Tuesday, December 10, 2019

California Consumer Protection Act and Data Governance Initiation Steps


California has the largest economy of any US State. In fact, if it were its own nation, it would be the fifth largest economy in the world with a GDP of $2.9 trillion Forbes (2018). It's quite obvious then, any new regulations and rules passed by the State with its 40 million population would certainly have a noticeable impact to many Organizations who serve its residents.

California Consumer Privacy Act is one such regulation that will go into effect on Jan 1, 2020 to protects its residents of their Privacy and Protection rights. My attempt here is to elucidate the need to build an effective Data Governance Framework not just to meet regulatory compliance requirements but also to effectively manage the burgeoning of data ingestion's with effective Business Processes, Controls, Fit for Purpose of the data sets in Analytics & Reporting thus increasing the trust factor coupled with reduction in Cost.

CCPA
Californian residents will have following rights from Jan 1, 2020 under CCPA
  • Know what personal information is collected about them for the prior 12 months by Organizations 
  • Know whether their personal information is sold or shared for a business purpose and to whom for the prior 12 months 
  • Access their personal information, with limited rights to delete or opt-out of sales 
  • Equal service and price even if they exercise their privacy rights

Comply
Any Organization which meets any of the following criteria needs to comply with CCPA
  • Any Organization whose Annual revenue is in excess of $25M 
  • Obtains data of 50K of Californian residents annually 
  • Derives over 50% of revenue from selling California residents personal data

PIA Impact Study
Every Organization dealing with Californians residents’ information can potentially perform a Privacy Impact Assessment (PIA) by answering the following key questions.
  • Is the Customer information storage dispersed and # of copies exists with its own flavors?
  • Who all have access and Is there some level access controls with audit on their usage with PI attributes contextually anonymized?
  • What are the legal or compliance business processes that surround the PI information and its data sharing agreements Internally and Externally?
  • Are there policies built around Business context as well the Legal context for usage of Customer PI information?
  • Is there a tribal knowledge among the various Departments and its line of business that needs to be articulated, standardize and documented?
  • Are there Data Stewards or Owners who manage and identify PI attributes with knowledge of risk remediation steps to be taken for any breaches?
PIA study will enable Organizations to built Use Cases which can then be prioritized. Executive Sponsorship and Support is very crucial as this initiative endeavors cross functional communications with different groups and often is a Journey rather a Sprint.

Checklists
Preparing a checklist could be taken as the next step to capture the requirement details from identified Department Stakeholders and Data Stewards
  • Controller Checklist to assess Lawfulness, Fairness and Transparency of individual rights, data security, data transfers and data breaches
  • Processors Checklist includes documentation, accountability as well approach to individual rights on the Processors side
  • Information Security Checklists includes how businesses handles management and Organizational Information Security
  • Direct Marketing and Records Management Checklists
  • Data Sharing and Subject Access Checklists
  • CCTV Checklist on Close Circuit Television and Internal Cameras installed and its impact on privacy of Employees & Customers

Data Protection Impact Assessment (DPIA)
Start small and identify business lineage of importance to the Organization based on the checklist findings of relevant Use Cases. One may also utilize templates provided by tool vendors like Collibra Data Governance Center, IBM InfoSphere Information Data Governance, SAP Master Data Governance to document your Processes and Workflows
  • Conduct Risk Assessment to check and assess the maturity of risk management framework with any predefined workflows 
  • Identify and validate if the Processors of Individuals data rights are in alignment with the CCPA
  • Identify Remediation Plans to control or identify reduction in steps of risk severity aspects for any breaches with accountability to boot
  • Validate if there is a built-in sufficiency mechanism of technical and Organizational measures to help assess threshold scores
  • Identify Sharing risks of data with external party and its remediation actions

Non-Compliance of CCPA
The major risk for any Organization for any breach is the loss of Trust and its Reputation impacting its growth more than monetary fines as indicated in the CCPA
  • The following are monetary fines laid out in the CCPA
  • $100 - $750 per consumer per incident or actual damages whichever is greater 
  • If Organizations fail to cure any alleged violations within 30 days the following fines are enforced
    • 2,500 in civil penalties for each violation
    • 7,500 for each intentional violation
Residents Consent and Rights
Organizations do not need a consent from data subjects to use their data. However, safeguards and provisions need to be in place besides provisions for the subjects to implement any Right to Erasure or Right to be Forgotten provisions. Although there are some exemptions, but these depend on case to case basis and certainly does not provide any business with carte blanche to keep or use Customer information.

Finally, there are already many such Regulatory & Compliance Laws in place including New York Cyber Security Regulations, GDPR for European Countries, PIPEDA in Canada, China’s Cyber Security Law and potentially many more are in the horizon. As a result many Organizations are in already in some pipeline of building a robust Data Governance over its Data Assets with Process & Access Controls with ample Risk mediation actions.

Wednesday, November 20, 2019

Data Governance Framework Maturity


According to the 2019 State of Data Management Report from 863 participants across Globe by Profisee, Data Governance is one of the top 5 Strategic initiatives in 2019. Advance trends in Machine Learning and AI has bolstered the digital transformation initiatives globally along with availability of full fledge DG (Data Governance) platform products like Collibra DG, Erwin DG, Informatica DG, SAP Master Data Governance and others have accelerated its adoption.

One must evaluate these platforms as they differ in terms of its features and its capabilities like the ability in providing Native Connectors, API’s and Webhooks to synch data with various Applications and thus enabling to build workflows to automate data rather than manually synch them up. Some platforms also provide Cloud and/or Server options and while some provide Hybrid Option with Secured Gateways.

Recent high-profile incidents at Facebook and loss of Customer data at regular intervals from high profile Organizations has also brought back Data Governance and Security into the front pages and into limelight with the Executives. Secondly, most Enterprises have realized that by maturing Data Governance, one could measurably benefit from Quality, Transparency and Trust in their Reports, Measures & KPI’s and thus improvement in the bottom line.

Maturity
An Organization can be grouped into any one of the 6 different maturity levels from an Immature to Sophisticated Maturity Levels and this can easily be validated by conducting an internal Survey and Assessment of their current State.

Instead of boiling the Ocean, Organizations can identify the Business Verticals of importance in their EIM Model along with its domains with a prioritization schedule. The most important requirement for a successful Data Governance engagement is to get an Executive Support all the way in its implementation.

Building a smaller yet nimble Organizational structure with clarity on Collaboration, Engagement, Transparency & Responsibility of efforts among various stakeholders, Data stewards is a prerequisite for an effective engagement.

Conducting roadshows on Success Stories to build more Successful ones, does keep the foresight needle straight with gusto as the Journey being bit long towards reaching its Zenith phase along the Data Governance Maturity Curve.

