SlideShare ist ein Scribd-Unternehmen logo
1 von 44
Downloaden Sie, um offline zu lesen
Raimund Laqua, PMP, P.Eng
ray.laqua@leancompliance.ca
WWW.LEANCOMPLIANCE.CA
PREPARING FOR
POST COVID-19
FROM CRISIS TO RECOVERY
WWW.LEANCOMPLIANCE.CA
PREPARING FOR POST COVID-19
The Big Idea
As the lifting of Covid-19 restrictions begin all around the world, companies
are starting to transition to a next normal for their business. This requires a
risk-based business recovery plan that:
• Reimagines what normal looks like
• Safely restarts operations
• Recovers business that was lost
• Reinforces defenses against future uncertainty
This is an opportunity for risk & compliance to be at the table to lead and
coordinate efforts to improve the probability of mission success.
WWW.LEANCOMPLIANCE.CA
☐Implemented, and underway
☐Completed, and ready to go
☐Developing, and going well.
☐Started, and struggling to get it done.
☐Not started.
PREPARING FOR POST COVID-19
1. What is the status of your business recovery plan?
Webinar Poll
WWW.LEANCOMPLIANCE.CA
PREPARING FOR POST COVID-19
Outline
Outcome:
Understand what a risk-based
business recovery plan consists of
that addresses the risks that
really matter to improve the
probability of mission success.
Outline:
1. Risk Context
2. Risk Assessment
3. Risk Attitude
4. Risk Scenarios
5. Risk Treatment
COVID-19 CRISIS COVID-19 RECOVERY
WWW.LEANCOMPLIANCE.CA
PREPARING FOR POST COVID-19
1. Risk Context
To establish the context means to define the external and internal
parameters that organizations must consider when they manage risk.
An organization’s external context includes its external stakeholders,
its local, national, and international environment, as well as any
external factors that influence its objectives.
An organization’s internal context includes its internal stakeholders,
its approach to governance, its contractual relationships, and its
capabilities, culture, and standards.
† https://www.praxiom.com/iso-31000.htm
WWW.LEANCOMPLIANCE.CA
PREPARING FOR POST COVID-19
1. Risk Context
☐ Impacts due to COVID-19: health, supply, demand, operations
☐ Employee rights to refuse work if workplace is unsafe
☐ Ethical and legal concerns with respect to contact tracing, and
proximity technologies
☐ Obligations at risk, deferred obligations that are coming due
☐ Business assumptions challenged
☐ Reduction in workforce: lay offs, retention, etc.
☐ Changing definition of what the next "normal" looks like
☐ Remote work
☐ Contract failures and disputes arising from COVID-19
☐ Increased litigation and lawsuits
☐ Worker health checks and monitoring
☐ Lineups at elevators, shift work, and distanced desks
☐ New safety guidelines and conditions to resume operations
☐ Staggered recovery of businesses
☐ Anticipated second COVID-19 wave, recession
COVID-19 CRISIS
Which factors really matter?
PREPARING FOR POST COVID-19
1. Risk Context
Mission
Quality
Health & Safety
Security
Environmental
Process Safety
Pipeline Safety
Food Safety
Patient Safety
Conformance
to Industry Standards
Conformance
to Legal Requirements
Accept Stakeholder
Responsibilities
Accept Public
Responsibilities
Institutional Risk
Missional Risk
Operational Risk
Reputational Risk
Cyber Risk
Financial Risk
Third Party Risk
Sustainability Risk
Public Safety Risk
Trustability Risk
Legal
Regulatory
Ethics
Code of Conduct
Contracts
Certifications
Public Safety
Social License
Regulatory License
WWW.LEANCOMPLIANCE.CA
• Voluntary
• Outcome-focused
• Risk-based
• Learn / Improve
• Proactive
• Mandatory
• Rules-focused
• Prescriptive
• Audit / Fix
• Reactive
ORGANIZATIONAL CORPORATERISK
What is the status of compliance obligations?
PREPARING FOR POST COVID-19
1. Risk Context
† Modified Value Chain Analysis (Michael Porter)
PRODUCTIVTY
Inbound
Logistics
Operations Outboun
d
Logistics
Marketing
&
Sales
Service
Inbound
Logistics
Outboun
d
Logistics
Marketing
&
Sales
ServiceOperations
ETHICS & REGULATORY
ENVIRONMENTAL
SAFETY & SECURITY
QUALITY
RISK&COMPLIANCE
RISK
VALUE
CHAIN
Sustainability
Reputation
Quality
Safety
Trust
OUTCOMESTRANSFORMATION
M
A
R
G
IN
INBOUND
LOGISTICS
OPERATIONS OUTBOUND
LOGISTICS
MARKETING
&
SALES
SERVICE
INFRASTRUCTURE
HUMAN RESOURCE
TECHNOLOGY
PROCUREMENT
TOTALVALUE
Profit
Growth
Margins
Efficiency
Productivity
WWW.LEANCOMPLIANCE.CA
Where does risk and compliance contribute to outcomes
WWW.LEANCOMPLIANCE.CA
PREPARING FOR POST COVID-19
1. Risk Context
• When will the money run out?
• When will the lay offs begin?
• When will we close for good?
Crisis Management
• What risks really matter?
• What risks can we buy down?
• What risks require margin?
Risk Management
• What is the next normal?
• How do we get there?
• What resources do we need?
• What threats or opportunities
should we consider?
• How do we measure our progress?
Change
Management
Which management approach should be used?
WWW.LEANCOMPLIANCE.CA
PREPARING FOR POST COVID-19
1. Risk Context
“Over the years, compliance officers have designed and implemented the
now recognized three pillars of an effective compliance system: prevent,
detect and respond, including monitoring and remediation.
This system is equally valid for all relevant risk functions in a corporation,
including health, safety and environment, business continuity and
emergency management, data privacy, quality, IT security, finance and
others.
Instead of being “just another workstream,” courageous, risk-aware and
crisis-resilient compliance officers can rightfully claim consideration for
the lead or at least the coordination of an integrated risk management
system in corporations."
– Dr. Klaus Moosmayer
COMPLIANCE OFFICER ROLE
Which role will lead the recovery?
WWW.LEANCOMPLIANCE.CA
☐Chief Executive Officer (CEO)
☐Chief Compliance / Risk Officer (CCO) or (CRO)
☐Crisis Team / Task force
☐Committee
☐No one
PREPARING FOR POST COVID-19
2. Who is leading your recovery efforts?
Webinar Poll
WWW.LEANCOMPLIANCE.CA
PREPARING FOR POST COVID-19
Outline
Outcome:
Understand what a risk-based
business recovery plan consists of
that addresses the risks that
really matter to improve the
probability of mission success.
Outline:
1. Risk Context
2. Risk Assessment
3. Risk Attitude
4. Risk Scenarios
5. Risk Treatment
COVID-19 CRISIS COVID-19 RECOVERY
WWW.LEANCOMPLIANCE.CA
PREPARING FOR POST COVID-19
2. Risk Assessment
Risk assessment is a process that is made up of three separate processes: risk
identification, risk analysis, and risk evaluation.
Risk identification is a process that is used to find, recognize, and describe the
risks that could affect the achievement of objectives.
Risk analysis is a process that is used to understand the nature, sources, and
causes of the risks that you have identified and to estimate the level of risk. It
is also used to study impacts and consequences and to examine the controls
that exist.
Risk evaluation is a process that is used to compare risk analysis results with
risk criteria in order to determine whether or not a specified level of risk is
acceptable or tolerable.
† https://www.praxiom.com/iso-31000.htm
WWW.LEANCOMPLIANCE.CA
PREPARING FOR POST COVID-19
2. Risk Assessment
COVID-19 PANDEMIC COVID-19 SHUTDOWN COVID-19 IMPACTS
How do we control transmission? How do we survive the crisis? How do we recover?
RISK
SOURCES
WWW.LEANCOMPLIANCE.CA
PREPARING FOR POST COVID-19
RISK MEASURES
RISK SCENARIO
2. Risk Assessment
• Collect data, develop tests, work on a vaccine
• Introduce safety measures: washing hands, social
distancing, self-isolation, reduce travel, PPE, etc.
• Prepare for significant increase in hospitalization
• “Flatten the curve”
• New variant of the corona virus
• Worldwide pandemic, Infection rate 2.5
• Impacts are asymmetric
• No vaccine
• Deaths 284,000 / Cases 4,200,957
• Significant uncertainty
LOSS OF LIFE
CAUSES
CONSEQUENCES
PREVENTIVE
CONTROLS
MITIGATIVE
CONTROLS
LOSS OF LIFE
MAJOR SYMPTOMS
MINOR SYMPTOMS
NO SYMPTOMS
ECONOMIC SLOWDOWN
WASHING HANDS, SELF ISOLATION,
SOCIAL DISTANCING,
ECONOMIC SHUTDOWN
QUARANTINE,
HOSPITALIZATION,
RESERVES
INFECTED PERSON
SURFACES
HYGIENE
THREAT
COVID-19 PANDEMIC
How do we control transmission?
WWW.LEANCOMPLIANCE.CA
PREPARING FOR POST COVID-19
RISK MEASURES
RISK SCENARIO
2. Risk Assessment
• Declared Emergency / Crisis
• Quarantine as many as possible (shutdown
