Showing posts with label corporate governance. Show all posts
Showing posts with label corporate governance. Show all posts

Saturday, August 22, 2026

Innovation: Truth in Data Provenance...

For years mathematicians and computer scientists have written about the trustworthiness of “Data Provenance”.


Relying on the integrity of data collection, transport and of course the source of data is a real science.  Our modern day zeros and ones span all aspects of our lives and Operational Risk Management (ORM) professionals have encountered the questions surrounding trust and the process of decision making long before the invention of computing machines.


At the root of decision making with integrity the source of data is questioned.  The reliability and history of previous data from the source.  As the data was transported from Point A to Point B was there any possibility that the data was altered, modified or corrupted.


Couriers and the use of a "Hawala" type system have been used by traders and terrorists for hundreds of years.


"Truth in Data Provenance" is the question mark that enables trust decisions.  This is why modern day cryptography is at the center of so many arguments and debates, when it comes to the topic of trusted information.  Yet hundreds of years ago, long before telecom and ICT was invented, the trustworthiness of data provenance was a vital factor.  The use of transposition ciphers were in use by the ancient Greeks.


So what?  In 2026 what does the truth in data provenance have to do with our business commerce, our transportation, our banking, even our abilities as governments to maintain our defense against attack?


The topic is vast and deep and worth exploration at the top level of human decision-making.  Yes, it is vital that our computing machines have high-assurance data integrity, in order for our global systems to operate day-to-day.


Yet what impact does trusted information have with humans in an environment of work and daily collaboration?  How does truth in data provenance, affect our decision making and the environments we work in?


In a report by LRN, the subject of trust in the work environment as a motivator has become more apparent:


Another fascinating result of the study had to do with two squishy-sounding characteristics of a company: character and trust. Companies deemed by employees to have both strong character and inspired trust performed almost four times better, using the metrics mentioned earlier, than those that had other positive cultural attributes, such as collaboration and celebrating others. (This applied to all three types of companies, though, naturally, culture and trust were much more prevalent in the self-governing ones) What’s more, “high trust” organizations were 11 times as likely to be called more innovative than their competitors. Trust, the How Report suggests, is more important than virtually any other characteristic.

How organizations address the trustworthiness of data provenance is still a new frontier in this day and age.  The use of new sensors, sophisticated analysis of "Big Data" by computer algorithms (AI) and the pace at which new data is generated by the "Internet of Things" (IOT) makes this a significant area of focus for our current executives and enlightened organizational leadership.


Why?


But what does that really mean? How does one measure the absence or presence of something as abstract as trust? The How survey defines it as “a catalyst that enhances performance, binds people together, and shapes the way people relate to each other.” High trust groups encourage risk-taking, which in turn is what is necessary for true innovation to occur. When innovation fails, it’s because companies don’t put enough faith in employees to let them take risks. The industries with the highest amount of trust were “computers/electronics,” followed by “software/Internet.” Coming in last? Government.

At the most fundamental level, the culture you are operating in has all to do with the trust that exists or is absent.


It has all to do with the trustworthiness of data provenance.  Leadership in any organization, must see the relevance between trust and innovation.  Between innovation and risk-taking. 


Your future and your culture depends on it...

Saturday, August 15, 2026

Virtual Truth: False Information Risk...

How does "False Information" impact the risk to your organization? 


Decisions based upon faulty or inaccurate information is the root of many of the systemic failures of catastrophic history. The Titanic, Challenger Shuttle and Three Mile Island nuclear incident can all be attributed to the integrity of vital information.


Fast forward to the financial crisis and the past decades of consumer credit expansion strategies. What data have you been collecting from US consumers or clients about their personal identifiable information attributes?


The Information Age has drawn us into a more dangerous business operating environment as these digital assets have become another commodity to be sold in an international market place, to the highest bidder. Are you ready when the federal "Suits" or the local LEO's (Law Enforcement Officer) knock on your door in pursuit of the truth:


The Fair Credit Reporting Act (FCRA) spells out rights for victims of identity theft, as well as responsibilities for businesses. Identity theft victims are entitled to ask businesses for a copy of transaction records — such as applications for credit — relating to the theft of their identity. Indeed, victims can authorize law enforcement officers to get the records or ask that the business send a copy of the records directly to a law enforcement officer. The businesses covered by the law must provide copies of these records, free of charge, within 30 days of receiving the request for them in writing. This means that the law enforcement officials who ask for these records in writing may get them from your business without a subpoena, as long as they have the victim’s authorization.

