Frameworks relevant to Change Management - Across Business Domains, Sectors and Industry Contexts:

Organisational change is complex, risky, and often falters or stalls. An estimated 60–70% of transformation initiatives miss objectives or exceed budgets. Why? Not because companies lack ambition or resources, but because change requires systematic approaches—not intuition or heroic effort.

This guide presents 35 proven frameworks relevant to managing change. These frameworks are not theories; they are tools used by savvy small and large organisations, to navigate uncertainty, align stakeholders, measure progress, and sustain new ways of working.

Change happens at multiple levels: strategic (why), operational (how), and individual (who). This guide maps frameworks to each level and shows how they interconnect.

Key Insight: Change requires discipline, not luck. All 35 Frameworks are explained below - Scroll and Enjoy !

Operating since 2015, (Next Level Group) NLBPi is a change management consultancy; focused on maturity uplift, performance improvement, scaling and growth. Helping client organisations and businesses to improve maturity across disciplines, ways of working, maturity uplift, governance, risk, scalability, organisational maturity, leadership capability, and AI-enabled business performance via change management consulting, coaching, systems implementation, and practical change and transformation programs.

Porter's Five Porter's Five Forces

PESTEL Analysis

OKRs (Objectives & Key Results)

EOS (Entrepreneurial Operating System)

Jobs to be Done (JTBD)

Ansoff Growth Grid

McKinsey Strategy Execution Discipline

Lean Methodology

Six Sigma / DMAIC

PDCA Cycle (Plan-Do-Check-Act)

ISO 9001:2015 (Quality Management System)

CMMI (Capability Maturity Model Integration)

TPM (Total Productive Maintenance)

RASCI / RACI

9-Box Model (Talent Assessment)

ADKAR Model (Individual Change Management)

Kotter's 8-Step Change Model

Balanced Scorecard

StaffEng Model (Technical Careers)

Psychological Safety

ISO 45001 (Occupational Health & Safety Management)

Activity-Based Costing (ABC/M)

DuPont Analysis

Customer Lifetime Value (CLV)

Net Promoter System (NPS)

Design Thinking

Lean Startup (Build-Measure-Learn, MVP)

Pirate Metrics (AARRR)

Service Design

Agile / Scrum

ITIL (IT Service Management)

NIST Cybersecurity Framework

ISO/IEC 27001 (Information Security Management System)

Scaling Up (Verne Harnish)

Sandler Sales Methodology

Governance & Risk in Transformation

Section 1: Strategic Analysis Frameworks

Porter's Five Forces

Category: Strategic Analysis - Porter's Five Forces

Process & Sequence:

Analyze Threat of New Entrants:

In change management terms, identify which internal stakeholders or external parties might resist or disrupt the transformation. How does this influence change urgency or strategy?

Examine Bargaining Power of Buyers:

Understand customer (internal and external client) expectations driving change. Are clients demanding faster delivery or different service models? This is your change driver. Use this to build the business case for transformation - client centric delivery, linked to business centric outcomes.

Assess Bargaining Power of Suppliers:

Identify dependency risks. Are critical suppliers dependent on legacy processes? Will they support digital transformation or resist because they lack capability?

Evaluate Threat of Substitutes:

Determine what alternative solutions exist if change fails. This clarifies urgency and risk. Are customers switching to competitors? This justifies investment in transformation.

Measure Industry Rivalry Intensity:

Quantify competitive pressure. High rivalry forces faster change cycles. Use this to justify aggressive transformation timelines to stakeholders.

PESTEL Analysis

Category: Environmental Scanning

Process & Sequence:

Political Assessment:

Identify regulatory changes ahead (data protection, employment law, taxation). These force structural change. Map compliance deadlines to transformation roadmap.

Economic Evaluation:

Track interest rates, inflation, currency fluctuation. Economic downturns require cost reduction (operational excellence). Growth periods allow investment in capability building.

Social Analysis:

Monitor demographic shifts, workforce expectations, skill availability. Gen Z demand flexible work; this drives remote-first process redesign. Generational change is organizational change.

Technological Scanning:

Identify AI, automation, and platform shifts. This is your primary change catalyst. Rate adoption urgency: is cloud mandatory or optional in your sector?

Environmental Review:

Track ESG expectations and carbon regulations. These drive sustainability-focused process redesign and often require technology investment.

Legal Evaluation:

Assess employment law, safety regulations, data privacy. Compliance failures force reactive crisis change; anticipating them enables proactive transformation.

Section 2: Goal Setting & Execution

OKRs (Objectives & Key Results)

Category: Goal Setting

Process & Sequence:

Define Transformation Objective:

Write a qualitative, compelling statement of transformation intent. Example: 'Become a data-driven organisation' not 'implement analytics platform.' This clarifies PURPOSE of change.

Establish 2–5 Key Results:

Translate objective into measurable quarterly outcomes. Example: 'Increase data literacy from 15% to 60% of workforce' or 'Reduce decision cycle time from 2 weeks to 2 days.' Key Results drive accountability.

Cascade OKRs Vertically:

Each team writes OKRs supporting company transformation. Finance OKRs include cost reduction targets; HR OKRs include training completion; IT OKRs include system deployment.

Align Cross-Functional Dependencies:

Identify OKRs that depend on other teams' completion. This creates interdependency visibility essential for managing change sequencing.

Review and Iterate Weekly:

Score OKRs as 0.0 (not met) to 1.0 (exceeded). Use weekly reviews to identify early signals of change resistance or blockers. Act on variance immediately.

EOS (Entrepreneurial Operating System)

Category: Operating System

Process & Sequence:

Establish Core Values:

Articulate 3–5 values that guide behaviour during transformation. Example: 'Radical transparency' signals you'll over-communicate. 'Customer obsession' prioritises external over internal politics. Values become change adoption criteria.

Define Vision/Traction Organizer (V/TO):

Create one-page strategic plan showing 1–3 year vision. This is your change destination. Communicate why the journey is necessary and where it leads.

Set Quarterly Rocks:

Define 3–7 quarterly priorities (60–90 day goals). Rocks MUST support vision. Example Rock: 'Migrate 80% of transactions to digital' demonstrates tangible progress toward transformation.

Run Level 10 Meetings:

Weekly 60-minute structured meeting: Segue (5 min good news), Metrics review (5 min), To-Do list review (5 min), IDS (50 min, Identify-Discuss-Solve), and Cascade (5 min). This drumbeat keeps change visible and accountable.

Implement Accountability Chart:

Define clear roles, responsibilities, and reporting lines. During transformation, role clarity prevents confusion and competing priorities. Reorganising the accountability chart IS often the transformation.

Document Core Processes:

Identify 3–5 critical processes and standardise them. Documentation is non-negotiable for scaling. Without process documentation, people carry legacy 'ways of working' in their heads.

Jobs to be Done (JTBD)

Category: Customer Insight

Process & Sequence:

Identify the Core Job:

In change terms, the 'job' is what your customer or employee is trying to accomplish. Example: 'Get paid accurately and on time' (not 'run payroll software'). This reframes change around human need, not tools.

Understand Functional, Emotional, Social Jobs:

Functional: accuracy, speed. Emotional: peace of mind, feeling valued. Social: being seen as professional. Change that only addresses functional needs will fail if emotional/social jobs are neglected.

Conduct Problem Interview:

Ask: 'Tell me about the last time you tried to [accomplish the job]. What was difficult?' Listen for workarounds, manual steps, frustrations. These reveal where change creates real value.

Identify Competing Solutions:

What is the current 'solution'? Often it's not your competitor; it's 'doing nothing' or 'accepting poor outcomes.' Understand the status quo bias you're fighting. Change requires overcoming inertia.

Design for the Job, Not the Feature:

If your transformation is 'implement CRM' but the job is 'understand customer needs faster,' redesign so CRM enables speed, not data entry burden. Wrong design kills adoption.

Ansoff Growth Grid

Category: Growth Strategy

Process & Sequence:

Market Penetration Strategy:

Existing products, existing markets. Change focus: efficiency and quality. Reduce cost per transaction; improve accuracy. This is incremental continuous improvement (small C change).

Market Development Strategy:

Existing products, new geographies/segments. Change focus: localisation and capability building. Entering Bangkok requires understanding Thai payroll law; this is significant change.

Product Development Strategy:

New services, existing customers. Change focus: capability and culture. Building an EOR offering when you're a payroll provider requires new skills, processes, and mindsets.

Diversification Strategy:

New products, new markets. Change focus: complete transformation. Highest risk. Requires new capabilities, different customer base, unfamiliar processes. Examples: moving from HR consulting to HR technology.

Apply to Transformation Sequencing:

Use Ansoff to explain which changes are evolutionary vs revolutionary. This frames stakeholder expectations: 'We're doing Market Penetration + Product Development, not Diversification, so expect 8–12 month timeline, not 3 years.'

McKinsey Strategy Execution Discipline

Category: Execution Framework

Process & Sequence:

Align Strategy (the 7S Model):

Ensure all seven elements support transformation: Strategy (clear vision), Structure (organisation design), Systems (IT/processes), Skills (capability), Staff (right people), Style (leadership culture), Shared Values (culture/beliefs). Misalignment kills execution.

Define Clear Strategic Priorities:

Name 3–5 transformation priorities. Example: 'Digital-first operations,' 'Data-driven decision making,' 'Integrated global payroll.' Clarity prevents competing initiatives consuming resources.

Allocate Resources Explicitly:

Transformation requires dedicated funding. Budget line items: technology, training, change management, backfill for people leading change. Hiding costs in existing budgets guarantees failure.

Assign Accountability:

Single leader accountable for each priority. In transformation, unclear accountability is fatal. 'Strategy is everyone's job' means it's no one's job. Assign explicitly.

Establish Governance and Review Cadence:

Weekly/bi-weekly reviews at team level, monthly at leadership, quarterly at board. Reviews answer: 'Are we on track? What blockers exist? What's our risk? Do we have support?' Regular reviews catch drift early.

Manage Interdependencies:

Map which initiatives depend on others. Example: digital CRM depends on data integration; data integration depends on legacy system decommission. Sequence work to manage dependencies.

Lean Methodology

Category: Process Improvement

Process & Sequence:

Create Value Stream Map (VSM):

Draw every step from customer request to delivery. Mark value-add (customer pays for) vs non-value-add (she doesn't). In payroll: data entry is non-value; accuracy is value. Automation removes non-value steps. VSM makes waste VISIBLE.

Identify 8 Wastes (DOWNTIME):

Defects (rework), Overproduction (output nobody wants), Waiting (idle people/data), Non-utilised talent (not using staff skills), Transportation (unnecessary handoffs), Inventory excess, Motion (unnecessary movement), Extra processing. Each wastes budget and extends timelines.

Implement Pull System:

Stop 'pushing' work downstream. Move to pull: upstream acts only when downstream signals demand. Example: Don't batch payroll advice; generate it when accountants request it. Reduces inventory of 'work waiting.'

Run Daily Kaizen (5-minute improvement meetings):

Team huddle: 'What got in the way yesterday? What's one small fix we'll try today?' Small daily improvements compound. Kaizen embeds continuous improvement as operating norm during transformation.

Apply 5S Workplace Discipline:

Sort (remove unnecessary items), Set in order (logical arrangement), Shine (clean/maintain), Standardise (visual controls, procedures), Sustain (daily discipline). During transformation, 5S creates visible order, builds confidence that change is managed.

Section 3: Process Improvement

Six Sigma / DMAIC

Category: Defect Reduction

Process & Sequence:

Define Problem and Goal (DEFINE):

Be specific. Not 'improve payroll accuracy' but 'reduce payment errors from 2.3% to 0.5%.' Baseline the current state with data. Define success metric and acceptable timeline (e.g., 6 months).

