United States (ANSI-accredited; used internationally)

NFPA 1600

220 controls. 196 other frameworks in our corpus share controls with it. Here is all of it, and how much of it you are already doing.

Page built . This page is derived from the framework corpus, which changes when the corpus is extended rather than daily.

220 controls 196 frameworks share controls with it United States (ANSI-accredited; used internationally) verified against its source document

Every control below is one this framework asks for. The right hand column counts how many other frameworks in our corpus carry the same control, which is the difference between doing this work once and doing it again for the next standard.

NFPA 1600 Continuity Emergency and Crisis Management Evidence & Implementation Kit

220 controls is the documentation set somebody has to write. This is that set, already written: an adopt-ready artifact for every control in policy and procedure text you edit rather than draft, and the evidence checklist an auditor asks for against each.

See what is in it, $249

The same set every buyer of this kit receives. Nothing here is produced on request.

What you already have

Frameworks whose controls overlap this one, most first. If you run any of them, the count is roughly what you have already evidenced.

Every control

CodeControlAlso in
NFPA1600-01Program Scope and Objectives0
NFPA1600-02Program Coordinator and Committee0
NFPA1600-03Laws and Authorities Identification0
NFPA1600-04Risk Assessment4
NFPA1600-05Business Impact Analysis1
NFPA1600-06Resource Needs Assessment0
NFPA1600-07Prevention and Mitigation Strategy0
NFPA1600-08Emergency Operations and Response Plan0
NFPA1600-09Crisis Communications0
NFPA1600-10Continuity of Operations Plan0
NFPA1600-11Recovery Plan0
NFPA1600-12Employee Assistance and Support0
NFPA1600-13Training0
NFPA1600-14Exercises0
NFPA1600-15Program Evaluation and Maintenance0
NFPA1600-16Records Management0
NFPA1600-17Finance and Administration0
NFPA1600-18Mutual Aid and Assistance0
NFPA1600-4.1Leadership and Commitment40
NFPA1600-4.2Program Coordinator0
NFPA1600-4.3Program Committee0
NFPA1600-4.4Laws, Authorities and Financing0
NFPA1600-4.5Records Management0
NFPA1600-5.1Risk Assessment107
NFPA1600-5.2Business Impact Analysis1
NFPA1600-5.3Resource Needs Assessment60
NFPA1600-6.1Prevention and Mitigation0
NFPA1600-6.2Crisis Management and Communications25
NFPA1600-6.3Emergency Response Operations90
NFPA1600-6.4Continuity and Recovery67
NFPA1600-6.5Employee Assistance and Support0
NFPA1600-7.1Exercise Program0
NFPA1600-7.2After-Action Reporting34
NFPA1600-8.1Program Review and Evaluation0
NFPA1600-8.2Corrective Action36
10.110.1 Program reviews evaluating policies, program, procedures and capabilities against performance objectives0
10.1.110.1.1 Effectiveness improved by evaluating the changes made through preventive and corrective action0
10.1.210.1.2 Evaluations on a regular schedule and when the situation changes0
10.1.310.1.3 Re-evaluation on changes in regulations, hazards, resources, organisation, funding, infrastructure, stability, operations or critical suppliers0
10.1.410.1.4 Reviews including post-incident analyses, lessons learned and program performance0
10.1.510.1.5 Records of reviews and evaluations kept0
10.1.610.1.6 Documentation, records and reports provided to management for review and follow-up0
10.210.2 Corrective Action0
10.2.110.2.1 A corrective action process0
10.2.210.2.2 Corrective action taken on identified deficiencies0
10.310.3 Continuous improvement through program reviews and corrective action0
4.14.1 Administration0
4.24.2 Leadership and Commitment0
4.2.14.2.1 Leadership commitment to the program across prevention, mitigation, preparedness, response, continuity and recovery0
4.2.24.2.2 Leadership commitment: support, resources, review and corrective action0
4.2.34.2.3 Adherence to the program's policies, plans and procedures0
4.34.3 A program coordinator appointed and authorised by leadership0
4.44.4 Performance Objectives0
4.4.14.4.1 Performance objectives for the program and every element of chapters 5 to 100
4.4.24.4.2 Performance objectives addressing the hazard identification, risk assessment and BIA results0
4.4.34.4.3 Short-term and long-term performance objectives0
4.4.44.4.4 Short term and long term defined by the entity0
4.54.5 Program Committee0
4.5.14.5.1 A program committee established under the entity's policy0
4.5.24.5.2 The committee's input into and coordination of the program0
4.5.34.5.3 Committee membership: the coordinator and people with expertise, knowledge and resource authority from every key function0
