| A business impact analysis identifies what happens when an important business activity stops, how the impact grows over time, and how quickly the activity has to resume. It covers financial loss, operational disruption, customer commitments and other consequences that matter to your business. It produces what a continuity plan is built against, so the analysis comes first and the plan is built to fit what it finds. |
The order system goes down at twenty to ten on a Tuesday. Sales cannot take orders, the warehouse cannot pick, and the phone starts.
Somebody asks the owner how long until it is back. The honest answer is that nobody knows yet. The second question matters more and is harder to answer: what does this hour cost, and how long can the business carry it before something breaks that money will not fix?
Without that figure every continuity decision after it is a guess. The business cannot say what a faster restore is worth buying, which system to fix first, or whether the money it already spends is pointed at the right thing.
A business impact analysis produces that answer. Part of it is arithmetic and the inputs are mostly in the accounting system. The rest is judgement about deadlines, customers and obligations that no ledger records.
The figures below are illustrative. Take a New Zealand wholesale distributor, Christchurch based, with thirty-five staff and $9.2 million of revenue, trading ten hours a day, two hundred and fifty days a year.
Revenue per trading hour is about $3,680. Six orders in ten get placed again on Wednesday, so the lost revenue is nearer $1,472 an hour.
Then the idle staff. Twenty-two of the thirty-five cannot do their job without the order system, and at a loaded $38 an hour that is another $836.
So an hour without the order system costs about $2,308. An hour without the file server, measured the same way, costs about $180.
That Tuesday outage ran three hours and forty minutes. On those figures the standing cost was about $8,460 before anybody had finished arguing about whose fault it was, and before the recovery bill.
That business spends $7,200 a year on redundancy for the file server, and nothing on the order system. The money is real and the intent is right, and those two figures give the owner a reason to look again at where it is pointed.
One boundary before we start. This analysis establishes what the business needs and by when. Designing the recovery capability that meets it, and the detail behind RTO and RPO, belongs to the disaster recovery plan, and deciding who does what on the day belongs to the continuity plan.
This article stays with the assessment underneath both of them.
What Is a Business Impact Analysis?
A business impact analysis is a structured assessment of disruption. It lists what the business does, works out what stopping each activity costs and disrupts as time passes, and ranks them so money and attention reach the serious end first.
Cost per hour is the input most businesses reach for, and it is the right place to start. It is not the whole picture. An activity that earns nothing can still need urgent recovery because it protects people, meets a statutory deadline, or carries a customer commitment the business cannot be seen to miss.
Most documents shorten it to BIA. The output is a ranked list short enough for a director to act on in an afternoon, carrying what each activity costs when it stops, how that grows with time, and how quickly it has to resume.

How is it different from a risk assessment?
A risk assessment examines threats, how likely they are and what they could lead to. A BIA assumes the disruption has happened and examines how it affects business activities as time passes.
The two are complements. The risk work tells you what threatens the business, and the BIA tells you which disruptions it can least afford to carry. Businesses run them in either order, and plenty run them alongside each other.
A business that has only done the risk half usually has a long register and no budget logic. It knows twenty things could happen and cannot rank them by consequence.
Who needs to be in the room?
Finance, operations and whoever owns each system, with a director to settle disputes. The IT provider supplies system dependencies and realistic restore times, and has no way to supply the revenue figures.
Keep it to four or five people and two sessions. A BIA run by committee takes three months and lands after the budget it was meant to inform.
How Do You Calculate What Downtime Costs Per Hour?
Downtime cost per hour equals lost revenue for the hour, plus the cost of staff capacity that cannot be used, plus any penalty that accrues hourly. One-off recovery costs are added separately, per event. Work the whole thing for one named function, on one page.
Lost revenue is the input people get wrong most often. Annual revenue divided by trading hours gives revenue per hour. Multiply that by the proportion you will not recover later, which is the opposite of the share customers simply defer: if six orders in ten are placed again on Wednesday, use the remaining four.
Then label it accurately. That figure is lost revenue, and lost revenue is not net loss. Goods not sold usually mean purchase and other variable costs avoided, so finance should work back to lost contribution before anybody calls it a loss, and add only the disruption costs that are genuinely additional.