Measure Current Performance (MEASURE):

Collect data on the problem. How often? What types of errors? From which process step? Use statistical tools: control charts, histograms, pareto analysis. Data replaces opinion.

Analyse Root Cause (ANALYSE):

Use fishbone diagram, 5 whys, process flow analysis. Example: 80% of payroll errors from manual bonus calculation. Root cause: bonus rule is complex, documented in email, not system. Don't blame people; fix the process.

Improve: Address Root Cause (IMPROVE):

Design solution to eliminate root cause, not just symptom. Example: Automate bonus calculation based on rule logic. Run pilot with 10% of payroll. Measure error rate. If 90% reduction achieved, scale.

Control to Sustain the Gain (CONTROL):

Establish control plan: monitoring metrics (weekly error report), control limits (alert if error rate > 0.6%), accountability (who monitors?), corrective actions (what happens if threshold breached?). Without controls, process drifts back.

PDCA Cycle (Plan-Do-Check-Act)

Category: Experimentation

Process & Sequence:

PLAN: Define Hypothesis:

'If we automate expense approval workflow, we'll reduce approval cycle from 5 days to 2 days.' Make hypothesis testable. State assumption clearly: 'We assume bottleneck is manual review.'

DO: Run Small Test:

Pilot with one department, 100 transactions, 2-week duration. Small scope = fast feedback, low risk. Don't full-roll-out without testing.

CHECK: Measure Results:

Did approval cycle drop to 2 days? Compare actual vs hypothesis. If yes, proceed. If no, diagnose why. Example: cycle improved to 3 days, not 2. Question: Why? Was hypothesis wrong? Did we miss a step?

ACT: Standardise or Repeat:

If successful: standardise across organisation, document procedure, train teams. If unsuccessful: adjust and repeat PDCA. Example: If automation alone didn't work, maybe we also need role redesign. Run new PDCA.

Document Learning:

Record what worked, why, and unexpected outcomes. This builds institutional knowledge. Transformation is pattern recognition; each PDCA cycle teaches the organisation.

ISO 9001:2015 (Quality Management System)

Category: Governance

Process & Sequence:

Establish Quality Policy:

Senior leadership commits to product/service quality and continuous improvement. Policy shapes decision-making. Example: 'We prioritise accuracy over speed; zero defects is non-negotiable.' This influences which changes get funded.

Define Customer Focus:

Understand customer requirements. Document them (SLA: '99.5% payment accuracy'). Every process is designed to meet customer requirement. This prevents changes that optimise for cost but sacrifice quality.

Map and Document Processes:

Identify all significant processes (payroll, training, compliance). Document: purpose, inputs, outputs, controls, risks, responsible people. Documentation makes processes repeatable and auditable.

Establish Performance Metrics:

Define KPIs for each process: accuracy %, cycle time, cost per transaction. Monthly review: 'Are we meeting targets? If not, why?' Metrics drive accountability.

Run Management Review:

Quarterly executive review of quality performance. Questions: Are we meeting customer requirements? Are processes effective? Do we see improvement trends? Is training adequate? This ensures quality stays on leadership agenda.

Conduct Internal Audits:

Quarterly independent review: 'Are we following our documented procedures? Are controls working?' Audits identify gaps. Corrective actions close gaps. This prevents drift from standards.

Section 4: Quality & Maturity

CMMI (Capability Maturity Model Integration)

Category: Maturity Assessment

Process & Sequence:

Understand CMMI Levels 1–5:

Level 1 (Initial/Chaotic): Ad hoc processes, unpredictable results. Level 2 (Managed): Basic project discipline, some documentation. Level 3 (Defined): Standardised processes across organisation. Level 4 (Quantitatively Managed): Data-driven process control. Level 5 (Optimizing): Continuous improvement embedded.

Assess Current State:

Evaluate where your organisation sits. Typical SMEs are Level 1–2: talented people doing good work but inconsistently, undocumented. Assessment reveals gaps. Example: Project delivery varies 3x depending on team.

Define Transformation Path:

Moving Level 2 → 3 requires process standardisation (documentation, training, control). Moving Level 3 → 4 requires data analytics (metrics, statistical process control). Each level jump requires different capability investment.

Establish Process Improvement Program:

Assign process owners. Set improvement priorities. Example: 'Payroll process to Level 3 (defined), then Finance to Level 3.' Sequence improvements to build momentum.

Measure and Track Progress:

Track: process compliance (% following documented procedures), capability assessment results, defect trends. Progress is visible; morale improves when people see advancement.

Use CMMI as Transformation Roadmap:

Clarify for stakeholders: 'We're moving to Level 3. This means every process will be documented and standardised. Initial pace is slower (more documentation) but variability drops and quality improves.' CMMI provides vocabulary to explain maturity progression.

TPM (Total Productive Maintenance)

Category: Asset Management

Process & Sequence:

Define TPM Goal (Zero Breakdowns, Defects, Accidents):

Move from 'reactive maintenance' (fix when broken) to 'predictive maintenance' (prevent breakdowns). In digital transformation terms: Move from 'system outages' to 'zero downtime deployment.' Goal is business continuity.

Engage All Employees:

Maintenance is not just the IT/ops team's job. Equipment operators perform daily checks: clean, inspect, lubricate. In digital terms: end-users are trained to report small bugs before they become critical. Everyone is responsible.

Implement Autonomous Maintenance:

Operators perform routine care: checks, oil changes, belt adjustments. In systems terms: teams own health of their systems, run daily deployment checks, monitor logs. Operators become first line of defence.

Establish Planned Maintenance Schedule:

Regular deep maintenance: hardware upgrade, OS patches, security scans. Schedule during low-traffic periods. In digital terms: monthly release windows, quarterly infrastructure upgrades. Planned beats emergency.

Track Mean Time Between Failures (MTBF):

Measure: how often do systems fail? Graph trend. In manufacturing, MTBF of 1000 hours → 500 → 200 hours shows maintenance program failing. If your system has weekly outages, TPM isn't working.

Calculate Return on Investment:

Cost of TPM (training, tools, time) vs. downtime cost. Usually ROI is positive: fewer outages = more revenue, better customer satisfaction, fewer firefights. Transformation investment pays for itself.

Section 5: People & Talent Management

RASCI / RACI

Category: Governance

Process & Sequence:

Define Responsible Role:

Who does the work? One or more people can be Responsible. Example: Software engineers are Responsible for code deployment. They own the task.

Assign Accountability:

Exactly ONE person is Accountable. They sign off, make final decisions, bear consequences if work fails. In transformation: one change lead per workstream. No shared accountability; clear ownership.

Identify Consulted Stakeholders:

Who provides two-way input? Example: Business analyst is Consulted on requirements; they provide input, listen to feedback. Consulted people influence decisions but don't make them.

Name Informed Parties:

Who gets one-way status updates? HR manager is Informed when IT system goes live. They don't provide input but need to know. One-way communication prevents over-involving people in every decision.

Apply RASCI Matrix:

Create table: rows = tasks/decisions, columns = roles. Each cell = R/A/S/C/I. Example: 'System migration' is: R = IT team, A = CTO, S = external consultant, C = business process owner, I = finance (they need to know about costs). Visual matrix clarifies expectations.

Prevent Accountability Gaps:

Red flag: task with no Accountable person (gets lost). Red flag: everyone Consulted (nobody listens). RASCI forces clarity. Confusion during transformation = execution failure. Clarity = accountability = delivery.

9-Box Model (Talent Assessment)

Category: Talent Management

Process & Sequence:

Define Performance Axis (X-axis: Low, Medium, High):

Rate current performance. Use data: exceed targets (high), meet targets (medium), below targets (low). Don't rely on perception. Example: Sales rep with 120% of quota = high performer.

Assess Potential Axis (Y-axis: Low, Medium, High):

Potential = capability to succeed in more senior/complex role. Look for: learning agility, problem solving, leadership qualities. High potential doesn't mean high current performance. Sometimes top performers have hit their ceiling.

Map Talent to 9 Zones:

High Performance + High Potential = Future Leaders (invest, develop, accelerate). High Performance + Low Potential = Solid Performers (keep happy, value, reward). Low Performance + High Potential = High Potentials (coach, redirect, develop). Low Performance + Low Potential = Poor Fits (exit, redeploy, or accept they're in right role).

Apply to Transformation Staffing:

Future Leaders lead workstreams; they want challenge. Solid Performers do the steady work; they want recognition. High Potentials are early adopters; put them in change roles. Use 9-box to staff transformation with right-fit people.

Plan Succession:

Identify High Potential + High Performance people for critical leadership roles. Succession plan: who replaces whom if someone leaves? Plan for top 5 critical roles. During transformation, losing a change leader is catastrophic.

Make Difficult People Decisions:

If someone is Low/Low, retain them only if: role is truly entry-level, or high technical skill in niche area, or irreplaceable in short term. Otherwise, plan graceful exit. Keeping wrong-fit people undermines culture during stressful transformation.

ADKAR Model (Individual Change Management)

Category: Change Management

Process & Sequence:

Build Awareness of Why Change is Needed:

Communicate: 'Why are we changing? What problem does it solve? What happens if we don't change?' Examples: market pressure, customer demand, cost crisis, regulatory requirement. People resist change they don't understand.

Cultivate Desire to Participate:

Move beyond knowing why to wanting to participate. Address: 'What's in it for me?' Career growth? Easier job? Better tools? Create personal relevance. People adopt when they see personal benefit, not just business rationale.

Provide Knowledge (How to Change):

Training: new systems, new processes, new tools. Knowledge is necessary but not sufficient. People can learn software but still resist using it if they don't see the point (back to Desire).

Build Ability to Implement:

More than training. Coaching, practice, shadowing, documentation. Example: training payroll officers on new software (knowledge). But ability comes from: practising 20 live transactions with mentor, working through edge cases, building confidence.

Reinforce to Sustain:

Don't assume change sticks. Reinforce through: performance metrics, manager coaching, refresher training, celebrating successes, correcting backsliding quickly. Reinforcement requires sustained effort for 3–6 months post-launch.

Diagnose Where Change Stalls:

If adoption is poor, diagnose: Do people understand why (Awareness)? Do they want to change (Desire)? Can they do it (Knowledge + Ability)? Is it reinforced (Reinforcement)? Usually failure is Desire gap, not Ability gap. Fix the right problem.

Kotter's 8-Step Change Model

Category: Organisational Change

Process & Sequence:

1. Create Urgency:

Paint clear, compelling picture of why change is essential now. Data helps: 'We've lost 3 major clients to competitors with AI; at current rate, we'll lose 30% revenue in 2 years.' Or: 'New regulation effective Jan 2026 means we must decommission legacy system by Dec 2025.' Urgency overcomes inertia.

2. Build Guiding Coalition:

Assemble ~10 senior leaders (mix: formal authority + informal influencers). They champion change across organisation. Example: CEO + CFO (formal) + respected payroll manager + IT architect + HR business partner (influencers). Coalition creates political cover for change.

3. Form Strategic Vision:

Paint picture of desired future state (3-year horizon). Not a list of projects but a narrative. Example: 'We are a data-driven organisation where every decision is informed by real-time insights and every team operates with digital-first processes.' Vision aligns effort; without it, change becomes list of unrelated projects.

4. Enlist Volunteer Army:

Identify and activate change enthusiasts (early adopters) at all levels. Not mandatory; voluntary. They evangelise change to peers. Bottom-up energy complements top-down leadership. Example: IT team leads 'digital skills' working groups.

