SlideShare a Scribd company logo
1 of 47
Fit for Service
A strategy for service organizations.
Michael Werneburg, 2013.04.13
Updated 2015.11.16
TL;DR
A technology & service provider can have great products and still get nowhere
because the clients lack trust. An enterprise risk function can overcome this by
guiding improvements to service consistency.
Bend your audits to shift your focus & capabilities, then use your audit report as a
hall pass.
You want to sell to the financial
industry.
But it’s becoming harder.
The target market—banks and life
insurance firms—are jointly called
“federally regulated entities”.
They are accountable to
several regulators
domestically and abroad.
OSFI CSA
IIROCOSC
MFDA FSCO
DEEPLY
Of particular interest to regulators is the preservation at the
regulated entity of strong corporate governance. In this regard
outsourcing activities that may impede an outsourcing firm's
management from fulfilling its regulatory responsibilities are of
concern to regulators. The rapid rate of IT innovation, along with
an increasing reliance on external service providers have the
potential of leading to systemic problems unless appropriately
constrained by a combination of market and regulatory influences.
Outsourcing in Financial Services.
Basel Committee on Banking Supervision,
Bank of International Settlement, 2005
http://bit.ly/1kGr8wv
The regulators are deeply
concerned with third party risk.
Selling information services to
these regulated entities means
meeting their stringent regulations.
The vetting process for a new
vendor can involve 80-page RFI’s
full of questions.
Dealing with these requirements
ad-hoc can be difficult, lengthy,
and disruptive.
ITLegalComplianceRisk
Mgmt.
PMOVendor
Mgmt.
…
But these clients now also want
annual service audits and SOC-2
attestation reports.
Passing these audits can require
new activities for your firm, and
hundreds of new internal controls.
(You do have internal controls, right?)
Your clients know the risks can
be complex.
Fatal to the relationship.
Even “systemic”.
What to do
Turn the problem into a strength.
The service you offer is where you
have chosen to compete.
Performing at the mandated level
is how you will win.1
You can leverage the risk
management function to get
you there.
1. Drucker. Or someone.
Key outcomes:
• Consistently excel in all points of
contact with clients.
• Optimize the fit between internal
activities.
• Adopt managed change as a way of
life.
Implementing a “fitness” regime
How to turn this mess around and build a resilient business that performs.
The evolving SOC-2 standard is embodied
in the AICPA’s “trust services principles
and criteria”1.
1. http://bit.ly/1luCdHr
It sets the level of performance, and
suggests a governance framework
to monitor and foster progress.
DO NOT just approach this as a huge list
of controls to implement.
Instead, step back and understand
what you’re really doing:
altering your company forever.
I’ve written about this here1 and here2.
1. http://risktopics.com/service-audits-are-risky-business
2. http://risktopics.com/a-strategic-approach-to-the-value-chain
But it’s a fairly simple. When we
make changes to our core practices,
we’re building a new company.
Put it this way: your technology firm
already has standards and practices.
But you’re about to review
hundreds of these, and start
making changes.
Your business is a unique collection of
processes and competencies. The crucial
ones span departments, and add value
to your clients1.
Change those crucial processes
and competencies, and you’re
finding a new unique mix.
1. Porter. And then everyone.
It’s a new company!
But not just any new.
You’ll build a more consistent
company. Consistency is the heart of
culture, and of brand1.
Consistency is a natural outcome
of the governance function
built into the audit process.
1. Porter, again.
You’ll also be building a more competent
firm; when you build governance into
your processes, your people eliminate
uncertainty.
A certain company where
everyone understands their role
and what to do next.
When your people understand that they
are responsible for reaching a certain
bar for achievement, something magical
happens.
People who have taken a quality
standard to heart expect quality
in everything they do.
Even when no auditor is watching.
Adults don’t say, “Oh, we have to
do X and Y right, but the auditor’s
not looking at Z.”
A holistic approach can make all this
happen. This is “doing things the hard
way”.
But an unplanned approach will
leave your firm with a countless,
seemingly unrelated, controls.
Again, I’ve written about this here1 and
here2.
1. http://risktopics.com/service-audits-are-risky-business
2. http://risktopics.com/a-strategic-approach-to-the-value-chain
But enough; let’s have a look at the
company that emerges.
