Showing posts with label risk. Show all posts
Showing posts with label risk. Show all posts

Friday, November 13, 2009

Internal Audit - CCM and Risk Management

Internal auditors are familiar with walking those fine lines, but championing a "Continuous Controls Monitoring" (CCM) program requires an extra fine sense of balance.

Designing effective controls, especially those aimed at preventing incompetence and financial fraud, is typically defined as an activity performed by company management or business units and, under internal auditing standards, internal audit departments must be seen to be independent from management.

Clearly, that doesn't mean internal auditors don't have a role to play in Continuous Controls Monitoring (CCM). Auditors may not be able to help management design effective cost controls or tell them whether a particular control is the right one to have, but they can help in monitoring the situation.

Auditors are not 'troubleshooters' or management consultants, but they are very capable of testing your controls and processes and providing you with the results. In addition to these results, the auditor should provide some searching questions, which can be fed back into and addressed, in the next management meeting. This is an important feedback loop for management, which should not be under estimated.

The need for strong internal controls is heightened in public and financial companies, because of the Sarbanes-Oxley, Basel II requirements, etc . and external auditors have an equally heightened role to play in testing the soundness of these controls.

In these cases, the management are obliged to design controls to fulfill a regulatory obligation and win accreditation or regulatory approval, verifying the effectiveness of these controls. This verifying audit is required to be carried out by its external auditors, but this will only happen after due diligence and much work has been carried out internally, by the organisation's own audit team.

In reality, internal audit departments, conduct their audits to prevent or to root out fraud and error in high-risk transactional areas. Technology is a powerful double-edged tool, that can be used both for and against an organisation. So, it is vital that internal audit teams maintain tight control of that the tool so that the parameters of the tests don't get changed without their knowledge.

Monday, October 5, 2009

Is SOX Gonna Hang You out to Dry?

The US Securities and Exchange Commission announced Friday that starting in nine months, it will require the smallest public companies to provide the auditor assessments of internal controls over financial reporting that are required by the Sarbanes-Oxley Act of 2002.

Under Section 404 of Sarbox, public companies and their independent auditors are each required to report to the public on the effectiveness of the companies' internal controls. Companies with a public float below $75 million have been given extra time to design, implement, and document their controls before their auditors must attest to the controls' effectiveness.

That extension will cease starting with the 10-K reports of companies with fiscal years ending on or after June 15, 2010. Formerly, that deadline was for fiscal years ending on or after December 15, 2009. The extension was granted so that the SEC's Office of Economic Analysis could complete a study of whether additional guidance provided to company managers and auditors in 2007 was effective in reducing the costs of compliance.

Because the study was published in September, less than three months before the December 15 deadline, the SEC decided that adding more time was "appropriate and reasonable so that small public companies and their auditors can better plan for the required auditor attestation," according to the SEC.

While the largest U.S. publicly traded companies are in their fifth year of complying with Section 404, smaller companies have yet to fully comply. It was only last year that nonaccelerated filers — defined by the SEC as those with a market capitalization of below $75 million — began filing management's assessments of internal controls with their 10-Ks. Now, such companies that have fiscal years ending June 15 of next year will have to get their auditors' signoff on their internal controls, also known as 404(b) reports, for the first time.

"Since there will be no further Commission extensions, it is important for all public companies and their auditors to act with deliberate speed to move toward full Section 404 compliance," SEC chairman Mary Schapiro said in a release.

The controversial Sarbox provision has long drawn the ire of companies — particularly small public issuers — because of its allegedly high cost of compliance. The act, passed following the wave of corporate accounting scandals that included Enron and WorldCom, requires the SEC to mandate that corporate internal-controls reports state management's responsibility for setting up and maintaining an adequate internal-controls structure and procedures for financial reporting. It also must contain an assessment of the effectiveness of the company's controls structure and procedures for financial reporting, as of the end of the company's most-recent fiscal year.

The part of Section 404 related to the SEC's current action requires a company's auditors to attest to and report on the internal-controls assessments made by the management of the companies the accountants audit.

While the reporting and auditor attestation grew out of the 2002 law passed by Congress, all U.S. public companies have been required to maintain internal-accounting controls since 1977.

Shared via AddThis

Wednesday, September 23, 2009

Parallel Strategic Risk Profile of omnipotent Bankers versus omnipresent Bacteria

WHETHER you call the current financial situation a setback, a crisis or a meltdown, it has had at least one positive effect: financiers are searching for new ways to deal with complex risk.
Let's examine a new suggestion for them. Look to again at nature, where analogous problems have already been solved by engineers and computer scientists.

Bacteria, for example, have a robust, adaptive regulatory system that optimises the growth of the colony under any set of conditions. They adapt to the composition of their growth medium, the acidity, temperature and salinity of their environment, attack by other organisms and many other threats.
Adaptation and survival, depends on regulatory systems built into the system itself, and yet this regulation does not constrain growth or innovation.

What does this have to do with finance?
Clearly, there are formal similarities and parallel comparisons can be made from the architectures of financial systems and biological systems. Financial systems are composed of institutions - banks, pension funds, finance houses, insurance companies and the like.
These create credible packaged products; mortgages, mutual funds, insurance policies and credit default swaps. Consumers, by their nature, have confidence in these institutions and buy and sell these 'products', funds flow throughout the system and, in normal circumstances, growth follows.
In a bacterial colony, the equivalent of institutions are interactive chemical pathways - families of enzymes and metabolic reactions that are linked together to perform necessary functions. These create products in the form of molecules such as DNA, ATP, proteins and lipids.
These products are then used or consumed, by the bacteria and normally growth occurs. The most succesful of these reactions have risen to the top through an evolutionary process that rewards success.

In both financial and bacterial systems, commitment to growth does not come without risks. In financial systems, a party to a contract may not be able to meet its' obligations. In bacterial systems, molecules and organic elements that are necessary for growth may be missing or depleted.
Financial instruments may lose value because of price fluctuations and diverse market trends. A bacterial colony's external media may literally dry up or be excessively consumed. Financial markets may lack liquidity. Micro-organisms may lose their ability to generate their central energy molecule, ATP.

Bacteria have remarkable arrays of response mechanisms that protect them against these and other threats. While some regulatory mechanisms are engaged to counter specific threats, others operate in a more general way to protect against threats that the organism has not yet encountered. Bacteria also optimise growth for any external and internal conditions. That is why they represent an excellent system on which to base a model financial system.

Finance and biology are distant fields, of course, but there is a way to bridge them: engineering. Recently, my research group and others have found that biological systems such as bacterial colonies can be analysed and modelled using tools developed to study "hybrid systems", which are characterised by a combination of both continuous and discrete dynamic behaviour.
The classic example is a bouncing ball; other examples are air traffic control, production plants and wireless networks. This leads me to believe that we can use those same tools to analyse financial systems and make them more resilient.

As another example, consider two cars approaching an intersection. This is a hybrid system because the cars move smoothly forward but also stop, start and change direction. How do you ensure that the cars pass without crashing? How do you get them through in the fastest time possible? Can a system of regulators be designed to optimise both safety and speed? Where will the cars be at some specified time after they pass?

