Showing posts with label Performance Management. Show all posts
Showing posts with label Performance Management. Show all posts

28 February 2026

Operational Risk: The Pursuit of Trusted Information...

Operational Risk is about Performance Management and Business Resilience. A few months ago the topic of "Compete or Die" was discussed here. Why revisit this topic?

CEO's and the Board of Directors realize the road to eliminating fear in their organization and the marketplace is through trusted information.

Being agile, ready and capable of a quick recovery is what competitiveness is all about, on the field, on stage or around the table in the Board Room.

Working towards control and protection while "Fear" builds in the back of your mind makes you stiff, depletes your energy and creates doubt. And when you are operating a business or standing on the tee of your first sudden death hole on any PGA weekend, you better have resilience.
The business equivalent to Homeland Security and Critical Infrastructure Protection is Operational Risk Management—a domain that many executives see as the most important emerging area of risk for their firms. Increasingly, failure to plan for Operational Resilience can have “bet the firm” results. 
There are numerous examples of how errors, omissions and glitches have brought down the reputations of many a Fortune 500 companies. What do they all have in common that led to their demise? A lack of economic and business resilience to remain competitive in the marketplace.

The threat of Tort Liability and the loss of reputation is top of mind these days with every major global company executive. The threat is real and increasing at a faster rate than many other real operational risks to the enterprise. Litigation from regulators, class actions and competitors has given the term Legal Risk new emphasis and meaning.

Once corporate management understands the need for a "resilience" mentality in place of a "protection" mental state, a new perspective is found. Investing in the vitality, agility and competitive capabilities of the organization sounds and is more positive.

It alleviates the fear of doom and gloom and inspires new found innovation. The future of your organizations longevity and in it's adaptability can be achieved with a new perspective. Compete or die.

Performance Management could be enabled or suppressed by the amount of power you give your leadership. Do they have the ability to make a $1M decision or $10K decisions when it comes to investing budgeted capital into their business unit growth?

Do they manage risk on a level where they are the most informed and the most knowledgeable about the business, or is the "Mother Ship" back at the home office dictating the way they spend or the way they invest?

The ability to know how to manage risk at the point of creating new information is the nexus of several disciplines and requires substantial training. Every minute that goes by with people not behaving correctly puts the enterprise at greater risk to lost performance opportunities.

All these issues can be summed up in a single concept: trusted information. Simply accessing data is no longer enough. Today's CEOs, CFOs and knowledge-workers must be able to reliably track the information they use for decisions back to the original source systems in order to ensure its timeliness, accuracy and credibility.

Over the last few decades, organizations have invested Billions of dollars in systems to collect, store and distribute information more effectively. Despite this, information users at all levels of the organization are often uncomfortable with the quality, reliability and transparency of the information they receive.

Today's organizations rarely have a "single view of the truth." Executives waste time in meetings debating whose figures are correct, rather than what to do about the company's issues.

Additionally, they worry about the AI consequences of making strategic decisions using the wrong information, directly impacting the long-term survival of the organization.

The search for trusted information is a continuous pursuit for commanders in the "Mission Ready Room" and the "Corporate Board Room".

So how do you achieve the level of assurance that's required to make the "bet the farm" risk management decisions in your enterprise?

07 February 2026

SMART Objectives: The Catalyst for Resilience...

Operational Risk Management (ORM) is evolving into a discipline with an over arching set of objectives. The organizations and entities that do not understand the purpose and the reason behind having SMART objectives, might need a refresher:
  • Simple
  • Measurable
  • Achievable
  • Realistic
  • Task-oriented
Without "SMART" objectives, any project will continue to strive for a purpose and a relevant set of outcomes. Constituents, stakeholders and various affected employees that intersect with an internal risk mitigation exercise, will continuously require coaching on how to base the project on "SMART" objectives.

Next, the stakeholders will require a path forward that includes a building block approach to gaining consensus, agreement and a set of written events that will either be simulated or real.

These events comprise a master scenario, that the organization will utilize to test a hypothesis or set of operational capabilities. The high reaching outcome, is to determine where there are gaps, vulnerabilities and opportunities to improve.

The building blocks approach may include:
  1. Seminars
  2. Workshops
  3. Table Top Exercises
  4. Games
These provide the stakeholders with the opportunity to converge on their respective areas of expertise and integrate them with the overall scenario being developed. However, these are still based upon first identifying the "SMART Objectives" and the application to your particular business, organization, city, state or country.

Taking the foundation of Operational Risk Management and applying a process for evaluation, requires a set of standards so all of the respective constituents, will be talking and practicing from the same exercise play book.

In the United States this standard is HSEEP or "Homeland Security Exercise and Evaluation Program":
The Homeland Security Exercise and Evaluation Program (HSEEP) is a capabilities and performance-based exercise program that provides a standardized methodology and terminology for exercise design, development, conduct, evaluation, and improvement planning.

The Homeland Security Exercise and Evaluation Program (HSEEP) constitutes a national standard for all exercises. Through exercises, the National Exercise Program supports organizations to achieve objective assessments of their capabilities so that strengths and areas for improvement are identified, corrected, and shared as appropriate prior to a real incident.
Whether your organization is new to doing functional or full-scale exercises doesn't matter. Having a process oriented model for program management and project management will provide you with the tools and the foundation to achieve new found learning on where and how to improve your enterprise resilience.

Operational Risk Management professionals are working with an organization or population that is constantly striving to be more resilient.

Without testing, without exercising and without the process framework in place to try and achieve measurable objectives, the organization will never gain the vital insight on where and how it can improve rapidly.

It will never fully understand where the enemy will try and exploit the weaknesses. The organization will never realize their resilience factor at this point in time.

When was the last time your organization really tested itself, to survive? How long has it been since you re-established the relationships and the trusted connections with your own supply chain? Why has it been that long?

There are some elite organizations in the world who understand readiness, that have learned along the way of their evolution why exercising and a trusted supply chain is critical to their own survival before the next incident occurs:
To become a SEAL in the Naval Special Warfare/Naval Special Operations (NSW/NSO) community, you must first go through what is widely considered to be the most physically and mentally demanding military training in existence. Then comes the tough part: the job of essentially taking on any situation or foe that the world has to offer.
Direct action warfare. Special reconnaissance. Counterterrorism. Foreign internal defense. When there’s nowhere else to turn, Navy SEALs are in their element. Achieving the impossible by way of conditioned response, sheer willpower and absolute dedication to their training, their missions and their fellow spec ops team members.
This analogy to the Navy SEALs demonstrates that preparedness long before you are asked to test your own resilience, will save lives. Yet there are so many other ways that our planet and the people on it, are being tested every day outside of the context of counterterrorism or national defense missions.

