08 January 2015

Managers don't govern, they are governed

As people often use the word 'governance' in various and therefore confusing ways, I spent a while looking at some authoritative sources of governance wisdom, from which I've summarized the statements below. I now have a better understand of what governance is and what it is not. The statements without a reference, are my own opinions.

1. Corporate governance is the system by which organizations are directed and controlled. [ISO 38500, 2008, adapted from Cadbury, 1992 and OECD, 1999]

2. Boards of directors are responsible for the governance of their companies. [Cadbury, 1992]

3. The shareholders’ role in governance is to appoint the directors and auditors, and to satisfy themselves that an appropriate governance structure is in place. [Cadbury, 1992]

4. The responsibilities of the board include setting the company’s strategic aims, providing the leadership to put them into effect, supervising the management of the business and reporting to shareholders on their stewardship. [Cadbury, 1992]

5. A board of directors often has several committees, e.g. compensation committee, audit committee and governance committee,  to assist the board with the discussion and decision making within the board. [Andriole, 2009]

6. The board determines, within the bounds of laws and regulations,  which aspects of their organization they wish to direct and control by means of policies and plans that they issue to their executives, and, implicitly or explicitly, which aspects are left to the discretion of their executives.

7. From a semantic perspective, when directing and controlling aspects of the organization are delegated to executive management, this should be called management, not governance.

8. Directors are members of the most senior governing body of an organization, and include owners, board members, partners, senior executives or similar, and officers authorized by legislation or regulation. [ISO 38500, 2008]

9. Governance is by definition non-executive, although directors may also have other roles of an executive nature.

10. Directors should govern IT through three main tasks:
a) Evaluate the current and future use of IT
b) Direct preparation and implementation of plans and policies to ensure that use of IT meets business objectives
c) Monitor conformance to policies, and performance against the plans
[ISO 38500, 2008]

11. Governance ensures that enterprise objectives are achieved by evaluating stakeholder needs, conditions and options, setting direction through prioritisation and decision making, and monitoring performance, compliance, and progress against plans. [COBIT 5, 2012]

12. Management plans, builds, runs and monitors activities in alignment with the direction set by the governance body to achieve the enterprise objectives. [COBIT 5, 2012]

13. When an auditor reports to the board, auditing is part of governance's monitoring activities; otherwise it's part of management's monitoring activities.

14. Managers (including senior executives in their role as executives) don't govern, they are governed. They participate in governance activities by following the board's directives, and by demonstrating that they have done so - this is part of their management task. 


REFERENCES
[Andriole, 2009] Boards of Directors and Technology Governance: The Surprising State of the Practice, Stephen J. Andriole
[Cadbury, 1992] Report of the Committee on the Financial Aspects of Corporate Governance, Adrian Cadbury 
[COBIT 5, 2012] www.isaca.com
[ISO 38500, 2008] www.iso.com
[OECD, 1999] OECD Principles of Corporate Governance



11 December 2014

Contemplations on 2015

As for 2015, I’m expecting to see continuing interest in improving multidisciplinary collaboration using stuff like as Agile, DevOps, and Cynefin, and intrinsically linked to that, more interest in how to influence behaviour. My concern is the gap between understanding how to influence behaviour and actually doing something about it. The human condition.

I've noticed increased interest for security in 2014, although I haven’t investigated what’s driving it. I assume that’s going to be a 2015 topic.

It’s a no-brainer to expect continuing growth of (use of) external service providers and therefore the need for multi-vendor management (think SIAM). Because the market often does IT better, faster and cheaper than internal IT departments, we can expect internal IT to transform itself into a broker between demand and supply. Not everybody is suited for that role though – barring genetic manipulation – so consider your options carefully if you work in a centralized IT department. You have three options. If you want to continue doing traditional ITSM, quit and work for an external service provider – it’s their core business. Your second option is to help your IT department transform itself into a broker. Finally, if you have affinity with business processes and business people , jump the proverbial fence between IT and the business and help them deal with demand for, and use of, IT. And information, which is why I like to talk about I&T not IT.

Similarly, as business people become more IT-savvy, and they have more IT at their disposal without having to shop at the internal IT department, we’ll see more decentralized I&T functions within the various business divisions and departments. They’ll only use centralized IT if they have to or if centralized IT gets its act together and offers perceived added value. They will operate with the same degree of autonomy as the rest of their business activities, so expect more emphasis on effectiveness than enterprise-wide efficiency. I also expect that they’ll struggle with the basics of ITSM (incident, problem, change etc.) so that’s a great opportunity for seasoned ITSM practitioners to help them balance agility with an appropriate degree of predictability.   

