Ebook

[BCM] [Damanat] [E3] [RAR] [T2] Treatment and Control

Written by Dr Goh Moh Heng | Jul 20, 2026, 1:39:23 PM

Part 2: Risk Analysis and Review – Treatment and Control

Introduction

 

Following the completion of the Threat Register in Part 1: Risk Analysis and Review – List of Threats, the next step in the Risk Analysis and Review (RAR) process is to evaluate how each identified threat is currently managed and determine whether the existing control environment is adequate.

The objective is not merely to identify risks but to understand whether Damanat has implemented appropriate measures to prevent, reduce, transfer or formally accept those risks in accordance with its business continuity objectives.

This approach is consistent with the BCM Institute RAR methodology, where threat identification is followed by a structured assessment of treatment strategies and supporting controls.

A threat is a potential event that could disrupt Damanat's operations. A risk treatment is the overall strategy adopted to manage that threat, while a control is the specific administrative, technical or physical measure used to implement the chosen treatment.

A single threat frequently requires more than one treatment strategy. For example, ransomware may be reduced through preventive cybersecurity controls, transferred through cyber insurance and managed through formally approved residual risk acceptance.

Because the actual internal control environment of The Saudi Mortgage Guarantees Services Company (Damanat) has not been publicly documented, the existing controls described below are reasonable assumptions requiring validation during the BCM implementation project.

Recommended planned controls represent improvements that should be evaluated, prioritised and approved by management before implementation.

Table T2-P1: Treatment and Control

This section establishes treatment strategies for the first set of threats based on the Damanat threat register and follows the BCM Institute's structured RAR treatment methodology.

Threat

Existing Risk Treatment – Risk Avoidance

Existing Risk Treatment – Risk Reduction

Existing Risk Treatment – Risk Transference

Existing Risk Treatment – Risk Acceptance

Existing Controls

Additional (Planned) Controls

Earthquake

Not applicable—operations cannot avoid regional seismic events.

Emergency response procedures, alternate workplace arrangements and resilient ICT infrastructure.

Property and business interruption insurance.

Residual exposure accepted within Board-approved risk appetite after continuity arrangements.

Emergency evacuation procedures, backup power, off-site data backup, alternate workplace capability.

Seismic assessment of facilities, annual evacuation exercises, enhanced off-site replication, Facilities Manager, High Priority (12 months).

Flash Flood

Locate critical ICT infrastructure above flood-prone areas where practicable.

Flood monitoring, remote-working capability, and alternate workplace activation.

Insurance for property damage.

Residual exposure monitored during rainy seasons.

Environmental monitoring, emergency communication procedures.

Flood response plan, supplier recovery coordination, annual flood exercise, Facilities Manager, Medium Priority.

Severe Sandstorm

Not applicable.

Flexible working arrangements, remote access and environmental monitoring.

Not generally applicable.

Operational delays are accepted where employee safety is prioritised.

Remote access capability, weather alerts, work-from-home procedures.

Enhanced virtual collaboration capability and alternate telecommunications providers.

Extreme Heat

Avoid locating critical equipment in poorly controlled environments.

Redundant HVAC systems and preventive maintenance.

Equipment maintenance contracts.

Acceptable after environmental controls are verified.

Server room cooling, building management systems.

Thermal monitoring sensors and dual cooling redundancy.

Pandemic

Avoid unnecessary international travel during declared outbreaks.

Remote working, cross-training, workforce segregation and hygiene measures.

Employee medical insurance and outsourced occupational health services.

Residual absenteeism accepted under approved pandemic response plans.

Remote access, health monitoring, pandemic procedures, HR continuity arrangements.

Expand remote workforce capacity, digital workflow automation, annual pandemic simulation, HR Director, High Priority.

Fire

Prohibit hazardous storage and unsafe activities within office premises.

Fire detection, suppression and evacuation procedures.

Property insurance.

Residual damage accepted after protection measures.

Fire alarms, extinguishers, evacuation plans, emergency wardens.

