Key Person Risk in Singapore SMEs: Documenting the Decisions Only the Owner Can Make
Key person risk in a Singapore SME is almost never a skills problem — it is a decision rights problem, and you close it by documenting the judgement calls that currently route to the owner, not the tasks. If the boss is uncontactable for two weeks, the invoices still get raised and the orders still get packed. What stops is everything requiring approval: the discount on a repeat customer, the payment release above a threshold, the hire, the supplier switch, the exception to a policy. The fix is a one-page decision register, a written rule for each entry, and a named deputy with the access to execute it. That is a weekend of work for most owners, and it is the single highest-return resilience exercise a small business can do before December.
What does key person risk actually look like in a 10 to 30 person business?
It rarely announces itself. It shows up as a quote sitting unsent for three days, a supplier payment missed because only one person holds the bank token, or a customer complaint escalating because the staff member handling it could not approve a goodwill credit without checking first. Each delay is small. Collectively they are the reason the owner cannot take a two-week holiday without their phone on.
The sharper version of the risk is structural. In many Singapore SMEs one person is simultaneously the CorpPass administrator, the sole bank signatory, the only named contact at the main supplier, the holder of the domain registrar login, and the person whose personal mobile receives every OTP. That is not delegation failure — it is a concentration that accumulated quietly over years because it was faster each time. The business does not notice until the owner is hospitalised, stuck overseas, or simply exhausted.
Which decisions are actually stuck with the owner?
Do not start by writing procedures. Start by observing. For two weeks, keep a running note — a WhatsApp message to yourself is fine — of every time someone asks you to decide something. You are not recording the work; you are recording the interruption. At the end of a fortnight most owners have between 20 and 40 entries, and they cluster into five predictable groups:
- Money out — payment releases, refunds, credit notes, writing off a bad debt, approving overtime or a claim.
- Money in — discounts, payment terms, extending credit to a slow payer, quoting a non-standard job.
- People — hiring, confirming probation, approving leave that clashes, handling a performance conversation.
- Exceptions — a customer wants something outside the usual terms and someone needs to say yes.
- Access and identity — who gets a system account, who signs, who is named on an application.
Those five buckets are where the business is owner-dependent. Everything else is a task, and tasks are already being done by someone other than you.
How do you document a decision without writing a 40-page manual?
SOP projects die because they attempt completeness. A decision register does not. Each entry needs four lines, and nothing more:
- The decision — plainly stated. For example: approving a discount on a repeat customer order.
- The rule — the boundary within which someone else can just decide. Up to 10 percent on an order below $5,000 for a customer with no overdue invoices, no approval needed.
- The escalation — what falls outside the rule, and who it goes to when you are unreachable.
- The reasoning — one sentence on why the boundary sits there. This is the part everyone skips and the part that makes the rule survive a situation you did not anticipate.
Four lines times thirty decisions is six pages. It fits in a shared document and can be written over two evenings. The reasoning line matters most: a deputy who understands that the discount ceiling exists to protect a thin margin on freight-heavy items will make a sensible call on a case you never wrote down. A deputy who only has the number will either refuse or guess.
What has to change beyond the document?
A written rule that the deputy cannot execute is theatre. Three practical enablers usually need attention at the same time:
Access. Add a second CorpPass administrator. Add a second bank user with a view-and-prepare role even if approval stays with you — someone being able to stage a payment run cuts your involvement to thirty seconds. Move shared logins into a password manager so handover is a permission change rather than a message with a password in it.
Identity. OTPs landing only on the owner's personal mobile are a bottleneck disguised as security. Where the platform allows it, move to an authenticator app that can be provisioned to more than one trusted person, or at minimum register a company number as a backup.
Visibility. If approvals happen in a one-to-one WhatsApp chat with you, no one else can see the pattern or the precedent. Moving approvals into a shared channel or a simple form creates a record your deputy can learn from, and a trail you will want anyway as InvoiceNow adoption and tighter 2027 payroll and employment obligations push more of the business toward documented process.
Why do this in October rather than January?
Because the test is free in December and expensive in March. Q4 in Singapore brings the annual collision of year-end leave clearance, resignations tendered before bonus cycles, festive demand, and customers chasing delivery before their own financial year closes. That is precisely the period when the owner is least available and most needed. Writing the register in October gives you eight to ten weeks to run it live while you are still around to correct a bad boundary.
It also positions you for the January step-ups. CPF contribution and wage floor changes landing in 2027 are operational events, not just payroll arithmetic — someone has to decide how a cost increase is absorbed, repriced or passed on, customer by customer. An owner already running a decision register handles that as a rule change. An owner without one handles it as thirty individual interruptions.
How do you know it worked?
Run a deliberate test. Pick a week, tell your deputy they have the register, and decline to answer anything that the register already covers — redirect them to it instead. Log every question that arrives anyway. Those questions are your gaps, and there will be fewer than you fear. Repeat the test quarterly. The measure of success is not the thickness of the document; it is the drop in the number of times a week your business pauses waiting for you.
Frequently asked questions
Is key person insurance a substitute for this?
No. Key person insurance replaces money after a defined event such as death or permanent disability. It does nothing for the far more common scenarios — the owner on a flight, on leave, in hospital for a week, or simply saturated. Insurance covers the balance sheet; a decision register covers Tuesday.
What if I genuinely do not trust anyone to make these calls yet?
Then start with the rule and no delegation. Write the boundaries down for yourself first. You will find that half the decisions you were making were mechanical applications of a rule you already held in your head, and those can be delegated immediately. The remainder are the genuine judgement calls, and those are the ones to coach a deputy through over the next two quarters.
Does this conflict with keeping control of my business?
It does the opposite. Documenting a decision defines its boundary, which means you keep authority over everything outside it rather than re-granting it ad hoc every time. Owners who do this typically report being consulted less often but on more significant matters — which is what control is supposed to look like.
If you want a second pair of eyes on where your business is concentrated, Digital Perpetual runs a short dependency review that maps access, approvals and single points of failure across your systems. Most of what we find is fixable in an afternoon — the hard part is being told where to look.
Ready to Transform Your Business?
Let Digital Perpetual help you automate, streamline, and grow.
Get Started with Digital Perpetual →