.

Implementing Business Continuity Management for The Saudi Mortgage Guarantees Services Company: An Enterprise Implementation Guide
BB-CAAS-E1-1

[BCM] [Damanat] [E2] [C8] Program Management

[BCM] [Damanat] [Full Banner] Implementing BCM for The Saudi Mortgage Guarantees Services Company

The Program Management (PgM) phase is the final phase of the Business Continuity Management (BCM) Planning Methodology for The Saudi Mortgage Guarantees Services Company (Damanat).

The preceding phases establish Damanat's BCM capability through a structured implementation process:

→ Project Management (PM)

→ Risk Analysis and Review (RAR)

→ Business Impact Analysis (BIA)

→ Business Continuity Strategy (BCS)

→ Plan Development (PD)

→ Testing and Exercising (TE)

→ Program Management (PgM)

While the earlier phases establish the initial capability, Program Management ensures that this capability remains effective over time.

This distinction is important.

Business functions change. Employees move into new roles. Technology platforms are replaced. Suppliers change. New products and services are introduced. Regulatory requirements evolve.

New threats emerge. Recovery strategies that were appropriate when initially developed may become inadequate several years—or even several months—later.

Without ongoing Program Management, a Business Continuity Plan can progressively become disconnected from the organisation it is intended to protect.

For Damanat, Program Management should therefore establish a continuous governance and improvement framework that covers BCM policy, management oversight, plan maintenance, BIA and risk review, training, awareness, testing, corrective actions, assurance, performance monitoring, and management review.

The objective is to transition BCM from an implementation project into an embedded organisational management capability.

New call-to-action

Dr Goh Moh Heng
Business Continuity Management Certified Planner-Specialist-Expert
Damanat Legal Disclaimer Banner

eBook 2: Chapter 8

New call-to-action

 

Program Management Phase for BCM Planning Methodology for 

for The Saudi Mortgage Guarantees Services Company

 

 

Introduction

[BCM] [Damanat] [E2] [C8] Program Management

The Program Management (PgM) phase is the final phase of the Business Continuity Management (BCM) Planning Methodology for The Saudi Mortgage Guarantees Services Company (Damanat).

The preceding phases establish Damanat's BCM capability through a structured implementation process:

  • Project Management (PM)

  • Risk Analysis and Review (RAR)

  • Business Impact Analysis (BIA)

  • Business Continuity Strategy (BCS)

  • Plan Development (PD)

  • Testing and Exercising (TE)

  • Program Management (PgM)

While the earlier phases establish the initial capability, Program Management ensures that this capability remains effective over time.

This distinction is important.

Business functions change. Employees move into new roles. Technology platforms are replaced. Suppliers change.

New products and services are introduced. Regulatory requirements evolve. New threats emerge. Recovery strategies that were appropriate when initially developed may become inadequate several years—or even several months—later.

Without ongoing Program Management, a Business Continuity Plan can progressively become disconnected from the organisation it is intended to protect.

For Damanat, Program Management should therefore establish a continuous governance and improvement framework that covers BCM policy, management oversight, plan maintenance, BIA and risk review, training, awareness, testing, corrective actions, assurance, performance monitoring, and management review.

The objective is to transition BCM from an implementation project into an embedded organisational management capability.

 

Purpose of Program Management

Earlier chapters focus largely on creating BCM capability. This chapter focuses on sustaining that capability.

It provides a practical framework through which Damanat can:New call-to-action

  • establish ongoing BCM governance;
  • maintain BCM policies and methodologies;
  • keep BIAs and risk assessments current;
  • maintain Business Continuity Strategies;
  • review and update Business Continuity Plans;
  • maintain employee competency;
  • promote BCM awareness;
  • manage Testing and Exercising;
  • track corrective actions;
  • monitor BCM performance;
  • conduct management reviews;
  • provide independent assurance; and
  • continually improve the BCM program.

Program Management should answer the fundamental question:

“How does Damanat ensure that the BCM capability developed through the preceding phases remains current, effective and ready for use?”

 

How This Chapter Benefits Damanat

This chapter benefits Damanat by providing the management structure required to move BCM from a periodic planning exercise into a sustainable organisational discipline.

