. .

Implementing Business Continuity Management for The Saudi Mortgage Guarantees Services Company: An Enterprise Implementation Guide
BCM Ai Gen_with Cert Logo_2

[BCM] [Damanat] [E3] [BIA] [P4] [CBF] [1] Supporting IT Systems and Applications

[BCM] [Damanat] [Full Banner] Implementing BCM for The Saudi Mortgage Guarantees Services Company

Identifying supporting IT systems and applications is an essential component of the Business Impact Analysis (BIA) for Mortgage Guarantee Origination.

Each Sub-Critical Business Function relies on technology to receive applications, validate information, assess eligibility, conduct risk reviews, issue decisions, maintain records, communicate with participating financial institutions, and produce management or regulatory reports.

A disruption to these systems can therefore interrupt the end-to-end guarantee origination process even when business personnel remain available.

Technology dependencies should be analysed at the same level of detail as the business processes they support.

This enables The Saudi Mortgage Guarantees Services Company (Damanat) to determine which applications require the highest levels of availability, identify critical system integrations, define data protection requirements, and prioritise technology recovery during a disruption.

Banner [BCM] [E3] [BIA] [P4] Supporting IT Systems and Applications

Dr Goh Moh Heng
Business Continuity Management Certified Planner-Specialist-Expert

Damanat Legal Disclaimer Banner

New call-to-action

BIA Part 4: Supporting IT Systems and Applications

Banner [BCM] [E3] [BIA] [P4] Supporting IT Systems and Applications

CBF-1 Mortgage Guarantee Origination 

 

[BCM] [Damanat] [E3] [BIA] [T4] [CBF] [1] Mortgage Guarantee OriginationIdentifying supporting IT systems and applications is an essential component of the Business Impact Analysis (BIA) for Mortgage Guarantee Origination.

Each Sub-Critical Business Function relies on technology to receive applications, validate information, assess eligibility, conduct risk reviews, issue decisions, maintain records, communicate with participating financial institutions, and produce management or regulatory reports.

A disruption to these systems can therefore interrupt the end-to-end guarantee origination process even when business personnel remain available.

Technology dependencies should be analysed at the same level of detail as the business processes they support.

This enables The Saudi Mortgage Guarantees Services Company (Damanat) to determine which applications require the highest levels of availability, identify critical system integrations, define data protection requirements, and prioritise technology recovery during a disruption.

Business Continuity Planning and IT Disaster Recovery are closely connected but serve different purposes.

The Business Continuity Plan (BC Plan) defines how Damanat will continue or resume priority business activities, including manual workarounds, alternate locations, reassigned personnel, and stakeholder communication arrangements.

The IT Disaster Recovery Plan (IT DRP) focuses on restoring the technology infrastructure, applications, databases, interfaces, and communication services required to support those business activities. IT recovery arrangements must therefore be designed to meet the business's recovery needs.

Two key recovery parameters are used:

  • The Recovery Point Objective (RPO) defines the maximum acceptable period of data loss following a disruption. For example, an RPO of 15 minutes means that recovered data should be no more than 15 minutes behind the point of disruption.
  • The System Recovery Time Objective (System RTO) defines the target time within which an application, platform, or supporting technology should be restored following an outage.

The System RTO should be shorter than, or at least compatible with, the applicable Business RTO. This provides sufficient time for system validation, user access testing, data reconciliation, backlog processing, and stabilisation before the business function must resume.

Specialised equipment and supporting resources should also be identified because system availability alone may not restore the business process.

Secure connectivity, authentication tokens, digital signature infrastructure, high-speed scanners, secure mobile devices, cloud services, backup media, and disaster recovery facilities may all be required to complete the recovery capability.

Banner [Table] [BCM] [E3] [BIA] [P4] Supporting IT Systems and Applications  [BIAQ]

Table BIA P4: Supporting IT Systems and Applications for CBF-1 – Mortgage Guarantee Origination

Sub-CBF Code

Sub-CBF

IT Systems and Applications

RPO

System RTO

Supporting Special Equipment or Resources

Remarks

1.1

Mortgage Guarantee Application Intake

Mortgage Guarantee Origination Portal; Application Programming Interface gateway; Customer Relationship Management system; Workflow Management System; application database; email and collaboration platform

Less than 15 minutes

2 hours

Secure internet connectivity; high-availability infrastructure; load balancers; authentication tokens; alternate submission mailbox; cloud or disaster recovery hosting environment

Application intake is the entry point for all downstream activities. The portal, interfaces, and database should be prioritised for rapid restoration. A controlled manual intake register should be available if online channels are unavailable.

