Ebook

[BCM] [Damanat] [E3] [RAR] [T3] Risk Impact and Likelihood Assessment

Written by Dr Goh Moh Heng | Jul 20, 2026, 2:29:40 PM

 

Introduction

 

Following the identification of credible threats in Part 1: RAR – List of Threats and the evaluation of preventive, detective and corrective controls in Part 2: RAR – Treatment and Control, the next stage of the Risk Analysis and Review (RAR) process is to evaluate the residual business risk posed by each threat.

This chapter provides a structured assessment of the potential impact and likelihood of each approved threat affecting The Saudi Mortgage Guarantees Services Company (Damanat).

The objective is to establish a consistent and transparent assessment of current risk exposure, enabling management to prioritise Business Continuity Management (BCM) initiatives, determine continuity strategies and allocate resources appropriately.

For the purposes of this assessment, the risk evaluation is performed after considering the effectiveness of the existing controls identified in RAR Part 2, but before implementing any additional recommended controls or future improvement initiatives.

Consequently, the results represent the organisation's current residual risk profile, which should subsequently be validated by the respective business owners, risk owners and senior management.

The assessment follows recognised Business Continuity Management and Enterprise Risk Management principles, consistent with ISO 22301, ISO 22313, ISO 31000, and ISO 31010, while remaining suitable for organisations operating in the financial services sector in the Kingdom of Saudi Arabia.

 

Assessment Objectives

The Risk Impact and Likelihood Assessment has several important objectives:

  • evaluate the current exposure of Damanat to each approved threat;
  • determine the potential severity of business disruption should a threat materialise;
  • establish a consistent basis for prioritising Business Continuity planning activities;
  • identify threats requiring additional mitigation or recovery strategies;
  • support Business Impact Analysis (BIA) by understanding credible disruption scenarios;
  • facilitate informed decision-making by senior management; and
  • provide documented evidence supporting regulatory and governance requirements.

The assessment is not intended to predict future incidents. Rather, it provides a structured estimate of credible business risks based on current operating conditions, existing controls and professional judgement.

 

Assessment Basis

The assessment presented in this chapter is based on the following assumptions:

  • the approved threat register developed in RAR Part 1;
  • the existing treatment measures and controls documented in RAR Part 2;
  • Damanat's current organisational structure;
  • current operating environment within the Kingdom of Saudi Arabia;
  • publicly recognised financial-sector threats;
  • reasonable assumptions regarding mortgage guarantee operations where detailed internal information is unavailable.

The assessment represents current residual risk after considering existing controls.

It does not represent:

  • inherent risk before controls; or
  • future residual risk after planned improvements.

Final risk ratings should be reviewed and approved by business owners and the organisation's Risk Management Committee.

 

Approved Threat Coverage

The approved threats collectively address all major Business Continuity disruption categories.

 

Threat Category

Typical Approved Threats

Denial of Access – Natural Disaster

Flood, Severe Storm

Denial of Access – Man-made Disaster

Fire, Building Access Restriction

Unavailability of People

Pandemic, Loss of Key Personnel

Supply Chain Disruption

Critical Supplier Failure

Equipment and IT Disruption

Power Failure, Telecommunications Failure, Application Failure, Data Centre Outage, Cyberattack, Ransomware

The detailed assessment continues to use the specific threat names rather than the broader categories.

 

Risk Impact Assessment Methodology

Each threat is assessed against seven impact areas.

 

Impact Area

Description

Finance

Financial loss, recovery expenditure,  contractual obligations, and operational costs.

Operations

Disruption to critical mortgage guarantee services and supporting operations.

Legal and Regulatory

Failure to comply with applicable legal, contractual or regulatory obligations.

Reputation and Image

Loss of confidence among stakeholders, government agencies and financial institutions.

Social Responsibility

Effects on market confidence and Damanat's ability to support the national housing finance ecosystem.

People

Injury, illness, workforce availability, leadership disruption and staff welfare.

Assets, IT Systems and Information

Damage to facilities, ICT services, applications, information assets and vital records.

Each impact area is scored using the following five-point scale.

