This chapter is the 4th instalment of the BIA planning process and will cover:
Part 10: Determining the Maximum Tolerable Period of Disruption
Part 11: Determining Recovery Time Objectives
Part 12: Determining Recovery Point Objectives
Part 13: Establishing Minimum Business Continuity Objectives
The Maximum Tolerable Period of Disruption (MTPD) is the maximum duration a Critical Business Function (CBF) can remain unavailable before the consequences become unacceptable to Damanat. It establishes the outer limit of disruption tolerance and provides the basis for determining appropriate Recovery Time Objectives (RTOs).
Unlike the RTO, the MTPD does not represent the target recovery time. Instead, it defines the point beyond which Damanat would no longer be able to meet its statutory responsibilities, maintain stakeholder confidence, or operate within acceptable regulatory and business tolerances.
When determining the MTPD, Damanat should consider:
The MTPD should never be selected solely because it is operationally convenient or aligns with existing recovery capabilities. It should reflect the point at which business impacts become unacceptable.
Illustrative values only – subject to Business Impact Analysis validation and Senior Management approval.
| CBF Code | Critical Business Function | Indicative MTPD | Primary Impact Driving MTPD | Key Assumption | Validation Required |
|---|---|---|---|---|---|
| CBF-1 | Mortgage Guarantee Origination | 48 Hours | Operational backlog and stakeholder impact | Core ICT services recover within the target | Yes |
| CBF-2 | Guarantee Risk Assessment | 48 Hours | Credit risk exposure | Risk models available | Yes |
| CBF-3 | Guarantee Issuance and Administration | 72 Hours | Delayed guarantee issuance | Manual administration partially available | Yes |
| CBF-4 | Claims Assessment and Settlement | 5 Days | Customer and financial impact | Claims intake continues manually | Yes |
| CBF-5 | Financial and Treasury Management | 5 Days | Liquidity and financial control | Banking services remain available | Yes |
| CBF-6 | Enterprise Risk Management | 1 Week | Reduced enterprise oversight | Operational risk monitoring continues manually | Yes |
| CBF-7 | Regulatory Compliance and Reporting | 72 Hours | Regulatory obligations | Regulatory reporting deadlines unchanged | Yes |
| CBF-8 | Information Technology Services | 24 Hours | Enterprise ICT disruption | Disaster Recovery available | Yes |
| CBF-9 | Information Security and Cyber Resilience | 24 Hours | Cybersecurity exposure | Compensating controls activated | Yes |
| CBF-10 | Customer & Financial Institution Relationship Management | 72 Hours | Stakeholder confidence | Alternative communications available | Yes |
| CBF-11 | Legal and Corporate Governance | 5 Days | Governance decisions delayed | External legal support available | Yes |
| CBF-12 | Human Resource Management | 1 Week | Workforce administration | Manual HR processes available | Yes |
| CBF-13 | Procurement and Vendor Management | 1 Week | Supplier management delays | Existing contracts remain valid | Yes |
| CBF-14 | Corporate Communications and Stakeholder Management | 48 Hours | Reputational impact | Alternative communication channels available | Yes |
| CBF-15 | Business Continuity and Crisis Management | 24 Hours | Enterprise recovery coordination | Crisis team activated immediately | Yes |
The indicative MTPDs demonstrate that business functions supporting Damanat's core mortgage guarantee operations, ICT services and cybersecurity have significantly lower disruption tolerances than supporting administrative activities. This distinction enables management to prioritise recovery investments where they will provide the greatest organisational benefit.
The RTO is one of the most important outputs of the Business Impact Analysis because it establishes the recovery target that Business Continuity Strategies, ICT Disaster Recovery capabilities and Business Continuity Plans must be designed to achieve.
Unlike the MTPD, which defines the maximum tolerable interruption, the RTO should provide sufficient time for recovery activities to stabilise operations before unacceptable impacts occur.
