What on earth are managers up to these days? Here I write of the rise and rise of robotic, one dimensional, management-by-formula, and question if it is throttling innovation.
In linguistics, there is a rhetorical fondness of the imaginary “Martian Linguist” who, according to Chomskian thinking, on a visit to Earth would deduce from the evidence that all humans speak the one language, with only minor local variants. Well, I’m thinking that if management theorists from Mars were to watch the goings on at most board rooms today, they could be forgiven for thinking that all human enterprises are actually engaged in the same activity – compliance!
It might not be politically correct to question governance in these risk averse times, but here goes. Can we dare to ask, what is “governance”? In effect, as practiced, it is meta-management; that is, management of management.
The orthodox way to manage managers is simple really. First we get them to exhaustively write down what they and their work force should being do in their business. The documents are nicely formatted according to a standard table of contents, handed down. While it’s not always obvious what people are up to, thankfully processes and procedures may be divined from the everyday hurley burley, through all manner of workshops, special analytical tools, methodologies and the help of highly esteemed consultants. And then, with shiny new manuals in hand, meta-management proceeds by regularly auditing what’s going on, and applying corrections whenever a deviation from the chosen path is detected.
Over the course of twenty years in R&D and high tech industries, I have seen a steady succession of management methodologies that at their core are essentially the same: software development lifecycle management, the Quality movement, information security management, risk management and corporate governance (especially post Enron) and now privacy.
Compliance demands measurement. But unlike traditional industrial processes, most business processes are rather intangible. Managers all know what it’s like when their kids ask “what do you actually do all day Mummy?”. It’s not just the technical details of one’s job that makes this a tricky question – all serious management is subtle, personal and often unpredictable. So the only way to make business processes measurable is to document them, attacing tangible hooks here and there, so that they are rendered auditable. And then a terrible spiral develops; the only way to "increase" compliance is to increase the documents and the audits.
The orthodox governance mindset seems to breed an attitude where the only way to improve Risk Management (or Security or Privacy or whatever) is to create ever more detailed documents and submit to ever more detailed audits.
There is no limit to the amount of documentation that can be enthusiastically generated in any modern business. We start with standards, codes and policies, and move on to processes, procedures, and work instructions ad infinitum. It’s the very opposite, emotionally, of “analysis paralysis”. It feels so good, so productive to be specifying our business processes, that the act can become the main mission.
I don’t think mine is an overly cynical view. Seven years in the medical device industry in the 90s, followed by 12 years in information security, has shown me countless audits in which the dominant findings were that such-and-such a process was not properly documented, or not being properly measured.
The auditors' principal mode of work is to come back every 12 months to check if the documents and metrics found to be missing on their last visit have since been written, tracked and posted on the intranet. This sort of cycle is deeply robotic (in a way it is supposed to be, because of the understandable desire for metrics to be quantitative and objective). But the audit cycle too often veers from mechanical to moronic. Most of us have probably experienced the sheer inanity of an audit when the auditor is brand new, has no understanding of the business, and is simply re-tracing last year's report, and when the staffers are also new and are reading, often for the very first time, the documents written by their predecessors. They can't see the forrest for the trees.
We might all we agree that "Privacy is good for business" – just as self-evidently (?) "Security is good for business" and "Quality is good for business". But orthodox privacy/security/quality compliance regimes come with huge and unwelcome overheads, and it has to be said that the links between compliance and the bottom line are tenuous, subtle, controversial or frankly marginal. The benefit of compliance is not intuitively obvious to junior staff; instead it is the stuff of MBA courses and Harvard Business Review articles.
I wonder if the deep problem in orthodox meta-management is that it treats management like it must have an underlying algorithm? An algorithm is a repeatable procedure (akin to a recipe) that takes a fixed set of inputs, combines and processes them in a step-wise fashion, and eventually spits out an answer. If you want to boil an egg, or optimize a production run, or simulate the climate, then there are algorithms that do the job.
Consider conventional Threat & Risk Assessment (TRA). It is conducted algorithmically. You draw up a table that lists all known threats. For each you rate its probability of occurrence and its potential degree of impact. The algorithm then weights all the inputs, rolls them up and tells us simply whether to "Fix now", "Fix later" or "Don't worry".
If each TRA was started with a blank sheet of paper, and a genuine effort was made afresh to discover all real significant threats, then that would be great. But in reality most TRAs are cut-and-paste from the last TRA; few if any fresh inputs are considered. And even if an effort is made to look diligently for new threats, scant regard may be given to the philosophical problem of not knowing what you don't know. It's impossible to tell if a threat that has been missed by a TRA (and yet we kid ourselves that TRAs give conservative answers).
