eBook 2: Chapter 4
Implementing the Business Impact Analysis Phase for the Saudi Mortgage Guarantees Services Company
Introduction
The Business Impact Analysis (BIA) is one of the most important phases of the Business Continuity Management (BCM) Planning Methodology for The Saudi Mortgage Guarantees Services Company (Damanat).
The preceding Risk Analysis and Review (RAR) phase examines the threats and vulnerabilities that could disrupt Damanat.
The BIA approaches disruption from a different perspective. Rather than asking what caused the disruption, it asks:
“What happens to Damanat if a business function becomes unavailable, and how quickly must that function be recovered?”
This distinction is fundamental to effective BCM.
A cyberattack, technology outage, workplace disruption, loss of key personnel, supplier failure or infrastructure outage may have very different causes.
However, each could interrupt the same Critical Business Function (CBF). The BIA therefore focuses primarily on the consequences of disruption over time, irrespective of the initiating event.
For Damanat, the BIA should identify and assess the organisation's Critical Business Functions, determine the operational, financial, regulatory, legal, stakeholder and reputational consequences of their disruption, establish recovery priorities and identify the resources and dependencies required to support recovery.
The BIA provides the analytical bridge between understanding Damanat's operations and the development of appropriate Business Continuity Strategies.
The relationship can be represented as:
Risk Analysis and Review
What could disrupt Damanat?
↓
Business Impact Analysis
What would the consequences be, and what must be recovered by when?
↓
Business Continuity Strategy
How will Damanat achieve those recovery requirements?
The quality of the subsequent Business Continuity Strategy and Business Continuity Plans therefore depends heavily on the BIA.
Purpose of the Business Impact Analysis
The purpose of the BIA is to provide Damanat with an evidence-based understanding of the consequences of disruption and the recovery priorities required to protect its important business activities.
The BIA should enable Damanat to:
- identify Critical Business Functions;
- identify supporting business processes and activities;
- assess the impact of disruption over time;
- determine when disruption becomes unacceptable;
- establish recovery priorities;
- determine minimum operating requirements;
- establish Recovery Time Objectives;
- establish Recovery Point Objectives where applicable;
- determine minimum staffing requirements;
- identify critical technology and information;
- identify workplace requirements;
- identify internal dependencies;
- identify external dependencies;
- identify critical suppliers and service providers;
- identify dependencies on participating financial institutions; and
- provide the requirements for Business Continuity Strategy development.
The BIA is therefore not simply a questionnaire or inventory exercise.
It is a management decision-making process for determining what Damanat must protect and recover, by when, and with what resources.
Damanat's Critical Business Functions
For the purpose of this BCM implementation, the following 15 Critical Business Functions have been identified for assessment.
|
CBF Code |
Critical Business Function |
|
CBF-1 |
Mortgage Guarantee Origination |
|
CBF-2 |
Guarantee Risk Assessment |
|
CBF-3 |
Guarantee Issuance and Administration |
|
CBF-4 |
Claims Assessment and Settlement |
|
CBF-5 |
Financial and Treasury Management |
|
CBF-6 |
Enterprise Risk Management |
|
CBF-7 |
Regulatory Compliance and Reporting |
|
CBF-8 |
Information Technology Services |
|
CBF-9 |
Information Security and Cyber Resilience |
|
CBF-10 |
Customer and Financial Institution Relationship Management |
|
CBF-11 |
Legal and Corporate Governance |
|
CBF-12 |
Human Resource Management |
|
CBF-13 |
Procurement and Vendor Management |
|
CBF-14 |
Corporate Communications and Stakeholder Management |
|
CBF-15 |
Business Continuity and Crisis Management |
These CBFs provide the starting point for the BIA.
However, Damanat should avoid assuming that all 15 functions have the same recovery priority. One of the principal purposes of the BIA is to determine how the impact of interruption differs between functions and changes over time.
Understanding Criticality
A function should not be classified as critical merely because it is important during normal operations.
For BCM purposes, criticality should be determined primarily by the consequences of the function's unavailability over time.
For example, two functions may both be important to Damanat:
- Mortgage Guarantee Origination; and
- Procurement and Vendor Management.
However, the consequences of four hours of disruption may differ significantly across functions.
Likewise, a function that can tolerate one day of disruption may become extremely critical if the outage continues for one week.
The BIA should therefore assess:
Impact × Time
rather than relying solely on management perception of importance.
The Damanat BIA Methodology
A structured BIA for Damanat should follow a sequence such as:
Identify CBF
→ Identify Supporting Processes
→ Assess Impact Over Time
→ Determine Maximum Tolerable Disruption
→ Establish Recovery Priority
→ Determine MBCO
→ Establish RTO
→ Establish RPO
→ Identify Resource Requirements
→ Map Dependencies
→ Validate with Management
This process should be applied consistently across the identified CBFs.
