. .

Implementing Business Continuity Management for The Saudi Mortgage Guarantees Services Company: An Enterprise Implementation Guide
BCM Ai Gen_with Cert Logo_5

[BCM] [Damanat] [E3] [PD] [CBF] [1] Mortgage Guarantee Origination

[BCM] [Damanat] [Full Banner] Implementing BCM for The Saudi Mortgage Guarantees Services Company

Recovery procedures convert approved Business Continuity Strategies into coordinated operational actions.

They explain what recovery teams must do before, during and after a disruption to maintain or restore critical products and services within acceptable timeframes.

Within Damanat’s Business Continuity Plan, this procedure establishes the sequence for recovering CBF-1 Mortgage Guarantee Origination, including its people, facilities, systems, information, suppliers and interdependent processes.

It supports operational decision-making by defining responsibilities, escalation routes, manual workarounds, minimum resources and success measures.

Business Continuity recovery procedures differ from Crisis Management procedures. Crisis Management focuses on strategic command, executive decision-making, organisational priorities, stakeholder confidence and enterprise-level consequences.

The recovery procedure focuses on restoring the operational capability required to perform the Critical Business Function. Both processes must operate together: the Crisis Management Team establishes strategic direction, while the CBF Recovery Team implements the approved recovery actions.

Banner [BCM] [E3] [PD] Guidance Notes for Drafting BCM Procedures

Dr Goh Moh Heng
Business Continuity Management Certified Planner-Specialist-Expert

Damanat Legal Disclaimer Banner

Bann_BCM_PD_BCM Plan and Procedure

Banner [BCM] [E3] [PD] Guidance Notes for Drafting BCM ProceduresCBF-1 Mortgage Guarantee Origination

 

Chapter Objective

 

This chapter provides a practical Business Continuity Recovery Procedure for CBF-1 Mortgage Guarantee Origination at The Saudi Mortgage Guarantees Services Company (Damanat).

It is intended for incorporation into an operational Business Continuity Plan and provides the actions, responsibilities, decision criteria and recovery controls required to continue or rapidly resume mortgage guarantee origination following a disruption.

The procedure follows the Business Continuity Management lifecycle:

Reduce → Respond → Recover → Resume → Restore

All timings, resource levels, escalation thresholds and recovery priorities in this chapter are indicative.

They must be validated against Damanat’s approved Business Impact Analysis, Recovery Time Objectives, Minimum Business Continuity Objectives, technology recovery capabilities, regulatory obligations and management-approved recovery strategies.

 

Introduction

[BCM] [Damanat] [E3] [PD] [CBF] [1] Mortgage Guarantee OriginationRecovery procedures convert approved Business Continuity Strategies into coordinated operational actions.

They explain what recovery teams must do before, during and after a disruption to maintain or restore critical products and services within acceptable timeframes.

Within Damanat’s Business Continuity Plan, this procedure establishes the sequence for recovering CBF-1 Mortgage Guarantee Origination, including its people, facilities, systems, information, suppliers and interdependent processes.

It supports operational decision-making by defining responsibilities, escalation routes, manual workarounds, minimum resources and success measures.

Business Continuity recovery procedures differ from Crisis Management procedures. Crisis Management focuses on strategic command, executive decision-making, organisational priorities, stakeholder confidence and enterprise-level consequences.

The recovery procedure focuses on restoring the operational capability required to perform the Critical Business Function. Both processes must operate together: the Crisis Management Team establishes strategic direction, while the CBF Recovery Team implements the approved recovery actions.

Recovery activities must follow the strategies and recovery objectives approved by Damanat. Recovering a function too slowly may result in unacceptable operational, financial, regulatory or reputational consequences.

Attempting recovery faster than the approved capability may also lead to avoidable costs, security weaknesses, processing errors, and resource conflicts.

Recovery actions should therefore be aligned with approved Recovery Time Objectives, Recovery Point Objectives and Minimum Business Continuity Objectives.

CBF-1 comprises 15 interdependent Sub-CBFs. Application intake cannot lead to approval unless validation, eligibility assessment, risk assessment and compliance review are completed.

Guarantee certificates cannot be generated reliably unless decisions, records and supporting data are accurate. Management reporting depends on the completeness of earlier processes.

Recovery must therefore be coordinated across the entire operating chain rather than treating each Sub-CBF as an isolated activity.

This procedure should be validated regularly through document reviews, walkthroughs, tabletop exercises, simulations, partial activations, ICT Disaster Recovery exercises and integrated enterprise exercises.

Testing confirms whether responsibilities are understood, resources are available, systems can be restored, and recovery actions are achievable under realistic conditions.

Banner [Table] [BCM] [E3] [PD] [S] [1] Description of CBF

Part 1: WHAT

Purpose of CBF-1 Mortgage Guarantee Origination

CBF-1 Mortgage Guarantee Origination enables Damanat to receive, validate, assess, approve, issue, register, and monitor mortgage guarantee applications submitted by participating financial institutions.

It supports the controlled origination of mortgage guarantees and provides the operational basis for managing guarantee exposure.

The function is critical because disruption may:

  • Prevent new applications from being received or processed.
  • Delay mortgage financing decisions.
  • Create application backlogs.
  • Affect participating financial institutions and borrowers.
  • Interrupt guarantee approval and issuance.
  • Reduce management visibility over guarantee exposure.
  • Delay regulatory monitoring and reporting.
  • Create data-integrity and documentation risks.
  • Damage stakeholder confidence.
  • Increase operational and compliance exposure.

Damanat should validate the specific statutory and regulatory obligations applicable to mortgage guarantee origination under the requirements of the Saudi Central Bank (SAMA), the Insurance Authority, applicable legislation, regulatory instructions, contractual commitments and internal governance policies.

Services Delivered

CBF-1 delivers or supports:

  • Receipt and registration of mortgage guarantee applications.
  • Validation of submitted data and documents.
  • Borrower eligibility assessment.
  • Property eligibility assessment.
  • Mortgage risk assessment.
  • Guarantee policy compliance review.
  • Verification of participating financial institutions.
  • Approval or rejection of guarantee applications.
  • Generation and issuance of guarantee certificates.
  • Registration of approved guarantees.
  • Notification of decisions to relevant stakeholders.
  • Maintenance of complete and auditable records.
  • Administration of guarantee fees.
  • Post-issuance quality assurance.
  • Management and regulatory reporting.
Principal Customers and Stakeholders

Key stakeholders may include:

  • Participating financial institutions.
  • Mortgage lenders.
  • Eligible borrowers.
  • Damanat’s Executive Management.
  • Risk Management.
  • Finance.
  • Compliance.
  • Legal.
  • Information Technology.
  • Information Security.
  • Internal Audit.
  • The Saudi Central Bank.
  • The Insurance Authority.
  • Government housing and finance stakeholders.
  • Service providers supporting credit, valuation, digital certification, communications and data processing.
Key Dependencies

CBF-1 may depend on:

  • Mortgage guarantee processing platforms.
  • Workflow and case-management systems.
  • Identity and access-management services.
  • Credit information providers.
  • Property valuation information.
  • Participating financial institutions.
  • Secure telecommunications and internet access.
  • Document and records-management systems.
  • Financial and fee-management systems.
  • Regulatory reporting tools.
  • Digital signature or certificate services.
  • Skilled underwriting, risk, compliance and operational personnel.
  • Approved policies, procedures, forms and decision authorities.
  • Alternate workplace and remote-working capability.
Sub-CBF Overview

