Clause 5.4 of ISO/TS 22317:2021 — Determining Product and Service Priorities with Top Management
Introduction
After defining impact types, timeframes, and methodology in Clause 5.3, organizations are now ready to establish their continuity priorities.
Clause 5.4 of ISO/TS 22317:2021 describes how top management determines which products and services are most critical to the organization's survival, reputation, and regulatory obligations.
This phase moves the BIA from technical analysis to executive decision-making — translating impact data into strategic priorities that will drive continuity and recovery strategies under ISO 22331.
5.4 — Determining Product and Service Priorities
Objective
The objective of Clause 5.4 is to ensure that organizational leadership formally determines which products and services must be restored first following a disruption, and within what timeframe.
This determination must be based on:
· Measurable impact data from the BIA methodology (Clause 5.3)
· Legal, regulatory, contractual, and stakeholder obligations
· Strategic objectives and long-term business direction
Why Top Management Must Lead This Step
ISO 22317 clearly states that prioritization decisions cannot be delegated to operational levels alone.
Only top management has the full view of:
· Strategic goals and corporate mission
· Financial viability thresholds
· Legal and reputational risk exposure
· Balancing trade-offs between customer commitments and internal capacity
Crest Advisory Africa emphasizes that leadership's engagement here is both a compliance requirement and a strategic imperative — ensuring continuity planning aligns with the organization's governance, risk, and performance objectives.
5.4.1 — Overview
Top management's task is to evaluate impact evidence and determine, for each product or service:
· When a prolonged disruption becomes unacceptable
· The minimum acceptable level of service during recovery
· Which internal or external dependencies are mission-critical
· These decisions establish the foundation for subsequent recovery planning (Clause 5.5 - Determine Prioritized Activities).
5.4.2 — Inputs
Clause 5.4.2 defines the information required before prioritization begins. Leadership should review:
|
Input |
Description |
|
Mission and Strategic Objectives |
Understanding of how each product or service supports organizational goals. |
|
BCMS Scope |
Confirmation of which areas fall within the analysis boundary. |
|
Previous Reviews or BIAs |
Reference to existing priority decisions for comparison and validation. |
|
Legal and Regulatory Requirements |
Identification of statutory obligations and licensing dependencies. |
|
Contractual Commitments |
SLAs and penalty clauses that influence recovery urgency. |
|
Stakeholder Expectations |
Customer, investor, and community tolerance levels for downtime. |
|
Impact Assessment Results |
Data from Clause 5.3 showing escalation of impact over time. |
|
Lessons from Past Disruptions |
Historical evidence from incidents or exercises. |
This evidence ensures that decisions are fact-based and traceable to objective information.
5.4.3 — Product and Service Priority Determination
This is the core activity of Clause 5.4 — where leadership ranks all products and services by criticality and determines their corresponding recovery thresholds.
Step 1 — Evaluate Impacts
Using results from the BIA impact matrix, determine how each product or service contributes to:
· Revenue protection
· Regulatory compliance
· Reputation and customer trust
· Public safety or environmental obligations
Step 2 — Identify MTPD
For each product or service, establish the Maximum Tolerable Period of Disruption (MTPD) — the point at which continued downtime becomes unacceptable.
Example:
|
Product/Service |
MTPD |
Critical Impact |
|
Customer Call Centre Operations |
8 hours |
Severe reputational & financial loss |
|
Payroll Processing |
24 hours |
Employee welfare & compliance risk |
|
Client Data Hosting |
4 hours |
Legal & data protection exposure |
Step 3 — Define Minimum Acceptable Capacity
Determine the minimum capacity required to meet stakeholder needs during the recovery phase (e.g., 50 % service level, alternate site operation, manual process).
Step 4 — Rank and Approve Priorities
Products and services are ranked in order of importance, and top management approves the hierarchy formally.
This approval ensures corporate alignment between continuity plans and the organization's strategy.
5.4.4 — Outcomes
Clause 5.4 requires that the organization document and approve a list of prioritized products and services, including their continuity requirements and justifications.
Expected Outputs
|
Output |
Description |
|
Prioritized Products & Services Register |
A master list identifying all products/services with assigned criticality levels. |
|
MTPD & RTO Summary Table |
Defines recovery time expectations per service. |
|
Continuity Requirement Statement |
Outlines minimum capacity and dependencies. |
|
Updated BCMS Scope (if applicable) |
Adjusted based on new insights or exclusions. |
|
Management Approval Record |
Evidence of executive endorsement and sign-off. |
These outcomes become the baseline input for Clause 5.5 (Determining Prioritized Activities) and for strategy selection under ISO 22331.
Practical Implementation — Crest Advisory Africa Insights
To operationalize Clause 5.4 effectively, Crest Advisory Africa recommends:
· Use Executive Workshops
· Facilitate leadership sessions using visual prioritization tools (e.g., criticality heatmaps, impact-time graphs).
· Adopt a Tiered Criticality Model
· Categorize outputs into Tier 1 (Critical), Tier 2 (High), Tier 3 (Medium), and Tier 4 (Low).
· Integrate Decision Support Tools
· Utilize the ISOLTX BIA Module to consolidate inputs, auto-calculate recovery thresholds, and visualize dependencies in real time.
· Ensure Governance Alignment
· Record approvals through BCMS Steering Committee minutes and link outcomes to enterprise risk registers, ensuring traceability under ISO 31000 and ISO 22301.
Governance, Transparency, and Assurance
A well-governed Clause 5.4 process embodies combined assurance principles — Risk Management identifies threats, the BIA quantifies operational impact, and top management confirms priorities within the organization's risk appetite.
Documented evidence of these deliberations provides:
· Audit assurance under ISO 22301 (Clause 9.3 - Management Review)
· Demonstrable due diligence to regulators and certification bodies
· Tangible proof of leadership accountability in resilience management
Conclusion
Clause 5.4 of ISO/TS 22317:2021 transforms the BIA from an analytical exercise into a strategic decision-making process led by top management.
It ensures that recovery priorities are based on both quantitative impact data and strategic intent.
By implementing Clause 5.4 with rigor and governance, organizations achieve:
· Clear continuity priorities
· Alignment between business strategy and resilience planning
· Management ownership of continuity outcomes
At Crest Advisory Africa, we regard Clause 5.4 as the executive heartbeat of the BIA — the moment where leadership converts insight into strategy, ensuring that resilience becomes a board-level performance enabler, not just a compliance function.