Knowella

Site Resilience and Continuity Plan

A site resilience and continuity plan sets out how the whole site keeps operating, or recovers, through a major disruption: loss of power, refrigeration, water, IT, key equipment, key people or a critical supplier. Its recurring failure is timescale, a recovery horizon of days copied onto a chilled site where product loss starts within an hour of losing refrigeration.

KnowEnviroPlanENV-04643 fields across 5 sectionsFull researchSee the form

Reviewed by Siddarth SinghCSPLast reviewed 16 August 2026

Basis
ISO 14001 cl.8.2
Workspace
KnowEnviro
Form type
Plan
Review trigger
Change to critical dependency, an exercise finding, or the annual test
Feeds
Emergency plans, generator test, exercise record

The short version

  • The plan's most common failure is timescale: recovery objectives copied from a generic template understate how fast refrigeration loss becomes product loss, sometimes by an order of magnitude.
  • This is the all-hazards plan, not the flood-specific one. Using it to duplicate the flood plan, rather than cover power, IT, people and supply chain loss, produces two documents that both undersell what they should own.
  • ISO 14001 cl.8.2 covers the environmental consequences of these losses, but the real test is whether a recovery time objective was set for each scenario and checked against reality, not assumed.
  • Standby generation, alternative cold storage and an alternative production site are worth nothing if never tested; the Outcome section exists to distinguish availability from verified capability.
  • A continuity plan with no annual test behind it is a description of intent, and the gap only shows up during the actual disruption.

What this is

What is a site resilience and continuity plan?

What is a site resilience and continuity plan?

It sets out how a site continues operating, or recovers, when it loses a critical dependency: power, refrigeration, water, IT and control systems, key equipment, key people, or a critical supplier or haulier. It names recovery time objectives, standby arrangements and contact routes, and is tested rather than merely written.

How is this different from a flood risk and response plan?

The flood plan addresses one specific hazard and a defined sequence of actions around a flood warning. This plan is broader and cause-agnostic: what keeps the site running when any dependency is lost, whether the cause is a flood, a cyber incident, a supplier failure or loss of key staff.

Why does refrigeration get treated differently from the other scenarios?

Most scenarios have a recovery window of hours to days before the consequence becomes serious. Refrigeration does not: product temperature moves the moment cooling stops, and the effective window can be under an hour. Applying the same recovery time objective to refrigeration as to an IT outage assumes a timescale that doesn't hold.

Scope

When is a site resilience and continuity plan required?

This plan is the broad, all-hazards instrument. Where the disruption has its own dedicated template, complete that one in full, and reference it here rather than repeating it.

Use this template when

  • The site depends on power, refrigeration, water, IT, key equipment, key people or a specific supplier or haulier in a way that loss would stop operations
  • A new record is needed at the stated interval, or after a change to a critical dependency, supplier or key role
  • Recovery time objectives need setting and testing against standby arrangements such as generation, alternative cold storage or an alternative production site
  • The site needs a single reference point tying together its emergency, supply chain and staffing continuity arrangements
  • A linked record needs this one to exist: emergency plans or a generator test reference it

Do not use it for

  • Flood Risk and Response Plan, which sets out flood risk and the sequence of actions before, during and after a flood event
  • Climate Risk Assessment, which assesses flooding, heat, drought, storm and climate-driven supply chain disruption specifically
  • Business Continuity Exercise Record, which records a single test of this plan and what it found, not the arrangements themselves
  • Emergency Response Plan, which covers the trained response to an emergency as it unfolds, not the site's dependency and recovery arrangements
  • Anything outside KnowEnviro, which belongs in the workspace that owns that process

Compliance mapping

Which ISO 14001 cl.8.2 requirements does this satisfy?

Continuity planning is addressed indirectly through ISO 14001's emergency preparedness clause where the consequence is environmental, and directly through the business continuity standard where a site aligns with it, though the two are not the same obligation.

