The foundation decisions
Setting impact tolerances that survive supervision
Everything else in the operational resilience regime hangs off two decisions: which of your services are important business services, and how much disruption each can bear before harm becomes intolerable. Get them right and mapping, testing and the self-assessment all have something to stand on. This guide works through both decisions, with worked example statements and the criticism supervisors keep repeating.
First principles
What is an impact tolerance?
An impact tolerance is the maximum level of disruption a firm has decided an important business service can bear before the harm becomes intolerable. It is expressed with a metric, usually time plus at least one other measure, and it marks the line recovery must never cross rather than a target to aim at.
The distinction from risk appetite matters. Appetite is a statement about how much likelihood of disruption you will accept. A tolerance assumes the disruption has already happened and asks a harder question: how long, and at what scale, before the damage stops being recoverable? The rules require firms to set tolerances on the assumption that severe disruption will occur, which is what makes them useful.
Dual-regulated firms answer to two lenses. The FCA asks the tolerance to protect consumers and market integrity; the PRA asks it to protect the firm's safety and soundness, and policyholders where the firm is an insurer. The same service can carry two tolerances as a result. Where the wider regime is unfamiliar, the FCA operational resilience guide covers scope and expectations end to end.
Services, not systems
Identifying important business services
An important business service is a service the firm provides to external clients or market participants whose disruption could cause intolerable harm to consumers, or damage market integrity, safety and soundness, or financial stability. The test is that somebody outside the firm consumes it.
The discipline that separates good lists from poor ones is service, not system. Making payments, accessing funds, settling claims and executing orders are services. The core banking platform, the data centre and the operations department are resources that services depend on, and they belong in the mapping. If your candidate list reads like an application inventory, the exercise started in the wrong place.
Work the reasoning from the customer's chair. Take a payments firm: "client money processing" is too broad to carry one tolerance, because a customer whose outbound payment is stuck experiences a different harm, on a different clock, from a customer who cannot see their balance. Split candidates until each has a single harm story that one tolerance can honour, and stop splitting before the list stops being governable.
Record the exclusions alongside the inclusions. The service you decided was not important, and why, is evidence the exercise was real, and it is one of the first things a reviewer of your self-assessment looks for.
Where the line goes
Setting the tolerance: metrics that mean something
Start from where harm begins, not from where your recovery capability currently sits. The sequence that stands up is: establish the point at which disruption becomes intolerable for the people the service exists for, evidence that judgement, and only then compare it with what the firm can achieve today. Any gap between the two is the work of the resilience programme, and hiding the gap by moving the tolerance defeats the entire regime.
Time is the primary metric and is rarely sufficient on its own. Pair the clock with measures that track how harm actually accumulates: the value of payments delayed, the number of customers affected, the volume of data that cannot be recovered. A time-only tolerance treats an outage at 3am on a Sunday and an outage at month-end as the same event.
Dual-regulated firms should draft the FCA-facing and PRA-facing statements separately where the lenses diverge, consumer harm and market integrity on one side, safety and soundness on the other, then check the pair is coherent. The tolerances also set the bar for the scenario testing that follows: a test is only meaningful if the scenario is capable of threatening the line you drew.
The shape of a statement
Worked example tolerance statements
Three illustrative statements, drafted for fictional firms to show the shape. The numbers are inventions; yours must come out of your own harm analysis, not out of anyone's template.
Outbound client payments
Illustrative, a payments firm
"Following disruption, outbound client payments resume within four hours. At no point does the aggregate value of delayed client payments exceed £5m, and no payment flagged as time-critical is delayed beyond the same business day."
Why it is built this way: Time alone would hide the difference between a quiet afternoon and a peak day, so the tolerance pairs a clock with a value cap and a carve-out for the payments where harm is immediate.
Online account access
Illustrative, a retail bank
"Customers regain the ability to view balances and move money between their own accounts within 24 hours of disruption. A telephone route for customers in financial difficulty is operating within two hours."
Why it is built this way: The headline tolerance reflects when inconvenience becomes harm for the general population; the second metric recognises that harm arrives much faster for some customers than others.
Claims payment
Illustrative, a general insurer
"Approved claims payments resume within 48 hours of disruption, and no claimant recorded as vulnerable waits more than 72 hours for an approved payment. A separate PRA-facing tolerance for the same service is framed around safety and soundness rather than individual policyholder harm."
Why it is built this way: A dual-regulated firm may need two statements for one service, because the two regulators ask the tolerance to protect different things.
The criticism supervisors keep repeating
The FCA's March 2026 observations on the regime called out tolerances set at the level firms could already achieve rather than at the point harm begins: current capability dressed up as analysis. Other patterns that draw questions in our experience include time-only metrics, tolerances quietly treated as recovery targets, and statements with no visible harm reasoning behind the number. Each is fixable, and each is far cheaper to fix before a supervisory conversation than during one.
The impact tolerance statement template, free
The statement structure used in the examples above, with the metric and justification fields laid out per service. It lives in the resources library alongside the other templates, and there is no gate in front of it.
Done in a room, properly
The tolerance workshop, inside the Resilience Framework
Tolerances set by one person at a desk rarely survive contact with the board, let alone the regulator. The workshop puts the people who own the services in one room and gets the decisions made and defended there: we prepare beforehand by reviewing your service inventory, any existing statements and the harm analysis behind them, then facilitate a one-day session that works each service through identification, harm reasoning and metric setting.
You end with documented tolerance statements carrying the justification a supervisor will look for, ready to drop into your self-assessment and to set the severity bar for your next round of scenario testing.
The workshop is delivered as part of the Resilience Framework service, from £17,500, published on the pricing page with all our other services, so the cost is known before the first conversation.
Quick answers
Impact tolerance questions, answered
What are impact tolerances?
An impact tolerance is the maximum level of disruption a firm has decided an important business service can bear before the harm to consumers or to market integrity becomes intolerable. It is set on the assumption the disruption has already happened, expressed with a metric (usually time plus at least one other measure) and it marks the line recovery must never cross, not a target to aim at.
What is an important business service?
A service the firm provides to external clients or market participants whose disruption could cause intolerable harm to consumers, or damage market integrity, the firm's safety and soundness, or financial stability. The defining test is that somebody outside the firm consumes it: making a payment, accessing funds, having a claim paid. Internal functions and technology platforms support important business services, but they are not themselves the service.
How many impact tolerances should we have?
At least one per important business service, and dual-regulated firms may carry two for the same service where the FCA and PRA lenses diverge. The real question is how many important business services you have, and the answer is as many as the business genuinely runs, which for most firms is a handful. A list of thirty is not governable and suggests the exercise counted systems; a list of one is rarely believable for a firm of any breadth.
Tolerances with a defence
Set tolerances a supervisor will accept
Draft your own statements with the free template and worked examples, or book the fixed-fee workshop and leave the room with documented tolerances and the justification behind every number.