A founder who can sell, solve, decide, reassure customers and keep the books moving may look like the company’s greatest strength. Often that is true. The same concentration of judgment, trust and energy can be what allows a young business to survive its first difficult years. It becomes a risk when the business cannot continue to perform its essential work if that person is suddenly unavailable.
Key-person risk is not an accusation that a founder has failed to delegate. It is the operating exposure created when revenue, authority, relationships, knowledge, approvals or system access depend on one individual. The risk can arise through illness, death, incapacity, burnout, a family emergency, a dispute, a planned exit, or simply a period in which the founder cannot be reached. In a sole proprietorship, the exposure is sharper because the owner and business are legally and operationally intertwined. In a founder-led company, the legal entity may survive, but customers, lenders, employees and suppliers can still experience the business as inseparable from its founder.
The practical question is this: if the founder were unavailable tomorrow, which work would stop today, fail at the next deadline or become difficult to recover within a month? A serious answer is more useful than a comforting one. It turns a vague concern about succession into a manageable set of decisions.
The problem is concentration, not personality
Every enterprise depends on people. That is normal. Key-person risk begins when a critical activity has one effective owner and no workable substitute. The activity may be visible, such as approving payments or making the final sales call. It may also be hidden, such as knowing the password manager’s recovery process, understanding a customer’s pricing history, maintaining relationships with a regulator, or remembering how a spreadsheet produces the monthly cash forecast.
The G20/OECD Principles of Corporate Governance frame succession planning as a board responsibility for the chief executive and, where relevant, other key executives in support of business continuity [1]. The principle is useful beyond listed companies. It identifies a basic governance duty: leadership continuity should be designed before an emergency forces a decision.
Why sole proprietorships deserve special attention
A sole proprietorship can be an efficient way to start a business. Decisions can be quick, customer relationships can be personal and the owner may understand every moving part. Those advantages can create a false sense of continuity. A customer may see a familiar trading name, but contracts, records, bank access, tax obligations, licences, intellectual property and decision authority may all remain tied to one person.
The risk is not limited to death. A temporary incapacity can create a more confusing situation because the business may need to continue while the owner cannot give instructions. Who can communicate with clients? Who can access the accounting system? Who can honour a payroll commitment? Who has authority to accept a delivery, approve a refund or respond to a regulator? If the answers are unclear, the business is exposed even when it has cash and demand.
A sole proprietor should therefore plan for two related events. The first is operational absence: somebody needs authority and information to keep essential functions going for a defined period. The second is ownership transition: the owner, family, executor, buyer or successor needs a documented route for transferring, winding down or selling the business. These are different plans. One keeps promises alive this week. The other determines what becomes of the enterprise over time.
The U.S. Small Business Administration’s business-management guidance makes the same practical connection [2]. It treats continuity planning as a way to reduce financial loss and emphasises documenting critical functions and processes, forming a continuity team and evaluating recovery strategies. It also treats ownership transfer and closure as management tasks that require a thorough plan.
Start with a dependency map
The best first step is not writing a long succession document. It is identifying where the business depends on one person. A dependency map names the critical activity, the person who currently performs it, the information or authority required, the acceptable interruption period and the backup arrangement.
| Critical activity | Current dependency | What a backup needs | Acceptable interruption |
|---|---|---|---|
| Customer commitments | Founder knows terms, exceptions and key contacts | Contract register, customer notes, contact protocol and authority limits | Same day for urgent accounts |
| Cash and payments | Founder controls banking and approvals | Dual authority, bank mandate, cash calendar and payment list | One to three business days |
| Payroll and tax filings | Founder or one bookkeeper knows the process | Payroll calendar, accountant contact and delegated access | Before the next statutory or payroll deadline |
| Sales pipeline | Founder owns relationships and pricing logic | CRM notes, account plans, price bands and named relationship owner | No interruption for active opportunities |
| Operations | Founder resolves exceptions | Procedures, supplier contacts, escalation thresholds and trained deputy | Depends on service-level commitment |
| Digital systems | Founder holds credentials and recovery codes | Password vault, administrator roles, recovery contacts and access log | Immediate for critical systems |
The map should be completed with the people who actually do the work. A founder may believe a process is documented because it is familiar. The team will reveal whether the document is current, accessible and sufficient for someone else to use without a phone call. The map also exposes misleading labels. “Finance” may mean one spreadsheet. “Operations” may mean a founder’s memory of which supplier is reliable. “Customer relationship” may mean one person’s mobile phone.