Drivers
Here some key major data points that can be used to evaluate DG Maturity level Curve in an Organization. (If you agree on 5 or more data points, your Organization may be a good candidate to mature its Data Governance Framework)
  1. Lack of Trust in Critical and Significant Enterprise Reports
  2. Lack of Data Lineage of Reports to Models and Reports
  3. Lack of Transparency and Agreement to Measures and Metrics in Business and Cross Domains
  4. Lack of Data Stewardship, Ownership of Line of Business Data Assets
  5. Lack of identifying Redundant Reports and its Usage
  6. Lack of Role Based Access Control to PII Data
  7. Lack of Data Catalog & Business Glossary, MDM and Reference Data
  8. Lack of Data Quality Scores on Data Sets
  9. Lack of Ability to Tag Data Informational Tags by Users and Viewers to Organize its Usage
  10. Lack of Issue Stewardship & Resolution documentation process for repeat data issues

Conclusion


Organizations are maturing their Data Governance environment in their current ecosystem including Data Lakes in building and streamlining Data Governance Principles, Policies & Standards to Curate and build Conformed layer for Fit to Purpose of Enterprise Data Assets to enhance its high degree of Value and Trust for Self-Serve of Data by its Data Citizens.

Saturday, August 3, 2019

RPA Robots in Digital Transformation


Software Robots mimics human interactions not just Mouse Clicks, Key board Navigation's, Application Logins with Web, Desktop application but much more are often called Bots that are programmed to do repetitive or sequential tasks of Workplace Business Process Operations 24/7.

These Bots are not only cost effective and time enabler but support many of the Organizations digital transformation initiatives to achieve profitability and remain competitive. Global spending according to Gartner will pace a total of $2.4 billion by 2022 and nearly 85% of large and very large organizations will have deployed some form of RPA.

The biggest early adopters included Banks, Insurance companies, Utilities, Telecommunications and Transportation companies. Moreover any Industry's Workplace Business Operation which knits its Business Processes with different applications and platforms, or work involves mundane tasks performed manually are excellent candidates for RPA.

The ever growing adaptation of RPA by Industry is on account of its Low Code/No Code features with Drag and Drop features using robust framework and thousands of Library of Functions for Task Events while facilitation Monitoring & Scheduling thousands of Bots from a Control Room. 

Compare this with all the nine yards involved in Coding efforts which requires extensive Business Process requirements gathering and spending enormous time in search for highly skilled developers to build Robust, Modular and Scalable solutions.

Today’s Bots are easily built using Robotics Process Automation (RPA) tools offered by different vendors to support and improve accuracy and efficiency by automating repetitive tasks using Desktop Applications, Custom and Native application seamlessly. Some products also have Cognitive supportive capabilities like Machine Learning and AI with various degrees of maturity. 

RPA is now a new branch of IT Specialization area in the World of Automation euphoria and that is here to stay and is maturing very fast to meet demanding Business Workplace Process needs. 

Selecting an RPA Vendor tool from among the current offerings, one needs to focus on its features that are already build and its ease in building & deploying Bots along with support for its Maintenance, Monitoring, Scheduling and Reporting. One of my common thumb rules as well a proven one is to favor products which have Open Community Support with larger base that potentially would have well rounded features coming from the ground zero and also would have higher staying power in this fast-newer emerging technology.

An RPA tool should also have support for multiple platforms like Windows and Linux which are common workplace OS platforms to support various Desktop applications such as MS Office and Google G Suite. 

Many medium to large Organizations have either a large Offshore/Onsite support folks for their Business Process activities and hence any RPA product should also fully support VDI infrastructure products such as Citrix, Amazon WorkSpaces, IBM Cloud, VMware Horizon Cloud and other major VDI products.

RPA Bots Utilization
RPA Robots are game changers that can automate and perform very large repetitive transactions in simple or complex Organizational Business Operational processes. Robots can also be built to automate and streamline complex business interactions by integrating various operational tasks with multiple applications systems and channels. 

Here are some simple to complex RPA activities that can be automated   
  1. Opening user emails to download specific attachments into a network folder
  2. Moving files from a source directory/folder to another target source including from and/to FTP server
  3.  Logging into ERP or Native or Web applications and updating specific forms using data from files including CSV
  4.  Scrapping data from Websites to extract selective data such as Stock or Ticker Prices or in its entirety data sets
  5. Scanning PDF including support for OCR to convert them into text or hand written documents
  6. Selecting specific fields from Contract documents using AI based pattern matching
  7. Connecting to ODBC, JDBC supported Databases like Oracle, SQL Server to perform CRUD Operations
  8. Streamlining and supporting seamlessly major and key Business Operations by building workflows across multiple native custom applications using virtual user concept in the absence of API’s

Some key Industry Use Cases
  1. Data Intensive Operation Companies that Extract & Capture data by Scrapping the Web sites and converting data from different media types & formats including PDF with OCR requirements
  2.  Finance Organizations benefiting by accelerating their Mortgage Processing, Fraud Analysis tasks, Configuring and building business rules for Loan Origination, Automating tedious tasks like Bank Reconciliation reporting from different applications
  3. Facilitating faster Clinical trials and drug approvals oversight of Pharmacovigilance (PV) cases by reducing errors and enhanced compliance in a reduced process cycle time
  4. Automating Transportation and Logistical & Business Operations, Shipment Scheduling & Tracking by collating data and building Workflows thus increasing efficiencies and reducing costs
  5. Retail industry integrating their Invoice Processing and Credit Collections to streamline End to End Order-to-cash processes
  6. Telecommunication industry many manual repetitive rules-based processes
  7. Utilities Industry's highly traditional regulation driven marketplace rule driven process
  8. Lastly any Organization whose Business process are Rule based driven and are manual or Process interweaves through manual extraction of data data from many Native or Custom Applications including Web with tedious tasks can be automated using RPA Bots
Major RPA frameworks have fully functional GUI studios to build Robots using Drag and Drop features with enriched library in much shorter time window with Low Code No Code development efforts. One could also build Self learning Intelligent Robots that learn from repeatable actions using ML & AI features.

Saturday, July 27, 2019

IT Automation Implementation- Data Points


In today’s world, the word Automation conjures lot of confusion as well scares many workers as a disruptive technology that aims to eliminate ones jobs. The fact is its going to redefine the roles and process of their job functions rather than targeting them towards its elimination.

There is an interesting article by McKinsey's "Four Fundamentals of Workplace Automation" which states ALL jobs are bound to be impacted with various degrees of process automation at workplace from a CEO to Clerical Jobs.

Because of its negative bias opinion, Organizations need to tread cautiously and comfort its workers that an IT Automation effort is not aimed at individuals rather than redefining their tasks and activities that they perform in reducing and automating mundane ones.

To implement any automation of Business Operations, we should first rationalize its Operations in its entirety and identify and remove/modify redundant and inefficient process steps rather than simply build automation scripts on the top of its Standard Operation Procedures (SOP). It is not enough just to replace human interactive operational steps which is frown with many exceptions coupled with lack of standard documentation and thus difficult to program and handle.