Step 1 — Identify Business Processes Supporting Each CBF
Each Critical Business Function should be decomposed into its supporting business processes or Sub-CBFs.
This provides a more detailed basis for analysis.
For example, CBF-1 Mortgage Guarantee Origination may include processes such as:
- Mortgage Guarantee Application Intake;
- Application Validation;
- Borrower Eligibility Assessment;
- Property Eligibility Assessment;
- Mortgage Risk Assessment;
- Guarantee Policy Compliance Review;
- Financial Institution Verification;
- Guarantee Approval Decision;
- Guarantee Certificate Generation;
- Guarantee Registration;
- Stakeholder Notification;
- Documentation and Record Management;
- Guarantee Fee Administration; and
- Post-Issuance Quality Assurance.
The BIA should determine whether all supporting processes require the same recovery timeframe.
In many cases, they will not.
Step 2 — Assess the Impact of Disruption
Damanat should establish a standard set of impact categories to ensure consistency across Business Units.
Suitable categories include:
Financial Impact
Potential direct or indirect financial consequences.
Operational Impact
Inability to perform business activities or meet service requirements.
Regulatory Impact
Potential failure to comply with applicable regulatory obligations.
Legal and Contractual Impact
Potential breach of legal or contractual commitments.
Customer and Financial Institution Impact
Impact on participating financial institutions, customers and other stakeholders.
Reputational Impact
Potential loss of stakeholder confidence or adverse public perception.
Strategic Impact
Impact on Damanat's ability to achieve organisational objectives.
Each impact category should be evaluated according to agreed severity criteria.
Step 3 — Assess Impact Over Time
Business impact normally increases as disruption continues.
Damanat should therefore evaluate impact at defined time intervals.
An illustrative scale could include:
- 0–4 hours;
- 4–8 hours;
- 8–24 hours;
- 1–2 days;
- 3–5 days;
- 1 week; and
- beyond 1 week.
For example:
|
Time of Disruption |
Illustrative Impact on Mortgage Guarantee Origination |
|
0–4 Hours |
Processing delays begin; manageable backlog develops |
|
4–8 Hours |
Application queues increase; financial institution enquiries rise |
|
8–24 Hours |
Material processing delays; service commitments increasingly affected |
|
1–2 Days |
Significant operational and stakeholder impact |
|
3–5 Days |
Serious backlog and potential financial, contractual or regulatory concerns |
|
1 Week+ |
Potentially severe organisational and stakeholder consequences |
The actual impact thresholds should be determined through Damanat's BIA workshops rather than assumed in advance.
Step 4 — Determine the Maximum Tolerable Period of Disruption
The BIA should establish the point beyond which continued disruption would create unacceptable consequences for Damanat.
Depending on the terminology adopted in the BCM framework, this may be described as the:
- Maximum Acceptable Outage (MAO);
- Maximum Tolerable Period of Disruption (MTPD); or
- Maximum Tolerable Downtime (MTD).
The terminology should be applied consistently.
The important principle is:
The maximum tolerable disruption establishes the boundary beyond which the consequences of non-recovery become unacceptable.
The Recovery Time Objective must therefore be set within this boundary, allowing sufficient margin for stabilisation and recovery complications.
Step 5 — Establish the Recovery Time Objective
The Recovery Time Objective (RTO) identifies the targeted period within which a disrupted activity should be resumed.
For example:
Maximum Tolerable Disruption: 24 hours
does not automatically mean:
RTO: 24 hours
An RTO set exactly at the maximum tolerable limit leaves little margin for recovery uncertainty.
Damanat may instead determine:
Maximum Tolerable Disruption: 24 hours
RTO: 8 hours
The RTO then becomes a fundamental requirement for the development of a Business Continuity Strategy.
Illustrative Recovery Priorities for Damanat's CBFs
The following table demonstrates how BIA outputs could be presented. The recovery periods below are illustrative only and should not be treated as approved Damanat recovery objectives without formal BIA validation.
|
CBF |
Critical Business Function |
Illustrative Recovery Priority |
Key Consideration |
|
CBF-1 |
Mortgage Guarantee Origination |
High |
Continuity of guarantee application processing |
|
CBF-2 |
Guarantee Risk Assessment |
High |
Supports risk-informed guarantee decisions |
|
CBF-3 |
Guarantee Issuance and Administration |
High |
Supports guarantee issuance and ongoing administration |
|
CBF-4 |
Claims Assessment and Settlement |
High |
Supports timely claims processing and obligations |
|
CBF-5 |
Financial and Treasury Management |
High |
Supports liquidity, payments and financial obligations |
|
CBF-6 |
Enterprise Risk Management |
Medium–High |
Supports risk oversight and decision-making |
|
CBF-7 |
Regulatory Compliance and Reporting |
High |
Supports regulatory obligations and deadlines |
|
CBF-8 |
Information Technology Services |
Very High |
Enables multiple business and support functions |
|
CBF-9 |
Information Security and Cyber Resilience |
Very High |
Protects and restores secure technology operations |
|
CBF-10 |
Customer and Financial Institution Relationship Management |
High |
Maintains stakeholder coordination and service |
|
CBF-11 |
Legal and Corporate Governance |
Medium–High |
Supports legal, governance and decision requirements |
|
CBF-12 |
Human Resource Management |
Medium |
Supports workforce and employee requirements |
|
CBF-13 |
Procurement and Vendor Management |
Medium |
Supports critical supplier and procurement activities |
|
CBF-14 |
Corporate Communications and Stakeholder Management |
High during crisis |
Supports coordinated communications during disruption |
|
CBF-15 |
Business Continuity and Crisis Management |
Very High during major disruption |
Coordinates enterprise response and recovery |
The BIA should replace qualitative assumptions with validated recovery requirements.
