1. Purpose
This policy establishes the Group's governance framework for preparing for, responding to, and recovering from hurricanes, tropical storms, natural disasters, public emergencies, and material business disruptions affecting its Turks and Caicos Islands operations.
The purpose is to protect life and welfare, comply with official instructions, reduce avoidable damage, safeguard property and information, maintain critical activity where lawful and safe, protect customers and affected third parties, support orderly recovery, preserve evidence, and demonstrate reasonable corporate preparedness.
This policy does not promise uninterrupted operations, absolute safety, immediate reopening, fixed recovery times, or a guarantee that every loss can be prevented.
2. Scope
This policy applies to Murzo Group Ltd and all subsidiaries, controlled entities, divisions, brands, branches, premises, assets, products, systems, records, projects, and operations conducting business in or from the Turks and Caicos Islands.
It applies to all directors, officers, employees, temporary personnel, contractors, consultants, suppliers, agents, local representatives, visitors, and other persons acting on behalf of the Group within the scope of TCI operations.
It covers work conducted at Group premises, customer sites, supplier sites, ports, airports, warehouses, farms, accommodation, events, field locations, vehicles, vessels, remote locations, and online or cloud environments supporting TCI activity. It also covers events affecting TCI operations where the cause or consequence originates outside TCI.
3. Legal and Emergency Management Context
TCI is exposed to Atlantic hurricanes, tropical storms, storm surge, flooding, power interruption, transport disruption, communications failure, and wider Caribbean supply-chain disruption. The Atlantic hurricane season normally runs from 1 June to 30 November, but severe weather and other emergencies may occur outside those dates.
The Group must monitor and respect instructions from competent TCI authorities, including the Department of Disaster Management and Emergencies, the National Emergency Operations Centre, the TCI National Weather Service, Government press releases, emergency services, port and airport authorities, police, health authorities, utilities, and any other public authority with jurisdiction.
Where TCI orders, UK obligations, insurer requirements, contractual duties, customer duties, regulator requirements, or safety needs overlap, the Group should apply the requirement that best protects life, legal compliance, and essential continuity, unless doing so would breach applicable law.
4. Policy Objectives
- Apply an all-hazards approach to TCI continuity planning
- Treat life safety as the first priority
- Maintain clear decision-making authority and escalation routes
- Comply with official shutdown, evacuation, shelter-in-place, movement, curfew, reopening, and All Clear instructions
- Identify critical activities, key dependencies, and recovery priorities before a crisis
- Keep emergency plans proportionate, tested, and practical for each TCI operation
- Protect data, confidential information, customer commitments, products, assets, and records
- Control public, employee, supplier, regulator, and insurer communications
- Capture factual evidence of warnings, decisions, damage, recovery action, and lessons learned
5. Hazards Covered
This policy covers hurricanes, tropical storms, flooding, storm surge, high wind, lightning, fire, structural damage, earthquake, tsunami, utility failure, communications failure, public-health emergency, cyber or information-system disruption, supply-chain failure, port or airport closure, fuel shortage, transport interruption, security incident, civil disturbance, environmental incident, biological incident, food safety incident, biosecurity incident, government shutdown, loss of premises, loss of personnel, loss of critical suppliers, and any other event that materially affects TCI operations.
The policy applies whether the disruption affects one site, one island, several islands, the whole of TCI, a supplier outside TCI, or a central Group system supporting TCI activity.
6. Crisis Management Governance
The Group should maintain a TCI Crisis Management Team operating under Group authority. Roles should be assigned by function rather than by public policy text, with succession arrangements kept in a controlled contact register.
The TCI Crisis Management Team may include a Group Executive Lead, TCI Incident Lead, Health and Safety Lead, Operations Lead, People and Welfare Lead, Facilities and Security Lead, Technology and Information Lead, Finance and Insurance Lead, Communications Lead, Legal and Regulatory Lead, and other specialist leads required by the incident.
Names, telephone numbers, home addresses, supplier contacts, passwords, insurance values, alarm codes, access codes, and detailed succession arrangements must be kept in controlled emergency plans or registers, not in this public policy page.
7. Emergency Authority
Designated management may activate the continuity framework, close or restrict operations, release or evacuate personnel, prohibit access to unsafe premises, suspend products or services, disable or restrict systems, relocate people or assets, approve emergency expenditure, contact emergency services, notify regulators or insurers, commission inspections, preserve evidence, issue approved communications, and authorise phased recovery or reopening.
Local personnel may take immediate proportionate action where delay would create a serious risk to life, welfare, property, confidential information, evidence, critical assets, animals, insects, food safety, environmental protection, or public safety. Such action must be escalated as soon as practicable.
No person may use emergency authority to ignore official orders, conceal information, make unauthorised public statements, create false records, expose workers to unreasonable danger, or continue trading where closure is required.