 

Score

Rating

1

Very Low - Insignificant

2

Low - Minor

3

Moderate

4

High - Major

5

Very High - Severe

 

Likelihood Assessment Methodology

Likelihood estimates consider:

  • historical industry experience;
  • current threat intelligence;
  • operating environment;
  • exposure of business processes;
  • effectiveness of existing controls;
  • dependency upon suppliers;
  • maturity of ICT controls;
  • cybersecurity threat landscape; and
  • environmental and geopolitical factors.

 

Score

Likelihood

1

Very Low - Rare

2

Low - Unlikely

3

Moderate - Possible

4

High - Likely

5

Very High - Almost Certain

Likelihood is assessed independently from impact.

 

Risk Rating Methodology

The overall Risk Rating is calculated using the following formula:

Risk Rating = Highest Impact Score × Likelihood Score

The resulting Risk Level is determined using the following matrix.

Risk Rating

Risk Level

1–4

Low

5–9

Moderate

10–16

High

17–25

Extreme

Where multiple impact areas receive the same highest score, all applicable impact areas should be identified.

 

Expected Disruption Period

For each threat, an indicative disruption period is estimated after considering existing controls.

This estimate reflects:

  • expected interruption duration;
  • restoration complexity;
  • supplier dependency;
  • alternate workplace arrangements;
  • ICT disaster recovery capability;
  • availability of replacement resources; and
  • external agency response.

The disruption period should not be confused with either the Recovery Time Objective (RTO) or the Maximum Tolerable Period of Disruption (MTPD), both of which will be established during the Business Impact Analysis.

 

Risk Impact and Likelihood Assessment

The following table provides an illustrative implementation assessment based on recognised financial-sector threats and should be validated against the approved threat register and existing controls documented in RAR Parts 1 and 2.

