SEARCH
Find what you need
Search this site
615 results found with an empty search
- Agile Compliance
Organizations of all shapes and sizes utilize systems to ensure that the right work gets done at the right time in the right way. In fact many will have a system of systems to manage them all. However, over the years what I have noticed is many of these systems end up as little more (and far less) than the sum of their parts: processes, activities, tasks, etc. Systems rarely do or ever create the intended outcomes at the levels needed by the organization. There are many reasons for why this is the case. One of these reasons, which I have discussed before, has to do with the approach chosen for system implementation. Many implementations use a component-first approach using phases to build out capabilities over time to finally reach a system that is "effective." Unfortunately, the final state of "effective" is seldom reached. As a result companies end up with systems that do not fulfill their purpose and in many cases are barely operational. You might say that a component-first approach is the equivalent of the "waterfall" project methodology where benefits are realized only at the very end. This approach makes sense when you have a a high degree of certainty in both the ends and the means of what you are building. However, what if you needed to learn both what the ends are and the means to get there as you went along. Is this not what advancing capability maturity looks like? This kind of implementation requires a different approach. You would need a working system (i.e. operational) right at the start in the same way that "agile" focuses on having working software right at the start. In fact, this strategy is referred to as, "Lean Startup" which focuses no on having working code but having a working system or better – always having a system that works . This approach affords companies the opportunity to learn on an operational system to improve performance and effectiveness at every stage of system development. Benefits can be realized early rather than later and this is critical when it comes to advancing quality, safety, environmental and regulatory outcomes where the risks are high. Agile and Lean Startup are examples of system-thinking used in software development but also compliance solutions. The key is to take a holistic rather than reductive perspective when it comes to building a system. You can read more about the Lean Startup / Agile approach here . Members of The Proactive Certainty Program™ learn and use systems-thinking to reach operational and effective compliance faster and with high degree of certainty than traditional approaches. Find out more here .
- Good Things Take Time, Great Things Take a Little Longer
Over the last several years I have endeavoured to change the way we think and do compliance. Perhaps, a big hairy audacious goal (BHAG) as some might say. Others might even call it a fools errand. To be honest, it is hasn't been easy and it continues to be an uphill battle. As essential as compliance is, it is not the number one priority of things to improve or excel at for that matter. What has helped is knowing that I am not alone. There are others who are doing amazing things to help transform compliance. I have had the good fortune to connect with and work with some of you and look forward to meeting more in the months and years to come. What has amazed me is when I hear from someone who tells me that they have followed me on social media for a while, loved what we do, and have put the principles of lean compliance into practice to improve compliance in their organization. All I can say is, WOW. This is not an isolated case. I found your posts and the breadth of information you provide on compliance and risk topics to be particularly helpful in expanding my personal knowledge, as I am relatively early in my career and doing my best to learn on my own. I look forward to learning more from the generous amount of information you share freely on this platform. Grateful is an understatement. – Venessa Beunrostro (Compliance Analyst) It's not always possible to know how much we impact other people. However, sometimes you do hear and it reminds you why you work so hard to make a difference. Don’t underestimate the impact you are making. Good things take time, Great things take a little longer. Don’t give up. I am grateful to all those that have written to us and those who have not but have found our work helpful in supporting their compliance journey. Thank you for helping make our journey worthwhile.
- IS EDM DEAD?
Business processes require information to produce the desired outcomes. This information comes in various forms and is used in a variety of ways which cannot always be known in advance. However, there is a class of documents where it is necessary to control the format and its use in order to meet compliance requirements. Capabilities to manage these types of documents are needed today just as they were a few decades ago. However, in today's world of big data and artificial intelligence (AI) managing documents is not seen as important and some would even say no longer necessary. In fact, recently, some technology enthusiasts are proclaiming that electronic/enterprise document management (EDM) is dead or will be in the near future. The approaches and technologies used in the past no longer (if at all) work and should be abandoned in favor of newer technologies. There are many reasons that are typically given (several of which are well justified) as to why EDM has not provided the promised benefits. One key reason is that users still cannot find the documents they need even using EDM technology. EDM has traditionally relied on indexing documents using a classification scheme to locate documents. Developing and managing classification schemes is considered to be too costly, error prone, and not needed as you can just search the content within the documents directly. In Part 1, of this blog post we will look at this assertion, the state of EDM and reasons why it has not delivered on its objectives. In, Part 2, we will consider how to address these shortcomings and outline how EDM can be successfully implemented using existing technologies. HISTORICAL LESSONS To start, it is helpful to remind ourselves that similar statements about EDM have been made before. This tends to happen whenever newer technologies enter the marketplace. This was the case when full text was first introduced in the 90s. Leading vendors at that time advocated doing away with classification schemes. Forget about trying to manage data because we can find the data for you using our search technology. Today we hear the same argument from those that promote big data and artificial intelligence. Using full text search to discover information is useful and needed when looking for information stored in vast amounts of content. However, a critical problem with using these technologies is that they assume that the data is self-describing which means that data about the data (which we call metadata) is contained within the object we are looking for. If this is not the case then it becomes almost impossible to locate relevant information. It is worth noting that after many years of using the web and searching using the content alone we are now investing significant amount of time and money doing Search Engine Optimization (SEO) to improve search results. There are still problems with false positives and search accuracy. We are now inserting classification (i.e. metadata) back into documents in the form of keywords and tags so that the content we are looking for can be found. Google will get you close but not close enough which is a serious risk to compliance based processes. You can just imagine the consequences of retrieving and using the wrong procedure