When you think about resilience in the context and relevance of the threats before us, we all have to realize that whether it is the National Level Exercise (NLE), or our US Navy SEALs, only SMART objectives will increase our ability to learn, to save lives and allow for the potential survivability of our organizations or impacted populations.

26 July 2025

QFD: The End of Compliance...

Corporations will continue to be responsible for the criminal behavior and actions of their employees, 3rd party suppliers and other contractors for at least the near term.


In any case that has the defense legal eagles and "Usual Suspects" arguing against the corporate liability issue, the intent is getting cloudy or is it crystal clear?


Even if your Corporate Compliance Programs are in full force and the financial integrity unit is robust in it's efforts, the "Operational Risk" still exists for litigation.


Regardless of the amount of awareness building, education and corporate window dressing, you can't ultimately control human behavior. 


More compliance enforcement and regulatory pressure may seem to be the answer. A voluntary effort to shore up security, soundness and the opportunity for malfeasance in the work place may not be working effectively.


And still the liabilities exist from the plaintiffs and government adversaries to gain compensation. So what is the answer?


The answer lies in the "Enterprise Architecture" of our institutions and the failure to implement the process of "Quality Function Deployment" (QFD). This has been ignored by senior executives and US business because many judge it to be too complex.


One only has to look at the state of our automobile manufacturers versus the likes of Japanese companies to get a sense of the success of incorporating QFD on a comprehensive basis. But now apply this to the culture of an organization and how each individual makes logical business decisions instead of emotion-based decisions.


What many liability issues begin with are the employee(s) who made a bad decision.


QFD in its simplest form is a tool to promote communications. Among peers and connected teams within the organization it provides the methodology to catch errors, omissions and emotional bias early in the process.


As an example, let's take the Request for Proposal (RFP).


Many companies depend heavily on winning business by responding to RFP's. A "deal makers" perception of importance to the RFP determines the effort for the response.


Many times, this is influenced by an incentive plan. The human behavior to accept or decline the effort on an RFP as well as what it takes to push it through the organization for executive sign offs, is not always compatible with the strategic and quality measures of the enterprise.


Over time this will form an unimaginable amount of moral decay within a company. This leads to bad behavior and unethical decisions that people make because the business environment has rewarded it for far too long. So who is to blame here? The employee or the culture and company that has condoned and encouraged the behavior that ultimately damaged someone or something.


Implementing QFD in your information-based enterprise could have a dramatic impact on achieving a defensible standard of care by reducing the likelihood of catastrophic emotional decisions.


More importantly, QFD programs such as this that are directly reducing the likelihood of bad employee behavior and criminal incidents, can reduce the necessity for invasive compliance programs that most everyone wants to ignore.

04 December 2022

TrustDecisions: Quality of Innovation...

When you approach a new problem-set in your start-up or emerging business there are several methods for your teams approach to solving it.

The methodology that you and your team use to solve your particular problem, will make all the difference in how fast the business grows and accelerates towards ultimate success.

Our team continues to utilize a SPRINT-based approach and a lean launchpad mindset to find the correct solutions to deliver with quality.

Over the course of many years of growth, the patience and the focus on staying true to the system, to the proven steps in the sequence has always provided results.

In so many cases, the results are not what we could have imagined at the beginning of our journey.

The original hypothesis we thought was going to lead us to a successful outcome turned 90 or 180 degrees.

The answers to our problem-set changed as we interviewed more people, dozens of others in the same industry with a similar set of issues in the past.

The story continues as we designed the new prototype solution. It would change after several more iterations navigating us towards true innovation.

“Innovation Navigators” don’t give up easily. We test, we try and we make changes. The pursuit of information assurance is vital.

The quality of the solution that is designed and tested to solve the problem is a direct result of the number of times you test and the information captured for analysis.

How might you hold off the business needs just a little more longer, to truly improve the quality of your deliverable?

The speed of business in many cases calls for new designs and solutions to be delivered long before the “Quality Assurance” process is fully complete.

We have witnessed too many times a solution implemented long before it was ready for production, for the playing field or for the customers roll out.

When was the last time you encountered someone who states: “Our servers have been overwhelmed by the response to our new “X” and we apologize for any delays.”

You see, problem-sets will be encountered on a more frequent basis and will take much longer to solve if “Quality Assurance” testing is not completed or compromised.

How trustworthy will you become with your clients or customers?

Consider these principles from “Achieving Digital Trust” by Jeffrey Ritter on page 35 and 36:

  • Every transaction creating wealth first requires an affirmative decision to trust. 
  • Building trust creates new wealth. Sustaining trust creates recurring wealth. 
  • Achieving trust superior to your competition achieves market dominance. 
  • Leadership rises (or falls) based on trust (or the absence of trust).

“Innovation Navigators” in 2023 and beyond shall study each one of these principles in their own organization.

They will utilize a proven methodology, that is centered on the science of “TrustDecisions”…

11 December 2021

R3: Team Leaders On The Front Lines…

Now that you and your team have finished the mission strategy planning for 2022, how might you simplify this for those on the front line who work outside the building?

When you really understand what the product/solution does and you truly believe the benefit of someone using it, now what?

Your team may know the strategy and the “Why now”, yet will you still be wondering where all of the budget allocations have gone, after the first six months of your budget cycle?

What if you focused on a small part of your team, who you might name your company “Operators”. 

You know, the people who are eager to get out the door everyday to go see and solve problems for themselves. The people that will be responsible for the implementation of the product, the tool, and the solution on the customers premises in their environment.

"The team of “Operators” in your organization who are actually accountable for the final results."

Hopefully your organization has at least a 3:1 ratio of “Operators” to “Bean Counters”.

3-Operators to 1-Bean Counter, just might give you a chance of making your mission strategy work.

In our global world of business these days, the relationships are your Ground Zero.

Without effective relationships that exist and are continuously building rapidly across your intended target zones, you will have a much longer wait for your positive and smiley face of EBITDA.

Developing and growing “Relationships” is perhaps one of your greatest Operational Risks ahead of you, as the Leader of your particular team.

Having learned a simple yet “Never Forget” acronym from a few very wise business instructors (Randy & Wendy) many years ago, consider this:

R3 = Relationships >>> Results >>> Revenue.

Guess what? It is something the “Operators” will actually understand and since you have 3 times more of these people on your front line team, they must have their own business strategy acronym that they will be able to remember and execute on:

  1. Operators that are developing meaningful and effective Relationships are your way to mission accomplishment.
  2. Operators who realize how to produce tangible Results that can be measured are your way to mission accomplishment with end users, customers and clients.
  3. Operators will see Revenue if #1 and #2 are successful.