A Case Study
The story of a successful approach to SOC-2, by a technology & service provider.
We were a fifteen person firm.
With one client.
And big ambitions.
We’d been in business for a decade.
But new, regulated clients wanted
that SOC-2.
We were a fifteen person firm.
With one client.
And big ambitions.
We’d been in business for a decade.
We did SOC-2 “the easy way”,
implemented countless controls.
Executive: setting and communicating objectives; evaluating operations and financial
performance; service level management; business continuity planning; budget approval;
vendor management.
Human Resources: background checks; asset entitlements management; hiring and
termination policies; privacy; acceptable use; code of conduct; confidentiality; whistle-
blowing; site security; staff evaluations.
IT: SDLC; change control; disaster recovery; technology standards; patch management;
security incident management; information classification; log monitoring; viruses; bring-your-
own-device; data disposal; encryption; firewall management; remote access.
Internal control: internal audit; risk management; policy management.
(This is a sample; It is not practical to list everything.)
The scope was daunting.
Processes
&
controls
Clients
COBIT
Trust
Services
Auditors
Regulators
Vendors
CICA
The sources were many.
We did not know where we were going.
As unplanned as our initiative was,
it began to pay off at once.
1. Immediate sales benefits
• Easy RFP’s and RFI’s. Just hand over the
documentation.
• No more one-off requests for proof of
capability from vendor managers, IRM,
legal, etc.
• Shortened and easier sales cycle.
In the words of one software executive;
“Now that we have our audit report, we’re
having a whole other level of discussion. The
gate-keepers simply ask for the report and
we’re done. Everyone thanks us for making
their jobs easier.”
2. Operations running smoothly:
• Delivering software updates in a reliable
fashion (1 error in 557 releases)
• Hosting our service in a secure and
uninterrupted fashion (no downtime after
four years and counting).
• Stable processes free the time of SME’s and
management.
3. Life was easier for existing clients
• No more one-off requests for proof of
capability from vendor managers, IRM,
legal, etc.
• Improved “story” for service owners.
• More interest in expanding services with
us.
Confident and transparent
• Reduced need for monitoring by clients.
None has ever called for an ad-hoc audit.
• Clarity around roles and responsibilities.
• Comprehensive service level attainment is
demonstrable through reporting.
4. Leaders free to make decisions
and lead:
• Far fewer procedural questions.
• Far fewer mistakes due to uncertainty or
improper process.
• Stable processes free the time of SME’s and
management.
Cross-team processes smooth:
• Mature practices mean teams work together
as expected.
• Entrusting functional managers with
governance process leads to automatic
correction of deviations.
• A strong sense of ownership of product and
service.
5. Low turnover:
• People not wearing out from rework and
confusion.
• They enjoy the blend of responsibility and
quality outputs.
• Stable processes free the time of SME’s and
management.
6. Growth:
• Stable processes allow a business to scale.
• Problems that creep in turn up at the first
quarterly risk control self-assessment.
• Persistent problems turn up in the auditors’
report.
7. The magic of being “approved”:
• Having that audit report indicates that
you’re part of the regulated industry.
• Once you’re reached the level of being an
approved vendor, you’ll find yourself able to
rapidly grow in your industry.
• Partners will seek you out. Others will more
readily accept you as a mature organization
with the right types of clients.
These things occurred to us
with time.
And only when we had gone
through rounds of corrections
sensing that they were possible.
The results are worth it.
Your challenge is to do it
“the hard way”,
to realize the benefits the first time.
Having a great product got you
to the door.
Your risk management capabilities
are the security pass to get you in
and keep you in.
I can help
My role as a specialist in governance, risk, and strategy.
Reach out! I like to advise:
• Understanding risk analysis (MSc in Risk Management).
• Understanding service delivery strategies (20+ years experience).
• Understanding IT and IT governance frameworks (e.g. ITIL, COBIT).
• Mapping the governance framework to business strategy.
• Knowledge of regulated financial industries and the software/service
firms that support them.
• Business process renewal and the writing of process manuals.
• Managing the auditors. (Certified Internal Auditor designation).
• Project management (I am a PMP).
Michael Werneburg
647-896-3850
michael@risktopics.com

