The maximum tolerable period of disruption, often shortened to MTPD, is the length of time an activity can be unavailable before the resulting impacts become unacceptable to the organization. It is one of the central outputs of a business impact analysis, and it sets the outer limit for every recovery target that follows. Yet it is also one of the most misunderstood, because it is confused with recovery time objectives, and set by guesswork instead of evidence.
This guide explains what the maximum tolerable period of disruption means, how it relates to other continuity terms, how to determine it from impact data, how to check it against dependencies and how to record and review it.
What the maximum tolerable period of disruption means
Every activity that is stopped generates impacts that grow with time: lost revenue, missed obligations, customer harm, regulatory breaches, safety problems and damage to reputation. At some point those impacts cross a line that the organization cannot accept. The time to reach that line is the maximum tolerable period of disruption. ISO 22301:2019 expresses the idea in its business impact analysis requirement, which asks the organization to assess the impacts over time of not performing activities and to set prioritized time frames for resuming them within the time that impacts become unacceptable. You can view the standard on iso.org. Other terms, such as maximum acceptable outage and maximum tolerable downtime, are used for the same idea in different frameworks, so agree one term for your own documents and stick to it.
Free business impact analysis
How long can each activity really be down?
Rate the impact of an outage over time, set RTOs and maximum tolerable periods of disruption, map the people, systems and suppliers behind each activity, and get a recovery sequence back, free.
Run the free business impact analysis → or View premium report sample
The concept applies to activities, not to systems. A system has a recovery target derived from the activities that depend on it, and the target is set inside the tolerable period of the most demanding of them. Our guide to the ISO 22301 business impact analysis explains where this fits in the full method.
Maximum tolerable period of disruption compared with RTO and RPO
| Term | What it measures | Relationship |
|---|---|---|
| Maximum tolerable period of disruption | Time until impacts become unacceptable | The outer limit, set by the business |
| Recovery time objective | Target time to resume the activity or restore a system | Must be shorter than the tolerable period |
| Recovery point objective | Maximum acceptable data loss, measured in time | Set from the impact of lost data |
| Minimum business continuity objective | Level of service acceptable during disruption | Defines what recovery restores first |
The tolerable period is a limit you must not pass. The recovery time objective is the target you plan to meet, and it should leave a margin. If the tolerable period is two days, an objective of one day gives time for delays. An objective equal to the tolerable period leaves none. Our article on RTO and RPO covers the recovery targets in detail.
How to determine the maximum tolerable period of disruption
Work from impacts, not from opinion. For each prioritized activity, estimate the impact after intervals such as one hour, four hours, one day, three days, one week and two weeks, across categories such as financial, legal, customer, safety and reputation. The point at which a category first reaches your unacceptable level marks the tolerable period, and the shortest period across the categories is the one to use.
- Define impact categories and thresholds. Agree in advance what unacceptable means in each category, in figures where possible.
- Estimate impacts over time. Ask process owners for the effects after each interval, and use records such as past outages to check them.
- Identify the point of unacceptability. Find the first interval at which any category crosses its threshold.
- Consider peaks and calendars. An activity may tolerate a day off in a quiet week but not at month end or during a peak season.
- Record the reasoning. Note which impact category drove the result.
Our guide to financial impact in the business impact analysis explains how to put figures on the financial dimension, and the business impact analysis questionnaire guide shows how to ask the questions.
Account for time-varying impact
The tolerable period is often not a single number. A retailer may lose little during a Sunday night outage but a great deal on the Friday before a holiday. Record the worst-case value and note where the period varies, so that the plan protects the most demanding time. Where variation is large, consider setting different objectives for peak and off-peak periods.
Checking the period against dependencies
An activity can only be resumed within its tolerable period if everything it depends on can be too. Compare the period with the recovery times of the systems, suppliers, people and sites it relies on. If a supplier needs three days to recover and the activity’s tolerable period is two, you have a gap that no amount of internal effort will close. Our guide to business impact analysis dependencies shows how to build the map that makes this check possible.
Using the period to choose strategies and investment
Short tolerable periods justify significant investment in redundancy, replication and standby arrangements, while long ones may be met with cheaper options such as manual workarounds or restoration from backups. Use the tolerable period to sort activities into tiers, then match strategies to each tier. This keeps spending proportionate, and it gives leaders a rational basis for accepting that lower-priority activities will wait.
Validating and testing the figures
Numbers in a spreadsheet are only assumptions until they are tested. Challenge the figures in a workshop with senior managers, since owners often overstate how urgent their own activities are. Compare them against real incidents, customer contracts and regulatory limits. Then test that your recovery capability can meet the objectives inside them, through exercises. Our guide to the business continuity exercise explains how to run one, and the results should feed back into the analysis.
Communicating the figures
Share the approved figures with IT, procurement and suppliers in a simple table, so recovery teams design to the same limits the business accepted. Where a supplier contract promises a slower restoration than the business can tolerate, raise it at the next renewal, and record any interim workaround so that the gap is visible and owned rather than forgotten.
A short worked example
A payments processor analyzes its settlement activity. After one hour of outage the impact is minor. After four hours some merchants are unable to reconcile and complaints begin. After eight hours contractual service credits apply and a regulator expects notification. After one day the impact on customer funds availability becomes serious and the risk of regulatory action is high. The team sets the maximum tolerable period of disruption at eight hours, driven by the regulatory and contractual impact, and a recovery time objective of four hours to leave a margin. Its dependency check then shows that the database platform needs six hours to recover, so a replication upgrade is funded to close the gap.
Roles, records and review
Process owners propose the figures, the business continuity manager challenges them for consistency, and senior management approves them. Record the tolerable period, the impact category that drove it, the date, the approver and the evidence. Review the figures at least annually and when the business changes: new products, new contracts, new regulation, mergers and changes in seasonality. Keep the history so that you can see how the assumptions have moved.
Common mistakes with the maximum tolerable period of disruption
Organizations confuse it with the recovery time objective, set the same value for every activity, base it on what technology can deliver instead of what the business can bear, ignore peak periods, fail to check dependencies and leave the figures untested. Another is copying values from a template or another company. The number must reflect your own impacts, and the reasoning should be visible to anyone who reads the record.
Using a ready structure
If you want to avoid designing the forms yourself, the Business Impact Analysis Report and Workbook provides a structured report with impact scales, time-based ratings and recovery targets in a working register. You can also see the finished result in our business impact analysis example. Whatever tool you use, base the maximum tolerable period of disruption on evidence and revisit it regularly.
Maximum tolerable period of disruption FAQ
What is the maximum tolerable period of disruption?
It is the time an activity can be disrupted before the resulting impacts become unacceptable to the organization. It sets the outer limit for recovery objectives.
How is it different from RTO?
The recovery time objective is the target time to resume, while the tolerable period is the limit beyond which impacts are unacceptable. The objective must be shorter than the limit.
Does ISO 22301 use this term?
ISO 22301:2019 requires impacts over time to be assessed and prioritized time frames for resumption to be set within the time impacts become unacceptable. Terms such as MTPD and maximum acceptable outage are commonly used for this idea.
Who should approve the figures?
Process owners propose them, the business continuity manager challenges them and senior management approves them, so that the figures reflect the organization’s real tolerance for disruption.
How often should they be reviewed?
Review them at least annually and whenever the business, its contracts, its suppliers or the regulatory environment change materially.