This chapter is the 6th instalment of the BIA planning process and will cover:
Part 18: External Dependency Assessment
Part 19: Facility and Recovery-Location Requirements
Part 20: Manual Workaround Assessment
Part 21: Backlog and Catch-Up Assessment
In addition to internal dependencies, every Critical Business Function relies upon external organisations that provide products, services or infrastructure necessary for Damanat to continue operating.
The Business Impact Analysis (BIA) should therefore identify these external dependencies, evaluate their criticality and determine the potential consequences if they become unavailable during a disruption.
Effective management of third-party dependencies strengthens organisational resilience and supports the development of an informed Business Continuity Strategy.
When identifying external dependencies, Damanat should consider:
For each dependency, Damanat should determine:
|
Critical Business Function |
External Dependency |
Service Provided |
Dependency Criticality |
Consequence of Failure |
Existing Mitigation |
Recommended Improvement |
|---|---|---|---|---|---|---|
|
CBF-1 Mortgage Guarantee Origination |
Participating Financial Institutions |
Mortgage application submission |
Critical |
Applications cannot be received or processed |
Multiple participating institutions |
Periodic resilience reviews |
|
CBF-1 Mortgage Guarantee Origination |
Credit Bureau |
Credit information |
Critical |
Underwriting delayed |
Alternative credit verification |
Secondary data source |
|
CBF-2 Guarantee Risk Assessment |
Property Valuation Firms |
Property valuations |
High |
Risk assessments delayed |
Approved valuation panel |
Expand valuation panel |
|
CBF-3 Guarantee Issuance & Administration |
Digital Certificate Provider |
Electronic certification |
High |
Guarantee issuance delayed |
Existing contract |
Secondary certificate provider |
|
CBF-4 Claims Assessment |
Banking Partners |
Claims settlement |
Critical |
Payment delays |
Multiple banking arrangements |
Periodic payment contingency testing |
|
CBF-5 Financial & Treasury Management |
Commercial Banks |
Treasury and payment services |
Critical |
Liquidity management affected |
Multiple banking relationships |
Enhanced contingency procedures |
|
CBF-7 Regulatory Compliance |
SAMA & Insurance Authority Portals |
Regulatory submissions |
Critical |
Delayed reporting |
Manual submission procedures |
Alternative reporting channels |
|
CBF-8 Information Technology Services |
Cloud Service Provider |
Hosting and infrastructure |
Critical |
ICT service interruption |
Disaster Recovery environment |
Multi-region architecture |
|
CBF-8 Information Technology Services |
Telecommunications Provider |
Network connectivity |
Critical |
Enterprise communications disrupted |
Dual communication links |
Additional provider diversity |
|
CBF-9 Information Security |
Cybersecurity Managed Service Provider |
Threat monitoring |
High |
Reduced cyber visibility |
Internal monitoring capability |
Secondary monitoring provider |
|
CBF-13 Procurement |
Strategic Suppliers |
Critical goods and services |
Medium |
Delayed procurement |
Approved supplier list |
Supplier BCM assessments |
|
CBF-15 BCM & Crisis Management |
Emergency Response Agencies |
Incident coordination |
High |
Slower emergency response |
Existing liaison arrangements |
Joint exercising programme |
External dependency analysis should extend beyond identifying suppliers. Damanat should also assess each critical supplier's resilience by considering:
Critical suppliers should be incorporated into Damanat's Third-Party Risk Management and Business Continuity programmes.
The ability to recover critical business operations depends on the availability of suitable facilities where authorised personnel can perform essential activities.
The Business Impact Analysis should therefore identify the minimum requirements for the workplace, infrastructure, and recovery location necessary to achieve the approved Minimum Business Continuity Objectives (MBCOs).
Facility planning should address:
|
Critical Business Function |
Normal Workplace |
Recovery Location |
Minimum Workspace Requirement |
Special Facility Requirements |
Remote Working Suitable |
Priority |
|---|---|---|---|---|---|---|
|
CBF-1 Mortgage Guarantee Origination |
Head Office |
Alternate Recovery Site |
10 workstations |
Secure access, dual monitors |
Yes |
Critical |
|
CBF-2 Guarantee Risk Assessment |
Head Office |
Alternate Recovery Site |
5 workstations |
Access to risk systems |
Yes |
High |
|
CBF-3 Guarantee Issuance |
Head Office |
Recovery Office |
5 workstations |
Secure printing and scanning |
Partial |
High |
|
CBF-4 Claims Assessment |
Head Office |
Recovery Office |
5 workstations |
Secure payment facilities |
Partial |
High |
|
CBF-5 Finance |
Head Office |
Finance Recovery Area |
4 workstations |
Banking connectivity |
Partial |
High |
|
CBF-7 Compliance |
Head Office |
Remote Working |
3 workstations |
Secure regulatory access |
Yes |
Medium |
|
CBF-8 ICT Services |
Data Centre / ICT Office |
DR Site |
ICT Operations Room |
Server access |
Limited |
Critical |
|
CBF-9 Information Security |
Security Operations Centre |
Backup SOC |
Security Monitoring Centre |
Continuous monitoring |
Limited |
Critical |
|
CBF-10 Relationship Management |
Head Office |
Remote Working |
4 workstations |
CRM access |
Yes |
Medium |
|
CBF-14 Corporate Communications |
Head Office |
Crisis Communication Room |
Communications Centre |
Media facilities |
Yes |
High |
|
CBF-15 BCM & Crisis Management |
Crisis Management Centre |
Alternate Crisis Command Centre |
Executive meeting room |
Situation display, communications |
No |
Critical |
Recovery facilities should provide:
The selection of recovery facilities should align with the approved Business Continuity Strategy and be periodically validated through recovery exercises.