Efforts spent on understanding and streamlining the business processes will certainly help not only to avoid costly and redundant operations but also enables to build manageable building blocks like Lego blocks.

Also, any initiative if not properly thought through, can spiral into chaos, business disruptions, cost and worst frowned upon by employees with distrust resulting in higher attrition. Needless to say any unplanned automation without Goals & Objectives and proper identifiable measures and with right skills and tools is fumbling at the starting block.

IT Automation Implementation - Data Points
Here is my small attempt to identify some data points that could help Automation stakeholders and managers to help them place the right foot forward and avoid costly mistakes where they don’t have experienced Automation Czars or Evangelists to help them implement and navigate.
  • Define Automation Journey with Strategies
    • Identify Pressure points that are currently dragging productivity
    • Identify Challenges and potential bottlenecks for improvement
  • Get the biggest payback
    • Identify low lying fruits with its value
    • Do not try to automate every part of the Process at one GO
  • Validate Automation feasibility
    • Build POC’s as required and build and identify necessary steps to scale
    • Identify Complexities and time required to execute them while keeping a shorter window of weeks rather than months and years
  • Identify building blocks & framework for readiness in Automation
    • Rationalize and fine tune bulky or miniaturize monolith process steps
    • Build automation capabilities with skills & tools to manage the new Business Outlook Operating Business Model
  • Identify meaningful test with regression tests and recovery strategies
    • Identify and avoid any business disruptions as these can be costly
    • Group similar automation initiatives under automation Evangelists & Stewards
  • Identify feasibility of Automation within Product's platform
    • Identify Time based workflows, Trigger or Event based automation within the Platform, Application
    • Build with minimal wiring from external Software agents to trigger Automation work rules or notifications
  • Design & Build Automation efforts that are sustainable, maintainable & repeatable
    • Build manageable process steps with proper exception handlers
    • Build process steps that are configurable with external inputs and can be executed in parallel
  • Define Operating Model and Governance along with Goals
    • Raise awareness, get an alignment with folks impacted with Automation and address any negative and unfounded assumptions
    • Rationalize initiatives and identify Growth or Process improvement Opportunities and identify factors with measurable units towards Goals
Automation is a Journey and not a 100 meter dash and hence measure them at regular interval its benefits. Also, as McKinsey article indicates, Automation is not all about targeting low-wage roles but all ladders of workplace jobs including the highest paid occupations in the Organization.

Friday, March 23, 2018

Consortium Blockchain a Right Step


Blockchain is a very disruptive technology and if industries do not keep in pace both in terms of its understanding and impact, experimentation and adaptation with changing ecosystem could potentially lead its enterprise leader's fear of missing out (fomo) psyche becoming a reality as it did for brick & mortar companies when they missed the opportunities with the advent of Internet in the early 90’s.

Today, to be on the safer side many enterprises are forming or joining the Consortium and testing their feet not to be left out. Global financial companies lead the way followed by Cross Sector and Life Sciences & health care enterprises.

The significance and ripple effect of Bitcoin Cryptocurrency tsunami which is based on Blockchain made Industry leaders to pay attention bit more closely to its underlying technologies. Blockchain technology is not new, but how the Distributed paradigm of hardware (nodes) including the Distributed Ledger Technology (DLT) has been leveraged coupled with removing the fear of security on identity and the need for an intermediary of controller’s oversight to validate the truth of the transactions.

Smart Contracts implementation on the blockchain with a semi-trust control on transactions validity with heighted identity security by different niche platforms like Ethereum Consotium, Hyperledger Fabric Consortium (from Linux foundation), R3’s Corda, Quorum, Chain Core made it much more enticing for the industry leaders. Not to be outdone, major Cloud vendors including IBM, Microsoft, AWS made these platforms available on their portals along with development toolsets to build and deploy enterprise based applications.

Consortium Blockchain features
1.       Platforms support Privacy and Confidentiality for all the participants in the network
·         It is built on trust where participants know that all of their transactions can be traced
·         All network participants identities are backed with cryptographic certificates that are tied to its Organizations, network components and end users or client applications
·         Blockchain supports all business exchange of assets of tangible (Cars, Whole foods) to intangible ones like Futures, Intellectual properties etc
·         Only known participants can participate in the transactions thus it is private and permissioned system
2.       Distributed Ledger records transactions are built in a decentralized and collaborative way
·         Transactions Assets are defined using a collection of key value pairs (JSON) with digital signatures of every endorsing peer node with values that can be encrypted
·         Ledger is a sequenced, tamper-resistant record of all state transactions chained together in blockchain with one ledger per channel and making it immutable
·         Each participant will have their own replicated copy of the ledger besides being shared with its participants
·         There is a single place of Origin for all transactions in the blockchain to provide provenance for the transactions
3.       The ledger functions and control are implement using Smart Contracts to automate and execute mutually agreed upon by the participants
·         Privacy is key for B2B model and this is implemented using Smart Contracts and Channels
·         Smart contracts are written in chaincode which enforces the business logic in defining assets and transactional logic
·         Channel’s ledger contains a configuration block defining policies, ACL and other pertinent information
·         Major programming languages like C++, GO, Java, JavaScript are used to program the chaincode
4.       A process called Consensus is used to commit the transactions only on approval by the appropriate participants
·         Consensus allows for transactions to be synchronization across network thru this process with shared data ledgers as well shared programs that update them
·         Transactions are written in the order in which they occur in this consensus process to avoid any malicious entries
·         Transactions are committed only when the block’s transactions have met the explicit policy criteria checks and balances dictated by the members and endorsed, validated and versioned checked

·         Consensus mechanism utilizes different technology messaging brokers like SOLO, Kafka, Simplified Byzantine Fault Tolerance (SBFT)

Use Cases
There are many uses that are identified in various industries including Capital Markets, Financial Services, Healthcare, Government Legal/Regulatory, Insurance, Supply Chain Logistics, Anti Counterfeiting, Travel and these are in various stages of implementation, development, design and PoC’s. Here are some:

Healthcare
  1. Large Pharmaceutical companies are using Consortium blockchain platform for their clinical trials to overcome its higher cost and meet Government regulations. Clinical trials involves data collection and its management in timely fashion from patients, physician offices, recruiters and research centers spread around vast geographical areas.
  2. Medical Insurance claims is a 3 trillion dollar US healthcare market but still utilizes 40 year old EDI paying value-added services in validating the transactions along with a significant percentage of clerical staff processing the paper input to service long tail of small scale providers.

Supply Chain Logistics:
This use case is an ultimate for Blockchain implementation. There are two key dimensions that are required in any Supply Chain from its creation to end-delivery. 
  • End-to-End traceability with ability to trace back to its Origins which potentially increases with complexity of the product in varying degrees 
  • Identifying passage and impact of laws and regulations influencing the product’s journey
The complexity can further compounded when supply chain has to trace assembly of these products into SKD’s and into final product. Imagine If I extend the thought process to trace including installation issues, repairs, upgrades, warranties etc. 

