Person dependency and Records management

What is person dependency?

If a company is unable to carry out work processes or loses business-critical knowledge with the loss of individual employees, it is at a disadvantage. The unfortunately well-known term is called person dependency and can have significant business and legal consequences for the company.

In a records management context, person dependency is seen, for example, when only a single employee has knowledge of the location and handling of special records, has insight into self-developed systematization methods, is able to operate unsupported IT systems, or is familiar with undocumented processes.

Although person dependency arises unintentionally, it can also be a reflection of the individual employees having managed their own tasks, typically over a long period, where things outwardly seemed to function. Therefore, person dependency sometimes only becomes apparent after the employee has left. In general, person dependency can be difficult to spot, especially if it only occurs in specific parts of complex or extensive work processes.

It can obviously be cumbersome, time-consuming, and costly to resolve the problems that can arise as a result of person dependency. Furthermore, there is a risk of non-compliance with applicable requirements and legislation – for example, if, due to some of the aforementioned examples of person dependency, one is unable to demonstrate the integrity of their records.

Fired,Senior,Employee,Leaving,The,Office,With,The,Box
Business-critical knowledge can easily disappear with the individual employee.
Measures Against Person Dependency If you want to counteract and safeguard against person dependency, governance and audit are essential measures. By establishing governance in the form of fixed and clear procedures for work and decision-making processes and IT systems, you can prevent only a few individuals from having knowledge of, for example, unique workflows. This makes it possible for others to step in quickly and efficiently, thus maintaining business continuity. Likewise, policies that set requirements for documentation help ensure that relevant and critical knowledge is anchored in the company and not just with the individual employee. With both procedures and documentation requirements, you can also avoid the development of self-developed systems that only the “inventor” can understand. When you have developed solid governance, you have also created a foundation that can be used as a basis for audit or revision. Audit can reveal deviations, making it possible to tackle person dependency at the root, as well as identify other vulnerabilities and optimization opportunities. In addition to internal governance, we at Scandinavian Information Audit also use the ISO 30300 series (Management systems for records) as a framework for the audits we conduct. The ISO 30300 series focuses on person dependency and is therefore a solid standard to adhere to and rely on in both limited and extensive audits.