Assumed Accountability: The Silent Risk in UK Operating Models

Most operational failures in UK businesses do not announce themselves in advance. They do not appear on risk registers. They do not feature in board reports. They accumulate quietly, in the space between what is formally assigned and what actually keeps the organisation running, until something changes and the gap becomes impossible to ignore.

Assumed accountability is one of the most pervasive and least discussed risks in UK operating models. It is the risk that sits not in any documented process or identified control but in the unexamined belief that, because something has always been handled, someone must be responsible for handling it. It is the compliance task that gets done because a specific person has always done it. The escalation that works because the right two people happen to know each other. The process that runs smoothly in normal conditions but has no formal owner, no documented workflow, and no resilience when circumstances change.

In 2026, with regulatory expectations rising, talent markets remaining structurally constrained, and boards under increasing pressure to demonstrate active oversight of material controls, accountability in UK operating models has moved from a governance nicety to a business-critical requirement. The firms that understand this and act on it are building genuine operational resilience. Those that do not are carrying a risk they have not yet measured.

What Assumed Accountability Actually Looks Like

Assumed accountability is rarely the result of negligence or poor intent. It is almost always the product of organisations that have grown faster than their process architecture, or that have relied on capable individuals to hold things together in ways that were never formally designed or documented.

It looks like this: a compliance function that works because one experienced professional knows every nuance of the requirement, but where that knowledge has never been written down. A client reporting process that runs reliably because a specific team member has always managed it, but where the steps exist only in their head. An escalation pathway that resolves issues efficiently because the right relationships exist informally, but where there is no documented procedure that would survive the departure of those individuals.

In each case, the work gets done. In normal conditions, assumed accountability is invisible. It produces outcomes that look like structured delivery but are actually the product of individual commitment and institutional memory rather than designed process.

The problem is not that the work is being done. The problem is that accountability for doing it is not structural. It is personal. And personal accountability, however reliable, is inherently fragile.

Why It Is So Hard to Spot

The reason assumed accountability persists in so many UK operating models is that it is genuinely difficult to identify until something goes wrong.

When a capable person holds a process together informally, the output looks the same as it would from a well-documented, properly governed workflow. The reports arrive on time. The compliance tasks are completed. The escalations are resolved. From the outside, and often from the inside too, everything appears to be working.

The gap only becomes visible when the person is absent, overloaded, or when they leave. At that point, what appeared to be a functioning process reveals itself to be a dependency. And the question that follows, who is responsible for this now, is the moment at which assumed accountability becomes an operational problem.

This is what makes it a silent risk. Unlike a compliance failure or a system outage, assumed accountability does not trigger an alert. It compounds gradually, becoming more deeply embedded in the operating model with every year that passes without a formal review of how work is actually governed, owned, and delivered.

The Key Person Dependency Problem

The most visible manifestation of assumed accountability is key person dependency: the condition in which an organisation’s operational performance in a given area is disproportionately dependent on the presence and performance of one or a small number of individuals.

According to research by the Society for Human Resource Management, 72% of companies report having at least one employee whose sudden departure would significantly impact their operations. The financial cost of losing such an individual can range from 100% to 300% of their annual salary, according to the National Association of Insurance Commissioners, accounting for recruitment, training, and the productivity lost during transition.

In the UK context, where the average cost of replacing an employee earning £25,000 or more is estimated at £30,614 by Oxford Economics, and where annual staff turnover runs at approximately 15% according to CIPD data, key person dependency is not an abstract concern. It is a live operational risk that many firms are carrying without formally acknowledging it.

For senior or specialist roles, replacement costs can reach 150% to 200% of annual salary. For executive positions, the figure can exceed 200%. But the financial cost of replacement is only part of the picture. The more significant operational cost is the knowledge and process continuity that is lost when an individual who has been carrying accountability informally is no longer there. That loss does not appear on a balance sheet. It appears in delivery failures, compliance gaps, and the slow unravelling of processes that were never properly documented.

The Regulatory Dimension: When Assumed Accountability Becomes a Compliance Risk

For UK firms operating in regulated industries, assumed accountability carries a dimension beyond operational risk. It creates direct compliance exposure.

