Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

Business Impact Analysis questionnaire with 30 essential questions for governance and risk.

Business Impact Analysis Questionnaire: 30 Essential Questions (2026)

A business impact analysis questionnaire is how most organizations collect the raw material for a BIA, and it is also where most BIAs go wrong. Ask activity owners “how long can you be without your systems?” and you get wishes, not data. Ask the right questions in the right order and you get answers you can score, compare and defend to an auditor.

Below are 30 questions, grouped the way ISO 22301:2019 clause 8.2.2 structures the analysis, with a note on why each group matters and what to do with the answers.

How to run a business impact analysis questionnaire

The questionnaire works best as the first half of a two-step process, not as the whole thing:

  1. Agree the impact criteria first. Clause 8.2.2 a) requires impact types and criteria to be defined before any assessment. Send them with the questionnaire so every respondent scores against the same scale.
  2. Send it to activity owners, not department heads. The person who runs payroll knows what happens when it stops. The finance director knows in general terms.
  3. Give a deadline of about two weeks and offer a 30-minute call to anyone who gets stuck.
  4. Follow up with a short interview to challenge and validate the answers, then a consolidation workshop where owners see each other’s numbers.

The questionnaire collects. The interview and workshop test. Skip the second step and you will publish whatever each manager thought would get their activity prioritized.

Section 1: The activity (questions 1 to 5)

  1. What is the activity, in one sentence, and which product or service does it support?
  2. Who owns it, and who deputizes when the owner is away?
  3. How many people perform it in a normal week, and where?
  4. Does the workload vary by time of day, month or year? When is the worst possible time for it to stop?
  5. Which other internal activities depend on its output, and which does it depend on?

Question 4 matters more than it looks. Payroll can seem tolerant until you score it three days before pay day. A business impact analysis questionnaire that does not ask about peak periods will understate the impact of every cyclical activity.

Free business impact analysis

How long can each activity really be down?

Rate the impact of an outage over time, set RTOs and maximum tolerable periods of disruption, map the people, systems and suppliers behind each activity, and get a recovery sequence back, free.

Run the free business impact analysis →

Section 2: Impact over time (questions 6 to 11)

Clause 8.2.2 c) asks for impacts assessed over time. Give respondents a grid with your agreed impact types across the top and time points down the side (for example 4 hours, 1 day, 3 days, 1 week, 2 weeks, 1 month), and ask them to score each cell.

  1. If this activity stopped completely at the worst possible time, what would the financial impact be at each time point?
  2. What would customers experience at each time point, and when would the first key customer escalate or leave?
  3. Are there legal, regulatory or contractual deadlines this activity supports? What is the earliest one that would be missed?
  4. What would the reputational impact be at each time point?
  5. What would the impact on staff be (overtime, unpaid wages, safety)?
  6. At which time point does the impact first become unacceptable, and what makes it so?

Question 11 produces the maximum tolerable period of disruption (MTPD). Asking it last, after the respondent has worked through the grid, gives a far more honest answer than asking it first.

Section 3: Recovery objectives (questions 12 to 16)

Clause 8.2.2 e) asks for prioritized time frames for resuming each activity at a specified minimum acceptable capacity. This section of the business impact analysis questionnaire turns the impact grid into targets.

  1. How soon must the activity resume to stay safely inside the point you gave in question 11? This is the recovery time objective (RTO).
  2. What is the minimum level of output that would be acceptable at first, as a share of normal volume or a named subset of work?
  3. How long could you run at that minimum level before full capacity is needed?
  4. How much data or work in progress could you afford to lose and re-create? This is the recovery point objective (RPO).
  5. Once the activity resumes, how long would it take to clear the backlog?

Question 16 is the one most templates leave out. An RTO that leaves no time to clear the backlog before the MTPD is reached is not really an RTO. For how these numbers relate, see RTO and RPO: the four recovery metrics.

