eBook 2: Chapter 7
Testing and Exercising Phase as Part of the BCM Planning Methodology for
The Saudi Mortgage Guarantees Services Company
Introduction
The Testing and Exercising (TE) phase is the stage of the Business Continuity Management (BCM) Planning Methodology in which the Saudi Mortgage Guarantees Services Company (Damanat) validates whether its Business Continuity Plans, recovery strategies, personnel, technology, facilities and external dependencies can operate effectively during a disruptive incident.
The preceding Plan Development phase establishes what Damanat intends to do when normal operations are disrupted. Testing and Exercising determines whether those documented arrangements can actually be executed.
This distinction is fundamental.
A Business Continuity Plan may state that employees will relocate, work remotely, switch to alternative communication channels, implement manual workarounds, or recover critical technology in a disaster recovery environment.
Until those arrangements are exercised, however, Damanat cannot be sufficiently assured that they will meet the recovery requirements established in the Business Impact Analysis (BIA).
Testing and Exercising therefore moves BCM from:
“We have documented our recovery arrangements.”
to:
“We have demonstrated that our recovery arrangements can work.”
For Damanat, exercises should progressively validate the continuity of Critical Business Functions, such as Mortgage Guarantee Origination, and their supporting people, processes, technology, information, premises, participating financial institutions, and third-party service providers.
The exercise programme should be progressive. It should begin with relatively simple activities designed to validate individual components and familiarise personnel with their responsibilities.
As organisational capability matures, Damanat should progress toward increasingly complex exercises involving multiple Business Units, technology recovery, external dependencies, senior management and realistic disruption scenarios.
For the purpose of this methodology, the exercise programme is divided into two broad groups:
Initial Tests
- Component Tests
- Call Notification Tests
- Walkthrough Exercises
Advanced Tests
- Integrated Tests
- Simulation Tests
- Live Tests
The progression can therefore be represented as:
Component → Call Notification → Walkthrough → Integrated → Simulation → Live
This progressive approach allows Damanat to build capability before exposing the organisation to increasingly demanding and operationally complex exercises.
Purpose of Testing and Exercising
The purpose of Testing and Exercising is not simply to demonstrate regulatory compliance.
An effective exercise programme should determine whether Damanat can:
- activate Business Continuity Plans;
- mobilise recovery teams;
- communicate effectively during disruption;
- continue Critical Business Functions;
- achieve approved recovery objectives;
- recover critical technology;
- operate from alternate workplaces;
- use manual or alternative procedures;
- coordinate across Business Units;
- work with participating financial institutions;
- coordinate critical suppliers;
- make decisions under pressure;
- manage escalating incidents;
- recover critical data;
- maintain minimum service levels; and
- return safely to normal operations.
Testing should also identify weaknesses before those weaknesses are exposed during a real incident.
The principle should therefore be:
An exercise is successful when it provides reliable evidence about capability and identifies opportunities for improvement—not simply when participants complete the scenario without difficulty.
Relationship Between Plan Development and Testing
The Plan Development and Testing and Exercising phases are closely connected.
The Plan Development phase establishes:
What should happen.
Testing and Exercising determines:
Whether it can happen.
For example, Damanat's BCP may state:
Mortgage Guarantee Origination will continue through remote working if the primary workplace becomes unavailable.
An exercise should determine whether:
- employees can receive the activation notification;
- designated personnel know their roles;
- remote connectivity is available;
- authentication works;
- critical applications can be accessed;
- required information is available;
- approval authorities remain operational;
- participating financial institutions can communicate with Damanat; and
- the required MBCO can be achieved.
Exercise findings then feed back into the BCP.
The improvement cycle becomes:
Plan → Exercise → Observe → Identify Gaps → Correct → Update Plan → Re-test
Establishing the Damanat Testing and Exercising Programme
Damanat should establish an annual or multi-year exercise programme covering its Critical Business Functions and supporting resources.
The programme should identify:
- plans to be exercised;
- Critical Business Functions covered;
- exercise type;
- exercise objectives;
- disruption scenarios;
- participating Business Units;
- supporting technology;
- third-party involvement;
- exercise frequency;
- exercise dates;
- observers;
- evaluation methodology; and
- reporting requirements.
Not every exercise needs to test everything simultaneously.
A progressive programme allows Damanat to validate individual capabilities before combining them into more complex exercises.
