What risk management should hand off before a crisis is not a register or an appetite statement. It is the live assumptions the decision depends on, the signal that says those assumptions have broken, and the name of the person who owns the first call.

Most organisations have both a risk function and a crisis response capability; almost none have a written handoff between the two. ISO 31000 tells organisations how to manage risk, and ISO 22361 tells them how to manage a crisis. In nearly fifty years of professional work, I have never found the document that connects them: the one that specifies what the risk function must finish and deliver before an operational decision has to be made under pressure.

The two disciplines were built by different committees, taught by different consultants, and audited by different assessors, each of whom can certify compliance without ever asking whether the outputs connect.

When that gap is exposed, the response is usually to blame the risk function for missing the specific event, or the crisis team for not consulting the register. Neither accusation is fair. The risk function had recorded the category of event in its governance language; the crisis team needed operational instructions it could act on in the first hour. Nobody had specified what risk management should hand off because nobody's performance was ever measured by whether the handoff existed.

What risk management should hand off before a crisis is the pre-agreed transfer of assumptions, escalation triggers, and decision authority to whoever makes the first operational call when conditions break.

Why No Standard Covers What Risk Management Should Hand Off

The COSO Enterprise Risk Management framework, updated in 2017, describes five interrelated components and twenty principles for managing risk as a strategic discipline. Thomas Holland, a principal contributor to the COSO ERM Compendium, examined how those programmes performed during the pandemic and published his assessment through Guidehouse in 2021. The framework assumes a continuous loop: assess risk, design a response, monitor for variance. It never defines the moment that loop breaks because events are moving faster than the cycle time.

Two columns comparing what risk management files versus what the crisis team needs showing the handoff gap
The register described the risk. The crisis team needed the assumptions.
Click to expand

I have sat in post-incident reviews where the crisis team described improvising for the first seventy-two hours while the risk function produced a register that had, technically, listed the category of event. Both groups were telling the truth. The register described the risk in governance language; the crisis team needed live assumptions and a named decision authority. In every case I can recall, the register had never been designed for anyone outside the risk function to read, let alone act on under pressure.

That is the structural cause: the risk function was built to satisfy its own reporting chain, not to produce deliverables for a different team's operational moment.

Infectious diseases had sat on risk registers across most industries for years before 2020. The category was acknowledged, and the acknowledgement was a line item in a governance document that risk committees reviewed annually. Nobody had recorded which operational assumptions would fail first, how fast they could fail, or who had the authority to act when the committee's monitoring cadence proved too slow for the event.

What Risk Management Should Deliver Before Anyone Needs It

GBTEC's analysis of pandemic-era risk management found that business continuity plans were typically scoped to IT outages and localised disaster recovery, not to cross-continental operational disruption. Risk registers listed "pandemic" as a line item without any operational handoff to the people who would need to act.

I have watched this pattern in every industry I have worked in: the risk function finishes its assessment, files it in the governance cycle, and nobody asks whether the crisis team has ever seen it, let alone tested whether its outputs would survive contact with a fast-moving event.

A crisis-management plan is a secondary element of the decision it was built to protect: a resource prepared in advance to support the primary call when implementation does not proceed as assumed. It has value when tied to a specific assumption and a specific trigger; it becomes decoration when nobody in the room can say which assumption it covers or what signal would mean the plan no longer applies.

I have reviewed crisis-management plans that prescribed roles, communication trees, and escalation procedures in careful detail but never once recorded the assumptions those procedures depended on. The procedures were thorough. The connection to the live decision was absent.

That is what risk management should hand off: not the register, but the assumptions buried inside it. For each prepared action, someone needs to have recorded which assumptions it depends on, what signal means those assumptions have broken, and who has the authority to act without convening a committee. If the risk function cannot answer those questions for every contingency it maintains, the contingency is paperwork.

Name the assumptions your crisis plan depends on and record who acts first when the risk register stops being enough. Start the Walk →

Where the Handoff Breaks

The Canadian firm Stikeman Elliott identified five specific pitfalls in the gap between risk management and crisis response, publishing them in 2018, two years before the pandemic confirmed every one.

Their central observation was that most organisations never define in advance who owns the transition from monitoring a signal to acting on it. They investigate without a plan for the investigation; they fail to determine who needs to know and when; they underestimate how fast events escalate beyond the scope of the original monitoring arrangement.

BCMMetrics produced the most concrete handoff model from the business continuity side: a documentation template covering what happened, what actions have been taken, and who owns the next step.

That is closer than most frameworks get, and it is still not enough. It tells the crisis team what has happened since the trigger fired; it does not tell them what was assumed to be true before the event, what monitoring was designed to catch the variance, or what decision authority had already been assigned. The crisis team inherits a situation report when it should be inheriting a decision record.

If your crisis playbook tells people what to do but never says what would make those instructions wrong, the handoff has not happened; the plan has simply been filed in a different folder.

The Universal Decision-Making Method closes this gap by building monitoring into the decision at the time the decision is made, not as a separate governance exercise afterward. Monitoring is a secondary element designed when the Decider has the greatest awareness of the assumptions and is therefore best placed to specify what to watch and how often; deferring it to a different team or a different cadence severs the connection between the assumption and the person who understood why it mattered.

I have seen this consistently across nearly fifty years. The risk function and the crisis team each maintain documents that pass their own audits. When a crisis arrives, the crisis team starts cold because it does not know what was assumed to be working, and the risk function cannot help because its outputs were never designed to survive the transition from governance to operations. That is where leadership under pressure either holds or fails: at the handoff point nobody built.

What the Handoff Changes

When the handoff is designed, the monitoring cadence matches the speed at which assumptions can fail, not the speed at which the governance committee meets. I have worked with organisations where the monitoring cycle ran quarterly while the assumptions it tracked could break in days; the cadence was set for the committee's calendar, not for the decision's exposure.

Pre-assigning decision authority to someone close enough to the signal to respond before the situation compounds is what turns the handoff from a procedural artefact into a functioning transfer of accountability.

The gap persists because closing it would disturb comfortable arrangements. The risk function's register survives its audit whether or not anyone can use it during a crisis. Consultants sell risk services and crisis services as separate engagements (separate scopes, separate fees); the handoff would merge two revenue streams into one.

Auditors certify ISO 31000 and ISO 22361 independently, and nobody's assessment is marked down for failing to ask whether the two outputs connect. I have sat in rooms where every party at the table had a professional interest in the gap remaining unnamed, and not one of them would have described it that way.

Most crisis management strategies lack this handoff because naming assumptions exposes how fragile the original call was. The risk register describes risks in the abstract; the crisis management plan describes roles and procedures. Neither translates what the risk function knew into what the crisis team needs in the first minutes of an event. The two documents look complete; the connection between them does not exist.

The fix is not another standard. It is a decision discipline: at the time a risk is registered, record what would have to change for the prepared response to be wrong, and assign someone to watch for that change. Hand that to the crisis team before they need it.

If the risk function's only output is a register that describes risks without specifying what should be handed off to the crisis team before the situation breaks, the function is producing governance theatre, not crisis readiness.

You could file the risk register and the crisis plan in the same folder and still leave nobody holding the handoff.

Work through your decision

No sign-up. Just pick your decision and start.


Grant Purdy is the co-author, with Roger Estall, of Deciding (2020), and the architect of the Universal Decision-Making Method.