Showing posts with label supply chain. Show all posts
Showing posts with label supply chain. Show all posts

Thursday, 13 February 2014

A vision of the future

I’m relatively new to business continuity management, with only a little over ten years’ experience in this industry that is said to be made up of the 'Men in Grey' - bearded and grey suited men. Someone said this to me at last year’s BCI World Conference, I then looked in the mirror and sure enough that was me already.

So in my short time what changes have I seen, what incenses me and what gives me hope that as an Institute we are making progress?

Like many when they start out in this industry, I was volunteered as opposed to being a volunteer. It was in the days of PAS56 (Publicly Available Specification 56), the forerunner to BS25999 and now ultimately ISO22301.

My experience was that the business in Eastern Europe that I worked for needed to comply with various standards and regulations and business continuity management was beginning to be the latest fashionable topic.

Returning to the parent company in England, I was suddenly considered an expert because I had actually read the existing standard - "Dave can write us a plan" I was told. Oh dear! No ten pillars of business continuity (PAS56); no BCM Lifecycle (BS25999); just "write us a plan." This was post 2000 and the millennium bug scare which had achieved a lot in some respects, but also suggested that BCM was exaggerated to create a cottage industry.

So have we truly progressed? The point in time when business continuity management moved forward for me, I can now see clearly was driven by the right Top Management influencers driving it. Even then however, the dark side of 'minimum compliance' versus 'budget availability' was always present.

I’m proud to say I now tutor the topic for the BCI via one of its top training providers and in doing so I meet people from many business sectors from Directors to BC Coordinators, and yes, some of those who have been volunteered.

I still see in some of the biggest and multi-facetted global organizations a culture centred on compliance; equally I see huge amounts of dedication, expertise and frustration from people hugely committed to business continuity management.

So what incenses me?

The fact that we still use dramatic events to explain the concept of business continuity. As impacting as they are, and perhaps getting more frequent, I'm incensed that we still think this is how to promote this topic.

The fact that we are often still at loggerheads with the risk industry and that we struggle to embrace each other’s discipline to a common objective.

The fact that we as an Institute analyze supply chain continuity each year and come up with very similar data, yet we still do not have the means to change those findings through a common understanding of the issues.

Finally, the fact that whenever you attend forums, presentations are largely centred around statistics that depict the frequency of events and a series of pictures showing how bad things can get, invariably with no evidence of what we can do to make things practically better.

So, what is the solution and what are you doing about it I hear you say. My view is simple, but the solution may be a little more complex.

Organizations in this day and age have to be commercially driven, be they charities, public sector or private sector, small medium or global; they have to be commercially efficient. Top Management are driven by success often evidenced by financial targets.

The most common phrase I hear when discussing business continuity management and disruptive events is “what’s the chances of that happening?” the classic response borne out of risk appetite and risk attitude. Why spend budget on an unlikely event?

Top Management speak of 'risk' - they can comprehend this because it’s built in to us all from birth. Planning is counter intuitive, reacting is natural.

Something we all must do, and I try to, is promote the concept of business continuity as a value adding, commercially driven, essential part of a successful organization. This includes understanding your Top management’s appetite and attitude to risk, their maximum attitude to disruption (over time).

When it comes to procurement and managing supply chain continuity, Top Management need to understand the 'Risk/resilience Assessed Total Cost of Ownership'.

As an Institute, as BC professionals, we need to place business continuity at the top table by giving Top Management reasons to adopt it based on commercial efficiency, not compliance.

This cultural shift that the BCI Good Practice Guidelines tell us is so hard to measure will happen if we present commercial evidence as to why Top Management need business continuity management.
My part in this transition is to constantly discuss business continuity management in terms of a commercial imperative and offer solutions and concepts, not statistics and photographs.

David Window is the Managing Consultant of Continuity 22301 Ltd in Cheshire, UK.

Monday, 4 November 2013

How can we evaluate business continuity risks in the supply chain?

James Stevenson
Rolls-Royce plc

The experts keep telling us that supply chain risks are important and it is old news that:

  • An interruption could damage the business
  • Customers should work with their suppliers to reduce the risk of interruption
  • Sometimes the problem is with supplier’s supplier, or their suppliers
  • Unfortunately, supply chain risks seem to be increasing in scale and complexity

Occasionally, this kind of alarm call reaches the Board or Executive Management responsible for understanding the significant risks facing their business. They realise that the threat is real and ask around to see who is managing this area of risk.

In my view, BC Managers are well placed to do this and with some minor adjustments to the BCM programme we can help the business to understand and manage supply chain business continuity risks.

