Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

Business continuity risk criteria scales diagram

Business Continuity Risk Criteria: The Essential 2026 Guide to Setting Scales and Thresholds

Business continuity risk criteria are the agreed scales and thresholds you use to decide how serious a disruption risk is and what must be done about it. Without them, two people can score the same threat differently, and leaders cannot tell which risks need money or attention first.

This guide explains how to build business continuity risk criteria that link to your impact analysis, how to set thresholds and approvals, and how to keep the scales usable. It supports your risk register and your risk treatment decisions.

What business continuity risk criteria are for

Criteria turn opinion into a repeatable decision. They define how impact and likelihood are measured, when a risk is tolerable and who approves exceptions. ISO 22301:2019 expects an organization to assess continuity risks at planned intervals and to base decisions on defined criteria, and the standard is listed at ISO 22301:2019 on iso.org.

Good criteria also help you compare unlike risks, such as a supplier outage and a flood, on the same footing.

Free business impact analysis

How long can each activity really be down?

Rate the impact of an outage over time, set RTOs and maximum tolerable periods of disruption, map the people, systems and suppliers behind each activity, and get a recovery sequence back, free.

Run the free business impact analysis →  or  View premium report sample

Start from the business impact analysis

Continuity impact should be expressed in the same terms as your impact analysis: time to disruption becoming unacceptable, financial loss, customer harm, legal breach and reputational effect. If the analysis states a maximum tolerable period of disruption for an activity, your top impact level should match it.

The guide to the maximum tolerable period of disruption shows how to derive those limits.

Designing impact scales for business continuity risk criteria

Use five levels unless you have a reason not to. Define each level with concrete values: hours of downtime, revenue at risk, number of customers affected and regulatory consequence. Avoid words like “significant” without numbers.

Tailor the values to your size. A four-hour outage might be trivial to a consultancy and severe to a trading platform. Use the worked table in this article as a template only.

LevelImpact on operationsLikelihood in a yearTypical response
1 LowDisruption under 4 hours, no customer effectLess than 1 in 20Accept and monitor
2 MinorHalf a day, limited customer delay1 in 20 to 1 in 10Owner accepts
3 ModerateUp to 1 day, some customer harm1 in 10 to 1 in 4Treat or accept with plan
4 MajorSeveral days, contractual breach1 in 4 to 1 in 2Senior approval and treatment
5 SevereBeyond maximum tolerable periodMore than 1 in 2Executive action

Designing likelihood scales

Express likelihood as frequency bands over a stated horizon, usually one year, so that scenario workshops can use history and judgement. Note that rare events with severe impact, such as regional power loss, may have little history, so use external data and expert estimates and record the sources.

Keep band boundaries clear enough that assessors do not argue over which side of a line a risk falls on.

Combining scores across impact dimensions

Decide how to combine dimensions before you start scoring. The simplest rule is that the highest rated dimension determines the impact level, which suits safety-critical and regulated settings. Alternatives include weighting each dimension or averaging, but these can hide a severe outcome in one area. Write the rule down and give an example so assessors apply it the same way each time.

Setting thresholds and appetite

Thresholds turn scores into decisions. For example, scores of one to six may be accepted by the risk owner, seven to twelve need a treatment plan, and thirteen or more need executive approval. Link them to your stated risk appetite so that the numbers reflect board intent.

Free business continuity risk assessment

What could stop your most important activities?

List your prioritized activities and what they depend on, pick from 32 disruption scenarios, rate them and choose continuity measures for each. Built to ISO 22301 clause 8.2.3, and free.

Run the free continuity risk assessment →  or  View premium report sample

Record the thresholds in your procedure and test them on real risks before you finalize them.

Adding time-based criteria such as RTO and RPO

Continuity risk has a time dimension that generic scales miss. Compare the recovery time you can demonstrate with the recovery time objective the business needs, and count a gap as an impact driver. The guide to RTO and RPO explains those measures.

A risk that would push recovery beyond the objective should score high regardless of how unlikely it looks.

