When an earthquake, pandemic, cyberattack, or data center fire strikes, the organizations that survive are those that planned for it. Business Impact Analysis is the science of knowing which processes are critical, what happens when they fail, and how fast they must recover.
Without a BIA, BC planning is guesswork. The BIA answers three questions: Which processes are critical? How quickly must they recover (MTD/RTO)? How much data can we lose (RPO)? The BIA transforms abstract resilience goals into specific, measurable recovery requirements that drive all subsequent planning and investment decisions.
The BIA relies on structured interviews with process owners across all business units. Each interview covers: process description and dependencies, financial and operational impact of disruption at 1h, 4h, 24h, 72h, 1 week intervals, regulatory obligations, customer SLA impacts, and resource requirements for recovery. Impact curves plotted over time reveal the critical threshold — the point at which impact becomes unacceptable (the MTD).
The strategy for each process tier is determined by: RTO requirements (drives technology investment), RPO requirements (drives backup/replication investment), budget constraints, and regulatory requirements. Strategies range from hot standby (near-zero RTO/RPO, highest cost) to manual workarounds (immediate operation, no technology required). Most organizations need a portfolio of strategies matched to process criticality.
Catalog all business processes across every department. Include sub-processes and their dependencies. A bank may have 200+ processes: wire transfer, customer onboarding, trade settlement, loan origination, compliance reporting — each requires individual BIA analysis.
For each disruption time interval, quantify impact across dimensions: Financial (lost revenue, recovery costs, penalties), Operational (inability to serve customers, regulatory violations), Reputational (customer churn, media coverage), Legal (SLA breach, regulatory non-compliance).
Maximum Tolerable Downtime is the point at which cumulative impact becomes unacceptable — threatening the organization's ability to continue. MTD must be verified with process owners AND senior management — individual process owners often set MTD too low (protecting their own domain).
Map upstream (what does this process need to function?) and downstream (what processes depend on this one?) dependencies. A single-process disruption can cascade. Payment processing depends on: core banking system → network connectivity → authentication services → database availability.
Rank processes by criticality using MTD and financial impact. Recovery sequence must respect dependencies — restore databases before applications, restore authentication before business applications. The recovery sequence is a primary output of the BIA.
BC plans that are never tested do not work in practice. Three testing levels, progressively more rigorous:
Discussion-based walkthrough of a scenario. Key stakeholders gather (physical or virtual) and discuss how they would respond to a defined scenario. Identifies plan gaps, clarifies roles, tests communication procedures. Minimal disruption. Conduct quarterly minimum.
Activates and tests specific functions (not the full plan). Example: test only the DR failover procedure, or only the crisis communication tree. Identifies operational gaps in specific procedures. Conduct semi-annually.
Complete activation of the BCP/DRP as if a real event occurred. Systems actually fail over to DR site. Employees actually work from alternate locations. The most realistic test — and the most disruptive. Conduct annually.
Conducted within 1 week of every exercise. Document: what worked, what failed, what is unclear, recommended improvements. Update the BCP/DRP with exercise findings. Close action items within 30 days.
Technical recovery is only half of crisis management. Stakeholder communications during a disruption are equally critical:
| Stakeholder | Communication Priority | Key Message | Channel |
|---|---|---|---|
| Employees | Immediate | What happened, what to do, safety | Mass notification system (not email if affected) |
| Customers | Within 4 hours (P1) | Service status, expected resolution time, alternatives | Status page, social media, automated notification |
| Regulators | Per regulatory requirement | Factual, specific, acknowledge impact | Formal regulatory notification portal or letter |
| Board/Investors | Within 24 hours for material events | Business impact quantification, recovery timeline, cost estimate | Secure briefing (material information controls) |
| Media | Only through designated spokesperson | Controlled, factual, no speculation | Press release through PR team only |
You are the Business Continuity Manager at a regional bank whose primary data centre is in coastal Florida. A Category 4 hurricane is 36 hours away. Complete each BCP/DR task — from BIA to recovery sequencing to stakeholder notification — using the methodology from this module.