5. Enable Action by Removing Barriers:

Identify what blocks change: organisational structure (wrong reporting lines), systems (legacy IT), budgets (underfunded), skills (lack expertise), culture ('we've always done it this way'). Systematically remove obstacles. Example: If change needs budget decision, empower coalition to approve without board approval (enable). If process change needs ops IT support but IT blocked by legacy projects, reallocate IT resources (remove barrier).

6. Generate Short-Term Wins:

Plan for quick, visible successes within 6–12 months. Example: pilot digital onboarding in one office, reduce onboarding time 3 weeks → 1 week, celebrate with the team. Wins build momentum, prove change is possible, sustain energy. Without wins, change feels endless.

7. Sustain Acceleration:

After first wins, don't declare victory. Launch next phase. Example: After successful pilot, expand to 5 locations, then rollout globally. Change is 3–5 year journey. Sustain by reinforcing: progress updates, celebrating milestones, keeping urgency alive.

8. Institute Change in Culture:

Embed change in 'how we work.' Reflect in: hiring criteria (hire digital-ready people), performance management (reward digital adoption), promotion criteria (leaders demonstrate change leadership), stories (celebrate change heroes). Culture shift is final step; without it, change reverts under pressure.

Section 6: Customer & Performance

Balanced Scorecard

Category: Performance Management

Process & Sequence:

Financial Perspective: 'How Do We Look to Shareholders?':

Define financial outcomes of transformation. Example: 'Increase operating margin from 15% to 22%' or 'Reduce cost per payroll cycle from $8 to $5.' Financial metrics drive investment. Leaders care about ROI. Change that doesn't improve financials faces budget cuts.

Customer Perspective: 'How Do Customers See Us?':

Define customer-facing improvements. Example: 'Reduce payroll error from 2% to 0.2%' or 'Increase on-time delivery from 95% to 99.5%' or 'Improve NPS from 45 to 65.' Customer metrics tie change to revenue/retention.

Internal Process Perspective: 'What Must We Excel At?':

Define internal capabilities needed for customer/financial outcomes. Example: 'Achieve <2 day payroll cycle' or 'Zero critical system outages.' Internal process metrics show what your operations team must deliver.

Learning & Growth Perspective: 'How Can We Improve?':

Define capability, culture, and technology foundation. Example: 'Achieve 80% digital literacy' or 'Adopt cloud for 100% of systems' or 'Reduce staff turnover to <10%.' Learning metrics show long-term health. Example: digital literacy today → process automation tomorrow → margin improvement next year.

Link Perspectives in a Causal Chain:

Learning → Internal Process → Customer → Financial. Example: (Learning) Train staff on data analytics → (Process) Analytics inform all decisions → (Customer) Faster, better service → (Financial) Higher margin, retention. This causal chain explains how transformation drives results.

Use Scorecard as Executive Dashboard:

Monthly review: one page, 12–16 metrics (3–4 per perspective). Visual: 12-month trend line for each metric. Red/yellow/green status. Questions: Are we on track? Where are we lagging? What actions needed? Scorecard keeps executive team aligned on priorities during transformation chaos.

StaffEng Model (Technical Careers)

Category: Talent Strategy

Process & Sequence:

Recognise Technical Leadership Without Management:

Senior Engineer ≠ Engineering Manager. Both are senior; different paths. Technical leader: deep expertise, drives technical strategy, mentors engineers, leads complex projects. Manager: develops people, manages performance, hires, builds teams. Organisation needs both.

Define Staff Engineer Role:

Staff Engineer: 10+ years experience, recognised technical expert, drives technical decisions. Salary at or above manager level. Responsibilities: technical architecture, solve hard problems, mentor engineers, influence without authority.

Set Expectations: Scope, Impact, Breadth:

Staff Engineer impact is: multiple teams/years, architectural decisions, mentorship of 5+ engineers, influence on engineering culture. Differentiate from Senior Engineer (expert in one domain) from Manager (direct reports, performance management).

Ladder Advancement: Staff → Principal → Distinguished:

Staff Engineer: expert in one domain. Principal: multi-domain, company-level impact. Distinguished: industry-level impact. Each level has clearer scope and expectation. Path is clear.

Apply During Transformation:

Transformation needs strong technical leaders who aren't ready to manage. Example: Senior engineer leads cloud migration architecture, mentors team, influences decisions, but no direct reports. Prevent talented engineer from leaving because only path up was management. StaffEng retains technical talent.

Remove Ceiling on Technical Salary:

Typical organisations pay managers higher than senior engineers, forcing choice: manage or take pay cut. Remove artificial ceiling. Pay staff engineer equivalent to director. This signals: technical excellence is valued equally with people leadership.

Psychological Safety

Category: Culture

Process & Sequence:

Define: Belief That You Won't Be Punished:

Psychological safety = belief that I can speak up with ideas, questions, mistakes, or concerns without being humiliated or punished. It's NOT about being nice; it's about making it safe to take interpersonal risk.

Model Vulnerability as Leader:

Leaders admit mistakes publicly. Example CEO: 'I made a bad hiring decision 2 years ago; we parted ways and I learned X.' Or: 'I don't know the answer to that question; let's figure it out together.' When leaders admit fallibility, team feels safe doing same.

Respond Constructively to Bad News:

When team reports problem, respond: 'Thank you for bringing this up; let's understand what happened and fix it' not 'Why didn't you catch this earlier?' Punishment for bad news = team hides bad news = problems compound.

Acknowledge Fallibility:

Publicly acknowledge: 'We don't have all answers. We'll learn as we go. Mistakes are data.' This frames transformation as learning journey, not performance test.

Invite Input Explicitly:

Ask: 'What am I missing? What concerns do you have?' Don't wait for volunteers. Directly ask quieter voices. Some people won't speak unless explicitly invited.

Apply to Change Adoption:

High psychological safety = people report change blockers early, suggest improvements, admit confusion. Low safety = people hide problems ('I'll figure it out'), nod in meetings then revert to old ways, resist silently. Psychological safety accelerates adoption.

ISO 45001 (Occupational Health & Safety Management)

Category: Safety Management

Process & Sequence:

Establish Safety Policy and Leadership Commitment:

Senior leadership commits to OH&S. Policy: zero tolerance for injury, hazard elimination is priority, workers can stop unsafe work without penalty. Policy shapes decisions. Example: new process change requires safety assessment; if risk is unacceptable, change is postponed.

Identify Hazards and Assess Risks:

Systematic identification: what could cause injury? Chemical exposure? Repetitive strain? Psychological stress? For each, assess: likelihood (rare/possible/likely) × severity (minor/serious/death). High risk gets highest priority control.

Implement Hierarchy of Controls:

Elimination (remove hazard). Substitution (safer alternative). Engineering controls (machine guards, ventilation). Administrative controls (procedure, training). PPE (last resort). Elimination/substitution are preferred; PPE alone is weak.

Consult and Involve Workers:

Workers see hazards others miss. Involve in hazard identification, control design, decision-making. Example: warehouse staff suggest equipment change to reduce back strain; their voice is heard. Involvement builds ownership.

Investigate Incidents and Near-Misses:

When accident/near-miss occurs, investigate: What sequence of events led here? What allowed hazard to cause harm? Fix root cause, not symptom. Example: worker hurt; investigation shows guardrail was bypassed because it slowed work. Fix: process design that doesn't require bypassing safety.

Link to Transformation:

If transformation removes safety guard rails (speeds process at safety cost), it's wrong. Example: digitising approvals shouldn't mean removing quality checks. Safety is non-negotiable during change.

Activity-Based Costing (ABC/M)

Category: Cost Management

Process & Sequence:

Identify Activities:

What activities consume cost? Payroll: data entry, verification, payment processing, reconciliation, compliance reporting. Finance: invoice processing, AP approval, reconciliation. Each activity has cost.

Determine Cost Drivers:

Cost driver = measure of how much activity is consumed. Example: payroll data entry cost is driven by # of employees, # of changes (hires/terminations/pay adjustments). Verification cost driven by # of exception items.

Trace Costs to Drivers:

Example: payroll team costs $600k/year. 50% time on data entry = $300k. Data entry cost driver: # of pay adjustments. If 100 adjustments/month, cost per adjustment = $250. If we reduce adjustments 30%, cost saves $75k annually.

Assign Costs to Products/Customers:

Traditional costing: Payroll cost = (headcount × cost per employee). Wrong if customers vary in complexity. ABC: Cost = driver usage × rate. Example: customer A with 50 employees, few changes = $150/employee. Customer B with 50 employees, 20 changes/month = $180/employee. ABC reveals true cost.

Identify Unprofitable Customers:

ABC often reveals: Customer looks profitable by revenue/margin but is actually loss-making. Example: high-touch customer with frequent calls, exceptions, custom reports. Revenue $100k; actual cost $120k = loss. Decision: renegotiate, automate, or exit.

Use for Transformation ROI:

Calculate transformation cost per activity. Example: Automation of payroll data entry costs $150k. Current cost: $300k annually. Payback: 6 months. ABC makes ROI visible and defensible.

Section 7: Innovation & Development

DuPont Analysis

Category: Financial Analysis

Process & Sequence:

Calculate DuPont Ratio: ROE = Net Profit Margin × Asset Turnover × Financial Leverage:

ROE (Return on Equity) = Net Profit / Shareholder Equity. DuPont breaks this into three levers. Example: ROE of 15% = (10% Net Margin) × (1.5x Asset Turnover) × (1.0x Leverage).

Analyse Profit Margin Component:

Net Profit Margin = Net Profit / Revenue. Margin reflects pricing and cost control. If margin is 8% and industry average is 12%, organisation is charging too low or costing too high. Transformation to reduce cost or increase pricing improves margin.

Analyse Asset Turnover Component:

Asset Turnover = Revenue / Total Assets. Turnover reflects asset productivity. If asset turnover is 1.2x and competitor is 1.8x, you're using more assets to generate same revenue. Transformation to increase capacity or reduce asset base improves turnover.

Analyse Leverage Component:

Financial Leverage = Total Assets / Shareholders' Equity. Leverage reflects debt levels. High leverage = high risk, potential high return. Low leverage = conservative. Transformation focused on profitability can reduce need for debt.

Identify Improvement Opportunities:

Example: ROE is 10%, target is 15%. DuPont shows: Margin is fine (10%), but Turnover is low (1.0x vs 1.5x industry). Action: improve asset productivity. Invest in automation (increase output) or reduce assets (consolidate data centres). Transformation targets asset turnover.

Apply to Transformation Impact:

Forecast post-transformation DuPont: automation reduces cost per unit (margin ↑), process efficiency reduces inventory (turnover ↑). Example: ROE forecast 15% (up from 10%). This justifies transformation investment.

Customer Lifetime Value (CLV)

Category: Customer Economics

Process & Sequence:

Calculate Average Purchase Value:

Example: payroll customer annual contract value = $120k. Or SaaS customer MRR = $5k. Purchase value = typical transaction size or recurring revenue.

Determine Average Purchase Frequency:

Example: payroll customer pays monthly = 12 times/year. SaaS customer is monthly subscription = recurring. Ecommerce: customer purchases 24 times/year. Frequency = transactions per year or duration of subscription.

Estimate Average Customer Lifespan:

How long does customer stay? Payroll customer average tenure = 5 years. SaaS customer churn = 10% annually = 10-year average lifespan. Ecommerce repeat customer average lifecycle = 3 years. Lifespan = years until customer leaves.

