Business impact analysis vs risk assessment: what each one answers

A business impact analysis asks what hurts and how fast if a process stops. A risk assessment asks what is likely to happen and how bad it would be. You need both, and the BIA usually comes first, because it tells the risk assessment which processes matter most.

The difference in one line

The BIA measures consequence. The risk assessment measures likelihood against consequence, one threat at a time.

Put another way, the BIA does not care why payroll stopped. A fire, a ransomware attack and a failed software update lead to the same answer, for example staff unpaid after three days and a labour relations problem after five. The risk assessment cares a great deal about why, because the controls for each cause are different.

What a business impact analysis produces

A ranked list of critical processes, the systems, suppliers and people each depends on, and three numbers per process: maximum tolerable downtime, a recovery time objective and a recovery point objective. NIST’s contingency planning guide (SP 800-34) treats the BIA as the step that sets those recovery requirements.

The output feeds backup design, disaster recovery and continuity plans. Our approach is set out on business impact analysis and continuity planning.

What a risk assessment produces

A set of risk statements, each naming a threat, the asset or process it affects, how likely it is, how severe it would be, and what controls already reduce it. NIST’s guide for conducting risk assessments (SP 800-30) is a common reference for the method.

The results go into a risk register, where each risk gets an owner and a decision: treat, transfer, avoid or accept. What that register should hold is covered in what a cyber risk register should contain.

BIA vs risk assessment side by side

Business impact analysisRisk assessment
Asks what hurts and how fastAsks what is likely to happen
Ignores the causeStarts from the cause
Led by process ownersLed by risk and security, with owners
Produces MTD, RTO and RPOProduces rated risks and treatments
Drives recovery and continuityDrives controls and investment

Which one to do first

Start with the BIA. Once you know which processes the business cannot lose, the risk assessment can spend its effort on the threats to those.

Doing it the other way round is common, and it shows. Impact scores in a risk assessment built without a BIA tend to cluster at “high” for everything, because nobody has measured what an outage actually costs. The risk appetite statement then has nothing concrete to be measured against.

Questions we are asked

What is the difference between a BIA and a risk assessment?

A business impact analysis measures the consequence of losing a process over time, whatever the cause. A risk assessment estimates the likelihood and impact of specific threats, such as ransomware or a supplier failure.

Which comes first, the BIA or the risk assessment?

Usually the BIA first. It identifies the processes the business cannot lose, and the risk assessment then concentrates on the threats to those processes instead of spreading effort evenly across everything.

Can one replace the other?

No. A BIA without a risk assessment tells you what to protect but not what it needs protecting from, and a risk assessment without a BIA rates impact from guesswork.

How often should each be refreshed?

Refresh both yearly and after any major change. The risk assessment moves faster, because threats and controls change more often than which processes the business depends on.

Getting both done in the right order

Tell us whether you already have a BIA, a risk register or neither, and we will say where to start. More comparisons are indexed at writing.

Discuss a scope