borders, travel, economy, public spaces, etc.)
• #StayAtHome / Shelter-in-place
• Governments introduce emergency programs
• Businesses activate crisis management teams:
• when will the money run out?
• when will lay offs begin?
• when will we close for good?
• Transmission of COVID-19 multiplies
• Increase in number of cases and deaths
• No vaccine and “treatment” options are limited
• Identification of hot spots, super spreaders
• Panic increases
CAUSES
CONSEQUENCES
PREVENTIVE
CONTROLS
MITIGATIVE
CONTROLS
LOSS OF BUSINESS, LOSS OF LIVELIHOOD
LOSS OF BUSINESS
LOSS OF LIVELIHOOD
LOSS OF HOME
FAMILY BREAKDOWN
PERSONAL BANKRUPTCY
RESERVES, SAVINGS, GOVERNMENT SUPPORT,
FAMILY SUPPORT, COUNSELLING,
NEW BUSINESS, NEW LIVELIHOOD
SAFETY MEASURES
ECONOMIC SLOWDOWN
REDUCTION OF WORKFORCE
THREAT
NONE
COVID-19 SHUTDOWN
How do we survive the crisis?
WWW.LEANCOMPLIANCE.CA
PREPARING FOR POST COVID-19
2. Risk Assessment
COVID-19 IMPACTS
RISK MEASURES
RISK SCENARIO
• Pandemic continues
• Curve is flattening
• Reserves and contingencies running out
• Increase in layoffs and unemployment (20%)
• Closures and bankruptcies
• Significant market disruptions
• Increased vulnerabilities: cyber risk, operational risk, etc.
• Long tail of impacts
• Anticipated second wave, recession, ?
CAUSES
CONSEQUENCES
PREVENTIVE
CONTROLS
MITIGATIVE
CONTROLS
THREAT
CAUSES
CONSEQUENCES
ENABLE
CONTROLS
EXPLOIT
CONTROLS
OPPORTUNITY
How do we recover?
LOSS OF LIFE,
LOSS OF BUSINESS,
LOSS OF LIVELIHOOD
BETTER LIFE,
BETTER BUSINESS,
BETTER LIVELIHOOD
WWW.LEANCOMPLIANCE.CA
PREPARING FOR POST COVID-19
ORDER
• The place you are when
what you do works
• Predictable / Certain
• Occasional chaos
• Deterministic
• Routine
• Underwhelming
Order Chaos
2. Risk Assessment
CHAOS
• The place you are when
what you do doesn’t work
• Unpredictable / Uncertain
• Occasional order
• Random
• Abnormal
• Overwhelming
Uncertainty creates the opportunity for risk
WWW.LEANCOMPLIANCE.CA
☐Certain – Order, with occasional chaos.
☐Ambiguous – On the edge between order and chaos.
☐Uncertain – Chaos, with occasional order.
PREPARING FOR POST COVID-19
3. What is your level of uncertainty with respect to your mission objectives?
Webinar Poll
WWW.LEANCOMPLIANCE.CA
PREPARING FOR POST COVID-19
Outline
Outcome:
Understand what a risk-based
business recovery plan consists of
that addresses the risks that
really matter to improve the
probability of mission success.
Outline:
1. Risk Context
2. Risk Assessment
3. Risk Attitude
4. Risk Scenarios
5. Risk Treatment
COVID-19 CRISIS COVID-19 RECOVERY
WWW.LEANCOMPLIANCE.CA
PREPARING FOR POST COVID-19
3. Risk Attitude
An organization’s risk attitude defines its general approach to risk. An
organization’s risk attitude (and its risk criteria) influence how risks are
assessed and addressed. An organization’s attitude towards risk affects
whether or not risks are taken, tolerated, retained, shared, reduced, or
avoided, and whether or not treatments are implemented or postponed.
† https://www.praxiom.com/iso-31000.htm
WWW.LEANCOMPLIANCE.CA
PREPARING FOR POST COVID-19
3. Risk Attitude
Strategist
Let’s improve the
probability of success
RISK
STRATEGIST
Avoider
I don’t want
any risk
RISK
INTOLERANT
Gambler
Let’s play
the odds
RISK
SEEKING
Ostrich
I don’t want
to know
RISK
TOLERANT
Manager
Let’s size the risk
and decide
RISK
NEUTRAL
Our attitude towards risk affects our approach
WWW.LEANCOMPLIANCE.CA
• Protect (guard) against loss
• Minimize variation by preventing or recovery
from threats
• Focus on efficiency (cost, schedule,
performance)
• Pay attention to what might cause failure
and what could go wrong
PREPARING FOR POST COVID-19
• Ensure (make certain of) outcomes
• Maximize value by enabling and exploiting
opportunities
• Focus on effectiveness (outcomes, value
creation, benefits realization)
• Pay attention to what is critical to success
and what needs to go right
Avoid Failure Pursue Success
3. Risk Attitude
Objectives of a Risk Strategist
WWW.LEANCOMPLIANCE.CA
☐Ostrich, I don’t want to know.
☐Avoider, I don’t want any risk.
☐Manager, let’s do the math.
☐Gambler, let’s play the odds.
☐Strategist, let’s improve the probability of success.
PREPARING FOR POST COVID-19
4. What is your attitude towards risk?
Webinar Poll
WWW.LEANCOMPLIANCE.CA
PREPARING FOR POST COVID-19
Outline
Outcome:
Understand what a risk-based
business recovery plan consists of
that addresses the risks that
really matter to improve the
probability of mission success.
Outline:
1. Risk Context
2. Risk Assessment
3. Risk Attitude
4. Risk Scenarios
5. Risk Treatment
COVID-19 CRISIS COVID-19 RECOVERY
WWW.LEANCOMPLIANCE.CA
PREPARING FOR POST COVID-19
4. Risk Scenarios
Scenario analysis is a process of analyzing future events by considering
alternative possible outcomes (sometimes called "alternative worlds"). Thus,
scenario analysis, which is one of the main forms of projection, does not try to
show one exact picture of the future. Instead, it presents several alternative
future developments.
It does not rely on historical data and does not expect past observations to
remain valid in the future. Instead, it tries to consider possible developments
and turning points, which may only be connected to the past. In short, several
scenarios are fleshed out in a scenario analysis to show possible future
outcomes
† https://en.wikipedia.org/wiki/Scenario_analysis
WWW.LEANCOMPLIANCE.CA
PREPARING FOR POST COVID-19
4. Risk Scenarios
COVID-19 PANDEMIC COVID-19 SHUTDOWN COVID-19 IMPACTS
How do we control transmission? How do we sruvive the crisis? How do we recover?
How do we restart safely? How do we recover our business? How do we reinforce our defenses?
RESTART RECOVER REINFORCE
What is the next normal?
REIMAGINE
RISK
SCENARIOS
RISK
SOURCES
WWW.LEANCOMPLIANCE.CA
PREPARING FOR POST COVID-19
4. Risk Scenarios
RISK SCENARIOS
• What are possible next normals?
• Which ones address the risks that really matter?
• Which ones need to happen first (are their dependencies?)
• Which ones do you build your business recovery plan around?
WWW.LEANCOMPLIANCE.CA
☐Minor, business assumptions are mostly valid.
• tactical / safety changes are needed.
☐Moderate, significant changes to business assumptions.
• business model,
• tactical / safety changes are needed.
☐Major, business assumptions no longer valid.
• entire business strategy needs to be re-evaluated.
PREPARING FOR POST COVID-19
5. What is the level of impact caused by COVID-19 on your business?
Webinar Poll
WWW.LEANCOMPLIANCE.CA
PREPARING FOR POST COVID-19
4. Risk Scenarios
Who is leading
the recovery
effort?
What is the level of
uncertainty?
What is the risk
attitude?
What is the level of
impact caused by
COVID-19?
What phases are
necessary to
resume operations?
What type of
change is required?
CEO Certain Ostrich Minor Restart Tactical / Safety
CCO / CRO Ambiguous Avoider Moderate Recover Business Model
Crisis Team /
Task Force
Uncertain Manager Major Reinforce Business Strategy
Committee Gambler
No One Strategist
Scenario Decision Matrix
WWW.LEANCOMPLIANCE.CA
PREPARING FOR POST COVID-19
5. Risk Scenarios
Who is leading
the recovery
effort?
What is the level of
uncertainty?
What is the risk
attitude?
What is the level of
impact caused by
COVID-19?
What phases are
necessary to
resume operations?
What type of
change is required?
CEO Certain Ostrich Minor Restart Tactical / Safety
CCO / CRO Ambiguous Avoider Moderate Recover Business Model
Crisis Team /
Task Force
Uncertain Manager Major Reinforce Business Strategy
Committee Gambler
No One Strategist
Scenario #1 – TACTICAL / SAFETY CHANGE LOW RISK
WWW.LEANCOMPLIANCE.CA
PREPARING FOR POST COVID-19
4. Risk Scenarios
Who is leading
the recovery
effort?
What is the level of
uncertainty?
What is the risk
attitude?
What is the level of
impact caused by
COVID-19?
What phases are
necessary to
resume operations?
What type of
change is required?
CEO Certain Ostrich Minor Restart Tactical / Safety
CCO / CRO Ambiguous Avoider Moderate Recover Business Model
Crisis Team /
Task Force
Uncertain Manager Major Reinforce Business Strategy
Committee Gambler
No One Strategist
Scenario #2 – BUSINESS MODEL CHANGE MEDIUM RISK
WWW.LEANCOMPLIANCE.CA
PREPARING FOR POST COVID-19
4. Risk Scenarios
Who is leading
the recovery
effort?
