A business impact analysis tells you which activities matter most and how quickly they must come back. A business continuity risk assessment tells you what is most likely to stop them. ISO 22301 clause 8.2.3 asks for both: identify the risks of disruption to your prioritized activities and the resources they need, analyse and evaluate them against criteria you set, and decide which need treatment.
This tool takes you through it in that order. List your prioritized activities and the premises, systems, suppliers, people and records behind them, pick risks from a library of 32 disruption scenarios, rate them and choose the continuity measures that treat each one. It is free, and your answers save as you go.
Premium report
See what the premium business continuity risk assessment report looks like
A worked sample for a fictional organization: the ranked register of disruption risks, heat maps before and after treatment, the continuity measures chosen for each, every finding with the document that closes it, an AI-assisted analysis with a 30/60/90-day roadmap, plus the live Excel workbook.
Other free risk assessments: Information Security Risk Assessment (ISO 27001) Privacy Risk Assessment (ISO 27701) Enterprise Risk Assessment (ISO 31000) AI Risk Assessment (ISO 42001) Data Protection Impact Assessment (GDPR) Transfer Impact Assessment (GDPR) AI System Impact Assessment (ISO 42005) Legitimate Interests Assessment (GDPR) Third-Party Risk Assessment (ISO 27001)
What this tool covers
- Scope and criteria. Likelihood and impact scales, with impact described by how long and how costly a disruption would be, and the appetite line.
- What is in scope. Prioritized activities and the resources they depend on, each with its criticality. If you have already run our business impact analysis, import it and this step is done for you.
- Risks. Scenarios from the library, from power and IT outages, ransomware and supplier failure to fire, flood, pandemic and recovery plans that were never tested, or your own.
- Analysis. Likelihood and impact for each risk, with the arrangements already in place and the reason for the rating.
- Treatment. Modify, avoid, share or retain, the continuity measures the treatment relies on, grouped by the ISO 22301 clause 8.3 resource categories, an owner, a date, a target level and the risk owner’s acceptance.
What you get, free
Your heat map against your own appetite line, the highest risks of disruption in priority order, a process score out of 100 that shows how complete and defensible the assessment is, and the findings an auditor would raise. Sign in and it stays in your account, ready for next year’s review.
The full report adds the complete register, heat maps before and after treatment, the treatment plan with its continuity measures, owners and due dates, and an AI-assisted analysis with a 30/60/90-day roadmap, with the register as a live Excel workbook.
Where this fits
The measures you choose here become your business continuity strategy and the backbone of your business continuity plan. For the method in full, read our guide to the ISO 22301 risk assessment, and for how the two analyses relate, BIA vs risk assessment. To see how far your continuity programme is from the standard, run the ISO 22301 gap assessment.
To see what a finished assessment looks like, read our business continuity risk assessment example, a complete worked register for a fictional manufacturer.
Frequently asked questions
Do I need a business impact analysis first?
It helps. The analysis tells you which activities are prioritized and what they depend on, which is exactly what this assessment’s scope needs. Import it and the scope is filled in, with the criticality of each item. You can also list the scope by hand.
What are continuity measures?
The arrangements that keep an activity going or bring it back: alternate sites, remote working, backups and recovery environments, second suppliers, cross-training, emergency communications, insurance and tested plans. Each scenario suggests the ones that usually treat it.
How is this different from an information security risk assessment?
It looks at anything that could stop your activities, including events with no security element such as fire, flood, strikes or a supplier going out of business, and it rates impact by disruption rather than by loss of confidentiality or integrity.
What happens to the information I enter?
It is stored with your assessment so you can come back to it, and it is never shared. You can delete an assessment permanently from your account at any time.
Is this a substitute for an independent assessment?
No. It is a self-assessment built from the information you enter, and Governance Docs does not review or verify it.