Now multiply the number of cars by 1000 and add many more intersections. The problems become very difficult to solve, but not impossible. I suggest that the corresponding problems in the financial world - to avoid crashes, maximise productivity, design a regulatory system and predict the future - are equally accessible to our analytical tools.

First, though, we need to analyse finance as a hybrid system. I'm confident we can do that because of recent work showing that the tools we use to analyse such systems are applicable to biology.

Two results in particular will resonate with the financial sector. One predicts which bacterial genes are essential and which can be knocked out without killing the organism. This is the bacterial version of asking "is this bank too big to fail; if I get rid of it, will the whole system crash?"
The second models how flocks of birds or schools of fish perform collective tasks without centralised coordination. It is not a big stretch to propose that financial group behaviour, like panic selling, may be analysed using these tools.

More complex questions about the growth of bacterial colonies can be answered if more complete information is known, such as the individual biological properties of each cell. Similarly, more complete information about financial institutions will allow more complex questions about financial systems to be answered.

This proposal raises several practical questions. Will the relevant parties make the information available? Where should the information reside, who will have access to it and how will confidentiality be guaranteed?

In conversations with financiers, there is an appetite for making the information available if confidentiality and anonymity are guaranteed. There is also acceptance that a government agency should be the repository of the information.
All we need now is the political and corporate will to gather the information, engage the right team and apply these tools to help solve a really important problem.

Wednesday, July 1, 2009

Still Waiting on the Express Train to Financial Recovery? - Jose Manuel Gonzalez-Paramo

Trust me, you will have plenty of time to check out the RISK in Europe 2009 - Frankfurt Conference

If you missed the Risk Europe 2009 conference in Frankfurt in June, catch up with our exclusive video footage, including the keynote address by European Central Bank board member Jose Manuel Gonzalez-Paramo.

Thursday, June 18, 2009

Credit Crunch Drives Short term strategies

One of the most powerful and persistent arguments against spending money on risk management is the 'hope for the best' school of management that hide behind the casual observation that most companies survive from year to year even if they don’t do any formal business risk management.

Consider this against the current downturn caused by the banks taking enormous risks for a considerable period of time and fortunately getting away with it, until now. Indeed, both staff and shareholders of banks benefitted enormously from the increased short-term profits that were generated; but this was never a sensible or sustainable way to do business.

Given the catastrophic consequences of this criminal disregard for risk there is now much debate on how banks, and individual bankers, can be encouraged to take a longer-term view including:

  • Changes to remuneration packages, especially cash bonuses;
  • Ensuring that directors having a better understanding of the risks to which the bank is exposed; and
  • Institutional shareholders becoming more active.

Many of these debates will need to include and address the promotion of more effective risk management in all industry sectors.

Obviously incentivising employees appropriately and educating directors about business continuity management, resilience and risk, are important. Ultimately, most employees and directors will still have relatively short term or near horizon views (of the order of 3 – 5 years) compared to the longer time-frame of catastrophic events.

As has been graphically illustrated by the current crisis, it is the long-suffering investors and shareholders who sustain the big losses when risks are not managed effectively. So, improving the understanding of operational risk amongst institutional investors is paramount to the future success and stability of organisations.


Tuesday, May 12, 2009

Gauge your future prospects by the singing in the lifeboats

"Experience is what you get when you don't get what you want."

Whether you are a believer in inspirational quotes or not, you have to admit that they do have their moments. So, from the one provided we can gather that 'Experience' is a bit of a consolation prize.

If you have reached a cynical stage in your career then you should visit Despair.com and view the Demotivator's Calendar. A refreshingly silly five-minutes of your life you won't get back.

For the more serious minded classical students amongst you, here is a quote from the 18th-century French philosopher, wit and raconteur, Voltaire; "Life may be a shipwreck, but we must not forget to sing heartily in the lifeboats." Now does that not crystallise what life is like in this current recession, with just a hint of optimism and stoicism. Very French!

From previous blogs, you will know that I am in favour of establishing strong leadership skills in these troubled times by developing the potential and talent already visible in the new executives. Perhaps a hint of that same lifeboat spirit would help strengthen the resolve of our future leaders and younger executives.

There are difficult questions to be asked. Are you using your current business challenges as a learning experience? Are you addressing the difficult decisions leaders must make to adjust to this dynamic ever-changing environment?

It is so easy to let the development and management of talented performers sink to the bottom of the priority list, especially for many companies today. Remember, the next generation of leaders is developing around you, whether you want them to or not and whether your helping them or not. The risk is that those who "self-select" into leadership roles aren't necessarily qualified enough to succeed in their aims, certainly not without strong guidance and/or appropriate mentoring.

This crippled economy, wrecked on the reef of bad management and greed, is giving the emerging IT leaders of tomorrow some unprecedented opportunities to stand out and step forward. In turn, we must remember it is our role to keep the chorus going in the lifeboats, loud and strong.

The leadersof tomorrow should be true captains of industry, able to plot a safe course for tomorrow's adventure and navigate the dangerous shallows of short term gains and diminishing returns.

Thursday, April 30, 2009

Death comes to Queen's day: Serious security breaches


5 die and 13 are injured by a lone 'maniac' during Queen's Day

I have just witnessed the most apalling scenes at the Netherland's Queen's day celebration. It was disrupted and brought to a sudden and tragic end with the breakdown of weak security measures, quickly followed by poor crisis and incidence response measures. A complete abomination from a security risk and threat analysis, and from a public safety viewpoint. The time taken to respond and control the situation was woefully inadequate. If this had been a real incident, 'carnage' would have resulted. Whoever was responsible for the risk and threat assessment on this, is in the wrong business.

The incident today showed a complete lack of awareness for current threat reduction, vulnerability mitigation and crisis response management, prevalent in the rest of the world today. The arrogance and naivity inherent in providing this level of security to the NL Royal Family and the surrounding crowds, is both negligent and incompetent.

The ease by which a lone driver was able to breach the weak security measures was shocking but the response provided, during and following the incident was severely incompetent. If this had proved to be a real attempt to assasinate the Dutch Royal family by a cynical and trained group, then it would have been highly successful to a frightening degree and would have faced no serious resistance from the surrounding security forces.

Even following the incident there were no guns drawn; the car was not isolated to protect the Royal family and the surging crowd; there were no signs of protecting or rapid removal of the 'targets'; any anti-explosion measures were ignored; the 'containment' measures were non-existant, it was a dangerously embarassing and highly volatile situation that could have been easily exploited to a devastating effect.

I have studied the counter-terrorist measures of the Israelis, the South Afrikaans and the UK. I was online to the authortities in NY, both during the aftermath and the months following 9/11, offering support and advice.

The UK's own Royal Family has been at the centre of a number of attacks going back over several decades and have been a target of many such maniacs.

In 1974 a gunman tried to abduct Princess Anne as she and her first husband, Captain Mark Phillips, were being driven along the Mall in London after a charity film show. Would-be kidnapper Ian Ball forced the car to a halt and brandished a pistol. I had the pleasure of meeting the police detective that took 2 bullets for Princess Anne on this occasion and I have to say that he was a most modest and self-effacing man. The stuff that 'heroes' are made of.