1.2

Application Validation

Mortgage Guarantee Origination System; document validation module; Enterprise Content Management system; Workflow Management System; document management database

1 hour

4 hours

High-speed scanners; secure document upload capability; dedicated validation workstations; dual monitors; secure network access

Recovery should preserve submitted documents, validation results, and outstanding information requests. Manual validation may be used temporarily, but results must be recorded and reconciled once systems are restored.

1.3

Borrower Eligibility Assessment

Eligibility Rules Engine; Mortgage Guarantee Origination System; borrower data interface; participating financial institution interface; credit and affordability assessment tools; database management system

Less than 15 minutes

2 hours

Secure application programming interfaces; authentication tokens; encrypted connectivity; dedicated assessment workstations; access to approved eligibility criteria

Eligibility assessments depend on accurate borrower information and current programme rules. Recovery procedures should validate rules-engine configuration and the completeness of received borrower data before processing resumes.

1.4

Property Eligibility Assessment

Property Assessment Module; valuation information interface; Mortgage Guarantee Origination System; Enterprise Content Management system; geographic and property reference databases where applicable

1 hour

8 hours

Secure network connectivity; high-resolution monitors; document scanners; access to valuation reports and property records; secure remote workstations

The process may continue temporarily using approved property documents and valuation reports. Interfaces to external data providers should be included in third-party recovery arrangements.

1.5

Mortgage Risk Assessment

Credit and Guarantee Risk Assessment Platform; risk scoring engine; portfolio analytics platform; Mortgage Guarantee Origination System; data warehouse; business intelligence tools

Less than 15 minutes

2 hours

High-performance computing resources; secure analytical workstations; encrypted databases; disaster recovery environment; controlled access to risk models

This is a high-priority control function. Recovery must include validation of risk models, scoring rules, reference data, and integration with the origination platform before assessment activities restart.

1.6

Guarantee Policy Compliance Review

Compliance Management System; Policy and Rules Repository; Mortgage Guarantee Origination System; Workflow Management System; sanctions or screening interfaces where applicable; Enterprise Content Management system

Less than 15 minutes

2 hours

Secure compliance workstations; authentication tokens; encrypted network access; access to current policy documents; digital approval capability

Compliance review must not be bypassed during a disruption. The recovered environment should provide access to current policies, decision evidence, review checklists, and approval records.

1.7

Financial Institution Verification

Participating Financial Institution Registry; Customer Relationship Management system; third-party management platform; Mortgage Guarantee Origination System; regulatory and accreditation reference database

1 hour

4 hours

Secure external connectivity; authorised institution directory; authentication tokens; secure communication channels

Recovery should preserve the latest approved status of participating financial institutions. A validated offline register may be used temporarily, subject to subsequent system reconciliation.

1.8

Guarantee Approval Decision

Mortgage Guarantee Origination System; Workflow and Approval Management System; Delegated Authority Matrix; Identity and Access Management system; digital signature platform; notification engine

Real-time or less than 15 minutes

1 hour

Hardware Security Modules; digital signing certificates; authentication tokens; secure mobile devices; high-availability infrastructure; disaster recovery site

This is one of the highest-priority technology dependencies. Recovery must restore authorised approval workflows, segregation of duties, delegated authority controls, and auditable decision records.

1.9

Guarantee Certificate Generation

Certificate Generation Module; document composition system; digital signature platform; Mortgage Guarantee Origination System; Enterprise Content Management system; outbound communication platform

Less than 15 minutes

2 hours

Hardware Security Modules; digital certificates; secure printers where hard copies are required; encrypted storage; secure email gateway

Certificate generation should only resume after approval and registration data have been validated. Contingency templates may be used, but all issued certificates must remain uniquely identifiable and auditable.

1.10

Guarantee Registration

Guarantee Registry; Mortgage Guarantee Origination System; relational database management system; audit logging platform; data replication and backup systems

Real-time

1 hour

High-availability database infrastructure; synchronous replication; secure backup media; disaster recovery site; privileged access management tools

The registry is the authoritative record of issued guarantees. Strong data integrity, transaction logging, replication, and reconciliation controls are required to prevent duplicate, missing, or inconsistent records.

1.11

Stakeholder Notification

Customer Relationship Management system; email and collaboration platform; notification engine; secure messaging service; Mortgage Guarantee Origination System; contact directory

1 hour

4 hours

Secure email gateway; secure mobile devices; video conferencing tools; mass notification capability; alternate contact lists

Alternate communication channels should be available for urgent decisions and service-status updates. Contact information should be backed up and accessible independently of the primary CRM platform.

