21 January 2020

Convincing Boards to focus on Cyber Security is no easy task, when...

Convincing Boards to focus on Cyber Security if no easy task, when those working in the business have priorities, responsibilities and rewards specifically structured to make Cyber Security a lower priority. Convincing Boards starts from the "middle" and must work both "down" and "up", and it will not be an easy or fast process.

I recently spoke to the CRSA (Control Risk Self Assessment) Forum in London, hosted at the IRM's offices (with thanks to Carolyn Williams), and very ably organised by Paul Moxey. My desire was to highlight the challenges that management (operational to the C-suite) face, and the decisions that must be taken, many of which lead to a de-prioritisation, or even ignoring, of Information Security.

This is not to suggest that Information Security should be de-prioritised, far from it. But the purpose was to highlight the difficulties that the Risk Professional will have in gaining the internal support to both raise and then to gain resources required for effective InfoSec.

To encourage the participants to consider (and actually, engineer scenarios in which InfoSec would lose out to other priorities) I provided two "role-plays". A very quick caveat; neither case represented a real company or actual situation, but was built from a wide range of situations I have been party to or have been the Internal Auditor or Risk Manager associated with elements of the case.

Role-Play 1: "Complex project choices"

The first looked at project level issues and delivery concerns leading to a situation in which InfoSec, while critical, was actually "pushed into the long grass" by each group that considered the case.

You can "enjoy" the role-play case study here.

The constructed problem centres around the competing constraints facing any business when it comes to systems implementation. The various strains on all members of a project team, including the leadership, sponsor, and steering committee, require to balancing of resources and priorities. Sometimes individual incentives outweigh the needs of the business. While this is not acceptable, it is a reflection of the reality of motivating people, and in some cases, focusing those people on outcomes that they are responsible to deliver.

When participants received the "role-play", there were more than a few people saying "I've worked on this project".

The premise was fairly simple; the project is in its final stages but has run over budget (Quelle surprise) and over time: and the user community's level of frustration is rising to breaking point. The infrastructure model is not adequately integrated into the corporations secure environment, and the additional time and cost will push the project further over budget and time.

The groups were then asked, each playing a specific role, to provide a recommendation, as a group.

As expected (and constructed), not one of the groups said that project implementation should be delayed until security concerns were addressed. In one group, the person playing the role of the IT Infrastructure representative threatened to "call Internal Audit" to which there was a response, "So you plan to stab your colleagues in the back?"

Others proposed setting up a working group to assess and recommend addressing the security and infrastructure issues after the project, while acknowledging that this would become, in effect, a new project fight for resources against all other projects. But it wouldn't impact their ability to deliver what they were required to deliver.

The final takeaway for participants was that it will be difficult to gain the internal allies required to address security if their support will be counter to their own needs, responsibilities and rewards.

Role-Play 2: "The C-Suite and External Expectations"

Likewise, at the C-Suite level, internal and external expectations can be such that investment in Cyber Security becomes a secondary consideration behind meeting the short-term demands of shareholders, markets or owners. This Role-Play set out to demonstrate the push and pull of competing requirements, again against a backdrop of systems implementation coupled with quarterly reporting needs, in challenging market conditions.

Take a look at the Role-Play here.

The four participants (the COO, CFO, CIO and Director of Communications) each have competing priorities, yet all are also keenly interested in ensuring company success.

Read the Role-Play and decide for yourself how these individuals should respond, and challenge yourself to find a way for them to agree to invest in greater Cyber Security, or to make a recommendation to the Board to do so.

Once again, while all but one of the groups could bring themselves to abandon their roles' self-interest, they did all recommend that the CIO push Cyber Security to the top of his or her agenda for the coming quarter. The outlier group suggested that the business "take the hit" this quarter and focus on Cyber Security, while also communicating the markets that they were doing so to improve the company's ability to protect and server customers in the future (though they did not agree fully on how to avoid the potential ramifications of announcing that they would focus on Cyber Security and the potentially associated assumption that their systems were not secure).

Summing up:

In both, or either case, do you recognise your company, or a company you have worked with in the past?

If so, be assured that it is possible to convince Boards, but only once the required groundwork has been completed. In the two Role-Plays above, it is too early, and there are too many competing priorities. But there is hope in each, in that the need is recognised, and there are ways out.

