Key-Person Risk
What is key-person risk?
Key-person risk is the exposure an organisation carries when a critical process, decision or body of knowledge depends on one individual — so that their absence, departure or overload directly threatens output. It is the business-risk view of a bus factor of 1: the bus factor counts the people, key-person risk describes the consequence.
What does key-person risk look like in operations?
The symptoms are mundane, which is why the risk stays invisible until it triggers: approvals that queue behind one calendar; a release decision only one person is trusted to make; the "just ask Maria" step in an otherwise documented process; a two-week task that takes two months when its owner is on leave; an onboarding plan whose real content is "shadow the expert until it clicks". In regulated environments the consequences escalate from delay to compliance exposure — a deviation that cannot be closed or a batch that cannot be released is a finding waiting to happen.
How is key-person risk measured?
Asking "who are your key people?" measures reputation, not risk. The HDI methodology measures it behaviourally: for each process, what actually happens during an absence — documented backup, partial cover, slow-down, or full stop — plus how concentrated approvals are and how much critical knowledge is undocumented. The result locates key-person risk per process rather than per personality, which is what makes it fixable: the goal is never to replace the key person, but to stop the process depending on any single person.
Related terms
- Bus factor — the headcount view of the same exposure.
- Cognitive dependency — knowledge that exists only in someone's head.
- Operational leak — the monthly hours dependency consumes.