We’ll see various versions of CIO’s in various relationships with CXO’s. Will governance of I&T be embraced by the board as more than an afterthought? Are I&T as business assets really as important as the CIO and his or her I&T minions think? Or does the board have better things to do? We’ll see.

  

Recap 2014

Well, well. This ASL BiSL year took me to 16 cities, 12 countries and 4 continents. In terms of communities, I spoke and networked at events organized by APMG, BPMA, itSMF, PMI/IIBA, SDI, SITS, The Open Group, UNICOM, and Yale. In addition, I delivered webinars hosted by APMG, BrightTALK, TFT, and UNICOM. 

Slowly but surely, there’s more interest in ASL and BiSL in particular from beyond the home market in the Netherlands. I've come to believe that ‘Going Dutch IT’ – in other words making a pretty formal distinction between IT supply as the responsibility of the IT function, and demand and use as the business’ responsibility – might just have been a bridge too far for other regions in the past, but now that many business divisions are investing in the their own decentralized I&T functions (see below), it seems to becoming more pertinent and interesting.

My major topics this year were:

1. The changing dynamics within the ITSM industry, with more dominant roles for external service providers and for business units who are investing in their own decentralized I&T functions. The traditional centralized IT department is under pressure and its best bet as far as I’m concerned is to transform itself into an added value broker. Otherwise it’s over and out. The future of the decentralized I&T fascinates me. It’s where demand and supply are merging into a new paradigm: ‘deply’ or ‘summand’. By the way, please note the use of ‘I&T’. I continue to promote treating information and relate technology as two intimately intertwined entities that nevertheless are better off when managed in their own right.

2. BizDevOps (also known as ValOps): predicting the next wave of multidisciplinary collaboration. We’ve seen organizations apply Agile to improve the speed and quality with which new functionality is developed, and DevOps that improve the speed and quality of deployment. But there are still a couple of gaps that need to be addressed. Firstly the gap between high-procedure and bureaucratic ITSM functions and the business users. All too often, users are left to their own devices (literally!), leading to avoidable productivity losses in business operations. Secondly, there’s a need for better business-business alignment. No, that’s not a typo. The managers or their delegates who specify user needs during development projects, often in the role of an Agile product manager, lack insight into the practicalities of business operations and use of information systems, leading to a lower return on investment than could have been the case. 

3. Building bridges between bodies of knowledge. The ASL BISL Foundation has explored how its Application Management and Business Information Management domains interact with Business Analysis (IIBA’s BABOK®), Business Relationship Management (BRM Institute’s BRMP®), Enterprise Architecture (referencing The Open Group’s TOGAF®), Governance and management of information (ISACA’s COBIT®), IT Service Management (AXELOS’ ITIL®), and the Service Desk (SDI’s qualifications). I’m currently taking a look at IAITAM (Asset Management), and the IMBOK (Information management).

4. Exploring which behavioural changes are needed with both IT and the business. I conducted various workshops and have complied the findings. The consensus us that the business should focus on specifying outcomes rather than solutions, setting priorities and taking decisions, and understanding IT capabilities and limitations. And that IT should pay more attention to understanding the business context, communicating in terms of benefits, costs and risks, and replacing ‘technical’ SLA’s by more meaningful reporting.

5. Contributing modestly to the Take Service Forward initiative’s Adaptive Service Model, which has certainly given me a better way of looking at organizations. It gives me great satisfaction to see that ASM is being taken seriously by various industry bodies.

From a learning perspective, things that spring to mind are how I’ve benefited from (1) dealing with uncertainly by using Cynefin (you’ll easily find a great talk by Dave Snowden called Models, Frameworks and Messy Coherence, hosted by UNICOM), (2) using service-dominant logic (read the academic paper ‘The service system is the basic abstraction of service science’), (3) understanding social constructivism (e.g. Vimeo presentation ‘Ken Gergen talks about Social Constructionist Ideas, Theory and Practice’), (3)  a new way of looking at life in general as formulated by Michael Foley (YouTube ‘This Extraordinary World’), and (4) Adam Smith's 1759 classic The Theory of Moral Sentiments revisited by Russ Roberts in his book ‘How Adam Smith Can Change Your Life: An Unexpected Guide to Human Nature and Happiness’.

06 October 2014

Is the board on board?

At the annual itSMF Finland conference in Helsinki on October 2nd, I asked the opening keynote speaker, Frans Westerlund, CIO at Fiskars Corporation, about the attitude of the Fiskars board members with respect to IT. He said that he considered himself very lucky because the board members had a good understanding of IT and how to deal with it. He explained that many of them had learnt the hard way that you need to treat IT seriously in order to prevent disasters and ensure a good return on investment. He also mentioned being fortunate to be a permanent board member, instead of being invited to a board meeting just to report about IT, and often being the last and least important item on the agenda. I believe that it’s useful to distinguish between three scenarios:

Board on board
The Fiskars scenario is pretty much ideal, in which the board is conscious of the need to take ownership and is competent to govern IT. Unfortunately this is not often the case, as Frans intimated with his remarks about being lucky.

