Operational Resilience Audit

ORA [Implement] Questionnaires: Improve Lesson Learnt

Written by Moh Heng Goh | Jun 6, 2023 1:37:17 PM

Improve Lesson Learnt

 

What is Lesson Learnt?

The key to improving "Lesson Learnt" when implementing Operational Resilience or OR is for an organisation to promote a continuous learning and improvement culture.   It is essential to improve and communicate remediation and vulnerabilities after scenario testing.

This section is the "Implement" phase of the Operational Resilience Planning Methodology.  It is the last stage of the Implement phase: Improve Lesson Learnt.

 

Audit Checklist for Improve Lesson Learnt

 

Leadership Commitment

  • Is there a visible leadership commitment to promoting a culture of continuous learning and improvement?
  • Do leaders actively support and participate in scenario testing and incident review processes?
  • Are leaders accountable for implementing recommendations and lessons learned from scenario testing and incidents?
  • Is there a communication strategy emphasising the importance of continuous learning and improvement for all employees?
 

Learning Framework

  • Is there a documented framework or process for capturing and analysing lessons learned from scenario testing and incidents?
  • Does the framework include mechanisms for identifying and documenting root causes and contributing factors?
  • Are there standardised templates or tools for collecting and organising lessons learned information?
  • Is there a designated team or individual responsible for managing the lessons-learned process?
 

Incident Review and Analysis

  • Is there a structured process for reviewing and analysing actual incidents?
  • Are incidents thoroughly investigated to identify root causes and contributing factors?
  • Are incident review findings documented and shared with relevant stakeholders?
  • Is there a mechanism to track and monitor the implementation of corrective actions resulting from incident reviews?
 

Scenario Testing Evaluation

  • Is there a process for evaluating the effectiveness and impact of scenario testing exercises?
  • Are scenario testing results analyzed to identify areas for improvement and enhancement?
  • Are there mechanisms to capture feedback from participants and stakeholders on the scenario testing process?
  • Is there a feedback loop to incorporate insights from scenario testing into future exercises?
 

Knowledge Sharing and Communication

  • Is there a platform or mechanism for sharing lessons learned and best practices across the organisation?
  • Are lessons learned and best practices communicated to relevant teams and departments?
  • Are there regular communication channels, such as newsletters or internal portals, to disseminate information on operational resilience and continuous learning?
  • Is there a process for capturing and sharing success stories and examples of continuous learning and improvement?
 

Training and Development

  • Is there a training program in place to enhance employees' knowledge and skills related to operational resilience?
  • Are employees trained on incident response, scenario testing, and lessons learned?
  • Are there opportunities for employees to participate in specialised training or workshops related to operational resilience?
  • Is there a process to evaluate the effectiveness of training programs and incorporate feedback for improvement?
 

Metrics and Performance Monitoring

  • Are there defined metrics and indicators to measure the effectiveness of the continuous learning and improvement initiatives?
  • Is there a process to track and monitor the organization's performance in implementing lessons learned and recommendations?
  • Are performance metrics used to identify areas of success and areas that require further attention?
  • Is there a mechanism for reporting and communicating performance metrics related to operational resilience readiness?
 

Continuous Improvement Culture

  • Is there a culture of continuous improvement embedded in the organisation's values and behaviours?
  • Are employees encouraged and empowered to share insights, ideas, and suggestions for improving operational resilience?
  • Are there mechanisms to capture and evaluate employee suggestions, such as suggestion boxes or innovation platforms?
  • Are there recognition and reward mechanisms for individuals or teams that contribute to continuous learning and improvement?
 

External Benchmarking

  • Does the organisation seek opportunities for external benchmarking and learning from other organisations?
  • Are there partnerships or networks established to share experiences and best practices in operational resilience?
  • Is there a process to review and incorporate relevant industry standards and guidelines into the organisation's practices?
  • Are there mechanisms to learn from regulatory changes, industry trends, and emerging risks?
 

 

Governance and Oversight

  • Is there a designated governance body or committee responsible for overseeing and promoting continuous learning and improvement?
  • Are there regular reporting and updates provided to senior management or the board of directors on the organisation's operational resilience readiness and continuous improvement efforts?
  • Are clear accountability and responsibilities assigned for implementing and monitoring continuous learning initiatives?
  • Is there a process to review and assess the effectiveness of the organisation's continuous learning and improvement initiatives?
 

Some steps may overlap with the other "Implement" phase stages.

Questionnaires and Checklist "Implement" Phase

Identify Critical Business Services Map Processes and Resources

Set Impact Tolerance

Conduct Scenario Testing

Improve Lesson Learnt

Find out more about Blended Learning ORA-5000 [BL-ORA-5] & ORA-300 [BL-ORA-3]

Please feel free to send us a note if you have any of these questions.