Table T3: Risk Impact and Likelihood Assessment 

Threat

Finance

Operations

Legal & Regulatory

Reputation & Image

Social Responsibility

People

Assets / IT Systems / Information

Highest Impact Score

Likelihood

Risk Rating

Risk Level

Expected Period of Disruption

Earthquake 4 5 4 4 3 5 5 Operations, People, Assets/IT (5) 2 10 High 1–2 weeks
Flash Flood 3 4 3 3 2 3 4 Operations, Assets/IT (4) 2 8 Moderate 3–7 days
Severe Sandstorm 2 3 2 2 2 2 3 Operations, Assets/IT (3) 4 12 High 8–24 hours
Extreme Heat 3 3 2 2 2 3 4 Assets/IT (4) 4 16 High 8–24 hours
Pandemic 4 5 4 4 4 5 2 Operations, People (5) 3 15 High More than 1 month
Fire 4 5 4 4 3 5 5 Operations, People, Assets/IT (5) 2 10 High 1–2 weeks
Explosion 4 5 4 4 3 5 5 Operations, People, Assets/IT (5) 1 5 Moderate 1–2 weeks
Hazardous Material Release 3 4 3 3 3 4 3 People (4) 2 8 Moderate 1–3 days
Civil Disturbance 2 3 2 3 2 2 2 Operations, Reputation (3) 2 6 Moderate 1–3 days
Terrorist Incident 4 5 4 5 4 5 5 Operations, Reputation, People, Assets/IT (5) 1 5 Moderate 1–2 weeks
Building Access Restriction 3 4 3 3 2 3 2 Operations (4) 3 12 High 1–3 days
Loss of Key Personnel 3 4 3 3 2 4 2 Operations, People (4) 3 12 High 1–2 weeks
Industrial Action 2 3 2 2 2 3 1 Operations, People (3) 2 6 Moderate 3–7 days
High Staff Absenteeism 2 4 2 2 2 4 1 Operations, People (4) 3 12 High 1–2 weeks
Skills Shortage 2 4 3 3 2 3 1 Operations (4) 3 12 High More than 1 month
Human Error 3 4 3 3 2 2 3 Operations (4) 4 16 High 4–24 hours
Critical Supplier Failure 4 5 4 4 3 2 3 Operations (5) 3 15 High 3–7 days
Cloud Service Provider Outage 4 5 4 4 2 2 5 Operations, Assets/IT (5) 3 15 High 1–3 days
Telecommunications Failure 3 5 3 3 2 2 5 Operations, Assets/IT (5) 3 15 High 4–24 hours
Internet Service Provider Failure 3 4 3 3 2 2 5 Assets/IT (5) 3 15 High 4–24 hours
Credit Bureau Service Failure 3 4 3 3 2 1 2 Operations (4) 3 12 High 1–3 days
Banking Partner System Failure 4 5 4 4 2 1 3 Operations (5) 3 15 High 1–3 days
Outsourced ICT Support Failure 3 4 3 3 2 2 4 Operations, Assets/IT (4) 3 12 High 1–3 days
Commercial Power Failure 3 5 3 3 2 2 5 Operations, Assets/IT (5) 3 15 High 4–24 hours
HVAC Failure 2 3 2 2 1 1 4 Assets/IT (4) 3 12 High 8–24 hours
Network Failure 3 5 3 3 2 1 5 Operations, Assets/IT (5) 3 15 High 4–24 hours
Data Centre Outage 4 5 4 4 2 1 5 Operations, Assets/IT (5) 3 15 High 1–3 days
Core Mortgage Guarantee System Failure 4 5 4 4 2 1 5 Operations, Assets/IT (5) 3 15 High 8–24 hours
Database Failure 4 5 4 4 2 1 5 Operations, Assets/IT (5) 3 15 High 8–24 hours
Identity and Access Management Failure 3 4 4 4 2 1 5 Assets/IT (5) 3 15 High 4–24 hours
Backup Failure 3 5 4 4 2 1 5 Operations, Assets/IT (5) 2 10 High 1–3 days
Storage System Failure 3 4 3 3 2 1 5 Assets/IT (5) 3 15 High 8–24 hours
Ransomware Attack 5 5 5 5 3 2 5 Finance, Operations, Legal, Reputation, Assets/IT (5) 4 20 Extreme 2–4 weeks
Malware Infection 3 4 3 3 2 1 5 Assets/IT (5) 4 20 Extreme 1–3 days
Phishing Attack 3 4 4 4 2 2 4 Legal, Reputation, Assets/IT (4) 4 16 High 4–24 hours
Business Email Compromise 5 3 4 4 2 1 4 Finance (5) 3 15 High 1–3 days
Distributed Denial-of-Service (DDoS) Attack 3 5 3 4 2 1 5 Operations, Assets/IT (5) 3 15 High 8–24 hours
Insider Cyber Threat 4 4 5 5 2 2 5 Legal, Reputation, Assets/IT (5) 3 15 High 1–2 weeks
Data Breach 5 4 5 5 3 2 5 Finance, Legal, Reputation, Assets/IT (5) 3 15 High 2–4 weeks
Loss of Physical Records 3 4 4 3 2 1 4 Legal, Operations, Assets/IT (4) 2 8 Moderate 3–7 days
Electronic Record Corruption 3 4 4 3 2 1 5 Assets/IT (5) 3 15 High 1–3 days
Data Integrity Failure 3 4 4 3 2 1 4 Legal, Operations, Assets/IT (4) 3 12 High 1–3 days
Fraudulent Mortgage Applications 5 4 5 5 3 1 3 Finance, Legal, Reputation (5) 3 15 High 1–3 days
Internal Fraud 5 4 5 5 2 2 3 Finance, Legal, Reputation (5) 3 15 High 1–2 weeks
Financial Market Instability 5 4 3 3 3 1 2 Finance (5) 3 15 High More than 1 month
Regulatory Change 3 4 5 4 2 1 2 Legal & Regulatory (5) 4 20 Extreme 1–3 months
Regulatory Investigation 4 4 5 5 2 2 2 Legal & Regulatory, Reputation (5) 2 10 High 1–3 months
Legal Proceedings 5 3 5 4 2 1 2 Finance, Legal (5) 2 10 High More than 1 month
Physical Intrusion 3 3 3 3 2 3 4 Assets/IT (4) 2 8 Moderate 1–3 days
Theft 3 2 2 2 1 1 3 Finance, Assets/IT (3) 3 9 Moderate 1–3 days
Vandalism 2 2 2 2 1 1 3 Assets/IT (3) 2 6 Moderate 1–3 days
Process Failure 4 5 4 4 2 2 3 Operations (5) 3 15 High 1–3 days
Manual Workaround Failure 3 4 3 3 2 2 3 Operations (4) 3 12 High 1–3 days
Inadequate Business Continuity Planning 4 5 4 4 3 3 3 Operations (5) 3 15 High More than 1 month
Inadequate Crisis Management 4 5 4 5 3 3 2 Operations, Reputation (5) 3 15 High More than 1 month
Failure of Disaster Recovery Arrangements 4 5 4 4 2 2 5 Operations, Assets/IT (5) 3 15 High 1–2 weeks
Negative Media Coverage 3 2 2 5 3 1 1 Reputation (5) 3 15 High 1–3 months
Social Media Misinformation 2 2 2 4 3 1 1 Reputation (4) 4 16 High 1–3 weeks
Service Delivery Failure 4 5 4 4 3 2 2 Operations (5) 3 15 High 1–3 days
Governance Failure 4 4 5 5 2 2 2 Legal & Regulatory, Reputation (5) 2 10 High More than 1 month
Poor Change Management 3 4 4 3 2 2 4 Operations, Legal, Assets/IT (4) 3 12 High 1–3 days
Third-Party Concentration Risk 4 5 3 4 2 1 3 Operations (5) 3 15 High 1–2 weeks
Simultaneous Multiple Disruptions 5 5 5 5 5 5 5 All Impact Areas (5) 2 10 High More than 1 month

