eBook 2: Chapter 3
Risk Analysis and Review Phase of the BCM Planning Methodology for
The Saudi Mortgage Guarantees Services Company
Introduction
The Risk Analysis and Review (RAR) phase is the second implementation phase of the Business Continuity Management (BCM) Planning Methodology for The Saudi Mortgage Guarantees Services Company (Damanat).
Following the establishment of the BCM project, scope, governance structure, responsibilities and implementation arrangements during the Project Management phase, Damanat must determine the disruptive events that could prevent its business functions from operating normally.
The purpose of Risk Analysis and Review is therefore to answer four fundamental questions:
- What could disrupt Damanat's operations?
- How likely is the disruption to occur?
- How serious could the consequences be?
- What controls or treatments are required to reduce the risk?
Risk Analysis and Review should not be confused with the organisation's broader Enterprise Risk Management process.
While the two disciplines should be integrated, BCM-oriented risk assessment focuses specifically on threats that can cause business interruption, loss of critical resources, or a prolonged inability to perform important business activities.
For Damanat, these threats could affect mortgage guarantee origination, guarantee administration, claims processing, financial operations, interfaces with participating financial institutions, technology platforms, customer services, regulatory reporting, or other activities supporting the organisation's mandate.
The RAR methodology presented in this chapter consists of four principal steps:
Step 1 – Identifying Risks
Recognising potential threats that could disrupt operations.
Step 2 – Assessing Risks
Evaluating the likelihood and impact of identified risks.
Step 3 – Mitigating Risks
Implementing controls to reduce risks to an acceptable level.
Step 4 – Continuous Review
Regularly updating the risk profile in response to changes in the business environment.
Together, these steps provide Damanat with a structured mechanism to understand its disruption exposure and determine whether existing preventive and mitigating controls provide sufficient protection.
Purpose of Risk Analysis and Review
The primary objective of RAR is to identify the threats, vulnerabilities, and single points of failure that could disrupt Damanat's critical activities and to determine whether appropriate controls are in place.
The analysis should provide management with an understanding of:
- potential disruption threats;
- affected business functions;
- vulnerabilities;
- single points of failure;
- existing preventive controls;
- existing mitigating controls;
- likelihood of disruption;
- potential disruption impact;
- overall risk level;
- residual risk after existing controls;
- additional treatment requirements; and
- responsibility for implementing improvements.
The output should be documented in a BCM Threat and Risk Register.
The RAR is subsequently used together with the Business Impact Analysis (BIA). The two assessments answer different but complementary questions:
|
Assessment |
Primary Question |
|
Risk Analysis and Review |
What could cause the disruption? |
|
Business Impact Analysis |
What happens if the activity is disrupted? |
The RAR identifies potential causes, while the BIA determines the consequences of losing the affected business activity over time.
Relationship Between RAR and ISO 22301
ISO 22301 requires organisations implementing a Business Continuity Management System to understand the risks and opportunities that affect the effectiveness of the management system and to systematically analyse potential disruptions and their consequences.
For Damanat, this means that risk assessment should be part of the overall BCM lifecycle rather than a one-time exercise.
The RAR methodology should:
- be formally defined;
- use consistent assessment criteria;
- include relevant internal and external threats;
- consider dependencies and vulnerabilities;
- identify treatment requirements;
- be documented;
- be approved through appropriate governance;
- be reviewed periodically; and
- be updated following material organisational or environmental changes.
The results should also inform strategy development, Business Continuity Plan preparation and scenario selection for BCM exercises.
Regulatory Context for Damanat
The Saudi Central Bank's Business Continuity Management Framework explicitly integrates Business Impact Analysis and Risk Assessment as core BCM requirements.
The current SAMA Rulebook states that the methodology for both activities should be defined, approved, implemented and maintained.
The framework requires periodic business continuity risk assessments that consider internal and external threats and single points of failure affecting people, processes, technology, and premises.
It further calls for risks to be prioritised based on their operational impact and probability, appropriate controls to be selected, and treatment plans to be implemented.
SAMA also states that BIA and risk assessment should be updated annually and following major changes involving areas such as organisational structure, people, processes, technology, suppliers and locations.
