Search

Monday, November 13, 2017

The risk of portfolio management

The original of this article was posted on: Computerworld UK


Portfolio management is a tool promoted to improve business-IT alignment. According to the advocates it will help to ensure maximum business value creation from IT-enabled business projects. To make good on such a claim it must be a power(full) tool. However as any builder can tell you, when working with power tools, you better know what you are doing otherwise you could really hurt yourself.

There are many flavours of portfolio management these days. If you “Google” the term (as I did) you might be surprised about the end-less possibilities to apply this tool. The connoisseurs amongst the readers however may recognize terms and claims from the Val IT Framework owned by ISACA in the opening paragraph of this article. According to ISACA “The goal of the Val IT initiative, which .., is to help management ensure that organizations realize optimal value from IT-enabled business investments at an affordable cost with a known and acceptable level of risk.” One of the three processes that form the core of this model is called portfolio management. It is this (kind of) use of the tool portfolio management that forms the bases of this article.

Imagine the following situation. According to those in the business the IT Project “just do not deliver”. They are usually late, over budget and if they finally deliver the system functionality is “useless” from a business perspective. Time for change so we bring in a consult. The advice is that we will start managing our IT-enabled investment portfolio by implementing the Val IT approach. So the first step is to decide who should be at the decision table when it comes to choosing were to invest the scarce resources for IT enabled projects (In plain English: Who decides which IT Department and/ or project gets how much money). So we set up meeting schedules get business and It representatives, get the necessary mandates, set (strategic) boundaries etc. etc. In terms of Val IT we set up Value Governance (one of the three primary processes). Step two is that we stop the problem from growing. So for all new initiatives Business Cases become mandatory. Furthermore we ensure these business cases contain all relevant information so decision makers can compare apples with apples and make high-quality decisions about which investments should be pursued. The individual investments that do get funding are tracked (and if necessary adjusted) during their life-cycle to ensure they actually deliver on their initial promise (We just implemented the Val IT Investment Management process). To ensure we maintain a balanced mix of investments to “keep the lights on” (maintain the current operational systems) and create new business functionality (by building new systems and services) we introduce Portfolio Management (the third core Val IT process).

After initial implementation of the model we have the next challenge: How can we decide if the newly imbedded organizational model is actually working and what key performance indicator can we use to steer for continues improvement? A good indicator might be the number of Investments stopped during execution because they are no longer expected to deliver the business value initially promised (in the business case). Since we start with a lot of legacy investments (projects and budgets started based on the old decision making system) at first the indicator would be high because we ”need to clean house”. The old system (IT Departments and Projects) need to “shape up” and present (and if necessary create) the necessary business cases to the Value Governance institute. This will result in acceptance as a legitimate Investment into the Portfolio Management Process in which case the investment will be managed going forward according to the Investment Management process or in killing the funding. All “never ending projects” that lost sponsorship during their existence but somehow keep on running and all the systems, infrastructure and supporting It-departments that cannot show any business value what so ever will be weeded out as a result of this action. This is about as painful as it sounds. Most often the perception of the IT-domains performances will take an additional hit in this phase. After all we opened up the “black box” and cleaned out the “skeletons.”. But “no pain, no gain” so now we have a good new management system to improve Business-Value creation of IT enabled business investments. Based on our learning we should be able to improve our system so our KPI (% of our investments items stopped prior to completion because the expected business value is no-longer achievable) reaches zero. In plain English: “All investments are completed by achieving their expected business value. Since we only start “good” projects there is no reason to stop them half-way. “ I would say ultimate business value of IT!

Wrong, you most likely just killed all entrepreneurial spirit in your organisation. To understand this statement you need to understand the limitations of business cases. A prior article “Hail the almighty business case” explains that the purpose of a business case is not to eliminate all uncertainty and thus risk but to make the risks and uncertainties visible so those who need to decide can take them into consideration when they decide. The biggest risk to any organization will always be that things change in an unforeseen way over the course of time. So initially sound investments might need to be stopped early just because the “world keeps on turning” during the project (investment) execution phase. If we only invest in things we are certain will generate business value we might be overlooking high-value opportunities just because we are not 100% certain we can actually achieve the value. For example any investment in exploring new-technology for applicability to the organization would be stopped (by definition it is uncertain what the value potential of any such new technology might be when we start exploring). Entrepreneurship and innovation are valued terms for most organization. But these terms are closely associated with “exploration”, “going were no man has gone before”, “transforming uncertainty in understanding”. In general these kind of activities involve risk taking. If the value potential is considered high we may decide to accept the risk that the value does not materialise. So IT Portfolio management is not to avoid risk but to balance all the investment so the sum of all risk in the individual investments does not exceed the organizational risk appetite.

A better indicator would be to check how long it took the system to learn that the “world had turned” and how effective and efficient the reaction was (in adjusting or stopping the investment). Portfolio management is not about only honouring 100% “sure thing” investments it is about creating a balance between “keeping the lights on”, “no-brainer high-certainty, average-return-on-investment projects” and last but not least “cutting-edge, high-risk, high-value-potential investments”. To forget the last category is to forget about innovation!

Wednesday, May 7, 2014

Material Risk: Setting the board agenda for IT Governance

“The board of directors does not give IT Governance enough attention”, one of the most difficult tasks in IT Governance is to get the topic on the agenda of the Board of Directors. Identifying the material risks will give the arguments to achieve this task. 


The complaint quoted in the opening line is often heard amongst IT Governance experts. And within most organizations it is probably true. However most of the time the discussion stops there, a statement of fact. Many experts seem to share the frustration of lack of attention from top management but also believe there is very little they can do about it. No matter how hard they try, the board of directors just will not accept how important IT Governance is for the organization.

As a starting consultant I was educated by an organization that did not believe in such statements of fact. You address the issue, find the underlying causes and resolve those. So here goes. When I listen to the arguments of why the board of directors should get more involved with IT Governance I keep hearing the same arguments: “These days IT is persuasive in the organization”, “Cost of IT is high and subsequently so are the cost of failure of IT”, “IT Projects are big and costly projects and should get appropriate attention from the board of directors” and many more similar arguments. What almost all of these arguments have in common is that they are made from the perspective of the complainer who in most cases resides in or works for the IT domain. First of all we should address the issue from the perspective of the board of directors, after all they need convincing. So as usual it is much smarter to look at the issue from their side and then try and find the arguments that make sense from their side of the table. Look at the problem from the top down not from the bottom up. When you try to do this you might find it gives very interesting results. For example a couple of years ago I was assigned to a major oil company and as usual big organizations spend big money on IT related projects for instance SAP Implementation projects with budgets of hundreds of millions, Infrastructure projects with similar budgets. So yes, I felt that given the size of these projects IT Governance should rightfully get a lot of attention from the board of directors. Until I came across a listing of the top 50 biggest projects running in the organization. When I looked at the list I found that there was no IT Project ranked in the top 50. For this organization a “big project” was building a drilling rig capable of drilling “ultra-deep” in the Gulf of Mexico. Another project in the list, building a town for 10.000 people, harbour facilities, all infrastructure and industrial installations for the oil and gas drilling operation on a deserted Island of the cost of Siberia. In this organization, to reach top 50 the project budget had to be at least a billion instead of just a couple of 100 million. The moral of the story: It might look big and important from the bottom up but from the top down it may look completely different.

When you look at the issue from the perspective of the board of directors the first think you realise is that in most organizations the board does not fiddle around all day. The number and variation of topics that require their attention is vast and the agenda of the board is normally completely full. So if IT Governance claims more time in the board’s agenda other topics automatically get less attention since time is a finite resource. So the trick is to set the board’s agenda so all those topics that are important enough to receive direct attention get time relative to their importance. However given the incredible variety of topics this is like comparing apples to oranges.

