The Risk Analysis and Review (RAR) phase is the second implementation phase of the Business Continuity Management (BCM) Planning Methodology for The Saudi Mortgage Guarantees Services Company (Damanat).
Following the establishment of the BCM project, scope, governance structure, responsibilities and implementation arrangements during the Project Management phase, Damanat must determine the disruptive events that could prevent its business functions from operating normally.
The purpose of Risk Analysis and Review is therefore to answer four fundamental questions:
Risk Analysis and Review should not be confused with the organisation's broader Enterprise Risk Management process.
While the two disciplines should be integrated, BCM-oriented risk assessment focuses specifically on threats that can cause business interruption, loss of critical resources, or a prolonged inability to perform important business activities.
For Damanat, these threats could affect mortgage guarantee origination, guarantee administration, claims processing, financial operations, interfaces with participating financial institutions, technology platforms, customer services, regulatory reporting, or other activities supporting the organisation's mandate.
The RAR methodology presented in this chapter consists of four principal steps:
Recognising potential threats that could disrupt operations.
Evaluating the likelihood and impact of identified risks.
Implementing controls to reduce risks to an acceptable level.
Regularly updating the risk profile in response to changes in the business environment.
Together, these steps provide Damanat with a structured mechanism to understand its disruption exposure and determine whether existing preventive and mitigating controls provide sufficient protection.
The primary objective of RAR is to identify the threats, vulnerabilities, and single points of failure that could disrupt Damanat's critical activities and to determine whether appropriate controls are in place.
The analysis should provide management with an understanding of:
The output should be documented in a BCM Threat and Risk Register.
The RAR is subsequently used together with the Business Impact Analysis (BIA). The two assessments answer different but complementary questions:
|
Assessment |
Primary Question |
|
Risk Analysis and Review |
What could cause the disruption? |
|
Business Impact Analysis |
What happens if the activity is disrupted? |
The RAR identifies potential causes, while the BIA determines the consequences of losing the affected business activity over time.
ISO 22301 requires organisations implementing a Business Continuity Management System to understand the risks and opportunities that affect the effectiveness of the management system and to systematically analyse potential disruptions and their consequences.
For Damanat, this means that risk assessment should be part of the overall BCM lifecycle rather than a one-time exercise.
The RAR methodology should:
The results should also inform strategy development, Business Continuity Plan preparation and scenario selection for BCM exercises.
The Saudi Central Bank's Business Continuity Management Framework explicitly integrates Business Impact Analysis and Risk Assessment as core BCM requirements.
The current SAMA Rulebook states that the methodology for both activities should be defined, approved, implemented and maintained.
The framework requires periodic business continuity risk assessments that consider internal and external threats and single points of failure affecting people, processes, technology, and premises.
It further calls for risks to be prioritised based on their operational impact and probability, appropriate controls to be selected, and treatment plans to be implemented.
SAMA also states that BIA and risk assessment should be updated annually and following major changes involving areas such as organisational structure, people, processes, technology, suppliers and locations.
The framework additionally addresses the continuity capability of vendors, suppliers, and service providers that support prioritised activities.
For Damanat, these principles provide a useful regulatory basis for establishing a structured and repeatable RAR process.
Damanat's Risk Analysis and Review methodology should be structured around four interrelated steps:
Identify the threats that could disrupt Damanat's activities and resources.
Determine the likelihood and potential impact of each identified threat.
Determine whether existing controls are sufficient and implement additional controls where required.
Monitor changes in threats, vulnerabilities, operations and dependencies and update the risk assessment accordingly.
The cycle can be represented as:
This reinforces an important BCM principle: risk assessment is dynamic rather than static.
Risk identification begins by determining what events or circumstances could interrupt Damanat's ability to perform its business functions.
Threat identification should consider both internal and external threats.
Internal threats originate primarily within the organisation or from resources under its direct management.
Examples include:
External threats arise outside Damanat but may significantly affect its ability to operate.
Examples include:
The objective is not to predict every possible event. It is to identify credible categories of disruption that could materially affect Damanat's ability to perform priority activities.
