Ebook

[BCM] [Damanat] [E2] [C4] [P4] Business Impact Analysis

Written by Dr Goh Moh Heng | Jul 20, 2026 9:43:55 AM

eBook 2: Chapter 4: Part 4

 Implementing the Business Impact Analysis Phase in the Saudi Mortgage Guarantees Services Company BCM Planning Methodology 

 

Introduction


This chapter is the 4th instalment of the BIA planning process and will cover:

  • Part 10: Determining the Maximum Tolerable Period of Disruption

  • Part 11: Determining Recovery Time Objectives

  • Part 12: Determining Recovery Point Objectives

  • Part 13: Establishing Minimum Business Continuity Objectives

Part 10: Determining the Maximum Tolerable Period of Disruption (MTPD)

The Maximum Tolerable Period of Disruption (MTPD) is the maximum duration a Critical Business Function (CBF) can remain unavailable before the consequences become unacceptable to Damanat. It establishes the outer limit of disruption tolerance and provides the basis for determining appropriate Recovery Time Objectives (RTOs).

Unlike the RTO, the MTPD does not represent the target recovery time. Instead, it defines the point beyond which Damanat would no longer be able to meet its statutory responsibilities, maintain stakeholder confidence, or operate within acceptable regulatory and business tolerances.

When determining the MTPD, Damanat should consider:

  • Statutory and regulatory obligations.
  • Public-interest responsibilities.
  • Service commitments to financial institutions.
  • Financial consequences.
  • Accumulation of operational backlogs.
  • Reputational consequences.
  • Dependency failures.
  • Technology constraints.
  • Executive risk appetite.

The MTPD should never be selected solely because it is operationally convenient or aligns with existing recovery capabilities. It should reflect the point at which business impacts become unacceptable.

Table BIA 4.5: Indicative Maximum Tolerable Period of Disruption (MTPD)

Illustrative values only – subject to Business Impact Analysis validation and Senior Management approval.

CBF Code Critical Business Function Indicative MTPD Primary Impact Driving MTPD Key Assumption Validation Required
CBF-1 Mortgage Guarantee Origination 48 Hours Operational backlog and stakeholder impact Core ICT services recover within the target Yes
CBF-2 Guarantee Risk Assessment 48 Hours Credit risk exposure Risk models available Yes
CBF-3 Guarantee Issuance and Administration 72 Hours Delayed guarantee issuance Manual administration partially available Yes
CBF-4 Claims Assessment and Settlement 5 Days Customer and financial impact Claims intake continues manually Yes
CBF-5 Financial and Treasury Management 5 Days Liquidity and financial control Banking services remain available Yes
CBF-6 Enterprise Risk Management 1 Week Reduced enterprise oversight Operational risk monitoring continues manually Yes
CBF-7 Regulatory Compliance and Reporting 72 Hours Regulatory obligations Regulatory reporting deadlines unchanged Yes
CBF-8 Information Technology Services 24 Hours Enterprise ICT disruption Disaster Recovery available Yes
CBF-9 Information Security and Cyber Resilience 24 Hours Cybersecurity exposure Compensating controls activated Yes
CBF-10 Customer & Financial Institution Relationship Management 72 Hours Stakeholder confidence Alternative communications available Yes
CBF-11 Legal and Corporate Governance 5 Days Governance decisions delayed External legal support available Yes
CBF-12 Human Resource Management 1 Week Workforce administration Manual HR processes available Yes
CBF-13 Procurement and Vendor Management 1 Week Supplier management delays Existing contracts remain valid Yes
CBF-14 Corporate Communications and Stakeholder Management 48 Hours Reputational impact Alternative communication channels available Yes
CBF-15 Business Continuity and Crisis Management 24 Hours Enterprise recovery coordination Crisis team activated immediately Yes
Observations

The indicative MTPDs demonstrate that business functions supporting Damanat's core mortgage guarantee operations, ICT services and cybersecurity have significantly lower disruption tolerances than supporting administrative activities. This distinction enables management to prioritise recovery investments where they will provide the greatest organisational benefit.

 

Part 11: Determining Recovery Time Objectives (RTO)

The Recovery Time Objective (RTO) is the target time within which a Critical Business Function should be resumed at a predefined minimum service level following a disruption.

The RTO is one of the most important outputs of the Business Impact Analysis because it establishes the recovery target that Business Continuity Strategies, ICT Disaster Recovery capabilities and Business Continuity Plans must be designed to achieve.

Unlike the MTPD, which defines the maximum tolerable interruption, the RTO should provide sufficient time for recovery activities to stabilise operations before unacceptable impacts occur.

