
The interior of an Apple store, location unknown. Because shares of Apple (common) were among 2010's high flyers, there has been demand for the reports of analysts who follow the company. These analysts don't rely solely on the pronouncements of the companies they follow. They try to learn whatever they can about what the future holds using a variety of techniques, one of which is called a "channel check." In a channel check, an analyst interviews people at companies in the target's supply chain, to determine the future pace of business for the target company. See Susan Pulliam's report, "Supply Data Now a Focus of Probe", in the Wall Street Journal of November 24, 2010.
Although the present essay focuses on the impact of risk management plans on the privacy concerns of individuals (and vice versa), risk management plans also raise issues for projects analogous to the issues for companies raised by the channel check. For instance, the content of a risk management plan might be of some value to a political rival of the project's sponsor, especially if that rival plans to rely on some of the same people as the project does. Even though the project isn't especially sensitive in the proprietary sense, the enterprise-public status of its risk management plan could make the project vulnerable to the actions of the sponsor's rivals.
Photo by Hersch courtesy Wikimedia.
Personnel-sensitive risks are those that can be understood only after acquiring personnel-sensitive information — information that, if disclosed improperly, could compromise the privacy of an employee, and thus the enterprise or its security, or place the enterprise in legal jeopardy. Most enterprises are reasonably careful about these disclosures, but protecting employees' privacy can become problematic for risk management planning.
Risk management plans for typical projects are usually enterprise-public. That is, anyone with a reasonable business-related need to examine them can do so — sponsors, project managers, auditors, functional managers and many others. Even when the author's permission is required, the security protecting risk management plans is rarely any more robust than the security protecting their projects.
That creates problems. Suppose that Dan's elderly mother has been gravely ill. Because he's been shuttling back and forth to his hometown for six months, his availability has been unpredictable, and certainly less than 75%, but her death is expected mercifully soon.
Dan's project manager wants to revise the risk plan to take this into account, justifying a reduction in reserves previously allocated to covering for Dan. In many organizations, there is no way to do this transparently without compromising Dan's privacy.
This example probably lies at the innocuous end of the spectrum of personnel-sensitive risks. There are others far more sensitive — divorce, illness or injury physical or mental, disciplinary issues, substance abuse problems, office love affairs gone wrong, and toxic conflicts, to list just a few.
The inability to plan discretely for managing personnel-sensitive risks has important consequences.
- The risks aren't mitigated formally
- You can't document mitigation plans for risks you can't discuss.
- Risk mitigation is more likely to be incomplete or excessive
- Since risk managers can't safely discuss certain risks, they either fail to mitigate them adequately, or they conceal the mitigation elsewhere in the mitigations of risks they can discuss.
- Reflection is inhibited
- Learning Learning from past experience
is difficult when the risk plans
as documented differ from
what the risk managers
were actually doingfrom past experience is difficult when the risk plans as documented differ from what the risk managers were actually doing. - Personal information is more likely to be disclosed inappropriately
- Risk managers who do try to plan transparently are at risk of disclosing personal information that should not be disclosed. Such action could potentially create legal liability for the enterprise or for the discloser.
- Employees are less likely to be forthcoming about personal matters
- Knowing that personal information is at risk of disclosure, some employees keep personal information private, even when they know that doing so might harm the task for which they are responsible.
The risks that enterprise-public risk management plans cannot address are therefore rarely subjected to the best available risk management practices. These risks persist unmitigated, or at best, they're mitigated by informal, off-the-books decisions and allocations. Enterprise-public risk management plans are simply inadequate to the task.
What can we do about this? A modest proposal is our Part II, coming soon. Next issue in this series
Top
Next Issue
Are your projects always (or almost always) late and over budget? Are your project teams plagued by turnover, burnout, and high defect rates? Turn your culture around. Read 52 Tips for Leaders of Project-Oriented Organizations, filled with tips and techniques for organizational leaders. Order Now!
Your comments are welcome
Would you like to see your comments posted here? rbrenjTnUayrCbSnnEcYfner@ChacdcYpBKAaMJgMalFXoCanyon.comSend me your comments by email, or by Web form.About Point Lookout
Thank you for reading this article. I hope you enjoyed it and
found it useful, and that you'll consider recommending it to a friend.
This article in its entirety was written by a human being. No machine intelligence was involved in any way.
Point Lookout is a free weekly email newsletter. Browse the archive of past issues. Subscribe for free.
Support Point Lookout by joining the Friends of Point Lookout, as an individual or as an organization.
Do you face a complex interpersonal situation? Send it in, anonymously if you like, and I'll give you my two cents.
Related articles
More articles on Effective Communication at Work:
See No Evil
- When teams share information among themselves, they have their best opportunity to reach peak performance.
And when some information is withheld within an elite group, the team faces unique risks.
The Problem of Work Life Balance
- When we consider the problem of work life balance, we're at a disadvantage from the start. The term
itself is part of the problem.
Internal Audits Without Pain
- If adhering to established procedures is part of your job, you probably experience occasional audits.
You can manage the pain of the experience by regarding audit preparation as part of the job. Because
it is. Here are some tips for navigating audits.
Gratuitous Use of Synonyms, Aliases, and Metaphors
- The COVID-19 pandemic has permanently changed how we work. We're now more virtual than before. In this
new environment, synonyms, aliases, and metaphors can pave the path to trouble. To avoid expensive mistakes,
our use of language must be more precise.
Antipatterns for Time-Constrained Communication: III
- Recognizing just a few patterns that can lead to miscommunication can reduce the incidence of problems.
Here is Part III of a collection of antipatterns that arise in technical communication under time pressure,
emphasizing contextual factors.
See also Effective Communication at Work and Effective Communication at Work for more related articles.
Forthcoming issues of Point Lookout
Coming February 26: Devious Political Tactics: Bad Decisions
- When workplace politics influences the exchanges that lead to important organizational decisions, we sometimes make decisions for reasons other than the best interests of the organization. Recognizing these tactics can limit the risk of bad decisions. Available here and by RSS on February 26.
And on March 5: On Begging the Question
- Some of our most expensive wrong decisions have come about because we've tricked ourselves as we debated our options. The tricks sometimes arise from rhetorical fallacies that tangle our thinking. One of the trickiest is called Begging the Question. Available here and by RSS on March 5.
Coaching services
I offer email and telephone coaching at both corporate and individual rates. Contact Rick for details at rbrenjTnUayrCbSnnEcYfner@ChacdcYpBKAaMJgMalFXoCanyon.com or (650) 787-6475, or toll-free in the continental US at (866) 378-5470.
Get the ebook!
Past issues of Point Lookout are available in six ebooks:
- Get 2001-2 in Geese Don't Land on Twigs (PDF, )
- Get 2003-4 in Why Dogs Wag (PDF, )
- Get 2005-6 in Loopy Things We Do (PDF, )
- Get 2007-8 in Things We Believe That Maybe Aren't So True (PDF, )
- Get 2009-10 in The Questions Not Asked (PDF, )
- Get all of the first twelve years (2001-2012) in The Collected Issues of Point Lookout (PDF, )
Are you a writer, editor or publisher on deadline? Are you looking for an article that will get people talking and get compliments flying your way? You can have 500-1000 words in your inbox in one hour. License any article from this Web site. More info
Follow Rick





Recommend this issue to a friend
Send an email message to a friend
rbrenjTnUayrCbSnnEcYfner@ChacdcYpBKAaMJgMalFXoCanyon.comSend a message to Rick
A Tip A Day feed
Point Lookout weekly feed
