Showing posts with label ISO 22301. Show all posts
Showing posts with label ISO 22301. Show all posts

Friday, 31 October 2014

Resource-based contingency planning – an alternative approach to ISO22301 certification

Business continuity is, especially in the Anglo-American world, not that much a new concept. Being not new also means that it probably is due to be redesigned. Since the inception of Business Continuity Management in the late 80s and early 90s of the last century, the world has changed quite a bit. The main concepts, procedures and processes of BCM however have not changed that much in the past 25 or so years. We are still talking PDCA, we are still talking process-based business impact analysis, we are still trying to do the work of risk managers with our task in the fields of operational and reputation risks. We still have the BCM Lifecycle.

Those who are practitioners in the profession may have already realized that the theoretical strategies and tactics as outlined by the BCM Lifecycle approach may not always meet the needs and possibilities of an organization seeking to implement BCM. The business impact analysis for instance needs processes, since it aims to operationalize the damage because of failed process. But, which organization does have a complete and operationalized process document which allows it to just sum up losses and damages along process chains? And, how can the BCM organization define the so-called BCM-Strategies when they haven’t even asked the business what they think they need as workarounds to cover a resource which was lost or damaged because of some crisis situation?

Here we already have the word, what this presentation is about: Resources. What I do call resource-based contingency planning is actually not just contingency planning, but part of a new approach to business continuity, which offers an alternative to the BCM Lifecycle. In the first part of the presentation, I will briefly introduce this system, which covers all parts of what we know is demanded by the BCM Lifecycle, however in a quite different sequence and with partly completely different methods and tools, and which addresses all controls of the ISO22301 standard.

In the few minutes I have for the presentation, I cannot go through the complete methodology what I call resource-based business continuity. I only show a core part of it, one of the 15 deliverables and work objects of a business continuity management system – the business continuity plan, the probably most important one of five different plan types which need to be created for a complete BCMS (the others being the disaster recovery plans, the emergency and rescue plans, the crisis communication plan and the crisis management plan).

The most astonishing part of these BCPs may be the inclusion of a risk assessment as a part of this plan. The risk assessment, being a core element of ISO22301 requirements, is no longer a work package of its own, but an integral part of contingency planning. The reasons for this, and why this makes much more sense than to emulate the work of a risk manager prior to actually planning for catastrophes, will be given in my presentation. The same by the way, is true for the identification of critical suppliers and clients, which also is done in the course of discussing and deciding on a workaround in the case of the loss of a critical resource.

However, in the title of my presentation, you find the most important difference between the BCM Lifecycle approach to business continuity compared to what I am doing. Where the lifecycle’s objective and basis of action and contingency planning is the business process, in my world it is the resource. One does not need the availability of documented and operationalized business processes to implement a BCMS, but only knowledge about what resources an organization has. And, differently from processes, this bit of information is most often readily available, and if not, can be created without much work.

With the presentation, I will provide a view into a core part of an alternative approach to ISO22301 certification, which delivers some novel ideas how to structure a contingency plan, how to identify critical clients and suppliers, and how to identify and assess operational risks. And if you pay attention, you might get an idea, why this approach to implement business continuity allows for applying for certification some six months after start of the project already, and why this approach reduces the cost of BCM between 50% and 80%.

Rainer Hubert will be discussing ISO22301 further on day two of the BCI World Conference and Exhibition on Thursday 6th November. You will find him in seminar room 1 starting at 13.10.

Thursday, 30 October 2014

Becoming certified to ISO22301 - what NOT to do! (Why auditors get grumpy!)

Tip number 1: The lack of a regular supply of good quality biscuits is the first non-conformity!

Looking forward to my presentation at 13:10hrs on November 6th in seminar room 2 of the free exhibition part of this year’s BCI World Conference and Exhibition. I realise that there are many BC practitioners who, although practiced in the creation and maintenance of a Business Continuity Management System (BCMS), have yet to seek certification to a standard. Additionally I recognise that others may have only assisted in achieving certification and even those though certified constantly struggle with a stream of nonconformities found by external auditors and which if left unresolved threaten the organisations certification.

During the past three years I have been working as an externally contracted assessor and ‘Technical Specialist’ with one of the top assessment organisations in the world who, via audit, assess companies for the suitability of their BCMS for certification to initially the BS25999:2006 standard and subsequently its replacement ISO22301:2012. Over this time I have been fortunate to audit the BCMS of around 100 companies by pre-assessments, Stage 1, Stage 2 and Continuous Assessment Visits (CAV’s).

