About Me

This blog carries a series of posts and articles, mostly written by Anthony Fitzsimmons under the aegis of Reputability LLP, a business that is no longer trading as such. Anthony is a thought leader in reputational risk and its root causes, behavioural, organisational and leadership risk. His book 'Rethinking Reputational Risk' was widely acclaimed. Led by Anthony, Reputability helped business leaders to find, understand and deal with these widespread but hidden risks that regularly cause reputational disasters. You can contact Anthony via the contact form.

Sunday, 29 September 2013

Civil service competence revisited

Two years ago, I asked whether the Civil Service's top mandarins are competent.  I discussed two pieces of evidence suggesting that they have a reputation for incompetence among those who deal most closely with them. A third suggested that this reputation is deserved.

Two recent books have brought the subject back into focus. Both consider the role of politicians as well as mandarins.  Both are on my reading list on the strength of the experience of the authors and the reviews.  Here is a taster based on the reviews.  I'll write again when I've read the books. 

The first book is 'Conundrum: Why Every Government Gets Things Wrong and What We Can Do About it" by Richard Bacon MP and Christopher Hope.  It's a good team:  Bacon is the longest serving member of the Public Accounts Committee and Hope is senior political correspondent at the Daily Telegraph.

The Telegraph's reviewer,
"Conundrum pitches itself as an examination of the failures of government, but it is primarily about the failures of government procurement....One of the most interesting areas they cover is the relationship between civil servants and the politicians who, nominally, oversee them. In my experience, the majority of career civil servants regard politicians as meddling dilettantes, while politicians regard most civil servants as obstructive bureaucrats. It’s pleasing to find Hope and Bacon confirming that view"
The second book is 'The Blunders of our Governments' by Anthony King and Ivor Crewe.  The authors are eminent professorial political scientists of an age to have allowed each of them many decades observing the machinery of government.

According to the The Financial Times review by Philip Stephens, the book shatters the delusion of UK public administrators that British government is of 'Rolls Royce' quality.  Rather, through a "sometimes grimly entertaining" catalogue of public policy disasters over the past several decades, the authors show that Britain's public administration is characterised by "predictable and predicted blunders".

Not content with that, the authors explain that blunders are not the same as mistakes. "Mistakes count as blunders when they are stupid and careless – driven by some combination of hubris, laziness, wilful ignorance or sheer incompetence."

Both books appear to assert not only the incompetence of senior civil servants but also of the their political masters of all colours and persuasions.  It is no consolation that private sector failures display similar weaknesses, as was demonstrated by 'Roads to Ruin', the Cass Business School report for Airmic.

Is it too much to expect that the Civil Servants' leaders address weaknesses such as these?  Sadly, yes.   Cognitive biases make it hard for us all to see our own shortcomings, and civil servants and politicians are as human as you and I.  Overcoming this weaknesses requires a new attitude.

Until mandarins appreciate that they 'may' - the above authors would say 'do' - lie at the root cause of unacceptable behavioural and organisational risks, they will not allow investigation of their own weaknesses.  The signs are that mandarins are still in denial.  And it is far too dangerous for their subordinates to enlighten them of their weaknesses.  That is why suggestions that the Treasury's Orange Book on risk management needs revision to include behavoural and organisational risks have been ignored.

Once they have achieved acceptance that they may be part of the problem, mandarins will need a new tool.  In 'Deconstructing failure - Insights for boards', a report by Reputablity, we proposed a new tool to deal with the parallel weakness in company boards: the Board Vulnerability Evaluation.  Adapted to the Civil Service departmental leadership teams, this would help civil service leaders and their political masters to:
  • identify sources of risk within and outside the leadership that may impair leadership effectiveness, including risks from inadequate information flows to and from the leadership;
  • analyse the potential consequences of these risks and weaknesses individually, in combination and in combination with other risks;
  • prioritise action to mitigate these risks;
  • set risk appetite, and
  • gain insights as to the extent to which behavioural and organisational risks elsewhere in the organisation need investigation.
It is too often an unnecessary tragedy when a government project fails and the cost falls on the public purse.  But it will only be when influential insiders come to recognise the nature and scale of the problem, and their central role in it, that these apparently widespread weaknesses will be addressed.

Anthony Fitzsimmons
Reputability LLP
London

Anthony Fitzsimmons is Chairman of Reputability LLP and, with the late Derek Atkins, author of “Rethinking Reputational Risk: How to Manage the Risks that can Ruin Your Business, Your Reputation and You



Wednesday, 11 September 2013

'Three lines of defence': A dangerous delusion



A 'Three lines of Defence' risk management model sounds reassuring, but it contains a flaw.

