SlideShare a Scribd company logo
PEDCO – Bringing SAFe® to LIFE©PEDCO AG | Applied SAFe® | Challenges of Compliance | February 2019 Page 1
February 2019
Peter Pedross, PEDCO – CEO & Founder
Scaling Agile in Regulated Environments:
Addressing the Challenges of Compliance
with Applied SAFe
PEDCO – Bringing SAFe® to LIFE©PEDCO AG | Applied SAFe® | Challenges of Compliance | February 2019 Page 2
Peter Pedross
CEO & Founder
Phone: +41 76 373 35 95
E-Mail: peter.pedross@pedco.eu
Web: www.pedco.eu
Peter Pedross
• 30+ years experience in Software Engineering.
• Studied Software Engineering, Finance and
Management Psychology
• World-wide responsible for lifecycles, processes,
methods and tools at a leading Swiss financial
institute
• 50+ publications and lectures since 1995 in USA,
Japan and Europe.
• Certified in "Scaled Agile Framework" and
"Disciplined Agile Delivery", EFQA, CMMI, PMI.
• Encountered first experience with Agile in 1999 (XP)
• President of the Board for Computer Science at the
Swiss Association of Quality and member of the
Board of Directors.
CEO AND FOUNDER OF PEDCO
PEDCO – Bringing SAFe® to LIFE©PEDCO AG | Applied SAFe® | Challenges of Compliance | February 2019 Page 3
Content 1. Context
2. Compliance meets Agile Development
3. Motivation for a process model
4. Role of the Quality Management System
5. What is Applied SAFe?
6. Real live examples:
➢ Have a defined process
➢ Ensure process compliance
➢ Manage process variations
➢ Build quality in
➢ Continuously Verify and Validate
➢ Establish a Lean-Agile Learning Organization
7. Lessons Learned
8. Conclusion
9. Discussion, Q&A
PEDCO – Bringing SAFe® to LIFE©PEDCO AG | Applied SAFe® | Challenges of Compliance | February 2019 Page 4
Context
• Increasing competitive pressure
• High innovation levels and high efficiency
• Low time-to-market
• Industry 4.0, Lean Start up, Agile
• Cyber-physical systems, increased complexity and dependency
• Just agile teams are to small to build complex systems
• Regulatory and organisational environment is becoming ever more
demanding
• Most agile delivery teams face compliance requirements
(regulatory and/or organizational).
• Strategy and governance steering is needed
WHY SCALED AGILITY IN REGULATED ENVIRONMENTS?
POLL
PEDCO – Bringing SAFe® to LIFE©PEDCO AG | Applied SAFe® | Challenges of Compliance | February 2019 Page 5
Trends in Scaled Agility (12th State of Agile Report by Version One; April 2018)
OVERVIEW IN USAGE OF THE MOST COMMON AGILE FRAMEWORKS
PEDCO – Bringing SAFe® to LIFE©PEDCO AG | Applied SAFe® | Challenges of Compliance | February 2019 Page 6
SAFe® - #1 Framework for Scaled Agility
SCALING UP FROM TEAM TOWARDS PROGRAM, LARGE SOLUTION, PORTFOLIO AND ENTERPRISE
More Details on www.scaledagileframework.com
1. Alignment
2. Built-In Quality
3. Transparency
4. Program execution
Core Values
PEDCO – Bringing SAFe® to LIFE©PEDCO AG | Applied SAFe® | Challenges of Compliance | February 2019 Page 8
Compliance meets Agile Development
CONTRASTING TRADITIONAL REGULATORY AND COMPLIANCE CONCERNS WITH AGILE VALUES
PEDCO – Bringing SAFe® to LIFE©PEDCO AG | Applied SAFe® | Challenges of Compliance | February 2019 Page 13
LEAN-AGILE QMS IMPROVES QUALITY AND MAKES COMPLIANCE MORE PREDICTABLE
Implementing a QMS for Lean Agile Organizations
PEDCO – Bringing SAFe® to LIFE©PEDCO AG | Applied SAFe® | Challenges of Compliance | February 2019 Page 14
Scaled Agile Framework® (SAFe®)?
Build the Solution incrementally
• Apply fast Learning Cycles
• Apply objective Milestones based
on Progress, Product, Process
Metrics
Organize around Value
• Understand the full Value Stream
• Synchronize with PI Planning
(Dependencies, Risks, Priorities)
Build Quality in
• Solution Intent as a critical
Knowledge Repository
• MBSE facilitates emergent
Specifications
Apply continuous Verification and
Validation (V&V)
• Include Compliance Concerns in
Definition of Done (DoD)
• Inspect & Adapt and frequent V&V
reduce Risk and increase Assurance
… HAS MOST OF THE HOOKS NEEDED FOR COMPLIANCE WITH HIGH ASSURANCE SYSTEMS
POLL
PEDCO – Bringing SAFe® to LIFE©PEDCO AG | Applied SAFe® | Challenges of Compliance | February 2019 Page 15
Applied SAFe®
Implementation of a Lean Agile QMS based on SAFe
PEDCO – Bringing SAFe® to LIFE©PEDCO AG | Applied SAFe® | Challenges of Compliance | February 2019 Page 16
Applied SAFe®
A CUSTOMIZABLE IMPLEMENTATION OF SAFE® AS A PROCESS MODEL
Customize
and Extend
Develop
Compliant
Implement SAFe®
Fast & Precise
Learn, Innovate,
and Improve
PEDCO – Bringing SAFe® to LIFE©PEDCO AG | Applied SAFe® | Challenges of Compliance | February 2019 Page 18
Applied SAFe®
PROVEN BENEFITS
Customization and Compliance
PEDCO – Bringing SAFe® to LIFE©PEDCO AG | Applied SAFe® | Challenges of Compliance | February 2019 Page 20
VARYING LEVELS OF CRITICALITY, FROM SAFETY-CRITICAL TO SECURITY-CRITICAL
Scaled Agility in Regulated Environments
• Quality:
Have a managed process & established QMS
• Safety and Security:
Transparency in Execution & Continuous Compliance
• Effectiveness: Manage Process & Solution
variations, reduce waste and do exactly what is
needed
• Traceability:
• Ensure process & product compliance
• Coverage, completeness
• Verification and Validation:
• Engineering based on Principles & Practices
• Quality of code, system and documentation.