Step 6 — Establish the Minimum Business Continuity Objective
The Minimum Business Continuity Objective (MBCO) defines the minimum acceptable level of products or services that Damanat must provide during a disruption.
Recovery does not always mean restoring 100 per cent of normal operations immediately.
For example, Damanat may determine that during the early recovery period Mortgage Guarantee Origination should prioritise:
- urgent applications;
- applications nearing contractual or operational deadlines;
- transactions with significant stakeholder consequences; and
- applications already at advanced approval stages.
Lower-priority work may temporarily remain suspended.
The MBCO therefore answers:
“What minimum level of service must Damanat maintain while full recovery is still underway?”
Example of MBCO for Mortgage Guarantee Origination
Assume that normal processing capacity is 100 per cent.
An illustrative recovery profile might be:
Disruption
↓
RTO Achieved: Minimum service restored
↓
MBCO: 40% priority processing capacity
↓
Stabilisation: 70% capacity
↓
Full Recovery: 100% normal operations
The actual percentages must be determined through the BIA and Business Continuity Strategy process.
This staged approach is often more realistic than assuming instant restoration of full capacity.
Step 7 — Establish the Recovery Point Objective
The Recovery Point Objective (RPO) identifies the maximum tolerable amount of data loss measured in time.
This is particularly important for CBFs dependent on transactional information.
For example, if the RPO for a guarantee-processing database is 30 minutes, the recovery arrangement should enable restoration of information to a point no more than approximately 30 minutes before the disruption, subject to the approved technical design.
RPO considerations may be especially relevant to:
- Mortgage Guarantee Origination;
- Guarantee Risk Assessment;
- Guarantee Issuance and Administration;
- Claims Assessment and Settlement;
- Financial and Treasury Management; and
- supporting IT systems.
Business Units should establish the business requirement.
Technology teams should determine how to achieve that requirement.
Step 8 — Identify Minimum Personnel Requirements
The BIA should identify the minimum personnel required at different recovery stages.
For each CBF, Damanat should determine:
- minimum number of employees;
- essential roles;
- specialist competencies;
- approval authorities;
- alternates;
- cross-trained personnel; and
- external support requirements.
Example
Mortgage Guarantee Origination may require minimum representation from:
- application processing;
- eligibility assessment;
- risk assessment;
- guarantee approval;
- administration;
- technology support; and
- financial institution liaison.
The BIA should identify roles and competencies, not merely employee names.
Step 9 — Identify Technology Requirements
Technology dependencies should be identified for each CBF.
These may include:
- business applications;
- databases;
- document management systems;
- workflow systems;
- identity and access management;
- email;
- telecommunications;
- network connectivity;
- remote access;
- cybersecurity services;
- reporting platforms; and
- external interfaces.
For each system, the BIA should identify the required recovery timeframe based on the business requirement.
This is important because:
Technology recovery requirements should support business recovery requirements—not the reverse.
Business and Technology Recovery Alignment
Consider the following example:
CBF-1 Mortgage Guarantee Origination RTO: 4 hours
but:
Guarantee Processing Platform RTO: 8 hours
This creates a recovery gap.
The business cannot realistically recover within four hours if its essential technology requires eight hours.
Damanat would need to:
- improve technology recovery;
- implement an alternative business workaround;
- revise the recovery strategy; or
- formally reconsider the business RTO if justified.
The BIA therefore provides an important basis for aligning business and technology resilience.
Step 10 — Identify Information and Data Requirements
The BIA should identify critical information required for recovery.
Examples include:
- mortgage guarantee applications;
- customer information;
- financial institution information;
- eligibility records;
- property information;
- risk assessment records;
- approval records;
- guarantee certificates;
- claims records;
- financial records;
- contracts;
- regulatory information; and
- operating procedures.
Damanat should determine:
- where the information is stored;
- how it is protected;
- how quickly it is required;
- whether an alternative copy exists; and
- whether it can be accessed from the recovery environment.
