This chapter provides a structured assessment of the potential impact and likelihood of each approved threat affecting The Saudi Mortgage Guarantees Services Company (Damanat).
The objective is to establish a consistent and transparent assessment of current risk exposure, enabling management to prioritise Business Continuity Management (BCM) initiatives, determine continuity strategies and allocate resources appropriately.
For the purposes of this assessment, the risk evaluation is performed after considering the effectiveness of the existing controls identified in RAR Part 2, but before implementing any additional recommended controls or future improvement initiatives.
Consequently, the results represent the organisation's current residual risk profile, which should subsequently be validated by the respective business owners, risk owners and senior management.
The assessment follows recognised Business Continuity Management and Enterprise Risk Management principles, consistent with ISO 22301, ISO 22313, ISO 31000, and ISO 31010, while remaining suitable for organisations operating in the financial services sector in the Kingdom of Saudi Arabia.
The Risk Impact and Likelihood Assessment has several important objectives:
The assessment is not intended to predict future incidents. Rather, it provides a structured estimate of credible business risks based on current operating conditions, existing controls and professional judgement.
The assessment presented in this chapter is based on the following assumptions:
The assessment represents current residual risk after considering existing controls.
It does not represent:
Final risk ratings should be reviewed and approved by business owners and the organisation's Risk Management Committee.
The approved threats collectively address all major Business Continuity disruption categories.
|
Threat Category |
Typical Approved Threats |
|
Denial of Access – Natural Disaster |
Flood, Severe Storm |
|
Denial of Access – Man-made Disaster |
Fire, Building Access Restriction |
|
Unavailability of People |
Pandemic, Loss of Key Personnel |
|
Supply Chain Disruption |
Critical Supplier Failure |
|
Equipment and IT Disruption |
Power Failure, Telecommunications Failure, Application Failure, Data Centre Outage, Cyberattack, Ransomware |
The detailed assessment continues to use the specific threat names rather than the broader categories.
Each threat is assessed against seven impact areas.
|
Impact Area |
Description |
|
Finance |
Financial loss, recovery expenditure, contractual obligations, and operational costs. |
|
Operations |
Disruption to critical mortgage guarantee services and supporting operations. |
|
Legal and Regulatory |
Failure to comply with applicable legal, contractual or regulatory obligations. |
|
Reputation and Image |
Loss of confidence among stakeholders, government agencies and financial institutions. |
|
Social Responsibility |
Effects on market confidence and Damanat's ability to support the national housing finance ecosystem. |
|
People |
Injury, illness, workforce availability, leadership disruption and staff welfare. |
|
Assets, IT Systems and Information |
Damage to facilities, ICT services, applications, information assets and vital records. |
Each impact area is scored using the following five-point scale.
|
Score |
Rating |
|
1 |
Very Low - Insignificant |
|
2 |
Low - Minor |
|
3 |
Moderate |
|
4 |
High - Major |
|
5 |
Very High - Severe |
Likelihood estimates consider:
|
Score |
Likelihood |
|
1 |
Very Low - Rare |
|
2 |
Low - Unlikely |
|
3 |
Moderate - Possible |
|
4 |
High - Likely |
|
5 |
Very High - Almost Certain |
Likelihood is assessed independently from impact.
The overall Risk Rating is calculated using the following formula:
The resulting Risk Level is determined using the following matrix.
|
Risk Rating |
Risk Level |
|
1–4 |
Low |
|
5–9 |
Moderate |
|
10–16 |
High |
|
17–25 |
Extreme |
Where multiple impact areas receive the same highest score, all applicable impact areas should be identified.
For each threat, an indicative disruption period is estimated after considering existing controls.
This estimate reflects:
The disruption period should not be confused with either the Recovery Time Objective (RTO) or the Maximum Tolerable Period of Disruption (MTPD), both of which will be established during the Business Impact Analysis.
