ISO9001 System Document Package (47) | Emergency Preparedness and Response Work Instruction

By: QTank Published: 9/25/2026 Views: 16
Current rating: ★★★☆☆ Rate this Equivalent to 8 ratings

Document Description: This document is a third-level document (work instruction) that serves the emergency communication requirements under ISO 9001:2015 Clause 8.2 "Requirements for products and services," as well as the planning and control of operations under Clause 8.1, the improvement requirements under Clause 10.1, and the infrastructure and monitoring and measurement resources requirements under Clauses 7.1.3 and 7.1.5. It provides detailed implementation guidelines for the second-level procedure documents such as the "Production Process Control Procedure," "Product Protection Control Procedure," "Infrastructure and Equipment Management Procedure," "Customer-Related Process Control Procedure," and "Risk and Opportunity Management Procedure" in the context of "emergency situations." The procedure documents address "who is responsible, the scope of responsibility, and the approval process," while this work instruction answers "who does what at the first few minutes when a fire, leak, power outage, sudden equipment failure, personal injury, natural disaster, batch quality incident, or critical supplier disruption actually occurs, whether to prioritize personnel safety or property and delivery targets, how long it takes to report information, and how to resume production and document the process afterward." This document is applicable to manufacturing and assembly enterprises with production sites, hazardous chemicals, special equipment, critical equipment, and batch delivery commitments, as well as service organizations with server rooms, spare parts warehouses, and customer delivery nodes. Before using this document, please ensure that the "Risk and Opportunity Management Procedure" has been published and that the emergency risk identification list for your enterprise has been completed.

1. Purpose

To standardize the activities of prevention, warning, response, recovery, and continuous improvement for emergency situations, ensuring:

a) Pre-incident identification: Potential emergency situations (including safety, equipment, environmental, quality, supply chain, and natural incidents) within the enterprise are systematically identified, classified, and listed, leaving no "never thought of" gaps;

b) Incident response without panic: Once triggered, on-site personnel execute the predetermined alarm, evacuation, isolation, and loss mitigation actions within the shortest time, prioritizing personnel life safety over all property and delivery targets;

c) Orderly response during the incident: The emergency organization, communication methods, decision-making authority, and external communication are clear, avoiding multiple command sources, information distortion, and customers and regulatory bodies being "the last to know";

d) Post-incident recovery: Production, delivery, and monitoring and measurement capabilities are restored within the agreed time, and communication with customers is traceable, with records of delivery delays and temporary measures;

e) System improvement: Each response and drill is converted into revisions of emergency plans, resource supplementation, and training needs, forming a closed loop of "drill—evaluation—revision—re-drill" rather than locking the plans in a file cabinet;

f) Audit evidence: The emergency risk list, plans, drill records, resource inspection records, response records, recovery plans, and review records are complete, meeting the evidence requirements for internal audits, certification audits, and customer on-site audits.

2. Scope of Application

2.1 Types of Applicable Incidents:

a) Safety accidents: Fire, explosion, electric shock, mechanical injury, falls from height, object strikes, burns, confined space accidents, vehicle accidents (in-plant forklifts, transport vehicles);

b) Environmental and occupational health incidents: Hazardous chemical leaks, abnormal emissions of exhaust and wastewater, dust explosion risks, poisoning and asphyxiation, heatstroke, occupational health hazard factor exceedances;

c) Equipment and utility incidents: Sudden failures of critical production equipment, special equipment failures, power outages, water outages, gas outages, steam outages, failures of compressed air or chilled water systems, sudden damage to measuring instruments, loss of control of testing equipment;

d) Quality incidents: Batch nonconformities, material mix-ups, deviations of key characteristics, defects found in delivered products, product recalls, customer line stoppages and urgent complaints, major nonconformities found during customer surprise audits;

e) Supply chain incidents: Disruptions from critical suppliers, raw material price increases or quality degradation, logistics interruptions, delays in outsourced parts, customs clearance delays for imported parts;

f) Natural and external incidents: Typhoons, heavy rain, floods, lightning, earthquakes, extreme high and low temperatures, pandemics and public health events, regional power outages, network and data security incidents.

2.2 Applicable Locations and Times: Production workshops, storage areas, hazardous materials warehouses, power rooms (electrical distribution rooms, air compressor stations, boiler rooms), laboratories and metrology rooms, server rooms, loading and unloading areas, office areas; including regular shifts, overtime, night shifts, and shutdown maintenance periods.

