Thursday, March 31, 2011

So what?

Seems like we've been at war for a long time... World War II drifted into the Cold War and more recently War on Terror, War on Drugs, War on Poverty. Frankly it sounds more like a 'War on Commonsense' (oops, damn those renegade thought bubble).   Next we'll have a war on tsunami's.  Actually, it looks like we're almost there. Google reports 1,110 hits on "war on tsunamis" so it must be real.  We've got 20,800 hits for "war on heart disease" so that's not a bad thing but even that pales against the 8,530,000 hits that Google took 0.13 seconds to bring up when I searched for "war on terror".  

It's good to see that the essentially useless Homeland Security Advisory System (HSAS) is about to be replaced.  Steve Martin's assessment of the HSAS is probably more charitable than I or most of my security colleagues when he says: "The warnings were so vague that nobody could usefully do anything about them. The only possible purpose in issuing the warnings was to be able to say, 'I told you so' in the event of a terrorist attack. Well, that's the charitable interpretation. There are various less-charitable interpretations that are more to do with terrifying people. Surely that's the aim of terrorists though? Why would government authorities want to help them?"  Why indeed?  But that's for another section of the book.

Meanwhile, we're not sure yet what will replace HSAS but as of 30MAR11, the National Terrorism Advisory System (NTAS) "... is currently in a 90 day implementation period that began on January 27, 2011 – until the end of the implementation period, the existing HSAS will remain in effect".

I'd applaud that change if I knew what was actually going to replace it but apparently it "will more effectively communicate information about terrorist threats by providing timely, detailed information to the public, government agencies, first responders, airports and other transportation hubs, and the private sector."  Can't wait.  In the meantime, here's my suggestion for a real world threat advisory system.  Not to ignore the seriousness of terrorism to it's victims but frankly unless you live in the Middle East (which is a whole different ball game from anywhere else in the world) suicide and bathtub accidents kill more people than wannabe terrorists.
risk management
Real World Risk Advisory System (Note: If not living in America this may or may not apply to you)
I also quite like the way the CDC prepares some of it's mortality information (or at least the level of detail they go to) but this table particularly caught my eye.
Source: http://www.cdc.gov/injury/images/LC-Charts/10LC_overall_2005b-a.pdf

Some telling statistics there. If you click on the graphic or follow the link, you'll find unintentional injuries (slips, trips, falls, motor vehicle accidents, etc) is the leading cause of death in America for most of our life. It's not the biggest cause of death however. As we get older cancer (malignant neoplasms) gets more and more of us but with a current life expectancy of 79 years, most Americans are going to go down fighting with heart disease.  No votes in a "war on heart disease" that needs lifestyle changes - or is there?  It would certainly get my vote.

Tuesday, March 29, 2011

The basic outline of the book...

This book is being built to not only to mirror and expand on ISO31000 but equally to introduce a raft of new concepts and tools that support risk management. I’ve written it to flow logically you’ll probably get the most out of it if you have time to read it from start to finish but equally it’s being written so that you can jump into any section that you need when you need it. The book doesn’t just follow the flow of ISO31000 however.  Numerous annexes have been included to provide examples of risk templates and to expand on concepts such as enterprise risk management or opportunity realization.

Equally though, if all you need to know is how to identify and document risks, just jump right to section x.x (Identity Crisis… Will the ).  If you need a risk policy in a hurry, then head straight for Section x.y.  Likewise if your boss has told you they want a Risk Management Framework to present to the Board in 48 hours then Section x.z would be an ideal place to start.

I’ll also be including a number of Implementation Tips, Examples and Additional Information so if you just want specific how-to guides or examples of various aspects, you can simply go straight there.   When I pick up a book of this type, I’m usually looking for information to help me actually apply the material so you’ll find practical assistance and examples throughout each section as well as in the Annexes.

Section 2 will deal with some fundamental terms and definitions on which the rest of ISO31000 is predicated.  For the most part they are consistent with they way we understand terms in common usage however there are some particular differences in the way ISO31000 applies them which are worth understanding.

