In today’s bulletin, Charlie discusses the relationship between AI and business impact analysis (BIA), and provides some useful ways that AI can be incorporated into our own organisations’ analysis.
The BIA has, over the years since the initial inception of business continuity, survived, despite various people trying to replace it or say it is no longer fit for purpose. It has stood the test of time. Most practitioners would agree that the BIA is the foundation of business continuity; it is key, as it tells you which activities you need to recover, in what order, and what resources are required. Once you have these details, you can start planning your recovery strategies and solutions.
I have had issues for a long time with the BIA and its applicability. Yes, I have always done one, but I have failed to get the full value out of the data collected. I feel that one of the principles in conducting a BIA is to only collect information which takes you on a journey, leads you somewhere, and informs the organisation’s planning stage. The data has been difficult to interrogate and sort, and I rarely see organisations where BIA information is reflected in their plans. To me, this is sometimes due to a lack of imagination or effort, but often it is also because it is not easy to interrogate the data without lots of Microsoft Excel skills.
This week, I had an epiphany about the BIA when I realised how much could be done using AI. It could add real value to the data collected, streamline the collection of information, and greatly increase the value that the BIA can add to business continuity.
Below are some of the ways to use AI in the analysis stage of the BC lifecycle. Most of these activities could be carried out without AI, but AI greatly speeds up the process and makes many activities worth conducting:
- Transcribing interviews: Use AI to transcribe a BIA interview, allowing the interviewer more time to listen to the interviewee’s answers rather than trying to write notes at the same time. We have, in the past, used two interviewers, one to ask the questions and one to take notes. The interview transcript can be given to AI and it can automatically extract the details you require from it for populating either individual department BIAs or a master spreadsheet.
- Formatting interview notes: The notes from each interview can be formatted by AI and then sent as a document back to the interviewee for checking.
- Populating master data: AI can be given the notes from all the BIA interviews and it can populate a master spreadsheet with the data. You don’t even need to tell AI how to develop the spreadsheet; it will do it automatically.
- AI-led interviews: You might even get an AI avatar to carry out your BIA interview. I have built one of these and it works okay and can produce a reasonably good set of data. The interview can then take place at the interviewee’s convenience and can take just one person’s time, not two. I have never tried to get an avatar to debate with an interviewee what their RTO is, but if you ask about impacts and what their department does, AI can make a reasonable job of identifying their different activities, assessing what the impact would be if they were lost and suggesting an RTO. The practitioner would still need to check and verify the suggested activities, impacts, and RTOs. Talking to avatars is not everyone’s cup of tea, and there is the issue that humans can ask follow-up questions to glean nuance and additional information, but an avatar can do a good first pass at the data and then a human can carry out the follow-up questions.
- Standardising application names: Often when you collect data, especially if there is more than one person collecting it, there are different terms for the same thing. The number of BIA application lists I have seen where Microsoft 365 is listed as email, Microsoft, 365, or SharePoint, which are basically different names for the same or related SaaS application. You can set AI to look for these different names, and it can identify the duplicates; you can verify that they are the same applications and then AI can change the spreadsheet so they all read consistently.
- Tracking changes: I have always had an issue where BIA data is saved in a spreadsheet and, if changes are made on purpose or accidentally, it is very difficult to track those changes. With AI, you can have a master spreadsheet and ask AI each time you change it to log the changes so you know what has been changed.
- Integrating external data: In the past, when you went to IT, facilities management, or procurement and asked for their lists of applications, buildings and suppliers, they would often supply them in a format which did not suit how you had collected the data. If there were large lists, you would have to manipulate the data to fit into your existing collected data formats. AI will ingest large lists and can either reformat the data or search it, even if it is formatted differently from the other spreadsheets you have.
- Sorting recovery times: A simple thing which used to frustrate me was that Excel is useless at sorting by the lowest time if your times are recorded in hours, days, and weeks. You have to translate each time frame into hours and then sort by this. AI recognises time and the relationship between hours, days, weeks, and months, and will instantly sort by the lowest time.
- Searching BIA data: AI is also brilliant at searching data. You can ask it to give you all the departments which use software X, then give you all their RTOs and RPOs and highlight the lowest RTO and RPO. This can now be done instantly and can then be shared with IT or whoever else needs it.
- Updating master data: Once all the data is in a spreadsheet, we can ask AI to make changes to the data. Say you have replaced application A with application B, it can go through and make all the changes while recording the changes it has made in the QA log.
- Creating data views: You can very quickly generate cuts of the data. If you want all the departments which work in building X, this can be done instantly, as can identifying which departments have a dependency on the quality assurance department.
- Populating continuity plans: Many organisations I see do not have BIA data in their plans that is pertinent to the department’s plan. You can ask AI to provide the data required for a department’s plan, and this can be done instantly and put into a format ready for copying and pasting into the plan.
- Using BIA data during incidents: I have very rarely seen organisations talk about using BIA data as part of their response. The data is too difficult to access and would take too long to find what you are looking for. For example, imagine we have an incident where key system X has gone down. Using AI, I can list all departments and activities which depend on that application, what their activity RTO is, and how long before their MTPD will be reached. BIA data then becomes essential to understanding the impact of the incident, quantifying when the incident will get much worse if it is not resolved, and identifying which parts of the organisation will be impacted by the incident. Previously, this was really only available to those with expensive business continuity software.
- Creating a living BIA: Making the BIA a living data set will very quickly prove the usefulness of collecting the data. If the data is used in incidents, near misses, and exercises, and there is poor-quality or missing data, this can then be improved.
For me, AI has completely revolutionised how I think about the BIA and its usefulness. Prior to AI, I was really only bothered about activity RTOs, RPOs, and the resources required. Now, there is so much more that can be done with the data, so the BIA has really come of age.
My personal debate is still about how to hold the data. Should it be in a master Excel spreadsheet which a human can easily read and look through, as well as the AI, or should it be held in a machine-readable format and then completely rely on AI for interpreting, checking, and changing the data? I need to learn more about how AI works and also what clients want from their BIA data. Do they want to be completely dependent on AI, or do they want data that is both machine-readable and human-readable?
Previously, getting this sort of value from BIA data often required specialist business continuity software or considerable spreadsheet and data skills. With AI, even with a £20-a-month ChatGPT subscription, you can do amazing things with your BIA in terms of collecting, documenting, and then interrogating the data. This is the way of the future, so we should all be embracing AI and getting value out of all the hard work which has gone into collecting the BIA data.