Capital Markets:
Currently 26 member Japanese financial institutions have successfully implemented Internationally OTC (Over –the- Counter) derivatives using blockchain to apply master agreement without a need to renegotiate with counterparty thus improving transparency and simplifying data management.

Recently Credit Suisse and ING completed the first live securities lending transactions valued EUR 25 million using R3’s Corda Blockchain platform.

Conclusion:
A methodical study, evaluation of a disruptive and revolutionary paradigm such as Blockchain Technologies to its current landscape of ecosystem has more promises than failures.

Saturday, March 3, 2018

FHIR a Strategic Initiative for Healthcare Providers to build Clinical Data Repositories


Today’s Hospitals are collecting vast  amounts of data from their day to day operations on Patients like Clinical Observations, Conditions, Encounters, Medication, Pharmacy, Imaging including vital signs using sensors to support both Operational and Research requirements. They are also looking at ways and means to map their internal data with external data which conform to some standards for ease of mapping and contextualize the data.

However the major problem they face is in their inability to combine the data from multitude of silos created by different applications for any meaningful and well-rounded analysis either for research perspective or to support any policy decision making or provide better and cost effective analysis to improve Patient care.

Many major hospitals have built healthcare data storage repositories in their native format with metadata tags to identify the context of the data what they call Data lakes which can be queried and extracted based on questions they wish to answer.

The success and utilization of these Data lakes depends upon how lighter they have been designed and built in comparison to dark data silos and to minimize its inherent drawback limitations to address questions such as; how the data was brought in; how and where it can be found; how to explore; and what and how it needs to be transformed to be of use. This task of identifying, preparing, combining several data sets from different hierarchical depths is equally challenging for a NON-IT-STAFF members like Researcher and Business users if not equally easy for the IT folks without Health Domain knowledge.

What and How FHIR (FAST Healthcare Interoperability Resource) an Open Industry Standard from HL7 comes handy to elevate such and many other bottlenecks?

HL7 a Non Profit Organization accredited in building Healthcare Standards, introduced FHIR (pronounced as “FIRE”) www.hl7.org/fhir/ . 

Healthcare providers have been using various HL7 Open Standards for Exchange of Information in the past since 1987 like HL7 V1, V2, V3, CDA, CCDA. FHIR Framework standards were written to address various pitfalls of their earlier specifications and standards and also keeping in view advances in IT technologies that can be leveraged for its effective implementation.

FHIR is the new Open standard getting lot of traction in the Healthcare Industry that has defined more than 180 Granular and Normalized Entities with attributes with defined formats. These “Containerized” entities are called Resources and in NoSQL World called Collections and its rows as Documents. FHIR also provides RESTful API protocols for exchanging of information between legacy healthcare systems and for integrating with different application systems. 

The common data format standard used in FHIR are XML and JSON. The concept 80/20 rule is applied when Industry identified these distinct resources in the current draft of HL7 Version 3.x from value proposition to mean 80% of the Clinical data needs can be accomplished using 20% of the Resources identified by the Industry.

These FHIR Resources are grouped under various heads such as Individuals (Patient, Practitioner, Person, Group), Diagnostic (Observation, Specimen, ImagingStudy), Medications (Medication, Immunzation, MedicationRequest),  Care Provision (CarePlan, ReferralRequest, RiskAssessment), Management (Encounter, EpisodeOfCare), Workflow(Appointment, Schedule, Task) for Clinical data sets and many more to support Financial Domain Coverages like Billing, Payment and various Specialized Health Research domains.

FHIR Specifications and Standards are exhaustive and detailed and provides standards how Profiles and Extensions for Elements and Data Types can be extended for attributes in Resources and to combine Resources for different Use Cases.

The most conspicuous benefits of FHIR is the ability to  build a conformed standardized yet unified view of common data sets/documents that are interoperable and shared with precise definitions both internally and with external systems and vendors.

The other benefits includes its support for Clinical Terminologies and Ontologies for SNOWMED, ICD9/10, LOINC and other Open Standards thus avoiding to design a separate Terminology Services with Codes for Lab noting’s, Diagnostics, Medications, Imaging and others.

Lastly, the most important one for me, FHIR Resources can also be presented in an RDF format (Linked Data) specification by serializing property information using Turtle format or as JSON-LD and presenting data in RDF (Resource Description Framework) data model to support Graph DB. A RDF Graph DB(SPARQL)  can help and enhances Healthcare provider’s ability to identify complex patterns of relationship in real or near real time that could save lives and decrease costs to Patients.

FHIR Implementation
FHIR can be implemented in a phased manner depending upon how many different domain repositories and areas of interest that Healthcare provider intends to build and leverage insights. HL7 also provides HAPI pronounced “happy” a JAVA based health care package library to enable adding FHIR messaging to your applications in building different FHIR Resources.

NoSQL Database
Todays, Key Value store are the norm for its flexibility in building a schemaless and horizontally scalable databases that supports object oriented paradigm. To this add performance compared to RDBMS as you scale up data volumes into billions of rows or terabytes/petabytes data and also to meet high demand throughput with low latency traffic there is no next best alternative to NoSQL.So In my opinion, a NoSQL data store is a perfect match for FHIR.

Conclusion: Containerizing data using FHIR Standards as Resource Types (Collections/Documents) from Data Lakes, HL7 Messaging into a NoSQL Database work as a self-contained, documented, standardized basic building blocks which can be readily utilized by both Research and Business Users to meet their Operational and Research needs with ease.

Saturday, September 9, 2017

Connected Sensor Cars

When I bought my semi-upper end Toyota Prius Prime last month, I was surprised that the Car was build with many sensors that it could do self-parking, alert me when I am wavering into another lane and even more automatically adjust the speed on cruise control when another Vehicle moves into my lane or its sees danger of collision with another slow moving one.

These were all possible because it leveraged different kinds of sensors built into the Car. There are many luxury and top-end cars which has more features than this one. The point I am trying to make is current and future’ cars are likely to have 100’s of different kinds of sensors for Safety, Ease of Use and more truly to be called Connected Cars a phase before Automatic Cars takes on our roads and have a paradigm shift including using Car As a Service (CAaS).

A quarter of 100 million cars produced a year globally, have sensors providing functionality ranging from Personal Health Monitoring ( Impaired Driver Check to Emergency services), Vehicle Care ( Vehicle Remote repairs, Breakdown Mgmt), Digital Marketing (Location based Offers, Couponing), Connected ADAS (Road Sign Detection, Road Condition Warning), Safety features (Stolen Vehicle Tracking) and other services like Concierge, Infotainment and other Customer focused support features.

Connected Cars are leveraged to support Community based sharing of information from curb side parking availability to providing assistance in traffic movement metrics on Speeds and Congestion information on any given road to local authorities. A good example of that is Waze a Google owned Free Navigation support mobile software that has revolutionized GPS navigation with real-time traffic alerts on congestion, obstacles and even Cops nearby during one's drive using this Community Sharing paradigm.

