eBook 2: Chapter 4: Part 4
Implementing the Business Impact Analysis Phase in the Saudi Mortgage Guarantees Services Company BCM Planning Methodology
Introduction
![[BCM] [Damanat] [E2] [C4] [P4] Confirming the Critical Business Functions](https://no-cache.hubspot.com/cta/default/3893111/1729e39a-c267-4d7a-8282-0a30b44a296c.png)
This chapter is the 4th instalment of the BIA planning process and will cover:
-
Part 10: Determining the Maximum Tolerable Period of Disruption
-
Part 11: Determining Recovery Time Objectives
-
Part 12: Determining Recovery Point Objectives
-
Part 13: Establishing Minimum Business Continuity Objectives
Part 10: Determining the Maximum Tolerable Period of Disruption (MTPD)
The Maximum Tolerable Period of Disruption (MTPD) is the maximum duration a Critical Business Function (CBF) can remain unavailable before the consequences become unacceptable to Damanat. It establishes the outer limit of disruption tolerance and provides the basis for determining appropriate Recovery Time Objectives (RTOs).
Unlike the RTO, the MTPD does not represent the target recovery time. Instead, it defines the point beyond which Damanat would no longer be able to meet its statutory responsibilities, maintain stakeholder confidence, or operate within acceptable regulatory and business tolerances.
When determining the MTPD, Damanat should consider:
- Statutory and regulatory obligations.
- Public-interest responsibilities.
- Service commitments to financial institutions.
- Financial consequences.
- Accumulation of operational backlogs.
- Reputational consequences.
- Dependency failures.
- Technology constraints.
- Executive risk appetite.
The MTPD should never be selected solely because it is operationally convenient or aligns with existing recovery capabilities. It should reflect the point at which business impacts become unacceptable.
Table BIA 4.5: Indicative Maximum Tolerable Period of Disruption (MTPD)
Illustrative values only – subject to Business Impact Analysis validation and Senior Management approval.
| CBF Code | Critical Business Function | Indicative MTPD | Primary Impact Driving MTPD | Key Assumption | Validation Required |
|---|---|---|---|---|---|
| CBF-1 | Mortgage Guarantee Origination | 48 Hours | Operational backlog and stakeholder impact | Core ICT services recover within the target | Yes |
| CBF-2 | Guarantee Risk Assessment | 48 Hours | Credit risk exposure | Risk models available | Yes |
| CBF-3 | Guarantee Issuance and Administration | 72 Hours | Delayed guarantee issuance | Manual administration partially available | Yes |
| CBF-4 | Claims Assessment and Settlement | 5 Days | Customer and financial impact | Claims intake continues manually | Yes |
| CBF-5 | Financial and Treasury Management | 5 Days | Liquidity and financial control | Banking services remain available | Yes |
| CBF-6 | Enterprise Risk Management | 1 Week | Reduced enterprise oversight | Operational risk monitoring continues manually | Yes |
| CBF-7 | Regulatory Compliance and Reporting | 72 Hours | Regulatory obligations | Regulatory reporting deadlines unchanged | Yes |
| CBF-8 | Information Technology Services | 24 Hours | Enterprise ICT disruption | Disaster Recovery available | Yes |
| CBF-9 | Information Security and Cyber Resilience | 24 Hours | Cybersecurity exposure | Compensating controls activated | Yes |
| CBF-10 | Customer & Financial Institution Relationship Management | 72 Hours | Stakeholder confidence | Alternative communications available | Yes |
| CBF-11 | Legal and Corporate Governance | 5 Days | Governance decisions delayed | External legal support available | Yes |
| CBF-12 | Human Resource Management | 1 Week | Workforce administration | Manual HR processes available | Yes |
| CBF-13 | Procurement and Vendor Management | 1 Week | Supplier management delays | Existing contracts remain valid | Yes |
| CBF-14 | Corporate Communications and Stakeholder Management | 48 Hours | Reputational impact | Alternative communication channels available | Yes |
| CBF-15 | Business Continuity and Crisis Management | 24 Hours | Enterprise recovery coordination | Crisis team activated immediately | Yes |
Observations
The indicative MTPDs demonstrate that business functions supporting Damanat's core mortgage guarantee operations, ICT services and cybersecurity have significantly lower disruption tolerances than supporting administrative activities. This distinction enables management to prioritise recovery investments where they will provide the greatest organisational benefit.
Part 11: Determining Recovery Time Objectives (RTO)
The Recovery Time Objective (RTO) is the target time within which a Critical Business Function should be resumed at a predefined minimum service level following a disruption.
