A business impact analysis is the piece of work every continuity plan rests on, and the piece most organisations skip. Without it you are guessing which systems come back first, how many people you need on day one, and how long you can afford to be down before the damage stops being recoverable.
This tool walks you through one, activity by activity, and scores your own numbers against each other. It is free to complete, your answers save as you go, and it is structured to ISO 22301:2019 clause 8.2.2 so the output stands up as audit evidence rather than as a worksheet.
What this tool covers
Clause 8.2.2 asks an organisation to do five things. This walks through all of them in order:
- Define your impact types and criteria. What counts as a minor loss and what counts as severe, written down before you rate anything. It is the question an auditor asks first and the one most analyses cannot answer.
- Identify the activities that support your products and services. Not departments — the things the business actually does that a customer or a regulator would notice stopping.
- Assess the impact over time. Four hours of downtime and four weeks of downtime are different problems. You rate each activity at each point in time, across the categories you chose.
- Set prioritised timeframes for resumption. A recovery time objective for each activity, tested against the maximum tolerable period of disruption.
- Record the dependencies. The systems, suppliers, sites and vital records each activity needs before it can restart.
What it tells you for free
As soon as you finish, you see your recovery sequence — which activities come back first and in what order — and every place your own numbers contradict each other.
That second part is the useful one. The most common defect in a business impact analysis is a recovery time objective that sits at or beyond the maximum tolerable period of disruption. It means the organisation has committed to a target that, even if met exactly, still leaves it past the point it said it could not survive. The tool finds those and names them, at no cost.
RTO, MTPD and RPO
Three numbers do most of the work in a BIA, and they are routinely confused:
- MTPD — the maximum tolerable period of disruption. The point past which the organisation’s viability is genuinely threatened. It is a fact about your business, not a target.
- RTO — the recovery time objective. Your target for having the activity working again. It must be shorter than the MTPD, or it is not a target at all.
- RPO — the recovery point objective. How much data you can afford to lose, measured backwards from the moment of failure.
Our guide to RTO and RPO covers how to set them defensibly, and the business impact analysis guide covers the method in full.
Where this fits
A BIA is the input to almost everything else in a continuity programme. Your recovery strategies are chosen to meet the RTOs it sets. Your business continuity plan is built around the sequence it produces. Your exercises test whether the targets it set are achievable. Get it wrong and everything downstream inherits the error.
It also serves more than ISO 22301. The same analysis feeds a SAMA business continuity submission, DORA operational resilience work, and the ICT continuity requirements in ISO 27031.
Frequently asked questions
Is it really free?
Yes. The whole questionnaire, your recovery sequence and every error found in your own numbers cost nothing. A free account is needed to view the summary. The full report and the live workbook are a separate one-off purchase.
Do I have to finish in one sitting?
No. Every field saves the moment you enter it, and the analysis reopens where you left it — on the same device, or on another one once you have an account.
How long does it take?
Longer than a gap assessment, because you are producing original work rather than answering a checklist. A focused first pass over ten to fifteen activities takes one to two hours. Most organisations do it across two sessions.
What happens to the information I enter?
It is stored with your analysis so you can come back to it, and it is never shared. Supplier and system names are the most sensitive part, so if you would rather not have real names here, use internal codes instead — nothing in the analysis depends on the name being real.
Is this the same as a business continuity plan?
No. A BIA works out what has to come back and how fast. A continuity plan sets out how you will do it. The BIA comes first, and the plan is built to meet what it found.
How many activities should I include?
Start with the activities whose failure a customer or regulator would notice, which is usually somewhere between eight and twenty for a small or mid-sized organisation. A BIA covering everything the business does is a project; a BIA covering what matters is a morning.