An impact tolerance is not an RTO in disguise
One looks at harm suffered by the client; the other at the organisation's capability. Conflating them empties the exercise of meaning.
Two objects, two directions of gaze
The RTO is an internal commitment: "we will return this system to service within four hours." It looks inward, and it is necessarily constrained by what the organisation can do.
Impact tolerance is an external limit: "beyond six hours of disruption to this service, the harm caused to our clients becomes intolerable." It looks outward, and it is set regardless of feasibility.
Three practical consequences follow.
First consequence: the gap is information, not a problem
If tolerance is six hours and measured capability nine hours, the three-hour gap must not lead to raising the tolerance. It must be declared as a vulnerability in the self-assessment, with a dated remediation plan.
Aligning tolerance with current capability empties the exercise of meaning, and is spotted with one question: "how did you determine that number?" If the answer mentions technical capability, the supervisor knows the tolerance was not set from the client's viewpoint.
Second consequence: meeting every RTO guarantees nothing
An organisation can meet each of its RTOs and still breach its tolerance. It suffices for the end-to-end chain to have five four-hour links — none is in default, and the service is down for twenty hours.
That is precisely why end-to-end mapping precedes testing: without it, you measure components, not a service.
Third consequence: the client does not measure what you measure
A service can be technically restored and still be unavailable from the client's viewpoint, because the accumulated backlog takes eight hours to clear. Tolerance concerns the real experience, not the timestamp of service restoration.
That is also why sizing the degraded mode must include the catch-up load: recovery at fifty per cent of production takes eight hours to absorb four hours of backlog.
The signal the supervisor looks for
An annual self-assessment declaring that no tested scenario breached tolerance is not a sign of maturity. The UK regulator explicitly expects some severe but plausible scenarios to cause a breach: that breach is what identifies the vulnerabilities to address.
A tolerance tests never cross is either too wide or backed by scenarios that are too weak. Either way the exercise teaches nothing — and it shows immediately in the year-on-year comparison.