Annual fire evacuation exercises, fire compartment review, digital document conversion.

Explosion

Avoid storing hazardous materials on-site.

Emergency evacuation and business relocation capability.

Property insurance.

Residual risk is accepted because complete avoidance is impractical.

Crisis response procedures, alternate workplace.

Coordination with civil defence authorities and crisis simulation exercises.

Hazardous Material Release

Select facilities away from identified industrial hazards where feasible.

Building isolation procedures and emergency communications.

Insurance where applicable.

Temporary operational disruption accepted.

Evacuation procedures, emergency notification system.

Air-quality monitoring and mutual aid arrangements with neighbouring organisations.

Civil Disturbance

Avoid unnecessary travel to affected locations.

Flexible working and remote operations.

Not generally applicable.

Temporary service delays accepted.

Employee notification procedures, business travel guidance.

Crisis communications enhancement and alternative transport arrangements.

Terrorist Incident

Not applicable.

Physical security, access controls and emergency response.

Terrorism insurance is available.

Residual national security exposure accepted.

Visitor management, CCTV, security guards, emergency response plan.

Joint exercises with security agencies, enhanced perimeter protection, Security Manager, High Priority.

Building Access Restriction

Diversify workplace locations where possible.

Alternate workplace activation and remote working.

Facility lease provisions where applicable.

Temporary disruption accepted pending relocation.

Remote access capability, alternate office procedures.

Permanent alternate office arrangements and annual relocation exercises.

Loss of Key Personnel

Avoid dependence on single specialists.

Succession planning, cross-training and knowledge management.

Recruitment agencies and external specialist contracts.

Short-term resource constraints accepted pending replacement.

Delegation of authority, documented procedures, competency matrices.

Formal succession programme, knowledge repository, annual competency review, HR Director, Immediate Priority.

Industrial Action

Maintain positive employee engagement and compliance with labour obligations.

Cross-training and workforce contingency planning.

Outsourced temporary staffing where appropriate.

Limited operational disruption accepted.

HR policies, workforce communication plans.

Framework agreements with temporary staffing providers.

High Staff Absenteeism

Not applicable.

Remote working, workforce redistribution and overtime arrangements.

External contract resources.

Residual reduction in productivity accepted.

Flexible work policies and workforce scheduling.

Workforce resilience dashboard and cross-functional staffing pools.

Skills Shortage

Avoid sole dependency on scarce expertise.

Continuous professional development and mentoring.

External consultants were necessary.

Accepted only where recruitment is underway.

Training programmes, competency management.

Graduate development programme and structured capability framework.

Human Error

Simplify high-risk manual processes through automation.

Quality assurance, segregation of duties and maker-checker controls.

Professional indemnity insurance where applicable.

Minor residual errors accepted within quality thresholds.

SOPs, approval workflows, audit trails.

Workflow automation, AI-assisted validation and enhanced quality reviews.

Table T2-P2: Treatment and Control

This section assessed the treatment strategies and assumed control environment for supply chain disruptions, ICT failures and cybersecurity threats that are critical to Damanat's mortgage guarantee operations.

 

Threat

Existing Risk Treatment – Risk Avoidance

Existing Risk Treatment – Risk Reduction

Existing Risk Treatment – Risk Transference

Existing Risk Treatment – Risk Acceptance

Existing Controls

Additional (Planned) Controls

Critical Supplier Failure

Avoid reliance on a single critical supplier through procurement policy.

Supplier due diligence, continuity assessments and alternate supplier identification.

Contractual SLAs, indemnities and supplier performance guarantees.

Residual supplier risk accepted following annual review.

Vendor management programme, supplier contracts, periodic performance reviews.

Establish dual sourcing for critical services, annual supplier BCM audit, Procurement Director, High Priority (12 months).

Cloud Service Provider Outage

Avoid hosting critical services on a single cloud platform where practical.

Multi-zone deployment, resilient architecture and backup replication.

