SEARCH
Find what you need
Search this site
615 results found with an empty search
- Fighting Dragons using LEAN
In past presentations I have spoken on the topic of risk which of course meant we also talked about dragons. Dragons, metaphorically speaking, represent uncertainty in our endeavours that hinder and often thwart our adventures. In the real world uncertainty creates the opportunity for risk which if not addressed hinders or thwarts mission success. It should not come as any surprise that Implementing LEAN might have its share of dragons to contend with and overcome. In this article we explore the problem of why so many LEAN implementations end in failure. Although we will focus on the supply chain the problem of failed LEAN implementations crosses almost all domains where LEAN is used. There are many reasons why LEAN fails and there are many who have written about them. However, not many have talked about the root cause of these failures. That is why in this article we will be paying close attention to a specific dragon; one that hinders almost all LEAN implementations and probably yours. According to Eliyahu Goldratt (the author of Theory of Constraints) if we don’t contend with this dragon, we will never see the benefits of any of our LEAN initiatives. By finding this dragon I hope that we will find gold in learning what to avoid and what to pursue to successfully implement LEAN in our organizations. We know that hope is a wonderful thing but it is not an effective strategy against risk or dragons. Instead, we will use LEAN A3 problem solving and Theory of Constraints (TOC) as our guide to improve the chances of finding the dragon and the treasure that awaits us. In a manner of speaking, we are going to use LEAN to fight a dragon; the one responsible for causing so many LEAN initiatives to fail. At least that’s the plan. We have a lot of ground to cover (so too speak) so let’s start looking for this dragon. ROADMAP We will need a roadmap for our journey and for this we will use the LEAN A3 Process. Some of you might be familiar with A3 Problem Solving. It is simple method that is very effective applicable for problems small and large. Don’t worry if you haven’t’ seen A3 before. We will work through each part of the LEAN A3 process in detail starting with the definition of the problem. A3 - PROBLEM STATEMENT For A3 to work we need to first state our problem. This is perhaps the hardest part of the process with the greatest impact on failure if not done correctly. As has been said before, "A problem well-stated is a problem half solved." Not knowing the problem increases the certainty that whatever answers we come up will miss the mark. It is important to be clear what the problem is which in our case is this: 70% of LEAN implementations do not create value (i.e., benefits) which threatens mission success. Our dragon has been busy. The number of 70% is debatable but most people agree that many organizations struggle to apply LEAN successfully and receive real benefits. It seems that after the low hanging fruit has all been picked realizing any significant value from LEAN is few and far between. Perhaps, this resonates with some of you. Maybe you might be struggling with how to apply LEAN to improve your supply chain. We are going to look at the reasons why this might be. To do that we need to better understand the background to our problem. We need to answer the question of, “How did we get here?” A3 - BACKGROUND This leads us to the next step in the A3 process: BACKGROUND. Here we are looking to answer questions such as: Why is this topic important? What is the context of the problem? Why should our organization care about this situation and be motivated to participate in improving? Good questions that need good answers. SUPPLY CHAIN DISRUPTION Whatever has led organizations to consider LEAN in the past these reasons will mostly put aside as organizations all over the world contend with the ongoing effects of COVID-19. As a result of the current pandemic the supply chain has been disrupted more than it ever has in recent history. The following chart is from a study conducted by EY in 2021 on the top priorities that now face the supply chain: The top 5 include the need to: Increase efficiency Retrain / Re-skill workforce Increase visibility Increase responsiveness / resiliency Manage / reduce costs To address the top most priorities many organizations are looking to and doubling down on their LEAN initiatives. Applying LEAN around the edges of the supply chain with modest efficiency gains will not be enough to compete in a post pandemic world. THE STATUS OF LEAN LEAN has been adopted by many industries and is considered an important enabler to address the current and on-going supply chain issues. Unfortunately, the problem that is facing many is that they are struggling to receive any real benefits from their efforts which is putting their business at risk. Many are wondering which LEAN framework is best to use. Here are a few of the frameworks: Quality Strategies Lean TPS Lean Six Sigma Theory of Constraints Digitalization Agile Supply Chain Each of these have a different approach and a different goal. Knowing which one to use and how to leverage it to deliver real benefits are important questions that companies are attempting to answer. Having chosen a framework(s) the next question is where should it be applied to create a real impact on the supply chain? The following is Michael Porter’s value chain which we have extended to include risk & compliance components which also cut across the entire chain: You can consider this as a system of processes working together to create the desired outcomes for an organization. Knowing where and want to change is not trivial. It requires knowledge of dependancies and how things work overall. All too often there is no one that understands or has enough scope to sponsor system level changes across the entire chain. This leads to proximal and suboptimal improvements that do not contribute to value creation or value protection for that matter. Even when when changes are have been identified many organizations do not properly manage the change itself. Many focus only on the technical aspects of LEAN (i.e., tools) and ignore the people and process side of change as surprising as that might be. Steps needed to realize the benefits are seldom taken leaving much of the benefits to chance (another dragon indeed.) A3 – CURRENT CONDITION Now that we have a better idea of the context and why this is important we can move on to the next step in the A3 process: CURRENT CONDITION. Here we identify the situation right now in our organizations: How are things working today? What is contributing to our problem? What are the current LEAN capabilities to address the problem? Each company of course will have different answers to these questions. However, generally speaking there are two broad categories for how LEAN is working and what might be contributing to the problem we are trying to solve. OLD FACTORY MODEL The first category are organizations that are operating under the OLD FACTORY MODEL. This is a traditional, linear view of manufacturing. Value creation is measured by the difference between the price products or services are sold and the cost of making or delivering them. You can call this margin. To stay competitive these companies lower their prices while undergoing cost reduction programs by applying LEAN. This is a race to the