8.4 Crisis Management Planning & Incident Documentation
Key Takeaways
- A crisis management plan is strategic and deals with consequences to the whole organization, whereas a business continuity plan is operational and restores specific prioritised activities — the two are different documents with different owners and different activation triggers.
- ISO 22361:2022 is the ISO guidance standard for crisis management, covering crisis leadership, decision-making under uncertainty, and crisis communication; it is guidance and is not certifiable.
- A crisis management plan should describe capability and decision authority rather than prescribe step-by-step procedures, because a crisis is by definition a situation the organization did not pre-script.
- Every incident requires a contemporaneous decision log recording what was known at the time, what was decided, who decided it, and why — reconstructed logs are worthless for both improvement and legal defence.
- Incident documentation feeds four downstream processes: the post-incident review, regulatory notification, insurance and legal claims, and the Clause 10.1 corrective action that prevents recurrence.
Section 8.1 built the incident response structure and Section 8.2 built the business continuity plans. Both assume the organization is dealing with a disruption it anticipated in some form — a site is unavailable, a system is down, a supplier has failed, and a pre-designed solution is invoked.
A crisis is different. A crisis is a situation that threatens the organization's strategic objectives, reputation, or viability, in which the consequences exceed what any pre-written procedure anticipated, decisions must be made on incomplete information, and the decisions themselves become the story. The PECB Domain 4 competencies list "Ability to plan and develop a crisis management plan" and "Knowledge of documenting an incident" as distinct examinable items, and both sit here.
1. Four Plan Types, Clearly Separated
Candidates lose marks by treating these as synonyms. They differ on trigger, horizon, owner, and question answered.
| Plan | Question it answers | Tier | Horizon | Owner |
|---|---|---|---|---|
| Emergency response plan | How do we keep people alive and safe right now? | Bronze (operational) | Seconds to minutes | Facilities / HSE |
| Incident response plan | How do we detect, triage, contain, and escalate this event? | Silver (tactical) | Minutes to hours | Incident Manager |
| Business continuity plan | How do we keep prioritised activities delivering at or above MBCO? | Silver (tactical) | Hours to weeks | Activity / process owner |
| Crisis management plan | How do we lead the organization through strategic consequences we did not pre-script? | Gold (strategic) | Hours to months | Crisis Management Team, chaired by top management |
The relationships that follow are examinable:
- Not every incident is a crisis, and not every crisis begins as an incident. A server outage recovered inside RTO is an incident. A regulatory investigation into board conduct, a fatality on site, or a product recall may be a crisis with no continuity disruption at all — nothing needs recovering, but the organization's survival is in play.
- A crisis can be declared without a BCP invocation, and a BCP can be invoked without a crisis. These are independent decisions made by different authorities.
- Escalation is a judgement, not an arithmetic threshold. An incident becomes a crisis when consequences cross from operational into strategic — when they engage reputation, regulator relationships, market confidence, or the licence to operate.
ISO 22361:2022
ISO 22361:2022, Security and resilience — Crisis management — Guidelines (first edition, October 2022), is the ISO document devoted to crisis management. It provides guidance on developing a strategic crisis management capability and addresses context and core concepts, crisis leadership, the decision-making challenges facing a crisis team in action, and crisis communication.
Two exam-relevant properties: it is guidance, not requirements — you cannot be certified against it, and it uses "should" rather than "shall" — and it is aimed at top management with strategic responsibility, which is consistent with crisis management sitting at the Gold tier.
2. Why Crisis Plans Describe Capability, Not Procedure
This is the conceptual core of the section and the most frequently mishandled idea in the domain.
A business continuity plan can be procedural because the scenario is bounded: the activity is known, the RTO is known, the resources are pre-agreed, and the recovery steps can be written and rehearsed. A crisis plan cannot be procedural, because if the situation were predictable enough to script, it would not be a crisis. An organization that writes a 200-page crisis manual with a decision tree per scenario has built a document that will be wrong in the one situation it is opened for.