INRIX is another major traffic information aggregator providing travel information in real-time as well traffic patterns on the highways and local roads including intersections 24 X 7 to several private, municipalities and public institutions using its own GPS support navigation systems equipped in millions of Cars as well support from 3rd Parties and Community globally. Navigation features enables it to provide Smart routing, Live traffic information besides providing Traffic prediction.

The one major feature that is radically changing and getting highly visible is with regards to Parking. Last year Waze has teamed up with INRIX to provide a feature called “Where to Park” to the customers enabling them to identify optimal parking spots as they drive off to their destination. Customer can select from any of the Parking Spots including Commercial and updated Curb-side Open spots in near real-time by weighing in the walking distance info to their destination provided by the app.

Last year 2016, Federal US DOT (Department of Transportation) has funded more than $45 millions in 3 major US cities of (NY, Florida, Wyoming) to operationalize cutting edge mobile and roadside technologies to reduce environmental impacts designed to save lives and improve personal mobility. In my opinion with millions of Connected Cars on the road, these vehicles would become the game changer and present a more viable option to address the desired goals of many such initiatives in place of permanent fixtures.

The next generation Autonomous (Automatic Cars) will have much more radical and paradigm shift in how we use travel modes from point A to point B with ease besides opening up the congested roads, infusion of Warehouse parking options, reduction of car ownership, garage space requirements and so forth.

It’s no more a futuristic trend, but real. We are in exciting time period to watch this travel mode unfold before our own eyes opening up opportunities and challenges with its adaptation.

Monday, July 11, 2016

IoT Silhouette

It is an exciting period for UX (User Experience) with more and more IoT (Internet of Things) getting launched each day. Last month, Netherlands and South Korea become the firsts' two countries to have launched dedicated IoT networks in the world. More than 4 million IoT devices are likely to be connected by 2017 in South Korea alone.

The highlight of this low powered wide area network (LPWAN) is in its ability to transmit data between battery operated devices over many miles while using little power.

These IoT gadgets from consumer perspective can range from home devices, wearable's,  medical/wellness fitness devices, Connected cars with gadgets and Urban systems  like Parking meters, air quality sensors devices etc.

A user friendly UX design and functional capabilities to a large extent can differentiate a competitors products from each others. This is not to be confused with our IT terms as UI but much wider a term providing a holistic perspective of different design principles in creating a better product(useful, usable, aesthetically pleasurable). Experts estimate that by 2020 there will be almost 50 devices.

Most IoT are embedded devices which either have sensors that convert physical world (e.g. motion, light, air quality, contact, location, proximity, humidity, orientation etc) into digital or/and actuators which convert digital instructions into mechanical actions (e.g. start a motor or turn/off a device) besides services provision for smarter communication.

How does manufacturers IoT differentiates one with the other. We can view it from 3 basic parameters a) Acquiring connectivity, b) Sensing abilities and c) Computing power and all these rolled in with better UX design.

A connected IoT device is one which is connected to a network (cloud) whose behavior is controlled by the host programs to deliver a User experience.Today's IoT instruments are asynchronous just to preserve the battery power and does the sync with bit of latency with the host called system model.

This may be one area that could change with advances in power storage technologies. The other main beauty about IoT is in its ability to control, monitor and configure remotely using mobile and web applications.

IoT is a great product to integrate Customer experience (see my earlier blog on Customer Experience Alignment) because IoT Service is not necessarily like purchasing one-off the shelf product but rather it requires an ongoing service with a minimum of Internet to keep things running and customer support. So a delightful CX experience would make all the difference between you and the competitor.

A simple IoT service might serve only one or two devices like single or couple of connected light bulbs) but with a hub/gateway you could add many more edge devices and complex gadgetry's like . a security system using motion sensors, cameras, lights, alarm system and so forth.

This feature of mixing and matching of different products from IoT vendors throws up challenges as well opportunities. In this nascent stage of IoT development,  there are still no common standards between  different platforms to communicate with each other.

There is an ongoing effort by major companies to bring in some semblance and to bring some level of standards in the IoT ecosystem as they collaborate with each other. Secondly the potential market size of a trillion dollar plus perhaps could also force them to think collectively to build some open standards.

In fact there are some enterprises who are building a smaller footprint ecosystem that can talk to each other like Nest (Thermostat, Smoke detectors, Lights), GE & Honeywell (lighting and power sockets), Sonos (home audio), Schlage and Kwikset (door locks), Philips, Hue,Belkin, Withings (home connect products).

IoT network connectivity is bit more complex than our digital PC's or smartphones. IoT connected devices use different types of networks and patterns of connection and more over these devices are not constantly connected to provide an instant response thus resulting in being out of synch and with latency issues in the ecosystem.

In the basic System Architecture of IoT,  there are two different types of devices. There are IP based devices that are connected to Internet and they typically translate IP based communications. On the far end there are local Non IP based devices connected to a gateway also called edge devices.

The big advantage with these gateways is that they can work with different communication protocols of IoT devices and have built-in rules that can run even when the Internet is down. The major fault with Gateways is the single point of failure besides lack of technical standards and the need to customize with different products in the ecosystem.

The advent of low powered wide area networks (LPWAN) and technologies like LoRA (a proprietary of South Korea Service) or LTE-M a machine-to-machine communication technology to transmit data between battery operated devices over miles with little power could provide the required boost to overcome some of the challenges with gateways.

There is another major challenge of limitation in providing addresses to all the IP based gadgets in the IPv4 with its 32 bit addressing system and max addressable space of 4 billion devices.

This issue is addressed with incoming standards IPv6 which has a size of 128 bits. These new address format overrides all the limitations of Unicast identification networking addressing issues, Anycast address issues for group interfaces as well Multicast addresses for multiple hosts issues. This new addressing system number is so large that it is said that it would take 38 billion years to scan all the possible addresses at million addresses per second speed.

Going by today's adoption rate and acceptance in the market for IoT products in general it appears to be attracting more the early adopters market and for some good niche products appealing to the mass markets too.

The common thread among these successful products line appears to be great value proposition that these IoT products are able to provide to the customers. Experts believe that there are 3 key ingredients for any successful IoT products. RELEVANCE, SPECIFIC BENEFITS AND EASE OF USE.

To expand the market from early adopters to mass market,  the product needs to meet the requirements of different people and has good affordability price point for the expected value proposition. I am sure there are many more discussion points and topics across different types of products and different markets that can be penned. I will pause the discussion here and opt writing on those areas in my future blogs.

In today's market, there are some cool products out there which I would like to broach here briefly.

Belkin makes WeMo Home product series and many of them can be controlled, configured and monitored remotely using your smartphones such as electrical lights, sprinklers, blinds, crock-pot and other electronic DC devices.

