---
sourceDocument: Australia Governance, Risk, and Compliance
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/governance-risk-compliance

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Structured workflows for BIA

# Structured workflows for Business Impact Analysis {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 4 minutes to read

Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Structured workflows for Business Impact Analysis

Business Impact Analysis (BIA) helps ServiceNow customers predict the consequences of disruptions to business processes or functions, which are critical for delivering services or products.
Performing BIA enables organizations to identify and prioritize critical processes, assess impacts on revenue, legal compliance, workforce, and reputation, and understand dependencies on applications, technology, or vendors.
This analysis supports the development of effective recovery strategies and is ideally conducted annually.
Show full answer Show less  

## Impact Ratings and Assessment

The Business Continuity Management (BCM) administrator configures impact ratings to evaluate if the impact on a business process is tolerable. These ratings guide BIA owners in identifying disruption timelines and their effects, for example, when revenue impact exceeds a certain threshold. Multiple impact ratings can be assigned per impact category, each with a tolerability threshold set by the BCM administrator. This setup influences the determination of the Recovery Time Objective (RTO).

## Recovery Time Objective (RTO) Calculation

The RTO is derived from the first non-tolerable impact rating based on configured disruption durations. Key scenarios include:

* Non-tolerable low impact results in an RTO aligned with the low impact disruption duration.
* Non-tolerable moderate or high impacts set the RTO according to their respective disruption durations.
* If all impact ratings are tolerable, the RTO defaults to a maximum value specified in the template.

This approach ensures that recovery priorities align with the severity and tolerability of impacts.

## Recovery Point Objective (RPO) and Category Scoring

For impact categories contributing to RPO, each assessment question is evaluated to determine its criticality (e.g., business critical, operation essential). The highest value among these questions defines the category score and is stored for reference, supporting data-driven recovery planning.

## Overall Impact Assessment and Recovery Tiers

Updating disruption durations for impact categories automatically recalculates the BIA's RTO, set as the lowest tolerable downtime across all categories. The recalculated RTO determines the organization's Recovery Tier, which may range from Immediate Mission Critical to Non-Essential, depending on the recovery timeframe. This tiering helps prioritize recovery efforts effectively:

* Immediate Mission Critical: RTO within 1 hour
* Mission Critical: RTO within 4 to 8 hours
* Business Critical: RTO within 24 to 72 hours
* Essential: RTO within 1 to 2 weeks
* Non-Essential: RTO up to 1 month

ServiceNow customers can leverage these structured workflows to systematically assess business process disruptions, define recovery objectives, and enhance organizational resilience through informed recovery strategies.  
Business impact analysis helps you to predict the consequences of a disruption on a
business process or business function.

A business process is a set of tasks done by a business organization to deliver a business service or product to customers. When a business process is disrupted, the impact to the organization can be huge in terms of revenue and
reputation. Business impact analysis (BIA) is performed to identify and prioritize critical processes, quantify or qualify the impacts, and identify recovery dependencies. Ideally, business impact analysis on critical processes
must be performed annually.

The assessment of a business critical process disruption helps you to estimate the
consequential impact on your business revenue, legal issues, workforce disruption, or business
reputation. It also enables you to identify the dependencies of your business process on business
applications, technology, or vendors that might be affected. This analysis gathers the
information needed to develop recovery strategies.  
Figure 1. Business impact analysis overview

## Impact ratings for your business impact analysis {#structured-workflows-bia__section_amq_jzd_3xb}

The Business Continuity Management (BCM) administrator of your organization defines the impact ratings for your business impact analysis (BIA) and decides if the impact is tolerable for your business process. For more
information on the impact ratings, see [Configure an impact rating to assess an impact category](https://servicenow-prod.fluidtopics.net/EVnErjD3fbzvBwpWiLzsNA "Configure a rating for each category to help you measure the intensity of loss when a business downtime occurs."). According to the configuration set up by BCM administrator, the questions are displayed in the RTO Impact Assessment tab.

Consider the example where BCM administrator has configured an intolerable impact rating for the Revenue impact category. BCM administrator has defined what qualifies to be an intolerable impact. As a BIA owner, you must
identify the timeline at which the revenue impact may go beyond $1M.

