It’s Time to Rethink How Business Continuity Works

    Brian ZawadaSeptember 14, 2026
    It’s Time to Rethink How Business Continuity Works

    Business continuity has changed considerably over the past few decades.

    But many of its core processes haven't.

    We still conduct periodic business impact analyses, often by interviewing business owners. We ask people to identify dependencies and estimate recovery objectives. We document (often voluminous) plans. We ask people to review those plans annually. We design exercises. We track corrective actions. And when something bad actually happens, we assemble teams to determine what happened, what is affected, and what we should do about it.

    These are accepted as leading practices because, for a long time, they were the best ways available to solve the problem.

    But there's an important question we should be asking in the age of AI:

    If we were designing business continuity from scratch today, would we design it this way?

    Probably not.

    And that creates an enormous opportunity.

    The next generation of business continuity shouldn't simply use AI to perform traditional processes faster. We should reconsider why those processes exist in the first place, and determine which ones can be eliminated, fundamentally redesigned or replaced.

    The BIA shouldn't be an annual event

    Consider the traditional business impact analysis.

    The typical process involves questionnaires, interviews, workshops, spreadsheets, follow-up questions and significant coordination by the business continuity team. And no one – on both sides of the table – like to participate in this effort.

    And after all that effort, the information immediately begins aging.

    Why?

    Because historically, asking people was one of the only practical ways to understand how the organization operated.

    Today, organizations already possess enormous amounts of information about their products and services, processes, technology, suppliers, facilities, people and customers.

    AI changes our ability to collect, consume and understand that information.

    Instead of beginning a BIA by asking a business owner 50 or 70 questions, imagine beginning with this:

    “Here is what I understand about your business service, its criticality, its dependencies and its recovery requirements. Here is the evidence I used. Here are the seven things I need you to validate.”

    That reverses the traditional BIA. Instead of asking humans to create organizational knowledge, AI develops an initial understanding and asks humans to validate it.

    The result isn't simply a faster BIA. It's potentially a better BIA with dramatically less organizational friction.

    And instead of repeating the process every year, that understanding can evolve continuously as the organization changes.

    Recovery objectives shouldn't begin with a blank box

    Traditional BIAs frequently ask business leaders to determine an RTO, MTPD or similar business continuity requirement.

    But consider what we're really asking them to do.

    We're asking someone to convert a complicated combination of customer expectations, financial consequences, regulatory requirements, operational dependencies and downstream impacts into a number.

    Four hours. Eight hours. Twenty-four hours.

    Sometimes those numbers are well reasoned. Sometimes they're inherited from the previous BIA. Sometimes they're educated guesses.

    AI creates another possibility.

    The system can evaluate what is known about the service, its dependencies, contractual commitments, downstream impacts and historical information and recommend a recovery requirement, along with the reasoning and evidence behind it.

    Leadership still decides.

    But instead of asking: “What should the RTO be?”

    We can ask: “Based on this evidence, we recommend eight hours. Do you agree?”

    That's a much better conversation.

    Dependency analysis can become continuous

    Dependencies are the connective tissue of resilience.

    Applications depend on infrastructure. Business services depend on applications. Products depend on suppliers. Suppliers depend on other suppliers. Facilities depend on utilities. Customers depend on products.

    Traditional business continuity programs attempt to capture these relationships through questionnaires and interviews. The result is inevitably incomplete.

    AI combined with an organizational knowledge graph creates a fundamentally different approach.

    Instead of relying exclusively on someone to tell us every dependency, we can discover relationships from existing organizational information and continuously refine them.

    The role of the business owner changes from data entry to validation and that distinction matters.

    Because once those relationships are understood, they become useful for far more than the BIA. They become the foundation for understanding resilience.

    Annual plan maintenance shouldn't exist

    Every business continuity professional knows the ritual.

    A year has passed. It's time to review the plan. The owner receives a reminder, opens a document or application, scrolls through dozens of pages and eventually checks a box confirming the plan is current.

    But the calendar doesn't make a plan inaccurate. Change does.

    A system changed owners. A supplier changed. A facility closed. A department reorganized. A recovery strategy changed. A critical dependency appeared. A procedure became inconsistent with the organization's current technology.

    Instead of asking someone once a year to determine whether a plan changed, an AI agent can continuously identify information that may invalidate the plan.

    Then it can say: “I identified six changes that may affect your business continuity plan.”

    The human can accept the proposed update, reject it or investigate further.

    This transforms plan maintenance from calendar-driven compliance into change-driven assurance.

