
Organisations
What's actually at stake here isn't wellbeing.
Your best people are your biggest asset and your biggest risk.
So the question is simple:
is the biggest asset on your balance sheet actually supported like one?
Every organisation depends on a small number of people making crucial decisions under pressure — a leadership team, a handful of specialists, a cybersecurity team, a key accountant, the head of your security function, a night-shift guard — the people everything else quietly runs through.
When they're operating well, nobody notices. When they're not, it shows up everywhere except where you'd expect: not as a resignation letter, but as a slower decision here, a shorter fuse there, a missed meeting here, a lost negotiation there, an increased churn here, an overlooked procedure there — a standard that quietly slips. By the time it's visible enough to name, it's usually been true for months.
Most organisations have no structured way to see this coming.
You probably already have audit or controlling procedures, and a discipline built around them.
Finance has periodic reporting. Cyber risk has incident response plans and penetration testing. Supply chain has contingency planning and backup suppliers for when something breaks.
Somewhere along the way, the people who actually run all of those systems — and whose judgement, energy, focus, and decision-making capacity determine whether any of it holds under pressure — became the one risk category still managed by instinct. Usually, a benefits budget or a gym card, renewed each year on the assumption that offering something is the same as measuring and proactively supporting something.
That gap doesn't stay invisible forever.
It shows up as a key person whose judgement quietly degrades under sustained pressure for months before anyone names it. It shows up as a leadership team making worse decisions in a crisis because they were already operating at a physical and mental deficit going into it.
It shows up, eventually, as the exact kind of single point of failure any well-run risk process is supposed to catch — except this one was never written down anywhere, because nobody had a way to measure it.
If nothing changes, that's the failure state.
Workforce health stays a line item nobody can defend in a board conversation, a felt problem with no data behind it, addressed reactively after it's already cost something. Health and energy get treated as a personal matter, or a line in a benefits budget — something you offer, not something you hold people accountable for.
The alternative isn't a wellness perk.
It's key people's health treated with the same rigour as any other P&L variable you're already accountable for — a documented baseline, a defensible measurement framework, and outcomes you can actually put in front of the people who ask you to justify the spend.
That's the standard I work to. Not only because health deserves special treatment - because it does - but because it doesn't deserve less rigour than everything else you're already expected to account for.

3A Approach
Assess. Address. Account
Here's what a typical wellbeing benefit actually looks like: employees get access to a platform — a gym membership, a counselling line they can call whenever they need it, maybe a blood panel once a year, some of it free, some paid. And that's it.
No baseline beforehand. No goal. No follow-up after. No way, a year later, of knowing whether any of it changed anything.
Most of it goes untouched. What statistics show, across most organisations that offer one, barely one in twenty employees ever actually calls the counselling line in a given year — and fewer than one in ten employers even check whether the benefit does anything at all. The programme exists. Whether it worked was never anyone's question to answer. The benefit sits in the handbook, the usage numbers get reported at year-end, and everyone can point to something — while the actual outcome, whether anyone's health or performance genuinely improved, goes unchecked, because nothing was built to check it.
Both sides pay for that. The organisation, in spend with no measurable return. The employee, in a problem that was never actually addressed, just made to look attended to.
The 3A Approach exists because the same discipline that governs every other serious risk category — measure, act, verify — must be applied properly to this one. Otherwise, it's delusional.
1. Assess
Human Capital Resilience Assessment.
This isn't a single blood test applied to a handful of individuals. It's a structured, two-stage process for identifying where risk actually concentrates in your organisation, then matching the right depth of assessment to the right group.
Stage one: identify.
It starts with your own list — the roles you already know carry outsized weight, because that's organisational knowledge only you have. Alongside it, a structured pass across the organisation, using the same dependency-mapping logic a proper business impact analysis applies to any other critical resource, surfaces the roles a straightforward org chart tends to miss — criticality doesn't map cleanly onto seniority, and a single specialist with undocumented knowledge can represent a bigger point of failure than someone several pay grades above them.