Progressive Exercise Maturity
Damanat's exercise programme can be structured as follows:
|
Level |
Exercise Type |
Primary Purpose |
Complexity |
|
Initial |
Component Test |
Validate individual recovery components |
Low |
|
Initial |
Call Notification Test |
Validate communications and mobilisation |
Low |
|
Initial |
Walkthrough Exercise |
Review plans and procedures collectively |
Low–Moderate |
|
Advanced |
Integrated Test |
Validate multiple interconnected capabilities |
Moderate–High |
|
Advanced |
Simulation Test |
Validate decision-making under realistic conditions |
High |
|
Advanced |
Live Test |
Demonstrate operational recovery capability |
Very High |
The progression should not be interpreted as meaning that initial exercises become unnecessary once advanced exercises begin.
Component, notification and walkthrough exercises should continue to be used whenever appropriate.
Initial Tests
Initial tests provide the foundation for Damanat's exercise programme.
They are designed to verify individual components of the continuity arrangements, familiarise employees with their responsibilities and identify basic weaknesses before more complex exercises are attempted.
The three initial tests are:
- Component Tests
- Call Notification Tests
- Walkthrough Exercises
Component Tests
A Component Test validates a specific element of a Business Continuity or recovery arrangement rather than testing the entire plan.
Components may include:
- backup restoration;
- remote-access capability;
- alternative workplace equipment;
- emergency communications;
- application recovery;
- data restoration;
- power backup;
- manual processing procedures;
- emergency contact information;
- alternate approval procedures; or
- supplier escalation arrangements.
Component testing allows weaknesses to be isolated and corrected before the component is incorporated into a broader exercise.
Example of a Damanat Component Test
Consider Damanat's Mortgage Guarantee Origination function.
A component test could validate whether selected employees can access the mortgage guarantee processing environment remotely.
Objective
Confirm that designated recovery personnel can securely access the required application from an approved remote location.
Test Activities
Participants:
- receive instructions to activate remote access;
- authenticate using the approved security mechanism;
- connect to the required environment;
- access the guarantee-processing application;
- retrieve a designated test record;
- perform an approved test transaction; and
- confirm successful completion.
Success Criteria
The component test may be considered successful if:
- designated employees can authenticate;
- required systems are accessible;
- application performance is acceptable;
- required information is available; and
- the activity can be completed within the predetermined recovery requirement.
If ten designated employees are expected to operate remotely but only six can successfully access the application, the test has identified a continuity capability gap requiring remediation.
Technology Component Tests
Technology component tests are particularly important because many Damanat Critical Business Functions may depend upon electronic processing.
Examples include:
- restoring a database from backup;
- validating application failover;
- testing network redundancy;
- validating alternative telecommunications;
- testing backup power;
- restoring selected servers;
- testing identity and authentication services;
- verifying data replication; and
- testing interfaces with external systems.
Technology tests should be coordinated with Business Unit representatives whenever the recovered technology must ultimately support business operations.
A technically successful system recovery does not necessarily mean that the business service has recovered.
Call Notification Tests
A Call Notification Test validates whether Damanat can contact and mobilise designated personnel during a disruption.
The test should determine whether:
- contact information is accurate;
- notification mechanisms work;
- employees receive the notification;
- employees acknowledge receipt;
- alternates can be contacted;
- escalation occurs where personnel cannot be reached; and
- notification can be completed within the required timeframe.
The test may use:
- telephone calls;
- SMS;
- emergency notification systems;
- approved messaging platforms;
- email; or
- a combination of channels.
Example of a Damanat Call Notification Test
Suppose the Mortgage Guarantee Origination recovery team contains 20 designated employees.
The BCM Coordinator initiates a notification test.
The exercise records:
|
Measure |
Result |
|
Personnel to be contacted |
20 |
|
Successfully contacted |
18 |
|
Contact details incorrect |
1 |
|
No response |
1 |
|
Target notification time |
30 minutes |
|
Actual completion time |
24 minutes |
The test has therefore identified two issues requiring follow-up even though the overall notification time was achieved.
The objective is not simply to establish that a telephone number exists in the BCP. It is to confirm that the recovery team can actually be mobilised.
Walkthrough Exercises
A Walkthrough Exercise brings relevant plan owners and recovery personnel together to systematically review the BCP and discuss how they would respond to a specified disruption.
Unlike a simple document review, participants actively work through the plan.
The facilitator may present a scenario such as:
“Damanat's primary office will remain inaccessible for the next 48 hours. Critical technology services remain available.”
