Below fifty people, a founder can hold everyone's situation in their head. Who's on leave, who's due a review, who joined last month and still doesn't have access to the shared drive. None of it is written down, but it works, because one person knows.
At fifty that person stops being able to know. Not because they've gotten worse at it. There are simply more situations than a memory can carry, and the gaps start showing up as missed reviews, wrong payslips, and a new hire sitting at a desk with nothing to do.
Fifty also happens to be a legal line in more countries than people expect, which I'll come to. But the memory problem arrives first, and it's the one that decides whether the compliance problem is manageable or not.
This is the list of what has to exist by then.
What I mean by a process
Not a policy PDF. I've read a lot of those and most describe a company that doesn't exist.
A process, for this article, has five parts. An owner: one named person accountable for it running. A trigger: the event that starts it. The steps, including the handoffs between people. The system it lives in, whether that's an HR platform, a shared form, or a spreadsheet with rules. And a finish line, so everyone knows when it's done.
If any of those five is missing, what you have is an intention. I've written about why that distinction matters in Why SOPs Fail: The Document Is Not the System, so I won't repeat it. The short version: a document nobody can find, owned by nobody, describing steps that happen in a tool nobody uses, is paperwork.
Each process below ends with the five parts, so you can check yours against them.
The ten processes
Ordered from hire to exit, with the monthly processes in between.
1. Hiring and onboarding
Below fifty, hiring is an event. At fifty it's a monthly activity, and if there's no agreed process, every manager invents their own. Different interview formats, different offer letters, different answers to the same candidate question. That's the first place a business starts making promises it doesn't know it has made.
Onboarding is where the cost lands. Someone accepts, then spends their first week waiting: for a laptop, for system access, for someone to tell them what the job is day to day. It's the least productive week you'll ever pay for.
What it needs: an owner (the hiring manager, with one person coordinating across roles); a trigger (an approved role to fill); steps (one interview format, one offer template, a pre-start checklist with a name against each item); a system (anywhere candidates and checklists live, as long as it's one place); a finish line (the new hire can do a day's work without asking where anything is).
For remote teams I've covered the specifics in How to Build an Effective Onboarding Process for Remote Employees. Whether you're hiring the right people at all is in The Process to Hire and Maintain the Right Talent, and the three numbers worth tracking are in Hiring KPIs.
2. Employee records and document expiry
The process most often missing from lists like this, and the one I'd put first for any Gulf business.
At fifty you're holding contracts, identity documents, qualifications, residence permit details, emergency contacts, and a history of every change to someone's role and pay. Usually across a shared drive, an inbox, and a filing cabinet. The problem isn't storage. It's expiry. Permits expire. Contracts come up for renewal. Probation periods end. If nobody is tracking dates, you find out when something has already lapsed, and in some places that's a fine rather than an inconvenience.
What it needs: an owner (whoever runs HR admin, even part-time); a trigger (every hire, every change, every renewal date); steps (file it, log the expiry, act on the reminder); a system (this is the first HR process worth putting in real software, because the value is in the reminders); a finish line (nothing expires without someone having acted on it beforehand).
3. Attendance
This sounds too basic to need a process. It isn't, because attendance is an input to everything else.
Attendance feeds leave balances. Leave balances feed payroll. Payroll feeds the accounts. Say attendance lives in three places: a biometric device, a manager's spreadsheet, and people's memory. The first month those three disagree is the month payroll is wrong, and nobody can say which version was right.
What it needs: an owner (one person who reconciles exceptions); a trigger (every working day, and every exception); steps (a rule for what counts as present, including remote and site work, and a reconciliation before the payroll cut-off); a system (one place the answer lives); a finish line (the attendance record and the payroll input are the same numbers).
4. Leaves
Leave is the clearest example I know of approvals stalling at handoffs.
Someone asks their manager for a week off. The manager says probably fine. Nobody records it. Three weeks later a second person on the same team asks for the same week, the manager says yes again, and now there's a coverage problem nobody created on purpose. Or the request sits in a chat thread for ten days because the manager didn't know the balance and didn't want to check.
Without a rule, the manager decides case by case, and case by case is how fairness problems start. Two people in the same situation get two different answers.
What it needs: an owner (the line manager, with HR admin holding the balances); a trigger (a request through one route, not a chat message); steps (check the balance, check coverage, decide within a set time, record it); a rule worth writing down (on a team of five or fewer, no more than one person out at a time unless the manager explicitly overrides); a system (a shared calendar at minimum); a finish line (the request is recorded, the balance has moved, the team calendar shows it).
5. Payroll
The one process that must never be wrong, and the one most likely to still be run manually at fifty because it always has been.
