Skip to content
Risk Management

The Risk Management Process for Business Continuity: 6 Practical Steps

Richard Long

Published on: August 25, 2026
Last updated on: August 25, 2026

Relevant Contents

Need Tailored Business Continuity Insights?

Contact Us Now for Personalized Guidance!

A business continuity program is only as sound as the assumptions behind it. If your risk assessment is outdated or disconnected from current operations, your team may protect low-priority activities while overlooking the suppliers, systems, facilities, and people that can stop critical work.

A BCM-focused risk management process gives you a repeatable way to identify disruptive threats, judge their likelihood and consequences, select appropriate treatments, and determine how much exposure remains. The six-step process below is consistent with the principles of ISO 31000 and supports the management-system approach described in ISO 22301.

The risk management process at a glance

  1. Set the scope, context, and criteria. Define what you are assessing and how risks will be scored.
  2. Identify disruption risks. Document the threats, vulnerabilities, and dependencies that could interrupt critical operations.
  3. Analyze likelihood and impact. Determine the inherent exposure and evaluate existing controls.
  4. Evaluate and prioritize risks. Compare each risk with approved criteria, appetite, and tolerance.
  5. Select and implement treatments. Avoid, reduce, transfer, share, or accept the risk, then assign actions and owners.
  6. Measure residual risk and monitor change. Confirm what exposure remains and whether it stays within tolerance.

What is risk management in business continuity?

In business continuity, risk management is the ongoing process of identifying and addressing conditions that could disrupt priority products, services, processes, and supporting resources. Its purpose is not to eliminate every risk. That is rarely possible. The purpose is to make informed decisions about which exposures require action, which can be accepted, and where recovery capabilities are needed.

A business continuity risk assessment and a business impact analysis (BIA) are related, but they are not interchangeable. The risk assessment asks what could disrupt operations, why it could happen, and how likely it is. The BIA examines how a disruption would affect the organization over time and establishes recovery priorities. Together, they connect credible disruption scenarios to recovery requirements and strategies. For a deeper comparison, see BIAs vs. risk assessments.

The process must also be repeated. Vendors change. Systems migrate. Facilities close. Key employees leave. New regulations and contractual obligations appear. A risk register that was accurate last year may no longer reflect how the business operates today.

The six steps of the risk management process

1. Set the scope, context, and criteria

Start by defining what the assessment covers. This may be an enterprise, business unit, facility, product, service, process, or technology environment. Specify the time horizon, participants, information sources, and the likelihood and impact scales you will use.

For BCM purposes, the scope should account for the resources that support critical operations, including people, facilities, technology, data, utilities, suppliers, and other third parties. It should also define the organization's risk appetite and the more specific tolerances used to decide when an exposure requires treatment or escalation.

Consultant observation: MHA often sees teams begin scoring risks before agreeing on the criteria. The result is a register filled with ratings that look precise but mean different things to different assessors.

2. Identify disruption risks

Identify the events and conditions that could interrupt the operations within scope. Do not stop with a generic list of hazards such as cyberattack, severe weather, or power outage. Connect each threat to the vulnerability or dependency that makes it relevant to the organization.

A useful risk statement describes the cause, disruptive event, and operational consequence. For example: "Because customer support depends on one cloud contact-center provider, an extended provider outage could prevent the service team from handling inbound requests within its approved recovery time."

Use several sources to build the risk register: previous incidents and near misses, process-owner interviews, facility and technology assessments, supplier information, the enterprise risk register, BIA results, audit findings, and planned organizational changes. MHA's guide to identifying your biggest threats provides additional risk-assessment guidance.

3. Analyze likelihood and impact

Analyze each risk before assuming that current safeguards will work. This produces an inherent risk rating, meaning the exposure that exists before controls or continuity measures are considered.

Assess both likelihood and consequence using the criteria established in Step 1. Consequences may include operational downtime, harm to people, financial loss, contractual or regulatory failure, customer impact, and reputational damage. For BCM, the analysis should show which critical activities and recovery requirements could be affected.

Next, identify existing controls and evaluate their actual effectiveness. A documented recovery plan is not proof that recovery will work. Look for test results, current procedures, trained alternates, verified backup arrangements, supplier commitments, and other evidence that the controls can perform as intended.

4. Evaluate and prioritize risks

Compare the analysis with the organization's approved criteria and risk tolerance. This determines which risks require treatment, which need management review, and which can be accepted without additional action.

Priority should reflect more than a color on a heat map. Consider whether the risk could interrupt a time-sensitive product or service, whether existing recovery capabilities can meet the required recovery time, whether several critical activities depend on the same resource, and whether management has formally accepted the remaining exposure.

Consultant observation: Another pattern MHA sees is reporting activity instead of exposure. Counts of completed plans, BIAs, or exercises show work performed. They do not show whether the organization's most consequential risks are within tolerance.

