Skip to main content
Category: Business Continuity

Impact Tolerance

Also known as: impact tolerances
Simply put

Impact tolerance is the maximum level of disruption that an organization considers acceptable for one of its critical or important services before customers, markets, or the organization itself would suffer unacceptable harm. In practice, it sets a limit on how much disruption a service can experience before the consequences become intolerable. It is used in operational resilience to define the boundary an organization aims to stay within during a disruptive event.

Formal definition

In operational resilience practice, impact tolerance is commonly defined as the maximum tolerable level of disruption to an important or critical business service, typically expressed to include the maximum tolerable duration of disruption, beyond which the harm to customers, markets, or the organization would be considered intolerable. Impact tolerances are frequently set as limits by boards and, in some jurisdictions, expected or required by regulators, and firms may use scenario testing to assess whether they can remain within those defined tolerances under severe but plausible disruption. Impact tolerance is distinct from operational recovery metrics such as a recovery time objective: it defines the outer boundary of acceptable harm at the service level rather than an internal target for restoring a specific system or process. The specific parameters, expression, and regulatory status of impact tolerances vary by jurisdiction, sector, and organization; this entry does not address particular regulatory regimes, thresholds, or implementation methods.

Why it matters

Impact tolerance shifts the focus of resilience planning away from protecting individual systems and toward limiting harm to the services that customers and markets actually depend on. By defining the maximum level of disruption a critical or important service can experience before the consequences become intolerable, an organization establishes a clear boundary it aims to stay within during a disruptive event. This gives boards and senior management a concrete reference point for judging whether the organization is adequately prepared, rather than relying on general assurances that systems are robust.

Setting impact tolerances also reframes resilience as an assumption that disruption will occur, not merely that it might be prevented. Because tolerances are expressed at the service level and often include a maximum tolerable duration of disruption, they help an organization prioritize investment and response toward the outcomes that matter most to affected parties. In some jurisdictions, boards are expected or required to set these limits, and regulators may treat them as a supervisory expectation, which raises the governance stakes for defining and evidencing them accurately.

Impact tolerances are meaningful only when tested against severe but plausible conditions. Firms may use scenario testing to assess whether they can remain within their defined tolerances, which can surface gaps between stated limits and actual capability. Where scenario testing shows an organization cannot stay within a tolerance, it signals a need for remediation before a real disruption forces the issue.

Who it's relevant to

Boards and senior management
Boards are frequently responsible for setting impact tolerances as limits for critical or important services. Doing so requires them to understand where the organization's threshold for intolerable harm lies and to hold management accountable for staying within it.
Operational resilience and business continuity teams
These teams translate board-set tolerances into service-level analysis, map the resources supporting each service, and design scenario tests to assess whether the organization can remain within its defined impact tolerances under severe but plausible disruption.
Risk managers
Risk professionals use impact tolerances to frame the acceptable boundary of disruption at the service level and to distinguish this outer limit of harm from internal recovery targets such as recovery time objectives when assessing preparedness.
Compliance and regulatory specialists
In some jurisdictions, impact tolerances are expected or required by regulators. Compliance teams help ensure tolerances are defined, evidenced, and tested in line with applicable supervisory expectations, noting that regulatory status varies by jurisdiction and sector.
Internal auditors and assurance functions
Assurance functions may independently evaluate whether impact tolerances have been appropriately set and whether scenario testing credibly supports the claim that the organization can stay within them, without themselves owning the resilience activities being assessed.

Inside Impact Tolerance

Tolerable Level of Disruption
Impact tolerance expresses the maximum level of disruption to an important business service that an organization is willing to accept, commonly articulated as a threshold beyond which further disruption would cause intolerable harm.
Service-Level Orientation
The concept is typically set at the level of a specific important business service rather than at the level of individual systems or assets, focusing on the outcome experienced by clients, the market, or other stakeholders.
Quantitative Metrics
Impact tolerances are often expressed using measurable parameters such as a maximum duration of outage, volume of affected transactions, or number of affected customers, so that breaches can be objectively identified.
Severe-but-Plausible Scenario Basis
Impact tolerances are commonly tested against severe-but-plausible disruption scenarios to assess whether the organization could remain within tolerance under adverse conditions.
Operational Resilience Linkage
The term is most closely associated with operational resilience frameworks, where it supports decisions about investment, recovery capabilities, and prioritization of resources for critical services.

Common questions

Answers to the questions practitioners most commonly ask about Impact Tolerance.