What is the level of
uncertainty?
What is the risk
attitude?
What is the level of
impact caused by
COVID-19?
What phases are
necessary to
resume operations?
What type of
change is required?
CEO Certain Ostrich Minor Restart Tactical / Safety
CCO / CRO Ambiguous Avoider Moderate Recover Business Model
Crisis Team /
Task Force
Uncertain Manager Major Reinforce Business Strategy
Committee Gambler
No One Strategist
Scenario #3 – BUSINESS STRATEGY CHANGE HIGH RISK
WWW.LEANCOMPLIANCE.CA
☐Scenario #1 – Tactical / Safety
☐Scenario #2 – Business Model, includes #1
☐Scenario #3 – Business Strategy, includes #2 and #1
☐Not sure
PREPARING FOR POST COVID-19
6. Which scenario should your organization consider?
Webinar Poll
WWW.LEANCOMPLIANCE.CA
PREPARING FOR POST COVID-19
Outline
Outcome:
Understand what a risk-based
business recovery plan consists of
that addresses the risks that
really matter to improve the
probability of mission success.
Outline:
1. Risk Context
2. Risk Assessment
3. Risk Attitude
4. Risk Scenarios
5. Risk Treatment
COVID-19 CRISIS COVID-19 RECOVERY
WWW.LEANCOMPLIANCE.CA
PREPARING FOR POST COVID-19
5. Risk Treatment
Risk treatment is a risk modification process. It involves selecting and
implementing one or more treatment options. Once a treatment has been
implemented, it becomes a control, or it modifies existing controls.
You have many treatment options. You can avoid the risk, you can
reduce the risk, you can remove the source of the risk, you can modify
the consequences, you can change the probabilities, you can share the
risk with others, you can simply retain the risk, or you can even increase
the risk in order to pursue an opportunity.
† https://www.praxiom.com/iso-31000.htm
3. Do we have everything
we need to get the next
NORMAL?
1. What is the next
NORMAL?
5. What threats or
opportunities will we
encounter on the way
to the next NORMAL?
2. How do we get to
the next NORMAL?
4. How do we measure
our progress towards
the next NORMAL?
DESTINATION PLAN RESOURCES PROGRESS RISK
WWW.LEANCOMPLIANCE.CA
PREPARING FOR POST COVID-19
5. Risk Treatment
Each scenario must have compelling answers to these questions
WWW.LEANCOMPLIANCE.CA
PREPARING FOR POST COVID-19
5. Risk Treatment
• Define scenario: what are the business assumptions, what is the next
normal, how do we get there, what resources do we need, and how will
progress be measured.1. Define
• Introduce pre-mortem: open and honest discussion and imagine that your
company failed, and that it succeeded. In addition, estimate uncertainties.2. Introduce
• Debrief discussions: all team members describe why your company failed,
and why your company succeeded.3. Debrief
• Prioritize risk: separate into reducible (what you can buy down), and
irreducible (what you treat with margins).4. Prioritize
• Brainstorm handling strategies: identify steps to buy down risk or treat with
margins.5. Brainstorm
• Update Business Recovery Plan and Risk Register.
6. Document
SCENARIO RISK CANVAS
PREMORTEM1. DESTINATION
3. RESOURCES
2. PLAN 5. RISK
4. PROGRESS
UNCERTAINTIES
Do we have everything we need?
What does NORMAL look like?
Reducible / Buy down
How do we measure progress?
Why did we fail?
How do we get to NORMAL?
What didn’t we know?
Why did we succeed? What didn’t we control? Irreducible / Treat with Margin
What threats or opportunities
hinder or advance progress?
0. ASSUMPTIONS
SCENARIO:
SCENARIO RISK CANVAS
PREMORTEM1. DESTINATION
3. RESOURCES
2. PLAN 5. RISK
4. PROGRESS
UNCERTAINTIES
Sustainable critical safety roles
Additional office space
Enhanced cyber protection
Sustainable supply of PPE
Critical systems available remotely
Training for remote workers
Do we have everything we need?
COVID-19 Safety measures in place
Management reviews include safety
Operationalize remote work
Operationalize workplace distancing
Operational readiness @ 65% capacity
Pre-startup Safety Review include COVID
Sustainable supply chain
What does NORMAL look like?
T - Cyber risk
T - COVID-19 Infection
T- Weaker product demand
T- Supply chain vulnerabilities
O - Increase customer relationship
O - Improve workforce alignment
Reducible / Buy down
Operational readiness level
Corporate climate level
Supplier quality levels
Customer engagement levels
Product demand
How do we measure progress?
Didn’t prepare for second wave
Didn’t prepare for long term impacts
Didn’t’ prepare for another lockdown
Didn’t build up reserves
We didn’t’ address negativity
Didn’t train workforce for remote work
Didn’t strengthen IT systems
Why did we fail?Identify COVID-19 safety measures
Identify additional risk measures
Implement COVID-19 safety measures
Implement additional risk measures
Develop communication plan
Identify gating conditions for startup
Build up corporate morale
Improve remote access to systems
How do we get to NORMAL?
The long-term effects on our customers
Supply chain vulnerability
Weaker product demand
Critical safety functions not performing
What didn’t we know?
Continuous Risk Management
Maintained healthy workforce
Increased reserves
Increased cyber threat protection
Stayed connected with customers
Better remote work capabilities
Stayed connected with suppliers
Why did we succeed?
COVID-19 Transmission
Cyber risk
Corporate climate
Supply chain quality
Critical to Quality
Critical to Safety
Critical to Compliance
What didn’t we control?
COVID-19 Lockdown
Litigation
Irreducible / Treat with Margin
What threats or opportunities
hinder or advance progress?
0. ASSUMPTIONS
Demand will return to 80% by EOY
Existing business model valid and viable
Workforce morale is low
Impacts will continue until end of 2021
Integrity of value chain is a concern
Shareholder trust is high, but concerned
SCENARIO: #1 Tactical / Safety
O - Introduce digital services
WWW.LEANCOMPLIANCE.CA
PREPARING FOR POST COVID-19
5. Risk Treatment
NO. OBJECTIVE UNCERTAINTY
ESTIMATE
UNCERTAINTY
TYPE
RISK
(EFFECT OF UNCERTAINTY ON
OBJECTIVES)
PREVENTIVE MEASURES RECOVERY
MEASURES
1.1 Control transmission of COVID-19 at the
work site to acceptable levels as
reasonably practicable per provincial
guidelines.
Medium Reducible As a result of ineffective safety
measures,, infection may occur, leading
to health impacts.
Social Distancing
Face Masks
Remote Work
Shift work
Desk distancing
Disinfection Protocols
Employee Temperature monitoring
Quarantine
Hospitalization
1.2 Maintain safe operations of the plant. Low Reducible and
Irreducible
As a result of a reduction in workforce,
critical safety activities may not occur,
leading to an increase in safety incidents.
Pre-startup Safety Review Incident investigations
Emergency response
Insurance
1.3 Achieve operational readiness
compliant with all performance, safety,
security, quality, environmental,
regulatory obligations.
Medium Reducible As a result of a plant shutdown during
COVID-19, achieving stable operations
upon startup may not occur, leading to
more downtime.
Conduct operational readiness
assessment as per company policy
Execute contingency plan.
1.4 Improve cyber threat protection
capabilities
High Reducible As a result of increased cyber attacks, a
security breach may occur, leading to a
leak of private information.
Conduct Cyber Risk Resiliency
assessment
Strengthen threat protection
Incident Response
Incident Investigations
Insurance
Objective-based Risk Register: Scenario #1 - Tactical / Safety
Effective risk treatment requires effective compliance of risk measures
WWW.LEANCOMPLIANCE.CA
PREPARING FOR POST COVID-19
The Big Idea
As the lifting of Covid-19 restrictions begin all around the world, companies
are starting to transition to a next normal for their business. This requires a
risk-based business recovery plan that:
• Reimagines what normal looks like
• Safely restarts operations
• Recovers business that was lost
• Reinforces defenses against future uncertainty
This is an opportunity for risk & compliance to be at the table to lead and
coordinate efforts to improve the probability of mission success.
WWW.LEANCOMPLIANCE.CA
PREPARING FOR
POST COVID-19
FROM CRISIS TO RECOVERY
WHAT WILL YOU DO NEXT?
FREE COVID-19 MEMBERSHIP PACKAGE
ADDITIONAL RESOURCES
www.leancompliance.ca/members
Additional resources available:
COVID-19 Membership Package (FREE)
Sign up here:
www.leancompliance.ca/members

