eBook 2: Chapter 6
BC Plan Development Phase as part of the BCM Planning Methodology for
The Saudi Mortgage Guarantees Services Company
Introduction
Following the completion of the Business Continuity Strategy (BCS) phase, the next stage in the Business Continuity Management (BCM) Planning Methodology is the Business Continuity Plan (BC Plan) Development Phase.
This phase transforms the recovery strategies identified during earlier phases into documented procedures that can be executed during a disruption.
The objective of plan development is to ensure that all critical business functions within Damanat have clear, practical, and actionable recovery procedures that enable personnel to respond effectively during incidents.
A well-developed BC Plan provides a structured framework for managing disruptions, protecting regulatory responsibilities, and restoring normal operations within agreed recovery timeframes.
This chapter explains the key activities involved in developing Business Continuity Plans for Damanat and outlines how business units can create, validate, and maintain effective recovery plans.
What Does Plan Development Entail?
The Business Continuity Plan Development process consists of three major stages:
- Determination of the Organisation of the BC Plan Document.
- Conducting a BC Plan Writing Workshop.
- Finalisation of the BC Plan Production.
Each stage ensures that the resulting plans are comprehensive, practical, and aligned with Damanat's business continuity objectives.
Purpose
Plan Development (PD) translates approved Business Continuity Strategies into practical procedures that can be activated and executed during disruption.
The relationship is straightforward:
BIA establishes what must recover → BCS establishes how recovery will be achieved → PD documents what people must do.
A Business Continuity Plan should therefore not be developed independently of the preceding analytical and strategy phases.
Its procedures should reflect approved recovery requirements, available resources, defined responsibilities and actual recovery arrangements.
The plan should be designed for use under pressure.
It should be concise enough to navigate quickly yet sufficiently detailed to support personnel operating under unfamiliar and degraded conditions.
Structure of the Business Continuity Plan
Although plan structures may vary according to organisational requirements, Damanat's plans should generally address three operational periods:
Pre-Crisis Preparedness
Activities undertaken before disruption to ensure that the plan can be activated effectively.
Response and Recovery
Actions required following a disruption: assess the situation, activate the plan, mobilise resources, and resume priority activities.
Restore and Return
Actions required to move from temporary continuity arrangements toward normal operations.
This structure creates continuity between preparedness, disruption management, recovery and normalisation.
Pre-Crisis Preparedness
Pre-crisis arrangements should ensure that required capabilities are ready before an incident occurs.
These should include:
Team Readiness
Plan owners and recovery team members should understand:
- their responsibilities;
- activation arrangements;
- decision-making authority;
- escalation requirements;
- alternate roles; and
- reporting relationships.
Call Trees and Contact Information
Plans should contain or provide controlled access to current contact information for relevant:
- personnel;
- management;
- suppliers;
- technology teams;
- facilities contacts;
- external stakeholders; and
- other recovery resources.
Contact information should be maintained and tested.
Alternate Site Readiness
Where alternate workspace forms part of the approved strategy, readiness should include:
- physical access;
- workspace availability;
- equipment;
- connectivity;
- security;
- access credentials; and
- activation instructions.
Resource Preparation
Required continuity resources should be identified and, where appropriate, pre-positioned or made rapidly available.
System Access
Personnel expected to perform recovery activities should possess the necessary:
- devices;
- accounts;
- permissions;
- authentication methods; and
- remote-access capability.
Vital Records
Information required during disruption should remain available, accessible and appropriately protected.
Supplier Arrangements
Where recovery depends upon external providers, contractual and operational activation arrangements should be documented.
Training
Personnel with plan responsibilities should receive sufficient training before they are expected to perform those responsibilities during an actual disruption.
Response and Recovery Procedures
Once a disruptive event occurs, the Business Continuity Plan should provide a clear sequence of actions.
Incident Detection and Notification
The organisation should define how potentially disruptive events are identified and reported.
Escalation
The plan should define criteria for escalating an operational incident to the appropriate management, crisis management or business continuity level.
Activation
Activation procedures should identify:
- who may activate the plan;
- activation criteria;
- required approvals;
- notification requirements; and
- initial actions.
Mobilisation
Once activated, required teams, facilities, systems and suppliers should be mobilised.