More Related Content

What's hot

Case Organization, Analysis & Presentation in the Age of eDiscovery
Case Organization, Analysis & Presentation in the Age of eDiscoveryCase Organization, Analysis & Presentation in the Age of eDiscovery
Case Organization, Analysis & Presentation in the Age of eDiscoveryLexisNexis Software Division
 
Cachet Presentation Website Eliminating Business Disruption
Cachet Presentation Website Eliminating Business DisruptionCachet Presentation Website Eliminating Business Disruption
Cachet Presentation Website Eliminating Business Disruptionkevshin
 
Banking Industry Leverages Lean
Banking Industry Leverages LeanBanking Industry Leverages Lean
Banking Industry Leverages Leanscottomullen
 
Lean for Financial Services v1.1
Lean for Financial Services v1.1Lean for Financial Services v1.1
Lean for Financial Services v1.1Andrea Darabos
 
Client Onboarding PowerPoint Presentation Slides
Client Onboarding PowerPoint Presentation SlidesClient Onboarding PowerPoint Presentation Slides
Client Onboarding PowerPoint Presentation SlidesSlideTeam
 
system-selection-guide_synergist-v106
system-selection-guide_synergist-v106system-selection-guide_synergist-v106
system-selection-guide_synergist-v106Jason Neale
 
KRI Consulting Solutions LLC
KRI Consulting Solutions LLCKRI Consulting Solutions LLC
KRI Consulting Solutions LLCkrh96011
 

What's hot (8)

Case Organization, Analysis & Presentation in the Age of eDiscovery
Case Organization, Analysis & Presentation in the Age of eDiscoveryCase Organization, Analysis & Presentation in the Age of eDiscovery
Case Organization, Analysis & Presentation in the Age of eDiscovery
 
Cachet Presentation Website Eliminating Business Disruption
Cachet Presentation Website Eliminating Business DisruptionCachet Presentation Website Eliminating Business Disruption
Cachet Presentation Website Eliminating Business Disruption
 
LexisNexis Moneyball for Lawyers
LexisNexis Moneyball for LawyersLexisNexis Moneyball for Lawyers
LexisNexis Moneyball for Lawyers
 
Banking Industry Leverages Lean
Banking Industry Leverages LeanBanking Industry Leverages Lean
Banking Industry Leverages Lean
 
Lean for Financial Services v1.1
Lean for Financial Services v1.1Lean for Financial Services v1.1
Lean for Financial Services v1.1
 
Client Onboarding PowerPoint Presentation Slides
Client Onboarding PowerPoint Presentation SlidesClient Onboarding PowerPoint Presentation Slides
Client Onboarding PowerPoint Presentation Slides
 
system-selection-guide_synergist-v106
system-selection-guide_synergist-v106system-selection-guide_synergist-v106
system-selection-guide_synergist-v106
 
KRI Consulting Solutions LLC
KRI Consulting Solutions LLCKRI Consulting Solutions LLC
KRI Consulting Solutions LLC
 

Similar to Fit for Service - A strategy for service organizations.

Building an Effective Customer Experience within the ETA Risk Guidelines
Building an Effective Customer Experience within the ETA Risk GuidelinesBuilding an Effective Customer Experience within the ETA Risk Guidelines
Building an Effective Customer Experience within the ETA Risk GuidelinesAgreement Express Inc.
 
Building a business impact analysis (bia) process a hands on blueprint
Building a business impact analysis (bia) process a hands on blueprintBuilding a business impact analysis (bia) process a hands on blueprint
Building a business impact analysis (bia) process a hands on blueprintluweinet
 
RESPA-TILA Integrated Disclosure: Are You Ready?
RESPA-TILA Integrated Disclosure: Are You Ready?RESPA-TILA Integrated Disclosure: Are You Ready?
RESPA-TILA Integrated Disclosure: Are You Ready?Infinitive
 
Sole solicitor qaq electronic version[sra]
Sole solicitor   qaq electronic version[sra]Sole solicitor   qaq electronic version[sra]
Sole solicitor qaq electronic version[sra]swiss1234
 
Sole solicitor qaq electronic version[sra]
Sole solicitor   qaq electronic version[sra]Sole solicitor   qaq electronic version[sra]
Sole solicitor qaq electronic version[sra]engrsaeed
 
Sole solicitor qaq electronic version[sra](2)
Sole solicitor   qaq electronic version[sra](2)Sole solicitor   qaq electronic version[sra](2)
Sole solicitor qaq electronic version[sra](2)engrsaeed
 
2014-10-15 Agility Solution DF Session Slides
2014-10-15 Agility Solution DF Session Slides2014-10-15 Agility Solution DF Session Slides
2014-10-15 Agility Solution DF Session SlidesGeoff Rothman
 
Pricing in a Post Royal Commission world
Pricing in a Post Royal Commission worldPricing in a Post Royal Commission world
Pricing in a Post Royal Commission worldnetwealthInvest
 
Cga Assignment Au1 Essay
Cga Assignment Au1 EssayCga Assignment Au1 Essay
Cga Assignment Au1 EssaySandra Arveseth
 
Outsourcing GIA Accounting whitepaper 2016
Outsourcing GIA Accounting whitepaper 2016Outsourcing GIA Accounting whitepaper 2016
Outsourcing GIA Accounting whitepaper 2016Rich Lawrence
 
Janders dean 2011 Legal Knowledge & Innovation Conference
Janders dean 2011 Legal Knowledge & Innovation ConferenceJanders dean 2011 Legal Knowledge & Innovation Conference
Janders dean 2011 Legal Knowledge & Innovation ConferenceTom Baldwin
 
Agreement Express developing a strategic roadmap to automated underwriting
Agreement Express developing a strategic roadmap to automated underwritingAgreement Express developing a strategic roadmap to automated underwriting
Agreement Express developing a strategic roadmap to automated underwritingAgreement Express Inc.
 