Having spent the last 30 years of my life studying such incidents, with specific concern for the impact and consequences inflicted on civilian and security agencies. The effect of trauma on the victims, witnesses and spectators alike. It is with this close scrutiny of rare but extreme events and incidents perpetrated on the UK mainland by the IRA and others, that I am appalled at how easily the security today was compromised and how easily the Dutch Royal family could have been assailed and possibly assasinated. The transfer of trauma will be on an enormous scale.

When are the Netherland authorities going to realise that they have become a target for terrorism. Partly because they have proclaimed to the world that they are setting themselves up as the centre of justice for the war against international terrorists, organised criminals, sadistic dictators and mass murderers of all kinds.

Do not be mistaken, I applaude the Dutch in their stance against the evil that is so freely conducted. The establishment of the International Criminal Court against mass murderers wherever and however they manifest themselves, is a good and honourable achievement, even if it is somewhat tainted by the smell of the additional revenues that this will bring to local law firms and the other spin-off benefits that the NL authorities encourage. Unfortunately, in the eyes of the bad guys this also makes the NL a 'legitimate' target and by association the Duth people via the Dutch Royal family and other symbols of the 'establishment'.

The incident today was shocking and unbelieveable for a country that believes this sort of behaviour can only be perpetrated on them by others. I thought the world had already learned this harsh lesson. The US and the UK have certainly learned that the biggest threat comes from 'home grown' terrorist groups. Who else knows your weaknesses better than your close family and who else can get close to you to do you damage?

Let's not forget the victims in all this, and I offer them heart-felt condolenses to the victims of this incident and their families, they did not deserve this, no-one does. It will take them many years to rationalise this but clearly, they expected more protection from their guardians than was on offer today and they should demand better protection for the future. Substantial measures that go beyond the hype and rhetoric of politicians.

I also hope and pray that the NL authorites can contain the wave of xenophobia and the right-wing, anti-foreigner lobby that will spring up in the wake of this incident. Queen's day is already a symbol of white, Christian, conservative NL. There were few oriental or coloured faces on show in Apeldoorn. Marginalised and excluded from these occasions, it is easy for extremists to build on this 'pro-white' image and to corrupt the minds of the young people in NL. We must prevent this kind of backlash and counter-strike mentality that drives sectarianism and terrorism alike.

There are many serious questions here, and hard lessons to be learned. I hope everyone is open to them. The future is full of uncertainty and we need to be strong and determined to prevent terrorism and anti-social behaviour gaining ground. We have to be proactive and smart about it, not reactive and emotional. We need to address the cause of exclusion and dysfunction in this society and give the victims of this a voice to express themselves in a reasonable and rational manner. Otherwise they will find other ways to crash the party and express themselves in a dysfuntional way.

What is certain about the future, is that the 2010 Queen's day will be very different, perhaps more secure and less relaxed than previous years. The end of a dream, a childlike naivity and an optimistic but distorted perception of liberal NL. This may be a sad thing to propose but it is a more realistic approach, a practical sign of our times and the price we pay for the defense of civilisation, eternal vigilance.

Sunday, April 12, 2009

Where can I find a profit

'When you eliminate the obvious, then what remains, albeit improbable, must be the truth.

The times are tough, the going rough, the customers are in defensive mode and profits are a difficult thing to find. So, where do we look for profits? Consider there habits. Where have they been found in the past and where will they be found now?

The answers may differ from business model to business model but profits have always come from exploitation and RISK. You must exploit opportunities and take risks if you want to really be in business i.e. developing and profiting, no matter what the economic environment.

It is now, more than any other time in your lifetime, that those who have the courage will be able to take advantage of and exploit some of the greatest investment opportunities in this century. It is a buyers' market, whether you are in retail, stocks, real estate or a venture capitalist taking the biggest risk of all, looking to invest in a new business.

"I never guess. It is a shocking habit and destructive to the logical faculty."

There is an old adage in the business world that says “Be thoughtful and hesitant when others are greedy and be quick to exploit when others hesitate.”

Most business markets are based on a pack mentality. They cling together for protection and this 'pack' is currently hesitant and fearful in its approach. Not daring to be the first to break ranks, in case they are followed, found to be wrong and are pillaried and expelled by their peers. They have much fear and much to fear. Consequently, they are acting with a fearful mob mentality, hesitant, irrational and unpredictable in most cases.

If you have the courage and expertise to take some well measured and calculated risks at this time, you could become the new pack leader. The trend setter that sniffs out the route to safe and steady profit. Resulting in some, much or great profit in the months and years to come.

Your issue is what Risks do I need to take to make this vision come true and how best should I measure these risks?

"London, that great cesspool into which all the loungers and idlers of the Empire are irresistibly drained." Sir Arthur Conan Doyle

Risk Management; A mind set

To those who have not yet discovered it, security and risk management is a mind-set. When you go into a shop or restaurant, you may automatically check out the security and note where the exits are. If so, you will also check as to how secure the financial transactions are. How does the waitress handle the credit cards? How far the credit card machine is to staff and other customers. You will have noted the location of the security cameras, the lack of a security station or the location and the number of bouncers.

As a security and risk specialist, you will always be thinking about and assessing the security scenarios but not to exploit or take advantage of it but to be aware. You cannot switch it off, its the way you are. It is the same for members of the emergency services, never really off duty.

Security Compliance

If you have to consider a risk management approach to security compliance, as part of your many regulatory obligations, the best way to approach compliance is through risk. It is ineffective to focus on the bare minimum, just ensuring you are simply compliant. Threats and vulnerabilities are forever mutating, growing and changing. The bare minimum is not enough. This is the first principle of IT security and of risk-based IT management.

When looking at new applications, components, systems or architectures, check out the risks to your business and the risk to your core information. Those are the important things to note. You are concerned if it meets a line item associated with HIPAA and SOX.

Pattern recognition

The 'always on' risk management mind-set is always looking for patterns, checking out ways of doing rather than items on a regulatory checklist. You will look closely for items that pose a threat to your core assets, those that you are responsible for and have dedicated your reputation to protecting.

When somebody comes to you with a potential security problem, even if you know nothing about the particular system or application, you can assess it by the application of the risk framework and therefore formulate a validate set of pertinent and probing questions.

Secure games

Most security and risk managers live and breathe in a security mind-set, whether they are hardcore techies or recruits from the business side. The methodology they follow day by day at work is the methodology they live by, outside of work. Even at conferences, when they unwind afterwards with a soft drink, they invariably play a Where’s Waldo? version of security gaffes, competing to see who can spot the most security lapses. It can appear very weird and a little black, if you are outside the circle.

Nailed by the business

The mind-set can have its limitations and can be self-perpetuating. There is an old adage that says 'If you are a hammer, the whole world looks like a nail.' Indeed, when taken by surprise, the average security and risk manager is typically out manouvered by something that happens on the business side.

Good grief! Have they learned nothing? You can’t believe that the business would make such a decision. Just because you have a structured, risk averse and secure mind-set, you forget that 'normal' people don’t always think that way.

Damage control

What happens next is up to you. If the security has been jeopordised or the risks are too high then it is your task to get it back into line and put the geni back in the bottle. The fact is clear, you are dealing with consequences. The business has taken a chosen path and you have to control the damage, mitigate against it or make it right. After all, isn't that your job as security and risk 'support' person? In reality, you are seen by the business (suits) as being in the same category as the IT help desk and that is all you are.