The framework additionally addresses the continuity capability of vendors, suppliers, and service providers that support prioritised activities.
For Damanat, these principles provide a useful regulatory basis for establishing a structured and repeatable RAR process.
The Four-Step RAR Methodology
Damanat's Risk Analysis and Review methodology should be structured around four interrelated steps:
Step 1 — Identify Risks
Identify the threats that could disrupt Damanat's activities and resources.
Step 2 — Assess Risks
Determine the likelihood and potential impact of each identified threat.
Step 3 — Mitigate Risks
Determine whether existing controls are sufficient and implement additional controls where required.
Step 4 — Continuously Review Risks
Monitor changes in threats, vulnerabilities, operations and dependencies and update the risk assessment accordingly.
The cycle can be represented as:
Identify → Assess → Mitigate → Review → Re-identify
This reinforces an important BCM principle: risk assessment is dynamic rather than static.
Step 1 — Identifying Risks
Risk identification begins by determining what events or circumstances could interrupt Damanat's ability to perform its business functions.
Threat identification should consider both internal and external threats.
Internal Threats
Internal threats originate primarily within the organisation or from resources under its direct management.
Examples include:
- application or system failure;
- database corruption;
- internal network failure;
- human error;
- processing error;
- inadequate change management;
- loss of critical personnel;
- internal fraud;
- failure of internal procedures;
- equipment failure;
- accidental deletion of critical information;
- inadequate segregation of duties;
- building systems failure; and
- failure of internal control processes.
External Threats
External threats arise outside Damanat but may significantly affect its ability to operate.
Examples include:
- telecommunications disruption;
- electricity failure;
- cyberattack;
- ransomware;
- denial-of-service attack;
- third-party service-provider failure;
- cloud service interruption;
- disruption affecting participating financial institutions;
- severe weather;
- regional infrastructure disruption;
- fire affecting neighbouring premises;
- transportation disruption;
- civil emergencies;
- supply-chain disruption; and
- external data-provider failure.
The objective is not to predict every possible event. It is to identify credible categories of disruption that could materially affect Damanat's ability to perform priority activities.
Risk Identification by Resource Category
A practical RAR should examine threats by the resources required to deliver business activities.
For Damanat, these can be structured around:
People → Process → Technology → Premises → Information → Third Parties
People Risks
Damanat may depend on employees with specialist knowledge, authority or expertise.
Potential threats include:
- unavailability of key personnel;
- widespread illness;
- inability of employees to reach the workplace;
- loss of specialist technical expertise;
- resignation of critical personnel;
- inadequate succession arrangements; and
- excessive dependency on individual employees.
Damanat Example
Suppose only a small number of employees are authorised to approve particular mortgage guarantee transactions.
If those employees become unavailable simultaneously, the processing system may remain operational, but guaranteed approvals could still stop.
The underlying business continuity threat is therefore concentration of critical authority within too few individuals.
Process Risks
Business processes can contain single points of failure even when supporting technology remains available.
Potential vulnerabilities include:
- excessive manual approvals;
- dependency on one processing team;
- poorly documented procedures;
- sequential processes with no workaround;
- inadequate segregation of responsibilities;
- unavailable approval authorities; and
- dependencies between business units.
Damanat Example
Consider the following workflow:
Mortgage Guarantee Application Intake
→ Application Validation
→ Borrower Eligibility Assessment
→ Property Eligibility Assessment
→ Mortgage Risk Assessment
→ Guarantee Approval
→ Guarantee Certificate Generation
If the Mortgage Risk Assessment activity cannot be completed, downstream approval and certificate generation may also stop.
The RAR should therefore examine not merely individual functions but also process dependencies and bottlenecks.
Technology Risks
Damanat's business activities are likely to depend extensively on technology systems, data, communications and connectivity.
Threats may include:
- application failure;
- database failure;
- network outage;
- storage failure;
- cybersecurity incident;
- ransomware;
- telecommunications failure;
- interface failure;
- authentication service failure;
- data-centre outage;
- cloud service interruption;
- backup failure; and
- failure during system change or upgrade.
Damanat Example
A failure affecting the technology platform used to receive and process mortgage guarantee applications could prevent:
- applications from being received;
- applications from being validated;
- assessments from being completed;
- approvals from being recorded;
- guarantee certificates from being generated; and
- participating financial institutions from receiving confirmation.
