Your emergency preparedness and response procedure is almost certainly a good document. That is not a compliment — it is the problem. Across 200+ certification and surveillance audits, MSI has watched registrars open emergency plans that are thorough, current, correctly formatted, approved by the right person, and quietly missing the two obligations that would have made a difference on the day something happened. The documents are strong and the capability is thin, and the reason is structural rather than careless.
This article does something the standard’s guidance annexes do not. It sets the emergency preparedness and response procedure requirements of ISO 14001:2026, ISO 45001:2018, the combined environment-and-safety case, and ISO 7101:2023 side by side, obligation by obligation, and names every place they diverge. It explains why two of those obligations go unmet in most organizations regardless of budget or intent. And it walks two real-shaped worked examples where a competent response created the exposure, and where a four-liter spill carried more regulatory weight than a nine-hundred-liter one.
If you run one standard, read your section and the divergence tables. If you run two, read the combined section — the failure mode described there only exists in organizations holding two separate procedures, and it is the strongest structural argument for one document. If you run a healthcare quality management system, the ISO 7101 section covers a named requirement at Clause 7.5.4 f) that in most hospitals lives in no procedure whatsoever.
The structural argument
Why two obligations always go missing from an emergency preparedness and response procedure
Schedule. Coordinate. Prove.
Across ISO 14001 Clause 8.2 and ISO 45001 Clause 8.2, two obligations are unmet far more often than the rest. They are not the hardest to understand. They are not the most expensive. They are these:
- Periodic testing of the planned response. Both standards require it. One of them requires it without a practicability qualifier.
- Providing information to parties outside your own payroll. Contractors, visitors, emergency services, regulators, and in ISO 45001’s case the surrounding community.
Now look at what those two have in common that no other obligation in either clause shares. Every other requirement in an emergency preparedness and response procedure can be discharged by a competent person sitting alone at a keyboard. Determining credible emergency situations: desk work. Planning the response actions: desk work. Documenting the process: desk work. Reviewing and revising after an event: desk work, mostly. Assigning the emergency coordinator: a conversation and a name in a table.
Testing cannot be done at a desk. It requires a line to stop, a shift to be committed, a night crew to be present, and somebody senior enough to authorize the interruption. Getting the fire service to walk your site cannot be done at a desk either; it requires their diary, not yours. So the emergency preparedness and response procedure gets written well and the two scheduled obligations get deferred to a quarter that never arrives. Nobody decides to skip them. They are simply the only two items on the list that cannot be closed by the person who owns the list.
Why testing goes missing: it is the only obligation in an emergency preparedness and response procedure whose evidence requires production time, a committed shift, and management authority to interrupt operations. Every other obligation in ISO 14001 Clause 8.2 and ISO 45001 Clause 8.2 can be closed by one person working alone. That asymmetry — not carelessness — is why documents pass audit while capability stays untested, and it is the observation that shapes MSI’s entire ISO consulting approach to this clause.
This matters for how you fix it. If the cause were carelessness, the fix would be training or a stronger reminder. Because the cause is scheduling, the fix is a scheduling commitment: a named date on the production calendar, an owner with authority to hold it, and a record that the auditor can sample. MSI’s work on the management review procedure makes the same argument in a different clause — the inputs that vanish are always the inputs somebody else has to produce.
An auditor reading a well-written emergency preparedness and response procedure sees conformity. An event reveals something else. The distance between those two readings is the entire subject of this article.
The comparison nobody publishes
One clause number, four different emergency preparedness and response procedures
Compare. Reconcile. Decide.
A reader who runs more than one standard reasonably assumes Clause 8.2 is Clause 8.2. It is not. The clause numbers align because of the Harmonized Structure in ISO’s Annex SL; the obligations underneath them do not. Here is where an emergency preparedness and response procedure sits in each of the five standards MSI works in.
| Standard | Clause | Clause title | Lettered obligations |
|---|---|---|---|
| ISO 14001:2026 | 8.2 | Emergency preparedness and response | Six |
| ISO 45001:2018 | 8.2 | Emergency preparedness and response | Seven |
| ISO 7101:2023 | 8.2.2 | Contingency planning for facilities and services | Eight |
| ISO 9001:2015 | — | No equivalent clause exists | — |
| ISO 13485:2016 | — | No equivalent clause exists | — |
Clause locations verified against MSI’s licensed copies of each standard. ISO 13485 uses the pre-Annex SL structure and does not share the harmonized ten-clause numbering with ISO 9001, 14001, 45001 and 7101.