Across financial services, legal, property management, and professional services, the regulatory expectation in 2026 is not simply that firms are compliant. It is that they can demonstrate how they are compliant: with documented processes, clear ownership at every level, structured escalation pathways, and audit trails that reflect what actually happened rather than what should have happened.

The FCA’s operational resilience framework, which required in-scope firms to demonstrate by 31 March 2025 that they could remain within defined impact tolerances for each important business service, is explicit on this point. Regulators expect firms to have assigned accountable owners to each important business service, not just to have identified those services. Guidance from the FCA, PRA, and CMORG is clear that complex, siloed delivery models lead to gaps in understanding the resilience of business services, and that nominating a single accountable owner is often the optimal approach to closing those gaps.

In practice, this means that a firm whose compliance processes work because a knowledgeable individual manages them informally is not in a position to demonstrate the kind of structured, evidenced accountability that regulators are now looking for. The process may be delivering good outcomes. But if those outcomes cannot be evidenced through documented ownership and formal process governance, the firm is carrying regulatory exposure that the quality of its actual performance does not reflect.

The UK Corporate Governance Code: Accountability Is Now a Board-Level Obligation

The revised UK Corporate Governance Code, which introduced significant updates to board accountability requirements with provisions taking effect from 2025 and 2026, has elevated the accountability conversation to the highest level of UK organisations.

Provision 29 of the revised Code requires boards of premium-listed companies to make an annual declaration on the effectiveness of material controls, covering financial, operational, reporting, and compliance controls. This is not a documentation exercise. It is a substantive obligation to demonstrate that boards have actively assessed, tested, and evidenced the effectiveness of the controls their organisations rely on.

As PwC has noted in its guidance on the revised Code, vague or unsupported claims will invite board pushback, investor concern, and auditor attention. Directors who sign off on declarations that are not supported by genuine evidence of effective governance will face increasing scrutiny.

For firms where operational accountability is assumed rather than structured, meeting this obligation is not straightforward. A declaration that material controls are effective requires knowing, with confidence, who owns each control, how it is being monitored, and how it performs under pressure. Assumed accountability makes that confidence impossible to justify.

Where Operational Resilience Requirements Are Raising the Bar

The FCA and PRA’s operational resilience framework provides a particularly clear illustration of where accountability expectations have moved.

The framework requires in-scope firms to have mapped the resources required to deliver each important business service, assigned ownership at a governance level, conducted scenario testing to assess resilience under disruption, and produced evidence of that testing that goes beyond static documentation. From 2025 onwards, regulators are looking not just at whether firms have completed the required paperwork but at whether the accountability structures they describe hold up when conditions change.

This is a materially higher standard than many firms have historically operated to. And it is one that assumed accountability simply cannot meet. A process that works because of informal knowledge and individual commitment will not produce the kind of documented, tested, evidenced resilience that regulators are now looking for.

The firms that are performing well under the operational resilience framework share a common characteristic: they have made accountability structural. Ownership is assigned formally, processes are documented, testing is conducted against defined tolerances, and the results are reported to boards and governing bodies in a way that supports genuine oversight rather than nominal sign-off.

The Cost of Getting This Wrong

The operational and financial cost of assumed accountability revealing itself under pressure is difficult to quantify precisely, because it manifests differently in different organisations. But the components are consistent.

There is the direct cost of operational failure when a key individual is unavailable: delivery gaps, missed deadlines, compliance errors, and the management time required to resolve problems that a structured process would have prevented. There is the reputational cost with clients and regulators, which in regulated industries can carry consequences that far exceed the immediate operational impact. And there is the cost of remediation: building the process architecture retrospectively, under pressure, that should have been built proactively.

For UK firms in financial services, the cost of compliance failure has become increasingly concrete. The FCA’s focus on evidenced governance means that firms whose internal controls rely on assumed accountability face meaningful regulatory risk. Under the UK Corporate Governance Code, boards that cannot demonstrate genuine oversight of material controls face scrutiny from auditors, investors, and regulators simultaneously.

