Many business leaders are under the impression that they can protect their organizations by investing in either risk management or business continuity.
True resilience can only be achieved through the thoughtful implementation of both disciplines. This article is focused on operational risk, such as loss of technology, business function outages, and emergency response, rather than strategic business risk, such as changes in market conditions or insurance risk.
Related: Risk Assessment: The Best Way to Identify Your Biggest Threats
Summary
A common misconception among business leaders is that if their organization is diligent in practicing risk management, it does not need to bother with business continuity (BC).
An almost equally common misconception is that if their company excels at BC, it can get by without worrying about risk management.
These misunderstandings reflect a larger confusion about exactly what risk management and business continuity are and what role each plays in protecting organizations from threats and disruptions.
Risk management and business continuity are supportive and related, but they are two very different disciplines.
Risk management is about reducing the likelihood that disruptive events will occur or reducing their potential impact if they do occur. Organizations accomplish this by identifying significant risks, assessing their likelihood and consequences, and implementing measures to address them.
The first step in managing risk is conducting a threat and risk assessment (TRA) to identify potential sources of disruption and assess them based on likelihood and potential impact. Such assessments typically involve input from a range of sources, such as facility personnel, business leaders, security and safety teams, government agencies, and historical incident data.
Here are some potential risks that might be identified through a TRA:
What happens once an organization identifies the threats it faces? It must evaluate them based on two key factors: likelihood and potential impact. These are typically assessed through a combination of expert judgment, business knowledge, and analysis of potential effects on people, facilities, operations, customers, and other critical areas.
After identifying its risks and assessing how likely each is to occur and what the damage might be if it did, the organization should take steps to address them.
Organizations typically respond to risks through four primary strategies:
Risk avoidance means eliminating the activity that creates the risk.
Risk limitation means reducing the risk by implementing controls that lower its likelihood or impact.
Risk transfer means shifting some or all of the financial or operational consequences to another party, such as through insurance or outsourcing.
Risk acceptance means accepting the risk, usually because the likelihood and potential impact are low enough that additional protective measures are not justified.
Most organizations employ a combination of all four approaches. For example, a company might perform risk avoidance by choosing not to open a facility in a floodplain, risk limitation by installing a fire suppression system in a warehouse, risk transfer by outsourcing payroll administration to a third-party provider under terms that assign certain liabilities to the provider, and risk acceptance by deciding not to install backup power for a small storage building because the consequences of an outage would be minimal.
That is risk management in a nutshell. It is about preventing bad things from happening, with a special focus on preventing the things that, if they did occur, would cause the most damage to the organization.
Business continuity is a different discipline. If risk management is about prevention, BC is about what we do when prevention fails. Because sometimes, despite our best efforts, things will go wrong.
Risk management asks, “How can we reduce the chance that something bad will happen?” BC asks, “If something bad does happen, how will we continue operating?”
It is good to brush and floss. But if you develop a cavity or chip a tooth, you still want to be able to go to the dentist and get it fixed.
Business continuity focuses on preparing the organization to respond to and recover from disruptions regardless of their cause.
Where risk management starts with the threat and risk assessment, BC begins with the Business Impact Analysis (BIA), the study that identifies the organization’s critical business processes and determines how quickly they must be restored following a disruption to avoid unacceptable business impacts.
Using the results of the BIA, organizations develop recovery strategies and continuity plans designed to keep critical activities operating, or restore them within their required recovery timeframes.
BC strategies might include:
It is commonly thought that a business continuity program consists primarily of a collection of documents. In fact, documentation is only one output of the BC lifecycle. Business continuity is an ongoing process of planning, training, exercising, maintaining, reviewing, and improving the organization’s recovery capabilities so they remain effective as the business and its risks evolve.
The goal of BC is to ensure that critical business processes can continue, or be restored within acceptable timeframes, even when preventive measures fail or an unexpected event occurs.
Where risk management seeks to prevent or lessen disruptions, business continuity prepares the organization to operate through them and recover when they occur.
It should now be clear that organizations need both risk management and business continuity. They provide different kinds of protection and together amount to a defense in depth against organizational threats, risks, and disruptions.
