The Business Impact Analysis (BIA) is one of the most important phases of the Business Continuity Management (BCM) Planning Methodology for The Saudi Mortgage Guarantees Services Company (Damanat).
The preceding Risk Analysis and Review (RAR) phase examines the threats and vulnerabilities that could disrupt Damanat.
The BIA approaches disruption from a different perspective. Rather than asking what caused the disruption, it asks:
This distinction is fundamental to effective BCM.
A cyberattack, technology outage, workplace disruption, loss of key personnel, supplier failure or infrastructure outage may have very different causes.
However, each could interrupt the same Critical Business Function (CBF). The BIA therefore focuses primarily on the consequences of disruption over time, irrespective of the initiating event.
For Damanat, the BIA should identify and assess the organisation's Critical Business Functions, determine the operational, financial, regulatory, legal, stakeholder and reputational consequences of their disruption, establish recovery priorities and identify the resources and dependencies required to support recovery.
The BIA provides the analytical bridge between understanding Damanat's operations and the development of appropriate Business Continuity Strategies.
The relationship can be represented as:
What could disrupt Damanat?
↓
What would the consequences be, and what must be recovered by when?
↓
How will Damanat achieve those recovery requirements?
The quality of the subsequent Business Continuity Strategy and Business Continuity Plans therefore depends heavily on the BIA.
The purpose of the BIA is to provide Damanat with an evidence-based understanding of the consequences of disruption and the recovery priorities required to protect its important business activities.
The BIA should enable Damanat to:
The BIA is therefore not simply a questionnaire or inventory exercise.
It is a management decision-making process for determining what Damanat must protect and recover, by when, and with what resources.
For the purpose of this BCM implementation, the following 15 Critical Business Functions have been identified for assessment.
|
CBF Code |
Critical Business Function |
|
CBF-1 |
Mortgage Guarantee Origination |
|
CBF-2 |
Guarantee Risk Assessment |
|
CBF-3 |
Guarantee Issuance and Administration |
|
CBF-4 |
Claims Assessment and Settlement |
|
CBF-5 |
Financial and Treasury Management |
|
CBF-6 |
Enterprise Risk Management |
|
CBF-7 |
Regulatory Compliance and Reporting |
|
CBF-8 |
Information Technology Services |
|
CBF-9 |
Information Security and Cyber Resilience |
|
CBF-10 |
Customer and Financial Institution Relationship Management |
|
CBF-11 |
Legal and Corporate Governance |
|
CBF-12 |
Human Resource Management |
|
CBF-13 |
Procurement and Vendor Management |
|
CBF-14 |
Corporate Communications and Stakeholder Management |
|
CBF-15 |
Business Continuity and Crisis Management |
These CBFs provide the starting point for the BIA.
However, Damanat should avoid assuming that all 15 functions have the same recovery priority. One of the principal purposes of the BIA is to determine how the impact of interruption differs between functions and changes over time.
A function should not be classified as critical merely because it is important during normal operations.
For BCM purposes, criticality should be determined primarily by the consequences of the function's unavailability over time.
For example, two functions may both be important to Damanat:
However, the consequences of four hours of disruption may differ significantly across functions.
Likewise, a function that can tolerate one day of disruption may become extremely critical if the outage continues for one week.
The BIA should therefore assess:
rather than relying solely on management perception of importance.
A structured BIA for Damanat should follow a sequence such as:
→ Identify Supporting Processes
→ Assess Impact Over Time
→ Determine Maximum Tolerable Disruption
→ Establish Recovery Priority
→ Determine MBCO
→ Establish RTO
→ Establish RPO
→ Identify Resource Requirements
→ Map Dependencies
→ Validate with Management
This process should be applied consistently across the identified CBFs.
Each Critical Business Function should be decomposed into its supporting business processes or Sub-CBFs.
This provides a more detailed basis for analysis.
For example, CBF-1 Mortgage Guarantee Origination may include processes such as:
The BIA should determine whether all supporting processes require the same recovery timeframe.
In many cases, they will not.
Damanat should establish a standard set of impact categories to ensure consistency across Business Units.
Suitable categories include:
Potential direct or indirect financial consequences.
Inability to perform business activities or meet service requirements.
Potential failure to comply with applicable regulatory obligations.
Potential breach of legal or contractual commitments.
Impact on participating financial institutions, customers and other stakeholders.
Potential loss of stakeholder confidence or adverse public perception.
Impact on Damanat's ability to achieve organisational objectives.
Each impact category should be evaluated according to agreed severity criteria.