Participants then explain:
- whether the BCP should be activated;
- who has activation authority;
- who must be contacted;
- which Critical Business Functions require priority attention;
- where employees will work;
- what resources are required;
- which suppliers must be contacted;
- how participating financial institutions will be informed; and
- how management will receive situation reports.
Example of a Damanat Walkthrough
Consider the following scenario:
At 8:00 a.m., employees are informed that Damanat's primary workplace cannot be occupied because of a major building infrastructure failure. Access will not be possible for at least three working days.
Participants could be asked:
Activation
Who determines whether the BCP should be activated?
People
Which employees must become operational first?
Workplace
Can priority employees work remotely?
Technology
Can employees access all required applications remotely?
Business Functions
Which mortgage guarantee activities must continue first?
External Parties
Which participating financial institutions need to be informed?
Suppliers
Which suppliers need to support the alternate operating arrangements?
Communications
How will employees receive instructions?
Management
How will recovery status be reported?
The walkthrough can reveal gaps without interrupting live operations.
Moving from Initial to Advanced Tests
Once Damanat has demonstrated reasonable competence in component, notification and walkthrough exercises, the organisation should progress to more advanced exercises.
The objective changes from validating isolated components to validating interconnected organisational capability.
Advanced tests include:
- Integrated Tests
- Simulation Tests
- Live Tests
These exercises require greater involvement in planning, coordination, control, and management.
Integrated Tests
An Integrated Test validates the interaction between multiple Business Units, plans, technologies, recovery teams and external dependencies.
This is particularly important because Critical Business Functions rarely operate independently.
For example, Mortgage Guarantee Origination may depend on:
**Business Operations
- Technology
- Risk
- Records
- Communications
- Participating Financial Institutions
- External Service Providers**
An integrated exercise determines whether these dependencies can recover together.
Example of a Damanat Integrated Test
Damanat could conduct an integrated test in response to the loss of its primary technology environment.
Participants could include:
- Mortgage Guarantee Origination;
- IT;
- Risk Management;
- Finance;
- Customer or Financial Institution Support;
- BCM;
- Crisis Management;
- Communications; and
- selected technology providers.
The test might require:
- detection of technology failure;
- incident escalation;
- BCP activation;
- technology DR activation;
- recovery of critical applications;
- business-user validation;
- activation of alternative communications;
- processing of selected test transactions;
- verification of external interfaces; and
- management reporting.
The objective is to determine whether the entire recovery chain works, not merely whether the server can be restarted.
Testing Interdependencies
Integrated tests are particularly useful for identifying conflicting recovery assumptions.
For example:
Mortgage Guarantee Origination RTO: 4 hours
Required Technology Recovery: 4 hours
Required External Interface Recovery: 6 hours
Required Data Service Recovery: 8 hours
The business function cannot realistically recover within four hours if essential dependencies require six or eight hours.
An integrated exercise exposes such inconsistencies.
The findings should then be returned to the BIA, BCS or BCP for corrective action.
Simulation Tests
A Simulation Test creates a realistic but controlled disruption scenario in which participants must respond to evolving events.
Unlike a walkthrough, where participants primarily discuss actions, a simulation requires them to make decisions and perform selected response activities as though the event were actually occurring.
Simulations can include:
- timed scenario injects;
- changing incident conditions;
- simulated media enquiries;
- simulated regulator communications;
- supplier failures;
- employee issues;
- technology complications;
- customer enquiries;
- conflicting information; and
- management decision points.
The objective is to evaluate behaviour, coordination, decision-making and plan effectiveness under pressure.
Example: Damanat Cyber Disruption Simulation
A Damanat simulation could begin with:
9:00 a.m. – Employees report that the mortgage guarantee processing platform is unavailable.
The exercise then evolves.
Inject 1 — 9:15 a.m.
IT identifies unusual activity and suspects a cyber incident.
Inject 2 — 9:30 a.m.
Remote access to several critical applications is suspended as a precaution.
Inject 3 — 10:00 a.m.
Participating financial institutions begin requesting information about delayed guarantee applications.
Inject 4 — 10:30 a.m.
Technology teams advise that normal recovery may take more than eight hours.
Inject 5 — 11:00 a.m.
Senior management requests an assessment of business impact and recovery options.
Inject 6 — 12:00 p.m.
A critical third-party technology provider reports that one of its services is also affected.
Participants must determine:
- whether to activate BCPs;
- whether to escalate to crisis management;
- what activities should be prioritised;
- whether alternative procedures should be activated;
- how financial institutions should be informed;
- how technology recovery should proceed;
- what information should be escalated to management; and
- what regulatory notifications may be required.
