DISCLAIMER - NIKZAFRI.BLOGSPOT.COM

In order for to keep serving the readers with high quality articles/write-ups, I will need sponsors (will also write for any entities subject to terms and conditions. Also for prospects of consultancy or site visits - email me : nikzafri@gmail.com (All contacts and transaction shall be monitored under MACC Act and AMLATPUA). This blog also monitors IP/Mac Address including spoofed ones or protected by VPN



The information comprised in this section is not, nor is it held out to be, a solicitation of any person to take any form of investment decision. The content of the nikzafri.blogspot.com does not constitute advice or a recommendation by the author and should not be relied upon in making (or refraining from making) any decision relating to investments or any other matter. You should consult your own independent financial adviser and obtain professional advice before exercising any investment decisions or choices based on information featured in this.

The author of nikzafri.blogspot.com can not be held liable or responsible in any way for any opinions, suggestions, recommendations or comments made by any of the contributors to the various columns on nikzafri.blogspot.com nor do opinions of contributors necessarily reflect those of http://www. nikzafri.blogspot.com


In no event shall the author be liable for any damages whatsoever, including, without limitation, direct, special, indirect, consequential, or incidental damages, or damages for lost profits, loss of revenue, or loss of use, arising out of or related to the nikzafri.blogspot.com or the information contained in it, whether such damages arise in contract, negligence, tort, under statute, in equity, at law or otherwise.

CONSTRUCTION - WHAT A WORLD

The construction industry especially building or civil works may be complex and demanding, but to me it remains the most rewarding of all. Once a project is completed, teams disperse, some retire, others move on to the next site. Sometimes we bump into each other again on another project, and some just disappear into thin air.

The post-handover phase often feels quiet.

The real excitement lies in watching a project rise from the ground up. No matter our role or level, those of us in construction can always take pride in what we’ve built whenever we see a structure come to life and serve its purpose



MY EMPLOYERS AND CLIENTELLES




A THOUGHT

I identify myself as a Lifelong Learner and a Thought Leader

BIODATA - NIK ZAFRI



 



NIK ZAFRI BIN ABDUL MAJID,
CONSULTANT/TRAINER
Email: nikzafri@yahoo.com, nikzafri@gmail.com
https://nikzafri.wixstudio.com/nikzafriv2

Kelantanese, Alumni of Sultan Ismail College Kelantan (SICA), Business Management/Administration, IT Competency Cert, Certified Written English Professional US. Has participated in many seminars/conferences (local/ international) in the capacity of trainer/lecturer and participant.

Affiliations :- Council/Network Member of Gerson Lehrman Group, Institute of Quality Malaysia, Auditor ISO 9000 IRCAUK, Auditor OHSMS (SIRIM and STS) /EMS ISO 14000 and Construction Quality Assessment System CONQUAS, CIDB (Now BCA) Singapore),

* Possesses almost 30 years of experience/hands-on in the multi-modern management & technical disciplines (systems & methodologies) such as Knowledge Management (Hi-Impact Management/ICT Solutions), Quality (TQM/ISO), Safety Health Environment, Civil & Building (Construction), Manufacturing, Motivation & Team Building, HR, Marketing/Branding, Business Process Reengineering, Economy/Stock Market, Contracts/Project Management, Finance & Banking, etc. He was employed to international bluechips involving in national/international megaprojects such as Balfour Beatty Construction/Knight Piesold & Partners UK, MMI Insurance Group Australia, Hazama Corporation (Hazamagumi) Japan (with Mitsubishi Corporation, JA Jones US, MMCE and Ho-Hup) and Sunway Construction Berhad (The Sunway Group of Companies). Among major projects undertaken : Pergau Hydro Electric Project, KLCC Petronas Twin Towers, LRT Tunnelling, KLIA, Petronas Refineries Melaka, Putrajaya Government Complex, Sistem Lingkaran Lebuhraya Kajang (SILK), Mex Highway, KLIA1, KLIA2 etc. Once serviced SMPD Management Consultants as Associate Consultant cum Lecturer for Diploma in Management, Institute of Supervisory Management UK/SMPD JV. Currently – Associate/Visiting Consultants/Facilitators, Advisors/Technical Experts for leading consulting firms (local and international), certification bodies including project management. To name a few – Noma SWO Consult, Amiosh Resources, Timur West Consultant Sdn. Bhd., TIJ Consultants Group (Malaysia and Singapore), QHSEL Consultancy Sdn. Bhd.

