18 March 2012

Product Innovation: Individual Responsibility for Risk Management...

The next generation of Operational Risk Management professionals will be focused on a whole new set of thinking. Mitigating business risks that are associated with running the day to day functions of the enterprise will require people who have a command of their own accountability. The management of risks in their particular area of operations, will have an acute sensitivity to the level of experimentation, testing and innovation. This responsibility for individual levels of proactive risk management, begins with a new mind-set shift about the world of work itself, and our own management of our personal work product.

When you analyze where the financial services industry has exposed itself to tremendous losses over the years, it will no doubt be tied to some innovative instrument or product that was invented by some very creative and innovative people. These losses surrounding Credit Default Swaps (CDS) or Collateralized Debt Obligations (CDO) as an example, all started when an innovative person utilizing the latest tools available created a new product to be introduced to the marketplace. Sure, there were risk management professionals involved in the pipeline to production including lawyers, math quants and finance experts. Yet a failure of Operational Risk Management, led to serious losses and a global crisis, that may well be just the precursor to something even more sinister.

The humans quest for innovation, creativity and the ability to adapt is built into our DNA. So is the ability to survive and to overcome the adversities of our environment to sustain ourselves. Whether that is in the form of food and water or capital and manpower doesn't really matter. Leveraging the available resources to stay alive, being competitive and gaining more power in the conference rooms of Wall Street, or the Madrasahs in South Waziristan, remains a constant.

Innovation in the workplace, is vital for our employees to thrive and for new products to be discovered and old ones to be enhanced. Those new products are invented by people who will have the simultaneous task of doing a sound operational risk assessment. Managing risks at the same time you are innovating, is hard to separate from each other. The trade-offs and the decisions on whether to use this material or algorithm based upon use, shelf-life and the environment that the new product innovation will be operating in, takes prudent risk analysis.

So what will be different for our next generation of Operational Risk Management professionals? What will the new thinking be all about? It will be about engineering the four-step process into everything we do, and to reinforce the compliance with each step of the teams process:


1. Assess the situation.

The three conditions of the Assess step are task loading, additive conditions, and human factors.

  • Task loading refers to the negative effect of increased tasking on performance of the tasks.
  • Additive factors refers to having a situational awareness of the cumulative effect of variables (conditions, etc.).
  • Human factors refers to the limitations of the ability of the human body and mind to adapt to the work environment (e.g. stress, fatigue, impairment, lapses of attention, confusion, and willful violations of regulations).
2. Balance your resources.

This refers to balancing resources in three different ways:

  • Balancing resources and options available. This means evaluating and leveraging all the informational, labor, equipment, and material resources available.
  • Balancing Resources verses hazards. This means estimating how well prepared you are to safely accomplish a task and making a judgement call.
  • Balancing individual verses team effort. This means observing individual risk warning signs. It also means observing how well the team is communicating, knows the roles that each member is supposed to play, and the stress level and participation level of each team member.
3. Communicate risks and intentions.
  • Communicate hazards and intentions.
  • Communicate to the right people.
  • Use the right communication style. Asking questions is a technique to opening the lines of communication. A direct and forceful style of communication gets a specific result from a specific situation.
4. Do and debrief. (Take action and monitor for change.)

This is accomplished in three different phases:

  • Mission Completion is a point where the exercise can be evaluated and reviewed in full.
  • Execute and Gauge Risk involves managing change and risk while an exercise is in progess.
  • Future Performance Improvements refers to preparing a "lessons learned" for the next team that plans or executes a task.

So what does the renewed emphasis on the process being embedded into our work actually do for our work product? It gives the human a sense that the innovation is now ready for experimentation and field testing. This means that it is still not ready for prime time or the marketplace. You see, this realization is important. The recent focus on rapid prototyping and a push to get products to the marketplace before the competition, has produced the sinister and evil outcomes we have all witnessed. Why does it take so long for a new drug to make it through the pharmaceutical pipeline and end up being advertised on the CBS Evening News?

