Point Lookout: a free weekly publication of Chaco Canyon Consulting
Volume 11, Issue 11;   March 16, 2011: Personnel-Sensitive Risks: Part II

Personnel-Sensitive Risks: Part II

by

Personnel-sensitive risks are risks that are difficult to discuss openly. Open discussion could infringe on someone's privacy, or lead to hurt feelings, or to toxic politics or toxic conflict. If we can't discuss them openly, how can we deal with them?
Harry Stonecipher, former CEO of The Boeing Company

Harry Stonecipher, former CEO of The Boeing Company. Mr. Stonecipher, who had been recalled from retirement in 2003 to repair Boeing's image following a string of procurement scandals at the company, was asked to resign in 2005 following revelations of a love affair with a female executive. Ironically, Mr. Stonecipher had been viewed as "the fixer," and had presided over adoption of a new code of conduct for Boeing employees.

It's difficult to know for certain whether a situation like Mr. Stonecipher's might have been managed more effectively if more robust confidentiality-preserving procedures had been in place. But one can easily imagine similar situations that are allowed to persist much longer than they would have if such procedures were in place. Photo courtesy ChinaDaily.com.

A few weeks ago, we explored managing risks arising from situations of a delicate nature that cannot be widely disclosed within the enterprise. Because the conventional risk management apparatus — plans, meetings, publication, review and approval — is likely to lead to inappropriate disclosure of sensitive personal information, either such risks are not managed properly, or sensitive personal information is disclosed inappropriately or even illegally.

Let's examine what we would need to do to manage these risks while maintaining an appropriate level of confidentiality.

Confidentiality infrastructure
Whatever infrastructure we deploy must be capable of maintaining the confidentiality of sensitive personal information. It's likely that we need a tiered structure for access to personnel-sensitive risk management information. When designing or modifying procedures for managing personnel-sensitive risks, experts in management, security, risk management, and human resources must be involved.
Multi-part risk plans
Because some parts of a given risk plan could contain sensitive information, those parts might have to be separated and have controlled access. The number of controlled-access components of a risk plan could depend on the individuals who present personnel-sensitive risks. For instance, in a need-to-know based system, if risks associated with two people are involved and they have different supervisors, we might need independently confidential risk plan components for the two personnel-sensitive risks.
Access for project managers and sponsors
For a given project, the project manager and sponsor must have full access to risk management artifacts. To develop and manage their risk plan, they might need access to personnel-sensitive information not normally available to them. This could require adjustment of existing policies.
Confidential risk reviews for personnel-sensitive risks
Currently, It's likely that we need a tiered
structure for controlled access
to personnel-sensitive risk
management information
risk plan review is usually conducted without regard to personnel confidentiality. That process can continue for the enterprise-public portions of risk plans, but the personnel-sensitive components must be reviewed in a confidential manner.
Confidential budgeting and resource allocation
Components of project budgets and resource allocation plans intended to cover personnel-sensitive risks can remain enterprise-public, but the documents justifying these budgets and allocations are likely to be confidential and have controlled access, in parallel with the risk plans that drive them.
Training
Since the people involved in these procedures include some who are unfamiliar with procedures for maintaining confidentiality of personnel matters, training in personnel confidentiality is probably required. And since many of those already familiar with personnel matters are probably unfamiliar with the ways of risk management, they might also require some training.

Because the set of people with access to a given controlled-access document or decision can vary with the content of the document or decision, the requirement for confidentiality of some risk plan components can become cumbersome. But the alternatives — either non-compliance with regulations or poor risk management or both — is worse. First in this series  Go to top Top  Next issue: Indicators of Lock-In: Part I  Next Issue

52 Tips for Leaders of Project-Oriented OrganizationsAre your projects always (or almost always) late and over budget? Are your project teams plagued by turnover, burnout, and high defect rates? Turn your culture around. Read 52 Tips for Leaders of Project-Oriented Organizations, filled with tips and techniques for organizational leaders. Order Now!

Your comments are welcome

Would you like to see your comments posted here? rbrenVDgkyycXnGrCwwcZner@ChacnNJnUWnLVeoYSnOfoCanyon.comSend me your comments by email, or by Web form.

About Point Lookout

Thank you for reading this article. I hope you enjoyed it and found it useful, and that you'll consider recommending it to a friend.

Point Lookout is a free weekly email newsletter. Browse the archive of past issues. Subscribe for free.

Support Point Lookout by joining the Friends of Point Lookout, as an individual or as an organization.

Do you face a complex interpersonal situation? Send it in, anonymously if you like, and I'll give you my two cents.