R3 is your execution layer on top of the “Bean Counters” PEST, STEER, SWOT or any other planning acronym they might use in the “God Pod” upstairs or down a long corridor of the outside view offices in the E-ring.

In order for you as the field Team Leader, to truly better understand how to improve the “Revenue” and mitigate the Operational Risks in your business entity, you have got to get out on the front lines with your Operators.

To see and experience the real “Relationships” and the actual “Results”.

Where will your next “Senior Leader” tour of duty take you in the field of your Area of Responsibility (AOR)…

27 November 2021

Grateful: Appreciate, Reflect and Communicate...

Now that you have had a few days and been challenged to reflect on what and who you are grateful for in your life, how will you change?

The “Thanksgiving” holiday brings out some of the most interesting behaviors in people. It is now a time to reflect on what you have learned about the others in your clan, your community or your own household.

How might you take the words you acknowledged while talking to people about your“Gratefulness” and now putting those sentences into something more positive?

Rewarding outcomes for others and for yourself.

If you said you were grateful for your work/job as an example, how might you enhance the work you are doing each day to use your job as a platform.

A work platform for increased quality to create, design and deliver better solutions that provide an even more valuable result, for someone or some entity.

Is your work just one step in a multi-step process? How might you make the process more efficient, more effective or even more reliable?

If you said you were grateful for your family, how might you improve the relationships you have with your siblings, your cousins and even your Mother or Father?

What is just one way you could show your family member, that you trust them, love them and appreciate their continuous contributions?

Will you change your behavior going forward, based upon all that you have learned this past week?

Will you acknowledge your own thoughts and feelings about others, yet make the changes necessary to improve your important and vital relationships?

These two words “Thank You” are far more powerful, than you may ever realize.

These words are the beginning of a dialogue about something that is important or so vital to you.

Acknowledge it in a way, that the other person truly knows you are grateful.

Grateful adjective
grate· ful | \ ˈgrāt-fəl
Definition of grateful
1a : appreciative of benefits received
b : expressing gratitude grateful thanks
2a : affording pleasure or contentment : pleasing
b : pleasing by reason of comfort supplied or discomfort alleviated

Look them right in the eyes when you say it, or even with an appropriate emoji. If you have been successful, you will know it. Hopefully, they will acknowledge your kind words in some way.

Our personal and work environments are moving so rapidly and the ability to slow down just enough to actually Appreciate, Reflect and to Communicate effectively, is such a continuous challenge. Yet worth every minute of focus.

“Thank you” for all that you are doing, to make this place more effective, more livable, more comfortable, more enjoyable, more laughable, more loving, more faithful and more peaceful. You know who you are…

30 November 2019

Enterprise Resilience: Compete or Die...

Enterprise Resilience is the road to competitiveness. It is the global answer to many of the Chief Security Officers (CSO) who have faced the troublesome battle of selling more "Fear and Doubt" to the CEO and Board of Directors.

The 34th Overseas Security Advisory Council event was held the week before Thanksgiving as usual.  Yet flashback to when Deborah Wince-Smith stood up on the stage at the 21st Annual Security Briefing at OSAC on November 16th, 2006, when her words were music to our ears:

"It is undeniable that the world has gotten more risky. Businesses now function in a global economy characterized by increasing uncertainty, complexity, connectivity and speed. Managing this rapidly changing risk landscape is an emerging competitiveness challenge—a challenge that demands resilience: the capability to survive, adapt, evolve and grow in the face of change. The Council on Competitiveness is proud to offer this report, which promotes a strategy of resilience for both the public and private sectors a strategy with clear benefits for our companies’ competitiveness and our nation’s homeland security."


On the doorstep of 2020, globalization, technological complexity, interdependence, and speed of digital information are fundamentally changing the kind of risks and competitive challenges that companies— and countries—face.

Failure, whether by attack or accident, can spread quickly and cascade across networks, borders and societies.

Increasingly, disruptions can come from unforeseen directions with unanticipated effects. Global information and transportation networks create interdependencies that magnify the impact of individual incidents. These new types of risk, demand new methods of Risk Management.

Was this a way for the Chief Security Officers of the Fortune 500 to finally shift their thinking from protection to something less macho? How could "Resilience" become a platform for a mind set shift to justify new funding?

After all, now we aren't trying to scare people into the "Low Probability - High Impact" incidents anymore and focusing in on the high probability incidents, that may have enough impact to cause a significant business disruption.

What are the incidents and areas of risk that insurance won't touch these days? If the insurance companies can write the policy to give you peace of mind, then is this necessarily an area that you can ignore, because you have transfered the risk to someone else?  Maybe not.

Being agile, ready and capable of a quick recovery is what competitiveness is all about, on the field, on stage or around the table in the Board Room. Working towards control and protection while fear builds in the back of your mind makes you stiff, depletes your energy and creates doubt.

And when you are operating a business or standing on the tee of your first sudden death hole on any PGA weekend, you better have resilience.

The business equivalent to Homeland Security and Critical Infrastructure Protection is Operational Risk Management (ORM)—a domain that many executives see as the most important emerging area of risk for their firms. Increasingly, failure to plan for operational resilience can have “bet the firm” results.

Back in 2000, the Meta Group (now owned by Gartner) did a study on the cost of "An hour of computer downtime by industry group". These numbers are now 19 years old:
INDUSTRY SECTOR (Millions)
  • Energy - $2.8
  • Telecommunications - $2.0
  • Manufacturing - $1.6
  • Financial Institutions - $1.4
  • Information Technology - $1.3
  • Insurance - $1.2
  • Retail - $1.1
  • Pharmaceuticals - $1.0
  • Banking - $0.996
We all know that it costs lot of money to have any systems downtime, that's why so many dollars have been invested in Disaster Recovery (DRP) and other Business Continuity Planning (BCP).

Yet is this the kind of resilience that is going to make you more competitive, to seize more opportunities? The economics of resilience are more than investing for the likely or unlikely information systems incident (ransomware) that will attack your organization tomorrow.

The threat of Tort Liability and the loss of reputation is top of mind these days with every major global company executive. The threat is real and increasing at a faster rate than many other real operational risks to the enterprise. Litigation from regulators, class actions and competitors has given the term "Legal Risk" new emphasis and meaning.

Once corporate management understands the need for a "Resilience" mentality in place of a "Protection" mental state, a new perspective is found. Investing in the vitality, agility and competitive capabilities of the organization sounds and is more positive.

It alleviates the fear of doom and gloom and inspires new found innovation. The future of your organizations longevity and in its adaptability, can be achieved with a new perspective.

Compete or die.

"Enabling Global Enterprise Business Resilience
" is just the beginning...

18 August 2019

Performance Management: Risk on the Front Line...