And even then, after so much testing and study, we find that a new drug (product) is not really so safe compared to the long term complications of using it as prescribed. The risk reward equation is at stake in our financial services industry and every other economic sector that is striving to be more innovative in todays global marketplace: For individuals, here are $18 Million reasons:

Attorney Lynn Szymoniak had spent a career investigating insurance fraud when a bank moved to foreclose on her Florida home in 2008. Almost four years later, the fraud she said she uncovered by combing through mortgage documents earned her $18 million.

Szymoniak, 63, is among six whistle-blowers who will pocket $46.5 million as part of a $25 billion national foreclosure settlement that state and federal officials reached in February with five banks, including Bank of America Corp. andJPMorgan Chase & Co. (JPM), according to the U.S. Justice Department.

“When they did this to her, they picked the wrong person at the wrong time in the wrong place,” Richard Harpootlian, Szymoniak’s attorney in two whistle-blower cases, said in an interview. “They stuck their hand into the beehive.”

Szymoniak’s examination, in which she relied on her experience as an insurance-fraud investigator, led to her claims against banks for submitting fraudulent documents to the federal government asserting that they owned loans insured by the Federal Housing Administration, she said.

The national foreclosure settlement with the five banks, which resolves claims of abusive foreclosure practices, provides mortgage relief to borrowers, pays $1.5 billion to those who lost their homes to foreclosure, and sets standards for how the banks service mortgage loans.

Who will be your choice for effective operational risk management as your new innovative products are consumed by the marketplace?

A. Your employees or workplace stakeholders

B. Your customers or consumers

The choice is yours as your institution puts new resources and new incentives in front of your workplace stakeholders.

25 February 2012

RSA Conference: CSO Insomnia Over Insider Risk...

Next week in the U.S. there will be thousands of risk management and security professionals invading the RSA Conference in San Francisco. The myriad of topics, education and case studies are worth examining to see what is on the mind of these thought leaders and practitioners who are also designated speakers. You can even look to the popular press to see what the vibe is on what this years biggest worries will be:

  1. Mobile Devices
  2. Advanced Persistent Threat
  3. Big Data Privacy
  4. Hacktavists

However, if you spend some time to drill down on each of these topic areas and really look at the actual presentations of the presenters, some are based upon real cases and research and others are not. The one presentation that caught our eye and continues to be what some savvy CSOs would say keeps them sleeping with one eye open each night, is their insomnia over the "Insider Threat." That person or organized group of unidentified subjects that are there to recruit vulnerable people into initiating or perpetuating crimes against the organization.

Dawn Cappelli runs the Insider Threat Center at the Software Engineering Institute and highlights these areas of concern from their research and analysis of real cases:

The CERT Top 10 List for Winning the Battle Against Insider Threats

Dawn M. Cappelli Director, CERT Insider Threat Center CERT Program, Software Engineering Institute Carnegie Mellon University

  • 10. Learn from past incidents
  • 9. Focus on protecting the crown jewels
  • 8. Use your current technologies differently
  • 7. Mitigate threats from trusted business partners
  • 6. Recognize concerning behaviors as a potential indicator
  • 5. Educate employees regarding potential recruitment
  • 4. Pay close attention at resignation / termination!
  • 3. Address employee privacy issues with General Counsel
  • 2. Work together across the organization
  • 1. Create an insider threat program NOW!


Number Three on the list is certainly on the top third and for good reason. Employees and the policy decisions on what data is owned by the company and owned by the employee is of grave concern these days in the United States. Now after so many years it looks as if this issue is going to get more heated and see the light of day from a congressional point of view. Yet the CSO must feel that the ability for the safeguards necessary to keep the organization safe and secure are not in place yet. Catherine Dunn of ALMs Corporate Counsel sheds more light on this:

According to a new White House report on consumer data privacy protection, trust is worth a lot of money to U.S. businesses—users have to know their data will be protected if the economic engine of digital innovation is to keep roaring. Ergo, the U.S. needs a privacy framework that’s “flexible” enough to accommodate industry innovation, and comprehensive enough that consumers will feel safe—and keep clicking.