He is also currently holding the Position of Principal Consultant/Executive Director (Special Projects) - Systems and Methods, ESG, QHSE at QHSEL Consultancy Sdn. Bhd.* Ex-Resident Weekly Columnist of Utusan Malaysia (1995-1998) and have produced more than 100 articles related to ISO-9000– Management System and Documentation Models, TQM Strategic Management, Occupational Safety and Health (now OHSAS 18000) and Environmental Management Systems ISO 14000. His write-ups/experience has assisted many students/researchers alike in module developments based on competency or academics and completion of many theses. Once commended by the then Chief Secretary to the Government of Malaysia for his diligence in promoting and training the civil services (government sector) based on “Total Quality Management and Quality Management System ISO-9000 in Malaysian Civil Service – Paradigm Shift Scalar for Assessment System”

Among Nik Zafri’s clients : Adabi Consumer Industries Sdn. Bhd, (MRP II, Accounts/Credit Control) The HQ of Royal Customs and Excise Malaysia (ISO 9000), Veterinary Services Dept. Negeri Sembilan (ISO 9000), The Institution of Engineers Malaysia (Aspects of Project Management – KLCC construction), Corporate HQ of RHB (Peter Drucker's MBO/KRA), NEC Semiconductor - Klang Selangor (Productivity Management), Prime Minister’s Department Malaysia (ISO 9000), State Secretarial Office Negeri Sembilan (ISO 9000), Hidrological Department KL (ISO 9000), Asahi Kluang Johor(System Audit, Management/Supervisory Development), Tunku Mahmood (2) Primary School Kluang Johor (ISO 9000), Consortium PANZANA (HSSE 3rd Party Audit), Lecturer for Information Technology Training Centre (ITTC) – Authorised Training Center (ATC) – University of Technology Malaysia (UTM) Kluang Branch Johor, Kluang General Hospital Johor (Management/Supervision Development, Office Technology/Administration, ISO 9000 & Construction Management), Kahang Timur Secondary School Johor (ISO 9000), Sultan Abdul Jalil Secondary School Kluang Johor (Islamic Motivation and Team Building), Guocera Tiles Industries Kluang Johor (EMS ISO 14000), MNE Construction (M) Sdn. Bhd. Kota Tinggi Johor (ISO 9000 – Construction), UITM Shah Alam Selangor (Knowledge Management/Knowledge Based Economy /TQM), Telesystem Electronics/Digico Cable(ODM/OEM for Astro – ISO 9000), Sungai Long Industries Sdn. Bhd. (Bina Puri Group) - ISO 9000 Construction), Secura Security Printing Sdn. Bhd,(ISO 9000 – Security Printing) ROTOL AMS Bumi Sdn. Bhd & ROTOL Architectural Services Sdn. Bhd. (ROTOL Group) – ISO 9000 –Architecture, Bond M & E (KL) Sdn. Bhd. (ISO 9000 – Construction/M & E), Skyline Telco (M) Sdn. Bhd. (Knowledge Management),Technochase Sdn. Bhd JB (ISO 9000 – Construction), Institut Kefahaman Islam Malaysia (IKIM – ISO 9000 & Internal Audit Refresher), Shinryo/Steamline Consortium (Petronas/OGP Power Co-Generation Plant Melaka – Construction Management and Safety, Health, Environment), Hospital Universiti Kebangsaan Malaysia (Negotiation Skills), Association for Retired Intelligence Operatives of Malaysia (Cyber Security – Arpa/NSFUsenet, Cobit, Till, ISO/IEC ISMS 27000 for Law/Enforcement/Military), T.Yamaichi Corp. (M) Sdn. Bhd. (EMS ISO 14000) LSB Manufacturing Solutions Sdn. Bhd., (Lean Scoreboard (including a full development of System-Software-Application - MSC Malaysia & Six Sigma) PJZ Marine Services Sdn. Bhd., (Safety Management Systems and Internal Audit based on International Marine Organization Standards) UNITAR/UNTEC (Degree in Accountacy – Career Path/Roadmap) Cobrain Holdings Sdn. Bhd.(Managing Construction Safety & Health), Speaker for International Finance & Management Strategy (Closed Conference), Pembinaan Jaya Zira Sdn. Bhd. (ISO 9001:2008-Internal Audit for Construction Industry & Overview of version 2015), Straits Consulting Engineers Sdn. Bhd. (Full Integrated Management System – ISO 9000, OHSAS 18000 (ISO 45000) and EMS ISO 14000 for Civil/Structural/Geotechnical Consulting), Malaysia Management & Science University (MSU – (Managing Business in an Organization), Innoseven Sdn. Bhd. (KVMRT Line 1 MSPR8 – Awareness and Internal Audit (Construction), ISO 9001:2008 and 2015 overview for the Construction Industry), Kemakmuran Sdn. Bhd. (KVMRT Line 1 - Signages/Wayfinding - Project Quality Plan and Construction Method Statement ), Lembaga Tabung Haji - Flood ERP, WNA Consultants - DID/JPS -Flood Risk Assessment and Management Plan - Prelim, Conceptual Design, Interim and Final Report etc., Tunnel Fire Safety - Fire Risk Assessment Report - Design Fire Scenario), Safety, Health and Environmental Management Plans leading construction/property companies/corporations in Malaysia, Timur West Consultant : Business Methodology and System, Information Security Management Systems (ISMS) ISO/IEC 27001:2013 for Majlis Bandaraya Petaling Jaya ISMS/Audit/Risk/ITP Technical Team, MPDT Capital Berhad - ISO 9001: 2015 - Consultancy, Construction, Project Rehabilitation, Desalination (first one in Malaysia to receive certification on trades such as Reverse Osmosis Seawater Desalination and Project Recovery/Rehabilitation), ABAC Centre of Excellence UK (ABMS ISO 37001) Joint Assessment (Technical Expert)