This demonstrates how one technology dependency can affect multiple business processes simultaneously.
Premises and Physical Infrastructure Risks
Although many activities can increasingly be performed remotely, Damanat should still assess the risks associated with the loss of its premises and physical infrastructure.
Threats may include:
- fire;
- water damage;
- building evacuation;
- access restriction;
- utility outage;
- air-conditioning failure;
- physical security incident;
- telecommunications failure;
- transportation disruption; and
- prolonged building closure.
The analysis should determine whether essential activities can be relocated or performed remotely and whether critical equipment remains accessible.
Information and Data Risks
Business continuity depends not only on systems but also on the information contained within those systems.
Potential risks include:
- data corruption;
- data loss;
- inaccessible records;
- unavailable documentation;
- backup failure;
- loss of transaction records;
- database integrity failure; and
- inability to retrieve historical records.
Damanat Example
If Damanat's application processing platform is restored after a disruption but several hours of recently approved guarantee transactions cannot be recovered, operational capability has technically returned, but business recovery remains incomplete.
RAR should therefore consider both:
System Availability + Information Recoverability
Third-Party and External Dependency Risks
Damanat should identify organisations whose failure could disrupt its own activities.
These may include:
- participating financial institutions;
- telecommunications providers;
- technology vendors;
- hosting providers;
- cloud providers;
- data providers;
- payment-related service providers;
- facilities providers;
- professional service providers; and
- specialist outsourced suppliers.
The risk assessment should consider:
- dependency concentration;
- alternative suppliers;
- contractual recovery requirements;
- supplier disaster-recovery capabilities;
- supplier geographical concentration;
- supplier cybersecurity exposure; and
- Damanat's ability to operate temporarily without the supplier.
Damanat Example
If a critical third-party interface that supports the exchange of mortgage guarantee application information becomes unavailable, Damanat may remain internally operational but be unable to receive or transmit required information to participating financial institutions.
The RAR must therefore extend beyond Damanat's organisational boundary.
Identifying Single Points of Failure
A single point of failure (SPOF) is a resource whose loss could interrupt an activity because there is no effective alternative.
SPOFs are particularly important in BCM.
Examples for Damanat may include:
|
Resource |
Possible Single Point of Failure |
|
People |
One employee holding specialist approval authority |
|
Process |
One mandatory approval stage with no delegated alternative |
|
Technology |
One application supporting guarantee processing |
|
Data |
One repository containing critical records |
|
Connectivity |
One communications link |
|
Premises |
One location supporting a critical activity |
|
Supplier |
One provider with no substitute |
|
Interface |
One gateway connecting Damanat with an external institution |
The RAR should explicitly identify these vulnerabilities because eliminating or reducing SPOFs often provides significant improvement in continuity capability.
Developing the Threat Register
All identified threats should be documented within a Threat Register.
An illustrative Damanat register could include:
|
Ref |
Threat |
Potentially Affected Resource |
Potential Disruption |
|
T01 |
Critical application failure |
Technology |
Mortgage guarantee processing unavailable |
|
T02 |
Cyberattack/ransomware |
Technology / Information |
Systems or data inaccessible |
|
T03 |
Telecommunications outage |
Technology |
External connectivity unavailable |
|
T04 |
Power failure |
Premises / Technology |
Office or technology operations interrupted |
|
T05 |
Loss of key personnel |
People |
Critical approval or specialist activity unavailable |
|
T06 |
Fire or premises loss |
Premises |
Primary workplace unavailable |
|
T07 |
Third-party technology failure |
Supplier |
Dependent services unavailable |
|
T08 |
Data corruption |
Information |
Transaction information unreliable |
|
T09 |
Participating financial institution interface failure |
External dependency |
Application exchange interrupted |
|
T10 |
Major process error |
Process |
Processing suspended pending correction |
|
T11 |
Widespread employee unavailability |
People |
Insufficient staffing |
|
T12 |
Major infrastructure disruption |
External environment |
Multiple resources affected |
The detailed Threat Register can subsequently be expanded as additional Damanat-specific threats are identified.
