This chapter provides a practical Business Continuity Recovery Procedure for CBF-1 Mortgage Guarantee Origination at The Saudi Mortgage Guarantees Services Company (Damanat).
It is intended for incorporation into an operational Business Continuity Plan and provides the actions, responsibilities, decision criteria and recovery controls required to continue or rapidly resume mortgage guarantee origination following a disruption.
The procedure follows the Business Continuity Management lifecycle:
Reduce → Respond → Recover → Resume → Restore
All timings, resource levels, escalation thresholds and recovery priorities in this chapter are indicative.
They must be validated against Damanat’s approved Business Impact Analysis, Recovery Time Objectives, Minimum Business Continuity Objectives, technology recovery capabilities, regulatory obligations and management-approved recovery strategies.
They explain what recovery teams must do before, during and after a disruption to maintain or restore critical products and services within acceptable timeframes.
Within Damanat’s Business Continuity Plan, this procedure establishes the sequence for recovering CBF-1 Mortgage Guarantee Origination, including its people, facilities, systems, information, suppliers and interdependent processes.
It supports operational decision-making by defining responsibilities, escalation routes, manual workarounds, minimum resources and success measures.
Business Continuity recovery procedures differ from Crisis Management procedures. Crisis Management focuses on strategic command, executive decision-making, organisational priorities, stakeholder confidence and enterprise-level consequences.
The recovery procedure focuses on restoring the operational capability required to perform the Critical Business Function. Both processes must operate together: the Crisis Management Team establishes strategic direction, while the CBF Recovery Team implements the approved recovery actions.
Recovery activities must follow the strategies and recovery objectives approved by Damanat. Recovering a function too slowly may result in unacceptable operational, financial, regulatory or reputational consequences.
Attempting recovery faster than the approved capability may also lead to avoidable costs, security weaknesses, processing errors, and resource conflicts.
Recovery actions should therefore be aligned with approved Recovery Time Objectives, Recovery Point Objectives and Minimum Business Continuity Objectives.
CBF-1 comprises 15 interdependent Sub-CBFs. Application intake cannot lead to approval unless validation, eligibility assessment, risk assessment and compliance review are completed.
Guarantee certificates cannot be generated reliably unless decisions, records and supporting data are accurate. Management reporting depends on the completeness of earlier processes.
Recovery must therefore be coordinated across the entire operating chain rather than treating each Sub-CBF as an isolated activity.
This procedure should be validated regularly through document reviews, walkthroughs, tabletop exercises, simulations, partial activations, ICT Disaster Recovery exercises and integrated enterprise exercises.
Testing confirms whether responsibilities are understood, resources are available, systems can be restored, and recovery actions are achievable under realistic conditions.
CBF-1 Mortgage Guarantee Origination enables Damanat to receive, validate, assess, approve, issue, register, and monitor mortgage guarantee applications submitted by participating financial institutions.
It supports the controlled origination of mortgage guarantees and provides the operational basis for managing guarantee exposure.
The function is critical because disruption may:
Damanat should validate the specific statutory and regulatory obligations applicable to mortgage guarantee origination under the requirements of the Saudi Central Bank (SAMA), the Insurance Authority, applicable legislation, regulatory instructions, contractual commitments and internal governance policies.
