Ebook

[BCM] [Damanat] [E2] [C6] BCM Plan Development

Written by Dr Goh Moh Heng | Jul 28, 2026, 2:22:22 AM

eBook 2: Chapter 6

 

BC Plan Development Phase as part of the BCM Planning Methodology for 

The Saudi Mortgage Guarantees Services Company

 

 

Introduction

 

Following the completion of the Business Continuity Strategy (BCS) phase, the next stage in the Business Continuity Management (BCM) Planning Methodology is the Business Continuity Plan (BC Plan) Development Phase.

This phase transforms the recovery strategies identified during earlier phases into documented procedures that can be executed during a disruption.

The objective of plan development is to ensure that all critical business functions within Damanat have clear, practical, and actionable recovery procedures that enable personnel to respond effectively during incidents.

A well-developed BC Plan provides a structured framework for managing disruptions, protecting regulatory responsibilities, and restoring normal operations within agreed recovery timeframes.

This chapter explains the key activities involved in developing Business Continuity Plans for Damanat and outlines how business units can create, validate, and maintain effective recovery plans.

 

What Does Plan Development Entail?

The Business Continuity Plan Development process consists of three major stages:

  1. Determination of the Organisation of the BC Plan Document.
  2. Conducting a BC Plan Writing Workshop.
  3. Finalisation of the BC Plan Production.

Each stage ensures that the resulting plans are comprehensive, practical, and aligned with Damanat's business continuity objectives.

 

Purpose

Plan Development (PD) translates approved Business Continuity Strategies into practical procedures that can be activated and executed during disruption.

The relationship is straightforward:

BIA establishes what must recover → BCS establishes how recovery will be achieved → PD documents what people must do.

A Business Continuity Plan should therefore not be developed independently of the preceding analytical and strategy phases.

Its procedures should reflect approved recovery requirements, available resources, defined responsibilities and actual recovery arrangements.

The plan should be designed for use under pressure.

It should be concise enough to navigate quickly yet sufficiently detailed to support personnel operating under unfamiliar and degraded conditions.

 

Structure of the Business Continuity Plan

Although plan structures may vary according to organisational requirements, Damanat's plans should generally address three operational periods:

Pre-Crisis Preparedness

Activities undertaken before disruption to ensure that the plan can be activated effectively.

Response and Recovery

Actions required following a disruption: assess the situation, activate the plan, mobilise resources, and resume priority activities.

Restore and Return

Actions required to move from temporary continuity arrangements toward normal operations.

This structure creates continuity between preparedness, disruption management, recovery and normalisation.

 

Pre-Crisis Preparedness

Pre-crisis arrangements should ensure that required capabilities are ready before an incident occurs.

These should include:

Team Readiness

Plan owners and recovery team members should understand:

  • their responsibilities;
  • activation arrangements;
  • decision-making authority;
  • escalation requirements;
  • alternate roles; and
  • reporting relationships.
Call Trees and Contact Information

Plans should contain or provide controlled access to current contact information for relevant:

  • personnel;
  • management;
  • suppliers;
  • technology teams;
  • facilities contacts;
  • external stakeholders; and
  • other recovery resources.

Contact information should be maintained and tested.

Alternate Site Readiness

Where alternate workspace forms part of the approved strategy, readiness should include:

  • physical access;
  • workspace availability;
  • equipment;
  • connectivity;
  • security;
  • access credentials; and
  • activation instructions.
Resource Preparation

Required continuity resources should be identified and, where appropriate, pre-positioned or made rapidly available.

System Access

Personnel expected to perform recovery activities should possess the necessary:

  • devices;
  • accounts;
  • permissions;
  • authentication methods; and
  • remote-access capability.
Vital Records

Information required during disruption should remain available, accessible and appropriately protected.

Supplier Arrangements

Where recovery depends upon external providers, contractual and operational activation arrangements should be documented.

Training

Personnel with plan responsibilities should receive sufficient training before they are expected to perform those responsibilities during an actual disruption.

 

Response and Recovery Procedures

Once a disruptive event occurs, the Business Continuity Plan should provide a clear sequence of actions.

Incident Detection and Notification

The organisation should define how potentially disruptive events are identified and reported.

Escalation

The plan should define criteria for escalating an operational incident to the appropriate management, crisis management or business continuity level.

Activation

Activation procedures should identify:

  • who may activate the plan;
  • activation criteria;
  • required approvals;
  • notification requirements; and
  • initial actions.
Mobilisation

Once activated, required teams, facilities, systems and suppliers should be mobilised.

Damage and Impact Assessment

The organisation should determine:

  • what has been affected;
  • expected duration;
  • available resources;
  • affected CBFs;
  • technology status;
  • personnel status; and
  • immediate recovery priorities.
Alternate Workspace or Remote Operations

Where the primary workplace is unavailable, approved workplace recovery arrangements should be activated.

