ComplyChat Start free

Guide · Schools

School business continuity plan

A school business continuity plan sets out how a school will keep children safe, keep teaching and get back to normal after a disruption such as a fire, flood, cyber attack, power loss or staff shortage; the Department for Education says every school should have emergency plans, expects business continuity and disaster recovery plans that include digital technology and are reviewed at least annually, and the Academy trust handbook 2026 makes contingency and business continuity planning a requirement for academy trusts.

By ComplyChatPublished 12 minute read

During an early-morning power cut, a headteacher and the office manager work by battery lanterns at a dark primary school reception counter as the first staff arrive in coats behind them

A business continuity plan (BCP) has no form prescribed by statute, which is why so many school plans are templates nobody has opened since they were adopted. This guide sets out what the DfE expects a plan to contain, how to test it, and the records a school should be able to show afterwards.

01

Where the duty comes from

The Department for Education’s guidance Emergency planning and response for education, childcare and children’s social care settings (last updated 10 May 2023) is the starting point: “All education, childcare and children’s social care settings should have emergency plans in place. Your plan should explain how you would respond if you needed to take any temporary actions in the event of an emergency.” It adds that the guidance “does not cover every aspect” and that settings “must comply with your legal responsibilities, including under health and safety law”.

Business continuity is the part of that planning concerned with keeping going and recovering. The DfE’s school and college security guidance says that the competent person a school should have to lead on health and safety and security “will also need to ensure that business continuity plans are in place”, and that a business continuity plan “should define individual roles and responsibilities, explain how to respond to an incident and provide details of what steps will be taken in order to be able to get back to business as usual”.

Three further sources make it specific. The DfE’s digital leadership and governance standard says business continuity and disaster recovery plans should include digital technology and “need to be reviewed and updated annually or when a significant change occurs”. For academies, the Academy trust handbook 2026, in effect from 1 October 2026, says at paragraph 2.44: “The trust’s management of risks must include contingency and business continuity planning.” And the DfE’s data protection responsibilities page asks governors and trustees to check that the school “has a business continuity plan in place that includes cyber security”.

02

What the plan has to cover

The DfE says emergency plans “should be generic enough to cover a range of potential incidents” that “could happen during, and outside, normal working hours including weekends and holidays”, and lists them:

  • public health incidents, such as a significant infectious disease incident
  • severe weather – extreme heat, flooding, storms or snow
  • serious injury to a child or member of staff, for example a transport accident
  • fire risk and other hazards, and significant damage to the building
  • criminal activity, for example a bomb threat
  • loss of power or telecommunications, and disruption to normal services
  • a cyber incident or data breach
  • the impact and lasting effects of a disaster in the local community

The plan should also reach breakfast and after-school clubs, holiday activities, trips and outings, open days and live performances with an audience, and, where a school has wider facilities such as lettings or a leisure centre, “the whole of your estate”. Rather than a separate plan for every scenario, many schools write one plan around the effects that recur – loss of access to the school premises, loss of staff, loss of technology, loss of a supplier – and short action cards for the incidents that need an immediate procedure, such as evacuation, lockdown or a bomb threat.

03

What a school business continuity plan should contain

The DfE says “a good plan should cover” roles and responsibilities; “when and how to get advice”; the steps you might take and how to enact them quickly; “a list of key contacts”; how every pupil will still receive the education and care they are entitled to, “including through remote education where appropriate”; “how you would communicate any changes to children, pupils, students, parents, carers and staff”; and “how you would respond if your advice were not accepted”. Its business continuity plan template and checklist, published with the security guidance, turns that into sections a school can complete:

  1. Communications. Whether contact details for staff, governors, parents, the local authority, utilities, suppliers and insurers can be reached remotely, and whether the school can still update its website, email and text parents if the site is closed.
  2. Staffing. Deputies for every management and incident role, cross-skilling, and alternatives such as combined classes, remote learning or staff from other schools.
  3. Premises. Partial and total closure, temporary facilities, and alternative premises, which the template says “must be pre-arranged”.
  4. Technology. Off-site backups, paper contingencies “for record keeping, such as registers, accident forms etc”, offline devices, a data recovery plan and call forwarding.
  5. Suppliers and insurers. Current and alternative contractors and the insurance or risk protection arrangement contacts.
  6. Actions checklist. Invoke the emergency procedure, assess which activities are disrupted and which critical activities are approaching, such as exams, then plan communications, resources, finance and reporting.

