Skip to content
bazzi.ai
How long does an IRM or BCM programme take, and what drives the timeline?
All answers

How long does an IRM or BCM programme take, and what drives the timeline?

There is no fixed timeline for a BCM or IRM programme, because both are driven by scope and readiness rather than by the type of programme: how many business units and jurisdictions are in taxonomy, how much of the control library already exists, and whether the taxonomy and ownership questions are settled before platform work starts. If a programme moves into platform configuration before every risk owner has confirmed the taxonomy describes their own work, the timeline will run long regardless of the plan on paper.

Published · Updated

Maximilian Bazzi, Founder and CEO

Why there is no single duration

A BCM or IRM programme is not one fixed piece of work. It can mean defining a risk taxonomy from nothing, or configuring a platform against a taxonomy that already exists, or remediating a stalled implementation, and each of those has a different shape and a different timeline. Two organisations both asking for an IRM programme can be asking for pieces of work that differ by an order of magnitude, depending on what already exists.

What actually drives the timeline

The main driver is how quickly an organisation can settle its own taxonomy and ownership questions, since that requires input from risk owners across the business rather than only from the team running the programme. A programme that starts with a taxonomy and named ownership already agreed moves into platform configuration quickly. A programme that has to establish both first will spend most of its calendar time on that work, not on the technology.

Where the shape of the programme comes from

The number of business units and jurisdictions the taxonomy has to cover, and how much of the control library and business impact analysis already exists in usable form, set the shape of the work. Reusable, well-structured existing work shortens the programme significantly. Starting from scratch, or from a taxonomy that needs rebuilding rather than adopting, extends it, independently of which platform or build route is chosen afterwards.

Where teams commonly run into difficulty

The common difficulty is scoping a programme against a label, such as "an IRM implementation", before establishing what is actually being implemented against. A timeline given against a vague scope is not more useful for arriving early: it usually means the taxonomy and ownership work was never separated out as its own phase, which is the part that actually sets the pace.

How Bazzi Consulting helps

We scope against what your organisation actually needs done, settle the taxonomy and ownership questions as a distinct first phase, and sequence the platform work against that rather than against a generic programme label. See risk and resilience advisory.

Essential cookies keep the site working and cannot be switched off. Analytics is optional.

Always on. Required for the site to function.

Cookieless usage analytics (Vercel Analytics). No cross-site tracking.