because the search engine returned a list of close but not exact matches to your query. Managing document classifications is necessary when the purpose is to deliver exactly the correct document to the correct person at the correct time. This is still something that search engines alone cannot provide and one of the key reasons why you still need EDM. WHAT IS EDM? EDM is simply a system to manage documents and is considered part of the overall domain of Enterprise Content Management (ECM). EDM manages the class of documents that need to be controlled because they are inputs to critical business processes in the same way that raw materials are controlled in manufacturing processes. We find that these documents are still mostly unstructured requiring data describing them to be controlled and managed outside the document itself. EDM also provides other capabilities to manage important aspects that are critical to compliance which have largely been forgotten. It is common when talking about documents to take a reductionist view and lump them in the general bucket of data. This perspective unfortunately removes important distinctions that characterize the nature of documents which can be seen when considering the following definition for a document: "Something tangible that records communication or facts with the help of marks, words, or symbols. A document serves to establish one or several facts, and can be relied upon as a proof thereof. Generally speaking, documents function as evidence of intentions, whereas records function as evidence of activities" This definition suggests several characteristics that a document must have in order to be considered as evidence or as a record. These include: Unalterable Bi-temporal Structured Intentional And so on What is very common these days is to hear companies use the concept of a "living" document to describe their documents. These documents are constantly changing, edited in place, and where only the latest version should be used. This description defines a particularly use case for how documents are edited and retrieved. However, the notion of living documents is seldom if ever used in compliance processes were what is critical is that the user use the "latest approved" version and more correctly the one that he/she was trained on. The use cases for which version should be used is more nuanced, for example: The latest official release The latest approved version The latest approved version in the training system The latest work in progress version To effectively manage documents it is necessary to first understand what a document will be used for. It is in managing these intentions where EDM shines. This is very different from how content on the web is used. Content on the web typically is for a single use case and seldom has support for different uses of a document. EDM systems will have many more capabilities to support what is needed to preserve the integrity of documents across various uses to satisfy business and compliance requirements. These will include: Life Cycle Management (or workflow) Metadata Management Versioning Electronic Signatures Markup / Annotations Multiple Formats Office Integration Relationship Management Release Management Digital Rights Management Navigation / Search The power of EDM comes from managing all the dependent relationships with related information. In this way, EDM is more like a database than it is a file server. These relationships describe the intention for each document and therefore essential from a compliance perspective. For example, a document is: A Work Instruction, or Policy, or Standard Effective for the next 24 hours Superseded by the current version Controlled or Uncontrolled The latest approved version THE STATE OF EDM EDM has always suffered from an identity crisis. EDM started out as purpose built applications that utilized a relational database back end with an attached file store. This evolved to be more object oriented and over time transitioned to a platform offering in an attempt to become a "content" version of traditional database systems. API standards were developed to address proprietary interfaces and implementations. However, before these could gain traction the web took over. This would in many ways diminish the advances that EDM had up until then provided. It was very much three step forwards and two steps back. The introduction of the web and later content management did furnish a needed level of standardization along with enabling the shift from client/server technologies to web based architectures. While this was good it sacrificed functionality specific to managing documents in doing so. After many years of using HTML, creating web pages, and managing web content, most people consider managing content as synonymous with managing documents. Intranet platforms have for the most part replaced document management systems not in terms of capability but in terms of mind share. Many EDM vendors have been sidelined or have pivoted to content management providers. Some of them are doing both. One of these vendors is Microsoft with their SharePoint platform which is used in many organizations. SharePoint is an intranet platform that has over time added document and record management capabilities. SharePoint is worth mentioning because it has also become the defacto repository for documents in many companies. However, instead of controlling documents using EDM paradigms, instead we find that: 1. Documents are managed as files Metadata is not used, managed, or controlled New documents are created for every version Life cycles are implemented as folders were files are duplicated 2. Documents are managed as web content Minimal life cycle management Minimal relationship or Link management Minimal release management Minimal security 3. Document management is left to each business process owner IT is not involved Lack of consistent practices Lack of expertise and best practices 4. Documents are stored in communication channels E-mail Messaging 5. Documents are stored in collaboration platforms: File servers Intranets Cloud Applications While data awareness and capabilities have to some degree improved over the years these have been limited to what can be done using spreadsheets and what can be done using content management on intranets. Unfortunately, both of these tools are inadequate to effectively control and manage data and documents. The hope that content management would catch up to EDM still has not materialized. Many have waited for approaches such as the semantic web and RDF to create self-describing data however these have not advanced far enough to fill in the gaps. In the meantime, information technology has moved on. Enterprise IT is now preoccupied with moving to the cloud. Application developers are deconstructing workflows and redoing them for mobile. Cloud providers are racing to become the preferred repository for all your data but mostly agnostic to how you use this information. Information technology for all intents and purposes has abandoned the domain of controlled documents and EDM. WHAT CAN BE DONE? Given the limited resources available to companies, many are struggling to manage documents needed to support their business processes. Many technologies exist to help but have been largely forgotten, misunderstood, or otherwise neglected. The good news is that the steps to improve the management of documents have largely stayed the same and include: Identify which documents are critical for compliance. Conduct a document inventory to locate each document, and how they are used. Establish a standardized approach to managing these documents. Leverage existing technologies to manage the document life-cycle Automate management processes to embed evidence of compliance, streamline approvals, and manage document security.