Sub-CBF Code

Sub-CBF

Primary Purpose

Main Output

Recovery Priority

1.1

1.1 Mortgage Guarantee Application Intake

Receive and register submitted applications

Application record and acknowledgement

Immediate

1.2

Application Validation

Confirm completeness and accuracy of submissions

Validated or returned application

Immediate

1.3

Borrower Eligibility Assessment

Assess borrower eligibility against approved criteria

Borrower eligibility decision

High

1.4

Property Eligibility Assessment

Confirm property compliance with guarantee requirements

Property eligibility decision

High

1.5

Mortgage Risk Assessment

Evaluate mortgage and guarantee exposure

Risk assessment and recommendation

Immediate

1.6

Guarantee Policy Compliance Review

Confirm compliance with approved guarantee policies

Compliance confirmation or exception

Immediate

1.7

Financial Institution Verification

Validate participating institution status and authority

Institution verification result

High

1.8

1.8 Guarantee Approval Decision

Approve, reject, defer, or escalate the application

Formal approval decision

Immediate

1.9

Guarantee Certificate Generation

Produce the approved guarantee certificate

Guarantee certificate

High

1.10

Guarantee Registration

Enter the approved guarantee in the official register

Registered guarantee record

High

1.11

Stakeholder Notification

Communicate decisions and required actions

Confirmed stakeholder notification

High

1.12

Documentation and Record Management

Maintain complete and auditable case records

Controlled case file

High

1.13

Guarantee Fee Administration

Calculate, record and reconcile applicable fees

Fee record and reconciliation

Medium

1.14

Post-Issuance Quality Assurance

Verify accuracy and compliance after issuance

Quality assurance result

Medium

1.15

Management Reporting and Regulatory Monitoring

Monitor volumes, performance, exposures and compliance

Management and regulatory reports

High

 

New call-to-action

Part 2: PRE-CRISIS PREPAREDNESS

Reduce Phase
HOW — Governance

Objective

Establish clear accountability, decision authority and management oversight for recovering CBF-1.

Activities

  • Appoint a CBF Owner for Mortgage Guarantee Origination.
  • Appoint a Recovery Team Leader and alternates.
  • Define activation, escalation and stand-down authority.
  • Establish delegated approval limits for disrupted operations.
  • Define authority for manual processing and exceptional approvals.
  • Identify succession arrangements for all critical decision-makers.
  • Document links with the Crisis Management Team, Incident Management Team, ICT Disaster Recovery Team and Corporate Communications Team.
  • Establish a governance route for regulatory decisions and notifications.
  • Approve recovery priorities for all 15 Sub-CBFs.
  • Confirm who may accept temporary operating risks during recovery.

Deliverables

  • Approved recovery governance structure.
  • Responsibility and accountability matrix.
  • Delegated-authority schedule.
  • Succession list.
  • Escalation and reporting protocol.
  • Regulatory-notification authority matrix.

Ownership

  • Executive Sponsor.
  • CBF Owner.
  • BCM Manager.
  • Legal and Compliance.
  • Human Resources.

Expected Outcome

Recovery decisions can be made quickly without uncertainty, unauthorised activity or avoidable escalation delays.

HOW — Recovery Team

Objective

Ensure that trained personnel are available to activate and operate the recovery procedure.

Activities

  • Maintain a current activation roster.
  • Identify primary and alternate personnel for every critical role.
  • Record office, mobile and emergency contact details.
  • Assign personnel to Sub-CBF recovery teams.
  • Identify specialist skills, system access and approval authorities.
  • Cross-train personnel for critical operational roles.
  • Establish shift arrangements for prolonged recovery.
  • Define welfare, rest and fatigue controls.
  • Identify external specialists who may be required.
  • Validate contact details quarterly or after personnel changes.

Deliverables

  • Recovery-team roster.
  • Call tree.
  • Competency matrix.
  • Cross-training schedule.
  • Shift and relief plan.
  • Staff welfare protocol.

Ownership

  • CBF Recovery Team Leader.
  • Human Resources.
  • Department Managers.
  • BCM Coordinator.

Expected Outcome

The minimum competent workforce can be mobilised within the approved activation timeframe.

HOW — Facilities

Objective

Ensure that an alternate workplace can support the minimum required recovery capacity.

Activities

  • Identify an alternate recovery location.
  • Confirm seating capacity for priority recovery personnel.
  • Provide secure access arrangements.
  • Test access cards, visitor procedures and emergency entry arrangements.
  • Confirm power, cooling, lighting, water and telecommunications.
  • Provide secure meeting and decision rooms.
  • Ensure availability of printers, scanners and secure document storage.
  • Establish physical security and CCTV coverage.
  • Provide arrangements for remote working where appropriate.
  • Confirm transport and accessibility arrangements.
  • Maintain an inventory of recovery-site equipment.

Deliverables

  • Alternate-site plan.
  • Seating and workstation allocation.
  • Access list.
  • Facilities-readiness checklist.
  • Remote-working protocol.
  • Security arrangements.

Ownership

  • Facilities Management.
  • Security Management.
  • ICT.
  • BCM Manager.
  • CBF Owner.

Expected Outcome

Priority recovery personnel can operate from a secure and functional location when the normal workplace is unavailable.

HOW — Technology

Objective

Ensure that systems supporting CBF-1 can be recovered in the correct sequence and within approved recovery objectives.

Activities

  • Identify all systems supporting the 15 Sub-CBFs.
  • Map application, database, network, and authentication dependencies.
  • Align system-recovery targets with approved business RTOs and RPOs.
  • Maintain tested backups and replication arrangements.
  • Validate Disaster Recovery infrastructure.
  • Maintain secure remote-access capability.
  • Test multi-factor authentication and privileged access.
  • Define emergency user-account provisioning.
  • Maintain clean-device and cyber-recovery procedures.
  • Test failover and failback arrangements.
  • Confirm vendor support and escalation contacts.
  • Document minimum technical configurations.
  • Maintain recovery procedures for interfaces with external institutions.

Deliverables

  • Application dependency map.
  • ICT recovery sequence.
  • Backup and replication schedule.
  • Disaster Recovery runbooks.
  • Emergency-access procedure.
  • Technology-recovery test results.

Ownership

  • ICT Disaster Recovery Manager.
  • Application Owners.
  • Information Security.
  • Vendors.
  • CBF Owner.

Expected Outcome

Critical systems can be restored securely and in a sequence that supports business recovery priorities.

HOW — Information

Objective

Ensure that essential records, procedures and decision information remain accessible throughout a disruption.

Activities

  • Identify vital records for every Sub-CBF.
  • Maintain protected copies of policies, procedures and work instructions.
  • Store current forms and templates in an accessible recovery repository.
  • Maintain offline or alternate-access copies of critical documents.
  • Protect approval records, application data and audit trails.
  • Define record-reconstruction procedures.
  • Establish emergency document numbering and version control.
  • Maintain manual logs for use during system outages.
  • Test restoration of records from backup.
  • Confirm retention and confidentiality requirements.

Deliverables

  • Vital-records register.
  • Recovery document repository.
  • Manual forms and registers.
  • Record-reconstruction procedure.
  • Retention and access-control schedule.

Ownership

  • Records Management.
  • CBF Owner.
  • Information Security.
  • ICT.
  • Compliance.

Expected Outcome

Recovery teams can access reliable, current and controlled information even when normal systems are unavailable.

HOW — Communications

Objective

Provide timely, accurate and authorised communications to personnel, regulators, suppliers and stakeholders.

Activities

  • Maintain recovery-team call trees.
  • Develop notification templates for staff, financial institutions, regulators and suppliers.
  • Define communication approval authority.
  • Maintain alternative communication channels.
  • Establish procedures for service-status updates.
  • Coordinate all external statements with Corporate Communications.
  • Define media-handling arrangements.
  • Maintain emergency contact details for SAMA and the Insurance Authority.
  • Establish secure channels for sensitive operational information.
  • Test mass-notification and collaboration tools.
  • Define frequency and format of management situation reports.

Deliverables

  • Communication matrix.
  • Contact directory.
  • Notification templates.
  • Situation-report template.
  • Regulatory communication protocol.
  • Media escalation procedure.

Ownership

  • Corporate Communications.
  • CBF Recovery Team Leader.
  • Compliance.
  • Legal.
  • BCM Manager.