The RTO is one of the most important outputs of the Business Impact Analysis because it establishes the recovery target that Business Continuity Strategies, ICT Disaster Recovery capabilities and Business Continuity Plans must be designed to achieve.
Unlike the MTPD, which defines the maximum tolerable interruption, the RTO should provide sufficient time for recovery activities to stabilise operations before unacceptable impacts occur.
An effective RTO should be:
- Shorter than the applicable MTPD.
- Operationally achievable.
- Supported by ICT recovery capability.
- Based on business requirements rather than technology limitations.
- Validated through exercises and recovery testing.
- Approved by management.
Table BIA 4.6: Indicative Recovery Time Objectives for Damanat
Illustrative values only – subject to validation.
| CBF Code | Critical Business Function | Indicative RTO | Indicative MTPD | Minimum Service to be Resumed | Principal Dependency | RTO Rationale |
|---|---|---|---|---|---|---|
| CBF-1 | Mortgage Guarantee Origination | 12 Hours | 48 Hours | Priority mortgage guarantee processing | ICT, Credit Bureau | Prevent excessive application backlog |
| CBF-2 | Guarantee Risk Assessment | 12 Hours | 48 Hours | Priority guarantee assessments | Risk systems | Maintain underwriting capability |
| CBF-3 | Guarantee Issuance and Administration | 24 Hours | 72 Hours | Priority certificate issuance | Document management | Continue guarantee delivery |
| CBF-4 | Claims Assessment and Settlement | 24 Hours | 5 Days | Priority claims assessment | Claims system | Maintain financial obligations |
| CBF-5 | Financial and Treasury Management | 24 Hours | 5 Days | Essential financial processing | ERP, Banking | Preserve financial control |
| CBF-6 | Enterprise Risk Management | 48 Hours | 1 Week | Risk monitoring | Risk systems | Maintain governance |
| CBF-7 | Regulatory Compliance and Reporting | 24 Hours | 72 Hours | Mandatory regulatory reporting | Reporting systems | Meet supervisory expectations |
| CBF-8 | Information Technology Services | 8 Hours | 24 Hours | Core ICT services | Data Centre | Support all operational CBFs |
| CBF-9 | Information Security and Cyber Resilience | 4 Hours | 24 Hours | Cyber monitoring | SOC, Identity Services | Reduce cyber exposure |
| CBF-10 | Customer & Financial Institution Relationship Management | 24 Hours | 72 Hours | Priority stakeholder communications | CRM | Maintain confidence |
| CBF-11 | Legal and Corporate Governance | 48 Hours | 5 Days | Critical legal advice | Legal systems | Support executive decisions |
| CBF-12 | Human Resource Management | 72 Hours | 1 Week | Staff mobilisation | HRIS | Support recovery operations |
| CBF-13 | Procurement and Vendor Management | 72 Hours | 1 Week | Critical supplier support | Procurement system | Maintain supplier continuity |
| CBF-14 | Corporate Communications and Stakeholder Management | 12 Hours | 48 Hours | Emergency communications | Communications systems | Protect organisational reputation |
| CBF-15 | Business Continuity and Crisis Management | 2 Hours | 24 Hours | Crisis coordination | Executive Management | Coordinate enterprise recovery |
Alignment between Business and ICT Recovery
Business recovery objectives cannot be achieved unless supporting technology is restored first.
Consequently, ICT Disaster Recovery objectives should be derived from approved business RTOs rather than established independently.
For example:
- CBF-1 cannot resume within 12 hours if the Mortgage Guarantee Processing System requires 24 hours to recover.
- CBF-9 Information Security should recover before most operational functions because secure ICT services are a prerequisite for safe recovery.
- Business Continuity and Crisis Management should be operational within 2 hours to coordinate enterprise-wide recovery activities.
Accordingly, ICT recovery strategies, supplier service levels and infrastructure resilience should all be designed to support the approved business recovery objectives.
Part 12: Determining Recovery Point Objectives (RPO)
While the RTO addresses how quickly a business activity should be resumed, the Recovery Point Objective (RPO) addresses how much information loss is acceptable following a disruption.
The RPO is measured as the maximum acceptable period of data loss and is particularly relevant for information-intensive business activities and systems.
For Damanat, RPOs are especially important for systems that support mortgage guarantee processing, financial transactions, regulatory reporting, and cybersecurity. They should reflect:
- Transaction volumes.
- Business sensitivity of the information.
- Ability to reconstruct lost data.
- Legal and evidential requirements.
- Data integrity expectations.
