.

Implementing Business Continuity Management for The Saudi Mortgage Guarantees Services Company: An Enterprise Implementation Guide
BB-CAAS-E1-1

[BCM] [Damanat] [E2] [C4] [P5] Business Impact Analysis

[BCM] [Damanat] [Full Banner] Implementing BCM for The Saudi Mortgage Guarantees Services Company

This chapter is the 5th instalment of the BIA planning process and will cover:

  • Part 14: Minimum Personnel Requirements

  • Part 15: Supporting Technology Requirements

  • Part 16: Vital Records and Information Requirements

  • Part 17: Internal CBF Dependency Matrix

  • Part 18: External Dependency Assessment

  • Part 19: Facility and Recovery-Location Requirements

  • Part 20: Manual Workaround Assessment

New call-to-action

Dr Goh Moh Heng
Business Continuity Management Certified Planner-Specialist-Expert
Damanat Legal Disclaimer Banner

eBook 2: Chapter 4: Part 5

New call-to-action

[BCM] [Damanat] [Full Banner] Guide to Implementing Business Impact Analysis

 Implementing the Business Impact Analysis Phase in the Saudi Mortgage Guarantees Services Company BCM Planning Methodology 

 

Introduction

[BCM] [Damanat] [E2] [C4] [P5] Decomposing CBFs into Sub-CBFs
This chapter will cover:

  • Part 14: Minimum Personnel Requirements

  • Part 15: Supporting Technology Requirements

  • Part 16: Vital Records and Information Requirements

  • Part 17: Internal CBF Dependency Matrix

  • Part 18: External Dependency Assessment

  • Part 19: Facility and Recovery-Location Requirements

  • Part 20: Manual Workaround Assessment

Part 14: Identifying Minimum Personnel Requirements

People are the most critical resource in the successful recovery of any organisation.

Regardless of how resilient Damanat's facilities, technology and systems may be, business recovery cannot be achieved without competent personnel possessing the authority, skills and experience necessary to perform essential activities.

The Business Impact Analysis (BIA) should therefore determine not only the minimum number of staff required but also the competencies, delegated authorities and succession arrangements needed to sustain each Critical Business Function (CBF) during disruption.

When assessing personnel requirements, Damanat should consider:

  • Minimum staffing levels required to achieve the approved Minimum Business Continuity Objective (MBCO).
  • Specialist technical knowledge.
  • Delegated financial and operational approval authority.
  • Availability of alternate personnel.
  • Cross-training arrangements.
  • Segregation of duties.
  • Shift arrangements for prolonged incidents.
  • Staff welfare and fatigue management.
  • Remote-working suitability.
  • Maximum sustainable recovery staffing period.

The objective is to recover essential business capability rather than restore the full workforce immediately.

