Sunday, October 21, 2012

Three years to change perception of risk?

As individuals, we are prone to making poor risk decisions, yet it is potentially within our power to predict and calculate any number of risks, including murder, earthquakes, market crashes, or identity theft. Nevertheless, it is important to keep in mind, as Bruce Schneier points out, “risk management is also a feeling, based not on probabilities and mathematical calculations, but on your psychological reactions to both risks and countermeasures. You might feel terribly afraid of terrorism, or you might feel like it’s not something worth worrying about.” [1]

Let's say that we wanted to change peoples minds about something. Say for example, you wanted to convince the travelling public that it's safe to fly again, after a major terrorist attack involving aircraft hijacking. How long would it take? A long time. The evidence seems clear. Even with trillions of dollars in resources, it apparently takes three years or perhaps even five years to change peoples perception of the risk.  At least, that is what US road fatalities data suggests.


In the September 11 terrorist attacks, 2,974 people tragically lost their lives. The public was justifiably horrified, and several trillion dollars was allocated to counter-terrorism measures. In the same year, however, a staggering 42,196 people lost their lives in motor-vehicle fatalities with scarcely a comment in the media. Fear of hijacking, understandable though it may be, contributed to a drop of more than 30 percent in US domestic air travel in 2002; people chose to drive rather than fly. Meanwhile, US motor-vehicle fatalities (a number that was previously steady or falling) increased by 809 people that same year; from 42,196 fatalities in 2001 to 43,005 in 2002.  [3]



It can often be difficult to demonstrate a clear cause and effect between risks and outcomes, and this situation is no different. The above statistics however were not entirely unexpected. In December 2001, David Myers, professor of psychology at Hope College, postulated a further eight hundred road deaths due to people driving rather than flying in 2002, adding that “in just one year the terrorists may indirectly kill three times more people on our highways than died on those four fated planes.” [2]   Further indication of the lasting effect of this risk perception is that the average annual road fatalities in the five years after 2001 was 1,140 higher than the average five years before 2001 (41,848 versus 42,989). Yes, that's a total of 5,702 additional people were killed on the road in the five years following the September 11 attacks. In fact, it wasn’t until 2007, that road fatalities dropped below their 2001 levels.

It is of course, much more than the scope of this article to confirm that the drop in road fatalities was linked to rebuilding confidence in aviation. Change in perceptions about seatbelts and drink driving as well as improvements in motor vehicles have all played their part. It's striking however to look at the data graphically and it's clear that something changed significantly around 2008. Perhaps it was just the effect of the global financial crisis (GFC) - and that did cross my mind. So I had a look at the statistics regarding how many passengers actually flew each year in the United States. It turns out that the GFC did have an impact, but not enough to completely explain the road fatalities. From a low in 2002 of 670,604,493, passengers increased by roughly 5 percent per annum until 2007 but it took three years to return to the pre-2001 levels.  [4]  From 2007 onwards, it does seem likely that the GFC had some impact on both road fatalities and aviation passenger levels, but even so, it seems likely that it took most Americans up to five years to believe that flying was safer than driving - or at least, safe enough to take it up en masse.



Is this really a surprise? Anybody who has tried to convince someone that a belief held doesn’t match the facts, knows perception doesn't always align with facts. On the contrary, as John Kenneth Galbraith put it so eloquently, "Faced with the choice between changing one's mind and proving that there is no need to do so, almost everyone gets busy on the proof."

It's not only difficult for us to change other peoples minds but it's hard for them to change their own mind. Equally significantly, it's very difficult for us as risk managers to truly absorb new information in a way that changes our behaviours. In his latest book Changing Minds: The Art And Science of Changing Our Own And Other People's Minds (Leadership for the Common Good), Howard Gardner, a cognitive scientist, describes this phenomenon succinctly:
"People underestimate how difficult it is to change minds. ... When you’re little, your mind changes pretty readily, even if nobody pushes it. We are natural mind-changing entities until we are 10 or so. But as we get older and have acquired more formal and informal knowledge, then it’s very, very hard to change our minds. ... I’m not stating that on small matters it’s difficult to change people’s minds. A coffee break at 3:00 rather than 1:00—that’s trivial. But on fundamental ideas on how the world works, about what your enterprise is about, about what your life goals are, about what it takes to survive—it’s on these topics that it’s very difficult to change people’s minds. Most people, by the time they’re adults, not only have become used to a certain way of thinking, but in a sense it’s work for them [to change] because their neural pathways become set."
So, is it official that it takes five years to change peoples perception of a risk? Not by a long shot. But it's an interesting question to ask.



==========================

[1] Schneier, B (2007), The Psychology of Risk management, 28 February 2007, available at http://www.schneier.com/essay-155.html, viewed 20 August, 2011

[2] Myers, David (2001), “Do We Fear the Right Things?”, Observer (Journal of the American Psychological Society), December, 2001

[3] Motor vehicle fatality statistics calculated by U.S. Department of Transportation, Research and Innovative Technology Administration (RITA), Bureau of Transportation Statistics (BTS), ‘Table 2-17: Motor Vehicle Safety Data’.Viewed 20 October 2012.

[4] Aviation statistics calculated by U.S. Department of Transportation, Research and Innovative Technology Administration (RITA), Bureau of Transportation Statistics (BTS), Passengers
All Carriers - All Airports. Viewed 21 October 2012.

Sunday, August 26, 2012

What is Risk Management?



I love the simplicity and inclusiveness of the ISO 31000 definition of risk ("the effect of uncertainty on objectives") and think it is probably the best of a large number of alternatives for a definition of risk.  On the other hand, the ISO 31000 definition of 'risk management' - "coordinated activities to direct and control an organization with regard to risk" leaves me more than a little underwhelmed. So, rather than just criticise it, I'd suggest the following thoughts in support of a 'better'(?) definition.

If we accept the ISO 31000 definition for risk then it follows that 'managing risk' = 'managing the effect of uncertainty on objectives"?

We could take this argument further by suggesting that if we have objectives, we would like to achieve them. If that is the case, then we could define 'risk management' as 'reducing the effect of uncertainty on objectives'.

A quantitative analyst (quant) might suggest that risk management is all about reducing volatility, but that definition is still rather vague. With their focus on volatility and pricing, quants are more focussed on reducing something abstract, than achieving objectives, so a better view of managing risk might be something like: risk management = 'increasing the certainty of achieving objectives'.

And that gets my vote for a better definition of risk management. What do you think?







Thursday, August 2, 2012

Risk Informed Decision Making


I recently spent 10 days holiday scuba diving and sailing around the Whitsunday islands with my partner and a couple of friends. Being the only one in the group with any sailing experience, I got the role of 'skipper'. It's probably not everyone's idea of a great holiday but personally I love the challenge of navigating and sailing a 40 foot catamaran that I'd never been on before, through a group of islands that I really didn't know very well.  That's partly because I enjoy learning new skills and honing old ones, but mostly because the mental challenge involved with (safely) sailing a $500,000 yacht is enormously satisfying and stimulating.

