Search This Blog

Thursday, May 5, 2011

"Enterprise Risk Management" - COSO or ISO 31000

I have been recently asked to conduct a "workshop" on "Enterprise Risk Management". You know, the "COSO thing" which was a reaction to poor financial management. Followed by SOX et al. Ended up being a tick the box exercise for too many - and we had continued uncertainty and poor risk management. Not a good combination - as the latest financial crisis demonstrates.

So I was initially a little skeptical. Old wine, new bottles - maybe even a "corked" wine. However the organisers have been kind enough to steer away from a narrow, linear promotion of doctrine. Instead, I will facilitate the exploration of using the international risk management principles and guidelines (ISO 31000) to achieve enterprise-wide risk management outcomes. Ha! I hear you scoff - "that's hardly different". Well my friends, having worked in a few places and been around the traps for a few years I can tell you - not many entities actually have a tailored and integrated approach to risk management. Most are still characterised by a mixture of "layer cake" - with the top and bottom not knowing what each is up to. This mix is then pierced by some "silos" - of excellence maybe, but isolation definitely.

Anyway, if the topic appeals, and you are in Kuala Lumpur 5-6 July this year, and you can cover the fee - it would be great to have you as a participant. Regardless, the themes we will explore are laid out below if you just want to peruse and reflect.

Title: Enterprise-wide Risk Management
A workshop on using the international risk management principles and guidelines (ISO 31000) to achieve enterprise wide risk management outcomes.


Introduction to the scope of the workshop
 The risk management space is characterised by having a range of frameworks and guidelines. Many of these risk management frameworks reflect specific industry applications. Sometimes they have been developed to support quite narrow “agenda driven” purposes. Others are a reaction to risk events themselves. However, there are some which reflect a more thoughtful and engaging development. This workshop will consider the strengths of several approaches (such as Enterprise Risk Management, and Business Continuity Management). Further, we will explore how these specific applications can be integrated into a context sensitive application of the International Risk Management Principles and Guidelines to achieve relevant and robust outcomes in support of your entity’s objectives.


Pre-reading
On  January 11, 2011 – The Committee of Sponsoring Organizations of the Treadway Commission (COSO) – an organization providing thought leadership and guidance on internal controls, enterprise risk management (ERM), and fraud deterrence – released a new thought paper relating to ERM aimed at providing guidance to help organizations advance along the ERM maturity curve. If participants get an opportunity to pre-read this thought paper, they should find it provides useful background (especially if they are new to this area):



 Key elements and workshop sessions

1.    The maze of Standards, Frameworks, Principles and Guidelines


·         The structure of several specific standards (frameworks, principles, guidelines and standards) – in particular, Enterprise Risk Management COSO; Business Continuity Management BS 25999 and Risk Management ISO 31000.
·         How these different “standards” relate to each other.
·         How they can be harmonized into a nested framework which is aligned to your needs and context.


Learning outcomes include:
·         Knowledge of the structure of Enterprise Risk Management COSO; Business Continuity Management BS 25999 and Risk Management ISO 31000.
·         Understanding how these standards relate to each other.
·         Awareness of issues when translating standards into context.


2.    Gap Assessment

This session will explore:
·         Why it is important, as an early activity, to map where you are against where you need to be (in relation to risk management capability).
·         Identifying the necessary elements which should be measured.
·         What performance criteria for the elements might look like.
·         How the gap assessment might be displayed and communicated.
·         Developing an easy to use tool suitable for your context.


 Learning outcomes include:
·         Awareness of the importance of gap assessment.
·         Knowledge of the core relationship between necessary elements to be measured and sufficient performance criteria underpinning those elements.
·         Knowledge of how gap assessments might be displayed and communicated.
·         Knowledge of how to developing an easy to use tool suitable for your context.


3.    Decision Making

This session will explore:
·         What characterizes good decision making.
·         Whether risk management is just good problem solving re-badged.
·         Why analytic – deliberative processes are crucial.
·         Some tools and techniques for good decision making.


Learning outcomes include:
·         Awareness of what characterizes good decision making.
·         Knowledge of what differentiates risk management from good problem solving.
·         Awareness of why analytic – deliberative processes are crucial.
·         Knowledge of some tools and techniques for good decision making.

4.    Risk Criteria

This session will explore:
·         Developing risk assessment criteria.
·         Developing risk treatment selection criteria.
·         The criticality of context when developing risk criteria.
 