Gaining Board agreement on Cyber Security requires time and planning, with careful messaging along the way. In addition, before the Board can "buy-in" to investment in Cyber Security, key stakeholders within the business must also "buy-in", as it will be their alternative expenditure and investment plans and programmes that may suffer or be put on hold to accomplish improved security.


Role Play 2: "Shareholder Expectations"


Shareholder expectation generally revolves around the meeting of targets, primarily revenue and profitability targets that ensure either a dividend flow (private companies and utilities) or sustained growth in the share price. Senior managers, "C-Suite" executives and Directors know this and know that their bonuses and futures (in this company and in any others) depend on a track record of delivering to shareholders' expectations.

Welcome to the mid-year session of the Exco as it prepares for the upcoming earnings release season. Things seem to be on track, and the 1st Qtr results were in-line with expectations. The share price has responded roughly as expected. This quarter however, could be a little more difficult. Trading conditions are worrying the Marketing director, while internal costs are not dropping as quickly as budgeted. The new system is going to be at least two months late, possibly three, pushing benefits into the 4th Qtr.

You now have to make some decisions:

1. The COO. You have numbers to make, promises to keep. The numbers that you received from your senior managers are promising, but you don't believe them "I've seen numbers like these before, and they are always overly optimistic". Your CIO is constantly late with delivery, system outages have become too frequent, and the IVRs never seem to match the problem. To compound things, someone in IT changed the “404” error page to redirect to the Dictionary.com definition for “liars”.

2. Head of Corporate Communications. When dealing with crises and missed targets in the past, your motto has been "Bad news is good news, good news is no news" and the spin spin spin. But you feel things are reaching a point where your own credibility is coming into question. If things continue as they are, you're afraid the only professional option left to you will be to apply to become the Director of Communications at the White House in Washington.
                
3. CFO. You've managed to, just, get the numbers right for the 1st Qtr results, but this quarter will take a small miracle, and missed targets have been shown to severely limit the longevity of CFOs. The numbers expected by the markets (or owners) are possible, but there better not be any down-side surprises. There are costs that can be shifted into out-quarters, and revenue that can be brought forward, if we tweak our revenue recognition policy.

4. CIO. You know that the existing systems need replacing, that infrastructure is supporting the users, but the Security guy(s) are telling you that a serious architecture review is needed (again, "review" means they know there are problems but are too afraid to tell you everything), and the company simply cannot continue to avoid significant new investment. Your proposals for Security investment themselves will increase the overall IT budget to the equivalent of 12% of revenue from the current 10% of revenue, a level that is already at the high end of the scale for this kind of business.

Time to have your conversation, and come to an agreement that the CEO will be able to defend at the next earning call/shareholders meeting.


Role Play 1: "Complex Project Choices"


Scenario: A new system is in the final stages of development, and should "go-live" in three months. Testing is ongoing with the usual bugs and use-case mistakes. The project is projected (for the third month in a role) to come in at exactly 109% of budget, thus avoiding the need to go back to the Board for authorisation for additional spend.

The COO has committed to the Board that the system will go in on schedule. Internal Audit has given an "adequate" grading on a review of the project to date.

IT infrastructure has just reported that the servers will be ready, but that they will not be within the secured domains used by other corporate systems. To do so will require a re-architecting project. However, they do not think there is a major security threat, though when pressed, they've admitted that it would be possible, under "extreme" circumstances, for a hacker to gain access to "some" data. Re-architecting the environment will take an additional 4 months, and will add £275,000 to project costs, taking the project well over the 109% of budget.

You are now meeting to "discuss" the situation. You are:

1. Project manager. If you do not get this project in on time and within the allowed budget, you lose your bonus (20% of your salary), and you probably will not get that next project. Worse, you’re regular steering committee meetings with the sponsor (and team) are becoming a nightmare of complaints about timing, internal resources being diverted to testing, costs, etc.

2. IT infrastructure. You don't completely trust your own people's assessment, as there have been breaches before when some data was stolen. You also know that the 4-month estimate is probably optimistic. A few people in your IT team know too much about your systems, hoard that information, and honestly, you would have “moved a few on” if they didn’t hoard their knowledge. Can you trust them to fix the architecture in anywhere near to estimated time or budget?

3. Operations Manager from User Community. Your people have been crying out for this system for years, budgets have been cut, headcount reduced, and people are reaching a breaking point, with absenteeism escalating. Meanwhile, the project continues to demand more of your frontline experts for “testing”.