Several duties continue through any disruption and belong in the plan. The DfE says safeguarding “remains of paramount importance”, that schools must still have “a trained designated safeguarding lead (DSL) (or deputy) available on site” or, failing that, available by phone or video, and that vulnerable children, the children of critical workers and pupils due to take exams have priority if places must be limited. Pupils eligible for benefits-related free school meals should still be fed, and attendance must still be recorded with the appropriate code; the 2023 guidance cites the 2006 registration regulations, so check codes against the current School Attendance (Pupil Registration) (England) Regulations 2024 and attendance guidance.

Cyber attack deserves its own annex. The DfE’s cyber security standard asks schools to “put a cyber response plan in place”, which “as well as this being a part of your business continuity plan, it is also a condition of cover if you have risk protection arrangement (RPA) cover”; to keep “at least 3 backup copies of important data, on at least 2 separate devices – at least one of these copies must be off-site”; to make backups immutable; and to test the backup plan termly. Academy trusts “must not pay any ransom or extortion demands, including cyber ransomware” (Academy trust handbook 2026, paragraph 6.15). A cyber incident is often also a personal data breach with its own 72-hour clock.

04

Testing, review and the records to keep

A plan that has not been tested is an assumption. The DfE’s digital standard says the disaster recovery plan “should be tested annually (at a minimum)”, for example by simulating data loss or hardware failure, and the cyber standard says cyber risks belong in the risk register and in “a regularly tested business continuity plan”. The security guidance says “you should regularly test policies and handling plans”, suggests involving neighbouring schools, the police, the local authority or the trust in evaluating drills, and the emergency planning guidance lists “exercises and tests (for example, fire drills)” as part of the planning process. A tabletop exercise – a leadership team talking through a scenario against the plan for an hour – tests the decisions; a fire drill tests the procedure for pupils and staff; a restore from backup tests the technology.

Keep a short record of each test: the date, the scenario, who took part, what worked, what failed and the actions agreed, with an owner and a deadline. The DfE asks schools to consult “members of staff, management boards and governors” when developing the plan and to do “a lessons learnt exercise” after a real incident. The plan itself should be kept where it can be reached when the building and the network cannot: the digital standard says plans and their summary documents should be “printed out to retain hard copies in case of an emergency, such as a cyber incident” and “kept online in a secure, shared folder location in the cloud”.

During an incident, the most important record is the decision log. The DfE template’s actions checklist says: “Log all decisions and actions, including what you decide not to do and include your decision making rationale”, “Log all financial expenditure incurred”, then complete a lessons learnt log and a post-incident review. Those logs are what the governing board, the insurer or the risk protection arrangement, the local authority and, sometimes, an inquiry will ask for. Afterwards, update the plan and the risk register together, and report the incident and the review to the board; in a trust the board must review the risk register in full at least annually.

A secondary school leadership team runs a tabletop exercise around a table in a community centre meeting room, printed scenario cards and a site plan spread out, one deputy standing to point at the plan
05

Who owns the plan, and who acts on it

The headteacher usually owns the plan and leads the response, with the school business manager often writing and maintaining it and the site manager, IT lead and designated safeguarding lead each owning a part. The DfE’s digital standards give the senior leadership team’s digital lead the backup plan and the technology elements. In a trust or a local authority school, the plan should say what the trust or the local authority does centrally, who in the school contacts them, and when.

Governors and trustees oversee rather than operate it. They should see the plan when it is adopted, receive a summary of each test and each incident, and check that the actions agreed afterwards were completed. The DfE’s security guidance also expects the plan to explain “what will be done to handle the emotional impact” of a serious event and the specialist help available, because recovery after a traumatic incident is as much about people as premises.

Communication roles need names, not job titles alone. The security guidance says plans “should set out who is responsible for communication to parents, family members (where appropriate), any statutory organisations such as police or local authority as well as the use of social media, press/media handling”. Agree in advance who may decide to close the school, who tells staff, who tells parents and through which channel, and who speaks to the press – and what happens when any of them is the person who is unavailable.