At the BCM Global Conference, I will introduce the work underway at Rolls-Royce plc that is helping us to:

  • Assess the BCM process site by site
  • Evaluate the major SC risks at owned facilities
  • Evaluate the major SC risks presented by external suppliers

I hope that this will provide BC Managers with practical steps and simple suggestions to evaluate supply chain business continuity risks more effectively.

James will be discussing this and the issue of supply chain continuity within the 'BC in Action' stream at the BCM World Conference on Thursday 67h November, starting at 10:35.

Wednesday, 23 October 2013

Supply chain resilience

Lyndon Bird
Business Continuity Institute

In 2009 The Business Continuity Institute decided that more research was needed into the level of business disruption being caused by supply chain problems. The challenge we set ourselves was to provide data to help organizations develop and enhance resiliency within their supply chains. This work was done with the strong support of Zurich Insurance Services and in collaboration with the Chartered Institute of Purchasing and Supply.

Since then, this has become a regular annual survey and its findings have become increasingly influential to the business continuity, purchasing and supply and insurance communities. At BCM World 2013, the findings from the most recent survey will be announced and I will be leading a discussion on these alongside Nick Wildgoose of Zurich Insurance Services.

This is the first release of data from 2013 survey and those attending the session will be given a printed copy of the full report. Although the methodology used in 2013 was consistent with previous years, some additional questions were added.

One issue looked at in 2013 in some detail was the extent to which non-physical events in the supply chain were causing disruption. These are seen as those events where supply itself is unaffected in the short term but could cause potential long term damage to reputation or even business viability. Another new question in 2013 looked to understand the extent to which supply chain failures were generating negative and positive social media discussions.

The presentation will look at the key findings that emerged from the report relating to supply chain vulnerability and what organizations are doing about it. The causes of disruption are identified, together with their relative frequency of occurrence and the actual consequences. Strategic, financial and reputational exposures are considered, as well as the more typical short term operational disruptions resulting in reduced productivity. Comparisons with previous years will be discussed and these show that some interesting trends are starting to emerge.

The discussion will then look at the lessons for business continuity practitioners; the way organizations try to keep track of their key suppliers’ business continuity capabilities; what works well and what still needs changing. We perhaps need to look at the need for senior management to understand and participate more fully in the supply chain selection and monitoring process.

The takeaway from this session will be the recommendations that can be used immediately to start identifying supply chain weaknesses and strengthen supply chain resiliency.

Lyndon, along with Nick Wildgoose of Zurich Insurance Services, will be discussing the issue of supply chain resilience within the 'Thought Leadership' stream at the BCM World Conference on Wednesday 6th November, starting at 15:20.

Monday, 22 April 2013

Debate Unlimited – A glimpse into the Executive Forum

With this year’s Executive Forum running on 12th and 13th June in Brussels, it seems a good


Lee Glendon CBCI
Head of Research & Advocacy
time to look back at the two earlier Forums.  What does happen when 600+ years of BC experience converges on Brussels each year for two days?

 
As a recap, the purpose of the Forum is to generate informed debate among experienced BC professionals wrestling with ideas about the strategic direction of business continuity, while keeping a firm eye on what is achievable within a real organisation.
 
