The Board of Directors (the "Board) is obligated to ensure a disaster preparedness plan is reviewed annually and meets the goals of this policy. In the case of a disaster, the Foundation must be able to:
- Continue critical business functions.
- Inform staff, volunteers, board members, key donors, vendors and the community at large of the disruption.
- Protect assets and vital records.
- Provide assurance to all stakeholders of the security of Foundation assets.
Disaster Preparedness Plan
In the case of a disaster, Board members shall make reasonable efforts to be available for emergency meetings, conference calls and approvals. In the event of a disaster, the Chief Executive Officer ("CEO") will be responsible for leading the Foundation's response, including but not limited to:
- Assist in the establishment of an alternate office site if required.
- Ensuring the Foundation's office, and business functions, are returned to normal operations as quickly as possible
- Develop and implement a communications plan for the purpose of providing assurance to the Board, to Foundation stakeholders and to the larger community.
- Develop a plan and notify key stakeholders including board members, donors, grantees, suppliers and the media of the interruption to operations and strategies that will be taken to address the interruption.
- Recover computer and telephone technology (hardware and software). Copies of vital documents are backed up regularly and stored off-site. Forms and documents are listed on the Record Retention list.
- Coordinate paperwork required by insurers to initiate claims.
- Maintain daily cash funding for any essential business processes.
- Prepare and maintain a cumulative cost report for the event.
- Maintain payroll.
- Ensure easy access to necessary capital.
- Provide and encourage access to counseling for staff.
- Create and annually review two files with extra letterhead and envelopes, all relevant plans, instructions on how to access the website, email and phone message system, password list, and contact information for key stakeholders. One file shall be stored with the Chair of the Board and off-site where it may be accessed by the CEO.
Canadian Law and Regulatory Compliance
The recovery plan will identify critical services, maximum tolerable downtime, recovery-time and recovery-point objectives, decision authority, alternate communications, essential vendors, access to banking and CRA/corporate accounts, and the location of governing, financial, donor, grant and insurance records.
Backups will be encrypted, separated from production systems, access-controlled and tested through documented restoration exercises. The plan will coordinate with privacy-breach, cybersecurity, fraud, safeguarding, insurance and mandatory-notification procedures and will be exercised at least annually.
Application note: This template must be read with the Foundation's articles, bylaws, gift terms and the federal, provincial or territorial laws that apply to its incorporation, activities and operating jurisdictions. Organization-specific facts and provincial requirements require lawyer confirmation before adoption.
Monitoring: This policy will be reviewed every three years or following a disaster.
Board Acceptance: This policy was approved/reaffirmed at the ____________Board meeting.