Effective Program Management helps Damanat to:

Maintain Readiness

Business Continuity Plans and recovery arrangements remain aligned with current operating conditions.

Maintain Management Oversight

Senior management receives information on BCM capabilities, gaps, exercises, and improvement priorities.

Maintain Regulatory Alignment

Changes in applicable requirements can be incorporated into BCM policies, processes and evidence.

Maintain Employee Capability

Employees continue to understand their BCM responsibilities through training, awareness and exercises.

Maintain Recovery Capability

Changes to technology, suppliers, processes and resources are assessed for continuity implications.

Demonstrate Assurance

Damanat can provide evidence that its BCM arrangements are reviewed, tested, monitored and improved.

Support Continual Improvement

Lessons from incidents, exercises, audits and reviews are translated into measurable improvements.

The overall benefit is therefore the establishment of a living BCM program rather than a collection of static Business Continuity Plans.

 

From BCM Project to BCM Program

A distinction should be made between Project Management and Program Management.

Project Management is primarily concerned with implementing the BCM capability.

Program Management is concerned with sustaining it.

 

Project Management

Program Management

Establishes BCM

Sustains BCM

Defines initial scope

Maintains and reviews scope

Establishes governance

Operates governance

Conducts initial RAR and BIA

Periodically reviews RAR and BIA

Develops strategies

Reviews strategy effectiveness

Develops BCPs

Maintains BCPs

Establishes initial exercise program

Operates ongoing exercise cycle

Implements capability

Measures and improves capability

The transition occurs when the initial BCM implementation is substantially complete, and BCM activities move into a recurring management cycle.

 

Core Components of Damanat's BCM Program Management

Damanat's Program Management framework should include the following components:

  1. BCM governance and oversight.
  2. BCM policy and framework maintenance.
  3. RAR and BIA maintenance.
  4. Business Continuity Strategy maintenance.
  5. BCP maintenance.
  6. Testing and Exercising management.
  7. Training and competency.
  8. BCM awareness.
  9. Incident and exercise lessons learned.
  10. Corrective-action management.
  11. Supplier and third-party continuity oversight.
  12. BCM performance measurement.
  13. Internal review and assurance.
  14. Management review.
  15. Continual improvement.

These components collectively provide the mechanisms through which BCM remains embedded within normal organisational management.

 

BCM Governance and Oversight

Effective Program Management begins with governance.

Damanat should maintain a defined BCM governance structure that establishes:

  • senior management accountability;
  • BCM program ownership;
  • committee oversight;
  • Business Unit responsibilities;
  • BCM Coordinator responsibilities;
  • reporting requirements;
  • escalation arrangements; and
  • decision-making authority.

The BCM governance structure established during Project Management should therefore continue after the implementation project ends.

A typical governance model may include:

Board / Senior Management

BCM Committee

BCM Manager / BCM Function

Heads of Business Units

Business Unit BCM Coordinators

Business Continuity and Recovery Teams

Each level should understand its responsibilities.

 

BCM Committee

The BCM Committee should provide ongoing oversight of the program.

Its responsibilities may include:

  • reviewing BCM performance;
  • monitoring implementation status;
  • reviewing significant continuity risks;
  • approving BCM policies and methodologies;
  • reviewing BIA results;
  • reviewing recovery capability gaps;
  • monitoring exercise results;
  • tracking corrective actions;
  • reviewing major incidents;
  • addressing resource requirements;
  • reviewing supplier continuity concerns; and
  • escalating significant matters to senior management.

Meetings should be supported by documented agendas, minutes, decisions and action records.

 

BCM Policy and Framework Maintenance

Damanat's BCM Policy establishes the organisation's management commitment and overall requirements for business continuity.

The policy should be reviewed periodically and whenever significant changes occur.

The review should consider:

  • organisational changes;
  • regulatory changes;
  • changes in business strategy;
  • changes in Critical Business Functions;
  • major technology transformation;
  • significant outsourcing;
  • changes in operating locations;
  • lessons from incidents;
  • audit findings; and
  • exercise results.