Step 11 — Identify Workplace Requirements
Damanat should determine whether each CBF requires:
- primary office access;
- alternate workplace;
- remote working;
- specialist equipment;
- secure meeting facilities;
- command-centre capability; or
- other physical resources.
For example, if Mortgage Guarantee Origination can operate remotely, the BIA should still determine:
- how many employees need remote access;
- whether all required applications are remotely accessible;
- whether adequate bandwidth exists;
- whether secure authentication is available; and
- whether sensitive information can be handled appropriately.
The statement “employees can work remotely” is not sufficient without quantifying the recovery requirement.
Step 12 — Identify Internal Dependencies
Critical Business Functions frequently depend upon one another.
For example:
CBF-1 Mortgage Guarantee Origination
may depend upon:
- CBF-2 Guarantee Risk Assessment;
- CBF-8 Information Technology Services;
- CBF-9 Information Security and Cyber Resilience;
- CBF-10 Customer and Financial Institution Relationship Management; and
- CBF-11 Legal and Corporate Governance under certain circumstances.
Similarly:
CBF-4 Claims Assessment and Settlement
may depend upon:
- financial processing;
- technology;
- legal support;
- risk management; and
- external parties.
Understanding these relationships is essential for establishing realistic recovery sequences.
Illustrative CBF Dependency Map
|
CBF |
Key Internal Dependencies |
|
CBF-1 Mortgage Guarantee Origination |
CBF-2, CBF-8, CBF-9, CBF-10 |
|
CBF-2 Guarantee Risk Assessment |
CBF-8, CBF-9 |
|
CBF-3 Guarantee Issuance and Administration |
CBF-1, CBF-8, CBF-9 |
|
CBF-4 Claims Assessment and Settlement |
CBF-5, CBF-8, CBF-11 |
|
CBF-5 Financial and Treasury Management |
CBF-8, CBF-9 |
|
CBF-6 Enterprise Risk Management |
CBF-8, CBF-9 |
|
CBF-7 Regulatory Compliance and Reporting |
CBF-5, CBF-6, CBF-8, CBF-11 |
|
CBF-8 Information Technology Services |
CBF-9, CBF-13 |
|
CBF-9 Information Security and Cyber Resilience |
CBF-8, CBF-13 |
|
CBF-10 Customer and Financial Institution Relationship Management |
CBF-1, CBF-3, CBF-4, CBF-8 |
|
CBF-11 Legal and Corporate Governance |
CBF-7, CBF-8 |
|
CBF-12 Human Resource Management |
CBF-8 |
|
CBF-13 Procurement and Vendor Management |
CBF-5, CBF-8, CBF-11 |
|
CBF-14 Corporate Communications and Stakeholder Management |
CBF-8, CBF-10, CBF-15 |
|
CBF-15 Business Continuity and Crisis Management |
All relevant CBFs during major disruption |
These relationships are illustrative and should be validated through BIA workshops.
Step 13 — Identify External Dependencies
Damanat should identify external organisations required to support each CBF.
These may include:
- participating financial institutions;
- technology providers;
- telecommunications providers;
- cloud or hosting providers;
- banking service providers;
- professional advisers;
- facilities providers;
- specialist contractors; and
- other outsourced service providers.
The BIA should determine:
- service provided;
- CBF supported;
- required recovery timeframe;
- contractual recovery commitment;
- alternative provider availability;
- concentration risk; and
- consequences of provider failure.
Third-Party Recovery Alignment
A critical supplier's recovery capability should align with Damanat's business requirements.
For example:
Damanat CBF RTO: 4 hours
Critical Supplier Recovery Commitment: 24 hours
This represents a significant recovery gap.
Potential responses include:
- renegotiating the supplier requirement;
- establishing redundancy;
- maintaining an alternative supplier;
- developing a manual workaround;
- insourcing temporary capability; or
- formally accepting and managing the residual risk.
The BIA makes these dependency gaps visible.
Step 14 — Establish Recovery Priorities
Once impact and dependency information has been analysed, Damanat should establish an overall recovery sequence.
An illustrative tiering structure could be:
Tier 1 — Immediate / Very High Priority
Functions required rapidly to prevent severe consequences.
Tier 2 — High Priority
Functions required shortly after Tier 1 to maintain important services and obligations.
Tier 3 — Medium Priority
Functions that can tolerate a longer interruption but remain necessary for sustained operations.
Tier 4 — Deferred Recovery
Activities that can temporarily remain suspended while priority recovery occurs.
The classification should be based on BIA evidence rather than organisational hierarchy.
Example of Damanat Recovery Sequencing
During a major enterprise disruption, an illustrative sequence might be:
Crisis Coordination and Cyber/Technology Response
↓
Critical Technology and Communications
↓
Mortgage Guarantee and Claims Activities
↓
Financial, Regulatory and Stakeholder Activities
↓
Supporting Corporate Functions
This sequence should not be predetermined as the final answer.
The BIA should establish the actual sequence based on impact, dependencies and recovery requirements.
