Evidence
The business impact analysis, and why IT should not set the RTO
The most common continuity finding is an assumed recovery time — a number technology chose without asking the people who bear the consequences.
Facts checked — 2026-09-11
Who should set the RTO and RPO?
A business impact analysis identifies which activities deliver your products and services, what they depend on, and what happens as each hour of disruption passes. From that come the recovery time objective — how quickly an activity must resume — and the recovery point objective, how much data loss is tolerable.
Both belong to the activity owner, not to IT. Finance can say what four hours of an unavailable billing system costs; the infrastructure team can only say what it would take to restore it in four hours. Confusing those two is how organisations end up with expensive resilience nobody asked for and gaps nobody noticed.
The bottom line
Get the RTO and RPO signed by the person who owns the activity. An IT-set recovery objective is an assumption, and auditors treat it as one.
Related services
ISO 22301 — Business Continuity Management
Know which activities cannot stop, how long they can be down, and what you will actually do — tested before you need it.
Related insights
Evidence
Running an internal audit that is worth the day it costs
Its job is to find things before the external auditor does, not to pass.
Evidence
Corrective action is not the same as fixing it
A fix addresses the instance. Corrective action addresses why it happened.
Evidence
Evidence that collects itself
If producing evidence is a separate task, it will be skipped in a busy quarter.