Ebook

[BCM] [Damanat] [E2] [C3] Risk Analysis and Review

Written by Dr Goh Moh Heng | Jul 27, 2026, 8:37:29 AM

eBook 2: Chapter 3

 

Risk Analysis and Review Phase of the BCM Planning Methodology for 

The Saudi Mortgage Guarantees Services Company

 

Introduction


The Risk Analysis and Review (RAR) phase is the second implementation phase of the Business Continuity Management (BCM) Planning Methodology for The Saudi Mortgage Guarantees Services Company (Damanat).

Following the establishment of the BCM project, scope, governance structure, responsibilities and implementation arrangements during the Project Management phase, Damanat must determine the disruptive events that could prevent its business functions from operating normally.

The purpose of Risk Analysis and Review is therefore to answer four fundamental questions:

  • What could disrupt Damanat's operations?
  • How likely is the disruption to occur?
  • How serious could the consequences be?
  • What controls or treatments are required to reduce the risk?

Risk Analysis and Review should not be confused with the organisation's broader Enterprise Risk Management process.

While the two disciplines should be integrated, BCM-oriented risk assessment focuses specifically on threats that can cause business interruption, loss of critical resources, or a prolonged inability to perform important business activities.

For Damanat, these threats could affect mortgage guarantee origination, guarantee administration, claims processing, financial operations, interfaces with participating financial institutions, technology platforms, customer services, regulatory reporting, or other activities supporting the organisation's mandate.

The RAR methodology presented in this chapter consists of four principal steps:

Step 1 – Identifying Risks

Recognising potential threats that could disrupt operations.

Step 2 – Assessing Risks

Evaluating the likelihood and impact of identified risks.

Step 3 – Mitigating Risks

Implementing controls to reduce risks to an acceptable level.

Step 4 – Continuous Review

Regularly updating the risk profile in response to changes in the business environment.

Together, these steps provide Damanat with a structured mechanism to understand its disruption exposure and determine whether existing preventive and mitigating controls provide sufficient protection.

 

Purpose of Risk Analysis and Review

The primary objective of RAR is to identify the threats, vulnerabilities, and single points of failure that could disrupt Damanat's critical activities and to determine whether appropriate controls are in place.

The analysis should provide management with an understanding of:

  • potential disruption threats;
  • affected business functions;
  • vulnerabilities;
  • single points of failure;
  • existing preventive controls;
  • existing mitigating controls;
  • likelihood of disruption;
  • potential disruption impact;
  • overall risk level;
  • residual risk after existing controls;
  • additional treatment requirements; and
  • responsibility for implementing improvements.

The output should be documented in a BCM Threat and Risk Register.

The RAR is subsequently used together with the Business Impact Analysis (BIA). The two assessments answer different but complementary questions:

 

Assessment

Primary Question

Risk Analysis and Review

What could cause the disruption?

Business Impact Analysis

What happens if the activity is disrupted?

The RAR identifies potential causes, while the BIA determines the consequences of losing the affected business activity over time.

 

Relationship Between RAR and ISO 22301

ISO 22301 requires organisations implementing a Business Continuity Management System to understand the risks and opportunities that affect the effectiveness of the management system and to systematically analyse potential disruptions and their consequences.

For Damanat, this means that risk assessment should be part of the overall BCM lifecycle rather than a one-time exercise.

The RAR methodology should:

  • be formally defined;
  • use consistent assessment criteria;
  • include relevant internal and external threats;
  • consider dependencies and vulnerabilities;
  • identify treatment requirements;
  • be documented;
  • be approved through appropriate governance;
  • be reviewed periodically; and
  • be updated following material organisational or environmental changes.

The results should also inform strategy development, Business Continuity Plan preparation and scenario selection for BCM exercises.

 

Regulatory Context for Damanat

The Saudi Central Bank's Business Continuity Management Framework explicitly integrates Business Impact Analysis and Risk Assessment as core BCM requirements.

The current SAMA Rulebook states that the methodology for both activities should be defined, approved, implemented and maintained.

The framework requires periodic business continuity risk assessments that consider internal and external threats and single points of failure affecting people, processes, technology, and premises.

It further calls for risks to be prioritised based on their operational impact and probability, appropriate controls to be selected, and treatment plans to be implemented.

