Last updated:

Crisis Communication SOP: A Complete 7-Step Guide for Corporate PR Crisis Response

A public relations crisis can go from first spark to full outbreak in a matter of hours. Whether a company can protect its brand reputation during a crisis depends less on how well it improvises in the moment and more on whether a complete SOP (standard operating procedure) was already in place before the crisis hit. This guide covers crisis-level classification, the golden-hour response principle, and a full 7-step crisis-handling SOP, giving corporate PR and brand management teams an action framework they can adapt to their own circumstances, and explains how social listening tools can play a role at every stage of a crisis. The time targets and thresholds in this article are examples only and should be calibrated against your company's own baseline data and on-call capacity.

Infographic for Crisis Communication SOP: A 7-Step PR Guide, illustrating key concepts from AI Knowledge Hub

Crisis-level classification and assessment framework

Not every piece of negative sentiment is a "crisis." If a corporate PR team responds to every negative comment with top-tier crisis procedures, it not only burns through resources but can also amplify an otherwise manageable incident through overreaction. Building a clear crisis-level classification system is the first step toward effective crisis management.

Below is a sample four-tier crisis classification framework. Companies should calibrate the boundaries between tiers themselves, based on historical baselines and the nature of each incident — normal fluctuation ranges vary widely across industries, brand sizes, and customer bases, so directly copying someone else's thresholds is usually inaccurate:

Tier 1 (routine monitoring): Isolated negative comments or complaints with no signs of spreading; sentiment volume stays within the normal fluctuation range. Response: Customer service or community managers respond case by case, log it for monthly-report tracking, and no PR procedure needs to be triggered.

Tier 2 (early-warning watch): Negative sentiment shows signs of spreading, sparking discussion in specific communities (such as a particular PTT board or Facebook group); volume is noticeably above the same-period baseline but has not yet reached mainstream media attention. Response: Notify the PR lead and relevant business units, prepare a draft response, increase monitoring frequency, and assess whether proactive communication is needed.

Tier 3 (crisis response): Negative sentiment has been reported by mainstream media or has triggered large-scale, cross-platform discussion on social media; both volume and negative-sentiment ratio deviate sharply from baseline, and brand reputation is clearly impacted. Response: Immediately activate the crisis SOP, convene an emergency meeting, issue an official statement, and monitor sentiment developments around the clock.

Tier 4 (major crisis): The crisis triggers litigation, an investigation by the regulatory authority, sustained coverage by national media, or a material impact on the company's stock price or customer relationships. Response: Activate the highest level of crisis response, which may require engaging an external crisis management consultant, with top management directly involved in issuing statements and handling media communication.

How should classification thresholds be set so they're actually usable? We recommend separating "quantity" from "quality." For quantity, start with at least three months — ideally a full year — of historical volume data, calculate the median and dispersion for the same cycle (e.g., the same day of the week, the same time slot), and then set thresholds based on multiples of deviation from baseline or standard deviation, rather than a single percentage figure; you should also perform cross-platform deduplication and bot-account filtering first, or a single piece of content being reposted heavily will inflate into a false alarm. For quality, look at four dimensions: whether it involves personal safety or health, whether it could trigger a statutory reporting obligation, whether it targets the company's core value proposition, and whether there is an identifiable, named victim. If any one dimension applies, the tier should be escalated immediately even if volume is low.

When should a tier be escalated? Beyond sentiment volume continuing to climb, the following signals are, in practice, more worth watching than the raw numbers: the focus of discussion shifts from "the incident itself" to "the company's handling attitude"; concrete victim narratives or photo/video evidence emerge; mainstream media begins demanding an official response rather than citing online content; regulators, elected representatives, or consumer-protection groups get involved; competitors or interested parties start capitalizing on the situation; or the company's own statements are found to be inconsistent. Conversely, you should also set de-escalation and case-closure conditions — for example, volume returning to the baseline range for several consecutive monitoring cycles, no new propagation nodes, and remediation measures already publicly announced — to avoid keeping the crisis team spinning indefinitely.

