Inside every company a few processes carry the weight: stop them and objectives, obligations or revenue suffer within hours, not months. The critical process concept exists so that leadership can concentrate protection and recovery money where interruption bites fastest. It answers the allocation question every executive faces: we cannot duplicate everything, so what gets generators, spare capacity and rehearsed workarounds first? Without it, continuity budgets spread evenly and protect nothing well.
Criticality is determined in the business impact analysis: process owners estimate how fast harm grows, and management ranks processes against agreed criteria such as revenue at risk, legal deadlines, customer harm and safety. The ranking is recorded in the BIA report, and each critical process receives recovery targets, typically an RTO with MTPD as the outer limit, and priority in continuity plans. A manufacturer may find that invoicing can wait 5 days, while production scheduling cannot stop for more than 12 hours before contract penalties trigger. That documented contrast is what makes plans realistic.
The classic error is letting every department call itself critical, which produces a list where 80% of processes are top priority. Criticality must be earned with numbers from the BIA, and it shifts with context: payroll is routine most of the month and critical on payment day. Boards should ask for time-based evidence, not opinions. In the ERGP programme, a chapter of Module 3 on BIA covers ranking processes and defending the ranking in front of management.
This term is part of the working language of ERGP — the first resilience governance certification fully available in Arabic, also in English. 94 chapters, six modules, a verifiable certificate.
Explore the ERGP programme