CBF-1 delivers or supports:
Key stakeholders may include:
CBF-1 may depend on:
|
Sub-CBF Code |
Sub-CBF |
Primary Purpose |
Main Output |
Recovery Priority |
|
1.1 |
1.1 Mortgage Guarantee Application Intake |
Receive and register submitted applications |
Application record and acknowledgement |
Immediate |
|
1.2 |
Application Validation |
Confirm completeness and accuracy of submissions |
Validated or returned application |
Immediate |
|
1.3 |
Borrower Eligibility Assessment |
Assess borrower eligibility against approved criteria |
Borrower eligibility decision |
High |
|
1.4 |
Property Eligibility Assessment |
Confirm property compliance with guarantee requirements |
Property eligibility decision |
High |
|
1.5 |
Mortgage Risk Assessment |
Evaluate mortgage and guarantee exposure |
Risk assessment and recommendation |
Immediate |
|
1.6 |
Guarantee Policy Compliance Review |
Confirm compliance with approved guarantee policies |
Compliance confirmation or exception |
Immediate |
|
1.7 |
Financial Institution Verification |
Validate participating institution status and authority |
Institution verification result |
High |
|
1.8 |
1.8 Guarantee Approval Decision |
Approve, reject, defer, or escalate the application |
Formal approval decision |
Immediate |
|
1.9 |
Guarantee Certificate Generation |
Produce the approved guarantee certificate |
Guarantee certificate |
High |
|
1.10 |
Guarantee Registration |
Enter the approved guarantee in the official register |
Registered guarantee record |
High |
|
1.11 |
Stakeholder Notification |
Communicate decisions and required actions |
Confirmed stakeholder notification |
High |
|
1.12 |
Documentation and Record Management |
Maintain complete and auditable case records |
Controlled case file |
High |
|
1.13 |
Guarantee Fee Administration |
Calculate, record and reconcile applicable fees |
Fee record and reconciliation |
Medium |
|
1.14 |
Post-Issuance Quality Assurance |
Verify accuracy and compliance after issuance |
Quality assurance result |
Medium |
|
1.15 |
Management Reporting and Regulatory Monitoring |
Monitor volumes, performance, exposures and compliance |
Management and regulatory reports |
High |
Objective
Establish clear accountability, decision authority and management oversight for recovering CBF-1.
Activities
Deliverables
Ownership
Expected Outcome
Recovery decisions can be made quickly without uncertainty, unauthorised activity or avoidable escalation delays.
Objective
Ensure that trained personnel are available to activate and operate the recovery procedure.
Activities
Deliverables
Ownership
Expected Outcome
The minimum competent workforce can be mobilised within the approved activation timeframe.
Objective
Ensure that an alternate workplace can support the minimum required recovery capacity.
Activities
Deliverables
Ownership
Expected Outcome
Priority recovery personnel can operate from a secure and functional location when the normal workplace is unavailable.
Objective
Ensure that systems supporting CBF-1 can be recovered in the correct sequence and within approved recovery objectives.
Activities
Deliverables
Ownership
Expected Outcome
Critical systems can be restored securely and in a sequence that supports business recovery priorities.
Objective
Ensure that essential records, procedures and decision information remain accessible throughout a disruption.
Activities
Deliverables
Ownership
Expected Outcome
Recovery teams can access reliable, current and controlled information even when normal systems are unavailable.
Objective
Provide timely, accurate and authorised communications to personnel, regulators, suppliers and stakeholders.
Activities
Deliverables
Ownership
Expected Outcome
Stakeholders receive accurate and coordinated information without disclosure breaches, contradictory messages or unnecessary delay.
Objective
Ensure external dependencies can support Damanat’s recovery requirements.
Activities
Deliverables
Ownership
Expected Outcome
Critical suppliers and external agencies can support recovery or be replaced through pre-approved alternatives.
Objective
Ensure that minimum recovery resources are available when the plan is activated.
Activities
Deliverables
Ownership
Expected Outcome
The Recovery Team can begin operations without waiting for essential equipment, access or supplies.
Objective
Validate that the recovery procedure is practical and achievable.
Activities
Deliverables
Ownership
Expected Outcome
Recovery weaknesses are identified and corrected before an actual disruption.
Objective
Maintain the accuracy, relevance and effectiveness of the recovery procedure.
Activities
Deliverables
Ownership
Expected Outcome
The procedure remains current, approved, usable and aligned with Damanat’s operating environment.
Purpose: Identify an event that may disrupt CBF-1.
Responsible Role: Operations Supervisor or Incident Reporter.
