Insights on Crypto Payments, Infrastructure, and Operations

Key Person Risk

Pronunciation: KEE PUR-sun RISK

Also known as: Key Individual Risk

Definition

Key Person Risk is the operational, governance, fraud, continuity, or compliance risk created when critical knowledge, authority, access, or relationships depend excessively on one individual. It is used to identify where absence, misconduct, conflict, coercion, or account compromise could disrupt or endanger the organization. It differs from politically exposed person risk, which concerns public functions and corruption exposure rather than internal dependency on a critical employee or founder.

Overview

Key Person Risk is the operational, governance, fraud, continuity, or compliance risk created when critical knowledge, authority, access, or relationships depend excessively on one individual. Its operational purpose is to identify where absence, misconduct, conflict, coercion, or account compromise could disrupt or endanger the organization. It should be considered alongside Control Testing. The relevant distinction is politically exposed person risk, which concerns public functions and corruption exposure rather than internal dependency on a critical employee or founder.

A typical workflow is as follows: The organization maps critical activities, privileges, approvals, knowledge, vendor relationships, and recovery responsibilities to individuals, evaluates concentration, and establishes succession, documentation, and alternate authority.

Core controls include segregation of duties, dual control, access reviews, succession planning, cross-training, documented procedures, mandatory leave, monitored privileged activity, and emergency recovery.

In payment and crypto operations, Key person concentration is especially dangerous where one person can change payout addresses, approve treasury transfers, access private keys, alter sanctions rules, or reconcile their own transactions.

Evidence should include role and privilege inventory, critical processes, alternate owners, approval paths, access logs, training status, recovery tests, conflicts, and remediation plans. Strong trust in a founder or expert does not replace controls because accidental absence and credential theft can cause the same operational dependency.

For Key Person Risk, the trust decision should establish the operational, governance, fraud, continuity, or compliance risk created when critical knowledge, authority, access, or relationships depend excessively on one individual and bind the result to the requested action and protected resource. Teams should test issuance, storage, validation, expiry, revocation, recovery, and privileged override for key person drivers and conditions, rather than checking only a successful request. Logs concerning the Key Person exposure and key person drivers and conditions should support investigation without exposing reusable secrets or unnecessary personal data.

Key Takeaway

Key Person Risk is reduced by distributing authority and knowledge, enforcing dual control, documenting recovery, and testing that alternates can perform critical work.

Sources

  1. Security and Privacy Controls for Information Systems and Organizations — NIST (2026-08-03)
  2. BSA/AML Independent Testing — FFIEC (2026-08-03)
  3. Secrets Management Cheat Sheet — OWASP (2026-08-03)