Along the way, there is plenty of time to ponder the vagaries of risk management. While sailing through Solway passage one beautiful sunny morning, I was reminded of a comment made on one of the discussion forums that I participate in.  It's popular in some circles to be something of a sceptic regarding risk management. The question raised in this forum was basically asking if risk management even works. The author in this instance was challenging the value of ISO31000 and risk management in particular. He was (rightly enough) pointing out that there is little if any, research done to show that resources applied to risk management actually return any value.  Now, I don’t believe that risk management is the panacea for all ills, and I’d definitely like to see more research done on the value of risk management. The lack of research however, doesn’t prove a case either way.

There are even a few people (a minority to be sure) who would go so far as to suggest that risk management generates little or no value, and is simply is a fad invented by management consultants.  It amused me to reflect on this view while passing through Solway Passage. Solway is a picturesque but narrow channel between Whitsunday and Hazelbrook Island. It looks benign enough, but if you try to pass through when tide and wind are opposed, the turbulence and eddies in the channel that can rotate your boat 90 degrees. Add in the shallow patches, rocks on both sides, the possibility of a whale or two transiting at the same time, and you have a situation that's far from benign.

If the risk management sceptics were correct, anyone could blithely hire a $500,000 yacht and sail it through Solway with beer in hand, and scant regard to wind or tide.  It's ludicrous however, to suggest that such an approach would be overly helpful.  It's more likely, that the passage would quickly become littered with broken boats and flotsam. 

On the other hand, a few basic risk management strategies, such as acquiring some navigational skills beforehand and planning the journey based on tides and weather, are likely to increase your chance of meeting objectives (eg: reaching a safe anchorage without damaging the boat or crew).  Certainly, I might have gotten through with just a beer in my hand, and a vague lookout for rocks. Indeed most boats would probably get through just fine, but we're talking here about the 'effect of uncertainty on objectives'. The more we reduce the uncertainty, the more likely we are to achieve objectives.

It’s useful to be sceptical and ask the hard questions regarding the value of risk management, but such those questions are best answered in academia.  Real world examples such as scuba diving or sailing through Solway Passage, demonstrate that risk management does indeed add value. Indeed, it was amusing to me during this holiday, to wonder why it is that some people still feel the need to ask if risk management adds value.  Perhaps they feel erudite or learned by asking such questions, but to me it seems about as useful as asking "why bother with management, leadership or safety?"

As for ISO31000.... Did I use ISO31000 to get through the Solway Passage? No, I didn't (I'm not THAT much of a risk nerd). I did however, follow an intuitive human process that aligns nicely with the ISO31000 risk management process. I looked at my objectives for the trip (getting safely and happily to Whitehaven Beach), took stock of the tide, charts and weather (context) to see what threats and opportunities I might face (identify risk), looked at the interaction of the various factors (risk analysis), considered the situation against my risk attitude (risk evaluation) and chose my time/place/rigging/etc. to sail (risk treatment). Along the way I communicated with the crew (at least the ones who weren’t too seasick to comment), consulted the charts and monitored the situation.  

Perhaps it doesn't matter so much which risk management process you use, so long as you use one. It just so happens however, that the ISO31000 process is consistent with the way that most of us process and manage risk. 



Sunday, June 10, 2012

Until you do it, it’s still an unknown...


No matter how well you prepare, and how much you might think you understand a risk, there is a special category of risks which are worthy of the title...

"Until you do it, it's still an unknown." 

One of my personal heroes made history with just this type of risk. Joe Kittinger rode a balloon to 102,800 feet (31,300 m) then stepped out into space.
He fell for four minutes and 36 seconds, reaching a maximum speed of 614 miles per hour (988 km/h) before opening his parachute at 18,000 feet (5,500 m). Pressurization in his right glove malfunctioned during the ascent, and his right hand swelled up to twice its normal size. He set records for highest balloon ascent, highest parachute jump, longest drogue-fall (four minutes), and fastest speed by a human being through the atmosphere.  To give you an idea, just how amazing this is, he set these records on August 16th, 1960 and they are yet to be beaten.

That could be about to change however, with a "giant leap for one man" later this year. Austrian skydiver Felix Baumgartner will jump from a pressurized capsule under a balloon at 120,000 feet wearing  only a spacesuit.
Felix Baumgartner and Joe Kittinger beside the capsule that will take Baumgartner into space

Jonathan Clark, the medical director for Red Bull Stratos, the team assembled to help Baumgartner reach his lofty goal, gets credit for coining a new category of risk management, describing this amazing feat "Until you do it, it's still an unknown." As he plummets 23 miles in the highest skydive ever, Baumgartner will possibly become the first person to break the sound barrier in free fall but the uncertainties are countless:

  • What happens when Baumgartner encounters the shockwaves that will occur when he breaks the speed of sound?
  • How many things have to go right for him to succeed?
  • What's the likelihood of everything going right?
  • What are the consequences of a failure in components x, y or z?
  • Instability in freefall is one of the biggest risks for normal skydiving. Only one person in history has jumped from this height and instability plagued much of his fall until he opened his drogue shute. 



The modern parachute was invented in the late 18th century by Louis-Sébastien Lenormand in France, who made the first recorded public jump in 1783. Since then parachuting has evolved in many ways but it’s still unclear what will happen when Baumgartner steps out of his capsule. Whatever happens, it's a groundbreaking feat - in more than 50 years no one has been able to (or been courageous enough) to free-fall from higher than 102,800 feet.

“Until you do it, it’s still an unknown,”


Tuesday, June 5, 2012

Blame it on the genes..

It looks like it's official! Risk preferences are central to any model of human decision making but researchers are increasingly able to identify a link between our genetic makeup and our risk taking behaviour.

We've recognised for a long time that there are substantial differences in peoples willingness to trade off risk versus reward. Some of the variation in preferences can be explained by gender, race, culture, age, education and socioeconomic status but none of these differentiators were sufficient of themselves to explain the variation.  Research by Camelia Kuhnen and Joan Chiao of Northwestern University in the journal PLoS ONE, was able to link financial investment risk-taking to variations in certain genes that regulate chemicals in the brain.

In particular, it appears that those of use who enjoy risk taking, whether day-trading or motorcycling are likely to have specific differentes in our Dopamine Receptor D4 (DRD4) gene.  Without getting overly technical, it appears likely that 25% of the individual variation in risk taking can be explained by heritable differences.

It's early days yet of course, and risky to confuse cause with correlation but it appears that there is a definite genetic trait at play. For those of you who are really curious, you'll find more technical details in 'The 7R polymorphism in the dopamine receptor D4 gene (DRD4) is associated with financial risk taking in men' at Evolution and Human Behavior 30 (2009) 85–92.

For an easier read, New Scientist speculates that DRD4 could be responsible for the human migrated out of Africa around 50,000 years ago. Even to the point where DRD4 has moved us across the planet, thanks to a propensity for risk-taking and adventurousness. DRD4 comes in may shapes and forms whereby the 4R allele, is associated with being even-tempered, reflective and prudent. Ie. People who like to manage risk to be ALARP (as low as reasonably practicable).