## Multiple impact ratings for an impact category {#structured-workflows-bia__section_m22_l12_3xb}

If BCM administrator has configured the assessment questionnaire to include multiple impact ratings for an impact category, the impact category ratings are displayed in the Impact Category view.  
BCM administrators specify a threshold of non-tolerance for the impact ratings, per impact category. The disruption duration for the first non-tolerable impact category is selected for the recovery time objective (RTO). The impact ratings have the specified values:

* Low = 1
* Moderate = 2
* High = 3
{#structured-workflows-bia__ul_f14_4r2_3xb}  
See the example for the sample RTO calculation.Figure 2. Example to show the calculation of impact category {#structured-workflows-bia__table_zsm_2y2_3xb__entry__3}

| Scenario | Non-tolerable impact | Description |
|-|-|-|
| Scenario 1 | In the Impact Ratings table, the Tolerable field is set to false. | If the administrator has specified that Low regulatory impact is non-tolerable, its corresponding disruption duration is set as the recovery time objective (RTO). In this example, the disruption duration for the 01 - Low impact rating is set to 4 hours. Therefore, the recovery time objective (RTO) for the impact category is above 4 hours. Even if the moderate impact disruption duration is shorter, the calculation will select the value from the first alphanumerically sorted impact rating that has the Tolerable field set to false. |
| Scenario 2 | In the Impact Ratings table, the Tolerable field is set to false. | If the administrator has specified that Moderate regulatory impact is non-tolerable, its corresponding disruption duration is set as the recovery time objective (RTO). In this example, the disruption duration for 02 - Moderate impact is set to 24 hours. Therefore, the recovery time objective (RTO) for the impact category is above 24 hours. |
| Scenario 3 | In the Impact Ratings table, the Tolerable field is set to false. | If the administrator has specified that High regulatory impact is non-tolerable, its corresponding disruption duration is set as the recovery time objective (RTO) as shown in the example. In the tabular example, the disruption duration for 03 - High impact is set to 72 hours. Therefore, the recovery time objective for the impact category is above 72 hours. |
| Scenario 4 | The Tolerable field for the Low, Moderate, and High impact ratings is set to true. | If the administrator has set all the impact ratings as tolerable, the value specified in the Maximum RTO value field in the template is selected as the recovery time objective (RTO). In the example, the administrator has set all the impact ratings as tolerable. Therefore, the recovery time objective (RTO) is one month as per the value specified in the Maximum RTO value field. |
[Table 1. Sample RTO calculation]

{#structured-workflows-bia__table_zsm_2y2_3xb}

Calculation of category score from impact analysis questions for an impact category that contributes to Recovery Point Objective (RPO)

:   If the impact category contributes to RPO, then evaluate each impact analysis question in that RPO category based on data value. You can check business critical, operation critical, business essential, or operation
    essential. The maximum value among all the questions of that RPO is considered as the Category Score of that Impact Category. It is then stored in the Impact Category Results table \[sn_bia_category_result\].

Calculation of overall impact assessment result for a BIA

:   When you update the Disruption Duration of an impact category, the RTO of the BIA is automatically updated. The RTO of the BIA is set as the lowest tolerable downtime from each impact
    category.

    For example, consider a BIA having four impact categories -- Legal, Reputation, Workforce, and Regulatory. When you update the legal impact category disruption duration, the BIA RTO value is recalculated based on the
    lowest tolerable disruption duration from each impact category. The Recovery Tier varies from organization to organization and is set based on the recalculated RTO value.  
    {#structured-workflows-bia__table_wm3_ccw_xmb__entry__2}

    | RTO value | Recovery Tier |
    |-|-|
    | Immediate | Mission Critical |
    | 1 Hour | Mission Critical |
    | 4 Hours | Mission Critical |
    | 8 Hours | Business Critical |
    | 24 Hours | Business Critical |
    | 72 Hours | Essential |
    | 1 Week | Essential |
    | 2 Weeks | Non-Essential |
    | 1 Month | Non-Essential |
    [ ]

    {#structured-workflows-bia__table_wm3_ccw_xmb}