The cost of addressing assumed accountability proactively, through process documentation, formal ownership assignment, and structured governance, is consistently lower than the cost of addressing it reactively after a failure has occurred. The challenge is that the former requires deliberate investment in something that is not visibly broken. The latter feels urgent and unavoidable.

Building Structural Accountability: What It Looks Like in Practice

Addressing assumed accountability is not primarily a technology problem or a staffing problem. It is a design problem. And like most design problems, it requires a deliberate, structured approach rather than a reactive one.

The starting point is visibility. Before accountability can be made structural, it is necessary to understand where it is currently assumed. That means mapping how work actually flows through the business, not how it appears on the organisation chart, but how it moves in practice. Who manages what? Where do decisions actually get made? Which processes depend on specific individuals being present and engaged? Where are the informal escalation pathways that work because of relationships rather than procedure?

This kind of mapping is uncomfortable, because it typically reveals a gap between the organisation that exists on paper and the one that actually operates. But it is the necessary foundation for everything that follows.

From that foundation, structural accountability is built through three core mechanisms. First, formal process ownership: every material process has a named owner, with documented responsibility for delivery, monitoring, and escalation. Not assumed responsibility, not shared responsibility that belongs to no one in practice, but explicit, single-point ownership that is recorded and reviewed.

Second, documented workflows: the steps required to complete each material process are written down in sufficient detail that a competent person who had not previously performed the task could do so. This is not bureaucratic over-engineering. It is the minimum documentation standard required to make a process resilient.

Third, governance and oversight: a reporting structure that makes the performance of material processes visible to the right level of leadership, with defined triggers for escalation and a review cadence that ensures accountability remains active rather than nominal.

The Role of BPO in Closing Accountability Gaps

Business process outsourcing, when it is designed and governed properly, plays a specific and valuable role in addressing assumed accountability.

The most effective BPO relationships are not simply about moving work to a lower-cost environment. They are about building the process architecture, formal ownership frameworks, and governance structures that structural accountability requires. Because BPO engagements, by their nature, require processes to be documented and agreed before work begins, they create the opportunity to design accountability into the operating model from the outset, rather than having it accumulate informally over time.

For UK firms that have grown their operations faster than their process governance has kept pace, a well-structured BPO partnership can provide both the capacity to absorb operational work and the discipline to ensure that work is governed, evidenced, and owned in a way that holds up under scrutiny.

This matters particularly in regulated industries where the accountability expectations of the FCA, PRA, and other UK regulators are explicit and increasingly enforced. BPO partners who understand the governance requirements of those industries, and who build their delivery models around them, add value that goes beyond task completion.

At Alpha BPO, the operating principle is simple: accountability should be built into how work is designed, not assumed from how it has historically been managed. That principle shapes how we approach every client engagement, from the initial process mapping and documentation phase through to the reporting structures and governance frameworks that make ongoing oversight possible.

Conclusion

Assumed accountability is one of the most widespread and least examined risks in UK operating models. It does not appear on most risk registers. It does not generate alerts. It accumulates quietly, in the informal processes and individual dependencies that many organisations have allowed to develop in place of structured governance.

In 2026, the cost of carrying this risk is rising. Regulatory expectations, from the FCA’s operational resilience framework to the revised UK Corporate Governance Code, now require boards and senior leadership to demonstrate active, evidenced oversight of material controls. The standard is not whether processes are delivering acceptable outcomes in normal conditions. It is whether accountability is structural, documented, and capable of surviving the pressures that abnormal conditions create.

The firms building genuine operational resilience are the ones that have looked honestly at where accountability is assumed in their operating model and invested in making it structural. That investment requires deliberate effort, and it is rarely urgent until suddenly it is. But the gap between addressing it proactively and addressing it reactively is measured in operational failures, regulatory findings, and the reputational cost of a business that could not demonstrate it was in control.

Assumed accountability is a silent risk. But silence, in a regulatory environment that expects demonstrated governance, is no longer a defensible position.

At Alpha BPO, we help UK professional services firms and financial services organisations build the process governance, formal ownership frameworks, and structured accountability that consistent, evidenced operational performance requires. If ownership gaps in your operating model are a concern, we would welcome the conversation.

Sources and Outbound Links

Published On: 4 June, 2026