Introduction
Following the identification of credible threats in Part 1: RAR – List of Threats and the evaluation of preventive, detective and corrective controls in Part 2: RAR – Treatment and Control, the next stage of the Risk Analysis and Review (RAR) process is to evaluate the residual business risk posed by each threat.
This chapter provides a structured assessment of the potential impact and likelihood of each approved threat affecting The Saudi Mortgage Guarantees Services Company (Damanat).
The objective is to establish a consistent and transparent assessment of current risk exposure, enabling management to prioritise Business Continuity Management (BCM) initiatives, determine continuity strategies and allocate resources appropriately.
For the purposes of this assessment, the risk evaluation is performed after considering the effectiveness of the existing controls identified in RAR Part 2, but before implementing any additional recommended controls or future improvement initiatives.
Consequently, the results represent the organisation's current residual risk profile, which should subsequently be validated by the respective business owners, risk owners and senior management.
The assessment follows recognised Business Continuity Management and Enterprise Risk Management principles, consistent with ISO 22301, ISO 22313, ISO 31000, and ISO 31010, while remaining suitable for organisations operating in the financial services sector in the Kingdom of Saudi Arabia.
Assessment Objectives
The Risk Impact and Likelihood Assessment has several important objectives:
- evaluate the current exposure of Damanat to each approved threat;
- determine the potential severity of business disruption should a threat materialise;
- establish a consistent basis for prioritising Business Continuity planning activities;
- identify threats requiring additional mitigation or recovery strategies;
- support Business Impact Analysis (BIA) by understanding credible disruption scenarios;
- facilitate informed decision-making by senior management; and
- provide documented evidence supporting regulatory and governance requirements.
The assessment is not intended to predict future incidents. Rather, it provides a structured estimate of credible business risks based on current operating conditions, existing controls and professional judgement.
Assessment Basis
The assessment presented in this chapter is based on the following assumptions:
- the approved threat register developed in RAR Part 1;
- the existing treatment measures and controls documented in RAR Part 2;
- Damanat's current organisational structure;
- current operating environment within the Kingdom of Saudi Arabia;
- publicly recognised financial-sector threats;
- reasonable assumptions regarding mortgage guarantee operations where detailed internal information is unavailable.
The assessment represents current residual risk after considering existing controls.
It does not represent:
- inherent risk before controls; or
- future residual risk after planned improvements.
Final risk ratings should be reviewed and approved by business owners and the organisation's Risk Management Committee.
Approved Threat Coverage
The approved threats collectively address all major Business Continuity disruption categories.
|
Threat Category |
Typical Approved Threats |
|
Denial of Access – Natural Disaster |
Flood, Severe Storm |
|
Denial of Access – Man-made Disaster |
Fire, Building Access Restriction |
|
Unavailability of People |
Pandemic, Loss of Key Personnel |
|
Supply Chain Disruption |
Critical Supplier Failure |
|
Equipment and IT Disruption |
Power Failure, Telecommunications Failure, Application Failure, Data Centre Outage, Cyberattack, Ransomware |
The detailed assessment continues to use the specific threat names rather than the broader categories.
Risk Impact Assessment Methodology
Each threat is assessed against seven impact areas.
|
Impact Area |
Description |
|
Finance |
Financial loss, recovery expenditure, contractual obligations, and operational costs. |
|
Operations |
Disruption to critical mortgage guarantee services and supporting operations. |
|
Legal and Regulatory |
Failure to comply with applicable legal, contractual or regulatory obligations. |
|
Reputation and Image |
Loss of confidence among stakeholders, government agencies and financial institutions. |
|
Social Responsibility |
Effects on market confidence and Damanat's ability to support the national housing finance ecosystem. |
|
People |
Injury, illness, workforce availability, leadership disruption and staff welfare. |
|
Assets, IT Systems and Information |
Damage to facilities, ICT services, applications, information assets and vital records. |
Each impact area is scored using the following five-point scale.
|
Score |
Rating |
|
1 |
Very Low - Insignificant |
|
2 |
Low - Minor |
|
3 |
Moderate |
|
4 |
High - Major |
|
5 |
Very High - Severe |
Likelihood Assessment Methodology
Likelihood estimates consider:
- historical industry experience;
- current threat intelligence;
- operating environment;
- exposure of business processes;
- effectiveness of existing controls;
- dependency upon suppliers;
- maturity of ICT controls;
- cybersecurity threat landscape; and
- environmental and geopolitical factors.
|
Score |
Likelihood |
|
1 |
Very Low - Rare |
|
2 |
Low - Unlikely |
|
3 |
Moderate - Possible |
|
4 |
High - Likely |
|
5 |
Very High - Almost Certain |
Likelihood is assessed independently from impact.