BIA Workshops
The BIA should be conducted with knowledgeable representatives from the relevant Business Units.
Participants may include:
- Heads of Business Units;
- Business Unit BCM Coordinators;
- process owners;
- technology representatives;
- risk management;
- compliance;
- finance;
- information security;
- procurement;
- HR; and
- BCM representatives.
The BCM function should facilitate the methodology.
The Business Units should own and validate the business information.
This reflects the principle:
BCM facilitates the BIA; the business owns the impact and recovery requirements.
Questions to Ask During a Damanat BIA Workshop
For each CBF, the facilitator should ask questions such as:
- What business processes make up this function?
- What happens if the function stops?
- How does the impact change after four hours, one day, three days and one week?
- When does the disruption become unacceptable?
- What minimum service must continue?
- How quickly should the function recover?
- How much data loss can be tolerated?
- What minimum personnel are required?
- Which technology applications are essential?
- What information is required?
- What workplace capability is required?
- Which other Damanat functions are required?
- Which external parties are required?
- Which suppliers are critical?
- Are manual workarounds available?
- What backlog would accumulate?
- How long would backlog recovery take?
- What regulatory or contractual deadlines could be affected?
The responses should be supported by evidence wherever practical.
Avoiding Common BIA Weaknesses
Damanat should avoid several common BIA problems.
Everything Is Critical
If every function is classified as immediately critical, the BIA has not established meaningful priorities.
Arbitrary RTOs
RTOs should be derived from impact analysis rather than selected because a particular timeframe appears convenient.
Technology-Led RTOs
Business recovery requirements should drive technology requirements.
Ignoring Dependencies
A function cannot recover if essential supporting resources remain unavailable.
Confusing RTO with Full Recovery
RTO may represent restoration of an acceptable minimum capability rather than immediate return to 100 per cent normal capacity.
Ignoring Backlogs
The ability to resume processing does not mean accumulated work has disappeared.
Static BIA Information
BIA results should be reviewed when material organisational or technology changes occur.
Backlog Analysis
Damanat should assess the backlog created during disruption.
For example, if Mortgage Guarantee Origination normally processes a defined number of applications each working day, a three-day interruption may create a substantial queue.
The BIA should consider:
- backlog volume;
- prioritisation rules;
- additional staffing;
- overtime requirements;
- temporary processing capacity;
- stakeholder communications; and
- time required to return to normal service levels.
Recovery therefore has two dimensions:
Restore the capability
and
Recover the accumulated workload.
Specific BIA Requirements for Damanat
For Damanat, the BIA should establish, at minimum, the following for each CBF:
|
Requirement |
Expected BIA Output |
|
CBF identification |
Approved CBF and supporting process catalogue |
|
Business ownership |
Named accountable Business Unit |
|
Impact assessment |
Impact by category and time |
|
Maximum tolerable disruption |
Approved tolerance boundary |
|
Recovery Time Objective |
Target recovery time |
|
Recovery Point Objective |
Data recovery requirement where applicable |
|
MBCO |
Minimum acceptable operating capability |
|
Personnel |
Minimum roles and staffing |
|
Technology |
Required applications and infrastructure |
|
Information |
Critical records and data |
|
Workplace |
Recovery-location requirements |
|
Internal dependencies |
Supporting Damanat functions |
|
External dependencies |
Financial institutions and other parties |
|
Suppliers |
Critical third-party providers |
|
Backlog |
Accumulation and recovery requirements |
|
Workaround |
Available temporary procedures |
|
Validation |
Business Unit Head approval |
These requirements provide the inputs needed for the subsequent Business Continuity Strategy phase.
Regulatory Considerations for Damanat
As a Saudi financial-sector organisation, Damanat should ensure that its BIA methodology is aligned with applicable requirements and supervisory expectations of the Saudi Central Bank (SAMA) and, where relevant to its activities, the Insurance Authority.
The BIA should provide documented evidence demonstrating that Damanat has systematically:
- identified critical activities and services;
- assessed the consequences of their disruption;
- established recovery priorities;
- determined recovery time requirements;
- identified supporting resources;
- considered internal and external dependencies;
- aligned technology recovery with business requirements;
- considered critical third parties; and
- obtained appropriate management validation.
These requirements should be incorporated into Damanat's BCM methodology rather than treated as a separate compliance exercise.
Linking the BIA to ISO 22301
Within an ISO 22301-aligned Business Continuity Management System, the BIA forms part of the organisation's structured assessment of business continuity requirements.
For Damanat, this means the BIA should not exist as an isolated spreadsheet.
Its results should directly influence:
- continuity priorities;
- recovery objectives;
- continuity strategies and solutions;
- resource requirements;
- Business Continuity Plans;
- technology recovery requirements;
- supplier continuity requirements;
- exercise objectives; and
- continual improvement.
