Governance Series – Building Effective Assurance Programmes

Who doesn’t love an audit? Well, most people, actually.

There are plenty of reasons to dislike audits – the biggest one being they are often a bit of a waste of time (see the great work by Ben Hutchinson discussed in this Safety of Work episode). I’m not going to go into that here, nor the value (or otherwise) of certification audits. Suffice to say I don’t do audits in their traditional sense – but I do carry out (hopefully) useful reviews of systems and their effectiveness.

But, for Boards, getting assurance from the business is a key plank of successful governance. So, we do need to work out how we carry out that assurance in a way that does add value.

In the governance guide that triggered this blog series, we talk about responding to information in a constructive way and also presenting information in an insightful way. I’ve also blogged elsewhere about the danger of favouring compliance detail over system improvement (Be a bit worse at things to get better (cm-safety.com)).

But this all pre-supposes an assurance programme is in place and operating. Here, I want to just highlight a few areas to think about to make that programme helpful.

Scoring – don’t

I detest audit scores with a passion. While I can just about get on board with a pass/fail approach in some instances, there is nothing worse than getting a % headline score. This brings with it all the problems of metrics and leads people to worry about the score, rather than the issues raised. It denotes a simplicity and an accuracy that simply doesn’t exist. A ranged result is workable – we think you’re in a good space here, industry leading here, and a bit lacking over there – and can help focus improvements in the right areas. Putting hard line boundaries between those and a specific score against them adds no value to that qualitative conclusion and brings problems with it.

Independence – mostly don’t

While there is certainly a place for it, independence is vastly over-rated in audits. The need for independence makes a tacit assumption that people can’t be trusted and that they are trying to hide something. Boards need a degree of independence as part of their normal due diligence, so it is perfectly fine to bring in a third party to supply it. But not every audit needs it. You can get a lot of value from someone who understands the business and the activities deeply. Include internal peer reviews and inter-departmental checks in your assurance programme. In a trusting environment where audits are viewed as genuine learning opportunities, this can be really helpful. Fresh eyes are good, and a third party with specific expertise can be beneficial, but bring them in for the expertise, not the independence.  

Subject matter experts – do

While we’re on the subject of experts with fresh eyes, please, please use subject matter experts in the appropriate health and safety domain and not generic auditors. I cannot tell you the number of times I have followed an audit firm into an organisation and had to undo all the compliance-based, years-out-of-date, generic nonsense they’ve recommended. Some big audit consultancies have genuine safety capability. Most don’t and just send someone from the risk team with a tick list from a regulation or standard. And they cost a fortune.

Rigorous planning – do

Assurance programmes should be risk-based – those areas of highest risk, or of highest concern for some other reason should get most attention and get reviewed most frequently. Make sure all areas of your safety management system get reviewed at least once over, say, a three year period. You can have more frequent reviews of key areas within that, but a rolling programme makes sure that all areas are covered and prevents things falling through gaps. You can change that programme easily enough if performance warrants increasing priority for a particular area. A clear programme also lets you manage both your resources for carrying out reviews and the imposition on the operational teams.

In building that programme, include both horizontal and vertical slice audits. A horizontal slice takes a specific activity and looks at it across the organisation – how good is our isolation process in all our facilities? A vertical slice takes a single part of the business and looks at all the health and safety activities – how well is facility X implementing all the safety management requirements?

Your programme is made up of more than just formal audits. Think about the routine assurance that goes on every day – routine supervisory checks, for example – and consider how you best bring information from that to the governance level. The Institute of Internal Auditors’ three lines of defence model is a good way to visualise how the various different components come together Internal audit: three lines of defence model explained | ICAS.

If you are in a governance role, compare all the information you get from the various sources. Is the independent auditor giving you the same general feedback as the health and safety team? Is front line checking surfacing the same issues? Consistency between those information streams provides a type of additional meta-feedback.

Work together – do

A plea on behalf of all contracting organisations out there. Could clients work together a bit more and co-ordinate effort? There is nothing worse for a contractor than being audited by client one and then repeating the whole process for client two – a process that is just dissimilar enough that they can’t simply copy and paste the information. This takes time, effort and resource and is mind-numbingly pointless. As a client, you aren’t just paying for the auditor, you are also covering all the preparation time, and non-productive time, required for the contractor as it just ends up in their overheads that you then pay for in higher rates later on.

So, find out who else your contractor/supplier works for, develop a joint audit scope that everyone is happy with, do it once and share the results/follow-up actions. Everybody saves some money and time – you may be able to get a more comprehensive review done by a more capable auditor and still save money!

Certification is supposed to give this shared assurance, but as everyone still wants their own audit, they clearly don’t trust it (and don’t get me started on pre-qualification).

Reporting key findings – do

Finally, I’ve talked elsewhere about reporting, but give reports to the board that identify high-risk findings (and not all the trivial ones), detail what you are going to do about those and what the process is for reporting on successful implementation of improvements as they are made.

Happy auditing reviewing.

Subscribe below for more content, straight to your in-box

Leave a Reply

Discover more from Craig Marriott Consulting

Subscribe now to keep reading and get access to the full archive.

Continue reading