← ArticlesManaging Key-Person and Project Team RiskProject Delivery · RiskLesson 7/7← PrevNext →
GuidePublished 13 Aug 202612 min readBy Kevin Joginkey-person riskteam risksuccessionknowledge transfer

Project Delivery · Project Risk Management

Managing Key-Person and Project Team Risk

A practical guide to identifying concentration of knowledge, capacity constraints, succession gaps, behavioural risks and team resilience controls.

13 min read Handbook guide Reviewed 2026-08-13 De-identified examples

Executive summary

A practical guide to identifying concentration of knowledge, capacity constraints, succession gaps, behavioural risks and team resilience controls. The method is intended to improve decisions, not merely complete documentation. Apply it proportionately, preserve the evidence behind judgement and connect every action to an accountable owner.

Learning outcomes

  • Map critical roles and knowledge
  • Assess concentration and availability
  • Design succession and cross-training
  • Protect handovers and records
  • Monitor capacity and team conditions
  1. Map critical roles and knowledge
  2. Assess concentration and availability
  3. Design succession and cross-training
  4. Protect handovers and records
  5. Monitor capacity and team conditions

Why Your Project's Greatest Risk Might Walk Out the Door

Projects don't fail because of steel, software, or schedules alone. They fail because people leave — and when the wrong person leaves at the wrong time, the consequences cascade through every work package, every deliverable, and every stakeholder relationship.

In heavy engineering and defence contracting, the loss of a senior welding inspector can halt a submarine hull programme. In software development, the departure of a lead architect can orphan an entire codebase. In manufacturing, losing a master toolmaker mid-production run can turn a profitable contract into a penalty-clause disaster.

Yet despite its catastrophic potential, key staff loss remains one of the most under-managed risks on most project risk registers. Project managers instinctively recognise the threat but struggle to quantify it, treat it systematically, or build organisational resilience against it.

What Is Key Staff Loss Risk?

This risk has several dimensions that make it particularly dangerous:

Dimension Why It Matters
Knowledge concentration Critical project knowledge resides in one person's head, not in documented systems
Relationship dependency Key stakeholder or supplier relationships are personal, not institutional
Skill scarcity The individual possesses rare technical skills with long replacement lead times
Timing sensitivity Loss during critical path activities has disproportionate schedule impact
Morale cascade Departure of a respected leader triggers further attrition across the team

The Risk Event Status Formula

As with any project risk, key staff loss can be quantified:

Risk Event Status=P(departure)×Amount at Stake\text{Risk Event Status} = P(\text{departure}) \times \text{Amount at Stake}

Where:

How to Avoid, Mitigate, and Transfer Key Staff Loss Risk

The PMBOK identifies four strategies for negative risks. All four can be applied to key staff loss, but the emphasis should be on mitigation — because complete avoidance is rarely possible and pure acceptance is reckless for a risk of this magnitude.

Strategy 1: Avoid — Build Systems, Not Heroes

The most powerful avoidance strategy is architectural: design the project organisation so that no single individual is irreplaceable.

This is not about devaluing expertise — it is about ensuring that expertise is institutionalised rather than personalised.

Strategy 2: Mitigate — Reduce Probability and Impact

Reducing Probability (keeping people):

Technique Mechanism Limitation
Competitive remuneration Reduces financial motivation to leave Expensive; may trigger equity issues
Retention bonuses Tied to project milestones or completion dates Only effective short-term
Contractual lock-in periods Legal obligation to remain for a specified term May reduce morale if perceived as coercive
Career development pathways Intrinsic motivation through growth opportunities Requires genuine organisational commitment
Positive team culture Loyalty, purpose, and belonging reduce voluntary turnover Intangible and difficult to manufacture

Reducing Impact (preparing for loss):

Technique Mechanism
Cross-training Multiple team members trained on each critical function
Knowledge management Documented procedures, decision logs, lessons learned databases
Work overlap Swap tasks between contractors/departments periodically so everyone understands multiple areas
Succession planning Pre-identified internal candidates ready to step into critical roles
Shadowing programmes Junior team members paired with key personnel to absorb tacit knowledge

Strategy 3: Transfer — Shift the Risk to a Third Party

Strategy 4: Accept — When All Else Fails

For lower-criticality personnel, active acceptance may be appropriate:

Bow-Tie Analysis: Key Staff Loss

The Bow-Tie is a powerful visual risk analysis tool that maps causes on the left, the risk event at the centre, and consequences on the right — with proactive controls (barriers) preventing the event and reactive controls managing its consequences.