Although it is accepted that the security and risk manager serves and protects the
organisation and its profits, until it can be unequivacally determined how you can directly make money and grow the profits for the organisation, you will always be considered as merely a supporting act. So, let's make up and get on with it! The show must go on!

Monday, March 9, 2009

Probability - Birthday pairs

With my love of subjects around Probability and Risk, I find myself reading Simon Singh's book; Fermat's Last Theorem. I am a big fan of Simon and would certainly recommend his Book of Code to any intellectual IT persona. Coincidentally, I also bought the Book of Cod and the Book of God, both by completely different authors. Although both of these were entirely 'off subject', they threw an interesting light on the fishermen's pursuit of the Cod and mankind's pursuit of spiritual belief.

Let me provide you with an interesting story about counterintuitive Probability that I was reminded of, after reading Simon Singh's book. What is the probability of 2 people, at a party or sports gathering, sharing the same birthday. With 23 people on a football pitch or 23 people at a party you would imagine that the probability of 2 people in that group sharing the same birthday would be unlikely, given that there are 365 days to choose from. Most people would guess that there is less than 10% probability.

I will not keep you in suspense unnecessarily. The answer is just over 50%. Surprised? Well it is true. The likelihood of 2 people in a group of 23 sharing the same birthday is more than 50%. It is a counterintuitive dilemma with a counterintuitive answer.

The issue we have as humans, is that we tend to consider the problem as more complex than it is. We think that there are 23 people and 365 days in the year, so the answer must be some multiplicity of that but it is not.

The better approach is to consider the issue from a different angle entirley. The question is about pairs. How many pairs are there in such a group? To save you counting let me tell you, there are 253. The first person can be paired with 22 others, the second person can only be paired with 21 others because we have already paired up the first person. Thus, reducing the pool by 1. The third person can then be paired with 20 others and so on until we reach 253.

The odds of pairing increases dramatically when the number of people at the party increase. You will by now realise that the number of pairings with increase accordingly. The knowledge of these counterintutive issues is well known to mathematicians and your local bookmakers (bookies), one from a problematic view and the other from the view of economic gain.

So, the next time you are at a slow party, you may take the opportunity to gain kudos with the other partygoers or perhaps make some chump change. Good luck!

Monday, March 2, 2009

Outsourcing Risks - 25 Most Dangerous cities

After an eventful year that saw terrorist attacks in Mumbai, kidnapping for profit in Mexico, and the unexpected meltdown of Satyam, one of India's biggest IT services firms, the corporate cries to get things done "better, faster, cheaper" and offshore, may begin to be drowned out by the more moderate mantra of today's outsourcing customer: "safer, more stable and definitely more secure."

Interruptions to business customers have upset the sense of security that made Indian offshore outsourcing an uncomplicated buying decision. Companies are putting on hold the offshore projects that were routine just a year ago, puting more effort into investigating and analysing alternatives that help mitigate unresolved risks.

Promising locations like South Africa, Columbia, Malaysia, Thailand and Mexico have done little in terms of government initiatives or social change to allay client fears about their safety, as an outsourcing destination. Some countries with more established IT export businesses e.g. the Philippines and Brazil, have progressed slower than expected.

India's "tier II" cities, once poised to take business away from the cities like Bangalore, do not have the infrastructure and social improvements necessary to compete. India's track record does not bode well for fast development. This making other locations such as Latin America and central and eastern Europe more appealing to corporate organisations.

A number of emerging offshore locations have made great strides in mitigating risks inherent to their countries, while still keeping their costs and overheads low, e.g. Poland, the Czech Republic, Chile, Egypt, etc.

The risk factors involved in offshore outsourcing e.g. terrorism, potential war, disaster, network breaks, environmental disregards, crime and epidemic disease, make contingency plans a greater necessity. The emerging trend currently, is for IT outsourcing customers to seek out solutions closer to home, nearer their own shores or in the same country, where potential problems can be more readily understood, predicted and better managed.

The 25 Riskiest Outsourcing Cities in the World

Rankings based on mean scores in ten areas of risk as reported by The Brown-Wilson Group's "2009: The Year of Outsourcing Dangerously"

  1. Bogota, Columbia
  2. Bangkok, Thailand
  3. Johannesburg, South Africa
  4. Kuala Lumpur, Malaysia
  5. Kingston, Jamaica
  6. Delhi/Noida/Gurgaon, India
  7. Manila/Cebu/Makita, Philippines
  8. Rio de Janeiro, Brazil
  9. Mumbai, India
  10. Jerusalem, Israel
  11. Curitiba, Brazil
  12. Dalian, China
  13. Juarez, Mexico
  14. Brasilia, Brazil
  15. Chandigarh, India
  16. Colombo, Sri Lanka
  17. Ho Chi Minh City, Vietnam
  18. Quezon City, Philippines
  19. Accra, Ghana
  20. Pune, India
  21. Chennai, India
  22. Hanoi, Vietnam
  23. Bangalore, India
  24. Hyderabad, India
  25. Kolkata, India

The Worst Three Cities for;

Corruption & Organized Crime

  1. Bogota, Colombia
  2. Juarez, Mexico
  3. Johannesburg, South Africa

Heightening Trans-national & Geopolitical Issues

  1. Delhi/Noida/Gurgaon, India
  2. Jerusalem, Israel
  3. Colombo, Sri Lanka

Unsecured or Unprotected Networks and Infrastructure

  1. Bogota, Colombia
  2. Bangkok, Thailand
  3. Kingston, Jamaica

Unstable Currency

  1. Bangkok, Thailand
  2. Bogota, Colombia
  3. Johannesburg, South Africa

Personal Crime Rate/Police-to-Citizen Ratio

  1. Bangkok, Thailand
  2. Johannesburg, South Africa
  3. Rio de Janeiro, Brazil

Environmental Waste & Pollution

  1. Bangalore, India
  2. Chandigarh, India
  3. Kuala Lumpur, Malaysia

High Terrorism/Insurrection Threat

  1. Mumbai, India
  2. Delhi/Noida/Gurgaon, India
  3. Jerusalem, Israel

Legal System Immaturity

  1. Bangkok, Thailand
  2. Bogota, Colombia
  3. Kingston, Jamaica

Weather/Climate Threats

  1. Kingston, Jamaica
  2. Manila/Cebu/ Makati, Philippines
  3. Bangkok, Thailand

Wednesday, February 25, 2009

H5N1 Pandemic Flu - breakthrough research

From my previous article on the H5N1 Pandemic flu virus, you will know that the flu virus constantly alters its surface proteins and constantly mutates into variant forms. This means that we can be infected many times over a lifetime and a flu vaccine made last year has but a short period of effectiveness.

Now studies show that this behaviour is just a decoy to guard the virus's more vulnerable parts; a fact that might enable us to make drugs, or a vaccine, that will work on all kinds of flu, year after year.

Flu's main surface protein, haemagglutinin, looks like a lollipop. Our immune systems mostly produce antibodies to its rounded head, and it is this part that changes every year, making immunity short-lived. But in a large library of human antibodies, Wayne Marasco at Harvard University and colleagues found very few that bind its "stalk", which barely changes at all, either through time or between different flu viruses.

