Search

Showing posts with label IT Sourcing. Show all posts
Showing posts with label IT Sourcing. Show all posts

Thursday, August 26, 2010

Sourcing strategy – end-to-end or aligned

Reposted, original on the “IT Governance, the Kapteyn’s view” blog on Computerworld UK in October 2009

Some time ago I came across a question from Réal Rousseau on the itSMF Discussion Forum. After we discussed his initial question for a while we came down to the following underpinning issue: When you look at the IT Supply chain most services offered to the business are built by combining products and services from different organizations. For instance, a message service will combine at least a workstation service, a network service, a mail server service, WAN service, internet access service and maybe services like PDA/ Smartphone or mobile computing. These days no organization that I know will build, run and maintain all parts of this end-user service in-house (I do not think it would even by possible if you wanted to). So not only do different departments within the organization need to work together to create this business service, but there also has to be operational alignment with third parties. The question Réal and I were discussing is: In this complex, multi-organizational spaghetti would the ultimate goal be to create an end-end process model or just align the individual links. With one overarching (end-to-end) process model the designs of the internal operations of each link is adjusted to fit the tasks, activities and goals described by these end-to-end processes. The alternative would be to allow each organization in the chain to have their own internal operational process model and just ensure the operational alignment in the cooperation between these organizations. For alignment you ensure the output from each individual link matches the input requirements from the next link in the chain. In this case the way the output is created is not a topic of interest. The individual links are seen as just as many black-boxes. I have seen this discussion in different forms within different organizations.

But before we get further into this question, what does this have to do with (IT) sourcing strategies as the title suggests? You may have got the feeling from the opening paragraph that this article would turn into a highly technical discussion of different IT operating models and forms of process-cooperation, but that is not the point of the article.

An essential part of strategic thinking is to understand the consequences your choices of today will have for your options in the future. As I learned from the discussions with Réal and others there are pros and cons for creating one process model for the complete chain were each link just conforms and finds its place in the bigger picture. This is the same for the alternative where each link organizes its own (internal) processes – in this case, special attention should be paid to the alignment of the contact points between the individual links. If you are interested in discussing further, let me know and we can get a conversation started.

For most professionals, however, this discussion is completely academic. To be able to establish an end-to-end process framework for the complete supply chain you need to have one dominant link in the chain that can act as the “director” of the end-to-end model. If you look at the production supply chain from Dell or Wal-Mart, say, it is clear who is in the driving seat for the end-to-end chain. On the other hand, many organizations have a sourcing strategy that dictates that suppliers of equal size or stature are preferred. Since this will help to ensure adequate share of mind from the supplier (the supplier should not be much bigger) and stability (the supplier should not be much smaller) this is often a sound strategy. However if all links in the chain are of equal size it might be hard if not impossible to find the dominant link that can act as the director for an end-to-end process/operational model. For most of us the supplier portfolio is a given that you do not change in the short term.

So that’s the answer: Look at your current supplier portfolio. If you can identify a potential dominant link in the chain you might consider building an end-to-end operating framework, directed by this link. If you cannot find a clearly dominant link, each link should decide for itself how to organize its operation and each interaction point should be aligned by the parties involved with the individual contact. That sounds nice and responsive and is probably the only viable solution for most organizations. However, for organizations who want to be “master of their own destiny” and thus have decided that their (sourcing) strategy is important to be able to actively plot and navigate the course of the organization: Your IT Sourcing Strategy – more consequences than meets the eye!

Compliance for outsourcers

Reposted, original on the “IT Governance, the Kapteyn’s view” blog on Computerworld UK in September 2009 

This evening I attended a round table session organized by the Dutch chapter of ISACA. Antal, the presenter, did his best to show how compliance can influence the outsourcing relationship. At the end of the presentation Job, the host, concluded that this was a complex subject and that more time could, and should, be spent explaining all possible consequences. Antal, Job: sorry but I disagree with that conclusion.

Compliance is a requirement and non-compliance is a risk. In a demand-supply relationship (a.k.a. customer-supplier relationship). As the demand partner, the customer is accountable for identifying both his requirements and his risk acceptance levels. In case of compliance the customer should identify:

  1. Which rules and/ or regulations apply to the service agreement
  2. How he wishes to be assured about the compliance with the individual rules
  3. What is his risk acceptance level of non-compliance

