SEARCH
Find what you need
Search this site
615 results found with an empty search
- Not All Holes Are Hazards
Not all holes are hazards, not all risks matter The risks that matter are between you and your objective.
- Why IT is Failing Compliance
In the IT industry where I spent much of my early career, a significant amount of resources are dedicated to integrating components together. This is needed to build enterprise solutions made from capabilities across a variety of existing and new technologies. A common architectural principle used for this kind of integration is to minimize coupling, how tightly they are connected, between the solution and its components. That way you can, in theory, replace the components with something else downstream. You can also avoid unintended side effects when code changes. Along with the design goal to achieve loose coupling it is also standard practices to achieve a high-level of encapsulation – hiding the internals of the components from the solution that uses it. Both of these design principles are intended to minimize disruption arising from future changes to either the solution or its components. While these design principles makes sense for IT solutions, they are not what's needed for compliance. Instead, compliance needs to achieve a tighter coupling and greater transparency with the value chain. You could say in technical terms, there is an impedance mismatch between IT and compliance objectives. What Compliance Needs from IT Compliance needs an integrative approach with the value chain not just integrate with it. This also applies to the tools an technologies that are used to support compliance. However, IT solutions struggle to realize these principles particularly SAAS and cloud applications. While they may integrate with your business they seldom provide the means for compliance to be an integral part of the value chain so that the business always knows if it is operating between the lines. Negotiating the cultural and architectural differences between compliance and IT is critical for compliance to achieve higher levels of performance and effectiveness. This is more important now with the advent of artificial or rather machine intelligence where we need greater levels of transparency, explain-ability, and trust.
- The Need For Digital Twin Safety
Digital twins are virtual counterparts of physical entities that merge real-time data from sensors and IoT devices with sophisticated analytics and simulation, facilitating monitoring, analysis, and optimization of operations and assets. Alongside benefits of Digital Twins, the integration of Artificial Intelligence (AI) introduces additional considerations and risks commensurate with how digital twins are used either as a Digital Shadow, Decision Support, or for Autonomous Control: Digital Shadow: Digital twins provide real-time representations of physical entities, offering insights without direct interaction. AI algorithms enhance the analysis of data within digital twins, but they also introduce the risk of bias or errors if not carefully trained and validated. Moreover, AI-driven decisions may be opaque, making it challenging to understand their rationale and assess their reliability. Decision Support: Digital twins can serve as decision support tools by providing actionable intelligence through advanced analytics and simulation. AI algorithms within digital twins enable predictive modeling and optimization, but they may also amplify errors or biases present in the data. Additionally, complex AI models may lack interpretability, hindering decision-makers' ability to trust and understand their recommendations. Autonomous Control: Digital twins in its most advanced state enable autonomous control by acting on decision-making based on real-time data and predictive insights. AI algorithms drive autonomous actions within digital twins, enhancing efficiency and responsiveness. However, they also introduce risks of malfunction or adversarial attacks, potentially leading to unintended consequences or safety hazards. Additionally, AI-driven autonomous systems may face ethical considerations regarding accountability and transparency in decision-making. While the integration of AI enhances the capabilities of digital twins, it also introduces considerations related to algorithmic bias, interpretability, and system reliability. Addressing these considerations requires rigorous validation, transparency, and ethical oversight to ensure the responsible and effective use of AI within digital twin technologies across diverse applications and industries. Digital Twin Safety In light of the risks associated with digital twins, particularly when integrating Artificial Intelligence, establishing robust safety programs is imperative to protect the public and effectively contend with potential risks. A comprehensive Digital Twin Safety Program should encompass rigorous risk assessment, validation, and continuous monitoring mechanisms. This involves identifying and evaluating potential risks arising from data inaccuracies, algorithmic biases, cybersecurity threats, and system malfunctions. Additionally, the safety program should prioritize transparency and accountability in decision-making processes, ensuring that stakeholders understand the basis of AI-driven actions and can intervene if necessary. Regular audits and evaluations of digital twin systems are essential to identify emerging risks and adapt mitigation strategies accordingly. In addition, collaboration between industry stakeholders, regulatory bodies, and technology developers is crucial to establish standards, guidelines, and best practices for the responsible deployment of digital twin technologies that use machine intelligence capabilities. By implementing robust safety programs, organizations can mitigate risks, safeguard public welfare, and foster trust in the use of digital twins across various domains.
