The framework · Technology & Future

24 Governance, Risk, Compliance & Security

12 sub-categories. The three numbers on each are the typical opportunity in that area across businesses — not your result.

Time6.4/10Financial7.6/10Automation7.4/10

These three numbers are researched cross-business benchmarks for the area — the typical opportunity available in it. They are not your score, not a forecast, and not a promise. What is actually critical depends on your business, which is what the audit is for.

24.1

Legal obligations

Time5/10Financial7/10Automation5/10
What this is
The legal obligations that attach to your business — entity, employment, consumer, tax, sector-specific.
Why it matters
Obligations do not depend on knowing about them. The cost of a breach is usually far higher than the cost of having checked.
You have a problem here if
Nobody in the business could list your principal legal obligations.
What to automate
Maintain an obligations register with an owner and a review date for each, and automate the reminders. Interpretation is a professional-advice question, not a software one.
24.2

Regulatory compliance

Time6/10Financial8/10Automation7/10
What this is
Meeting the specific regulatory requirements of your industry, and being able to show it.
Why it matters
Regulators generally accept evidence, not assurances. Compliance without records is indistinguishable from non-compliance during an audit.
You have a problem here if
You believe you are compliant but could not evidence it quickly.
What to automate
Automate evidence collection as a by-product of doing the work — timestamps, sign-offs, records generated by the system rather than assembled later. Automate the calendar of recurring obligations.
24.3

Contracts

Time7/10Financial8/10Automation8/10
What this is
The agreements you have with customers, suppliers and staff — current, signed and findable.
Why it matters
Contracts decide who carries risk. Missing, expired or unsigned contracts are discovered during disputes, which is the most expensive time to find out.
You have a problem here if
You could not produce a signed current contract for every major customer within an hour.
What to automate
High automation potential: a contract register with key dates, automated renewal and expiry alerts, templated generation and e-signature. Getting terms drafted is legal work; never losing track of them is systems work.
24.4

Insurance

Time4/10Financial6/10Automation4/10
What this is
Cover appropriate to the risks the business actually carries.
Why it matters
Insurance is the cheapest transfer of catastrophic risk available, and it is commonly set once at formation and never revisited as the business changes.
You have a problem here if
Your cover has not been reviewed since the business materially changed.
What to automate
Four out of ten — mostly a reminder to review annually against a current risk register. The adequacy assessment needs a broker or adviser who knows your sector.
24.5

Privacy

Time6/10Financial7/10Automation8/10
What this is
How personal information is collected, stored, used and disposed of.
Why it matters
Privacy obligations apply to almost every business now, and breaches carry both regulatory and reputational cost. Customers increasingly ask.
You have a problem here if
You do not know everywhere customer personal data is stored.
What to automate
Automate the discoverable parts: data inventory, retention and deletion schedules, access controls and consent records. Build deletion in from the start — retrofitting it is far harder.
24.6

Cybersecurity

Time7/10Financial9/10Automation9/10
What this is
Protecting systems and data from attack, and being ready when one happens.
Why it matters
Nine out of ten financially. Security incidents in small businesses frequently cause more damage than the business can absorb, and preparation is dramatically cheaper than response.
You have a problem here if
You have no written plan for what to do in the first hour of a breach.
What to automate
Automate the fundamentals — enforced multi-factor authentication, patching, endpoint protection, email filtering, access reviews, monitoring and alerting. Write the incident response plan and rehearse it once; the rehearsal is what makes it real.
24.7

Financial controls

Time8/10Financial9/10Automation9/10
What this is
The controls that stop money leaving the business incorrectly.
Why it matters
Nine out of ten financially and one of the areas where small businesses are most exposed, because segregation of duties is difficult with few people.
You have a problem here if
One person can raise, approve and pay an invoice.
What to automate
High automation potential and a genuine substitute for headcount: approval thresholds, dual authorisation for payments above a limit, automated reconciliation, and exception reporting. Where you cannot segregate duties, compensate with visibility.
24.8

Fraud prevention

Time7/10Financial9/10Automation9/10
What this is
Defences against fraud committed from outside the business and from within it.
Why it matters
Nine out of ten financially. Small-business fraud is usually committed by trusted people over long periods precisely because nobody was looking.
You have a problem here if
Bank details for suppliers can be changed without independent verification.
What to automate
Automate detection: duplicate payments, unusual patterns, out-of-hours transactions, supplier bank-detail change alerts, and mandatory callback verification. These controls are cheap and they work.
24.9

Delegated authority

Time7/10Financial6/10Automation7/10
What this is
Who is allowed to commit the business, to what value, and in what circumstances.
Why it matters
Undefined authority produces both bottlenecks and unauthorised commitments — often in the same business at the same time.
You have a problem here if
Spending limits are informal and inconsistently applied.
What to automate
Write the delegation matrix, then enforce it in the systems where the commitments are made. This is one of the clearest cases where a policy becomes real only once it is encoded.
24.10

Operational risk

Time6/10Financial7/10Automation7/10
What this is
The risks arising from how the business runs day to day.
Why it matters
Operational risks are the ones most likely to actually happen. They are also the ones least likely to have been written down.
You have a problem here if
Risk is discussed only after an incident.
What to automate
Maintain a risk register with likelihood, impact and a named owner, and automate the review cadence. Identification is a structured conversation; the discipline of revisiting it should be systemic.
24.11

Business continuity

Time6/10Financial8/10Automation7/10
What this is
The plan for continuing to operate when something significant goes wrong.
Why it matters
The difference between a disruption and a closure is usually preparation. Most small businesses have never written this down.
You have a problem here if
You have no plan for losing premises, systems or a key person for two weeks.
What to automate
Automate the technical elements — backups, failover, contact lists kept current. The plan itself is a short document and a rehearsal; both are cheap and neither happens without being scheduled.
24.12

Risk identification and monitoring

Time8/10Financial7/10Automation9/10
What this is
A standing process for spotting risks before they materialise.
Why it matters
Risk identification is what converts governance from documentation into something that changes decisions.
You have a problem here if
The risk register, if it exists, has not changed in a year.
What to automate
Automate the monitoring where there are signals — financial thresholds, security alerts, supplier warnings, compliance dates, concentration measures. Route them to a person with authority to act, and review the register on a fixed cadence.

Category totals

Time 77/120 · Financial 91/120 · Automation 89/120. The sum is the official roll-up; the averages above exist so categories of different sizes can be compared.