Those of us more inclined to manage risk to be AHARP (as high as reasonably practicable) probably have the less common 7R and 2R versions, which by contrast have been linked to impulsive and exploratory behaviour, risk-taking and the ability to shrug off new situations. In short, the migrants with these versions were better able to deal with dangerous, fluctuating situations and more likely to survive and reproduce under those conditions.

So, before you have that risk conversation with your spouse or colleague at work, think about just how deep seated their risk attitude may in fact be.  Culture, perception, gender, education, age and many other factors are important but, in part at least, we can be pretty confident that it's hardwired.


Tuesday, May 22, 2012

Another view of a risk management framework


The previous blog entry on risk management frameworks, presented a relatively simple risk management framework but there are many ways to view risk and the interactions of the various elements involved. It’s not the intention to provide a single ‘perfect’ risk management framework – you need to work that out for yourself – but we’ll provide a couple of ideas to get you started.  

Figure 1 below (adapted from SRMBOK) presents a more complex example of a risk management framework.  In this model we break up the elements of risk management into six main categories:
• Activity Areas
• Practice Areas
• Enablers
• Strategic Knowledge Areas
• Operational Competency Areas
• Risk Treatments



Risk Management Framework
Figure 1: Risk Management Framework example


Looking at the above example, we can see a rough outline of how different elements of risk management support each other. For example:

  • Practice Areas – the activity groups that embody distinct areas of expertise. These areas can also be the scope of the risks to be managed, or primary area in which a risk practitioner is focused (eg: Safety, Finance, Enterprise risk, etc) 
  • Strategic Knowledge Areas – the four concepts which all risk practitioners must understand in order to achieve an optimal trade-off in support of risk treatments (Ref: The Quadruple Constraints of Risk Management)
  • Operational Competency Areas – a group of closely-related skill sets in which a risk practitioner needs to be competent in at least one of (if not all) in order to support effective risk management. 
  • Risk Treatments – the strategies that we put in place to support objectives. In the graphic above, ‘assets’ are placed at the center of concentric circles. These circles represent the layered approach known as hierarchy of controls (Ref: Slides 10 and 11) whereby multiple mutually supportive treatments are more effective than a single treatment (Ref: Swiss Cheese).
  • Activity Areas – principle risk countermeasure areas through the lifecycle from pre-incident prevention (planning and preparation) to post-event response (emergency management and business continuity). As indicated in the diagram, there should be a primary focus on various elements at the appropriate phase of a risk event (pre or post) but all four elements need to be considered at all times – albeit with varying levels of focus or priority.
  • Enablers – the underpinning elements required to ensure the application of risk management processes and activities in a sustained fashion (eg: Policies, training, etc) 

Why Build Such a Complex Model?

It’s important to remember that the model illustrated in Figure 1 is just one possible way to view how risk management fits together. It's useful nonetheless, to stimulate your risk thinking in three main areas:

  • GAP ANALYSIS. What elements aren’t happening right now in our organization and what do we need to do to fill in the gaps?
  • BENCHMARKING. If we had to measure the effectiveness of our risk management, which metrics would we choose and how do they relate to each other?
  • INTEGRATION. How does this model help us integrate various functions such as treasury, IT, emergency response, design, governance, assurance, policies etc?


Tuesday, April 10, 2012

First International Conference on ISO 31000

If you're looking for a good excuse to visit Paris in the spring, I can think of few better excuses than the First International conference on the ISO 31000 Risk Management Standard.
The conference will take place there on the 21st and 22nd of May 2012.



"This international conference on ISO 31000 is addressed for the first time to the global risk management community active across all fields, sectors, industries and services related to risk management. We have gathered together an outstanding panel of international experts and practitioners from your sector to share their current perspectives on the ISO 31000 Risk Management standard”, said Alex Dali, President of G31000, the international non-for-profit NGO based in France dedicated to raise awareness on ISO 31000 standard.

With more than 30+ speakers, 4 plenary sessions and 10 parallel sessions and a focus purely on applying ISO31000, this conference is the risk management event of the year.

Plenary sessions:
  • Why ISO 31000 will become the global Risk Management standard
  • 20 years of Risk Management Standardisation - Past, Present and Future 
  • Why every RM programme should be based on ISO 31000
  • How to implement or adapt your RM programme using ISO 31000
  • G31000 – the new Platform for ISO 31000
Parallel sessions:
  • Regulatory Authorities 
  • Business Continuity
  • Software
  • Security
  • Internal Audit
  • Finance and Banking
  • Moving from COSO ERM
  • Raising awareness, worldwide 
  • Education
  • Human Factors
More information and registration details can be found at http://www.G31000conference2012.org and a 10% discount is available if you use booking code: G7ACCX.


I'll be presenting there and will look forward to catching up with colleagues, and hopefully meeting a few readers of this blog at the conference.

Sunday, January 15, 2012

How to build a risk management framework


Section 4 of ISO31000 opens with the simple statement that "The success of risk management will depend on the effectiveness of the management framework providing the foundations and arrangements that will embed it throughout the organization at all levels."  The standard devotes about 5 pages to talking about what a framework requires and sums it up in the Figure 1 below.
Figure 1: Relationship between the components of the framework for managing risk (ISO31000)

We'll go even further, and say that the risk management framework is the heart of organizational risk management. It might be tempting to overlook this portion of ISO31000 or to downplay its significance and jump straight to Section 5: Process but that would be a mistake.  No matter how much you and your organization know about risk, no matter how excellent your latest risk assessment is and despite an outstanding risk treatment plan, unless an organization has a well structured and appropriate risk management framework it will not have a sustainable risk management system.

Of all the elements of ISO31000, building the risk management framework deserves primacy for this is where policy, mandate, organizational commitment and structure set the scene for ongoing successful application of risk management.  And it isn't a one-time event. Like most of risk management, it is an iterative, adaptive process and as you can see from Figure 1, the authors of ISO31000 clearly intended it to be a cyclical process.

At the very least a framework should provide you with guidance regarding how your organization manages risk and in particular provides:
• A centralized and comprehensive source of risk policy, procedures and information.
• A consistent taxonomy for classification and prioritization of risk.
• Automated (or at least consistent) workflow for risk management.
• Auditable paper trail of records, decisions made and changes.

Putting this into action however isn't a simple task but if you consider what actually needs to go into it, the following graphic and our next blog entry will offer a couple of suggestions. 

The three most important elements in actually turning risk management theory into risk management practice will inevitably be training, training and more training.  How you put together the underlying framework for your organization however, will depend on your context and existing management systems. Whatever result you end up with, It’s likely to include three common elements: Direction, Systems and Execution.  I built this framework for a large Commonwealth government department a few years ago, and part of the brief was that it had to be easy to grasp the underlying principle.