Weitere ähnliche Inhalte

Was ist angesagt?

GP Safety Culture in NB - finished
GP Safety Culture in NB - finishedGP Safety Culture in NB - finished
GP Safety Culture in NB - finished
Larry Harlow
 
Risk Management for Online PR
Risk Management for Online PRRisk Management for Online PR
Risk Management for Online PR
David Phillips
 
The Importance of Risk Management
The Importance of Risk ManagementThe Importance of Risk Management
The Importance of Risk Management
Vigilant Software
 
White paper holistic_approach_to_government_continuity_of_operations_apr2014
White paper holistic_approach_to_government_continuity_of_operations_apr2014White paper holistic_approach_to_government_continuity_of_operations_apr2014
White paper holistic_approach_to_government_continuity_of_operations_apr2014
EMC
 

Was ist angesagt? (20)

GP Safety Culture in NB - finished
GP Safety Culture in NB - finishedGP Safety Culture in NB - finished
GP Safety Culture in NB - finished
 
Human factors in major hazard safety Ronny Lardner
Human factors in major hazard safety  Ronny LardnerHuman factors in major hazard safety  Ronny Lardner
Human factors in major hazard safety Ronny Lardner
 
COVID-19: How Businesses Are Handling the Crisis
COVID-19: How Businesses Are Handling the CrisisCOVID-19: How Businesses Are Handling the Crisis
COVID-19: How Businesses Are Handling the Crisis
 
Progressive Audio Presentation 042010
Progressive Audio Presentation 042010Progressive Audio Presentation 042010
Progressive Audio Presentation 042010
 
A holistic approach to Safety and Asset Integrity Excellence
A holistic approach to Safety and Asset Integrity ExcellenceA holistic approach to Safety and Asset Integrity Excellence
A holistic approach to Safety and Asset Integrity Excellence
 
Risk Management for Online PR
Risk Management for Online PRRisk Management for Online PR
Risk Management for Online PR
 
2010; Risk Management Workshop Rev.1.1
2010; Risk Management Workshop Rev.1.12010; Risk Management Workshop Rev.1.1
2010; Risk Management Workshop Rev.1.1
 
The Importance of Risk Management
The Importance of Risk ManagementThe Importance of Risk Management
The Importance of Risk Management
 
2020 IIS global concerns report
2020 IIS global concerns report2020 IIS global concerns report
2020 IIS global concerns report
 
Risk Assessment Methodologies
Risk Assessment MethodologiesRisk Assessment Methodologies
Risk Assessment Methodologies
 
Risk management osh
Risk management oshRisk management osh
Risk management osh
 
Risk Management Training
Risk Management TrainingRisk Management Training
Risk Management Training
 
Evolving Risk Indicators
Evolving Risk IndicatorsEvolving Risk Indicators
Evolving Risk Indicators
 
ARC's Bob Mick's Cyber Security Standards Presentation at ARC's 2008 Industry...
ARC's Bob Mick's Cyber Security Standards Presentation at ARC's 2008 Industry...ARC's Bob Mick's Cyber Security Standards Presentation at ARC's 2008 Industry...
ARC's Bob Mick's Cyber Security Standards Presentation at ARC's 2008 Industry...
 
White paper pragmatic safety solutions
White paper pragmatic safety solutionsWhite paper pragmatic safety solutions
White paper pragmatic safety solutions
 
White paper holistic_approach_to_government_continuity_of_operations_apr2014
White paper holistic_approach_to_government_continuity_of_operations_apr2014White paper holistic_approach_to_government_continuity_of_operations_apr2014
White paper holistic_approach_to_government_continuity_of_operations_apr2014
 
Why a Unified Approach to Critical Event Management Improves Operational Resi...
Why a Unified Approach to Critical Event Management Improves Operational Resi...Why a Unified Approach to Critical Event Management Improves Operational Resi...
Why a Unified Approach to Critical Event Management Improves Operational Resi...
 
Osha Manager Role
Osha Manager RoleOsha Manager Role
Osha Manager Role
 
It32015 slides
It32015 slidesIt32015 slides
It32015 slides
 
OH&S Risk Management: Due Diligence in the Workplace
OH&S Risk Management: Due Diligence in the WorkplaceOH&S Risk Management: Due Diligence in the Workplace
OH&S Risk Management: Due Diligence in the Workplace
 

Ähnlich wie Preparing for a Post Covid World

Introduction to Risk ManagementMana.6330Overview
Introduction to Risk ManagementMana.6330OverviewIntroduction to Risk ManagementMana.6330Overview
Introduction to Risk ManagementMana.6330Overview
TatianaMajor22
 

Ähnlich wie Preparing for a Post Covid World (20)

Managing Risks in Turbulent Times by Dr. Emmanuel Moore ABOLO
Managing Risks in Turbulent Times by Dr. Emmanuel Moore ABOLOManaging Risks in Turbulent Times by Dr. Emmanuel Moore ABOLO
Managing Risks in Turbulent Times by Dr. Emmanuel Moore ABOLO
 
Monica Caballero, risk management in times of COVID 19 and beyond, SIGMA 10 M...
Monica Caballero, risk management in times of COVID 19 and beyond, SIGMA 10 M...Monica Caballero, risk management in times of COVID 19 and beyond, SIGMA 10 M...
Monica Caballero, risk management in times of COVID 19 and beyond, SIGMA 10 M...
 
Assessing health and safety risk in uncertain times
Assessing health and safety risk in uncertain timesAssessing health and safety risk in uncertain times
Assessing health and safety risk in uncertain times
 
FERMA presentation at the IIA Belgium Conference
FERMA presentation at the IIA Belgium ConferenceFERMA presentation at the IIA Belgium Conference
FERMA presentation at the IIA Belgium Conference
 
Easing of lockdown – practical considerations for managing and supporting staff
Easing of lockdown – practical considerations for managing and supporting staffEasing of lockdown – practical considerations for managing and supporting staff
Easing of lockdown – practical considerations for managing and supporting staff
 
NCVO Webinar: Legal and practical considerations for returning to work
NCVO Webinar: Legal and practical considerations for returning to workNCVO Webinar: Legal and practical considerations for returning to work
NCVO Webinar: Legal and practical considerations for returning to work
 
Moving from Process to Purpose, Risk Management after COVID19
Moving from Process to Purpose, Risk Management after COVID19 Moving from Process to Purpose, Risk Management after COVID19
Moving from Process to Purpose, Risk Management after COVID19
 
Risk Management (1) (1).ppt
Risk Management (1) (1).pptRisk Management (1) (1).ppt
Risk Management (1) (1).ppt
 
Introduction to Risk ManagementMana.6330Overview
Introduction to Risk ManagementMana.6330OverviewIntroduction to Risk ManagementMana.6330Overview
Introduction to Risk ManagementMana.6330Overview
 
