Ebook

[BCM] [Damanat] [E2] [C4] [P1] Business Impact Analysis

Written by Dr Goh Moh Heng | Jul 20, 2026 9:40:57 AM

eBook 2: Chapter 4: Part 1

 Implementing the Business Impact Analysis Phase in the Saudi Mortgage Guarantees Services Company BCM Planning Methodology 

Introduction

This chapter is the 1st instalment of the BIA planning process and will cover:

  • Part 1: Position of BIA in BCM Planning Methodology

  • Part 2: BIA Governance Structure

  • Part 3: Defining the BIA Scope

 

Part 1: Position of the Business Impact Analysis within the BCM Planning Methodology

The Business Continuity Management Planning Methodology comprises a sequence of interrelated phases that collectively enable an organisation to establish, implement, maintain and continually improve its Business Continuity Management capability.

The Business Impact Analysis occupies the central analytical position within this methodology because it translates organisational knowledge into measurable recovery requirements that guide all subsequent continuity planning activities.

The relationship between the principal phases can be summarised as follows.

 

BCM Phase

Primary Purpose

Principal Output

Project Management

Establish governance, scope, resources and implementation approach

Approved BCM project

Risk Assessment

Identify threats, vulnerabilities and existing controls

Enterprise risk profile

Business Impact Analysis

Assess the consequences of disruption and determine recovery requirements

Approved recovery requirements

Business Continuity Strategy

Select practical recovery solutions

Recovery strategies

Plan Development

Document operational recovery procedures

Business Continuity Plans

Testing and Exercising

Validate strategies and plans

Improvement actions

Programme Management

Maintain and improve the BCM programme

Continual improvement

Each phase depends upon information generated during earlier activities.

Project Management establishes governance and defines the scope of the BCM initiative. Risk Assessment provides an understanding of the threats and vulnerabilities facing Damanat, but it does not determine recovery priorities.

The BIA builds upon this information by evaluating how disruption affects each Critical Business Function over time and by identifying the operational capability required to resume those functions before impacts become unacceptable.

Business Continuity Strategy then uses the approved BIA outputs to determine how the identified recovery requirements will be achieved.

These strategies are translated into detailed Business Continuity Plans that specify the operational procedures required during an actual disruption.

Testing and exercising validate whether those strategies and plans can achieve the approved recovery objectives. Programme Management subsequently maintains all BIA information, ensuring that recovery requirements remain aligned with organisational changes.

Inputs Required Before Conducting the BIA

Before commencing the BIA, Damanat should confirm that the following information has been assembled and validated:

 

Required Input

Purpose within the BIA

Approved BCM Scope

Defines organisational coverage

Organisation Structure

Identifies accountable business units

Critical Business Function Catalogue

Establishes assessment scope

Business Process Documentation

Supports process decomposition

Risk Assessment Results

Provides disruption context

Service Commitments

Identifies delivery expectations

Statutory and Regulatory Obligations

Determines mandatory outcomes

Stakeholder Requirements

Establishes service expectations

Historical Incident Information

Supports realistic assumptions

Existing Recovery Arrangements

Identifies current capabilities

ICT Architecture

Determines technology dependencies

Supplier Information

Identifies external dependencies

Expected Outputs of the BIA

Upon completion, the BIA should produce a comprehensive set of management-approved outputs that support all subsequent BCM activities.

These include:

  • Validated Critical Business Function catalogue.
  • Validated Sub-CBF inventory.
  • Impact assessments across multiple impact categories.
  • Impact-over-time analysis.
  • Indicative Maximum Tolerable Periods of Disruption (MTPDs).
  • Indicative Recovery Time Objectives (RTOs).
  • Recovery Point Objectives (where applicable).
  • Minimum Business Continuity Objectives (MBCOs).
  • Recovery priorities.
  • Internal and external dependency registers.
  • Minimum resource requirements.
  • Vital records inventory.
  • Supporting systems inventory.
  • Management-approved recovery requirements.

Collectively, these outputs provide the evidence base required to design recovery strategies that are proportionate to the actual consequences of disruption rather than assumptions or historical practices.

Part 2: Establishing the BIA Governance Structure

An effective Business Impact Analysis requires strong governance to ensure that recovery priorities reflect organisational objectives, statutory responsibilities and operational realities.

Governance also promotes consistency, transparency and management accountability throughout the assessment process.

