Ebook

[BCM] [Damanat] [E2] [C4] [P7] Business Impact Analysis

Written by Dr Goh Moh Heng | Jul 20, 2026 9:46:47 AM

eBook 2: Chapter 4: Part 7

 Implementing the Business Impact Analysis Phase in the Saudi Mortgage Guarantees Services Company BCM Planning Methodology 

 

 

Introduction


This chapter will cover:

  • Part 22: Conducting the Business Impact Analysis.

  • Part 23: Business Impact Analysis Interview Questions.

  • Part 24: Business Impact Analysis Quality Assurance and Validation.

  • Part 25: Common Business Impact Analysis Weaknesses.

  • Part 26: Business Impact Analysis Deliverables.

  • Part 27: Business Impact Analysis Implementation Roadmap.

  • Part 28: Maintaining and Reviewing the Business Impact Analysis.

  • Chapter Conclusion.

Part 22: Conducting the Business Impact Analysis

The Business Impact Analysis (BIA) should be conducted as a structured, collaborative process involving business owners, operational managers, subject-matter experts, and supporting corporate functions.

The objective is not merely to complete questionnaires, but to develop a shared understanding of how disruptions affect Damanat's ability to achieve its strategic objectives, fulfil its regulatory obligations and maintain essential mortgage guarantee services.

The quality of the BIA depends on active participation, objective analysis, and management validation rather than on assumptions or historical practice.

The BCM Manager should coordinate the entire exercise, ensuring that all participants understand the purpose, methodology, terminology and expected outputs before assessments begin.

 

Recommended Business Impact Analysis Process

The following methodology provides a structured approach for conducting the BIA across Damanat.

Step 1 – Confirm Assessment Scope

Before commencing the assessment, confirm:

  • Approved BCM scope.
  • Critical Business Function (CBF) catalogue.
  • Business unit responsibilities.
  • Assessment schedule.
  • Participants.
  • Required documentation.
  • Assessment assumptions.

This ensures all participants evaluate the same organisational boundaries.

Step 2 – Conduct Business Unit Interviews

Structured interviews should be conducted with:

  • CBF Owners.
  • Department Managers.
  • Process Owners.
  • ICT Representatives.
  • Risk Management.
  • Compliance.
  • Finance.
  • Human Resources.
  • Facilities.
  • Procurement.
  • Information Security.

Interview discussions should be supported by documented evidence wherever possible.

Step 3 – Review Supporting Documentation

The assessment should reference:

  • Organisation charts.
  • Process maps.
  • Standard Operating Procedures.
  • Service Level Agreements.
  • Regulatory requirements.
  • ICT architecture.
  • Previous incident reports.
  • Audit findings.
  • Risk Assessment results.
  • Existing Business Continuity Plans.
Step 4 – Assess Business Impacts

Each CBF and Sub-CBF should be evaluated against the approved impact categories:

  • Financial.
  • Operational.
  • Regulatory.
  • Legal.
  • Reputation.
  • Stakeholder confidence.
  • Public interest.
  • Technology.
  • People.

The assessment should consider impacts over progressively longer periods of disruption.

Step 5 – Determine Recovery Requirements

For each CBF, determine:

  • Maximum Tolerable Period of Disruption (MTPD).
  • Recovery Time Objective (RTO).
  • Recovery Point Objective (RPO).
  • Minimum Business Continuity Objective (MBCO).
  • Minimum staffing.
  • Technology requirements.
  • Facility requirements.
  • Information requirements.
  • Internal dependencies.
  • External dependencies.
Step 6 – Validate Assessment Results

The BCM Manager should review all submissions for:

  • Consistency.
  • Completeness.
  • Reasonableness.
  • Alignment with organisational objectives.
  • Consistency across departments.
  • Compliance with approved methodology.

Any discrepancies should be resolved with business owners before management approval.

Step 7 – Obtain Management Approval

The completed BIA should be presented to Senior Management for approval.

Approval should confirm:

  • Recovery priorities.
  • Recovery objectives.
  • Resource requirements.
  • Organisational assumptions.
  • Identified improvement initiatives.

Only approved BIA outputs should be used to develop Business Continuity Strategies.

