Search

Showing posts with label Risk Management. Show all posts
Showing posts with label Risk Management. Show all posts

Monday, December 20, 2010

Bonuses and sanctions


In Holland there is a saying: You catch more flies with honey than with vinegar. Indeed if we look at the causes of the financial crisis in a number of cases the drive to achieve the incredible bonuses that are customary in the financial sector seem to have outweighed the sanctions the enterprise risk department might or might not have imposed for excessive risky behaviour.

First of all this shows an underpinning feeling regarding enterprise risk and control: Enterprise risk and control limit the possibilities of "the fast and the furious" to reach for the sky. This feeling that enterprise risk and control only limits the possibilities of the organization to maximize on growth and profit potential is surprisingly common also with people that should know better. Some time ago I had a conversation with an account manager of the management consulting firm I was working for at the time. The customer we were discussing was a supplier of high-tech production tools for the computer industry with a world-wide customer base. The company is a world-wide market leader in its field of business. We were discussing if they might be interested in my particular expertise (IT Governance, Risk, Security and Compliance). I will not soon forget one of the statements my discussion partner made: "This is a fast moving company with a young, entrepreneurial, can-do culture. They have no interest in the control resulting from IT GRSC since it would limit their possibilities to maximise growth and profit." Not his exact words by the way but close enough. Such convictions however are amazing for an account manager of a management consulting firm. What made it worse was that he was also the company director overseeing the consulting business for customers in the production sector. In response I have a question: Why does a formula 1 race car need breaks? Answer: To be able to drive faster. Explanation: No formula one driver in his right mind will drive his car at full speed unless he is convinced he will be able to slow down in time to make the next corner!

These days we look at the causes of the financial crisis and the actions to be taken to ensure it does not happen again. There seems to be consensus that Governance and Risk mechanisms have failed in the financial sector. Regarding the solutions the discussion often turns towards the (according to some excessively) high bonuses customary in the financial sector and the need to limit these. Interesting to notice that the amounts of the employee remunerations are not a primary focus point of any of the Governance and Risk models and regulations I checked (amongst others COSO ERM, OECD Principles of Corporate Governance, Basel II, ISO 38500). The Cadbury report does address the issue but comes with the following statement: "The Committee has received proposals for giving shareholders the opportunity to determine matters such as directors' pay at general meetings, but does not see how these suggestions could be made workable." Do the models and regulations have a blind spot on the issue? One could argue that (IT) Governance and Risk models and regulations do target organizational objectives and since bonuses (in general) are connected to achieving objectives there is a causal connection between the two. However this would not explain why the discussion only focuses on the height of the bonuses. One would expect the discussion to focus on the circumstances under which bonuses are awarded, not primarily the values.


It is understandable how the high financial bonuses are at the core of the public discussion since they speak to the imagination of the public and are sure to create public outrage: "Make so much money for yourself and loose so much money for the rest of the world". To exclusively focus on the amounts keeps it simple and understandable for the general public. For opportunistic politicians and press the opportunity is just too good to pass. Though I do not want to defend the bad apples we should not forget that it was the financial sector that made the economic boom of the last decades possible by creating new financial products that made more investment capital available to a wider audience. It is the COD's that made mortgages more widely available and made home-ownership possible for a bigger percentage of the population. These and other financial instruments that were eventually misused and are partially the cause of the disaster did initially do very good things. As long as the financial sector supported and fuelled the economic boom nobody seemed to care that they made a "good living" for their effort.


There is one reason to discuss the height of the bonuses and this is a basic law of security and control: The higher the possible benefits the bigger the temptation to break the rules to achieve them. As a result a bank is normally better protected against robbery than, let's say, a poor man's home. One response is to try and limit the possible benefits of misbehaviour (lower the bonuses). But it is a fact that the financial whiz kids who earn these incredible bonuses make even more money for their employers and they are in short supply. So unless you want to rethink the fundamental concept of capitalism any solution that might get implemented will go directly against the basic supply-and-demand law of economics (High demand for items in short supply will drive the price up).


There is however another approach. As we noted in the beginning, currently risk management is seen as a limiting factor on maximising growth and profit. The basic attitude seems to be: Don't do it because it is too risky. However an alternative approach would be to make target correction based on inherent risk. We all know this attitude: The better your financial situation and past history the better terms you are offered on new credits (Getting a loan or a new credit card is much more expensive for a person who went bankrupt in the past). In the stock market we expect a better return on investment for venture capital when compared to an investment in a blue-chip fund. As the Greek government learned the hard way in recent days a triple-A rated government bond does not have to offer as much interest as a bond of a less reputable (and thus lower rated) government to attract investors.