This creates a realistic decision-making environment without deliberately disrupting production operations.
Testing Crisis Management Integration
SAMA specifically expects BCP testing scenarios to cover activation and involvement of the crisis management team.
Damanat's advanced exercises should therefore validate the interface between:
Incident Management → Business Continuity → Technology Recovery → Crisis Management
The exercise should test:
- escalation criteria;
- decision authority;
- situation reporting;
- strategic decision-making;
- resource prioritisation;
- stakeholder communications;
- coordination between business and technology recovery; and
- return-to-normal decisions.
This prevents BCM and crisis management from operating as separate structures during a major disruption.
Live Tests
A Live Test is the most advanced form of exercise in this methodology.
It requires selected continuity or recovery arrangements to be physically activated rather than merely discussed or simulated.
Examples may include:
- relocating employees to an alternate workplace;
- operating Critical Business Functions from the recovery location;
- processing controlled transactions through recovery infrastructure;
- switching selected services to an alternate environment;
- using alternative telecommunications;
- operating under minimum staffing levels; or
- conducting business operations through approved continuity arrangements for a defined period.
Live tests provide strong evidence of actual recovery capability but also create greater operational risk.
They must therefore be carefully planned and controlled.
Example of a Damanat Live Test
Damanat could conduct a controlled live exercise involving selected Mortgage Guarantee Origination personnel.
The exercise could require participants to:
- receive a BCP activation notification;
- leave the normal operating arrangement;
- activate the designated recovery environment;
- connect to critical applications;
- establish communications;
- access required records;
- process controlled test transactions;
- demonstrate approval capability;
- maintain the minimum required service level; and
- return to normal operations.
The test should have safeguards to prevent unintended effects on live customer or financial institution transactions.
Live Test Risk Assessment
Before conducting a live exercise, Damanat should perform an exercise risk assessment.
Potential risks include:
- unintended service interruption;
- data corruption;
- duplicate transactions;
- customer impact;
- external stakeholder confusion;
- employee safety;
- production system instability;
- cybersecurity exposure; and
- inability to return to normal operations.
Controls may include:
- test-data segregation;
- controlled participant groups;
- rollback procedures;
- technical monitoring;
- management approval;
- exercise stop criteria; and
- dedicated exercise controllers.
The objective of exercising BCM should never be to create an unacceptable operational risk.
Comparison of Initial and Advanced Tests
|
Exercise Type |
Level |
Primary Focus |
Damanat Example |
|
Component Test |
Initial |
Individual recovery capability |
Restore selected guarantee-processing data |
|
Call Notification Test |
Initial |
Recovery-team mobilisation |
Contact Mortgage Guarantee Origination recovery personnel |
|
Walkthrough Exercise |
Initial |
Plan understanding |
Discuss response to three-day office loss |
|
Integrated Test |
Advanced |
Cross-functional recovery |
Business + IT + suppliers recover mortgage guarantee processing |
|
Simulation Test |
Advanced |
Decision-making under pressure |
Cyberattack affecting guarantee operations |
|
Live Test |
Advanced |
Actual operational capability |
Operate selected activities through recovery arrangements |
Each exercise provides a different form of assurance.
A mature Damanat exercise programme should use a combination of these approaches.
Developing Exercise Scenarios
Exercise scenarios should be selected from credible threats identified through the Risk Analysis and Review.
Examples relevant to Damanat could include:
- primary workplace unavailable;
- mortgage guarantee processing platform failure;
- cyberattack or ransomware;
- telecommunications outage;
- critical data corruption;
- widespread personnel unavailability;
- third-party technology provider failure;
- external interface disruption;
- prolonged power failure;
- simultaneous technology and workplace disruption; and
- disruption affecting a participating financial institution interface.
Scenarios should become progressively more complex as exercise maturity increases.
Scenario Selection Based on RAR and BIA
Exercise selection should not be arbitrary.
The scenario should connect:
RAR → BIA → BCS → PD → Exercise
For example:
RAR
Identifies cyberattack as a significant threat.
BIA
Identifies Mortgage Guarantee Origination as requiring recovery within a predetermined RTO.
BCS
Establishes technology DR and temporary processing arrangements.
PD
Documents activation and recovery procedures.
Exercise
Simulates a cyberattack and tests whether those arrangements can achieve the recovery requirement.
This traceability demonstrates that the exercise programme validates risks and capabilities relevant to Damanat.