Related articles

More articles on Ethics at Work:

A nervous dogThe Power of Presuppositions
Presuppositions are powerful tools for manipulating others. To defend yourself, know how they're used, know how to detect them, and know how to respond.
Archibald Cox, Special Watergate ProsecutorDifficult Decisions
Some decisions are difficult because they trigger us emotionally. They involve conflicts of interest, yielding to undesirable realities, or possibly pain and suffering for the deciders or for others. How can we make these emotionally difficult decisions with greater clarity and better outcomes?
Duma, a wolf at the UK Wolf Conservation Trust, rolls to capture a scent atop a moundTelephonic Deceptions: Part II
Deception at work probably wasn't invented at work. Most likely it is a continuation of deception in the rest of life. But the technologies of the modern workplace offer new opportunities to practice the art. Here's Part II of a handy guide for telephonic self-defense.
An actual red herringSome Truths About Lies: Part IV
Extended interviews provide multiple opportunities for detecting lies by people intent on deception. Here's Part IV of our little collection of lie detection techniques.
The Costanza MatrixThe Costanza Matrix
The Seinfeld character "George Costanza" is famous for having said, "It's not a lie if you believe it." What if you don't believe it and it's true? Some musings.

See also Ethics at Work and Project Management for more related articles.

Forthcoming issues of Point Lookout

A vizsla in a pose called the play bowComing April 26: Why Dogs Make the Best Teammates
Dogs make great teammates. It's in their constitutions. We can learn a lot from dogs about being good teammates. Available here and by RSS on April 26.
A business meetingAnd on May 3: Start the Meeting with a Check-In
Check-ins give meeting attendees a chance to express satisfaction or surface concerns about how things are going. They're a valuable aid to groups that want to stay on course, or get back on course when needed. Available here and by RSS on May 3.

Coaching services

I offer email and telephone coaching at both corporate and individual rates. Contact Rick for details at rbrenqwDFlOdAJVxKpUWaner@ChacWCCpqpJiYMubJmvqoCanyon.com or (617) 491-6289, or toll-free in the continental US at (866) 378-5470.

Get the ebook!

Past issues of Point Lookout are available in six ebooks:

Reprinting this article

Are you a writer, editor or publisher on deadline? Are you looking for an article that will get people talking and get compliments flying your way? You can have 500 words in your inbox in one hour. License any article from this Web site. More info

Public seminars

Changing How We Change: The Essence of Agility
MasteChanging How We Change: The Essence of Agilityry of the ability to adapt to unpredictable and changing circumstances is one way of understanding the success of Agile methodologies for product development. Applying the principles of Change Mastery, we can provide the analogous benefits in a larger arena. By exploring strategies and tactics for enhancing both the resilience and adaptability of projects and portfolios, we show why agile methodologies are so powerful, and how to extend them beyond product development to efforts of all kinds. Read more about this program. Here's an upcoming date for this program:

Creating High Performance Virtual Teams
Many Creating High Performance Virtual Teamspeople experience virtual teams as awkward, slow, and sometimes frustrating. Even when most team members hail from the same nation or culture, and even when they all speak the same language, geographic dispersion or the presence of employees from multiple enterprises is often enough to exclude all possibility of high performance. The problem is that we lead, manage, and support virtual teams in ways that are too much like the way we lead, manage, and support co-located teams. In this program, Rick Brenner shows you how to change your approach to leading, managing, and supporting virtual teams to achieve high performance using Simons' Four Spans model of high performance. Read more about this program. Here's an upcoming date for this program:

The Race to the South Pole: Ten Lessons for Project Managers
On 14The Race to the Pole: Ten Lessons for Project Managers December 1911, four men led by Roald Amundsen reached the South Pole. Thirty-five days later, Robert F. Scott and four others followed. Amundsen had won the race to the pole. Amundsen's party returned to base on 26 January 1912. Scott's party perished. As historical drama, why this happened is interesting enough, but to organizational leaders, business analysts, project sponsors, and project managers, the story is fascinating. Lessons abound. Read more about this program. Here's an upcoming date for this program:

Follow Rick

Send email or subscribe to one of my newsletters Follow me at LinkedIn Follow me at Twitter, or share a tweet Follow me at Google+ or share a post Subscribe to RSS feeds Subscribe to RSS feeds
The message of Point Lookout is unique. Help get the message out. Please donate to help keep Point Lookout available for free to everyone.
21st Century Business TravelAre your business trips long chains of stressful misadventures? Have you ever wondered if there's a better way to get from here to there relaxed and refreshed? First class travel is one alternative, but you can do almost as well (without the high costs) if you know the tricks of the masters of 21st-century e-enabled business travel…
Go For It: Sometimes It's Easier If You RunBad boss, long commute, troubling ethical questions, hateful colleague? Learn what we can do when we love the work but not the job.
303 Tips for Virtual and Global TeamsLearn how to make your virtual global team sing.
101 Tips for Managing ChangeAre you managing a change effort that faces rampant cynicism, passive non-cooperation, or maybe even outright revolt?
101 Tips for Effective MeetingsLearn how to make meetings more productive — and more rare.
Exchange your "personal trade secrets" — the tips, tricks and techniques that make you an ace — with other aces, anonymously. Visit the Library of Personal Trade Secrets.