What is Impact Tolerance?

Get reliable IT support and cyber security for your London business.

Contact us today to find out how we can help.

Impact tolerance is the maximum level of disruption to an important business service that an organisation can tolerate before the consequences become unacceptable. In operational resilience, it helps firms define how much disruption customers or markets could reasonably withstand before the resulting harm becomes intolerable.

For regulated financial services firms, impact tolerance provides a measurable boundary for resilience planning and testing. It is not simply a technical recovery target or an estimate of how quickly IT would like to restore a system. Instead, it should reflect the potential harm caused by disruption to the end-to-end business service and help the organisation determine whether its people, technology, suppliers, processes, and recovery arrangements are capable of keeping disruption within that limit.

Why Impact Tolerance Is Important for Businesses

Operational resilience is difficult to manage if an organisation cannot define how much disruption is too much.

A firm may know that a customer service is important, but without a measurable tolerance it becomes harder to determine whether recovery arrangements are sufficient, whether vulnerabilities require urgent remediation, or whether resilience investment is proportionate to the potential harm.

Impact tolerance provides that reference point.

Key benefits of defining impact tolerances include:

  • Clearer understanding of acceptable disruption
  • Better protection of important business services
  • Stronger alignment between resilience and customer outcomes
  • More meaningful scenario testing
  • Better prioritisation of technology investment
  • Improved recovery planning
  • Clearer management decision-making
  • Stronger visibility of resilience weaknesses
  • Better assessment of third-party dependencies
  • Improved operational resilience governance
  • More evidence-based remediation decisions
  • Stronger preparation for regulatory scrutiny

Impact tolerance also helps firms avoid focusing entirely on system availability.

A service may depend on several applications, employees, suppliers, and manual processes. Restoring one server does not necessarily mean that the business service has recovered.

For example, a customer platform may return online after two hours, but a large transaction backlog may mean customers continue experiencing significant disruption for several more hours.

Impact tolerance therefore considers the real consequence of disruption rather than only the technical restoration time.

How Impact Tolerance Works

Impact tolerance begins with an Important Business Service.

The organisation first needs to understand the service delivered to customers or other external users, why the service is important, and what could happen if it becomes unavailable or severely degraded.

It can then determine the point at which disruption would create intolerable harm.

A typical impact tolerance process includes:

  1. Identify the Important Business Service.
  2. Understand the customers or markets that depend on it.
  3. Assess the potential consequences of disruption.
  4. Determine what level of harm would become intolerable.
  5. Select appropriate measures for the tolerance.
  6. Document the rationale for the chosen threshold.
  7. Map the people, technology, data, processes, and suppliers supporting the service.
  8. Test whether the service can remain within the tolerance.
  9. Identify vulnerabilities that could cause the tolerance to be exceeded.
  10. Assign and track remediation.
  11. Retest after significant improvements.
  12. Review the tolerance when the business or service changes.

Time is commonly used when defining an impact tolerance.

For example, a firm may determine that a particular service cannot be disrupted for more than four hours before unacceptable harm occurs.

However, time alone may not always provide a complete picture.

An organisation may also consider:

  • Number of affected customers
  • Transaction volumes
  • Financial values
  • Size of a processing backlog
  • Number of failed payments
  • Geographic reach of disruption
  • Impact on vulnerable customers
  • Market consequences

Using additional measures can provide a clearer understanding of what intolerable harm actually means.

Impact Tolerance vs Recovery Time Objective

Impact tolerance and Recovery Time Objective (RTO) are related but serve different purposes.

An RTO is primarily a recovery planning metric. It defines the target time within which a system, application, or service should be restored after disruption.

Impact tolerance focuses on the maximum disruption the business can tolerate before harm becomes unacceptable.

The distinction matters.

An organisation may have:

  • An impact tolerance of four hours for an important business service
  • An RTO of two hours for a critical application supporting that service

The shorter RTO creates a buffer that gives the organisation time to restore technology and manage other operational consequences before the service reaches its impact tolerance.

Impact tolerance therefore starts from potential harm, while RTO generally starts from recovery capability.

Other important differences include:

Business Service Focus

Impact tolerance applies to the end-to-end Important Business Service rather than an individual technical component.

An RTO may apply to:

  • An application
  • A database
  • A server
  • A cloud platform
  • A network service

Impact tolerance considers how all these components combine to affect the service experienced by customers.

Harm-Based Measurement

Impact tolerances should reflect the point at which disruption causes intolerable harm.

Recovery targets may be based on technical capability, service levels, or business requirements.

Wider Dependencies

An application may be restored within its RTO, while the overall service remains unavailable because a supplier, employee, or data dependency has not recovered.

Impact tolerance encourages organisations to examine the full service chain.

Understanding this distinction helps prevent firms from assuming that existing disaster recovery targets automatically satisfy operational resilience requirements.

Key Factors When Setting Impact Tolerances

Setting an impact tolerance requires judgement and supporting evidence. Choosing an arbitrary number provides little assurance if the organisation cannot explain why that limit is appropriate.

Customer Harm

The potential impact on customers should be central to the assessment.

