Bulletin Board - Document Comments

Bulletin Board - Review and Comment

Step 1 of 4: Comment on Document

How to make a comment?

1. Use this Comment Icon to open a comment box for your chosen Section, Part, Heading or clause.

2. Type your feedback into the comments box and then click "save comment" button located in the lower-right of the comment box.

3. Do not open more than one comment box at the same time.

4. When you have finished making comments proceed to the next stage by clicking on the "Continue to Step 2" button at the very bottom of this page.

Important Information

During the comment process you are connected to a database.  The session that connects you to the database may time-out due to inactivity.  The following tips will help you to avoid losing your comments or corrupting your entries:

  1. Do not jump between web pages/applications while logging comments.
  2. Do not log comments for more than one document at a time. Complete and submit comments from one document before commenting on another.
  3. Do not leave your submission part way through the comment process. If you are part way through and need to take a break, submit your current set of comments. The system will email you a copy of your comments, so you will be able to identify where you were up to so you can add to them later.
  4. Do not exit the process until you have completed all three stages.

Business Resilience - Critical Incident Management Procedure

Section 1 - Summary

(1) This  Procedure  states  how  Victoria  University  (VU)  will  manage  critical  incidents as part of its Business Resilience Framework. It establishes the governance, escalation, response and recovery arrangements used to manage critical incidents that may impact the University's people, operations, assets, reputation or community.

Top of Page

Section 2 - Scope

(2) This Procedure applies to all University staff; students; contractors, consultants and volunteers engaged by the University; visitors to University campuses; University-controlled entities, offshore operations and partner-delivered activities, where applicable; and any person with responsibilities under this Procedure.  

(3) This Procedure applies to critical incidents occurring:  

  1. at University campuses and facilities;  
  2. during University activities conducted onshore or offshore;  
  3. through partner organisations or third-party arrangements undertaken on behalf of, or in association with, the University;  
  4. in circumstances where the incident has an actual or potential impact on the University's people, operations, assets, reputation or community.  

(4) This Procedure does not replace local emergency response arrangements, specialised operational procedures or business continuity plans. Where required, those arrangements will be activated and implemented in conjunction with this Procedure.  

Top of Page

Section 3 - Policy/Regulation

(5) Business Resilience Policy

Top of Page

Section 4 - Procedures

Part A - Summary of Roles and Responsibilities

Roles

Responsibilities

Critical Incident Management Lead (CIML)  Leads and coordinates the University's response to a Critical Incident and is responsible for incident activation, escalation, resource allocation, decision-making and recovery oversight. 
Critical Incident Management Team (CIMT)  Provides strategic oversight of the incident response; supports decision-making; coordinates response activities; monitors impacts and risks; and supports recovery and continuous improvement. 
Maintains capability to perform their role, participate in training and exercising activities, and ensure appropriate business continuity and succession arrangements are in place. 
Legal Lead  Responsible for student services, support, communications and engagement, including the wellbeing and welfare procedures relating to all students, the Safety and Triage Team and learning and teaching support areas such as Libraries and lab-based Technical Services.  Is the Deputy Incident Controller and will assume the role of the University Incident Controller as required.
Communication Lead  Provides legal advice and supports management of legal, regulatory, compliance and information disclosure obligations. 
Risk Lead  Advises on risks arising from the incident, monitors impacts and supports risk-informed decision-making. 
Critical Incident Support  Provides administrative and coordination support to the CIMT, including recordkeeping, action tracking and meeting support. 
Vice-Chancellor  Provides executive oversight of critical incidents, exercises delegated authority where required, and acts as the University's spokesperson or delegate, when required. 
Chief Student Officer   Leads the student welfare response to critical incidents involving students and, in consultation with the Critical Incident Management Lead, determines whether escalation under this Procedure is required. 
Chief People Officer  Leads the University's staff welfare response and coordinates support, wellbeing and recovery arrangements for affected staff, including employee assistance, workforce support and other people-related response activities. 
All other CIMT members  Provide specialist advice, support response and recovery activities, and implement agreed actions within their area of responsibility. 
Top of Page

Section 5 - Procedures

Pre-Crisis

(6) To support effective critical incident management, staff with responsibilities under this Procedure must understand their roles and responsibilities and participate in relevant training, exercising and preparedness activities in accordance with University critical incident management guidance and processes.

(7) The University may develop incident-specific response plans, playbooks or guidance materials to support preparedness and response for identified critical incident scenarios.

(8) Potential members of the CIMT will be trained for their roles and responsibilities.  