A wholesaler whose customers order again on Wednesday loses far less than a cafe whose lunch trade walks past. Ask the sales manager what proportion never comes back, and use their number.
| Cost line | How to work it out | Example |
|---|---|---|
| Recurs every hour | ||
| Lost revenue | Revenue per trading hour, less the share customers simply defer | $1,472 |
| Unused staff capacity | Staff who cannot do their normal work, times their loaded hourly cost | $836 |
| Standing total | The first two lines, which is what recurs every hour | $2,308 |
| Once per incident | ||
| Recovery cost | Fixed incident charges, plus provider time, overtime and rework that grow with the outage | Assumed $4,200 for this event |
| Penalties | Service credits, late-delivery clauses, statutory fines | Nil for this business |
Recovery cost sits outside the hourly figure on purpose, but it is not one number either. Separate the fixed charges that land whatever happens, the costs that grow with the length of the outage such as overtime and rework, and the ones triggered at a threshold, like a provider callout after four hours. The $4,200 above is an assumption for this illustrative event rather than a rate to reuse.
Watch the overlap between the first two lines as well. If finance measures loss as contribution, payroll may already sit inside it, and staff who cannot do their normal job often do something else useful for part of the time. Keep lost contribution, additional cash costs and unused staff capacity as three separate lines so the same effect is not counted twice.
Six to ten functions is a sensible starting group rather than a stopping rule. The ranking usually settles early, though a function further down can still change a decision if it carries a deadline or an obligation that the top of the list does not.
What does the hourly figure miss?
Timing, and the tail. An hour lost at the end of the month in a business that invoices on the last day is worth several ordinary hours, so record the peak alongside the average.
Duration works the same way. Impact rarely grows in a straight line: the first hour is absorbed by workarounds, the first day starts breaking customer commitments, and by the third day the losses are people rather than orders. Assess a short outage, a full day and several days rather than carrying one hourly rate forward.
So a single average is the wrong planning number. Cost the ordinary version, the peak-period version and the long version, and plan against the ones that hurt.
How do you cost a function that earns no revenue?
Use the cost of the consequence in place of the lost sale. Payroll earns nothing, and a payroll run that misses its deadline costs penalty interest, emergency accounting time and a day of management attention that was committed elsewhere.
Some carry a hard external deadline with a stated penalty, such as a late PAYE filing or a compliance return that slips its date. Others carry a consequence with no price on it at all. A missed tender submission usually costs you the work rather than a fine, and an obligation that affects safety is not a financial question at all.
Describe the actual consequence where you know it, and resist converting everything into dollars. Where a ranking judgement is still needed, what the business would pay to avoid the outage is a reasonable way to place it against the others, as long as it is recorded as a judgement and not as a measurement.
Which Business Functions Should You Measure First?
Start with the activities that take money in, get the product or service out the door, and carry an obligation you cannot miss. Order capture, invoicing, dispatch, payment processing and customer contact top the list in most trading businesses. In professional services it is client delivery and the deadlines attached to it, and where the work touches health or safety that comes before any of them.
Work in business language, using the words the people doing the job would use. The function is taking an order, and the systems behind it might be a website, an email inbox, a phone system and a stock file. Any one of them stops the function.
Without that distinction the exercise drifts into a server list. Owners can rank functions, and no owner can usefully rank virtual machines.
How do you find the dependencies nobody drew?
Ask each function owner what they would be unable to do if a given system was gone by ten this morning. The answers reach further than any diagram, because they include the spreadsheet on somebody’s desktop, the supplier portal nobody documented, and the fact that one person in accounts is the only one who can reissue a credit note.
Dependencies are not only systems. People, premises, suppliers, utilities and data all belong on the list, and the honest answer is often that the activity slows rather than stops, because a workaround holds for a while. Record the workaround and how long it lasts, because that is what sets the tolerable limit rather than the moment the system went dark.
Single points of failure surface fast in that conversation. So does the discovery that a nightly backup nobody has ever opened is the only copy of something, and that one goes straight to restore testing without waiting for the rest of the analysis.