Cloud service agreements with defined availability commitments.

Residual outage risk is accepted after resilience measures are validated.

Cloud backup, disaster recovery arrangements, SLA monitoring.

Evaluate multi-cloud strategy, annual cloud recovery testing, CIO, High Priority.

Telecommunications Failure

Avoid dependence on a single telecommunications carrier.

Dual communication links, mobile failover and alternate communications.

Carrier service-level agreements.

Temporary communication degradation accepted.

Multiple internet circuits, mobile communications, emergency contact procedures.

Implement SD-WAN with automatic failover and satellite communications for crisis use.

Internet Service Provider Failure

Diversify ISP providers.

Automatic failover to secondary provider.

Commercial service guarantees.

Short-term degradation accepted.

Redundant internet connectivity.

Quarterly resilience testing of ISP failover capability.

Credit Bureau Service Failure

Avoid sole dependence on a single credit information source where feasible.

Manual verification procedures and alternate credit information sources.

Third-party contractual obligations.

Temporary delays accepted pending restoration.

Escalation procedures, manual underwriting guidance.

Develop secondary credit data integration and contingency workflow.

Banking Partner System Failure

Avoid sole operational dependency on a single banking interface.

Queue management, transaction resubmission and manual processing.

Banking partnership agreements.

Temporary processing delays accepted.

Interface monitoring, incident escalation.

Implement alternate banking connectivity and regular integration testing.

Outsourced ICT Support Failure

Avoid relying on a single ICT support provider for critical services.

Cross-training internal ICT staff and documenting recovery procedures.

Managed service contracts.

Temporary reduction in support capacity accepted.

ICT support contracts, escalation matrix.

Develop internal recovery capability and maintain secondary ICT support provider.

Commercial Power Failure

Avoid locating critical ICT infrastructure where reliable backup power is unavailable.

UPS systems and standby generators.

Generator maintenance contracts.

Short interruptions accepted during generator transition.

UPS, emergency generator, preventive maintenance.

Extend generator runtime and perform quarterly load-bank testing, Facilities Manager, Immediate Priority.

HVAC Failure

Avoid housing critical systems without environmental controls.

Preventive maintenance and redundant cooling.

Maintenance agreements.

Limited downtime is accepted during repair.

Environmental monitoring, HVAC maintenance schedule.

Install N+1 cooling redundancy and automated thermal alerts.

Network Failure

Avoid a single network architecture.

Redundant switches, routing and monitoring.

Network maintenance agreements.

Residual network disruption accepted.

Network monitoring, redundancy, documented recovery procedures.

Network segmentation review and annual resilience testing.

Data Centre Outage

Avoid operating from a single production site.

Secondary recovery site and replicated infrastructure.

Colocation or managed recovery contracts.

Residual disruption is accepted after recovery capability is verified.

Disaster Recovery Plan, replicated infrastructure.

Conduct annual disaster recovery simulation and validate Recovery Time Objectives.

Core Mortgage Guarantee System Failure

Eliminate unsupported legacy applications.

High-availability architecture and preventive maintenance.

Vendor support agreements.

Short-term service interruption accepted.

Application monitoring, change management and backups.

Implement active-active architecture and automated application health monitoring.

Database Failure

Avoid unsupported database platforms.

Database clustering, backup and replication.

Vendor maintenance contracts.

Residual exposure is accepted after restoration capability is tested.

Database backup procedures, replication and integrity checks.

Quarterly database recovery exercises and integrity validation.

Identity and Access Management Failure

Avoid a single authentication platform where feasible.

Redundant identity infrastructure and privileged access management.

Vendor support agreements.

Temporary authentication delays accepted.

Active Directory redundancy, MFA, privileged account management.

Implement cloud identity failover and annual identity recovery testing.

Backup Failure

Avoid dependence on a single backup technology.

Multiple backup copies and routine restoration testing.

Off-site backup provider.

Minimal residual exposure accepted.

Scheduled backups, off-site storage and backup monitoring.