The problem isn't calculation. Software does that. The problem is the inputs: attendance, leave, new joiners, leavers, changes to rate, one-off deductions. Each arrives from a different person at a different time, usually by message, usually late. Payroll becomes a monthly scramble to reconstruct what happened, and errors get discovered by the employee on payday, which is the worst way to find them.
In the Gulf there's a compliance layer on top. Wage-protection requirements, including WPS in the UAE and wage-protection reporting through Mudad in Saudi Arabia, make accurate payroll records part of compliance, not just internal administration.
What it needs: an owner (whoever runs payroll, with a second person approving); a trigger (a cut-off date everyone knows); steps (inputs arrive through one route, reconcile against attendance and leave, approve, pay); a system (payroll software fed from the attendance and leave records, not from messages); a finish line (paid, filed, and no corrections in the following month).
6. Performance management
Below fifty, the founder assesses everyone personally, informally, and it works because they see everyone's work. At fifty they don't see everyone's work anymore. If there's no process, assessment becomes a matter of who is visible rather than who is good.
That has a slow cost and a fast one. The slow cost is that good people in less visible roles stop being recognized, and eventually leave. The fast cost is that promotion and pay decisions start to look political, because nobody can point to the criteria they were made on.
What it needs: an owner (each manager, with HR holding the calendar); a trigger (a fixed cadence, quarterly or twice a year); steps (criteria written before the review, a conversation, a record of what was agreed); a system (a form and a calendar are enough for a long time); a finish line (a written record that the next process can use).
7. Rate increases
If there's no process for pay increases, the process is that whoever asks gets one.
I've seen this in businesses that would never describe themselves that way. Someone asks for a raise in a one-to-one. The manager has no rule to point to, the conversation is awkward, and the easiest way out is yes. Six months later someone else finds out, and now the manager has a second conversation, worse than the first.
What it needs: an owner (the founder or whoever holds the budget); a trigger (a cycle, so increases happen at a known time rather than on request); steps (criteria tied to the performance record, a budget set before the cycle opens, an approval route, a way of telling people the outcome); a system (the performance records from process six); a finish line (every decision is recorded with the reason).
The leveling structure that makes this fair is in Job Titles, Descriptions and Leveling, and the org structure it sits inside is in How to Create an Org Chart with Clear Roles.
8. Training and development
Two things get lumped together here. Separating them is most of the work.
The first is the training people need to do the job. At fifty, this is usually onboarding content that never got written down, so it's delivered by whoever happens to be free that week. A new hire learns the job the way that one colleague does it, including that colleague's shortcuts. Two months later the attendance data or the invoicing has a pattern in it that nobody can explain, and the explanation is that three people were trained three ways.
The second is development: what people need to grow into the next role. At fifty this is usually nothing formal, and requests are handled the way raise requests are handled without a process. Whoever asks, gets.
What it needs: an owner (one person for job training, usually the team lead; one for development budget, usually the founder); a trigger (every new hire; an annual development cycle); steps (a short written curriculum for the job, and a rule for who can access development budget); a system (a shared folder is fine to start); a finish line (a new hire has completed the same training as the last one, and the record says so).
I've written a starting point in Training Policy Foundations.
9. Grievance and disciplinary
Nobody wants to design this process, which is why it gets designed in the middle of the first serious incident, by people who are upset.
At fifty, someone will raise a complaint, and someone will need a formal warning, and both will happen in the same year. Without an agreed route, a complaint goes to whoever the person trusts, who may have no authority to act on it. A warning gets issued verbally, isn't recorded, and can't be relied on later.
The purpose of the process is to protect both sides. An employee who knows how to raise something is less likely to leave over it. A manager who has followed a documented process has a record to point to if a decision is ever challenged.
What it needs: an owner (a named person who receives concerns, and it can't only be the person's manager); a trigger (a concern raised, or a conduct issue identified); steps (acknowledge, investigate, decide, record, each with a timeline); a system (a confidential record, separate from general HR files); a finish line (a written outcome the employee has seen).
10. Termination and offboarding
The highest-risk process on the list, and the one businesses most often improvise.
Operationally, the failure is access. Someone leaves and still has the shared drive, the CRM login, the company card, the client's WhatsApp group. I've seen this more than once: former employees with system access for months, because nobody owned the list of what to revoke. On the settlement side, the failure is the final calculation. Notice, accrued leave, and in the Gulf the end-of-service payment, each depends on records being right, which loops back to process two.
What it needs: an owner (HR admin, with IT or whoever holds the systems); a trigger (a resignation received or a dismissal decided); steps (a checklist of access and property with a name per item, a work handover, a settlement calculation that a second person checks); a system (the same records from process two); a finish line (access revoked, property returned, settlement paid, file closed).
The harder question, when to let someone go, is in Hire Slow, Fire Fast.
They're connected, and that's why they fail
Every list presents these as ten separate things. They aren't, and treating them separately is why they fail one at a time.
