Each Sub-Critical Business Function relies on technology to receive applications, validate information, assess eligibility, conduct risk reviews, issue decisions, maintain records, communicate with participating financial institutions, and produce management or regulatory reports.
A disruption to these systems can therefore interrupt the end-to-end guarantee origination process even when business personnel remain available.
Technology dependencies should be analysed at the same level of detail as the business processes they support.
This enables The Saudi Mortgage Guarantees Services Company (Damanat) to determine which applications require the highest levels of availability, identify critical system integrations, define data protection requirements, and prioritise technology recovery during a disruption.
Business Continuity Planning and IT Disaster Recovery are closely connected but serve different purposes.
The Business Continuity Plan (BC Plan) defines how Damanat will continue or resume priority business activities, including manual workarounds, alternate locations, reassigned personnel, and stakeholder communication arrangements.
The IT Disaster Recovery Plan (IT DRP) focuses on restoring the technology infrastructure, applications, databases, interfaces, and communication services required to support those business activities. IT recovery arrangements must therefore be designed to meet the business's recovery needs.
Two key recovery parameters are used:
The System RTO should be shorter than, or at least compatible with, the applicable Business RTO. This provides sufficient time for system validation, user access testing, data reconciliation, backlog processing, and stabilisation before the business function must resume.
Specialised equipment and supporting resources should also be identified because system availability alone may not restore the business process.
Secure connectivity, authentication tokens, digital signature infrastructure, high-speed scanners, secure mobile devices, cloud services, backup media, and disaster recovery facilities may all be required to complete the recovery capability.
|
Sub-CBF Code |
Sub-CBF |
IT Systems and Applications |
RPO |
System RTO |
Supporting Special Equipment or Resources |
Remarks |
|
1.1 |
Mortgage Guarantee Application Intake |
Mortgage Guarantee Origination Portal; Application Programming Interface gateway; Customer Relationship Management system; Workflow Management System; application database; email and collaboration platform |
Less than 15 minutes |
2 hours |
Secure internet connectivity; high-availability infrastructure; load balancers; authentication tokens; alternate submission mailbox; cloud or disaster recovery hosting environment |
Application intake is the entry point for all downstream activities. The portal, interfaces, and database should be prioritised for rapid restoration. A controlled manual intake register should be available if online channels are unavailable. |
|
1.2 |
Application Validation |
Mortgage Guarantee Origination System; document validation module; Enterprise Content Management system; Workflow Management System; document management database |
1 hour |
4 hours |
High-speed scanners; secure document upload capability; dedicated validation workstations; dual monitors; secure network access |
Recovery should preserve submitted documents, validation results, and outstanding information requests. Manual validation may be used temporarily, but results must be recorded and reconciled once systems are restored. |
|
1.3 |
Borrower Eligibility Assessment |
Eligibility Rules Engine; Mortgage Guarantee Origination System; borrower data interface; participating financial institution interface; credit and affordability assessment tools; database management system |
Less than 15 minutes |
2 hours |
Secure application programming interfaces; authentication tokens; encrypted connectivity; dedicated assessment workstations; access to approved eligibility criteria |
Eligibility assessments depend on accurate borrower information and current programme rules. Recovery procedures should validate rules-engine configuration and the completeness of received borrower data before processing resumes. |
|
1.4 |
Property Eligibility Assessment |
Property Assessment Module; valuation information interface; Mortgage Guarantee Origination System; Enterprise Content Management system; geographic and property reference databases where applicable |
1 hour |
8 hours |
Secure network connectivity; high-resolution monitors; document scanners; access to valuation reports and property records; secure remote workstations |
The process may continue temporarily using approved property documents and valuation reports. Interfaces to external data providers should be included in third-party recovery arrangements. |
|
1.5 |
Mortgage Risk Assessment |
Credit and Guarantee Risk Assessment Platform; risk scoring engine; portfolio analytics platform; Mortgage Guarantee Origination System; data warehouse; business intelligence tools |
Less than 15 minutes |
2 hours |
High-performance computing resources; secure analytical workstations; encrypted databases; disaster recovery environment; controlled access to risk models |
This is a high-priority control function. Recovery must include validation of risk models, scoring rules, reference data, and integration with the origination platform before assessment activities restart. |
|
1.6 |
Guarantee Policy Compliance Review |
Compliance Management System; Policy and Rules Repository; Mortgage Guarantee Origination System; Workflow Management System; sanctions or screening interfaces where applicable; Enterprise Content Management system |
Less than 15 minutes |
2 hours |