bottom strategy. To win you need the lowest price and own the majority of the market. This approach however often leads to less value for the customer and fragility (the opposite of resilience) across the supply chain as most of the margins have been removed or greatly reduced. I am still shocked to find that many have eliminated their safety stock to further drive down costs. This creates vulnerabilities instead of value. This is the situation facing many LEAN implementations; the drive to the bottom. NEW FACTORY MODEL The second category are organizations that are operating under the NEW FACTORY MODEL. This model is based on seeing the supply chain as a network or hub. The goal of the NEW FACTORY MODEL is to continuously add new value for each customer. Apple and Amazon are good examples of how this is done. These companies focus on value creation activities as well as cost reduction programs but this time without losing value. Margins (and by this I mean value) get larger over time and organizations become more resilient (the opposite of fragility). This is called a race to the top strategy. Notice that LEAN is used as before but this time with a different strategy, purpose and a different outcome. LEAN is creating greater resiliency and value rather than fragility and loss. You might now start to get where I am heading and why LEAN projects fail and why they succeed. We are close to finding our dragon. A3 – GOAL / TARGET CONDITION The next step of the A3 process is to identify the goal or next target condition: What does success look like for LEAN implementation? What outcome are we expecting and for what reasons? Our goal is to have the majority of LEAN implementations create real value. Value realization is the measure of success. This is essential to create greater resiliency, better margins, improved visibility, and other outcomes for the supply chain. Even organizations that have efficient supply chains can still be noncompetitive. What is preventing us from achieving our goal of more successful implementations? A3 – ROOT CAUSE ANALYSIS This brings us to the root cause analysis step of A3 and where we hope to find our dragon at last. To achieve our goal we need to address the root cause or causes for why LEAN implementations are failing. The tool we will use is based on lessons from Eliyahu Goldratt based on Theory of Constraints (TOC). This starts with recognizing that LEAN is (among other things) primarily a technology. LEAN AS A TECHNOLOGY LEAN is no different from any other body of knowledge or know-how we apply to achieve some result or purpose. What Goldratt recognized and perhaps you have as well is that we are really bad at adopting new technology. But that is not the worst of it – we are worse at is exploiting new technology. And there-in lies the rub. Here lies our dragon. Eliyahu Goldratt proposes that: “Technology can bring benefit if, and only if, it diminishes a limitation.“ In our case, LEAN can deliver benefit if, and only if, it diminishes a limitation. Think about this for a moment. This is critical to what follows. We can imagine that our supply chain is operating at certain level of performance. We can change any part of the chain which may improve something. However, if this does not eliminate or vastly reduce a limitation, this change will have little effect on the supply chain as a whole. LEAN may eliminate waste, or variation, or achieve some other improvement but if it does not eliminate a limitation we will never see any real impact. This is why LEAN fails. This is our dragon. Are you getting this? THE POWER OF LEAN To better understand this important insight Goldratt developed four questions that if we answer carefully will uncover the gold that our dragon has been hoarding: What is the power of the new technology? What current limitation or barrier does the new technology eliminate or vastly reduce? What rules, patterns and behaviours are used today to bypass the limitation? (work arounds) What rules, patterns or behaviours should be adopted to benefit from the new technology? Let’s see how this is applied as we consider three scenarios: The Power of MRP (Materials Requirements Planning) The Power of LEAN TPS The Power of DESIGN THE POWER OF MRP In the 1980's many companies were adopting MRP (Material requirements planning) capabilities, the precursor to ERP. At that time it would take, let's say, 5 days to create a master production schedule (MPS) manually with a large department. As a result companies would only perform these calculations once a month. This meant that the orders needed to be frozen for the month; you couldn't make any changes until the next month. It also meant that manufacturing and shipping were organized around monthly cycles. This was the norm. With the introduction of MRP companies could calculate an MPS within a day. This was the power of MRP – it could perform calculations faster. Large departments to perform calculations were no longer needed so staff could be reduced. This was an improvement in efficiency and savings for many companies. This was the return of investment that most realized. However, some companies got more from their MRP implementation. What was the limitation before MRP? The limitation was that production schedules could only be updated once a month. What was the work around for this? What were the rules that were introduced by the limitation? The answer is that production and shipments were also done monthly. Some companies decided to change these rules. They started to calculate the MPS every week and some every day. What they also did was change their manufacturing and shipping rules to align with the increased frequency. This is one of the reasons why Amazon became a huge success. You can place an order today and have it delivered the next or even the same day. They exploited the power of MRP better than most companies. Same technology, better results. THE POWER OF LEAN TPS How about Taichii Ohno the father of Toyota Production System? Did he know about this dragon? You bet. In one of the books about Taichii Ohno there is a story about when he was assigned to address a problem in manufacturing where a line was not able to meet the demand. The line was producing, let's say, 50 cars per day and the demand was for 200. Good problem to have but also a very big problem for Toyota. So, what did Ohno do? He began to work with one of the workers to improve a work centre which they were able to eliminate entirely from the line. This improved cycle time and he now had a person to work on more improvements forming the first Kaizen Team. He continued this approach which further improved efficiency and increased the production to 75 cars per month. He also increased his Kaizen team to make even more improvements. Sounds like the beginnings of a virtuous cycle of continuous improvement. Now, you may be tempted to stop here. Many do but Ohno didn’t. The work around to the original limitations was building inventory in the line which he now exploited. While he continued to make improvements on LINE 1 he also reassigned workers that were no longer needed to start a second line. Others would have let these workers go and they would never realize the benefits from applying LEAN. By creating another line, production was increased to 200 cars per month meeting the market demand. All with the same number of workers Ohno started with. No wonder LEAN has transformed the automotive industry along with almost