It examines how the consequences of losing a business function change as the duration of disruption increases.
Rather than assigning a single static criticality rating, the analysis evaluates each Sub-Critical Business Function at defined time intervals to identify when operational, financial, regulatory, information, and stakeholder consequences become increasingly severe.
For the Saudi Mortgage Guarantees Services Company (Damanat), the analysis is particularly important because Mortgage Guarantee Origination is carried out through an interconnected sequence of application intake, eligibility verification, risk assessment, approval, guarantee issuance, registration, communication, and reporting.
Damanat operates through a business-to-business model involving financial institutions and other participants in the Saudi real estate finance ecosystem.
Disruption to one part of the origination process can therefore create backlogs and delays across multiple downstream activities.
Business impacts normally escalate as a disruption continues.
An interruption lasting several hours may initially be managed through existing work queues, manual procedures, or temporary communication channels.
As the disruption extends into days, however, application backlogs increase, service commitments are missed, guarantee decisions are delayed, records may become incomplete, and participating financial institutions may be unable to progress related mortgage financing transactions.
Prolonged disruption can also affect regulatory obligations, management oversight, financial reconciliation, and stakeholder confidence.
The impact scores in this assessment use the following scale:
|
Score |
Impact level |
General interpretation |
|
1 |
Very Low |
Limited disruption that can be absorbed through normal operational arrangements. |
|
2 |
Low |
Manageable service degradation requiring local workarounds or additional effort. |
|
3 |
Moderate |
Material backlog, missed internal targets, or increasing stakeholder consequences. |
|
4 |
High |
Serious operational, financial, regulatory, or stakeholder consequences requiring urgent recovery. |
|
5 |
Very High |
Intolerable impact that threatens compliance, service viability, financial exposure, or the continued delivery of the Critical Business Function. |
The progressive impact ratings support the establishment of two important recovery parameters:
This approach is consistent with impact-over-time analysis, which uses progressive impact ratings to support recovery prioritisation and the development of continuity strategies.
The assessment also identifies Vulnerable Periods—specific operational windows during which a disruption would produce unusually severe consequences.
These periods should be reflected in continuity arrangements, staffing plans, system change controls, third-party coordination, and recovery readiness.
SAMA’s BCM framework emphasises establishing continuity controls, plans, recovery capabilities, and tested arrangements that enable critical and urgent activities to continue at predefined acceptable levels.
|
Sub-CBF Code |
Sub-CBF |
Highest-Impact Area |
4 Hour |
8 Hour |
1 Day |
2 Day |
3 Day |
5 Day |
7 Day |
10 Day |
14 Day |
21 Day |
30 Day |
60 Day |
|
1.1 |
Mortgage Guarantee Application Intake |
Operational |
2 |
2 |
3 |
3 |
4 |
4 |
5 |
5 |
5 |
5 |
5 |
5 |
|
1.2 |
Application Validation |
Operational |
1 |
2 |
2 |
3 |
3 |
4 |
4 |
5 |
5 |
5 |
5 |
5 |
|
1.3 |
Borrower Eligibility Assessment |
Regulatory |
2 |
2 |
3 |
3 |
4 |
4 |
5 |
5 |
5 |
5 |
5 |
5 |
|
1.4 |
Property Eligibility Assessment |
Operational |
1 |
2 |
2 |
3 |
3 |
4 |
4 |
5 |
5 |
5 |
5 |
5 |
|
1.5 |
Mortgage Risk Assessment |
Financial |
2 |
3 |
3 |
4 |
4 |
5 |
5 |
5 |
5 |
5 |
5 |
5 |
|
1.6 |
Guarantee Policy Compliance Review |
Regulatory |
2 |
3 |
3 |
4 |
5 |
5 |
5 |
5 |
5 |
5 |
5 |
5 |
|
1.7 |
Financial Institution Verification |
Third-Party Dependency |
1 |
2 |
2 |
3 |
3 |
4 |
4 |
5 |
5 |
5 |
5 |
5 |
|
1.8 |
Guarantee Approval Decision |
Operational |
2 |
3 |
4 |
4 |
5 |
5 |
5 |
5 |
5 |
5 |
5 |
5 |
|
1.9 |
Guarantee Certificate Generation |
Customer / Stakeholder |
2 |
2 |
3 |
4 |
4 |
5 |
5 |
5 |
5 |
5 |
5 |
5 |
|
1.10 |
Guarantee Registration |
Information |
2 |
3 |
3 |
4 |
4 |
5 |
5 |
5 |
5 |
5 |
5 |
5 |
|
1.11 |
Stakeholder Notification |
Customer / Stakeholder |
2 |
2 |
3 |
3 |
4 |
4 |
5 |
5 |
5 |
5 |
5 |
5 |
|
1.12 |
Documentation and Record Management |
