17 August 2014

Governance revisited

As part of my preparation for a panel discussion entitled The Strategic Roles of Governance in Delivering Enterprise Capabilities for the Open Group Summit in Kuala Lumpur on 18th August 2014, I revisited the topic of governance. The term is often abused in an attempt to make something sound more interesting, with such ridiculous examples as "SharePoint Governance". Governance is something that governors do, not managers. It's the stuff that board members do: they direct, monitor and evaluate how their managers are running the business. Some highlights from various sources follow.

Robert Tricker wrote first book to use the title Corporate Governance in 1984 and defined the difference between governance and management as:  “Management runs the business; the [governance] board ensures that it is being run well and run in the right direction”.

Peter Weill defines governance as “Specifying the decision rights and accountability framework to encourage desirable behaviour in the use of IT” and identifies 5 critical IT domains:
  • principles
  • architecture
  • infrastructure
  • business application needs
  • investment and prioritisation


ISO 38500, the international standard for Governance of IT defines governance as “The system by which the current and future use of IT is directed and controlled.” and stipulates “Corporate governance of IT involves evaluating and directing the use of IT to support the organization and monitoring this use to achieve plans. It includes the strategy and policies for using IT within an organization.”
ISO 38500 refers to six dimensions that need to be addressed:
  • Responsibility
  • Strategy
  • Acquisition
  • Performance
  • Conformance
  • Human Behaviour

Weill’s ‘desirable behaviour’ and ISO 38500’s ‘human behaviour’ are key. It’s about directing, monitoring and evaluating what people actually do. Effective governance recognizes the inherent weaknesses of the human condition and takes appropriate measures.

It has been observed that the most important word in the title of ISO 38500, ‘Governance of IT’, is ‘of’. IT is governed by another body, not by itself. IT departments manage IT, and are governed by directors at a higher level of authority.

While ISO 38500’s scope is limited to IT, COBIT addresses a broader scope, explicitly referring to information and related technology as two separate entities that deserve to be managed in their own right. COBIT’s definition exhibits similarities with ISO38500 because it also speaks about ‘direct and control’: “A structure of relationships and processes to direct and control the enterprise in order to achieve the enterprise’s goals by adding value while balancing risk versus return over IT and its processes”.


11 August 2014

What’s your focus: cars or drivers?

At the LEADit conference in Melbourne on August 13th 2014 I’ll be talking about the pressures that are driving change in IT Departments, and offering three scenarios for career development if you happen to work for an IT Department.

The pressures are twofold and come from opposite directions. First we've got an increasing number of external service providers who offer standard products and services faster, cheaper and often better than IT Departments. This is a natural result of standardization and commoditization of technology, and the specialization of suppliers. The other pressure comes from the IT Department’s customers: the business. Increasingly IT-savvy business people are putting IT Departments under pressure to perform better, faster and cheaper, and are bypassing IT Departments and creating their own IT ecosystem when the IT Department doesn't respond. The IT Department is in the squeeze between both demand and supply.

Given this situation, a plausible future for the IT Department is to become a broker. As Charles Araujo describes it in his book The Quantum Age of IT, there’s a transformation from IT Retail to IT Manufacturing. This entails a significant shift in competences and is not for the weak of heart. But the alternative is extinction. A hundred years ago, many organizations had their own electricity departments with their own generators and technicians. But as electricity became a commodity, they got replaced by external service providers. You get the point.

Another trend is the realization that while the IT systems and services have to be fit for purpose and fit for use, no value is actually realized until the users use the systems effectively and efficiently. Research in the area of productivity loss due to IT issues indicates that by better training and in particular monitoring how users actually use systems can produce productivity gains that are the equivalent of a 20% cost reduction of IT costs. But who ensures that the users are using the systems effectively and efficiently? To use a transport analogy, if the IT Department is in the business of building cars, who’s helping the drivers to get to the right destination? Think about your own organization. Yes, maybe you have super users but odds on that they’re pretty reactive. I’m thinking more about ‘super duper users’ who are tasked with proactive support and guidance. The domain where the super duper users reside, is not in the IT Department. It’s part of the business. Part of the IT ecosystem that I referred to earlier, where the business is developing capabilities to ensure that Demand and Use is just as strong as Supply.