4.  Strategic Planning. Your models show that this system is going to boost profit by 5% annually, with an immediate 2% this year, to a profit-line that is already stressed. Missing the targets is not an option, as the cost of future external funding through equity or bond issuances will be impacted by the company’s evidence of being able to meet market expectations.

So, what do you all agree to recommend and do?

18 December 2019

Why Greece?

Yes, we've moved to Greece; Thessaloniki to be specific. On seeing this, a long-time friend sent me a message asking "But why move when the country seems in so much turmoil?"

It is a great question. Why would anyone move to a country that is in such a sorry state, after years of economic devastation and waste, where the pictures we see juxtapose ancient ruins with modern ruins and riots? Really though, the decision was easy.

Consider this the first, and not the complete, post on "Why Greece", and expect more posts to come. There is simply no way to say all there is to say in one post. 

Ivory figurine from the
tomb of Phillip II
(actual size: ~2cmx2cm)

When Francoise and I were considering where after Panama, which as you'll have seen is simply too corrupt for us to do anything meaningful, and the weather is too brutal to be enjoyable for other than a few months of the year, we considered several places. In Panama, the food is terrible, and the service culture simply does not exist, and "gringos" (any "white" or "European" looking person regardless of nationality, language or accent) are not welcomed other than as marks.

Greece is entirely different, in almost every way (other than corruption, but that will be a different story).

So where to begin? Greece is lovely, and the food is incredible. It is cheap, plentiful and fresh. Eating out is inexpensive (our meals out when there was no real kitchen where we are staying) have averaged Euro 35 (approx $40 for two people, with wine). And we have been over-ordering and over-eating. Since then, we have learned to order a third less.


And while it is possible to eat nothing but "classic" Greek food (tzatziki, souvlaki, fried calamari, fish, etc) is is also easy to find variations and experimentation, creating simply fantastic dishes and eating experiences. And all at very reasonable prices.

We have found a wonderful little place in the market in downtown Thessaloniki.
A small cafe on the market square, next door to a tourist souvenir shop on one side, and a bread shop and Orthodox icon shop on the other.

Greek people are famous for their hospitality and friendliness, and we see that around us every day, and in small ways. Certainly, there are rude people; they exist in every culture and community. But here it seems even the boy-racers in their (older) speedy kids cars, are polite and will wave a thank you as you let them merge ahead of you. I've had taxis wave me into traffic to merge ahead of them, and the natural response is, next time, to wave a taxi or other car into traffic in front of me. Simple politeness is contagious.


More important than simply being friendly, the people are good. What do I base that on? The way they treat animals. Complete strangers feed the stray dogs and cats, of which there are many. Every restaurant seems to have a cat or two, or three, wandering around outside. We joke that if the cats won't eat there, there you probably shouldn't either. Yet no one shoos the cats away, and the servers negotiate their way around the cats. Dogs definitely stay outside, but they lay around on the sidewalks and in the grass, waiting their turn.

Greece certainly has been through very difficult times and is still in that difficulty. But it has, I believe, turned a corner, and certainly, Europe has turned a corner in its view of Greece. After all, Greece carries a national debt of close to 200% of GDP (it was smaller, but the IMF/Troika's programme actually shrank the Greek economy, so the debt grew as a percentage of GDP). Greece has gone through a terrible depression, and many young Greeks have left the country in search of work. In addition, Greece is one of the countries on the fringe of Europe with a serious immigrant problem, fuelled by Turkey and the games that they are playing with Europe and the US.

Yet Greece has much going for it. For one, the terrible economic conditions have been buffered by the close family ties that exist in Greece. As families lost jobs and homes, the larger family welcomed them in. Children, including adult and married, moved back home with parents. The coffee culture ensured that the young unemployed could sit outside with their friends nursing a coffee for hours (at 1.20 Euro per, instead of $4 - $5 in the US or the UK).

As the difficulties really bit, shops failed across the country, more jobs were lost, and the cycle continued for years. But then something else began to happen. New stored opened, but with cheaper goods. New jobs were created at half the previous salaries. Rents went down, home prices dropped by almost 50% (they are beginning to rise again, but slowly). The economy "reset".

