A pandemic risk assessment examines how a widespread outbreak of disease would affect your people, suppliers, customers and critical activities, and what you would do at each stage. Many organizations wrote pandemic plans after earlier outbreaks, discovered in 2020 which assumptions failed, and then let the plans lapse again. A short, well-structured assessment kept up to date is far more useful than a long plan nobody reads.
This guide explains how to carry out a pandemic risk assessment as part of business continuity management: what makes a pandemic different from other disruptions, how to build scenarios, how to identify essential roles, how to test supply and demand effects, and how to record triggers and decisions.
Why a pandemic differs from other business continuity events
Most continuity planning focuses on the loss of a site, a system or a supplier. A pandemic is different in four ways. It affects people rather than places, so relocating does not help. It can last for months and arrive in waves rather than as a single event. It hits many organizations at once, including your suppliers, your customers and the services you rely on. And the severity is uncertain at the start, so decisions must be made with incomplete information.
These features change the questions you ask. Instead of asking how quickly you can recover a system, you ask how long you can operate with a fraction of staff absent, and what you would stop doing first. Our guide to business impact analysis versus risk assessment explains how the impact analysis identifies which activities matter, which is the basis for choosing what to protect.
Free business impact analysis
How long can each activity really be down?
Rate the impact of an outage over time, set RTOs and maximum tolerable periods of disruption, map the people, systems and suppliers behind each activity, and get a recovery sequence back, free.
Run the free business impact analysis → or View premium report sample
Where a pandemic risk assessment fits in ISO 22301
ISO 22301:2019 requires an organization to assess risks of disruption to prioritized activities and to establish continuity strategies and plans. A pandemic is one of the disruption scenarios to consider, alongside events covered by a general business continuity threat assessment. Feed the results into the same risk register and plans, so that the pandemic is not handled in a separate document that drifts out of date. See our guide to ISO 22301 risk assessment for the requirements.
Free business continuity risk assessment
What could stop your most important activities?
List your prioritized activities and what they depend on, pick from 32 disruption scenarios, rate them and choose continuity measures for each. Built to ISO 22301 clause 8.2.3, and free.
Run the free continuity risk assessment → or View premium report sample
Public health bodies publish guidance and planning tools. The US government’s Ready.gov pandemic page gives basic preparedness advice, and your national health agency will have sector-specific material and current advice, which should take precedence over anything general.
Lessons from recent experience for a pandemic risk assessment
The World Health Organization declared COVID-19 a pandemic on 11 March 2020, and organizations everywhere tested plans that had rarely been exercised. Common lessons were consistent. Plans assumed short events, but disruption lasted years. Remote working capacity was inadequate at first. Supply chains that looked diversified turned out to share upstream sources. Communication was slower than expected, and decisions about closing sites, protecting staff and serving customers were made without pre-agreed criteria. Use these lessons as prompts: for each, ask whether your current assumptions would hold, and record what you would change.
Building scenarios for the pandemic risk assessment
Define a small number of scenarios of increasing severity, rather than trying to predict one. Each scenario should describe the level of staff absence, the duration, and effects on suppliers and demand. The descriptions below are illustrations to be replaced with your own assumptions and current public health advice.
| Scenario | Staff absence assumption | Other effects to consider |
|---|---|---|
| Moderate | Modest peak absence for a few weeks | Some supplier delays, more remote work |
| Serious | High absence at peak in waves over several months | Supply shortages, demand shifts, travel limits |
| Severe | Very high absence and restrictions on movement | Closures of sites, supplier failures, border limits |
State the assumptions and their sources in the record, and revisit them when new data or advice appears. Absence includes people who are ill, who are caring for others, who cannot travel and who are asked to stay away, so the number is higher than illness alone.
Identifying essential roles and single-person dependencies
Work from your prioritized activities to the roles needed to run them at a reduced level. For each, record the minimum staffing, the skills involved and whether another person could cover. Look especially for one-person dependencies: the only person who can run payroll, release code, operate a machine or hold a licence. Our guide to single point of failure analysis shows how to find and treat them.
- List critical activities from the impact analysis.