Business impact normally increases as disruption continues.
Damanat should therefore evaluate impact at defined time intervals.
An illustrative scale could include:
For example:
|
Time of Disruption |
Illustrative Impact on Mortgage Guarantee Origination |
|
0–4 Hours |
Processing delays begin; manageable backlog develops |
|
4–8 Hours |
Application queues increase; financial institution enquiries rise |
|
8–24 Hours |
Material processing delays; service commitments increasingly affected |
|
1–2 Days |
Significant operational and stakeholder impact |
|
3–5 Days |
Serious backlog and potential financial, contractual or regulatory concerns |
|
1 Week+ |
Potentially severe organisational and stakeholder consequences |
The actual impact thresholds should be determined through Damanat's BIA workshops rather than assumed in advance.
The BIA should establish the point beyond which continued disruption would create unacceptable consequences for Damanat.
The terminology should be applied consistently.
The important principle is:
The Recovery Time Objective must therefore be set within this boundary, allowing sufficient margin for stabilisation and recovery complications.
For example:
does not automatically mean:
An RTO set exactly at the maximum tolerable limit leaves little margin for recovery uncertainty.
Damanat may instead determine:
RTO: 8 hours
The RTO then becomes a fundamental requirement for the development of a Business Continuity Strategy.
The following table demonstrates how BIA outputs could be presented. The recovery periods below are illustrative only and should not be treated as approved Damanat recovery objectives without formal BIA validation.
|
CBF |
Critical Business Function |
Illustrative Recovery Priority |
Key Consideration |
|
CBF-1 |
Mortgage Guarantee Origination |
High |
Continuity of guarantee application processing |
|
CBF-2 |
Guarantee Risk Assessment |
High |
Supports risk-informed guarantee decisions |
|
CBF-3 |
Guarantee Issuance and Administration |
High |
Supports guarantee issuance and ongoing administration |
|
CBF-4 |
Claims Assessment and Settlement |
High |
Supports timely claims processing and obligations |
|
CBF-5 |
Financial and Treasury Management |
High |
Supports liquidity, payments and financial obligations |
|
CBF-6 |
Enterprise Risk Management |
Medium–High |
Supports risk oversight and decision-making |
|
CBF-7 |
Regulatory Compliance and Reporting |
High |
Supports regulatory obligations and deadlines |
|
CBF-8 |
Information Technology Services |
Very High |
Enables multiple business and support functions |
|
CBF-9 |
Information Security and Cyber Resilience |
Very High |
Protects and restores secure technology operations |
|
CBF-10 |
Customer and Financial Institution Relationship Management |
High |
Maintains stakeholder coordination and service |
|
CBF-11 |
Legal and Corporate Governance |
Medium–High |
Supports legal, governance and decision requirements |
|
CBF-12 |
Human Resource Management |
Medium |
Supports workforce and employee requirements |
|
CBF-13 |
Procurement and Vendor Management |
Medium |
Supports critical supplier and procurement activities |
|
CBF-14 |
Corporate Communications and Stakeholder Management |
High during crisis |
Supports coordinated communications during disruption |
|
CBF-15 |
Business Continuity and Crisis Management |
Very High during major disruption |
Coordinates enterprise response and recovery |
The BIA should replace qualitative assumptions with validated recovery requirements.
Recovery does not always mean restoring 100 per cent of normal operations immediately.
For example, Damanat may determine that during the early recovery period Mortgage Guarantee Origination should prioritise:
Lower-priority work may temporarily remain suspended.
The MBCO therefore answers:
Assume that normal processing capacity is 100 per cent.
An illustrative recovery profile might be:
Disruption
↓
RTO Achieved: Minimum service restored
↓
MBCO: 40% priority processing capacity
↓
Stabilisation: 70% capacity
↓
Full Recovery: 100% normal operations
The actual percentages must be determined through the BIA and Business Continuity Strategy process.
This staged approach is often more realistic than assuming instant restoration of full capacity.
This is particularly important for CBFs dependent on transactional information.
For example, if the RPO for a guarantee-processing database is 30 minutes, the recovery arrangement should enable restoration of information to a point no more than approximately 30 minutes before the disruption, subject to the approved technical design.
RPO considerations may be especially relevant to:
Business Units should establish the business requirement.
Technology teams should determine how to achieve that requirement.
The BIA should identify the minimum personnel required at different recovery stages.
For each CBF, Damanat should determine:
Mortgage Guarantee Origination may require minimum representation from:
The BIA should identify roles and competencies, not merely employee names.
