The Business Continuity Strategy (BCS) phase is the stage of the Business Continuity Management (BCM) Planning Methodology in which The Saudi Mortgage Guarantees Services Company (Damanat) determines how its Critical Business Functions (CBFs) will be protected, continued and recovered following a disruptive incident.
The preceding Risk Analysis and Review (RAR) phase identifies the threats, vulnerabilities and single points of failure that could disrupt Damanat.
The Business Impact Analysis (BIA) establishes which business functions and supporting activities require priority recovery, how quickly they must be restored and what minimum resources are required.
The Business Continuity Strategy phase translates these findings into practical solutions.
In simple terms:
RAR identifies what could cause disruption.
BIA identifies what must be recovered and by when.
BCS determines how continuity and recovery will be achieved.
For Damanat, business continuity strategies should address the combination of people, processes, technology, information, premises, suppliers and external interfaces required to support mortgage guarantee operations and other Critical Business Functions.
The selected strategies should incorporate three complementary forms of resilience:
Prevention – reducing the likelihood of disruption.
Mitigation – reducing the severity of the consequences when disruption occurs.
Recovery – restoring affected Critical Business Functions and resources within predetermined recovery objectives.
The objective is not to eliminate every possible disruption. That is neither realistic nor economically practical. Instead, Damanat should establish a balanced portfolio of preventive, mitigating and recovery capabilities that allows priority business activities to remain within acceptable levels of disruption.
The purpose of the BCS phase is to identify, evaluate, select and approve continuity solutions that enable Damanat to achieve the recovery requirements established during the BIA.
The phase should answer questions such as:
The resulting strategy should provide the foundation for the next BCM phase: Plan Development (PD).
Business Continuity Strategies should not be selected simply because they represent common industry practices.
Each strategy should be supported by the results of Damanat's RAR and BIA.
The selection process should consider:
The strategy must be capable of meeting the approved Recovery Time Objective (RTO), Recovery Point Objective (RPO), Maximum Acceptable Outage (MAO) and Minimum Business Continuity Objective (MBCO), where applicable.
Higher-risk functions may require greater resilience or redundancy.
The solution must work under realistic disruption conditions.
The required people, facilities, technology, information, and suppliers must be available when the strategy is activated.
Implementation and maintenance costs should be proportionate to the potential consequences of disruption.
The strategy should meet applicable legal, regulatory and supervisory expectations.
The strategy should take account of internal and external dependencies.
The strategy should remain effective against disruptions of varying durations and severities.
Damanat should be able to operate under the continuity arrangement for the period required to restore normal operations.
The Saudi Central Bank's Business Continuity Management Framework requires a business continuity strategy to be formally defined, approved, implemented, maintained, and aligned with the organisation's strategic objectives.
The framework also requires BIA results to identify recovery objectives, interdependencies, and supporting resources, while continuity plans must support the continuation of critical activities within those recovery objectives.
The SAMA framework also addresses alternative business workspaces, technology disaster recovery, backup and recovery processes, critical service providers, and contractual arrangements supporting continuity.
It specifies that alternative workspaces should support the delivery of critical processes in accordance with BIA recovery objectives, and that IT Disaster Recovery Plans should align with the BIA and restore critical technology infrastructure, data, systems, networks, and applications.
For Damanat, this means strategy selection should be demonstrably linked to:
For example:
This traceability demonstrates that continuity arrangements are based on established business requirements rather than arbitrary technical solutions.
Business Continuity Strategies for Damanat's Critical Business Functions should establish the capabilities necessary to maintain an acceptable level of mortgage guarantee and supporting operations during disruption.
A Critical Business Function normally depends upon several resources simultaneously. A recovery strategy should therefore not focus only on a single dimension such as technology.
For example, recovering a mortgage guarantee application system will not restore Mortgage Guarantee Origination if:
Damanat should therefore develop strategies across the following resource dimensions:
→ Processes
→ Technology
→ Information and Data
→ Premises
→ Suppliers and Third Parties
→ Communications
→ External Dependencies
Each Critical Business Function should have an appropriate combination of strategies covering these dimensions.
Prevention strategies reduce the likelihood of disruption.
These arrangements generally operate before an incident and form part of normal business operations.
