PP3: The Blueprint of Priority: Why You Can’t Save Everything at Once
When disruption strikes, recovery shouldn't belong to whoever shouts loudest. Explore BCI GPG 7.0 Professional Practice 3 (PP3: Analysis)— covering BIA modular levels, survival metrics (MTPD, RTO, RPO), and consequence-first risk assessment.
This article is part of my hands-on BCMS Implementation Series, where we build an end-to-end Business Continuity Management System following the BCI Good Practice Guidelines (GPG Edition 7.0).
- Previous in Series: PP1: Establishing a BCMS | PP2: Embracing Business Continuity
- CBCI Exam Study Reference: If you are preparing for your certification, read my original study notes in the PP3 Analysis Learning Notes.
When a major disruption strikes—whether it’s a total system outage, a cyber incident, or a regional power failure—the atmosphere in an unprepared organisation is dictated by the "Scream Test."
In this reactive environment, recovery resources flow toward whichever department head shouts the loudest or carries the most political weight. This isn't strategy; it’s survival by volume, and it is a guaranteed recipe for failure.
To transcend this chaos, senior leadership must first lay the policy and governance foundations in PP1: Establishing a BCMS and build organisational buy-in through PP2: Embracing Business Continuity.
Once governance and culture are aligned, we move to the first technical stage of the BCMS lifecycle: BCI Professional Practice 3 (PP3: Analysis).
As detailed in GPG Edition 7.0, PP3 contains two core analytical disciplines: the Business Impact Analysis (BIA) and the Risk Assessment (RA). Together, they form the data-driven antidote to the Scream Test. By identifying what truly matters before a crisis hits, we shift from reactive chaos to structured, strategic resilience.
Part 1: The Business Impact Analysis (BIA)
The BIA is the core technique used to define the impact of a disruption over time. It establishes our prioritised activities, recovery timeframes, and resource requirements.
GPG Edition 7.0 outlines a modular approach to the BIA across three distinct levels, preventing organisations from getting bogged down in "analysis paralysis":
1. The Product & Services BIA
Products and services represent the high-level outputs provided to external interested parties. Assigned and approved directly by Top Management, this BIA confirms or modifies the overarching scope of our BCMS.
Real-World Baseline: In a professional services or regulatory environment, this represents the primary client-facing delivery pipeline (e.g., end-to-end client onboarding or scheduled assessments).
2. The Process BIA (Optional)
A process is a set of interrelated activities that transform inputs into outputs. While mandatory for process-heavy industries like manufacturing, GPG 7.0 explicitly makes the Process BIA optional for service-based organisations. Skipping this layer for service-driven entities significantly reduces administrative overhead without sacrificing analytical rigour.
3. The Activity BIA
Activities are the ground-level tasks that deliver our products and services. The Activity BIA breaks down the specific resource dependencies required to keep these activities alive: People, Vital Records, Physical Infrastructure, IT Systems, Logistics, Finance, and Priority Suppliers.
Survival Metrics: Defining the Parameters of Resilience
To make BIA data actionable, we must translate qualitative "feelings" into quantifiable survival thresholds. Using a core enterprise application platform as our baseline, GPG 7.0 defines four critical metrics:
- MTPD (Maximum Tolerable Period of Disruption): Our survival cliff-edge. If the enterprise portal is unavailable for 5 days, a fundamental breach of statutory SLAs and operational delivery is triggered. This is not an inconvenience—it is a compliance failure and a legal vulnerability.
- RTO (Recovery Time Objective): Our target safety margin. Set safely within the MTPD (e.g., 2 days), the RTO dictates how fast disrupted activities must resume at a specified minimum capacity.
- MBCO (Minimum Business Continuity Objective): Our lifeboat capacity. We do not need 100% operational capacity on day one; we set an MBCO (e.g., 60% of scheduled processing volume) to maintain core operational integrity.
- RPO (Recovery Point Objective): The non-negotiable threshold for data integrity and maximum tolerable data loss. Given the sensitivity of transactional data submissions, the business mandates a 1-hour RPO, driving IT backup schedules.
BIA Data Collection: The BC Professional as a Corporate Detective
A common executive error is viewing the BIA as a dry administrative audit. In reality, the BC practitioner acts as a corporate detective.
While questionnaires and surveys generate volume, GPG 7.0 highlights face-to-face collaborative workshops as the gold standard for data gathering. Workshops bring activity owners together to uncover:
- Single Points of Failure (SPOFs): Spotting the "lone wolf" staff member holding the only key to a critical process.
- Manual Workarounds: Uncovering how teams can run paper-based fallback options if digital platforms fail.
- Interdependencies: Mapping complex internal and external supply chain links.
Note: These workshops do double duty—they serve as an active mechanism for PP2: Embracing Business Continuity, reinforcing awareness and converting individual heroics into a shared corporate resilience culture.
Part 2: The Risk Assessment (RA)
Once the BIA is consolidated and approved by Top Management, we move to the second half of PP3: the Risk Assessment (RA).
Flipping the Sequence: Consequence-First Thinking
Conventional wisdom suggests conducting a Risk Assessment first—cataloguing threats like floods, cyberattacks, or power outages. However, GPG Edition 7.0 advocates for "consequence-first" thinking: performing the BIA before the RA.
By completing the BIA first, the organization establishes its critical operational delivery timelines as absolute priorities. The subsequent Risk Assessment then focuses exclusively on threats that could impact those specific prioritised activities and their required resources.
This creates massive efficiency gains for leadership. Instead of wasting time assessing generic risks to non-critical administrative functions, we only investigate threats to the assets we have already proved we cannot afford to lose.
Using a standard risk matrix (Likelihood × Impact), the Risk Assessment highlights unacceptable threat exposures, single points of failure, and supply chain vulnerabilities.
From Analysis to Design
The Business Impact Analysis and Risk Assessment are not compliance obligations to be filed away in a drawer; they form a living strategic dashboard.
A successful PP3 phase delivers the exact engineering specifications required for cost-effective recovery solution design in the next stage of our implementation journey.
In a world of infinite potential disruptions and finite budgets, PP3 Analysis remains our most powerful tool for ensuring that when you cannot save everything at once, you save exactly what matters most.
Up Next in the Series...
Now that we have established our BC requirements, MTPDs, and RTOs through PP3, how do we actually build cost-effective recovery options to meet them?
In the next article, we cover PP4: Solutions Design, where we look at gap analysis, strategy selection, and designing recovery options for People, IT, Premises, and Suppliers.
