Showing posts with label Business Continuity (BC). Show all posts
Showing posts with label Business Continuity (BC). Show all posts

Thursday, April 19, 2018

Enterprise Risk Management (ERM)

Real risk management
Vs. Disaster recovery
& Business Continuity

ONE OF THE PROBLEMS WITH THE TERM “RISK MANAGEMENT” is that it means different things to different people.

For many. “risk management” means something related to insurance.

To others, “risk management” means patient safety.

To this scrivener, “risk management” should be prefaced with the word “enterprise” and it should include everything and anything that might impact “business as usual.”

ENTERPRISE RISK MANAGEMENT is more than “just” insurance, although it includes insurance as a way to mitigate loss due to a risk.

It also is more than “just” patient safety,” although in a medical environment patient safety should be a primary concern.

Enterprise risk management is the maturing of a process that started with Disaster Recovery (DR), a function associated solely with Information Technology (IT) or Management Information Systems (MIS). I got my start with DR on a data company’s national network.

DR morphed into Business Continuity, (BC). Business Continuity focused on an organization’s profit center(s) and what it took to keep the profit centers profitable. BC was primarily “within the confines of the organization’s building(s).” (Business Continuity in “government speak” is Continuation Of OPerations, COOP.)

The trouble with business continuity is that it failed to consider “I/O” – input and output.

Even organizations lacking product production – e.g., widgets, doo-hickies, and thingies of all types and shapes – still have I/O. Production facilities are more obvious candidates for enterprise risk management, but all organizations – even non-profits – need a viable (read “proven”) enterprise risk management plan.

Even charities need a plan. What happens if contributions dry up; how will commitments to clients be sustained?

Then there is image. The organization’s image can make or break it. In this day and age of “social” media, an organization is well advised to monitor what is being said about it.

Never forget regulators. EVERYTHING is regulated by some government or association somewhere. (OK, almost everything except the media, social and otherwise.)

Enterprise risk management is not nuclear science; it is “thinking outside the box” to identify ALL threats to “business as usual.” After the identification comes triage – which threats are most likely to occur. Then comes decisions to avoid (expensive) or mitigate the threats. Even if a threat is considered highly unlikely, the plan should include how to respond to it “in the event of.” Insurance may be part of the mitigation plan, but the policy must be c-a-r-e-f-u-l-l-y read and vetted by both an insurance adjuster (not associated with the insurer) and a lawyer who specializes in insurance.

    What type insurance to consider? Here are five broad categories: Business interruption, Directors and Officers, Liability, Physical hazards (fire, flood, etc.), Workers’ compensation. The list is NOT “all inclusive.”

One thing an enterprise risk management practitioner cannot be is an expert in all industries or even all organizations in one of the North American Industry Classification System (NAICS) classifications. (NAICS superseded the Standard Industrial Classification (SIC) system. It was developed jointly by the U.S. Economic Classification Policy Committee (ECPC), Statistics Canada , and Mexico's Instituto Nacional de Estadistica y Geografia , to allow for a high level of comparability in business statistics among the North American countries. 1)

The practitioner must
  • Have highly visible support from senior management
  • Work closely with Subject Matter Experts – the people who actually do the work
  • John Donne was spot on when he penned “No man is an island.”2. This is especially true with enterprise risk management.

    Finally, management must commit to both exercising the plan and maintaining the plan. Lack of either and the plan won’t be worth the paper on which it is printed. (Yes, Virginia, there should be a paper copy, “just in case.”)


    Sources

    1. http://tinyurl.com/yaoym7y2

    2. Complete poem at: http://tinyurl.com/yajdumzj

    PLAGIARISM is the act of appropriating the literary composition of another, or parts or passages of his writings, or the ideas or language of the same, and passing them off as the product of one’s own mind.

    Comments on Real risk management


    Tuesday, May 5, 2015

    ERM-BC-COOP:

    PwC (finally?) realizes
    Vendors are a real risk

     

    MY FAVORITE SOURCE of links to risk articles, Advisen FPN, pointed me to a PwC puff piece (it came via PR Newswire) titled Growing Use of Vendors Intensifies Risk of Business Interruption, According to PwC US.

    PwC, a/k/a PricewaterhouseCoopers LLP, tells us that

      As businesses increasingly rely on external parties for critical services, they become more vulnerable to business interruptions. This is especially true when such businesses know little about their third party vendors' resiliency and recovery capabilities, according to a new PwC US whitepaper, which examines the effects that vendor resiliency, or lack thereof, can have on an organization's business continuity strategy. Titled, Business continuity beyond company walls: When a crisis hits, will your vendors' resiliency match your own?, the PwC report also notes that risk becomes greater when the organization has a limited understanding of its own business interruption threats, resiliency status and recovery capabilities and strategies.

    I wonder if, coming from PwC, that basic information experienced risk management practitioners have been preaching for years - decades - will have some impact.

    According to PwC's report,

      (R)eliance on third parties is gaining momentum, and if companies lack insight into their critical vendors' resiliency and recovery capabilities, they run the risk of their own strategic goals being derailed. "Our clients are adjusting to the shift in global economic power and demographic shifts – two of the megatrends we identified – by increasing their use of strategic vendors to accelerate their global growth strategy and decrease time-to-market for their products and services. Along with the increase in strategic vendor reliance comes the need to more formally monitor vendor and other third party risks," said Brian Schwartz, PwC US Risk Assurance, Governance, Risk and Compliance leader.

      In order to protect against business interruption risks, companies should institute a business continuity management program that encompasses vendor risk by incorporating increased resiliency and rapid recovery. PwC outlines five steps to help companies look beyond their own walls and examine interruption risk among the vendors who provide support.

    While I would suggest that "reliance on third parties" is not gaining momentum, it is a fact of life for almost every organization; I cannot think of any that survives sans vendors. No man is an island, nor is any organization.

    Slowly, slowly business continuity practitioners are learning that limiting their search for risks "inside the building" is hardly sufficient. It could be compared to searching for hametz NB only in the kitchen while ignoring the dining room (and kids rooms).

    Business continuity must expand to become true ENTERPRISE Risk Management considering ALL risks from ALL areas - from incoming (raw materials, orders, payments, delivery systems) to outgoing (QA/QC, advertising/PR, delivery systems, customer financial well being,), and the items mentioned here are only the tip of the proverbial iceberg. (Add to that government regulations, taxes, and fees, competition, lenders, investors, and many, many more potential "got'chas.")

    Most practitioners have expanded out from behind the locked doors of IT/MIS to try to discover an organization's raison d'etre, but - unfortunately - many still are looking for risks only within the organization.

    As PwC now recognizes, as "businesses increasingly rely on external parties for critical services, they become more vulnerable to business interruptions."

    'Course you knew that.

     

    Note 1 Hametz - leavened food prohibited to Jews during Passover