PEDCO – Bringing SAFe® to LIFE©PEDCO AG | Applied SAFe® | Challenges of Compliance | February 2019 Page 21
Quality:
Have a Defined Process & an Established QMS
PEDCO – Bringing SAFe® to LIFE©PEDCO AG | Applied SAFe® | Challenges of Compliance | February 2019 Page 22
Have a Defined Process
• Tom is new to the company
• He has several years experience in IT and has been
working in an agile team.
• He loves to code and to test, but hasn’t that much
experience with Scaled Agility yet.
• Tom has been working in a small Scrum-team and
has some basic knowledge about SAFe®.
• Tom is interested to see, how epics are handled on
a Portfolio Level at his new company.
DEMO OF APPLIED SAFE®
PEDCO – Bringing SAFe® to LIFE©PEDCO AG | Applied SAFe® | Challenges of Compliance | February 2019 Page 23
Traceability:
Ensure Process Compliance
PEDCO – Bringing SAFe® to LIFE©PEDCO AG | Applied SAFe® | Challenges of Compliance | February 2019 Page 24
Mapped,harderforAssessment&QA,
optimizedforusageincompany
Process Design for regulated Environments
PROCESSES NEED TO COMPLY, NOT TO REPLICATE A REFERENCE MODEL
Reference Model
• Process Area 1
• GP 1.1
• GP 1.2
• …
• Work Products
• WP 1
• WP 2
• …
Company Process Model
• Process Area 1
• GP 1.1
• GP 1.2
• …
• Work Products
• WP 1
• WP 2
• …
Easy for
Assessment
CMMI
• Process Area X
• GP x.1
• GP x.2
• …
• Work Products
• WP x1
• WP x2
• …
AS9100
• Process Area Y
• GP y.1
• GP y.2
• …
• Work Products
• WP y1
• WP y2
• …
A-SPICE 3.0
• Process Area Z
• GP z.1
• GP z.2
• …
• Work Products
• WP z1
• WP z2
• …
Custom
• Process Area W
• GP w.1
• GP w.2
• …
• Work Products
• WP w1
• WP w2
• …
My Company Process Model
• Epic Kanban
• What I do
• The way we like it
• Is better for us
• Work Products
• SAD
• CM Plan
• …
• Roles
• Business Owner
• Developer
• Tester
Spec with
text / model
_____
AAAAA
BBBBBB
Spec with
text / model
_____
AAAAA
BBBBBB
Spec with
text / model
_____
AAAAA
BBBBBB
Spec with
text / model
_____
AAAAA
BBBBBB
PEDCO – Bringing SAFe® to LIFE©PEDCO AG | Applied SAFe® | Challenges of Compliance | February 2019 Page 27
...and identify gaps.
Assure Compliance to Reference Models
ENSURE COMPLIANCE WITH A SUSTAINABLE MECHANISM; AVOID INTERPRETATION GAMES
Map standard requirements...
...to defined process assets
© PEDCO AG 2019, Applied SAFe® all rights reserved
PEDCO – Bringing SAFe® to LIFE©PEDCO AG | Applied SAFe® | Challenges of Compliance | February 2019 Page 28
Transparency in Execution and
Continuous Compliance
• Linda is the Agile Release Train Engineer
• The program has run two PI’s so far.
• Linda needs to get an approval from an assessment for
compliance with there regulated requirements
• Convince assessor that the program has a defined process
variation
• Prove that they know what, why and how they are ensure
the stakeholder requirements.
DEMO IN APPLIED SAFE WITH PI PLANNING
PEDCO – Bringing SAFe® to LIFE©PEDCO AG | Applied SAFe® | Challenges of Compliance | February 2019 Page 29
AAMI: TIR 45
GUIDANCE ON THE USE OF AGILE PRACTICES IN THE DEVELOPMENT OF MEDICAL DEVICE SOFTWARE
© 2012 Association for the Advancement of Medical Instrumentation AAMI TIR45:2012
http://www.pedco.eu/tir45-agile-in-medical/
PEDCO – Bringing SAFe® to LIFE©PEDCO AG | Applied SAFe® | Challenges of Compliance | February 2019 Page 30
Effectiveness:
Manage process variations
PEDCO – Bringing SAFe® to LIFE©PEDCO AG | Applied SAFe® | Challenges of Compliance | February 2019 Page 31
Different use of Process Instances on
Defined Levels
OVERVIEW OF INSTANTIATIONS WITH DIFFERENT CONFIGURATIONS OF THE SAFE® MODEL
PEDCO – Bringing SAFe® to LIFE©PEDCO AG | Applied SAFe® | Challenges of Compliance | February 2019 Page 32
Workspace and Instantiations in the real World
A Swiss Banking Institute Example
Process Instantiations can be done on any given level.
PEDCO – Bringing SAFe® to LIFE©PEDCO AG | Applied SAFe® | Challenges of Compliance | February 2019 Page 35
Manage Process Variation
• Linda is an Agile Release Train Engineer
• Linda knows the company very well
• The program has run one PI so far.
• Linda has several years experience in IT and project
management.
• Linde loves to manage and is PMI-certified Project
Manager.
• She is also certified Scaled Agilest and has some
knowledge of SAFe.
