How to Write an Emergency Response Plan: Which Scenarios It Should Cover, Who Holds Which Role, and What Triggers Activation at Three in the Morning

The First Twelve Minutes Belong to Whoever Is Already There

Published 2026-09-25 · EuroQuest International

Quick summary

  • It covers the first hours, not the recovery. An emergency response plan protects people and stops the situation getting worse. Restoring the business is a different document with a different owner.
  • Plan for effects, not for causes. A building you cannot enter is one scenario whether the reason was fire, flood, a gas leak or a police cordon. Five effect-based scenarios cover more ground than thirty hazard-based ones.
  • Name roles, never people. A plan naming individuals expires the first time somebody resigns, and it fails at two in the morning when that person does not answer.
  • Activation needs a threshold, not a judgment call. Write down what condition triggers what level, so the person on site is confirming a rule rather than deciding a career question alone.
  • Exposure is rising even as deaths fall. Global disaster mortality per 100,000 people fell by 49 percent between two recent ten-year periods, while the number of people affected rose by 71 percent.

Something happens at 06:40 on a Saturday. A smell of gas in a plant room, a flooded basement, an assault in a car park, a contractor who has stopped responding on a roof. Whoever is standing there has two problems at once: deciding what to do, and deciding who to tell. An emergency response plan exists so that neither of those is invented on the spot. It is the shortest, most operational document an organization owns, and it is the one most likely to be written once, filed, and never opened again until the morning it is needed.

This guide covers what an emergency response plan is and where it stops, which scenarios genuinely need to be in it, how to assign roles that survive staff turnover, what should trigger activation, what belongs in the document versus in an annex, and how to find out whether any of it works. It is a process guide and not legal, regulatory or safety advice. Duties differ by jurisdiction, sector and site, and where a regulator prescribes a plan's contents, a review cycle or a drill frequency, that requirement governs and should be treated as a floor rather than a target.

On this page

  1. What is an emergency response plan, and where does it stop?
  2. Which scenarios should the plan actually cover?
  3. Who holds which role once it starts?
  4. What triggers activation, and who is allowed to call it?
  5. What belongs in the plan, and what belongs in an annex?
  6. How do you find out whether the plan works?
  7. Frequently asked questions
71%
Rise in disaster-affected people per 100,000 population between 2005 to 2014 and 2014 to 2023, while mortality over the same periods fell 49 percent, in the Sendai Framework Monitor
6 steps
In the planning process set out by the US emergency management agency, revised to bring businesses and infrastructure operators into planning alongside public bodies, in its planning guide
Grade 3
The level at which the World Health Organization mobilizes assets across the whole organization, one of three written grades in its emergency grading procedure

What Is an Emergency Response Plan, and Where Does It Stop?

An emergency response plan sets out what people do in the first minutes and hours of a situation that threatens life, health, the environment or the site itself. Its purpose is narrow and urgent: get people safe, stop the situation escalating, summon the right help, and tell the right people. Everything about the document should serve someone reading it under pressure, in poor light, possibly on a phone, possibly having never read it before.

That narrowness is the most useful thing about it, and the most commonly lost. Plans grow because every function wants its concerns represented, and a document that started as eight usable pages becomes sixty that nobody opens. The test for any sentence is whether someone would act on it within the first two hours. Insurance notification procedures, media strategy, payroll continuity and supplier substitution are all real obligations, and none of them belongs in the first two hours.

It Is Not a Business Continuity Plan

The two are routinely merged, and merging them is why so many organizations have a document that is too long to use in an emergency and too shallow to guide a recovery. Emergency response protects people and contains the event. Business continuity restores the delivery of products and services afterward, over days and weeks, and answers questions about alternate sites, minimum staffing and acceptable downtime. They have different time horizons, different decision-makers and often different regulators. Keep them as separate documents that reference each other, and be explicit about the handover point, which is usually the moment the site is declared safe and the question shifts from protection to restoration. Teams that own both usually build the two disciplines together through crisis management and business continuity training.