Write the dependency list down as you go. Half the value of the exercise sits in that list, and people forget to capture it every time.
How Long Can Each Function Be Down Before It Hurts?
Anything from twenty minutes for order capture to a fortnight for archived records, and every activity gets its own answer. The maximum tolerable period of disruption, or MTPD, is the point beyond which the impact becomes unacceptable, and it is the headline output of the analysis. The business sets it, not the IT team.
The recovery time objective is the target time for resuming the activity, or for restoring the service that supports it. It has to be shorter than the MTPD, and shorter by enough to cover the work still needed once the system is back before the business is genuinely operating again: reconciling, re-keying, calling customers. Where data matters, record how much of it the business can afford to lose as well, which is the recovery point objective.
A target is not evidence. Setting a four-hour objective states what the business needs, not that the current arrangements can deliver it, and the gap between the two is one of the more useful things this analysis surfaces.
The terminology follows ISO 22301:2019, the second edition of the business continuity management systems requirements, which is published and currently under systematic review.

Where do the numbers go once you have them?
Into the plan that spends them. The ranked list and the MTPD for each function are the inputs to a business continuity plan, which decides what happens on the day and who does it.
Keeping the two documents apart matters more than it sounds. The analysis records what is true about the business. The plan sets out the response, and when strategy shifts you revise the plan and leave the arithmetic alone.
What Does a Finished Business Impact Analysis Look Like?
One table, six to ten rows, on a single page. Each row is a business activity, and the columns carry the impact when it stops, the tolerable outage, what the activity depends on, and what the business currently spends protecting it. Where the impact is not financial, say what it is rather than inventing a figure for it.
Most templates leave that last column out, and it is the one that changes decisions. Put cost and spend side by side and the page gives a director something to approve or refuse.
Everything else belongs in an appendix. The interview notes, the dependency lists and the finance workings all matter for defending a number later, and none of them belongs on the page a director reads.
Keep the page dated and name an owner on it. A costing carrying last year’s revenue figures and nobody’s name gets ignored the first time somebody disagrees with it.
What if two functions depend on the same system?
Model the combined outage rather than adding the two figures. A stock file sitting under order capture at $2,308 an hour and dispatch at $640 an hour does not automatically carry $2,948, because both figures may rest on the same lost sales and the same idle staff. Count each lost sale and each cost once, then add whatever the second activity loses on top that the first did not already capture.
Most businesses find their real priority at this step, and it is rarely the system anybody nominated at the start. Shared infrastructure accumulates exposure from every function sitting on top of it.
Watch for the reverse case as well. A system carrying one function at $90 an hour and nothing else is a candidate for saving money, and those savings are what fund the changes at the top of the list.
Who signs it off?
A director or the owner, because the tolerances on it are commercial commitments. Signing off a four-hour tolerable limit on order capture says the business has decided it can carry up to four hours without unacceptable harm. It is a ceiling rather than a target, and it is not a budgeted loss: what any given outage costs depends on when it lands and how long it runs.
A signed and dated document is also easier to put in front of a tender panel or an insurer than a working spreadsheet, though what each of them asks for varies and none of them treats a signature as the whole answer.
Where Does a Business Impact Analysis Go Wrong?
Four ways, and the first two are decided before anybody collects a number. The commonest is measuring systems where the business needed functions, which produces a technically correct document nobody outside IT can use.
The second is letting the exercise sprawl. Thirty functions takes a quarter to get through, by which point the early figures are out of date, and the extra twenty add nothing the first ten had not already settled.
The third is accepting revenue per hour without the deferred share taken out. That single omission inflates every figure on the page, and it is the reason some published downtime costs look implausible to the people who run the business.
The fourth arrives later. Numbers are collected, the page is written, and nothing is ever compared against the current spend, so the page documents the problem and never triggers the decision it was written to inform.
How do you keep the numbers current?
Re-run the arithmetic annually and leave the function list alone unless the business has changed shape. Revenue moves every year, staff counts move, and the ranking occasionally flips on the back of both.
Three events should trigger a re-run regardless of the calendar: a new site, a system replacement, and a customer large enough to change the revenue mix on their own.