Step 2 — Assessing Risks
Once threats have been identified, Damanat should determine their relative significance.
A practical BCM risk assessment normally considers:
Risk = Likelihood × Impact
This enables threats to be prioritised according to their potential to cause material business interruption.
Assessing Likelihood
Likelihood reflects the probability or frequency of a disruptive event.
An illustrative five-level scale is:
|
Rating |
Likelihood |
Description |
|
1 |
Rare |
Event would occur only under exceptional circumstances |
|
2 |
Unlikely |
Event could occur but is not expected |
|
3 |
Possible |
Event may occur periodically |
|
4 |
Likely |
Event is reasonably expected to occur |
|
5 |
Almost Certain |
Event occurs frequently or is strongly expected |
Likelihood should not be based solely on personal opinion.
Damanat may consider:
- previous incidents;
- internal loss data;
- industry experience;
- audit findings;
- threat intelligence;
- technology incidents;
- supplier performance;
- environmental conditions;
- operational changes; and
- expert judgement.
Assessing Impact
Impact reflects the severity of disruption if the threat materialises.
An illustrative five-level scale could be:
|
Rating |
Impact |
General Interpretation |
|
1 |
Insignificant |
Negligible operational disruption |
|
2 |
Minor |
Limited interruption manageable through normal procedures |
|
3 |
Moderate |
Noticeable interruption requiring management intervention |
|
4 |
Major |
Significant interruption to important business functions |
|
5 |
Severe |
Prolonged or widespread inability to perform critical activities |
Impact assessment may consider:
- operational disruption;
- financial consequences;
- customer impact;
- participating financial institution impact;
- legal consequences;
- regulatory consequences;
- reputational damage;
- data impact; and
- strategic consequences.
Risk Scoring
A simple risk rating can be calculated as:
Likelihood Rating × Impact Rating = Risk Score
For example:
|
Threat |
Likelihood |
Impact |
Risk Score |
|
Application platform outage |
3 |
5 |
15 |
|
Loss of one office area |
2 |
3 |
6 |
|
Telecommunications failure |
3 |
4 |
12 |
|
Loss of specialist personnel |
3 |
4 |
12 |
|
Major cyberattack |
4 |
5 |
20 |
The score enables Damanat to prioritise risks requiring additional attention.
The numerical result should, however, support rather than replace professional judgement.
A relatively low-probability event may still require significant continuity arrangements where its consequences would be severe.
Inherent and Residual Risk
The assessment should distinguish between inherent risk and residual risk.
Inherent Risk
The level of risk assuming existing controls are absent or ineffective.
Residual Risk
The level of risk remaining after existing controls have been considered.
The process can be represented as:
Inherent Risk → Existing Controls → Residual Risk
This distinction is important because a threat may have severe inherent consequences but already be well controlled.
Conversely, a relatively common threat may retain a high residual risk because existing controls are inadequate.
Evaluating Existing Controls
For each significant threat, Damanat should identify existing controls.
Controls may be:
Preventive Controls
Designed to reduce the probability of disruption.
Examples:
- cybersecurity protection;
- preventive maintenance;
- redundant infrastructure;
- access controls;
- change management;
- staff cross-training; and
- supplier due diligence.
Detective Controls
Designed to identify abnormal conditions quickly.
Examples:
- monitoring systems;
- security alerts;
- system health monitoring;
- operational exception reporting; and
- environmental alarms.
Mitigating or Recovery Controls
Designed to reduce the consequences after disruption occurs.
Examples:
- backup systems;
- alternate workplaces;
- remote working;
- system disaster recovery;
- manual workarounds;
- alternative suppliers;
- cross-trained personnel; and
- Business Continuity Plans.
Example Risk Assessment for Damanat
Consider the threat:
Threat: Mortgage Guarantee Processing Platform Failure
Potential Cause:
Hardware failure, software error, unsuccessful change, database issue or infrastructure outage.
Potential Impact:
Damanat may be unable to receive, assess, approve or issue mortgage guarantees.
Likelihood:
Possible – Rating 3.
Impact:
Severe – Rating 5.
Inherent Risk Score:
3 × 5 = 15
Existing Controls:
- infrastructure redundancy;
- system monitoring;
- backup arrangements;
- disaster recovery capability;
- technical support;
- incident management procedures.