Could we use that principle elsewhere? If we look at the Investment portfolio for (IT enabled) organizational investments, for instance, we could look at introducing a risk-rating system for each of the proposed investments. The (financial) goals, for instance the expected return on investment, could be adjusted based on the project risk rating. If we came up with a rating system that factored in the past performance of the key-project personal like project and program managers etc. we could use that as the bases to steer risk-aware behaviour of these people. Risk aware attitudes would translate towards better (financial) goals and targets. Since these targets in general form the bases for the bonuses earned this would mean bonuses are inherently connected towards risk attitude. This is just one example. An risk aware culture that better aligns benefit and sanction instead of perceiving these two as two seperate worlds can be achieved in multiple ways.


Too often I encounter organization with on the one side a focus on performance management, goal setting, monitoring, etc. and this would include the remuneration for good performance. On the other side (in complete isolation) there is the governance; risk and compliance (GRC) function. They are trying to limited the risk exposure and ensure organizational compliance. Operating in isolation from performance management they do not have the "weapon" of remuneration (and bonuses) to stimulate desired behaviour. All GRC is left with is sanctions to stop unwanted risky behaviour. If these sanctions are perceived to stand in the way of achieving the bonus benefits one can clearly recognise the basis for possible future disaster.


Bottom line: There is so much to align, in this case performance and risk management

Thursday, August 26, 2010

What doesn’t make you stronger might kill you

Reposted, original on the “IT Governance, the Kapteyn’s view” blog on Computerworld UK in January 2010

I was reading John Thorps Blog entry “Getting Information Management Right” and read that Gartner predicts that the amount of Enterprise Data will grow by 650 percent in the next 5 years. The article makes a number of excellent points and kept me thinking. But back to the 650 percent, it is not like this is a new development. The amount of data we store (both private and for business) has been growing explosively the last decades.

You do not explain the dangers of overweight to an audience of starving people. Not only is it tasteless but chances are you will find you have a less than captive audience. So the topic of this article is only of interest to those who are not completely starving for information. To stay with the analogy a moment longer, in famine areas of the third world there is virtually no discussions about junk-food since everything is better than starving. It is only when we reach the higher levels of the Maslow’s pyramid that we start to question the quality and necessity of our food and drinks. So the first conclusion: If you, at times, wonder what the added value of all that data/ information is that is so readily available these days you are no longer starving for information. In fact in the “information first world” we run the risk of drowning in all data that is available to us. For these organizations it is no longer about the quantity of data and subsequent information but about the quality.

To establish which world your organization belongs to it is important to recognize a fundamental truth: The primary purpose of enterprise information is to support decision making. No matter how interesting or special you might find a certain bit of information, if it has no (possible) influence on your actions and/ or decisions it is not relevant for your role in the organization. This would basically be junk-information; it might taste good but has no nutritional value. So quality information is not just trustworthy but, just as important, relevant. Good information will support decision-making by bringing down the “guess factor”. The “guess factor” plays part in almost all decisions we make. It is rare that we have all information available at top quality level when we make decisions. We assume that the information we have is correct. We make assumptions about the thinks we just do not know. Since it is the nature of an assumption that it might be false each new assumption increases the risk connected to an individual decision. So now we can assess our informational demand: If we take the importance of the decision under consideration and we look at the risk appetite of the organization we can establish which assumptions we can leave as such and when we want to mitigate by gathering additional information. Since making additional information available will cost resources (money) this gives a nice trade-off: The cost of quality information relevant to the decision versus the level of risk associated to the decision.

Enough theory let’s bring this back to day-to-day impact. We can turn the theory around and assess the actions and decisions made over a certain period of time. If we were to ask a cross section of organizational personnel to look at the last, let’s say, 10 decisions they made. Did they feel they had the necessary information to make good quality decisions? Was the level of risk due to assumptions in line with the importance of the decision? Did they feel confident in the outcome they reached? If not, why not? Was there too little information? Was there too much with the result that the important stuff got buried? Was the quality of information trustworthy? These and other questions will give you insight in the status of your information management from the demand side. We can go one step further and ask those interviewed if they knew where to get the required information. Was it easy to find and access? Could they find somebody responsible for the information? Could they find help to get questions answered? Would they know what to do when their information requirements changed over time? These and other questions will give you insight in the supply side of your Information Management. Doing this on different levels of your organization for decisions of various levels of importance will give you a good overview of the challenges you face. The connection with actual decisions will also tell you if the cost of all this information is in line with the risk reduction achieved. In this context it is good to remember that continued bad-decision making of lower impact decisions at lower levels of the organization might “kill” the organization just as much as one “bad call” on board room level. On the other hand you would not be the first to learn that the cost of acquiring, storing and supplying all this information is completely over the top compared to the nature of the risk it mitigates. Often a “best guess” will do the job just fine.

