{"id":5174,"date":"2015-04-07T10:47:58","date_gmt":"2015-04-07T15:47:58","guid":{"rendered":"http:\/\/www.oxebridge.com\/emma\/?p=5174"},"modified":"2015-11-18T09:40:11","modified_gmt":"2015-11-18T14:40:11","slug":"the-meme-is-set-risk-based-thinking-risk-management-no-matter-what-tc-176-says","status":"publish","type":"post","link":"https:\/\/www.oxebridge.com\/emma\/the-meme-is-set-risk-based-thinking-risk-management-no-matter-what-tc-176-says\/","title":{"rendered":"The Meme is Set: Risk-Based Thinking = Risk Management No Matter What TC 176 Says"},"content":{"rendered":"<p>The so-called professionals are declaring that the upcoming ISO 9001 revision&#8217;s New Age, beaded-curtain fabrication called &#8220;risk based thinking&#8221; is actually full-blown risk management, even as TC 176 scrambles to get them to stop saying this.<\/p>\n<p>RBT was invented as a concession to the ISO Technical Management Board which demanded the new 9001:2015 standard include some form of risk, whether TC 176 wanted it or not. In order to comply, the TC invented a thing calledf &#8220;risk based thinking&#8221; which simultaneously satisfied the TMB, while trying to address previous weaknesses in the language on preventive action. (For a more detailed\u00a0primer on the origin of &#8220;RBT&#8221; click <a href=\"http:\/\/www.oxebridge.com\/emma\/timeline-the-origin-of-iso-9001s-risk-based-thinking\/\" target=\"_blank\">here<\/a>. ) RBT has never before existed in any risk management profession or body of knowledge, and has been derided by many professional, published risk management experts as a complete joke.<\/p>\n<p>The intent was to create &#8220;risk lite,&#8221; something flexible enough to fit a giant global corporation that might implement ERM (enterprise risk management) along the lines of COSO or some other established standard, as well as the tiny 5-man machine shop that might not have ever heard the word &#8220;risk&#8221; before. It was an admirable goal, but the execution has proven disastrous.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignright wp-image-5182 size-full\" style=\"margin-left: 14px;\" src=\"http:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2015\/04\/footbridge2.jpg\" alt=\"footbridge2\" width=\"251\" height=\"251\" srcset=\"https:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2015\/04\/footbridge2.jpg 251w, https:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2015\/04\/footbridge2-150x150.jpg 150w, https:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2015\/04\/footbridge2-45x45.jpg 45w\" sizes=\"(max-width: 251px) 100vw, 251px\" \/>TC 176 attempted to clear up their scented candle, Om-gong meditative process by publishing a few <a href=\"https:\/\/www.standard.no\/Global\/PDF\/Kvalitet\/ISO-TC176-SC2_N1222_N1222_-_Risk_in_ISO_9001_2014-07.pdf\" target=\"_blank\">official documents<\/a> on RBT, and openly stating that no, risk based thinking did not require full blown risk management. But the result comes off as a manifesto written by a stoned 60&#8217;s hippie, which probably made sense to the author, but which doesn&#8217;t quite work to anyone in the sober world. Their reliance on inane &#8220;real-world&#8221; metaphors (that goddamn\u00a0footbridge story insults the entire planet&#8217;s intelligence in one swipe) and lack of firm requirements has left RBT an open vessel, ready to be filled by whatever crap the usual suspects can spew.<\/p>\n<p>And spew they have.<\/p>\n<p><strong>Release the Hounds<\/strong><\/p>\n<p>Larry Whittington recently published a newsletter on RBT in which he, too, declares RBT is risk management, and then goes on to define the standard FMEA-style of risk assessments that requires one to assign a likelihood factor and multiply it by a consequence factor, to come up with a magical number that will solve all your problems. Nowhere does Whittington clarify that this is just his opinion on how to approach RBT, nor that it contradicts what TC 176 has said about it. A casual reader will understand this as a <strong><em>requirement<\/em><\/strong>, in fact. Of course, he&#8217;s selling courses on this approach, complete with <a href=\"http:\/\/www.whittingtonassociates.com\/wp-content\/uploads\/ISO-DIS-9001-2015-Risk-Based-Thinking-2-Ups.pdf\" target=\"_blank\">FMEA style handouts<\/a>, so admitting that RBT doesn&#8217;t actually require any of this stuff would hurt his bottom line.<\/p>\n<p>(When I confronted Larry about this, he merely changed the title of his article, but hasn&#8217;t changed a word in his training presentations or marketing.)<\/p>\n<div id=\"attachment_5175\" style=\"width: 422px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-5175\" class=\"wp-image-5175\" src=\"http:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2015\/04\/whittingtonrisk.jpg\" alt=\"whittingtonrisk\" width=\"412\" height=\"308\" srcset=\"https:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2015\/04\/whittingtonrisk.jpg 800w, https:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2015\/04\/whittingtonrisk-150x111.jpg 150w\" sizes=\"(max-width: 412px) 100vw, 412px\" \/><p id=\"caption-attachment-5175\" class=\"wp-caption-text\">From the Whittington training materials. Not a single thing here is an actual requirement, and actually contradicts official TC 176 opinion.