Incident Response Plan Template (Business Continuity)
A practical, ready-to-use playbook for restaurants and hospitality teams to prepare for, respond to, recover from, and learn after operational disruptions (power outages, supplier shocks, staffing crises, food safety incidents, system outages). Includes incident categories, severity levels, step-by-step response actions, an owner/responsibility matrix, guest and staff communications templates, recovery and reopening checklists, and a structured post-incident review template.
Purpose and scope
This playbook helps hospitality operators prepare for and respond to disruptions in ways that protect guests, staff, revenue, and reputation. Use it for predictable events (power outages, supplier delays, seasonal staff shortages) and unpredictable incidents (major equipment failure, food safety event, sudden facility closure). Adapt roles, contact lists, and thresholds to your location's size and local regulations.
How to use this template
Keep an editable version for your location. Assign primary and backup owners for each role. Practice the key steps in tabletop drills at least twice per year. After any incident, run the post-incident review and update the plan within 14 days.
Incident categories (typical)
- Power outage / HVAC failure
- Supplier disruption (ingredient unavailable or contaminated)
- Staffing crisis (mass call-offs, strike)
- Food safety incident (possible foodborne illness, allergen exposure)
- IT / POS / payments outage
- Water leak, fire, or structural damage
- Health or public-safety event affecting staff or guests
- Reputation/PR incident (bad viral review, social media escalation)
Severity levels and quick triggers
Use simple severity levels to decide who to activate and how fast to escalate.
- Severity 1 — Critical: Immediate closure or major guest harm likely. Activate full incident team and notify corporate/owner immediately.
- Severity 2 — Major: Significant impact on service, revenue, or safety but manageable with focused response. Activate core responders and communications.
- Severity 3 — Minor / Local: Small interruption with limited exposure. Local manager resolves and documents the event.
Immediate response checklist (first 60 minutes)
- Ensure safety of guests and staff. If there is any safety risk, call emergency services first.
- Confirm incident category and severity level (use the categories above).
- Notify the incident owner (see owner matrix) and stand up the incident team for Severity 1–2.
- Isolate the cause where possible (turn off affected equipment, quarantine suspect food, stop service to affected area).
- Record time, initial observations, and immediate actions in the Incident Log (who, what, where, impact).
- Send an initial staff message (template below) and guest-facing notice if needed.
- Begin containment actions and short-term mitigation (alternative suppliers, transfer guests, backup generators if available).
Owner / Responsibility matrix (example)
Assign a primary and backup for each role. Replace titles with names and phone numbers for your location.
- Incident Commander (overall decision authority) — General Manager (Backup: Assistant Manager)
- Safety & Compliance Lead — Kitchen Manager / Head Chef (Backup: Senior Cook)
- Operations & Recovery Lead — Shift Supervisor (Backup: Floor Manager)
- Communications Lead (guests & public) — Front-of-House Manager (Backup: Marketing/Owner)
- Supplier & Purchasing Lead — Purchasing/Manager on duty (Backup: Owner)
- IT / POS Contact — IT vendor or designated staff (Backup: POS vendor 24/7 line)
- Finance & Insurance Lead — Owner/Controller (Backup: Regional Manager)
Guest and staff communications (templates)
Use short, clear messages. Prioritize safety, transparency, and concrete next steps.
Staff initial message (example)
"Team — we have a [category] in [area]. Safety first: please follow direction from [Incident Commander name]. Do not attempt to handle this alone. Report to [designated area] for briefing. Further instructions to follow."
Guest-facing notice (in-venue / signage)
"Due to [brief reason—e.g., a temporary power issue], we are making changes to keep guests safe. We expect service will be affected. Our team can answer questions at the host stand. Thank you for your patience."
Social media / website short post (example)
"We're experiencing a temporary [issue]. We're working to resolve it and will update here. Call [phone number] for reservations or questions. We're sorry for any inconvenience."
Staff follow-up checklist for communications
- Confirm a single spokesperson for external communications.
- Log all messages and who sent them.
- Keep messages factual; do not speculate about cause or liability.
Recovery checklist (short-term and reopening)
Use these items to verify you can safely resume normal operations.
- Containment confirmed: hazard removed or secured.
- Food safety evaluation complete: review affected inventory, follow discard & quarantine procedures, consult Safety Lead or local health department if needed.
- Equipment checks: verify power, refrigeration temperatures, cooking equipment, and water supply.
- Systems tested: POS, payments, reservations, phone lines, online ordering.
- Staffing: confirm trained staff are available for reopening shifts; update schedules as needed.
- Sanitation: complete targeted cleaning and sanitation of affected areas.
- Guest notification: update reservations, post clear reopening message online and at the venue.
- Documentation: complete Incident Log and attach receipts, photos, supplier communications.
- Sign-off: Incident Commander and Safety Lead sign-off before full reopening.
Post-incident review template (to complete within 7–14 days)
Run a structured review with involved staff. Capture facts, causes, impacts, and actions. Assign owners and due dates for corrective actions.
- Incident summary: Date/time, category, severity, duration, locations affected, immediate outcome.
- What went well: Actions that reduced harm or restored operations quickly.
- What went poorly: Confusion, resource gaps, delays, communication failures.
- Root causes: Identify underlying causes (supplier, equipment, process, training). Use 5 Whys as needed.
- Corrective actions: Specific tasks, assigned owner, and due date. Examples: change supplier, add backup generator maintenance, revise SOP, retrain staff, update contact list.
- Learning & updates: Update this plan and any SOPs, checklists, or training materials. Schedule a drill to test changes within 90 days.
- Impact metrics: Estimated lost revenue, number of guests affected, days closed, reputational metrics (mentions, negative reviews), insurance claims filed.
Incident log (what to record)
- Date/time incident discovered
- Reporter name & contact
- Brief description of incident
- Severity level chosen & who approved it
- Immediate actions taken (who did what and when)
- Communications sent (copy or link to messages)
- Photos, receipts, supplier notes, vendor work orders
- Time incident closed, sign-off
Practice, training and maintenance
- Run tabletop exercises twice per year covering at least two different incident categories.
- Train new managers on this plan during onboarding and test them in a simulated incident within 60 days.
- Update contact lists and vendor SLAs annually or when key staff change.
Quick reference templates and checklists (copy into your location plan)
Include the following in a printed/accessible binder and a digital copy reachable offline:
- Incident contact list (names, role, mobile, backup, escalation chain)
- Supplier contacts and alternatives
- Emergency services and local health authority contacts
- Short communications templates (staff, guests, social)
- Pre-filled recovery checklist for common incidents (power loss, spoilage protocol, POS outage)
Versioning and ownership
Record plan version, date of last update, and owner. After every incident update the version and keep a short changelog: what changed and why.
Example scenario (power outage)
- Discover outage — confirm building-wide vs. isolated circuit.
- Safety check — move perishables if temperatures risk; discard per SOP for critical time/temperature limits.
- Communication — post short guest notice and staff message. Contact utility company and estimate restoration time.
- Decision — if restoration > 2 hours or refrigeration compromised, consider safe closure and notify guests with options for rescheduling or refunds.
- Recover — verify refrigeration temperatures after power returns for at least 2 hours before using stored food unless SOP allows otherwise. Complete incident log and post-incident review.
Next steps to make this playbook actionable for your site
- Customize the owner matrix with names and backup contacts.
- Complete the incident contact list and supplier alternatives.
- Run a tabletop exercise using one scenario and update the plan with identified gaps.
Keep this playbook near the manager station and in the cloud where it can be accessed offline. After any incident, use the post-incident review to convert lessons into updated SOPs and training.
Discussion
Comments and conversation will live here.