article review
' \
or Mitigating Risks to alleviate the common problems of limited staff, time, and budget
R ecords management has become an integraJ iispect of how most large organiza- tions do business - ¡n fact, It's increasingly taking center
stage. While many organizations have implemented or are in the process of implementing enterprise records manage- ment solutions, there seems to be var)'ing degrees of utilization, success, and return on investments. Establishing a sound records management program in today's environment requires not only a thorough understanding of the fundamenta! records management principles but also the legal, regulatory, financial, and operational requirements of the organization.
At the Core This article
• • Identifies the need for a risk-based approach to records management
• Defines the risk-based approach
• Describes lessons learned in apply- ing the risk-based approach
Frequently, organizations have well- intentioned strategies and well-chosen technologies but have trouble orchestrat- ing them to develop and deliver a cohesive enterprise records management platform. Furthermore, records management is a complex task made more so with the advent of newer types of media, formats, locations, and technologies.
Records managers are being asked not only to manage the traditional paper and electronic files but also to address more esoteric pieces of information such as instant messages, blogs, and wikis. As most corporate records managers will attest, senior management wants to comply with records management requirements, but questions the hard returns and the busi- ness value provided by implementing a records management program. Records managers are, thus, increasingly, turning their attention to the tangible value that the records management program can offer the organization.
A clear-cut example of a return on
The Inlormotion Management Journal 4 9
investment is in the e-discovery space. Fifteen years ago when litigations were not as prevalent and legal fines were some- where on the order of a slap on the wrist, records management was considered an operational/legal expense. These days, however, e-discovery and litigation spe- cialists are propounding the solid benefits of a proper records management program and are providing numerous real life data points on the millions of dollars saved through more efficient ways to locate, search, categorize, and present records.
Chief executive officers, chief financial officers, and chief operational officers are looking at records management in some- what of a new light and recognizing the
ly clear that attempting to manage the uni- verse of all records wiil simply result in a black hole. The data ocean in most organ- izations shows no sign of ebbing; instead it's increasingly akin to a perfect storm, threatening to wash over most well-inten- tioned controls and processes.
The most well-thought-out records management program can be subverted by the most innocuous of things (e.g., the thumb drive), Records managers thus have the dubious distinction of seeing no new dollars but having to manage a more significant workload. How then are records managers ever going to soive the records management problem? Are they going to be in catch-up mode forever,
The data ocean in most organizations shows no sign of ebbing; instead it s increasingly akin to a perfect
storm, threatening to wash over most well-intentioned controls and processes.
bottom line value that a solid records management program provides. This new visibility, however, has not translated into significant new spending on records man- agement. In fact, in some organizations, records managers increasingly face budg- etary constraints and ongoing pressure to better manage records in this litigious environment.
Given the long-term nature of records management and the ever-changing land- scape, it is no surprise that records man- agers have felt the need to invest in more systematic approaches, including auto- dassification of records, auto-promotion of records when certain events in the busi- ness process happen, automated disposi- tion, and having to make somewhat large- scale assumptions around the true scope and requirements of the program. There have been instances where comers have been cut because the work involved was too much, too soon, and there was just not enough time in the day to address it appropriately.
Records managers have thus made the best of what they could with the best of what they have. It has become increasing-
chasing one fire drill after another? Is there a pragmatic way to address the issues at hand?
There are several methods that a num- ber of records managers across various organizations have implemented to ensure that records are properly managed given all the constraints. One method to serious- ly consider is a risk-based approach to records management.
The Risk-Based Approach to Records Management
Picture a budget meeting where the first hour goes perfectly. The records man- ager presents the work plan for the year, talks about accomplishments for the past year, reviews the new litigation and regula- tory landscape affecting the company, talks about the return on existing invest- ment around increasing the availability, integrity, and authenticity of records, and finally presents a reasonable and minor increase in the budget.
The smiles in the room drop, the silence becomes deafening; the cold air in the room could be cut with a pocket knife. The records manager just committed a
cardinal sin - asking for more. Suffice it to say that the post-meeting message was very loud and very clear - no new budget or the records manager will be searching soon for a new job.
