Clause 5.4 of ISO/TS 22317:2021 — Determining Product and Service Priorities with Top Management

Introduction

After defining impact types, timeframes, and methodology in Clause 5.3, organizations are now ready to establish their continuity priorities.

Clause 5.4 of ISO/TS 22317:2021 describes how top management determines which products and services are most critical to the organization's survival, reputation, and regulatory obligations.

This phase moves the BIA from technical analysis to executive decision-making — translating impact data into strategic priorities that will drive continuity and recovery strategies under ISO 22331.

5.4 — Determining Product and Service Priorities

Objective

The objective of Clause 5.4 is to ensure that organizational leadership formally determines which products and services must be restored first following a disruption, and within what timeframe.

This determination must be based on:

· Measurable impact data from the BIA methodology (Clause 5.3)

· Legal, regulatory, contractual, and stakeholder obligations

· Strategic objectives and long-term business direction

Why Top Management Must Lead This Step

ISO 22317 clearly states that prioritization decisions cannot be delegated to operational levels alone.
Only top management has the full view of:

· Strategic goals and corporate mission

· Financial viability thresholds

· Legal and reputational risk exposure

· Balancing trade-offs between customer commitments and internal capacity

Crest Advisory Africa emphasizes that leadership's engagement here is both a compliance requirement and a strategic imperative — ensuring continuity planning aligns with the organization's governance, risk, and performance objectives.

5.4.1 — Overview

Top management's task is to evaluate impact evidence and determine, for each product or service:

· When a prolonged disruption becomes unacceptable

· The minimum acceptable level of service during recovery

· Which internal or external dependencies are mission-critical

· These decisions establish the foundation for subsequent recovery planning (Clause 5.5 - Determine Prioritized Activities).

5.4.2 — Inputs

Clause 5.4.2 defines the information required before prioritization begins. Leadership should review:

Input

Description

Mission and Strategic Objectives

Understanding of how each product or service supports organizational goals.

BCMS Scope

Confirmation of which areas fall within the analysis boundary.

Previous Reviews or BIAs

Reference to existing priority decisions for comparison and validation.

Legal and Regulatory Requirements

Identification of statutory obligations and licensing dependencies.

Contractual Commitments

SLAs and penalty clauses that influence recovery urgency.

Stakeholder Expectations

Customer, investor, and community tolerance levels for downtime.

Impact Assessment Results

Data from Clause 5.3 showing escalation of impact over time.

Lessons from Past Disruptions

Historical evidence from incidents or exercises.

This evidence ensures that decisions are fact-based and traceable to objective information.

5.4.3 — Product and Service Priority Determination

This is the core activity of Clause 5.4 — where leadership ranks all products and services by criticality and determines their corresponding recovery thresholds.

Step 1 — Evaluate Impacts

Using results from the BIA impact matrix, determine how each product or service contributes to:

· Revenue protection

· Regulatory compliance

· Reputation and customer trust

· Public safety or environmental obligations

Step 2 — Identify MTPD

For each product or service, establish the Maximum Tolerable Period of Disruption (MTPD) — the point at which continued downtime becomes unacceptable.

Example:

Product/Service

MTPD

Critical Impact

Customer Call Centre Operations

8 hours

Severe reputational & financial loss

Payroll Processing

24 hours

Employee welfare & compliance risk

Client Data Hosting

4 hours

Legal & data protection exposure

Step 3 — Define Minimum Acceptable Capacity

Determine the minimum capacity required to meet stakeholder needs during the recovery phase (e.g., 50 % service level, alternate site operation, manual process).

Step 4 — Rank and Approve Priorities

Products and services are ranked in order of importance, and top management approves the hierarchy formally.

This approval ensures corporate alignment between continuity plans and the organization's strategy.

5.4.4 — Outcomes

Clause 5.4 requires that the organization document and approve a list of prioritized products and services, including their continuity requirements and justifications.

Expected Outputs

Output

Description

Prioritized Products & Services Register

A master list identifying all products/services with assigned criticality levels.

MTPD & RTO Summary Table

Defines recovery time expectations per service.

Continuity Requirement Statement

Outlines minimum capacity and dependencies.

Updated BCMS Scope (if applicable)

Adjusted based on new insights or exclusions.

Management Approval Record

Evidence of executive endorsement and sign-off.

These outcomes become the baseline input for Clause 5.5 (Determining Prioritized Activities) and for strategy selection under ISO 22331.

Practical Implementation — Crest Advisory Africa Insights

To operationalize Clause 5.4 effectively, Crest Advisory Africa recommends:

· Use Executive Workshops

· Facilitate leadership sessions using visual prioritization tools (e.g., criticality heatmaps, impact-time graphs).

· Adopt a Tiered Criticality Model

· Categorize outputs into Tier 1 (Critical), Tier 2 (High), Tier 3 (Medium), and Tier 4 (Low).

· Integrate Decision Support Tools

· Utilize the ISOLTX BIA Module to consolidate inputs, auto-calculate recovery thresholds, and visualize dependencies in real time.

· Ensure Governance Alignment

· Record approvals through BCMS Steering Committee minutes and link outcomes to enterprise risk registers, ensuring traceability under ISO 31000 and ISO 22301.

Governance, Transparency, and Assurance

A well-governed Clause 5.4 process embodies combined assurance principles — Risk Management identifies threats, the BIA quantifies operational impact, and top management confirms priorities within the organization's risk appetite.

Documented evidence of these deliberations provides:

· Audit assurance under ISO 22301 (Clause 9.3 - Management Review)

· Demonstrable due diligence to regulators and certification bodies

· Tangible proof of leadership accountability in resilience management

Conclusion

Clause 5.4 of ISO/TS 22317:2021 transforms the BIA from an analytical exercise into a strategic decision-making process led by top management.
It ensures that recovery priorities are based on both quantitative impact data and strategic intent.

By implementing Clause 5.4 with rigor and governance, organizations achieve:

· Clear continuity priorities

· Alignment between business strategy and resilience planning

· Management ownership of continuity outcomes

At Crest Advisory Africa, we regard Clause 5.4 as the executive heartbeat of the BIA — the moment where leadership converts insight into strategy, ensuring that resilience becomes a board-level performance enabler, not just a compliance function.