Information |
2 |
3 |
3 |
4 |
4 |
5 |
5 |
5 |
5 |
5 |
5 |
5 |
|
1.13 |
Guarantee Fee Administration |
Financial |
1 |
1 |
2 |
2 |
3 |
3 |
4 |
4 |
5 |
5 |
5 |
5 |
|
1.14 |
Post-Issuance Quality Assurance |
Regulatory |
1 |
1 |
2 |
2 |
2 |
3 |
3 |
4 |
4 |
5 |
5 |
5 |
|
1.15 |
Management Reporting and Regulatory Monitoring |
Regulatory |
1 |
2 |
2 |
3 |
3 |
4 |
4 |
5 |
5 |
5 |
5 |
5 |
|
Sub-CBF Code |
Sub-CBF |
Highest-Impact Area |
Recovery Time Objective (RTO) |
Maximum Tolerable Period of Disruption (MTPD) |
Vulnerable Period |
|
1.1 |
Mortgage Guarantee Application Intake |
Operational |
8 hours |
3 days |
Peak application submission periods; product launches; campaign-driven surges; and the final working days before programme or financing cut-off dates. |
|
1.2 |
Application Validation |
Operational |
1 day |
5 days |
High-volume submission periods require identifying incomplete applications quickly to prevent downstream assessment backlogs. |
|
1.3 |
Borrower Eligibility Assessment |
Regulatory |
1 day |
3 days |
Periods preceding lender financing commitments, eligibility-rule changes, government housing initiatives, and high-volume home-purchase campaigns. |
|
1.4 |
Property Eligibility Assessment |
Operational |
2 days |
5 days |
Property completion and handover periods, valuation-validity cut-offs, major housing development releases, and month-end financing completion. |
|
1.5 |
Mortgage Risk Assessment |
Financial |
8 hours |
2 days |
High-value or higher-risk application periods; portfolio concentration reviews; economic volatility; and periods following material changes in credit-risk criteria. |
|
1.6 |
Guarantee Policy Compliance Review |
Regulatory |
8 hours |
2 days |
Regulatory reporting periods, policy implementation dates, audit or regulatory examination windows, and periods immediately following changes to guarantee requirements. |
|
1.7 |
Financial Institution Verification |
Third-Party Dependency |
1 day |
5 days |
Onboarding or renewal of participating institutions, changes in lender authorisation status, and periods of elevated submissions from newly approved partners. |
|
1.8 |
Guarantee Approval Decision |
Operational |
4 hours |
2 days |
Daily approval cut-off periods, month-end transaction completion, high-volume campaigns, delegated-authority absences, and urgent financing completion dates. |
|
1.9 |
Guarantee Certificate Generation |
Customer / Stakeholder |
8 hours |
3 days |
Property-transfer deadlines, lender disbursement cut-offs, month-end completion, and periods when approved financing depends upon evidence of guarantee issuance. |
|
1.10 |
Guarantee Registration |
Information |
8 hours |
2 days |
High transaction-volume periods, daily reconciliation windows, month-end closing, regulatory data extraction, and system migration or maintenance windows. |
|
1.11 |
Stakeholder Notification |
Customer / Stakeholder |
8 hours |
3 days |
Approval cut-off periods, urgent financing cases, application campaign periods, and incidents generating high enquiry volumes from participating institutions. |
|
1.12 |
Documentation and Record Management |
Information |
4 hours |
2 days |
Regulatory examinations, internal or external audits, litigation or dispute-response periods, data migrations, month-end reconciliation, and records-retention reviews. |
|
1.13 |
Guarantee Fee Administration |
Financial |
3 days |
10 days |
Month-end and year-end financial closing, invoicing cycles, fee reconciliation periods, and periods immediately before the general ledger is closed. |
|
1.14 |
Post-Issuance Quality Assurance |
Regulatory |
5 days |
14 days |
Regulatory inspections, internal audit reviews, post-product-launch monitoring, periods of increased exception rates, and high-risk portfolio review cycles. |
|
1.15 |
Management Reporting and Regulatory Monitoring |
Regulatory |
1 day |
5 days |
SAMA submission deadlines, executive and board reporting cycles, month-end and quarter-end reporting, financial year-end, and periods of enhanced regulatory monitoring. |
The following Sub-CBFs require the fastest recovery because their interruption can rapidly prevent Damanat from making controlled guarantee decisions or maintaining reliable records:
These functions either enable the progression of priority applications, control financial and regulatory exposure, formalise approved guarantees, or preserve the integrity of official records.