- Management Previews
When it comes to management-based standards and regulations they almost all include a requirement for Management Review. The purpose of a management review has traditionally been to look at what has been accomplished and make necessary corrections to maintain targeted levels of performance applied to quality, safety & security, environmental and regulatory objectives. In recent years requirements have been expanded to consider strategic alignment and overall effectiveness, which requires a different point of view. The prevailing perspective to Management Review is looking at a rear-view mirror of past performance and using lagging indicators to make adjustments that improve consistency. This is necessary but limited in terms of contending with what's coming ahead and often very soon. A proactive approach to Management Review, let's call it, Management Preview adds another perspective by looking at what's ahead and using leading indicators to make course corrections that improve effectiveness. The purpose of systems is to achieve consistency by adhering to procedures, resisting change and reacting to variation. While programs anticipate conditions, introduce change, and advance outcomes. While this distinction is conflated in many management-based standards and regulations it helps to better understand the difference between governance, the process of steering; and managing, the process of controlling. Using this distinction we can say that Management Review is a function of systems that control processes whereas Management Preview is a function of programs which govern systems. Management Previews are essential for all purposeful endeavors where outcomes are being advanced and improvement in performance is needed not only to maintain consistency but to improve outcomes.
- When Is the Right Time to Introduce Technology?
Recently, I spoke with a client who answered this question by saying that technology can, when introduced too soon, short circuit the learning process. People can lean too much on the technology without fully understanding what the process and tools are really trying to do. This can work against trying to establish new behaviors and practices. In a fashion, my client's response speaks against today's widespread perspective that technology is the answer to many of our problems. For some, the introduction and use of technology is necessary to achieve the outcomes we want. However, is there a point where technology can actually get in the way from achieving these outcomes. And if so, how do you know when you have reached that point? This perspective that technology is the answer to our problems partly comes from a mindset of what is called technology determinism also referred to as technology-push. This view suggests that technology drives the solution instead of the business shaping what is needed. In many ways technology is the key enabler to change. However, technology-push can cause issues when the technology runs ahead of the business need. In this case, you end up with a solution looking for a problem rather than the other way around. This is where the rub is and the heart of where my client was coming from. Technology is often needed to support change but without the right balance it can "push" beyond what is needed and cause issues that can work against achieving the desired outcomes. Keeping the tension between the business demand and technology push is difficult. Here are a few things that can help: Keep the overall outcomes in mind. Don't forget what the technology is for. Keep the business need and the technology capabilities in sync. Don't let either get too far ahead of the other (i.e. don't over or under invest). Keep measuring and monitoring your outcomes and adjust capabilities when necessary. It is possible to slow or speed up adoption to stay in sync with technology introduction. Remember this is more like dancing than racing. Plan -Do-Check-Act Questions: What ways have you observed technology hindering or advancing your program outcomes? What needs to happen to keep the business need and the technology capabilities in sync? What would it look like if technology was at the right level? What step can you take to adjust your use of technology to match your business need?
- Compliance Technologies – Part 1
Navigating the constantly evolving landscape of compliance can be a challenging task for organizations, as it involves adhering to various regulations and stakeholder obligations across industries and countries. A comprehensive compliance program that covers all applicable laws and stakeholder requirements is crucial for every business to stay on top of their compliance obligations. At Lean Compliance , we specialize in helping organizations stay between the lines and head of risk. Through the lens of our proactive integrative approach we help organizations evaluate and improve existing compliance programs, systems, and technologies used to address both management and technical aspects of compliance. In this series we explore the technology side of compliance which we have categorized into the following solution categories: Regulatory Compliance solutions - these solutions are designed specifically to help organizations comply with regulations and laws. This can include tools for monitoring regulatory changes, automating compliance tasks, and managing compliance documentation. Risk Management solutions - these solutions help organizations identify, assess, and mitigate compliance risks. This can include tools for conducting risk assessments, implementing internal controls, and monitoring compliance metrics. Environmental, Health, and Safety (EHS) solutions - these solutions are designed to help organizations manage compliance with environmental, health, and safety regulations. This can include tools for managing hazardous materials, tracking safety incidents, and monitoring compliance with OSHA regulations. Governance, Risk, and Compliance (GRC) solutions - these solutions provide a holistic approach to managing compliance, risk, and governance issues. This can include tools for managing policies and procedures, conducting risk assessments, and monitoring compliance metrics across the organization. Compliance Management software - this category includes software solutions that help organizations manage their compliance programs. This can include tools for tracking compliance obligations, managing audits and inspections, and monitoring compliance metrics. In this first article we look at four vendors that specialize in the Regulatory Compliance solutions category: Enhensa , Nimonik , RegScan , and STP Publishing : ENHESA is a consulting firm that specializes in providing EHS regulatory compliance services to multinational companies. They provide expert guidance on regulatory compliance issues, helping organizations to identify and mitigate risks, develop compliance strategies, and stay up-to-date with the latest regulatory changes. Nimonik is a compliance software company that provides environmental, health, and safety compliance auditing and monitoring solutions. They offer a web-based platform that helps organizations manage their regulatory compliance obligations through automated audits, corrective actions, and tracking of regulatory changes. RegScan is a company that provides compliance solutions to help businesses manage their environmental, health, and safety (EHS) regulations. They offer a web-based platform that provides access to regulatory data, analysis tools, and compliance management systems to help organizations stay up-to-date with regulatory changes and ensure compliance. STP Publishers