Exercise Objectives
Every exercise should have clearly defined objectives.
Examples include:
- validate BCP activation;
- verify employee notification;
- validate recovery-team roles;
- confirm remote-working capability;
- validate alternate workplace readiness;
- demonstrate technology recovery;
- achieve a specified RTO;
- validate RPO;
- demonstrate MBCO;
- verify supplier response;
- test crisis escalation;
- validate external communication;
- identify plan weaknesses; and
- test return-to-normal procedures.
An exercise should not simply have the objective:
“Test the Business Continuity Plan.”
That is too broad to provide meaningful evaluation.
Exercise Success Criteria
Objectives should have measurable success criteria.
For example:
Objective
Validate notification of the Mortgage Guarantee Origination recovery team.
Success Criteria
95 percent of designated personnel acknowledge notification within 30 minutes.
Objective
Validate technology recovery.
Success Criteria
Critical processing capability becomes available within the approved RTO.
Objective
Validate minimum operating capability.
Success Criteria
The recovery environment demonstrates the ability to support the approved MBCO.
Clear criteria make exercise evaluation evidence-based.
Exercise Participants and Roles
A structured exercise may involve several roles.
Participants
Individuals expected to respond to the scenario.
Facilitators
Guide the exercise.
Exercise Controllers
Manage scenario progression and injects.
Observers
Observe performance without directing participants.
Evaluators
Assess performance against objectives.
Technical Support
Ensures safe operation of exercise technology.
Senior Management
Participates where escalation and crisis management are being tested.
Clear separation of these roles improves the objectivity of the exercise.
Third-Party Participation
Damanat should progressively include critical third parties in exercises in which those organisations are part of the recovery strategy.
Participants may include:
- technology providers;
- telecommunications providers;
- critical outsourced service providers;
- facilities providers; and
- other parties supporting Critical Business Functions.
SAMA's BCM Framework also requires key service providers supporting critical activities to have continuity plans and to test them at least yearly.
For Damanat, supplier participation can reveal whether contractual recovery commitments can actually support its BIA-derived recovery requirements.
Testing RTO, RPO and MBCO
Exercises should progressively validate the recovery objectives established during the BIA.
Recovery Time Objective
Did the activity recover within the required time?
Recovery Point Objective
Was data recovered to the required point?
Minimum Business Continuity Objective
Could the required minimum level of activity be sustained?
For example:
RTO: 4 hours
Actual Recovery: 5 hours 20 minutes
The exercise has identified a recovery gap of 1 hour 20 minutes.
The appropriate response is not to redefine the exercise as successful. Damanat should determine why the recovery requirement was missed and establish corrective action.
Exercise Evaluation
Immediately after an exercise, participants should conduct a structured debrief.
The evaluation should identify:
What Worked?
Capabilities demonstrated successfully.
What Did Not Work?
Failures or difficulties.
What Was Missing?
Resources, information, procedures or capabilities that were unavailable.
What Was Unclear?
Roles, responsibilities, escalation or procedures that caused confusion.
What Must Improve?
Corrective actions required before the next exercise.
This information should be documented in an exercise report.
Exercise Report
The exercise report should include:
- exercise title;
- date;
- scope;
- scenario;
- participants;
- objectives;
- success criteria;
- timeline;
- observations;
- achievements;
- deficiencies;
- lessons learned;
- corrective actions;
- responsible owners;
- target dates; and
- requirement for re-testing.
The report should provide an evidence trail demonstrating that the exercise was performed and that findings were addressed.
Corrective Action Management
The value of an exercise depends heavily on what Damanat does with the findings.
Each significant finding should be tracked as a corrective action.
For example:
|
Finding |
Required Action |
Owner |
Target |
|
Recovery-team contacts outdated |
Update notification directory |
BCM Coordinator |
2 weeks |
|
Remote capacity insufficient |
Increase concurrent-user capacity |
IT |
2 months |
|
Supplier recovery exceeds required RTO |
Review supplier recovery arrangement |
Procurement |
3 months |
|
Approval authority unclear |
Update delegation procedure |
Business Unit Head |
1 month |
|
BCP missing reconciliation procedure |
Update BCP |
BCM Coordinator |
1 month |
Actions should remain open until satisfactory evidence confirms completion.
Re-Testing
Where an exercise identifies a significant failure, Damanat should re-test the affected capability after corrective actions have been implemented.
This establishes the cycle:
Test → Failure Identified → Root Cause → Corrective Action → Re-test → Validate
A failed test is therefore not the end of the exercise process.