But trust between consumers and companies in the U.S. is only part of the equation. There’s another important element, too: how compatible U.S. safeguards are with those of the rest of the world, and particularly Europe. This new proposal arrives a month ahead of a conference on data protection between E.U. and U.S. officials in Washington, D.C., leading to questions about whether Europe and the U.S. are any closer to getting on the same page when it comes to data privacy.

The answer not only depends on who you ask, but also what section of the White House’s report you’re looking at. The white paper lists seven principles and stresses that these principles should form the basis of voluntary codes of conduct adopted by industry. Once adopted, the Federal Trade Commission would have the power to enforce compliance to those codes. The paper also includes a call for Congress to pass legislation based on these principles, and devotes a section to “international interoperability”—which considers how data can be sent across international borders without violating laws on either side of the transaction.

This is where we need to make sure we understand the difference between what privacy issues have to do with a company employee and the privacy associated with just a U.S. consumer, who is not an employee but perhaps a member, client or customer of the organization.

If we go back to the big worries at RSA and combine this with the employees who are operating at the "Speed of Business" in your enterprise, you begin to see the difference. Actually, if you think about it some more, every employee of the organization has a duty to care for the information inside the organization, in order to better protect the assets of the enterprise but simultaneously the assets of the consumer.

The consumer assets are their "Personal Identifiable Information" (PII) and this represents in many cases what the organized criminals are after in the first place. This is where the outside recruitment threat starts to have its nexus. However, even the highly trained and state sponsored agents who are inside the enterprise to steal corporate or national security secrets are far and few these days. That may be surprising to some, but if you look at how the exfiltration of data is taking place it's almost all automated. No human intervention is required.

If that is the case, then what is Dawn Cappelli and the Insider Threat Team at CERT so concerned about from their research insights:

Criminal enterprises mask their fraud by involving multiple insiders who often work in different areas of the organization and who know how to bypass critical processes and remain undetected. In several cases, management is involved in the fraud. Those insiders affiliated with organized crime are either selling information to these groups for further exploitation or are directly employed by them. Ties to organized crime appear in only 24 cases in the CERT insider threat database and are characterized by multiple insiders and/or outsiders committing long-term fraud.
All of the insiders involved with organized crime attacked the organization for financial gain. The insiders usually were employed in lower level positions in the organization, were motivated by financial gain, and were recruited by outsiders to commit their crimes. The average damages in these cases exceed $3M, with some cases resulting in $50M in losses.


Now you know why your CSO is headed to the RSA Conference this week and why they are sleeping with one eye open these days.

07 January 2012

PPD-8: Resilience of the Whole Community...

Business Resilience in 2012 will continue to be a factor of the private sectors ability to withstand the Operational Risks that it encounters. The strategy for business assurance will be cognizant of the environments developed for preparedness and sustainability set forth by local and federal governments.

This bottom up approach to achieving a "Whole Community" resilience depends upon the cooperation, coordination and communication at the citizen, city and county level. In the United States, Presidential Preparedness Directive 8 (PPD-8) has been put forth as the future baseline for both private and public entities to adopt and implement going forward:

National Preparedness is aimed at strengthening the security and resilience of the Nation by preparing for the full range of 21st century risks that threaten national security, including weapons of mass destruction, cyber attacks, terrorism, pandemics, transnational threats and catastrophic natural disasters.

The National Preparedness System Description is the second deliverable required under Presidential Policy Directive (PPD) 8: National Preparedness. The National Preparedness System Description concisely describes current efforts and how we will build on those efforts, many of which are established in the Post-Katrina Emergency Management Reform Act and other statutes, to build, sustain and deliver the core capabilities needed to achieve the National Preparedness Goal.