- Backup and replication capability.
- Cost and operational impact of data loss.
Table BIA 4.7: Indicative Information Recovery Requirements
| Critical Business Function | Key Information or System | Indicative RPO | Data Loss Consequence | Reconstruction Capability | Validation Required |
|---|---|---|---|---|---|
| Mortgage Guarantee Origination | Mortgage Guarantee Processing System | 15 Minutes | Lost applications and transaction records | Limited | Yes |
| Guarantee Risk Assessment | Risk Assessment Database | 30 Minutes | Incomplete underwriting information | Moderate | Yes |
| Guarantee Issuance & Administration | Guarantee Register | 30 Minutes | Missing guarantee records | Moderate | Yes |
| Claims Assessment | Claims Database | 1 Hour | Delayed claims processing | Moderate | Yes |
| Financial & Treasury Management | Financial Transactions | 15 Minutes | Financial reconciliation issues | Low | Yes |
| Regulatory Compliance | Regulatory Reporting Database | 1 Hour | Inaccurate regulatory reporting | Moderate | Yes |
| Information Technology Services | Configuration Repository | 4 Hours | Delayed infrastructure recovery | High | Yes |
| Information Security | Security Logs and SIEM | Near Zero to 15 Minutes | Loss of forensic evidence | Very Limited | Yes |
| Customer Relationship Management | CRM Database | 1 Hour | Customer information loss | Moderate | Yes |
| Business Continuity & Crisis Management | Incident Management Records | 15 Minutes | Loss of crisis decision records | Limited | Yes |
Part 13: Establishing Minimum Business Continuity Objectives (MBCO)
The Minimum Business Continuity Objective (MBCO) defines the minimum acceptable level of products, services or activities that must continue during a disruption.
Unlike the RTO, which specifies when recovery should occur, the MBCO specifies what minimum level of service must be delivered while full operations are being restored.
The MBCO should be measurable and may be expressed in terms of:
- Percentage of normal operational capacity.
- Number of priority mortgage guarantee applications processed.
- Essential regulatory reporting obligations fulfilled.
- Minimum service hours maintained.
- Maximum acceptable backlog.
- Minimum staffing levels.
- Minimum ICT service availability.
Table BIA 4.8: Indicative Minimum Business Continuity Objectives
| CBF Code | Critical Business Function | Indicative MBCO | Priority Activities | Activities That May Be Deferred | Maximum Deferral Period | Validation Required |
|---|---|---|---|---|---|---|
| CBF-1 | Mortgage Guarantee Origination | Process 40% of priority applications | Priority mortgage guarantees | Non-urgent applications | 5 Days | Yes |
| CBF-2 | Guarantee Risk Assessment | Assess priority guarantees only | High-risk assessments | Low-risk reviews | 5 Days | Yes |
| CBF-3 | Guarantee Issuance & Administration | Issue approved priority guarantees | Priority certificates | Routine administrative updates | 1 Week | Yes |
| CBF-4 | Claims Assessment | Process urgent claims | High-priority settlements | Routine claims reviews | 1 Week | Yes |
| CBF-5 | Financial & Treasury Management | Maintain essential financial controls | Payments and liquidity | Non-essential reporting | 1 Week | Yes |
| CBF-6 | Enterprise Risk Management | Monitor significant enterprise risks | Executive reporting | Routine assessments | 2 Weeks | Yes |
| CBF-7 | Regulatory Compliance | Meet mandatory regulatory deadlines | Statutory reporting | Advisory activities | 1 Week | Yes |
| CBF-8 | Information Technology Services | Restore all critical business systems | Core infrastructure | Enhancement activities | 2 Weeks | Yes |
| CBF-9 | Information Security | Maintain continuous cyber monitoring | Threat detection | Improvement initiatives | 2 Weeks | Yes |
| CBF-10 | Customer & Financial Institution Relationship Management | Respond to priority stakeholder enquiries | Critical communications | Routine relationship activities | 1 Week | Yes |
| CBF-11 | Legal & Corporate Governance | Provide essential legal advice | Critical governance support | Routine legal reviews | 2 Weeks | Yes |
| CBF-12 | Human Resource Management | Support recovery staffing | Staff mobilisation | Routine HR administration | 2 Weeks | Yes |
| CBF-13 | Procurement & Vendor Management | Maintain critical supplier support | Emergency procurement | Strategic sourcing | 2 Weeks | Yes |
| CBF-14 | Corporate Communications | Issue essential communications | Crisis communications | Routine media activities | 1 Week | Yes |
| CBF-15 | Business Continuity & Crisis Management | Maintain full crisis coordination capability | Incident management | Programme improvement | Not Applicable | Yes |
Relationship Between MTPD, RTO, RPO and MBCO
The four key BIA outputs are complementary and support different management decisions:
- MTPD defines the maximum acceptable duration of disruption.
