Ebook

[BCM] [Damanat] [E2] [C4] [P2] Business Impact Analysis

Written by Dr Goh Moh Heng | Jul 20, 2026 9:41:33 AM

eBook 2: Chapter 4: Part 2

 Implementing the Business Impact Analysis Phase in the Saudi Mortgage Guarantees Services Company BCM Planning Methodology 

 

Introduction


This chapter is the 2nd instalment of the BIA planning process and will cover:

  • Part 4: Critical Business Function Catalogue.

  • Part 5: Sub-CBF Decomposition.

  • Part 6: Identifying Products, Services and Regulatory Outcomes.

Part 4: Confirming the Critical Business Functions

Following the approval of the Business Impact Analysis (BIA) scope, Damanat should confirm the catalogue of Critical Business Functions (CBFs) that will form the basis of the assessment.

A Critical Business Function is an activity whose disruption would significantly affect Damanat's ability to fulfil its statutory mandate, meet regulatory obligations, support Saudi Arabia's housing finance ecosystem, or maintain stakeholder confidence.

The confirmed CBF catalogue provides a consistent enterprise-wide framework for impact assessment, recovery prioritisation, dependency analysis and Business Continuity Strategy development.

The catalogue should be reviewed and approved by senior management before detailed impact assessments commence. T

he indicative criticality classifications shown below are illustrative only and require validation by Damanat through the BIA process.

Table BIA 4.1: Critical Business Function Catalogue for The Saudi Mortgage Guarantees Services Company (Damanat)

 

CBF Code Critical Business Function Primary Purpose Principal Regulatory or Organisational Outcome Indicative Criticality (Subject to Validation) Key CBF Owner / Functional Area Key Dependencies
CBF-1 Mortgage Guarantee Origination Receive, assess and approve mortgage guarantee applications Mortgage guarantee approval and housing finance support Time-Critical Mortgage Operations ICT, Credit Bureau, Financial Institutions
CBF-2 Guarantee Risk Assessment Assess guarantee exposure and financial risk Prudent guarantee underwriting Time-Critical Risk Management Risk Models, Data, ICT
CBF-3 Guarantee Issuance and Administration Issue and administer approved guarantees Accurate guarantee administration Highly Critical Guarantee Administration Document Management, ICT
CBF-4 Claims Assessment and Settlement Evaluate and settle guarantee claims Timely claims processing Highly Critical Claims Department Financial Institutions, Finance
CBF-5 Financial and Treasury Management Manage liquidity, accounting and financial reporting Financial sustainability Critical Finance Banking Partners, ERP
CBF-6 Enterprise Risk Management Monitor enterprise risks Risk governance Critical Enterprise Risk Business Units
CBF-7 Regulatory Compliance and Reporting Ensure compliance with SAMA and Insurance Authority requirements Regulatory compliance Highly Critical Compliance All Business Units
CBF-8 Information Technology Services Deliver enterprise ICT services Technology availability Time-Critical ICT Data Centre, Networks
CBF-9 Information Security and Cyber Resilience Protect information assets Cyber resilience Time-Critical Information Security SOC, Identity Management
CBF-10 Customer and Financial Institution Relationship Management Support financial institutions and stakeholders Customer confidence Critical Relationship Management CRM, Communications
CBF-11 Legal and Corporate Governance Provide legal advice and governance oversight Legal compliance Important Legal Executive Management
CBF-12 Human Resource Management Manage workforce capability Staff mobilisation Supporting Human Resources Payroll, HRIS
CBF-13 Procurement and Vendor Management Manage suppliers and contracts Supplier continuity Supporting Procurement Third-Party Providers
CBF-14 Corporate Communications and Stakeholder Management Manage internal and external communications Stakeholder confidence Critical Corporate Communications Communications Systems
CBF-15 Business Continuity and Crisis Management Coordinate organisational resilience and crisis response Enterprise resilience Highly Critical BCM Office Executive Management, ICT
Observations

The indicative assessment demonstrates that not all CBFs require the same recovery priority.

Functions directly supporting mortgage guarantee processing, technology availability and cybersecurity are likely to require the shortest recovery times because disruption would rapidly affect Damanat's core services.

Supporting functions such as Procurement and Human Resources remain essential but may tolerate longer interruptions provided they continue to support higher-priority operational functions.

Part 5: Decomposing Critical Business Functions into Sub-CBFs

Once the CBF catalogue has been confirmed, each function should be decomposed into manageable operational components known as Sub-Critical Business Functions (Sub-CBFs).

This decomposition enables the BIA to identify variations in recovery requirements within a single business function.

For example, within CBF-1 Mortgage Guarantee Origination, application intake, risk assessment and guarantee approval may require recovery within hours, whereas post-issuance quality assurance activities may tolerate a longer interruption.

 

Note to Reader: The detailed decomposition or breakdown of the critical business function, such as CBF-1 Mortgage Guarantee Origination, will be discussed in greater detail under CBF-1 in eBook 3.

Treating the entire CBF as a single activity would obscure these differences and lead to inefficient recovery planning.

