Ho Do You Reduce Key Person Risk In A Small Business

Adam Fox • 6 October 2026

You reduce key-person risk by making sure important business outcomes do not depend on one individual being permanently available.

That does not mean everybody needs to be replaceable tomorrow.

It means identifying where the company has dangerous single points of failure, then deliberately spreading:

  • Knowledge
  • Capability
  • Authority
  • Relationships
  • Access
  • Decision-making
  • Succession options

across more than one person or system.

The key person might be the owner.

It might also be:

Your Operations Director.

Estimator.

Finance Manager.

Engineer.

Salesperson.

Payroll administrator.

Technical specialist.

Project Manager.

IT person.

Someone who has worked there for twenty years and apparently knows where every body is buried.

Their job title is not what makes them key.

The consequence of losing them is.

If one person's unexpected absence would stop sales, delay customers, prevent payments, remove critical knowledge or leave nobody legally or technically capable of doing something important, you have key-person risk.

And the best time to reduce it is while that person is still sitting at their desk.

This is broader than owner dependency

Article #71 asked what would happen if you, the owner, suddenly became unable to work.

This article asks the wider question:

Who else could disappear tomorrow and seriously damage the business?

That matters because businesses often spend years reducing owner dependency and accidentally create another version of exactly the same problem.

The owner delegates everything operational to an excellent General Manager.

Wonderful.

Six months later, the owner can finally step back.

Except now:

Only the General Manager understands the operation.

Everybody takes difficult decisions to them.

All the key customers know them.

All supplier issues route through them.

When they take two weeks' holiday, the company quietly panics.

You moved the dependency.

You did not remove it.

Key-person risk is a single point of failure

Think of it that way.

If removing one individual causes a disproportionate amount of the business to stop functioning, that person represents concentration risk.

Perhaps they are the only person who can:

Price complex projects.

Operate specialist equipment.

Sign off technical work.

Run payroll.

Produce the monthly accounts.

Access a critical platform.

Manage your largest customer.

Understand a particular contract.

Maintain a bespoke software system.

Approve significant expenditure.

Deal with the bank.

Recruit specialist staff.

Solve a recurring production problem.

Some dependencies are unavoidable in the short term.

The question is whether they remain invisible and unmanaged.

Do not start by asking who your “best people” are

That produces the wrong list.

Your highest performer may not actually be a key-person risk.

Perhaps Sarah is an extraordinary salesperson.

But:

Her CRM records are excellent.

The Sales Director understands every account.

Customers know several people.

Other salespeople can cover.

The sales process is clear.

Losing Sarah would hurt.

That is different from business interruption.

Meanwhile Bob works quietly in Finance.

Nobody describes Bob as a superstar.

Bob happens to be the only person who knows:

How payroll works.

Where the banking files come from.

How a particular customer billing process operates.

Which spreadsheet feeds the cash forecast.

How to fix the weird VAT export every quarter.

Bob takes three weeks off unexpectedly.

Now everybody discovers Bob was infrastructure.

That is why you identify key people by dependency, not status.

Run the 30-Day Absence Test across the business

Take every important role and ask:

What happens if this person becomes completely unavailable tomorrow for 30 days?

Not resigns with a three-month handover.

Not answers occasional questions.

Unavailable.

What stops?

What slows?

Who struggles?

What customer notices?

What decision cannot be made?

What information disappears?

What deadline might be missed?

What system becomes inaccessible?

What regulation or licence creates a problem?

What revenue becomes vulnerable?

This is essentially business-continuity thinking applied specifically to people.

Current UK government guidance describes business continuity management as identifying critical activities and the resources supporting them, then planning how important functions can continue when disruption occurs. It specifically recommends understanding changes in staff, suppliers, organisational structure and other resources that could affect continuity.

Do not begin by trying to predict why somebody becomes unavailable.

Illness.

Resignation.

Family emergency.

Competitor recruitment.

Accident.

Retirement.

The cause matters later.

The operational question is:

What disappears when the person does?

Look for seven types of dependency

Most key-person risk I see falls into a handful of categories.

1. Knowledge dependency

One person knows something important that nobody else can easily reconstruct.

That might be:

Technical knowledge.

Customer history.

