<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Capable People Blog &#187; Risk &amp; Assurance</title>
	<atom:link href="http://blog.capablepeople.co.uk/category/risk-assurance/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.capablepeople.co.uk</link>
	<description>Just another WordPress weblog</description>
	<lastBuildDate>Mon, 26 Jul 2010 06:20:18 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Quality risk</title>
		<link>http://blog.capablepeople.co.uk/2010/01/quality-risk/</link>
		<comments>http://blog.capablepeople.co.uk/2010/01/quality-risk/#comments</comments>
		<pubDate>Thu, 21 Jan 2010 17:34:27 +0000</pubDate>
		<dc:creator>Shaun</dc:creator>
				<category><![CDATA[Quality Improvement]]></category>
		<category><![CDATA[Risk & Assurance]]></category>
		<category><![CDATA[ISO 9000]]></category>
		<category><![CDATA[ISO 9001]]></category>
		<category><![CDATA[ISO 9001 audit]]></category>
		<category><![CDATA[quality management]]></category>
		<category><![CDATA[quality risk]]></category>
		<category><![CDATA[risk]]></category>
		<category><![CDATA[risk management]]></category>

		<guid isPermaLink="false">http://blog.capablepeople.co.uk/?p=1408</guid>
		<description><![CDATA[Does the principle of quality management have anything at all to do with the management of risk?<p>Post from: <a href="http://www.capablepeople.co.uk/blog">Capable People Blog</a><br/><br/><a href="http://blog.capablepeople.co.uk/2010/01/quality-risk/">Quality risk</a></p>
]]></description>
			<content:encoded><![CDATA[<p><script type="text/javascript" src="http://tweetmeme.com/i/scripts/button.js"></script></p>
<p>I was on a quality management discussion forum the other day and stumbled upon an argument that made me wonder if I had lost my sanity</p>
<p>The gist of it was whether or not the management of &#8220;risk&#8221; had anything to do with quality management and whether an understanding of &#8220;risk&#8221; was necessarily a knowledge pre-requisite for a QMS auditor. The case for the defence cited that nowhere in ISO 19011 was there any specific reference to &#8220;risk&#8221;. And on that point, they were quite right &#8211; I checked</p>
<p>That really made me wonder whether the &#8220;quality fraternity&#8221; had actually lost the plot. Or, more to the point, whether they had ever had it in the first place</p>
<p>It started me on a bit of a quest to see if I could unravel any semblance of rationale from this apparent nonsense. After all, it could be just me. So I started by looking in ISO 9000:2005. I found this</p>
<p><em><strong>&#8220;2.8.1 Evaluating processes within the quality management system</strong></em></p>
<p><em>When evaluating quality management systems, there are four basic questions that should be asked in relation to every process being evaluated.<br />
a) Is the process identified and appropriately defined?<br />
b) Are responsibilities assigned?<br />
c) Are the procedures implemented and maintained?&#8221;</em><br />
<em>d) Is the process effective in achieving the required results?&#8221;</em></p>
<p>On the face of it that doesn&#8217;t introduce much controversy. those are, after all, reasonable questions. But there is no mention of assessing how well risks are controlled, so should there be?<em> </em></p>
<p>Well I&#8217;d have to say &#8220;yes&#8221; to that, and my reason for that is why should a quality management system be any different to any other management system? If we take the example of ANY other management system, financial, information security, environmental, occupational health &amp; safety, the identification and control of risk is an absolute cornerstone. It is the inarguable starting point. No debate about that at all. So why is &#8220;quality&#8221; different? What is it about quality management that justifies developing the management system from a completely different starting point, with almost completely different priorities, and to somehow justify side-stepping the whole concept of risk management at every stage?</p>
<p>One question that it does leave unanswered (for me at least) is how this all sits with the inclusion of &#8220;quality&#8221; within an integrated management system?</p>
<p>So, what do you think? Am I right? Am I the one who has lost the plot? Am I missing something? Seriously, tell me</p>
<p>Post from: <a href="http://www.capablepeople.co.uk/blog">Capable People Blog</a><br/><br/><a href="http://blog.capablepeople.co.uk/2010/01/quality-risk/">Quality risk</a></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.capablepeople.co.uk/2010/01/quality-risk/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>What is &#8220;risk&#8221;?</title>
		<link>http://blog.capablepeople.co.uk/2009/11/what-is-risk/</link>
		<comments>http://blog.capablepeople.co.uk/2009/11/what-is-risk/#comments</comments>
		<pubDate>Tue, 17 Nov 2009 11:35:36 +0000</pubDate>
		<dc:creator>Shaun</dc:creator>
				<category><![CDATA[Risk & Assurance]]></category>
		<category><![CDATA[risk]]></category>
		<category><![CDATA[risk management]]></category>

		<guid isPermaLink="false">http://blog.capablepeople.co.uk/?p=1204</guid>
		<description><![CDATA[Too many people have no idea what &#8220;risk&#8221; actually means &#8211; let alone how risks can be mitigated or controlled. So let&#8217;s try and get to grips in this post with the fundamental principles Too risky &#8230; Risk is a combination of the harm or damage that an event may cause, and the likelihood that [...]<p>Post from: <a href="http://www.capablepeople.co.uk/blog">Capable People Blog</a><br/><br/><a href="http://blog.capablepeople.co.uk/2009/11/what-is-risk/">What is &#8220;risk&#8221;?</a></p>
]]></description>
			<content:encoded><![CDATA[<p><script type="text/javascript" src="http://tweetmeme.com/i/scripts/button.js"></script></p>
<p>Too many people have no idea what &#8220;risk&#8221; actually means &#8211; let alone how risks can be mitigated or controlled. So let&#8217;s try and get to grips in this post with the fundamental principles</p>
<h2>Too risky &#8230;</h2>
<p>Risk is a <strong>combination </strong>of the <strong>harm </strong>or damage that an event may cause, and the <strong>likelihood </strong>that the event will occur. What that means is that the highest risk activities are those that are highly likely to happen and will cause a lot of harm when they do. The lowest risk activities are obviously the reverse of that, events that are unlikely to occur and would cause little harm even if they did</p>
<p>As an example to illustrate this I heard an interesting debate halfway through the year when scientists were preparing to fire up the Large Hadron Collider (LHC) under the Alps. Some people suggested that the event could get out of hand and create a black hole that would swallow the earth. This would be a highly inconvenient event for all of us should it happen. The scare stories were immediately tempered by many qualified scientists who were keen to point out just how minuscule the likelihood of that was. So in &#8220;risk&#8221; terms, we were talking about <strong>high harm</strong> versus <strong>tiny likelihood</strong> &#8211; giving an overall low risk score. However, one commentator asked how high the likelihood of planetary oblivion needed to be before the risk became unacceptable. In other words, is a very small chance we will wipe out civilization tolerable? A fair point you might think</p>
<p>But <strong>tolerable risk</strong> is a difficult concept over which to achieve universal agreement. Some years ago, the Health &amp; Safety Commission published a document entitled &#8220;Taking a Sensible Approach to Risk&#8221;. This was seen by many at the time to be a reaction to some high profile inappropriate risk management strategies that had been adopted particularly by public sector bodies, especially schools. The problem with quantifying risk is that it is not an exact science. People have different perceptions of what might be the potential harm and particularly the likelihood of it transpiring. When we identify a risk, we have three broad choices for how we deal with it. We can;</p>
<ul>
<li>Accept it (decide we can live with it, or that we can&#8217;t do much about it anyway)</li>
<li>Reduce the risk (implement controls that reduce the potential harm of the event, or reduce the likelihood, or both)</li>
<li>Eliminate the risk completely (clearly, all things being equal, the most preferred option)</li>
