Skip to main content
a promotional graphic telling you that PCI Compliance is no longer an annual exercise and that continuous monitory must be built in
Category: Business Continuity & Resilience

Impact Tolerance

Also known as: Impact Tolerances
Simply put

Impact tolerance is the maximum level of disruption to an important service that an organization considers it can withstand before that disruption causes unacceptable harm. It sets a clear limit that helps a firm judge whether a disruption has gone too far. In practice, it is often expressed in relation to critical or important business services and the harm disruption could cause to customers, markets, or the organization itself.

Formal definition

In operational resilience practice, impact tolerance is commonly defined as the maximum tolerable level of disruption to an important or critical business service, beyond which the harm to customers, markets, or the organization is considered intolerable. It functions as a defined limit, frequently set by boards and, in some jurisdictions, informed by regulatory expectations, against which a firm assesses whether it can continue to operate within acceptable bounds during a disruption. Impact tolerance is typically applied at the level of a specific important business service and is often validated through scenario testing that evaluates whether the service can remain within its defined tolerances under severe but plausible conditions. It should be distinguished from operational recovery metrics such as the Recovery Time Objective, which addresses target restoration times rather than the outer boundary of tolerable harm. The precise definition, thresholds, and regulatory applicability vary by jurisdiction, sector, and organization, and firms should verify specific requirements against the applicable regulatory source.

Why it matters

Impact tolerance shifts the resilience conversation from an inward focus on how quickly systems can be restored to an outward focus on the harm that disruption causes to customers, markets, and the organization itself. By defining the maximum level of disruption a firm considers it can withstand before that harm becomes unacceptable, impact tolerance gives boards and management a concrete limit against which to judge whether a disruption has gone too far. Without such a limit, an organization may respond to incidents without a clear reference point for when a service failure crosses from manageable to intolerable.

Because impact tolerance is set at the level of a specific important or critical business service, it directs resilience investment toward the services whose failure would cause the most harm, rather than treating all systems as equally significant. In some jurisdictions, expectations around impact tolerance are informed by regulatory requirements, which raises the stakes for firms to define, evidence, and test their tolerances rigorously. Setting a tolerance is not a one-time exercise; it is often validated through scenario testing that examines whether a service can remain within its defined limits under severe but plausible conditions.

The practical value of impact tolerance depends on how carefully it is distinguished from related metrics. It is not the same as a Recovery Time Objective, which addresses a target restoration time rather than the outer boundary of tolerable harm. Confusing the two can lead a firm to believe it is resilient because it can restore a service quickly, while overlooking whether the cumulative harm during that restoration period would already exceed what customers or markets can bear. The precise thresholds and regulatory applicability vary by jurisdiction, sector, and organization, so firms should verify specific requirements against the applicable regulatory source.

Who it's relevant to

Boards and senior management
Impact tolerances are frequently set at board level, making directors and senior leaders accountable for defining the maximum disruption an important service can withstand before harm becomes unacceptable. This positions impact tolerance as a governance matter that informs oversight, escalation, and resilience investment decisions.
Operational resilience and business continuity professionals
Those responsible for operational resilience apply impact tolerance at the level of specific important or critical business services and design scenario tests to evaluate whether those services can remain within defined tolerances under severe but plausible conditions. They also work to keep impact tolerance distinct from recovery metrics such as the Recovery Time Objective.
Compliance and regulatory affairs teams
In some jurisdictions, expectations around impact tolerance are informed by regulatory requirements. Compliance and regulatory affairs staff help interpret how those expectations apply to the firm and verify specific thresholds and applicability against the relevant regulatory source, given that requirements vary by jurisdiction, sector, and organization.
Risk managers
Risk managers use impact tolerance as a defined limit against which to assess whether the firm can continue to operate within acceptable bounds during a disruption, helping to focus attention and treatment on the services whose failure would cause the most harm to customers, markets, or the organization.

Inside Impact Tolerance

Tolerable Level of Disruption
The maximum extent of disruption to an important business service that an organization is prepared to accept, typically expressed as a threshold beyond which harm becomes unacceptable to the firm, its clients, or wider stakeholders.
Metrics and Measures
The quantitative or qualitative parameters used to express the tolerance, which in many frameworks may include time (duration of outage), volume (number of transactions or customers affected), or other service-specific indicators. The appropriate measure varies by service and context.
Important Business Services
The specific services or functions to which impact tolerances are attached. Impact tolerance is typically set at the level of individual important business services rather than for the organization as a whole.
Point of Intolerable Harm
The conceptual boundary the tolerance seeks to define, being the point at which disruption would cause harm considered unacceptable. Where this boundary lies is context-dependent and often involves judgment about effects on consumers, market integrity, or the firm's safety and soundness.
Severe-but-Plausible Scenarios
The stress conditions against which the ability to remain within impact tolerance is commonly tested. These are scenarios considered severe yet realistic, used to assess resilience rather than routine operating assumptions.
Relationship to Operational Resilience
Impact tolerance is generally a component of broader operational resilience arrangements, informing how an organization prioritizes investment, response, and recovery to stay within acceptable limits of disruption.

