BIA review and maintenance is what keeps a business impact analysis from becoming a well-written description of an organization that no longer exists. Teams reorganise, systems change, suppliers are replaced and customers behave differently. If the analysis is not refreshed, recovery priorities drift away from reality, and the plans built on them fail when they are needed.
This guide explains how often to review a BIA, what events should trigger an update, who should own it, what to check and how to record and communicate the changes. It is general guidance that you should adapt to the pace of change in your organization.
Why BIA review and maintenance matters
The BIA is the foundation of a continuity programme. It determines which activities matter most, how quickly they must return and what they depend on. Strategy, risk assessment, plans and budgets all build on it. If the foundation moves and nobody notices, everything on top of it becomes unreliable.
Free business impact analysis
How long can each activity really be down?
Rate the impact of an outage over time, set RTOs and maximum tolerable periods of disruption, map the people, systems and suppliers behind each activity, and get a recovery sequence back, free.
Run the free business impact analysis → or View premium report sample
ISO 22301 expects the organization to review and update its business continuity arrangements at planned intervals and when significant changes occur. A documented BIA review and maintenance routine shows that you do this, and it protects the organization from relying on obsolete assumptions.
Set a cycle for BIA review and maintenance
Most organizations refresh the whole BIA once a year, with a lighter check every six months for fast-changing areas. The right rhythm depends on how quickly your business changes. A start-up may need quarterly reviews. A stable utility may be comfortable with an annual cycle plus event-driven updates.
Put dates in the continuity calendar and assign an owner. Avoid the trap of running a full BIA every three years because the last one was painful. Smaller, regular refreshes are easier, cheaper and give better results than an occasional major overhaul.
Define review triggers
Do not wait for the calendar when something significant changes. Build triggers into your change management: restructures, acquisitions, new products, new sites, system migrations, key supplier changes, regulatory changes and major incidents. Each should prompt a check of the affected part of the BIA.
Make the trigger simple to use. A single question on project and change forms, such as “does this alter any critical activity, system or supplier?” lets the continuity team learn about changes early. Our page on the business continuity risk register shows how changes can also feed risk updates.
Free business continuity risk assessment
What could stop your most important activities?
List your prioritized activities and what they depend on, pick from 32 disruption scenarios, rate them and choose continuity measures for each. Built to ISO 22301 clause 8.2.3, and free.
Run the free continuity risk assessment → or View premium report sample
| Review trigger | Example | What to update |
|---|---|---|
| Scheduled cycle | Annual review | All activities and scores |
| Organizational change | Merger, restructure, new site | Activities, owners, dependencies |
| New product or service | Launch of an online channel | Add activities and impacts |
| Technology change | Migration to cloud | Application dependencies and RTOs |
| Supplier change | New logistics provider | Dependencies and contract terms |
| Incident or exercise | Outage lasted longer than planned | Recovery targets and assumptions |
- Add a continuity question to change and project forms
- Notify the continuity team of acquisitions and restructures
- Review after significant incidents and exercises
- Track regulatory changes that alter deadlines or duties
Ownership of BIA review and maintenance
A named person, usually the business continuity manager, owns the process and schedule. Activity owners own their own data: they confirm impacts, dependencies and recovery needs. Senior management approves the results and any changes to recovery priorities.
Make expectations clear. Activity owners should know that they will be asked to confirm their entries each year and to report changes in between. If ownership is vague, reviews slip and data decays.
What to check in a review
A focused review does not need to repeat the whole analysis. Ask each activity owner a short list of questions and record the answers.
- Activities: have any been added, merged, stopped or moved?
- Impact: have volumes, revenues, customers or regulations changed the impact at each time point?
- Dependencies: are the systems, suppliers, people and sites still correct? See BIA dependencies.
- Recovery targets: do the RTO and RPO still match tolerance and capability? See RTO and RPO.
- Peaks: have busy periods shifted? See BIA peak periods.
Use incidents and exercises as evidence
Real events and exercises test the BIA better than any workshop. If an outage lasted longer than the stated RTO without serious harm, the target may be too tight. If a short outage caused unexpected damage, the target may be too loose. Feed these lessons straight into the analysis.