- RTO establishes the target time to restore a function before the MTPD is reached.
- RPO determines the maximum acceptable loss of information following disruption.
- MBCO specifies the minimum level of service that must be maintained during recovery.
Together, these outputs provide the foundation for developing recovery strategies, ICT Disaster Recovery capabilities and Business Continuity Plans that are aligned with Damanat's operational, regulatory and stakeholder requirements.
End of Part 4
The next instalment will cover:
- Part 14: Minimum Personnel Requirements (Table BIA 4.9)
- Part 15: Supporting Technology Requirements (Table BIA 4.10)
- Part 16: Vital Records and Information Requirements (Table BIA 4.11)
- Part 17: Internal CBF Dependency Matrix (Table BIA 4.12)
- Part 18: External Dependency Assessment (Table BIA 4.13)
- Part 19: Facility and Recovery-Location Requirements (Table BIA 4.14)
- Part 20: Manual Workaround Assessment (Table BIA 4.15)
To learn more about the course and schedule, click the buttons below for the BCM-300 Business Continuity Management Implementer [BCM-3] and the BCM-5000 Business Continuity Management Expert Implementer [BCM-5].


![[BCM] [Damanat] [Full Banner] Implementing BCM for The Saudi Mortgage Guarantees Services Company](https://no-cache.hubspot.com/cta/default/3893111/221734db-8c33-48bd-8147-fc740eecaf83.png)


![[BCM] [Damanat] [Full Banner] Guide to Implementing Business Impact Analysis](https://no-cache.hubspot.com/cta/default/3893111/8c9c1922-5a52-4f2f-9d38-6465514a7caf.png)
![Banner [Summary] [BCM] [E2] [C4] Business Impact Analysis](https://no-cache.hubspot.com/cta/default/3893111/3d259877-5780-4502-9473-1129f6d08a8c.png)

![[BCM] [Damanat] [3/4 Banner] Implementing BCM for The Saudi Mortgage Guarantees Services Company](https://no-cache.hubspot.com/cta/default/3893111/eb2678e7-9b23-4a73-827d-897c4b20315c.png)
![[BCM] [Damanat] [E2] [C4] [P0] Introduction](https://no-cache.hubspot.com/cta/default/3893111/cf1089fb-ba15-4935-bafe-d469db8b731b.png)
![[BCM] [Damanat] [E2] [C4] [P1] Position of BIA in the BCM Planning Methodology](https://no-cache.hubspot.com/cta/default/3893111/0ca2ca7d-0103-44fe-9d63-4bc2ed724444.png)
![[BCM] [Damanat] [E2] [C4] [P2] Establishing the BIA Governance Structure](https://no-cache.hubspot.com/cta/default/3893111/41158d1a-4d94-4fff-b5be-4e5866e18add.png)
![[BCM] [Damanat] [E2] [C4] [P3] Defining the BIA Scope](https://no-cache.hubspot.com/cta/default/3893111/357a1d12-62f0-467a-9b5b-881b817063c6.png)
![[BCM] [Damanat] [E2] [C4] [P5] Decomposing CBFs into Sub-CBFs](https://no-cache.hubspot.com/cta/default/3893111/9a19fac4-668e-41e2-b188-f08991e6097a.png)
![[BCM] [Damanat] [E2] [C4] [P6] Identifying Product, Services and Outcomes](https://no-cache.hubspot.com/cta/default/3893111/d6db6926-824a-4256-9c3b-f781422ce57e.png)
![[BCM] [Damanat] [E2] [C4] [P7] Identifying Impact Areas](https://no-cache.hubspot.com/cta/default/3893111/23e335dc-644f-4a06-bdde-067b828f8b55.png)


![Register [BL-B-3]*](https://no-cache.hubspot.com/cta/default/3893111/ac6cf073-4cdd-4541-91ed-889f731d5076.png)



![FAQ [BL-B-3]](https://no-cache.hubspot.com/cta/default/3893111/b3824ba1-7aa1-4eb6-bef8-94f57121c5ae.png)
![Email to Sales Team [BCM Institute]](https://no-cache.hubspot.com/cta/default/3893111/3c53daeb-2836-4843-b0e0-645baee2ab9e.png)





