Showing posts with label iso 9001. Show all posts
Showing posts with label iso 9001. Show all posts

Saturday, February 4, 2012

ISO 9001 Standard Quality Manual Template

The quality manual is the necessary cornerstone for any business venturing out on the ISO 9001:2008 accreditation route as it exhibits top management’s determination to managing an useful quality management system. The quality manual is a type of most essential document which provides the right impression to clients, staff, inspectors and all the parties interested in your company, about your company’s efforts to satisfy all their clientele’s needs. People through your company will relate to it whenever they prefer to find the big picture of the system, or exactly what guidelines have been organized. You can save your valuable time and hard earned money with the quality manual template we offer you. If you really compile the quality manual, you will easily comprehend and apply ISO 9001:2008, which is one of the best methods to do so.By reading by the needs one-by-one and assigning each prerequisite a specific document, process or technique that exists within your company, you will get that over half of the demands have already been resolved. Quality manual makes the relation, between the process and the documents, an official one. Format and content Write your quality manual to ensure that it works for you, for your company and also the manner you work, it is totally your selection however generally make sure that it supports your organisation’s targets. The quality manual should not contain any confidential or proprietary information as it should be readily available to third party auditors and customers. You should also ensure that a clear distinction is made between the contents of the quality manual and the procedures. The quality manual identifies the intention of top management for the operation of the quality management system, whilst the operations explain how these kind of purposes are integrated. There are three things that must be included in the quality manual:

1. The probability of the quality management system such as details of the validation of any exclusions

2. For quality management system, the procedures should be standard or should be mentioned in them

3. A explanation of the discussion between the procedures of the quality management system Who will use your Quality Manual and why?

In general, the clients and the prospective customers need it in order to know how your company system meets their requirements. If your quality manual includes two pages, it may not motivate trust that your system is strong enough to be an useful quality management system. Customers and Clients want assurance that you know how to plan, implement, and control the processes that affect their products or service delivery. The third party inspectors will b interested to know how your company meets their standard needs and also if perhaps the quality management system is useful in accomplishing your organization’s targets. Auditors will use the quality manual as a guide to help out discover and also form the purpose facts that they have to find in exhibition of your company’s compliance with the standard. Internal inspectors can review and inspect their own company for their needs rather than referring to standard documents from external sources. Management ought to be able to determine, from the manual, how the numerous processes and also systems have interaction, and at a high level what policies and methods have been established to maintain and control the processes and systems . The quality manual is usually presented to fresh recruits to familiarize themselves with the organization’s quality management system and also the manuals are often used as an in-house training resource. Most importantly, your quality manual ought to not sit on a dirty shelf or be hidden in an obscure position on the computer network; it is an active and powerful document that requires coverage in order for it to grow and also improve. Please click on the links below to learn more about Quality Manual Templates and view some free examples.

Wednesday, August 3, 2011

ISO 9001 Standard Quality Manual Template

The quality manual is the necessary cornerstone for any business venturing out on the ISO 9001:2008 accreditation route as it exhibits top management’s determination to managing an useful quality management system. The quality manual is a type of most essential document which provides the right impression to clients, staff, inspectors and all the parties interested in your company, about your company’s efforts to satisfy all their clientele’s needs. People through your company will relate to it whenever they prefer to find the big picture of the system, or exactly what guidelines have been organized. You can save your valuable time and hard earned money with the quality manual template we offer you. If you really compile the quality manual, you will easily comprehend and apply ISO 9001:2008, which is one of the best methods to do so.By reading by the needs one-by-one and assigning each prerequisite a specific document, process or technique that exists within your company, you will get that over half of the demands have already been resolved. Quality manual makes the relation, between the process and the documents, an official one. Format and content Write your quality manual to ensure that it works for you, for your company and also the manner you work, it is totally your selection however generally make sure that it supports your organisation’s targets. The quality manual should not contain any confidential or proprietary information as it should be readily available to third party auditors and customers. You should also ensure that a clear distinction is made between the contents of the quality manual and the procedures. The quality manual identifies the intention of top management for the operation of the quality management system, whilst the operations explain how these kind of purposes are integrated. There are three things that must be included in the quality manual:

1. The probability of the quality management system such as details of the validation of any exclusions

2. For quality management system, the procedures should be standard or should be mentioned in them

3. A explanation of the discussion between the procedures of the quality management system Who will use your Quality Manual and why?

In general, the clients and the prospective customers need it in order to know how your company system meets their requirements. If your quality manual includes two pages, it may not motivate trust that your system is strong enough to be an useful quality management system. Customers and Clients want assurance that you know how to plan, implement, and control the processes that affect their products or service delivery. The third party inspectors will b interested to know how your company meets their standard needs and also if perhaps the quality management system is useful in accomplishing your organization’s targets. Auditors will use the quality manual as a guide to help out discover and also form the purpose facts that they have to find in exhibition of your company’s compliance with the standard. Internal inspectors can review and inspect their own company for their needs rather than referring to standard documents from external sources. Management ought to be able to determine, from the manual, how the numerous processes and also systems have interaction, and at a high level what policies and methods have been established to maintain and control the processes and systems . The quality manual is usually presented to fresh recruits to familiarize themselves with the organization’s quality management system and also the manuals are often used as an in-house training resource. Most importantly, your quality manual ought to not sit on a dirty shelf or be hidden in an obscure position on the computer network; it is an active and powerful document that requires coverage in order for it to grow and also improve. Please click on the links below to learn more about Quality Manual Templates and view some free examples.

Read more on ISO 9001 at http://www.iso-9001-store.com

Tuesday, May 24, 2011

Why Quality System Training Is Important In ISO 9001 Standards?

Quality system design is an essential foundation for successful quality management, but quality systems training – for all employees – maybe the key to successful implementation and maintenance.

For most life science companies, maintaining a quality system has become a way of life. However, it probably isn’t these companies’ quality systems that keep their products and services afloat.