Digital Transformation for Insurance and Underwriting Processes - Caroly Mart...
Digital Transformation for Insurance and Underwriting Processes - Caroly Mart...Digital Transformation for Insurance and Underwriting Processes - Caroly Mart...
Digital Transformation for Insurance and Underwriting Processes - Caroly Mart...SigortaTatbikatcilariDernegi
 
Conducting a Large Admin Team by Andrew Wainacht & Judith Shimer
Conducting a Large Admin Team by Andrew Wainacht & Judith ShimerConducting a Large Admin Team by Andrew Wainacht & Judith Shimer
Conducting a Large Admin Team by Andrew Wainacht & Judith ShimerSalesforce Admins
 
How To Save Millions At Your Company
How To Save Millions At Your CompanyHow To Save Millions At Your Company
How To Save Millions At Your Companyrichlanza
 
The Sarbanes Oxley ( Sox ) Act
The Sarbanes Oxley ( Sox ) ActThe Sarbanes Oxley ( Sox ) Act
The Sarbanes Oxley ( Sox ) ActDana Boo
 
Commercial Due Diligence - More than a rubber stamp
Commercial Due Diligence - More than a rubber stampCommercial Due Diligence - More than a rubber stamp
Commercial Due Diligence - More than a rubber stampCarl Brostrom
 
InfinityQS_7 Habits of Quality Obsessed Manufacturers_Print final
InfinityQS_7 Habits of Quality Obsessed Manufacturers_Print finalInfinityQS_7 Habits of Quality Obsessed Manufacturers_Print final
InfinityQS_7 Habits of Quality Obsessed Manufacturers_Print finalVanessa Stirling
 

Similar to Fit for Service - A strategy for service organizations. (20)

Building an Effective Customer Experience within the ETA Risk Guidelines
Building an Effective Customer Experience within the ETA Risk GuidelinesBuilding an Effective Customer Experience within the ETA Risk Guidelines
Building an Effective Customer Experience within the ETA Risk Guidelines
 
Building a business impact analysis (bia) process a hands on blueprint
Building a business impact analysis (bia) process a hands on blueprintBuilding a business impact analysis (bia) process a hands on blueprint
Building a business impact analysis (bia) process a hands on blueprint
 
RESPA-TILA Integrated Disclosure: Are You Ready?
RESPA-TILA Integrated Disclosure: Are You Ready?RESPA-TILA Integrated Disclosure: Are You Ready?
RESPA-TILA Integrated Disclosure: Are You Ready?
 
Sole solicitor qaq electronic version[sra]
Sole solicitor   qaq electronic version[sra]Sole solicitor   qaq electronic version[sra]
Sole solicitor qaq electronic version[sra]
 
Sole solicitor qaq electronic version[sra]
Sole solicitor   qaq electronic version[sra]Sole solicitor   qaq electronic version[sra]
Sole solicitor qaq electronic version[sra]
 
Sole solicitor qaq electronic version[sra](2)
Sole solicitor   qaq electronic version[sra](2)Sole solicitor   qaq electronic version[sra](2)
Sole solicitor qaq electronic version[sra](2)
 
2014-10-15 Agility Solution DF Session Slides
2014-10-15 Agility Solution DF Session Slides2014-10-15 Agility Solution DF Session Slides
2014-10-15 Agility Solution DF Session Slides
 
Nextcard Case Essay
Nextcard Case EssayNextcard Case Essay
Nextcard Case Essay
 
Pricing in a Post Royal Commission world
Pricing in a Post Royal Commission worldPricing in a Post Royal Commission world
Pricing in a Post Royal Commission world
 
Cga Assignment Au1 Essay
Cga Assignment Au1 EssayCga Assignment Au1 Essay
Cga Assignment Au1 Essay
 
Outsourcing GIA Accounting whitepaper 2016
Outsourcing GIA Accounting whitepaper 2016Outsourcing GIA Accounting whitepaper 2016
Outsourcing GIA Accounting whitepaper 2016
 
Janders dean 2011 Legal Knowledge & Innovation Conference
Janders dean 2011 Legal Knowledge & Innovation ConferenceJanders dean 2011 Legal Knowledge & Innovation Conference
Janders dean 2011 Legal Knowledge & Innovation Conference
 
Reducing Regulatory Capital
Reducing Regulatory CapitalReducing Regulatory Capital
Reducing Regulatory Capital
 
Agreement Express developing a strategic roadmap to automated underwriting
Agreement Express developing a strategic roadmap to automated underwritingAgreement Express developing a strategic roadmap to automated underwriting
Agreement Express developing a strategic roadmap to automated underwriting
 
Digital Transformation for Insurance and Underwriting Processes - Caroly Mart...
Digital Transformation for Insurance and Underwriting Processes - Caroly Mart...Digital Transformation for Insurance and Underwriting Processes - Caroly Mart...
Digital Transformation for Insurance and Underwriting Processes - Caroly Mart...
 