Expected Outcome

Stakeholders receive accurate and coordinated information without disclosure breaches, contradictory messages or unnecessary delay.

HOW — Third Parties

Objective

Ensure external dependencies can support Damanat’s recovery requirements.

Activities

  • Identify critical service providers.
  • Confirm contractual recovery commitments.
  • Review supplier Business Continuity arrangements.
  • Maintain escalation contacts.
  • Confirm alternate service providers.
  • Test critical interfaces and recovery arrangements.
  • Include continuity clauses in contracts.
  • Assess geographic and technology concentration risks.
  • Confirm regulatory and government-agency coordination routes.
  • Establish alternative submission or communication channels.

Deliverables

  • Critical-supplier register.
  • Supplier recovery requirements.
  • Contractual continuity clauses.
  • Escalation directory.
  • Alternate-provider arrangements.
  • Supplier-test records.

Ownership

  • Procurement.
  • Third-Party Risk Management.
  • Legal.
  • ICT.
  • CBF Owner.

Expected Outcome

Critical suppliers and external agencies can support recovery or be replaced through pre-approved alternatives.

HOW — Resources

Objective

Ensure that minimum recovery resources are available when the plan is activated.

Activities

  • Determine minimum staffing by recovery phase.
  • Allocate laptops, phones and secure tokens.
  • Maintain spare power supplies and chargers.
  • Provide printers, scanners and secure storage.
  • Prepare manual forms, stationery and registers.
  • Maintain emergency procurement arrangements.
  • Confirm licences for remote access and applications.
  • Identify transport, accommodation and catering needs for prolonged recovery.
  • Store recovery kits securely.
  • Inspect recovery resources periodically.

Deliverables

  • Minimum-resource register.
  • Recovery-kit inventory.
  • Equipment allocation list.
  • Emergency procurement procedure.
  • Resource-inspection record.

Ownership

  • CBF Owner.
  • Facilities.
  • ICT.
  • Procurement.
  • Human Resources.

Expected Outcome

The Recovery Team can begin operations without waiting for essential equipment, access or supplies.

HOW — Testing

Objective

Validate that the recovery procedure is practical and achievable.

Activities

  • Conduct regular document reviews.
  • Perform recovery-team walkthroughs.
  • Conduct scenario-based tabletop exercises.
  • Simulate disruptions to systems, facilities, suppliers, and staffing.
  • Activate selected manual workarounds.
  • Conduct alternate-site exercises.
  • Integrate CBF-1 testing with ICT Disaster Recovery.
  • Test regulator and stakeholder notification processes.
  • Measure recovery against approved objectives.
  • Record issues, decisions and lessons.

Deliverables

  • Annual exercise schedule.
  • Exercise plans and scenarios.
  • Test evidence.
  • Performance results.
  • Improvement-action register.

Ownership

  • BCM Manager.
  • CBF Owner.
  • ICT Disaster Recovery Team.
  • Internal Audit or independent reviewers.

Expected Outcome

Recovery weaknesses are identified and corrected before an actual disruption.

HOW — Continuous Improvement

Objective

Maintain the accuracy, relevance and effectiveness of the recovery procedure.

Activities

  • Review the procedure at least annually.
  • Update it following organisational or system changes.
  • Incorporate lessons from incidents and exercises.
  • Track audit and review findings.
  • Update contact details and resource inventories.
  • Reassess dependencies.
  • Validate recovery objectives against the current BIA.
  • Review supplier resilience.
  • Obtain formal approval for material changes.
  • Maintain version control and controlled distribution.

Deliverables

  • Updated recovery procedure.
  • Change log.
  • Corrective-action register.
  • Approval record.
  • Current controlled copies.

Ownership

  • CBF Owner.
  • BCM Manager.
  • Document Control.
  • Internal Audit.
  • Functional Owners.

Expected Outcome

The procedure remains current, approved, usable and aligned with Damanat’s operating environment.

 

New call-to-action

Part 3: WITHIN T+24 HOURS

Response, Recovery and Resume Phases
HOW — Detect the Incident

Purpose: Identify an event that may disrupt CBF-1.

Responsible Role: Operations Supervisor or Incident Reporter.

Detailed Actions:

  • Identify abnormal system, facility, supplier or staffing conditions.
  • Record the time, source, and nature of the disruption.
  • Confirm whether the issue affects one or more Sub-CBFs.
  • Contact ICT, Facilities, Security or the relevant supplier.
  • Preserve evidence where cyber, fraud or security concerns exist.
  • Open an incident record.

Expected Completion: Within 15 minutes of detection.

Dependencies: Monitoring tools, staff awareness, reporting channels.

Decision Criteria: Actual or potential interruption exceeding normal operating tolerance.

Success Indicators: Incident logged, affected processes identified, and responsible teams notified.

HOW — Assess Severity

Purpose: Determine the operational and regulatory significance of the incident.

Responsible Role: CBF Recovery Team Leader with Incident Manager.

Detailed Actions:

  • Determine affected services, locations, systems, and stakeholders.
  • Estimate expected duration.
  • Identify impacted Sub-CBFs.
  • Assess application backlog and transaction exposure.
  • Determine whether manual workarounds are available.
  • Assess information-security implications.
  • Identify regulatory deadlines at risk.
  • Assign an incident severity level.

Expected Completion: Within 30 minutes.

Dependencies: Technical assessment, business-impact information, supplier updates.

Decision Criteria: Scale, duration, safety implications, data impact, stakeholder impact and likelihood of missing recovery objectives.

Success Indicators: Severity agreed, assumptions documented and escalation decision made.

HOW — Escalate

Purpose: Ensure that the incident reaches the appropriate management level.

Responsible Role: Incident Manager.

Detailed Actions:

  • Notify the CBF Owner.
  • Notify BCM and Crisis Management personnel.
  • Escalate cyber incidents to Information Security.
  • Escalate premises incidents to Facilities and Security.
  • Escalate regulatory concerns to Compliance and Legal.
  • Initiate executive notification where thresholds are met.
  • Record all escalation decisions.

Expected Completion: Within 45 minutes.

Dependencies: Escalation matrix and current contact lists.

Decision Criteria: Expected disruption exceeds operational tolerance, affects multiple Sub-CBFs or creates regulatory, data, safety or reputational consequences.

Success Indicators: Correct management level engaged and decision authority established.

HOW — Activate the Business Continuity Plan

Purpose: Formally initiate recovery arrangements.

Responsible Role: Authorised CBF Owner, BCM Manager or Incident Commander.

Detailed Actions:

  • Confirm the activation scope.
  • Record activation time and authorising person.
  • Activate the CBF Recovery Team.
  • Identify recovery strategy to be used.
  • Establish operational reporting intervals.
  • Notify the Crisis Management Team where required.
  • Activate alternate-site, remote-working or manual-processing arrangements.

Expected Completion: Within one hour.

Dependencies: Activation authority, recovery strategy and team availability.

Decision Criteria: Normal operations cannot be restored within the approved operational tolerance.

Success Indicators: Plan formally activated, team mobilised and recovery strategy initiated.

HOW — Notify Recovery Teams

Purpose: Mobilise the personnel required to recover CBF-1.

Responsible Role: Recovery Team Coordinator.

Detailed Actions:

  • Initiate the call tree.
  • Confirm availability and location of each team member.
  • Mobilise alternates for unavailable personnel.
  • Issue reporting instructions.
  • Confirm system-access requirements.
  • Allocate roles and shifts.
  • Record successful and unsuccessful contacts.

Expected Completion: Within 90 minutes.

Dependencies: Contact directory, telecommunications, alternates.

Decision Criteria: The required minimum staffing cannot be achieved with primary personnel.

Success Indicators: Minimum recovery team confirmed and reporting instructions acknowledged.

HOW — Notify Stakeholders

Purpose: Inform affected stakeholders without creating confusion or unsupported commitments.

Responsible Role: Corporate Communications with CBF Owner and Compliance.