Yes, the manner in which a quality system is designed is duly important but the reality of the situation is that many quality system designs can work equally well in the same (or similar) environments. For example, one life science company may implement a well-known and highly recommended quality system design (ISO 9001 for example) and find great success while another very similar company may implement the same system and fail miserably.

The ability to get company employees to “buy into” a quality system is likely to make a big difference in a “pass or fail” quality system trial even, when a well known quality system design has been implemented. Whether it is change control, CAPA management, internal audits, customer complaints management, document control or deviations management, every company employee needs to know the following regarding his or her company’s quality system:

  1. What the quality system policies are (at least those that will directly or indirectly affect him or her);
  2. What the company’s objectives are in relation to the quality system policies, especially those objectives which the employee may be contributing to directly or indirectly;
  3. What the company’s plans are to achieve those objectives especially those plans that will directly or indirectly affect the employee involved.

Every company should also take steps towards the testing of every employee’s comprehension of policies, objectives and plans related to quality system management. Measuring comprehension does NOT infer that a written exam be administered to employees. Perhaps simple observation from employee supervisors will be sufficient to determine whether one employee has a sufficient grasp of the policies objectives and plans that he or she should be aware of.

According to the FDA’s guidance document: Quality Systems Approach to Pharmaceutical cGMP Regulations, “Policies, objectives, and plans under a modern quality system provide the means by which senior managers articulate their vision of and commitment to quality to all levels of the organization.”1

The FDA guidance also states that “senior management should incorporate a strong commitment to quality into the organizational mission.”2This of course can be accomplished by writing a “commitment to quality statement” in the company’s organizational mission. However, without training, employees are unlikely to care about or even think about quality management ideals and expectations.

To remedy this common dilemma, quality managers need to consider taking the following steps:

  1. Ask Questions – Quality managers need to take time to talk, and most importantly, ask questions of every employee involved in quality. Well thought out questions regarding quality will at the very least get employees considering the endeavors they are involved in.
  2. Delegate – More and more, quality is becoming less of a department and more of a group effort. That may seem scary for quality professionals but the reality is that delegation to numerous people (and/or departments) – combined with consistent follow through – always results in better business and better relationships between those who lead and those who follow.
  3. A Quality Example – If quality managers don’t take quality seriously then it is less likely that other department employees will take the time to contribute to a company “quality cause.”

In short, quality management system may at times seem complex but it’s actually like most managerial responsibilities – primarily a people process.

Visit http://www.iso9001store.com for moure information.

Tuesday, July 13, 2010

What is ‘Root Cause Analysis’ In ISO 9001 Standards?

What is ‘Root Cause Analysis’ In ISO 9001 Standards?
Suppose you come across a dandelion weed while in your garden. (If you have as little time in the garden as I do, at times you may find too many!) You pull off the head of the dandelion and all the leaves. There – you can’t see it any more.
The question is: does this fix the problem?
To illustrate, let me share some findings from an audit in a type of courier company. They collect & deliver items for their customers, and have contracts with large customers. If any customer complaints arise, the operations manager must respond in writing.
For audit, I chose a sample of complaints from the last 3 months and looked at what they’d done with them. Most complaints were for late/missed pick-ups or deliveries.
Some sample responses from the manager to the client:
A. This route has too many sites on it, we are looking at changing it.’
B. ‘The entry disappeared from the system. It was re-entered, and the pick-up went ahead the next day.’
C. ‘The driver was new and didn’t know. He has been spoken to.’ (A week later, the same driver missed another pick-up for the same customer.) ‘He no longer works for us.’
D. ‘I can only assume this happened while I was on leave, and the supervisor didn’t know he had to respond to your calls urgently.’

And my favourite E: ‘The driver was late because there were delays during the day.’
These responses are typical of just looking at symptoms: pulling off the dandelion leaves. That approach leaves the root of the problem still intact. Like the dandelion, you can pretty much bank on the fact that it’s going to come up again. And again. And again. Until you do something to find the real cause (or causes). That’s effective root cause analysis, because you get to the root: the real underlying cause.
For example: Why does a route have ‘too many sites’ on it? What does ‘looking at changing it’ mean? Has it been done? If it was changed, did the changes work? If not, when will it be done? How did that route get ‘too many sites’ on it? And what would stop that happening again, or on another route?
Consider the ‘new’ driver: Why didn’t he know what to do? Had he received the information he needed such as induction and training? If not, why not? Why is ’speaking to’ a driver adequate to prevent recurrence? (it’s not) Has the company reviewed how it selects its drivers? Because the recurrence a week is a strong sign of inadequate cause analysis and ineffective corrective action.
Why Find the Root Cause?
Most organisations are busy and somewhat chaotic. Immediacy often rules. So there’s often a tendency to go for the quick fix – treat the symptom rather than the real, underlying cause. The driver is ’spoken to’, the order ‘re-entered into the system’. But this almost guarantees the same or very similar situation will recur, and have to be dealt with again. And again.
When problems come up in your organisation – which they will – you can choose how to respond. You can look for someone to blame and stop at the symptom (’the driver was new… the supervisor didn’t know… it disappeared from the system’). Quite apart from the damage it causes to personnel relations, this approach isn’t effective.
An organisation with an intelligent approach to quality knows the value of a systematic approach to problems, including root cause analysis. The best question is: What can we learn from this situation? And then: How can we apply that learning to improve?
When Should You Use Root Cause Analysis?
If you have or aspire to ISO 9001, you must have a systematic approach to problems: nonconformance, corrective and preventive action. Without it, you’ll find it hard to pick problems for root cause analysis, because they’re often distributed over time (so you don’t realize they recur), or happen to different people (so you don’t realise they recur in your organisation).
Good candidates for root cause analysis are the situations that recur most often, and use the most resources to rectify or those that cause the most damage when they do.
Remove the Root Cause or Not?
After you’ve identified the root cause/s, you have to decide if it’s worth removing the root cause or whether you continue to treat the symptoms. This isn’t always an easy decision.
It’s often relatively easy to estimate the cost of removing the root cause, but less easy to assess the cost of not doing so. Suppose, for example, a truck breakdown turns out to have been caused by ineffective maintenance by a supplier. And suppose that supplier costs $10,000 less per year than the other. Superficially, the cost vs savings looks good.
But suppose that also means a truck off the road for at least an extra 5 days a year – and your largest customer got so angry about one too many crucial but failed pick-ups that they don’t renew your contract. And tell everyone what an unreliable company you are.

