top of page

SEARCH

Find what you need

Search this site

615 results found with an empty search

  • Everything an Organization Does is Compliance

    I realize this statement may be controversial or even provocative to some, but I kindly ask that you hear me out. For many organizations, compliance sits apart from what the organization does. It’s often seen as an obstacle in the way of innovation and getting things done. This perspective often arises from having a narrow view of compliance influenced by years of prescriptive and legal regulations. However, this perspective is only part of what compliance now means and why we need to think about compliance differently. Let’s start with the definition of compliance found in the international standard ISO 37301:2021, Compliance is the outcome of meeting all your obligations. This definition implies there are two aspects to compliance: Compliance is an outcome, that arises from Meeting all your obligations This parallels the dictionary definitions for compliance most often described as: The state of conformity with official requirements The act or process of complying Let's look at the first part. Compliance as Obligations The first thing we can say about compliance is that it involves obligations. Without obligations there is no need for compliance. Obligations are explicit requirements that in some cases will be legal in nature, some will be ethical, and others are beneficial to mission success. Whatever the motivation, these requirements are explicitly defined and are intended to create outcomes beyond just that of conformance. It's also generally understood that not meeting obligations may also create outcomes: losses arising from not meeting the obligation (penalties, fines, sanctions, etc.), and loss of value associated with unrealized obligation outcome Obligations can be expressed in several ways that include: rules to be adhered to, practices to follow, targets to achieve, or outcomes to advance. No matter the shape or size, or when compelled by law, moral values, or corporate strategy, obligations give rise for the need of the act of compliance. Compliance Promises This brings us to the second part of the definition: meeting the obligation – the act or process of complying. When a company decides to accept an obligation, for example: to achieve carbon neutrality by 2035 they are making a commitment, in this case with an environmental obligation. However, in practice this can be any obligation imposed from outside or inside of organization. Until the obligation is accepted, there is no need for the act of compliance. When it is accepted, a commitment is made to engage in the act of complying. According to Promise Theory (Mark Burgess), compliance commitments describe promises an organization makes and intends to keep to meet a given obligation. Promises shape policy, strategies, goals and objectives for the organization to meet all their obligations. In essence, promises define the means rather than the ends. Compliance as a Regulatory Process Now we come to the heart of the matter. The primary means by which compliance meets organizational obligations is by regulation. I don't meet regulations, but rather the regulatory process. Many organizations view regulation narrowly as: Rules : A set of rules or principles that control how something is done. These rules are often set by an authority, like a government agency, to ensure safety, fairness, or a certain standard. It can also be define by internal policy. The act of controlling : The process of enforcing these rules or principles. This can involve things like inspections, licensing, and penalties for non-compliance. As a result of changes in the compliance landscape in recent decades, meeting obligations has become more than adherence to rules or the establishment of controls. Fundamentally, compliance involves regulating organizational behaviours and actions to meet accepted obligations of all shapes and sizes. This regulatory process is not the responsibility of the compliance function or limited to what is traditionally considered as compliance obligations. In fact, meeting such things as production schedules, sales quotas, or new product launches also requires a regulatory function which for the most part reside with functional managers although they simply call this activity – management . When we look more broadly, we can see that every part of the organization is working to achieve compliance with respect to their specific goals and objectives. You may recognize this as the chain of accountability. Employees are meeting obligations from Managers Managers are meeting obligations from Directors Directors are meeting obligations from General Managers General Managers are meeting obligations from the CEO CEO is meeting obligations from the Board The Board is meeting obligations from Stakeholders Everything an organization does is compliance. Now, I am not saying management should now adopt a check-box or audit approach that is followed by traditional compliance functions. In fact, just the opposite. Compliance should adopt an operational and performance-based approach found in functional departments. Functional managers know how to negotiate operational goals and objectives, develop strategies and plans, monitor performance, and continuously improve. While their obligations are related to operational objectives they still require a commitment (a promise) that must be kept. This is the contract between one accountability level and another. In this sense, functional managers have been practising the act of compliance for years and many excel at it. Pressing the point further, some use the Lean practice of Hoshin Kanri (policy deployment) / Catchball to align operational goals and objectives with organizational values and outcomes. What is unfortunate is this process traditionally has not included compliance obligations. This presents an opportunity for organizations to leverage these capabilities to better operationalize all their obligations. Eating the Other Half of the Elephant We have observed in recent years that at least half of an organization’s obligations come from internal policy and not from external regulations. These obligations are not compelled by law but instead are voluntarily chosen to support stakeholder expectations. These obligations are often associated with quality, environmental, ethics, safety, security, sustainability and other expectations that have more to do with a social license rather than a legal license to operate. While these obligations do overlap with legal obligations they require operational capabilities similar to those found in functional units across other parts of the organization rather than a compliance department. This is Not a New Path I realize many do not view compliance in this way which is not surprising. Their compliance experience for the most has come from finance and legal where obligations are prescriptive and enforcement is reactive. They do not know what compliance looks like from an operational and proactive perspective. This is not the first time organizations have faced this situation. Back in the 1980s a similar thing happened with the quality movement. Back then we strove to achieve zero-defects utilizing quality control (QC) and quality assurance (QA) roles. This is not fundamentally different from achieving vision zero targets such as: zero incidents, zero non-conformance, or zero violations. What is different is we don't need to do it like we did back in the 80s. What we have learned since then is that inspection and audits seldom improve quality. Instead quality needs to be designed into products, services, and processes. Today, we can't imagine managing quality without managing it in every part of the value creation process. This approach is what is needed now to meet safety, security, sustainability, environmental, ethical, and even regulatory compliance obligations. We need to manage all our obligations in every part of value creation. The good news is that organizations have been doing the act of compliance with respect to operational objectives for years in production, sales, marketing, HR, and other business functions. They have for the most part the capabilities needed to meet all their obligations. They just need to leverage the capabilities they already have. However, this won't happen until they realize that everything an organization does is compliance.