Senior Management

Senior Management provides executive sponsorship and retains overall accountability for the BIA. Their responsibilities include:

  • Approving the BIA methodology.
  • Endorsing impact assessment criteria.
  • Defining organisational disruption tolerance.
  • Resolving disagreements between CBF owners.
  • Approving enterprise recovery priorities.
  • Authorising significant resource investments.
  • Accepting justified recovery gaps.
  • Providing final management approval of BIA outputs.
BCM Steering Committee

The BCM Steering Committee provides strategic oversight and cross-functional coordination.

Its responsibilities include:

  • Monitoring BIA progress.
  • Reviewing assessment consistency.
  • Challenging assumptions.
  • Resolving cross-functional dependency issues.
  • Reviewing enterprise-wide recovery priorities.
  • Endorsing completed BIA findings.
  • Monitoring corrective actions arising from the BIA.
BCM Manager or BCM Coordinator

The BCM Manager is responsible for planning and coordinating the entire BIA exercise.

Typical responsibilities include:

  • Developing the BIA methodology and templates.
  • Planning interviews and workshops.
  • Facilitating assessments.
  • Maintaining consistency across business units.
  • Challenging incomplete responses.
  • Consolidating assessment results.
  • Preparing management reports.
  • Maintaining the central BIA repository.
Critical Business Function Owners

Each CBF Owner is responsible for validating the operational content of the assessment.

Responsibilities include:

  • Confirming the purpose of the CBF.
  • Validating Sub-CBF decomposition.
  • Assessing business impacts.
  • Proposing recovery requirements.
  • Identifying dependencies.
  • Determining minimum service levels.
  • Confirming operational assumptions.
  • Approving completed BIA submissions.
Sub-CBF or Process Owners

Operational managers provide the detailed information necessary for accurate analysis.

Typical responsibilities include:

  • Documenting business activities.
  • Confirming process dependencies.
  • Identifying essential systems and records.
  • Assessing manual workaround capability.
  • Estimating backlog accumulation.
  • Validating operational recovery assumptions.
Specialist Support Functions

Several corporate functions should participate in validating specialist assumptions.

 

Function

Primary Contribution

ICT

Technology dependencies and recovery capability

Cybersecurity

Security controls and cyber resilience

Human Resources

Staffing, succession and mobilisation

Facilities

Recovery of workplaces and infrastructure

Finance

Financial impacts and recovery funding

Procurement

Supplier continuity arrangements

Legal

Statutory obligations and legal impacts

Compliance

Regulatory obligations

Records Management

Vital records and information governance

Communications

Stakeholder communications

Security

Physical security arrangements

Third-Party Risk Management

Supplier dependency validation

These specialist functions ensure that business assumptions are technically feasible, legally compliant and operationally achievable before they are approved.

Part 3: Defining the Scope of the Business Impact Analysis

The scope of the Business Impact Analysis should encompass all activities necessary for Damanat to fulfil its statutory responsibilities and deliver essential mortgage guarantee services. Defining an appropriate scope is fundamental because incomplete coverage may result in critical recovery requirements being overlooked.

The BIA should include:

  • All approved Critical Business Functions.
  • Supporting Sub-CBFs and operational processes.
  • Mortgage guarantee products and services.
  • Business units and functional departments.
  • Offices and operational locations.
  • Personnel and specialist competencies.
  • Premises and recovery facilities.
  • ICT systems and applications.
  • Information assets and vital records.
  • Internal support services.
  • Third-party suppliers.
  • Financial institutions.
  • Government agencies.
  • Communications channels.
  • Statutory and regulatory obligations.

When determining whether a process falls within the BIA scope, Damanat should consider whether disruption would:

  • Affect statutory responsibilities.
  • Prevent delivery of mortgage guarantee services.
  • Delay regulatory or contractual commitments.
  • Affect financial institutions or borrowers.
  • Interrupt executive decision-making.
  • Create significant legal, financial or reputational consequences.
  • Prevent other Critical Business Functions from operating.
  • Support ICT, information management or corporate governance.

Not every function requires the same recovery priority. The purpose of the BIA is to identify those differences objectively so that recovery resources are directed first toward the activities that have the greatest organisational, regulatory and stakeholder consequences if disrupted.

 

The next instalment will cover:

  • Part 4: Critical Business Function Catalogue.

  • Part 5: Sub-CBF Decomposition.

  • Part 6: Identifying Products, Services and Regulatory Outcomes.

P0 P1 P2 P3 P4 P5 P6 P7

 

More Information About Business Continuity Management Courses

To learn more about the course and schedule, click the buttons below for the  BCM-300 Business Continuity Management Implementer [BCM-3] and the BCM-5000 Business Continuity Management Expert Implementer [BCM-5].

 

Please feel free to send us a note if you have any questions.