Ebook

[BCM] [Damanat] [E2] [C4] Business Impact Analysis

Written by Dr Goh Moh Heng | Jul 25, 2026, 12:46:31 PM

eBook 2: Chapter 4

 

 Implementing the Business Impact Analysis Phase for the Saudi Mortgage Guarantees Services Company 

 

 

Introduction

The Business Impact Analysis (BIA) is one of the most important phases of the Business Continuity Management (BCM) Planning Methodology for The Saudi Mortgage Guarantees Services Company (Damanat).

The preceding Risk Analysis and Review (RAR) phase examines the threats and vulnerabilities that could disrupt Damanat.

The BIA approaches disruption from a different perspective. Rather than asking what caused the disruption, it asks:

“What happens to Damanat if a business function becomes unavailable, and how quickly must that function be recovered?”

This distinction is fundamental to effective BCM.

A cyberattack, technology outage, workplace disruption, loss of key personnel, supplier failure or infrastructure outage may have very different causes.

However, each could interrupt the same Critical Business Function (CBF). The BIA therefore focuses primarily on the consequences of disruption over time, irrespective of the initiating event.

For Damanat, the BIA should identify and assess the organisation's Critical Business Functions, determine the operational, financial, regulatory, legal, stakeholder and reputational consequences of their disruption, establish recovery priorities and identify the resources and dependencies required to support recovery.

The BIA provides the analytical bridge between understanding Damanat's operations and the development of appropriate Business Continuity Strategies.

The relationship can be represented as:

Risk Analysis and Review

What could disrupt Damanat?

Business Impact Analysis

What would the consequences be, and what must be recovered by when?

Business Continuity Strategy

How will Damanat achieve those recovery requirements?

 

The quality of the subsequent Business Continuity Strategy and Business Continuity Plans therefore depends heavily on the BIA.

 

Purpose of the Business Impact Analysis

The purpose of the BIA is to provide Damanat with an evidence-based understanding of the consequences of disruption and the recovery priorities required to protect its important business activities.

The BIA should enable Damanat to:

  • identify Critical Business Functions;
  • identify supporting business processes and activities;
  • assess the impact of disruption over time;
  • determine when disruption becomes unacceptable;
  • establish recovery priorities;
  • determine minimum operating requirements;
  • establish Recovery Time Objectives;
  • establish Recovery Point Objectives where applicable;
  • determine minimum staffing requirements;
  • identify critical technology and information;
  • identify workplace requirements;
  • identify internal dependencies;
  • identify external dependencies;
  • identify critical suppliers and service providers;
  • identify dependencies on participating financial institutions; and
  • provide the requirements for Business Continuity Strategy development.

The BIA is therefore not simply a questionnaire or inventory exercise.

It is a management decision-making process for determining what Damanat must protect and recover, by when, and with what resources.

 

Damanat's Critical Business Functions

For the purpose of this BCM implementation, the following 15 Critical Business Functions have been identified for assessment.

 

CBF Code

Critical Business Function

CBF-1

Mortgage Guarantee Origination

CBF-2

Guarantee Risk Assessment

CBF-3

Guarantee Issuance and Administration

CBF-4

Claims Assessment and Settlement

CBF-5

Financial and Treasury Management

CBF-6

Enterprise Risk Management

CBF-7

Regulatory Compliance and Reporting

CBF-8

Information Technology Services

CBF-9

Information Security and Cyber Resilience

CBF-10

Customer and Financial Institution Relationship Management

CBF-11

Legal and Corporate Governance

CBF-12

Human Resource Management

CBF-13

Procurement and Vendor Management

CBF-14

Corporate Communications and Stakeholder Management

CBF-15

Business Continuity and Crisis Management

These CBFs provide the starting point for the BIA.

However, Damanat should avoid assuming that all 15 functions have the same recovery priority. One of the principal purposes of the BIA is to determine how the impact of interruption differs between functions and changes over time.

 

Understanding Criticality

A function should not be classified as critical merely because it is important during normal operations.

For BCM purposes, criticality should be determined primarily by the consequences of the function's unavailability over time.

For example, two functions may both be important to Damanat:

  • Mortgage Guarantee Origination; and
  • Procurement and Vendor Management.