Immutable backup storage and monthly restoration validation.

Storage System Failure

Avoid single storage platform dependency.

RAID, storage replication and proactive monitoring.

Vendor warranty and maintenance.

Residual storage risk accepted.

Enterprise SAN monitoring and maintenance.

Deploy geographically separate replicated storage.

Ransomware Attack

Eliminate unsupported operating systems and high-risk applications.

Endpoint protection, network segmentation, MFA, security awareness and immutable backups.

Cyber insurance and incident response retainers.

Residual cyber risk is accepted within the approved cyber risk appetite.

Endpoint detection and response (EDR), SIEM, email filtering, privileged access controls.

Zero Trust architecture, continuous threat hunting, annual ransomware simulation, CISO, Immediate Priority.

Malware Infection

Remove unsupported software.

Antivirus, application control and user awareness.

Cyber insurance.

Low residual exposure accepted.

Endpoint protection and patch management.

Advanced behavioural malware detection and automated isolation.

Phishing Attack

Restrict high-risk email behaviours where possible.

Security awareness, email filtering and MFA.

Cyber insurance.

Residual phishing exposure monitored.

Email gateway protection, phishing simulations.

Quarterly phishing campaigns with targeted retraining.

Business Email Compromise

Avoid approving payments manually via email alone.

Segregation of duties and payment verification.

Crime insurance.

Residual fraud exposure accepted after control review.

Multi-level payment approval and call-back verification.

AI-powered email fraud detection and payment workflow automation.

Distributed Denial-of-Service (DDoS) Attack

Avoid exposing unnecessary public-facing services.

Traffic filtering, content delivery network and rate limiting.

Managed DDoS protection provider.

Residual service degradation accepted.

Firewall, DDoS protection and network monitoring.

Annual DDoS simulation and enhancement of public service resilience.

Insider Cyber Threat

Avoid excessive privileged access.

Least-privilege access, monitoring and segregation of duties.

Fidelity insurance where applicable.

Residual insider risk accepted under governance oversight.

User activity monitoring and privileged access reviews.

User Behaviour Analytics (UBA) and enhanced insider risk programme.

Data Breach

Minimise unnecessary storage of confidential information.

Encryption, DLP, access controls and monitoring.

Cyber liability insurance.

Residual privacy exposure accepted after governance approval.

Encryption, DLP, information classification and incident response.

Privacy impact assessments and automated data discovery tools.

Table T2-P3: Treatment and Control

This section completes the Treatment and Control Assessment by addressing the remaining threats identified in the Threat Register.

 

Threat

Existing Risk Treatment – Risk Avoidance

Existing Risk Treatment – Risk Reduction

Existing Risk Treatment – Risk Transference

Existing Risk Treatment – Risk Acceptance

Existing Controls

Additional (Planned) Controls

Loss of Physical Records

Eliminate unnecessary paper records through digitalisation.

Fire-resistant storage, secure archiving and document scanning.

Off-site records storage provider.

Minimal residual exposure accepted following digitisation.

Records management procedures, archive storage and controlled access.

Complete electronic document management system, Records Manager, High Priority (12 months).

Electronic Record Corruption

Avoid unsupported document repositories.

Database integrity checking, version control and backups.

Vendor maintenance agreements.

Residual corruption risk accepted after restoration testing.

Backup procedures, integrity monitoring and audit trails.

Automated file integrity monitoring and quarterly restoration testing.

Data Integrity Failure

Eliminate duplicate manual data entry where practical.

Input validation, maker-checker controls and reconciliation.

Not generally applicable.

Minor residual discrepancies are accepted within the approved tolerance.

Validation rules, approval workflow and reconciliation reports.

AI-assisted data validation and enhanced exception reporting.

Fraudulent Mortgage Applications

Avoid manual acceptance of unverifiable applications.

Identity verification, fraud analytics and due diligence.

Fraud loss insurance where appropriate.

Residual fraud exposure accepted following investigation controls.

