SEARCH
Find what you need
Search this site
615 results found with an empty search
- We Don't Protect What We Don't Value
Business success is often measured by a single metric: profit. However, in today's economic climate, organizations are increasingly recognizing the importance of a broader concept - Total Value . This goes beyond just the financial bottom line and encompasses protecting value creation across all aspects of a company's operations. Protecting Total Value The saying goes, "we don't protect what we don't value." This contributes to why compliance doesn't have the role that it should. Organization's just don't value the outcomes needed to ensure mission success. When a company prioritizes short-term gains over compliance, it essentially devalues the very things that contribute to its long-term success. By neglecting safety regulations, environmental standards, or ethical practices, a company puts its reputation, integrity, and even the safety of its employees at risk. These are the very things it needs to protect to build trust with stakeholders and achieve corporate sustainability. Present Bias Is Not A Gift Imagine a business that cuts corners to maximize profit. This may lead to non-compliance with safety and security regulations along with breaking promises made to stakeholders to achieve adequate safety and security performance targets. While short-term profits might increase, a potential incident could damage the company's reputation, incur hefty fines, and erode stakeholder trust. It only takes one violation, one incident, or one non-conformance to realize significant loss of value. This is an example of "Present Bias" – the tendency of people to give stronger weight to payoffs that are closer to the present time when considering trade-offs between two future moments. Here's where the concept of T otal Value Advantage comes in. Building on Michael Porter's Value Chain Analysis, this approach recognizes that competitive advantage goes beyond just price and product features. It encompasses all aspects that deliver value to a company's stakeholders in the broadest sense of the term: customers, suppliers, shareholders, employees, communities, or the public at large. Establishing effective compliance programs that actively manage its role to protect and ensure Total Value both in the present and the future, a company gains a significant advantage. It demonstrates its commitment to responsible practices, builds trust with customers and partners, and fosters a safe and productive work environment. This, in turn, attracts and retains talent, enhances brand reputation, and ultimately leads to corporate sustainability. The Bottom Line Focusing solely on profit is a short-sighted strategy. However, by embracing the concept of Total Value and recognizing the crucial role compliance plays to protect its creation, businesses can improve the probability of mission success. This leads to a Total Value Advantage , fostering trust, building resilience, and ultimately achieving corporate sustainability. It's time to change the sign for compliance to read, "We Protect Total Value."
- Leading Health Systems Innovation
Like other sectors, health care also requires innovation. Current models are based on a reactive and transactional approach to how health care is delivered. As patients, we wait for symptoms to present themselves before making any improvements to our health. In a similar way, health care providers often wait for regulatory changes before making adjustments to the systems that deliver the needed care. What is common to both is all the waiting. Time for Change I attended a presentation a few years back on the topic of Health Systems Innovation at McMaster University (Hamilton, Ontario), where the discussion focused on the future of health care, what it might look like, and how it can change from a reactive model to one that is proactive, participatory and where risk is shared. The speakers where: Dr. Des Gorman (Faculty of Medical and Health Sciences, University of Auckland), and Mrs. Danielle Freschette (Executive Director, Health Systems Innovation and External Relations, Royal college of Physicians and Surgeons of Canada) Here is my brief summary of the presentations and ensuing discussions. What I found most interesting is that many of the issues presented are also found in other sectors. Health care is not the only industry that suffers from being too reactive. We have the wrong model Reactive Transactional Funding the wrong things Regulation that constrains innovation Health care is moving towards Participatory health care Self-management Focus on outcomes Co-development Mutualised risk Process agnostic Insights Within 5-7 years whatever new system you put in place becomes corrupt. People figure out how to game it. We need to design systems that are intended to be gamed but where everyone wins. People want to pay for outcomes not activity (i.e. transactions). Yet, there is little motivation to do anything other than continue to transact. Evidence based medicine was introduced to reduce variation and improve outcomes but is no longer innovating. We should have a strong skepticism around data and its use. Data only tells "half" the story. Health care is not ready for industry 4.0. We are not teaching people how to adapt. In many cases providers do not have the capacity to change. In Canada (specifically Ontario) there are too many pilot programs. Not enough have reached the point of viability and able to scale. Innovation is currently driven by technicians and technology. Technology should not be the driving factor; patient outcomes should be instead. For health care to be proactive it needs to be based on outcomes and competency We need greater participation from all areas of health care if we are to come up with better approaches. There is no lack of desire to do this but a lack of effective ways to engage everyone. We need to create the conditions that encourage innovation not stifle it. My thoughts Health care systems are based on a model that is not sustainable and it has been this way for some time. There are many factors that contribute to this and there is a multitude of options for how to improve. However, what is not clear, is how these innovations are funded, introduced, and scale to achieve the intended benefits. Some of these can be done incrementally. but others may require changes to current systems to enable these innovations. What is clear, is that more engagement is necessary from all who provide health care and those that benefit from it. Perhaps, this is where innovation is most needed. A participatory approach based on mutualised risk that focuses on patient outcomes might just be the kind of innovation we need to become more proactive with our health care. This approach may also be helpful in other industries that are highly regulated, where risks need to be managed, and that suffer from being too reactive. Amendment In the years since I wrote this the Healthcare system in Ontario has started to transition towards a teams-based approach to improve overall coordination and improve support for proactive health care strategies. Having recently undergone surgery to remove a gall bladder I have now experienced first hand the level of care which was excellent. After the surgery I was sent home as part of a virtual nurse program. During this program which lasted two weeks, I took my vitals each day which where uploaded using a tablet and then interacted with nurses and physicians through video sessions. Throughout this entire process I was treated with respect, dignity and with great care. More work is still needed to address systemic issues across the healthcare systems along with new realities of sustainability and burn-out. However, several of the shortcomings I wrote about have now been addressed at least within the primary care system which I am very grateful.
