{"id":5967,"date":"2015-08-24T08:20:09","date_gmt":"2015-08-24T13:20:09","guid":{"rendered":"http:\/\/www.oxebridge.com\/emma\/?p=5967"},"modified":"2015-10-23T17:04:55","modified_gmt":"2015-10-23T22:04:55","slug":"practical-implementation-of-risk-based-thinking-part-2","status":"publish","type":"post","link":"https:\/\/www.oxebridge.com\/emma\/practical-implementation-of-risk-based-thinking-part-2\/","title":{"rendered":"Practical Implementation of &#8220;Risk Based Thinking&#8221; &#8211; Part 2"},"content":{"rendered":"<p><strong>Part 2:\u00a0Defining Risk and Opportunity<\/strong><\/p>\n<p><em>(For Part 1, <a href=\"http:\/\/www.oxebridge.com\/emma\/practical-implementation-of-risk-based-thinking-part-1\/\">click here<\/a>.)<\/em><\/p>\n<p>From the information you have derived from <a href=\"http:\/\/www.oxebridge.com\/emma\/practical-implementation-of-risk-based-thinking-part-1\/\">the COTO exercise<\/a>, you now have a better understanding of the company, it&#8217;s stakeholders, internal and external issues of concern, and other factors which will build the framework for your thinking about risk.<\/p>\n<p>You will also realize that because the information derived from the COTO exercise\u00a0will be\u00a0different for every company, the\u00a0risks will also be different for every company.\u00a0This means <strong><em>no auditor can tell you what your risks are.<\/em><\/strong> (Of course they are going to anyway, but you have to push back.) <strong><em>You<\/em> <\/strong>decide which risks are going to be managed&#8230; no one else. This is explicitly hard-coded into the standard, which says:<\/p>\n<blockquote><p>6.1.1 When planning for the quality management system, the <strong><em>organization<\/em> <\/strong>shall &#8230;\u00a0determine the risks and opportunities that need to be addressed.<\/p><\/blockquote>\n<p>In the AS9100 scheme, which has had requirements for risk management since 2009, we have seen auditors come on site and try to dream up risks during the audit, and then play &#8220;gotcha&#8221; with the client. Despite being presented with formal risk registers, they will stroke their chin\u00a0and muse on things you&#8217;ve missed:\u00a0&#8220;well, did you think of whether or not a meteor will strike your HR manager on her way to work?&#8221; or &#8220;did you assess the risk of a zombie apocalypse?&#8221; Now, under 9001:2015, you get to tell them to\u00a0<a href=\"https:\/\/s-media-cache-ak0.pinimg.com\/736x\/9c\/64\/52\/9c645259f3d161d4006eb05bdc331ffb.jpg\">STFU <\/a>and look at the risks you&#8217;ve addressed, to stop auditing by fantasy, and for God&#8217;s sake, stop stroking their\u00a0chin.<\/p>\n<p><strong>Re-Defining Risk and Opportunity<\/strong><\/p>\n<p>So the next step is to &#8220;determine&#8221; your risks. Unfortunately, we have another slight speedbump: ISO has completely mucked\u00a0up traditional concepts of risk. The reasons for this are <a href=\"http:\/\/www.oxebridge.com\/emma\/practical-implementation-of-risk-based-thinking-part-1\/\">complicated and political<\/a>, and not at all universally agreed-upon. There are two camps: one that thinks &#8220;risk&#8221; is neutral, and thus can be either negative or positive (thus defying the dictionary) and the other that believes risk is solely negative.\u00a0 The &#8220;positive risk&#8221; crowd has won over the ISO Technical Management Board and the authors of ISO 31000 on risk management, but did not win over TC 176. In fact, the &#8220;positive risk&#8221; debate is one of the main sticking points for ISO 9001 ratification across\u00a0the world.<\/p>\n<p>Why does this matter? Wouldn&#8217;t it be nice to let ISO have their fight and watch from the sidelines? Well, this has a real-word impact on you right now. You see, normally you work to mitigate risk &#8212; meaning <strong><em>minimize<\/em> <\/strong>it &#8212; because it&#8217;s bad. If you suddenly treat risk as &#8220;positive&#8221; then you would want to <strong><em>maximize<\/em> <\/strong>the possibility of the risk, right? But you can&#8217;t use the same tools to both minimize and maximize something at the same time. SWOT comes close, but other traditional tools like FMEA focus only on reducing\u00a0risk, understanding that risk is inherently bad. Other tools might work to maximize opportunities (such as expanding business development leads) but these wouldn&#8217;t work for reducing negative risk.