Clause 5.3 of ISO/TS 22317:2021 — Defining the Approach for an Effective Business Impact Analysis

Introduction

Clause 5.3 of ISO/TS 22317:2021 marks the critical stage where the Business Impact Analysis (BIA) moves from planning to execution.
It requires the organization to formally agree on the approach that will govern how the BIA is performed, ensuring that impact assessments are consistent, measurable, and defendable.

This clause is divided into four sub-clauses — each forming a cornerstone of methodological integrity:

  1. 5.3.1 Understand Impacts
  2. 5.3.2 Define Impact Types and Criteria
  3. 5.3.3 Define Time Frames
  4. 5.3.4 Define Methodology

When properly implemented, these steps ensure the BIA produces results that are both quantitative and strategic, directly supporting the continuity strategy phase under ISO 22331.

5.3.1 — Understand Impacts

Purpose

Before measuring impact, the organization must first understand what impact means in its context.
A “disruption” is not just a technical failure — it's an event that prevents or degrades the delivery of products and services, affecting customers, regulators, employees, or the community.

Key Requirements

To comply with 5.3.1, organizations must:

  • Identify how internal and external disruptions could affect delivery of products and services.
  • Recognize the stakeholders or interested parties who experience or react to these impacts.
  • Understand that impacts intensify over time — even a short outage can escalate into regulatory, reputational, or financial crises.

Typical Impact Sources

Interested Party

Example of Impact

Customers

Complaints, loss of confidence, revenue loss

Regulators

Sanctions, withdrawal of license

Shareholders

Drop in valuation or investment confidence

Employees

Loss of productivity, attrition

Partners/Suppliers

Contract penalties or disrupted supply chain

Public/Media

Negative reputation or loss of trust

Crest Advisory Africa advises that this phase include stakeholder mapping and risk-impact workshops, ensuring a full 360° view of how disruption manifests across the ecosystem.

5.3.2 — Define Impact Types and Criteria

Purpose

To measure consistently, an organization must define its impact types and rating criteria.
This ensures that qualitative and quantitative impacts are translated into comparable metrics.

Common Impact Types

While ISO 22317 offers flexibility, the standard recommends consideration of the following eight impact dimensions:

  • Business Objectives
  • Financial
  • Legal, Regulatory & Contractual
  • Operational
  • Reputational
  • Health & Safety
  • Environmental
  • Market Share or Customer Impact

Organizations may consolidate or expand these, depending on their context.

Developing Impact Criteria

Each impact type should have a graded scale — typically five levels (Insignificant to Catastrophic).
Crest Advisory Africa's 5-Point Impact Scale matrix aligns perfectly with ISO 22317's guidance and can be customized to industry thresholds.

Example excerpt from a standardized scale:

Impact Level

Financial Impact

Reputational Impact

Regulatory Impact

1 - Low

< R100 000 loss

Minor internal concern

Informal query from regulator

3 - High

R1 - 5 million loss

Regional media attention

Public warning or minor fine

5 - Catastrophic

> R10 million loss

National crisis / brand collapse

License suspension / criminal sanction

Thresholds and Acceptability

The organization must also determine when impact becomes unacceptable — the Maximum Tolerable Period of Disruption (MTPD).

This is the time at which operational or reputational damage exceeds acceptable limits.

5.3.3 — Define Time Frames

Purpose

Different impacts evolve at different rates.
Financial losses may grow gradually, while reputational or regulatory impacts can spike instantly.

Clause 5.3.3 requires defining consistent time intervals to evaluate how impact escalates.

ISO 22317-Aligned Example

Time Frame

Description

0 - 1 hour

Immediate response phase

1 - 6 hours

Short-term disruption

6 - 24 hours

Same-day operational risk

24 - 72 hours

Multi-day service degradation

> 1 week

Strategic or systemic failure

These intervals should be approved by top management and applied uniformly across all activities.

5.3.4 — Define Methodology

Purpose

The methodology ensures that every department applies the same rules for impact assessment.
This promotes consistency, comparability, and defensibility of BIA results.

Core Methodological Components

  1. Impact Assessment Process
    Define how impacts will be assessed over time using agreed types, criteria, and timeframes.
    Always assume the worst-case scenario — peak operating period or high-demand season.
  2. Determining Recovery Objectives
    • Identify when impacts reach an unacceptable level → this defines the MTPD.
    • Set the Recovery Time Objective (RTO) — the time needed to recover activities before hitting MTPD.
    • Establish the Recovery Point Objective (RPO) — the acceptable level of data loss.
      These objectives must be realistic, measurable, and approved by management.
  3. Documentation and Templates
    Standardize BIA questionnaires, impact matrices, and reporting formats.
    This ensures uniformity whether data is gathered through interviews, surveys, or workshops.
  4. Information Validation

The BIA Leader should cross-check data for completeness and resolve discrepancies before analysis begins.

  1. Governance and Sign-Off

Top management must approve the agreed methodology before the organization proceeds to product, service, and activity prioritization (Clause 5.4).

Practical Tools and Crest Advisory Africa Best Practices

· ISOLTX BIA Module: Automates impact assessments, time-horizon analysis, and RTO/RPO calculations.

· ICE Matrix (Internal Control Effectiveness): Integrates BIA data with control assurance scoring.

· Combined Assurance Matrix: Aligns continuity, risk, audit, and compliance perspectives.

· P²ST² Framework: Ensures complete coverage of People, Processes, Systems, Technologies, and Tools dependencies.

Outputs of Clause 5.3

By the end of this clause, organizations should have:

Output

Description

Approved Impact Types & Criteria

Standardized across all units

Defined Time-Horizon Framework

Consistent intervals for escalation analysis

Agreed BIA Methodology

Documented process endorsed by leadership

Initial BIA Template or Tool

Used to capture and analyse results

Conclusion

Clause 5.3 of ISO/TS 22317:2021 represents the heart of the BIA methodology — transforming high-level planning into a practical, evidence-driven process.
It ensures that all participants share a common language for assessing impact and recovery priorities.

When implemented correctly, Clause 5.3 provides:

  • Consistency in measurement,
  • Transparency in analysis, and
  • Confidence in decision-making.

At Crest Advisory Africa, we position this clause as the bridge between compliance and strategic insight — ensuring that every BIA not only meets ISO standards but also drives resilient performance and certainty across the enterprise.