Residual Risk:
To be determined after assessing the effectiveness of these controls.
Possible Additional Treatment:
- increase system resilience;
- strengthen failover capability;
- improve recovery testing;
- establish documented manual processing procedures;
- improve alternative communication arrangements with participating financial institutions.
This structure provides a clear link between the identified threat and required continuity improvements.
Step 3 — Mitigating Risks
Risk mitigation determines what should be done about unacceptable risks.
Possible responses include:
Avoid
Stop or redesign the activity creating unacceptable exposure.
Reduce
Introduce additional preventive, detective or recovery controls.
Transfer
Transfer some consequences through insurance, outsourcing or contractual arrangements.
Accept
Formally accept residual risk where it falls within approved risk tolerance.
For BCM purposes, risk reduction is typically the most significant response, as Damanat may still need to perform the affected business activity.
Developing Risk Treatment Plans
Where residual risk exceeds acceptable levels, Damanat should establish a formal treatment plan.
The plan should identify:
- identified risk;
- control deficiency;
- proposed improvement;
- responsible owner;
- required resources;
- target completion date;
- status;
- residual risk after treatment; and
- approval or acceptance authority.
An illustrative treatment register is:
|
Risk |
Weakness |
Treatment |
Owner |
Target |
|
Key-person dependency |
One specialist performs critical activity |
Cross-train additional employees |
Business Owner |
Q3 |
|
Technology failure |
Insufficient recovery capability |
Enhance DR architecture |
IT |
Q4 |
|
Supplier failure |
No alternative service provider |
Establish contingency arrangement |
Procurement |
Q4 |
|
Premises loss |
Limited alternative workspace |
Expand remote working capability |
Administration / IT |
Q3 |
|
Data loss |
Recovery arrangements not recently validated |
Conduct restoration test |
IT |
Q2 |
The treatment register should be reviewed through Damanat's BCM governance structure.
Selecting Appropriate BCM Controls
Mitigation should consider the relationship between:
Threat → Vulnerability → Control → Residual Risk
For example:
Threat
Critical employee becomes unavailable.
Vulnerability
Only one employee understands a specialist guarantee-processing activity.
Control
Cross-train two additional employees and document the procedure.
Residual Risk
Reduced dependency on a single individual.
This approach ensures that controls directly address identified vulnerabilities rather than being implemented simply because they are considered good practice.
Risk Acceptance
Not every identified risk can be eliminated.
Some residual risks may be accepted where:
- further control is technically impractical;
- treatment cost is disproportionate;
- the exposure falls within approved risk tolerance; or
- alternative continuity arrangements adequately manage the potential consequences.
Risk acceptance should not occur informally.
Significant residual risks should be:
- documented;
- supported by justification;
- assigned to a risk owner;
- approved at the appropriate level; and
- reviewed periodically.
Linking Risk Treatment to Business Continuity Strategy
Some RAR findings cannot be eliminated through preventive controls.
For example, Damanat cannot guarantee that:
- an office will never become inaccessible;
- a telecommunications provider will never fail;
- a cyberattack will never occur;
- a critical supplier will never experience disruption; or
- employees will always be available.
The BCM approach must therefore combine:
Prevention + Preparedness + Response + Recovery
Where disruption cannot reasonably be prevented, the risk should be incorporated into the Business Continuity Strategy phase.
For example:
|
Risk |
Possible Continuity Strategy |
|
Primary office unavailable |
Remote working / alternate site |
|
Critical employee unavailable |
Cross-training / succession |
|
Technology application unavailable |
Disaster recovery / manual workaround |
|
Supplier unavailable |
Alternative supplier |
|
Data centre unavailable |
Alternate recovery environment |
|
Telecommunications unavailable |
Alternative communications |
|
External interface unavailable |
Alternative information exchange procedure |
RAR therefore establishes an important bridge between risk management and continuity strategy.
Step 4 — Continuous Review
Damanat's risk environment will change continuously.
New technologies, suppliers, processes, regulations, business arrangements and threat conditions can create risks that were not present during the original assessment.
Risk Analysis and Review must therefore become an ongoing management activity.