• Linda wants to tailor the process accordingly to
what was decided during I&A
DEMO IN APPLIED SAFE
PEDCO – Bringing SAFe® to LIFE©PEDCO AG | Applied SAFe® | Challenges of Compliance | February 2019 Page 36
Verification & Validation:
Engineering based on SAFe® Principles & Practices
Solution Intent and Solution Context
Model-based Systems Engineering (MBSE)
Definition od Done (DoD)
PEDCO – Bringing SAFe® to LIFE©PEDCO AG | Applied SAFe® | Challenges of Compliance | February 2019 Page 37
RAPID LEARNING CYCLES INCREASE QUALITY AND REDUCE RISK
Build Solution and Compliance Incrementally
PEDCO – Bringing SAFe® to LIFE©PEDCO AG | Applied SAFe® | Challenges of Compliance | February 2019 Page 38
Example: Solution Intent in SAFe
WHAT DOES THE CURRENT SYSTEM NOW, AND WHAT CHANGES ARE INTENDED FOR A FUTURE STATE
Source: www.scaledagileframework.com
PEDCO – Bringing SAFe® to LIFE©PEDCO AG | Applied SAFe® | Challenges of Compliance | February 2019 Page 39
Solution Intent
APPLICATION IN DETAIL
Source: www.scaledagileframework.com
PEDCO – Bringing SAFe® to LIFE©PEDCO AG | Applied SAFe® | Challenges of Compliance | February 2019 Page 41
Context, theory with Applied SAFe
HOW DO YOU WORK WITH DEFINITIONS OF DONE?
PEDCO – Bringing SAFe® to LIFE©PEDCO AG | Applied SAFe® | Challenges of Compliance | February 2019 Page 42
Definition of Done
MAKE V&V AND COMPLIANCE ACTIVITIES PART OF REGULAR FLOW
PEDCO – Bringing SAFe® to LIFE©PEDCO AG | Applied SAFe® | Challenges of Compliance | February 2019 Page 43
Applied SAFe: Concepts
DEFINITION OF DONE (DOD) IN SCALED AGILITY
PEDCO – Bringing SAFe® to LIFE©PEDCO AG | Applied SAFe® | Challenges of Compliance | February 2019 Page 46
Relentless Improvement:
Establish a Lean-Agile Learning Organization
PEDCO – Bringing SAFe® to LIFE©PEDCO AG | Applied SAFe® | Challenges of Compliance | February 2019 Page 47
Quality Processes for Mature Agile Organizations
METHODS AND PROCESSES FOR COMPLIANCE WITHIN REGULATED ENVIRONMENTS
PEDCO – Bringing SAFe® to LIFE©PEDCO AG | Applied SAFe® | Challenges of Compliance | February 2019 Page 48
Lessons Learned
PEDCO – Bringing SAFe® to LIFE©PEDCO AG | Applied SAFe® | Challenges of Compliance | February 2019 Page 49
Lessons Learned (1/2)
Read/use available sources; e.g:
• Software Engineering Institute:
‘Scaling Agile Methods for
Departments of Defense Program
• CMMI Institute:
‘A Guide to Scrum and CMMI’
• TIR45 from AAMI: ‘Agile practices
in the development of medical
device software’
Be very clear on what is compliance and what is not.
• Mapping of scaled agility to reference model is surprisingly
straight forward, once the lean-agile mindset is understood
• Avoid the bear trap: Map compliance elements always to value
adding deliverables
• Automate mechanisms to prove mapping to reference models
-> reduce discussion time and interpretation games
• Some reference models ask for process- and product-specific
requirements -> Scope those requirements for purpose
Compliance is often a ‘negotiation game’
• Don’t forget the human element of stakeholders & appraisers
• Solution Intent and agile Design control needs to be established
Demonstrate compliance in small iterations based on flow’
• Avoid ‘quality depth’; do not ‘build in’ compliance at the end of
development
• Treat audits like a normal system demo
• Focus on outcomes
OF SCALED AGILE APPLICATIONS/MAPPINGS TO VARIOUS REFERENCE MODELS
PEDCO – Bringing SAFe® to LIFE©PEDCO AG | Applied SAFe® | Challenges of Compliance | February 2019 Page 50
Lessons Learned (2/2)
Some experiences:
• A mapping of Scaled Agile
Frameworks to reference
models is achievable within a
lower number of weeks.
• Depending on the attributes
of a solution or on existing
documentation the form of
‘DoD’s can vary very much.
• Commercial frameworks such
as SAFe® or others are an
excellent starting point to be
applied in the development of
high assurance systems.
Separate ‘What shall be done’ from ‘How something is done’
• Model only necessary steps in the process
• Build and rely on heuristics to model the process for usage
• Ensure that practices can be changed/selected easily by
performers
Quality Management System
• Let the QMS be easily accessible and easy to use.
• Promote transparency for each endeavor, process instantiations
need to be specialized to reduce waste.
• Allow fast process changes and pilot in appropriate levels.
• Allow process users to perform tailoring themselves in a
controlled and easy way. Trust that they will do it good!
OF SCALED AGILE APPLICATIONS/MAPPINGS TO VARIOUS REFERENCE MODELS
PEDCO – Bringing SAFe® to LIFE©PEDCO AG | Applied SAFe® | Challenges of Compliance | February 2019 Page 51
Conclusion
PEDCO – Bringing SAFe® to LIFE©PEDCO AG | Applied SAFe® | Challenges of Compliance | February 2019 Page 52
Scaled Agility can be successfully applied in
regulated environments!
Agile practices for reg. env. in
SAFe:
• Build the solution
incrementally
• Apply fast learning cycles
• Apply objectives milestones
• Demo frequently; routinely
deliver objective progress,
product, and process metrics
• Organize around value
• Build quality in
• Apply continuous verification
and validation
• Include compliance concerns
in Definition of Done
• Solution intent as concept for
requirements
• Inspect & Adapt lead to
continuous improvement
FRAMEWORKS HAVE MOST OF THE HOOKS NEEDED FOR COMPLIANCE WITH HIGH ASSURANCE SYSTEMS
✓ Read and understand the regulations! Strive to map existing
agile behavior and don’t impose unnecessary work.
✓ Regulated requirements have common background!
✓ Regulations do not imply how some thing shall be done.
Use given freedom and map agile practices ->
✓ Not all regulations are as stringent as others; tailoring of
processes is a must to reflect applicable regulations.
✓ Establish a managed process and Quality Management System
(QMS)
✓ Address live cycle concerns of solutions (e.g. live time)
✓ Build your own Lean Agile Center of Excellence (LACE)
✓ Include executive level in the cultural change
✓ Lead the change, it won’t be easy
✓ Define governance and responsibilities, also on an Enterprise
level
✓ Exchange your experience with others!