The model was implicitly endorsed by the UK's now defunct Financial Services Authority in 2003 and is still characterised as “sound operational risk governance” by the Basel Committee on Banking Supervision, failed to prevent the recent financial sector crisis.

‘Three lines of defence’, ubiquitous in financial services and widespread elsewhere, actually has four layers.  Line managers deal with risks as they take them.  Centralised teams monitor and report on risk to the CEO’s team and to the board.  Internal and external auditors should bring an independent view.  And the whole is overseen by non-executive directors, typically the Audit or Risk Committee.

The Parliamentary Commission on Banking Standards recently criticised the model, for promoting a ‘wholly misplaced sense of security’, blurring responsibility, diluting accountability and leaving risk, compliance and internal audit staff with insufficient status to do their job properly.  They thought much of the system had become a box-ticking exercise.

The Commission has correctly identified a failure in implementation of the model, but the model has a deeper, more dangerous flaw because it takes no account of the evidence on the real root causes of failures.  

Most major institutional disasters lead to an inquiry. But as Anthony Hilton, the City commentator sagely remarked:-

“Inquiries are rarely the answer because it is in the nature of inquiries to stop just at the point when they get interesting; in other words they stop when they have found someone to blame. Not for nothing did the late management guru Peter Drucker say that too often the first rule in any corporate disaster was to find a scapegoat. So inquiries focus on the processes within an organisation until they find some hapless individual or group who departed from the manual.”

We have been deeply involved in two recent studies of the root causes of major crises and failures.  We were two of the four authors of ‘Roads to Ruin’, the Cass Business School report for Airmic.   More recently, we doubled the scale of the study, publishing our conclusions as Reputability’s report ‘Deconstructing failure – Insights for boards’.  Taken together these seminal reports dig to the root causes of over 40 major crises and failures, spread across the financial and non-financial sectors and involving companies with collective pre-crisis assets beyond the GDP of the USA.  The reports bring a new, and fundamentally different, insight into why large, respected companies fail.  The patterns of failure revealed show that the ‘three lines of defence’ model failed because of a fundamental gap in risk management.

Our breakthrough is the recognition that the root causes of almost all the crises and failures we studied emerge from normal human behaviour and the way in which humans are organised and led within firms.  We call these previously unrecognised risk areas ‘Behavioural’ and ‘Organisational’ risks, collectively ‘People’ risks. (Since we wrote this article Andrew Bailey, then Chief Executive of the Bank of England's Prudential Regulation Authority, put this robustly in his speech on 9 May 2016.)

People risks lie at the root of all the failures studied for ‘Deconstructing failure’ both in the financial sector and outside it.  But ‘three lines of defence’ provides no defence against people risks in general, still less against people risks within or emanating from the board, because risk management systems don’t go there.  Risk management hasn’t yet evolved systematically to take in people risks, so few risk professionals understand them; and the most important risks are also too hot to handle because they emanate from boards. 

With these insights it is no surprise that the doctrine failed to prevent the last banking crisis.  Nor will it prevent the next one – or crises in other sectors.

These gaps have to be filled if boards and regulators are to be able to sleep at night.  Two developments are required. The first is to develop a cadre of risk professionals with skills in people risks, the main drivers of reputational damage and corporate collapse.

But that will not deal with the issue of vulnerabilities in or emanating from boards that regularly bring organisations to their knees.  For that, a second development is essential.  Boards need new tools that will both assess risks in and caused by the board; and help boards to overcome the cognitive biases that make it hard for all of us to see ourselves as others can.

In ‘Deconstructing failure’ we recommend a new tool to meet this need.  We call it the ‘Board Vulnerability Evaluation’ (and we have now done the work to develop it).  The tool is designed to help chairmen and their Boards to:-

  • Systematically understand and identify potential sources of corporate vulnerability within and outside the board, including people risks and risks from inadequate information flows to and from the board;
  • analyse the potential consequences of these risks and weaknesses individually, in combination and in combination with other risks;
  • prioritise and galvanise action where needed to mitigate these risks;
  • set risk appetite, and
  • gain insights as to the extent to which people risks elsewhere in the organisation need investigation.

It is a tragedy when a respected company fails and the cost can be catastrophic.  Board Vulnerability Evaluation will give Boards the opportunity to find, prioritise and where appropriate deal with these unrecognised but potentially devastating risks before they cause serious harm.  

