How to Build an Emergency Response Plan (ERP) for Corporate Security
Learn how to build a corporate emergency response plan with clear roles, scenario procedures, integrated systems, and exercise cycles that hold up under pressure.
An emergency response plan helps a corporate security team act in coordinated seconds during a time-critical incident. For corporate security leaders, the plan turns life-safety requirements into clear operational direction before confusion and delay compound the incident. In the strongest plans, security teams have a practical way to make fast decisions under pressure while protecting people and property and stabilizing operations.
Key Takeaways
- Facility threats drive scenario selection, so a site-specific risk assessment shapes the plan and no procedure set should be copied from another location.
- Clear command authority keeps hesitation from stalling the response, with one person empowered to order evacuation, lockdown, or shutdown and a named alternate ready to step in.
- Each protective action ties to defined triggering conditions, and integrating access control, video, and AI threat detection converts those triggers into fast execution.
- A plan holds value only when exercises, after-action reviews, and revision cycles keep it aligned with current threats, staffing, and facility conditions.
What an Emergency Response Plan Covers and How It Differs from an EAP and BCP
Corporate security leaders often use "emergency response plan," "emergency action plan," and "business continuity plan" interchangeably. Each plan has its own purpose and activates under different authorities at a different incident stage.
Emergency Action Plan
Under OSHA 1910.38, an emergency action plan (EAP) organizes employer and employee actions during workplace emergencies: evacuation routes, shelter, personnel accounting, and emergency reporting. OSHA applies it to employers whose employees evacuate and do not actively respond. For corporate security teams, the EAP is the baseline employee-facing instruction set for moving people to safety and accounting for them upon arrival.
Emergency Response Plan
The emergency response plan (ERP) picks up where the EAP stops. It is a written plan developed to handle anticipated emergencies before response operations begin. Facilities with hazmat teams, fire brigades, or personnel who actively suppress, control, or remediate an incident need procedures that go deeper than employee evacuation instructions. Active responders need written authority and coordination procedures before response operations start, so the distinction changes the plan's required depth.
Business Continuity Plan
The business continuity plan (BCP) operates on a different timeline. Continuity planning protects against disruptive incidents and supports recovery of critical functions afterward. Where the ERP governs the incident itself, the BCP governs operational recovery once immediate danger has passed. The BCP sustains or restores critical functions after immediate danger has passed.
Preparedness breaks into distinct stages: prevention, mitigation, emergency response, business continuity, crisis communications, and disaster recovery. A corporate office can build the plan to the EAP floor at minimum and extend it toward full ERP requirements wherever active response personnel operate on site.

Start with a Site-Specific Risk Assessment
No two facilities carry the same threat profile, and a plan copied from another site protects nothing. Actual facility threats determine which scenario procedures the plan needs.
Assessment Process
Risk assessment identifies and prioritizes risks by likelihood and consequences. It incorporates threat and vulnerability analyses and accounts for existing security controls. Teams select scenarios based on each threat's likelihood and consequences.
A site assessment starts with a current-state review of assets, policies, personnel, and physical security technology. The team then weighs man-made threats and natural hazards against the facility's location, uses interviews and inspections to identify vulnerabilities and countermeasures, estimates likelihood and the cost of loss, and prioritizes mitigation against defined risk tolerance.
Scenario Selection
The scenario set for a corporate assessment maps to organizational threats such as workplace violence and active-assailant incidents alongside ransomware. Natural disaster scenarios and property or intellectual theft by outsiders and insiders complete the set. For physical security planning, plans can cover active shooters, intrusion and insider threats, fire, medical emergencies, severe weather, and bomb threats.
Define Roles and the Chain of Command
A plan with no clear authority produces hesitation when hesitation is most dangerous. The ERP should identify a clear chain of command and designate a person authorized to order an evacuation or shutdown. That designation is the spine of the response.
Organizations can use the Incident Command System (ICS) as a planning model for on-scene command, control, and coordination that lets multiple organizations work within a common hierarchy. The Incident Commander holds primary authority: establishing the command post, setting objectives, approving the incident action plan, and approving resource requests. If the Incident Commander has not delegated a function, that function remains the Incident Commander's responsibility.