Of course, Greece is also on the front-lines of the Migrant Crisis, and its position in the Mediterranean and as a "front-line" state facing Turkey makes that inevitable. There are UN and EU programmes to help, but mostly common Greeks and international volunteers are filling the gaps.  

So why Greece? Yes, my own history and the fact that there are still friends here plays a big part. But another part is looking at the global, US and European situations. When we considered France, my comment to Francoise was that this is a country (just like the UK and especially the US) that is waiting for it's "Greek moment". I said that I would rather live in a country that had that moment behind it, and not in front of it. I want us to buy a property closer to the bottom of the market than near the top, even if we will be buying mortgage-free. 

5 seconds of the Thessaloniki waterfront

Remember also that part of the horror of the Greek depression, imposed by the Troika/IMF/Germany was a requirement that the Greek government run a 3.5% national surplus. Greece for a few years now has been running a budget surplus. Imagine what would happen in the US if Washington actually ran a surplus? How many jobs would disappear overnight? Almost all US economic growth over the past decade has come from increased government deficits. Turn off the borrowed money, and the economy would contract massively. 

Without the deep family ties that exist in Greece, and with the even greater social fracture that is happening in the US, the period of adjustment to a "new normal" will be even worse. Charleston and Portland will be remembered as the opening shots in a new civil war. Yes, I really do think that is possible in the US. Especially when China and the rest of the world stop buying US debt.

In all of this, I'm taking the long(er) view. Greece has better prospects simply because it was been through the worst, while other countries have not started down that debt imposed path.

The imposed reforms of the Greek economy are, finally, beginning to pay off. The Bank of Greece has projected a 1.9% growth in 2019, and up to 2.5% growth in 2020. Yet unemployment remains just under 20%, and is exacerbated by a lopsided annual business cycle, with high tourism-based employment for six months of the year, and cyclical unemployment the other six months. 

What else then?


Casket of Philip II of Macedon
There is more history here than almost anywhere we can go, and it is all around us. Athens is only 4.5 hours from away, with all its history. 1.5 hours from here is the tomb (and associated museum, one of the best I have ever been in) of Philip II of Macedon, the father of Alexander the Great. The tomb was discovered intact in 1977, and all the artefacts are in the museum that is built around and over the tomb. 

A 1.5 hours drive and we are at the base of Mount Olympus (which on a clear day/night can be seen from Thessaloniki where we are) - Home of the Gods. 1 - 1.5 hours away are some wonderful beaches in the holiday area of Halkidiki. Paris is a 2.5-hour flight away on discount airlines, and London, where I will continue to work, is a 3.5-hour flight, also on discount airlines.

That is why Greece, for what it has now, what it had, and for what it will be like in the future.

The economy is recovering, and house prices have been inching upward over the past year, though they remain 40% down from their peak.

So to summarise, yes, even though Greece remains in a perilous state, it remains a wonderful place to live, and it is improving every day.

06 August 2019

Hong Kong – THE Geopolitical Risk

What happens when Beijing loses patience with the Hong Kong demonstrators? What happens when Beijing decides ongoing trade / diplomatic conditions cannot get worse? What happens when Beijing decides it can ride out any storm? 

Hong Kong, and the ongoing protests, is now THE only geopolitical risk that matters.

22 years ago Governor Chris Patten presided over the lowering of the flag of the United Kingdom and the raising of the flag of the Special Administrative Region of Hong Kong. The 1st of July 1997 saw the end of British rule over Hong Kong, and a promise of a 50-year transition under the “One Country, Two Systems” principle. 


“In accordance with the "One country, two systems" principle agreed between the United Kingdom and the People's Republic of China, the socialist system of the People's Republic of China would not be practised in the Hong Kong Special Administrative Region (HKSAR), and Hong Kong's previous capitalist system and its way of life would remain unchanged for a period of 50 years. This would have left Hong Kong unchanged until 2047.”

Fairly obviously that was never going to happen, and the underlying rationale for agreement to the principle was to avoid the collapse of the economic golden goose and to ease the way for a potential peaceful unification with Taiwan. Well, the golden goose has done its part, but Taiwan has not budged. Furthermore, China itself was able to assimilate Hong Kong while at the same time expanding its own economy to the point that Hong Kong is no longer the entry to China. 