Risk Rating Methodology
The overall Risk Rating is calculated using the following formula:
Risk Rating = Highest Impact Score × Likelihood Score
The resulting Risk Level is determined using the following matrix.
|
Risk Rating |
Risk Level |
|
1–4 |
Low |
|
5–9 |
Moderate |
|
10–16 |
High |
|
17–25 |
Extreme |
Where multiple impact areas receive the same highest score, all applicable impact areas should be identified.
Expected Disruption Period
For each threat, an indicative disruption period is estimated after considering existing controls.
This estimate reflects:
- expected interruption duration;
- restoration complexity;
- supplier dependency;
- alternate workplace arrangements;
- ICT disaster recovery capability;
- availability of replacement resources; and
- external agency response.
The disruption period should not be confused with either the Recovery Time Objective (RTO) or the Maximum Tolerable Period of Disruption (MTPD), both of which will be established during the Business Impact Analysis.
Risk Impact and Likelihood Assessment
The following table provides an illustrative implementation assessment based on recognised financial-sector threats and should be validated against the approved threat register and existing controls documented in RAR Parts 1 and 2.
Table T3: Risk Impact and Likelihood Assessment
|
Threat |
Finance |
Operations |
Legal & Regulatory |
Reputation & Image |
Social Responsibility |
People |
Assets / IT Systems / Information |
Highest Impact Score |
Likelihood |
Risk Rating |
Risk Level |
Expected Period of Disruption |
| Earthquake | 4 | 5 | 4 | 4 | 3 | 5 | 5 | Operations, People, Assets/IT (5) | 2 | 10 | High | 1–2 weeks |
| Flash Flood | 3 | 4 | 3 | 3 | 2 | 3 | 4 | Operations, Assets/IT (4) | 2 | 8 | Moderate | 3–7 days |
| Severe Sandstorm | 2 | 3 | 2 | 2 | 2 | 2 | 3 | Operations, Assets/IT (3) | 4 | 12 | High | 8–24 hours |
| Extreme Heat | 3 | 3 | 2 | 2 | 2 | 3 | 4 | Assets/IT (4) | 4 | 16 | High | 8–24 hours |
| Pandemic | 4 | 5 | 4 | 4 | 4 | 5 | 2 | Operations, People (5) | 3 | 15 | High | More than 1 month |
| Fire | 4 | 5 | 4 | 4 | 3 | 5 | 5 | Operations, People, Assets/IT (5) | 2 | 10 | High | 1–2 weeks |
| Explosion | 4 | 5 | 4 | 4 | 3 | 5 | 5 | Operations, People, Assets/IT (5) | 1 | 5 | Moderate | 1–2 weeks |
| Hazardous Material Release | 3 | 4 | 3 | 3 | 3 | 4 | 3 | People (4) | 2 | 8 | Moderate | 1–3 days |
| Civil Disturbance | 2 | 3 | 2 | 3 | 2 | 2 | 2 | Operations, Reputation (3) | 2 | 6 | Moderate | 1–3 days |
| Terrorist Incident | 4 | 5 | 4 | 5 | 4 | 5 | 5 | Operations, Reputation, People, Assets/IT (5) | 1 | 5 | Moderate | 1–2 weeks |
| Building Access Restriction | 3 | 4 | 3 | 3 | 2 | 3 | 2 | Operations (4) | 3 | 12 | High | 1–3 days |
| Loss of Key Personnel | 3 | 4 | 3 | 3 | 2 | 4 | 2 | Operations, People (4) | 3 | 12 | High | 1–2 weeks |
| Industrial Action | 2 | 3 | 2 | 2 | 2 | 3 | 1 | Operations, People (3) | 2 | 6 | Moderate | 3–7 days |
| High Staff Absenteeism | 2 | 4 | 2 | 2 | 2 | 4 | 1 | Operations, People (4) | 3 | 12 | High | 1–2 weeks |
