Key Person Dependency in Finance: The Control Risk That Boards Routinely Underestimate
When critical finance knowledge sits with one person, the risk is not just operational — it is a governance and audit concern that investors take seriously.
Most boards understand key person risk in theory. They discuss it in the context of the CEO, the top salesperson, the lead developer. They sometimes have insurance against it. They may even have a succession plan, or at least the intention of one.
What boards are less likely to discuss is key person risk in the finance function — and in particular, the specific and serious control risk that arises when critical financial knowledge, access and process execution sit almost entirely with one individual.
This is one of the most common and most underestimated risks in PE-backed SME finance. It is also one of the most readily identifiable, once you know what to look for.
What key person dependency looks like in finance
In a well-controlled finance function, processes are documented, access is role-based and any sufficiently trained person in the relevant role could, with a reasonable handover period, pick up the work. In a key-person-dependent finance function, this is not true — because the process exists in someone's head, the access is personal to them, and the institutional knowledge required to reconstruct what they know is not captured anywhere.
The most common version of this is a Finance Director or Financial Controller who has been in the role for a long time, has built the systems and processes from scratch, and is the only person who fully understands how everything fits together. They know which supplier balances to watch, which recurring journal entries are non-obvious, which reconciliations have an unusual treatment and why, and which numbers the board cares about most. They are excellent at their job. And the business is, without fully realising it, highly dependent on their continued presence and availability.
A less common but equally significant version involves IT or systems access that has accumulated in one person's hands — a financial system administrator who is also a member of the finance team, with a level of combined access that would be difficult to reconstruct if they left, and which has never been formally reviewed.
Why this matters to auditors and investors
From an audit perspective, key person dependency creates two related concerns. The first is about controls: if the only person who performs a particular control is unavailable, does the control operate or does it simply not happen? Controls that depend on a specific individual rather than a documented process and a role are fragile controls, and auditors will assess them accordingly.
The second is about evidence: if the knowledge required to explain a balance, a treatment or a transaction is held only by one person, and that person is unavailable during fieldwork — through illness, holiday or departure — the audit is slowed and sometimes stalled. Auditors are not unsympathetic to this, but it affects their assessment of the control environment and it affects timetables.
From an investor perspective, key person dependency in finance is a value risk. If the person who knows how the business works financially leaves, the cost of replacing that knowledge — through recruitment, through transition time, through the errors and inefficiencies of a new hire getting up to speed — is real and sometimes substantial. In transaction contexts, it is also a due diligence concern: a business where the CFO or FD cannot be adequately replaced within a reasonable period is a business with an embedded fragility that sophisticated buyers will price.
Where the dependency typically sits
The areas where key person dependency most commonly creates control risk in SME finance functions are worth naming specifically.
The month-end close is the most frequent. In many businesses, the close process is understood and managed by one person, with other team members performing discrete tasks within it. If that person is absent, the close does not happen as it should — because no one else has the full picture.
Journal entry and adjustment decisions are another. The non-standard journals — the accruals that require judgement, the provisions that depend on business knowledge, the allocations that reflect an understanding of how costs should be treated — often depend on a single person knowing what to do and why. These decisions are rarely documented in a way that would allow someone else to replicate them.
Relationships with external parties are a third. The audit relationship, the banking relationship, the relationship with the company's tax advisers — these often sit with one person. When that person leaves, the institutional context of those relationships goes with them, and rebuilding it takes time that the business usually does not have.
System access and administration is the fourth. Where the most senior finance person also has the highest level of system access, and where that access has never been formally reviewed against a role-based framework, their departure can create both an operational gap and a control gap simultaneously.
What good governance looks like
Addressing key person dependency in finance does not require a large team. It requires deliberate design. The starting point is documentation: every significant process in the finance function should be described in enough detail that a competent professional could follow it. This does not mean exhaustive manuals — it means a clear enough description of the steps, the decisions involved and the supporting references that continuity is possible.
The second element is access design. Financial system access should be role-based, reviewed periodically and not bundled with administrative rights unless there is a clear reason. Where one person holds a combination of access that creates both operational capability and the ability to override controls, that is a segregation of duty risk that needs to be addressed — either by separating the access or by implementing compensating controls that provide independent oversight.
The third element is cross-training. The finance team does not need to be interchangeable, but the most critical activities — those that would stall if one person were absent — should have a designated backup who understands the process and has performed it, at least occasionally, under supervision.
The fourth element is an honest conversation at board level. Key person dependency in finance is a board-level risk. It should be named in the risk register, owned by someone at executive level and reviewed annually. Boards that treat it as an operational matter for the FD to sort out are delegating a governance responsibility they should be holding.
The businesses that handle this well are the ones where the finance function could survive the departure of its most senior member without a governance crisis. That is a higher standard than most PE-backed SMEs currently meet — but it is the right one to aim for.