every other industry where companies have understood how to exploit the power of LEAN to realize real value. THE POWER OF DESIGN One more story. This one is a cautionary tale and why Eliyahu Goldratt added a 5th question. Let’s see if you can see why. In the book, Thinking in Systems by Donella H. Meadows, the author writes: Once upon a time, people raced sailboats not for millions of dollars or for national glory, but just for the fun of it. They raced the boats they already had for normal purposes, boats that were designed for fishing, or transporting goods, or sailing around on weekends. It quickly was observed that races are more interesting if the competitors are roughly equal in speed and maneuverability. So rules evolved, that defined various classes of boat by length, and sail area and other parameters, and that restricted races to competitors of the same class. Soon boats were designed not for normal sailing, but for winning races within the categories defined by the rules. They squeezed the last possible burst of speed out of a square inch of sail, or the lightest possible load out of a standard-sized rudder. These boats were strange-looking and strange-handling, not at all the sort of boat you would want to take out fishing or for a Sunday sail. As the races became more serious, the rules became stricter and the boat designs more bizarre. Now racing sailboats were extremely fast, highly responsive, and nearly unseaworthy. They need athletic and expert crews to manage them. No one would think of using an America's Cup yacht for any purpose other than racing within the rules. The boats are so optimized around the present rules that they have lost all resilience. Any change in the rules would render them useless. This may remind you of LEAN organizations that have an entire army of LEAN coaches, black belts, brown belts, yellow belts engaging in numerous Kaizen Events, Lean Six Sigma Projects, Rapid Improvement Events, and so on. These companies find that they too need LEAN athletes to effect change as the rules have become more complicated, and stricter. In many ways, these companies have become less agile, less resilient – more vulnerable to breaking when the business climate changes. In the words of Meadows, these companies have become nearly unseaworthy . Too much LEAN is also a thing and something to pay attention to. That is why we have another question: What new limitation, rules, or behaviours are introduced by the new technology? THE TREASURE IS FOUND We now have our dragon: LEAN can deliver benefit if, and only if, it diminishes a limitation. What treasure has the dragon been hoarding? LEAN implementations must eliminate or vastly reduce a limitation including the work arounds followed to bypass the limitation. New rules must be adopted to exploit the removal of this limitation. This is what creates real value and the benefits for the organization. From this we can identify the root causes along with countermeasures to formulate a plan for successful LEAN implementations: The counter measures include: Focus on the whole system and dependencies Eliminate or reduce a limitation Change the old rules after a change is made (eliminate the workarounds) Adopt new rules to exploit the diminished limitation Manage the change effectively (people, process, and technology) LEAN implementations that fail are those that fail to include these counter measures. A3 – IMPLEMENTATION Implementing countermeasures successfully requires a risk-adjusted plan. The following are the 5 Immutable Principles of Project Success created by Glen A Alleman: From these principles we have 5 questions that will help to develop a plan for success: What does DONE look like? How do we get there? Do we have enough time, resources, and money to get there? What impediments will we encounter along the way? (Yes there are always more dragons!) How do we know we are making progress? Answering these questions will help to ensure (make certain) that LEAN projects deliver the needed benefits. A3 – VERIFICATION / VALIDATION After the plan is completed it’s time to assess the results. There are two categories of assessments that are needed: Verification : Did we do what we said we would do? Validation : Did we get the outcomes (i.e., benefits) we intended: efficiency, breakthrough, or even unintended results? The A3 process is not complete until the targeted benefits have been obtained and followup actions have been identified. A3 - FOLLOW UP The last step of the A3 process is to identify next steps and capture lessons learned. Here is the completed A3 process that we have followed: While many, perhaps most, organizations experience marginal and incremental results from their LEAN implementations others have experienced breakthrough benefits. These organizations have taken the lessons of Eliyahu Goldratt and A3 Problem Solving to achieve much more than their peers with the same technology, but with better outcomes. If you want to learn more on the topic of LEAN and its use in the supply chain I recommend the following resources:
- You May Be Using The Wrong Compliance Software And Here's Why
Management systems are efficient at what they do, that is, doing the same thing the same way over and over again. What they tend not to be good at is change and improvement. What compliance needs most of all is the ability to improve and mature capability over time to advance compliance outcomes. This means change and this is something that management software often does not support very well. Many organizations chose software based only on improving efficiencies with respect to a fixed set of basic compliance requirements. These capabilities are often directed at the reactive side of compliance focused on reporting, audits and the collection of lagging indicators. Software applications and platforms in this space often do not support processes that allow you to be proactive as you improve towards higher standards, and better outcomes. The majority of regulations and industry standards are now performance and risk-based that require companies advance their capability maturity over time. Compliance systems must move beyond just focusing on improving efficiencies and instead support the capabilities leadership needs to improve effectiveness. Compliance technology must now support proactive as well as reactive processes. Modern compliance systems should include capabilities that support: Managing all obligations (mandatory and voluntary) Managing traceability of promises and commitments in support of accepted obligations Managing the alignment of organizational values with operational objectives Managing preventive and mitigatve measures to contend with uncertainty and risk Real-time monitoring of compliance status and capacities Discovery of insights to proactively stay in compliance and ahead of risk Learning and skill development to advance capabilities that advance compliance outcomes (safety, security, sustainability, quality, regulatory, ethical, etc.) Continuous improvement across measures of conformance, performance, effectiveness, and assurance. Support for front-view planning, management preview, pre-incident investigations, program pre-mortems, evaluate/elevate cycles, prevention and improvement, benefit realization. Organizations should not settle on software that only meets basic, reactive requirements. When it comes to meeting modern day obligations, there is more at stake than just saving money.