However, the consequences of four hours of disruption may differ significantly across functions.

Likewise, a function that can tolerate one day of disruption may become extremely critical if the outage continues for one week.

The BIA should therefore assess:

Impact × Time

rather than relying solely on management perception of importance.

 

The Damanat BIA Methodology

A structured BIA for Damanat should follow a sequence such as:

Identify CBF

→ Identify Supporting Processes

→ Assess Impact Over Time

→ Determine Maximum Tolerable Disruption

→ Establish Recovery Priority

→ Determine MBCO

→ Establish RTO

→ Establish RPO

→ Identify Resource Requirements

→ Map Dependencies

→ Validate with Management

This process should be applied consistently across the identified CBFs.

 

Step 1 — Identify Business Processes Supporting Each CBF

Each Critical Business Function should be decomposed into its supporting business processes or Sub-CBFs.

This provides a more detailed basis for analysis.

For example, CBF-1 Mortgage Guarantee Origination may include processes such as:

  • Mortgage Guarantee Application Intake;
  • Application Validation;
  • Borrower Eligibility Assessment;
  • Property Eligibility Assessment;
  • Mortgage Risk Assessment;
  • Guarantee Policy Compliance Review;
  • Financial Institution Verification;
  • Guarantee Approval Decision;
  • Guarantee Certificate Generation;
  • Guarantee Registration;
  • Stakeholder Notification;
  • Documentation and Record Management;
  • Guarantee Fee Administration; and
  • Post-Issuance Quality Assurance.

The BIA should determine whether all supporting processes require the same recovery timeframe.

In many cases, they will not.

 

Step 2 — Assess the Impact of Disruption

Damanat should establish a standard set of impact categories to ensure consistency across Business Units.

Suitable categories include:

Financial Impact

Potential direct or indirect financial consequences.

Operational Impact

Inability to perform business activities or meet service requirements.

Regulatory Impact

Potential failure to comply with applicable regulatory obligations.

Legal and Contractual Impact

Potential breach of legal or contractual commitments.

Customer and Financial Institution Impact

Impact on participating financial institutions, customers and other stakeholders.

Reputational Impact

Potential loss of stakeholder confidence or adverse public perception.

Strategic Impact

Impact on Damanat's ability to achieve organisational objectives.

Each impact category should be evaluated according to agreed severity criteria.

 

Step 3 — Assess Impact Over Time

Business impact normally increases as disruption continues.

Damanat should therefore evaluate impact at defined time intervals.

An illustrative scale could include:

  • 0–4 hours;
  • 4–8 hours;
  • 8–24 hours;
  • 1–2 days;
  • 3–5 days;
  • 1 week; and
  • beyond 1 week.

For example:

 

Time of Disruption

Illustrative Impact on Mortgage Guarantee Origination

0–4 Hours

Processing delays begin; manageable backlog develops

4–8 Hours

Application queues increase; financial institution enquiries rise

8–24 Hours

Material processing delays; service commitments increasingly affected

1–2 Days

Significant operational and stakeholder impact

3–5 Days

Serious backlog and potential financial, contractual or regulatory concerns

1 Week+

Potentially severe organisational and stakeholder consequences

The actual impact thresholds should be determined through Damanat's BIA workshops rather than assumed in advance.

 

Step 4 — Determine the Maximum Tolerable Period of Disruption

The BIA should establish the point beyond which continued disruption would create unacceptable consequences for Damanat.

Depending on the terminology adopted in the BCM framework, this may be described as the:

  • Maximum Acceptable Outage (MAO);
  • Maximum Tolerable Period of Disruption (MTPD); or
  • Maximum Tolerable Downtime (MTD).

The terminology should be applied consistently.

The important principle is:

The maximum tolerable disruption establishes the boundary beyond which the consequences of non-recovery become unacceptable.

The Recovery Time Objective must therefore be set within this boundary, allowing sufficient margin for stabilisation and recovery complications.

 

Step 5 — Establish the Recovery Time Objective

The Recovery Time Objective (RTO) identifies the targeted period within which a disrupted activity should be resumed.