 Learning outcomes include:
·         Understanding a range of issues involved in the development of risk assessment criteria.
·         Understanding a range of issues involved in the development of risk treatment selection criteria.
·         An awareness of critical, context sensitive factors when developing risk criteria.


5.    From Principles to Integrated Implementation

This session will explore:
·         Different models for implementing Enterprise-wide Risk Management
·         Key issues of stakeholder engagement, marketing and training.
·         Drafting an action plan for an Enterprise Risk Management initiative


Learning outcomes include:
·         Awareness of the advantages and disadvantages of different models for implementing Enterprise-wide Risk Management
·         Understanding the importance of stakeholder engagement, marketing and training.
·         Knowledge of drafting an action plan for an Enterprise Risk Management initiative


6.    Risk Assessment

This session will explore:
·         The process role of risk assessment.
·         A range of tools and techniques.
·         A particular focus on vulnerability through scenario analysis.
·         Some of the pros and cons - and what can we learn from them.
 Learning outcomes include:
·         An awareness of the core role of risk assessment processes.
·         An awareness of a range of tools and techniques.
·         Knowledge of why it is crucial to focus on vulnerability through scenario analysis.
·         Knowledge of lessons learnt from inappropriate risk assessments.


7.    Business Resilience

This session will explore:
·         Leveraging the top three to five foreseeable extreme event scenarios.
·         The advantages of moving away from a focus on extreme events and hazard to a focus on the vulnerability of the things we depend upon.
·         The application of a scalable tool aligned with a best practice Business Continuity Standard (BS 25999).


 Learning outcomes include:
·         Understanding the value of leveraging the top three to five foreseeable extreme event scenarios.
·         Understanding the advantages of moving away from a focus on extreme events and hazard to a focus on the vulnerability of the things we depend upon.
·         Understanding how to apply a scalable tool aligned with a best practice Business Continuity Standard (BS 25999).

8.    Continuous Improvement

This session will explore:
·         How to improve corporate capabilities on an ongoing basis by training and exercising
·         The key role of well designed desktop exercises before any extreme event
·         The key role of sensitively facilitated organization debriefs after any extreme event.


Learning outcomes include:
·         Awareness of the importance of improving corporate capabilities on an ongoing basis by training and exercising.
·         Understanding how to manage a well designed desktop exercises before any extreme event.
·         Understanding how to manage a sensitively facilitated organization debrief after any extreme event.

Thursday, April 14, 2011

After an emergency - a seven point self assessment

This diagnostic tool will enable you to identify areas of strength and weakness in processes, capabilities and skills. The results from carrying out the assessment will also help in planning and implementing process capability improvements and systematically focus on areas of weakness.

Format of the self assessment
The self assessment consists of worksheets within a free MS Excel workbook.
 

Scoring - The relevant matters to take into account in considering the quality of management exercised center around seven key performance tests.
 

Sections cover performance in the following areas:

Seven Key Performance Elements
1. Detection
To what degree were early warning systems in place? To what degree were they effective?

2. Interpretation
To what degree were systems and methods which "mapped" answers to the question "what does this mean?" (This might have involved sophisticated geographic information systems, or meetings with hard copy map overlays). To what degree were these methods effective?

3. Planning to Communicate
To what degree had you premised the range of stakeholders who needed to be listened to, and communicated with? This reflection should consider how you planned for those who were likely to be at risk and how you planned with those who had a responsibility to support the management of the risks.

4. Communicating - with those at risk
To what degree was your communication to and with people at risk effective? To what extent did it elicit "appropriate protective behaviour"?

5. Communicating - with those managing the risks
To what degree was your communication with people with a responsibility to support the management of the risks effective?

6. Roles and Responsibilities
To what degree did plans contain a method by which they were invoked, up-to-date contact and mobilization details for any relevant agencies, organizations and resources that might be required to support the response. (For example, did they contain guidelines regarding which individuals have the authority to invoke the plan and under what circumstances; and contain identified lines of communications, roles and responsibilities, key tasks and reference information.)

7. Organisation
To what degree was a method for the organisation of a broader (i.e. beyond your own organisation) collaborative management system in place? (Such a system would allow stakeholders from across the community to establish agreed and prioritized objectives in terms of the critical activities to be undertaken, the timescales in which they are to be undertaken and measures of success in terms of outcomes to be achieved.)
Performance levels are attributed: N - not at all, P - partial, L - largely, and F - fully

Monday, March 28, 2011

Focused information supports sharp decision making

Good CEOs know that when it comes to the relationship between information and decision making, more is not better.