Fundamentally Hong Kong has become just another Chinese city, albeit a separate financial centre and vibrant port. We are continually told that the Chinese are masters at the long game and, given the current situation in Hong Kong, and the increasingly uncertain global economic status, that long game could go either way.  If they want to preserve the economic benefits, they play long; if a unified China is the prize, then it is possible that the current global situation may give Beijing confidence that with global attention diverted in so many areas including Iran, this may be their opportunity. 

So why is this THE Geopolitical Risk?

Yes, Iran is a major geopolitical risk, but nothing compared to Hong Kong right now. Iran provides focus and noise, being at the crossroads (and chokepoint) of global oil traffic. Yet the world has been through a "tanker war" once already during the Iran-Iraq war of the 1980s. 

Over the past two and a half decades the West has tied itself economically to China, to an extent that is simply frightening. Were it done as a national policy with alternative plans and capacity already in place and maintained, the West would, in theory, be able to recover quickly from the isolation that a true economic war or sanctions regime would entail. Yet across the developed world, critical national capacity and capability have been outsourced to Chinese companies and/or had production itself moved to China.


The steel industry is a good example. In search of cheaper steel (and cleaner air at home), the West has happily watched and contributed to the growth of the Chinese steel industry. Currently, over 50% of world steel production is in China. Chinese overproduction and dumping of steel on global markets has further undermined Western economies, closed steel mills and slowly built greater reliance on China. This capacity does not return overnight.

Image from Worldsteel.org

In the area of microchip production, China has set out to meet all domestic needs as well as positioning itself to be able to economically undercut and dominate international markets. In July 2017, the Wall Street Journal stated:


The U.S. views China as its biggest semiconductor challenge since Japan in the late 1980s. The U.S. triumphed then through trade sanctions and technological advances. Japanese firms couldn’t match U.S. microprocessor technology, which powered the personal computer revolution, and fell behind South Korea in low-margin memory chips.
China has advantages Japan didn’t. It is the world’s biggest chip market, consuming 58.5% of the global $354 billion semiconductor sales in 2015 according to PricewaterhouseCoopers LLP. That gives Beijing power to discriminate, if it wants, against overseas suppliers.


With these two sectors, China has positioned itself to be able to survive any attempts to isolate it or to economically undermine it. More importantly, China has positioned itself to be able to thwart any attempts at a sanctions regime, knowing that sanctions will hurt the sectioning countries more than they will hurt China. 

Imagine the impact on global trade and development if access to steel and microchips were to be curtailed or limited by sanctions or political risk?

No one should be fooled by the promise of 50 years of limited interference. Beijing has been there all along, and if Beijing has not run out of patience, it will very soon. It is also realistic to expect that in the 22 years since handover there would be changes, and there have been.

The protests started over the extradition law that would have allowed the Hong Kong government to extradite individuals to be tried in China proper. The protests managed to force the Hong Kong government to back down. All well and good, to that point.

It was time for the protesters to go back to university, back to work, and back home. A little local difference that we can all learn from.

But having forced the local government to back down, like so many “protest” movements, they did not see that their primary goal was all that they could actually gain in concessions. They are pushing further, and they may have pushed too far. The current general strike and protest actions such as blocking the subways, roads, and painting over street lights to block traffic are bad enough. To call for “revolution” will probably push Beijing over the line.


“Restore Hong Kong. Revolution of our time,” protesters chanted in a demonstration on Monday at a temple in Wong Tai Sin, a working-class neighborhood that was the site of weekend clashes in which enraged residents went into the streets in flip-flops and shorts to drive out police.

In a broader geopolitical context, Hong Kong is now a proxy that is never should have been, and that it really does not want to be. It is a bastion of Western Liberalism deep in the heart of China. Protests are acceptable when they are local only. But when China is facing off against the United States, loyalties are being examined. 

The breakdown in relations with the West (the United States anyway) make any overt and internationally extravagant protest a form of disloyalty, and that is not acceptable to Beijing. 

There have been reports of Chinese forces (vague reports) on the Chinese side of the border between China and Hong Kong. I expect we will see more such reports. It will be interesting to see what units are included, both by name and by type of units. Those forces will not stay there indefinitely.

Late last week (1st August) the Hong Kong element of the PLA (People’s Liberation Army) released a video showing the unit practising anti-riot exercises “showing its soldiers dressed in riot gear and riding in tanks in scenes that bore striking similarities to the Tiananmen Square protests in 1989”. It is not possible to see this as anything other than a warning that what was done 31 years ago, to protect China and more importantly the Communist Party, will be visited on the people of Hong Kong if they continue to protest.