He is also rediscovering long time passions in Artificial Intelligence, ICT and National Security, Urban Intelligence/Smart Cities, Environmental Social and Governance, Solar Energy, Data Centers - BESS, Tiers etc. and how these are being applied.

* Has appeared for 10 consecutive series in “Good Morning Malaysia RTM TV1’ Corporate Talk Segment discussing on ISO 9000/14000 in various industries. For ICT, his inputs garnered from his expertise have successfully led to development of work-process e-enabling systems in the environments of intranet, portal and interactive web design especially for the construction and manufacturing. Some of the end products have won various competitions of innovativeness, quality, continual-improvements and construction industry award at national level. He has also in advisory capacity – involved in development and moderation of websites, portals and e-profiles for mainly corporate and private sectors, public figures etc. He is also one of the recipients for MOSTE Innovation for RFID use in Electronic Toll Collection in Malaysia.

Note :


TO SEE ALL ARTICLES

ON THE"LABEL" SECTION BELOW (RIGHT SIDE COLUMN), YOU CAN CLICK ON ANY TAG - TO READ ALL ARTICLES ACCORDING TO ITS CATEGORY (E.G. LABEL : CONSTRUCTION) OR GO TO THE VERY END OF THIS BLOG AND CLICK "Older Posts"

Saturday, May 23, 2026

HIGH RETURNS - SMALL CAPITAL?

Be cautious of investment apps that promise “high returns with very small capital” or claim you can become wealthy quickly with minimal effort.

Many of these platforms use attractive advertisements, fake testimonials, manipulated profit screenshots, and pressure tactics to lure people into depositing money. Some may initially show small “profits” to gain trust before eventually restricting withdrawals or disappearing altogether.