Supporting methodologies should also remain aligned with the policy.

These may include:

  • RAR methodology;
  • BIA methodology;
  • BCS methodology;
  • BCP methodology;
  • Testing and Exercising methodology; and
  • BCM maintenance requirements.

 

Maintaining the Risk Analysis and Review

Threats and vulnerabilities change over time.

Damanat should therefore periodically review its BCM Threat and Risk Register.

The review should consider changes affecting:

People + Processes + Technology + Premises + Information + Suppliers + External Environment

Example

Suppose Damanat migrates its major mortgage-guarantee processing capability to a new technology platform.

The change could introduce:

  • new technology dependencies;
  • new service providers;
  • different recovery capabilities;
  • new cybersecurity risks;
  • changed backup arrangements; and
  • new external interfaces.

The existing RAR should therefore be reviewed rather than waiting for the next routine BCM cycle.

 

Maintaining the Business Impact Analysis

BIA information should also be periodically validated.

Business Units should confirm whether:

  • Critical Business Functions remain correctly identified;
  • impact assessments remain accurate;
  • RTOs remain appropriate;
  • RPOs remain appropriate;
  • MBCOs remain appropriate;
  • minimum staffing requirements have changed;
  • technology dependencies have changed;
  • premises requirements have changed;
  • supplier dependencies have changed; and
  • internal interdependencies remain accurate.
Damanat Example

If Mortgage Guarantee Origination becomes increasingly automated, its dependence on technology may increase while its minimum staffing requirements decrease.

The BIA should reflect these changes.

An outdated BIA leads directly to inappropriate recovery strategies.

 

Maintaining Business Continuity Strategies

Strategies should be periodically reviewed to determine whether they continue to meet approved recovery requirements.

Damanat should ask:

  • Can the strategy still achieve the RTO?
  • Can the required RPO still be achieved?
  • Can the MBCO be supported?
  • Are required employees still available?
  • Does the alternate workplace have sufficient capacity?
  • Is remote-access capacity sufficient?
  • Has technology architecture changed?
  • Are critical suppliers still contracted?
  • Have supplier recovery capabilities changed?
  • Are alternative communication arrangements still operational?
Example

A remote-working strategy designed when 30 employees needed recovery access may no longer be adequate if the current requirement is 80 employees.

Program Management should identify this capacity gap before an actual disruption.

 

Business Continuity Plan Maintenance

BCPs should be treated as controlled operational documents.

Damanat should establish a formal review cycle and event-driven update process.

Plan maintenance should verify:

  • contact information;
  • plan ownership;
  • recovery-team membership;
  • alternate personnel;
  • activation procedures;
  • recovery priorities;
  • technology dependencies;
  • supplier information;
  • workplace arrangements;
  • recovery procedures;
  • communication arrangements; and
  • return-to-normal procedures.

Updates should be subject to document control and appropriate approval.

 

Event-Driven Plan Reviews

BCPs should not be updated only according to a fixed calendar.

Certain changes should automatically trigger review.

Examples include:

  • organisational restructuring;
  • Business Unit reorganisation;
  • personnel changes affecting recovery roles;
  • relocation;
  • new technology;
  • major application upgrades;
  • supplier changes;
  • outsourcing;
  • new Critical Business Functions;
  • significant process changes;
  • actual incidents;
  • failed exercises; and
  • regulatory changes.
Damanat Example

If the primary BCM Coordinator for Mortgage Guarantee Origination leaves Damanat, the relevant BCP should be updated promptly rather than waiting for its next annual review.

 

Testing and Exercising Program Management

Testing and Exercising should operate as a recurring program rather than a collection of isolated tests.

Damanat should maintain an exercise schedule covering:

Initial Tests
  • Component Tests
  • Call Notification Tests
  • Walkthrough Exercises
Advanced Tests
  • Integrated Tests
  • Simulation Tests
  • Live Tests

The exercise program should identify:

  • plans to be tested;
  • exercise objectives;
  • Critical Business Functions;
  • exercise type;
  • participants;
  • scenarios;
  • third parties;
  • target dates;
  • results;
  • corrective actions; and
  • re-testing requirements.

