
By Vincent Howard, CPA | Managing Partner, Howard, Howard and Hodges | SkillAbility for Accounting Firms
Last updated: July 20, 2026 | 24-minute read
- What key-person risk means in a CPA firm
- Why firms should assess risk before busy season
- What qualifies as a single point of failure
- Seven key-person risk areas
- The eight-step assessment process
- The 100-point inherent-risk score
- The 25-point control-strength score
- How to calculate residual key-person risk
- Copy-and-use risk assessment template
- Questions to ask process owners and backups
- How to test whether the risk is actually controlled
- Completed CPA firm example
- Risk-treatment options
- A 90-day pre–busy season plan
- Security, access, and separation-of-duties issues
- What the firm should measure
Busy season does not create single points of failure.
It exposes them.
A tax manager becomes unavailable, and no one else can review a group of complex business returns.
A partner owns the history, expectations, and trust of several major clients, but the rest of the firm knows only the current engagement tasks.
An operations employee is the only person who understands the exact sequence for setting up engagements, monitoring filing acknowledgments, resolving workflow exceptions, and confirming that deadlines were completed.
A senior accountant knows why one client’s monthly close is handled differently, but the reasoning is not documented anywhere.
A technology administrator controls a critical integration, and no one has confirmed whether another authorized person can restore access or continue the process.
The firm may operate this way for years without an obvious failure.
The expert remains available. The partner answers the call. The manager clears the issue. The administrator remembers the password-reset path. The senior recognizes the unusual fact.
Availability hides dependency.
Then illness, resignation, retirement, family emergency, vacation, promotion, overload, cyber incident, or a deadline collision removes the person from the workflow.
The work does not disappear.
The client expectation does not disappear.
The filing obligation does not disappear.
Key-person risk is not a judgment about whether an employee is replaceable. It is an operating-risk question: can the firm continue the critical responsibility safely, securely, and at an acceptable level when the primary person is unavailable?
This article gives CPA firms a structured way to find those dependencies, score the exposure, test the existing controls, and prioritize action before busy-season workload makes knowledge transfer and backup development much harder.
Who I Am and Why This Matters
I have practiced public accounting since 1990. I founded my accounting firm in 1993, merged it in 2001 to form Howard, Howard and Hodges, and helped grow the organization from three people to approximately 50 staff across four locations and multiple states. Our firm was named PASBA Firm of the Year in 2015.
In a small firm, concentration often feels efficient.
One person becomes very good at a client, service, system, or process. Questions go to the same expert. Work moves quickly because that person understands the history and can make decisions without rebuilding context.
That efficiency can become fragility.
The more often the expert rescues the workflow, the less pressure the firm feels to transfer the knowledge. Other employees may learn pieces of the task but not the full responsibility. Documentation describes the normal steps but not the exceptions. A backup has access but not judgment. A second relationship contact attends meetings but cannot lead the conversation.
The organization chart shows coverage.
The work still depends on one person.
Since 2020, I have built and run the SkillAbility accounting workforce development platform used by more than 1,000 accounting professionals across dozens of PASBA firms. That experience has reinforced a practical lesson:
Risk is reduced only when another qualified person can carry a clearly defined responsibility at an approved level—not when someone else has merely seen the work.
Why CPA Firms Should Assess Key-Person Risk Before Busy Season
The accounting workforce continues to move through promotions, job changes, leave, retirement, and changing responsibilities.
The U.S. Bureau of Labor Statistics reports 1,579,800 accountant and auditor jobs in 2024 and projects approximately 124,200 openings per year from 2024 through 2034. Many openings are expected to result from people transferring to other occupations or leaving the labor force, including retirement.
BLS also notes that longer hours are typical during tax season and other deadline-heavy periods. At the same time, automation is expected to make analytical, advisory, and judgment-based responsibilities more prominent.
Firms Need Reliable Coverage While People and Work Continue Moving
Source: U.S. Bureau of Labor Statistics, Occupational Outlook Handbook.
The AICPA PCPS CPA Firm Competency Model, updated in October 2025, defines productivity, technical knowledge, client service, people development and teamwork, business development, and culture and inclusion across associate through partner roles.