The golden-hour principle: the time logic of crisis response

The "golden hour" is a term commonly used in PR practice to describe the response window in the early stages of a crisis. It's worth noting that this is a working principle meant to encourage a prompt response, not a universally validated rule: actual spread speed depends on the nature of the issue, the algorithm and propagation structure of the platform where it occurs, the scale of the opinion leaders involved, whether the incident has visual evidence, and whether it happens to compete with other major news for attention. The same piece of content spreads at a different pace in a closed group, an open forum, and a short-video platform, so treating one case's spread rate as a universal time rule can easily lead a team to misjudge the situation.

What doesn't change is the logic of the information vacuum: before the company speaks, others will define the narrative. This is why the golden-hour principle isn't really about a specific number of hours — it's about staged goals: first confirm the incident and determine its tier, then issue an initial response signaling that the company is aware and taking action, and finally provide a full account once the facts and legal input are in place. The time targets listed in the SOP below are illustrative examples; the actual service levels should be set according to the company's on-call capacity, the time legal review requires, and the severity of the incident, and validated through drills to confirm they're actually achievable.

To achieve a real-time response, a company needs two preconditions in place: first, a robust sentiment monitoring and alert system that ensures notification the moment a crisis starts to emerge; second, a pre-built crisis communication framework (including core message points, a list of authorized spokespeople, and statement templates) so the PR team can quickly assemble an effective response under pressure, rather than starting from scratch to debate "what should we say."

A consistent external message is the piece most likely to break down at this stage — and the piece most likely to come under close scrutiny once it does. In practice, four things help hold it together. First, maintain a single messaging master document that clearly separates information into three categories — "confirmed and can be said externally," "confirmed but not yet for external release," and "not yet confirmed" — with an update timestamp on each item. Second, narrow the number of speaking channels: customer service, sales, storefront staff, and social media managers should never improvise explanations of their own and should only use the approved wording from the master document, referring anything else to the authorized spokesperson. Third, internal syncs should happen more frequently than external releases, so frontline staff always learn about a change in messaging before the outside world does. Fourth, any adjustment to the messaging should come with a stated reason and be updated across every channel at the same time, so an old version of the message doesn't linger on some platform to be used as a contradiction. If the facts later change, proactively explaining "what we understood before, and why it's different now" is usually less damaging than quietly changing the story without comment.

The cost of silence deserves particular caution. Many companies choose to "get a full understanding before saying anything" in the early stages of a crisis — an understandable instinct — but during the information vacuum on social media, speculation, rumor, and interpretations unfavorable to the company tend to fill that vacuum quickly. Even while the facts are still being clarified, issuing a statement along the lines of "we are aware of the incident, are actively looking into it, and commit to providing an update within X hours" is usually preferable to staying silent.

The complete 7-step crisis-handling SOP

What follows is a suggested template for a crisis-handling standard operating procedure, not a universally applicable standard. The time markers noted for each step are illustrative targets; companies should set their own service levels based on on-call staffing, the legal review process, cross-departmental decision-making layers, and incident severity, and should validate feasibility through tabletop drills before writing them into a formal document:

Step 1: Crisis detection and initial assessment (example target: within 30 minutes of the alert)

Once the sentiment system issues an alert, the crisis response process begins immediately. Sentiment monitoring staff or community managers carry out the initial assessment: confirming the incident is genuine (is there a clear, identifiable trigger), evaluating the current spread (the platform of origin, platforms it has already reached, and key propagation nodes), and identifying the key opinion leaders involved (the KOLs or media outlets fueling it). Based on this assessment, the team determines the crisis tier (level 2 through 4) and decides whether to activate the full SOP.

Step 2: Internal notification and crisis-team assembly (example target: within 1 hour of the alert)

Once the crisis tier is confirmed at level 3 or above, the internal notification mechanism is activated immediately. The notification list should already be established in advance and include: the PR/brand lead (primary owner), legal (assessing legal risk), the head of the relevant business unit (holding the facts), the customer service lead (coordinating the frontline response), and top management (notified as needed). Convene an emergency call or video conference to confirm the facts, assign responsibilities, and agree on an initial response strategy.