Technology dependencies should be identified for each CBF.
These may include:
For each system, the BIA should identify the required recovery timeframe based on the business requirement.
This is important because:
Consider the following example:
CBF-1 Mortgage Guarantee Origination RTO: 4 hours
but:
Guarantee Processing Platform RTO: 8 hours
This creates a recovery gap.
The business cannot realistically recover within four hours if its essential technology requires eight hours.
Damanat would need to:
The BIA therefore provides an important basis for aligning business and technology resilience.
The BIA should identify critical information required for recovery.
Examples include:
Damanat should determine:
Damanat should determine whether each CBF requires:
For example, if Mortgage Guarantee Origination can operate remotely, the BIA should still determine:
The statement “employees can work remotely” is not sufficient without quantifying the recovery requirement.
Critical Business Functions frequently depend upon one another.
For example:
may depend upon:
Similarly:
may depend upon:
Understanding these relationships is essential for establishing realistic recovery sequences.
|
CBF |
Key Internal Dependencies |
|
CBF-1 Mortgage Guarantee Origination |
CBF-2, CBF-8, CBF-9, CBF-10 |
|
CBF-2 Guarantee Risk Assessment |
CBF-8, CBF-9 |
|
CBF-3 Guarantee Issuance and Administration |
CBF-1, CBF-8, CBF-9 |
|
CBF-4 Claims Assessment and Settlement |
CBF-5, CBF-8, CBF-11 |
|
CBF-5 Financial and Treasury Management |
CBF-8, CBF-9 |
|
CBF-6 Enterprise Risk Management |
CBF-8, CBF-9 |
|
CBF-7 Regulatory Compliance and Reporting |
CBF-5, CBF-6, CBF-8, CBF-11 |
|
CBF-8 Information Technology Services |
CBF-9, CBF-13 |
|
CBF-9 Information Security and Cyber Resilience |
CBF-8, CBF-13 |
|
CBF-10 Customer and Financial Institution Relationship Management |
CBF-1, CBF-3, CBF-4, CBF-8 |
|
CBF-11 Legal and Corporate Governance |
CBF-7, CBF-8 |
|
CBF-12 Human Resource Management |
CBF-8 |
|
CBF-13 Procurement and Vendor Management |
CBF-5, CBF-8, CBF-11 |
|
CBF-14 Corporate Communications and Stakeholder Management |
CBF-8, CBF-10, CBF-15 |
|
CBF-15 Business Continuity and Crisis Management |
All relevant CBFs during major disruption |
These relationships are illustrative and should be validated through BIA workshops.
Damanat should identify external organisations required to support each CBF.
These may include:
The BIA should determine:
A critical supplier's recovery capability should align with Damanat's business requirements.
For example:
This represents a significant recovery gap.
Potential responses include:
The BIA makes these dependency gaps visible.
Once impact and dependency information has been analysed, Damanat should establish an overall recovery sequence.
An illustrative tiering structure could be:
Functions required rapidly to prevent severe consequences.
Functions required shortly after Tier 1 to maintain important services and obligations.
Functions that can tolerate a longer interruption but remain necessary for sustained operations.
Activities that can temporarily remain suspended while priority recovery occurs.
The classification should be based on BIA evidence rather than organisational hierarchy.
During a major enterprise disruption, an illustrative sequence might be:
Crisis Coordination and Cyber/Technology Response
↓
Critical Technology and Communications
↓
Mortgage Guarantee and Claims Activities
↓
Financial, Regulatory and Stakeholder Activities
↓
Supporting Corporate Functions
This sequence should not be predetermined as the final answer.
The BIA should establish the actual sequence based on impact, dependencies and recovery requirements.
The BIA should be conducted with knowledgeable representatives from the relevant Business Units.
Participants may include:
The BCM function should facilitate the methodology.
The Business Units should own and validate the business information.
This reflects the principle:
BCM facilitates the BIA; the business owns the impact and recovery requirements.
For each CBF, the facilitator should ask questions such as:
The responses should be supported by evidence wherever practical.
Damanat should avoid several common BIA problems.
If every function is classified as immediately critical, the BIA has not established meaningful priorities.
RTOs should be derived from impact analysis rather than selected because a particular timeframe appears convenient.
Business recovery requirements should drive technology requirements.
A function cannot recover if essential supporting resources remain unavailable.
RTO may represent restoration of an acceptable minimum capability rather than immediate return to 100 per cent normal capacity.
The ability to resume processing does not mean accumulated work has disappeared.