</ul>
<p>Take the example of school field trips and excursions as an example of an activity that carries some risk. At worst it may present a combination of circumstances that may end up with a fatality &#8211; it happens unfortunately. Because of this risk many school headmasters are minded to take the &#8220;most preferred option&#8221; of eliminating all risk associated with these activities &#8230;. by banning them. Is this the right thing to do or is it a disproportionate action? It&#8217;s a difficult call, but normally we have to find a way of getting on with our lives, doing things, but also finding ways of reducing our exposure to unnecessary risk. We can&#8217;t hide under the bed indefinitely. It might collapse on top of us and kill us</p>
<h2>People&#8217;s perception of risk</h2>
<p>The way that people view a risk is in turn affected by variables. There is, for example, the phenomenon of desensitization. That means that the more we are exposed to a risk without suffering harm, the less high we are likely to rate that risk. A good example of this might be the attitude of a dangerous driver. The more times he gets away with dangerous over-taking manoevres, the more cavalier his attitude to the inherent risk is likely to be. In this case the individual is underestimating the size of the risk by underestimating the &#8220;likelihood&#8221; side of the equation. Chances are he knows fine well that a head-on collision will do him no favours at all, he just believes it is unlikely to happen</p>
<p>Another thing that affects people&#8217;s attitude to risk is previous experience of or exposure to the harm. For example a person who has recently been bitten by a dog (or knows someone that has) is likely to see the event as more likely to occur than someone who has not. Maybe that&#8217;s where the old saying comes from &#8230;</p>
<p>In business terms we have to find a way to get things done and, as it is often very difficult to eliminate risk, it is usually inevitable that a certain amount of risk must be tolerated. It is difficult to quantify what &#8220;tolerable&#8221; actually is, however perhaps the best way to look at it might be to apply the old gambling adage</p>
<p style="text-align: center;"><em><strong>Never bet more than you can afford to lose</strong></em></p>
<p style="text-align: center;">
<p style="text-align: center;"><em><strong><p><a href="http://blog.capablepeople.co.uk/2009/11/what-is-risk/"><em>Click here to view the embedded video.</em></a></p></strong></em></p>
<p style="text-align: center;">
<p style="text-align: left;">This clip actually provides a useful illustration on the concept of &#8220;desensitization&#8221; to risk. Despite the fact that the young lady comes within a second of being pulped, notice how quickly she recomposes herself and walks off as though this was the most normal of occurrences<em><strong>. </strong></em>If that had been me, I&#8217;d have been quivering on the platform for a good few minutes<em><strong><br />
</strong></em></p>
<p>Post from: <a href="http://www.capablepeople.co.uk/blog">Capable People Blog</a><br/><br/><a href="http://blog.capablepeople.co.uk/2009/11/what-is-risk/">What is &#8220;risk&#8221;?</a></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.capablepeople.co.uk/2009/11/what-is-risk/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Making sense of Deming</title>
		<link>http://blog.capablepeople.co.uk/2009/10/making-sense-of-deming/</link>
		<comments>http://blog.capablepeople.co.uk/2009/10/making-sense-of-deming/#comments</comments>
		<pubDate>Fri, 09 Oct 2009 13:21:34 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Deming]]></category>
		<category><![CDATA[Leadership & Management]]></category>
		<category><![CDATA[Quality Improvement]]></category>
		<category><![CDATA[Risk & Assurance]]></category>
		<category><![CDATA[continual improvement]]></category>
		<category><![CDATA[quality management]]></category>

		<guid isPermaLink="false">http://www.thetyphon.com/capableblog/?p=128</guid>
		<description><![CDATA[This article reprises the themes raised by my earlier post Deming&#8217;s inconvenient truth, and makes an attempt to draw some additional sense from the apparent paradox. For this article I have Hilary Burrage to offer some credit to, for posing a question on the LinkedIn forum that got some pennies dropping Let&#8217;s start the story [...]<p>Post from: <a href="http://www.capablepeople.co.uk/blog">Capable People Blog</a><br/><br/><a href="http://blog.capablepeople.co.uk/2009/10/making-sense-of-deming/">Making sense of Deming</a></p>
]]></description>
			<content:encoded><![CDATA[<p><script type="text/javascript" src="http://tweetmeme.com/i/scripts/button.js"></script></p>
<p>This article reprises the themes raised by my earlier post <a href="http://blog.capablepeople.co.uk/2008/07/demings-inconvenient-truth/">Deming&#8217;s inconvenient truth</a>, and makes an attempt to draw some additional sense from the apparent paradox. For this article I have <a href="http://www.hilaryburrage.com/">Hilary Burrage</a> to offer some credit to, for posing a question on the <a href="http://www.linkedin.com/answers/management/corporate-governance/MGM_CGV/166388-13361034?browseIdx=0&amp;sik=1202291835964&amp;goback=%2Eama">LinkedIn forum</a> that got some pennies dropping</p>
<p>Let&#8217;s start the story at the beginning. Sometime in 2005 I was on my way back home on a Thai Air flight from Jakarta to Heathrow, via Bangkok. In Bangkok I was joined by a casually dressed, youngish Englishman. One look told me he had some money because his clothes and shoes looked expensive, as was his seat on the plane. After a while we got talking. I told him what I did, he told me what he did. Turned out he was a professional gambler living in Thailand. I was immediately captivated by the glamour of his chosen profession, he seemed keen to talk and while away the hours, I was keen to listen. So in the intervening 12 hours or so I got a pretty good insight into the life of a professional gambler</p>
<p>Well, surprise surprise, it&#8217;s not all glamour and it&#8217;s not all luck. That was lesson number one and two. The man was a statistician by education, a former mathematics teacher of all things, who had turned a knowledge of statistics to his advantage in the arena of sports betting. The trick to making a profit in the longer term was, apparently, to have an ability to identify when the bookies have got the odds wrong. That&#8217;s when you place your bets. They don&#8217;t all come off, but the odds start slanting your way as opposed to the way of the bookie. Being able to identify when the odds were wrong involved a working knowledge of statistics, and a better knowledge of the event than the bookie appeared to have, and that usually involved some very painstaking research. He was based in Thailand because the bookies in South East Asia get the odds wrong more often than they do elsewhere. Makes sense</p>
<p>So what were his strategies? Well, here are some that I can remember:</p>
<p><span style="font-style: italic;">* Bet with a clear head. If you have a favourite team, leave it alone</span><br style="font-style: italic;" /><span style="font-style: italic;">* Avoid accumulator bets. With each accumulated event, the odds lurch further the way of the bookie</span><br style="font-style: italic;" /><span style="font-style: italic;">* Do your research. Pick, say, ten football teams a year and study them continually. Find out which games they tend to win, which they lose, which players appear to be key, injury situations etc. This will all give you a clear advantage over the lazier bookies</span><br style="font-style: italic;" /><span style="font-style: italic;">* Stick to sports you like and understand. You&#8217;ll have to study hard, but it will be easier for you if you happen to enjoy the game</span><br style="font-style: italic;" /><span style="font-style: italic;">* Steer clear of boxing</span></p>
<p>There were a few others, but that gives a feel for it<br />
<span id="more-128"></span><br />
<span style="font-style: italic;">Very interesting, </span>(you may say)<span style="font-style: italic;"> but what&#8217;s this all got to do with <a href="http://en.wikipedia.org/wiki/W._Edwards_Deming">Deming</a>? This is (supposed to be) a quality improvement blog, is it not? </span></p>
<p>Well there is a point to this tale, and here it is</p>