Stage two: match the tool to the group.
Once the full picture exists, two approaches run in parallel. The individuals carrying the most concentrated risk get a full, personal clinical baseline. The wider population identified alongside them — real risk, but distributed rather than concentrated in any single person — gets a group-level assessment: different tools, calibrated for breadth, built on the same underlying method.
The output is a written report built to sit in a risk register or board pack, where health-related risk concentrates, what it's already costing, and where the case for intervention is strongest.
This stage is crucial for the whole process.
You can treat this stage as a single engagement on its own — enough to understand where things actually stand, before deciding whether, and with which part of your organisation, to continue. By the end of it, you'll know what needs to happen next, which tools are the right fit, and roughly what the full programme is likely to cost — priced per person, since that's the only honest way to quote something whose actual scale depends on what this stage finds.
2. Address
Key Person Health Resilience Programme
What Assess identifies, Address responds to — at two different depths and for two different groups.
For the individuals carrying concentrated risk
The people Assess identified as genuine single points of failure — the response matches that depth: a fully individualised clinical programme. Functional testing-informed protocols, one-to-one structured coaching, delivered over a period long enough to produce a measurable shift. This is the resource-intensive tier, and it's intentionally reserved for the people where that intensity is actually justified by what Assess found, not applied uniformly regardless of concentration of risk.
For the wider population
Assess also identified — real risk, but distributed across a group rather than concentrated in any one person — the response is calibrated for breadth: structured group programmes, educational and supportive sessions built around the specific risk pattern or health-related topic Assess surfaced for that group, not the same individual-depth protocol thinned out to cover more people. This tier draws on a distinct library of group-facing formats — workshops, smaller or bigger group coaching, structured sessions, manager briefings — matched to what the assessment actually found for that population, rather than a generic "wellness day" applied because it's what's available.
At any point, individuals can be offered to switch tiers. Risk isn't static. Someone in the group tier whose situation changes — surfaced through the ongoing monitoring built into Account, not guesswork — can be offered individual-depth support when the evidence actually shows it's needed. Someone who's stabilised can be offered to step back down. The tier reflects current, evidenced need — assessed by a practitioner, offered as a choice and never assumed or applied without agreement.
3. Account
This isn't a final step — it's a cycle, the same one ISO 22301 itself runs on: Check, then Act, then Plan again.
Check. Both tiers get retested on a set schedule, tied to your existing reporting cadence. For the individual tier, not every marker needs the same interval — some data comes from questionnaires or sources already available; the more expensive panels get retested only as often as the marker itself actually warrants.
For the group tier, monitoring runs at population scale: validated instruments and aggregate trend data across the cohort — a different tool for a different shape of risk, not a smaller version of the individual one.
Act. A genuine change in someone's data, in either tier, becomes an actual decision rather than a missed signal — the tier-switch offer in Address gets made from evidence gathered here, not a guess. Correcting based on what Check actually shows also means dropping or adjusting anything, in either tier, that isn't moving the numbers it was meant to move.
Plan, again. What Check and Act reveal feeds directly into the next cycle — for individuals and groups already in the programme, and, on a longer interval, for the organisation as a whole, since key-person risk isn't fixed at the point Assess first mapped it.
That's what continuity actually means. That's what resilience is — not a benefit that exists, or a gym card in a wallet, but a risk that's actually being managed.
On your data.
Health information is legally sensitive, and it's treated that way here — always.
Individual health data is held only by the practitioner providing your assessment or programme, under professional confidentiality, and is never shared with your employer in a form that identifies you. What an employer receives is aggregate, anonymised reporting — patterns and trends across a group, never individual results.
Your genuine, informed agreement is sought before any assessment or testing begins, and you can ask questions or decline at any point without consequence. Data is processed under UK and EU data protection law, stored securely, and kept only as long as it's needed for the purpose it was collected for.
Full details — what's collected, how it's used, who can see it, and your rights over it — are set out in our Privacy Policy. If anything here isn't clear, ask before proceeding.
