<?xml version="1.0" encoding="ISO-8859-1"?>
<rss version="2.0">
	<channel>
		<title>The Risk Briefing</title>
		<link>http://www.assentriskmanagement.co.uk/blog/index.php</link>
		<description><![CDATA[Copyright Assent Risk Management]]></description>
		<copyright>Copyright 2012, Assent Risk Management</copyright>
		<managingEditor>Assent Risk Management</managingEditor>
		<language>en-US</language>
		<generator>SPHPBLOG 0.5.1</generator>
		<item>
			<title>Verify your Supply Chain with Supplier Audits</title>
			<link>http://www.assentriskmanagement.co.uk/blog/index.php?entry=entry120501-124859</link>
			<description><![CDATA[<b>Why Audit the Supply Chain?</b><br />It can be very difficult to know if your supply chain is operating in line with the policies and procedures of your business, as each supplier operates independently under its own governance.<br /><br />However, as a buyer, you may be able to identify opportunities to coordinate the supply chain, achieve cost savings and meet your own environmental or other objectives.<br /><br />An audit of the supply chain can encompass:<br />- Environmental impact.<br />- Information security.<br />- Data protection compliance.<br />- Business continuity plans.<br />- Social impact.<br />- Technology compatibility.<br />- Knowledge and cross training.<br />- Price and value.<br /><br />For example, software can be a point of failure, as compatibility and version issues arise causing extended cost and delivery times.<br /><br /><b>ISO 28000 - security management systems for the supply chain</b><br />ISO have also looked at security for the supply chain, providing a framework for managing risk and planning for deliberate or environmental threats.  Ultimately aiming to minimise disruption.<br /><br /><b>An Impartial Audit </b><br />Outsourcing the verification and monitoring of your supply chain has many benefits.  Our auditors can design a programme to meet your verification and monitoring requirements, using some or all of the factors listed above.<br /><br />We will ensure that the auditors are completely independent of your supply chain, so you can be assured that there are no conflicts of interests.  The findings of our audit will be based on no-bias sampling as per the audit programme.<br /><br />Contact us on 020 3432 2854 for more information.]]></description>
			<category>General</category>
			<guid isPermaLink="true">http://www.assentriskmanagement.co.uk/blog/index.php?entry=entry120501-124859</guid>
			<author>Assent Risk Management</author>
			<pubDate>Tue, 01 May 2012 11:48:59 GMT</pubDate>
		</item>
		<item>
			<title>Grants for Manufacturers to implement ISO Standards.</title>
			<link>http://www.assentriskmanagement.co.uk/blog/index.php?entry=entry120412-132655</link>
			<description><![CDATA[Manufacturing companies in England could be eligible for up to 50% funding to implement ISO management systems including <a href="http://www.assentriskmanagement.co.uk/iso9001/" target="_blank" >ISO 9001 Quality Management</a> and <a href="http://www.assentriskmanagement.co.uk/iso14001/" target="_blank" >ISO 14001 Environmental Management</a>.<br /><br />The scheme is provided by the Manufacturing Advisory Services (MAS) for Small/Medium sized manufacturing businesses to help them achieve their ambitions and increase their abilities.<br /><br />ISO standards are internationally recognised and provide a competitive advantage when tendering for larger contracts.  There are many other benefits to implementing a management system, which provides a structured approach to quality assurance and controlling the company&#039;s impact on the environment.<br /><br /><b>Easy To Apply</b><br />If you are considering implementing ISO standards in your manufacturing business, we are offering free assistance to apply for funding as part of our quoting process.<br /><br /><a href="http://www.assentriskmanagement.co.uk/contact/" target="_blank" >Contact us</a> to find out how we can help your business move forward with funding from MAS.]]></description>
			<category>General, Health and Safety, Environmental, Quality</category>
			<guid isPermaLink="true">http://www.assentriskmanagement.co.uk/blog/index.php?entry=entry120412-132655</guid>
			<author>Assent Risk Management</author>
			<pubDate>Thu, 12 Apr 2012 12:26:55 GMT</pubDate>
		</item>
		<item>