Detailed Actions:

  • Identify affected financial institutions and internal functions.
  • Prepare an approved service-status message.
  • Explain available alternative submission routes.
  • Provide expected update times rather than unverified restoration promises.
  • Notify regulators where required.
  • Maintain a communication log.
  • Coordinate external statements through authorised channels.

Expected Completion: Initial notification within two hours where material impact exists.

Dependencies: Confirmed facts, approval authority and contact details.

Decision Criteria: Service disruption affects external stakeholders, regulatory obligations or agreed service levels.

Success Indicators: Priority stakeholders receive consistent and authorised information.

HOW — Protect Personnel

Purpose: Preserve life, safety and staff welfare.

Responsible Role: Security, Facilities and Recovery Team Leader.

Detailed Actions:

  • Account for personnel.
  • Follow evacuation or shelter procedures.
  • Prevent access to unsafe areas.
  • Provide medical support where required.
  • Confirm remote-working safety.
  • Establish work-rest cycles.
  • Provide psychological and welfare support during prolonged incidents.

Expected Completion: Immediate and continuous.

Dependencies: Emergency response arrangements.

Decision Criteria: Any threat to health, safety or wellbeing.

Success Indicators: Personnel accounted for, and no recovery activity compromises safety.

HOW — Secure Facilities

Purpose: Prevent further damage, unauthorised access or evidence loss.

Responsible Role: Facilities and Security.

Detailed Actions:

  • Isolate affected areas.
  • Control physical access.
  • Protect equipment and documents.
  • Coordinate with emergency services.
  • Preserve evidence.
  • Assess whether partial re-entry is safe.
  • Maintain security at the alternate site.

Expected Completion: Initial controls within one hour.

Dependencies: Security personnel, emergency services and building management.

Decision Criteria: Facility is unsafe, inaccessible or vulnerable.

Success Indicators: Site controlled and further loss prevented.

HOW — Protect Information

Purpose: Preserve confidentiality, integrity, availability and evidential value.

Responsible Role: Information Security and Records Management.

Detailed Actions:

  • Isolate compromised systems where necessary.
  • Preserve logs and audit trails.
  • Prevent unauthorised copying or transfer.
  • Secure physical records.
  • Confirm backup integrity.
  • Suspend questionable accounts or credentials.
  • Establish approved channels for recovery information.
  • Document any suspected data loss.

Expected Completion: Immediate and continuous.

Dependencies: Security tools, access controls, and backup systems.

Decision Criteria: Suspected compromise, corruption, loss or unauthorised access.

Success Indicators: Information exposure contained and recoverable data preserved.

HOW — Activate the Alternate Site

Purpose: Establish an operational workplace when the normal site is unavailable.

Responsible Role: Facilities Recovery Coordinator.

Detailed Actions:

  • Open and inspect the alternate site.
  • Activate access controls.
  • Allocate workstations by priority.
  • Confirm connectivity, power, and communications.
  • Establish secure printing and storage.
  • Set up the Recovery Team coordination room.
  • Register arriving personnel.
  • Report capacity or equipment shortages.

Expected Completion: Within four hours, subject to approved strategy.

Dependencies: Site availability, transport, ICT and security.

Decision Criteria: Primary site unavailable beyond the agreed tolerance.

Success Indicators: Minimum recovery team can work securely from the alternate location.

HOW — Activate ICT Recovery

Purpose: Initiate technology restoration in the approved sequence.

Responsible Role: ICT Disaster Recovery Manager.

Detailed Actions:

  • Declare the technology-recovery event.
  • Confirm affected infrastructure and applications.
  • Activate the Disaster Recovery site or cloud recovery environment.
  • Restore network, identity and security services.
  • Restore databases and applications in order of priority.
  • Coordinate vendor support.
  • Record restoration times and issues.
  • Maintain security monitoring throughout recovery.

Expected Completion: Initiated within one hour of activation.

Dependencies: DR environment, backups, vendors, and technical personnel.

Decision Criteria: Production systems cannot be restored within business tolerance.

Success Indicators: Core infrastructure restored and priority application recovery underway.

HOW — Restore Critical Systems

Purpose: Recover the applications required for priority Sub-CBFs.

Responsible Role: Application Owners and ICT Disaster Recovery Team.

Detailed Actions:

  1. Restore identity, authentication, and security monitoring.
  2. Restore network and telecommunications.
  3. Restore the mortgage guarantee processing platform.
  4. Restore workflow and case-management tools.
  5. Restore document and records-management systems.
  6. Restore reporting and financial interfaces.
  7. Validate external connections.
  8. Perform technical and business acceptance tests.
  9. Release systems to authorised users.

Expected Completion: In accordance with approved ICT and business RTOs.

Dependencies: Infrastructure, data restoration, cybersecurity validation and vendor support.

Decision Criteria: System is technically stable, secure and capable of supporting minimum business operations.

Success Indicators: Authorised users can process priority cases without critical errors.

HOW — Recover Vital Records

Purpose: Restore the information required for controlled processing.

Responsible Role: Records Manager and Application Owners.

Detailed Actions:

  • Retrieve electronic records from replicated or backup storage.
  • Retrieve controlled offline copies where required.
  • Validate record completeness and currency.
  • Establish a temporary manual register for missing records.
  • Prioritise records associated with pending approvals and regulatory deadlines.
  • Preserve version control.
  • Document unrecoverable information.

Expected Completion: Within approved information-recovery objectives.

Dependencies: Backup integrity, repository access and record ownership.

Decision Criteria: Records are complete enough to support safe processing.

Success Indicators: Priority case files and decision records are available and validated.

HOW — Prioritise Sub-CBF Recovery

Purpose: Resume activities in the sequence that produces the highest-value operational outcome.

Responsible Role: CBF Recovery Team Leader.

Detailed Actions by Sub-CBF:

1.1 Mortgage Guarantee Application Intake
  • Open alternate electronic or secure manual intake channels.
  • Date- and time-stamp all submissions.
  • Issue acknowledgements where possible.
  • Separate urgent, incomplete and duplicate applications.
1.2 Application Validation
  • Validate mandatory fields and documents.
  • Prioritise applications linked to near-term financing deadlines.
  • Record deficiencies for follow-up.
1.3 Borrower Eligibility Assessment
  • Resume assessment using verified borrower data.
  • Escalate cases dependent on unavailable external information.
  • Prevent approval based on unverified assumptions.
1.4 Property Eligibility Assessment
  • Confirm access to property and valuation data.
  • Hold cases where required evidence cannot be validated.
  • Use approved alternate valuation sources where permitted.
1.5 Mortgage Risk Assessment
  • Restore risk models and assessment tools.
  • Apply manual assessment only where approved.
  • Route high-value or exceptional cases to senior reviewers.
1.6 Guarantee Policy Compliance Review
  • Confirm current policy versions.
  • Document exceptions and approvals.
  • Suspend cases where mandatory controls cannot be completed.
1.7 Financial Institution Verification
  • Verify the institution's status, authorised contacts, and submission authority.
  • Use controlled alternate verification processes if the normal interface is unavailable.
1.8 Guarantee Approval Decision
  • Convene authorised decision-makers.
  • Apply delegated approval limits.
  • Record decisions in the recovery register.
  • Separate approved, rejected, deferred and escalated cases.
1.9 Guarantee Certificate Generation
  • Generate certificates through the recovered platform.
  • Use controlled manual certificates only where approved.
  • Apply unique numbering and dual review.
1.10 Guarantee Registration
  • Register approved guarantees in the official system or temporary controlled register.
  • Prevent duplicate registration.
  • Reconcile temporary records when the system is restored.
1.11 Stakeholder Notification
  • Notify financial institutions and relevant internal teams.
  • Confirm successful delivery.
  • Record failed or delayed notifications.
1.12 Documentation and Record Management
  • Assemble a complete case file.
  • Link manual and electronic records.
  • Maintain audit trails and version control.
1.13 Guarantee Fee Administration
  • Calculate and record applicable fees.
  • Defer non-critical collection activity only with approval.
  • Maintain reconciliation records.