- Prioritizing CI Projects – Mission Impossible?
Continuous improvement is needed across all business functions including those that are responsible for safety, security, sustainability, quality, regulatory, and other stakeholder obligations. Whether you are responsible for maintenance, continuous improvement, or capital projects there comes a day when you need to provide an answer to which projects you should do and in what order to improve the probability of mission success. Let’s imagine that today you are that person who has to decide. Here is your challenge should you chose to accept it: Mission Possible Note: while this scenario is fictitious, it is based on real-world examples I have been involved in over the years. Scenario You are the CI Officer responsible for continuous improvement across your organization. You have compiled a list of candidate projects that promise improvements to productivity (margin, throughput, costs, waste, etc.) as well as better outcomes for compliance, quality, safety, security, and so on. Some of these projects depend on others, and some may cause significant disruption before benefits are realized. Each has different costs, benefits, and risk associated with them. Some may actually fail, and some are critical to mission success. You need to decide which ones to do and in what order so they don’t compromise current outcomes or productivity. In other words, improvements can’t break the bank or the business. Ideally, changes (on the whole) should generate financial gains sufficient to fund other projects creating a virtuous cycle of improvement. Problem Create a self-funding continuous improvement (CI) portfolio providing a rank order of projects that optimizes overall outcomes and productivity while avoiding negative impacts to the business. Assume the first set of projects will receive sufficient capital to get things going. This initial set should be optimized to minimize the initial investment but sufficient to create future gains to fund successive improvements based on the rank ordering of projects. New projects will be added at the end of each year and incorporated into the portfolio of projects. Assumptions and Constraints Your organization provides highly regulated services to customers. Your organization is organized as functional teams with hierarchical management. Advancing outcomes is preferred over cost reductions. The project portfolio should be self-funding beyond the initial seed investment. Mission critical projects have highest priority. No staff reductions. Eliminated resources will be reallocated to support further improvements. Assume a 5 year planning horizon with 20% new projects added each year. Assume that 33% (1/3rd) of the projects are critical to mission success but with various degrees of criticality. Methodology and Approach How would you meet this challenge? What approach would you use? What principles could be applied to categorize and select projects? What additional information do you need to know about the business, projects or otherwise? What capabilities are needed to meet the portfolio objectives? How would you ensure improvement benefits are realized? How would you manage and measure progress across the five years? And finally, would you accept this challenge? Why or why not?
- We Don’t Live in Models; We Live in Reality
With all the talk about artificial intelligence it’s easy to get caught up in a world of machine models, digital twins, and virtual reality. It’s important to remember that we don’t live in these worlds; we live in reality. The world we live in is not the “Matrix” nor is it a game we can start over with a push of a button. We have one life to live and one world to live in. The question is how best to live our real lives in the real world. May we have the courage to face and meet the demands of reality rather than escaping to simulated worlds with artificial friendships and artificial lives.
- Don’t Confuse Computer Programs with Compliance Programs
Many organizations identify the need for a program to help them meet all their compliance obligations. They will then procure a computer program (or a suite of them) that claims to be the best solution to their compliance challenges and help them achieve compliance success. After implementation, they may observe the solution has helped them report on data and metrics, store and manage procedures, keep track of controls, and remind them when to get ready for their next audit. However, many will also discover their quality, security, safety, sustainability, or environmental outcomes have not improved. They are still just as uncertain as they were before that their compliance efforts are making a difference to what really matters. What they most likely thought they purchased was a compliance program; something that could actually advance outcomes and help them stay ahead of risk. A computer program while necessary to manage information and may help to achieve certification is not enough for compliance success. If you want to make a qualitative difference to compliance outcomes you need a compliance program and preferably one that is operational. Don’t make the mistake between computer and compliance programs. Make sure you have what you really need for mission and compliance success.