A business impact analysis helps prioritise this exercise. The National Institute of Standards and Technology (NIST) defines it as analysing operational functions and the effect of their disruption [3]. Its contingency-planning guidance recommends using the analysis to identify dependencies, recovery priorities and recovery-time objectives [4]. A small business does not need a complex enterprise framework. It does need to decide which activities must resume in hours, days or weeks, and what minimum resources allow that to happen.
Separate authority from access
Many continuity plans fail because they confuse access with authority. Giving a deputy a password is not the same as giving that deputy the legal or organisational authority to act. Conversely, an authorised signatory cannot help if they do not know which account, system, document or person they need.
This separation is especially important for money, contracts and data. Banking arrangements should identify who can view balances, prepare payments, approve payments and change mandates. A business should avoid creating a single unchecked path to cash, but it should also avoid creating a situation in which a legitimate payment cannot be made because the only approver is unavailable. The right design often uses limits, two-person approval above a threshold, an independent accountant or director, and a documented emergency escalation route.
The same logic applies to customer contracts. A deputy may be able to maintain an existing service commitment while a major price change, new long-term contract or asset sale requires a higher level of approval. Writing the boundaries down reduces both paralysis and opportunism during an absence.
Digital access is now part of governance. The owner of a small firm may hold the domain registrar login, email administrator account, accounting software credentials, cloud storage recovery key, payment gateway access and social-media accounts. If those credentials are scattered across personal devices, continuity depends on luck. Use a business-owned password manager, assign at least two controlled administrators, keep recovery contacts current and maintain an access register. The register should record the system, account owner, purpose, administrator, recovery method and review date. It should never expose passwords in a general operations manual.
Build deputies through real work
A named successor who has never done the work is a label, not a control. Deputies become credible when they perform the activity before a crisis. They should attend important customer reviews, approve a defined class of routine decision, run a monthly close, lead a supplier discussion or make a scheduled presentation while the founder is available to coach them.
This is not a demand that every job be duplicated fully. It is a deliberate choice about the few activities whose failure would harm customers, cash flow, compliance or safety. Some expertise can be bought from an outside accountant, lawyer, technology provider or interim executive. Other expertise must exist inside the business because response time and context matter.
The UK Financial Reporting Council’s Corporate Governance Code Guidance notes that over-reliance on one person is a risk and connects succession planning to talent development, mentoring and a written plan [5]. The scale of a sole proprietorship is different from that of a listed company, but the implication is the same: the replacement pipeline cannot be created on the day it is needed.
Treat customer relationships as business assets
Founder-led firms often have deep customer loyalty. That can be a competitive advantage. It becomes fragile if the relationship exists only in the founder’s head or private messages. Customers should know more than one competent person in the business. The second relationship should be authentic, not ceremonial. A deputy account lead should understand the customer’s goals, service history, commercial terms, open issues and decision process.
The same approach applies to suppliers, lenders, advisers and regulators. Create an up-to-date contact map, record contract dates and obligations, note any personal guarantees or renewal deadlines, and identify the person who should be contacted first during an interruption. The purpose is not to replace trust with a spreadsheet. It is to make trust usable by the organisation.
Make the continuity plan short enough to use
A plan that cannot be used under pressure is not a continuity plan. The useful version usually has a short first-response section and supporting schedules. The first section answers five questions: who declares an interruption, who leads the response, what must happen in the first hour, who must be notified and where the records are held. The schedules then provide the detail for banking, customers, payroll, systems, suppliers, insurance, legal advisers and key contracts.
UK government continuity guidance emphasises that planned continuity reassures staff, customers and suppliers [6]. NIST’s contingency-planning guide similarly links analysis to recovery priorities, communication and testing [4]. The shared lesson is that a plan should not sit in a drawer. It should be reviewed, practised and changed when the business changes.
A modest annual exercise is enough to expose most weaknesses. Ask the deputy to run a week without founder intervention. Simulate an unavailable email account. Test whether the payroll provider will accept a valid instruction from the designated person. Restore a document from the backup. Call a customer using the documented account brief. Compare what happened with the plan, then improve the plan. This is not theatre. It is evidence that the business can keep its promises.
Govern the founder’s exit without making it personal
Key-person planning is sometimes resisted because it can feel like planning a founder out of their own company. That reaction is understandable. The better framing is stewardship. The founder is protecting employees, customers, family, co-owners and their own legacy by ensuring that the enterprise can honour commitments through a period of change.