The financial integrity of your future as a business and as a consumer is at stake. Christopher Burns brings this to light in a dramatic fashion in his book; Deadly Decisions:



"First, it is often extremely difficult to validate, corroborate, or verify the information we are dealing with, except by comparing it to the other information we are dealing with. And often the whole system is contaminated by misunderstanding, bad data and false assumptions that are hard to spot. The truth test rarely works. And second, the real issue of truth is not whether you or I should believe this or that, it is what we believe together. The truth that matters is group truth, and where we get into trouble is when a whole organization--a company, a community, a nation--starts to act on information that has been gathered from many sources and processed by many people but has come to contain significant elements that are false.”


Trusted Information is at the core of current global trading, business transactions and the fabric of our own personal identities. False information and knowledge is what creates operational risk factors that can change a whole company or the integrity of a whole nation.

Systems that comprise vast databases of "so called" trusted information are at our fingertips being utilized to make coherent and effective decisions. Yet what may be the more catastrophic Operational Risk beyond the simple stealing of information is the potential opportunity for the destruction of vital information.

The vulnerability of our institutions and the critical infrastructure of the United States economy is ever more at risk of a systemic loss. While our stolen data will continue to be sold to the highest bidder on a global platform for trading, the 4GW "Non-State" actors will change their modus operandi. This is a given.

Trusted Information systems that have certified integrity and the oversight controls to ensure the highest level of virtual truth is the "Holy Grail.”

The degree to which these same systems include false knowledge is our most complex problem for business and government in the next decade…

Sunday, July 26, 2026

Trust Decisions: Future Risk Architecture...

Leadership within the enterprise requires "Trust Decisions" that they can count on.  Operational Risk Officers have a fiduciary duty to provide top executives with the confidence that the data and information they provide is trusted.

So how do you assist any corporate leader, who has the responsibility and accountability to the Board of Directors to make informed and sound decisions?  The answer is, that it depends on how willing the CxO's in the enterprise are to engineer a "Trust Decision" model and framework for the business.

The truth is, most executive managers have their own way of doing this.  The process that the CEO makes decisions, is quite different from how the CFO makes decisions and the COO may have a documented and tested way to make their decisions.  The point is, that major "Trust Decisions" for the good and welfare of the enterprise are being made by people who are each doing it differently.  These human decision makers are relying on a number of ways to get to the final answer.  The decisions from leadership are not as trusted and reliable as they could be.

As an Operational Risk executive charged with making timely and correct decisions you have no choice but to have the tools and the trusted sources to enhance your situational awareness.  The safety and security of the facility, information or peoples lives are at stake.  That is why you test and continually improve the process so your analytics dashboard, intelligence feeds and data sensors are all operating with integrity and in real-time.

You are relying on information that changes by the nanosecond and a system designed to provide decision support.  Intelligence-led investigations or reacting to the latest incident requires systems designed and tested to support human "Trust Decisions."  Now back to the executive leadership and their process for decision-making.  What is it?  How does the CEO make the final decisions for the future wealth of the company and it's stakeholders?  Are they trustworthy?

Unless you have seen the "Trust Decision" process and trusted data framework engineered for your enterprise, then probably not.  Think about all of the leadership level projects and how they turned out.  How did executive leadership decide to buy that other company or merge with their favorite supplier?  What process did they use to ensure all of the due diligence data was correct?  Why are the sources of data trusted?

We have the opportunity to improve and to arrive at a point where we make "Trust Decisions" our priority and a prerequisite.  After all, our employees, customers, shareholders and even mankind deserve it.  The challenge begins.

Whenever you encounter your next major business decision with your CxO, ask them how they arrived at the decision.  Ask them to explain the process they used and the sources of trusted data they relied on.  Ask them why they think the architecture of the decision at hand, is the most sound and trusted decision that can be made with the time available.