- Define minimum staffing for each at reduced service.
- Identify backups and cross-training needs.
- Identify roles that can be done remotely and those that cannot.
- Prioritize what to stop if absence exceeds what you can cover.
Testing remote working and technology capacity
Remote working is the main mitigation for office-based work, but it has limits. Check that enough staff have suitable devices, secure access, bandwidth, and the ability to work from home for long periods. Test the capacity of remote access, identity services and collaboration tools under a full-workforce load, not just a small pilot. Consider security: a sudden move to remote work increases exposure to phishing and unmanaged devices. For roles that cannot be done remotely, such as manufacturing, healthcare, logistics and retail, plan for on-site controls, shift patterns and separation of teams, following current health guidance.
Supply chain and demand effects
A pandemic disrupts suppliers, transport and customers at the same time. For each critical supplier, ask about their own plans, their sources of labor and materials, the countries involved and their ability to prioritize you. Identify items with a single source and consider stock, alternative suppliers or design changes. On the demand side, consider sharp falls, surges or shifts in what customers need, and what that means for cash flow and capacity. Our article on supplier business continuity assessment explains how to gather assurance from suppliers.
Triggers, decisions and communication
Write down the triggers that move you from one response level to another, such as a public health declaration, a defined level of absence, restrictions on movement or the closure of a key supplier. Name who makes each decision, and how staff, customers and suppliers will be informed. Prepare template messages in advance. Decisions in a slow-moving crisis can drift, so record them with dates and reasons, and review the situation on a fixed schedule.
A short worked example
A regional insurer completes its assessment. It finds that claims handling needs at least half of normal staffing at reduced service, that two roles in payment approval have no cover, and that the office network cannot support more than a third of staff working remotely. It agrees a serious scenario with high absence at peak, trains four backups, adds capacity to the remote access service and sets triggers for moving to remote working and for pausing non-urgent projects. It tests the plan with a desktop exercise, records what failed and updates the plan. The next review is set for the following year, or earlier if public health advice changes.
Roles, records and governance
Give the plan an owner and a small group that can meet quickly when the situation changes. Typical members are the business continuity manager, a senior executive with authority to close or reopen sites, and representatives from HR, IT, operations, procurement, communications and legal. Record decisions with dates and reasons, and keep the assumptions about absence, supply and demand together in one place so that they can be updated as facts emerge. Keep records of staff contact details and of who is unable to work on site, following privacy rules for health information, since a pandemic response involves sensitive data that must be handled carefully.
Finally, connect the work to your wider assessments. The results of the pandemic risk assessment should appear in the enterprise and business continuity risk registers, and any single points of failure found here should be treated in the same plan as those found for other scenarios.
Exercising and reviewing the plan
Test the plan with a scenario exercise that includes absence injects, supplier failures and decisions about stopping activities. Our guide to the business continuity exercise shows how to design one. Review the assessment annually, after real events and when regulation or guidance changes. Keep a lessons-learned log, since it improves the next version more than any external template.
Using a ready structure
To avoid starting with a blank page, the Business Continuity Risk Assessment Report and Workbook provides a structured report, scoring and a working register into which pandemic scenarios can be added. See also our business continuity risk assessment example for a completed record. Whichever format you choose, a pandemic risk assessment should be short, tied to your prioritized activities and refreshed regularly.
Pandemic risk assessment FAQ
Is a pandemic risk assessment required by ISO 22301?
The standard does not name pandemics, but it requires risk assessment of disruptions to prioritized activities. A pandemic is a credible scenario for most organizations, so it should be considered.
What absence rate should I assume?
Choose assumptions from current public health advice and your own experience, and test several levels. Record the source and review it when guidance changes.
How is it different from a general business continuity plan?
A pandemic affects people over a long period and hits suppliers and customers together, so plans focus on staffing, remote work and prioritization rather than on relocating or recovering a single site or system.
Who should own it?
The business continuity manager should own the method, with input from HR, operations, IT and procurement, and executive approval of triggers and priorities.
How often should it be reviewed?
Review it at least annually, after any real outbreak or exercise and when public health guidance, regulation or your operations change materially.