Professionals coordinating a crisis response in a business continuity operations room

How to Build a Crisis Governance Structure for Business Continuity

To build a crisis governance structure, define the outcomes that must be protected, assign strategic, tactical and operational decision rights, establish activation and escalation thresholds, create a verified information process, connect crisis leadership to business continuity and recovery, and test the whole arrangement through exercises and independent assurance.

A crisis structure should make decisions faster without abandoning accountability. It must answer six questions under pressure: who leads, what they can decide, what information they need, how priorities are set, who communicates, and how the organisation moves from response to sustained recovery.

Key takeaways

  • Build the structure around decisions and outcomes, not job titles alone.
  • Separate strategic direction from tactical co-ordination and operational command.
  • Activation criteria, delegated authority and escalation triggers should be agreed before an incident.
  • Business continuity plans supply service priorities and recovery options to the crisis team.
  • Exercises must test authority, information, handovers, communications and recovery—not merely plan recall.

What is a crisis governance structure?

A crisis governance structure is the temporary but pre-authorised system used to direct, co-ordinate and control an organisation’s response to a severe, uncertain and consequential situation. It links the governing body and senior leaders with incident management, business continuity, specialist advice, stakeholder communication and recovery.

Crisis governance is wider than emergency response. Emergency teams may protect life, property or a technical environment. Business-continuity teams maintain priority products and services. The crisis team integrates those efforts, resolves cross-functional trade-offs, protects legitimacy and decides how the organisation will recover.

ISO 22301:2019 describes a business continuity management system as a framework for planning, implementing, operating, monitoring, reviewing, maintaining and continually improving the organisation’s ability to protect against, reduce the likelihood of and recover from disruptive incidents. That management-system logic is important: crisis arrangements require leadership, resources, evidence, evaluation and improvement, not only a response plan.

How to build a crisis governance structure in nine steps

1. Define protected outcomes and scope

Identify what the organisation must protect: people, essential services, legal obligations, customers, data, assets, cash, reputation and public trust. Define which entities, sites, services, outsourced activities and jurisdictions are in scope. A structure designed only around headquarters may fail when authority, operations or stakeholders are distributed.

Translate broad aims into priorities that can guide decisions. “Maintain operations” is too vague. “Protect life, continue the emergency customer channel, meet statutory notification duties and restore priority payments within the approved time objective” is decision-ready.

2. Set governance principles

Agree the principles that apply when facts are incomplete: protect life; comply with law; use the lowest appropriate decision level; escalate cross-boundary consequences; document material decisions; communicate verified information; and preserve options for recovery. Principles provide consistency when a plan cannot predict the event.

The UK Cabinet Office’s Emergency response and recovery guidance identifies anticipation, preparedness, subsidiarity, direction, information, integration, co-operation and continuity as underpinning principles. Although written for UK responders, these concepts provide a useful challenge for organisational design when adapted to the relevant jurisdiction.

3. Create three decision levels

Use distinct but connected levels:

  • Strategic: sets the aim, approves major trade-offs, allocates exceptional resources, engages the board and owns high-consequence external decisions.
  • Tactical: co-ordinates functions, converts the strategic aim into objectives, resolves dependencies and manages the common operating picture.
  • Operational: controls activity at the incident, service, site or technical level within delegated authority.

The labels can vary. The important point is to prevent senior leaders from micromanaging tasks while operational teams make strategic commitments without authority.

4. Assign roles, deputies and decision rights

Name a crisis director, co-ordinator, information lead, continuity lead, communications lead, legal or compliance adviser, people lead, security or safety lead, technology lead and recovery lead as relevant. Every critical role needs a trained deputy and a handover method.

Use a decision-rights schedule that states who may close a site, suspend a service, notify a regulator, make a public statement, approve emergency expenditure, share sensitive information, invoke a supplier contingency, accept temporary risk and declare transition to recovery. Record consultation requirements without creating approval chains that are too slow for the risk.

5. Establish activation, escalation and stand-down criteria

Activation should depend on consequences and co-ordination needs, not on a perfect diagnosis. Possible triggers include risk to life, loss of a priority service beyond tolerance, material data compromise, multi-site impact, regulatory notification, intense stakeholder concern, resource conflict or uncertainty that exceeds normal management capacity.