Friday, October 2, 2009

KEY CONSIDERATIONS IN IMPLEMENTING ISO 9001 IN SMEs

KEY CONSIDERATIONS IN IMPLEMENTING ISO 9001 IN SMEs
There are many issues that must be addressed in moving the QMS from the initial state to the desired state. For example, all organizations implementing ISO 9001 will need to consider the unique culture within the organization, its size, and the resources available. Beyond those widely discussed points, three issues that merit particular attention are (1) consideration of the QMS as a parallel function, (2) training, and (3) auditing. Key points associated with these issues are discussed below.
Consideration of QMS as Parallel Function
In the case of all of the transitions depicted, real benefits from the QMS are more likely to be experienced if the QMS is implemented directly into the core structure of the organization. SMEs must be cautious against establishing a QMS that is run separately in parallel to its other systems. In SMEs, the parallel subsystem most commonly exhibits itself as a separate Quality Assurance, or in some cases, ISO 9001 department. Possible reasons for this may include the existence of rigid departmental boundaries in some SMEs or overemphasis on core activities. As Yauch and Steudel [10] note, SMEs tend to focus their attention on “…necessary routine activities (such as sales, production, shipping, etc.) rather than activities aimed at improving processes or systems.” If a SME insists on establishing a separate quality department, its level of effectiveness can be increased by embedding the QMS in widely-used organizational systems where practical. The integration is largely a function of how well the QMS manages to share information with other subsystems and its ability to align with the policies, norms, goals, and values in place throughout the organization.
Training
In SMEs, training and staff development is more likely to be ad hoc and small scale because of modest human and financial resources and the absence of a specific training budget. To prevent the problems arising from lack of education and training, two things must be done:
1. Education of Top Management: The centralization of decision-making processes within many SMEs means that the management can either be the main stumbling block to change or the main catalyst for change. Therefore, any approach to ISO 9001 implementation must involve considerable education for the top management of the organization to create awareness and understanding of the implementation process as a change initiative. Implementing a fully functional and documented QMS requires motivation by top management to appreciate, achieve, and implement the necessary measures to meet the standards’ criteria.
2. Education and Training of Employees: SMEs are often under pressure to quickly gain ISO 9001 registration. Meeting the requirements of the standard in a short period of time can prove a formidable obstacle for a small company. Since most SMEs do not possess the needed expertise internally, they may be inclined to hire external experts to provide the necessary technical expertise and manpower. However, having a functioning and documented QMS requires more than that. It requires ensuring that all employees in the organization clearly know what is expected of them and how they can contribute to the attainment of their organizations’ goals. This will likely require the preparation and implementation of a training plan tailored specifically to the unique characteristics and maturity level of the SME.
Auditing
As emphasized throughout the paper, a QMS is not going to produce the expected results unless it is fully functional. While auditing must therefore verify the existence of the necessary documentation, it must also focus on the functionality of the QMS. The measurement of the functionality and the qualitative and financial impacts of a QMS have been the subject of several studies, including Kaynak [11]. Among the categories used to measure functionality and performance improvement, two are particularly noteworthy for our purposes: management commitment and employee involvement. A QMS cannot be functional in the absence of those two characteristics. Therefore, as a minimum, internal and external auditors should continually verify top management’s commitment to increased company-wide quality awareness and improvement in addition to employee involvement in the design, implementation, operation, and improvement of quality related processes and procedures.

Monday, August 31, 2009

Establishing a ISO 9001 records procedure

The standard requires records to remain legible, readily identifiable and retrievable and that a procedure defines the controls needed for the identification, storage, protection, retrieval, retention time and disposition of records. Records have a life cycle. They are generated during
which time they acquire an identity and are then assigned for storage for a prescribed period. During use and storage they need to be protected from inadvertent or malicious destruction and as they may be required to support current activities or investigations, they need to be brought out of storage quickly. When their usefulness has lapsed, a decision is made as to whether to
retain them further or to destroy them. Readily retrievable means that records can be obtained on demand within a reasonable period (hours not days or weeks) Readily identifiable means that
the identity can be discerned at a glance.

Although the requirement implies a single procedure, several may be necessary because there are several unconnected tasks to perform. A procedure cannot in fact ensure a result. It may prescribe a course of action which if followed may lead to the correct result, but it is the process that ensures the result not the procedure.

The revised requirement omits several aspects covered in clause 4.16 of the 1994 version.
Collection of records is now addressed by Analysis of data (clause 8.4)
Indexing of records is a specific form of identification and is therefore already addressed
Access is now addressed by the requirement for record retrieval
Filing is a specific form of storage and is therefore already addressed

You may only need one procedure which covers all the requirements but this is not always practical. The provisions you make for specific records should be included in the documentation for controlling the activity being recorded. For example, provisions for inspection records should be included in the inspection procedures; provisions for design review records should be included in the design review procedure. Within such procedures you should provide the forms (or content requirement for the records), the identification, collection/ submission provisions, the indexing and filing provisions. It may be more practical to cover the storage, disposal and retention provisions in separate procedures because they may not be type-dependent. Where each department retains their own records, these provisions may vary and therefore warrant
separate procedures.

Unlike prescriptive documents, records may contain handwritten elements and therefore it is important that the handwriting is legible. If this becomes a problem, you either improve discipline or consider electronic data capture.

Records also become soiled in a workshop environment so may need to be protected to remain legible. With electronically captured data, legibility is often not a problem. However, photographs and other scanned images may not transfer as well as the original and lose detail so care has to be taken in selecting appropriate equipment for this task.