Calculate CLV = (Purchase Value) × (Frequency) × (Lifespan):

Example: Payroll customer: $120k × 1 × 5 = $600k CLV. SaaS customer: $60k/year × 1 × 10 = $600k CLV. CLV shows total profit a customer generates over relationship.

Subtract Acquisition and Service Costs:

Simple CLV ignores costs. More accurate: CLV = (Revenue - Cost) per customer over lifetime. Example: $600k revenue - $200k service cost = $400k profit CLV. Or annual basis: $120k - $40k = $80k profit CLV.

Use for Transformation Investment:

If CLV is $600k and transformation cost is $200k to improve customer retention 5% (1 year longer per 20 customers), ROI is strong. Also use for acquisition decisions: spend up to 20% of CLV on acquisition = $120k to acquire $600k CLV customer.

Net Promoter System (NPS)

Category: Customer Feedback

Process & Sequence:

Ask the Core Question:

'How likely are you to recommend us to a friend/colleague on a scale of 0–10?' One question, simple. This reveals overall satisfaction and willingness to advocate.

Categorise Responses:

9–10 = Promoters (loyal, likely to refer). 7–8 = Passives (satisfied but vulnerable, might switch if competitor offers slightly better). 0–6 = Detractors (unhappy, may actively discourage others).

Calculate NPS Score:

NPS = (% Promoters) - (% Detractors). Example: 60% Promoters, 20% Detractors = NPS of 40. Benchmark: NPS >50 is excellent, 30–50 is good, <30 is at-risk.

Follow Up With Open Question:

'Why did you give that score?' This is the real gold. Promoters reveal what you're doing right (reinforce it). Detractors reveal problems (fix them). Passives reveal vulnerabilities (address them before they leave).

Segment By Cohort:

Track NPS by customer segment: enterprise vs SME, new vs established, by region. Example: SME NPS is 30 (at-risk) while enterprise NPS is 55 (strong). Investigate why; allocate resources to fix SME experience.

Link to Transformation:

If transformation aims to improve customer experience, NPS is key metric. Example: target NPS improvement 40 → 55 in 12 months. Track quarterly NPS during transformation. If improvement slips, diagnose: is service quality degrading? Communication unclear? Use NPS to steer change.

Section 8: Operations & IT

Design Thinking

Category: Innovation

Process & Sequence:

EMPATHISE: Understand User Needs:

Observe customers and employees using product/process. Interview: 'Tell me about last time you [used the system]. What was hard? What did you wish worked differently?' Don't assume you know the problem. Listen deeply.

DEFINE: Frame the Problem:

Synthesis: what problem did you hear repeatedly? Not 'customers want faster response' but 'customers can't track order status; they call and ask.' Framing the right problem is critical. Wrong problem = wrong solution.

IDEATE: Generate Solutions:

Brainstorm without judgment: quantity before quality. 'How might we reduce support calls about order status?' Ideas: status page, SMS updates, order tracking chatbot, proactive email notifications. Diverge first (many ideas), then converge (best ideas).

PROTOTYPE: Build Quick, Cheap Mockup:

Don't build full system. Build testable prototype. Example: static web page showing order status. Show to customer. Gather feedback. Prototype cost = $2k and 1 week. Full build cost = $100k and 3 months. Fail cheap, fail fast.

TEST: Get Feedback from Users:

Show prototype to 10 users. Question: 'Does this solve your problem?' Watch them use it. Where do they struggle? What's confusing? Iterate based on feedback. Multiple test cycles narrow in on solution.

Apply to Transformation:

Don't design new process in isolation. Design thinking: observe current process, interview users, prototype new design, test with users before full rollout. Prevents 'we built something nobody wants' scenario. Design thinking = better adoption.

Lean Startup (Build-Measure-Learn, MVP)

Category: Product Development

Process & Sequence:

Define Hypothesis:

'If we offer digital HR service to SMEs, SMEs will buy because it's cheaper than consultants.' Hypothesis is educated guess about market. Base on customer research, not wishful thinking.

Build Minimum Viable Product (MVP):

MVP = smallest version that tests hypothesis. Example: HR service MVP = 5 templated HR documents (contract, policy, handbook) + 2-hour setup call. Not full platform; not competitor-ready. Just enough to test.

Release MVP to Real Customers:

Small initial launch: 5–10 early adopter customers. Not beta; real money changes hands (if hypothesis proves wrong, you learn fast). Customers are patient; they know it's minimal. They provide honest feedback.

Measure: Gather Data:

Track: How many purchased? How many stuck (churn)? How much revenue? Where did they struggle? What did they request? Measure, don't assume. Example: 10 customers, 7 stuck after 3 months = 70% churn. Not sustainable.

Learn: Analyse Results:

Did hypothesis hold? If yes: 'Digital HR service appeals to SMEs.' If no: 'SMEs want consulting, not templates.' Learning guides next decision: iterate (improve MVP), pivot (change direction), or persevere (scale).

Iterate or Pivot:

If 70% churn, don't launch 100 customers. Iterate: add hand-holding, improve templates, add training. Test again. If still failing, pivot: maybe SMEs want consulting + templates (higher price), not templates alone. Lean startup prevents building full product nobody wants.

Pirate Metrics (AARRR)

Category: Customer Lifecycle

Process & Sequence:

ACQUISITION: How Do Users Find You?:

Track sources: organic search, paid ads, referral, direct. Metric: monthly users acquired. Example: 1,000 users acquired monthly. Cost: $30k on ads = $30/user acquisition cost. Benchmark against CLV; should be <20% of CLV.

ACTIVATION: Do They Have Positive First Experience?:

Not all acquired users engage. Track: % completing first meaningful action. Example: % of new users completing their first payroll = 60% activation. Missing 40% never get value; they churn. Improve onboarding to boost activation.

RETENTION: Do They Keep Using?:

Track: Monthly Active Users (MAU) / cohort size. Example: 100 users acquired month 1; 60 still active month 3 = 60% 3-month retention. Benchmark: SaaS target 90% monthly retention. If 70%, you're losing 30% cohort monthly; unsustainable.

REVENUE: Are They Paying?:

Not all active users monetise. Track: ARPU (Average Revenue Per User). Example: 60 active users generating $5k revenue = $83/user. Track: gross margin (revenue - cost). If margin is negative, business is broken.

REFERRAL: Are They Telling Others?:

Track: referral rate (% of users referring others). Example: 5 of 60 active users refer friends = 8% referral rate. Referral users have lower acquisition cost and higher LTV. Optimise for referral = viral growth.

Identify Bottleneck:

Funnel: 1,000 Acquired → 600 Activated → 300 Retained → 150 Revenue-generating → 12 Referrers. Which step is weakest? Likely retention (biggest drop). Fix retention first. If acquisition is weak, that's second priority. AARRR shows where to focus effort.

Section 9: Security & Risk

Service Design

Category: Experience Design

Process & Sequence:

Map Customer Journey (Touchpoints):

Document every interaction: awareness (ad, word-of-mouth), consideration (website, demo), purchase (sales call, contract), onboarding (setup, training), support (help, escalation), renewal (account review, upsell). Front-stage: customer-facing. Back-stage: internal operations.

Identify Moments of Truth:

Which touchpoints matter most? Example in payroll: accurate payment (critical), error resolution (critical), year-end reporting (moderate), renewal conversation (moderate). Allocate resources to critical moments.

Design Front-stage Experience:

Customer-facing. Example: onboarding. Problem: customers don't understand process. Design: step-by-step welcome email, 1-on-1 setup call, knowledge base. Each touchpoint removes friction.

Design Back-stage Operations:

Behind the scenes, what must happen to deliver front-stage experience? Example: onboarding requires: data validation, training, system setup, quality check. All happen behind stage. If any missing, front-stage suffers.

Blueprint the Service:

Create visual service blueprint: top row = customer actions, middle row = front-stage employee actions, bottom row = back-stage operations. Show dependencies. Example: customer action 'requests invoice review' requires back-stage 'accountant audits invoice' before front-stage employee delivers.

Identify Handoff Failures:

Typical SME problem: 'Sales promises X; operations delivers Y.' Service blueprint makes promises visible. Example: sales says 'onboarding complete in 1 day' but ops needs 5 days. Misalignment. Blueprint forces conversation and alignment before failure.

Agile / Scrum

Category: Work Management

Process & Sequence:

Define Product Owner Role:

Product Owner (PO) owns what to build: vision, requirements, priority. PO is not committee; one person decides. Example: IT transformation PO decides: 'Phase 1 is cloud migration, Phase 2 is automation.' Team executes what PO prioritizes.

Assemble Scrum Team (5–9 people):

Cross-functional: developers, testers, analysts. Team size = size of 2 pizzas (small). Larger team = communication overhead. One team owns one feature end-to-end.

Assign Scrum Master (Facilitator):

SM is not manager; is facilitator. Role: remove blockers ('team can't deploy because change control process takes 2 weeks; SM escalates and fixes'). SM protects team from interruptions. SM is servant-leader.

Create Product Backlog:

List of features/fixes prioritized by PO. Example: Cloud migration backlog: 'Migrate identity system,' 'Migrate database,' 'Migrate apps,' 'Validate performance,' 'Cutover.' Not all in current sprint; highest priority at top.

Run Sprint Planning (1–2 hours per week):

Team and PO meet. PO presents top backlog items. Team estimates effort. Team commits to items achievable in sprint (1–4 weeks, typically 2). Example: 'We'll migrate identity system this sprint.'

Daily Standup (15 minutes):

Every day: What did I do yesterday? What will I do today? Any blockers? Standup keeps team synchronised and surfaces blockers fast. Blocker on day 1 gets fixed day 1, not day 5.

Sprint Review (1 hour):

Team demos what was completed. PO verifies it meets definition of done. Stakeholders give feedback. Feedback informs next sprint priorities. Example: 'Identity migration works; performance is good; team requests next sprint focus on database.'

Sprint Retrospective (1 hour):

Team reflects: 'What went well? What didn't? What will we improve?' Example: 'Daily standup is effective; we'll keep it. Testing was slow; we'll pair test with dev next sprint.' Continuous improvement baked in.

ITIL (IT Service Management)

Category: IT Operations

Process & Sequence:

Service Desk: Single Point of Contact:

Centralise all IT requests/incidents. One phone number, one ticket system. Service desk logs issue, assigns priority, tracks resolution. Users know where to report problems. No more 'I'll email IT guy directly' circumventing tracking.

Incident Management: Handle Outages:

When system goes down: Service desk logs incident, assesses impact/urgency (critical/high/medium/low), assigns to team, monitors resolution. SLA: critical resolved in 4 hours. Incident post-mortem: what caused it? How prevent recurrence?

Problem Management: Fix Root Causes:

Incident = symptom. Problem = root cause. Example: incident = 'payroll system slow.' Problem = 'database not optimised.' Problem management solves problems once; prevents recurring incidents. Proactive vs reactive.

Change Control: Prevent Unintended Impact:

Before deploying change: submit for review (what's changing? why? who's affected? rollback plan?). Review checks: 'Is there risk? Can we handle it?' Approval gates prevent 'oops, that broke production.' Process is bureaucratic but prevents catastrophes.

Service Level Management (SLM): Define & Monitor Expectations:

Agree with business: 'System availability 99.5% annually' or 'Incident response <4 hours critical.' Monitor monthly: 'Were we 99.5%?' If not, investigate. SLM creates accountability between IT and business.

Asset Management: Track IT Inventory:

Know what you own: servers, licenses, tools, versions. Why? License compliance, security patches, capacity planning. Example: 'We own 150 servers; 80 are past EOL; need upgrade budget.' Asset register prevents 'ghost' servers nobody remembers.

