Technology
IT Disaster Recovery RTO/RPO Gaps
Recovery time and recovery point objectives versus tested actuals for critical IT systems.
Why RTO and RPO Gaps Are an Audit Concern
When a critical system fails, the gap between what the entity promised and what it can actually recover determines whether services and revenue collection survive the outage. Testing recovery time and recovery point objectives against real results is central to the IT governance King IV expects and to the business-continuity controls AGSA increasingly examines. AuditPro Core compares each critical system's stated RTO and RPO against its last tested actual so untested or failing recovery plans are exposed before a real incident.
The Numbers
AuditPro Core renders this view from your tenant's live, tamper-evident records. The figures below are illustrative sample data.
Critical systems
18
Meeting RTO
11
of 18
RPO breaches
5
data loss risk
Untested DR
3
no recovery test
RTO target vs tested actual (hours)
Recovery objective compliance
| System | RTO gap (h) | RPO gap (h) | Status |
|---|---|---|---|
| Financial ledger | 5 | 2 | Breach |
| Billing | 8 | 4 | Breach |
| Payroll | -1 | 0 | Met |
| GIS / valuations | 7 | 3 | Breach |
Figures shown are illustrative sample data for demonstration. AuditPro Core renders these views from your own tenant's live, tamper-evident records.
RTO and RPO Defined
Recovery time objective is how quickly a system must be restored; recovery point objective is how much data loss is tolerable, measured backwards from the failure. Together they define the continuity promise made to the business.
Stated versus Tested
An objective written in a plan is meaningless until a recovery test proves it can be met. The dangerous gap is a system with an ambitious RTO that has never been tested or has failed its last test.
Criticality Drives Tolerance
A revenue or payroll system warrants a far tighter RTO than a back-office reporting tool. Aligning objectives to business criticality stops the entity from over-investing in trivial systems while under-protecting essential ones.
Dependency Chains
A system can only recover as fast as the infrastructure, networks and data feeds it depends on. Recovery testing that ignores these dependencies produces optimistic objectives that collapse in a real outage.
How AuditPro Core Bridges the Gap
- Objective-versus-actual tracking: each critical system's stated RTO and RPO is held against its most recent tested result so paper plans are separated from proven ones.
- Gap flagging: systems with untested, stale or failed recovery results are escalated for re-testing before an incident exposes them.
- Continuous monitoring: test currency is tracked so recovery assurance does not quietly lapse between cycles.
- Traceability to source: every actual links to the recovery test log and evidence for IT audit review.
Key Takeaways
- RTO governs recovery speed; RPO governs tolerable data loss — both define the continuity promise.
- An untested or failed recovery objective offers no real protection.
- Align recovery tolerance to each system's business criticality.
- Recovery is only as fast as the dependencies a system relies on.
See This on Your Own Data
AuditPro Core renders this dashboard from your tenant's live, tamper-evident records — every figure traceable to source.