4.5.44.5.4 External representation solicited for the committee0
4.64.6 Program Administration0
4.6.14.6.1 A documented program: executive policy, scope and objectives, authorities, budget and schedule, plans and procedures, records management, management of change0
4.6.24.6.2 Program scope set by an all-hazards approach and the risk assessment0
4.6.34.6.3 Program requirements applied to preparedness across prevention, mitigation, response, continuity and recovery0
4.74.7 Laws and Authorities0
4.7.14.7.1 Compliance with applicable legislation, policies, regulations and directives0
4.7.24.7.2 Documented procedures for legal and regulatory compliance0
4.7.34.7.3 A strategy for addressing needed revisions to laws, regulations, directives, policies and codes0
4.84.8 Finance and Administration0
4.8.14.8.1 Finance and administrative procedures before, during and after an incident0
4.8.24.8.2 A responsive finance and administrative framework linked to response, continuity and recovery with maximum flexibility to move funds0
4.8.34.8.3 Procedures expediting fiscal decisions within authorisation levels and fiscal policy0
4.8.44.8.4 Finance and administrative procedures covering nine elements from finance authority to managing appropriated funds0
4.94.9 Records Management0
4.9.14.9.1 A records management program keeping records available to the entity0
4.9.24.9.2 Records management: vital records identified, backed up, validated, storable and recoverable, protected, reviewed and access-controlled0
5.15.1 Planning and Design Process0
5.1.15.1.1 A planning process that develops strategies, plans and capabilities0
5.1.25.1.2 Strategic planning defining the program's vision, mission and goals0
5.1.35.1.3 Risk assessment and BIA informing prevention and mitigation strategies0
5.1.45.1.4 Risk assessment, BIA and resource needs assessment informing response, crisis communications, continuity and recovery plans0
5.1.55.1.5 Crisis management planning addressing events that severely impact operations, brand, reputation, market share, ability to do business or stakeholder relationships0
5.1.65.1.6 Key stakeholders included in planning0
5.25.2 Risk Assessment0
5.2.15.2.1 A risk assessment conducted0
5.2.25.2.2 Hazards identified and monitored for likelihood and severity over time0
5.2.2.15.2.2.1 Hazards evaluated across the eight categories from geological to humanitarian0
5.2.2.25.2.2.2 Vulnerability of people, property, operations, environment, the entity and its supply chain identified, evaluated and monitored0
5.2.35.2.3 Impact analysis across thirteen areas from health and safety to work and labour arrangements0
5.2.45.2.4 Escalation of impacts over time analysed0
5.2.55.2.5 Cascading impacts of regional, national or international incidents evaluated0
5.2.65.2.6 Adequacy of existing prevention and mitigation strategies evaluated0
5.35.3 Business Impact Analysis (BIA)0
5.3.15.3.1 A business impact analysis of how disruption affects operations, reputation, market share, ability to do business and stakeholder relationships0
5.3.1.15.3.1.1 Mission-critical processes identified0
5.3.1.25.3.1.2 Enabling resources identified: personnel, equipment, infrastructure, technology, information and supply chain0
5.3.25.3.2 Dependencies, single- and sole-source suppliers, single points of failure and the impacts of disruption evaluated0
5.3.2.15.3.2.1 The recovery time objective determined0
5.3.35.3.3 The recovery point objective identified0
5.3.45.3.4 Gaps between RTOs, RPOs and demonstrated capabilities identified0
5.3.55.3.5 The BIA used to develop continuity and recovery strategies and plans0
5.3.65.3.6 Critical supply chains, including those exposed to domestic and international risk, and when they become critical0
5.45.4 Resource Needs Assessment0
5.4.15.4.1 A resource needs assessment based on the hazards and continuity requirements0
5.4.25.4.2 Resource needs by type, time frame, quantity, response time, capability, limits, cost and liability0
5.4.35.4.3 Procedures to locate, acquire, store, distribute, maintain, test and account for procured or donated resources0
5.4.45.4.4 Facilities for response, continuity and recovery identified0
5.4.55.4.5 Mutual aid, assistance or partnership agreements determined and documented0
6.16.1 Common Plan Requirements0
6.1.16.1.1 Plans addressing personnel health and safety0
6.1.26.1.2 Plans documenting assumptions, roles, lines of authority, delegation, succession, liaisons and logistics0
6.1.36.1.3 Plans individual, integrated or combined0
6.1.46.1.4 Plan sections made available to those with assigned tasks and to key stakeholders0
6.106.10 Continuity and Recovery0
6.10.16.10.1 Continuity0
