Policy Register

Business impact analysis

Which activities matter most, how quickly each must be recovered, what it depends on and what its loss costs over time.

How the register reads it

Also calledBIA, recovery time objectives
FamilyResilience and incidents
Document typeRecord. The regimes ask for the content, not the label; a line pasted as a standard, procedure, plan or schedule is placed here with the label noted.
Folds intoThe regimes accept it folded into the business continuity plan; when neither is listed, the gap is counted once, under the parent.
Expected ownerThe business continuity manager or COO.
Review cadenceAnnual (the register's default: the clauses say planned intervals and on significant change, and do not fix a period).
On the gap list whenISO 22301 is ticked and no line resolves to it or to its parent (DORA requires it too, inside a parent document, so it does not list it separately).
TemplateBusiness impact analysis template.

Which standards require it, and what each expects it to contain

2 requiring clauses, 2 regimes

Shown on a register for the regimes you tick; with none ticked, ISO 27001 is applied. Requirement text drawn from a human-verified compliance corpus under licence: the corpus statement of each clause, not the instrument verbatim.

ISO 22301:2019

ISO 22301 8.2.2 Business impact analysis

Use the impact analysis process to set continuity priorities and requirements: define the impact types and criteria relevant to the organization's context, identify the activities supporting delivery of products and services, assess impacts over time from disrupting those activities, fix the point at which non resumption becomes unacceptable, set prioritized time frames within that point for resuming activities at a specified minimum acceptable capacity, identify the prioritized activities, and determine the resources, dependencies and interdependencies they rely on including partners and suppliers.

Evidence an auditor accepts: Defined impact types and criteria approved for this organization; activity inventory mapped to products and services; impact over time analysis per activity
Common gap: Recovery time frames set by aspiration and never reconciled to the impact analysis that should produce them
Source: ISO 22301:2019

DORA (Regulation (EU) 2022/2554)

DORA Art. 11 Response and recovery

Financial entities shall put in place an ICT business continuity policy and ICT response and recovery plans (including measures, procedures and arrangements) to ensure continuity of critical or important functions, quickly contain damage, resume activities and recover, subject to regular testing.

Evidence an auditor accepts: ICT business continuity policy + response/recovery plans; records of plan testing
Common gap: No ICT continuity/response/recovery plans
Source: DORA (Regulation (EU) 2022/2554)

Do this for every document on your list

Paste the list and get this reading for every document at once, with the owner and cadence against each, the clauses quoted, and the documents the regimes expect that the list does not carry. Eight documents free, no account.

Build a register

Business continuity policy · Crisis management plan