| Skills Shortage | 2 | 4 | 3 | 3 | 2 | 3 | 1 | Operations (4) | 3 | 12 | High | More than 1 month |
| Human Error | 3 | 4 | 3 | 3 | 2 | 2 | 3 | Operations (4) | 4 | 16 | High | 4–24 hours |
| Critical Supplier Failure | 4 | 5 | 4 | 4 | 3 | 2 | 3 | Operations (5) | 3 | 15 | High | 3–7 days |
| Cloud Service Provider Outage | 4 | 5 | 4 | 4 | 2 | 2 | 5 | Operations, Assets/IT (5) | 3 | 15 | High | 1–3 days |
| Telecommunications Failure | 3 | 5 | 3 | 3 | 2 | 2 | 5 | Operations, Assets/IT (5) | 3 | 15 | High | 4–24 hours |
| Internet Service Provider Failure | 3 | 4 | 3 | 3 | 2 | 2 | 5 | Assets/IT (5) | 3 | 15 | High | 4–24 hours |
| Credit Bureau Service Failure | 3 | 4 | 3 | 3 | 2 | 1 | 2 | Operations (4) | 3 | 12 | High | 1–3 days |
| Banking Partner System Failure | 4 | 5 | 4 | 4 | 2 | 1 | 3 | Operations (5) | 3 | 15 | High | 1–3 days |
| Outsourced ICT Support Failure | 3 | 4 | 3 | 3 | 2 | 2 | 4 | Operations, Assets/IT (4) | 3 | 12 | High | 1–3 days |
| Commercial Power Failure | 3 | 5 | 3 | 3 | 2 | 2 | 5 | Operations, Assets/IT (5) | 3 | 15 | High | 4–24 hours |
| HVAC Failure | 2 | 3 | 2 | 2 | 1 | 1 | 4 | Assets/IT (4) | 3 | 12 | High | 8–24 hours |
| Network Failure | 3 | 5 | 3 | 3 | 2 | 1 | 5 | Operations, Assets/IT (5) | 3 | 15 | High | 4–24 hours |
| Data Centre Outage | 4 | 5 | 4 | 4 | 2 | 1 | 5 | Operations, Assets/IT (5) | 3 | 15 | High | 1–3 days |
| Core Mortgage Guarantee System Failure | 4 | 5 | 4 | 4 | 2 | 1 | 5 | Operations, Assets/IT (5) | 3 | 15 | High | 8–24 hours |
| Database Failure | 4 | 5 | 4 | 4 | 2 | 1 | 5 | Operations, Assets/IT (5) | 3 | 15 | High | 8–24 hours |
| Identity and Access Management Failure | 3 | 4 | 4 | 4 | 2 | 1 | 5 | Assets/IT (5) | 3 | 15 | High | 4–24 hours |
| Backup Failure | 3 | 5 | 4 | 4 | 2 | 1 | 5 | Operations, Assets/IT (5) | 2 | 10 | High | 1–3 days |
| Storage System Failure | 3 | 4 | 3 | 3 | 2 | 1 | 5 | Assets/IT (5) | 3 | 15 | High | 8–24 hours |
| Ransomware Attack | 5 | 5 | 5 | 5 | 3 | 2 | 5 | Finance, Operations, Legal, Reputation, Assets/IT (5) | 4 | 20 | Extreme | 2–4 weeks |
| Malware Infection | 3 | 4 | 3 | 3 | 2 | 1 | 5 | Assets/IT (5) | 4 | 20 | Extreme | 1–3 days |
| Phishing Attack | 3 | 4 | 4 | 4 | 2 | 2 | 4 | Legal, Reputation, Assets/IT (4) | 4 | 16 | High | 4–24 hours |
| Business Email Compromise | 5 | 3 | 4 | 4 | 2 | 1 | 4 | Finance (5) | 3 | 15 | High | 1–3 days |
| Distributed Denial-of-Service (DDoS) Attack | 3 | 5 | 3 | 4 | 2 | 1 | 5 | Operations, Assets/IT (5) | 3 | 15 | High | 8–24 hours |
| Insider Cyber Threat | 4 | 4 | 5 | 5 | 2 | 2 | 5 | Legal, Reputation, Assets/IT (5) | 3 | 15 | High | 1–2 weeks |
| Data Breach | 5 | 4 | 5 | 5 | 3 | 2 | 5 | Finance, Legal, Reputation, Assets/IT (5) | 3 | 15 | High | 2–4 weeks |
| Loss of Physical Records | 3 | 4 | 4 | 3 | 2 | 1 | 4 | Legal, Operations, Assets/IT (4) | 2 | 8 | Moderate | 3–7 days |
| Electronic Record Corruption | 3 | 4 | 4 | 3 | 2 | 1 | 5 | Assets/IT (5) | 3 | 15 | High | 1–3 days |