  • Keep Humans In The Loop

    When it comes to AI we must: Keep Humans In The Loop When there is a chance of harm, the decision to proceed is an ethical choice and can only be made by humans. AI should not make ethical decisions for you. They are not accountable and cannot answer for the outcomes. However, having humans in the loop means more than participating in an approval control process and checking a box. Accountable and responsible parties must be involved in identifying ethical dilemmas, impacts & risks, solutions, and arriving at a decision that is consistent with organizational values. What steps can you take starting today to ensure your organization is responsible with its use of AI?

  • Uncertainty and Risk

    This event has already occurred. Given that uncertainty and risk are on everyone's minds we have decided to go ahead and offer this workshop so you could benefit from important risk management principles and practices to improve the probability of project success in the presence of the COVID-19 uncertainties. In consideration of the public health recommendations this workshop to will now be a virtual format. This event will still take place on Saturday March 28th . However, the timing for the event has been adjusted based on the new format. The event will take place from 9 am until 12 pm and consist of three 50 minute sessions with 10 minute breaks between each session. The PMI chapter (PMI-CTT) will still be offering 3.0 PDUs for eligible attendees. However, this event is open to everyone. If you are involved with projects and looking for ways to improve your chances of success, you will benefit from this workshop. I would like to express my appreciation to the PMI-CTT chapter for all their hard work to make this workshop possible. This new format will provide the opportunity for more people to take advantage of this workshop and learn important risk management principles and practices which are needed more than ever in the presence of the COVID-19 uncertainties. If you haven't registered you can do so at this link . We look forward to connecting with you on Saturday, March 28th. It's time to defeat the dragon of uncertainty.

  • How Is Your Compliance Managing the Shift?

    In the last few decades there has been a paradigm shift towards risk-based regulators and regulation.   In the traditional model regulators identify the public harm, conduct an assessment, and come up with prescriptive treatments (rules) that industry is expected to adhere to.    Adhering to these rules is what compliance has meant and still does in many sectors but that is changing.   Regulators in high-risk sectors are modernizing their approaches to better contend with uncertainty.   They are transitioning towards being a risk-based regulator. If you want to learn more on this, I recommend you read the work by Malcolm Sparrow.   Risk-based regulators understand that industry is closer to the risk specifically with respect to determining how best to handle them.   In this new model, regulators establish performance and outcome-based obligations for industry to achieve and advance.    This requires organizations take on more of the risk function, defining treatment, and monitoring to satisfy the obligations.  This also means organizations must be proactive if they expect to meet obligations that arise from risk-based regulation. They need to set goals, define objectives, and make progress towards specified outcomes.  To manage this shift, compliance must be more than procedural, it must now become operational.

