Governance, Risk & Compliance

Business continuity planning for workforce disruption

How Australian employers build the workforce side of business continuity: business-impact analysis and minimum service levels, dependency mapping, lawful response options, decision authority, communication and privacy, safety in degraded operation, testing and controlled recovery.

By the AWS Editorial Team
Leadership team reviewing a business continuity scenario plan
Structured scenario planning prepares leadership teams for workforce disruption before it occurs.

Key points

  • Business continuity, crisis management, emergency planning and IT disaster recovery are connected but distinct, and a continuity plan does not discharge jurisdiction-specific emergency-plan or WHS/OHS duties.
  • ISO 22301 certification is voluntary; neither certification nor a successful exercise proves legal compliance or real operating capability.
  • Workforce dependency mapping must reach past job titles to skills, licences, tacit knowledge, delegations, credentials, physical access and external labour.
  • Response options such as stand down, altered duties, hours or location depend on the applicable statute, instrument or contract and the facts; a plan cannot create rights that do not otherwise exist.
  • Employment, consultation, WHS/OHS, privacy and discrimination obligations continue during disruption, and degraded operation itself creates fatigue and psychosocial risk.
  • Test operating capability rather than document completeness, and manage recovery as a controlled phase with backlog decisions, reconciliation and verified corrective actions.

What workforce continuity is — and is not

Business continuity, crisis management, emergency planning and IT disaster recovery are connected, but they are not the same discipline and they do not discharge the same obligations. Crisis management is the leadership response in the acute phase. Emergency planning deals with immediate threats to people and premises, and in Australia it is governed by enacted work health and safety or occupational health and safety law in each jurisdiction rather than by any continuity framework. Disaster recovery is the technical restoration of systems and data. Business continuity is the wider capability that keeps prioritised activities running at an acceptable level while those other processes do their work, and that brings the organisation back to normal operation in a controlled way.

The workforce dimension is the part most often left implicit. Plans frequently describe which systems must be restored and in what order, without stating who is expected to perform the prioritised work, what authority they hold, what happens when they are unavailable, and which options for changing work, hours, duties or location are lawfully available. A continuity plan is a management instrument. It cannot override employment, industrial, work health and safety, privacy, consultation, discrimination or contractual obligations, and it cannot create a right to vary those arrangements that does not otherwise exist under an award, enterprise agreement, contract or statute.

ISO 22301:2019 is a voluntary requirements standard for a business continuity management system, updated by Amendment 1:2024; the ISO public overview material sets out the general approach. Certification is optional. Neither certification nor a well-run exercise establishes or proves legal compliance or real operating capability, and an organisation that never seeks certification can still adopt the useful disciplines: impact analysis, prioritisation, tested options, defined authority and verified evidence.

Start with business impact, tolerances and minimum service

A workforce-aware business impact analysis begins with activities rather than departments. For each prioritised activity, the analysis records what the activity delivers, who depends on it internally and externally, what happens as disruption extends across defined time bands, and the point at which consequences change in character rather than degree — a delay becomes a safety issue, a service failure becomes a regulatory notification, a backlog becomes irrecoverable. Those thresholds are more useful than a single recovery-time figure, because they tell decision-makers when the response must change.

Tolerances should be expressed as the minimum acceptable level of service and the minimum capacity required to deliver it, not as an aspiration to maintain normal output with fewer people. That distinction matters. Stating that a function can run at sixty per cent capacity for five working days is a planning assumption that must be tested; asserting it without examining workload, skills, supervision and safety is a way of importing risk into the plan. Where an activity cannot be performed safely or lawfully below a given staffing level, that floor belongs in the analysis as a stop-work threshold with a named person authorised to suspend the activity.

The analysis should also record the sequence in which activities resume, the backlog each will generate, and who is authorised to defer or suspend non-critical work so that capacity can be redirected. Deferral decisions made in advance are far easier to execute than deferral decisions negotiated during disruption. No single metric or template is universally mandated; the useful test is whether the analysis supports a decision that a leader would actually be prepared to make and defend.

