Showing posts with label Audit. Show all posts
Showing posts with label Audit. Show all posts
'Can you do "proxy approval" in this Workflow system?'
Although it is a casual word, it seems like that is used in a broad sense surprisingly.
In the Japanese government" for example, assuming the various cases, internal mandate system is in place such as "agency system", "proxy officers system" or "deputy bureaucrat system".
  • A. The person in the next positions can perform the proxy processing on a case-by-case basis, only during short-term absence, such as going out for visit.
  • B. Entrust a person for particular processing of specific tasks, only during short-term absence, such as going out for visit.
  • C. Entrust a person for the full rights of all tasks, only during the absence of long-term, such as hospitalization or travel.
  • D. Always delegating authority for processing some specific tasks.
General companies might develop a rule of delegation of decision-making authority assuming a situation in which the sales manager is too busy to login the Workflow system and cannot give approval readily.

The following decision making flow is an example of an approval flow by "Proxy approval" in A pattern above.
It is a mechanism decision-making authority will be delegated to multiple proxy as well (such as the deputy general manager and deputy general manager), when the task of official approver (sales manager) [2. approval] has been left to stand for 3 hours.

[Approval flow with after 3 hours authorization delegation]
Every business has to do with Contracts.
And, "Conclusion of a Contract" it is a very important human process, yet it is cumbersome. It requires division of labor because of specialization. Want to make it efficiently more even a little bit.

By the way, Japanese major companies demand 'Conclusion of NDA (Non-disclosure agreement)' in the beginning of a trade. However, what is written on the template is the mostly the duplication of "Unfair Competition Prevention Law" (1993). Sometimes matters about basic right as written in "Paris Convention for the Protection of Industrial Property" (1883) are added in the contract. Anyway, the company on the side of receiving the contract will be forced to 'barren work' of checking if "something strange have been written" or not.

We would want to design the business processes in mind that the Legal check includes also extremely unproductive matters like "conclusion of NDA".

# Japanese GDP might grow steadily if 'NDA templates' by all major companies had been changed to 'Let's comply with the Unfair Competition Prevention Law' only...

In the following Legal Checking Workflow, Task of [2. Approve Draft of Contract] by the Boss and [3. Approve Draft of Contract] by the Legal are able to be skipped.

[Contract flow]
'Buying a computer', 'hiring a person'...
In fact, sometimes things are promptly decided by 'Top-down', sometimes are approved from 'bottom-up'. You cannot tell whichone is always the better. However, it should be better recorded unitarily both of 'top-down decisions' and 'bottom-up approval', as decision information as an organization.

The following business process definition is an example of 'a Decision-making process' that allows recording (aside the proposer) the final decision maker, decision time, decision content, in a same format. Decisions as an organization, it is sufficient to refer to the process that has flown on it. There, it never be recorded 'top-down decisions' as if it was 'bottom-up approval'.

In this age of cloud computing, it is as a matter of course to digitize the "data of the decisions as an organization", but like this case, it is also important to assume multiple 'decisions as an organization flow' for securing organizational mobility.

# You would hardly be able to even find the "decision of the past" if you had saved the 'request for approval documents' in 'paper'.


In addition...
In Japan, there is a mechanism called 'RINGI, request for decision' the recording format of a bottom-up decision-making.

Drawn up by the authority responsible for drafting stipulated by internal regulations, after obtaining the consent of the multiplayer, will be approved by the final decision maker. For example when placement "a massive advertisement", the people responsible for drafting must create a document that is an overview of advertising or the reason why the massive advertisement is needed, and submit along with an estimate of the cost of each ad. Actually, it takes considerable time and effort to the RINGI, the request for approval, to arrive at the approver.

But from a different perspective of view, I can say the discussion about;


  • Is there really a need to "massive advertising"?
  • There might be a need to be more "massive advertising"?
  • The "risk" accompanying the ad have been supported?
  • "Effect" obtained by the ad are expected correctly?


has been done well at the time of the approval. That is, after the approval, work of advertisements placement will be processed surprisingly quickly and smoothly. In many cases, the top himself is not necessary to instruct for tasks of advertisement placement.
RINGI is a mechanism that has been deeply supported by Japanese companies, and it would survive enduringly in the future.


[Procurement Approval flow]

In the manufacturing industry and the construction industry or B2C business, FAX is still active.
Here, we would like to introduce a mechanism to automatically send FAX of the "business documents in a workflow" via the Internet. When all is said, FAX sender achieve Paperless. In addition, all FAX transmission related information such as transmission date-time and transmitting data, will be as are recorded automatically! (Easy visualization to Operational efficiency indicators as well.)

It may sound cool somehow, but calmly thinking, it is wrong that the fact that the routing of
  1. Printout by the MFP, then
  2. Scan the paper and send a FAX by the same MFP
has not been eradicated until now, in this year of 2012 which "2001: A Space Odyssey" of course is supposed to be finished even "2010: Odyssey Two".

[Internet FAX Outbound]

Internet FAX - SaaS Workflow

Monday, September 10, 2012
'I don't need fax anymore!' (anachronism)

Yeah, that's right!
That's right, okay, but... we still need it...