Step 3: Fact confirmation and information control (example target: as soon as possible after the team is assembled)

Before issuing any external statement, the company must first confirm the facts internally. The core tasks of this step are: (1) clarifying the cause and course of the incident and whether the company was at fault; (2) assessing the incident's potential legal liability (if there is legal risk, all external communication should first be reviewed by legal); (3) confirming the company's position and core message points; and (4) designating the spokesperson — in principle, external communication during a crisis should be handled solely by the authorized spokesperson to avoid inconsistent messages from different departments.

Step 4: Initial statement release (example target: as soon as the outline of the facts and legal input are ready)

The core purpose of the initial statement is to "fill the information vacuum and demonstrate the company's response attitude," not to provide a complete account of the incident (a complete account should not be rushed out before the facts are fully clarified). An effective initial statement should include: (1) a brief acknowledgment of the incident (showing the company is aware of it); (2) expressed concern for affected parties (showing empathy if there are victims); (3) the actions the company is currently taking (an investigation underway, emergency measures already activated, etc.); and (4) a commitment to a follow-up update ("we will provide more detailed information within X hours/days"). The statement should be published simultaneously on official social media accounts and on the press-release page of the corporate website.

Step 5: Ongoing sentiment monitoring and dynamic adjustment (throughout the crisis)

During crisis handling, sentiment monitoring frequency should be upgraded from the normal hourly update to every 15-30 minutes (or higher). Key monitoring points include: (1) the trend in sentiment volume — is it continuing to rise, stabilizing, or starting to decline? (2) new propagation nodes — have new media outlets or KOLs started covering it? (3) how the discussion theme is evolving — has the public's focus shifted from "the incident itself" to "the company's handling attitude"? (4) how competitors are reacting — are any of them piling on or capitalizing on the situation? Based on real-time feedback from sentiment monitoring, the crisis team should dynamically adjust its response strategy.

Step 6: Full statement and remedial measures (example target: after the facts are confirmed and internal sign-off is complete)

Once the facts are confirmed, issue a more complete official statement that clearly explains: the full course of the incident (based on the facts the company has established); the company's position and attitude toward the incident (if there was a fault, it should be honestly acknowledged with an apology); the specific remedial measures the company has taken (refund plans, product recalls, personnel actions, etc.); and a commitment to prevent similar incidents going forward. The timing of announcing remedial measures matters greatly: announcing too early risks creating new problems before details are confirmed, while announcing too late may be interpreted as stalling.

Step 7: Post-crisis follow-up and recovery strategy (example duration: continuing for several months after the heat dies down)

Once the news heat around a crisis subsides, the company enters the brand recovery phase. Recovery strategy includes: (1) continuing to track brand sentiment metrics, monitoring how quickly positive sentiment recovers; (2) executing a systematic brand-rebuilding content plan (positive stories, customer testimonials, social responsibility initiatives, etc.); (3) conducting a full retrospective and review of the entire crisis handling process, identifying gaps in the SOP and updating it; and (4) establishing a more robust crisis prevention mechanism (adjusting alert thresholds, closing gaps in the keyword monitoring system). There is no fixed timeline for brand reputation recovery — it depends on whether the incident involved substantive harm, how thoroughly the company's remedial measures were carried out, and whether new controversies follow. Rather than setting a deadline, it's better to judge recovery by whether sentiment metrics have returned to their pre-crisis baseline range.

Response strategy differences across crisis types

PR crises of different natures each have their own particularities when it comes to response strategy. Below are differentiated recommendations for several crisis types commonly seen in practice:

Product quality crises (food safety, defective-product recalls): Food safety and product safety incidents involve more than just a communications strategy — they also carry statutory obligations around reporting, delisting, and recall. Taiwan's Act Governing Food Safety and Sanitation, the Consumer Protection Act, and related regulations issued by the competent authorities impose requirements on how a business must handle and report a product once a safety concern is identified, and the specific requirements that apply vary by product category, risk level, and the facts of the incident. The correct approach, therefore, is not to automatically recall and pull the product across the board, but to run two tracks in parallel: one, led by quality assurance and legal, that decides whether to recall, halt sales, or report based on risk assessment and instructions from the competent authority and legal counsel; and another, led by PR, that communicates the status of the response externally based on confirmed facts. The general communications principle still holds: the more transparent the explanation of the testing and handling process, the less room there is for speculation; statements that get read as shifting blame tend to make the crisis worse.