For example:

 
Maximum Tolerable Disruption: 24 hours

does not automatically mean:

RTO: 24 hours

An RTO set exactly at the maximum tolerable limit leaves little margin for recovery uncertainty.

Damanat may instead determine:

Maximum Tolerable Disruption: 24 hours

RTO: 8 hours

The RTO then becomes a fundamental requirement for the development of a Business Continuity Strategy.

 

Illustrative Recovery Priorities for Damanat's CBFs

The following table demonstrates how BIA outputs could be presented. The recovery periods below are illustrative only and should not be treated as approved Damanat recovery objectives without formal BIA validation.

 

CBF

Critical Business Function

Illustrative Recovery Priority

Key Consideration

CBF-1

Mortgage Guarantee Origination

High

Continuity of guarantee application processing

CBF-2

Guarantee Risk Assessment

High

Supports risk-informed guarantee decisions

CBF-3

Guarantee Issuance and Administration

High

Supports guarantee issuance and ongoing administration

CBF-4

Claims Assessment and Settlement

High

Supports timely claims processing and obligations

CBF-5

Financial and Treasury Management

High

Supports liquidity, payments and financial obligations

CBF-6

Enterprise Risk Management

Medium–High

Supports risk oversight and decision-making

CBF-7

Regulatory Compliance and Reporting

High

Supports regulatory obligations and deadlines

CBF-8

Information Technology Services

Very High

Enables multiple business and support functions

CBF-9

Information Security and Cyber Resilience

Very High

Protects and restores secure technology operations

CBF-10

Customer and Financial Institution Relationship Management

High

Maintains stakeholder coordination and service

CBF-11

Legal and Corporate Governance

Medium–High

Supports legal, governance and decision requirements

CBF-12

Human Resource Management

Medium

Supports workforce and employee requirements

CBF-13

Procurement and Vendor Management

Medium

Supports critical supplier and procurement activities

CBF-14

Corporate Communications and Stakeholder Management

High during crisis

Supports coordinated communications during disruption

CBF-15

Business Continuity and Crisis Management

Very High during major disruption

Coordinates enterprise response and recovery

The BIA should replace qualitative assumptions with validated recovery requirements.

 

Step 6 — Establish the Minimum Business Continuity Objective

The Minimum Business Continuity Objective (MBCO) defines the minimum acceptable level of products or services that Damanat must provide during a disruption.

Recovery does not always mean restoring 100 per cent of normal operations immediately.

For example, Damanat may determine that during the early recovery period Mortgage Guarantee Origination should prioritise:

  • urgent applications;
  • applications nearing contractual or operational deadlines;
  • transactions with significant stakeholder consequences; and
  • applications already at advanced approval stages.

Lower-priority work may temporarily remain suspended.

The MBCO therefore answers:

“What minimum level of service must Damanat maintain while full recovery is still underway?

 

Example of MBCO for Mortgage Guarantee Origination

Assume that normal processing capacity is 100 per cent.

An illustrative recovery profile might be:

Disruption

RTO Achieved: Minimum service restored

MBCO: 40% priority processing capacity

Stabilisation: 70% capacity

Full Recovery: 100% normal operations

The actual percentages must be determined through the BIA and Business Continuity Strategy process.

This staged approach is often more realistic than assuming instant restoration of full capacity.

 

Step 7 — Establish the Recovery Point Objective

The Recovery Point Objective (RPO) identifies the maximum tolerable amount of data loss measured in time.

This is particularly important for CBFs dependent on transactional information.

For example, if the RPO for a guarantee-processing database is 30 minutes, the recovery arrangement should enable restoration of information to a point no more than approximately 30 minutes before the disruption, subject to the approved technical design.

RPO considerations may be especially relevant to:

  • Mortgage Guarantee Origination;
  • Guarantee Risk Assessment;
  • Guarantee Issuance and Administration;
  • Claims Assessment and Settlement;
  • Financial and Treasury Management; and
  • supporting IT systems.

Business Units should establish the business requirement.

Technology teams should determine how to achieve that requirement.

 

Step 8 — Identify Minimum Personnel Requirements

The BIA should identify the minimum personnel required at different recovery stages.