That absence is worth stating plainly because people search for it. An integrated management system covering quality, environment and safety will hold an emergency preparedness and response procedure, but the obligation arrives from the environmental and safety standards, never from the quality one. When ISO 9001:2026 publishes on September 16, 2026, the same will remain true — the revision aligns the quality standard more closely with the current Harmonized Structure, and does not import an emergency clause. MSI’s ISO Executive Decision Briefs cover what the 2026 revisions do and do not change for leadership teams.
The five real divergences between ISO 14001 and ISO 45001
This is the table that determines whether one combined emergency preparedness and response procedure is defensible or whether you need two. Every row is a place where satisfying one standard leaves you short of the other.
| Point of divergence | ISO 14001:2026 Clause 8.2 | ISO 45001:2018 Clause 8.2 |
|---|---|---|
| Testing | Periodically test the planned response actions, where practicable | Periodically test and exercise the planned response — no qualifier |
| Documented information | The process available as documented information | The process and plans, maintained and retained |
| First aid | Not named in the clause | Named explicitly among the response provisions |
| Who must be told | Relevant interested parties, including persons working under its control | Enumerated: workers, contractors, visitors, emergency services, authorities, and the surrounding community |
| Involvement in developing the plan | Not required | Involvement of relevant interested parties in the development of the planned response is required |
| Proportionality to magnitude | Action appropriate to the magnitude of the emergency and the potential environmental impact | Not expressed as a separate obligation |
Comparison drawn from MSI’s licensed copies of ISO 14001:2026 and ISO 45001:2018.
Read the asymmetry rather than just the rows. ISO 45001 is more prescriptive on five of the six points, and the reason is honest: the consequence it guards against is immediate and human, arrives in seconds, and is not recoverable. A safety standard that left testing to practicability would be leaving the most consequential obligation to whoever is busiest.
Why does the environmental standard carry the stricter proportionality obligation? Because environmental consequence scales with quantity and receptor in a way injury does not. A person is injured or not. A release is measured against what receives it — a sealed yard, a storm drain, a permitted watercourse, a drinking-water aquifer. The same volume of the same substance produces radically different consequence depending on where it lands, which is exactly the logic behind receptor-based significance in ISO 14001 environmental aspects determination.
Environment
The ISO 14001:2026 emergency preparedness and response procedure in full
Determine. Prepare. Proportion.
ISO 14001:2026 published on April 15, 2026, and the transition window closes on April 30, 2029. Clause 8.2 survives the revision largely intact in wording, which has led a number of transition summaries to mark it “no change” and move on. That reading is wrong in a way that costs work, because what feeds Clause 8.2 changed materially even though Clause 8.2 itself did not.
The determination of potential emergency situations lives in Clause 6.1.2, not in Clause 8.2, and the 2026 edition promotes it to a standalone sentence with an explicit cross-reference into 8.2. It also drops “operating” from the phrase covering normal and abnormal conditions. That single deleted word widens the scope of your emergency preparedness and response procedure beyond running operations to shutdown, start-up, maintenance, construction, and the weekend when nothing is supposed to be happening. MSI covers the full set of changes in its guide to the ISO 14001:2026 updates.
The six obligations, one at a time
- a) Prepare by planning action. The plan has to prevent or mitigate adverse environmental impacts, which means the response is judged on what it protects rather than on whether it was followed. A response executed perfectly that still discharged to a watercourse has satisfied the procedure and failed the clause.
- b) Respond to actual emergency situations. Straightforward in text, and the source of the most common evidence gap: organizations respond, and never write it down in a form that ties back to the plan the response was supposed to execute.
- c) Take action proportionate to magnitude and potential environmental impact. The obligation ISO 45001 does not carry. It requires tiering, and it requires the tiers to be judged against the receiving environment rather than against volume alone. This is the single most common structural weakness MSI sees in an environmental emergency preparedness and response procedure.