Exercise maturity should increase progressively.

 

BCM Training and Competency

Employees with BCM responsibilities should possess the knowledge and skills required to perform their roles.

Training should be role-based.

Senior Management

Training should address:

  • BCM governance;
  • decision-making;
  • crisis escalation;
  • regulatory responsibilities; and
  • strategic recovery priorities.
Business Unit Heads

Training should address:

  • BIA ownership;
  • strategy approval;
  • BCP responsibilities;
  • resource requirements; and
  • recovery leadership.
BCM Coordinators

Training should address:

  • RAR;
  • BIA;
  • strategy development;
  • BCP development;
  • plan maintenance;
  • exercise coordination; and
  • recovery procedures.
Recovery Team Members

Training should focus on:

  • activation;
  • individual responsibilities;
  • recovery procedures;
  • communication; and
  • escalation.

Competency should be reinforced through exercises rather than relying only on classroom instruction.

 

BCM Awareness

Training and awareness serve different purposes.

Training develops competency among employees with specific BCM responsibilities.

Awareness ensures that the wider organisation understands basic continuity expectations.

Damanat's awareness program may include:

  • employee induction;
  • awareness briefings;
  • intranet information;
  • BCM awareness campaigns;
  • quick-reference guides;
  • posters;
  • short videos;
  • management messages; and
  • periodic exercises.

Employees should at minimum understand:

  • how they will be notified;
  • where to obtain instructions;
  • basic evacuation and safety expectations;
  • remote-working requirements;
  • communication responsibilities; and
  • who to contact regarding BCM matters.

 

Lessons Learned Management

Every significant incident and exercise should create an opportunity for organisational learning.

Damanat should establish a formal process:

Incident / Exercise

→ Debrief

→ Lessons Identified

→ Root Cause Analysis

→ Corrective Action

→ Owner Assigned

→ Implementation

→ Validation

→ Closure

Lessons should not remain only within exercise reports.

They should feed into relevant:

  • RARs;
  • BIAs;
  • strategies;
  • BCPs;
  • training;
  • technology recovery arrangements;
  • supplier arrangements; and
  • future exercises.

 

Corrective-Action Management

Program Management should maintain a central BCM Corrective Action Register.

An illustrative structure is:

 

Finding

Source

Required Action

Owner

Target

Status

Remote access capacity inadequate

Exercise

Increase recovery capacity

IT

Q3

Open

Contact information outdated

Call test

Update recovery contacts

BU BCM Coordinator

2 weeks

Open

Supplier RTO exceeds Damanat requirement

BIA review

Review contractual recovery

Procurement

Q4

Open

Approval authority unclear

Walkthrough

Update delegation arrangement

BU Head

1 month

Completed

Data restoration exceeds RPO

DR Test

Improve recovery arrangement

IT

Q3

Open

Significant overdue actions should be escalated through BCM governance.

 

Managing Third-Party Continuity

Damanat's BCM capability can be weakened by dependencies on suppliers that cannot meet required recovery objectives.

Program Management should therefore maintain oversight of critical suppliers.

The process may include:

  • identifying critical suppliers;
  • maintaining supplier BCM requirements;
  • reviewing supplier BCPs;
  • obtaining evidence of exercises;
  • reviewing supplier recovery objectives;
  • assessing concentration risk;
  • monitoring service changes;
  • reviewing contractual BCM clauses;
  • including suppliers in Damanat exercises; and
  • tracking supplier continuity deficiencies.
Damanat Example

If an external technology provider supports a service required by Mortgage Guarantee Origination within four hours, Damanat should determine whether that provider can support the same recovery requirement.

If the provider's recovery commitment is 24 hours, a significant dependency gap exists.

 

Managing Changes to Critical Business Functions

Program Management should be integrated with organisational change.

When Damanat introduces a significant new service, process, technology or supplier, BCM implications should be assessed as part of the change rather than after implementation.