It triggers improvement and subsequent validation.
SAMA Regulatory Requirements for Testing and Exercising
The Saudi Central Bank (SAMA) Business Continuity Management Framework contains explicit requirements for testing.
The framework is currently identified by SAMA as In-Force, and its stated scope includes the banking sector, finance sector, payment systems/payment service providers and credit bureaus.
Section 2.9 – Testing establishes the principle that applicable Member Organisations should define, approve, implement, execute and monitor regular BCP and DRP tests.
The stated objective is both to verify that the plans operate as defined and to train employees and relevant third parties to execute them.
For BCP testing specifically, SAMA requires periodic simulation exercises at least annually. Scenarios should be appropriately planned, have clearly defined objectives, cover relevant functions, services, processes, locations or severe scenarios, and take cybersecurity scenarios into consideration.
Scenarios should also involve activation of the crisis management team. After individual tests have been completed, organisations should consider an integrated BCM test covering critical services, business processes and functions.
SAMA separately requires DR testing combined with BCP testing at least annually.
The test should evaluate the readiness and capability of the disaster recovery infrastructure supporting critical systems and generate recommendations for improvement.
Crisis management involvement is also expected.
SAMA Requirements Following an Exercise
SAMA's requirements extend beyond conducting the exercise itself.
Detailed results should be documented and should confirm whether exercise objectives were achieved and recovery resources were capable and ready.
Lessons learned and required improvements should be documented. Where a test fails, the root cause and remediation actions should be identified and tracked.
Importantly, when re-testing is required following a failure, the SAMA framework specifies that the defined re-test timeline should not exceed 3 months.
The framework also expects Internal Audit or a qualified external auditor to observe business continuity and disaster recovery testing as an independent participant, providing assurance over execution and results.
BCP and DRP test results should be reported to the BCM Committee, senior management and board.
For Damanat, these expectations should be built directly into the exercise methodology rather than treated as post-exercise administrative activities.
Translating SAMA Requirements into Damanat's Exercise Programme
For practical implementation, Damanat should establish the following minimum controls:
|
SAMA Testing Expectation |
Damanat Implementation |
|
Regular BCP and DRP testing |
Maintain an approved annual exercise programme |
|
BCP simulation at least annually |
Conduct at least one suitable annual BCP simulation |
|
Clearly defined scenarios and objectives |
Maintain an approved exercise plan |
|
Cybersecurity scenarios |
Include cyber disruption in the exercise programme |
|
Crisis Management Team involvement |
Include escalation and crisis activation in advanced exercises |
|
Integrated BCM testing |
Progressively test multiple CBFs and dependencies together |
|
DR combined with BCP at least annually |
Validate technology recovery with business participation |
|
Document results |
Produce formal exercise reports |
|
Validate recovery resources |
Test people, technology, facilities and dependencies |
|
Lessons learned |
Conduct post-exercise review |
|
Root-cause analysis for failure |
Document causes rather than symptoms |
|
Corrective-action tracking |
Maintain an improvement register |
|
Re-test following failure |
Re-test within the applicable timeframe, not exceeding three months under the framework |
|
Independent observation |
Involve Internal Audit or qualified external assurance |
|
Management reporting |
Report results through BCM governance and senior management |
This creates traceability between Damanat's exercise programme and the relevant regulatory testing expectations.
Testing and Exercising Deliverables
At the conclusion of the TE phase, Damanat should maintain, at minimum:
|
Ref |
Deliverable |
Purpose |
|
TE-01 |
Testing and Exercising Methodology |
Defines exercise approach |
|
TE-02 |
Annual Exercise Programme |
Establishes planned exercises |
|
TE-03 |
Exercise Scenario Catalogue |
Provides credible disruption scenarios |
|
TE-04 |
Exercise Plan |
Defines scope, objectives and participants |
|
TE-05 |
Exercise Risk Assessment |
Controls exercise-related operational risk |
|
TE-06 |
Exercise Scripts / Injects |
Supports simulations |
|
TE-07 |
Observation Records |
Captures performance |
|
TE-08 |
Exercise Report |
Documents results |
|
TE-09 |
Lessons Learned Register |
Records improvement opportunities |
|
TE-10 |
Corrective Action Register |
Tracks remediation |
|
TE-11 |
Re-Testing Records |
Demonstrates remediation effectiveness |
|
TE-12 |
Management Reporting |
Provides governance oversight |
|
TE-13 |
Exercise Evidence |
Demonstrates execution and participation |
Completion Criteria for the Testing and Exercising Phase
Damanat should consider the TE phase effective when:
- an approved exercise methodology exists;
- an exercise programme has been established;
- Critical Business Functions are progressively covered;
- initial tests are conducted;
- advanced exercises are introduced as maturity increases;
- scenarios reflect RAR findings;
- BIA recovery objectives are tested;
- BCP activation is validated;
- Crisis Management involvement is tested where appropriate;
- technology recovery is integrated with business recovery;
- critical suppliers are included where relevant;
- RTO, RPO and MBCO are validated where practical;
- results are formally documented;
- lessons learned are identified;
- failures undergo root-cause analysis;
- corrective actions have accountable owners;
- re-testing is performed where required;
- results are reported through appropriate governance; and
- plans and strategies are updated based on findings.