6.10.1.16.10.1.1 Continuity plans with strategies for the critical and time-sensitive processes of the BIA0
6.10.1.26.10.1.2 Continuity plan contents: stakeholders to notify, processes to maintain, roles, activation authority, critical technology and information, information security, alternativ0
6.10.1.36.10.1.3 Continuity plans designed to meet the RTO and RPO0
6.10.1.46.10.1.4 Continuity plans addressing supply chain disruption0
6.10.26.10.2 Recovery0
6.10.2.16.10.2.1 Recovery plans restoring processes, technology, information, services, resources, facilities, programs and infrastructure0
6.10.2.26.10.2.2 Recovery plan contents: damage assessment, coordinated restoration, supply chain, stakeholder communications, critical process recovery, roles, support personnel, data con0
6.116.11 Employee Assistance and Support0
6.11.16.11.1 An employee assistance and support strategy: communications, contacts, accounting for people, housing and care, well-being, awareness0
6.11.26.11.2 The support strategy flexible for all incidents0
6.11.36.11.3 Family preparedness education and training promoted0
6.26.2 Prevention0
6.2.16.2.1 A prevention strategy against incidents threatening life, property, operations, information and the environment0
6.2.26.2.2 The prevention strategy kept current through information collection and intelligence0
6.2.36.2.3 Prevention strategy based on hazards, risk, impacts, constraints, experience and cost-benefit analysis0
6.2.46.2.4 Preventive measures adjusted to the monitored risk0
6.36.3 Mitigation0
6.3.16.3.1 A mitigation strategy limiting the consequences of incidents that cannot be prevented0
6.3.26.3.2 Mitigation strategy based on hazards, risk, impacts, constraints, experience and cost-benefit analysis0
6.3.36.3.3 Interim and long-term actions to reduce vulnerabilities0
6.46.4 Crisis Management0
6.4.16.4.1 A crisis management capability for events that severely impact brand, reputation, market share, ability to do business or stakeholder relationships0
6.4.26.4.2 Crisis management processes: engage leadership, detect signals, analyse, declare and activate, identify issues, develop strategies, direct and support, coordinate communicati0
6.56.5 Crisis Communications and Public Information0
6.5.16.5.1 A plan and procedures to inform and answer internal and external audiences before, during and after an incident0
6.5.26.5.2 A crisis communications capability: a contact hub, an information center, information gathering and dissemination, coordinated messages and a release protocol0
6.66.6 Warning, Notifications, and Communications0
6.6.16.6.1 Warning, notification and communications needs determined0
6.6.26.6.2 Warning, notification and communications systems reliable, redundant and interoperable0
6.6.36.6.3 Warning protocols developed, tested and used to alert stakeholders at risk0
6.6.46.6.4 Warnings through authorised agencies where the law requires, with pre-scripted bulletins0
6.6.56.6.5 Information disseminated through the most effective media, social media or other means0
6.76.7 Operational Procedures0
6.7.16.7.1 Operational procedures developed, coordinated and implemented0
6.7.26.7.2 Procedures for response to and recovery from the identified hazards0
6.7.36.7.3 Procedures providing for life safety, property conservation, incident stabilisation, continuity and environmental protection0
6.7.46.7.4 Procedures for access control, identification and accounting of personnel, and mobilisation and demobilisation0
6.7.56.7.5 Concurrent response, continuity, recovery and mitigation allowed for0
6.86.8 Incident Management0
6.8.16.8.1 An incident management system directing, controlling and coordinating response, continuity and recovery0
6.8.1.16.8.1.1 Emergency Operations Centers (EOCs)0
6.8.1.1.16.8.1.1.1 Primary and alternate emergency operations centers0
6.8.1.1.26.8.1.1.2 EOCs physical or virtual0
6.8.1.1.36.8.1.1.3 Communications and coordination between incident command and an activated EOC0
6.8.26.8.2 Roles, titles and responsibilities for each incident management function0
6.8.36.8.3 Procedures and policies coordinating the six program activities0
6.8.46.8.4 Those activities coordinated with stakeholders0
6.8.56.8.5 A situation analysis assessing casualties, damage, disruption, information, contamination, reputation and resource needs to decide plan activation0
6.8.66.8.6 Response guided by an incident action plan or management by objectives0
6.8.76.8.7 Resource management: describing, inventorying, requesting and tracking, typing, mobilising and demobilising, contingency planning for deficiencies0
6.8.86.8.8 A current inventory of internal and external resources0
6.8.96.8.9 Donations managed0
