Business & Leadership Wednesday, July 29, 2026
Spotlight · Operations & Project Delivery

How to Conduct a Business Impact Analysis (BIA)

A step-by-step guide to conducting a business impact analysis: identifying critical activities, quantifying downtime, and setting recovery targets.

How to Conduct a Business Impact Analysis (BIA)

Ask a leadership team which of their operations they cannot live without, and you will usually get a confident answer that turns out to be wrong. The business impact analysis, or BIA, exists to replace that guess with evidence. It is the analytical core of any serious continuity program, and getting it right is what keeps the rest of the plan from being fiction. Here is how to conduct one.

What a business impact analysis is

A BIA identifies the activities an organization must perform to survive, then quantifies what happens, and how fast, if each one stops. It answers three questions in order: which processes are critical, how much disruption each can tolerate, and what those processes depend on. The output is a prioritized picture of the business that tells you where to spend recovery effort first. It is the step that feeds the recovery targets in our guide to business continuity versus disaster recovery, and it is the foundation the rest of a business continuity plan is built on.

Step one: list your critical activities

Start with what the organization actually does to generate revenue, meet obligations, and protect its reputation. Work with the people who run each function, not just executives, because the dependencies that matter are often invisible from the top. The goal is a short list of activities the business cannot do without, not an inventory of everything it does.

Step two: estimate impact over time

For each critical activity, estimate the financial and operational damage if it is unavailable for one hour, one day, three days, and a week. Impact is rarely linear. A payroll run can slip a day with little effect and become a crisis at a week. Mapping impact against time is what reveals your true priorities and prevents the common error of treating everything as equally urgent.

Step three: set recovery targets

The time curve gives you two numbers for each activity:

  • Recovery Time Objective (RTO): how quickly the activity must be restored.
  • Recovery Point Objective (RPO): how much data you can afford to lose, which sets backup frequency.

Set these against reality. An aggressive RTO that your team cannot actually meet is worse than an honest one, because it manufactures false confidence.

Step four: map dependencies

Finally, document what each critical activity relies on: people and their skills, systems and data, facilities, and outside suppliers. Dependencies are where continuity plans quietly fail, because a process you protected can still stop when a single vendor or a single specialist becomes unavailable. That is why supplier mapping deserves its own discipline, which we cover in supply chain resilience.

Done well, a BIA turns “we think this matters” into “this is what matters, this is how fast we need it back, and this is what it depends on.” That clarity is the difference between a plan that holds and one that does not, a theme that runs through our guide to workplace emergency preparedness. More is in our Operations & Project Delivery section.

Frequently asked questions

What is the difference between a business impact analysis and a risk assessment?

A BIA identifies critical activities and the impact of losing them, focusing on consequences. A risk assessment identifies the threats that could cause the loss, focusing on causes. A complete continuity program uses both.

What does a BIA produce?

A prioritized list of critical activities with recovery targets (RTO and RPO) and a map of the people, systems, and suppliers each activity depends on.

Who should be involved in a business impact analysis?

The people who actually run each function, alongside leadership. Frontline staff surface the dependencies and workarounds that are invisible from the executive level.

General guidance, not legal or compliance advice. See Ready.gov and ISO 22301 for authoritative detail.