| Data Integrity Failure | 3 | 4 | 4 | 3 | 2 | 1 | 4 | Legal, Operations, Assets/IT (4) | 3 | 12 | High | 1–3 days |
| Fraudulent Mortgage Applications | 5 | 4 | 5 | 5 | 3 | 1 | 3 | Finance, Legal, Reputation (5) | 3 | 15 | High | 1–3 days |
| Internal Fraud | 5 | 4 | 5 | 5 | 2 | 2 | 3 | Finance, Legal, Reputation (5) | 3 | 15 | High | 1–2 weeks |
| Financial Market Instability | 5 | 4 | 3 | 3 | 3 | 1 | 2 | Finance (5) | 3 | 15 | High | More than 1 month |
| Regulatory Change | 3 | 4 | 5 | 4 | 2 | 1 | 2 | Legal & Regulatory (5) | 4 | 20 | Extreme | 1–3 months |
| Regulatory Investigation | 4 | 4 | 5 | 5 | 2 | 2 | 2 | Legal & Regulatory, Reputation (5) | 2 | 10 | High | 1–3 months |
| Legal Proceedings | 5 | 3 | 5 | 4 | 2 | 1 | 2 | Finance, Legal (5) | 2 | 10 | High | More than 1 month |
| Physical Intrusion | 3 | 3 | 3 | 3 | 2 | 3 | 4 | Assets/IT (4) | 2 | 8 | Moderate | 1–3 days |
| Theft | 3 | 2 | 2 | 2 | 1 | 1 | 3 | Finance, Assets/IT (3) | 3 | 9 | Moderate | 1–3 days |
| Vandalism | 2 | 2 | 2 | 2 | 1 | 1 | 3 | Assets/IT (3) | 2 | 6 | Moderate | 1–3 days |
| Process Failure | 4 | 5 | 4 | 4 | 2 | 2 | 3 | Operations (5) | 3 | 15 | High | 1–3 days |
| Manual Workaround Failure | 3 | 4 | 3 | 3 | 2 | 2 | 3 | Operations (4) | 3 | 12 | High | 1–3 days |
| Inadequate Business Continuity Planning | 4 | 5 | 4 | 4 | 3 | 3 | 3 | Operations (5) | 3 | 15 | High | More than 1 month |
| Inadequate Crisis Management | 4 | 5 | 4 | 5 | 3 | 3 | 2 | Operations, Reputation (5) | 3 | 15 | High | More than 1 month |
| Failure of Disaster Recovery Arrangements | 4 | 5 | 4 | 4 | 2 | 2 | 5 | Operations, Assets/IT (5) | 3 | 15 | High | 1–2 weeks |
| Negative Media Coverage | 3 | 2 | 2 | 5 | 3 | 1 | 1 | Reputation (5) | 3 | 15 | High | 1–3 months |
| Social Media Misinformation | 2 | 2 | 2 | 4 | 3 | 1 | 1 | Reputation (4) | 4 | 16 | High | 1–3 weeks |
| Service Delivery Failure | 4 | 5 | 4 | 4 | 3 | 2 | 2 | Operations (5) | 3 | 15 | High | 1–3 days |
| Governance Failure | 4 | 4 | 5 | 5 | 2 | 2 | 2 | Legal & Regulatory, Reputation (5) | 2 | 10 | High | More than 1 month |
| Poor Change Management | 3 | 4 | 4 | 3 | 2 | 2 | 4 | Operations, Legal, Assets/IT (4) | 3 | 12 | High | 1–3 days |
| Third-Party Concentration Risk | 4 | 5 | 3 | 4 | 2 | 1 | 3 | Operations (5) | 3 | 15 | High | 1–2 weeks |
| Simultaneous Multiple Disruptions | 5 | 5 | 5 | 5 | 5 | 5 | 5 | All Impact Areas (5) | 2 | 10 | High | More than 1 month |
Overall Assessment
The assessment indicates that Damanat's highest residual risks are associated with disruptions affecting information technology, cybersecurity and critical business applications.
These threats have the potential to interrupt mortgage guarantee operations, affect regulatory reporting, delay customer services and impact relationships with financial institutions.
Business disruptions arising from workforce unavailability and critical third-party failures also pose significant operational challenges, as many mortgage guarantee processes depend on specialist expertise, external service providers, and secure digital platforms.
