Clause 6.2 of ISO/TS 22317:2021 — Reviewing the BIA Results

Introduction

The Business Impact Analysis (BIA) is not a one-time compliance exercise; it is a living component of the Business Continuity Management System (BCMS).
Clause 6.2 of ISO/TS 22317:2021 requires organizations to periodically review and validate BIA results to ensure they remain representative of current business operations, dependencies, and strategic objectives.

This review safeguards the integrity of the BCMS, ensuring that continuity priorities and recovery objectives remain fit for purpose as the organization grows, transforms, and faces new risks.

6.2 — Review of BIA Results

Purpose

The intent of Clause 6.2 is to confirm that:

· The outputs of the BIA (priorities, RTOs, RPOs, MTPDs, dependencies) still reflect how the organization operates today;

· No outdated, inaccurate, or redundant information is being used to guide continuity decisions; and

· Emerging risks, technologies, and obligations are integrated into updated BIA findings.

This review converts the BIA from a static report into a continuous assurance mechanism.

1. Review Triggers

ISO 22317 identifies two main review triggers: periodic and event-driven.

a) Periodic Review

BIA results should be reassessed on a regular cycle, typically every 12 months, to maintain certification readiness and management confidence.

b) Event-Driven Review

A review must also occur whenever significant internal or external changes affect continuity priorities.
Typical triggers include:

Trigger Event

Impact on BIA

Mergers, Acquisitions, or Restructures

New processes, systems, and dependencies introduced.

Strategic Direction Change

Altered objectives or markets shift product/service priorities.

New or Amended Legislation

Changes in regulatory response times or data protection requirements.

Customer or Contractual Changes

Updated service levels or penalties affect recovery objectives.

Major ICT or Process Transformation

New applications or automation alter RTOs and resource needs.

Disruptions or Exercises

Lessons learned reveal weaknesses or capability gaps.

Crest Advisory Africa recommends linking BIA review scheduling directly to the BCMS Management Review Calendar and Risk Register updates, ensuring synchronization across governance functions.

2. Review Activities

The review of BIA results should include:

· Verification of Current Operations

Confirm that listed products, services, and activities still exist and are correctly prioritized.
Remove obsolete ones and add new functions or assets.

· Validation of Recovery Objectives

Re-evaluate RTOs, RPOs, and MTPDs against real recovery performance or recent incidents.
Adjust thresholds where operational capability or risk tolerance has changed.

· Assessment of Dependencies

Review whether supplier relationships, IT systems, or facilities have changed and whether recovery expectations remain valid.

· Alignment with Strategy

Ensure that continuity priorities remain consistent with the organization's current strategic direction and business model.

· Stakeholder Consultation

Engage activity owners, IT, risk, and compliance functions to confirm accuracy and gather cross-functional insights.

· Update Documentation

Amend the BIA Report, Continuity Requirements Statement, and BCMS records accordingly.

3. Analytical Considerations

When reviewing BIA results, organizations should analyse trends over time:

· Have RTOs become shorter due to improved technology or automation?

· Are cost-benefit trade-offs for continuity strategies still valid?

· Are resource dependencies consolidating or diversifying (e.g., cloud migrations)?

· Are any impact ratings escalating because of regulatory or reputational sensitivity?

This trend analysis ensures the organization continually strengthens its resilience maturity rather than simply maintaining compliance.

4. Integration with the BCMS Management Review

Clause 6.2 feeds directly into ISO 22301 Clause 9.3 (Management Review).
Findings from the BIA review become a standing agenda item, enabling leadership to:

· Confirm continuity priorities remain aligned with corporate objectives;

· Approve any changes to RTO/RPO targets or resource allocations; and

· Authorize necessary corrective actions or strategy updates.

Crest Advisory Africa encourages documenting these decisions in Management Review Minutes and Combined Assurance Reports for traceability and audit assurance.

5. Deliverables of Clause 6.2

Deliverable

Description

Updated BIA Results Report

Revised document reflecting current operational context.

Change Log / Version History

Record of modifications to activities, impacts, or RTOs.

Validation Checklist

Evidence of stakeholder verification and approval.

Revised Continuity Requirements Statement (CRS)

Updated business continuity priorities and dependencies.

Management Review Record

Formal acknowledgment of reviewed and approved updates.

These deliverables ensure that the BIA remains a controlled, auditable artefact of the BCMS.

6. Crest Advisory Africa Best-Practice Insights

· Automate the Review Cycle

Use the ISOLTX BIA Module to set automated reminders, track change approvals, and manage version control for all BIA records.

· Link to Performance Metrics

Incorporate continuity performance data (from exercises or real incidents) to adjust RTOs based on factual evidence.

· Engage Assurance Functions

Include Risk, Audit, and Compliance in the review to ensure consistency with the Combined Assurance Matrix.

· Maintain Stakeholder Engagement

Treat BIA review workshops as awareness sessions that reinforce resilience culture across the organization.

· Benchmark Against Industry Trends

Compare your updated BIA results to peer benchmarks or ISO benchmarking data to maintain competitive resilience posture.

Conclusion

Clause 6.2 of ISO/TS 22317:2021 ensures that the Business Impact Analysis remains relevant, reliable, and resilient in a changing world.
By systematically reviewing and updating BIA results, organizations maintain agility, compliance, and confidence in their ability to respond to disruption.

At Crest Advisory Africa, we position Clause 6.2 as the assurance anchor of the BIA lifecycle — the mechanism that keeps the BCMS synchronized with real-world dynamics.
Through the P²ST² Methodology, the ISOLTX Platform, and our Risk Maturity Process Assessment Model (RMPAM), we help organizations institutionalize a cycle of review, refinement, and readiness — ensuring enduring Performance and Certainty.