  • Refactoring Compliance For a Leaner, Smaller, and More Effective Program

    Compliance often becomes a labyrinth of obligations, commitments, controls, audits, processes, and many other activities and artifacts that are built up over time which makes compliance more complicated and difficult to manage, operate, and maintain. In many ways, this not unlike the software domain that contends with legacy code, technical debt, and changing and new requirements. In compliance, obligations are the requirements, and promises are the specifications used to engineer systems and processes to deliver on objectives that will in turn achieve the outcome of compliance. What if there was a way to streamline compliance in the same way that software engineers refactor code resulting in a simpler, more effective program? Lean Obligation Management for Compliance This approach focuses on simplifying the compliance burden by systematically removing unnecessary elements (i.e. compliance waste). Imagine it as de-cluttering or refactoring your management program by removing old obligations, restructuring poorly define promises, and addressing obligation debt. To understand how this can be accomplished we need to understand the nature of obligations and promises. Obligations : These are the requirements for each internal or external obligation. They define what your organization is expected to achieve in terms of compliance (adherence to rules, conformity to standard practices, achievement of performance targets, or the advancement of compliance outcomes: the benefits of being in compliance. Promises : These are the commitments, the specifications, your organization identifies to fulfill all their obligations. They detail how and to what degree you'll meet the requirements (e.g., designated data security officer role, mandatory annual compliance training, improving net zero targets, realizing better safety and security). Lean Obligation Management in Action This approach focuses on systematically removing unnecessary elements from your program, resulting in a simpler and more effective system. 1. Remove outdated or no longer applicable obligations. Obligations evolve and change over time. Regularly audit your management program to identify and remove obligations (internal or external) that are no longer applicable or have been superseded. This frees your organization from the weight of outdated compliance measures. 2. Remove duplicate promises. Duplication can bloat your program and introduce inconsistencies. Identify and remove any redundant compliance promises within your program. This ensures a single, clear commitment for each obligation, simplifying program management and reducing the risk of errors. 3. Remove promises that are no longer connected to an obligation (zombies). Sometimes, promises are made within an organization that no longer serve a purpose. These "compliance zombies” add to the overall cost without delivering any value. Lean Obligation Management encourages you to remove them along with the controls, workflows and processes that are no longer needed. 4. Consolidate promises within promise fulfillment systems based on common capabilities . Identify commonalities in how your organizations fulfills its compliance promises. Group similar promises together and consolidate them within dedicated promise fulfillment systems. These systems can be specific tools, processes, or workflows designed to efficiently address multiple compliance requirements. This reduces redundancy and streamlines your overall compliance efforts. 5 . Integrate New Obligations and Promises Strategically. When new regulations or stakeholder expectations introduce fresh compliance requirements, don't simply add them on top of your existing program. Instead, use the knowledge gained from Step 1 to strategically integrate them. This can be achieved through three key approaches: Leveraging Existing Fulfillment Systems: Look for opportunities to fulfill the new obligations using existing compliance systems you already have in place. These systems might be designed for similar purposes or share some overlapping functionalities. This approach reduces redundancy and streamlines the implementation of the new requirements. Adapting Existing Systems: If the new obligations have some overlap with existing compliance areas, consider modifying your current fulfillment systems to accommodate the additional requirements. This can be a cost-effective solution if the changes needed are minor. Developing New Fulfillment Systems: For entirely new compliance needs that don't align with existing systems, you may need to develop dedicated fulfillment systems. These systems should be designed to be efficient and effective in meeting the specific requirements of the new obligations. If you find yourself unable to follow these steps, it's a strong signal that your compliance program has become overly complex and you may have lost control of your compliance. Lean Obligation Management provides an approach to gain control back by promoting compliance simplicity. By actively managing the promises your organization makes to meet obligations, you gain a clear understanding of your compliance efforts and ensure they remain effective and easy to understand for everyone involved. Benefits of Lean Obligation Management: By actively reducing unnecessary elements and ensuring clear promises meet specific obligations, you can achieve a simpler, more effective program capable of meeting all your compliance needs. This will help create the following benefits: Reduced Program Complexity : A leaner management program with clear promises for each obligation is easier to maintain, implement, and understand for all stakeholders. Improved Efficiency : By focusing on essential compliance elements, your program operates more efficiently, saving time and resources. Enhanced Agility : A streamlined program allows you to adapt to changing external and internal obligations more readily. Proactive Management of New Obligations : Evaluating the true nature of new obligations before integrating them allows for a more strategic approach to compliance.