- Training Users To Be Unethical
The decline of moral integrity Every time we skip past an EULA (end-user license agreement) and just click the checkbox we give up something and probably more than we realize. We have given up: our data our privacy rights our software ownership the content we create and other things that may not be in our best interest. But more than all of those, we have given up our moral integrity. This doesn't mean these practices were necessarily illegal or in violation of any government regulation. However, slowly but surely, we have agreed to practices that in some cases were arguably unethical, unjust, unfair, and unwarranted. Even the act of not reading the EULA but signing it anyways has ceded moral territory. We reinforced by our actions that these licenses don't matter and what we are giving up doesn't matter as well. We were implicitly being asked to "just trust." And here's the thing, by agreeing to what is unethical we become more unethical ourselves. Over-time we lower our standards, our values and our morality. And for what? Who knows what else we might agree to knowingly or unknowingly for the promise of a shiny new application, platform or AI chat-bot. How far are we willing to lower our standards? There is more at stake then access to software; we are at risk of losing our souls. With the rise of Artificial Intelligence systems, the demand for data and access to our digital representations are growing without bounds. Many have already naively given up confidential corporate and private data to AI chat-bots putting themselves and their businesses at risk. We are placing our trust in something where trust was not earned. We haven't performed our due diligence. We did not ask critical and important questions. We just clicked the box. How did we get here? It's not hard to believe that years of skipping EULAs has trained us to just trust in technology and the organizations behind them. Don't look too closely or ask too many questions, and don't read the small print. Just click the box and everything will be fine. We may believe we don't have any choices, but we always do. Don’t accept anything that weakens your ability to live by your higher standards or might otherwise comprise your moral integrity.
- Zones of Compliance
Which Zone Are You Operating In? Regulatory designs of which there are four primary types spanning micro-means to macro ends, demand different operational capabilities for compliance. In fact, at least half an organization's obligations are non-legal requirements having more to do with outcomes and performance rather than rules or controls. Meeting all these obligations requires measures of conformance, measures of performance, measures of effectiveness, and measures of assurance. To establish these capabilities organizations must transform how they address compliance. They need to take on operational principles and practices that help ensure that essential functions, behaviours, and interactions are working at levels sufficient to create the outcome of compliance. However, many organizations are caught in a prescriptive, reactive, and reductive trap where audits, complaints, and incidents are the only drivers for change. They are operating at the edge of uncertainty; one violation, one injury, one defect, or one mishap away from mission failure. They are in operating in the: REACTIVE COMPLIANCE ZONE. It’s here that compliance functions as a guardrail; the last line of defence at the end of the line. Instead of operating at the edge of uncertainty, ethical and forward-thinking organizations operate in the: PROACTIVE COMPLIANCE ZONE. It’s there where compliance functions as an offensive force ensuring that organizations are always between the lines and ahead of risk. Instead of a guard rail, compliance is a dynamic enabler of compliance outcomes, proactivity, and holistic improvements triggered by the presence of uncertainty not only incidents that happened in the past. Operating in the PROACTIVE COMPLIANCE ZONE creates a strong compliance culture ensuring not only compliance success but also mission success.
- Don’t Fly with Only One Wing
Can you have a balanced scorecard without compliance? When it comes to navigating organizations many use a balanced scorecard (BSC) to keep their businesses in the air and on course. A balanced scorecard maps strategic measures and initiatives to appropriate aspects of the business. Along with value chain activities many only use one wing to keep them aloft — productivity programs. Productivity programs improve margin to contend with aleatory uncertainty (having to do with chance) to cover losses that cannot be avoided or reduced. However, there are other outcomes that a company needs to achieve such as: safety, security, sustainability, quality, regulatory, and more. It’s here that certainty programs are used to achieve compliance associated with buying-down risk that is reducible – those connected with epistemic uncertainty (lack of knowledge). Certainty programs create a second wing that truly balances corporate activities to keep businesses flying in the air and on course towards total value. Compliance failure means mission failure. To ensure mission success make sure compliance is part of your Balanced Scorecard.