Demand and Use is one of the three options that you could consider as a career move if you currently work for an IT Department. But you’ll have to ‘jump the fence’ and work for the business. The other is to stay put in the IT Department and transform into a broker. The final option, which I believe is best option if you want to stick to the IT Manufacturing part of ITSM, is to work for an external service provider.

12 July 2014

Planes, cars and drivers

I fly a fair bit. Usually economy. But for a recent trip to China I thought that I'd inquire about an upgrade to business class. Maybe I could spend some of my air miles. So on the day of departure at the airport I went to the ticketing office and asked the apparently simple question "Are there any business class seats available and what would it cost me?" The rest of this story hinges around the word "apparently"...

The very attentive lady who helped me kept apologizing for the time it was taking her to give me an answer. "What's the problem?" I asked sympathetically. "Well," she said, "it takes a lot longer with our new system. The system is quite beautiful but it you just can't use it. It used to take us about five minutes but now it takes five times as long". She was juggling with information on the screen and a stack of printouts on her desk, because it was difficult to find the information in the system. We got there in the end and it took half an hour - partly due to her having to call somebody because it was the last seat and she needed human confirmation that it was still available. Surprised by the time it took and the inefficiency, I asked whether this was a common transaction. She said that they do it multiple times a day.

The University of Twente in the Netherlands conducted research into productivity losses due to IT issues and discovered that 6% to 10% productivity loss is caused by IT problems, almost half of which is due to ineffective or inefficient use of the systems. Was the productivity loss in this case caused by lack of functionality for this task or did the ticketing agent simply not know how to use it? We will probably never know.

I speak a lot at IT conferences and share this story to illustrate how IT departments are often oblivious of what happens on the shop floor. And how little effort is spent on ensuring that users actually realize the the systems' potential value. To use a transport analogy, if the IT department is in the business of building and supplying cars, who is helping the drivers to get to the right destination?

21 June 2014

itSMF Ireland's Initiatives for Business IT Collaboration

On August the 19th 2014, itSMF Ireland hosted a workshop that was conducted by Howard Kendall (Service Desk Institute) and Mark Smalley (ASL BiSL Foundation & APMG-International). In the workshop, forty itSMF Ireland members – divided up into seven discussion groups – explored how collaboration between the business and IT could be improved. The results are listed below and can be summarized as:

  • IT needs a better understanding of the business needs and context
  • IT should abandon ‘technical’ SLA’s and explain in more meaningful ways what they’re doing for the business, involving the business in designing the reporting
  • IT should regard itself not as a separate silo but as an integral part of the business
  • The business and IT should talk to each other more often, creating more mutual understanding of pains, priorities, possibilities and limitations
  • The business should stop bullying IT and start trusting them to be their IT partner
  • The business should communicate in terms of problems, no solutions
  • The business should allocate more time to IT, e.g. explaining situation to IT, and training users


Asked which bottlenecks could impede these improvements, several participants suggested "pressure to deliver" as the main reason, while one participant said “we don’t value thinking”.

Involving the business more in all things IT is a high change priority, and somebody suggested thinking about what you’d do if you had the luxury to start from scratch (instead of just patching things up).

A final comment was that unless you have everybody at the table and have their buy-in, you won’t achieve much (we’ve been working with separated silos for too long).

Details per group:

Group 1
• IT collaborates with the business (getting insight into needs, wants, wishes, desires)
• IT benchmarks whether they are delivering what the business wants
• IT increases engagement with the business
• IT bins the SLA
• IT makes IT easy (inspired by Amazon etc)
• IT stands up and shows (doesn’t hide; shows users what IT does; sells IT; shows what IT can do)
• IT promotes IT as a business enabler

Group 2
• IT understands the business
• IT uses better reporting to give feedback, explaining what they do
• IT regards itself as part of the business

Group 3
• IT embeds ITSM in all business projects and vice versa
• IT uses business-oriented dashboards with design input from the business
• IT designates an IT service owner and the business designates a business service owner
• “Division of business and IT is irrelevant”
• IT communicates, communicates, communicates