PEDCO – Bringing SAFe® to LIFE©PEDCO AG | Applied SAFe® | Challenges of Compliance | February 2019 Page 53
Applied SAFe Value Proposition
ADVANTAGES FOR YOU
Customize
and Extend
Develop
Compliant
Implement SAFe
Fast & Precise
Learn, Innovate,
and Improve
PEDCO – Bringing SAFe® to LIFE©PEDCO AG | Applied SAFe® | Challenges of Compliance | February 2019 Page 54
Questions? Discussion?
PEDCO – Bringing SAFe® to LIFE©PEDCO AG | Applied SAFe® | Challenges of Compliance | February 2019 Page 55
Tel. +41 44 542 45 45
www.pedco.eu
pedco@pedco.eu
PEDCO AG
Zelgstrasse 5
CH-8003 Zürich

More Related Content

PPTX
Agile Transformation Kick Start - Sathyanaraya H R - Scrum Bangalore 19th Meetup
KEY
Agile Program and Portfolio Management
KEY
Agile Estimating & Planning
PDF
Agile methodologiesvswaterfall
PPTX
Scrum Master Interview Questions SlideShare
PDF
Agile+Slides.pdf
PPTX
Agile Transformation: People, Process and Tools to Make Your Transformation S...
PDF
LKCE16 -Upstream & Customer Kanban by Patrick Steyaert
Agile Transformation Kick Start - Sathyanaraya H R - Scrum Bangalore 19th Meetup
Agile Program and Portfolio Management
Agile Estimating & Planning
Agile methodologiesvswaterfall
Scrum Master Interview Questions SlideShare
Agile+Slides.pdf
Agile Transformation: People, Process and Tools to Make Your Transformation S...
LKCE16 -Upstream & Customer Kanban by Patrick Steyaert

What's hot (20)

PPTX
Agile Mindset For Executives
PPTX
Agile transformation by Gnanasambandham anbazhagan
PDF
Agile at Spotify
PPTX
Agile Project Management
PPTX
Strategies for Large Scale Agile Transformation
PDF
The Synergistic Nature of PI Objectives
PDF
Agile IT Operatinos - Getting to Daily Releases
PDF
Scrum - Agile Methodology
PPT
What Is Agile Scrum
PPTX
What is Agile Project Management? | Agile Project Management | Invensis Learn...
PDF
SAFe® - scaled agile framework in practice
PDF
Foundations of the Scaled Agile Framework® (SAFe® ) 4.5
PDF
¿Cuál es el siguiente paso después de Agile? Enterprise Agility
PDF
The ART of Value Streams: Determining Paths of Value Through Value Streams Wo...
PDF
An Overview of SAFe
PPT
Agile Project Management for IT Projects
PPTX
SAFe Roadmap
PPTX
Introduction to SAFe, the Scaled Agile Framework
PPTX
2017 Scrum by Picture
PDF
Agile Transformation at Scale
Agile Mindset For Executives
Agile transformation by Gnanasambandham anbazhagan
Agile at Spotify
Agile Project Management
Strategies for Large Scale Agile Transformation
The Synergistic Nature of PI Objectives
Agile IT Operatinos - Getting to Daily Releases
Scrum - Agile Methodology
What Is Agile Scrum
What is Agile Project Management? | Agile Project Management | Invensis Learn...
SAFe® - scaled agile framework in practice
Foundations of the Scaled Agile Framework® (SAFe® ) 4.5
¿Cuál es el siguiente paso después de Agile? Enterprise Agility
The ART of Value Streams: Determining Paths of Value Through Value Streams Wo...
An Overview of SAFe
Agile Project Management for IT Projects
SAFe Roadmap
Introduction to SAFe, the Scaled Agile Framework
2017 Scrum by Picture
Agile Transformation at Scale
Ad

Similar to Scaling Agile in Regulated Environments: Addressing the Challenges of Compliance with Applied SAFe (20)

PPTX
SAP awards 2014 solunion cloud category SuccessFactors
PPTX
SAP TechEd 2018 OPP103 – An Introduction to DevOps
PDF
The How and the Why of Making a Smart S&OP Technology Solution
PDF
"Implementing a lean approach in IT operations and infrastructure" by Philipp...
PPT
Asap implementation methodology (2)
PPTX
Top Five Techniques for Managing Programs and Portfolios
PDF
Agile and Stage-Gate - Getting it Right
PPT
Sap Eng Presentation Win It07 Project Managment02
PDF
SAP TechEd 2019 CAA217 – Efficient Continuous Delivery in the SAP Ecosystem
PPTX
8 reasons to adopt AgilePM
PPTX
Introducing_SAFe_for_Lean_Enterprises-1.pptx
PDF
GRI Conference, 27 May, Peterschmitt - Learn About GRI Certified Software...
PDF
Process-Driven SAP Management for successful SAP Projects
PPT
Erp Asap implementation 1214825612078403-9
PPT
Erpasapimplementation 1214825612078403-9
PDF
White Paper: Product Regulatory Compliance
PPT
Sap Eng Presentation Win It10 Us
PPTX
Adaptive Processes's competency development services
PPT
Sap Eng Presentation Win It10 Euro
PPTX
Archimides Panagotides- Software AG: Charting Your Course in ESG Integration
SAP awards 2014 solunion cloud category SuccessFactors
SAP TechEd 2018 OPP103 – An Introduction to DevOps
The How and the Why of Making a Smart S&OP Technology Solution
"Implementing a lean approach in IT operations and infrastructure" by Philipp...
Asap implementation methodology (2)
Top Five Techniques for Managing Programs and Portfolios
Agile and Stage-Gate - Getting it Right
Sap Eng Presentation Win It07 Project Managment02
SAP TechEd 2019 CAA217 – Efficient Continuous Delivery in the SAP Ecosystem
8 reasons to adopt AgilePM
Introducing_SAFe_for_Lean_Enterprises-1.pptx
GRI Conference, 27 May, Peterschmitt - Learn About GRI Certified Software...
