ISO 31000 Risk Management (Part 2)

A second guest post on this topic by Karel Simpson, Corporate Risk Manager, GardaWorld. You can find part 1 here

Hopefully part 1 of my view on ISO 31000 has brought you back to look at part 2, albeit a little late in coming. In this part we are going to continue talking about the actual standard itself and then look to add a third part a little bit later down the line on what it all really means and not just a look at the standard.  This ensures these posts are kept hopefully short and sweet.

So if we now take the term risk, this is a term most people understand by the common definition of being known as the likelihood of harm being realised, normally shown as risk=  likelihood x severity.

ISO 31000 defines risk as ‘effect of uncertainty on objectives’; where an effect is a deviation from the expected and objectives having different aspects with examples stating financial, health and safety, and environmental goals.  This can be applied to different levels for example strategic, projects, products, processes or organisation wide. Although a different definition initially, the notes then talk about risk being categorised by reference to potential events and consequences or a combination of these and the associated likelihood.

Now I could try and list certain terms used in ISO 31000 as a blog post, it may however become long, boring and misses the point, so instead I will refer readers to the following website , http://www.praxiom.com/iso-31000-terms.htm,  which in plain English covers key terms of ISO 31000 .

The standard is focused on creating a framework for use, remember risk management is different to managing risks; see the first part on ISO 31000. A framework is the foundations and arrangements of the organisation.  It assists in the management of risks and ensures information about risk from the management processes is adequately reported and used as a basis for decision making and accountability.

To ensure a strong risk management approach exists and ensuring its on-going effectiveness requires a strong and sustained approach from management, combined with strategic and rigorous planning.  Part of this process should see management (4.2 Mandate and Commitment):

  • Define and endorse the risk management policy.
  • Ensure that the organisations culture and risk management policy are aligned.
  • Determine risk management performance indications that align with performance indicators of the organisation.
  • Align risk management objectives with the objectives and strategies of the organisation.
  • Ensure legal and regulatory compliance.
  • Assign accountabilities and responsibilities at appropriate levels within the organisation.
  • Ensure that the necessary resources are allocated to risk management.
  • Communicate the benefits of risk management to all stakeholders.
  • Ensure that the framework for risk continues to remain appropriate.

In establishing this framework it is vital to ensure that an evaluation is made of the organisation and its context in which to provide an understanding of the environments both internally and externally that you are trying to achieve your objectives within.  Once the context is established then the risk management framework can be established.

Within the risk management process itself, we will revert to the adoption of risk assessment, a term used throughout industry to a large scale and sometimes the results, formats and information can be of quantity and not quality.  The risk assessment is the process and means by which you are going to identify your risks and this will influence decision making, therefore it is important to get this right.

Within the risk assessment process is a simple approach involving

Risk Identification – the initial risks being identified

Risk Analysis – Analysing the specific risks, how they are presented, influencing factors etc

Risk Evaluation – Evaluating the risk and making a decision using the information gained through the analysis of the risk.

Risk Treatment – Decision time is here, are you going to tolerate the risk and accept it, decide to further control the risk with different risk treatment, avoiding the activity altogether or transfer part of the risk through using a third party or obtaining insurance against any potential losses.

Note that when it comes to making a decision on risk we talk about risk appetite. I could of course again ramble on this point but will once again point you in the direction of a website that I think sums it up quite well. Although I have never used this product and do not know the company, they summarise the risk appetite point very well in my viewpoint and in trying to sell their product provide some pointers along the way, see http://www.logicmanager.com/erm-software/knowledge-center/best-practice-articles/risk-appetite-risk-tolerance-residual-risk/.

The above is a summary of the risk treatment options and stages of the assessment without going too in depth and detailed. The risk assessment process and the risk decision making of course needs to be recorded to show the decisions being made. As with all risk based decisions, risk very rarely remains static and therefore reviews need to take place, it may be that a risk increases resulting in a business deciding to stop a specific activity until it reduces.  A perfect example of this is airline movements into certain countries being stopped due to the perceived risk to the passengers, airline, crew, reputation etc.

One point I will make and one that is often overlooked in the management of risk is ensuring that the workforce is both consulted in the risk decision or information feeds and that they participate in the risk assessment process, this will tend to bring about a better quality assessment.

Posted in ISO 31000, Risk & Assurance | Tagged , , , | 3 Comments

ISO 31000 Risk Management (Part 1)

Thanks to Karel Simpson for this guest post

ISO 31000 – Risk Management

This short article is an introduction towards a two part blog entry on the subject of the standard on risk management, ISO 31000.