The relationship is:
Business Impact → Recovery Requirement → Continuity Solution → Recovery Procedure → Exercise
This traceability is essential for demonstrating that BCM arrangements have been developed from actual business requirements.
BIA Validation and Approval
Following completion of the analysis, results should be validated by the relevant Business Unit Heads.
Validation should confirm that:
- business processes are correctly identified;
- impact assessments are reasonable;
- recovery priorities are justified;
- RTOs are realistic;
- MBCOs reflect minimum operational requirements;
- resource requirements are accurate;
- technology dependencies are complete;
- internal dependencies are understood;
- external dependencies are identified; and
- significant gaps have been documented.
The central BCM function should subsequently perform a cross-functional review.
This is necessary because individual Business Units may identify conflicting recovery assumptions.
Cross-Functional BIA Validation
Consider the following example:
CBF-1 Mortgage Guarantee Origination RTO: 4 hours
CBF-8 Information Technology Services recovery capability for required application: 8 hours
External service provider recovery: 12 hours
The business requirement cannot currently be achieved.
This should be recorded as a recovery capability gap.
The Business Continuity Strategy phase must then determine how to address the gap.
This illustrates why the BIA is not merely about assigning RTOs.
It identifies the requirements against which Damanat's actual recovery capability must subsequently be designed and tested.
BIA Deliverables
At the completion of the BIA phase, Damanat should maintain a structured set of deliverables.
|
Ref |
Deliverable |
Purpose |
|
BIA-01 |
BIA Methodology |
Defines the assessment approach |
|
BIA-02 |
CBF Catalogue |
Identifies functions to be assessed |
|
BIA-03 |
Sub-CBF / Process Catalogue |
Identifies supporting activities |
|
BIA-04 |
Impact Assessment |
Evaluates consequences over time |
|
BIA-05 |
Recovery Priority Schedule |
Establishes recovery sequencing |
|
BIA-06 |
RTO Register |
Records recovery-time requirements |
|
BIA-07 |
RPO Register |
Records data-recovery requirements |
|
BIA-08 |
MBCO Register |
Records minimum service requirements |
|
BIA-09 |
Resource Requirements |
Identifies minimum recovery resources |
|
BIA-10 |
Dependency Register |
Records internal and external dependencies |
|
BIA-11 |
Critical Supplier Register |
Identifies continuity-sensitive suppliers |
|
BIA-12 |
Recovery Gap Register |
Identifies capability deficiencies |
|
BIA-13 |
BIA Report |
Consolidates analysis and findings |
|
BIA-14 |
Management Approval |
Provides formal validation |
Together, these outputs establish the business requirements for the next BCM phase.
Example of a Consolidated Damanat BIA Record
A simplified BIA record might appear as follows:
|
Field |
Illustrative Entry |
|
CBF |
CBF-1 Mortgage Guarantee Origination |
|
Business Owner |
Mortgage Guarantee Operations |
|
Impact |
High operational and stakeholder impact as disruption extends |
|
Maximum Tolerable Disruption |
To be established through approved BIA |
|
RTO |
To be established through approved BIA |
|
RPO |
To be established based on transaction and data requirements |
|
MBCO |
Priority mortgage guarantee processing |
|
Minimum Personnel |
Designated processing, assessment and approval roles |
|
Critical Technology |
Guarantee processing and supporting systems |
|
Critical Information |
Applications, assessment records, approvals and guarantee records |
|
Internal Dependencies |
Risk, IT, Information Security and relationship management |
|
External Dependencies |
Participating financial institutions and critical service providers |
|
Workaround |
Approved temporary/manual procedure where feasible |
|
Backlog Requirement |
Prioritise and reconcile outstanding applications |
|
Approval |
Relevant Business Unit Head |
The purpose of this record is to provide a concise recovery requirement that can be translated into continuity strategy.
Moving from BIA to Business Continuity Strategy
The BIA tells Damanat what is required.
The Business Continuity Strategy determines how that requirement will be achieved.
For example:
BIA Requirement
Mortgage Guarantee Origination must resume within the approved RTO.
Identified Dependency
The function requires the guarantee processing platform.
Current Capability
The platform cannot currently recover within the business requirement.
Strategy Question
What solution will enable Damanat to close the gap?
Possible options might include:
- improved disaster recovery;
- high-availability architecture;
- alternative processing capability;
- manual workaround;
- enhanced data replication; or
- a combination of solutions.
The BIA therefore establishes the demand for resilience.
The BCS phase establishes the supply of resilience.
BIA as the Foundation for Recovery Investment
The BIA also provides Damanat with an evidence base for investment decisions.
Without a BIA, a proposal for additional recovery technology may appear to be a purely technical request.
With a BIA, management can understand:
- which CBF depends on the technology;
- how quickly the function must recover;
- what happens if recovery is delayed;
- which stakeholders are affected;
- what existing capability can achieve; and
- what recovery gap remains.
