Showing posts with label Audit & Compliance. Show all posts
Showing posts with label Audit & Compliance. Show all posts

ISO 27701:2019 - ISO Standard for Managing Information Security and Data Privacy of Personal Information

ISO 27701:2019 provides the approach and structure to an organization for building its PIMS (Personal Information Management System).

Like ISO 9001 pertains to QMS (Quality Management System) and ISO 27001 pertains to ISMS (Information Security Management System), ISO 27701 pertains to PIMS.

The primary aim of PIMS is to provide a comprehensive system which can take care of the management of information security and data privacy of personal information (either identified or identifiable) in a systematic and structured manner.

ISO 27701 is considered to be an extension of ISO 27001.

When it comes to personal information, ISO 27001 is supposed to take care of security aspects whereas ISO 27701 is supposed to extend that further to additionally take care of privacy aspects.

An organization needs to first implement ISO 27001 which lays down the foundation for implementing ISO 27701.

From certification point of view too ISO 27701 certification is possible only on top of ISO 27001 certification.


How Much Value Do Model-based Appraisers and Consultants Add?

The question "how much value do model-based appraisers and consultants really add?" is an interesting one.

In fact, it is quite a fundamental question.

But the more fundamental question is this:

"Do they actually add much value?"

And perhaps the most fundamental questions of all would be:

"Do they actually add any value?"

Most of them do little or no value addition.
Appraiser and Consultant - No Value, No Need

The consultants and appraisers are, at the core, mostly one-trick ponies who regurgitate the same set of nonsense whichever organization they go to.

The work like a pair of clowns who ask dumb questions and expect you to think they are smart.

They re-phrase and paraphrase your questions and ask them back.

That's very irritating, to say the least.

They have some rigid notions about the concepts and terms and refuse to see the underlying logic that governs those concepts and terms.

They have no concrete and specific solutions to offer.

So you can expect them to only say this much:

"We ask questions".

Well, what else would someone do when he or she doesn't know the basic stuff?

They know something is crystal clear.

But they would go on and on and repeatedly raise the same, silly and invalid questions.

And to prove their point, they repeat a falsehood again and again.

In every discussion, they hover around the same set of points like:
  • You must understand the pain points
    • this is a completely nonsensical point 
    • you would start an initiative only when you have a business need, real or perceived
    • no one would allocate budget for an activity if there is no business case for it
  • You must articulate the business problem clearly
    • this is another utterly nonsensical and comical point
    • articulation of a business problem is not a linear thing and is done based on the context and the level of the person it is being communicated to
    • Also business problems may not always be straightforward, number-based statements but may involve complex, subjective issues with multiple dimensions
  • You must have the data for this and for that
    • one big question is why should you collect the data without any thought to the overall burden of collecting that data?
    • ignoring the ROI of data collection is a clear reflection of the ignorance of the consultant and appraiser who suggest get the data for this and for that
    • data should be seen in the context of process and should not be used to blindly infer and conclude anything about the process
  • You only would need to define the right approach for doing this
    • then what are you doing and why are you needed?
    • the consultant and appraiser need to be a part of the solution and not offer arcane and generic and non-implementable suggestions
    • everyone knows the usual stuff and if you can't suggest the specifics then you are good for nothing as a consultant and appraiser
It is interesting to note here that many, if not all, pairs of consultant and appraiser are actually good for nothing.

It is, therefore, very important for an organization to thoroughly evaluate the competency of the consultant and appraiser they are hiring.

You are paying them to be a part of the solution and not to just give you some kind of gyan.

You have to set the context and clear the situation by calling a spade as a spade.

You are paying them.

So you better ask them to listen to you.

You have to manage and drive them.

What if they refuse to get the signal?

There is a very simple answer to that.

Change your consultant and appraiser next time around.

They should not become like a millstone around you neck.

They better add value.

Or you kick them out.

So if there is no value from a consultant and appraiser then there is absolutely no need of such a consultant and appraiser.

Process Definition Continuum

An earlier post on this blog titled Process Tailoring, Process Deviation, Process Exception, Approval and Waiver dwelt upon concepts such as tailoring, deviation, exception, approval and waiver in relation to the defined process that gets used for performing any work.

In light of that, it can very well be said that process definition in the real sense happens over a wide continuum starting from standard process getting used to a situation of "no process".

As an aside, an important one though, it needs to be clearly understood that "no process" does not mean no process is being used but that their is no agreed/common/consistent process in place that is getting used.
  • Everyone is on their own and supposed to deliver their piece
  • Work would seemingly happen but their is no assurance about what exactly will be coming out of that work at the end of it, if the work even reaches its end ever!
  • There will be a lot of friction between the manager and the team, between the team members and between various sub-teams engaged in that work
  • There will rise out of the ashes some "heroes" who may happen to save the day, but only in certain instances and that too after they and the others would have undergone severe burn-out
Clear understanding of the continuum concept is necessary to ensure a systematic and structured approach is firmly put in place while following the standard processes or the variations thereof.

The continuum view of process definition also implies that the process definition that is finally put into use is the one that happens at the granular level.