8. Official Warnings, Shutdown Orders and All Clear
The Group must monitor official TCI alerts, watches, warnings, advisories, shutdown orders, shelter instructions, evacuation orders, movement restrictions, airport and port notices, utility notices, emergency service instructions, and All Clear or reactivation announcements.
Where the TCI Government implements a national, island-specific, phased, or systematic shutdown, the Group must close, restrict, or suspend affected operations within the required time unless a competent authority confirms that a lawful essential-service exception applies.
No person may require workers, contractors, customers, suppliers, or visitors to disobey an official shutdown, evacuation, shelter-in-place, curfew, road closure, port closure, airport closure, or emergency order for the Group's benefit.
Operations must not reopen before the official All Clear or before the competent authority permits reactivation, unless authorised by law and necessary to prevent imminent harm. Where instructions conflict or are unclear, the matter must be escalated and the safer lawful interpretation applied pending clarification.
9. Essential Services and Restricted Operations
If any Group activity may be classed as an essential, critical, emergency, humanitarian, regulated, food, security, utility-support, accommodation, logistics, animal welfare, biosecurity, or public-interest service, that classification must be confirmed before relying on it.
An essential-service classification does not remove duties to protect workers, follow official directions, control fatigue, maintain insurance conditions, keep accurate records, and avoid unsafe trading. Personnel assigned to essential work must be specifically authorised and must understand the limits of the role.
10. Risk and Business Impact Assessment
Each material TCI operation should identify critical activities, maximum tolerable interruption, recovery priorities, key personnel, premises dependencies, utilities, communications, technology, data, suppliers, vehicles, logistics, regulatory duties, customer commitments, insurance conditions, financial consequences, and health, safety, environmental, food, biosecurity, security, and reputational risks.
The detailed business impact assessment should be kept in a controlled continuity plan or register. The policy does not require unnecessary paperwork for low-risk exploratory activity, but material operations must have enough analysis to support reasonable decisions under pressure.
11. Hurricane Season Preparedness
Before each Atlantic hurricane season, and whenever risk materially changes, the Group should carry out a TCI readiness review covering premises, drainage, roof and shutter readiness, outdoor items, critical equipment, generators, fuel arrangements, batteries, water, emergency supplies, first aid, PPE, staff contact routes, emergency roles, insurance, records, data backup, supplier dependencies, customer commitments, and reopening controls.
The review should be proportionate to the size and risk of the operation. Food, farming, live insect, animal, cultural object, high-value asset, security, property, hospitality, tourism, and customer-facing operations may need deeper readiness checks because failure can affect people, ecosystems, products, evidence, or public trust.
Preparedness must start before a storm is imminent. Last-minute work during official alerts should be limited to tasks that can be done safely, lawfully, and without delaying evacuation or shutdown.
12. Site and Premises Preparation
Site preparation may include securing loose objects, checking doors, shutters, windows, roof points, water entry points, drains, gutters, storage areas, chemicals, fuel, vehicles, equipment, electrical systems, fire systems, access controls, CCTV, alarms, stock, documents, servers, customer property, and high-value assets.
No worker should be sent to prepare or inspect a site where the conditions, official order, travel route, building condition, or expected weather make that work unsafe or unlawful. Where a landlord, site operator, or customer controls the premises, responsibilities must be agreed or escalated before the hazard arrives where practicable.
13. Personnel Protection and Welfare
Life safety takes priority over property, products, revenue, evidence, continuity targets, or continued trading. No person is expected to enter, remain in, or travel to an unsafe location for the Group.
Workers must receive clear closure, evacuation, shelter, remote work, pay, attendance, absence, reporting, and return-to-work instructions where practicable. Vulnerable workers, workers with disabilities, lone workers, pregnant workers, work-permit holders, temporary workers, and workers with transport or accommodation dependencies may require additional practical consideration.
Employee pay, attendance, disciplinary questions, work-permit consequences, housing, and return-to-work issues should be handled under the TCI Employment and Workplace Policy and applicable law.
14. Customers, Visitors and Public Safety
Customer-facing and visitor-facing operations must not invite people into unsafe premises or encourage unnecessary travel during official warnings or restrictions. Customers should receive clear information on closure, cancellation, delay, collection, delivery, refund, support, or rescheduling arrangements where appropriate.
Where the Group controls premises, events, customer sites, accommodation, retail spaces, public-facing facilities, or guided activities, it must consider evacuation, shelter, accessibility, first aid, communications, crowd control, security, and liaison with emergency services or property managers.
Communications must not overstate safety, promise availability, imply official approval, or contradict TCI public authority instructions.
