Clause 5.3 of ISO/TS 22317:2021 — Defining the Approach for an Effective Business Impact Analysis
Introduction
Clause 5.3 of ISO/TS 22317:2021 marks the critical stage where the Business Impact Analysis (BIA) moves from planning to execution.
It requires the organization to formally agree on the approach that will govern how the BIA is performed, ensuring that impact assessments are consistent, measurable, and defendable.
This clause is divided into four sub-clauses — each forming a cornerstone of methodological integrity:
- 5.3.1 Understand Impacts
- 5.3.2 Define Impact Types and Criteria
- 5.3.3 Define Time Frames
- 5.3.4 Define Methodology
When properly implemented, these steps ensure the BIA produces results that are both quantitative and strategic, directly supporting the continuity strategy phase under ISO 22331.
5.3.1 — Understand Impacts
Purpose
Before measuring impact, the organization must first understand what impact means in its context.
A “disruption†is not just a technical failure — it's an event that prevents or degrades the delivery of products and services, affecting customers, regulators, employees, or the community.
Key Requirements
To comply with 5.3.1, organizations must:
- Identify how internal and external disruptions could affect delivery of products and services.
- Recognize the stakeholders or interested parties who experience or react to these impacts.
- Understand that impacts intensify over time — even a short outage can escalate into regulatory, reputational, or financial crises.
Typical Impact Sources
|
Interested Party |
Example of Impact |
|
Customers |
Complaints, loss of confidence, revenue loss |
|
Regulators |
Sanctions, withdrawal of license |
|
Shareholders |
Drop in valuation or investment confidence |
|
Employees |
Loss of productivity, attrition |
|
Partners/Suppliers |
Contract penalties or disrupted supply chain |
|
Public/Media |
Negative reputation or loss of trust |
Crest Advisory Africa advises that this phase include stakeholder mapping and risk-impact workshops, ensuring a full 360° view of how disruption manifests across the ecosystem.
5.3.2 — Define Impact Types and Criteria
Purpose
To measure consistently, an organization must define its impact types and rating criteria.
This ensures that qualitative and quantitative impacts are translated into comparable metrics.
Common Impact Types
While ISO 22317 offers flexibility, the standard recommends consideration of the following eight impact dimensions:
- Business Objectives
- Financial
- Legal, Regulatory & Contractual
- Operational
- Reputational
- Health & Safety
- Environmental
- Market Share or Customer Impact
Organizations may consolidate or expand these, depending on their context.
Developing Impact Criteria
Each impact type should have a graded scale — typically five levels (Insignificant to Catastrophic).
Crest Advisory Africa's 5-Point Impact Scale matrix aligns perfectly with ISO 22317's guidance and can be customized to industry thresholds.
Example excerpt from a standardized scale:
|
Impact Level |
Financial Impact |
Reputational Impact |
Regulatory Impact |
|
1 - Low |
< R100 000 loss |
Minor internal concern |
Informal query from regulator |
|
3 - High |
R1 - 5 million loss |
Regional media attention |
Public warning or minor fine |
|
5 - Catastrophic |
> R10 million loss |
National crisis / brand collapse |
License suspension / criminal sanction |
Thresholds and Acceptability
The organization must also determine when impact becomes unacceptable — the Maximum Tolerable Period of Disruption (MTPD).
This is the time at which operational or reputational damage exceeds acceptable limits.
5.3.3 — Define Time Frames
Purpose
Different impacts evolve at different rates.
Financial losses may grow gradually, while reputational or regulatory impacts can spike instantly.
Clause 5.3.3 requires defining consistent time intervals to evaluate how impact escalates.
ISO 22317-Aligned Example
|
Time Frame |
Description |
|
0 - 1 hour |
Immediate response phase |
|
1 - 6 hours |
Short-term disruption |
|
6 - 24 hours |
Same-day operational risk |
|
24 - 72 hours |
Multi-day service degradation |
|
> 1 week |
Strategic or systemic failure |
These intervals should be approved by top management and applied uniformly across all activities.
5.3.4 — Define Methodology
Purpose
The methodology ensures that every department applies the same rules for impact assessment.
This promotes consistency, comparability, and defensibility of BIA results.
Core Methodological Components
- Impact Assessment Process
Define how impacts will be assessed over time using agreed types, criteria, and timeframes.
Always assume the worst-case scenario — peak operating period or high-demand season. - Determining Recovery Objectives
- Identify when impacts reach an unacceptable level → this defines the MTPD.
- Set the Recovery Time Objective (RTO) — the time needed to recover activities before hitting MTPD.
- Establish the Recovery Point Objective (RPO) — the acceptable level of data loss.
These objectives must be realistic, measurable, and approved by management. - Documentation and Templates
Standardize BIA questionnaires, impact matrices, and reporting formats.
This ensures uniformity whether data is gathered through interviews, surveys, or workshops. - Information Validation
The BIA Leader should cross-check data for completeness and resolve discrepancies before analysis begins.
- Governance and Sign-Off
Top management must approve the agreed methodology before the organization proceeds to product, service, and activity prioritization (Clause 5.4).
Practical Tools and Crest Advisory Africa Best Practices
· ISOLTX BIA Module: Automates impact assessments, time-horizon analysis, and RTO/RPO calculations.
· ICE Matrix (Internal Control Effectiveness): Integrates BIA data with control assurance scoring.
· Combined Assurance Matrix: Aligns continuity, risk, audit, and compliance perspectives.
· P²ST² Framework: Ensures complete coverage of People, Processes, Systems, Technologies, and Tools dependencies.
Outputs of Clause 5.3
By the end of this clause, organizations should have:
|
Output |
Description |
|
Approved Impact Types & Criteria |
Standardized across all units |
|
Defined Time-Horizon Framework |
Consistent intervals for escalation analysis |
|
Agreed BIA Methodology |
Documented process endorsed by leadership |
|
Initial BIA Template or Tool |
Used to capture and analyse results |
Conclusion
Clause 5.3 of ISO/TS 22317:2021 represents the heart of the BIA methodology — transforming high-level planning into a practical, evidence-driven process.
It ensures that all participants share a common language for assessing impact and recovery priorities.
When implemented correctly, Clause 5.3 provides:
- Consistency in measurement,
- Transparency in analysis, and
- Confidence in decision-making.
At Crest Advisory Africa, we position this clause as the bridge between compliance and strategic insight — ensuring that every BIA not only meets ISO standards but also drives resilient performance and certainty across the enterprise.