Impact criteria turn disruption consequences into a common decision language. The aim is not to manufacture a single “criticality score”; it is to describe how consequences grow over time so different activities can be compared consistently and recovery priorities can be defended.
Start with time, not a generic risk score
A BIA asks what happens when an activity is unavailable for a period of time. Define common assessment points—such as hours, days or weeks—appropriate to the organization, then assess each impact dimension at those same points. This exposes the point at which an interruption becomes unacceptable and prevents teams from choosing recovery targets simply because a familiar number looks important.
Keep probability out of the impact scale. Likelihood belongs in continuity risk assessment; BIA impact criteria describe consequence if disruption occurs. Mixing the two can make a low-frequency but intolerable obligation appear less important than it is.
- Use the same time bands across comparable business units.
- Define what each severity level means before workshops begin.
- Allow evidence and narrative to override false precision from arithmetic averages.
Define dimensions with observable anchors
Each impact dimension needs anchors that a facilitator can test. Financial criteria can use ranges plus materiality context; regulatory criteria should refer to breached duties, reporting deadlines or licence conditions; safety criteria should describe credible harm or loss of protective controls; customer criteria should consider affected population, vulnerability, service alternatives and duration; operational criteria should describe backlog, capacity loss and cascading dependencies; reputation criteria should use observable stakeholder consequences rather than subjective embarrassment.
- Avoid labels such as low/medium/high without definitions.
- Do not use financial thresholds as a proxy for safety or regulatory severity.
- Document whether thresholds are absolute, percentage-based, or both.
Calibrate the scale before using it
Test draft criteria against several known services: one clearly critical, one moderately time-sensitive and one that can wait. If every activity becomes severe at the first time band, the thresholds are too broad. If legal, safety or customer obligations disappear inside an average score, the aggregation rule is unsafe. Calibration should involve BCM, finance, legal/compliance, safety, customer operations and technology where relevant.
- Record examples at each severity level.
- Resolve terminology differences before workshops.
- Approve the criteria and effective date so later BIAs use the same baseline.
Use scoring without hiding the decision
A numeric score can help sort a large portfolio, but it should not replace the underlying impact profile. Preserve dimension-by-dimension results and the time at which each threshold is crossed. A practical prioritization rule can use the highest material impact, mandatory obligations and dependency effects, then use a composite score only as supporting information.
- Flag non-negotiable obligations separately.
- Show the time-to-threshold alongside any score.
- Require rationale when a final priority differs from the calculated result.
Worked example
Suppose a customer payment activity has modest direct loss after four hours, but after eight hours a regulatory settlement deadline is missed and vulnerable customers cannot access an alternative channel. The correct conclusion is not simply an average of “financial 2, regulatory 5, customer 4.” The BIA should record the eight-hour decision point, the obligations that drive it, the affected customers and the capability needed before that threshold.
Evidence and governance
Retain the approved scale, definitions, calibration examples, workshop evidence, source data, exceptions and approval history. Review criteria after major regulatory change, material incidents, acquisitions, service redesign or changes in organizational risk tolerance. When thresholds change, identify which existing BIAs need reassessment rather than silently applying the new scale to old results.
- Criteria have an owner and version.
- Scoring can be traced to evidence.
- Exceptions and overrides are visible and approved.
- The scale produces meaningful differentiation across activities.
Acceptance test
A reviewer should be able to take two different activities, apply the published criteria at the same time bands and understand why their impact profiles differ. The result should support recovery sequencing and management decisions without requiring knowledge of who completed the original workshop.
Designing thresholds that work across business units
Thresholds should be material enough to distinguish decisions but flexible enough to work across different service sizes. For financial impact, combine absolute ranges with context such as percentage of daily revenue or contractual exposure. For customer impact, consider both volume and severity: a small number of medically or financially vulnerable customers can justify a higher consequence than a much larger population facing a minor inconvenience. For regulatory impact, distinguish a reportable event, a missed mandatory deadline, a repeated control failure and a threat to licence or authorization.
Where an organization operates across jurisdictions, maintain a common enterprise scale but document local overlays for legal and regulatory obligations. The local overlay should not silently change the meaning of enterprise severity levels; it should explain which local events meet those levels. This preserves portfolio comparability while respecting jurisdiction-specific duties.
Facilitating scoring discussions
Ask participants to describe the consequence first and select the score second. Questions such as “what stops, who is affected, what deadline is missed, how large is the backlog, and what evidence supports that?” produce better results than asking “is this a four or a five?” Challenge sudden jumps between time bands and confirm whether the impact is cumulative, triggered by a fixed deadline, or dependent on another event.
Record uncertainty instead of forcing false certainty. If a contractual penalty is disputed or customer volume is unknown, capture the range, source and action needed to validate it. The BIA can still support a provisional decision while making the evidence gap visible.
Common scoring mistakes
- Averaging safety or regulatory severity down with low financial impact.
- Using probability, control maturity or risk likelihood inside an impact score.
- Allowing every department to define its own meaning of “major.”
- Scoring reputation from intuition without identifying an observable stakeholder consequence.
- Setting thresholds so low that almost every activity reaches the maximum level immediately.
- Changing criteria between workshops without reassessing earlier results.
Related BCM.Center resources: Reputation Impact in BIA · Safety Impact in BIA.