- A Little About Myself
Talking about oneself does not come easily to some of us. This can get in the way of building trust with the people we work with. But how much should you share and how much is TMI – too much information? In the spirit of building trust, I thought I might risk sharing a few things about myself. To start with I am the CEO and founder of Lean Compliance. I started this business in 2017 to help forward-looking compliance leaders succeed at keeping their organizations between the lines and ahead of risk. To achieve this success, I believe that compliance must be more proactive, integrative, and capable to contend with risk to ensure total value is protected and created. This requires a new approach that aligns more with operational excellence than it does audit and reporting. I am currently authoring a book on the topic of, "Operational Compliance: Staying Between the Lines and Ahead of Risk". This is based on my experience across my career working for hundreds of organizations and companies in highly regulated, high-risk industries and lessons learned making compliance work. This has given me a unique perspective having witnessed how safety, security, sustainability, quality, environmental, legal, and regulatory programs and technologies are used to advance compliance outcomes. I also write and publish weekly blog articles, and speak on the topics of risk, compliance, ethics, AI, and Lean principles and practices. I recently started a community of practice to help all compliance practitioners across all sectors elevate their compliance. This community meets every Monday @ Noon on Zoom. I chair the AI Committee at E4P (Engineers for the Profession) advocating for the recognition and right to practice for emerging engineering disciplines. As a profession we need to do more to elevate the role engineering across the multiple disciplines that are needed today such as AI engineering, Cybersecurity, Quantum and many others. As a professional engineer I recognize that I have a duty to uphold the public welfare as paramount and this informs my work and how I engage with clients, my community, and others to advance human flourishing. In many ways, this has raised my ethical standards which I hope will in turn do the same for my clients. In conjunction with my church, I also facilitate a monthly Biz Group for christian business leaders to help connect our faith with our practice. Ultimately, how we lead is grounded by the values we hold and what we believe demonstrated by our actions. Aligning these is a measure of Integrity and is something we must all continue to work on. I also have three wonderful grown kids and the best wife a man could ever have. I don’t believe we come into this world half complete in need of someone to complete us. However, my wife has added more to my life than I could have imagined making it better than I thought possible. Finding a life partner is indeed a wonderful thing. So, now you know a little more about me. How about you? How did you get into compliance, and what are you currently working on?
- Interview with the Founder
The following questions were asked in an interview with Raimund Laqua, Founder and Chief Compliance Engineer at Lean Compliance. 1. What made you decide to start Lean Compliance? Over the last 25 years I noticed that many companies start well with their compliance initiatives but they don't end well. It always was 2 steps forward and 3 steps back. It was hard for them to advance their safety, quality, environmental and regulatory compliance programs when the ground was constantly shifting beneath their feet due to changes in standards, regulations, organizational structures, leadership and so on. There had to be a way to help these companies that are struggling to stay above water to do better and in the process achieve better outcomes. That is why I started Lean Compliance to answer that question. 2. Why did you pick the name Lean Compliance? Early on I realized that companies could not make any improvements if all their resources were tied up fighting fires. To advance compliance more, capacity was needed and that is precisely what LEAN helps with. LEAN has helped many companies and industries to reduce waste in their processes. This creates room for further improvements to be made including those needed for compliance. As far as using the word "Compliance" goes, I am not fond of it. Few people like compliance and it brings with it negative connotations. I always knew that compliance needed to go beyond conformance and focus instead on outcomes. This should if done properly be received more positively. Perhaps, someday we might call it something else. Until then, I am trying to change our mindset from being reactive and negative and tilt it towards being proactive and positive. 3. What are the challenges that you see with how compliance is currently done? This may seem odd to mention, but the most serious problem has to do with our attitude towards compliance. Most companies see compliance as a necessary evil instead of as a necessary good. This attitude reinforces a reactive behavior that only deals with compliance after the fact. Companies spend most of their time paying off their compliance debt by addressing corrective actions. However, this takes too long and prevents them from benefiting from the outcomes of their investment. It's like a mortgage to them that they hope to pay off eventually not realizing that when they do they will have paid several times for it in interest. Another important challenge is how standards and regulations have changed. They are not as prescriptive as they once were. Many are now management or performance based requiring companies to continuously improve and advance outcomes. Its no longer enough to just follow procedures, companies now need to actually improve safety, quality, and environmental impacts. This requires knowledge of how to deliver effective programs and systems and this is something that many companies are lacking. 4. How does Lean Compliance help companies address these challenges? There are no silver bullets, or one time fixes. Depending on how much compliance debt a company has will determine how best to proceed. That is why we created, "The Proactive Certainty Program." This program follows a process we developed that helps companies to continuously improve their compliance so that they not only pay off their debt but stay out of debt. As each company is different we tailor this process based on the capabilities and competencies they already have. 5. What would you like to say to those who are feeling the weight of compliance but not sure what to do next? Don't wait for a heart attack before you decide to improve your health. In the same way, don't wait for an incident or an audit finding before you act. As with your health, being proactive can decrease the likelihood of a heart attack in addition to bringing with it the benefits of a healthier life style. Compliance functions the same way. It all begins with your attitude and that is something that you need to change. We can help you do the rest.