Before investing in any platform:

• Verify whether it is licensed and regulated by the relevant financial authorities.

• Avoid schemes that guarantee profits or “zero risk.”

• Do proper background checks on the company, founders, and payment methods.

• Never invest money you cannot afford to lose.

• Be extra careful when recruitment, referrals, or “top-up packages” become the main focus rather than genuine investment activities.

Remember:

If an investment sounds too good to be true, it usually is. Financial growth normally takes time, patience, proper knowledge, and calculated risk management.

IMPORTANCE OF A PROPER MONITORING SYSTEM



The images shown reflect actual incidents where TM responded promptly. In one case, suspects fled after nearby residents raised alarms. Permission was obtained before taking the photographs, including a still image captured from my concealed CCTV system.


CCTV systems have become increasingly important today, not only for businesses and infrastructure facilities, but also for homes including rooftops, perimeter areas, and blind spots often overlooked.

However, surveillance systems must never be misused for spying or invading others’ privacy. Such actions are unethical and illegal. Technology should always be used responsibly and within the law.

From my own experience, CCTV systems have helped detect suspicious individuals and monitor unusual activities around the neighbourhood. In some cases, integrated alarm systems connected to hidden surveillance devices including lamp-style units with concealed infrared sensors were able to trigger immediate alerts and deter possible intrusions.

While installing a proper monitoring system can be costly, it is ultimately a worthwhile investment. Protecting lives, assets, and critical infrastructure is far more important than the expense involved.

A proper monitoring system:

• Acts as both a deterrent and an evidence-gathering tool
• Allows real-time monitoring through mobile integration and remote access
• Requires strategic camera placement rather than simply installing large numbers of cameras
• Needs regular maintenance and testing for reliability
• Must comply with legal and ethical boundaries

Personally, I do not make such incidents viral or circulate them publicly. Instead, I hand the relevant information and recordings directly to the authorities.

This helps:

• Prevent investigations from being compromised
• Preserve the integrity of evidence
• Respect legal procedures and privacy
• Avoid rumours and misinformation
• Allow enforcement agencies to investigate professionally

Recently, there have been incidents involving attempts to steal electrical cables from stations and fibre optic cables from surrounding grounds.

Following brief discussions with relevant authorities as a concerned neighbour, both Tenaga Nasional Berhad and Telekom Malaysia officials reviewed CCTV footage from official systems and nearby premises

Observations suggested that these activities were not random, but involved individuals with some technical knowledge.

It was also highlighted that legitimate maintenance or replacement works can only be carried out by authorised contractors or qualified personnel familiar with shutdown procedures, cable routes, excavation points, and operational safety requirements.

Sometimes, vigilance from both the community and authorities can make a significant difference.

DON'T DO OTHER PEOPLE'S JOB


In a management and leadership context, this principle is about role clarity, accountability, and respect for organizational structure and it's not about avoiding teamwork.

Core principle
Do not perform or take over another person’s responsibilities without proper authority, agreement, or coordination.
Management
In an effective organization:
  • Respect defined roles and responsibilities
  • Every team member is assigned specific duties. Overlapping or bypassing roles without consent can disrupt workflow and accountability.
  • Maintain clear accountability
  • When someone else’s task is done by another person unofficially, it becomes unclear who is responsible for outcomes, errors, or decisions.
  • Avoid undermining authority structures
  • Taking over tasks without permission can unintentionally weaken supervisors, team leads, or assigned owners of the work.
Coordinate, don’t override
If support is needed, the correct approach is to communicate, offer assistance, or escalate through proper channels not to replace the assigned person.
  • Prevent confusion and duplication of work
  • Uncoordinated intervention can lead to conflicting decisions, rework, or inconsistent outputs.
Support teamwork through trust, not substitution
A strong team is built on trust in each member’s role, while still being ready to assist when formally requested.
Escalate concerns properly
If someone is underperforming or unavailable, the issue should be raised to the appropriate supervisor rather than independently taking over their responsibilities.
Leadership
Good leadership is not about doing everything yourself or others’ work it is about ensuring the right people do the right tasks, at the right time, through the right process

WARNING: Possible Scam Loan Offer Using Government Email Identity

 


I want to share this as a public awareness message.