For Damanat, preventive measures may include:
If Mortgage Guarantee Origination depends heavily on a central processing platform, preventive strategies might include:
These measures reduce the probability that a single technical fault causes a complete processing outage.
Mitigation strategies reduce the consequences of a disruptive incident after it has occurred or when disruption cannot be completely prevented.
Examples for Damanat may include:
Suppose the normal guarantee application interface with a participating financial institution becomes unavailable.
A mitigation strategy might permit priority applications to be securely exchanged through an approved alternative channel until the primary interface is restored.
This does not prevent the outage. It reduces the operational consequences.
Recovery strategies restore interrupted activities and supporting resources following disruption.
They normally include:
Recovery strategies should be designed to achieve the recovery objectives established during the BIA.
People are fundamental to Damanat's capability for continuity.
Critical activities may depend on employees possessing specialist knowledge, approval authority, system privileges or relationships with external stakeholders.
Potential strategies include:
Train multiple employees to perform critical activities.
Identify alternates for critical managerial and specialist roles.
Define alternative approval authorities for disruptions.
Enable employees to perform critical activities from approved remote locations.
Transfer employees temporarily to alternative premises.
Separate critical employees across locations or working arrangements to reduce concentration exposure.
Reassign suitably skilled employees from lower-priority functions.
If only two employees can authorise high-priority guarantee decisions, their simultaneous unavailability could create a significant processing bottleneck.
A continuity strategy might therefore require:
Some processes can continue even when normal operating arrangements become unavailable.
Strategies may include:
During a major systems disruption, Damanat might prioritise:
The strategy should also determine how transactions processed through temporary arrangements will later be reconciled with the main system.
Technology resilience is particularly important for activities involving electronic application processing, decision support, record management, communications and interfaces with financial institutions.
Potential strategies include:
SAMA's BCM Framework requires IT disaster recovery arrangements for critical technology infrastructure to be aligned with BIA requirements, including data, systems, networks, services and applications.
It also specifies backup and recovery arrangements, as well as an appropriately located alternative data centre for applicable member organisations.
For a platform supporting Mortgage Guarantee Origination, the technology strategy may provide:
Technology recovery should then be tested against the recovery objectives established through the BIA.
Recovering an application is insufficient if critical business data is unavailable or unreliable.
Damanat should therefore establish strategies covering:
Suppose Damanat's RPO for a critical guarantee-processing database is 30 minutes.
The selected backup and replication arrangement should demonstrate that data can ordinarily be recovered to within that approved tolerance.
If the technology can only restore data from a backup taken 24 hours earlier, the strategy would not meet the BIA requirement.
Loss of the primary workplace should not prevent priority activities from being performed beyond their allowable interruption period.
Possible strategies include:
The SAMA BCM Framework states that applicable organisations should have sufficient alternative business workspace to relocate required resources and to deliver critical processes in accordance with BIA recovery objectives.
Damanat could establish a strategy under which:
First Response: Priority employees switch to remote working.
If disruption continues: Designated teams operate from an alternate workplace.
If disruption becomes prolonged: Additional resources are transferred to the alternate operating environment.
This provides scalability according to incident duration.
Damanat's recovery capability may depend on external organisations over which it does not have direct operational control.
Strategies may include:
The SAMA BCM Framework addresses the continuity capabilities of vendors, suppliers, and service providers and requires key providers supporting critical activities to maintain continuity arrangements and to be tested periodically.
If a third-party provider supports an important technology interface, Damanat should determine:
A supplier with an RTO of 48 hours cannot support a Damanat function that must recover within four hours unless another continuity arrangement exists.
Mortgage guarantee activities involve interactions with financial institutions.
Damanat should therefore consider continuity arrangements for external communication and the exchange of transactions.
Strategies may include:
If the normal application interface is unavailable, Damanat may activate a predefined alternative method for receiving specifically prioritised applications.
The strategy would need to address:
Effective continuity operations require reliable communications.
Damanat should consider:
Multiple channels should be available where communication itself represents a critical dependency.
A cyber incident may require different continuity approaches from a conventional technology outage.
Immediately restoring compromised infrastructure may not be appropriate if the security threat remains active.
Cyber continuity strategies may therefore include:
The continuity strategy should therefore integrate BCM, IT disaster recovery, cybersecurity, and incident management requirements.
Damanat should distinguish between short-term workarounds and arrangements that can support prolonged disruption.
