Introducing FACILEX® ATOMIC nuclear quality assurance software for small modular reactors, fusion and advanced fission. 

Bus Factor One: When Critical Safety Systems Depend on a Single Individual

A Bus Factor of One means that a single individual possesses so much knowledge that the organization’s ability to maintain, support, or evolve the system depends almost entirely upon them.

The term “Bus Factor” originates from the software industry. It refers to the number of people whose sudden absence would place a project or system at serious risk. 

A Bus Factor of One means that a single individual possesses so much knowledge that the organization’s ability to maintain, support, or evolve the system depends almost entirely upon them. 

While the name may sound informal, the risk is very real.  In many industrial organizations, critical Process Safety Management systems operate with exactly this type of vulnerability.

The Hidden Vulnerability in Many Legacy Systems

Many organizations have deployed point solutions for:

  • Management of Change
  • Process Hazard Analysis
  • Incident Investigations
  • Action Items
  • Audits
  • Process Safety Information 
  • Training

Over time, customizations are added, integrations are developed, reports are modified, and business rules become embedded within the various solutions.

Unfortunately, documentation rarely keeps pace with these changes.  As a result, practical knowledge becomes concentrated within a small group of individuals, or in some cases, a single person.  The organization gradually becomes dependent on that individual’s experience rather than on documented processes and maintainable architecture.

Why Process Safety Leaders Should Care

A Process Safety Management platform supports critical business processes that directly influence operational risk.  If key personnel leave unexpectedly, organizations may find themselves unable to provide:

  • User support and access to information
  • Monitoring and backup 
  • Updates and upgrades
  • System security  
  • System recovery

What begins as an IT dependency can quickly become an operational constraint.

The Illusion of Stability

One of the reasons Bus Factor risk remains hidden is that systems often appear stable. The platform is running.  Users can log in. Reports are being generated. Management assumes everything is under control. However, stability does not necessarily indicate resilience.

Many organizations discover their Bus Factor only when one of the following events occurs:

  • Retirement.
  • Resignation.
  • Internal transfer.
  • Medical leave.
  • Acquisition or restructuring.
  • Major system upgrade.
  • Cybersecurity incident.

Suddenly, the organization realizes that years of accumulated knowledge were never documented or transferred.  The system worked because a specific individual knew how to keep it working.

Applying Risk-Based Thinking to Information Systems

Process safety professionals routinely evaluate safeguards and failure scenarios. The same approach can be applied to information systems.

Ask the following questions:

  • How many people fully understand our system architecture?
  • How many people could restore the system after a major failure?
  • How many people understand our customizations?
  • How many people can administer user permissions?
  • How many people can support an upgrade?

If the answer to most of these questions is “one person,” the organization may have identified a significant operational risk.  From a process safety perspective, this is simply another form of single-point dependency.

Increasing Your Bus Factor

Fortunately, reducing Bus Factor risk does not always require replacing existing systems.

Organizations can improve resilience by:

Documenting Critical Knowledge

System architecture, configuration decisions, integrations, and recovery procedures should be maintained as living documents rather than tribal knowledge.

Cross-Training Personnel

Knowledge should be shared across multiple individuals and departments. The goal is not redundancy in job titles but redundancy in capability.

Standardizing Platforms

Highly customized environments often become difficult to support because knowledge remains locked within the minds of a few specialists. Standardized architecture reduces dependence on individual expertise.

Modernizing Aging Systems

Legacy technologies frequently suffer from shrinking support communities and declining availability of qualified resources. Modernization can improve both technical supportability and organizational resilience.

Partnering Strategically

Organizations should ensure that critical system knowledge exists beyond their own walls. Vendor support teams, implementation partners, and managed service providers can provide additional depth and continuity.

Share:

More Posts

Does AI Deliver Differentiated Value—or Just Accelerate What Already Exists?

Artificial intelligence is now embedded in nearly every digital strategy. Vendors promise efficiency, insight, and competitive advantage. Boards ask whether the organization has an AI roadmap. Executives ask how quickly AI can be deployed.  The more important question is rarely asked: Is AI providing differentiated value that justifies its use?