Impact Tolerance
Impact tolerance is the maximum level of disruption that an organization considers acceptable for one of its critical or important services before customers, markets, or the organization itself would suffer unacceptable harm. In practice, it sets a limit on how much disruption a service can experience before the consequences become intolerable. It is used in operational resilience to define the boundary an organization aims to stay within during a disruptive event.
In operational resilience practice, impact tolerance is commonly defined as the maximum tolerable level of disruption to an important or critical business service, typically expressed to include the maximum tolerable duration of disruption, beyond which the harm to customers, markets, or the organization would be considered intolerable. Impact tolerances are frequently set as limits by boards and, in some jurisdictions, expected or required by regulators, and firms may use scenario testing to assess whether they can remain within those defined tolerances under severe but plausible disruption. Impact tolerance is distinct from operational recovery metrics such as a recovery time objective: it defines the outer boundary of acceptable harm at the service level rather than an internal target for restoring a specific system or process. The specific parameters, expression, and regulatory status of impact tolerances vary by jurisdiction, sector, and organization; this entry does not address particular regulatory regimes, thresholds, or implementation methods.
Why it matters
Impact tolerance shifts the focus of resilience planning away from protecting individual systems and toward limiting harm to the services that customers and markets actually depend on. By defining the maximum level of disruption a critical or important service can experience before the consequences become intolerable, an organization establishes a clear boundary it aims to stay within during a disruptive event. This gives boards and senior management a concrete reference point for judging whether the organization is adequately prepared, rather than relying on general assurances that systems are robust.
Setting impact tolerances also reframes resilience as an assumption that disruption will occur, not merely that it might be prevented. Because tolerances are expressed at the service level and often include a maximum tolerable duration of disruption, they help an organization prioritize investment and response toward the outcomes that matter most to affected parties. In some jurisdictions, boards are expected or required to set these limits, and regulators may treat them as a supervisory expectation, which raises the governance stakes for defining and evidencing them accurately.
Impact tolerances are meaningful only when tested against severe but plausible conditions. Firms may use scenario testing to assess whether they can remain within their defined tolerances, which can surface gaps between stated limits and actual capability. Where scenario testing shows an organization cannot stay within a tolerance, it signals a need for remediation before a real disruption forces the issue.
Who it's relevant to
Inside Impact Tolerance
Common questions
Answers to the questions practitioners most commonly ask about Impact Tolerance.