A practical RAR should examine threats by the resources required to deliver business activities.
For Damanat, these can be structured around:
Damanat may depend on employees with specialist knowledge, authority or expertise.
Potential threats include:
Suppose only a small number of employees are authorised to approve particular mortgage guarantee transactions.
If those employees become unavailable simultaneously, the processing system may remain operational, but guaranteed approvals could still stop.
The underlying business continuity threat is therefore concentration of critical authority within too few individuals.
Business processes can contain single points of failure even when supporting technology remains available.
Potential vulnerabilities include:
Consider the following workflow:
Mortgage Guarantee Application Intake
→ Application Validation
→ Borrower Eligibility Assessment
→ Property Eligibility Assessment
→ Mortgage Risk Assessment
→ Guarantee Approval
→ Guarantee Certificate Generation
If the Mortgage Risk Assessment activity cannot be completed, downstream approval and certificate generation may also stop.
The RAR should therefore examine not merely individual functions but also process dependencies and bottlenecks.
Damanat's business activities are likely to depend extensively on technology systems, data, communications and connectivity.
Threats may include:
A failure affecting the technology platform used to receive and process mortgage guarantee applications could prevent:
This demonstrates how one technology dependency can affect multiple business processes simultaneously.
Although many activities can increasingly be performed remotely, Damanat should still assess the risks associated with the loss of its premises and physical infrastructure.
Threats may include:
The analysis should determine whether essential activities can be relocated or performed remotely and whether critical equipment remains accessible.
Business continuity depends not only on systems but also on the information contained within those systems.
Potential risks include:
If Damanat's application processing platform is restored after a disruption but several hours of recently approved guarantee transactions cannot be recovered, operational capability has technically returned, but business recovery remains incomplete.
RAR should therefore consider both:
Damanat should identify organisations whose failure could disrupt its own activities.
These may include:
The risk assessment should consider:
If a critical third-party interface that supports the exchange of mortgage guarantee application information becomes unavailable, Damanat may remain internally operational but be unable to receive or transmit required information to participating financial institutions.
The RAR must therefore extend beyond Damanat's organisational boundary.
A single point of failure (SPOF) is a resource whose loss could interrupt an activity because there is no effective alternative.
SPOFs are particularly important in BCM.
Examples for Damanat may include:
|
Resource |
Possible Single Point of Failure |
|
People |
One employee holding specialist approval authority |
|
Process |
One mandatory approval stage with no delegated alternative |
|
Technology |
One application supporting guarantee processing |
|
Data |
One repository containing critical records |
|
Connectivity |
One communications link |
|
Premises |
One location supporting a critical activity |
|
Supplier |
One provider with no substitute |
|
Interface |
One gateway connecting Damanat with an external institution |
The RAR should explicitly identify these vulnerabilities because eliminating or reducing SPOFs often provides significant improvement in continuity capability.
All identified threats should be documented within a Threat Register.
An illustrative Damanat register could include:
|
Ref |
Threat |
Potentially Affected Resource |
Potential Disruption |
|
T01 |
Critical application failure |
Technology |
Mortgage guarantee processing unavailable |
|
T02 |
Cyberattack/ransomware |
Technology / Information |
Systems or data inaccessible |
|
T03 |
Telecommunications outage |
Technology |
External connectivity unavailable |
|
T04 |
Power failure |
Premises / Technology |
Office or technology operations interrupted |
|
T05 |
Loss of key personnel |
People |
Critical approval or specialist activity unavailable |
|
T06 |
Fire or premises loss |
Premises |
Primary workplace unavailable |
|
T07 |
Third-party technology failure |
Supplier |
Dependent services unavailable |
|
T08 |
Data corruption |
Information |
Transaction information unreliable |
|
T09 |
Participating financial institution interface failure |
External dependency |
Application exchange interrupted |
|
T10 |
Major process error |
Process |
Processing suspended pending correction |
|
T11 |
Widespread employee unavailability |
People |
Insufficient staffing |
|
T12 |
Major infrastructure disruption |
External environment |
Multiple resources affected |
The detailed Threat Register can subsequently be expanded as additional Damanat-specific threats are identified.
