Showing posts with label Regulatory Compliance. Show all posts
Showing posts with label Regulatory Compliance. Show all posts

Monday, November 14, 2016

Elephants can dance, but can they win a dance competition ?

The company let’s call it A was the posterchild of the industry; they had grown faster than the market, had better margins, and a product portfolio that gave them higher traction with customers. The war chest thus created was used to acquire business interests and market expansion globally; the stock market rewarded them with benchmark beating valuations with a rare possibility of anyone catching up. The promoters kept tight control over the business and expenses with close trusted advisors – part of the inner circle.

Investments in manufacturing excellence fueled the growth, quality was a way of life which enamored them to their customers. Practicing frugality in other areas, they perceived COTS to be uneconomical in comparison to home grown solutions. Thus they built a reasonably large team to recreate the wheel for every process, automation with custom built solutions for all areas of the business. While the industry adopted globally accepted best practices and solutions, company A justified its decision to stay different.

Industry faced regulation in growing degrees making it mandatory for everyone to adopt technology based solutions for compliance. Auditors expected electronic trails and information as tamperproof evidence of process adherence. Major part of the industry prepared for and over a period of time gained compliance; the cost of deviation was adverse impact to business, and customer dissatisfaction. Industry norms demand compliance, so do adherence to country specific laws which is treated as a part of doing business.

While major part of the industry simply bought solutions from existing providers and got done with it, company A tasked the IT team to build the necessary systems. Step by step the solution was built to specifications signed off by the business teams based on downloaded information from regulatory websites and second hand experience. Since they were building the basic minimum functionality, where technology was lacking compensating manual controls were put in place, deemed adequate for audit purposes.

Faced with an audit during the phase of construction, company A demonstrated the scope of work and the fact that they were building everything required to make the process compliant. The auditors cognizant of the effort, accepted the input as work in progress and signed off on the timeline, to be reviewed during the next audit. Step by step functionality was put in place albeit slower than anticipated with parts of the business used to freedom and flexibility finding it too complex to adapt to the new way of working.

Increased regulatory activity and deadlines with harsher penalties for non-compliance put the industry on alert specifically in some of the large markets. Cost of non-compliance was denied access to consumers until remediation fixed the gaps and there was enough evidence to demonstrate end-to-end process non-repudiation. The increased complexity of the new laws put the laggards in a precarious situation, especially ones who had custom built solutions which required longer time to validate.

Vendors and consultants offered help to anyone willing to accept the problem and assist in putting together a compliant solution. Many global solution providers who had not explored niche markets by virtue of their size and cost of doing business, sensed a tactical opportunity to gain market share and grow the business. Leadership teams swooped down on the big targets including company A. Having survived the economic ups and downs with their own solutions, company A reluctantly agreed to the meeting.

The CIO who was brought on board post the last large acquisition to drive technology led efficiency and transformation; coming from one of the leaders in technology adoption, he was seen as a good catch. The CIO with long industry background was aware of the problem and informed that they were on the way to solve the problem in the next 12 months – the deadline to be compliant. He did not believe that there was a need to press the panic button; deadlines do shift when it comes to regulatory requirements.

After a couple of attempts at elevating the issue, vendors decided not to waste any more time in their quest to gain the business of company A. The CIO guarded the rest of the company executives to the upcoming challenge who were known to throw around their weight to get things done eventually, attempting to second guess the inner circle. The sycophant environment and the belief that we are too big to fail made them vulnerable to the upcoming date, their size made it almost impossible to breast the tape in time.

Company A scrambled to the finish line partially ready, the business impact was significantly larger to the investment, attitude and inertia cost them a few notches in market standing. The CIO was fired for not elevating the issue and preparing the business; he had not taken the initiative nor involved other CXOs. Dip in profits and dividend crashed market capitalization, they had to fight hard to stave off an unfriendly takeover bid. Elephants can dance was a turnaround story, repeating history is not easy.

Monday, November 07, 2016

When running against time, you rarely win !

Every industry has its share of regulations to which they need to comply; regulations could vary by geography or product within the industry. In a global economy this becomes important towards growth as well as the ability to continue doing business in a market. Enterprises have over a period of time set in a process to respond to changes in regulations which impact their profitability or revenue in any significant way; most compliances are driven by technology solutions driven by IT teams and thus making the CIO a key stakeholder.

Compliance requirements are broadly of two types: the first one related to taxes and levies which apply in the operating market or country of origin of the enterprise. Companies have to comply to both and at times they can be complex and time consuming; applicable benefits and incentives also need to be factored in to get the financial benefit. Most large software vendors have modules to help their customers comply within the timelines; for custom solutions, IT organizations eventually get the process and timeline right.

The second type of compliance is driven by consuming markets driven by protectionist measures or keeping in mind the interests of citizen consumers. Such requirements have a much wider impact to the industry and result in lobbying for and against depending on the impact. Such regulations or laws tend to have high budgetary requirements and need longer timelines to get the organization ready. At times they may impact core processes or make a market unviable to service, requiring a strategic decision to continue to operate.

While the discussion started a decade back, in the last 5 years there has been impending regulation which required every company in that sector to comply to continue doing business. The timeline shifted a couple of times and then a phased compliance roadmap spread over 5 years was published allowing more than reasonable time to plan, execute and comply. The high complexity technology dependent process that impacted core business thus necessitated companies to go back to the Board to gain approval for budgets.

This was a big one and had real impact to business; so Consultants, vendors, business partners and IT solution providers started discussion with their customers who needed to comply with the new regulation. Different companies reacted in as many ways; the early adopters listened to everyone, initiated a cross-functional team to review the impact and craft a program towards compliance while there is still time. They ensured that there is adequate time to get it right and make it standard process before the deadline.

The second lot of companies took the wait and watch approach observing the early adopters, talking to the ecosystem who helped the first lot and then put together a program to implement solutions that have already been proven to work. They did not get early pricing benefit but took relatively less time to implement the solutions towards compliance in time; they could compare options from within the working set. Surprisingly between the first and the second set of companies they represented only about 60 percent of the industry.

So what about the rest ? Did they know something the others did not ? Did they not understand the adverse impact of their inaction or failure to comply ? Was the problem not as acute as the industry touted it to be ? No exemption was available nor there existed possibility of an extension to the deadline. The group had enterprises big and small, multi-national as well as family owned companies and they were geographically spread thereby not forming any trend that could justify their stance of not taking action.

Talking to a few of these companies, they fell into a few distinct buckets: the first who would do only the bare minimum to comply, and that is what they had done. Their decision making criteria was that why change until absolutely necessary. The second understood the problem and took decisions based on cash outflow, deferring until the last minute and choosing the lowest cost option. The rest of the rest were resting not necessarily fully aware of the challenge and the solution; some were surprised that many in the industry had already taken big steps.

Will they make it unscathed ? Coming soon …