Map workforce dependencies and single points of failure

Dependency mapping fails when it stops at job titles. A title tells you almost nothing about whether the work can continue. The map needs to reach the attributes that actually make the work possible: specific skills and current licences or registrations; tacit knowledge held by long-tenured people and never written down; formal decision authority and financial or operational delegations; system permissions and administrative credentials; physical access to sites, plant or secure areas; and the hand-offs that connect the activity to upstream and downstream teams.

External dependencies deserve the same treatment. Labour hire, contractors, professional service providers, managed service vendors and outsourced payroll or contact-centre functions all carry their own workforce risk, and their continuity arrangements are rarely visible unless someone asks. Contractual service commitments are not the same as tested capability, and a supplier's continuity plan may assume access to the same labour pool the organisation is relying on.

Single points of failure become tractable once they are named. Cross-training, documented short-form runbooks and planned succession reduce single-person dependence, but they must be honest about their limits. A runbook does not confer competence, and cross-training does not confer a licence, a supervisory qualification or a delegated authority the person does not hold. Where a task legally requires a particular licence, authorisation or level of supervision, the continuity option is to arrange a genuinely qualified alternate in advance — not to assume the task can be covered informally.

A five-scenario workforce-continuity decision matrix

The matrix below is a planning aid. It frames the questions leaders should be able to answer before disruption, the options that may be available, and the evidence that shows whether a control works. It does not determine legality. Whether a particular response is available in a given situation depends on the applicable instrument, contract and statute and on the facts, and fact-specific questions belong with a qualified legal adviser.

Scenario or signalContinuity objectiveWorkforce options and constraintsDecision owner and escalationEvidence and effectiveness test
Illness or absence cluster reducing available staff across a shift or siteHold prioritised activities at minimum service; protect safe staffing floors; prevent backlog becoming irrecoverableRedeploy trained staff, adjust rosters within the applicable instrument, engage pre-qualified relief, defer non-critical work. Roster, hours and duties changes may require agreement, notice or consultation; leave entitlements continueOperational owner, with the workplace adviser consulted; escalate to the continuity lead when a stop-work threshold is approachedRoster and coverage records; overtime and fatigue data; deferred-work log. Test: was minimum service held without breaching fatigue limits or entitlements?
Sudden loss of a critical role, licence holder or delegated decision-makerRestore authority and competence to the activity without misrepresenting qualificationActivate named alternate; confirm the alternate holds the required licence, competence and delegation; suspend the activity where no qualified alternate existsAuthorised executive for delegations; operational owner for task allocation; escalate where suspension affects customer or regulatory commitmentsDelegation instrument, licence register, runbook currency. Test: did the alternate operate the activity without a competence, supervision or authority gap?
Notified industrial action affecting a critical operationMaintain safety and lawful minimum service; plan contingencies without interfering with workplace rightsPlanning question, not a legal conclusion: whether action is protected or unprotected, and what may lawfully be done in response, depends on the Fair Work Act and the facts (FWO industrial action guidance). Options must be assessed before useContinuity lead with the workplace adviser and authorised executive; legal advice obtained before any pay, engagement or response decisionNotices received, advice sought and recorded, safety assessments, communications issued. Test: were decisions made on advice and recorded contemporaneously?
Payroll or core-system outageKeep people paid correctly and on time; keep prioritised work moving under manual controlsPre-agreed manual or provisional payment approach with reconciliation, offline time capture, restricted manual approvals. Pay obligations continue during an outage; provisional payments require a defined correction pathPayroll and finance owner with the privacy or security lead; escalate to the authorised executive for provisional payment approvalOutage log, provisional payment register, reconciliation results, access records. Test: were all affected employees paid correctly after reconciliation, with variances identified and closed?
Site inaccessibility or supplier / labour-hire failureRelocate, degrade or suspend affected activity safely; maintain external commitments where possibleAlternate site or remote work where the work can be done safely and lawfully; substitute suppliers pre-qualified; changes to location or duties may require agreement or consultation and raise WHS or OHS duties for the new arrangementIncident controller for site decisions; WHS or OHS lead for the safety of altered work; escalate supplier substitution to procurement and the authorised executiveAccess decisions, risk assessments for altered work, supplier activation records. Test: was the alternate arrangement assessed for safety before use, and did it deliver the planned service level?