<p>Remember in the earlier post, <a href="http://blog.capablepeople.co.uk/2008/07/demings-inconvenient-truth/">Deming&#8217;s inconvenient truth</a>, I suggested that <a href="http://en.wikipedia.org/wiki/W._Edwards_Deming">Deming</a> taught that management decisions should wherever possible be based on hard facts and evidence? But also that a lot of management information is both unknown and unknowable? Well that summarises in a nutshell that business is one big lottery. There are no certainties, and for every success there is a failure. If all management information was knowable there would be a scientific formula to remove all elements of risk from the decision making process. But it isn&#8217;t and there isn&#8217;t. That is a lot like the world of professional gambling. All bets carry an inherent risk, and professional gamblers accept risk and occasional failure as an unavoidable fact of life. <strong>HOWEVER</strong> the most successful gamblers use as much Management Information as they can get their hands on to slant the odds their way</p>
<p>That, I propose, is probably as close to an absolute definition of <strong><em>&#8220;Management Information&#8221;,</em></strong> its uses and limitations, that you&#8217;re ever likely to get</p>
<p>As definitions go, it is a bit on the long side. Sorry<br />
<a target="_new" href="http://EzineArticles.com/"><br />
<img src="http://EzineArticles.com/featured/images/ea_featured_1.gif" border="0" alt="As Featured On EzineArticles" title="Making sense of Deming" /><br />
</a></p>
<p>Post from: <a href="http://www.capablepeople.co.uk/blog">Capable People Blog</a><br/><br/><a href="http://blog.capablepeople.co.uk/2009/10/making-sense-of-deming/">Making sense of Deming</a></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.capablepeople.co.uk/2009/10/making-sense-of-deming/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Embedding Risk Management</title>
		<link>http://blog.capablepeople.co.uk/2009/05/embedding-risk-management/</link>
		<comments>http://blog.capablepeople.co.uk/2009/05/embedding-risk-management/#comments</comments>
		<pubDate>Sat, 30 May 2009 11:33:15 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Risk & Assurance]]></category>
		<category><![CDATA[risk management]]></category>

		<guid isPermaLink="false">http://www.thetyphon.com/capableblog/?p=56</guid>
		<description><![CDATA[Risk management needs to become part of the way business is conducted. Embedding risk management in the regular, daily affairs of the organisation is not an easy task and requires continuous effort. To achieve this measure of acceptance may take some time; however, a number of steps can be taken to help the process SUPPORT [...]<p>Post from: <a href="http://www.capablepeople.co.uk/blog">Capable People Blog</a><br/><br/><a href="http://blog.capablepeople.co.uk/2009/05/embedding-risk-management/">Embedding Risk Management</a></p>
]]></description>
			<content:encoded><![CDATA[<p class="MsoNormal" style="line-height: 150%;"><span style="font-family: &quot;Trebuchet MS&quot;,&quot;sans-serif&quot;;">Risk management needs to become part of the way business is conducted. Embedding risk management in the regular, daily affairs of the organisation is not an easy task and requires continuous effort. To achieve this measure of acceptance may take some time; however, a number of steps can be taken to help the process</span></p>
<p><span style="font-family: &quot;Trebuchet MS&quot;,&quot;sans-serif&quot;;"><span style="font-weight: bold;">SUPPORT (Sponsorship) from the Top</span></span></p>
<p class="MsoNormal" style="line-height: 150%;"><span style="font-family: &quot;Trebuchet MS&quot;,&quot;sans-serif&quot;;">The implementation must be sponsored at board level and positively supported by all senior people within the organisation. There are a number of ways this can be done: presentations, devising a risk policy, inclusion on agendas</span></p>
<p class="MsoNormal"><span style="font-family: &quot;Trebuchet MS&quot;,&quot;sans-serif&quot;;"><span style="font-weight: bold;">POLICY</span></span></p>
<p style="line-height: 150%;"><span style="font-family: &quot;Trebuchet MS&quot;,&quot;sans-serif&quot;;">Every organisation should have a risk management policy, whatever the approach by the organisation is to risk. Such a policy should be formal and set a framework within which an organisation has to implement its risk management responsibilities and processes. The policy should include:</span></p>
<ul type="disc">
<li class="MsoNormal" style="line-height: 150%;"><span style="font-family: &quot;Trebuchet MS&quot;,&quot;sans-serif&quot;;">Objectives and the overall purpose of risk management for the organisation (statement of intent). There should be links to other policies, for example audit (internal and external), control, governance, conduct, insurance and so on </span></li>
<li class="MsoNormal" style="line-height: 150%;"><span style="font-family: &quot;Trebuchet MS&quot;,&quot;sans-serif&quot;;">Responsibility for risk management should be clearly set out at board, management and operating levels. This should be repeated in specific functionresponsibilities and job descriptions throughout the organisation. </span></li>
<li class="MsoNormal" style="line-height: 150%;"><span style="font-family: &quot;Trebuchet MS&quot;,&quot;sans-serif&quot;;">If there is an audit and/or risk committee in an organisation their responsibilities for risk management should be clearly stated in their terms of reference. This applies also to internal audit and any other internal or external assurance activity</span></li>
<li class="MsoNormal" style="line-height: 150%;"><span style="font-family: &quot;Trebuchet MS&quot;,&quot;sans-serif&quot;;">Risk appetite, the level of risk the board is prepared to accept to achieve its objectives, in specific circumstances or possible events. Indicating the levels of control that are needed to mitigate against specific risks</span></li>
<li class="MsoNormal" style="line-height: 150%;"><span style="font-family: &quot;Trebuchet MS&quot;,&quot;sans-serif&quot;;">An explanation of the key components that sets out the overall approach to risk management, including the commitment of resources (staff and information systems), training and development</span></li>
<li class="MsoNormal" style="line-height: 150%;"><span style="font-family: &quot;Trebuchet MS&quot;,&quot;sans-serif&quot;;">It is necessary for key risks to be considered on a regular basis and reported up the hierarchy as required. Designated managers at various levels report upwards (on either a quarterly of half yearly basis) on the work done to keep risk and control procedures up to date and appropriate to circumstances within their particular area of responsibility.</span><span style="font-family: &quot;Trebuchet MS&quot;,&quot;sans-serif&quot;;"></span></li>
<li class="MsoNormal" style="line-height: 150%;"><span style="font-family: &quot;Trebuchet MS&quot;,&quot;sans-serif&quot;;">A common risk language, defining the terms to be used<span> </span></span></li>
</ul>
<p class="MsoNormal" style="margin-left: 18pt;"><strong><span style="font-family: &quot;Trebuchet MS&quot;,&quot;sans-serif&quot;; font-weight: normal;"><span style="font-weight: bold;">STRATEGY</span></span></strong></p>
<p class="MsoNormal" style="margin-left: 18pt; line-height: 150%;"><span style="font-family: &quot;Trebuchet MS&quot;,&quot;sans-serif&quot;;">The organisation must develop a clear articulated and communicated strategy, explaining how risk management will operate according to an implementation plan (timetable). This will be consistent with specific responsibilities and roles set out within the policy</span></p>
<p class="MsoNormal" style="margin-left: 18pt; line-height: 150%;"><span style="font-family: &quot;Trebuchet MS&quot;,&quot;sans-serif&quot;;">Risk management must be linked into other activities as a matter of routine, such as business plans, project plans, team meetings etc. </span></p>
<p class="MsoNormal" style="margin-left: 18pt; line-height: 150%;"><span style="font-family: &quot;Trebuchet MS&quot;,&quot;sans-serif&quot;;">Risk management must be a high priority for everyone in the organisation and must be clearly built into both departmental and individual performance objectives.</span><br />
<span id="more-56"></span></p>
<p class="MsoNormal" style="margin-left: 18pt;"><span style="font-family: &quot;Trebuchet MS&quot;,&quot;sans-serif&quot;;"><span style="font-weight: bold;">STRUCTURE (STAFF)</span></span></p>