Diarise it against the budget round, not the anniversary of the last one. An analysis that arrives two weeks before the numbers are set will be read.
How Do You Do a Business Impact Analysis, Step by Step?
List the activities before touching a single system, because everything else hangs off that list. Then work through the six steps below.
List the activities, not the systems
Six to ten business activities in plain language, in the words the people who do them would use. Taking an order is an activity; the website, the inbox and the stock file behind it are not.
Work out the revenue you will not recover
Get revenue per trading hour from finance and the deferred share from sales, then multiply by the share that is not deferred. Ask finance to work that back to lost contribution before anybody records it as a loss.
Add the other consequences
Count the staff capacity that cannot be used and any penalty that accrues, then record the effects that are not financial at all: safety, customer commitments, statutory deadlines and obligations. Leave those as what they are rather than forcing a dollar figure onto them.
Map the dependencies
Ask each activity owner what they could not do if the system went at ten this morning. Record everything they name, including people, premises, suppliers, utilities and the spreadsheets, and note any workaround and how long it holds.
Set the tolerable limit, then the recovery target
Agree an MTPD for each activity with a director in the room, then a recovery time objective short enough to leave room for the work still needed once the system is back. Where the room cannot agree, write both numbers down and mark it for the board.
Compare exposure against current spend
Rank the activities, put what the business currently spends protecting each one beside it, and look for the mismatch. That comparison is what turns the document into a decision rather than a description.
Expect the ranking to surprise somebody in the room. The activity people assume is critical is often the one with the shortest queue behind it, and the unremarkable system sitting underneath three others turns out to carry the exposure.
What Does the Exercise Cost?
Scope decides it, and scope is settled before the work is quoted. What moves it: how many activities and sites are in scope, how many dependencies they run through, how much of the business information already exists in a usable form, and how much depth the result has to stand up to. The initial engagement and any later review or update are separate pieces of work.
Take the distributor from the opening and put that against what the analysis found. It did not conclude that the business should spend more. It concluded that the $7,200 committed to file-server redundancy deserved re-examining against an order system carrying $2,308 an hour of exposure rather than $180.
That comparison starts the decision rather than settling it. Whether to move the money depends on how likely each outage is, how long it would run, what each option would actually prevent or shorten, and what it costs to meet the recovery requirement. The same budget does not buy the same protection in two different places.
Our free IT assessment is a separate thing and costs nothing. It reviews the systems, backups and risks in your environment, and it is the sensible first step. It stops short of the revenue-by-function costing, which needs your finance figures and your own people in the room.

Putting exposure and current spend side by side is the part a director acts on, and it is the column most templates leave out.
Most of the elapsed time goes on finance producing figures split by activity, which is quick in a business that already reports margin by product line and slow in one that does not.
Book the follow-up session before the first one finishes. Analyses that lose momentum after the interviews are the ones that never reach a signed page.
How do you sanity-check this before commissioning anything?
Do one function yourself this week. Take whichever system takes money in, work out its cost per hour on the back of the two figures above, and write it on a sticky note.
Then find what you currently spend protecting that system, and put the two numbers beside each other. Most owners can do this in forty minutes with the annual accounts and one conversation with their bookkeeper.
If the two figures are already in proportion, you have your answer for the price of an afternoon. If they are a long way apart, as they were for the distributor, that is the point at which working through the rest properly starts to earn its keep.
Is there a free business impact analysis template?
Yes. The NIST contingency planning guide publishes a BIA template as a free downloadable document, with no sign-up behind it, and it is a sound structure to work through before paying anybody.
It is written for United States government systems, so expect to delete whole sections. Keep the function table, the dependency columns and the recovery-priority fields, and keep its impact categories rather than replacing them with dollar figures. Put your own costing alongside them instead, because the categories are what stop the exercise collapsing back into a revenue calculation.
Working through it yourself also tells you what a paid engagement should cost. If the template takes a fortnight of your own time to populate, a fixed fee starts looking reasonable.
What makes one analysis cost more than another?
The number of distinct activities, and whether finance can split revenue across them. Where the accounts show a single revenue line, somebody has to allocate it before the costing can start, and that is usually the slowest part of the exercise.
