This chapter is the 2nd instalment of the BIA planning process and will cover:
Part 4: Critical Business Function Catalogue.
Part 5: Sub-CBF Decomposition.
Part 6: Identifying Products, Services and Regulatory Outcomes.
Following the approval of the Business Impact Analysis (BIA) scope, Damanat should confirm the catalogue of Critical Business Functions (CBFs) that will form the basis of the assessment.
A Critical Business Function is an activity whose disruption would significantly affect Damanat's ability to fulfil its statutory mandate, meet regulatory obligations, support Saudi Arabia's housing finance ecosystem, or maintain stakeholder confidence.
The confirmed CBF catalogue provides a consistent enterprise-wide framework for impact assessment, recovery prioritisation, dependency analysis and Business Continuity Strategy development.
The catalogue should be reviewed and approved by senior management before detailed impact assessments commence. T
he indicative criticality classifications shown below are illustrative only and require validation by Damanat through the BIA process.
| CBF Code | Critical Business Function | Primary Purpose | Principal Regulatory or Organisational Outcome | Indicative Criticality (Subject to Validation) | Key CBF Owner / Functional Area | Key Dependencies |
|---|---|---|---|---|---|---|
| CBF-1 | Mortgage Guarantee Origination | Receive, assess and approve mortgage guarantee applications | Mortgage guarantee approval and housing finance support | Time-Critical | Mortgage Operations | ICT, Credit Bureau, Financial Institutions |
| CBF-2 | Guarantee Risk Assessment | Assess guarantee exposure and financial risk | Prudent guarantee underwriting | Time-Critical | Risk Management | Risk Models, Data, ICT |
| CBF-3 | Guarantee Issuance and Administration | Issue and administer approved guarantees | Accurate guarantee administration | Highly Critical | Guarantee Administration | Document Management, ICT |
| CBF-4 | Claims Assessment and Settlement | Evaluate and settle guarantee claims | Timely claims processing | Highly Critical | Claims Department | Financial Institutions, Finance |
| CBF-5 | Financial and Treasury Management | Manage liquidity, accounting and financial reporting | Financial sustainability | Critical | Finance | Banking Partners, ERP |
| CBF-6 | Enterprise Risk Management | Monitor enterprise risks | Risk governance | Critical | Enterprise Risk | Business Units |
| CBF-7 | Regulatory Compliance and Reporting | Ensure compliance with SAMA and Insurance Authority requirements | Regulatory compliance | Highly Critical | Compliance | All Business Units |
| CBF-8 | Information Technology Services | Deliver enterprise ICT services | Technology availability | Time-Critical | ICT | Data Centre, Networks |
| CBF-9 | Information Security and Cyber Resilience | Protect information assets | Cyber resilience | Time-Critical | Information Security | SOC, Identity Management |
| CBF-10 | Customer and Financial Institution Relationship Management | Support financial institutions and stakeholders | Customer confidence | Critical | Relationship Management | CRM, Communications |
| CBF-11 | Legal and Corporate Governance | Provide legal advice and governance oversight | Legal compliance | Important | Legal | Executive Management |
| CBF-12 | Human Resource Management | Manage workforce capability | Staff mobilisation | Supporting | Human Resources | Payroll, HRIS |
| CBF-13 | Procurement and Vendor Management | Manage suppliers and contracts | Supplier continuity | Supporting | Procurement | Third-Party Providers |
| CBF-14 | Corporate Communications and Stakeholder Management | Manage internal and external communications | Stakeholder confidence | Critical | Corporate Communications | Communications Systems |
| CBF-15 | Business Continuity and Crisis Management | Coordinate organisational resilience and crisis response | Enterprise resilience | Highly Critical | BCM Office | Executive Management, ICT |
The indicative assessment demonstrates that not all CBFs require the same recovery priority.
Functions directly supporting mortgage guarantee processing, technology availability and cybersecurity are likely to require the shortest recovery times because disruption would rapidly affect Damanat's core services.
Supporting functions such as Procurement and Human Resources remain essential but may tolerate longer interruptions provided they continue to support higher-priority operational functions.
Once the CBF catalogue has been confirmed, each function should be decomposed into manageable operational components known as Sub-Critical Business Functions (Sub-CBFs).
This decomposition enables the BIA to identify variations in recovery requirements within a single business function.