Section 3 will be about the underlying Principles of Risk Management in order that anyone applying ISO31000 will have a consistent understanding of they ways in which risk management can be applied.  This section also discusses some of the concepts behind how risk management could, should and would be applied if implemented fully.

Section 4 will focus on how to actually build a risk management framework for your organization, the elements and their respective interactions.   It is the precursor step to Section 5 where the rubber hits the road so to speak.

Section 5 is where risk management concepts will turn into risk management practice.  This is the section that most people in any given organization will have the most interaction with, whether in complex risk analysis, simple risk assessments or in contributing to implementing risk treatments.

You’ll ideally need to have a copy of ISO31000 handy.  You could simply implement risk management from the contents of this book however, I’m assuming that you bought this book because you’d like to implement risk management the ISO31000 way.  It’s not my intention to duplicate ISO31000 and hence you won’t find it repeated word for word here.  What I’ve attempted to do is to offer at least one if not several interpretations of how you might choose to actually apply the standard.
The book aligns with the flow of ISO31000 but there are some sections that simply don’t align specifically with just one part of the Standard.  You’ll find these sections in Section 7 Enhanced risk management.

ISO31000 risk management process and framework
 Figure 2: Relationship between Principles, Framework and Process (Source: ISO31000)

Sunday, March 27, 2011

Risk Communication - Perception and Deception

Another simple example of poor or misleading risk communication can be found in the O. J. Simpson murder trial.  One piece of information that OJ’s defense team were able to quash was the prosecutions assertion that spousal abuse leads to murder.  The defense argued that Simpsons history of assaulting his wife, Nicole Brown Simpson was not relevant to whether or not he had murdered her.

Alan Dershowitz, a Harvard Law Professor in his book about the case argued that in the United States:
“As many as 4 million women are battered annually by husbands and boyfriends. Yet in 1992, according to the FBI Uniform Crime Reports, a total of 913 women were killed by their husbands and 519 were killed by their boyfriends.  In other words, while there were 2 ½ to 4 million incidents of abuse, there were only 1,432 homicides.  Some of these homicides may have occurred after a history of abuse but obviously most abuse, presumably even more serious abuse, does not end in murder” [8]

Essentially the defense argued that based on these figures, there is less than one homicide per 2,500 incidents of abuse and they used this to argue that there was no evidence of domestic violence being a prelude to murder.  While this is factually true, it is not a useful statistic.

Not only was it not useful but it may well have misled the court. The correct question to ask should have been: “How many women were murdered by men who had previously abused them?”  At the time of the trial, statistics showed that out of every 100,000 battered women, 45 were murdered. Of those 45, 40 were murdered by men who had previously battered them.  In short, 90% of murdered women who had been battered by their partners had in fact, been killed by their partners.  Rather than a 1 in 2,500 probability, past data suggested a statistically significant probability of 90% that OJ was the murderer.

It’s also worth bearing in mind that the death of a woman at the hands of a partner who has previously battered her may appear predictable in hindsight but when only 1 in 2,500 battered women go on to be murdered, this statistic has little if any utility when predicting the likely risk of murder.
Does a 90% probability constitute evidence of OJ’s guilt? Of course not!  Whether or not it would have influenced the jury is another story. We can never say for certain but ask yourself – is it likely that the way in which this information was presented would have influenced your views?

A Call to Action

Given what you now know, is it any wonder that our political leaders and the general public have trouble understanding and prioritising risks such as terrorism, crime, health, national security and hundreds of other risks.  It seems that even in the 21st century with all our amazing communications technologies we have a long way to go to master the simple act of communication risk in any meaningful fashion.  The groundwork on how to present risks using natural frequencies has been done for us by practitioners in areas such as medicine, psychology and statistics. Perhaps it is time that we as risk professionals, managers and policy makers started to look more closely at exactly how we choose to present our risk data?

==================
[8] Dershowitz, Alan (1997), Reasonable Doubts: The Criminal Justice System and The O.J. Simpson Case, Touchstone, New York, USA.

Friday, March 25, 2011

Risk Communication - Using Natural Frequencies

Following on from the previous blog entry, if we want to understand why otherwise knowledgeable health professionals should be so consistently ill-informed, consider this the results of some research by Gerd Gigerenzer. [iv] He first phrased the following question to HIV counselors in probabilities, as is fairly typical of the way statistics are presented to counselors and medical professionals.