For each CBF, Damanat should determine:

  • minimum number of employees;
  • essential roles;
  • specialist competencies;
  • approval authorities;
  • alternates;
  • cross-trained personnel; and
  • external support requirements.
Example

Mortgage Guarantee Origination may require minimum representation from:

  • application processing;
  • eligibility assessment;
  • risk assessment;
  • guarantee approval;
  • administration;
  • technology support; and
  • financial institution liaison.

The BIA should identify roles and competencies, not merely employee names.

 

Step 9 — Identify Technology Requirements

Technology dependencies should be identified for each CBF.

These may include:

  • business applications;
  • databases;
  • document management systems;
  • workflow systems;
  • identity and access management;
  • email;
  • telecommunications;
  • network connectivity;
  • remote access;
  • cybersecurity services;
  • reporting platforms; and
  • external interfaces.

For each system, the BIA should identify the required recovery timeframe based on the business requirement.

This is important because:

Technology recovery requirements should support business recovery requirements—not the reverse.

 

Business and Technology Recovery Alignment

Consider the following example:

CBF-1 Mortgage Guarantee Origination RTO: 4 hours

but:

Guarantee Processing Platform RTO: 8 hours

This creates a recovery gap.

The business cannot realistically recover within four hours if its essential technology requires eight hours.

Damanat would need to:

  • improve technology recovery;
  • implement an alternative business workaround;
  • revise the recovery strategy; or
  • formally reconsider the business RTO if justified.

The BIA therefore provides an important basis for aligning business and technology resilience.

 

Step 10 — Identify Information and Data Requirements

The BIA should identify critical information required for recovery.

Examples include:

  • mortgage guarantee applications;
  • customer information;
  • financial institution information;
  • eligibility records;
  • property information;
  • risk assessment records;
  • approval records;
  • guarantee certificates;
  • claims records;
  • financial records;
  • contracts;
  • regulatory information; and
  • operating procedures.

Damanat should determine:

  • where the information is stored;
  • how it is protected;
  • how quickly it is required;
  • whether an alternative copy exists; and
  • whether it can be accessed from the recovery environment.

 

Step 11 — Identify Workplace Requirements

Damanat should determine whether each CBF requires:

  • primary office access;
  • alternate workplace;
  • remote working;
  • specialist equipment;
  • secure meeting facilities;
  • command-centre capability; or
  • other physical resources.

For example, if Mortgage Guarantee Origination can operate remotely, the BIA should still determine:

  • how many employees need remote access;
  • whether all required applications are remotely accessible;
  • whether adequate bandwidth exists;
  • whether secure authentication is available; and
  • whether sensitive information can be handled appropriately.

The statement “employees can work remotely” is not sufficient without quantifying the recovery requirement.

 

Step 12 — Identify Internal Dependencies

Critical Business Functions frequently depend upon one another.

For example:

CBF-1 Mortgage Guarantee Origination

may depend upon:

  • CBF-2 Guarantee Risk Assessment;
  • CBF-8 Information Technology Services;
  • CBF-9 Information Security and Cyber Resilience;
  • CBF-10 Customer and Financial Institution Relationship Management; and
  • CBF-11 Legal and Corporate Governance under certain circumstances.

Similarly:

CBF-4 Claims Assessment and Settlement

may depend upon:

  • financial processing;
  • technology;
  • legal support;
  • risk management; and
  • external parties.

Understanding these relationships is essential for establishing realistic recovery sequences.

 

Illustrative CBF Dependency Map

 