Here we introduce the concept of “material risk”. For me a material risk is such a risk that if it happened it would gain the (negative) attention of the organizational stakeholders. More specifically those stakeholders that the Board of Directors is accountable to. Some examples, a project failure of the SAP Project with the Oil Company would have internal repercussions but would most likely not have a serious impact on the financial figures for the organization so it probably would not attract a serious negative reaction from stakeholders like the shareholders. On the other hand a major Dutch bank had a project to upgrade its internet payment services. When customers of the bank were unable to use their internet banking facilities for the third time in a row the CEO of the bank decided to apologise on national TV promising it would not happen again. This in reaction to the public outrage resulting from the (recurring) incidents. Clearly the IT Project of the bank had a material risk attached to it.

So to set the board agenda you look for the topics that have material risks attached. Interestingly those topics that usually make the board agenda (strategy, major projects and sizeable investments) always seem to have material risks attached to them. The difference is that now the reason why they are on the agenda can be logically assessed and compared based on the change and impact of the attached material risks. It is note worthy that in almost all cases were disaster struck an organization and the board of directors was taken by surprise, the unawareness of the board can be found in the failure to identify and manage a material risk. For example at the start of the financial crisis almost all boards of financial institutes were taken by surprise because almost nobody correctly identified the material risks attached to the financial products and services that were arguably one of the causes for the crisis.

Thursday, November 24, 2011

Not my problem fields, Lessons from the Hitchhikers' Guide to the Galaxy

Repost, article originally posted on ComputerWorld UK

Have you ever noticed how good humour can make you laugh and cry at the same time? Laugh because the situation it describes is so ridiculous, cry because it is “too close for comfort”.
Recently I came across “the Hitchhikers Guide to the Galaxy” (again) and once again I was confronted with the “Not my problem field”. For those not acquainted with the guide the “Not my problem Field” explained in my own words (I hope the creators of the guide do not object too much to my interpretation): In the distant future it is recognized that most creatures are curious by nature. Therefore trying to establish invisibility technology goes against a basic force in the universe (curiosity) and thus is very hard if not impossible to achieve.
However another basic force in the universe is the tendency of creatures to shy away from things that might have a negative impact on them. So instead of convincing creatures that something is not there one should convince them that they should consider it “not their problem” because showing an interest might have negative impact for them.
As a result they will ignore items surrounded by the “not my problem field” effectively blocking it from their mind and making them invisible. Hence the “Not my problem field” technology is developed in the future according to the Hitchhikers Guide.

When I came across this section of the guide once again I had the tendency to laugh and cry at the same time. Since I was reminded of the “not my problem field” theory I became convinced this is not an Einstein like theoretical line of thought (disguised in comedy) I am now convinced we see the practical impact of these forces in the universe in everyday life. When I hear a project manager say that operational maintainability of the IT System he is supposed to deliver is not described in the specification and therefore not his….. I think: Field operational! Or the IT domain that has no idea what business value of IT means, strong field in place!

But the worse of them all is the field created by outsourcing. It is amazing how many organizations believe that if they outsource their IT (Support, development, etc.) things like Information Security, IT Compliance and even IT (related) Risk are no longer their problem. Only recently somebody told me that they had an SLA (with penalty clauses) with their external providers so IT Security, IT Control and IT Risk were no longer their problem.
So I asked him if he thought the existence of penalties ensured that the provider would always meet the SLA values. As an example we looked at the Service Level were the provider promised he would resolve 90% of all high priority incidents within 4 hours and 100% within one workday. Focusing on this promise alone we could easily come up with a number of scenarios were the provider just would not be able to meet the commitment even if he wanted to.
This showed two things:

1. One should look at 100% promises with suspicion
2. Penalties are not risk mitigating controls

At best penalties transfer the risk from the customer to the provider. Based on this realization customers should think of the potential impact of their providers failing to meet their service levels. On most cases they will find that the penalties imposes do not even start to cover their potential losses (both material and immaterial) recent examples of data privacy breaches for example show the incredible reputational damage these can do.
The fact that the IT Service Provider might share some of the blame almost never eases the pain for the organization. The situation becomes even worse if one realizes that it is common practice amongst IT Service Providers to implement risk mark-ups for those contracts involving penalties. In this case the mark-up is reserved to pay the penalties should they be imposed so basically the customer pays for his own penalty!

So where do all these “not my problem fields” come from if they are so undesirable? In the case of outsourcing they are actually a sales argument “outsource and all these operational issues are no longer your concern we will handle them for you”. What this statement fails to recognize is that you can outsource (operational) responsibility but not overall accountability towards the organizational owners and stakeholders.
Furthermore “not my problem fields” are the (unwanted) side effects of establishing governance structures and their supporting assignments of authority and responsibility. On the one hand it is undesirable that everybody is involved with each and every decision because such an organization would lose all agility. On the other hand every time somebody is excluded from the decision making process a small “not my problem field” is established and it might become stronger over time.

So when you accept that “not my problem fields” exist and are very often undesirable how should one react? I came across one organization that had (at least in theory) the answer and till date I feel they do a good job with the operational implementation of the solution. For this organization the solution comes from one of their core cultural values. The value is called “enterprise first”.
It basically means that the overall good of the organization comes before the individual interests of, managers, departments, divisions, etc. If somebody is asked to assist with an issue he cannot respond that he will not assist since “he is not responsible” (read: not my problem) if the enterprise benefits from resolving the issue everybody should think “enterprise first” and assist if required.
With this solution it is important to realise that it is comparatively easy to commit such a corporate value to paper. However to implement it and make it part of the standard attitude of all those who take part in the daily operation of the enterprise is a completely different challenge. The more so if you realize that those involved with daily operations are not necessarily employees of the organization these days. In recent years a growing percentage are temporarily assigned external (human) resources that might not share (or be exposed to) the same core corporate values.

IT project management: The standards of change

Reposted from the original article on ComputerWorld UK

IT projects are a vital element in the activities of the IT domain. For a project manager what standards are there to help organise their work and how do they relate to the other IT activities and standards?

The IT domain offers services related to the information used by the organisation. When we look at the internal working of the IT domain there are two important fields of operation. First ensuring the continued availability of services currently offered by IT and used by the business. Second building new services or changing current offerings to keep aligned with the ever changing requirements of the business. Creating new services or changing current services are often organised in the form of projects.

Wikipedia defines project management as “the discipline of planning, organising, securing and managing resources to bring about the successful completion of specific engineering project goals and objectives.”

Pure project management methods

When looking at the above definition for project management it is clear it is not just for IT Projects but applies to any type of project. The second observation is that the goals and objectives are a given in this definition.
When we look at project management an important organisation to start with is the Project Management Institute the Wikipedia page gives an overview of the PMI and their offerings. Note worthy are that the PMI offers certification and owns the Project Management Body of Knowledge (PMBOK). The PMBOK is a world-wide known and accepted standard for project management which offers a common language, structure and definitions for those using the standard. However PMBOK was created as a standard for any type of projects not specifically for IT Projects. As a result it can be challenging to decide what sections are applicable and how they should be used to structure IT projects.

Developed specifically for the management of IT projects is PRojects IN Controlled Environments (PRINCE 2). The Wikipedia page gives a good overview of prince 2. Furthermore the Office of Government Commerce (OGC) maintains the official website for the method. The official website also shows that OGC owns a number of related models such as ITIL (a best practice model to help organise the operational section of the IT Domain).

Since the deliverables of the projects are handed over to this part of the IT Domain alignment between these organisations (and the models used) is important. The strength of Prince 2 is that it offers a lot of help to internally structure IT Projects. Since the OGC is an institute from the British Government it is no surprise that Prince 2 is widely accepted and used in Europe. Even more so it is one of the leading project management methods worldwide.