Process-Driven SAP Management for successful SAP Projects
Erp Asap implementation 1214825612078403-9
Erpasapimplementation 1214825612078403-9
White Paper: Product Regulatory Compliance
Sap Eng Presentation Win It10 Us
Adaptive Processes's competency development services
Sap Eng Presentation Win It10 Euro
Archimides Panagotides- Software AG: Charting Your Course in ESG Integration
Ad

More from Cprime (20)

PDF
Achieving Sustainable Growth in the Digital Age
PDF
Mastering an Integrated Atlassian Tooling Ecosystem: Strategies, Success Stor...
PDF
A Framework for Development in the AI Age
PDF
Improving IT Investment Decisions and Business Outcomes with Integrated Enter...
PDF
Harnessing Atlassian's Power Through Cloud Transformation and Adoption
PDF
AI-powered Service Management: Streamlining Incident Management in JSM using ...
PDF
Enterprise Migration from Data Center to Atlassian Cloud: Start with an Asses...
PDF
AI for Everyone: Demystifying Large Language Models (LLMs) Like ChatGPT
PDF
From Project to Product - The Need for Speed
PDF
We Need a Hero — How to Find and Support Your Next Superstar Product Owner
PDF
How to Unlock Productivity and Innovation with Generative AI and ChatGPT
PDF
Modern Learning for Enterprises: How to Empower Your Teams
PDF
Enterprise Service Management for Finance, HR, and Marketing
PDF
ESM Webinar Series Part 2 | The Keys to Optimal ESM are Automation and Integr...
PDF
Perfecting Customer Management Using Jira Service Management
PDF
From Project to Product: Leaders, Here's What It Means to You
PDF
Using a Service Catalog and CMDB to Standardize Change Management in Jira Ser...
PDF
6 Common Challenges RTEs Face & How to Solve Them
PDF
Enterprise Service Management Webinar Series Part 1
PDF
How to Enable Change Management with Jira Service Management
Achieving Sustainable Growth in the Digital Age
Mastering an Integrated Atlassian Tooling Ecosystem: Strategies, Success Stor...
A Framework for Development in the AI Age
Improving IT Investment Decisions and Business Outcomes with Integrated Enter...
Harnessing Atlassian's Power Through Cloud Transformation and Adoption
AI-powered Service Management: Streamlining Incident Management in JSM using ...
Enterprise Migration from Data Center to Atlassian Cloud: Start with an Asses...
AI for Everyone: Demystifying Large Language Models (LLMs) Like ChatGPT
From Project to Product - The Need for Speed
We Need a Hero — How to Find and Support Your Next Superstar Product Owner
How to Unlock Productivity and Innovation with Generative AI and ChatGPT
Modern Learning for Enterprises: How to Empower Your Teams
Enterprise Service Management for Finance, HR, and Marketing
ESM Webinar Series Part 2 | The Keys to Optimal ESM are Automation and Integr...
Perfecting Customer Management Using Jira Service Management
From Project to Product: Leaders, Here's What It Means to You
Using a Service Catalog and CMDB to Standardize Change Management in Jira Ser...
6 Common Challenges RTEs Face & How to Solve Them
Enterprise Service Management Webinar Series Part 1
How to Enable Change Management with Jira Service Management

Recently uploaded (20)

PPTX
Spectroscopy.pptx food analysis technology
PDF
NewMind AI Weekly Chronicles - August'25 Week I
PDF
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
PDF
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
PDF
Mobile App Security Testing_ A Comprehensive Guide.pdf
PDF
Building Integrated photovoltaic BIPV_UPV.pdf
PDF
Advanced methodologies resolving dimensionality complications for autism neur...
PDF
Spectral efficient network and resource selection model in 5G networks
PPT
“AI and Expert System Decision Support & Business Intelligence Systems”
PPTX
sap open course for s4hana steps from ECC to s4
PPTX
Detection-First SIEM: Rule Types, Dashboards, and Threat-Informed Strategy
PDF
Unlocking AI with Model Context Protocol (MCP)
PPTX
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
PPTX
Big Data Technologies - Introduction.pptx
PDF
Reach Out and Touch Someone: Haptics and Empathic Computing
PDF
Optimiser vos workloads AI/ML sur Amazon EC2 et AWS Graviton
PPTX
MYSQL Presentation for SQL database connectivity
PDF
KodekX | Application Modernization Development
PDF
Dropbox Q2 2025 Financial Results & Investor Presentation
PDF
How UI/UX Design Impacts User Retention in Mobile Apps.pdf
Spectroscopy.pptx food analysis technology
NewMind AI Weekly Chronicles - August'25 Week I
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
Mobile App Security Testing_ A Comprehensive Guide.pdf
Building Integrated photovoltaic BIPV_UPV.pdf
Advanced methodologies resolving dimensionality complications for autism neur...
