CheckoryCheckory
Clause 11.4 MSA, commercially reasonable backup circled, two clock blanks empty, no face

How to Review Vendor RTO, RPO, and Disaster-Recovery Test Evidence

Review vendor RTO, RPO, and DR test evidence: write two clocks, name systems, demand a dated written result, then match, add a schedule, or walk.

9 min readArticle
💡

Key takeaway in 30 seconds

Knowing how to review vendor rto rpo and disaster recovery test evidence is a two-clock hunt on the vendor paper. Write hours to restore and hours of data you can lose. Demand named systems, not commercially reasonable backup. Require a last test date with a written actual-versus-target result. Add one sentence that force majeure does not excuse the BCDR plan. Then match, add a schedule, or walk.

Niko, Ops at a 29-person UK fintech, is about to accept a vendor MSA — the umbrella contract that order forms sit under — because sales said the backup is commercially reasonable. Write two clocks, name the systems, refuse a 2019 tabletop as a 2026 result, then match, add a schedule, or walk.

September 2026. Finance signed off £6,200 a month on a payments-reconciliation SaaS under the customer-payment important business service. Clause 11.4: “Supplier shall maintain commercially reasonable backup and disaster-recovery arrangements.” No hours. No named production ledger, payout file, or identity store. AE Slack: “we have SOC 2.” They send November 2019 tabletop minutes. Niko’s last card-scheme miss burned a Friday of manual payouts. That outage was costly. Go-live is Monday.

Commercially reasonable backup is not an RTO, and a 2019 tabletop is older than the FCA operational-resilience transition. FCA rules came into force 31 March 2022; payment institutions and electronic money institutions had until 31 March 2025 to map and test inside impact tolerances. Niko is not a PRA bank. The firm still owns a third-party miss.

Disclaimer: Checkory provides AI support, not legal advice. Consult a qualified lawyer for binding decisions.

How do you split hours to restore from hours of data you can lose?

RTO is hours forward from the outage — how long the named service may stay down. RPO is hours back — the age of the backup you are allowed to land on. Write both blanks before anyone debates “backup.” A nightly job with a three-day restore is a 24-hour RPO story and a 72-hour RTO story.

Freeze the packet — the signed file stack (MSA plus any BCDR schedule). Circle the backup sentence. Write RTO = ___ hours and RPO = ___ hours or minutes. If both are empty, write “clocks silent.” NIST CSRC defines recovery time objective in a vendor contract as how long a system may stay in recovery before the mission is harmed — US structure, not England-and-Wales statute. Recovery point objective is the point in time to which data must be recovered — the rpo backup age commitment. For example, Niko’s heading names neither clock. Do: fill two blanks or write silent. Don’t: treat “we back everything up” as hours.

Typical mistake

A 24-hour backup job with a 72-hour restore still loses a weekend of payouts.

Two clocks: hours forward versus hours of data you lose, no face
Two clocks: hours forward versus hours of data you lose, no face

What to demand instead of commercially reasonable backup?

A recovery time objective in a vendor contract is hours on named systems, not an adjective. Circle clause 11.4 and write “systems: none / hours: none.” Demand an exhibit — an attached schedule — that names the ledger, payout file, identity store, and a default for anything unlisted.

If it is not on the list, expect a coverage fight. Granite GRC calls commercially reasonable efforts dangerous ambiguity. Jones IT is blunt: no named numbers means no measurable recovery commitment. In practice, “we have SOC 2” does not print hours onto 11.4 — Type II PDF is a different hunt on the vendor security addendum checklist. Do: name systems plus hours. Don’t: accept the slogan as market.

What does a 2019 tabletop fail as disaster-recovery test evidence?

A policy PDF or a seven-year-old tabletop is not a written 2026 result. Demand a last test date and actual versus target on the same page. Niko’s November 2019 minutes predate the 31 March 2025 mapping deadline. That is the hidden risk in the “we tested once” file.

A disaster recovery test report cadence starts with a dated written pack: scope, systems, recovery point, start and end, observed RTO and RPO, issues, owners. Different Dev (27 July 2026) is clear: an annual tabletop may satisfy a basic policy but does not prove current restore. A four-hour target that takes seven hours has failed. FCA “one year on” wants third-party testing outcomes in the map, not only tech. Annual full exercise is baseline colour, not a seven-year gap. Do: refuse 2019 minutes. Don’t: file a policy PDF as evidence.

2019 tabletop minutes versus a dated actual-versus-target pack, no face
2019 tabletop minutes versus a dated actual-versus-target pack, no face

Which force-majeure line can excuse the BCDR plan?

A force-majeure clause two sections later can cancel the recovery Niko thinks he bought. Write one sentence on the DR schedule: force majeure does not limit the duty to implement the BCDR plan and hit the restoration times. Then stop. Do not retell the event list here.