  • Managing Risks caused by Cost Reductions

    Cost reduction programs while sometimes necessary all too often end up removing value and expose companies to unnecessary risk. Deferring maintenance, not doing critical improvements, pushing more work on employees, switching to cheaper suppliers, and even moving to the cloud may eliminate some costs in the short term, but may also impact future benefits and affect a company's ability to meet its compliance obligations. As change can be a significant source of risk it is important that companies put in place an effective change process that covers possible impacts to critical programs, systems, and processes. An effective change process acts as a layer of defense against exposure to risks caused by changes to compliance systems. Embedding a risk assessment into this process also ensures that risks are properly identified, evaluated, and implemented along with the change itself. The following diagram depicts a simplified change process to manage changes to critical programs, systems, and processes: 1. Scoping define the proposed change identify affected programs, systems and processes identify alternatives estimate savings and costs 2. Impact / Risk Assessment identify impacts on identified programs, systems, and processes identify impacts affecting critical to compliance objectives (CTCs) identify threats and opportunities, evaluate risks, and determine prevention/mitigation and enable/exploit controls create implementation and risk response plans 3. Approvals obtain necessary approvals, based on accountability and level of risk, to proceed with implementation 4. Implementation implement change and risk response plans 5. Verification verify that changes were made according to plan and standard procedures Implementing a change process requires that critical systems are identified first, followed by critical to compliance (CTC) objectives so that impacts can be identified and monitored. CTCs are key results, activities, documented evidence, reports and so on, identified as critical to meeting agreed to compliance obligations. Identifying these is part of proactively managing overall compliance (shown in the following compliance map) to maintain a continuous state of compliance. Effects impacting CTCs can be anticipated and addressed to ensure that there are never any gaps in meeting compliance obligations. Cost reduction programs benefit from an effective change process to ensure that potential savings are not offset by costs associated with increased exposure to risk. In addition, an effective change process can also provide the following benefits: a stage and gate approach to properly sequence the work a cross-functional team derived based on the identified scope and impacts the tools and practices needed to implement changes safely visibility of the level of risk associated with all changes being introduced visibility as to the level of work and bottlenecks across all changes All of these benefits help to ensure that risks are addressed, compliance is maintained, and that the promised savings are actually achieved.

  • Is Compliance Risk Reducible?