SAMA also states that BIA and risk assessment should be updated annually and following major changes involving areas such as organisational structure, people, processes, technology, suppliers and locations.

The framework additionally addresses the continuity capability of vendors, suppliers, and service providers that support prioritised activities.

For Damanat, these principles provide a useful regulatory basis for establishing a structured and repeatable RAR process.

 

The Four-Step RAR Methodology

Damanat's Risk Analysis and Review methodology should be structured around four interrelated steps:

Step 1 — Identify Risks

Identify the threats that could disrupt Damanat's activities and resources.

Step 2 — Assess Risks

Determine the likelihood and potential impact of each identified threat.

Step 3 — Mitigate Risks

Determine whether existing controls are sufficient and implement additional controls where required.

Step 4 — Continuously Review Risks

Monitor changes in threats, vulnerabilities, operations and dependencies and update the risk assessment accordingly.

The cycle can be represented as:

Identify → Assess → Mitigate → Review → Re-identify

This reinforces an important BCM principle: risk assessment is dynamic rather than static.

 

Step 1 — Identifying Risks

Risk identification begins by determining what events or circumstances could interrupt Damanat's ability to perform its business functions.

Threat identification should consider both internal and external threats.

Internal Threats

Internal threats originate primarily within the organisation or from resources under its direct management.

Examples include:

  • application or system failure;
  • database corruption;
  • internal network failure;
  • human error;
  • processing error;
  • inadequate change management;
  • loss of critical personnel;
  • internal fraud;
  • failure of internal procedures;
  • equipment failure;
  • accidental deletion of critical information;
  • inadequate segregation of duties;
  • building systems failure; and
  • failure of internal control processes.
External Threats

External threats arise outside Damanat but may significantly affect its ability to operate.

Examples include:

  • telecommunications disruption;
  • electricity failure;
  • cyberattack;
  • ransomware;
  • denial-of-service attack;
  • third-party service-provider failure;
  • cloud service interruption;
  • disruption affecting participating financial institutions;
  • severe weather;
  • regional infrastructure disruption;
  • fire affecting neighbouring premises;
  • transportation disruption;
  • civil emergencies;
  • supply-chain disruption; and
  • external data-provider failure.

The objective is not to predict every possible event. It is to identify credible categories of disruption that could materially affect Damanat's ability to perform priority activities.

 

Risk Identification by Resource Category

A practical RAR should examine threats by the resources required to deliver business activities.

For Damanat, these can be structured around:

People → Process → Technology → Premises → Information → Third Parties

 

People Risks

Damanat may depend on employees with specialist knowledge, authority or expertise.

Potential threats include:

  • unavailability of key personnel;
  • widespread illness;
  • inability of employees to reach the workplace;
  • loss of specialist technical expertise;
  • resignation of critical personnel;
  • inadequate succession arrangements; and
  • excessive dependency on individual employees.
Damanat Example

Suppose only a small number of employees are authorised to approve particular mortgage guarantee transactions.

If those employees become unavailable simultaneously, the processing system may remain operational, but guaranteed approvals could still stop.

The underlying business continuity threat is therefore concentration of critical authority within too few individuals.

 

Process Risks

Business processes can contain single points of failure even when supporting technology remains available.

Potential vulnerabilities include:

  • excessive manual approvals;
  • dependency on one processing team;
  • poorly documented procedures;
  • sequential processes with no workaround;
  • inadequate segregation of responsibilities;
  • unavailable approval authorities; and
  • dependencies between business units.
Damanat Example

Consider the following workflow:

Mortgage Guarantee Application Intake

→ Application Validation

→ Borrower Eligibility Assessment

→ Property Eligibility Assessment

→ Mortgage Risk Assessment

→ Guarantee Approval

→ Guarantee Certificate Generation

If the Mortgage Risk Assessment activity cannot be completed, downstream approval and certificate generation may also stop.

The RAR should therefore examine not merely individual functions but also process dependencies and bottlenecks.

 

Technology Risks

Damanat's business activities are likely to depend extensively on technology systems, data, communications and connectivity.