Build lawful response options before disruption

The value of a continuity plan lies in options that have already been tested for lawfulness. Under time pressure, organisations reach for whichever lever appears closest to hand, and the levers that appear closest are often the ones with the most conditions attached. Stand down is the clearest example. It is not a general continuity option and not an automatic right to stop pay: its availability depends on the Fair Work Act or an applicable enterprise agreement or contract term, and on the facts, including whether employees can be usefully employed because of a stoppage for which the employer cannot reasonably be held responsible. The Fair Work Ombudsman's stand-down guidance is a starting point, not a substitute for advice on a specific set of facts.

The same discipline applies to alternative duties, changes of location or hours, direction to take leave, reduced hours and temporary redeployment. Each depends on the source of the authority relied on — an express contract term, an award or enterprise agreement provision, a statutory power, or the employee's agreement — and several will engage consultation obligations about major change or roster change. Employment, award, agreement, general protections, discrimination, leave and pay obligations continue during disruption. A plan that assumes a change can simply be directed because the circumstances are exceptional is a plan that generates a second dispute on top of the first.

The practical approach is to record, for each option, the authority relied on, the conditions attached, who may approve it, what consultation or agreement is required, and the point at which legal advice must be obtained before use. Where major change or restructuring is contemplated as an outcome rather than a temporary measure, the separate obligations discussed in the guide to employee communication during restructure apply and should not be collapsed into the continuity response.

Decision authority, alternates and escalation

Disruption exposes ambiguity in authority faster than it exposes any other weakness. The plan should name the continuity lead, the incident controller or crisis lead, the operational owner for each prioritised activity, the human resources or workplace adviser, the work health and safety lead, the communications lead, the privacy and security lead, the payroll and finance owner, and the executive authorised to commit expenditure or approve exceptions. For each, it should name at least one alternate who is genuinely available and has been briefed.

A responsibility matrix is useful only when the authority behind it is real. That means confirming that delegations are documented and current, that the alternate can actually exercise them, that escalation thresholds are stated in observable terms rather than as judgement calls, and that the people named have exercised the role in an exercise at least once. Delegations that exist only in a plan tend to fail at the first approval that requires a signature, a system permission or a bank authorisation.

Escalation should be defined by trigger rather than by seniority instinct: a stop-work threshold reached, a safety incident, a suspected data breach, an approach from a regulator or union, a decision requiring legal advice, or disruption extending beyond a stated tolerance. Recording who decided what, on what information and at what time is part of the operating discipline, not an administrative afterthought; those records are what allow the organisation to explain its decisions afterwards.

Communication, consultation and privacy

Communication capability depends on channels that have been verified recently. Contact details decay, personal numbers change, distribution lists inherit people who have left, and the intranet is unavailable in precisely the scenarios where it is most needed. Primary and fallback channels should be tested, and the test recorded. Messages should be prepared for distinct audiences — affected employees, managers, employees not directly affected, contractors and labour hire, customers, suppliers, and representatives or regulators where relevant — because a single all-staff message rarely serves any of them well.

Content discipline matters more than speed. Each message should distinguish what is known, what is not yet known, what is being done and when the next update will come, and should be accessible to employees with disability, employees who do not work at a screen and employees whose first language is not English. It is not universally true that an immediate holding message is the better course: in some situations a short delay to verify facts prevents a correction that damages credibility. What should be fixed in advance is the cadence and the person authorised to issue updates, not a promise about timing that the organisation cannot keep.

Consultation obligations continue during disruption. Work health and safety consultation with workers and health and safety representatives applies to emergency arrangements and to changes affecting health and safety — Safe Work Australia's material on emergency plan duties describes the model-law position, which has effect only as enacted in each jurisdiction. Industrial consultation obligations under an award or enterprise agreement are separate, with their own triggers.

Privacy obligations also continue. Workforce contact details, emergency contacts, and any health information collected during disruption must be collected, used, disclosed, secured, retained and destroyed lawfully. The OAIC's guidance on emergencies and disasters explains that particular permitted handling arrangements have a defined scope and conditions; an emergency does not operate as a general waiver. The federal employee-records exemption is limited in the entities, records and handling activities it covers, and should not be assumed to apply to every organisation or to every record created during a disruption.

