A crisis playbook that tells you when to break it is worth more than one that pretends completeness. Each prepared action needs a stated assumption, an owner, a break trigger, and a reversal rule. Without those four fields, the playbook traps your team in a response designed for a crisis that no longer exists.

I have watched a chief executive call for the crisis playbook at 7:20 am on a Monday. The question sounded administrative; it was not. Someone in that room had to decide whether the document described the situation in front of them and, if it did not, who had authority to depart from it.

That is why a crisis playbook should not be a tidy set of roles and pre-written actions. It is a prepared response that must remain open to judgement. A document that tells people what to do, yet gives nobody authority to stop doing it, has converted preparation into delay.

Four fields turn that principle into practice: an exit condition for each prepared action, a named decision owner, a break trigger tied to a stated assumption, and a reversal rule. Leave any one out and someone will have to improvise at the worst moment.

A crisis playbook is a documented set of prepared responses to a disruptive incident, with assigned authority and escalation arrangements.

Four labelled columns showing the fields each crisis playbook action needs: exit condition, named owner, break trigger, and reversal rule
Each prepared action needs four fields. Leave one out and someone improvises.
Click to expand

A Crisis Playbook Needs an Exit Condition

An exit condition says when the prepared action is no longer sufficiently reliable to continue. It is not an invitation to abandon a plan whenever somebody dislikes it. It is a stated condition, attached to a specific response, that tells the team the basis for that response has failed and a different decision is required.

Exit conditions are often left as the word "escalate" beside a contact number. That does not answer the question the person on the ground will face. Escalate because the customer impact is wider than expected? Because the source of the fault cannot be identified? Because the chief executive wants to be involved? Each could be a sensible reason in a particular organisation, but they lead to different decisions. The playbook has to say which condition applies to this action, who receives the escalation, and what authority moves with it. Otherwise people wait for permission while the evidence changes around them.

The UK Cabinet Office distinguishes a generic continuity plan from specific arrangements needed where the generic response will not be sufficient. Its guidance also says that plans need exercising and review at a frequency that reflects how quickly the organisation or its risk profile changes. The document must do more than note that exceptions exist. The people using the crisis management plan need to know what makes the ordinary response insufficient in this incident. The Cabinet Office guidance gives the useful distinction; the work is to turn it into a decision condition.

Roger Estall and I wrote in Deciding that crisis-management plans are contingent actions, not decisions in their own right. A contingent action may be exactly what is needed, but only while the conditions that made it appropriate remain true. The same applies to the emergency meeting, the manual work-around, or the instruction to keep a site operating. Calling it a playbook does not give it judgement.

Give a Crisis Playbook a Real Owner

A name in a contact list is not enough. The owner of a prepared action must have the authority to decide that its operating assumption is no longer sound. If the document requires a committee to notice the problem, convene, and seek an executive approval before anyone can change course, the plan has added a delay at the point where the organisation needs a decision.

FEMA's incident-management material treats a transfer of command as an event that may be required when the incident changes. The transfer requires a full briefing and a recorded effective time. A corporate plan does not need to copy an emergency-service structure, although it does need a plain record of who holds the authority and when that authority takes effect. FEMA's transfer-of-command guide is more explicit about this than many corporate plans.

Authority must be decided before the incident, particularly where the board expects to be kept informed but is not equipped to run the response. That distinction protects the operating team and the board. The board may set constraints or require notice at a threshold; it should not become an unplanned approval gate for an action that needs to be changed within an hour. The nominated owner must know the boundary of the delegation, including the point at which a wider decision is required. The owner should make that boundary visible in the first briefing, before anyone is asked to act.

The owner also needs a defined purpose. During the 2017 NotPetya disruption, A.P. Moller - Maersk reported losses of USD 250-300 million in disruption, lost revenue and restoration costs, while customer service across its transport and logistics businesses was disrupted. I cannot say from its annual report which response decisions were available inside Maersk at the time. A recovery instruction built on an assumption of normal systems and reliable information is already broken when neither is available. Maersk's 2017 annual report records both the disruption and the later changes to resilience and recovery arrangements.

Open your crisis playbook and find the action that has no exit condition, before the next incident runs it past the point where it helps. Start the Walk →

Write the Trigger and Reversal Rule Before the Incident

The operating assumption belongs beside the action, in ordinary language. A product-recall holding action may depend on the assumption that the affected batch can be identified. A data response may depend on the assumption that the investigation team can still trust the relevant logs. The assumption does not have to be comforting; it has to be visible enough that someone can test it.

The trigger is the observable result that ends the default response. It needs to be specific enough to bring the authorised owner into the decision, rather than leave staff arguing about whether events feel serious. If the batch cannot be identified by a stated time, the response changes. If the logs cannot be relied upon, the investigation is treated differently.

The point is not to pretend that every fact can be anticipated. It is to identify the condition whose failure removes enough certainty to continue with the present action.

I have watched teams avoid writing that condition because it feels like admitting the plan could be wrong. The omission does not make the plan stronger. It leaves the first person to notice the variance arguing from instinct, while the person with authority assumes that silence means the response is still working. The team ends up following a crisis plan that no longer fits while everybody assumes it still does.

The reversal rule then states the first action after the trigger. It should be reversible where that is possible, because a team with damaged information should avoid committing itself further merely to look decisive. It must also say how the change is recorded and when the new position is reviewed. A reversal without a new review point is simply another unexamined instruction. That discipline, testing the assumption and recording the change, is the substance of leadership under pressure.

Exercises are where these fields are exposed. The Cabinet Office's exercise guidance cites a Chartered Management Institute survey in which 78% of organisations that had exercised their plans found shortcomings. That finding should not surprise anybody who has tested a plan against a change in conditions rather than a confirmation of the script. The exercise guidance treats rehearsal as validation and improvement, which is the right starting point.

Exercise the Hand-Off, Not Compliance

An exercise should force a change in the basis for action and make the team deal with it. Give the response owner information that weakens the assumption. Require that person to decide whether the trigger has been met. Then make the authority transfer, the briefing record, and the first reversible action happen under the same constraints that apply to decision-making under pressure. A test that merely confirms people can find their pages says almost nothing useful.

ISO 22301 treats business continuity as a managed system, not a filed document. The standard rejects the idea that a plan can be written once and left alone, which is the right starting position. However, the document cycle only earns its keep when a person can use it to make the current decision. A review date on the calendar is no substitute for a signal that arrives before the next scheduled review. ISO 22301:2019 supplies the lifecycle; the hard part is deciding what signal must reopen the response before circumstances make the document irrelevant.

Every change to the prepared response should leave a short record. It does not need to be a report written after the pressure has passed. The record should identify the decision and the condition that changed it. It should also name the person who made the call and state the next review time. A later hand-over becomes much less dangerous when the incoming owner can see why the previous action ended and what evidence is still being watched.

The Universal Decision-Making Method gives this structure a sequence: state the purpose of the response, identify the assumption it depends on, decide who tests that assumption while the incident is live. The leader has to leave a record of why the response was reasonable when it was made, and what would tell the organisation it was no longer reasonable.

You could rehearse the playbook and still leave no one authorised to abandon it.

Work through your decision

No sign-up. Just pick your decision and start.


Grant Purdy is the co-author, with Roger Estall, of Deciding (2020), and the architect of the Universal Decision-Making Method.