 

1.14 Post-Issuance Quality Assurance
  • Prioritise high-risk and manually processed guarantees.
  • Check approvals, data, certificate accuracy and registration.
  • Correct errors promptly.
1.15 Management Reporting and Regulatory Monitoring
  • Produce situation reports.
  • Monitor application volumes, decisions, backlog and control exceptions.
  • Identify regulatory deadlines and reporting concerns.
  • Escalate material deviations.

Expected Completion: Priority Sub-CBFs operational within approved RTOs.

Dependencies: Systems, records, staff, approvals and external providers.

Decision Criteria: Activities may resume only when minimum controls and required data are available.

Success Indicators: Priority applications progress through a controlled end-to-end process.

HOW — Resume Priority Activities

Purpose: Deliver the Minimum Business Continuity Objective.

Responsible Role: Sub-CBF Owners.

Detailed Actions:

  • Process urgent and high-priority applications first.
  • Defer non-essential administrative work.
  • Apply approved capacity targets.
  • Establish daily processing goals.
  • Monitor errors, exceptions, and delays.
  • Maintain segregation of duties.
  • Report service performance.

Expected Completion: Within approved RTO.

Dependencies: Minimum staff, systems, and information.

Decision Criteria: Safe minimum operating conditions achieved.

Success Indicators: Priority cases processed within the agreed recovery service level.

HOW — Implement Manual Workarounds

Purpose: Continue essential work when normal systems remain unavailable.

Responsible Role: CBF Recovery Team Leader.

Detailed Actions:

  • Activate approved manual forms and registers.
  • Assign unique temporary reference numbers.
  • Require dual review for approvals and certificates.
  • Secure paper and offline records.
  • Record all transactions requiring later system entry.
  • Limit manual processing to approved categories.
  • Monitor error rates and workload.
  • Stop the workaround if control risks become unacceptable.

Expected Completion: As soon as required and within approved manual-workaround tolerance.

Dependencies: Forms, procedures, trained personnel and secure storage.

Decision Criteria: Workaround remains controlled, auditable and within delegated authority.

Success Indicators: Priority operations continue without loss of traceability.

HOW — Manage Backlogs

Purpose: Control accumulated work and avoid uncontrolled service deterioration.

Responsible Role: Operations Manager.

Detailed Actions:

  • Quantify backlog by Sub-CBF.
  • Classify cases by urgency, age, value, and regulatory significance.
  • Prevent duplicate submissions.
  • Set daily clearance targets.
  • Allocate additional staff.
  • Extend operating hours where approved.
  • Communicate realistic service expectations.
  • Monitor backlog age and error rates.

Expected Completion: Initial backlog assessment within six hours of activation.

Dependencies: Reliable volume information and staffing.

Decision Criteria: Backlog threatens MTPD, service commitments or control quality.

Success Indicators: Backlog growth stabilised and reduction plan approved.

HOW — Coordinate with Government Agencies and Regulators

Purpose: Maintain regulatory alignment and government coordination.

Responsible Role: Compliance and Executive Management.

Detailed Actions:

  • Assess notification obligations.
  • Prepare factual incident summaries.
  • Explain affected services and recovery measures.
  • Request alternative submission arrangements where necessary.
  • Maintain records of instructions received.
  • Escalate material regulatory risks.
  • Coordinate messages with Legal and Corporate Communications.

Expected Completion: Within applicable regulatory timelines.

Dependencies: Verified incident information and authorised spokespersons.

Decision Criteria: Disruption affects regulatory reporting, customer outcomes, controlled records or critical services.

Success Indicators: Required notifications completed and regulatory directions incorporated.

HOW — Coordinate Suppliers

Purpose: Restore critical external services.

Responsible Role: Procurement and Service Owners.

Detailed Actions:

  • Contact affected suppliers.
  • Invoke contractual continuity provisions.
  • Request recovery status and estimated restoration milestones.
  • Escalate through supplier management.
  • Activate alternate suppliers where approved.
  • Monitor supplier performance.
  • Document service failures and decisions.

Expected Completion: Initial supplier engagement within two hours.

Dependencies: Contracts, service contacts and alternatives.

Decision Criteria: Supplier service failure prevents the achievement of recovery objectives.

Success Indicators: Supplier recovery plan agreed or alternate service activated.

HOW — Monitor Progress

Purpose: Maintain operational control and support informed decisions.

Responsible Role: Recovery Team Leader.

Detailed Actions:

  • Track recovery milestones.
  • Monitor staffing, systems, facilities, and supplier status.
  • Measure transaction volumes and backlogs.
  • Record control exceptions.
  • Compare progress with RTOs.
  • Update the incident action plan.
  • Hold scheduled recovery briefings.

Expected Completion: Continuous, with reports at approved intervals.

Dependencies: Accurate status information.

Decision Criteria: Variances require corrective action or escalation.

Success Indicators: Management receives reliable and timely recovery status.

HOW — Escalate Recovery Issues

Purpose: Resolve obstacles that exceed Recovery Team authority.

Responsible Role: CBF Owner.

Detailed Actions:

  • Identify the issue and affected objective.
  • Quantify operational and regulatory consequences.
  • Present available options.
  • Escalate resource conflicts.
  • Request executive risk acceptance where necessary.
  • Record decisions and conditions.
  • Reassess recovery priorities.

Expected Completion: Immediately when a critical milestone is threatened.

Dependencies: Escalation route and decision authority.

Decision Criteria: RTO, MBCO, regulatory obligation or critical control is at risk.

Success Indicators: Issue resolved, accepted or transferred to authorised management.

HOW — Report to Management

Purpose: Provide executive oversight.

Responsible Role: CBF Owner or Recovery Team Leader.

Detailed Actions:

  • Report current impact.
  • Confirm services resumed.
  • Identify missed or threatened objectives.
  • Report staffing, system, and supplier status.
  • Quantify backlog.
  • Identify regulatory concerns.
  • Request decisions or resources.
  • State next reporting time.

Expected Completion: Initial report within two hours of activation and periodically thereafter.

Dependencies: Consolidated recovery information.

Decision Criteria: Frequency increases with impact or uncertainty.

Success Indicators: Management decisions are supported by current information.

HOW — Prepare for Sustained Recovery

Purpose: Transition from immediate response to prolonged controlled operations.

Responsible Role: CBF Recovery Team Leader and Human Resources.

Detailed Actions:

  • Establish shift rotations.
  • Mobilise relief personnel.
  • Confirm accommodation and transport.
  • Replenish equipment and supplies.
  • Review staff welfare.
  • Prepare expanded workspace.
  • Review financial and procurement requirements.
  • Establish a multi-day backlog plan.
  • Confirm continuing regulatory communication.

Expected Completion: Before the end of the first 24 hours.

Dependencies: Resources, staffing, and incident outlook.

Decision Criteria: Full restoration is not expected within 24 hours.

Success Indicators: Recovery operations can continue safely beyond the initial period.

 

New call-to-action

Part 4: AFTER T+24 HOURS

Restore and Return Phase
HOW — Expand Recovery Operations

Purpose: Increase capacity beyond the initial minimum service level.

Detailed Implementation:

  • Add workstations and personnel.
  • Extend processing to additional application categories.
  • Increase supervisory coverage.
  • Expand supplier and stakeholder support.
  • Reassess daily recovery targets.
  • Maintain control quality while increasing volume.

Responsible Owner: CBF Owner.

Deliverables: Expanded recovery plan and revised capacity targets.

Success Measures: Increased throughput without unacceptable error or control failure.

HOW — Restore Deferred Activities

Purpose: Resume activities postponed during the initial recovery period.

Detailed Implementation:

  • List all deferred work.
  • Prioritise according to age, risk and obligation.
  • Allocate responsible teams.
  • Confirm systems and records are available.
  • Track completion separately from new work.