The granular level process would get captured as part of the project management plan, service delivery plan, product management plan, etc.

And even if localized processes are used or the "no process" type of process is used, there is still an overall governance layer to take care of deviations as also the exceptions.

The big thought here is that there is a well-defined process in place for handling any situation, including that of the situation of "no process" too!

The following figure presents the process definition continuum illustrating the different levels at which process definition at the project plan level would typically play out.

Here are the four levels in which the process definition continuum can be categorized into.

ORGANIZATION’S STANDARD PROCESS
  • Ideally speaking, standard process should be followed by every project.
  • This will enable meaningful comparison of performance across different projects in the organization.
PROCESS TAILORING
  • There are situations, where a project would require that it be allowed specified variation over the standard process without the need for any approval.
  • Such variations should get included in the tailoring guidelines and govern any process tailoring.
PROCESS DEVIATION
  • Then there are situations, which should be infrequent, where a project would follow an applicable process but in a manner that is different than the standard process as well as the tailoring guidelines.
  • Such case-specific process deviation should get approved and waived-off by the topmost authorities accountable for process and delivery outcomes of the organization.
PROCESS EXCEPTION
  • And lastly, there are situations, which should ideally be rare, where a project would work with no basis in standard process, process tailoring or process deviation. 
  • Such process exception (either to few or all applicable processes) should get approved and waived-off by the topmost authority accountable for business outcomes of the organization. 

Data Privacy and Information Security - How are they different and how are they same?

Data privacy has become a commonly used term in the industry now.

Though this term has been around for several decades, the introduction of the GDPR law in the EU on 25th of May 2018 has brought this into the mainstream.

In any case, data breaches are dreaded by the information security folks.

These folks are essentially cyber warriors who take care of two crucial things for any organization:
  • protect the organization's information from getting into wrong hands.
  • secure the organization's IT assets from getting hijacked or compromised by other cyber warriors.
Data privacy adds a new twist to the already existing tale.

It actually makes it much more serious by bringing legal angle into the already complicated cyber security equation.

Data breach is a serious thing.

And if the data breach involves personal data of living individuals the seriousness gets compounded by a significant degree.

Data breach involving data privacy doesn't remain just a security breach but becomes a legal violation.

That's the reason for the increased focus on data privacy in the organizations in the business world as well as in other organizations that handle personal data.

It is important to note that the administrative fines and compensation for damages may have significant material impact both in financial terms as well on the organization's brand equity.

How are privacy and security different?

Here are some of the aspects where they are different like chalk and cheese:
  • Privacy is important when the data is personal in nature, whereas security is important with any data.
  • Privacy breaches would directly amount to legal violations, whereas security breaches may or may not amount to legal violations.
  • Privacy is concerned not just with securing the personal data but also adherence to the generally accepted privacy principles (GAPP) whereas security is concerned just with securing the data.
How are privacy and security same?

Well, they are not exactly same, speaking in a strict technical sense. They are however strongly linked.

Here are some of the aspects where they are linked with each other:
  • Privacy breaches in many instances would generally get reported as a security breach first where subsequent investigation may turn it into a privacy breach also should any personal data found to have been involved.
  • Privacy cannot be ensured and assured unless security is taken care of as the basic building block over which privacy would get built (security for privacy).
  • Privacy would mostly rely upon the technical controls implemented as part of information security to take care of adequate technical measures required for ensuring privacy.
Data privacy and information security are actually comrade in arms.

Improving one would make the other better.

However, security has to be seen as a more fundamental thing as compared to privacy.

For any organization, the first step in strengthening its cyber defense systems should start with information security measures.

The next step would be to go with data privacy measures.

Regular reviews, audits and technical assessments of information security and data privacy in an organization has become a sine-qua-non in the present context.

In summary, it can very well be said that security first, privacy next and after that both together forever and ever.

Data Privacy Regulations - Some Key Practices

Given that there is no escaping from data privacy regulations it is important to understand some of the key practices that an organization should implement.

Following list provides some of the key data privacy practices that an organization needs to put in place and in practice to ensure compliance with data privacy regulations:

Identification of operational/functional business units in the organization that need to be made owners of data privacy compliance
  • Since activities of each and every employee should be covered under data privacy regulation, at times, logical entities may have to be identified and treated as operational/functional business units so that all employees are brought under the purview of data privacy regulation.
Identification of business processes in different business units that handle personal data
  • This is a crucial step in ensuring no business process gets missed out, even by chance.
  • The owner of the respective business units need to be made accountable to ensure that all relevant business processes in that area get identified
Identification of personal data in the applicable business processes
  • Even if there is one element of personal data involved, data privacy regulations apply and need to be taken care of adequately and appropriately.
  • Identification of personal data being handled across the multitude of processes and transactions across the various business units in an organization is the most important and crucial step in ensuring 100% compliance to data privacy laws.
  • The key outcome in this case is the setting up of a personally identifiable information inventory (PII inventory).
Handing of personal data across the entire life-cycle of a data element
  • Data collection
  • Data storage
  • Data access or view
  • Data processing which involves active use of data for agreed, declared and specific purposes
  • Data transfer including cross-border
  • Data deletion, archival, de-identification
Retention strategy for personal data
  • How long to retain the data for active use? The duration of retention should be in consonance with both the purpose for which that data was collected and the fact that minimum necessary data should only get collected.
  • What to do at the end of retention period? This includes clarity whether data would need to be deleted or whether data would be de-identified or masked and kept for a longer duration.
  • How to ensure data is not stored in any media beyond the specified retention period? Clarity with respect to where all a certain personal data would get stored in the PII inventory would greatly facilitate this.
Determination and declaration of basis of processing data that makes it lawful
  • The best thing is to obtain data subject consent or have a contract that would govern the processing of personal data.
  • If not, legitimate interest analysis needs to be performed. This is a risky option to choose and needs to be well supported by a strong and logically formulated business rationale.
  • For any business organization, typically the public interest and vital interest would not be a valid basis in most situations.
Risk assessment around data privacy
  • The first step here is to do screening
  • And as as needed perform detailed data privacy impact analysis (DPIA) and identify risks and mitigating controls and actions that would be required.

Personal Data Privacy Regulations - Some Interesting Corollaries

Since May 2018 when EU GDPR came into force, privacy and protection of personal data and information has become a critical compliance requirement for organizations.

It is important to note here that privacy laws are applicable to all organizations, whether private, public or government and whether business or others.

Any organization that handles personal data needs to ensure their data privacy practices are in consonance with and in full compliance to the data privacy regulations.

The above statement leads to some direct and interesting corollaries.

Corollary 1 - Data privacy must be a matter of grave concern for every living person in the world.
  • Data privacy laws consider natural living persons as data subjects.
  • Speaking differently, you are a data subject and so is every one else.
  • You are a data subject much before you are the owner or employee of an organization and in that capacity expected to protect the organization's interest..
  • Violation of data privacy laws by organizations impinge directly upon your civil rights as a data subject.
  • You are the rightful owner of your personal data and should have complete say on anything related to it except for matters pertaining to national security, public safety and law enforcement.
  • The "Digital Parasites" in the digital economy like Facebook, et al if not tethered would continue to devour your personal data to mint money.
  • The digital economy will continue to grow and become bigger with newer "Digital Parasites" coming into existence as time unfolds.
  • Hence data privacy must be a matter of grave concern for every living person in the world.
Corollary 2 - Data privacy regulations are applicable to each and every organization.
  • Any organization will have employees at the very least.
  • By definition, every employee is a data subject (in GDPR) or a data principal (in the proposed Indian Data Protection Act). 
  • Hence data privacy regulations are applicable to each and every organization.
Corollary 3 - Every employee must ensure individual-level compliance with data privacy regulations.
  • Any employee will come across personal information of some of the other employees or other persons outside that organization in some or the other manner in the course of fulfilling work responsibilities.
  • By definition, when an employee is handling personal information as part of work responsibilities, the organization, effectively speaking, acts either in the capacity of a data controller (or data fiduciary) or a data processor.
  • Hence every employee must ensure individual-level compliance with data privacy regulations.
Corollary 4 - Even one bit of personal data must be viewed as one too many. 
  • Every bit of personal data that is handled by an organization needs to adhere to the data privacy principles:
    • Lawfulness, Fairness and Transparency
    • Purpose Limitation
    • Data Minimization
    • Storage Limitation
    • Accuracy
    • Confidentiality and Integrity
  • The above data privacy principles have to be individually and independently applied to each and every bit of personal data handled by an organization.
  • Hence even one bit of personal data must be viewed as one too many.
Corollary 5 - Every organization must appoint a DPO (data protection officer) with direct reporting into the Board of Directors to drive enterprise-level compliance.
  • Since even one bit of personal data is one too many, every organization must ensure enterprise-level compliance.
  • Any organization that wants to live to see tomorrow must secure and protect every bit of personal data it comes across.
  • Violations by an organization can lead to abrupt cessation of its operations or even a quick end to it's very existence like what happened in the Cambridge Analytica case.
  • For ensuring business continuity on data privacy front and  to avoid going the Cambridge Analytica way, organizations must appoint an executive-level officer to drive enterprise-level compliance and advise the Board of Directors on data privacy matters.
  • The executive-level officer can report into the Chairman/CEO also but should certainly have direct reporting into the Board of Directors too.
  • Hence every organization must appoint a DPO (data protection officer) with direct reporting into the Board of Directors to drive enterprise-level compliance.
In the end, and just to summarize, organizations must carefully watch out for the following business-critical aspects:
  • Given that data privacy is a given now, organizations must take care of the above corollaries that provide the broad guiding principles to appreciate the usefulness of data privacy regulations as well as key enablers to ensure compliance.
  • The executive-level management must be genuinely committed to ensuring the  privacy and protection of personal data and information handled by the organization.
  • The tendency to find short-cuts in implementing data privacy practices in the name of cost to compliance should be strictly avoided.
  • Comprehensive records of PII (personally identifiable information) processing activities must be maintained diligently to avoid any possibility of litigation risks to the organization.
If only someone had advised on the above business-critical aspects to the Board of Directors and Chairman/CEO of Cambridge Analytica in good time!