- Cleaning Up Your Documents Before The Auditor Comes Over
When it comes to audits there is a popular meme that goes something like this: Before the audit : documents out of conformance During the audit: documents in conformance After the audit : documents out of conformance We like to laugh at this, and many just say it’s just human behaviour. When do we clean up our home? Right before our friends and family come over. It’s just what we all do. However, I believe the problem is much worse than waiting to tidy up our house. The problem has more to do with our behaviours throughout the year rather than the condition of what is being audited. So what’s going on? Why do we wait until people come over before we tidy things up when we could experience the benefits from having a place for everything and every thing in its place? In the case of our homes, we may value the approval of others more than experiencing the benefits of living in clean and tidy home. We may also not want or can not put in the effort to keep our homes clean. We need to be compelled by external forces more than our internal values. In some ways we are behaving like children having always to be told to clean our rooms. When it comes to audits we value a stamp of approval more than doing what we know is right all the time. This demonstrates a lack of integrity, and frankly also a lack of honesty. However, that’s not the worst of it. Companies hoping to act more like adults will conduct pre-audits to get ready for an internal audit to get ready for an external audit. If that sounds absurd – it is. This train of audits may improve the chances of passing an audit but it doesn’t address the problem of motivation. Henry Ford was right Henry Ford once said, “Quality is doing it right when no one is looking.” He was right. Not only is doing the right thing when no one is watching a measure of quality, it’s also a measure of integrity. And that's why ethical, forward-looking companies practice proactive compliance. Instead of waiting for an auditor to tell them if they were off-side they establish measures to make sure they never are. They always keep their rooms clean because they know it’s the right thing to do. They also know that it will deliver benefits. These organizations are able to say: “Audit us whenever you like. We already know the answer." They can also say: "The time we are saving by avoiding excessive audits we use to get ahead of our competition who spend their time getting ready for their many audits, performing corrective and preventive actions, and paying back for losses from not meeting their obligations throughout the year.” It's not about audit readiness The goal is not to always be ready for an audit as many suggest. That still focuses too much on external motivation. Instead, the goal is to behave with integrity. This means keeping the promises we made connected with our legal license to operate and stakeholders expectations. We need to become an organization that our stakeholders can trust not because we pass an audit once a year but because we are trustworthy, reliable, and keep all our promises everyday – all day. You can continue to practice reactive compliance and perhaps even reduce some of your losses. Or You can practice proactive compliance and avoid the losses altogether, and experience the benefits that come from always being between the lines and ahead of risk. So, clean up your documents and put in a process to keep them always evergreen. Do it not because you are told, but because you are keeping your promise to meet all your obligations.
- Alignment Conversations - A Dialog Towards Program Success
When it comes to compliance a lack of clarity and alignment often leads to program failure. This manifests in many ways that include discontent, negative attitudes, lack of motivation, and a lack of engagement from obligation owners along with those responsible for the work of compliance. Ultimately, misalignment leads to obligations not being met, promises not kept, and an increase in overall compliance risk. Alignment is a measure of compliance integrity. Achieving and maintaining alignment is therefore an important performance objective for all compliance programs whether that is safety, security, sustainability, quality, regulatory, ethics, or other managed outcomes of the organization. Establishing alignment based on the five principles of program success is a good place to start and will help identify areas of improvement. Are we aligned on: Destination : the outcomes, our goals, where we are heading? Strategy : the plan and approach to getting to our destination? Capabilities : the resources, budget, talent, technologies, functions, and time needed to follow the strategy? Obstacles and Opportunities that need to be negotiated or exploited to improve the probability of success? Measures of Success : measures of effectiveness, performance, conformance, and assurance? Having conversations and dialog around these questions can be difficult particularly when existing answers are vague and ambiguous. You may need to clarify these first which when done in a participatory fashion will help also improve alignment as well. Sometimes having an outsider lead the discussion can help diffuse tensions, help identify important insights, and facilitate a successful outcome. We need to always remember that it's not the plan but the planning that is most important. These conversations should be held periodically and used to drive continual improvement towards program success. This contributes to the development of a virtuous cycle of conformance where things get better and the faster things get better over time. And It all begins with a conversation. Lean Compliance offers a "Plan for Success" kaizen (change for the better) engagement to help you and your team create a risk-based plan for program success: Facilitator led workshop to develop risked-based compliance plan for your program based on the 5 principles of program success. Engagement: 5 Sessions / 1.5 Hours Each / Teams of 4 or less Format: Facilitated, Online (Zoom) Outcome: Compliance Program Plan for Success Use this engagement to help facilitate greater team and program alignment.