Table BIA 4.9: Minimum Personnel Requirements

Critical Business Function

Essential Roles

Indicative Minimum Staff

Alternate / Backup Roles

Specialist Competencies

Key Person Risk

Required Improvement

CBF-1 Mortgage Guarantee Origination

Mortgage Guarantee Officers, Team Leader

8

Cross-trained Operations Officers

Mortgage underwriting

Medium

Increase cross-training

CBF-2 Guarantee Risk Assessment

Risk Analysts

4

Senior Credit Officers

Financial risk modelling

High

Develop additional certified analysts

CBF-3 Guarantee Issuance & Administration

Guarantee Administrators

4

Operations Officers

Documentation management

Medium

Improve succession planning

CBF-4 Claims Assessment & Settlement

Claims Specialists

4

Senior Operations Officers

Claims evaluation

Medium

Cross-functional training

CBF-5 Financial & Treasury Management

Finance Manager, Treasury Officers

4

Senior Accountants

Treasury operations

Medium

Dual-authority coverage

CBF-6 Enterprise Risk Management

Enterprise Risk Manager

3

Compliance Officers

Enterprise risk management

High

Increase backup capability

CBF-7 Regulatory Compliance

Compliance Manager

3

Legal Officers

Regulatory reporting

Medium

Knowledge transfer programme

CBF-8 Information Technology Services

Infrastructure Engineers

5

Senior System Administrators

Infrastructure recovery

High

Expand technical succession

CBF-9 Information Security

Cybersecurity Analysts

4

ICT Security Engineers

Incident response

High

Continuous cyber training

CBF-10 Relationship Management

Relationship Managers

4

Customer Service Officers

Stakeholder engagement

Low

Cross-training

CBF-11 Legal & Corporate Governance

Legal Counsel

2

External Legal Adviser

Regulatory law

Medium

Panel legal support

CBF-12 Human Resource Management

HR Manager

2

HR Executives

Workforce mobilisation

Low

Update succession plan

CBF-13 Procurement & Vendor Management

Procurement Officers

2

Finance Officers

Emergency procurement

Low

Supplier continuity training

CBF-14 Corporate Communications

Communications Manager

2

Executive Assistant

Crisis communications

Medium

Media training

CBF-15 BCM & Crisis Management

BCM Manager

3

Deputy BCM Coordinator

BCM and crisis management

High

Additional BCM training

Competence Before Headcount

The BIA should recognise that recovery capability depends more on competence than on total staff numbers. A larger workforce without the appropriate knowledge, delegated authority or technical expertise may be less effective than a smaller, well-trained recovery team.

Accordingly, Damanat should ensure that:

  • Critical decision-making authority is delegated appropriately.
  • Specialist knowledge is documented.
  • Cross-training programmes are implemented.
  • Successors are identified for key positions.
  • Recovery teams participate regularly in BCM exercises.

Part 15: Identifying Supporting Technology Requirements

Nearly every Critical Business Function performed by Damanat depends on technology.

Consequently, the Business Impact Analysis should identify the ICT systems, applications and infrastructure necessary to support business recovery. Technology recovery priorities should always be derived from business recovery requirements rather than determined independently by ICT.

Technology dependency analysis should consider:

  • Business applications.
  • Databases.
  • Network infrastructure.
  • Internet connectivity.
  • Telecommunications.
  • Cloud services.
  • Identity and access management.
  • Multi-factor authentication.
  • Cybersecurity monitoring.
  • Backup and replication.
  • End-user devices.
  • Collaboration platforms.
  • Vendor support arrangements.
Table BIA 4.10: Supporting Technology Requirements

 

Critical Business Function

Supporting System / Technology

Business Use

Required Availability

Business RTO

Indicative System RTO

Indicative RPO

Manual Workaround

System Owner

CBF-1

Mortgage Guarantee Processing System

Application processing

Continuous

12 hrs

8 hrs

15 min

Limited

ICT

CBF-2

Risk Assessment Platform

Credit risk analysis

High

12 hrs

8 hrs

30 min

Partial

ICT

CBF-3

Document Management System

Guarantee documentation

High

24 hrs

12 hrs

30 min

Paper forms

ICT

CBF-4

Claims Management System

Claims processing

High

24 hrs

12 hrs

1 hr

Manual register

ICT

CBF-5

ERP & Financial System

Finance operations

High

24 hrs

12 hrs

15 min

Manual ledger

Finance/ICT

CBF-7

Regulatory Reporting System

Compliance reporting

High

24 hrs

12 hrs

1 hr

Spreadsheet reporting

Compliance

CBF-8

Network Infrastructure

Enterprise ICT

Critical

8 hrs

4 hrs

Near Zero

None

ICT

CBF-9

SIEM & SOC Platform

Cyber monitoring

Critical

4 hrs

2 hrs

Near Zero

Limited

Cybersecurity

CBF-10

CRM

Customer management

High

24 hrs

12 hrs

1 hr

Manual contact lists

ICT

CBF-15

Incident Management Platform

Crisis coordination

Critical

2 hrs

1 hr

15 min

Manual incident log

BCM

Technology Recovery Principles

The supporting technology assessment should demonstrate that:

  • Business priorities determine ICT priorities.
  • Critical systems are recovered before dependent applications.
  • Supporting infrastructure is restored before end-user services.
  • Technology recovery objectives are validated through Disaster Recovery testing.
  • Supplier service levels align with business recovery requirements.

Part 16: Identifying Vital Records and Information Requirements

Information is a critical organisational asset. Without access to accurate, complete and reliable information, Damanat would be unable to process mortgage guarantees, demonstrate regulatory compliance or make informed management decisions. The BIA should therefore identify the vital records required to support each CBF and define how they will be protected and recovered during disruption.

Vital records should be assessed according to:

  • Confidentiality.
  • Integrity.
  • Availability.
  • Retention requirements.
  • Evidential value.
  • Secure backup arrangements.
  • Version control.
  • Alternate access methods.
Table BIA 4.11: Vital Records and Information Requirements

 