Customer due diligence, AML screening, document verification and fraud monitoring.

Deploy advanced fraud detection analytics and property verification integration.

Internal Fraud

Avoid excessive concentration of authority.

Segregation of duties, mandatory leave and internal audits.

Fidelity guarantee insurance.

Residual exposure accepted under Board oversight.

Delegation of authority, audit programme and whistleblowing procedures.

Continuous transaction monitoring and behavioural analytics.

Financial Market Instability

Avoid excessive dependence on a single market segment.

Strategic portfolio monitoring and scenario planning.

Financial hedging where applicable.

Market fluctuations accepted within corporate strategy.

Financial monitoring, management reporting and strategic planning.

Quarterly economic stress testing and scenario analysis.

Regulatory Change

Avoid processes dependent upon obsolete regulations.

Regulatory monitoring, compliance reviews and policy updates.

External legal advisory services.

Temporary compliance risk accepted during the implementation period.

Compliance programme, regulatory watch process and legal review.

Regulatory change management framework and compliance impact assessments, Chief Compliance Officer, High Priority.

Regulatory Investigation

Avoid non-compliance through effective governance.

Internal audits, compliance monitoring and issue remediation.

Professional indemnity insurance where appropriate.

Residual regulatory exposure accepted following governance review.

Internal audit programme, compliance reviews and management reporting.

Annual regulatory readiness assessment and mock supervisory inspections.

Legal Proceedings

Avoid contractual ambiguity through legal review.

Legal compliance and contract management.

Legal expense insurance.

Litigation risk is accepted where unavoidable.

Legal review process and contract approval procedures.

Centralised legal obligations register and litigation response plan.

Physical Intrusion

Avoid unrestricted public access to secure areas.

Security guards, access control and surveillance.

Security services contract.

Residual physical security risk accepted.

CCTV, electronic access control and visitor management.

Biometric access control and integrated security monitoring.

Theft

Avoid unsecured storage of valuable assets.

Asset inventory management, CCTV and security patrols.

Property insurance.

Minor losses are accepted within the insurance excess.

Asset register, visitor controls and security patrols.

RFID asset tracking and enhanced security awareness training.

Vandalism

Avoid locating critical assets in vulnerable public areas.

Physical protection and perimeter security.

Property insurance.

Minor cosmetic damage accepted.

Building security, lighting and surveillance.

Smart intrusion detection and external perimeter reinforcement.

Process Failure

Eliminate unnecessary manual activities through automation.

SOPs, workflow management and quality assurance.

Not applicable.

Minor process deviations are accepted under the continuous improvement programme.

Process documentation, approval workflows and quality reviews.

Business process automation and periodic process maturity assessments.

Manual Workaround Failure

Reduce reliance on manual workarounds by improving ICT resilience.

Documented manual procedures, staff training and exercises.

Not applicable.

Temporary manual inefficiencies accepted.

Manual processing procedures and continuity plans.

Annual manual processing exercises and digital workflow improvements.

Inadequate Business Continuity Planning

Avoid operating without approved BCM governance.

BCM programme, periodic reviews and testing.

External BCM consultancy support where required.

No acceptance until minimum BCM capability is established.

Business Continuity Policy, BCM governance and annual exercises.

ISO 22301 implementation programme, annual maturity assessment, BCM Manager, Immediate Priority.

Inadequate Crisis Management

Avoid undefined crisis governance arrangements.

Crisis Management Team, crisis procedures and exercises.

Specialist crisis advisory services.

Residual crisis exposure accepted after executive approval.

Crisis Management Framework, incident escalation procedures and communications plans.

Executive crisis simulation programme and media response training.

Failure of Disaster Recovery Arrangements

Avoid unsupported ICT recovery capability.

Disaster Recovery Plans, replication and recovery exercises.

Managed disaster recovery provider.

Residual ICT outage accepted following successful annual testing.

Disaster Recovery Plan, off-site backup and recovery procedures.