			<title>Is PAT testing Electrical Equipment a Legal Requirement?</title>
			<link>http://www.assentriskmanagement.co.uk/blog/index.php?entry=entry120410-120312</link>
			<description><![CDATA[A recent call from a panicked client has led to this blog post regarding PAT testing.<br /><br /><b>Portable Appliance Testing (PAT)</b>, is a process of periodically testing electronic devices to ensure they are maintained and safe for use.  <br /><br />If a device has been PAT tested you will usually find a sticker on the plug, which has the date of the last test.  <br /><br />This formal process of regular inspection and testing has clear advantages for reducing risks associated with electronic devices in the workplace.  However, I often hear PAT testing quoted as a legal requirement for businesses.  This is incorrect.  <br /><br /><b>Electrically Safe - The Law</b><br />Regulation 4(2) of the Electricity at Work Regulations 1989 says<br /> <blockquote>&quot;As may be necessary to prevent danger, all systems shall be maintained so as to prevent, so far as is reasonably practicable, such danger&quot;</blockquote><br /><br />The Health and Safety Executive (HSE) provides a useful leaflet to help you manage electrical risk in your workplace.  In offices and low risk environments, often a visual inspection is all that is required, however with some portable devices, testing may be more appropriate to ensure it&#039;s safety.<br /><br />Think carefully about the best way to manage this risk using the HSE&#039;s advice, PAT testing or both.<br /><br /><b>References</b><br /><br />HSE <i>PAT - Portable appliance testing FAQs</i> - May 2012. <a href="http://www.hse.gov.uk/electricity/faq-portable-appliance-testing.htm" target="_blank" >http://www.hse.gov.uk/electricity/faq-p ... esting.htm</a><br /><br />HSE Guidance Leaflet, <i>Maintaining portable electric equipment in office and other low risk environments</i> - April 2011. <a href="http://www.hse.gov.uk/pubns/indg236.pdf" target="_blank" >http://www.hse.gov.uk/pubns/indg236.pdf</a><br /><br />HSE Article, <i>Myth: All office equipment must be tested by a qualified electrician every year</i> - July 2007. <a href="http://www.hse.gov.uk/myth/july.htm" target="_blank" >http://www.hse.gov.uk/myth/july.htm</a>]]></description>
			<category>Health and Safety</category>
			<guid isPermaLink="true">http://www.assentriskmanagement.co.uk/blog/index.php?entry=entry120410-120312</guid>
			<author>Assent Risk Management</author>
			<pubDate>Tue, 10 Apr 2012 11:03:12 GMT</pubDate>
		</item>
		<item>
			<title>Business Continuity Planning for Letting Agents</title>
			<link>http://www.assentriskmanagement.co.uk/blog/index.php?entry=entry120402-115308</link>
			<description><![CDATA[<b>The Obvious</b><br /><br /><i>Scenario: The office has burnt down/flooded/been broken in to and all our data is lost.</i><br /><br />It&#039;s important to know your data is back up and available off site, should your main place of business be compromised.<br /><br />It&#039;s also wise to consider: <br />- an alternative place to trade from, <br />- how to redirect the telephones,<br />- how to communicate any issues to landlords and tenants.<br /><br /><b>The Not So Obvious</b><br /><br /><i>Scenario: A natural disaster has damaged a large number of properties on our books.</i><br /><br />If you browse the properties you manage, you will probably find that they are all within a close proximity to each other, and your lettings office.  <br /><br />While this is convenient for everyone most of the time, it could leave you vulnerable in the event of a natural disaster.  <br /><br />For example, the great storm of 1987, which was famously unexpected by weather forecasters, left many properties with damage to fences, roofs, windows and worse.  <br /><br />While letting agents are insured for such events, realistically, how many are capable of quickly responding to these incidents, particularly when the trades people required will be in such high demand.<br /><br />Therefore a prudent letting agent will have invested some time in making a business continuity plan that addresses questions such as:<br /><br />- Who are our suppliers?<br />- How good is our relationship with our suppliers and is it formalised?<br />- Do we have alternative suppliers available, if we need extra capacity?<br />- How will we manage the increased calls from tenants?<br />- How will we staff the office?<br /><br /><b>More Information</b><br /><br />If you require some help producing a business continuity plan, call our consultants on 020 3432 2854<br /><br />See also: <a href="http://www.assentriskmanagement.co.uk/bs25999" target="_blank" >BS25999 standard</a>.<br />]]></description>