Critics of Prince 2 say it is too much internally focused towards organising the internal project structure and does not offer enough focus on the interaction of the project with the “outside world” and “what comes next”. Prince 2 advocates counter that the method is OK but that it’s the way the method is used that does not pay enough attention to the outside world. Furthermore that ITIL and Prince 2 are developed, ran and maintained but the same (OGC) institute helps to ensure aligned between the two models which should help to facilitate the hand over from service creation into service production.

Other relevant models for project management

How to organize the interaction between the project (manager and team) and the environment? Depending on the size and nature, a project can have many different external stakeholders.
For a Project Manager stakeholder management is a very important skill. Stakeholder management is all about indentifying those who are affected or who can affect the project, understanding their needs and managing their interests. Unfortunately there is no generally accepted standard approach for stakeholder management. The above link to Wikipedia gives a general introduction and a starting point for those interested in the subject.

ITIL

We identified one stakeholder already: IT Operations, charged with the run and maintain of the deliverables of the IT project. For a project manager who does not like negative surprises at the end of his projects it is good to ensure a basic understanding of what drives this stakeholder. ITIL as one of the leading process frameworks for this stakeholder would help facilitate the relationship. Owned by the OGC (also owner of Prince2) the day to day management of the model is left to the IT Service Management Forum (itSMF).
The ITIL model is the leading process model for the operational management of IT Services. According to critics it is too much focussed on Infrastructure Management and does not pay enough attention to Application Management. With the introduction of ITIL version 3 the model also addresses topics regarding the strategy and design of Services but it still does not address the topic of Project Management.
An even more important stakeholder is the project owner. Somebody (usually in the business) has a requirement for a new or changed IT Service and, just as important, can make available the resources mentioned in the definition of project management. Mismanagement of this stakeholder is arguably the primary reason of IT Project failure. Clear and correct translation of the requirements from the project owner and limitations set by this stakeholder into workable project goals and objectives is a science if not an art in itself.
Business case creation and management is a field of expertise focused on structuring and improving the Project Owner/ Project Manager interaction. Especially with bigger longer running projects, circumstances change over time and the initial owner requirements might change during the course of the project. So Business Case management does not stop at business case creation, continued validation and updating of the business case is also part of this discipline. Since this is a relatively new area of attention there is currently no clearly leading method for Business Case Management. Prince 2 offers some assistance here. So does the ISACA framework for Business Technology Management (ValIT).

ValIT

ValIT uses an angle towards the relationship between the Project Owner and Project Manager different from pure Business Case Management. According to ValIT the relation between the business demand and IT Supply is not just one set of requirements for a new or changed services combined in a single project. The relationship consist of a portfolio of services the IT Domain offers towards (sections of) the business. Given the limited resources of the organisation Business and IT together have to decide how to ensure maximum business value from the IT Portfolio in an ever changing environment.
So not only different (change) projects are competing for the scarce resources but also the funding for the operational services is taken into consideration. The benefit of this approach is that it places the individual project into its contexts towards other IT-related investment categories and thus gives information about the “boundaries” for the project. On the other hand the project manager often has very little influence on the decisions made in the “grant scheme of things”.
Since the definition of Project Management also mentions “securing resources” a project manager should have an understanding of (IT) Portfolio Managementbecause this discipline is responsible for the allocation of resources to projects and other IT-investment categories. Besides the ISACA model already mentioned the OGC has models and methods addressing this field of attention:
  • Management of Portfolios (MoP)
  • The Portfolio, Programme, and Project Management Maturity Model (P3M3)
  • Portfolio, Programme and Project Offices (P3O)

Programme management

Besides projects and portfolios we also recognise programmes. In practice one often finds that organisations call large, influential projects programmes. This would indicate that programme and project management are basically the same.
In theory however there is a clear difference between the two Wikipedia describes it as follows: “Project Management... It is sometimes conflated with programme management, however technically that is actually a higher level construction: a group of related and somehow interdependent engineering projects.”
Without further discussing the distinction between projects and programmes it is important to recognise these two are closely aligned. A Project Manager working in an environment where program management is established should ensure that he has a basic understand of programme management, specifically what the applicable definition in his environment is. The OGC offers a model for “Managing Successful Programmes” (MSP) furthermore the PMBok offers a lot of information about program management.
A special application of programme management techniques are the so called “organisational change programmes” these recognise that when you change one component of the (business) organisation this will impact other components as well. For example if you change a system this will most likely change the way is it is used (the business process) it will affects the users (People), etc.
A business change programme looks at all these different aspects that need to be addressed by as many different projects. These projects are clearly related and might have interdependences. From a manageability perspective however, the program is dissected into multiple better controllable and manageable projects.
The importance (and value) of IT for the correct operation of the business has grown over the decades. This also means that failed IT Projects can have an ever growing devastating effect on the organisation. As a result more and more stakeholders have a growing demand for control over IT Projects. The requirements for control might come from the higher management and/ or enterprise directors (IT Governance), internal or external rules and legislation (Compliance), demand for the management of security and/ or risk (Security and Risk). For the project manager all this translates into requirements to proof he is in control of the project and its inherent risk.
These requirements can differ greatly depending on the size and nature of the organisation and the individual project. These days you find that more and more organisations have an IT general control framework applicable to their IT Domain this framework would most likely also contain general controls for projects. Standards and frameworks used are (amongst others) the ISO 27000 standard for Information Security Management Systems, ISACA’s Cobit and RiskIT.
Part of the stakeholder management required from the Project Manager is to understand who the parties are that require control and what their requirements are. The control models target the complete IT Domain not just the IT Project organisation so choosing with standard(s) to adopt is often decided elsewhere in the organisation.

Organisational and process improvement models

Until now we have looked at the use of standards and the way they impact projects from the viewpoint of individual projects. However standards like CMMi from The Carnegie Mellon Software Engineering Institute (SEI) and Six Sigma (originally developed by Motorola) aim to organise the processes for the complete IT Project Organisation (the section of the IT domain responsible for all IT Projects combined).
These approaches basically try to learn from past mistakes and create and improve the organisation specific Project Management processes for time. For the individual project manager this means he can build on past experiences and does not have to re-invent the wheel for each specific project.
This article does not pretend to offer a complete overview of all models and standards that might be relevant to IT Project Management. Other organisations like ISO, the NIST (from the American Government) and Standards Australia have a wide variety of standards and frameworks which might help organise specific IT Project Management related topics.

It is important to realise: You need a screwdriver if you want to fix a screw but a hammer for a nail. Depending on the issue a nail or a screw will offer the better solution. Understanding the positioning, goals, strengths and weaknesses of individual models is the best way to decide which is most appropriate given the individual situation.

Tuesday, January 4, 2011

Internet information havens - the 21st century tax haven?

The original of this article was posted on: Computerworld UK

The Wikileaks saga raises information freedom issues that affect us all.
In the dispute between the US Government and Wikileaks it is interesting to see the tactics used. We are breaking new ground here. The way this fight is fought leads to all kind of observations and questions.

So what is it that is happening here? Let us start with an unnamed US governor that wants to “Hunt Assange down like a terrorist.”Well, there once was this religious leader that did not like a book written about his religion so he called for ''all the Muslims to execute them, wherever they find them.'' In this quote “them” is the author and (that’s interesting) the publisher. Remember Salmon Rushdie? I have no idea why this image came up in my mind clearly there is no analogy here.

In an earlier article I questioned the ownership of the information published by Wikileaks. If you hold that the US Government owns that information than basically it was stolen which would make Wikileaks guilty of fencing stolen goods. But in that case the logical course of action for the US Government would be to accuse Wikileaks and/ or Assange of this particular crime. The next step would be to ask the United Kingdom for his extradition. I am no expert but given the good US – UK relationship I would expect they have reasonable extradition regulations in place to make this possible. For some reason the US Government chooses not to walk this road. Makes you wonder about the initial ownership assumption.

