should consider relevant categories such as:
The BIA should establish appropriate recovery requirements, including where applicable:
The results allow Damanat to prioritise recovery based on business impact rather than attempting to recover every activity simultaneously.
The purpose of this phase is to determine how Damanat will continue or recover priority activities within the recovery requirements established by the BIA.
Strategies should be practical, proportionate, technically achievable, financially justified, and consistent with approved recovery objectives.
Strategy development should consider:
Alternative staffing, cross-training, succession arrangements, remote-working capability, workforce relocation, and availability of specialist personnel.
Alternative workplaces, reciprocal arrangements, remote operations, distributed working, and recovery-site requirements.
System resilience, redundancy, disaster recovery, alternative connectivity, backup arrangements, recovery infrastructure, and manual workarounds.
Protection, accessibility, backup, restoration, integrity, and availability of critical records and operational information.
Alternative suppliers, contractual continuity requirements, service-level expectations, concentration risks, contingency arrangements, and supplier recovery capabilities.
Alternative processing arrangements, temporary procedures, workarounds, prioritisation mechanisms, and reduced-service operating models.
Selected strategies should demonstrate that Damanat can achieve the recovery requirements established through the BIA.
Business Continuity Plans should therefore be operational documents rather than theoretical descriptions of BCM arrangements.
Plans should enable responsible personnel to understand:
Damanat's BCM documentation should establish appropriate links between incident management, crisis management, business continuity, technology disaster recovery, communications, and other organisational response arrangements.
Plans should also contain escalation criteria, contact arrangements, recovery procedures, resource requirements, dependencies, and procedures for returning from continuity operations to normal business operations.
Damanat should establish a structured Testing and Exercising programme to validate whether strategies, plans, personnel, technologies, facilities, suppliers, and decision-making arrangements can perform as expected during disruption.
Exercises may progressively include:
Exercise objectives and success criteria should be established before each exercise.
Following completion, Damanat should document observations, deficiencies, lessons learned, corrective actions, responsible owners, and target completion dates.
Where significant deficiencies are identified, the affected arrangements should be corrected and revalidated.
Testing and exercising therefore creates the feedback mechanism through which documented BCM arrangements become demonstrated organisational capabilities.
Program Management establishes the ongoing governance required to maintain and improve Damanat's BCM capability.
The BCM program should ensure that continuity arrangements remain aligned with changes affecting:
Program Management should include:
This phase converts BCM from a one-time implementation project into an embedded organisational management discipline.
Damanat operates within Saudi Arabia's financial-services ecosystem; therefore, its BCM methodology should reflect both ISO 22301 and applicable Saudi regulatory expectations.
The Saudi Central Bank's Business Continuity Management Framework states that its requirements draw on international standards including ISO 22301 and require applicable member organisations to formally integrate BCM into their programmes.
The framework addresses governance, BCM strategy and policy, BIA and risk assessment, continuity planning, testing, awareness, document review and independent assurance.
Of particular relevance to Damanat, the SAMA framework requires a defined and maintained methodology for BIA and risk assessment.
It calls for identification of internal and external threats and single points of failure across people, process, technology and premises; prioritisation of activities through BIA; identification of internal and external dependencies; determination of recovery resources; and establishment of measures including RTO, RPO and MAO.
It also specifies annual BIA and risk-assessment updates and updates following major organisational, process, technology, supplier or location changes.
Governance is equally important. The SAMA framework places ultimate BCM responsibility with the board or an appropriately delegated executive, requires sufficient resources, calls for a BCM Committee and BCM function, and expects cross-functional participation in implementation and maintenance of continuity and disaster-recovery arrangements.
Accordingly, a specific requirement for Damanat should be:
Damanat shall establish, document, implement, maintain and continually improve an enterprise BCM program covering its critical business functions and the people, processes, technology, premises, information, suppliers and external dependencies required to deliver them.
The program shall establish approved recovery requirements through BIA and disruption-risk assessment; implement appropriate continuity and recovery strategies; maintain actionable Business Continuity Plans; periodically exercise those arrangements; and ensure that identified deficiencies are assigned, tracked and resolved through formal BCM governance.
For Damanat specifically, this means the BCM methodology should address disruption not only within Damanat itself but also across the dependencies supporting the delivery of mortgage guarantee services.
These may include participating financial institutions, technology and telecommunications providers, data and information services, outsourced service providers, government or regulatory interfaces, payment or settlement dependencies, and other parties required to originate, administer and support mortgage guarantees.
Supplier and service-provider resilience should therefore form an explicit part of the RAR, BIA, BCS and TE phases.
SAMA's framework specifically requires assessment, at least annually, of vendors', suppliers' and service providers' capability to support prioritised activities during disruptive incidents.
The seven-phase methodology therefore provides Damanat with a practical mechanism for translating ISO 22301 and relevant regulatory expectations into an operational BCM capability.
The strength of the methodology comes from the relationship between its seven phases.
Risk Analysis and Review determines what could disrupt Damanat.
Business Impact Analysis determines what must be recovered and how quickly.
Business Continuity Strategy determines how recovery requirements will be achieved.
Plan Development documents how Damanat will respond and recover.
Testing and Exercising determines whether those arrangements actually work.
Program Management ensures that the capability remains current, governed, tested and continually improved.
The resulting lifecycle can therefore be represented as:
Importantly, the completion of Program Management does not represent the end of BCM. Changes in Damanat's operating environment, technology, business model, regulatory obligations, suppliers or risk landscape should trigger reassessment and, where necessary, another iteration through the relevant phases.
The Business Continuity Management Planning Methodology establishes the implementation architecture for BCM within The Saudi Mortgage Guarantees Services Company.
By structuring implementation around Project Management, Risk Analysis and Review, Business Impact Analysis, Business Continuity Strategy, Plan Development, Testing and Exercising, and Program Management, Damanat can progress systematically from understanding its disruption exposure to establishing and demonstrating practical recovery capability.
More importantly, the methodology establishes traceability across the BCM lifecycle. Threats identified during RAR influence the scenarios for which Damanat must prepare. Recovery priorities established through the BIA determine the capabilities required from continuity strategies.
Those strategies are translated into operational procedures through Plan Development.
Testing and exercising validate whether those procedures and resources can meet the intended recovery objectives.
Program Management then ensures that lessons learned, organisational changes and emerging risks are incorporated into the BCM programme.
This lifecycle approach supports the intent of ISO 22301 while providing a practical structure through which Damanat can address applicable Saudi regulatory expectations and its own operational requirements.
For Damanat, successful BCM implementation ultimately depends on moving beyond the production of continuity documents toward the establishment of a demonstrable organisational capability—one in which management, employees, technology teams, business functions and critical external parties understand their responsibilities and can work collectively to maintain or restore priority activities when disruption occurs.
The subsequent chapters of this eBook will progressively apply the seven-phase methodology, beginning with the establishment and management of the BCM implementation project and continuing through risk assessment, business impact analysis, strategy development, plan development, exercising and ongoing programme management.
| eBook 2: Implementing Business Continuity Management | ||||
| C1 | C2 | C3 | C4 | C5 |
| C6 | C7 | C8 | C9 | C10 |
To learn more about the course and schedule, click the buttons below for BCM-300 Business Continuity Management Implementer [BCM-3] and BCM-5000 Business Continuity Management Expert Implementer [BCM-5]
|
Please feel free to send us a note if you have any questions. |
||