Business Continuity, Crisis & Resilience

Business Impact Analysis and Recovery Planning Course

Quantify operational risk, establish robust recovery metrics, and build an airtight business continuity strategy.

Programme overview

Technical depth: Practitioner · Practical mode: Case study

Introduction

Many organisations hold continuity plans that were written before anyone established which activities matter most, how quickly each must resume, or what resources recovery would need. The result is recovery times set by opinion, technology recovery that does not match business need, and plans that fail when tested. This Core Concept course equips managers to run a business impact analysis to recognised practice and turn its findings into recovery strategies and plans. Participants work through case material from several sectors and leave with a BIA Report and Recovery Plan Outline for a product or service of their own.

Course Objectives

  • Scope and plan a business impact analysis at product, process and activity level in line with ISO 22301 and ISO/TS 22317
  • Design impact rating scales and questionnaires, and run BIA interviews that produce defensible impact data
  • Set MTPD, RTO, RPO and minimum resource levels for prioritised activities and map the dependencies behind them
  • Evaluate recovery strategy options against cost, capability and residual risk, and expose gaps between required and actual recovery capability
  • Structure recovery plans and procedures that follow ISO/TS 22332
  • Produce a BIA Report and Recovery Plan Outline ready for management sign-off

Target Audience

  • Business continuity managers and coordinators responsible for running the BIA cycle
  • Risk managers integrating disruption scenarios into the organisation's risk profile
  • Operations and service managers accountable for the recovery of critical products and services
  • IT service continuity and disaster recovery managers aligning technical recovery with business requirements
  • Internal audit and compliance managers reviewing the adequacy of continuity arrangements
  • Facilities and supply managers responsible for premises and supplier dependencies

Course Outline

Day 1: Business Impact Analysis in Context

  • ISO 22301:2019 Clause 8.2 Requirements for Business Impact Analysis and Risk Assessment
  • Recovery Terminology in ISO 22300:2025: MTPD, RTO, RPO and Minimum Business Continuity Objective
  • Strategic, Tactical and Operational BIA Levels
  • Product and Service Prioritisation Matrix
  • BIA Maturity Current-State Checklist

Day 2: BIA Standards and Methods

  • ISO/TS 22317:2021 BIA Process: Scope, Governance and Resourcing
  • BCI Good Practice Guidelines 7.0 Analysis Professional Practice
  • Impact Categories and Time-Band Rating Scale Design
  • Disruption Scenario Risk Assessment Using ISO 31000 and IEC 31010 Techniques
  • NIST SP 800-34 Rev. 1 BIA Template for Information Systems

Day 3: Conducting the Analysis

  • BIA Questionnaire Design and Structured Interview Technique
  • Impact-over-Time Curves and MTPD Determination
  • Deriving RTO and RPO Within the MTPD
  • Dependency and Single-Point-of-Failure Mapping Across People, Premises, Technology, Information and Suppliers
  • Minimum Resource Requirements Schedule by Recovery Time Band

Day 4: Recovery Strategies, Gaps and Problem Cases

  • ISO/TS 22331:2018 Recovery Strategy Options by Resource Type
  • Cost-Benefit Comparison of Recovery Options
  • Business RTO Versus IT Disaster Recovery Capability Gap Analysis
  • Recovery Plan and Procedure Structure Under ISO/TS 22332:2021
  • BIA Validation Workshops and Correction of Inflated Recovery Times

Day 5: Case Work and the BIA Report

  • Payments Service Case Study: Setting Recovery Objectives Under Time Pressure
  • Manufacturing Plant Case Study: Supplier and Premises Dependencies
  • BIA Register Build for an Own Product or Service
  • BIA Report and Recovery Plan Outline Drafting
  • Management Sign-Off Briefing and Peer Review

Skills You Will Gain

  • Business Impact Analysis
  • Recovery Objective Setting
  • Dependency Mapping
  • Impact Scale Design
  • Stakeholder Interviewing
  • Recovery Strategy Selection
  • Continuity Requirements Analysis
  • Recovery Plan Writing

Why Attend This Course

  • Return to work with a BIA Report and Recovery Plan Outline for a real product or service, already tested in peer review
  • Challenge recovery times that business owners overstate or understate, using evidence rather than opinion
  • Show management where current recovery capability falls short and what closing each gap would cost
  • Compare BIA practice with continuity, risk and IT colleagues from other sectors and countries

Conclusion

A continuity plan is only as sound as the analysis beneath it. This course moves from the requirements and vocabulary of business impact analysis, through the standards and methods that govern it, to the interviews, time-based impact assessment and dependency mapping that produce reliable recovery objectives. It then addresses recovery strategy choice, capability gaps and the flaws that weaken many BIAs. The final day turns that work into a BIA Report and Recovery Plan Outline that participants can take straight to management for approval.

Dates & destinations

Frequently asked questions

What does this course cover?

Technical depth: Practitioner · Practical mode: Case studyIntroductionMany organisations hold continuity plans that were written before anyone established which activities matter most, how quickly each must resume, or what resources recovery would need. The result is recovery times set by opinion, technology recovery that does not match business need, and…

Are training dates available?

Yes. Available dates and destinations are listed in the course dates section on this page.

How can I register?

Choose an available date on this page and complete the registration form, or send a programme enquiry.

Can I download the course brochure?

Yes. Use the brochure download link provided on this page.

Ask about this programme

Your data is safe. We respect your privacy.