Close Menu
  • Home
  • Managing resilience
    • AI resilience
    • Business continuity
    • Business resilience
    • Climate resilience
    • C-suite and the board
    • DORA – the EU Digital Operational Resilience Act
    • Operational resilience
    • Organizational resilience
    • Supply chain resilience
    • Technology
  • Risk
    • Enterprise risk management
    • Operational risk
    • Threatscape
  • Cyber resilience
    • Cyber resilience updates
    • DORA – the EU Digital Operational Resilience Act
    • Product updates
More items
  • All News
  • Research
  • Jobs in Resilience
  • Resilience Resources
  • About Resilience Forward
X (Twitter) LinkedIn
  • Home
  • Managing resilience
    • AI resilience
    • Business continuity
    • Business resilience
    • Climate resilience
    • C-suite and the board
    • DORA – the EU Digital Operational Resilience Act
    • Operational resilience
    • Organizational resilience
    • Supply chain resilience
    • Technology
  • Risk
    • Enterprise risk management
    • Operational risk
    • Threatscape
  • Cyber resilience
    • Cyber resilience updates
    • DORA – the EU Digital Operational Resilience Act
    • Product updates
Login
LinkedIn Bluesky
Resilience Forward
Subscribe Now
  • All News
  • Research
  • Jobs in Resilience
  • Resilience Resources
  • About Resilience Forward
Resilience Forward
You are at:Home»Managing resilience»Operational resilience»Developing and managing impact tolerances (Page 6)
Operational resilience

Developing and managing impact tolerances

Identifying impact tolerances for important business services is one of the main ingredients for developing an operational resilience management system in any type of organization. In this article by Dr. Alberto G. Alexander, the process of identifying impact tolerances is presented and some guidelines for managing the impact tolerances in an organization are described.
February 15, 20249 Mins Read
Three executives meet to develop impact tolerances for their organization.

Operational resilience, as a concept, is receiving a lot of attention. A combination of COVID, increased concern over the intensification, likelihood, and magnitude of major shocks, and the attention given to operational resilience by financial services regulators has placed it firmly on the corporate agenda.

Resilience derives from the Latin word ‘resilire’, which means to recoll or rebound. Operational resilience is considered “the ability of an organization to absorb and adapt in a changing environment,” (Alexander, 2023). It is considered an organizational trait that allows it to carry out its mission or business despite the presence of operational stress and disruption.

Operational resilience is considered to be the organization’s ability to handle and control external factors that may hinder it from functioning.

Turning to the financial services world, it is defined as “the ability of a bank to deliver critical operations through disruption,” (Bank of England Prudential Regulation Authority, 2022).

In the following the key components of operational resilience will be described, the steps for determining impact tolerances will be presented and, finally, some guidelines for monitoring impact tolerances will be discussed.

Key components of operational resilience

In figure one the key components of operational resilience are depicted. These five actions (prevention, robustness, recovery, adaption, and learning) have to be part of the company’s values and principles which are used on a continuous process within the organization: “They have to permeate through the company’s organizational culture,”  (Alexander, 2023).

Figure one: key components of operational resilience.
Figure one: key components of operational resilience.

How to define and set impact tolerances

Once the strategic level in the organization has decided to implement an operational resilience management system, they should follow a methodological approach which will allow the organization to move forward in an effective and efficient way.

The first step is the identification of key business services. Organizations must define their most important products and services and then the impact tolerances for each.

Impact tolerances are very important metrics that define the point (in time, money, or other impacts) at which the consequences of a disruption become intolerable.

For example: “Impact tolerances could include the amount of revenue or customers the company is prepared to lose, or transactions that could go unfulfilled during a disruption. For an airline, an impact tolerance might be cancelled flights. For a healthcare entity the impact tolerance might be untreated patients,” (Aztek, 2022). It’s up to each organization to determine the impacts that they can tolerate from a disruption.

The setting of impact tolerances includes four defined steps:

Identify key business services

A prerequisite to starting work on impact tolerances is to identify, at an organizational level, at least one important business service. A methodological way to approach this would be to identify the full universe of business services that an organization delivers to its customers and then use clear criteria to shortlist those which are ‘important’. It is very important to be clear what an important business service is. An “important business service is an outcome the organization delivers, which if disrupted, could cause catastrophic consequences for the market, organization and /or the most vulnerable customers,” (Griffith, 2023). The impact tolerance for an important business service is the maximum tolerable level of disruption (MTLD), developed in consideration with the maximum duration of a disruption.