Spectral efficient network and resource selection model in 5G networks
“AI and Expert System Decision Support & Business Intelligence Systems”
sap open course for s4hana steps from ECC to s4
Detection-First SIEM: Rule Types, Dashboards, and Threat-Informed Strategy
Unlocking AI with Model Context Protocol (MCP)
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
Big Data Technologies - Introduction.pptx
Reach Out and Touch Someone: Haptics and Empathic Computing
Optimiser vos workloads AI/ML sur Amazon EC2 et AWS Graviton
MYSQL Presentation for SQL database connectivity
KodekX | Application Modernization Development
Dropbox Q2 2025 Financial Results & Investor Presentation
How UI/UX Design Impacts User Retention in Mobile Apps.pdf

Scaling Agile in Regulated Environments: Addressing the Challenges of Compliance with Applied SAFe

  • 1. PEDCO – Bringing SAFe® to LIFE©PEDCO AG | Applied SAFe® | Challenges of Compliance | February 2019 Page 1 February 2019 Peter Pedross, PEDCO – CEO & Founder Scaling Agile in Regulated Environments: Addressing the Challenges of Compliance with Applied SAFe
  • 2. PEDCO – Bringing SAFe® to LIFE©PEDCO AG | Applied SAFe® | Challenges of Compliance | February 2019 Page 2 Peter Pedross CEO & Founder Phone: +41 76 373 35 95 E-Mail: peter.pedross@pedco.eu Web: www.pedco.eu Peter Pedross • 30+ years experience in Software Engineering. • Studied Software Engineering, Finance and Management Psychology • World-wide responsible for lifecycles, processes, methods and tools at a leading Swiss financial institute • 50+ publications and lectures since 1995 in USA, Japan and Europe. • Certified in "Scaled Agile Framework" and "Disciplined Agile Delivery", EFQA, CMMI, PMI. • Encountered first experience with Agile in 1999 (XP) • President of the Board for Computer Science at the Swiss Association of Quality and member of the Board of Directors. CEO AND FOUNDER OF PEDCO
  • 3. PEDCO – Bringing SAFe® to LIFE©PEDCO AG | Applied SAFe® | Challenges of Compliance | February 2019 Page 3 Content 1. Context 2. Compliance meets Agile Development 3. Motivation for a process model 4. Role of the Quality Management System 5. What is Applied SAFe? 6. Real live examples: ➢ Have a defined process ➢ Ensure process compliance ➢ Manage process variations ➢ Build quality in ➢ Continuously Verify and Validate ➢ Establish a Lean-Agile Learning Organization 7. Lessons Learned 8. Conclusion 9. Discussion, Q&A
  • 4. PEDCO – Bringing SAFe® to LIFE©PEDCO AG | Applied SAFe® | Challenges of Compliance | February 2019 Page 4 Context • Increasing competitive pressure • High innovation levels and high efficiency • Low time-to-market • Industry 4.0, Lean Start up, Agile • Cyber-physical systems, increased complexity and dependency • Just agile teams are to small to build complex systems • Regulatory and organisational environment is becoming ever more demanding • Most agile delivery teams face compliance requirements (regulatory and/or organizational). • Strategy and governance steering is needed WHY SCALED AGILITY IN REGULATED ENVIRONMENTS? POLL
  • 5. PEDCO – Bringing SAFe® to LIFE©PEDCO AG | Applied SAFe® | Challenges of Compliance | February 2019 Page 5 Trends in Scaled Agility (12th State of Agile Report by Version One; April 2018) OVERVIEW IN USAGE OF THE MOST COMMON AGILE FRAMEWORKS
  • 6. PEDCO – Bringing SAFe® to LIFE©PEDCO AG | Applied SAFe® | Challenges of Compliance | February 2019 Page 6 SAFe® - #1 Framework for Scaled Agility SCALING UP FROM TEAM TOWARDS PROGRAM, LARGE SOLUTION, PORTFOLIO AND ENTERPRISE More Details on www.scaledagileframework.com 1. Alignment 2. Built-In Quality 3. Transparency 4. Program execution Core Values
  • 7. PEDCO – Bringing SAFe® to LIFE©PEDCO AG | Applied SAFe® | Challenges of Compliance | February 2019 Page 8 Compliance meets Agile Development CONTRASTING TRADITIONAL REGULATORY AND COMPLIANCE CONCERNS WITH AGILE VALUES
  • 8. PEDCO – Bringing SAFe® to LIFE©PEDCO AG | Applied SAFe® | Challenges of Compliance | February 2019 Page 13 LEAN-AGILE QMS IMPROVES QUALITY AND MAKES COMPLIANCE MORE PREDICTABLE Implementing a QMS for Lean Agile Organizations
  • 9. PEDCO – Bringing SAFe® to LIFE©PEDCO AG | Applied SAFe® | Challenges of Compliance | February 2019 Page 14 Scaled Agile Framework® (SAFe®)? Build the Solution incrementally • Apply fast Learning Cycles • Apply objective Milestones based on Progress, Product, Process Metrics Organize around Value • Understand the full Value Stream • Synchronize with PI Planning (Dependencies, Risks, Priorities) Build Quality in • Solution Intent as a critical Knowledge Repository • MBSE facilitates emergent Specifications Apply continuous Verification and Validation (V&V) • Include Compliance Concerns in Definition of Done (DoD) • Inspect & Adapt and frequent V&V reduce Risk and increase Assurance … HAS MOST OF THE HOOKS NEEDED FOR COMPLIANCE WITH HIGH ASSURANCE SYSTEMS POLL
  • 10. PEDCO – Bringing SAFe® to LIFE©PEDCO AG | Applied SAFe® | Challenges of Compliance | February 2019 Page 15 Applied SAFe® Implementation of a Lean Agile QMS based on SAFe
  • 11. PEDCO – Bringing SAFe® to LIFE©PEDCO AG | Applied SAFe® | Challenges of Compliance | February 2019 Page 16 Applied SAFe® A CUSTOMIZABLE IMPLEMENTATION OF SAFE® AS A PROCESS MODEL Customize and Extend Develop Compliant Implement SAFe® Fast & Precise Learn, Innovate, and Improve
  • 12. PEDCO – Bringing SAFe® to LIFE©PEDCO AG | Applied SAFe® | Challenges of Compliance | February 2019 Page 18 Applied SAFe® PROVEN BENEFITS Customization and Compliance
  • 13. PEDCO – Bringing SAFe® to LIFE©PEDCO AG | Applied SAFe® | Challenges of Compliance | February 2019 Page 20 VARYING LEVELS OF CRITICALITY, FROM SAFETY-CRITICAL TO SECURITY-CRITICAL Scaled Agility in Regulated Environments • Quality: Have a managed process & established QMS • Safety and Security: Transparency in Execution & Continuous Compliance • Effectiveness: Manage Process & Solution variations, reduce waste and do exactly what is needed • Traceability: • Ensure process & product compliance • Coverage, completeness • Verification and Validation: • Engineering based on Principles & Practices • Quality of code, system and documentation.