Amazons Echo product provides hands free voice activation to several compatile WeMo, Philips Hue, Samsung Smarthings, Wink and other Smartdevices besides reading news, weather & traffic and playing music on its Alexa voice service.

Mimo smart baby products embedded in baby's kimono can allow parents to track baby's sleep, movements, temperatures and provides relief and feel secured and connected albeit remotely even in day care centers with their smartphones.

Nest  thermostat is another product line that I like which stands out among other such products both in terms of design, usability and intelligence and above all user experience. There are also several geeky gadgets like Ambient Umbrella which has light integrated into its handle that glows different lights when rain, snow or thunderstorm is forecasted.

The trend of interoperability and above all the collective synergies where the sum of value of each IoT product being greater than its individual values for a customer is encouraging buyers to adopt IoT devices with enthusiasm and building fan followings.

Some major manufacturers like Belkins (WeMo), Samsung (SmartThings), Philips (Hue), Qualcomm (AllJoyn)  have built  Open platforms and hubs that work with many of their own products and cross company products. There are others who have built Home Automation network protocols like ZigBee, ZWave, Insteaon, Lutron Clear Connect that plug with products with their Hubs for edge products. Amazon's Echo, Lowes Iris, Staples Connect are good examples of IoT product that works with majority of the platforms and hubs/gateways.

There are many companies seeking to become the de facto gateway/cloud integration platforms for different IoT ecosystem

Xively Connected Product Management is one such enabling platform for Enterprises. Xively provides a rich set of API's, Libraries, SDK, Services to Connect, Manage and Engage IoT products.

Here is a listing of 15 other major companies in today's perspective showing greater investment and product, services and technology maturity offerings in IoT arena.

Amazon, Bosch, Cisco, GE, Google,  IBM, Hitachi, Huawei, Microsoft, Oracle, Philips, PTC, Samsung, Siemens and Qualcomm in this game provide products and solutions in areas such as Network Connectivity, IOx and Fog Applications, Data Analytics, Security, Management and Automation and Application platform for IoT.

The Internet of Things (IoT) is still nascent, but growing quickly. Research firm IDC predicts it will become a $1.46 trillion international market by 2020, up from $700 billion last year 2015.

The potential big market is obviously the replacement market to swap the legacy house hold products from these niche manufacturers. Second there could  be new services enabled by IoT devices that are not available today like  diagnostic devices that could monitor before your gadgets fail (example Water boilers/heaters).

The most important IoT product category for me is the bio and wearables one that has the potential to change the quality of health care of human being from being reactive to being proactive and importantly being aware and in command with knowledge.





Wednesday, June 29, 2016

Customer Experience Alignment

Why do we as Customers prefer to buy branded products or obtain services from already known places. The answer seems very simple that these products or services could meet our perceived expectations. On the flip side of this question to Producer ask them what makes them tick with their customer, the answer is definitely not so simple.

Today most companies are trying to answer this question and also stay ahead of it by trying to understand their Customers with emphasis on 4C's paradigm besides their age old 4P's approach.

The 4C's approach keeps the Consumer at the center of the sphere with "Outside in" approach rather than  the "Inside out" which was more evident in 4P's approach. In fact even 6 decades ago, Peter Drucker the Management Guru in his "The Practice of Management(1954)" has said "There is only one valid definition of business purpose: To create a Customer."

The Customer centric approach emphasizes that Value creation is a bidirectional and enterprises have to create a mindset to listen to their Customers from as many touch-points as possible and to collect their interactions of experiences expressed by them across many of their channels.

The Social media and Enterprise multi-channels needs to be tapped into 360 Customer view to enable and see a holistic picture as well at a granular level of their Customer with different lens/views created with # of Customer profiles for their different functional business departments.

The task of building a Customer 360 Experiences Engagement hub is not an easy project. The major challenges for any enterprise needs to be addressed not from a technology perspective but rather first clearly understand what is the objective, goal of building one.

In a siloed state of many Business functional units of an Enterprise, the first and foremost act is to undertake an assessment exercise to identify the state of  Customer Journey identifying concerns, issues and processes in play across their multi-channels. Second align the assessment findings with Corporate's objective which could be either Cost containment, Improve Revenue or Improve Satisfaction or even meet regulatory compliance requirements.

Customers in any large organization come in various hues and colors of their expectations and requirements. Identifying the personas of these customer with proper segmentation to bring the granularity level of understanding to individual customer level would enable enterprises to align with Customer expectations.

Involving, engaging, training and motivating employees who man the front office of these multi-channels is also crucial in building and improving customer experience.  Forrester Research in their 2011 has indicated that  CXPi (Customer Experience Index)  in some large global brands companies who have moved their needle up from below average to above average CXPi have seen an increase of $1.3 billions, I mean billions in their revenue bucket.

From a technology side, depending upon their level of maturity and IT support, there are some good options. One could embrace CRM + Social media suite of Products or engage Consulting vendor who have already  built similar hub on a Big Data platform.

However the former may not provide a Complete and True Customer 360 Engagement hub for the following reasons. It may not be able create data piping from all your traditional multi-channel sources and second, it may not able to beef up with 3rd party data with appropriate connectors and build different hierarchical views required by different functional business units. One of the other significant drawback also appears to be in their analytical platform offerings with embedded engines to process Unstructured & Semi structured of Text & Speech data sources and contextualize them. This option may not also meet your demanding and individual specific requirements for comprehensive Predictive Analytics in Real-time to monitor and provide better experience.

Nevertheless it does provide a good first step to move in the right direction for companies who currently don't have common Customer Center platform to bring in Customer interactions to club with transactional data overlaid with common denominator analytics.

The Vendor option does not go without its own challenges and problems. The major challenges appears to be articulating clearly what is to be delivered or what will be delivered that meets your requirements in a phased manner with a clear Road-map.

One needs to understand that you are actually building a System of Systems as Gartner calls it for building Customer Engagement hub. In the paper on "The Top 10 Strategic Technologies for Customer Experience" Gartner indicates that there are more than 50 Technologies that can be used to build a good orchestrated Customer Engagement platform.

Here is the conceptual view of a Customer 360 Engagement




Objective of the Blog:
The objective of this blog is to emphasize the importance of alignment of Customer Experience. Enterprises could build an expensive and real-time platform in-house or in cloud, but if the Customer's experiences are not aligned, then we are trying to knock at doors which may open and pave way to a myopic solution.

Identifying and laying out the efforts for a greater benefits for Customer and Business needs to be the ultimate goal. There are Strategic and Operational steps that needs to be undertaken to convert a Discrete Customer into a Trust based relationship Customer.

Building a Customer relationship should be the utmost important one and this need to build as continuous process. Here is how we can visualize it in converting a Discrete Transaction to Relational one with relationship maturing from Symmetry to Trust relationship


Second, building a Value-Centered design by taking all Customer interactions in the Organization and trying to realize the benefits out of them. These mapping can be built either by using Service Blueprints, Customer Journey Maps, Experience Maps, Mental Model and Spatial Map diagrams.