It Is Not a Risk Assessment, and It Is Not Your Communications Plan

A risk assessment is the input. It establishes what can go wrong, how likely it is, and how bad it would be, and the response plan is built on its conclusions rather than replacing them. If you have not done that work, the earlier guide on how to conduct a risk assessment comes first. Equally, what you say publicly during an incident is a separate discipline with separate skills and separate timing pressures, covered in the guide to building a crisis communication plan. The response plan should say who notifies the communications lead and by when. It should not try to draft the statement.

A wider point about scope that plans tend to miss: the people responding are themselves exposed. The US National Institute for Occupational Safety and Health puts it plainly, noting that emergency response and recovery workers "are a common denominator at any disaster or novel emergency event", and that preparedness and response activities should address those workers' safety and health before, during and after an event. A plan that protects everyone except the people carrying it out has a gap in it.

Which Scenarios Should the Plan Actually Cover?

This is where most plans go wrong, and they go wrong in a specific, predictable way: by organizing around causes. A hazard register produces a long list of things that could happen, and a plan written from that list produces a chapter for each one. Thirty chapters, each with its own procedure, most of which say very nearly the same thing.

Plan for Effects, Not for Causes

Organize instead around what the event does to you. A building you cannot enter is one scenario, and it does not much matter to the first hour whether the cause was a fire, a flood, a gas leak, a structural fault or a police cordon around the street. The actions are the same: account for everyone, keep them somewhere safe, find out how long, decide what happens to the people who were meant to be working. Five or six effect-based scenarios will cover almost everything a site faces.

A serviceable set for most organizations: a site you cannot occupy, a casualty or fatality on the premises, a release of something hazardous, a loss of a critical utility or system, a security or violence incident, and a large number of people suddenly unavailable. Each gets a short, concrete procedure. Cause-specific detail, where it genuinely differs, goes in a one-page annex rather than a chapter. Choosing between these on evidence rather than intuition is the substance of a risk-based approach to emergency management.

Let the Assessment Choose, and Say Why Something Is Out

Scenario selection should be traceable to the risk assessment, and the exclusions matter as much as the inclusions. If tsunami is not in the plan for an inland site, write one line saying so and why. This sounds bureaucratic until the first review, when somebody asks whether an obvious hazard was considered, and the choice between a documented decision and a silence is the difference between a plan and an oversight. The same logic applies to scale: planning for a wide-area event that closes roads and saturates the emergency services is a different exercise from planning for an incident confined to your fence line, which is why disaster risk reduction and emergency planning is usually treated as its own subject.

Who Holds Which Role Once It Starts?

An emergency reorganizes an organization for a few hours. The normal hierarchy is too slow and often the wrong shape, so the plan has to say what replaces it, who steps into each position, and how that is handed over when the shift changes or the right person finally arrives.

Name Roles, Never Individuals

A plan that says "call Sarah Whitfield" is out of date the day Sarah changes jobs, and useless at two in the morning when she does not answer. Name the role, define what it is responsible for and what it can authorize, then keep the people-to-role mapping in a contact annex that a named owner updates on a fixed cycle. The annex changes often; the plan itself should change rarely.

A workable minimum for a single site is four roles. An incident controller who owns the decisions and the priorities. A safety officer with standing authority to stop any activity, reporting to the controller but not overridable on a safety call. A communications and liaison role handling emergency services, the wider organization and the families of anyone injured. A logistics and welfare role finding the things the response needs, including food, shelter and relief for people who have been on their feet for six hours. Larger or multi-site organizations add structure above this, and at that scale the coordination problem becomes its own discipline, taught as managing large-scale public safety incidents.

Three Deep, and Someone Who Is Not on Site

Every role needs a first and second alternate, because the primary may be on leave, abroad, unreachable, or directly involved in the incident. Two names deep is the common standard and three is better, since the same conference, the same flight and the same building take out more people than anyone plans for. At least one alternate for the controller role should normally be based somewhere other than the site, for the obvious reason.