To see if this might provide a way to attack the virus, they produced large amounts of the antibodies that home in on the stalk and found that they cured and protected mice from two kinds of H5N1 bird flu, as well as many other flu families including H1N1 pandemic and ordinary flu. The researchers now want to develop the antibodies as a flu drug, possibly to stockpile for pandemics.

The team also plans to test the stalk antibody as a vaccine, so that people produce more of these antibodies themselves. They suspect haemagglutinin's big head is a decoy aimed to attract the immune system's attention and to stop us making many antibodies to the stalk – a delicate bit of molecular machinery that not be so easy to change to evade our immune attacks. In tests on mice, they found that the flu viruses did not evolve to escape the treatment.

Another benefit is that such antibodies stay effective for more than three weeks when injected into people, and in a pandemic could keep people alive long enough to produce their own antibodies to the virus.

Tuesday, February 10, 2009

Use the Power of persuasion

Are you hunting for a new job or the next step up the ladder? Well, it may come as a small surprise to you to hear that one of your main objective is simply to be persuasive.

What are the most effective approaches?
  • These days networking is sited as the most effective way of finding a new job. So firstly, you need to build your personal network and then persuade the loyal members of your network to introduce you to people who might connect you with someone who knows someone ..........who has a suitable opening for you to fill.
  • Secondly, you need to get your CV read and acknowledged. So you need to persuade HR professionals and recruiters to not just read and discard résumé but to consume, digest and ruminate over it.
  • Having got as far as the HR dept, you need to persuade the hiring managers that you're the perfect candidate for their organisations. The missing link they have been seeking, even if they didn't realise it themselves

Be convincing - Some people are easier to convince in your job search than others. Getting friends and colleagues to arrange introductions for you doesn't require much persuasive effort because they know you and some may even like you or owe you money. Therefore, they're willing to play their part on your behalf. After all if the circumstances were reversed, you would do the same for them. Your powers of persuasion over your friends should stem from your mutual friendship, natural charm, credibility and likeability, not from your rhetorical prowess or physical strength.

The Gatekeeper - The hiring manager, knows nothing about you, apart from the fact that he has seen your name in a pile of CVs that need to be filtered. He has to create a short list of candidates fit for interviewing and you must be on it. How are you going to stand out from the crowd and rise loftily above the other candidates. You have to think better and work harder to convince them that you're worthy of their time. In such situations, job seekers need the advantages gained from fully understanding the fundamentals of persuasion.

Easy as ABC
Effective persuasion combines equal parts communication and observation. It hinges on having good people skills;
  1. being able to read people,
  2. being a good listener and
  3. being empathetic.

You need to be a keen observer of the person you're trying to persuade. Otherwise how can you match the tone and language you use in conversation to the other person's tone and language. Watch how the other person reacts to what you are proposing, either physically, through their facial expressions and body language, or in their tone of voice. If you notice a negative reaction, or discomfort, you should be alerted and quickly change or slightly adjust your approach.

Under your Influence - To be an effective influencer, you also need to be likeable, outwardly open and trustworthy. It doesn't matter whether you're selling an idea, a service or a product, people tend to buy from people. If I like you, I will listen to you. If I don't like you or your message, I won't listen to you. Getting someone to listen to you is the first stage of persuasion.

Persuasion isn't inherently difficult. To do it right, people just need to focus on listening to the person they're trying to persuade and adjusting their communication accordingly.

Whether you're seeking a new job, clinging to an existing one or out to climb higher, persuading people of your value is going to be your key to success, especially during times of low market confidence and recession.

How do you persuade others without appearing pushy and what about the dangers of steamrolling people into submission. The Hard Sell!

What is one of the biggest mistakes you can make when trying to influence or persuade others?

One of the worst crimes you can commit is the lack of true or active listening. Far too many people only half-listen to other people who are speaking and the same people are equally unlikely to closely observe people either. We sentient humans have the capacity to think at four or five times the rate of someone who's speaking. Consequently, we can often listen badly because we're too busy looking ahead and formulating our responses while the other person is still speaking, or we're thinking about something else entirely, like shopping or the size of the other person's nose. We fail to pick up clues that indicate what the other person is really saying or thinking because we are not even listening.

Body Language

Observing body language is the closest we can come to mind-reading. If you make a statement, and that statement produces a grimace or a shift in posture of the other person, their body is telling you that something you said doesn't gel with them. It's a clue for you to change your tact or to inquire what it is that's bothering that person.

Negative pressure

Some individuals lack the level of people skills that are needed to persuade others. However, they can and are able to sway and influence their co-workers by taking a dominant posture. This is observeable, because they always have a response to a point or counterpoint. Their constant pressure exhaust others' patience and endurance, leading to submission. It is more like verbal tennis or squash than persuasion.

Is there anything wrong with this sporty method of persuasion if it accomplishes the persuader's goals?

Clealry. beating someone into submission is not good practice. It is not what we understand to be true persuasion. A truly persuasive person will not leave you in an exhausted state. The ultimate goal of effective persuasion, is that the relationship between the two people hasn't suffered, even after one has changed the other person's belief or behavior. There should be no 'losers' as there are in competitive sports.

Certain personality types are better at persuasion than others?

Extroverted people tend to be more persuasive than people who are prone to introversion. Extroverts are often in people facing jobs, such as sales or advertising, where they have to influence or persuade people to buy a product, take some kind of action or adopt a different lifestyle goal.

Introverted People will take jobs that are less people-focused and more facts and figures focused. They are the back-room people, often evry talented but lacking the self confidence that their knowledge should bring. Therefore, they have less experience of dealing with people than extroverts. Consequently, they don't develop the people skills that extroverts develop. It is a vicious circle that is not so easily broken.

Introverts can be good persuaders, when dealing with other introverts; people of their own type. Introverts have more difficulty in persuading extroverts because extroverts tend to speak louder and faster than introverts. Whereas, the introverts tend to conduct their interactions in a much slower manner.

Extroverts have similar difficulty in trying to persuade introverts. When you look at workplace disputes, some can be attributed to personality clashes between introverts and extroverts.

Logical arguments besides, just do it!

May I also postulate a theory that the extoverts are more emotionally open and accepting of emotive reasons for doing something. Whereas, extroverts may be less willing to expose their feelings to scrutiny and therefore take the safer option of discussions based on known facts. It is easier to dis-arm an introvert using facts and logic than it is an extravert. Discuss!

Is there a difference between persuasion and manipulation? Some people don't like the idea of having to persuade or influence others. It strikes them as unseemly, pushy or manipulative.

Persuasion is essentially about changing someone's perception, questioning their assumptions. You are trying to alter their beliefs and behaviour. Persuasion is really about moving someone from point A to point B.

Manipulation implies coercion. When we're talking about persuasion, you are seeking a win-win scenario, where both parties are happy. Manipulation implies that only one party is satisfied and the other is out-manouvred.

It's all about the approach

Manipulation is often synonymous with some kind of threat: If you don't do this, this will happen. Persuasion is a meeting of minds: You are persuading another to come around to your point of view. Ideally, no one gets hurt. You have simply changed a person's perception, not by coercion or threat.

It is better to have cross-pollination than a cross Polynesian

(old Hawaii proverb, alledgely)

Tuesday, February 3, 2009

PM for Network Professional

Good Timing is the key to Good Project success!
Professionals know what they know and network professionals are typically well-versed in the technical aspects of networking: protocols, router and switch configuration, server deployment and management, and so on.

