Start-up Guide / Governance

Keep control as you grow

Make it clear who owns what, who decides and who steps in when something goes wrong.

You don’t need a large team to lose track of accounts, suppliers or responsibilities. Here’s how to put enough structure in place to keep control as the business changes.

Make responsibilities clear

Governance means deciding who is responsible, how decisions get made and what happens when something goes wrong. In a small team, a short set of shared rules can go a long way.

The aim is to make the business easier to run. Add detail where the risks need it; keep everyday instructions easy to find and follow.

Know what needs an owner

Give each important system or activity a named owner. One person can cover several areas, but “everyone looks after it” is hard to act on when something breaks.

A starting point for assigning responsibility
AreaThe owner should know
Accounts and accessWho can sign in, who has admin access and how to remove or recover it.
Business dataWhere it lives, who can use it, how long it is kept and how to recover it.
Security and incidentsWhat protections are expected and who coordinates a response.
SuppliersWhat each provider does, what they control and how to leave.
ComplianceWhich obligations apply, who checks them and when specialist advice is needed.

Write rules people can follow

Start with account access, passwords and MFA, device use, data handling, software updates and use of AI tools. For each, explain the rule, who owns it and what to do if it cannot be followed.

A short instruction that people use is more useful than a long document nobody opens. Keep the current version somewhere the whole team can find it.

Make risks visible

List the most likely or most damaging problems, their likelihood and impact, and what you are doing about them. Assign an owner and a review date. This is the start of a risk register.

Company access should survive one person leaving. Use delegated access or a documented recovery route; this does not mean giving everyone administrator permissions.

Know what to do when something goes wrong

A lost laptop, exposed password or unavailable system needs a clear response. Decide who coordinates it and where people should report problems before an incident happens.

A simple response plan needs to cover
  1. ReportHow alerts and concerns reach the right person.
  2. CoordinateWho assesses the impact and gets help.
  3. RespondHow to contain the problem and restore service safely.
  4. ReviewWhat happened and what needs to change.

Keep a record of events and changes. Include how you would communicate with the team, customers or others affected, and who checks whether any reporting obligations apply. The response will depend on the incident; this is a planning outline.

The NCSC’s response and recovery guidance gives small organisations a practical starting point.

Keep control when suppliers help

Before granting access, agree what a supplier will do, which systems they need and how long access should last. Give individual accounts with the permissions needed for the work.

If changing supplier would leave you unable to run your own systems, address the access and handover gaps while the relationship is still working.

Know what personal data you hold

Start with an inventory: what personal data you collect, why you need it, where it is stored, who can access it and how long you keep it.

Your obligations depend on the data, activities and where you operate. Small teams can have responsibilities from the outset. Use the ICO’s small-organisation guidance for UK personal-data work, and get specialist advice when requirements are unclear or the data is sensitive.

Review the arrangements as you grow

Revisit responsibilities when someone joins or leaves, you add a supplier, or the business starts handling different data. Schedule access and policy reviews too, so changes do not depend on someone noticing a problem.

  • New people: can they find the rules and the person responsible?
  • New systems: are ownership, access and recovery recorded?
  • New risks: do existing controls still fit the work?

Unclear ownership and important changes without review are signs that the arrangements need attention.

Get help with the gaps

If nobody can explain who controls key systems, or a supplier holds access the company cannot recover, I can help establish what needs attention and put practical arrangements in place.

See how I help with fragile systems.

Get professional advice