As a leader in your particular organization, how often during your busy day do you think about culture.  The organizational pace.  The transparency and integrity that each key leader exemplifies, as they operate each hour with employees, partners and your most important community stakeholders.

Competent leaders who model peformance management processes to make Operational Risk Management (ORM) an enabling and growth oriented mechanism, truly understand that this requires a mind-set shift.

Executing on how to enable more risk taking and catalyst innovations to achieve superior growth, requires the ability to effectively incorporate risk management into your daily work products.

When you login to your APP, create a new document, start a new e-mail or enter new data into the database in the course of your daily work, you are playing the role of an information risk manager.  When you meet with, counsel, or coach another fellow employee, you have full control of how you are achieving new levels of trust.

The degree to which you follow protocols, procedures and training involved with corporate records management, information security and work place employment policies, creates the foundation for how much risk and trust, you will generate today.

Now think about how this, will impact your continuous ability to be innovative, competitive and productive, while building a trusted culture, that employees, partners and community stakeholders will quickly recognize as trustworthy and extraordinary:
So, what is trust?  
"Trust is the affirmative output of a disciplined, analytical decision process that measures and scores the suitability of the next actions taken by you, your team, your business, or your community. Trust is the calculation of the probability of outcomes. In every interaction with the world, you are identifying, measuring, and figuring out the likelihoods. When the results are positive, you move ahead, from here to there. When the results are negative, you rarely move ahead; you stay put or you find an alternate path."   Jeffrey Ritter- Achieving Digital Trust
Turning risk management into performance management, shall begin on the front line of the enterprise, with the ideal compensation strategy and the behaviors you are seeking from your front line customer service and field-based revenue generators.

Whether it's direct or in-direct channel personnel, you have to understand how to use the right mix of compensation and incentives, to drive a revenue risk appetite, that is appropriate for your organizaition.

Performance Management could also be enabled or supressed, by the amount of power you give your 2nd Tier leadership. Do they have the ability to make a $1M decision or just $10K decisions when it comes to investing budgeted capital into their particular business unit growth?

Do they manage risk on a field or geographic level where they are the most informed and the most knowledgeable about the business, or is the "Mother Ship" back at the home office, dictating the way they spend or the way they invest?

The ability to know how to manage operational risk, at the point of creating new information is the nexus of several disciplines and requires substantial situational awareness training.

Every minute that goes by, with derailed leadership or a negative culture, puts the enterprise at greater risk to lost performance opportunities.

Your cultural trustworthiness depends on how effective you are as a leader, to communicate with those who you trust the most in your organization.

You need them to assist you, with perpetuating a culture that understands the relationship with operational risk and performance management simultaneously on the front line...

03 August 2019

Intelligence Factor: A Decisive Risk Element...

In this John Keegan book review by Thomas Powers of Intelligence in War: Knowledge of the Enemy from Napoleon to Al-Qaeda ; Mr. Powers captures the essence of the decisive risk element of local information:
"The real challenge in the war on terror is one we got right in the war against Nazi Germany and failed badly at in the war in Vietnam -- helping the locals do what they want to do on their own. The free French, the partisans in Yugoslavia, the Poles and the Czechs all desperately wanted the United States to win because our enemy was their enemy. In Vietnam, our locals were defeated by their locals, who just wanted us to leave.
The war on terror is something of an afterthought in Keegan's book, added because he believes intelligence is likely to be the decisive weapon. He is surely right about that. But victory won't come from big intelligence, the kind Americans are best at -- gathering so much information and acting on it in so timely a manner that the terrorists will be nailed as soon as they step out the door. Winning this contest requires an older kind of intelligence: the kind that grows out of deep knowledge of place, language, culture and people, and then getting the basic question right -- knowing what the locals want to do on their own and putting that first."
Operational Risk Management (ORM) in your particular Area of Responsibility or Enterprise, is about the mitigation of attacks on your assets and eliminating potential hazards, in order to be a more resilient foe, or competitor on the corporate battlefield. Intelligence is information. Only information at the right time and from the right source, can give you the edge to fend off the latest barrage of share holder law suits, denial of service attacks on your corporate web site or the smoldering fire in the janitors closet.

Whether that intelligence (information) is being gathered by sensors detecting smoke, packets on the network, or the late night cleaning crew; you will not have a chance of acting in time without the human element. The human factor is still the last fail safe for determination whether a "False Positive" or "True Negative" is at hand.

Human Intelligence is being gathered every hour of every day humans are talking to each other, writing to each other or walking around using other signals to communicate. The eyes and ears of your organization are what will ultimately determine whether you win or lose the risk mitigation battle you are fighting.

Managing risks to your operations requires a network of human intelligence from the front desk to the loading dock. Intelligence is being gathered on every sales call and each customer service call to the 800 number. However, it is not until you act on what you are learning, that all of this information is converted to something productive or protective.

Look around you. How many sensors and repositories of intelligence are walking around your organization today without anyway or anyone, to convert all of that raw information into a mechanism for effective Operational Risk Management?

The organization who truly understands how to capitalize on the collection of organizational intelligence and act on it without hesitation, will be the most resilient operators and the most formidable competitors on our global asymmetric business landscape...

09 February 2019

Givers: The Master Plan for Grit...

"Of course, natural talent also matters, but once you have a pool of candidates above the threshold of necessary potential, grit is a major factor that predicts how close they get to achieving their potential. This is why givers focus on gritty people: it’s where givers have the greatest return on their investment, the most meaningful and lasting impact."  Grant Ph.D., Adam M.. Give and Take (p. 106). Penguin Publishing Group. Kindle Edition.
This quote is in chapter 4, Finding the Diamond in the Rough - The Fact and Fiction of Recognizing Potential.

Having passion and perseverance in any endeavor is worthwhile.  In this chapter of Adam Grant's book, he is talking about "Givers".  You will have to read the book to better understand the research of 30,000 people behind who you are and the difference between "Givers and Takers".

Flashback to your early years as a kid in elementary school.  Now think about all of the activities and endeavors your parent(s) had you involved with, in or outside the classroom.  Were you involved in the scouting or other after school activities?  What about your local church or synagogue?  Maybe your parents were even Boy or Girl Scouts themselves?  Did they achieve "Eagle" or the "Gold Award"?

Flashback to your years in Middle and High School.  Were you involved in Sports Teams or maybe the Marching Band?  Or perhaps the more academic or creative teams like "Debate" or the "Thespian Club".

What about in University or College?  Did your passion and perseverance for sports or other skill-building endeavors, keep you gaining more of what is called "Grit", a firmness of mind or spirit, unyielding courage in the face of hardship or danger.  Were you able to graduate within 4 years and then obtain a decent job or commission to start your career?

