Why ‘we’ll figure it out’ is not a good plan

Most SMEs and NFPs do not fail because the idea was wrong. They fail, stall or their people get hurt because the way the business actually runs lives in one person’s head instead of in a formal document anyone can pick up and follow. That gap between what they do and what is written down is where cost, risk and lost growth occur.

This article looks at what happens when policies, procedures and important plans are missing, why that generic template downloaded last year probably will not save you, and why things like a business disruption or emergency management plan are not a compliance box-tick but a genuine competitive advantage.

What we actually mean by policies, procedures and plans

The three terms get used interchangeably, but they do different jobs.

  • A policy sets the rule: what the organisation will and will not do, and why.

  • A procedure sets the method: the exact steps someone follows to apply that policy consistently.

  • A plan sets the response: what happens, who does what, and in what order, when a specific situation arises, such as a system outage, a key person leaving, a natural disaster or a data breach.

Together they turn how a business is run, from something one founder or manager carries around in their head, into something the whole team can execute the same way each time, whether or not that leader is in the room.

The disadvantages and risks of having none

Everything routes through one person

When processes are not documented, the business becomes dependent on whoever happens to know how things work. That person cannot take leave without being contactable, cannot be promoted without leaving a gap behind them, and cannot be replaced without a painful and expensive rebuild of institutional knowledge. This is the single most common risk BusinessRx sees in businesses where they have outgrown what that one person can hold in their head, and nothing has been built to replace that dependency.

Decisions become inconsistent

Without a written policy, two managers could make two different calls on the same situation, whether that is a customer refund, a leave request or a supplier dispute. Inconsistency erodes trust with staff and customers alike, and it is very hard to defend in a dispute or a performance conversation when there was never a documented standard to apply.

Onboarding takes far longer than it should

New staff learn by shadowing someone rather than by following a written process, which means ramp-up time blows out and quality varies depending on who trained them. Learning from someone who never had a great handle on what to do in the first place, or simply learnt wrong, is not ideal and every new hire effectively has to reinvent the wheel.

Compliance and insurance exposure increases

Many obligations, work health and safety, privacy, industry-specific licensing, expect the organisation to be able to produce a documented policy and evidence that it is followed, not just a verbal assurance that we do the right thing. In an incident, insurers, regulators and courts will ask what was documented at the time, not what everyone intended to do.

There is no way to respond well under pressure

This can be one of the biggest risks of all. When something goes wrong, a system outage, a fire, flood or other natural event, the sudden loss of a key person, a cyber incident, a business without a plan does not calmly execute a response. It improvises, under stress, in real time, often with the person who best understood the risk unavailable or overwhelmed. Decisions made in that state are slower, more expensive, more dangerous, and more likely to make the situation worse.

Growth stalls rather than accelerates

Founders who want to step back from day-to-day operations, bring on a manager, franchise, sell the business or simply take a genuine holiday cannot do any of it while the operation only runs properly with them personally driving it.

Why off-the-shelf templates do not fix this

A generic policy or procedure template downloaded from the internet feels like progress. In practice it usually creates a different problem: the appearance of governance without the substance of it.

Generic or template policies do not reflect how the business actually operates

A template is written for an average business in an average industry. It will not match your actual approval chain, your actual software stack, your actual staffing structure, your actual day-to-day way of working, or the specific risks of your industry, whether that is a company that manages large public gatherings, a business managing seasonal and physical hazards, or a people service provider managing vulnerable clients.

Staff do not follow what does not match reality

If a procedure describes a process that is not how the team actually works, people simply stop following it. The document exists, technically, but it has no operational value and provides no real protection.

It creates false confidence

Having a folder of downloaded policies can feel like the risk is covered. It is not. In an audit, an insurance claim or a legal dispute, a generic document that was never adapted, never trained on, never reviewed or updated, and never actually followed is often worse than having nothing, because it demonstrates the organisation knew a standard existed and did not implement it properly.

It misses what makes your risk profile unique

A generic emergency plan will not account for your specific single points of failure: the one team member who holds a critical relationship or piece of knowledge, the one supplier you cannot easily replace, the specific physical or seasonal risks of your location and industry.

It is rarely maintained

A template downloaded once and never revisited becomes outdated the moment the business changes its systems, structure or regulatory environment, which for a growing organisation is constantly.

The alternative is not necessarily a longer document. It is a document built from how the organisation actually runs, tested against real scenarios, and owned by someone accountable for keeping it current.

Why business disruption and emergency management plans benefit everyone

Business disruption and emergency management plans are often the first things cut from the to-do list because the risk feels theoretical, until it is not. The organisations that recover fastest from a serious disruption are almost never the ones improvising well. They are the ones who had already answered the hard questions before they needed the answers.

  • For the owner or MD, a tested plan means a genuine ability to step back, take leave or focus on strategy, because the business can respond to a crisis without the business leader personally holding every answer.

  • For leadership and managers, a plan removes the guesswork under pressure. It sets out who has authority to make which decisions, what the communication chain looks like, and what the situation should look like in the first hours of a disruption.

  • For staff, a plan is protective rather than bureaucratic. It tells people what is expected of them, keeps them safer in a genuine emergency, and removes the anxiety of not knowing what to do when something goes wrong.

  • For the board or governance body, a documented and tested plan is evidence of proper oversight and risk management, which matters incredibly for director duties and for satisfying funders, regulators and insurers that the organisation is being run responsibly.

  • For customers, members and the community the organisation serves, continuity planning is often invisible until it is not there when it’s actually needed. An organisation that can keep serving people, or communicate clearly and quickly when it cannot, protects trust that would otherwise take years to rebuild.

  • For insurers and lenders, demonstrable planning can directly affect terms and premiums, and can be the difference between a claim being paid smoothly and a claim being disputed on the basis that reasonable steps were not taken.

Where to start

Building a suite of policies, procedures and plans properly does not have to mean stopping the business to write a 200-page manual. It means starting with the plans and policies that address the biggest points of failure first, usually the ones tied to key people, key systems and the most likely disruption scenarios for your specific industry, then building from there as the organisation grows.

This is the gap that BusinessRx can help you close: not generic advice about why documentation matters, but hands-on, execution-based work to build the policies, procedures and plans a specific business actually needs, written to match how the organisation genuinely runs, and tested well before they are ever needed for real.

BusinessRx. Your SME sorted. DOING, not just advising.

Next
Next

10 processes every SME should automate