In today’s bulletin, Charlie revisits how organisations can define their Maximum Tolerable Period of Disruption (MTPD) and gives an insight into its importance within our organisations.
This week, I have been writing procedures for Databarracks on how we deliver a number of business continuity items. We are moving from delivering one-off business continuity assignments to providing clients with a business continuity managed service. This requires us to change the way we work. Instead of handing over business continuity items at the end of a project, we are responsible for managing the items ourselves. I have been working on our approach to the analysis stage of business continuity. I have noticed that LinkedIn seems full of a new generation of business continuity practitioners, many of whom are writing posts defining elements of business continuity, often accompanied by AI-generated infographics. These frequently cover basic terms such as MTPD or MBCO, as well as newer concepts such as Minimum Viable Company (MVC).
So for this week’s bulletin, I thought I would go back to basics and give my definition of how to determine an MTPD. I am interested in any comments on this and whether people do it differently.
The Importance of the MTPD
For me, one of the most important parts of business continuity is determining an organisation’s Recovery Time Objective (RTO). Get these wrong and recovery can fail because the RTOs for key activities are too long. If they are too short, the organisation is probably wasting money by providing strategies and solutions that are not required. If we agree that RTOs are one of the key building blocks of business continuity recovery planning, the MTPD is critical in determining the RTO. There should be a direct relationship between the MTPD and the RTO, so determining the MTPD across an organisation correctly is essential.
The term is not actually used within ISO 22301:2019, because ISO standards try to avoid industry-specific terms, but the concept is defined as: “The time frame within which the impacts of not resuming activities would become unacceptable to the organisation.” The Good Practice Guidelines reference the ISO 22301 definition, but explicitly use the term MTPD.

MTPD is the point in time at which the impact of an activity being unavailable becomes unacceptable to the organisation and crosses the red line shown in Figure 1.
Figure 1 shows this basic concept. Time is shown along the horizontal axis and the impact on the organisation is shown on the vertical axis. The red dashed line represents the organisation’s unacceptable impact threshold. The first part of determining an RTO is to define what is unacceptable.
Determining Impact Types
The MTPD is not simply the longest period a manager would prefer to operate without their activity, nor is it necessarily the point at which the entire organisation would collapse or become financially unviable, it is the point at which the consequences of the disruption exceed a threshold that the organisation has agreed it is not prepared to tolerate.
Before asking activity owners to estimate their MTPDs, the organisation should agree the types of impact to be considered and the impact types should be relevant to the organisation. A hospital may give particular weight to patient safety, while a financial services organisation may focus on regulatory obligations, customer outcomes, and financial market deadlines. A government organisation may be particularly concerned about its ability to deliver essential public services.
Possible impact types could include:
- Financial – Financial consequences that could threaten the organisation’s performance or viability, such as loss of revenue, additional costs, fines, penalties, or cash-flow problems. This could also include the amount of money that, if lost, could make the organisation unviable.
- Customer/service – The impact on customers or service users, including an inability to provide an expected service, loss of customers, complaints, or difficulty attracting new customers.
- Reputation and stakeholder confidence – Damage to the organisation’s reputation or loss of confidence among customers, investors, partners, employees, regulators, or other important stakeholders.
- Regulatory compliance – Failure to meet regulatory requirements, potentially resulting in regulatory criticism, enforcement action, fines, restrictions, or loss of a licence to operate.
- Legal/contractual – Failure to meet legal or contractual obligations, including breach of contract, legal action, penalties, or termination of important contracts.
- Life, health and safety – The potential for disruption to result in injury, ill health, or loss of life, affecting employees, customers, service users or members of the public.
- Environmental – The potential for disruption to cause significant environmental harm, such as pollution, contamination, uncontrolled releases, or other lasting environmental damage.
- Delivery of critical products/services – The inability to continue delivering a product or service that is essential to customers, service users, the community, or the organisation’s continued operation.
There is no benefit in including impact types that are not relevant to the organisation. The criteria should be tailored to its particular objectives, responsibilities, stakeholders, and operating environment.
Top management should determine the impact types, I usually hold a workshop with them to identify the organisation’s impact types. Obtaining the impact types from top management prevents each person interviewed during the BIA process from having their own definition of what is unacceptable. There should normally be between three and five impact types, having too many may result in every impact being considered unacceptable.
Where possible, the threshold should be described in clear and measurable terms. A financial threshold might be expressed as a monetary amount. A regulatory threshold might relate to formal censure, a significant fine, or the possible loss of an operating licence.
Other impacts will be more difficult to quantify. Reputation is a good example – the consequences of an incident will depend on the circumstances, stakeholder reaction, and the level of media attention. The aim is therefore not to create an apparently precise calculation, but to establish a consistent and credible description of the point at which the impact would become unacceptable.
The thresholds should reflect the organisation’s objectives, legal, and regulatory obligations, risk appetite, culture, and stakeholder expectations. This prevents each activity owner from using their own personal definition of “unacceptable”.
Now that we have the organisation’s definition of unacceptable impacts, we can see that different activities will take different lengths of time to reach an unacceptable level.