Detailed Actions:
Expected Completion: Within 15 minutes of detection.
Dependencies: Monitoring tools, staff awareness, reporting channels.
Decision Criteria: Actual or potential interruption exceeding normal operating tolerance.
Success Indicators: Incident logged, affected processes identified, and responsible teams notified.
Purpose: Determine the operational and regulatory significance of the incident.
Responsible Role: CBF Recovery Team Leader with Incident Manager.
Detailed Actions:
Expected Completion: Within 30 minutes.
Dependencies: Technical assessment, business-impact information, supplier updates.
Decision Criteria: Scale, duration, safety implications, data impact, stakeholder impact and likelihood of missing recovery objectives.
Success Indicators: Severity agreed, assumptions documented and escalation decision made.
Purpose: Ensure that the incident reaches the appropriate management level.
Responsible Role: Incident Manager.
Detailed Actions:
Expected Completion: Within 45 minutes.
Dependencies: Escalation matrix and current contact lists.
Decision Criteria: Expected disruption exceeds operational tolerance, affects multiple Sub-CBFs or creates regulatory, data, safety or reputational consequences.
Success Indicators: Correct management level engaged and decision authority established.
Purpose: Formally initiate recovery arrangements.
Responsible Role: Authorised CBF Owner, BCM Manager or Incident Commander.
Detailed Actions:
Expected Completion: Within one hour.
Dependencies: Activation authority, recovery strategy and team availability.
Decision Criteria: Normal operations cannot be restored within the approved operational tolerance.
Success Indicators: Plan formally activated, team mobilised and recovery strategy initiated.
Purpose: Mobilise the personnel required to recover CBF-1.
Responsible Role: Recovery Team Coordinator.
Detailed Actions:
Expected Completion: Within 90 minutes.
Dependencies: Contact directory, telecommunications, alternates.
Decision Criteria: The required minimum staffing cannot be achieved with primary personnel.
Success Indicators: Minimum recovery team confirmed and reporting instructions acknowledged.
Purpose: Inform affected stakeholders without creating confusion or unsupported commitments.
Responsible Role: Corporate Communications with CBF Owner and Compliance.
Detailed Actions:
Expected Completion: Initial notification within two hours where material impact exists.
Dependencies: Confirmed facts, approval authority and contact details.
Decision Criteria: Service disruption affects external stakeholders, regulatory obligations or agreed service levels.
Success Indicators: Priority stakeholders receive consistent and authorised information.
Purpose: Preserve life, safety and staff welfare.
Responsible Role: Security, Facilities and Recovery Team Leader.
Detailed Actions:
Expected Completion: Immediate and continuous.
Dependencies: Emergency response arrangements.
Decision Criteria: Any threat to health, safety or wellbeing.
Success Indicators: Personnel accounted for, and no recovery activity compromises safety.
Purpose: Prevent further damage, unauthorised access or evidence loss.
Responsible Role: Facilities and Security.
Detailed Actions:
Expected Completion: Initial controls within one hour.
Dependencies: Security personnel, emergency services and building management.
Decision Criteria: Facility is unsafe, inaccessible or vulnerable.
Success Indicators: Site controlled and further loss prevented.
Purpose: Preserve confidentiality, integrity, availability and evidential value.
Responsible Role: Information Security and Records Management.
Detailed Actions:
Expected Completion: Immediate and continuous.
Dependencies: Security tools, access controls, and backup systems.
Decision Criteria: Suspected compromise, corruption, loss or unauthorised access.
Success Indicators: Information exposure contained and recoverable data preserved.
Purpose: Establish an operational workplace when the normal site is unavailable.
Responsible Role: Facilities Recovery Coordinator.
Detailed Actions:
Expected Completion: Within four hours, subject to approved strategy.
Dependencies: Site availability, transport, ICT and security.
Decision Criteria: Primary site unavailable beyond the agreed tolerance.