Secure compliance workstations; authentication tokens; encrypted network access; access to current policy documents; digital approval capability |
Compliance review must not be bypassed during a disruption. The recovered environment should provide access to current policies, decision evidence, review checklists, and approval records. |
|
1.7 |
Financial Institution Verification |
Participating Financial Institution Registry; Customer Relationship Management system; third-party management platform; Mortgage Guarantee Origination System; regulatory and accreditation reference database |
1 hour |
4 hours |
Secure external connectivity; authorised institution directory; authentication tokens; secure communication channels |
Recovery should preserve the latest approved status of participating financial institutions. A validated offline register may be used temporarily, subject to subsequent system reconciliation. |
|
1.8 |
Guarantee Approval Decision |
Mortgage Guarantee Origination System; Workflow and Approval Management System; Delegated Authority Matrix; Identity and Access Management system; digital signature platform; notification engine |
Real-time or less than 15 minutes |
1 hour |
Hardware Security Modules; digital signing certificates; authentication tokens; secure mobile devices; high-availability infrastructure; disaster recovery site |
This is one of the highest-priority technology dependencies. Recovery must restore authorised approval workflows, segregation of duties, delegated authority controls, and auditable decision records. |
|
1.9 |
Guarantee Certificate Generation |
Certificate Generation Module; document composition system; digital signature platform; Mortgage Guarantee Origination System; Enterprise Content Management system; outbound communication platform |
Less than 15 minutes |
2 hours |
Hardware Security Modules; digital certificates; secure printers where hard copies are required; encrypted storage; secure email gateway |
Certificate generation should only resume after approval and registration data have been validated. Contingency templates may be used, but all issued certificates must remain uniquely identifiable and auditable. |
|
1.10 |
Guarantee Registration |
Guarantee Registry; Mortgage Guarantee Origination System; relational database management system; audit logging platform; data replication and backup systems |
Real-time |
1 hour |
High-availability database infrastructure; synchronous replication; secure backup media; disaster recovery site; privileged access management tools |
The registry is the authoritative record of issued guarantees. Strong data integrity, transaction logging, replication, and reconciliation controls are required to prevent duplicate, missing, or inconsistent records. |
|
1.11 |
Stakeholder Notification |
Customer Relationship Management system; email and collaboration platform; notification engine; secure messaging service; Mortgage Guarantee Origination System; contact directory |
1 hour |
4 hours |
Secure email gateway; secure mobile devices; video conferencing tools; mass notification capability; alternate contact lists |
Alternate communication channels should be available for urgent decisions and service-status updates. Contact information should be backed up and accessible independently of the primary CRM platform. |
|
1.12 |
Documentation and Record Management |
Enterprise Content Management system; electronic records management system; secure document repository; archival platform; database management system; backup and retention platform |
Less than 15 minutes |
2 hours |
High-speed scanners; encrypted storage; immutable backup capability; secure evidence storage; backup media; disaster recovery site |
Records must remain complete, secure, retrievable, and auditable. Recovery arrangements should protect document versions, access permissions, retention requirements, and links between records and guarantee cases. |
|
1.13 |
Guarantee Fee Administration |
Financial Management System; billing and invoicing module; Mortgage Guarantee Origination System; payment and reconciliation interfaces; general ledger; reporting platform |
4 hours |
24 hours |
Secure finance workstations; authentication tokens; bank connectivity; backup reports; controlled spreadsheet templates for temporary processing |
Fee processing can tolerate a longer recovery period than guarantee approval, provided transactions are recorded for later reconciliation. Month-end and year-end periods may require a shorter temporary System RTO. |
|
1.14 |
Post-Issuance Quality Assurance |
Quality Assurance and Case Review System; Mortgage Guarantee Origination System; Enterprise Content Management system; compliance analytics tools; exception reporting platform |
4 hours |
24 hours |
Secure review workstations; dual monitors; controlled access to case records; analytics environment; approved sampling tools |
Priority should be given to high-value, high-risk, or exceptional guarantee cases. Routine reviews may be deferred temporarily, but the outstanding review population must remain visible and controlled. |
|
1.15 |
Management Reporting and Regulatory Monitoring |
Regulatory Reporting Platform; business intelligence and analytics tools; data warehouse; management dashboard; financial reporting system; Mortgage Guarantee Origination System |
1 hour |
8 hours |
Secure reporting workstations; encrypted data extracts; secure regulatory submission channel; backup reporting templates; disaster recovery analytics environment |
Recovery must support executive oversight, operational monitoring, and time-sensitive regulatory submissions. Data completeness and reconciliation should be confirmed before reports are issued externally. |
The System RTO for each application should support the corresponding Business RTO established during the impact-over-time assessment.