Recently, there has been an email circulating offering a “working capital loan for business owners” claiming to come from:
...........@ camacari [dot] ba [dot] gov [dot] br

At first glance, the domain looks like an official government address (and technically, the domain format does exist as part of a Brazilian municipal system). However, several red flags strongly indicate this is a fraudulent or phishing attempt: - No official application portal or government website provided - No proper reply-to government address instead uses: .......@ outlook [dot] com Requests contact via WhatsApp (+1 US number), which is not standard for government loan programs - Generic message offering loans “for all categories” without eligibility criteria - No official program name, reference number, or verification channel - Suspicious mismatch between government domain and external personal contacts Important Reminder Even if an email appears to come from a legitimate government domain, it can still be: Spoofed (fake sender identity) or Misused in phishing attempts My Advice: - Do NOT respond to such emails - Do NOT contact the WhatsApp number provided - Do NOT share personal, banking, or business documents Always verify loan schemes through official government websites only Thus : If a “government loan” requires WhatsApp contact or Outlook/Gmail replies, treat it as highly suspicious.
Stay alert and share this to protect others, especially business owners.

Friday, May 22, 2026

PROJECT MANAGEMENT 101 : WORK IN A TEAM

Project Management 101:

Work in a Team

Yes, there are moments when independent work is necessary, but in construction, those situations are rare. Most of the time, the nature of the industry demands collaboration, coordination, and constant communication across multiple disciplines. Very few tasks can truly be done in isolation. One common mistake during construction meetings or consultancy work is the moment someone assumes they can handle the assigned task alone. The first and most critical failure is the inability or unwillingness to work effectively with others. In most cases, it is already foreseeable, without even a formal risk assessment, that the assignment will fail regardless of how competent one believes they are. - Overconfidence leads to isolation in decision-making - Lack of collaboration weakens project execution - Ignoring team input increases avoidable errors and rework - Technical skill alone is not enough without coordination - Early warning signs of failure are often visible but overlooked - Successful delivery depends on shared responsibility, not individual dominance
Yes, I have seen this pattern before, and the outcome is rarely positive. When collaboration breaks down, colleagues tend to disengage, observing from a distance rather than contributing actively. Over time, trust erodes, and communication becomes minimal. In some cases, even non-verbal reactions during meetings especially when issues are raised by clients can reflect underlying frustration or loss of confidence in the team dynamic

Thursday, May 21, 2026

This scammer is really getting on my nerves


There are several strong signs this could be a phishing or scam email impersonating LEMBAGA HASIL DALAM NEGERI Malaysia/HM Revenue & Customs (HMRC) style tax authorities.


Here are the red flags:

Wrong / mixed terminology : Malaysia’s tax authority is usually referred to as LHDN or IRBM, not “HMRC” (which is the UK tax authority: HM Revenue and Customs).

- The email mixes “Akta Kastam 1967” and “Akta Cukai Pendapatan 1967” strangely in one notice.

- Suspicious short link - ....bttlib [dot] s [dot] gy... is highly suspicious.
Government agencies in Malaysia normally use official domains such as: hasil [dot] gov [dot] my, mytax [dot] hasil [dot] gov [dot] my. Shortened links are commonly used in phishing attacks to hide the real destination.

- Generic formatting

The letter lacks:

official reference number, taxpayer/company name, tax file number (TIN) assessment number, branch office details, formal letterhead

Real audit notices are usually far more structured.

Pressure tactics

“7 working days” plus threats of enforcement are common social engineering tactics to induce panic and rushed action.

Odd signature block

The inclusion of an IC number (“No. KP”) of Director General? in this manner is unusual for official correspondence. Government emails typically contain department contacts, official extension numbers, and verifiable office information.

