Skip to main content
Category: Enterprise Risk Management

Crisis Communication

Also known as: Crisis Communications
Simply put

Crisis communication is how an organization gathers, manages, and shares information when it faces an event that threatens its reputation or operations. It focuses on responding quickly and clearly under pressure to inform stakeholders and help reduce the harm caused by the crisis. Many organizations prepare in advance with a crisis communication plan that sets out strategies, protocols, and tools.

Formal definition

Crisis communication is the process of collecting, processing, and disseminating information to address a situation that poses a threat to an organization's reputation or operations. It typically encompasses communication strategies, protocols, and tools used to raise awareness of a specific threat, its magnitude and potential outcomes, and the behaviors intended to reduce that threat. In practice, it is often supported by a documented crisis communication plan that functions as a pre-established blueprint enabling an organization to respond immediately when a crisis arises. The scope, ownership, and integration of this activity with broader governance, risk, and incident-response functions generally vary by organization and are not specified in the evidence provided.

Why it matters

When an organization faces an event that threatens its reputation or operations, the speed and clarity of its communication can materially affect the harm that results. Crisis communication matters because stakeholders, employees, customers, regulators, investors, and the public, form judgments quickly during a crisis, often on the basis of incomplete information. An organization that can gather, process, and disseminate accurate information promptly is generally better positioned to inform those stakeholders and reduce the threat than one that responds slowly or inconsistently.

Preparation is a recurring theme in how organizations approach this discipline. Many maintain a documented crisis communication plan that functions as a pre-established blueprint, setting out communication strategies, protocols, and tools before a crisis occurs. Because a crisis by definition arrives under time pressure, having agreed protocols in place typically enables an organization to respond immediately rather than improvising while events unfold. The aim is often to raise awareness of the specific threat, its magnitude and potential outcomes, and the behaviors intended to reduce that threat.

It is worth noting that crisis communication is one component of a broader response capability. The way it is owned and integrated with governance, risk management, and incident-response functions generally varies by organization and depends on facts and structure that this entry does not attempt to specify. This entry is educational and does not constitute legal, audit, or compliance advice.

Who it's relevant to

Boards and their committees
The board and relevant committees typically hold an oversight interest in whether the organization is prepared to communicate effectively when its reputation or operations are threatened. This generally involves satisfying themselves that appropriate plans and protocols exist, rather than directing the operational response themselves. The precise allocation of oversight responsibilities varies by organization.
Executive management and communications leaders
Management is generally accountable for developing and executing the crisis communication response, gathering and processing information, approving messaging, and disseminating it to stakeholders. Communications and public-relations functions often lead the design of the crisis communication plan and the strategies, protocols, and tools it contains.
Risk and incident-response functions
Because crisis communication addresses events that threaten operations or reputation, it is generally relevant to those managing risk and coordinating incident response. How this activity integrates with broader risk management and incident-response arrangements varies by organization and is not specified in the evidence underlying this entry.
Stakeholders receiving the communication
Employees, customers, regulators, investors, and the public are typically the audiences a crisis communication effort seeks to inform. The messaging is often aimed at raising their awareness of the threat, its magnitude and outcomes, and the behaviors intended to reduce it.

Inside Crisis Communication

Crisis Communication Plan
A pre-established, documented protocol that sets out how an organization coordinates the flow of information to internal and external audiences during a disruptive event. It typically identifies decision-making authority, escalation triggers, approved spokespersons, and channels. It is generally treated as a component of broader crisis management and business continuity arrangements rather than a standalone compliance requirement, though certain sectors and jurisdictions may impose specific disclosure or notification obligations.
Spokesperson Designation and Message Authority
The predefined assignment of who is authorized to speak on the organization's behalf and who approves messaging before release. This element clarifies accountability and helps prevent inconsistent or unauthorized statements. Responsibility for delivery typically sits with management and communications functions, while the board or a designated committee generally exercises oversight rather than operational control.
Stakeholder Identification and Segmentation
The mapping of audiences that may need to receive information, such as employees, customers, investors, regulators, media, and affected communities. Tailoring content, timing, and channel to each audience helps address differing information needs and expectations. Where regulators or listed-entity investors are involved, specific legal or listing-rule disclosure obligations may apply and vary by jurisdiction and entity type.
Escalation and Activation Triggers
Predefined thresholds and criteria that determine when the plan is activated and how an incident is escalated to senior management or the board. These triggers connect crisis communication to the organization's broader incident response and risk management processes, and help distinguish routine issues from events warranting coordinated response.
Regulatory and Legal Disclosure Considerations
The interface between crisis messaging and any binding obligations to notify regulators, markets, or affected parties. The existence, scope, and timing of such obligations depend heavily on jurisdiction, sector, and entity type, and often require input from legal counsel. This element concerns coordination with disclosure duties rather than replacing them.
Post-Incident Review and Feedback Loop
The structured evaluation conducted after an event to assess how communication performed, capture lessons learned, and update the plan. This supports continuous improvement and links crisis communication to assurance and oversight activities, such as reporting outcomes to relevant committees.