1.12

Documentation and Record Management

Enterprise Content Management system; electronic records management system; secure document repository; archival platform; database management system; backup and retention platform

Less than 15 minutes

2 hours

High-speed scanners; encrypted storage; immutable backup capability; secure evidence storage; backup media; disaster recovery site

Records must remain complete, secure, retrievable, and auditable. Recovery arrangements should protect document versions, access permissions, retention requirements, and links between records and guarantee cases.

1.13

Guarantee Fee Administration

Financial Management System; billing and invoicing module; Mortgage Guarantee Origination System; payment and reconciliation interfaces; general ledger; reporting platform

4 hours

24 hours

Secure finance workstations; authentication tokens; bank connectivity; backup reports; controlled spreadsheet templates for temporary processing

Fee processing can tolerate a longer recovery period than guarantee approval, provided transactions are recorded for later reconciliation. Month-end and year-end periods may require a shorter temporary System RTO.

1.14

Post-Issuance Quality Assurance

Quality Assurance and Case Review System; Mortgage Guarantee Origination System; Enterprise Content Management system; compliance analytics tools; exception reporting platform

4 hours

24 hours

Secure review workstations; dual monitors; controlled access to case records; analytics environment; approved sampling tools

Priority should be given to high-value, high-risk, or exceptional guarantee cases. Routine reviews may be deferred temporarily, but the outstanding review population must remain visible and controlled.

1.15

Management Reporting and Regulatory Monitoring

Regulatory Reporting Platform; business intelligence and analytics tools; data warehouse; management dashboard; financial reporting system; Mortgage Guarantee Origination System

1 hour

8 hours

Secure reporting workstations; encrypted data extracts; secure regulatory submission channel; backup reporting templates; disaster recovery analytics environment

Recovery must support executive oversight, operational monitoring, and time-sensitive regulatory submissions. Data completeness and reconciliation should be confirmed before reports are issued externally.

 

 

Implementation Considerations

Alignment of Business and System Recovery Objectives

The System RTO for each application should support the corresponding Business RTO established during the impact-over-time assessment.

For example, if Guarantee Approval Decision has a Business RTO of four hours, the underlying approval workflow, identity management, digital signature infrastructure, and guarantee database should be restored earlier—preferably within one hour—to provide sufficient time for:

  • technical validation;
  • business-user access testing;
  • confirmation of delegated approval authorities;
  • data reconciliation;
  • completion of pending approval cases; and
  • controlled resumption of the business process.

A technology platform may support several Sub-CBFs with different Business RTOs. In such cases, the shortest applicable Business RTO should generally determine the shared platform's recovery priority.

Shared Technology Dependencies

Several systems are likely to support multiple parts of Mortgage Guarantee Origination. These may include:

  • Mortgage Guarantee Origination System;
  • Workflow Management System;
  • Enterprise Content Management system;
  • Identity and Access Management;
  • database management and replication services;
  • integration and application programming interface platforms;
  • email and collaboration services;
  • reporting and analytics platforms; and
  • network and cybersecurity infrastructure.

These shared systems should be treated as enterprise-level technology dependencies.

Failure of a shared platform could simultaneously interrupt several Sub-CBFs and cause a broader service outage than the loss of a standalone application.

Data Recovery and Reconciliation

The recommended RPOs reflect the maximum acceptable data loss for each process.

Systems containing guarantee approvals, registration records, certificates, compliance decisions, and risk assessments require the most stringent RPOs because lost or inconsistent data could result in:

  • duplicate guarantee issuance;
  • unrecorded approvals;
  • incorrect financial exposure;
  • incomplete audit trails;
  • inconsistent stakeholder communication;
  • breaches of internal controls; and
  • inaccurate management or regulatory reporting.

Recovery procedures should define how data will be reconciled against workflow logs, interface records, application submissions, issued certificates, financial institution acknowledgements, and manually maintained contingency records.

Manual Workarounds

Manual workarounds may help sustain minimum operations while systems are unavailable, but they should be controlled and used selectively. Appropriate controls include:

  • unique manual reference numbers;
  • approved forms and templates;
  • dual verification of critical decisions;
  • segregation of duties;
  • secure storage of temporary records;
  • documented approval authorities;
  • tracking of all manually processed cases; and
  • post-recovery reconciliation.

Manual procedures should not bypass mandatory eligibility, risk, compliance, or approval controls.

Third-Party and External Interfaces

Mortgage Guarantee Origination may depend on external parties and technology services, including participating financial institutions, data providers, cloud service providers, telecommunications providers, valuation sources, and payment or banking platforms.

Damanat should establish continuity and recovery requirements for these dependencies through:

  • service-level agreements;
  • recovery commitments;
  • incident notification requirements;
  • alternate communication arrangements;
  • interface fallback procedures;
  • data protection obligations;
  • resilience testing; and
  • third-party assurance reviews.