Success Indicators: Minimum recovery team can work securely from the alternate location.
Purpose: Initiate technology restoration in the approved sequence.
Responsible Role: ICT Disaster Recovery Manager.
Detailed Actions:
Expected Completion: Initiated within one hour of activation.
Dependencies: DR environment, backups, vendors, and technical personnel.
Decision Criteria: Production systems cannot be restored within business tolerance.
Success Indicators: Core infrastructure restored and priority application recovery underway.
Purpose: Recover the applications required for priority Sub-CBFs.
Responsible Role: Application Owners and ICT Disaster Recovery Team.
Detailed Actions:
Expected Completion: In accordance with approved ICT and business RTOs.
Dependencies: Infrastructure, data restoration, cybersecurity validation and vendor support.
Decision Criteria: System is technically stable, secure and capable of supporting minimum business operations.
Success Indicators: Authorised users can process priority cases without critical errors.
Purpose: Restore the information required for controlled processing.
Responsible Role: Records Manager and Application Owners.
Detailed Actions:
Expected Completion: Within approved information-recovery objectives.
Dependencies: Backup integrity, repository access and record ownership.
Decision Criteria: Records are complete enough to support safe processing.
Success Indicators: Priority case files and decision records are available and validated.
Purpose: Resume activities in the sequence that produces the highest-value operational outcome.
Responsible Role: CBF Recovery Team Leader.
Expected Completion: Priority Sub-CBFs operational within approved RTOs.
Dependencies: Systems, records, staff, approvals and external providers.
Decision Criteria: Activities may resume only when minimum controls and required data are available.
Success Indicators: Priority applications progress through a controlled end-to-end process.
Purpose: Deliver the Minimum Business Continuity Objective.
Responsible Role: Sub-CBF Owners.
Detailed Actions:
Expected Completion: Within approved RTO.
Dependencies: Minimum staff, systems, and information.
Decision Criteria: Safe minimum operating conditions achieved.
Success Indicators: Priority cases processed within the agreed recovery service level.
Purpose: Continue essential work when normal systems remain unavailable.
Responsible Role: CBF Recovery Team Leader.
Detailed Actions:
Expected Completion: As soon as required and within approved manual-workaround tolerance.
Dependencies: Forms, procedures, trained personnel and secure storage.
Decision Criteria: Workaround remains controlled, auditable and within delegated authority.
Success Indicators: Priority operations continue without loss of traceability.
Purpose: Control accumulated work and avoid uncontrolled service deterioration.
Responsible Role: Operations Manager.
Detailed Actions:
Expected Completion: Initial backlog assessment within six hours of activation.
Dependencies: Reliable volume information and staffing.
Decision Criteria: Backlog threatens MTPD, service commitments or control quality.
Success Indicators: Backlog growth stabilised and reduction plan approved.
Purpose: Maintain regulatory alignment and government coordination.
Responsible Role: Compliance and Executive Management.
Detailed Actions:
Expected Completion: Within applicable regulatory timelines.
Dependencies: Verified incident information and authorised spokespersons.
Decision Criteria: Disruption affects regulatory reporting, customer outcomes, controlled records or critical services.
Success Indicators: Required notifications completed and regulatory directions incorporated.
Purpose: Restore critical external services.
Responsible Role: Procurement and Service Owners.
Detailed Actions:
Expected Completion: Initial supplier engagement within two hours.
Dependencies: Contracts, service contacts and alternatives.
Decision Criteria: Supplier service failure prevents the achievement of recovery objectives.
Success Indicators: Supplier recovery plan agreed or alternate service activated.
Purpose: Maintain operational control and support informed decisions.
Responsible Role: Recovery Team Leader.
Detailed Actions:
Expected Completion: Continuous, with reports at approved intervals.
Dependencies: Accurate status information.
Decision Criteria: Variances require corrective action or escalation.
Success Indicators: Management receives reliable and timely recovery status.