Although many companies and enterprises dismiss 'FAX machine to waste paper', but they are introducing the "Internet FAX". There are various services provided in Japan such as eFax, BizFAX, D-FAX, Paperless FAX or Toones. Simply, you can save the FAX machine Price / Supplies expense / Communication expense. Needless to say, it is easy to circulars and to save.

Furthermore here, we would like to introduce a sample to efficiently process 'received FAX' (Image data).

[Internet FAX]
'Obtaining multiple quotations', it is quite a day-to-day work.
In particular, there is price competition between distributors such as electricity products and moving services . The ordering side, basically makes a contract to trader who gave quote less expensive.
On the other hand however, it is not so simple to compare companies such as consign System Development or Designing, by price. Because they have differences of "level of recognition on order side company situation", and also they have likes and dislikes.

Well honestly,,, I don't think this business template is ready to use, because situation of procurement is different between the companies. Yet, I sincerely would like you to establish a Workflow of "Competitive Quotations and Vendor Selection flow".
At least, it is tremendously significant to record progress from 'multiple Quotations' to 'vendor selection' and 'the final contract'. When you count to ten contracts recorded, you will see various 'problems'.

In the Workflow below, the procurement personnel who collects quotations from vendors, is different to evaluation personnel who selects a vendor by their quotations. You can call it a Workflow definition that prevent fraudulent transactions.

[Competitive Quotations and Vendor Selection flow]


Want to "move" to new system with "business data" of the past, together ?
It's the 'migration' that most of SIers hate. Customers of Questetra often ask question about it.

However...
In the first place, "the date of processed" of each Tasks is that important. It doesn't make much sense to move "business data" as final deliverable alone. No, rather you shouldn't move 'business data' at all... (Whoops, I shouldn't be curt that way. Some people want solution seriously.)

If you do want to migrate "business data" in your workflow to your new system, you've got to do is to setup a 'data spout'. For a concrete example, I will show you a process model in my latest article "Learn BPMN by 'Daily Report'". The workflow definition (Workflow Diagram) below looks like the same as the one before at a glance. But there added one strange Start point.


[Daily Report flow - Record Tasks]

The Workflow notation nowadays are easy to understand. (BPMN)
The most fascinating point is 'anyone can understand flow of works at first sight'. And it's also good that it is 'World's standard' De facto.

But in the other hand...
Employees who work on site can participate in the discussion, and exchange hot debate about 'Workflow to be'. As the result, Process owners will be in the situation that their adjusting ability to be asked. That's right, they can't be helped because it is what they are working for, but they can get Knowledge armament by reading "The Golden Rules of Business Process Modeling". Yes, BPMN is also an 'discussion tool'.

Now...
There is a request on Decision Making Flow, that an approver himself can add other approver before the approval. There are somebody to be asked to approve, even by the regulation (Business rule) does not require to do so. Behind-the-scenes work, or NEMAWASHI in Japanese... Well now, what you do?


[Decision Making Flow]

Whistle-blower on "Anonymous Web Form"

Monday, September 19, 2011
Nobody would deny the thought of "Regulations document is important for corporate compliance". On the other hand, it is not realistic to all employees to get interested in the "Charter" or "Regulations" continuously.

1.To maintain a compliance system.
2.The essence: All the employee must comply "Constitution and laws".
3.The policy: "Mutual Surveillance system" should be built.
4.The method: Install "Accusation forum" which acknowledged throughout company.

This way of thinking is right. Establishing a postbox inside company will do. But thinking on "stress on posting" and "troublesome on collecting", it would be better done online. There will be no "Lost" or "Hushed up".

<Tasks>
1. Post, 2. Check Post, 3. Survey & Statement, 3a.Respond Question, 4. Bulletin Answer

Secureness for Password Reissue

Monday, September 5, 2011
Working on ID & password issue seems subdued, but it is extremely important. Failure in the operation may cause "Information leakage" or " information system hijacking", which may disrupt even business continuity. At least issuance logs should be exactly recorded.

The following Workflow model is for

  • A. a case of "automatic start" by "Workflow for pre-employment training program" of Personnel Department.(New ID issuance)
  • B1. a case "Applieed" ID for temporary employment.(New ID issuance)
  • B2. a case of "Forgotten Password" or "Change Account name" (Issued ID update)

Case 'A.'is on Trans-Workflow connection, 'B.'is on Web form connection. (Process model connecting API)

As a matter of course, talking over account issuance or re-issuance, we also must talk about "deletion". We will talk in some other time.

<Tasks>
0. Approver Nomination, 1. Approval, 2. Authorization Code issuance, 3. Input from Hearing, 4. Check P.W.Change, 5.Confirmation

[Password issue: [2. Authorization Code issuance] screen]


In Japan after the earthquake, products and services related with BCP are in "emergency demands". Demands for Cloud-related products are growing also in IT industry. (Everyday we find in newspapers such words of "electricity saving"and "telecommuting" and "BCP")

BCP stands for Business Continuity Plan. Compare to "Contingency Plan", BCP defines actions that "action in order to recover the business" in relatively long-term, whereas Contingency Plan is focused on "actions in emergency"

But creating "business continuity plan" is not easy. It is necessary to consider during peacetime "How should major operation processes be recovered"on assumed scenarios such as "blackout" or "traffic network breakdown". So to consider this, not only one must be familiar with the flow of operation in peacetime, in some cases he also will be required consideration of the perspectives advanced management.