Threats may include:

  • application failure;
  • database failure;
  • network outage;
  • storage failure;
  • cybersecurity incident;
  • ransomware;
  • telecommunications failure;
  • interface failure;
  • authentication service failure;
  • data-centre outage;
  • cloud service interruption;
  • backup failure; and
  • failure during system change or upgrade.
Damanat Example

A failure affecting the technology platform used to receive and process mortgage guarantee applications could prevent:

  • applications from being received;
  • applications from being validated;
  • assessments from being completed;
  • approvals from being recorded;
  • guarantee certificates from being generated; and
  • participating financial institutions from receiving confirmation.

This demonstrates how one technology dependency can affect multiple business processes simultaneously.

 

Premises and Physical Infrastructure Risks

Although many activities can increasingly be performed remotely, Damanat should still assess the risks associated with the loss of its premises and physical infrastructure.

Threats may include:

  • fire;
  • water damage;
  • building evacuation;
  • access restriction;
  • utility outage;
  • air-conditioning failure;
  • physical security incident;
  • telecommunications failure;
  • transportation disruption; and
  • prolonged building closure.

The analysis should determine whether essential activities can be relocated or performed remotely and whether critical equipment remains accessible.

 

Information and Data Risks

Business continuity depends not only on systems but also on the information contained within those systems.

Potential risks include:

  • data corruption;
  • data loss;
  • inaccessible records;
  • unavailable documentation;
  • backup failure;
  • loss of transaction records;
  • database integrity failure; and
  • inability to retrieve historical records.
Damanat Example

If Damanat's application processing platform is restored after a disruption but several hours of recently approved guarantee transactions cannot be recovered, operational capability has technically returned, but business recovery remains incomplete.

RAR should therefore consider both:

System Availability + Information Recoverability

 

Third-Party and External Dependency Risks

Damanat should identify organisations whose failure could disrupt its own activities.

These may include:

  • participating financial institutions;
  • telecommunications providers;
  • technology vendors;
  • hosting providers;
  • cloud providers;
  • data providers;
  • payment-related service providers;
  • facilities providers;
  • professional service providers; and
  • specialist outsourced suppliers.

The risk assessment should consider:

  • dependency concentration;
  • alternative suppliers;
  • contractual recovery requirements;
  • supplier disaster-recovery capabilities;
  • supplier geographical concentration;
  • supplier cybersecurity exposure; and
  • Damanat's ability to operate temporarily without the supplier.
Damanat Example

If a critical third-party interface that supports the exchange of mortgage guarantee application information becomes unavailable, Damanat may remain internally operational but be unable to receive or transmit required information to participating financial institutions.

The RAR must therefore extend beyond Damanat's organisational boundary.

 

Identifying Single Points of Failure

A single point of failure (SPOF) is a resource whose loss could interrupt an activity because there is no effective alternative.

SPOFs are particularly important in BCM.

Examples for Damanat may include:

 

Resource

Possible Single Point of Failure

People

One employee holding specialist approval authority

Process

One mandatory approval stage with no delegated alternative

Technology

One application supporting guarantee processing

Data

One repository containing critical records

Connectivity

One communications link

Premises

One location supporting a critical activity

Supplier

One provider with no substitute

Interface

One gateway connecting Damanat with an external institution

The RAR should explicitly identify these vulnerabilities because eliminating or reducing SPOFs often provides significant improvement in continuity capability.

 

Developing the Threat Register

All identified threats should be documented within a Threat Register.

An illustrative Damanat register could include:

 

Ref

Threat

Potentially Affected Resource

Potential Disruption

T01

Critical application failure

Technology

Mortgage guarantee processing unavailable

T02

Cyberattack/ransomware

Technology / Information

Systems or data inaccessible

T03

Telecommunications outage

Technology

External connectivity unavailable

T04

Power failure

Premises / Technology

Office or technology operations interrupted

T05

Loss of key personnel

People

Critical approval or specialist activity unavailable

T06

Fire or premises loss

Premises

Primary workplace unavailable

T07

Third-party technology failure

Supplier

Dependent services unavailable

T08

Data corruption

Information

Transaction information unreliable

T09

Participating financial institution interface failure

External dependency

Application exchange interrupted

T10

Major process error

Process

Processing suspended pending correction

T11

Widespread employee unavailability

People

Insufficient staffing

T12

Major infrastructure disruption

External environment

Multiple resources affected

The detailed Threat Register can subsequently be expanded as additional Damanat-specific threats are identified.