Part 23: Business Impact Analysis Interview Questions

Structured interviews form the foundation of an effective Business Impact Analysis. The questions should encourage discussion rather than simple yes-or-no responses and should help business owners identify operational realities, dependencies and recovery requirements.

Organisation and Business Activities
  • What is the purpose of this Critical Business Function?
  • Which organisational objectives does it support?
  • Which stakeholders depend upon this function?
  • What products or services are delivered?
  • Which activities are time-critical?
  • Which activities may be temporarily deferred?
Business Process
  • Describe the end-to-end workflow.
  • What are the major decision points?
  • Which activities require management approval?
  • Which processes are completely dependent on technology?
  • Which processes can be performed manually?
Business Impacts
  • What happens if this function stops for four hours?
  • What changes after one day?
  • When do impacts become unacceptable?
  • What regulatory obligations would be affected?
  • Which stakeholders would be impacted first?
Resource Requirements
  • What minimum staffing is required?
  • Which specialist competencies are essential?
  • What ICT systems are required?
  • Which facilities are necessary?
  • Which vital records must remain available?
Dependencies
  • Which internal departments support this function?
  • Which external organisations are essential?
  • Are there single points of failure?
  • Are alternative suppliers available?
Recovery
  • What minimum level of service can be maintained?
  • How much backlog accumulates?
  • How long would backlog recovery require?
  • What manual workarounds exist?
  • What improvements would significantly increase resilience?
Improvement Opportunities
  • Which risks concern you most?
  • Which investments would improve recovery?
  • Which procedures require revision?
  • Which recovery exercises would be most valuable?
  • What lessons have been learned from previous disruptions?

Part 24: Business Impact Analysis Quality Assurance and Validation

The credibility of the Business Impact Analysis depends upon the quality of its underlying information.

Quality assurance ensures that recovery objectives are realistic, evidence-based and consistently applied across the organisation.

Validation also provides confidence that the outputs can be relied upon when developing Business Continuity Strategies and Plans.

The BCM Manager should coordinate a formal quality review before presenting the BIA for management approval.

Table BIA 4.17: Business Impact Analysis Validation Checklist

Validation Area

Review Question

Responsible Party

Validation Status

Scope

Are all approved CBFs included?

BCM Manager

Ownership

Has every CBF Owner approved the assessment?

Business Owners

Impacts

Are impact assessments consistent?

BCM Team

Recovery Objectives

Are MTPDs, RTOs and RPOs justified?

Senior Management

Dependencies

Have internal and external dependencies been validated?

Business Units

Resources

Are staffing and technology requirements realistic?

Functional Managers

Information

Are vital records identified?

Records Management

ICT

Are system recovery capabilities aligned?

ICT

Suppliers

Have critical supplier dependencies been confirmed?

Procurement

Approval

Has Executive Management approved the completed BIA?

Executive Management

Validation Principles

The review should ensure that:

  • All assumptions are documented.
  • Recovery objectives are evidence-based.
  • Resource requirements are achievable.
  • Technology capabilities support business recovery targets.
  • Dependencies are complete and accurate.
  • Business owners accept accountability for their assessments.
  • Executive Management formally approves the completed BIA.

Part 25: Common Business Impact Analysis Weaknesses

Many organisations complete a BIA as a compliance exercise rather than a management decision-making process.

This often results in recovery objectives that are unrealistic, inconsistent or unsupported by evidence.

Recognising these common weaknesses enables Damanat to produce a more robust and actionable Business Impact Analysis.

Table BIA 4.18: Common Weaknesses and Recommended Improvements

 

Common Weakness

Potential Consequence

Recommended Improvement

All functions classified as critical

Recovery priorities become meaningless

Differentiate priorities objectively

RTOs based on technology capability

Business needs are not reflected

Base RTOs on business impact

Insufficient management involvement

Limited organisational ownership

Increase executive participation

Incomplete dependency analysis

Recovery failures

Map end-to-end dependencies

Limited supplier assessment

Third-party failures overlooked

Include supplier resilience reviews

Lack of evidence

Inaccurate recovery objectives

Validate with operational data

Failure to review BIA

Outdated recovery requirements

Schedule periodic reviews

Excessive optimism

Recovery plans fail during incidents

Validate through exercising

No backlog analysis

Recovery period underestimated

Include backlog modelling

No linkage to Business Continuity Strategy

Poor continuity planning

Use BIA outputs as mandatory strategy inputs

Lessons Learned

An effective BIA should:

  • Be owned by business management.
  • Use consistent assessment criteria.
  • Be supported by objective evidence.
  • Be reviewed regularly.
  • Drive recovery strategy decisions.
  • Be validated through exercises and real incidents.