- d) Periodically test the planned response actions, where practicable. Note the qualifier — and note that a qualifier is not an exemption. Where testing is not practicable, the reason belongs in the record. “We did not get to it” is not a practicability argument.
- e) Periodically review and revise the process and planned response actions. Explicitly triggered by the occurrence of an emergency or by a test. A test that produces no revision and no recorded conclusion that revision was unnecessary is a test that generated no evidence.
- f) Provide relevant information and training on emergency preparedness and response. To relevant interested parties, including persons working under the organization’s control. Contractors sit inside that phrase whether or not your induction covers them.
Two of those six — d) and f) — are the scheduled obligations from the opening argument. The other four are desk work. If you are auditing your own emergency preparedness and response procedure tonight, start at d) and f), because that is where the finding will be.
Where an ISO 14001 emergency procedure connects to the rest of the system
An emergency preparedness and response procedure that sits in isolation is the version that gets written once and never updated. The 2026 edition ties it into four other clauses, and each connection is a place a registrar can pull the thread:
- Clause 6.1.2 — aspect and emergency determination. The emergency list is an output of aspect determination, not a separate exercise. If the two lists disagree, one of them is wrong. MSI’s guide to identifying environmental aspects in the 2026 edition covers the reconciliation in detail, and the Risk, Aspect and Job Hazard Maturity Check scores it.
- Clause 4.1 — environmental conditions. The 2026 edition brings climate, biodiversity, ecosystem health, pollution levels and natural resource availability into scope as conditions capable of affecting the organization. Flood, wildfire and extreme heat are now context inputs with a documented home. See MSI’s work on ISO 14001 environmental conditions and on biodiversity in the 2026 revision.
- Clause 6.3 — planning of changes. New in the 2026 edition. A new tank, a new solvent, a new building line all change the emergency picture, and Clause 6.3 is now the traceable route by which that change reaches your emergency preparedness and response procedure.
- Clause 9.3 — management review. Test results, actual events and revisions all belong in the performance information reaching top management. MSI’s analysis of management review benefits explains why the input that never arrives is always the one nobody owns.
If you want only the emergency document rather than the full library, the ISO 14001:2026 emergency preparedness and response procedure template and guide runs thirty-one pages and covers all six obligations with the proportionality tiering already built. The ISO 14001:2026 transition course is the companion for organizations holding a current 2015 certificate.
Occupational health and safety
The ISO 45001:2018 emergency preparedness and response procedure in full
Test. Exercise. Include.
ISO 45001 places emergency preparedness and response at Clause 8.2, alongside operational planning and control rather than inside it. Seven lettered obligations follow, and the differences from the environmental version are not cosmetic. A safety emergency preparedness and response procedure copied from an environmental one will be short on five counts.
The seven obligations, one at a time
- a) An established planned response, including first aid. First aid is named in the clause, which places it inside the emergency system rather than in a separate welfare arrangement. The corresponding US regulation, 29 CFR 1910.151, adds quick-drenching or flushing facilities where corrosives are present — a provision routinely missed in laboratories and plating operations.
- b) Provision of training for the planned response. Training is separated from the plan itself, which means the record has to show competence rather than circulation.
- c) Periodic testing and exercising of the planned response capability. Two verbs, no qualifier. Testing checks whether the mechanism works; exercising checks whether people can execute under conditions they did not choose. Both are required, and evidence of one does not satisfy the other.
- d) Evaluation of performance and revision of the planned response. Explicitly after testing and after an actual event. A drill with no debrief record is a drill that never happened for audit purposes.
- e) Communication and provision of relevant information to all workers on their duties and responsibilities. All workers — not all employees. The distinction carries agency staff, labor-only contractors, and anyone else working under the organization’s control.
- f) Communication of relevant information to contractors, visitors, emergency response services, government authorities and, as appropriate, the local community. The enumerated list. This is the second of the two scheduled obligations, and the one requiring somebody else’s calendar.