- The Power of Attention to Improve Compliance
Have you ever noticed how quickly things start to shape up when senior management turn their gaze to a particular corner of the company? It's almost like magic – suddenly, that chronically underperforming function or system is hitting targets, or that long-neglected process gets a much-needed overhaul. This phenomenon isn't just coincidence; it's the power of attention at work. Attention, particularly from senior management, acts as a powerful catalyst for change. When leaders focus on an area, several things happen: Resources are allocated : Time, money, and personnel are directed towards the area of focus. Accountability increases : People know they're being watched, so they step up their game. Innovation is encouraged : Fresh ideas are sought out and implemented to show progress. Priorities shift : The highlighted area becomes a top concern for everyone involved. This sudden influx of energy and resources often leads to rapid improvements. It's like shining a spotlight on a dusty corner – you can't help but notice what needs cleaning. But here's the million-dollar question: Is attention alone enough to sustain long-term improvement? The short answer is no. While attention is a great kick-starter, it's not a sustainable strategy for continuous improvement. Here's why: Attention is finite : Leaders can't focus on everything all the time. Eventually, their gaze will shift elsewhere. Quick fixes vs. systemic change : The pressure of attention often leads to band-aid solutions rather than addressing root causes. Burnout : Constant scrutiny can lead to stress and decreased morale over time. Dependency : Teams may become reliant on leadership attention to drive improvement, rather than developing their own initiative. So, what's the solution? How can businesses harness the power of attention while ensuring lasting improvement? Here are a few strategies: Develop robust systems : Create processes that maintain high standards even when leadership isn't watching. Foster a culture of continuous improvement : Encourage all employees to constantly seek ways to enhance their work. Implement regular check-ins : Schedule periodic reviews to maintain accountability without constant oversight. Empower middle managemen t: Equip them with the tools and authority to drive ongoing improvement in their areas. Celebrate and reward sustained excellence : Recognize long-term performance, not just short-term gains. Attention from senior management is indeed a powerful tool for driving improvement in business. However, it's most effective when used as a catalyst for creating self-sustaining systems of excellence. By combining the motivating power of attention with strategies for long-term success, businesses can achieve more than low hanging fruit, but also address root causes which lead to longer lasting improvement. What are your thoughts? Have you experienced the attention effect in your organization? How do you balance the need for leadership focus with sustainable improvement strategies?
- Latent Vulnerabilities and System Crashes: A Deeper Look at CrowdStrike's RCA
CrowdStrike recently published the results of a technical root cause analysis (RCA) stemming from the July 19th, 2024 incident that caused millions of computer system crashes worldwide. The report identifies several factors contributing to the incident and presents mitigative actions. It cites an out-of-bounds memory read leading to the failure of the EDR sensor, causing Windows operating systems to crash, as the root cause. The root cause analysis presents findings and remedies, which form the basis for actions now underway, as summarized in the RCA executive summary: Update Content Configuration System test procedures. This work has been completed. This includes upgraded tests for Template Type development, with automated tests for all existing Template Types. Template Types are part of the sensor and contain predefined fields for threat detection engineers to leverage in Rapid Response Content. Add additional deployment layers and acceptance checks for the Content Configuration System . This work has been completed with an updated deployment ring process, ensuring Template Instances pass successive deployment rings before rollout into production. Provide customers additional control over the deployment of Rapid Response Content updates . New capabilities have been implemented and deployed to our cloud that allow customers to control how Rapid Response Content is deployed, with additional functionality planned for the future. Prevent the creation of problematic Channel 291 files . Validation for the number of input fields has been implemented to prevent this issue from happening. Implement additional checks in the Content Validator. Additional checks are planned for release into production by August 19, 2024. Enhance bounds checking in the Content Interpreter for Rapid Response Content in Channel File 291 . Bounds checking was added on July 25, 2024, with general availability expected August 9, 2024. These fixes are being backported to all Windows sensor versions 7.11 and above through a sensor software hotfix release. Engage two independent third-party software security vendors to conduct further review of the Falcon sensor code and end-to-end quality control and release processes . This work has begun and will be ongoing as part of our focus on security and resilience by design. While these actions and the specific mitigative measures in the RCA report are important, they may not be sufficient. The reason? The root cause may not be purely technical. The Scope of the RCA Was Limited and Reductive The findings reported in the RCA only considered technical, proximal causes. Proximal (or first-order) causes are closest to the event and often don't provide sufficient explanation of what initiated the causal chain leading to the incident. Identifying the causal chain requires looking beyond first-order causes and considering non-technical factors. The analysis failed to answer: What were the prior conditions or actions that created the opportunity for an unmitigated high-risk software change to be deployed to customers? This question can only be answered by taking a systems perspective that includes both technical and non-technical factors. Based on what has been reported, this comprehensive analysis has yet to be conducted. The Root Cause Was Likely Not