Clause 6.2 of ISO/TS 22317:2021 — Reviewing the BIA Results
Introduction
The Business Impact Analysis (BIA) is not a one-time compliance exercise; it is a living component of the Business Continuity Management System (BCMS).
Clause 6.2 of ISO/TS 22317:2021 requires organizations to periodically review and validate BIA results to ensure they remain representative of current business operations, dependencies, and strategic objectives.
This review safeguards the integrity of the BCMS, ensuring that continuity priorities and recovery objectives remain fit for purpose as the organization grows, transforms, and faces new risks.
6.2 — Review of BIA Results
Purpose
The intent of Clause 6.2 is to confirm that:
· The outputs of the BIA (priorities, RTOs, RPOs, MTPDs, dependencies) still reflect how the organization operates today;
· No outdated, inaccurate, or redundant information is being used to guide continuity decisions; and
· Emerging risks, technologies, and obligations are integrated into updated BIA findings.
This review converts the BIA from a static report into a continuous assurance mechanism.
1. Review Triggers
ISO 22317 identifies two main review triggers: periodic and event-driven.
a) Periodic Review
BIA results should be reassessed on a regular cycle, typically every 12 months, to maintain certification readiness and management confidence.
b) Event-Driven Review
A review must also occur whenever significant internal or external changes affect continuity priorities.
Typical triggers include:
|
Trigger Event |
Impact on BIA |
|
Mergers, Acquisitions, or Restructures |
New processes, systems, and dependencies introduced. |
|
Strategic Direction Change |
Altered objectives or markets shift product/service priorities. |
|
New or Amended Legislation |
Changes in regulatory response times or data protection requirements. |
|
Customer or Contractual Changes |
Updated service levels or penalties affect recovery objectives. |
|
Major ICT or Process Transformation |
New applications or automation alter RTOs and resource needs. |
|
Disruptions or Exercises |
Lessons learned reveal weaknesses or capability gaps. |
Crest Advisory Africa recommends linking BIA review scheduling directly to the BCMS Management Review Calendar and Risk Register updates, ensuring synchronization across governance functions.
2. Review Activities
The review of BIA results should include:
· Verification of Current Operations
Confirm that listed products, services, and activities still exist and are correctly prioritized.
Remove obsolete ones and add new functions or assets.
· Validation of Recovery Objectives
Re-evaluate RTOs, RPOs, and MTPDs against real recovery performance or recent incidents.
Adjust thresholds where operational capability or risk tolerance has changed.
· Assessment of Dependencies
Review whether supplier relationships, IT systems, or facilities have changed and whether recovery expectations remain valid.
· Alignment with Strategy
Ensure that continuity priorities remain consistent with the organization's current strategic direction and business model.
· Stakeholder Consultation
Engage activity owners, IT, risk, and compliance functions to confirm accuracy and gather cross-functional insights.
· Update Documentation
Amend the BIA Report, Continuity Requirements Statement, and BCMS records accordingly.
3. Analytical Considerations
When reviewing BIA results, organizations should analyse trends over time:
· Have RTOs become shorter due to improved technology or automation?
· Are cost-benefit trade-offs for continuity strategies still valid?
· Are resource dependencies consolidating or diversifying (e.g., cloud migrations)?
· Are any impact ratings escalating because of regulatory or reputational sensitivity?
This trend analysis ensures the organization continually strengthens its resilience maturity rather than simply maintaining compliance.
4. Integration with the BCMS Management Review
Clause 6.2 feeds directly into ISO 22301 Clause 9.3 (Management Review).
Findings from the BIA review become a standing agenda item, enabling leadership to:
· Confirm continuity priorities remain aligned with corporate objectives;
· Approve any changes to RTO/RPO targets or resource allocations; and
· Authorize necessary corrective actions or strategy updates.
Crest Advisory Africa encourages documenting these decisions in Management Review Minutes and Combined Assurance Reports for traceability and audit assurance.
5. Deliverables of Clause 6.2
|
Deliverable |
Description |
|
Updated BIA Results Report |
Revised document reflecting current operational context. |
|
Change Log / Version History |
Record of modifications to activities, impacts, or RTOs. |
|
Validation Checklist |
Evidence of stakeholder verification and approval. |
|
Revised Continuity Requirements Statement (CRS) |
Updated business continuity priorities and dependencies. |
|
Management Review Record |
Formal acknowledgment of reviewed and approved updates. |
These deliverables ensure that the BIA remains a controlled, auditable artefact of the BCMS.
6. Crest Advisory Africa Best-Practice Insights
· Automate the Review Cycle
Use the ISOLTX BIA Module to set automated reminders, track change approvals, and manage version control for all BIA records.
· Link to Performance Metrics
Incorporate continuity performance data (from exercises or real incidents) to adjust RTOs based on factual evidence.
· Engage Assurance Functions
Include Risk, Audit, and Compliance in the review to ensure consistency with the Combined Assurance Matrix.
· Maintain Stakeholder Engagement
Treat BIA review workshops as awareness sessions that reinforce resilience culture across the organization.
· Benchmark Against Industry Trends
Compare your updated BIA results to peer benchmarks or ISO benchmarking data to maintain competitive resilience posture.
Conclusion
Clause 6.2 of ISO/TS 22317:2021 ensures that the Business Impact Analysis remains relevant, reliable, and resilient in a changing world.
By systematically reviewing and updating BIA results, organizations maintain agility, compliance, and confidence in their ability to respond to disruption.
At Crest Advisory Africa, we position Clause 6.2 as the assurance anchor of the BIA lifecycle — the mechanism that keeps the BCMS synchronized with real-world dynamics.
Through the P²ST² Methodology, the ISOLTX Platform, and our Risk Maturity Process Assessment Model (RMPAM), we help organizations institutionalize a cycle of review, refinement, and readiness — ensuring enduring Performance and Certainty.