Whatever the records, they should carry some identification in order that you can determine what they are, what kind of information they record and what they relate to. A simple way of doing this is to give each record a reference number and a name or title in a prominent location on the record.

1994 –2000 Differences

Previously the standard covered retrieval in four ways. It required:

(a) that quality records be made available for evaluation by the customer or his representative for an agreed period, where agreed contractually

Records can take various forms – reports containing narrative, computer data, and forms containing data in boxes, graphs, tables, lists and many others. Where forms are used to collect data, they should carry a form number and name as their identification. When completed they should carry a serial number to give each a separate identity. Records should also be traceable to the product or service they represent and this can be achieved either within the reference number or separately, provided that the chance of mistaken identity is eliminated. The standard does not require records to be identifiable to the product involved but unless you do make such
provision you will not be able to access the pertinent records or demonstrate conformance to specified requirements.

Friday, August 21, 2009

Origins of the ISO 9001’s Work

The ISO is a federation of non-governmental organizations established in 1947 to develop international standards, improve international communication and collaboration, and facilitate the exchange of goods and services. The federation is currently comprised of close to 100 national standards bodies (member bodies) from countries representing approximately 95 percent of the world’s industrial production.
The headquarters of the ISO 9001 secretariat is in Geneva, Switzerland.2 The ISO 9000’s involvement in establishing environmental standardsbegan in 1991 after organizers for the UN Conference on Environment and Development (held in Rio de Janeiro in 1992) asked whether or not ISO would be attending the conference and whether it was involved in any environmental activities. As a result, the ISO established a Strategic Advisory Group on the Environment (SAGE) in 1991 to assess the need for international environmental management standards.3 SAGE recommended that ISO proceed with an environmental standard by 1992 and that a technical committee be established to carry it through. On June 1, 1993, ISO’s Technical Committee 207 (TC 207) held its first plenary meeting.
TC 207 was directed to establish environmental standards in five areas of environmental management:- environmental management systems; environmental auditing and related- environmental investigation; environmental labeling; environmental performance evaluation; and life-cycle assessment.
Consequently, TC 207 was divided into five subcommittees (SCs) for each category of standard and one SC to cover the terms and definitions of the standards. In addition, a working group, which reports directly to TC 207, was formed to deal with the environmental aspects in product standards. The five SCs have two or more working groups (WGs) that report to them (unlike the WG on product standards previously mentioned which reports directly to TC 207).
The key factor that has propelled the ISO 14000 series of standards forward throughout the early 1990s is the increase in national environmental standards. Examples of these standards include some two dozen eco-labeling schemes worldwide (see Annex 1), the British Standards Institute’s BS 7750 (Specification for Environmental Management Systems), the Canadian Standards Association’s Z750 (A Guide for a Voluntary Environmental Management System), and the EU EMAS (Eco-Management and Audit Scheme). Other similar environmental management standards have been developed by the French Standards Association, the South African Bureau of Standards and the Spanish Standards Association.
With the proliferation of environmental standards, concerns have been expressed that these standards would fragment international markets and unduly favor the companies of the countries or of the regions where these standards were developed, unless they were developed by authoritative and broadly based international bodies. The ISO was to serve this role.

Tuesday, August 11, 2009

Establishing a ISO 9001 records procedure

Establishing a ISO 9001 records procedure

The ISO 9001 standard requires records to remain legible, readily
identifiable and retrievable and that a procedure defines
the controls needed for the identification, storage,
protec- tion, retrieval, retention time and disposition of records.
Records have a life cycle. They are generated during
which time they acquire an identity and are then
assigned for storage for a prescribed period. During
use and storage they need to be protected from
inadvertent or malicious destruction and as they
may be required to support current activities or
investigations, they need to be brought out of storage
quickly. When their usefulness has lapsed, a decision is made as to whether to
retain them further or to destroy them.
Readily retrievable means that records can be obtained on demand within a
reasonable period (hours not days or weeks) Readily identifiable means that
the identity can be discerned at a glance.
Although the requirement implies a single procedure, several may be
necessary because there are several unconnected tasks to perform. A procedure
cannot in fact ensure a result. It may prescribe a course of action which if
followed may lead to the correct result, but it is the process that ensures the
result not the procedure.
The revised requirement omits several aspects covered in clause 4.16 of the
1994 version.
Collection of records is now addressed by Analysis of data (clause 8.4)
Indexing of records is a specific form of identification and is therefore
already addressed
Access is now addressed by the requirement for record retrieval
Filing is a specific form of storage and is therefore already addressed
You may only need one procedure which covers all the requirements but this
is not always practical. The provisions you make for specific records should be
included in the documentation for controlling the activity being recorded. For
example, provisions for inspection records should be included in the inspection
procedures; provisions for design review records should be included in the
design review procedure. Within such procedures you should provide the
forms (or content requirement for the records), the identification, collection/
submission provisions, the indexing and filing provisions. It may be more
practical to cover the storage, disposal and retention provisions in separate
procedures because they may not be type-dependent. Where each department
retains their own records, these provisions may vary and therefore warrant
separate procedures.
Unlike prescriptive documents, records may contain handwritten elements and
therefore it is important that the handwriting is legible. If this becomes a
problem, you either improve discipline or consider electronic data capture.
Records also become soiled in a workshop environment so may need to be
protected to remain legible. With electronically captured data, legibility is often
not a problem. However, photographs and other scanned images may not
transfer as well as the original and lose detail so care has to be taken in
selecting appropriate equipment for this task.
Whatever the records, they should carry some
identification in order that you can determine what
they are, what kind of information they record and
what they relate to. A simple way of doing this is to
give each record a reference number and a name or
title in a prominent location on the record.

1994 –2000 Differences

Previously the ISO 9001 standard covered retrieval in four ways. It required:
(a) that quality records be

made available for evaluation by the customer or his representative for an
agreed period, where agreed contractually

Records can take various forms – reports containing narrative,
computer data, and forms containing data in boxes, graphs, tables, lists and many others.
Where forms are used to collect data, they should carry a form number and name as their identification. When completed they should carry a serial number to give each a separate identity. Records should also be traceable to the product or service
they represent and this can be achieved either within the reference number or separately, provided that the chance of mistaken identity is eliminated. The standard does not require records to be identifiable to the product involved but unless you do make such
provision you will not be able to access the pertinent records or demonstrate conformance to specified requirements.