2.3 Boundary Between Emergency and Business Continuity: This document covers the entire process from "incident occurrence to the resumption of normal production and delivery." The company's overall business continuity plan (including off-site backup plants and long-term alternative plans) is an operational-level document, and this document complements but does not replace it. The investigation and handling of personal injury accidents should be conducted according to national laws and local regulatory requirements, and this document does not reduce any legal requirements.

2.4 Not Applicable: Routine equipment maintenance, inspections, and hazard rectifications should be carried out according to the corresponding work instructions; however, if any identified hazards meet the classification criteria in Section 4.1, they should be transferred to the emergency management process.

3. Responsibilities

3.1 General Manager: Serve as the emergency commander-in-chief (or authorize a designated person); approve the emergency risk classification list and all emergency plans; provide resource support for emergency resources (firefighting facilities, alarm systems, emergency supplies, training and drills, insurance); decide on the internal and external communication lines for major incidents; approve production recovery plans and changes in delivery commitments to customers.

3.2 Management Representative / Emergency Management Responsible Person: Organize emergency risk identification and classification; organize the preparation, review, release, and revision of emergency plans; develop and implement the annual drill plan; coordinate on-site and gather information during incidents; report the status of emergency resources and hazard rectification progress to the General Manager monthly.

3.3 Safety and Environmental Health Department (EHS): Manage firefighting and safety facilities, develop special emergency plans for hazardous chemicals and special equipment, review the legal compliance of emergency plans, provide technical guidance and archive records for emergency drills, conduct accident investigations and coordinate with external regulatory bodies (safety, fire, environmental protection).

3.4 Production Department: First response on-site (alarm, power off, machine stop, evacuation guidance, initial handling); team leaders are responsible for counting and reporting personnel in their areas; organize production resumption according to the recovery plan after the incident; participate in drills and implement hazard rectifications in their areas.

3.5 Equipment / Utility Department: Emergency repairs and spare parts support for critical equipment and utilities, temporary power and gas supply plans; emergency measures for special equipment; confirm and re-inspect the equipment status after the incident.

3.6 Quality Department: Determine and issue isolation instructions for quality-related emergencies; define the traceability scope for batch nonconformities; assess the risks of delivered products and communicate technical lines to customers; confirm the first article and arrange for intensified inspections after production resumption.

3.7 Procurement and Storage Department: Activate alternative suppliers, emergency procurement, and inventory adjustments for supply chain disruptions; store and regularly inspect emergency supplies (protective equipment, containment and adsorption materials, backup packaging).

3.8 Human Resources and Administration: Organize and record emergency training; accompany and report on personnel injuries and work-related injury claims; maintain and update the emergency contact list; provide emergency knowledge training to new employees and annual retraining.

3.9 Marketing / Sales and Customer Interface Department: Emergency communication with customers during incidents (impact on delivery schedules, temporary measures, recovery plans); transmit information about customer urgent complaints and line stoppages; external information releases must be approved by the General Manager, and no one should make unauthorized statements.

4. Work Procedures

4.1 Emergency Risk Identification and Classification

4.1.1 At least once a year, organized by the Management Representative with participation from all departments, use the "hazard identification + failure scenario simulation" method to identify potential emergency situations in each area, forming the "Emergency Risk Identification and Classification List."

4.1.2 During identification, assess three aspects for each scenario: likelihood of occurrence (high/medium/low), severity of consequences (five dimensions: personal injury, environmental impact, delivery impact, financial loss, and reputational impact, taking the highest value), and the effectiveness of existing control measures. The combination of these three aspects is classified into three levels as follows:

Level Determination Criteria Response Requirements
Level 1 (Company Level) May cause serious personal injury or worse, fire or explosion, large-scale production shutdown, batch recall, regulatory intervention Immediately activate the company emergency plan, the commander-in-chief arrives, all personnel evacuate, report to the General Manager within 1 hour and to external authorities as required
Level 2 (Department Level) Local equipment damage, local production shutdown for 4-24 hours, delivery schedule affected for a single customer, no personal injury The department head initiates departmental response measures, report to the Management Representative within 30 minutes, and to the commander-in-chief if necessary
Level 3 (On-site Level) Single machine short-term shutdown, minor hazards, minor abrasions, can be handled within the current shift Team leader handles on-site and records, reports to the production department on the same day, and tracks in the hazard register

4.1.3 The list should indicate the corresponding plan number, responsible person, required resources, and primary actions for each scenario. The list should be updated within 15 working days when changes occur (new equipment, new processes, new chemicals, new plant areas, regulatory updates).