Although the standard itself has been around for a few years now, it seems that the inclusion in the draft of ISO 9001 on risk management seems to have got people thinking and an interest in risk management in general.

I personally like some of the terminology used around the standard itself and the fact it describes ‘Risk Management’ as being the architecture for managing risk, it is the framework, principles to be applied and procedures. ‘Managing Risk’ is the implementation of this architecture.  I come across people who say that they conduct risk management and maybe get confused whereas they are really managing risk, although you can argue terminology does not matter I do believe a clear distinction is needed between them both, as everybody understands the need to manage risk but perhaps think risk management is someone else’s job to do. I hope that makes sense!

A key point that does frustrate and annoy me is the fact companies claim that they are certified to ISO 31000. Firstly this will not be a UKAS certification etc, secondly the standard is asset of principles and guidelines and most importantly the standard itself states that it is not for certification.

The next follow up posts, coming over the next few weeks will allow me the chance to explain a little bit more about the standard, although ISO 31000 does cover risks and identifies some generic processes that will allow organisations to move forward with their own risk management practices, it aims to encourage you to build your own framework for the management of risk.  In my next article I will look to give an oversight on the principles and framework involved for creating risk management practices in a business.

So why should you manage risk? Let’s finish off with some food for thought in what the standard states an organisation can be assisted towards when managing risk.

The management of risk, if following the standard can enable an organisation to

  • Increase the likelihood of achieving objectives
  • Encourage proactive management
  • Be aware of the need to identify and treat risk throughout the organisation
  • Improve the identification of opportunities and threats
  • Comply with relevant legal and regulatory requirements and internationals norms
  • Improve mandatory and voluntary reporting
  • Improve governance
  • Improve stakeholder confidence and trust
  • Establish a reliable basis for decision making and planning
  • Improve controls
  • Effectively allocate and use resources for risk treatment
  • Improve operational effectiveness and efficiency
  • Enhance health and safety performance, as well as environmental protection
  • Improve loss prevention and incident management
  • Minimise losses
  • Improve organisational learning
  • Improve organisational resilience

The standard intends to meet the needs of a wide range of stakeholders, including

  • Those responsible for developing risk management policy within their organisation
  • Those accountable for the ensuring that risk is effectively managed
  • Those who need to evaluate an organisations effectiveness in managing risk
  • Developers of standards, guides, procedures and codes of practice that (in whole or part) set out how risk is to be managed

It claims a lot can be achieved, what is this like in real practice….stay tuned for the future posts on this topic.

The ISO 31000 standard can be purchased and downloaded from the BSI website

Posted in ISO 31000, Risk & Assurance | Tagged , | 3 Comments

Upside risk?

We’ve discussed this topic briefly in the Capable People LinkedIn Discussion Group, while we examined the definition of “risk” that will apparently underpin ISO 9001:2015 – the effect of uncertainty on objectives. However I have never been 100% certain about what exactly is meant when “upside risks” are mentioned. I can have a view on it, as can others, but do we KNOW what the intent of that reference is?

Yesterday I saw a news report about BBC commissioning strategy that made me think again about it in a different way. The piece suggested the BBC should “take more risks”. The context was that playing safe in the commissioning of TV programs might not be the best thing to do. It was suggested that some of the more groundbreaking programs of recent times have initially been programs the BBC was not 100% sure about for one reason or another. Is THIS “upside risk” I asked myself? If it is, what are the practical implications when it comes to managing “upside risks”? Obviously the process for managing negative risks (risk assessment and risk treatment) is well established, but upside risks? An upside risk is something you’d like to transpire, and you may elect to take a punt on it, but can you control an upside risk? And if so, what would the structure for “upside risk treatment” look like?

My first thoughts are that it should encourage the organisation to understand the negative implications of “safe” or “risk averse” strategies. Nothing ventured, nothing gained in other words, and also maybe to have a really close look at what “tolerable risk” might be on a case by case basis. In business I do this all the time. I do take a few risks, and several have lost me time and money, however (by trial and error) I have been able to distill my own strategy (if you can call it that) into a few simple mantras;

  • never bet more than you can afford to lose
  • make sure you understand worst case scenario and can live with it
  • apply limits and stick to them

The thing is, in business especially, there are few certainties, and understanding the odds as well as you can is about as much as you can do. This actually brings me back to an article I wrote over 5 years ago about a conversation I had on a long haul flight with a professional gambler. Funny how things come full circle every now and then, isn’t it?

