Asian Piracy and Crime Incidents Drop 65%

The number of piracy and armed robbery incidents in Asia from January to September 2016 decreased by 65% compared to the same period in 2015. A total of 59 incidents were reported during the period, including three piracy and 56 armed robbery incidents, according to the Regional Cooperation Agreement on Combating Piracy and Armed Robbery against Ships in Asia (ReCAAP).

ReCAAP emphasized that the decrease in the overall number of incidents was most evident in the Straits of Malacca and Singapore. Other improvements were reported at ports and anchorages in Bangladesh and Vietnam. In these regions, there were only two incidents from January to September 2016, compared to 96 incidents in the same period last year.

About 73% of the incidents occurred on board ships while at ports and anchorages, and 27% on ships while underway.

There was also a decrease in hijacking of ships for oil cargo theft during the nine-month period—only two such incidents occurred, compared to 12 incidents in 2015.

Although the total number of incidents has decreased, there is no room for complacency, ReCAAP emphasized. Measures must be implemented to prevent recurrence of incidents involving the abduction of crew in the Sulu Sea and hijacking ships to steal oil cargo. Crews need to be vigilant while underway and maintain watch at ports and anchorages. In addition, authorities should implement port security measures and maintain regular surveillance.


Chipotle Provides Yet More Reminders of D&O and Food Safety Risks

If the average food safety crisis or product recall forces companies to weather a storm, Chipotle has spent the past year trying to weather a category 4 hurricane. Now months into their recovery effort, it seems they are still seeing significant storm surges.
Last week, a group of Chipotle shareholders filed a federal lawsuit accusing executives of “failing to establish quality-control and emergency-response measures to prevent and then stop food-borne illnesses that sickened customers across the country and proved costly to the company,” the Denver Post reported. The suit accuses executives, the board of directors, and managers of unjust enrichment and seeks compensation from Chipotle’s co-CEOs, while also asking for corporate-governance reforms and changes to internal procedures to comply with laws and protect shareholders.

Sales remain significantly impacted by the series of six foodborne illness outbreaks last year.

The company reported in July that same-store sales fell another 23.6% in Q2, marking the third straight quarter of declines for performance even lower than analysts had predicted. The company’s stock remains drastically impacted, currently trading at about 4 compared to a high of 9 before the outbreaks came to light a year ago.

In addition to the most recent shareholder lawsuit, the bad news for directors and officers specifically has also been further compounded recently.

Shareholder lawsuits were filed earlier this year alleging the company had misled investors about its food safety measures, made “materially false and misleading statements,” and did not disclose that its “quality controls were not in compliance with applicable consumer and workplace safety regulations.” In June, a group of shareholders sued a number of top executives for allegedly violating their fiduciary responsibilities and engaging in insider trading.

Relying on insider knowledge about insufficient food safety protocols, the suit alleges that the executives sold hundreds of thousands of shares in the first half of 2015 before the food poisoning scandal was made public.

Vendor Risks: Preventing Recalls with ERM

In 2016 alone, there have been dozens of recalls, by food companies, car manufacturers, and vitamin producers, among others. Not only do these recalls greatly impact a company’s bottom line, they can also affect the health and safety of consumers. With this in mind, what can organizations—both within the food industry and otherwise—do to improve their chances of uncovering suppliers operating in subpar conditions? How can they mitigate the risk of recalls?

Customers of CRF Frozen Foods, for example, a full-line, individually quick frozen processing plant that packages fruits and vegetables for a variety of customers, recently had big problems when it was linked to a widespread listeria outbreak. Contaminated foods affected big-name distributors like Trader Joe’s, Costco and Safeway, and some customers fell ill as a result.
Even though a series of sanitation concerns and other facility issues at CRF had been exposed by regulators as early as 2014, the factory was allowed to continue operating and its customers weren’t notified.

Red flags raised by regulators aren’t always seen by the companies they’re most relevant to, however.

The fact that these outbreaks occurred seems to demonstrate that customers’ vendor management practices either failed or simply weren’t robust enough to detect issues. It all comes down to effective enterprise risk management (ERM). ERM provides the tools and framework that allow any organization to standardize processes and effectively mitigate vendor risk.

An ERM approach is characterized by standard criteria, interdepartmental communication, and automatic alerts and notifications. It keeps everyone in the organization on the same page and ensures assessment results are always understandable and accessible. This eliminates redundancy in the risk management process. As a result, you can quickly and easily determine the last time your organization evaluated a supplier. Something as simple as a notification that regulators have published new requirements might save your organization from acquiring infected or defective products.

There are three general stages that apply to any successful risk management effort:

  1. Identify specific risks, followed by assessment and evaluation
  2. Implement tailored mitigation activities to address those risks
  3. Monitor those mitigations to ensure long-term effectiveness

The first step serves as the foundation for steps two and three. Without a proper understanding of what risks your organization faces, it is impossible to prioritize and mitigate them. Especially across multiple business departments or within supply chains—it is quite difficult to identify and account for every variable.

To keep up with vendors’ fluctuating conditions, teams need to systematically identify and assess risks, catching them as they crop up. Preventing assessments from becoming obsolete is the key to keeping a pulse on everything that may affect the business, therefore avoiding unwanted surprises.

Risk assessments also help determine the best way to allocate limited resources. Minimizing vendor-related risks needn’t be burdensome, however. It should be a streamlined process that, by enabling you to avoid harmful incidents, improves operational efficiency. Once your risk assessments reveal the areas of highest priority, you can determine exactly how to mitigate those concerns.