    Exercises should test what actually worries us

    Exercises are another area ripe for change. Today, developing a good exercise can require substantial research, scenario design, facilitation and documentation.

    AI can help design exercises based on the organization's actual vulnerabilities.

    What happens if this supplier fails? What happens if this application is unavailable? What happens if these two dependencies fail simultaneously? What happens if the documented recovery strategy doesn't work?

    The agent can generate the scenario, introduce injects, capture decisions, ask follow-up questions and adapt the exercise as participants respond.

    More importantly, exercises can become directly connected to the organization's risk and dependency information. Instead of exercising because “it's time for the annual exercise,” we can exercise because we have identified something worth testing.

    Incident response can start with understanding

    Perhaps the most significant opportunity appears when something actually goes wrong.

    Consider how organizations develop situational awareness today.

    An alert arrives. Someone sends an email. A meeting gets scheduled. People begin asking questions. Who uses this supplier? Which locations are affected? What systems support this operation? What products could be affected? Do we have alternatives? Who needs to know?

    Eventually, the organization develops an understanding of the situation. But understanding shouldn't be the end result of hours of coordination. It should be the starting point.

    Imagine an external event affecting a supplier facility. An intelligent resilience platform recognizes the supplier, traverses organizational dependencies and determines that the supplier provides a component used in two products. One product has adequate inventory. The other has eleven days of inventory and no documented alternate source.

    The system can immediately explain: What happened. What may be affected. Why it matters. What we should investigate. What actions we should consider.

    Humans still make the decisions. But they begin with context instead of a blank page. That could turn hours of impact assessment into minutes.

    Even our metrics need to change

    Many continuity programs measure what their systems make easy to count.

    Percentage of BIAs completed. Percentage of plans current. Percentage of exercises completed. Percentage of corrective actions closed.

    Those measures aren't useless. But consider what they actually tell an executive.

    An organization can have 100% current plans and still have significant resilience problems.

    The more interesting questions are different. Where do our most critical services have unmitigated dependencies? Where are recovery objectives inconsistent with actual recovery capability? Where do multiple critical services depend on the same supplier, application, facility or piece of infrastructure? Which controls haven't demonstrated that they work? Where are our documented recovery strategies based on assumptions that haven't been tested? Where is organizational change creating new resilience exposure?

    Those are measures of resilience, rather than measures of business continuity administration.

    AI makes many of those questions increasingly answerable.

    The annual business continuity lifecycle may eventually disappear

    This may be the biggest change of all. Traditional business continuity operates as a lifecycle. Conduct the BIA. Perform the risk assessment. Update the plan. Conduct the exercise. Document the findings. Track the actions. Report the results. Then eventually start again.

    But organizations don't change annually. They change constantly.

    Suppliers change. Applications change. People change. Facilities change. products change. Regulations change. Risks change. Controls change. The external environment changes.

    Why should our understanding of resilience wait for the next lifecycle?

    The future may look less like a lifecycle and more like a continuous loop: Observe → Understand → Recommend → Act → Learn

    The organization changes. The system observes those changes. The agent determines what they may mean. Humans validate important conclusions and make decisions. Exercises and incidents create new evidence. And the organization's understanding gets better. Nothing resets because January arrived.

    This changes the role of the business continuity professional

    Perhaps the most exciting implication isn't technological. It's human.

    Think about how much time business continuity professionals spend collecting information, scheduling interviews, chasing responses, updating documents, sending reminders, reconciling spreadsheets, preparing reports and administering programs.

    Now imagine redirecting much of that time toward challenging assumptions. Analyzing vulnerabilities. Testing strategies. Advising leadership. Designing better resilience capabilities. Making decisions. Helping the organization prepare for what matters.

    The goal shouldn't be to automate the business continuity professional. It should be to automate much of the administration of business continuity. That allows the profession to spend more time actually managing resilience.

    From periodic compliance to continuous resilience

    None of this means that everything we've done in business continuity was wrong. Quite the opposite. These practices evolved because they solved difficult problems using the tools available at the time. But the tools have changed.

    And when the underlying constraints change, leading practices should change with them.

    The opportunity with AI isn't simply to perform yesterday's BIA faster, generate yesterday's plan faster or write yesterday's exercise report faster.

    That's useful. But it isn't transformative. The bigger opportunity is to ask whether we need to perform those processes the same way at all. Traditional business continuity periodically asks the organization whether it is prepared.

    The next generation of business continuity can continuously develop evidence about whether it is prepared.

    That is a fundamentally different operating model. And it may finally allow us to spend less time administering business continuity and more time building resilient organizations.