You are now well on your way to better understanding the power and the future risk architecture of TrustDecisions.

Saturday, July 18, 2026

Asymmetric Warfare: Board Room to Battlefield...

The planet Earth is experiencing a multitude of historical and 21st century "Asymmetric Wars" from the Board Rooms of the Global 500, Internet Cafes of Third World countries and the Miranshah.

Operational Risk Management (ORM) doctrine will continue to be a factor:

a·sym·met·ric

  [ey-suh-me-trik, as-uh-]  Show IPA
adjective
1.
not identical on both sides of a central line;
"Asymmetric warfare" can describe a conflict in which the resources of two belligerents differ in essence and in the struggle, interact and attempt to exploit each other's characteristic weaknesses. Such struggles often involve strategies and tactics of unconventional warfare, the "weaker" combatants attempting to use strategy to offset deficiencies in quantity or quality.[1] Such strategies may not necessarily be militarized.[2] This is in contrast to symmetric warfare, where two powers have similar military power and resources and rely on tactics that are similar overall, differing only in details and execution.
The Irish Republican Army (IRA) perfected the car bomb against the British.  Now "Improvised Explosive Devices" (IED) and suicide bombers continue to be the single greatest threat to U.S. troops in Afghanistan as we withdrew and in Iraq as we engage once again. The Middle East has been embroiled in conflicts with the modern use of "Social Media" and an asymmetric rebel element to initiate change in labor laws or to overthrow a nation states leadership.

A laymen may not understand the relevance of "Asymmetric Warfare" on the corporate battlefield. Some would describe the age old tactic of industrial espionage, competitive intelligence or even patent litigation as a method for a small unknown company to gain an advantage over a much larger and established institution. This is a strategy of Asymmetric Warfare, nothing new.

In any case, the perception is that the small and agile still have the means, tools and tactics to defeat the large and overbearing with the benefit of time, resources and the will of the people.

So what are some good examples of modern day asymmetric conflicts:
  • Apple vs. Google
  • NATO vs. Putin
  • Sunni vs. Shiite
  • BMW vs. Jaguar
  • Earth vs. Anonymous
  • Taliban vs. Afghans
  • United States vs. Jones
Each of these represent a conflict between two able parties, regardless of the perception of who is the "David" and who is the "Goliath". So what can your organization or nations state do to prepare yourself for the inevitable risks that will be associated with doing business or operating your enterprise across countries and in hostile environments?

By providing your employees and stakeholders the best education, research, training and exercise programs; technology test and evaluation and capability improvement programs that your resources can offer.  Why?  In a few words, to make faster and more informed "Trust Decisions".

The desire to Deter, Detect, Defend and Document is prudent doctrine in Operational Risk Management (ORM). You may call these steps or tactics by other names in your particular process; such as Observe, Orient, Decide Act (OODA). What matters most is that the environment and landscape for the "Asymmetric Threats" and "Asymmetric Warfare" will continue to be challenging and dynamic.
BY ASSOCIATED PRESS June 16 2014
WASHINGTON — Judges around the country are grappling with the ripple effects of a 2-year-old Supreme Court ruling on GPS tracking, reaching conflicting conclusions on the case’s broader meaning and tackling unresolved questions that flare in a world where privacy and technology increasingly collide. 
The January 2012 opinion in United States v. Jones set constitutional boundaries for law enforcement’s use of GPS devices to track the whereabouts of criminal suspects. But the different legal rationales offered by the justices have left a muddled legal landscape for police and lower-court judges, who have struggled in the last two years with how and when to apply the decision — especially at a time when new technologies are developed at a faster rate than judicial opinions are issued. 
The result is that courts in different jurisdictions have reached different conclusions on similar issues, providing little uniformity for law enforcement and judges on core constitutional questions. Technological advancements are forcing the issue more and more, a development magnified by a heightened national debate over privacy versus surveillance and the disclosure of the National Security Agency’s bulk collection of Americans’ telephone records.

Saturday, July 11, 2026

Continuous Continuity (C2): Organizational Survivability...