Section 10: Growth & Sales

NIST Cybersecurity Framework

Category: Risk Management

Process & Sequence:

IDENTIFY: Know Your Assets and Risks:

Inventory: systems, data, people, dependencies. Map: what data do we hold? Where? Who accesses it? What's the risk if it's stolen/leaked? Example: customer PII is high-risk. Employee email is lower-risk. Identify forces you to think about what matters.

PROTECT: Implement Safeguards:

Access control: who can access what data? Encryption: at rest (stored data) and in transit (network traffic). Example: customer data encrypted; only authorized staff access. Authentication: strong passwords, multi-factor. Training: staff know not to click phishing. Protections reduce attack surface.

DETECT: Monitor for Attacks:

Monitoring: unusual access patterns, failed login attempts, data transfers. Alerts: if IT detects 100 failed logins to one account, alert security. Log analysis: monthly review of logs for suspicious activity. Example: detect unauthorised access attempt on day 1, not month later.

RESPOND: Have Incident Plan:

When breach detected: immediate steps (isolate affected system, notify leadership), investigation (what was accessed? how?), communication (who needs to know? when?), remediation (fix the vulnerability). Without plan, response is chaotic.

RECOVER: Restore Services and Data:

After incident, restore from backup. Validate: is backup clean (not containing malware)? How long does recovery take? Test recovery quarterly; don't discover recovery is broken when you actually need it. Backup is insurance.

Apply During Transformation:

New system deployment? Security review required before go-live. Change IT tools? Verify new vendor's security practices. Don't sacrifice security for speed. Breach during transformation = transformation failure + legal liability.

ISO/IEC 27001 (Information Security Management System)

Category: Information Security

Process & Sequence:

Define Information Security Objectives:

Senior leadership commits: 'We protect confidentiality, integrity, availability of information.' Objectives guide all security decisions. Policies reflect commitment.

Perform Risk Assessment:

Identify threats: What could happen? Hacker accesses customer data. Insider steals IP. System fails. For each, assess: likelihood (rare/possible/likely) × impact (minor/severe/catastrophic). Highest risk gets priority controls.

Implement Access Controls:

Principle of least privilege: people access only what they need. Example: payroll clerk accesses payroll module, not finance module. New hire gets minimal access; access granted as needed. Offboarding immediately revokes access. Prevents insider threats.

Encrypt Sensitive Data:

Data at rest: customer databases encrypted with strong keys. Data in transit: HTTPS (secure web traffic), VPN (secure remote access). Example: if hacker steals database, data is encrypted gibberish without key. Encryption assumes worst-case.

Manage Supplier/Vendor Security:

If vendor holds your data, require: security audit, NDA, incident notification clause. Example: cloud provider certification, SLA with incident response time. Vendor breaches = your breach. Manage supplier risk.

Plan for Business Continuity:

If system fails or is breached, how do you recover? Backup strategy: daily backups, tested recovery, offsite copy. Failover: standby system if primary fails. RTO (Recovery Time Objective): 24 hours, 4 hours? Define and test. Don't assume recovery works until you test.

Conduct Internal Audits:

Quarterly: are we following security procedures? Are controls working? Example: audit finds 20% of staff use weak passwords despite policy. Corrective action: enforce multi-factor. Audits find gaps before hackers do.

Scaling Up (Verne Harnish)

Category: Growth & Execution

Process & Sequence:

Master the Four Decisions:

1) PEOPLE: Right people in right seats? Do roles match capabilities? Are there skill gaps? 2) STRATEGY: Is strategy clear? Do leaders agree? Is it differentiated? 3) EXECUTION: Is strategy executed? Are OKRs on track? Are blockers addressed? 4) CASH: Do we have cash? Runway? Growth-strains cash; plan for it.

Create One-Page Strategic Plan:

Annual: vision (3-year picture), 1-year priorities (3–5), quarterly Rocks (3–7 goals per 90 days), key metrics (dashboard of 10–15). One page forces clarity. If it doesn't fit one page, strategy is fuzzy.

Establish Functional Accountability Chart:

Visual org chart: CEO at top, then functional leaders (CFO, COO, CTO, etc.). One person accountable for each function. No shared accountability. During growth, unclear accountability = chaos.

Master Cash Conversion Cycle (CCC):

CCC = Days Inventory + Days Sales Outstanding (DSO) - Days Payable Outstanding (DPO). Example: inventory 30 days + DSO 45 days - DPO 30 days = 45-day CCC. Faster CCC = less working capital needed. Growth requires cash; optimise CCC.

Run Quarterly Business Reviews:

Quarterly: analyse past 90 days. Did Rocks get completed? Why/why not? Cashflow: are we profitable? Forecast: what's ahead? People: any issues? Reviews drive accountability. Written notes prevent 'I thought we decided X.'

Apply to Transformation:

Scaling Up ensures transformation doesn't just happen; it's executed. Rocks keep focus (3–5 priorities, not 15). One-page plan forces clarity. CCC management ensures cash doesn't run out mid-transformation. Scaling Up + change management = better outcomes.

Sandler Sales Methodology

Category: Sales Approach

Process & Sequence:

Establish Up-Front Contracts:

Before sales conversation: 'Here's the agenda: I'll ask questions (20 min), give brief overview (10 min), discuss next steps (10 min). OK?' Agreement on agenda = no surprises, efficient use of time. Respects prospect's time.

Discover Pain (Problem Interview):

Ask: 'Tell me about the last time you had issue X. What happened? How did you solve it?' Listen to problems. Don't pitch solutions yet. Understanding pain comes before selling. Example: 'We had payroll errors last month; took 2 days to fix.'

Reverse the Roles (Challenge Status Quo):

At end of conversation, flip: prospect asks about your solution; you ask: 'Before we discuss that, do you feel this problem is significant enough to address in next 90 days? What's holding you back from fixing it?' Reversal challenges prospect to commit. Weak yes = not real interest.

Avoid Free Consulting:

If prospect asks detailed questions ('How would you implement X?'), Sandler response: 'Great question; I'd love to explore that, but let's make sure we're both investing time wisely. If you see value, would you be open to exploring further?' Don't do work without commitment.

Qualify Hard:

Is prospect truly interested? Budget? Timeline? Authority to decide? Sandler rule: walk away from unqualified prospects. Time spent on prospects who won't buy = lost opportunity for real opportunities. Better to have 3 qualified prospects than 10 unqualified.

Apply to Change Adoption:

Like sales, change adoption requires: up-front contract ('Here's our transformation timeline'), understanding resistance (pain), reversing roles ('What's preventing you from adopting?'), avoiding endless discussions without commitment, qualifying stakeholder readiness ('Do you support this change?'). Same discipline applies.

Conclusion: Orchestrating Change

These 35 frameworks are not isolated tools; they are interconnected systems. A successful transformation typically uses 5–8 frameworks in concert:

  • Strategic frameworks (Porter's, PESTEL) identify WHY change is needed
  • Goal-setting frameworks (OKRs, EOS, Scaling Up) define WHAT to achieve
  • Change management frameworks (ADKAR, Kotter's 8-Step) guide HOW people adopt
  • Execution frameworks (Lean, Agile, McKinsey 7S) ensure work gets done
  • Performance frameworks (Balanced Scorecard, NPS) measure progress
  • People frameworks (9-Box, StaffEng) ensure right talent in right roles

Successful change requires discipline:

  • Choose frameworks that fit your context (industry, scale, culture)
  • Use frameworks to create structure, not to replace judgment
  • Adapt frameworks to your organisation; don't become framework slaves
  • Measure progress using frameworks; adjust when data shows drift
  • Reinforce adoption through consistent application and leadership modeling

... ...

Governance & Risk in Transformation

Transformation is inherently risky. Systems fail, people resist, markets shift, regulations change, vendors disappoint. Many transformations underestimate risk, proceeding as if change is inevitable and failure isn't possible. They're wrong.

Governance and risk management frameworks exist precisely because change is uncertain. They provide discipline to identify risks before they materialize, plan mitigation, monitor progress, and escalate issues early. They transform risk from 'something that happens to us' to 'something we manage proactively.'

This guide presents 20 governance and risk frameworks essential for change leadership. These frameworks address: enterprise risk (what could go wrong), internal controls (prevent/detect problems), compliance (meet regulations), resilience (survive disruptions), and stakeholder oversight (accountability).

Key Insight: Transformation fails not because risks exist, but because risks are ignored. These frameworks ensure risks are seen, understood, and managed.

GRC - Governance, Risk and Compliance Frameworks and Approaches

Section 1: Enterprise Risk Management

ISO 31000 (Risk Management)

Category: Enterprise Risk

Process & Sequence:

Define Risk Context:

Establish organisational context: what are we trying to achieve? Who are stakeholders? What are internal/external environments? During transformation, context is clear: 'Move to digital-first operations within 18 months.' Risk context = everything that could prevent this.

Identify Risks:

Brainstorm what could go wrong: technical risks (system outages, data loss), people risks (staff resistance, skill gaps), business risks (market shift, customer loss), external risks (regulation, competitor moves). Create risk register: list of identified risks.

Analyse Risk: Likelihood × Impact:

For each risk, assess: How likely (rare/possible/likely/almost certain)? What impact (negligible/minor/moderate/major/catastrophic)? Plot on risk matrix (low/medium/high). Example: staff resistance = possible × major = high risk. Data loss = rare × catastrophic = high risk.

Evaluate: Compare to Risk Tolerance:

Organisations have risk tolerance: 'We accept risk score <10; score >20 is unacceptable.' Evaluate identified risks against tolerance. Risks above tolerance require treatment (mitigation action). Risks below tolerance can be accepted.

Treat Risks: Avoidance, Mitigation, Transfer, Acceptance:

Avoidance: don't do the risky thing (cancel transformation). Mitigation: reduce risk (pilot before rollout). Transfer: insurance or outsource (buy cyber insurance). Accept: accept risk, plan response. Transformation = mitigation approach (reduce risk while pursuing change).

Monitor and Review:

Risk register is living document, not static. Monthly review: have identified risks materialised? New risks emerged? Risk scores changed? Example: if staff training completion is 90% (better than expected), staff resistance score drops. Adjust treatment plans.

COSO Internal Control Framework

Category: Internal Controls

Process & Sequence:

Control Environment (Tone at the Top):

Leadership sets tone: are controls important? Is integrity valued? Do people trust leadership? Weak control environment = controls ignored. Strong environment = culture of compliance. During transformation, tone is critical: 'We change processes, but control principles remain non-negotiable.'

Risk Assessment (Identify Risks to Objectives):

Define objectives: what should happen? (Transactions are accurate, assets are secure, reporting is reliable.) Identify risks to objectives. Example: objective = accurate payroll; risk = manual entry error; assessment = controls needed to prevent.

Control Activities (Preventive & Detective):

Preventive controls: stop bad thing before it happens. Example: segregation of duties (same person can't approve and pay). Detective controls: find bad thing after it happens. Example: reconciliation (find discrepancies). Both types needed; preventive preferred (prevent > detect).

Information & Communication:

System must communicate control requirements. Who owns each control? What's the procedure? Training needed? Documentation. Example: 'Approvers must verify invoice matches PO before payment. Procedure is in system with checklist.' Communication prevents 'I didn't know.'

Monitoring & Testing:

Evaluate whether controls are working. Sample test: review 30 transactions; were all approved? Were all documented? Did system enforce controls? Findings: 28 OK, 2 missing approvals = controls 93% effective. Remediate failed controls.

