Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

Business continuity risk treatment options linking assessed risks to prevention, protection and recovery measures

Business Continuity Risk Treatment Guide 2026

Business continuity risk treatment is the step that turns an assessment into action. Having listed the events that could disrupt critical activities and rated their likelihood and effect, the organization must decide what to do about each: prevent it, reduce its consequences, share the burden or knowingly accept it. Without that step, a risk register is a catalogue of worries, and the plan is a document that will not work when needed. This guide explains the options for business continuity risk treatment, how to choose between them, how to relate treatment to continuity strategies and plans, how to assign ownership and track progress, and what to record.

Where treatment fits in ISO 22301

ISO 22301:2019 sets the context in its operation clause. Organizations carry out a business impact analysis, assess the risks of disruption to prioritized activities, and then determine and select business continuity strategies and solutions, along with the resources needed to implement them. Risk treatment is the link between the assessment and the strategy: it asks what should be done about the risks found, and the strategy states how the organization will continue or recover when the risk materializes. You can view the standard’s listing at ISO 22301:2019 on iso.org, and our guide to ISO 22301 risk assessment covers the assessment step that feeds it.

Free business impact analysis

How long can each activity really be down?

Rate the impact of an outage over time, set RTOs and maximum tolerable periods of disruption, map the people, systems and suppliers behind each activity, and get a recovery sequence back, free.

Run the free business impact analysis →  or  View premium report sample

The options for business continuity risk treatment

General risk management guidance, such as ISO 31000, describes the choices available for treating risk. In continuity work they translate as follows.

OptionMeaningContinuity example
AvoidStop or change the activity that creates the riskRelocate a critical function away from a flood zone
Reduce likelihoodMake the event less likelyImprove maintenance, add fire suppression, harden systems
Reduce consequencesLimit the effect if it happensRedundant site, backups, cross-training, spare stock
Share or transferPass part of the burden to another partyInsurance, contractual service credits, outsourcing with resilience terms
AcceptTake the risk knowinglyRare, low-impact events documented and approved

Note that sharing risk does not remove the obligation to continue critical services. Insurance may repay a loss, but it will not restore a lost customer relationship or a regulatory license. Treat it as a financial protection alongside continuity measures, not a substitute.

Prevention, protection and recovery

A helpful way to structure treatments is in three layers. Prevention reduces the chance that an event occurs. Protection limits its damage when it does. Recovery restores operations within the required time. The right mix depends on the risk. For events you can influence, such as equipment failure, prevention is often the most cost-effective. For events you cannot, such as severe weather or a supplier’s collapse, protection and recovery matter more. Check that each high risk has at least one measure at each layer where a measure is possible.

Choosing among treatments

Use criteria that you set in advance, so that choices can be explained.

  1. Effectiveness. How much does it reduce the risk, and does it meet the recovery objectives from the impact analysis?
  2. Cost. What are the setup and running costs, compared with the loss it avoids?
  3. Feasibility and time. Can it be implemented soon enough, and do you have the skills and suppliers?
  4. Side effects. Does it create new risks, such as complexity, new dependencies or security exposure?
  5. Fit with appetite. Does the residual risk fall within what leadership will accept?

Compare at least two options for the most significant risks, and record why the chosen one was preferred. Our guide to business impact analysis versus risk assessment shows how the recovery objectives that constrain the choice are derived.

Match treatments to recovery objectives

A treatment that cannot meet the recovery time objective for the activity it protects is not adequate, however cheap. If an activity must resume within four hours, a plan to rebuild from backups over two days is not a valid treatment for the loss of its system. Use the recovery targets as a filter to remove options that cannot deliver, then compare cost among those that can.

Turning treatments into continuity strategies

Strategies describe how you will maintain or recover activities, using options such as alternative sites, remote working, mutual aid arrangements, manual workarounds, stockholding, alternative suppliers, cross-trained staff and standby technology. Each strategy needs resources: people, information, technology, premises, equipment and suppliers. Record the resources required, who provides them and what agreements support them. Our guide to single point of failure analysis shows how to find and treat dependencies that would defeat a strategy.

