A business impact analysis (BIA) is an assessment of how a disruption to each business process would hurt the organization as the outage goes on: lost revenue, missed obligations, regulatory or safety exposure, and damage to customer trust. It identifies which processes matter most, what they depend on, and how quickly they need to be restored. The results set recovery priorities and targets for continuity planning and for buying backup and recovery services.
At a glance
- A BIA measures the impact of a process stopping, regardless of what caused it.
- It is done with business owners, not just IT, because they know what downtime actually costs.
- Outputs include priorities, dependencies, and recovery targets such as RTO and RPO.
- It is the foundation of a business continuity and disaster recovery program.
- It needs regular updates as systems, sites and the business change.
What problem it solves
When something fails, everything feels urgent. Without agreed priorities, IT recovers systems in whatever order seems sensible at the time, and the business may find its most important process waiting behind a less important one. Before an outage, the same lack of priorities leads to spending the same on protecting every system, or to protecting the systems IT knows best rather than those the business depends on most.
A BIA replaces assumptions with an agreed view. It asks each part of the business what happens if its process stops for an hour, a day or a week, and what it depends on to run. That gives leadership a basis for deciding where fast recovery is worth paying for, and gives IT clear, defensible targets to design and buy against.
How it works
Scope and process list. The organization lists its key business processes, such as taking orders, paying staff, serving customers or shipping goods, and names an owner for each.
Impact over time. Owners estimate what an outage costs at intervals: an hour, a day, a week. Impacts are usually both financial (lost sales, penalties, overtime) and non-financial (customer harm, regulatory exposure, safety, reputation). Many BIAs use simple rating scales rather than precise figures.
Dependencies. For each process, the BIA maps what it needs: applications, data, networks, people, sites, suppliers and other processes. This often reveals hidden dependencies, such as a single supplier, a shared service or a person who holds key knowledge.
Recovery targets. From the impact curve, the organization sets a maximum tolerable downtime, a recovery time objective (RTO) and a recovery point objective (RPO) for each process and its systems.
Review and sign-off. Leadership reviews the priorities and accepts the targets and their cost implications. The results feed into the business continuity and disaster recovery (BCDR) plan.
When it matters for buyers
- Before buying backup or disaster recovery services. The BIA tells you which systems need fast recovery, like disaster recovery as a service (DRaaS), and which can rely on backup.
- When the board asks about resilience. A BIA gives a structured, business-led answer.
- When insurers, auditors or large customers ask. A documented basis for recovery priorities is often expected.
- After a major change. New core systems, acquisitions, new sites and moves to SaaS all shift dependencies.
- After an outage. Real downtime is a chance to check whether the estimated impacts were right.
Questions to ask vendors
- Do you run business impact analyses as part of your service, or expect us to bring our own targets?
- What method and templates do you use, and how do you involve our business owners?
- How do you turn BIA results into recovery tiers and service choices?
- Can your service meet the recovery targets the BIA sets for each tier, and at what cost per tier?
- How often do you recommend revisiting the BIA, and is that included?
How it differs from a risk assessment
A risk assessment looks at threats and vulnerabilities: what could go wrong, how likely it is and how to reduce the chance. A BIA looks at consequences: if a process stops, for whatever reason, how bad does it get and how fast. The two complement each other. A risk assessment might show that a single internet connection is a likely point of failure; the BIA shows how much an outage of the processes behind it would cost, which helps justify the fix. Our governance, risk and compliance overview covers how both fit into a wider program.