The Role of the CFO in Response to the COVID-19 Crisis
The Role of the CFO in Response to the COVID-19 CrisisThe Role of the CFO in Response to the COVID-19 Crisis
The Role of the CFO in Response to the COVID-19 Crisis
 
Logistic insurance ch1 risk concept
Logistic insurance ch1 risk conceptLogistic insurance ch1 risk concept
Logistic insurance ch1 risk concept
 
Supply chain, a risk management survey results and analysis
Supply chain, a risk management survey results and analysisSupply chain, a risk management survey results and analysis
Supply chain, a risk management survey results and analysis
 
Managing Risk in the Global Supply Chain
Managing Risk in the Global Supply ChainManaging Risk in the Global Supply Chain
Managing Risk in the Global Supply Chain
 
RISK MANAGEMENT.pptx
RISK MANAGEMENT.pptxRISK MANAGEMENT.pptx
RISK MANAGEMENT.pptx
 
Economic Impact of Coronavirus by Slidesgo.pdf
Economic Impact of Coronavirus by Slidesgo.pdfEconomic Impact of Coronavirus by Slidesgo.pdf
Economic Impact of Coronavirus by Slidesgo.pdf
 
DRIDeckFinalMar3
DRIDeckFinalMar3DRIDeckFinalMar3
DRIDeckFinalMar3
 
Presentation on Risk management & controlling (Corporate Finance & Internatio...
Presentation on Risk management & controlling (Corporate Finance & Internatio...Presentation on Risk management & controlling (Corporate Finance & Internatio...
Presentation on Risk management & controlling (Corporate Finance & Internatio...
 
Risk Check Survey
Risk Check SurveyRisk Check Survey
Risk Check Survey
 
Risk-benefit analysis
Risk-benefit analysisRisk-benefit analysis
Risk-benefit analysis
 
BCM Webinar presentation
BCM Webinar presentationBCM Webinar presentation
BCM Webinar presentation
 

Mehr von Nimonik

Mehr von Nimonik (20)

Generative AI for Regulatory Analysis
Generative AI for Regulatory AnalysisGenerative AI for Regulatory Analysis
Generative AI for Regulatory Analysis
 
Nimonik Brochure
Nimonik BrochureNimonik Brochure
Nimonik Brochure
 
ISO 37301 Compliance Management Systems
ISO 37301 Compliance Management SystemsISO 37301 Compliance Management Systems
ISO 37301 Compliance Management Systems
 
Calgary Oil & Gas Regulatory and Standards Day January 18th 2023
Calgary Oil & Gas Regulatory and Standards Day January 18th 2023Calgary Oil & Gas Regulatory and Standards Day January 18th 2023
Calgary Oil & Gas Regulatory and Standards Day January 18th 2023
 
Best Practices for Regulatory Change Management
Best Practices for Regulatory Change ManagementBest Practices for Regulatory Change Management
Best Practices for Regulatory Change Management
 
Build a business case for compliance March 2022
Build a business case for compliance March 2022Build a business case for compliance March 2022
Build a business case for compliance March 2022
 
ESG and Compliance: Where do we go from here?
ESG and Compliance: Where do we go from here?ESG and Compliance: Where do we go from here?
ESG and Compliance: Where do we go from here?
 
State of Compliance 2021 at Mid-Market Firms - Nimonik
State of Compliance 2021 at Mid-Market Firms - NimonikState of Compliance 2021 at Mid-Market Firms - Nimonik
State of Compliance 2021 at Mid-Market Firms - Nimonik
 
ISO 19600 Section 4.5 - Know your Obligations
ISO 19600 Section 4.5 - Know your ObligationsISO 19600 Section 4.5 - Know your Obligations
ISO 19600 Section 4.5 - Know your Obligations
 
Identify Applicable EHS Regulatory Documents
Identify Applicable EHS Regulatory DocumentsIdentify Applicable EHS Regulatory Documents
Identify Applicable EHS Regulatory Documents
 
19600 Compliance Management System Guidelines
19600 Compliance Management System Guidelines19600 Compliance Management System Guidelines
19600 Compliance Management System Guidelines
 
19600 compliance management system guidelines
19600   compliance management system guidelines19600   compliance management system guidelines
19600 compliance management system guidelines
 
Survey results - Centrally vs Locally managed compliance
Survey results - Centrally vs Locally managed complianceSurvey results - Centrally vs Locally managed compliance
Survey results - Centrally vs Locally managed compliance
 
Continous compliance october 2019 webinar (2)
Continous compliance   october 2019 webinar (2)Continous compliance   october 2019 webinar (2)
Continous compliance october 2019 webinar (2)
 
The not so hidden costs of non-compliance
The not so hidden costs of non-complianceThe not so hidden costs of non-compliance
The not so hidden costs of non-compliance
 
The 4 key types of regulations and how to comply (3)
The 4 key types of regulations and how to comply (3)The 4 key types of regulations and how to comply (3)
The 4 key types of regulations and how to comply (3)
 
Comprehensive Compliance for Environmental, Safety, Quality Requirements in C...
Comprehensive Compliance for Environmental, Safety, Quality Requirements in C...Comprehensive Compliance for Environmental, Safety, Quality Requirements in C...
Comprehensive Compliance for Environmental, Safety, Quality Requirements in C...
 
Process Area Site Assessments techniques for the Management
Process Area Site Assessments techniques for the ManagementProcess Area Site Assessments techniques for the Management
Process Area Site Assessments techniques for the Management
 
Air monitoring presentation
Air monitoring presentationAir monitoring presentation
Air monitoring presentation
 
Legal Register / Compliance Obligations ISO 14001
Legal Register / Compliance Obligations ISO 14001Legal Register / Compliance Obligations ISO 14001
Legal Register / Compliance Obligations ISO 14001
 

Kürzlich hochgeladen

Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Victor Rentea
 
Architecting Cloud Native Applications
Architecting Cloud Native ApplicationsArchitecting Cloud Native Applications
Architecting Cloud Native Applications
WSO2
 
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Victor Rentea
 

Kürzlich hochgeladen (20)

Platformless Horizons for Digital Adaptability
Platformless Horizons for Digital AdaptabilityPlatformless Horizons for Digital Adaptability
Platformless Horizons for Digital Adaptability
 
Strategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherStrategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a Fresher
 
[BuildWithAI] Introduction to Gemini.pdf
[BuildWithAI] Introduction to Gemini.pdf[BuildWithAI] Introduction to Gemini.pdf
[BuildWithAI] Introduction to Gemini.pdf
 
Introduction to use of FHIR Documents in ABDM
Introduction to use of FHIR Documents in ABDMIntroduction to use of FHIR Documents in ABDM
Introduction to use of FHIR Documents in ABDM
 
DBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor PresentationDBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor Presentation
 
Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024
 
ICT role in 21st century education and its challenges
ICT role in 21st century education and its challengesICT role in 21st century education and its challenges
ICT role in 21st century education and its challenges
 
AWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of Terraform
 
"I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ..."I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ...
 
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
 
Understanding the FAA Part 107 License ..
Understanding the FAA Part 107 License ..Understanding the FAA Part 107 License ..
Understanding the FAA Part 107 License ..
 
Architecting Cloud Native Applications
Architecting Cloud Native ApplicationsArchitecting Cloud Native Applications
Architecting Cloud Native Applications
 
Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...
 
Artificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : UncertaintyArtificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : Uncertainty
 
Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...
Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...
Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...
 