<\/p>\n<p><strong>The Silver Lining Theory<\/strong><\/p>\n<p>The &#8220;positive risk&#8221; camp tends to defend its view using what I have dubbed the &#8220;Silver Lining Theory&#8221; &#8212; this is where they paint risk as being positive only because there may be an accidental benefit of an otherwise disastrous thing. The example I often hear is the &#8220;hurricane&#8221; scenario: a hurricane is a bad thing because it causes damage.\u00a0The &#8220;Silver Lining&#8221; crowd says that a hurricane is also positive, since the destruction it leaves behind becomes an opportunity for those in the construction industry.<\/p>\n<p>The reason the Silver Lining Theory fails is when you try to apply it in a practical way. Remember, for negative risk we work to minimize the likelihood and severity; so\u00a0companies must reduce the risks associated with hurricane damage by having\u00a0business continuity plans in place, escape routes, shelters, data backups. etc.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignright wp-image-6020\" style=\"margin-top: 15px; margin-bottom: 15px; margin-left: 15px;\" src=\"http:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2015\/08\/devil.png\" alt=\"devil\" width=\"272\" height=\"204\" srcset=\"https:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2015\/08\/devil.png 600w, https:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2015\/08\/devil-150x113.png 150w\" sizes=\"(max-width: 272px) 100vw, 272px\" \/>Remember too that positive opportunities must be managed to increase their likelihood and maximize the benefits. However, those in the construction industry cannot\u00a0increase the likelihood of a hurricane, and cannot maximize the damage (which to them is a benefit) unless they hire hordes of looters to tear the city apart, which they can rebuild later. Not a great business plan.<\/p>\n<p>The best a construction company can do is plan to have additional resources ready (reconstruction teams, hardware, etc.) in the event there is damage they can repair. But that&#8217;s not the same as risk management since mere planning does not increase either likelihood or severity. And, in fact, they may expend money to have those resources ready and it be all for naught, if the hurricane doesn&#8217;t make landfall at all. In which case, they&#8217;ve created a\u00a0problem (now they&#8217;re broke) and not achieved any opportunity. Not to mention they need to do all of this while mitigating their own exposure to the damage of the hurricane, like making sure the people they have on standby don&#8217;t get killed themselves. None of this magically turns a hurricane into a good thing; it just tries to examine the &#8220;silver lining&#8221; behind an\u00a0overwhelmingly bad thing.<\/p>\n<p>(The most ghoulish explanation I&#8217;ve heard is related to cancer. A few &#8220;positive risk&#8221; advocates claim that cancer is good because it creates jobs. They ignore the fact that those jobs are seeking to eradicate\u00a0cancer, an admission that cancer researchers never view cancer as an &#8220;opportunity&#8221; but as a risk that must be eliminated.)<\/p>\n<p>A &#8220;pure&#8221; positive opportunity exists, first and foremost, as an opportunity; it\u00a0is not an\u00a0accidental positive side effect of a bad thing, it is inherently good to start with. For example, a positive opportunity might be that the government puts a $5 Billion contract out for bid, and it&#8217;s something your company is qualified in. Another opportunity might be you find $100 on the street, or prices drop on a critical raw material, or that nerdy engineer who works in the lab and smells like tuna fish accidentally invented antigravity. All these things are positive first; they may have hidden negatives (a &#8220;tarnished silver lining&#8221; if you will) but they are primarily opportunities. You work to exploit them, not run from them.<\/p>\n<p><strong>The Uncertainty Battery<\/strong><\/p>\n<p>So what you have is the reality that <strong><em>uncertainty is neutral<\/em><\/strong>, while\u00a0&#8220;risk&#8221; and &#8220;opportunity&#8221; are the negative and positive aspects of uncertainty.