Once threats have been identified, Damanat should determine their relative significance.
A practical BCM risk assessment normally considers:
Risk = Likelihood × Impact
This enables threats to be prioritised according to their potential to cause material business interruption.
Likelihood reflects the probability or frequency of a disruptive event.
An illustrative five-level scale is:
|
Rating |
Likelihood |
Description |
|
1 |
Rare |
Event would occur only under exceptional circumstances |
|
2 |
Unlikely |
Event could occur but is not expected |
|
3 |
Possible |
Event may occur periodically |
|
4 |
Likely |
Event is reasonably expected to occur |
|
5 |
Almost Certain |
Event occurs frequently or is strongly expected |
Likelihood should not be based solely on personal opinion.
Damanat may consider:
Impact reflects the severity of disruption if the threat materialises.
An illustrative five-level scale could be:
|
Rating |
Impact |
General Interpretation |
|
1 |
Insignificant |
Negligible operational disruption |
|
2 |
Minor |
Limited interruption manageable through normal procedures |
|
3 |
Moderate |
Noticeable interruption requiring management intervention |
|
4 |
Major |
Significant interruption to important business functions |
|
5 |
Severe |
Prolonged or widespread inability to perform critical activities |
Impact assessment may consider:
A simple risk rating can be calculated as:
Likelihood Rating × Impact Rating = Risk Score
For example:
|
Threat |
Likelihood |
Impact |
Risk Score |
|
Application platform outage |
3 |
5 |
15 |
|
Loss of one office area |
2 |
3 |
6 |
|
Telecommunications failure |
3 |
4 |
12 |
|
Loss of specialist personnel |
3 |
4 |
12 |
|
Major cyberattack |
4 |
5 |
20 |
The score enables Damanat to prioritise risks requiring additional attention.
The numerical result should, however, support rather than replace professional judgement.
A relatively low-probability event may still require significant continuity arrangements where its consequences would be severe.
The assessment should distinguish between inherent risk and residual risk.
The level of risk assuming existing controls are absent or ineffective.
The level of risk remaining after existing controls have been considered.
The process can be represented as:
This distinction is important because a threat may have severe inherent consequences but already be well controlled.
Conversely, a relatively common threat may retain a high residual risk because existing controls are inadequate.
For each significant threat, Damanat should identify existing controls.
Controls may be:
Designed to reduce the probability of disruption.
Examples:
Designed to identify abnormal conditions quickly.
Examples:
Designed to reduce the consequences after disruption occurs.
Examples:
Consider the threat:
Hardware failure, software error, unsuccessful change, database issue or infrastructure outage.
Damanat may be unable to receive, assess, approve or issue mortgage guarantees.
Possible – Rating 3.
Severe – Rating 5.
3 × 5 = 15
To be determined after assessing the effectiveness of these controls.
This structure provides a clear link between the identified threat and required continuity improvements.
Risk mitigation determines what should be done about unacceptable risks.
Possible responses include:
Stop or redesign the activity creating unacceptable exposure.
Introduce additional preventive, detective or recovery controls.
Transfer some consequences through insurance, outsourcing or contractual arrangements.
Formally accept residual risk where it falls within approved risk tolerance.
For BCM purposes, risk reduction is typically the most significant response, as Damanat may still need to perform the affected business activity.
Where residual risk exceeds acceptable levels, Damanat should establish a formal treatment plan.
The plan should identify:
An illustrative treatment register is:
|
Risk |
Weakness |
Treatment |
Owner |
Target |
|
Key-person dependency |
One specialist performs critical activity |
Cross-train additional employees |
Business Owner |
Q3 |
|
Technology failure |
Insufficient recovery capability |
Enhance DR architecture |
IT |
Q4 |
|
Supplier failure |
No alternative service provider |
Establish contingency arrangement |
Procurement |
Q4 |
|
Premises loss |
Limited alternative workspace |
Expand remote working capability |
Administration / IT |
Q3 |
|
Data loss |
Recovery arrangements not recently validated |
Conduct restoration test |
IT |
Q2 |
The treatment register should be reviewed through Damanat's BCM governance structure.