Conversely, we don't always know what we don't know and our colleagues, the network pros, are rarely trained on how to manage projects. Fortunately, most of the problems that networkers face in projects can be addressed and mitigated against using standard project management methodologies and techniques.

Consider the effect of some Probability and a little influence from Evolutionary learning can have on your projects. If you are not proficient in something but do it often and long enough and are determined enough, sooner or later you will start to have a greater degree of success or a lesser degree of failure. Design and install networks long enough, and you'll be sure to have some of those projects go awry due to predictable, 'unforeseen' 'surprises'. Two words that you do not want to use in your monthly Project Progress Report. Two words that clearly depict the reasons why you should be applying Project and Risk management methodologies.

....and then they put the phone lines in!

Sometimes the infrastructure you need, such as power in a communications room, is not ready when you need to install an Ethernet switch. Other times, your network equipment vendor may seem to be perpetually on "back order" with the one module you need. Or perhaps it's the all-too-familiar "scope creep" when users decide they need greater wireless coverage than they asked for at the beginning of the project, without increasing costs of course.

Managing network projects is not an exercise in fortune telling, far from it. When analysed the core components for network projects are just like any other project, IT or otherwise: There is an objective, a time line, a budget and expectations of those who will benefit from the network once it is completed.

Professional project managers command good salaries because they understand these processes. Executives know that certified project managers are less apt to have projects run away from them. Attaining project management certifications such as the Project Management Institute's Project Management Professional (PMP) could be just as valuable to you as a network professional as a Cisco Certified Internetwork Expert or a Microsoft Certified Systems Engineer but you don't have to earn the full PMP certification to reap some benefits.

Applying a few simple project management tips will quickly earn you a reputation for delivering network projects on time and within budget and this is the sort of reputation that opens doors.

Quick Fix is leading but .............!


Triple constraints; I once saw the following on the wall of a drive-in oil-change service: "You can have it done cheap, fast or right; pick two." This is true of all projects, and it illustrates the so-called "triple constraints" rule: projects are subject to cost, schedule and performance parameters. Changing one will affect at least one of the remaining two. e.g. when installing a network for a local bank branch office to allow for Internet access and e-mail. The project includes configuring a Microsoft Exchange server and installing a virtual private network firewall for security. You included labor in your project schedule and quote to ensure that the project is done in two months, as requested.

One week into the project, the bank announces acceleration in plans, the office network needs to be done in three weeks instead of two months.Your staff is already fully devoted to this and other projects. You can't cut out functionality because the office still requires all of the network connectivity and e-mail functionality. What can you do?

The only way to accommodate is to add more staff, either by paying overtime to your employees or subcontracting another IT firm. Either way, the cost will go up, yet the bank will likely baulk at the new cost. At that point, armed with the understanding of the "triple constraints" principle, you as a network pro knowledgeable in project management concepts can calmly explain why the request to change time will increase the overall network project cost.

......there be monsters here!
Project charter and scope; To reduce the likelihood of the network project growing uncontrollably, make sure that everyone understands the project deliverables, what the network will provide, how long it will take and at what cost. Your key constituencies here are the project sponsor and the network administrator.

By following project management methodologies, this can be accomplished by starting from the general (project charter) and migrating to specifics (project scope).

For network projects, the project charter could be simply "provide network connections for the new Shelbyville Bank and Trust building at 3 Main Street." Details including the number of connections, security protections needed and services desired are best left to the project scope. The scope simply supports the goals defined in the charter while providing more details; it is not a complete network engineering plan in itself.

You can create an initial cost estimate for the project from the scope. When the scope is broad or when there is only a charter, precise estimates are not possible.

A good option, is to take a network project of comparable scope that you worked on previously and use that as a basis for the estimate. It's also wise to not give a single figure estimate but rather a range, say maybe 50 percent on either side of the estimate derived from historical knowledge. As the scope is more clearly defined, refine the cost estimate by changing the midpoint as appropriate and reducing the range size.

Project schedule; Once scope is known, a project schedule should be determined. You'll already know the two most important project points: the beginning,following soon after the project scope is approved and the end, when the network is in place as requested by the sponsor. It's up to you to fill in the blanks.

Here's where a project management software package such as Microsoft Project really comes in handy. It can tie all aspects of the project together by providing a relatively easy way to create the plan for the network installation. Setting up the project plan can take some time at the beginning, but it will pay dividends many times over the course of the network project.

When planning network projects, break the project into the following six phases:

  • Information gathering—scope, existing infrastructure
  • Purchasing decisions—which switches, routers, firewalls, servers and so on are needed
  • Ordering equipment
  • Configuring and installing the servers and network equipment, and testing connectivity and functionality
  • Customer acceptance
  • Documentation

However, you decide to manage your network project, breaking it into smaller miniprojects makes the overall project more manageable. Suppose you know from experience that you generally receive network equipment from your supplier four weeks from order. Furthermore, you know that it typically takes two weeks to configure and burn in the equipment and another two weeks to install and test. So, start from the end of project date and count backward eight weeks; that then becomes your milestone date for ordering the equipment.

Scope creep. Performance constraints can also change, and in networking, they are usually on the side of more functionality, not less. Scope creep is a change in project requirements after the project has been planned and is under way.

A common example of scope creep that every network professional I know has experienced, is when the customer decides he needs more network capacity (number of jacks) than what you planned for at the beginning of the project. I like to inform customers upfront about the magic number: 24. Many vendor enterprise workgroup switches have a minimum of 24 Ethernet ports (some allow 48). Pass the magic number, or a multiple thereof, and expect the project's cost to increase (refer back to the "triple constraints" rule).

Of course, changing the number of connections does not just affect network electronics costs. Additional cable drops and possibly patch panels for terminations may be needed. An increase in electronics (switches or servers) may require heftier uninterruptible power supplies and may increase heat generation, forcing an upgrade of the HVAC design of the communications room or data center. It's clear to see that expanding the project requirements increases its cost, which is a problem when budgets are limited and fixed.

These problems exist because all involved with the project; the sponsor, network administrators and the other stakeholders (end users, equipment vendors, cabling contractors, customers), assumed that everyone was in agreement at the beginning of the project. But this was not the case. When all parties agree on and understand the scope at the beginning of the project, it is less likely that scope creep will occur.

Finally, should the scope still need to change, simply create a new cost estimate and timeline to accommodate the scope modification. Changes are not necessarily all bad, as long as all involved understand the effects that any changes may have.

Closing out a project. Once the network infrastructure is completed, there are still three major tasks to accomplish before the project can be closed. The first is rather obvious, ensuring the network functions as the customer intended. The customer should perform as many business-related tasks as possible to test the infrastructure and formally sign off accepting the project when complete. The latter will prevent end-of-project scope creep as well as provide a milestone for you to close the chapter on this project.

The second job, too often neglected, is to fully document the network. Remember, one of the goals when the project scope was created was to ensure the manageability and supportability of the network. Network drawings, router configurations, circuit numbers, server disk partition information, IP address assignment—anything and everything that was pertinent to the successful completion of this project should be documented and stored where it can be easily retrieved.