is a publishing company that provides regulatory compliance information in various formats, including online, print, and mobile applications. They offer a range of products, such as guides, handbooks, and manuals, covering various EHS regulatory topics, including OSHA, EPA, and DOT regulations. These companies provide various solutions to help organizations stay compliant with obligations that include (but not limited to): environmental, health, and safety requirements. They all offer expertise, software solutions, and regulatory information to assist businesses better meet their compliance obligations. Where do ENHESA, Nimonik, Regscan and STP Publishers map to the solutions categories? There is often significant overlap with technology solutions, and this is no different when it comes to compliance. Solutions offered by each company may vary depending on the specific package or plan that an organization chooses to subscribe to, and the categories listed above are not exhaustive. However, based on their websites and marketing materials, here's how the solutions compare to the compliance solution categories: Regulatory compliance solutions : All four companies offer regulatory compliance solutions that help organizations comply with laws and regulations. These solutions can include tools for monitoring regulatory changes, automating compliance tasks, and managing compliance documentation. Risk management solutions : all four companies offer partial risk management solutions to help organizations identify, assess, and mitigate compliance risks with support for conducting risk assessments and capturing risk metrics. Environmental, health, and safety (EHS) solutions : Nimonik, ENHESA, EHS solutions to help organizations manage compliance with environmental, health, and safety regulations. Governance, risk, and compliance (GRC) solutions: ENHESA, and Nimonik both offer partial GRC solutions to address compliance, risk, and governance requirements that include managing policies and procedures and monitoring compliance metrics. Compliance management software : ENHESA, and Nimonik both offer compliance management software solutions that allow organizations to track compliance obligations, manage compliance activity, conduct audits and inspections, and monitor compliance metrics. Here's a summary comparison of the solutions offered by Enhensa , Nimonik , RegScan , and STP Publishing against the solution categories listed above: Compliance Solutions Category ENHESA Nimonik Regscan STP Publishers Regulatory compliance solutions Yes Yes Yes Yes Risk management solutions Partial Partial Partial Partial Environmental, health, and safety (EHS) solutions Yes Yes No No Governance, risk, and compliance (GRC) solutions Partial Partial No No Compliance management software Yes Yes Partial Partial This comparison is based on publicly available information and may not be exhaustive or completely accurate. How do ENHESA, Nimonik, Regscan and STP Publishers help you stay between the lines and ahead of risk? ENHESA, Nimonik, Regscan, and STP Publishers are all designed to help companies manage compliance. However, the effectiveness of each solution in handling compliance risk depends on several factors, including the specific industry, the types of regulations that the organization must comply with, and the organization's specific compliance needs and requirements. That being said, ENHESA is generally considered to be a leading provider of compliance solutions for multinational companies that need to manage compliance across multiple jurisdictions. ENHESA's solutions provide a comprehensive approach to compliance risk management, including a focus on risk assessments, compliance audits, and compliance gap analysis. Nimonik also offers a comprehensive range of compliance management tools and features to identify and manage obligations, create and track compliance activity, conduct audits, and capture and monitor compliance risks. STP Publishers and RegsScan primarily provide compliance content (RegScan also provides audit capabilities) such as manuals and online resources, that can help organizations stay up-to-date with regulatory changes and requirements. While these resources can be useful in staying between the lines, they may not provide the same level of hands-on support and guidance needed to contend with uncertainty and risk. Overall, the effectiveness of each solution in handling compliance risk will depend on the specific needs and requirements of the organization. It is important to evaluate each solution based on its specific features, capabilities, and industry focus to determine which one will best meet the organization's compliance risk management needs. Here's how each compare against key compliance capabilities: Features ENHESA Nimonik Regscan STP Publishers Compliance monitoring and tracking Yes Yes Yes No Regulatory updates and alerts Yes Yes Yes Yes Compliance gap analysis Yes Yes Yes No Compliance risk assessments Yes Yes Partial No Compliance audit tools Yes Yes Yes Partial Multinational compliance management Yes No No No Environmental, health, and safety compliance management Partial Yes No No Industry-specific compliance guidance No No No Yes Integration with enterprise systems Yes Yes Yes Yes This comparison is not meant to be exhaustive and there may be additional features and capabilities offered by each solution beyond those listed here. Additionally, the specific features and capabilities of each solution may vary depending on the specific package or plan that an organization chooses to subscribe to. What are the main differences between ENHESA, Nimonik, Regscan and STP Publishers? ENHESA, Nimonik, Regscan, and STP Publishers all provide regulatory compliance solutions, but there are some differences between them. ENHESA is a global environmental, health, and safety (EHS) consultancy that provides compliance solutions to businesses operating in various industries. Their services include regulatory analysis, EHS audits, and compliance management systems. Nimonik provides a turn-key web-based compliance monitoring platform that helps organizations to identify, track, and comply with applicable regulations. Their services include audit and inspection tools, document management, and automated compliance alerts. The main differentiator is that they have both software and content, allowing you to rapidly deploy a compliance monitoring program. They can also extract obligations from your internal documents such as permits, policies and procedures. RegScan is a global regulatory compliance solution provider that offers compliance monitoring, analysis, and management solutions for businesses. Their services include compliance audits, training, and consulting. They are now owned by ENHESA, which is based in Belgium. STP Publishers is a provider of EHS and sustainability regulatory compliance solutions, offering online tools and consulting services to help organizations stay up-to-date with regulatory changes. Their services include regulatory compliance news and analysis, training, and audit checklists. Regscan, ENHESA and STP focus on providing data. To fully use their information you often need to purchase software programs such as a GRC platform or an EHS platform. If you are a large organization with a big team and budget, this might be the best option as you will be able to fully customize the program. The main differences between these providers are the scope of the industries they serve as well as the management capabilities they provide. For example, while all four providers offer compliance monitoring and management solutions, ENHESA focuses specifically