#2 – RISK MANAGEMENT AND LEAN SIX SIGMA – ADINA SUCIU/G. HUTCHINS – SIX SIGMA@RISK™

By Adina Suciu & Greg Hutchins
adina@adavconsulting.com 206.234.8014

We are living in a VUCA world.

VUCA is an acronym for ‘volatility, uncertainty, complexity, and ambiguity:

  • Volatility is the accelerating rate of change around competition, business, employment, career, and job challenges.
  • Uncertainty may be our biggest challenge and is our inability to cope with volatility.  Things are changing so fast and in so many unexpected ways that it’s overwhelming our ability to cope and to understand what’s going on.
  • Complexity entails all the issues and the chaos that surrounds us, that lead to confusion in making smart decisions in what we call the ‘fog of reality.’
  • Ambiguity is the difficulty and inability to solve complex problems and make clear decisions because of the ‘fog of reality.’  There doesn’t seem to be a linear cause-and-effect relationship between problems and solutions.  This can result in misreads, poor decisions, or more often no decisions.

RESPONDING INSTEAD OF REACTING
VUCA is increasing the dimensions of risk the organizations are facing in today’s competitive environment. One solution is to understand that VUCA is presenting new opportunities to capitalize.  When the answer to VUCA is responding and not reacting, there is the benefit of the innovation opportunities that VUCA is fostering. Responding and reframing VUCA can lead to the following[1]:

  • Volatility yields to Vision:  Vision implies there is a clear understanding of the desired future state.
  • Uncertainty yields to Understanding:  Understanding is the critical acceptance of the short and long term factors that can affect one’s career, work, and personal life.
  • Complexity yields to Clarity:  Clarity is the basis for understanding how to deliver personal value through staying flexible, keeping current with technology, learning new value adding skills, being able to innovate, and being able to deliver increasing value.
  • Ambiguity yields to Agility:  Agility is the ability to be nimble by responding to new situations with new ideas, new approaches, and new skills.

STRENGHENING BUSINESS SUSTAINABILITY
Building the mechanisms to responding to VUCA strengthen business sustainability. Organizational agility encompasses a number of elements including the ability to innovate, collaborate, and manage risks.  In other words, the VUCA responsive organization is an agile organization. An agile organization has mechanisms in place to assess and continuously improve its performance. The Baldrige Criteria for performance excellence defines the following types of performance:

  1. Product performance refers to performance relative to measures and indicators of product and service characteristics important to customers. Examples include product reliability, on-time delivery, customer-experience defect levels, and service response time.
  2. Customer-focus performance refers to performance relative to measures and indicators of customers perceptions, reactions and behaviors.
  3. Operational performance refers to workforce, leadership, organizational, and ethical performance relative to effectiveness, efficiency, and accountability measures and indicators. Examples include cycle time, productivity, waste reduction, compliance, fiscal accountability, strategy accomplishment, and community involvement. Operational performance might be measured at the work level, key work process level, and organizational level.
  4. Financial and marketplace performance refers to performance relative to measures of cost, revenue, and market position, including asset utilization, asset growth, and market share.

ENTERPRISE RISK MANAGER SOLUTIONS
Managing performance includes managing risk at enterprise level. There are many Enterprise Risk Frameworks. For example, the COSO ERM:

As we can see, it has all the dimensions of managing performance and addressing VUCA. Managing performance implies managing risk and it is more efficient if they are done together, as part of the value stream. Performance management is effective when processes are well defined and managed. Using Lean Six Sigma methodology and tools proved to be key in ensuring high performance levels.

One best practice in Lean Six Sigma Methodology is to clearly define the quality requirements for inputs and outputs along the value stream. When we also define the assumptions on the inputs and outputs, we have the risks exposed and an opportunity to assess, mitigate and control. We also want to discuss the regulatory and compliance requirements and the response to emergency and business continuity requirements and assumptions along the end to end processes. With this approach, operations incorporate not only quality, but also risk.