Group 4
• Business creates business awareness
• Business and IT ensure strategic alignment
• The business invites the CIO to sit at the top table (but not as a minister without portfolio)
• Business makes IT aware of business pain
• IT makes business aware of IT pain
• Business makes IT aware of users’ needs
• Business shares knowledge with users, enabling users to fix own issues
• Business and IT communicate better especially about changes

Group 5
• Business stops bullying IT
• Business and IT collaborate more
• Business and IT agree what is important
• Business asks IT to help them understand what they want
• Business allocates more time to IT (e.g. explaining to IT, training users)

Group 6
• Business gives IT problems, not solutions
• Business trusts IT to be the IT experts
• Business shares strategy/plans/goals early
• Business revisits project scope regularly

Group 7
• Business listens
• Business communicates
• Business keeps it simple

13 May 2014

Information Management Workshop at The Open Group Amsterdam Summit




25 attendees at The Open Group Amsterdam Summit participated in a workshop about Information Management on May 13th 2014. A short version of GamingWorks’ BookStore® business simulation was played, in which the participants were divided up into three groups: Business, Information Management and IT. The game simulates a bookstore that is tasked with improving its revenue and profit by introducing new products and services than depend heavily on information and related technology. Business, Information Management and IT have to collaborate effectively and efficiently to translate business demands into working functionality.

After playing the first iteration of the game, people remarked on the similarities with real life, for instance “I only heard at the last minute that I had to develop the application” and “The business wants a cloud but doesn’t know why”. Somebody made a comment that he wished that his company had such effective feedback loops as in the game. The ‘CEO’ made a wistful remark about this fictitious (and closely collaborating) enterprise: “I had the company that I’d like to work for”.

As usual when playing games, the first iterations are interspersed with minor issues such as the Information Manager interrupting discussion with “Why am I not part of this meeting?” and somebody in a project planning meeting saying “Where’s the project manager?”.

The majority of the participants being architects, several comments were made about the relevance of architecture: “Don’t think solutions, think architecture”, “Architecture happens, one way or another – if it’s not top down it’ll be bottom up”, and “Architecture is about feasibility and change”. Alignment of Architecture and IM was also mentioned including the question how to organize architecture across Business, IM and IT and the need for a reference model. Somebody stated that Architecture should be part of the CIO Office: “You need someone (EA) with a vision of the whole”. An aside about the CIO Office: “What will the CIO Office look like when everything is in the cloud?”

One of the interesting topics that was discussed in length was how Demand and Supply is organised across the whole IT value chain (Business, Information Management and IT). Is Information Management part of the business and therefore Demand? Or is Information Management the front end of the IT function and therefore Supply? Somebody commented that it doesn’t make that much difference – they’re just part of the whole process. Another valuable comment was that Demand/Supply is not just a ‘line’ but encompasses activities such as planning. Maturity was also referenced, in particular its influence on the positioning of Information Management and IT: “When you’re immature you’re just an order-taker”. Another valuable point was how positioning has changed – in the beginning IT was about ‘support’ but we’re moving through ‘aligned’ and ‘integrated’ towards ‘co-creation’.

The final take-away was the finding that in real life the Business and IT are often so isolated from each other that major improvements can be made just by getting the two parties to talk to each other more often. This is why organizations often use BookStore® game ‘in house’ to improve the collaboration between various departments.
  

The BookStore® workshop was facilitated by Christian Nissen and Mark Smalley. 

26 March 2014

IT Value Chain

Summary
 Issue: Technically-oriented people often find it difficult to ‘sell’ their initiatives to decision-makers, resulting in missed opportunities, frustration and a poor image for the IT department.
Guidance: The IT Value Chain is a way of articulating the outcomes of an IT initiative in terms that make sense to business people, e.g. more business, better business, cheaper business.

IT Value Chain

The IT Value Chain is a way of articulating an IT initiative in terms of benefits for both the business (IT’s customer: the user organization) and the IT organization. Being aware of how an IT solution impacts the ‘bottom line’ is beneficial to both the design of the solution and to how to ‘sell’ it to the business. 