“About 0.01 percent of men with no known risk behavior are infected with HIV. If such a man has the virus, there is a 99.99 percent chance that the test result will be positive. If a man is not infected, there is a 99.99 percent chance that the test result will be negative. What is the chance that a man with no known risk behavior who tests positive actually has the virus?”

Most people think that it is 99.99 percent or higher (including most of the counselors in the above study).  Now consider the same question worded differently.

“Imagine 10,000 men who are not in any known risk category. One is infected and will test positive with practical certainty. Of the 9,999 men who are not infected, one will test positive.  So we can expect that two men will test positive.”

From this latter question, you can easily see that the odds are roughly 1 in 2 or 50% that someone from a low-risk category who has a positive test result is actually HIV positive.

The reason that the above wording appears so much clearer is because our brain absorbs the information in a distinctly different way. Presenting the data using natural frequencies means that we are evaluating it using numbers that we can intuitively understand. It yields the same result but is much easier for our brains to calculate that result.   The difference between these two ways is most easily seen in an illustration. Presenting the data in a complex formula produces the right answer but is anything but intuitive.


Using natural frequencies or presenting the same information in a tree based on actual numbers of people as shown below yields the same result but is much easier for us to calculate the correct answer.

The significance of this information for low risk individuals should not be underestimated.  Countless people have endured traumatic psychological stress, lost jobs, separated from spouses, participated in unprotected sex with HIV positive persons or committed suicide as a result of false positive tests.  By 1987 for example, 22 blood donors in Florida had committed suicide after being told that they were HIV positive.   An analysis of these cases many years later concluded that the chances were at most only 50-50 that these individual were actually infected. [v]   The downstream impacts of poor risk communication are not confined to the recipients of the communication either. The potential for legal action against Doctors or government agencies is just one example of a potential cascading spiral of risk begetting risk.

It’s worth noting that for men in high-risk categories (homosexual men or IV drug users for example) with a base rate of 1.5% HIV infection, the chance of a false positive is less than 1 percent.  In a group of 10,000 homosexual men we would expect about 150 to be HIV positive and with practical certainty they will all test positive.  Of the 9,850 who are HIV negative, it is likely that 1 would test positive.  The chance therefore of this person receiving a false positive is therefore 1 in 151 or less than 1 percent.

As you can see from the example above, the way in which we communicate risk can  have a significant impact. Risk communication can of itself, introduce considerable risks where none existed if it is not carefully considered.  The problem of inappropriate risk communication is by no means rare but it is relatively easily addressed. An example of how the above information could be better communicated would be to provide patients and counselors with the same information presented in terms of natural frequencies as outlined below. [vi]

"Depending on the exact procedure used, an HIV test is likely to be positive for about 998 of 1,000 people infected with HIV. About 1 in 10,000 persons will generate a false positive result. False positives can be reduced by repeated testing using different methods but not completely eliminated as certain medical conditions and laboratory errors can still generate false positives. About 1 in 10,000 heterosexual men with low-risk behavior are infected with HIV. Of those 10,000 low-risk men, one is likely to be infected and will almost certainly test positive (99.8% likelihood). Of the 9,999 non-infected men, 1 will also test positive. Thus we expect that out of 2 men who test positive, only 1 has HIV. This is the situation you would be in if you were to test positive and are in a low-risk group. Your chance of having the virus would be about 1 in 2". [vii].

It should go without saying by now that for persons with no known risk behaviors, a second HIV test should be conducted before confirming the positive diagnosis but how would you know this unless the risks are adequately communicated.

====================

[4] Gigerenzer, Gerd (2002), Calculated Risks, Simon & Schuster, New York, USA
[5] Stine,  G. J. (1996), Acquired immune deficiency syndrom: Biological, medical, social, and legal issues. (2nd ed.), Prentice Hall, Englewood Cliffs, NJ USA.
[6] Adapted from Gigerenzer (2002)
[7] Gigerenger, Hoffrage and Ebert (1998)