The following is a Workflow model "to prepare for Workflow under assumed condition"

<Tasks>
1. Workflow and Assumption, 2. Study Flow chart, 2b. Discussion, 3. Review, 4. Confirmation

[Creating Flow chart: "2.Study Flow chart" screen]


It's easier to understand SFA systems if you understand daily sales activities to be "continuous maintenance of customer information." This is because sales members are constantly collecting data on customer needs and wants, regardless of whether they are new customers or old.
FYR: Building an SFA System INSIDE a BPM System

Using this maintained information in estimate processes, proposal processes, agreement processes, etc., helps to eliminate input. Initiating smaller processes using copied data from the primary process also eliminates careless mistakes and send-backs. When you're not sure whether you will be using all the information, just go ahead and send all the information. The below workflow sample is a contract check workflow.
Similar article: Visualizing if estimates have posted properly

<Tasks>
1. Input Contract, 2. Approve Contract, 3. Discuss Contract Content, 4. Signature and Seal

[Contract Check <Supervisor Approval>: "Input Contract" screen]

We introduced a workflow for Taking Data Outside the Office in the Era of Cloud Computing, but you don't want to grant and cancel temporary authorization manually. Naturally, the authorization settings for accessing data files depends on the system that manages those files. For example, if your company uses Google Apps as an internal platform, it will be necessary to use Google Documents APIs. (We must borrow the power of SE.)

* Google Documents List Data API v3.0 (Labs) - Modifying Document and Folder Sharing Permissions
* Google Documents List Data API v2.0 - Modifying Document Sharing Permissions


Tasks: Apply for Authorization to Access, 2. Give Temporary Authorization, 3. Handle Rejection, 4. Report Action, 5. Cancel Authorization, 6. Confirm Cancellation


[Data Access <Change External Authorization>: "4. Report Action" screen]

Can data saved in the "Cloud" be taken out freely?
It is only a matter of time before Cloud computing hits mainstream. The era of limiting locations (headquarters, plants, call centers, etc.) used VPN technology to keep things closed even when separated. However, today's hot words are telecommuting and Cloud computing. We have to reconsider the problem of carrying data outside the office from scratch.

As one opinion, we offer the below four principles to work from, with a perspective of optimizing work (continuance of current work, using teleworking, assuming global businesses) and handling natural disasters.
[Centralization] Data should be centrally managed on the Cloud.
[Control] Authorization to access each data should be kept at the bare minimum.
[Log] Every reference and browsing of data should be recorded and logged.
[Education] Duplicating data to local disks or media should be prohibited (personal education).

Today let's introduce a workflow for giving temporary permission to browse particularly sensitive data.


Tasks: 1. Apply for Authorization to Access, 2. Give Temporary Authorization, 3. Handle Rejection, 4. Report Action, 5. Cancel Authorization


[Data Access <Confirm Cancellation>: "2. Give Temporary Authorization" screen]

In regards to security management, employees should not take data and computers outside the office. But when it is absolutely unavoidable for telecommuting or outside work, the important points are "prior application" and "appropriate follow-ups." The below workflow is modeled after a paper-based "permission to take out data" form, and automatically records who took out what computer or USB memory, when, for what reasons, etc.

* We'll talk more about the discussion of carrying data outside the office in the era of Cloud computing tomorrow.


Tasks: 1. Apply for Authorization to Transport Data, 2. Approve Authorization, 3. Handle Rejection, 4. Report Action


[Permission to Transport Data <Confirm Follow-up>: "2. Approve Authorization" screen]

Using Your iPad for Audit Inspections

Tuesday, February 8, 2011
Internal auditing processes should be continuously reviewed, to ensure they don't end up being a system that ends with the identification of problems.

As we discussed in "Facilitating Internal Auditing," digitizing auditing outputs alone makes aggregating and storing the results much easier. Now let's think about an internal inspection that has to be conducted multiple times a month, and that uses a fixed set of questions... Wouldn't it be nice to be able to integrate the questions into the workflow? That would eliminate the need to upload files each time, and would also enable complex monitoring of the results. Depending on the workflow product you use, you may be able to use an iPad or other type of tablet device to directly input inspection results and submit with a "tap of the finger."

Quality Management Simple Check



Facilitating Internal Auditing

Monday, February 7, 2011
Companies tend to have a lot of stuff to do internal auditing on—performance, quality, environmental impact, etc. You may already know about the influence of an environmental management system (ISO 14000 family) and quality management system (ISO 9000 family), and possibly the increasingly popular information security management system (ISMS, ISO 27000 family).

Of course, you can just make checklists to go through and cross out, but managing everything on paper slows things down and costs a lot just to aggregate the results. That's why it's good to use an efficient information system.