- Audits Don’t Deliver Compliance
Audit is not the function that fulfills obligations. It’s the function that verifies you are keeping your commitments associated with them. What delivers on obligations is an Operational Compliance Program . Here's a breakdown of the different functions: Audit : An audit is an independent review process that verifies if an organization is following the rules and procedures it has set for itself. It's like a financial examiner looking at a company's books to make sure everything adds up. An audit can identify areas where controls are weak or where procedures aren't being followed. However, it seldom validates effectiveness with respect to achieving goals, performance targets, or compliance outcomes. Operational Compliance Program : This is the program that actually ensures an organization meets its obligations. It's a set of policies, systems, processes, procedures, and training that helps an organization understand and follow the rules, conform to standard practices, achieve performance targets, and advance compliance outcomes. An effective compliance program will have things like a code of conduct, clear guidelines for different activities, and regular monitoring to identify and address any issues. It will also have continuous improvement processes to improve its effectiveness over time. Imagine you promised a friend you'd help them move (your obligation). An audit would be like calling them afterwards to see if they actually moved (verification). But the real key to fulfilling your obligation is keeping your promise to show up on moving day and helping them lift boxes (compliance program). That is the purpose of an operational compliance program. It is the proactive function that helps you meet your commitments, while an audit is the reactive assessment that verifies if you're doing what you said you would. Compliance Effectiveness The heart of an effective compliance program is integrity - closing the gap between what we promised and our actions. Integrity is a measure of compliance performance and a leading indicator of effectiveness: Compliance Integrity = Number of Promises Kept / Number of Promises Made If you want to know how well compliance is working measure how well an organization keeps its promises and commitments. However, the final word on whether or not obligations are satisfied will always be the authority that created the obligation. For external obligations this may be a regulatory agency, court judgments, or legislature. When it comes to internal or voluntary obligations this will be corporate or organizational governance. Auditing of voluntary obligations can and is often misunderstood. For example, if you adopt an ISO standard for quality, the certification you receive is based on a conformance audit with that standard. While this standard is voluntary it creates an obligation to maintain the practice or risk losing your certification. What's important to realize is that certification audits do not validate if you have met your internal obligations associated with goals, performance targets, or quality outcomes. These obligations are defined by the organization acting in the role as internal regulator and it's these obligations that internal audit should be evaluating. Why? because no one else is! In many cases internal audit is only concerned with external or legal obligations. The interesting thing is there are just as many internal as there are external obligations. Organizations may report on these but seldom have the programs to advance or make progress towards the promised outcomes. ESG and Sustainability obligations fit into this category although others exist across every compliance domain. What Does this Mean for Compliance? Audit plays an important role to verify organizational practices but is not the function that delivers on internal or external obligations. The function that is responsible is an Operational Compliance Program which works with the business to make and keep promises with respect to satisfying obligations. While it doesn’t own the obligations it provides the expertise and capabilities to equip the business to always stay between the lines and ahead of risk. Failure to deliver on obligations is not a failure of audit but rather a failure of your compliance program. An effective compliance program will always let you know in real-time if you are keeping your promises with respect to both internal and external obligations. This helps organizations make course corrections while there is still time to do something about it – something that audit cannot provide.
- One Day or Day 1
Many organizations recognize that meeting all their obligations and staying ahead of risk requires adopting a holistic, proactive, and integrative approach to compliance. However, they also find themselves trapped by a siloed, reactive, and divided practice reinforced by years of prescriptive rules and audits. They often tell me, I know we need to change but we have too much on our plate. We’re too busy putting in controls, auditing, and working on corrective actions to be proactive. Perhaps one day we will be in better shape to change. But I tell them, That day will never come, you will never catch up, and you will never make the changes you need to really protect value creation and keep all your stakeholder commitments. The difference between compliance failure or success depends on one decision: One Day or Day 1? You need to decide to change today. You may not know what’s needed or how to proceed at first. That can be improved over time. But no change will happen until you decide to start. You can wait until something bad happens and when it might be too late to change. Or You can decide to make One Day into Day 1.
- What Prevents Compliance From Failing?