Handling Change in the Lead Auditor

Any change in the lead auditor would result in changes related to the level of compliance expected from an organization's systems and processes.

At times the question is not just the level of compliance but the appropriateness of the manner in which compliance was being demonstrated by an organization till the point of change in the lead auditor.

Every person is different in terms of his or her viewpoint, outlook, perspective, understanding, expectations and articulation.

Auditors are no different on the above account.

With auditors the above aspect is compounded manifold due to the fact that they have extensive experience of seeing varied implementations of the standards for which conduct audits.

And when you are a lead auditor, you would tend to acquire an attitude also.

An attitude of "having seen it all and done it all".

Such an attitude will generally result in the person becoming rigid in terms of how easily and quickly he or she would want to understand and adopt alternative thought processes.

So if you are the one who is supposed to handle change in the lead auditor as the program lead for certification in your organization how should you go about it?

How do you handle change in the lead auditor?

Here are few points you should consider:
  • Initiate discussion with the lead auditor to get introduced to him or her and also to understand the kind of person you will be dealing with
  • Provide a broad overview of your organization's business context as well as salient aspects of the approach used for implementation of systems and processes in your organization
  • Share any challenge or peculiarity in your compliance set-up. For example:
    • You may  have a small remote site office 
      • that doesn't have many of the standard controls and practises that are there in the main office (like there is no dedicated security staff  but a shared one).
      • that doesn't have the usual support system from functional point of view (like there may be no team at that site to take care of process and compliance and such support is provided remotely by the team at the main office which may not really be that effective).
    • Certain part of the business is outside the ambit of compliance requirements (which in turn would be a deciding factor for the scope of audit).
    • Non-standard organization structure where the MR may not report into the CEO or the MD but someone lower down in the hierarchy (and this person would usually will not have the required competency for that position and is simply there due to his blind loyalty towards the master!).
    • Other certifications the organization has that would support or/and strengthen the implementation of the standard for which the lead auditor will conduct audits.
  • Organize a pre-audit or gap assessment by the lead auditor. This would help in following major ways:
    • Better understand the auditor as a person so as to know his or her expectations as well as any idiosyncrasies that you will need to manage.
    • Give the auditor chance to raise any fundamental issues upfront so that such issues won't come up later during the final audit which is a serious affair.
    • Use the pre-audit as an opportunity to ensure the auditor fully understands your business context and is fully made aware of any challenges and constraints the organization is facing that would bear upon process and compliance in the organization.
  • Close the observations and suggestions from the pre-audit before the final audit happens
    • This may sound simple but is an extremely fine point to be duly taken care of as the closure has to be exactly in line with the new lead auditor's expectations and not how they used to be closed with the earlier lead auditor around.
    • Even if all points do not get closed it is important the organization is able to demonstrate the seriousness of their intent and the fact that the extent of progress made was reasonable given the time available after the pre-audit and before the final audit.
  • Get ready for show time
    • Yes plan for, prepare for and get the final audit conducted.
    • Hope for the best.
    • But most importantly, expect the best if you indeed did manage the change in the lead auditor well!

How to Plan and Conduct a Gap Analysis Exercise?

In case an organization wants to implement a framework or a methodology, either at the enterprise-level or in a large part of its business, it must use gap analysis as the first step in its journey.

Gap analysis is a very useful mechanism that can make an organizational initiative if done well and mar it if done otherwise.

Gap analysis is conceptually like an audit or assessment where the objective is to determine the difference between the "To Be" state versus the "As Is" state.

Planning and conducting a gap analysis exercise requires consideration of several key aspects.

Some such aspects are explained below.

Pre-Gap Analysis
  • The first and foremost and the most important step in any organizational initiative is to designate a senior person as the leader of the initiative
    • The appointed person should be selected based on the competency and fitment requirements and loyalty should not have any role to play in that
    • The appointed person should be duly empowered, and his accountability should be backed up with adequate level of authority
    • In some organizations, initiatives are started to give "some job" to some "special folks who have nothing to do" in the real sense, such people can't be fired and are also not adding much value but someone senior enough likes them (no need to ask what for?) and unless that is the situation the leader should have no reason to worry!
  • The second thing is to build the required level of awareness and understanding among the leader, the second line and those who will be part of the primary task force as well the POCs from various departments

Planning Gap Analysis
  • Then comes the road map and the plan
    • Once the road map is in place it is important to know where the organization stands
    • Basically answer the question - "where do we stand today?"
  • That requires conducting gap analysis exercise
  • Planning for gap analysis requires clarity on several aspects such as:
    • Scope of business operations that are impacted by the initiative
    • Good idea about which entities to involve in the initiative
    • Expected or desired timeline
    • Assessment and selection of appropriate external agency (if engaging one of them is needed)
    • Budget at hand
    • Organizational structure and internal dynamics.

