In a management session during diligence, a buyer's advisor asks a routine question: what happened the last time a primary supplier failed to deliver, a production line stopped, or a key customer threatened to leave. The answer usually arrives quickly, in detail, and with visible pride — the founder describes phone calls made at midnight, a substitute supplier located within two days, a customer relationship personally repaired. The narrative is accurate and the outcome was genuinely good. What follows, however, is a second question that produces a noticeably slower answer: who decided, on what authority, within what threshold, and what record exists of that decision. The room changes at that moment, not because the company handled the crisis badly, but because the handling lived entirely in one person's judgment and left almost no trace behind it.

This pattern repeats across companies of very different sizes and sectors, which suggests it is structural rather than a matter of individual discipline. Crisis response concentrates in the founder because, in the formative years of a company, that concentration is the efficient arrangement: the founder holds the widest map of suppliers, customers, financing lines and internal constraints, and routing every anomaly through that map produces faster and better decisions than any procedure could. Delegation at that stage would cost more than it saves. The behavior is not a failure of governance; it is governance calibrated to a condition that was true.

The difficulty emerges when the condition changes and the arrangement does not. As headcount, geography, product lines and counterparty count grow, the founder's map stops being complete, yet the escalation habit built around that map persists. Incidents continue to travel upward for resolution, but they now travel through a longer chain and arrive at a decision-maker with partial information. The organization interprets this as a bottleneck problem and typically responds by adding communication — more updates, more group messages, more escalation channels — rather than by distributing authority. Adding communication without adding decision rights increases the volume of the response while leaving its speed unchanged.

What a review process looks for, therefore, is not evidence of heroism but evidence of structure across several distinct layers. The first is simply whether a defined response capability exists at all as something other than a verbal claim: a named set of disruption scenarios, an escalation path, a threshold at which an incident becomes a crisis. The second is whether that definition is carried by current, approved and retrievable documents rather than by institutional memory, since undocumented practice cannot be verified by a third party and therefore cannot be underwritten. A plan that exists but was last approved three restructurings ago carries roughly the evidentiary weight of no plan at all.

The third layer is where most well-prepared companies are separated from genuinely prepared ones. A response framework that exists on paper but has never been exercised — no tabletop walkthrough, no post-incident review, no record of the framework actually governing a real event — is a document produced for an audit rather than a capability operating in the business. Diligence detects this quickly by comparing the written escalation path against how the last three actual disruptions were handled. Where the two diverge, the written path is treated as decorative, and, in a revealing number of cases, an informal but consistently logged practice is treated as stronger evidence than a formal but dormant manual.

The fourth layer is measurement, and it is the one most frequently absent even in otherwise disciplined organizations. Companies count incidents; far fewer measure the intervals that determine what an incident costs — the time between detection and decision, the time between decision and containment, the proportion of corrective actions that are actually closed rather than logged and forgotten, and the share of incidents resolved without escalation to the founder. That last ratio is the single most informative number a buyer can be shown, because it converts an unverifiable claim about institutional depth into an observable trend line. Without such measures, the buyer must treat management quality, forecast reliability and scalability as matters of assertion.

The fifth and sixth layers — ownership and continuity — are the ones that ultimately drive pricing behavior. Ownership asks whether a named role, rather than a name, holds decision authority within defined limits, and whether that role is accountable for outcomes through some reviewable mechanism. Continuity asks the harder question: if the founder were unreachable for a month, would the response degrade gracefully or stop. An area without a defined owner produces exactly what diligence is trained to find — implementation gaps, delay, and dependency on a single person whose departure the buyer must now price.

That price rarely appears as a visible reduction in the headline multiple, which is why sellers often fail to notice they have paid it. It surfaces instead in the architecture around the number. Key-person retention lengthens, and the retained founder's compensation is restructured so that a meaningful portion sits behind post-closing performance. Escrow sizing widens and the release schedule extends, because the buyer is holding capital against operational events it cannot yet model. Representations concerning business continuity, supplier concentration and material customer relationships are drafted more broadly, and their survival periods run longer. Closing conditions begin to include the delivery of a documented continuity framework before funds move, converting an internal management topic into a gating item on the transaction calendar.

There is a second, quieter channel through which the gap reaches valuation, and it operates through the forecast rather than the contract. A buyer assessing a business whose disruption response is undocumented cannot distinguish between a company that has been resilient and a company that has been fortunate, and, unable to make that distinction, will apply a wider band of downside scenarios to the operating model. The consequence is not an argument about the multiple but a change in which case is treated as the base case. Two companies with identical historical performance can therefore be underwritten to materially different numbers, entirely on the basis of whether their performance can be shown to be reproducible.

The structural remedy is not a thicker manual, because manuals are exactly what the review process discounts. It is a small number of mechanisms that change how decisions are made and recorded. Four components carry most of the weight: a defined escalation threshold that specifies at which financial, operational or reputational magnitude an incident stops being routine; a delegation matrix that assigns decision authority by amount and category to roles rather than individuals, so that authority is available when the individual is not; a decision record kept at the moment a decision is proposed rather than after it is approved, capturing what was known and what was assumed; and a review rhythm in which each significant incident is examined against those records within a fixed window.

In the engagements we run, this is the sequence we install, and the order matters more than the content. We begin by reconstructing how the last several material disruptions were actually handled — not how the policy says they should have been — because that reconstruction exposes the real escalation path, which is almost never the drawn one. We then set delegation thresholds against that observed reality rather than against an aspirational structure, since thresholds set too far above actual practice are ignored within a quarter. We install the decision record at the proposal stage, which is the single change that most reliably shifts an organization from narrative memory to auditable memory, and we run the incident review on a fixed calendar so that the discipline survives periods in which nothing goes wrong.

The measurement layer is built last and deliberately kept narrow. Three indicators are generally sufficient to make the capability legible to an outside reviewer: median time from detection to decision, the share of incidents closed at the level at which they arose, and the closure rate of corrective actions against their committed dates. These are reportable within a normal management pack, they resist cosmetic improvement, and, over four to six quarters, they produce precisely the artifact a buyer cannot construct from interviews — a trend showing that response quality is held by the organization rather than borrowed from one person. The same record also has an internal function that outlasts any transaction, since it is what allows a management layer to be built without the founder having to be present at every failure.

The question worth sitting with is not whether a company would survive its next serious disruption; most companies with competent founders would. It is whether the survival would produce anything an outside party could examine afterward, and whether the same outcome would be reached if the founder happened to be unavailable that week. A company that can answer the second question with evidence is describing a capability. A company that can only answer the first is describing a person, and the difference between the two is settled not in conversation but in the closing documents.