 

Banner [BCM] [E3] [BIA] [Summing Up] [P4] Supporting IT Systems and Applications  [BIAQ]

 Supporting IT systems and applications across every stage of Mortgage Guarantee Origination, from the initial receipt of an application through registration, issuance, communication, financial administration, and reporting of a mortgage guarantee.

Identifying these dependencies during the Business Impact Analysis enables Damanat to understand which systems are essential, how quickly they must be restored, and how much data loss can be tolerated.

The defined Recovery Point Objectives provide the basis for selecting appropriate backup, replication, journalling, and data recovery arrangements.

Systems containing approval, guarantee registration, risk, compliance, and official record data require particularly stringent RPOs because even a small amount of data loss could affect control integrity, financial exposure, or regulatory accountability.

The System Recovery Time Objectives translate business recovery requirements into measurable technology recovery targets.

These targets support the design of high-availability architectures, disaster-recovery environments, cloud resilience, infrastructure redundancy, recovery procedures, and technology testing programmes.

They also enable IT teams to prioritise the restoration of shared services and applications based on the business's operational needs.

Specialised equipment and supporting resources must be included in Business Continuity Plans because restoring an application does not automatically restore the complete business capability.

Secure connectivity, authentication tokens, digital signature infrastructure, scanners, secure devices, backup media, and alternate facilities may all be necessary before users can resume work effectively.

By documenting the complete technology dependency chain, Damanat can better align Business Continuity Planning with IT Disaster Recovery, strengthen system resilience, protect critical data, and improve its ability to resume Mortgage Guarantee Origination within approved recovery objectives.

This integrated approach supports effective disruption management, regulatory accountability, stakeholder confidence, and the continued resilience of Damanat’s mortgage guarantee operations.

 

[BCM] [Damanat] [3/4 Banner] Implementing BCM for The Saudi Mortgage Guarantees Services Company

eBook 3: Starting Your BCM Implementation
MBCO P&S RAR T1 RAR T2 RAR T3 BCS T1  CBF
[BCM] [Damanat] [E3] [BIA] MBCO Corporate MBCO [BCM] [Damanat] [E3] [BIA] [PS] Key Product and Services [BCM] [Damanat] [E3] [RAR] [T1] List of Threats [BCM] [Damanat] [E3] [RAR] [T2] Treatment and Control [BCM] [Damanat] [E3] [RAR] [T3] Risk Impact and Likelihood Assessment [BCM] [Damanat] [E3] [BCS] [T1] Mitigation Strategies and Justification BCM] [Damanat] [E1] [C10] Identifying Critical Business Functions
CBF-1 Mortgage Guarantee Origination
DP BIAQ P1 BIAQ P2 BIAQ P3 BIAQ P4 BIAQ P5 BIAQ P6
[BCM] [Damanat] [E3] [BIA] [DP] [CBF] [1] Mortgage Guarantee Origination [BCM] [Damanat] [E3] [BIA] [T1] [CBF] [1] Mortgage Guarantee Origination [BCM] [Damanat] [E3] [BIA] [T2] [CBF] [1] Mortgage Guarantee Origination [BCM] [Damanat] [E3] [BIA] [T3] [CBF] [1] Mortgage Guarantee Origination [BCM] [Damanat] [E3] [BIA] [T4] [CBF] [1] Mortgage Guarantee Origination [BCM] [Damanat] [E3] [BIA] [T5] [CBF] [1] Mortgage Guarantee Origination [BCM] [Damanat] [E3] [BIA] [T6] [CBF] [1] Mortgage Guarantee Origination
    BCS T2 BCS T3 PD    
    [BCM] [Damanat] [E3] [BCS] [T2] [CBF] [1] Mortgage Guarantee Origination [BCM] [Damanat] [E3] [BCS] [T3] [CBF] [1] Mortgage Guarantee Origination [BCM] [Damanat] [E3] [PD] [CBF] [1] Mortgage Guarantee Origination    
 

 

 

More Information About Business Continuity Management Courses

To learn more about the course and schedule, click the buttons below for the  BCM-300 Business Continuity Management Implementer [BCM-3] and the BCM-5000 Business Continuity Management Expert Implementer [BCM-5].

New call-to-action New call-to-action Register [BL-B-3]*
New call-to-action New call-to-action New call-to-action
FAQ [BL-B-3]

Please feel free to send us a note if you have any questions.

Email to Sales Team [BCM Institute]

 FAQ BL-B-5 BCM-5000
New call-to-action New call-to-action New call-to-action
 
 

Your Comments Here:

 

More Posts

New Call-to-action