- g) Taking into account the needs and capabilities of all relevant interested parties and ensuring their involvement in the development of the planned response. The requirement almost nobody implements. It gets its own section below.
Note what the enumerated list at f) does to your evidence set. A safety emergency preparedness and response procedure claiming conformity needs a record for each named category. Contractors: an induction log. Visitors: signage and a signing-in briefing. Emergency services: correspondence, a site familiarization visit, or a pre-incident plan lodged with the fire authority. Government authorities: a submission record. The local community, as appropriate: a determination that it is or is not appropriate, and the record supporting that determination. Five categories, five different evidence types, none of which can be produced at a desk.
Where the ISO 45001 emergency procedure connects to the rest of the system
- Clause 6.1.2 — hazard identification. Emergency situations are an output of hazard identification, and ISO 45001 requires emergency situations to be considered explicitly during that identification.
- Clause 5.4 — consultation and participation of workers. The clause names Clause 8.2 directly among the matters on which workers must be consulted. This is the mechanism that makes obligation g) enforceable, and the reason it goes missing is explained below.
- Clause 8.1.2 — the hierarchy of controls. Emergency response sits at the bottom of the hierarchy by definition — it is what remains once elimination, substitution and engineering have done their work. NIOSH publishes the same hierarchy, and a control set weighted toward administrative measures and personal protective equipment is itself an audit finding. MSI’s ISO 45001 operational control procedure template covers the boundary.
- Clause 8.1.4 — procurement, contractors and outsourcing. The contractor coordination duty in a multi-employer workplace runs straight through the emergency plan and into purchasing and supplier control.
The forthcoming ISO 45001 revision is expected to strengthen how organizations anticipate climate-driven disruption — severe weather, extreme heat and wildfire smoke as worker-safety events rather than only environmental ones. MSI’s coverage of the ISO 45001 revision sets out what is expected to change and what is not. An emergency preparedness and response procedure rebuilt now should anticipate that direction rather than be rebuilt again in two years.
Environment and safety together
The combined ISO 14001 and ISO 45001 emergency preparedness and response procedure
Merge. Preserve. Own.
Most organizations running both standards hold two emergency documents: an environmental one owned by the EHS or environmental lead, and a safety one owned by the safety lead or the site manager. Both are competent. Both pass audit. And between them sits a failure mode that cannot exist in an organization holding a single combined emergency preparedness and response procedure, because it is created by the boundary itself.
Worked example: the successful response that created the incident
A cardboard compactor fire on an afternoon shift. The response was fast and correct. The area was cleared, the fire team deployed, the fire was out in under ten minutes, nobody was hurt, and the debrief recorded a clean response well within the team’s training. By every measure the safety plan defines, this was a success.
Approximately nine hundred liters of firewater ran across the yard, entered the yard drain, and reached the watercourse. The firewater carried the contents of what had been burning. The regulator’s interest was not in the fire.
One document or two? Two separate procedures are conformant, and for many organizations they are the right answer. But a combined emergency preparedness and response procedure is the only structure that forces somebody to own the interaction cases — where the safety response creates the environmental release, or where environmental containment blocks the evacuation route. Those cases fall between two correct procedures and belong to neither. If you hold two documents, the minimum fix is a named interaction section in both, reviewed together in one sitting rather than separately.
The interaction cases are not exotic. Foam and firewater runoff is the common one. Bunding a spill in a bay that is also an evacuation route is another. Shutting ventilation to contain a vapor release while people are still inside is a third. Isolating power to stop a leak and disabling the fire alarm panel in the process is a fourth. Each has a correct answer, and each answer requires a decision made in advance by somebody holding both scopes at once.
What a combined document has to preserve
The risk in merging is sanding off each standard’s specific obligation to reach a lowest common denominator. A defensible combined emergency preparedness and response procedure preserves all of it:
- Testing at the stricter of the two. ISO 45001’s unqualified “test and exercise” becomes the operating requirement. Applying ISO 14001’s practicability qualifier to the whole document is the classic merge failure.
- Documented information at the stricter of the two. Plans maintained and retained, not merely the process available.
- Proportionality preserved from ISO 14001. The one obligation running the other way. It must survive the merge intact or the environmental audit finds it missing.