CBF

Key Internal Dependencies

CBF-1 Mortgage Guarantee Origination

CBF-2, CBF-8, CBF-9, CBF-10

CBF-2 Guarantee Risk Assessment

CBF-8, CBF-9

CBF-3 Guarantee Issuance and Administration

CBF-1, CBF-8, CBF-9

CBF-4 Claims Assessment and Settlement

CBF-5, CBF-8, CBF-11

CBF-5 Financial and Treasury Management

CBF-8, CBF-9

CBF-6 Enterprise Risk Management

CBF-8, CBF-9

CBF-7 Regulatory Compliance and Reporting

CBF-5, CBF-6, CBF-8, CBF-11

CBF-8 Information Technology Services

CBF-9, CBF-13

CBF-9 Information Security and Cyber Resilience

CBF-8, CBF-13

CBF-10 Customer and Financial Institution Relationship Management

CBF-1, CBF-3, CBF-4, CBF-8

CBF-11 Legal and Corporate Governance

CBF-7, CBF-8

CBF-12 Human Resource Management

CBF-8

CBF-13 Procurement and Vendor Management

CBF-5, CBF-8, CBF-11

CBF-14 Corporate Communications and Stakeholder Management

CBF-8, CBF-10, CBF-15

CBF-15 Business Continuity and Crisis Management

All relevant CBFs during major disruption

These relationships are illustrative and should be validated through BIA workshops.

 

Step 13 — Identify External Dependencies

Damanat should identify external organisations required to support each CBF.

These may include:

  • participating financial institutions;
  • technology providers;
  • telecommunications providers;
  • cloud or hosting providers;
  • banking service providers;
  • professional advisers;
  • facilities providers;
  • specialist contractors; and
  • other outsourced service providers.

The BIA should determine:

  • service provided;
  • CBF supported;
  • required recovery timeframe;
  • contractual recovery commitment;
  • alternative provider availability;
  • concentration risk; and
  • consequences of provider failure.

 

Third-Party Recovery Alignment

A critical supplier's recovery capability should align with Damanat's business requirements.

For example:

Damanat CBF RTO: 4 hours
Critical Supplier Recovery Commitment: 24 hours

This represents a significant recovery gap.

Potential responses include:

  • renegotiating the supplier requirement;
  • establishing redundancy;
  • maintaining an alternative supplier;
  • developing a manual workaround;
  • insourcing temporary capability; or
  • formally accepting and managing the residual risk.

The BIA makes these dependency gaps visible.

 

Step 14 — Establish Recovery Priorities

Once impact and dependency information has been analysed, Damanat should establish an overall recovery sequence.

An illustrative tiering structure could be:

Tier 1 — Immediate / Very High Priority

Functions required rapidly to prevent severe consequences.

Tier 2 — High Priority

Functions required shortly after Tier 1 to maintain important services and obligations.

Tier 3 — Medium Priority

Functions that can tolerate a longer interruption but remain necessary for sustained operations.

Tier 4 — Deferred Recovery

Activities that can temporarily remain suspended while priority recovery occurs.

The classification should be based on BIA evidence rather than organisational hierarchy.

 

Example of Damanat Recovery Sequencing

During a major enterprise disruption, an illustrative sequence might be:

Crisis Coordination and Cyber/Technology Response

Critical Technology and Communications

Mortgage Guarantee and Claims Activities

Financial, Regulatory and Stakeholder Activities

Supporting Corporate Functions

This sequence should not be predetermined as the final answer.

The BIA should establish the actual sequence based on impact, dependencies and recovery requirements.

 

BIA Workshops

The BIA should be conducted with knowledgeable representatives from the relevant Business Units.

Participants may include:

  • Heads of Business Units;
  • Business Unit BCM Coordinators;
  • process owners;
  • technology representatives;
  • risk management;
  • compliance;
  • finance;
  • information security;
  • procurement;
  • HR; and
  • BCM representatives.

The BCM function should facilitate the methodology.

The Business Units should own and validate the business information.

This reflects the principle:

BCM facilitates the BIA; the business owns the impact and recovery requirements.

 

Questions to Ask During a Damanat BIA Workshop

For each CBF, the facilitator should ask questions such as:

  1. What business processes make up this function?
  2. What happens if the function stops?
  3. How does the impact change after four hours, one day, three days and one week?
  4. When does the disruption become unacceptable?
  5. What minimum service must continue?
  6. How quickly should the function recover?
  7. How much data loss can be tolerated?
  8. What minimum personnel are required?
  9. Which technology applications are essential?
  10. What information is required?
  11. What workplace capability is required?
  12. Which other Damanat functions are required?
  13. Which external parties are required?
  14. Which suppliers are critical?
  15. Are manual workarounds available?
  16. What backlog would accumulate?
  17. How long would backlog recovery take?
  18. What regulatory or contractual deadlines could be affected?