    The primary purpose of risk management is to handle the possible effects of uncertainty against specified objectives. This handling involves establishing risk treatments where effectiveness is measured by the difference in risk levels between treated and untreated risk. This difference is often referred to as, “residual risk.” It is the objective of risk managers to establish risk treatments so that residual risk is below an organization’s risk tolerance. To accomplish this an organization first needs to know the level of risk they will, should, or can tolerate. This is defined by the level of risk below which an organization is willing to accept the positive or negative outcomes of not meeting their obligations. In other words, they will tolerate whatever happens for all risk below this level. The next step in establishing risk treatments is to understand the nature of the compliance risk which involves evaluating the uncertainty associated with an organization’s capability to meet each obligation. Risk is always associated with uncertainty as defined by ISO 31000 where risk is, “the effects of uncertainty on objectives.” We can therefore classify risk treatments according to the nature of this uncertainty as follows: Risk due to epistemic uncertainty; lack of knowledge or know how; this risk is reducible. Risk due to aleatory uncertainty ; caused by inherent randomness or natural/common variation; this risk is irreducible. Reducible risk is treated by buying down uncertainty to improve the probability of meeting each obligation. In some compliance domains this is called preventable risk. Irreducible risk is treated by applying margin in the form of contingency, management reserve, buffers, insurance and other measures to mitigate the effects of the risk. In practice, many organizations buy-down what they can afford and accept the consequences for the residual risk should it become a reality. Companies tend to consider any residual risk as if it were irreducible and treat it with margins. This begs the question of why not treat all compliance risk as irreducible which by-the-way many do. The answer can be found by considering the factors that contribute to an organization’s financial margin. A company's margin is significantly and negatively impacted by the cost of realized reducible compliance risk. These costs are associated with such things as defects, incidents, breaches, violations, emissions, and other non-conformance. All of these are sources of waste which for the most part can be and should be reduced or eliminated. This waste not only hurts the bottom line but also a company's reputation. Organizations that do not address risk that's reducible will never have enough margin to cushion for the effects of risk that's irreducible. Saying it another way, the more a company invests in buying down reducible risk the more margin they will have to use for the things that really matter. It is incumbent on management to effectively buy-down reducible risk to avoid unnecessary and preventable waste (i.e. the effects of uncertainty), to improve margins and increase the probability of mission success. For everything else, they should ensure there is sufficient margins to cushion the effects when and if they are realized.

  • Beyond Compliance: Building Trust Through Commitment

    In my years working across high-risk, highly regulated industries like medical device, pharmaceuticals, and energy, compliance used to be a simple matter of ticking legal boxes. But that's no longer enough, and hasn’t been for some time. Today, compliance is about fulfilling all our commitments, not just the ones mandated by law. Think of it as keeping promises – the promises we make to our stakeholders, as outlined in ISO-37301 and Promise Theory . “Promises are the uniquely human way of ordering the future, making it predictable and reliable to the extent that this is humanly possible.”– Hannah Arendt” The gap between making those promises and following through is a measure of our integrity – are we walking the walk, not just talking the talk? In fact, a strong compliance integrity score can be calculated by the number of promises kept compared to the number made. The problem is, many still see compliance as an after-the-fact audit function, solely focused on legal compliance. Sure, that might keep them licensed to operate, but it doesn't inspire confidence that they will achieve the goals that really matter. That’s why to truly build trust and ensure success, organizations are moving towards a more proactive and integrative approach to compliance. They’re weaving a "golden thread" of assurance that encompasses not just legal obligations, but also voluntary commitments to safety, security, sustainability, quality, environmental, and ethics. This fortified compliance chain will lead to greater trust from everyone who has a stake in their success – employees, partners, suppliers, customers, communities, and beyond.

  • Compliance Capabilities

    Compliance is often organized into isolated functions that are separate from the production management structure. However, we know that programs that support: quality, safety, risk, regulatory, environmental, and other compliance objectives, are not effective when implemented in isolation. Instead, they are more effective when seen as horizontal capabilities that cross the entire value stream. It's time to make the vertical compliance function into a horizontal compliance capability.

  • LEAN RISK

    LEAN when applied properly is an effective measure to improve the probability of mission success. All the waste that LEAN seeks to eliminate is caused by the same thing: uncertainty, and this uncertainty creates the opportunity for risk – the true waste that threatens mission success. Here are a few examples of how this happens: We create defects because of uncertainty associated with process capabilities, standards, and work practices. We conduct excess processing because of uncertainty associated with what is only needed - what is value add and what is not. We over produce because of uncertain production requirements. We wait because of uncertainty associated with: process control, equipment reliability, or maintenance activities. We create excess inventory because of uncertain demand requirements and external risk We transport more than necessary because of logistics uncertainty. We move more than necessary because of uncertainty associated with work procedures and standards. We have non-utilized talent because we are uncertain of the skills people have and how best to use them. If you want to eliminate waste, eliminate uncertainty first.

