How to assess whether a target depends dangerously on a handful of individuals, why key person risk is hard to quantify, and how to flag it in an FDD report.
A business can post a flawless five-year EBITDA growth trend and still be a fragile asset if that performance rests entirely on one person who might walk the day after completion. Key person risk is one of the trickiest findings in financial due diligence: it rarely reduces to a clean number, yet it can move a deal's structure, its price, and occasionally the decision to proceed at all. Get comfortable articulating it clearly and you will stand out, because most junior analysts either miss it or bury it in a footnote.
The textbook version is the founder-led business where one individual personally owns the key customer relationships, signs off every meaningful operational decision, and has never genuinely delegated authority. On the org chart there is a management team; in practice, the business is the founder plus some supporting infrastructure. Strip the founder out and you are not left with a smaller version of the same company - you are left with something materially different.
The less obvious versions are the ones that catch buyers out. A single technical lead who holds critical product or system knowledge that lives nowhere but in their head. A lead salesperson who personally controls the relationships with the handful of accounts that make up the bulk of revenue. A finance director who is the only person who understands how the numbers actually knit together. None of these people appear risky on a P&L. All of them are single points of failure.
The test that matters: if this individual resigned on Monday with no notice, how much of next year's revenue and margin would you genuinely worry about? If the honest answer is "a lot", you have found key person risk, whatever the org chart says.
Most FDD findings resolve to a figure. A net debt item is a euro amount. A working capital peg is a number you can argue over. Even a contingent liability can be probability-weighted into an expected value. Key person risk resists that treatment because it is a judgement about what happens to future performance if a specific person leaves - and that depends on factors you can observe (management depth, documentation, how customer relationships are structured) crossed with factors you can never fully know (whether the individual will actually stay, and how the business would truly cope without them).
This is precisely why key person risk is usually managed contractually rather than as a numbers adjustment. A seller staying on through an earn-out period, a founder rolling meaningful equity into the new structure, retention packages tied to defined milestones - these are all mechanisms designed to mitigate the risk rather than simply price it in. As a TS analyst your job is not to produce a spurious "€3.2m key person adjustment". It is to characterise the risk sharply enough that the deal team can choose the right mechanism.
You cannot produce a precise number, but you can and should frame the exposure so the buyer grasps the magnitude. Here is the kind of simple exposure map that belongs in a report appendix or a call.
| Individual | Role | Revenue influenced | Documented / delegable? | Exposure if they leave |
|---|---|---|---|---|
| Founder / CEO | Top-5 customer relationships | €6.0m (40% of revenue) | Largely undocumented | High |
| Technical lead | Core platform knowledge | Indirect - supports all revenue | Poorly documented | High |
| Sales director | Mid-market pipeline | €3.0m (20%) | Partially institutionalised | Medium |
| FD | Reporting & controls | None directly | Documented, deputy exists | Low |
On €15m of revenue, roughly 60% is influenced by two undocumented individuals. You are not claiming 60% of revenue disappears if they leave - that would be lazy and wrong. You are showing the buyer that the majority of the revenue base is exposed to two retention decisions, which is exactly the insight that drives whether they demand a two-year earn-out and a beefy retention pool. That framing is far more useful than a false-precision figure. It also connects directly to your revenue quality work, where relationship-owned revenue scores lower than institutionalised revenue.
Key person risk is not a standalone workstream that lives in a box of its own. It threads through several of the areas you are already covering, and the sharpest reports surface it inside those sections rather than bolting on a disconnected paragraph.
Practical signals, in rough order of how much they tell you:
None of these has a clean numerical answer. But consistently poor signals across several of them should meaningfully raise your concern level and the prominence you give the finding.
Watch for these in the target, and avoid these in your own work.
Red flags in the target:
Common mistakes analysts make:
Interviewers love this topic because it separates candidates who can only chase numbers from those who understand what a buyer actually worries about. Expect something like: "You're doing FDD on a founder-led business with strong EBITDA growth. What would concern you about relying on that track record?"
"My first concern would be whether that growth is institutionalised or whether it lives in the founder. I'd look at how the top customer relationships are held - if the founder personally owns the largest accounts and there's no account management layer beneath them, then a big chunk of revenue is really a bet on the founder staying. I'd sanity-check that against the org chart for genuine depth, and against the data room for documented processes versus knowledge that only exists in a few people's heads. I wouldn't try to put a precise number on it, because I can't reliably predict retention - but I would size the exposure, for instance flagging that, say, 40% of revenue routes through one undocumented relationship. Then I'd frame it for the deal team as a structuring question: this is the kind of risk you address with an earn-out, an equity rollover, or a retention package rather than a price chip. And I'd tie it back to revenue quality, because relationship-owned revenue is lower quality than institutionalised revenue even before anyone leaves."
That answer works because it shows judgement, connects the finding to revenue quality and deal structure, and resists the temptation to invent false precision. If you can also name the mitigants, you sound like someone who has sat on a live deal.
Key person risk is exactly the kind of finding that gets under-weighted because it does not arrive with a clean dollar figure the way a QoE adjustment does. Resist that instinct hard. A clear, well-evidenced discussion of key person risk - even absent a precise valuation impact - hands the buyer genuinely decision-relevant information: whether to demand retention packages, how to structure an earn-out, how long a transition period needs to be, and in extreme cases whether the asset is as valuable as the numbers suggest. A report that quietly omits it because it was awkward to quantify has failed the client on one of the questions they most needed answered.
The best FDD analysts understand that the buyer is not really buying last year's EBITDA. They are buying the continuation of it - and continuation is exactly what key person risk threatens. Surface it plainly, size the exposure without faking a number, tie it to revenue quality and deal structure, and you will have written the paragraph the deal team actually reads twice.
The Transaction Services Interview Programme (€119.99, one-time) includes a dedicated module on qualitative findings that resist quantification - key person risk, customer concentration, and revenue quality - with model interview answers and a framework for sizing exposure without inventing false precision. Enrol today.
Hundreds of candidates prepared their interviews with this programme. Those who landed the role have one thing in common: they worked the cases before walking into the room.