The Wikileaks webservers are located in Sweden and it is interesting to note that at no time the Swedish Government openly considered “pulling the plug” on the servers. They might have been asked to do something like that but till now they managed to steer clear of this fight. More interesting however is that Wikileaks and Assange have very close connections with the Icelandic government.
According to the stories they were involved with drafting legislation for Iceland about freedom of information which should position Iceland as a “New media haven”. Something similar to a tax haven but than for information instead of money. Interesting to note that Assange and Wikileaks trusted the deliverables of their efforts so much that decided to host their site in…. Sweden!

The incredible coincidence that Assange is accused exactly at this point in time has so much similarities with the plot of the movie “Enemy of the State” it has to be a coincidence. Nobody can be that obvious, or can they? Let’s treat this issue separate and leave the rest for the conspiracy theorists.

Next thing that happens is that third-party Internet service providers start pulling the plug on services that Wikileaks needs. Let us assume that I have a fight with my government about money (let say they claim I owe them taxes) but my money is located in a Swiss bank and we all know countries like Switzerland will not cooperate unless you prove to them that I was involved in illegal activities while gathering that money. See the analogy here? This amazing thing happens, the energy supplier of the bank let us know they will not supply any further electricity so the bank cannot operate anymore. Even more so the vault supplier cancels the contract with the bank. One by one the supporting services are dropped. And funny enough the internet services are all supplied by US companies.
It is unclear if the suppliers have been “persuaded” or if this is some kind of self-censorship but the message is clear. As one supplier states on their website: “… provides developers the tools to build failure resilient applications and isolate themselves from common failure scenarios.” Not a single lie there, you only invent a new failure scenario! At this time you think you have seen it all but guess what. Reality is stranger than fiction.

The Wikileaks site is provided by the same provider a few weeks later. This time a Danish newspaper decides to host a mirror of the Wikileaks site using exactly the same service provider. Politiken, we all believe the fact you choose this provider is a coincidence. After all no self-respecting newspaper would try to manipulate the situation so they are in the middle of a news scope. The press writes about the news they do not try to create it. After all if the police did anything like that we would call it entrapment!

Another of these suppliers claim on their website: “It's safer, it's faster and it's everywhere. Use XXX to shop at thousands of web-sites, knowing that your financial details are never shared.” Indeed you cannot share what you cannot use but “it’s everywhere”? Guess not.

Off course there is the stupidity of those on the other side as well. “Operation-payback”, I get the image of football hooligans. Not really interested in the welfare of their club just aggression and stupidity looking for a reason to manifest itself. Their actions, they give the “other side” the opportunity to portrait themselves as the victims and legitimize their actions in the eyes of the general public.

So what is the conclusion who wins who loses? Assange and Wikileaks, they clearly gained publicity but as the new form of Internet aided journalism or just an opportunistic, “shoot everything that moves”, conspiracy paranoid new form of anarchy? I guess time will tell.

The lady governor? She lost so much credibility in the past it would be impossible to lose even more. However she did get publicity so I would say a draw for her.

The multinational, independent Internet Service providers that are caught with their paints down? I hope they make a decent portion of their turnover in the US because it will cost them a bundle to re-establishtheir lost credibility in the rest of the world. Then again the as the newspaper showed within two weeks it is business as usual with new sites using the same services. I would say these companies lost. Still I would love to see their financial figures in the coming period to see if their actions were indeed “bad for business”. Maybe the world has turned so cynical that organizations that prove to be this untrustworthy do not even have to pay the price.

The US Government? In this world there are a number of countries were the government operates a “ministry of truth”. The way this incident has been handled basically showed those governments “how it’s done”. Even worse countries like Venezuela, Iran, North Korea but also Russia and China now have example tactics towards information on the Internet they do not appreciate.
The US Government has lost the “high ground” should other governments use similar bully tactics. Complaining would be like “pots calling the kettle black”. US Government how does it feel to run a “ministry of truth”? You lose!

So who wins? Countries like Luxembourg, Switzerland, the Caymans and others made billions by providing tax havens with banking regulations that give them the image of independence and trustworthiness even when the “big boys” come knocking. I do agree with Wikileaks and Assange about the need to create “New media havens”. However I would not make it especially for “New media” but for information in all forms so I would call it an “Information haven”.
This incident shows the need for these information havens and in my book Sweden gained admittance to the list. Given the still growing importance of internet in this century of information I would expect that this list will become as rewarding in this century as being considered a tax-haven was in the last one. Sweden, you win!

Wednesday, December 22, 2010

Wikileaks: Freedom of information versus information privacy

Article reposted from original posting on ComputerWorldUK

The commotion over Wikileaks and Julian Assange is incredible. Even more incredible is the polarisation of opinions you find on the internet. It ranges from “Assange for president” to “Assange the digital Osama Bin Laden”.
Stepping away from the opportunistic rhetoric we should realise that this discussion involves fundamental issues concerning information ownership, information privacy, freedom of information and the way we handle information on the Internet.

I believe that the law should just be the written representation of what we as society believe is right and wrong. So this article is not intended to discuss if Wikileaks and Assange are acting unlawfully and should be persecuted but our beliefs, as a society, of what is right and wrong. In itself the lawfulness is already an interesting discussion since the Internet supersedes any geographical boundaries. So which country law should govern the Internet?

Monday, December 20, 2010

Bonuses and sanctions


In Holland there is a saying: You catch more flies with honey than with vinegar. Indeed if we look at the causes of the financial crisis in a number of cases the drive to achieve the incredible bonuses that are customary in the financial sector seem to have outweighed the sanctions the enterprise risk department might or might not have imposed for excessive risky behaviour.

First of all this shows an underpinning feeling regarding enterprise risk and control: Enterprise risk and control limit the possibilities of "the fast and the furious" to reach for the sky. This feeling that enterprise risk and control only limits the possibilities of the organization to maximize on growth and profit potential is surprisingly common also with people that should know better. Some time ago I had a conversation with an account manager of the management consulting firm I was working for at the time. The customer we were discussing was a supplier of high-tech production tools for the computer industry with a world-wide customer base. The company is a world-wide market leader in its field of business. We were discussing if they might be interested in my particular expertise (IT Governance, Risk, Security and Compliance). I will not soon forget one of the statements my discussion partner made: "This is a fast moving company with a young, entrepreneurial, can-do culture. They have no interest in the control resulting from IT GRSC since it would limit their possibilities to maximise growth and profit." Not his exact words by the way but close enough. Such convictions however are amazing for an account manager of a management consulting firm. What made it worse was that he was also the company director overseeing the consulting business for customers in the production sector. In response I have a question: Why does a formula 1 race car need breaks? Answer: To be able to drive faster. Explanation: No formula one driver in his right mind will drive his car at full speed unless he is convinced he will be able to slow down in time to make the next corner!

These days we look at the causes of the financial crisis and the actions to be taken to ensure it does not happen again. There seems to be consensus that Governance and Risk mechanisms have failed in the financial sector. Regarding the solutions the discussion often turns towards the (according to some excessively) high bonuses customary in the financial sector and the need to limit these. Interesting to notice that the amounts of the employee remunerations are not a primary focus point of any of the Governance and Risk models and regulations I checked (amongst others COSO ERM, OECD Principles of Corporate Governance, Basel II, ISO 38500). The Cadbury report does address the issue but comes with the following statement: "The Committee has received proposals for giving shareholders the opportunity to determine matters such as directors' pay at general meetings, but does not see how these suggestions could be made workable." Do the models and regulations have a blind spot on the issue? One could argue that (IT) Governance and Risk models and regulations do target organizational objectives and since bonuses (in general) are connected to achieving objectives there is a causal connection between the two. However this would not explain why the discussion only focuses on the height of the bonuses. One would expect the discussion to focus on the circumstances under which bonuses are awarded, not primarily the values.


