The approval bottleneck that only exists because one person is on holiday
Written by Ray Stephens
A finance director I worked with once told me her entire invoicing process stopped for two weeks every August. Not because of a system failure, because she was the only person who could sign off supplier payments over a certain threshold and she was on a beach in Cornwall.

Nobody had designed it that way on purpose. It had simply built up over years, one exception and one trusted colleague at a time, until an entire operational process depended on a single person answering their phone.
The failure point nobody plans for
Most organisations spend real money protecting against technical single points of failure. Backup servers. Redundant infrastructure. Disaster recovery plans that get tested and refined.
Far fewer apply the same thinking to people. Approval processes, reviews, sign offs, decision gates. These often sit with one individual because it made sense at the time. They understood the detail. They carried the authority. Nobody questioned it, because most days it worked fine.
Then that person takes annual leave, changes role, or leaves the business. Suddenly a process that ran smoothly for years grinds to a halt, and everyone downstream is left waiting.
That's not a resourcing problem. It's a design problem.
Process controls that are really just people dependencies
Here's the pattern I keep seeing. A business calls something a process control when actually it's a person dependency wearing a process label.
The approval sits with one named individual rather than a role. The knowledge required to make the decision lives in someone's head rather than anywhere documented. The escalation path, if one exists at all, is informal, built on who happens to know who.
None of this looks risky when everyone is present and available. It only becomes visible the moment someone isn't, and by then the cost is already landing on your teams, your customers, and your timelines.
Why single ownership isn't actually faster
There's a common assumption that giving one person sole authority speeds things up. Fewer opinions, fewer meetings, faster decisions. Sometimes that's true in the short term.
But concentrating knowledge and authority in one individual creates a different kind of cost. Every decision now has a single point of dependency. Every delay in that person's availability becomes a delay across every process that relies on them.
Speed on a good day isn't the same as resilience on a difficult one. The businesses that get caught out aren't the ones moving slowly. They're the ones who never noticed how much was resting on one person's calendar.
Designing for roles, not individuals
The fix isn't removing accountability. It's making sure accountability sits with a role rather than a name. That starts with mapping your critical workflows properly. Where does progress actually depend on a specific person being available, rather than a specific skill set or level of authority being present?
From there, digital workflows can do genuine work. Delegated authority that activates automatically when the primary approver is unavailable. Escalation paths that are built into the system rather than relying on someone remembering to mention it. Automated approvals for routine, low risk decisions that don't need a senior signature every time.
None of this weakens governance. Done properly, it strengthens it. You get a clear audit trail of who approved what, and under which circumstances, rather than an informal understanding that only exists in one person's head.
What resilient organisations do differently
The businesses that handle this well aren't the ones with the most process documentation. They're the ones who've asked a simple, uncomfortable question about every critical workflow they run. If this person were unavailable for two weeks, what would stop.
Where the answer is anything meaningful, that's not a resourcing gap. It's a design opportunity, and usually one that's cheaper to fix than the disruption it eventually causes.
Where this leaves you
Single points of failure rarely announce themselves in advance. They sit quietly inside processes that work perfectly well right up until the moment they don't.
Take one critical workflow in your business and ask honestly where it depends on a specific person rather than a defined role. Ask what would happen if that person were unreachable for two weeks. Ask who else could step in, and whether your systems would actually let them.
Those questions won't slow you down. They'll show you exactly where your operational risk is hiding.
If you want to talk through what that audit might look like for your business, I'm glad to have that conversation.