Wliile this describes a hypothetical sit- uation, the reality is that records managers are currently facing a fiindamental issue in setting boundaries around what to man- age in a restricted budgeting world. New information channels are emerging almost every year, and the difficulties in managing them make it virtually impossible to tight- ly control all possible sources of records. It is thus imperative tor records managers to establish a well-defined execution model that meets legal and regulatory require-
ments and at the same time is not cost- prohibitive and resource-intensive.
One good outcome of applying the risk model is that it provides a fairly quick and clear-cut picture of the organization- al areas where there is significantly more risk probabüity than others. This is iio( to say that records that do not full into the high-risk areas can be ignored. Rather, it is to emphasize that the level of effort must be prioritized on securing records consti- tuting higher risk first. Prioritizing effort becomes all the more evident when records management has limited staffing, time, and budget, and using the risk-based model to prioritize the areas that will be addressed first becomes a much more practical approach.
The risk-based approach to records management is one approach to mitigat- ing the issue of limited staff, time, and budget. This approach takes into account the most critical factors affecting a com- pany and then addresses the correspon- ding set of records in a sound and princi- pled manner.
Simply put, the risk-based approach has arisen fix)m the need to balance prop-
5 0 The Information Management Journal • J u l y / A u g u s t 2008
er records management with the harsh
realities of budgets, time, and resource
constraints.
Risk Deñned According to Wikipedia, "risk" is a
concept that denotes a potential nega- tive impact to some characteristic of value that may arise from a future event. Exposure to the consequences of uncertainty constitutes a risk. In every- day usage, risk is often used synony- mously with the probability of a known loss.
In the context of records manage-
records management controls, organi- zations should consider conducting a comprehensive risk assessment of their records management controls to gauge how effective the controls are and to identify and analyze any gaps.
In some cases, records management controls are well-intentioned, but they fail to produce the desired impact in the long term. Records management risk assessments can proactively bring for- ward records management controls that are not very effective. A six-step model for assessing records management con- trols is reproduced below.
in tne context ot records management, risk plays an important role in determining the exposure of
an organization to its legal, financial, and / operational well being.
Financial Risk. Impact to financial well being of the company; includes loss that can be reflected in financial state- ments (such as loss or damage to assets), or an indirect loss (such as addi- tional requirements on staff time or loss of market share).
Operational Risk. Risk of loss result- ing from inadequate or failed internal processes, people, or systems and from internal and external events; includes operational incidents.
"Reputational" Risk. Failure to meet business expectations or obligations resulting in damage to the organiza-
ment, risk plays an important role in determining the exposure of an organiza- tion to its legal, financial, and operational well being. The appetite of an organiza- tion to deal with the risk of failure of a records management control is usually limited and, in these days of highly liti- gious environments, it makes organiza- tions wary of not being able to demon- strate proper records management.
The Committee of Sponsoring Organizations of the Treadway Com- mission's Internal Gontrol - Integrated Framework defines internal control as "a process, effected by an entity's board of directors, management, and other per- sonnel, designed to provide reasonable assurance regarding the achievement of objectives in the following categories:
• Effectiveness and efficiency of oper- ations
• Reliability of financial reporting
• Compliance with applicable laws
and regulations"
Records Management Risk Assessment Model
To effectively manage and establish
1. Determine Records Management Risk.
Review the corporate landscape to determine what constitutes the highest risk to the organization. Each organiza- tion, given its unique way of doing busi- ness, will have varying degrees of risk tolerance, and knowing what the most critical risk factors are vrill go a long way in establishing the right set of policies, procedures, and controls around records management.
Wlien determining risk, consider the key factors that affect the organiza- tion:
Legal Risk. Risk arising from pend- ing or potential legal action; legal driv- ers including legal retention require- ments, history of litigation holds, sub- poenas, and previous fines or legal actions; e-discovery requests; includes violation of privacy and non-public information laws.
Regulatory Risk Federal/state agency rules and/or regulations such as from the Securities and Exchange Commission and the National Association of Securities Dealers; includes risk associated with the inability to produce records as part of a governmental audit, examination, or inquiry.
tion's public image, confidence, or repu- tation.
For each of the risk factors, deter- mine a score card and a weighted matrix to enable proper classification and cate- gorization of records management risk. This will assist senior management in identifying affected areas and selecting the appropriate response and imple- mentation plans.