It is understandable how the high financial bonuses are at the core of the public discussion since they speak to the imagination of the public and are sure to create public outrage: "Make so much money for yourself and loose so much money for the rest of the world". To exclusively focus on the amounts keeps it simple and understandable for the general public. For opportunistic politicians and press the opportunity is just too good to pass. Though I do not want to defend the bad apples we should not forget that it was the financial sector that made the economic boom of the last decades possible by creating new financial products that made more investment capital available to a wider audience. It is the COD's that made mortgages more widely available and made home-ownership possible for a bigger percentage of the population. These and other financial instruments that were eventually misused and are partially the cause of the disaster did initially do very good things. As long as the financial sector supported and fuelled the economic boom nobody seemed to care that they made a "good living" for their effort.


There is one reason to discuss the height of the bonuses and this is a basic law of security and control: The higher the possible benefits the bigger the temptation to break the rules to achieve them. As a result a bank is normally better protected against robbery than, let's say, a poor man's home. One response is to try and limit the possible benefits of misbehaviour (lower the bonuses). But it is a fact that the financial whiz kids who earn these incredible bonuses make even more money for their employers and they are in short supply. So unless you want to rethink the fundamental concept of capitalism any solution that might get implemented will go directly against the basic supply-and-demand law of economics (High demand for items in short supply will drive the price up).


There is however another approach. As we noted in the beginning, currently risk management is seen as a limiting factor on maximising growth and profit. The basic attitude seems to be: Don't do it because it is too risky. However an alternative approach would be to make target correction based on inherent risk. We all know this attitude: The better your financial situation and past history the better terms you are offered on new credits (Getting a loan or a new credit card is much more expensive for a person who went bankrupt in the past). In the stock market we expect a better return on investment for venture capital when compared to an investment in a blue-chip fund. As the Greek government learned the hard way in recent days a triple-A rated government bond does not have to offer as much interest as a bond of a less reputable (and thus lower rated) government to attract investors.


Could we use that principle elsewhere? If we look at the Investment portfolio for (IT enabled) organizational investments, for instance, we could look at introducing a risk-rating system for each of the proposed investments. The (financial) goals, for instance the expected return on investment, could be adjusted based on the project risk rating. If we came up with a rating system that factored in the past performance of the key-project personal like project and program managers etc. we could use that as the bases to steer risk-aware behaviour of these people. Risk aware attitudes would translate towards better (financial) goals and targets. Since these targets in general form the bases for the bonuses earned this would mean bonuses are inherently connected towards risk attitude. This is just one example. An risk aware culture that better aligns benefit and sanction instead of perceiving these two as two seperate worlds can be achieved in multiple ways.


Too often I encounter organization with on the one side a focus on performance management, goal setting, monitoring, etc. and this would include the remuneration for good performance. On the other side (in complete isolation) there is the governance; risk and compliance (GRC) function. They are trying to limited the risk exposure and ensure organizational compliance. Operating in isolation from performance management they do not have the "weapon" of remuneration (and bonuses) to stimulate desired behaviour. All GRC is left with is sanctions to stop unwanted risky behaviour. If these sanctions are perceived to stand in the way of achieving the bonus benefits one can clearly recognise the basis for possible future disaster.


Bottom line: There is so much to align, in this case performance and risk management

Tuesday, December 7, 2010

So you think you are compliant

Article originally posted on: Computerworld UK

Remember, risk management does not necessarily mean risk elimination.

Organisational compliance is not a “black and white”, “yes or no” status but a “more or less”, “better or worse” continuous scale. Organisations that are 100% certain of organisational compliance should verify their belief by considering the questions in this article.

First the article title, you might have recognised the reference to a television show called “So you think you can dance?”. I am not a big fan of the show but I love the title. For me it holds both a challenge for the contenders to show “their stuff” combined with a high-level of “who do you think you are to think you are good enough to appear before us?” arrogance. And indeed, as expected, self-appointed experts and has-been celebrities in the jury will cut overconfident no-talent participants down to size.
Too often I have to think about this image when I see (IT) auditors’ fresh out of school present their audit findings passing judgement over the organisational compliance effort. Please do not misunderstand me, there is nothing wrong with the auditing profession as such, but at times we seem to forget that the audit reports describes the auditors’ opinion not the absolute truth.
I have no respect for auditors that think they can pass final (and absolute) judgement on the workings of an organisation based on a two week (or even shorter) audit period. Yes they might be able to find examples of what went wrong in the operations. And a good auditor will be able to form an opinion about the mentality and culture of the organisation in such a time frame.
However a great auditor will be the first to admit that his report is just an opinion. He will discuss his findings with the organisation he investigated and more importantly will have an open mind for arguments that might change his opinion.
Too often the equality between auditor and audited department is gone. It is the same with these talent shows, if the performance is ridiculously bad it might be warranted to put somebody “out of his misery”. However when it comes to judging those that clearly show promise and commitment judges should discuss “opportunities for improvement” instead of passing “final verdict”.
Granted, where the purpose of the audit is to assure compliance with an individual regulation or to issue certification to a standard, the end result will be a pass or fail “bottom-line” statement. My comment is related to the relationship and attitudes during the assurance process to deliver that verdict.

So when assessing the compliance status of your organisation there are a number of questions you should consider. By answering them truthfully you will probably find that 100% certainty of organisational compliance is both impossible and if possible undesirable.
Compliance is a requirement; somebody wants your organisation or department to comply with a set of rules and/ or regulations. For instance the financial administration of an organisation that handles credit card transactions has to comply with the rules set by the credit card companies (PCI-DSS). In turn the administration will have to articulate the security requirements for their relevant IT-services to the IT Department. In the same manner the finance department will react to the Sox regulations (if applicable). The HR and Marketing/ Sales departments might require compliance with Data Privacy regulations. The logistics department may have requirements based on import/ export regulations.
Off course IT itself has to comply with software and hardware license requirements. We have the requirements originating for fire, health and (personal) security. The industry specific regulations for instance Basel II for finance or Hipaa for US Health Care organisations might be an issue. There are local regulations regarding building, parking, signage, etc., etc. Just to name a few.
The list of organisational stakeholders with rules and regulations to comply with is endless. So how sure are you that you know all the compliance requirements you are supposed to meet as an organisation or department? When answering this question it is important to realise: To be 100% certain you know all applicable rules and regulations you would need infinite resources to keep checking with every possible stakeholder.

This is the first compliance risk: Not knowing of the existence of the requirement.

So 100% certainty is both impossible and undesirable since one has or would want to spend infinite resources. The real question then becomes what is your organisational risk posture? How much risk are you willing to accept? And how much are you willing to invest to mitigate the risk of non-compliance due to unawareness?

Most rules and regulations are created with the best intentions. That is, to try and limit the change that an undesirable event or situation occurs. But there are places were rules and regulations are created to support corruption.
The basic idea is that the requirements of these regulations are purposely impossible to meet and the only way not to get punished for non-compliance is to bribe those who create and enforce those rules. I have experienced these situations in the past and basically non-compliance and bribery is an accepted part of doing business in these places. Trying to achieve your goals in a fully compliant manner is a very expensive, inefficient, if not impossible task. Even more so in some cases, where it might put the organisation in an undesirable competitive disadvantage.
These days I see non-bribery policies with more and more (multi-national) organisations some of them active in these kinds of places. In a number of instances I believe the policy is more about “don’t ask don’t tell” than anything else. It is not my intention to advocate bribery but we do live in the real world and an ostrich should not claim 100% certainty of compliance.