Conducting Gap Analysis
  • First step in this involves communicating the gap analysis purpose and schedule to the impacted stakeholders
  • Doing a kick-off meeting is generally recommended as it helps both in building wider visibility about the initiative in the organization as well as helps in sharing crucial details related to the gap analysis with the impacted stakeholders
  • At the very start of the gap analysis, the leader should clearly state the expectations from the initiative as well as ensure all support elements are well in place 
  • Gap analysis if planned well and scheduled well should generally run through smoothly
  • There might be some "funny" stakeholders in the organization who may want special treatment or considerations and that should be dealt with firmly and quickly
    • Letting such stakeholders dictate terms may derail the plan as well as trivialize the entire initiative
  • For coordinating the conduct of gap analysis the leader should appoint someone to take care of the logistics and operational aspects
    • Someone who is good with people handling and schedule management is generally a good choice for this job
    •  Someone who has been in the role of audit coordinator or site coordinator in external audits and has done a great job there would be the perfect choice
  • The leader should keep an eye on how the gap analysis exercise is progressing both in terms of the schedule as well as the quality of the technical results
    • The gap analysis should uncover salient points of difference between the "To Be" and "As Is" states so as to effectively guide the next leg of the initiative
    • The findings should be captured clearly and documented in much detail so that recommendations can easily follow from them
  • The last but one part of gap analysis involves preparing the final findings report and sharing with key stakeholders.
  •  And the last part of gap analysis is the draw up the recommended actions.

Post-Gap Analysis

After the gap analysis findings and recommended actions are made available to the organization, the leader of the initiative should get down to defining the detailed action plan.

The detailed action plan should clearly state who will do what and by when.

No ambiguities there.

This should then end logically with the dates for follow-up discussions for gap closure verification and the final closure of the gaps.

And if things go all well the "To Be" will eventually become "As Is".

When that happens, the gap analysis did serve its purpose.

And the gap analysis exercise can be termed as successful

Job done and mission accomplished.

Compliance of Business is Good for Business of Compliance but Great for the Society

These days business enterprises are supposed to ensure their compliance to various laws and regulations.

Over time, the list of such laws and regulations has kept on growing in size.

A very recent example being Data Privacy Laws.

On 28th May 2018, in the European Union, EU GDPR, a reformed legislation on Data Privacy came into effect which lays down rules for the protection of personal data of EU residents both inside and outside the EU.
On 27th Jul 2018, in India, the Government released Justice BN Srikrishna Committee of Experts Report on Data Protection as well as a Personal Data Protection Bill, 2018.
One important point that emerges when such a thing happens is that the compliance of business results in a positive impact on the business of compliance.

The business of compliance is a lucrative one.

Whenever a new act of law or legislation comes into force, it acts as a force multiplier for those in the business of compliance.

The advisers, consultants, auditors, lawyers and other experts find that there is sudden surge in their demand.

Obviously, increased demand means increased earning potential.

The business of compliance loves changes in the landscape constituting the compliance of business.

New laws, new regulations, new legislation are all good news.

Compliance of business is good for business.

For the organizations, however, this increases the cost of compliance and hence the eventual cost of doing business.

Which is eventually passed to the buyers and the consumers.

This is all fine because many of the new laws, new regulations, new legislation arise due to the ever evolving needs of the society, the buyers and the consumers and also several other stakeholders.

Governments and legislators read the signals and legislate new rules and regulations to keep pace with ever evolving needs of the society, the buyers and the consumers and also other stakeholders.

In summary, it can very well be said that compliance of business is good for business of compliance but great for the society.

Handling an Egotist Auditor

The term egotist auditor can not be viewed as an oxymoron.

An auditor cannot but be an egotist.

And like any egotist will do, any auditor doesn't like to be challenged.

If you challenge an egotist he will dig his heels deeper.

He will be more adamant.

Also, like any egotist will do, any auditor would demand to be respected by those that are audited.

Auditors may have richer experience due to the fact that they visit different set-ups but then the other fact is also there that the concepts and basic principles remain same whichever organization it might be.

Auditors need to justify their worth.

So if they fail to find any gaps in an audit it, in their view. might reflect poorly upon their competency.

So at times they end up highlighting issues which may really be non-issues.

Some examples:
  • Something was missed five years back but after that that process continued to be followed. Is such a gap worth highlighting? Ideally, no. But auditors may take vicarious pleasure in doing so. And what action would be required to close this issue? Nothing, since its already happening.
  • The reference model or standard may not require it but the auditor may have his quirks and idiosyncrasies and demand certain things to be done for reasons best known to him. How can a "good to do" thing be a requirement? It can't be and shouldn't be but an egotist would not care to bother.
  • The auditor would raise illogical, unnecessary and meaningless findings that would be technically feasible and would need to be logically closed by saying this was analyzed and found to be technically not feasible. If that point is brought up to the auditor's notice he would refuse to even have a discussion on it. He might say, "is it urgent"and sweep the need for a discussion under the carpet. Or say "leave that to me". Basically wherever he is on weak ground he will refuse to listen. 
The above examples show what kind of idiotic things can happen when you have to handle an egotist auditor.