on EHS compliance, while Nimonik covers regulatory change for privacy, cybersecurity, HR, aviation and numerous other areas of concern. Each have different ways for risk to be captured, evaluated and managed. Ultimately, the choice of provider will depend on your organization's specific needs and the industries you operate in. It's important to conduct thorough research and evaluation of the various providers to determine which one offers the best fit for your organization's compliance needs. Summary In today's business landscape, regulatory compliance is more important than ever. Failure to comply with regulations can result in hefty fines, legal action, and damage to a company's reputation. Fortunately, technology solutions have emerged to help organizations manage compliance more efficiently and effectively. ENHESA, Nimonik, Regscan, and STP Publishers are four companies that offer regulatory compliance solutions that assist organizations in complying with laws and regulations. These solutions include tools for monitoring regulatory changes, automating compliance tasks, and managing compliance documentation and information. Overall, compliance technology solutions are becoming more critical for organizations to effectively manage their regulatory and stakeholder obligations. The solutions offered by these companies can provide organizations with the tools they need to stay compliant, avoid costly penalties, and protect their reputation. Lean Compliance helps organizations stay between the lines and head of risk. Visit our website to learn how you can improve the probability of mission success by using a proactive and integrative approach to compliance.
- Turning Best Effort Into Best Outcome
When it comes to playing games where the goal is to have fun “Best Effort” is often applauded and even celebrated. We often hear statements like, “you did your best and as long as you had fun that’s all that matters.” This may provide some consolation when stakes are low and dealing with a bruised ego. However, when the stakes are higher and the goal is to save lives, “Best Effort” may not be enough. Knowing that you did your best when an incident occurs provides little comfort to those who have been injured or those who are responsible for their well being. A “Best Effort” approach is also rarely acceptable for high performing companies when it involves making production numbers or other business goals. However, it is surprisingly the approach often adopted for meeting compliance objectives. In this blog we will look at why a “Best Effort” approach is not enough and how you can turn it into a “Best Outcome” strategy to advance compliance objectives and improve overall outcomes. The Tale of Two Companies Let’s consider two companies each operating processing facilities that produce natural gas for distribution by downstream operators. They are both focused on operational excellence, cost reduction, and have a safety culture in place. Their safety records to date have not been stellar both having had numerous incidents as well as at least one fatality in the last decade. Both companies have come to realize that they need to improve their safety record and have decided to adopt a new safety initiative and introduce a new safety management system. At this point, as far as one can tell, these companies look the same and are taking the same kind of actions to improve. However, their results may turn out differently. One company has adopted a “Best Effort” approach, whereas, the other an approach based on “Best Outcome.” Best Effort Approach The best effort approach is more common than one would expect. Companies promise to achieve the desired outcomes (ex. zero incidents, zero defects, zero fatalities, and so on) but their focus is on “effort” rather than “results.” Companies may implement standard practices and behaviours, management systems, safety culture, and even continuous improvement, however outcomes remain largely incidental and contingent (subject to chance) rather than planned and managed. The “best effort” approach is characteristic of organizations in early stages of capability maturity as attention is given to: Standard work Process consistency Inspections and audits Corrective actions Systems (safety, quality, environmental, etc.) are introduced to manage processes and industry standards help to ensure that the minimum processes are in place. The goal of all systems is to “execute processes as consistently as possible” or using the previous analogy “play the game the best you can.” This approach has the greatest impact when essential processes, practices, or culture is missing or not meeting a minimum standard. Outcomes may improve although these are often not measured or used to drive continuous improvement. Since the goal is to “execute processes as consistently as possible” resources are aligned to achieve that end, rather than on advancing outcomes. From a systems-theory perspective we know that when optimizing for a given outcome you will necessarily optimize away from other outcomes. In other words, you can only improve in the direction you are facing. When you are facing “consistency” you will necessarily move away from “effectiveness.” Best Outcome Approach A “Best Outcome” approach differs from “Best Effort” in that it optimizes for progress with respect to outcomes rather than effort or efficiency. This is more than just a subtle change in focus or a play on words, it defines a different strategy altogether. Companies will still implement standard practices and behaviours, management systems, safety culture, and even continuous improvement. However, focus is on whether or not they have the “right” capabilities at the “right” level of performance to achieve the promised outcomes. This is one of the roles that governance and associated programs (i.e. the permanent versions of steering committees) has which is to steer capabilities towards creating “Best Outcomes.” This approach is “proactive” in that it doesn’t wait until an incident has occurred before making further improvements. Instead, it anticipates, plans, and acts to ensure that progress against outcomes is made. This requires that risk is managed, and improvement is made by continually steering towards defined goals, objectives, and intended results. Adopting a “Best Outcome” Approach When companies are in early stages of capability maturity a “Best Effort” approach can provide utility to introduce missing capabilities. For some companies this is a starting point but for all companies it is not the destination when it comes to advancing compliance outcomes. Without a steering function a “Best Effort” approach will “continuously improve” towards greater consistency rather than effectiveness. Unfortunately, this tends to promote more inspections, audits, and corrective actions which is commonly referred to as the “audit-fix cycle.” However, there is a way for companies that have adopted this approach or caught in the audit-fix cycle to become more effective. Here are 5 steps towards that end: Clearly define goals, objectives, and expected outcomes. Determine the capabilities (people, processes, organization, technology, culture, etc) needed to achieve them. Develop a risk plan to ensure progress is made. Define how progress will be measured. Establish a governance program to continuously improve compliance effectiveness. Two Companies, Two Outcomes? The outcomes of the two companies mentioned previously are still pending. Which one do you think will reach zero incidents, the one that chose a “Best Effort” or “Best Outcome” approach? Let me know what you think or which approach you would use.