5. Select and implement risk treatments

Choose a treatment that fits the risk, operational need, cost, and approved tolerance. Common options include:

  • Avoid: Stop the activity or remove the dependency creating the exposure.
  • Reduce: Lower the likelihood or consequence through preventive controls, recovery strategies, alternate suppliers, redundant systems, cross-training, manual workarounds, or exercises.
  • Transfer or share: Allocate part of the financial or operational exposure through insurance, contracts, or third-party arrangements.
  • Accept: Retain the exposure through an informed decision by someone with the authority to do so.

Transferring financial risk does not necessarily transfer the operational consequences of a disruption. An insurance policy may cover part of the loss, but it will not answer customer calls, recover a system, or restore a supplier's capacity.

Each treatment plan should identify an owner, specific actions, required resources, due dates, and the evidence that will demonstrate effectiveness. For help choosing among the options, see how to choose the right risk mitigation strategy.

6. Measure residual risk and monitor change

Residual risk is the exposure that remains after controls and treatments are applied. Reassess likelihood and consequence using evidence from implementation, testing, exercises, incidents, and corrective actions. Then compare the result with the organization's risk tolerance.

If residual risk remains above tolerance, the organization needs additional treatment, a different recovery strategy, or a documented management decision to accept the exposure. If the exposure is well below tolerance, review whether resources could be redirected to more significant gaps.

Monitoring should be continuous, but review frequency should reflect the risk. Review high-priority risks more frequently, conduct a broader program review on a scheduled basis, and reassess whenever a material change occurs. Common triggers include a new critical supplier, a major system migration, a facility change, an incident or near miss, a regulatory change, or revised BIA findings.

A practical business continuity risk example

The following simplified example shows how the six steps connect. Actual ratings must use the organization's approved criteria.

Element Example
Critical activity Customer support and incident intake
Risk statement An extended outage at the sole contact-center provider could prevent the service team from handling customer requests within its approved recovery time.
Current control A vendor service-level agreement and a documented manual escalation process
Control gap The manual process has not been exercised, and customer contact data is not available outside the provider's platform.
Treatment Create an alternate routing method, maintain a protected export of essential contact data, document manual procedures, and exercise the workaround.
Residual-risk decision Reassess after the workaround is successfully exercised, then escalate if the remaining exposure exceeds tolerance.

What should a business continuity risk register contain?

A useful risk register supports decisions, ownership, and follow-through. At a minimum, document:

  • A clear cause-event-consequence risk statement
  • The affected product, service, activity, location, or resource
  • The risk owner
  • Likelihood and consequence ratings
  • The inherent risk rating
  • Existing controls and evidence of their effectiveness
  • The selected treatment, action owner, resources, and due date
  • The residual risk rating and approval status
  • The next review date and change triggers

The register should not become a static inventory. It is a management record that shows what the organization knows, what it has decided, who is responsible, and whether the remaining exposure is acceptable.

Where BCM risk management commonly breaks down

Across consulting engagements, MHA repeatedly encounters several weaknesses:

  • The assessment focuses on familiar hazards but misses changing technology, supplier, facility, or workforce dependencies.
  • Different teams score similar risks differently because criteria are unclear.
  • Controls are credited without evidence that they work.
  • Treatment actions lack owners, deadlines, or management support.
  • Accepted risks are not formally documented or approved.
  • Reports emphasize completed activities rather than changes in residual risk.
  • The assessment is updated annually even when the business changes more frequently.

The practical test is simple: Can the BCM team show management which disruption risks matter most, what has been done about them, what evidence supports the current rating, and where exposure remains? If not, the process is not yet producing the decisions the organization needs.

Frequently asked questions

What are the six steps of the risk management process?

The six steps are setting the scope, context, and criteria; identifying risks; analyzing likelihood and impact; evaluating and prioritizing risks; selecting and implementing treatments; and measuring residual risk while monitoring for change. Communication, consultation, recording, and reporting should occur throughout the process.

What is the difference between a risk assessment and a BIA?

A risk assessment identifies threats, vulnerabilities, dependencies, likelihood, and potential consequences. A BIA determines how disruption affects the organization over time and establishes recovery priorities and requirements. BCM programs need both.

How often should BCM risks be reviewed?

Review frequency should match the exposure and rate of change. High-priority risks may require monthly or quarterly review. The full register should be reviewed on a defined schedule and whenever material operational, technology, supplier, facility, regulatory, or organizational changes occur.

What is the difference between inherent and residual risk?

Inherent risk is the exposure before controls and treatments are considered. Residual risk is what remains after those measures are applied. Management should compare residual risk with approved tolerance and decide whether further action or formal acceptance is required.



Start building a stronger future

Navigate uncertainty with an expert - schedule your free consultation with our CEO, Michael Herrera.

Other resources you might enjoy

Ready to start focusing on higher-level challenges?