4.2 Emergency Organization Structure and Responsibility Allocation

4.2.1 The company establishes an emergency command center with six action groups, staffed with "primary + backup" personnel to avoid key positions being incapacitated due to leave:

a) Command Group: Commander-in-chief (General Manager), Deputy Commander (Management Representative), Liaison Officer; responsible for decision-making, resource allocation, external communication, escalation, and termination.

b) Rescue and Repair Group: Composed of equipment, utility, and production backbone personnel; responsible for power and source cutoff, initial firefighting, leak containment, repairs, and temporary alternatives.

c) Evacuation and First Aid Group: Composed of HR and workshop management personnel; responsible for evacuation guidance, personnel counting, first aid and medical transport, and on-site security.

d) Communication and Liaison Group: Composed of administrative and IT personnel; responsible for alarms (119/120/110/local emergency management), internal hierarchical reporting, and external unit contact.

e) Resource Support Group: Composed of storage and procurement personnel; responsible for emergency supply distribution, backup power and lighting, vehicle dispatch, and temporary procurement.

f) Post-Incident Recovery Group: Composed of quality, process, production, and sales personnel; responsible for damage assessment, product handling, production resumption plans, customer communication, and loss statistics.

4.2.2 The emergency contact list should include the mobile phones, family emergency contacts, local fire and hospital, power and water supply units, key supplier and customer contacts of each group member. The list should be verified for accuracy every quarter and updated within 3 working days of any personnel changes.

4.3 Preparation, Approval, and Distribution of Emergency Plans

4.3.1 Each Level 1 and Level 2 risk scenario should have a corresponding plan or a specialized response scheme within a comprehensive plan. The content should at least include: applicable scenarios and activation conditions, command and responsibilities, alarm and reporting procedures, on-site response steps, evacuation routes and assembly points, external rescue coordination, resource list, response termination conditions, recovery and post-incident actions, appendices, and revision records.

4.3.2 Approval: Plans are drafted by the responsible department, reviewed by the Management Representative, and approved by the General Manager. Plans involving firefighting, hazardous chemicals, and special equipment must be confirmed for legal compliance by EHS.

4.3.3 Distribution: Emergency cards (simplified version: alarm numbers, primary actions, evacuation route maps, assembly points) are posted in key areas such as office areas, production workshops, hazardous materials warehouses, and electrical distribution rooms. The full version is distributed to the heads of each action group and a sign-off record is kept. An offline-accessible copy of the electronic version is retained in the shared system to avoid file unavailability during network outages.

4.3.4 Revision: The plan should be revised within 15 working days if any of the following occur: organizational structure or personnel changes, significant changes in processes or equipment, changes in plant layout, defects exposed during drills or actual responses, regulatory and standard updates, or requirements from customers or regulators. After revision, the plan should be re-approved and re-distributed, and the old version should be recalled and destroyed according to the "Document Control Procedure."

4.4 Emergency Resource Allocation and Routine Inspections

4.4.1 The resource list should at least cover: fire extinguishers and hydrants, fire alarms and emergency lighting, evacuation indicators, gas masks and protective clothing, eyewash stations and emergency showers, containment and adsorption materials, first aid kits and stretchers, emergency power and generators, backup pumps and spare parts, warning tape and signs, emergency vehicles and communication equipment, specialized tools for hazardous materials emergency response.

4.4.2 Inspection frequency and responsibility: Firefighting facilities are inspected monthly and tested annually by a professional agency; emergency lighting and evacuation indicators are tested monthly; first aid kits are inventoried monthly for expiration dates; containment and adsorption materials are inventoried quarterly; generators are tested quarterly under load and records are kept; alarm systems are tested annually for联动 (interconnected operation). All inspections are recorded in the "Emergency Resource Inspection Record Form," and any missing or ineffective items are replenished within 3 working days. Items that cannot be immediately resolved are listed as hazards and tracked to closure.

4.4.3 Key areas such as hazardous materials warehouses, electrical distribution rooms, and boiler rooms are managed by designated personnel, with key and access records available. Unauthorized personnel are not allowed to enter.

