Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

Business continuity risk assessment example with criteria and treatment plan.

Business Continuity Risk Assessment Example: Complete 2026 Walkthrough

A business continuity risk assessment example is the fastest way to see what the finished work should look like, because the standard itself describes the process, not the output. ISO 22301 asks you to identify, analyse and evaluate the risks of disruption to your prioritized activities and decide which need treatment, but it does not hand you a template. This article walks through a complete worked example for a fictional food manufacturer, from criteria to treatment plan, so you can compare it with your own.

Business continuity risk assessment example

The example is deliberately small, and it uses the same register structure our free tool produces, so you can check your own output against it. It has twelve risks, one production site and one distribution centre. A real register for a mid-sized organization is usually larger, but the structure does not change.

Where the Risk Assessment Sits in ISO 22301

ISO 22301:2019 puts the business impact analysis and the risk assessment side by side in clause 8.2. The business impact analysis (clause 8.2.2) tells you which activities matter most and how quickly they must come back. The risk assessment (clause 8.2.3) tells you what is most likely to stop them. Together they drive the continuity strategies in clause 8.3 and the plans in clause 8.4. The standard itself is available from ISO; the 2024 amendment added climate change considerations to the context clauses.

Free business impact analysis

How long can each activity really be down?

Rate the impact of an outage over time, set RTOs and maximum tolerable periods of disruption, map the people, systems and suppliers behind each activity, and get a recovery sequence back, free.

Run the free business impact analysis →  or  View premium report sample

If you are unsure how the two analyses differ, read our BIA vs risk assessment comparison first. For the method in full, our ISO 22301 risk assessment guide is the pillar this example builds on.

The Organization in This Business Continuity Risk Assessment Example

Kestrel Foods (a fictional company) makes chilled ready meals for three national retailers. Orders arrive by EDI into an ERP system; production runs on one site with refrigerated storage; finished goods leave from a separate distribution centre through two courier contracts. Its business impact analysis identified four prioritized activities:

  • Production: maximum tolerable period of disruption 24 hours, because chilled stock spoils and retailer slots are lost.
  • Customer order intake: 8 hours, because missing the daily EDI order cut-off means a lost day of sales.
  • Dispatch and delivery: 12 hours.
  • Payroll: 3 days.

The resources behind those activities (the production site, the distribution centre, the ERP system, the refrigeration control system, the key raw material supplier, the courier network and the operations team) become the scope items of the risk assessment. Our business impact analysis example shows how that first step is documented.

Step 1: The Criteria

Every rating in a business continuity risk assessment example like this one must be made against scales agreed in advance. Kestrel uses a five-point scale for each axis and rates impact by how long and how costly a disruption would be, tied back to the recovery objectives from the BIA:

RatingLikelihoodImpact
1Rare: not expected in the next 10 yearsNegligible: absorbed within normal operations
2Unlikely: could happen once in 5 to 10 yearsMinor: disruption well inside every recovery objective
3Possible: once in 2 to 5 yearsModerate: one activity approaches its recovery time objective
4Likely: about once a yearMajor: a prioritized activity exceeds its recovery time objective
5Almost certain: several times a yearSevere: a prioritized activity exceeds its maximum tolerable period of disruption

The risk level is likelihood multiplied by impact, from 1 to 25. Kestrel’s appetite line is 9: anything at level 9 or below is accepted without treatment, and anything above it needs a decision.

Step 2: The Risk Register in This Business Continuity Risk Assessment Example

Each risk is written as a scenario: the event, the weakness that makes it disruptive, and the effect on the prioritized activities. The ratings take the arrangements already in place into account.

RefRisk of disruptionExisting arrangementsLILevel
R-01Prolonged power failure at the production site; no standby power for refrigerationSingle grid supply3515
R-02Ransomware halts the ERP; backups reachable from the office networkEndpoint protection, nightly backup3515
R-03Recovery arrangements never testedPlan written two years ago4416
R-04Single-source supplier of the main raw material failsTwo weeks of packaging stock only3412
R-05ERP outage stops order intakeVendor support contract3412
R-06Only one engineer can reset the refrigeration controlsNone339
R-07Pandemic reduces production staffing below 70%Pandemic plan from 2020248
R-08Courier partner cannot deliverSecond courier can take 60% of volume236
R-09Fire closes the production siteSprinklers, annual fire risk assessment155
R-10Flooding of the distribution centre loading baySite outside the flood zone144

Two further risks were identified but are not shown: one was not yet rated (cash flow during a prolonged disruption) and one had no owner. Both are findings an auditor would raise, and both show up in a good tool as gaps rather than disappearing silently.