Technical A statement from the report offers a clue about the nature of the root cause and why the primary cause may not be purely technical: "In summary, it was the confluence of these issues that resulted in a system crash: the mismatch between the 21 inputs validated by the Content Validator versus the 20 provided to the Content Interpreter, the latent [emphasis added] out-of-bounds read issue in the Content Interpreter, and the lack of a specific test for non-wildcard matching criteria in the 21st field." The word "LATENT" stands out. The vulnerability that led to the incident already existed, lying dormant and waiting for a software change to expose it. This form of risk propagation, proposed by James Reason and illustrated by the well-known Swiss cheese model, is not new. Studies of other complex systems have shown that the greatest risk is usually not a failure in a single component, but rather the existence of smaller latent vulnerabilities that, as a result of ongoing changes, align to allow risk to materialize. This raises further questions: What other latent vulnerabilities reside within the software? What future changes will cause these latent risks to breach the defenses? What is causing the vulnerabilities to be introduced in the first place? Why was the software change process ineffective at identifying and mitigating potential risks? The last question suggests an alternative root cause: A failure to effectively handle risk due to planned software changes. A Software Engineering Failure In high-risk sectors such as chemical processing, nuclear energy, and medical devices, safety is paramount, and change is considered a significant source of risk. That's why managing change is regulated to ensure organizations take necessary steps to protect the public, employees, assets, and the environment. It's also why we have process, safety, industrial, and quality engineers to design safety into system processes and ensure it is managed effectively throughout the life-cycle of facilities, products, or services. What appears to be missing is this same level of concern for safety in software engineering and in particular with respect to this incident. The Need to Dig Deeper While the out-of-bounds read error may have caused the sensor failure, there is an argument to be made that it may not be the root cause. To discover the true root cause, we must look beyond technical considerations and proximal causes. We need to dig deeper into the systems that create conditions for vulnerabilities to emerge and lie dormant, waiting for future changes to expose them. There is much to learn from other high-risk domains that can be applied to the practice of software development. However, this knowledge can only be effectively implemented when the real root causes are uncovered. Only then will preventive and mitigative risk measures be truly effective.
- Beyond Balance: Sustainability as a Legacy of Sacrifice and Investment
Sustainability is often defined as fulfilling current needs without jeopardizing future generations' ability to do the same. In simpler terms, we should not sacrifice the future for short-term gains. However, I believe this definition is incomplete. We must also acknowledge another truth which we learned from our parents, many of whom sacrificed their present needs so that their children could thrive in the future. Interestingly, rather than viewing this as a loss, they counted it as gain. True sustainability is not only about striving for a balance between short-term and long-term objectives. It also involves making an investment: exchanging something of value for something of greater value. This perspective challenges us to rethink our approach to sustainability. It's not just about preserving resources for the future, but also about actively investing in it. Our parents' generation understood this intuitively, making sacrifices that they saw as investments in their children's futures. This expanded view of sustainability invites us to reconsider our approach to global challenges. It suggests that true sustainability isn't just about maintaining a delicate balance or preserving what we have. Instead, it's about making deliberate choices to improve our collective future, even if it means short-term sacrifices. Finding balance is a necessary part of sustainability. However, addressing the most pressing environmental, social, and economic issues will require sacrifice in the present. We should not view this as a loss, but rather as an investment in our future well-being.
- Delivering on the Promise: Compliance Through Performance
Organizations face a complex landscape of regulatory, ethical, and stakeholder expectations. These obligations, both explicit and implicit, shape the operational environment. To thrive, organizations must translate these obligations into tangible commitments or promises. However, true success lies in delivering on these promises, ensuring compliance and building trust. Compliance performance is the bridge between commitments and expectations. By carefully tracking performance against promises – a measure of integrity – organizations gain valuable insights to predict and mitigate risks. This proactive approach is essential for navigating a dynamic regulatory landscape and exceeding stakeholder expectations. Obligations (must happen): serve as the foundational elements, shaping the organization's operational and compliance landscape. They directly influence the promises and commitments that are made. Promises (plan to happen) : are operationalizations of obligations, transforming compliance requirements into concrete actions and commitments. They directly contribute to prediction by providing specific targets and benchmarks. Predictions (forecast to happen): are informed by the performance of promise keeping (integrity). By analyzing historical performance against these parameters, organizations can forecast potential risks and opportunities in meeting obligations. Expectations (should happen) : influenced from obligations are often amplified or modified by predicted performance. The interplay of obligations, promises, and performance is a continuous cycle. As the external environment evolves, organizations must adapt their promises to align with changing obligations. By mastering this dynamic, businesses not only meet compliance requirements but also create sustainable value and build a strong reputation.