The modern enterprise that effectively manages the myriad of potential threats to its people, processes, systems and critical infrastructures stands to be better equipped for sustained continuity. A Business Crisis and Continuity Management (BCCM) program is a dynamic change management initiative that requires dedicated resources, funding and auditing. Corporate Directors must scrutinize organizational survivability on a global basis. 

Corporate Directors are ultimately responsible for Continuous Continuity (C2) of the Enterprise and Organizational Survivability is a Board Room issue. 

Since effective BCCM analysis is a 24/7 operation, it takes a combination of factors across the organization to provide what one might call C2, or "Continuous Continuity". A one-time threat or risk assessment or even an annual look at what has changed across the enterprise is opening the door for a Board of Directors worst nightmare. These nightmares are "Loss Events" that could have been prevented or mitigated all together.

According to the risk management best practices from sources such as the Turnbull Report1 and specifically Principle 13 of the Basel II Capital Accord, the Board of Directors and corporate management are responsible for the effectiveness of the Business Crisis and Continuity Management of an organization.

Certainly the largest organizations realize that the external threats are taking on new and different forms than the standard fire, flood, earthquake and twister scenarios. These historically large catastrophic external loss events have been insured against and the premiums are substantial. 

What it is less easy to analyze from a threat perspective are the constantly changing landscapes and continuity postures of the internal facets of the organization having to do with people, processes and systems. 

Corporate Boards of Director’s are now being consistently subjected to regulatory scrutiny across the globe to ensure the continuity and survivability of the enterprise. It is their duty and responsibility to their shareholders to make sure this occurs on a continuous basis.

The world can only hope that our Global 500 companies are well on their way to achieving C2 already...

Saturday, March 28, 2026

CRMS: Mechanisms for Continuous Risk Monitoring...

Stryker, Lloyds Bank, European Commission, Fortinet and others have yet to announce their settlement with recent hacker and/or data breach law suits.


One of the systemic resilience problems at large institutions including large and global organizations like Stryker is keeping your finger on the pulse of "Risk Indicators”.


Unfortunately for SVP's and other CxO executives in the corporate hierarchy, your middle managers are creating the layer that impedes the best Early Warning System you have at your disposal.


When problems surface on the front line or in the "Cube City" down in Information Systems, the normal agenda is for the employee to go to their direct supervisor to raise the "Red Flag" or disclose the incident.


And the first behavioral response by the Middle Manager is to keep it quiet. Fix it before anyone else finds out. Keep it under wraps until damage control can be implemented.


When you are the head of Enterprise Risk Management, you need mechanisms to bypass and eradicate the barrier holding your intelligence, incidents and overall hunches for ransom.


There is no magic system or process that will solve it all. The only way to attempt at breaking through this layer of social and organizational dysfunction is to circumvent it.


A continuous risk monitoring system has to be implemented and operating anonymously 24/7 if the upper echelons of executive management are ever going to "Feel the Pulse" of true risk hotspots in the company.


These hotspots translate into human "Risk Indicators" from the sources themselves, people who know what's going wrong and know the truth.


A Continuous Risk Monitoring System (CRMS) is an automated human feedback and problem identification mechanism for detecting risks. It allows leaders of large organizations to quickly identify problems and incidents of all kinds in their company.


Call it a sophisticated whistle-blower system or suggestion box but that is exactly what it is, on steroids.


The ideal system would emulate communication patterns in small groups which is often a major ingredient in successful teams. It would also run on the existing computers and networks of the organization or from home by logging in via a trusted VPN.


The soldiers on the front line know what is going on far sooner than the commanders in the “Joint Operations Center” just as the employee or 3rd party supplier does and they need a way to communicate the issue, concern or threat in a rapid and efficient manner.


The system provides the executives with instant or trend based Intel that is actionable. It provides the "Insight" as well as the pertinent facts that you need to make quick effective decisions.


Think about how long it takes for data and relevant information to percolate and bubble up from the places in your organization that are considered "Current Risk Hot Spots”.


The point is that for far too long we have been playing the old telephone game. You know, the one that you played as a kid sitting around the kitchen table or on the floor in a circle.