Assuming the intentions behind the regulations are good that does not mean the actual requirements are clear. Many laws and regulations are supposed to last over a longer period of time and cover a wide area. It would be impractical to describe the do’s and don’ts for each individual situation and even impossible to predict how the situation will evolve over time. As a result numerous rules and regulations are purposely written with room for interpretation. It is left to the individual judges and juries to fine-tune the rules by creating jurisprudence. But until jurisprudence has been created there is no way to be 100% certain what the exact requirements are.

This is the second risk of compliance, the risk of misinterpretation of the requirements.

It is always good to get assistance of a regulations expert when assessing the requirements of individual regulations. Expert involvement will reduce the risk of misinterpretation. However in a number of cases all an expert can offer is an expert opinion which is not the same as the absolute truth.
Again, risk management offers additional means to manage this risk. The risk avoidance response would suggest you adopt a “worse case” interpretation of the rules and act accordingly. In this case the chances the judge and jury rules the organisation broke the rules is clearly lower than when the organisation “lives close to the edge”. However rules and regulations, by nature, limit the organisational flexibility and agility. They limit the number of possible responses to a given situation. So again, the organisational risk appetite for non-compliance due to misinterpretation is important. In turn this will tell “how close to the edge” the organisation is willing to operate.

Once we know what the applicable rules and subsequent requirements are the daily compliance of the operational organisations is ensured by creating policies, processes, controls and procedures. These tell individual employees how to conduct their tasks and duties so they do not (inadvertently) break the rules. Everybody knows however people can have unexpected behaviour that deviates from the described actions. In this context it is important to realise often such a deviation is for the best of reasons and not always because of ignorance, fault or malice.

So the third risk of compliance is deviation from design/ expected actions resulting in breaking the rules.

By training, testing, coaching, etc. we can mitigate the risk of unexpected/ undesirable actions by man or machine. But again this is a risk: How much uncertainty is the organisation willing to accept? How many resources will the organisation make available to mitigate the risk? With people there is another consideration.
We value the creativity of people, in this context I mean their ability to think of actions and solutions for unexpected situations. But if the situation is unplanned for the reaction as a result of human creativity is clearly unplanned for as well. So the creativity we value so much might easily be at odds with organisational compliance.
The only way to ensure actions resulting from on the spot creativity align with the compliance requirements is to make sure people do not only understand what they should or should not do but also why.
What are the underpinning regulations and requirements? Based on that knowledge those on the spot can than decide on creative solutions that fit within the regulatory requirements. Empowering people with that kind of knowledge means you can enhance the flexibility and agility of your organisation while ensuring a higher certainty of organisational compliance. But again this empowerment can be resource intense so once more the organisation needs to strike a balance between empowerment (lowering the risk of non-compliance) and the cost involved.

What is the consequence of non-compliance?
The moral of this article is that Compliance is a requirement and non-compliance is a risk and should be treated accordingly. In the same way we cannot exclude all risk from the organisation, 100% certainty of organisational compliance is an illusion. Any organisation will have to think about the level of non-compliance risk it is willing to accept.
A popular way to categorise risk is to look at both likelihood and impact. Identifying the sources of uncertainty is the first step to assess likelihood. I have seen strategic statements and policies that claim “the organisation will comply with all applicable regulation” or something to the same effect.
What this statement does not say but what is does imply is “at all cost”. In practise however most organisations will assess the impact of public non-compliance. They will look at possible fines, reputational damage and other possible negative consequences. Even though very few organisations will come out and say it, they will look at the negative consequences of non-compliance before they decide how many resources are committed to ensure compliance (and thus mitigate the risk of non compliance).
At one time I came across a courier that made speed of delivery their unique selling point. They worked for broadcast companies for example. They ensured the fasted possible transfer of physical news footage arriving at the airport to the television studios. Before the digital age, with breaking news, this transfer time was a valuable commodity. So valuable even that the drivers were instructed (never in writing off course) to break traffic regulations in favour of speed and the company would cover the possible fines.
There are very few people that live by the credo that “everything goes as long as you do not get caught”. On the other hand there are very few people that will ensure compliance at all cost. For organisations risk (of non-compliance) is just another risk that they should manage but risk management does not necessarily mean risk elimination.

Thursday, September 23, 2010

The primary trait required for Governance: Wisdom

Reposted, original on the site of Computerworld UK in August 2010

Wisdom, Solomon recognized its value in the bible. Lao-tzu describes its importance in the Te-tao Ching. But let’s face it: That was then. Wisdom is something for old people who can no-longer keep up with the pace of modern day live. It has no place in the everyday business of our fast moving society. Or does it?
Let’s start with Wikipedia: “Wisdom is a deep understanding and realizing of people, things, events or situations, resulting in the ability to choose....boring, boring, more boring.” No not what I was looking for, even I fall asleep on that one. Further down the page that’s it: “A standard philosophical definition says that wisdom consists of making the best use of knowledge.” Yes, that is what I was looking for. Have you ever noticed that in modern day life we got very good at acquiring knowledge? Understanding how to use that knowledge is a completely different ball-game.
People I talk to from my field of expertise who look at my LinkedIn profile tend to be impressed with my extensive knowledge of the different GRSC models. Having said that, everything is relative: Those not impressed with my level of knowledge (because they know even more) are mostly civil enough not to say so when we meet. Or, even worse, they find me such a dilettante that they do not want to speak with me to begin with. But that’s a different subject. I think I can claim a fair level of knowledge about the GRSC field of expertise. So how about the application of that knowledge? Very often I meet colleagues who just want to apply all they know: Let’s implement ITIL, CobiT or any of the models and/ or standards end-to-end. Without any consideration for the special circumstances of the individual organization their credo is: If the knowledge was important enough for me to acquire, it is important to use aka implement.
In other articles I have used the analogy with a builder: A builder has a tool-box containing all the tools he might need to complete the individual tasks. But no self respecting builder will expect to use all his tools for each task. Knowledge of models and frameworks are just the tools for consultants. If the goal of the task is only the implementation of the tool there is no way to measure if the knowledge was used wisely!
So much about wisdom on an individual level now let us look at wisdom on an organizational level. In the definition it says wisdom is about understanding how to apply knowledge (my slightly adjusted personal definition). It is not exclusively about applying your own knowledge. So for a manager wisdom is about understanding how to apply the knowledge of the entity he manages. The primary task of a manager is to manage: Acquire, combine and facilitate the scarce resources in the entity he manages so they meet the objectives of the entity in the most efficient way. To understand these statements consider the following: A manager who always has a lot of technical (content) ideas is a bad manager. To be able to get these ideas one of two things has to be happening: Either the manager spends his time thinking about content were he should be focussed on creating an environment that ensures maximum performance of his resources (people). Or even worse, he does facilitate his people so they come up with great ideas but then he “steals” them and presents them as his own. Everyday live is not this straight forward but still....
The best managers I know will tell their bosses about the great deliverables (and ideas) of their employees, ensuring the employee receives the credit for the idea. A great boss will give the credit for departmental performance and idea generation to the resources (aka people) it contains. The credit for the wisdom to make maximum use of the knowledge goes to the manager. This might even include the manager’s wisdom to use knowledge from outside his department.
We talked about knowledge and for now associated it with content: In this case knowledge of (expert) models but there is also the knowledge of form. We all know the “teckie” who knows everything there is to know about his field of expertise but there is no way to have a conversation with him because after three words you have no idea what he is talking about. On the other hand there is the “fast talking sales-rep”: Hear him speak and you “get” him. It is utterly clear that his solution is the only possible way forward until... You actually try to follow his suggestion and find he really did not have a clue of what he was talking about. Both had knowledge: The “teckie” knowledge of content the “sales rep” knowledge of form.
On this scale each individual has its own place. Some are better in transferring the message, making others understand even if they might not know the content of the message for a fact. Some people know the answer but are less able to convince others. Knowing where you stand and accepting your limitations is the first step. The next step is the decision to enhance on your weak spots or to accept them and seek a partner that will compensate, like the manager deciding to bring in outside knowledge to assist his department in achieving its objectives.
It is human nature to prefer the company of like minded people. However this might not actually be in your own best interest. A content oriented person might not like to cooperate with a form oriented person however it is here that we see most often that the sum is more than the total of its parts (the 1+1=3 rule).
With organizations it is just the same: People seek to work for organizations were the corporate culture fits their personality. A “black-box” IT department left on its own to do the “really smart stuff these guys do, though I have no idea what it is” attracts “teckie's”. That same “teckie” would most likely not feel at home on a fast-passed, yuppie populated, trading floor were a sharp tongue is a basic necessity to survive. The result is that the company or entity culture (and the kind of knowledge that goes with it) tends to re-enforce itself with the risk of creating serious blind-spots that get worse over time. If you look at the causes of the financial crisis this tendency has certainly played its part.
The governance function should keep oversight over the organization, knowing in which knowledge areas the organization is strong but more importantly were it is left wanting. Understanding the culture and how it is most like to develop over time. Including the consequences this developing culture has on the availability of knowledge and the way it is used by the organization. Finding the blind spots and correcting for them is a primary task of the governance function. Directors do not need the content knowledge to create ideas and generate deliverables. They do need the wisdom to understand how to acquire, combine and apply knowledge (balancing both form and content) so the organization can obtain its goals in an efficient manner.