Pricing logic.

Production setup.

A complicated spreadsheet.

A legacy system.

How a particular contract works.

Which suppliers can solve unusual problems.

Why a process exists.

Knowledge dependency is dangerous because the business may not realise what has disappeared until it needs it.

You only discover the information mattered when nobody can answer the question.

2. Capability dependency

Several people understand what needs doing.

Only one person can actually do it.

Perhaps one employee is:

Qualified.

Licensed.

Technically competent.

Experienced enough.

Trained on specialist equipment.

Able to prepare a particular calculation.

This is different from undocumented knowledge.

The knowledge may be available.

The capability is not.

3. Relationship dependency

One employee holds a commercially important relationship.

Customer.

Supplier.

Referral partner.

Bank.

Professional adviser.

Key subcontractor.

If that person leaves, does the relationship stay with the business?

Or did the company effectively borrow their personal relationship?

This is particularly dangerous where one salesperson or founder controls a large share of customer revenue.

4. Authority dependency

Other people know what to do.

They simply cannot authorise it.

Only one person can:

Approve payments.

Sign contracts.

Authorise purchases.

Agree discounts.

Approve refunds.

Hire.

Commit resources.

You have capability.

But the business still stalls because authority is concentrated.

5. Access dependency

One employee holds the digital or physical keys.

Administrator account.

Bank authentication.

Domain control.

Payroll credentials.

Software ownership.

Building access.

Encryption keys.

Supplier portals.

This is an increasingly important risk because a company can contain plenty of competent people who remain completely unable to act if the required digital access disappears.

6. Capacity dependency

One person can technically be covered.

But not without overwhelming everybody else.

Suppose you have three project managers.

One leaves.

The remaining two understand their work.

They simply have no realistic capacity to absorb it.

That is still resilience risk.

Cross-training without spare capacity is not always enough.

7. Leadership dependency

Someone holds the organisation together.

They coordinate.

Resolve disagreements.

Set direction.

Make judgement calls.

Keep people calm.

The written processes may survive their absence.

The management system may not.

This tends to appear at owner, director or senior-manager level.

But not always.

Start with the roles that could materially interrupt the business

Do not turn this into an audit of all 83 employees.

Start with the handful of roles where absence could cause serious damage.

CIPD's current succession-planning guidance recommends identifying business-critical positions first, rather than assuming succession planning should only focus on the most senior jobs. It also notes that modern succession planning increasingly uses pools of people capable of covering groups of roles rather than simply identifying one replacement for one executive.

For a small business, I would identify perhaps:

Five.

Ten.

Maybe fifteen critical roles.

Depending on size and complexity.

Then go deeper.

Estimate the impact

For each key person, ask what a prolonged absence could affect.

Revenue

Would sales stop?

Could important customers leave?

Would orders be delayed?

Delivery

Would projects stop?

Could deadlines be missed?

Would quality deteriorate?

Cash

Could invoices still go out?

Could payroll run?

Could payments be approved?

Compliance

Does the person hold a qualification, licence or statutory responsibility the company depends upon?

Customers

Would anyone else understand the account?

Systems

Does the company still have administrative access?

People

Who leads their team?

Replacement time

Could you recruit another capable person in:

Two weeks?

Six months?

Two years?

The longer replacement takes, the more seriously I would treat the dependency.

Do not obsess over creating a precise risk score

You can absolutely use:

High.

Medium.

Low.

Or a numerical matrix if that helps.

But avoid spending three weeks debating whether Jim is:

7.4 out of 10 key-person risk

rather than:

7.1.

The useful question is:

Which few dependencies could seriously hurt us, and what are we going to do about them?

You are building resilience.

Not a scoring competition.

Step 1: Get important knowledge out of people's heads

This is the obvious intervention.

Also the one most likely to become absurd.

Please do not respond by asking everyone to write a 90-page procedure for every element of their job.

Focus on information that is:

Critical.

Difficult to reconstruct.

Time-sensitive.

Used infrequently enough that others would not know it.

Ask the key person:

If you disappeared tomorrow, what would we desperately wish you had written down?

Start there.

That might include:

Process notes.

Customer histories.

Technical procedures.

Pricing logic.

System architecture.