Define who can activate the team, how members are alerted, the initial meeting deadline and the minimum quorum. Escalation triggers should identify when the board, parent entity, insurer, authority, customer or emergency service must be engaged. Stand-down criteria should confirm ownership of residual issues and continuing monitoring.

Three-level crisis governance structure for strategic tactical and operational decisions
Distinct decision levels reduce duplication while preserving escalation and delegated authority.

6. Design the information system

Create one common operating picture with time-stamped facts, assumptions, unknowns, impacts, actions, decisions and forecasts. Assign sources and confidence levels. Separate the situation report from the decision log: one describes the current picture; the other records options, rationale, authority and follow-up.

Define update frequency, access control, alternative communication channels and records retention. Leaders should receive concise information that supports decisions, while operational teams need detailed task and dependency data. The information lead should challenge unverified claims and reconcile conflicting sources.

7. Connect continuity, response and recovery

The crisis team needs outputs from business impact analysis: priority activities, maximum tolerable disruption, recovery time objectives, minimum resources, dependencies and workarounds. It should also know the limitations of each continuity option.

Define transition points between immediate response, continuity operation and recovery. Recovery should begin while response is active, because temporary workarounds can create financial, safety, conduct and control risks. The UK Government Resilience Framework emphasises strengthening the systems and capabilities that support collective resilience; the organisational equivalent is to connect risk understanding, preparedness, response capability and learning rather than maintain isolated plans.

8. Build stakeholder and communication governance

Map employees, customers, regulators, emergency services, suppliers, insurers, communities, media and governing bodies. For each, define accountable owner, information need, channel, approval route and timing. Pre-approved holding statements can accelerate initial communication, but they must never substitute for verified, incident-specific facts.

One spokesperson does not mean one communication team. Legal, operations, people and customer functions should feed a common message process. Track what was said, to whom, by whom and when. Correct material errors openly and quickly.

9. Resource, exercise and assure the structure

Provide secure meeting facilities, collaboration tools, contact data, alternates, emergency spending, specialist advisers and resilient communications. Training should cover role decisions and information discipline rather than plan memorisation.

Use a progressive exercise programme: notification tests, role walkthroughs, decision exercises, technical simulations and multi-party scenarios. Capture actions with owners and deadlines. The UK National Cyber Security Centre’s incident-management guidance is a useful specialist reference for preparing response capability to cyber incidents, but cyber playbooks should connect to the organisation-wide crisis structure when consequences extend beyond technology.

Crisis roles and decision rights

Role Primary accountability Typical decisions
Board or governing body Oversight of resilience and management response Challenge material risk, approve extraordinary strategic changes, oversee recovery
Crisis director Strategic aim and integrated decisions Priorities, resource trade-offs, major stakeholder commitments, risk acceptance
Crisis co-ordinator Team rhythm and decision process Agenda, action tracking, escalation, handovers and meeting cadence
Information lead Common operating picture Evidence standards, situation reports, uncertainty and information gaps
Continuity lead Priority service continuity Workarounds, recovery sequence, resource dependencies and service restoration
Communications lead Coherent stakeholder information Message timing, channels, spokesperson support and correction of errors
Legal or compliance adviser Obligations and defensibility Notification duties, privilege where applicable, record preservation and constraints
Recovery lead Transition and sustainable restoration Recovery structure, exit from workarounds, remediation and lessons

Specialists advise; accountable leaders decide. Where a specialist has statutory or professional authority, document that boundary explicitly. Internal audit should normally remain independent rather than take operational command.

The minimum crisis information pack

  • strategic aim and current objectives;
  • verified incident summary and timeline;
  • people, service, legal, financial and stakeholder impacts;
  • priority activities and recovery tolerances;
  • assumptions, unknowns and confidence levels;
  • options with consequences and constraints;
  • decision log and unresolved escalations;
  • action owners, deadlines and dependencies;
  • communications issued and planned;
  • forecast for the next operational period.