The following table provides an illustrative implementation assessment based on recognised financial-sector threats and should be validated against the approved threat register and existing controls documented in RAR Parts 1 and 2.
|
Threat |
Finance |
Operations |
Legal & Regulatory |
Reputation & Image |
Social Responsibility |
People |
Assets / IT Systems / Information |
Highest Impact Score |
Likelihood |
Risk Rating |
Risk Level |
Expected Period of Disruption |
| Earthquake | 4 | 5 | 4 | 4 | 3 | 5 | 5 | Operations, People, Assets/IT (5) | 2 | 10 | High | 1–2 weeks |
| Flash Flood | 3 | 4 | 3 | 3 | 2 | 3 | 4 | Operations, Assets/IT (4) | 2 | 8 | Moderate | 3–7 days |
| Severe Sandstorm | 2 | 3 | 2 | 2 | 2 | 2 | 3 | Operations, Assets/IT (3) | 4 | 12 | High | 8–24 hours |
| Extreme Heat | 3 | 3 | 2 | 2 | 2 | 3 | 4 | Assets/IT (4) | 4 | 16 | High | 8–24 hours |
| Pandemic | 4 | 5 | 4 | 4 | 4 | 5 | 2 | Operations, People (5) | 3 | 15 | High | More than 1 month |
| Fire | 4 | 5 | 4 | 4 | 3 | 5 | 5 | Operations, People, Assets/IT (5) | 2 | 10 | High | 1–2 weeks |
| Explosion | 4 | 5 | 4 | 4 | 3 | 5 | 5 | Operations, People, Assets/IT (5) | 1 | 5 | Moderate | 1–2 weeks |
| Hazardous Material Release | 3 | 4 | 3 | 3 | 3 | 4 | 3 | People (4) | 2 | 8 | Moderate | 1–3 days |
| Civil Disturbance | 2 | 3 | 2 | 3 | 2 | 2 | 2 | Operations, Reputation (3) | 2 | 6 | Moderate | 1–3 days |
| Terrorist Incident | 4 | 5 | 4 | 5 | 4 | 5 | 5 | Operations, Reputation, People, Assets/IT (5) | 1 | 5 | Moderate | 1–2 weeks |
| Building Access Restriction | 3 | 4 | 3 | 3 | 2 | 3 | 2 | Operations (4) | 3 | 12 | High | 1–3 days |
| Loss of Key Personnel | 3 | 4 | 3 | 3 | 2 | 4 | 2 | Operations, People (4) | 3 | 12 | High | 1–2 weeks |
| Industrial Action | 2 | 3 | 2 | 2 | 2 | 3 | 1 | Operations, People (3) | 2 | 6 | Moderate | 3–7 days |
| High Staff Absenteeism | 2 | 4 | 2 | 2 | 2 | 4 | 1 | Operations, People (4) | 3 | 12 | High | 1–2 weeks |
| Skills Shortage | 2 | 4 | 3 | 3 | 2 | 3 | 1 | Operations (4) | 3 | 12 | High | More than 1 month |
| Human Error | 3 | 4 | 3 | 3 | 2 | 2 | 3 | Operations (4) | 4 | 16 | High | 4–24 hours |
| Critical Supplier Failure | 4 | 5 | 4 | 4 | 3 | 2 | 3 | Operations (5) | 3 | 15 | High | 3–7 days |
| Cloud Service Provider Outage | 4 | 5 | 4 | 4 | 2 | 2 | 5 | Operations, Assets/IT (5) | 3 | 15 | High | 1–3 days |
| Telecommunications Failure | 3 | 5 | 3 | 3 | 2 | 2 | 5 | Operations, Assets/IT (5) | 3 | 15 | High | 4–24 hours |
| Internet Service Provider Failure | 3 | 4 | 3 | 3 | 2 | 2 | 5 | Assets/IT (5) | 3 | 15 | High | 4–24 hours |
| Credit Bureau Service Failure | 3 | 4 | 3 | 3 | 2 | 1 | 2 | Operations (4) | 3 | 12 | High | 1–3 days |
| Banking Partner System Failure | 4 | 5 | 4 | 4 | 2 | 1 | 3 | Operations (5) | 3 | 15 | High | 1–3 days |
| Outsourced ICT Support Failure | 3 | 4 | 3 | 3 | 2 | 2 | 4 | Operations, Assets/IT (4) | 3 | 12 | High | 1–3 days |
| Commercial Power Failure | 3 | 5 | 3 | 3 | 2 | 2 | 5 | Operations, Assets/IT (5) | 3 | 15 | High | 4–24 hours |
| HVAC Failure | 2 | 3 | 2 | 2 | 1 | 1 | 4 | Assets/IT (4) | 3 | 12 | High | 8–24 hours |
| Network Failure | 3 | 5 | 3 | 3 | 2 | 1 | 5 | Operations, Assets/IT (5) | 3 | 15 | High | 4–24 hours |
| Data Centre Outage | 4 | 5 | 4 | 4 | 2 | 1 | 5 | Operations, Assets/IT (5) | 3 | 15 | High | 1–3 days |