A crisis management plan therefore specifies capability:
| Component | What it must establish |
|---|---|
| Activation criteria and authority | What constitutes a crisis, who can declare one, and — critically — that anyone in the organization can escalate even though only named roles can declare |
| CMT composition and deputies | Core members (chair, operations, communications, legal, HR, finance, IT/security) plus co-opted expertise, each with at least two deputies |
| Convening mechanism | How the team is summoned, primary and alternate channels, target time to convene, virtual and physical locations |
| Decision authority and delegations | Financial limits, authority to suspend normal policy, authority to stop operations, authority to speak publicly |
| Battle rhythm | Meeting cadence, standing agenda, situation-report format — so the team spends its time deciding rather than organising itself |
| Information management | Who maintains the common operating picture; how the CMT receives fact from the Silver tier without being flooded by it |
| Stakeholder and communication strategy | Spokesperson governance, holding statements, notification obligations (Section 8.3) |
| Standing down and transition | Criteria for de-escalation and handover to recovery and post-incident review |
The standing agenda that survives contact
Because the content of a crisis is unpredictable, the CMT's process must be fixed. A widely used cycle, and one worth carrying into the exam:
- Situation — what do we know, what do we not know, and what is our confidence in each?
- Impact — on life safety, on customers, on obligations, on reputation, on finances
- Objectives — what must be true in 24 hours, in 72 hours, in a week?
- Options — at least three, with consequences and who is disadvantaged by each
- Decision — taken, owned, timed, and logged
- Communication — who is told what, by whom, when
- Review — next meeting time and what evidence is needed by then
Life safety leads every cycle and overrides every commercial consideration (Section 8.1). A CMT that opens with financial exposure has already made an error an auditor and a court will both notice.
3. Documenting the Incident
PECB lists "Knowledge of documenting an incident" as a Domain 4 knowledge statement, and it is examined as a discipline, not as a form.
The contemporaneous rule
Records must be created as events unfold, not reconstructed afterwards. A log written after the event records what people now believe they knew; a contemporaneous log records what they actually knew, which is the only basis on which a decision can fairly be judged. Reconstructed logs also carry little evidential weight in litigation or regulatory investigation.
Three distinct records are required, and merging them is a common failure:
| Record | Captures | Kept by |
|---|---|---|
| Incident / event log | Facts and events with timestamps: what happened, what was observed, what was reported, by whom | Loggist / incident support |
| Decision log | Decisions with rationale: what was decided, by whom, on what information, what alternatives were rejected and why | Loggist for the CMT |
| Action log | Tasks assigned: action, owner, deadline, status, closure evidence | Incident/crisis coordinator |
What a decision log entry must contain
The entry that is defensible three years later has six fields:
- Timestamp — with time zone, for multi-jurisdiction incidents
- Decision-maker — by name and role
- Information available at the time — including the known unknowns
- The decision
- Rationale, including options rejected
- Review trigger — the condition under which the decision will be revisited
The phrase "information available at the time" is what protects the decision-maker. A decision to keep a plant running that later proves wrong is defensible if the log shows the data then available reasonably supported it; the same decision is indefensible if no record exists.
Practical logging discipline
- Appoint a dedicated loggist. A CMT member cannot both participate and log reliably; logging is a full-time role during a crisis and should be exercised.
- Log in ink or in an append-only system. No erasures. Corrections are struck through, initialled, and timed — never overwritten.
- Number pages and record attendance, including arrival and departure times of members.
- Assume disclosure. Every entry may be read by a regulator, an insurer, a claimant's counsel, or a public inquiry. Write facts and reasoning; do not speculate on blame or liability in the log.
- Preserve technical evidence alongside the narrative — system logs, alerts, and notification-system delivery reports — with retention aligned to the organization's documented retention rules (Section 4.3).
Where the records go
Incident documentation is not an end in itself. It feeds four processes:
- Post-incident review — the incident equivalent of the After-Action Report in Section 9.3, generating findings and a corrective action plan
- Regulatory and contractual notification — proving that the 72-hour, 24-hour, or 6-hour clocks in Section 8.3 were met
- Insurance and legal — substantiating business interruption claims, which typically require evidence of loss magnitude and of mitigation efforts
- Clause 10.1 corrective action — the root cause analysis and systemic fix that prevents recurrence (Sections 10.3 and 11.4)
An incident that is closed without a documented review has produced cost and no learning, and it is a nonconformity waiting to be found: Clause 10.1 requires the organization to react to nonconformity, evaluate the need for action to eliminate its causes, and retain documented information as evidence.
4. Worked Implementation Scenario: A Food Manufacturer's Contamination Crisis
Context. A mid-sized food manufacturer supplying four national grocery chains detects, through routine end-of-line testing, a possible allergen cross-contamination in a product line dispatched over the preceding nine days.