An effective RTO should be:

  • Shorter than the applicable MTPD.
  • Operationally achievable.
  • Supported by ICT recovery capability.
  • Based on business requirements rather than technology limitations.
  • Validated through exercises and recovery testing.
  • Approved by management.
Table BIA 4.6: Indicative Recovery Time Objectives for Damanat

Illustrative values only – subject to validation.

CBF Code Critical Business Function Indicative RTO Indicative MTPD Minimum Service to be Resumed Principal Dependency RTO Rationale
CBF-1 Mortgage Guarantee Origination 12 Hours 48 Hours Priority mortgage guarantee processing ICT, Credit Bureau Prevent excessive application backlog
CBF-2 Guarantee Risk Assessment 12 Hours 48 Hours Priority guarantee assessments Risk systems Maintain underwriting capability
CBF-3 Guarantee Issuance and Administration 24 Hours 72 Hours Priority certificate issuance Document management Continue guarantee delivery
CBF-4 Claims Assessment and Settlement 24 Hours 5 Days Priority claims assessment Claims system Maintain financial obligations
CBF-5 Financial and Treasury Management 24 Hours 5 Days Essential financial processing ERP, Banking Preserve financial control
CBF-6 Enterprise Risk Management 48 Hours 1 Week Risk monitoring Risk systems Maintain governance
CBF-7 Regulatory Compliance and Reporting 24 Hours 72 Hours Mandatory regulatory reporting Reporting systems Meet supervisory expectations
CBF-8 Information Technology Services 8 Hours 24 Hours Core ICT services Data Centre Support all operational CBFs
CBF-9 Information Security and Cyber Resilience 4 Hours 24 Hours Cyber monitoring SOC, Identity Services Reduce cyber exposure
CBF-10 Customer & Financial Institution Relationship Management 24 Hours 72 Hours Priority stakeholder communications CRM Maintain confidence
CBF-11 Legal and Corporate Governance 48 Hours 5 Days Critical legal advice Legal systems Support executive decisions
CBF-12 Human Resource Management 72 Hours 1 Week Staff mobilisation HRIS Support recovery operations
CBF-13 Procurement and Vendor Management 72 Hours 1 Week Critical supplier support Procurement system Maintain supplier continuity
CBF-14 Corporate Communications and Stakeholder Management 12 Hours 48 Hours Emergency communications Communications systems Protect organisational reputation
CBF-15 Business Continuity and Crisis Management 2 Hours 24 Hours Crisis coordination Executive Management Coordinate enterprise recovery
Alignment between Business and ICT Recovery

Business recovery objectives cannot be achieved unless supporting technology is restored first.

Consequently, ICT Disaster Recovery objectives should be derived from approved business RTOs rather than established independently.

For example:

  • CBF-1 cannot resume within 12 hours if the Mortgage Guarantee Processing System requires 24 hours to recover.
  • CBF-9 Information Security should recover before most operational functions because secure ICT services are a prerequisite for safe recovery.
  • Business Continuity and Crisis Management should be operational within 2 hours to coordinate enterprise-wide recovery activities.

Accordingly, ICT recovery strategies, supplier service levels and infrastructure resilience should all be designed to support the approved business recovery objectives.

Part 12: Determining Recovery Point Objectives (RPO)

While the RTO addresses how quickly a business activity should be resumed, the Recovery Point Objective (RPO) addresses how much information loss is acceptable following a disruption.

The RPO is measured as the maximum acceptable period of data loss and is particularly relevant for information-intensive business activities and systems.

For Damanat, RPOs are especially important for systems that support mortgage guarantee processing, financial transactions, regulatory reporting, and cybersecurity. They should reflect:

  • Transaction volumes.
  • Business sensitivity of the information.
  • Ability to reconstruct lost data.
  • Legal and evidential requirements.
  • Data integrity expectations.
  • Backup and replication capability.
  • Cost and operational impact of data loss.
Table BIA 4.7: Indicative Information Recovery Requirements
Critical Business Function Key Information or System Indicative RPO Data Loss Consequence Reconstruction Capability Validation Required
Mortgage Guarantee Origination Mortgage Guarantee Processing System 15 Minutes Lost applications and transaction records Limited Yes
Guarantee Risk Assessment Risk Assessment Database 30 Minutes Incomplete underwriting information Moderate Yes
Guarantee Issuance & Administration Guarantee Register 30 Minutes Missing guarantee records Moderate Yes
Claims Assessment Claims Database 1 Hour Delayed claims processing Moderate Yes
Financial & Treasury Management Financial Transactions 15 Minutes Financial reconciliation issues Low Yes
Regulatory Compliance Regulatory Reporting Database 1 Hour Inaccurate regulatory reporting Moderate Yes
Information Technology Services Configuration Repository 4 Hours Delayed infrastructure recovery High Yes
Information Security Security Logs and SIEM Near Zero to 15 Minutes Loss of forensic evidence Very Limited Yes
Customer Relationship Management CRM Database 1 Hour Customer information loss Moderate Yes
Business Continuity & Crisis Management Incident Management Records 15 Minutes Loss of crisis decision records Limited Yes

Part 13: Establishing Minimum Business Continuity Objectives (MBCO)

The Minimum Business Continuity Objective (MBCO) defines the minimum acceptable level of products, services or activities that must continue during a disruption.