Finally, network projects rarely go exactly to plan, and sometimes surprises occur that could really not have been foretold. A postproject review, particularly of what went wrong, will help prevent the same mistakes from happening on a future project. I recall one network installation in which a concrete slab was poured before conduits were installed, necessitating cutting the slab to install the conduits. The lesson learned was to include regular on-site network infrastructure inspection dates as tasks in the network project plan.

For more information; You don't have to be a certified project management professional to take advantage of project management techniques to aid in your network projects - but it helps!

There are numerous Internet resources related to project management, including the following:
The Project Management Institute is the source of the Project Management Professional as well as other certifications. In addition, Prince2 is the preferred project management methodology and certifications in Europe, particularly in the U.K.

Stop your IT Projects getting canned

To weather the current economic maelstrom, enterprises are not only reducing head count but also are cutting back on ambitious or long-term projects in IT. Knowing how best to keep your IT project in the pipeline could mean taking a cue from those best versed in achieving project approval: Project and risk management business consultants.

Companies are cutting back significantly this year. They're under more than usual pressure to optimize every dollar, to either stop the bleeding or start the recovery. The key to retaining business is to build /re-enforce customer loyalty. This is demonstrating that continuing with your current initiatives should not only cut their costs but also help generate additional revenue.

What's true for consultants is equally true for IT managers looking to kick-start an internal project or to keep their project funding flowing. Those who are best at proving the value of their projects will win. And when it comes to uncertain times, keeping your project off the chopping block can end up saving your future and enhancing your career. There are many ways to do this and I would like to suggest a few.

Benjamin Disraeli
Benjamin Disraeli, is reputed to have said that there are three kinds of lies: lies, damn lies, and TCO/ROI calculations for IT projects.

Clearly, no professional right-minded company will pour money into IT without a strong business case. There has to be a payback and that final payback is that the business will get something beneficial in return. Before you can be a part of this, you will have to address the issue of choosing the right metrics and presenting them well.

Calculating the true return on investment goes beyond demonstrating cost reduction or bottom-line enhancement. Those days are gone. Today's executives are no longer likely to let simplistic metrics pull the wool over their eyes, after all, presenting statistics and compiling business cases is part of their job too. You have to provide something they can sell on to their people.

ROI dismissals
As we move deeper into belt-tightening, we are seeing more and more ROI calculations being dismissed. Most ROI calculations from vendors are flawed toward magical and large returns, and most calculations from users are too simplistic and unreliable. Bottom line: accountants don't believe them and cannot use them anymore.

Though numbers can't be rejected entirely, the kind of numbers you use should vary depending on the ultimate goals of the project. Despite being a great decision-making tool, ROI is often a misleading indicator for deciding whether a project should be pursued or not.

Case Studies Testimonials
Reliable case studies showing how other organisations implemented similar projects successfully and achieved positive results, may have more credibility with cynical management teams rather than simple ROI projections. All you have to do is find the appropriate cases.

Hard or Soft?
If the project aims to reduce head count, inventory, or transaction costs, so-called hard ROI numbers may be sufficient but for projects with less measurable aims, e.g. improving the business environment or coping with service provision changes in the competitive landscape, soft ROI, e.g. the increase in growth potential or business value as a result of improved relationships, comes into play.

Thus, positively demonstrating the beneficial value of your project can prove tricky, but if you focus on added and hidden value in these areas and make a strong case, you will significantly improve the likelihood that your IT project doesn't get canned.

Helicopter views
But don't focus too narrowly on your project's niche lest you lose sight of the big picture.
IT managers always need to step back and look at the impact their project could have on the entire organisation. You need to look at the cost of lost opportunities. What are we not going to be able to do, in terms of people, hardware, software, training and other monetary issues, all because we took on this project?

Will we be able to do more of what we do well or do what we do more effectively? Will this give the company, service or product a competitive edge in the marketplace? It can't just be a cool thing to do anymore.

Business needs direct IT
The true business need meets the true ROI. If the business has asked IT for a helping hand in a project, that should be enough. If you're doing an IT project that is either not driven by the business or does not have direct bottom-line financial impact to the company, you should not be doing the project in the first place. Would you have the business or IT shop do an ROI on something as basic as an e-mail server? No one would tell you that because there is no ROI, therefore we don't need it. The business need bypasses the requirement for IT to sell an ROI back to those who requested it in the first place.

Customer loyalty
Building and re-enforcing customer satisfaction and loyalty is paramount in troubled times. Despite the cost, executives will approve high risk investments because the cost of not doing the project in terms of dissatisfied and lost customers, can be far greater than the addition of new IT capabilities. Projects that reduce customer retention costs or increase the efficiency of marketing campaigns are more likely to get a green light.

Making it real
Even the most ruthless, cost-slashing IT project can die a swift death if it's pitched in language your accountant can't understand. Be aware that everybody talks and thinks about TCO and ROI just a little differently, depending on their view. It may help to manage the differences in understanding by the creation of a glossary or terms definition, distributed to the key executives.

Language
As the PM, you are the communicator and you need to have a sound understanding of whatever language your company works in. Do they use internal rate of return, payback period, time to value? Sometimes business leaders don't always sync up to the value language of the company. If capital is involved, you need to understand the process your finance department uses to approve the budget and get it into the language they speak.

Keeping it real
Business case assumptions must be thoughtful and clearly supported in terms an accountant will understand. Include metrics on power usage, maintenance contracts, and head-count savings. These often can't clearly be seen until the next fiscal year. Accountants crave short term gains and cost-control drivers that help manage long-term planning.

If you can show payback for an IT investment over 18 months or less, even better. Accountants love to recover the cost of expensive volatile technical assets before they're fully depreciated. They know the rapid rate of obsolescence in high tech toys, the lock-in tactics and the long licensing traps.

Don't stick your neck out
Embrace Optimism when you can. All projects rely on assumptions and the associated risks. The bigger the project, the bigger the risks. The key to getting your project approved is simply to do your homework. Study, analyse and assess the risks rather than assuming the best and being surprised by the worst.

Positive risk management
Planning for a positive outcome needs implementing better risk management, plus the provision of accurate financials, supported by proven program management methodologies and earned value. Also, you will gain more oversight and control with smaller and more frequent milestones.

It's better to be transparent and realistic about everything but base your budget contingencies on sound risk management analysis and assessment. You should never presume to receive 100 percent of a project's costs initially when you don't know 100 percent of the project requirements. Manage the risks and issues as you go and adjust your expenditure according to your project plan, risk management actions and develop a positive outlook in the team. Look for positive risks; opportunities and assess them as you would a negative risk, fully.

Building a project
PMs and IT managers will find it more palatable to take a staged or phased approach when pushing ambitious projects, one that relies on shorter, clearer milestones with conditional metrics tied to future funding. If you cannot get funding for the whole project because of skepticism of deliverability or payback, ask for phased funding. Each phase can have a checkpoint where progress is measured and funding for the next phase is approved or denied. If the business isn't happy with progress or results, there is much less risk.

Messy eaters
Try scaling back and down to move forward. Keeping your project off the pig swill scrap heap may mean settling for a digestible piece of the pie instead of the whole thing. That way you don't kill the chef and you can always go back for more later.

Even a broken clock is correct twice a day!

Wednesday, January 28, 2009

Why Projects are Failing

Warning!
Projects can go up as well as done, especially in the current economic storm.