 

Step 2 — Assessing Risks

Once threats have been identified, Damanat should determine their relative significance.

A practical BCM risk assessment normally considers:

Risk = Likelihood × Impact

This enables threats to be prioritised according to their potential to cause material business interruption.

 

Assessing Likelihood

Likelihood reflects the probability or frequency of a disruptive event.

An illustrative five-level scale is:

Rating

Likelihood

Description

1

Rare

Event would occur only under exceptional circumstances

2

Unlikely

Event could occur but is not expected

3

Possible

Event may occur periodically

4

Likely

Event is reasonably expected to occur

5

Almost Certain

Event occurs frequently or is strongly expected

Likelihood should not be based solely on personal opinion.

Damanat may consider:

  • previous incidents;
  • internal loss data;
  • industry experience;
  • audit findings;
  • threat intelligence;
  • technology incidents;
  • supplier performance;
  • environmental conditions;
  • operational changes; and
  • expert judgement.

 

Assessing Impact

Impact reflects the severity of disruption if the threat materialises.

An illustrative five-level scale could be:

 

Rating

Impact

General Interpretation

1

Insignificant

Negligible operational disruption

2

Minor

Limited interruption manageable through normal procedures

3

Moderate

Noticeable interruption requiring management intervention

4

Major

Significant interruption to important business functions

5

Severe

Prolonged or widespread inability to perform critical activities

Impact assessment may consider:

  • operational disruption;
  • financial consequences;
  • customer impact;
  • participating financial institution impact;
  • legal consequences;
  • regulatory consequences;
  • reputational damage;
  • data impact; and
  • strategic consequences.

 

Risk Scoring

A simple risk rating can be calculated as:

Likelihood Rating × Impact Rating = Risk Score

For example:

Threat

Likelihood

Impact

Risk Score

Application platform outage

3

5

15

Loss of one office area

2

3

6

Telecommunications failure

3

4

12

Loss of specialist personnel

3

4

12

Major cyberattack

4

5

20

The score enables Damanat to prioritise risks requiring additional attention.

The numerical result should, however, support rather than replace professional judgement.

A relatively low-probability event may still require significant continuity arrangements where its consequences would be severe.

 

Inherent and Residual Risk

The assessment should distinguish between inherent risk and residual risk.

Inherent Risk

The level of risk assuming existing controls are absent or ineffective.

Residual Risk

The level of risk remaining after existing controls have been considered.

The process can be represented as:

Inherent Risk → Existing Controls → Residual Risk

This distinction is important because a threat may have severe inherent consequences but already be well controlled.

Conversely, a relatively common threat may retain a high residual risk because existing controls are inadequate.

 

Evaluating Existing Controls

For each significant threat, Damanat should identify existing controls.

Controls may be:

Preventive Controls

Designed to reduce the probability of disruption.

Examples:

  • cybersecurity protection;
  • preventive maintenance;
  • redundant infrastructure;
  • access controls;
  • change management;
  • staff cross-training; and
  • supplier due diligence.
Detective Controls

Designed to identify abnormal conditions quickly.

Examples:

  • monitoring systems;
  • security alerts;
  • system health monitoring;
  • operational exception reporting; and
  • environmental alarms.
Mitigating or Recovery Controls

Designed to reduce the consequences after disruption occurs.

Examples:

  • backup systems;
  • alternate workplaces;
  • remote working;
  • system disaster recovery;
  • manual workarounds;
  • alternative suppliers;
  • cross-trained personnel; and
  • Business Continuity Plans.

 

Example Risk Assessment for Damanat

Consider the threat:

Threat: Mortgage Guarantee Processing Platform Failure
Potential Cause:

Hardware failure, software error, unsuccessful change, database issue or infrastructure outage.

Potential Impact:

Damanat may be unable to receive, assess, approve or issue mortgage guarantees.

Likelihood:

Possible – Rating 3.

Impact:

Severe – Rating 5.

Inherent Risk Score:

3 × 5 = 15

Existing Controls:
  • infrastructure redundancy;
  • system monitoring;
  • backup arrangements;
  • disaster recovery capability;
  • technical support;
  • incident management procedures.
Residual Risk:

To be determined after assessing the effectiveness of these controls.