Although technology plays a central role in Damanat's operations, many critical activities can continue temporarily through manual procedures when automated systems are unavailable. The Business Impact Analysis should identify these manual workarounds, evaluate their limitations and determine how long they can be sustained before business impacts become unacceptable.
Manual workarounds should never be regarded as permanent solutions. They are temporary measures intended to maintain essential operations until normal systems are restored.
|
Critical Business Function |
Manual Workaround Available |
Description |
Maximum Sustainable Duration |
Key Limitations |
Residual Risk |
|---|---|---|---|---|---|
|
CBF-1 Mortgage Guarantee Origination |
Yes |
Manual application registration and prioritisation |
24 Hours |
Limited processing capacity |
High |
|
CBF-2 Guarantee Risk Assessment |
Partial |
Manual credit assessment using available records |
24 Hours |
Reduced analytical capability |
High |
|
CBF-3 Guarantee Issuance |
Yes |
Manual preparation of guarantee documentation |
2 Days |
Slower processing |
Medium |
|
CBF-4 Claims Assessment |
Partial |
Manual claims logging and prioritisation |
2 Days |
Payment delays |
Medium |
|
CBF-5 Financial & Treasury Management |
Yes |
Manual payment authorisation and reconciliation |
3 Days |
Increased operational risk |
Medium |
|
CBF-7 Regulatory Compliance |
Yes |
Manual preparation of regulatory reports |
3 Days |
Greater administrative effort |
Medium |
|
CBF-8 Information Technology Services |
No |
Infrastructure restoration required |
Not Applicable |
No practical manual alternative |
Very High |
|
CBF-9 Information Security |
Partial |
Enhanced manual monitoring procedures |
12 Hours |
Reduced threat visibility |
Very High |
|
CBF-10 Relationship Management |
Yes |
Telephone and email communications |
5 Days |
Limited customer tracking |
Low |
|
CBF-14 Corporate Communications |
Yes |
Manual approval and distribution of communications |
5 Days |
Slower dissemination |
Low |
|
CBF-15 BCM & Crisis Management |
Yes |
Paper-based incident logs and manual situation reports |
Entire Incident |
Administrative burden |
Low |
While manual workarounds improve organisational resilience, they also introduce additional operational risks, including:
Accordingly, manual workarounds should be regularly tested and documented within Business Continuity Plans to ensure personnel understand how to implement them effectively.
Disruptions inevitably result in the accumulation of unprocessed work.
Even after critical services are restored, Damanat must manage the backlog of mortgage guarantee applications, risk assessments, claims, regulatory reports and administrative activities that accumulated during the outage.
The Business Impact Analysis should therefore estimate backlog growth, identify acceptable limits and determine the resources required to eliminate the backlog without compromising service quality or regulatory compliance.
|
Critical Business Function |
Typical Daily Volume (Illustrative) |
Backlog Growth During Disruption |
Maximum Acceptable Backlog |
Estimated Recovery Period |
Recommended Recovery Strategy |
|---|---|---|---|---|---|
|
CBF-1 Mortgage Guarantee Origination |
120 applications |
Approximately 120 applications per day |
360 applications |
3–5 days |
Extended operating hours and prioritisation |
|
CBF-2 Guarantee Risk Assessment |
100 assessments |
Approximately 100 assessments per day |
300 assessments |
3–5 days |
Additional risk analysts |
|
CBF-3 Guarantee Issuance |
80 guarantees |
Approximately 80 guarantees per day |
240 guarantees |
3 days |
Dedicated recovery team |
|
CBF-4 Claims Assessment |
30 claims |
Approximately 30 claims per day |
90 claims |
5 days |
Prioritise urgent claims |
|
CBF-7 Regulatory Compliance |
Variable |
Deadline-driven |
No missed statutory deadlines |
Immediately after restoration |
Priority regulatory reporting |
|
CBF-10 Relationship Management |
200 enquiries |
Approximately 200 enquiries per day |
600 enquiries |
2–3 days |
Temporary customer support resources |
To restore normal operations efficiently, Damanat should:
Effective backlog management ensures that recovery extends beyond system restoration to the timely resumption of normal service levels.
The next instalment will cover:
| P0 | P1 | P2 | P3 | P4 | P5 | P6 | P7 |
|
|
To learn more about the course and schedule, click the buttons below for the BCM-300 Business Continuity Management Implementer [BCM-3] and the BCM-5000 Business Continuity Management Expert Implementer [BCM-5].
|
Please feel free to send us a note if you have any questions. |
||