\u00a0If you imagine a battery is, itself, neutral and only the poles have a charge, then you begin to understand the true nature of uncertainty:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-6008\" src=\"http:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2015\/08\/riskbattery.png\" alt=\"riskbattery\" width=\"339\" height=\"227\" srcset=\"https:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2015\/08\/riskbattery.png 752w, https:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2015\/08\/riskbattery-150x101.png 150w\" sizes=\"(max-width: 339px) 100vw, 339px\" \/><\/p>\n<p>So the\u00a0Oxebridge view is that <em><strong>uncertainty<\/strong> <\/em>is neutral; risk is the <em><strong>negative effect of uncertainty<\/strong><\/em>, and opportunity is the <em><strong>positive effect of uncertainty<\/strong><\/em>. This interpretation has the benefit of (a) complying with English dictionaries and (b) actually making sense. I strongly suggest you adopt this view to proceed, but if you do, you may need to indicate this in your QMS documentation somewhere. Auditors may come in and disagree, depending on which ISO school of thought they were trained in, but\u00a0<strong><em>you<\/em> <\/strong>get to define concepts for your QMS, not them.<\/p>\n<p><strong>The ISO 9000 Problem<\/strong><\/p>\n<p>An aside: some will say that ISO 9001 calls out the definitions in ISO 9000 as a &#8220;normative reference&#8221; which thus makes the\u00a0definition of &#8220;risk&#8221;\u00a0from ISO 9000 a mandatory requirement. This is not true, and you must be ready to defend yourself against this argument as well. Here are the talking points for your defense:<\/p>\n<ul>\n<li>ISO 9000&#8217;s definition is not universally adopted within ISO itself, which has 40 different and often contradictory definitions of the term &#8220;risk&#8221;.<\/li>\n<li>ISO 9000&#8217;s definition of &#8220;risk&#8221; has been viewed as controversial and may be changed or revoked, and you don&#8217;t want to hold your QMS hostage to something that could change easily.<\/li>\n<li>ISO 9000&#8217;s definition of risk is impossible to implement in a practical way, since negative risks must be managed differently than positive opportunities, so the definition needed &#8220;tailoring&#8221;.<\/li>\n<li>The tailored definition doesn&#8217;t\u00a0inherently contradict ISO 9000&#8217;s definition anyway, they merely provide greater\u00a0context.<\/li>\n<\/ul>\n<p>As we will see, having this definition in place will become necessary to continue.<\/p>\n<p><strong><em>Continued in <a href=\"http:\/\/www.oxebridge.com\/emma\/practical-implementation-of-risk-based-thinking-part-3\/\">Part 3: RBT in Practice<\/a><\/em><\/strong><\/p>\n<p><em>Like this topic? Book Christopher Paris for a speaking event at your\u00a0organization\u00a0on <strong>Practical Implementation of Risk-Based Thinking.<\/strong> Click <a href=\"http:\/\/www.oxebridge.com\/emma\/public-speaking-engagements\/\">here<\/a> for more\u00a0details.<\/em><\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>","protected":false},"excerpt":{"rendered":"<p>Part 2:\u00a0Defining Risk and Opportunity (For Part 1, click here.) From the information you have derived from the COTO exercise, you now have a better understanding of the company, it&#8217;s stakeholders, internal and external issues of concern, and other factors which will build the framework for your thinking about risk. You will also realize that [&hellip;]<\/p>","protected":false},"author":2,"featured_media":5969,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_et_pb_use_builder":"","_et_pb_old_content":"","_et_gb_content_width":"","mc4wp_mailchimp_campaign":[],"footnotes":""},"categories":[4],"tags":[404,403,43,14,116,263,147,240,148],"class_list":["post-5967","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-guidance","tag-context-of-the-organization","tag-coto","tag-iso","tag-iso-9001","tag-iso-90012015","tag-rbt","tag-risk","tag-risk-based-thinking","tag-risk-management","et-has-post-format-content","et_post_format-et-post-format-standard"],"_links":{"self":[{"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/posts\/5967","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/comments?post=5967"}],"version-history":[{"count":16,"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/posts\/5967\/revisions"}],"predecessor-version":[{"id":6505,"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/posts\/5967\/revisions\/6505"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/media\/5969"}],"wp:attachment":[{"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/media?parent=5967"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/categories?post=5967"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/tags?post=5967"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}