4.5 Early Warning, Reporting, and Activation Conditions

4.5.1 Sources of early warning information: Weather and disaster warnings, power and water supply notifications, equipment status monitoring and inspection anomalies, customer and supplier early warning information, employee reports, regulatory notifications. After receiving a warning, the responsible department assesses the impact and takes preventive measures (strengthening, production halt, material transfer, advance stock preparation, production schedule adjustment) if necessary.

4.5.2 Reporting paths (text flowchart):

Discoverer → Immediate alarm/report (within 30 seconds) → Team leader (within 1 minute) → Department head (within 5 minutes) → Management Representative (within 15 minutes) → General Manager (within 1 hour for Level 1 incidents)

External reporting: Personal injury 119/120; fire 119; hazardous chemical leaks that may affect outside the plant to local emergency management and environmental protection departments; batch quality incidents and recalls according to customer agreements and regulatory requirements.

4.5.3 Reporting content should be unified according to the P-A-C-T four elements: Position (location and area), Answer/Incident (nature of the incident and its consequences), Condition (current status, whether anyone is trapped, whether there is a risk of spread), Treatment (measures taken and required actions). Hanging up after a single "something happened" is prohibited.

4.5.4 No one should conceal, delay, or misreport. Self-reported and confirmed hazards are positively incentivized; concealing and leading to expanded consequences will be held accountable according to company policies.

4.6 Emergency Response Procedures (Scenario-Specific Actions)

General process: Alarm and evacuation → Power and source cutoff → Isolation and security → On-site response → Personnel counting and first aid → Escalation or termination determination → Recovery and post-incident actions → Record and review.

4.6.1 Fire and Explosion

a) Upon discovering flames or smoke: Immediately shout an alarm and press the manual alarm button, use the nearest fire extinguisher to combat initial fires (limited to small fires controllable within 1 minute);

b) If uncontrollable (fire spreads, heavy smoke, involves oil or chemicals, explosion risk): Immediately stop firefighting, cut off equipment power and gas sources, and evacuate according to the evacuation route;

c) The Evacuation and First Aid Group guides personnel to evacuate through the nearest safe exit to the assembly point, counts personnel by team, and immediately reports any missing persons to the command group and on-site firefighters;

d) The Rescue and Repair Group, under safe conditions, cuts off the main power and flammable gas valves in the affected area, removes surrounding flammable materials, and closes fire doors;

e) After firefighters arrive, the command group coordinates with them, providing a plant layout, a list of hazardous materials and their storage locations, and information about trapped personnel;

f) After the fire is extinguished, protect the scene and do not clean up without the approval of the fire department or EHS, and assist in the investigation and evidence collection.

4.6.2 Hazardous Chemical Leaks and Poisoning

a) Identify the leaked substance, quantity, and direction of spread (check SDS and on-site labels), and have irrelevant personnel evacuate to the upwind direction and set up a warning line;

b) Response personnel enter the area wearing protective equipment based on the substance's characteristics, first cutting off the leak source (closing valves, plugging leaks, stabilizing containers), then containing and adsorbing the leak, avoiding tools that may produce sparks;

c) Contain the leaked substance in a specialized container and label it, to be handled by a qualified unit, and do not flush it directly into the rainwater drainage system;

d) If someone has contact or inhalation: Immediately move them to a well-ventilated area, rinse the skin with large amounts of water for more than 15 minutes, use an eyewash station to rinse the eyes and transport to a hospital, providing SDS to medical personnel simultaneously;

e) Post-incident, test the residual concentration in the air and the impact on soil/water, confirm safety before lifting the warning, and document the response and include it in the hazard rectification process.

4.6.3 Personal Injury and Electric Shock

a) Electric shock: First cut off the power or use an insulating object to separate the injured person from the electrified object, do not pull them by hand; immediately perform CPR (if no breathing or heartbeat) and call 120;

b) Mechanical injury: Immediately stop the machine, cut off the power, and hang a "Do Not Operate" sign, do not restart the machine; do not remove any inserted objects, stop bleeding and bandage before transporting to a hospital;

c) Falls from height and fractures: Keep the injured person still, immobilize the injured area, and wait for professional rescue to avoid secondary injuries from moving;

d) Burns: Rinse with large amounts of water to cool for more than 20 minutes, do not apply ointments or remove adhered clothing, cover with clean dressings and transport to a hospital;

e) Photograph the accident scene, record injured personnel, time, equipment status, and witness statements, report according to legal requirements, and initiate the work injury claim process.

