Impact tolerances are a business decision, not a technical one
An impact tolerance answers a different question: at what point does disruption to this service cause harm the organization is unwilling to accept — to customers, to the market, to the public? That is a judgment for executives and the board, informed by operations rather than delegated to them.
Why the distinction matters
Once the tolerance is set from the business side, the gap between it and current capability becomes visible, quantifiable, and fundable. Before that, it is invisible — because the target was quietly reverse-engineered from what the organization already does.
This is also what makes the number defensible to a regulator. A tolerance derived from customer harm can be explained. A tolerance derived from current recovery capability explains nothing except that the organization measured itself against itself.
A target reverse-engineered from current capability will always be met, and will never tell you anything.
Setting one
Start with the service, not the system. Ask what happens to the customer at one hour, four hours, one day, one week. Find the point where the answer stops being inconvenience and starts being harm. That point is the tolerance, and it belongs to the executive who owns the service.