The relevant regulations can be looked up in Taiwan's national Laws & Regulations Database:Laws & Regulations Database of the Republic of China (Taiwan). The actual scope of application and operational requirements should still be based on the competent authority's latest announcements and your company's legal counsel's determination; this article does not constitute legal advice.

Crises triggered by employee misconduct: PR crises triggered by an employee's personal words or conduct (especially statements made on social media) have become fairly common in recent public cases. Key response points: first, respond quickly (distancing the company from the conduct in question); second, avoid making specific commitments about personnel action before a full investigation is complete (to prevent later findings from complicating the situation further, and to avoid creating labor-law disputes); third, distinguish clearly between "individual conduct" and "company position" to avoid letting the incident escalate into a debate about "corporate culture."

Online rumors or disinformation attacks: When faced with maliciously spread false information, the key response is to "clarify quickly and provide evidence." We recommend preparing, as soon as possible, a clarification statement that includes original documents, screenshots, or third-party verification, refuting it clearly through official accounts, and proactively contacting the media outlets that reported it to provide accurate information. Legal action can be initiated when necessary, but it's worth noting that "using litigation to counter media criticism" can sometimes be perceived as deepening social polarization.

Building a post-crisis recovery and prevention system

Every crisis is an opportunity to strengthen the crisis management system. Once a crisis ends, the following retrospective work should be carried out systematically:

Crisis timeline reconstruction: Fully document the complete timeline of the incident from its emergence to its resolution, marking every key decision point and the actions actually taken, along with a retrospective assessment of how effective each action was. This record forms an important foundation for future crisis training and SOP refinement.

Reviewing the sentiment system's alert mechanism: Look back at how the sentiment system's alerts performed during this crisis: did it issue an alert early in the crisis? Was the alert threshold reasonable? Were there any important propagation nodes that went undetected? Based on the lessons from this crisis, optimize the alert keyword system and threshold settings to improve early-detection capability for the next crisis.

SOP updates: Based on the actual experience of handling this crisis, update the crisis SOP document to incorporate newly identified improvements (such as communication bottlenecks in the notification process or ambiguities in the spokesperson-authorization mechanism), ensuring the SOP reflects the organization's latest learnings rather than remaining a theoretical framework on paper.

Re-establishing the brand sentiment baseline: After a crisis ends, continue tracking brand sentiment metrics for a period of time to confirm whether sentiment data has returned to its pre-crisis range. If sentiment data remains persistently depressed, it may indicate the crisis's negative impact hasn't fully cleared, requiring a more proactive brand-recovery content plan. Comparing sentiment data before and after the crisis can serve as one basis for evaluating how effective the crisis response was.

Which metrics should a post-mortem look at? We recommend organizing them into three groups. The first group is response speed: the gap between the first related content appearing and the system issuing an alert, the time from alert to completed internal notification, and the time from notification to the first external response. Each of these three intervals maps to a different area for improvement: the first reflects monitoring coverage and keyword design, the second reflects on-call staffing and the notification mechanism, and the third reflects authorization and review processes. The second group is spread and narrative: the peak and decay speed of volume and negative-sentiment ratio, the number of cross-platform propagation nodes, the proportion of mainstream media citing the company's own statement, and how the composition of discussion topics shifted (how much was about the incident itself, the company's attitude, and remedial measures respectively). The third group is substantive outcomes: the volume of complaints and returns, the actual response from channels and clients, the reach and engagement quality of official statements, and whether a similar incident recurs afterward.

When conducting a review, avoid two common pitfalls. The first is declaring success just because volume has dropped: a decline in volume often just means the news cycle has ended, not that trust has been restored — it must be read together with sentiment structure and substantive outcomes. The second is blaming the tool for an alert that never fired, without examining who set the keywords and thresholds and how long ago they were last updated; in most cases, the root cause of a missed detection is that monitoring settings failed to keep pace with changes in product lines, channels, or terminology. Review conclusions should be converted into action items with a named owner and a deadline, and validated in the next drill to confirm they actually made a difference.