Figure 2 shows three different activities, A, B and C, and how their impacts reach the unacceptable threshold at different times. Activity A has a rapidly increasing impact and crosses the unacceptable impact threshold first. It might be a call centre receiving customer orders or an activity involved in making urgent payments.The impact of Activity B develops more gradually, but it eventually crosses the unacceptable threshold. Activity C has the slowest-developing impact, its impact has not yet become unacceptable during the period shown on the diagram.
Agreeing the Unacceptable Time Frame
There is rarely a precise moment when an organisation moves from an acceptable to an unacceptable position.
It is often impossible to say that an impact becomes unacceptable after exactly 17 hours or 23 days. The MTPD is an estimate, and excessive precision can make the result appear more certain than it really is. Take reputation as an example. On a slow news day, an incident affecting an organisation may become the main news story. Its stakeholders may quickly become aware of the incident and its reputation may be damaged. If a major news story is dominating the media, the same incident may receive little coverage because everyone’s attention is focused elsewhere. Its impact may therefore take longer to be felt and noticed. Determining when an impact becomes unacceptable and reaches the impact threshold is not a precise science.
For this reason, I recommend using a set of time bands. The time bands should reflect the speed at which impacts are likely to develop within the organisation.
An office-based organisation might use:
- 0–24 hours
- 24 hours–3 days
- 3 days–1 week
- 1 week–1 month
- More than 1 month
A hospital, utility or another organisation operating continuously may need shorter bands at the start of the scale, such as:
- Less than 15 minutes
- 15 minutes–1 hour
- 1–4 hours
- 4–24 hours
- 1–3 days
- 3 days–1 week
- More than 1 week
The time bands should be sufficiently detailed to distinguish between activities, but not so detailed that they create a false impression of accuracy. The BCI’s Good Practice Guidelines Edition 7.0 similarly advises that time ranges should not be broken down too finely.
Figure 3 shows that, by using a series of time bands, we can estimate the band within which the impact becomes unacceptable, while acknowledging that there may be some variation in when this occurs.

Using time bands acknowledges that the MTPD is an estimate, while still allowing the organisation to distinguish between activities whose impacts develop at different speeds. The lower boundary of the time band is the earliest point at which the MTPD could be reached.
Defining the Activities
Before assessing the impact, make sure that the activities across the organisation are clearly defined.
An activity should have a recognisable output. Examples might include:
- Answering customer calls
- Processing payments
- Raising invoices
- Dispatching customer orders
- Providing patient care
- Completing regulatory reports
If an activity is defined too broadly, different parts of the same activity may have different MTPDs. If it is defined too narrowly, the BIA may produce hundreds of small activities that are difficult to analyse and use. The activity owner should understand what is included in the activity, what it produces and which products, services or processes it supports.
How to Determine the MTPD
For each activity, consider what would happen if the entire activity became unavailable. The assessment should not be based on one particular disruption scenario. For example, one activity owner should not assume a short IT outage while another assumes the complete destruction of their workplace. Using different scenarios would make the results inconsistent.
Instead, ask: If this activity became completely unavailable or stopped entirely, how would the impact on the organisation develop over time?
Although the BIA should be scenario-independent, the assessment should consider whether the disruption happens at the worst reasonable time for the organisation. This might be during a seasonal peak, immediately before a regulatory deadline, or during an important financial processing period.
It is important to assess the impact against all the agreed impact types. The MTPD is determined by the first impact to become unacceptable. For example, the financial consequences may remain tolerable for two weeks, but a regulatory breach may become unacceptable after three days. In this case, the activity’s MTPD would be three days.
Record the Reason for the MTPD
The MTPD should never be recorded as a time without an explanation. For each activity, the BIA should record:
- The agreed MTPD time band
- The impact that becomes unacceptable first
- Why that impact becomes unacceptable
- Any important deadlines, peak periods or assumptions
- The activity owner who validated the information
For example:
If the activity is unavailable for more than three days, customer payments cannot be processed. This would cause a breach of regulatory requirements, significant customer harm, and the rapid accumulation of a backlog that could not be cleared within the required period. The MTPD is therefore between one and three days.
Recording the justification makes it possible to challenge, review, and update the MTPD. It also prevents the organisation from being left with a spreadsheet containing unexplained times that nobody can understand several months later.
Challenge and Compare the Results
Once the initial MTPDs have been collected, review them across the organisation.
Look for:
- Similar activities with very different MTPDs
- MTPDs that appear to reflect the importance of a manager rather than the impact of disruption
- Activities with short MTPDs but little supporting justification
- Different interpretations of the impact thresholds
- Activities supporting the same product or service but with conflicting times
- Important dependencies that have not been considered
- Large numbers of activities placed in the shortest time band
It is quite common for activity owners to say that their activity cannot be unavailable for any length of time. The BIA interviewer’s role is to challenge this constructively, and ask what would actually happen over time. An activity may be important without being urgent. The MTPD is about how quickly the impact becomes unacceptable, not how valuable, busy, or prestigious the activity is during normal operations.
The MTPD Relationship with the RTO
The MTPD does not, by itself, provide the complete recovery sequence or determine the recovery solution. However, it gives us an essential indication of how quickly the impact of losing each activity becomes unacceptable and why different activities within the organisation should have different recovery timeframes.
Once we have determined the MTPDs for all the activities across the organisation, we can determine the RTOs. The RTO must always be shorter than the MTPD and should state the timeframe within which the activity is to be resumed at a specified minimum acceptable capacity. The setting of the RTO is a separate process and a subject for another bulletin!
Final Thoughts
Defining an MTPD is not an exact science. The purpose is not to predict the precise minute at which an organisation will suffer an unacceptable impact, it is to make a reasoned and consistent estimate using impact thresholds that matter to the organisation.
The key to producing credible MTPDs is consistency:
- Use the same impact types
- Use the same definitions of unacceptable impact
- Use the same time bands
- Assess the unavailability of the activity rather than different disruption scenarios
- Consider disruption at the worst reasonable operating time
- Record the reasons and assumptions behind every MTPD
- Compare and challenge the results across the organisation
If these steps are followed, the MTPD becomes a defensible business continuity requirement rather than a time selected according to personal opinion or internal politics.
This bulletin is a rewrite of my 2015 bulletin on how to determine your RTOs.