			<category>Information Security</category>
			<guid isPermaLink="true">http://www.assentriskmanagement.co.uk/blog/index.php?entry=entry120402-115308</guid>
			<author>Assent Risk Management</author>
			<pubDate>Mon, 02 Apr 2012 10:53:08 GMT</pubDate>
		</item>
		<item>
			<title>What Data is Covered by the Data Protection Act?</title>
			<link>http://www.assentriskmanagement.co.uk/blog/index.php?entry=entry120315-104845</link>
			<description><![CDATA[While almost every business in the UK is required to notify the Information Commissioner under the data protection act, many are unclear as to what data is being protected.<br /><br />Of course, it is good practice to protect all data relating to the business, it is also important to know your statutory obligations under the Data Protection Act.<br /><br />&quot;Personal Data&quot;<br />The act is intended to regulate &quot;Personal Data&quot;, which is defined in the act as quoted below:<br /><br /><blockquote>Personal data means data which relate to a living individual who can be identified –<br /><br />(a) from those data, or<br /><br />(b) from those data and other information which is in the possession of, or is likely to come into the possession of, the data controller,<br /><br />and includes any expression of opinion about the individual and any indication of the intentions of the data controller or any other person in respect of the individual.<br /></blockquote><br />Even if a reference number or other code is used in place of a name, it will still be &quot;personal data&quot; covered by the act if there is a method of identifying the individual, whether that method is classed as &#039;data&#039; or not. <br /><br />Common &quot;personal data&quot; stored by companies include:<br />Employment and Payroll information.<br />Employee medical information.  <br />Customer delivery addresses<br />Feedback from customers.<br />Personal contacts within a company, for example emails and letters marked to the attention of.<br /><br />As part of a structured information security management system, data protection act compliance can be easily measured and managed.  <br /><br />For help with your Data Protection Act Notification or implementing a ISO 27001 Information Security Management System contact our consultants on 020 3432 2854.<br /><br /><b>References</b> <br />Key definitions of the Data Protection Act - <a href="http://www.ico.gov.uk/for_organisations/data_protection/the_guide/key_definitions.aspx" target="_blank" >http://www.ico.gov.uk/for_organisations ... tions.aspx</a><br /><br />Data Protections Services at Assent - <a href="http://www.assentriskmanagement.co.uk/dataprotection/" target="_blank" >http://www.assentriskmanagement.co.uk/dataprotection/</a><br /><br />ISO 27001 - <a href="http://www.assentriskmanagement.co.uk/iso27001/" target="_blank" >http://www.assentriskmanagement.co.uk/iso27001/</a><br />]]></description>
			<category>Information Security</category>
			<guid isPermaLink="true">http://www.assentriskmanagement.co.uk/blog/index.php?entry=entry120315-104845</guid>
			<author>Assent Risk Management</author>
			<pubDate>Thu, 15 Mar 2012 10:48:45 GMT</pubDate>
		</item>
		<item>
			<title>How Green is the Cloud? CEEDA, ISO14001, ISO50001</title>
			<link>http://www.assentriskmanagement.co.uk/blog/index.php?entry=entry120313-104841</link>