Supplier contacts.

Recurring deadlines.

Decision rules.

Exception handling.

Location of critical documents.

It does not need to become War and Peace.

It needs to let another competent person continue.

Documentation should explain judgement, not only clicks

Weak procedure:

Click File.

Click Export.

Select CSV.

Save to desktop.

Great.

Why are we doing this?

What does the output mean?

What happens if the numbers look wrong?

Which exceptions matter?

What decisions follow?

Key-person knowledge often lives in judgement, not merely procedure.

Capture some of the reasoning.

For example:

“If project margin drops below 25%, check labour overrun first because that is historically the most common cause. If labour looks normal, check subcontract variation orders before changing forecast.”

That is much more useful than:

“Open the margin report.”

Record specialist processes where appropriate

Sometimes written instructions are enough.

Sometimes video is better.

Screen recordings can be excellent for:

Software workflows.

Reports.

Technical administration.

Complex spreadsheet processes.

Combine them with concise written notes so somebody can quickly find what they need.

The objective is not beautiful documentation.

It is recoverability.

Step 2: Build a second capable person

Documentation alone does not create capability.

I can give you a manual for flying a helicopter.

Please do not give me the helicopter.

Some roles require:

Experience.

Practice.

Technical skill.

Professional qualifications.

Judgement.

So somebody else needs exposure before the key person disappears.

CIPD's December 2025 succession guidance specifically recommends proactive development through practical experience, job moves, secondments and other opportunities that prepare people for future or emergency roles.

For an SME, that might simply mean:

Shadowing.

Joint customer meetings.

Cross-training.

Covering holidays.

Leading a project.

Attending key financial meetings.

Running the monthly process once.

Learning specialist equipment.

Gradually making decisions with oversight.

Do not wait for the emergency before beginning the training.

Holiday cover is one of the cheapest resilience tests you have

Your key employee takes two weeks off.

Good.

Let them actually take two weeks off.

Do not build a continuity system that consists of:

“Ring Dave on holiday.”

Before they leave:

Who covers?

What do they need?

Which decisions can they make?

What has to wait?

What might break?

Then observe.

Every question sent to the absent person tells you something.

That is dependency data.

Use it.

Step 3: Develop talent pools, not one heir to every throne

Traditional succession planning can become:

Sarah replaces Dave.

What if Sarah leaves first?

Or does not want the job?

Or turns out not to be ready?

Where possible, build broader capability.

CIPD's latest guidance describes a shift towards talent pools and groups of roles where several individuals develop the skills required for multiple critical positions.

That approach often makes sense in smaller businesses too.

Maybe you cannot have:

Three Finance Directors.

But perhaps two people understand enough of the finance function to maintain basic continuity.

Three people can quote standard work.

Two managers can deal with important customers.

Several supervisors can run a shift.

Resilience improves when capability spreads.

Step 4: Spread customer relationships

This is one of the highest-value interventions.

If your largest customer's entire relationship sits with one individual, widen it.

Not awkwardly.

Naturally.

Introduce:

Another salesperson.

Operations contact.

Director.

Account Manager.

Technical person.

Attend important reviews together.

Make sure customer history is recorded properly.

Let the customer experience the capability of the wider company.

This is particularly important if the key person is the owner.

A company becomes far more robust when customers trust the organisation rather than one personal contact.

Do not suddenly swarm the customer

There is a balance.

You do not need six people joining every account meeting to prove resilience.

That wastes everybody's time.

Build sensible relationship coverage.

Maybe:

Primary commercial contact.

Operational contact.

Senior sponsor.

Enough that the customer knows where to go if one person disappears.

Step 5: Spread supplier and adviser relationships too

The same applies outside sales.

Does only one person know:

Your accountant?

Insurance broker?

Solicitor?

Bank manager?

Landlord?

Critical manufacturer?

IT provider?

Key subcontractor?

If the relationship matters, somebody else should at least know:

Who they are.

What they do.

Where the agreement sits.

How to contact them.

What current issues exist.

Again:

Not everybody.

Enough people.

Step 6: Fix access before it becomes an emergency

This should be boring.

That is good.

Identify the accounts capable of seriously disrupting the company if access is lost.

Banking.