Lost at sea
The doom scenario at the other end of the spectrum is of course the unconscious/incompetent combination. Attempts by the CIO to ‘sell’ the governance role to the board have fallen on deaf ears, and only a (near) disaster will get the message across. The CIO and his or her team will just have to play a defensive game in damage control mode until the climate changes.

Waving, not drowning
A more promising scenario is when the board is conscious of the importance of IT and is managing but struggling with their governance capabilities. This is probably the ideal situation to play the BRM card. Not that you shouldn’t deploy Business Relationship Management in the other two scenarios, but you’ll probably get the most return in terms of capability growth.

According to the BRM Institute, Business Relationship Management is not only a role ‘Business Relationship Manager’ but also an organizational capability in the sense that many roles contribute to BRM, particularly the customer-facing ones such as those tasked with service desk and service level management. The Business Relationship Manager fulfils the role of an expert trusted advisor who has sufficient expertise in key business domains to be able to communicate the costs, the business value, and the risks of services in clear, specific, and meaningful terms using the language the business partner understands. The Business Relationship Manager is completely transparent about the costs, benefits (business value and ROI), and risks of a service. It is the Business Relationship Manager’s job to make sure that both the business partner and the service provider have complete clarity. Finally the Business Relationship Manager practices informed leadership, engaging from the moment the business strategy is formulated to shape its implications on the IT service delivery, overseeing its execution, and planning the next improved iteration. The Business Relationship Manager understands the business and service dynamics well enough to foresee and guide rather than be pushed around by changes.

CIO’s who recognize this opportunity to demonstrate their collaborative value are well-advised to invest in this strategic role. An important precondition is that ‘IT-as-usual’ is under control before you start talking about the strategic use of IT. If so, carefully select somebody who will serve as the strategic interface between the provider and one or more business partners to stimulate, surface, and shape demand for the provider’s products and services and ensure that the potential business value from those products and services is defined, realized, optimized, and recognized. Consider not only the technical proficiencies but in particular the relational competences and personal fit with the business partners.

Various standards and frameworks provide board level guidance, amongst which:

ISO/IEC 38500:2008
The international standard for Governance of IT sets the scene for the board’s role by providing a principles for evaluating, directing and monitoring the use of IT in their organization. ISO 38500 assures stakeholders (including consumers, shareholders, and employees) that, if the standard is followed, they can have confidence in the organization’s corporate governance of IT. It also informs and guides directors in governing the use of IT in their organization and provides a basis for objective evaluation of the corporate governance of IT.

COBIT® 5
The COBIT framework helps enterprises create optimal value from IT by maintaining a balance between realising benefits and optimising risk levels and resource use. In particular, COBIT’s Goals Cascade is useful in translating strategic business goals into concrete goals for IT-related enablers.

ITIL® 2011
The ITIL framework is referred to by COBIT for more detailed guidance for the supplier of IT services. This guidance spans service operations to service strategy, and at the strategic level, the service portfolio represents the commitments and investments made, and the related value, outcomes, costs and risks.

BiSL®
Similarly, COBIT also refers to BiSL. This framework provides guidance from operations to strategy for both information management and demand and use of IT services, complementing ITIL’s supply-oriented guidance. At the strategic level, policies regarding data ownership and strategic use of information – e.g. Big Data and Social Media – are board level topics.

With the exception of ISO 38500, board members are not expected to understand these frameworks but the BIO and the Business Relationship Manager will make use of this guidance in their board level interactions. The board should foster a culture in which business and IT share the same table and have a joint vision. The board should also encourage effective behaviour. Examples of effective behaviour are that the business takes the lead by specifying and prioritizing desired outcomes from IT investments, and trusts IT to propose options for solutions. IT then communicates the various solutions in terms of the associated benefits, costs and risks, in order that the business can take well-informed decisions.

COBIT is a registered trademark of ISACA.
ITIL is a registered trademark of AXELOS Ltd.
BiSL is a registered trademark of the ASL BiSL Foundation.


05 October 2014

Behaviour that gets more business value out of IT

Defining desired behaviour is recognized as an essential part of getting more return on investment in training and improvement initiatives. It is the bridge between the problem that an organization wants to solve, and the competences and training that are needed to solve it. The 8 Fields Model that GamingWorks uses and recommends described this in more detail.