For example, employees may be able to use a manual spreadsheet for several hours, but this may not remain practical for several weeks.
Strategies should therefore consider different stages:
Maintain essential operations during the first hours.
Operate priority functions for several days.
Sustain operations during prolonged disruption.
Restore normal or replacement operating capability.
Transfer from continuity arrangements to normal operations.
Where appropriate, Damanat should establish the Minimum Business Continuity Objective (MBCO) for Critical Business Functions.
The MBCO represents the minimum acceptable level of service or activity that must be achieved during continuity operations.
For example, normal Mortgage Guarantee Origination might process 100 per cent of applications.
During a severe disruption, the approved strategy might initially support:
The strategy must therefore answer not only how quickly the activity recovers, but also at what minimum operating capacity.
Damanat should normally consider more than one strategy option before selecting the preferred solution.
For example, for loss of premises:
Higher cost but strong readiness.
Lower infrastructure cost but dependent on employee connectivity and remote-access capability.
Potentially cost-effective but may involve availability limitations.
Remote working for most employees with reserved alternate-site capacity for essential roles.
Each option should be evaluated against the BIA requirement.
A structured evaluation may consider:
|
Criterion |
Key Question |
|
RTO Compliance |
Can the strategy recover the activity within the required time? |
|
RPO Compliance |
Can acceptable data loss be maintained? |
|
MBCO |
Can minimum required service levels be achieved? |
|
Operational Feasibility |
Can the strategy actually be activated? |
|
Resource Availability |
Will people, technology and facilities be available? |
|
Dependency Risk |
Does the strategy introduce another critical dependency? |
|
Sustainability |
How long can the arrangement operate? |
|
Security |
Are information and physical security maintained? |
|
Regulatory Alignment |
Does the approach meet applicable requirements? |
|
Cost |
Is the solution financially proportionate? |
|
Complexity |
Can employees realistically execute it? |
|
Testability |
Can the arrangement be validated regularly? |
Consider the loss of Damanat's primary office.
Advantage: Minimal additional cost.
Disadvantage: Recovery time is unpredictable.
Assessment: Unsuitable for functions requiring rapid recovery.
Advantage: Rapid activation for suitable roles.
Disadvantage: Depends on connectivity, equipment and remote system access.
Assessment: Suitable for many knowledge-based functions if capacity is validated.
Advantage: Controlled environment and dedicated recovery resources.
Disadvantage: Higher cost.
Assessment: Suitable for functions requiring secure infrastructure or physical coordination.
Damanat could adopt a hybrid strategy, combining remote work with alternate-site capacity for functions that cannot be performed entirely remotely.
The following provides an illustrative strategy model for Damanat's Critical Business Functions.
Damanat should ensure that applications can continue to be received, assessed, approved and issued when normal operating arrangements are disrupted.
Strategies may include resilient processing systems, remote access, alternative application submission arrangements, cross-trained assessment personnel, alternate approval authorities, data recovery, technology disaster recovery and temporary manual processing procedures.
Guarantee records and servicing activities should remain accessible through redundant systems, recoverable data repositories and alternative working arrangements.
Critical updates may be prioritised during reduced-capacity operations.
Damanat should maintain access to claim information, authorised decision-makers and supporting documents.
Temporary manual workflows and alternative communication channels may be required where normal claims-processing technology is unavailable.
Priority financial obligations should be identified and supported by alternate authorised personnel, secure remote banking capability, alternative processing arrangements and defined escalation procedures.
Critical regulatory deadlines should be identified in advance.
Strategies should provide alternative access to required data, backup personnel, documented report-production procedures and secure communication channels with regulators.
Alternative telephone, email and digital channels should support priority communications where normal channels are unavailable.
Emergency contact and escalation arrangements should be established for participating financial institutions.
Critical applications, infrastructure, networks and data should be supported by disaster recovery, backup, redundancy, alternative connectivity and tested restoration arrangements.