Semi-annual technical recovery simulations and recovery assurance reviews.

Negative Media Coverage

Avoid unnecessary disclosure of inaccurate information.

Media management and stakeholder communications.

Public relations advisory support.

Residual reputational exposure is accepted following communications planning.

Crisis communication procedures and media spokesperson.

Reputation monitoring platform and executive media training.

Social Media Misinformation

Avoid unmanaged social media channels.

Social media monitoring and rapid response.

Communications agency support.

Residual misinformation risk is accepted after monitoring.

Corporate communications procedures.

Real-time social listening platform and misinformation response playbook.

Service Delivery Failure

Avoid overdependence on manual service delivery.

Performance monitoring, customer feedback and quality management.

Service contracts where applicable.

Minor service interruptions are accepted within approved service standards.

KPI monitoring, customer complaints management and operational reporting.

Customer experience dashboard and operational resilience metrics.

Governance Failure

Avoid unclear governance responsibilities.

Defined governance framework and Board oversight.

Independent assurance reviews.

Residual governance risk accepted after Board review.

Governance committees, internal audit and risk management framework.

Governance effectiveness assessment every two years.

Poor Change Management

Avoid uncontrolled system or business changes.

Formal change management process and testing.

Specialist implementation support.

Residual implementation risk accepted after CAB approval.

Change Advisory Board, testing and release management.

Enterprise change governance framework and post-implementation reviews.

Third-Party Concentration Risk

Avoid reliance on a single critical supplier.

Supplier diversification and resilience assessments.

Multi-vendor contracts.

Residual dependency accepted following annual review.

Third-party risk management programme.

Supplier concentration dashboard and dual-vendor strategy.

Simultaneous Multiple Disruptions

Cannot realistically be avoided.

Enterprise Crisis Management, integrated BCM and scenario planning.

Insurance and reciprocal support arrangements.

Residual enterprise risk is accepted after Board approval.

Enterprise Crisis Management Plan, BCM, Disaster Recovery Plan and Emergency Response Plan.

Enterprise-wide simulation involving multiple concurrent scenarios every year, CEO, Immediate Priority.

 

Treatment and Control Gap Analysis

Confirmed and Inferred Control Gaps

Based on the assumed control environment, several important gaps should be validated during the BCM implementation programme.

Threats Without Practical Risk Avoidance

The following threats cannot realistically be eliminated and therefore require robust preventive, response and recovery capabilities:

  • Earthquake
  • Flash Flood
  • Sandstorm
  • Pandemic
  • Commercial Power Failure
  • Cyberattack
  • Ransomware
  • Data Centre Outage
  • Simultaneous Multiple Disruptions

These threats rely predominantly on Risk Reduction supported by continuity planning and resilience investments.

Single Points of Failure Requiring Validation

Potential single-point dependencies include:

  • Mortgage Guarantee Processing System
  • Identity and Access Management platform
  • Credit Bureau integration
  • Banking interfaces
  • Cloud infrastructure
  • Specialist mortgage guarantee personnel
  • Critical telecommunications providers

These dependencies should be analysed further during the Business Impact Analysis (BIA) and dependency mapping exercises.

Controls Requiring Periodic Testing

The effectiveness of the following controls depends on regular testing:

  • Business Continuity Plans
  • Disaster Recovery Plans
  • Crisis Management Plans
  • Backup restoration procedures
  • Generator failover
  • Alternate workplace activation
  • Cloud recovery capability
  • Supplier continuity arrangements
  • Emergency communications
  • Incident escalation procedures

Untested controls should not be assumed to be fully effective.

Common Weaknesses Across Multiple Threats

Several threats share common vulnerabilities, including:

  • Dependence on a limited number of ICT suppliers
  • Dependence on key personnel
  • Increasing cybersecurity exposure
  • Limited automation of manual processes
  • Third-party service concentration
  • Insufficient integrated testing across business units

Addressing these systemic weaknesses will improve resilience across multiple threat scenarios simultaneously.