Although natural hazards generally have a lower likelihood in the Kingdom of Saudi Arabia than cyber-related threats, they remain credible scenarios that should be incorporated into continuity planning due to their potential impact on facilities, staff accessibility, and operational resilience.
The assessment further demonstrates that many risks can be significantly reduced through strong governance, resilient ICT architecture, effective incident response procedures, supplier resilience arrangements, workforce succession planning and regular Business Continuity exercises.
Validation Requirements
The indicative assessment contained within this chapter should be validated through structured workshops involving:
- Executive Management;
- Enterprise Risk Management;
- Business Continuity Management;
- Information Technology;
- Information Security;
- Human Resources;
- Facilities Management;
- Procurement;
- Legal and Compliance; and
- representatives from each Critical Business Function.
During validation, participants should confirm:
- impact scores;
- likelihood estimates;
- effectiveness of existing controls;
- disruption duration assumptions;
- risk ratings;
- ownership of risks; and
- priority improvement initiatives.
Any amendments approved during these workshops should be reflected in the final Risk Assessment Report before progressing to the Business Impact Analysis phase.
The Risk Impact and Likelihood Assessment transforms the approved threat register into a structured evaluation of Damanat's current residual risk profile.
By consistently assessing the potential business consequences and probability of each threat after considering existing controls, management can identify priority risks that require enhanced resilience measures and continuity planning.
The validated risk ratings developed in this chapter provide essential input to the subsequent Business Impact Analysis, in which the organisation will determine recovery priorities, establish recovery objectives, and develop practical continuity strategies for each Critical Business Function.


![[BCM] [Damanat] [Full Banner] Implementing BCM for The Saudi Mortgage Guarantees Services Company](https://no-cache.hubspot.com/cta/default/3893111/221734db-8c33-48bd-8147-fc740eecaf83.png)
![x eBook Cover [BCM] [Damanat] [E3] [2D]](https://no-cache.hubspot.com/cta/default/3893111/9c8a0e17-f242-4419-8556-3a72acb6397e.png)
![Banner [BCM] [E3] [RAR] [T3] Risk Impact and Likelihood Assessment](https://no-cache.hubspot.com/cta/default/3893111/1626b4db-b5dd-4c9d-8d1d-c84aa9a691f1.png)




![[BCM] [Damanat] [3/4 Banner] Implementing BCM for The Saudi Mortgage Guarantees Services Company](https://no-cache.hubspot.com/cta/default/3893111/0252380a-b2dc-4059-be10-b5566002b711.png)
![[BCM] [Damanat] [E3] [BIA] MBCO Corporate MBCO](https://no-cache.hubspot.com/cta/default/3893111/be2d62c7-973a-489a-8556-d73428e73448.png)
![[BCM] [Damanat] [E3] [BIA] [PS] Key Product and Services](https://no-cache.hubspot.com/cta/default/3893111/db1b84bd-ff7f-4d59-8efb-d610b612a861.png)
![[BCM] [Damanat] [E3] [RAR] [T1] List of Threats](https://no-cache.hubspot.com/cta/default/3893111/3c267477-b524-461e-982d-1218d6bcac5b.png)
![[BCM] [Damanat] [E3] [RAR] [T2] Treatment and Control](https://no-cache.hubspot.com/cta/default/3893111/683192aa-bac0-4658-981a-a392b104aa51.png)
![[BCM] [Damanat] [E3] [BCS] [T1] Mitigation Strategies and Justification](https://no-cache.hubspot.com/cta/default/3893111/65dcb68f-d4c9-4517-94f6-8d6df193c7bd.png)
![BCM] [Damanat] [E1] [C10] Identifying Critical Business Functions](https://no-cache.hubspot.com/cta/default/3893111/09f61f4b-0a96-4099-90ad-ec4db212874e.png)


![Register [BL-B-3]*](https://no-cache.hubspot.com/cta/default/3893111/ac6cf073-4cdd-4541-91ed-889f731d5076.png)



![FAQ [BL-B-3]](https://no-cache.hubspot.com/cta/default/3893111/b3824ba1-7aa1-4eb6-bef8-94f57121c5ae.png)
![Email to Sales Team [BCM Institute]](https://no-cache.hubspot.com/cta/default/3893111/3c53daeb-2836-4843-b0e0-645baee2ab9e.png)