Alert and Assess

(9) Actual or suspected critical incidents must be reported to the Office of the DVC Enterprise and Digital (DVC E&D). 

(10) The Deputy Vice-Chancellor Enterprise and Digital, as CIML, will assess the incident and determine the severity classification of the incident and whether activation ofe a Critical Incident Response is required. The following definitions broadly categorises the 4 severity classifications.  Major and Critical incidents will generally require activation of this Procedure. 

(11) Table 1: Incident Severity Classifications 

Severity Definition Typical Characteristics Typical Response
Minor  A localised incident with limited impact that can be managed by the affected faculty, school, or business unit using normal operational procedures 
• Minimal disruption to teaching, research or services 
• Limited financial or reputational impact 
• No serious injuries or significant safety concerns 
• No external agency coordination required 
Managed by the local area.  
Escalated only if the situation deteriorates. 
Moderate An incident with measurable operational impacts that affects multiple areas or requires coordinated management beyond the local business unit, but where operational procedures still respond. 
• Disruption to multiple services or campuses 
• Potential injury, safety concerns, or regulatory implications 
• Moderate financial or reputational impact 
• Increased stakeholder communications required 
Coordinated by relevant functional leaders with support from University management.  
A response team may be convened. 
Major An incident that disrupts targeted operations, poses risks to people or assets, or requires executive oversight and cross-functional coordination. 
• Serious injury, fatality, or significant threat to the safety of any person arising from a University activity or occurring on University premises. 
• significant property or infrastructure damage 
• High media interest or regulatory involvement 
• Significant Financial, legal, or reputational event 
Notify the CIML.

Relevant Executive VCG leadership directs the response with coordinated internal and external communications.

Activation of relevant business continuity arrangements may be required. 
Those events must be reported to the Office of the CRO. 
Critical An incident that threatens life, the University's ability to operate, or its reputation, requiring immediate executive
• Significant disruption to teaching, research or critical services 
• Fatality or multiple serious injuries on Campus or VU activity 
Critical Incident Management Team (CIMT) activated.  Business continuity and recovery arrangements activated as required. 

(12) The CIML has delegated authority to declare a critical incident and to determine the level of response required to support the University’s response and recovery actions. 

(13) All incidents that present an immediately threat to people, operations or the environment  must be reported immediately to the University's Security Services or emergency services, as appropriate, who will coordinate the emergency response. 

(14) Any incident that meets the MAJOR category must be reported to the Office of the CRO for consolidated reporting to the ARC and Council. 

Activate and Respond

(15) The CIMLU may delegate some or all management functions of incident control - planning, intelligence/public information, operations, logistics and finance as the incident or critical incidents escalate in size or complexity.

(16) At a minimum, the CIMT will comprise: 

  1. The Critical Incident Management Lead (the DVC E&D or their delegate) 
  2. The Legal Lead 
  3. The Communication Lead 
  4. The Risk Lead 
  5. The Critical Incident Support  

(17) Together, this core team will determine the additional members and subject matter experts required to respond to the specific circumstances of the critical incident.  

(18) Each core role must have at least one trained alternate. 

(19) The Subject Matter Experts may be engaged from within or external to the University to: 

  1. assist with the response as required; 
  2. implement relevant operational guidelines relating to the incident type, including the  Student Crisis Response Procedure, Safety and Welfare of Children and Young People - International Student Welfare Procedure, Emergency Management Response Procedure (pending) and other relevant procedures.

(20) Where a critical incident involves students, the Student Crisis Response Procedure must also be activated to ensure appropriate student welfare, support and recovery actions are undertaken. 

(21) The CIML will review the information known about the incident and the impact it has on VU’s operations. Using the Business Impact Assessment (BIA) data, it will prioritise response and recovery efforts to the critical functions impacted first. 

(22) Where the special Crisis Delegations are not enough for the CIML to take appropriate action, the CIML will first go to the Vice-Chancellor to seek approval. If the VC’s delegations are not sufficient, the Critical Incident Council Delegation Group (CICDG) will be convened. 

(23) The CIMT  will ensure that: 

  1. any statutory, regulatory and policy obligations arising from a critical incident are identified and managed;
  2. relevant stakeholders and regulatory bodies, including but not limited to, the Tertiary Education Quality Standards Agency (TEQSA), Australian Skills Quality Authority (ASQA), Work Safe Victoria and the University's insurer are notified in a timely manner and provided with appropriate information.

(24) Each nominated key decision-making member of the CIMT must have delegated powers for operational decisions made within the scope of their specific role. Such decisions must always place primary importance on the impact on the VU community. These decisions must also be consistent with the purpose, values and objectives of the University.