Damage and Impact Assessment
The organisation should determine:
- what has been affected;
- expected duration;
- available resources;
- affected CBFs;
- technology status;
- personnel status; and
- immediate recovery priorities.
Alternate Workspace or Remote Operations
Where the primary workplace is unavailable, approved workplace recovery arrangements should be activated.
ICT Recovery
ICT Disaster Recovery should be initiated in accordance with business recovery priorities and coordinated with business recovery teams.
Stakeholder Notification
Relevant internal and external stakeholders should receive timely, controlled information appropriate to the situation.
Priority Service Resumption
CBFs should be restored according to approved recovery priorities, RTOs and MBCOs.
Recovery teams should record:
- actions;
- decisions;
- approvals;
- exceptions;
- outstanding issues; and
- service status.
Restore and Return
Recovery does not end when minimum operations resume.
The organisation must eventually restore deferred activities and transition from temporary arrangements to a sustainable normal operating environment.
Activities may include:
- clearing accumulated backlogs;
- reconciling manually processed transactions;
- validating recovered data;
- restoring deferred activities;
- increasing service capacity;
- returning to primary premises;
- normalising staffing;
- recovering temporary equipment;
- terminating temporary supplier arrangements;
- confirming full restoration;
- standing down recovery teams; and
- conducting post-incident review.
Particular attention should be given to data reconciliation following manual or alternative processing.
The objective is to prevent continuity arrangements themselves from creating subsequent operational, financial or information-integrity problems.
Key Deliverables
PD should generate:
- Business Continuity Plan;
- activation procedures;
- escalation procedures;
- communication procedures;
- business recovery procedures;
- contact information;
- resource checklists;
- alternate-workplace procedures;
- ICT recovery interfaces; and
- return-to-normal procedures.
Table: Plan Development Requirements
|
PD Component |
Objective |
Main Procedure |
Responsible Role |
Required Supporting Information |
|
Activation |
Formally initiate continuity arrangements |
Assess criteria, authorise activation and notify teams |
Plan Owner/ Authorised Management |
Activation criteria and authority matrix |
|
Escalation |
Ensure disruption receives appropriate management attention |
Escalate based on impact and severity |
Incident/Business Management |
Escalation thresholds |
|
Team mobilisation |
Assemble required recovery personnel |
Notify and mobilise recovery teams |
Team Leader |
Contact lists and call tree |
|
Damage assessment |
Establish operational consequences |
Assess affected people, premises, technology and activities |
Recovery Team |
CBF and dependency information |
|
Workplace recovery |
Provide alternate operating capability |
Activate remote or alternate workspace |
Facilities/ICT/Business Team |
Approved workplace strategy |
|
ICT recovery |
Restore technology supporting CBFs |
Activate Disaster Recovery procedures |
ICT |
RTO, RPO and application priorities |
|
Business recovery |
Resume priority activities |
Execute approved recovery procedures |
CBF Owner/Recovery Team |
RTO, MBCO and strategy |
|
Communications |
Maintain controlled stakeholder information |
Prepare, approve and distribute communications |
Communications/Management |
Stakeholder and contact information |
|
Resource management |
Provide minimum recovery resources |
Allocate personnel, equipment and services |
Recovery Team |
Resource checklist |
|
Return to normal |
Restore normal operating arrangements |
Reconcile, migrate, restore and stand down |
CBF Owner |
Restoration criteria and reconciliation requirements |
|
Post-incident review |
Capture improvement opportunities |
Review performance and identify corrective actions |
BCM Programme Manager |
Incident logs and recovery records |
Damanat-Specific PD Requirements
Damanat's continuity procedures should incorporate, where applicable:
- preservation of delegated and approval authorities;
- controlled handling of mortgage guarantee and supporting records;
- retention of decision and transaction audit trails;
- secure communications;
- controlled access to sensitive information;
- coordination with financial institutions and other relevant external parties;
- maintenance of accurate stakeholder information;
- secure operation under remote or alternate arrangements; and
- protection of confidential information during degraded operations.
Temporary continuity arrangements should not unintentionally bypass essential governance, financial, legal, information-security or approval controls.
The objective is controlled degradation, not uncontrolled relaxation of organisational safeguards.
The Business Continuity Plan Development Phase is the process by which Damanat's continuity strategies are translated into practical, executable recovery procedures.