Building Exercise Maturity at Damanat
Testing and Exercising should evolve as Damanat's BCM capability matures.
An illustrative maturity progression is:
Year / Stage 1 — Validate Components
Component tests and call notification exercises.
Year / Stage 2 — Validate Plans
Walkthrough exercises for individual Business Units.
Year / Stage 3 — Validate Interdependencies
Integrated tests involving multiple functions.
Year / Stage 4 — Validate Decision-Making
Complex simulation exercises.
Year / Stage 5 — Demonstrate Operational Capability
Controlled live exercises.
This does not mean Damanat must wait several years before conducting advanced exercises. The progression should reflect actual capability, risk and regulatory requirements.
The key principle is to avoid moving directly into highly complex exercises before fundamental recovery capabilities have been validated.
Testing as Evidence of Organisational Resilience
Testing and exercising provide evidence that Damanat's BCM arrangements extend beyond documentation.
A mature BCM capability should be able to demonstrate:
Plan Exists
→ Personnel Understand It
→ Resources Are Available
→ Procedures Can Be Executed
→ Recovery Objectives Can Be Achieved
→ Weaknesses Are Corrected
→ Capability Is Re-tested
This evidence is valuable not only for BCM management but also for senior management, internal audit, regulators and other assurance stakeholders.
The Testing and Exercising phase is the mechanism through which The Saudi Mortgage Guarantees Services Company validates that its Business Continuity capability can operate during a disruption, rather than merely exist in documentation.
For Damanat, testing should be progressive.
The organisation should begin with Initial Tests:
Component Tests validate individual continuity and recovery capabilities.
Call Notification Tests determine whether recovery personnel can be contacted and mobilised.
Walkthrough Exercises ensure that plan owners and recovery personnel understand the Business Continuity Plan and can work through the required response and recovery actions.
Once these capabilities have been established, Damanat should progress toward Advanced Tests:
Integrated Tests validate the interactions among Business Units, technology, suppliers, and other dependencies.
Simulation Tests expose participants to realistic, evolving disruption scenarios that require decision-making, escalation, and coordination.
Live Tests provide the highest level of operational validation by physically activating selected continuity and recovery arrangements under carefully controlled conditions.
The progression is therefore:
Component → Call Notification → Walkthrough → Integrated → Simulation → Live
Each stage provides a different level of assurance.
For Damanat, exercises should ultimately determine whether the complete recovery chain works:
Incident Detection
→ Escalation
→ BCP Activation
→ Recovery-Team Mobilisation
→ Crisis Management
→ Continuity Strategy Activation
→ Critical Business Function Recovery
→ Technology Recovery
→ External Coordination
→ Minimum Service Delivery
→ Stabilisation
→ Return to Normal
The exercise programme should also remain directly connected to the earlier phases of the BCM Planning Methodology.
-
RAR identifies the disruption scenarios to consider.
-
BIA establishes the recovery requirements that should be validated.
-
BCS establishes the recovery solutions that should be tested.
-
PD establishes the procedures that participants should execute.
-
TE determines whether the complete arrangement actually works.
Most importantly, testing should not be judged solely by whether an exercise was completed successfully.
An exercise that exposes weaknesses in Damanat's remote-access capacity, technology recovery, supplier arrangements, decision authority, communication procedures or cross-functional dependencies has produced valuable information.
The critical requirement is that these findings lead to action.
The improvement cycle should therefore continue:
Exercise → Observe → Learn → Correct → Update → Re-test
This approach also supports the expectations established in the Saudi Central Bank's BCM Framework for regular BCP and DRP testing, annual simulation and DR testing, appropriately designed scenarios, crisis-management involvement, integrated BCM testing, documented results, corrective action and re-testing following significant failure.