If you accomplished all of this and are now well on your way to discovering and building a life full of rewarding experiences, you probably need to say "Thank You".  To your Mother, Father, Teacher, Boy/Girl Scout Leader, Coach, Commander or Professor.  They are the ones that got you to where you are today.

Yet if someone ever calls you a "Diamond in the Rough" you should consider that a complement.

And you should also consider what they meant by that reference.  It means that they as a "Giver" who focus on gritty people, have found what they are always searching for.  They have recognized that you too are someone that stands out, that has the knowledge and the skills and that extra perseverance they are always in search of.

You may be wondering when your time will come.  When you will finally feel like you have "Made It" in life.  That you are truly happy.  Guess what, you are not there yet...

Why?

It is because you have not reached all of your potential, designed just for you.  The "Master Plan" for you is unique and you must realize that there is no visible finish line.  There are only more opportunities, tests, more challenges, significant success and substantial road blocks.

Being a "Giver" in your life means that you seek a path that puts you in pursuit of others just like you.  You know when you have found your Tribe, your calling and you know that they will be there to help you through the tough times and to persevere.

Now it is time, for you to contribute.  Your knowledge.  Your skills.  Your passion...yet do not fear asking for help.  The "Givers" in your community are searching for you now...

Godspeed!

02 February 2019

Transparency: "Square One" in ORM...

Operational Risk Management (ORM) has been evolving for over a decade. There are new insights into why effective business process management coupled with Operational Risk architecture makes sense, through the lens of the Board of Directors. Transparency.

Still to this day, the questions remain:
  • What can my organization do about the risk of loss resulting from inadequate processes, people, or systems?
  • To what extent should my organization link employee compensation or job performance with operational risk management?
  • How is operational risk taken into consideration when new products or technology solutions are designed or acquired, deployed, and executed?
  • Does my organization have an inventory of its key business processes with documented controls and designated senior managers responsible?
Can these questions be answered in a book of 308 pages from 2008? It was a good start, to say the least. The authors understood, that to really embed a culture of (ORM) into the enterprise, you have to begin at the architecture level, the business process level.

This is far in advance of the governance of information and the business rules coded into software systems, even for such mundane corporate tasks as expense report or travel request review and sign-off.

You see, some companies still think that they are just doing fine with their Safety and Security Team, Continuity of Operations and Crisis Team, Chief Information Officer (CIO), General Counsel (GC), Chief Financial Officer (CFO) and in limited cases the Travel Risk Management department all working autonomously. They think that having a few dedicated investigators to look into corporate malfeasance, is all they require in a corporate population of tens of thousands.

What do we mean by autonomous? Not what you may think. There is no doubt that the leaders of these organizational departments are cooperating and coordinating functionally. They have each other on speed dial. They share high level red alert Intel with each other.

The question is, what is being done at the metadata level of the Operational Risk Enterprise Architecture (OREA)?

How are they designing Operational Risk Management systems to answer key questions at the speed of business? To continuously adapt to an organization’s changing global environment, executives must know about, keep in balance, and communicate several vital components:
  • What are the organizational strategies (Strategic Intent) and how these should be implemented (Strategy Development and Organizational Change)
  • What organizational processes are executed and why, how they are integrated, and how they contribute to the strategy of the organization (Business Process Management)
  • How human resource utilization is working and whether there is optimum use of skills and resources available across processes and functions (Human Resource Management)
  • To what extent the enterprise organizational chart is cognizant of appropriate roles and responsibilities, in order to effectively and efficiently carry out all work (Organization Management)
  • What IT applications exist and how they interface with what processes and functions they support (IT Portfolio Management)
  • How the performance of each process, each function and each individual adds up to the organization’s performance (Performance Management)
  • What projects are currently underway, how they effect and impact change, what processes and IT applications they change and how this contributes to the strategy of the organization (Project & Program Management) 
Is Operational Risk Management (ORM) about "Big Data Analytics"?

Only if your organization values better transparency, governance and regulatory compliance. Ask the Board of Directors their answer on this question to determine whether ORM is a "Big Data Analytics" issue. How big is big?

The momentum for transparency is now at the U.S. government level of commitment.   It is the law. Big Data Analytics will mean nothing, without increased transparency. Now we can ask the questions that we all want answers to.

The Operational Risk Management (ORM) architecture of your enterprise will now begin with transparency, as the fundamental "Square One".

01 December 2018

Survival: Experiential Learning to the Rescue...

Change is in the wind.  You have heard this before and the truth is, that this is not anything new.  We have only started to understand however, how the accelerating pace of change, is impacting us.

The number of App's staring at you in the palm of your hand should be one indicator.  How many are you using on a daily basis now?  No longer are we spending a work day logged into an e-mail client, our word processor and maybe the spreadsheet or database application.

The pace of change and the number of places we access our valuable daily information is rapidly taking over our lives.  We have seen the growth of Fortnite now at exponential proportions and little did Potomac Computer Systems, now Epic Games know what was ahead of them upon their founding in 1992.

In the gaming industry they have genre(s) and Fortnite is a survival game:
Survival games are a subgenre of action video games set in a hostile, intense, open-world environment, where players generally begin with minimal equipment and are required to collect resources, craft tools, weapons, and shelter, and survive as long as possible. Many survival games are based on randomly or procedurally generated persistent environments; more-recently created games are often playable online, allowing multiple players to interact in a single persistent world. 
Wake up corporate management.  As you proceed to continue your growth in your particular industry over the next decade, think about the pace of change.  How fast will you be able to pivot, adapt and survive in your persistent environment?

Think about your latest strategic endeavors that you have launched in the past year.  Has the process and goals been achieved, without some level of challenge, disruption or even misdeeds?  The likelihood is, that somewhere along the way, the project, the business or the endgame was at risk.  Perhaps not a total failure, yet not the envisioned outcome.

It is this game of perceived survival and the new pace of change in our lives, that is the greatest Operational Risk before us.  How will we mitigate the risk of such rapid change?

Experiential business learning is a vital way forward.

"Experiential business learning is the process of learning and developing business skills through the medium of shared experience. The main point of difference between this and academic learning is more “real-life” experience for the recipient.[31][32][33]

This may include for example, learning gained from a network of business leaders sharing best practice, or individuals being mentored or coached by a person who has faced similar challenges and issues, or simply listening to an expert or thought leader in current business thinking.

Providers of this type of experiential business learning often include membership organisations who offer product offerings such as peer group learning, professional business networking, expert/speaker sessions, mentoring and/or coaching."

How are you capitalizing on the people in your organization who are part of an external group or other network of like-minded professionals?  It's difficult if you don't even understand who or where your own employees are interacting on a daily basis outside your company.

So what?