The plan's emergency response coordinator assesses whether an emergency exists, supervises evacuation, coordinates outside emergency services, and directs shutdown when required. Designating both a coordinator and a backup keeps authority from lapsing.
GSOC and SOC Operators
During an incident, the global security operations center consolidates situational awareness. GSOC operators relay information to guards and field resources; when needed, they contact emergency services and route field updates back to the center. During a building incident, operators contact potentially affected employees to confirm safety, push updates, and coordinate assistance.
Operators may need to multitask under acute stress while incident information changes quickly. A well-built plan accounts for this by defining operator tasks per scenario and distributing monitoring load so no single operator carries more feeds than one person can absorb.
Floor Wardens
Floor wardens put the plan into action on every floor. As they exit, they direct occupants to evacuation routes and confirm their floor is clear before reporting completion to the command center. Warden coverage should be adequate during all working hours. Wardens must know the workplace layout, alternative escape routes, and any occupants who need assistance. Their duties often include checking offices and restrooms and ensuring fire doors close on exit.
Guards, Search Teams, and Executive Notification
Security guards are first responders and guides. They control access during evacuations and coordinate with arriving responders, while search and rescue members sweep designated areas and report status to the Incident Commander. The plan should define executive notification, including the senior-leadership notification owner, threshold, and channel, so the Incident Commander retains operational decisions.
Build Scenario-Specific Procedures and the Decision Criteria for Each
Security leaders remove ambiguity by tying each response to defined triggering conditions.
For the scenarios corporate sites face, the details vary. Active-shooter planning documents vulnerability factors such as occupancy and access, plus threat history. It organizes response into hot, warm, and cold zones by proximity to the threat.
Fire planning documents evacuation and drills and follows NFPA 72 for alarm and signaling. Medical planning documents personnel trained in first aid, CPR, and AED use, along with kit and defibrillator locations so responders can act without delay. Tornado planning identifies safe interior areas away from windows and confirms accountability procedures. Bomb threats are classified as risk levels of low, medium, or high, with response options escalating from assess-and-discount through lockdown, evacuation, and search.
Evacuation
Evacuation moves people away from a threat immediately and applies to fires, explosions, floods, severe weather, hazardous releases, and workplace violence. The plan must specify the reporting method, evacuation routes and assignments, procedures for anyone who stays to run critical operations before leaving, and rescue and medical duties.
Post-evacuation steps carry equal weight. The plan designates assembly areas and requires a headcount. Anyone unaccounted for is reported to the Emergency Operations Center with a name and last-known location. It also establishes how to account for visitors and contractors, and how to extend the evacuation if the incident grows.
Shelter-in-Place
Shelter-in-place directs occupants to select interior rooms with few or no windows and take refuge there. It is the correct response when chemical, biological, or radiological contaminants are released outdoors in quantities that make staying inside safer than leaving. The decision trigger depends on information from local police and fire officials indicating that remaining inside is safer than evacuating.
Occupants close or tape vents, seal gaps under doors and windows with plastic sheeting or wet towels, and set HVAC to full recirculation or shut it off. Procedures should cover both short sheltering periods and chemical emergencies that require sheltering for far longer.
Lockdown
Lockdown temporarily shelters occupants from a security threat outside the facility. Occupants lock doors, close shades, move away from doors and windows, take cover, and hold position until the lockdown lifts. For workplace planning, terminology varies by jurisdiction and facility policy, so the plan should define whether gunfire in the immediate vicinity of the building triggers lockdown, shelter-in-place, or another protective action.
For an active shooter or violent intruder, Run, Hide, Fight gives people response options that they apply by proximity to the threat:
- Run means escaping if a path exists and leaving belongings behind.
- Hide means locking and barricading, silencing devices, and staying out of view.
- Fight, as a last resort, means committing to decisive action to incapacitate the attacker.
Individuals assess their own proximity to the threat and choose independently, which is why the plan trains options instead of dictating one path.