<p class="MsoNormal" style="margin-left: 18pt; text-align: justify; line-height: 150%;"><strong><span style="font-family: &quot;Trebuchet MS&quot;,&quot;sans-serif&quot;; font-weight: normal;">Linked to strategy there needs to be in-house expertise and sufficient resources within the business in the form of an organisational structure</span></strong></p>
<p class="MsoNormal" style="margin-left: 18pt;"><strong><span style="font-family: &quot;Trebuchet MS&quot;,&quot;sans-serif&quot;; font-weight: normal;"><span style="font-weight: bold;">TRAINING &amp; EDUCATION (SKILLS)</span></span></strong></p>
<p class="MsoNormal" style="margin-left: 18pt; line-height: 150%;"><strong><span style="font-family: &quot;Trebuchet MS&quot;,&quot;sans-serif&quot;; font-weight: normal;">Training and education are needed to help people understand their role as well providing explanation and practice of the process. This helps to ensure consistency and should be based upon clear guidelines and a simple working method that is effective. The method for identifying and assessing risk must be easy to use and not be an end in itself</span></strong></p>
<p class="MsoNormal" style="margin-left: 18pt; line-height: 150%;"><strong><span style="font-family: &quot;Trebuchet MS&quot;,&quot;sans-serif&quot;; font-weight: normal;"><span> </span>A good way of helping the process is to run risk workshops</span></strong></p>
<p class="MsoNormal" style="margin-left: 18pt; line-height: 150%;"><strong><span style="font-family: &quot;Trebuchet MS&quot;,&quot;sans-serif&quot;; font-weight: normal;">If you&#8217;d like a full copy of Chris&#8217; article, please request it using the <a href="http://www.capablepeople.co.uk/contact-us">contact form</a> on the Capable People <a href="http://www.capablepeople.co.uk/">website</a><br />
</span></strong></p>
<p>The McKinsey’s 7 S framework is a good basis for developing a risk culture</p>
<p>Post from: <a href="http://www.capablepeople.co.uk/blog">Capable People Blog</a><br/><br/><a href="http://blog.capablepeople.co.uk/2009/05/embedding-risk-management/">Embedding Risk Management</a></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.capablepeople.co.uk/2009/05/embedding-risk-management/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Corporate Governance</title>
		<link>http://blog.capablepeople.co.uk/2009/04/corporate-governance/</link>
		<comments>http://blog.capablepeople.co.uk/2009/04/corporate-governance/#comments</comments>
		<pubDate>Wed, 08 Apr 2009 16:27:34 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Leadership & Management]]></category>
		<category><![CDATA[Risk & Assurance]]></category>
		<category><![CDATA[corporate governance]]></category>
		<category><![CDATA[management of risk]]></category>
		<category><![CDATA[risk management]]></category>

		<guid isPermaLink="false">http://www.thetyphon.com/capableblog/?p=203</guid>
		<description><![CDATA[GOVERNANCE PRINCIPLES The phrase “corporate governance” is prominent in both the business world and the public sector. This is due to the increasing pressure to protect shareholder value and public money following a number of high profile financial scandals, which have received media attention Good governance is about the effective supervision of the company, and managing [...]<p>Post from: <a href="http://www.capablepeople.co.uk/blog">Capable People Blog</a><br/><br/><a href="http://blog.capablepeople.co.uk/2009/04/corporate-governance/">Corporate Governance</a></p>
]]></description>
			<content:encoded><![CDATA[<p>GOVERNANCE PRINCIPLES</p>
<p class="MsoNormal" style="line-height: 150%;"><span style="font-family: 'Arial','sans-serif';">The phrase “corporate governance” is prominent in both the business world and the public sector. This is due to the increasing pressure to protect shareholder value and public money following a number of high profile financial scandals, which have received media attention </span></p>
<p>Good governance is about the effective supervision of the company, and managing risk, so that business is done competently, with integrity and due regard of the interests of all stakeholders. It is the means by which organisations can achieve their objectives and sustain their performance</p>
<p class="MsoNormal" style="line-height: 150%;"><span style="font-family: 'Arial','sans-serif';">Investors, including financial institutions and banks, have put a growing emphasis on how well companies manage themselves and their relationships with shareholders and stakeholders. Those organisations that can demonstrate that they act with honesty and probity are now seen as having a competitive advantage </span></p>
<p class="MsoNormal" style="line-height: 150%;"><span style="font-family: 'Arial','sans-serif';">The benefits to be gained from applying best practice in governance include: </span></p>
<p>Confidence of investors – who may be more inclined to support development and growth</p>
<p>Trust of employees – with the likelihood of increased commitment and retention</p>
<p>Stakeholder &amp; Customer confidence – leading to increased competitiveness in the market place</p>
<p>Long-term sustainability – through achievement of aims and financial strength</p>
<p>Resilience and adaptable to change – built upon a firm foundation of risk management and control</p>
<p class="MsoNormal" style="line-height: 150%;"><span style="font-family: 'Arial','sans-serif';">The key guidance on corporate governance is directed towards companies listed upon the stock exchange and is set out within the Combined Code, which was originally published in 1998 but has been revised in 2003 and 2006. The code is voluntary and is designed to strengthen and increase the effectiveness of the unitary Board system (one main board with a chairman and a CEO). The main principles of the code are as follows:</span></p>
<p class="MsoNormal" style="margin-left: 36pt; text-indent: -36pt;"><span style="font-family: 'Arial','sans-serif';">A. <span> </span>Every company should be headed by an effective board collectively responsible for the Company. Their duties should include:</span></p>
<p class="MsoNormal" style="margin-left: 54pt; text-indent: -18pt; line-height: 150%;"><span style="font-family: 'Courier New';"><span>o<span style="font-family: 'Times New Roman'; font-style: normal; font-variant: normal; font-weight: normal; font-size: 7pt; line-height: normal; font-size-adjust: none; font-stretch: normal;"> </span></span></span><span style="font-family: 'Arial','sans-serif';">Setting the company’s strategic aims</span></p>
<p class="MsoNormal" style="margin-left: 54pt; text-indent: -18pt; line-height: 150%;"><span style="font-family: 'Courier New';"><span>o<span style="font-family: 'Times New Roman'; font-style: normal; font-variant: normal; font-weight: normal; font-size: 7pt; line-height: normal; font-size-adjust: none; font-stretch: normal;"> </span></span></span><span style="font-family: 'Arial','sans-serif';">Providing the leadership to put strategies into effect</span></p>
<p class="MsoNormal" style="margin-left: 54pt; text-indent: -18pt; line-height: 150%;"><span style="font-family: 'Courier New';"><span>o<span style="font-family: 'Times New Roman'; font-style: normal; font-variant: normal; font-weight: normal; font-size: 7pt; line-height: normal; font-size-adjust: none; font-stretch: normal;"> </span></span></span><span style="font-family: 'Arial','sans-serif';">Supervising the management of the business</span></p>
<p class="MsoNormal" style="margin-left: 54pt; text-indent: -18pt; line-height: 150%;"><span style="font-family: 'Courier New';"><span>o<span style="font-family: 'Times New Roman'; font-style: normal; font-variant: normal; font-weight: normal; font-size: 7pt; line-height: normal; font-size-adjust: none; font-stretch: normal;"> </span></span></span><span style="font-family: 'Arial','sans-serif';">Reporting to shareholder on their stewardship</span></p>
<p class="MsoNormal" style="margin-left: 36pt; text-indent: -36pt;"><span style="font-family: 'Arial','sans-serif';">B. <span> </span>Levels of remuneration should be sufficient to attract, retain and motivate directors. There should also be a transparent policy for setting executive remuneration.</span></p>
<p class="MsoNormal" style="margin-left: 36pt; text-indent: -36pt;"><span style="font-family: 'Arial','sans-serif';">C.<span> </span>The Board should carry out a balanced and understandable assessment of the company’s position: </span></p>