These maps irrespective of the choices provide Chronological, Hierarchical, Spatial story line with their interactions to show case actions of individuals and appropriate process involvement of the Organization. Care must be taken that these visual diagrams are not meant as colorful wall posters but important diagrams to bring in right conversation about creating values.

Thirdly, bringing in Employees into the center stage by training, engaging them for insights and keeping them motivated because they represent the front office folks in the Customer Engagement in building progressive and positive relationship.

Fourthly, frequently, enterprises should be able to unearth Voice of the Customer (VoC) using Surveys, Feedback or employing 3rd parties to gather such information.

Lastly,  building appropriate analytical models and utilizing them their Analytical engines to contextualize the interactions to view as connected pieces rather than as isolated measures.

But here is a common approach followed and advised by all: Start Small, but aim Big or Sweat the Small Stuff







Sunday, September 20, 2015

Basel III and IT Implementation Overview

The aim of this blog is to provide a brief overview of Basel accords which provides financial supervisory controls at broader level in the global financial market and brief IT Implementation steps to accomplish for BCBS 239 regulatory requirements. I am relying on my financial & accounting academic background and learnings & experience with the financial clients in my consulting world, while I profess my career as an IT professional.

Basel
Basel Committee on Banking Supervision (BCBS) based in Switzerland was created in 1974 to establish standards on regulation and supervision for SIB banks. The first major accord Basel-1 in 1988 was published to provide supervisory and regulatory controls for banks in G-10 countries after several International Banks faced heavy losses on account of closure of German Bank Herstatt and Franklin National Bank of New York whose foreign exchange exposure was more than 3 times that of their capital and found this issue more as a symptomatic pattern among other major international banks.

Over the period, there were major and minor accords created by BCBS & Financial Stability Board (FSB) to provide for fair play, regulatory requirements based on firms risk exposure, management and their appetite. Among various accords Basel-III so far is a complex package that supersedes its earlier versions including Basel –I and Basel-II. The growing economies of Asia and its influence on the financial and economic activities has also prompted them to expand the landscape from G-10 to G-20 countries and today more banks from 140 countries follow the regulatory requirements.

Basel accord is not just a recommendation but a package of regulatory controls aimed at Systemically Important Financial Institutions (SIFI) of both local and global organizations. In normal parlance, common banking activities like lending, investments involves risk exposure, and the willingness or the appetite for risk depends upon its infrastructure reach and capital strength, to drive its core and secondary commercial activities.

These activities results in the creation of different types of risk (Operational Risk, Credit Risk, Interest Risk, Liquidity Risk, Market Risk and other risks).  Strong and solid Governance & Controls provide stability to their operations to understand both inherent and residual risks.These risks can be originated internally and externally by different pillars of the heterogeneous economies and organizations have to take appropriate risk mediation steps to overcome these potential risks and its survivability while limiting its collateral damages.

Basel accord emphasizes in creating liquidity, capital adequacy, operations leverage in the global economy with host of other measures aimed at providing stability to avoid another financial meltdown.

Blame Game and Cause for Financial meltdown
There were many fingers that pointed out by eminent people for the cause of this meltdown right from accusing few CEO’s greed to lack of knowledge or even understand to the basic question in the bank wide transactions as simple as “who is who”, “who owns whom” and “who owns what” with clarity.

There were some who have indicated that lack of corporate governance structure and absence of precise and intuitive corporate management language which failed them to understand, monitor and control the fancy and complex products that were put in the market abetting the financial collapse. There are others who argue that letting down  Lehman "a too big to fail" institute caused and exacerbated the collapse with severe collateral damages. Rating companies attesting better rankings to a "Junk" instruments based on the incorrect assessments of financial statements also played a role in the crisis.


BASEL-I, 1988
This was the first major accord where BCBS provided definitions on the classification of Bank’s Capital and set certain minimum requirement standards. The Tier-1 and Tier-2 Capital for all International Banks emphasized the banks to maintain a minimum of 8% of its Risk Weighted Assets (RWA) to avoid financial failures on account of closures of German and American bank due to their overexposure on foreign exchange in relation to their capital adequacy.

BASEL-II 2004
Superseded BASEL-I in the risk and capital management requirements by further emphasizing on the adequacy requirements to the exposure of risk in their businesses of lending, investment and trading. Some of the key takeaways from this accord are as follows:
  • Regulatory compliance should not become a sore point among the international banks on their competitiveness to operate with big banks
  •  Capital adequacy was considered as a risk sensitive function with greater the risk, more capital needs to be held by the banks to maintain its solvency
  • Emphasis was made on Credit Risk, but left to individual banks to manage other major risks like Operational Risk, Market Risk on their own
  •  Emphasis on greater disclosure requirements twice a year, so regulatory bodies can monitor the various adequacy requirements and also enable assessments by analysts, investors, international financial bodies and other banks to showcase the effective corporate governance of individual banks among other details on
    • Details on Risk Exposure & Risk Assessment Process
    •  Capital Adequacy requirements and their validations
BASEL-III 2010
Accord was revisited after the financial meltdown in 2007-2008 that revealed additional financial regulations needed to be in place towards Capital Adequacy Requirements (CAR), Stress Testing, Funding Stability and Market Liquidity Risks, Liquidity Coverage Ratio (LCR) to effectively and Banks Leverage ratios.

It also defined Common Equity requirements as a Well Capitalized, Adequate Capitalized, Inadequate Capitalized under different Tiers (CET-1, CET-2, and CET-3) and High Quality Liquid Assets (HQLA) at different levels (Level 1, 2A, and 2B). 

Another major component of this accord defined was to maintain a net stable funding profile in relation to their on-and off- balance sheet activities to reduce the funding disruptions and its impact to liquidity. Finally, the focus is also able to identify KRI Key Risk Indicators (KRI) and build Risk and Control Self-Assessment (RCSA) methods to identify inherent and residual risk exposures.

Basel Summary
In Summary, Basel attempted to create a harmonized set of quality, consistent policy accords that aids in the better management of financial operations of SIFI’s complex products by increasing reserves based on key ratios and slew of measures. It created new Counterparty Credit Risk (CCR) ratios, Liquidity Risk Ratios like Liquidity Coverage Ratios (LCR), NSFR (Net Stable Funding Ratio) and Collateral risk ratios for Quality coverage such as Initial Margin (IM), Variation Margin (VM) among others.

It also created additional buffer requirements like Capital conservation buffers to be infused in during normal period and to be utilized during stress periods. Some other key components like Stressed VaR (SVaR), Trading book positions and changes to general, and specific Market Risk Models with respective to changes in parameter values were also highlighted during stress and normal periods.