Retention of ISO 9001 records

ISO 9001 Record Retention

It is important that ISO 9000 records are not destroyed before their useful life is over.
There are several factors to consider when determining the retention time for
records.

The duration of the contract – some records are only of value whilst the
contract is in force.

The life of the product – access to the records will probably not be needed for
some considerable time, possibly long after the contract has closed. On
defence contracts the contractor has to keep records for up to 20 years and
for product liability purposes, in the worst-case situation (taking account of
appeals) you could be asked to produce records up to 17 years after you
made the produc
The period between management system assessments – assessors may wish to see
evidence that corrective actions from the last assessment were taken. If the
period of assessment is three years and you dispose of the evidence after 2
years, you will have some difficulty in convincing the assessor that you
corrected the deficiency.
While the ISO 9001 requirement applies only to records, you may also need to
retain tools, jigs, fixtures, test software – in fact anything that is needed to repair
or reproduce equipment in order to honour your long-term commitments.
Should the customer specify a retention period greater than what you
prescribe in your procedures, special provisions will need to be made and this
is a potential area of risk. Customers may choose not to specify a particular
time and require you to seek approval before destruction. Any contract that
requires you to do something different creates a problem in conveying the
requirements to those who are to implement them. The simple solution is to
persuade your customer to accept your policy. You may not want to change
your procedures for one contract. If you can’t change the contract, the only
alternative is to issue special instructions. You may be better off storing the
records in a special contract store away from the normal store or alternatively
attach special labels to the files to alert the people looking after the archives.

Disposition of ISO 9001 records

ISO 9001 Records Disposition

Disposition in this context means the disposal of records once their useful life
has ended. The requirement should not be confused with that on the retention
of records. Retention times are one thing and disposal procedures quite
another.
The ISO 9001 standard does not specifically require records to be authenticated, certified
or validated other than product verification records in clause 8.2.4. A set of
results without being endorsed with the signature of the person who captured
them or other authentication lacks credibility. Facts that have been obtained by
whatever means should be certified for three reasons:

They provide a means of tracing the result to the originator in the event of
problems.
They indicate that the provider believes them to be correct.
They enable you to verify whether the originator was appropriately
qualified.

They give the results credibility.

If the records are generated by computer and retained in computerized form,
a means needs to be provided for the results to be authenticated. This can be
accomplished through appropriate process controls by installing provisions for
automated data recording or preventing unauthorized access.

Control of ISO 9000 records

The ISO 9001 standard requires records to be established and
maintained to provide evidence of conformity to require-
ments and the effective operation of the quality manage-
ment system.
A record is defined in ISO 9000 as a document stating
results achieved or providing evidence of activities
performed.

Although a record is a document, the document
control
requirement of clause 4.2.3 do not apply to
records primarily because records are not issued,
neither do they exhibit revision status simply
because they are results that are factual when
recorded. If the facts change, a new record is usually
created rather than the previous record revised. Even
where a record is revised and new facts added, the
old facts remain identified as to their date. The only reason for revising facts
contained in a record without changing the identity of the record or the date
when they were collected is where the facts were incorrectly recorded. This
subtle difference demands different treatment for documents that are classed
as records to those that are classed as informative. As with other types of
documents, records result from processes and may be used as inputs to other
processes.
Records required by the management system means records used or
generated by the management system. There is therefore no requirement to
produce records solely to satisfy an auditor. The records required are those for
the effective operation of the organization’s processes (see clause 4.1d of ISO
9001
). If a record has no useful purpose within the management system there
is no requirement that it be established or maintained.
This does not mean that a record is required to prove conformity with every
single requirement for every product and service. There are those records
required by the standard (see below) that are required for every product and
service where applicable and in all other cases, audit records showing
compliance on a sample of operations would be sufficient.
Compliance with many requirements can be demonstrated by observation,
analysis, interview or examination of documentation. If a result or an activity
is not required to be recorded in order to manage the organization effectively
and satisfy the interested parties, it is not necessary to maintain records of it.

Monday, August 10, 2009

ISO 9000 vs Quality

ISO 9000 was conceived to bring about an improvement in product quality. It
was believed that if organizations were able to demonstrate they were
operating a quality system that met international standards, customers would
gain greater confidence in the quality of products they purchased. It was also
believed that by operating in accordance with documented procedures, errors
would be reduced and consistency of output ensured. If you find the best way
of achieving a result, put in place measures to prevent variation, document it
and train others to apply it, it follows that the results produced should be
consistently good.

The requirements of the standard were perceived to be a list of things to do
to achieve quality. The ISO co-ordinator would often draw up a plan based on
the following logic:
1. We have to identify resource requirements so I will write a procedure on
identifying resource requirements
2. We have to produce quality plans so I will write a procedure on producing
quality plans
3. We have to record contract review so I will write a procedure on recording
contract reviews
4. We have to identify design changes so I will write a procedure on identifying
design changes

The requirements in the standard were often not expressed as results to be
achieved. Requirements for a documented procedure to be established resulted
in just that. Invariably the objectives of the procedure were to define something
rather than to achieve something. This led to documentation without any clear
purpose that related to the achievement of quality. Those producing the
documentation were focusing on meeting the standard not on achieving quality.
Those producing the product were focusing on meeting the customer
requirement but the two were often out of sync. As quality assurance became
synonymous with procedures, so people perceived that they could achieve
quality by following procedures. The dominance of procedures to the exclusion
of performance is a misunderstanding of the implementers. The standard
required a documented system that ensured product met specified requirements – a
clear purpose. Once again the implementers lost sight of the objective. Or was it
that they knew the objective but in order to meet it, the culture would have to
change and if they could get the badge without doing so, why should they?