Is impact tolerance the same as risk appetite?
No. Risk appetite expresses the amount and type of risk an organization is willing to pursue or accept in pursuit of its objectives, whereas impact tolerance typically expresses the maximum level of disruption to an important business service that an organization can withstand, often defined by the point beyond which harm becomes intolerable. The two are related but distinct: risk appetite is generally a forward-looking positioning statement about accepting uncertainty, while impact tolerance sets an outer boundary on the consequences of disruption. Confusing the two can lead to setting a tolerance that reflects a desired risk posture rather than a genuine limit on survivable harm.
Does staying within impact tolerance mean a disruption caused no harm or that recovery was successful?
Not necessarily. Impact tolerance commonly defines the outer boundary of tolerable disruption rather than a target or an indicator of a good outcome. Remaining within tolerance means the disruption did not exceed the point at which harm is considered intolerable, but harm may still have occurred below that threshold. It is a limit, not a performance goal, and staying within it does not by itself confirm that recovery arrangements performed as intended or that customers and other stakeholders were unaffected.
How is impact tolerance typically expressed in practice?
It is often articulated in measurable terms tied to a specific important business service, such as a maximum tolerable duration of disruption, a volume of affected transactions or customers, or another quantifiable measure of harm. The specific metrics chosen depend on the nature of the service and the relevant regulatory context, where applicable. This entry does not prescribe particular metrics or thresholds, as appropriate measures vary by organization, service, and jurisdiction.
Who is usually responsible for setting and approving impact tolerances?
Setting impact tolerances is generally a management and governance activity rather than an assurance function. In many arrangements, senior management proposes tolerances and the board or an equivalent governing body reviews or approves them, given that the exercise involves judgments about what level of harm to the organization and its stakeholders is tolerable. Assurance functions, such as internal audit, would typically evaluate the process independently rather than set the tolerances themselves, preserving their objectivity.
How does impact tolerance relate to scenario testing?
Organizations commonly test their ability to remain within impact tolerance by running scenarios, including severe but plausible disruption scenarios, to assess whether important business services could be delivered within the defined boundary. Testing may reveal vulnerabilities where the organization could exceed its tolerance, informing remediation and investment decisions. The design, severity, and frequency of such testing vary by organization and by any applicable regulatory expectations, and this entry does not cover specific testing methodologies or tooling.
How often should impact tolerances be reviewed?
Impact tolerances are typically reviewed periodically and when material changes occur, such as changes to important business services, the operating environment, third-party dependencies, or applicable regulatory requirements. The appropriate cadence depends on the organization's context and any relevant supervisory expectations, so no single universal frequency applies. Reviews generally consider whether previously set tolerances remain aligned with what the organization can genuinely withstand.

Common misconceptions

Impact tolerance is the same as risk appetite or risk tolerance.
Impact tolerance concerns the maximum tolerable level of disruption to an important business service assuming a disruption occurs, whereas risk appetite and risk tolerance concern the amount and type of risk an organization is willing to pursue or accept in pursuit of objectives. They address different questions and should not be used interchangeably.
Impact tolerance is equivalent to a recovery time objective (RTO).
While both may reference time, an RTO is typically an internal recovery target for a system or process, whereas impact tolerance defines the outer limit of disruption to an important business service beyond which harm becomes intolerable. Impact tolerance is generally set from the perspective of the service outcome and stakeholders rather than an internal recovery goal.
Setting an impact tolerance guarantees the organization will remain resilient.
Defining an impact tolerance is a benchmark for assessment and prioritization, not a control that ensures outcomes. Remaining within tolerance depends on the effectiveness of resilience capabilities, and testing against severe-but-plausible scenarios may reveal gaps.

Best practices

Define impact tolerances at the level of important business services, focusing on the outcome experienced by clients and stakeholders rather than on individual systems or assets.
Express impact tolerances using measurable metrics, such as maximum outage duration or volume of affected transactions, so that breaches can be objectively identified.
Test impact tolerances against severe-but-plausible disruption scenarios to assess whether the organization can remain within tolerance under adverse conditions.
Distinguish impact tolerance clearly from related concepts such as risk appetite, risk tolerance, and recovery time objectives in documentation to avoid conflation.
Use identified gaps between current capabilities and impact tolerances to prioritize investment in recovery and resilience measures.
Confirm the applicable regulatory and jurisdictional context before treating any specific impact tolerance requirement as binding, as expectations may differ across jurisdictions and sectors.
a promotional banner asking how ready are you for PCI DSS 4.0? With a call-to-action to get the checklist now.