Business Impact Analysis (BIA): The SMB Guide + Sample Template
A Business Impact Analysis is the single document auditors, insurers, and enterprise buyers ask for first. This guide explains what a BIA is, walks through the five steps to build one, and gives you a copy-ready sample BIA template mapped to SOC 2, HIPAA, and NIST CSF 2.0.
What Is a Business Impact Analysis?
A Business Impact Analysis (BIA) is a structured assessment that identifies your critical business processes, the systems and data they depend on, and the operational and financial impact if any of them go down. The output is a prioritized list of what to protect first — and how quickly it must come back after an incident.
A BIA is the foundation for your Business Continuity Plan (BCP) and Disaster Recovery Plan (DRP). Without one, backup investments, incident response runbooks, and vendor SLAs are guesses. With one, every recovery decision maps to a documented business impact.
BIAs are explicitly required or strongly expected by SOC 2 (CC7.5, A1.2), HIPAA Security Rule § 164.308(a)(7) Contingency Plan, NIST CSF 2.0 (RC.RP, ID.BE), and ISO 27001 Annex A.5.29 / A.5.30.
Key BIA Terms
RTO — Recovery Time Objective
The maximum tolerable time a process can be down before real damage occurs. Example: 4 hours for order intake.
RPO — Recovery Point Objective
The maximum tolerable data loss, measured in time. Example: 15 minutes of transactions.
MTD — Maximum Tolerable Downtime
The absolute ceiling before the outage causes existential harm — lost customers, contract breach, regulator action.
Criticality Tier
The priority ranking (Tier 1 mission-critical → Tier 4 deferrable) that drives backup, HA, and vendor SLA spend.
The 5 Steps to Run a BIA
- 1
Inventory business processes
List every revenue-generating and regulated process — order fulfillment, patient scheduling, payroll, PHI handling, customer support. One row per process.
- 2
Map processes to systems, data, and people
For each process, identify the applications, databases, SaaS vendors, network dependencies, and staff roles required to run it.
- 3
Assess impact of disruption
Estimate financial ($/hour), operational, reputational, and regulatory impact for outages of 1 hour, 24 hours, and 1 week. Interview process owners — don't guess.
- 4
Set RTO, RPO, and criticality tier
Convert impact into recovery targets. Anything with impact > $10K/hour or PHI exposure typically lands in Tier 1 (RTO ≤ 4h, RPO ≤ 1h).
- 5
Review, approve, and re-run annually
Executive sign-off makes the BIA an auditable record. Re-run after major system changes, M&A, or at least annually — auditors will ask for the date.
Sample BIA Template
Copy the table below into a spreadsheet or your GRC platform. One row per business process. The example rows show how a healthcare-adjacent SMB might fill it in.
| Process | Owner | Systems / Data | Financial Impact (per day) | Regulatory Impact | RTO | RPO | Tier |
|---|---|---|---|---|---|---|---|
| Patient scheduling | Practice Manager | EHR, phone system, PHI | $18,000 | HIPAA availability | 4 hrs | 15 min | Tier 1 |
| Billing / claims submission | CFO | Billing SaaS, clearinghouse | $9,500 | Cash flow, SOC 2 A1.2 | 24 hrs | 1 hr | Tier 2 |
| Corporate email | IT Lead | Microsoft 365 | $4,000 | Communication continuity | 8 hrs | 1 hr | Tier 2 |
| Marketing website | Marketing Lead | CMS, CDN | $800 | None | 72 hrs | 24 hrs | Tier 4 |
Columns to add for your own BIA: upstream/downstream dependencies, workaround procedure, assigned recovery team, last-tested date, residual risk.
Need a defensible BIA before your next audit?
Senticit runs BIAs for SMBs preparing for SOC 2, HIPAA, and NIST reviews — interviewing your process owners, quantifying impact, and delivering an auditor-ready deliverable in two weeks.
Talk to a Compliance Lead