Specifically, it identifies six components to improve national preparedness for a wide range of threats and hazards, such as acts of terrorism, cyber attacks, pandemics and catastrophic natural disasters. The system description explains how as a nation we will build on current efforts, many of which are already established in the law and have been in use for many years. These six components include:

  • Identifying and assessing risks;
  • Estimating capability requirements;
  • Building or sustaining capabilities;
  • Developing and implementing plans to deliver those capabilities;
  • Validating and monitoring progress made towards achieving the National Preparedness Goal; and
  • Reviewing and updating efforts to promote continuous improvement.

The six components can be internalized for the citizen, community and private sector to encompass into their own respective operational risk management strategy. The mechanisms for elevating situational awareness have improved dramatically over the years since 9/11. Citizens have prepared their own personal 72 hour kits, business organizations have created awareness programs for their members to heighten planning activities and local city and counties have trained thousands of volunteers for the Community Emergency Response Team (CERT).

This continues to get us so close to the goal and yet so far from really understanding the reality of where we are weak and where the single points of failure still remain. Think about it. How often has your household, community or business actually tested and exercised your ability to withstand a 72 hour crisis? The odds are you haven't and therefore all your planning and preparedness will never know where to improve and what resource investment is required to achieve greater degrees of safety, security and overall resilience.

Ten years after the 9/11 attacks, are our first responders prepared? A new report conducted by Capella University seeks to answer this question.

"To assess our preparedness for another disaster, Capella University partnered with leading national public service and public safety organizations, including the U.S. Council of the International Association of Emergency Managers, the American Public Health Association, the American Society for Public Administration, the Comprehensive Emergency Management Research Foundation, and the FBI National Academy Associates to conduct a nationwide survey of more than 1,000 public service and public safety professionals. We wanted to hear directly from those who would be on the front lines of the next crisis."

Key findings include:

  • 71% believe the United States is better prepared for a terrorist attack today than we were in the days before September 11, 2001.
  • 67% think the federal government and our leaders in Washington, DC, are not giving this issue enough attention.
  • 66% say their governor and state government leaders are not giving this issue enough attention.
  • 69% are worried that the United States will experience another major terrorist attack.

Regardless of the outcomes of this study, each community, state and region will be at a different degree of readiness. Your job, should you choose to accept it, is to figure out where your community is today and how to get to the next level:

  1. No Awareness
  2. Denial / Resistance
  3. Vague Awareness
  4. Preplanning
  5. Preparation
  6. Initiation
  7. Stabilization
  8. Confirmation / Expansion
  9. High Level of Community Ownership

Do you think that Houston is more prepared than Denver? Why or why not. Do you think Los Angeles is more prepared than Las Vegas? The degree to which an area has an ongoing perceived threat and vulnerability will in most cases dictate where they are on the 1-9 scale above.

Ultimately, the United States National Preparedness System’s ability to succeed, is based upon ensuring the whole community has the opportunity to contribute to its implementation to achieve the goal of a secure and resilient Nation. How often is the private sector the catalyst or the citizens community asking government to participate in their exercise, as opposed to the other way around?

31 December 2011

OPS Risk 2011: A Year of Living Dangerously...

2011 has been a year of living dangerously. Operational Risks have plagued governments, private sector companies and the citizens of local communities across the globe. The continuous threats from people, processes, systems and external events will become substantially more asymmetric in 2012 and volatility will become the new normal.

As professionals plan and budget for the next annual cycle there will be tremendous debate on where to invest in new mitigation and remediation strategies. The economics of austerity programs will now become another threat to consider as infrastructures continue to decay. People are leveraging the power of mobile devices to perpetuate their situational awareness and to wage "Information Warfare" on the brand equity of Fortune 500 companies. Verizon has followed the foot steps of Bank of America. Ylan Mui and the Washington Post explain:

Verizon backed away on Friday from plans to charge customers a $2 fee to pay their bills online or over the phone after receiving thousands of complaints, the latest victory in a wave of consumer activism that has roiled some of the nation’s largest companies.