ClauseRequirementWhere it lands
ISO 14001 cl.6.1.2Determination of environmental aspects including abnormal and emergency conditions, to inform which disruptions carry environmental consequenceHeader
ISO 14001 cl.8.2Establishing processes to identify potential emergency situations and plan the response, given the nature of the siteScenarios covered
ISO 22301:2019 cl.8.2Business impact analysis and risk assessment identifying dependencies and their disruption consequencesPeople and supply
ISO 22301:2019 cl.8.4Business continuity plans and procedures, including recovery time objectives and recovery arrangementsPreparedness
ISO 14001 cl.8.2Periodically testing planned response actions where practicableOutcome
ISO 22301:2019 cl.8.5Exercise programme validating that arrangements deliver the recovery objectives setOutcome
ISO 14001 cl.10.2Reacting to nonconformity, evaluating the need for action, and implementing corrective actionOutcome

What it does not cover

  • Flood Risk and Response Plan, which sets out flood risk and what happens before, during and after a flood event specifically, rather than the site's dependencies in general.
  • Climate Risk Assessment, which assesses flooding, heat, drought, storm and climate-driven supply chain disruption as a combined exposure.
  • Business Continuity Exercise Record, which documents a single test of this plan, what worked and what did not, separate from the plan being current.
  • The emergency response itself, which belongs in the site's emergency plans and trained response arrangements, not this plan's description of who should do what.
  • Supplier or contract risk management, which owns the commercial relationship with a critical supplier or haulier; this plan only records the operational consequence of it failing.

Global

Site Resilience and Continuity Plan requirements by country

No jurisdiction mandates a site continuity plan by name for most commercial premises; the obligation is either indirect, through environmental or food safety consequence, or voluntary, through alignment with a recognised continuity standard.

United States

NFPA 1600, Standard on Continuity, Emergency, and Crisis Management

A voluntary consensus standard, referenced by regulators, insurers and auditors as the benchmark for a defensible continuity programme.

No federal mandate exists to hold a plan, but alignment with NFPA 1600 shows arrangements meet an accepted standard, not an improvised one.

United Kingdom

ISO 22301, developed from the UK's own BS 25999

A certifiable management system standard for business continuity, adopted voluntarily rather than mandated for most sites.

Certification is optional, but customer contracts and insurers increasingly expect ISO 22301's substance: recovery objectives, tested arrangements, impact analysis.

International

ISO 14001:2015 cl.8.2 and ISO 22301:2019

Environmental emergency preparedness is certifiable under ISO 14001; continuity management has its own certifiable standard in ISO 22301.

A site can be ISO 14001 certified with sound emergency preparedness and still have a plan never tested against ISO 22301's exercise expectations.

How to complete it

How to complete a site resilience and continuity plan, step by step

The form asks whether each scenario is covered and whether standby exists. Whether the plan holds up during a disruption comes down to judgement calls the fields don't force.

Set a recovery time objective per scenario, not one for the whole plan

Power, refrigeration, water, IT and people loss each have different tolerances. Refrigeration on a chilled site is measured in hours; an IT outage might tolerate a day. One objective applied to all of them is wrong for at least one, usually the one that matters most.

Distinguish available from tested

Standby generation, alternative cold storage and an alternative production site are recorded as available, and separately as tested, or not. An arrangement that exists on paper but was never exercised is an assumption, and the plan should say so.

Treat supplier and people loss with the same rigour as physical loss

Haulier failure, supplier failure and loss of key people sit alongside power and refrigeration for a reason: a sound site can still stop if its one haulier fails, or the person holding undocumented knowledge is unavailable. These get skipped because they feel less concrete than a generator.

Keep the plan accessible when the thing it depends on has failed

A plan stored only on the system an IT or power failure would take down is unavailable exactly when needed. Whether it is genuinely accessible offline, and contact trees are current, separates a plan that survives its own scenario from one that doesn't.

What auditors find

Most common site resilience and continuity plan findings

Findings rarely concern whether the plan exists. They concern whether its recovery time objectives and standby arrangements would actually hold during the disruption they describe.

FindingClauseWhat fixes it
A single recovery time objective applied across scenarios with materially different tolerances.ISO 22301:2019 cl.8.4Set a distinct objective per scenario, starting with refrigeration and power.
Standby generation or alternative cold storage recorded as available but never tested.ISO 14001 cl.8.2Record availability and test status separately, and schedule the test.
Supplier and haulier failure scenarios left blank or dismissed as out of scope.ISO 22301:2019 cl.8.2Assess supplier and haulier dependency with the same rigour as physical loss.
Plan not accessible offline, or contact trees not current, when actually needed.ISO 14001 cl.7.4Verify offline access and refresh contact trees at each review.
Plan not tested within the last twelve months despite the stated annual cycle.ISO 22301:2019 cl.8.5Run the exercise on schedule and record the result against the exercise reference.
Critical gaps identified in a prior exercise carried forward without a corrective action.ISO 14001 cl.10.2Raise a CAPA against every significant gap, with an owner and a date.

