Skills Development, Succession and Key-Person Dependency
Within the CGEIT domain of IT Resources (resource optimization), people are treated as a critical enterprise asset that governance must deliberately manage, alongside infrastructure, applications and information. Skills development, succession planning and key-person dependency management help ensu… Within the CGEIT domain of IT Resources (resource optimization), people are treated as a critical enterprise asset that governance must deliberately manage, alongside infrastructure, applications and information. Skills development, succession planning and key-person dependency management help ensure that the enterprise has the human capability needed to deliver IT-enabled value, both now and in the future. Skills Development: The board and executive management must ensure that IT staff and business users have the competencies needed to achieve strategic objectives. Governance practices include conducting periodic skills inventories and gap analyses against the IT strategy, defining competency frameworks such as SFIA or e-CF, and funding training, certification, mentoring and job rotation. COBIT objectives such as APO07 (Managed Human Resources) and APO01 support this by requiring skills to be planned, monitored and aligned with enterprise goals. Effective skills development also covers decisions about whether to build capabilities internally or acquire them through sourcing partners. Succession Planning: Governance requires that critical IT leadership and specialist roles, such as the CIO, enterprise architect or security lead, have identified and prepared successors. This involves talent assessment, development plans for high-potential staff, documented role profiles and regular review by HR and senior management. Succession planning protects strategic continuity, preserves institutional knowledge and reduces disruption during turnover, retirement or reorganization. Key-Person Dependency: This is the risk that essential knowledge, skills or system access is concentrated in one individual or a small group, creating a single point of failure. Governance responses include cross-training, documentation of procedures and architectures, knowledge-management repositories, segregation of duties, mandatory vacations, backup staffing and retention incentives. These dependencies should be recorded in the IT risk register and reported to risk owners. Together, these practices support benefits realization and risk optimization. They ensure that human resources are adequate, resilient and aligned with business needs, and that the enterprise can sustain IT services despite staff changes.
Skills Development, Succession and Key-Person Dependency (CGEIT – IT Resources)
Introduction
In the CGEIT (Certified in the Governance of Enterprise IT) body of knowledge, people are treated as one of the most critical IT resources. They sit alongside infrastructure, applications and information. Skills Development, Succession and Key-Person Dependency is the governance discipline that keeps the enterprise able to deliver IT-enabled value over time. It does this by building the right competencies, planning for leadership and role continuity, and reducing the risk of relying too heavily on a few individuals.
Why It Is Important
1. Value delivery depends on capability. Strategic IT investments only produce benefits if the organization has people with the skills to design, implement, operate and improve the solutions.
2. Risk optimization. Losing a key person through resignation, illness, retirement or poaching can halt critical operations, delay projects and expose the enterprise to security and compliance failures. Key-person dependency is a recognized IT risk scenario in COBIT and risk frameworks.
3. Resource optimization. Governance requires that resources be adequate, appropriate and used efficiently. Skills gaps lead to overreliance on expensive contractors, rework and poor decisions.
4. Business continuity and resilience. Knowledge held only in someone's head is a single point of failure, just like an unreplicated server.
5. Strategic agility. New technologies such as cloud, AI and cybersecurity tools require continuous reskilling. Without planned development, the enterprise cannot execute its digital strategy.
6. Regulatory and stakeholder expectations. Boards, auditors and regulators increasingly expect evidence of workforce planning, segregation of duties and continuity of critical roles.
What It Is
Skills Development is the systematic identification, acquisition and maintenance of the competencies the IT function and business need, both now and in the future. It includes:
- Skills inventories
- Competency frameworks such as SFIA (Skills Framework for the Information Age) and e-CF
- Gap analysis
- Training, certification, mentoring and job rotation
Succession Planning is the proactive identification and preparation of potential successors for critical roles, especially leadership positions such as the CIO, CISO and enterprise architect, and specialist positions. Its goal is to ensure continuity when incumbents leave.
Key-Person Dependency is the risk that arises when critical knowledge, authority, relationships or skills are concentrated in one or a few individuals. Their unavailability would significantly impair operations or the achievement of objectives. This applies to both internal staff and vendor or contractor personnel.
Relevant Framework Context
- COBIT 2019, especially APO07 Managed Human Resources, which covers:
- maintaining adequate and appropriate staffing
- identifying key IT personnel
- maintaining the skills and competencies of personnel
- assessing and recognizing employee job performance
- planning and tracking the usage of IT and business human resources
- managing contract staff
- EDM04 Ensured Resource Optimization, where the board evaluates, directs and monitors resource capability, including people.
- People, Skills and Competencies is one of the seven COBIT components (enablers).
How It Works
Step 1: Align with strategy. Derive future skill requirements from the business and IT strategy, the enterprise architecture roadmap and the project portfolio. Ask: what capabilities will we need in 1, 3 and 5 years?
Step 2: Build a skills inventory and competency model. Document current skills, proficiency levels and certifications against a standard framework. This creates a baseline.
Step 3: Perform gap analysis. Compare required versus available competencies. Prioritize gaps by business impact and risk.
Step 4: Choose sourcing strategies. Close gaps through one or more of these:
- Build: training, certification, mentoring
- Buy: recruitment
- Borrow: contractors, outsourcing, partners
- Bot: automation
Governance chooses based on cost, speed, risk and strategic importance. Core and strategic capabilities are usually retained in-house.