4.6.4 Sudden Equipment Failure and Power, Water, and Gas Outages

a) Equipment alarm or abnormality: The operator immediately presses the stop button, cuts off the power, and hangs a "Do Not Operate" sign, reporting to the equipment department and team leader;

b) Power outage: Confirm whether it is an internal trip (check the distribution cabinet and residual current device), if unable to restore, activate the backup power, prioritizing lighting, firefighting, critical testing equipment, and in-process product safety;

c) Water and gas outages: Determine the affected processes and in-process product status, isolate and temporarily store in-process products according to labels and record the downtime, avoiding prolonged exposure or curing failure of semi-finished products;

d) Equipment repair: Maintenance personnel fill out the repair record, specifying the cause of the failure, replaced parts, and restored parameters; after repair, the quality department confirms the equipment capability (re-validation and first article inspection if necessary), and production must not resume without confirmation;

e) If measuring instruments are damaged during the incident: Immediately isolate and send for inspection or scrap, and evaluate the affected batches according to the nonconforming product process.

4.6.5 Natural Disasters (Typhoons, Heavy Rain, Lightning, Earthquakes, Extreme Temperatures)

a) Upon receiving a warning: Reinforce doors and windows, cover materials, transfer low-lying inventory, inspect drainage and lightning protection facilities, and halt production and evacuate personnel if necessary;

b) Heavy rain and flooding: Cut off power in the affected area, stack sandbags, and evacuate immediately if water levels rise, do not operate equipment in flooded areas;

c) Lightning: Stop outdoor lifting, high-altitude work, and charging operations, disconnect sensitive equipment power and network, and have personnel enter buildings;

d) Earthquake: Seek shelter nearby during the quake (away from shelves, glass, and hanging objects), evacuate orderly to open areas after the quake, and do not return to the workshop until structural safety is confirmed;

e) Extreme high/low temperatures: Adjust working hours, implement heatstroke prevention or cold protection measures, and monitor the status of in-process products and materials.

4.6.6 Batch Quality Incidents, Product Recalls, and Customer Line Stoppages

a) Upon discovery or report: The quality department immediately issues a stop production and stop shipping order, isolating in-process products, inventory, and in-transit items;

b) Traceability scope: Define by batch, production date, equipment, operator, and raw material batch number, and expand to all suspicious batches if necessary; the defined scope forms a traceability list;

c) Risk assessment: Evaluate the risk level and regulatory impact of delivered products, and initiate recalls according to customer agreements and national recall regulations if safety characteristics are involved; the entire process of recall notifications, recovered quantities, and handling methods is recorded;

d) Customer communication: Coordinated by sales and quality, provide preliminary causes and temporary measures within 48 hours, and root causes and corrective actions within 10 working days (or as required by customer agreements); external communication must be approved by the General Manager;

e) Production resumption: After completing cause analysis and measure verification, resume production with the approval of the quality department; after resumption, follow the intensified inspection plan (100% first article inspection + intensified inspections for three consecutive batches), and return to regular inspections once data is normal.

4.6.7 Critical Supplier Disruption and Logistics Interruption

a) Trigger conditions: Supplier shutdown, quality degradation, price increases exceeding agreements, logistics disruptions, customs clearance delays leading to supply risks;

b) Inventory and impact assessment: Calculate the number of days the existing inventory can support and the affected order list, and classify by the number of days impacted;

c) Measures: Prioritize activating alternative suppliers from the qualified supplier list (sample verification and simplified entry procedures must be completed, inspection and release cannot be skipped); adjust production schedules if necessary, negotiate delivery schedules with customers, and activate safety stock;

d) Records: Document the disruption event, impact scope, response measures, losses, and additional costs, and include the recovery time in the "Emergency Response Record Form" as input for the next supplier evaluation.

4.6.8 Information Systems and Data Damage

a) Critical data (drawings, inspection data, system documents, customer information) is regularly backed up, with backup media physically separated from the host, and at least one recovery drill per quarter;

b) In the event of data damage or ransomware attacks: Immediately disconnect the network, isolate affected terminals, notify the information responsible person and the Management Representative, and assess the scope of data loss;

c) Restore from the most recent backup and verify completeness, determine whether re-inspection or re-confirmation of related records is necessary; document the incident and recovery results.