Fellow practitioners sometimes ask me if I get bored with assessing to the same standard day after day. Fortunately this is not a problem as although the same standard no BCMS is alike and understanding the multiple ways of constructing a BCMS compliant with the standard has been fascinating and provides me with continuous opportunities for my own personal development, sometimes by observing good practice but unfortunately all too often from seeing practices which fail to meet the basic requirements.

I should make it clear, and possibly surprising for those who know me, that I am a big supporter of the 22301 standard. Now it is by no means the perfect standard, if indeed that could ever be achieved. However, I am someone who began in this business when training courses, good practice guides and the words “Business Continuity Management System” were things of the future and, to be frank, “making it up as we went along” was the name of the game. As a result it is in my view great to have a common structure around which to create a Business Continuity Management System. Now of course we need to improve it.

So what will I be presenting? Will it be the secret formula which all Business Continuity practitioners seek to create the perfect BCMS? Will it be the best way to smooth the ego of your auditor to the point where they are purring over your perfect creation? Only one way to find out, be there, oh and bring a biscuit or two.

Colin Ive has been a Member of the Business Continuity Institute since 2001 and is a qualified Lead Auditor for ISO9001, ISO22301 & ISO28000. He is a regular presenter at European & USA Business Continuity and Business Resilience Conferences and a contributing author to both the ‘BCI Good Practice Guide for Business Continuity Planning’ and the acclaimed ‘Business Continuity for Dummies’, in addition to numerous articles.

Colin will be discussing ISO22301 further on day two of the BCI World Conference and Exhibition on Thursday 6th November. You will find him in seminar room 2 starting at 13.10.

Friday, 10 October 2014

ISO22301 certification at the UK's Houses of Parliament

"If you don’t know where you are going you’ll probably end up somewhere else!” At the BCI World Conference in November I’ve been asked to run a session on two key stages of the BC Lifecycle; Policy and Programme Management and Embedding BC into the organisation. Can you imagine my excitement?!

Well, having just achieved ISO22301 certification for the Houses of Parliament I see the outer ring of the lifecycle (Policy and programme management) and the inner core (Embedding) as the tyre and axel of the wheel; get this right and you’ll have a smoother journey.

There are many lessons to share and I hope the conference provides an opportunity to do so. Let me give you an example of what I mean. My BC policy originally said that it ‘would be reviewed on a regular basis’. The external auditor from the BSI pointed out that ISO22301 requires that the policy is reviewed at ‘planned intervals’. My policy now says it will be reviewed ‘at least annually’; that is what we always meant but didn’t make clear. Other examples of poor language are found in phrases from Management Board papers saying “Human Resources might want to look into….” What does ‘look into’ mean exactly? It is not about being pedantic, it’s about being clear in your planning so that all interested parties understand what is being asked of them and how this will be assessed.

The policy sets out what you are going to do, the scope of your BC capability and defines roles and responsibilities. The programme will set out how and when you will implement the BC capability. So, the policy will help you know where you are going and the embedding will help you stay on course. My workshop at the conference will describe how these parts of the BC Lifecycle can be achieved.

Martin Fenlon MBCI, Business Resilience Coordinator at the UK's Houses of Parliament, will be discussing this issue within the 'Learn' stream at the BCI World Conference on Wednesday 5th November, starting at 10:30.

Tuesday, 29 October 2013

Crossing boundaries

John Robinson
INONI

Our BCM World Conference presentation is an illustration of how BCM can pleasantly surprise business leaders with the value it brings. Our case study will be about Reed and MacKay, a £200M turnover top-end executive travel firm located in Farringdon close to the heart of London’s legal, media and financial district. This is a multi-faceted, time-pressured and highly successful business and illustrates perfectly the importance of accurate and decisive BIA. The following explains why I believe they found it so valuable, noting that Reed and Mackay subsequently gained accreditation to ISO 22301 at the first attempt.

On the heels of recession, R&M’s 2012 budget for BCM was tight, so this was by necessity Business Impact Analysis (BIA) in a hurry, allowing just six days to complete. Head of GRC Suzanne Elmore and I booked the ‘goldfish bowl’ office for an initial two days’ intensive research, compiling all the information we needed, hauling in knowledgeable others wherever and whenever we couldn’t find the answers ourselves. It was intense, coffee fuelled work, but for the business we were conspicuous by our absence - no long haul activity, no hit-and-miss scheduling of meetings and consequently no interruption. From their standpoint, the BIA was building itself painlessly; from ours it was systematically providing a detailed and accurate view of the business, marketplace and supply chain.