- Proactive Planning
Does your approach to planning adequately address performance and outcome-based obligations?
- Risk-Based CAPA?
Many companies are in the midst of adopting changes introduced by ISO 9001:2015. One of the most significant of these, is incorporating "Risk-based Thinking." Risk-based thinking was introduced to improve (among other things) the effectiveness of how corrective and preventative actions (CAPA) were handled. From the standard we know that preventative actions has been replaced with taking a risk-based approach. I am going to explore in this blog the concept that some have proposed to replace CAPA with CARA (i.e. Corrective Action / Risk Assessment). At the basic level this is conducting a risk assessment for the corrective action. First of all, there are good reasons to conduct a risk assessment on corrective actions. We know that change can be a significant source of new and emerging risks. When dealing with any change there are two primary sources of risk that need to be addressed: Risks implementing the change – these are risks in conducting the work needed to effect the change. These risks may include: worker safety, temporary impacts on other processes (including risk controls), and so on. A portion of these risks can be addressed proactively by using safe work practices which are procedures that have been previously risk-assessed. Risks introduced by the change – these are new risks or changes to existing risks that result after the change has been made. These risks are identified as part of the change process usually by a cross-functional team with experience in detecting risks within their particular discipline. Depending on the scope of the change it is not uncommon to have: occupational safety, process safety, IT, compliance, regulatory, environment, and other specialists involved as part of the risk assessment team. Corrective actions are a source of change and therefore also a potential source of risk. However, there are limitations in using these as the only trigger to identify and manage both external as well as internal program risks. These limitations result from the fact that corrective actions are often: addressed in isolation from other actions triggered by symptoms and not systemic causes a reaction to a non-conformance leading to lagging actions not effective at addressing latent failure modes (those that have yet to be discovered by the customer for example) To overcome these limitations companies should take a proactive and holistic/systems approach to assess risk. In fact, ISO 9001:2015 states that each company must identify and manage threats and opportunities associated with each process within their quality program. While this is good, it is not enough to identify risks associated with the objectives of the entire program. The latter requires consideration of not only individual processes but also how they interact with other processes within and outside the quality program. All with the goal of assessing how uncertainty affects achieving program outcomes. The first step is having clear and concise program objectives for each system and process. This will properly constrain risk assessments along with resulting treatments to ensure that the certainty of achieving program goals are increased. The advantages of being proactive and using a holistic/systems approach to risk assessment include: Improving processes before non-conformance is realized Addressing latent failure modes before they become active Minimizing disruption, and risks introduced by implementing the change by consolidating changes Avoiding higher costs associated with addressing non-compliance after the fact Applying resources to risks that really matter to achieving program outcomes Including risk assessments as part of corrective actions is indeed part of risk-based thinking. However, on its own, it is not enough to address uncertainty in achieving program outcomes. #RiskbasedThinking #CAPA #ISO9001 #ManagementofChange
- Does Compliance Need an Incident Management System?
