Conduct Business Impact Analysis (BIA) to identify critical functions, assess impact categories, set recovery objectives, and generate recovery sequences.
This calculator does the arithmetic at the centre of a business impact analysis: for each business function you describe, it works out what an hour of downtime costs, scores how critical the function is, ranks every function against every other one, and derives a recovery sequence that respects the dependencies between them. It is about outage — what stops working, how much that costs per hour, and what you restore first.
Everything runs in your browser. You are typing revenue figures and headcount into a page, and none of it is transmitted; the PDF report is generated locally and downloaded straight to your machine. Nothing is saved between visits either, so export before you close the tab.
A BIA is only as good as the unit of analysis. This tool works at the level of a business function — order processing, payroll, customer support, warehouse dispatch — not at the level of a server. For each one you provide:
Nothing here is hidden, and it is all worth checking against your own assumptions.
Hourly loss. The headline money figure is revenue plus idle labour:
Overall impact score is a weighted average of your five 1–5 ratings:
| Axis | Weight |
|---|---|
| Financial | 0.30 |
| Operational | 0.25 |
| Legal / regulatory | 0.20 |
| Reputational | 0.15 |
| Safety | 0.10 |
Risk score blends that with duration sensitivity and size:
Criticality tiers follow from that score: 4.0 and above is Critical, 3.0 to 3.99 is High, 2.0 to 2.99 is Medium, below 2.0 is Low. Functions are then sorted by risk score descending and numbered as priority ranks.
Total annual risk sums each function's hourly loss multiplied by a fixed assumption of four hours of downtime per year. That constant is not configurable, so read the figure as “what four hours of outage across every function would cost” rather than as a probability-weighted expected loss. If you want annualised loss driven by real event frequency, that is a different calculation and a different tool.
Take an order-processing function: $4,000,000 of attributed annual revenue, 12 staff, impact ratings of financial 5, operational 4, legal 3, reputational 4, safety 1, and time-based impact of 3, 4, 5, 5, 5, 5 across the six horizons.
For contrast, the tool's default new-function values — $500,000 revenue, 5 staff, ratings of 3/3/2/2/1 and time impact 2/3/4/4/5/5 — give an impact score of 2.45, a time average of 3.83, a risk score of 1.90 (Low), and an hourly loss of $240.38 + $250.00 = $490.38. Note that at five staff the labour component exceeds the revenue component. That crossover happens below roughly $520,000 of attributed revenue, and it is a useful sanity marker: if a function you consider critical is coming out labour-dominated, its revenue attribution is probably understated.
Three assumptions do most of the work, and you should decide consciously whether each holds for you.
Two more limits worth stating plainly. RTO, RPO and MTD are captured and reported but do not feed the risk score — they appear in the tables and the PDF as the recovery targets you have declared, not as scoring inputs. And the score caps bite: revenue weight stops climbing above $5m and staff weight above 20 people, so a $50m function and a $5m function contribute the same revenue weight. That is intentional — it stops one enormous function from flattening the ranking — but it means very large functions are compressed together and you will need judgement to separate them.
This is the part a spreadsheet does badly. Ranking functions by criticality gives you a priority list; it does not give you a recovery order, because restoring the highest-value function first is useless if it depends on something further down the list.
The tool resolves this with a dependency-aware ordering: at each step it finds the functions whose dependencies have all been restored already (or whose dependencies are not in your list at all), picks the highest-priority one among them, and repeats. The result is a sequence in which nothing is restored before what it needs. If it detects a circular dependency it cannot resolve, it stops resolving and appends the remainder in priority order — so a recovery sequence that suddenly reverts to pure priority ranking is a signal that you have declared a dependency loop worth going back and untangling.
The practical value shows up when a Medium-tier function like identity or network services turns out to sit ahead of a Critical revenue function in the sequence. That inversion is exactly the finding a BIA exists to produce, and it is invisible if you only rank by impact.
Three tabs present the same analysis at different depths:
The PDF export produces a report with an executive summary, the critical-function list, a per-function table (priority, tier, risk score, RTO, MTD, hourly loss) and the recovery sequence. It is generated in the browser and saved locally.