Real-World Application: Defence Manufacturing

Consider a Tier-1 defence contractor manufacturing armoured vehicles. The programme has a single master jig-and-fixture designer whose expertise in complex welding jig geometry is not replicated anywhere else in the organisation. Risk Assessment:

  1. Mitigate (Impact): Assign a junior designer to shadow the master designer for 6 months; document all jig design rationale in a standardised knowledge base
  2. Mitigate (Probability): Negotiate a retention bonus tied to programme completion milestones
  3. Transfer: Procure key-person insurance covering recruitment and onboarding costs
  4. Accept (Residual): Maintain a AUD 200k contingency reserve for residual risk after mitigation

This layered approach reduces both the probability and impact of the risk to within the programme's risk appetite.

The Pitfalls: Common Mistakes in Managing Key Staff Risk

1. Relying solely on financial incentives. Money buys time, not loyalty. Perks and remuneration work for a while, but they do not address root causes like burnout, lack of purpose, or toxic leadership. 2. Assuming documentation replaces expertise. Tacit knowledge — the intuition, judgement, and relational context that experts carry — cannot be fully captured in procedures. Cross-training and shadowing are essential complements to documentation. 3. Treating key staff risk as an HR problem. It is a project risk that belongs on the risk register, with an owner, a treatment plan, trigger conditions, and regular review — just like any technical or financial risk. 4. Ignoring the morale cascade. When a respected team member leaves, others reconsider their own positions. The secondary attrition risk can exceed the primary loss. Proactive communication and team engagement after a departure are critical reactive controls. 5. Failing to update the analysis. Team composition changes throughout the project lifecycle. A person who was non-critical during design may become critical during commissioning. The key staff risk assessment must be reviewed at every project phase gate.

Key Takeaways

Decision-Making Under Pressure

When Cool Heads Matter Most

Practitioner guidance made a crucial observation about the timing of risk-related decisions: "The best time to make a decision is when heads are cool and the pressure is not yet on. That means looking ahead at potential problems and forming plans before they are needed."

Yet common practice in many organisations is precisely the opposite. Significant decisions about risk response are deferred until the risk materialises — by which point the decision must be made under time pressure, emotional stress, and with limited options. Pre-planned contingency responses, developed when the team has time to think clearly and evaluate alternatives, consistently produce better outcomes than reactive decisions made in crisis conditions.

The Authority to Decide

Effective risk management requires that people at the right organisational level have the authority to make risk-related decisions. When every risk response requires escalation to a steering board that meets quarterly, the response time is inadequate for dynamic project environments.

The PRAM Guide's emphasis on assigning risk owners is intended to address this, but ownership without authority is meaningless. A risk owner must have the authority to commit resources, adjust plans, and implement responses within agreed parameters — escalating only when those parameters are exceeded.

The Behavioural Barriers to Effective Risk Management

Cognitive Biases in Risk Assessment

Every risk workshop, every probability estimate, and every impact assessment is filtered through the cognitive biases of the people involved. The most consequential biases in project risk management include:

Optimism bias — the systematic tendency to underestimate costs, durations, and the likelihood of negative outcomes while overestimating benefits and the probability of success. Megaproject research documented this bias across hundreds of megaprojects, finding that cost overruns were the norm rather than the exception — not because of unforeseeable events, but because of systematically biased estimation. Anchoring — the tendency to fixate on an initial estimate or piece of information, adjusting insufficiently from that anchor. In risk workshops, the first probability estimate voiced tends to anchor all subsequent assessments by other participants. Availability heuristic — judging the likelihood of events based on how easily examples come to mind. Risks similar to recently experienced problems are overestimated; risks with no recent precedent are underestimated, regardless of their actual probability. Groupthink — the tendency for cohesive groups to reach consensus without critically examining alternatives. In risk identification workshops, this manifests as teams agreeing on a comfortable set of "usual suspect" risks while avoiding discussion of uncomfortable uncertainties that might challenge the project's viability. Normalcy bias — the assumption that because something has not happened before, it will not happen in the future. This bias is particularly dangerous in novel or first-of-class projects, where historical precedent provides a false sense of security.