15. Continuity of Critical Operations
Continuity arrangements should consider alternative premises, remote work, manual workarounds, backup communications, cloud access, offline records, supplier substitution, customer prioritisation, payroll continuity, finance continuity, product holds, service suspension, and phased restoration.
The Group may suspend orders, services, shipments, fieldwork, events, customer access, product launches, marketplace listings, contractor work, travel, deliveries, or support channels where safety, legal compliance, logistics, staff welfare, or quality cannot be assured.
Continuity decisions should be lawful, proportionate, documented, and aligned with official directions and insurer requirements.
16. Technology, Data and Cyber Resilience
TCI continuity planning must consider internet failure, mobile network congestion, power outage, cloud access loss, device loss, cyberattack during disruption, phishing using disaster themes, corrupted backups, payment-system interruption, CCTV outage, access-control failure, and remote-work security.
Critical data should be backed up, recoverable, access-controlled, and protected from unauthorised disclosure. Emergency communications must not require staff to share passwords, use insecure public devices, expose customer records, or bypass security controls without approval.
Chatbots, automated messages, AI systems, public status banners, email auto-replies, and customer support tools must not give unapproved emergency advice, contradict official warnings, or falsely state that a site, product, shipment, or service is safe or available.
17. Records, Evidence and Legal Hold
Material decisions, warnings received, official instructions, closure times, evacuation decisions, staff welfare actions, damage, injuries, near misses, data impacts, environmental impacts, supplier failures, customer communications, regulator contacts, insurer contacts, reopening approvals, and corrective actions should be recorded factually and preserved where proportionate.
Records must be accurate, contemporaneous where possible, and limited to what is needed for safety, legal, regulatory, insurance, employment, customer, supplier, financial, and recovery purposes. Records should be managed under the Records Retention Policy and any legal hold instruction.
No person may alter, delete, hide, backdate, or create misleading emergency records, photographs, logs, invoices, inspection notes, system records, or communications.
18. Communications
Only authorised representatives may speak publicly, respond to media, issue customer statements, contact regulators, make social media statements, update websites, speak to insurers on coverage matters, or make statements on behalf of the Group.
Communications must be accurate, verified, calm, and consistent with official TCI information where relevant. Employees, contractors, agents, and suppliers must not speculate, allocate blame, admit liability without authority, publish damage images, identify injured persons, disclose private information, or share confidential material.
Serious injury, death, missing persons, family liaison, safeguarding, police matters, public-health matters, and regulator communications require controlled escalation.
19. Insurance, Claims and Loss Control
The Group should review TCI insurance arrangements periodically and before hurricane season where appropriate, including property, hurricane, flood, business interruption, public liability, employer liability, stock, vehicles, marine, cargo, cyber, directors and officers, professional, event, travel, and specialist cover relevant to the operation.
Incidents must be notified to insurers or brokers promptly where required. Damaged property should be preserved where safe and reasonable, photographs and inventories should be captured where appropriate, and repairs should be controlled so that evidence and insurer conditions are not compromised.
No person may make unauthorised admissions of liability, settle claims, dispose of material evidence, exaggerate losses, understate damage, misstate timings, or obstruct lawful insurer, regulator, or authority cooperation.
20. Finance, Payroll and Emergency Expenditure
Emergency expenditure may be authorised by designated management where required to protect life, legal compliance, property, data, products, animals, insects, food safety, environmental protection, business continuity, or recovery.
Finance continuity should consider payroll, worker support, supplier payments, emergency purchasing, fuel, accommodation, transport, refunds, customer deposits, banking access, payment provider disruption, cash controls, invoice evidence, customs or logistics charges, and insurer recovery.
Emergency purchasing must remain honest and proportionate. Price gouging, bribery, false invoicing, hidden commissions, inflated claims, and conflicts of interest are prohibited.
21. Supply Chain, Transport and Logistics
TCI operations may depend on ports, airports, shipping, fuel, ferries, roads, cold-chain providers, customs brokers, carriers, suppliers, utility providers, internet providers, landlords, security providers, maintenance providers, and external professional advisers.
Continuity plans should identify critical suppliers, alternative suppliers, likely lead times, shipment holds, customs issues, expiry dates, product safety risks, customer commitments, route closures, and communication routes. The Group may delay or refuse shipments where safety, quality, lawful import/export, temperature control, biosecurity, security, or customer delivery cannot be assured.
22. Food, Farming, Biosecurity and Environmental Controls
Where TCI operations involve food, feed, farming, insects, animals, plants, soil, compost, chemicals, fuel, waste, water, refrigerated goods, packaging, equipment, or environmental risks, continuity plans must address containment, temperature control, contamination, spoilage, pest escape, animal welfare, product hold, disposal, clean-up, regulator escalation, and recall or withdrawal risk.
