Purpose and Scope
This policy sets out how [Organisation Name] responds to major operational disruptions at [Site Location(s)]. It applies to incidents that halt or severely impair our ability to trade, deliver services, or pay staff, not minor daily operational issues.
This policy applies to all personnel. The primary plan resides at [Location], with an accessible off-site copy stored at [Location/System].
Working through related paperwork at the same time? See also our US Business Continuity Plan Template, Customer Service Process Template and The Ultimate Action Plan Template.
Policy Statement
[Organisation Name] prioritises human life above all else. After securing personal safety, our priority is maintaining customer service and meeting obligations to staff, suppliers, and regulators. We keep this plan effective through realistic risk evaluations, continuous updates, and regular testing.
Roles and Responsibilities
- Continuity Lead ([Role]): Holds sole authority to activate this plan, leads emergency response, and serves as the single decision-maker during an incident. Deputy: [Role].
- Communications Owner ([Role]): Directs all internal and external messaging to personnel, customers, and suppliers.
- IT Lead ([Role]): Directs IT and data recovery, restores backups, and conducts initial assessments of data security incidents.
- All Personnel: Must know where this plan is stored, use designated internal communication channels, and refrain from speaking to the media or posting incident details on social media.
Planned Disruption Scenarios
- Premises Unusable (Fire, Flood, Damage, Loss of Access): Fallback arrangement is [Alternative Site / Remote Working / Mobile Operations].
- IT Failure or Cyber Attack: Fallback arrangement is [Backup and Restore System / Manual Workaround].
- Loss of Utilities (Power, Water, Gas): Fallback arrangement is [Safe Shutdown Procedures / Temporary Closure Criteria].
- Key Personnel Unavailable (Illness, Resignation, Emergency): Critical tasks and pre-assigned deputies follow designated recovery priorities.
- Key Supplier Failure: Alternative suppliers for critical items are documented in the contacts register.
Use our templates to fast-track your documentation
Customize this template and 100s of others for free in Whale, the fastest way to get your team aligned.
Plan Invocation Procedure
- Prioritise safety first. Follow site emergency response procedures (evacuation, first aid, emergency services) before taking action under this plan.
- The Continuity Lead (or Deputy) evaluates the situation, formally activates the plan, and logs the decision time.
- Convene the response team in person or via [Designated Channel] to assess operational impacts, estimated downtime, and active capability.
- Check whether personal data is compromised. If you suspect or confirm a data breach, activate breach procedures immediately to meet the statutory 72-hour reporting deadline.
- Notify the insurer ([Insurer Name / Policy Number]) and landlord [if applicable] before authorising site repairs or clean-up beyond initial safety controls.
- Execute recovery priorities, maintain an active log of all decisions and costs, and review status at least daily.
Communications During Disruption
- Internal Communications: The Communications Owner contacts personnel through [Channel, e.g. Phone Cascade / Automated Messaging]. The staff contact directory is maintained at [Location].
- External Communications: We inform customers and suppliers of operational impacts and updated schedules via [Website / Signage / Direct Contact].
- Media & Public Enquiries: Only the Continuity Lead or Communications Owner may issue public statements.
Recovery Priorities
- Within [Number] Hours: [e.g. Secure premises, secure stock and cash, contact personnel, redirect incoming deliveries].
- Within [Number] Days: [e.g. Restore payment systems, resume core operational services, contact primary clients and key suppliers].
- Within [Number] Weeks: [e.g. Restore full trading capability, replace damaged equipment, progress insurance claims, complete incident review].
- Critical Dependencies: [Task / Process, Primary Role, Designated Deputy Role].
Testing, Records, and Review
- Testing: Conduct a scenario walkthrough at least [Frequency, e.g. Annually].
- Contact Verification: Verify emergency contact lists at least [Frequency, e.g. Quarterly].
- Record Keeping: Store test logs, incident records, and operational decision logs at [System/Location].
- Review Cycle: Review this document [Frequency, e.g. Annually], following any plan invocation, after a significant near-miss, or upon major operational changes.
- Document Owner: [Role]
- Next Review Date: [Date]
FAQs on a business continuity plan
What is a business continuity plan?
A business continuity plan sets out how your organisation responds to major operational disruptions at your site. It applies to incidents that halt or severely impair our ability to trade, deliver services, or pay staff, not minor daily operational issues.
Having it written down means the same rules apply to everyone, so managers are not making judgement calls case by case under pressure.
What does a business continuity plan include?
This template covers planned disruption scenarios, plan invocation procedure, communications during disruption and recovery priorities.
Every section is written to be filled in. The bracketed placeholders mark the decisions that are yours to make, such as timescales, approval owners and retention periods.
How to implement a business continuity plan with Whale
Copy this template into Whale and work through the bracketed placeholders so it reflects how your organisation actually operates.
Assign it to the teams it applies to so it sits where people work rather than in a shared drive, and set a review date so it gets revisited on schedule instead of quietly going out of date.
Use our templates to fast-track your documentation
Customize this template and 100s of others for free in Whale, the fastest way to get your team aligned.