After each exercise or incident, review the assumptions: staffing, dependencies, workarounds and communications. Record the changes and update the plans. Our guide to business continuity exercises explains how to capture and act on results.
Record, approve and communicate changes
Keep a change log showing what was updated, when, by whom and why. Version the BIA document, and keep earlier versions. When recovery priorities change, obtain management approval, because resources and budgets may change with them.
Then tell the people who use the BIA: those who maintain recovery plans, IT teams who manage systems and procurement teams who manage suppliers. A revised priority that never reaches the plan owners changes nothing in practice.
Keep the method consistent
Use the same scales and definitions from one review to the next so results can be compared over time; see BIA impact scoring scales for how to define them. If you must change the method, explain why and note that results before and after are not directly comparable.
Use the same questionnaire structure and, where possible, the same people. Continuity in the process reduces effort and helps you spot trends, such as growing dependence on a single supplier.
Common mistakes in BIA review and maintenance
Typical problems include reviewing only on the calendar, ignoring changes between reviews, failing to update owners after reorganisations, losing earlier versions, never linking incidents to the analysis and not telling plan owners about changed priorities. Another is treating the review as a form-filling exercise where owners simply tick “no change”.
Avoid these by using triggers, asking specific questions, sampling entries for verification and reporting results to management. A short workshop, as described in the BIA workshop, often reveals changes that forms miss.
Reporting the results to management
Give leaders a short summary after each review: what changed, which recovery priorities moved, what gaps were found and what decisions are needed. A one-page summary with a table of changes is enough. Highlight any activity whose recovery target became shorter, because it may need funding, and any dependency that became a single point of failure. Ask management to approve the updated priorities and record the decision.
Over time, track a few indicators: percentage of activities reviewed on time, number of triggers raised, number of changes made and number of overdue actions. They show whether maintenance is real or only nominal.
Making reviews efficient
Pre-populate each activity owner’s form with last year’s answers, so they only need to confirm or amend. Use a short workshop for areas with heavy change, and send reminders a month before the deadline. Give owners a clear window, such as four weeks, and escalate gaps to their line manager. Efficient reviews get better cooperation and produce more accurate data than long, unfamiliar questionnaires.
Where possible, connect the BIA to other data sources such as asset inventories, supplier registers and organization charts. When those change, the BIA owner can be alerted, which reduces reliance on memory and makes it easier to spot drift between formal reviews.
Handling overdue reviews
Some reviews will slip. Set a rule that overdue items are reported to the governance forum after thirty days, and that any activity without a current review is flagged as unverified in plans and reports. This keeps attention on the problem and prevents old data being trusted by default.
A short worked example
A manufacturer runs an annual BIA review. This year it discovers that a new customer portal now handles thirty percent of orders, that a key component supplier has been replaced and that a plant moved to a new site. The team adds the portal as a critical activity with a two-hour RTO, updates the supplier dependency and revises recovery locations.
It records the changes in the log, obtains management approval and sends the updated priorities to plan owners and IT. Three months later, a small outage confirms the portal target was right. The analysis stayed useful because it was maintained.
Structuring the review
If you want a workbook that holds activities, scores, dependencies, targets and a change log, the Business Impact Analysis Report and Workbook provides a structured report and workbook that supports regular refreshes, consistent with ISO 22301:2019 on business continuity management. Whatever the format, disciplined BIA review and maintenance means a fixed cycle, clear triggers and visible ownership.
BIA review and maintenance FAQ
How often should a BIA be reviewed?
At least annually, with additional reviews when significant changes or incidents occur. Fast-changing organizations may review more often.
What should trigger an unscheduled review?
Restructures, acquisitions, new products or sites, technology or supplier changes, regulatory changes and significant incidents or exercises.
Who is responsible for keeping the BIA up to date?
The continuity manager owns the process, activity owners keep their data current and senior management approves changes to priorities.
Do we need to redo the whole BIA each year?
Not necessarily. A focused refresh that confirms or updates each activity is enough, provided changes are captured and approved.
How do we prove reviews happened?
Keep dated versions, a change log, approvals and records of communication to plan owners.