<p class="MsoNormal" style="margin-left: 54pt; text-indent: -18pt;"><span style="font-family: 'Courier New';"><span>o<span style="font-family: 'Times New Roman'; font-style: normal; font-variant: normal; font-weight: normal; font-size: 7pt; line-height: normal; font-size-adjust: none; font-stretch: normal;"> </span></span></span><span style="font-family: 'Arial','sans-serif';">The board should maintain a sound system of internal control to safeguard shareholder’s investment and the company’s assets</span></p>
<p class="MsoNormal" style="margin-left: 18pt; text-indent: -36pt;"><span style="font-family: 'Arial','sans-serif';"> </span></p>
<p class="MsoNormal" style="margin-left: 54pt; text-indent: -18pt;"><span style="font-family: 'Courier New';"><span>o<span style="font-family: 'Times New Roman'; font-style: normal; font-variant: normal; font-weight: normal; font-size: 7pt; line-height: normal; font-size-adjust: none; font-stretch: normal;"> </span></span></span><span style="font-family: 'Arial','sans-serif';">The board should at least annually conduct a review of the effectiveness of the system of internal control and should report to shareholders that they have done so. </span></p>
<p class="MsoNormal" style="margin-left: 36pt;"><span style="font-family: 'Arial','sans-serif';"> </span></p>
<p class="MsoNormal" style="margin-left: 54pt; text-indent: -18pt;"><span style="font-family: 'Courier New';"><span>o<span style="font-family: 'Times New Roman'; font-style: normal; font-variant: normal; font-weight: normal; font-size: 7pt; line-height: normal; font-size-adjust: none; font-stretch: normal;"> </span></span></span><span style="font-family: 'Arial','sans-serif';">The review should cover all material controls, including Financial, Operational and Compliance controls and Risk Management systems</span></p>
<p class="MsoNormal" style="margin-left: 36pt; text-indent: -36pt;"><span style="font-family: 'Arial','sans-serif';">D.<span> </span>Dialogue with shareholders based on objectives, including an AGM to encourage shareholder participation</span></p>
<p><span id="more-204"></span></p>
<p class="MsoNormal" style="line-height: 150%;"><span style="font-family: 'Arial','sans-serif';">Since the publication of the Combined Code and related guidance upon the nature of internal control issued in 1999 (Turnbull Report) there has been a great deal of debate and academic research upon what represents best practice with regard to corporate governance. There are differences of opinion but the following list, reported in </span><em><span style="font-style: normal; font-family: 'Arial','sans-serif';">Tottel’s Corporate Governance Handbook</span></em><span style="font-family: 'Arial','sans-serif';">2005, is generally regarded as a useful summary</span></p>
<p>Principles of Corporate Governance, Tottel’s Handbook 2005.</p>
<p>1. Stakeholder involvement and control in the business<br />
2. A strong, involved board of directors<br />
3. Risk assessment and control<br />
4. A strong, independent element on the board<br />
5. A balanced board composition<br />
6. Maximum and reliable public reporting<br />
7. Avoidance of excessive power at the top of the business<br />
8. Effective monitoring of management by the board<br />
9. Competence and commitment<br />
10. A strong audit process</p>
<p class="MsoNormal" style="line-height: 150%;"><span style="font-family: 'Arial','sans-serif';">While much of this may seem remote and of passing interest to small or medium size companies there are a several practical aspects that can be drawn from the detail that could provide a competitive advantage to small and medium size organisations. Consider the action you can take under the following categories to improve governance</span></p>
<p class="MsoNormal" style="margin-bottom: 12pt; margin-left: 18pt;"><strong><span style="font-family: 'Arial','sans-serif';">Strategic</span></strong></p>
<ul type="disc">
<li class="MsoNormal" style="margin-bottom: 12pt;"><strong><span style="font-weight: normal; font-family: 'Arial','sans-serif';">Fully document and communicate your values and business objectives to stakeholders: employees, customers, investors. Seek feedback</span></strong></li>
<li class="MsoNormal" style="margin-bottom: 12pt;"><strong><span style="font-weight: normal; font-family: 'Arial','sans-serif';">Set specific targets and objectives for the most senior managers and hold review meetings</span></strong></li>
<li class="MsoNormal" style="margin-bottom: 12pt;"><strong><span style="font-weight: normal; font-family: 'Arial','sans-serif';">Establish a simple and effective system of risk management that will prevent things from going wrong. Encourage involvement is risk</span></strong></li>
<li class="MsoNormal" style="margin-bottom: 12pt;"><strong><span style="font-weight: normal; font-family: 'Arial','sans-serif';">Find or appoint a critical friend(s) who is prepared to ask challenging questions about performance and direction of the business</span></strong></li>
</ul>
<p class="MsoNormal" style="margin-bottom: 12pt; margin-left: 18pt;"><strong><span style="font-family: 'Arial','sans-serif';">Operational</span></strong></p>
<ul type="disc">
<li class="MsoNormal" style="margin-bottom: 12pt;"><strong><span style="font-weight: normal; font-family: 'Arial','sans-serif';">Look at how you receive assurance that the business complies with regulations and contractual conditions, such as the Companies Act, Inland Revenue, VAT, Data Protection, and Health &amp; Safety etc </span></strong></li>
<li class="MsoNormal" style="margin-bottom: 12pt;"><strong><span style="font-weight: normal; font-family: 'Arial','sans-serif';">Consider the need for audit processes to gain full assurance</span></strong></li>
<li class="MsoNormal" style="margin-bottom: 12pt;"><span style="font-family: 'Arial','sans-serif';">Create a simple set of measures (key performance indicators) that tell you how the business is performing. Include stakeholder measures to provide a balanced scorecard</span></li>
<li class="MsoNormal" style="margin-bottom: 12pt;"><span style="font-family: 'Arial','sans-serif';">Set out standards of behaviour and customer expectations to emphasis the importance of customer care</span></li>
</ul>
<p class="MsoNormal" style="margin-bottom: 12pt; margin-left: 18pt;"><strong><span style="font-family: 'Arial','sans-serif';">Financial</span></strong></p>
<ul type="disc">
<li class="MsoNormal" style="margin-bottom: 12pt;"><span style="font-family: 'Arial','sans-serif';">Prepare long-term financial plans, cash flow projections and annual budgets that link directly to your business plans and objectives</span></li>
<li class="MsoNormal" style="margin-bottom: 12pt;"><span style="font-family: 'Arial','sans-serif';">Establish decision and authority levels for managers so that financial risks are understood and applied.</span></li>
<li class="MsoNormal" style="margin-bottom: 12pt;"><span style="font-family: 'Arial','sans-serif';">Set credit limits for your key customers and carefully monitor and mange your debts.</span></li>
<li class="MsoNormal" style="margin-bottom: 12pt;"><span style="font-family: 'Arial','sans-serif';">Ensure that there is reconciliation of your balance sheet figures to supporting records. Report and regularly review financial performance</span></li>
</ul>
<p class="MsoNormal" style="line-height: 150%;"><span style="font-family: 'Arial','sans-serif';">If you would like to discuss corporate governance issues further or would like to implement risk management and audit processes within your business please <a href="http://www.capablepeople.co.uk/contact-us">contact</a> <a href="http://www.capablepeople.co.uk/">Capable People</a> </span></p>
<p>Chris Baker</p>
<p class="MsoNormal" style="line-height: 150%;"><span style="font-family: 'Arial','sans-serif';">Technical Development Manager for the Institute of Internal Auditors, </span></p>
<p class="MsoNormal" style="line-height: 150%;"><span style="font-family: 'Arial','sans-serif';">and critical friend of <a href="http://www.capablepeople.co.uk/">Capable People</a></span></p>
<p>Post from: <a href="http://www.capablepeople.co.uk/blog">Capable People Blog</a><br/><br/><a href="http://blog.capablepeople.co.uk/2009/04/corporate-governance/">Corporate Governance</a></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.capablepeople.co.uk/2009/04/corporate-governance/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Risk and assurance &#8211; A business approach to managing quality</title>