This enables Damanat to prioritise recovery investment based on business impact rather than technology preference.
Maintaining the BIA
BIA information changes as the organisation changes.
Damanat should establish both periodic and event-driven BIA reviews.
Review triggers may include:
- introduction of new mortgage guarantee products or services;
- major process changes;
- technology transformation;
- organisational restructuring;
- new outsourcing arrangements;
- changes in participating financial institutions;
- new critical suppliers;
- changes in operating locations;
- significant incidents;
- exercise findings; and
- changes in regulatory obligations.
The BIA should therefore be treated as a living business analysis, not a one-time implementation document.
Completion Criteria for the BIA Phase
The BIA phase should be considered complete for the initial BCM implementation when:
- all identified CBFs have been assessed;
- supporting processes have been identified;
- impacts have been evaluated over time;
- maximum tolerable disruption has been determined;
- recovery priorities have been established;
- RTOs have been approved;
- RPOs have been established where appropriate;
- MBCOs have been determined;
- minimum personnel requirements have been identified;
- technology requirements have been identified;
- information requirements have been documented;
- workplace requirements have been established;
- internal dependencies have been mapped;
- external dependencies have been identified;
- critical suppliers have been assessed;
- backlog requirements have been considered;
- recovery gaps have been documented; and
- Business Unit Heads have validated the results.
At that point, Damanat has established a sufficiently structured set of business recovery requirements to proceed to the Business Continuity Strategy phase.
The Business Impact Analysis phase provides the business-driven foundation for Business Continuity Management at The Saudi Mortgage Guarantees Services Company.
While Risk Analysis and Review identifies the threats capable of disrupting Damanat, the BIA determines the consequences of those disruptions and establishes the recovery requirements necessary to prevent them from becoming unacceptable.
For Damanat, the BIA should therefore move systematically through:
Critical Business Function
→ Supporting Processes
→ Impact Over Time
→ Maximum Tolerable Disruption
→ Recovery Priority
→ RTO
→ RPO
→ MBCO
→ Resource Requirements
→ Dependencies
→ Recovery Gaps
Applying this methodology across Damanat's 15 Critical Business Functions enables management to distinguish between activities that require rapid recovery and those that can tolerate longer periods of disruption.
The BIA also makes the interdependent nature of Damanat's operations visible.
Mortgage Guarantee Origination cannot be considered only as an operational process.
Its recovery may depend upon Guarantee Risk Assessment, Information Technology Services, Information Security and Cyber Resilience, participating financial institutions, critical data, authorised employees and third-party service providers.
The same principle applies across the other Critical Business Functions.
Consequently, the BIA should not answer only:
“How quickly does this Business Unit want to recover?”
It should answer:
“Based on the consequences of disruption, how quickly must this Critical Business Function recover, what minimum level of service must it provide, and what resources and dependencies must be available to make that recovery possible?”
The resulting recovery requirements provide the foundation for the next phase of Damanat's BCM Planning Methodology—Business Continuity Strategy (BCS).
The transition is therefore:
-
RAR identifies what can go wrong.
-
BIA determines what matters and by when.
-
BCS determines how Damanat will achieve the required recovery.
This progression ensures that Damanat's continuity strategies are not selected arbitrarily. They are developed in response to clearly defined, management-approved business requirements.
Ultimately, a well-executed BIA enables Damanat to direct people, technology, financial resources and management attention toward the activities where disruption would create the greatest consequences.
That is what transforms Business Continuity Management from a collection of recovery plans into a business-driven resilience capability.
Note from Author: These additional eight chapters (Intro P0 to Part 7) are developed purely for Saudi Mortgage Guarantees Services Company (Damanat) and serve as a training guide for its further drill-down of the business impact analysis phase.