DIRECTION is set by the Executive management team and in order of priority is based on:
  • Organizational objectives vision and mission (ie. The reason for existence of the organization). 
  • A risk assessment based on those objectives
  • A risk treatment plan to support achievement of the objectives (which might also be known as a Strategic Plan, Operational Plan, etc)
SYSTEMS are the management infrastructure that provides technical and policy guidance for implementation of the organizations plans and uses four core elements:
  • Policies and Management Standards - set the high level expectations and guide decision making
  • Procedures and Guidelines - provide the step by step process flows to implement the policies as well as some general guidance about how to interpret high level policy or standards.
  • Work Instructions – provide task specific detailed instructions for each step in the process flow.
  • Forms, Templates & Tools – are the specific tools and documentation that people will use to identify, assess and document risks.
EXECUTION is the phase where the plans, policies, objectives that have been so carefully developed, are finally implemented using three phases of this process:
  • Training Needs Analysis – involves identifying what people need to know in order to implement the ‘Systems’ previously developed. 
  • Training & Implementation – involves delivering the training that your people will need so that they can begin to correctly implement the various elements that support organizational objectives.
  • Reporting, Monitoring & Review – are the final elements to close the feedback look, assess how effective the framework is and provide appropriate feedback for continuous improvement. 
You’ll find this concept illustrated in Figure 2 below. It’s a relatively simple example of a framework but is easy enough to explain to people and equally importantly is highly scalable. 
Figure 2: Illustrative Example of a Risk Management Framework
Figure 2 is a relatively simple risk management framework. There are of course, many ways to view risk and the interactions of the various elements involved. It’s not the intention of this book to provide a single ‘perfect’ risk management framework – you need to work that out for yourself- but we’ll provide a couple of ideas to get you started.

In the next blog article, we'll look at a more complex version of a risk management framework which might suit larger organizations.


Friday, December 16, 2011

The role of the business case in risk management


Well-conceived and thoroughly researched business cases can play a pivotal role in improving the quality of organizational decision-making. The business case does not however, stand by itself as a risk management tool. It is simply part of a toolbox for analyzing and making decisions about proposed risk treatments.

Whatever risk treatment you’re considering, and whatever means you used to identify it, the business case is designed to determine and enunciate the value of that treatment. In Figure 1, we’ve used the ISO31000:2009 Risk Management Standard process to illustrate the role of the business case. Quite simply, it supports analysis, selection and implementation of risk treatments.
Figure 1: The Role of Business Cases in the context of ISO31000 Risk Management Process
At the risk of stating the obvious, lets go back to basics for a moment. Any proposed risk treatment should relate directly to a specific risk or risks. For example, if risk number one in your risk register is “Failure to deliver organizational outcomes within budget due to inadequate financial reporting” you might end up with a range of risk treatments, each of which will have different merits.  It’s worth pointing out at the moment that ‘risk’ includes both opportunities and threats (benefits and costs). Accordingly, you might also choose to rephrase the above risk in as an opportunity, such as “Increased profitability due to cost reductions resulting from improved financial reporting”.

Irrespective of how you phrase this risk, lets say that in our hypothetical example, you have identified two main treatments to address it. You’ll note from the examples in Table 1, that we’ve included a reference to which risk(s) each treatment addresses.

Table 1: Example of Risk Treatment Plan
In this hypothetical treatment plan (Table 1) each treatment has a reference to the risks it addresses. Risk Treatments number 1 and 2, primarily address risk number 1 but they also contribute to reducing the risks associated with risks 5 and 8. It’s not important what risks 5 and 8 actually are (it’s a hypothetical example remember). Risk number 8 may in fact be addressed primarily by Treatment number 4 and potentially also be improved by Treatments 1 and 11. It’s a complicated scenario but it’s worth remembering when you are defining the benefits of treatment number one, that you should consider it’s impact on risks number 5 and 8. You never know, it could be the indirect benefits of your proposed risk treatment that sways the decision makers in favor of supporting it. Add in ALL the intangible and indirect benefits. They all count.

Thursday, December 15, 2011

The Evolution of Risk Management...


It is sometimes tempting to respond to a risk or an incident, with a knee-jerk response by throwing time, money and effort at a quick fix.  That’s entirely understandable, given that our risk management decision-making evolved from a fight or flight response.  As Daniel Kahneman says in his latest book, "Thinking, Fast and Slow"we have two risk management decision making processes. Our ancient limbic brain is largely unconscious and it makes rapid decisions based on memory and emotions. Our more recently developed mammalian brain (neocortex) has the capacity for detailed analysis, abstract thought and logical inquiry. Unfortunately our logical brain is easily distracted, painfully slow and hard to engage, while our Limbic brain is (in todays modern world) wrong as often as it is right.

So, as it turns out, despite millions of years of evolution, we still make the majority of our risk management decisions in the emotional center of our brains.   This was fine when we lived in small Paleolithic communities, but the complexity of the modern world means we need better approaches to decision making.  Fortunately, we do have the capacity for analysis, and with hundreds of years of research in science, finance and engineering to name but a few, we have a pool of knowledge to draw on.

Until recently, when ISO31000 Risk Management Standard defined risk as “the effect of uncertainty on objectives”, risk management focused on negative risks. In this scenario, risk was bad, and had to be avoided, mitigated or to be transferred to another party through outsourcing or purchasing insurance. This led to risks being addressed as separate compliance issues and not integrated or managed broadly across the organization. Only comparatively recently has the role of Chief Risk Officer been created with the main focus (as it needs to be) on business integration, enterprise risk management and value creation.


Effective implementation of risk management into organizations and projects is not common.  Organizations that have tried to integrate risk management into their business processes have reported differing degrees of success and some have given up the attempt without achieving the potential benefits.  Aligning risk management with standard management systems including financial systems, workplace health and safety (WHS) and human resources is a key element of success in this area.  Existing platforms such as ISO9000 Quality Management and Balanced ScoreCards also help to demonstrate alignment with the business and are a key element of the process.

Linking business management to strategic risk management means setting up the corporate "infrastructure" for risk management. The evolving risk management function is designed to enhance understanding and communication of risk issues internally, to provide clear direction and demonstrate senior management support.  To be effective, this risk management framework needs to be aligned with the organization’s overall objectives, corporate focus, strategic direction, operating practices and internal culture.  Additionally, in order to ensure risk management is a consideration in priority setting and budget allocation, it needs to be integrated within existing governance and decision-making structures at the operational and strategic levels.



Tuesday, November 22, 2011

Emotions Drive Risk Decisions


“Once you know what it is you want to be true, instinct is a very useful device for enabling you to know that it is.” 
Douglas Adams, The Hitchikers Guide to the Galaxy

Despite our best intentions, education, intelligence and analytical ability, there is plenty of evidence to support the assertion that we make our risk management decisions base on emotions. Hard to believe - but true. We’re not the logical beings that we might like to think we are when it comes to risk management. Studies have shown in fact that stroke victims who have damaged the part of the brain that controls emotions are often incapable of making decisions. Even when provided with obvious rational data to make a decision, they often are unable to simply settle on one option.

