Showing posts with label risk management. Show all posts
Showing posts with label risk management. Show all posts

Tuesday, 28 October 2014

A case study of the integration of ERM and BCM as an independent function

At the 2014 BCI World Conference and Exhibition, participants will have an opportunity to listen to a real case study of the integration of Enterprise Risk Management (ERM) and Business Continuity Management (BCM) as an independent function. This is an innovative and forefront role for the ERM and BCM function.

In my presentation, I will show how the traditional reporting structure and work functions of ERM and BCM in an organisation are usually separated from each other. The ERM and BCM functions are typically part of the executive management team and the head of ERM and BCM reports to the executives such as the CEO or the CFO.

I will share with you the real life case in Malaysia where the ERM and BCM functions are integrated as a 'single' function and act as an 'independent' unit - assuming the roles and responsibilities similar to those of the Internal Audit - separated from the Management. The integrated ERM and BCM independent function reports functionally to the Board of Directors via the Board Audit Committee and administratively to the CEO.

The integrated ERM and BCM function will serve as the foundation for a well-governed and well-managed organisation that is built on a solid resilient foundation of BCM and supported by three pillars of Corporate Governance - Governance, Risk and Compliance.

In order to ensure the effectiveness of an integrated ERM and BCM independent function in an organisation, the following pre-requisite criteria must be established:
  1. An integrated ERM and BCM Charter clearly stating the independent, authority, position, roles and responsibilities of the ERM and BCM functions
  2. Unbiased support from the Board of Directors and the CEO on the independent roles and responsibilities of the integrated ERM and BCM function. The Board of Directors via Board Audit Committee is responsible for the oversight of the work of the integrated ERM and BCM function and for the performance and oversight of the Head of Integrated ERM and BCM function, and ensures that it has a sufficient amount, and quality of resources to fulfil its roles
  3. The appointment of the Head of integrated ERM and BCM function must be approved by the Board of Directors. The Chair of the Board Audit Committee is consulted before the appointment of the Head of integrated ERM and BCM function or the termination of his/her employment and conducts entry and exit interviews with the same
  4. The Head of integrated ERM and BCM function and the supporting subordinates should possess strong knowledge in the disciplines on both ERM and BCM
  5. The Management shall know its role as risk owners and BCM process owners, and these must be clearly communicated and supported by the Management
I will also share with you the benefits of an integrated ERM and BCM independent function and some of the limitations that you may face if you implement the said function in your organisation.

In conclusion, I will share the key takeaways on the lessons learnt from the Malaysian experience that can be adapted to your organisation since there is no 'one-size-fits all' integrated ERM and BCM function. The ultimate goal of the integration is to have a synergy between the two functions as an independent function that will contribute towards a well-governed and well-managed organisation.

Chong Chen Voon is currently the Managing Director of GRC Consulting Services and an Executive Director of EJF Group, a group of consulting firms providing Consulting, Advisory and Training services.

Chong will be discussing 'the integration of ERM and BCM as an independent function' on day one of the BCI World Conference on Wednesday 5th November. You will find him in seminar room 3 starting at 13:10.

Wednesday, 22 October 2014

Genoa: The city where maths kills people

On October 9th, 2014 - with HI CARE Association and PANTA RAY - the BCI Italian Forum was launched, the first Business Continuity Institute affiliated network in Italy for business continuity professionals. In a conference held in Milan, I had the chance to point out how the culture on this topic in our country is still very low and how it is important to pursue a radical change in mentality and in the approach to crisis management.

There was no need for the umpteenth flood in Genoa to confirm how urgent the need for change is. But unfortunately just a few nights before our forum, the Bisagno river overcame its embankments killing one person (in 2011 the victims were 6). The city woke up with a widely spread black-out, Enel declared that over 2,000 clients had no power, schools and universities were closed, several blocks were flooded and economic and infrastructural damages were significant (circa €200 million of public expenses and approximately €100 million of private damages to companies and shops).

A scene we are used to, not only in Genoa unfortunately. But there is a good piece of news, we finally found the guilty party: maths! The President of the Liguria Region Burlando declared: “It is the first time that mathematical models are wrong.” He must have missed all the financial slumps in the history of the world. “The phenomenon that was registered yesterday has never happened before and our weather forecasting models could not anticipate it. The model is still valid though, until now it has always predicted the weather so that we never made mistakes related to severe crises”. Good to know.

I think we can list thousands of reasons that led to the umpteenth tragedy: bureaucracy, soil consumption (which in Italy is twice the European average), the lack of resources, the typical Italian mentality that is nothing but focused on prevention and planning, etc. All valid considerations that highlight the need for careful reflections. But, maths?

I really do not want to concentrate the attacks on President Burlando, but I do have to highlight these statements because they reveal a problem that I have to face quite often as a business continuity and crisis management consultant, either with public entities and private companies. Here is the deal: Business continuity is often confused with risk management, a discipline that – by definition – is based on probability calculation and therefore on mathematical models. This is a problem, since business continuity is meant to ensure resilience to an organization regardless of the probability of occurrence of a potential disruption. Business continuity is applied on the so-called 'residual risk', or the part of risk which is not manageable or computable. Outcome: when mathematical models fail and no business continuity practices are embedded in the organization, disasters happen!

Risk management (and math, of course) is a fundamental discipline, as weather forecasting is fundamental as well. But thinking that they never fail is crazy and not doing anything but rely just on math models is criminal. It has to be said pretty clear, because people die and companies fail. The Ferraris Stadium in Genoa is right next to the Bisagno river. What if the 'math models' fail again on a football match day, when the area is full with thousands of supporters?