Through this exercise an organiza- tion can prioritize the records manage- ment implementation process by deter- mining the most critical records that affect its day-to-day operations and provide appropriate controls based on priority to manage those records.
2. Determine Probability. For each of the identified risks,
determine the likelihood of the risk occurring. History repeats itself, so they say, and past occurrences may be a good indicator of the probability that the risk incident will happen again. Under- standing the risk probability is an important factor when determining the records management controls needed in various parts of the overall information life cycle of the organization.
5 2 The Informotion Manogemenf Jojrnol - July/Augjsl 2008
Applying a Risk Model to Records Management
Determin« Risks
Probability
Criticality
Risk Mitigation
Risk Controls
Measure & Monitor
Process & Procedures Inventory & Retention
3. Analyze and Detemiine Criticality. Once the risk and the associated prob-
ability are known, analyze the impact of the risk occurrence. For example, in some companies, "reputational" risk can make or break the entire business model. In this case, the organization must ensure that any and all records affecting the crganiza- tion's reputation are tightly contre'lied and managed. This does not mean that the remaining risks are not important, but it simply provides a mechanism for the organization and, in turn, the records managers to identity on which aieas they need to focus first.
4. Detemiine Risk Mitigation. Determine mitigation strategies for
each oí the identified risks, keeping in mind the associated criticality and proba- bility of occurrence. Each risk and its asso- ciated mitigation response must lave the right set of controls and prcicedures around them. An example of risli mitiga- tion would be the response to an organiza- tion's financial risk. To mitigate the finan- cial risk, proper controls and che;ks have to be establi.shed around the afsociated records, including policies, procedures, approvals, and audits.
5. Establish Risk Controb. Implement records management con-
trols based on the risk mitigation strategy discussed above. Each risk mitigation strategy may have one or more risk con- trols associated with it. In the ccntext of
Implementstion
records management, these controls will take the form of policies, procedures, and automated systems. Identification of the risk, the mitigation strategy, and the avail- able resources (budget, staffing, and time) will allow the records managers to deter- mine appropriate controls and how to implement them.
6. Measure Effectiveness and Monitoring. Once the controls are established and
implemented, ongoing monitoring of their effectiveness is critical. Monitoring ensures that the right controls have been put in place and that there is appropriate understanding of the control, including how, where, and when to implement the control, Establishing metrics around the controls will enable appropriate monitor- ing and tracking. Monitoring also serves as a report card that can be used to eval- uate how well the overall program is doing.
Lessons Learned from Applying the Risk Model
Organizations are always applying a risk perspective - be it in developing long- term plans, responding to competitive threats, or meeting legal and regulatory requirements. Eormalizing the records management program to leverage a risk- based approach is a natural extension of the risk function.
A typical situation faced by many records managers is that the organization allocates a limited set of dollars to imple-
ment records management. While the debate on how best to allocate the money rages among the concerned parties, the records management team, working col- laboratively with the business units, employs a variation of the risk model to determine what are the most critical record series within the company and present the business case for why the funding should be allocated first to address these record series.
Management treats the decision as a no-brainer, and the records management team is successfijl not only in getting the budget, it also receives a "high five" on the pragmatic appnsach undertaken. This is a solid win with the executive management that atn go a long way towai'd ensuring ongoing visibility and support for the records management program.
Applying the risk model is akin to mak- ing a sound financial decision - paying money toward a loan principal or bumping up a CD to a higher rate. It pays in the long run. Applying the risk model in a method- ical and systematic way will ensure success and relevant return on investment. Following are tips for applying the model.
Socialize risk concepts early in the records and information management cycle. The records management team working in conjunction with legal and compliance functions must develop a holistic risk-based approach and then meet with business unit leaders to review and obtain supjrort. It is import;int at this time tor the records management team to play the "sales" role and present a message that is both palatable and doable. The risk apîproach will be successful only If man- agement buys into the risk concept.
Look past the obvious risks. Wiiile legal, financial, and operational risks are inherent in every business, it behooves the records management team to evaluate the magni- tude associated with different types of risk. For example, what level of risk could be associated with personnel by îassing inter- nal controls? .̂ s one major European finan- cial institution recently discovered, the costs could be in the biüions.