Risk, risk and more risk

Reposted, original on the “IT Governance, the Kapteyn’s view” blog on Computerworld UK in December 2009

When I look at the world today it seems everything is about risk these days. Data breaches left and right (your private data is continually at risk). Systemic risk and failed risk management is what caused the financial crisis. Earth quacks, tidal waves, forest fires, global warming, HIV, Mexican flue are threatening humanity. The current state of the economy is threatening the IT budgets and as a result my job as an IT Consultant is at risk. There is a risk of a new wave of regulations in response to the world-wide need for governments to bail-out private enterprise. As a result the lack of IT risk and compliance expertise is a risk. Or am I just paranoid?

First of all there is a saying that goes “the fact that I am paranoid does not mean that I am not being followed”. Secondly if you do a more objective assessment of the situation it does seem that the term risk is used more than before. Google always offers a good opportunity for fast research so here goes: the term risk gave me 52.000.000 hits compared to governance which gave “only” 10.400.000 and compliance 22.200.000 hits. On the other hand, to give some perspective, security gave 102.000.000 hits and sex 98.100.000. So what does that proof other than that security is more interesting than sex and the fact that you can statically proof anything with the right data set? Actually, very little. But it is not about hard fact but about perception. I attended the ISACA Information Security and Risk Management conferences (both the North American edition in Las Vegas and the European conference in Amsterdam) and the general feeling I got from the presentations is that these days it is customary to translate our issues into risks. Lack of expertise and tools in an organization is a risk for information security, lack of compliance is a risk for the license to operate. On the other hand compliance with the regulations has the risk of organizational complacency “if we comply with the rules we must have covered all risks”. If you believe that you might want to look outside on Christmas evening, maybe you will see Santa Claus fly by in his sled.

A second indicator: I am always scanning the job and assignments market and given my expertise I use search terms like Governance, Risk, Security, and Compliance. I have clearly noticed that in the last half year we are looking for IT Risk experts more than before compared to the other terms. So my conclusion: the age of governance and compliance is over, welcome in the era of Risk!

Those who have read my articles before will have probably guessed my real conclusion: Risk, the buzz-word for 2010 happy New Year! So besides the fact that all GRC consultants, managers, experts, etc. will have to re-write their CV’s to give their Risk expertise a more prominent place is this a bad thing? Contrary to popular believe IT managers and corporate purchasers are not complete idiots so they will soon recognize the IT suppliers that try to sell last year’s products under the new “hype” label. My prediction for 2010: A number of the products that were “must haves” to achieve governance and compliance nirvana in the last decade will become absolutely vital if you wish to achieve risk management bliss. The problem is that as a result organizations might totally disregard “risk” since it is just hype. As usual, however, this hype is based on real challenges that require adequate attention. Failed risk management was one of the causes for the financial crisis and the subsequent economic down-turn so we might better do some of that “continues improvement stuff” and analyze what went wrong and see how we can improve it. On the positive side the risk-hype could create a common language to compare our issues: If we translate all our issues (business and IT alike) into the risks they may pose for the organization it will become much easier for top management to compare and prioritize them. But then again, I spend every Christmas evening outside hoping to finally get a glimpse of Santa Claus.

G R C, where did the S go?

Reposted, original on the “IT Governance, the Kapteyn’s view” blog on Computerworld UK in April 2009

The Blog post “To GRC or not to GRC, that is the question” looked at the integrated function of IT governance, risk and compliance (GRC) and why it is logical to combine these functions. The article ended with a question: “Why not integrate even more functions?” To answer that question we now look at integrating the ‘s’ of IT security.

IT security is often regarded as the dusty IT department living in the IT-dungeons. Concerned with the latest virus information and hack-attack news, it investigates how to adjust the firewall settings to minimize exposure to any such new threats. Basically, highly technical expertise, disconnected from the real world spending time thinking of things that users ‘should not do’ or things that ‘cannot be done’ because of security risks. And really how risky can it be if everybody does it? As always Dilbert has a brilliant character that portrays how many people see the security function and those associated with it. The character is called Mordac, the preventer of information services, which sums it up really nicely. As the saying goes, ‘there’s no smoke without fire’ so IT Security is probably (partially) to blame for this image problem.

Though this might be how the function is perceived there are forces at work to change this image and positioning. This new IT security function can be defined as ‘the function responsible for discussing the information risks with the information owner and designing, implementing and assuring the risk responses for the IT domain’. This definition suggests it is about informational risk management. It is about alignment with a stakeholder (the information owner) who resides in the business in most organizations. It positions the function not in the ‘IT dungeons’ but as an expert partner to the business information owner with knowledge and advice on how to safeguard the all important corporate information assets. This makes it part of the business IT alignment challenge we hear so much about. With new positioning and goal for the function it immediately becomes clear that integration with the IT GRC function should be considered. Instead of talking about the IT GRC function we might think about creating a GRSC function. There is one problem, we love our acronyms to have three letters; GRSC has four! Not to worry, we can apply a trick: Just rename IT Security as IT Operational Risk Management - this nicely distinguishes the new (existing) function from the dusty old image anyway. Now you can capture it under the ‘r’ from risk. A TLA again, problem solved. It works but in practice people tend to forget that security is supposed to be an integral part of such a GRC function. Furthermore, the security people feel unappreciated. So personally I would advocate giving security its rightful place under the sun and recognizing that in most organizations IT security was around before the GRC hype started. At the end of the day all these dust gathering activities will need to find their place in this new function (what IT security used to do wasn’t all that bad). Credit where credit is due: GRSC, Governance Risk, Security and Compliance.