With the emergence of the COIVID-19 pandemic many are working remotely with minimal on-site presence. This has put a strain on existing operational systems and processes particularly those connected with risk and compliance designed for and under different conditions. Organizations that have relied solely on audits to identify gaps in their compliance may now discover them to be too late and too slow for that purpose. In fact, as operating conditions have significantly changed they may no longer be effective at all. What should organizations do to deal with possible increases in incidents across their safety, environmental, regulatory, or quality programs? In this blog I will explore how organizations can answer this question but first we need to understand why audits are used in the first place. Use of Audits The use of periodic audits as the primary compliance control is all too common and has always had its limitations. By design audits provide evidence of what has happened. Audits provide a lagging indicator that can be used to identify and then correct prescriptive compliance gaps so that they don’t reoccur. Audits work best when organizations are mostly “in-compliance.” Audits cannot correct what has already happened. However, they do provide status of the integrity of financial and other reports that give witness to the conditions at a certain point in time. Under normal conditions when organization's are mostly “in-compliance” they may be also help to identify minor violations or infractions against standard practices and procedures. However, conditions today are not normal. The assumption that organizations are still mostly “in-compliance” may no longer be warranted or wise. In the presence of significant uncertainty in a COVID-19 pandemic world what should organizations now do so that they continue to operate between the lines? Are audits enough to provide the assurance that stakeholders require? Lessons from Process Safety In highly-regulated high-risk industries another process is used to stay ahead of the effects of uncertainty. This process is known as “Incident Management (IM)” and is a one of the pillars of an effective risk & compliance program. Incident management systems are used to address emergencies but also to discover when organizations cross the lines well before audits might otherwise catch them. The hope is that infractions are caught when the consequences and the cost to correct them is small. In fact it may even capture near misses which can provide an earlier warning of possible future incidents. Incident Management (IM) systems help to turn this hope into a reality. Incident management systems are used by safety-first organizations that have a culture of preparedness and response something that almost all compliance programs need these days. The following are key principles of effective incident management programs. Practice of these principles can be observed in industries such as Energy, Oil & Gas, and Mining. However, they also can also provide insights for others who are experiencing higher levels of uncertainty and risk as result of the on-going COVID-19 pandemic. Incident Management Principles 1. Preparedness and Response While effective risk management aims to prevent incidents before they happen; incident management aims to protect the public, workers, property and the environment just in case it does. This requires awareness of the effects of uncertainty (c.f. RISK: ISO 31000) and establishing measures in advance to mitigate the effects should an adverse situation arise. Establishing response standards is essential to knowing the level of preparedness needed along with how best to address specific cases such as emergencies. 3. Emergency Management Process Emergency management involves all the activities prior to and in response to a significant adverse event that has the potential of doing harm. Having a comprehensive response plan focused on rapid response can mean the difference between life and death along with the potential to avoid substantial remediation costs. After the emergency has been addressed, clean up, restoration, and remediation efforts are put in place informed by the results of a thorough incident investigation. 4. Incident Investigation To prevent re-occurrence of an adverse event it is necessary to understand the root cause or at least primary causes leading to the event occurrence. This requires thorough investigation and expert practice of root cause analysis (ex. Apollo Method), STAMP (Systems Theoretic Accident Modelling and Processing), HAZOPS, and other techniques designed to identify factors that may create the conditions and actions for the re-occurrence of the incident or similar ones. 5. Incident Resolution Investigation while important will not have its full effect unless measures are put in place to implement recommendations to reduce the probability of re-occurrence. Establishing new or updated measures and monitoring their effectiveness are necessary and where much of the failure in risk management occurs. Continuous evaluation of risk measure effectiveness is an essential practice for companies that strive towards operational excellence. 6. Incident Reporting Incident reporting provides both leading and lagging information of incidents. Tracking of events that fall outside of risk and compliance boundaries or targets are essential for both government reporting as well as in the discovery of causes leading to possible future events. Capturing of “near misses” while not easy to define or to do is the current focus for many safety-first organizations that are serious on preventing harm to their workers, property, communities, and the environment. 7. Continuous Learning and Adaptation For an incident management program to remain relevant and effective it must continually adapt to changing conditions and consider learning from within as well as outside of the organization. When conditions are changing as fast and as significantly as they are now it is imperative that organizations continue to learn and adapt their risk and compliance programs. For some (perhaps many) this begins with not assuming the state of existing risk & compliance is what it was prior to the pandemic. This will necessarily lead to establishing and or upgrading processes associated with incident management. Summary: COVID-19 has created significant disruption and uncertainty across the world, across communities, and across businesses of all shapes and sizes. Assuming that prior risk & compliance controls have remained intact and are still effective may no longer be warranted or wise. Waiting for downstream audits and reports may not be fast enough to close the gaps in programs essential to keep organizations operating between the lines and protect against harm or loss. Under current pandemic conditions or until the state of risk and compliance programs are better understood, organizations should consider implementing incident management programs to mitigate the effect of adverse events which are now more likely to occur. Tracking and monitoring of incidents may themselves provide early warning giving organizations time to prepare. However, safety-first organizations will take the proactive step to first understand their risks to ensure that they are ready to respond. Lean Compliance helps forward looking organizations improve stakeholder trust by improving the effectiveness of risk and compliance programs.
