Article Overview
Practical guidance for real-world site decisions.
Plenty of organisations have a thorough risk assessment and a procedure nobody can recall under pressure. Bridging that gap is mostly about making the plan short, concrete and practised.
At a Glance
- If the procedure cannot be summarised on one page, it will not be followed.
- Name roles rather than individuals, so the plan survives absence and turnover.
- A plan that has never been tested is an assumption, not a procedure.
- Keep a short record of what you tested and what changed.
Section 01
The gap between the document and the moment
Risk assessments are written calmly, at a desk, with time to think. They are used, if at all, in the opposite conditions. That mismatch is why thorough documents often produce hesitant responses.
The test is simple. Can someone who read the procedure once, months ago, do the right thing in the first ten seconds. If the honest answer is no, the issue is usually the format rather than the content.
Section 02
What the one-page version should contain
Underneath the full assessment there should be a short operational version, brief enough to be read in a minute and displayed where people work.
- What the signal sounds and looks like
- The first action, stated in one sentence
- Where to go and where not to go
- What not to do, such as opening doors or leaving the room
- How the all-clear is given and by whom
Section 03
Name roles, not people
Plans that depend on named individuals fail predictably, because people are on leave, off site, in meetings, or have left the organisation. A plan that says the duty lead makes the call still works when the post holder changes.
Then check the role is always filled. If there are hours in the week when nobody holds it, that is a genuine gap, and it is far better identified during a review than during an incident.
Section 04
Test it, then change it
A procedure that has never been exercised is a set of assumptions. Testing turns those assumptions into findings, and the findings are what make the next version better.
Keep a short record of what was tested, what did not work and what changed as a result. That record demonstrates a genuine cycle of review, which is exactly what governors, insurers and inspectors look for.
Section 05
Where risk assessments usually go wrong
The most common failure is not an absent assessment but an unusable one. A document that is thorough, well researched and forty pages long will satisfy a review and fail completely at the moment it is needed.
The second most common failure is conditionality. Procedures that branch repeatedly, asking staff to assess the situation and choose between several responses, produce hesitation. People need one default action they can take immediately, with exceptions handled separately.
The third is drift. A procedure written three years ago may name a room that has been repurposed, a role that no longer exists, or a phone number that nobody answers. None of this is visible until it is tested, which is the argument for testing.
Section 06
Translating findings into a shorter document
The full assessment and the operational summary serve different readers and should be written differently. The assessment justifies the decisions; the summary tells someone what to do. Trying to make one document do both produces something that does neither well.
A practical approach is to write the assessment first, then extract from it the smallest set of instructions that would produce the right behaviour. If that extraction is difficult, it is usually a sign the underlying plan has too many branches.
- Full assessment: rationale, scenarios, governance, review history
- One-page summary: signal, first action, where to go, all-clear
- Site annexe: local detail such as secure areas and assembly points
- Role card: for those who can trigger or give the all-clear
Section 07
Making it survive staff turnover
A procedure that depends on institutional memory degrades every time someone leaves. Within a few years, the people who understood why decisions were made have gone, and what remains is a document nobody feels ownership of.
Naming roles rather than individuals is the first defence. The second is including the procedure in induction properly, rather than as a document in a pack. A five-minute conversation on day one is worth more than twenty pages nobody opens.
The third is the review cycle. If the procedure is genuinely revisited after each drill, the knowledge is continually refreshed across whoever currently holds the roles, rather than sitting with one long-serving member of staff.
Section 08
Working with your wider safeguarding and estates plans
A lockdown procedure does not sit on its own. It overlaps with safeguarding policy, critical incident planning, business continuity and site security, and it is worth checking those documents say compatible things.
Contradictions between documents are common and usually accidental. A safeguarding policy that describes one response and an emergency plan that describes another will be resolved, under pressure, by whichever the individual read most recently.
A short cross-check when any of these documents is updated prevents most of it. It is also the kind of joined-up review that governing bodies tend to look for, because it demonstrates the plans are managed together rather than separately.
Section 09
Running a tabletop exercise
Before committing to a full drill, a tabletop exercise is an efficient way to test a procedure. It takes an hour, involves no disruption, and typically finds more problems per minute spent than a physical drill does.
The format is simple. Gather the people who would be involved, describe a scenario, and work through what each of them would actually do, minute by minute. The gaps appear quickly, usually as silences when nobody is sure who acts.
It is particularly good for testing the decision-making layer, which a physical drill tends to skip because the decision has already been made by whoever scheduled it. Asking who would decide, on what information, and how quickly, is where most procedures show their weak points.
- Pick a plausible scenario rather than a dramatic one
- Include site staff and office staff, not only leadership
- Work through it in real time, minute by minute
- Write down every point where someone hesitated
- Finish by agreeing who will change what, and by when
Section 010
Reviewing after a real incident
If you ever use the procedure for real, even for something minor that stands down quickly, the review afterwards is the most valuable one you will ever do. Real use surfaces things no exercise does.
Do it quickly, while detail is fresh, and separate it from any investigation of the incident itself. The question is not whether people did the right thing but whether the procedure made the right thing obvious.
It is also worth capturing what worked. Procedures tend to accumulate changes after problems and never record the parts that functioned well, which makes later reviewers uncertain about what they can safely simplify.
Section 011
Keeping the document short as it ages
Every review adds. Over several cycles, a one-page procedure becomes three pages, then a booklet, and the qualities that made it usable disappear one clarification at a time.
The discipline is to treat length as a constraint rather than an outcome. If a review adds something, ask what can come out, and push detail into the full assessment rather than the operational summary.
A useful test is to hand the current version to someone who has not read it and ask them what they would do. If they hesitate or start scanning, the document has grown past the point where it works, regardless of how accurate it has become.
Section 012
Using a template without inheriting its assumptions
Templates are a reasonable starting point and a poor finishing point. Local authorities, trusts and sector bodies all publish them, and they save real time on structure and wording.
The risk is that a template carries assumptions about the site it was written for. It may assume a single building, a full-time senior leadership presence, no outdoor areas of consequence, or a particular alerting capability you do not have.
Those assumptions are invisible until tested, because the document reads as complete. A procedure adopted from a template and never exercised is one of the more common ways a site ends up confident in a plan that would not work.
The way to use one well is to treat it as a checklist of things to decide rather than a set of decisions already made. Work through each statement and ask whether it is true of your site. Where it is not, change it, and where you are unsure, that is the item to test first.
- Check every named location actually exists and is suitable
- Check every named role exists and is filled during opening hours
- Check the alerting method described matches what you have
- Check outdoor areas and detached buildings are covered
- Test the adapted version rather than assuming it transfers
Frequently Asked
Questions we get asked about this
How long should a lockdown procedure be?
The full document can be as long as your governance requires, but the operational version staff actually use should fit on one page. Length is the enemy of recall when people are under pressure.
How often should we review it?
After every drill or incident, plus at least annually. Reviewing only on a calendar cycle means findings from a drill sit unused for months.
Should the procedure be public?
The existence of a procedure can be public, but the operational detail generally should not be. Most organisations share the principles with parents or stakeholders and keep specifics internal.
Who should sign it off?
Typically senior leadership with governor or board oversight. The important thing is that whoever approves it has read the one-page version and believes staff could follow it.
Do we need a separate procedure for each building?
The response should be consistent, but site-specific detail such as where to go and which areas are secure will differ. Keep one procedure with site annexes rather than entirely separate documents.
Need help applying this to your site?
We can turn the principles in this article into a practical recommendation based on your building, procedures, and response priorities.