The announcement came a day after the fee was made public. Consumer advocacy groups derided the charge as “pay-to-pay.” The fee also caught the eye of Verizon’s regulator, the Federal Communications Commission, which had said it would look into the issue. But it was individual consumers — amped up after battles this year with corporate giants such as Bank of America and Target — that the company said tipped the scale.


Corporate brand managers and CEO's have little tolerance to an erosion in brand equity. This is counter to the politicians who are continuously operating at an approval rating hovering at 50%. How different the behavior remains in the public vs. private sector. Look for this to change in 2012 as an election year takes hold in the United States.

The systemic impacts from failed banking institutions and nation states will not be under estimated any longer. Will the rise of democratic states in the Middle East increase the risk to your organization? Think about the new risks that are yet to be discovered as a result of the death of Usama bin Laden. al-Qa'ida's so called new American recruits suggests a pattern to be debated and includes:

  • Omar Hammami
  • Daniel Boyd
  • Carlos Bledsoe
  • David Headley
  • Michael Finton
  • Hosam Smadi
  • Betim Kaziu
  • Terek Mehanna
  • Jaime Paulin-Ramirez

Today's radicalization process is domestic to the U.S. and can take only months. It is decentralized and is taking place on the Internet, not in churches, synagogues, mosques or other locations of religious worship. The face of terrorism has morphed to people born in the USA, educated here and who have never left the homeland. They are invisible.

The number of supply-chain disruptions that have occurred over the course of 2011 is undetermined due to the sensitivity of the information and the implications to a business market share or stock price. Suffice it to say that the multi-headed hydra unleashed from the Macondo Gulf Oil Disaster is still being calculated even as new criminal charges are being considered by the Justice Department. Consider the possibility of some of the insurance industries scariest risks from Willis:

In the energy industry, the unthinkable has perhaps already happened: the $40 billion in losses associated with the Macondo well that blew out last year were utterly unprecedented. Most of that risk was uninsured, so the energy market got off relatively lightly in this case. But as the drive to drill wells similar to Macondo continues, the nightmare scenario for the energy market is the “perfect storm” of another blowout of a similar nature combined with a Gulf of Mexico windstorm on the scale of a Katrina, Rita or Ike. That would almost certainly lead to underwriting losses that would be sufficient to prompt a potential capacity crisis.

The point is that the attacks will continue and the defenses will never be high enough or wide enough to protect your assets from loss and harm. Then if this is the case, what have you planned for 2012 that will encompass the business resiliency doctrine? Who is your Chief Continuity Officer and how will they be investing in your continuous survival next year?

Operational Risks in 2012 will trend higher for organizations because there are decision makers who will continue to ignore the factors of resiliency. The mind set associated with resiliency takes the point of view that you will be attacked by cyber marauders, that your supply chain will suffer a catastrophe of epic proportions from a natural phenomenon, that you will suffer the consequences of a significant employee-based litigation. And the list goes on...

Which risk is scariest for your business?

  • Terrorism (14%)
  • Environmental Unknowns (8%)
  • Death of Innovation (8%)
  • Data Breach (8%)
  • Supply Chain Disruption (8%)
  • Not Understanding Risk (8%)
  • Italian Default (7%)
  • Chinese Pandemic (5%)
  • Exploding Health Care Costs (5%)
  • Macondo Mach II (5%)
  • Mass Real Estate Disruption (5%)
  • Systemic Risk (3%)
  • Coal-tastrophe (3%)
  • New Frontiers in Renewables (2%)
  • D&O Insolvency (2%)
  • Middle East Oil Prices (2%)
  • Blackout Britain (2%)
  • Aerospace Fuel Prices (2%)
  • Credit Price Hikes (0%)
  • Solvency II (0%)
  • Obstetrics (3%)
Finally, we want to thank you for raising this blog to the #2 link on Google when searching for Operational Risk and Operational Risk Management. We agree that Wikipedia should remain #1. In 2012, look for more topics and expanded investigative reporting. And one of these days, perhaps it will be time to create the best of our over 1,000+ posts to create an e-book for your Kindle.

