Crisis management plan examples that actually work under pressure share three elements every template leaves out. Stated assumptions the plan depends on. A named owner responsible for verifying each assumption still holds. And a defined trigger that tells the organisation when the scripted response should stop and a fresh decision is needed.

An operations director I worked with showed me her plan. It ran to 14 pages: eight committee members, three escalation paths, two external counsel phone numbers, a media holding statement pre-approved by legal. She opened it when a supplier lost a shipping container of customer data. The plan told her who to call. It did not tell her what to decide. She did not know which assumptions the plan depended on, whether any still held, or when the scripted response should be abandoned in favour of a different call.

Her plan had procedures. It did not have foundations. The difference between that plan and one that works is not length or formatting. It is whether the document records what it depends on.

A crisis management plan is a set of pre-built responses to scenarios an organisation has already imagined, assigning roles and initial actions so the first minutes of a crisis are not spent deciding who does what.

How Aviation Builds Plans That Survive Contact

I have spent close to fifty years working with organisations that face decisions under pressure, and the best crisis management plan example I can point to is one most people would never associate with crisis management: civil aviation maintenance records.

Every commercial aircraft carries a permanent maintenance record that transfers with it when the aircraft is sold. The record does not simply list what work was done. It records what was checked, what was assumed serviceable, what evidence supported that judgment, and what the basis was for continuing operations. If a component inspection was deferred, the record states why and when the deferred check must occur. When a regulator investigates, when an insurer assesses a claim, when a buyer evaluates a purchase, that record is the first document reviewed. It is not paperwork. It is the decision trail that defends every call the maintenance team made.

What struck me when I first worked with these records was not their thoroughness but their honesty. A maintenance team that defers an inspection does not hide it. The deferral is entered, justified, and time-limited. The record does not pretend the aircraft is in perfect condition. It states what is known, what is assumed, and what must be checked by when. That is a standard no crisis management template I have ever reviewed comes close to meeting.

A crisis management plan works the same way when it records what most templates leave out:

Stated assumptions. "This plan assumes our backup data centre will be operational within four hours" is a testable claim. Someone can pick up a phone and verify it before the crisis arrives. "Activate backup systems" is not testable. It is an instruction that assumes the systems exist, that they are current, and that someone knows how to start them. Every time I have asked a crisis committee to list the assumptions their plan depends on, the room goes quiet. The assumptions were never written down. They were absorbed into the procedures and became invisible.

Named owners. A specific person responsible for confirming each critical assumption still holds, checked at a defined interval. Not the committee. Not "the team." One name, one assumption, one schedule. Aviation assigns every deferred inspection to an individual engineer with a recorded deadline. A crisis management plan needs the same discipline: if no individual is named, no individual checks, and the assumption drifts from fact to hope between annual reviews.

Decision triggers. The condition under which the planned response stops being valid and a named Decider must make a fresh call. Not "review annually." A specific trigger: "If supplier X loses their clearance to handle our data, this response pathway is suspended until a replacement is contracted." Without a trigger, the plan runs on regardless of whether its foundations still hold. This is what leadership under pressure actually requires: knowing when to stop following the script and start deciding.

The Universal Decision-Making Method treats these as the foundation of any decision worth defending: stated assumptions, sufficient certainty on those assumptions, and monitoring that catches the moment an assumption breaks. A crisis plan built on that foundation is not a longer document. It is a document that knows what it depends on.

Comparison of what crisis management plans record versus what they leave unstated, with FEMA and Grenfell as examples
What every plan records versus what no plan states. Sources: FEMA AAR 2018, Grenfell Inquiry 2019.
Click to expand

What FEMA's Hurricane Plan Was Missing

The United States Federal Emergency Management Agency maintained a detailed crisis management plan for hurricane response. It covered logistics chains, staffing allocations, communications protocols and resource pre-positioning across regions. FEMA's own after-action report, published after the 2017 hurricane season, documents what the plan had and what it was missing.

The plan assumed single-event staffing levels. When Hurricanes Harvey, Irma and Maria made landfall within weeks of each other, personnel deployed to Texas for Harvey were unavailable for Florida or Puerto Rico. The plan assumed mainland logistics infrastructure. Puerto Rico is an island with no land bridge for surface transport. FEMA had 695 generators in stock when Maria hit, nowhere near what was needed, and no advance contracts for bulk shipping to island territories. The plan assumed commodity supply chains would function under concurrent demand from multiple disaster zones. They did not.