FAQ

Yes, we strongly recommend preparing default statement templates in advance. Start by mapping out the crisis types the company is most likely to face (product defects, food safety incidents, employee misconduct, data breaches, etc.) — the number depends on how complex your business is — and prepare a statement template framework for each category in advance, with placeholders such as [incident details to be filled in]. When a crisis hits, the PR team only needs to fill in the specific details rather than drafting from scratch, which noticeably shortens response time; the actual amount of time saved depends on the level of review required and how much legal involvement is needed. Templates should be reviewed and updated regularly to stay aligned with the company's brand voice and latest communication strategy, and their usability should be confirmed through drills.
This is generally not recommended and often backfires. In the social media era, the act of deleting a post can itself become a new source of negative sentiment, getting screenshotted, circulated, and interpreted as "the company is covering something up." The recommended approach is: for comments involving a clear factual error, clarify through a public response; for comments that are emotional but not factually incorrect, you can choose not to respond or respond with understanding; deletion should only be considered in extreme cases involving personal attacks, hate speech, or deliberately misleading disinformation — and even then, there should be clear deletion criteria applied consistently.
This depends on the severity of the crisis. A typical Tier 3 crisis can usually be handled by the PR lead or chief brand officer; a Tier 4 major crisis — involving large-scale casualties, a serious violation, or the company's survival — is what calls for the CEO to step in personally. Having the CEO appear demonstrates the highest level of corporate attention, but it also means any misstep in what's said directly damages the credibility of the top leadership. We recommend that, before a CEO appears publicly, a crisis management consultant provide thorough media training to ensure the message is consistent and delivered appropriately.
Sentiment monitoring tools support crisis early warning through the following mechanisms: (1) sentiment anomaly alerts — when the negative sentiment ratio deviates from the historical baseline by a set threshold within a short period, the system automatically sends an alert notification, with the threshold calibrated to each brand's own volatility; (2) sudden-volume-spike detection — an alert is triggered when mentions of a specific keyword or brand name significantly exceed the same-period baseline; (3) KOL-mention alerts — notification when an account with a large follower base mentions the brand; and (4) media monitoring — real-time notification when specific media outlets report on brand-related issues. These multi-tier alert mechanisms help provide early warning while a crisis is still emerging, but the actual coverage rate and false-positive rate depend on keyword design, data source scope, and deduplication rules, and need to be reviewed periodically.
Yes — small and medium-sized businesses need a pre-established crisis SOP even more than large enterprises, because compared with large companies, SMEs lack sufficient PR resources and buffer capacity when a crisis hits, so once a response goes wrong, the resulting damage is harder to repair. An SME's crisis SOP doesn't need to be elaborate — a short response checklist that can be read under pressure is usually enough, with the focus on ensuring: (1) a clear point of contact for crisis reporting; (2) a clearly designated, authorized spokesperson; (3) a basic statement template; and (4) a simple, usable sentiment monitoring mechanism. Document length isn't what matters — what matters is whether it can be found and followed the moment something happens.
This depends on the severity of the crisis and how far brand sentiment has recovered. We recommend using sentiment data as the basis for this decision: only consider resuming general marketing activity once the brand's negative-sentiment ratio has fallen back to its pre-crisis normal level and media and social discussion of the incident has clearly cooled. Before that point, all external communication should center on "demonstrating the company's improvement actions and accountability," to avoid being seen as engaging in inappropriate self-promotion "before the crisis has even settled." For a severe Tier 4 crisis, the time needed for recovery varies widely and should be judged by whether sentiment metrics have returned to the baseline range and whether remedial measures have genuinely been carried out, rather than by a preset timeline.

Make your sentiment system the first line of defense for your crisis SOP

Learn about InfoMiner's multi-tier crisis alert mechanism to make sure your crisis SOP can be triggered the moment it's needed — protecting your company's brand reputation.

Contact Us