For example, if Guarantee Approval Decision has a Business RTO of four hours, the underlying approval workflow, identity management, digital signature infrastructure, and guarantee database should be restored earlier—preferably within one hour—to provide sufficient time for:
A technology platform may support several Sub-CBFs with different Business RTOs. In such cases, the shortest applicable Business RTO should generally determine the shared platform's recovery priority.
Several systems are likely to support multiple parts of Mortgage Guarantee Origination. These may include:
These shared systems should be treated as enterprise-level technology dependencies.
Failure of a shared platform could simultaneously interrupt several Sub-CBFs and cause a broader service outage than the loss of a standalone application.
The recommended RPOs reflect the maximum acceptable data loss for each process.
Systems containing guarantee approvals, registration records, certificates, compliance decisions, and risk assessments require the most stringent RPOs because lost or inconsistent data could result in:
Recovery procedures should define how data will be reconciled against workflow logs, interface records, application submissions, issued certificates, financial institution acknowledgements, and manually maintained contingency records.
Manual workarounds may help sustain minimum operations while systems are unavailable, but they should be controlled and used selectively. Appropriate controls include:
Manual procedures should not bypass mandatory eligibility, risk, compliance, or approval controls.
Mortgage Guarantee Origination may depend on external parties and technology services, including participating financial institutions, data providers, cloud service providers, telecommunications providers, valuation sources, and payment or banking platforms.
Damanat should establish continuity and recovery requirements for these dependencies through:
Supporting IT systems and applications across every stage of Mortgage Guarantee Origination, from the initial receipt of an application through registration, issuance, communication, financial administration, and reporting of a mortgage guarantee.
Identifying these dependencies during the Business Impact Analysis enables Damanat to understand which systems are essential, how quickly they must be restored, and how much data loss can be tolerated.
The defined Recovery Point Objectives provide the basis for selecting appropriate backup, replication, journalling, and data recovery arrangements.
Systems containing approval, guarantee registration, risk, compliance, and official record data require particularly stringent RPOs because even a small amount of data loss could affect control integrity, financial exposure, or regulatory accountability.
The System Recovery Time Objectives translate business recovery requirements into measurable technology recovery targets.
These targets support the design of high-availability architectures, disaster-recovery environments, cloud resilience, infrastructure redundancy, recovery procedures, and technology testing programmes.
They also enable IT teams to prioritise the restoration of shared services and applications based on the business's operational needs.
Specialised equipment and supporting resources must be included in Business Continuity Plans because restoring an application does not automatically restore the complete business capability.
Secure connectivity, authentication tokens, digital signature infrastructure, scanners, secure devices, backup media, and alternate facilities may all be necessary before users can resume work effectively.
By documenting the complete technology dependency chain, Damanat can better align Business Continuity Planning with IT Disaster Recovery, strengthen system resilience, protect critical data, and improve its ability to resume Mortgage Guarantee Origination within approved recovery objectives.
This integrated approach supports effective disruption management, regulatory accountability, stakeholder confidence, and the continued resilience of Damanat’s mortgage guarantee operations.
| eBook 3: Starting Your BCM Implementation |
||||||
| MBCO | P&S | RAR T1 | RAR T2 | RAR T3 | BCS T1 | CBF |
| CBF-1 Mortgage Guarantee Origination | ||||||
| DP | BIAQ P1 | BIAQ P2 | BIAQ P3 | BIAQ P4 | BIAQ P5 | BIAQ P6 |
| BCS T2 | BCS T3 | PD | ||||
To learn more about the course and schedule, click the buttons below for the BCM-300 Business Continuity Management Implementer [BCM-3] and the BCM-5000 Business Continuity Management Expert Implementer [BCM-5].
|
Please feel free to send us a note if you have any questions. |
||