  • Applying Lean 5S to Compliance

    Compliance is an essential aspect of any business, ensuring that organizations operate within the legal and regulatory framework set by the government. It is a critical component that helps organizations maintain their reputation, protect their stakeholders, and avoid potential legal or financial penalties. However, complying with regulations can be a daunting task, especially for small and medium-sized businesses that may not have dedicated compliance teams or the necessary resources. To help organizations navigate the complex world of compliance, the Lean 5S methodology can be applied to obligations, ensuring that companies are organized and structured in a way that promotes compliance. Here's how: 1. Sort: Start by identifying all compliance obligations that apply to your organization. This could include regulatory requirements, contractual obligations, or internal policies. Once identified, remove any obligations that are no longer relevant or necessary, reducing clutter and streamlining compliance processes. This step can help organizations stay focused on the obligations that matter, ensuring that resources are directed towards meeting those obligations. 2. Set in Order: Once you have sorted through the obligations, organize them in a logical and systematic way. This could involve categorizing obligations by compliance area, risk level, or regulatory authority. Establish clear guidelines for managing and monitoring compliance, making it easier for employees to understand and follow. This step can help organizations stay on top of their compliance obligations, ensuring that they are prepared for regulatory audits and inquiries. 3. Shine: Ensure that all compliance-related processes are working effectively and efficiently. This may involve conducting regular assessments, reviewing policies and procedures, and identifying areas for improvement. By shining a light on compliance processes, organizations can identify potential risks and take steps to mitigate them, reducing the likelihood of compliance violations. 4. Standardize: Develop clear and consistent compliance standards that are easy for employees to understand and follow. This could involve creating checklists, developing training programs, and establishing protocols for managing and monitoring compliance obligations. By standardizing compliance processes, organizations can ensure that employees are aware of their compliance obligations and are equipped with the necessary tools to meet those obligations. 5. Sustain: Maintain and continuously improve compliance processes by regularly reviewing and updating policies and procedures, conducting training programs, and fostering a culture of compliance within the organization. This can help ensure that compliance is integrated into the company's day-to-day operations and becomes a part of its overall business strategy. By sustaining a culture of compliance, organizations can build trust with their stakeholders and avoid costly legal and financial penalties. In today's regulatory environment, compliance is more important than ever. Failure to comply with regulations can have severe consequences, including hefty fines, legal action, and damage to a company's reputation. By using the Lean 5S methodology, organizations can streamline compliance processes, reduce the risk of non-compliance, and build a culture of compliance that helps them stay ahead of regulatory changes. So, if you haven't yet implemented the Lean 5S methodology for your compliance obligations, there's no better time to start than now!