The responses should be supported by evidence wherever practical.

 

Avoiding Common BIA Weaknesses

Damanat should avoid several common BIA problems.

Everything Is Critical

If every function is classified as immediately critical, the BIA has not established meaningful priorities.

Arbitrary RTOs

RTOs should be derived from impact analysis rather than selected because a particular timeframe appears convenient.

Technology-Led RTOs

Business recovery requirements should drive technology requirements.

Ignoring Dependencies

A function cannot recover if essential supporting resources remain unavailable.

Confusing RTO with Full Recovery

RTO may represent restoration of an acceptable minimum capability rather than immediate return to 100 per cent normal capacity.

Ignoring Backlogs

The ability to resume processing does not mean accumulated work has disappeared.

Static BIA Information

BIA results should be reviewed when material organisational or technology changes occur.

 

Backlog Analysis

Damanat should assess the backlog created during disruption.

For example, if Mortgage Guarantee Origination normally processes a defined number of applications each working day, a three-day interruption may create a substantial queue.

The BIA should consider:

  • backlog volume;
  • prioritisation rules;
  • additional staffing;
  • overtime requirements;
  • temporary processing capacity;
  • stakeholder communications; and
  • time required to return to normal service levels.

Recovery therefore has two dimensions:

Restore the capability

and

Recover the accumulated workload.

 

Specific BIA Requirements for Damanat

For Damanat, the BIA should establish, at minimum, the following for each CBF:

Requirement

Expected BIA Output

CBF identification

Approved CBF and supporting process catalogue

Business ownership

Named accountable Business Unit

Impact assessment

Impact by category and time

Maximum tolerable disruption

Approved tolerance boundary

Recovery Time Objective

Target recovery time

Recovery Point Objective

Data recovery requirement where applicable

MBCO

Minimum acceptable operating capability

Personnel

Minimum roles and staffing

Technology

Required applications and infrastructure

Information

Critical records and data

Workplace

Recovery-location requirements

Internal dependencies

Supporting Damanat functions

External dependencies

Financial institutions and other parties

Suppliers

Critical third-party providers

Backlog

Accumulation and recovery requirements

Workaround

Available temporary procedures

Validation

Business Unit Head approval

These requirements provide the inputs needed for the subsequent Business Continuity Strategy phase.

 

Regulatory Considerations for Damanat

As a Saudi financial-sector organisation, Damanat should ensure that its BIA methodology is aligned with applicable requirements and supervisory expectations of the Saudi Central Bank (SAMA) and, where relevant to its activities, the Insurance Authority.

The BIA should provide documented evidence demonstrating that Damanat has systematically:

  • identified critical activities and services;
  • assessed the consequences of their disruption;
  • established recovery priorities;
  • determined recovery time requirements;
  • identified supporting resources;
  • considered internal and external dependencies;
  • aligned technology recovery with business requirements;
  • considered critical third parties; and
  • obtained appropriate management validation.

These requirements should be incorporated into Damanat's BCM methodology rather than treated as a separate compliance exercise.

 

Linking the BIA to ISO 22301

Within an ISO 22301-aligned Business Continuity Management System, the BIA forms part of the organisation's structured assessment of business continuity requirements.

For Damanat, this means the BIA should not exist as an isolated spreadsheet.

Its results should directly influence:

  • continuity priorities;
  • recovery objectives;
  • continuity strategies and solutions;
  • resource requirements;
  • Business Continuity Plans;
  • technology recovery requirements;
  • supplier continuity requirements;
  • exercise objectives; and
  • continual improvement.

The relationship is:

Business Impact → Recovery Requirement → Continuity Solution → Recovery Procedure → Exercise

This traceability is essential for demonstrating that BCM arrangements have been developed from actual business requirements.

 

BIA Validation and Approval

Following completion of the analysis, results should be validated by the relevant Business Unit Heads.

Validation should confirm that:

  • business processes are correctly identified;
  • impact assessments are reasonable;
  • recovery priorities are justified;
  • RTOs are realistic;
  • MBCOs reflect minimum operational requirements;
  • resource requirements are accurate;
  • technology dependencies are complete;
  • internal dependencies are understood;
  • external dependencies are identified; and
  • significant gaps have been documented.