 

Overall Assessment

The assessment indicates that Damanat's highest residual risks are associated with disruptions affecting information technology, cybersecurity and critical business applications.

These threats have the potential to interrupt mortgage guarantee operations, affect regulatory reporting, delay customer services and impact relationships with financial institutions.

Business disruptions arising from workforce unavailability and critical third-party failures also pose significant operational challenges, as many mortgage guarantee processes depend on specialist expertise, external service providers, and secure digital platforms.

Although natural hazards generally have a lower likelihood in the Kingdom of Saudi Arabia than cyber-related threats, they remain credible scenarios that should be incorporated into continuity planning due to their potential impact on facilities, staff accessibility, and operational resilience.

The assessment further demonstrates that many risks can be significantly reduced through strong governance, resilient ICT architecture, effective incident response procedures, supplier resilience arrangements, workforce succession planning and regular Business Continuity exercises.

 

Validation Requirements

The indicative assessment contained within this chapter should be validated through structured workshops involving:

  • Executive Management;
  • Enterprise Risk Management;
  • Business Continuity Management;
  • Information Technology;
  • Information Security;
  • Human Resources;
  • Facilities Management;
  • Procurement;
  • Legal and Compliance; and
  • representatives from each Critical Business Function.

During validation, participants should confirm:

  • impact scores;
  • likelihood estimates;
  • effectiveness of existing controls;
  • disruption duration assumptions;
  • risk ratings;
  • ownership of risks; and
  • priority improvement initiatives.

Any amendments approved during these workshops should be reflected in the final Risk Assessment Report before progressing to the Business Impact Analysis phase.

 

The Risk Impact and Likelihood Assessment transforms the approved threat register into a structured evaluation of Damanat's current residual risk profile.

By consistently assessing the potential business consequences and probability of each threat after considering existing controls, management can identify priority risks that require enhanced resilience measures and continuity planning.

The validated risk ratings developed in this chapter provide essential input to the subsequent Business Impact Analysis, in which the organisation will determine recovery priorities, establish recovery objectives, and develop practical continuity strategies for each Critical Business Function.

 

eBook 3: Starting Your BCM Implementation
MBCO P&S RAR T1 RAR T2 RAR T3 BCS T1  CBF

 

 

More Information About Business Continuity Management Courses

To learn more about the course and schedule, click the buttons below for the  BCM-300 Business Continuity Management Implementer [BCM-3] and the BCM-5000 Business Continuity Management Expert Implementer [BCM-5].

 

Please feel free to send us a note if you have any questions.