That role-based structure matters because backup coverage should be based on demonstrated competency, not title proximity.
A senior may be able to prepare a complex engagement without being ready to approve it. A manager may understand the technical issue without holding the client relationship. An administrator may know the process but lack the required system authority. A partner may know the relationship but not the daily workflow.
Continuity should be managed as a system
ISO 22301:2019 remains the published international standard for business continuity management systems as of July 2026, with a replacement edition under development. It emphasizes planning, implementing, monitoring, reviewing, maintaining, and continually improving an organization’s ability to continue through disruption.
ISO 30401:2018 remains the published knowledge-management systems standard while a replacement draft proceeds through development. Its central principle is equally relevant: organizational knowledge must be established, maintained, reviewed, and improved.
A CPA firm does not need ISO certification to apply the practical lesson:
Continuity and knowledge transfer are ongoing management responsibilities—not one-time documents created after a resignation notice.
What Is Key-Person Risk in a CPA Firm?
Key-person risk in a CPA firm is the risk that a critical business result cannot continue safely, securely, accurately, or on time because the required knowledge, authority, access, relationship, or judgment is concentrated in one person.
A key-person risk assessment should identify:
- The critical responsibility
- The business result it protects
- The primary owner
- The exact dependency
- The impact if the person is unavailable
- The time available to recover
- The current backup capability
- The documentation, access, and relationship controls
- The residual risk after those controls
- The treatment owner and deadline
The assessment is about responsibilities, not a list of “important employees.”
One employee may own several high-risk responsibilities. Another highly valued employee may perform work that has strong redundancy and therefore creates lower continuity risk.
What Qualifies as a Single Point of Failure?
A responsibility is a single point of failure when one person’s absence causes the firm to lose one or more of the following:
- Required technical capability
- Final review or approval authority
- Access to a system, record, account, or workflow
- Knowledge of the process and exceptions
- Client trust, history, or communication continuity
- Control of a deadline or required handoff
- Ability to make a material business decision
A named backup does not automatically remove the risk
The backup may:
- Know the normal steps but not the exceptions
- Have observed the work but never completed it
- Be able to prepare but not review or approve
- Lack access to the required system
- Be assigned to the same deadline conflict
- Depend on the primary owner for answers
- Know the file but not the client relationship
Documentation alone does not automatically remove the risk
A procedure may be:
- Outdated
- Difficult to find
- Missing decision rules
- Disconnected from live systems
- Written by the expert but never tested by another user
Use the Accounting Firm SOP Template to build living workflow documentation rather than a dead manual.
Seven Key-Person Risk Areas in CPA Firms
Clients → Technical Work → Review → Workflow → Systems → Operations → Leadership
History, trust, commitments, communication preferences, scope sensitivities, and revenue concentration.
Specialized tax, audit, accounting, industry, advisory, technology, valuation, or planning judgment.
Authority and capability to evaluate, conclude, approve, sign, release, or escalate work.
Sequencing, status knowledge, handoffs, filing acknowledgments, exceptions, and deadline ownership.
Administrative credentials, integrations, permissions, secure data locations, recovery procedures, and vendor contacts.
Billing, collections, payroll, HR, insurance, banking, vendor management, facilities, and compliance administration.
Pricing, staffing, client acceptance, risk decisions, conflict resolution, strategy, governance, and succession.
1. Client relationship risk
Ask whether more than one person understands:
- The client’s business and decision makers
- Prior commitments and unresolved concerns
- Communication style and expectations
- Scope and pricing history
- Relationship risks and opportunities
2. Technical knowledge risk
Identify work where only one person can recognize the issue, research the answer, evaluate alternatives, or support the conclusion.
3. Review and approval risk
A firm may have several preparers and only one qualified reviewer. This is often the highest busy-season constraint.
4. Workflow and deadline risk
Look for processes that depend on one person’s memory rather than visible status, documented ownership, and tested handoffs.
5. System and access risk
Find systems where only one employee can administer users, restore access, operate an integration, retrieve records, contact the vendor, or complete a required secure workflow.
6. Operational risk
Administrative processes can stop production as quickly as technical issues.
