| name | design-crisis-management-governance-protocol |
| description | Use when an organization needs a defined governance chain of command for a major corporate crisis — a product safety failure, an executive scandal, a data breach, a natural disaster affecting operations — establishing who has decision authority at each severity level and when the board itself must be activated, rather than discovering the chain of command for the first time while the crisis is already unfolding. |
| source | National Association of Corporate Directors (NACD), crisis governance and board oversight guidance |
| tags | ["business","operations","crisis-management","board-governance","incident-command","escalation-protocol"] |
| related | ["design-business-continuity-plan","plan-incident-response","design-enterprise-risk-management-committee"] |
Design Crisis Management Governance Protocol
Establish a defined governance chain of command for a major corporate crisis — who has decision authority at each severity level, and specifically when the board itself must be activated — rather than discovering the chain of command for the first time while the crisis is already unfolding.
Why This Is Best Practice
Adopted by: The National Association of Corporate Directors documents defined crisis governance protocols — distinct from operational incident response — as a specific board oversight responsibility, since major corporate crises (executive misconduct, product safety failures, significant data breaches) frequently require board-level engagement beyond what a purely operational incident-response team can provide, particularly when the crisis involves the CEO or implicates the board's own oversight.
Impact: Organizations without a pre-defined crisis governance protocol are documented to experience materially slower and more confused initial crisis response — precious early hours are spent determining who has authority to make key decisions (public statement approval, executive suspension, regulator notification) rather than executing an already-understood chain of command, a delay that compounds reputational and legal exposure during exactly the window when rapid, coordinated response matters most.
Why best: A crisis is specifically the wrong moment to be determining governance structure for the first time — the pressure, time constraints, and stakes of an actual crisis are exactly the conditions under which an undefined chain of command produces the most costly delay and confusion, while a protocol established and understood in advance allows the organization to move directly to substantive crisis response rather than first resolving who's actually in charge.
Sources: National Association of Corporate Directors (NACD), crisis governance and board oversight guidance
Steps
Step 1: Define crisis severity tiers and the corresponding decision authority
Define specific severity tiers for a potential crisis (operational disruption, significant reputational event, existential threat to the company) and specify which level of the organization holds decision authority at each tier — operational management for lower tiers, executive leadership for mid tiers, and the board itself for the most severe tier.
Step 2: Define specific trigger conditions for board activation
Define specific, concrete trigger conditions that activate board-level crisis governance — a crisis implicating the CEO or other senior executive, a matter with potential criminal or major regulatory exposure, or an event threatening the company's fundamental viability — rather than leaving "when does the board get involved" as an ambiguous, case-by-case judgment made in the moment.
Step 3: Establish a defined crisis communications approval chain
Establish who has authority to approve public statements and media communications during a crisis, at each severity tier, since uncoordinated or unauthorized public statements during a crisis are a documented common source of compounding reputational damage beyond the original incident itself.
Step 4: Define the board's specific role distinct from management's operational response
Define the board's specific role during a major crisis — oversight of management's response, direct engagement with external advisors (crisis communications, outside counsel) where warranted, and its own fiduciary assessment of management's handling of the crisis — distinct from executing the operational response itself, which remains management's responsibility even during board-level crisis governance activation.
Step 5: Rehearse the protocol through periodic tabletop exercises
Rehearse the crisis governance protocol through periodic tabletop exercises simulating a realistic crisis scenario, since a protocol that exists only on paper and has never been exercised tends to reveal gaps and confusion precisely when actually invoked for the first time during a real crisis.
Rules
- Define specific severity tiers with corresponding decision authority at each level — don't leave this as an ambiguous, case-by-case judgment.
- Define specific, concrete trigger conditions for board-level activation, not a vague "the board will be involved if needed" standard.
- Establish a clear crisis communications approval chain, since uncoordinated public statements are a documented common source of compounding damage.
- Rehearse the protocol through periodic tabletop exercises — an unrehearsed protocol tends to reveal its gaps for the first time during an actual crisis.
Examples
Pre-defined protocol enabling rapid, coordinated response: A company experiences a significant data breach implicating a senior executive. Because the crisis governance protocol pre-defined this exact trigger condition for board activation, the board convenes within hours with a clear understanding of its oversight role, while management executes the pre-understood operational response — avoiding the confusion and delay an undefined chain of command would have produced in determining who has authority to act.
Tabletop exercise revealing a gap before a real crisis: A company's periodic crisis governance tabletop exercise reveals that the defined communications approval chain doesn't address weekend or after-hours activation, a gap identified and corrected during the exercise rather than during an actual crisis that happens to occur outside business hours.
Common Mistakes
- Leaving crisis governance authority as an ambiguous, case-by-case judgment rather than pre-defined tiers and triggers — this produces exactly the confusion and delay during an actual crisis that a pre-defined protocol is designed to prevent.
- Failing to define specific trigger conditions for board activation — a vague standard leaves the actual activation decision to be argued over during the crisis itself, when time is most scarce.
- Allowing uncoordinated public communications during a crisis with no clear approval chain — this is a documented common source of compounding reputational damage beyond the original incident.
- Never rehearsing the protocol through tabletop exercises — an unrehearsed protocol's gaps tend to surface for the first time precisely when the organization can least afford them, during an actual crisis.
When NOT to Use
- For routine operational incidents adequately handled by existing incident-response processes with no genuine board-level implication — reserve this protocol for crises of a severity or nature genuinely warranting board engagement (see
plan-incident-response for operational-level incident response).
- For a very small organization where informal, direct communication among a small leadership team can genuinely substitute for formal protocol — apply formal protocol infrastructure proportionate to organizational scale and complexity.
- As a substitute for the organization's broader business continuity planning — crisis governance addresses the decision-authority chain during a crisis; business continuity addresses the operational continuation of critical functions (see
design-business-continuity-plan), a related but distinct practice.