Earlier this year, we held a conference at the Chamber of Deputy with Joseph Bruno - Commissioner of the New York City Office of Emergency Management as the guest speaker. We discussed these topics and we presented the crisis management model of the City of New York to politicians and the highest members of institutional entities. Now we have launched this BCI Italian Forum, which is completely free and aims at aggregating the most important competencies on the subject to create a network in Italy as well. I want to stress a concept I already mentioned during my speech at the conference in Milan: there are no excuses anymore! Each of us needs to accept his/her own responsibilities and act to raise the awareness on prevention and preparedness in this country. Otherwise, to find the guilty party you just need to look in the mirror.

Alberto Mattia is Managing Director at Panta Ray, a management consulting company specialized in business continuity and crisis management and Secretary-General at HI CARE Association, a non-profit organization dealing with territorial security projects in Italy. Graduated in Economics and Finance at the Università Bocconi in Milan - Italy, Alberto has started his career in the US at BT Radianz and then JPMorgan Chase Bank. He has then worked as a Project Manager at Centrobanca and as a Risk Manager at UniCredit Group.

Monday, 20 October 2014

Business continuity vs risk management

According to ISO22301, business continuity is defined as the capability of an organisation to continue the delivery of its products or services at acceptable predefined levels following a disruptive incident.

Risk management on the other hand is the systematic process of understanding, evaluating and addressing the risks that an organisation faces in order to mitigate against them.

So that all sounds quite clear. The former is more concerned with the management of a disruptive incident after the event and so deals with the consequences, while the latter focusses on the management prior to any incident taking place and so deals with the threats. Two very distinct disciplines, aren’t they?

If you go back to the basics however, risk management assesses the likelihood of an incident occurring and the impact that it would have on the organisation. If one of the aims of risk management is to mitigate against the impact of an incident, then isn’t this moving into business continuity territory? Doesn't this mean that business continuity is just a function of risk management?

This is the issue that is up for discussion on day two of the BCI World Conference and Exhibition on the 6th November. Panel members from a wide variety of organisations on both sides of the debate will clash as they discuss the motion ‘business continuity can only ever be subservient to risk management’. Don’t miss out on this opportunity, book your place at the conference and join the debate.

Thursday, 13 February 2014

A vision of the future

I’m relatively new to business continuity management, with only a little over ten years’ experience in this industry that is said to be made up of the 'Men in Grey' - bearded and grey suited men. Someone said this to me at last year’s BCI World Conference, I then looked in the mirror and sure enough that was me already.

So in my short time what changes have I seen, what incenses me and what gives me hope that as an Institute we are making progress?

Like many when they start out in this industry, I was volunteered as opposed to being a volunteer. It was in the days of PAS56 (Publicly Available Specification 56), the forerunner to BS25999 and now ultimately ISO22301.

My experience was that the business in Eastern Europe that I worked for needed to comply with various standards and regulations and business continuity management was beginning to be the latest fashionable topic.

Returning to the parent company in England, I was suddenly considered an expert because I had actually read the existing standard - "Dave can write us a plan" I was told. Oh dear! No ten pillars of business continuity (PAS56); no BCM Lifecycle (BS25999); just "write us a plan." This was post 2000 and the millennium bug scare which had achieved a lot in some respects, but also suggested that BCM was exaggerated to create a cottage industry.

So have we truly progressed? The point in time when business continuity management moved forward for me, I can now see clearly was driven by the right Top Management influencers driving it. Even then however, the dark side of 'minimum compliance' versus 'budget availability' was always present.

I’m proud to say I now tutor the topic for the BCI via one of its top training providers and in doing so I meet people from many business sectors from Directors to BC Coordinators, and yes, some of those who have been volunteered.

I still see in some of the biggest and multi-facetted global organizations a culture centred on compliance; equally I see huge amounts of dedication, expertise and frustration from people hugely committed to business continuity management.

So what incenses me?

The fact that we still use dramatic events to explain the concept of business continuity. As impacting as they are, and perhaps getting more frequent, I'm incensed that we still think this is how to promote this topic.

The fact that we are often still at loggerheads with the risk industry and that we struggle to embrace each other’s discipline to a common objective.

The fact that we as an Institute analyze supply chain continuity each year and come up with very similar data, yet we still do not have the means to change those findings through a common understanding of the issues.

Finally, the fact that whenever you attend forums, presentations are largely centred around statistics that depict the frequency of events and a series of pictures showing how bad things can get, invariably with no evidence of what we can do to make things practically better.

So, what is the solution and what are you doing about it I hear you say. My view is simple, but the solution may be a little more complex.

Organizations in this day and age have to be commercially driven, be they charities, public sector or private sector, small medium or global; they have to be commercially efficient. Top Management are driven by success often evidenced by financial targets.

The most common phrase I hear when discussing business continuity management and disruptive events is “what’s the chances of that happening?” the classic response borne out of risk appetite and risk attitude. Why spend budget on an unlikely event?

Top Management speak of 'risk' - they can comprehend this because it’s built in to us all from birth. Planning is counter intuitive, reacting is natural.

Something we all must do, and I try to, is promote the concept of business continuity as a value adding, commercially driven, essential part of a successful organization. This includes understanding your Top management’s appetite and attitude to risk, their maximum attitude to disruption (over time).

When it comes to procurement and managing supply chain continuity, Top Management need to understand the 'Risk/resilience Assessed Total Cost of Ownership'.

As an Institute, as BC professionals, we need to place business continuity at the top table by giving Top Management reasons to adopt it based on commercial efficiency, not compliance.

This cultural shift that the BCI Good Practice Guidelines tell us is so hard to measure will happen if we present commercial evidence as to why Top Management need business continuity management.
My part in this transition is to constantly discuss business continuity management in terms of a commercial imperative and offer solutions and concepts, not statistics and photographs.

David Window is the Managing Consultant of Continuity 22301 Ltd in Cheshire, UK.