The other half of role design is evacuation and accounting for people, which sounds simple and is the part that fails most often in practice. Assembly points that are downwind, marshals who were not on shift, visitor and contractor lists that live in a system nobody can reach from outside the building, and no agreed way to confirm that a missing person is missing rather than merely at a dentist appointment. This is narrow, physical, site-specific work, and it is the subject of evacuation planning and crisis coordination.

What Triggers Activation, and Who Is Allowed to Call It?

Activation is the weakest point in most plans. The document describes in detail what happens once the plan is running and says almost nothing about how it starts, which leaves a supervisor at 06:40 deciding alone whether a situation is serious enough to wake the executive team. Faced with that, people under-call. Nobody wants to be the person who escalated a nothing.

Write the Threshold Down So Nobody Has to Be Brave

The fix is to convert the judgment into a rule. Define levels, and attach observable conditions to each: anyone taken to hospital, any release beyond the bund, any evacuation lasting more than a set number of minutes, any incident involving a member of the public, any event likely to reach a regulator or the news. Then say explicitly that the person on site confirms a condition rather than assesses a severity, that erring upward is the expected behavior, and that standing an incident down early costs nothing.

The World Health Organization runs exactly this pattern at institutional scale, and its published grading procedure is a useful model precisely because it is written plainly. Grading, in its own words, "is an internal activation procedure that triggers WHO emergency procedures and activities for the management of the response." The grades then describe what each level sets in motion, in organizational terms rather than in adjectives: a Grade 1 event requires "a limited response by WHO, which exceeds the usual country-level cooperation that the country office has with the Member State", while a Grade 3 event requires "a major to maximal WHO response" and the mobilization of assets from across the organization. The lesson is not the specific wording. It is that each level is tied to what actually happens next.

The four things an activation clause has to answer

  • What condition. Observable and checkable, not "a significant incident".
  • Who can call it. A list of roles, deliberately longer than you are comfortable with, any one of whom can activate alone.
  • What happens automatically. Which numbers ring, which room opens, which log starts, without anyone deciding.
  • And who stands it down, which should be a higher bar than calling it, held by a named role and recorded with a time.

What Belongs in the Plan, and What Belongs in an Annex?

Usability under stress is a design constraint, not a nicety. The split that works is simple: stable material that changes rarely goes in the plan, and volatile material that changes constantly goes in annexes with named owners and review dates. That way the plan does not need reapproving every time a phone number changes, and the phone numbers actually get updated.

Goes in the plan Goes in an annex Does not belong here at all
Scope, sites and scenarios covered, and what is deliberately excluded Contact lists, call trees and out-of-hours numbers Insurance claim procedures and loss adjuster contacts
Roles, their authority and their alternates, by title The current people-to-role mapping Media statements and holding lines
Activation levels and the conditions that trigger each Site plans, isolation points, assembly points, access routes Recovery sequencing and minimum service levels
Immediate actions per scenario, on one page each Equipment inventories and their locations Root cause analysis method
Notification duties, including any regulatory reporting clock Mutual aid agreements and external service contacts Supplier substitution and procurement workarounds

Two formatting decisions do more for usability than any amount of rewriting. Put an action card at the front for each scenario, one page, numbered steps, no prose, and make it printable in isolation so someone can carry it. And keep a copy that works when the network is down and the building is inaccessible, which in practice means printed copies in more than one place plus something on a phone that does not require a login the holder has forgotten.

One more structural point about method. The planning guidance published by the US emergency management agency describes a six-step planning process and, in its most recent revision, was explicitly widened to bring "businesses and infrastructure owners and operators, public sector partners, community-based organizations, and nonprofit sector partners" into that process. The implication for a private organization is that a plan written entirely inside the organization, without a conversation with the people who would actually turn up, is missing the part where assumptions get corrected. That conversation is routine practice in emergency preparedness and crisis response work and unusual in most companies.

How Do You Find Out Whether the Plan Works?