Finance.

Payroll.

HR.

Cloud storage.

Domain.

Website.

CRM.

Key supplier portals.

Important social accounts.

NCSC's April 2026 small-organisation guidance specifically highlights banking, HR and payroll, cloud storage, websites and other important online services and recommends regularly reviewing who has access. It also advises against leaving responsibility for cyber security with a single person.

You want:

Appropriate separate user accounts.

More than one suitably authorised administrator where sensible.

Secure recovery arrangements.

Managed access.

Clear offboarding.

Not:

“Dave has the password.”

Do not reduce key-person risk by wrecking cyber security

The answer is not:

Everybody gets administrator access.

Passwords pasted into Teams.

Bank details in a shared spreadsheet.

That merely exchanges one risk for another.

Resilience and security need to coexist.

Use:

Proper permissions.

Password-management tools where appropriate.

Role-based access.

Documented recovery routes.

Separate administrator accounts.

Your IT provider or security adviser can help for critical systems.

Step 7: Spread authority

If an Operations Director is expected to run operations, decide what they can approve.

If Finance is responsible for paying suppliers, make sure banking and approval structures can continue appropriately when one person is absent.

If Sales owns routine commercial negotiations, define the boundaries.

This is not about eliminating control.

It is about avoiding a control system whose entire design is:

Ask Martin.

A good authority structure answers:

Who can decide?

Within what limit?

What requires a second approval?

What escalates?

What happens if the normal approver is unavailable?

Those questions should be answered before somebody disappears.

Step 8: Remove unnecessary specialist dependency

This is where systems and automation can help.

Suppose only one person knows how to produce the weekly report because it requires:

Four exports.

Three spreadsheets.

Two manual reconciliations.

And one ritual sacrifice.

You could cross-train somebody else.

Good.

You could also ask:

Why is the process like this?

Perhaps Article #70 applies.

Could it be:

Simplified?

Integrated?

Automated?

Redesigned?

The best key-person-risk intervention is sometimes eliminating the specialised task entirely.

Do not preserve complexity just so two people can understand it

This is worth emphasising.

Process is complex.

One person understands it.

Leadership decides:

“We need another person to understand it.”

Maybe.

But first ask whether it should remain complex.

Agency asks:

Is there a better way?

If a process can be reduced from eleven manual steps to three standard ones, you reduce:

Training demand.

Error.

Time.

Dependency.

Do not replicate avoidable complexity.

Step 9: Separate role risk from person risk

This distinction is useful.

Suppose your Operations Director leaves.

Risk exists because:

The Operations Director role is critical.

That may be unavoidable.

But person-specific risk exists if:

Nobody else understands it.

No deputy exists.

No systems exist.

No information exists.

Customers only know them.

Reduce the second.

You cannot design a business where senior leadership suddenly disappearing causes zero inconvenience.

You can stop it causing paralysis.

Step 10: Recruit with succession in mind

Not every hire needs to be someone's successor.

But look at capability depth.

Suppose you have one excellent estimator.

Next hire?

Maybe another estimator becomes strategically more valuable than another salesperson, even if Sales is louder about needing help.

Workforce planning should consider:

Current workload.

Growth.

Scarcity of skills.

Retirement.

Turnover.

Critical-role cover.

CIPD treats succession planning as part of broader workforce and talent planning, specifically linking business-critical roles with recruitment, development and retention decisions.

That is much more useful than thinking about succession only when somebody hands in their notice.

Do not assume succession means promotion

Perhaps your Technical Director disappears.

Their responsibilities could be split between:

Two internal employees.

External consultant.

Another director.

Recruitment.

Temporary specialist support.

Succession does not always mean identifying one replacement human in advance.

The objective is continuity of the capability.

Be flexible.

Planned succession is much easier than emergency succession

You know someone intends to retire in eighteen months.

Excellent.

That is a gift.

Use the time.

Identify what they know.

What relationships they hold.

What nobody else can do.

What should transfer.

Who needs experience.

Which customers need introductions.

Do not spend seventeen months saying:

“We'll really miss Brian.”

and the final month asking:

“Brian, could you document 34 years of knowledge before Friday?”

That is not succession planning.

That is archaeology with a deadline.

