
Most business impact analyses die in week three. The kickoff went well, the questionnaire went out, a third of the process owners answered, and the rest are sitting on a second reminder from someone in "Resilience" they have never met. By the time the stragglers reply, the early answers are out of date and the program manager is quietly copying last year's numbers into the gaps. The report gets written anyway. Its recovery targets are whatever owners guessed late on a Friday, and nobody above director level has read it.
The fix is rarely a better template. It is a smaller ask, a sharper conversation, and a method that turns answers into decisions executives can see and sign. The sequence below is the one that tends to hold up in banks, broker-dealers and other firms where the BIA also has to survive an examiner.
Step 1: Scope by process, and be strict about granularity
Start from what the organization delivers rather than from the org chart. A department is a cost center. A process has an output that a client, a regulator or another team is waiting for. "Treasury operations" is not a BIA unit; "releasing outgoing client wires before the Fedwire cutoff" is.
A useful test: the owner should be able to describe the process in one sentence with a verb and an output, and should be able to say who outside the team would notice within a day if it stopped. If the description needs three sentences, you probably have two processes. If nobody would notice for a month, record it as deferrable and skip the interview.
Two scoping decisions save more time than anything else:
- Send drafts, not blank forms. Pull the previous BIA, the application inventory, the vendor list and the org chart, and pre-populate what you can. People correct a wrong answer far faster than they write a right one from scratch.
- Tier the effort. Decide up front which processes get a full interview and which get a short confirmation. For the stable long tail, last cycle's ratings plus one question ("has anything material changed?") is usually enough.
Write the scope down, including what is out and why. Auditors and examiners ask about exclusions, and a documented rationale ends that line of questioning quickly. Our briefing on surviving a BCM audit or regulatory examination covers what else they tend to probe.
Step 2: Choose interview, survey, or a blend
Surveys scale. Interviews get the truth. Use a survey for low-impact processes, confirmations and widely dispersed organizations. Use an interview for anything that touches clients, money movement, regulatory deadlines or other teams' inputs, and for any process where last cycle's answers looked implausible.
The blend that works best in practice is a pre-populated survey sent a week ahead, followed by a 45-minute interview for the top tier that challenges and completes it. A few habits make those interviews productive:
- Bring two people from the continuity side: one asks, one writes. Nobody listens well while typing.
- Invite the person who actually does the work as well as the owner. The analyst who runs the reconciliation knows the workaround; the managing director knows the client.
- Never say "RTO" in the room. Ask business questions instead. If this stopped at 9 a.m. on the last business day of the quarter, when would someone outside your team notice? When would it start costing money? When would we have to tell a regulator or a client in writing?
- Ask what they would do with pencil, paper and a phone. The answer tells you whether a manual workaround exists and how long it lasts.
- Ask about the calendar. Month-end, quarter-end, payroll Fridays, tax deadlines and option expirations change the answer more than any other variable.
Good BIA interviewing is a learnable skill, and it is one of the clearer markers between analyst and program-lead roles on most business continuity career paths. Debrief after each session.
Step 3: Fix the impact categories and time buckets before anyone rates anything
Ratings are only comparable if everyone uses the same yardstick. Agree on the categories, the scale and the time buckets with finance and risk before the first interview, and do not let owners redefine them.
Five categories cover most firms: financial, customer, regulatory and legal, reputational, and operational (backlog and workload). Define a 1 to 5 scale with plain-language anchors. Tie the financial anchors to thresholds the firm already uses, such as its risk appetite statement or its operational loss reporting levels, so a "4" means the same thing in every division.
| Rating | Meaning (example anchors) |
|---|---|
| 1, Negligible | Absorbed in normal operations |
| 2, Minor | Overtime, small fees, a handful of client complaints |
| 3, Moderate | Measurable loss, client escalations, internal incident reporting |
| 4, Major | Material loss, regulatory notification or contractual breach, press interest |
| 5, Severe | Threat to licenses, liquidity or the firm's role in a market |
Time buckets should match real decision points. In financial services the first day matters hour by hour because of intraday cutoffs, so a common set is 0–4 hours, 4–24 hours, 1–3 days, 3–7 days and more than 7 days. Use the same buckets enterprise-wide or the roll-up will be meaningless.
Here is an illustrative rating for one process, outgoing client wire transfers at a mid-size bank, rated as if the disruption began at the worst plausible time:
| Impact category | 0–4 hrs | 4–24 hrs | 1–3 days | 3–7 days | 7+ days |
|---|---|---|---|---|---|
| Financial (fees, interest claims, funding costs) | 1 | 3 | 4 | 5 | 5 |
| Customer (missed closings, payroll, settlements) | 2 | 4 | 5 | 5 | 5 |
| Regulatory and legal | 1 | 2 | 4 | 5 | 5 |
| Reputational | 1 | 3 | 4 | 5 | 5 |
| Operational (backlog, manual workload) | 2 | 3 | 4 | 5 | 5 |
| Highest rating | 2 | 4 | 5 | 5 | 5 |
The shape is what matters. Impact turns "major" in the 4–24 hour bucket and severe within three days. That is a same-day process, whatever the owner assumed beforehand.