Why this is a crisis and not merely an incident. No production line is down. No RTO is breached. No BCP requires invocation. Yet the consequences are strategic: consumer safety, mandatory regulatory notification, a potential public recall, four commercial relationships, and brand survival. The Operations Director escalates and the CEO declares a crisis at 14:20.
Capability, not procedure. The crisis management plan contains no "allergen contamination playbook" — and does not need one. What it provides is the CMT roster with deputies, a 45-minute convening target, pre-authorised spend of up to $2m for recall logistics without board approval, a nominated spokesperson, pre-drafted holding statements, and the standing agenda.
The cycle in action (first meeting, 15:05).
- Situation: one positive result, retest pending at 18:00; nine days of dispatch; approximately 240,000 units in trade; distribution records available. Known unknown: whether the result is a false positive.
- Impact: potential anaphylaxis risk to allergic consumers — life safety, therefore first.
- Objectives: no consumer harm; regulator notified within statutory window; retailers informed before they hear it elsewhere.
- Options: (a) await retest before acting; (b) immediate precautionary withdrawal from retailers with public recall held pending retest; (c) immediate full public recall.
- Decision: option (b), taken by the CEO at 15:40.
- Rationale logged: a three-and-a-half hour wait for retest was judged an unacceptable exposure on a life-safety risk, while a full public recall on a single unconfirmed result would be disproportionate and could not be reversed. Review trigger: the 18:00 retest result.
The documentation that mattered. A dedicated loggist recorded the meeting. The retest at 18:20 confirmed contamination and the CMT escalated to a full public recall at 18:35, logged against the pre-set review trigger.
Outcome. No consumer illness was reported. During the subsequent regulatory investigation, the decision log demonstrated that a precautionary withdrawal had been initiated before confirmation, on a documented life-safety rationale. The investigator's report noted the promptness of precautionary action as a mitigating factor. The post-incident review traced the root cause to an unvalidated line-changeover cleaning procedure, and the resulting Clause 10.1 corrective action revised the procedure and added a verification swab step across all lines.
Had the CMT waited for certainty before acting, or had it acted identically but kept no contemporaneous record of why, the same facts would have supported a very different regulatory conclusion.
5. PECB Exam Warning Traps & Implementation Pitfalls
[!WARNING] Trap 1 (Crisis management plan is not a bigger BCP): They differ in kind, not degree. A BCP restores prioritised activities to MBCO and is operational and procedural. A crisis management plan governs strategic consequences and is about leadership, decision authority, and communication. An exam option describing a crisis plan as "the plan invoked when the BCP is insufficient" is wrong — a crisis may involve no continuity disruption at all.
[!WARNING] Trap 2 (Scripting the unscriptable): Crisis plans specify capability — who convenes, who decides, what authority they hold, how information flows — not step-by-step procedures. An organization proud of its scenario-specific crisis playbooks has misunderstood the problem.
[!WARNING] Trap 3 (Escalation authority vs. declaration authority): These are deliberately different. Anyone must be able to escalate a concern; only named roles may declare a crisis. A plan permitting only senior managers to raise an alarm has designed in the delay that turns incidents into crises.
[!WARNING] Trap 4 (Contemporaneous means during, not after): A log written after the incident records hindsight. Its value in post-incident review, regulatory investigation, and litigation depends entirely on capturing what was known at the time, including the unknowns.
[!WARNING] Trap 5 (Separate the three logs): Events, decisions, and actions are distinct records. Merging them into a single narrative loses the decision rationale — the one element that makes the record defensible — and makes action closure impossible to track.
[!WARNING] Trap 6 (ISO 22361 is guidance): It offers recommendations for a crisis management capability and is not certifiable. Options claiming an organization can be "certified to ISO 22361" or that ISO 22301 "requires conformity with ISO 22361" are wrong.
A pharmaceutical company faces a regulatory investigation into whether its clinical trial data was falsified. No system is offline, no facility is unavailable, no activity has breached its RTO, and no business continuity plan has been invoked. How should this situation be classified?
A crisis management team convenes and a member proposes that the team first quantify the financial exposure and the likely share-price impact before addressing anything else. Applying the standing agenda for crisis decision-making, what is wrong with this proposal?
Two years after a major outage, an organization faces a regulatory investigation into whether its decision to delay customer notification was reasonable. Which documentation practice most directly determines whether that decision is defensible?