Another critical component of agility is collaboration, the bases of a learning organization.  Collaboration or teamwork can foster innovation and product development.  Team work is essential: everybody in the organization, all the process participants, directly involved in day-to-day operations, are the people in the best position to innovate. Looking at risks, will trigger other opportunities for innovation. The leaders’ responsibility is to allow and foster a culture of organizational learning. This means the employees are empowered to continuously improve and make the right risk based decisions.  The above characteristics of an agile organization are also characteristics of a high performing organization.

QUALITY AND SIX SIGMA
Quality does not specifically address VUCA.  But it is much easier to start to manage VUCA (build or strengthen the Enterprise Risk Management) when quality systems and processes are  in place; in other words, when processes are stable and capability is ensured by managing the risk-controls. By building on an effective quality deployment, organizations can get an early jump by incorporating risk management into their strategic planning and operational processes. External and internal risk factors will be identified, addressed and continuously monitored to be minimized. In this way, organizations will be better prepared to handle rapid changes and unexpected challenging events.

Addressing risk, organizations will strengthen not only operations, but also the product and service offerings because the potential harm to the environment and society (communities, customer, employees) of their offerings will also be identified as another type of risk and it will be managed and minimized. In doing so, organizations ensure their long-term survival in a VUCA world.

Quality offers the ideal platform for risk management. Quality tools assist in risk management and the quality professionals are well positioned to expand their skills to risk management. Systemic thinking and process thinking along with ability to use tools like SWOT analysis, FMEA, Capability Studies, QFD, Statistical Process Controls, etc, are a strong foundation for VUCA management.

For  engineers involved with quality, it is a natural evolution to incorporate risk management in their work. There is an increased awareness regarding risk management: even if the quality compliance is very high, one gap in risk management could have dramatic impacts. Any process has to be effective, efficient, well measured and monitored for key performance indicators and key risk indicators. All the interdependencies between processes within work systems have to be assessed and the risk mitigated.

The shift from quality to risk management is a “must” in this VUCA world. The engineers who recognize this fact and expand their skills to incorporate risk management will be very well positioned in the job market for many years to come.

Bio:

Greg Hutchins PE and CERM (503.233.101 & GregH@QualityPlusEngineering.com)  is the founder of:

CERMAcademy.com
800Compete.com
QualityPlusEngineering.com

WorkingIt.com

He is the evangelist behind Future of Quality: Risk®.  He is currently working on the Future of Work and machine learning projects.

He is a frequent speaker and expert on Supply Chain Risk Management and cyber security.  His current books available on all platform are shown below:

#2 – ASSESSING THE RISKS OF RISK ANALYSIS – UMBERTO TUNESI – QUALITY@RISK™

By Umberto Tunesi
Management System Auditor
© 2012 Quality Digest, All Rights Reserved

Just a few reminders to start with: In the automotive supply chain, process failure mode and effects analysis (FMEA) must be based on—or at least must take into consideration—design FMEA. This is the case whether a given supplier is responsible for the design or not.

During an FMEA, severity (S) is ranked from 1 to 10, depending on the severity of an effect on a product, customer, manufacturing process, or operator.

Occurrence (O) is ranked from 1 to 10, based on the number of incidents per items per vehicles. It’s interesting to note that a rank of 1 (i.e., very low) is based on the criterion “failure is eliminated through preventive control.”

Detection (D) is also ranked from 1 to 10. A rank of 1 is based on error prevention, but a rank of 10 is assessed as “no current process control.” Curiously enough, ISO/TS 16949:2009 cites “error prevention” in the notes to clauses 7.1 and 7.3, but then switches to “error-proofing” in the note to clause 7.3.2.2 (“Manufacturing process design input”: mark it!), as well as for clauses 7.3.3.1, 7.3.3.2 (“Manufacturing process design output”), 8.5.2.2, and Annex A, Section A.2d.

Now, if detection is ranked as 1 when errors are prevented, should it be ranked zero when error-proofing methods are in place?

There is something more to this. ISO/TS 16949 clause 7.6.1 states, “This requirement shall apply to measurement systems referenced in the control plan.” Since these systems shall be developed from the process FMEA, and clause 7.5.2.1 requires that “all process for production and service provision” be revalidated, doesn’t this mean that the process FMEA must be subjected to measurement system analysis and revalidation?