Clearly articulate risk definitions in lay person terms. WTiiie the textbook defini-
Jjly/August 2008 • The Infor mol ion Monogemeni Journol 5 3
tion of risk types may suffice for research papers and articles, getting the business user on the ground to understand the def- inition may be a different story. Records managers must provide clear definitions of risks as they relate to activities per- formed by users. Some business users sim- ply assume that "financial" risk means records generally reiated to financial state- ments, but in reality, there is a whole slew of records that falls under the purview of financial rislc Defining risk in an easy-to- understand manner will go a long way toward alleviating these t)'pes of issues.
Avoid over-engineering. It is impera- tive to keep the risk model as simple and as relevant as possible. The tendency to include as many risk factors as applicable will make it unduly complex to implement and manage. Keep tlie number of key risks to a maximum of tour or five.
Institute a risk oversight committee. Establish a steering committee to review and discuss key risks affecting the organi- zation's records and to make recommen- dations around managing risk. The risk oversight committee comprises key stake- holders and sets direction on the risk- based approach,
Develop a communications plan. The communications plan will detail the risk approach and assist business users in understating the why, what, and how of the program. This is a chance for the records management team to step up and shine. Newsletters, all-hands meetings, business unit forums, and periodic com- muniqués all provide an opportunity to emphasize the records management pro- gram.
Develop or update policies and proce- dures to include a risk section. Factor the risk-based approach into policies and pro- cedures. Inside each business procedure, add a risk section that describes the risk rating, crificality, probability, and controls that have been established to mitigate the risk associated with the procedure. This ensures a clear line of association between the policy, the associate procedure(s), the record outputs, and the risk controls.
Perform a cost-beneßt analysis of managing high- vs. low-risk records. Once
there is a good understanding of the high- risk record sets and their associated impact to the organization, the records manage- ment team can start to identily what sys- tem solutions will be appropriate to man- age these records sets, Performing a cost- benefit analysis will assist with the decision about what records need to be managed where.
Use manual controls, if appropriate. These days, there is a rush to evaluate the latest and greatest system solution. Organizations should, however, consider leveraging manual controls where appro- priate to manage records as part of their overall strategy. A methodical and process- based manual approach may produce results similar to a highly sophisticated, iiilly automated system solution.
Consider challenges with auto-man- aging structured content. While there is buzz around federated records manage- ment - implementing such a solution to manage all structured and unstructured content is fi"aught with significant chal- lenges. Vendor solutions are just getting off the ground in this area. Instead, it is better to isolate those structured systems that represent the greatest risk to the organiza- tion and enforce systematic and/or proce-
dural controls.
Institute a compliance plan focused on risk management. Develop a compliance plan that measures records risk mitigation and evaluates the effectiveness of the con- trols. Business units' compliance with the plan should be measured on a periodic basis, and any required remediation should be monitored and tracked.
Develop a continuous improvement platform. Once the program has been implemented, establish a support struc- ture that includes periodic review of risk factors and analysis of new and obsolete risks. Any required program updates should also be addressed as part of this function.
Conclusion The risk-based approach to records
management allows records managers to categorize and prioritize the universe of records that they need to manage. With the increasing challenges and constraints around cost, resources, and time, the risk- based approach allows records managers to focus on areas that will have the greatest impact and address the biggest risk to the records management function of an organization. PJ
Michelle Rush is a senior project manager with significant records management experience. She has been involved in all aspeas of records management program implementation and has more than ¡5 years of business and technology management experience. She may be con- tacted at michelle_rush@fan niemae.com.
Ganesh Vednere is a manager with Capgemini Financial Services and is experienced in implementing enterprise-wide content and records management programs. He has more than U years of relevant industry experience in various business and technology areas. He may be contacted tit [email protected].
The authors wish to state that the opinions, views, and ideas contained in this article are their own and do not reflect or represent the views of their employers.
References
Basel Committee on Banking Supervision. International Convergence of Capital Measurement and Capital Standards: A Revised Framework [Basel II]. Basel, Switzerland: Bank for International Settlements Press & Communications, 2004. Available at
www.bis.org/publ/bcbsl07.pdj?nofranies=l.
Committee of Sponsoring Organizations of the Treadway Commission. Internal Control — Integrated Framework. New York: American Institute of Certified Public Accountants, 1992.
5 4 Tiie I r f o r m a l i o n Mcnogement Journal • J u l y / A u g u s t ! 0 0 S