Firms may consider:

  • Loss of access to essential services
  • Financial loss
  • Delayed transactions
  • Inability to obtain funds
  • Missed deadlines
  • Disruption affecting vulnerable customers
  • Accumulating complaints

The tolerance should reflect when these consequences could become intolerable.

Market Impact

Some financial services may affect broader market integrity.

Disruption could influence:

  • Transaction processing
  • Market operations
  • Liquidity
  • Settlement activity
  • Confidence in financial services

These wider consequences may need to be considered when determining tolerances.

Duration

The length of disruption remains an important measure.

Some services can tolerate several hours of unavailability, while others may cause serious harm much sooner.

Duration should be based on business impact rather than convenience.

Scale of Disruption

The same outage can have very different consequences depending on how many customers are affected.

A problem affecting ten customers may be manageable, while the same failure affecting thousands could exceed the organisation’s tolerance.

Timing

The impact of disruption may also depend on when it occurs.

An outage during a low-volume period may have different consequences from the same outage during:

  • Payroll processing
  • Market opening
  • Month-end activity
  • A high-volume trading period
  • A major customer deadline

Testing should therefore consider timing as well as duration.

Vulnerable Customers

Regulated firms should consider whether disruption may disproportionately affect vulnerable customers.

A service that appears recoverable within a reasonable period may still create unacceptable harm for particular customer groups.

Together, these factors help create a tolerance that reflects real-world consequences rather than a purely technical target.

Common Impact Tolerance Challenges

Impact tolerance can be difficult to define because organisations are attempting to determine the point at which disruption moves from manageable inconvenience to intolerable harm.

Common challenges include:

  • Setting tolerances without enough evidence
  • Copying existing RTOs without considering customer harm
  • Using time as the only measure
  • Defining tolerances around individual systems rather than business services
  • Poor understanding of customer impact
  • Incomplete dependency mapping
  • Ignoring third-party dependencies
  • Setting tolerances that existing recovery capabilities cannot support
  • Weak documentation of the rationale
  • Failure to test the tolerance
  • Using overly optimistic assumptions
  • Not considering peak business periods
  • Failing to reassess tolerances after material changes
  • Limited management involvement

One particularly common issue is choosing a precise number without a clear explanation.

A tolerance of three hours may appear robust, but reviewers may ask why three hours represents the boundary between tolerable and intolerable harm.

The organisation should be able to explain what happens during those three hours.

For example:

  • How many customers are affected?
  • How quickly does a backlog grow?
  • What financial impact occurs?
  • Are vulnerable customers affected differently?
  • Can manual workarounds support the required volume?
  • What happens immediately after systems recover?

These questions help determine whether the tolerance is grounded in reality.

Another challenge is setting a tolerance that the organisation has never tested.

A firm may believe it can remain within a four-hour tolerance, but a realistic scenario exercise may reveal that full service recovery actually takes six hours.

That difference identifies a meaningful resilience vulnerability that should be managed.

Best Practices for Impact Tolerance

Impact tolerances should be evidence-based, measurable, regularly tested, and aligned with real customer and market outcomes.

Best practices include:

  • Starting with clearly defined Important Business Services
  • Assessing customer and market harm
  • Using meaningful measures in addition to time where appropriate
  • Documenting the rationale for each tolerance
  • Mapping end-to-end service dependencies
  • Comparing tolerances with actual recovery capabilities
  • Testing severe but plausible scenarios
  • Including supplier and cloud failures in testing
  • Considering high-volume and peak periods
  • Assessing impacts on vulnerable customers
  • Recording vulnerabilities revealed through testing
  • Assigning remediation owners and deadlines
  • Retesting after resilience improvements
  • Reviewing tolerances after major business changes
  • Reporting material resilience gaps to senior management
  • Maintaining evidence supporting tolerance decisions

Scenario testing is particularly important.

A tolerance should not remain theoretical.

For example, if a service has a four-hour impact tolerance, the firm should test whether technology, employees, suppliers, communication processes, and recovery arrangements can actually keep the service within that limit during a realistic disruption.

Testing may reveal that a manual workaround works for normal volumes but cannot cope during a peak period.

It may reveal that two supposedly independent services depend on the same cloud provider.

It may also show that systems can be technically restored within the required timeframe but that operational recovery takes significantly longer.

These findings should feed into remediation and future testing.

Impact tolerances should also be reviewed as the business evolves. New products, acquisitions, technology changes, customer growth, supplier changes, or different customer expectations can all affect how quickly disruption becomes intolerable.

Conclusion: Why Impact Tolerance Matters

Impact tolerance provides regulated firms with a practical way to define how much disruption an Important Business Service can withstand before the consequences become unacceptable. It shifts resilience planning away from assumptions about individual systems and towards the real outcomes experienced by customers and markets.

A well-defined impact tolerance helps organisations test recovery capabilities, prioritise resilience improvements, understand critical dependencies, and identify where existing arrangements may not be sufficient. It also creates a measurable standard against which scenario testing and remediation can be assessed.

Impact tolerances should not remain static numbers inside an operational resilience document. Services, customers, systems, suppliers, and risks continue to change. When tolerances are regularly reviewed, tested, and supported by current evidence, they provide a much stronger foundation for understanding whether the organisation can remain resilient when serious disruption occurs.