<\/p><\/div>\n<p>Over at Scott Paton&#8217;s website InsideStandards, which also publishes Whittington&#8217;s stuff, Lance Coleman <a href=\"http:\/\/www.insidestandards.com\/risky-business-twelve-steps-to-prepare-for-iso-90012015\/\" target=\"_blank\">wrote a piece<\/a> on RBT also declaring (wrongly) that it is &#8220;risk management&#8221; not just once, but <em><strong>fifteen times<\/strong><\/em>. Editor Paton never seemed to notice.<\/p>\n<div id=\"attachment_5178\" style=\"width: 449px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-5178\" class=\"wp-image-5178\" src=\"http:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2015\/04\/colemanrisk.jpg\" alt=\"colemanrisk\" width=\"439\" height=\"366\" srcset=\"https:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2015\/04\/colemanrisk.jpg 644w, https:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2015\/04\/colemanrisk-150x125.jpg 150w\" sizes=\"(max-width: 439px) 100vw, 439px\" \/><p id=\"caption-attachment-5178\" class=\"wp-caption-text\">From the InsideStandards piece by Lance Coleman; even the graphic is wrong.<\/p><\/div>\n<p>Not to be left out whenever gross misreporting is going on, Quality Digest gets it&#8217;s spin machine rolling in <a href=\"http:\/\/www.qualitydigest.com\/inside\/quality-insider-article\/risk-management-iso-9001-and-iso-14001.html\" target=\"_blank\">an article<\/a> written by Intertek&#8217;s Paula Oddy and Jeff Eves, which declares\u00a0the new ISO 9001 draft is <em>&#8220;proof that quality management and risk management can no longer be considered separate issues for your organization.&#8221; <\/em>Waiter, I&#8217;ll have what they&#8217;re drinking.<\/p>\n<p>The ever-spamming CERM Academy founder Greg Hutchins is <a href=\"http:\/\/cermacademy.com\/iso-risk-based-thinking\/\" target=\"_blank\">insisting<\/a>, also falsely, that ISO has adopted risk-based thinking for <strong><em>all<\/em> <\/strong>its management standards, when of course it hasn&#8217;t; RBT only applies to\u00a09001. Nevertheless, Hutchins &#8212; who only refers to himself in the plural (&#8220;we&#8221;) &#8212; has refused to correct this misinformation even after being confronted with it multiple times. He is using his distortion of ISO&#8217;s risk-based thinking to sell &#8220;Certified Risk Manager&#8221; certificates to anyone stupid enough to believe they mean anything. Not only that, Hutchins is just falling short of claiming he <strong><em>invented<\/em> <\/strong>risk-based thinking, saying he started &#8220;the journey&#8221; of RBT over a decade\u00a0ago, even though he had no role in TC 176 nor in the development of ISO 9001, and nobody on the committee knows who he is.<\/p>\n<p>Michael Shuff at Cognidox <a href=\"https:\/\/www.cognidox.com\/2015\/02\/iso-90012015-the-likely-impact-part-ii\/\" target=\"_blank\">claims<\/a>\u00a0<em>&#8220;among the key changes &#8230;\u00a0in the ISO 9001:2015 quality management system standard, and available to read in the Draft International Standard (DIS) published in May 2014, are&#8230; the focus on risk management.&#8221;<\/em><\/p>\n<p>The registrars, who have a lot to gain by selling risk management training courses and (<a href=\"http:\/\/www.oxebridge.com\/emma\/bsi-begins-issuing-iso-31000-certificates-even-though-standard-denies-certification-usage\/\" target=\"_blank\">soon<\/a>) organizational risk management certifications, are in on the game, too, natch. SGS just opens the fountain of nonsense by <a href=\"http:\/\/www.sgs.com\/en\/Health-Safety\/Quality-Health-Safety-and-Environment\/Quality\/ISO-9001-2015-Revision\/ISO-DIS-9001-Risk-Based-Thinking-Awareness.aspx\" target=\"_blank\">selling a course<\/a> that claims you can develop a full-blown &#8220;<em>risk management system (RMS) based on the principles of ISO 9001.<\/em>&#8221;\u00a0As I mentioned above, Intertek is busy spreading the same stuff, but using their &#8220;content partner&#8221; Quality Digest as their platform.\u00a0BSI admits that, no, ISO 9001 doesn&#8217;t require risk management, but then <a href=\"https:\/\/bsi.learncentral.com\/shop\/Course.aspx?id=23514&amp;name=From+CAPA+to+Risk+Management+and+Resilience+-+Module+2+-+Risk+Methodologies\" target=\"_blank\">goes on to lie<\/a> and tell you why you need to take their risk management training anyway:<\/p>\n<blockquote><p>While the new structure for these updated standards does not mandate a specific risk methodology, regulators and other third-party auditors require evidence of the logic behind an organization\u2019s decision process. Therefore, risk-based thinking begins to require a more formal and organized approach.