Possible Additional Treatment:
  • increase system resilience;
  • strengthen failover capability;
  • improve recovery testing;
  • establish documented manual processing procedures;
  • improve alternative communication arrangements with participating financial institutions.

This structure provides a clear link between the identified threat and required continuity improvements.

 

Step 3 — Mitigating Risks

Risk mitigation determines what should be done about unacceptable risks.

Possible responses include:

Avoid

Stop or redesign the activity creating unacceptable exposure.

Reduce

Introduce additional preventive, detective or recovery controls.

Transfer

Transfer some consequences through insurance, outsourcing or contractual arrangements.

Accept

Formally accept residual risk where it falls within approved risk tolerance.

For BCM purposes, risk reduction is typically the most significant response, as Damanat may still need to perform the affected business activity.

 

Developing Risk Treatment Plans

Where residual risk exceeds acceptable levels, Damanat should establish a formal treatment plan.

The plan should identify:

  • identified risk;
  • control deficiency;
  • proposed improvement;
  • responsible owner;
  • required resources;
  • target completion date;
  • status;
  • residual risk after treatment; and
  • approval or acceptance authority.

An illustrative treatment register is:

 

Risk

Weakness

Treatment

Owner

Target

Key-person dependency

One specialist performs critical activity

Cross-train additional employees

Business Owner

Q3

Technology failure

Insufficient recovery capability

Enhance DR architecture

IT

Q4

Supplier failure

No alternative service provider

Establish contingency arrangement

Procurement

Q4

Premises loss

Limited alternative workspace

Expand remote working capability

Administration / IT

Q3

Data loss

Recovery arrangements not recently validated

Conduct restoration test

IT

Q2

The treatment register should be reviewed through Damanat's BCM governance structure.

 

Selecting Appropriate BCM Controls

Mitigation should consider the relationship between:

Threat → Vulnerability → Control → Residual Risk

For example:

Threat

Critical employee becomes unavailable.

Vulnerability

Only one employee understands a specialist guarantee-processing activity.

Control

Cross-train two additional employees and document the procedure.

Residual Risk

Reduced dependency on a single individual.

This approach ensures that controls directly address identified vulnerabilities rather than being implemented simply because they are considered good practice.

 

Risk Acceptance

Not every identified risk can be eliminated.

Some residual risks may be accepted where:

  • further control is technically impractical;
  • treatment cost is disproportionate;
  • the exposure falls within approved risk tolerance; or
  • alternative continuity arrangements adequately manage the potential consequences.

Risk acceptance should not occur informally.

Significant residual risks should be:

  • documented;
  • supported by justification;
  • assigned to a risk owner;
  • approved at the appropriate level; and
  • reviewed periodically.

 

Linking Risk Treatment to Business Continuity Strategy

Some RAR findings cannot be eliminated through preventive controls.

For example, Damanat cannot guarantee that:

  • an office will never become inaccessible;
  • a telecommunications provider will never fail;
  • a cyberattack will never occur;
  • a critical supplier will never experience disruption; or
  • employees will always be available.

The BCM approach must therefore combine:

Prevention + Preparedness + Response + Recovery

Where disruption cannot reasonably be prevented, the risk should be incorporated into the Business Continuity Strategy phase.

For example:

Risk

Possible Continuity Strategy

Primary office unavailable

Remote working / alternate site

Critical employee unavailable

Cross-training / succession

Technology application unavailable

Disaster recovery / manual workaround

Supplier unavailable

Alternative supplier

Data centre unavailable

Alternate recovery environment

Telecommunications unavailable

Alternative communications

External interface unavailable

Alternative information exchange procedure

RAR therefore establishes an important bridge between risk management and continuity strategy.

 

Step 4 — Continuous Review

Damanat's risk environment will change continuously.

New technologies, suppliers, processes, regulations, business arrangements and threat conditions can create risks that were not present during the original assessment.

Risk Analysis and Review must therefore become an ongoing management activity.

The SAMA BCM Framework specifically states that BIA and risk assessment should be updated annually and when major changes occur involving areas such as people, processes, technology, suppliers and locations.