ICT Recovery

ICT Disaster Recovery should be initiated in accordance with business recovery priorities and coordinated with business recovery teams.

Stakeholder Notification

Relevant internal and external stakeholders should receive timely, controlled information appropriate to the situation.

Priority Service Resumption

CBFs should be restored according to approved recovery priorities, RTOs and MBCOs.

Recovery teams should record:

  • actions;
  • decisions;
  • approvals;
  • exceptions;
  • outstanding issues; and
  • service status.

 

Restore and Return

Recovery does not end when minimum operations resume.

The organisation must eventually restore deferred activities and transition from temporary arrangements to a sustainable normal operating environment.

Activities may include:

  • clearing accumulated backlogs;
  • reconciling manually processed transactions;
  • validating recovered data;
  • restoring deferred activities;
  • increasing service capacity;
  • returning to primary premises;
  • normalising staffing;
  • recovering temporary equipment;
  • terminating temporary supplier arrangements;
  • confirming full restoration;
  • standing down recovery teams; and
  • conducting post-incident review.

Particular attention should be given to data reconciliation following manual or alternative processing.

The objective is to prevent continuity arrangements themselves from creating subsequent operational, financial or information-integrity problems.

 

Key Deliverables

PD should generate:

  • Business Continuity Plan;
  • activation procedures;
  • escalation procedures;
  • communication procedures;
  • business recovery procedures;
  • contact information;
  • resource checklists;
  • alternate-workplace procedures;
  • ICT recovery interfaces; and
  • return-to-normal procedures.
Table:  Plan Development Requirements

PD Component

Objective

Main Procedure

Responsible Role

Required Supporting Information

Activation

Formally initiate continuity arrangements

Assess criteria, authorise activation and notify teams

Plan Owner/ Authorised Management

Activation criteria and authority matrix

Escalation

Ensure disruption receives appropriate management attention

Escalate based on impact and severity

Incident/Business Management

Escalation thresholds

Team mobilisation

Assemble required recovery personnel

Notify and mobilise recovery teams

Team Leader

Contact lists and call tree

Damage assessment

Establish operational consequences

Assess affected people, premises, technology and activities

Recovery Team

CBF and dependency information

Workplace recovery

Provide alternate operating capability

Activate remote or alternate workspace

Facilities/ICT/Business Team

Approved workplace strategy

ICT recovery

Restore technology supporting CBFs

Activate Disaster Recovery procedures

ICT

RTO, RPO and application priorities

Business recovery

Resume priority activities

Execute approved recovery procedures

CBF Owner/Recovery Team

RTO, MBCO and strategy

Communications

Maintain controlled stakeholder information

Prepare, approve and distribute communications

Communications/Management

Stakeholder and contact information

Resource management

Provide minimum recovery resources

Allocate personnel, equipment and services

Recovery Team

Resource checklist

Return to normal

Restore normal operating arrangements

Reconcile, migrate, restore and stand down

CBF Owner

Restoration criteria and reconciliation requirements

Post-incident review

Capture improvement opportunities

Review performance and identify corrective actions

BCM Programme Manager

Incident logs and recovery records

 

Damanat-Specific PD Requirements

Damanat's continuity procedures should incorporate, where applicable:

  • preservation of delegated and approval authorities;
  • controlled handling of mortgage guarantee and supporting records;
  • retention of decision and transaction audit trails;
  • secure communications;
  • controlled access to sensitive information;
  • coordination with financial institutions and other relevant external parties;
  • maintenance of accurate stakeholder information;
  • secure operation under remote or alternate arrangements; and
  • protection of confidential information during degraded operations.

Temporary continuity arrangements should not unintentionally bypass essential governance, financial, legal, information-security or approval controls.

The objective is controlled degradation, not uncontrolled relaxation of organisational safeguards.

The Business Continuity Plan Development Phase is the process by which Damanat's continuity strategies are translated into practical, executable recovery procedures.

By establishing a standardised BC Plan structure, defining a recovery organisation, conducting plan-writing workshops, and validating completed plans, Damanat can ensure that each critical business function has clear guidance for responding to disruptions.

Well-developed BC Plans enable Damanat to continue essential regulatory activities, protect critical information assets, maintain stakeholder confidence, and fulfil its statutory obligations during adverse events.

As required by ISO 22301, these plans should be regularly reviewed, updated, and tested to ensure they remain effective and aligned with the evolving operational and regulatory environment.

The completion of this phase provides the foundation for the next stage of the BCM Planning Methodology—Testing and Exercising—where the effectiveness of the plans will be validated through structured exercises and simulations.

 

eBook 2: Implementing Business Continuity Management
C1 C2 C3 C4 C5
C6 C7 C8 C9 C10
 

More Information About Business Continuity Management Courses

To learn more about the course and schedule, click the buttons below for BCM-300 Business Continuity Management Implementer [BCM-3] and BCM-5000 Business Continuity Management Expert Implementer [BCM-5]

 

Please feel free to send us a note if you have any questions.