| Core Mortgage Guarantee System Failure | 4 | 5 | 4 | 4 | 2 | 1 | 5 | Operations, Assets/IT (5) | 3 | 15 | High | 8–24 hours |
| Database Failure | 4 | 5 | 4 | 4 | 2 | 1 | 5 | Operations, Assets/IT (5) | 3 | 15 | High | 8–24 hours |
| Identity and Access Management Failure | 3 | 4 | 4 | 4 | 2 | 1 | 5 | Assets/IT (5) | 3 | 15 | High | 4–24 hours |
| Backup Failure | 3 | 5 | 4 | 4 | 2 | 1 | 5 | Operations, Assets/IT (5) | 2 | 10 | High | 1–3 days |
| Storage System Failure | 3 | 4 | 3 | 3 | 2 | 1 | 5 | Assets/IT (5) | 3 | 15 | High | 8–24 hours |
| Ransomware Attack | 5 | 5 | 5 | 5 | 3 | 2 | 5 | Finance, Operations, Legal, Reputation, Assets/IT (5) | 4 | 20 | Extreme | 2–4 weeks |
| Malware Infection | 3 | 4 | 3 | 3 | 2 | 1 | 5 | Assets/IT (5) | 4 | 20 | Extreme | 1–3 days |
| Phishing Attack | 3 | 4 | 4 | 4 | 2 | 2 | 4 | Legal, Reputation, Assets/IT (4) | 4 | 16 | High | 4–24 hours |
| Business Email Compromise | 5 | 3 | 4 | 4 | 2 | 1 | 4 | Finance (5) | 3 | 15 | High | 1–3 days |
| Distributed Denial-of-Service (DDoS) Attack | 3 | 5 | 3 | 4 | 2 | 1 | 5 | Operations, Assets/IT (5) | 3 | 15 | High | 8–24 hours |
| Insider Cyber Threat | 4 | 4 | 5 | 5 | 2 | 2 | 5 | Legal, Reputation, Assets/IT (5) | 3 | 15 | High | 1–2 weeks |
| Data Breach | 5 | 4 | 5 | 5 | 3 | 2 | 5 | Finance, Legal, Reputation, Assets/IT (5) | 3 | 15 | High | 2–4 weeks |
| Loss of Physical Records | 3 | 4 | 4 | 3 | 2 | 1 | 4 | Legal, Operations, Assets/IT (4) | 2 | 8 | Moderate | 3–7 days |
| Electronic Record Corruption | 3 | 4 | 4 | 3 | 2 | 1 | 5 | Assets/IT (5) | 3 | 15 | High | 1–3 days |
| Data Integrity Failure | 3 | 4 | 4 | 3 | 2 | 1 | 4 | Legal, Operations, Assets/IT (4) | 3 | 12 | High | 1–3 days |
| Fraudulent Mortgage Applications | 5 | 4 | 5 | 5 | 3 | 1 | 3 | Finance, Legal, Reputation (5) | 3 | 15 | High | 1–3 days |
| Internal Fraud | 5 | 4 | 5 | 5 | 2 | 2 | 3 | Finance, Legal, Reputation (5) | 3 | 15 | High | 1–2 weeks |
| Financial Market Instability | 5 | 4 | 3 | 3 | 3 | 1 | 2 | Finance (5) | 3 | 15 | High | More than 1 month |
| Regulatory Change | 3 | 4 | 5 | 4 | 2 | 1 | 2 | Legal & Regulatory (5) | 4 | 20 | Extreme | 1–3 months |
| Regulatory Investigation | 4 | 4 | 5 | 5 | 2 | 2 | 2 | Legal & Regulatory, Reputation (5) | 2 | 10 | High | 1–3 months |
| Legal Proceedings | 5 | 3 | 5 | 4 | 2 | 1 | 2 | Finance, Legal (5) | 2 | 10 | High | More than 1 month |
| Physical Intrusion | 3 | 3 | 3 | 3 | 2 | 3 | 4 | Assets/IT (4) | 2 | 8 | Moderate | 1–3 days |
| Theft | 3 | 2 | 2 | 2 | 1 | 1 | 3 | Finance, Assets/IT (3) | 3 | 9 | Moderate | 1–3 days |
| Vandalism | 2 | 2 | 2 | 2 | 1 | 1 | 3 | Assets/IT (3) | 2 | 6 | Moderate | 1–3 days |
| Process Failure | 4 | 5 | 4 | 4 | 2 | 2 | 3 | Operations (5) | 3 | 15 | High | 1–3 days |
| Manual Workaround Failure | 3 | 4 | 3 | 3 | 2 | 2 | 3 | Operations (4) | 3 | 12 | High | 1–3 days |
| Inadequate Business Continuity Planning | 4 | 5 | 4 | 4 | 3 | 3 | 3 | Operations (5) | 3 | 15 | High | More than 1 month |
| Inadequate Crisis Management | 4 | 5 | 4 | 5 | 3 | 3 | 2 | Operations, Reputation (5) | 3 | 15 | High | More than 1 month |
| Failure of Disaster Recovery Arrangements | 4 | 5 | 4 | 4 | 2 | 2 | 5 | Operations, Assets/IT (5) | 3 | 15 | High | 1–2 weeks |
| Negative Media Coverage | 3 | 2 | 2 | 5 | 3 | 1 | 1 | Reputation (5) | 3 | 15 | High | 1–3 months |
