Skip to main content
Category: Enterprise Risk Management

Crisis Management Plan

Also known as: CMP, Crisis Response Plan
Simply put

A crisis management plan is a documented set of actions an organization prepares in advance to respond to a serious, disruptive event such as a catastrophe or major incident. It generally sets out who does what, how the organization communicates, and how it protects people, property, and operations before, during, and after the event. It is typically developed, tested, and maintained ahead of any actual crisis so the response can be activated quickly.

Formal definition

A crisis management plan is a formal, pre-established framework outlining the actions to be taken immediately before, during, and after a catastrophic or significant disruptive event to preserve lives, safeguard property, and maintain business continuity. In practice it typically includes a risk or threat assessment, a designated crisis management team with defined roles and responsibilities, activation triggers, communication protocols, and recovery tasks. Development generally follows a lifecycle of assessing threats, documenting the plan, and periodically testing and maintaining it. The specific scope, structure, and rigor of a CMP vary by organization, sector, and the nature of the risks it addresses; this entry is educational and not legal, audit, or compliance advice.

Why it matters

A crisis management plan matters because serious disruptive events, natural catastrophes, safety incidents, data breaches, or other major operational failures, rarely allow time for organizations to design a considered response once the event is unfolding. Preparing a documented plan in advance generally enables an organization to activate its response quickly, coordinate the people involved, and focus decision-making on preserving lives, safeguarding property, and maintaining continuity of operations rather than improvising under pressure.

From a governance perspective, a CMP is one of the tools through which an organization operationalizes its broader risk management posture. Because such a plan typically clarifies who does what, how the organization communicates internally and externally, and how it recovers, it can reduce the confusion and conflicting messaging that often compounds the harm caused by a crisis. The plan's value depends heavily on whether it is realistic, understood by those expected to use it, and kept current; a plan that exists on paper but has never been tested may offer limited protection when an actual event occurs.

The specific scope, rigor, and structure of a CMP vary by organization, sector, and the nature of the risks addressed. This entry is educational and does not constitute legal, audit, or compliance advice, and whether a particular organization is expected to maintain such a plan, and to what standard, depends on its circumstances, jurisdiction, and applicable requirements.

Who it's relevant to

Boards and Risk Committees
Boards and their risk committees typically hold an oversight role, satisfying themselves that management has developed, tested, and maintained appropriate crisis response capabilities for the organization's material risks. This is generally an oversight responsibility rather than an operational one, the board does not usually execute the plan, but it may seek assurance that a credible plan exists and is kept current.
Management and the Crisis Management Team
Management typically owns the development, activation, and execution of the plan, including assembling the designated crisis management team, defining roles and responsibilities, and coordinating the response during an event. The crisis management team is the group with operational accountability once activation triggers are met.
Risk and Business Continuity Functions
Risk and business continuity professionals are generally involved in the underlying risk or threat assessment that informs the plan, in identifying continuity and recovery tasks, and in supporting the testing and maintenance lifecycle. Their work helps ensure the plan is grounded in the organization's actual risk profile.
Communications and Legal Functions
Communications teams are typically relevant because crisis management plans generally include communication protocols for internal and external audiences during an event. Legal and compliance functions may be engaged to address obligations that can arise during a crisis, though specific requirements depend on the facts, jurisdiction, and applicable rules.
Internal Audit and Assurance Providers
Internal audit and other assurance functions may evaluate whether a crisis management plan has been designed appropriately and whether testing and maintenance activities operate effectively, providing independent assurance to the board and management without owning the plan itself.

Inside CMP

Activation Criteria and Escalation Triggers
Predefined thresholds and event types that determine when the plan is invoked and how an incident escalates through management to the board or a designated crisis committee. Generally clarifies who has authority to declare a crisis and at what point oversight bodies are notified.
Roles, Responsibilities, and the Crisis Team
Designation of a crisis management team, with clear separation between management's operational response duties and the board's oversight role. Typically identifies decision-makers, deputies, and functional leads (legal, communications, operations, security) to avoid ambiguity during an event.
Communication Protocols
Internal and external communication procedures, including notification chains, spokesperson designation, and approval steps for public statements. Often addresses coordination with regulators, employees, customers, and other stakeholders, subject to any disclosure obligations that vary by jurisdiction and sector.
Scenario Playbooks and Response Procedures
Documented response steps for plausible crisis scenarios (for example, cyber incidents, operational disruptions, or safety events). These generally provide guidance rather than rigid scripts, given that real events rarely match assumptions precisely.
Resource and Continuity Linkages
References to supporting arrangements such as business continuity and disaster recovery plans, contact lists, alternate facilities, and third-party support. Clarifies how the crisis plan interacts with, but is distinct from, continuity planning.
Post-Incident Review and Improvement
A process for capturing lessons learned, evaluating response effectiveness, and updating the plan. Typically feeds back into risk assessment and assurance activities, supporting continuous improvement.

Common questions

Answers to the questions practitioners most commonly ask about CMP.

