What it answers
Which processes and services matter most, what happens if each one stops for an hour, a day or a week, which systems, people, suppliers and data each one depends on, and how quickly each must be back. The answers come from interviews with process owners, not only from IT.
Key outputs
For each critical activity: the impacts over time (financial, operational, legal and reputational), the maximum tolerable period of disruption, the recovery time and data loss targets known as RTO and RPO, and the dependencies that must be recovered first. Together they show where to invest in resilience and in what order to restore services.
How it feeds other work
The BIA drives the business continuity plan and the disaster recovery plan, sets backup frequency and retention, and informs the risk assessment. It should be reviewed at least once a year and after major changes, such as a new product, a new key supplier or a move to the cloud.
Where it shows up in compliance
ISO 22301 requires a BIA as part of its business continuity management system. ISO 27001 expects ICT readiness to be planned from business continuity objectives (Annex A 5.30). The ENS includes an impact analysis measure for continuity, and DORA requires financial entities to carry out business impact analyses of severe disruption scenarios.