One person starts and whispers into the ear of the person to their right. Just a sentence or two. By the time the message gets around to the 3rd or 4th person, now the data is dramatically different than the original. It's been interpreted, edited and sanitized.


Walk down the hall or pick up the phone and contact the person in person who is in charge of the corporate “Emergency Operations Plan (EOP)”, electronic suggestion box or corporate whistle-blower program at your institution.


Ask them for the most recent activity log.  Ask yourself how you could get this mechanism to perform better and then work with your front line to develop something that middle management can't filter, change or delete.


That is when you will be on your way to getting the real story, in more recent real time…


Monday, December 08, 2025

Linchpin: Trust in a Continuously Changing Environment...

In the early morning nautical twilight on a cold winter morning, thoughts about how the world is changing comes into clarity.  What do you believe in?

As the asymmetric threats seem to grow and our respective thoughts scan a vast Operational Risk landscape of people, processes, systems and external events; there is a mission worth pursuing.  It is a mission that is uncertain, full of unexpected change and potential catastrophes.

The outcomes that you seek will not always materialize as you wish, yet that is to be expected.  After all, what would an organization, state, region or country be like, without any substantial changes, unexpected events or new challenges?  You see, humans do not thrive in environments where behavior or events are 100% predictive.

We work best when there is a problem to solve, an environment or challenge that we can explore.  We can conquer or adapt to, in order to survive another day.  It is this ability to explore, to test, to solve problems that sets us apart from the current state of "Artificial Intelligence", for now.

Now, pivot your thoughts to the current ecosystem of people you encounter on a daily basis.  How does that environment change each day?  What mechanisms do you have in place to mitigate the risks that could create negative consequences and outcomes?  Think about all of the behaviors, tools and ways that you operate each day to deal with risks in your life.

The truth is, humans are curious and seek out risk.  Even if you get to a place where there is a perception that no risks are present, that no risks are over the horizon, we will look for new adventure, new learning and ways to adapt to a new environment.  So what really is the top priority for a parent, big brother/sister, manager, instructor, chief executive, commander or other organizational/constituent leader?

To create an environment of trust.  In a place where people have the ability to create the rules, teach the rules and operate within the rules.  Think about any environment where humans can't create the rules, or rely on the rules.  Where they are not effectively communicated or where people don't follow the rules.  Trust breaks down and uncertainty permeates our consciousness.  The decisions to trust become questionable.

Your goal, is to become a "Linchpin".  As Seth Godin has described in Linchpin:  Are you Indispensable?:
"Is there anyone in an organization who is absolutely irreplaceable?  Probably not.  But the most essential people are so difficult to replace, so risky to lose, and so valuable that they might as well be irreplaceable."
How many linchpins do you have on your team?  Guess what?  If everyone is so specialized, so vital and there is little or no backup and redundancy, you may have a single point of failure.  This is why as a linchpin, you need to be continuously training and teaching to be replaceable.  If you are not confident that you have done all you can do, to become replaced, then you as a linchpin have failed.  Your resilience factor is zero.

Your tasks will create more redundant linchpins and you shall create a consistent and highly trusted environment, physical or virtual.  A changing environment is inevitable.  Achieve a culture where trust is paramount and the team, class, cohort, company and community that creates the rules, communicates the rules, enforces the rules and follows the rules.

We as curious humans seek out unpredictable places, full of risk and simultaneously we wish the environment can be trusted?  Yes we do.

Onward!

Sunday, August 11, 2024

Volatility: Enemy #1...

Organizations implement Operational Risk solutions to lower "volatility" in earnings growth and return on capital. The focus on volatility is because no institution likes to see peaks and valleys in their earnings or their return on capital. A steady and consistent growth curve without "Volatility" is the goal by many steadfast organizations.

Contrary to the goal of minimized "volatility" there are also those who feed off of the chaos and the large swings between these highs and lows in the marketplace and with specific companies in vital sectors of the financial economy. Will a Blueprint for Regulatory Reform be the answer?

As a hedge fund investor, can you explain what the strategy is for your investment fund? Do you know what your money is being invested in? Does your hedge fund manager provide transparency on calculating your return on funds invested? What was the reason you invested in alternative investments to begin with?

