Why a Business Impact Assessment matters
Referenced against ISO 22301 — the international standard for Business Continuity Management Systems (BCMS).
What ISO 22301 says
ISO 22301 (Clause 8.2.2) requires organizations to perform a Business Impact Analysis to determine priorities and requirements for continuity. Specifically, the standard requires you to:
- Identify activities that support the delivery of products and services.
- Assess the impacts over time of not performing these activities.
- Set prioritized timeframes for resuming activities at a specified minimum acceptable capacity (the MTPD and RTO).
- Identify dependencies and supporting resources for these activities, including suppliers and outsource partners.
BIA → BCP → DRP
The BIA is the evidence base that justifies every downstream continuity investment:
- Business Continuity Plan (BCP) — driven by BIA outputs (RTO, MBCO, dependencies) to describe how the organization continues delivering products and services during disruption.
- Disaster Recovery Plan (DRP) — the technology arm of the BCP; the BIA’s RPO defines the acceptable data-loss window that DR architecture (backups, replication, failover) must meet.
Without a BIA you cannot defensibly set an RTO or RPO. Without RTO/RPO your BCP and DRP become opinions rather than engineered controls.
How Contanam BIA aligns
- Per-line-of-business questionnaires seeded with ISO 22301-aligned prompts.
- Explicit RTO / RPO / MTPD capture that feeds into your BCP and DRP.
- Risk register with likelihood × impact scoring and cost estimation.
- Evidence library reusable across BIAs, so audit trails compound.
- Framework mapping — ISO 27001, GDPR, CMMC, HIPAA, NIST 800-53 — at the company level.