I can almost hear it: “Why not leave well enough alone?” Let the security nerds play in there dungeons and I will create a nice new hype function called GRC. That sounds much better when I discuss the state of the world with my fellow management friends on the golf course or over a glass of Chardonnay. And indeed, you are right it is easier to explain. But be warned, you are heading for trouble and here is why. An important part of the work of the IT GRC function is to design, implement and assure control over the IT domain. To this purpose the function discusses the requirements of different stakeholder groups (IT-management, legal, financial etc.), combines the outcome and translates them in a set of controls for the IT domain. These (IT general) controls should be understandable and achievable for the different operational IT departments. Guess what, this is exactly what IT security (new style) will do. In some organizations a basic truth is forgotten: the security function should not invent security controls by itself, instead the security controls should be the appropriate response to the IT security risk as identified together with the information owner. Too often you will find a disconnection between IT security and the business owner of the information. IT security single-handedly decides what the security controls are for the IT functions. In these cases IT security might easily be perceived as ‘uninformed of the business requirements‘ and ’unwilling to work towards business requirements‘. If this is the case you should think about transforming your function into the new style anyway. When doing so you might as well integrate the IT GRC function in one go. When looking at the day to day tasks and activities of both functions there is much overlap. Integrating the functions offers the opportunity for efficiency improvement.

The next example shows the problems you might encounter if you keep two separate functions. It describes a real situation for an unnamed organization. The organization is subject to the Sox regulation and a couple of years ago it had to proof compliance for the first time. Organized by the finance department this resulted in a worldwide (business driven) program to achieve SOX compliancy. Since SOX has direct requirements for the IT domain the program also included a stream focused on this domain. Those involved with this stream noted that in the IT domain there already was another worldwide program to implement a new IT security standard (transforming the IT security function towards the new position as described above). Combining those two (control oriented) programs was considered but since both programs were on a very tight time schedule it was decided to leave them separate. From a project perspective this made sense and indeed both achieved their project goals. This is when the trouble started. Although for different regulations, both programs aimed for sustained compliance of the IT domain. So both functions independently created a run-and-maintain organization with the assignment to ensure continued compliance with their respective control framework. As a result IT operations had to comply with two different IT-control frameworks, each asking for different ways to prove compliance and both using audits as a means to double check. In practice this resulted in some (high-profile) IT shops being audited up to five times per year. For those on the work floor it was very clear that each auditor often asked the same questions. The time, effort and resources spent on assurance were considered unsustainable. So a new project was started to integrate the IT GRC and IT security function. However the IT organization, tired of anything to do with control, resisted the changes from the integration effort. Even though they were intended to improve efficiency and reduce the impact of the control requirements on the day-to-day operation. So what went wrong and how could it have been avoided? By the time programs were started (especially the SOX program) they were so urgent that any effort to integrate them would have caused unacceptable delay. Besides developing and implementing the SOX control framework, a new run and maintain organization was also created instead of transforming the already available (IT security) operational organization. The latter was considered too costly and time consuming to fit the SOX timetable. Furthermore the IT security function was already being transformed as part of the IT security program which complicated the issue. This newly envisioned run-and-maintain organization should have been in place before either program started. Basically the programs should have been in charge of describing what control objectives should be met - and by which section of the IT domain. The IT GRSC function should have designed the (integrated) IT control response in answer to those requirements. Given the nature of the IT security function at the time it was not considered capable of performing that role.

Looking at the current economic situation, it is foreseeable that a new wave of regulation is on the horizon (see the article “Weathering the financial crisis, other challenges for IT Governance are glooming on the horizon”). Though we do not know what the actual regulatory requirements might be it would be prudent to start building the (integrated) GRSC function. This way, once the requirements are known, the GRSC function has a clear view of the controls already in place and has the agility to react fast and appropriately to make the necessary adjustments. Last minute reactions under time pressure tend to be very costly. A timely investment in a fit-for-purpose IT GRSC function can start by looking at opportunities for efficiency improvement with current IT controls (thus creating an immediate return on investment) and will most likely pay for itself with the savings on compliance programs for future regulations. As Sun Tzu wrote in his classic on strategy (The Art of War): “Thus, though we have heard of stupid haste in war, cleverness has never been seen associated with long delays.”