Corporate risk management produces committees and matrices. Small-business risk management answers one question: what are the five things that could genuinely end this business, and what have we done about each? Most SME failures come from a short, boring list — a key person lost, a big customer gone, cash stuck, a fire or flood, a compliance blow, a partner dispute. Every item on that list can be made survivable in advance, cheaply. That work is this guide.
Map your real risks in one hour
List everything that could hurt the business, then place each on two axes: how likely, and how fatal. Ignore the exotic; concentrate on the top-right — likely and severe. For a typical SME the top-right holds: dependence on one customer or supplier, the owner's own incapacity, receivable concentration, fire/theft at a single location, a statutory default snowballing, and data/payment fraud. Your risk register is one page: the risk, what would actually happen, what you're doing about it, and who owns it. Review it twice a year.
Concentration: the silent killer
- Customer: any single customer above ~20–25% of revenue owns you — diversify deliberately, or at minimum contract the relationship and watch their payment behaviour like a creditor
- Supplier: for every A-input, a qualified second source at 20–30% share; an annual price disruption is cheaper than a supply hostage situation
- Person: the salesperson who owns the relationships, the technician who alone knows the machine, the accountant who alone knows the books — document, cross-train, and split knowledge so no exit is existential
- Channel: a business built entirely on one aggregator or marketplace lives at the mercy of its commission slab and ranking algorithm — build a second channel before you need it
The owner is the biggest single point of failure
In most SMEs, signatures, passwords, supplier relationships and pricing knowledge live in one head. The fixes are unglamorous: a second authorised signatory with defined limits; documented banking, portal and licence credentials in a sealed, trusted arrangement; SOPs for the decisions only you currently make; term insurance and keyman insurance sized to debts and family needs; and a one-page 'if I am unavailable for 90 days' note. This is not morbidity — it is the difference between a bad quarter and a shutdown.
Twice a year, ask: if this location burned tonight, what exactly happens tomorrow? Where are the backups of accounts and customer data? What does insurance actually cover? Where would we operate from? Businesses that can answer in writing recover in weeks; the rest liquidate.
Transfer, contract and comply
Some risks are cheapest to transfer: fire/burglary/liability insurance sized honestly (see our insurance guide), employee compensation cover, and cyber cover as digital payments grow. Some are cheapest to contract away: written terms with customers (payment days, delivery conditions, liability caps), rate contracts with suppliers, employment agreements with confidentiality and notice clauses, and a partnership deed with exit and valuation clauses. And compliance risk is simply scheduled away: a statutory calendar owned by a named person, filings never bartered against cash convenience — because penalty interest and prosecution risk compound faster than any business return.
Build the cash shock-absorber
Every risk eventually presents as a cash problem. The universal mitigations: a reserve of one to two months' fixed costs untouched by operations; an unused OD/CC limit arranged in good times; receivables watched weekly with credit limits per customer; and personal guarantees given sparingly and tracked. Resilience is mostly just liquidity plus time — enough of both converts most disasters into stories.
How Aidwish helps
Aidwish runs risk reviews inside its Business Health Score and retainers — the one-page register, insurance adequacy, contract gaps, compliance calendar and continuity basics — so clients spend a few hours and a few thousand rupees preventing the failures that end comparable businesses.