- ISO 22301 frames BCMS monitoring, review, management review, update, and improvement expectations that keep BIA outputs current.
"Business continuity management systems — Requirements"
Use this ISO 22301 BIA template to assess impacts over time, identify prioritized activities, set resumption time and capacity, record resources and dependencies, and supply evidence for continuity strategy decisions.
Designed for BCMS owners, process owners, resilience teams, and auditors who need a useful BIA record rather than generic continuity wording.
Structured answer sets in this page tree.
Cited legal and guidance references.
An ISO 22301 determines business continuity priorities and requirements. For each activity that supports a product or service, record impact over time, when non-resumption would become unacceptable, the earlier prioritized time for resuming at minimum acceptable capacity, required resources, and dependencies. Use the result to identify prioritized activities and supply inputs to continuity strategy. This page describes a working record, not an official ISO form.
Start with a stable activity inventory. Each BIA row should name the product or service supported, the activity being analysed, the accountable business owner, the location or delivery model, and the disruption impacts to assess. Choose impact types and criteria that fit the organization's context; examples may include customer, safety, legal or regulatory, financial, operational, and reputational effects.
ISO 22301 requires the process to determine business continuity priorities and requirements. The BCMS owner should maintain the method and template, while product, service, and activity owners provide and approve the operating facts. The template should produce enough information to decide which activities are prioritized and what is needed to continue or recover them.
For each activity, assess how disruption impacts change over time using the defined impact types and criteria. Use time bands that fit the service, operating cycle, and evidence. A single severity score cannot show when an impact crosses the organization's unacceptable threshold.
Record the time frame within which not resuming the activity would become unacceptable. Then set a prioritized time within that limit for resuming the activity at a specified minimum acceptable capacity. ISO 22301 notes that these time frames can be called and , respectively.
The BIA should make dependencies visible enough for continuity strategies to be selected. Ask each process owner what the activity needs at minimum acceptable capacity, then separate internal dependencies from third-party and infrastructure dependencies.
The result should be a resource profile for each . ISO 22301's resource categories include people; information and data; facilities and utilities; equipment and consumables; ICT; transport and logistics; finance; and partners and suppliers. Use the profile to identify candidate continuity solutions.
This BIA structure helps collect activity impacts, recovery targets, dependencies, resources, evidence, and review triggers in a workflow your BCMS owners can maintain.
Convert BIA rows into accountable evidence requests, recovery-target reviews, resource gaps, and strategy handoffs.
Review your activity inventory, impact time bands, dependencies, recovery assumptions, and audit-ready evidence model.
End the template with a controlled handoff. For each , record the resumption time, minimum capacity, dependencies, resource requirements, disruption risks, open gaps, and decision owner. Strategy selection should consider whether options meet time and capacity, the amount and type of risk the organization may or may not take, and costs and benefits.
The handoff should identify the selected strategy and one or more solutions, the approval rationale, the implementation owner, the linked plan, and how the organization will test whether the solution can be activated and meet the BIA requirement. Keep the disruption risk assessment as a linked but distinct record: the BIA determines impact-based priorities and requirements, while the risk assessment identifies, analyses, and evaluates disruption risks to prioritized activities and their required resources.
A BIA that records opinions without decisions cannot support the next step. The completed record should identify prioritized activities, resumption time and minimum capacity, required resources, dependencies, evidence, assumptions, approvals, and open gaps.
Do not copy recovery targets across activities without analysis. Each target should follow from the activity's impact over time and sit within the point where non-resumption becomes unacceptable. Dependencies and current capability determine whether the target is feasible.
Set planned review intervals and significant-change triggers. ISO 22301 requires review of the BIA and risk assessment at planned intervals and when significant changes occur within the organization or its operating context. Triggers may include new products, supplier or system changes, acquisitions, site moves, changed commitments, failed assumptions in an exercise, or an incident that reveals a gap.
The review output should be practical: updated BIA rows, changed continuity strategies, updated plans, corrective actions, risk acceptance, management-review input, or supplier follow-up.
"Business continuity management systems — Requirements"
"does not prescribe a uniform process"