Project management has been a big part of my business management career for the last 35 years. I attended my first course in project management in the early ‘70s. Since then I have accrued a large collection of practical theories that I would like to share, starting here with the bogey man of project management, Project Failure, how to avoid it.

GOAL!
Like all good team managers or players; Start by considering the goals!
Projects have 3 basic criteria by which they are measured. They are deemed to have failed if they do not meet the following simple success criteria:
• Deliver project within planned timelines – TIME
• Deliver project as per forecast budget – MONEY
• Delivering planned results – BUSINESS BENEFITS

Only around 30% of projects achieve all three facets of the Golden Triangle, especially the last one; Business Benefits, the project ROI, the business case justification, call it what you will.

Projects Delivered or abandoned?
Partly successful projects are deemed to be ‘delivered’, even if they fail on one or more of these criteria. According to Gartner this can account for 30% of projects. They also believe that 15% are wisely cancelled before the end, having failed outright to meet their original criteria. I can only surmise that this last group did not seek expert PM rescue advice to determine if they could pull it back from the brink or limit the damage. Instead, we will assume that these projects had a high certainty or potential for failure.

Thus, it raises the questions;
  • Were they doomed from the start
  • Did they lose direction or support on the way
  • Were they really viable and therefore saveable
  • Others. Discuss!
Very few projects that are struggling have the reporting visibility that allows executive management the knowledge and insight to determine their real status. There is a conspiracy of silence and misinformation that prevails, along with the belief that all is well, right up until they crash into the buffers. So, for the 15% of projects that fail, let us speculate that it should have been clear for some time that they were struggling and needed to be euthanised, if only we had known earlier. Discuss!

Mid Zone muddle
With around 30% of projects succeeding and 15% failing, we need to consider the 55% remaining projects in the mid zone, struggling for a foothold in the ‘shallows’ and ‘shifting sands’ between success and failure. Do these projects ‘partly succeed’ or ‘partly fail’? Are they caught up in some ‘timeless whirlpool’ that cycles them, infinitely? Clearly, not. They would run out of money, time or support for never to be achieved benefits. If we want to draw sensible conclusions from statistics, we need more accurate reporting methods, with more precise detail and granularity. Build in tighter controls. Build a better dashboard. Lead this ship of lost souls out of the doldrums.

Choose Success or Failure?
Moving on, let’s get back to the big fight; Success v Failure. The first question to be considered is; Should we be,
  1. Considering the key factors leading to success or the risk of success or;
  2. Examining the sources of and risk of failure?
They are linked, of course but one is intrinsically passive and reactive, whereas the other is more proactive. In Project Management and in business today, we need strong proactive project management resources that encourage, understand and support, the risk of success and can quickly recognise the need to mitigate away from failure.

In the latter stages of a project, this turnaround from imminent failure to possible success, can be achieved by bringing in an experienced rescue PM. They will quickly assess the damage, examine the mitigation potential and plot a course out of the swamp.

How? Simply through the disciplined use of proactive PM methodology and tools, plus the implementation and positive use of strong Risk management approaches. Oh Yes! and the benefit of decades of PM experience. Call me sooner than later.

Remember: Charismatic figureheads need to be ahead of the crowd! AND the crowd need to be behind them, all the way! (not as easy as it sounds)

Friday, January 23, 2009

Getting on top - Dominate your Credit Risk

Until recently, when debt became more expensive and harder to come by, companies generally had a blasé attitude toward managing their trade-credit risk. Most corporations, big and small, don't have credit risk procedures any more sophisticated than the sub prime lenders did. In which case you are flying in dangerous territory with your defenses down.

A simple tip but one that's been largely ignored until recently: Be more wary before extending credit to new customers. Make them prove their creditworthiness. Currently, companies take more a of shy unassuming approach to trade credit by quickly granting it to every new client that comes across their threshold. Once aboard they hope for the best and follow the client's payment performance over time.

Companies too often get into the habit of not asking for any financial information from their customers in favor of speeding up a much coveted deal. Suppliers have been doling out credit based on what little information may be available on their privately held clients, despite the fact that private firms have a higher rate of bad debt. Even after a credit account has been granted, the supplying company may shy away from asking for financial data because they don't want to offend a brand-new client. Clearly the banks have a part to play in all this because they too have been willing to extend credit lines far beyond reasonable doubt.

Companies should ask for customer and bank references up front. Although, that information may be biased and unreliable because of the struggling financial institutions. Will the bank and lenders be there in the long term for their customer? Are they going to provide financing or will they make a quick exit and leave the company with a liquidity shortfall, which may or may not cause the demise of the company? Are the financial institutes responsible for the ongoing viability of their clients, i.e. the corporate companies. What support and backup can they provide a struggling company when they themselves are in difficulty. These and many more, are all questions vendors need to ask themselves when looking over a customer's bank information.

Companies should request that all customers, new and old to fill out a one-page credit profile every year. The sheet should include the company's cash position and the most up-to-date contact information. A type of credit probe which may or may not provide the correct level of information in the right format, in a timely manner. This will lead to more overhead in the accountancy dept or with the business analysts, but if addressed properly, it may provide early warning of difficulties.

If there is any good news to be had during this economic downturn, it's that everyone is in the same boat. Your customers are asking their customers for more financial information. It's now become perfectly acceptable to ask about a client's financial status because everyone is being scrutinized by every supplier. Its a big global circle of accountants, checking each others assets.

If it's impractical to demand financial information up-front, then come up with a triggering number for when your company will demand it. A simple threshold or framework will suffice. If clients cross the established and agreed amount, then they must provide their trade creditors with financial statements to validate their credit. The type and level of the threshold can vary depending on client, industry, item value, uniqueness, development costs, credit exposure, etc. Its not a numerical value, its a way of thinking about and controlling your risk exposure.

Another way to improve your credit /risk management is to conduct a detailed assessment and calculate each customer's probability of default. With such precise knowledge you can price your services accordingly, and by showing your client the calculations, you can easily justify a premium rate. Cash has always been king and currently it is even more critical to companies health and financial welfare, but many companies have no idea who they're selling to, never mind who owns the company or their cash position. Its never been more critical to know your customer.

Moreover, suppliers can no longer rely on traditionally held views that big-name companies are safe from sudden and dire financial problems even if they don't have strong cash flow. Many of these companies have lived on extended credit lines for years and are not asset rich. Other companies can have negative cash flow and positive net worth. They're sitting on land or occupy buildings that no one's willing to buy. If their credit is pulled and they end up going bankrupt, the asset value won't cover the debts.

Experts also suggest sales and credit departments improve their communications between salespeople and the collections side. Your salespeople are trying to maintain the vendor /customer relationship at the same time as maximising their commission payments. This is a tightrope, and is a very dangerous situation for the company to ignore. It must be very, very tightly controlled. Don't allow salespeople to grant extended payment terms, without justification and authorisation, before checking in with their credit counterparts. Companies should use these negotiations to get more financial information out of their privately held clients and reprice future services if possible.

Moreover, salespeople may be able to offer the credit department more insight into a customer's financial situation. Therefore it is imperative that they have the influence, motivation and the time to actually get involved in credit and collections questions. Its a team effort and everyone better be on the team or the game is over.