7. Leadership and decision risk
Identify decisions that stop when one partner or executive is unavailable. Some decisions should remain concentrated; the firm still needs emergency authority, documented limits, and an escalation path.
The Eight-Step Key-Person Risk Assessment Process
Step 1: Identify critical business results
Start with outcomes the firm cannot allow to stop:
- Meeting filing and reporting deadlines
- Completing substantive review
- Maintaining key client relationships
- Protecting confidential information
- Processing payroll and firm obligations
- Maintaining access to critical systems
- Making time-sensitive operating decisions
Step 2: Break each result into responsibilities
“Tax department” is too broad.
Define the actual responsibility:
- Final review of multistate business returns
- Resolution of rejected electronic filings
- Communication with the firm’s ten largest CAS clients
- Approval of client acceptance exceptions
- Administration of the document-management platform
Step 3: Identify the primary owner and dependencies
Document where knowledge, authority, access, and relationships sit.
Step 4: Assess business impact
Estimate the client, deadline, quality, security, revenue, legal, regulatory, reputation, and employee consequences.
Step 5: Evaluate current controls
Do not assume a control works because it exists on paper.
Step 6: Calculate residual risk
Compare inherent risk with the strength of existing coverage.
Step 7: Select treatment and owner
Assign a specific action, responsible person, required evidence, and completion date.
Step 8: Test and maintain
Repeat the assessment when roles, clients, systems, standards, or business priorities change.
The 100-Point Inherent Key-Person Risk Score
Score each factor from 0 to 5, then multiply by the assigned weight.
| Risk Factor | Weight | 0–1: Lower Exposure | 4–5: Severe Exposure |
|---|---|---|---|
| Business impact | 30% | Minor inconvenience or easily deferred internal work | Major client, deadline, financial, security, compliance, or reputation consequence |
| Knowledge and judgment concentration | 20% | Several people understand normal and exceptional cases | One person holds essential technical or contextual judgment |
| Authority and access concentration | 15% | Authorized alternatives exist and have tested access | Only one person can approve, administer, release, or retrieve what is required |
| Client or stakeholder concentration | 15% | Several informed relationship contacts exist | Trust, history, commitments, or communication depend on one person |
| Deadline and timing sensitivity | 10% | Flexible timing and long recovery window | Immediate, high-volume, sequential, or immovable deadline |
| Recovery difficulty | 10% | Responsibility can be restored quickly from current records and available talent | Recovery requires rare expertise, unavailable history, new authority, or lengthy reconstruction |
The result ranges from 0 to 100.
Suggested inherent-risk bands
- 75–100: Critical dependency
- 50–74: High dependency
- 25–49: Moderate dependency
- 0–24: Lower dependency
A lower score does not mean the work is unimportant. It means the responsibility is less concentrated or easier to recover.
The 25-Point Control-Strength Score
Score each control from 0 to 5.
| Control | 0 Points | 5 Points |
|---|---|---|
| Qualified backup capability | No named or capable backup | Backup independently performs the approved scope |
| Current documentation and knowledge | Knowledge exists mainly in memory | Current workflow, exceptions, decisions, sources, and contacts are findable and tested |
| Secure access and authority | Backup lacks access or proper authority | Role-based access and emergency authority are approved, current, secure, and tested |
| Relationship and communication continuity | Client or stakeholder knows only the primary owner | Backup has context, credibility, participation, and an approved communication role |
| Independent validation and maintenance | No test, drill, or current review | Coverage has passed a realistic independent test and has an update schedule |
A person who attended a walkthrough may score one or two points for familiarity.
A backup who independently performs the work, recognizes exceptions, protects data, communicates appropriately, and escalates within defined boundaries may score four or five.
How to Calculate Residual Key-Person Risk
Example
- Inherent risk: 84
- Control strength: 10 out of 25
Suggested residual-risk priorities
- 50–100: Critical treatment before busy season or immediate executive acceptance of the exposure
- 30–49: High-priority treatment with named owner and near-term deadline
- 15–29: Moderate risk; improve and monitor
- 0–14: Controlled risk; maintain and retest
This is a management tool, not an actuarial model. Adjust thresholds to the firm’s size, services, clients, risk tolerance, and regulatory environment.
