Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

BIA for outsourced processes linking internal activities to supplier services, contract terms and recovery targets

BIA for Outsourced Processes: A 2026 Guide

A BIA for outsourced processes is the step that stops a continuity plan from failing at the supplier boundary. When a payroll bureau, a cloud host or a call centre runs part of your operation, you may still be accountable to customers and regulators for its availability, yet you cannot restore it yourself. The analysis has to show how long you can live without each outsourced service and whether the supplier can meet that number.

This guide explains how to identify outsourced activities, translate your recovery targets into supplier requirements, review contracts and evidence, plan for supplier failure and keep the analysis current. It is general guidance and should be adapted to your sector and regulatory duties.

Why outsourcing changes the BIA

Outsourcing moves the work but not the responsibility. Regulators in many sectors expect firms to manage the operational resilience of outsourced services, and customers do not care whose data centre failed. Your BIA has to show which important activities depend on suppliers and how much disruption they can tolerate.

Free business impact analysis

How long can each activity really be down?

Rate the impact of an outage over time, set RTOs and maximum tolerable periods of disruption, map the people, systems and suppliers behind each activity, and get a recovery sequence back, free.

Run the free business impact analysis →  or  View premium report sample

Standards such as ISO 22301 expect you to consider dependencies, including suppliers and partners, when analysing the impact of disruption. See BIA dependencies for the general approach. A BIA for outsourced processes applies the same thinking to services you do not control, with extra attention to contracts and evidence.

Identify outsourced and part-outsourced activities

Start from your list of activities and ask, for each one, which parts are performed by a third party. Include obvious cases such as payroll, IT hosting and customer service, and less obvious ones such as software libraries, payment gateways, courier networks and consultants holding critical knowledge.

Also ask about sub-contractors. Your supplier may rely on a fourth party, such as a hosting provider, that creates a hidden single point of failure. Our guide to single point of failure analysis helps you find them, and fourth-party risk explains how to manage them.

Set your requirement first for a BIA for outsourced processes

Before you ask the supplier anything, decide what you need. From the BIA, determine the maximum tolerable period of disruption, the recovery time objective and the acceptable data loss for each outsourced service. Use your scoring scale, as described in BIA impact scoring scales, so the numbers are defensible.

Then express them as requirements in supplier terms: service restored within a set number of hours, data no older than a set number of minutes, communication within a specified time. A vague request such as “high availability” gives you nothing to test.

Outsourced serviceYour impact if it stopsQuestion for the supplier
Cloud hostingCustomer portal unavailableWhat are your recovery time and data loss targets?
Payroll bureauStaff unpaid, legal exposureHow do you recover if your site is lost?
Contact centreCustomer queries unansweredCan you switch sites or staff remotely?
Logistics providerDeliveries stoppedWhat alternative routes and capacity exist?
Software as a serviceCore process blockedCan we export data and run manually?
  • State recovery time and data loss targets in hours or minutes
  • Define what counts as recovery, such as full or minimum service
  • Specify communication and escalation expectations
  • Identify any regulatory limits on where data may be processed

Compare supplier capability with your target

Ask suppliers for their own recovery targets, business continuity arrangements, testing results and dependency on other providers. Compare them with your requirement. Where the supplier’s recovery time is longer than your tolerance, you have a gap that needs treatment.

Ask for evidence, not just assurances: a summary of recent test results, a certificate to a continuity or security standard, or a description of their failover design. Use questionnaires where suitable, and see supplier business continuity assessment for what to ask.

Review the contract

Check that the contract reflects your needs: service levels tied to recovery, notification of incidents, right to audit or receive test results, sub-contractor controls, data return and exit assistance. A service level of 99.9 percent availability may sound good, but says little about how quickly a major failure is repaired.

Where the contract is weak, negotiate at renewal or add addenda for critical services. Where you cannot change it, record the residual risk and put compensating measures in place, such as a secondary supplier or manual workarounds.

Plan for supplier failure

Every critical outsourced service needs a plan for what you do if the supplier is down, or fails altogether. Options include a second supplier, an in-house fallback, manual procedures, stored copies of data and pre-agreed exit arrangements. Decide which option meets your recovery time, and test it.