Issuing a procedure was considered to equate to task completed. Unfortu-
nately, for those on the receiving end, the procedures were filed and forgotten.
When the auditor came around, the individual was found to be totally
unaware of the ‘procedure’ and consequently found noncompliant with it.
However, the auditor would discover that the individual was doing the right
things so the corrective action was inevitably to change the procedure. The
process of issuing procedures was not questioned, the individual concerned
was blamed for not knowing the procedure and the whole episode failed to
make any positive contribution to the achievement of quality. But it left the
impression on the individual that quality was all about following procedures.
It also left the impression that quality was about consistency and providing
you did what you said you would do regardless of it being in the interests of
satisfying customers, it was OK. One is left wondering whether anyone
consulted the dictionary in which quality is defined as a degree of excellence?

Another problem was that those who were to implement requirements were
often excluded from the process. Instead of enquiring as to the best way of
meeting a requirement, those in charge of ISO 9000 implementation assumed
that issuing procedures would in fact cause compliance with requirements. It
requires a study of the way work gets done to appreciate how best to meet a
requirement. Procedures were required to be documented and the range and
detail was intended to be appropriate to the complexity of the work, the
methods used and the skills and training needed. The standard also only
required work instructions where their absence would adversely affect quality.
It is as though the people concerned did not read the requirement properly or
had no curiosity to find out for themselves what ISO had to say about
procedures – they were all too ready to be told what to do without questioning
why they should be doing it.

More often than not, the topics covered by the standard were only a sample
of all the things that need to be done to achieve the organization’s objectives.
The way the standard classified the topics was also often not appropriate to the
way work was performed. As a consequence, procedures failed to be
implemented because they mirrored the standard and not the work. ISO 9000
may have required documented procedures but it did not insist that they be
produced in separate documents, with titles or an identification convention
that was traceable to the requirements.

Critics argue (Seddon, John, 2000)3 that ISO 9000 did not enable organiza-
tions to reduce variation as a result of following the procedures. It is true that
ISO 9000 did not explain the theory of variation – it could have done, but
perhaps it was felt that this was better handled by the wealth of literature
available at the time. However, ISO 9000 did require organizations to identify
where the use of statistical techniques was necessary for establishing,
controlling and verifying process capability but this was often misunderstood.
Clause 4.14 of ISO 9001 required corrective action procedures – procedures to
identify variation and eliminate the cause so this should have resulted in a
reduction in variation. The procedures did not always focus on results – they
tended to focus on transactions – sending information or product from A to B.
The concept of corrective action was often misunderstood. It was believed to be
about fixing the problem and preventive action was believed to be about
preventing recurrence. Had users read ISO 8402 they should have been
enlightened. Had they read Deming they would have been enlightened but in
many cases the language of ISO 9000 was a deterrent to learning. Had the
auditors understood variation, they too could have assisted in clarifying these
issues but they too seemed ignorant – willing to regard clause 4.20 as not
applicable in many cases.

Clause 4.6 of the undervalued and forgotten standard ISO 9000 –1 starts with
‘The International Standards in the ISO 9000 family are founded upon the
understanding that all work is accomplished by a process.’ In clause 4.7 it starts
with ‘Every organization exists to accomplish value-adding work. The work is
accomplished through a network of processes’ In clause 4.8 it starts with ‘It is
conventional to speak of quality systems as consisting of a number of elements.
The quality system is carried out by means of processes which exist both within
and across functions’ Alas, few people read ISO 9000–1 and as a result the
baggage that had amassed was difficult to shed especially because there were
few if any certification bodies suggesting that the guidance contained in ISO
9000 –1 should be applied. Unfortunately, this message from ISO 9000 –1 was not
conveyed through the requirements of ISO 9001. ISO 9001 was not intended as
a design tool. It was produced for contractual and assessment purposes but was
used as a design tool instead of ISO 9000 –1 and ISO 9004 –1.

Quality Management

There are two schools of thought on quality management. One views quality
management as the management of success and the other the elimination of
failure. They are both valid. Each approaches the subject from a different
angle:

The ‘success’ school is characterized by five questions (Hoyle, David and
Thompson, John, 2001)3 :
1 What are you trying to do?
2 How do you make it happen?
3 How do you know it’s right?
4 How do you know it’s the best way of doing it?
5 How do you know it’s the right thing to do?

The ‘failure elimination’ school is characterized by five different questions
1 How do you know what is needed?
2 What could affect your ability to do it right?
3 What checks are made to verify achievement?
4 How do you ensure the integrity of these checks?
5 What action is taken to prevent a recurrence of failure?

In an ideal world, if we could design products, services and processes that
could not fail we would have achieved the ultimate goal. Success means not
only that products, services and processes fulfil their function but also that the
function is what customers’ desire. Failure means not only that products,
services and processes would fail to fulfil their function but also that their
function was not what customers desired. A gold-plated mousetrap that does
not fail is not a success if no one needs a gold-plated mousetrap!
The introductory clause of ISO 9001:1994 contained a statement that the aim
of the requirements is to achieve customer satisfaction by prevention of
nonconformities. (This was indicative of the failure school of thought.) The
introductory clause of ISO 9001:2000 contains a statement that the aim is to
enhance customer satisfaction through the effective application of the quality
management system
and the assurance of conformity to customer and
applicable regulatory requirements. (This is indicative of the success school of
thought.)

In reality you cannot be successful unless you know of the risks you are
taking and plan to eliminate, reduce or control them. A unification of these
approaches is what is therefore needed for organizations to achieve, sustain
and improve quality. You therefore need to approach the achievement of
quality from two different angles and answer two questions. What do we need
to do to succeed and what do we need to do to prevent failure?

