Unfortunately looking at just the business rules and procedures leaves the oft-hidden 'soft' requirements (the -ities) in the dust. Unless you explicitly state the corresponding requirements, having the business rules and procedures as your overriding concern will lead to pain. And explicitly stating a testable requirement for e.g. maintainability or security tends to be quite hard in practice.