06

The channel the plan forgot

Many incidents in a school begin outside the school day, and the first hours are run from phones. The site manager messages the headteacher a photograph of water coming through the hall ceiling. The headteacher asks the senior leaders’ group chat whether anyone can get in early, and the decision to close is agreed there, in a dozen messages, before anyone opens the plan. Staff are told through a staff group on a consumer app that includes a teacher who left at Easter. On the day of a cyber attack, when the school’s email and management information system are down, everyone moves to personal apps by default, because that is the only thing left working.

Those messages are the decision log the DfE template asks for – including “what you decide not to do” and why – and they are where the school’s record of the incident will actually be. They sit on personal devices in groups whose membership nobody manages, outside the school’s retention schedule, and they are hard to produce for the board, the insurer or the risk protection arrangement weeks later. A communications plan that lists the website, email and text messages but not the channel staff actually used has a gap exactly where the decisions were made.

The fix is planning, not prohibition: decide before the incident which channel leaders and staff will use when the normal systems are down, who controls its membership, how it is reached from a personal phone, and how its messages become part of the incident log. The question for the next leadership or governing board meeting is this: if the school closed at six tomorrow morning, where would the decision to close be recorded, and could the board read it afterwards?

07

Questions people ask

Do schools have to have a business continuity plan?

Academy trusts must: paragraph 2.44 of the Academy trust handbook 2026 says the trust’s management of risks “must include contingency and business continuity planning”. For maintained schools there is no single statutory requirement, but the Department for Education says all schools should have emergency plans, expects business continuity and disaster recovery plans that include digital technology, and asks governors to check the school has a business continuity plan that includes cyber security.

What should a school business continuity plan include?

A school business continuity plan should include roles and responsibilities, key contacts, the steps to take in an emergency, how pupils will continue to receive education and care, how changes will be communicated to pupils, parents and staff, and how the school will recover, according to the Department for Education. Its template adds communications, staffing, premises, technology and supplier sections, and a log of decisions and spending during an incident.

How often should a school test its business continuity plan?

At least once a year: the Department for Education’s digital leadership and governance standard says business continuity and disaster recovery plans should be reviewed and updated annually or when a significant change occurs, and the disaster recovery plan tested annually at a minimum. Its cyber security standard says backups should be tested termly, and its security guidance asks schools to test plans regularly through practice drills.

What is the difference between an emergency plan and a business continuity plan?

An emergency plan covers the immediate emergency response to an incident – evacuation, lockdown, calling the emergency services, keeping people safe – while a business continuity plan covers how the school keeps its essential activities going and gets back to business as usual afterwards. The Department for Education’s security guidance treats both as part of a school’s security policy and plan, and many schools combine them in one document.

08

Official guidance and your next step

The DfE’s emergency planning and response guidance and its school and college security publication, with its templates for business continuity, evacuation, lockdown, post-incident support and lessons learned, are the core sources. For technology read the digital leadership and governance and cyber security standards; academy trusts should read section 2 of the Academy trust handbook 2026. Your local authority or trust may also have its own template and local resilience arrangements, and the DfE suggests building links with nearby schools, the police, the local authority and the local resilience forum before they are needed.

This guide summarises published guidance for schools in England and is not legal advice; insurers and the risk protection arrangement set their own conditions, so check yours.

Then do one thing: put a one-hour tabletop exercise in the diary this term – the school’s systems are down at 7am on an exam day – and record what the plan answered and what it did not.

Why we publish this

We build ComplyChat for the work conversations schools need to keep, and an incident is when the most consequential ones happen. ComplyChat is not an emergency alerting system or a parent text service, and like any online service it is not a substitute for the paper copy of the plan. It gives staff a channel the school runs and can reach from a compatible phone, including a personal one, where everyone added is told the conversation is on the record and messages are recorded on the server as they are sent, so the decisions taken during an incident stay with the school; on paid plans, once the school’s Microsoft 365 tenant is connected, the lasting record files there under the school’s own retention rules.

Explore Free · How it works · Compare plans

Sources

Every document this guide quotes or links to, in the order it first cites them.

  1. Emergency planning and response for education, childcare and children’s social care settings gov.uk
  2. School and college security guidance gov.uk
  3. Digital leadership and governance standard gov.uk
  4. Academy trust handbook 2026 gov.uk
  5. Data protection responsibilities gov.uk
  6. Business continuity plan template and checklist assets.publishing.service.gov.uk
  7. Cyber security standard gov.uk
  8. School and college security gov.uk