Jame Clear, author of Atomic Habits, writes: “You do not rise to the level of your goals, You fall to the level of your systems” He is correct. Left on our own we drift into disorder away from our goals. Systems prevent you from falling into disorder. Systems act as a guardrail by resisting change to reduce variation. Now, how do you raise your system levels? That’s the role of management programs which introduce change. They adjust system targets to higher levels of performance to advance overall outcomes. Programs bridge the gap between operational objectives and organizational outcomes by elevating the quality of our systems. Without them you fall to the level of procedural conformance. With them you elevate your compliance to higher standards of safety, security, sustainability, and other compliance objectives. Programs are an essential component of operational compliance, necessary (but not sufficient) to meet performance and outcome-based obligations. Are you missing this essential function of compliance?
- Is your compliance software hindering your effectiveness?
Technology is a pervasive force that significantly influences our lives in various ways, particularly with the widespread integration of AI. The impact of software on us is not always apparent, as we've learned from years of using social media. It's crucial to be aware of how technology can amplify certain behaviors while constraining others. Gone are the days when we could perceive technology as neutral, merely consisting of data collection, processing, or output devices. We now understand that information possesses influence beyond our explicit requests or desires. In many ways, information has agency. Therefore, it's imperative to ensure that our technology choices align with our values, contribute to our objectives, and, most importantly, reinforce the behaviors essential for achieving our mission. Failing to do so may result in reinforcing what benefits technology at the expense of our own interests. Be mindful of your technology choices and choose wisely.
- Achieving Success in Compliance: Three Key Strategies
A common problem facing organizations in highly regulated, high-risk environments is how to properly govern their operations to ensure they meet all their obligations and keep all their stakeholder commitments. This problem in many ways is about aligning the ends with the means, or better, bridging the gap between organizational outcomes and operational objectives. In fact, it’s a problem of managing compliance in the middle. When one considers the combinatorial explosion of obligations and associated risks connected with safety, security, sustainability, quality, regulatory along with ethical conduct the problem is almost intractable. This is evidenced by a large number of end points, connections, and interactions to control particularly when addressing the problem through a reactive and reductive model centred on controls, tasks, issues, and corrective actions. Technology offers some relief by enabling certain processes and making some more efficient. However, automation can all too often result in baking in processes, or what we used to call, “paving the cowpath” resulting in greater fragility rather than agility to contend with uncertainty and complexity. To reduce complexity and improve overall compliance effectiveness organizations will adopt different strategies some of which are compelled by regulation, others are voluntarily chosen. These can be categorized by their primary focus: standardizing practices, integrating controls, or operationilzing systems. Standardize Practices - example: management system standards and frameworks (ISO, ICH, NIST, CSA, FDA, OSHA, etc.) Integrate Processes - example: GRC (Governance, Risk and Compliance ) Operationalize Systems - example: Lean TCM (Total Compliance Management) These approaches overlap to various degrees but differ in how they work, and where they operate within an organization. In this article we explore each of them and compare their advantages and disadvantages. Standardize Practices ISO management systems standards such as ISO 37301 (CMS) are examples of this approach. ISO standards are a set of internationally recognized guidelines designed to assist organizations in achieving operational excellence, ensuring quality, and promoting continual improvement. These standards are developed by the International Organization for Standardization (ISO), a non-governmental organization that brings together experts from various industries to create consensus-based specifications. The primary objective of ISO management standards is to establish a common framework that organizations can implement to enhance efficiency, reduce risks, and meet the expectations of stakeholders. These standards cover a wide range of disciplines, including quality management, environmental management, information security, and occupational health and safety. Implementation of ISO management standards typically involves a systematic approach, starting with a thorough understanding of the organization's processes and objectives. Organizations seeking certification adhere to the specific requirements outlined in the relevant ISO standard. The implementation process often includes the development of documented policies, procedures, and guidelines, as well as the establishment of key performance indicators to measure progress. Certification, which is usually assessed by independent third-party auditors, serves as a formal recognition that the organization's management system conforms to the specified ISO standard. Achieving and maintaining ISO certification demonstrates a commitment to excellence and can enhance an organization's reputation, fostering trust among customers, partners, and regulatory authorities. One of the fundamental principles of ISO management standards is the concept of continual improvement. Organizations are encouraged to regularly review and refine their management systems to adapt to changes in the internal and external environment. Continuous monitoring, measurement, and evaluation of performance metrics help identify areas for enhancement and ensure that the organization remains responsive to evolving circumstances. This iterative process not only drives efficiency but also cultivates a culture of innovation and adaptability within the organization. In essence, ISO management standards provide a dynamic and flexible framework that empowers organizations to navigate the complexities of today's business landscape while fostering a commitment to ongoing improvement and customer satisfaction. Potential Weaknesses While ISO standards provide valuable guidelines for organizations seeking to enhance their processes and ensure quality, there are some key weaknesses associated with their implementation: Rigidity