Notice what the ratings reveal. Fire is the scenario most people start with, yet it sits well within appetite because the likelihood is rare. The highest risk is the untested plan, because it multiplies the damage of every other scenario: an outage that should take eight hours to recover from takes three days when the restore procedure has never been run.

Step 3: Treatment Decisions

In this business continuity risk assessment example, five risks sit above the appetite line, so each needs one of the four treatment options: modify, avoid, share or retain.

RefDecisionContinuity measureOwner and dateTarget level
R-03ModifyTabletop exercise this quarter, full recovery test within 12 monthsBusiness Continuity Manager, Q48
R-01ModifyStandby generator for refrigeration, fuel supply contractFacilities Manager, Q16
R-02ModifyOffline, immutable backups and a tested ERP restore within 8 hoursIT Manager, Q48
R-04ModifyQualify a second supplier with a call-off contractProcurement Manager, Q16
R-05ModifyDocumented manual order process for EDI outagesIT Manager, Q46

After treatment, every risk is expected to sit at or below the appetite line. Each treatment has a named owner and a date, and the risk owner signs off the residual level. That sign-off is the piece most often missing when a certification auditor samples the register.

Step 4: What the Business Continuity Risk Assessment Example Tells Management

A business continuity risk assessment is only useful if it changes decisions. From this register, Kestrel’s management can see three things at a glance:

  1. The biggest exposures are concentrated. Power, the ERP and one supplier account for most of the risk above the line. That is where the continuity budget should go first.
  2. Testing is a control in its own right. The untested plan is rated higher than any single physical threat. Exercising the plan reduces every other risk at once.
  3. Some familiar risks need no spend. Fire and flood are within appetite with the arrangements already in place, which frees budget for the risks that are not.

How to Build Your Own

You can copy the structure of this business continuity risk assessment example directly:

  • Start from your business impact analysis, so the scope is your prioritized activities and the resources they need.
  • Define impact in terms of your recovery objectives, not only money.
  • Write every risk as a scenario with a weakness, not just an event name like “fire”.
  • Record the existing arrangements and the reason for each rating.
  • Give every risk above the line a decision, a continuity measure, an owner, a date and a target.
  • Repeat the assessment at planned intervals, usually once a year, and after any significant change.

The quickest way to produce the same output for your own organization is our free business continuity risk assessment tool. It imports your business impact analysis as the scope, offers 32 disruption scenarios with the continuity measures that usually treat them, and gives you a heat map and findings straight away. The optional report adds the register, treatment plan and a live Excel workbook.

Frequently Asked Questions

Is a business continuity risk assessment mandatory under ISO 22301?

Yes. Clause 8.2 requires both a business impact analysis and a risk assessment as part of the business continuity management system, and a certification auditor will expect to see evidence of each. A business continuity risk assessment example like the one above is the kind of record they sample.

How is this different from an information security risk assessment?

It covers anything that could stop your prioritized activities, including events with no security element such as power failures, supplier insolvency or loss of key people, and it rates impact by disruption rather than by loss of confidentiality or integrity.

Should the risk assessment come before or after the BIA?

Usually after. The BIA identifies what must be protected and how quickly it must recover; the risk assessment then looks at what threatens those activities. Many organizations iterate between the two in the first year.

Can I reuse this business continuity risk assessment example as a template?

Yes, the structure transfers directly: criteria tied to your recovery objectives, scenarios with a weakness, existing arrangements, ratings with a rationale, and a treatment plan with owners and dates. Replace the scenarios and ratings with your own; copying someone else’s ratings defeats the purpose.

How many risks should the register contain?

Enough to cover every prioritized activity and critical resource. For a single-site business, 15 to 30 well-written scenarios is typical; group near-duplicates rather than listing every variation.

For the full set of policies, plans and registers that sit around this assessment, see the ISO 22301 Toolkit.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.

Leave a Reply

Your email address will not be published. Required fields are marked *