Their continuity strategies should therefore include rapid access to designated recovery personnel, alternate system access, controlled manual procedures, emergency approval authorities, and priority restoration of technology.
The following functions should generally be restored within one or two days:
Although short manual workarounds may be possible, prolonged disruption would increase the application backlog, weaken the control environment, reduce management visibility, and affect service commitments to participating financial institutions.
Guarantee Fee Administration and Post-Issuance Quality Assurance may tolerate longer disruption periods, provided that:
These functions should not be treated as non-critical. Their longer RTOs reflect the availability of temporary deferral and reconciliation procedures, rather than an absence of financial or regulatory consequences.
The recommended RTOs represent the targeted restoration times under approved continuity arrangements.
The MTPDs represent the outer limits at which disruption would create intolerable consequences for the relevant Sub-CBF and the overall Mortgage Guarantee Origination process.
For example, Guarantee Approval Decision has an RTO of four hours and an MTPD of two days.
This means Damanat should aim to restore an emergency approval capability within four hours, even though the function may not become completely intolerable until the disruption approaches two days.
The time between the RTO and MTPD provides a recovery margin for:
An RTO should not be set equal to the MTPD because doing so leaves no margin for unsuccessful recovery attempts, technology complications, data validation, or backlog clearance.
Vulnerable Periods should be incorporated directly into Damanat’s continuity and operational planning. Before a known vulnerable period, the responsible business unit should consider:
Where a vulnerable period coincides with system maintenance, public holidays, reduced staffing, major programme launches, or high application volumes, management may temporarily require enhanced recovery readiness or a shorter operational RTO.
Impact-over-time analysis provides Damanat with a structured view of how the consequences of disruption escalate across the entire Mortgage Guarantee Origination lifecycle.
It distinguishes functions that require restoration within hours from those that can be temporarily deferred under controlled conditions.
This enables recovery priorities to be based on the timing and severity of business consequences rather than on perceived importance alone.
The impact scores provide an evidence-based foundation for setting Recovery Time Objectives. Functions whose impacts reach High or Very High levels rapidly should receive earlier recovery targets, stronger system availability arrangements, and more robust manual workarounds.
Functions whose effects develop more gradually may receive longer RTOs, provided that their deferred activities are securely recorded and subsequently reconciled.
The Maximum Tolerable Periods of Disruption establish the outer operating limits for the Sub-CBFs.
These limits guide the design and capacity of recovery strategies by clarifying how long Damanat can rely on degraded service, manual processing, alternate technology, reassigned staff, or third-party support before the consequences become intolerable.
Recovery strategies must be capable of restoring the minimum required service before the relevant MTPD is reached.
The identification of Vulnerable Periods further strengthens contingency planning by showing when ordinary recovery arrangements may be insufficient.
During these periods, Damanat may need additional staffing, tighter change controls, enhanced technology support, accelerated escalation, or pre-emptive backlog reduction.
Collectively, the impact ratings, RTOs, MTPDs, and Vulnerable Periods provide key inputs for:
By applying these outputs consistently, Damanat can strengthen its ability to continue delivering important mortgage guarantee activities at an acceptable predefined level, maintain appropriate records and controls, support participating financial institutions, and protect the resilience of the wider mortgage finance ecosystem.
This reflects the broader BCM expectation that organisations establish, implement, maintain, and test continuity arrangements for critical services and business processes.
| eBook 3: Starting Your BCM Implementation |
||||||
| MBCO | P&S | RAR T1 | RAR T2 | RAR T3 | BCS T1 | CBF |
| CBF-1 Mortgage Guarantee Origination | ||||||
| DP | BIAQ P1 | BIAQ P2 | BIAQ P3 | BIAQ P4 | BIAQ P5 | BIAQ P6 |
| BCS T2 | BCS T3 | PD | ||||
To learn more about the course and schedule, click the buttons below for the BCM-300 Business Continuity Management Implementer [BCM-3] and the BCM-5000 Business Continuity Management Expert Implementer [BCM-5].
|
Please feel free to send us a note if you have any questions. |
||