Step 5: Identify critical roles and key persons. Use criteria such as:
- uniqueness of knowledge
- impact of absence
- difficulty of replacement
- access to sensitive systems
- vendor relationship ownership
Step 6: Mitigate key-person dependency. Controls include:
- Documentation of procedures, configurations and architecture
- Knowledge management repositories and wikis
- Cross-training and job rotation
- Backup or deputy assignments
- Mandatory vacations, which also act as a fraud-detection control
- Pair working and shadowing
- Segregation of duties
- Retention incentives for critical staff
- Contractual clauses for vendor key personnel, such as named resources, replacement terms and knowledge transfer obligations
- Escrow and knowledge-transfer requirements at contract exit
Step 7: Succession planning.
- Identify ready-now and ready-later successors for each critical role.
- Create individual development plans.
- Use talent reviews.
- Record interim emergency successors.
- Review the plan at least annually.
Step 8: Monitor and measure. Example metrics include:
- percentage of critical roles with identified successors
- number of single points of knowledge
- training hours and certification rates against plan
- skills gap closure rate
- turnover of key staff
- time to fill critical vacancies
- dependency on contractors for core functions
Report these to IT steering committees and the board.
Step 9: Integrate with risk and continuity management. Record key-person risk in the IT risk register. Include personnel unavailability in BCP and DRP scenarios.
Roles and Responsibilities
- Board / governance body: Directs that human resource capability supports strategy, approves policy and monitors results (EDM04).
- Executive management / CIO: Accountable for workforce planning, succession and capability building.
- HR: Partners on recruitment, development programs, retention and succession processes.
- Line managers: Identify key persons, enforce cross-training and maintain documentation.
- Risk management and internal audit: Assess and provide assurance over people-related risks.
Common Pitfalls
- Treating training as a cost to cut rather than an investment.
- Succession plans that exist only for the CEO and not for critical IT roles.
- Relying on a long-tenured administrator who is the only person who knows a legacy system.
- Outsourcing core knowledge without retaining enough in-house expertise to manage the vendor, which leads to loss of intelligent customer capability.
- Not aligning skills plans with the strategic roadmap.
Exam Tips: Answering Questions on Skills Development, Succession and Key-Person Dependency
1. Think like a governance professional, not a technician. CGEIT answers favor strategic, enterprise-wide, sustainable solutions. Avoid quick fixes such as giving the key person a raise as the sole remedy.
2. Alignment with strategy comes first. If asked what should be done FIRST when developing a skills program, the answer is usually to identify required competencies based on the business and IT strategy, or to perform a gap analysis against them. Buying training comes later.
3. The best mitigation for key-person dependency is usually a combination of cross-training, documentation and knowledge management, plus succession planning. Look for answers that remove the single point of failure rather than merely retain the person.
4. The greatest risk in scenarios where one person maintains a critical system is typically loss of knowledge and operational continuity. If that person also has excessive access, a segregation-of-duties or fraud risk applies too.
5. Mandatory vacations and job rotation serve two purposes: they reduce dependency and they detect irregularities. Recognize this in questions.
6. Outsourcing questions: the enterprise retains accountability. The best answer often involves retaining in-house skills to oversee the vendor and adding contractual knowledge-transfer and key-personnel clauses.
7. Prefer measurable and monitored answers. When asked how the board knows the program is effective, choose metrics and KPIs reported regularly, such as the percentage of critical roles with successors.
8. Accountability wording matters.
- The board directs and monitors.
- Executive management is accountable for implementation.
- HR supports.
- Do not choose HR as ultimately accountable for IT capability.
9. Link to risk management. Key-person risk should be in the risk register and addressed in business continuity planning. Answers integrating people risk into enterprise risk management are strong.
10. Watch for keywords:
- MOST important, BEST, FIRST, PRIMARY
- The PRIMARY purpose of succession planning is ensuring continuity of critical roles and leadership. Cost reduction and employee morale are not the primary purpose.
11. Eliminate reactive answers. Options like hiring a replacement after the person leaves or terminating the employee are rarely correct. Proactive, preventive governance is preferred.
12. Recognize COBIT references. APO07 relates to human resources, EDM04 to resource optimization, and People, Skills and Competencies is a COBIT component. Linking a scenario to the right process helps eliminate distractors.
Sample Question
An organization discovers that only one senior engineer understands its core legacy billing system. What should the IT steering committee recommend FIRST?
A) Increase the engineer's salary to ensure retention
B) Replace the legacy system immediately
C) Assess the risk and implement documentation, cross-training and succession for the role
D) Outsource the system support
Answer: C. It addresses the root cause, the single point of knowledge, through structured, sustainable governance controls. A is a short-term retention tactic. B is an overreaction without analysis. D transfers the dependency to a vendor without resolving it.
Summary
Skills development ensures the enterprise has the capabilities its strategy requires. Succession planning ensures continuity of critical roles. Managing key-person dependency removes human single points of failure. In the exam, choose answers that are strategic, proactive, risk-based and aligned with business objectives.
Unlock Premium Access
Certified in the Governance of Enterprise IT
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 2995 Superior-grade Certified in the Governance of Enterprise IT practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- CGEIT: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!