And yes, we are perfectly capable of analysis and logic – we just don’t use it as often as we think we do. The neo-cortex in our mammalian brain can reason and make more nuanced trade-offs about long term risks but it's also much slower than our other systems. We actually have two systems for managing risk:

  • a primitive intuitive system in our Limbic brain (mostly centred in the amygdala) which deals with fight or flight type risks
  • a more advanced analytic system in the neocortex which is pretty good at abstract concepts 

Our limbic system in particular, is very fast, relatively autonomous and for very good survival reasons, able to hijack our thought processes for fight or flight responses. Unfortunately it doesn’t care in the slightest about abstract concepts like cancer or climate change and given it's primacy in our decision making, it's a real challenge for our neocortex to over-ride the amygdala.

Not yet convinced? Head around to the back door of a hospital one day and have a chat with the Doctors and Nurses standing outside smoking. Ask them if they understand the long term risks of smoking… Then ask them what they are doing about it. The immediate pleasurable sensation that smoking releases is appealing directly to the limbic system which is busy self-medicating for depression. Feeling bad is a very visceral and immediate risk. Lung cancer is a very real but entirely abstract risk and you can tell which system is in control - at least for the smokers among us.

Equally, the motorcycle racer has a fair idea of the risks associated with racing, but it's fun! The limbic brain is balancing up the risks and it feels good, so the potential risks of broken bones, paraplegia or death although real, are abstract concepts that our emotional brain struggles to fully evaluate.

Friday, November 18, 2011

So what what's so important that it's worth writing a whole book about?

If you have a specific issue or question that you’d like to address, please let me know but here's a short list of thoughts that are finding their way into the book.

Let's start with the three most common errors when doing a risk assessment:
  1. Inadequate risk identification.  Will the real risk please stand up! How to identify and document a risk in watertight fashion.
  2. Failure to show a link between proposed treatments, the risks and organizational objectives.  Watch out for an example of a risk register which links risks to both organizational objectives and to treatments.  If you can't show these linkages, then why should your treatments get funding?
  3. Failing to understand the context.  Don’t do it. If you don’t nail the context, you will never get agreement on the risks.  
Why failure to identify risks is the leading cause of inadequate risk assessments
Inevitably, we will fail to anticipate or identify many risks simply by the nature of uncertainty.  The main problem is typically a failure to explicitly state a risk in terms which allow stakeholders to accurately consider it and agree on effective treatments.  You can't just say 'Terrorism' is a risk or 'Climate Change' is a risk. Those aren't risks! They are words from a dictionary. Have a look at 'The CASE for risk identification' for a simple way to correctly describe a risk.

How to know whether or not you need a subject matter expert to help you and if so, how to select the right consultant for the job
This one is worth an entire book on it's own. The section on 'The Elusive Risk SME' will cover a ten step process that should help you find someone who has the skills you need when you need them.

How to build a watertight yet succinct risk management plan that will get funded
Ah, yes. One of the Holy Grails of risk management.  Designing a good risk management plan is one thing but as most people will agree getting it funded is a whole other step.   

How to spot the flaws or weaknesses in a risk report (yours or someone else's) in minutes
This is much easier than it looks.  Just ask these three questions:
  • Do all the risk statements satisfy the four requirements of the CASE Tool? (Condition, Asset, Source, Event)
  • Do all the treatment recommendations satisfy the requirements of the 4A’s? (Appropriate, Agreed, Actionable, Achievable)
  • Can you easily draw a causal link back from each risk treatment to the risk that it’s treating?
That’s all there is to it. Hit those buttons and you’ll pick up 90% of the strengths or weaknesses in a risk report – and look like a guru in the process. 


How to build an all-hazards risk management framework that deals with Black Swans
Plenty of research can help you out on this.  In particular the studies that have been done into a group of organizations which continue year after year with better than average safety records despite operating in some of the most dangerous and complex arenas the world has ever seen.   ‘High Reliability Organizations’ (HRO’s) is the common term for a category of organizations such as air traffic control systems, aircraft carriers and nuclear power stations that seem to continue on and on despite dicing with calamity on a daily basis. Karl Weick and Katherine Sutcliffe have a great book on how to incorporate the lessons from HROs into your organization called 'Managing the Unexpected'.


Enterprise risk management
Enterprise Risk Management (ERM) is more than just a question of scaling up. You can’t simply aggregate all the risks for an organization into a database and say that you have ERM sorted.  What the CEO and shareholders see and what they care about at the enterprise level are often much different to risk management issues at the operational or tactical level.  If on the other hand, you implement ISO31000's Risk Management Framework, you will be 90% of the way there. Let's not over-complicate things - Enterprise risk management is just risk management with a scope that includes the entire organization.

How to introduce a continuum of risk management tools so that everybody from the cleaner to the CEO can apply appropriate risk assessment tools
Often people complain that “risk management is too complex” and usually they are right. Not because risk management is too complex but because they are trying to use a chainsaw to prune a bonsai plant.  Get the right tool for the job and you’ll be fine.  

Adapting ISO31000 to meet the needs of everyone - whether in safety, procurement, finance, security, information technology, human resources of the Board of Directors – and do it in such a way that they will buy-in to it
Read the book! OK, just kidding (sort of).  ISO31000 has been designed to be generic. It works for everyone at all levels. In fact, that’s the real power of the standard. It’s not that it’s inherently the best of all possible risk management systems – nothing could promise to do that – but when you apply it across the board it allows you to aggregate and compare risks in a consistent fashion. I was asked after a presentation in the United States recently, what I thought of risk management in the US. I replied that I thought it was great but that  there were about 432 different flavors to choose from. At the same conference two presenters had given excellent presentations on terrorism risks to US ports. One system was done by the New York Port Authority and the other was done by the US Coast Guard using Los Angeles as the first test of the model.  They were both excellent. Sadly they were so different that it was impossible to tell which port was more at risk and hence which one needed the funding most of all. 
ISO31000 is my pick because it supports an apples for apples comparison.

Managing personal career risk – why do our leaders make such (seemingly) misguided decisions?
Why do our bosses and politicians allocate resources to some items and not others that seem to be blindingly obviously of more concern?  This question has intrigued me for years, and I think I’ve come to some sort of understanding on the contradictory nature of some of these complex questions.  The answer is – as you’d expect – not so simple.  But it’s not that complicated either - but it's the 'elephant in the room' when it comes to modern risk management.

Advanced Risk Modelling
How to crunch the numbers and come up with some reliable risk management using stats, Monte Carlo modeling and more - without having to do a PhD in statistics or spreadsheets. And yes, there are some relatively easy ways to get reliable data.  It all starts when you change the mindset from a statement of "we don't have enough data to model that" to "what data do we actually need, what do we already have and what can we inexpensively source?"

Friday, November 11, 2011

Risk Management Performance Benchmarking: Performance Benchmarking and Attribution Bias

Risk Management Performance Benchmarking: Performance Benchmarking and Attribution Bias 


One of the challenges for measuring the effectiveness of risk management (or any type of management system for that matter) is a little glitch in human perception known as attribution bias.   Attribution bias is simply our tendency to invent explanations and to attribute things to a particular cause (whether real or imagined).  These attributions serve to help us understand the world and give us reasons for a particular event.