			<description><![CDATA[The word &#039;Cloud&#039; has gained new meaning in recent years, as a string of Internet based services have arisen including:<br /><br /><blockquote><b>SAAS</b> - Software as a Service, web based applications run from data centres rather than your PC.<br /><b>IAAS</b> - Infrastructure as a Service, virtualised systems taking advantage of bandwidth, processing and memory on a scalable basis.<br /><b>Social Media</b> - Web based communities that are occurring in everyday life.<br /><b>Media Streaming</b> - Services that provide TV and movies on our Internet enabled devices.<br /></blockquote><br /><b>This all raises the question. How Green is the &#039;Cloud&#039;?</b><br /><br />We once saw a statistic which claimed every two Google searches produces the same amount of CO2 as boiling a kettle.  <br /><br />Among the various schemes and tools available to measure and address energy efficiency in data centres is an offering from BCS, The Chartered Institute for IT.  <br /><br /><b>CEEDA - Certified Energy Efficient Data Centre Award</b> sets out to verify the measures implemented by an organisation with three award levels: Bronze, Silver, Gold.  <br /><br />It uses the &#039;EU Code of Conduct for Data Centres&#039; as the foundation for best practice and assessment, adding a &#039;continual improvement&#039; element similar to standards issued by ISO.<br /><br />CEEDA can be applied internationally and has the advantage of being externally verified by the trained assessors.  <br /><br />For further information on CEEDA, please see references below.<br /><br /><b>Going Greener</b><br />There are plenty of other steps that can save energy and money.  In order to manage something, it needs to be measured, and this can be done in various ways.  <br /><br />For example, the <a href="http://www.assentriskmanagement.co.uk/iso50001" target="_blank" >ISO 50001</a> Energy Management Standard sets a framework for taking a baseline energy measurement and setting objectives for reducing consumption.<br /><br /><a href="http://www.assentriskmanagement.co.uk/iso14001" target="_blank" >ISO 14001</a> Environmental Management takes a broad look at aspects of the business which impact the environment and, again, requires objects set to for continue improvement.<br /><br />For more information, contact us on 020 3432 2854.  <br /><br /><b>References</b><br /><br /><b>Official CEEDA Websites</b><br />CEEDA Website: <a href="http://www.ceeda-award.org" target="_blank" >http://www.ceeda-award.org</a><br />BCS, The Chartered Institute for IT: <a href="http://www.bcs.org" target="_blank" >http://www.bcs.org</a><br /><br /><b>External Contacts (Not Affiliated to Assent)</b><br />David Carter CEEDA Relationship Manager at DCD - <a href="http://www.datacenterdynamics.com" target="_blank" >http://www.datacenterdynamics.com</a><br />John Booth @Carbon3IT - <a href="http://www.carbon3it.com" target="_blank" >http://www.carbon3it.com</a><br /><br /><b>Other</b> <br />Two Google searches &#039;produce same CO2 as boiling a kettle&#039;, The Telegraph <a href="http://www.telegraph.co.uk/technology/google/4217055/Two-Google-searches-produce-same-CO2-as-boiling-a-kettle.html" target="_blank" >http://www.telegraph.co.uk/technology/g ... ettle.html</a><br />Power Usage Effectiveness (PUE) and Data Centre Infrastructure Efficiency (DCiE): <a href="http://www.assentriskmanagement.co.uk/blog/index.php?entry=entry110218-161859" target="_blank" >http://www.assentriskmanagement.co.uk/b ... 218-161859</a><br />]]></description>
			<category>Environmental</category>
			<guid isPermaLink="true">http://www.assentriskmanagement.co.uk/blog/index.php?entry=entry120313-104841</guid>
			<author>Assent Risk Management</author>
			<pubDate>Tue, 13 Mar 2012 10:48:41 GMT</pubDate>
		</item>
		<item>
			<title>Opportunities in the Motor Industry with ISO/TS 16949</title>
			<link>http://www.assentriskmanagement.co.uk/blog/index.php?entry=entry120306-143856</link>
			<description><![CDATA[Today&#039;s announcement that car maker Nissan is to build a new model at it&#039;s factory in Sunderland was welcome news for the North, and the UK. <br /><br />It&#039;s estimated that 2,000 jobs will be created with 1,600 of those being in the supply chain.  This is fantastic news for small manufacturing businesses, but how can they stand the best chance of winning work with one of the worlds biggest car makers.<br /><br />One way to be competitive is to implement an Automotive Quality Management System and achieve certification to ISO 16949.  <br /><br />The automotive industry recognises ISO/TS 16949 certification in the tendering process, and implementing the system can help you operate more efficiently.  Similar to ISO 9001, there are many benefits to controlling the quality of your output.<br /><br />Assent has consultants with industry specific experience and we can guide you through the process of achieving certification with a recognised body.