| eBook 2: Implementing Business Continuity Management | ||||
| C1 | C2 | C3 | C4 | C5 |
![]() |
![]() |
![]() |
![]() |
![]() |
| C6 | C7 | C8 | C9 | C10 |
![]() |
![]() |
![]() |
![]() |
![]() |
More Information About Business Continuity Management Courses
To learn more about the course and schedule, click the buttons below for BCM-300 Business Continuity Management Implementer [BCM-3] and BCM-5000 Business Continuity Management Expert Implementer [BCM-5]
![]() |
![]() |
![]() |
![]() |
![]() |
![]() |
![]() |
Please feel free to send us a note if you have any questions. |
![]() |
![]() |
![]() |
![]() |


![[BCM] [Damanat] [Full Banner] Implementing BCM for The Saudi Mortgage Guarantees Services Company](https://no-cache.hubspot.com/cta/default/3893111/221734db-8c33-48bd-8147-fc740eecaf83.png)


![Banner [Summary] [BCM] [E2] [C4] Business Impact Analysis](https://no-cache.hubspot.com/cta/default/3893111/3d259877-5780-4502-9473-1129f6d08a8c.png)
![[BCM] [Damanat] [3/4 Banner] Implementing BCM for The Saudi Mortgage Guarantees Services Company](https://no-cache.hubspot.com/cta/default/3893111/eb2678e7-9b23-4a73-827d-897c4b20315c.png)
![[BCM] [Damanat] [E2] [C4] [P0] Introduction](https://no-cache.hubspot.com/cta/default/3893111/cf1089fb-ba15-4935-bafe-d469db8b731b.png)
![[BCM] [Damanat] [E2] [C4] [P1] Position of BIA in the BCM Planning Methodology](https://no-cache.hubspot.com/cta/default/3893111/0ca2ca7d-0103-44fe-9d63-4bc2ed724444.png)
![[BCM] [Damanat] [E2] [C4] [P2] Establishing the BIA Governance Structure](https://no-cache.hubspot.com/cta/default/3893111/41158d1a-4d94-4fff-b5be-4e5866e18add.png)
![[BCM] [Damanat] [E2] [C4] [P3] Defining the BIA Scope](https://no-cache.hubspot.com/cta/default/3893111/357a1d12-62f0-467a-9b5b-881b817063c6.png)
![[BCM] [Damanat] [E2] [C4] [P4] Confirming the Critical Business Functions](https://no-cache.hubspot.com/cta/default/3893111/1729e39a-c267-4d7a-8282-0a30b44a296c.png)
![[BCM] [Damanat] [E2] [C4] [P5] Decomposing CBFs into Sub-CBFs](https://no-cache.hubspot.com/cta/default/3893111/9a19fac4-668e-41e2-b188-f08991e6097a.png)
![[BCM] [Damanat] [E2] [C4] [P6] Identifying Product, Services and Outcomes](https://no-cache.hubspot.com/cta/default/3893111/d6db6926-824a-4256-9c3b-f781422ce57e.png)
![[BCM] [Damanat] [E2] [C4] [P7] Identifying Impact Areas](https://no-cache.hubspot.com/cta/default/3893111/23e335dc-644f-4a06-bdde-067b828f8b55.png)
![[BCM] [Damanat] [3/4 Banner] Implementing BCM for The Saudi Mortgage Guarantees Services Company](https://no-cache.hubspot.com/cta/default/3893111/0252380a-b2dc-4059-be10-b5566002b711.png)
![[BCM] [Damanat] [E2] [C1] Business Continuity Management Planning Methodology](https://no-cache.hubspot.com/cta/default/3893111/b17b614b-c36c-4437-95ca-5c1d44ac6ce3.png)
![[BCM] [Damanat] [E2] [C2] Project Management](https://no-cache.hubspot.com/cta/default/3893111/4663bc6b-2e85-4e17-b6af-b5c784413b28.png)
![[BCM] [Damanat] [E2] [C3] Risk Analysis and Review](https://no-cache.hubspot.com/cta/default/3893111/5423f27a-6048-40c1-b55c-238fafb59648.png)
![[BCM] [Damanat] [E2] [C4] Business Impact Analysis](https://no-cache.hubspot.com/cta/default/3893111/7a3c1a1f-d7f6-4d5d-8fef-deedc7d91f63.png)
![[BCM] [Damanat] [E2] [C5] Business Continuity Strategy](https://no-cache.hubspot.com/cta/default/3893111/a27d7e1e-8571-421d-9467-cc02614820e1.png)
![[BCM] [Damanat] [E2] [C6] BCM Plan Development](https://no-cache.hubspot.com/cta/default/3893111/ebff27c2-d3e9-4f2c-9a4c-0534e01fa535.png)
![[BCM] [Damanat] [E2] [C7] Testing and Exercising](https://no-cache.hubspot.com/cta/default/3893111/ed03c310-870a-482d-bac6-446897084091.png)
![[BCM] [Damanat] [E2] [C8] Program Management](https://no-cache.hubspot.com/cta/default/3893111/f52be888-834d-480c-9149-1167d38f1147.png)
![[BCM] [Damanat] [E2] [C9] Summary](https://no-cache.hubspot.com/cta/default/3893111/dab5bc8f-3d96-444b-880f-78cf037fc906.png)
![[BCM] [Damanat] [E2] [C10] Back Cover](https://no-cache.hubspot.com/cta/default/3893111/351b85f0-d850-4dee-a5c0-55c2b37c3075.png)


![Register [BL-B-3]*](https://no-cache.hubspot.com/cta/default/3893111/ac6cf073-4cdd-4541-91ed-889f731d5076.png)



![FAQ [BL-B-3]](https://no-cache.hubspot.com/cta/default/3893111/b3824ba1-7aa1-4eb6-bef8-94f57121c5ae.png)
![Email to Sales Team [BCM Institute]](https://no-cache.hubspot.com/cta/default/3893111/3c53daeb-2836-4843-b0e0-645baee2ab9e.png)