(25) The University will allocate appropriate resources to respond to a critical incident. The CIML may activate the Crisis Operations Centre as required, convene regular briefings  of the CIMT for key senior officers and key subject matter experts as required.

Escalation

(26) Upon activation of a critical incident response, the following internal communication and escalation protocols will be enacted: 

  1. The CIML will notify the Vice-Chancellor. 
  2. The Vice-Chancellor, or their delegate, will determine any governance escalation requirements, including notification of the Chancellor, Chair of the Audit and Risk Committee (ARC), or other relevant governance office holders, as appropriate. 
  3. The Chancellor will determine whether activation of the Critical Incident Council Delegation Group (CICDG) is required.

Statements to the media or public

(27) Internal and external communications arising from a critical incident must be managed in accordance with the Media Policy, Media Protocol and any critical incident communication plan approved for the incident. 

(28) The CIML will ensure that appropriate communications resources are engaged to support the response and recovery activities associated with the critical incident.  

Business Continuity

(29) Critical incident management and business continuity form part of the University's broader Business Resilience Framework. Where a critical incident impacts, or is likely to impact, the University's critical functions, relevant Business Continuity Plans may be activated to support response and recovery activities. 

(30) Not all critical Incidents will require the activation of Business Continuity Plans (Response Plans and/or Recovery Plans).

(31) Implementation of an appropriate business continuity response is the responsibility of the relevant  delegated officer/s.  The most senior officer responsible for the affected area will liaise with the CIML regarding response and recovery activities, as required.

Post-Incident

(32) Following resolution of the critical incident, the CIML or nominee will coordinate a post-incident operational debrief (within 10 University business days) to: 

  1. review the effectiveness of the response and recovery activities; 
  2. identify lessons learnt; and,  
  3. determine opportunities for improvement. 

(33) A Post Incident Report will be prepared. Where appropriate, the report may be provided to the Vice-Chancellor, Audit and Risk Committee, the Council or other relevant governance body as determined by the CIML. 

Records

(34) The CIML or delegated person will ensure records are maintained for each critical incident, including key decisions, actions, and communications undertaken during the University’s response.   

(35) Members of the CIMT are responsible for maintaining appropriate records relating to decisions and actions taken within their respective portfolios. 

(36) Records created under this Procedure must be managed in accordance with the Records Management Policy, Information Security Policy  and relevant associated procedures.

(37) Information relating to a critical incident must be protected from unauthorised access, use, disclosure, alteration or loss and handled in accordance with applicable privacy, information management and legal requirements.

Top of Page

Section 6 - HESF/ASQA/ESOS Alignment

(38) HESF: Standard 2.3 Wellbeing and Safety; 6.2.1 Corporate Monitoring and Accountability; 7.3.3 Information Management.

(39) Outcome Standards for NVR Registered Training Organisations Instrument 2025: Standard 2.6 Wellbeing. Compliance Standards for NVR Registered Training Organisations and FPP Requirements 2025: Standard 20 Compliance with Laws.

(40) ESOS National Code of Practice 2018:  Standard 5 Younger overseas students, 6 Overseas student support services.

Top of Page

Section 7 - Definitions

(41) Business Continuity: The capability of the University to continue delivering critical services and functions at acceptable levels during and following a disruption, through the use of planned strategies, processes, resources, and recovery arrangements 

(42) Business Reliance: The University's ability to anticipate, prepare for, respond to, adapt to, and recover from disruptive events while continuing to achieve its objectives. 

(43) Crisis or Critical Incident: An event that has the potential to cause significant harm to people, disrupt critical University operations, impact the University's reputation, or require a coordinated response involving senior leadership and multiple functions. 

(44) Critical Incident Management Team: A designated group of senior leaders and subject matter experts responsible for providing strategic oversight, decision-making, coordination, and direction during a critical incident or crisis response. 

(45) Crisis Operations Centre: A designated physical or virtual coordination environment established to support the management of a crisis by enabling information sharing, situational awareness, decision-making, resource coordination, and communication between response teams 

(46) Incident: An event, situation, or occurrence that has caused, or has the potential to cause, disruption, harm, loss, or adverse impacts to University operations, people, assets, or reputation.

(47) Incident Classification: The process of assessing and categorising an incident based on factors such as severity, impact, complexity, urgency, and potential consequences to determine the appropriate level of response and escalation. 

(48) Critical Incident Management Plan: A documented framework that defines the University's approach to preparing for, responding to, managing, and recovering from critical incidents. It outlines governance structures, roles and responsibilities, escalation processes, communication arrangements, and response procedures.