Critical Business Function

Vital Record / Information

Format

Storage Location

Required Recovery Time

Minimum Version

Alternate Access Method

Record Owner

CBF-1

Mortgage Guarantee Applications

Electronic

EDMS

12 hrs

Current

Replicated storage

Operations

CBF-2

Risk Assessment Models

Electronic

Risk Repository

12 hrs

Current

DR Repository

Risk Management

CBF-3

Guarantee Register

Database

Production Database

24 hrs

Current

DR Database

Operations

CBF-4

Claims Files

Electronic

Claims Repository

24 hrs

Current

Backup Repository

Claims

CBF-5

Financial Records

Electronic

ERP

24 hrs

Current

Finance Backup

Finance

CBF-7

Regulatory Reports

Electronic

Compliance Repository

24 hrs

Current

Secure Archive

Compliance

CBF-8

System Configuration Documentation

Electronic

ICT Repository

8 hrs

Latest Approved

Offline Copy

ICT

CBF-9

Security Logs

Electronic

SIEM

4 hrs

Real-time

Secure Backup

Cybersecurity

CBF-15

BCM Documentation

Electronic

BCM Repository

2 hrs

Latest Approved

Printed Emergency Copy

BCM Office

Information Governance Considerations

Each vital record should have:

  • A designated owner.
  • Defined retention requirements.
  • Secure storage arrangements.
  • Recovery procedures.
  • Backup schedules.
  • Access controls.
  • Encryption where appropriate.
  • Periodic restoration testing.

Part 17: Identifying Internal Dependencies

No Critical Business Function operates independently.

The BIA should identify how business functions rely upon one another to deliver Damanat's services.

Understanding these internal dependencies enables management to identify shared resources, single points of failure and enterprise-wide recovery priorities.

Table BIA 4.12: Internal CBF Dependency Matrix

 

Dependent CBF

Supporting CBF

Nature of Dependency

Dependency Criticality

Required Availability

Consequence of Failure

Possible Workaround

CBF-1

CBF-8 ICT Services

Mortgage processing systems

Critical

Immediate

Processing stops

Limited manual intake

CBF-1

CBF-9 Information Security

Secure authentication

Critical

Immediate

Cyber risk

Temporary enhanced controls

CBF-2

CBF-5 Finance

Financial information

High

24 hrs

Incomplete assessments

Manual verification

CBF-3

CBF-8 ICT

Document management

High

12 hrs

Guarantee issuance delayed

Paper documentation

CBF-4

CBF-5 Finance

Payment processing

High

24 hrs

Claims delayed

Manual payment approval

CBF-7

CBF-11 Legal

Regulatory interpretation

Medium

48 hrs

Compliance uncertainty

External legal advice

CBF-15

CBF-14 Communications

Stakeholder communications

High

4 hrs

Delayed crisis communications

Alternative communication channels

Managing Internal Dependencies

Dependency analysis should identify:

  • Shared ICT platforms.
  • Shared personnel.
  • Shared facilities.
  • Shared suppliers.
  • Shared information repositories.
  • Shared approval authorities.

These shared dependencies often become enterprise-wide recovery priorities because disruptions affect multiple CBFs simultaneously.

Banner [Summary] [BCM] [E2] [C4] Business Impact Analysis

The next instalment will cover:

  • Part 18: External Dependency Assessment
  • Part 19: Facility and Recovery-Location Requirements
  • Part 20: Manual Workaround Assessment
  • Part 21: Backlog and Catch-Up Assessment

BL-OR-3-5 Blog Under Construction

[BCM] [Damanat] [3/4 Banner] Implementing BCM for The Saudi Mortgage Guarantees Services Company

P0 P1 P2 P3 P4 P5 P6 P7
[BCM] [Damanat] [E2] [C4] [P0] Introduction
[BCM] [Damanat] [E2] [C4] [P1] Position of BIA in the BCM Planning Methodology [BCM] [Damanat] [E2] [C4] [P2] Establishing the BIA Governance Structure [BCM] [Damanat] [E2] [C4] [P3] Defining the BIA Scope [BCM] [Damanat] [E2] [C4] [P4] Confirming the Critical Business Functions [BCM] [Damanat] [E2] [C4] [P5] Decomposing CBFs into Sub-CBFs [BCM] [Damanat] [E2] [C4] [P6] Identifying Product, Services and Outcomes [BCM] [Damanat] [E2] [C4] [P7] Identifying Impact Areas

 

More Information About Business Continuity Management Courses

To learn more about the course and schedule, click the buttons below for the  BCM-300 Business Continuity Management Implementer [BCM-3] and the BCM-5000 Business Continuity Management Expert Implementer [BCM-5].

New call-to-action  New call-to-action Register [BL-B-3]*
New call-to-action New call-to-action New call-to-action
FAQ [BL-B-3]

Please feel free to send us a note if you have any questions.

Email to Sales Team [BCM Institute]

 FAQ BL-B-5 BCM-5000
New call-to-action New call-to-action New call-to-action
 
 

 

Comments

More Posts

New Call-to-action