AI+A11Y 11MAY2024 HYDERBAD GAAD 2024 - HelloA11Y (11 May 2024)
AI+A11Y 11MAY2024 HYDERBAD GAAD 2024 - HelloA11Y (11 May 2024)AI+A11Y 11MAY2024 HYDERBAD GAAD 2024 - HelloA11Y (11 May 2024)
AI+A11Y 11MAY2024 HYDERBAD GAAD 2024 - HelloA11Y (11 May 2024)
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
 
CNIC Information System with Pakdata Cf In Pakistan
CNIC Information System with Pakdata Cf In PakistanCNIC Information System with Pakdata Cf In Pakistan
CNIC Information System with Pakdata Cf In Pakistan
 
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
 

Preparing for a Post Covid World

  • 1. Raimund Laqua, PMP, P.Eng ray.laqua@leancompliance.ca WWW.LEANCOMPLIANCE.CA PREPARING FOR POST COVID-19 FROM CRISIS TO RECOVERY
  • 2. WWW.LEANCOMPLIANCE.CA PREPARING FOR POST COVID-19 The Big Idea As the lifting of Covid-19 restrictions begin all around the world, companies are starting to transition to a next normal for their business. This requires a risk-based business recovery plan that: • Reimagines what normal looks like • Safely restarts operations • Recovers business that was lost • Reinforces defenses against future uncertainty This is an opportunity for risk & compliance to be at the table to lead and coordinate efforts to improve the probability of mission success.
  • 3. WWW.LEANCOMPLIANCE.CA ☐Implemented, and underway ☐Completed, and ready to go ☐Developing, and going well. ☐Started, and struggling to get it done. ☐Not started. PREPARING FOR POST COVID-19 1. What is the status of your business recovery plan? Webinar Poll
  • 4. WWW.LEANCOMPLIANCE.CA PREPARING FOR POST COVID-19 Outline Outcome: Understand what a risk-based business recovery plan consists of that addresses the risks that really matter to improve the probability of mission success. Outline: 1. Risk Context 2. Risk Assessment 3. Risk Attitude 4. Risk Scenarios 5. Risk Treatment COVID-19 CRISIS COVID-19 RECOVERY
  • 5. WWW.LEANCOMPLIANCE.CA PREPARING FOR POST COVID-19 1. Risk Context To establish the context means to define the external and internal parameters that organizations must consider when they manage risk. An organization’s external context includes its external stakeholders, its local, national, and international environment, as well as any external factors that influence its objectives. An organization’s internal context includes its internal stakeholders, its approach to governance, its contractual relationships, and its capabilities, culture, and standards. † https://www.praxiom.com/iso-31000.htm
  • 6. WWW.LEANCOMPLIANCE.CA PREPARING FOR POST COVID-19 1. Risk Context ☐ Impacts due to COVID-19: health, supply, demand, operations ☐ Employee rights to refuse work if workplace is unsafe ☐ Ethical and legal concerns with respect to contact tracing, and proximity technologies ☐ Obligations at risk, deferred obligations that are coming due ☐ Business assumptions challenged ☐ Reduction in workforce: lay offs, retention, etc. ☐ Changing definition of what the next "normal" looks like ☐ Remote work ☐ Contract failures and disputes arising from COVID-19 ☐ Increased litigation and lawsuits ☐ Worker health checks and monitoring ☐ Lineups at elevators, shift work, and distanced desks ☐ New safety guidelines and conditions to resume operations ☐ Staggered recovery of businesses ☐ Anticipated second COVID-19 wave, recession COVID-19 CRISIS Which factors really matter?
  • 7. PREPARING FOR POST COVID-19 1. Risk Context Mission Quality Health & Safety Security Environmental Process Safety Pipeline Safety Food Safety Patient Safety Conformance to Industry Standards Conformance to Legal Requirements Accept Stakeholder Responsibilities Accept Public Responsibilities Institutional Risk Missional Risk Operational Risk Reputational Risk Cyber Risk Financial Risk Third Party Risk Sustainability Risk Public Safety Risk Trustability Risk Legal Regulatory Ethics Code of Conduct Contracts Certifications Public Safety Social License Regulatory License WWW.LEANCOMPLIANCE.CA • Voluntary • Outcome-focused • Risk-based • Learn / Improve • Proactive • Mandatory • Rules-focused • Prescriptive • Audit / Fix • Reactive ORGANIZATIONAL CORPORATERISK What is the status of compliance obligations?
  • 8. PREPARING FOR POST COVID-19 1. Risk Context † Modified Value Chain Analysis (Michael Porter) PRODUCTIVTY Inbound Logistics Operations Outboun d Logistics Marketing & Sales Service Inbound Logistics Outboun d Logistics Marketing & Sales ServiceOperations ETHICS & REGULATORY ENVIRONMENTAL SAFETY & SECURITY QUALITY RISK&COMPLIANCE RISK VALUE CHAIN Sustainability Reputation Quality Safety Trust OUTCOMESTRANSFORMATION M A R G IN INBOUND LOGISTICS OPERATIONS OUTBOUND LOGISTICS MARKETING & SALES SERVICE INFRASTRUCTURE HUMAN RESOURCE TECHNOLOGY PROCUREMENT TOTALVALUE Profit Growth Margins Efficiency Productivity WWW.LEANCOMPLIANCE.CA Where does risk and compliance contribute to outcomes
  • 9. WWW.LEANCOMPLIANCE.CA PREPARING FOR POST COVID-19 1. Risk Context • When will the money run out? • When will the lay offs begin? • When will we close for good? Crisis Management • What risks really matter? • What risks can we buy down? • What risks require margin? Risk Management • What is the next normal? • How do we get there? • What resources do we need? • What threats or opportunities should we consider? • How do we measure our progress? Change Management Which management approach should be used?
  • 10. WWW.LEANCOMPLIANCE.CA PREPARING FOR POST COVID-19 1. Risk Context “Over the years, compliance officers have designed and implemented the now recognized three pillars of an effective compliance system: prevent, detect and respond, including monitoring and remediation. This system is equally valid for all relevant risk functions in a corporation, including health, safety and environment, business continuity and emergency management, data privacy, quality, IT security, finance and others. Instead of being “just another workstream,” courageous, risk-aware and crisis-resilient compliance officers can rightfully claim consideration for the lead or at least the coordination of an integrated risk management system in corporations." – Dr. Klaus Moosmayer COMPLIANCE OFFICER ROLE Which role will lead the recovery?
  • 11. WWW.LEANCOMPLIANCE.CA ☐Chief Executive Officer (CEO) ☐Chief Compliance / Risk Officer (CCO) or (CRO) ☐Crisis Team / Task force ☐Committee ☐No one PREPARING FOR POST COVID-19 2. Who is leading your recovery efforts? Webinar Poll
  • 12. WWW.LEANCOMPLIANCE.CA PREPARING FOR POST COVID-19 Outline Outcome: Understand what a risk-based business recovery plan consists of that addresses the risks that really matter to improve the probability of mission success. Outline: 1. Risk Context 2. Risk Assessment 3. Risk Attitude 4. Risk Scenarios 5. Risk Treatment COVID-19 CRISIS COVID-19 RECOVERY
  • 13. WWW.LEANCOMPLIANCE.CA PREPARING FOR POST COVID-19 2. Risk Assessment Risk assessment is a process that is made up of three separate processes: risk identification, risk analysis, and risk evaluation. Risk identification is a process that is used to find, recognize, and describe the risks that could affect the achievement of objectives. Risk analysis is a process that is used to understand the nature, sources, and causes of the risks that you have identified and to estimate the level of risk. It is also used to study impacts and consequences and to examine the controls that exist. Risk evaluation is a process that is used to compare risk analysis results with risk criteria in order to determine whether or not a specified level of risk is acceptable or tolerable. † https://www.praxiom.com/iso-31000.htm
  • 14. WWW.LEANCOMPLIANCE.CA PREPARING FOR POST COVID-19 2. Risk Assessment COVID-19 PANDEMIC COVID-19 SHUTDOWN COVID-19 IMPACTS How do we control transmission? How do we survive the crisis? How do we recover? RISK SOURCES
  • 15. WWW.LEANCOMPLIANCE.CA PREPARING FOR POST COVID-19 RISK MEASURES RISK SCENARIO 2. Risk Assessment • Collect data, develop tests, work on a vaccine • Introduce safety measures: washing hands, social distancing, self-isolation, reduce travel, PPE, etc. • Prepare for significant increase in hospitalization • “Flatten the curve” • New variant of the corona virus • Worldwide pandemic, Infection rate 2.5 • Impacts are asymmetric • No vaccine • Deaths 284,000 / Cases 4,200,957 • Significant uncertainty LOSS OF LIFE CAUSES CONSEQUENCES PREVENTIVE CONTROLS MITIGATIVE CONTROLS LOSS OF LIFE MAJOR SYMPTOMS MINOR SYMPTOMS NO SYMPTOMS ECONOMIC SLOWDOWN WASHING HANDS, SELF ISOLATION, SOCIAL DISTANCING, ECONOMIC SHUTDOWN QUARANTINE, HOSPITALIZATION, RESERVES INFECTED PERSON SURFACES HYGIENE THREAT COVID-19 PANDEMIC How do we control transmission?