4.7 Emergency Drills

4.7.1 At least two drills are organized annually: one fire evacuation drill (all personnel participate, with goals of evacuation time and accurate personnel counting), and one specialized drill based on the highest risk scenario of the enterprise (hazardous chemical leaks, electric shock first aid, power outage recovery, batch recalls, natural disaster preparedness, etc.).

4.7.2 The drill plan is compiled at the beginning of the year, specifying the scenario, participating departments, time, evaluation points, and observers. A brief briefing is given to participants before the drill, avoiding "advance rehearsals."

4.7.3 Within 5 working days after the drill, complete the evaluation, which should at least include: whether the alarm was timely, whether evacuation routes were clear, whether personnel counting was accurate, whether response actions were correct, whether resources were available, whether communication was smooth, and whether the plan has any deficiencies. Form the "Emergency Drill Record and Evaluation Form," listing corrective items, responsible persons, and completion deadlines.

4.7.4 New employees must receive emergency knowledge training (evacuation routes, assembly points, alarm methods, fire extinguisher use); key positions are retrained and assessed annually, and training and assessment records are archived according to the "Human Resources Management Procedure."

4.8 Response Termination, Recovery, and Business Continuity

4.8.1 Termination conditions: Hazards are eliminated, personnel are safe, environmental indicators are normal, and there are no secondary risks on-site. The commander-in-chief or their authorized person announces the termination of the response and records the termination time and basis.

4.8.2 Recovery steps: On-site cleanup and safety confirmation → Equipment and facility re-inspection (including electrical, mechanical, and metrology) → In-process product and inventory status determination (continue, rework, scrap, downgrade) → First article confirmation after resumption → Intensified inspection → Resume regular production → Communicate delivery schedules and customer updates.

4.8.3 Event loss statistics: Record personnel, equipment, materials, production downtime, and additional costs separately, to be used as input for management reviews and insurance claims.

4.8.4 Within 10 working days after each Level 1 and Level 2 incident, the Management Representative organizes a cause analysis (using 5Why or cause-and-effect analysis), forming corrective actions and plan revisions, specifying responsible persons and completion deadlines, and tracking the effectiveness of the actions according to the "Corrective Action Implementation and Verification Work Instruction."

4.9 Records and Evaluation

4.9.1 Emergency-related records are uniformly archived by the responsible department, with a retention period of no less than three years (extended to no less than ten years for incidents involving personal injury, environmental protection, and recalls as required by law).

4.9.2 The performance of emergency responsibilities by each department is included in the annual performance evaluation, with evaluation dimensions including: number of hazards identified and reported, participation and assessment results in drills, closure rate of corrective actions, completion rate of emergency supply inspections, and the timeliness and standardization of incident responses.

5. Related Records

Form Number Form Name Main Fields Filling Instructions
QR-EHS-01 Emergency Risk Identification and Classification List Serial number, area/process, incident scenario, likelihood, severity, level, existing control measures, plan number, responsible person, update date Reviewed annually, supplemented within 15 working days for new processes or equipment
QR-EHS-02 Emergency Plan Approval and Distribution Record Plan name and number, version, preparer, reviewer, approver, release date, distribution department/area, signatory Consistent with the distribution records in the "Document Control Procedure," old versions must be noted when recalled
QR-EHS-03 Emergency Resource Inspection Record Form Inspection date, area, resource name and quantity, status (good/faulty/missing), validity period, inspector, corrective requirements, closure date Separate pages for monthly fire inspections, monthly first aid kit inspections, quarterly leak material inspections, and quarterly generator inspections
QR-EHS-04 Emergency Contact List Group, name, position, mobile, backup contact, external units (fire/hospital/power/local emergency), verification date Verified quarterly, updated within 3 working days of personnel changes
QR-EHS-05 Emergency Drill Plan Year, drill scenario, participating departments, planned time, observers, evaluation points Compiled at the beginning of the year and approved by the Management Representative
QR-EHS-06 Emergency Drill Record and Evaluation Form Drill time and location, scenario, number of participants, evacuation time, personnel count, evaluation of response actions, exposed issues, corrective items, responsible person, completion deadline Completed within 5 working days after the drill, corrective items tracked to closure
QR-EHS-07 Emergency Response Record Form Incident time and location, incident type and level, discoverer, report time, response start time, response measures, external coordination, personnel and property losses, termination time, basis Mandatory for Level 1 and Level 2 incidents, used as input for corrective actions and management reviews
QR-EHS-08 Production Resumption Confirmation Form Affected process/equipment, re-inspection items and results, in-process product determination, first article confirmation results, resumption time, approver Production can only resume with the approval of the quality department, and intensified inspection batches and conclusions are recorded together
QR-EHS-09 Emergency Procurement and Alternative Supplier Activation Record Required materials, reason, alternative supplier name, verification method and results, approver, incoming inspection conclusion Alternative suppliers must not skip incoming inspection, and verification records are archived with the batch
QR-EHS-10 Emergency Training Record Form Training date, participants, content, hours, instructor, assessment method and results, sign-in Mandatory for new employees, annual retraining for key positions