<\/p><\/blockquote>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter  wp-image-5179\" src=\"http:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2015\/04\/bsirisk.jpg\" alt=\"bsirisk\" width=\"420\" height=\"254\" srcset=\"https:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2015\/04\/bsirisk.jpg 759w, https:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2015\/04\/bsirisk-150x90.jpg 150w\" sizes=\"(max-width: 420px) 100vw, 420px\" \/><\/p>\n<p><strong>The Fallout<\/strong><\/p>\n<p>So what&#8217;s the impact of this mess? Other than, of course, an entire industry filling in the vacuum left by TC 176 with misinformation? There are multiple problems that will affect real ISO 9001 end users, and cost them real dollars, both problems about\u00a0which the spreaders of this junk simply don&#8217;t care.<\/p>\n<p>First, the imposition of a single method of risk management &#8212; which, by the looks of it, will be FMEA &#8212; doesn&#8217;t allow for the flexibility originally envisioned by TC 176. In fact, it <em>contradicts<\/em> it, and risks strangling smaller companies who don&#8217;t have the resources to do this kind of thing.<\/p>\n<p>Next, no two sources of this misinformation agree on specifically <em>how<\/em> RBT is equal to risk management, even as each one of them insists they are the most reliable subject matter expert. So an end user may adopt the approach of one source (probably a trainer, consultant or registrar) only to find their CB auditor &#8212; who was trained by some <em>other<\/em> source &#8212; disagrees. Now we have conflict over what is a bogus nonconformity to begin with.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignright  wp-image-5181\" src=\"http:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2015\/04\/riskfacepalm2.jpg\" alt=\"riskfacepalm2\" width=\"356\" height=\"292\" srcset=\"https:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2015\/04\/riskfacepalm2.jpg 402w, https:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2015\/04\/riskfacepalm2-150x123.jpg 150w, https:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2015\/04\/riskfacepalm2-183x150.jpg 183w\" sizes=\"(max-width: 356px) 100vw, 356px\" \/>Next, most of the methods being proposed (such as, again, FMEA) are grossly inadequate to begin with. They are mathematically flawed, junk science magic tricks that result in nearly no reliable data with which management can work, and &#8212; in the worst cases &#8212; actually provide erroneous information, which can lead companies to pursue nonsensical risks while ignoring the more critical ones.<\/p>\n<p>Finally, the costs of all these activities can mount quickly. Training, execution and then the ultimate repairs when the whole thing fails to work, will cost companies a bundle, thus increasing ISO 9001&#8217;s poor reputation for lousy ROI, and further alienating potential users.<\/p>\n<p>If, instead, those claiming to know this stuff admitted that, no, risk-based thinking <em>doesn&#8217;t<\/em> require full blown risk management, we would be off to a good start. Instead, such experts should be presenting a flexible, scaled idea of what companies <em>might<\/em>\u00a0do to comply, and offer it as a suggestion, not imply that it is a single means to meet an imaginary requirement.<\/p>\n<p>Meanwhile, TC 176 can&#8217;t seem to get its act together, is denying there&#8217;s a problem, and insists on telling us it&#8217;s all about a footbridge.<\/p>","protected":false},"excerpt":{"rendered":"<p>The so-called professionals are declaring that the upcoming ISO 9001 revision&#8217;s New Age, beaded-curtain fabrication called &#8220;risk based thinking&#8221; is actually full-blown risk management, even as TC 176 scrambles to get them to stop saying this.<\/p>","protected":false},"author":2,"featured_media":5181,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_et_pb_use_builder":"","_et_pb_old_content":"","_et_gb_content_width":"","mc4wp_mailchimp_campaign":[],"footnotes":""},"categories":[450,5],"tags":[359,43,14,116,194,263,240,42],"class_list":["post-5174","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-best-of","category-opinion","tag-insidestandards","tag-iso","tag-iso-9001","tag-iso-90012015","tag-quality-digest","tag-rbt","tag-risk-based-thinking","tag-tc-176","et-has-post-format-content","et_post_format-et-post-format-standard"],"_links":{"self":[{"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/posts\/5174","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/comments?post=5174"}],"version-history":[{"count":3,"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/posts\/5174\/revisions"}],"predecessor-version":[{"id":5183,"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/posts\/5174\/revisions\/5183"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/media\/5181"}],"wp:attachment":[{"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/media?parent=5174"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/categories?post=5174"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/tags?post=5174"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}