<br /><br />For more information, contact us on 020 3432 2854.<br /><br /><b>References</b><br /><br />ISO/TS 16949 Automotive Quality Management: <a href="http://www.assentriskmanagement.co.uk/iso16949/" target="_blank" >http://www.assentriskmanagement.co.uk/iso16949/</a><br /><br />PJC Consultancy - Aerospace and Automotive: <a href="http://www.peterjclements.co.uk/about/" target="_blank" >http://www.peterjclements.co.uk/about/</a><br /><br />BBC News, Nissan to build new car in Sunderland: <a href="http://www.bbc.co.uk/news/business-17266087" target="_blank" >http://www.bbc.co.uk/news/business-17266087</a><br /><br />For Tendering Advice and Services: <a href="http://www.assentriskmanagement.co.uk/blog/comments.php?y=12&amp;m=02&amp;entry=entry120206-104003" target="_blank" >http://www.assentriskmanagement.co.uk/b ... 206-104003</a>]]></description>
			<category>Quality</category>
			<guid isPermaLink="true">http://www.assentriskmanagement.co.uk/blog/index.php?entry=entry120306-143856</guid>
			<author>Assent Risk Management</author>
			<pubDate>Tue, 06 Mar 2012 14:38:56 GMT</pubDate>
		</item>
		<item>
			<title>Social Responsibility - 7 Core Subjects</title>
			<link>http://www.assentriskmanagement.co.uk/blog/index.php?entry=entry120301-145258</link>
			<description><![CDATA[Organisations and their stakeholders are becoming more aware of their need to behave responsibly and consider their impacts on Human Rights, the Environment and Ethical/sustainable behaviour.<br /><br />There are several standards, guidelines and tools which address corporate social responsibility, here we take a brief look at the voluntary International Standard, ISO 26000:2010, Guidance for social responsibility.<br /> <br />ISO26001 is not a &#039;management system&#039; standard and there is no certification for it.  It is intended to help organisations of all types and sizes contribute to sustainable development.  <br /><br />The standard defines 7 core subjects for social responsibility which are interdependent:<br />6.2 Organisational Governance<br />6.3 Human Rights<br />6.4 Labour Practices<br />6.5 The Environment<br />6.6 Fair Operating Practices<br />6.7 Consumer Issues<br />6.8 Community Involvement and Development<br /><br />Within each of these core subjects, the standard identifies issues which should be addressed.<br /><br />ISO26000 can be used in conjunction with other measures implemented by a company to managed it&#039;s corporate social responsibilities (CSR)<br /><br /><b>Poor working Conditions in Apple&#039;s Supply Chain?</b><br />In early 2012, technology company Apple made an unusual move and released a list of it&#039;s suppliers in an attempt to  deal with poor working conditions in Asian factories that supplied Apple components.<br /><br />Its said, they conducted 229 supplier audits over the previous year and found various areas for improvement, which the company is now addressing.  <br /><br />Perhaps bold for such a large corporate to admit failings in order to progress to a sustainable supply chain.<br /><br /><b>References</b><br />ISO26000:2010 standard page: <a href="http://www.iso.org/iso/iso_catalogue/management_and_leadership_standards/social_responsibility/sr_discovering_iso26000.htm" target="_blank" >http://www.iso.org/iso/iso_catalogue/ma ... o26000.htm</a><br /><br />7 Core Subjects poster:<br /><a href="http://www.iso.org/iso/sr_7_core_subjects.pdf" target="_blank" >http://www.iso.org/iso/sr_7_core_subjects.pdf</a><br /><br />BBC News, <i>Apple publishes supplier details for the first time</i>: <a href="http://www.bbc.co.uk/news/business-16570765" target="_blank" >http://www.bbc.co.uk/news/business-16570765</a>]]></description>
			<category>Social Responsibility</category>
			<guid isPermaLink="true">http://www.assentriskmanagement.co.uk/blog/index.php?entry=entry120301-145258</guid>
			<author>Assent Risk Management</author>
			<pubDate>Thu, 01 Mar 2012 14:52:58 GMT</pubDate>
		</item>
		<item>
			<title>Processes and Process Auditing</title>
			<link>http://www.assentriskmanagement.co.uk/blog/index.php?entry=entry120209-123359</link>
