Home · Glossary · Recovery objectives
Business continuity guide

RTO, RPO, MAO, MBCO: recovery objectives on real examples

Four numbers turn "recover quickly" into a requirement that can be engineered, budgeted and tested: MAO, RTO, RPO and MBCO. Set together, they define how much disruption your company can actually survive.

Why four numbers, and who approves them

"We will recover as fast as possible" is not a plan — it is a hope. Recovery becomes manageable when it is expressed as targets: how long the business survives an outage (MAO), how fast a process must be restored (RTO), how much data may be lost (RPO), and what minimum level of service must be kept during recovery (MBCO). Process owners propose the numbers based on the Business Impact Analysis (BIA), finance checks them against the cost of downtime, executive management approves them, and the board sees the aggregate picture. The approved numbers then flow into architecture decisions, supplier SLAs and test plans.

MAO: the boundary of the unacceptable

The Maximum Acceptable Outage is the longest a process can stand still before the damage becomes unacceptable: contract penalties, regulatory breach, patient safety, irreversible loss of clients. Some standards call the same boundary MTPD — the Maximum Tolerable Period of Disruption. Beyond this line you are no longer managing an incident; you are managing the survival of the business. The MAO comes from business analysis, not from IT: it reflects what customers, contracts and regulators will tolerate.

Timeline diagram showing the Maximum Acceptable Outage (MAO) as the boundary where disruption damage becomes unacceptable
The MAO marks the point where disruption damage becomes unacceptable.

RTO: inside the MAO, with margin

The Recovery Time Objective is the target time to restore the process. It must sit inside the MAO with a margin, because real recoveries slip: a key person is unreachable, a step fails, a dependency surprises you. A margin of 30-50% of the MAO is a reasonable rule of thumb. Speed is bought, not declared — the shorter the RTO, the more expensive the standby architecture behind it, which is why an RTO is approved together with its price.

Recovery timeline showing the Recovery Time Objective (RTO) positioned inside the MAO with a safety margin
The RTO sits inside the MAO, leaving a safety margin for slippage.

RPO: how much data you may lose

The Recovery Point Objective limits data loss, measured in time. An RPO of 5 minutes means the last usable copy of the data is never older than 5 minutes — which dictates replication or backup at least that frequent. RTO and RPO answer different questions: RTO is about when customers are served again, RPO is about how much of their data survived. And a backup that has never been restored in a test does not count as a backup.

MBCO: the minimum level of service

The Minimum Business Continuity Objective defines the level of service the company commits to deliver while recovery is under way — for example, 50% of normal throughput, priority customers first. Without an MBCO, recovery implicitly aims at 100% from the first minute, which inflates cost and blocks realistic decisions about what to restore first.

A worked example: a payment service

Consider a payment processor whose merchant contracts trigger penalties after 6 hours of outage, and whose clients begin switching providers after roughly a working day. The company sets the MAO at 6 hours. The RTO is set at 4 hours, leaving a 2-hour margin; the last failover test came in at 3 hours 10 minutes, so the chain holds — tested time under RTO, RTO under MAO. Replication to the standby site runs every 5 minutes, matching an approved RPO of 5 minutes. The MBCO states that during recovery the company keeps at least 50% of normal transaction throughput, with card authorisation prioritised over reporting services. Every number has an owner, an approval and a test behind it.

How the four numbers relate

ObjectiveQuestion it answersExample value
MAO (MTPD)How long can we survive an outage?6 hours
RTOHow fast must the process be restored?4 hours (margin 2 hours)
RPOHow much data may we lose?5 minutes
MBCOWhat minimum service do we keep meanwhile?50% of throughput

Common mistakes

How these targets are derived from impact analysis — and what they cost — is the subject of module M3 of the ERGP programme. For the method itself, start with our guide to the Business Impact Analysis.

Frequently asked questions

What is the difference between MBCO and MTPD?

MTPD (or MAO) is about time — how long the organisation can survive without the service before damage becomes unacceptable. MBCO is about level — the minimum volume of the service that must be kept or restored first. One caps the outage, the other defines the floor of delivery during it.

Is MTPD the same as MAO?

In substance, yes. MTPD is the ISO 22301 term, MAO appears in other frameworks; both name the boundary beyond which disruption is unacceptable. Pick one term for your programme and use it consistently.

In what order are the four numbers set?

From the impact analysis: first MAO/MTPD as the ceiling, then MBCO as the service floor, then RTO inside the ceiling with a margin, then RPO from the data-loss tolerance. Arrangements and budgets follow the numbers, never the other way round.

Related termsRTO · Recovery Time Objective RPO · Recovery Point Objective MAO · Maximum Acceptable Outage MBCO · Minimum Business Continuity Objective MTPD · Maximum Tolerable Period of Disruption BIA · Business Impact Analysis

These objectives are part of the working language of ERGP — the first resilience governance certification fully available in Arabic, also in English. 94 chapters, six modules, a verifiable certificate.

Explore the ERGP programme