For example, let’s say that Bill gets sacked from his job. He will attribute his sacking to... 

Wednesday, October 26, 2011

Likelihood versus consequence management...

It often seems that as a species (and indeed as a society) that we spend most of our efforts on managing risks after they occur, rather than preventing them from happening. .  The difference between the two approaches can be described as consequence management versus likelihood management, and is illustrated in the figure below.
Likelihood Management versus Hazard Management
This principle seems to apply whether we're talking positive or negative risk management.  For an example of consequence management of positive risks, we've probably all come across the salesperson or manager who likes to take credit when things are going well and will often put more effort into promoting this fact than they did into achieving that success. In theory, we'd all be much better off putting our efforts into increasing the likelihood of a positive business outcome, but there can be rewards for people who do little or nothing, at least until after success becomes assured. People often don't even really know the cause of their success but they do know that by trumpeting it loudly, they increase their chances of a bonus or promotion. This certainly isn't true of everyone by any means but it's a common enough trait across our collective humankind.

When to Use Consequence Management
The tendency towards managing consequences after a risk has manifested isn't necessarily a bad thing and indeed, sometimes it's entirely appropriate. If your job involves emergency management or disaster relief then ‘consequence management’ is absolutely the right area to be focused on. Natural disasters such as earthquakes are typical of risks where consequence management is more important than likelihood management. I'm not suggesting by any means, that we do away with likelihood management, but rather that we understand the role that these two elements have in any risk management strategy. With bushfire management for example, it's important to reduce likelihood by managing fuel loads, fire bans, bushfire alerts, reducing housing pressures in bushland etc, but ultimately bushfires will occur no matter what we do. Indeed the ecosystem needs them to occur in order to stay in balance. Hence, the focus has to be on resources, training and leadership to reduce the consequence of inevitable fires. For most of us however, an ounce of prevention is worth a ton of cure and this is the area of ‘likelihood management’.

The Symbiosis of Likelihood and Consequence Management
A good illustration of the relationship between likelihood and consequence management is the link between security (likelihood management) and emergency response (consequence management).  Post 9/11 when we were looking at protecting a major hydrocarbon facility from terrorist attack, we quickly came to the conclusion that we were well into consequence management territory. Security could do a lot of useful things to reduce the risk of an attack but ultimately we couldn't stop a determined adversary. At least, not without a ridiculous amount of resources and some military assistance - certainly way beyond our ability to provide cost effectively. We decided instead, to focus most or our resources on consequence management including the following steps:
  • Upgrade the muster system to get people more quickly to blast resistant emergency shelters
  • Establish reciprocal arrangements with other hydrocarbon facilities to swap cargoes so that our customers would receive continuity of supply
  • Upgrade our terrorism insurance policies
Getting the Balance Right
By way of an example with mixed results, let’s take a look at allopathic (modern western) medicine. We've achieved great advances with trauma medicine and diseases such as typhoid, malaria and bacterial infection. The track record with illness and disease however is somewhat variable and recent years seem to have seen an increasingly heavy reliance on consequence management. As you can see from an earlier blog entry, cancer and heart disease (both highly preventable) are two of the leading killers in the United States and, I think we can safely say, most of the developed world. Take diabetes as another example of an incredibly preventable disease, which still has an enormous reliance on drug related consequence management therapies.

Different Strategies for the Same Risk
Even where we have that have achieved great success in likelihood management, that success is often confined to the developed world. In remote parts of Africa, such as the location where I sit while writing this paragraph, 'preventable' diseases are still killing people on a daily basis. According to the World Health Organization's 2010 World Malaria Report, malaria alone still kills 781,000 people every year with 99% of those in sub-Saharan Africa.

In developed nations, malaria risk management is all about likelihood management. In Africa it's primarily on the right hand side of the bow-tie - very much into the realm of consequence management. According to WHO, there are 225 million cases of malaria each year, most of which are treated successfully with medications after the event (ie. consequence management).  By contrast, malaria was also once rife in America and Europe.   It was so pervasive in Rome that it is even suspected of contributing to the decline of the Roman Empire. Even the word 'malaria' originates from Medieval Italian "mala aria" or "bad air" due due to its association with marshland. Simple steps such as adding screens to windows, avoiding mosquitos, draining open bodies of water and selective spraying of mosquito habitat have all but eliminated malaria from most of the world. This is 'likelihood management' working at it's best.

By contrast, likelihood management isn't working extraordinarily well with malaria in sub-Saharan Africa. To be fair, it is achieving some success and the main reasons why malaria is still rampant have more to do with much broader cultural, political and economic issues - all of which are way beyond the scope of this short article. It does go to show however, that consequence management can still work reasonably when likelihood management hasn't been enough.

Which One Is More Important?
Neither is more important than the other. Likelihood management can stake a legitimate claim to supremacy - after all, prevention is better than cure. It's a tenuous claim however and the reason is self-evident when you think about it. 'Likelihood Management' is really only about tilting the odds in our favor  Almost by definition, there are no guarantees of any given outcome. It's at this point then, that Consequence Management can pipe up and say "you'll always need me, therefore I am more important!". When we look at it more closely however, Consequence Management is always going to have a certain stigma. No matter how good we are at it, there will always be an element of 'we got here by luck' (in the case of positive outcomes) or a sense of failure and loss (in the case of negative outcomes).

It's interesting then to look at what drives our decisions in terms of which strategy to pursue and when. I suspect, it depends a lot on our own predilections, experience and capabilities. If the only tool in our toolbox is a hammer, after a while everything starts to look like a nail - or at least something which will respond to a spot of 'percussive maintenance'. The other critical element which steers our decision making however, is incentives. Think very carefully about how you incentivize your employees. Incentives drive behavior, and I've met executives who openly admit that the main risk they manage is their 'personal career risk' (ie. bonuses and promotions).

Equally, at the industry level, you'll find incentives-driven behavior. When we look at an industry such as the healthcare industry, it's easy to see an increasing focus on insurance, vertical integration and development of drugs that can be patented coming from the allopathic sector.  There aren't many patents that you can take out on a healthy diet, exercise or prevention of disease - and as a result, not as much research or marketing resources going into such things. Pharmaceutical companies focus on consequence management such as patentable drugs, because that is where they make their profit. Once you have a disease, they know that we'll pay almost anything for the cure. In the world of likelihood management, there is less money to be made but there are still plenty of profitable businesses among nutritionists, vitamin companies and gym owners.

In summary however, we can say that even in the most obvious of cases - the pursuit of good health - it's one thing to know that we should all eat healthy diets and exercise, but that simply isn't the way humans are programmed. Likelihood and consequence management both have their place in the real world - the trick is to know which one you're doing and why you chose that approach at any given time.









Monday, October 17, 2011

First Global Survey of ISO 31000 Gets Underway

The closing date for the first global survey of ISO 31000–Risk Management Principle and Guidelines has been extended to 30 November 2011 and I would STRONGLY encourage every risk management professional to take advantage of this opportunity to comment on ISO31000. NB: If you are reading this after 30NOV11, you can still join the ongoing discussion at the ISO 31000 LinkedIn group.


