All resources
Playbook 6 min read

MTPD, RTO, RPO: the three numbers at the heart of a BIA

C1The Compliance One team25 August 2026

A Business Impact Analysis sounds intimidating. Strip it back and it's really an exercise in setting three numbers for each activity that matters — and once you understand them, the whole of ISO 22301 Clause 8 clicks into place.

MTPD — Maximum Tolerable Period of Disruption

The longest an activity can be down before the damage becomes unacceptable — regulatory breach, contracts lost, safety at risk, the business genuinely threatened. It's the ceiling. If your payment processing has an MTPD of 24 hours, then at hour 25 you're in territory the business can't absorb. MTPD is a business judgement, not a technical one: you're deciding how much pain is too much.

RTO — Recovery Time Objective

Your target to get the activity back, at a minimum acceptable capacity, and it must be shorter than the MTPD — that gap is your safety margin. If MTPD is 24 hours, an RTO of 8 hours leaves room for things to go wrong. The RTO is what your continuity strategy has to actually deliver, so it's the number that drives spend: a four-hour RTO buys very different infrastructure than a three-day one.

RPO — Recovery Point Objective

How much data you can afford to lose, measured in time. An RPO of one hour means that after an incident you can lose at most the last hour of data — which dictates how often you back up or replicate. RTO is about downtime; RPO is about data loss. They're independent: you can be back online fast (low RTO) but have lost a day of data (high RPO), or vice versa.

How they fit together

  • MTPD is the deadline you must never miss.
  • RTO is the target you set inside it — the promise your strategy has to keep.
  • RPO is the data-loss limit that sets your backup and replication cadence.
  • Set them per activity, not org-wide — your public marketing site and your core transaction ledger do not deserve the same numbers.

Setting them without the pain

In Compliance One, the BIA register captures all three for every activity alongside its dependencies, resources and priority — so the numbers live in a sortable table you can act on, not buried in a document. Sort by RTO and you instantly see what needs the most resilient (and expensive) treatment. That ranked list is the input to every continuity strategy decision you'll make.

See it on your own frameworks

Book a 30-minute walkthrough and we'll map this to your environment.