With no end in sight to the protests, Beijing may well have come to the conclusion that now is the time to end two systems. “The PLA can help restore peace in Hong Kong if necessary: Hong Kong lawmaker Junius Ho Kwan-yiu”. It might not be the 27th Group Army (responsible for Tiananmen Square, and disbanded in 2017), but that will not stop them from being equally brutal and effective.

If they have, Hong Kong will be crushed, and we will see an impotent West rush to the UN Security Council fully aware that China will veto any resolution.

Tiananmen Square may be visited on all of Hong Kong. If this happens, the bloodshed will be terrible, and it will be broadcast to the world. The outrage will be both real and impotent. But within China, the message will be two-fold; Hong Kong is now fully integrated into China, and internal dissent will be tolerated only as long as the role of the Communist Party is not questioned.

The West (and Beijing) will discover if it is possible to engage in urban warfare in a modern mega-city. What better place and time to test doctrine, in a place where they control all physical access, and where, eventually, they can control all communications (though that one will take some time). Beijing will also be watching closely to see what lessons they can learn in relation to Taiwan. 

It will not be fast, but it will be effective. Professionals will be "spared" though families may be invited to visit the countryside. After all, the financial systems and global trade must continue.

By the time the international community is able to respond meaningfully, Hong Kong will be subjugated. China (and the rest of the world) knows full well that Hong Kong is not Kuwait, and Xi Jinping is not Saddam. The United States will not be pushing the PLA out of Hong Kong.

What will happen to global markets? From China’s perspective, nothing that they are not willing to allow anyway, in their trade fight with the United States. In Asia “Face” is all-important, and to allow insults of the leader and the country is to lose face.

So anyone who thinks that China will not “invade” and “pacify” Hong Kong should be careful with their assumptions. Geopolitical risk is exceptionally high, and unless both China and the United States have a way to convince the protesters to end their protests and calm their slogans, there will be major trouble.

China has positioned itself to be able to survive any sanctions regime, or at least to impose a greater cost on sanctioning countries. This limits the ability to use threats of sanctions to influence China. This also means that China may feel that they will be given a "free hand" to suppress Hong Kong. 

There is a very significant danger of miscalculation. We already know that words alone will move markets. A Chinese "Tiananmen" style suppression of Hong Kong could generate global market chaos.

Today, next to China and Hong Kong, all other geopolitical risk pales. 


29 July 2019

Saving the SEC’s XBRL Program

Some years ago I promised myself that I would not write about XBRL again. I’m breaking that promise. eXtensible Business Reporting Language was a major conceptual breakthrough when it was first developed in 1998. But that was over 20 years ago, and XBRL has progressed little beyond a regulator-demanded user-unfriendly standard with little (voluntary) uptake by report producers, and less evidence that anyone actually consumer and uses native XBRL. There are financial analysts in university (and possibly beyond) who were not born when XBRL was developed. 

At the heart of displeasure with the SEC’s XBRL program at the core of XBRL, the “eXtensible” concept, or as the XBRL community liked to sell the concept, “tell your story, your way”. Thankfully there is a “simple” fix that will save the SEC’s XBRL program, save filers time and money, enable to (almost) pain-free expansion of the program, and increase the likelihood of uptake by consumers of financial information.

Unfortunately, the complexity of XBRL has been a problem from day one. My all-time favourite condemnation of XBRL goes all the way back to 2008 when someone said that XBRL was “using a dinosaur to crack a walnut”.

But first some background:

There are uses for XBRL and XBRL-type reporting technology, but if you are considering going down that route, beware.

The idea was simple; each piece of information in a financial statement/report could be tagged in such a way as to enable the machine to machine communication of financial and business information. The use of a common taxonomy of elements ensured that a piece of data (a “fact”) tagged would mean the same thing to any consumer of that piece of data. Anyone producing financial or business data that was to be shared would be able to ensure that the consumers of that data would know exactly what they were consuming.

Soon, the FDIC (Federal Deposit Insurance Corporation), the US banking regulator, had incorporated XBRL into the Call Report process, ensuring as early as 2004 that all reporting banks in the United States were reporting using a common taxonomy.

All “successful” XBRL implementations share one key factor; they use “closed” taxonomies and do not allow filers or providers to add extension elements.