I conducted a workshop about desired behaviour at the annual itSMF Finland conference in Helsinki on October 2nd 2014. The question that the participants discussed, was “Which behaviour will get most business value out of IT?”. The participants focused on the behaviour that the business should exhibit, in their role of IT’s customer. They said that the business ideally:
·        Shares the strategy / big picture / longer-term plan with IT
·        Discusses the ‘why’ behind IT investments with the IT department and reaches agreement
·        Improves its understanding of IT and the IT dept’s capabilities
·        Trusts the IT department with the ‘how’
·        Formulates concrete and simple targets, and expected measurable value 
·        Defines and prioritizes needs and requirements
·        Leads and executes business change management and global portfolio management, in close collaboration with IT
·        Takes charge of the business’ information and its flow

In the past 12 months I have conducted two similar workshops together with SDI’s Howard Kendall for itSMF UK in Birmingham and itSMF Ireland in Dublin. The two workshops also considered the behaviour that IT should exhibit. Combining the findings from these three workshops, we have three groups of desired behaviour from the business, the IT function and the enterprise as a whole.

The business:
·        Has a good understanding of IT capabilities
·        Shares the strategy / big picture / longer-term plan with IT
·        Discusses the ‘why’ behind IT investments with the IT department and reaches agreement
·        Specifies outcomes rather than output
·        Prioritizes outcomes
·        Formulates concrete and simple targets, and expected measurable value 
·        Is the accountable owner of information systems
·        Leads IT
·        Doesn’t bully IT but trusts them to be their IT partner
·        Allocates more time to IT, e.g. explain situation to IT, train users, inform users about changes
·        Leads and executes business change management and global portfolio management, in close collaboration with IT
·        Takes charge of the business’ information and its flow

The IT function:
·        Has a good understanding of the business’ need and context
·        Communicates in terms of benefits, costs and risks, in order that the business can take well-informed decisions
·        Abandons ‘technical’ SLA’s and explains in more meaningful ways what they’re doing for the business, involving the business in designing the reporting
·        Regards itself not as a separate silo but as an integral part of the business

Finally, the enterprise fosters a culture in which business and IT share the same table and have a joint vision, and the business and IT talk to each other more often, creating more mutual understanding of pains, priorities, possibilities and limitations.

04 October 2014

ITSM in 2020

When I was asked to participate in a panel discussion at the annual itSMF Finland conference in Helsinki on October 3rd 2014, I did some preparation. Unfortunately, I misread the topic and prepared to share my vision about IT Service Management (ITSM) in 2020, rather than my vision about itSMF and ITIL as requested. The good news was that ITSM is of course closely related to itSMF and ITIL. It added an extra dimension to the discussion in the sense that both itSMF and ITIL exist to serve ITSM. Both itSMF and ITIL should therefore be aligned with how ITSM is changing. We discussed that itSMF and ITIL should have different value propositions for each of the markets that they serve. I distinguish between internal IT departments and external service providers (ESP), and within internal IT departments I make the distinction between centralized IT departments and decentralized I&T departments within the various business divisions. ‘I&T’ refers to information and related technology: two intimately intertwined entities that should be managed in their own right. My vision for ITSM in 2020 is summarized in the following statements:

  • Non-differentiating IT services will be provided by ESP’s; differentiating application of I&T will be performed by decentralized I&T departments in the business; centralized IT will focus on governance and architecture
  • ESP’s will provide more and more of the services that IT departments used to provide - better, quicker, cheaper 
  • Centralized IT departments will transform into brokers – if they can integrate services better than ESP’s
  • Decentralized I&T departments will perform ITSM as part of their activities but the major part will be the application of I&T
  • ITIL will remain the same but will be applied selectively, depending on who uses it:
    • ESP’s need full blown ITSM but will they use ITIL? (does Amazon use ITIL?)
    • Brokers will focus on Service portfolio management, Business relationship management, Supplier management, Information security management
    • Decentralized I&T departments will be innovative but ‘immature’ in ITSM, and will benefit from the basics, e.g. incident / problem / change 


01 September 2014

Is the business the weakest link in the IT value chain?

Here are six questions that identify business responsibilities that are often less mature than their IT equivalents and therefore need attention to prevent them from being the weakest link in the value chain.

  • If the IT department identifies new technological developments, who identifies the opportunities to apply them to innovate the business?
  • If the IT department builds solutions, who identifies demand and specifies requirements?
  • If the IT department runs the information systems, who ensures that they are used effectively and efficiently?
  • If the IT department manages the service level agreement from a provider’s perspective, who manages the contract as the IT department’s customer? 
  • If the IT department’s Business Relationship Manager manages IT’s relationship with the business, who manages the business’ relationship with IT?
  • If the IT department manages the applications and infrastructure, who manages information and technology as business assets?

So how do you score?