Perhaps the place to start is by asking people.  Ask them over coffee in the corporate food court or that new Open Space floor plan with the "Bistro" on every other floor.  What if they told you, that they were a member of an external or virtual organization because they could not find the information or the people with the expertise inside your own organization?

Your goal is to figure out how to capitalize on all of these external groups, organizations and "Experiential Business Learning," that is going on within your own company today.
 How might you capture that passion and the excitement this individual has for the network or "Virtuous Insurgency" they are learning from everyday?
The Operational Risks before you, spans the number of people in your team who are learning somewhere else X the number of other networks they are affiliated with.

Who on your team is gaining new insight somewhere else?  Who are building valuable relationships outside the perimeter.  Who are living in a new unpredictable world of survival...without you even knowing about it.

What could you be learning today?

18 November 2018

Risk Parity: Ideal Organizational Design...

Organizations across the globe are operating each day with Operational Risks. As a result, management is doing their best to implement a combination of Operational Risk Management (ORM) capabilities.

The strategy is to manage risk to the enterprise through a series of controls and modification of human behavior. Is it possible to create the most ideal organization from the start? Could you design it with the lowest possible Operational Risk exposure at every physical, process, virtual and human component?

What do we mean by this? Lets play a game. Or more importantly, lets imagine a workplace exercise to design the ideal professional services organization in one hour:

This organization will be in the private sector. The fictitious name for the organization is "Improvise, Inc." All of the legal entities have been created and it is registered as a U.S. Delaware company. It will have the following characteristics, capabilities, assets and purpose:

200 humans with advanced education between 25 and 65 years old. 50% Men & 50% Women
Global reach of professional services. (It sells intellectual capital and information)
Office hubs are physically located across four locations: Denver, Zurich, Abu Dhabi, and Singapore.
Language expertise includes English, German, French, Italian, Arabic and Mandarin.

Subject Matter Expertise of the Improvise associates is diversified. The core staff devoted to operational administrative processes is also diversified by physical location, 4 people each. Therefore, less than 10% core overhead.

Improvise, Inc. generates revenues by selling information, advisory services and subject matter expertise. The diversity of it's 200 humans and their Intellectual Capital provides professional services to Fortune Global 500 companies.

Now, to start the exercise you will have one hour to design the ideal mosaic of people, processes, systems and external factors to operate Improvise, Inc. on a daily basis. Begin.

How would you begin designing the ideal organization? Will you have a headquarters location? Will the offices have four leased corporate offices or utilize a virtual / shared space model? What will the facilities layout be with single offices, cubicles, conference rooms? Would you start with human resources and the hiring and selection process? What kind of systems and tools would you procure to issue to your new associates? How would you communicate and what vendor/providers will Improvise use outside its core? What organizational "Rule-sets" will be established?

Who will govern and what roles of power and influence will these employee-owners (Associates) have to make decisions for the good of Improvise? What countries across the globe will you dispatch your associates to do their work? How will you keep them safe and secure where and how they travel? What vendors and service providers will you contract with to provide digital communications and store your valuable intellectual property?

Will you locate your Associates across the four locations equally? Since you have 200 split into 100 men and 100 women, will you have 25 of each or 50 people in each office? Will they all be citizens of that native country only? Again, we are designing the ideal organization with Operational Risk Management (ORM), as our highest priority in the design. Is this even a valid consideration?

What about the use of digital assets? Will your associates at Improvise use PC or Mac, both? Microsoft or Linux-based? Android or iOS? Anti-virus scans daily or monthly. VPN, yes or no. Public or Private cloud? Encrypt data to remote sites? Retention and privacy policy? What happens when an associate goes home? When they leave the organization? Is there an "Acceptable Use" policy in place? And the list goes on.

Will Improvise standardize on a single travel agency, airline or hotel chain? What kind of training will occur with your associates on international customs, cultures, threats and vulnerabilities. Who will be accompanied by a buddy system or personal protection specialist when they travel? Will travelers receive intelligence briefings or reports in advance of their departure? Commercial or private carrier?

What processes are to be put in place for Improvise to follow, in the way it sells and delivers it's professional services? What autonomy does each associate have to make their own decisions on the price, scope and deliverable to a client? How do you interact, treat and question yourselves? Are your associates subject to any laws from the U.S. or the country they are operating in with regard to selling your professional services? Why are we doing all of this?

So when you are done with this first phase of the exercise after one hour, how could you improve Improvise, Inc. over your lifetime? Hopefully, this illustrates the breadth and depth of Operational Risk Management (ORM) and some of the key considerations. Your single points of potential failure. Your risk exposures and places to focus your design. Your decisions and how this shapes your culture and principles. Your trust and transparency.

One last thought. How would you currently judge your risk parity? In other words, how have you allocated risk effectively across the organization. Not in terms of assets, but in terms of volatility. Think about it. What kind of social contract do you have in place to operate together?

Is it true, that you are now on your way to achieving true "Business Resilience"...

20 October 2018

Linchpin: Who will you call?

Are you a "Linchpin" in your organization? The person who people may call the "Fixer", "Troubleshooter" or just plain "Rainmaker". Are you considered to be a combination of all three and indispensable?

By now, hundreds of thousands or maybe millions of people have read Seth Godin's book, Linchpin: Are you Indespensable.  They are now well on their way to becoming more self-aware of their position within their organization and the others they interact with on a daily basis. Are you just following instructions or are you a leader or an artist in your industry or company?

Operational Risk Management (ORM) Executives know who in the organization are considered "Linchpins". If they don't now, then it's time to learn who they are and why. Some of these people may even be outside the formal organization and it's imperative that you know who they are as well.

Why?

Because when the next major incident makes itself visible or when the Emergency Management Broadcast System breaks into the TV or there is a breaking story on the Radio show you're listening to, then you will know the correct "Linchpin" to deal with the risk category and situation that is unfolding before you.

So who are some good examples of Linchpins in your life or organization? The people who get the call to handle the problem, issue or opportunity in their particular category or area of subject matter expertise.

Each one of these people at their respective organizations or category, has been a "Linchpin" at a particular moment in history with the following characteristics articulated by Seth Godin in his book:
  • Charm
  • Talent
  • Perseverance
Seth does a great Venn Diagram on page 43 of his book that describes those who may have only two out of these three traits or areas of competency. If you only have Charm and Talent then you are a Prodigy. If you have Charm and Perseverance then you are a Princess. If you have Talent and Perseverance without Charm then this is pure Frustration. Yet if you have all three, then you are a Linchpin.

Now think about the people you know in your organization who have all three. These are the "Linchpins" that you want to know and you want to have at the tip of your call list.