| Social Media Misinformation | 2 | 2 | 2 | 4 | 3 | 1 | 1 | Reputation (4) | 4 | 16 | High | 1–3 weeks |
| Service Delivery Failure | 4 | 5 | 4 | 4 | 3 | 2 | 2 | Operations (5) | 3 | 15 | High | 1–3 days |
| Governance Failure | 4 | 4 | 5 | 5 | 2 | 2 | 2 | Legal & Regulatory, Reputation (5) | 2 | 10 | High | More than 1 month |
| Poor Change Management | 3 | 4 | 4 | 3 | 2 | 2 | 4 | Operations, Legal, Assets/IT (4) | 3 | 12 | High | 1–3 days |
| Third-Party Concentration Risk | 4 | 5 | 3 | 4 | 2 | 1 | 3 | Operations (5) | 3 | 15 | High | 1–2 weeks |
| Simultaneous Multiple Disruptions | 5 | 5 | 5 | 5 | 5 | 5 | 5 | All Impact Areas (5) | 2 | 10 | High | More than 1 month |
The assessment indicates that Damanat's highest residual risks are associated with disruptions affecting information technology, cybersecurity and critical business applications.
These threats have the potential to interrupt mortgage guarantee operations, affect regulatory reporting, delay customer services and impact relationships with financial institutions.
Business disruptions arising from workforce unavailability and critical third-party failures also pose significant operational challenges, as many mortgage guarantee processes depend on specialist expertise, external service providers, and secure digital platforms.
Although natural hazards generally have a lower likelihood in the Kingdom of Saudi Arabia than cyber-related threats, they remain credible scenarios that should be incorporated into continuity planning due to their potential impact on facilities, staff accessibility, and operational resilience.
The assessment further demonstrates that many risks can be significantly reduced through strong governance, resilient ICT architecture, effective incident response procedures, supplier resilience arrangements, workforce succession planning and regular Business Continuity exercises.
The indicative assessment contained within this chapter should be validated through structured workshops involving:
During validation, participants should confirm:
Any amendments approved during these workshops should be reflected in the final Risk Assessment Report before progressing to the Business Impact Analysis phase.
The Risk Impact and Likelihood Assessment transforms the approved threat register into a structured evaluation of Damanat's current residual risk profile.
By consistently assessing the potential business consequences and probability of each threat after considering existing controls, management can identify priority risks that require enhanced resilience measures and continuity planning.
The validated risk ratings developed in this chapter provide essential input to the subsequent Business Impact Analysis, in which the organisation will determine recovery priorities, establish recovery objectives, and develop practical continuity strategies for each Critical Business Function.
| eBook 3: Starting Your BCM Implementation |
||||||
| MBCO | P&S | RAR T1 | RAR T2 | RAR T3 | BCS T1 | CBF |
To learn more about the course and schedule, click the buttons below for the BCM-300 Business Continuity Management Implementer [BCM-3] and the BCM-5000 Business Continuity Management Expert Implementer [BCM-5].
|
Please feel free to send us a note if you have any questions. |
||