Posted in ISO 9000, Risk & Assurance | Tagged , , , | Leave a comment

My early thoughts on ISO 9001:2015 DIS

The draft international standard (DIS) of ISO 9001:2015 is available. CQI members can access it for free via the CQI website, it’s £25 otherwise. I’ve had a scan through it and a few things struck me.

First, I don’t think there is anything actually wrong with most of its new departures – I’ll pick out a few later in this post. There has been an attempt to make it more effective as a general QMS standard however it has, in the main, become more general (i.e. less specific). There are fewer mandatory documentary requirements and a focus more on what the management system should ACHIEVE rather than an attempt to dictate any prescriptive methods for achieving the outcome. In essence nothing wrong with that, but it does concern me. My main concern is based on past experience where the concept and the consequent reality have ended up being poles apart.

Auditor competence

The more specific you make something, the easier it is to break it into bite size components that either are or are not there. Prescriptive requirements are easier to audit and therefore require lower innate competence levels. A more flexible, less specific standard that focuses on outcomes and the appropriateness of non-prescribed controls requires a highly competent, thinking auditor.

Can you see where I am going with this?

A lot of auditors have been able to feign competence via a formulaic process. Take them one centimetre outside of their limits and you may as well have removed their lungs. How will they cope? My fear is that they will cope just fine, not by becoming competent, but because the standard will adopt some “customs and practices” that enable incompetents to get by. As an example, just look at how Preventative Action or Monitoring and Processes is audited now. They are roundly ignored as an inconvenience and nobody blinks an eye. Apparently “process based” management systems will now be mandatory. I’m sorry, but if that requirement can be ignored for 15 years, it can be ignored in the future.

The biggest worry for me is not so much the general auditor competences that will be required (they are required now, after all) it is the additional knowledge requirements. Various concepts are to be introduced such as;

  • Knowledge management
  • System design
  • Leadership

Exactly how are auditors to be determined as competent to assess these management system aspects? Knowledge management is a specialism in itself with its own concepts, methods and respected practitioners. It isn’t something you can simply self-declare expertise in, or work out for yourself. Same with system deign. Leadership, whilst important, is infamous for its inability to generate consensus. It is a topic awash with alternative theories and saturated with unfathomable uninformed opinion and drivel. Will this create a new breed of Armchair Tom Peters’? Probably.

Anyway, I’m concerned. Not so much with the shape and content of the emerging standard, but with what I fear will be the result. The race to the bottom will no doubt ultimately find where the bottom is, it always does.

The $10,000 question – Is it what purchasing organisations want?

The primary use of ISO 9001 and certification is to help purchasing organisations choose suppliers. Therefore the criteria of ISO 9001 should be aligned with attributes that are important to purchasers (the automotive, aerospace, pharma, oil & gas, manufacturers etc) and their supply chain. Unfortunately I have my doubts as to whether the changes that have been made have been influenced to a very high degree by the wants and needs of the main customer, and that makes me sad. Customer focus? Irony?

The FAQs so far

The IRCA recently ran a webinar on the ISO 9001:2015 story so far, including some FAQs

Posted in Auditing, ISO 9000 | Tagged , , , | Leave a comment

Auditing: Teach a Man to Think ….

I’m sure we’ve all heard the following phrase before

Give a man a fish and feed him for a day, teach a man to fish and feed him for life

Obviously it tries to summarise the principle that having a capability enables a person to be self sufficient. Just lately I’ve been thinking about auditing in exactly the same way. It may seem an obvious concept, but too often I see arguments in professional discussion groups that are simply not thought through. I see people trying to support a point by quoting facts, definitions, clause requirements and so on, often so far out of context it makes my mind boggle. People who just can’t seem to rationalise situations and circumstances – what made them that way?

Lately the IRCA has made some attempt to add weight to the development of thought processes and abilities in their course criteria. That means less weighting on memorising facts and definitions, and more scenario based testing. I think maybe the old systems are at least partly to blame for the levels of unconscious incompetence that I see too regularly. The old courses, and the old papers tested memory, and that is useful but only up to a point, because what good is factual knowledge without the ability to apply it? And can we even call factual knowledge that is not really understood knowledge at all?

I can only see the problem getting worse before it gets better, in QMS auditing at least. ISO 9001:2015 appears to be incorporating some quite reasonable aspects of context and management system flexibility. Good in one respect, but a nightmare for an auditor who can only audit by numbers. I’ll certainly be interested to see what will be the result of the new standard in the hands of incompetents, because I see that as being an inevitable outcome.

Posted in Auditing, IRCA | Tagged , , , , , , , | Leave a comment