Basel regulatory compliance works hand in glove with other controlling agencies like Federal Reserve Bank, Financial Stability Board (FSB), Security Exchange Commission (SEC), International Organization of Securities Commissions (IOSCO), Regulatory Oversight Committee (ROC), Federal Deposit Insurance Corporation (FDIC) and many other International Regulatory bodies and Reserve Banks of native countries to build a customized version of requirements, ratios and timelines by which these accords needs can be implemented.

Business, IT and other professional folks are still working towards assessing the changes warranted to implement this complex package of rules and regulatory requirements. One may identify and group these requirements into 4 buckets:
1.       New Capital definitions and its adequacy requirements impacting Operational & Functional aspects of the Organization
2.       Creation of additional Buffers and its operations during normal and stress time windows
3.       Building and maintaining Leverage & Liquidity Ratios and its changes to the Operational and Functional system of the Organization
4.       Implementing CCR changes across US, EU and Asia for Global companies. This one I believe is bit more complex to implement as it transcends many areas of the institutions business model and geographies.

Some of the reasons for the financial meltdown were attributed to lack of comprehensive risk reporting and its aggregation abilities that fell short on its accuracy, reliability and timeliness. To address these and more, Basel also created a BCBS 239 document to be implemented by the SIFI’s with eye on creating a stable all-encompassing Risk Data Aggregation Reporting (RDAR) repository.

BCBS 239, Jan 2013 a regulatory document on “Principles for effective Risk Data Aggregation and Risk Reporting” was created by BASEL and FSB to provide guidance to enhance the bank’s ability to identify and manage bank wide risks. It consists of 14 principles to guide the banks to develop and build process and methods for a Risk MIS that provide Qualitative and Quantitative measures and reporting mechanism. These broad principles can be summarized as follows:

1.       Overarching Governance & Infrastructure: Build Strong Governance over bank's risk data aggregation capabilities, risk reporting practices and IT capabilities. It should cover design, build and maintenance of data and IT architecture to fully support its data aggregation capabilities and risk reporting at all times.

2.       Risk Data Aggregation Capabilities: Build adequate system controls in the generation of risk data with capability to quickly adapt to changes in the key risk identification and decision making arrangements and regulatory and compliance requirements.

3.       Risk Reporting Practices: System should be able to provide forward looking accurate, reliable, timely & useful risk distribution reports and assessments on risk with build in procedures to monitor and control.

Link to BCBS Principles Guidelines

Common IT Challenges among SIB’s.
1.       There are many silos of data in heterogeneous platforms with different aging and reporting capabilities
2.       Lack or Limited Master & Reference Data across different domains (Operational Risk, Market Risk, Liquidity Risk, and Credit Risks) leaves big hole to validate it as single source of truth
3.       Minimum or lack of Governance bank wide to build a cohesive audit controls and corrective measures
4.       Lack of Data Quality inhibits reporting accuracy and many don’t see data as an asset and uncorrected data flows into other systems thus cascading the imperfection
5.       Different grains levels of data processed and stored for analysis and thus creates compatibility issues on its usage and reporting
6.       Many risk modeling are done outside the integrated systems with no loop back mechanism and often are out of synch and difficult to consolidate
7.       Latency issues in gathering and reporting across multiple channels thus missing on many windows of opportunity to address and fix the issues
8.       Many of the measures & metrics are created on assessments rather than being measured thus are not a good candidates for aggregation
9.       Lack of coordination & understanding of business needs between IT and Business and vice versa resulting in creation of many inefficiencies on productivity of resources leading to  time & cost overruns
10.   Lack of Matured Interactive Reporting Platform with Dashboards, Scorecards, Slicing/Dicing capabilities across many constructs or dimensions

The implementation of BCBS 239 should not be viewed just as a Data Management project but coordinated between Technology, Data Management & Governance and Risk Management Business teams with clear ownership and responsibilities among the stakeholders.

Implementation Steps in Building a Robust BCBS 239 Compliant System
I have read several times the principles and each time, I could make bit more meaningful sense on each reading. So here are some suggestions for both IT, Business and other stake holders.

  • Understand clearly each of the BCBS 239 principles in totality with one principle at a time
  • Create a game plan by organizing the task of the requirements with a bottom-up approach
  •  Create an Information Governance Catalog of Labels and identify the stewards for each of those information
    • Identify Risk Metrics and its related terms, Custom terms and its evolution with history to identify the changes and record them appropriately for compliance
    • Create Business lineage of source, targets and reporting assets across different domains
    • Create Data lineage of column level flow activity of source to targets across different data silos, transformation of expressions, flow activity trace, abstractions, derivations, STP, Data movement process like FTP and any touch points
    • Profiling data both history and intermittent from time to time, updating the Information Governance Catalog for regulatory compliance
  • Flatten the hierarchical risk metrics views with relationships across different constructs/dimensions as a Blue print for better understanding and grasp of its complexity
  •  Create Metadata tables for expressions and its terms along with showing calculations precedence and expected intermediary and expected results
  • Document models usage and its various algorithms
Options in Building RDAR (Data Virtualization)
As I have indicated earlier one of the reasons for the financial meltdown was inability in providing a single bank wide view of risks in timely fashions and providing consolidation of individual risk practices into an enterprise wide one. This has also made it difficult to monitor and identify systemic risk and provide for regulatory transparency.

Data Virtualization is one solution that is creating traction with many company’s which has 100’s of silos of data stores and multitude of heterogeneous database platforms with dynamic rules changes to be compliant.

Financial institutions can built single view of institution wide risks to better manage Market, Credit, Liquidity and Operational risks with data being pulled from multitude of sources like trading, portfolio applications, account systems and others in real-time for timely assessment. In addition many financial companies employ several financial analytical and research applications and these can also be combined for identifying trading opportunities and also address any regulatory compliance requirements.

On the horizon Financial Transaction Barcodes (LEI, UPI, UTI)
Just as a 9 digit routing number of bank can participate in a financial transaction like ACH and Wire transfer, global banks are working towards building a Legal Entity Identifier (LEI) that can be used in their financial transactions. The objective of BCBS regulators is to observe the buildup of enterprise risk and understand the capital adequacy across silos of business by aggregation within each financial institutions and identify systemic risk across global financial system.

This initiative has been tasked by Financial Stability Board (FSB) and is getting tested with complex derivative product like Swaps with billions of transactions both in US and EU. However the coding scheme used is still not up to mark as per the researchers and academicians to meet the BSBS regulators objective of aggregation. The mapping services for LEI still has gaps in parent/control/ownership hierarchies and its linkages to the issuer, obligor, counterparties and guarantee relationships.

Regulators are hoping this initiative would be able to create global identification system with Unique Product Identifier (UPI), Unique Transaction Identifier (UTI) along with LEI to reduce risk, lower cost and improve efficiencies in the middle office infrastructure by enabling the industry as a whole into digital age.

Conclusion:

I am excited at the outlook and the opportunities that this new Global Financial System brings to its stakeholders as they move cautiously and surely into digital world after a major crisis.

"We cannot solve our problems with the same thinking we used when we created them.
Albert Einstein