The SAMA BCM Framework specifically states that BIA and risk assessment should be updated annually and when major changes occur involving areas such as people, processes, technology, suppliers and locations.
For Damanat, review triggers should include:
- significant organisational restructuring;
- introduction of new products or services;
- implementation of new technology;
- major system upgrades;
- outsourcing arrangements;
- appointment or replacement of critical suppliers;
- relocation of operations;
- emerging cyber threats;
- actual disruption incidents;
- audit findings;
- exercise findings;
- regulatory change;
- major process redesign; and
- changes involving participating financial institutions or external interfaces.
Lessons from Incidents and Exercises
Actual incidents and BCM exercises provide valuable information about risks that may not have been identified during workshops.
For example, an exercise might reveal that:
- employees cannot access a required application remotely;
- contact information is outdated;
- a supplier's recovery time exceeds Damanat's requirement;
- alternative communication channels have insufficient capacity;
- an approval process depends on one individual; or
- backup data cannot be restored within the required timeframe.
These findings should be incorporated into the Threat and Risk Register.
The continuous improvement cycle therefore becomes:
Incident / Exercise → Lesson Identified → Risk Reassessed → Control Improved → Capability Revalidated
Reviewing Third-Party Risks
Third-party risk should receive particular attention during periodic review.
The SAMA BCM Framework calls for the capability of vendors, suppliers, and service providers to support prioritised activities during disruptive incidents to be assessed at least annually.
For Damanat, this review could examine:
- supplier continuity plans;
- disaster-recovery capabilities;
- testing frequency;
- recovery times;
- alternative operating locations;
- subcontractor dependency;
- concentration risks;
- communication procedures;
- contractual BCM requirements; and
- evidence of recent continuity testing.
A contract stating that a provider has a Business Continuity Plan should not automatically be considered sufficient evidence of resilience.
Damanat should determine whether the provider's actual recovery capability is consistent with Damanat's own recovery requirements.
Risk Analysis at the Critical Business Function Level
RAR should eventually be applied to Damanat's identified Critical Business Functions.
For example, for:
CBF-1 Mortgage Guarantee Origination
Potential disruption scenarios could include:
|
Threat |
Possible Effect |
|
Application intake interface failure |
New guarantee applications cannot be received |
|
Processing application failure |
Applications cannot progress |
|
Specialist staff unavailable |
Risk assessments cannot be completed |
|
Approval authority unavailable |
Guarantee decisions delayed |
|
Database corruption |
Application information becomes unreliable |
|
Cyberattack |
Processing platform inaccessible |
|
Participating financial institution connectivity failure |
Application exchange interrupted |
|
Guarantee certificate system failure |
Approved guarantees cannot be formally issued |
This level of assessment enables risk analysis to reflect actual operating processes rather than generic organisational threats.
Recommended Damanat RAR Register
Damanat's BCM Risk Register should contain sufficient information to support risk treatment and future continuity planning.
A recommended structure is:
|
Field |
Purpose |
|
Risk Reference |
Unique identifier |
|
Business Function |
Activity exposed to the risk |
|
Threat |
Disruption event |
|
Cause |
Why the event could occur |
|
Vulnerability |
Weakness enabling disruption |
|
Affected Resource |
People, process, technology, premises, information or supplier |
|
Existing Controls |
Controls already implemented |
|
Likelihood |
Probability rating |
|
Impact |
Severity rating |
|
Inherent Risk |
Risk before controls |
|
Control Effectiveness |
Adequacy of existing controls |
|
Residual Risk |
Risk after controls |
|
Required Treatment |
Additional improvement |
|
Risk Owner |
Responsible individual |
|
Target Date |
Completion requirement |
|
Status |
Current progress |
|
Review Date |
Next assessment |
|
Remarks |
Additional observations |
This register should become the principal evidence of the RAR process.