An effective RTO should be:
Illustrative values only – subject to validation.
| CBF Code | Critical Business Function | Indicative RTO | Indicative MTPD | Minimum Service to be Resumed | Principal Dependency | RTO Rationale |
|---|---|---|---|---|---|---|
| CBF-1 | Mortgage Guarantee Origination | 12 Hours | 48 Hours | Priority mortgage guarantee processing | ICT, Credit Bureau | Prevent excessive application backlog |
| CBF-2 | Guarantee Risk Assessment | 12 Hours | 48 Hours | Priority guarantee assessments | Risk systems | Maintain underwriting capability |
| CBF-3 | Guarantee Issuance and Administration | 24 Hours | 72 Hours | Priority certificate issuance | Document management | Continue guarantee delivery |
| CBF-4 | Claims Assessment and Settlement | 24 Hours | 5 Days | Priority claims assessment | Claims system | Maintain financial obligations |
| CBF-5 | Financial and Treasury Management | 24 Hours | 5 Days | Essential financial processing | ERP, Banking | Preserve financial control |
| CBF-6 | Enterprise Risk Management | 48 Hours | 1 Week | Risk monitoring | Risk systems | Maintain governance |
| CBF-7 | Regulatory Compliance and Reporting | 24 Hours | 72 Hours | Mandatory regulatory reporting | Reporting systems | Meet supervisory expectations |
| CBF-8 | Information Technology Services | 8 Hours | 24 Hours | Core ICT services | Data Centre | Support all operational CBFs |
| CBF-9 | Information Security and Cyber Resilience | 4 Hours | 24 Hours | Cyber monitoring | SOC, Identity Services | Reduce cyber exposure |
| CBF-10 | Customer & Financial Institution Relationship Management | 24 Hours | 72 Hours | Priority stakeholder communications | CRM | Maintain confidence |
| CBF-11 | Legal and Corporate Governance | 48 Hours | 5 Days | Critical legal advice | Legal systems | Support executive decisions |
| CBF-12 | Human Resource Management | 72 Hours | 1 Week | Staff mobilisation | HRIS | Support recovery operations |
| CBF-13 | Procurement and Vendor Management | 72 Hours | 1 Week | Critical supplier support | Procurement system | Maintain supplier continuity |
| CBF-14 | Corporate Communications and Stakeholder Management | 12 Hours | 48 Hours | Emergency communications | Communications systems | Protect organisational reputation |
| CBF-15 | Business Continuity and Crisis Management | 2 Hours | 24 Hours | Crisis coordination | Executive Management | Coordinate enterprise recovery |
Business recovery objectives cannot be achieved unless supporting technology is restored first.
Consequently, ICT Disaster Recovery objectives should be derived from approved business RTOs rather than established independently.
For example:
Accordingly, ICT recovery strategies, supplier service levels and infrastructure resilience should all be designed to support the approved business recovery objectives.
While the RTO addresses how quickly a business activity should be resumed, the Recovery Point Objective (RPO) addresses how much information loss is acceptable following a disruption.
The RPO is measured as the maximum acceptable period of data loss and is particularly relevant for information-intensive business activities and systems.
For Damanat, RPOs are especially important for systems that support mortgage guarantee processing, financial transactions, regulatory reporting, and cybersecurity. They should reflect:
| Critical Business Function | Key Information or System | Indicative RPO | Data Loss Consequence | Reconstruction Capability | Validation Required |
|---|---|---|---|---|---|
| Mortgage Guarantee Origination | Mortgage Guarantee Processing System | 15 Minutes | Lost applications and transaction records | Limited | Yes |
| Guarantee Risk Assessment | Risk Assessment Database | 30 Minutes | Incomplete underwriting information | Moderate | Yes |
| Guarantee Issuance & Administration | Guarantee Register | 30 Minutes | Missing guarantee records | Moderate | Yes |
| Claims Assessment | Claims Database | 1 Hour | Delayed claims processing | Moderate | Yes |
| Financial & Treasury Management | Financial Transactions | 15 Minutes | Financial reconciliation issues | Low | Yes |
| Regulatory Compliance | Regulatory Reporting Database | 1 Hour | Inaccurate regulatory reporting | Moderate | Yes |
| Information Technology Services | Configuration Repository | 4 Hours | Delayed infrastructure recovery | High | Yes |
| Information Security | Security Logs and SIEM | Near Zero to 15 Minutes | Loss of forensic evidence | Very Limited | Yes |
| Customer Relationship Management | CRM Database | 1 Hour | Customer information loss | Moderate | Yes |
| Business Continuity & Crisis Management | Incident Management Records | 15 Minutes | Loss of crisis decision records | Limited | Yes |
Unlike the RTO, which specifies when recovery should occur, the MBCO specifies what minimum level of service must be delivered while full operations are being restored.