Conducting a Large Admin Team by Andrew Wainacht & Judith Shimer
Conducting a Large Admin Team by Andrew Wainacht & Judith ShimerConducting a Large Admin Team by Andrew Wainacht & Judith Shimer
Conducting a Large Admin Team by Andrew Wainacht & Judith Shimer
 
How To Save Millions At Your Company
How To Save Millions At Your CompanyHow To Save Millions At Your Company
How To Save Millions At Your Company
 
The Sarbanes Oxley ( Sox ) Act
The Sarbanes Oxley ( Sox ) ActThe Sarbanes Oxley ( Sox ) Act
The Sarbanes Oxley ( Sox ) Act
 
Commercial Due Diligence - More than a rubber stamp
Commercial Due Diligence - More than a rubber stampCommercial Due Diligence - More than a rubber stamp
Commercial Due Diligence - More than a rubber stamp
 
InfinityQS_7 Habits of Quality Obsessed Manufacturers_Print final
InfinityQS_7 Habits of Quality Obsessed Manufacturers_Print finalInfinityQS_7 Habits of Quality Obsessed Manufacturers_Print final
InfinityQS_7 Habits of Quality Obsessed Manufacturers_Print final
 

Recently uploaded

Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...Dave Litwiller
 
Best VIP Call Girls Noida Sector 40 Call Me: 8448380779
Best VIP Call Girls Noida Sector 40 Call Me: 8448380779Best VIP Call Girls Noida Sector 40 Call Me: 8448380779
Best VIP Call Girls Noida Sector 40 Call Me: 8448380779Delhi Call girls
 
VIP Call Girls In Saharaganj ( Lucknow ) 🔝 8923113531 🔝 Cash Payment (COD) 👒
VIP Call Girls In Saharaganj ( Lucknow  ) 🔝 8923113531 🔝  Cash Payment (COD) 👒VIP Call Girls In Saharaganj ( Lucknow  ) 🔝 8923113531 🔝  Cash Payment (COD) 👒
VIP Call Girls In Saharaganj ( Lucknow ) 🔝 8923113531 🔝 Cash Payment (COD) 👒anilsa9823
 
Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...
Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...
Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...Dipal Arora
 
Vip Dewas Call Girls #9907093804 Contact Number Escorts Service Dewas
Vip Dewas Call Girls #9907093804 Contact Number Escorts Service DewasVip Dewas Call Girls #9907093804 Contact Number Escorts Service Dewas
Vip Dewas Call Girls #9907093804 Contact Number Escorts Service Dewasmakika9823
 
Regression analysis: Simple Linear Regression Multiple Linear Regression
Regression analysis:  Simple Linear Regression Multiple Linear RegressionRegression analysis:  Simple Linear Regression Multiple Linear Regression
Regression analysis: Simple Linear Regression Multiple Linear RegressionRavindra Nath Shukla
 
VIP Kolkata Call Girl Howrah 👉 8250192130 Available With Room
VIP Kolkata Call Girl Howrah 👉 8250192130  Available With RoomVIP Kolkata Call Girl Howrah 👉 8250192130  Available With Room
VIP Kolkata Call Girl Howrah 👉 8250192130 Available With Roomdivyansh0kumar0
 
7.pdf This presentation captures many uses and the significance of the number...
7.pdf This presentation captures many uses and the significance of the number...7.pdf This presentation captures many uses and the significance of the number...
7.pdf This presentation captures many uses and the significance of the number...Paul Menig
 
Catalogue ONG NUOC PPR DE NHAT .pdf
Catalogue ONG NUOC PPR DE NHAT      .pdfCatalogue ONG NUOC PPR DE NHAT      .pdf
Catalogue ONG NUOC PPR DE NHAT .pdfOrient Homes
 
Sales & Marketing Alignment: How to Synergize for Success
Sales & Marketing Alignment: How to Synergize for SuccessSales & Marketing Alignment: How to Synergize for Success
Sales & Marketing Alignment: How to Synergize for SuccessAggregage
 
Monthly Social Media Update April 2024 pptx.pptx
Monthly Social Media Update April 2024 pptx.pptxMonthly Social Media Update April 2024 pptx.pptx
Monthly Social Media Update April 2024 pptx.pptxAndy Lambert
 