WHS/OHS and psychosocial safety during degraded operations

Degraded operation is the condition in which safety risk most often increases. Fewer people do more work, supervision thins, unfamiliar staff perform unfamiliar tasks, manual workarounds replace system controls, and hours extend. Duties under the applicable enacted work health and safety or occupational health and safety law continue in full, and continuity arrangements are themselves a change to the way work is carried out. Safe Work Australia's overview of emergency plans reflects the model laws, which apply in a jurisdiction only as enacted there. Victoria has not adopted the model laws; Victorian duties arise under the Occupational Health and Safety Act 2004 (Vic) and its regulations, expressed in terms of employers and employees rather than PCBUs and workers, and Victorian arrangements should be described in Victorian terms.

The hazards worth planning for in degraded operation are predictable: fatigue from extended hours and consecutive shifts; excessive demands and low job control; role ambiguity when authority shifts; remote or isolated work introduced at short notice; exposure to distressed customers, aggression or traumatic material; and the cumulative effect of prolonged uncertainty. Fatigue limits and workload thresholds should be stated in the plan and treated as controls rather than guidance, with a named person authorised to stop or reduce work when they are reached.

Support arrangements have a role, but they are not controls for work design. An employee assistance program does not reduce workload, restore supervision or fix an unsafe manual workaround. Where a continuity arrangement is expected to run for more than a short period, the psychosocial dimensions should be assessed in the same way as any other change to work; the material on managing psychosocial risk during organisational change sets out that approach in more detail.

Testing capability rather than testing the document

Most continuity testing measures whether a document exists and whether people can find it. Useful testing measures whether the organisation can operate. That means exercising the things that fail in practice: the call tree with real numbers dialled; role failover with the nominated alternate actually making the decisions while the primary is unavailable; the manual workaround performed end to end by the people who would perform it; a payroll or core-system outage run through to reconciliation; and a recovery rehearsal that includes the backlog, not only the restoration.

An exercise needs the same structure as any other controlled activity: stated objectives, explicit assumptions, injects that change conditions mid-exercise, independent observers, safety boundaries so the exercise itself does not create risk, and a record of what was observed rather than what was intended. Where an exercise is designed so that it cannot fail, it produces reassurance and no information. It is more useful to run a narrow exercise that surfaces two real defects than a broad one that confirms the plan reads well.

Every exercise should close with findings that have owners, due dates and a verification step confirming that the change was made and works. Frequency depends on risk and rate of change rather than a fixed rule: material changes to structure, systems, sites, suppliers or key personnel are better triggers than the calendar, though most organisations benefit from at least an annual cycle that touches each critical activity over time.

Recovery, backlog and return to normal authority

Recovery is a phase to be managed, not the absence of disruption. It should begin with stated restoration criteria — what must be true before an activity returns to normal operation — and a deliberate review of every temporary control introduced during the response. Manual approvals, elevated system access, relaxed segregation of duties, temporary delegations and short-term supplier arrangements should each be either formally retained with justification or withdrawn, and the withdrawal recorded.

Accumulated work is where recovery most often goes wrong. Backlog should be prioritised on the same basis as the original impact analysis, with explicit decisions about what will not be recovered, and communicated to the customers, regulators or internal stakeholders affected. Clearing a backlog by asking an already-depleted workforce to absorb it is a fatigue and psychosocial risk in its own right, and should be planned with the same limits that applied during the response.

The closing steps are administrative but consequential: reconcile data created under manual controls, return delegated authority to the substantive holders, confirm that access granted during the disruption has been revoked, meet or renegotiate commitments made to customers and regulators, and run an after-action review that records what actually happened, which assumptions held, which did not, and what will change. Findings should feed back into the impact analysis and the dependency map rather than sitting in a standalone report.