It may sound a bit crazy, yet it isn’t really so when we consider the reality behind FMEA and observe how S, O, and, D rankings are personality-driven. As happens elsewhere in human interactions, the person who shouts the loudest, looks the fiercest, or whose fist hits the table first, is the “winner who takes all.”

Let’s look at a typical production process. In the beginning, there’s a customer’s request for a quote, along with the usual deadline for submittal “yesterday.” Then the supplier’s top management—under time and budget constraints—comes up with a quote based on the criteria, “Let’s put the order in the box, then we’ll see; this widget is similar to what we’ve been doing for years.”

The drawing comes in and is read as such, not as the design record that it actually is. There are also tests and their specifications, and these reference further standards, specifications, and customer-specific requirements.

A production part approval process (PPAP) package is hastily put together and submitted to the customer, together with an initial sampling. The customer’s quality manager, under similar time constraints as the supplier, signs the parts submission warrant, and there we are.

We then move to the ramp-up and mass production, where the only documentation is the setup and work instructions from the similar widget the company has already produced, and the drawing of the new one. But what about the records? Well, let’s not waste time making the line operators write down the measurements that they read; they take more measurements than what’s required, so an OK or a tick is more than enough. Plus there’s quality control at the end of the line; they will do offline controls with a CMM and all sorts of expensive devices.

Sooner or later, though, there’s a mess, a catch, be it an 8D or similar request, a CSL1 or CSL2, a new business hold (NBH), a customer audit, or the periodic registrar’s audit.

And the mess, whatever it is, highlights that the PPAP package is mostly comprised of counterfeits: process flowcharting, process FMEA, control plan, work instructions, measurement system analysis, training records, feasibility commitment, and so on.

Therefore—and now we’re back to time constraints—the business is at stake. The poor quality manager, who may have sounded the alarm well in advance of the quote and the PSW submittal, now bears all the weight on his shoulders.

Of course, this is a worst case scenario, yet many similarities are found in real cases, where control plans come after work instructions, FMEAs come after control plans, process flowcharting comes after PPAP—just the opposite of any golden rule for prevention.

It’s true the automotive supply chain is under a lot of pressure to save both money and meet deadlines. And I have no financial title to back my opinions about costing issues, yet I believe suppliers could and should do better, in terms of risk assessment, feasibility analysis, and prevention.

For one thing, it’s the suppliers that own the knowledge of the machinery, materials, personnel, products, and processes. It’s useless to start a process FMEA at the same time as the incoming inspection, especially when incoming materials are inspected only for quantity and external appearance. The same holds true for sampling plans, both in-line and at the end of the line: The usual answer to the question, “Why every hour and not every four?” is, “We’ve always done it this way.”

Process flows are charted with the same level of detail as the history of humankind, beginning with Adam and Eve. These charts don’t focus on risks and often are too generic to pinpoint what can—and will—make the process go wrong.

Process FMEAs often suffer the same problem: All sorts of potential failure modes are listed, along with issues that have little to do with the operation in question, based on the criterion that “one never knows what can happen.” The redundancy is built in just to err on the safe side. (“Let’s see, belt and suspenders, what else? Fasteners on the waist?”)

No wonder that “severities” are seldom ranked below 7. Is this effective risk analysis?

The process of determining potential effect(s) of failure is based on the same criteria, but it’s made worse when FMEA-makers confuse product failure—and therefore design failure—with process operation failure.

To quantify these situations, Mr. Pareto would need to revise his famous 80-20 rule—where 80 percent of the effects come from 20 percent of the causes—to say that 99 percent of the effects of process failure are “human error”—i.e., humans who erred when they wrote the process FMEA, and humans who erred by endorsing it. This can extend even to high-severity rankings when no corrective action is determined. It seems these people adhere to the principle that “to err is human,” but forget that “to persist is the devil’s work.”