Benefits of Sub-CBF Analysis

Breaking each CBF into its operational components enables Damanat to:

  • Differentiate recovery priorities within the same business function.
  • Identify technology dependencies at the process level.
  • Determine minimum staffing for each operational activity.
  • Assess differing statutory or contractual deadlines.
  • Identify manual workaround opportunities.
  • Determine suitable recovery locations.
  • Understand upstream and downstream process dependencies.
  • Develop more precise Business Continuity Plans.
Recommended Methodology

Damanat should adopt the following approach when decomposing each CBF:

  1. Confirm the purpose and boundaries of the CBF.
  2. Map the complete end-to-end workflow.
  3. Identify operational activities and key decision points.
  4. Separate activities with different recovery requirements.
  5. Identify enabling and supporting processes.
  6. Identify upstream and downstream dependencies.
  7. Assign ownership for each Sub-CBF.
  8. Validate the decomposition with the CBF Owner and relevant stakeholders.
Table BIA 4.2: Illustrative Sub-CBF Decomposition

 

CBF Code Critical Business Function Illustrative Sub-CBF Purpose Main Output Indicative Recovery Priority
CBF-1 Mortgage Guarantee Origination Mortgage Guarantee Application Intake Receive guarantee applications Registered applications Immediate
Mortgage Risk Assessment Assess guarantee risk Risk assessment decision Immediate
Guarantee Approval Approve eligible guarantees Approved guarantee Immediate
CBF-3 Guarantee Issuance and Administration Certificate Generation Produce guarantee certificates Guarantee certificate High
CBF-4 Claims Assessment and Settlement Claims Validation Verify submitted claims Validated claim High
CBF-5 Financial and Treasury Management Payment Processing Execute financial transactions Settled payments High
CBF-7 Regulatory Compliance and Reporting Regulatory Reporting Prepare mandatory reports Submitted regulatory reports High
CBF-8 Information Technology Services Infrastructure Operations Maintain ICT services Available ICT infrastructure Immediate
CBF-9 Information Security and Cyber Resilience Security Monitoring Detect cyber threats Security alerts Immediate
CBF-14 Corporate Communications and Stakeholder Management Stakeholder Communications Provide operational updates Stakeholder notifications High
CBF-15 Business Continuity and Crisis Management Crisis Coordination Coordinate organisational response Coordinated recovery activities Immediate

Note: The above examples are illustrative only. A complete Sub-CBF catalogue should be developed separately for every CBF to ensure comprehensive Business Impact Analysis and recovery planning.

Part 6: Identifying Products, Services and Organisational Outcomes

The Business Impact Analysis should not assess business processes in isolation. Instead, it should identify the products, services and organisational outcomes that each Critical Business Function delivers, together with the stakeholders who depend on those outcomes. This ensures that recovery priorities are based on the consequences of service disruption rather than the perceived importance of individual activities.

For Damanat, the principal products, services and outcomes generated by its Critical Business Functions include:

 

Critical Business Function Primary Products, Services or Outcomes Primary Recipients
Mortgage Guarantee Origination Approved mortgage guarantees Financial institutions, borrowers
Guarantee Risk Assessment Risk assessment decisions Internal management
Guarantee Issuance and Administration Guarantee certificates and administration Financial institutions
Claims Assessment and Settlement Claim settlement decisions Financial institutions
Financial and Treasury Management Financial reporting, payments and treasury operations Executive Management, regulators
Regulatory Compliance and Reporting Regulatory reports and compliance submissions SAMA, Insurance Authority
Information Technology Services ICT services All business units
Information Security and Cyber Resilience Cybersecurity protection Entire organisation
Customer and Financial Institution Relationship Management Stakeholder support and relationship management Financial institutions
Business Continuity and Crisis Management Coordinated crisis response and business recovery Executive Management

For each product or service, the BIA should determine:

  • The intended recipient or beneficiary.
  • Required delivery timeframe.
  • Applicable statutory or regulatory deadlines.
  • Minimum acceptable service level during disruption.
  • Consequences of delayed delivery.
  • Critical internal and external dependencies.
  • Available manual workarounds.
  • Expected backlog accumulation if the service is interrupted.

This analysis ensures that recovery priorities are aligned with Damanat's statutory responsibilities, contractual commitments and operational objectives, thereby providing a sound basis for the subsequent determination of impact criteria, disruption tolerances and recovery objectives.


The next instalment will cover:

  • Part 7: Identifying Impact Areas.
  • Part 8: Table BIA 4.3 – Illustrative BIA Impact Scale.
  • Part 9: Table BIA 4.4 – Impact-over-Time Assessment Template.

P0 P1 P2 P3 P4 P5 P6 P7

 

More Information About Business Continuity Management Courses

To learn more about the course and schedule, click the buttons below for the  BCM-300 Business Continuity Management Implementer [BCM-3] and the BCM-5000 Business Continuity Management Expert Implementer [BCM-5].

 

Please feel free to send us a note if you have any questions.