- Using Dependency Structure Matrix (DSM) to Improve Compliance
When it comes to compliance alignment we need to have answers to the following two questions: 1. How do compliance pillars (programs) depend on each other? 2. How do business functions contribute to meeting pillar obligations? For the first we use a compliance pillar Dependency Structure Matrix (DSM). Each pillar will have a PDP (Policy Deployment Plan (for example, there will be one for safety, security, and so on.) What we want to know is how each pillar depends on any of the others to fulfill their commitments. For example, How much does security support safety? If you ever wondered how to get more than the sum of your compliance parts, this is how you do it. For the second question we do the same analysis across functional groups. Again, each function will have their own PDP consisting of their promises for each of the compliance pillars. What we are evaluating is each function’s contribution to overall safety, security, and so on. Knowing this information will help you prioritize your efforts to cover all your obligations as well as strengthen pillars and/or functions where compliance risk is the greatest.
- Catching Up to Compliance
“We need to move beyond compliance.” I used to think that moving beyond compliance was the answer. Many others did too. It seemed like the obvious next step. But after thinking more carefully over the last 10 years, I've realized that's not the solution. In fact, it could make things worse. When we say, “we need to move beyond compliance” where exactly do we need to move to? This is where the rub lies, and what's bothered me. Let me explain. Traditionally, we've viewed compliance through a narrow lens: ensuring adherence to prescriptive rules imposed by law. While it's essential to meet these obligations, it’s also limiting. It implies that compliance is merely a hurdle to clear or a box to check, rather than a cornerstone of responsible business. While many still view compliance using this narrow lens, the reality is the landscape has changed. Compliance has and continues to expand to encompass a broader spectrum of responsibilities. ISO 37301, for example, defines compliance as fulfilling all obligations, both mandatory and voluntary – those that are compelled by law and others we voluntarily decide to adopt. This definition recognizes that businesses have a duty to operate ethically and sustainably, beyond what the law requires. However, what this means is that: We don’t need to move beyond compliance. We need to catch up to where compliance now is. This does require going beyond “basic compliance” – adhering to legal requirements – towards “total compliance” – fulfilling all obligations, including those imposed by ethical and beneficial motivations. This is the next step, motivated by a genuine commitment to doing what's needed to meet all obligations, not just the basics. It's about assurance that organizations will keep the promises they have made. In fact, on a daily basis, catching up to compliance would look like a continuous process of making and keeping promises (a measure of integrity) associated with organizational, project, and operational obligations: Macro-ends (outcome-based) - outcomes, values, code of ethics, duties & liabilities Micro-ends (performance-based) - targets, key results, outputs Macro-means (management-based) - management standards, plans, processes Micro-means (prescriptive) - design standards (codes), rules, tasks, work instructions, procedures Instead of moving beyond compliance, let’s instead strive to keep our promises.
- Isn't Lean Compliance the same as Lean Six Sigma?
I've been asked this question several times, so I thought I'd share my answer here: The short answer is no. The longer answer is that Lean Compliance is a new practice area of Lean specifically for compliance, created in 2017 by Raimund Laqua, PMP, P.Eng. (Founder and Chief Compliance Engineer at Lean Compliance Consulting, Inc.). Lean Compliance is a methodology designed to overcome the challenges introduced by old-factory thinking, reactive behaviours, and traditional training, inspection, and audits as the means to ensure obligations are met. The Lean Compliance approach helps organizations eliminate compliance waste, leverage existing talent and capabilities, adopt proactive behaviours, establish operational programs and systems, and engage in continuous improvement to establish a virtuous cycle that effectively contends with modern-day risk, performance, and outcome-based obligations. While the practice of Lean Compliance is new, many of its principles come from existing areas of practice, including Lean Management, Lean Startup, Lean TPS, Engineering, Systems Thinking, Cybernetics, Promise Theory, Uncertainty and Risk Management, Performance Management, and Ethics. This may seem overwhelming; however, so is designing a car. That’s why we have engineers! The good news is that driving a car is much easier and something everyone can learn. It is this reason that we created "The Proactive Certainty Program." This is a four-step process that every organization can easily adopt to transform compliance from procedural or paper-based compliance to operational compliance using the principles of Lean Compliance. The question you need to answer is: Are you ready to learn to drive compliance towards better outcomes?
- Who Decides?