Ownership, budget and tracking

Every treatment needs a named owner, a budget, a due date and a way to show completion. Add each to the risk register, and review progress at a regular meeting. Distinguish between a treatment planned, in progress and in place, and between in place and tested. Our guide to the business continuity risk register shows how to structure the record. Report overdue treatments for the highest risks to senior management, since they represent exposure that leadership has agreed to remove and has not yet.

Free business continuity risk assessment

What could stop your most important activities?

List your prioritized activities and what they depend on, pick from 32 disruption scenarios, rate them and choose continuity measures for each. Built to ISO 22301 clause 8.2.3, and free.

Run the free continuity risk assessment →  or  View premium report sample

Budgeting and business cases for continuity measures

Continuity measures compete with other projects for funds, so present each significant treatment as a short business case. State the risk, the potential loss or obligation at stake, the recovery objective, the options compared, the recommended option with cost and the residual risk. Use figures from the impact analysis where you have them, such as revenue per hour or contractual penalties, and be honest about uncertainty. Leaders are more willing to fund a measure when they can see what it protects and what happens without it.

Break large measures into stages that deliver value early, for example protecting the most critical application first. Track spending against the plan and report changes. Where funds are limited, use the ranking of risks and the tolerable periods to explain what is being protected first, and record what has been deferred and the decision maker who accepted the deferral.

Testing that treatments work

A treatment is not proven until it has been exercised. Backups must be restored, failover must be triggered, alternative sites must be occupied, manual procedures must be followed by staff who have not done them before. Plan exercises that test the highest-risk treatments first, and record the outcomes, including failures. Our guide to the business continuity exercise explains how to design and run them. Use the findings to correct the plan and the risk ratings.

Handling residual risk after business continuity risk treatment

After treatment, rate the residual risk and compare it with your appetite. Where it remains too high, decide whether to add treatments, change the objective or formally accept it with senior approval and a review date. Do not let unacceptable residual risk drift. Also review risks that were accepted earlier, because changing circumstances can make an acceptable risk unacceptable.

A short worked example

A logistics company rates the loss of its single warehouse management system as a high risk to order fulfilment, with a tolerable period of eight hours. Options considered are a second data center with replication, a cloud-based standby, and a manual paper process with restoration from daily backups. The paper process cannot meet the objective and is rejected as the primary measure. The cloud standby costs less than a second data center and meets a four-hour target, so it is chosen, with a manual process retained as a fallback for reduced volume. The owner is the head of operations, the budget is approved, the standby goes live in the next quarter and a failover test is scheduled. The residual risk is rated medium and accepted by the executive committee.

Common mistakes in business continuity risk treatment

Organizations treat every risk the same way, choose measures without checking recovery objectives, rely on insurance alone, fail to assign owners, do not track completion, leave measures untested and forget to reassess residual risk. Another mistake is proposing treatments that create new single points of failure. A review by someone outside the project often finds these before an incident does.

Using a ready structure

If you want a starting structure for the assessment and its treatment plan, the Business Continuity Risk Assessment Report and Workbook provides a structured report, scoring and a working register with treatment fields for owners, dates and status. You can also see a completed record in our business continuity risk assessment example. Whatever tool you use, make business continuity risk treatment a tracked process that ends in tested measures.

Business continuity risk treatment FAQ

What is business continuity risk treatment?

It is the process of choosing and implementing measures to deal with risks of disruption: avoiding, reducing, sharing or accepting them, and linking them to continuity strategies and plans.

Can insurance be the only treatment?

Usually not. Insurance may cover financial loss but does not restore operations or customers, so it should complement continuity measures for critical activities.

How do I choose between treatments?

Compare effectiveness against recovery objectives, cost, feasibility, side effects and fit with risk appetite, and record why the chosen option was preferred.

Who should own a treatment?

A named manager with authority and budget for the area concerned, with progress tracked in the risk register and reviewed at a regular meeting.

How do I know a treatment works?

Test it through exercises such as restoring backups, triggering failover or running the manual process, and record and correct any failures.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.