By the end of day two we had a large and colourful layered map and a steady stream of visitors poking their heads round the door just to see what the pictures actually meant. One was the CEO. His initial reaction was ‘what on earth is that?!’ After a brief explanation, he got it… and asked us to deliver a presentation of the map to the extended management team – for a full day. He realised our technique would let him pinpoint the organisation context and that this would allow executives to think outside their areas for both BCM and normal business.

We delivered to a room of around 15 C-level execs and managers, testing and refining the picture using scenarios. Engagement was total and by 4pm everyone understood the effect of disruption, risks and priorities, dependencies, strengths and weaknesses. Our approach reduced the effects of personality and gave individual execs ownership of the outcome. We authored the formal BIA document based on the high grade information we took from the workshop, requiring the bare minimum review before release and allowing us to complete on time.

Finally, on completing the workshop, we were approached and thanked by the Commercial Director who saw the exercise as exemplary PR for the firm and who now uses their accreditation to emphasise R&M’s superior service to clients.

The message to you from me is this: we know that BIA is the foundation for effective BCM, setting out the organisation’s context for managing this important aspect of business risk. It can seem daunting the first time, trying to see a way through that is efficient and cost effective, and which is accurate and capable of being totally embraced by senior management. We achieved exactly that and gained accreditation on the back of it, with total management support. Please attend our presentation if you’d like to know more about how we did it. We’ll be pleased to see you and answer your questions.

John, along with R&M's Suzanne Elmore, will be discussing the issue of crossing boundaries during his Practitioner Presentation at the BCM World Conference. This will be part of the free seminar programme within the exhibition.

Thursday, 24 October 2013

Drivers for the employment of BCI members in large UK companies

Patrick Roberts
Cambridge Risk Solutions

Ever since becoming involved in the profession, nearly ten years ago, I have been constantly intrigued by the attitude of different organisations towards business continuity. Simplistically, I began by assuming that large well known companies, with both assets and reputation to protect would be universally receptive to the idea of BCM, but (painful) experience has taught me that this is not the case. Equally, since starting our own BCM consultancy in the east of England, we have been surprised by the number of very small organisations that have asked us for assistance, organisations that we would never have considered approaching as potential clients. The same surprising pattern is borne out if you look at the firms which are certified to BS 2599, and are now certifying to ISO 22301. It is a curious mixture of large household names and much smaller firms.

My presentation at the BCI World Conference and Exhibition is based on PhD research conducted at Nottingham University Business School, and attempts to understand these differing attitudes towards BCM in a more formal way. The starting point of the study is the observation, based on data provided by the BCI in 2011, that only 70 firms in the FTSE 350 actually employed a member of the BCI at that time. The research then goes on to explore the relationship between various observable characteristics of these large publicly quoted companies and the likelihood of them employing BCI members. A broad range of possible drivers are identified from reviewing previous work on risk management and from specific consideration of the aims and objectives of BCM.

The main finding is that, at least within these large UK companies, the employment of BCI members appears to be primarily driven by the expectations and demands of external stakeholders such as lenders and regulators. I’m not sure how much this insight helps me in targeting our marketing efforts more effectively, but it has certainly helped to make sense of some of the patterns that we have observed over the years and I look forward to sharing more insights with you in November.

Patrick will be discussing this issue further in his Practitioner Presentation at the BCM World Conference and Exhibition. The Practitioner Presentations are part of the seminar programme at the free exhibition.

Monday, 21 October 2013

Establishing ISO 22301 in Europe’s largest construction project

Katie Collison
Steelhenge

Crossrail is the biggest construction project currently in Europe and is one of the largest single infrastructure investments ever undertaken in the UK. It is a rail link that will run 118km from Maidenhead and Heathrow airport to the West of London, through new twin bore 21 km tunnels under central London to Shenfield and Abbey Wood, east of London. Crossrail will increase London’s rail based transport network capacity by 10% and bring an additional 1.5 million people to within 45 minutes of commuting time to London’s key business districts, supporting regeneration across the capital. It represents construction on a staggering scale.

Presently in the tunnel boring phase, Crossrail is managing a multiple worksite programme with construction works running concurrently across the entire route with:

  • Over 10,000 people working on the project
  • Over 35 million working hours completed on the project so far
  • 40 construction sites

For the first train to roll in 2018, the schedule must be adhered to so the next stage of the programme, the stations fit out, can commence on time.

So where does ISO 22301 fit in and why is business continuity important to Crossrail? In part this question is answered by the statistics above. The Crossrail construction programme is being delivered at an astonishing pace with any delays to construction works on one site, big or small, having the potential to impact the time and budgetary constraints of the entire programme. As with any major construction project Crossrail recognises the inevitable risks. Health and safety is taken extremely seriously, and a zero harm target is promoted with an incident response philosophy of ‘prudent overreaction’.