Common questions

Answers to the questions practitioners most commonly ask about Crisis Communication.

Is crisis communication just a public relations or media relations function?
No. While media relations is one component, crisis communication is broader and generally spans internal and external stakeholders, including employees, the board, regulators, customers, investors, and business partners. Treating it purely as a PR exercise risks neglecting legally sensitive audiences and internal coordination. In many organizations, communications, legal, compliance, and risk functions collaborate, with the board or a designated committee exercising oversight rather than managing messaging directly. The precise allocation of roles depends on the entity's structure, sector, and applicable requirements.
Does having a crisis communication plan mean the organization has managed the underlying risk?
No. Crisis communication addresses how an organization conveys information during and after a disruptive event; it does not by itself reduce the likelihood or impact of the underlying risk. It is generally one element of broader crisis management and business continuity arrangements, which in turn sit within enterprise risk management. A communication plan may be well designed on paper but still fail if not tested, and its existence should not be confused with the operating effectiveness of the controls intended to prevent or mitigate the event itself.
Who typically owns crisis communication, and what is the board's role?
Operational responsibility generally rests with management, often through a designated crisis or communications team drawing on legal, compliance, risk, and communications expertise. The board's role is typically one of oversight: satisfying itself that credible plans exist, that roles are defined, and that it will receive timely, accurate information during a crisis. In serious situations, the board or a committee may be directly engaged, particularly where disclosure obligations, reputational exposure, or fiduciary duties are implicated. The specific split depends on governance arrangements, severity, and applicable requirements.
How can an organization prepare its crisis communication capability before an event occurs?
Common preparatory steps include identifying plausible crisis scenarios, defining escalation triggers and decision-making authority, designating and training spokespersons, pre-clearing approval workflows involving legal and compliance, and mapping stakeholders and their information needs. Many organizations test arrangements through exercises or simulations to assess whether the plan works in practice rather than only on paper. The appropriate level of preparation varies by the organization's size, sector, and risk profile, and these steps are illustrative rather than a mandatory checklist.
How should crisis communication be coordinated with legal and regulatory disclosure obligations?
Communications and disclosure are related but distinct. Certain events may trigger binding disclosure obligations under securities laws, listing rules, or sector-specific regulation, and these vary significantly by jurisdiction and entity type. Public statements made during a crisis can carry legal consequences, so many organizations involve legal counsel and compliance in reviewing messaging for accuracy and consistency with formal disclosures. This coordination is a matter of professional judgment on the specific facts; entries here are educational and not a substitute for legal or compliance advice on any particular obligation.
How can an organization evaluate whether its crisis communication performed effectively after an event?
Post-incident review, sometimes called a lessons-learned or after-action process, is commonly used to assess whether messaging was timely, accurate, consistent, and reached the intended stakeholders, and whether escalation and approval steps functioned as designed. Such reviews may distinguish between whether the plan was well designed and whether it operated effectively in practice. Findings can inform updates to plans, training, and controls. The depth and formality of review generally depend on the severity of the event and the organization's own governance and assurance arrangements.

Common misconceptions

Crisis communication is the board's operational responsibility during an incident.
In many governance models, executing crisis communication is a management and communications function activity, while the board or a designated committee typically exercises oversight, ensuring an adequate plan exists, is tested, and is reported on, rather than managing message delivery. The precise allocation depends on the organization's structure and mandate.
Crisis communication and regulatory disclosure are the same thing.
They are related but distinct. Crisis communication addresses coordinated messaging to a range of stakeholders, whereas regulatory or market disclosure may be a binding legal obligation whose existence, scope, and timing vary by jurisdiction, sector, and entity type. Communications activity does not substitute for meeting any applicable legal disclosure duties.
Having a written crisis communication plan is enough to ensure readiness.
A documented plan reflects control design, but readiness also depends on operating effectiveness, whether the plan is understood, tested, and workable under pressure. A plan that is never exercised or reviewed may not perform as intended when a real event occurs.

Best practices

Clearly define and document decision-making authority, escalation triggers, and designated spokespersons before an incident occurs, so roles are not improvised under pressure.
Coordinate crisis messaging with legal counsel to align communications with any applicable disclosure or notification obligations, recognizing these obligations vary by jurisdiction, sector, and entity type.
Distinguish management's operational role in executing communications from the board or committee's oversight role, and establish how and when incidents are escalated and reported to those charged with oversight.
Map stakeholder audiences in advance and tailor content, timing, and channel to each group's information needs.
Test the plan periodically through exercises or simulations to assess not only whether it is well designed but whether it operates effectively in practice.
Conduct structured post-incident reviews to capture lessons learned and feed improvements back into the plan and relevant oversight reporting.
Treat this entry as educational; specific plans should reflect professional judgment and the organization's own facts, and are not a substitute for legal, audit, or compliance advice.