A business continuity risk assessment example is the fastest way to see what the finished work should look like, because the standard itself describes the process, not the output. ISO 22301 asks you to identify, analyse and evaluate the risks of disruption to your prioritized activities and decide which need treatment, but it does not hand you a template. This article walks through a complete worked example for a fictional food manufacturer, from criteria to treatment plan, so you can compare it with your own.

The example is deliberately small, and it uses the same register structure our free tool produces, so you can check your own output against it. It has twelve risks, one production site and one distribution centre. A real register for a mid-sized organization is usually larger, but the structure does not change.
Where the Risk Assessment Sits in ISO 22301
ISO 22301:2019 puts the business impact analysis and the risk assessment side by side in clause 8.2. The business impact analysis (clause 8.2.2) tells you which activities matter most and how quickly they must come back. The risk assessment (clause 8.2.3) tells you what is most likely to stop them. Together they drive the continuity strategies in clause 8.3 and the plans in clause 8.4. The standard itself is available from ISO; the 2024 amendment added climate change considerations to the context clauses.
Free business impact analysis
How long can each activity really be down?
Rate the impact of an outage over time, set RTOs and maximum tolerable periods of disruption, map the people, systems and suppliers behind each activity, and get a recovery sequence back, free.
Run the free business impact analysis → or View premium report sample
If you are unsure how the two analyses differ, read our BIA vs risk assessment comparison first. For the method in full, our ISO 22301 risk assessment guide is the pillar this example builds on.
The Organization in This Business Continuity Risk Assessment Example
Kestrel Foods (a fictional company) makes chilled ready meals for three national retailers. Orders arrive by EDI into an ERP system; production runs on one site with refrigerated storage; finished goods leave from a separate distribution centre through two courier contracts. Its business impact analysis identified four prioritized activities:
- Production: maximum tolerable period of disruption 24 hours, because chilled stock spoils and retailer slots are lost.
- Customer order intake: 8 hours, because missing the daily EDI order cut-off means a lost day of sales.
- Dispatch and delivery: 12 hours.
- Payroll: 3 days.
The resources behind those activities (the production site, the distribution centre, the ERP system, the refrigeration control system, the key raw material supplier, the courier network and the operations team) become the scope items of the risk assessment. Our business impact analysis example shows how that first step is documented.
Step 1: The Criteria
Every rating in a business continuity risk assessment example like this one must be made against scales agreed in advance. Kestrel uses a five-point scale for each axis and rates impact by how long and how costly a disruption would be, tied back to the recovery objectives from the BIA:
| Rating | Likelihood | Impact |
|---|---|---|
| 1 | Rare: not expected in the next 10 years | Negligible: absorbed within normal operations |
| 2 | Unlikely: could happen once in 5 to 10 years | Minor: disruption well inside every recovery objective |
| 3 | Possible: once in 2 to 5 years | Moderate: one activity approaches its recovery time objective |
| 4 | Likely: about once a year | Major: a prioritized activity exceeds its recovery time objective |
| 5 | Almost certain: several times a year | Severe: a prioritized activity exceeds its maximum tolerable period of disruption |
The risk level is likelihood multiplied by impact, from 1 to 25. Kestrel’s appetite line is 9: anything at level 9 or below is accepted without treatment, and anything above it needs a decision.
Step 2: The Risk Register in This Business Continuity Risk Assessment Example
Each risk is written as a scenario: the event, the weakness that makes it disruptive, and the effect on the prioritized activities. The ratings take the arrangements already in place into account.
| Ref | Risk of disruption | Existing arrangements | L | I | Level |
|---|---|---|---|---|---|
| R-01 | Prolonged power failure at the production site; no standby power for refrigeration | Single grid supply | 3 | 5 | 15 |
| R-02 | Ransomware halts the ERP; backups reachable from the office network | Endpoint protection, nightly backup | 3 | 5 | 15 |
| R-03 | Recovery arrangements never tested | Plan written two years ago | 4 | 4 | 16 |
| R-04 | Single-source supplier of the main raw material fails | Two weeks of packaging stock only | 3 | 4 | 12 |
| R-05 | ERP outage stops order intake | Vendor support contract | 3 | 4 | 12 |
| R-06 | Only one engineer can reset the refrigeration controls | None | 3 | 3 | 9 |
| R-07 | Pandemic reduces production staffing below 70% | Pandemic plan from 2020 | 2 | 4 | 8 |
| R-08 | Courier partner cannot deliver | Second courier can take 60% of volume | 2 | 3 | 6 |
| R-09 | Fire closes the production site | Sprinklers, annual fire risk assessment | 1 | 5 | 5 |
| R-10 | Flooding of the distribution centre loading bay | Site outside the flood zone | 1 | 4 | 4 |
Two further risks were identified but are not shown: one was not yet rated (cash flow during a prolonged disruption) and one had no owner. Both are findings an auditor would raise, and both show up in a good tool as gaps rather than disappearing silently.