Professor Derek Atkins
Anthony Fitzsimmons
Reputability LLP
London

Anthony Fitzsimmons is Chairman of Reputability LLP and, with the late Derek Atkins, author of “Rethinking Reputational Risk: How to Manage the Risks that can Ruin Your Business, Your Reputation and You

Friday, 2 August 2013

The Care Quality Commission takes a step in the right direction

My despair at reading that the CQC had spent hundreds of thousands of pounds on new spin doctors struck a chord, to judge from the response that my earlier blog on NHS safety culture produced.

However, I’m pleased to report that the CQC has taken a bold step in the right direction, in carrying out and now publishing a highly critical review of their organisation, 'Exploring bullying and harassment at the CQC’

"Exploring bullying and harassment at the CQC"


The review highlights allegations of a culture of bullying and harassment under the previous leadership.  Publishing the results and addressing the issue head-on is the right way to deal with it.

The failings are all too familiar to us both from our work and as summarised in our latest report ‘Deconstructing failure – Insights for boards’.  The report appears to highlight three major problem areas at the CQC: 
  • A failure of leadership to create the right ethos and culture
  • A dominant leader not welcoming challenge
  • Risks arising from incentives/targets set by leaders - in this case with the added fear of penalties for failure

All three are among the top seven risk areas identified in ‘Deconstructing failure’. 

Since the review did not pretend to make a root cause analysis of the problems at the CQC, it does not comment on other fundamental risks that may have been at work at the CQC, such as an ineffective board, a board lacking key skills, poor information flows to the board, organisational complexity and board blindness to key risks to their licence to operate.

Finding a solution

From my experience as a regulatory chief executive, a particularly interesting aspect is the collected views of staff on "What would it be like to work here, if things changed for the better."  It is our experience that when things are not right, insiders still know what “good” would look like – if only someone is prepared to listen to them.

This list of staff aspirations will help the new management team in the cultural change programme that should be the next step. It will not be easy, or quick, but given time and sound leadership, such a programme should ensure dramatic improvement in the work of this much criticised regulator.  Politicians must allow management enough time to bring about the necessary changes.

A better future?

I look forward to a future when the CQC is admired and respected by all its stakeholders, and the NHS has learned that the best way to achieve high standards is to regulate their own organisation to observe the highest standards, and invite the regulator to approve what they have done. This has been the guiding principle for the aviation industry, and has been adopted all around the globe with the result that the flight safety system is not an issue of public concern. Let's hope the CQC and the NHS will learn from best practice wherever it is found.

Mike Bell
Reputability LLP
London
www.reputability.co.uk

Wednesday, 31 July 2013

Hacking, blagging and stealing

Keith Vaz, Chairman of the UK Parliament’s Home Affairs Select Committee is building pressure to publish a list of 102 “blue chip” organisations that have “commissioned private detectives that hack, blag and steal personal information” from banks, utilities, the UK’s taxman HMRC and, it is also alleged, from serving policemen. The list has been provided, confidentially, provided to the Select Committee by the Serious Organised Crime Agency (SOCA). Names of some of the firms allegedly on the list have begun to leak.

Twenty-one law firms, nine insurance companies and eight other financial services firms apparently head the list, which also includes management consultants, oil companies, accountancy firms and venture capitalists. Ominously it includes 16 other private investigation agencies, suggesting that the number of end-users could grow substantially.  The FT reports that there is apparently another list, of 200 companies, held by the Metropolitan Police.

Before the 1990s even the courts regularly accepted information from sources such as private detectives.  But things changed radically with the Data Protection Act 1998, brought in to implement an EU Directive of 1995. The legality of fishing for private data changed abruptly, and with it the morality, as the continuing press phone hacking scandal, centred on News International, has shown.

So what is going on in these ‘Blue Chip’ companies?  The fact that you happen to employ a private detective who sometimes uses illegal means to get information does not mean that your information will be gathered by illegal means.   Some companies will have specified “use no illegal means”.  But at the other end of the spectrum, some clients will deliberately have chosen an agency because it is known to be able to obtain hard-to-get personal information.  

When the list is published, some company leaders will be “shocked” to discover that their employees have been using bent private eyes illegally to obtain personal information.

They shouldn’t be surprised.  It is a frequent feature of unexpected crises afflicting respectable companies that the leadership didn’t know what was really going on below them.