BIA results should be reviewed when material organisational or technology changes occur.
Damanat should assess the backlog created during disruption.
For example, if Mortgage Guarantee Origination normally processes a defined number of applications each working day, a three-day interruption may create a substantial queue.
The BIA should consider:
Recovery therefore has two dimensions:
Restore the capability
and
Recover the accumulated workload.
For Damanat, the BIA should establish, at minimum, the following for each CBF:
|
Requirement |
Expected BIA Output |
|
CBF identification |
Approved CBF and supporting process catalogue |
|
Business ownership |
Named accountable Business Unit |
|
Impact assessment |
Impact by category and time |
|
Maximum tolerable disruption |
Approved tolerance boundary |
|
Recovery Time Objective |
Target recovery time |
|
Recovery Point Objective |
Data recovery requirement where applicable |
|
MBCO |
Minimum acceptable operating capability |
|
Personnel |
Minimum roles and staffing |
|
Technology |
Required applications and infrastructure |
|
Information |
Critical records and data |
|
Workplace |
Recovery-location requirements |
|
Internal dependencies |
Supporting Damanat functions |
|
External dependencies |
Financial institutions and other parties |
|
Suppliers |
Critical third-party providers |
|
Backlog |
Accumulation and recovery requirements |
|
Workaround |
Available temporary procedures |
|
Validation |
Business Unit Head approval |
These requirements provide the inputs needed for the subsequent Business Continuity Strategy phase.
As a Saudi financial-sector organisation, Damanat should ensure that its BIA methodology is aligned with applicable requirements and supervisory expectations of the Saudi Central Bank (SAMA) and, where relevant to its activities, the Insurance Authority.
The BIA should provide documented evidence demonstrating that Damanat has systematically:
These requirements should be incorporated into Damanat's BCM methodology rather than treated as a separate compliance exercise.
Within an ISO 22301-aligned Business Continuity Management System, the BIA forms part of the organisation's structured assessment of business continuity requirements.
For Damanat, this means the BIA should not exist as an isolated spreadsheet.
Its results should directly influence:
The relationship is:
Business Impact → Recovery Requirement → Continuity Solution → Recovery Procedure → Exercise
This traceability is essential for demonstrating that BCM arrangements have been developed from actual business requirements.
Following completion of the analysis, results should be validated by the relevant Business Unit Heads.
Validation should confirm that:
The central BCM function should subsequently perform a cross-functional review.
This is necessary because individual Business Units may identify conflicting recovery assumptions.
Consider the following example:
CBF-1 Mortgage Guarantee Origination RTO: 4 hours
CBF-8 Information Technology Services recovery capability for required application: 8 hours
External service provider recovery: 12 hours
The business requirement cannot currently be achieved.
This should be recorded as a recovery capability gap.
The Business Continuity Strategy phase must then determine how to address the gap.
This illustrates why the BIA is not merely about assigning RTOs.
It identifies the requirements against which Damanat's actual recovery capability must subsequently be designed and tested.
At the completion of the BIA phase, Damanat should maintain a structured set of deliverables.
|
Ref |
Deliverable |
Purpose |
|
BIA-01 |
BIA Methodology |
Defines the assessment approach |
|
BIA-02 |
CBF Catalogue |
Identifies functions to be assessed |
|
BIA-03 |
Sub-CBF / Process Catalogue |
Identifies supporting activities |
|
BIA-04 |
Impact Assessment |
Evaluates consequences over time |
|
BIA-05 |
Recovery Priority Schedule |
Establishes recovery sequencing |
|
BIA-06 |
RTO Register |
Records recovery-time requirements |
|
BIA-07 |
RPO Register |
Records data-recovery requirements |
|
BIA-08 |
MBCO Register |
Records minimum service requirements |
|
BIA-09 |
Resource Requirements |
Identifies minimum recovery resources |
|
BIA-10 |
Dependency Register |
Records internal and external dependencies |
|
BIA-11 |
Critical Supplier Register |
Identifies continuity-sensitive suppliers |
|
BIA-12 |
Recovery Gap Register |
Identifies capability deficiencies |
|
BIA-13 |
BIA Report |
Consolidates analysis and findings |
|
BIA-14 |
Management Approval |
Provides formal validation |
Together, these outputs establish the business requirements for the next BCM phase.