Controls Reduce Exposure Only When They Work
Illustrative scores. A policy, backup name, or procedure does not reduce risk unless the control is current, authorized, secure, and independently usable.
Copy-and-Use CPA Firm Key-Person Risk Assessment Template
Critical Responsibility Risk Assessment
| Critical responsibility | |
| Business result protected | |
| Primary owner | |
| Current backup / escalation owner | |
| Risk period and required recovery time | |
| Assessment owner and date |
1. Dependency description
2. Inherent-risk score
| Factor | Rating 0–5 | Weight | Weighted Score | Evidence |
|---|---|---|---|---|
| Business impact | 30% | |||
| Knowledge and judgment | 20% | |||
| Authority and access | 15% | |||
| Client / stakeholder relationship | 15% | |||
| Deadline sensitivity | 10% | |||
| Recovery difficulty | 10% | |||
| Total inherent risk | ||||
3. Control-strength score
| Control | Score 0–5 | Evidence / Gap |
|---|---|---|
| Qualified backup capability | ||
| Current documentation and knowledge | ||
| Secure access and authority | ||
| Relationship / communication continuity | ||
| Independent validation and maintenance | ||
| Total control strength |
4. Residual risk and treatment
| Residual risk score | |
| Risk decision | Treat / Transfer / Avoid / Accept with approval |
| Target residual risk | |
| Treatment owner and deadline | |
| Required validation evidence | |
| Next review date / change triggers |
5. Risk treatment actions
☐ Document normal workflow and exceptions
☐ Capture client or stakeholder context
☐ Grant secure role-based access
☐ Transfer decision rights or emergency authority
☐ Complete guided practice
☐ Complete independent work sample
☐ Run absence or no-rescue drill
☐ Add secondary escalation coverage
☐ Reassign, automate, outsource, reprice, rescope, or discontinue the work
☐ Obtain leadership acceptance of remaining exposure
Questions to Ask Process Owners and Backups
Questions for the primary owner
- What result are you personally protecting?
- Which parts of the work can another person already perform?
- Where do they still need you?
- What exceptions are not written down?
- Which client or stakeholder expectations exist only in your memory?
- What access, approvals, or contacts would another person need?
- What is most likely to go wrong during your absence?
- Which decisions should remain reserved for a higher authority?
Questions for the named backup
- What are you expected to perform, review, approve, communicate, and escalate?
- Where would you find the current information?
- Which systems can you access now?
- What warning signs would make you stop the normal process?
- Who would you contact for technical, client, security, or operational escalation?
- What parts have you performed independently?
- What would still require the primary owner to rescue you?
Compare the answers
Differences reveal hidden risk.
The owner may believe the backup understands the full workflow. The backup may believe the role is limited to one step. The owner may assume access exists. The backup may never have tested it. The owner may expect the backup to speak with the client. The client may not know the backup’s name.
How to Test Whether Key-Person Risk Is Controlled
1. Findability test
Can the backup locate the correct procedure, client context, source records, contacts, and current status without asking the primary owner?
2. Access test
Can the backup enter the approved systems using individual credentials and the correct permissions?
3. Normal-case performance test
Can the backup complete the routine responsibility accurately and on time?
4. Exception test
Can the backup recognize when the normal process no longer applies?
5. Communication test
Can the backup explain status, request information, manage expectations, and preserve the relationship?
6. Authority and escalation test
Can the backup distinguish decisions within scope from matters requiring manager, partner, specialist, legal, HR, or security involvement?
7. No-rescue drill
The primary owner should be unavailable for the approved test window. Observers may protect the client and firm, but they should record every hidden intervention.
For the treatment process after assessment, use the Accounting Firm Cross-Training Plan.