Retention is part of key-person-risk management

If somebody is difficult to replace, keeping them matters.

Article #73 covered retention in depth.

For a key person, understand:

Are they engaged?

Paid fairly?

Overloaded?

Developing?

Do they have a credible future?

What might cause them to leave?

Would you know before the resignation arrived?

Retention reduces probability.

It does not remove the risk.

Do not try to solve key-person risk with golden handcuffs alone

Pay them more.

Give shares.

Bonus.

Long notice period.

Maybe useful.

None guarantees permanent availability.

They can still:

Become ill.

Have a family crisis.

Retire.

Change career.

Move country.

Die.

Decide they have had enough.

Retention tools can reduce avoidable loss.

You still need continuity.

Long notice periods are not a substitute for resilience either

Perhaps your contract requires three or six months' notice.

Useful.

It may allow time for transition.

But:

The employee could be placed on leave.

Relationships can deteriorate.

They may be mentally checked out.

Illness does not provide notice.

You still need business capability beyond the individual.

Consider external backup for highly specialist roles

A small company cannot duplicate every specialist employee internally.

That would be wildly expensive.

Perhaps you employ one:

IT specialist.

Technical consultant.

Health and safety professional.

Payroll person.

In some situations, external backup may be sensible.

A retained specialist.

Trusted contractor.

Professional firm.

Partner organisation.

Someone capable of stepping in or supporting transition.

The principle appears explicitly in ICAEW's July 2026 alternate guidance for sole practitioners. ICAEW recommends appropriate alternate arrangements so clients and critical work can continue if a sole principal becomes incapacitated or dies, including clarity around skills, capacity, access and authority. That guidance is specific to accountancy practices and certain regulated situations, but it provides a useful real-world example of formal backup capability for a genuinely critical person.

Your industry may have its own version.

Regulated or licensed roles need special attention

Some dependencies cannot simply be delegated because:

The person holds a statutory appointment.

Licence.

Professional registration.

Authorisation.

Specific competency.

In those cases, the business needs to understand:

What the requirement actually says.

Who else could qualify.

Whether temporary arrangements exist.

Which regulator or customer needs notifying.

How long replacement could take.

Use appropriate legal, regulatory or professional advice.

Do not assume:

“Steve showed Dave how he does it”

creates authority where the law, licence or contract says otherwise.

Key-person insurance can protect the finances

Insurance can be appropriate where the loss of a particular individual could create a serious financial impact.

Business.gov.uk describes key-person insurance as cover against losses associated with a key individual becoming critically ill or dying where the business relies heavily on that person.

That can provide valuable money for things such as:

Recruitment.

Interim management.

Debt.

Lost profit.

Business stabilisation.

The exact cover, definitions, exclusions, tax treatment and structure require appropriate insurance and professional advice.

But understand what insurance cannot do.

Insurance cannot download someone's brain

A policy cannot:

Train their successor.

Explain the customer history.

Provide administrator access.

Take over the relationship.

Finish the technical project.

Lead the department.

Approve payroll.

Money buys time and options.

It does not remove operational dependency.

Treat key-person insurance as one layer.

Not the solution.

One of the best risk controls is testing the business without the person

Once you believe cover exists, test it.

Planned absence is ideal.

The key person takes leave.

They do not answer routine questions.

The deputy runs the process.

What happens?

Document:

What stopped?

What took much longer?

What information was missing?

What authority was unclear?

What customer became nervous?

What required emergency access?

Then improve the system.

Business-continuity guidance recommends exercising and reviewing continuity arrangements rather than assuming a written plan will work when required.

A continuity plan that has never been tested is a theory.

Start with a day, then a week

You do not need to simulate the CFO disappearing for six months next Tuesday.

Take stages.

Can somebody else run:

Payroll this month?

The management meeting?

The key customer review?

The pricing process?

The supplier order?

Then perhaps:

Two weeks of genuine holiday cover.

Confidence develops through use.

The business learns.

The successor learns.

The key person learns what they were still holding unnecessarily.

The key person must cooperate with reducing their own importance

This can become psychologically interesting.

Some people love being indispensable.

Not only owners.

Employees too.

They become:

The only person who knows.

The only person customers trust.