Used this way, the output is a defensible priority order and a per-hour cost you can put next to the price of shortening an RTO — which is the argument a BIA is ultimately for.
Business Impact Analysis (BIA) is a systematic process for determining the potential effects of disruptions to critical business functions and processes. BIA quantifies the financial, operational, legal, and reputational consequences of downtime, enabling organizations to prioritize recovery efforts and justify investments in business continuity and disaster recovery.
BIA is a foundational requirement for business continuity planning (BCP) and disaster recovery (DR). Frameworks including ISO 22301 (Business Continuity Management), NIST SP 800-34 (Contingency Planning), and regulatory standards like FFIEC and HIPAA all require BIA as the basis for continuity strategies.
| Step | Activity | Output |
|---|---|---|
| 1. Identify functions | Catalog all business processes and supporting IT systems | Business function inventory |
| 2. Assess impact | Determine financial and operational impact of each function's loss over time | Impact over time curves |
| 3. Set recovery objectives | Define RTO (Recovery Time Objective) and RPO (Recovery Point Objective) | RTO/RPO per function |
| 4. Identify dependencies | Map internal and external dependencies (systems, vendors, people) | Dependency map |
| 5. Prioritize | Rank functions by criticality for recovery sequencing | Recovery priority tiers |
| Metric | Definition | Example |
|---|---|---|
| RTO | Maximum acceptable downtime before critical impact | 4 hours for payment processing |
| RPO | Maximum acceptable data loss measured in time | 1 hour for transaction database |
| MTPD | Maximum Tolerable Period of Disruption | 24 hours before business viability is threatened |
| MBCO | Minimum Business Continuity Objective — minimum service level during recovery | Process 50% of normal transaction volume |
A Business Impact Analysis (BIA) is a systematic process for identifying and evaluating the potential effects of disruptions to critical business functions. It helps organizations understand which processes are most essential, how quickly they need to be restored after an incident, and what resources are required for recovery. BIAs are fundamental to business continuity planning and are often required by compliance frameworks like ISO 22301.
RTO (Recovery Time Objective) is the maximum acceptable time to restore a business function after a disruption. RPO (Recovery Point Objective) is the maximum acceptable amount of data loss measured in time, determining how frequently you need backups. MTD (Maximum Tolerable Downtime) is the longest period a business can survive without a particular function before suffering unacceptable consequences. These metrics guide your recovery strategies and resource allocation.
Criticality tiers are determined by analyzing multiple impact categories including financial loss, operational disruption, legal and compliance exposure, reputational damage, and health and safety risks. The calculator weights these factors based on how quickly impacts escalate over time, from one hour to one week of downtime. Functions that show high impact across multiple categories and escalate rapidly are classified as Critical or High priority.
The calculator evaluates five key impact categories: Financial Impact (revenue loss, penalties, recovery costs), Operational Impact (productivity loss, supply chain disruption), Legal and Compliance Impact (regulatory violations, contractual breaches), Reputational Impact (customer trust, brand damage, media exposure), and Health and Safety Impact (employee and public safety risks). Each category is rated from None to Catastrophic across different time periods.
The calculator allows you to specify both internal dependencies (other business functions your process relies on) and external dependencies (third-party vendors, utilities, or services). Understanding dependencies helps identify cascade effects where one failed function can impact multiple others. This information is critical for prioritizing recovery sequence and ensuring dependent functions are restored in the correct order.
Yes, the calculator provides a comprehensive PDF export feature that generates a professional Business Impact Analysis report. The PDF includes all function details, impact assessments across time periods, radar and bar charts visualizing impact distribution, recovery objectives, dependencies, and criticality tier assignments. This report can be used for management presentations, compliance audits, or insurance documentation.
You should review and update your BIA at least annually or whenever significant changes occur to your business operations, systems, or organizational structure. Major triggers for updates include new product or service launches, system migrations, organizational restructuring, regulatory changes, or lessons learned from actual incidents or exercises. Regular updates ensure your recovery priorities remain aligned with current business needs.