Case in point

Case in point: the generator that had never run under load

A chilled distribution site held a continuity plan naming a 24-hour recovery time objective across every scenario, including refrigeration, and recorded standby generation as available. The generator had been installed three years earlier, serviced annually, and started briefly each month. It had never run under the site's actual refrigeration load.

A regional power outage lasting six hours triggered the plan. The generator started but tripped within twenty minutes once the full load came on, a fault the monthly no-load test had never revealed. By the time a mobile generator arrived, product temperature had exceeded its threshold well inside the 24-hour window the plan assumed, because refrigeration's real tolerance was a fraction of that figure.

The template

The template, field by field

The form exactly as it installs. Every field, option, score and conditional rule is editable, and the links to other templates come with it.

43fields
5 sections
Reference
ENV-046
Archetype
Plan
Record ID
BCP-2026-000
Scoring
Plan tested
Direction
High is good
Singleton
No
Basis
ISO 14001 cl.8.2
Links
Links Emergency plans, Generator test
Tags
Climate, Continuity
Sections
5
Fields
43
Follow up fields
3
Repeating sections
0
Links out
3
Field typesOwn ID, generated on saveCase thread and parentPick list from a registryLinked to another templateFollow up, dashed outlineScored

Header

11 fields
Text

Plan ID*

Generated on save

Auto sequence. Format BCP-2026-000.

The record's own ID. Other templates point at this value.

Single Choice

Status*

Scored

Drives who this goes to next.

  • Planned2 pts
  • In progress2 pts
  • Complete3 pts
  • Deferred0 pts
  • Open0 pts
  • Closed3 pts
  • Overdue0 pts
Pick List

Site*

From FDN-001 Site NameFilter: Status is Active
Text

Site ID*

Linked

Format SITE-000.

Links to FDN-001 Site ID

Text

Version*

Date & Time

Issue Date*

Date & Time

Next Review Due*

Users

Plan Owner*

Users

Approved By*

Single Choice

Board Or Group Approved*

Scored
  • Yes3 pts
  • No1 pt
Info

Refrigeration Loss Is Measured In Hours

Most continuity plans assume days to recover. On a chilled site, the clock on the product starts within an hour of losing refrigeration.

Scenarios covered

6 fields
Single Choice

Power Loss*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Refrigeration Failure*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Water Supply Loss*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Steam Or Utility Loss*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

IT And Control System Failure*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Loss Of Key Equipment*

Scored
  • Covered3 pts
  • Partly1 pt
  • Not covered0 pts

People and supply

6 fields
Single Choice

Loss Of Key People*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Widespread Absence*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Supplier Failure*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Haulier Failure*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Site Access Denied*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Cyber Incident*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts

Preparedness

6 fields
Single Choice

Recovery Time Objectives Set*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Standby Generation Available And Tested*

Scored
  • Yes2 pts
  • No0 pts
  • N/Aexcluded from denominator
Single Choice

Alternative Cold Storage Identified*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Alternative Production Site Identified*

Scored
  • Yes2 pts
  • No0 pts
  • N/Aexcluded from denominator
Single Choice

Contact Trees Current*

Scored
  • Yes2 pts
  • No0 pts
  • N/Aexcluded from denominator
Single Choice

Plan Accessible Offline*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts

Outcome

14 fields
Single Choice

Plan Current*

Scored
  • Yes2 pts
  • No0 pts
  • N/Aexcluded from denominator
Single Choice

Tested In Last 12 Months*

Scored
  • Yes3 pts
  • No0 pts
Text

Exercise Record ID

OptionalLinked

Links to ENV-047 Record ID

Single Choice

Critical Gaps Identified*

Scored
  • None3 pts
  • Some1 pt
  • Significant0 pts
Text

Main Gap

Optional
Date & Time

Next Test Due*

Single Choice

Action Required*

Scored

Raise the action record, then enter its reference here.

  • No2 pts
  • Yes0 pts
Single Choice

Priority

OptionalScoredShows if Action Required equals Yes
  • High0 pts
  • Medium1 pt
  • Low3 pts
Text

CAPA ID

OptionalLinkedShows if Action Required equals Yes

Format CAPA-2026-00000.

