Executive Summary

The report reviews the effectiveness of the IT Controller role, currently centred around Derek Lamb, and covers 63 linked processes (42 active and 21 responsibility-only). Overall, the IT function appears to be well documented, with many mature, regularly performed processes, but there are several governance risks that should be addressed before the next management review.

Overall Risk Indicators

The review highlights several key concerns:

42 active IT processes under the role.
3 overdue rolling tasks/audits.
5 processes have not been reviewed for over 24 months.
7 processes have only one trained employee.
1 process has no measurable objective.
14 processes have no audit configured.
The biggest concern is a single point of failure, with Derek linked to 41 of the 42 active processes (98%). This means the organisation is heavily dependent on one individual for critical IT knowledge and operation.
Positive Findings

The majority of operational IT processes are in good condition:

Most core processes have documented risk assessments.
Many have measurable objectives.
Most have been reviewed within the past 12 months.
Evidence exists showing regular completion of recurring tasks.
Core activities such as:
Email systems
Domain management
Google Search Console
AWS
Invoice processing
all have established procedures and recurring reviews.

Several processes achieve 100% maturity (6/6), demonstrating well-maintained documentation, audits and objectives.

Areas Needing Attention
1. Single Point of Failure (Highest Priority)

This is by far the largest organisational risk.

Although Michael and Helen have been trained on several systems, almost every active IT process ultimately relies on Derek.

The report specifically identifies:

98% dependency on Derek.
Seven processes with only one trained employee.
Limited succession or business continuity should Derek become unavailable.
2. Out-of-date Processes

Some procedures remain in the system despite no longer being required.

Example:

Backup Jean's Local Folder
Last reviewed in 2021
Process itself states it is no longer required because Jean no longer has the folder
No activity for two years.

These obsolete processes should either be archived or formally retired.

3. Outstanding Rolling Tasks

Several recurring operational tasks are currently overdue, including examples such as:

Emailed Invoice Cleardown
Domain Name Management
Google Search Console

Most are only overdue by a few weeks rather than months, suggesting workload rather than systemic failure.

4. Missing Audits

Fourteen IT processes currently have no formal audit configured.

Many are low-risk operational processes, but introducing simple annual verification would strengthen ISO evidence.

Performance Trend

The recurring task history shows:

Most tasks are completed consistently.
Completion times generally fall into acceptable ranges.
There are occasional delays of 20–40 days.
A small number exceed 100 days (for example, one FastHosts invoice collection), but these appear to be isolated rather than representative of overall performance.
Overall Assessment
Strengths
Strong procedural documentation.
High process maturity across core IT activities.
Good evidence of recurring operational work.
Risks generally assessed as low.
Good linkage into ISO 9001 and ISO 13485 requirements.
Weaknesses
Heavy dependence on one individual.
Several overdue reviews.
Some obsolete processes remain active.
Limited cross-training in specialist IT functions.
Several processes lack audit coverage.
Recommended Management Actions
Reduce the single-person dependency by cross-training Michael (and where appropriate others) on more IT processes.
Review and formally retire obsolete processes such as Backup Jean's Local Folder.
Clear the small backlog of overdue recurring IT tasks.
Review the five processes older than 24 months and update them.
Consider adding lightweight annual audits to the 14 unaudited processes.
Continue documenting systems and procedures to preserve organisational knowledge and improve resilience.
Overall Conclusion

The IT Controller function is operationally strong, with mature documentation and regular task completion. The principal issue is organisational resilience rather than technical performance. The report indicates that the systems themselves are generally well managed, but there remains a significant business continuity risk due to the concentration of knowledge and responsibility in a single individual.
