#133 – RISK IS NOT EVEN HALF OF IT! – IAN DALLING

Featured

AAA DallingLast month’s Insight explained that MSS 1000 is a universal management system standard that facilitates the creation of fully integrated management systems without boundaries addressing the totality of the management of an organisation irrespective of size and type. We now look at how it promotes a holistic management of uncertainty. Continue reading

#133 – PROJECT DASHBOARDS: ARE WE MISSING THE PICTURE? – MALCOLM PEART

Featured

Malcom Peart pixI was once asked by a non-English speaker; “What is a dashboard?” Our Client wanted a ‘dashboard’ summary of the monthly status as part of Project Controls for a ‘health check’.

I explained that cars have dashboards. Analogously, I told her that my first car (a Spitfire) had a ‘dashboard’ with a speedometer (marginally functional) to measure speed, temperature gauge (working) to warn of impending overheating, fuel gauge (temperamental) to let me know when I needed to top-up the tank, an odometer (erratic) to let me know how far I had travelled, plus a rev-counter that didn’t work. Continue reading

#132 – WHAT TO DO IF THERE IS NO AUDIT DOCUMENTATION? – GREG HUTCHINS

Featured

Greg Hutchins pixMost organizations have established operational standards, objectives, metrics and expectations, which are operationalized through procedures and work instructions. If these exist, then the value added auditor can use these as a metric to conduct an audit.

The internal auditor determines whether the business objectives, standards, metrics, processes and work instructions are acceptable to meet audit objectives and then determine if they are being met.

But, what does the internal auditor do if there are no technical, procedures, policies, specifications, standards, or other types of documents? Continue reading

#132 – STRUCTURING ICT MANAGEMENT TO ALIGN IT WITH THE ENTERPRISE: PART 3 CHARTING TO BE – HOWARD M. WIENER

Featured

Howard Wiener PixIn previous posts (Part 2) , I defined a simple hierarchy for portraying the Enterprise and made a case for the importance of understanding and documenting the as-is Enterprise Architecture to a reasonable level of detail.

Continue reading

#132 – MERITS OF RISK MANAGEMENT: COMPLIANCE AS AN INVESTMENT – ANNETTE DAVISON, BOB BURFORD

Featured

AAA&Burford

ABSTRACT

Understanding and implementing sound compliance programs is a fundamental component of corporate governance and risk management. Effective risk management is not limited to understanding an organisation’s regulator-driven compliance requirements. It also includes managing an organisation’s overall operating context risks, within a business outcomes’ framework in order to mitigate these risks and in some cases, turn them into opportunities. With the increasing costs of implementing compliance systems and risk management measures, questions are often asked about their ‘worth’ to an organisation. In this paper, the costs of non-compliance as well as the benefits of good compliance and risk management programs are considered. Continue reading