Human Resources, facilities, procurement, legal, risk, compliance and other support functions should maintain continuity capabilities proportionate to their role in supporting critical operations.
|
Critical Business Function / Resource |
Key Disruption |
Prevention Strategy |
Mitigation Strategy |
Recovery Strategy |
|
Mortgage Guarantee Origination |
Processing platform failure |
High availability, monitoring, controlled changes |
Prioritise urgent applications; temporary workaround |
DR platform and application recovery |
|
Application Intake |
External interface unavailable |
Redundant interface and monitoring |
Alternative secure submission channel |
Restore interface and reconcile transactions |
|
Eligibility and Risk Assessment |
Specialist personnel unavailable |
Cross-training and succession |
Redistribute workload |
Activate alternate trained assessors |
|
Guarantee Approval |
Authorised approvers unavailable |
Multiple delegated approvers |
Remote approval |
Activate alternate approval authority |
|
Guarantee Certificate Generation |
Application/service failure |
Redundant system components |
Temporary confirmation procedures |
Restore certificate-generation capability |
|
Guarantee Administration |
Core system unavailable |
Resilient infrastructure |
Priority servicing only |
Recover application and database |
|
Claims Management |
Claims system or staff unavailable |
Cross-training and system resilience |
Manual priority claims handling |
Restore claims platform and records |
|
Financial Operations |
Payment capability unavailable |
Multiple authorised personnel and resilient banking channels |
Prioritise critical obligations |
Activate alternate payment arrangement |
|
Regulatory Reporting |
Reporting platform/data unavailable |
Backup reporting data and cross-trained personnel |
Manual data consolidation |
Restore reporting environment |
|
Customer / FI Support |
Contact channel unavailable |
Multiple communications channels |
Redirect calls/email to alternatives |
Restore normal communication services |
|
Critical Data |
Corruption or loss |
Replication, backup, access controls |
Use last validated dataset |
Restore within approved RPO |
|
Primary Workplace |
Building inaccessible |
Geographic and workspace planning |
Remote working |
Relocate priority teams to alternate site |
|
Critical Personnel |
Widespread unavailability |
Cross-training and succession |
Reduce activity to MBCO |
Redeploy alternates |
|
Telecommunications |
Carrier outage |
Diverse connectivity |
Mobile or alternative communications |
Restore primary telecommunications |
|
Third-Party Technology |
Provider failure |
Supplier resilience assessment |
Alternative manual/service route |
Activate alternative provider or provider DR |
|
Cyber Incident |
Systems compromised |
Cybersecurity controls and monitoring |
Isolate affected systems; manual procedures |
Clean-system recovery from validated backups |
The specific strategy for each Critical Business Function should ultimately be determined from its approved BIA and RAR results rather than from generic assumptions.
Damanat should document the selected strategy for each Critical Business Function.
A strategy record could contain:
|
Field |
Description |
|
CBF |
Critical Business Function |
|
BIA Recovery Requirement |
RTO, RPO, MAO and MBCO |
|
Key Dependencies |
People, process, technology, premises and suppliers |
|
Identified Threat |
Relevant RAR finding |
|
Existing Capability |
Current continuity arrangement |
|
Strategy Options |
Alternatives evaluated |
|
Selected Strategy |
Approved solution |
|
Required Resources |
Resources required for activation |
|
Implementation Actions |
Capability gaps to close |
|
Strategy Owner |
Accountable owner |
|
Target Date |
Implementation deadline |
|
Approval |
Management/committee approval |
|
Validation Method |
How the strategy will be tested |
Selecting a strategy does not mean the required capability already exists.
Damanat should compare:
The difference becomes the strategy gap.
For example:
BIA Requirement
Mortgage Guarantee Origination must recover within four hours.
Current Capability
Technology recovery takes eight hours.
Gap
Four-hour recovery deficit.
Required Action
Improve infrastructure, automation or failover capability to achieve the four-hour requirement.
This gap analysis should produce an implementation plan.
For each identified gap, Damanat should document:
Significant gaps should be reported to the BCM Committee or appropriate governance authority.
Business Continuity Strategies should receive formal approval because they frequently involve investment, operational changes and acceptance of residual risks.
Approval should confirm that management accepts:
Where a strategy cannot achieve an approved BIA requirement, the shortfall should be clearly escalated rather than hidden within the BCP.
The BCS phase determines what continuity capabilities Damanat will use.
The next Plan Development phase determines how those capabilities will be activated and operated during an incident.
For example:
Employees will work remotely following loss of the primary workplace.
Business Continuity Plan
The BCP specifies:
Similarly:
Mortgage Guarantee Origination will fail over to the DR environment.
