The framework · Technology & Future
24 Governance, Risk, Compliance & Security
12 sub-categories. The three numbers on each are the typical opportunity in that area across businesses — not your result.
Time6.4/10Financial7.6/10Automation7.4/10
These three numbers are researched cross-business benchmarks for the area — the typical opportunity available in it. They are not your score, not a forecast, and not a promise. What is actually critical depends on your business, which is what the audit is for.
24.1Legal obligations
Time5/10Financial7/10Automation5/10
▸
- What this is
- The legal obligations that attach to your business — entity, employment, consumer, tax, sector-specific.
- Why it matters
- Obligations do not depend on knowing about them. The cost of a breach is usually far higher than the cost of having checked.
- You have a problem here if
- Nobody in the business could list your principal legal obligations.
- What to automate
- Maintain an obligations register with an owner and a review date for each, and automate the reminders. Interpretation is a professional-advice question, not a software one.
24.2Regulatory compliance
Time6/10Financial8/10Automation7/10
▸
- What this is
- Meeting the specific regulatory requirements of your industry, and being able to show it.
- Why it matters
- Regulators generally accept evidence, not assurances. Compliance without records is indistinguishable from non-compliance during an audit.
- You have a problem here if
- You believe you are compliant but could not evidence it quickly.
- What to automate
- Automate evidence collection as a by-product of doing the work — timestamps, sign-offs, records generated by the system rather than assembled later. Automate the calendar of recurring obligations.
24.3Contracts
Time7/10Financial8/10Automation8/10
▸
- What this is
- The agreements you have with customers, suppliers and staff — current, signed and findable.
- Why it matters
- Contracts decide who carries risk. Missing, expired or unsigned contracts are discovered during disputes, which is the most expensive time to find out.
- You have a problem here if
- You could not produce a signed current contract for every major customer within an hour.
- What to automate
- High automation potential: a contract register with key dates, automated renewal and expiry alerts, templated generation and e-signature. Getting terms drafted is legal work; never losing track of them is systems work.
24.4Insurance
Time4/10Financial6/10Automation4/10
▸
- What this is
- Cover appropriate to the risks the business actually carries.
- Why it matters
- Insurance is the cheapest transfer of catastrophic risk available, and it is commonly set once at formation and never revisited as the business changes.
- You have a problem here if
- Your cover has not been reviewed since the business materially changed.
- What to automate
- Four out of ten — mostly a reminder to review annually against a current risk register. The adequacy assessment needs a broker or adviser who knows your sector.
24.5Privacy
Time6/10Financial7/10Automation8/10
▸
- What this is
- How personal information is collected, stored, used and disposed of.
- Why it matters
- Privacy obligations apply to almost every business now, and breaches carry both regulatory and reputational cost. Customers increasingly ask.
- You have a problem here if
- You do not know everywhere customer personal data is stored.
- What to automate
- Automate the discoverable parts: data inventory, retention and deletion schedules, access controls and consent records. Build deletion in from the start — retrofitting it is far harder.
24.6Cybersecurity
Time7/10Financial9/10Automation9/10
▸
- What this is
- Protecting systems and data from attack, and being ready when one happens.
- Why it matters
- Nine out of ten financially. Security incidents in small businesses frequently cause more damage than the business can absorb, and preparation is dramatically cheaper than response.
- You have a problem here if
- You have no written plan for what to do in the first hour of a breach.
- What to automate
- Automate the fundamentals — enforced multi-factor authentication, patching, endpoint protection, email filtering, access reviews, monitoring and alerting. Write the incident response plan and rehearse it once; the rehearsal is what makes it real.
24.7Financial controls
Time8/10Financial9/10Automation9/10
▸
- What this is
- The controls that stop money leaving the business incorrectly.
- Why it matters
- Nine out of ten financially and one of the areas where small businesses are most exposed, because segregation of duties is difficult with few people.
- You have a problem here if
- One person can raise, approve and pay an invoice.
- What to automate
- High automation potential and a genuine substitute for headcount: approval thresholds, dual authorisation for payments above a limit, automated reconciliation, and exception reporting. Where you cannot segregate duties, compensate with visibility.
24.8Fraud prevention
Time7/10Financial9/10Automation9/10
▸
- What this is
- Defences against fraud committed from outside the business and from within it.
- Why it matters
- Nine out of ten financially. Small-business fraud is usually committed by trusted people over long periods precisely because nobody was looking.
- You have a problem here if
- Bank details for suppliers can be changed without independent verification.
- What to automate
- Automate detection: duplicate payments, unusual patterns, out-of-hours transactions, supplier bank-detail change alerts, and mandatory callback verification. These controls are cheap and they work.
24.9Delegated authority
Time7/10Financial6/10Automation7/10
▸
- What this is
- Who is allowed to commit the business, to what value, and in what circumstances.
- Why it matters
- Undefined authority produces both bottlenecks and unauthorised commitments — often in the same business at the same time.
- You have a problem here if
- Spending limits are informal and inconsistently applied.
- What to automate
- Write the delegation matrix, then enforce it in the systems where the commitments are made. This is one of the clearest cases where a policy becomes real only once it is encoded.
24.10Operational risk
Time6/10Financial7/10Automation7/10
▸
- What this is
- The risks arising from how the business runs day to day.
- Why it matters
- Operational risks are the ones most likely to actually happen. They are also the ones least likely to have been written down.
- You have a problem here if
- Risk is discussed only after an incident.
- What to automate
- Maintain a risk register with likelihood, impact and a named owner, and automate the review cadence. Identification is a structured conversation; the discipline of revisiting it should be systemic.
24.11Business continuity
Time6/10Financial8/10Automation7/10
▸
- What this is
- The plan for continuing to operate when something significant goes wrong.
- Why it matters
- The difference between a disruption and a closure is usually preparation. Most small businesses have never written this down.
- You have a problem here if
- You have no plan for losing premises, systems or a key person for two weeks.
- What to automate
- Automate the technical elements — backups, failover, contact lists kept current. The plan itself is a short document and a rehearsal; both are cheap and neither happens without being scheduled.
24.12Risk identification and monitoring
Time8/10Financial7/10Automation9/10
▸
- What this is
- A standing process for spotting risks before they materialise.
- Why it matters
- Risk identification is what converts governance from documentation into something that changes decisions.
- You have a problem here if
- The risk register, if it exists, has not changed in a year.
- What to automate
- Automate the monitoring where there are signals — financial thresholds, security alerts, supplier warnings, compliance dates, concentration measures. Route them to a person with authority to act, and review the register on a fixed cadence.
Category totals
Time 77/120 · Financial 91/120 · Automation 89/120. The sum is the official roll-up; the averages above exist so categories of different sizes can be compared.