Bias Effect on Risk Management Mitigation Strategy
Optimism Underestimates threats, overestimates opportunities Reference class forecasting; independent review of estimates
Anchoring First estimate dominates assessment Blind estimation before group discussion; Delphi technique
Availability Overweights recent/vivid events Structured prompt lists; RBS-based identification
Groupthink Suppresses dissenting risk views Devil's advocate role; anonymous risk submission
Normalcy Dismisses unprecedented scenarios Scenario analysis; pre-mortem exercises

The Experience Paradox

An experienced risk practitioner identified a subtle barrier: experience itself can be an obstacle to effective risk management. Experienced project managers develop strong intuitions about what can go wrong — but these intuitions are shaped by their specific past experience, which may not be representative of the current project's risk profile.

When an experienced engineer says "I've been doing big projects for 25 years — who are you to tell me how to run my projects?", they are expressing not just resistance to change but a genuine belief that their tacit knowledge supersedes formal risk processes. The challenge is to honour that experience while creating structures that surface knowledge that individuals may not recognise they hold, capture insights from the entire team rather than just the most vocal members, and address risks that fall outside any individual's experience base.

Practical Strategies for Addressing the Human Factor

Pre-Mortem Analysis

Instead of asking "What could go wrong?" (which triggers defensive thinking), the pre-mortem technique asks: "Imagine the project has failed. What caused the failure?" This cognitive reframing gives participants permission to voice concerns that they might otherwise suppress, producing richer and more honest risk identification.

Delphi Technique for Assessment

Anonymous, iterative estimation removes the influence of seniority, personality, and groupthink from probability and impact assessment. Each participant provides independent estimates; the results are aggregated and shared; outliers are invited to explain their reasoning; and the process repeats until convergence is achieved.

Risk Attitude Assessment

A recognised project-risk framework's work on risk attitude provides a framework for understanding how individuals and teams approach uncertainty. The four key attitudes are:

Attitude Behaviour Impact on Risk Management
Risk-averse Uncomfortable with uncertainty; seeks to eliminate risk May over-invest in mitigation; may avoid beneficial innovation
Risk-tolerant Comfortable with moderate uncertainty Generally balanced approach to risk management
Risk-seeking Attracted to uncertainty; embraces high-risk options May under-invest in mitigation; may pursue unwarranted opportunities
Risk-neutral Unaffected by uncertainty; focuses on expected values Theoretically optimal but rarely observed in practice

Making these attitudes explicit within the team — and at the steering board level — enables more transparent risk discussions. When a risk-averse sponsor and a risk-seeking project manager disagree about the appropriate response to a particular threat, understanding that their disagreement stems from different risk attitudes (not different information) enables more productive resolution.

Structured Decision Protocols

For high-consequence risk decisions, structured protocols prevent the degradation of decision quality under pressure. These protocols specify trigger conditions (when does a pre-planned response activate?), escalation thresholds (at what point does the decision move to a higher authority?), information requirements (what data must be available before a decision is made?), and decision authorities (who has the authority to commit resources at each level?).

Practitioner completion checks

Use these checks before closing the analysis or taking the decision forward. Scale the evidence to the consequence, uncertainty and reversibility of the decision.

Check 01Map critical roles and knowledge is defined, owned, evidenced and linked to the relevant project decision.
Check 02Assess concentration and availability is defined, owned, evidenced and linked to the relevant project decision.
Check 03Design succession and cross-training is defined, owned, evidenced and linked to the relevant project decision.
Check 04Protect handovers and records is defined, owned, evidenced and linked to the relevant project decision.
Check 05Monitor capacity and team conditions is defined, owned, evidenced and linked to the relevant project decision.
How much detail is enough?

Use the least complex method that can support a defensible decision. Increase rigour when consequences are high, uncertainty is material, interfaces are complex, evidence is weak or the decision is difficult to reverse.

What should the decision record contain?

Record the objective, scope, inputs, assumptions, method, uncertainties, options, judgement, owner, approval, actions, residual exposure and the trigger or date for review.

When should the work be repeated?

Repeat it when a key assumption changes, new evidence appears, exposure crosses a threshold, a response fails, scope or interfaces change, or the next governance decision requires refreshed information.

Current authoritative reference points

Use the current published documents and the requirements adopted for the project's jurisdiction and contract. Links below support currency checking; they do not reproduce copyrighted standards.

Continue learning

Risk Ownership, Allocation and ProcurementGuide · RiskRisk Monitoring, Reporting and ControlGuide · RiskRisk Triggers, Contingencies and Early WarningGuide · RiskRisk Controls and Defence in DepthGuide · Risk