  • 14. PEDCO – Bringing SAFe® to LIFE©PEDCO AG | Applied SAFe® | Challenges of Compliance | February 2019 Page 21 Quality: Have a Defined Process & an Established QMS
  • 15. PEDCO – Bringing SAFe® to LIFE©PEDCO AG | Applied SAFe® | Challenges of Compliance | February 2019 Page 22 Have a Defined Process • Tom is new to the company • He has several years experience in IT and has been working in an agile team. • He loves to code and to test, but hasn’t that much experience with Scaled Agility yet. • Tom has been working in a small Scrum-team and has some basic knowledge about SAFe®. • Tom is interested to see, how epics are handled on a Portfolio Level at his new company. DEMO OF APPLIED SAFE®
  • 16. PEDCO – Bringing SAFe® to LIFE©PEDCO AG | Applied SAFe® | Challenges of Compliance | February 2019 Page 23 Traceability: Ensure Process Compliance
  • 17. PEDCO – Bringing SAFe® to LIFE©PEDCO AG | Applied SAFe® | Challenges of Compliance | February 2019 Page 24 Mapped,harderforAssessment&QA, optimizedforusageincompany Process Design for regulated Environments PROCESSES NEED TO COMPLY, NOT TO REPLICATE A REFERENCE MODEL Reference Model • Process Area 1 • GP 1.1 • GP 1.2 • … • Work Products • WP 1 • WP 2 • … Company Process Model • Process Area 1 • GP 1.1 • GP 1.2 • … • Work Products • WP 1 • WP 2 • … Easy for Assessment CMMI • Process Area X • GP x.1 • GP x.2 • … • Work Products • WP x1 • WP x2 • … AS9100 • Process Area Y • GP y.1 • GP y.2 • … • Work Products • WP y1 • WP y2 • … A-SPICE 3.0 • Process Area Z • GP z.1 • GP z.2 • … • Work Products • WP z1 • WP z2 • … Custom • Process Area W • GP w.1 • GP w.2 • … • Work Products • WP w1 • WP w2 • … My Company Process Model • Epic Kanban • What I do • The way we like it • Is better for us • Work Products • SAD • CM Plan • … • Roles • Business Owner • Developer • Tester Spec with text / model _____ AAAAA BBBBBB Spec with text / model _____ AAAAA BBBBBB Spec with text / model _____ AAAAA BBBBBB Spec with text / model _____ AAAAA BBBBBB
  • 18. PEDCO – Bringing SAFe® to LIFE©PEDCO AG | Applied SAFe® | Challenges of Compliance | February 2019 Page 27 ...and identify gaps. Assure Compliance to Reference Models ENSURE COMPLIANCE WITH A SUSTAINABLE MECHANISM; AVOID INTERPRETATION GAMES Map standard requirements... ...to defined process assets © PEDCO AG 2019, Applied SAFe® all rights reserved
  • 19. PEDCO – Bringing SAFe® to LIFE©PEDCO AG | Applied SAFe® | Challenges of Compliance | February 2019 Page 28 Transparency in Execution and Continuous Compliance • Linda is the Agile Release Train Engineer • The program has run two PI’s so far. • Linda needs to get an approval from an assessment for compliance with there regulated requirements • Convince assessor that the program has a defined process variation • Prove that they know what, why and how they are ensure the stakeholder requirements. DEMO IN APPLIED SAFE WITH PI PLANNING
  • 20. PEDCO – Bringing SAFe® to LIFE©PEDCO AG | Applied SAFe® | Challenges of Compliance | February 2019 Page 29 AAMI: TIR 45 GUIDANCE ON THE USE OF AGILE PRACTICES IN THE DEVELOPMENT OF MEDICAL DEVICE SOFTWARE © 2012 Association for the Advancement of Medical Instrumentation AAMI TIR45:2012 http://www.pedco.eu/tir45-agile-in-medical/
  • 21. PEDCO – Bringing SAFe® to LIFE©PEDCO AG | Applied SAFe® | Challenges of Compliance | February 2019 Page 30 Effectiveness: Manage process variations
  • 22. PEDCO – Bringing SAFe® to LIFE©PEDCO AG | Applied SAFe® | Challenges of Compliance | February 2019 Page 31 Different use of Process Instances on Defined Levels OVERVIEW OF INSTANTIATIONS WITH DIFFERENT CONFIGURATIONS OF THE SAFE® MODEL
  • 23. PEDCO – Bringing SAFe® to LIFE©PEDCO AG | Applied SAFe® | Challenges of Compliance | February 2019 Page 32 Workspace and Instantiations in the real World A Swiss Banking Institute Example Process Instantiations can be done on any given level.
  • 24. PEDCO – Bringing SAFe® to LIFE©PEDCO AG | Applied SAFe® | Challenges of Compliance | February 2019 Page 35 Manage Process Variation • Linda is an Agile Release Train Engineer • Linda knows the company very well • The program has run one PI so far. • Linda has several years experience in IT and project management. • Linde loves to manage and is PMI-certified Project Manager. • She is also certified Scaled Agilest and has some knowledge of SAFe. • Linda wants to tailor the process accordingly to what was decided during I&A DEMO IN APPLIED SAFE
  • 25. PEDCO – Bringing SAFe® to LIFE©PEDCO AG | Applied SAFe® | Challenges of Compliance | February 2019 Page 36 Verification & Validation: Engineering based on SAFe® Principles & Practices Solution Intent and Solution Context Model-based Systems Engineering (MBSE) Definition od Done (DoD)
  • 26. PEDCO – Bringing SAFe® to LIFE©PEDCO AG | Applied SAFe® | Challenges of Compliance | February 2019 Page 37 RAPID LEARNING CYCLES INCREASE QUALITY AND REDUCE RISK Build Solution and Compliance Incrementally
  • 27. PEDCO – Bringing SAFe® to LIFE©PEDCO AG | Applied SAFe® | Challenges of Compliance | February 2019 Page 38 Example: Solution Intent in SAFe WHAT DOES THE CURRENT SYSTEM NOW, AND WHAT CHANGES ARE INTENDED FOR A FUTURE STATE Source: www.scaledagileframework.com
  • 28. PEDCO – Bringing SAFe® to LIFE©PEDCO AG | Applied SAFe® | Challenges of Compliance | February 2019 Page 39 Solution Intent APPLICATION IN DETAIL Source: www.scaledagileframework.com
  • 29. PEDCO – Bringing SAFe® to LIFE©PEDCO AG | Applied SAFe® | Challenges of Compliance | February 2019 Page 41 Context, theory with Applied SAFe HOW DO YOU WORK WITH DEFINITIONS OF DONE?
