Aranisdocs
aranis.ai
Docs/Organizational Risk/Business Impact Analysis (BIA)

Business Impact Analysis (BIA)

Impact across four monetary spheres, the curve over time, and how object criticality is derived.

Updated on August 17, 2026

The unit of analysis is the object

BIA is anchored to the object, which in Aranis is a product or service. You register the object and then relate the business processes and assets that sustain it. Each object has exactly one BIA assessment. The methodology references are ISO 22317 and FAIR.

Four spheres, all in money

Under FAIR, all impact is monetary. The object is assessed by loss across four spheres: operational (cost to resume operations), legal (fines and legal costs), technological (cost of recovery or replacement), and financial (lost revenue). Consolidated impact is the sum of the four.

There are no weights. FAIR sums real loss values rather than weighted levels — adding money to money removes the weighting a 1-to-5 scale would demand. The platform is also currency-agnostic: it uses the $ symbol without fixing which currency.

Impact scales with duration

An object down for an hour does not cost what it costs down for a week, so impact is not a single value: each sphere is entered as a curve, the money accumulated across time checkpoints your organization defines. The defaults are 1 hour, 4 hours, 1 day, 3 days, and 7 days, editable under Settings › BIA.

Between two checkpoints the curve is interpolated linearly; before the first it ramps up from zero; after the last it saturates into a plateau rather than growing indefinitely.

Where the curve is read

The object's consolidated figure is read at the MTPD — the maximum tolerable period of disruption, which you provide. For each sphere the interpolated value at that point is taken, and the four are summed. If MTPD is empty, the consolidated figure uses the peak, that is, the worst tolerated case.

Criticality and appetite

The consolidated figure maps to a criticality — low, medium, high, or critical — through money bands your organization defines. The platform supplies the level names and editable defaults, not the ruler.

Risk appetite is an illustrative line: when the consolidated figure at MTPD crosses it, the object is flagged. It changes neither criticality nor MTPD — it exists so you can see the crossing, not to reclassify automatically.

Partial saves

Saving an assessment that already exists does not erase what was not sent. A missing sphere is kept, a sent sphere replaces the previous one, and a sphere sent empty clears it. RTO, RPO, MTPD, and the personal-data flag follow the same rule. The consolidated figure and criticality are always recomputed over the merged state, never over the fragment received — without that rule, adjusting only the RTO would silently downgrade a critical object.