Common questions

Answers to the questions practitioners most commonly ask about Impact Tolerance.

Is impact tolerance the same as risk appetite?
No. The two concepts are related but distinct and are frequently confused. Risk appetite typically describes the amount and type of risk an organization is willing to pursue or accept in pursuit of its objectives, expressed forward-looking across a portfolio of risks. Impact tolerance, by contrast, is generally framed around the maximum level of disruption an organization is prepared to withstand for a specific important business service, often expressed as a point beyond which the harm becomes unacceptable. In many operational resilience frameworks, impact tolerance functions as a threshold for tolerable disruption rather than a statement of willingness to take on risk. Because usage varies by framework and jurisdiction, the two terms should not be treated as interchangeable.
Does setting an impact tolerance mean the organization is planning to allow disruption up to that level?
Not in the way that phrasing suggests. An impact tolerance is often best understood as an outer boundary of tolerable harm, not a target or an operating goal. Setting it does not imply the organization intends to disrupt service up to that point; rather, it typically defines the level of disruption beyond which the consequences would be considered unacceptable, so that the organization can prioritize investment, testing, and response to remain within it. The intent in many frameworks is to drive the organization to stay well inside the boundary, not to operate at it.
How is an impact tolerance typically expressed for an important business service?
In practice, impact tolerance is often articulated using measurable dimensions tied to a specific important business service, such as maximum tolerable duration of disruption, the point in time by which service must be restored, or thresholds relating to the number of affected customers or transactions. The precise metrics and how they are set vary by organization, sector, and applicable regulatory expectations. Because the appropriate measures depend on the service and the harm it could cause, definitions should be tailored to context rather than applied generically, and any sector-specific expectations should be verified against the relevant primary source.
Who should be involved in setting and approving impact tolerances?
Setting impact tolerances generally spans governance and risk management responsibilities. In many arrangements, business service owners and operational teams contribute the practical understanding of how services function and could fail, while senior management and the board or an appropriate committee often hold accountability for approving the tolerances, since they represent decisions about acceptable harm. This division reflects the governance principle that decision rights over material thresholds rest at an appropriately senior level. Specific roles, committee structures, and approval requirements will depend on the organization's governance model and any applicable regulatory expectations.
How can an organization test whether it can remain within its impact tolerances?
Organizations commonly use scenario testing to assess whether an important business service can be maintained within its impact tolerance during plausible disruptions. This often involves designing severe but plausible scenarios, simulating their effect on the service, and evaluating whether recovery and continuity capabilities keep disruption inside the defined threshold. Testing may reveal vulnerabilities or dependencies that need remediation. The nature, frequency, and rigor of such testing vary by organization and sector, and any specific supervisory expectations should be verified against the relevant primary source.
What should an organization do if testing shows it cannot stay within an impact tolerance?
A finding that a service could breach its impact tolerance under a plausible scenario is typically treated as a signal to act. Organizations often respond by identifying the gap, prioritizing remediation such as strengthening controls, addressing single points of failure, improving recovery arrangements, or reducing dependencies, and tracking progress through governance oversight. In some cases the analysis may also prompt a reconsideration of whether the tolerance itself was set appropriately. Because these are matters of both operational judgment and, in regulated sectors, potential supervisory interest, decisions should be documented and, where relevant, informed by professional and legal advice.

Common misconceptions

Impact tolerance is the same as risk appetite.
The two are related but distinct. Risk appetite typically expresses the amount and type of risk an organization is willing to pursue or retain in pursuit of objectives, whereas impact tolerance focuses specifically on the maximum acceptable level of disruption to an important business service, often assuming a disruption has occurred. They operate at different levels and answer different questions.
Setting an impact tolerance means the organization can prevent disruption from ever exceeding it.
An impact tolerance defines a threshold the organization aims to remain within; it does not eliminate the possibility of exceeding it. Its purpose is to guide resilience planning and prioritization. No control or tolerance guarantees that disruption will stay within the stated limit, which is why testing against severe-but-plausible scenarios is commonly emphasized.
A single impact tolerance can be set for the whole organization.
In many frameworks, impact tolerances are set for each important business service individually, because the point at which disruption causes intolerable harm differs across services. A single organization-wide figure would typically obscure these service-specific differences.

Best practices

Identify and clearly define the important business services first, then set an impact tolerance for each rather than attempting a single organization-wide figure.
Express each tolerance using measures appropriate to the service, such as time, volume, or other relevant indicators, and document the rationale for the threshold chosen.
Test the ability to remain within impact tolerances against a range of severe-but-plausible disruption scenarios, and update assumptions as the operating environment changes.
Distinguish impact tolerance from related concepts such as risk appetite and recovery objectives in governance documentation to avoid conflation.
Involve relevant stakeholders, including business owners, risk, compliance, and where applicable legal, when defining the point of intolerable harm, since this involves judgment about effects on consumers and the firm.
Verify specific regulatory expectations, effective dates, and any prescribed requirements against the primary source applicable to the organization's jurisdiction and sector, as applicability varies.
Promotional banner for the Pentest Readiness checklist download