Purpose: Resolve obstacles that exceed Recovery Team authority.
Responsible Role: CBF Owner.
Detailed Actions:
Expected Completion: Immediately when a critical milestone is threatened.
Dependencies: Escalation route and decision authority.
Decision Criteria: RTO, MBCO, regulatory obligation or critical control is at risk.
Success Indicators: Issue resolved, accepted or transferred to authorised management.
Purpose: Provide executive oversight.
Responsible Role: CBF Owner or Recovery Team Leader.
Detailed Actions:
Expected Completion: Initial report within two hours of activation and periodically thereafter.
Dependencies: Consolidated recovery information.
Decision Criteria: Frequency increases with impact or uncertainty.
Success Indicators: Management decisions are supported by current information.
Purpose: Transition from immediate response to prolonged controlled operations.
Responsible Role: CBF Recovery Team Leader and Human Resources.
Detailed Actions:
Expected Completion: Before the end of the first 24 hours.
Dependencies: Resources, staffing, and incident outlook.
Decision Criteria: Full restoration is not expected within 24 hours.
Success Indicators: Recovery operations can continue safely beyond the initial period.
Purpose: Increase capacity beyond the initial minimum service level.
Detailed Implementation:
Responsible Owner: CBF Owner.
Deliverables: Expanded recovery plan and revised capacity targets.
Success Measures: Increased throughput without unacceptable error or control failure.
Purpose: Resume activities postponed during the initial recovery period.
Detailed Implementation:
Responsible Owner: Sub-CBF Owners.
Deliverables: Deferred-activity register and clearance plan.
Success Measures: Deferred work resumed within approved limits.
Purpose: Support higher processing volumes and prolonged recovery.
Detailed Implementation:
Responsible Owner: Human Resources and Operations.
Deliverables: Revised staffing roster.
Success Measures: Adequate coverage with no critical role gaps.
Purpose: Recover remaining systems and return technology capacity toward normal levels.
Detailed Implementation:
Responsible Owner: ICT Disaster Recovery Manager.
Deliverables: Technology restoration report.
Success Measures: All required services available, secure and stable.
Purpose: Confirm that recovered information is accurate and complete.
Detailed Implementation:
Responsible Owner: Data Owners and ICT.
Deliverables: Data-validation report.
Success Measures: Recovered data accepted by business owners.
Purpose: Confirm that each case contains complete and auditable documentation.
Detailed Implementation:
Responsible Owner: Records Management.
Deliverables: Record-validation checklist.
Success Measures: Case records meet legal, regulatory and internal requirements.
Purpose: Transfer temporary manual activity into normal systems without duplication or omission.
Detailed Implementation:
Responsible Owner: Operations and Finance.
Deliverables: Signed reconciliation report.
Success Measures: All manual transactions accounted for exactly once.
Purpose: Progress applications interrupted by the incident.
Detailed Implementation:
Responsible Owner: Mortgage Guarantee Operations Manager.
Deliverables: Outstanding-application register.
Success Measures: Interrupted cases recovered without inappropriate duplication or loss.
Purpose: Return transaction volumes and service levels to normal.
Detailed Implementation:
Responsible Owner: CBF Owner.
Deliverables: Backlog-clearance report.
Success Measures: Backlog reduced to normal operating levels.
Purpose: Reinstate normal third-party support.
Detailed Implementation:
Responsible Owner: Procurement and Service Owners.
Deliverables: Supplier-restoration confirmation.
Success Measures: Required supplier services operating within agreed levels.
Purpose: Restore normal interactions with regulators and government stakeholders.
Detailed Implementation:
Responsible Owner: Compliance and Regulatory Affairs.
Deliverables: Regulatory and inter-agency closure record.
Success Measures: No unaddressed reporting or coordination obligations remain.
Purpose: Confirm that recovery processing meets required standards.
Detailed Implementation:
Responsible Owner: Quality Assurance Manager.