Frequently Asked Questions
What is a business impact analysis in simple terms?
A BIA works out what happens when an important business activity stops, how the impact grows over time, and how quickly the activity has to resume. Cost per hour is one input, alongside customer commitments, deadlines and obligations that never appear as a dollar figure. The output is a ranked list of activities with recovery priorities against them. It is not a plan in itself, and a continuity plan is built from it.
What is the difference between a business impact analysis and a risk assessment?
A risk assessment examines threats, how likely they are and what they could lead to. A business impact analysis assumes the disruption has happened and examines how it affects business activities as time passes. Most businesses need both, and they can be run in either order or alongside each other.
How do you calculate the cost of one hour of downtime?
Take revenue per trading hour from annual revenue divided by trading hours, then multiply by the share customers will not place again later. Add the cost of staff capacity that cannot be used and any penalty that accrues hourly. Keep one-off recovery costs separate, because they land per event rather than every hour. Lost revenue is also not net loss: goods not sold usually mean costs avoided, so ask finance to work it back to lost contribution.
What is a maximum tolerable period of disruption?
The MTPD is the point beyond which an activity being unavailable causes unacceptable harm. The business sets it rather than the IT team, and every recovery target has to be shorter than it.
Is MTPD the same as a recovery time objective?
No. The MTPD is the point beyond which the impact becomes unacceptable, and the recovery time objective is the target time for resuming the activity or restoring the service behind it. The RTO has to be shorter than the MTPD, and shorter by enough to cover the work still needed once the system is back. A target is also not proof that the current arrangements can meet it.
How often should a BIA be repeated?
Once a year is a useful default, and sooner whenever something changes: a new site, a system replacement, a customer large enough to move the revenue mix, a new obligation, a change of supplier, or a change in the recovery arrangements the analysis assumed. Re-running the arithmetic alone is not always enough, because what has changed is often a dependency or a deadline rather than a number.
Who should carry out a BIA?
Finance and operations own the numbers, an IT provider supplies system dependencies and realistic restore times, and a director signs off the tolerances. An analysis produced by the IT team alone tends to rank servers, and a director cannot budget from that.
Is a BIA required for ISO 22301 or cyber insurance?
They ask different things. ISO 22301 requires a business impact analysis as part of a certified business continuity management system. A SOC 2 engagement looks for the reasoning behind availability commitments, which is related but not the same requirement. Insurers vary, and what any one of them asks for depends on the policy. Even where nobody is asking, the analysis is what makes the rest of the continuity spending defensible at board level.
Is there a free BIA template?
Yes. The NIST contingency planning guide publishes a downloadable BIA template that is free to use and structured well enough to run a first pass. It is written for government systems, so expect to cut sections that do not apply to a smaller business.
How long does a BIA take?
Most of the elapsed time goes on finance producing figures split by activity, so a business that already reports margin by product line moves faster than one working from a single revenue line. The working sessions themselves are short. Booking the follow-up before the first session finishes is what keeps it moving.
How much does a business impact analysis cost?
Scope decides it, and scope is settled before the work is quoted. What moves it is how many activities and sites are involved, how many dependencies they run through, how much usable business information already exists, and how much depth the result has to stand up to. The initial engagement and any later review are separate pieces of work. A free IT assessment is a different thing and costs nothing, but it stops short of the revenue-by-activity figures.
What should you do first if you have never run one?
Pick the single function that takes money in, and cost one hour of it this week. That one figure usually changes a spending decision on its own, and it makes the case for doing the other nine properly.
Exodesk has operated since 1989, with offices in Christchurch and Dunedin serving businesses across New Zealand. We run the analysis with your finance and operations people and leave you with a ranked list you can budget against.
Contact us today to discuss how we can help your business or connect with us on LinkedIn to stay updated with more insights.
Next step
Is your continuity budget aimed at the right system?
Most continuity budgets are not too small. They are aimed at the system somebody nominated years ago rather than the one carrying the exposure. A free IT assessment maps what your business functions actually depend on, and shows where the protection you already pay for is sitting against them.
For the wider advisory work behind this, see IT consulting.