The central BCM function should subsequently perform a cross-functional review.

This is necessary because individual Business Units may identify conflicting recovery assumptions.

 

Cross-Functional BIA Validation

Consider the following example:

CBF-1 Mortgage Guarantee Origination RTO: 4 hours

CBF-8 Information Technology Services recovery capability for required application: 8 hours

External service provider recovery: 12 hours

The business requirement cannot currently be achieved.

This should be recorded as a recovery capability gap.

The Business Continuity Strategy phase must then determine how to address the gap.

This illustrates why the BIA is not merely about assigning RTOs.

It identifies the requirements against which Damanat's actual recovery capability must subsequently be designed and tested.

 

BIA Deliverables

At the completion of the BIA phase, Damanat should maintain a structured set of deliverables.

Ref

Deliverable

Purpose

BIA-01

BIA Methodology

Defines the assessment approach

BIA-02

CBF Catalogue

Identifies functions to be assessed

BIA-03

Sub-CBF / Process Catalogue

Identifies supporting activities

BIA-04

Impact Assessment

Evaluates consequences over time

BIA-05

Recovery Priority Schedule

Establishes recovery sequencing

BIA-06

RTO Register

Records recovery-time requirements

BIA-07

RPO Register

Records data-recovery requirements

BIA-08

MBCO Register

Records minimum service requirements

BIA-09

Resource Requirements

Identifies minimum recovery resources

BIA-10

Dependency Register

Records internal and external dependencies

BIA-11

Critical Supplier Register

Identifies continuity-sensitive suppliers

BIA-12

Recovery Gap Register

Identifies capability deficiencies

BIA-13

BIA Report

Consolidates analysis and findings

BIA-14

Management Approval

Provides formal validation

Together, these outputs establish the business requirements for the next BCM phase.

 

Example of a Consolidated Damanat BIA Record

A simplified BIA record might appear as follows:

Field

Illustrative Entry

CBF

CBF-1 Mortgage Guarantee Origination

Business Owner

Mortgage Guarantee Operations

Impact

High operational and stakeholder impact as disruption extends

Maximum Tolerable Disruption

To be established through approved BIA

RTO

To be established through approved BIA

RPO

To be established based on transaction and data requirements

MBCO

Priority mortgage guarantee processing

Minimum Personnel

Designated processing, assessment and approval roles

Critical Technology

Guarantee processing and supporting systems

Critical Information

Applications, assessment records, approvals and guarantee records

Internal Dependencies

Risk, IT, Information Security and relationship management

External Dependencies

Participating financial institutions and critical service providers

Workaround

Approved temporary/manual procedure where feasible

Backlog Requirement

Prioritise and reconcile outstanding applications

Approval

Relevant Business Unit Head

The purpose of this record is to provide a concise recovery requirement that can be translated into continuity strategy.

 

Moving from BIA to Business Continuity Strategy

The BIA tells Damanat what is required.

The Business Continuity Strategy determines how that requirement will be achieved.

For example:

BIA Requirement

Mortgage Guarantee Origination must resume within the approved RTO.

Identified Dependency

The function requires the guarantee processing platform.

Current Capability

The platform cannot currently recover within the business requirement.

Strategy Question

What solution will enable Damanat to close the gap?

Possible options might include:

  • improved disaster recovery;
  • high-availability architecture;
  • alternative processing capability;
  • manual workaround;
  • enhanced data replication; or
  • a combination of solutions.

The BIA therefore establishes the demand for resilience.

The BCS phase establishes the supply of resilience.

 

BIA as the Foundation for Recovery Investment

The BIA also provides Damanat with an evidence base for investment decisions.

Without a BIA, a proposal for additional recovery technology may appear to be a purely technical request.

With a BIA, management can understand:

  • which CBF depends on the technology;
  • how quickly the function must recover;
  • what happens if recovery is delayed;
  • which stakeholders are affected;
  • what existing capability can achieve; and
  • what recovery gap remains.

This enables Damanat to prioritise recovery investment based on business impact rather than technology preference.

 

Maintaining the BIA

BIA information changes as the organisation changes.