Deliverables: Recovery quality-assurance report.
Success Measures: Error rates remain within approved tolerance and material defects are corrected.
Purpose: Confirm progress toward normal performance.
Detailed Implementation:
Responsible Owner: Management Reporting Team.
Deliverables: Service-restoration dashboard.
Success Measures: Service levels improve consistently toward business-as-usual targets.
Purpose: Transfer operations safely back to the normal workplace.
Detailed Implementation:
Responsible Owner: Facilities Manager and CBF Owner.
Deliverables: Primary-site return plan.
Success Measures: Operations transferred without interruption or loss.
Purpose: Close temporary recovery arrangements in a controlled manner.
Detailed Implementation:
Responsible Owner: Facilities and Security.
Deliverables: Alternate-site stand-down checklist.
Success Measures: Site secured, reconciled and ready for future activation.
Purpose: Return decision-making and approvals to normal organisational structures.
Detailed Implementation:
Responsible Owner: Executive Management.
Deliverables: Governance restoration notice.
Success Measures: Temporary authorities withdrawn and normal accountability restored.
Purpose: Evaluate the effectiveness of the response and recovery.
Detailed Implementation:
Responsible Owner: BCM Manager.
Deliverables: Post-Incident Review report.
Success Measures: Findings are evidence-based, agreed and assigned.
Purpose: Convert experience into measurable improvements.
Detailed Implementation:
Responsible Owner: BCM Manager.
Deliverables: Lessons-learned register.
Success Measures: Actions completed and effectiveness verified.
Purpose: Correct weaknesses identified during the incident.
Detailed Implementation:
Responsible Owner: CBF Owner and BCM Manager.
Deliverables: Updated Business Continuity documentation.
Success Measures: Revised documents approved and available to users.
Purpose: Reflect newly identified threats, vulnerabilities, and control weaknesses.
Detailed Implementation:
Responsible Owner: Enterprise Risk Management.
Deliverables: Updated Risk Assessment and treatment plan.
Success Measures: Material lessons incorporated into risk governance.
Purpose: Strengthen future recovery capability.
Detailed Implementation:
Responsible Owner: CBF Owner and BCM Steering Committee.
Deliverables: Recovery-strategy improvement plan.
Success Measures: Approved actions reduce identified recovery gaps.
Purpose: Verify that corrective actions improve readiness.
Detailed Implementation:
Responsible Owner: BCM Manager.
Deliverables: Exercise schedule and test plan.
Success Measures: Corrective actions validated under realistic conditions.
|
Sub-CBF Code |
Sub-CBF |
Immediate Actions |
Recovery Actions |
Restore Actions |
Primary Owner |
Key Dependencies |
|
1.1 |
Mortgage Guarantee Application Intake |
Open alternate intake channel; register all submissions |
Restore intake platform; prioritise urgent cases |
Reconcile manual and electronic submissions |
Application Intake Manager |
Financial institutions, portal, email, records |
|
1.2 |
Application Validation |
Screen for mandatory data and documents |
Resume validation workflow |
Clear validation backlog and correct errors |
Validation Team Leader |
Application records, procedures, staff |
|
1.3 |
Borrower Eligibility Assessment |
Identify urgent pending assessments |
Restore eligibility tools and verified data sources |
Complete deferred assessments and QA review |
Eligibility Assessment Manager |
Borrower data, credit information, policy |
|
1.4 |
Property Eligibility Assessment |
Hold cases lacking reliable property evidence |
Restore valuation and property-data access |
Complete deferred property reviews |
Property Assessment Manager |
Valuers, property records, criteria |
|
1.5 |
Mortgage Risk Assessment |
Prioritise high-value and time-sensitive cases |
Restore models and risk systems |
Reassess manual or exceptional decisions |
Head of Mortgage Risk |
Risk platform, data, analysts |
|
1.6 |
Guarantee Policy Compliance Review |
Confirm current policy and exception authority |
Resume compliance workflow |
Review emergency exceptions |
Compliance Review Manager |
Policy repository, Legal, Compliance |
|
1.7 |
Financial Institution Verification |
Verify institution status through alternate means |
Restore normal verification interface |
Reconcile temporary verification records |
Relationship Management Head |
Institution register, authorised contacts |
|
1.8 |
Guarantee Approval Decision |
Convene authorised decision-makers |
Restore approval workflow and delegated authority |
Review emergency decisions and exceptions |