A BCM change assessment could ask:

  1. Does the change create a new Critical Business Function?
  2. Does it change an existing RTO or RPO?
  3. Does it introduce a new supplier?
  4. Does it introduce a new technology dependency?
  5. Does it remove an existing recovery arrangement?
  6. Does it change minimum staffing?
  7. Does it affect alternate workplace requirements?
  8. Does the BCP require updating?
  9. Is additional testing required?

This makes BCM proactive rather than reactive.

 

BCM Performance Measurement

Damanat should establish Key Performance Indicators (KPIs) and Key Risk Indicators (KRIs) to monitor the BCM program.

Possible indicators include:

 

Indicator

Example Measure

BIA Currency

% of BIAs reviewed within the required cycle

BCP Currency

% of BCPs currently approved

Exercise Completion

% of planned exercises completed

Exercise Success

% achieving defined objectives

RTO Achievement

% of tested functions meeting RTO

Training

% of BCM personnel completing required training

Corrective Actions

% closed by target date

Supplier Assurance

% of critical suppliers assessed

Contact Accuracy

% of recovery contacts successfully validated

Audit Findings

Number of overdue significant BCM findings

The purpose of measurement is not to produce large volumes of statistics. Metrics should help management determine whether Damanat's continuity capability is improving or deteriorating.

 

BCM Management Dashboard

A management dashboard may summarise the overall status of the BCM program.

For example:

BCM Area

Status

Key Observation

RAR

Current

Annual review completed

BIA

Attention Required

Two functions overdue

BCP

Current

95% approved

Testing

Attention Required

One DR test below RTO

Training

Current

Recovery-team training completed

Suppliers

Attention Required

One critical supplier recovery gap

Corrective Actions

Attention Required

Three overdue actions

Audit

Current

No major outstanding findings

The dashboard should support decision-making and escalation.

 

Internal Review and Assurance

Damanat should periodically assess whether its BCM program is operating as intended.

Assurance may include:

  • self-assessment;
  • BCM quality review;
  • internal audit;
  • compliance review;
  • independent external review; and
  • regulatory examination.

The review should evaluate both:

Design Effectiveness – Are appropriate BCM controls and arrangements defined?

and

Operating Effectiveness – Are those controls actually implemented and working?

For example, requiring that every BCP be tested annually demonstrates design.

Evidence that the exercises occurred, findings were documented, and corrective actions were completed demonstrates operating effectiveness.

 

Independent Assurance

Independent review provides management with greater confidence that BCM arrangements are not being assessed solely by the individuals responsible for operating them.

Independent assurance may examine:

  • governance;
  • policy;
  • methodology;
  • RAR;
  • BIA;
  • strategy;
  • BCPs;
  • technology recovery;
  • exercises;
  • supplier continuity;
  • training;
  • corrective actions; and
  • regulatory alignment.

Findings should be formally tracked to closure.

 

Management Review

Senior management should periodically review the effectiveness of the BCM program.

The management review should consider:

  • BCM performance;
  • significant changes;
  • major risks;
  • BIA status;
  • exercise results;
  • incidents;
  • audit findings;
  • regulatory developments;
  • supplier concerns;
  • corrective actions;
  • resource requirements; and
  • improvement opportunities.

Management review should result in decisions and actions rather than functioning only as a reporting meeting.

Possible outcomes include:

  • approval of additional recovery investment;
  • revision of recovery priorities;
  • strengthening of supplier requirements;
  • changes to exercise frequency;
  • additional employee training;
  • remediation of technology resilience gaps; or
  • changes to BCM governance.

 

Specific Program Management Requirements for Damanat

For Damanat, the Program Management phase should establish several specific requirements.

Requirement 1 — Maintain BCM Governance

Damanat should maintain clearly assigned BCM ownership, senior management oversight and Business Unit accountability.

Requirement 2 — Maintain Current RAR and BIA Information

Risk assessments and BIAs should be periodically reviewed and updated following material changes to organisational, process, technology, supplier, or location.

Requirement 3 — Maintain Approved Business Continuity Plans

Each relevant Business Unit should have a current, approved and accessible BCP.

Requirement 4 — Maintain Recovery Capability

Recovery arrangements for people, processes, technology, premises, information and critical suppliers should remain capable of meeting approved recovery requirements.