Completed Example: Construction-Client Business Tax Review
One Tax Manager Reviews a Specialized Client Group
| Critical responsibility | Review and escalation of business tax returns for a group of construction clients with multistate activity and specialized accounting issues. |
| Primary dependency | One tax manager holds most technical history, review judgment, client context, and sequencing knowledge. |
| Current backup | A senior has prepared several returns and observed reviews but has not independently reviewed a complete file or handled an exception. |
| Impact | Potential review backlog, deadline risk, partner intervention, inconsistent client communication, and delayed technical resolution. |
Inherent-risk score
| Factor | Rating | Weighted Result |
|---|---|---|
| Business impact | 5 | 30 |
| Knowledge and judgment | 5 | 20 |
| Authority and access | 3 | 9 |
| Client relationship | 4 | 12 |
| Deadline sensitivity | 5 | 10 |
| Recovery difficulty | 4 | 8 |
| Total inherent risk | 89 | |
Initial control strength
- Backup capability: 2
- Documentation: 2
- Access and authority: 4
- Relationship continuity: 2
- Validation and maintenance: 0
Total control strength: 10 out of 25
Initial residual risk: 89 × (1 − 10 ÷ 25) = 53.4
Treatment plan
- Define the senior’s backup scope for routine review, open-item coordination, and specified client communication.
- Capture the client-group history, recurring technical issues, source guidance, review standards, and escalation triggers.
- Assign six guided reviews and three independent reviews before the peak deadline period.
- Include the senior in client status conversations.
- Run a no-rescue review with one planted multistate exception.
- Maintain partner approval for conclusions outside the defined scope.
Post-validation controls
- Backup capability: 4
- Documentation: 4
- Access and authority: 5
- Relationship continuity: 4
- Validation and maintenance: 4
Revised control strength: 21 out of 25
Revised residual risk: 89 × (1 − 21 ÷ 25) = 14.2
Decision: Controlled within the defined routine-review scope. Technical partner escalation remains mandatory for specified exceptions.
The firm did not attempt to make the senior a complete replacement for the tax manager.
It reduced a critical dependency by creating validated coverage for the portion of the responsibility most likely to disrupt busy-season flow.
Key-Person Risk Treatment Options
| Treatment | Best Used When | Required Evidence |
|---|---|---|
| Cross-train a backup | The responsibility should remain inside the firm and another employee can develop the capability | Independent performance within defined scope |
| Document and structure knowledge | Process, context, decisions, or contacts are concentrated in memory | Another qualified user can find and apply the knowledge |
| Transfer relationship ownership | Client trust and history depend on one partner or manager | Second contact participates, leads defined discussions, and holds current context |
| Redistribute authority | One person controls approvals or emergency decisions | Approved limits, separation of duties, access, and escalation are documented and tested |
| Automate or redesign workflow | Dependency exists because status, sequence, or routine action relies on memory | Workflow remains visible and recoverable without the primary owner |
| Use external coverage | Rare expertise or temporary capacity cannot be developed in time | Contract, confidentiality, access, service level, handoff, and fallback are tested |
| Reprice, rescope, or exit the work | The responsibility consumes disproportionate risk or cannot support required redundancy | Leadership decision, client communication, and transition plan |
| Accept the risk | Treatment cost exceeds exposure or concentration is intentional | Explicit leadership approval, contingency, review date, and documented rationale |
For a broader succession framework, read the CPA Firm Succession Planning Checklist.
A 90-Day Pre–Busy Season Risk-Reduction Plan
| Period | Primary Focus | Required Evidence |
|---|---|---|
| Days 1–30 | Identify critical results and responsibilities, interview owners and backups, score inherent risk, inventory documentation and access, and build the risk register | Top-risk register, dependency descriptions, current control scores, residual-risk priorities, and treatment owners |
| Days 31–60 | Transfer critical knowledge, define backup scope, update SOPs, grant secure access, involve second relationship contacts, and complete guided practice | Current procedures, context records, access tests, practice work, review feedback, and client or stakeholder participation |
| Days 61–90 | Run normal-case and exception drills, correct gaps, recalculate residual risk, approve coverage, document accepted risks, and schedule maintenance | Independent validation, revised scores, approved coverage levels, escalation maps, leadership acceptance, and next review dates |
Do not attempt to fix every dependency at once
Begin with:
- High-impact deadlines inside the next 90 days
- Important client relationships with one owner
- Review stages with no qualified backup
- Systems with one administrator or recovery contact
- Operational processes that can stop production
- Leadership decisions without emergency authority
Security, Access, and Separation-of-Duties Issues
Risk reduction should not create uncontrolled access.
