“I gotta take a little time, a little time to think things over
I better read between the lines, in case I need it when I’m older”
— “I want to know what Risk is”, Foreigner
The broader impact
Now, more than any other time, your human resource practices and procedures are being tested.
In a previous article we discussed your obligations as a licensee with regards to monitoring and the supervision of your staff, your management of risk, training, and your technology.
We’ve faced the same threats and have had to review our Human Resource Manual and related policies, procedures, contracts, and processes.
So, when we recommend to you to check the integrity of your human resource framework and make adjustments to ensure it can cope under the COVID strain, we’re speaking from experience.
Remember that if you’re a licensee, your risk framework needs to recalibrate to:
- cope with new ways of decision making;
- identify risks triggered by COVID and your appetite for those risks; and
- grapple with the emergence of risks such as cyber and/or third-party risks.
In particular, you need to focus on three things:
- Your people – and prioritisation of health, working from home and prevention of fraud
- Your data – and the security of data against cyber threats and breaches of privacy
- Your risk management framework – and the impact of the virus on your business
Let’s have a look at each one in turn.
Your people
The focus on the wellbeing of your employees is especially important as your team are probably juggling multiple roles (teacher, parent, counsellor, nurse, employee) and dealing with the general anxiety of the pandemic and managing a work-life integration.
We’ve all had to place a high level of trust in technology and the commitment and conscientiousness of our teams. We’ve had to learn how to manage a remote workforce and adapt our technology to enable an extended and remote workplace. We’ve had to evolve to collaborative remote functioning and build practical solutions to unanticipated conflicts (such as employees sharing home-office’ space (and competing for resources) with family members employed by other businesses). Information barriers are the least of the challenges.
Times like these really stress test your human resource policies and procedures, your contractual provisions with outsourced providers and your code of conduct.
Here are some practical suggestions:
- Re-look at your HR manual in terms of work health and safety and how you manage people, ergonomics, and extended periods of desk time. At Assured Support we have supplied our staff with some 80’s gym outfits, sweat bands, leg warmers and leotards (photos available on application) and have focused our training on movement with the clear direction ‘let’s get physical people’. According to Safe Work Australia the top causes for injury in the Financial Services Industry include:
- Muscular and tendon injuries due to sitting for prolonged periods of time and repetitive activities such as typing. Australian workers spend approx. 76% of their time at work sitting (i.e. 5 hours per day). With remote work this number increases exponentially.
- Sedentary work increases the risk of cardiovascular disease, some cancers, type II diabetes and musculoskeletal disorders.
- Slips, trips and falls.
Blurred lines
Ensure your staff maintain a strict work/life balance as lines become blurred when working from home.
- In uncertain times, communication, connectedness, and consistency are key. We have a regular weekly meeting and our Managing Director regularly catches up to ensure we stay connected. We also have a social virtual gatherings to facilitate the water cooler moments. In addition, we use tools like Trello to facilitate transparency with regards to work tasks and workflow. Ensuring a structured approach to connecting, work tasks and expectations facilitates consistency and reliability.
- Review your monitoring and supervision controls in relation to fraud. In a previous article we discussed the 21% increase in fraud in time like these. Just last week we saw a joint operation between ASIC, ATO and the Federal Police tackling a major fraud issue.
ASIC, ATO and AFP action: fraud
For those of you who have remote workers, how are you monitoring for fraud?
In a 2020 Global Economic Crime and Fraud Survey conducted by PwC (PwC’s 2020 Global Economic Crime and Fraud Survey) nearly half (43%) of reported fraud incidents were committed by insiders, and resulted in losses of US$100 million or more.
This is the time to re-look at your vendors, and business partners.
Through their study PwC found that one in five survey respondents cited vendors and suppliers as the source of their most disruptive external fraud incidents. PwC suggest you consider the following in relation to your outsourced provides:
- Assess their financial viability;
- Review how they, and can they support you in this time of crisis;
- Ask yourself if you are across all your outsourced providers;
- Review contract terms to understand how they manage fraud;
- Understand if they can provide ongoing maintenance and emergency response; and
- Consider if you have an alternative provider who can step in.
For more information regarding fraud, please see our previous article where we discussed red flags and how you might respond.
Your data
We won’t spend too much time outlining the threats, as you’ve probably already read our previous article on the topic.
Instead, we want to briefly highlight a couple of things for your attention:
- Re-look at your HR framework to ensure it can cope with the increased digital footprint, traffic and the virtual exchange and flow of data;
- Review your IT policies to ensure they can accommodate the decentralised workplace and locations;
- Review your contracts with external service providers to ensure they can support and mitigate cyber-attacks; and
- Train your people to heighten their awareness; understand how they can maximise the integrity of their home-based systems and mitigate cyber-attacks.
Your Risk Framework
“If you want to make God laugh, tell him your plans”
— Woody Allen
We have seen a real shift in how organisations are managing their risks.
Using the International Standards: Australian Standards 19600:2015 Compliance Management Systems and AS ISO 31000:2018 Risk Management as our guide, it’s clear we’ve arrived at a point where element standards are strained and being challenged.
Risk is defined in the standard as effect of uncertainty on objectives and COVID19 has underscored uncertainty, capitalised it and placed it on steroids.
It would be a fair observation that most risk frameworks and risk appetite did not contemplate this type of scenario during planning, or anticipate the risks associated with a pandemic.
Organisations seem to be collaborating with a refocus to the customer and sustainability of the organisation, ahead of prioritising shareholders. Regulators are using instruments to provide temporary relief from certain compliance obligations, extending capital relief and re-organising regulatory focus and activity.
The idea of “risk managing” COVID19 seems unrealistic, arrogant and hubristic.
It’s hard enough to manage the effects of the coronavirus and organise our activities in the face of a virus which, on a daily basis, is writing its own agenda.
If developing a robust risk framework starts with understanding the organisation and its context and determining external and internal issues. So many external factors including social and cultural contexts and the economic situation seem to be operating without a playbook.
Here are some practical things to consider:
- Leadership and decision making – review who makes the decisions and ensure you have a succession process in place in case there is a disruption because they have become sick, need to isolate etc;
- Review your risk criteria and appetite. Do you need to re-classify the amount and type of risk that you may or may not take on, relative to your objectives;
- Re-assess your compliance risks through the lens of the significant external change we are experiencing which extend to financial, economic, market conditions, liabilities, and client relationships;
- Review any new risks that have emerged (i.e. heightened cyber issues, third party risks) and respond;
- Develop new controls and procedures to address risks;
- Review your compliance obligations to ensure they have absorbed any new orders, rules, and guidance as a result of COVID19.