Point Lookout: a free weekly publication of Chaco Canyon Consulting
Volume 11, Issue 8;   February 23, 2011: Personnel-Sensitive Risks: Part I

Personnel-Sensitive Risks: Part I

by

Some risks and the plans for managing them are personnel-sensitive in the sense that disclosure can harm the enterprise or its people. Since most risk management plans are available to a broad internal audience, personnel-sensitive risks cannot be managed in the customary way. Why not?
The interior of an Apple store, location unknown

The interior of an Apple store, location unknown. Because shares of Apple (common) were among 2010's high flyers, there has been demand for the reports of analysts who follow the company. These analysts don't rely solely on the pronouncements of the companies they follow. They try to learn whatever they can about what the future holds using a variety of techniques, one of which is called a "channel check." In a channel check, an analyst interviews people at companies in the target's supply chain, to determine the future pace of business for the target company. See Susan Pulliam's report, "Supply Data Now a Focus of Probe," in the Wall Street Journal of November 24, 2010.

Although the present essay focuses on the impact of risk management plans on the privacy concerns of individuals (and vice versa), risk management plans also raise issues for projects analogous to the issues for companies raised by the channel check. For instance, the content of a risk management plan might be of some value to a political rival of the project's sponsor, especially if that rival plans to rely on some of the same people as the project does. Even though the project isn't especially sensitive in the proprietary sense, the enterprise-public status of its risk management plan could make the project vulnerable to the actions of the sponsor's rivals.

Personnel-sensitive risks are those that can be understood only after acquiring personnel-sensitive information — information that, if disclosed improperly, could compromise the privacy of an employee, and thus the enterprise or its security, or place the enterprise in legal jeopardy. Most enterprises are reasonably careful about these disclosures, but protecting employees' privacy can become problematic for risk management planning.

Risk management plans for typical projects are usually enterprise-public. That is, anyone with a reasonable business-related need to examine them can do so — sponsors, project managers, auditors, functional managers and many others. Even when the author's permission is required, the security protecting risk management plans is rarely any more robust than the security protecting their projects.

That creates problems. Suppose that Dan's elderly mother has been gravely ill. Because he's been shuttling back and forth to his hometown for six months, his availability has been unpredictable, and certainly less than 75%, but her death is expected mercifully soon.

Dan's project manager wants to revise the risk plan to take this into account, justifying a reduction in reserves previously allocated to covering for Dan. In many organizations, there is no way to do this transparently without compromising Dan's privacy.

This example probably lies at the innocuous end of the spectrum of personnel-sensitive risks. There are others far more sensitive — divorce, illness or injury physical or mental, disciplinary issues, substance abuse problems, office love affairs gone wrong, and toxic conflicts, to list just a few.

The inability to plan discretely for managing personnel-sensitive risks has important consequences.

The risks aren't mitigated formally
You can't document mitigation plans for risks you can't discuss.
Risk mitigation is more likely to be incomplete or excessive
Since risk managers can't safely discuss certain risks, they either fail to mitigate them adequately, or they conceal the mitigation elsewhere in the mitigations of risks they can discuss.
Reflection is inhibited
Learning Learning from past experience
is difficult when the risk plans
as documented differ from
what the risk managers
were actually doing
from past experience is difficult when the risk plans as documented differ from what the risk managers were actually doing.
Personal information is more likely to be disclosed inappropriately
Risk managers who do try to plan transparently are at risk of disclosing personal information that should not be disclosed. Such action could potentially create legal liability for the enterprise or for the discloser.
Employees are less likely to be forthcoming about personal matters
Knowing that personal information is at risk of disclosure, some employees keep personal information private, even when they know that doing so might harm the task for which they are responsible.

The risks that enterprise-public risk management plans cannot address are therefore rarely subjected to the best available risk management practices. These risks persist unmitigated, or at best, they're mitigated by informal, off-the-books decisions and allocations. Enterprise-public risk management plans are simply inadequate to the task.

What can we do about this? A modest proposal is our Part II, coming soon. Next in this series  Go to top Top  Next issue: Publish an Internal Newsletter  Next Issue

52 Tips for Leaders of Project-Oriented OrganizationsAre your projects always (or almost always) late and over budget? Are your project teams plagued by turnover, burnout, and high defect rates? Turn your culture around. Read 52 Tips for Leaders of Project-Oriented Organizations, filled with tips and techniques for organizational leaders. Order Now!