Thursday, August 26, 2010

Aligning information supply and demand

Reposted, original on the “IT Governance, the Kapteyn’s view” blog on Computerworld UK in April 2010

Business - IT alignment, when you read the articles written on the subject it turns out most of the time they focus on alignment between business and IT on a strategic level. But alignment between the two on tactical and operational level is just as important. So how about the Information Supply and demand relationship?

For some reason when we talk about IT we all seem to focus on the T of technology instead of the I of information. But at the end of the day what the IT-domain delivers to the business is information. One of my business customers translated it real nice (though very blunt): “Don’t talk about your technology-gizmo’s those are your (IT department) toys. For me to run my business I need you to deliver the agreed information according to the required specifications”. So Information not technology is of interest to this business executive. When we look at the quote a bit further we see the business (executive) demands information and wants the IT-domain to supply it (according to specifications). So there you go: The Information Supply and Demand relationship.

The first thing to realize is that the demand side of this relationship is not situated in the IT-domain but in the business domain. Here we find the first challenge. In the earlier posting on the Blog called “Business-IT alignment, a bad term (part one)” I already wrote “I have never seen an organizational chart were there was one organizational entity marked ‘business’ as opposed to an entity called ‘IT’.” Basically: THE business does not exist, in most organizations it is a complex set of departments with different information needs from each department. The article concludes the time of the one size fits all IT-approach is over for most organizations. The IT-domain should start looking at its core product (information services) with a marketing approach: What is the market? What are the market segments? Who wants what product (in this case information)? What are the required specifications for the product (think in terms of confidentiality, integrity, availability, etc.)?

If you made it this far reading this article and are still interested I would like you to think a moment about the current status in your organization. Are you confident that the demand side of clearly segmented? The information needs are identified per segment? Are the requirements for each Information type clearly defined? If you can confidently answer with yes, congratulations you are among the happy few! If the answer is no it is important to realize alignment goes both ways: If there is misalignment it might just as well be that the demand side of the Information relationship is chaos. Before a business manager starts complaining that “the IT department does not understand his needs” he might take a moment to see if he himself understands his needs and has clearly articulated them.

If you find the status of your IT-demand organization has room for improvement were should you start to improve the situation? Well the first step would be to identify the information-market segments. As most organizational models and experts will tell you information is one of the core production resources. Operational production is organized (formally or informally) in business processes. So if you want to know your (segmented) information requirements start looking at the business processes. For each of the steps of these processes you should be able to identify what information is needed to efficiently complete the step and what the secondary requirements for that information are (in terms of confidentiality, integrity and availability). When the basic structure for your information demand is clear you could think about building an Information demand organization. This helps to ensure a more structured approach towards information demand both on an operational, tactical and a strategic level. If you want to know how such an organization could be created, have a look at the BiSL model. Available from the ASL BiSL foundation, this is one of the few models that I am aware of focused on the information demand organization. The fact that the BiSL is in the public domain makes it easy to use it as a starting point.

All this on the IT Governance Blog, what is the connection? First of all some definitions (as I use them) to ensure common language, I have learned use of different definitions is the most common source of misunderstanding. The IT Domain is the organizational entity responsible for the Information supply side of the relationship. It includes the internal IT Department and any third-party suppliers involved in the creation of the Information Services. This is basically the complete IT supply chain. Information (demand) management is the management on the demand side of the relationship. As such it is very closely related, if not part of, the business (processes). There is confusion on this topic in real life; I also see definitions were Information Management is accountable for the complete Information supply and demand relationship, not just the demand side. Though this might seem as a slight (semantic) difference it is important for the mandate of the Information Manager: Does he just have authority for the business (supply) side of the relationship or is he also in charge of the IT (supply) domain? I hope you appreciate that makes for a substantial difference. As long as everybody agrees on one or the other in your organization both can work depending on your organizational structure.

I am a member of the ISO JTC1 WG6 Committee which is responsible for the maintenance and the continued development of the ISO 38500 standard on corporate governance of IT. One of the discussions I have with other committee members is about the scope of this standard: What does the standard govern? Though I personally find the statement could be articulated clearer, the consensus in the committee is that the standard concerns itself with the Governance of the Information Supply and Demand Relationship. So both sides supply AND demand, not just the IT Domain but Information (demand) management as well. Since (as we noticed earlier) most of the time information demand management is organized in the business domain this immediately goes to show that IT Governance is not just for the IT domain but business executives should be involved as well. But then again I am not the only one that is trying to get that message across. To reduce the confusion it might be better to start talking about Information Governance (or corporate governance of Information). But then again I guess that would just add to the confusion instead of reducing it, so better not introduce a new term.

This brings me to the next observation, within the C-suite the logical primary contact for issues concerning IT governance is the Chief Information Officer (CIO) this makes him responsible for the complete information supply and demand relationship, not just the IT Domain. So the role of CIO is not equal to the role of head of IT even though both roles are often combined in one function. When you look at the mandate of many CIO’s these days you will find that they are actually head of the IT department, not CIO (according to this definition). But what’s in a name? One last observation, do you ever look at publications (print, internet or otherwise) directed at CIO’s? Have ever noticed how 90% of the content of these publications is basically about Technology and almost none of it is focused on Information? Talk about misalignment, I guess information is just not “sexy” enough!

Hail the almighty business case.

Reposted, original on the “IT Governance, the Kapteyn’s view” blog on Computerworld UK in April 2010

These days if you want to gain access to investment funds you better be able to create a good business case. The marvels of the business case are many. Opportunities are quantified while all (relevant) aspects are captured in a structured manner. This means we can easily compare and prioritize, etc. etc. How did we survive before the invention of the business case? Or are there possible down-sides to this powerful tool?

First of all let me stress that I think the business case is a very potent and powerful tool. The whole concept of project and program portfolio management would be very hard to implement without a tool to ensure you can compare like-for-like. Furthermore the use of business cases ensures that people with “a brilliant idea” sit back and reflect for a moment and are forced to look at their idea from different perspectives (financial, economical, risk, strategic, etc.) before they start wasting other peoples time pushing clearly flawed ideas. But as with most tools in live that which can bring good can also be used for evil. The value of quantification has its limits. To proof a point the following example. If statistics is not your strongest point please bare with me, you will probably be amazed at the conclusions achieved. If you do not believe me when I say that everything in the example is statistically and mathematically sound ask an expert to verify. Of course there is a catch which I promise to explain at the end of the article. Here goes:

In a Casino one of the games is roulette. As part of roulette you can make a bet whether the next number will be red or green. Since there are just as many red numbers as green numbers on the roulette wheel changes are exactly 50% that either red or green comes up. The exclusion is the number zero which is black. However in some casinos, if zero comes up bets on green and red “ride” this means no loss and no gains and the bet stays on the table for the next round of the roulette wheel. As a result, for the purpose of this Business Case there is no influence from having the number zero.