What else can be expected from an egotist?

Anyone full of lot of conceit and needlessly high sense of self-importance would do precisely that.

Also, such an auditor may take affront for trivial reasons.

This shows the fact that the egotist auditor has a short fuse which is always in a ready state to blow up.

The slightest of challenge or provocation can result in the auditor loosing his cool.

He may throw unnecessary tantrums too.

An auditee may fall sick and there's not much that can be done to help that.

Why, even the auditor may also fall sick.

If someone is not available for medical emergency, the audit process should have provision to handle such a situation.

So how to handle an egotist auditor?

This involves a very simple trick.

Pamper his ego. Keep him in good humour. Tolerate his tantrums.

Showing respect (fake or otherwise) for the ego of an egotist is all that is needed.

That's all. Nothing beyond that.

How to Handle a Bad Ass Auditor?

Before getting to the question "how to handle a bad ass auditor" it is useful to first understand what a bad ass auditor is.

So what a bad ass auditor is?

A bad ass auditor typically exhibits the following characteristics:
  • He is close to the top man in the organization and his cotrerie and is more like a friend who will oblige, eventually.
  • He is not really that competent in the subject matter but has this great (but unfortunately, totally false) impression going for him that "he is highly knowledgeable".
  • His knowledge is very shallow and at times totally wrong. However, in case he is challenged he immediately and visibly gets very upset.
  • He is very polished in his interactions but carries a jumbo-sized ego behind the facade of professionalism. When push comes to shove he shows his true colours.
  • He shows that he is very principled and highly ethical but scratch the surface a little bit and the underlying layer which is dark and dirty comes out into the open.
  • He has preconceived and cliched views on most of the concepts and doesn't deviate from them even when the situations would demand so.
  • He is generally incompetent but adopts a formulaic approach to talk about things and to get things done and thus create the impression that he is not incompetent.
So how to handle such a bad ass auditor?

Here are some tricks that can be considered.

However, remember the bad ass auditor has a big, jumbo-sized ego.

So the exact trick for handling him will have be to gradually evolved through several hits and trials.
  • Massage his ego, praise his knowledge and understanding of the formulaic things he speaks about, Some of those things will be completely incorrect and nonsensical but as long as he sticks to the formula it is perfectly fine.
  • Confront him in case he speaks something totally incorrect on anything outside the formulaic things he generally talks about. Though that will hurt his ego, there is a possibility he will be careful when speaking about new things and stick to his formula. Such occasions also bring forth his incompetence but never highlight that too much.
  • See if you can discuss about some of these aspects with the top man in the organization  and his coterie. This may as well back-fire because the bad ass auditor takes care to create great impression about himself with these folks. That's why he is bad ass and not only that the top man and his coterie in such organizations are also bad ass at some level. The simple corollary being, a bad ass will always like another!

Why Compliance to Laid Down Processes is So Very Important?

The ISO standards are supposedly famous for the following quote:

"Say/write precisely what you will do and do exactly as what you said/wrote you will"


Two words from the above are worth looking into at a more granular level.

Precise and Exact.

So what do they mean?

Precise (Reference: http://www.dictionary.com/browse/precise)

adjective
1. definitely or strictly stated, defined, or fixed: precise directions.
2. being exactly that and neither more nor less: a precise temperature; a precise amount. 
3. being just that and no other: the precise dress she had wanted.
4. definite or exact in statement, as a person.
5. carefully distinct: precise articulation.
6. exact in measuring, recording, etc.: a precise instrument.
7. excessively or rigidly particular: precise observance of regulations; precise grooming.


adjective
1. strictly accurate or correct: an exact likeness; an exact description.
2. precise, as opposed to approximate: the exact sum; the exact date.
3. admitting of no deviation, as laws or discipline; strict or rigorous.
4. capable of the greatest precision: exact instruments.
5. characterized by or using strict accuracy: an exact thinker.

Going through the details of the dictionary meanings of the two key words makes it amply clear as to why the statement "Say/write precisely what you will do and do exactly as what you said/wrote you will" is so very logical and so very sensible.

Think about it this way.

If you want things to happen in a certain way, every time it is done, what is the best way to ensure it happens with the same consistency.

The best bet is - define precisely how things have to happen and ask for things to be done exactly as it has been defined.

That will certainly ensure the certainty of the outcome, come what may.

Remember the following quote:

"Insanity is doing the same thing over and over again, but expecting different results."

It can very well be rephrased as:

"It is perfectly sane and sensible to do the same thing over and over again, and not only expect but indeed obtain results that are no different"

The above also reflects the power of using a systems-driven and process-oriented approach.

At this point, based on the above, it should be obviously clear why compliance to laid down processes is so very important.