  • 16. WWW.LEANCOMPLIANCE.CA PREPARING FOR POST COVID-19 RISK MEASURES RISK SCENARIO 2. Risk Assessment • Declared Emergency / Crisis • Quarantine as many as possible (shutdown borders, travel, economy, public spaces, etc.) • #StayAtHome / Shelter-in-place • Governments introduce emergency programs • Businesses activate crisis management teams: • when will the money run out? • when will lay offs begin? • when will we close for good? • Transmission of COVID-19 multiplies • Increase in number of cases and deaths • No vaccine and “treatment” options are limited • Identification of hot spots, super spreaders • Panic increases CAUSES CONSEQUENCES PREVENTIVE CONTROLS MITIGATIVE CONTROLS LOSS OF BUSINESS, LOSS OF LIVELIHOOD LOSS OF BUSINESS LOSS OF LIVELIHOOD LOSS OF HOME FAMILY BREAKDOWN PERSONAL BANKRUPTCY RESERVES, SAVINGS, GOVERNMENT SUPPORT, FAMILY SUPPORT, COUNSELLING, NEW BUSINESS, NEW LIVELIHOOD SAFETY MEASURES ECONOMIC SLOWDOWN REDUCTION OF WORKFORCE THREAT NONE COVID-19 SHUTDOWN How do we survive the crisis?
  • 17. WWW.LEANCOMPLIANCE.CA PREPARING FOR POST COVID-19 2. Risk Assessment COVID-19 IMPACTS RISK MEASURES RISK SCENARIO • Pandemic continues • Curve is flattening • Reserves and contingencies running out • Increase in layoffs and unemployment (20%) • Closures and bankruptcies • Significant market disruptions • Increased vulnerabilities: cyber risk, operational risk, etc. • Long tail of impacts • Anticipated second wave, recession, ? CAUSES CONSEQUENCES PREVENTIVE CONTROLS MITIGATIVE CONTROLS THREAT CAUSES CONSEQUENCES ENABLE CONTROLS EXPLOIT CONTROLS OPPORTUNITY How do we recover? LOSS OF LIFE, LOSS OF BUSINESS, LOSS OF LIVELIHOOD BETTER LIFE, BETTER BUSINESS, BETTER LIVELIHOOD
  • 18. WWW.LEANCOMPLIANCE.CA PREPARING FOR POST COVID-19 ORDER • The place you are when what you do works • Predictable / Certain • Occasional chaos • Deterministic • Routine • Underwhelming Order Chaos 2. Risk Assessment CHAOS • The place you are when what you do doesn’t work • Unpredictable / Uncertain • Occasional order • Random • Abnormal • Overwhelming Uncertainty creates the opportunity for risk
  • 19. WWW.LEANCOMPLIANCE.CA ☐Certain – Order, with occasional chaos. ☐Ambiguous – On the edge between order and chaos. ☐Uncertain – Chaos, with occasional order. PREPARING FOR POST COVID-19 3. What is your level of uncertainty with respect to your mission objectives? Webinar Poll
  • 20. WWW.LEANCOMPLIANCE.CA PREPARING FOR POST COVID-19 Outline Outcome: Understand what a risk-based business recovery plan consists of that addresses the risks that really matter to improve the probability of mission success. Outline: 1. Risk Context 2. Risk Assessment 3. Risk Attitude 4. Risk Scenarios 5. Risk Treatment COVID-19 CRISIS COVID-19 RECOVERY
  • 21. WWW.LEANCOMPLIANCE.CA PREPARING FOR POST COVID-19 3. Risk Attitude An organization’s risk attitude defines its general approach to risk. An organization’s risk attitude (and its risk criteria) influence how risks are assessed and addressed. An organization’s attitude towards risk affects whether or not risks are taken, tolerated, retained, shared, reduced, or avoided, and whether or not treatments are implemented or postponed. † https://www.praxiom.com/iso-31000.htm
  • 22. WWW.LEANCOMPLIANCE.CA PREPARING FOR POST COVID-19 3. Risk Attitude Strategist Let’s improve the probability of success RISK STRATEGIST Avoider I don’t want any risk RISK INTOLERANT Gambler Let’s play the odds RISK SEEKING Ostrich I don’t want to know RISK TOLERANT Manager Let’s size the risk and decide RISK NEUTRAL Our attitude towards risk affects our approach
  • 23. WWW.LEANCOMPLIANCE.CA • Protect (guard) against loss • Minimize variation by preventing or recovery from threats • Focus on efficiency (cost, schedule, performance) • Pay attention to what might cause failure and what could go wrong PREPARING FOR POST COVID-19 • Ensure (make certain of) outcomes • Maximize value by enabling and exploiting opportunities • Focus on effectiveness (outcomes, value creation, benefits realization) • Pay attention to what is critical to success and what needs to go right Avoid Failure Pursue Success 3. Risk Attitude Objectives of a Risk Strategist
  • 24. WWW.LEANCOMPLIANCE.CA ☐Ostrich, I don’t want to know. ☐Avoider, I don’t want any risk. ☐Manager, let’s do the math. ☐Gambler, let’s play the odds. ☐Strategist, let’s improve the probability of success. PREPARING FOR POST COVID-19 4. What is your attitude towards risk? Webinar Poll
  • 25. WWW.LEANCOMPLIANCE.CA PREPARING FOR POST COVID-19 Outline Outcome: Understand what a risk-based business recovery plan consists of that addresses the risks that really matter to improve the probability of mission success. Outline: 1. Risk Context 2. Risk Assessment 3. Risk Attitude 4. Risk Scenarios 5. Risk Treatment COVID-19 CRISIS COVID-19 RECOVERY
  • 26. WWW.LEANCOMPLIANCE.CA PREPARING FOR POST COVID-19 4. Risk Scenarios Scenario analysis is a process of analyzing future events by considering alternative possible outcomes (sometimes called "alternative worlds"). Thus, scenario analysis, which is one of the main forms of projection, does not try to show one exact picture of the future. Instead, it presents several alternative future developments. It does not rely on historical data and does not expect past observations to remain valid in the future. Instead, it tries to consider possible developments and turning points, which may only be connected to the past. In short, several scenarios are fleshed out in a scenario analysis to show possible future outcomes † https://en.wikipedia.org/wiki/Scenario_analysis
  • 27. WWW.LEANCOMPLIANCE.CA PREPARING FOR POST COVID-19 4. Risk Scenarios COVID-19 PANDEMIC COVID-19 SHUTDOWN COVID-19 IMPACTS How do we control transmission? How do we sruvive the crisis? How do we recover? How do we restart safely? How do we recover our business? How do we reinforce our defenses? RESTART RECOVER REINFORCE What is the next normal? REIMAGINE RISK SCENARIOS RISK SOURCES
  • 28. WWW.LEANCOMPLIANCE.CA PREPARING FOR POST COVID-19 4. Risk Scenarios RISK SCENARIOS • What are possible next normals? • Which ones address the risks that really matter? • Which ones need to happen first (are their dependencies?) • Which ones do you build your business recovery plan around?
  • 29. WWW.LEANCOMPLIANCE.CA ☐Minor, business assumptions are mostly valid. • tactical / safety changes are needed. ☐Moderate, significant changes to business assumptions. • business model, • tactical / safety changes are needed. ☐Major, business assumptions no longer valid. • entire business strategy needs to be re-evaluated. PREPARING FOR POST COVID-19 5. What is the level of impact caused by COVID-19 on your business? Webinar Poll
  • 30. WWW.LEANCOMPLIANCE.CA PREPARING FOR POST COVID-19 4. Risk Scenarios Who is leading the recovery effort? What is the level of uncertainty? What is the risk attitude? What is the level of impact caused by COVID-19? What phases are necessary to resume operations? What type of change is required? CEO Certain Ostrich Minor Restart Tactical / Safety CCO / CRO Ambiguous Avoider Moderate Recover Business Model Crisis Team / Task Force Uncertain Manager Major Reinforce Business Strategy Committee Gambler No One Strategist Scenario Decision Matrix
  • 31. WWW.LEANCOMPLIANCE.CA PREPARING FOR POST COVID-19 5. Risk Scenarios Who is leading the recovery effort? What is the level of uncertainty? What is the risk attitude? What is the level of impact caused by COVID-19? What phases are necessary to resume operations? What type of change is required? CEO Certain Ostrich Minor Restart Tactical / Safety CCO / CRO Ambiguous Avoider Moderate Recover Business Model Crisis Team / Task Force Uncertain Manager Major Reinforce Business Strategy Committee Gambler No One Strategist Scenario #1 – TACTICAL / SAFETY CHANGE LOW RISK
  • 32. WWW.LEANCOMPLIANCE.CA PREPARING FOR POST COVID-19 4. Risk Scenarios Who is leading the recovery effort? What is the level of uncertainty? What is the risk attitude? What is the level of impact caused by COVID-19? What phases are necessary to resume operations? What type of change is required? CEO Certain Ostrich Minor Restart Tactical / Safety CCO / CRO Ambiguous Avoider Moderate Recover Business Model Crisis Team / Task Force Uncertain Manager Major Reinforce Business Strategy Committee Gambler No One Strategist Scenario #2 – BUSINESS MODEL CHANGE MEDIUM RISK