Mitigation should consider the relationship between:
For example:
Critical employee becomes unavailable.
Only one employee understands a specialist guarantee-processing activity.
Cross-train two additional employees and document the procedure.
Reduced dependency on a single individual.
This approach ensures that controls directly address identified vulnerabilities rather than being implemented simply because they are considered good practice.
Not every identified risk can be eliminated.
Some residual risks may be accepted where:
Risk acceptance should not occur informally.
Significant residual risks should be:
Some RAR findings cannot be eliminated through preventive controls.
For example, Damanat cannot guarantee that:
The BCM approach must therefore combine:
Where disruption cannot reasonably be prevented, the risk should be incorporated into the Business Continuity Strategy phase.
For example:
|
Risk |
Possible Continuity Strategy |
|
Primary office unavailable |
Remote working / alternate site |
|
Critical employee unavailable |
Cross-training / succession |
|
Technology application unavailable |
Disaster recovery / manual workaround |
|
Supplier unavailable |
Alternative supplier |
|
Data centre unavailable |
Alternate recovery environment |
|
Telecommunications unavailable |
Alternative communications |
|
External interface unavailable |
Alternative information exchange procedure |
RAR therefore establishes an important bridge between risk management and continuity strategy.
Damanat's risk environment will change continuously.
New technologies, suppliers, processes, regulations, business arrangements and threat conditions can create risks that were not present during the original assessment.
Risk Analysis and Review must therefore become an ongoing management activity.
The SAMA BCM Framework specifically states that BIA and risk assessment should be updated annually and when major changes occur involving areas such as people, processes, technology, suppliers and locations.
For Damanat, review triggers should include:
Actual incidents and BCM exercises provide valuable information about risks that may not have been identified during workshops.
For example, an exercise might reveal that:
These findings should be incorporated into the Threat and Risk Register.
The continuous improvement cycle therefore becomes:
Third-party risk should receive particular attention during periodic review.
The SAMA BCM Framework calls for the capability of vendors, suppliers, and service providers to support prioritised activities during disruptive incidents to be assessed at least annually.
For Damanat, this review could examine:
A contract stating that a provider has a Business Continuity Plan should not automatically be considered sufficient evidence of resilience.
Damanat should determine whether the provider's actual recovery capability is consistent with Damanat's own recovery requirements.
RAR should eventually be applied to Damanat's identified Critical Business Functions.
For example, for:
Potential disruption scenarios could include:
|
Threat |
Possible Effect |
|
Application intake interface failure |
New guarantee applications cannot be received |
|
Processing application failure |
Applications cannot progress |
|
Specialist staff unavailable |
Risk assessments cannot be completed |
|
Approval authority unavailable |
Guarantee decisions delayed |
|
Database corruption |
Application information becomes unreliable |
|
Cyberattack |
Processing platform inaccessible |
|
Participating financial institution connectivity failure |
Application exchange interrupted |
|
Guarantee certificate system failure |
Approved guarantees cannot be formally issued |
This level of assessment enables risk analysis to reflect actual operating processes rather than generic organisational threats.
Damanat's BCM Risk Register should contain sufficient information to support risk treatment and future continuity planning.
A recommended structure is:
|
Field |
Purpose |
|
Risk Reference |
Unique identifier |
|
Business Function |
Activity exposed to the risk |
|
Threat |
Disruption event |
|
Cause |
Why the event could occur |
|
Vulnerability |
Weakness enabling disruption |
|
Affected Resource |
People, process, technology, premises, information or supplier |
|
Existing Controls |
Controls already implemented |
|
Likelihood |
Probability rating |
|
Impact |
Severity rating |
|
Inherent Risk |
Risk before controls |
|
Control Effectiveness |
Adequacy of existing controls |
|
Residual Risk |
Risk after controls |
|
Required Treatment |
Additional improvement |
|
Risk Owner |
Responsible individual |
|
Target Date |
Completion requirement |
|
Status |
Current progress |
|
Review Date |
Next assessment |
|
Remarks |
Additional observations |
This register should become the principal evidence of the RAR process.