The Freedom of Information Act can be extremely helpful when it comes to your third-party risk management efforts. It grants all companies the right to ask vendors for specific information about plant processes, worker training, sanitation practices, and maintenance. Suppliers are required to be forthcoming with all information (when asked), and teams need to take advantage of this opportunity. It is an important part of the risk management equation and will help you understand your risks before disruptions occur.

Performing vendor risk assessments—in the form of inspections, questionnaires, and service level agreements—generates an enormous amount of data and information. This information is useful for mitigating risk, but only if it is up to date, consistent and distributed to the appropriate individuals. The Freedom of Information Act provides an opportunity to evaluate suppliers with robust risk assessments, and ERM provides the means to capitalize on that opportunity. Ad-hoc assessments of current and prospective vendors, without standardized processes, will only get your team so far.

Steps to Effective ERM

Capitalizing on your vendor assessment rights is only part of the equation. Without an appropriate means of processing, distributing, and making data actionable, you’re back at square one. To make sense of important data, follow these steps:

  1. Create a taxonomy: define relationships between risks, requirements, goals, resources and processes. If each area of the business uses its own system for identifying and classifying risk, the resulting information is subjective and unusable by other departments. There is also significant information overlap—and therefore waste. Use your existing information to create a standard for data collection with minimal work.
  1. Streamline with the standardized risk assessments identified in step one. Risk assessments can be conducted in many different formats and qualities. Use resources already in place and streamline the results using the standard from step one. The most effective way to collect risk data is by identifying the root cause, or why an incident occurred. Honing in on the root cause provides useful information about what triggers loss and your organization’s vulnerabilities.
    When you link a specific root cause to a specific business process, designing and implementing mitigations is simpler and more effective.

  1. Connect mitigation activities to each of the key risks in these processes. A risk taxonomy gives you a more holistic understanding of all the moving parts in your organization. This makes it easier to design mitigation activities.
  1. Connect incidents, complaints and metrics (for each business process) to mitigation activities. Typically, companies already dedicate many resources to monitoring business performance, collecting information about incidents, complaints and metrics. These processes are often inefficient and ineffective. Simply connecting them to mitigation activities, however, identifies the reason such incidents happen. You can then take straightforward corrective actions, meeting top priorities and allocating resources with forward-looking measures. Risk management, after all, is not about minimizing fallout after an incident, but preventing such an incident from happening in the first place.

To make this entire process effective, management must work to develop an enterprise-wide risk culture. ERM is not just an executive-level process, but should be pushed all the way to frontline managers, where everyday decisions are made and the risks are known—but resources are often absent.

Approach your vendor risk assessments as you would any other risk assessment—they should be reoccurring and standardized. Perform them regularly and evaluate the results with the same scale and criteria with which you evaluate all other risks. Finally, automate information collection and review so that reporting reveals cross-silo dependencies before these risks turn into scandals. The result will be increased vendor security and the prevention of surprises, at a fraction of the cost.

New Rail Tank Car Usage Promises Safer Crude Oil Transport

Added capacity of pipelines used to transport crude oil and declining prices are contributing to decreasing transport of crude oil—and an almost 97% drop in the use of older, less safe transport cars between 2014 and the end of March, Gannett reported this week.

Rail tank car shipments of crude oil from the Bakken oil fields in North Dakota have declined from a peak of 498,271 in 2014 to 424,996 in 2015, according to the Association of American Railroads. An AAR official made the announcement at a rail tanker car safety forum sponsored by the National Transportation Safety Board, according to Gannett.

In the December 2013 report “Moving Crude Oil by Rail,” the AAR noted that the rail industry has been urging federal regulators “to toughen existing standards for new tank cars” and recommended that the estimated 92,000 existing tank cars used to transport flammable liquids, including crude oil, be retrofitted with advanced safety-enhancing technologies, or phased out if they cannot be upgraded.

While there are obvious issues with the transportation of oil by rail, the AAR has pointed out that railroads have an excellent safety record with crude, even surpassing pipelines in recent years. But the industry and federal regulators acknowledge there is much room for improvement.

The new, safer tank cars have thicker steel shells, insulating materials, full-size metal shields at each end and improved outlet valves underneath the car. Increased use of the new cars is good news for densely populated areas on the east and west coasts that have numerous trains—often of at least 100 tank cars—moving through daily.

DOT 117 train car
A transportation law, the FAST Act, signed by President Obama in December 2015, includes new mandates for freight trains transporting crude oil through the U.S. The law requires that older tank cars be replaced by the newer, safer car for shipping flammable liquids by March 1, 2018, phasing out the older model used, according to the U.S. Department of Transportation.

A rail disaster in Lac-Mégantic, Canada, on July 26, 2013, that killed 42 people brought a heightened focus on the dangers of transporting highly flammable Bakken crude oil by train.

According to the DOT, the rule also:

  • Requires an enhanced tank car standard and an aggressive, risk-based retrofitting schedule for older tank cars carrying crude oil and ethanol.
  • Requires a new braking standard for certain trains that will offer a higher level of safety by potentially reducing the severity of an accident.
  • Designates new operational protocols for trains transporting large volumes of flammable liquids, such as routing requirements, speed restrictions, and information for local government agencies.
  • Provides new sampling and testing requirements to improve classification of energy products placed into transport.