 

Planned Control Priorities

Following the assessment of existing and assumed controls, Damanat should establish a structured improvement programme to address identified gaps.

The implementation priorities below are based on the potential impact on critical business functions, regulatory expectations, operational resilience, and Business Continuity Management (BCM) maturity.

Each recommendation should be validated through detailed project planning, budget approval, and governance oversight.

 

Priority

Improvement Initiative

Primary Threat(s) Addressed

Expected Benefit

Suggested Owner

Recommended Timeframe

Immediate

Implement an ISO 22301-aligned Business Continuity Management System (BCMS).

All operational disruptions

Establishes enterprise-wide BCM governance and structured resilience.

Executive Management / BCM Manager

6–12 months

Immediate

Strengthen cybersecurity using a Zero Trust architecture, multi-factor authentication (MFA), endpoint detection and response (EDR), and Security Information and Event Management (SIEM).

Cyberattack, ransomware, phishing, malware, insider threats

Reduces cyber risk and improves incident detection and response capability.

Chief Information Security Officer (CISO)

6–12 months

Immediate

Conduct enterprise-wide Business Impact Analysis (BIA) and dependency mapping.

All critical business disruptions

Identifies recovery priorities, dependencies and recovery objectives.

BCM Manager

6 months

Immediate

Validate Disaster Recovery (DR) capability through technical recovery testing.

Data centre outage, application failure, database failure, backup failure

Confirms recoverability of critical ICT systems within target recovery objectives.

CIO / ICT Infrastructure Manager

Annually

Immediate

Develop an enterprise Crisis Management Plan integrated with BCM.

Major operational disruptions, multiple concurrent incidents

Improves strategic decision-making during crises.

Crisis Management Team

6 months

High

Establish an alternate workplace capability with secure remote working.

Pandemic, fire, building access restriction, severe weather

Maintains continuity when primary facilities are unavailable.

Facilities Manager / HR Director

12 months

High

Strengthen supplier resilience through Third-Party Risk Management (TPRM).

Critical supplier failure, cloud provider outage, telecommunications failure

Reduces dependency on critical third parties and improves supply chain resilience.

Procurement Director

12 months

High

Implement enterprise-wide electronic document and records management.

Loss of physical records, data integrity issues

Improves information availability and regulatory compliance.

Records Manager

12–18 months

High

Introduce structured succession planning and cross-training programme.

Loss of key personnel, skills shortage, absenteeism

Reduces dependency on specialist staff and improves workforce resilience.

HR Director

12 months

High

Implement automated fraud detection and advanced analytics.

Fraudulent mortgage applications, internal fraud

Improves fraud prevention and operational efficiency.

Risk Management Director

12–18 months

Medium

Diversify telecommunications and internet providers.

Telecommunications failure, ISP outage

Improves communications resilience.

CIO

12–18 months

Medium

Expand cloud resilience using multi-region or multi-cloud deployment.

Cloud service outage, data centre failure

Improves ICT availability and disaster recovery capability.

CIO

18 months

Medium

Enhance physical security with biometric access control and integrated surveillance.

Physical intrusion, theft, vandalism

Improves protection of personnel and physical assets.

Security Manager

18 months

Medium

Establish enterprise-wide resilience dashboards and Key Risk Indicators (KRIs).

Strategic and operational threats

Provides management with timely resilience reporting.

Enterprise Risk Manager

12 months

Ongoing

Conduct annual integrated BCM, Crisis Management and Disaster Recovery exercises.

All identified threats

Validates plans, improves organisational preparedness and supports continual improvement.

BCM Manager

Annual

Ongoing

Perform periodic BCM maturity assessments against ISO 22301 and organisational objectives.

Enterprise-wide

Supports continual improvement and governance oversight.

Internal Audit / BCM Manager

Every two years

 

Control Governance and Ownership

Effective risk treatment requires more than implementing controls; it requires clear governance to ensure that controls remain appropriate, effective, and aligned with Damanat's strategic objectives.