		<link>http://blog.capablepeople.co.uk/2008/10/risk-and-assurance-a-business-approach-to-managing-quality/</link>
		<comments>http://blog.capablepeople.co.uk/2008/10/risk-and-assurance-a-business-approach-to-managing-quality/#comments</comments>
		<pubDate>Wed, 22 Oct 2008 17:58:00 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Leadership & Management]]></category>
		<category><![CDATA[Quality Improvement]]></category>
		<category><![CDATA[Risk & Assurance]]></category>
		<category><![CDATA[management of risk]]></category>
		<category><![CDATA[quality management]]></category>
		<category><![CDATA[risk and assurance]]></category>
		<category><![CDATA[risk management]]></category>

		<guid isPermaLink="false">http://www.thetyphon.com/capableblog/?p=130</guid>
		<description><![CDATA[Here&#8217;s a bit of a thread started off with an innocuous question regarding the proposed redefinition of the word &#8220;product&#8221; in ISO 9000:2008. This meanders around a bit until Paul Staiano makes a profound point that got us thinking. Is there really a difference between a &#8220;process approach&#8221; to managing quality and a &#8220;quality approach&#8221; [...]<p>Post from: <a href="http://www.capablepeople.co.uk/blog">Capable People Blog</a><br/><br/><a href="http://blog.capablepeople.co.uk/2008/10/risk-and-assurance-a-business-approach-to-managing-quality/">Risk and assurance &#8211; A business approach to managing quality</a></p>
]]></description>
			<content:encoded><![CDATA[<p>Here&#8217;s a bit of a <a href="http://www.linkedin.com/answers/business-operations/quality-management-standards/OPS_QMA/128544-5354732?browseIdx=3&amp;sik=1195377326763&amp;goback=%2Eahp%2Each_OPS*4QMA%2Eabq_1_1195377326763_n_c_OPS*4QMA">thread</a> started off with an innocuous question regarding the proposed redefinition of the word &#8220;product&#8221; in ISO 9000:2008. This meanders around a bit until Paul Staiano makes a profound point that got us thinking. Is there really a difference between a <span style="font-style: italic;">&#8220;process approach&#8221;</span> to managing quality and a <span style="font-style: italic;">&#8220;quality approach&#8221;</span> to managing quality? And if there is, what is it, what does it mean and which is best?</p>
<p>Well there&#8217;s no doubting that some quality departments are so wrapped up with their own methods, tools, techniques, definitions and auditor requirements that there is a risk that the whole concept of &#8220;business&#8221; gets blurred, lost even. Maybe that is where Paul was coming from. But even then, is it right to re-focus just on process? We recall a quote attributed to <a href="http://en.wikipedia.org/wiki/Winston_Churchill">Winston Churchill</a> (that we can no longer locate, so we&#8217;ll have to paraphrase) that went something like <span style="font-style: italic;">&#8220;no matter how beautiful the process, we do have to keep an eye on the result&#8221;</span>. Can&#8217;t argue with that surely. What with our obsession with elegant solutions, we do have to ensure that they are, fundamentally, solutions, don&#8217;t we?</p>
<p>There was a great thread on <a href="http://learnsigma.com/">learn sigma</a> (14th November) that demonstrated how some people can get all hot under the collar as soon as a particular methodology is mentioned. So much so that the whole issue of <a href="http://learnsigma.com/innovation-six-sigma-disaster/#comments">context </a>is completely ignored. Quality guys, eh? So where does that take us? Well somewhere along the line we need to raise the sites up a bit above all our ISO/EFQM/Lean/Sigma and remember what the business is trying to achieve and the fundamental dynamics of it all. The 7th November thread on <a href="http://www.racheleelnaugh.blogspot.com/">Rachel Elnaugh&#8217;s blog</a> brings us back to risk and reputation management. So are we about to propose that we actually need to adopt a <span style="font-style: italic; font-weight: bold;">business approach</span> to managing quality? Worth thinking about. We&#8217;ve had a <a href="http://www.capablepeople.co.uk/documents/GOVERNANCEandSMEs.pdf">great article</a> (an as yet undiscovered gem to most) on the high level concepts of risk and assurance posted in our <a href="http://www.capablepeople.co.uk/">main site</a> members&#8217; area for a little while now, we may as well share it with you. Take a look at it. It&#8217;s great sense, the foundation of a quality strategy you could say. But after reading it ask yourself the question <span style="font-style: italic;">&#8220;by the time we get to the operational implementation of quality, do we still remember where it all came from and why we&#8217;re doing it?&#8221;</span></p>
<p>In other words <span style="font-style: italic;">&#8220;do we adopt <span style="font-weight: bold;">business approach</span> to managing quality or a <span style="font-weight: bold;">quality approach</span> to managing quality?&#8221;</span></p>
<p>Dare we suggest that if the QA department was as fastidious with the calibration and periodic re-calibration of its strategy as it is with the re-calibration of its measuring instruments, that we&#8217;d all be a bit better off?<br />
<span style="font-style: italic;"><br />
</span></p>
<p>&#8220;poking the eye of quality &#8230; just to see what happens&#8221;</p>
<p>Post from: <a href="http://www.capablepeople.co.uk/blog">Capable People Blog</a><br/><br/><a href="http://blog.capablepeople.co.uk/2008/10/risk-and-assurance-a-business-approach-to-managing-quality/">Risk and assurance &#8211; A business approach to managing quality</a></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.capablepeople.co.uk/2008/10/risk-and-assurance-a-business-approach-to-managing-quality/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Understanding your risks &#8211; the key to quality control</title>
		<link>http://blog.capablepeople.co.uk/2008/09/understanding-your-risks-the-key-to-quality-control/</link>
		<comments>http://blog.capablepeople.co.uk/2008/09/understanding-your-risks-the-key-to-quality-control/#comments</comments>
		<pubDate>Fri, 26 Sep 2008 17:30:44 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Occupational Health & Safety]]></category>
		<category><![CDATA[Quality Improvement]]></category>
		<category><![CDATA[Risk & Assurance]]></category>

		<guid isPermaLink="false">http://www.thetyphon.com/capableblog/?p=126</guid>
		<description><![CDATA[The recent financial troubles in Wall Street and across the wider globe should have at least reminded us of one thing. Where there is a lot of money flying around, and a weakness in regulation, greed will prosper and corruption will not be far behind. Like it or not, that is the way that we [...]<p>Post from: <a href="http://www.capablepeople.co.uk/blog">Capable People Blog</a><br/><br/><a href="http://blog.capablepeople.co.uk/2008/09/understanding-your-risks-the-key-to-quality-control/">Understanding your risks &#8211; the key to quality control</a></p>
]]></description>
			<content:encoded><![CDATA[<p>The recent <a href="http://news.bbc.co.uk/1/hi/business/7625419.stm">financial troubles</a> in Wall Street and across the wider globe should have at least reminded us of one thing. Where there is a lot of money flying around, and a weakness in regulation, greed will prosper and <a href="http://news.bbc.co.uk/1/hi/business/7632790.stm">corruption</a> will not be far behind. Like it or not, that is the way that we appear to be hard-wired as a species. Effective risk and quality management should never ignore these factors.</p>
<p>Certain things shouldn&#8217;t happen, true enough, but if they can happen they will do  In risk management terms we must assume that anything that can happen, sooner or later, will. The only question worth asking is whether the risk is worth managing, or whether we are prepared to <a href="http://news.bbc.co.uk/1/hi/uk/7637605.stm">accept the risk</a> and live with the consequences  The recent problems concerning the contamination of <a href="http://news.bbc.co.uk/1/hi/world/asia-pacific/7620812.stm">baby milk</a>, and <a href="http://news.bbc.co.uk/1/hi/world/asia-pacific/7637001.stm">confectionery</a> with the harmful chemical <a href="http://en.wikipedia.org/wiki/Melamine">melamine</a>, demonstrate the potential consequences of poor management of risk.</p>