Tech Startup Growth Hacking 101 - Basics on Growth Marketing
Tech Startup Growth Hacking 101  - Basics on Growth MarketingTech Startup Growth Hacking 101  - Basics on Growth Marketing
Tech Startup Growth Hacking 101 - Basics on Growth MarketingShawn Pang
 
Mysore Call Girls 8617370543 WhatsApp Number 24x7 Best Services
Mysore Call Girls 8617370543 WhatsApp Number 24x7 Best ServicesMysore Call Girls 8617370543 WhatsApp Number 24x7 Best Services
Mysore Call Girls 8617370543 WhatsApp Number 24x7 Best ServicesDipal Arora
 
It will be International Nurses' Day on 12 May
It will be International Nurses' Day on 12 MayIt will be International Nurses' Day on 12 May
It will be International Nurses' Day on 12 MayNZSG
 
Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...
Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...
Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...lizamodels9
 
MONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRL
MONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRLMONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRL
MONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRLSeo
 
Insurers' journeys to build a mastery in the IoT usage
Insurers' journeys to build a mastery in the IoT usageInsurers' journeys to build a mastery in the IoT usage
Insurers' journeys to build a mastery in the IoT usageMatteo Carbone
 
Monte Carlo simulation : Simulation using MCSM
Monte Carlo simulation : Simulation using MCSMMonte Carlo simulation : Simulation using MCSM
Monte Carlo simulation : Simulation using MCSMRavindra Nath Shukla
 

Recently uploaded (20)

Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...
 
Best VIP Call Girls Noida Sector 40 Call Me: 8448380779
Best VIP Call Girls Noida Sector 40 Call Me: 8448380779Best VIP Call Girls Noida Sector 40 Call Me: 8448380779
Best VIP Call Girls Noida Sector 40 Call Me: 8448380779
 
VIP Call Girls In Saharaganj ( Lucknow ) 🔝 8923113531 🔝 Cash Payment (COD) 👒
VIP Call Girls In Saharaganj ( Lucknow  ) 🔝 8923113531 🔝  Cash Payment (COD) 👒VIP Call Girls In Saharaganj ( Lucknow  ) 🔝 8923113531 🔝  Cash Payment (COD) 👒
VIP Call Girls In Saharaganj ( Lucknow ) 🔝 8923113531 🔝 Cash Payment (COD) 👒
 
Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...
Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...
Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...
 
Vip Dewas Call Girls #9907093804 Contact Number Escorts Service Dewas
Vip Dewas Call Girls #9907093804 Contact Number Escorts Service DewasVip Dewas Call Girls #9907093804 Contact Number Escorts Service Dewas
Vip Dewas Call Girls #9907093804 Contact Number Escorts Service Dewas
 
Regression analysis: Simple Linear Regression Multiple Linear Regression
Regression analysis:  Simple Linear Regression Multiple Linear RegressionRegression analysis:  Simple Linear Regression Multiple Linear Regression
Regression analysis: Simple Linear Regression Multiple Linear Regression
 
VIP Kolkata Call Girl Howrah 👉 8250192130 Available With Room
VIP Kolkata Call Girl Howrah 👉 8250192130  Available With RoomVIP Kolkata Call Girl Howrah 👉 8250192130  Available With Room
VIP Kolkata Call Girl Howrah 👉 8250192130 Available With Room
 
7.pdf This presentation captures many uses and the significance of the number...
7.pdf This presentation captures many uses and the significance of the number...7.pdf This presentation captures many uses and the significance of the number...
7.pdf This presentation captures many uses and the significance of the number...
 
Forklift Operations: Safety through Cartoons
Forklift Operations: Safety through CartoonsForklift Operations: Safety through Cartoons
Forklift Operations: Safety through Cartoons
 
Catalogue ONG NUOC PPR DE NHAT .pdf
Catalogue ONG NUOC PPR DE NHAT      .pdfCatalogue ONG NUOC PPR DE NHAT      .pdf
Catalogue ONG NUOC PPR DE NHAT .pdf
 
Sales & Marketing Alignment: How to Synergize for Success
Sales & Marketing Alignment: How to Synergize for SuccessSales & Marketing Alignment: How to Synergize for Success
Sales & Marketing Alignment: How to Synergize for Success
 
Monthly Social Media Update April 2024 pptx.pptx
Monthly Social Media Update April 2024 pptx.pptxMonthly Social Media Update April 2024 pptx.pptx
Monthly Social Media Update April 2024 pptx.pptx
 
Best Practices for Implementing an External Recruiting Partnership
Best Practices for Implementing an External Recruiting PartnershipBest Practices for Implementing an External Recruiting Partnership
Best Practices for Implementing an External Recruiting Partnership
 
Tech Startup Growth Hacking 101 - Basics on Growth Marketing
Tech Startup Growth Hacking 101  - Basics on Growth MarketingTech Startup Growth Hacking 101  - Basics on Growth Marketing
Tech Startup Growth Hacking 101 - Basics on Growth Marketing
 
Mysore Call Girls 8617370543 WhatsApp Number 24x7 Best Services
Mysore Call Girls 8617370543 WhatsApp Number 24x7 Best ServicesMysore Call Girls 8617370543 WhatsApp Number 24x7 Best Services
Mysore Call Girls 8617370543 WhatsApp Number 24x7 Best Services
 
It will be International Nurses' Day on 12 May
It will be International Nurses' Day on 12 MayIt will be International Nurses' Day on 12 May
It will be International Nurses' Day on 12 May
 
Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...
Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...
Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...
 
MONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRL
MONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRLMONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRL
MONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRL
 
Insurers' journeys to build a mastery in the IoT usage
Insurers' journeys to build a mastery in the IoT usageInsurers' journeys to build a mastery in the IoT usage
Insurers' journeys to build a mastery in the IoT usage
 
Monte Carlo simulation : Simulation using MCSM
Monte Carlo simulation : Simulation using MCSMMonte Carlo simulation : Simulation using MCSM
Monte Carlo simulation : Simulation using MCSM
 

Fit for Service - A strategy for service organizations.

  • 1. Fit for Service A strategy for service organizations. Michael Werneburg, 2013.04.13 Updated 2015.11.16
  • 2. TL;DR A technology & service provider can have great products and still get nowhere because the clients lack trust. An enterprise risk function can overcome this by guiding improvements to service consistency. Bend your audits to shift your focus & capabilities, then use your audit report as a hall pass.
  • 3. You want to sell to the financial industry. But it’s becoming harder.
  • 4. The target market—banks and life insurance firms—are jointly called “federally regulated entities”. They are accountable to several regulators domestically and abroad. OSFI CSA IIROCOSC MFDA FSCO
  • 5. DEEPLY Of particular interest to regulators is the preservation at the regulated entity of strong corporate governance. In this regard outsourcing activities that may impede an outsourcing firm's management from fulfilling its regulatory responsibilities are of concern to regulators. The rapid rate of IT innovation, along with an increasing reliance on external service providers have the potential of leading to systemic problems unless appropriately constrained by a combination of market and regulatory influences. Outsourcing in Financial Services. Basel Committee on Banking Supervision, Bank of International Settlement, 2005 http://bit.ly/1kGr8wv The regulators are deeply concerned with third party risk.
  • 6. Selling information services to these regulated entities means meeting their stringent regulations. The vetting process for a new vendor can involve 80-page RFI’s full of questions.
  • 7. Dealing with these requirements ad-hoc can be difficult, lengthy, and disruptive. ITLegalComplianceRisk Mgmt. PMOVendor Mgmt. …
  • 8. But these clients now also want annual service audits and SOC-2 attestation reports. Passing these audits can require new activities for your firm, and hundreds of new internal controls. (You do have internal controls, right?)
  • 9. Your clients know the risks can be complex. Fatal to the relationship. Even “systemic”.
  • 10. What to do Turn the problem into a strength.
  • 11. The service you offer is where you have chosen to compete. Performing at the mandated level is how you will win.1 You can leverage the risk management function to get you there. 1. Drucker. Or someone.
  • 12. Key outcomes: • Consistently excel in all points of contact with clients. • Optimize the fit between internal activities. • Adopt managed change as a way of life.
  • 13. Implementing a “fitness” regime How to turn this mess around and build a resilient business that performs.
  • 14. The evolving SOC-2 standard is embodied in the AICPA’s “trust services principles and criteria”1. 1. http://bit.ly/1luCdHr It sets the level of performance, and suggests a governance framework to monitor and foster progress.
  • 15. DO NOT just approach this as a huge list of controls to implement. Instead, step back and understand what you’re really doing: altering your company forever.
  • 16. I’ve written about this here1 and here2. 1. http://risktopics.com/service-audits-are-risky-business 2. http://risktopics.com/a-strategic-approach-to-the-value-chain But it’s a fairly simple. When we make changes to our core practices, we’re building a new company.
  • 17. Put it this way: your technology firm already has standards and practices. But you’re about to review hundreds of these, and start making changes.
  • 18. Your business is a unique collection of processes and competencies. The crucial ones span departments, and add value to your clients1. Change those crucial processes and competencies, and you’re finding a new unique mix. 1. Porter. And then everyone.
  • 19. It’s a new company! But not just any new.
  • 20. You’ll build a more consistent company. Consistency is the heart of culture, and of brand1. Consistency is a natural outcome of the governance function built into the audit process. 1. Porter, again.
  • 21. You’ll also be building a more competent firm; when you build governance into your processes, your people eliminate uncertainty. A certain company where everyone understands their role and what to do next.
  • 22. When your people understand that they are responsible for reaching a certain bar for achievement, something magical happens. People who have taken a quality standard to heart expect quality in everything they do.
  • 23. Even when no auditor is watching. Adults don’t say, “Oh, we have to do X and Y right, but the auditor’s not looking at Z.”
