The Integrity Gap

Not everything is a crisis

In many of your roles, you may meet people on (one of) the worst days of their lives. The person who will be fired for fraud. The person who got their device hacked.

The Integrity GapNot everything is a crisis

In many of your roles, you may meet people on (one of) the worst days of their lives. The person who will be fired for fraud. The person who got their device hacked. The person who was harassed. The person accused of harassment. It’s messy and complex.

In that setting, I’d always refer to the basic framework below.

We tend to leap to conclusions based on assumptions. If you can arrest that tendency, the battle is half-won. Often, we’re starting with slim pickings, factually. Someone has alleged something; no facts, yet. In that setting, choose the sensible (wise/prudent) assumptions and rank them according to how easy they would be to test. For example, I responded to an extortion case where the extortionist threatened to release sensitive data that would threaten a nation’s national security. The big assumption was they had that data. The first test then became: has all that data been accessed? If so, when, by whom, and how? It’s not complex.

As we start to calibrate the assumptions better, we move to scenarios.

If you’re doing this with a leadership team (the ExCo/board, usually), there will be no shortage of dominant personalities. You don’t need these people hijacking the process. They can lead, pressure, or otherwise skew the outcomes. We need ideas. A simple hack is to present the current situation and ask each person to take five minutes (in silence) to write down the most likely, best, and outlier scenarios. The quieter folks often see options and issues that bombastic types don’t.

Why this topic and why now? Well, I hope you’re not managing a crisis. But I imagine many of you are being asked to calibrate risk.

We’d need this level of rigour to arrive at risk impact properly. Considering all assumptions, facts, perspectives, and scenarios. That soon becomes unwieldy. It’s why, in my work with impact investors, I no longer assess the impact of various risks in their PortCos (irony intended). This example explains why:

👉 A minister threatens to cancel your concession unless you pay a bribe.

So, what’s the impact? Well, a non-exhaustive list of scenarios:

👉 You refuse to pay, and he cancels your concession. 👉 You escalate to your embassy, and he backs off. Later, you start losing business locally. 👉 You meet and try to find a compromise (nothing unethical). He may use your location for a rally if he promises to desist extorting. 👉 You ignore; he was shaking down tens of other businesses to try and raise funds to buy votes. 👉 You stall and delay, knowing he probably won’t get re-elected in a few months. 👉 You refuse to pay (zero tolerance), blah blah. The minister goes away.

Let’s avoid the typical corruption scare tactics used in training and risk assessment. These scenarios, such as ‘you pay, get caught and investigated, huge FCPA fines ensue,’ are often exaggerated and do not reflect reality. Instead, let’s focus on the importance of simplicity in our risk assessment and training methods. Remember, most people don’t get caught; we all know this.

I discussed all those scenarios with a client in precisely that situation - pay or we drive you out of your most lucrative market in Asia. We worked out how to test the various options’ likely efficacy.

In a crisis, it makes sense to calibrate risk and scenarios to this degree. In a predictive assessment, it doesn’t. You’d spend months on something that no one would read or action.

In a risk assessment, it’s crucial to prioritise the most likely scenarios. We should ask ourselves, ‘If that occurred, how much chaos could it cause?’ If the answer is ‘a lot,’ then we keep it simple and look at the steps to decrease the likelihood. Remember, probability is the (more) controllable variable, not impact. So, when doing a risk assessment, we keep it simple: not everything is a crisis.

Keeping advice simple

On simplicity, I’m co-authoring an interactive training program on bribery, corruption, and fraud for a multilateral organisation operating across 50+ challenging markets. Keeping it simple has been the main challenge. I was grateful to receive this timely advice in a newsletter, quoting Sarah Helm (or London E1), who had written to The Times, saying:

“The best advice I was given as a head teacher about the appropriate dress (“Appropriate office wear looks more M&S than S&M”, Aug 6) was from a brilliant safeguarding consultant: “I do not want to see up it, down it or through it.” That seems to cover all eventualities!”

What other risk advice could we distil into the “up it, down it, or through it” level of clarity!?

Do share!

More Ethics Insight writing

Is it worth a conversation?

Tell us what you are trying to decide. We will listen, ask a few questions and tell you whether we can help.

Start a conversation