Perhaps, the two most memorable ideas that emerged from the 2011 Forum, was that ‘business continuity is not about compliance, it is about embedding resilience through silent running’ and secondly that a key benefit of BC was to identify and prevent ‘sideways bleeding’.   
The debate on compliance started with an academic view that BCM was about compliance:  BCM had become a discussion, which assumed that you can stop things happening if only people followed the rules; BCM lacked emotional intelligence and was seen as a tax on people’s jobs in some organisations; and standards weren’t helping either as they were based on bad organisations and stifled creativity.  With the gauntlet firmly thrown down, an electrifying discussion ensued which ultimately led to the conclusion that BC should actually free-up minds, as it actually assumes that things do go wrong!  While it was acknowledged that ‘tick-box’ might be the starting point for BC, it is not the final destination. There is a need to develop a roadmap and engage and sustain the interest of top management to realise the full potential that BC can bring.
As part of the debate on compliance, there had been extensive discussion around whether BC should look for value add, let alone articulate the next step of what the value would be.  Some asserted that BC was not about helping the financials and in the short term it was a cost, and others argued that adding value is not the same as stopping failures from bringing down the business.  Some questioned whether raising the ability of the organisation to respond to incidents before a major disruption occurred was adding value or capability.   In a sign of conversations to come, one delegate felt that the value add of BC was to be found in facilitating the mission of the organisation and its contribution to the sustainability of the organisation.
The ‘sideways bleeding’ idea came out of a workshop discussion where one participant articulated that external strategy consultants had been retained by their top management to bring about significant cost reductions.  The consultants advocated a vertical approach to securing the costs savings in IT.  The BC team could see the consequences of this initiative as the savings secured in one area of the organisation were effectively nullified by increasing costs and productivity losses in other areas.  This generated a healthy debate about the service that BC professionals should be offering their organisation – while the operational level BC service may be well established in many firms, what would a strategic level service look like?
The 2012 Forum picked up the challenge of defining the strategic level service and identified its key components from developing a centre of excellence in contingency and continuity to engaging top management through crisis response and focusing on the risks that concern them through exercising and scenario analysis.  Value measurement became a hot topic of debate with a very blunt statement from one delegate that reporting to executives that you were doing the job they pay you to do was not ‘adding value’ and BC professionals should take advantage of reporting structures to articulate the value that BC could bring beyond what was expected i.e. compliance to regulations.   Two areas dominated subsequent discussions:  supply chain resilience and horizon scanning.
The academic re-framing of supply chain complexity in terms of layers and networks rather than supply chains was brought to life over the two days with examples ranging from overlooking single points of failure beyond tier one suppliers to unforeseen cascading risks at the logistics level.   One organisation highlighted how its ability to maintain its supply chain during the Arab Spring - through preparedness and enhanced security - secured increased market share.    Supply chain risk was confirmed by all as one risk that can raise the profile and relevancy of BC.  But where should you start?   The advice was to use your analytical skills and look for single points of failure and examine outsource deals; from here you can offer to run an exercise and see what you learn – you may well highlight unknown vulnerabilities and win the mandate to bring in BC.
Horizon Scanning was seen as both a technique to change the conversation with executives from general loss scenarios to a more engaging discussion of specific threats and their strategic consequences.  It was seen as an essential source of developing a situational picture to improve not just the response to events but anticipation of events as well.  The ‘BC radar’ was introduced as an accessible model to set requirements for capability development and ensure readiness in the right areas.
Finally, in 2012 the Open Forum sessions were brought into the programme.  Here delegates proposed and prioritised seven topics of their own choosing to take advantage of the collective experience and expertise of fellow delegates.  Topics included the establishment and composition of ‘resilience councils’, the synergies between BCM and Security disciplines, and Eurozone contingency planning.  For those who take a look at the 2013 programme they will see that some of these topics are going to be developed further this year.
The Executive Forum is a rather unique event:  it seeks to bring together best practice from within the profession while drawing on inspiration from outside.  Participants leave refreshed and invigorated, ready to march towards the sound of gunfire!
Notes:
The Reports from the 2011 and 2012 Forums will be available to purchase from the BCI Shop in May 2013.
To find out more about this year’s Forum please visit the BCI website: http://www.thebci.org/index.php?option=com_content&view=article&id=379&Itemid=293
 
 

Monday, 1 April 2013

Meeting the Supply Chain Complexity Challenge - Part Two

 
Lee Glendon CBCI
Head of Research and Advocacy
Having identified some of the drivers of complexity in supply chains in the first part of the roundtable report, how are organisations dealing with the challenge?
 
In dealing with the challenge of multiple tiers in the supply chain, there was common agreement on the need to gain better visibility but divergence of approach in practice.  Some organisations were looking at better methods to manage tier two supplier relationships, while others recommended that the best approach was to work with tier one suppliers and get them to work with their suppliers in turn.  In the case of one large retail organisation, they worked through their supply chains to the source applying a consistent code of expectation in terms of product quality and integrity throughout.  It was recognised that this was a very resource intensive process. However, it was an embedded practice, so for them it was not a case of having to justify the investment each time; an enviable position in the eyes of most of the roundtable participants.
 
The discussion moved on to the challenge of managing 10’s of thousands of suppliers and there was consensus on the need to focus efforts on key suppliers and key supply chains.  It was recommended that filters are applied to provide focus – these filters should be based around criticality in the sense of ‘would failure of this supply chain quickly stop my organisation from being able to carry out its key activities, and how quickly could they be replaced’ and secondly around risks or threats that might cause disruption, such as the supplier’s financial profile, the health of the industry in which they operate, their locations and consequent exposure to risks as diverse as flooding, earthquakes and geo-political instability.   These filters help generate a ‘shorter-list’ to scrutinise.  Another approach favoured by many at the roundtable was to use procurement ‘category management’ to breakdown suppliers into common supply groups and then perform risk profiling on this basis.
 