17 December 2011

Integrity & Ethics: Whistleblower Risk...

Operational Risk Management in your organization may be in need of a more robust awareness campaign.  Malfeasance and ethical wrongdoing is continuously perpetuated in the workplace when those who are victims or witnesses refuse to speak up. Many fear the retaliation by supervisors or other co-workers. This study emphasizes the issue at hand:

Labaton Sucharow LLP yesterday announced the results of its nationwide Ethics & Action Survey. Conducted by ORC International between November 17-20, the survey questioned 1,000 Americans on their knowledge of wrongdoing in the workplace and willingness to come forward and report it. With significant financial rewards and strengthened anti-retaliation and anonymity protections offered under Dodd-Frank, an overwhelming 78% of respondents indicated they would report wrongdoing in the workplace if it could be done anonymously, without retaliation and result in a monetary award. In fact, more than one-third (34%) of respondents knew about wrongdoing in the workplace. However, 68% were unaware that the Securities and Exchange Commission (SEC) has a new Whistleblower Program designed to protect and reward individuals who report violations of the federal securities laws.

This kind of Operational Risk doesn't have to involve insider trading or the SEC to be an issue.  Do you have a controlling boss or a bully in the organization who uses their position of power to get what they want at any cost or to force you to look the other direction?  What kind of facts point to their behaviors and the actions by others that contribute to a caustic and toxic work place setting or to further perpetuate the situation?  Whether it is your Fortune 500 public company or your tiny 501(c)3 non-profit does not matter.  When over one-third of the respondents of the ORC Ethics and Action Survey knowingly ignore or are afraid to report incidents of wrongdoing or ethics violations the culture is broken and in need of repair.  The people who have the fiduciary duty to see that this kind of behavior is deterred also have the responsibility to provide the tools and the mechanism for those being victimized and those who are observing the malfeasance to anonymously defend themselves.

So what should you do as an Operational Risk professional to make sure this doesn't happen to the people in your respective organization?  Here is a good start:

Many corporations have internal compliance programs for corporate misconduct. These programs are, in theory, designed to provide an audience for workers who want to report unethical or illegal corporate conduct. Whether to utilize internal compliance reporting procedures is not an easy question to answer. As a general proposition, some believe that where the wrongdoing is pervasive—as in the case of securities fraud—an internal compliance program will not provide an adequate means of redress. Some believe that where the issue involves massive overbilling to the Government, or an allegation that a corporation is receiving significant dollars in unlawful revenue through fraudulent conduct, the internal compliance system will not work.

It's imperative that you also become aware of and communicate to employees and volunteers what their rights are outside the formal processes that are in place within the organization. Sometimes the nature of the ethics violations will not easily fall into the category for the internal compliance department.

So even "A Decade After the Fall of Enron" the laws and the rules provide us with a false sense of security from the corporate and workplace malfeasance that so many U.S. citizens are being subjected to on a daily basis.  And based upon the current-state-of-play around the beltway in Washington, DC you can expect that the coordination and cooperation is increasing by the minute.

The increased collaboration among the alphabet soup of enforcement and regulatory agencies is also due to a collateral effect of the current financial crisis: declining agency budgets. In the current downward budget cycle, agencies are working in concert more than ever before. This trend is exacerbated by a change in the mission of the FBI in the post-Sept. 11, 2001, world, shifting resources to counterterrorism and creating a need for other agencies to play an increased role. The overarching lesson from this increased collaboration is clear: Gone are the days that inside or in-house counsel can assume that the state or federal agency with whom they are dealing is acting alone; it is increasingly likely there are additional state or federal agencies involved, resulting in overlapping criminal, civil or regulatory exposure.

If you are charged with the position of the Senior Operational Risk professional in your organization, this topic of wrongdoing in the workplace can not be overlooked any longer.  It is not too late to create a "Defensible Standard of Care" and to turn the word "Integrity" into a cultural pursuit for all to aspire to, before it is too late.