Section 4: People and skills (questions 17 to 20)

  1. What is the minimum number of people needed to deliver the minimum capacity from question 13?
  2. Which tasks can only be done by one or two named people?
  3. Can the activity be done remotely, and for how long?
  4. Could staff from another team be redeployed, and how much training would they need?

Question 18 regularly produces the most important finding in the whole analysis: the key person dependency nobody wrote down.

Section 5: Systems, data and records (questions 21 to 24)

  1. Which applications, systems and shared drives does the activity use? Which are essential for the minimum capacity?
  2. Which paper or offline records are needed?
  3. If the essential systems were unavailable, is there a manual workaround? How long could it be sustained?
  4. Do you know what the IT recovery time for each essential system actually is, or are you assuming?

Question 24 is deliberately pointed. When the activity RTO and the system’s real recovery capability are placed side by side, the gaps show up immediately, and closing those gaps is the practical purpose of the whole exercise.

Section 6: Premises, equipment and suppliers (questions 25 to 28)

  1. Does the activity need a specific site, or specialist equipment?
  2. Which external suppliers or service providers does it depend on?
  3. For each critical supplier, is there an alternative, and how quickly could it be used?
  4. Do you know what each critical supplier has committed to in terms of recovery time?

Clause 8.2.2 f) specifically requires dependencies, including partners and suppliers, to be determined. These answers feed straight into the ISO 22301 risk assessment, which looks at what could take each dependency away.

Section 7: Workarounds and lessons (questions 29 and 30)

  1. Has this activity been disrupted before? What happened, and what worked?
  2. What single change would most improve its ability to recover?

These two open questions often surface fixes that are cheap and obvious to the people doing the work, and invisible to everyone else.

Questionnaire vs interview: which should you use?

QuestionnaireInterview
Best forCollecting consistent data from many activity ownersChallenging and validating the answers
Effort for the BIA leadLow to send, moderate to consolidateHigh, roughly an hour per activity
Quality of answersVariable, often optimisticHigher, because assumptions get questioned
Consistency across activitiesHigh, if criteria are fixedDepends on the interviewer
Audit evidenceCompleted formsInterview notes, ideally signed off

Most mature programs use both: the business impact analysis questionnaire for breadth, then interviews for the activities that end up prioritized.

Common business impact analysis questionnaire mistakes

  • Letting respondents set their own criteria. If “severe” means something different in every reply, the answers cannot be compared.
  • Sending it to IT to complete. IT can tell you how long a system takes to restore. Only the business can tell you how long it can wait.
  • Asking for the RTO before the impact grid. The answer will be “immediately” for everything.
  • Treating returned forms as the finished BIA. They are raw data until someone has consolidated, challenged and signed them off.

Frequently asked questions

How long should a business impact analysis questionnaire be?

Long enough to cover the activity, impacts over time, recovery objectives, and resources and dependencies, which usually means 25 to 35 questions. Much shorter and something required by clause 8.2.2 is missing. Much longer and response quality drops.

Who should fill in the questionnaire?

The owner of each activity, with input from the people who perform it. Department heads should review and sign off, not complete it on everyone’s behalf.

Is a questionnaire enough for ISO 22301?

The standard does not prescribe the collection method. What an auditor will look for is that the analysis meets clause 8.2.2 and that the results are consistent, justified and reviewed. Questionnaires alone rarely achieve that without follow-up.

How often should the questionnaire be repeated?

Clause 8.2.1 requires the analysis to be reviewed at planned intervals and when significant changes occur. Most organizations re-run it annually, and for individual activities whenever a new system, site, supplier or major customer changes the picture.

Where this leaves you

A good business impact analysis questionnaire does most of its work through the order of its questions: criteria first, impacts over time next, targets last, and dependencies checked against reality. To see what the consolidated answers turn into, read our worked business impact analysis example, and for the overall method, our business impact analysis guide.

If you would rather start from ready-made documents, the ISO 22301 Toolkit includes a Business Impact Analysis Tool, a BIA report template and a completed worked example alongside the rest of the documented BCMS, for $99.

References

More on business continuity

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.