Once Damanat has established this testing discipline, the BCM Planning Methodology moves into its final lifecycle phase—Program Management (PgM).
The focus then changes from:
“Can our Business Continuity Plans work?”
to:
“How do we ensure that Damanat's entire BCM capability remains current, competent, tested, governed and continually improved?”
Program Management provides the governance, maintenance, training, awareness, assurance, and continual improvement mechanisms required to sustain Damanat's Business Continuity capability over time.
| eBook 2: Implementing Business Continuity Management | ||||
| C1 | C2 | C3 | C4 | C5 |
![]() |
![]() |
![]() |
![]() |
![]() |
| C6 | C7 | C8 | C9 | C10 |
![]() |
![]() |
![]() |
![]() |
![]() |
More Information About Business Continuity Management Courses
To learn more about the course and schedule, click the buttons below for BCM-300 Business Continuity Management Implementer [BCM-3] and BCM-5000 Business Continuity Management Expert Implementer [BCM-5]
![]() |
||
![]() |
![]() |
![]() |
![]() |
Please feel free to send us a note if you have any questions. |
![]() |
![]() |
![]() |
![]() |


![[BCM] [Damanat] [Full Banner] Implementing BCM for The Saudi Mortgage Guarantees Services Company](https://no-cache.hubspot.com/cta/default/3893111/221734db-8c33-48bd-8147-fc740eecaf83.png)


![[BCM] [Damanat] [E2] [C7] Testing and Exercising](https://no-cache.hubspot.com/cta/default/3893111/ed03c310-870a-482d-bac6-446897084091.png)
![Banner [Summary] [BCM] [E2] [C7] Testing and Exercising](https://no-cache.hubspot.com/cta/default/3893111/af76bb57-f906-4422-8548-3912930c76a7.png)
![[BCM] [Damanat] [3/4 Banner] Implementing BCM for The Saudi Mortgage Guarantees Services Company](https://no-cache.hubspot.com/cta/default/3893111/0252380a-b2dc-4059-be10-b5566002b711.png)
![[BCM] [Damanat] [E2] [C1] Business Continuity Management Planning Methodology](https://no-cache.hubspot.com/cta/default/3893111/b17b614b-c36c-4437-95ca-5c1d44ac6ce3.png)
![[BCM] [Damanat] [E2] [C2] Project Management](https://no-cache.hubspot.com/cta/default/3893111/4663bc6b-2e85-4e17-b6af-b5c784413b28.png)
![[BCM] [Damanat] [E2] [C3] Risk Analysis and Review](https://no-cache.hubspot.com/cta/default/3893111/5423f27a-6048-40c1-b55c-238fafb59648.png)
![[BCM] [Damanat] [E2] [C4] Business Impact Analysis](https://no-cache.hubspot.com/cta/default/3893111/7a3c1a1f-d7f6-4d5d-8fef-deedc7d91f63.png)
![[BCM] [Damanat] [E2] [C5] Business Continuity Strategy](https://no-cache.hubspot.com/cta/default/3893111/a27d7e1e-8571-421d-9467-cc02614820e1.png)
![[BCM] [Damanat] [E2] [C6] BCM Plan Development](https://no-cache.hubspot.com/cta/default/3893111/ebff27c2-d3e9-4f2c-9a4c-0534e01fa535.png)
![[BCM] [Damanat] [E2] [C8] Program Management](https://no-cache.hubspot.com/cta/default/3893111/f52be888-834d-480c-9149-1167d38f1147.png)
![[BCM] [Damanat] [E2] [C9] Summary](https://no-cache.hubspot.com/cta/default/3893111/dab5bc8f-3d96-444b-880f-78cf037fc906.png)
![[BCM] [Damanat] [E2] [C10] Back Cover](https://no-cache.hubspot.com/cta/default/3893111/351b85f0-d850-4dee-a5c0-55c2b37c3075.png)
![Register [BL-B-3]*](https://no-cache.hubspot.com/cta/default/3893111/ac6cf073-4cdd-4541-91ed-889f731d5076.png)



![FAQ [BL-B-3]](https://no-cache.hubspot.com/cta/default/3893111/b3824ba1-7aa1-4eb6-bef8-94f57121c5ae.png)
![Email to Sales Team [BCM Institute]](https://no-cache.hubspot.com/cta/default/3893111/3c53daeb-2836-4843-b0e0-645baee2ab9e.png)





