Showing posts with label regulator. Show all posts
Showing posts with label regulator. Show all posts

Tuesday, 3 August 2010

How regulated organisations can deal with social networking issues

In my last post I raised the point that in amongst the excuses applied in some organisations, particularly regulated ones, to avoid letting employees use social media, there are some real issues. This post looks at some of them, and proposes solutions.

I can think of four main types of issue, which I'll call, respectively, Conduct Unbecoming, Company Secrets, Off-the-Record Contracting and Chinese Walls. Let's look at each in turn.

Conduct Unbecoming

This rather old-fashioned expression I take to mean anything that an employee might say that the firm would not wish to be associated with its name. This could be inside or outside the firewall. The fears are more reputational than regulatory, although for internal-only material they may well be more about power and the prevention of the usurping thereof.

It should be possible to deal with both instances (inside and outside the firewall) by means of a policy. I'm tempted to say this could be as short as "Don't give away company secrets and don't diss the firm", but it will probably be a little longer and more formal than that. Nevertheless, that's basically the message. Whistleblowing rights would of course remain, but those aside a company can reasonably expect some measure of loyalty and good behaviour from its people.

Company Secrets

This covers commercially confidential material, client confidential material and so on. There's an art to saying something interesting online that doesn't breach confidences. Ever since the invention of email people have been learning the hard way that people react differently to opinions expressed in writing as opposed to face-to-face or on the phone, especially when the opinions are negative. It's not a simple matter to craft work-related posts that are interesting to you and your readers, and at the same time won't upset your boss. But this art must be learnt, because short of never mentioning work online - which probably means not being online at all - everyone will have to face up to the consequences of getting it wrong. As far as the company's concerned, again policies have a role, but they might amount to closing the stable door after the horse has bolted. Someone who doesn't understand 'netiquette' might blunder even though s/he's read the policy, and once that tweet or Facebook post's in the public domain it's too late. So there's a role for training here: in how to use social media effectively and safely in a work-related context.

Off-the-Record Contracting

This is the issue of people using unofficial channels to record or make agreements which could bind the firm legally. The issue isn't so much about secret or under-the-counter deals - intentional concealment - as people wanting to do them will always find a way, and there are legal sanctions available to deal with transgressions. It's more about the fact that there's a grey area between the conversations that lead up to a deal, and the formal contract documents. A firm can't afford to lose track of even the 'grey' bits. That is very tricky even if email were to be the only channel used, both in relation to finding stuff later and to dealing with multiple email accounts and platforms. Banks that I have worked for tend to block webmail at work to try to deal with the second point. (As for finding stuff for, for example, disclosure purposes, social media platforms can score over email there, but that's a bit off topic). The problem with blocking email, as opposed to making it a policy not to use non-firm email for business purposes, is it's a slippery slope towards banning all non-firm communication platforms. This can mean no access to (public) blogs, wikis, social networking sites and so on. in fact, no Web 2.0 at all. For me, that's throwing the baby out with the bath water. A better approach would be to state in a policy that such channels shouldn't be used for anything that could have contractual implications. But, of course, the regulators, and not just the firms, need to be convinced that this is satisfactory before it has a chance of flying.

Chinese Walls

A well-known concept in banking circles, the Chinese Wall is a necessary separation of communication between certain departments, usually to prevent conflicts of interest. Any 'social' platforms must take them into account. Broadly, there are two possible approaches. the first is to make all social platforms inside the firewall accessible to everyone in the firm, and make it clear that no discussion that should be bounded by a Chinese Wall should appear on them. This has the virtues of simplicity, clarity and ease of maintenance. Its downside is that it precludes the use of social tools within a Chinese Wall, which can seriously limit useful knowledge-sharing and collaboration. If a firm does decide to allow confidential social platforms it needs to be aware that it could let itself in for a big maintenance overhead - as I know from experience! The chances are that your Active Directory (or equivalent) does not flag people with the characteristics that your Chinese-wall-related privacy settings require on your social platform. Therefore, you'll need to have someone constantly adding leavers and joiners of the department or project in question, possibly by hand. It's wise to think hard at the outset how you can best set things up to minimise this manual effort. If you use Sharepoint, make sure you fully understand how security-enabled groups work.

Policing

Whether you adopt the approach that, broadly, I'm recommending, namely to allow quite liberal access to Web 2.0 sites outside the firewall and encourage their equivalent inside it, and deal with potential 'issues' by means of policies and training, or you decide to 'batten down the hatches' and block or ban most things Web 2.0, you'll probably wonder how you can police what's actually going on. In an ideal world you'll have trusted and trustworthy employees who are netiquette-savvy and won't put a foot wrong. If they do, however, you will probably want to know about it. But how to do this?

You might run searches for the company name on, say, Google. This should pick up most stuff on public platforms. It won't pick up 'walled' material like email, of course, or Facebook posts behind privacy settings. Then, of course, as there's no search that I know of that will pick up only 'inappropriate' comments about the firm, there will be a lot of link-clicking and reading for somebody to do. Auto-moderation software exists, and I'm guessing this could pick up combinations of swear words plus company name, for example, thus narrowing things down. But there might still be a lot to read, and as I said earlier, it will be after the fact. So you might decide not to monitor at all, and just deal with incidents as they arise and are made known.