Responsible Owner: Sub-CBF Owners.

Deliverables: Deferred-activity register and clearance plan.

Success Measures: Deferred work resumed within approved limits.

HOW — Increase Staffing

Purpose: Support higher processing volumes and prolonged recovery.

Detailed Implementation:

  • Mobilise alternates and cross-trained personnel.
  • Use approved temporary resources.
  • Adjust shifts and supervision.
  • Maintain segregation of duties.
  • Monitor fatigue and competence.

Responsible Owner: Human Resources and Operations.

Deliverables: Revised staffing roster.

Success Measures: Adequate coverage with no critical role gaps.

HOW — Restore ICT Services

Purpose: Recover remaining systems and return technology capacity toward normal levels.

Detailed Implementation:

  • Restore deferred applications.
  • Verify interfaces and reporting feeds.
  • Remove temporary configurations.
  • Monitor stability and performance.
  • Plan controlled failback.
  • Maintain cyber monitoring.

Responsible Owner: ICT Disaster Recovery Manager.

Deliverables: Technology restoration report.

Success Measures: All required services available, secure and stable.

HOW — Validate Data

Purpose: Confirm that recovered information is accurate and complete.

Detailed Implementation:

  • Compare recovered records with backups and manual logs.
  • Identify missing or duplicated transactions.
  • Verify timestamps and approval records.
  • Reconstruct missing information where possible.
  • Escalate material discrepancies.

Responsible Owner: Data Owners and ICT.

Deliverables: Data-validation report.

Success Measures: Recovered data accepted by business owners.

HOW — Validate Records

Purpose: Confirm that each case contains complete and auditable documentation.

Detailed Implementation:

  • Review files for mandatory records.
  • Link manual documents to electronic cases.
  • Confirm current policy and form versions.
  • Validate approvals and exceptions.
  • Correct indexing and classification errors.

Responsible Owner: Records Management.

Deliverables: Record-validation checklist.

Success Measures: Case records meet legal, regulatory and internal requirements.

HOW — Reconcile Manual Transactions

Purpose: Transfer temporary manual activity into normal systems without duplication or omission.

Detailed Implementation:

  • Freeze manual registers at a controlled cut-off time.
  • Number and verify all transactions.
  • Enter them into restored systems.
  • Perform independent reconciliation.
  • Retain original manual evidence.
  • investigate variances.

Responsible Owner: Operations and Finance.

Deliverables: Signed reconciliation report.

Success Measures: All manual transactions accounted for exactly once.

HOW — Recover Outstanding Applications

Purpose: Progress applications interrupted by the incident.

Detailed Implementation:

  • Identify each outstanding application.
  • Determine its last completed stage.
  • Validate data before continuing.
  • Contact financial institutions where information requires reconfirmation.
  • Prioritise aged and time-sensitive cases.
  • Track completion.

Responsible Owner: Mortgage Guarantee Operations Manager.

Deliverables: Outstanding-application register.

Success Measures: Interrupted cases recovered without inappropriate duplication or loss.

HOW — Resolve Backlogs

Purpose: Return transaction volumes and service levels to normal.

Detailed Implementation:

  • Forecast backlog-clearance requirements.
  • Establish daily reduction targets.
  • Assign dedicated clearance teams.
  • Extend operating hours if approved.
  • Prioritise high-risk and aged cases.
  • Monitor quality.
  • report progress daily.

Responsible Owner: CBF Owner.

Deliverables: Backlog-clearance report.

Success Measures: Backlog reduced to normal operating levels.

HOW — Resume Supplier Services

Purpose: Reinstate normal third-party support.

Detailed Implementation:

  • Confirm supplier service stability.
  • Validate data exchanges.
  • Withdraw temporary alternatives gradually.
  • Reconcile supplier transactions.
  • Review contractual performance.
  • Record failures for follow-up.

Responsible Owner: Procurement and Service Owners.

Deliverables: Supplier-restoration confirmation.

Success Measures: Required supplier services operating within agreed levels.

HOW — Resume Inter-agency Processes

Purpose: Restore normal interactions with regulators and government stakeholders.

Detailed Implementation:

  • Reinstate normal reporting channels.
  • Submit delayed information.
  • Reconcile temporary communications.
  • Confirm outstanding instructions.
  • Notify agencies of restored service levels.

Responsible Owner: Compliance and Regulatory Affairs.

Deliverables: Regulatory and inter-agency closure record.

Success Measures: No unaddressed reporting or coordination obligations remain.

HOW — Conduct Quality Assurance

Purpose: Confirm that recovery processing meets required standards.

Detailed Implementation:

  • Sample manually and electronically processed cases.
  • Review eligibility, risk, compliance, and approval decisions.
  • Validate certificate accuracy and registration.
  • Assess fee calculations.
  • Identify systemic errors.
  • Initiate corrective action.

Responsible Owner: Quality Assurance Manager.

Deliverables: Recovery quality-assurance report.

Success Measures: Error rates remain within approved tolerance and material defects are corrected.

HOW — Monitor Service Levels

Purpose: Confirm progress toward normal performance.

Detailed Implementation:

  • Track turnaround time.
  • Monitor backlog age and volume.
  • Compare capacity with normal operations.
  • Measure stakeholder complaints.
  • Track system availability.
  • Report exceptions.

Responsible Owner: Management Reporting Team.

Deliverables: Service-restoration dashboard.

Success Measures: Service levels improve consistently toward business-as-usual targets.

HOW — Return to the Primary Site

Purpose: Transfer operations safely back to the normal workplace.

Detailed Implementation:

  • Confirm building safety and readiness.
  • Validate ICT connectivity and security.
  • Approve the return sequence.
  • communicate relocation instructions.
  • Transfer records and equipment securely.
  • maintain fallback capability during transition.
  • Verify operations after return.

Responsible Owner: Facilities Manager and CBF Owner.

Deliverables: Primary-site return plan.

Success Measures: Operations transferred without interruption or loss.

HOW — Stand Down the Alternate Site

Purpose: Close temporary recovery arrangements in a controlled manner.

Detailed Implementation:

  • Confirm all teams have relocated.
  • Remove sensitive information.
  • inventory equipment.
  • Terminate temporary access.
  • archive recovery logs.
  • Restore the site to standby condition.
  • Record damage or replenishment needs.

Responsible Owner: Facilities and Security.

Deliverables: Alternate-site stand-down checklist.

Success Measures: Site secured, reconciled and ready for future activation.

HOW — Restore Normal Governance

Purpose: Return decision-making and approvals to normal organisational structures.

Detailed Implementation:

  • Withdraw temporary delegations.
  • Close emergency approval routes.
  • Reinstate normal committee oversight.
  • Transfer unresolved matters to business owners.
  • Archive crisis decisions.
  • Formally close recovery governance.

Responsible Owner: Executive Management.

Deliverables: Governance restoration notice.

Success Measures: Temporary authorities withdrawn and normal accountability restored.

HOW — Conduct the Post-Incident Review

Purpose: Evaluate the effectiveness of the response and recovery.

Detailed Implementation:

  • Collect input from all teams.
  • Compare performance with objectives.
  • Identify delays, failures, and successful practices.
  • review decisions and communications.
  • Assess supplier performance.
  • determine root causes.

Responsible Owner: BCM Manager.

Deliverables: Post-Incident Review report.

Success Measures: Findings are evidence-based, agreed and assigned.

HOW — Capture Lessons Learned

Purpose: Convert experience into measurable improvements.

Detailed Implementation:

  • Record lessons by people, process, facilities, technology, suppliers, and information.
  • Distinguish immediate fixes from strategic improvements.
  • Assign owners and completion dates.
  • Track actions through governance committees.

Responsible Owner: BCM Manager.

Deliverables: Lessons-learned register.

Success Measures: Actions completed and effectiveness verified.

HOW — Update BCM Documentation

Purpose: Correct weaknesses identified during the incident.