  • 30. PEDCO – Bringing SAFe® to LIFE©PEDCO AG | Applied SAFe® | Challenges of Compliance | February 2019 Page 42 Definition of Done MAKE V&V AND COMPLIANCE ACTIVITIES PART OF REGULAR FLOW
  • 31. PEDCO – Bringing SAFe® to LIFE©PEDCO AG | Applied SAFe® | Challenges of Compliance | February 2019 Page 43 Applied SAFe: Concepts DEFINITION OF DONE (DOD) IN SCALED AGILITY
  • 32. PEDCO – Bringing SAFe® to LIFE©PEDCO AG | Applied SAFe® | Challenges of Compliance | February 2019 Page 46 Relentless Improvement: Establish a Lean-Agile Learning Organization
  • 33. PEDCO – Bringing SAFe® to LIFE©PEDCO AG | Applied SAFe® | Challenges of Compliance | February 2019 Page 47 Quality Processes for Mature Agile Organizations METHODS AND PROCESSES FOR COMPLIANCE WITHIN REGULATED ENVIRONMENTS
  • 34. PEDCO – Bringing SAFe® to LIFE©PEDCO AG | Applied SAFe® | Challenges of Compliance | February 2019 Page 48 Lessons Learned
  • 35. PEDCO – Bringing SAFe® to LIFE©PEDCO AG | Applied SAFe® | Challenges of Compliance | February 2019 Page 49 Lessons Learned (1/2) Read/use available sources; e.g: • Software Engineering Institute: ‘Scaling Agile Methods for Departments of Defense Program • CMMI Institute: ‘A Guide to Scrum and CMMI’ • TIR45 from AAMI: ‘Agile practices in the development of medical device software’ Be very clear on what is compliance and what is not. • Mapping of scaled agility to reference model is surprisingly straight forward, once the lean-agile mindset is understood • Avoid the bear trap: Map compliance elements always to value adding deliverables • Automate mechanisms to prove mapping to reference models -> reduce discussion time and interpretation games • Some reference models ask for process- and product-specific requirements -> Scope those requirements for purpose Compliance is often a ‘negotiation game’ • Don’t forget the human element of stakeholders & appraisers • Solution Intent and agile Design control needs to be established Demonstrate compliance in small iterations based on flow’ • Avoid ‘quality depth’; do not ‘build in’ compliance at the end of development • Treat audits like a normal system demo • Focus on outcomes OF SCALED AGILE APPLICATIONS/MAPPINGS TO VARIOUS REFERENCE MODELS
  • 36. PEDCO – Bringing SAFe® to LIFE©PEDCO AG | Applied SAFe® | Challenges of Compliance | February 2019 Page 50 Lessons Learned (2/2) Some experiences: • A mapping of Scaled Agile Frameworks to reference models is achievable within a lower number of weeks. • Depending on the attributes of a solution or on existing documentation the form of ‘DoD’s can vary very much. • Commercial frameworks such as SAFe® or others are an excellent starting point to be applied in the development of high assurance systems. Separate ‘What shall be done’ from ‘How something is done’ • Model only necessary steps in the process • Build and rely on heuristics to model the process for usage • Ensure that practices can be changed/selected easily by performers Quality Management System • Let the QMS be easily accessible and easy to use. • Promote transparency for each endeavor, process instantiations need to be specialized to reduce waste. • Allow fast process changes and pilot in appropriate levels. • Allow process users to perform tailoring themselves in a controlled and easy way. Trust that they will do it good! OF SCALED AGILE APPLICATIONS/MAPPINGS TO VARIOUS REFERENCE MODELS
  • 37. PEDCO – Bringing SAFe® to LIFE©PEDCO AG | Applied SAFe® | Challenges of Compliance | February 2019 Page 51 Conclusion
  • 38. PEDCO – Bringing SAFe® to LIFE©PEDCO AG | Applied SAFe® | Challenges of Compliance | February 2019 Page 52 Scaled Agility can be successfully applied in regulated environments! Agile practices for reg. env. in SAFe: • Build the solution incrementally • Apply fast learning cycles • Apply objectives milestones • Demo frequently; routinely deliver objective progress, product, and process metrics • Organize around value • Build quality in • Apply continuous verification and validation • Include compliance concerns in Definition of Done • Solution intent as concept for requirements • Inspect & Adapt lead to continuous improvement FRAMEWORKS HAVE MOST OF THE HOOKS NEEDED FOR COMPLIANCE WITH HIGH ASSURANCE SYSTEMS ✓ Read and understand the regulations! Strive to map existing agile behavior and don’t impose unnecessary work. ✓ Regulated requirements have common background! ✓ Regulations do not imply how some thing shall be done. Use given freedom and map agile practices -> ✓ Not all regulations are as stringent as others; tailoring of processes is a must to reflect applicable regulations. ✓ Establish a managed process and Quality Management System (QMS) ✓ Address live cycle concerns of solutions (e.g. live time) ✓ Build your own Lean Agile Center of Excellence (LACE) ✓ Include executive level in the cultural change ✓ Lead the change, it won’t be easy ✓ Define governance and responsibilities, also on an Enterprise level ✓ Exchange your experience with others!
  • 39. PEDCO – Bringing SAFe® to LIFE©PEDCO AG | Applied SAFe® | Challenges of Compliance | February 2019 Page 53 Applied SAFe Value Proposition ADVANTAGES FOR YOU Customize and Extend Develop Compliant Implement SAFe Fast & Precise Learn, Innovate, and Improve
  • 40. PEDCO – Bringing SAFe® to LIFE©PEDCO AG | Applied SAFe® | Challenges of Compliance | February 2019 Page 54 Questions? Discussion?
  • 41. PEDCO – Bringing SAFe® to LIFE©PEDCO AG | Applied SAFe® | Challenges of Compliance | February 2019 Page 55 Tel. +41 44 542 45 45 www.pedco.eu pedco@pedco.eu PEDCO AG Zelgstrasse 5 CH-8003 Zürich