Impact tolerance shifts the executive question from whether a disruption can happen to how much disruption customers and the market can absorb. The term comes from the Bank of England supervisory statement SS1/21 and the FCA operational resilience rules, and similar language now appears in regulatory expectations across the Gulf, including from the Central Bank of the UAE. Setting a tolerance forces the board to state, in numbers, the point at which harm becomes unacceptable. That statement then drives the investment decisions behind resilience.
A tolerance is set for each important business service, not for systems or departments. The service owner and the resilience team propose it, the board approves it, and it is recorded in the firm's resilience self-assessment. A retail payments service, for example, may carry a tolerance of 8 hours of disruption or 5 percent of failed transactions in a day, whichever comes first. The firm then tests severe but plausible scenarios to prove it can stay within the tolerance. Unlike an internal MAO, the tolerance is anchored in harm to customers and market integrity, not in internal recovery convenience.
The common error is relabelling an existing RTO or MAO as an impact tolerance and changing nothing else. A tolerance answers a different question — how much harm is acceptable outside the firm — and usually forces harder scenarios and larger investment than internal targets do. How regulators frame and supervise these expectations is examined in ERGP module M5 on regulation.
This term is part of the working language of ERGP — the first resilience governance certification fully available in Arabic, also in English. 94 chapters, six modules, a verifiable certificate.
Explore the ERGP programme