Two worked examples

Example A — payroll and core-system outage with reduced availability. A services organisation loses its payroll and rostering platform on the Tuesday of a pay week while an absence cluster has already reduced available staff by around a quarter. The continuity lead applies the impact analysis: client-facing delivery for two priority contracts and the pay run itself are held at minimum service, while internal reporting, non-urgent onboarding and scheduled audits are formally deferred with a dated record. Time capture reverts to a pre-agreed offline method with supervisor verification, and manual approval limits are activated with restricted access and a log of every approval. Payroll and finance propose provisional payments based on the previous cycle for employees whose hours cannot be verified in time; the authorised executive approves the approach on advice, and a correction path with a stated date is set for the following cycle. Communications go out through a verified fallback channel, distinguishing what is known from what is not, and are repeated on a stated cadence. Fatigue limits are applied to the payroll team despite the pressure, with a second-day handover rather than extended shifts. On restoration, every provisional payment is reconciled, variances are identified and corrected, elevated access is revoked, and the after-action review notes that the offline time-capture method worked but that two supervisors had never used it. That becomes a training action with an owner and a verification date. The outage is contained, but not costlessly: the deferred audits still have to be rescheduled and one contract commitment is renegotiated.

Example B — notified industrial action affecting a critical operation. A distribution operation receives notice of proposed industrial action affecting a shift that supports a time-critical service. The organisation's first step is to obtain legal advice on the notice, the status of the proposed action and what it may and may not lawfully do in response; nothing about pay, engagement of other labour or the response to employees is decided before that advice is received and recorded. Continuity planning proceeds on the questions that are properly management questions: which activities are prioritised, what the safe minimum staffing level is, at what point the activity would be suspended rather than run understaffed, and which customer commitments would be varied. The work health and safety lead assesses the safety of any altered arrangement, and consultation with workers and health and safety representatives about those safety arrangements proceeds under the applicable enacted law. Communications are factual and neutral, avoid commentary on the merits of the dispute or on employees' choices, and are checked before issue. Established representative and dispute-resolution channels are used rather than bypassed. Escalation points are set in advance: a change in the notice, a safety threshold reached, or any proposal that could affect employees' entitlements or workplace rights goes back to the adviser and to legal advice before action. The evidence retained includes the notices, the advice sought, the safety assessments, the minimum-service decisions and the communications issued. The operation runs at reduced service for the period; the organisation cannot guarantee that outcome in advance, and the plan says so.

Where AWS assists and when legal advice is required

Australian Workplace Strategies, a division of Parke Corporation Pty Ltd, is a workplace consultancy. AWS assists employers with workforce-aware business impact analysis, continuity governance design, scenario development and facilitated tabletop exercises, consultation and communication design, assurance reviews of existing plans, and the workflow and evidence support available through GRC technology and Strobe. Where a continuity program needs to sit inside a broader compliance structure, the approach described in the guide to a workplace compliance framework that is monitored and evidenced is a useful reference point.

AWS does not provide legal advice. Questions about whether a stand down is available, whether a direction may lawfully be given, how a particular award or enterprise agreement term operates, the status and consequences of industrial action, or the application of privacy or work health and safety law to a specific set of facts should be referred to a qualified legal adviser, and the plan should say when that referral is mandatory rather than optional.

A platform supports continuity governance; it does not constitute it. Software can hold approved plan versions, dependency maps, delegations, contact-verification records, exercise findings and corrective actions, and can make overdue items visible. Accountability for the decisions those records describe remains with the named owners and the executive. Where the employment or industrial dimensions of a scenario are material, workplace advisory support alongside legal advice is usually the more efficient path.

A 12-step workforce continuity checklist

  • 1. Complete a workforce-aware business impact analysis identifying prioritised activities, disruption tolerances and the point at which consequences change in character.
  • 2. Define the minimum acceptable service level and minimum safe capacity for each prioritised activity, with stated stop-work thresholds.
  • 3. Map workforce dependencies beyond job titles: skills, licences, tacit knowledge, delegations, credentials, physical access, external labour and hand-offs.
  • 4. Identify single points of failure and address them through cross-training, short-form runbooks and qualified alternates, without misrepresenting competence or authorisation.
  • 5. Record each response option with the authority relied on, conditions, approver, consultation or agreement required, and the point at which legal advice must be obtained.
  • 6. Name the continuity, incident, operational, workplace-adviser, WHS/OHS, communications, privacy, payroll and executive roles, each with a briefed alternate and current delegations.
  • 7. Verify primary and fallback contact channels and distribution lists, and record the date and result of each verification.
  • 8. Assess the work health and safety and psychosocial implications of degraded operation, including fatigue limits, workload thresholds, remote or isolated work and altered supervision, under the enacted law of each jurisdiction.
  • 9. Confirm lawful handling of workforce contact and health information, including collection limits, access control, retention, destruction and the limited scope of any exemption relied on.
  • 10. Prepare audience-specific communication templates and a defined update cadence that separate known facts from provisional information.
  • 11. Exercise operating capability — call trees, role failover, manual workarounds, payroll or system outage and recovery rehearsal — with objectives, injects, observers and recorded findings.
  • 12. Plan recovery and verification: restoration criteria, temporary-control withdrawal, backlog prioritisation, data reconciliation, after-action review, and closure of every action with evidence that the change works.