There are many rules and regulations in this world SOx, Hipaa, PCI, Information Security (compliance with internal rules and regulations is just as much compliance as compliance with external rules), Data Privacy, etc. Compliance requirements form part of the integral requirements set that the customer hands to the service provider; this accountability cannot be transferred. In the same way, the method of assuring and reporting the compliance status forms part of the compliance requirements. Working with an outsourcing partner does not make a difference on these points. And then there is the third point: acceptance of the non-compliance risk. In theory, if we had unlimited resources we would be able to completely mitigate risk so there is no residual risk. In practice, the best (and probably only) way to achieve this is to stop all activity of the organization (i.e. go out of business). So it starts with your cultural attitude towards risk. I was working for a financial institution during the SOx glory days and their attitude towards compliance could be described as follows: “We are a financial institution. The trust of our customers, based on our reputation, keeps us in business. SOx compliance failure is not an option.” And believe me they put their money where their mouth was; I was very impressed with that effort. Another company, also on the SOX compliancy ticket: “Our reputation with the financial world has been tarnished because of mistakes we made in the past. We will use SOx to show and prove that we have learned from our mistakes and (if possible) wipe the slate clean.” And again: “SOx compliance failure is not an option, we do not even want it to be a close call”. They also backed that statement with the necessary resources. On the other hand, there is the story of another financial institution. That story is written in a Dutch Book called “De Prooi”(The Perfect Prey). It is about the Dutch ABN Amro bank, a global bank that struggled and was finally sold in parts. From a governance perspective this is an absolute “must read” in my opinion. Amongst others because it describes how mistakes in governance, risk and compliance management were amongst the root causes of the failure of what was a great institution.

In this book it is described how the Bank had a “cavalier” attitude towards compliance and after repeated warnings they were punished by the US financial authorities. The point I am trying to make is not that you should do everything to comply, but to think: What is the risk, what is the cost of non- compliance? In money, reputation, etc. But this is nothing new; these are the questions you can also read in “Risk Management for dummies”. However, you are not supposed to think it, let alone say it, but at times it might be worth taking the penalty for non-compliance since the cost of achieving compliance is ridiculous compared to the penalty. I have never heard it stated but I have seen situations where the organization was clearly non-compliant (and that fact was known to those who should take action) yet it was decided that no action would be taken. When the cost of compliance is internal to the organization (even if it is another department) most people understand this trade-off and will act accordingly. But somehow when a third party is responsible for remaining in-compliance the customer often forgets: Compliance costs money! Since third-party outsourcers are not in business just for the fun of it, they will transfer the cost of compliance to their customers. If they don’t it is even worse, they are likely to go out of business. So from the perspective of the demand side: be clear in what you want regarding compliance for your service, why you want it and do not go overboard, every extra costs money!

Now to the supply side. As with any good outsourcing deal the customer should clearly specify what he wants, not how the supplier is supposed to provide it! If I walk into a car dealer, do I get to tell the dealer how to run his business? Can I order the manufacturer to build his assembly plant in a certain manor? Not exactly, I can tell him for example that the car should meet the European Union road-safety regulations as I want it delivered in Europe and I want to drive it there. When I walk into an US car dealer, that might pose a problem for him. Chances are I am the first customer ever to ask him that question, so if he decides to take my order he will have to investigate what the rules are and figure out how to change the car (and the service that goes with it). If he has to go through all that trouble just for me, it will be very expensive. This is where a smart outsourcer can make a difference: If you have a lot of customers all wanting cars for the European Union, you might set-up a special assembly line just to comply with those rules. Once you have done that, you walk over to the European authorities and get a seal of approval for the complete assembly line. As a result you do not need to prove compliance for each individual car produced. The tool to achieve this for an outsourcer is called the SAS 70. The external auditor of the outsourcer supplies a statement that the outsourcer has implemented sufficient control to meet named control objectives. If the control objectives the regulator wants the customer to meet are amongst those on the named list of the SAS 70, he may use that statement as proof of compliance towards his external regulator. A SAS 70 expert might have issues with my layman’s explanation of a SAS 70, but in broad lines that’s how it works. So if you are considering outsourcing your Compliance sensitive services, look for a partner that already has knowledge and experience with the regulations you need to comply with; you might be able to achieve considerable economies of scale and thus cost savings.

Business-IT alignment, a bad term (part two)

Reposted, original on the “IT Governance, the Kapteyn’s view” blog on Computerworld UK in September 2009

In part one I discussed the first reason why I do not like the term ’business-IT alignment’. The term suggests that business is one homogenous entity with clear and consistent requirements for the IT domain, which in my experience it is not. The second reason I dislike the term is that it suggests an “us against them” mentality between business and IT that is common and (even worse) found acceptable in many organizations.

Too often I read articles or hear conversations where it is suggested that IT should have an extraordinary position within an organization. In my opinion IT is just another member of the corporate family. In any family the members are unique in their specifications, issues and relations with other family members. However when a family member is no longer considered part of the family structure but tarnished with the ’special position other than the other family members‘ brush you know you have a problem.

To me that is what business – IT alignment suggests. We have all these departments who cooperate together as ‘the business’ and then there is IT; the unloved, unwanted, misunderstood corporate member, not part of the business ‘in crowd’. If this sounds familiar and the accepted situation in your organization then consider the following.

For those in the IT domain: when the business is given the choice of IT service supplier the most important advantage the internal department has over an external third party provider is its intimate knowledge of the corporate business. If the IT domain places itself outside the corporate family this differentiator is diminished. If this is the (accepted) situation, then consider outsourcing the IT department. In which case IT can at least offer the corporation economies of scale by joining another IT focused family were it does feel at home.

