Business Continuity Risk Assessment

Type: Assessment Confidence: 0.86 Sources: 6 Verified: 2026-03-10

Purpose

This assessment evaluates an organization's preparedness for disruptive events across six dimensions: business impact analysis, disaster recovery readiness, key-person dependency, insurance and financial resilience, crisis communication, and testing practices. Aligned with ISO 22301 principles, the output identifies the most critical gaps in organizational resilience. [src1]

Constraints

Assessment Dimensions

Dimension 1: Business Impact Analysis and Risk Identification

What this measures: How well the organization understands critical processes, likely disruptions, and financial impact of downtime.

ScoreLevelDescriptionEvidence
1Ad hocNo formal risk identification; critical processes undocumentedNo BIA; cannot list top 5 risks; no RTO/RPO defined
2EmergingInformal risk awareness; some critical processes identifiedAd hoc risk discussions; systems loosely identified
3DefinedFormal BIA; processes ranked by impact; RTO/RPO for tier-1 systemsDocumented BIA; risk register; RTO/RPO for critical systems
4ManagedBIA updated annually; quantitative risk modeling; dependency mappingQuantitative models; scenario-based financial impact analysis
5OptimizedContinuous monitoring; AI-driven threat intelligence; dynamic BIAAutomated scanning; real-time dependency graphs

Red flags: Cannot state cost of 24 hours downtime; RTO/RPO undefined; risk discussions only after incidents. [src2]

Quick diagnostic question: "What is the cost of 24 hours downtime for your most critical process?"

Dimension 2: Disaster Recovery Readiness

What this measures: Maturity of technical DR capabilities — backups, failover, and recovery procedures.

ScoreLevelDescriptionEvidence
1Ad hocNo DR plan; backups inconsistent or untestedNo documented DR plan; backups not verified
2EmergingBasic backups; DR plan on paper but never testedDaily backups; written plan; no testing; RPO in days
3DefinedTested DR for critical systems; automated backup verificationAnnual DR test; cloud DR for tier-1; RPO <24 hours
4ManagedQuarterly DR tests; automated failover; RPO <4 hoursQuarterly drills; multi-AZ; DR metrics tracked
5OptimizedNear-zero RPO/RTO; chaos engineering; self-healing infraActive-active multi-region; chaos testing; RPO <1 hour

Red flags: Last DR test 12+ months ago or never; backups never restored; single point of failure. [src4]

Quick diagnostic question: "When was your last DR test, and what was the actual recovery time vs. target RTO?"

Dimension 3: Key-Person and Knowledge Dependency

What this measures: Vulnerability to loss of critical individuals and institutional knowledge.

ScoreLevelDescriptionEvidence
1Ad hocCritical knowledge in individuals; no documentation; bus factor = 1Single person knows critical systems; no cross-training
2EmergingKey-person risks acknowledged; some documentation existsPartial documentation; 1-2 backups for some roles
3DefinedDependency map created; documentation enforced; cross-training activeKey-person register; runbooks; each critical role has backup
4ManagedKMS active; succession planning for leadership; knowledge auditsKMS with search; succession plans reviewed quarterly
5OptimizedSelf-documenting systems; no single points of failureAutomated documentation; knowledge base as team culture

Red flags: "Only [name] knows how to do that"; vendor relationships tied to one person; no succession plan. [src3]

Quick diagnostic question: "If your most critical employee were unavailable for 30 days, what would break?"

Dimension 4: Insurance and Financial Resilience

What this measures: Adequacy of financial protection against disruptive events.

ScoreLevelDescriptionEvidence
1Ad hocMinimal insurance; no financial contingency planningBasic liability only; no business interruption; no cash reserve policy
2EmergingStandard policies not reviewed against risks; limited reservesGeneral liability + property; 1-2 months cash
3DefinedAnnual review mapped to risks; business interruption adequate; 3-6 months cashAnnual review; BI policy with adequate limits; documented gaps
4ManagedOptimized portfolio; cyber + key-person insurance; 6-12 months reservesComprehensive coverage; scenario-tested reserves
5OptimizedDynamic program; parametric triggers; stress-tested financial modelParametric insurance; captive program; quarterly stress tests

Red flags: Insurance not reviewed in 3+ years; no cyber insurance; BI limits below 3 months revenue. [src5]

Quick diagnostic question: "When was your insurance last reviewed against your risk profile?"

