Business Impact Analysis

MBCO Guide: Define Minimum Business Continuity Objectives That Can Be Tested

MBCO expresses the minimum acceptable level of products or services during disruption and makes recovery capacity measurable rather than binary.

A Minimum Business Continuity Objective (MBCO) describes the minimum level of products or services that an organisation considers acceptable during disruption. It adds an important dimension to time-based recovery objectives: not only when service should resume, but how much service must be available.

Why MBCO matters

A team may report that a process recovered within its four-hour RTO even though it can handle only 5% of normal demand. Without a minimum service objective, that result can appear successful while customers, regulators or dependent processes still experience unacceptable impact. MBCO turns recovery into a capacity question.

Define the service measure first

ServicePossible MBCO measurePoor measure
Contact centreAnswer 70% of priority calls within agreed thresholdPhones available
PaymentsProcess critical payments up to defined daily value/volumePayment system online
WarehouseDispatch 60% of priority orders per shiftWarehouse open
Digital serviceSupport defined priority transactions at minimum throughputWebsite reachable
Regulatory reportingProduce mandatory report by statutory deadlineReporting team active

Link MBCO to impact tolerance

The minimum level should be justified by impact. Determine what demand can be deferred, which customer segments or transactions are priority, what legal or safety obligations must continue, and how long reduced capacity can be tolerated. An arbitrary percentage such as “50% for all processes” is rarely defensible.

Use staged recovery where useful

One MBCO may not describe a long disruption. Define recovery stages when impact grows over time. For example: 20% priority service within two hours, 60% within eight hours, 90% within 24 hours and normal capacity within 48 hours. Each stage should map to resources and dependencies.

Translate capacity into resources

If the MBCO is 500 priority transactions per hour, determine the minimum people, application capacity, network access, workspace, supplier support and data needed to achieve it. This exposes whether the selected continuity strategy can actually meet the objective.

Worked example: claims processing

A claims function normally handles 4,000 cases per day. During disruption, analysis shows that life-safety and high-value claims cannot wait, while routine cases can be deferred for 48 hours. The MBCO is therefore defined as the ability to process all priority claims plus at least 30% of normal total volume within six hours. The alternate environment supports only 600 cases per day, so the strategy fails even though users can log in within the six-hour RTO. The organisation must increase alternate capacity, change prioritization rules, or accept the risk.

MBCO, RTO and MTPD are different

RTO is a target time for resuming an activity or resource. MBCO is the minimum acceptable service level during disruption. Maximum tolerable period of disruption (or related tolerance concepts used by the organisation) describes the boundary beyond which impact becomes unacceptable. They should be consistent, but they answer different questions.

Test the objective under realistic constraints

Exercises should measure throughput, not only activation. If remote work is the strategy, test concurrent user capacity, telephony, authentication, data access and supervision. If manual processing is the workaround, measure how many transactions people can actually complete per hour and for how many days the workaround is sustainable.

Common MBCO mistakes

  • Using the same percentage for every service.
  • Defining “minimum service” without a measurable unit.
  • Ignoring demand spikes during the disruption scenario.
  • Counting technical availability as business capacity.
  • Setting an objective without checking shared-resource constraints.
  • Failing to define which customers, products or transactions receive priority.

Review checklist

  • The MBCO has a measurable service or output unit.
  • The value is justified by impact and obligations.
  • Priority demand is explicitly defined.
  • Resource requirements are quantified.
  • Dependencies can support the same recovery stage.
  • The strategy has been tested at realistic capacity.
  • Business owners understand what will be deferred.
  • Changes in demand or operating model trigger review.

Account for backlog and surge

Minimum capacity during disruption can create a growing backlog. Model how quickly deferred work accumulates, when the backlog itself becomes unacceptable and what surge capacity is needed after restoration. A strategy that sustains 40% of demand for three days may still fail if the organisation has no credible way to clear the accumulated work without breaching customer or regulatory commitments.

Use MBCO in prioritization decisions

When several services compete for scarce people, workspace or technology, approved MBCOs provide a defensible basis for allocation. Recovery teams can prioritize the resources needed to achieve minimum service across the portfolio before restoring lower-priority capacity. The decision rules should be agreed before an incident, while allowing crisis leadership to adjust them when the actual impact differs from planning assumptions.

Frequently asked questions

Is MBCO always a percentage?

No. It can be transactions per hour, priority customers served, minimum production units, statutory outputs completed or another measure that represents acceptable service.

Can MBCO be 100%?

Yes, where obligations or impact require full service, but the strategy must then demonstrate that full capacity is feasible under the defined disruption conditions.

Who approves the MBCO?

The accountable business owner should approve it within the organisation's BIA/governance process, with validation from relevant dependency owners and BCM practitioners.

Test MBCO as an operating state

During an exercise, do not simply ask whether the service “could operate.” Specify the transactions, users, locations or throughput that represent the MBCO and measure whether they were achieved. Record bottlenecks such as staff, licenses, network capacity or supplier limits. This turns MBCO from a planning statement into a testable service level.

Express MBCO as a measurable minimum service

An MBCO is easier to use when it describes an observable level of product or service rather than a percentage with no operating meaning. Define the minimum transactions, cases, production volume, service hours, channels or customer groups that must be supported at a stated point in disruption. Then identify the people, applications, information, workspace, equipment and suppliers needed to deliver that minimum level.

The value can change over time. A service may need a small manual capability during the first few hours, a larger partial capacity by the end of the day and near-normal throughput later to prevent backlog from becoming unacceptable. Document those stages when they matter. This makes the strategy more precise than a single “50% capacity” statement and gives exercises something concrete to test.

Check that the minimum can actually be sustained

  • Calculate whether available staff can support the minimum volume for the expected disruption duration, including shift and welfare constraints.
  • Confirm that manual workarounds have enough forms, devices, access, reconciliation controls and supervisory capacity.
  • Verify that suppliers and technology services supporting the MBCO have compatible recovery commitments.
  • Define how backlogs will be prioritized and cleared when normal service returns.
  • Set a trigger for escalation if actual capacity falls below the MBCO or cannot be sustained.

MBCO should connect BIA to strategy selection: it tells designers what “good enough to continue” means before full recovery. Review it when service volumes, customer commitments, operating models or dependency architecture change.