---
sourceDocument: Xanadu Governance, Risk, and Compliance
sourceDocumentLink: https://www.servicenow.com/docs/r/xanadu/governance-risk-compliance

 Release :

    - xanadu

ft:locale :

    - en-US

ft:publication_title :

    - Xanadu Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# RTO, RPO, and recovery tiers

# RTO, RPO, and recovery tiers {#ariaid-title1}

* Release version: Xanadu
* 
* Updated July 31, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 3 minutes to read

Due to unforeseen disruptive events, the business processes in your organization can face a downtime. It is important to classify your business processes in the recovery tiers and calculate the amount of time and amount of data
loss that your organization can handle without significant effect on the operations.

## Recovery time objective {#rto-rpo-recovery-tiers__section_gq2_cdt_pxb}

Recovery time objective (RTO) is the maximum amount of time a computer, system, network, or application takes to recover after an outage event or data loss without causing much effect to your business operations.

The business users and IT owners can perform business impact analysis and technical impact analysis respectively by responding to the assessment in the BIA component in the BCM UIB Workspace. A sample view of the Assessments tab is shown in the following example.

If you are the business user, you can estimate the recovery time objective for your business services and processes by responding to the Recovery time objective assessment in the Assessments tab. The questions
are displayed in the Recovery time objective assessment tab according to the configuration set up by the BCM administrator. A sample Recovery time objective assessment with demo data is shown in the following
example.

## Recovery point objective {#rto-rpo-recovery-tiers__section_zhm_cdt_pxb}

Recovery point objective (RPO) defines the maximum acceptable data loss that a business process can handle without significant effect on operations.

If you are the IT owner, you can estimate the recovery point objective for your data applications and systems by responding to the Recovery point objective assessment in the BIA. Based on the configuration set up by the BCM
administrator, the questions are displayed in the Recovery time objective assessment tab as shown in the following example.

## Recovery tier {#rto-rpo-recovery-tiers__section_df1_ddt_pxb}

If you are the BCM administrator, you can classify a set of business applications that follow a similar range of recovery time objective (RTO) values in one type of recovery tier. For example, for the Mission Critical recovery tiers,
recovery time objectives can be Immediately, one Hour, and four Hours.

The recovery tiers and their associated recovery time objectives are displayed in the following example.

The BCM administrator can configure a recovery tier and set its recovery time objective as shown in the following example.

Recovery tiers are also associated with other organizational expectations such as levels of support, escalation, and communication. Recovery tiers are used in the following areas:

* BIA scores and impact assessment result
* Element recovery times
{#rto-rpo-recovery-tiers__ul_ttx_3gt_zxb}Although there is no limitation to the number of the recovery tiers, an organization can set 4 to 6 recovery tiers. Recovery tiers are automatically calculated on BIAs and element RTO by selecting the nearest recovery tier maximum time.  
Recovery tiers can be classified as per their importance and criticality:

* Mission Critical
* Business Critical
* Essential
* Non-essential
* Critical
* Non-Critical
{#rto-rpo-recovery-tiers__ul_m4g_2fp_cyb}

## Recovery tier configuration by the administrators {#rto-rpo-recovery-tiers__id_vlr_xss_zxb}

For more information on how to configure a recovery tier in the Business Continuity Management application, see [Configure recovery tiers for BIA](https://www.servicenow.com/docs/llzoPy0E3touExQ7_kUBQw "Configure a recovery tier with a set of business applications that follow a similar range of recovery time objective (RTO) values. Use the Recovery Tiers module in the Business Continuity Management application navigator to configure a recovery tier.").

## Recovery timeframe {#rto-rpo-recovery-tiers__section_m1k_tgz_fyb}

You can set up the recovery timeframe for a recovery tier. It is the timeframe that starts from when a disruptive event happens to the time when your business can resume usual operations. The BCM administrator can configure the recovery timeframe and its start time. You can configure different recovery timeframes as shown in the following example:

* Immediately
* 1 Hour
* 4 Hours
* 8 Hours
* 24 Hours
* 72 Hours
* 1 Week
* 2 weeks

{#rto-rpo-recovery-tiers__ul_xzw_qht_pxb}The following example shows the configured recovery timeframes in the Business Continuity Management application.

The following example shows the configuration of a recovery timeframe in the Business Continuity Management application.

For more information on how to configure a recovery timeframe in the Business Continuity Management application, see [Set up recovery timeframe for a recovery tier](https://www.servicenow.com/docs/nmuOYw97OJKGIEG27aUMiw "Set up recovery timeframe that starts from when an incident or crisis happens to the time your business can resume usual operations.").