By establishing a standardised BC Plan structure, defining a recovery organisation, conducting plan-writing workshops, and validating completed plans, Damanat can ensure that each critical business function has clear guidance for responding to disruptions.
Well-developed BC Plans enable Damanat to continue essential regulatory activities, protect critical information assets, maintain stakeholder confidence, and fulfil its statutory obligations during adverse events.
As required by ISO 22301, these plans should be regularly reviewed, updated, and tested to ensure they remain effective and aligned with the evolving operational and regulatory environment.
The completion of this phase provides the foundation for the next stage of the BCM Planning Methodology—Testing and Exercising—where the effectiveness of the plans will be validated through structured exercises and simulations.
| eBook 2: Implementing Business Continuity Management | ||||
| C1 | C2 | C3 | C4 | C5 |
![]() |
![]() |
![]() |
![]() |
![]() |
| C6 | C7 | C8 | C9 | C10 |
![]() |
![]() |
![]() |
![]() |
![]() |
More Information About Business Continuity Management Courses
To learn more about the course and schedule, click the buttons below for BCM-300 Business Continuity Management Implementer [BCM-3] and BCM-5000 Business Continuity Management Expert Implementer [BCM-5]


![[BCM] [Damanat] [Full Banner] Implementing BCM for The Saudi Mortgage Guarantees Services Company](https://no-cache.hubspot.com/cta/default/3893111/221734db-8c33-48bd-8147-fc740eecaf83.png)



![Banner [Summary] [BCM] [E2] [C6] BCM Plan Development](https://no-cache.hubspot.com/cta/default/3893111/a8cffab8-99ea-4a3b-8755-e4196a5d5b95.png)
![[BCM] [Damanat] [3/4 Banner] Implementing BCM for The Saudi Mortgage Guarantees Services Company](https://no-cache.hubspot.com/cta/default/3893111/0252380a-b2dc-4059-be10-b5566002b711.png)
![[BCM] [Damanat] [E2] [C1] Business Continuity Management Planning Methodology](https://no-cache.hubspot.com/cta/default/3893111/b17b614b-c36c-4437-95ca-5c1d44ac6ce3.png)
![[BCM] [Damanat] [E2] [C2] Project Management](https://no-cache.hubspot.com/cta/default/3893111/4663bc6b-2e85-4e17-b6af-b5c784413b28.png)
![[BCM] [Damanat] [E2] [C3] Risk Analysis and Review](https://no-cache.hubspot.com/cta/default/3893111/5423f27a-6048-40c1-b55c-238fafb59648.png)
![[BCM] [Damanat] [E2] [C4] Business Impact Analysis](https://no-cache.hubspot.com/cta/default/3893111/7a3c1a1f-d7f6-4d5d-8fef-deedc7d91f63.png)
![[BCM] [Damanat] [E2] [C5] Business Continuity Strategy](https://no-cache.hubspot.com/cta/default/3893111/a27d7e1e-8571-421d-9467-cc02614820e1.png)
![[BCM] [Damanat] [E2] [C7] Testing and Exercising](https://no-cache.hubspot.com/cta/default/3893111/ed03c310-870a-482d-bac6-446897084091.png)
![[BCM] [Damanat] [E2] [C8] Program Management](https://no-cache.hubspot.com/cta/default/3893111/f52be888-834d-480c-9149-1167d38f1147.png)
![[BCM] [Damanat] [E2] [C9] Summary](https://no-cache.hubspot.com/cta/default/3893111/dab5bc8f-3d96-444b-880f-78cf037fc906.png)
![[BCM] [Damanat] [E2] [C10] Back Cover](https://no-cache.hubspot.com/cta/default/3893111/351b85f0-d850-4dee-a5c0-55c2b37c3075.png)


![Register [BL-B-3]*](https://no-cache.hubspot.com/cta/default/3893111/ac6cf073-4cdd-4541-91ed-889f731d5076.png)



![FAQ [BL-B-3]](https://no-cache.hubspot.com/cta/default/3893111/b3824ba1-7aa1-4eb6-bef8-94f57121c5ae.png)
![Email to Sales Team [BCM Institute]](https://no-cache.hubspot.com/cta/default/3893111/3c53daeb-2836-4843-b0e0-645baee2ab9e.png)