<p>But let&#8217;s not dress this up as anything it is not. This is not a case where incompetence, weak process control or contaminated materials have allowed out of specification product to be <span style="font-weight: bold; font-style: italic; text-decoration: underline;">inadvertently</span> produced and shipped. In each of these cases it was a deliberate act by the manufacturer concerned. The melamine was <span style="font-weight: bold;">supposed </span>to be there, the products were <span style="font-weight: bold; font-style: italic; text-decoration: underline;">designed </span>to be poisonous. The consequences for the consumer being of secondary importance to the manipulation of test results to show a higher than actual protein content (something that melamine does), and therefore to command a higher sale price  So what lessons can be learned from these recent events?</p>
<p>Well, if nothing else, that there is no such thing in life as a free lunch. The low cost of Chinese produced goods has been attractive to many western firms over the past half decade or so, but we do need to proceed with our eyes wide open. Certain risks are increased and, let&#8217;s face it, if <a href="http://news.bbc.co.uk/1/hi/world/asia-pacific/7637001.stm">children&#8217;s sweets</a> and <a href="http://news.bbc.co.uk/1/hi/world/asia-pacific/7629130.stm">baby milk</a> are not off-limits for dangerous and fraudulent activity, nothing is. <a href="http://en.wikipedia.org/wiki/Melamine">Melamine</a> even <a href="http://news.bbc.co.uk/1/hi/world/asia-pacific/7635432.stm">poisons primates</a></p>
<p>The European Commission has <a href="http://news.bbc.co.uk/1/hi/world/europe/7635594.stm">&#8220;acted swiftly</a>&#8221; to suspend the import of all Chinese baby food that contains traces of milk to the EU. Given China&#8217;s recent record it beggars belief that anyone would contemplate importing baby milk from that location just now under almost any circumstances  Everything comes at a cost, and with low production costs often that means corners are cut.</p>
<p>incredible</p>
<p><a href="http://www.capablepeople.co.uk">www.capablepeople.co.uk</a></p>
<p>Post from: <a href="http://www.capablepeople.co.uk/blog">Capable People Blog</a><br/><br/><a href="http://blog.capablepeople.co.uk/2008/09/understanding-your-risks-the-key-to-quality-control/">Understanding your risks &#8211; the key to quality control</a></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.capablepeople.co.uk/2008/09/understanding-your-risks-the-key-to-quality-control/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Information Risk &#8211; It&#8217;s a Board Room Matter</title>
		<link>http://blog.capablepeople.co.uk/2008/09/information-risk-its-a-board-room-matter/</link>
		<comments>http://blog.capablepeople.co.uk/2008/09/information-risk-its-a-board-room-matter/#comments</comments>
		<pubDate>Fri, 19 Sep 2008 17:51:55 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Risk & Assurance]]></category>

		<guid isPermaLink="false">http://www.thetyphon.com/capableblog/?p=125</guid>
		<description><![CDATA[Why Information Risk is a Board-level Issue • Every organisation, whether public or private sector, handles information. This information must be appropriately controlled and protected against the threats, non-technical as well as technical, that can affect it • Compromised information can cause enormous damage to an organisation’s operations and reputation. Information not appropriately protected can [...]<p>Post from: <a href="http://www.capablepeople.co.uk/blog">Capable People Blog</a><br/><br/><a href="http://blog.capablepeople.co.uk/2008/09/information-risk-its-a-board-room-matter/">Information Risk &#8211; It&#8217;s a Board Room Matter</a></p>
]]></description>
			<content:encoded><![CDATA[<p>Why Information Risk is a Board-level Issue</span><br style="font-weight: bold; text-decoration: underline;" /><br />
• Every organisation, whether public or private sector, handles information. This information must be appropriately controlled and protected against the threats, non-technical as well as technical, that can affect it</p>
<p>• Compromised information can cause enormous damage to an organisation’s operations and reputation. Information not appropriately protected can lead to serious compliance and legal failures</p>
<p>• Good Information Risk Management helps an organisation get the best out of its information and to move forward and develop, confident that its risks</p>
<p><a href="http://www.capablepeople.co.uk/documents/INFoBoardRoom.pdf">Read more &#8230;</a></p>
<p><a href="http://www.capablepeople.co.uk">www.capablepeople.co.uk</a></p>
<p>Post from: <a href="http://www.capablepeople.co.uk/blog">Capable People Blog</a><br/><br/><a href="http://blog.capablepeople.co.uk/2008/09/information-risk-its-a-board-room-matter/">Information Risk &#8211; It&#8217;s a Board Room Matter</a></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.capablepeople.co.uk/2008/09/information-risk-its-a-board-room-matter/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Is long-term, goal driven planning a waste of time?</title>
		<link>http://blog.capablepeople.co.uk/2008/08/is-long-term-goal-driven-planning-a-waste-of-time/</link>
		<comments>http://blog.capablepeople.co.uk/2008/08/is-long-term-goal-driven-planning-a-waste-of-time/#comments</comments>
		<pubDate>Wed, 27 Aug 2008 17:22:00 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Leadership & Management]]></category>
		<category><![CDATA[Quality Improvement]]></category>
		<category><![CDATA[Risk & Assurance]]></category>

		<guid isPermaLink="false">http://www.thetyphon.com/capableblog/?p=123</guid>
		<description><![CDATA[There is a well-known joke in economics circles that goes something like this: A student approaches his economics professor to challenge a low mark that he has been given on a recent assignment “I can’t understand the low mark you’ve given me – I got the same question last year and you yourself gave me [...]<p>Post from: <a href="http://www.capablepeople.co.uk/blog">Capable People Blog</a><br/><br/><a href="http://blog.capablepeople.co.uk/2008/08/is-long-term-goal-driven-planning-a-waste-of-time/">Is long-term, goal driven planning a waste of time?</a></p>
]]></description>
			<content:encoded><![CDATA[<p class="MsoNormal">There is a well-known joke in economics circles that goes something like this:</p>
<p class="MsoNormal">A student approaches his economics professor to challenge a low mark that he has been given on a recent assignment</p>
<p class="MsoNormal"><span style="font-style: italic;">“I can’t understand the low mark you’ve given me – I got the same question last year and you yourself gave me an A-grade” </span>wails the student</p>
<p class="MsoNormal"><span style="font-style: italic;">“Yes I did”</span> responds the professor <span style="font-style: italic;">“but this year the correct answer is different”</span></p>
<p class="MsoNormal">We are living in a continually changing world with few stable and absolute truths, consequently the future is at best difficult to predict. On any given day we can listen to countless economics experts debating the state of the global economy and what even the short-term future is likely to mean to nations, sectors and economies. There are dozens of different points of view and, no doubt, in two years time, somebody or other will be able to proclaim that they were right. Thing is, though, statistically, provided there are enough differing points of view, <span style="font-weight: bold; font-style: italic;">someone </span>has to be right. But let’s not get too carried away with ourselves. No-one is <span style="font-weight: bold; font-style: italic;">always </span>right because if such a person existed we would all know his name, because he would be king of the world. We actually live in a world of uncertainties. Deming knew this, and <a href="http://blog.capablepeople.co.uk/2008/07/demings-inconvenient-truth/">we’ve written on the subject</a> a couple of times in the past. He knew that not all management information was known or even knowable, and that planning was merely an exercise in trying to shorten the odds on success – but it was <a href="http://blog.capablepeople.co.uk2008/10/making-sense-of-deming/">no guarantee</a></p>