Control plans, which should in principle originate from process FMEAs, often are mish-mashes of input from the FMEA, previous experience of the same or similar process, and a constraint to produce either stamp-sized or a monster-sized documents—in either case useless except for documentation purposes.

But there’s no need to drift into a Hamlet-type soliloquy here: It’s not a question of “to FMEA or not to FMEA.” Rather, how should we effectively assess risk, using FMEA or alternative methods? I find hazard analysis and critical control points (HACCP) a great, simple, and effective way. It’s still used chiefly in the food and cosmetic business, although its key principles pop up elsewhere occasionally. HACCP is based on FMEA, and in its simplest form states that, given any potential failure, if the downstream process will take care of it, then it’s not critical, or a risk, anymore.

This is the closest to error-prevention I can think of—and to error-proofing, too, for that matter. The product-realization process can be so designed and engineered that it can take risks for various reasons (e.g., cost, cycle-time, tolerance, machinery age, shop-floor layout, operators’ skills), but there will always be an operation, or a device, that will correct or scrap the defect.

Those of you who are familiar with AIAG’s APQP manual may share my interest in it. I find it very valuable. The supplements J and K, and A-1 through A-8, pose stimulating, though sometimes redundant, questions. I particularly like the following from the A-7 Process FMEA checklist:

  • Do the effects consider the customer in terms of the subsequent operation assembly, and product?
  • Have the causes been described in terms of something that can be corrected or controlled?
  • Have provisions been made to control the cause of the failure mode prior to the subsequent or the next operation?

And the A-8 Control Plan checklist:  Are sample sizes based upon industry standards, statistical sampling plan tables, or other statistical process control methods or techniques?

ISO 31000:2009—“Risk Management—Principles and guidelines” is surely worth at least reading. Sections 4.3—“Design of framework for managing risk”; 4.4—“Implementing risk magement”; and 4.5—“Monitoring and review of the framework” demonstrate that risk assessment and analysis, as part of risk management, is itself a process, and therefore worth investigating for stability, variability, and revalidation.

ACM Tech News – an excellent resource

From http://technews.acm.org:
Welcome to the April 27, 2012 edition of ACM TechNews, providing timely information for IT professionals three times a week.

ACM TechNews mobile apps are available for Android phones and tablets  and for iPhones  and iPads .

HEADLINES AT A GLANCE
In U.S.-Russia Deal, Nuclear Communication System May Be Used for Cybersecurity
Computer Surveillance Will Help Keep an Eye on National Security
Tiny Crystal Revolutionizes Computing
Tech Needs Girls: World Leaders Draw Up Roadmap for Female Tech Education and Careers Push
CAPTCHA, Crowdsourcing Pioneer von Ahn Captures Grace Murray Hopper Award
Algorithmic Incentives
Dynasty? U of W Repeats as National Cyber Defense Champ.
NSF, SRC Partner on Failure-Resistant Systems
In U.S.-Russia Deal, Nuclear Communication System May Be Used for Cybersecurity
Washington Post (04/27/12) Ellen Nakashima

U.S. and Russian negotiators are close to completing a deal in which a secure communications channel originally established to prevent misperceptions that might lead to a nuclear conflict will be expanded to accommodate cybersecurity. U.S. officials and experts from both countries say the Nuclear Risk Reduction Center would be a major step forward in the initiative to guarantee that misunderstandings in cyberspace do not escalate to full hostilities. The system features computer terminals at the U.S. State Department and the Russian Defense Ministry that are manned 24 hours a day, and it permits the rapid translation of electronic messages to key officials. Officials say that in the event of a cyberincident, the communications channel could be triggered if either Russia or the U.S. identifies seemingly hostile cyberactivity. The channel’s use would only be mandated if the activity is of “such substantial concern that it could be perceived as threatening national security,” according to an Obama administration official. The official notes the Russians asked for a phone-based hotline between the White House and the Kremlin for cyberincidents that is separate from the nuclear hotline. The pact would be the first between the U.S. and another nation that aims to lower the likelihood of a cyberconflict.
View Full Article | Return to Headlines