Operational Risk Management that is effective and responsive may require the Linchpin to handle a dire situation or rectify a dispute or investigate an allegation or discover the right balance of art and science.

The road to becoming indispensable in your group, organization, unit or department may begin with some DNA, yet it is something that almost every human can aspire to become.

Search out the people in your organization who are Operational Risk Linchpins and find out a way to have them start teaching your most promising students, on how to achieve greater levels of charm, talent and perseverance.

17 June 2017

Innovation: Investing in the Linchpins...

There are new innovation initiatives that have been launched across America and internationally over the past few years.  Each has a vertical or horizontal focus to attract a particular set of entrepreneurs, coders, researchers and founders or data scientists.

You may have seen the accelerators, the incubators, training boot camps or even the H4D class being offered in your particular U.S. city or university lately.  Behind these initiatives are leaders, executives and fellow startup founders/practitioners who have developed a combination of methodologies and strategies, to produce new products and problem-solving business platforms.

After several years of practicing and mentoring in this category and recently devoting 30+ hours of first hand observation, there are several insights that were discovered.

First off, the quality and experience of instructors, mentors and the support ecosystem is vital.  You must create a robust program to recruit, train and continuously facilitate the actual people who surround the accelerator, incubator or university class and are devoting their time and resources to volunteer.

The ecosystem itself requires tested and proven processes, business rules and significant buy-in by all contributors.  The volunteers need a set of program prerequisites, a framework and the coaching along the way, to make their experience just as valuable as the participants in the innovation entities program.  Many of the mature innovation programs do this already.

Second, the founders, subject matter experts, linchpins, content providers or problem-set sponsors should have their own meetings and live interactions before and after each iteration of the participants program.  As an example, if the incubator has a cohort that is in-residence over the course of 10 weeks, on Tuesday's from 4:30-7:30PM, then the volunteers should meet for 30 minutes before and 30 minutes afterwards.

Why?

During those 3 hours there are plenty of live interactions, new learning, comments and ideas generated with the actual program participants.  It is just as valuable for the volunteers to share and interact after each iteration or cohort meeting to prepare and to debrief.  Certainly some of the follow-up learning could be captured using Slack or other online tools, yet having those linchpins face-to-face and interacting live is ever so valuable.

So What?

The maturity of the systems and processes associated with the innovation initiative, will be a key factor in the long term success and longevity of a particular program.  Yet even a set of solid systems can be influenced and characterized simply by the combination and quality of people, who are interacting and supporting these systems.  The parallel effort and devotion of one-to-one development, training and post program-metrics of these instructors, mentors, problem-sponsors and facilities or resources donors is paramount.
If you are an innovation engine producing new entrepreneurs and business startups that utilizes an ecosystem of volunteers, your future success will be directly linked to these vital linchpins...

15 January 2017

Inspired Outcomes: A Culture of Why...

Why does your organization exist?  Most people answer this question with the kinds of products or services provided.  This is "What you do".  Some people talk about how they provide the service or how the product works.  This is "How you do it".  This does not answer the question.

Most organizations have it backwards.  What >> How >> Why.  Now think, Why >> How >> What.

Why your organization exists, is paramount to understanding the real purpose and DNA of your culture.  It is vital to the people who show up every day, the core reason they perform their role or contribute to the measurable outcomes of the team.  True Operational Risk Management (ORM) professionals discover the "Why" at the beginning.  Without the truth behind "The Why", nothing after it, has enough context.

When you begin the journey to build a better product, or invent a new process you better know the answer to "Why".  Discovering this first, will provide the inspiration, the creativity and the fortitude to get you and your team out of bed the next day, to do it all over again.  Without the "Why", we as humans lose sight of our destined purpose.

Over seven years ago, Simon Sinek was advocating for "Why" in his book and on Ted Talks.  A few years later, he was helping the Air Force hone new leadership skills in it's pilots:
"I told the guys, it's not enough any more to be ace of the base," said Col. Richard "Tex" Coe, commandant of the United States Air Force Weapons School. "We have to bring others with us.

Coe believes the school's new leadership curriculum will translate to success in the global war on terrorism, particularly in the fight in Afghanistan.

"What we're going to be doing is purposely developing these innovative and creative leaders that will go out there and face problems," Coe said.

"We don't even know our problems yet, and we'll be able to put our pieces together and use resources and other people around us to get the mission accomplished."

Coe, a master navigator with more than 3,000 flight hours including 460 combat hours, left Afghanistan in 2002. Today, the country "is a new and different place" he said.

"It's a completely different problem than it was back then. It's ever changing, and we're preparing them for that ever-changing problem."
"What we believe" is not the same as "Why We Exist".  It is different and it could mean the difference to owners, employees, partners and external customers or clients.  Here is just one example from Palantir:
Why
We’re Here

"We believe in augmenting human intelligence, not replacing it.

With good data and the right technology, people and institutions today can still solve hard problems and change the world for the better."
How could you make this even more compelling?  More inspiring and motivating, so that you want to jump out of bed each day at the sound of the morning alarm.

Behind every process, product and service there are humans who must see, feel and smell the "Why".  If and when they do, now they are ready to endure the journey, the quest and the challenges ahead.  They are there for a purpose they can internalize and outcomes that they can pursue vigorously, each day.

Discover the "Why" from your clients and customers, if you have not already done so.  Understand deeply the reason why they are doing business with you.  You may be surprised to know that your clients are paying you more than your competitors, for the same product or service.  You may soon find out the real value of "Trust."

Making the "Decision to Trust" one product or service over another, can not be under estimated.  Yet so many organizations and companies fail to find the truth about "Why" in their ecosystems of followers.  Is it the location, the price, the ease of use, the color, the feel, the endurance, the speed, the intelligence?

Once you have discovered the truth on "Why", you must know "How".  Then the "What" will follow, with the name of your product or brand.  Isn't it interesting that when you are attending a networking or convention event, that when you meet someone new, they may ask:  "What do you do?"

What if you answered the question like this.  "I work with "X" and we exist to "Y".  The cause and reason for your organizations existence transcends everything.  It provides the foundation for why this person is going to trust you and your organization.  Now if they would only start the conversation with:  "Why does your organization exist?"

Once you have a solid foundation for "Why", then you must know "The How" and then "The What".  Here is another example:
SpaceX designs, manufactures and launches advanced rockets and spacecraft. The company was founded in 2002 to revolutionize space technology, with the ultimate goal of enabling people to live on other planets.
Or how about:

"SpaceX exists to enable people to live on other planets.  We manufacture rockets and launch them so that our customers can supply other spacecraft or travel to other destinations beyond Earth."

Now think about your organization.  Take a deep look at your culture.  What is the fuel that will propel it into the future to achieve extraordinary outcomes?  Exponential results...