A plan nobody has tested is a hypothesis. Testing it is a separate activity from writing it, and it has its own guide: the piece on how to run a tabletop exercise covers the cheapest version, where the people who would really be deciding sit in a room and talk through a situation. What matters here is what you do with what it finds.

Three signals tell you more than any audit score. Whether the contact annex survives an unannounced call to three numbers picked at random. Whether somebody who has never read the plan can find the right action card in under a minute. And whether the last exercise produced changes to the document, because an exercise that changed nothing either found nothing or found things that were quietly ignored, and the second is more common.

Set a review cycle and attach it to events as well as dates. Annually is the usual baseline, and again, where a regulator prescribes a frequency, that frequency is the floor. Beyond the calendar, review after any activation, after any near miss that would have activated the plan under slightly different conditions, after a change to the site or the process, and after any change to the response organization. Organizations running a formal occupational health and safety management system will already have a management review mechanism to hang this on, as the explainer on ISO 45001 sets out.

Where Teams Build This Capability

EuroQuest International runs emergency and crisis programs for safety, security, operations and facilities teams in Geneva, Madrid, Zurich, Amman and Istanbul. Sessions are built around the participants' own sites and scenarios, so people leave with a draft they can take into a review rather than a set of templates. The full range sits under safety, security and emergency management.

Frequently Asked Questions

What should an emergency response plan contain?

Scope and the scenarios covered, including what is deliberately excluded and why. Roles with their authority and their alternates, named by title rather than by person. Activation levels tied to observable conditions, and who may call each. A one-page action card per scenario. Notification duties, including any regulatory reporting clock. Everything volatile belongs in annexes with named owners: contact lists, site plans, isolation and assembly points, equipment inventories. If the main document runs past about twenty pages, material has usually migrated in from continuity or communications planning and should be moved back out.

How is an emergency response plan different from a business continuity plan?

By time horizon and by purpose. Emergency response governs the first minutes and hours, and its objectives are protecting people, containing the event and summoning help. Business continuity governs the days and weeks afterward, and its objective is restoring the delivery of products and services within an acceptable window. They usually have different owners and often different regulators. The two should be separate documents that cross-reference each other, with an explicit handover point, normally the moment the site is declared safe. Combining them tends to produce something too long to use in an emergency and too thin to guide a recovery.

How many scenarios should the plan cover?

Five or six, if they are written around effects rather than causes. A site you cannot occupy, a casualty or fatality, a hazardous release, loss of a critical utility or system, a security or violence incident, and a sudden loss of people will cover the great majority of what an organization faces. Cause-specific detail goes into short annexes where it genuinely differs. Plans organized by hazard instead tend to run to thirty near-identical chapters, which is both more work to maintain and slower to use, because the reader has to classify the cause before they can find their instructions.

Who should be allowed to activate the plan?

More people than feels comfortable. Under-activation is the far more common failure, because the person on site is weighing an uncertain situation against the cost of disturbing senior people for nothing. Counter it structurally: list several roles, any one of whom can activate alone; tie activation to observable conditions rather than to a severity judgment; state in the document that erring upward is expected; and make standing down cheap and quick. Standing down should have the higher bar, held by a named role, with the time recorded. A plan that can only be activated by one executive is a plan that activates late.

How often should an emergency response plan be reviewed?

Annually as a baseline, and wherever a regulator prescribes a frequency, treat that as a floor rather than a target. Calendar reviews alone are not enough, because the things that invalidate a plan do not arrive on schedule. Review after any activation, after a near miss that would have activated the plan under slightly different conditions, after any change to the site, process or occupancy, and after any change to the response organization itself. The contact annex needs a much shorter cycle than the plan, quarterly in most organizations, with a named owner and an unannounced spot check rather than an emailed request for confirmation.

Write the plan the night shift can actually use

EuroQuest International runs practitioner training in emergency preparedness, evacuation planning, crisis response and business continuity across Europe, the Gulf and Asia.

Explore safety, security and emergency management programs