Unlike the RTO, which specifies when recovery should occur, the MBCO specifies what minimum level of service must be delivered while full operations are being restored.

The MBCO should be measurable and may be expressed in terms of:

  • Percentage of normal operational capacity.
  • Number of priority mortgage guarantee applications processed.
  • Essential regulatory reporting obligations fulfilled.
  • Minimum service hours maintained.
  • Maximum acceptable backlog.
  • Minimum staffing levels.
  • Minimum ICT service availability.
Table BIA 4.8: Indicative Minimum Business Continuity Objectives
CBF Code Critical Business Function Indicative MBCO Priority Activities Activities That May Be Deferred Maximum Deferral Period Validation Required
CBF-1 Mortgage Guarantee Origination Process 40% of priority applications Priority mortgage guarantees Non-urgent applications 5 Days Yes
CBF-2 Guarantee Risk Assessment Assess priority guarantees only High-risk assessments Low-risk reviews 5 Days Yes
CBF-3 Guarantee Issuance & Administration Issue approved priority guarantees Priority certificates Routine administrative updates 1 Week Yes
CBF-4 Claims Assessment Process urgent claims High-priority settlements Routine claims reviews 1 Week Yes
CBF-5 Financial & Treasury Management Maintain essential financial controls Payments and liquidity Non-essential reporting 1 Week Yes
CBF-6 Enterprise Risk Management Monitor significant enterprise risks Executive reporting Routine assessments 2 Weeks Yes
CBF-7 Regulatory Compliance Meet mandatory regulatory deadlines Statutory reporting Advisory activities 1 Week Yes
CBF-8 Information Technology Services Restore all critical business systems Core infrastructure Enhancement activities 2 Weeks Yes
CBF-9 Information Security Maintain continuous cyber monitoring Threat detection Improvement initiatives 2 Weeks Yes
CBF-10 Customer & Financial Institution Relationship Management Respond to priority stakeholder enquiries Critical communications Routine relationship activities 1 Week Yes
CBF-11 Legal & Corporate Governance Provide essential legal advice Critical governance support Routine legal reviews 2 Weeks Yes
CBF-12 Human Resource Management Support recovery staffing Staff mobilisation Routine HR administration 2 Weeks Yes
CBF-13 Procurement & Vendor Management Maintain critical supplier support Emergency procurement Strategic sourcing 2 Weeks Yes
CBF-14 Corporate Communications Issue essential communications Crisis communications Routine media activities 1 Week Yes
CBF-15 Business Continuity & Crisis Management Maintain full crisis coordination capability Incident management Programme improvement Not Applicable Yes
Relationship Between MTPD, RTO, RPO and MBCO

The four key BIA outputs are complementary and support different management decisions:

  • MTPD defines the maximum acceptable duration of disruption.
  • RTO establishes the target time to restore a function before the MTPD is reached.
  • RPO determines the maximum acceptable loss of information following disruption.
  • MBCO specifies the minimum level of service that must be maintained during recovery.

Together, these outputs provide the foundation for developing recovery strategies, ICT Disaster Recovery capabilities and Business Continuity Plans that are aligned with Damanat's operational, regulatory and stakeholder requirements.



End of Part 4

The next instalment will cover:

  • Part 14: Minimum Personnel Requirements (Table BIA 4.9)
  • Part 15: Supporting Technology Requirements (Table BIA 4.10)
  • Part 16: Vital Records and Information Requirements (Table BIA 4.11)
  • Part 17: Internal CBF Dependency Matrix (Table BIA 4.12)
  • Part 18: External Dependency Assessment (Table BIA 4.13)
  • Part 19: Facility and Recovery-Location Requirements (Table BIA 4.14)
  • Part 20: Manual Workaround Assessment (Table BIA 4.15)

P0 P1 P2 P3 P4 P5 P6 P7

 More Information About Business Continuity Management Courses

To learn more about the course and schedule, click the buttons below for the  BCM-300 Business Continuity Management Implementer [BCM-3] and the BCM-5000 Business Continuity Management Expert Implementer [BCM-5].

 

Please feel free to send us a note if you have any questions.