That would ensure the following: 
  • There is certainty of outcome at the end of the whole thing. 
    • Not only that, it is also clear as to what should come out at each intermediate step. 
    • This will result in consistency and certainly of deliverable(s) produced by the process.
  • The steps including their sequence that needs to be followed while performing an activity are precisely known.
    • Not only that, they can be easily traced back to the defined process. 
    • This will ensure high level of process compliance.
  • It is clear as to what steps should have been taken and what were, so the gaps, if any, that need to be taken care of, are obvious. 
    • This will facilitate quick and objective process assessments or audits.
For the discussion so far in this post, it is assumed that there is no challenge in respect of the correctness/accuracy of the defined process.

That is really not true and will be dwelt upon in detail in another post.

At this point, however, it is not hard to see that as the process is precisely laid down and exactly adhered to, changes/improvements that need to happen to the process will be obviously easy to determine.

That  will eventually aid in continual improvement to the process.

Note:

The quote "Insanity is doing the same thing over and over again, but expecting different results." is generally attributed to Albert Einstein but apparently he said none of it.

Rita Mae Brown, the mystery novelist in her 1983 book "Sudden Death", attributes the above quote to a fictional "Jane Fulton," writing, "Unfortunately, Susan didn't remember what Jane Fulton once said. 'Insanity is doing the same thing over and over again, but expecting different results.'"

Selecting Internal Auditors for Internal Audits

Selecting internal auditors for performing internal audits needs to be done with a lot of due diligence and a lot of care.

It is a fact that many a times you have to make someone an internal auditor for reasons that have nothing to do with the person's competency.

When someone incompetent is imposed on a department from above because he is a pet stooge of the top dog, he or she needs to be made an internal auditor.

The stooge being a part of the auditors pool will ensure the top dog doesn't get the chance to say that "we don't have good auditors".

After all his pet stooge is a part of the auditors pool.

What kind of people should not be made auditors?

The above is a good question so that the "bad particles" are filtered out.

This filtering doesn't apply to the stooges though.

Avoiding following types of people when selecting internal auditors will go a long way in  making the audit process professional and objective:
  • Avoid people who don't come on time but expect others to be there when they come in
  • Avoid people who create nuisance before and after the audit
  • Avoid people who come with preconceived biases
  • Avoid people who carry a condescending attitude towards other auditors and auditees 
  • Avoid people who don't prepare and share auditor notes promptly
  • Avoid people who have serious behavioural issues
  • Avoid people who lack motivation and energy to act as auditors
In addition to that, it is a good idea to know which auditors should be allocated for auditing which areas and which not.

Like the pet stooges are unfit to be selected as an auditor for several areas. 

It is better to assign them to audit areas that are manned by other pet stooges.

The audits done by the pet stooges will not be effective as the stooges are the insiders and will not want to bring up anything that the peer stooge doesn't want to be highlighted.

Internal audits can go a long way in helping a professional organization introspect and improve on its internal processes and practices.

In case an organization has too many people who are not fit to be auditors, especially at senior levels when they are expected to be mature and sound, it is clear warning sign.

There are undoubtedly deep-rooted cultural issues in such companies.

They are everything but professional.

They are actually "Lala" set-ups!

If the top man in such organization is not aware of this then he is totally incompetent and if he knows but doesn't care he is a partner in crime.

He is perhaps the biggest Lala of all. The king of Lalas.

His pet stooges being the other Lalas.

In fact, he would the prime suspect for things to have reached such a state.

After all, everything that has happened or is happening is under this man's watch.

If that be so, doing internal audits and findings internal auditors will remain a vexing challenge in such organizations.

In case you happen to be the unfortunate one who is supposed to take care of internal audits in such an organization be prepared to handle shit.

Get ready for a ride in the hell!

And yes, tighten your seat belt.

Adding a New Office/Location to Your Scope of Certification - Important Things to Do to Get Started

For any organization, business growth may mean opening up of new offices at new locations.

Adding a new office/location presents its own unique set of logistics and people challenges.

Beyond that and generally very soon the organization will reach a situation where it will have to add the new office/location to its scope of certification - ISO, CMMI, et al.

So what are the important things to do to get started for an organization that wants to add a new office/location to its current scope of certification?

Here are some important things to do to get started:
  • Share the communication related to this with concerned stakeholders both at the corporate office as well as the new office/location 
  • Discuss with the auditing partners and understand their expectations for successful audit at the new office/location 
  • Assign someone as the overall SPOC for this initiative. The SPOC should have good knowledge of the certification standards and models and past experience with site coordination in external audits 
  • Perform quick gap analysis to understand the major gaps and the key pre-requisites and pre-conditions for successful audit 
  • Prepare a detailed road-map (who will do what by when) and share with the concerned stakeholders both at the corporate office as well as the new office/location 
  • Perform detailed gap analysis and prepare a list of checkpoints that need to be taken care of. This should be done by the SPOC 
  • Plan for pre-audit by external auditors at the new office/location before the final audit. It is an effective way to avoid any surprises cropping up in the final audit 
  • Identify and communicate the risks and challenges to the concerned to ensure that the entire journey is smooth and happens as per the road-map 
  • Adjust and modify the road-map to address issues and challenges that come up during the entire journey 
  • Stick to the road-map but be flexible to change the course if the situation demands so. But never forget the milestones in the journey that have hard dates!