Avoid dashboards that look precise but conceal uncertainty. Time-stamp every material figure, state the source and show where information is provisional.

Crisis common operating picture with facts impacts decisions actions and unknowns
A concise, time-stamped operating picture keeps decisions connected to verified evidence and uncertainty.

Worked example: loss of a critical service provider

A cloud provider suffers a regional outage that stops a customer service platform. Operational technology teams begin failover. The tactical team co-ordinates customer operations, data, suppliers, staffing and regulatory assessment. The crisis director sets three priorities: protect affected customers, restore the minimum viable service within tolerance and communicate verified facts.

The information lead records that the cause is unknown, the failover estimate has medium confidence and one customer channel remains available. The continuity lead compares manual and alternative-platform options. Legal and compliance advisers identify notification thresholds. Communications prepares messages for employees, customers and key clients using the same verified timeline.

When recovery exceeds tolerance, the crisis director approves emergency capacity and invokes the contractual escalation route. A recovery lead is appointed before service restoration to govern backlog, data reconciliation, temporary access and control exceptions. Stand-down occurs only when priority services are stable, residual actions have owners and the board has received the initial review.

How to test and assure crisis governance

Exercises should test observable performance:

  • Was the team activated within the target time?
  • Did members understand their authority and escalation duties?
  • Were facts distinguished from assumptions?
  • Did the strategic aim guide conflicting priorities?
  • Were continuity options based on current dependency and tolerance data?
  • Were stakeholders informed accurately and at the right time?
  • Did shift handovers preserve decisions, uncertainty and actions?
  • Was recovery governance established early enough?

Management owns remediation. Internal audit may evaluate design, exercise evidence and improvement tracking while preserving independence. The Global Internal Audit Standards support systematic planning, evidence-based conclusions, communication and monitoring of action plans.

Crisis governance checklist

  • Protected outcomes and priority services are explicit.
  • Strategic, tactical and operational decisions are separated.
  • Every critical role has a deputy and handover process.
  • Activation, escalation, regulatory notification and stand-down criteria are documented.
  • Delegated authority covers emergency spending, service suspension and risk acceptance.
  • A common operating picture and decision log have named owners.
  • Continuity strategies, supplier dependencies and recovery tolerances are current.
  • Stakeholder communication uses verified facts and recorded approvals.
  • Exercises test decisions, information flow and recovery transition.
  • Lessons become funded actions with deadlines and independent follow-up.

Build business continuity and crisis-governance capability

Explore EPW’s Auditing, Governance, and Risk Compliance Training Courses. Related programmes include Enterprise Risk Management Frameworks and Strategies and Third Party Risk Management and Due Diligence.

To practise crisis structures, continuity priorities, scenario analysis, decision rights, communication and recovery governance, review EPW’s Business Continuity Risk and Crisis Governance course. View current dates and locations or request a tailored in-house programme.

Conclusion

A sound crisis structure converts urgency into disciplined action. Define the outcomes, separate decision levels, delegate authority, establish activation triggers, build a verified information process and connect response with continuity and recovery. Then test the structure until people can use it under pressure without relying on improvisation or a single individual.

Sources and References

  1. International Organization for Standardization. ISO 22301:2019 Security and resilience — Business continuity management systems — Requirements. Published October 2019; Amendment 1 published 2024. Accessed 10 September 2026. https://www.iso.org/standard/75106.html
  2. UK Cabinet Office. Emergency response and recovery. Published 20 February 2013. Accessed 10 September 2026. https://www.gov.uk/guidance/emergency-response-and-recovery
  3. UK Cabinet Office. The UK Government Resilience Framework. Published 19 December 2022; updated 4 December 2023. Accessed 10 September 2026. https://www.gov.uk/government/publications/the-uk-government-resilience-framework
  4. UK National Cyber Security Centre. Incident management guidance. Accessed 10 September 2026. https://www.ncsc.gov.uk/collection/incident-management
  5. The Institute of Internal Auditors. Global Internal Audit Standards, 2024 edition, effective 9 January 2025. Accessed 10 September 2026. https://www.theiia.org/en/standards/2024-standards/global-internal-audit-standards/