For Damanat, review triggers should include:

  • significant organisational restructuring;
  • introduction of new products or services;
  • implementation of new technology;
  • major system upgrades;
  • outsourcing arrangements;
  • appointment or replacement of critical suppliers;
  • relocation of operations;
  • emerging cyber threats;
  • actual disruption incidents;
  • audit findings;
  • exercise findings;
  • regulatory change;
  • major process redesign; and
  • changes involving participating financial institutions or external interfaces.

 

Lessons from Incidents and Exercises

Actual incidents and BCM exercises provide valuable information about risks that may not have been identified during workshops.

For example, an exercise might reveal that:

  • employees cannot access a required application remotely;
  • contact information is outdated;
  • a supplier's recovery time exceeds Damanat's requirement;
  • alternative communication channels have insufficient capacity;
  • an approval process depends on one individual; or
  • backup data cannot be restored within the required timeframe.

These findings should be incorporated into the Threat and Risk Register.

The continuous improvement cycle therefore becomes:

Incident / Exercise → Lesson Identified → Risk Reassessed → Control Improved → Capability Revalidated

 

Reviewing Third-Party Risks

Third-party risk should receive particular attention during periodic review.

The SAMA BCM Framework calls for the capability of vendors, suppliers, and service providers to support prioritised activities during disruptive incidents to be assessed at least annually.

For Damanat, this review could examine:

  • supplier continuity plans;
  • disaster-recovery capabilities;
  • testing frequency;
  • recovery times;
  • alternative operating locations;
  • subcontractor dependency;
  • concentration risks;
  • communication procedures;
  • contractual BCM requirements; and
  • evidence of recent continuity testing.

A contract stating that a provider has a Business Continuity Plan should not automatically be considered sufficient evidence of resilience.

Damanat should determine whether the provider's actual recovery capability is consistent with Damanat's own recovery requirements.

 

Risk Analysis at the Critical Business Function Level

RAR should eventually be applied to Damanat's identified Critical Business Functions.

For example, for:

CBF-1 Mortgage Guarantee Origination

Potential disruption scenarios could include:

Threat

Possible Effect

Application intake interface failure

New guarantee applications cannot be received

Processing application failure

Applications cannot progress

Specialist staff unavailable

Risk assessments cannot be completed

Approval authority unavailable

Guarantee decisions delayed

Database corruption

Application information becomes unreliable

Cyberattack

Processing platform inaccessible

Participating financial institution connectivity failure

Application exchange interrupted

Guarantee certificate system failure

Approved guarantees cannot be formally issued

This level of assessment enables risk analysis to reflect actual operating processes rather than generic organisational threats.

 

Recommended Damanat RAR Register

Damanat's BCM Risk Register should contain sufficient information to support risk treatment and future continuity planning.

A recommended structure is:

Field

Purpose

Risk Reference

Unique identifier

Business Function

Activity exposed to the risk

Threat

Disruption event

Cause

Why the event could occur

Vulnerability

Weakness enabling disruption

Affected Resource

People, process, technology, premises, information or supplier

Existing Controls

Controls already implemented

Likelihood

Probability rating

Impact

Severity rating

Inherent Risk

Risk before controls

Control Effectiveness

Adequacy of existing controls

Residual Risk

Risk after controls

Required Treatment

Additional improvement

Risk Owner

Responsible individual

Target Date

Completion requirement

Status

Current progress

Review Date

Next assessment

Remarks

Additional observations

This register should become the principal evidence of the RAR process.

 

RAR Deliverables

At the conclusion of the Risk Analysis and Review phase, Damanat should have produced at minimum:

Ref

Deliverable

Purpose

RAR-01

RAR Methodology

Establishes assessment approach

RAR-02

Threat Catalogue

Documents credible disruption threats

RAR-03

Likelihood Criteria

Standardises probability assessment

RAR-04

Impact Criteria

Standardises consequence assessment

RAR-05

Risk Matrix

Defines risk prioritisation

RAR-06

Threat and Risk Register

Records assessed BCM risks

RAR-07

Single Point of Failure Register

Identifies critical vulnerabilities

RAR-08

Existing Control Assessment

Determines control adequacy

RAR-09

Risk Treatment Plan

Records required improvements

RAR-10

Residual Risk Register

Records remaining exposures

RAR-11

Third-Party Continuity Assessment

Assesses important suppliers

RAR-12

Management RAR Report

Provides governance oversight

 

Completion Criteria for the RAR Phase

Damanat should consider the RAR sufficiently complete when:

  • relevant internal and external threats have been identified;
  • people, process, technology, premises, information and supplier risks have been considered;
  • single points of failure have been identified;
  • likelihood and impact criteria have been consistently applied;
  • inherent risks have been assessed;
  • existing controls have been evaluated;
  • residual risks have been determined;
  • unacceptable risks have treatment plans;
  • risk owners have been assigned;
  • significant residual risks have been escalated;
  • third-party continuity risks have been considered;
  • results have been reviewed through appropriate BCM governance; and
  • mechanisms for periodic review have been established.