Why the Job of an Auditor is a Difficult One?

Auditors work in a very, very difficult job.

If they are tough on the organization and "go by the letter" of the standard or model they are auditing against, no organization would ever get certified.

So they "go by the spirit" of the standard or model they are auditing against, and every organization that applies for it gets certified!

That's a very difficult task to perform.

An auditor has to be both tough and flexible at the same time.

Very hard to do in a normal situation, for anyone.

The other aspect to consider is that the organization applying for the certification is supposed to pay for the expense involved.

The expenses incurred in the certification process forms the revenue for the auditing organization and which organization in its right mind will even think of cutting the revenue stream?

So the auditing organizations usually have an unwritten rule for their auditors - act smart!

And the auditors indeed do so.

Auditors are trained to come across as hard-nosed and raise hell while they are auditing an organization but write a soft report at the end of it.

Things cannot be any other way.

Auditors need to make their intellectual presence felt while doing audits and most of them, invariably, are highly intelligent and smart individuals and can easily do so.

However, auditors are bound by business logic too.

They have to look other way while writing the formal audit report and most of them, invariably, are highly intelligent and smart individuals and can easily do that as well.

But one thing is sure. Auditors are smart folks.

Whatever they may do, they very well understand what's really going on in the organization they audit.

They may choose not to say certain things but that is not because they are incompetent but they choose not to say that.

Also, they may choose not to write certain things but that doesn't mean they can't.

Audits and Project Success

Project success depends on several mechanisms which form part of the overall governance framework.

The mechanisms include management reviews like proposal reviews, project status reviews, program status reviews, top management reviews and process audits.

In addition to the above management reviews, there needs to be rigorous technical reviews of requirements, design, implementation, verification & validation, delivery and installation.

Audits are but one of the several mechanisms for an organization to make sure things go right. Some organizations think that audits can solve all their problems.

Its like thinking that more testing will help improve product quality.

However, the focus should be on improving how things get done right the first time rather than how to better find whether they got done right.

In the case of software, quality of the software depends on the quality of the code and not how well it got tested.

Testing cannot inject quality it can only enable quality by identifying issues and defects before it gets shipped to the customer.

It would, in fact, add to the eventual cost of the software and someone has to pay for it.

Trend of CMMI High Maturity Appraisals

An earlier post on CMMI high maturity titled "Is Achieving CMMI High Maturity Tougher Now?" explored the trend of CMMI high maturity appraisals.

Earlier Analysis of Trend of CMMI High Maturity Appraisals

This trend analysis clearly indicated towards a decline in the number of organizations that were appraised at CMMI high maturity (maturity level 4 and 5) as a percentage of all organizations that were appraised either at maturity level upto 3 (maturity level 1 through 3) or CMMI high maturity (maturity level 4 and 5).

The above analysis was performed using data published by SEI in the CMMI Process Maturity Profile reports starting 2005-Mar through 2009-Sep. Three years have passed since then and it would be of interest to note how this trend looks like at this point in time. For understanding the trend from the very beginning, data right from 2004-Mar till 2012-Mar has been included.

CMMI Appraised Organizations - Upto ML3 & High Maturity

First the comparison of high maturity (maturity level 4 and 5) versus upto maturity level 3(level 1 through 3) was performed to determine change in the trend, if any. The percentage of high maturity organizations seems to have stabilized in single digit close to 8% to 10%. 







CMMI Appraised Organizations - ML1 through ML5

The comparison of organizations appraised at various maturity levels (level 1 through level 5) was also performed to understand the overall trend. Some key signals that emerge from this analysis are as follows:
  • Percentage of maturity level 2 organizations has remained at around 25%
  • Percentage of maturity level 3 organizations has increased significantly from around 30% to 65%
  • Percentage of maturity level 4 organizations has declined marginally from around 5% to 2%
  • Percentage of maturity level 5 organizations has declined significantly from around 30% to 5% 




Some Indicators from the Trend Analysis

The above analysis provides some indicators in respect of the CMMI appraised organizations. Some of these indicators are listed below:
  • It appears logical and cost-effective to implement and get appraised at maturity level 2 and 3 in one step and then level 4 and 5 in another step
  • Maturity level 3 has come to be viewed as a milestone on the way to level 5 where an organization would like to pause and consolidate the gains before moving on towards level 5
  • The higher density at maturity level 3 is a reflection of the fact that even if an organizations stays at maturity level 3 and continuously strengthens practices the business gains can be huge
  • Attaining level 5 has indeed become tough which points towards increased expectations from level 5 organizations and higher rigor called for in SCAMPI appraisals
  • Maturity level 5 has truly become a point of differentiation now and the business gains that can accrue to an organization can be phenomenal provided the level 5 practices are internalized into the organization's culture and becomes an integral part of its DNA
Note: “Process Maturity Profile by All Reporting Organizations” which provides the “%CMMI Appraised Organizations” against the 5 maturity levels and also for cases where no maturity ratings were given have been considered.