6. Related Documents

a) "Risk and Opportunity Management Procedure" — higher-level requirements for emergency risk identification and classification;

b) "Production Process Control Procedure" — process continuity requirements for interruptions and resumption;

c) "Infrastructure and Equipment Management Procedure" — equipment repairs, re-inspection, and capability confirmation;

d) "Monitoring and Measurement Resources Control Procedure" — isolation and inspection of damaged measuring instruments;

e) "Product Protection Control Procedure" — protection and isolation of in-process products and inventory during incidents;

f) "Nonconforming Product Control Procedure" and "Nonconformity and Corrective Action Procedure" — determination of damaged products and root cause closure;

g) "Customer-Related Process Control Procedure" and "Customer Satisfaction Monitoring and Measurement Procedure" — changes in delivery schedules and emergency customer communication;

h) "Procurement and External Provision Control Procedure" — activation of alternative suppliers and emergency procurement;

i) "Document Control Procedure" and "Record Control Procedure" — approval, distribution, and archiving of plans;

j) "Internal Audit Procedure" and "Management Review Procedure" — audit and review inputs for emergency management;

k) Safety Data Sheets (SDS) and hazardous materials inventory list;

l) Firefighting facilities layout, evacuation route maps, and assembly point signs.

Usage Instructions

1. Key Points for Customization Based on Actual Enterprise Conditions

  1. Identify risks first, then copy the text. The classification table and control requirements in this work instruction are a general framework. Directly copying them can lead to awkward situations like "the plan mentions hazardous chemical leaks, but the plant doesn't use chemicals." The correct approach is to first list the real scenarios for your enterprise (up to ten) using the method in Section 4.1, then apply the response steps in Section 4.6, deleting any inapplicable items and explaining in the revision record.

  2. Organizational structure and personnel scale should be appropriate. For enterprises with over 100 people, six action groups can be set up as in Section 4.2. For small factories with fewer than 30 people, groups can be merged into "one commander + two on-site responders + two evacuation and first aid personnel + one liaison," but each role must have a primary and backup person, and names or positions must be clearly listed, not just "a certain department."

  3. Product and industry-specific adaptation. For mechanical processing enterprises, focus on mechanical injuries, lifting injuries, and equipment failures; for electronic assembly enterprises, focus on static electricity and material moisture, power outages, and reflow soldering equipment failures; for food and chemical enterprises, focus on cross-contamination, leaks, fires, and recalls; for service organizations, focus on server rooms, data security, and delivery interruptions. Natural disaster clauses should be adjusted based on the region (inland enterprises can de-emphasize typhoons, coastal enterprises must detail them).

  4. Resource clauses must specify quantities and locations. "Workshops are equipped with fire extinguishers" is not an effective requirement. "Two 4kg dry powder fire extinguishers, numbered M-01/M-02, on the east wall of Workshop A, inspected by the team leader before the 5th of each month" is an auditable requirement. Similarly, emergency supplies should clearly indicate storage locations and retrieval routes.

  5. Time and deadlines should be adjusted based on actual enterprise conditions. The reporting deadlines (1 minute, 5 minutes, 15 minutes, 1 hour) in this work instruction are reference values. Enterprises can adjust based on plant size and personnel density, but once written into the document, they become audit criteria and must be confirmed as achievable.

  6. Avoid duplication with existing documents. If the enterprise already has a "Fire Safety Management System" or "Safety Production Emergency Plan" (legally required safety plans), this work instruction should not repeat their entire content but should serve as an interface for the quality management system: reference the legal plan numbers and supplement quality and delivery-related requirements not covered (such as batch recalls, emergency customer communication, production resumption confirmation, and handling of damaged measuring instruments).

