Business Impact Analysis
Definition
Business Impact Analysis
A business impact analysis is the assessment that works out what a disruption costs as time passes, and which activities must therefore be restored first. It measures loss, not likelihood — probability belongs to the risk assessment that sits alongside it.
The output is a ranked list with numbers attached. Every activity carries a tolerable outage period and a maximum acceptable data loss, and those two figures drive every recovery investment that follows.
Managers consistently overstate their own urgency, which is why the assessment uses a consistent scoring method rather than a show of hands. Two departments claiming a four-hour tolerance cannot both be right.
The timing of a disruption changes its cost, and good analyses say so explicitly. A payroll system failing on the twentieth of the month is a different event from the same failure on the third.
Key takeaways
- The assessment quantifies loss over time, not the chance of an event occurring.
- Each activity receives a recovery time objective and a recovery point objective.
- Results rank restoration order, so scarce recovery capacity goes to the right place.
- Timing changes impact, so seasonal and cyclical peaks are assessed separately.
How it works
Analysts survey the people who run each activity, then convert their answers into comparable numbers. Ready.gov describes the method plainly: use a questionnaire to “survey managers and others within the business” who hold detailed operational knowledge.
The federal guidance is equally direct about the purpose. A business impact analysis “predicts the consequences of a disruption to your business, and gathers information needed to develop recovery strategies”.
Impacts are recorded in two columns. Operational impacts cover service failure, regulatory breach and reputational damage; financial impacts cover lost revenue, penalties and the cost of working around the outage manually.
Ranking follows from the totals. The same guidance states that processes “with the greatest operational and financial impacts should be restored first”, which is the whole reason the exercise produces an ordered list.
Dependencies are the part most often missed. An activity with a two-hour tolerance inherits that figure from every system, supplier and named person it relies on — and the weakest of those sets the real number.
| Output | What it states | Typical unit |
|---|---|---|
| Recovery time objective | How long an activity can be down | Hours or days |
| Recovery point objective | How much recent data may be lost | Minutes or hours |
| Peak exposure window | When an outage costs most | Calendar dates |
| Minimum resource set | What is needed to resume at reduced capacity | People and systems |
The technique is standardised in government practice. NIST’s contingency planning guide publishes a business impact analysis template alongside its low, moderate and high impact system plans.
Examples
The same assessment produces very different answers depending on what the organisation actually does. Three cases show how the tolerable outage period moves with the nature of the work.
A hospital finds its patient record system has a two-hour tolerance while its procurement system has five days. The gap justifies duplicate infrastructure for one and nothing at all for the other.
An outsourcing buyer scores contact handling at four hours and back-office claims at three days. The business continuity management programme sizes its standby capacity from those two numbers.
A logistics firm discovers its dispatch tolerance falls to thirty minutes in December. Its escalation plan and its service uptime commitments both change for that month only.
Related terms
Continuity work splits into an assessment stage, a planning stage and a set of contractual commitments. The entries below sit at those different points, and this one supplies the numbers the rest consume.
- Business continuity plan (BCP): the document this assessment feeds, not the assessment itself.
- Business continuity clause: the contractual obligation placed on a provider.
- Risk outsourcing: transferring exposure rather than measuring its cost.
- Vendor risk assessment: judges a supplier, where this judges an activity.
FAQ
How is this different from a risk assessment?
A risk assessment estimates how likely a threat is. This assessment estimates what the loss would be if the activity stopped, whatever caused it.
How often should it be repeated?
Annually for most organisations, and immediately after any material change to products, sites, suppliers or systems. Restructures invalidate the results faster than anything else.
How is a change impact analysis different?
A change impact analysis asks what a planned change will touch. This asks what an unplanned stoppage would cost. One reads reach, the other reads loss.
Who owns the numbers?
The activity owner, not the continuity team. The analysis is only defensible if the person accountable for the process signed off the tolerance.
What makes the results unreliable?
Self-assessment without challenge. When every department claims the shortest tolerance, ranking becomes impossible and recovery investment spreads too thin to help. A moderation session across departments fixes most of it.
Does it cover suppliers?
It should. Outsourced activities carry the same tolerances as internal ones, and a provider’s own tolerance must be at least as tight as yours — otherwise the figure on paper is fiction.
Read more resilience and sourcing guidance at Outsource Accelerator.







Independent