Computer Surveillance Will Help Keep an Eye on National Security
Queensland University of Technology (04/26/12) Stephanie Harrington

Technology that combines two-dimensional (2D) and three-dimensional (3D) video images taken from a variety of challenging environments will make it easier to identify people who are not facing cameras, according to Queensland University of Technology researchers. Queensland professors Sridha Sridharan and Clinton Fookes plan to develop mathematical algorithms that will make it possible to take features from video and convert them into a model capable of recognizing and matching facial features. “What we are trying to do is use multiple cameras in space to reconstruct a face in 3D, or use multiple images over time of the same face to reconstruct into 3D,” Fookes says. “Once we have the information, the system will then be able to identify a shortlist of possible candidates and it will then be up to a human observer to authenticate the correct match.” The result of the project will be a set of tools for facial analysis in visual surveillance and video content extraction applications. The surveillance technology would benefit law enforcement agencies, which often struggle with poor quality video and images during investigations.
View Full Article | Return to Headlines

Tiny Crystal Revolutionizes Computing
University of Sydney (04/26/12) Verity Leatherdale

Researchers at the University of Sydney, the U.S. National Institute of Standards and Technology, Georgetown University, North Carolina State University, and the Council for Scientific and Industrial Research have developed a tiny crystal that enables a computer to perform calculations that are too difficult for the world’s most powerful supercomputers. “The system we have developed has the potential to perform calculations that would require a supercomputer larger than the size of the known universe–and it does it all in a diameter of less than a millimeter,” says Sydney’s Michael Biercuk. The new quantum simulator is potentially faster than any known computer by 10 to the power of 80, according to the researchers. They say the crystal goes beyond all previous experimental attempts in providing “programmability” and the critical threshold of qubits needed for the simulator to exceed the capability of most supercomputers. The simulator also can be used to gain insights about complex quantum systems. “We are studying the interactions of spins in the field of quantum magnetism–a key problem that underlies new discoveries in materials science for energy, biology, and medicine,” Biercuk says.

Tech Needs Girls: World Leaders Draw Up Roadmap for Female Tech Education and Careers Push
International Telecommunication Union (04/26/12)

American, European, African, and Asian leaders recently gathered for a high-level dialogue hosted by the International Telecommunication Union (ITU) to outline a roadmap to get more girls into technology-oriented studies and careers. ITU Secretary-General Hamadoun Toure says information and communications technology (ICT) jobs are expected to greatly outstrip the supply of professionals to fill them within the next 10 years, which represents “an extraordinary opportunity for girls and young women.” He stresses that stereotypes and obsolete attitudes about ICT careers being too difficult, unfeminine, or boring for girls should be abolished. “Encouraging girls into the technology industry will create a positive feedback loop–in turn … inspiring new role models for the next generation,” Toure says. Other factors the dialogue identified as collectively impeding girls’ progress in technology fields are a geeky image of the tech discipline promulgated by the popular media, misguided school-age career counseling, a lack of inspirational female role models, and a shortage of supportive home- and workplace-based frameworks. Toure urged the event’s participants to work with ITU on a three-year Tech Needs Girls campaign concentrating on the themes of empowerment, equality, education, and employment.

CAPTCHA, Crowdsourcing Pioneer von Ahn Captures Grace Murray Hopper Award
Network World (04/26/12) Bob Brown

Carnegie Mellon University associate professor Luis von Ahn has received ACM’s 2011 Grace Murray Hopper Award, which recognizes outstanding work from young computer professionals and comes with a $35,000 prize. Von Ahn’s latest project, Duolingo, helps people learn foreign languages while translating text on the Web. “Professor von Ahn’s breakthrough research has changed the game for how we use computers,” says ACM president Alain Chesnais. “His innovations impact our personal usage of computing devices and make commercial applications of computing more secure.” Von Ahn’s accomplishments also include the development of the widely used Completely Automated Public Turing Tests to Tell Computers and Humans Apart technology, a challenge-response test designed to ensure that the response is from a person. A second generation of the technology uses crowdsourcing to simultaneously digitize books. Chesnais says von Ahn’s “potential for further altering how we work and play in the digital age seems boundless.”