For those outside the IT domain, it can be compared to living as a family. Since you live so close together, you get to know all the issues, problems and specialties of the other family members. You also learn about aspects and habits you do not like. Small irritations that get blown up over time because of the intimate relationship are often the cause of these fights. So you might decide to break up the relationship in favor of a new one at arm’s length; like getting a third party provider for your IT services. But do you honestly believe that since your partner is now so far away you do not see ‘the wrinkles and flaws’ they do not exist? As the Counting Crows (or Joni Mitchell for the older generation) say: “you don't know what you got 'til it's gone”.

So what is the message of this article? First of all stop fighting and blaming, accept that perfection does not exist. Secondly start on the path of continuous improvement to try and achieve a harmonious relationship between the different corporate family members. This way the business – IT alignment is an intermediate goal at best and corporate integration of IT is the ultimate target.

The IT Supply Chain

Reposted, original on the “IT Governance, the Kapteyn’s view” blog on Computerworld UK in July 2009

One of my favorite books is The World is Flat from Thomas L. Friedman. In this book he describes a number of technological developments and how they lead to globalization. Though you might disagree with some of his conclusions, the (technological) developments are undeniable and so is the general trend towards globalization. What the effect of the current financial/ economical crisis will be on this trend is uncertain, but if we steer clear of the threat of protectionism this trend will probably continue. One of the driving forces for globalization he describes is ‘supply-chaining’. According to Wikipedia, “A supply chain is the system of organizations, people, technology, activities, information and resources involved in moving a product or service from supplier to customer.” This brings me to the topic of this article: the IT Supply Chain.

One economic rule says that a specialized economy where entities use their resources to produce goods and services that they can produce efficiently, and then trade the surplus for items they need but that others can produce more efficiently, will have a larger overall production than an economy where each entity produces everything it requires by itself. This is the underpinning argument for globalization advocates; global trade will benefit the entire world in the long run. This law however also applies on a much smaller scale: for each required product or service, an organization needs to decide to “make or buy”. Often buying will be more efficient but will have a number of negative side effects (including risks) that the organization needs to be aware of and manage. For example the product/ service offered by an external party might not fit the organizational specifications 100%. Furthermore there is always the risk of a supplier defaulting on his promises. All this should be reflected in the corporate sourcing strategy which sets the rules and guidelines for the “make or buy” decision process and for deciding on who should be an external supplier or partner. In turn the corporate sourcing strategy should be “operationalized” for the IT function in the IT sourcing strategy. For the clarification of this term please read the article “Operationalizing” strategic goals in this blog. Examples of guidance from the IT Sourcing Strategy might be: IT technology systems, services and/ or knowledge that are part of the Corporate Unique Selling Points shall be developed, run and maintained in house. We want to work with a limited number of (preferred) IT suppliers. We always want to work with the best of breed technology that matches our requirements; who supplies that technology is a secondary concern. As these examples already show, some of these strategic statements might be mutually exclusive, so it is important that an individual organization really looks at its culture and requirements when developing its sourcing strategy. This also means that an (IT) sourcing strategy is as unique as the organization it was developed for.

If we have a good overview of the IT services required by the business and how they can be broken down into their sub-services (IT systems, infrastructure, components, etc.), we can apply the sourcing strategy to each of the components and describe the overall IT supply chain for the complete set of IT services offered to the business. Not only does this help decide on the internal structure of the IT function, but more broadly, it shows the complete IT environment including the external suppliers and partners, their importance, risks, etc. Once we have an overview, we can start managing it to improve efficiency, effectiveness, performance. We can look at the IT-related risks, not just for the internal function but for the entire environment, and manage it. Basically we can apply all knowledge and experience available on the topic of supply chain management to the IT environment of the organization.

One of the most important rules of supply-chain management is to ensure a common language, with well defined terminology, to be used by all parties in the supply chain so to minimize the risk of misunderstanding. This drives the development of open standards for a wide range of topics, ranging from technical specification for the smallest components to standard government approaches towards import duties etc. In the same way, open standards for IT organizational models would help to improve the efficiency and effectiveness of the IT supply chain. If we have a common understanding of the basic definition, goal, purpose of the incident management process, say, it will be that much simpler to transfer the operational maintenance of IT systems to an external partner (outsourcing), should this be in line with the sourcing strategy. It will make the IT supply chain more flexible and agile to change should circumstances require it. This is one of the reasons why I advocate the closer alignment (if not integration) of the leading IT Organizational Models (ITIL, CobiT, ISO 20000/ 27000/ 38500, etc.). Having said this, I subscribe to the view that “on implementation a model should be adjusted to the need of the individual organization not the other way around”. As a result, each individual implementation of any of the industry standards might differ from one organization to the next. So as usual a careful balance has to be struck between customization versus standardization, also when designing and implementing IT organizational structures according to industry standards and best practices. Both the internal organizational situation and culture and the external IT environment relevant to the organization should be considered. A well established and managed supply-chain is so much more than the sum of its parts, as Dell and Walmart show.