GlossaryCompliance operations

Business impact analysis

Short answer

A business impact analysis (BIA) identifies an organisation's critical activities and estimates how a disruption to each of them would affect the business over time. It sets recovery priorities and targets such as RTO and RPO, and is the starting point of any business continuity plan.

What it answers

Which processes and services matter most, what happens if each one stops for an hour, a day or a week, which systems, people, suppliers and data each one depends on, and how quickly each must be back. The answers come from interviews with process owners, not only from IT.

Key outputs

For each critical activity: the impacts over time (financial, operational, legal and reputational), the maximum tolerable period of disruption, the recovery time and data loss targets known as RTO and RPO, and the dependencies that must be recovered first. Together they show where to invest in resilience and in what order to restore services.

How it feeds other work

The BIA drives the business continuity plan and the disaster recovery plan, sets backup frequency and retention, and informs the risk assessment. It should be reviewed at least once a year and after major changes, such as a new product, a new key supplier or a move to the cloud.

Where it shows up in compliance

ISO 22301 requires a BIA as part of its business continuity management system. ISO 27001 expects ICT readiness to be planned from business continuity objectives (Annex A 5.30). The ENS includes an impact analysis measure for continuity, and DORA requires financial entities to carry out business impact analyses of severe disruption scenarios.

Related terms

Keep reading on this topic

Running security as a repeatable process: policy management, risk registers, evidence upkeep, supplier assessment and audit readiness between cycles.

Go to the topic hub