- Both communication lists, unioned not averaged. ISO 45001’s enumerated categories plus ISO 14001’s relevant interested parties.
- Involvement in development, from ISO 45001 g). A participation record, not a circulation list.
- Two registers, one determination. The emergency situation list is derived once, from a determination that satisfies both hazard identification and aspect identification, and then recorded against both scopes. MSI applies the same principle in the combined job hazard and aspect identification procedure.
Where the two standards genuinely disagree, the decision has to be made once, recorded, and defensible — not left implicit for an auditor to discover. That integration decision record is what separates a combined emergency preparedness and response procedure from a merged one.
The requirement almost nobody implements
ISO 45001 Clause 8.2 g) and the emergency preparedness and response procedure that never got participatory
Involve. Record. Prove.
ISO 45001 Clause 8.2 g) requires the needs and capabilities of relevant interested parties to be taken into account, and their involvement ensured in the development of the planned response. Read it slowly. It is not a duty to inform — that duty already exists at e) and f). It is not satisfied by circulating a draft for comment, because circulating a draft is consultation on a finished thing rather than involvement in making it.
Why it goes missing, structurally
Emergency plans are treated as a document deliverable rather than as a participation activity. So the plan routes through document control: drafted, reviewed, approved, issued, filed. That route is correct for a document and wrong for this obligation, because the obligation lives in Clause 5.4 — consultation and participation of workers — which names Clause 8.2 explicitly among the matters requiring worker participation.
The fix is not a new form. It is a routing change: the emergency preparedness and response procedure enters through the participation process and exits through document control, rather than existing only in the second. Practically, that is one workshop with the people who would run the response, minuted, with the changes traceable to who raised them. It takes an afternoon and it closes an obligation most organizations have carried open for years.
This is a recurring theme in MSI’s work. The same structural logic explains why corrective action closure rates look healthy while causes go unremoved, and why management review inputs vanish. When an obligation belongs to a process it was never routed through, the responsible person never sees it and the internal audit never samples for it.
Healthcare
The ISO 7101:2023 emergency preparedness and response procedure for healthcare organizations
Continue. Protect. Deliver.
ISO 7101:2023 is the first international consensus standard for healthcare quality management, and it handles emergencies differently from either the environmental or the safety standard. Its Clause 8.2.2 is titled contingency planning for facilities and services, and the shift in vocabulary is the point. An industrial emergency preparedness and response procedure asks how you stop the event. A healthcare one asks how care continues while the event is happening.
Why the healthcare version is structurally harder
A manufacturing site can stop. Production halts, the area clears, the response runs, and nothing irreversible happens because the line was idle. A hospital cannot stop. The patients in the building during the emergency are the same patients who were being treated before it, and their treatment does not pause because the power did. This is why ISO 7101 frames the requirement as contingency planning rather than emergency response: the obligation is continuity of care under degraded conditions.
That reframing changes what belongs in the emergency preparedness and response procedure. Alongside evacuation and fire, a healthcare document has to address surge, staffing shortfall, supply interruption, medical gas and utility failure, loss of the electronic record, and the dependency relationships between wards and services. The World Health Organization’s emergency response framework works from the same premise at the health-system level.
The requirement that lives in no procedure: Clause 7.5.4 f)
ISO 7101 Clause 7.5.4 f) requires the information management system to have contingency plans so that services are not disrupted. It is a named shall. In most organizations it is homeless, and the reason is a clean example of the structural argument running through this article:
- It is not in the emergency plan, because the emergency plan is about the building — fire, flood, evacuation, muster, structural failure.
- It is not in the IT policy, because the IT policy is about backups, recovery time objectives and restoration priority — how the system comes back, not how care is delivered while it is down.
- So it is nowhere. The question “how does a nurse give the right medication to the right patient with no record system” has an owner in neither document, and the answer is usually improvised at three in the morning by whoever is on.
An ISO 7101 emergency preparedness and response procedure that addresses this holds the downtime dependency list as a physical artifact with a stated refresh frequency, an owner, and a location known to the night team — not as a report the system generates on request. MSI’s guide to implementing ISO 7101 covers the wider framework, and the ISO 7101 overview course walks the standard end to end for organizations new to it. Healthcare clients typically reach MSI’s ISO consulting practice at exactly this point — when the clause list is clear and the ownership question is not.