The only person allowed to touch the spreadsheet.

That indispensability can create:

Security.

Status.

Power.

Identity.

So documentation requests get delayed.

Cross-training never quite happens.

Knowledge remains guarded.

Managers need to be alert to this.

The conversation should not be:

“We're trying to make you replaceable.”

You are building:

Resilience.

Progression.

Holidays without interruption.

A stronger team.

An opportunity for the key person to move into more valuable work.

Nobody should need to remain operationally trapped in their current job to prove their worth.

Reward people for building capability beneath them

This matters.

A manager should not become less valued when their team needs them less for routine work.

That is backwards.

One sign of excellent management is:

Their people become stronger.

Knowledge spreads.

Decisions improve.

The department keeps running when they leave.

If your reward system celebrates heroic firefighting but ignores capability building, guess what managers will optimise for?

Heroics.

Beware the “hero employee”

Every company loves the person who saves the day.

System breaks?

They fix it.

Customer furious?

They rescue it.

Deadline impossible?

They stay until midnight.

Useful person.

But if the same hero repeatedly saves the same type of problem, investigate.

Why does the organisation keep requiring heroics?

A resilient business should increasingly convert hero knowledge into normal organisational capability.

Heroes are excellent during genuine emergencies.

They should not be the business model.

The owner's behaviour matters here too

You cannot tell managers:

“Make sure your teams don't depend on individuals”

while every manager depends on you.

Model it.

Take proper leave.

Transfer authority.

Share information.

Introduce other people into relationships.

Document important things.

Reduce your own Fixer Loop.

Article #78 asked whether you own a business or have built yourself a job.

Key-person resilience is one of the clearest ways of moving the answer towards:

Business.

Key-person risk affects growth

Imagine doubling the company.

One estimator currently produces every complex quote.

What happens?

They become twice as busy.

Eventually:

Delay.

Errors.

Bottleneck.

Recruit another salesperson if you like.

All that does is create more work for the estimator.

Scale-readiness Article #76 applies here.

Before increasing demand, find critical people whose capacity does not scale easily.

Build capability ahead of growth.

It also affects saleability

Potential buyers care about whether the company can continue after important people leave.

British Business Bank's current sale guidance explicitly warns that heavy reliance on the owner can make an exit less viable. The same commercial logic extends beyond the founder: a purchaser will care if crucial sales, customer, technical or operational capability is dangerously concentrated in individuals.

Ask:

What would a buyer worry about if they interviewed our management team tomorrow?

That is often a useful way to identify hidden dependencies.

A key-person register can be very simple

You do not need enterprise risk software.

For each critical role, capture:

Who is the key person?

What business capability depends on them?

What is the impact of 30 days' absence?

Who can currently cover?

How capable is that cover?

What knowledge needs transferring?

What access or authority needs addressing?

What relationships need widening?

What is the realistic replacement time?

What action are we taking?

Who owns the action?

When will we test it?

That is enough to turn:

“We'd be screwed if Jane left”

into something manageable.

Review it when the business changes

Key-person risk moves.

You recruit.

Promote.

Automate.

Lose employees.

Open locations.

Win major customers.

Introduce software.

Acquire companies.

Someone who was critical last year may no longer be.

Someone else may have quietly become indispensable.

CIPD's succession guidance stresses that planning needs to reflect both current critical roles and the capabilities the organisation will require as strategy evolves.

Review regularly.

Not only when somebody resigns.

A practical key-person risk audit

If I were doing this with an established small business, I would use five stages.

Stage 1: Identify

Ask managers:

Which individual's 30-day absence would create the most disruption?

Do not restrict them to senior people.

Compare the answers.

Stage 2: Diagnose

For each key person, identify the dependency:

Knowledge?

Capability?

Relationship?

Authority?

Access?

Capacity?

Leadership?

Most people will have more than one.

Stage 3: Prioritise

Which dependencies could materially affect:

Customers?

Revenue?

Cash?

Compliance?

Safety?

Business continuity?

Deal with those first.

Stage 4: Reduce

Choose the right intervention:

Document.

Cross-train.

Develop successor.

Spread relationships.

Change authority.

Fix access.

Automate.

Simplify.