Business Continuity / DR Procedure
The plan specifies:
This demonstrates the distinction between strategy and plan.
At the conclusion of the BCS phase, Damanat should have developed at minimum:
|
Ref |
Deliverable |
Purpose |
|
BCS-01 |
Business Continuity Strategy Methodology |
Defines strategy-development approach |
|
BCS-02 |
Strategy Requirements Register |
Consolidates BIA recovery requirements |
|
BCS-03 |
Strategy Options Analysis |
Documents alternatives |
|
BCS-04 |
CBF Continuity Strategies |
Defines strategies for priority functions |
|
BCS-05 |
People Strategy |
Addresses workforce continuity |
|
BCS-06 |
Premises Strategy |
Addresses workplace loss |
|
BCS-07 |
Technology Recovery Strategy |
Addresses systems and infrastructure |
|
BCS-08 |
Information Recovery Strategy |
Addresses data and records |
|
BCS-09 |
Supplier Continuity Strategy |
Addresses third-party dependencies |
|
BCS-10 |
Communication Strategy |
Addresses disruption communications |
|
BCS-11 |
Strategy Gap Register |
Identifies capability deficiencies |
|
BCS-12 |
Implementation Plan |
Closes identified strategy gaps |
|
BCS-13 |
Strategy Approval Record |
Documents management acceptance |
Damanat should consider the Business Continuity Strategy phase sufficiently complete when:
A mature continuity strategy should not rely on one type of control.
Damanat should combine:
Consider a critical technology platform.
Redundant infrastructure and cybersecurity controls reduce the likelihood of failure.
Manual or alternative procedures reduce the immediate business impact.
The disaster recovery environment restores technology capability.
Similarly, for critical personnel:
Succession planning and cross-training reduce concentration risk.
Workload prioritisation reduces immediate disruption.
Alternative personnel assume the required roles.
This layered approach provides greater resilience than relying on recovery alone.
The Business Continuity Strategy phase transforms Damanat's understanding of risk and business impact into practical resilience capability.
Through the preceding Risk Analysis and Review, Damanat identifies the threats, vulnerabilities, and single points of failure that could disrupt operations.
Through the Business Impact Analysis, Damanat determines which Critical Business Functions must be prioritised, how quickly they must recover, the acceptable level of data loss, the minimum operating capacity required, and the resources on which those activities depend.
The Business Continuity Strategy phase answers the next essential question:
For Damanat, the answer should not be limited to technology disaster recovery.
A complete strategy must consider:
The strategy should also incorporate three complementary layers of resilience:
Prevention reduces the likelihood of disruption.
Mitigation limits the immediate consequences of disruption.
Recovery restores the affected Critical Business Function within its approved recovery objectives.
For example:
→ Cross-training
→ Alternative authority
→ Redeployment of trained personnel
→ Distributed working capability
→ Remote working
→ Alternate workspace
→ High-availability infrastructure
→ Temporary workaround
→ Disaster recovery
→ Supplier resilience controls
→ Temporary alternative arrangements
→ Alternative provider
→ Replication and backup
→ Use of validated recovery data
→ Restoration within the approved RPO
The resulting strategies provide the bridge between analysis and action.
They transform the findings of the RAR and BIA into the capabilities that Damanat will depend upon during an actual disruption.
The strategy phase should therefore produce approved, funded, implementable and testable solutions for each Critical Business Function.
Where current capabilities cannot achieve the established recovery requirements, the resulting gaps should be visible to management and addressed through formal improvement plans.
Once these strategies have been selected and approved, Damanat can proceed to the next phase of its BCM Planning Methodology—Plan Development (PD).
The focus then changes from:
to:
The next chapter will translate Damanat's approved Business Continuity Strategies into practical Business Continuity Plans, activation procedures, escalation arrangements, response actions, recovery procedures and return-to-normal activities.
| eBook 2: Implementing Business Continuity Management | ||||
| C1 | C2 | C3 | C4 | C5 |
| C6 | C7 | C8 | C9 | C10 |
To learn more about the course and schedule, click the buttons below for BCM-300 Business Continuity Management Implementer [BCM-3] and BCM-5000 Business Continuity Management Expert Implementer [BCM-5]
|
Please feel free to send us a note if you have any questions. |
||