We call this the 'Unknown knowns' problem.  It regularly turns out that many people in a firm known things aren’t as they should be, but either no-one is prepared to tell the leadership or the leadership won't listen.  In our recently published research report, ‘Deconstructing failure - Insights for boards’ we found 'Defective information flows to and from the board' were a cause of 60% of the crises we analysed.

The phone hacking scandal created a reputational maelstrom for the media, particularly for News International.  All those on these lists can expect rough treatment by the media, especially those in financial and professional service firms that trade on their trustworthiness.

As leading City commentator Anthony Hilton wrote recently, PR won’t be an adequate solution.  Leaders of implicated firms will have to dig deep to find the real root causes of the problem before they can even start to regain public trust. Scapegoats will not be enough.

Anthony Fitzsimmons
Reputability LLP
London
www.reputability.co.uk

Thursday, 18 July 2013

Boards in the dark

As stories continue to emerge from China this week about GlaxoSmithKline's operations there, it must be an anxious time for the Company Board. Four top Chinese employees have been arrested and are reported as likely to serve long prison sentences for alleged crimes of bribery and price fixing of the company's products - some of which, it is alleged were sold at 10 times their true value. The English head of GSK China, is reported to have left on a one-way ticket in June, and rumours abound about the scale and diverse nature of the alleged fraud. Chinese police claim the total to be over £300m in the last 5 years. Recent annual sales figures for GSK in China have reached £750m.

The alleged scam allegedly involved the use of travel agents to pass money intended for conferences and seminars directly to doctors in return for prescribing GSK products. This type of activity could be difficult to detect as books would balance, and "rewards" in the form of expense claims could easily be made to look legitimate.

How can a Board effectively oversee an operation in another continent, with an unfamiliar culture, where the legal system’s interpretation, responsibility for investigation and ultimate judgement rest with the dominant political grouping? And how can they ensure that their corporate ethos prevails?

A recurring theme in our field, strongly reinforced by our latest research, concerns boards that not only don’t know what is really going on inside the business but don’t even know that they don’t know what is going on – until they discover the gap in their knowledge during a crisis. We call it the 'unknown knowns' problem because it frequently turns out that lots of people internally knew something was amis.  But behavioural and organisational risks have typically kept the board in the dark through an information 'glass ceiling' that prevents unwelcome information moving upwards.  And other behavioural forces can prevent the board’s good intentions from percolating down to the rest of the business.

The GSK board now knows that it may not have known what was really going on in their Chinese business.

The worrying question remains for all boards: to what extent can the board be confident that it knows what is really going on in the business, especially the unwelcome stuff?

Boards need to be aware of vulnerabilities such as these.  It's not easy, but boards need to find and fix these unknown knowns before they cause serious harm.

Mike Bell
Reputability LLP
London
www.reputability.co.uk

Monday, 15 July 2013

Reality Matters

Did the hapless “senior civil servant ” really spend more than £73,000.00 on his personal media training, in order to perform better in front of the Public Accounts Committee, as reported by The Times recently?

The simple absurdity of committing that much money to polish one’s skills for a professional meeting makes me wince.  But it also highlights a current and common over-reliance on  presentation,  design and marketing.

Of course, these are some of the business functions in which the UK is particularly skilled.  Our creative services are world class and their outputs improve our lives in many ways, both personal and professional.  But communications services cannot be cherry-picked to make organisations appear better. All business functions are not equivalent.  Outputs, sales, target must be set and met and companies must be run by boards which have an appropriate level of understanding of corporate activities.  It is astonishing then, that Reputability’s new research, “Deconstructing failure, Insights for boards”  shows that three of the main risk factors that lie at the root of most of the failures studied, are:   “Gaps in board skill-sets and the inability of the Board to influence Executives (88%)”, “inability of boards to engage with fundamental risks to the business (85%)” and, “Defective information flows to and from the Board (59%).  In the majority of the 41 corporate failures studied, Boards simply lacked important information that might have helped them  to prevent a catastrophe. 

Are  the business functions that supply timely, up-to-date and relevant information to Boards less well-developed than  those of their marketing and communications colleagues?    Or are there “glass ceilings” blocking valuable intelligence?  Or, as Margaret Heffernan, author of “Wilful Blindness”  contends that the biggest problems are often, “right in the public eye and require the active participation of hundreds, or sometimes thousands, of people”.  Or is it simply the cumulative inability of people to absorb information that contradicts their existing world view?

Whatever the cause, the post mortems of crises regularly expose a disconnect between corporate claims and corporate reality.   Boards need to be better aware of the quality and extent of their information, something no amount of media training can sort out.