and Formality : ISO standards can be perceived as rigid and overly formal, leading to a potential disconnect between the prescribed requirements and the dynamic needs of certain organizations. This formality may hinder innovation and creativity within some contexts, especially in rapidly evolving industries where flexibility is crucial. Resource Intensiveness: Achieving and maintaining ISO certification can be resource-intensive, particularly for small and medium-sized enterprises (SMEs). The documentation, training, and audit processes involved can be time-consuming and costly, posing a challenge for organizations with limited budgets or manpower. Focus on Documentation : ISO standards often emphasize extensive documentation to demonstrate compliance. While documentation is essential for clarity and accountability, an excessive focus on paperwork can lead to a "box-ticking" mentality, where organizations prioritize meeting documentation requirements over genuine process improvement and effectiveness. Limited Adaptability: ISO standards may not always adapt quickly enough to emerging trends, technologies, or industry-specific nuances. This limitation can make it challenging for organizations in cutting-edge or highly specialized fields to fully align their management systems with the most current best practices. Lack of Strategic Guidance : ISO standards provide a framework for establishing management systems but may not offer specific strategic guidance tailored to individual organizations. This can result in organizations achieving ISO certification without necessarily aligning their management systems with their strategic goals. Perceived Bureaucracy: The implementation of ISO standards can sometimes be viewed as bureaucratic, especially by employees who may feel burdened by additional administrative tasks. This perception may hinder employee engagement and commitment to the principles of the ISO management system. Overemphasis on Documentation Compliance: In some cases, organizations may prioritize demonstrating compliance with documentation requirements rather than focusing on the underlying principles and effectiveness of the management system. This can lead to a superficial adherence to ISO standards without realizing the intended benefits. It's important to note that these weaknesses do not negate the overall value of ISO standards. Organizations should carefully consider their specific needs, industry context, and strategic objectives when deciding to adopt and implement ISO management standards. Integrate Processes Governance, Risk, and Compliance (GRC) frameworks are an example of this approach. GRC is a holistic framework that integrates three critical components of organizational management: governance, which involves the establishment of structures and processes for decision-making and accountability; risk management, which focuses on identifying, assessing, and mitigating potential threats to an organization's objectives; and compliance, which ensures adherence to relevant laws, regulations, and internal policies. The GRC framework aims to harmonize these elements to promote effective decision-making, mitigate risks, and ensure compliance with legal and regulatory requirements. Within a GRC framework, governance sets the tone for the organization by defining its strategic objectives and establishing the framework for decision-making. It involves the allocation of responsibilities, creation of policies, and development of communication structures to guide the organization toward its goals. Risk management within GRC involves the identification, assessment, and prioritization of potential threats to the achievement of objectives. This proactive approach enables organizations to implement strategies to mitigate risks and capitalize on opportunities effectively. Compliance, the third pillar of GRC, ensures that an organization operates within the bounds of relevant laws, regulations, and internal policies. It involves monitoring, reporting, and taking corrective actions to address any non-compliance issues. The GRC framework operates synergistically, providing a structured approach to managing the complex interplay between governance, risk, and compliance. Implementation often involves the use of technology and specialized software solutions to streamline processes, enhance visibility, and facilitate real-time monitoring. GRC frameworks not only help organizations avoid legal and financial pitfalls but also contribute to overall business resilience and sustainability. By embedding a culture of accountability and transparency, GRC facilitates the establishment of robust internal controls, ultimately leading to improved decision-making, stakeholder trust, and long-term organizational success. Potential Weaknesses While Governance, Risk, and Compliance (GRC) frameworks offer valuable tools for managing and aligning organizational processes, they are not without potential weaknesses. Here are some common weaknesses associated with GRC frameworks: Complexity : GRC frameworks can be intricate and complex, particularly in large organizations. The complexity may lead to confusion among employees and make it challenging to implement and maintain the framework effectively. One-Size-Fits-All Approach : Some GRC frameworks may adopt a generic or standardized approach that might not suit the specific needs and nuances of an organization. This can result in inefficiencies and may not adequately address the unique risks and compliance requirements of the organization. Lack of Integration: Integration is the by-word of GRC and issues may arise if the GRC framework is not well-integrated with existing business processes and systems. Siloed information and disconnected processes can hinder the effectiveness of risk management and compliance efforts. Overemphasis on Conformance : In some cases, organizations may focus too heavily on adherence to procedures, neglecting the broader aspects of governance and risk management. This can lead to a reactive approach rather than a proactive one. Resistance to Change : Implementing a GRC framework often requires significant changes in organizational culture, processes, and structures. Resistance from employees and stakeholders can impede successful adoption and implementation. Resource Intensive: Developing, implementing, and maintaining a GRC framework can be resource-intensive. Small and medium-sized enterprises may find it challenging to allocate the necessary resources for a comprehensive GRC program. Technology Dependence : Some organizations heavily rely on technology solutions for GRC management. While technology is essential, over-dependence on tools without a solid understanding of underlying principles and processes can be a weakness. Inadequate Communication : Effective communication