An important business service means a service provided by a firm to an external end user, where a disruption to the provision of the service could cause intolerable harm to consumers or market participants; harm market integrity; threaten policyholder protection, safety and soundness, or financial stability.

A way to approach the identification of important business services is to ask the following question: “Does the absence of this business service…

  • Create market disruption with catastrophic consequences for other market participants and large groups of people?
  • Create catastrophic consequences and unacceptable harm to customers?
  • Potentially threaten the organization’s viability?

At this stage organizations should map all the resources and components needed to perform each service, including facilities, people, teams, equipment and infrastructure, IT applications, and internal and external service providers. The impact to the overall service needs to be considered if any one of these resources or components were removed or severely disrupted. When mapping services, time should be given to cross-referencing resources and components common to many services. This mapping will help to identify vulnerabilities in operations; and possibly help to address them. When addressing vulnerabilities, it’s essential not only to consider the importance of the services for which a vulnerability exists but also to consider whether a single vulnerability exists for many services.

By knowing what’s important, what’s vulnerable, and where disruption could cause the most harm or have the most widespread effect, investment priorities and strategic and tactical decisions can be taken.

Baseline data collection

Once an important business service has been selected and mapped out, the organization needs to establish what constitutes business as usual functioning for that business service. This involves considering possible metrics that can describe the typical functioning of the business service through measuring both outcomes and the resources to deliver the service (i.e. inputs). Agreeing a shortlist of appropriate metrics at this stage is key as they will form the basis on which impact tolerances will be set.

Set impact tolerances

Setting impact tolerances is an art! As discussed above, an impact tolerance should reflect the timeframe that the organization believes is the point in time following a disruption to an important business service that will likely result in intolerable impacts to customers, the broader market, or irrevocably threaten the organization’s viability.

The impact tolerance should specify that a particular important business service must not be disrupted beyond a certain period or point in time. Other relevant metrics, such as cost, regulatory breach, or client or service volumes, also need to be considered. Impact tolerances should also consider peak times or periods of increased activity where impact may become evident more quickly.

Both risk appetite and impact tolerance are essential in supporting the organization’s operational and financial resilience, but aligning impact tolerances to important business services will give a better indication of where investments need to be made. It will also help to determine which vulnerabilities need to be addressed to ensure the organization’s ability to continue to deliver within the impact tolerances despite – and throughout – a severe disruption.

Scenario testing

Testing is crucial to assess an organization’s impact tolerances and determine if its incident response is able to ensure that the organization can recover the business service within the impact tolerance that has been defined.

Testing also gives the organization a clear understanding of the ‘severe but plausible scenarios’ that it can use to exercise and measure its operational resilience capabilities.

The process of performing scenario testing is composed of five sequential steps:

Define scenarios: a range of realistic scenarios representing potential operational disruptions need to be identified. Several factors should be considered, such as cyber attacks, natural disasters, system failures, supply chain disruptions, and regulatory changes.

Assess impact: evaluate the potential impact of each scenario on important business services, systems, processes, and stakeholders. Consider financial, operational, reputational, and customer impacts.

Conduct testing: simulate each scenario and observe how the organization’s operational resilience measures and response plans perform as the scenario plays out. This may involve tabletop exercises, simulations, or real-time testing of specific systems or processes.

Evaluate responses: analyze the organization’s response to each scenario, including the effectiveness of incident management, communication, and recovery strategies. Identify strengths, weaknesses, and areas for improvement.

Document the lessons learned: document the lessons learned from each scenario test, including successful strategies, areas of improvement, and recommendations for enhancing operational resilience.

It’s very important to keep in mind that, however the scenario gets tested, the objective is not to assess whether crisis or business continuity plans are effective (though that might also be assessed); it’s to determine whether impact tolerances can be achieved. It could be found that for some severe but plausible scenarios, the recovery time objective of those plans cannot be achieved, but impact tolerance can.

Impact tolerances and the board

The responsibility for the implementation and control of operational resilience in the company is at the corporate level: ownership sits with the board and senior management.

Boards are specifically required to approve the important business services identified for their firm and the impact tolerances that have been set for each of these. In delivering this responsibility, boards must regularly review assessments of the organization’s important business services, impact tolerances, and the scenario analyses of its ability to remain within the impact tolerance for these important business services.

An organization’s board has the ultimate responsibility for the approval and oversight of the operational resilience framework. Leadership from the top down should ensure that resilience is intrinsically built into an organization’s strategic decisions, allowing boards to prioritize activities and target investment towards making critical or important business services more resilient. A top-down approach to operational resilience creates a uniform process flow and enhances clarity on responsibilities throughout the organization. This enables the organization to conduct business within its approved impact tolerances.

