At what level should a multi-site organisation write its continuity plans, site or function?
Both, layered, and the framing of the question is the problem. Site level owns emergency and incident response: life safety, evacuation, damage assessment, local incident command. Product line, value stream or business service level owns business continuity and recovery, and this is the layer most organisations are missing. Corporate level owns crisis management and arbitration of resources across the network. Location is a dependency attribute, not a plan silo.
Published
Maximilian Bazzi, Founder and CEOWhy the question is framed the wrong way round
Asking whether continuity plans belong at site or function level assumes one has to replace the other. In a multi-site organisation, they answer different questions and neither is optional. Site level owns emergency and incident response: life safety, evacuation, damage assessment and local incident command, none of which can be run from anywhere but the site itself. Product line, value stream or business service level owns business continuity and recovery: whether the organisation can keep delivering a given product or service when one site cannot produce it, which a single site's own plan structurally cannot answer. Corporate level owns crisis management and the arbitration of shared resources across the network when more than one site or product line needs them at once.
The objection that has to be conceded, not dismissed
Centrally written, function-level plans have a genuine and well-earned reputation as shelfware. The plant manager, during an actual incident, opens the site plan, not a corporate document written for a layer they do not operate at and rarely read outside an audit. That criticism is correct about a function-level plan built to replace the site plan. It is not an argument against having a product-line or function layer at all, only against building it as a substitute for the plan that does the job only the site can do.
The site plan keeps that job. What the product-line layer answers is the question the site plan cannot answer by design: how the organisation keeps delivering when the resource that is lost, whether tooling, qualified staff or a specific process, is shared across more than one site. Both layers stay usable, and stay used, because the underlying dependency data is mastered once and presented back as a role-specific view: an evacuation and local recovery view for the site, a substitution and resource-arbitration view for the layer above it.
What the standard actually says
It is worth being precise here, because getting it wrong undermines the argument with anyone who has read the standard. ISO 22301 does not prescribe a site-level or function-level plan structure, and ISO 22313 states explicitly that uniformity of structure is not the intent. The honest claim is narrower and still decisive: the standard's own logic runs from products and services, through the activities that deliver them, to the resources those activities depend on. Location falls out of that chain as a dependency attribute, one property of a resource among several, rather than the organising unit for the whole plan structure.
Why regulated manufacturing makes this non-negotiable
A site-only plan implicitly assumes production can move to wherever capacity exists. In regulated manufacturing, that assumption is often illegal or impossibly slow to act on within any relevant recovery window. Pharmaceutical technology transfer between sites can run into years before regulatory review is even complete. Aerospace parts require sequential certification that cannot be skipped under pressure. Automotive part approval prohibits shipping from an alternate site until approval is granted, regardless of physical capacity to produce. In each case, the product-line layer is not an optimisation on top of the site plan. It is the layer that tells you, before an incident, whether substitution is even a legally available option.
How Bazzi Consulting helps
We build the product-line and corporate layers that sit above your existing site plans, mapping the dependency and qualification data that determines whether substitution is real, without replacing the plans your site teams already rely on. See risk and resilience advisory.