Create external backup.

Insure financial exposure.

Stage 5: Test

Remove the person temporarily where practical.

See whether the solution works.

Then improve it.

That is key-person risk management.

Not a document.

A 90-day reduction plan

Do not attempt to remove every single dependency at once.

Pick perhaps your highest three.

For example:

Risk 1: Complex estimating depends on Technical Director

Over the next 90 days:

Second estimator shadows all complex quotes.

Pricing logic documented.

Second estimator independently prepares five quotes for review.

By quarter end, at least 60% of complex quotes can be produced without the Technical Director.

Risk 2: Largest customer relationship held only by owner

Over 90 days:

Operations Director attends account reviews.

Commercial history fully recorded.

Customer receives alternative senior contact.

Owner stops being default operational contact.

Risk 3: Payroll dependent on one Finance Manager

Over 90 days:

Deputy trained.

Process documented.

Required secure system access created.

Deputy runs one complete payroll cycle with Finance Manager observing.

Those are real outcomes.

Much better than:

“Improve business continuity.”

The goal is not to make talented people unimportant

This needs saying.

A brilliant employee should matter.

Their absence should be felt.

The company should miss:

Their judgement.

Experience.

Leadership.

Relationships.

Talent.

You are not trying to create a business where people are interchangeable cogs.

You are trying to create a business where one person's unexpected absence does not unnecessarily threaten everybody else's livelihood.

That is completely different.

The strongest people often become more valuable after dependency reduces

Once a key person is no longer spending half their week being the only person capable of performing routine critical work, they can often move upwards.

They can:

Develop others.

Improve systems.

Solve more difficult problems.

Lead.

Innovate.

Think.

The business gains resilience.

The employee gains room to grow.

That is an excellent outcome.

Key-person risk is often invisible precisely because the key person is so reliable

They never miss.

Never take much leave.

Always answer.

Always fix it.

So the company has no reason to discover how dependent it has become.

Until suddenly it does.

The reliable employee leaves.

The owner becomes ill.

The technical specialist retires.

Someone gets recruited by a competitor.

Then the business starts trying to transfer knowledge that is no longer sitting in the building.

Do not wait.

The best time to build redundancy is before it feels necessary

Find your critical people.

Understand what disappears with them.

Move important knowledge into the organisation.

Build another capable person.

Widen important relationships.

Create sensible authority.

Secure access without weakening security.

Develop future successors.

Insure the financial exposure where appropriate.

Test the arrangements.

Then repeat.

The objective is not a business without important people.

It is a business where important people have made the company stronger than their own availability.

That is what resilience looks like.

Something in your business needs to change?

You probably already know more than enough to keep reading about it.


If you want an experienced outside perspective to help you work out what’s really getting in the way — and what to do about it — let’s have a conversation.

Business owner adding another task to an already long handwritten to-do list outdoors
by Adam Fox • 6 October 2026
Your to-do list grows when commitments enter faster than they leave. Learn how to reduce workload using DROP, delegation, capacity and better weekly planning.
Small-business owner reviewing a marketing budget while real promotional activity is prepared
by Adam Fox • 6 October 2026
Forget generic percentage rules. Learn how to set a small-business marketing budget using growth targets, customer value, acquisition cost, cash and proven ROI.
Car-detailing team handling several vehicles while a manager checks inconsistent finish quality
by Adam Fox • 6 October 2026
Quality slipping as your business grows? Learn why founder oversight stops scaling and how better managers, training, feedback and systems restore standards.
Food-truck owner reviewing a weekly cash forecast before upcoming business costs and sales
by Adam Fox • 6 October 2026
Build a practical 13-week cash flow forecast showing weekly receipts, payments, cash balances and potential shortfalls before they become urgent problems.
Road worker redirecting a car that has bypassed an established roadworks diversion
by Adam Fox • 6 October 2026
Have processes but still spend every day firefighting? Learn why procedures fail under pressure and how to fix capacity, handoffs, ownership and management systems.
Art conservator focusing on one painting while other important works wait safely nearby
by Adam Fox • 6 October 2026
Too many business priorities? Learn how to choose strategic goals using constraints, commercial value, risk, leverage, sequencing and realistic resources.
Show More