The criteria for the identification of critical or important business services should be reviewed and approved by the board annually or at the time of implementing material changes to the business  – where additional critical or important business services could be introduced.

A board should review and approve impact tolerances at least annually, or when a disruption occurs, to determine whether the original approved impact tolerances are still fit for purpose.

An organization’s board should review the results of all scenario testing carried out on critical or important business services. If scenario testing identifies a situation where impact tolerances may be breached then it would be the responsibility of the board and senior management to take action to improve the resilience of the business service and focus investment where needed.

The author

Dr. Alberto G. Alexander holds a Ph.D  from The University of Kansas and a M.A. from Northern Michigan University. He is a MBCI, BCMS IRCA Lead Auditor and Approved Tutor. He is the managing director of the international consulting and managerial training firm: Eficiencia Gerencial y Productividad SAC, located in Lima, Peru. He can be contacted at: alexander@egpsac.com  He is currently Professor at the Graduate Business School of ESAN University, Lima, Peru.


References

  • Alexander, G. Alberto. Managing Operational Resilience Resilienceforward.com, Nov 2023.
  • K. Scott Griffith. The Leaders Guide to Managing Risk: a Proven Method to Build Resilience and Reliability. Harper Collins, Nov 2023.
  • AZTEC Group. Building Resilience: The key to the Continuity and Long-Term Success of your Business. 2022.
  • Bank of England Prudential Regulation Authority, 2022.
Africa Asia Asia Pacific Australasia Europe Middle East North America UK
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email WhatsApp
Previous ArticleRiskonnect announces gen AI-powered enhancements to its Business Continuity & Resilience solution
Next Article AI and cyber risk: how are insurers addressing the threat and resilience landscape?

Related Posts

An exploding digital padlock illustrates the requirement for post-quantum cryptography.

Research breakthrough brings reliable quantum computers and Q-day closer to reality

September 10, 2026
A danger sign on a digital background.

New blob URL phishing technique evades detection by using legitimate Microsoft services

September 10, 2026
AI risks

Unmanaged AI workflows expose EMEA organizations to rising compliance and data risks

September 9, 2026
City skyline at sunset with bright light trails and a translucent blue smart-city grid overlay and GPS pins indicating locations.

AI world models: future possibilities for organizational resilience?

September 7, 2026
DRJ and BCI logos

DRJ and BCI publish guidance for governing, managing, and using AI in resilience

September 7, 2026
Decision making with over whelming information.

AI can find the vulnerability. Accountability still sits with your crisis leadership

September 7, 2026
Advertisement
Resilience First
This week's most read articles
Under pressure: An egg cracking under pressure applied by squeezing clamps form the sides.

Managing scenario testing for operational resilience

May 16, 2024
COSO logo

New COSO ERM guidance aims to help organizations with practical implementation

May 12, 2026
Close-up of a green-brown iris peering through a jagged tear in dark paper or wall material.

The blind spots in business continuity

September 2, 2026
Latest resources
Graphic showing a range of risks from green to red grades.

2026 update to the UK National Risk Register published

July 15, 2026
Load More

Subscribe to Updates

Get our Resilience Updates newsletter.

Most Popular Feature Articles
Three dark coloured light bulbs on a black background illustrate the concept of The Dark Triad in Crisis Management.

The Dark Triad in crisis management

Five stage crisis management framework

A five stage framework for a crisis management process

Blue interconnected gears and network nodes symbolizing automation and complex machinery.

Agent zero – the 2028 digital pandemic

Latest Reports
A futuristic red warning alert icon with glowing exclamation mark.

Cloud Security Alliance publishes Hugging Face Incident Initial Post-Mortem

A person hold a building door open for a person behind who is tailgating to get unauthorised access.

Security Culture: A Strategic Capability That Builds Resilience in a Volatile World

An identity icon with a map marker on it, indicating the concept of identity as a target for attackers. The icon is on a generic IT background predominantly in black and orange.

Identity-based approaches dominate initial access for ransomware attacks

A promo box for an article about resilience governance.
© 2026 Resilience Forward
  • About Resilience Forward
  • Newsletter
  • Newsfeed
  • Advertise
  • Call for Papers
  • Contact
  • Privacy Policy and Cookie Use
  • AI Use Policy

Type above and press Enter to search. Press Esc to cancel.

Manage Cookie Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Manage Cookie Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Ad Blocker Enabled!
Ad Blocker Enabled!
Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.

Sign In or Register

Welcome Back!

Login to your account below.

Lost password?