Guide
What is a BIA?
A business impact analysis is a simple exercise with a serious purpose: working out what actually happens to your organisation when a system, team or supplier stops working — and how long you can cope before it hurts.
The short answer
BIA stands for business impact analysis (sometimes called a business impact assessment). You list what the business depends on — usually the applications and services your teams use every day — and for each one you answer a few questions: who relies on it, what breaks if it disappears, how quickly that becomes serious, and how much damage it would do. The result is a ranked picture of what matters most, which is what continuity planning, disaster recovery and risk decisions are built on.
Why organisations run one
Most teams have a rough sense of what is important, but it lives in people's heads. A BIA turns that into something you can show, challenge and act on. It is used to:
- Decide what gets restored first when something goes wrong.
- Set realistic recovery targets instead of promising everything at once.
- Justify spending on backups, redundancy or support contracts.
- Answer auditors, insurers and customers asking about resilience — ISO 22301, ISO 27001, DORA and similar frameworks all expect one.
- Show the board, in one page, where the business is genuinely exposed.
What a BIA actually contains
The vocabulary sounds technical, but each item is a plain question:
- Confidentiality, integrity and availability (CIA) — how bad is it if the information leaks, if it is quietly wrong, or if nobody can use it?
- Impact and likelihood — how much damage one bad day would cause, and how often you would honestly expect it.
- Outage tolerance — how long the team can keep working without it before the business feels it.
- Dependencies — what else the system talks to, because most outages travel along those lines.
- Crown jewels — the handful of systems you genuinely could not trade without.
- Owner — the person you would phone when it breaks.
How a BIA is usually done
The traditional route is a consultant, a workshop diary and a very large spreadsheet. Someone interviews each department, transcribes the answers, chases the gaps, and produces a document that is accurate on the day it is delivered and out of date within a quarter. It works, but it is slow, expensive and hard to repeat.
How Meridian does it differently
Meridian keeps the same method and removes the paperwork. You add a department, list the applications it uses, and score each one through short questions written in plain language — no jargon and no training day. From there:
- AI drafts a first pass of each assessment from what it can infer about the application; you review and apply it, and nothing is saved without your click.
- Shared applications stay a single entry, so two departments never create two conflicting versions of the truth.
- A dependency map shows what leans on what, so single points of failure surface on their own.
- A board report — cover page, risk spread, crown jewels and priorities — downloads as an editable Word document.
- The register stays live, so next year is a review rather than a restart.
Most teams get a first useful picture in an afternoon rather than a quarter.
How often should you redo it?
Once a year for the whole register, and immediately whenever you adopt or retire a significant system. Meridian nudges you when assessments have not been reviewed for 90 days, so the register does not quietly go stale.
Start your own
There is a free seven-day trial, then $9 a month. If you would rather see it first, the walkthrough shows the whole flow, and the FAQ answers the practical questions about data, billing and teams.