- Why I Conduct Team Meetings on Mondays
As a young engineer in the 1990s, I took on the role of IT Manager, my first management position. Now, for those that can remember, IT at that time was exploding on the scene. Communication, information and computing were expanding in capabilities, scope, and scale across all businesses and sectors around the world. We were experiencing the beginning of the digital era and things were happening. The company I worked at was an Integrated Circuit (IC) manufacturer, one of only a few in Canada. As a business we too were shifting from analog to digital circuits. From an IT perspective, we had just started our journey away from mainframes to client-server topologies, local networking to the web, MRP to ERP, and PCs were being used at work and also in the home. On the design and engineering front, we were adopting advanced Computer Aided Design (CAD) technologies (Mentor and Silicon Graphics), we were developing software to support data collection and automation. We were building databases as fast as we could manage, along with implementing Commercial-Off-The-Shelf (COTS) document and records management solutions. At the same time, we were adopting ISO standards for quality, SPC, six sigma, and what we now call LEAN. Imagine Khan-ban on the shop floor of an integrated circuits manufacturer! IT was involved in everything and in many ways leading the charge. It was common practice for managers to meet with their staff on Fridays to review the status of the week’s activities. So, that’s what I did as well, at least at the start. It didn’t take too long for me to realize this was not working. Our weekly meetings were spent discussing what we did rather than what was needed for the week ahead. We had too much to do to focus only on the past. When we finally came to "Next Steps" we almost always ran out of time. At this point, physiologically, we were also thinking more about the weekend. This all made sense, but something needed to change. As a young manager and wanting to prove myself I decided to make a bold move. We shifted our staff meeting to Monday. This practice, was against the norm. However, what I would later find out, this shift changed everything for the better. We still spent time talking about the activities of the prior week. However, our gaze was clearing set on the week ahead and what we needed to do as a team to succeed. We started to change from reactive thinking, focused on what was or wasn’t done to proactive thinking, focusing on what's needed to meet our objectives going forward. We were also in a better mindset. Having come back refreshed from the weekend we were now ready psychologically to face the future. The morale of my team picked up, instead of feeling always behind we started to get ahead. We felt we had more agency to negotiate the obstacles and exploit the opportunities that were in front of us. We felt we could succeed, and we did. Years have passed since my early days as a manager. IT has moved onto the cloud, managing outsourced services, integrating dev-ops, deploying mobile, internet-of-things and platforms, adopting cybersecurity, and AI among other things. Businesses also use far more management standards across almost every domain. What has not changed is: Uncertainty and risk are still knocking on our front door. Just like back when I was a young manager, we need to be proactive. Unfortunately, the common practice for management still has not changed. For many it's still reactive and focused on the past. In fact, the majority of management standards call out the need for management review which is very much like meeting with staff on Fridays. It's time to make a bold move. Change your management reviews to management previews. Meet with your staff on Mondays when your mindset is on the future and when you can still do something to improve your probability of success. Take it from me, it will change everything for the better.