At the conclusion of the Risk Analysis and Review phase, Damanat should have produced at minimum:
|
Ref |
Deliverable |
Purpose |
|
RAR-01 |
RAR Methodology |
Establishes assessment approach |
|
RAR-02 |
Threat Catalogue |
Documents credible disruption threats |
|
RAR-03 |
Likelihood Criteria |
Standardises probability assessment |
|
RAR-04 |
Impact Criteria |
Standardises consequence assessment |
|
RAR-05 |
Risk Matrix |
Defines risk prioritisation |
|
RAR-06 |
Threat and Risk Register |
Records assessed BCM risks |
|
RAR-07 |
Single Point of Failure Register |
Identifies critical vulnerabilities |
|
RAR-08 |
Existing Control Assessment |
Determines control adequacy |
|
RAR-09 |
Risk Treatment Plan |
Records required improvements |
|
RAR-10 |
Residual Risk Register |
Records remaining exposures |
|
RAR-11 |
Third-Party Continuity Assessment |
Assesses important suppliers |
|
RAR-12 |
Management RAR Report |
Provides governance oversight |
Damanat should consider the RAR sufficiently complete when:
The output can then be used as input to the Business Impact Analysis and, later, to continuity strategy development.
Risk Analysis and Review identifies how disruption could occur.
The next phase, Business Impact Analysis, determines the consequences if the disruption actually occurred.
For example:
A technology failure could prevent Mortgage Guarantee Origination.
The RAR evaluates:
If Mortgage Guarantee Origination becomes unavailable:
The two assessments therefore work together.
The Risk Analysis and Review phase enables The Saudi Mortgage Guarantees Services Company to understand what could disrupt its operations and whether existing controls provide sufficient protection against those disruptions.
For Damanat, the analysis should extend beyond conventional physical threats to consider the interconnected environment that supports mortgage guarantee operations.
This includes people, processes, technology, information, premises, participating financial institutions, outsourced service providers and other critical external dependencies.
The RAR methodology is built around four continuing activities:
Risk identification establishes Damanat's threat landscape.
Risk assessment determines which threats require the greatest attention by considering likelihood and impact.
Risk mitigation determines whether existing controls are sufficient and establishes additional treatments where residual exposure remains unacceptable.
Continuous review ensures that the risk profile changes alongside Damanat's organisation, technology, processes, suppliers, operating environment and emerging threats.
The most important output of this phase is therefore not simply a list of threats. It is a structured understanding of the relationship between threats, vulnerabilities, controls and residual disruption risk.
For example:
This understanding enables Damanat to determine where preventive controls should be strengthened and where continuity and recovery arrangements must be established because disruption cannot reasonably be eliminated.
The RAR phase therefore provides a critical input into the remaining BCM methodology:
→ Risk Analysis and Review
→ Business Impact Analysis
→ Business Continuity Strategy
→ Plan Development
→ Testing and Exercising
→ Program Management
With Damanat's disruption threats and vulnerabilities identified, assessed, and prioritised, the next phase shifts from examining the cause of disruption to its business consequences.
The next chapter, Business Impact Analysis (BIA), should therefore answer the critical question:
The resulting recovery priorities, recovery objectives, dependency requirements and minimum resource needs will provide the basis for developing Damanat's Business Continuity Strategies.
| eBook 2: Implementing Business Continuity Management | ||||
| C1 | C2 | C3 | C4 | C5 |
| C6 | C7 | C8 | C9 | C10 |
To learn more about the course and schedule, click the buttons below for BCM-300 Business Continuity Management Implementer [BCM-3] and BCM-5000 Business Continuity Management Expert Implementer [BCM-5]
|
Please feel free to send us a note if you have any questions. |
||