Detailed Implementation:

  • Revise recovery procedures.
  • Update contact lists.
  • Update manual workarounds.
  • Revise resource requirements.
  • Incorporate new dependencies.
  • Obtain approval and redistribute controlled documents.

Responsible Owner: CBF Owner and BCM Manager.

Deliverables: Updated Business Continuity documentation.

Success Measures: Revised documents approved and available to users.

HOW — Update the Risk Assessment

Purpose: Reflect newly identified threats, vulnerabilities, and control weaknesses.

Detailed Implementation:

  • Reassess incident causes.
  • Evaluate control performance.
  • Identify emerging risks.
  • Revise likelihood and impact ratings.
  • establish treatment actions.

Responsible Owner: Enterprise Risk Management.

Deliverables: Updated Risk Assessment and treatment plan.

Success Measures: Material lessons incorporated into risk governance.

HOW — Improve Recovery Strategies

Purpose: Strengthen future recovery capability.

Detailed Implementation:

  • Review alternate-site capacity.
  • Assess DR architecture.
  • Improve remote-working capability.
  • Reduce supplier concentration.
  • Improve automation, redundancy and cross-training.
  • Prepare investment proposals.

Responsible Owner: CBF Owner and BCM Steering Committee.

Deliverables: Recovery-strategy improvement plan.

Success Measures: Approved actions reduce identified recovery gaps.

HOW — Schedule Future Exercises

Purpose: Verify that corrective actions improve readiness.

Detailed Implementation:

  • Design exercises around identified weaknesses.
  • Assign exercise objectives.
  • Involve relevant internal and external teams.
  • Test revised procedures.
  • Measure results against approved criteria.

Responsible Owner: BCM Manager.

Deliverables: Exercise schedule and test plan.

Success Measures: Corrective actions validated under realistic conditions.

Recovery Procedure Matrix for CBF-1 Mortgage Guarantee Origination

 

Sub-CBF Code

Sub-CBF

Immediate Actions

Recovery Actions

Restore Actions

Primary Owner

Key Dependencies

1.1

Mortgage Guarantee Application Intake

Open alternate intake channel; register all submissions

Restore intake platform; prioritise urgent cases

Reconcile manual and electronic submissions

Application Intake Manager

Financial institutions, portal, email, records

1.2

Application Validation

Screen for mandatory data and documents

Resume validation workflow

Clear validation backlog and correct errors

Validation Team Leader

Application records, procedures, staff

1.3

Borrower Eligibility Assessment

Identify urgent pending assessments

Restore eligibility tools and verified data sources

Complete deferred assessments and QA review

Eligibility Assessment Manager

Borrower data, credit information, policy

1.4

Property Eligibility Assessment

Hold cases lacking reliable property evidence

Restore valuation and property-data access

Complete deferred property reviews

Property Assessment Manager

Valuers, property records, criteria

1.5

Mortgage Risk Assessment

Prioritise high-value and time-sensitive cases

Restore models and risk systems

Reassess manual or exceptional decisions

Head of Mortgage Risk

Risk platform, data, analysts

1.6

Guarantee Policy Compliance Review

Confirm current policy and exception authority

Resume compliance workflow

Review emergency exceptions

Compliance Review Manager

Policy repository, Legal, Compliance

1.7

Financial Institution Verification

Verify institution status through alternate means

Restore normal verification interface

Reconcile temporary verification records

Relationship Management Head

Institution register, authorised contacts

1.8

Guarantee Approval Decision

Convene authorised decision-makers

Restore approval workflow and delegated authority

Review emergency decisions and exceptions

Approval Committee Chair

Assessments, compliance, authority matrix

1.9

Guarantee Certificate Generation

Prepare controlled temporary certificates if approved

Restore certificate-generation platform

Replace or reconcile temporary certificates

Guarantee Administration Manager

Approval records, digital certificates, templates

1.10

Guarantee Registration

Use a controlled temporary register

Restore registration system

Reconcile and validate all registrations

Registration Manager

Guarantee records, database, identifiers

1.11

Stakeholder Notification

Issue initial status and decision notifications

Restore automated notifications

Confirm delivery and resolve failures

Communications and Relationship Manager

CRM, email, SMS, approved messages

1.12

Documentation and Record Management

Secure records and initiate manual case files

Restore document repository

Link, index and validate all records

Records Manager

EDMS, storage, retention controls

1.13

Guarantee Fee Administration

Record fees in a temporary ledger

Restore finance and fee systems

Reconcile charges, receipts and exceptions

Finance Manager

ERP, banking, guarantee records

1.14

Post-Issuance Quality Assurance

Prioritise manually processed and high-risk cases

Resume QA sampling and control checks

Complete retrospective review

Quality Assurance Manager

Case files, approval records, certificates

1.15

Management Reporting and Regulatory Monitoring

Produce manual situation and exposure reports

Restore reporting tools and data feeds

Submit delayed reports and reconcile metrics

Management Reporting and Compliance Head

BI tools, case data, regulatory requirements

 

Management Checklists

Before Disruption
  • CBF Owner and Recovery Team Leader appointed.
  • Recovery-team contact list current.
  • Delegated authorities approved.
  • Alternate personnel identified.
  • Recovery systems and applications mapped.
  • ICT recovery targets aligned with business RTOs.
  • Vital records identified and protected.
  • Alternate-site access tested.
  • Remote-working arrangements tested.
  • Manual forms and registers available.
  • Critical suppliers assessed.
  • Regulatory contacts verified.
  • Recovery procedure exercised.
  • Corrective actions tracked to completion.
During Disruption
  • Incident detected and logged.
  • Severity assessed.
  • Escalation completed.
  • Business Continuity Plan activated.
  • Recovery teams notified.
  • Personnel protected and accounted for.
  • Facilities secured.
  • Information protected.
  • Alternate site or remote working activated.
  • ICT Disaster Recovery initiated.
  • Vital records recovered.
  • Sub-CBF recovery prioritised.
  • Stakeholders notified.
  • Regulators notified where required.
  • Manual workarounds controlled.
  • Backlog measured.
  • Management reports issued.
After Disruption
  • Deferred systems restored.
  • Data validated.
  • Records validated.
  • Manual transactions reconciled.
  • Outstanding applications recovered.
  • Backlog-clearance plan implemented.
  • Supplier services restored.
  • Regulatory submissions completed.
  • Quality-assurance review conducted.
  • Service levels monitored.
  • Primary-site return approved.
Return to Business-as-Usual
  • Primary site confirmed safe and ready.
  • Operations transferred successfully.
  • Alternate site stood down.
  • Temporary access withdrawn.
  • Emergency delegations cancelled.
  • Normal governance restored.
  • Staff welfare reviewed.
  • Stakeholders informed of service restoration.
  • Incident formally closed.
Lessons Learned
  • Post-Incident Review completed.
  • Root causes identified.
  • Recovery performance compared with objectives.
  • Supplier performance reviewed.
  • Communication effectiveness assessed.
  • Corrective actions assigned.
  • BCM documentation updated.
  • Risk Assessment updated.
  • Recovery strategies reviewed.
  • Follow-up exercises scheduled.