Language inconsistencies

“Penalti Pentadbiran Cukai”, “Pendapatan boleh cukai kurang dilaporkan”, “Bayaran kurang bagi PCB”

These are technically plausible phrases, but the overall composition reads more like copied/generated text than a formal assessment notice.

What you should do immediately:

Do NOT click the link, Do NOT download attachments, Do NOT reply, Check directly via the official tax portal:

MyTax Portal, LHDN Official Website

Call LHDN directly using numbers from the official website only.

Additional safety steps:

- Hover over the sender’s email address and inspect the real domain, Check email headers for spoofing.

If anyone clicked the link:

- change passwords immediately, enable MFA/2FA, run antivirus scans, monitor bank and tax accounts

Final Verdict : It's a SCAM

Tuesday, May 19, 2026

DIRECTOR RESPONSIBILITY UNDER GOOD GOVERNANCE

As a Director, we need to fully understand the responsibilities, fiduciary duties, and legal accountabilities entrusted upon us under the law. It is not merely a title, but a serious obligation that requires continuous learning, awareness, and ethical governance.

It is therefore essential for Directors to actively participate (which in courses, forums, conferences, audits, assessments, and governance-related programmes involving Anti-Bribery and Anti-Corruption, Anti-Money Laundering (AML), Counter Financing of Terrorism (CFT), the Anti-Money Laundering, Anti-Terrorism Financing and Proceeds of Unlawful Activities Act 2001 (Act 613), MACC Act (esp 17A) CCMA, corporate governance, compliance, integrity, risk management, and regulatory requirements.

Over the years, I took my own initiative to be involved in programmes and engagements with organisations and authorities such as BNM, SC, SSM, ROS, CCM and many others. (I still do) Directors should take proactive initiative to equip themselves with knowledge, compliance awareness, and governance competencies instead of waiting until enforcement authorities issue summonses, investigations, or regulatory actions. Prevention, awareness, integrity, and accountability are always better than damage control after a crisis occurs.
Good governance is not only about protecting the company, but also protecting shareholders, employees, stakeholders, public trust, and ultimately the nation's integrity and economic stability.

Monday, May 18, 2026

FAKE PROFILES AND FAKE SERVICE REQUESTS

Been dealing with a growing number of fake accounts and impersonators on my service request page lately. Most of them are not even within my network or professional circle. I’ve blocked many of these accounts, reported several, yet more continue to appear. 

Some of these are clearly the same individuals operating multiple fake LinkedIn accounts often without profile photos, using suspicious job titles, copied profiles, or recycled information from legitimate users. That’s one of the reasons why I prefer proper email communication and PMs, as it makes tracing and verification much easier.

What’s interesting is that many of these accounts appear to originate from the same country, while some pretend to be from other countries, including Malaysia. Unfortunately, online impersonation and social engineering tactics are becoming more common nowadays.

They probably assumed they were targeting an ordinary user this time. Instead, they attempted to deceive someone already familiar with cyber security, digital footprints, impersonation patterns, and verification methods.

Always verify before trusting. A professional profile does not always mean a genuine person behind it.

To everyone engaging online, please verify profiles carefully before interacting, especially when it involves business, services, or professional matters. The digital space is becoming increasingly vulnerable to scams, fake identities, and misleading accounts. Stay alert, protect your information, and always exercise caution.

Sunday, May 17, 2026

PREPARING A PROPOSAL/QUOTATION - Things you need to be aware of. (from my own experience)

Disclaimer: The following tips may not apply universally to every consultant or consultancy firm. However, many of the points highlighted here represent common industry practices, professional expectations, and generic fundamentals that consultants should generally be aware of.

Different consultants may have different approaches, methodologies, and working styles depending on their field, experience, and organisational culture. Nevertheless, there are also many similarities in terms of professional conduct, commercial practices, project management, client engagement, ethics, and risk management much of which is reflected in my own experience and practice.