The IRS states that tax professionals are required to maintain a written information security plan tailored to the firm’s size, complexity, activities, and sensitivity of customer information. Current IRS guidance emphasizes employee management and training, risk assessment, safeguards, monitoring, testing, and adjustment when business conditions change.
The FTC Safeguards Rule guidance emphasizes periodically reviewing access controls, understanding where customer information is collected and stored, maintaining inventories of systems and personnel, encrypting information, and designing safeguards for resilience.
Use individual credentials
Do not reduce key-person risk by sharing passwords.
Use least-necessary access
Give the backup the permissions required for the approved scope—not unrestricted access.
Preserve separation of duties
A backup plan should not allow one person to initiate, approve, release, and reconcile a sensitive financial transaction when those duties should remain separated.
Test emergency authority before it is needed
Confirm who can approve access changes, contact vendors, operate during an absence, and document the emergency action.
Remove access when the coverage changes
Update permissions after reassignment, role change, termination, client transition, or completion of temporary coverage.
What Should the Firm Measure?
Exposure
Critical responsibilities, inherent-risk scores, single-owner processes, concentrated clients, and time-to-recovery.
Control Strength
Qualified backups, current knowledge, tested access, relationship coverage, drills, and update schedules.
Residual Risk
Critical and high risks remaining, overdue treatments, accepted exposures, and risk reduction by quarter.
Continuity Performance
Deadline performance during absences, rescue required, client handoffs, access failures, and successful coverage tests.
Useful measures include:
- Percentage of critical responsibilities assessed
- Number of responsibilities with only one capable owner
- Number of residual risks above the firm’s treatment threshold
- Percentage of critical responsibilities with a qualified backup
- Percentage with current and tested documentation
- Percentage with secure backup access
- Percentage of major client relationships with a second informed contact
- Independent drill pass rate
- Procedural rescue required during tests
- Average days to close a critical treatment action
- Deadline or client disruptions caused by person dependency
- Critical responsibilities reassessed after role or system changes
Do not measure how many people appear in the backup column.
Measure how many critical responsibilities can continue at the required level without the primary owner.
How SkillAbility Helps CPA Firms Reduce Key-Person Risk
SkillAbility helps accounting firms convert person-dependent knowledge into structured, demonstrated, and transferable capability.
It is an accounting workforce development and knowledge-transfer platform built around a pathway from new hire to future partner.
The SkillAbility Development Pathway
Develops accounting, tax, payroll, software workflow, documentation, self-review, issue recognition, and review-ready execution through realistic practice.
Develops client communication, financial interpretation, advisory thinking, business acumen, professional presence, and judgment so relationships and decisions do not remain concentrated.
Develops review leadership, delegation, coaching, client transition, firm economics, succession, strategic execution, and future-partner ownership.
The assessment identifies where the firm is vulnerable.
Structured development creates the capability needed to reduce that exposure.
For the broader model, read Accounting Workforce Development: How CPA Firms Build Capacity From Within.
The goal is not to make every employee interchangeable. It is to ensure that critical knowledge, authority, access, client trust, and professional judgment do not disappear from the firm when one person is unavailable.
Frequently Asked Questions
What is key-person risk in a CPA firm?
It is the risk that a critical client, technical, review, workflow, system, operational, or leadership responsibility cannot continue safely or on time because essential knowledge, authority, access, relationships, or judgment are concentrated in one person.
What should a CPA firm key-person risk assessment include?
It should include the critical responsibility, business result, owner, dependency, impact, timing, knowledge and authority concentration, relationship concentration, recovery difficulty, current controls, residual risk, treatment owner, evidence, and review date.
How do you identify a single point of failure?
Ask what stops, becomes unsafe, misses a deadline, loses client trust, or requires emergency reconstruction when the primary person is unavailable. Then test whether another authorized person can perform the responsibility independently.
Is a named backup enough?
No. The backup must understand the scope, locate current information, use approved access, perform the normal workflow, recognize exceptions, communicate appropriately, and escalate matters outside authority.
