The Integrity Gap

Risk Assessment, Gap Analysis, or Benchmark?

On 12 March, I'll run an SCCE session around conducting practical risk assessments. Last week, I had to develop the dreaded blurb about why people should attend.

The Integrity GapRisk Assessment, Gap Analysis, or Benchmark?

On 12 March, I’ll run an SCCE session around conducting practical risk assessments. Last week, I had to develop the dreaded blurb about why people should attend.

Initially, my notes went like this: When we do proper assessments, we shrink and rightsize risk. If we don’t do a 3D (external, internal, behavioural) assessment, typically, we’ll waste time and money. Worse, we might miss risks and have bad things happen.

But then I remembered that everyone says they do a risk assessment. I can count on the fingers of one hand the number of (mid-cap and above) companies who say they don’t have a risk assessment. However, when you look into the details, it’s often a gap analysis or benchmark. Let’s define each.

Gap Analysis

A gap analysis might pretend to be a risk assessment by having a few lines referencing things like “country risk” and the Transparency International Corruption Perception Index scores in the preamble. But it quickly reveals its true colours when we get a lot of questions around “Do you have X or Y?” Here, we’re measuring the existence of things (“having”). If we’re lucky, we might also get some “doing” questions, like, “We test comprehension of training [agree-disagree].” The result has utility. It helps us quickly identify gaps in controls. But it’s not a risk assessment without context (risk, behaviour, and comparison). To make the point, imagine we ask, “Does your company have an anonymous whistleblowing system?” Answering “yes” may get a green tick. But consider these recent issues uncovered during risk assessments:

  1. The company had a speak-up framework that wasn’t accessible at many sites (network coverage, some workers can’t read, others don’t have smartphones, etc.).
  2. The company didn’t have a formal framework but had a very effective speak-up culture (it can happen!).
  3. They had a framework, but it wasn’t accessible to third-parties (a problem when 90% of their risk exposure came through EPC and O&M contractors).
  4. The company had grown inorganically, and large parts of the new business didn’t know about the framework.
  5. They had botched investigations in the past, and speak-up numbers had fallen off a cliff.

Benchmarks

A benchmark typically follows a gap analysis, where you’re compared to others. This can be exceptionally useful, especially if the comparison is with direct peers or against a universal regulation/risk. For example, retail banks benchmarking their consumer cybersecurity protections makes sense, as would all businesses benchmarking their compliance against changed employment laws in a given location. But it’s still not a risk assessment until we consider the context, doing, and behavioural aspects.

Are they useful?

Benchmarks and gap analyses are like routine medicals. Results become helpful when coupled with (honest) answers to lifestyle questions. On its own, it might be misleading. For example, BMI (body mass index) scores can be deceptive. Most rugby players and mixed martial artists would be classified as “overweight.” Their weight is not the primary risk they face…

Why, then, does Ethics Insight offer several assessments that are, essentially, gap analyses with benefits (more “doing” questions than “having”)? Because they’re more (i.e. freely) accessible than a proper risk assessment, and they’re a call to action—a nudge. They’re the start of the conversation, not an exam we pass or fail.

If you want to start the conversation, I’ve ranked the free assessments we provide in order of complexity:

Let me know which one(s) you like best and why.

Framing questions matters

I and several others are supporting a global accreditation body with an extensive study of fraud (and fraud prevention). And no, this body isn’t the Association of Certified Fraud Examiners (not this time!).

Part of the study involves a questionnaire. The first step involved compiling everyone’s views, which (understandably) led to a War & Peace edition we are now trying to edit. But sometimes, to edit, you need to add first.

There is currently a whole sequence of questions about whistleblowing and reporting. For example, one asks, “What would make you more likely to report fraud in the workplace?” (Select all that apply.) The following options discuss training, clearer policies, protection against retaliation, etc. Three other questions seem to overlap, asking if we’d feel comfortable reporting fraud.

How, then, to proceed? Let’s ask a simple question at the beginning of that section. Something like, “What prevented you from speaking up or reporting (any type of) wrongdoing in the past?” The question is intentionally presumptuous. Most of the recipients will be senior finance professionals. We’ve all seen bad behaviour (from office parties to bullying managers or actual compliance violations). The question could be open, or we could use options we know to be the case (for starters):

  1. I didn’t think it was my place.
  2. I was nervous or scared about speaking up.
  3. I didn’t think it would make a difference.
  4. I was involved.
  5. I was told (not) to.

Now, with the respondent to the survey ‘primed’, we might better use one next question (not three or four). Something like, “What would make you more likely to report fraud in the future.” Compiling surveys, assessments, benchmarks, and the rest is challenging. Sometimes, we must step back from the issue and tap into emotions (they provide the answers we want: honest ones).

More Ethics Insight writing

Is it worth a conversation?

Tell us what you are trying to decide. We will listen, ask a few questions and tell you whether we can help.

Start a conversation