  • An Objective View of Obligations

    ISO 19600 and 37301 define compliance as the outcome of meeting a company's obligations. These obligations arise from such things as regulations, standards, policies, guidelines, permits, contracts, codes of conduct and many other sources. A subset of these will be legal obligations which tend to be prescriptive in nature, for example, "Companies must report all tier one releases within 24 hours." Whereas, industry standards and guidelines tend to be more risk and performance-based where companies are expected to make progress towards reducing such things as emissions, violations, fatalities, breaches, and so on. Intermediate targets for these obligations may be dictated by regulatory bodies making them mandatory, however, the means by which these are achieved is usually left to each organization based on their level of risk. Independent of the source of the obligations or whether they are mandatory of voluntary we can categorize them by four different types each with their own specific demands on the organization as shown in the following diagram: Each type of obligation will in turn give rise to compliance objectives in order to meet the obligation demand. Companies will put in place compliance systems of processes to efficiently manage and ensure these objectives are met taking advantage of shared capabilities and resources to keep the costs within sustainable levels commensurate with a tolerated level of obligation risk across categories that include: safety, regulatory, reputation, environmental and other areas of concern. Compliance Systems To understand how best to meet each compliance objective we need to understand the dynamics of systems and specifically purposeful systems that are goal-seeking which is the case for compliance which where systems are used to ensure meeting targeted objectives. Dr. Russell Ackoff defined a system as: " a whole which is defined by its function in a larger system of which it's a part. For a system to perform its function it has essential parts: Essential parts are necessary for the system to perform its function but not sufficient Implies that an essential property of a system is that it can not be divided into independent parts. Its properties derive out of the interaction of its parts and not the actions of its parts taken separately." It is this last part which is often overlooked that I want to focus our attention on. Outcomes vs. Objectives: Making progress towards compliance outcomes is a primary measure of effectiveness for compliance programs. Since outcomes are an emergent property of compliance systems it is important that we understand how the parts interact with each other to create the outcome of compliance. To help with this we need to clear up confusion around the notions of outcomes, objectives, goals, results, and even initiatives. For now we will define and consider the difference between outcomes and objectives since they are the primary components of a compliance system (c.f. ISO 19600, ISO 37301:2021 ). Outcomes : these are the ends that we expect to attain over time and where progress is expected through the achievement of planned objectives. Examples of these include: zero incidents, zero harm, zero breaches, zero emissions, zero defects, and many others. These are often described in qualitative terms but may also have defined measures of effectiveness to indicate progress towards the targeted outcome. Objectives : these are the ends that we expect to attain within the period covered by planning. These results contribute to making progress towards the targeted compliance outcome. An outcome may require several objectives done in parallel, sequentially, continuously, and some contingent on others. Some form of causation model (deterministic, probabilistic, linear, non-linear, etc.) is used to estimate the confidence level of achieving the desired outcomes by means of objectives. In cases of greater uncertainty these models will be adjusted over time as more information is gathered and correlation between objectives and outcomes are better known. Objective Criteria and Evaluation Objective Criteria: these are attributes that describe an objective. These may consist of measures of performance, conformance, risk, or other attributes that are used to evaluate whether an objective has or is being met. Objective Scorecard: a qualitative and/or quantitative evaluation of the attributes that define an objective. These are often aggregated to form a single score used to rank the overall status of each objective. A point worth mentioning is that measures of effectiveness are usually associated with outcomes and often measured as progress towards these outcomes. However, in some cases where objectives require obtaining a specified result over a period of time, the objective may also have a measure of progress. An example would be reducing the level of risk to an acceptable level for a given objective over time. Those familiar with performance-based systems will notice that evaluation of outcomes is a form of performance assessment rather than an audit. Assessments are usually conducted more frequently to measure the ability to achieve outcomes as opposed to audits which are conducted to validate outcomes have been achieved or the existence of evidentiary material related to prescriptive conformance. This differentiation is important particularly when trying to maintain a status of compliance during the period between when audits are conducted. An Example From Occupational Safety In this example we will look at making progress towards zero safety incidents which is a goal that many organizations have. For our purposes we will define as the outcome of our safety compliance system as zero incidents . To make progress towards zero incidents (the ultimate or terminal goal) there will be a number of objectives to be managed by a safety compliance system. Here is a list of examples: Increase the number of documented near misses Create a safe work culture as evaluated by an organizational culture survey Ensure effective safeguards on machinery and equipment Provide effective safety training for all workers and contractors Ensure works use PPE appropriate for the level of risk Maintain and train against up to date safe-work procedures and practices Establish and maintain an effective joint health and safety committee Establish an effective emergency response system Conduct a yearly risk and hazard assessment Reduce the level of safety risk by 10% year over year Each of these objectives will have their own set of criteria relative to current conditions, the planning time frame, and targeted results. Let's take a look at one of these objectives in more detail, "Establish an effective emergency response system." This objective would include attribute criteria such as: Activation of emergency response plan occurs within X hours of a reported incident. Affected stakeholders notified within X hours. Response plan is updated after risk and hazard assessments. Performance of emergency response plan is tested once per year. Local authorities are notified within X hours. Response teams receive refresher training once per year. Some of these criteria come directly from regulations while other may come from internal policies and other sources. Objectives and their attributes will have dependencies with other objectives which will also need to managed. In addition, each objective will require a set of capabilities (some shared) to meet all its criteria. And finally, objectives may be connected with other safety obligations. What does this all mean? For compliance to be effective organizations must be clear about the outcomes they are trying to achieve and the objectives that need to be met to get there. Objectives are more than gaps identified by audit findings. Objectives define what is needed to ensure that obligations are met continuously all the time so there are no gaps in the first place. They also define what is needed to realize compliance outcomes – the benefits from being in compliance.

bottom of page