Most businesses discover how much institutional knowledge they have lost only after it has already left. A senior partner retires. A lead consultant takes a competing offer. An office manager who has been there since the beginning decides to move on. Then comes the scramble: who knew how to handle that client? Who managed that vendor relationship? Who understood why the process works the way it does?

A knowledge audit is the systematic approach to answering those questions before the crisis, not after it. This article gives you a practical framework for running one — including a working checklist you can use today.

What a Knowledge Audit Actually Is

A knowledge audit is an institutional knowledge assessment that answers three questions:

  1. What does our business know? Not just what is documented — everything: client relationships, vendor arrangements, undocumented processes, workarounds that became standard practice, and tribal knowledge that lives only in specific people's heads.
  2. Where does each piece of knowledge live? Is it documented? If so, where and how current is it? Is it in one person's head? In email threads? In a shared drive no one has organized since 2019?
  3. What is the risk profile? Which knowledge is at risk of being lost — because the person who holds it is approaching retirement, has been underperforming, or is a flight risk? What would it cost the business if that knowledge disappeared tomorrow?

The output of a knowledge audit is not a comprehensive document. It is a prioritized list of knowledge gaps and risks, with an action plan for closing the most critical ones first.

The Four Categories of Business Knowledge

Before you can audit what you know, you need a framework for categorizing it. Business knowledge falls into four types:

1. Explicit Knowledge

This is knowledge that is already documented somewhere: in procedures, policies, contracts, client files, or training materials. Explicit knowledge is not risk-free — documentation goes stale, files get siloed, and the person who knows where everything lives may be just as much a single point of failure as someone who holds undocumented knowledge. But it is the most recoverable category.

2. Tacit Knowledge

This is expertise that exists in people's heads but has never been written down. How to read a particular client's mood before a call. Which approach works for which type of audit situation. The workaround for the system bug that has never been fixed. Tacit knowledge is what exits the building when people leave — quietly, with no fanfare and often no awareness.

3. Embedded Knowledge

Knowledge that lives in systems, processes, and routines: the way the CRM is configured, the custom fields in the project management tool, the logic behind the pricing model. Embedded knowledge is often well-preserved until the underlying system changes — then it disappears along with the context for why things were built the way they were.

4. Cultural Knowledge

The unwritten rules of how decisions get made, who actually has influence, what the firm's real standards are versus the stated ones. This is the hardest category to capture and the most disorienting to lose. New hires often describe the experience as “learning the rules by breaking them” — which is an expensive form of knowledge transfer.

The Knowledge Audit Framework

Run the audit in three phases: inventory, assessment, and action planning. Most organizations try to skip to action planning without doing the inventory honestly, which produces a plan that optimizes for the wrong risks.

Phase 1: Inventory

List every significant area of business activity and identify who holds critical knowledge in each area. Do not limit this to formal roles. “Sarah is the only person who knows how to get anything approved by that client” is a knowledge risk even if Sarah's title is Associate.

Phase 2: Assessment

For each piece of critical knowledge, assess two dimensions: documentation status (does it exist in documented form?) and key-person risk (how many people hold it, and how likely are those people to leave?).

Phase 3: Action Planning

Prioritize by the intersection of high risk and high impact. Start with knowledge that is both undocumented and held by a person who is at risk of leaving. Those are your active fires. Everything else can wait.

Turn Your Knowledge Audit Into Captured SOPs

BrainVault's AI interview mode captures the tacit knowledge your audit surfaces — before it walks out the door.

Start Capturing Knowledge Free

The Knowledge Audit Checklist

Use this checklist to run your institutional knowledge assessment. Work through each section systematically. A checkbox marked is not “done” — it means you have identified what you know, what you do not know, and who holds it.

Client and Relationship Knowledge

Key client preferences, communication styles, and sensitivities are documented High Risk
Client history (past work, decisions made, reasons behind them) is accessible to more than one person
Client relationships are not solely held by one individual High Risk
Vendor relationships and negotiated terms are documented beyond the contract itself
Referral sources and relationship context are captured, not just the contact information High Risk

Process and Operational Knowledge

Core service delivery processes are documented with enough specificity that someone new could follow them
Workarounds and exceptions are documented, not just the standard path Medium Risk
Quality standards and checkpoints are explicit, not assumed Medium Risk
Escalation paths are documented and known by more than one person
Processes that exist only in one person's head are identified and prioritized for capture High Risk

Technical and Systems Knowledge

The rationale behind system configurations is documented (not just the configuration itself)
Custom fields, automations, and integrations are documented with their business logic
Known system bugs and their workarounds are written down Medium Risk
Access credentials and administrative controls are held by more than one person High Risk
Reporting logic and business definitions (what counts as a “client”, how revenue is calculated) are documented

Regulatory and Compliance Knowledge

Compliance requirements are documented beyond the regulations themselves — including how the firm interprets and applies them High Risk
Filing deadlines, exception processes, and regulator relationships are held by more than one person
Past compliance decisions and their rationale are preserved and accessible
Engagement-specific regulatory context is captured at the matter level, not just the partner level Medium Risk

People and Cultural Knowledge

Role-specific knowledge is captured before transitions, not after High Risk
Team preferences, working styles, and decision-making patterns are documented for key roles
Onboarding materials reflect how the firm actually works, not just the org chart and policies
Knowledge transfer is part of the standard offboarding process, not an afterthought

Scoring Your Knowledge Risk

After completing the checklist, calculate a rough risk score for each area by answering two questions:

The areas with low documentation scores and high key-person risk are your priorities. Everything else is important but not urgent.

The right time to run a knowledge audit is before you need one. The second-best time is now. The worst time is after someone has already left.

What to Do With What You Find

The audit produces a list of knowledge gaps. Closing those gaps requires a systematic capture process — and the right tool for most of them is a structured expert interview, not a request to write something down.

For professional services firms — accounting practices, consulting firms, financial advisory businesses — knowledge audits often reveal that 60–80% of business-critical knowledge is held by fewer than five people, most of it undocumented. The audit makes this concrete. The capture process turns it into an organizational asset that does not leave when people do.

For firms going through succession planning, acquisitions, or rapid growth, a knowledge audit is not optional — it is the foundational step that determines whether the business survives the transition or whether value walks out the door with the people who built it.

Running the Audit: Practical Notes

Involve people at every level. Knowledge does not follow org charts. The person who knows the most about a process is often not the most senior person in the room. Include them in the audit.

Be specific about undocumented knowledge. “Sarah knows how we handle the Smith account” is not an audit finding. “Client preferences for communication frequency, preferred contact method, history of past disputes and how they were resolved, and the specific partner relationship context from the 2023 engagement” is an audit finding. The specificity determines whether the capture effort actually closes the gap.

Do not let the audit become the goal. The audit is a diagnostic, not a solution. If your knowledge audit produces a beautiful spreadsheet and no subsequent capture effort, you have spent time documenting your risk without reducing it.

Once you have identified what is at risk, the next step is systematic capture. BrainVault's AI interview mode is designed for exactly this: turning the tacit knowledge your audit surfaces into documented SOPs and reference materials your team can actually use.

Before you start capturing, it helps to know how severe your exposure is. Our Knowledge Risk Assessment scores your organization across 8 dimensions — undocumented knowledge holders, succession exposure, onboarding time, and more — and gives you a prioritized action plan in under 3 minutes.