Tiering the response
Why quantity is the wrong trigger in an emergency preparedness and response procedure
Receptor. Route. Reality.
Almost every emergency preparedness and response procedure MSI reviews tiers its response by quantity. Minor spill under twenty liters, handle locally. Moderate spill, call the coordinator. Major spill, notify. It is tidy, it audits well against ISO 14001 Clause 8.2 c) at a glance, and it is wrong.
Worked example: the small event whose exposure had nothing to do with its size
Four liters of spent solvent seeping from a drum onto a yard surface during a shutdown weekend. On quantity alone, a housekeeping matter. Under the site’s tiering, it did not reach the threshold that would have summoned anyone.
- The yard drained to a storm drain discharging to a permitted watercourse. Not a sealed bay, not the process sewer.
- The substance was a listed hazardous waste, which changes the regulatory consequence of the same four liters entirely.
- The vapor accumulated in a partly enclosed bay, which made it a health exposure to the forklift driver — a fact nobody considered, because the situation had been classed environmental-only the moment it was reported.
- The drain cover was locked in a bay whose only keyholder was off site for the weekend.
Tier by criteria, not by value. An emergency preparedness and response procedure that tiers on quantity alone will under-respond to small releases reaching sensitive receptors and over-respond to large ones that are fully contained. Tier on the receiving environment, the substance classification, the presence of a person, and the availability of the control — then let quantity modify the tier rather than set it. Exposure is proportional to the receptor and the person standing next to it, never to the volume.
Criteria-based tiering is also what ISO 14001 Clause 8.2 c) actually asks for. Proportionate to the magnitude of the emergency and the potential environmental impact — two variables, and the second is about where it goes, not how much there is. A tiering table with one column has already lost half the requirement. This is the same receptor logic that governs significance determination in the 2026 aspects register, which is why the two documents should be built from a single determination rather than separately.
The keyholder detail is worth sitting with, because it is the most transferable finding in the example. The control existed. It was correct, it was documented, and it was inaccessible for the seventy-two hours that mattered. An emergency preparedness and response procedure that lists controls without verifying access under the conditions the emergency creates — night, weekend, shutdown, one person on site — has documented an intention rather than a capability. Test the access, not just the plan.
The regulatory layer
US requirements your emergency preparedness and response procedure has to carry alongside the standard
Cite. Submit. Resend.
Neither ISO 14001 nor ISO 45001 tells you what your legal requirements are; both require you to determine them. In the United States, an emergency preparedness and response procedure at most industrial sites is carrying obligations from at least three regulatory families at once, and the interfaces between them are where the findings live.
Environmental: RCRA, SPCC and EPCRA
- 40 CFR 262 Subpart M — large quantity generator preparedness. Contingency plan content at § 262.261, an emergency coordinator on the premises or on call at all times at § 262.264, arrangements attempted with local authorities, equipment and testing provisions, and aisle space. The “at all times” wording is what the locked-drain-cover example above ran into.
- 40 CFR 262.262 — the submission duty, and the single most under-implemented item on this page. The plan must be sent to local police and fire departments, hospitals, and State and local emergency response teams. A quick reference guide is required for generators first subject after May 30, 2017 or amending the plan — and it must be updated whenever the plan is amended. Organizations revise the emergency preparedness and response procedure properly, approve it properly, file it properly, and never re-send it. The amendment triggers themselves sit at § 262.263.
- 40 CFR 112.7 — SPCC. A written plan, a designated person accountable for discharge prevention reporting to management, annual discharge prevention briefings for oil-handling personnel, and written inspection procedures with three-year record retention. EPA’s oil spill prevention program sets out the applicability thresholds.
- EPCRA Section 304 and 40 CFR 355 — release notification. Immediate notification to the State Emergency Response Commission and Local Emergency Planning Committee, plus the National Response Center where a CERCLA substance is involved, followed by a written report. The notification decision has to be executable by whoever is on shift, which means the emergency preparedness and response procedure carries the numbers and the thresholds, not a pointer to a binder.