For example, within CBF-1 Mortgage Guarantee Origination, application intake, risk assessment and guarantee approval may require recovery within hours, whereas post-issuance quality assurance activities may tolerate a longer interruption.
Note to Reader: The detailed decomposition or breakdown of the critical business function, such as CBF-1 Mortgage Guarantee Origination, will be discussed in greater detail under CBF-1 in eBook 3.
Treating the entire CBF as a single activity would obscure these differences and lead to inefficient recovery planning.
Breaking each CBF into its operational components enables Damanat to:
Damanat should adopt the following approach when decomposing each CBF:
| CBF Code | Critical Business Function | Illustrative Sub-CBF | Purpose | Main Output | Indicative Recovery Priority |
|---|---|---|---|---|---|
| CBF-1 | Mortgage Guarantee Origination | Mortgage Guarantee Application Intake | Receive guarantee applications | Registered applications | Immediate |
| Mortgage Risk Assessment | Assess guarantee risk | Risk assessment decision | Immediate | ||
| Guarantee Approval | Approve eligible guarantees | Approved guarantee | Immediate | ||
| CBF-3 | Guarantee Issuance and Administration | Certificate Generation | Produce guarantee certificates | Guarantee certificate | High |
| CBF-4 | Claims Assessment and Settlement | Claims Validation | Verify submitted claims | Validated claim | High |
| CBF-5 | Financial and Treasury Management | Payment Processing | Execute financial transactions | Settled payments | High |
| CBF-7 | Regulatory Compliance and Reporting | Regulatory Reporting | Prepare mandatory reports | Submitted regulatory reports | High |
| CBF-8 | Information Technology Services | Infrastructure Operations | Maintain ICT services | Available ICT infrastructure | Immediate |
| CBF-9 | Information Security and Cyber Resilience | Security Monitoring | Detect cyber threats | Security alerts | Immediate |
| CBF-14 | Corporate Communications and Stakeholder Management | Stakeholder Communications | Provide operational updates | Stakeholder notifications | High |
| CBF-15 | Business Continuity and Crisis Management | Crisis Coordination | Coordinate organisational response | Coordinated recovery activities | Immediate |
Note: The above examples are illustrative only. A complete Sub-CBF catalogue should be developed separately for every CBF to ensure comprehensive Business Impact Analysis and recovery planning.
The Business Impact Analysis should not assess business processes in isolation. Instead, it should identify the products, services and organisational outcomes that each Critical Business Function delivers, together with the stakeholders who depend on those outcomes. This ensures that recovery priorities are based on the consequences of service disruption rather than the perceived importance of individual activities.
For Damanat, the principal products, services and outcomes generated by its Critical Business Functions include:
| Critical Business Function | Primary Products, Services or Outcomes | Primary Recipients |
|---|---|---|
| Mortgage Guarantee Origination | Approved mortgage guarantees | Financial institutions, borrowers |
| Guarantee Risk Assessment | Risk assessment decisions | Internal management |
| Guarantee Issuance and Administration | Guarantee certificates and administration | Financial institutions |
| Claims Assessment and Settlement | Claim settlement decisions | Financial institutions |
| Financial and Treasury Management | Financial reporting, payments and treasury operations | Executive Management, regulators |
| Regulatory Compliance and Reporting | Regulatory reports and compliance submissions | SAMA, Insurance Authority |
| Information Technology Services | ICT services | All business units |
| Information Security and Cyber Resilience | Cybersecurity protection | Entire organisation |
| Customer and Financial Institution Relationship Management | Stakeholder support and relationship management | Financial institutions |
| Business Continuity and Crisis Management | Coordinated crisis response and business recovery | Executive Management |
For each product or service, the BIA should determine:
This analysis ensures that recovery priorities are aligned with Damanat's statutory responsibilities, contractual commitments and operational objectives, thereby providing a sound basis for the subsequent determination of impact criteria, disruption tolerances and recovery objectives.
The next instalment will cover:
| P0 | P1 | P2 | P3 | P4 | P5 | P6 | P7 |
|
|
To learn more about the course and schedule, click the buttons below for the BCM-300 Business Continuity Management Implementer [BCM-3] and the BCM-5000 Business Continuity Management Expert Implementer [BCM-5].
|
Please feel free to send us a note if you have any questions. |
||