Establishing a framework for it governance by dave cunningham 2007


Published on

Published in: Business, Economy & Finance
  • Be the first to comment

  • Be the first to like this

No Downloads
Total views
On SlideShare
From Embeds
Number of Embeds
Embeds 0
No embeds

No notes for slide

Establishing a framework for it governance by dave cunningham 2007

  1. 1. Establishing a Framework for IT Governance <ul><li>Perspective of Law Firm Business Leaders </li></ul><ul><li>Background on Published Frameworks </li></ul><ul><li>Lessons Learned from Law Firm Technology Scorecards </li></ul>Dave Cunningham, Managing Director Baker Robbins & Company
  2. 2. Basic Questions from Firm Management <ul><li>What are other firms doing? </li></ul><ul><li>Are we prepared for disasters? </li></ul><ul><li>Are we spending the right amount of money for what we are getting? </li></ul><ul><li>Is my CIO doing a good job? </li></ul><ul><li>Should we outsource more? </li></ul><ul><li>Why are people complaining about…. </li></ul>
  3. 3. Evolving Questions from Firm Management <ul><li>What are the indicators of good performance? </li></ul><ul><li>What are the critical success factors? </li></ul><ul><li>What are the risks of not achieving our objectives? </li></ul><ul><li>How do we measure and compare to others? </li></ul><ul><li>What is the business case for this change? </li></ul><ul><li>How much would alternative service models and levels cost? </li></ul><ul><li>How can technology affect lawyer productivity? How do we define lawyer productivity? </li></ul><ul><li>How can IT use relevant information to deliver business intelligence? </li></ul>
  4. 4. Using a Published Framework <ul><li>For: </li></ul><ul><li>Provides perspective </li></ul><ul><li>Provides a common language </li></ul><ul><li>Training available and consistent </li></ul><ul><li>Most frameworks advocate “adopt and adapt” not certification </li></ul><ul><li>Frameworks promote short cuts and combining best of other frameworks </li></ul><ul><li>Increases ability to benchmark </li></ul><ul><li>Software increasingly builds in ITIL processes and measures </li></ul><ul><li>Larger outsourcers use ITIL </li></ul><ul><li>Against: </li></ul><ul><li>Too complex for a law firm; too procedural; too much bureaucracy </li></ul><ul><li>Hinders creativity and agility </li></ul><ul><li>SLAs don’t work in a law firm </li></ul><ul><li>Personal experience is more relevant </li></ul><ul><li>Law firms deal with exceptions, not rules </li></ul><ul><li>Too many standards to choose from </li></ul><ul><li>I have good people so don’t need someone telling me processes </li></ul>
  5. 5. <ul><li>“ All models are wrong, but some are useful.” </li></ul><ul><li>George Box, co-founder of the Center for Quality and Productivity Improvement </li></ul>
  6. 6. Comparison of IT Frameworks Source: CobiT Mapping, Overview of International IT Guidance, 2nd Edition
  7. 7. Components of IT Governance (CObIT v4.1) Source: Control Objectives for Information and related Technology (CObIT) One of the responsibilities of management is to ensure that the IT department has adequate resources to evaluate and implement new technologies as well as determining when to abandon obsolete technologies. This requires educating IT personnel and keeping their skills current to ensure they have the capabilities to do so. Resource Management To ensure that the previous four objectives can be managed, the organization must have a methodology to evaluate and track progress of the firm's IT governance. This includes the use of tools such as ROI measurement, IT performance benchmarks and balanced scorecards. Performance Measurement The IT function must effectively identify threats and vulnerabilities to the organization's IT infrastructure and then take steps to effectively mitigate the impact of those items. Risk Management IT must be able to respond to strategic objectives of adding value to the organization’s processes while at the same time maintaining fiscal responsibility and adhering to implementation time frames including measuring and achieving the expected return on the IT investment. Value Proposition Information technology must be in alignment with the evolving strategic objectives of the organization. As organizations evaluate their future strategies and new opportunities present themselves, it is critical that the IT function’s ability to address and deliver these opportunities is considered. Strategic Alignment
  8. 8. IT Supporting Strategic Objectives Source: Board Briefing on IT Governance, IT Governance Institute
  9. 9. From: Aligning COBIT®, ITIL® and ISO 17799 for Business Benefit