- One plan, not five. EPA permits a single integrated document at § 262.261(b), and the National Response Team Integrated Contingency Plan guidance sets out the one-plan format. Sites maintaining separate RCRA, SPCC and EPCRA documents are doing optional work and creating three chances to update two.
Safety: the OSHA layer
- 29 CFR 1910.38 — emergency action plans. Six minimum elements. Employers with ten or fewer employees may communicate the plan orally rather than in writing. Designated and trained evacuation assistants are required, and the plan must be reviewed with each employee at three defined points — on assignment, when responsibilities change, and when the plan changes.
- 29 CFR 1910.39 — fire prevention plans. A distinct document from the emergency action plan, and routinely conflated with it. One is about preventing the fire; the other is about what happens once there is one.
- 29 CFR 1910.165 — employee alarm systems. A distinctive signal for each purpose. A site using one tone for fire, evacuation, shelter in place and end-of-shift has a finding waiting.
- 29 CFR 1910.120(q) — HAZWOPER emergency response. This is where the two scopes collide most sharply: the trigger is a hazardous substance release, which reads as an environmental event, and the obligations are responder competence duties, which read as safety. Sites running two separate procedures typically have it in neither, because each owner reasonably assumed it belonged to the other.
- 29 CFR 1910.151 — medical services and first aid, including quick-drenching or flushing facilities where corrosive materials are present.
Evidence
What testing an emergency preparedness and response procedure actually has to produce
Schedule. Stress. Record.
Testing is the obligation that fails most often, so it is worth being concrete about what closes it. Three artifacts, and most organizations have the first only.
- A schedule with dates in the future. Not a policy statement that testing occurs annually. Named dates, named scenarios, named owner, on a calendar somebody with production authority has agreed to.
- A record of what was tested and under what constraint. The value of a test is in the constraint. Primary route blocked. Coordinator unavailable. Night shift staffing. A test run in daylight with everyone present and the best route open confirms nothing you did not already believe.
- A revision decision. Either the procedure changed, or there is a recorded conclusion that it did not need to. ISO 14001 Clause 8.2 e) and ISO 45001 Clause 8.2 d) both require review and revision after testing; a test with no downstream decision has produced no evidence that the review happened.
How often? Neither ISO 14001 nor ISO 45001 states an interval — both say periodically, which means you set the frequency and defend it. A defensible testing frequency for an emergency preparedness and response procedure is derived from the severity of the credible scenarios, the rate of change in the operation, and the turnover of the people who would respond. Annually per scenario family is the floor MSI sees registrars accept, with high-consequence scenarios more often and any scenario retested after a material change or an actual event.
One more evidence point that catches people. The obligation to review and revise is triggered by an actual event as well as by a test — and an actual event includes the near miss that did not become anything. Organizations record the event in the incident system and never route it to the emergency preparedness and response procedure owner, so the plan never learns from the one rehearsal reality provided free of charge.
Building it
A five-step sequence for writing an emergency preparedness and response procedure that survives audit
Derive. Decide. Deploy.
- Derive the emergency list from the determination you already have. Not a fresh brainstorm. Pull it from hazard identification and aspect determination so the three lists cannot disagree. Include shutdown, start-up, maintenance and abnormal conditions — the 2026 edition of ISO 14001 removed the word that had been letting people scope this to running operations only.
- Set criteria-based tiers before writing any response. Receptor, substance classification, presence of a person, availability of control. Quantity modifies; it does not decide. This is where ISO 14001 Clause 8.2 c) is satisfied or lost.
- Write the interaction cases explicitly. Firewater runoff. Containment across an evacuation route. Ventilation shutdown with people inside. Isolation that disables detection. If you hold two procedures, this section goes in both and is reviewed in one sitting.
- Route the draft through participation, not document control. One workshop with the people who would run it, minuted, changes traceable to who raised them. That record is what closes ISO 45001 Clause 8.2 g), and it is the artifact that does not exist in most organizations.
