Key-person dependency and Basel execution, delivery, and process-management…
Key-person dependency and Basel execution, delivery, and process-management risk linkage
- Basel Committee on Banking Supervision guidance supports classifying key-person dependency as operational risk because a process that depends on one indispensable person's availability or tacit knowledge fits the published definition of loss arising from failed people, processes, and systemsSupervision (2021)
- The Basel loss-event type "Execution, Delivery & Process Management" is the closest specific event classification when the dependency threatens transaction capture, execution, maintenance, deadlines, responsibilities, reconciliations, handoffs, or delivery steps, because the published category explicitly covers failed transaction processing and process managementSupervision (2001)
- A workforce-critical key-person dependency should be escalated into operational-resilience reporting when the person's absence could disrupt a critical operation, because banks are required to map people, technology, processes, information, facilities, and their interdependencies against tolerance for disruptionSupervision (2021)
- Basel Committee on Banking Supervision guidance expects business-continuity planning to address disruption that impacts key personnel and to define internal decision-making and invocation triggers, which makes a single-person bottleneck in a critical process a continuity-planning issue rather than only an informal staffing noteSupervision (2021)
- When the same key-person dependency controls manual spreadsheets, desktop databases, or similar workflows used for risk aggregation or risk reporting, Basel Committee on Banking Supervision 239 adds a second supervisory concern because the framework requires largely automated aggregation and effective mitigants over manual desktop applicationsSupervision (2013)
- Escalation becomes strongest once the dependency can cause missed responsibility, task misperformance, delivery failure, business-continuity invocation, or inaccurate, incomplete, or untimely risk dataSupervision (2001)Supervision (2021)Supervision (2013)
- Basel-compatible reporting should therefore describe key-person dependency as a causal concentration in process execution and then add the relevant Basel surface labels, instead of treating it as a generic human-resources issue with no explicit operational-risk taxonomySupervision (2021)Supervision (2001)Supervision (2021)Supervision (2013)Mitchell (2026)
Research Question
How should key-person dependency in workforce-critical processes be mapped to execution, delivery, and process-management risk categories in Basel Committee framing?
Findings
Executive Summary
Key-person dependency in a workforce-critical process should be classified first as Basel Committee on Banking Supervision operational risk, and then mapped specifically to "Execution, Delivery & Process Management" when the dependency threatens recurring process execution, handoffs, deadlines, or delivery outcomes. The same dependency should be escalated into operational-resilience reporting when the person's unavailability could disrupt a critical operation, because Basel Committee on Banking Supervision guidance requires banks to map people, processes, information, technology, facilities, and their interdependencies against tolerance for disruption and business-continuity triggers. If the dependency also sits inside manual spreadsheet or desktop-database production of risk data or risk reports, Basel Committee on Banking Supervision 239 adds a separate classification as a risk-data-aggregation, automation, and control weakness requiring effective mitigants or more automated design. The strongest Basel-compatible reporting pattern is therefore to write key-person dependency as a causal driver and then name the activated Basel surface or surfaces: base operational risk, execution-delivery-process-management event risk, operational-resilience dependency risk, and Basel Committee on Banking Supervision 239 control weakness where applicable.
Key Findings
- Basel Committee on Banking Supervision guidance supports classifying key-person dependency as operational risk because a process that depends on one indispensable person's availability or tacit knowledge fits the published definition of loss arising from failed people, processes, and systems.
- The Basel loss-event type "Execution, Delivery & Process Management" is the closest specific event classification when the dependency threatens transaction capture, execution, maintenance, deadlines, responsibilities, reconciliations, handoffs, or delivery steps, because the published category explicitly covers failed transaction processing and process management.
- A workforce-critical key-person dependency should be escalated into operational-resilience reporting when the person's absence could disrupt a critical operation, because banks are required to map people, technology, processes, information, facilities, and their interdependencies against tolerance for disruption.
- Basel Committee on Banking Supervision guidance expects business-continuity planning to address disruption that impacts key personnel and to define internal decision-making and invocation triggers, which makes a single-person bottleneck in a critical process a continuity-planning issue rather than only an informal staffing note.
- When the same key-person dependency controls manual spreadsheets, desktop databases, or similar workflows used for risk aggregation or risk reporting, Basel Committee on Banking Supervision 239 adds a second supervisory concern because the framework requires largely automated aggregation and effective mitigants over manual desktop applications.
