August 25, 2026

A key person risk map identifies where knowledge and activity are concentrated in a single individual — the one person who touches a given client, system, document set or recurring obligation — by deriving it from real activity data rather than from organisational charts or manager intuition.

Why intuition gets this wrong

Managers assess key person risk by seniority and visibility. Both are poor proxies. The genuinely concentrated roles tend to be invisible by construction — someone builds a reliable routine, it stops generating problems, and it disappears from management attention entirely, right up until the person who maintains it leaves.

What the map is derived from

Sole authorship or editing of a document set over time, sole correspondence with a client or supplier, sole approver of a recurring item, only holder of an access right or licence, the person consistently asked in threads about a topic, and sole author of an internal tool or script still in use — the last of which is a recurring surprise.

What the output should look like

A ranked register: the area (client, system, obligation, or body of knowledge), the individual by role, the evidence, impact if unavailable, substitutability, and remediation (pairing, documentation, cross-training, or access redistribution). Weight by impact and speed of failure, not raw exclusivity.

Handling this without damaging trust

Announce it before it runs. Report at role level, not performance level. Attach it to remediation, not review. Treat the finding as a compliment — you have become indispensable and we need to fix that for your sake as well as ours.

FAQs

How often should the map be refreshed?
Doesn't cross-training solve this without the analysis?
Does this need access to message content?
What if the concentration is the founder?

Contact us

Subscribe to our newsletter

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.