  • 33. WWW.LEANCOMPLIANCE.CA PREPARING FOR POST COVID-19 4. Risk Scenarios Who is leading the recovery effort? What is the level of uncertainty? What is the risk attitude? What is the level of impact caused by COVID-19? What phases are necessary to resume operations? What type of change is required? CEO Certain Ostrich Minor Restart Tactical / Safety CCO / CRO Ambiguous Avoider Moderate Recover Business Model Crisis Team / Task Force Uncertain Manager Major Reinforce Business Strategy Committee Gambler No One Strategist Scenario #3 – BUSINESS STRATEGY CHANGE HIGH RISK
  • 34. WWW.LEANCOMPLIANCE.CA ☐Scenario #1 – Tactical / Safety ☐Scenario #2 – Business Model, includes #1 ☐Scenario #3 – Business Strategy, includes #2 and #1 ☐Not sure PREPARING FOR POST COVID-19 6. Which scenario should your organization consider? Webinar Poll
  • 35. WWW.LEANCOMPLIANCE.CA PREPARING FOR POST COVID-19 Outline Outcome: Understand what a risk-based business recovery plan consists of that addresses the risks that really matter to improve the probability of mission success. Outline: 1. Risk Context 2. Risk Assessment 3. Risk Attitude 4. Risk Scenarios 5. Risk Treatment COVID-19 CRISIS COVID-19 RECOVERY
  • 36. WWW.LEANCOMPLIANCE.CA PREPARING FOR POST COVID-19 5. Risk Treatment Risk treatment is a risk modification process. It involves selecting and implementing one or more treatment options. Once a treatment has been implemented, it becomes a control, or it modifies existing controls. You have many treatment options. You can avoid the risk, you can reduce the risk, you can remove the source of the risk, you can modify the consequences, you can change the probabilities, you can share the risk with others, you can simply retain the risk, or you can even increase the risk in order to pursue an opportunity. † https://www.praxiom.com/iso-31000.htm
  • 37. 3. Do we have everything we need to get the next NORMAL? 1. What is the next NORMAL? 5. What threats or opportunities will we encounter on the way to the next NORMAL? 2. How do we get to the next NORMAL? 4. How do we measure our progress towards the next NORMAL? DESTINATION PLAN RESOURCES PROGRESS RISK WWW.LEANCOMPLIANCE.CA PREPARING FOR POST COVID-19 5. Risk Treatment Each scenario must have compelling answers to these questions
  • 38. WWW.LEANCOMPLIANCE.CA PREPARING FOR POST COVID-19 5. Risk Treatment • Define scenario: what are the business assumptions, what is the next normal, how do we get there, what resources do we need, and how will progress be measured.1. Define • Introduce pre-mortem: open and honest discussion and imagine that your company failed, and that it succeeded. In addition, estimate uncertainties.2. Introduce • Debrief discussions: all team members describe why your company failed, and why your company succeeded.3. Debrief • Prioritize risk: separate into reducible (what you can buy down), and irreducible (what you treat with margins).4. Prioritize • Brainstorm handling strategies: identify steps to buy down risk or treat with margins.5. Brainstorm • Update Business Recovery Plan and Risk Register. 6. Document
  • 39. SCENARIO RISK CANVAS PREMORTEM1. DESTINATION 3. RESOURCES 2. PLAN 5. RISK 4. PROGRESS UNCERTAINTIES Do we have everything we need? What does NORMAL look like? Reducible / Buy down How do we measure progress? Why did we fail? How do we get to NORMAL? What didn’t we know? Why did we succeed? What didn’t we control? Irreducible / Treat with Margin What threats or opportunities hinder or advance progress? 0. ASSUMPTIONS SCENARIO:
  • 40. SCENARIO RISK CANVAS PREMORTEM1. DESTINATION 3. RESOURCES 2. PLAN 5. RISK 4. PROGRESS UNCERTAINTIES Sustainable critical safety roles Additional office space Enhanced cyber protection Sustainable supply of PPE Critical systems available remotely Training for remote workers Do we have everything we need? COVID-19 Safety measures in place Management reviews include safety Operationalize remote work Operationalize workplace distancing Operational readiness @ 65% capacity Pre-startup Safety Review include COVID Sustainable supply chain What does NORMAL look like? T - Cyber risk T - COVID-19 Infection T- Weaker product demand T- Supply chain vulnerabilities O - Increase customer relationship O - Improve workforce alignment Reducible / Buy down Operational readiness level Corporate climate level Supplier quality levels Customer engagement levels Product demand How do we measure progress? Didn’t prepare for second wave Didn’t prepare for long term impacts Didn’t’ prepare for another lockdown Didn’t build up reserves We didn’t’ address negativity Didn’t train workforce for remote work Didn’t strengthen IT systems Why did we fail?Identify COVID-19 safety measures Identify additional risk measures Implement COVID-19 safety measures Implement additional risk measures Develop communication plan Identify gating conditions for startup Build up corporate morale Improve remote access to systems How do we get to NORMAL? The long-term effects on our customers Supply chain vulnerability Weaker product demand Critical safety functions not performing What didn’t we know? Continuous Risk Management Maintained healthy workforce Increased reserves Increased cyber threat protection Stayed connected with customers Better remote work capabilities Stayed connected with suppliers Why did we succeed? COVID-19 Transmission Cyber risk Corporate climate Supply chain quality Critical to Quality Critical to Safety Critical to Compliance What didn’t we control? COVID-19 Lockdown Litigation Irreducible / Treat with Margin What threats or opportunities hinder or advance progress? 0. ASSUMPTIONS Demand will return to 80% by EOY Existing business model valid and viable Workforce morale is low Impacts will continue until end of 2021 Integrity of value chain is a concern Shareholder trust is high, but concerned SCENARIO: #1 Tactical / Safety O - Introduce digital services
  • 41. WWW.LEANCOMPLIANCE.CA PREPARING FOR POST COVID-19 5. Risk Treatment NO. OBJECTIVE UNCERTAINTY ESTIMATE UNCERTAINTY TYPE RISK (EFFECT OF UNCERTAINTY ON OBJECTIVES) PREVENTIVE MEASURES RECOVERY MEASURES 1.1 Control transmission of COVID-19 at the work site to acceptable levels as reasonably practicable per provincial guidelines. Medium Reducible As a result of ineffective safety measures,, infection may occur, leading to health impacts. Social Distancing Face Masks Remote Work Shift work Desk distancing Disinfection Protocols Employee Temperature monitoring Quarantine Hospitalization 1.2 Maintain safe operations of the plant. Low Reducible and Irreducible As a result of a reduction in workforce, critical safety activities may not occur, leading to an increase in safety incidents. Pre-startup Safety Review Incident investigations Emergency response Insurance 1.3 Achieve operational readiness compliant with all performance, safety, security, quality, environmental, regulatory obligations. Medium Reducible As a result of a plant shutdown during COVID-19, achieving stable operations upon startup may not occur, leading to more downtime. Conduct operational readiness assessment as per company policy Execute contingency plan. 1.4 Improve cyber threat protection capabilities High Reducible As a result of increased cyber attacks, a security breach may occur, leading to a leak of private information. Conduct Cyber Risk Resiliency assessment Strengthen threat protection Incident Response Incident Investigations Insurance Objective-based Risk Register: Scenario #1 - Tactical / Safety Effective risk treatment requires effective compliance of risk measures
  • 42. WWW.LEANCOMPLIANCE.CA PREPARING FOR POST COVID-19 The Big Idea As the lifting of Covid-19 restrictions begin all around the world, companies are starting to transition to a next normal for their business. This requires a risk-based business recovery plan that: • Reimagines what normal looks like • Safely restarts operations • Recovers business that was lost • Reinforces defenses against future uncertainty This is an opportunity for risk & compliance to be at the table to lead and coordinate efforts to improve the probability of mission success.
  • 43. WWW.LEANCOMPLIANCE.CA PREPARING FOR POST COVID-19 FROM CRISIS TO RECOVERY WHAT WILL YOU DO NEXT?
  • 44. FREE COVID-19 MEMBERSHIP PACKAGE ADDITIONAL RESOURCES www.leancompliance.ca/members Additional resources available: COVID-19 Membership Package (FREE) Sign up here: www.leancompliance.ca/members