			<description><![CDATA[The concept of a &quot;processes&quot; is key in many management systems, frameworks and theories.  <br /><br />A process is a &quot;set of interrelated or interacting activities which transforms inputs to outputs&quot;.  ISO9001<br /><br />A process &quot;may define policies, standards, guidelines, activities or work instructions if they are needed&quot;. ITIL (Service Strategy).<br /><br />There are particular characteristics you would expect to find in an efficient and effective process such as:<br />- Defined actions.<br />- Measurable in terms of cost or quality.  Duration or productivity.<br />- Deliver specific identifiable and countable results.<br />- Have customers/stakeholders who have expectations of the results of the process.<br />- React to events in terms of a trigger.<br /><br /><b>Why use Process Auditing? </b><br />Audits use sampling due to time and practical restraints. <br /><br />Process auditing usually makes the best use of the time available, as a process is often confined to a small area in the business, for example the HR process is in one office and the Accounts process is in another.  This way each process can be assess against all relevant parts of the audit without having to visit areas several times during the audit.  <br /><br />We can also get a good idea about how the processes connect, by planning the audit to move from one to the next.<br /><br /><br /><b>Why have an Audit?</b><br />The main reasons you may wish to audit are:<br />- To verify a process is operating as intended.<br />- To identify improvements to a process.<br />- To achieve ISO certification.<br /><br />Contact us for more information on auditing: 020 3432 2854.]]></description>
			<category>General</category>
			<guid isPermaLink="true">http://www.assentriskmanagement.co.uk/blog/index.php?entry=entry120209-123359</guid>
			<author>Assent Risk Management</author>
			<pubDate>Thu, 09 Feb 2012 12:33:59 GMT</pubDate>
		</item>
		<item>
			<title>Win Public Sector Contracts with Accreditations</title>
			<link>http://www.assentriskmanagement.co.uk/blog/index.php?entry=entry120206-104003</link>
			<description><![CDATA[<b>The Benefits</b><br />The rewards of public sector tendering are plentiful with over £236 Billion spent in the year 2009/2010.<br /><br />2500 Contract Notices are published each week and 25% are awarded to Small and Medium Sized Enterprises (SMEs).<br /><br />Unfortunately many businesses do not take full advantage of these opportunities because they are unclear about the process and how to answer the many intimidating questions.<br /><br />Achieving accreditations and ISO certification is a great way to demonstrate your commitment and capabilities but it only forms part of the tendering process.<br /><br /><b>Register for Tender Alerts</b><br />It is mandatory that public sector contracts above £173,934 are publicly released. However, many contracts far below this value are put through the same channels.<br /><br />There are many services that distribute tender notices at varying costs.<br /><br /><b>Pre - Qualification Questionnaire [PQQ]</b><br />If you then decide to apply for a contract the next step will be the PQQ.  This can be a daunting document and you may wish to seek advice on how to answer the questions to ensure you represent your company well.<br /><br />The PQQ gives the awarding authority an opportunity to filter applicants into a short list and, at this stage, accreditations play a vital role!<br /><br /><b>Invitation To Tender [ITT]</b><br />If you successfully reach a short list you may be invited to tender.  At this stage the authority is more concerned with the &quot;what, where, when and how&quot; of your service delivery.<br /><br />This is a good time to seek advice and guidance if you are unsure how to respond.<br /><br /><b>Tender Award</b><br />After successfully completing the process you will be awarded the contract and it&#039;s time to deliver. Don&#039;t miss the opportunity!<br /><br />Thank you to <b>Tender Assist</b> for their input into this article.  Tender assist can help your business tender for public sector contracts. <br />Contact 01438 861931 or visit <a href="http://www.tenderassist.co.uk" target="_blank" >www.tenderassist.co.uk</a> for details.<br />]]></description>
			<category>General</category>
			<guid isPermaLink="true">http://www.assentriskmanagement.co.uk/blog/index.php?entry=entry120206-104003</guid>
			<author>Assent Risk Management</author>
			<pubDate>Mon, 06 Feb 2012 10:40:03 GMT</pubDate>
		</item>
	</channel>
</rss>