Algorithmic Incentives
MIT News (04/25/12) Larry Hardesty

Massachusetts Institute of Technology (MIT) professor Silvio Micali and graduate student Pablo Azar have developed a type of mathematical game called a rational proof, which varies interactive proofs by giving them an economic component. Rational proofs could have implications for cryptography, but they also could suggest new ways to structure incentives in contracts. Research on both interactive proofs and rational proofs falls under the designation of computational-complexity theory, which classifies computational problems according to how hard they are to solve. Although interactive proofs take millions of rounds of questioning, rational proofs enable researchers to establish one round of questioning. With rational proofs, “we have yet another twist, where, if you assign some game-theoretical rationality to the prover, then the proof is yet another thing that we didn’t think of in the past,” says Weizmann Institute of Science professor Moni Naor. Rational-proof systems that describe simple interactions also could have applications in crowdsourcing, Micali says. He notes that research on rational proofs is just getting started. “Right now, we’ve developed it for problems that are very, very hard,” Micali says. “But how about problems that are very, very simple?”

Dynasty? U of W Repeats as National Cyber Defense Champ.
Government Computer News (04/25/12) William Jackson

A team from the University of Washington recently won the National Collegiate Cyber Defense Competition for the second straight year, defeating regional champions from nine other schools. The tournament, which began in 2005, is part of a nationwide effort to identify and develop cybersecurity talent. The U.S. Air Force Academy finished second in the competition and Texas A&M University came in third. As part of the competition, each team was given an operational network for a fictional Web services hosting company with subsidiary retail operations, such as email, Web sites, data files and users. The network had to be operated and services maintained in the face of outside attacks. The teams were scored on their ability to maintain services while completing business tasks and lost points for failing to meet service-level agreements. In addition, cloud computing was a major component of the competition this year, says University of Washington cybersecurity program director Melody Kadenko. She notes that teamwork helped the Washington team win the competition. “The most important component was how they interact with each other,” Kadenko says. “They already had the knowledge … but you can’t teach how to get along with somebody.”

NSF, SRC Partner on Failure-Resistant Systems
CCC Blog (04/24/12) Erwin Gianchandani

The U.S. National Science Foundation (NSF) and the Semiconductor Research Corp. (SRC) recently announced Failure-Resistant Systems, a joint initiative that seeks proposals for new techniques that would ensure the reliability of systems. The proposals should focus on a system-level cross-layer approach to reliability, and encompass the failure mechanisms of both digital and analog components. Such a technique would potentially offer high reliability and lower power and performance overheads. “By distributing reliability across the system design stack, cross-layer approaches can take advantage of the information available at each level, including even application-level knowledge, to efficiently tolerate errors, aging, and variation,” the initiative’s solicitation says. “This will allow handling of different physical effects at the most efficient stack layer, and can be adapted to varying application needs, operating environments, and changing hardware state.” NSF and SRC plan to fund 15 to 20 awards, each ranging from $300,000 to $400,000, over three years. The deadline for proposals is June 26, 2012.

Software Risk References

Here are a set of references for topics discussed in the webinar:

–SP 800-39 Mar. 2011 Managing Information Security Risk: Organization, Mission, and Information System View
SP800-39-final.pdf
–SP 800-27 Rev. A Jun 2004 Engineering Principles for Information Technology Security (A Baseline for Achieving Security)
SP800-27-RevA.pdf
–SP 800-12 Oct 1995 An Introduction to Computer Security: The NIST Handbook
handbook.pdf
–SP 800-142 Oct. 2010 Practical Combinatorial Testing
SP800-142-101006.pdf
Open Web Application Security Project (OWASP) Cheat Sheets: https://www.owasp.org/index.php/Cheat_Sheets
“Design Patterns: Elements of Reusable Object-Oriented Software” by Erich Gamma , Richard Helm , Ralph Johnson , John Vlissides
“Metrics and Models in Software Quality Engineering”, 2nd Edition | InformIT http://www.informit.com/store/product.aspx?isbn=0201729156