A founder-led company should agree in advance how leadership decisions will be made if the founder is absent. If there is a board, advisory board or investor group, specify its role in naming an interim leader, communicating with stakeholders and approving significant actions. If there is no board, establish a small external continuity group that could include a trusted adviser, accountant and independent business leader. Its authority should be limited, written and proportionate to the company’s size.
Ownership arrangements deserve equal clarity. Shareholder agreements, buy-sell terms, insurance, powers of attorney, wills, employment contracts, director appointments and bank mandates must fit together. No general article can determine the right legal documents for every jurisdiction or family situation. The leadership responsibility is to identify the decisions early and obtain the appropriate professional advice before an emergency makes choices irreversible.
The U.S. Internal Revenue Service’s successor and predecessor reporting guidance illustrates the administrative dimension of a transition: even where a successor continues a business, information-reporting responsibilities need explicit treatment [7]. That is a useful reminder beyond the U.S. A continuity plan must address the less visible obligations that keep an enterprise legitimate, such as records, payroll, tax filings, licences, insurance and regulatory communications.
A ninety-day resilience programme
The work can begin without a large budget. The following sequence is practical for many sole proprietorships and founder-led firms.
| Period | Leadership action | Evidence of progress |
|---|---|---|
| Days 1 to 30 | Create the dependency map; identify the ten most critical activities; name provisional deputies; collect contracts, credentials and contact lists | A signed list of critical functions, owners, backups and interruption targets |
| Days 31 to 60 | Set access and authority rules; move credentials into a business-owned vault; document cash, payroll and customer procedures; begin cross-training | Tested access records, delegated approval limits and procedures another person can follow |
| Days 61 to 90 | Run a simulated absence; review gaps with advisers; complete succession and continuity documents; set quarterly review dates | Exercise record, amended plan, communication list and board or owner review |
The programme should remain proportionate. A five-person professional firm does not need the same machinery as a regulated bank. It does need a clear answer for client communication, delivery commitments, cash, records, technology and ownership decisions. A larger founder-led business will need deeper delegation, board oversight, management succession and formal control testing.
The leadership outcome
The goal is not to make the founder irrelevant. Great founders remain valuable because they set direction, attract talent, understand customers and make hard calls. The goal is to ensure that the company is valuable in a way that outlasts any one person’s availability.
A resilient business gives employees confidence that their jobs and work have continuity. It gives customers confidence that service is institutional rather than personal whim. It gives lenders and investors a clearer view of operational risk. It gives the founder a business that can take leave, absorb a shock, attract a successor and eventually be transferred with less disruption.
Key-person risk is therefore a leadership test. The founder who builds a capable second line, documents critical work, separates authority from access, tests continuity and plans for succession has not surrendered control. They have converted personal control into organisational strength.
References
[1] Organisation for Economic Co-operation and Development, G20/OECD Principles of Corporate Governance 2023. Paris, France: OECD Publishing, 2023. [Online]. Available: https://www.oecd.org/en/publications/g20-oecd-principles-of-corporate-governance-2023_ed750b30-en/full-report/component-8.html. [Accessed: Sep. 13, 2026].
[2] U.S. Small Business Administration, “Manage your business.” [Online]. Available: https://www.sba.gov/counseling/manage-your-business/. [Accessed: Sep. 13, 2026].
[3] National Institute of Standards and Technology, “Business impact analysis,” Computer Security Resource Center Glossary. [Online]. Available: https://csrc.nist.gov/glossary/term/business_impact_analysis. [Accessed: Sep. 13, 2026].
[4] M. Swanson, P. Bowen, A. Phillips, D. Gallup, and D. Lynes, Contingency Planning Guide for Federal Information Systems, NIST Special Publication 800-34 Rev. 1, May 2010. [Online]. Available: https://csrc.nist.gov/pubs/sp/800/34/r1/upd1/final. [Accessed: Sep. 13, 2026].
[5] Financial Reporting Council, UK Corporate Governance Code Guidance. London, U.K.: Financial Reporting Council. [Online]. Available: https://www.frc.org.uk/library/standards-codes-policy/corporate-governance/corporate-governance-code-guidance/. [Accessed: Sep. 13, 2026].
[6] U.K. Government, Expecting the Unexpected: Business Continuity in an Uncertain World. [Online]. Available: https://www.gov.uk/government/publications/expecting-the-unexpected. [Accessed: Sep. 13, 2026].
[7] Internal Revenue Service, General Instructions for Certain Information Returns, Publication 1099. [Online]. Available: https://www.irs.gov/publications/p1099. [Accessed: Sep. 13, 2026].
No public comments yet. The first thoughtful question can start the discussion.