This is in contrast to the real politik reflected in the wry humour of "The Smokescreen" (in Yes Prime Minister, by Jonathan Lynn and Anthony  Jay, page 188). In the world of politics, perception is key. So decision making is dangerous - and to be avoided wherever possible. To this end, the passage from "The Smokescreen" notes:

"There are eleven stages in a decision making process -
  1.  Informal discussions
  2. Formal proposals
  3. Preliminary study
  4. Discussion document
  5. In-depth study
  6. Revised proposal
  7. Policy
  8. Strategy
  9. Implementation plan circulated
  10. Revised implementation plan
  11. Cabinet authorisation"
The pasage goes on to note that any public servant should be able to ensure that if a policy is unwelcome, stage 11 will not be reached until the next election. Unfortunately this approach is seen too often - I guess that is why the television series was so popular with politicians.

In the real world, decisions have to be made - often quickly - and frequently under conditions of uncertainty.

It is under these circumstances that information which is focused on the decision makers' needs is critical. The decision maker may need to know all that is available to him or her. However it is more likely that they will appreciate a focused set of information tailored to their needs. At EPCB we address this requirement with a framework of information based on best practice business continuity standards, with which we then support clients to tailor to their context.
Excerpt from the Table used to Tailor Reports

The approach can be seen at "Tailored Reporting to meet your needs".

Friday, February 25, 2011

Innovative responses mitigate disaster impact (Christchurch 2011)



Christchurch impact indicator - dust rising from collapses after quake.
As the response moves to recognise the breadth of impact across the city, its infrastructure and its people, New Zealanders are applying several innovative "emergent resources" to mitigate the impact of this disaster.
Key issues are around "lifelines" - the networks that supply and link us to meet our core needs (from power, and water to communication).

The need to communicate is the glue that binds the efforts and three illustrations are apt:
1. Telecom NZ has 60 electricity generators and five portable mobile phone towers to keep the phone network up.
2. Google has set up an online finding service:

3. Online auction site Trade Me, set up a service linking people needing accommodation and assistance with those willing to offer it.
In this scenario of devestation, one hopes that these and other emergent, innovative approaches will be enough to see Christchurch get up and running.

Tuesday, February 1, 2011

Obvious and Necessary - modern risk management.

I came across an interesting article by Leon Gettler today titled "Risk management in the era of unpredictability" (page 6, in the Opinion and Analysis Business Section of The Age newspaper, 1 Feb 2011).

Interesting not only because it reflected a position dear to my heart, - but interesting because it was a lead article specialising in what I thought was "a given". Can it still be that modern companies and organisations HAVE NOT adopted a flexible approach to risk management? What are they thinking? The solution is necessary - and it is not difficult.

In terms of the necessity of the solution Gettler wrote:
"The conventional risk-management approach lists possible events and determines the probability of their occurring based on experience. You measure the costs and benefits of specific risk-protection measures and implement these measures for each risk. The problem is that it assumes risks are local and routine and fails to take into account the impact they may have on different organisations and states. It does not factor in the impact of the growing number of unlikely but potentially devastating events. It is an outdated approach that robs organisations of their agility. Clearly, these sorts of events are impossible to predict. So, how should organisations respond? It is a subject that should be reviewed by boards regularly. Companies should have scenario-mapping teams that report to the board and work with suppliers and customers to identify potential threats. Twenty-first century risk management is not about predicting the future. It is about systems and relationships that create an organisation agile enough to respond when disaster strikes. (my emphasis) As it will."

In terms of the solution being "straightforward", if an organisation asks the fifteen questions in the diagram below, they will have the necessary and sufficient profile - of both their vulnerability and their needs.



Friday, January 21, 2011

"One Off" disaster levies reflect poor policy.