The MBCO should be measurable and may be expressed in terms of:
| CBF Code | Critical Business Function | Indicative MBCO | Priority Activities | Activities That May Be Deferred | Maximum Deferral Period | Validation Required |
|---|---|---|---|---|---|---|
| CBF-1 | Mortgage Guarantee Origination | Process 40% of priority applications | Priority mortgage guarantees | Non-urgent applications | 5 Days | Yes |
| CBF-2 | Guarantee Risk Assessment | Assess priority guarantees only | High-risk assessments | Low-risk reviews | 5 Days | Yes |
| CBF-3 | Guarantee Issuance & Administration | Issue approved priority guarantees | Priority certificates | Routine administrative updates | 1 Week | Yes |
| CBF-4 | Claims Assessment | Process urgent claims | High-priority settlements | Routine claims reviews | 1 Week | Yes |
| CBF-5 | Financial & Treasury Management | Maintain essential financial controls | Payments and liquidity | Non-essential reporting | 1 Week | Yes |
| CBF-6 | Enterprise Risk Management | Monitor significant enterprise risks | Executive reporting | Routine assessments | 2 Weeks | Yes |
| CBF-7 | Regulatory Compliance | Meet mandatory regulatory deadlines | Statutory reporting | Advisory activities | 1 Week | Yes |
| CBF-8 | Information Technology Services | Restore all critical business systems | Core infrastructure | Enhancement activities | 2 Weeks | Yes |
| CBF-9 | Information Security | Maintain continuous cyber monitoring | Threat detection | Improvement initiatives | 2 Weeks | Yes |
| CBF-10 | Customer & Financial Institution Relationship Management | Respond to priority stakeholder enquiries | Critical communications | Routine relationship activities | 1 Week | Yes |
| CBF-11 | Legal & Corporate Governance | Provide essential legal advice | Critical governance support | Routine legal reviews | 2 Weeks | Yes |
| CBF-12 | Human Resource Management | Support recovery staffing | Staff mobilisation | Routine HR administration | 2 Weeks | Yes |
| CBF-13 | Procurement & Vendor Management | Maintain critical supplier support | Emergency procurement | Strategic sourcing | 2 Weeks | Yes |
| CBF-14 | Corporate Communications | Issue essential communications | Crisis communications | Routine media activities | 1 Week | Yes |
| CBF-15 | Business Continuity & Crisis Management | Maintain full crisis coordination capability | Incident management | Programme improvement | Not Applicable | Yes |
The four key BIA outputs are complementary and support different management decisions:
Together, these outputs provide the foundation for developing recovery strategies, ICT Disaster Recovery capabilities and Business Continuity Plans that are aligned with Damanat's operational, regulatory and stakeholder requirements.
End of Part 4
The next instalment will cover:
| P0 | P1 | P2 | P3 | P4 | P5 | P6 | P7 |
|
|
More Information About Business Continuity Management Courses
To learn more about the course and schedule, click the buttons below for the BCM-300 Business Continuity Management Implementer [BCM-3] and the BCM-5000 Business Continuity Management Expert Implementer [BCM-5].
|
Please feel free to send us a note if you have any questions. |
||