The organization must establish a ICT risk tolerance level by identifying key ICT risk categories (e.g., cybersecurity threats, system downtime, data loss) and defining the level of risk the financial entity is willing to accept, in line with its overall risk appetite
The organization should analyse the impact tolerance for ICT disruptions by determining the maximum acceptable downtime and data loss for critical ICT services, considering potential business, customer, and regulatory impacts. Document the defined risk tolerance and impact thresholds for management review and approval.