RAR Deliverables
At the conclusion of the Risk Analysis and Review phase, Damanat should have produced at minimum:
|
Ref |
Deliverable |
Purpose |
|
RAR-01 |
RAR Methodology |
Establishes assessment approach |
|
RAR-02 |
Threat Catalogue |
Documents credible disruption threats |
|
RAR-03 |
Likelihood Criteria |
Standardises probability assessment |
|
RAR-04 |
Impact Criteria |
Standardises consequence assessment |
|
RAR-05 |
Risk Matrix |
Defines risk prioritisation |
|
RAR-06 |
Threat and Risk Register |
Records assessed BCM risks |
|
RAR-07 |
Single Point of Failure Register |
Identifies critical vulnerabilities |
|
RAR-08 |
Existing Control Assessment |
Determines control adequacy |
|
RAR-09 |
Risk Treatment Plan |
Records required improvements |
|
RAR-10 |
Residual Risk Register |
Records remaining exposures |
|
RAR-11 |
Third-Party Continuity Assessment |
Assesses important suppliers |
|
RAR-12 |
Management RAR Report |
Provides governance oversight |
Completion Criteria for the RAR Phase
Damanat should consider the RAR sufficiently complete when:
- relevant internal and external threats have been identified;
- people, process, technology, premises, information and supplier risks have been considered;
- single points of failure have been identified;
- likelihood and impact criteria have been consistently applied;
- inherent risks have been assessed;
- existing controls have been evaluated;
- residual risks have been determined;
- unacceptable risks have treatment plans;
- risk owners have been assigned;
- significant residual risks have been escalated;
- third-party continuity risks have been considered;
- results have been reviewed through appropriate BCM governance; and
- mechanisms for periodic review have been established.
The output can then be used as input to the Business Impact Analysis and, later, to continuity strategy development.
Relationship Between RAR and the Next BCM Phase
Risk Analysis and Review identifies how disruption could occur.
The next phase, Business Impact Analysis, determines the consequences if the disruption actually occurred.
For example:
RAR Finding
A technology failure could prevent Mortgage Guarantee Origination.
The RAR evaluates:
- the cause;
- likelihood;
- vulnerabilities;
- controls; and
- residual risk.
BIA Question
If Mortgage Guarantee Origination becomes unavailable:
- what happens after four hours?
- what happens after one day?
- what happens after three days?
- when do consequences become unacceptable?
- which activities must recover first?
- what resources are required?
- what recovery time should be established?
The two assessments therefore work together.
RAR identifies the threat.
BIA quantifies the business consequence.
BCS determines the recovery solution.
The Risk Analysis and Review phase enables The Saudi Mortgage Guarantees Services Company to understand what could disrupt its operations and whether existing controls provide sufficient protection against those disruptions.
For Damanat, the analysis should extend beyond conventional physical threats to consider the interconnected environment that supports mortgage guarantee operations.
This includes people, processes, technology, information, premises, participating financial institutions, outsourced service providers and other critical external dependencies.
The RAR methodology is built around four continuing activities:
Identify Risks → Assess Risks → Mitigate Risks → Continuously Review Risks
Risk identification establishes Damanat's threat landscape.
Risk assessment determines which threats require the greatest attention by considering likelihood and impact.
Risk mitigation determines whether existing controls are sufficient and establishes additional treatments where residual exposure remains unacceptable.
Continuous review ensures that the risk profile changes alongside Damanat's organisation, technology, processes, suppliers, operating environment and emerging threats.
The most important output of this phase is therefore not simply a list of threats. It is a structured understanding of the relationship between threats, vulnerabilities, controls and residual disruption risk.
For example:
Cyberattack → Technology vulnerability → Processing interruption → Cybersecurity and recovery controls → Residual risk
Loss of specialist personnel → Key-person dependency → Approval delays → Cross-training and succession → Residual risk
Supplier failure → External dependency → Service unavailable → Alternative arrangements → Residual risk
Premises loss → Workplace dependency → Employees unable to operate → Remote-working capability → Residual risk
This understanding enables Damanat to determine where preventive controls should be strengthened and where continuity and recovery arrangements must be established because disruption cannot reasonably be eliminated.
The RAR phase therefore provides a critical input into the remaining BCM methodology:
Project Management
→ Risk Analysis and Review
→ Business Impact Analysis
→ Business Continuity Strategy
→ Plan Development
→ Testing and Exercising
→ Program Management
With Damanat's disruption threats and vulnerabilities identified, assessed, and prioritised, the next phase shifts from examining the cause of disruption to its business consequences.
