(1) The Critical Incident Management Policy provides the guidance for ACU to plan for, respond to and manage Events, Incidents and Critical Incidents from a personnel, hazard identification, and risk management perspective. (2) It ensures the University meets its legislative and duty of care obligations in providing the highest possible standard of health and safety to its staff, students, contractors, volunteers and visitors. (3) The terms “Event, Incident and Critical Incident” are used to define categories and levels of issues or disruptions and their associated response and management. For the purposes of this Policy, the term Critical Incident Management refers to all three levels (Event, Incident and Critical Incident) unless otherwise specified. (4) The Critical Incident Management Policy and Critical Incident Management Procedure informs part of ACU’s Business Resilience Program. (5) This Policy applies to staff, students, contractors, volunteers and visitors while they are participating in University-related activities, both on and off campus, within Australia or overseas. (6) Nothing in this Policy overrides the Code of Conduct for Staff or the Student Conduct Policy. (7) This Policy applies to ACU and is subject to all applicable laws, regulations and codes. (8) This Policy and the Critical Incident Management Procedure demonstrate ACU’s commitment to: (9) The Vice-Chancellor and President is the Approval Authority for this Policy. (10) The Chief Operating Officer and Deputy Vice-Chancellor, as Governing Authority, will raise awareness of this Policy and Critical Incident Management Procedure to ensure that all staff, students, contractors, volunteers and visitors comply with their requirements. (11) The Deputy Chief Operating Officer, as Responsible Officer, is responsible for the establishment, operation and review of the Critical Incident Management Policy and Procedure. (12) The Director, Student Experience, Director, Student Administration and the Chief People Officer will ensure students and staff receive information about this Policy and Procedure as part of their induction or orientation to the University. All staff who support the University’s business continuity and recovery processes are required to familiarise themselves with the Critical Incident Management Policy and Procedure. (13) The following criteria apply to the categorisation of Events, Incidents and Critical Incidents. (14) Due to the broad definition of what comprises a Critical Incident, ACU is committed to applying the International Coding of Incidents to increase its response preparedness and effectiveness. (15) Incidents are allocated to one of the Incident Convenors based on five categories - Students, Staff, Physical, Virtual, and Reputation. (16) The Critical Incident Convener and each Incident Convener must nominate one proxy to act as Convener on their behalf. (17) A new Incident Response Group is formed by the Incident Convener for the management of each Incident. Incident Conveners can select and approve any ACU staff for inclusion in an Incident Response Group. Staff are selected based on the Incident type, colour code and campus, to provide expertise and resources to support the Incident Convener during the management of an Incident. (18) For the purposes of oversight and communication, the Critical Incident Convener and the five Incident Conveners are members of each Incident Response Group. (19) Representatives from AskACU, Service Central and Facilities Management must be kept informed of decisions so that they can prepare for queries and provide a response that is consistent with the organisational message coordinated by the Incident Convenor (Reputation). (20) The Critical Incident Management Procedure accompanying this Policy provides further guidance on organisational staff positions that may inform an Incident Response Group. (21) The Chief Operating Officer and Deputy Vice-Chancellor is the Critical Incident Convenor and can declare a Critical Incident at their discretion and activate the Critical Incident Response Group (CIRG) if required. (22) The Critical Incident Response Group includes the Incident Conveners and other officers of the University who can provide their expertise, resources and support to the Critical Incident Convener while managing a Critical Incident. (23) Events (Level 1) are managed by local responsible frontline staff and supervisors including, but not limited to, staff from the National Security Centre, campus facilities, fire wardens, first aid officers, Student Administration, Campus Ministry, Service Central, AskACU and Student Experience. (24) The Event is either resolved or escalated to an Incident and the National Security Centre is notified. (25) Incidents (Level 2) are managed by one of the five Incident Convenors (Students, Staff, Physical, Virtual, Reputation). (26) The National Security Centre notifies the five Incident Convenors and the Critical Incident Convenor. The Incident is allocated to one of the five Incident Convenors who also determines the Incident Colour Code, campus location and Incident Response Group members. (27) The Incident is either resolved or escalated to a Critical Incident. (28) The Critical Incident Management Procedure that accompany this Policy provide further details on the incident management process and flowchart. (29) Critical Incidents (Level 3) are managed by the Critical Incident Convener in conjunction with the Incident Conveners and the Critical Incident Response Group. (30) The Critical Incident Convener and Critical Incident Response Group provide regular updates on the management of, and response to, the Critical Incident to the Vice-Chancellor and President and members of the Vice-Chancellor's Advisory Committee, ACU staff and students, the Chancellor, members of Senate and external regulatory bodies, as required. (31) ACU’s Business Continuity and Business Impact Assessment information is utilised in the management of a Critical Incident. (32) Refer