Requirement 5 — Maintain an Exercise Program

Damanat should operate a structured testing program that progresses from component and walkthrough activities to integrated and simulation exercises, as appropriate.

Requirement 6 — Manage Exercise and Incident Findings

Corrective actions should have assigned owners, deadlines, and evidence of escalation and closure.

Requirement 7 — Maintain BCM Competency

Personnel assigned continuity and recovery responsibilities should receive appropriate training and participate in exercises.

Requirement 8 — Maintain Third-Party Resilience Oversight

Critical suppliers supporting priority activities should be assessed for their ability to support Damanat during disruption.

Requirement 9 — Monitor BCM Performance

Management should receive periodic information concerning BCM capability, gaps and overdue actions.

Requirement 10 — Provide Independent Assurance

The BCM program should be subject to appropriate independent review or audit.

Requirement 11 — Maintain Regulatory Traceability

Damanat should maintain evidence demonstrating how applicable regulatory requirements are addressed through BCM policies, processes, plans, exercises and governance.

Requirement 12 — Continually Improve BCM

Lessons from incidents, exercises, audits, reviews and organisational changes should result in measurable improvement.

 

SAMA Regulatory Considerations

For Damanat, the Saudi Central Bank (SAMA) Business Continuity Management Framework provides an important regulatory reference for ongoing BCM management.

The framework addresses BCM as a continuing management capability rather than simply requiring organisations to prepare Business Continuity Plans.

Accordingly, Damanat's Program Management arrangements should address areas such as:

  • governance and management oversight;
  • BCM policy and strategy;
  • BIA and risk assessment;
  • Business Continuity Planning;
  • disaster recovery;
  • Testing and Exercising;
  • awareness and training;
  • document review;
  • independent assurance; and
  • management reporting.

For implementation purposes, Damanat should maintain a regulatory traceability matrix linking applicable requirements with responsible owners, BCM evidence and review status.

An illustrative structure is:

Regulatory Area

Damanat Program Control

Evidence

BCM Governance

BCM Committee

Terms of reference and minutes

Risk Assessment

Periodic RAR

Approved Threat and Risk Register

BIA

Periodic BIA review

Approved BIA reports

Business Continuity Planning

BCP maintenance cycle

Current approved BCPs

Technology Recovery

DR program

DR plans and test results

Testing

Annual exercise program

Exercise plans and reports

Training

Role-based training

Training records

Supplier Continuity

Third-party review

Supplier BCM assessments

Corrective Actions

Improvement process

Corrective Action Register

Independent Review

Internal/external assurance

Audit or review reports

Management Oversight

Periodic reporting

BCM dashboard and management review

This traceability provides Damanat with an organised evidence base for management assurance and regulatory review.

 

Annual BCM Program Cycle

A practical annual BCM cycle for Damanat could follow this sequence:

Quarter 1

Review BCM policy, governance, RAR and BIA.

Quarter 2

Review continuity strategies, BCPs and critical supplier arrangements.

Quarter 3

Conduct planned exercises and technology recovery testing.

Quarter 4

Complete corrective actions, assurance review, management review and planning for the following year.

This is illustrative rather than prescriptive. Activities should be scheduled according to Damanat's operational and regulatory requirements.

More importantly, material changes should trigger immediate BCM review rather than waiting for the next annual cycle.

 

Example: Managing Mortgage Guarantee Origination as an Ongoing BCM Capability

Consider Mortgage Guarantee Origination.

During initial BCM implementation, Damanat may have:

  1. identified its disruption risks;
  2. completed the BIA;
  3. established its RTO, RPO and MBCO;
  4. selected continuity strategies;
  5. prepared a BCP; and
  6. conducted an exercise.

Program Management then ensures that this capability remains effective.

For example:

Change

Damanat introduces a new guarantee processing platform.

Program Management Response

Review:

  • RAR;
  • technology dependency;
  • BIA;
  • RPO;
  • disaster recovery capability;
  • BCP procedures;
  • user access;
  • supplier dependency; and
  • exercise requirements.
Validation

Conduct a component- or integrated-recovery test.