6.96.9 Emergency Operations/Response Plan0
6.9.16.9.1 Emergency operations and response plans defining responsibilities for specific actions0
6.9.26.9.2 Actions to protect people including those with disabilities and access and functional needs, information, property, operations, the environment and the entity0
6.9.36.9.3 Actions for incident stabilisation0
6.9.46.9.4 Plan contents: protective actions, warnings, crisis communication, resource management and donation management0
7.17.1 Incident recognition: a common reference for the incident types that could affect the entity0
7.27.2 Initial reporting and notification by all appropriate stakeholders0
7.37.3 Plan Activation and Incident Action Plan0
7.3.17.3.1 A process to assess the incident's impact0
7.3.27.3.2 A time frame for activating plans, coordinated with public declarations0
7.47.4 Activate Incident Management System0
7.4.17.4.1 Procedures executed from the documented plans0
7.4.27.4.2 The incident management system executed in support of objectives and tasks0
7.4.37.4.3 Communications between incident command and an activated EOC0
7.57.5 Ongoing Incident Management and Communications0
7.5.17.5.1 Continual impact assessment and re-evaluation of the action plan0
7.5.27.5.2 Warning, notification and communications systems used to alert stakeholders at risk0
7.5.37.5.3 Special authorities invoked and assistance requested per chapter 4 according to the damage0
7.67.6 A system tracking incident information, decisions, resources and actions0
7.77.7 Criteria for incident stabilisation0
7.87.8 Termination, demobilisation and resumption of operations0
8.18.1 A competency-based training and education curriculum for everyone with a program role0
8.28.2 Curriculum goal: awareness and the knowledge, skills and abilities to implement, support and maintain the program0
8.38.3 Scope and frequency of instruction identified0
8.48.4 Personnel trained in the incident management system to their level of involvement0
8.58.5 Training records kept under the records management program0
8.68.6 Curriculum compliant with regulatory and program requirements0
8.78.7 A public education program on hazard impacts, preparedness and preparedness planning0
9.19.1 Program Evaluation0
9.1.19.1.1 Plans, procedures, training and capabilities evaluated through periodic exercises and tests0
9.1.29.1.2 Evaluation from post-incident analyses, lessons learned and operational performance0
9.1.39.1.3 Exercises and tests documented0
9.29.2 Exercise and Test Methodology0
9.2.19.2.1 Exercises as a standardised methodology to practise procedures and interact with other entities0
9.2.29.2.2 Exercises designed to assess the maturity of plans, procedures and strategies0
9.2.39.2.3 Tests designed to demonstrate capabilities0
9.39.3 Exercises designed to the fourteen purposes from participant safety to individual performance0
9.49.4 Exercise and Test Evaluation0
9.4.19.4.1 Exercises evaluating plans, procedures, training and capabilities for improvement0
9.4.29.4.2 Tests evaluated as pass or fail0
9.59.5 Frequency0
9.5.19.5.1 Exercises and tests at the frequency needed to establish and maintain capabilities0
C10Chapter 10: Program Maintenance and Improvement0
C4Chapter 4: Program Management0
C5Chapter 5: Planning0
C6Chapter 6: Implementation0
C7Chapter 7: Execution0
C8Chapter 8: Training and Education0
C9Chapter 9: Exercises and Tests0
SCOPE4.1 Administration: scope, purpose and application0
STDNFPA 1600 and NFPA 1660: the standard, its editions, the 2024 consolidation and what is held0

Tell me when NFPA 1600 files something new

One email when a public company newly discloses something this framework governs, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.

What an auditor will ask you to produce

The artefacts named on the failure modes this framework speaks to.

  • Records retention schedule
  • Retention schedule
  • Retention schedule and disposal records
  • Records inventory
  • Document management platform export
  • Evidence repository index
  • Internal audit programme and reports
  • Auditor qualifications and independence
  • Management review minutes with inputs and outputs
  • Corrective action tracking

How programmes fail on this

Failure modes named by this framework and others. Each opens the full record.

What this page is

A control-level reference for NFPA 1600, drawn from our framework corpus. Control codes and titles are references to the standard, not reproductions of it. The overlap counts and the auditor artefacts are our own work and are the part you will not find elsewhere.

Measure this against what you already run · All frameworks · Today's edition