Jane Howard
Reputability LLP
London
www.reputability.co.uk

Thursday, 11 July 2013

NHS culture: lessons from flight safety

After a career in aviation and aviation safety spanning four decades, I have been reflecting on why aviation is so safe but the NHS suffers a succession of disasters.

Aviation wasn’t born safe.  It was a disaster-prone industry until the 1970s but it has been transformed beyond recognition today.  It is extraordinary that in the debate over Heathrow's third runway, the topic of safety is not mentioned. Thirty years ago the increased risk of a crash and its impact on the local environment would have been top of the objectors' agenda.

I despair for improvements in the health service when I see headlines such as "NHS watchdog spent £785,000 on spin team" and on the same day "Death rates for doctors misleading, say experts" These two examples highlight the muddleheaded thinking and lack of clear leadership in the NHS. The fact that the Care Quality Commission is reportedly recruiting a new spin doctor with the task of "expertly managing" its reputation does it no credit at all; and it is reported that they are losing expert inspectors faster than they can recruit them. As if that were not enough, "experts" have pointed out that just publishing surgeons' death rates might be a seriously flawed idea.  They point out, rightly, that death rates have a lot to do with the type of patients, and type of operations performed.

All this shows how a spin-led approach, driven by fear of headlines and devoid of serious analysis, can damage reputations needlessly. Would any surgeon ever consider not operating on a particular patient with a poorer prognosis because of such an approach? We all hope not, but ill-considered regulation could drive surgeons that way.

So what are the differences that have led one safety-critical industry to a crisis of confidence and reputational meltdown whilst over the same time period, another safety-critical industry has gone from unacceptably low levels of safety to such high, measurable levels of safety that safety is not a live issue in the public’s mind?

There are two principal factors involved in aviation’s success: 
  • There is an independent regulator, with a clearly defined role, expert staff, accountable to parliament, and funded by those it regulates; and 
  • There is a culture of openness, with timely and honest reporting of all untoward occurrences whether or not they cause harm and widespread dissemination of the lessons to be learnt. 
These two factors have underpinned the successful story of UK civil aviation safety. Independent safety regulators like UK's Civil Aviation Authority have gained the respect of both politicians and those regulated. It is staffed and led by professionals with actual experience in the industry and technical competence.  As an example, I was the CAA board director with specific responsibility for aviation safety and also had the aviation experience of having been the CAA's Chief Test Pilot.

In contrast, it is clear from the sorry tale of the Care Quality Commission and its predecessors that health regulators have not been free from political influence, and that the views of its own experts have been ignored or suppressed.

Threats from politicians and prosecutors directly discourage an open culture and stop people from reporting occurrences. To manage any industry, managers need to know what is going wrong, and to learn from and fix problems, on a daily basis. This includes near misses. Others in similar operations can then also benefit from this knowledge. This happens in aviation with the CAA publishing a monthly report of aviation occurrences, mostly mistakes or technical problems that did not cause accidents, so that everyone can learn from what has occurred.

All hospitals in the UK should be able to learn from each others' mistakes and experiences of human and technical failures. Giving anonymity has been tried in aviation.  It is a useful backstop, but very few anonymous reports are in fact received. The vast majority of occurrences reported are logged by individuals or operating companies. This is a credit to the open culture prevailing among UK air operators - though ill-informed politicians regularly try to destroy this successful culture by threatening to prosecute those who make mistakes.

Anonymous reporting has been tried in the NHS, but when the same event is reported anonymously by more than one person, it can be very difficult to deal with the results obtained. By far the best way forward is to remove fear of prosecution and persecution and to offer a fair and supportive environment to those who report mistakes they have made. Lessons can then be learnt before they cause serious harm.  With such a culture in the NHS, we would not be hearing of events in the past, where real, recurring but fixable problems have existed, only discovered by subsequent analyses years after the events.

The NHS’ corrosive culture is leading to low morale, and reinforces calls for prosecutions. It is a self-defeating cycle made worse by political interference that comes from distrust, which makes the NHS secretive and much less safe than it should be.

But, it need not be so. The NHS needs a regulatory framework and a culture whose aims are to promote NHS-wide learning from mistakes.  It needs to destroy the current pattern of cover-up and fear that prevents system-wide learning.

It took time for aviation to make flying so safe and it requires constant vigilance to maintain it that way.  There is no reason why the NHS can’t make the transition. But it will require strong leadership and regulation that bases its decisions on good evidence.

Mike Bell, CBE
Reputability LLP
London
www.reputability.co.uk