Why you should participate
ISO31000 has it's critics as well as it's champions. You may not agree with even ISO31000. The definition of Risk as "the effect of uncertainty on objectives" is for example still disputed, but the fact remains that it is one of the best selling management standards in the world.

Even if (maybe especially if) you don't like or agree with the Standard, this is your chance to have some input. Members of more than 70 risk management associations around the world have been invited to participate in the study which is being run through an initiative by the LinkedIn discussion group on ISO 31000. Even if you don't use ISO31000 in your organization, it's worth completing the survey just to let us know a) what you think about it and b) why your organization doesn't use it.

It takes less than 5 MINUTES to complete and it is TOTALLY CONFIDENTIAL The data collected will be represented in aggregate form without naming in particular a risk management association, LinkedIn group or entity. No individual name or company name is asked.


What the survey is about
The aim of the survey is to gauge how ISO 31000 is perceived by risk practitioners across all sectors and to provide input for the preparation of the ISO 31004 guide, (due out in 2013).

The survey has been organized by Alex Dali, moderator of the LinkedIn ISO 31000 Risk Management Standard Group with the help of a group of volunteers and Alex sums it up well when he says: "This is the first time the global risk management community active across all fields, sectors, industries and services is being invited to participate in an international survey on ISO 31000. It is a great opportunity to share your thoughts and concerns about the ISO standard on risk management".

The survey will run from 17th of October until the 31st of October 2011. You will be encouraged to participate through your National Standardisation Body, risk management association or the ISO 31000 LinkedIn group.


What is ISO31000:2009 Risk Management Standard
Issued in November 2009, ISO 31000 provides principles and generic guidelines on risk management. It can be used by any public, private or community enterprise, association, group or individual and is not specific to any industry or sector.

This is your opportunity to comment on what is one of the most significant, and best selling international standard so please take the time to provide your input via the survey: www.iso31000survey.com.  Feel free to share this link to any interested contacts, groups, associations or interested entities.

Friday, October 14, 2011

As High or Low As Reasonably Practicable (AHLARP)

We've been debating lately, how well the ALARP concept withstands scrutiny under the ISO31000 definition of risk? The answer - not very well.   In a previous blog, we looked at the traditional view of mitigating risk to be as low as reasonably practicable which is fine when we look at negative risk. Unfortunately for ALARP, the ISO 31000 definition - the effect of uncertainty on objectives - includes both positive and negative risk.  In the case of positive outcomes, we want to manage them to be as HIGH as reasonably practicable.

We decided that it was time to upgrade ALARP to AHLARP (As High/Low as Reasonably Practicable) and being visual thinkers, decided that it was time for a new model.  Along the way, we came up with new acronyms, including RTP. RTP stands for 'Risk Tipping Point' and builds on Malcolm Gladwells concept of a tipping point. It's the point where positive risk starts to outweigh negative risk.

Whether we talk about IT projects, business activities or saving an endangered species, it is fair to say that without some input of resources/effort, the initiative is more likely to fail than to succeed. Putting this into ISO31000 speak, we would say that 'objectives are unlikely to be met'. Simply putting resources into something is of course, no guarantee that it will succeed, but it's fair to say that (assuming some level of planning and quality) the more resources we put in, the lower the negative risk and the higher the positive risk.

Figure 1: AHLARP Model
Using a notional example in Figure 1 above, you can see that it doesn't take a huge amount of resources to reach the risk tipping point. A few more resources and you've hopefully managed negative risk down to the point where additional resources aren't making a huge difference to reducing hazards. Positive risk should in theory continue to increase up to the point where it (green line) starts to flatten out and increasing resources (blue line) don't have much impact.

AHLARP becomes the conceptual area where our risk strategies are achieving the optimal range of benefits for a given range of resource inputs. This infers what we already know from experience, that there is no single perfect point for risk/reward optimization, but rather a range where we are trying to balance resource (cost) with positive risk (potential benefit) and negative risk (potential loss).

Accepting that there is rarely if ever, a single point where likelihood and consequence form a point value (eg: "this risk as a 57.6% likelihood of generating $123,000 benefit") we can look at illustrating risk across a spread of outcomes. Figure 2 below, illustrates the likely spread of outcomes if we apply insufficient resources (or quality) to manage a risk.
Figure 2: Inadequate resources increase the likelihood of negative consequences
Figure 3 by comparison, looks at what we seek to do with risk management. If we had to sum up risk management in a single picture, this would be a worthy contender. What we try to do is quite simply, to push the spread of likely outcomes towards the positive. A statistician might say that we're applying resources to left-skew the possible range of outcomes. ISO31000 might say that we're attempting to reduce the 'effect of uncertainty on objectives'.
Figure 3: Applying management resources to shift risk outcomes towards the positive
Judging just how much investment is appropriate to achieve AHLARP, is of course no simple feat. Too little is, well... too little and likely to be a waste of money/time/effort with little impact on outcomes. By contrast, applying an excess of resources is just wasteful and leaves inadequate resources for other projects.  Figure 4 illustrates this idea as a general concept but sadly doesn't give us the magic formula (hey, if it was easy, there'd be no need for risk management, and few if any Enrons, HIH, Exxon Valdes, etc).
Figure 4: Range of 'prudent' investment
Determining what is 'prudent' or 'appropriate' requires significant analysis, well beyond the scope of any single book or blog entry.  That being said, there are some general principles that can be applied. It's tempting to say that 'the more risky a venture is, the more resources should be applied' but that simply isn't the case. Some ventures have significant upside risk, with little downside risk. Running a stationery manufacturer or bookshop will probably work out well without a huge need to manage downside risk. Sure, you probably won't create the next Amazon but you're likely to make a good living and steady income. A hydrocarbon plant by comparison, can turn out to be brilliantly profitable or catastrophically bad - and it can turn around from one to the other in a matter for days, weeks or months.
Figure 5: 'Prudent' is context driven
Figure 5 illustrates the different nature of investment depending on your context. 'Prudent' investment for a gas plant is likely to involve a significantly larger amount of resources and cash than making prudent investments for a bicycle manufacturer or a stationary supplier. Even if the businesses have the same turnover and relative size,  one is simply more volatile than the other. Which leads us to the concluding point.

The more volatile a risk is, the more resources need to be applied. If the green and red lines in Figure 1 have a lot of potential ranges, it's going to be expensive to stay consistently within the AHLARP zone.









Thursday, October 13, 2011

How to deal with complexity...


It's a question of context. We live in a complex world - so much so, that we could describe it as a world of complexity in a universe of uncertainty. But is this a good thing?  If more uncertainty = more risk, then more uncertainty is a good thing for an optimist but a bad thing for a pessimist. What does it mean for a risk manager though?   If you ask 100 people how to assess 'quality' of life, you're likely to get more than a hundred answers. Personally though, I measure the quality of my life by how many options I have. For me, it's all about choices. Increasing my range of options is the reason that I did the Master of Risk Management. If I’d just wanted the knowledge, I could have studied any number of texts (I do anyway) but having the paper that proclaims me as a ‘Master of Risk’ bestows upon me an increasing number of options -  not least of all the ability to legitimately work in any profession, industry or continent.