Dimension 5: Crisis Communication and Response

What this measures: Ability to communicate and coordinate during a crisis.

ScoreLevelDescriptionEvidence
1Ad hocNo plan; response improvised; stakeholders learn through informal channelsNo templates; no spokesperson; reactive social media
2EmergingBasic contact lists; draft plan untested; single channelEmergency contacts; draft plan; CEO handles all crisis comms
3DefinedDocumented plan with roles; templates for scenarios; multi-channelTested plan; pre-drafted templates; notification system
4ManagedTested via tabletop exercises; stakeholder-specific messagingAnnual tabletops; stakeholder matrix; media monitoring
5OptimizedAutomated notification; real-time sentiment monitoring; simulation programAutomated alerting; sentiment dashboards; regular simulations

Red flags: No crisis plan; customers learn about outages from social media first; no media training. [src6]

Quick diagnostic question: "Do you have a crisis communication plan, and when was it last tested?"

Dimension 6: Testing, Maintenance, and Improvement

What this measures: How rigorously the organization tests, maintains, and improves continuity plans.

ScoreLevelDescriptionEvidence
1Ad hocNo testing; plans outdatedPlans last updated years ago; no test schedule
2EmergingAnnual document review; one-time DR testAnnual review; one-time test at deployment
3DefinedAnnual BCP testing; semi-annual DR drills; after-action reportsTest calendar; after-action reports; plan updates post-test
4ManagedQuarterly scenarios; unannounced tests; metrics-driven improvementQuarterly cadence; surprise drills; improvement backlog
5OptimizedContinuous testing via chaos engineering; automated validationChaos engineering; automated validation; continuous loop

Red flags: BCP never tested; DR "success" with no metrics; plans reference departed employees. [src3]

Quick diagnostic question: "How often do you test BCP, and what changed after the last test?"

Scoring & Interpretation

Overall Score Calculation

Overall Score = (BIA + DR Readiness + Key-Person + Insurance + Crisis Comms + Testing) / 6

Score Interpretation

Overall ScoreMaturity LevelInterpretationRecommended Next Step
1.0 - 1.9CriticalUnprepared for disruption; significant incident could threaten survivalConduct BIA; establish basic DR and crisis communication; review insurance
2.0 - 2.9DevelopingBasic awareness but plans untested; recovery would be slow and chaoticComplete formal BIA; test DR; address key-person risks; update insurance
3.0 - 3.9CompetentSolid foundation with tested plans; may struggle with novel disruptionsExpand scenarios; increase test frequency; build financial resilience
4.0 - 4.5AdvancedComprehensive program with regular testing and improvementFocus on emerging risks; chaos engineering; advanced financial instruments
4.6 - 5.0Best-in-classResilience embedded in culture; self-healing capabilitiesMaintain through continuous testing; innovate on resilience approaches

Dimension-Level Action Routing

Weak Dimension (Score < 3)Fetch This Card
Business Impact AnalysisBIA Development Guide
Disaster RecoveryDR Planning Playbook
Key-Person DependencySuccession Planning Framework
Insurance and FinancialInsurance Coverage Review
Crisis CommunicationCrisis Communication Playbook
Testing and MaintenanceBCP Testing Program Guide

Benchmarks by Segment

SegmentExpected Average Score"Good" Threshold"Alarm" Threshold
Startup/SMB (<50 employees)1.52.21.0
Mid-market (50-500)2.33.01.5
Large enterprise (500-5000)3.23.82.5
Global enterprise (5000+)3.84.33.0

Common Pitfalls in Assessment

When This Matters

Fetch when a user asks to evaluate disaster preparedness, assess organizational resilience, prepare for a board risk review, evaluate key-person dependencies, or comply with business continuity regulations.

Related Units