Carrying this analogy to the operational processes within your organization, the goal is to keep the processes running smoothly. When people or systems deviate from the agreed upon "Rule Sets" then change ensues along with the volatility of the performance measures.

Errors, Omissions and systemic "glitches" are the catalysts to volatility that creates fear, uncertainty and doubt. Do you understand the Math? When the process gets to this stage and people don't trust the rules anymore, you are on the brink of a failure and impending loss, in dollars or peoples lives.

Operational Risk Management is a discipline that is emerging in corporate ranks because it has already proven that it saves lives. The regulators and inspector generals are going to demand it.

The "Rule Sets" of playing business in the financial, health care and energy sectors are not the only ones being subjected to this increased scrutiny and renewed focus on OPS Risk.

Lessons learned are being discussed in the ranks of the U.S. Treasury Department and the Department of Defense all relating to the failure of people, processes, systems and or external events.

Whether you utilize Operational Risk Management (ORM) in the Defense Industrial Base or in the Financial Services sector it's important to revisit what it is NOT:

Operational Risk is Not:

  • About avoiding risk
  • A safety only program
  • Limited to complex-high risk evolutions
  • A program -- but a process
  • Only for on-duty
  • Just for your boss
  • Just a planning tool
  • Automatic
  • Static
  • Difficult
  • Someone else’s job
  • A well kept secret
  • A fail-safe process
  • A bunch of checklists 
  • Just a bullet in a briefing guide
  • “TQL”
  • Going away

The goal of Risk Management is not to eliminate risk, but to manage risk so the mission can be accomplished with minimum impact. We manage risk to operate, not avoid risk as a means to prevent loss.

Operational Risk is all around us and now ready for prime time focus in terms of strategy execution, implementation and measurement...

Saturday, May 18, 2024

Trust Decisions: EO of ORM...

 In our most uncertain times over the past few years, it is again time to revisit several key factors of Operational Risk Management (ORM) within our Global Critical Infrastructure organizations.

Think of examples like Maersk or Boeing and UnitedHealth Group or Silicon Valley Bank.

Into the future, our Risk, Security and Controls personnel shall have equal power with the executives who are responsible for bringing in the revenue.

This means that the future power-base of the Sales and Marketing teams would need to also be on par with the Internal Audit, Security and Risk Management executives.

This internal culture shift is harder to achieve than one would think.

The ego's aside, the people who make it their job to worry about potential losses, look over the horizon and to mitigate risks day in and day out, are just not used to warning everyone each day to every alert, each instance or possible threats.

It is because everybody loves to hear that the business has been won, the competition defeated and the company just closed the biggest "Deal" in it's history. Let the spin doctors in Marcom get the Press Releases flying!

Not the doom and gloom.

It has been said before, the tone starts at the top.

The CEO and Board of Directors who are cognizant of the necessity for effective risk management objectives must also create a balanced power-base at the top to balance the "Revenue Generators" with the “Risk & Loss mitigators.”

So who are some of these people who deserve a greater exposure to this new born culture shift:

  • _Director of Information Security promoted to CISO. (Chief Information Security Officer)
  • _Director of Corporate Facilities to CSO. (Chief Security Officer)
  • _Director of Regulatory Affairs to CCO. (Chief Compliance Officer)
  • _Director of Privacy to CPO. (Chief Privacy Officer)
  • _Director of Human Resources to CHO. (Chief Humanity Officer)

If the CEO thinks that this is too many chiefs in the "C" Suite, then what about the idea of creating the:

Executive Office of Operational Risk Management (ORM)

This would be on par with the Chief Financial Officer and might even include the Chief Information Officer.

The new EO of ORM would now be on the same level of power with the EVP of Sales or Marketing and beyond the Chief Operations Officer (COO).

They would be laser focused on mitigating a spectrum of corporate threats, implementing relevant employee education and determining the true effectiveness of any organizational risk controls.

Just not so much on the effectiveness of sales incentives and corporate promotions or the uptime of corporate marketing processes.