Everyone has their own value system but the pursuit of ever increasing options is what drives a lot of my decision in life. It does have it's downside though - along with increasing my options comes an increase in uncertainty (after all, I have to make more decisions), ambiguity and complexity. What prompts me to reflect on this today is that I've just received my monthly edition of 'Market Talk' from my friendly Swiss banker, Philip and this month is all about 'complexity'. It’s appropriate that I reflect on that topic while consulting in Africa at a remote camp on the edge of the Rift Valley.  While I sit here with my offshore bank accounts, mortgages, spreadsheets and blogs, the local villagers are at the other end of the complexity scale. It's a scenic place but we're deep in grass-hut, subsistence farming territory. Although we have satellite internet at camp, we're a days drive from the nearest petrol station and four hours walk from the nearest hill with phone reception.. Most of the locals are pretty happy with their lot, but I sometimes see them looking at us mzungus in a way that clearly says “gee, I wish I had all their choices/vehicles/money/toys/etc".  In truth, or at least in all likelihood, most of them couldn't cope with the complexities and ambiguities that come with such things.

Driving around in a Landcruiser looks like an easy and pleasant way to get around compared to walking (and it is) but there is an invisible complexity to the tip of that 4WD iceberg. Keeping those Landcruisers running, managing a million dollar budget, bringing food and spare parts down a 1,500 km supply line, let alone all that goes into geological exploration in Africa, are below the surface of that dusty and dented Landcruiser/iceberg. Go a little further down the rabbit hole and you find a sea of complexities. Investors, stock markets, recruitment of skilled professionals, timetables and deadlines, mortgages and leases, credit cards, exams, job applications, budgets, drivers licenses and and much, much more comprise the minutiae of life that most blog readers will be familiar with.

That’s the downside of choices. If you have only one option when it comes to job, house, education, healthcare, etc then you don’t need to consider trade-offs, or make any significant decisions. Most of the locals out here don’t have to make many decisions and I can understand the appeal of that. Every so often, I like to take a complete break and just sit on a beach for two weeks. When the biggest decision of the day is picking what to eat, it's a wonderfully relaxing lifestyle - for a short while. I couldn't live like that long term, but many people do so happily. The locals here know when the wet season comes, they know how to build a hut, plant a maize crop, what to eat for breakfast (maize porridge - the same as they had for every preceding breakfast of their lives). And for the most part, it seems that they are pretty happy with that state of affairs.  Personally... I’ll take the choices, accept the complexity, make the decisions and seek to have ever more options available to choose from.

But the blog isn't just about the 'benefits of complexity' - it's called "How to deal with complexity...'

When it comes to complexity, my approach is simple. I embrace it - and surf the wave. But this book after all, is about the 'how to' of risk management (ISO 31000 style).  There are many perspectives we can use for understanding our world a little better, but when it comes to what ISO31000 would describe as 'establishing the context' I find the VUCA model a pleasantly KISS (Keep it short & simple) approach.

VUCA is an acronym used to describe, or at least reflect on and discuss, the volatility, uncertainty, complexity and ambiguity of general conditions and situations. The term VUCA came into use in the late 1990s in the military and has been subsequently adopted in strategic leadership. One way to phrase the questions would be:
  • Volatility. How volatile is our current situation? What are the nature and dynamics of change, and the change catalysts that effect our organization?  What is the nature and speed of  those change forces? Last but perhaps most important is: what aspect or element of our situation is the most volatile (ie. 
  • Uncertainty. How much predictability do we have and in particular which areas of our business have the least levels of certainty? What issues around lack of predictability, the prospects for surprise, and the sense of awareness and understanding of issues and events should we be concerned about?
  • Complexity. How complex is our context, our business model and the environment we operate in? What are the multiplex of forces, the confounding of issues and the chaos and confusion that surround our organization?
  • Ambiguity. What level of ambiguity are we facing now or in the future? In what areas are we facing them and how are they likely to effect us?  Specifically, what are the key issues around any haziness of reality, potential for misreads, or mixed meanings of conditions and cause-and-effect confusion?
Out of all these questions, the last but perhaps most important to return to is the question of Volatility. In particular, what aspect of our situation is the most volatile? This question can take some time to answer as it’s often not going to be the most obvious. A security risk assessment that I did for a large oil project turned up all the usual risks (terrorism, war, disgruntled employees, fraud, hacking, etc) as you'd expect. None of these were particularly volatile however, as we could identify indicators which could offer months or even years of advance notice.  The only risk that could realistically change overnight was environmental activism, and the main trigger for it wasn’t even a security risk. The plant had a great operating record, but experience from other similar facilities, indicated that within 24 hours of an oil spill, we were likely to have busloads of protestors at the gate, blocking traffic and creating chaos. And at the risk of stating the obvious, the easiest (but neither not the smartest, nor safest) way to shut down a hydrocarbon facility is to organise protestors to climb the fence and drape banners over the processing equipment. It’s just too dangerous to have people in a hydrocarbon facility who haven’t done the safety induction. Even the spark from a mobile phone can have catastrophic consequences and once people get into the operations area, an emergency shutdown can cost millions of dollars. Identifying this as the most volatile security risk resulted in changing a host of procedures and systems. Nothing we did as a result of this was particularly costly, and there was already a major focus on spill preventions but on the security side for example, we:

  • prepared a safety training program and leaflets for environmental protestors 
  • reviewed security procedures to automatically trigger additional staff in the event of an environmental incident
  • updated our liaison program to reach out to the leaders of more environmental groups to ensure that we had pre-existing lines of communication

Dealing with complexity is all about understanding the range of interactions and interconnectedness of seemingly unrelated things.  Looking at complexity through the VUCA lens helps us to understand the context in which organizations (or people) operate and in particular their current and future state. Used as discussion or analysis questions, they provide not only a better understanding of the current environment, but can offer insights into to how people view the conditions under which they make decisions, plan forward, manage risks, foster change and solve problems. In particular, it can help you to:
  • Anticipate the issues that shape conditions
  • Understand the consequences of issues and actions
  • Appreciate the interdependence of variables
  • Prepare for alternative realities and challenges
  • Interpret and address relevant opportunities
You could if you so chose, take these four simple questions and evolve a semi-quantitative scale to suit your particular situation.  This might help you for example, to compare the merits and uncertainties of various projects. It could be equally useful for comparing the various elements of your financial or resources portfolios and that in itself would be valuable. Overall though, the discussion that leads to those rankings is likely to be the most useful part of the process.

As Dwight D. Eisenhower said, "Plans are worthless but planning is everything."  Similarly, our limited understanding of the world is unlikely to outlast first contact with reality - but making the attempt to understand the complexities of life, gives us the best chance of achieving objectives.