Historically, the responsibility of decision-making has predominantly fallen upon humans. However, with the rapid evolution of artificial intelligence, the landscape has shifted, and decisions are now frequently made by machines. Here are examples of questions that need to be answered? Should autonomous decision-making determine what is safe? Should it make decisions within what is already determined as being safe? When should human oversight and intervention occur? How much uncertainty is necessary and risk before this is needed? How should the use of AI be governed when used in safety devices or as part of a safety component? This poses a fundamental question: which decisions are appropriate for computers to make, and by what standards should these by governed? In this article, we will examine the use of decision support systems (DSS) and their role in decision-making, including their ability to function as autonomous decision makers. Furthermore, we will explore the implications of this shift on organizational compliance for entities that opt to utilize this technology. Decision Support Systems Decision Support Systems (DSS) are a class of information systems that help individuals or organizations make choices by providing relevant data and models to facilitate analysis, visualization, and interpretation of information. The ultimate goal of a DSS is to support decision-making processes by providing users with the necessary information and insights to make informed decisions based on a variety of criteria, such as cost, risk, efficiency, and effectiveness. DSS typically includes software tools, techniques, and models that enable users to access and analyze data from different sources, perform “what-if” analyses, create scenarios, and generate reports. Examples of decision support systems include financial planning software, inventory management systems, and supply chain optimization tools. How Have DSS Changed? Decision support systems (DSS) have been enhanced in recent years by the integration of artificial intelligence (AI) technologies. AI-enabled DSS can provide more accurate and personalized recommendations, improve decision-making speed, and reduce human errors. Here are some of the ways AI have improved DSS: Automated Data Analysis : AI algorithms can automatically process large volumes of data and identify patterns, trends, and anomalies that may be overlooked by human analysts. This capability can help users make more informed decisions by providing them with accurate and timely information. Personalized Recommendations : AI-enabled DSS can provide personalized recommendations based on an individual user's preferences and past behaviors. This approach can improve decision-making outcomes by tailoring the suggestions to the specific needs of each user. Predictive Analytics : AI-powered DSS can perform predictive analytics to anticipate future trends, events, and outcomes. This can help users identify potential risks and opportunities and adjust their decisions accordingly. Natural Language Processing : AI algorithms can understand and interpret natural language inputs, such as text or speech. This capability can improve user experience by enabling them to interact with the DSS in a more natural and intuitive way. Machine Learning : AI-enabled DSS can use machine learning algorithms to improve the accuracy of its predictions and recommendations over time. The system can learn from its past decisions and outcomes and adjust its models and parameters to optimize its performance. AI technologies have transformed decision support systems by enhancing their accuracy, speed, and personalization. This evolution has enabled organizations and individuals to make better-informed decisions, improve their efficiency, and gain a competitive advantage. However, DSS now have something else to offer – the possibility of autonomous decision-making. Autonomous Decision-Making Decision support and autonomous decision-making are both capabilities to assist with decision-making processes. However, they differ in their level of automation and human involvement. Decision support, including those enhanced by AI, focus on supporting decision making rather than making decisions. Decision support systems typically require human input to generate recommended decisions. The ultimate decision-making power remains with the human user, who can choose to accept, reject or modify the recommendations generated by the DSS. On the other hand, autonomous decision-making involves the use of artificial intelligence algorithms to make decisions automatically without human intervention. The AI algorithms analyze data, learn from patterns, and generate decisions based on this analysis. The decision-making process is entirely automated, with no human input required. Here are some advantages and disadvantages of decision support systems (DSS) and autonomous decision making using AI: Advantages of Decision Support Systems (DSS): Improved decision-making : DSS can provide decision-makers with access to more comprehensive and accurate data. This can improve the quality of decision-making and help organizations make more informed decisions. Speed and efficiency : DSS can automate the process of data analysis and provide real-time decision support. This can help organizations make faster and more efficient decisions. Flexibility: DSS can be designed to meet the specific needs of an organization or department. This means that decision-makers can customize the system to address their unique needs. Disadvantages of Decision Support Systems (DSS): Complexity : DSS can be complex and difficult to use, requiring specialized knowledge and training. This can make it challenging for non-experts to use the system effectively. Dependence on data quality : DSS rely on data quality to generate accurate recommendations. If the data used by the system is flawed or incomplete, it can lead to inaccurate or biased results. Limited scope : DSS are designed to provide decision support for specific tasks or processes. This means that they may not be effective for more complex decision-making processes. Advantages of Autonomous Decision-Making using AI: Speed and efficiency: AI can analyze data at a much faster rate than humans, allowing for faster decision-making and improved efficiency. Consistency : AI algorithms can make decisions consistently, without the variability that can come with human decision-making. Scalability : AI can handle large volumes of data, making it an effective tool for organizations dealing with big data. Disadvantages of Autonomous Decision Making using AI: Lack of human oversight: AI systems can make decisions (an act on them) without human input, leading to potential biases or errors. Dependence on data quality: Like DSS, AI systems rely on data quality to generate accurate results. If the data used is flawed or incomplete, it can lead to inaccurate or biased results. Complexity: AI algorithms can be complex and difficult to understand, making it challenging for non-experts to use or interpret the results. While DSS and autonomous decision-making have their own advantages and disadvantages, it is important for organizations to carefully consider their needs and goals before implementing these systems. Additionally, it is crucial to ensure the accuracy and integrity of the data used in decision-making processes, regardless of the system used. What Impact Does Autonomous Decision-Making have on Compliance? Autonomous decision making using AI can have both positive and negative impacts on compliance, depending on how the technology is implemented and monitored. On the positive side, AI-enabled autonomous decision-making systems can help organizations improve compliance by: Reducing Bias : AI algorithms can make decisions