Finding

The new application can be restored within the required RTO, but the external interface requires additional recovery time.

Corrective Action

Improve the interface recovery arrangement.

Re-Test

Validate the complete Mortgage Guarantee Origination recovery chain.

This demonstrates how Program Management keeps BCM aligned with organisational change.

BCM Program Management Deliverables

Damanat should maintain, at minimum:

Ref

Deliverable

Purpose

PgM-01

BCM Program Management Framework

Defines ongoing management arrangements

PgM-02

BCM Governance Structure

Maintains accountability

PgM-03

BCM Annual Program

Establishes recurring activities

PgM-04

RAR Review Schedule

Maintains threat assessments

PgM-05

BIA Review Schedule

Maintains recovery requirements

PgM-06

BCP Maintenance Schedule

Maintains plan currency

PgM-07

Testing and Exercising Program

Maintains recovery validation

PgM-08

Training Program

Maintains competency

PgM-09

Awareness Program

Maintains organisational awareness

PgM-10

Supplier BCM Review

Maintains third-party assurance

PgM-11

Corrective Action Register

Tracks improvements

PgM-12

BCM Performance Dashboard

Supports management oversight

PgM-13

Regulatory Requirements Register

Maintains compliance traceability

PgM-14

Assurance / Audit Reports

Provides independent assessment

PgM-15

Management Review

Provides senior management oversight

PgM-16

Continual Improvement Register

Documents capability enhancement

Completion Criteria for Program Management

Unlike earlier BCM phases, Program Management does not have a final completion date.

It represents an ongoing management cycle.

Damanat can, however, assess whether an effective Program Management capability has been established.

This should include confirmation that:

  • BCM governance is operating;
  • responsibilities remain assigned;
  • RARs and BIAs are reviewed;
  • BCPs remain current;
  • continuity strategies remain viable;
  • exercises are conducted according to plan;
  • technology recovery is periodically validated;
  • employees receive appropriate training;
  • BCM awareness activities occur;
  • critical suppliers are assessed;
  • corrective actions are tracked;
  • performance is measured;
  • significant issues are escalated;
  • independent assurance is conducted;
  • senior management reviews BCM performance; and
  • lessons learned result in improvements.

The BCM program can then be considered sustained rather than merely implemented.

 

The BCM Continual Improvement Cycle

The seven-phase methodology should ultimately operate as a continuous lifecycle rather than a linear project.

The initial implementation sequence is:

PM → RAR → BIA → BCS → PD → TE → PgM

Once Program Management has been established, the lifecycle continues:

→ Monitor

→ Review

→ Identify Change

→ Reassess Risk

→ Reassess Business Impact

→ Adjust Strategy

→ Update Plans

→ Exercise

→ Learn

→ Improve

→ Monitor Again

For Damanat, this means BCM is never permanently “finished.”

The organisation should instead seek to maintain an appropriate level of readiness as its operating environment evolves.

 

Integrating the Seven BCM Phases

The complete Damanat BCM Planning Methodology can now be viewed as an integrated management system.

Phase 1 — Project Management

Question: How will BCM implementation be organised?

Outcome: Governance, scope, responsibilities and implementation plan.

Phase 2 — Risk Analysis and Review

Question: What could disrupt Damanat?

Outcome: Threats, vulnerabilities, controls and residual risks.

Phase 3 — Business Impact Analysis

Question: What must be recovered and how quickly?

Outcome: Recovery priorities, RTO, RPO, MBCO and dependencies.

Phase 4 — Business Continuity Strategy

 

Question: How will recovery requirements be achieved?

Outcome: Prevention, mitigation and recovery strategies.

Phase 5 — Plan Development

Question: How will the strategy be executed during disruption?

Outcome: Business Continuity Plans and recovery procedures.

Phase 6 — Testing and Exercising

Question: Do the arrangements actually work?

Outcome: Validated capability, lessons learned and corrective actions.

Phase 7 — Program Management

Question: How will Damanat keep the capability effective?

Outcome: Governance, maintenance, assurance and continual improvement.