- Commit the two scheduled obligations before you publish the document. Testing dates on the production calendar with an owner who can hold them, and the external communication list with a first contact date against each named category. If those two are not committed at the moment the emergency preparedness and response procedure is approved, they will not be committed later.
That sequence is deliberately front-loaded. Four of the five steps happen before the document takes its final shape, because every failure mode in this article originates in a decision made before the writing started — or not made at all. MSI applies the same front-loading discipline to risk management procedure design and to production, service and operational control maturity. Twenty-eight years of ISO consulting has produced one consistent lesson here: the documents organizations struggle to defend are the ones whose hard decisions were deferred until after the drafting began.
Next steps
Where to take your emergency preparedness and response procedure from here
Score. Build. Sustain.
Four paths, depending on where you are. Each one leads somewhere specific.
Running more than one standard? The ISO 7101:2023 procedure library and the ISO 14001:2026 transition bundle both include the emergency document alongside the procedures that feed it, which is the version that stays consistent. Industry-specific context is covered in MSI’s work on ISO for energy companies and ISO for logistics and supply chain, where emergency preparedness carries unusually high weight.
Questions people actually ask
Emergency preparedness and response procedure FAQ
Ask. Answer. Apply.
Is an emergency preparedness and response procedure mandatory under ISO 9001?
Can one emergency preparedness and response procedure cover ISO 14001 and ISO 45001 together?
What changed for emergency preparedness in ISO 14001:2026?
How often does an emergency preparedness and response procedure have to be tested?
Who must be informed under an emergency preparedness and response procedure?
Does an emergency preparedness and response procedure cover business continuity?
Does an ISO emergency preparedness and response procedure satisfy OSHA 29 CFR 1910.38?
What is the fastest way to fix a weak emergency preparedness and response procedure?
References and primary sources
- ISO 14001, Environmental management systems — ISO
- ISO 45001, Occupational health and safety management systems — ISO
- ISO 7101:2023, Healthcare organization management — ISO
- ISO 9001, Quality management systems — ISO
- ISO 19011, Guidelines for auditing management systems — ISO
- 40 CFR 262 Subpart M, Preparedness, prevention and emergency procedures — eCFR
- 40 CFR 262.261, Content of contingency plan — eCFR
- 40 CFR 262.262, Copies of contingency plan and quick reference guide — eCFR
- 40 CFR 262.263, Amendment of contingency plan — eCFR
- 40 CFR 262.264, Emergency coordinator — eCFR
- 40 CFR 112.7, General requirements for SPCC plans — eCFR
- 40 CFR 355, Emergency planning and notification — eCFR
- 29 CFR 1910.38, Emergency action plans — OSHA
- 29 CFR 1910.39, Fire prevention plans — OSHA
- 29 CFR 1910.120, Hazardous waste operations and emergency response — OSHA
- 29 CFR 1910.151, Medical services and first aid — OSHA
- 29 CFR 1910.165, Employee alarm systems — OSHA
- Oil spills prevention and preparedness regulations — US EPA
- Summary of the Emergency Planning and Community Right-to-Know Act — US EPA
- Integrated Contingency Plan guidance — US EPA / National Response Team
- National Response Center — US EPA
- Hierarchy of controls — NIOSH
- National Risk Index, natural hazard exposure — FEMA
- Emergency response framework — World Health Organization
- Global Accreditation Cooperation, successor to IAF and ILAC
- ANAB, US accreditation body for management system certification
Clause content is summarized from MSI’s licensed copies of ISO 14001:2026, ISO 45001:2018 and ISO 7101:2023. This article is educational and is not certification, legal or regulatory advice; your compliance obligations are yours to determine.
About Management Systems International (MSI)
Diana Lynn is President and Principal ISO Consultant at Management Systems International (MSI), a consulting firm she co-founded in 1998. With 28 years of experience, MSI’s track record includes 80+ certifications supported, 200+ audits attended, and 600+ professionals trained across manufacturing, technology, medical device, government, healthcare, and other regulated industries. Today MSI implements ISO 9001, ISO 13485, ISO 14001, and ISO 45001, with an expanding focus on ISO 7101 healthcare quality. MSI is veteran-owned and female-owned.
msi-international.com · 760-434-9141