is crucial for the success of any GRC framework. Weaknesses may emerge if there is a lack of clear communication regarding roles, responsibilities, and expectations related to governance, risk, and compliance. Insufficient Training and Awareness: Employees may not fully understand the importance of GRC or their roles in the framework. Lack of training and awareness can result in non-compliance and ineffective risk management practices. Despite these weaknesses, a well-designed and effectively implemented GRC framework can provide substantial benefits to organizations. It's crucial for organizations to carefully tailor GRC practices to their specific needs, regularly assess their effectiveness, and continuously improve their approach to governance, risk management, and compliance. Operationalize Systems Lean TCM (developed by Lean Compliance) is an example of this strategy. Lean TCM takes a different approach from other methodologies by considering a different set of questions: What would compliance look like if it was already an integral part of the value chain? How could effectiveness be realized right from the start? What is necessary to meet all obligations and keep promises? How would it need to operate and what is essential for operability? Instead of standardizing and integrating all the pieces of a “broken” system at the task or process level, Lean TCM endeavours to establish an integrative operating model that works at the point where obligations become promises. Lean TCM operates in the middle of an organization, bridging the gap between outcomes and objectives which is essential to achieve effectiveness (i.e. the realization of benefits). Unlike traditional compliance approaches, Lean TCM does not replace existing management standards; instead, it elevates them to a higher level, providing essential capabilities that extend beyond mere certification. It addresses both Compliance 1 (rules and practices) and Compliance 2 (targets and outcomes), encompassing legal and social licenses to operate. This framework serves as a guiding navigator for organizations, ensuring the right balance between reactive and proactive behaviors and practices. Drawing inspiration from various management disciplines such as Total Quality Management, Continuous Improvement, Lean Startup, Hoshin Kanri, ISO standards (e.g., ISO 37301 for CMS and ISO 31000 for RM), Performance Management, Promise Theory, and Cybernetics, Lean TCM is designed to tackle modern-day compliance challenges. It enables organizations to not only achieve more benefits than certification alone but also handle regulatory and stakeholder obligations efficiently. The framework emphasizes sustainability, trust-building, and the fulfillment of obligations, equipped with strategies for improvement, alignment, and accountability at every organizational level. The Lean TCM Framework provides organizations with a holistic, proactive, and integrative approach to operate in highly regulated and high-risk environments. It serves as more than just a means to an end, defining an operational approach for sustainable mission success. The Operational Compliance Model within Lean TCM ensures that compliance is not just a set of rules but an operational function, achieving Minimal Viable Compliance (MVC) by incorporating regulatory design principles derived from systems theory and cybernetics. Additionally, Lean Compliance offers advanced programs such as The Proactive Certainty Program™ and The Elevate Compliance Program, both designed to facilitate compliance transformation, strengthen defenses, and address modern compliance challenges with assurance. Lean TCM emphasizes the following: You start with something that is already operational, simpler, and capable of delivering benefits. The point of intervention happens where obligations align with promises, outcomes align with objectives, and the ends align with the means. Adds the function of management programs missing from management system standards, including GRC frameworks. Implemented using Lean Startup to accelerate learning and improvement Focuses on outcomes and operational risk. Harnesses lean principles to reduce waste to create the opportunity for proactive improvements. You learn to drive towards compliance outcomes by driving right from the start. Weaknesses: While Lean Total Compliance Management (Lean TCM) offers a robust framework for organizations to enhance their compliance efforts, there are certain weaknesses associated with this approach: Novel Implementation (lean startup): Lean TCM utilizes the Lean Startup approach which may not be as familiar to those who have followed traditional bottom-up approaches. Resource Intensiveness: Similar to other comprehensive compliance frameworks, Lean TCM may demand significant resources, both in terms of time and financial investment. Smaller organizations or those with tight budgets may find it challenging to allocate the necessary resources for successful implementation. Resistance to Change : The introduction of a holistic and integrative compliance approach may face resistance from employees accustomed to traditional compliance methods. The shift towards a proactive and operational compliance culture might encounter pushback, requiring effective change management strategies to ensure successful adoption. Limited Experience : While Lean TCM incorporates well known principles and practices from different domains, its overall approach may not be as familiar. This could pose a challenge for organizations looking for traditional methods. Not Elevating Minimal Viable Compliance : While the concept of achieving Minimal Viable Compliance (MVC) is integral to Lean TCM, there is a risk of organizations focusing solely on meeting the minimum requirements rather than striving for continuous improvement and excellence in compliance practices. Dependency on Existing Capabilities: Lean TCM emphasizes elevating existing resources for compliance benefits. However, organizations with inadequate existing capabilities or those lacking a strong foundation in relevant management principles may struggle to realize the full potential of Lean TCM. Limited Industry-Specific Guidance : Lean TCM provides a broad framework applicable across various industries and compliance domains, but it may lack specific guidance tailored to certain sectors with unique compliance challenges. Organizations in highly specialized fields may need to supplement Lean TCM with industry-specific expertise. Potential Overemphasis on Effectiveness: The focus on outcomes may lead to an overemphasis on outcomes potentially neglecting the importance of efficiency. Despite these weaknesses, organizations can mitigate challenges by carefully assessing their specific needs, participate in educational programs, and develop a tailored