Together:

Organise → Understand Risk → Understand Impact → Develop Strategy → Document Response → Validate Capability → Sustain and Improve

 

Banner [Summary] [BCM] [E2] [C8] Program Management

The Program Management phase completes the implementation framework for Business Continuity Management at The Saudi Mortgage Guarantees Services Company, but it does not represent the end of BCM.

Instead, it marks the transition from establishing BCM capability to sustaining organisational resilience over time.

The earlier phases provide Damanat with the fundamental building blocks:

  • Project Management establishes the implementation framework.

  • Risk Analysis and Review identifies disruption threats and vulnerabilities.

  • Business Impact Analysis establishes recovery priorities and requirements.

  • Business Continuity Strategy determines how those requirements will be achieved.

  • Plan Development translates strategies into actionable procedures.

  • Testing and Exercising demonstrates whether those arrangements can work.

  • Program Management ensures that everything remains current, governed, competent, tested and continually improved.

For Damanat, this final phase is particularly important because mortgage guarantee operations operate within a dynamic ecosystem of business processes, technology, financial institutions, suppliers, regulatory requirements, and operational risks.

A BCP that accurately reflects today's organisation may no longer be appropriate following a significant technology transformation, organisational restructuring, an outsourcing arrangement, or a change in a critical service provider.

Program Management provides the mechanism to identify and respond to those changes.

The objective should therefore be to establish a recurring cycle:

Govern → Maintain → Train → Exercise → Measure → Review → Improve

A mature BCM program should enable Damanat to demonstrate not merely that continuity documentation exists, but that:

  • management actively oversees BCM;
  • recovery requirements remain current;
  • Business Continuity Plans remain accurate;
  • employees understand their responsibilities;
  • recovery capabilities are regularly exercised;
  • critical dependencies are monitored;
  • deficiencies are corrected;
  • management understands significant residual risks; and
  • the BCM program improves in response to change and experience.

Ultimately, the value of Program Management lies in maintaining readiness.

Damanat cannot predict every disruptive event that may occur. It can, however, maintain an organisation that understands its critical activities, recognises its dependencies, prepares appropriate recovery capabilities, exercises those capabilities and systematically learns from experience.

The complete BCM Planning Methodology for Damanat can therefore be summarised as:

PM → RAR → BIA → BCS → PD → TE → PgM → Continual Improvement

The first six phases build and validate the capability.

The seventh phase keeps the capability alive.

Through disciplined Program Management, Business Continuity Management becomes an ongoing organisational capability that supports Damanat's ability to continue priority mortgage guarantee activities, meet stakeholder and regulatory expectations, and respond effectively to significant disruption.

 

[BCM] [Damanat] [3/4 Banner] Implementing BCM for The Saudi Mortgage Guarantees Services Company

eBook 2: Implementing Business Continuity Management
C1 C2 C3 C4 C5
[BCM] [Damanat] [E2] [C1] Business Continuity Management Planning Methodology [BCM] [Damanat] [E2] [C2] Project Management [BCM] [Damanat] [E2] [C3] Risk Analysis and Review [BCM] [Damanat] [E2] [C4] Business Impact Analysis [BCM] [Damanat] [E2] [C5] Business Continuity Strategy
C6 C7 C8 C9 C10
[BCM] [Damanat] [E2] [C6] BCM Plan Development [BCM] [Damanat] [E2] [C7] Testing and Exercising [BCM] [Damanat] [E2] [C8] Program Management [BCM] [Damanat] [E2] [C9] Summary [BCM] [Damanat] [E2] [C10] Back Cover
 

More Information About Business Continuity Management Courses

To learn more about the course and schedule, click the buttons below for BCM-300 Business Continuity Management Implementer [BCM-3] and BCM-5000 Business Continuity Management Expert Implementer [BCM-5]

New call-to-action  New call-to-action Register [BL-B-3]*
New call-to-action New call-to-action New call-to-action
FAQ [BL-B-3]

Please feel free to send us a note if you have any questions.

Email to Sales Team [BCM Institute]

 FAQ BL-B-5 BCM-5000
New call-to-action New call-to-action New call-to-action
 

 

Comments

More Posts

New Call-to-action