Senior management should establish a governance framework that defines accountability for implementing, monitoring, reviewing, and continually improving business continuity controls.

The Board of Directors should approve the organisation's Business Continuity Policy, risk appetite, and resilience objectives. Executive Management should ensure that sufficient resources are allocated to implement approved control improvements and oversee enterprise-wide resilience initiatives.

A Business Continuity Steering Committee should coordinate implementation across business units, monitor programme progress, and report significant issues to senior leadership.

Operational ownership should be clearly assigned according to functional responsibilities:

 

Role

Primary Governance Responsibilities

Board of Directors

Approve BCM policy, risk appetite, strategic resilience objectives, and receive regular assurance reports.

Executive Management

Sponsor BCM implementation, allocate resources and monitor enterprise resilience performance.

Business Continuity Manager

Maintain the BCMS, coordinate Business Impact Analysis (BIA), Risk Analysis and Review (RAR), plan development, testing and continual improvement.

Chief Risk Officer / Enterprise Risk Manager

Integrate BCM risks into the Enterprise Risk Management framework and monitor enterprise risk exposure.

Chief Information Officer (CIO)

Ensure resilience of ICT infrastructure, cloud services, networks, data centres and disaster recovery capability.

Chief Information Security Officer (CISO)

Protect information assets through cybersecurity governance, monitoring and incident response.

Chief Compliance Officer

Monitor regulatory developments and ensure continued compliance with SAMA, the Insurance Authority and other applicable regulatory requirements.

Human Resources Director

Maintain succession planning, workforce resilience, employee awareness and crisis staffing arrangements.

Procurement / Third-Party Risk Manager

Manage supplier resilience, contractual obligations and third-party continuity assurance.

Facilities and Security Manager

Maintain workplace resilience, physical security, emergency preparedness and facility recovery arrangements.

Internal Audit

Independently assess the effectiveness of the Business Continuity Management System and verify implementation of approved controls.

Regular governance activities should include quarterly management reviews, annual risk reassessments, periodic Business Continuity Plan reviews, testing and exercising programmes, supplier assurance reviews, internal audits, and management reporting.

Significant changes to business processes, technology, regulatory requirements, or organisational structure should trigger a review of the Risk Analysis and Review to ensure that treatment strategies and controls remain appropriate.

 

Risk treatment transforms a list of identified threats into a practical resilience programme by determining how each risk will be managed through appropriate treatment strategies and effective controls.

For Damanat, the assessment demonstrates that while some risks can be partially avoided, the majority require a combination of Risk Reduction, Risk Transference, and carefully governed Risk Acceptance.

The effectiveness of these strategies depends not only on the existence of documented controls but also on their regular validation through testing, exercising, monitoring, and continual improvement.

The Treatment and Control assessment also highlights that organisational resilience is strengthened by addressing common dependencies rather than treating each threat in isolation.

Investments in cybersecurity, resilient ICT infrastructure, supplier resilience, workforce capability, governance, and integrated business continuity arrangements simultaneously reduce exposure across multiple threat scenarios.

By implementing the recommended control improvements, validating existing arrangements, and maintaining effective governance, Damanat will be better positioned to protect its critical business functions, fulfil its regulatory obligations, and maintain stakeholder confidence during periods of disruption.

This completed Treatment and Control assessment provides the foundation for the next stage of the Business Continuity Management planning process, in which the effectiveness of the identified controls will be evaluated through likelihood and impact assessments, enabling management to prioritise risks and allocate resources in line with the organisation's overall risk appetite and resilience objectives.

 

 

eBook 3: Starting Your BCM Implementation
MBCO P&S RAR T1 RAR T2 RAR T3 BCS T1  CBF

 

 

More Information About Business Continuity Management Courses

To learn more about the course and schedule, click the buttons below for the BCM-300 Business Continuity Management Implementer [B-3] course and the BCM-5000 Business Continuity Management Expert Implementer [B-5].

If you have any questions, click to contact us.