A possible additional misconception about these two disciplines is that applying both will require a bottomless budget.
In fact, a central tenet of both risk management and BC is that of proportionality. The risks that are the likeliest to occur and have the potential to cause the most damage require the most vigorous treatment. Similarly, the business processes that are the most critically time sensitive are the ones that need to be recoverable in the shortest amount of time. Other risks and processes do not require the same heightened degree of response.
Another key principle shared by both risk management and BC is the importance of making conscious, informed choices. Neither discipline calls for protecting everything to the highest possible standard. Instead, both emphasize understanding the risks, weighing the potential consequences, investing in prevention and preparedness where they will have the greatest impact, and consciously accepting the risks and recovery gaps that remain rather than pretending they don’t exist.
A simple example might drive the point home.
Think about two common machines: the dishwasher and the car.
It is not very likely your dishwasher will break tomorrow, and if it did, the consequences would be pretty mild. You might have to wash the dishes by hand for a few days. So keep a sponge and some dish liquid on hand. Beyond that, it does not make sense to worry about it too much.
A car is very different. Here again, the likelihood of your having car trouble is probably low. But if you did get a flat or break down, the consequences could be significant. You could be stranded, miss an important appointment, or find yourself in an unsafe situation. Here it would make sense to try to prevent problems and be equipped to deal with them if they occur, such as by making sure you have a viable spare and know how to put it on or making sure auto club membership is up to date.
Organizations should approach resilience the same way. They should not try to eliminate every possible risk or build elaborate continuity capabilities for every conceivable disruption. They should assess the likelihood and potential impact of the threats they face, invest where the consequences justify it, and consciously accept the remaining risks.
Risk management and business continuity are complementary disciplines, not competing alternatives. Risk management seeks to prevent or reduce disruptions. BC prepares the organization to continue operating when prevention is unsuccessful.
Organizations do not become resilient by relying exclusively on either discipline. They become resilient by thoughtfully combining prevention with preparedness and by making informed, proportionate decisions about where to invest, where to plan, and which remaining risks they are prepared to accept.
If your organization wants to strengthen its resilience by integrating risk management and business continuity into a coordinated strategy, MHA Consulting can help. Contact us to learn how our consultants can help you identify your most significant risks, develop practical continuity capabilities, and build a program that is both effective and proportionate.
Risk management focuses on reducing the likelihood that disruptive events will occur or reducing their potential impact if they do occur. It involves identifying significant risks, assessing their likelihood and consequences, and implementing measures to address them.
Business continuity focuses on preparing the organization to continue operating and recover when disruptions occur. While risk management aims to prevent or lessen disruptions, business continuity ensures the organization has plans, strategies, and capabilities in place when prevention is unsuccessful.
Organizations typically address risks through four primary approaches: avoidance, limitation, transfer, and acceptance.
Risk avoidance eliminates an activity that creates a risk. Risk limitation reduces the likelihood or impact of a risk through safeguards. Risk transfer shifts some or all consequences of a risk to another party, such as through insurance arrangements. Risk acceptance involves consciously deciding that the potential consequences of a risk do not justify additional protective measures.
Most organizations use a combination of these approaches based on the likelihood and potential impact of the risks they face.
Yes. Effective risk management can reduce the likelihood and severity of disruptions, but it cannot eliminate all uncertainty. Even if an organization has measures in place to prevent a disruption, there is still a possibility that something unexpected will occur or that those measures will not be sufficient. Business continuity prepares the organization to respond and recover when those situations arise.
Business continuity begins with a business impact analysis (BIA), an assessment that identifies the most critical business processes. Organizations then develop recovery strategies and continuity plans, establish procedures for responding to disruptions, train personnel, conduct exercises, maintain documentation, and regularly review and improve their capabilities. The goal is to ensure critical activities can continue or be restored within acceptable timeframes.
No. Effective resilience is based on proportionality, not trying to protect everything to the highest possible standard. Organizations should evaluate risks based on their likelihood and potential impact and focus resources where they will provide the greatest benefit. Similarly, recovery capabilities should be designed around the importance and time sensitivity of business processes.