Quality does not appear by chance, or if it does it may not be repeated. One
has to design quality into the products and services. It has often been said that
one cannot inspect quality into a product. A product remains the same after
inspection as it did before, so no amount of inspection will change the quality
of the product. However, what inspection does is measure quality in a way that
allows us to make decisions on whether or not to release a piece of work. Work
that passes inspection should be quality work but inspection unfortunately is
not 100% reliable. Most inspection relies on human judgement and this can be
affected by many factors, some of which are outside our control (such as the
private life, health or mood of the inspector). We may also fail to predict the
effect that our decisions have on others. Sometimes we go to great lengths in
preparing organization changes and find to our surprise that we neglected
something or underestimated the effect of something. We therefore need other
means to deliver quality products – we have to adopt practices that enable us
to achieve our objectives while preventing failures from occurring.

ISO 9001:2008 Documentation Requirements

ISO 9001:2008 clause 4.1 General requirements requires an organization to “establish, document, implement, and maintain a quality management system and continually improve its effectiveness in accordance with the requirements of this International Standard”
ISO 9001:2008 Clause 4.2.1 General explains that the quality management system documentation shall include:
documented statements of a quality policy and quality objectives;
a quality manual
documented procedures required by this International Standard
documents needed by the organization to ensure the effective planning, operation and control of its processes, and
records required by this International Standard;
The notes after Clause 4.2 make it clear that where the standard specifically requires a “documented procedure”, the procedure has to be established, documented, implemented and maintained. It also emphasizes that the extent of the QMS documentation may differ from one organization to another due to:
the size of organization and type of activities;
the complexity of processes and their interactions, and
the competence of personnel.
All the documents that form part of the QMS have to be controlled in accordance with clause 4.2.3 of ISO 9001:2008, or, for the particular case of records, according to clause 4.2.4.
Guidance on Clause 4.2 of ISO 9001:2008
The following comments are intended to assist users of ISO 9001:2008 in understanding the intent of the general documentation requirements of the International Standard.
a) Documented statements of a quality policy and objectives:
Requirements for the quality policy are defined in clause 5.3 of ISO 9001:2008. The documented quality policy has to be controlled according to the requirements of clause 4.2.3.Note: Organizations that are revising their quality policy for the first time, or in order to meet the amended requirements in ISO 9001:2008, should pay particular attention to clause 4.2.3 (c), (d) and (g).
Requirements for quality objectives are defined in clause 5.4.1 of ISO 9001:2008. These documented quality objectives are also subject to the document control requirements of clause 4.2.3.
b) Quality Manual:
Clause 4.2.2 of ISO 9001:2008 specifies the minimum content for a quality manual. The format and structure of the manual is a decision for each organization, and will depend on the organization’s size, culture and complexity. Some organizations may choose to use the quality manual for other purposes besides that of simply documenting the QMS
A small organization may find it appropriate to include the description of its entire QMS within a single manual, including all the documented procedures required by the standard.
Large, multi-national organizations may need several manuals at the global, national or regional level, and a more complex hierarchy of documentation.
The quality manual is a document that has to be controlled in accordance with the requirements of clause 4.2.3.
c) Documented procedures:
ISO 9001:2008 specifically requires the organization to have “documented procedures” for the following six activities:4.2.3 Control of documents4.2.4 Control of records8.2.2 Internal audit8.3 Control of nonconforming product8.5.2 Corrective action8.5.3 Preventive action
These documented procedures have to be controlled in accordance with the requirements of clause 4.2.3
Some organizations may find it convenient to combine the procedure for several activities into a single documented procedure (for example, corrective action and preventive action). Others may choose to document a given activity by using more than one documented procedure (for example, internal audits). Both are acceptable.
Some organizations (particularly larger organizations, or those with more complex processes) may require additional documented procedures (particularly those relating to product realization processes) to implement an effective QMS.
Other organizations may require additional procedures, but the size and/or culture of the organization could enable these to be effectively implemented without necessarily being documented. However, in order to demonstrate compliance with ISO 9001:2008, the organization has to be able to provide objective evidence (not necessarily documented) that its QMS has been effectively implemented.
d) Documents needed by the organization to ensure the effective planning, operation and control of its processes:
In order for an organization to demonstrate the effective implementation of its QMS, it may be necessary to develop documents other than documented procedures. However, the only documents specifically mentioned in ISO 9001:2008 are:- Quality policy (clause 4.2.1.a)- Quality objectives (clause 4.2.1.a)- Quality manual (clause 4.2.1.b)
There are several requirements of ISO 9001:2008 where an organization could add value to its QMS and demonstrate conformity by the preparation of other documents, even though the standard does not specifically require them. Examples may include:- Process maps, process flow charts and/or process descriptions- Organization charts- Specifications- Work and/or test instructions- Documents containing internal communications- Production schedules- Approved supplier lists- Test and inspection plans- Quality plans
All such documents have to be controlled in accordance with the requirements of clause 4.2.3 and/or 4.2.4, as applicable
e) Records:
Examples of records specifically required by ISO 9001:2008 are presented in Annex B.
Organizations are free to develop other records that may be needed to demonstrate conformity of their processes, products and quality management system.
Requirements for the control of records are different from those for other documents, and all records have to be controlled according to those of clause 4.2.4 of ISO 9001:2008.

Why is Six Sigma Fascinating in ISO 9000?