Planners pre-resolve these choices by threat type: an outdoor chemical release or a tornado drives shelter-in-place, an indoor release or fire drives evacuation when leaving is safe, and an outside security threat drives lockdown. Each scenario affords a different amount of time, and the plan should reflect how much each realistically allows.
Establish Communication Protocols
Coordinated response depends on messages reaching the right people through channels that survive the incident. Communication protocols cover occupant mass notification and the escalation paths that connect command staff with law enforcement and EMS.
Mass Notification
NFPA 72 governs mass notification technically, and Chapter 24 covers emergency communications systems. The standard organizes notification into layers. In-building systems alert occupants inside a structure. Wide-area systems reach occupants across multiple buildings or a campus from centralized control.
Where the emergency response plan requires it, NFPA 72 mandates remote activation of live and prerecorded emergency messages. In-building notification must deliver intelligible audio alongside visible notification for hearing-impaired occupants and high-noise areas.
Internal Escalation
Internal escalation uses the ICS structure. A single Incident Commander or a Unified Command provides orderly command across the Command, Operations, Planning, Logistics, Intelligence/Investigations, and Finance/Administration functions.
A workable escalation model names the authority holding operational direction and logs key decisions with timestamps. Because the structure identifies who holds command at each stage, it keeps operational direction from fragmenting across guards, operators, executives, or outside responders. The timestamped log also gives the team a record for after-action review once the incident closes.
Outside Responder Coordination
Coordination with law enforcement, fire, and EMS should be arranged before an incident, not improvised during one. Share the location of public-address systems, two-way radios, security cameras, alarm controls, building schematics, door and window locations, access controls, and where occupants with disabilities may shelter. Outside responders then arrive with better situational awareness and can act on the same reference points the internal team is using.
Integrate Security Systems into the Response
Security teams act faster when access-control events and video verification feed directly into alarm response actions. Integrated systems can convert a written procedure into a defined technical trigger.
Access Control Lockdown
Access control lockdown gives the plan a clear technical trigger. A physical access control system authenticates credentials, authorizes entry and then logs activity. It lets authorized personnel lock individual doors or an entire facility from a single control, securing doors within seconds. NIST SP 800-53 control PE-6 requires organizations to monitor physical access to detect and respond to incidents, review access logs, and coordinate results with incident response, with an additional requirement for automated recognition of defined intrusion classes and automated response actions. Access control tied to roll-call systems also produces real-time occupancy reports during a lockdown or evacuation.
Video Verification
With video verification, operators can make faster, better-informed dispatch decisions. When access is denied at a perimeter, footage from a nearby camera can display at the operator workstation and alert the facility manager to a potential breach. Central-station operators confirm signals before dispatching responders. Effective plans provide CCTV coverage across multiple angles and access points, viewable from a central command center.
Security teams should map each alarm point to the camera views needed to confirm what happened. They should also document who can pull live and recorded views and define when video confirmation changes dispatch priority. During drills, teams should test whether camera views, access-control events, and operator instructions line up at the workstation before an actual alarm.
AI Threat Detection
Operators respond faster when AI threat detection surfaces incidents on live feeds without waiting for a person to notice something is wrong. AI can flag events such as a weapon visible in a lobby, an unauthorized entry into a restricted corridor, or a person collapsed on a stairwell landing, then route the alert to the operators and responders the plan designates.
When an emergency occurs, the response team gains immediate access to relevant information, including the camera view, location, event type, and time, so decisions are based on what is happening rather than partial reports. That gives the Incident Commander earlier awareness for evacuation, lockdown, or shelter-in-place decisions and shortens the window between the incident starting and coordinated action beginning.
For the plan itself, this shifts the trigger point. Rather than depending on someone spotting an incident and reporting it, defined event criteria drive the escalation. Plans that integrate AI detection should document which events auto-notify which roles, how operators verify each alert, and how the alert connects to the mass notification and access-control actions defined elsewhere in the plan.
Train the Plan Through Exercises
Exercises include discussion-based and operations-based formats, and a mature program moves progressively from one to the other. A plan that has never been exercised is an untested assumption.