based on objective data and criteria, which can reduce the impact of human biases that may lead to non-compliant actions. Enhancing Accuracy: AI-powered systems can process large volumes of data and analyze it accurately and consistently, which can help organizations identify potential compliance issues and take corrective actions quickly. Improving Efficiency: AI systems can automate routine compliance tasks, such as monitoring and reporting, which can reduce the workload of compliance staff and improve their productivity. Enabling Predictive Compliance : AI can analyze historical data and identify patterns and trends that may indicate future compliance risks. This approach can help organizations anticipate potential compliance issues and take preventive actions before they occur. However, there are also potential risks and challenges associated with the use of autonomous decision-making systems in compliance: Lack of Human Oversight: Autonomous systems may make decisions that violate ethical or legal standards if not adequately monitored by human experts. Therefore, organizations must ensure that human oversight and control mechanisms are in place to avoid such risks. Limited Transparency: The use of complex AI algorithms can make it difficult for compliance staff and external regulators to understand how decisions are made. Lack of transparency can undermine trust and confidence in the system and raise compliance risks. Unintended Consequences : Autonomous systems can generate unexpected results that may lead to unintended consequences that violate ethical or legal standards. Therefore, organizations must ensure that their systems are designed to anticipate and mitigate such risks. While autonomous decision-making using AI can help improve compliance, it is critical to balance the potential benefits with the potential risks and challenges. Organizations must ensure that their systems are transparent, explainable, and subject to appropriate human oversight and control mechanisms to achieve the desired outcomes. Not My Final Thoughts When making decisions, and more importantly acting on them, involving uncertainty where people, public, or the environment may be at risk, it becomes a moral imperative. It is up to humans to determine what level of safety is acceptable and what risks are tolerable, not machines. Therefore, it is the responsibility of humans to establish the parameters within which AI operates, including the acceptable level of risk. This ultimately holds people accountable for the outcomes of their decisions, a responsibility that machines are unable to fulfill, regardless of its level of "intelligence". Where does the science experiment end and responsible engineering begin? The idea of unsupervised or autonomous decision-making by AI systems promotes a use where decisions can step outside the lines and create risk. To provide assurance that organizations stay within appropriate boundaries, they must ensure that their employees, as well as their systems (including AI), are operating ethically and within regulatory frameworks. Perhaps, the risk is not so much in making decisions but on deciding which ones to act on which should probably be left to humans to decide particularly when the things we care about are at risk. What do you think?
- Compliance 1 and 2
Many organizations begin meeting compliance obligations using Compliance 1 practices. These are founded on basic capabilities that are mostly reactive in nature focused on meeting prescriptive regulatory requirements. Compliance is added "on top" of what is already happening. The hope is that this will be enough to satisfy external regulators and maintain a regulatory license to operate. While this is how most start it is not the way compliance should continue. Obligations today have expanded beyond regulatory prescription to encompass a broader set of commitments. Many of these are risk-based focused on performance and advancing outcomes such as net zero emissions, zero incidents, and so on. These have more to do with providing legitimacy for a social license rather than strictly regulatory adherence. To contend with these broader obligations many organizations scale up their compliance by doubling down on their existing practices. Unfortunately, Compliance 1 practices lack the capability to provide the assurance that stakeholders require. Today's compliance challenges requires proactive and systems capabilities that integrate with the business and not just sit on top of it. It also has to contend with uncertainty and risk. We call this Compliance 2 which compared with Compliance 1 is analogous to the difference between total quality management (TQM) and quality control & assurance (QC/QA), or Safety 1 and Safety 2 from the safety domain. Adopting Compliance 2 requires establishing processes to define the lines followed by the operational capabilities to stay within them. Operational compliance is responsible to implement these capabilities and processes. The internal audit function still has a role under Compliance 2. However, auditing now focuses on evaluating effectiveness as measured against compliance outcomes. This will include evaluating the level of compliance and operational risk. If you are ready to elevate your compliance consider joining The Proactive Certainty Program™
- How Your Business's Digital Twin Empowers Real-Time Compliance
Many of you may be familiar with the concept of digital twins in futuristic factories, but what if I told you your business is already building one, right now? The truth is, every company, from the corner bakery to the global conglomerate, is accumulating a powerful – and often unrecognized – tool: its digital twin. Imagine this: a vast collection of data – customer interactions, sales figures, website clicks. Valuable information, certainly, but without context, it's akin to a disorganized warehouse. This is where the current landscape is changing. In today's hyper-instrumented world, every click, transaction, and interaction is captured, generating a mountain of data. Yet, without proper organization, it becomes overwhelming and unusable. That's where meta data steps in. This isn't about your customers; it's about your internal operations – the processes, systems, and the flow of information that make your business tick. Think of it as the labelling system for your digital world, creating the opportunity for real-time intelligence as well as compliance. By meticulously building a robust foundation of meta data, you're essentially creating a digital replica of your business – a digital twin. This unseen partner unlocks a game-changer for compliance: real-time assurance. The digital twin serves as your "golden thread" of compliance. It's a continuously updated digital record that tracks evidence, your commitments (regulations!), and ultimately, your obligations. Imagine a clear audit trail readily available at your fingertips. No more waiting for audits to find out that you are off-side and at risk. But the power goes beyond simple record keeping. The digital twin empowers a proactive approach to compliance. It acts as a virtual model, allowing you to identify potential issues before they snowball into problems. This translates to improving the probability of staying between the lines and ahead of risk. The big idea? Just collecting data is no longer enough. At Lean Compliance, we understand the importance of context and connections. By harnessing the power of meta data and your hidden digital twin, you're not just organizing your data; you're building a powerful compliance ally, ready to navigate the ever-changing regulatory landscape with confidence. This is the future of compliance – real-time, proactive, and driven by the insights hidden within your own business.