 

Common Recovery Issues

 

Recovery Issue

Likely Cause

Operational Impact

Immediate Response

Long-Term Corrective Action

Staffing shortages

Illness, transport disruption, concentration of specialist knowledge

Priority processes cannot meet minimum capacity

Activate alternates, cross-trained staff and revised shifts

Increase cross-training, succession and geographic workforce diversity

ICT failures

Infrastructure outage, failed recovery, cyber incident

Applications and records unavailable

Activate DR, prioritise critical systems and use controlled workarounds

Improve architecture, redundancy, testing and monitoring

Supplier failures

Supplier outage, insolvency, telecommunications failure

External data or services unavailable

Escalate supplier, activate alternatives and adjust priorities

Strengthen contracts, diversify providers and test supplier continuity

Communications failures

Network outage, outdated contacts, overloaded channels

Teams and stakeholders receive delayed or conflicting information

Use alternate channels and centralise message approval

Improve channel redundancy, contact maintenance and communication exercises

Inaccessible facilities

Fire, flood, security event or utility failure

Staff cannot access normal workplace

Activate alternate site or remote work

Improve site resilience and alternate-location capacity

Unavailable records

Data corruption, backup failure, inaccessible repository

Assessments and approvals cannot be completed reliably

Retrieve alternate copies and start controlled manual records

Improve backup, replication, classification and restoration testing

Decision bottlenecks

Unavailable approvers or unclear authority

Applications accumulate, and recovery slows

Activate delegated authority and executive escalation

Strengthen succession and pre-approved emergency authority

Regulatory delays

Portal outage, incomplete data or unclear reporting obligation

Reporting deadlines missed or supervisory concern increases

Contact regulator and agree alternate submission route

Establish regulatory contingency procedures and test reporting alternatives

Stakeholder concerns

Delayed service, inconsistent updates or uncertainty

Complaints and reputational damage

Issue factual updates and prioritise critical cases

Improve communication planning, service transparency and relationship management

Prolonged recovery

Extensive damage, failed DR, supplier dependency or large backlog

Staff fatigue, rising costs and missed objectives

Expand staffing, shifts, facilities and executive oversight

Invest in resilience, improve recovery strategy and conduct severe-scenario exercises

 

Testing the Procedure

Document Review

Conduct a structured review to confirm that names, contacts, systems, dependencies, forms, recovery objectives and responsibilities remain current.

This should occur at least annually and after material change.

Walkthrough

Recovery-team members should review the procedure step by step and explain how they would perform each action.

The walkthrough should identify ambiguity, missing information, and unrealistic assumptions.

Tabletop Exercise

Use a facilitated scenario such as loss of the mortgage guarantee platform, denial of access to the primary office, cyber compromise, or failure of a critical external service.

Participants should make decisions, apply escalation procedures and assess Sub-CBF recovery priorities.

Simulation

Simulate realistic operational conditions, including incomplete information, absent personnel, supplier delays, high application volumes and regulatory deadlines.

No live production activity needs to be affected, but participants should generate realistic records and situation reports.

Partial Activation

Activate selected components, such as:

  • Recovery-team notification.
  • Alternate-site mobilisation.
  • Manual application intake.
  • Regulatory communications.
  • Restoration of selected systems.
  • Reconciliation of test transactions.
Full Activation

Mobilise the complete CBF Recovery Team and operate the recovery procedure for a defined period.

Test the full end-to-end process from application intake through approval, certificate generation, registration, notification and reporting.

Integrated BCM Exercise

Coordinate CBF-1 recovery with:

  • Crisis Management.
  • Incident Management.
  • ICT Disaster Recovery.
  • Corporate Communications.
  • Facilities.
  • Security.
  • Human Resources.
  • Procurement.
  • Legal and Compliance.

This confirms that strategic command and operational recovery operate together.

ICT Disaster Recovery Exercise

Test:

  • Infrastructure failover.
  • Application recovery.
  • Database restoration.
  • Authentication.
  • Cybersecurity monitoring.
  • External interfaces.
  • Business acceptance testing.
  • Failback to normal production.

Business users should verify that recovered systems can support priority processes in practice, rather than relying solely on technical test results.

Post-Exercise Review

After every exercise:

  • Compare actual performance with objectives.
  • Identify delays, control failures, and successful practices.
  • Confirm whether all 15 Sub-CBFs were considered.
  • Assign corrective actions.
  • Update plans and procedures.
  • Schedule retesting.
  • Report material weaknesses to management.

 

Banner [BCM] [E3] [PD] [S] [1] [Summary] Critical Business Function

Recovery procedures are essential because they transform Damanat’s approved Business Continuity Strategies into practical, role-based actions.

They provide recovery teams with the sequence, responsibilities, decision criteria, and controls required to continue or resume mortgage guarantee origination following a disruptive event.

The continuity of CBF-1 depends on coordinated recovery across all 15 Sub-CBFs.

Application intake, validation, eligibility assessment, risk assessment, compliance review, approval, certificate generation, registration, notification, records management, fee administration, quality assurance, and reporting form an interconnected operational chain.

Recovering one component without its dependencies will not restore the complete service.

The procedure must remain practical. It should reflect available personnel, real system capabilities, approved facilities, reliable information, tested suppliers and achievable recovery objectives.

It should not depend on unrealistic staffing levels, untested technology or undocumented assumptions.

Continual improvement is necessary because personnel, systems, policies, suppliers, regulatory obligations and operating volumes change.

Lessons from incidents, exercises, audits and management reviews should be incorporated into the procedure through controlled updates.

Regular exercises provide the evidence that Damanat’s recovery arrangements are operationally ready.

They test whether personnel understand their responsibilities, systems recover within approved objectives, manual workarounds remain controlled, and dependencies can support the required service levels.

The Saudi Mortgage Guarantees Services Company can maintain critical mortgage guarantee services only through well-documented, regularly tested, and continually improved recovery procedures for every Sub-CBF supporting CBF-1 Mortgage Guarantee Origination.

 

[BCM] [Damanat] [3/4 Banner] Implementing BCM for The Saudi Mortgage Guarantees Services Company

eBook 3: Starting Your BCM Implementation
MBCO P&S RAR T1 RAR T2 RAR T3 BCS T1  CBF
[BCM] [Damanat] [E3] [BIA] MBCO Corporate MBCO [BCM] [Damanat] [E3] [BIA] [PS] Key Product and Services [BCM] [Damanat] [E3] [RAR] [T1] List of Threats [BCM] [Damanat] [E3] [RAR] [T2] Treatment and Control [BCM] [Damanat] [E3] [RAR] [T3] Risk Impact and Likelihood Assessment [BCM] [Damanat] [E3] [BCS] [T1] Mitigation Strategies and Justification BCM] [Damanat] [E1] [C10] Identifying Critical Business Functions
CBF-1 Mortgage Guarantee Origination
DP BIAQ P1 BIAQ P2 BIAQ P3 BIAQ P4 BIAQ P5 BIAQ P6
[BCM] [Damanat] [E3] [BIA] [DP] [CBF] [1] Mortgage Guarantee Origination [BCM] [Damanat] [E3] [BIA] [T1] [CBF] [1] Mortgage Guarantee Origination [BCM] [Damanat] [E3] [BIA] [T2] [CBF] [1] Mortgage Guarantee Origination [BCM] [Damanat] [E3] [BIA] [T3] [CBF] [1] Mortgage Guarantee Origination [BCM] [Damanat] [E3] [BIA] [T4] [CBF] [1] Mortgage Guarantee Origination [BCM] [Damanat] [E3] [BIA] [T5] [CBF] [1] Mortgage Guarantee Origination [BCM] [Damanat] [E3] [BIA] [T6] [CBF] [1] Mortgage Guarantee Origination
    BCS T2 BCS T3 PD    
    [BCM] [Damanat] [E3] [BCS] [T2] [CBF] [1] Mortgage Guarantee Origination [BCM] [Damanat] [E3] [BCS] [T3] [CBF] [1] Mortgage Guarantee Origination [BCM] [Damanat] [E3] [PD] [CBF] [1] Mortgage Guarantee Origination    
 

 

More Information About Business Continuity Management Courses

To learn more about the course and schedule, click the buttons below for the  BCM-300 Business Continuity Management Implementer [BCM-3] and the BCM-5000 Business Continuity Management Expert Implementer [BCM-5].

New call-to-action New call-to-action Register [BL-B-3]*
New call-to-action New call-to-action New call-to-action
FAQ [BL-B-3]

Please feel free to send us a note if you have any questions.

Email to Sales Team [BCM Institute]

 FAQ BL-B-5 BCM-5000
New call-to-action New call-to-action New call-to-action
 
 

Your Comments Here:

 

More Posts

New Call-to-action