This morning, Australians woke to page one headlines "PM Flags one-off flood tax".
This raises questions beyond those driven by party politics. It raises issues around how we, as a community, operate strategically. To what degree we operate sustainably.
Inundated floodplain development, Queensland, 2011
As a community, (in this case the "shared association" is as a nation) our constitution clearly nests the responsibility for the protection of life and property with State governments. Founded as a colony, we have a legacy of ports and hinterlands which have competed to attract development. A key discount lever used to attract development in the past has been "discounting". Sometimes with cheap flat land served with transport infrastructure and subsidised migrant labor. Sometimes with "light" requirements around standards. This has been so from flood plains to industrial zones. The outcome has been "hazard havens" where some States have imposed risks on citizens more severly than other States. Further, the benefits from such ventures do not generally go to those living near to the risky sites.

All of this is contextual to the challenges of the future.
Now - at a national level - we need to agree approaches to some fundamental questions.
By what country wide, consistently applied criteria will we address risks?
A systematic risk management framework
The risk management record of this national government has been characterised by a series of policy failures (from pink batts to school funding). Central to all of these failures has been the inability to bring the right questions to the table. The current knee jerk looks like the trend is embedded in their culture. One off fixes applied indiscriminately and an ignorance of insurance are indications of a government struggling to develop and apply a comprehensive and integrated approach. Unless a systematic and thoughtful approach is undertaken, we are likely to see further grounds for challenging the integrity of the current government.

Tuesday, January 4, 2011

New Business Continuity Standard for Australia's financial sector


The Private Sector is increasingly held accountable for quality risk management. In many cases this takes the form of mandated performance standards. The Australian Prudential Regulation Authority has recently released the draft of their proposed Business Continuity Management Standard. The proposed standard aligns with international best practices. It makes Boards accountable for very specific Business Continuity Management capabilities - summarised in Clause 21 - to include (at a minimum):
1. Business Continuity Management Policy;
2. Business Impact Analysis including Risk Assessment;
3. Recovery Objectives and Strategies;
4. Business Continuity Plan including Crisis Management and Recovery; and
5. Programs for Review and Testing of the Business Continuity Plan; and Training and Awareness of staff in relation to Business Continuity Management.

APRA's draft Business Continuity Management Standard (PDF)

Monday, December 13, 2010

In any Risk Management venture "Establishing Context" is crucial

There is a tendency for people to want to rush to the exciting stuff. To get their hands dirty with extreme event scenarios and risk assessments. That is a mistake.

It is important to pack your bags for the long trip - to lean your ladder up against the right wall - to start with an awareness of issues which might ambush "the end in mind". These phrases apply to any systematic risk management process - where an initial emphasis should be on scoping context. If not, believe me, it will unravel later.

So with many "burn and learn" examples over many years, may I suggest the following three key considerations:
1.    Develop a project plan to establish the risk management context which includes:
a.    the aims and objectives for the establishment of context;
b.    a matrix of stakeholders against their roles and responsibilities; and
c.    a budgeted and scheduled plan for anticipated research and consultation.

2.    Profile the entity for which “context” is being established (e.g. the structure of the organisation; or the demographics of a community) by mapping key networks including:
a.    relationships between people and organisations to identify and evaluate existing networks; and
b.    other network relationships that do not exist, but which might add value should they be developed and established through negotiation, consultation and marketing strategies to gain trust cooperation and support.

3.   Apply strategies to seek and obtain stakeholders’ co-operation and ownership of the risk management context including:
a.    establish and coordinate open communication structures among the networks mapped;
b.    consult with stakeholders to map their issues and needs across the following aspects or “spaces” - social, legal, technical, political, environmental, and financial; and
Establishing risk appetite early is fundamental
c.    identify criteria and thresholds for “acceptable risk” across the aspects or “spaces” identified with stakeholders; and document the level of agreement and divergence between stakeholders regarding risk criteria to be applied. Two sets of criteria should be addressed. Risk assessment criteria – that is, “what do we care about - and how much do we care”; and what are agreed risk treatment selection criteria to be applied.

Friday, November 26, 2010

Disaster Funds: Lessons & Guidance on the Management & Distribution of Disaster Funds

Please find reproduced below, in full, an email from Dr. John Twigg

Disaster Action - a great organisation - has just released what looks like a really useful new publication:

"Controversy surrounds many disaster funds, even decades after they were launched. Little guidance is available to those who take on the responsibility of managing and distributing funds in accordance with the wishes of the donors. Disaster Funds: Lessons & Guidance on the Management & Distribution of Disaster Funds, published by Disaster Action with support from the DCMS and the British Red Cross, fills that gap. It is an essential resource for emergency planners, fund trustees, administrators and managers."