The consequences were measured in weeks without power and months without stable housing for millions of people. A concurrent multi-event hurricane season was not unimaginable. Island logistics differ from mainland logistics in structural ways that surprise nobody in the field. The plan did not fail because FEMA lacked procedures. It failed because the assumptions embedded in the plan were never stated as assumptions. Nobody had written "this plan works only if one major hurricane makes landfall at a time" where it could be read, challenged and monitored. No owner was assigned to verify the single-event assumption before each hurricane season. No trigger existed to switch from single-event to concurrent-event protocols. The gap was not in the procedures. It was in the foundations, and every unchecked season compounded the cost of waiting.

Take your crisis plan and list the three assumptions it depends on, then ask who last verified each one. Start the Walk →

One Unstated Assumption at Grenfell Tower

Grenfell Tower in London had a fire safety plan. It relied on a "stay put" policy: residents should remain in their flats during a fire, protected by the building's compartmentalisation. The Grenfell Tower Inquiry Phase 1 Report found that the entire policy rested on a single assumption: the building's exterior would not carry fire from one floor to the next.

In 2015 and 2016, combustible cladding was added to the building's exterior walls. The assumption behind the stay-put policy was now false. The fire safety plan was not updated. No one was assigned to verify whether the assumption on which the entire policy rested still held after the renovation. No trigger existed in the plan to force a review when building materials changed.

On 14 June 2017, fire spread via the cladding within 12 minutes, defeating compartmentalisation completely. The stay-put advice remained in effect for another hour and 39 minutes because the London Fire Brigade was following the plan. By the time an evacuation order was issued, 61 flats were affected and 107 people were still inside the building. Seventy-two people died.

One stated assumption would have named what the policy depended on. One named owner would have checked it after the cladding was installed. One decision trigger would have suspended the stay-put advice the moment compartmentalisation could no longer be confirmed. The plan had been filed, distributed and accepted by every authority responsible. Three elements. All absent.

Why Most Plan Testing Misses the Point

The standard method for testing a crisis management plan is a tabletop exercise. The committee gathers, a scenario is read aloud, and participants walk through their assigned responses. A 2025 Delphi study published in Safety Science found that tabletop exercises systematically reinforce false preparedness. The exercise validates the plan's procedures. It does not challenge the plan's assumptions. Participants leave the room more confident in a plan whose foundations remain untested. A business wargame has the same weakness: its lessons inherit whatever the facilitators ruled plausible, so what to do after a wargame begins with testing those rulings.

The scale of the gap is visible in industry data. The Business Continuity Institute reports that 44 percent of organisations have never exercised their crisis plans at all. Nearly half of all plans exist as documents that no one has walked through even once.

An exercise that confirms people know the call tree is testing logistics. An exercise that asks "what if our supplier assumption fails on the same day our backup site is offline?" is testing the plan. The first type of exercise is common. The second is rare. Most crisis management examples in the public record are cases where the logistics were rehearsed and the assumptions were not.

Before the next exercise, try listing the five assumptions your plan depends on. For each one, ask who last verified it and what happens to the response if that assumption fails. That exercise will reveal more about the plan's readiness than walking through the call tree for the fourth year running. Once the next exercise has run, review what its scenario never tested before the improvement plan closes.

The Record That Defends the Call

Every crisis management plan example on the first page of a search engine promises a template with roles, communication trees and checklists. Those are useful for the first minutes of a crisis. They are not what separates a plan that works from one that collapses when the scenario arrives differently from the one imagined.

Aviation records assumptions, owners and triggers by regulation. FEMA's hurricane plan did not record them at all. Grenfell's fire plan rested on one assumption that had no owner and no trigger. The difference was not in the quality of the procedures. It was in whether anyone knew what the plan depended on.

A crisis management plan that survives reality records assumptions alongside actions, assigns ownership of those assumptions to named people, and defines the triggers that tell the organisation when the plan no longer fits and a new decision is required.

Open your plan and look for three things. The assumptions it depends on, written as testable claims. The name of the person who last verified each one. And the trigger that would tell you the plan is no longer valid. If you find roles, phone trees and checklists but not those three, you have a document. You do not yet have a plan that can survive what actually happens.

You could fill in every template field and still leave no record of what the plan assumed.

Work through your decision

No sign-up. Just pick your decision and start.


Grant Purdy is the co-author, with Roger Estall, of Deciding (2020), and the architect of the Universal Decision-Making Method.