How should CPA firms score key-person risk?
Score inherent exposure based on business impact, knowledge concentration, authority and access, relationship concentration, deadline sensitivity, and recovery difficulty. Then reduce the score based on validated backup, documentation, access, relationship, and testing controls.
When should a firm complete the assessment?
Complete the initial assessment at least 60 to 90 days before major deadline periods when possible. Reassess after promotions, departures, leaves, client changes, system changes, acquisitions, or significant workflow redesign.
What areas create the most key-person risk?
Common areas include important client relationships, specialized technical knowledge, final review, filing and workflow administration, systems access, firm operations, pricing and staffing decisions, and partner-level leadership.
How do firms reduce client relationship concentration?
Introduce a qualified second contact, document current history and commitments, include the backup in meetings, transfer defined communication responsibilities, and test whether the relationship can continue without the primary owner.
How do firms reduce technical key-person risk?
Define the technical scope, organize authoritative sources and prior conclusions, develop a qualified reviewer, use realistic cases, document exceptions and escalation, and validate the backup through independent work.
Can an SOP eliminate key-person risk?
An SOP can reduce process dependence, but it does not prove technical judgment, client capability, access, or authority. Documentation should be combined with practice, feedback, secure access, and independent validation.
How should firms handle system-access concentration?
Use individual credentials, role-based access, approved secondary administrators, secure recovery procedures, vendor contacts, monitoring, and periodic access tests. Do not share passwords to create backup access.
Should every key-person risk be eliminated?
No. Some concentration is intentional or too costly to remove completely. Leadership should understand the residual exposure, create a contingency, document the decision, and review it regularly.
What is the difference between key-person risk assessment and cross-training?
The assessment identifies and prioritizes exposed responsibilities. Cross-training is one treatment used to build qualified backup capability for selected risks.
How does reducing key-person risk help busy-season capacity?
It distributes routine review, client communication, workflow control, and technical coverage; reduces emergency manager rescue; improves absence coverage; and prevents one overloaded person from constraining the entire workflow.
External Research and Authority Sources
The Bottom Line
A CPA firm should not wait for an absence, resignation, retirement, or emergency to discover that a critical responsibility belongs to one person instead of the firm.
Identify the business results that cannot stop.
Break those results into specific responsibilities.
Score the impact and concentration of knowledge, authority, access, relationships, timing, and recovery difficulty.
Evaluate whether the backup capability, documentation, access, relationship continuity, and testing actually work.
Calculate residual risk.
Treat the highest exposures before busy season.
The answer may be cross-training. It may also be documentation, relationship transition, secure secondary access, delegated authority, workflow redesign, outside coverage, repricing, rescoping, or leadership acceptance of the remaining risk.
The firm controls key-person risk when critical responsibility can continue at the required level—not when a spreadsheet contains a second name.
Protect Knowledge. Develop People. Scale the Firm.
How many critical responsibilities in your firm still stop when one person is unavailable?
SkillAbility helps CPA firms transfer technical execution, client knowledge, professional judgment, review capability, and leadership responsibility through structured practice and measurable evidence.
Book Your Free 10-Minute Structural Alignment Review →
Includes our 45-Day Out-of-Pocket Performance Guarantee.
To finding the dependency before the deadline,
Vincent Howard, CPA
Managing Partner, Howard, Howard and Hodges
SkillAbility for Accounting Firms
About the Author
Vincent Howard, CPA has practiced public accounting since 1990. He holds a Master’s degree in Taxation from the University of Central Florida, founded his accounting firm in 1993, and serves as Managing Partner of Howard, Howard and Hodges. He helped grow the organization from three people to approximately 50 staff across multiple Florida locations and states. He has participated in PASBA since 1997, and the firm was named PASBA Firm of the Year in 2015. Since 2020, he has built and run the SkillAbility accounting workforce development platform, used by more than 1,000 accounting professionals across dozens of PASBA firms.
© 2026 SkillAbility for Accounting Firms. This article provides general educational information and does not replace legal, employment, human-resources, accounting, tax, insurance, business-continuity, data-security, or regulatory advice.