Deciding who approves what

Assign approval levels by score. Owners can accept low residual risk, department heads take the middle band and executive management or the board takes the top. Write these authorities down.

Approval keeps continuity risk from being ignored: someone with authority has to say yes to living with it.

Reputation, people and safety in business continuity risk criteria

Some of the worst continuity impacts are hard to price. Add rows to your scale for harm to people, loss of customer trust and public attention. Injury or loss of life should sit at the top level regardless of cost, and prolonged loss of a key service to vulnerable customers deserves a high rating even when revenue impact is modest. For reputation, use observable markers such as regional or national media coverage, regulator enquiries or a spike in complaints. Concrete markers help assessors avoid subjective arguments.

Keep the scale coherent: a level should not be high on money but low on safety unless the definition says the highest applicable dimension wins.

Testing the criteria before adopting them

Take five to ten real scenarios and have several people score them independently. If scores differ by more than one level, the definitions need work. Adjust, retest and only then publish.

Also test edge cases, such as a low-likelihood but catastrophic event, to confirm the matrix does not bury it.

Money and law give impact scales their sharpest edges. Express financial impact either in absolute amounts or as a share of revenue or operating profit, and state which you use. Add legal and contractual triggers, for example breach of a service level agreement with penalties, failure to meet a regulatory reporting deadline or loss of a licence to operate. Sector rules such as operational resilience regimes for financial firms may set minimum expectations, so check the requirements that apply to you. Recording these anchors makes it easier to defend scores to auditors and to regulators.

Where losses can be insured, score the gross impact first and then note the insurance as a treatment, so cover does not hide the underlying exposure.

Common mistakes when setting the criteria

Watch for these problems.

  • Scales without numbers, so everything drifts towards “medium”.
  • Impact levels that ignore the maximum tolerable period.
  • Thresholds copied from another organization.
  • No approval authority for high scores.
  • Criteria never reviewed after the business changes.

Keeping the criteria consistent across departments

A single set of criteria across the business lets leaders compare risks from different teams. Allow local additions, such as site-specific examples, but keep the core scales fixed. Central ownership by the continuity lead, with change control, prevents drift.

Communicating the criteria to risk owners

Criteria only work when the people scoring risks understand them. Give owners a one-page summary of the scales, thresholds and approval levels, with two worked examples drawn from your own business. Offer a short briefing when new owners join, and refresh it whenever the criteria change. Clear communication reduces disputes at review meetings and improves the quality of the scores that reach senior management.

Make the summary easy to find, for example by attaching it to the register template and linking it from the continuity procedure.

Reviewing business continuity risk criteria over time

Review the criteria at least annually and after major changes: a new product line, acquisition, regulatory shift or significant incident. Keep old versions so past scores can be interpreted correctly, and note when rescoring is needed after a change. See the guide to risk assessment example for how scores are applied in practice.

Applying the criteria to continuity scenarios

Use the scales during scenario workshops. Take a plausible event, such as loss of a data centre, and walk through the impact on each critical activity, then assign a level for each dimension and a likelihood band. Record the reasoning next to the score. Over time, the scenarios become a library that speeds later assessments and shows how criteria behave in practice.

Documenting and using the criteria

Put the criteria in the continuity risk procedure and attach them to the register template, so every assessor sees the same definitions. If you would prefer a ready structure, the Business Continuity Risk Assessment Report and Workbook includes scoring fields and a workbook that applies consistent scales to each assessment.

Business continuity risk criteria FAQ

What are business continuity risk criteria?

They are the scales, thresholds and approval rules used to score continuity risks and decide whether to accept or treat them.

How many levels should the scales have?

Five is common because it balances precision and simplicity, though three or four can work for small organizations.

Do criteria need to match the business impact analysis?

Yes. Impact levels should use the same measures and align the top level with the maximum tolerable period.

Who approves the criteria?

Senior management should approve them, since they define how much risk the organization is prepared to carry.

How often should criteria be reviewed?

At least annually and after any major change or incident.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.