2. Audit Focus Points (Typically Pursued by Auditors)

  1. Whether the emergency risk list covers all clauses. Auditors will verify if the list in Section 4.1 includes scenarios such as water and power outages, equipment failures, supply chain disruptions, and natural disasters, which many enterprises only list as fire.

  2. Whether the plan matches the actual response. Randomly check an incident record to see if the actual actions align with the alarm paths, response steps, and deadlines specified in the plan. Non-compliance without a revision explanation will be judged as a nonconformity.

  3. Whether the drills are genuine. Focus on whether the drill records specify evacuation times, number of participants, exposed issues, and corrective actions. If the records only state "successfully completed, good results" with no issues, auditors will typically ask for details and question the authenticity.

  4. Whether resource inspection records match the on-site physical items. If the record shows that fire extinguishers are in good condition, but on-site inspections reveal pressure gauges in the red zone or fire extinguishers blocked by shelves, this is a typical nonconformity.

  5. Whether corrective actions are closed after the response. Check if the "Emergency Response Record Form" includes cause analysis, measures, and verification conclusions. If there are only records without corrective actions, Clause 10.2 will be cited.

  6. Whether production resumption is confirmed. After equipment repairs, whether there are re-inspection records and first article confirmations, and whether damaged measuring instruments have isolation and inspection records, and affected batches have traceability and determination—this is the core of quality incident audits.

  7. Whether external communication is traceable. Whether changes in customer delivery schedules and recall notifications have written records and customer feedback. Unauthorized verbal commitments without records will be judged as a lack of communication control.

3. The Ten Most Common Errors

  1. Plans are locked in a cabinet, and no one on-site knows about them. In case of a fire, employees first look for their supervisor rather than sounding the alarm. Solution: Post emergency cards in key areas, provide mandatory training upon hiring, and repeatedly practice "nearest alarm, evacuate according to the route" in pre-shift meetings.

  2. Alarm numbers on the wall are outdated. The contact list has not been updated for two years, and key personnel have already left. Solution: Quarterly verification mechanism + update within 3 working days of personnel changes, with the responsible person's signature.

  3. Emergency supplies are ignored after purchase. Gas mask filters expire, first aid kit medicines become ineffective, and adsorption cotton molds. Solution: Create a ledger for supplies upon receipt, mark expiration dates, and set a 30-day reminder before expiration.

  4. Evacuation routes are used as temporary storage. Finished product transfer carts and packaging boxes block safety exits for long periods. Solution: Mark evacuation routes with yellow lines and include them in daily 5S inspections, and issue nonconformities for blockages.

  5. Plans are copied from other enterprises and do not match the plant layout. The evacuation route map shows doors that do not exist in the plant. Solution: Draw plans based on the plant layout and update labels simultaneously during revisions.

  6. Drills are formalities. Advance notice, scheduled start, and passing-by evacuation are completed in 2 minutes. Solution: Do not rehearse in advance, start randomly, record actual evacuation times, and use the number of issues found as the standard for successful drills.

  7. Incidents are not reported and are handled independently. Equipment is damaged or a batch of materials is ruined, and the incident is only discovered afterward. Solution: Clearly define reporting obligations and exemption clauses (no accountability for proactive reporting), and list concealment as a serious violation.

  8. Only fire drills are conducted, not quality or supply chain drills. Batch recalls and supply disruptions are never practiced, and no one can provide a customer response within 48 hours when they occur. Solution: At least one of the two annual drills should be a quality or supply chain tabletop exercise.

  9. Equipment is put back into production without capability confirmation. After replacing a servo or sensor, no capability confirmation is done, leading to batch size deviations. Solution: The production resumption confirmation form is a mandatory release document, and production can only resume with the quality department's signature.

  10. No corrective actions are taken after incidents. Records are archived and the incident is considered closed, but similar incidents occur three times within a year. Solution: Level 1 and Level 2 incidents must go through the 5Why and measure verification process, and the recurrence rate should be reported in management reviews.


One point of pre-incident identification, ten points less panic during the incident, one improvement after the incident

Knowledge code: 2.3.1

Version: v20260809

Author: QTank QTank is dedicated to providing systematic professional knowledge, methodologies, and practical tools for quality management practitioners, helping enterprises continuously improve their quality capabilities.