Today, around the world, XBRL is required by various regulators are the standard for data tagging of financial statements. And in virtually all of those implementations, from the UK to Singapore to Japan and the Netherlands (to name a few), financial statements are provided to the accountant or service provider who then converts Excel into XBRL and then submits that file to the regulator. The regulator then gets to convert the XBRL back into Excel for analysis. Why? Because XBRL is complex and resource-hungry, where the equivalent benefit can be achieved from a spreadsheet.

In the US, the SEC (Securities and Exchange Commission) requires that financial statements in the 10Q, 10K and a range of other filings, be filed in HTML and in an XBRL version. The SEC is also moving to require “Inline-XBRL” filings. Unfortunately, the SEC’s XBRL program remains a burden for which there has simply not been adequate, or even partial, buy-in from the producers or the consumers of companies SEC filings.

Fundamentally the SEC’s XBRL program has been a failure.

Producers of filings to not like it, and consider the production of XBRL to be costly and time-consuming. Don’t take my word for it, read the recent article following the SEC’s roundtable on short-termism from July 2019.

In listing the bullet points from the discussion of how to improve the 10Q process, the final bullet point stated: “And then, what about XBRL? (It was noted here that many issuers find XBRL expensive and very time-consuming and highly doubt its usefulness, not to mention that the SEC has just increased the XBRL burden for companies. Another panellist quoted an issuer as describing it as the “worst part” of the process.)” (emphasis mine).

The SEC itself is a lukewarm user, and if they have ever announced that it was the XBRL that allowed them to spot a case of fraud or financial misstatement then I missed that announcement. 

Data providers such as Yahoo Finance do not bother to provide a “download XBRL” button, and if you want the data, download it in Excel. If you want to XBRL, you’ll need to go to individual filing companies’ websites and download the files from their Invest Relations page, or you will need to go into the SEC’s EDGAR system and search on the company and download the XBRL from the SEC’s site.

While iXBRL (inline-XBRL) will be a boon to consumers of XBRL, at least those reading documents through their eyes, and wondering if the XBRL-tagged facts actually match the information on the printed form, this does little or nothing to solve the main problem; the difficulty of producing the XBRL in the first place.

The “FIX”

The US GAAP Taxonomy, the “dictionary” of allowable tags for financial statements contains over 18,000 elements. Or, as the AICPA said, “The US GAAP Taxonomies contain over 15,000 elements representing commonly reported financial concepts for US GAAP financial statements”. That was a number of years ago. But really? 15,000 “commonly reported”. And this number does not include the plethora of company-specific extension elements that are created every year. 

Fundamentally, every significant implementation of XBRL for the past 15 years (as long as there really have been any implementations of XBRL) has been based on a “closed” taxonomy in which filers are not able to create company-specific extensions.

To fix the SEC’s XBRL program, they should consider the following:


  1. Create a limited-set US GAAP Taxonomy. The original estimate was that at fully functioning IS GAAP taxonomy could be created with 4500 elements. While that number clearly is low, it should be possible to create a taxonomy that allows companies to report all “common” concepts in under 10,000 elements.
  2. Where companies cannot find the “perfect” fit element, they should use the closest element, and/or revise their reporting to ensure that they are reporting information that is common to their industry of to US GAAP principles.
  3. Encourage the development of “templates” for reporting. This will enable companies and service providers to produce XBRL as standard output, saving time and cost, especially for smaller filing companies.


Yes, this sounds simplistic, and it probably will not happen. 

Why not? Unfortunately, there are drivers for the retention of the complex system of company-specific extensions. Simply put, too many jobs are on the line. 

The FASB maintains a team whose job is the “maintain” the US GAAP taxonomy. This includes the annual release of an updated taxonomy in which new elements are added to cater for “common” company-specific extensions. Companies providing software will see their market disappear if the reporting process can be simplified. And of course, if XBRL is actually simplified, then it will become clear that almost anything that can be done with XBRL should be possible with learning engines and (gasp) Excel.  

After all, XBRL has been around for 20 years. That is 20 years of Moore’s Law improving the speed of processes, 20 years of improvements in systems and analytic capabilities, and 20 years in which IA and learning engines have, if not matured, then at least become mainstream.

It is time to fix the SEC's filing program. Fix it, or abandon XBRL.