Notice what the ratings reveal. Fire is the scenario most people start with, yet it sits well within appetite because the likelihood is rare. The highest risk is the untested plan, because it multiplies the damage of every other scenario: an outage that should take eight hours to recover from takes three days when the restore procedure has never been run.
Step 3: Treatment Decisions
In this business continuity risk assessment example, five risks sit above the appetite line, so each needs one of the four treatment options: modify, avoid, share or retain.
| Ref | Decision | Continuity measure | Owner and date | Target level |
|---|---|---|---|---|
| R-03 | Modify | Tabletop exercise this quarter, full recovery test within 12 months | Business Continuity Manager, Q4 | 8 |
| R-01 | Modify | Standby generator for refrigeration, fuel supply contract | Facilities Manager, Q1 | 6 |
| R-02 | Modify | Offline, immutable backups and a tested ERP restore within 8 hours | IT Manager, Q4 | 8 |
| R-04 | Modify | Qualify a second supplier with a call-off contract | Procurement Manager, Q1 | 6 |
| R-05 | Modify | Documented manual order process for EDI outages | IT Manager, Q4 | 6 |
After treatment, every risk is expected to sit at or below the appetite line. Each treatment has a named owner and a date, and the risk owner signs off the residual level. That sign-off is the piece most often missing when a certification auditor samples the register.
Step 4: What the Business Continuity Risk Assessment Example Tells Management
A business continuity risk assessment is only useful if it changes decisions. From this register, Kestrel’s management can see three things at a glance:
- The biggest exposures are concentrated. Power, the ERP and one supplier account for most of the risk above the line. That is where the continuity budget should go first.
- Testing is a control in its own right. The untested plan is rated higher than any single physical threat. Exercising the plan reduces every other risk at once.
- Some familiar risks need no spend. Fire and flood are within appetite with the arrangements already in place, which frees budget for the risks that are not.
How to Build Your Own
You can copy the structure of this business continuity risk assessment example directly:
- Start from your business impact analysis, so the scope is your prioritized activities and the resources they need.
- Define impact in terms of your recovery objectives, not only money.
- Write every risk as a scenario with a weakness, not just an event name like “fire”.
- Record the existing arrangements and the reason for each rating.
- Give every risk above the line a decision, a continuity measure, an owner, a date and a target.
- Repeat the assessment at planned intervals, usually once a year, and after any significant change.
The quickest way to produce the same output for your own organization is our free business continuity risk assessment tool. It imports your business impact analysis as the scope, offers 32 disruption scenarios with the continuity measures that usually treat them, and gives you a heat map and findings straight away. The optional report adds the register, treatment plan and a live Excel workbook.
Frequently Asked Questions
Is a business continuity risk assessment mandatory under ISO 22301?
Yes. Clause 8.2 requires both a business impact analysis and a risk assessment as part of the business continuity management system, and a certification auditor will expect to see evidence of each. A business continuity risk assessment example like the one above is the kind of record they sample.
How is this different from an information security risk assessment?
It covers anything that could stop your prioritized activities, including events with no security element such as power failures, supplier insolvency or loss of key people, and it rates impact by disruption rather than by loss of confidentiality or integrity.
Should the risk assessment come before or after the BIA?
Usually after. The BIA identifies what must be protected and how quickly it must recover; the risk assessment then looks at what threatens those activities. Many organizations iterate between the two in the first year.
Can I reuse this business continuity risk assessment example as a template?
Yes, the structure transfers directly: criteria tied to your recovery objectives, scenarios with a weakness, existing arrangements, ratings with a rationale, and a treatment plan with owners and dates. Replace the scenarios and ratings with your own; copying someone else’s ratings defeats the purpose.
How many risks should the register contain?
Enough to cover every prioritized activity and critical resource. For a single-site business, 15 to 30 well-written scenarios is typical; group near-duplicates rather than listing every variation.
For the full set of policies, plans and registers that sit around this assessment, see the ISO 22301 Toolkit.