20 March 2016

Vigilance: The Casualty of the Truth...

On the other end of a planned cyber threat are the motives and plans by a person.  Sometimes that person puts into play the use of a "Bot" to carry out many of their planned steps in their scheme.  Operational Risk Management (ORM) professionals have been classifying these cybercriminals for a decade or more yet even now in 2016 they are getting more formal profiles:

BAE Systems, the London-based, multinational security company, recently released profiles of “six prominent types of cybercriminals” and detailed how they could hurt companies around the globe, officials say.

Threat intelligence experts at BAE Systems have compiled a list, “The Unusual Suspects,” that has been created from “research that uncovers the motivations and methods of the most common types of cybercriminals,” according to BAE. “The intention of the campaign is to help enterprises understand the various enemies they face so they can better defend against cyberattacks.” BAE Systems officials have profiled six cybercriminal types:
  • The Mule – naive opportunists that may not even realize they work for criminal gangs to launder money;
  • The Professional – career criminals who work 9-to-5 in the digital shadows;
  • The Nation State Actor – individuals who work directly or indirectly for their government to steal sensitive information and disrupt enemies’ capabilities;
  • The Activist – motivated to change the world via questionable means;
  • The Getaway – the youthful teenager who can escape a custodial sentence due to their age;
  • And The Insider – disillusioned, blackmailed or even over-helpful employees operating from within the walls of their own company.
These individuals and groups have caused billions of dollars in losses and caused significant harm to millions of people and organizations.  Now what?

It will be many more years to come, before the laws catch-up to the technology and those who use the vector of the Internet to carry out their crimes against humanity.  Law enforcement has their hands continually tied by the laws and the geographic challenges of a global epidemic.  Governments and politicians are in constant battle over the privacy vs. security philosophy and all the legal issues.

While the wheels of Parliament, or the U.S. Congress slowly turn and the mechanisms for law enforcement become more robust for evidence collection, investigations and prosecutions, there are significant strategies of resilience that we must focus our respective vigilance.  It is not anything new per se, just a renewed emphasis and a new commitment to redesigning our digital environments.  We can do better.

For now, what if we just pick one cybercriminal type to focus on.  The "Insider".

The "Insider" is most likely in almost every formal organization today, working diligently to mask and perpetuate their goals until they are revealed.  It is your "Duty of Care" to continuously deter, detect, defend and document within your enterprise.  The "Insider" could be anyone and so how can the organization work ever more so vigilantly?

It begins at the core of the business and the culture that surrounds those principles within your company, your team or your relationship with suppliers.  The environment you build and sustain shall have the transparency and the elements necessary to sustain a culture where the "Insider" is incapable of operating.  Where the culture itself, makes the environment impossible for the "Insider" to operate without disclosure.

We would encourage Operational Risk Management (ORM) professionals to incorporate new found strategies, new management tools and a renewed effort to extinguish the "Insider" threat across the globe.  The best way we can do this today, is to work on the culture and to establish the foundations for future "Trust Decisions" within the enterprise.  The root of changing the culture and achieving the desired future environment, begins with every single decision to trust.

The journey ahead will be long and full of new found challenges.  The vision of the future and the outcomes received will soon be more apparent.  Now the real work begins to start the journey with your own organization, with each person and understanding the environment and culture you seek.  And remember:
"In war, truth is the first casualty."
Aeschylus
Greek tragic dramatist (525 BC - 456 BC)

    31 January 2016

    Risk Culture: The Root Cause of Business Assurance...

    There is a scarcity of enlightened organizations who truly understand the root cause of risk in their enterprise. The business assurance they seek and the Operational Risk Management (ORM) outcomes they receive, are in direct proportion to the "Risk Culture Maturity" within the company.  This risk culture maturity, is at the root cause of why certain kinds of risks exist and what ability the organization has to accept, mitigate or transfer that risk.

    A risk culture begins and ends with a human ability to communicate effectively with other humans. The human behaviors associated with communicating risk has all to do with the ability of one person to know the truth and to effectively tell the other accurately and effectively what the risk is and how it could impact the business. The trouble is, most organizations fail to spend enough time doing exactly that and doing it with out fear.
    "What kind of fear? The fear that by telling your supervisor you might offend them. The fear that by questioning the co-worker about their decision, that you will alienate them. The fear that by uncovering a fellow workers risky behaviors to the rest of the team, that you will jeopardize the overall mission."
    The ability or lack of ability by a human to communicate risk factors to each other with the truth and without the fear of judgement or retribution is why you either live or die. This is the reason why your organization continues to flourish or rots from the inside out. You see, the risk management environment in your team, unit, office location or FOB has all to do with communicating the truth in an effective way.

    The risk culture problem, is one that continues to rear its ugly head time and time again and exemplifies itself in the published press, or the digital eDiscovery process of modern day litigation. Look back on most any loss event like this and you will see that it could have been addressed or contained, if only humans would have communicated effectively about risk(s) to them personally or to the unit. Whether it be a family, a branch office, partner or entire agency of government.
    Companies need to put in place oversight of strategic partners, vendors and service providers to ensure that those support organizations are meeting their own risk standards. A company should share its risk management guiding principles with third-party suppliers or partners to influence their decision-making process. Risks and controls should be a consideration when choosing new partners, and they should be re-evaluated on a regular basis to help avoid the potential of vicarious liability by the poor decisions of an alliance partner.
    The organizations that survive and are able to out perform their competition are those that understand this reality. Leadership who magnifies the requirement for people to strip away the fear of judgement, retribution, or long term bias and to communicate the reality of what they truly sense as humans will be superior. The risk culture that is understood, truly, and simultaneously monitors peoples ability to learn from their mistakes will continue to outperform and survive in whatever environment it lives in.

    Leadership is charged with the state of their organizational culture. The fundamental risk to any organization, is that leadership does not recognize this and pays little or no attention to maturity of their culture to deal with risk and human factors ecosystem. This begins with the person across the table, by your side in bed or next to you in control of a vehicle, on land in the air or in the ocean.

    It doesn't matter who the leader is. The Founder, CEO or Chief Risk Officer. The Branch Manager, Area Supervisor or Vice-President. The Element Leader, Master Chief or C.O.. Mother or Father. Managing the culture of communicating the truth, reality and without judgement begins the process of a risk management entity that will not only survive; it will outperform the perceived opposition.

    Enlightened individuals who are multi-dimensional and are comprised of a brain trust of diverse people who have different life experiences. These courageous people must then be engaged in the correct setting and risk culture, with the right combination of business objectives, resources and highly detailed mission outcomes. Only then will the environment they operate in determine who survives the continuous performance evolution.

    The root cause of Business Assurance and Resilience is the Risk Culture.