I know of a system to play roulettes which will give you an incredible Return on Investment (we are talking double digit percentages) at a given (known) investment with a negligible risk of loss. Interested? You start playing by betting your base amount (let’s say 5 Euro) on either red or green. If the bet wins you won 5 euro and the cycle ends. You start a new cycle. The change of winning is 50%. If you lose you double your bet in the next round so now you bet 10 euro. If you win in the second round you have won 10 euro but since you lost 5 euro on the first round your net winning is (again) 5 euro. Winning concludes the cycle. You start again with a new cycle by betting 5 euro. The change you lose two times in a row, however, is 0,5 (50%) x 0,5 (50%) = 0,25 (25%). This is a basic mathematical law of change. Still there is a good chance you lose two times in a row, if so again you double your bet for the next round (so this time to 20 euro’s). If you win in the third turn your net gain is 5 euro (20 – 10 – 5 = 5). The changes of losing three times in a row 0,125 (12,5%) = 0,5x0,5x0,5. I hope you get the picture: You keep doubling your bet when you lose until you win at which point you always have a net return of 5 euro. The system only has one risk and that is that you run out of money and cannot double your bet anymore. In that case you will not be able to recover your previous losses and basically you will be bankrupted. But we saw that we can calculate the changes of a series of consecutive losses and that the change is getting smaller and smaller (1 round 50%, 2 consecutive losses 25%, 3x 12,5% etc.). So by ensuring we have enough capital available we can mitigate the risk to an acceptable level. The change (for instance) that you lose 17 times in a row (the residual risk factor) is 0,001% which I will hold is negligible small (especially if you compare it to the risks on the stock market). So if you ensure you have enough investment capital to keep doubling your bet 17 times you can accept the residual risk. We can calculate that your investment capital needs to be euro 655.355. With this capital you will make a return of 5 euro per cycle (ROI: 0,0008% per cycle). Is that all? That is not very impressive. Not yet! If we assume that it takes 2 minutes to play a round on the roulette table (place the bet, roll the ball, collect the losses and pay the winner) we can calculate the average time it takes to play a cycle. Rules of change tell you that on average a winning cycle (the number of times it takes before you win the 5 euro’s and start over) contains 2 rounds. So you will be able to play an average of 15 cycles per hour winning 5 euro each cycle that means you win 75 euro per hour. If we than assume you play 8 hours per day, 200 days per year you will have won 120.005 euro per year. This translates to a yearly return on investment of 18%. So if you have 655.355 euro’s in the bank and find a 0,001% change of loss acceptable start playing, a yearly income of 120.000 euro’s will be yours. How is that for a business case?

If you accept that all figures used are correct the conclusion seems warranted. I wonder if you have spotted the “catch”. In short the moral of this example is something my statistics professor used to say: With the right data set I can proof anything! This is the first risk of using business cases, it may offer false security. By using a lot of numbers the business case looks really sound, only a subject matter expert (in this case I would expect a risk expert of mathematician) will be able to identify the logic flaw.

A second issue is the use of assumptions. My business case contained the assumption that it takes 2 minutes to play a round on the roulette table. If I recalculate based on an adjusted business case of 5 minutes per round one can only play 6 rounds per hour and thus win “only” 48.000 euro’s per year (a yearly ROI of 7%). Though still not bad there is a substantial difference. So some assumptions can have major influence on the final conclusions. Very seldom do I see business cases that clearly identify the assumptions. It is even more rare that an explanation is given of why the assumption is quantified on the value as presented. Finally it is extremely rare that the consequences are calculated should the assumption be wrong. If information is present it should be available in the risk section of the business case since wrong assumptions are basically a risk. I have read business cases that reached quantified conclusions that were quoted in 3 decimals (look at my residual risk factor). Thus suggesting a very high accuracy of calculation. However in one particular case it also contained a completely unfounded assumption that was hard to pick up on. When I adjusted the assumption “downward” by only one percent the business case conclusion changed from a profit at a healthy return on investment into an unrecoverable loss. I cannot but wonder if the writer did not knowingly manipulated his figures to reach the desired conclusion trying to hide the “weak” assumptions. It happens and to me that kind of behavior boarders on fraud: Willingly leading people to make bad decisions by supplying untrustworthy information and presenting the information as “sound” for personal gain. That type of use of business cases is evil.

Which brings me to the third flaw of business cases. Not all benefits and or (business) value is easily quantifiable. I have been known to say that I can quantify anything should you want me to and I will. I will just make ever bigger assumptions. In business the example often used is the value of advertising. What is my return on investment on advertising spending? This is one of the hardest things to quantify but it can be done. I will give you an example of how one could quantify (with imaginary figures): A full page add in a daily newspaper costs 10.000 Euros (imaginary fact) the paper has 10.000 subscribers (imaginary fact) and is read by, on average, 2 people per delivery address (assumption) this would give an exposure to 20.000 people. 5% actively notices/ reads the add (assumption) that would mean 1000 readers. If 1% would be interested in my product (assumption) I would have reached 10 potential clients. I sell, for instance, cars at a 1000 euro profit margin (imaginary fact). That would mean I break even if every potential customer actually bought the product (assumption). As most people would agree the added value of such a quantification is basically zero since it is just a bunch of assumptions stacked on top of one another.

For some things quantification is just not worth the effort. For instance I tell you that you should buy suntan lotion because the sun is hot and you run the risk of sunburn. Would you ask me for a business case to justify the investment against the possible pain and agony of having to walk around with a burned skin? If so my response would be that any quantification is just a stack of assumptions and thus offers phony security. Would you than conclude that you will not consider the suggestion because if it cannot be quantified it cannot be real? When it comes to investing in things like (IT) Governance, Risk, Compliance, Security and Control I encounter that line of thinking almost on a daily bases! It even went as far that these days we are trying to accommodate this drive for quantification by models like Return on Security Investment (ROSI). Using the business case tool to create barriers against valuable investment proposals just because it is hard to quantify the (business) value is using a perfectly good tool for evil!

PS

I promised to tell the catch of my business case. As every risk expert (should) know, to assess risk you should not just look at the probability but also to the impact. In this case: The changes of losing all the investment money because there is no more money to double goes down with larger “pockets” but if the risk does occur the amount of money lost increases just as fast. In the example: If the investment money is only 5 euro the change is 50% of going broke the risk value, change x impact (5 x 50%) = 2,5. With investment money available for 17 rounds this value calculates to 5. When you build a spreadsheet (as I have) showing investment requirements and residual risks for different cycle lengths you will find this value starts at 2,5 and increases towards 5 which it approaches ever closer. I learned from experimenting that the value approaches your starting stake so if you start the cycle with 10 euro it closes towards 10, etc. I could probably explain that if I sat down for it but since it is of no particular importance for this story I will leave that for the mathematicians amongst my readers. To try and explain in a different way: I have a risk of losing euro 655.355 while winning 5 euro per cycle. I would have to play 655.355 / 5 = 131071 cycles to recover the lost investment should the unthinkable happen (18 consecutive losses) since the average number of rounds per cycle is 2 this would mean the roulette table has turned 131071 x 2 = 262142 to win that much money. If you have played that long the change of the unthinkable happening is that much greater. If you wait long enough every risk bigger than zero (no matter how small) will occasionally happen. Unless, off course, you avoid the risk all together (do not play the roulette). I hope this makes sense otherwise just trust me, the system doesn’t work!