Six Sigma has become very popular throughout the whole world. There are several reasons for this popularity. First, it is regarded as a fresh quality management strategy which can replace TQC, TQM and others.
Many companies, which were not quite successful in implementing previous management strategies such as TQC and TQM, are eager to introduce Six Sigma.
Development process of Six Sigma in quality management
Six Sigma is viewed as a systematic, scientific, statistical and smarter (4S) approach for management innovation which is quite suitable for use in a knowledge-based information society.
Second, Six Sigma provides efficient manpower cultivation and utilization. It employs a “belt system” in which the levels of mastery are classified as green belt, black belt, master black belt and champion. As a person in a company obtains certain
training, he acquires a belt. Usually, a black belt is the leader of a project team and several green belts work together for the project team.
Third, there are many success stories of Six Sigma application in well known world-class companies. As mentioned earlier, Six Sigma was pioneered by Motorola and launched as a strategic initiative in 1987. Since then, and particularly from 1995, an exponentially growing number of prestigious global firms have launched a Six Sigma program. It has been noted that many globally leading companies run Six Sigma programs (see Figure 3), and it has been well known that Motorola, GE, Allied Signal, IBM, DEC, Texas Instruments, Sony, Kodak, Nokia, and Philips Electronics among others have been quite successful in Six Sigma. In Korea, the Samsung, LG, Hyundai groups and Korea Heavy Industries & Construction Company have been quite successful with Six Sigma.
Lastly, Six Sigma provides flexibility in the new millennium of 3Cs, which are:
• Change: Changing society
• Customer: Power is shifted to customer and customer demand is high
• Competition: Competition in quality and productivity
The pace of change during the last decade has been unprecedented, and the speed of change in this new millennium is perhaps faster than ever before. Most notably, the power has shifted from producer to customer. The producer-oriented industrial society is over, and the customer-oriented information society has arrived. The customer has all the rights to order, select and buy goods and services. Especially, in e-business, the customer has all-mighty power.
Six Sigma with its 4S(systematic, scientific, statistical and smarter) approaches provides flexibility in managing a business unit.

Quality Characteristic in ISO 9000

Any feature or characteristic of a product or service that is needed to satisfy
customer needs or achieve fitness for use is a quality characteristic. When
dealing with products the characteristics are almost always technical character-
istics, whereas service quality characteristics have a human dimension. Some
typical quality characteristics are given below.

Product characteristics
1. Accessibility Functionality Size
2. Availability Interchangeability Susceptibility
3. Appearance Maintainability Storability
4. Adaptability Odour – Strength
5. Cleanliness Operability -Taste
6. Consumption Portability – Testability
7. Durability Producibility Traceability
8. Disposability Reliability – Toxicity
9. Emittance Reparability Transportability
10. Flammability Safety – Vulnerability
11. Flexibility Security – Weight

Service quality characteristics
1. Accessibility Credibility – Honesty
2. Accuracy Dependability Promptness
3. Courtesy Efficiency – Responsiveness
4. Comfort Effectiveness Reliability
5. Competence Flexibility – Security

These are the characteristics that need to be specified and their achievement
controlled, assured, improved, managed and demonstrated. These are the
characteristics that form the subject matter of the product requirements
referred to in ISO 9000. When the value of these characteristics is quantified or
qualified they are termed product requirements. We used to use the term quality
requirements but this caused a division in thinking that resulted in people
regarding quality requirements as the domain of the quality personnel and
technical requirements being the domain of the technical personnel. All
requirements are quality requirements – they express needs or expectations that
are intended to be fulfilled by a process output that possesses inherent
characteristics. We can therefore drop the word quality. If a modifying word is
needed in front of the word requirements it should be a word that signifies the
subject of the requirements. Transportation system requirements would be
requirements for a transportation system, Audio speaker design requirements
would be requirements for the design of an audio speaker, component test
requirements would be requirements for testing components, and management
training requirements would be requirements for training managers. ISO 9000
requirements
are often referred to as quality requirements as distinct from other
types of requirements but this is misleading. ISO 9000 is no more a quality
requirement than is ISO 1000 on SI units, ISO 2365 for Ammonium nitrate or
ISO 246 for Rolling Bearings. The requirements of ISO 9000 are quality
management system requirements – requirements for a quality management
system.

Quality Management

There are two schools of thought on quality management. One views quality
management as the management of success and the other the elimination of
failure. They are both valid. Each approaches the subject from a different
angle:

The ‘success’ school is characterized by five questions (Hoyle, David and
Thompson, John, 2001)3 :
1 What are you trying to do?
2 How do you make it happen?
3 How do you know it’s right?
4 How do you know it’s the best way of doing it?
5 How do you know it’s the right thing to do?

The ‘failure elimination’ school is characterized by five different questions
1 How do you know what is needed?
2 What could affect your ability to do it right?
3 What checks are made to verify achievement?
4 How do you ensure the integrity of these checks?
5 What action is taken to prevent a recurrence of failure?

In an ideal world, if we could design products, services and processes that
could not fail we would have achieved the ultimate goal. Success means not
only that products, services and processes fulfil their function but also that the
function is what customers’ desire. Failure means not only that products,
services and processes would fail to fulfil their function but also that their
function was not what customers desired. A gold-plated mousetrap that does
not fail is not a success if no one needs a gold-plated mousetrap!
The introductory clause of ISO 9001:1994 contained a statement that the aim
of the requirements is to achieve customer satisfaction by prevention of
nonconformities. (This was indicative of the failure school of thought.) The
introductory clause of ISO 9001:2000 contains a statement that the aim is to
enhance customer satisfaction through the effective application of the quality
management system and the assurance of conformity to customer and
applicable regulatory requirements. (This is indicative of the success school of
thought.)

In reality you cannot be successful unless you know of the risks you are
taking and plan to eliminate, reduce or control them. A unification of these
approaches is what is therefore needed for organizations to achieve, sustain
and improve quality. You therefore need to approach the achievement of
quality from two different angles and answer two questions. What do we need
to do to succeed and what do we need to do to prevent failure?

Quality does not appear by chance, or if it does it may not be repeated. One
has to design quality into the products and services. It has often been said that
one cannot inspect quality into a product. A product remains the same after
inspection as it did before, so no amount of inspection will change the quality
of the product. However, what inspection does is measure quality in a way that
allows us to make decisions on whether or not to release a piece of work. Work
that passes inspection should be quality work but inspection unfortunately is
not 100% reliable. Most inspection relies on human judgement and this can be
affected by many factors, some of which are outside our control (such as the
private life, health or mood of the inspector). We may also fail to predict the
effect that our decisions have on others. Sometimes we go to great lengths in
preparing organization changes and find to our surprise that we neglected
something or underestimated the effect of something. We therefore need other
means to deliver quality products – we have to adopt practices that enable us
to achieve our objectives while preventing failures from occurring.
http://www.e-wia.com
http://www.iso-consults.com