Apply During Transformation:

When redesigning process (e.g., digital approval), COSO ensures controls embedded. Example: old process = manual approval + filing. New process = digital approval with audit trail. Control = audit trail functionality must be present, tested before go-live. Don't remove controls; modernise them.

COSO Enterprise Risk Management (ERM)

Category: Enterprise Risk

Process & Sequence:

Governance and Culture:

Board sets risk appetite: 'We accept X% variance from plan, Y% chance of setback.' Leadership embeds risk thinking in culture. Question: 'What could go wrong?' is asked routinely. Risk is not taboo. During transformation, risk is explicitly acknowledged: 'This change has 20% probability of 3-month delay; we accept this risk.'

Strategy and Objective-Setting:

Strategies have inherent risks. Compare strategic options: 'Cloud migration risk = vendor dependency, migration complexity. Hybrid approach risk = ongoing integration cost.' Risk helps leaders choose strategy. 'We'll do phased cloud migration (lower risk) over 18 months, not big-bang (higher risk) in 6 months.'

Performance (Identify and Assess Risks):

As execution happens, risks emerge. Daily: 'Payroll vendor delayed system access; 1-week delay risk.' Weekly: 'Staff training is 20% behind plan; full adoption risk.' Assess: can we absorb delay? Or does this jeopardise whole transformation? Real-time risk awareness.

Review and Revision:

Quarterly executive review: are we seeing new risks? Have risk scores changed? Is our risk response working? Example: 'Regulatory risk we identified upfront hasn't materialised (guidance was delayed); score drops. But staff adoption risk has increased; score rises.' Adjust treatments.

Risk Appetite Statement:

Articulate: 'We pursue transformation because strategic benefit outweighs risks. We accept: 15% probability of 6-month delay, 10% probability of cost overrun, but will not accept: data breach or compliance violation.' Statement guides decisions when trade-offs arise.

Apply to Transformation:

ERM prevents 'we didn't see that coming.' Transformation has risks; ERM manages them systematically. Example: transformation leader can say, 'Yes, vendor dependency is a risk, and here's our mitigation plan (contractual SLA, backup vendor, rollback plan).'

Section 2: Risk Identification & Visibility

Three Lines of Defence

Category: Risk Governance

Process & Sequence:

First Line: Business Operations (Managers):

Front-line managers own control and risk in their process. Payroll manager: 'My team enters data accurately; we spot-check 10% of entries daily.' First line identifies risks, takes corrective action. Most controls are first line.

Second Line: Risk & Compliance (Central Functions):

Dedicated team monitors first line. Finance/Compliance/HR: 'We audit payroll monthly, check controls are working, assess new regulatory requirements.' Second line raises visibility to senior management. Example: 'First line payroll controls are working, but new tax law creates new risk; recommendation: update procedure.'

Third Line: Internal Audit (Independence):

Independent audit function audits first and second lines. Not operational; objective. Audit: 'We tested payroll controls; found 95% compliance, 2 control gaps. Second line is aware and has remediation plan.' Audit adds credibility.

Apply During Transformation:

Transformation creates control risk (new systems, processes, staff). Use three lines: (1st) business teams implement controls in new process, (2nd) compliance validates controls work during pilot, (3rd) audit certifies new process meets control standards before full rollout. Example: 'New cloud payroll system' → First line: input controls implemented; Second line: tested 100 transactions; Third line: audit confirms compliance. Go-live certified.

Escalation Protocol:

If risk is identified at any line, clear escalation: issue found at first line → second line → management → board if needed. Example: 'New system has data security gap' → immediate escalation, senior IT involvement, decision: delay go-live or accept risk.

Avoid Duplication:

Three lines can create overlap if not clear. Define: who owns what? First line does daily control. Second line audits first line, not repeats it. Third line audits both, not redoes controls. Clarity prevents waste and confusion.

Risk Register & Heat Maps

Category: Risk Visibility

Process & Sequence:

Identify and List All Risks:

Brainstorm all potential risks. Categories: technical, people, business, external, compliance. Document each: risk name, description, owner. Example: 'Staff adoption lag—risk that <50% of staff use new system after go-live. Owner: HR change lead.' Don't filter; list all.

Assess Likelihood and Impact:

For each risk, estimate: How likely on scale 1–5 (1=rare, 5=almost certain)? Impact on scale 1–5 (1=negligible, 5=catastrophic). Example: staff adoption lag = likelihood 3 (possible, not rare), impact 4 (reduces productivity). Score = likelihood × impact = 12.

Calculate Risk Score and Rank:

Risk scores 1–25. Rank: 20–25 = critical, 12–19 = high, 5–11 = medium, 1–4 = low. Example risk register: 5 critical risks, 8 high, 12 medium, 10 low. Total: 35 risks tracked.

Identify Risk Owner and Treatment:

Each risk has owner (responsible for monitoring and treatment). Treatment: avoidance (cancel activity), mitigation (reduce likelihood/impact), transfer (insurance), or acceptance (plan response). Example: staff adoption lag owner = HR change lead. Treatment = mitigation: pilot training, change management plan, post-launch support.

Create Heat Map (Visual Representation):

Matrix: x-axis = likelihood, y-axis = impact. Plot each risk as dot. Visual shows at-a-glance: most critical risks (upper right). Example: data breach = rare (low likelihood) but catastrophic (high impact) = upper left. Staff adoption lag = possible (medium) and high impact = middle-right. Heat map guides focus.

Update Monthly and Report Quarterly:

Risk register is living. Monthly: any new risks? Any risks materialised? Any scores changed? Document closure when risk passes. Quarterly executive report: summary of top risks, treatments in progress, emerging risks. Heat map shows trend: are we reducing risk over time?

Section 3: Resilience & Continuity

Business Continuity Management (BCM)

Category: Resilience

Process & Sequence:

Identify Critical Functions and Processes:

Which processes must keep running for business to function? Payroll: critical (affects all employees, compliance). Expense report: important but not critical (2-week delay acceptable). Analysis guides investment: critical = highest resilience spend.

Perform Business Impact Analysis (BIA):

For each critical process: what's the impact if it's down? Revenue loss? Compliance violation? Reputational damage? Timeline: how long can it be down? Payroll can't be down 1 day; customer service can be down 4 hours max. BIA defines Recovery Time Objective (RTO) and Recovery Point Objective (RPO).

Develop Contingency Plans (Disaster Recovery Plan):

If critical system fails, what's the backup? Cloud backup and failover? Alternate facility? Manual procedures? Example: payroll system down → switch to cloud backup (15 min recovery) or manual payroll run (3 day workaround). Document, test procedures.

Establish Communication Plan:

When disaster strikes, who communicates what to whom? CEOs and board need to know immediately. Customers need timely update. Staff need procedures. Plan: who (CEO, comms lead, IT manager), what (status, ETA), frequency (initial update 1 hour, then every 2 hours), channels (email, phone, website).

Test and Exercise Plans:

Don't wait for real disaster to discover plan is broken. Annual or bi-annual tests: simulate system failure, execute contingency, measure: can we recover? How long? Example test: 'Payroll system fails at 3 PM Friday; team activates manual payroll procedure; measure time to complete payroll by Sunday.' Results: success if Monday payroll runs on time.

Apply During Transformation:

Transformation creates continuity risk. New system failure = business impact. BCM ensures: new system has backup, recovery procedures documented, team trained, RTO/RPO met. Example: new cloud payroll deployed; backup cloud region spun up within 4 hours; tested quarterly. Transformation doesn't sacrifice resilience.

Crisis Management Framework

Category: Emergency Response

Process & Sequence:

Define Crisis Scenarios:

What could happen? System breach (data stolen). Major customer loss (revenue drop 20%). Senior leader departure (uncertainty). Regulatory fine (compliance violation). System failure (payroll late). List credible scenarios; don't catastrophise but don't under-estimate either.

Establish Crisis Leadership Team:

Pre-identify: CEO (decision lead), CFO (financial impact), CTO (tech issues), General Counsel (legal implications), HR (people/comms). Team assembled, briefed, ready to activate. Example: cyber breach occurs; crisis team meets within 2 hours, decisions made by 3 hours.

Create Decision-Making Protocol:

In crisis, speed matters. Authority: who decides what? CEO decides strategic response ('Do we disclose breach?'). CFO decides financial response ('Do we reserve funds?'). CTO decides technical response ('Isolate systems?'). Pre-defined authority prevents 'we don't know who decides.''

Prepare Communication Strategy:

Different messages to different audiences. Employees: 'Here's what happened, here's what we're doing, here's how it affects you.' Customers: 'Here's the impact on you, here's our action, here's timeline.' Regulators: 'Here's the fact, here's our root cause analysis, here's remediation.' Each message prepared in advance (template); customised when real crisis hits.

Establish External Support Resources:

Don't rely on internal capability alone. Relationships in advance: crisis PR firm (helps media comms), forensic investigator (breach investigation), legal counsel (regulatory response), business continuity vendor (facility backup). Relationships established before crisis; activated during.

Post-Crisis Review (After-Action Report):

Once crisis resolves, review: what happened? What did we do right? What failed? Root cause? How prevent recurrence? Document, share learnings. Example: breach post-action: 'We detected breach 48 hours after event; good. But comms were slow (3 days to customer notice); poor. Action: improve monitoring and shorten comms approval process.'

Section 4: Data & Information Security

Compliance Management Framework

Category: Regulatory

Process & Sequence:

Identify Applicable Regulations:

What rules apply to your business? Industry regulations (banking = capital requirements, healthcare = HIPAA), data protection (GDPR in EU, CCPA in California), employment law, tax law. Document comprehensively: don't miss a requirement.

Map Regulations to Processes:

Which process is affected by which rule? Payroll → employment law, tax law. Customer data → data protection. Financial reporting → accounting standards. Map forces clarity: if regulation changes, you know which process is affected.

Define Compliance Requirements:

For each regulation, translate to requirement. GDPR 'right to be forgotten' → requirement 'customer can request data deletion; IT deletes within 30 days.' Data deletion requirement → process: 1) customer submits request, 2) legal approves, 3) IT executes deletion, 4) IT confirms completion.

Implement Controls:

Embed controls in process to meet requirement. Example: data deletion. Control: deletion request goes to legal (prevents unauthorised deletion), deletion logged (proves it happened), confirmation email sent (documents completion). Controls ensure compliance.

Monitor Compliance:

Track: are controls working? Monthly: sample 10 data deletion requests; were all processed within 30 days? If 9 of 10 yes, compliance = 90%. If not 100%, investigate: why delay? Remediate.

Report to Regulators and Board:

Board/audit committee gets quarterly report: compliance status of top 10 regulations. Red/yellow/green status. Exceptions: any violations? Any close calls? Example: 'GDPR compliance status = green; no violations; 2 deletion requests delayed 5 days (root cause: approval process); remediation: legal approval SLA implemented.' Transparency builds confidence.

Apply During Transformation:

New process = new compliance risk. Example: moving to cloud payroll. Regulatory requirement = data protected in transit/at rest. Transformation: ensure cloud provider encrypts data, has audit cert, meets compliance. Compliance controls baked into new process from day 1, not added after.

Data Governance

Category: Data Management

Process & Sequence:

Define Data Ownership:

Who owns each data set? Finance owns GL data; HR owns employee data; Sales owns customer data. Owner is accountable: is data accurate? Secure? Compliant? Example: HR data owner ensures payroll data is correct (owner = payroll manager); employee directory is up-to-date (owner = HR systems manager).

Establish Data Quality Standards:

What does good data look like? Completeness: all required fields populated. Accuracy: matches reality. Consistency: same data, same format across systems. Timeliness: current. Standards = KPIs. Example: 'Customer email 99% complete, phone number 85% complete; action: improve phone capture at signup.'