  10. 10. Components of ITIL Service Management (v3) Source: OGC Focuses on the activities required to operate the services and maintain their functionality as defined in the Service Level Agreements with the customers. Key areas of this volume are Incident Management, Problem Management and Request Fulfillment. Service Operation Focuses on the ability to deliver continual improvement to the quality of the services that the IT organization delivers to the business. Key areas of this volume are Service Reporting, Service Measurement and Service Level Management. Continual Service Improvement Focuses on the implementation of the output of the service design activities and the creation of a production service or modification of an existing service. There is an area of overlap between Service Transition and Service Operation. Key areas of this volume are Change Management, Release Management, Configuration Management and Service Knowledge Management. Service Transition Focuses on the activities that take place in order to develop the strategy into a design document which addresses all aspects of the proposed service, as well as the processes intended to support it. Key areas of this volume are Availability Management, Capacity Management, Continuity Management and Security Management. Service Design Focuses on the identification of market opportunities for which services could be developed in order to meet a requirement on the part of internal or external customers. The output is a strategy for the design, implementation, maintenance and continual improvement of the service as an organizational capability and a strategic asset. Key areas of this volume are Service Portfolio Management and Financial Management. Service Strategy
  11. 12. Process Ratings on Spider Chart (example, 1 of 4)
  12. 15. <ul><li>CONFLICTS & ETHICS </li></ul><ul><li>Conflicts & Ethics and Securities Transaction Committees </li></ul><ul><li>Information Services and Records Department </li></ul><ul><li>Outside Counsel </li></ul><ul><li>EMPLOYMENT & PERSONNEL MATTERS </li></ul><ul><li>Professional Personnel and Admin HR </li></ul><ul><li>Outside Counsel </li></ul><ul><li>PARTNERSHIP ELECTIONS </li></ul><ul><li>Policy Committee </li></ul><ul><li>Executive Group </li></ul><ul><li>Finance Department </li></ul><ul><li>IT </li></ul><ul><li>PARTNERSHIP ELECTIONS </li></ul><ul><li>(Governance, Departures, Disputes) </li></ul><ul><li>Executive Group </li></ul><ul><li>Policy Committee </li></ul><ul><li>Pension Committee </li></ul><ul><li>Finance Department </li></ul><ul><li>Professional Personnel </li></ul><ul><li>Outside Counsel </li></ul><ul><li>LITIGATION & SUBPOENA MATTERS </li></ul><ul><li>Litigation Attorneys </li></ul><ul><li>Managing Attorney’s Office </li></ul><ul><li>Outside Counsel </li></ul><ul><li>DATA PRIVACY, SECURITY MATTERS </li></ul><ul><li>Finance Department </li></ul><ul><li>IT </li></ul><ul><li>Professional Personnel and Admin HR </li></ul><ul><li>MARKETING & COMMUNICATIONS </li></ul><ul><li>(Website, Branding, Copyright, Reviewing Marketing Materials, etc.) </li></ul><ul><ul><li>Marketing/Communications Department </li></ul></ul><ul><li>PROFESSIONAL DEVELOPMENT </li></ul><ul><li>Professional Development Department </li></ul><ul><li>Professional Personnel </li></ul><ul><li>VENDOR CONTRACTS </li></ul><ul><li>Applicable Departments (IT, Finance, HR, M/C, etc.) </li></ul><ul><li>AUDIT </li></ul><ul><li>Audit Committee </li></ul><ul><li>Finance Department </li></ul><ul><li>INSURANCE </li></ul><ul><li>Professional Indemnity </li></ul><ul><li>Professional Insurance Committee </li></ul><ul><li>Executive Group </li></ul><ul><li>Finance Department </li></ul><ul><li>Employment/Worker’s Compensation </li></ul><ul><li>Administrative HR </li></ul><ul><li>Finance Department </li></ul><ul><li>Other Insurance </li></ul><ul><li>Finance Department </li></ul><ul><li>Executive Group </li></ul><ul><li>FIRM MANUALS AND GUIDANCE </li></ul><ul><li>Executive Group (and delegates) </li></ul><ul><li>Applicable Practice Groups & Departments </li></ul><ul><li>INFORMATION RETENTION </li></ul><ul><li>IR Project Team </li></ul><ul><li>Steering Group </li></ul><ul><li>Outside Consultants </li></ul><ul><li>All Practice Groups and Departments </li></ul><ul><li>FIRM INVESTMENTS </li></ul><ul><li>Investment Committee </li></ul>Areas of a Firm Addressing Risk (Example)
  13. 16. Enterprise Risk Management: Business Impact <ul><li>Gartner research shows that 60% of large enterprises without best practice risk management implemented consistently across the enterprise will significantly under-perform their peers. </li></ul><ul><li>Impact on insurable losses has not been measured. ERM helps you look better to the insurance company and establish a sense of awareness. - Lead of law firm insurance group, Aon </li></ul>
  14. 17. Technology Scorecard Assessments - What Have We Learned? <ul><li>Firms most often in 2+ range (scale of 5) for process and organizational maturity </li></ul><ul><li>Staffing and cost levels </li></ul><ul><ul><li>When apples-to-apples, highest firms are double the lowest firms without double the value </li></ul></ul><ul><ul><li>Firms struggle to provide same service/risk level as outsourcers for the same cost </li></ul></ul><ul><ul><li>IT Departments are largely still geared toward operational and support responsibilities </li></ul></ul><ul><li>Wide penetration of ITIL programs and selective outsourcing </li></ul><ul><li>Use of Service Level Objectives / Agreements still minimal </li></ul><ul><li>External surveys not taken seriously </li></ul><ul><li>Lack of transparency of IT’s cost, value and risks is one of the most important drivers for IT governance </li></ul>
  15. 18. Thank you. <ul><li>Dave Cunningham </li></ul><ul><li>Managing Director, Strategic Technology Services </li></ul><ul><li>Baker Robbins & Company </li></ul>