Frequently asked questions

How is business continuity different from crisis management and emergency planning?
Crisis management is the leadership response during the acute phase of an event. Emergency planning addresses immediate threats to people and premises and is governed by the enacted work health and safety or occupational health and safety law of each jurisdiction. Business continuity is the wider capability that keeps prioritised activities running at an acceptable level during disruption and returns the organisation to normal operation in a controlled way. They overlap, but a continuity plan does not by itself satisfy emergency-plan or WHS/OHS duties.
Does ISO 22301 certification prove that an organisation is resilient or legally compliant?
No. ISO 22301:2019 is a voluntary requirements standard for a business continuity management system, and certification against it is optional. Certification indicates that a management system met the standard's requirements at the time of audit. Certification does not establish or prove compliance with Australian employment, work health and safety or privacy obligations, and it does not demonstrate that the organisation can actually operate through a disruption. A successful exercise is similarly limited: it shows what was tested under the assumptions used.
Can an employer stand employees down whenever disruption prevents normal operations?
No. Stand down is not a general continuity option or an automatic right to stop pay. Its availability depends on the Fair Work Act or an applicable enterprise agreement or contract term, and on the facts — including whether employees can be usefully employed because of a stoppage for which the employer cannot reasonably be held responsible. Alternatives such as altered duties, changed location or hours, or directed leave each require their own source of authority and may trigger consultation or agreement. These are fact-specific questions for legal advice.
How should industrial action be handled in a continuity plan?
A continuity plan can address contingency questions that are properly management questions: which activities are prioritised, what the safe minimum staffing level is, when an activity would be suspended, and how communications and escalation will work. It should not attempt to determine whether particular action is protected or unprotected, and it must not be used to interfere with workplace rights. Decisions affecting pay, engagement of other labour or responses to employees should be taken on legal advice, and the plan should say so explicitly.
What workforce dependencies should a business-impact analysis identify?
More than job titles. A useful analysis records the specific skills, current licences and registrations, tacit knowledge, formal decision authority and delegations, system permissions and credentials, physical site or plant access, and upstream and downstream hand-offs each prioritised activity relies on. It should also cover external dependencies — labour hire, contractors, vendors and outsourced functions — because their continuity arrangements may assume the same labour pool the organisation is relying on.
How should employee contact and health information be handled during disruption?
Lawfully, and on the same terms as at any other time. Collection should be limited to what is needed, access restricted to those who require it, disclosure justified, and retention and destruction managed. The OAIC's emergencies and disasters guidance explains that particular permitted handling arrangements have a defined scope and conditions; an emergency is not a general privacy waiver. The federal employee-records exemption is limited in the entities, records and handling activities it covers and should not be assumed to apply to every organisation or record.
How often should a workforce continuity plan be tested?
Frequency should follow risk and rate of change rather than a fixed rule. Material changes to structure, systems, sites, suppliers or key personnel are stronger triggers than the calendar, though most organisations benefit from a cycle that touches each critical activity at least annually. What matters more than frequency is what is tested: call trees with numbers actually dialled, role failover with the nominated alternate deciding, manual workarounds run end to end, and recovery rehearsed including the backlog.
Can Strobe or another GRC platform replace accountable continuity governance?
No. A platform can hold approved plan versions, impact-analysis assumptions, dependency maps, delegations, contact-verification records, exercise findings, decisions, exceptions and corrective actions, and can make overdue items visible to the people accountable for them. It supports workflow and evidence. Accountability for the decisions those records describe remains with the named owners and the responsible executive, and no system substitutes for tested capability.

Discuss this matter with AWS

Briefings can be scoped on a confidential basis. We respond within two business days.

Contact AWS