Your comments are welcome

Would you like to see your comments posted here? rbrenOgKdwBkCnahqVCYZner@ChacfkYjLbQAJjmcyXYboCanyon.comSend me your comments by email, or by Web form.

About Point Lookout

Thank you for reading this article. I hope you enjoyed it and found it useful, and that you'll consider recommending it to a friend.

Point Lookout is a free weekly email newsletter. Browse the archive of past issues. Subscribe for free.

Support Point Lookout by joining the Friends of Point Lookout, as an individual or as an organization.

Do you face a complex interpersonal situation? Send it in, anonymously if you like, and I'll give you my two cents.

Related articles

More articles on Ethics at Work:

Mark Twain in 1907When You're Scared to Tell the Truth
In the project context, we need to know that whatever we're hearing from colleagues is the truth as they see it. Yet, sometimes we shade the truth, or omit important details. Here's a list of some of the advantages of telling the truth.
BalletWorkplace Politics vs. Integrity
A reader wrote recently of wanting to learn "to effectively participate in office politics without compromising my integrity." It sometimes seems that those who succeed in workplace politics must know how to descend to the blackest depths, and still sleep at night. Must we abandon our integrity to participate in workplace politics?
The rabbit that went down the rabbit-holeIt Might Be Legal, but It's Unethical
Now that CEOs will be held personally accountable for statements they make about their organizations, we can all expect to be held to higher standards of professional ethics. Some professions have formal codes of ethics, but most don't. What ethical principles guide you?
Lt. Col. John Paul VannManaging Personal Risk Management
When we bias organizational decisions to manage our personal risks, we're sometimes acting ethically — and sometimes not. What can we do to limit personal risk management?
A field of Cereal RyeApproval Ploys
If you approve or evaluate proposals or requests made by others, you've probably noticed patterns approval seekers use to enhance their success rates. Here are some tactics approval seekers use.

See also Ethics at Work and Project Management for more related articles.

Forthcoming issues of Point Lookout

Balancing talk time and the value of the contributionComing March 29: Virtual Blowhards
Controlling meeting blowhards is difficult enough in face-to-face meetings, but virtual meetings present next-level problems, because techniques that work face-to-face are unavailable. Here are eight tactics for controlling virtual blowhards. Available here and by RSS on March 29.
kudzu enveloping a Mississippi landscapeAnd on April 5: Listening to Ramblers
Ramblers are people who can't get to the point. They ramble, they get lost in detail, and listeners can't follow their logic, if there is any. How can you deal with ramblers while maintaining civility and decorum? Available here and by RSS on April 5.

Coaching services

I offer email and telephone coaching at both corporate and individual rates. Contact Rick for details at rbrenyesRibINcUGwvuMhner@ChacHlWJFMIGkIOLCMGpoCanyon.com or (617) 491-6289, or toll-free in the continental US at (866) 378-5470.

Get the ebook!

Past issues of Point Lookout are available in six ebooks:

Reprinting this article

Are you a writer, editor or publisher on deadline? Are you looking for an article that will get people talking and get compliments flying your way? You can have 500 words in your inbox in one hour. License any article from this Web site. More info

Public seminars

Changing How We Change: The Essence of Agility
MasteChanging How We Change: The Essence of Agilityry of the ability to adapt to unpredictable and changing circumstances is one way of understanding the success of Agile methodologies for product development. Applying the principles of Change Mastery, we can provide the analogous benefits in a larger arena. By exploring strategies and tactics for enhancing both the resilience and adaptability of projects and portfolios, we show why agile methodologies are so powerful, and how to extend them beyond product development to efforts of all kinds. Read more about this program. Here are some upcoming dates for this program:

Conflict Resolution Skills for Leaders
ConflConflict Resolution Skills for Leadersict is inherent in collaborative work. When conflict is constructive, it produces better outcomes. When it's destructive, it can be an insurmountable obstacle to success. In this program, we explore the connections between the outcomes of collaboration and conflict in both of its forms. And we emphasize the skills needed most by leaders. The leader's task is to manage conflict so as to ensure that the group achieves its objective with its capacity to collaborate intact, or even enhanced. Rick Brenner shows team leaders and team sponsors the techniques they need to manage team conflict for relationship safety and better outcomes. Read more about this program. Here's an upcoming date for this program:

Influencing Outcomes Without Authority
Your Influencing Outcomes Without Authorityability to influence others — whether upward, downward, laterally, or within a team — always depends on both the quality of your relationships with the people you influence, and on your perception and their perception of your personal power. In this program, Rick Brenner shows you the techniques for making things happen not by using formal organizational power, but by using informal, personal power. Read more about this program. Here's an upcoming date for this program:

Strategies for Leading Teams in Hard Times
When Strategies for Leading Teams in Hard Timesa project team is on task, the contributions of leaders are important, and little noticed. Sometimes the team encounters unexpected difficulty, or requirements change, or budgets are reduced, or any of a number of other things might happen. In these cases, the leader must make or facilitate decisions about how to respond or how to revise the plan. We get through it somehow. Hard times are something else altogether. Despondency, disillusionment, resource shortages, unexpected and severe failure of the plan, and toxic conflict can erode morale. How can leaders deal with such situations? Read more about this program. Here's an upcoming date for this program:

Strategies for Technical Debt: A Workshop for Enterprise Leaders
TechnTechnical Debt Management for Enterprise Leadersical debt is more than mere IT jargon. It's a metaphor that refers to the accumulation of technical artifacts that really ought to be retired, replaced, rewritten, re-implemented, or, if absent, created. We can find technical debt in almost any system, including those that seem to be working well. So what's the problem? The problem is the "interest charges." Systems carrying technical debt are more difficult to maintain, more difficult to extend or enhance, and more difficult to use, than they would be if we "retired" the debt. This engaging and eye-opening program points the way to a path that leads your organization out of technical debt, to make it more adaptable, more transformable, and more agile. Read more about this program. Here's an upcoming date for this program:

Creating High Performance Virtual Teams
Many Creating High Performance Virtual Teamspeople experience virtual teams as awkward, slow, and sometimes frustrating. Even when most team members hail from the same nation or culture, and even when they all speak the same language, geographic dispersion or the presence of employees from multiple enterprises is often enough to exclude all possibility of high performance. The problem is that we lead, manage, and support virtual teams in ways that are too much like the way we lead, manage, and support co-located teams. In this program, Rick Brenner shows you how to change your approach to leading, managing, and supporting virtual teams to achieve high performance using Simons' Four Spans model of high performance. Read more about this program. Here's an upcoming date for this program:

The Race to the South Pole: Ten Lessons for Project Managers
On 14The Race to the Pole: Ten Lessons for Project Managers December 1911, four men led by Roald Amundsen reached the South Pole. Thirty-five days later, Robert F. Scott and four others followed. Amundsen had won the race to the pole. Amundsen's party returned to base on 26 January 1912. Scott's party perished. As historical drama, why this happened is interesting enough, but to organizational leaders, business analysts, project sponsors, and project managers, the story is fascinating. Lessons abound. Read more about this program. Here's an upcoming date for this program:

Follow Rick

Send email or subscribe to one of my newsletters Follow me at LinkedIn Follow me at Twitter, or share a tweet Follow me at Google+ or share a post Subscribe to RSS feeds Subscribe to RSS feeds
The message of Point Lookout is unique. Help get the message out. Please donate to help keep Point Lookout available for free to everyone.
21st Century Business TravelAre your business trips long chains of stressful misadventures? Have you ever wondered if there's a better way to get from here to there relaxed and refreshed? First class travel is one alternative, but you can do almost as well (without the high costs) if you know the tricks of the masters of 21st-century e-enabled business travel…
Go For It: Sometimes It's Easier If You RunBad boss, long commute, troubling ethical questions, hateful colleague? Learn what we can do when we love the work but not the job.
303 Tips for Virtual and Global TeamsLearn how to make your virtual global team sing.
101 Tips for Managing ChangeAre you managing a change effort that faces rampant cynicism, passive non-cooperation, or maybe even outright revolt?
101 Tips for Effective MeetingsLearn how to make meetings more productive — and more rare.
Exchange your "personal trade secrets" — the tips, tricks and techniques that make you an ace — with other aces, anonymously. Visit the Library of Personal Trade Secrets.