Understanding Impact Tolerances and How to Set Them
Learn what impact tolerances are, why regulators require them, and practical methods for defining meaningful thresholds for your important business services.
Regulators across multiple sectors now expect organisations to define and manage impact tolerances for their important business services. Yet many organisations struggle to understand what this actually means in practice and how to set tolerances that are both meaningful and achievable. Getting this right matters not just for compliance, but for building genuine operational resilience.
Impact tolerances represent the maximum level of disruption that would be tolerable before unacceptable harm occurs to customers, market integrity, or the organisation itself. They are not aspirational targets or service level agreements. They are the outer boundaries beyond which an organisation accepts it cannot safely operate.
The Regulatory Context for Impact Tolerances
Financial services regulators, including the Financial Conduct Authority and Prudential Regulation Authority in the UK, have placed impact tolerances at the centre of their operational resilience frameworks. The requirements came into full effect in March 2025, meaning organisations must now be able to remain within their tolerances during severe but plausible disruption scenarios.
This regulatory approach represents a fundamental shift in thinking about resilience. Rather than focusing primarily on preventing disruptions, regulators now expect organisations to demonstrate they can continue delivering critical services even when things go wrong. Impact tolerances provide the measurable standard against which this capability is assessed.
Other sectors are following similar paths. Healthcare, utilities, and critical infrastructure organisations increasingly face expectations to define acceptable levels of service disruption and demonstrate their ability to operate within these limits.
The Relationship Between Impact Tolerances and Business Impact Analysis
Impact tolerances build upon but differ from traditional business impact analysis. A business impact analysis identifies how disruption affects an organisation and helps prioritise recovery efforts. Impact tolerances take this further by defining the point at which disruption becomes unacceptable and must be avoided.
Think of business impact analysis as understanding the consequences of disruption across a spectrum of time and severity. Impact tolerances draw a specific line on that spectrum, saying that disruption beyond this point cannot be allowed to occur without fundamental harm to customers or the organisation.
This relationship means that good business impact analysis provides essential input for setting impact tolerances. You cannot define acceptable limits without first understanding what happens as disruption duration and severity increase.
Practical Methods for Defining Meaningful Thresholds
Setting impact tolerances requires balancing multiple considerations. Tolerances that are too tight may be impossible to achieve and could divert resources from more practical resilience improvements. Tolerances that are too loose fail to drive meaningful change and may not satisfy regulatory expectations.
Start by identifying your important business services. These are the services that, if disrupted, would cause harm to customers, market integrity, or the safety and soundness of your organisation. Not everything you do qualifies as an important business service, and trying to set tolerances for every activity dilutes focus and resources.
For each important business service, consider what would constitute intolerable harm. This requires thinking about different types of impact including financial harm to customers, inability to access essential services, data loss or exposure, and broader market effects. Different stakeholders may have different perspectives on what constitutes intolerable harm.
Time is typically the primary dimension for impact tolerances. How long can a service be unavailable before harm becomes unacceptable? The answer varies significantly across different services and different types of disruption. A payment processing service may have very short tolerances measured in hours, while a monthly reporting service might tolerate days of disruption.
Mapping Tolerances to Important Business Services
Each important business service needs its own impact tolerance, calibrated to the specific harms that would arise from its disruption. This mapping exercise requires understanding both the service itself and the broader context in which it operates.
Consider the dependencies that underpin each service. A service might be disrupted because of technology failure, supplier problems, loss of premises, or unavailability of key people. Your impact tolerance must be achievable regardless of which dependency fails.
Examine the resources required to deliver the service. Technology systems, data, people, premises, and third-party relationships all contribute to service delivery. For each resource, consider whether you could continue operating within tolerance if that resource became unavailable.
Document the mapping clearly. Regulators expect to see evidence that you understand how your important business services depend on underlying resources and how you would maintain service delivery within tolerance if any of those resources failed.
Monitoring and Reporting Against Tolerances
Setting impact tolerances is only the beginning. Organisations must also monitor their performance against tolerances and report breaches appropriately. This requires establishing metrics, building monitoring capabilities, and creating escalation processes.
Lead indicators can provide early warning of potential tolerance breaches. Rather than waiting until a service fails, monitoring trends in system performance, third-party delivery, and other factors can highlight emerging risks before they materialise.
When tolerance breaches occur, having clear reporting channels ensures appropriate visibility and response. Regulators expect boards to receive regular information about operational resilience performance including any actual or near-miss tolerance breaches.
Periodic testing validates that you can actually operate within tolerance during disruption scenarios. This testing should cover a range of severe but plausible scenarios and should demonstrate not just that recovery is theoretically possible, but that it can be achieved in practice with the resources and capabilities currently available.
Building Organisational Capability
Impact tolerances work best when they are embedded into organisational decision-making rather than treated as a compliance exercise. This means connecting tolerance requirements to investment decisions, change management processes, and risk appetite frameworks.
When considering new initiatives or changes to existing services, assess whether the proposed change would affect your ability to operate within tolerance. Changes that would increase recovery times or create new dependencies need scrutiny to ensure tolerances remain achievable.
Third-party management becomes particularly important in this context. Many important business services depend on suppliers and partners. Your contracts and oversight arrangements should ensure that third parties support your ability to operate within tolerance.
Getting Expert Support
Developing and implementing an effective impact tolerance framework requires specialist knowledge and practical experience. Our Certified Operational Resilience Manager training provides comprehensive coverage of regulatory requirements and practical approaches to building operational resilience capabilities. For organisations seeking tailored guidance, our consulting services can help you develop impact tolerances that satisfy regulatory expectations while driving genuine improvements in resilience.
Impact tolerances represent a significant evolution in how organisations think about and manage operational resilience. Getting them right requires investment in understanding, capability building, and ongoing monitoring. The organisations that embrace this challenge will find themselves better prepared for disruption and better positioned to maintain stakeholder confidence when incidents occur.
Related services
More insights
Keep reading.
Related thinking from the Oakwood team.
Operational resilience: what 'beyond March 2025' actually looks like
The FCA's transitional period has closed. The interesting question now isn't whether you're compliant — it's whether the framework you built is doing any real work.
Supply chain resilience: five lessons from a disruptive 2025
From Red Sea disruption to concentrated cloud outages, last year was an unusually clean test of how resilient your suppliers really are. The results were not flattering.
Why most business continuity plans fail under pressure
The plan is rarely the problem. The problem is the gap between the document and the organisation's ability to operate it.