The next chapter, Business Impact Analysis (BIA), should therefore answer the critical question:
“If one of Damanat's business activities is interrupted, how severe will the impact become over time, and how quickly must that activity be recovered?”
The resulting recovery priorities, recovery objectives, dependency requirements and minimum resource needs will provide the basis for developing Damanat's Business Continuity Strategies.
| eBook 2: Implementing Business Continuity Management | ||||
| C1 | C2 | C3 | C4 | C5 |
![]() |
![]() |
![]() |
![]() |
![]() |
| C6 | C7 | C8 | C9 | C10 |
![]() |
![]() |
![]() |
![]() |
![]() |
More Information About Business Continuity Management Courses
To learn more about the course and schedule, click the buttons below for BCM-300 Business Continuity Management Implementer [BCM-3] and BCM-5000 Business Continuity Management Expert Implementer [BCM-5]


![[BCM] [Damanat] [Full Banner] Implementing BCM for The Saudi Mortgage Guarantees Services Company](https://no-cache.hubspot.com/cta/default/3893111/221734db-8c33-48bd-8147-fc740eecaf83.png)



![[BCM] [Damanat] [E2] [C3] Risk Analysis and Review](https://no-cache.hubspot.com/cta/default/3893111/5423f27a-6048-40c1-b55c-238fafb59648.png)
![Banner [Summary] [BCM] [E2] [C3] Risk Analysis and Review](https://no-cache.hubspot.com/cta/default/3893111/a7beedb7-3b4e-4374-ae50-974a76b94b61.png)
![[BCM] [Damanat] [3/4 Banner] Implementing BCM for The Saudi Mortgage Guarantees Services Company](https://no-cache.hubspot.com/cta/default/3893111/0252380a-b2dc-4059-be10-b5566002b711.png)
![[BCM] [Damanat] [E2] [C1] Business Continuity Management Planning Methodology](https://no-cache.hubspot.com/cta/default/3893111/b17b614b-c36c-4437-95ca-5c1d44ac6ce3.png)
![[BCM] [Damanat] [E2] [C2] Project Management](https://no-cache.hubspot.com/cta/default/3893111/4663bc6b-2e85-4e17-b6af-b5c784413b28.png)
![[BCM] [Damanat] [E2] [C4] Business Impact Analysis](https://no-cache.hubspot.com/cta/default/3893111/7a3c1a1f-d7f6-4d5d-8fef-deedc7d91f63.png)
![[BCM] [Damanat] [E2] [C5] Business Continuity Strategy](https://no-cache.hubspot.com/cta/default/3893111/a27d7e1e-8571-421d-9467-cc02614820e1.png)
![[BCM] [Damanat] [E2] [C6] BCM Plan Development](https://no-cache.hubspot.com/cta/default/3893111/ebff27c2-d3e9-4f2c-9a4c-0534e01fa535.png)
![[BCM] [Damanat] [E2] [C7] Testing and Exercising](https://no-cache.hubspot.com/cta/default/3893111/ed03c310-870a-482d-bac6-446897084091.png)
![[BCM] [Damanat] [E2] [C8] Program Management](https://no-cache.hubspot.com/cta/default/3893111/f52be888-834d-480c-9149-1167d38f1147.png)
![[BCM] [Damanat] [E2] [C9] Summary](https://no-cache.hubspot.com/cta/default/3893111/dab5bc8f-3d96-444b-880f-78cf037fc906.png)
![[BCM] [Damanat] [E2] [C10] Back Cover](https://no-cache.hubspot.com/cta/default/3893111/351b85f0-d850-4dee-a5c0-55c2b37c3075.png)


![Register [BL-B-3]*](https://no-cache.hubspot.com/cta/default/3893111/ac6cf073-4cdd-4541-91ed-889f731d5076.png)



![FAQ [BL-B-3]](https://no-cache.hubspot.com/cta/default/3893111/b3824ba1-7aa1-4eb6-bef8-94f57121c5ae.png)
![Email to Sales Team [BCM Institute]](https://no-cache.hubspot.com/cta/default/3893111/3c53daeb-2836-4843-b0e0-645baee2ab9e.png)