Is a crisis management plan the same as a business continuity plan?
No, though they are related and often coordinated. A crisis management plan generally focuses on the leadership, decision-making, communication, and escalation processes needed to respond to a serious, often unanticipated disruptive event, including strategic, reputational, and stakeholder dimensions. A business continuity plan typically focuses on maintaining or restoring critical operations and services during and after a disruption. In many organizations the two are designed to work together, with the crisis management plan providing the coordinating and decision-making layer, but they address different objectives and are usually owned and exercised as distinct (if linked) documents. The precise relationship depends on how an organization structures its resilience program.
Does having a crisis management plan mean the board is responsible for executing the response?
Generally no. Executing a crisis response is typically a management function, often led by a designated crisis or incident response team, while the board's role is usually one of oversight, satisfying itself that credible plans exist, are tested, and are appropriately resourced, and engaging on matters of significant strategic, reputational, or existential consequence. The line between oversight and execution can shift for the most severe events, where directors may need to be informed more frequently or convene to consider decisions within their remit. The specific allocation of responsibility depends on the organization's governance structure, delegated authorities, and the nature of the crisis, and should be defined in advance rather than improvised.
Who should own and maintain the crisis management plan within an organization?
Ownership generally sits with management rather than the board, though practice varies by organization. In many entities a senior executive, such as a chief risk officer, chief operating officer, head of resilience, or general counsel, holds accountability for keeping the plan current, coordinating with related plans, and ensuring exercises occur. Assurance functions such as internal audit may independently review the plan's design and readiness but typically do not own it, to preserve their independence. The appropriate owner depends on the organization's size, sector, and how it structures risk and resilience responsibilities; the key is that accountability is clearly assigned and understood in advance.
How often should a crisis management plan be reviewed and tested?
There is no single mandated frequency across all jurisdictions and sectors; the appropriate cadence depends on the organization's risk profile, regulatory expectations, and rate of change in its operating environment. As a general practice, many organizations review the plan periodically and after any significant change, such as a merger, major system change, or lessons learned from a real event or exercise, and conduct exercises (for example tabletop or simulation-based) on a recurring basis. Some regulated sectors impose specific testing expectations. Organizations should confirm any applicable requirements for their jurisdiction and sector and treat testing as a means of validating that the plan works in practice, not merely that it exists on paper.
What elements are commonly included in a crisis management plan?
Contents vary by organization, but plans commonly address activation and escalation triggers, roles and responsibilities (including who leads and who has decision-making authority), team structure and succession or backup arrangements, internal and external communication protocols, stakeholder identification, contact and notification procedures, coordination with related plans such as business continuity and incident response, and provisions for stand-down, recovery, and post-incident review. Some plans also cover regulatory or legal notification obligations. This list is illustrative rather than prescriptive; the specific components should be tailored to the organization's risks, structure, and any applicable requirements, and are best developed with relevant professional input.
How does a crisis management plan connect to an organization's broader risk management framework?
A crisis management plan generally functions as one response and preparedness component within a wider risk management framework rather than as a standalone document. Enterprise risk management typically informs which scenarios warrant crisis planning by identifying significant risks and assessing their potential likelihood and impact, while the crisis plan addresses how the organization would respond should such an event materialize despite preventive controls. Linking the two helps ensure planning is focused on the risks that matter most and that residual risks the organization has chosen to accept or cannot fully mitigate have a response pathway. The strength of this linkage depends on how integrated an organization's risk and resilience activities are, and the connection is a matter of design judgment rather than a fixed rule.

Common misconceptions

A crisis management plan is the same thing as a business continuity or disaster recovery plan.
These are related but distinct. Crisis management generally focuses on coordinating leadership decision-making, communications, and stakeholder response during a disruptive event, while business continuity and disaster recovery focus on restoring operations and systems. Mature programs typically maintain them as complementary but separate documents.
Once a crisis management plan is written and approved, the organization is prepared.
A documented plan reflects design; preparedness depends on operating effectiveness, which is generally demonstrated through training, exercises, and testing. An untested plan may fail under real conditions, and the plan should be reviewed and updated as risks and the organization change.
Crisis management is primarily a board responsibility.
In most governance models, executing the crisis response is a management function, while the board's role is typically oversight, satisfying itself that a credible plan exists, is tested, and is adequately resourced. Attributing operational response duties to the board conflates oversight with management accountability.

Best practices

Clearly define activation and escalation criteria in advance, specifying who can declare a crisis and when the board or a designated committee must be informed, so accountability is not improvised during an event.
Separate management's operational response responsibilities from the board's oversight role in the plan documentation, and confirm the board periodically reviews whether the plan exists, is tested, and is adequately resourced.
Test the plan regularly through tabletop exercises or simulations to validate operating effectiveness, not just design, and document findings for follow-up.
Integrate the crisis plan with, but keep it distinct from, business continuity, disaster recovery, and enterprise risk management processes, ensuring cross-references and shared contact information stay current.
Establish communication protocols that designate spokespersons and approval steps, and account for any disclosure or notification obligations, recognizing these requirements vary by jurisdiction, sector, and entity type.
Conduct structured post-incident reviews to capture lessons learned and feed improvements back into risk assessment, control updates, and revisions of the plan itself.