Morgan Lewis (23 July 2021) says an FM event does not excuse the duty to restore. Tech Contracts one-liner: the FM section does not apply to disaster-recovery obligations. Event list, notice, longstop, or product-sunset-as-FM is a different hunt — force majeure first-pass. Do: carve BCDR out of FM. Don’t: assume a disaster heading already did that work.

When to lock who you call, and when, during a failover?

Acknowledgement is not restore. Name a role — not support@ — a channel that works at 02:00, and acknowledgement minutes. Write whether Niko may declare failover or only the vendor can. A tabletop does not prove the phone tree.

Circle “we will email.” LegalClarity treats a 15-minute critical acknowledgement as a start clock, not resolution. If they offer service credits instead of hours, that is a different hunt on the SLA service-credits checklist. Credits rarely make a payout weekend whole. Do: write role, channel, ack minutes. Don’t: wait until the outage to find the number.

Workflow

two clocks → named systems + hours → dated written result → FM does not excuse BCDR → failover contact → match / add exhibit / walk

Failover role, 02:00 channel, and 15-minute acknowledgement, no face
Failover role, 02:00 channel, and 15-minute acknowledgement, no face

How do you match, add an exhibit, or walk?

Match only if named systems, RTO and RPO in hours, a last written test within 12 months with actual versus target, FM that does not excuse BCDR, and a named failover contact are on the paper. Silent hours plus a 2019 PDF is add-exhibit or walk — not a green light.

Success bar before FAQ: fill the one-page log — two clocks, named systems, last test date plus actual-versus-target, FM carve-out, failover contact — and point to one sentence that would pause Monday. “Commercially reasonable backup” and “we have SOC 2” are not that sentence if the paper has no hours and a 2019 tabletop. SYSC 8.1.8R(11) colour — only if this outsourcing is a critical function in that perimeter — wants a written plan and periodic testing. Optional: a Checkory first-pass — a machine extract before a human reads every page — on the same PDF at document analysis, then a human opens every High flag — a high-severity hit a human must verify — and the 2019 date. Counsel — a solicitor who can bind a decision — still owns the walk.

Match, add exhibit, or walk

GateMatchAdd exhibitWalk
Two clocksRTO + RPO in hoursSlogan only — write the blanksBackup treated as hours
Named systemsLedger, payout, identity + defaultHeading, no listFight on unlisted apps
Test evidenceDated actual vs target ≤12 monthsPolicy PDF, no timestampsNovember 2019 tabletop
FM vs BCDRFM does not excuse restore timesSilent overlapFM swallows the DR duty
FailoverRole + 02:00 channel + ack minutessupport@ / we will emailNo one to call at 02:00

Seven steps

1

Freeze the packet

MSA plus order form plus any BCDR schedule. Circle the backup sentence.

2

Split the clocks

RTO hours forward. RPO hours or minutes back. If both empty, write clocks silent.

3

Name the systems

Ledger, payout file, identity store, plus a default. Strike the slogan as the only promise.

4

Demand dated written result

Last test date, actual versus target, issues, owners. Refuse a 2019 tabletop.

5

Carve BCDR out of FM

One sentence: force majeure does not excuse the plan or the restoration times.

6

Lock the failover phone

Role, 02:00 channel, acknowledgement minutes, who may declare failover.

7

Match, add exhibit, or walk

Log the live clocks and the 2019 date. Owner = Niko or a deputy. No green light.

Frequently asked questions

Is a 72-hour RTO enough?
Only if it sits inside your impact tolerance for that important business service. No statutory or Checkory 72-hour default.
Does SOC 2 replace an RTO number?
No. A SOC 2 Availability PDF does not print hours onto the MSA. Type II versus a badge: /en-gb/blog/vendor-security-addendum-review-checklist.
Can they call a product sunset force majeure?
Different hunt. Event list, notice, longstop: /en-gb/blog/force-majeure-clause-first-pass-review.
Does commercially reasonable backup count as an RPO backup-age commitment?
No. An RPO backup-age commitment is hours or minutes on named systems. An adjective with no number is clocks silent.
What disaster recovery test report cadence should I demand?
A dated written actual-versus-target pack, not a policy PDF. Annual full exercise is baseline; a 2019 tabletop is not.
If they offer SLA credits instead of hours, am I covered?
Credits are not hours. Credit table or exclusive credits: /en-gb/blog/saas-sla-service-credits-review-checklist.

Highlight RTO, RPO, and the last-test date

Upload the same PDF. A human opens the hours and the 2019 date.

Start document analysis

What to do next

Sources

Related guides

Updated: September 8, 2026