also the Event, Incident and Critical Incident Response Flowchart for a visual representation of the incident management workflow. (33) Incident Convenors should communicate regularly with their Incident Response Group and hold work-in-progress or briefing meetings during the management of an incident. During these meetings, communications to external or other stakeholders should be discussed and managed. (34) All communication to staff, students, contractors, volunteers or visitors concerning an Incident or a Critical Incident will be coordinated by the Incident Convenor (Reputation), who is the Chief Marketing Officer, in consultation with the Critical Incident Convenor. AskACU, Service Central and Facilities Management are informed so that they can prepare for queries and provide a response to staff and students that is consistent with the organisational message coordinated by the Incident Convenor (Reputation). (35) Such communication should be sent first and foremost by the Critical Incident Convener, however, staff designated as ‘Convenor’ or ‘Critical Incident Convenor’, their designated proxies and Executive Officers, and those additionally listed below, are authorised within the ACU Distribution List Policy to send to all Dynamic Distribution Lists for the purposes of communication information regarding a major university disruption. (36) In the event of an Incident or Critical Incident, ACU campuses remain open and staff are to stay at work until advice is received only from the Critical Incident Convenor. (37) The decision to close a campus is made when it is requested by State or Federal Government authorities, or decided by the Critical Incident Convenor to be necessary in the best interests of the campus students and staff. (38) Incident Conveners should consult the Privacy Officer to ensure that any disclosure of personal information associated with an Incident or Critical Incident is managed in accordance with the Privacy Policy, Privacy Inquiry and Complaints Procedure and Third Party Access to Personal Information Protocol. (39) A Post-Incident Report should be delivered to Incident Conveners and the Critical Incident Convener within one week of the close of an Incident and a debrief meeting held within one week of the Post-Incident Report being received. (40) A Post-Incident Report template is available in the Critical Incident Management Procedure that accompanies this Policy. The Report should be completed by the Convener who managed the Incident (or a designated member of their Response Team) and should: (41) Business continuity is the management of the priorities, recovery procedures, responsibilities and resources that support the University and each individual business unit in managing recovery from a business disruption. (42) In the event of a major Incident or Critical Incident, the University can implement business continuity and recovery management measures in addition to the Critical Incident processes identified in this Policy and its accompanying Procedure. (43) Business resilience resources include: (44) This Policy and Critical Incident Management Procedure will be regularly reviewed to ensure they: (45) Annual scenario exercises will be conducted to: (46) Unless otherwise indicated, this Policy will still apply beyond the review date. (47) Please contact the Office of the Deputy Chief Operating Officer for any proposed changes or amendments.Critical Incident Management Policy
Section 1 - Purpose
Section 2 - Scope / Application
Top of PageSection 3 - Roles and Responsibilities
Approval Authority
Governing Authority
Responsible Officer
Other Relevant Stakeholders
Section 4 - Categories and Codes
Events, Incidents and Critical Incidents Assessment Categories
Criteria / Description
Managed by
Level 1
Local responsible frontline staff and supervisors
Level 2
Incident Response Group
Level 3
Critical Incident
Critical Incident Convenor
Critical Incident Response GroupIncident and Critical Incident Codes
Top of Page
Internal Incident
IT / Business Systems
Bomb threat
Personal Threat
Sexual assault/ harassment
Building evacuation
Section 5 - Responsible Staff
Incident Convenors
Incident Convenors and Categories
Director, Student Administration
Chief People Officer
Director, Properties and Facilities
Chief Information and Digital Officer
Chief Marketing Officer
Critical Incident Convenor
Chief Operating Officer and Deputy Vice-Chancellor
Incident Response Group
Critical Incident Convener and Response Group
Section 6 - Activation and Management
Critical Incident
Section 7 - Communication
Top of PageSection 8 - Campus and Service Closure
Section 9 - Privacy
Section 10 - Post Incident Report
Top of Page
Section 11 - Business Continuity and Resilience
Top of PageSection 12 - Review
Section 13 - Further Assistance
View Document
This is not a current document. To view the current version, click the link in the document's navigation bar.
An Event is a localised, minor issue that can be managed with local services and does not affect the ongoing viability of the organisation.
It is unlikely to escalate in severity but still requires response and management by local ACU personnel using appropriate processes and procedures.
An Incident is a moderate issue that can interrupt business processes sufficiently to threaten the viability of the organisation or the welfare of an individual or individuals.
It could escalate unless it is responded to by ACU personnel using operating and incident response procedures.
A Critical Incident is any emergency or adverse situation that will or may have the potential to significantly impact the University’s business viability, threaten the lives of employees or others, and jeopardise ACU’s reputation.
It requires a significant response and ongoing management including implementation of incident recovery processes and business continuity and recovery plans.
Colour Code
Type of Incident or Critical Incident
Examples of Threats and Risks
Fire / Smoke
Medical Emergency / Threat