Document triggers and responsibilities: who declares that the supplier has failed, who talks to customers and who activates the fallback. Integrate these steps into your wider continuity plans. Our guides to business continuity risk treatment and business continuity exercises show how to plan and test.

Free third-party risk assessment

How much risk does this vendor bring?

Tier the vendor, check the evidence, rate the risks from 30 third-party scenarios and choose controls referenced to ISO 27001, NIST CSF 2.0 and DORA. You get a tier, a heat map and the findings an auditor would raise, free.

Start the free vendor risk assessment →  or  View premium report sample

Test with the supplier

A plan that has never been tested is a hypothesis. Include critical suppliers in exercises, from simple communication checks to joint scenario tests. Even a short tabletop exercise reveals gaps in contacts, authority and assumptions.

Ask suppliers to share the results of their own tests, and agree how issues will be tracked to closure. For the most critical services, consider a live failover test at a low-risk time. Record outcomes and update the BIA and the plans accordingly.

Keep the BIA for outsourced processes current

Supplier arrangements change as contracts renew, services move and suppliers merge. Review the outsourced part of your BIA at least annually, and whenever a critical supplier changes its service, location or ownership. Record changes and reassess the impact and the requirement.

Add a trigger to procurement and change processes so that new outsourcing arrangements are assessed before signature, rather than after go-live. That is when you have the most leverage to get the right clauses.

Common mistakes in a BIA for outsourced processes

Frequent errors include leaving outsourced activities out of the BIA, accepting supplier statements without evidence, using availability percentages as a substitute for recovery time, ignoring fourth parties, assuming the supplier’s plan covers your priority and never testing the fallback. Another is failing to record who owns each supplier relationship.

Avoid these by assigning an internal owner to each critical supplier, keeping a register of requirements and evidence and including suppliers in exercises.

Governance and reporting for a BIA for outsourced processes

Give each critical outsourced service an internal owner who is responsible for the requirement, the contract, the evidence and the fallback. Report the status to a governance forum at least twice a year: which suppliers meet the target, which do not, what is being done and what risk remains. Senior managers can then decide where to invest. Without ownership and reporting, supplier resilience tends to be forgotten until an incident forces the question.

Keep a simple register of critical suppliers with their services, targets, contract dates, last test and open actions. A page of dates and owners is far more useful in a crisis than a folder of unread contracts.

Regulatory expectations for outsourcing

Many regulated sectors, such as banking, insurance and healthcare, set explicit expectations for outsourced services, including exit plans, audit access and notification of incidents. Check the rules that apply to you and reflect them in the analysis and the contract. Even where no rule applies, showing that you assessed each critical supplier is good practice and helps in customer due diligence, because clients increasingly ask how you manage the resilience of the services you rely on.

A short worked example

A retailer outsources its online store hosting. The BIA shows that an outage costs significant revenue after two hours, so the recovery time target is one hour with data loss under five minutes. The supplier states a four-hour recovery time. The retailer negotiates a faster tier with a secondary region, adds a service credit clause and schedules a joint failover test.

It also builds a static fallback page and a manual order route for phone sales. After the test, recovery is confirmed at fifty minutes. The analysis, the contract and the plan now line up.

Structuring the analysis

If you want the activity list, dependencies, targets and supplier evidence organised in one place, the Business Impact Analysis Report and Workbook provides a report and workbook that supports this kind of analysis, consistent with ISO 22301:2019 on business continuity management. Whichever tool you use, a BIA for outsourced processes should end with clear requirements, tested fallbacks and named owners.

BIA for outsourced processes FAQ

Do outsourced activities belong in our BIA?

Yes. If an important activity depends on a supplier, its impact and recovery target must be analysed, and the supplier’s capability compared with your needs.

Is an availability percentage enough?

No. Percentages say little about how long a major failure lasts. Ask for recovery time and data loss targets and evidence they can be met.

What if the supplier cannot meet our target?

Negotiate improvements, add a second supplier or fallback, or accept and record the residual risk with senior approval.

Should we test suppliers?

Yes, for critical services. Include them in exercises and ask for the results of their own tests, then track issues to closure.

How often should we review this part of the BIA?

At least annually and whenever a critical supplier changes its service, location or ownership.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.