Guide · Method · BIA

Business impact analysis: the money-first method

The BIA is where continuity stops being opinions and becomes numbers: which activities matter most, what a lost day costs, how fast you must recover. Done right, it takes weeks — and pays for every decision that follows.

What a BIA answers

A business impact analysis answers four questions with numbers: Which activities are critical — whose interruption hurts revenue, obligations or safety first? How does the damage grow over time — what does hour four cost versus day three? How fast must each activity recover (RTO) and how much data can you afford to lose (RPO)? And what do those activities depend on — systems, people, suppliers, facilities?

Everything downstream — plans, alternate sites, technology spend, insurance limits — is priced by these answers. Which is why a BIA built on adjectives («critical», «high impact») instead of dirhams and hours quietly poisons the whole system.

The method, step by step

Deliverable test: one table — activity, cost of a lost day, RTO, RPO, top dependencies, single points of failure. If it fits on two pages and the CFO signed it, you have a BIA. If it is forty pages of prose, you have a report.

The mistakes that sink BIAs

Frequently asked questions

How long does a BIA take?

For a mid-size organisation: 2-4 weeks including interviews, curves and CFO reconciliation. Longer usually means scope creep; shorter usually means questionnaires.

How is cost of downtime calculated?

Per activity: lost revenue and margin, contractual penalties, recovery overtime and expediting, regulatory exposure, and customer attrition risk — over the impact curve, from your own finance data. Precision matters less than honesty; ±20% is fine, adjectives are not.

Who should own the BIA?

The continuity or risk function runs it; activity owners supply the facts; finance validates the money; leadership signs. A BIA owned by IT alone becomes a systems inventory.

BIA or risk assessment first?

In practice, together: the BIA tells you what matters and how fast it must return; the risk assessment tells you what can take it down. NCEMA 7000 and ISO 22301 expect both.

More from the continuity hub

Want your cost of downtime calculated from your own data?

Request a gap assessmentTake the free readiness check
NCEMA-ready gap assessment