In line with all of the work that has already been achieved by Crossrail in this area, a comprehensive business continuity management system (BCMS) to manage and minimise the impact of disruptions was both an identified gap and an obvious addition to the organisation’s resilience portfolio. The decision to establish a BCMS in line with ISO 22301 was driven by Crossrail’s desire to deliver a world class railway that genuinely improves standards within the construction industry and meets best practice in all areas.

The challenges and route to success

However, the rate at which the project is being delivered and the finite existence of Crossrail Ltd in its current form meant that any business continuity programme needed to be pragmatic, simple to update, and easy to maintain. Something which typically contradicts management system standards, but which is achievable under ISO 22301.

Steve Hails, Crossrail Health and Safety Director, and Katie Collison, Steelhenge Senior Manager; will be discussing this topic and the path to ISO22301 success within the ‘BC in Action’ stream at the BCM World Conference on Thursday 7th November, starting at 13.05.

Friday, 11 October 2013

Building resilience in the provision of critical national infrastructure with ISO 22301

David Clarke
Telefónica UK

At Telefónica UK we are proud to be one of the first UK businesses to achieve the international ISO 22301 accreditation for business continuity management. We’ve always worked hard to ensure that all parts of our business are robust. Our business continuity provisions were accredited under the former British standard BS 25999, so the transition to ISO 22301 was a natural one for us.

Our COO and business continuity champion on the Board, Derek McManus, summed it up nicely when he said: “Achieving ISO 22301 accreditation demonstrates our commitment to providing a reliable, high quality service to our customers. It shows that we have the resources, investment and processes in place to protect ourselves from potential service disruption – minimising the impact on our customers.”

The acid test

Last year, in the run up to the Olympic Games, we got an opportunity that most businesses don’t – the chance to put our business continuity plans to the test.

We undertook a number of activities, and one of the most high profile involved asking 2,500 of our employees to work away from our Slough Head Office for one day. The goal was to try out our technology, our network and the way we work – for real, on a working day.

I’m glad to say that we passed the test. Everyone was able to do their normal work – with no impact on our customers.

The ISO 22301 accreditation and the results of our flexible working day both demonstrate that we really do understand business readiness and continuity, and that our customers can rely on us when the unexpected occurs.

David will be discussing this and the issue of standards within the 'Supply Chain Continuity' stream at the BCM World Conference on Thursday 7th November, starting at 13:05.

Wednesday, 9 October 2013

The return on investment of a BCM programme

Rainer Hübert
HiSolutions AG

When will the investment for a BCM programme pay off? Most people think that the only correct answer is when a damage scenario has taken place. Hopefully then an effective BCM programme will reduce an otherwise much more costly, or even possibly fatal financial impact to a bearable amount. Then, and only then, will the investment in BCM be paid off – just like insurance policy.

In our finance driven business world however, investment in BCM needs to be justified in financial terms, unless a BCM programme is forced upon an organization by its clients or by regulatory authorities.

While the cost of a BCM programme is widely known, many people will have no idea what the returns will be. During my presentation at the BCM World Conference, I will discuss what I believe are four sources of return for those investments that go some way to justifying a BCM programme.

Insurance premiums and interest rates are the most obvious candidates; however they are the least effective ones. One can reduce the business disruption insurance premium by reducing the time coverage of the business disruption pay out. At banks, it is possible to negotiate the interest rates with by providing additional information about a reduced credit default risk due to a working BCM programme.

More potential for a return of investment however stems from the lowering of process costs by improving process efficiency. When discussing contingency procedures and measures, the way the business operates is more closely scrutinised and so the opportunity is provided to generate ideas as to where efficiencies and savings can be made. These ideas may find their way into day to day operations of a company with the potential to improve the effectiveness or efficiency of business processes across the board.

The largest effect however will actually come from the new ISO 22301 standard. This standard will become instrumental to comply with purchase regulations of clients, especially the larger ones. More often than not, contingency planning will become a requirement of critical suppliers. In future, one may lose existing contracts or fail to win new tenders without a certified BCM programme. BCM will be fundamental to winning or sustaining these contracts.

BCM leaders often struggle with justification for investment in a BCM programme in general or individual BCM measures in particular. Especially when discussing with economists or business administrators, those working in the BC industry are regularly confronted with standard business case approaches to justify BCM, which require a detailed explanation of the return on investment. My talk offers a way to meet this demand and outlines in more detail an approach on how to calculate and demonstrate a return on investment of a BCM programme.

Rainer will be discussing this and the issue of measurement within the 'BC in Action' stream at the BCM World Conference on Wednesday 6th November, starting at 13:30.