roadmap for their organization. An Aside From the Past For those working in the IT industry in the 90’s may remember using CORBA ( www.corba.org ). The CORBA approach is based on the concept of a middleware infrastructure, known as the Object Request Broker (ORB), which facilitates communication and interaction between distributed objects. Back then we attempted to create business objects written in Java for every object of interest to the business which would then be integrated together using a CORBA broker. Sounds great! It also sounds very familiar and similar to the approaches taken by GRC frameworks and to a lessor degree management system standards. As you can imagine, there was not enough time, energy or funding to define and integrate everything, so CORBA implementations usually failed. This is an important lesson for any holistic approach particular those that depend on tight coupling of objects and the need for everything to be perfect. This is something that Lean TCM attempts to address by operating in the middle, above the task and procedure level, and using concept of minimal viable programs (MVPs), which can elevated over time. Implementing CORBA also taught me that just because you integrate everything together doesn’t mean you will end up with more than you started with apart from now having to manage all the integration touch points. When you connect reactive processes together you still end up with a reactive system. Integration only makes sense when used to build a system that is capable of delivering benefits which is something that many organizations fail to understand. Summary In this article we explored three key strategies for achieving success in compliance within highly regulated, high-risk environments. The common challenge faced by organizations in these environments is effectively governing their operations to meet obligations and stakeholder commitments while bridging the gap between organizational outcomes and operational objectives. The strategies discussed include standardizing practices, integrating processes through Governance, Risk, and Compliance (GRC), and operationalizing systems with Lean Total Compliance Management (Lean TCM). The first strategy involves standardizing practices using management standards, which provide recognized guidelines to enhance efficiency, reduce risks, and meet stakeholder expectations. While management system standards offer valuable guidance, potential weaknesses include rigidity, resource intensiveness, and a potential overemphasis on documentation compliance. The second strategy focuses on integrating processes through GRC frameworks, harmonizing governance, risk management, and compliance. Despite its advantages, GRC frameworks have potential weaknesses, such as complexity, a one-size-fits-all approach, and the challenge of integration with existing business processes. The third strategy introduces Lean TCM, a unique approach developed by Lean Compliance that operationalizes obligations by integrating compliance into the value chain. Lean TCM addresses Compliance 1 and Compliance 2 requirements, offering a holistic, proactive, and integrative approach. However, potential weaknesses include its novel implementation using Lean Startup, limited industry-specific guidance, and potential resistance to something different. In essence, each strategy has its strengths and weaknesses, and organizations must carefully consider their specific needs, industry context, and strategic objectives when choosing a compliance approach. While ISO standards, GRC frameworks, and Lean TCM offer valuable insights, successful implementation requires a tailored approach, ongoing assessment, and a commitment to continuous improvement.
- Shingo Model: 3 + 1 Insights to Achieve Organizational Excellence
With compliance in all of its manifestations (safety, security, sustainability, quality, environmental, regulatory, etc.) taking on a more integral role in the operations of an organization it also takes on greater responsibilities. One of these is the pursuit of operational excellence. Operational excellence refers to an organizational philosophy and management approach that focuses on consistently achieving optimal performance and efficiency in all aspects of business operations. It involves the continuous improvement of processes, systems, and workflows to enhance productivity, reduce waste, and deliver high-quality products or services. Operational excellence is often associated with Lean management principles, Total Quality Management (TQM), and other methodologies that aim to create a culture of continuous improvement. The Shingo Institute (home of the Shingo Prize) is a non-profit organization that focuses on promoting organizational excellence using a methodology that has gained prominence for its transformative approach to achieving operational excellence and continuous improvement. At the heart of the Shingo Model™ are three pivotal insights that guide organizations toward mission success. In this article, we delve into these insights along with one that we learned as part of Lean Compliance and explore how these are beneficial to compliance excellence: Insight #1: Ideal Results Require Ideal Behaviour, Insight #2: Purpose and Systems Drive Behaviour, Insight #3: Principles Inform Behaviour, and Insight #4 : Programs Elevate Systems (Lean Compliance) Insight 1: Ideal Results Require Ideal Behaviour Central to the Shingo Model™ is the understanding that achieving ideal results necessitates cultivating ideal behaviours within an organization. This insight emphasizes the critical role of leadership in setting the tone for expected behaviours. Leaders are urged to inspire and model the behaviours that align with the organization's goals, fostering a culture where everyone is committed to excellence. By promoting a mindset where individuals take ownership of their actions (along with obligations) and continuously strive for improvement, organizations can create a ripple effect of positive behaviours that lead to optimal outcomes. This insight encourages leaders to not only focus on end results but to also consider the behaviours and practices that drive those results. Insight 2: Purpose and Systems Drive Behaviour The second key insight of the Shingo Institute Management System underscores the influence of purpose and systems on shaping organizational behaviour. Purpose serves as a guiding force, aligning the actions of individuals and teams with the overall mission and vision of the organization. When individuals understand the purpose behind their work, they are more likely to engage in behaviours that contribute to the achievement of organizational goals. Additionally, systems play a crucial role in influencing behaviour. The design and structure of systems within an