So what does someone such as Sherron Watkins, the former VP of Corporate Development at Enron Corporation think the moral is?

You've been asked this one numerous times Sherron, I'm sure, but what's the moral of the story?

“Being an ethical person is more than knowing right from wrong. It is having the fortitude to do right even when there is much at stake.”

Friday, May 03, 2024

Reputation Risk: Is Murphy to Blame?

Any board member or executive today is well aware of the direct impact of an adverse event or significant business disruption can have on shareholder value and customer confidence. When it does happen, how many people just throw up their hands and shout, Murphy's Law!

"Murphy's Law ("If anything can go wrong, it will") was born at Edwards Air Force Base in 1949 at North Base.

It was named after Capt. Edward A. Murphy, an engineer working on Air Force Project MX981, (a project) designed to see how much sudden deceleration a person can stand in a crash."

Murphy is all about managing the "What if's" and planning for their possibility.

More than one business has been subjected to the Law's of Murphy whenever a complex and logistical project or program is underway.

If you are one of those corporate executives who has been unable to use your security badge the Monday after the big office move, you are not alone.

The question is not that it could happen, it's what impact will it have on employee satisfaction the day it happens, and beyond.

In your future planning to mitigate the Operational Risks associated with Murphy and your reputation, we are reminded of a few of our favorite Murphy's Laws:

1._Computer systems are unreliable, but humans are even more unreliable. Any system which depends on human reliability is unreliable.

2._If there is a possibility of several things going wrong the one that will cause the most damage will be the one to go wrong.

3._A difficult task will be halted near completion by one tiny, previously insignificant detail.

4._High speed chases will always proceed from an area of light traffic to an area of extremely heavy traffic.

5._Every emergency has three phases: PANIC... FEAR... REMORSE.

Do you think you're spending too much time with your team planning? You haven’t.

Success in your organization doesn't happen because everything goes according to the plan. It happens because you were prepared when things go wrong.

The organizations whose team has planned for every possible scenario and trained together in live simulations will become the most successful.

Their missions will be accomplished on time and within budget.

Incidents of different severity and frequency are happening around you and your organization every day.

Would your employees know what an incident looks like let alone know what to do next to mitigate the risk to them and the organization?

Friday, January 26, 2024

Operational Risk: Volatility of Change...

What is volatility and how could this be an operational risk in your particular institution or organization?


The threat of "Volatility" depends on what is being measured. The stock price. The return on capital. The key is that you want to reduce volatility in most cases.


It scares some people. Long term investors, employees and customers.


Volatility is the standard deviation of the change in value of a financial instrument with a specific time horizon. It is often used to quantify the risk of the instrument over that time period.


Who likes volatility?


Volatility is often viewed as a negative in that it represents uncertainty and risk.


However, volatility can be good in that if one shorts on the peaks, and buys on the lows one can make money, with greater money coming with greater volatility.


The possibility for money to be made via volatile markets is how short term market players like day traders make money, and is in contrast to the long term investment view of buy and hold.


So volatility is in the "eye of the beholder". The point is that some people thrive on it and others are better off with that smooth and predictable future.


Risk in a financial institution is defined in terms of earnings volatility. Earnings volatility creates the potential for loss. Losses, in turn, need to be funded, and it is the potential for loss that imposes a need for institutions to hold capital in reserve.


This capital provides a balance sheet cushion to absorb losses, without which an institution subjected to large (negative) earnings swings could become insolvent.


How much capital is allocated to Operational Risk is a measurement issue. The decisions an institution makes in managing Operational Risks is not risk versus return, but risk versus the cost it takes to avoid these threats.


The key determinant of an institutions risk factor against operational failures is not the amount of reserve capital, it is the performance of management.


In fact, in a few spectacular cases of operational failures, incremental capital would have made no difference to the firm's survivability. It comes back to strategy, safety, security and soundness.


How volatile are your earnings? At the end of the day the question is about management controls and measurement.  What if your measurements were not earnings, but the number of workplace accidents and acts of violence?



How effective are they at mitigating operational risks in the areas of the institution that can't be insured?


Look at places where "Change" is happening in huge volumes and at a rapid pace and you will know where to begin.