A simplified BIA record might appear as follows:
|
Field |
Illustrative Entry |
|
CBF |
CBF-1 Mortgage Guarantee Origination |
|
Business Owner |
Mortgage Guarantee Operations |
|
Impact |
High operational and stakeholder impact as disruption extends |
|
Maximum Tolerable Disruption |
To be established through approved BIA |
|
RTO |
To be established through approved BIA |
|
RPO |
To be established based on transaction and data requirements |
|
MBCO |
Priority mortgage guarantee processing |
|
Minimum Personnel |
Designated processing, assessment and approval roles |
|
Critical Technology |
Guarantee processing and supporting systems |
|
Critical Information |
Applications, assessment records, approvals and guarantee records |
|
Internal Dependencies |
Risk, IT, Information Security and relationship management |
|
External Dependencies |
Participating financial institutions and critical service providers |
|
Workaround |
Approved temporary/manual procedure where feasible |
|
Backlog Requirement |
Prioritise and reconcile outstanding applications |
|
Approval |
Relevant Business Unit Head |
The purpose of this record is to provide a concise recovery requirement that can be translated into continuity strategy.
The BIA tells Damanat what is required.
The Business Continuity Strategy determines how that requirement will be achieved.
For example:
Mortgage Guarantee Origination must resume within the approved RTO.
The function requires the guarantee processing platform.
The platform cannot currently recover within the business requirement.
What solution will enable Damanat to close the gap?
Possible options might include:
The BIA therefore establishes the demand for resilience.
The BCS phase establishes the supply of resilience.
The BIA also provides Damanat with an evidence base for investment decisions.
Without a BIA, a proposal for additional recovery technology may appear to be a purely technical request.
With a BIA, management can understand:
This enables Damanat to prioritise recovery investment based on business impact rather than technology preference.
BIA information changes as the organisation changes.
Damanat should establish both periodic and event-driven BIA reviews.
Review triggers may include:
The BIA should therefore be treated as a living business analysis, not a one-time implementation document.
The BIA phase should be considered complete for the initial BCM implementation when:
At that point, Damanat has established a sufficiently structured set of business recovery requirements to proceed to the Business Continuity Strategy phase.
The Business Impact Analysis phase provides the business-driven foundation for Business Continuity Management at The Saudi Mortgage Guarantees Services Company.
While Risk Analysis and Review identifies the threats capable of disrupting Damanat, the BIA determines the consequences of those disruptions and establishes the recovery requirements necessary to prevent them from becoming unacceptable.
For Damanat, the BIA should therefore move systematically through:
→ Supporting Processes
→ Impact Over Time
→ Maximum Tolerable Disruption
→ Recovery Priority
→ RTO
→ RPO
→ MBCO
→ Resource Requirements
→ Dependencies
→ Recovery Gaps
Applying this methodology across Damanat's 15 Critical Business Functions enables management to distinguish between activities that require rapid recovery and those that can tolerate longer periods of disruption.
The BIA also makes the interdependent nature of Damanat's operations visible.
Mortgage Guarantee Origination cannot be considered only as an operational process.
Its recovery may depend upon Guarantee Risk Assessment, Information Technology Services, Information Security and Cyber Resilience, participating financial institutions, critical data, authorised employees and third-party service providers.
The same principle applies across the other Critical Business Functions.
Consequently, the BIA should not answer only:
It should answer:
The resulting recovery requirements provide the foundation for the next phase of Damanat's BCM Planning Methodology—Business Continuity Strategy (BCS).
The transition is therefore:
RAR identifies what can go wrong.
BIA determines what matters and by when.
BCS determines how Damanat will achieve the required recovery.
This progression ensures that Damanat's continuity strategies are not selected arbitrarily. They are developed in response to clearly defined, management-approved business requirements.
Ultimately, a well-executed BIA enables Damanat to direct people, technology, financial resources and management attention toward the activities where disruption would create the greatest consequences.
That is what transforms Business Continuity Management from a collection of recovery plans into a business-driven resilience capability.
Note from Author: These additional eight chapters (Intro P0 to Part 7) are developed purely for Saudi Mortgage Guarantees Services Company (Damanat) and serve as a training guide for its further drill-down of the business impact analysis phase.
| P0 | P1 | P2 | P3 | P4 | P5 | P6 | P7 |
|
|
| eBook 2: Implementing Business Continuity Management | ||||
| C1 | C2 | C3 | C4 | C5 |
| C6 | C7 | C8 | C9 | C10 |
To learn more about the course and schedule, click the buttons below for BCM-300 Business Continuity Management Implementer [BCM-3] and BCM-5000 Business Continuity Management Expert Implementer [BCM-5]
|
Please feel free to send us a note if you have any questions. |
||