"Do not be too proud or talk in an arrogant manner especially if you've invited into Board Meetings, remember you're just a Consultant, not a CEO or President of a major corporation"

(I’ve seen this mistake happen before, and it can be one of the most damaging ways to engage with clients. Always remain calm and composed, especially when being grilled with questions, the client is often testing your resilience, depth of knowledge, and how you handle pressure in a crisis situation. Remember that today’s knowledge can quickly become yesterday’s. It is important to continuously update yourself with current industry developments, especially in areas such as AI and emerging technologies, to stay relevant and effective.)

PREPARING A PROPOSAL AND QUOTATION

When preparing a proposal and quotation for consultancy services whether in construction, engineering, management, ICT, ESG, training, or any other industry, it is common practice to provide a proper breakdown of the scope of work, deliverables, phases, man-days, and the corresponding cost for each item before arriving at the grand total.

At the proposal stage, you normally do not provide a full detailed schedule or execution programme yet unless the quotation has been officially approved or awarded. The quotation stage is usually part of the commercial evaluation and negotiation process. Clients are expected to negotiate on pricing, scope, duration, or deliverables, so ensure that whatever you quote remains commercially reasonable, technically justifiable, and aligned with current market practices.

Do your homework properly. Conduct market surveys, understand prevailing industry rates, benchmark competitors where possible, and ensure the value you provide matches the fee you are charging. Sometimes providing a few additional value-added services, limited advisory support, or certain minor items on an FOC basis can strengthen client confidence and improve long-term relationships.

It is also common industry practice to request a mobilization fee or upfront payment upon award confirmation. This reflects the consultant’s initial commitment cost such as travelling, accommodation, manpower preparation, preliminary site visits, documentation, insurance, and operational readiness. In some projects, the client may separately cover OPE (Out-of-Pocket Expenses), but in many cases mobilization is necessary before any substantial work begins. From a business and risk management perspective, obtaining the mobilization fee first is important to ensure commitment from both parties.

Another important point, never simply “sub-out” the entire job using your own company name if you do not possess the required competency, technical capability, or experience in the field you are quoting for. But you can collaborate with other experts/consultants in the field that you do not possess the strength. Clients today commonly conduct background screening, capability assessments, financial reviews, and technical evaluations before appointing consultants. If your documentation, experience, certifications, and procedures are genuine, there is nothing to fear.

At the same time, consultants should also conduct their own due diligence on clients discreetly and professionally. Review their company background, annual reports, financial standing, project track record, litigation history if any, ownership structure, and identify who the actual decision makers or PICs are. This is part of proper commercial risk management.

Equally important is maintaining ethical boundaries. Be cautious of red flags that may expose you to bribery, corruption, kickbacks, or disguised “facilitation payments.” Some payments may appear harmless initially but can later create legal, contractual, governance, or reputational problems. Proper documentation, transparency, and compliance with company SOPs and anti-bribery policies are extremely important.

As for marketing commissions, there is a major difference between legitimate business development arrangements and unethical inducements. In my own practice, when a marketer successfully helps secure a project, I normally compensate them through an agreed marketing commission. More importantly, I encourage them to remain involved in the project execution itself so the commission reflects actual contribution and continuing value creation. Additional payments are then tied to actual involvement, phases completed, deliverables, or man-days contributed rather than hidden transactions.

Lastly, from experience, I would strongly advise consultants to be very careful about proceeding with consultancy work, training programmes, or project execution entirely using your own funds first with the intention to “claim later,” even if you have sufficient capital reserves. In reality, this often leads to prolonged disputes over claims, delayed payments, variation disagreements, documentation arguments, strained relationships, and in some cases escalation into legal disputes or court proceedings.

A good consultancy engagement is not only about technical capability. It is also about professionalism, documentation, ethics, commercial awareness, risk management, financial discipline, and protecting both parties through clear procedures and proper agreements from the very beginning.