Part 26: Business Impact Analysis Deliverables

Upon completion of the BIA, Damanat should possess a comprehensive set of approved deliverables that support subsequent Business Continuity Strategy development and Business Continuity Plan preparation.

Table BIA 4.19: Expected BIA Deliverables

 

Deliverable

Purpose

Primary User

Approved CBF Catalogue

Enterprise recovery priorities

Senior Management

Sub-CBF Register

Process-level recovery planning

Business Units

Impact Assessments

Recovery prioritisation

BCM Team

MTPD Register

Disruption tolerance

Executive Management

RTO Register

Recovery planning

ICT & BCM

RPO Register

Data recovery planning

ICT

MBCO Register

Minimum service delivery

Business Owners

Dependency Registers

Recovery sequencing

BCM Team

Minimum Resource Register

Resource planning

Functional Managers

BIA Report

Management approval

Executive Management

Part 27: Business Impact Analysis Implementation Roadmap

The implementation of the BIA should follow a phased approach that allows Damanat to progressively build organisational capability while ensuring stakeholder engagement and management oversight.

 

Phase

Key Activities

Primary Deliverables

Phase 1 – Preparation

Confirm scope, governance, and methodology

Approved BIA framework

Phase 2 – Data Collection

Conduct interviews and workshops

Completed assessment templates

Phase 3 – Analysis

Evaluate impacts, dependencies and recovery requirements

Draft BIA report

Phase 4 – Validation

Quality assurance and management review

Validated BIA

Phase 5 – Approval

Executive endorsement

Approved BIA

Phase 6 – Integration

Develop Business Continuity Strategies and Plans

Recovery strategies and BCPs

Phase 7 – Maintenance

Periodic review and continuous improvement

Updated BIA documentation

Part 28: Maintaining and Reviewing the Business Impact Analysis

The Business Impact Analysis is a living management document and should be reviewed regularly to ensure it continues to reflect

Damanat's organisational structure, products, services, technologies and regulatory obligations.

Changes to the business environment may invalidate recovery assumptions and require revisions to recovery objectives.

The BIA should be reviewed:

  • At least annually.
  • Following significant organisational restructuring.
  • Following the introduction of new products or services.
  • After major technology changes.
  • Following significant regulatory changes.
  • After major incidents or exercises.
  • Following mergers, acquisitions or outsourcing.
  • Whenever management determines that recovery priorities have changed.

The review process should confirm:

  • Recovery objectives remain appropriate.
  • Critical Business Functions remain current.
  • Dependencies remain accurate.
  • Recovery resources remain adequate.
  • Lessons learned have been incorporated.
  • Recovery strategies continue to support business requirements.

The Business Impact Analysis is the analytical foundation of Damanat's Business Continuity Management programme.

By systematically identifying Critical Business Functions, assessing the consequences of disruption, analysing dependencies and establishing management-approved recovery objectives, the organisation gains a clear understanding of the operational capabilities required to continue delivering essential mortgage guarantee services during disruptive events.

More importantly, the BIA transforms continuity planning from a compliance activity into a strategic management process that aligns resilience investments with business priorities and regulatory expectations.

The approved outputs of the BIA—including the MTPD, RTO, RPO, MBCO, dependency analysis and minimum resource requirements—provide the evidence base for the next phase of the BCM Planning Methodology: the development of Business Continuity Strategies.

In that phase, Damanat will determine how these recovery requirements can be met through appropriate people, facilities, technology, supplier arrangements, and operational recovery solutions, ensuring that its resilience capability remains practical, proportionate, and aligned with its role in supporting Saudi Arabia's housing finance ecosystem.

 

P0 P1 P2 P3 P4 P5 P6 P7

 

More Information About Business Continuity Management Courses

To learn more about the course and schedule, click the buttons below for the  BCM-300 Business Continuity Management Implementer [BCM-3] and the BCM-5000 Business Continuity Management Expert Implementer [BCM-5].

 

Please feel free to send us a note if you have any questions.