A bit scary? Welcome to the new world! Now's maybe the time to reflect on the way your employees might feel about the firm, and, if that feeling's more negative, overall, than positive, whether it's actually realistic to try to keep the lid on that.

Tuesday, 13 July 2010

Social Media in Corporate Environments: Realism Needed

Prompted by a tweet by Phil Bradley, linking to his blog, it occurred to me finally to get round to posting something on the subject of control, trust and social media in large (especially regulated) organisations.

Many of my social media / Enterprise 2.0 evangelist friends seem to be pretty laissez-faire when it comes to the subject of the amount of freedom employees ought to have in relation to the use of social media tools. I have a lot of sympathy for that viewpoint. Widespread adoption of blogging, tweeting/yammering and the use of collaborative spaces within and even outside the firewall has the capacity, at least in theory, to open up an organisation and make it both more effective and more congenial a place to work. Or, to turn that around, the open culture required to enable widespread use of these tools is a prerequisite to an effective and congenial organisation in the modern era.

I also think, though, that the extreme libertarians, if I can call them that, are either unaware of, or are ignoring, some important legal and regulatory matters that apply to many large firms. If these are ignored, a firm can easily find itself exposed to reputational damage, loss of confidential information and/or perhaps regulatory sanctions.

The problem is that in some, probably many, firms these issues are cited as the reason for not letting employees use social media. They may have genuine fears about the legal or commercial risks, or they may simply not want to do it for other reasons, and use these risks as an excuse. The ones with genuine fears and concerns can be helped, and my next post will provide some ideas for tackling the issues. Those firms that are making excuses will need to get through their state of denial before anything can be done. As a starting point they need to realise that the genie is out of the bottle; that social media/networking is here to stay, and that if they don't get involved their competitors will start to leave them behind.

Tuesday, 23 September 2008

Systemic risk and social media

Presumably there's nobody who hasn't heard of the recent, er, problems in the finance industry. Whilst the wailing and gnashing of teeth are going on, presumably the FSA, SEC and other regulators are pondering how to ensure it 'never happens again'. Targets in the firing line seem to include bonuses and shorting, plus that rather vague term 'transparency' (or rather, opacity, since that's the bogey).

But is there anything much that regulators can do, without throwing the baby out with the bathwater (ie over-regulating and thus stifling enterprise)? And if so is there any connection with social software in the enterprise, thus justifying this post?

I think there might be, but it's not a nice thought. Let me step back a moment. The credit crunch and recent investment bank failures stem from the fact that a duff security - sub-prime mortgages - was wrapped up into opaque financial instruments such as CDOs (collateralised debt obligations). If I understand it correctly, this opacity made these instruments easier to sell than the underlying assets alone would have been, and it became harder for banks to know the true systemic risk they were running. When the sh*t hit the fan, ie the mortgages became worthless because of falling property prices and consequent defaults, not only were the CDOs etc devalued but putting a price on the devaluation became very hard, as did knowing which bank was exposed to what. So the problem was a combination of devaluation and ignorance. It was the ignorance as much as the loss of value that led to the credit crunch and the failures of Bear Stearns, Lehmans and (nearly) Merrill Lynch.

So where am I going with this? The regulators need to get a better, and earlier, hold on systemic risk in future, no matter what gives rise to it. This is not easy to do. Theoretically it can be done by external observation of economic indicators. It might have been possible to deduce that property prices were about to crash and that mortgage-related securities would go with them. But it's always hard to guess when a market has reached its peak, otherwise we'd all be rich. And probability is only one element of risk, the other being consequences or impact. The latter was probably very hard to measure, again because of opacity of the instruments. It all reminds me a bit of the problems at Lloyd's of London in the 1980s with the so-called LMX Spiral: risk accumulated through a chain of reinsurance contracts and no-one knew (until the s*it hit the fan) that it had ended up with a small number of syndicates, who were left holding the parcel when the music stopped.

But is it really true that no-one knows? I emphatically think not. The people who know are those doing the business. You can bet that there were people who knew how potentially toxic those CDOs and what-have-you were. I'm not talking about fraud here, although that did happen also. I mean people doing a relatively honest (by investment banking standards) job, who could see the risk, but had no incentive to do anything about it. In fact they had a big incentive not to - their bonus.

So how does a regulator find out about these risks? S/he needs to tap into what the traders are saying. Once upon a time they just said it in pubs and on street corners. Then, when email came along, some indiscreetly wrote things down, thinking it would remain private. But the regulators could order discovery of it as evidence when something went wrong and it appeared that rules had been broken.

Finally I'm getting to the point. Just as young people often blab about everything they are doing and thinking on social networking sites, then get embarrassed (and maybe risk their employment prospects) when they realise who might be reading it, we can perhaps expect such indiscretion inevitably to occur on social media within the enterprise, when its use becomes widespread. It might come to include traders talking about the latest securitisation wheeze, and how it's gonna be a great little earner for a couple of years until the sh*t hits the fan when x happens. Regulators would be very interested in seeing this material. We may even come to see it as their duty to obtain it. And perhaps to obtain it not just after the horse has bolted, but on an ongoing basis. Not a nice thought, but perhaps inevitable?