Attendance feeds leave. Leave feeds payroll. Performance feeds rate increases, which feed payroll. Hiring creates records, and offboarding depends on them. Change one without knowing what it feeds and you've created a discrepancy downstream that will surface as a wrong payslip or a lapsed permit.
This is also why buying an HR system doesn't fix it on its own. The system can hold all ten, but only the version of them you've agreed. If the leave approval rule was never defined, the system will either enforce a rule you didn't choose or leave the question open, and people go back to asking in the chat.
A client of mine had this exact problem with a CRM rather than an HR system. They'd bought it, but there was no process around it, so barely anyone used it. I designed the workflow first, then built the automations behind it: assignments, status triggers, escalations, reporting views. Then documented it and trained the team so it stuck after I stepped back. The tool hadn't changed. The agreement about how the work ran had.
Define the process first, including what it feeds and what feeds it. Then configure the system to match. The other way round costs more, because by then people have opinions about the software instead of the work.
Where to start
Not with all ten.
If nothing is documented, start with leave and payroll. They run every month, everyone feels them, and they're connected, so fixing one forces you to look at the other. Records and expiry come next for any business with permit-holders, because the cost of getting that wrong is external.
If something is already hurting, start there. The process that's currently delayed, repeated, inconsistent, or hard to see is the one to map first.
Why fifty can also be a legal line
I said I'd come back to this. These examples show why headcount matters, but fifty is not a universal starting point for employment obligations.
In the United States, the Family and Medical Leave Act generally covers private-sector employers with at least fifty employees in twenty or more workweeks in the current or preceding calendar year. Employee eligibility has additional requirements. Under the Affordable Care Act, applicable-large-employer status generally starts at an average of fifty full-time employees, including full-time equivalents, in the previous year. The counting rules are different.
In the UAE, covered private-sector establishments with fifty or more employees have Emiratisation targets for skilled roles: a 2% annual increase toward the 10% target by the end of 2026. June 2026 reporting of MoHRE's announcement describes a Dh10,000 monthly contribution for each required Emirati position left unfilled from 1 July. Selected businesses with twenty to forty-nine workers also have obligations; being below fifty is not an exemption.
In Saudi Arabia, do not use fifty as a blanket compliance threshold. The Labor Law's work-regulation requirement applies generally to employers, subject to ministerial exceptions. Qiwa's approval process distinguishes model regulations from customized ones. Saudization requirements also depend on the establishment and activity. The ministry has announced a new Nitaqat cycle for 2026, and electronically documented Qiwa contracts became a condition for counting Saudi employees from 15 April 2026. That is a records-and-workflow issue, not just a headcount calculation.
Employment obligations exist well below fifty. The point is not that all ten processes become legally mandatory at the same number. It is that growing headcount makes informal administration harder to defend and harder to run.
One thing to be clear about: I'm not an employment lawyer, and these examples are for orientation, not legal advice or a complete compliance checklist. Rules, coverage and counting methods change. Check the current position with someone qualified in your jurisdiction before you build a process around a number.
Where this doesn't apply
Below fifty, a lot of this is more than you need. A fifteen-person business with a founder who knows everyone can run leave on a shared calendar and be fine. There's a shorter note on that size in The Must-Have Processes for Small Businesses With 1–50 Employees, and the wider operational picture at fifty and above, beyond HR, is in Essential Processes Every Growing Company Needs (50–200 Employees).
Frequently asked
Do I need HR software at fifty employees?
Not necessarily, and not first. You need the ten processes defined. Records and expiry are worth putting into a system early because the value is in the reminders. Performance reviews can run on a form and a calendar for a long time. Define the process, then decide what it needs to live in.
Who owns HR processes at fifty employees if there's no HR manager?
Usually an office manager or finance lead holds the admin processes (records, attendance, leave, payroll), line managers hold the people processes (performance, training), and the founder holds the ones with money or risk attached (rate increases, grievance, termination). That split works until around a hundred people. What doesn't work is "everyone," because that means nobody.
What's the difference between an HR policy and an HR process?
A policy says what the rule is. A process says who does what, in what order, in which system, and when it's finished. Most businesses at fifty have policies. Very few have processes, which is why the policies aren't followed.
If one of these ten is currently delayed, repeated, inconsistent, or difficult to see in your business, that's the place to start.
Thirty minutes on that one process: where it's breaking, and what the next useful step is. If the answer is to map it properly and agree how it should run before anything gets built, that's the process mapping and documentation work, and we can talk about what that looks like on the call.
Which of the ten is the one your managers are currently working around?
Ahmed Fahmy is Co-Founder of Blackwing. He has 8+ years in business analysis, business process management and process reengineering, was Head of BPM at New Age, and is BPMN certified.