Approval Committee Chair |
Assessments, compliance, authority matrix |
|
1.9 |
Guarantee Certificate Generation |
Prepare controlled temporary certificates if approved |
Restore certificate-generation platform |
Replace or reconcile temporary certificates |
Guarantee Administration Manager |
Approval records, digital certificates, templates |
|
1.10 |
Guarantee Registration |
Use a controlled temporary register |
Restore registration system |
Reconcile and validate all registrations |
Registration Manager |
Guarantee records, database, identifiers |
|
1.11 |
Stakeholder Notification |
Issue initial status and decision notifications |
Restore automated notifications |
Confirm delivery and resolve failures |
Communications and Relationship Manager |
CRM, email, SMS, approved messages |
|
1.12 |
Documentation and Record Management |
Secure records and initiate manual case files |
Restore document repository |
Link, index and validate all records |
Records Manager |
EDMS, storage, retention controls |
|
1.13 |
Guarantee Fee Administration |
Record fees in a temporary ledger |
Restore finance and fee systems |
Reconcile charges, receipts and exceptions |
Finance Manager |
ERP, banking, guarantee records |
|
1.14 |
Post-Issuance Quality Assurance |
Prioritise manually processed and high-risk cases |
Resume QA sampling and control checks |
Complete retrospective review |
Quality Assurance Manager |
Case files, approval records, certificates |
|
1.15 |
Management Reporting and Regulatory Monitoring |
Produce manual situation and exposure reports |
Restore reporting tools and data feeds |
Submit delayed reports and reconcile metrics |
Management Reporting and Compliance Head |
BI tools, case data, regulatory requirements |
|
Recovery Issue |
Likely Cause |
Operational Impact |
Immediate Response |
Long-Term Corrective Action |
|
Staffing shortages |
Illness, transport disruption, concentration of specialist knowledge |
Priority processes cannot meet minimum capacity |
Activate alternates, cross-trained staff and revised shifts |
Increase cross-training, succession and geographic workforce diversity |
|
ICT failures |
Infrastructure outage, failed recovery, cyber incident |
Applications and records unavailable |
Activate DR, prioritise critical systems and use controlled workarounds |
Improve architecture, redundancy, testing and monitoring |
|
Supplier failures |
Supplier outage, insolvency, telecommunications failure |
External data or services unavailable |
Escalate supplier, activate alternatives and adjust priorities |
Strengthen contracts, diversify providers and test supplier continuity |
|
Communications failures |
Network outage, outdated contacts, overloaded channels |
Teams and stakeholders receive delayed or conflicting information |
Use alternate channels and centralise message approval |
Improve channel redundancy, contact maintenance and communication exercises |
|
Inaccessible facilities |
Fire, flood, security event or utility failure |
Staff cannot access normal workplace |
Activate alternate site or remote work |
Improve site resilience and alternate-location capacity |
|
Unavailable records |
Data corruption, backup failure, inaccessible repository |
Assessments and approvals cannot be completed reliably |
Retrieve alternate copies and start controlled manual records |
Improve backup, replication, classification and restoration testing |
|
Decision bottlenecks |
Unavailable approvers or unclear authority |
Applications accumulate, and recovery slows |
Activate delegated authority and executive escalation |
Strengthen succession and pre-approved emergency authority |
|
Regulatory delays |
Portal outage, incomplete data or unclear reporting obligation |
Reporting deadlines missed or supervisory concern increases |
Contact regulator and agree alternate submission route |
Establish regulatory contingency procedures and test reporting alternatives |
|
Stakeholder concerns |
Delayed service, inconsistent updates or uncertainty |
Complaints and reputational damage |
Issue factual updates and prioritise critical cases |
Improve communication planning, service transparency and relationship management |
|
Prolonged recovery |
Extensive damage, failed DR, supplier dependency or large backlog |
Staff fatigue, rising costs and missed objectives |
Expand staffing, shifts, facilities and executive oversight |
Invest in resilience, improve recovery strategy and conduct severe-scenario exercises |
Conduct a structured review to confirm that names, contacts, systems, dependencies, forms, recovery objectives and responsibilities remain current.