Business goals
In the example above, based on a generic commercial enterprise, the bottom line performance is expressed in terms of profit, which is of course the difference between revenue and costs. Costs (the red lines) are either related to IT or the business. Revenue (the blue lines) comes from selling more products and/or services, and/or selling better products at a higher margin. Business goals are expressed simplistically as more, better and/or cheaper business. These goals apply to many commercial enterprises but can be adjusted to accommodate other relevant aspects, for instance capital investment. Public organizations are usually driven by different goals; for instance the criminal justice system in England and Wales aims to "reduce crime by bringing more offences to justice, and to raise public confidence that the system is fair and will deliver for the law-abiding citizen”. So the right hand side of the IT Value Chain should be constructed accordingly. Identifying the enterprise’s goals is an important part of the IT Value Chain process because it focuses the attention on the right aspects.

Business benefitsThe left hand side of the example shows how the outcomes of an IT initiative can be split up into two parts: business benefits and IT benefits. Business benefits have been broken down into better functionality, quicker time to market, and fewer and shorter outages. Better functionality can have service multiple business goals. Better functionality can simply mean that business processes can be executed more efficiently, by automating manual work and reducing labour costs. But better functionality can also contribute to better customer service by providing employees and/or customers with information that enhances the customer experience, for instance by giving insight into current waiting times at a hospital department. And better functionality can also contribute to achieving more business by giving access to new markets through different channels.A quicker time to market means that the IT solution is delivered promptly, enabling the other benefits to be achieved earlier, and for instance beating a competitor to a new market.Fewer an shorter outages contribute to business efficiency but also to a better customer experience, and in turn to better business. Just as the business goals can differ from enterprise to enterprise, these benefits can also differ.

IT benefits
In addition to the business benefits, there are benefits for the IT organization, that translate into lower costs and/or an improve capability to deliver the business benefits. The IT benefits in the example are a more flexible, more productive, and cheaper IT organization. Investment in Agile could make an IT organization more flexible. Investment in tooling lead to better productivity. And application rationalization could reduce IT costs. But just as the business goals and benefits can differ from enterprise to enterprise, these benefits can also differ.

Desired attitude and behavior

Attitude
Being aware of the importance of translating the output of IT initiatives into outcomes that are formulated in such a way that business people understand them
Realizing that users often exhibit irrational (‘normal’) behavior and that just communicating in terms of logic may not be effective
   
Behavior
Engaging with business people to identify the relevant business goals and in so doing, to demonstrate commitment to supporting these goals 
Talking about the IT solution ‘above the line’, i.e. in terms of the benefits and how they affect the business goals
Monitoring the actual results in terms of the benefits and the business goals

Additional guidance

COBIT®5 guides enterprises in rigorous governance and management of processes and other enablers related to demand, supply and use of information and technology. It provides excellent guidance for assurance of benefits realization, risk optimization and resource optimization.

Managing BenefitsTM has been carefully designed to complement existing Best Practice in portfolio, programme and project management such as PRINCE2®, MSP®, P3O® & MoP®. It consolidates existing guidance on benefits management into one place, while expanding on the specific practices and techniques aimed at optimizing benefits realization.

The underlying structure of the IT Value Chain has been inspired by the DuPont Analysis and Capgemini’s Benefits LogicTM.

References
COBIT®5 - www.isaca.org 
Managing BenefitsTM - www.apmg-international.com
DuPont Analysis -  www.wikipedia.org 
Benefits LogicTM - www.capgemini.com 


17 February 2014

3 career options if you work in a traditional IT department


IT departments are under pressure from two sides. On the supply side from multiple external service providers that are encroaching into the IT departments’ space and eroding jobs. And on the demand side from the business that is claiming a more dominant role and is engaging external service providers directly, but that at the same time is struggling with their new responsibilities. No, you weren’t expecting this and no, you probably don’t welcome it. But it’s happened and it’s called progress. If you work in an IT department, you have three main options.
  • If you want to continue doing IT service management as you always have done, go work for an external services provider.
  • If you have feel for logistics and retail, stay in the IT department and develop the competences that will help the IT department fulfill an ‘IT Retail’ function. With increasing technological standardization, ‘IT Manufacturing’ has moved from the IT department to the external service providers.
  • If you understand the business and get along well with business people (or ‘normal people’ as my wife likes to call them), jump the fence and move across to the business, where business and IT are morphing into a new function.
Things will change, they might just change without you. So go reinvent yourself.