Create Data Dictionary:

Document what each data field means. Employee ID = unique number assigned at hire. Start Date = first day of work (not offer date). Department = organisational unit. Dictionary prevents 'John said start date means X, Mary said it means Y.' Common understanding essential.

Implement Data Classification:

Classify by sensitivity: public (marketing materials), internal (employee directory), confidential (financial data), restricted (personal/health data). Classification determines protection: public = low security, restricted = high security (encryption, access limits, audit trail).

Establish Access Control:

Who can access what data? Payroll clerk accesses payroll data, not customer data. Customer service rep accesses customer data, not HR data. Principle of least privilege: access only what you need. Access documented, audited.

Define Data Retention and Disposal:

How long do we keep data? Payroll records: 7 years (tax requirement). Customer inquiry: 1 year (legal requirement). Logs: 90 days (audit requirement). After retention period, securely delete (don't just archive forever). Retention = legal requirement + cost (storage, security).

Apply During Transformation:

Moving to new system? Data governance says: migrate data matching classification, delete out-of-retention data before migration, assign new system data owners, validate data in new system matches quality standards. Example: migrating customer database to cloud. Pre-migration: delete old customer records (1 year inactive). During: encrypt in transit. Post: validate completeness/accuracy in cloud. Data governance ensures data integrity through change.

Vendor & Third-Party Risk Management

Category: External Risk

Process & Sequence:

Identify Critical Vendors:

Which vendors are essential? Cloud provider (data availability), payroll vendor (payroll can't be late), banking partner (payment processing). Loss of critical vendor = business impact. These need extra scrutiny.

Assess Vendor Risk:

Evaluate: financial stability (will they stay in business?), security (do they protect our data?), service quality (do they meet SLAs?), compliance (are they regulated?). Assessment helps identify risk. Example: 'Small payroll vendor has been on market 3 years; financial stability unclear; risk = medium. Action: require audited financials or switch to larger vendor.'

Define SLA and KPIs:

Service Level Agreement = contract specifying what vendor will deliver. Payroll SLA: 'Process payroll by 2 PM day X, 99.9% accuracy.' KPIs measured monthly. Example: if accuracy is 98%, vendor is underperforming; discuss corrective action.

Establish Oversight and Monitoring:

Don't trust and ignore. Monthly: review SLA metrics (are targets met?). Quarterly: business review with vendor (bigger picture: roadmap, issues, relationship). Annual: formal assessment (continue or find alternative?). Monitoring catches problems early.

Create Exit Plan:

What if vendor fails? Data portability: can we move our data to another vendor? Transition timeline: how long to switch? Example: 'If cloud provider fails, we have 30-day data export, then 60 days to migrate to alternative cloud.' Exit plan reduces switching cost.

Manage Vendor Changes:

Vendor contracts for 3 years; company changes in year 2 (acquisition, strategic shift). Does vendor contract allow adjustment? Pricing changes? Service changes? Vendor management = proactive renegotiation, not just acceptance of terms.

Apply During Transformation:

Selecting new vendor for transformation (e.g., cloud provider, consulting firm, software vendor). Third-party risk management ensures: vendor meets requirements, contract protects you, vendor meets SLAs during migration, exit plan exists if needed. Example: 'New payroll vendor needs to support 3-month parallel run (old + new systems both running) and rollback capability if go-live fails.' SLA built into contract.

Section 5: Vendor & Compliance Management

Project Risk Management

Category: Project Controls

Process & Sequence:

Identify Project-Specific Risks:

Transformation project risks: scope creep (requirements expand mid-project), resource constraints (not enough skilled people), technical complexity (underestimated), schedule pressure (forced deadline), budget overrun. Identify specific to your project.

Analyse Probability and Impact:

For each risk: How likely? How bad? Example: scope creep = likely (80%) and moderate impact (schedule slips 4 weeks) = high risk. Resource constraint = possible (50%) and high impact (project fails) = high risk. Analysis prioritises focus.

Plan Mitigation Strategies:

For high risks, define mitigation. Scope creep: change control process (no scope change without approval). Resource constraint: early hiring, external contractor, or descope. Technical complexity: proof of concept, risk reduction testing. Mitigation = reduce likelihood or impact.

Assign Risk Owner:

Each high risk has owner. Scope creep owner = product manager. Resource constraint owner = HR/resource manager. Owner monitors risk, escalates if it materialises. Example: 'Scope creep owner says 2 change requests pending; workload impact = 2 weeks. We'll prioritise; defer lower-priority features.'

Track During Execution:

Weekly project meeting: any new risks? Any risks materialised? Risk register updated. Example: 'Resource risk score changed from 50% to 70% (junior developer has health issue, less available). New mitigation: hire contractor to backfill.' Real-time tracking.

Report to Steering Committee:

Bi-weekly executive report: project status, top 5 risks, mitigations in progress. Red = critical risk (immediate action needed). Yellow = significant risk (monitoring). Green = manageable. Steering committee makes decisions when risk requires trade-off (e.g., extend timeline to reduce quality risk).

Apply to Transformation:

Transformation = large project; project risk management is critical. Example: digital transformation risks = technology integration (hard), staff adoption (unpredictable), vendor dependency (external), regulatory changes (external). Systematic risk identification, analysis, mitigation increases success probability.

Board Governance & Oversight

Category: Governance Structure

Process & Sequence:

Define Board Composition:

Board = mix of CEO (executive), independent directors (external), audit committee chair, risk committee chair. Mix brings different perspectives. Independent directors challenge management, hold leadership accountable. Diversity (industry, background, skill) = better governance.

Establish Board Committees:

Audit Committee: oversees financial reporting, internal controls, audit. Risk Committee: oversees enterprise risk management. Compensation Committee: oversees executive compensation, succession planning. Nomination Committee: oversees board composition, director evaluation. Committees divide labour, add expertise.

Define Board Responsibilities:

Board (not management) is accountable for: strategy approval, risk oversight, financial integrity, leadership evaluation, shareholder communication. Board doesn't run day-to-day operations (that's management); board sets direction and holds management accountable.

Establish Meeting Cadence and Information Needs:

Board meets quarterly or more often. Meetings include: financial review, risk report (top risks, any materialised?), strategy/transformation update, audit findings, compliance status. Information provided 1 week before meeting; board members prepare. Meetings are strategic, not reactive.

Board Evaluation:

Annually: board evaluates self. Questions: are we effective? Are committees functioning? Do we have right expertise? Are directors engaged? Self-assessment drives improvement. Example: 'We lack cyber expertise; action: recruit new independent director with CISO background.'

Apply During Transformation:

Board has stewardship responsibility for transformation. Board-level questions: is transformation strategically sound? Are risks managed? Is progress on track? What's the financial impact? Has leadership capability to deliver? Board doesn't manage transformation (that's management/PMO); board provides oversight and holds management accountable.

Regulatory Risk & Compliance Reporting

Category: Regulatory

Process & Sequence:

Identify Regulatory Bodies and Requirements:

Who regulates you? Tax authority (REVENUE), labor department (employment law), data protection authority (GDPR), industry regulator (banking/insurance). Each has requirements, reporting, audit rights. Comprehensive list avoids surprises.

Map Regulatory Requirements to Operations:

GDPR: data protection. Tax law: payroll withholding, reporting. Employment law: minimum wage, work hours, safety. Map shows: which process must meet which requirement? Example: payroll process must comply with 5 tax laws, 2 employment laws.

Establish Regulatory Reporting Calendar:

Monthly: tax withholding report. Quarterly: employment law report (workers compensation). Annually: tax return, audit. Calendar prevents 'we forgot deadline.' Responsible person assigned for each report.

Implement Quality Reviews Pre-Submission:

Before submitting tax return, financial report, or compliance filing: quality review. Who checks? Not the person who prepared; independent reviewer. Example: 'Tax return prepared by accountant A; reviewed by accountant B; issues found and corrected before submission.' Quality reduces errors, penalties, reputational damage.

Track Regulatory Feedback and Inspection Results:

Regulators send feedback: 'Your report was late,' 'You're missing data,' or 'Congratulations, compliant.' Inspection: 'We audit your records; we found 2 issues, require corrective action.' Log feedback, implement corrections.

Maintain Regulatory Documentation:

Keep records: submissions, correspondence, inspection reports, corrective actions. Documentation proves you tried to comply. Example: tax authority questions: 'Why did you claim this deduction?' You show: calculation, supporting docs, process. Documentation = defence.

Apply During Transformation:

New processes create compliance risk. Example: digital payroll system. Regulatory question: is data transmission secure (tax confidentiality)? Audit trail (employment law audit-ability)? Before go-live, regulatory check: does new system meet requirements? Certification: 'IT auditor confirms system meets tax law data handling requirements.'

Section 6: Fraud Prevention & Asset Protection

Fraud Risk Management

Category: Fraud Prevention

Process & Sequence:

Identify Fraud Risk:

What could be defrauded? Cash (embezzlement), inventory (theft), expense reimbursement (false claims), payroll (ghost employees), customer refunds (collusion). Identify vulnerabilities. Example: cash handling: two cashiers no oversight = risk.

Assess Fraud Risk Factors (Motive, Means, Opportunity):

Fraud triangle: Motive (person needs money), Means (person has skill), Opportunity (weak controls). Example: accounting clerk with access to bank transfers + financial stress (motive) + no approval control (opportunity) = fraud risk. Remove one factor (add approval control) = risk reduced.

Design Prevention Controls:

Segregation of duties: different people initiate, approve, reconcile. Example: requester ≠ approver ≠ payer. Exception review: transactions outside normal pattern flagged. Example: 'Wire transfers >$100k require CEO approval.' Physical security: safe, locked drawers. Controls are preventive.

Implement Detective Controls:

Find fraud if prevention fails. Bank reconciliation: does cash match records? Inventory count: does inventory match records? Surprise audits: unannounced check. Example: internal audit randomly tests 5% of expense reimbursements; checks receipts, validates business purpose.

Create Reporting Mechanisms:

Fraud hotline: anonymous way to report suspected fraud. Example: 'Employee suspects colleague is falsifying timesheets; calls hotline.' Investigation triggered, confidentiality protected. Hotline encourages reporting; prevents cover-ups.

Investigate and Report:

If fraud suspected: investigation launched (evidence gathering, interviews, written statement). If confirmed: police report, employee termination, management notification. Board informed of significant fraud. Post-incident: process review (how did this happen?), control improvement.

Apply During Transformation:

Change = opportunity for fraud if not managed. Example: moving to new system, old system decommissioned. Fraud risk: insider steals data during migration (opportunity). Prevention: segregate access during migration (different team), audit migration, validate data completeness. Transformation requires enhanced fraud controls, not reduced.

Information Security Risk Management

Category: Cybersecurity

Process & Sequence:

Identify Security Assets and Threats:

Assets: customer data, IP, financial data, employee data. Threats: hackers (external), insiders (employee theft/sabotage), malware (viruses/ransomware), physical theft (laptop theft). Comprehensive threat list = foundation.

Assess Likelihood and Impact:

Likelihood: how probable is breach? Impact: if breach happens, what's the damage (data exposed, revenue loss, reputation, regulatory fine)? Example: ransomware attack likelihood = high (many happening), impact = catastrophic (operations down, demand payment). High risk = top priority.

Implement Technical Controls:

Firewalls: block unauthorised access. Encryption: protect data if stolen. Intrusion detection: monitor for attacks. Backup: recovery from ransomware. Patch management: fix vulnerabilities. Technical controls reduce attack surface.