Links to FDN-014 CAPA ID

Users

Action Owner

OptionalShows if Action Required equals Yes
Users

Site Manager*

Signature

Signature*

Users

Group*

Signature

Second Signature*

ENV-046 · record IDs look like BCP-2026-000 · Links Emergency plans, Generator test

Open in Knowella

Run it with agents

From a document you fill in to a programme that runs itself

The plan itself is a description. What decides whether the site actually keeps running is whether the standby arrangements it names have been proven under real conditions, and whether a dependency change reached the plan before the disruption did.

KnowEnviro

Holds the continuity plan against the site's dependency register, flags a changed critical supplier, haulier or key person, and keeps the emergency plan and generator test links current.

KnowMaintain

Tracks whether standby generation and other physical arrangements have been tested under load, not just serviced, so availability and verified capability stop being conflated.

Ella
Ella

Watches exercise results and dependency changes for findings that should trigger an early review, and rolls critical gaps into corrective actions rather than letting them sit unaddressed.

This template lives in KnowEnviro — environment and energy. Aspects, permits, waste, emissions, spills and sustainability reporting.

Meet KnowEnviro→

Glossary

Site Resilience and Continuity Plan definitions and key terms

Recovery time objective
The maximum tolerable duration a dependency can be lost before the consequence becomes serious, set separately per scenario, not as one figure for the plan.
Business impact analysis
The structured assessment of what the site depends on and what happens if each dependency is lost, underpinning the recovery objectives set.
Standby arrangement
A pre-identified fallback, standby generation, alternative cold storage, an alternative production site, whose value depends on whether it has been tested.
Single point of failure
A dependency, whether equipment, a supplier or a person, whose loss stops the site with no fallback, the condition this plan exists to remove.
Exercise
A deliberate test of the plan's arrangements, distinct from a routine no-load check, intended to reveal whether the recovery objective would actually be met.

FAQ

Frequently asked questions about site resilience and continuity plan

Is this the same as a flood plan?+

No. The flood plan is specific to one hazard and its own sequence of actions. This plan is cause-agnostic: it covers what keeps the site running when any critical dependency is lost, and a flood is one of the events that can trigger it.

Why does refrigeration need its own recovery time objective?+

Its tolerance is far shorter than most dependencies. A general 24 or 48-hour objective applied to refrigeration assumes a timescale product physics doesn't support, and the gap only shows once stock is lost.

How do we know if a standby arrangement is actually adequate?+

By testing it under the conditions it would face, not confirming it exists. A generator that starts on a no-load check tells you almost nothing about carrying the site's real load during an outage.

Does loss of key people really belong in the same plan as generator failure?+

Yes. Both are single points of failure, and the plan's job is to find every one that could stop the site, not only the mechanical ones. Undocumented knowledge held by one person is the same exposure as no backup generator.

How often should this plan be tested?+

At least annually. A plan that is current on paper but was last tested over twelve months ago should be treated as unverified, because that interval is exactly when standby arrangements quietly stop working.

What should happen when an exercise finds a critical gap?+

It should generate a corrective action with an owner and a date, referenced from the plan. A gap recorded and carried forward unchanged into the next exercise is a plan that has stopped improving.

Keep going

Related templates and programmes

Siddarth Singh

Written and reviewed by

Siddarth Singh

Founder & Chief Executive Officer, Knowella

Certified Safety Professional and industrial and systems engineer with more than a decade inside food supply chain, freight and manufacturing operations. This page was written against the current text of the standards it cites, not against secondary summaries of them.

  • Certified Safety Professional (CSP), Board of Certified Safety Professionals
  • MBA, University of Chicago Booth School of Business
  • MS and BS, The Ohio State University, Industrial and Systems Engineering
  • Six Sigma Black Belt
Verify with BCSP →

Sources and last review. Reviewed 16 August 2026 against:

  • ISO 14001:2015 clauses 6.1.2, 8.2, 7.4 and 10.2
  • ISO 22301:2019, Security and resilience — Business continuity management systems
  • NFPA 1600, Standard on Continuity, Emergency, and Crisis Management (US)

This page is general guidance, not legal advice. Confirm requirements with your jurisdiction’s regulator.

Start in Minutes, Not Weeks

Launch a Ready-Made Template and Customize It Your Way

Every template is fully editable. Adjust fields, workflows, and branding to match your processes, then deploy to your team instantly.