For those suppliers identified as key to the organisation, the favoured approach was to seek to build closer relationships at executive and operational levels with the objective of improving communication and co-operation and thereby reduce the number of ‘surprises’.  For one organisation, this took the form of running workshops on business continuity and running joint exercises.  Toolkits were provided free of charge and their business continuity plans were shared to help get alignment.  They would also recommend that supplier staff joined institutes such as the BCI to develop capability and drive programme improvement.  Interestingly, one of the unintended consequences of this deepening of the relationship, is the difficulty of exiting such relationship, as it would mean investing a considerable amount of time bringing on board a new supplier to get to the same level of understanding.
 
Some organisations were concerned about being overly onerous on their supply network, especially those operating in sectors where there are a limited number of suppliers.  One person noted that they had experienced suppliers not wanting to do business because the compliance requirements did not make it worthwhile.  In such cases, purchasing organisations are co-operating to reduce the burden on their suppliers through articulating common requirements.  
 
Following a good discussion on approaches to deal with the consequences of increasing supply chain complexity, the ‘wish list’ of participants included the need to gain a better understanding of ‘what supports the supply chain’ and mapping out supply chain networks.  Others were looking for a more dynamic set of indicators that would flag signs of difficulty and an impending risk event in the supply chain.  Another felt that there was a need to consider ‘profit impact’ rather than spend in identifying key supply chains.  While one delegate felt there was a need for procurement to drive risk conversations with suppliers and ensure due diligence had happened.  In this last respect CIPS is planning to develop a number of educational and training resources to support development of its members to meet the challenge.
 
The final thought from the discussion should go to the ‘what’s the return on investment’ question when it comes to investing in supply chain resilience.   For one major organisation top management evaluates the value of investment in resilience in terms of how well it prevented a problem and how well the organisation come out of it.   Quite simple really. 

Monday, 25 March 2013

What’s driving supply chain complexity? Part One

Lee Glendon CBCI
Head of Research and Advocacy
In the BCI’s report Horizon Scan 2013, one of the key trends of concern identified by Business Continuity professionals was “increasing supply chain complexity”.  So on Tuesday 19th March, the BCI and the Chartered Institute of Purchasing & Supply (CIPS) convened a roundtable of senior supply chain, risk and business continuity practitioners from sectors as diverse as retail, manufacturing, energy, housing, construction and telecommunications to share experiences and discuss how they were dealing with the challenge.
 
If folk were hoping that complexity is something that will stop or slowly unwind, then they would not have got much comfort from the discussion.  
 

BCAW Roundtable Discussion 2013
Perhaps, the most important driver of complexity is the customer and the desire of businesses to develop the right supply chain to meet the needs of the customer.  For example, the supply chain required to be able to sell a product as “made in Italy” sets its own restrictions and risks that need to be managed.  
 
Many of the drivers of complexity have come about through conscious business decisions.  A number of organisations had decided to consolidate their tier one suppliers – while this simplifies the number of interfaces at tier one, what is has done has created many more tiers below the immediate supplier, reducing visibility.  Participants noted that they were now experiencing disruption originating at tiers five and even six!  
 
Another issue raised by a number of people was around the illusion of diversity that dual-sourcing can bring.  While many had introduced dual-sourcing in terms of immediate suppliers, some had found to their cost that at tier two or three they were reliant on a single supplier again.  This point opened up a wider discussion about how difficult it was to understand interdependencies between suppliers and that the term supply chain should perhaps be replaced by ‘supply chain networks’.
 
Some sectors were suffering from lack of communication around changes in their extended supply chain.  More than one participant commented that their suppliers would change the location of production or the people providing a service without informing them, so organisations would be caught out in finding that an event, for example industrial action, in one country affected them, even though they didn’t think they had any exposure to the event.
 
Representatives from the public sector provided an interesting contrast to their colleagues in the private sector.  Their driver of complexity was government policy which was requiring not supplier consolidation but increasing their spend with small and medium sized businesses, while this was sometimes managed through a large tier one supplier, there was a need to monitor the success of this policy and provide extensive training and development support for small businesses to work with government entities.
 
The consequences of redrawing the boundaries of organisations over many years through outsourcing were also flagged as creating challenges in that the suppliers often had more knowledge and expertise than the client. Some felt that too much intellectual power had been outsourced and one organisation stated that they were now bringing back in-house some of the higher skilled activities.
 
In concluding this part of the roundtable discussion, it’s much clearer why complexity is such a taxing trend for Business Continuity professionals and why it is so important to find an approach to manage it effectively. 
 
In Part 2 of this roundtable report, we’ll look at some of the techniques that are being used to manage complexity.