Implement Operational Controls:

Strong passwords (enforced complexity, change regularly). Multi-factor authentication (password + code). Security training (don't click phishing). Incident response plan (what to do if hacked). Vendor security checks (do partners protect our data). Operational = people + process.

Monitor and Detect:

Security monitoring: logs reviewed daily for suspicious activity. Intrusion detection: system detects attacks in progress. Incident detection: how fast from breach to discovery? Target: detect breach within 24 hours, not months. Speed matters; every day exposed = more damage.

Incident Response:

When breach detected: isolate affected systems (stop spread), investigate (what was accessed?), notify leadership, plan remediation, notify customers/regulators if required. Incident plan pre-established; activated when needed. Example: 'Hacker accessed customer data; ISO isolates systems within 2 hours; investigation in progress; customer notification ready if needed.'

Apply During Transformation:

New systems = new security risks. Cloud migration: data in cloud, not on-prem; is cloud provider secure? API integration: new integration points, new vulnerabilities. Transformation security includes: pre-deployment security assessment, penetration testing (attempt to hack before launch), security training for new system, incident response plan for new system.

Section 7: External Risk

Privacy Risk & Data Protection Compliance

Category: Privacy

Process & Sequence:

Understand Privacy Regulations:

GDPR (EU): individuals own their data, right to access, delete, portability. CCPA (California): similar rights. HIPAA (US healthcare): patient privacy. Each has requirements, consent rules, breach notification. Know what applies to you.

Map Personal Data Flows:

Where does personal data come from? (Customer signup, HR hire). Where is it stored? (Database, files). Who accesses it? (Support team, HR). Where does it go? (Reports, vendors). Flow map shows: what controls needed, where's risk?

Establish Data Processing Agreements:

If vendor processes data (cloud provider, payroll vendor): written contract specifying data use. Example: 'Cloud provider will process payroll data only per our instructions, will not share with third parties, will delete on request.' DPA protects both parties.

Implement Privacy Controls:

Consent: have we asked permission to use data? Notice: tell people how we'll use data (privacy policy). Encryption: protect data. Minimisation: collect only needed data (don't collect extra). Purpose limitation: use for stated purpose only. Controls = data protection.

Fulfil Privacy Rights:

Right to access: person asks 'what data do you have on me?'; respond in 30 days with data copy. Right to delete: person asks 'delete my data'; delete (with exceptions). Right to portability: person asks 'give me my data in format I can transfer'; provide. Rights = legally required.

Handle Breaches:

Data breach (unauthorised access): notify within timeframe (GDPR = 72 hours). Determine: what data? How many people? What's the risk? Notification includes: what happened, what we're doing, steps they should take. Lack of transparency = larger fines.

Apply During Transformation:

New system handling customer data? Privacy assessment required. Example: 'New CRM will store customer phone, email, purchase history. Privacy check: does CRM consent management work (we can track consent)? Encryption? Deletion capability? Pre-launch: privacy assessment confirms system meets GDPR, CCPA. Transformation doesn't sacrifice privacy.

Supply Chain Risk Management

Category: Operational Risk

Process & Sequence:

Map Supply Chain:

What do we rely on? Materials (raw materials for production), logistics (vendors to deliver), labour (staffing agencies), utilities (power, water). Map each: source (single vs multiple), dependency (how critical?), alternatives (what if they fail?).

Identify Critical Suppliers:

Which few suppliers would jeopardise business if they fail? Single-source suppliers = high risk. Sole manufacturer of key component = critical. Focus assessment here.

Assess Supplier Risk:

Financial stability: will they stay in business? Capacity: can they scale if we grow? Compliance: do they meet standards (quality, safety, labor)? Geographic risk: are they in stable country? Assessment identifies vulnerabilities.

Develop Supplier Diversity:

Don't rely on one supplier. Multi-source: two suppliers per critical item. Risk = if one fails, alternate takes over. Cost: slightly higher (diversity premium). Benefit: resilience (no single point of failure).

Establish Supplier Agreements:

Contract specifies: delivery terms, quality standards, compliance, contingency (what if disaster?). Example: 'Supplier will deliver by day 10; if late, $1k/day penalty; if 5 days late, we can source elsewhere without penalty.' Terms align incentives.

Monitor Supplier Performance:

On-time delivery rate, quality (defects), compliance (audits), responsiveness. Monthly review: are they performing? If not, corrective action plan. Annual: strategic review (continue or find alternative?).

Build Supplier Partnerships:

Don't treat suppliers as vendors; treat as partners. Regular communication, share forecasts (they plan capacity), listen to their concerns (cost pressures), collaborate on improvements. Strong partnerships = better resilience, innovation.

Apply During Transformation:

Outsourcing or new vendor relationship (e.g., outsource HR to vendor). Supply chain risk: vendor fails, transformation stalls. Mitigation: multi-year SLA, penalty clauses, contingency plan (backup vendor), periodic audits. Transformation dependent on vendors = vendor risk critical.

Section 8: Stakeholder & Emerging Risk

Insurance Risk Transfer

Category: Risk Transfer

Process & Sequence:

Identify Insurable Risks:

What risks can insurance transfer? Property damage (building, equipment), liability (sued by customer), cyber (data breach, ransomware), business interruption (revenue loss if operations down), key person (death/incapacity of critical leader). Insurance can't transfer all risks (fraud, poor strategy); transfers financial risks.

Assess Insurance Needs:

What's the financial impact if risk materialises? Building fire: rebuild cost $5M? Cyber breach: notification cost + fines + reputation = $10M? Key person dies: how long to replace, cost? Assessment determines insurance amount (coverage limit).

Evaluate Insurance Options:

Insurer: buy from reputable insurer (financial strength = they'll pay when needed). Policy terms: premiums, deductibles (you pay first $100k; insurer pays rest), coverage limits, exclusions. Shop options: different insurers, different terms, different prices.

Define Retention and Coverage:

Retention = risk you keep (deductible). Example: $100k deductible = you absorb first $100k; insurer covers beyond. Higher deductible = lower premium but higher your risk. Balance: low deductible = high cost; high deductible = more financial exposure.

Manage Claims:

If loss occurs (fire, lawsuit, cyber attack): notify insurer quickly. Provide documentation (proof of loss, receipts). Insurer investigates (is loss covered per policy?). If approved: reimbursement. If denied: dispute (may go to court). Claims process = critical.

Review and Adjust Annually:

Insurance needs change with business. Expansion = higher asset values = need more coverage. New risk (cyber) = need cyber insurance. Annual review: coverage adequate? Premiums competitive? Claims experience? Adjust as needed.

Apply During Transformation:

Transformation creates new risks: system outage (business interruption insurance), cyber attack (cyber insurance), key person (transformation lead) leaves. Insurance can transfer some risks (financial impact if system fails), not all (reputational damage if failed transformation). Insurance + mitigation = risk management.

Environmental, Social, Governance (ESG) Risk

Category: ESG

Process & Sequence:

Environmental Risk:

What environmental risks affect business? Climate change (supply chain disruption, physical asset risk), carbon regulations (cost of emissions), resource scarcity (water, minerals). Example: manufacturer: droughts in key supply region = raw material shortage. Action: diversify suppliers, invest in water efficiency.

Social Risk:

Reputation risk, employee risk, community risk. Example: poor labor practices = brand damage, recruitment difficulty. Actions: ensure fair wages, safe conditions, ethical supplier sourcing. Employee wellbeing: burnout during transformation? Action: change management, support services.

Governance Risk:

Board composition, executive compensation, shareholder rights, conflict of interest. Example: CEO compensation too high relative to performance = shareholder backlash. Action: align CEO pay to performance, be transparent.

Measure ESG Performance:

Track metrics: carbon emissions (environmental), employee retention (social), board diversity (governance). Benchmark: are we better/worse than peers? Report externally: stakeholders care about ESG. Example: 'ESG report: carbon down 10%, women in leadership increased to 30%, board now 50% independent directors.'

Integrate ESG into Strategy:

ESG is not compliance checkbox; it's business strategy. Example: sustainability goal (carbon neutral by 2030) = shapes investment, operations, supplier choices. ESG focus = attracts talent, customers, investors.

Apply During Transformation:

Transformation should improve ESG: moving to cloud = lower carbon (vs on-prem data centre). Automating processes = fewer errors = better quality = better customer outcomes = social benefit. Digital-first = less paper = environmental benefit. Intentional ESG during transformation = value creation.

Geopolitical & Macroeconomic Risk

Category: External Risk

Process & Sequence:

Monitor Geopolitical Developments:

What's happening globally that affects business? Trade tensions (tariffs), sanctions (restricted markets), conflicts (supply chain disruption), political instability (uncertain rules). Example: reliant on Chinese suppliers + escalating US-China tensions = supply chain risk.

Assess Macroeconomic Trends:

Interest rates rising = borrowing costs up; recession = demand down. Inflation = cost pressures. Currency fluctuation = import/export pricing impact. Example: European company exporting to UK: GBP/EUR weakness = UK products less price-competitive.

Develop Scenario Planning:

Plan for multiple futures: optimistic (growth), base (current path), pessimistic (recession). For each, what happens to business? Example: recession scenario → customer demand down 20% → cost reduction plan, cash preservation. Scenarios prepare leadership for contingencies.

Diversify Geographic and Market Risk:

Don't depend on one country, one customer, one market. Expansion to new geographies, new customer segments, new markets = portfolio approach. Example: reliant on US customer base during US recession. Action: expand to EU, Asia. Diversification hedges risk.

Build Financial Resilience:

Strong balance sheet: low debt, cash reserves. Why? When crisis hits (recession, supply chain shock), cash gives you staying power. Companies with cash survive; companies reliant on credit fail when credit dries up.

Apply During Transformation:

Transformation requires investment during uncertain times. Board question: can we afford this if recession hits? Plan: lower-cost transformation (cloud vs on-prem), shorter timeline (get ROI before recession), phased approach (stop if economics deteriorate). Macro risk shapes transformation approach.

Conclusion: Risk Management as Competitive Advantage

Organisations often view governance and risk management as cost (compliance burden, bureaucracy). But transformed organisations see it differently: risk management as competitive advantage.

Why? Because transformation undertaken without risk discipline fails. Transformation undertaken with risk discipline succeeds. The difference is systematic thinking.

How These Frameworks Interlock:

  • ISO 31000 identifies what could go wrong (risks)
  • COSO Internal Control embeds safeguards into processes
  • Three Lines of Defence layers oversight (management, compliance, audit)
  • Risk Register makes risks visible and tracked
  • Business Continuity ensures organisation survives when risks materialise
  • Project Risk Management keeps transformation on track despite obstacles
  • Board Governance holds leadership accountable for risk management
  • Emerging Risk Monitoring scans horizon for future threats

During Transformation, Apply These Principles:

  • Identify risks explicitly (don't assume 'it will work')
  • Assess likelihood and impact (which risks matter most?)
  • Plan mitigation (for high risks, what's your backup plan?)
  • Assign ownership (who watches each risk?)
  • Monitor continuously (early detection = faster correction)
  • Report transparently (stakeholders need to know status)
  • Escalate quickly (don't hide problems)
  • Learn from incidents (if something goes wrong, improve process)

The organisations that manage transformation successfully aren't the ones that planned perfectly; they're the ones that managed risk intelligently. These frameworks are the tools for intelligent risk management.

....

Change is sometimes uncomfortable, more so when unsupported, unstructured or unplanned. Frameworks make discomfort more navigable by providing clarity, reducing ambiguity, and creating a roadmap and accountability. Find out more - click here