Logicians have long known that there exist very simple problems for which there are no algorithms. For instance, there is no algorithmic solution to the "Stopping Problem" in Computer Science; that is, no computer program can be written that will tell us if another program, given as input, will ever stop. Similarly, there is no efficient algorithm for the "Traveling Salesman" problem (how to work out the shortest route for visiting every town connected by an arbitrary network of roads).
So it should not surprise us that in human affairs, there is probably no algorithm for management. It is high time that we tempered our expectations that organisations will benefit intrinsically from adopting standards, writing policy documents, auditing compliance with those documents, and continuously writing new ones.
"Quality is dead", indeed, killed off by the mechanistic naivety of the Total Quality Movement. Yet the very same meta-management paradigm of document, audit and document some more, was adopted in the Information Security industry and continues to be extended endlessly (the only thing better than the old standard ISO 17799 is the new standard ISO 27001; it’s as if standards intrinsically weave magic). It seems to me that the Sarbanes Oxley regime reflects the same thinking. This huge set of new overheads (not to mention, rich vein of consulting opportunities for the professional services firms) was a response to the shenanigans of white collar criminals. One has to wonder how the introduction of new compliance rules is really expected to deter crooks who aren’t exactly given to following rules in the first place?
Of all the different flavours of meta-management, at least it can be said of TQM that it was motivated by a desire to enable a better job to be done. But all the other methodologies are about a less risky job being done. How can this mindset not suffocate innovation?
Don’t great organisations have some sort of spark? Aren’t entrepreneurship and innovation usually fuelled by smart people who see things that others have not? Encouraging our people to “think outside the box” is such a hollow cliché in practice. In respect of process, it should mean buck the process! But few organisations these days truly reward people for stepping outside the strictures of compliance and governance and security, to accommodate new views – that is, to look for the unexpected inputs that elude any algorithm. Surely if we wish to cultivate innovation, originality and creativity, then we need fewer standards, not more.
Comments
A Silver Lining
Any successful creature develops internal and external parasites. Most of the time the mighty hosts are robust enough to stumble on despite being infested with the free riding worms and blood sucking fleas but, if wounded or aging, the load gets too much and they can quickly succumb. Companies too find themselves infested with red tape worms as ever more people are employed to warm ever more ludicrously expensive office furniture to write forms, fill forms, assess forms and file forms without ever actually producing anything of benefit to the consumer. This inevitably pushes up the costs incurred, and prices charged, by these firms, destroys their ability to innovate and blinds their managers to the old fashioned imperatives of providing goods that work and services which satisfy because they're too busy ensuring their mission statements are nicely printed in shiny plastic folders. However this is all to the good as it leaves the field open to newer, hungrier, more efficient firms to stomp all over the aging leviathans market share and so ensures a vigorous, fluid economy. If you spend all your time ticking boxes then the last one you fill will be the delivery note for your own commercial coffin.
Government departments are, of course, even more grotesquely bloated than private sector firms as they cannot be driven out of business no matter how redundant their staffing becomes. Many branches of the state seem to do little but employ diversity officers, health and safety executives and sensitivity training advisors but this is again to the good as the more inefficient and impotent government departments become, the less harm they can do to the honest business and private lives of the long suffering citizenry.
The empty drivel of management training cliches is much derided in this article, and rightly so, but the ability to mouth useless slogans by rote with one's fellow detainees on training days may come in terribly handy once we are forced to welcome our new overlords with chants from the Koran or Das Kapital. Sadly we'll have been unable to resist their assault because the twenty seven servicemen left in the Navy will be absent from their posts due to mandatory attendance at their weekly team bonding African drumming sessions or a seminar tackling the very real problems faced by the transgendered indigenous community at sea.
Good managers pick competent people for the job in hand and retire to the golf course to allow them to complete that task in the way they see fit. A little extra cash is a greater incentive than every team bonding course known to man and the judicious use of the sack soon weeds out the lazy and incompetent. Let us be clear about this. Every minute spent in a meeting is a wasted minute of your life. Like answering e mail and attending conferences it looks like work but produces nothing. The biggest threat that any business faces is spending all its time doing threat assessment reports instead of actually producing something someone else wants to buy.
Douglas Adams hit the nail on the head in the Hitchhikers Guide to the Galaxy. He invented a planet which separated its population into three categories - the brilliant achievers, the workers who actually got things done and, well, everyone else. The useless middle third of the population - from telephone sanitisers to tired TV executives - were tricked into boarding the 'B' ark and blasted off into space. This, of course, is too harsh. Management theorists deserve a home of their own and we have a perfectly good moon which is currently just lying about up there doing nothing. What is more we could blast them all up there in the sure and certain knowledge that, brilliant organisers though I'm sure they all are, there be no possibility whatsoever of them designing or building their own spaceship to find their own way back.