---
sourceDocument: Australia Governance, Risk, and Compliance
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/governance-risk-compliance

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Assess impact categories and dependencies of process

# Assess impact categories and dependencies of a process {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 5 minutes to read

Assess the different components of a business impact analysis (BIA). First by
assessing and determining the impact categories of a business process. Second, by
identifying any underlying dependencies that the business process requires across different
dependency types.

## Before you begin

Role required: sn_bcm.program_manager or sn_bcm.planner

## Procedure

1. Navigate to Business ContinuityBusiness Continuity Workspace.
2. Click the lists icon (![Lists icon]()).  
   By default, the list of BIA records in the In Draft state opens.
3. To create a business impact analysis (BIA) record, click New.
4. To update an existing BIA, click the link to the record in the Name column.  
   You can view cards that display impact assessment results, progress, and business process dependencies on applications, hardware, software, or vendors.  
   Figure 1. BIA impact assessment and dependency views

   Impact Assessment Result

   :   This card provides the assessment results of the recovery tier
       level and the recovery time objective for the item that is
       assessed.

       * Recovery Point Objective (RPO): Metric that evaluates the data loss during the business disruption duration that can exceed the tolerance level. RPO results appear in the Impact Assessment Result card only when the primary element assessed in the BIA requires data backup. Otherwise the card shows only the Recovery Time Objective (RTO) and recovery tier results.
       * Recovery Time Objective: Metric that calculates how quickly the business must recover an element or an item after a disruption. RTO is measured in terms of how long your business can survive following a disaster before operations are restored to normalcy. If the RTO is four hours and the item recovered is beyond four hours, then your business could suffer quite some loss.
       * Recovery Tier: Organizations differ in defining recovery tiers depending on the item and the time by which it should be recovered on the state of a crisis. A recovery time objective of Immediately, 1 hour, or 4 hours is impending and falls within the Mission Critical recovery tier level. On the other hand, an RTO of two weeks to one month can be graded as a Non-Essential recovery tier, which may not incur considerable loss to the business.

       {#assess-impact-categories-bia__ul_uvl_dnx_vmb}  
       Note:  
       You can configure the mapping of recovery tiers to RTOs as per your requirement.  
       Figure 2. Impact assessment result

   Impact Assessment Progress

   :   This component indicates the categories of impact that you have
       assessed and completed in relation to the categories that are
       assessment pending. As you complete the assessment for each
       category of impact, you can see the progress of the
       Impact Assessment Progress ribbon
       component. The color-coded ribbon component prompts you to
       complete the assessment for the pending impact categories.

       Figure 3. Impact assessment progress component

   Dependent Assessment Progress

   :   Identifies the dependency of the business process on different
       asset classes or types for its functioning. The assessment
       identifies the relationship between the business process and the
       business application, software, workplaces, or vendors. Or, the
       asset types that the process uses. The progress of the
       dependency assessment pie chart advances as you complete
       assessing the business applications, software or hardware, and
       vendors that the business process depends on.

       Figure 4. Dependency assessment progress pie chart

   BIA SLA

   :   The business impact analysis also requires a specific time by which the assessment of a business process must be completed. By default, the SLA timer is set to 30 days and tracks the time from when the BIA enters In Draft state until it reaches Approved state.

5. To assess the different types of business impact categories on the business process, click the RTO Impact Assessment tab.  
   All impact categories are configurable. A business process draws a set of impact categories, by default, from the template that you have used for the business impact analysis. For more information, see: [Review an impact category and assess
   its downtime](https://servicenow-prod.fluidtopics.net/Bozd5taN2W4cY~Blx_WcMg "Review the impact categories and define the timeframe during which the organization would experience the downtime of its business processes. Analyze the downtime or disruption duration, which helps to determine the recovery time objective for the asset that is assessed.").
6. To answer questions on the data value of the asset in terms of its impact on the business and its data change frequency, click RPO Impact Assessment tab.  
   For more information, see [Assess RPO impact of technology assets on the business](https://servicenow-prod.fluidtopics.net/4QZFXpOCV1cWzzH10PZ3nw "Use the RPO impact assessment tab to enter asset information. The information can be critical from the objective of its recovery, the data value of the asset, and the frequency at which the data changes in the asset.").
7. To review the dependency groups and identify the items within each group that your business process depends on, click the Dependency Assessment tab.  
   You can prioritize your business continuity and recovery plans based on the criticality of the assets that your business process utilizes. For more information, see: [Identify
   dependent items to prioritize recovery plans](https://servicenow-prod.fluidtopics.net/xOv6AY55GrNSEgX63w1VTw "Use the Dependency Assessment tab to identify items or assets that belong to a definite object type or a dependency group.").

   Order of impact categories
   :   The order in which the impact categories appear in the RTO Impact Assessment, RPO Impact Assessment, and Dependency Assessment tabs depend on the
       order in which the impact categories are created in the template that is used in the BIA.

       The order of impact ratings in the RTO impact assessment grid is defined by the impact rating scale in the BIA. The order of
       questions in the RPO impact assessment grid is defined by the impact analysis questions in the BIA. However, any user who can access the BIA can change the order of the RPO impact grid, RTO impact categories, and
       dependency groups.

   Columns in dependency group grid
   :   If you had set up column configurations for an element of a dependency group and enabled your grid configuration as active, then you can view those columns in the dependency grid for the corresponding dependency group in which element definition matches with the grid configuration element definition. Otherwise, you can view the grid that is rendered based on the configured view; that is either IT asset or non-IT asset view based on the required data backup value of the dependency group. Figure 5. Grid columns for dependency assessment Figure 6. Grid configuration setup

       For ad-hoc reporting: Add columns to the Dependency report source \[sn_bia_dependency_report_source\] table that match the dependency variables you defined in Element variable with Enable reporting option set to true. A scheduled job runs weekly to retrieve dependencies (sn_bia_dependency) and their corresponding elements, then updates the data in the reporting
       table. The job retrieves dependencies where the impact analysis is in approved state, was updated in the last seven days, and has not expired. To display the columns that you require you must set up the [element variable](https://servicenow-prod.fluidtopics.net/Fp_HJpSKE38JBfPGTRRQ1Q "As a functional system administrator, you can set up an element variable that is a specific custom column required for a particular dependency of an element.") and [grid configuration](https://servicenow-prod.fluidtopics.net/B8Ad2Hs5qctUL~1z8~dP1Q "Set up the grid configuration to render the BIA dependency assessment grid with configured columns."). For more information, see, [Grid configuration for column display](https://servicenow-prod.fluidtopics.net/XeAXRLErsALQXFpLa19_LA "Grid configuration for column display helps you to capture specific columns in the dependency grid that corresponds to an element.").
8. To change the order of appearance of the impact categories in RTO, RPO, and dependency groups in dependency assessment, navigate to Business ContinuityBusiness Impact AnalysisImpact Category Results.
   1. Click the impact analysis record.
   2. To change the order of the impact categories for RTO and RPO, click the Impact Category Results related list and change the order in the Order column.
   3. To change the order of dependency groups, click the Impact Dependency Groups related list and change the order.
   {#assess-impact-categories-bia__substeps_tgr_z1v_1rb}

*[\>]: and then