Saturday, May 16, 2026

TWO LIVING LEGENDS OF CULINARY WORLD

 


(This is not a real photo, only AI-generated.)
I think it’s the wish of many fans, including myself, to see two world-renowned culinary icons, Robert Irvine and Gordon Ramsay , sharing the same space together. Watching two leading chefs and personalities in the food industry side by side is truly a rare and exciting moment for food lovers around the world.
Their dedication, creativity, discipline, and influence have inspired countless chefs, restaurateurs, and aspiring culinary talents globally. Beyond cooking, they have elevated the culinary profession into an art form and a respected global industry.
Moments like this remind us how food can connect cultures, inspire passion, and bring people together through excellence, innovation, and shared experience


Friday, May 15, 2026

DIGITAL BANKING AS CRITICAL INFRASTRUCTURE

Maybank stated on its website that the service disruption would last until 8.00 a.m., but it is now already 10.20 a.m. Maybank also mentioned that balance checking (limited view) was still available, yet the app shuts down almost immediately upon entry.

I had a very urgent matter and needed to carry out an important transaction about an hour ago, and I am sure many other account holders are facing the same situation. Receivers are already making noise because payments and transfers cannot be completed. In the end, I have no choice but to do things manually, and the nearest Maybank branch is about 3 km away which I had to walk (taking a bus would be too tricky) as my car is used by my son.
I believe the estimated recovery time should have been communicated more accurately instead of issuing what appears to be a generic copy-and-paste explanation. Please understand that this is a serious matter affecting many users, businesses, commitments, and urgent transactions.
Maybank has one of the most user-friendly and technologically advanced banking apps in Malaysia, which is why expectations are naturally high. A few months ago, I even advised another bank that pending maintenance, the must ensure proper backup systems not only for ATMs, but also for their banking applications and digital infrastructure themselves. I suppose it's written in your banking manual as well.
System maintenance and disruptions can happen, but timely updates, transparent communication, and reliable fallback systems are equally important in maintaining public confidence and trust. The response and my interaction :
My proposal :
DIGITAL BANKING AS CRITICAL INFRASTRUCTURE



My experience interacting with a banking service disruption has reinforced a some observations I’ve consistently raised in my advisory work with other financial institutions, particularly around ICT resilience, application architecture, and operational risk management. I've been involved in gap analysis, risk assessments, and process improvement reviews for various financial and banking-related systems. A few key reflections stand out: Some banks now enforce a strict “one device, one account” policy, limiting access to a registered mobile device and removing or restricting web-based access. While I fully understand the rationale, strengthening security against fraud, bribery, money laundering, and scam risks, it raises a practical question: Why do other banks maintain both mobile app and web access concurrently, yet still achieve strong security controls through multi-factor authentication, device binding, and behavioural monitoring? This becomes a balance between security hardening and operational accessibility, especially during service disruption scenarios. 1) Common technical challenges in banking applications Issues often arise from: - Tight coupling between frontend apps and backend services - Lack of proper failover or redundancy layers - Insufficient separation between production and maintenance environments - Rapid deployment cycles without robust rollback mechanisms These are typically solvable through stronger DevOps practices, microservices segregation, and better release governance. 2) Business continuity and backup readiness I emphasised to one bank that backup systems must extend beyond ATMs. They must also include digital banking applications, web banking platforms, payment gateways and authentication services True resilience is not just physical redundancy, it is digital continuity. 3) Maintenance and upgrade strategy in banking apps Best practice in many institutions is to avoid direct disruption of the live system by: - Running parallel environments (production vs staging) - Performing upgrades in mirrored systems - Gradually rolling out updates (blue-green deployment or canary releases) In contrast, when upgrades are performed directly on the same production instance without a parallel fallback layer, users experience full-service interruption during maintenance windows. 4) Universal View Digital banking has evolved into a critical infrastructure service. As such, expectations around uptime, transparency, and fail-safe design are now similar to utilities. Even short disruptions have immediate real-world financial impact on individuals and businesses. The key challenge moving forward is not only security vs convenience, but also resilience vs transformation speed and how well institutions balance both without compromising trust.
End users rarely see the complexity behind these systems but they always feel the impact when something breaks.