The Purpose and Value of a Business Impact Analysis (BIA)
I am often asked the purpose and value of a Business Impact Analysis (BIA). The purpose of a BIA is to quantify the impact to the business (in dollars and cents) that the loss of a service would have. It is a valuable source of input when trying to ascertain the business needs, impacts and risks that the organization may face in the delivery of services. The BIA is an essential element of the overall business continuity process. It identifies the most important services to the organization and therefore will help to define the overall strategy for risk reduction and disaster recovery. At a more granular level this analysis enables the mapping of critical service applications and technology components to critical business processes. It is an invaluable input for Continuity, Strategy, Availability, Design, and Capacity Management and can have a significant impact on the cost of designing, delivering and maintaining these services based on their criticality as defined by the business.
The BIA’s strategic purpose is to show which parts of the business will be most affected by a major incident and what affect it will have on the company as a whole. The form these damages or losses may come in are:
- Loss of income
- Additional costs
- Damaged reputation
- Loss of goodwill
- Loss of competitive advantage
- Breach of law, health or safety
- Immediate and long term loss of market share
- Political, corporate or personal embarrassment
- Loss of operational capability
As part of the design phase of a new or changed service the BIA should be conducted to help enable a greater understanding about the function and importance of a service. Working with Service Level Management, this will allow the business to define:
- Acceptable levels and times of a service outage. How the degree of damage is likely to escalate after a service disruption, and the times of day, week, month or year when a disruption will inflict the greatest damage.
- The staffing, skills, facilities and services necessary to enable critical and essential business processes to continue to operate at minimum acceptable levels.
- The time within which all required business processes and supporting staff, facilities and services should be fully recovered.
- The cost the loss of a service has to the business. This is critical for Financial Management.
- How to appropriately develop a budget for being able to institute the appropriate countermeasures for any and all services.