Discussion-Based Exercises
Discussion-based exercises build familiarity. Tabletops let participants analyze a scenario without deployed resources or time pressure, while seminars orient them to updated procedures and workshops produce drafts. For a corporate security team, a tabletop can walk the Incident Commander, GSOC operators, floor wardens, guards, and executive-notification contact through the same scenario and surface a short list of procedure gaps to revise before live testing.
Operations-Based Exercises
Operations-based exercises test execution. Drills train on new equipment or a single skill. Functional exercises test coordination and command functions without boots on the ground, while full-scale exercises simulate reality with multiple agencies and real-time movement of resources. For corporate sites, these exercises should include the systems and handoffs the plan relies on, such as mass notification, access-control lockdown, camera verification, roll-call information, and outside responder coordination.
Exercise Cadence and Revision
Awareness training belongs in onboarding and should recur regularly, and active-assailant training should run on a recurring cadence defined in the plan itself. Plans should also be evaluated after each drill, actual emergency, personnel change, facility layout change, or procedure change. Every HSEEP exercise type produces an After-Action Report and Improvement Plan that connects the exercise to plan revision.
Document the Plan and Keep It Reachable During an Incident
A plan no one can reach during an emergency fails at the only moment it matters. Documentation and accessibility determine whether responders can actually use it.
Plan Records and Version Control
The written plan pairs the OSHA-mandated elements with internal-control records that keep it authoritative. FEMA CPG 101 calls for a Record of Changes capturing change number, date, author, and summary, plus a Record of Distribution listing each recipient and copy count. Senior officials sign and date the plan and delegate who may modify it without senior approval. Any public or media version should omit standard operating procedures, call-down lists, and other sensitive detail.
Incident Accessibility
Accessibility during an active incident demands redundancy that assumes normal systems fail. With email, chat, and document storage all potentially unavailable, printed copies of the plan and contact list should go to everyone with a role. A practical model keeps a master copy with the response team leader, print copies inside the emergency operations center, and an electronic copy on a secure external site, with at least one copy held offsite.
Close the Loop with After-Action Reviews and Audits
The After-Action Report and Improvement Plan drives the maintenance loop that keeps the plan from aging into inaccuracy. The report documents observations and analyzes effectiveness; the improvement plan assigns corrective actions with owners and due dates. After-action reports should be completed within 120 days of any major incident, and small-scale incidents warrant a hot-wash before returning to normal operations.
Revision triggers set the loop's cadence. CPG 101 triggers include a major incident, a change in operational resources, updated planning guidance, each use of the plan, major exercises, and any change in the hazard profile. Review criteria can also account for changes in regulations, hazards, resources, infrastructure, and significant personnel turnover, supplemented by internal audits and periodic management reviews.
From Written Plan to Practiced Readiness
The strongest emergency response plans move from paper into muscle memory. Site-specific risk assessments, named authority, scenario-tied triggers, integrated systems, and rehearsed handoffs are what turn a document into coordinated action when seconds matter. Assign owners for every role, exercise the plan against realistic scenarios, and revise it after each drill, incident, staffing shift, or facility change. Readiness is measured in how quickly a team converts a warning into a decision, and how consistently that decision protects the people inside the building.
Frequently Asked Questions
What is the difference between an emergency response plan (ERP), an emergency action plan (EAP), and a business continuity plan (BCP)?
The distinction rests on who acts and when. An EAP covers emergency evacuation procedures along with other required actions during workplace emergencies, such as procedures for employees who remain to perform critical operations, accounting for all employees after evacuation, and assigning rescue and medical duties. An ERP governs responders who suppress the incident. A BCP governs operational recovery after danger ends, restoring business functions.
How do you integrate AI threat detection and access control systems into an emergency response plan to speed up incident response?
Map AI-detected events to responder roles with documented verification steps. Establish automated handoffs where alerts trigger predefined actions like zone lockdowns, then test during drills to confirm alerts, feeds, and instructions arrive simultaneously at workstations.
How often should an emergency response plan be tested and updated, and what triggers a revision?
Testing cadence should align with risk tolerance and regulatory requirements. Revision triggers include gaps found during hot-washes, vendor upgrades changing workflows, shifts in threat intelligence, construction altering evacuation routes, and lessons from peer incidents.