brainis
Business Strategyai-automationoperationsrisk

Business Continuity for Small Companies: The Bus Factor Problem

The realistic risk is not a disaster. It is one person leaving with knowledge nobody else has.

B
Brainis Team
August 14, 20263 min read · 595 words

Small companies plan for fires and outages and rarely plan for the far more likely event: the person who knows how something works is unavailable.

What you'll learn
  • Finding your single points of failure
  • The four things to fix first
  • What to document versus what to systematize
  • A quarterly check

Finding the single points of failure

Ask three questions about every critical function:

1
Who is the only person who can do this?
2
What would we not be able to do next week if they were unavailable?
3
Where does this knowledge live outside their head?

Common answers in small companies: the person who runs payroll, the one who knows the deployment process, the founder who holds every customer relationship, the one who understands the spreadsheet everything depends on.

The four to fix first

Access and credentials. If one person holds the only access to a critical account, that is a bus factor of one and it is the easiest to fix. Use a shared password manager with documented ownership and a break-glass procedure.

Financial operations. Payment authorization, banking access, and payroll execution. There should be a documented second person, and they should have done it once.

Customer relationships. Every significant customer should know at least two people at your company. This also improves retention independently.

Systems and processes nobody else has run. The deploy, the close, the renewal process. The test is not whether it is documented; it is whether someone else has actually done it.

Document versus systematize

Systematize anything that recurs. A process in a system, with owners and steps, survives a departure. A process in someone's head does not, and a process in a document sits between the two.

Document the judgment: why things are done this way, what the exceptions are, what went wrong last time. This is the part systems cannot hold. See the company brain.

The test for documentation quality: could someone competent but unfamiliar do this from what is written? Most process documentation fails that test because it was written by someone who already knew.

Tip: Run the check by having the second person actually do the thing once, with the primary watching. Documentation that has never been executed by a second person is a hypothesis.

A quarterly check

Fifteen minutes, four questions:

1
What is the current bus factor on each critical function?
2
Has anything become single-threaded since last quarter? (New processes default to bus factor one.)
3
Are credentials and access still correctly held?
4
Has the second person for financial operations changed?

What this is not

Not a disaster recovery plan, and not a compliance exercise. A 30-person company writing a 40-page continuity document is doing the wrong version of this. The useful version is a short list of single points of failure with a plan for each.

FAQ

What about the founder?

The hardest case, and the most important one for anything involving the company's survival: banking, legal, and key relationships. At minimum, ensure someone else can access what would be needed.

How much documentation is enough?

Enough that someone competent could continue. Perfect documentation is a project that never finishes; adequate documentation of the top five risks takes an afternoon.

Does this matter before we are profitable?

More, not less. A small company has less slack to absorb a key departure.

Brainis keeps processes, decisions, and institutional knowledge in one system with permissions, so continuity is a property of the setup rather than of one person. See pricing.

ai-automationoperationsrisk
B
Brainis Team

Sharing insights on business operations, AI, and modern team management.

Run your company on Brainis

All 11 Operating Systems on every plan, from $29 a month. No per-seat pricing — you pay for AI capacity, not headcount.

See pricing