Knowledge base

How to Conduct a Meaningful Business Impact Analysis (BIA)

The Business Impact Analysis (BIA) is the foundation of ISO 22301. It helps identify what is most important to the business and provides a clear, well-supported basis for the rest of the requirements.

Neha Dvivedi · 16 tháng 8, 2026

A Business Impact Analysis (BIA) is one of the most important parts of ISO 22301. It helps an organisation understand what could happen if important business activities are interrupted and how quickly they need to be restored.

A good BIA should be based on clear facts and evidence—not assumptions or opinions.

Step 1: Decide the Impact Criteria First

Before starting the analysis, agree with senior management on what types of impact will be measured and how they will be rated.

Common impact areas include:

• Financial losses

• Customer and contractual impact

• Legal and regulatory consequences

• Damage to reputation

• Health and safety, where applicable

Define each impact level clearly.

For example, saying "major financial loss" is not specific enough. Instead, define it with a measurable figure, such as "financial loss above ₹50 lakh."

Get management approval for these criteria before starting the BIA. If the criteria are decided later, they may be changed to support the conclusions already reached.

Step 2: Analyse Activities, Not Departments

Start with the products and services covered by the organisation and identify the activities required to deliver them.

Do not simply analyse departments such as HR, IT, Finance or Operations. Important business activities often involve multiple departments, and problems can occur when work moves from one team to another.

Keep the analysis at the right level:

• Too broad → everything may appear critical.

• Too detailed → the exercise becomes difficult to manage.

Step 3: Measure Impact Over Time

Instead of simply asking, "Is this activity critical?", ask:

"What happens if we cannot perform this activity for a specific period?"

For example, assess the impact after:

• 4 hours

• 1 day

• 3 days

• 1 week

• 1 month

The time periods should be adjusted according to your business.

For every time period, identify the actual consequence.

An activity may seem urgent but may have very little impact during the first 24 hours. On the other hand, an activity that appears routine may create a regulatory or contractual problem within just a few hours.

This approach makes the BIA evidence-based rather than based on personal opinions.

Step 4: Set Recovery Priorities and Timeframes

Use the impact assessment to determine:

• Which activities need to be restored first?

• How quickly do they need to be restored?

The recovery timeframe should be based on the point at which the impact becomes unacceptable according to the agreed criteria.

Document the reason behind each timeframe.

An auditor, customer or management team should be able to understand why a particular recovery time was selected.

Step 5: Identify Dependencies

For every priority activity, identify everything it needs to continue or recover.

This could include:

• People and key individuals

• Offices or other premises

• IT systems and information

• Equipment

• Suppliers and business partners

• Outsourced services

• Electricity, internet and other utilities

Be specific.

For example, writing "IT systems" is too general. Identify the actual application or system and explain what it depends on.

Step 6: Identify Concentration Risks

Now compare the dependencies across all priority activities.

Look for resources that are being used by several important activities.

For example:

• One supplier supporting several critical activities

• One IT application supporting multiple services

• One key employee responsible for several important processes

This creates a concentration risk. If that single resource becomes unavailable, several activities could be affected at the same time.

This step is often one of the most valuable parts of the BIA because these risks may not be visible when activities are analysed individually.

Step 7: Define Minimum Resources

For each priority activity, determine the minimum resources required to continue operating during a disruption.

Consider:

• Minimum number of employees

• Minimum IT systems

• Minimum facilities

• Minimum equipment

Remember that business continuity does not always mean operating at 100% capacity.

Define what an acceptable reduced level of service looks like. This can make continuity plans more practical and cost-effective.

Step 8: Validate the Results

Do not rely only on the people who completed the BIA.

Discuss the findings with:

• Sales and commercial teams

• Customer-facing employees

• Other relevant business teams

Ask whether the expected consequences are realistic from the customer's point of view.

Organisations sometimes make incorrect assumptions about how much disruption customers will actually tolerate.

Keep the BIA Updated

A BIA should not be treated as a one-time exercise completed only for certification.

Review it regularly and whenever there is a significant change, such as:

• A new or discontinued product or service

• A new location

• Organisational restructuring

• A new critical supplier

• Changes in laws or regulations

• A major business disruption or incident

Even when there are no changes, record the review date and conclusion.

Common BIA Weaknesses

Some of the most common problems are:

1. Asking whether an activity is "critical" instead of measuring its impact over time.

2. Not defining impact criteria clearly before starting the analysis.

3. Analysing departments instead of business activities and missing cross-functional dependencies.

4. Setting recovery times without explaining the consequences behind them.

5. Recording dependencies too generally instead of identifying the actual systems, people or suppliers.

6. Failing to check whether the same resource supports multiple critical activities.

7. Consulting only department heads and not the people who actually perform the work.

8. Not reviewing the BIA after certification or when significant changes occur.

The Key Principle

A useful BIA should answer three simple questions:

What happens if this activity stops?

How quickly does it need to be restored?

What does it depend on to recover?

When these answers are supported by clear evidence and regularly reviewed, the BIA becomes a practical business continuity tool—not just an ISO 22301 certification document.

What this covers

See how this looks as a working system

Reading about a requirement and seeing the documentation that satisfies it are different things. In a short demo we open the actual manual, procedures and records set for ISO 22301, show you how each clause is answered and where your existing way of working already fits. You will know what implementation involves before you commit to it.

Ask us about this

Tell us what is being asked of you and by whom.

What are you looking for?

We reply within one working day. Your details stay with our consultants.

More reading

All articles