The output can then be used as input to the Business Impact Analysis and, later, to continuity strategy development.

 

Relationship Between RAR and the Next BCM Phase

Risk Analysis and Review identifies how disruption could occur.

The next phase, Business Impact Analysis, determines the consequences if the disruption actually occurred.

For example:

RAR Finding

A technology failure could prevent Mortgage Guarantee Origination.

The RAR evaluates:

  • the cause;
  • likelihood;
  • vulnerabilities;
  • controls; and
  • residual risk.
BIA Question

If Mortgage Guarantee Origination becomes unavailable:

  • what happens after four hours?
  • what happens after one day?
  • what happens after three days?
  • when do consequences become unacceptable?
  • which activities must recover first?
  • what resources are required?
  • what recovery time should be established?

The two assessments therefore work together.

RAR identifies the threat.
BIA quantifies the business consequence.
BCS determines the recovery solution.

The Risk Analysis and Review phase enables The Saudi Mortgage Guarantees Services Company to understand what could disrupt its operations and whether existing controls provide sufficient protection against those disruptions.

For Damanat, the analysis should extend beyond conventional physical threats to consider the interconnected environment that supports mortgage guarantee operations.

This includes people, processes, technology, information, premises, participating financial institutions, outsourced service providers and other critical external dependencies.

The RAR methodology is built around four continuing activities:

Identify Risks → Assess Risks → Mitigate Risks → Continuously Review Risks

Risk identification establishes Damanat's threat landscape.

Risk assessment determines which threats require the greatest attention by considering likelihood and impact.

Risk mitigation determines whether existing controls are sufficient and establishes additional treatments where residual exposure remains unacceptable.

Continuous review ensures that the risk profile changes alongside Damanat's organisation, technology, processes, suppliers, operating environment and emerging threats.

The most important output of this phase is therefore not simply a list of threats. It is a structured understanding of the relationship between threats, vulnerabilities, controls and residual disruption risk.

For example:

Cyberattack → Technology vulnerability → Processing interruption → Cybersecurity and recovery controls → Residual risk
 
Loss of specialist personnel → Key-person dependency → Approval delays → Cross-training and succession → Residual risk
 
Supplier failure → External dependency → Service unavailable → Alternative arrangements → Residual risk
 
Premises loss → Workplace dependency → Employees unable to operate → Remote-working capability → Residual risk

This understanding enables Damanat to determine where preventive controls should be strengthened and where continuity and recovery arrangements must be established because disruption cannot reasonably be eliminated.

The RAR phase therefore provides a critical input into the remaining BCM methodology:

Project Management

→ Risk Analysis and Review

→ Business Impact Analysis

→ Business Continuity Strategy

→ Plan Development

→ Testing and Exercising

→ Program Management

With Damanat's disruption threats and vulnerabilities identified, assessed, and prioritised, the next phase shifts from examining the cause of disruption to its business consequences.

The next chapter, Business Impact Analysis (BIA), should therefore answer the critical question:

“If one of Damanat's business activities is interrupted, how severe will the impact become over time, and how quickly must that activity be recovered?”

The resulting recovery priorities, recovery objectives, dependency requirements and minimum resource needs will provide the basis for developing Damanat's Business Continuity Strategies.

 

eBook 2: Implementing Business Continuity Management
C1 C2 C3 C4 C5
C6 C7 C8 C9 C10
 

More Information About Business Continuity Management Courses

To learn more about the course and schedule, click the buttons below for BCM-300 Business Continuity Management Implementer [BCM-3] and BCM-5000 Business Continuity Management Expert Implementer [BCM-5]

 

Please feel free to send us a note if you have any questions.