Damanat should establish both periodic and event-driven BIA reviews.

Review triggers may include:

  • introduction of new mortgage guarantee products or services;
  • major process changes;
  • technology transformation;
  • organisational restructuring;
  • new outsourcing arrangements;
  • changes in participating financial institutions;
  • new critical suppliers;
  • changes in operating locations;
  • significant incidents;
  • exercise findings; and
  • changes in regulatory obligations.

The BIA should therefore be treated as a living business analysis, not a one-time implementation document.

 

Completion Criteria for the BIA Phase

The BIA phase should be considered complete for the initial BCM implementation when:

  • all identified CBFs have been assessed;
  • supporting processes have been identified;
  • impacts have been evaluated over time;
  • maximum tolerable disruption has been determined;
  • recovery priorities have been established;
  • RTOs have been approved;
  • RPOs have been established where appropriate;
  • MBCOs have been determined;
  • minimum personnel requirements have been identified;
  • technology requirements have been identified;
  • information requirements have been documented;
  • workplace requirements have been established;
  • internal dependencies have been mapped;
  • external dependencies have been identified;
  • critical suppliers have been assessed;
  • backlog requirements have been considered;
  • recovery gaps have been documented; and
  • Business Unit Heads have validated the results.

At that point, Damanat has established a sufficiently structured set of business recovery requirements to proceed to the Business Continuity Strategy phase.

 

 

The Business Impact Analysis phase provides the business-driven foundation for Business Continuity Management at The Saudi Mortgage Guarantees Services Company.

While Risk Analysis and Review identifies the threats capable of disrupting Damanat, the BIA determines the consequences of those disruptions and establishes the recovery requirements necessary to prevent them from becoming unacceptable.

For Damanat, the BIA should therefore move systematically through:

Critical Business Function

→ Supporting Processes

→ Impact Over Time

→ Maximum Tolerable Disruption

→ Recovery Priority

→ RTO

→ RPO

→ MBCO

→ Resource Requirements

→ Dependencies

→ Recovery Gaps

Applying this methodology across Damanat's 15 Critical Business Functions enables management to distinguish between activities that require rapid recovery and those that can tolerate longer periods of disruption.

The BIA also makes the interdependent nature of Damanat's operations visible.

Mortgage Guarantee Origination cannot be considered only as an operational process.

Its recovery may depend upon Guarantee Risk Assessment, Information Technology Services, Information Security and Cyber Resilience, participating financial institutions, critical data, authorised employees and third-party service providers.

The same principle applies across the other Critical Business Functions.

Consequently, the BIA should not answer only:

“How quickly does this Business Unit want to recover?”

It should answer:

“Based on the consequences of disruption, how quickly must this Critical Business Function recover, what minimum level of service must it provide, and what resources and dependencies must be available to make that recovery possible?”

The resulting recovery requirements provide the foundation for the next phase of Damanat's BCM Planning Methodology—Business Continuity Strategy (BCS).

The transition is therefore:

  • RAR identifies what can go wrong.

  • BIA determines what matters and by when.

  • BCS determines how Damanat will achieve the required recovery.

This progression ensures that Damanat's continuity strategies are not selected arbitrarily. They are developed in response to clearly defined, management-approved business requirements.

Ultimately, a well-executed BIA enables Damanat to direct people, technology, financial resources and management attention toward the activities where disruption would create the greatest consequences.

That is what transforms Business Continuity Management from a collection of recovery plans into a business-driven resilience capability.

 

Note from Author: These additional eight chapters (Intro P0 to Part 7) are developed purely for Saudi Mortgage Guarantees Services Company (Damanat) and serve as a training guide for its further drill-down of the business impact analysis phase.

P0 P1 P2 P3 P4 P5 P6 P7

eBook 2: Implementing Business Continuity Management
C1 C2 C3 C4 C5
C6 C7 C8 C9 C10
 

More Information About Business Continuity Management Courses

To learn more about the course and schedule, click the buttons below for BCM-300 Business Continuity Management Implementer [BCM-3] and BCM-5000 Business Continuity Management Expert Implementer [BCM-5]

Please feel free to send us a note if you have any questions.