- Escalation becomes strongest once the dependency can cause missed responsibility, task misperformance, delivery failure, business-continuity invocation, or inaccurate, incomplete, or untimely risk data.
- Basel-compatible reporting should therefore describe key-person dependency as a causal concentration in process execution and then add the relevant Basel surface labels, instead of treating it as a generic human-resources issue with no explicit operational-risk taxonomy.
Assumptions
- The process is assumed to be material to operational delivery, control execution, or risk reporting; if it were not material, Basel classification would still indicate weak control design but would not necessarily trigger resilience or Basel Committee on Banking Supervision 239 escalation.
Analysis
| Condition | Basel-compatible classification | Main control surface | Source |
|---|---|---|---|
| Single-person dependency exists in a material process, even before disruption occurs. | [inference] Operational risk driven by concentrated people-process dependency. | process design, role concentration, control ownership | Basel Committee on Banking Supervision (2021) Revisions to the Principles for the Sound Management of Operational Risk |
| The dependency threatens recurring execution quality, deadlines, handoffs, reconciliations, or delivery steps. | [inference] Execution, Delivery & Process Management loss-event exposure. | transaction processing, process management, task performance | Basel Committee on Banking Supervision (2001) Operational Risk Loss Data |
| The dependency can interrupt a critical operation if the individual is unavailable. | [inference] Operational-resilience dependency and business-continuity issue. | critical-operation mapping, tolerance for disruption, key-person continuity | Basel Committee on Banking Supervision (2021) Principles for operational resilience |
| The dependency controls manual risk-data or risk-reporting workflows in spreadsheets or desktop databases. | [inference] Basel Committee on Banking Supervision 239 risk-data aggregation and control weakness. | automation, spreadsheet control, manual-process mitigants | Basel Committee on Banking Supervision (2013) Principles for effective risk data aggregation and risk reporting |
Basel Committee on Banking Supervision operational-risk guidance was weighted first because it answers the threshold question of whether key-person dependency is a prudentially relevant risk at all. The loss-event classification note was weighted next because it provides the most specific Basel wording for execution-facing manifestations of the dependency, even though it is older than the 2021 principles documents. The strongest rival interpretation is that key-person dependency should stay in human-resources language unless a loss already occurred, but Basel Committee on Banking Supervision resilience and risk-data guidance reject that narrow view by requiring advance mapping, trigger definition, and control treatment before disruption or reporting failure crystallizes.
Risks, Gaps, and Uncertainties
- Basel Committee on Banking Supervision does not publish a dedicated named "key-person dependency" event type, so the item's mapping remains an inference from the published operational-risk, loss-event, resilience, and risk-data texts rather than from one source that states the full conclusion directly.
- The "Execution, Delivery & Process Management" wording is drawn from a 2001 Basel Committee on Banking Supervision operational-risk classification note rather than from the 2021 principles documents.
- The exact escalation threshold still depends on materiality, because the sources define critical operations, tolerance for disruption, and risk-data quality obligations, but they do not publish a universal numeric threshold for when every single-person dependency becomes reportable.
Open Questions
- What internal taxonomies do large banks currently use to distinguish between latent key-person concentration and already material execution-process dependency in operational-risk registers?
- Which testing methods best demonstrate that a documented backup or alternate operator is sufficient to keep a critical operation inside tolerance for disruption?
- How should Basel-compatible reporting language change when the dependency is concentrated in an external vendor specialist rather than in an internal employee?
sources
- [x] Basel Committee on Banking Supervision (2021) Revisions to the Principles for the Sound Management of Operational Risk - core operational-risk definition and governance expectations
- [x] Basel Committee on Banking Supervision (2021) Principles for operational resilience - critical-operations dependency mapping, tolerance for disruption, and business-continuity triggers
- [x] Basel Committee on Banking Supervision (2013) Principles for effective risk data aggregation and risk reporting - automation, spreadsheet, database, and control expectations
- [x] Basel Committee on Banking Supervision (2001) Operational Risk Loss Data - Basel loss-event type wording for execution, delivery, and process management
- [x] Mitchell (2026) Basel Committee on Banking Supervision (BCBS), International Organization for Standardization (ISO), and National Institute of Standards and Technology (NIST): classifying shadow workforce-system risk - adjacent completed item on framework-level shadow-workforce classification