Step 4: Derive MTPD, then RTO, then RPO
Maximum tolerable period of disruption (MTPD) comes from the grid, using a threshold that leadership sets once for the whole firm. A common rule: the MTPD is the start of the first time bucket in which any category reaches 4. For the wire example that lands inside the first business day, and the interview sharpens it. Wires not released before the cutoff roll to the next day, so the practical MTPD is the same-day cutoff.
Recovery time objective (RTO) must be shorter than the MTPD, with room for three things people forget: the time to detect and declare, the time to stand up the workaround or failover, and the time to clear the backlog that built up while you were down. An RTO equal to the MTPD is a plan to fail on schedule. For the wire process, an RTO of around four hours from the start of the business day leaves time to work the queue before the cutoff. That process RTO then drives the application targets. The payment hub has to be back earlier than the process, because people need it running before they can start catching up.
Many programs also record a minimum business continuity objective: the reduced level of service that is acceptable for a period. For wires, that might mean processing time-critical and high-value payments first and deferring the rest by a day.
Recovery point objective (RPO) is a data question, so ask it as one. "If the system came back missing the last two hours of entries, could you reconstruct them? From what source, and how long would it take?" For payments, the honest answer is usually that losing even a few minutes is dangerous, because you may not know which instructions already went out and you risk sending duplicates. The RPO is effectively near zero, and the reconciliation procedure matters as much as the replication. Our piece on setting RTO and RPO without guesswork goes further into the technical side.
Step 5: Capture dependencies the way recovery teams will use them
A BIA that stops at ratings is an inventory. The value is in the dependencies, recorded so the people restoring things can act on them. For each in-scope process, capture:
- People: minimum staffing to run at the reduced level, named skills, and any single person whose absence stops the work.
- Applications and data: which systems support which step, and the vital records needed to restart.
- Facilities and equipment: recorded lines, check scanners, secure printers, hardware tokens.
- Third parties: vendors, market utilities, correspondent banks, and the contract terms that govern their recovery.
- Internal upstream and downstream: whose output you consume and who consumes yours.
- Workarounds: what they are, who knows them, and how long they can carry the load before they break.
Then compare. If the wire process needs four hours and the payment hub's documented recovery capability is 24 hours, that gap belongs on a list with an owner and a date. The gap list is the most useful output of the whole exercise, and it is the page executives actually read.
Step 6: Validate with executives, not only owners
Owners rate their own processes high. Left alone, a BIA drifts toward everything being tier 1, which means nothing is. The cure is a calibration session with each business line head.
Show the roll-up sorted by MTPD. Challenge the outliers in both directions. Ask the forced-ranking question: if only five processes could come back in the first day, which five? Put the gap list next to the ratings, with rough costs to close each gap, so the conversation becomes a decision about money and risk rather than a debate about adjectives.
Record the outcome. Examiners and internal audit expect evidence of senior management review, and a dated approval beats an email thread. When an executive changes a rating, note who changed it and why.
Step 7: Keep it current without rerunning it
A full BIA every year exhausts the business. A better model is a full cycle every two to three years, with triggered updates in between and a light annual attestation for stable processes.
Triggers worth wiring into existing workflows include a reorganization, a new product, a new critical vendor, a system migration, an acquisition, and any incident or exercise that exposed a wrong assumption. The easiest way to catch them is to add one question to the change-management ticket and the vendor onboarding form: does this affect a process rated 4 or above within 24 hours?
Store the results as data, not as a 90-page document, so a changed target flows into the plan that depends on it. If your plans follow a structure like our annotated sample business continuity plan table of contents, the BIA summary and recovery targets have an obvious home near the front.
A checklist for the next cycle
- Scope written down, with exclusions and reasons.
- Drafts pre-populated from the last BIA, the application inventory and the vendor list.
- Impact categories, rating anchors and time buckets approved by finance and risk before kickoff.
- Interviews for the top tier, with the person who does the work in the room as well as the owner.
- MTPD threshold set once by leadership, not negotiated process by process.
- RTO shorter than MTPD, with explicit margin for detection, failover and backlog.
- RPO derived from reconstruction questions, not picked from a menu of hours.
- Dependency gaps listed with owners, dates and rough costs.
- Executive calibration completed and approval dated.
- Change and vendor triggers built into forms people already fill in.
If the next cycle does only the first three items and the last two well, it will still be better than most.