<p class="MsoNormal">Over past few weeks, Channel 4 has been showing <a href="http://en.wikipedia.org/wiki/Richard_Dawkins">Richard Dawkins’</a> excellent series <span style="font-weight: bold; font-style: italic;">“The Genius of Darwin”</span>. During the course of the series a few striking and maybe unexpected parallels between the natural world and the business world have, well, <span style="font-style: italic;">evolved.</span> They may be direct parallels, they may be metaphors, they may only be coincidental, but at worst they offer a new way of looking at things, which is usually a good thing in itself</p>
<p class="MsoNormal">Let’s start by taking a look at evolution (assuming you believe in it, if you seriously think the world is only a few thousand years old, this article is definitely not for you). There are a few general truths about evolution that you need to understand before you can get your head around the way it works</p>
<p class="MsoListParagraphCxSpFirst" style="text-indent: -18pt; margin-left: 40px;"><span><span>1. </span></span>Evolution has no goals. It just happens. Some species survive, others die out, but there is no end-game as such</p>
<p class="MsoListParagraphCxSpMiddle" style="text-indent: -18pt; margin-left: 40px;"><!--[if !supportLists]--><span><span>2. </span></span>The more successful species in the short term are those that can successfully exploit the status quo</p>
<p class="MsoListParagraphCxSpMiddle" style="text-indent: -18pt; margin-left: 40px;"><!--[if !supportLists]--><span><span>3. </span></span>The more specialised and “niche” a species is, the more vulnerable it is to environmental change</p>
<p class="MsoListParagraphCxSpLast" style="text-indent: -18pt; margin-left: 40px;"><!--[if !supportLists]--><span><span>4. </span></span>The more successful species in the longer term (especially in times of change) are those that can exploit a changing set of circumstances (i.e. they can learn and/or adapt)</p>
<p class="MsoListParagraphCxSpLast" style="text-indent: -18pt; margin-left: 40px;">
<p class="MsoNormal">
<p><span id="more-123"></span></p>
<p class="MsoNormal">Right, what does that have to do with goal-driven long-term business planning and how does that even suggest it may be a waste of time?</p>
<p class="MsoNormal">Well, first we must make a distinction between making provision for the future (which is eminently sensible) and trying to predict what the future may look like and then identify what will be our specific niche in that unknown<br />
future-world. It is the latter that we propose may largely be a waste of time – simply because there are far too many unknowable variables to make any sort of rational specific predictions worthwhile. We can aim to make the most of today, certainly, as there are fewer unknowns. We can make reasonably specific short-term plans as the volume of variables in the short-term will be lower. However the longer our time horizon, the less likely it is that we will be able to plan accurately, because we are likely to get more than a few things wrong</p>
<p class="MsoNormal">So why do people bother with long-term, goal driven planning (because they do)? Well, maybe because it is a comfort. Like the idea of an after-life, it’s nice to think that we can develop and execute long-term plans, because the alternative may be an uncomfortable thought. Maybe</p>
<p class="MsoNormal">Returning to the evolutionary metaphor, if we really want to survive (and even thrive) in the longer term, and we would prefer to have some influence over our chances, it may be more practical to concentrate on developing our inherent capabilities, rather than goal or outcome driven strategies. In planning terms we may find it difficult to identify what volume of widgets we will be selling in what market and at what margin in 5 years time &#8211; although we can easily <span style="font-weight: bold; font-style: italic;">wish </span>for it. What we can do more easily, however, is to adopt a policy of re-investment with <span style="font-weight: bold; font-style: italic;">capability </span>driven outcomes, and to place our faith in the general statistical rule that it is the more <span style="font-weight: bold; font-style: italic;">capable </span>that survive, grow stronger etc.</p>
<p class="MsoNormal">Now, some people may counter this view with an argument along the lines of <span style="font-style: italic;"><br />
</span></p>
<p class="MsoNormal"><span style="font-style: italic;">“Well I bought this book in an airport last week written by this millionaire tycoon chappy, and he quite graphically describes how he built his empire up based on a long-term strategic vision. He may not have predicted the future, but he certainly anticipated the future AND he was right – you can get his book yourself if you don’t believe me”</span></p>
<p class="MsoNormal">OK yes, we do have our tycoons and, yes, many of them do claim to have some sort of gift of foresight. Some may even claim you can learn it (usually after reading their $19.99 book). However for every startling success there are numerous abject failures about whom no books are written. It’s like if we put 100 would-be tycoons in a room and asked them to flip a coin over and over. If we wait long enough someone will flip 20 consecutive heads. We may actually find that when we speak to our expert coin-tosser that he attributes his success to technique rather than pure chance. Maybe he too would put all that it in a book. You see statistically there <span style="font-weight: bold; font-style: italic;">has </span>to be some successes, but some factors will be completely incidental to that success, even though in hind-sight we may be able to weave an alternative and plausible yarn. Be entertained by it by all means, but don&#8217;t be fooled</p>
<p class="MsoNormal">Anyway, the gist of this article is to suggest that far too much time and effort is wasted on planning for a future that never arrives, at the expense of continual and relentless investment in <span style="font-weight: bold; font-style: italic;">capability</span>. The future contains too many unknowns</p>
<p class="MsoNormal">
<p>Carpe Diem</p>
<p class="MsoNormal" style="text-align: center;"><a href="http://www.capablepeople.co.uk">www.capablepeople.co.uk</a></p>
<p>Post from: <a href="http://www.capablepeople.co.uk/blog">Capable People Blog</a><br/><br/><a href="http://blog.capablepeople.co.uk/2008/08/is-long-term-goal-driven-planning-a-waste-of-time/">Is long-term, goal driven planning a waste of time?</a></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.capablepeople.co.uk/2008/08/is-long-term-goal-driven-planning-a-waste-of-time/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>BS 31100 &#8211; a new code of practice for risk management</title>
		<link>http://blog.capablepeople.co.uk/2008/08/bs-31100-a-new-code-of-practice-for-risk-management/</link>
		<comments>http://blog.capablepeople.co.uk/2008/08/bs-31100-a-new-code-of-practice-for-risk-management/#comments</comments>
		<pubDate>Fri, 01 Aug 2008 20:58:03 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Risk & Assurance]]></category>

		<guid isPermaLink="false">http://www.thetyphon.com/capableblog/?p=120</guid>
		<description><![CDATA[Follow this link to Oliver Cann&#8217;s excellent summary on the emerging issues that BS 31100 aims to address &#8230; and then some light relief Post from: Capable People BlogBS 31100 &#8211; a new code of practice for risk management<p>Post from: <a href="http://www.capablepeople.co.uk/blog">Capable People Blog</a><br/><br/><a href="http://blog.capablepeople.co.uk/2008/08/bs-31100-a-new-code-of-practice-for-risk-management/">BS 31100 &#8211; a new code of practice for risk management</a></p>
]]></description>
			<content:encoded><![CDATA[<p>Follow <a href="http://www.businessstandards.com/Articles/080724_BS24_Risk">this link</a> to Oliver Cann&#8217;s excellent summary on the emerging issues that BS 31100 aims to address</p>
<p>&#8230; and then some light relief</p>
<p>Post from: <a href="http://www.capablepeople.co.uk/blog">Capable People Blog</a><br/><br/><a href="http://blog.capablepeople.co.uk/2008/08/bs-31100-a-new-code-of-practice-for-risk-management/">BS 31100 &#8211; a new code of practice for risk management</a></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.capablepeople.co.uk/2008/08/bs-31100-a-new-code-of-practice-for-risk-management/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
