Fewer assumptions, more proven recovery time.
A process register with impact analysis, dependencies on systems and suppliers tested against recovery time, and continuity plans that only count once they have been exercised. Built and hosted in the EU.
From now to next
From a BIA in a spreadsheet to a chain that holds
Most organisations manage to produce an impact analysis once. Keeping it current, tying it to what actually runs underneath a process and showing that the recovery plan works is the work that tends to stall.
The BIA is a snapshot
Recovery times live in a spreadsheet from two years ago. Nobody knows whether they still apply.
A BIA with a life cycle
Draft, submit, approve. Recovery times can only change through a new, approved BIA, and an overdue review triggers a reminder.
The chain lives in people's heads
The process owner knows which systems and suppliers a process needs. Whether their recovery time fits within the RTO, nobody knows.
Recovery time against the RTO
Systems from the asset register and suppliers from TPRM sit under the process, with their recovery time next to the RTO. A link that is too slow turns red.
The plan has never been tested
There is a continuity plan in a folder. Nobody remembers the last exercise.
Plans with an exercise cycle
Every plan carries its exercises, results and findings. A successful exercise moves the next date on by a year; a plan without one shows up as a gap in the cockpit.
The supervisor asks for evidence
For ISO 22301 or DORA you gather whatever exists after the fact.
Assurance from the register
The assurance view derives, per framework, which requirement your own processes, BIAs and exercises cover and which they do not.
This is what it looks like
A selection from BCM
Click a thumbnail for that screen, or the image itself for the full-size view.
Frequently asked questions
What you want to know about BCM beforehand
What is BCM?
BCM is Audirium's business continuity application: a process register with business impact analysis (BIA), dependencies on systems and suppliers, continuity plans with exercises and a cockpit that shows where the organisation is vulnerable. It is part of the Audirium suite and reads from the asset register and TPRM.
Who is BCM for?
For the person responsible for business continuity or operational resilience, the process owners who complete a BIA, and the risk or compliance function that has to demonstrate ISO 22301 or DORA compliance. Process owners do not need an account to complete a BIA.
What does BCM actually do?
BCM maintains the process register, lets each process score an impact matrix from which MTPD, RTO and RPO follow, tests the recovery time of systems and suppliers against the RTO, stores continuity plans with their exercises, and derives per framework which requirements are covered. Review dates are monitored with reminders.
How does BCM differ from a BIA in a spreadsheet?
A spreadsheet captures a moment. In BCM recovery times can only change through an approved BIA, an RTO longer than the MTPD is refused, and dependencies sit under the process with their own recovery time from the asset register and TPRM. A plan without an exercise appears as a gap in the cockpit.
Does BCM work with other parts of the suite?
Yes. BCM reads systems and their recovery time from the asset register and suppliers with their SLA from TPRM. In turn, TPRM shows for each supplier which processes depend on it. Barriers from the Bowtie application appear on the service card. Every link stays within your own organisation.
Where is BCM data stored?
On Hetzner servers in the EU. Each organisation has its own separate database; data from different organisations never ends up in one file. BCM uses no AI and sends no data to third parties.
What BCM offers
One place for process, impact, chain and exercise
BCM is the source for the process register and the impact analysis. Other parts of the suite read from it, so a process exists in one place only.
Process register
Every process with owner, deputy, criticality and review date. Processes from TPRM can be taken over in a single action.
Impact matrix
Score impact per criterion (financial, customers, regulatory, reputation, staff) across five time bands. MTPD, RTO and RPO follow from the matrix; an RTO longer than the MTPD is refused.
Survey without an account
Send the process owner a one-time link. They complete the BIA without logging in, in Dutch or English, and the link expires on submission.
Dependencies with recovery time
Systems from the asset register, suppliers from TPRM, locations, people and data under each process. Recovery time comes from the source and is tested against the RTO of the process.
Service card
For each critical service: tolerance limit versus achievable recovery time, the slowest link in the chain, the barriers from the bowtie and whether it has ever been exercised.
Plans and exercises
One continuity plan per process, approved and still editable afterwards. Walkthrough, simulation or full test, with result, findings and follow-up.
Scenarios
A starter set of nine scenarios based on RTS (EU) 2024/1774, extended with your own and linked to exercises.
Assurance per framework
ISO 22301, DORA and ISO 27001: for each requirement you see whether your register, BIAs and exercises cover it.
A cockpit that counts honestly
One continuity score from BIA coverage, chain, plans, exercises and reviews. A measure that does not apply to you is not counted as zero, and every gap links through to the processes behind it.
How it works
From process register to proven recovery in six steps
Record the processes
Register processes with owner, deputy and criticality, or take them over from TPRM.
Start a BIA round
Open a draft BIA for the selected processes in one go and send the owners a survey link.
Approve the BIA
Check the impact matrix, approve MTPD, RTO and RPO and set the review date.
Map the chain
Link systems from the asset register and suppliers from TPRM to the process and see which link misses the RTO.
Write the plan and exercise it
Approve a continuity plan per process and record every exercise with its result and follow-up.
Report per framework
Read in the assurance view which ISO 22301 or DORA requirements are covered, and in the cockpit who needs to act.
Want to know which process misses its recovery time before it fails?
Request a demo or get in touch for more information about BCM for your organisation.