  • 24. A holistic approach can make all this happen. This is “doing things the hard way”. But an unplanned approach will leave your firm with a countless, seemingly unrelated, controls.
  • 25. Again, I’ve written about this here1 and here2. 1. http://risktopics.com/service-audits-are-risky-business 2. http://risktopics.com/a-strategic-approach-to-the-value-chain But enough; let’s have a look at the company that emerges.
  • 26. A Case Study The story of a successful approach to SOC-2, by a technology & service provider.
  • 27. We were a fifteen person firm. With one client. And big ambitions. We’d been in business for a decade. But new, regulated clients wanted that SOC-2.
  • 28. We were a fifteen person firm. With one client. And big ambitions. We’d been in business for a decade. We did SOC-2 “the easy way”, implemented countless controls.
  • 29. Executive: setting and communicating objectives; evaluating operations and financial performance; service level management; business continuity planning; budget approval; vendor management. Human Resources: background checks; asset entitlements management; hiring and termination policies; privacy; acceptable use; code of conduct; confidentiality; whistle- blowing; site security; staff evaluations. IT: SDLC; change control; disaster recovery; technology standards; patch management; security incident management; information classification; log monitoring; viruses; bring-your- own-device; data disposal; encryption; firewall management; remote access. Internal control: internal audit; risk management; policy management. (This is a sample; It is not practical to list everything.) The scope was daunting.
  • 31. We did not know where we were going. As unplanned as our initiative was, it began to pay off at once.
  • 32. 1. Immediate sales benefits • Easy RFP’s and RFI’s. Just hand over the documentation. • No more one-off requests for proof of capability from vendor managers, IRM, legal, etc. • Shortened and easier sales cycle.
  • 33. In the words of one software executive; “Now that we have our audit report, we’re having a whole other level of discussion. The gate-keepers simply ask for the report and we’re done. Everyone thanks us for making their jobs easier.”
  • 34. 2. Operations running smoothly: • Delivering software updates in a reliable fashion (1 error in 557 releases) • Hosting our service in a secure and uninterrupted fashion (no downtime after four years and counting). • Stable processes free the time of SME’s and management.
  • 35. 3. Life was easier for existing clients • No more one-off requests for proof of capability from vendor managers, IRM, legal, etc. • Improved “story” for service owners. • More interest in expanding services with us.
  • 36. Confident and transparent • Reduced need for monitoring by clients. None has ever called for an ad-hoc audit. • Clarity around roles and responsibilities. • Comprehensive service level attainment is demonstrable through reporting.
  • 37. 4. Leaders free to make decisions and lead: • Far fewer procedural questions. • Far fewer mistakes due to uncertainty or improper process. • Stable processes free the time of SME’s and management.
  • 38. Cross-team processes smooth: • Mature practices mean teams work together as expected. • Entrusting functional managers with governance process leads to automatic correction of deviations. • A strong sense of ownership of product and service.
  • 39. 5. Low turnover: • People not wearing out from rework and confusion. • They enjoy the blend of responsibility and quality outputs. • Stable processes free the time of SME’s and management.
  • 40. 6. Growth: • Stable processes allow a business to scale. • Problems that creep in turn up at the first quarterly risk control self-assessment. • Persistent problems turn up in the auditors’ report.
  • 41. 7. The magic of being “approved”: • Having that audit report indicates that you’re part of the regulated industry. • Once you’re reached the level of being an approved vendor, you’ll find yourself able to rapidly grow in your industry. • Partners will seek you out. Others will more readily accept you as a mature organization with the right types of clients.
  • 42. These things occurred to us with time. And only when we had gone through rounds of corrections sensing that they were possible.
  • 43. The results are worth it. Your challenge is to do it “the hard way”, to realize the benefits the first time.
  • 44. Having a great product got you to the door. Your risk management capabilities are the security pass to get you in and keep you in.
  • 45. I can help My role as a specialist in governance, risk, and strategy.
  • 46. Reach out! I like to advise: • Understanding risk analysis (MSc in Risk Management). • Understanding service delivery strategies (20+ years experience). • Understanding IT and IT governance frameworks (e.g. ITIL, COBIT). • Mapping the governance framework to business strategy. • Knowledge of regulated financial industries and the software/service firms that support them. • Business process renewal and the writing of process manuals. • Managing the auditors. (Certified Internal Auditor designation). • Project management (I am a PMP).