organization can either support or hinder the desired behaviours. The Shingo approach encourages leaders to examine and optimize systems to ensure they drive behaviours that align with the organization's purpose and goals. Insight 3: Principles Inform Behaviour The third insight centres around the idea that principles inform behaviour. The Shingo Institute Management System is built on a set of guiding principles that serve as a compass for decision-making and action. These principles, which include humility, respect, and continuous improvement, are the foundation for creating a culture of excellence. By embedding these principles into the organizational DNA, leaders can guide behaviour at all levels. Principles inform the choices individuals make, the way teams collaborate, and the overall culture of the organization. This insight emphasizes the importance of aligning actions with enduring principles to foster a sustainable culture of excellence. Insight 4: Programs Elevate Systems (Lean Compliance) This insight comes from Lean TCM (Total Compliance Management) emphasizing the idea that management programs elevate system performance. Whereas, systems are designed to resist change by removing variability, management programs introduce change to advance outcomes. Management programs drive system performance levels needed to advance targeted compliance outcomes. In essence, programs regulate systems towards desired outcomes in the same way that systems regulate processes toward desired outputs. This insight emphasizes the importance that to achieve better outcomes you need programs to elevate systems. Conclusion The Shingo Institute’s along with the Lean Compliance Model offer profound approaches to organizational and compliance excellence. By recognizing the interplay between ideal behaviour, purpose-driven systems and programs, and guiding principles, organizations can create a framework for continuous improvement and mission success. Embracing these insights empowers leaders and teams to cultivate a culture where behaviours are aligned with organizational goals and obligations, driving sustained excellence and adaptability in a dynamic business environment.
- Controls without Systems are not Controls
Controls without systems are not controls, they are only processes. In many compliance domains meeting obligations is seen as a controls problem. As a result, documenting, building, managing, and monitoring controls is at the forefront of compliance activities. This is reinforced if not driven by industry management system standards which conceptualize compliance in the same way and provide a long list of controls that you “should” implement. However, focusing solely on controls often results in losing sight of the big picture. Many have lost sight of the forest for the trees. Controls are processes that adjust operating system parameters to maintain output between targeted values. Technically, controls perform the function of regulation needed to achieve compliance to a given standard of performance. This applies to all systems including socio-technical ones. However, all too often controls are implemented without knowledge of what they are intended to control, how they work, or what they are supposed to accomplish. Many may not be connected to the systems they are intended to control. They may even operate at cross-purposes implemented to work separately and not together. This is definitely a significant source of compliance waste. Instead of compliance systems, many organizations have control management systems often not doing more than mapping controls to regulatory elements. They might even have all the boxes checked and able to pass an audit. What many organizations don’t have (but need) are controlled systems to deliver on commitments associated with their obligations. They need systems capable of creating the outcomes of compliance. Compliance is about regulation and you cannot regulate without a system – you cannot regulate with controls alone. If you are not realizing desired outcomes from your compliance efforts, check to make sure your controls are connected, operational, and are effective at regulating your safety, security, sustainability, quality, environmental, regulatory and ethics systems. Don’t lose sight of compliance for the controls.
- Is Your Compliance Regulating Fast Enough?
Modern compliance must regulate at faster rates to keep an organization always on-side and operating between acceptable safety, security, sustainability, quality, regulatory and ethical levels. In an electrical circuit, voltage regulation (maintaining a consistent voltage level) is achieved using a feedback process that measures the output to adjust the circuit to remove variation from the output. In modern switch-mode power supplies this happens at a frequency between 20,000 to 2 million cycles per second. In theory, the frequency of regulation is chosen to be fast enough to maintain variation in the output within acceptable levels. The greater the variation in input voltage the higher the regulation frequency needs to be. This is not unlike how audit-correction cycles work. In theory, audits and corrections should happen as frequently as necessary to maintain adherence to standard within acceptable levels. The number of days spent operating outside the lines along with the time it takes to return to acceptable levels are measures of compliance effectiveness and performance respectively. However, what many don't consider is: The more often things change, the higher the frequency of audits need to be. Let’s assume you audit conformance to prescribed controls once every year. It's therefore possible to be off-side for an entire year before it’s noticed plus the time it takes to correct the deviation – hopefully before the next audit. In the worst case, it could be two years before you get back on-side. What impact would being off-side for two-years have on your operations? That’s why audits are often too slow and too late to protect value creation. Never mind that audits seldom evaluate effectiveness against targeted compliance goals and outcomes. As change can be a significant source of risk, organizations in highly regulated, high-risk sectors use a Management of Change ( MOC ) process to keep up with the speed of risk due to planned changes. This process functions as a real-time compliance regulator to keep an organization always operating between the lines. Here are a few questions to consider when planning your compliance: How long do you wait before knowing when you are off-side? What are acceptable levels of effectiveness and performance for compliance? What capabilities and capacities do you need to regulate your compliance to meet your measures of success? What strategies can you apply to always stay between the lines?