This should occur at least annually and after material change.
Recovery-team members should review the procedure step by step and explain how they would perform each action.
The walkthrough should identify ambiguity, missing information, and unrealistic assumptions.
Use a facilitated scenario such as loss of the mortgage guarantee platform, denial of access to the primary office, cyber compromise, or failure of a critical external service.
Participants should make decisions, apply escalation procedures and assess Sub-CBF recovery priorities.
Simulate realistic operational conditions, including incomplete information, absent personnel, supplier delays, high application volumes and regulatory deadlines.
No live production activity needs to be affected, but participants should generate realistic records and situation reports.
Activate selected components, such as:
Mobilise the complete CBF Recovery Team and operate the recovery procedure for a defined period.
Test the full end-to-end process from application intake through approval, certificate generation, registration, notification and reporting.
Coordinate CBF-1 recovery with:
This confirms that strategic command and operational recovery operate together.
Test:
Business users should verify that recovered systems can support priority processes in practice, rather than relying solely on technical test results.
After every exercise:
Recovery procedures are essential because they transform Damanat’s approved Business Continuity Strategies into practical, role-based actions.
They provide recovery teams with the sequence, responsibilities, decision criteria, and controls required to continue or resume mortgage guarantee origination following a disruptive event.
The continuity of CBF-1 depends on coordinated recovery across all 15 Sub-CBFs.
Application intake, validation, eligibility assessment, risk assessment, compliance review, approval, certificate generation, registration, notification, records management, fee administration, quality assurance, and reporting form an interconnected operational chain.
Recovering one component without its dependencies will not restore the complete service.
The procedure must remain practical. It should reflect available personnel, real system capabilities, approved facilities, reliable information, tested suppliers and achievable recovery objectives.
It should not depend on unrealistic staffing levels, untested technology or undocumented assumptions.
Continual improvement is necessary because personnel, systems, policies, suppliers, regulatory obligations and operating volumes change.
Lessons from incidents, exercises, audits and management reviews should be incorporated into the procedure through controlled updates.
Regular exercises provide the evidence that Damanat’s recovery arrangements are operationally ready.
They test whether personnel understand their responsibilities, systems recover within approved objectives, manual workarounds remain controlled, and dependencies can support the required service levels.
The Saudi Mortgage Guarantees Services Company can maintain critical mortgage guarantee services only through well-documented, regularly tested, and continually improved recovery procedures for every Sub-CBF supporting CBF-1 Mortgage Guarantee Origination.
| eBook 3: Starting Your BCM Implementation |
||||||
| MBCO | P&S | RAR T1 | RAR T2 | RAR T3 | BCS T1 | CBF |
| CBF-1 Mortgage Guarantee Origination | ||||||
| DP | BIAQ P1 | BIAQ P2 | BIAQ P3 | BIAQ P4 | BIAQ P5 | BIAQ P6 |
| BCS T2 | BCS T3 | PD | ||||
To learn more about the course and schedule, click the buttons below for the BCM-300 Business Continuity Management Implementer [BCM-3] and the BCM-5000 Business Continuity Management Expert Implementer [BCM-5].
|
Please feel free to send us a note if you have any questions. |
||