- Regulatory Compliance Not Enough
In a recent decision of the Ontario Court of Appeal they stated that the general duty clause in the Occupational Health and Safety Act, can impose higher obligations than specific requirements in regulations. They concluded the following in the case involving Quinton Steel with respect to a case involving guard rails: "It may not be possible for all risk to be eliminated from a workplace, as this court noted in Sheehan Truck, at para. 30, but it does not follow that employers need do only as little as is specifically prescribed in the regulations. There may be cases in which more is required – in which additional safety precautions tailored to fit the distinctive nature of a workplace are reasonably required by s. 25(2)(h) in order to protect workers. The trial justice’s erroneous conception of the relationship between s. 25(2)(h) and the regulations resulted in his failure to adjudicate the s. 25(2)(h) charge as laid." – Emphasis added in bold. Based on this decision, the general duty clause could require employers to do more than the prescriptive requirements of any hazard-specific regulations. Some might argue that this has expanded the scope of an employer's obligations. However, what this decision has affirmed is that regulations should be considered as "the low-water mark" when it comes to safety. It is therefore essential that employers understand exactly what and how they will keep their obligations. This requires greater consideration when it comes to duty and liability as well as other categories of obligations: Micro-means (prescriptive) Macro-means (management-based) Micro-ends (performance-based) Macro-ends (duty and liability) It is common for employers to focus on the prescriptive elements as these can be more easily quantified and measured. Whereas, the others often require the establishment of systems and processes to achieve standards that go above and beyond prescriptive elements. To address these companies will implement processes to address uncertainty and the management of risk, along with continuous improvement specifically with respect to performance and outcomes. A primary difference between following prescription compared with duty and liability obligations is the latter requires employers to be more proactive with their compliance. And this begins with taking ownership for each obligation and not waiting for an audit or a fine for improvements to occur. There will always be more risk than a company can contend with and so each company must decide which risks really matter. When it comes to duty of care the decision should always side in favor of employee safety. If you want to be more certain about your compliance you may want to consider joining – The Proactive Certainty Program™ – designed to help you avoid – The Reactive Uncertainty Trap™ . Visit our website at www.leancompliance.ca for more information on how to join. Sources: [1] - http://www.occupationalhealthandsafetylaw.com/in-important-decision-ontario-appeal-court-says-that-general-duty-clause-in-ohsa-can-impose-higher-obligations-than-specific-requirements-in-regulations?utm_source=Mondaq&utm_medium=syndication&utm_campaign=LinkedIn-integration [2] - Canadian Occupational Safety, www.cos-mag.com, "Regulatory compliance not enough: Court", Jeremy Warning
- Essential Properties for Compliance Systems
Compliance management systems are used by organizations for the purpose of helping them first achieve and then maintain compliance which is the outcome of meeting all your obligations (ISO 19600). The question is what properties or behaviours of a compliance system are needed for this outcome to be created? What is essential for a compliance system to be effective? How are outcomes created? To answer this we need to understand how outcomes are created in the first place. A system outcome is an emergent property that for compliance may be greater safety, quality, security, reputation, or any number of desired objectives. It is the collective interactions of all essential parts of a compliance system that are responsible for the overall system behaviour and any emergent properties. Dr. Russell Ackoff defined a system as: " a whole which is defined by its function in a larger system of which it's a part. For a system to perform its function it has essential parts: Essential parts are necessary for the system to perform its function but not sufficient Implies that an essential property of a system is that it can not be divided into independent parts. Its properties derive out of the interaction of its parts and not the actions of its parts taken separately." For example, using a transportation system such as a car, transporting someone from point A to B is an emergent property. A car fulfills this purpose when all its essential parts are working together to "transport" someone. It is not the property of any of its parts taken separately. When you take a car apart it is no longer a car. It cannot perform its function. You can take all the parts and put them on the ground. You can analyze them, improve them, but you still don’t have a car. There are also no parts on their own that can perform the function of a car. A car engine by itself cannot transport anything including itself. Another way of saying this is a compliance system is not the sum of its parts. In fact, it is a product of the interaction of its parts. Without the interactions you only have a bin of parts, a collection of components, a set of elements, but you do not have a system. Building parts For many organizations, compliance remains an exercise in manufacturing parts which they add to their collective parts bin. Unfortunately, none of the parts on their own will produce the desired compliance outcome. Audits, obligation registers, controls, risk measures, training; none of these by themselves is enough. Even if all the parts existed, if they do not work together as a whole you will still not have a compliance system. As with a transportation system we could have something simple like a skateboard or bicycle or more capable such as a motorcycle, car or a plane. What is important is that they all fulfill the transportation function recognizing that some are more effective than others. Instead of focusing on building parts organizations need to think about enhancing systems. They perhaps need to start with a skateboard equivalent of a compliance system, then move onto a bicycle, and so on. Each version of the system can produce compliance and will manifest all essential properties. Compliance system properties We have found that the following properties contribute to a compliance system's effectiveness: Operational – must have all the essential parts working together as a whole to produce an emergent property of compliance evidenced by the advancement of outcomes. Proactive – capable of establishing new goals and measures that continually advance outcomes. (ex. governance) Viable - capable of being achieved using current technologies. While new technologies may be helpful the system must be operational with the technologies currently available. Sustainable – capable of consistently achieving targeted levels. Resilient – consistently performs in the presence of changing conditions. Feed-back controls are used to reduce variation and to create consistency in both performance and outcomes. Efficient – capable of achieving targeted performance with minimum waste. Adaptive – capable of learning from the past to improve future outcomes. Performance and outcomes are measured to understand correlation and causation. Transparent – capable of retrospective investigation and analysis. We are able to know what the rules are. Compliance systems that have these properties in increasing measure of capability maturity are more likely to fulfill their compliance function. What is essential? We can now answer the question as to what properties are essential for a compliance system. The properties that are essential are those that are needed for the system to be operational. These are not sufficient for it to be effective but are necessary to perform in such a way to create the emergent property of compliance. The system may not perform much beyond a skateboard at first but you can still get from point A to B. You can improve capabilities over time to get faster, with less resources, and so on. Determining what is needed to be operational requires clearly defining the purpose of your compliance system (what are the desired outcomes) and then identifying the capabilities along with their interactions (i.e. the behaviours) to fulfill that purpose.