No person may release insects, animals, contaminated materials, chemicals, waste, unsafe food, or damaged products into the environment or supply chain to avoid cost, delay, insurance scrutiny, or disposal requirements.
Environmental damage, pollution, biosecurity breach, food safety issue, or release risk must be escalated promptly and managed under the relevant Group policies and applicable law.
23. Property, Cultural Objects and High-Value Assets
TCI continuity planning must consider buildings, leases, landlord duties, access rights, collections, cultural property, art, artefacts, fashion stock, high-value goods, vehicles, machinery, tools, electronics, data carriers, security systems, and customer or supplier property held by the Group.
High-value, sensitive, fragile, hazardous, regulated, or culturally significant assets should have proportionate pre-season storage, movement, insurance, documentation, access-control, and evidence-preservation arrangements. No emergency movement should create greater risk to life or breach customs, cultural property, sanctions, security, ownership, or insurance rules.
24. Security, Access Control and Site Protection
During an emergency, sites may face looting, unauthorised entry, theft, vandalism, data loss, fuel theft, trespass, false contractor access, and impersonation attempts. Access controls, keys, alarms, CCTV, guards, locks, perimeter checks, and contractor permissions should be reviewed before and after major incidents where safe.
Security activity must remain lawful and proportionate. Staff and contractors must not place themselves at risk to protect property and must not use force, weapons, threats, surveillance, or detention outside lawful authority.
25. Reopening and Reactivation
Reopening should require reasonable confirmation that the official All Clear or lawful reactivation permission has been issued, access is lawful and safe, the premises are structurally suitable, essential utilities are safe, critical systems are secure, material hazards have been controlled, employees can return safely, required inspections have occurred where needed, and management approval has been recorded.
Reopening may be phased by site, island, function, customer group, risk level, system, or product line. A site may remain closed even after an official All Clear where local damage, safety risk, utility failure, staffing, insurer condition, product safety, or security risk remains unresolved.
Managers must not pressure employees, contractors, customers, suppliers, or visitors to return before the site and route are reasonably safe.
26. Third Parties and Contracted Services
Critical suppliers, contractors, landlords, logistics providers, technology providers, security contractors, accommodation providers, maintenance providers, customs brokers, professional advisers, and local representatives should understand their emergency responsibilities where relevant.
Contracts should allocate responsibilities for preparation, closure, emergency access, notifications, insurance, data recovery, restoration timing, evidence, premises security, staff safety, damage reporting, and service resumption. Third parties must not make unauthorised public statements or promises on behalf of the Group.
27. Training, Testing and Exercises
The Group should conduct an annual TCI hurricane readiness review, periodic emergency communication tests, relevant staff training, continuity exercises, IT recovery checks, and post-exercise corrective actions proportionate to the operation.
Training should cover life safety, official alerts, closure instructions, evacuation or shelter decisions, role authority, communications discipline, evidence preservation, cyber caution, data protection, site-specific hazards, and return-to-work expectations.
Exercise details, contact lists, weaknesses, and remediation actions should be kept in controlled plans or registers rather than in the public policy.
28. Post-Incident Review and Improvement
After a material incident, the Group should consider what happened, what worked, what failed, whether official instructions were followed, whether staff were protected, whether customers were treated fairly, whether records and evidence were sufficient, whether insurance conditions were met, and whether controls should be improved.
Corrective actions should be proportionate and may include site repairs, supplier changes, training, revised contact routes, improved backups, contract updates, insurance review, stock relocation, stronger shutters, updated authority maps, revised communication templates, or disciplinary or contract action where misconduct occurred.
29. Compliance and Accountability
Failure to comply with this policy may result in retraining, removal of emergency authority, corrective action, contract remedies, disciplinary action under the TCI Employment and Workplace Policy, insurer notification, regulator notification, law enforcement referral, or other lawful action.
No person will be punished merely for making a good-faith emergency decision intended to protect life, welfare, property, evidence, data, or the environment where the decision was reasonable in the circumstances and escalated as soon as practicable.
30. Relationship With Other Policies and Controlled Plans
This policy should be read with the TCI Legal and Regulatory Compliance Policy, TCI Business Licensing and Corporate Compliance Procedure, TCI Employment and Workplace Policy, Health, Safety and Wellbeing Policy, Business Continuity and Disaster Recovery Policy, Crisis Communications and Incident Response Policy, Cybersecurity and Data Breach Policy, Records Retention Policy, Insurance and Liability Disclosure Statement, Environmental policies, Food Safety policies, Biosecurity policies, Security policies, and relevant site emergency plans.
Detailed evacuation maps, contact registers, passwords, system credentials, supplier contracts, insurance values, equipment inventories, farm containment instructions, food-safety procedures, security tactics, and individual telephone numbers must remain in controlled operational documents.