Saturday, June 12, 2010

ISO 9000 Standards Training Video

ISO 9000 Standards Training DVD

ISO 9000 Process Based Auditing


ISO 9000 Process Based Auditing

Any effective quality management system (including the subsystems) works as a control process, which has the ability to detect deviations and nonconforming products and assures that the corrective and preventive action measures are effective. The regulatory auditor should check that all subsystems and processes of the quality management system are structured as self-regulating control processes. For example Deming’s PDCA cycle demonstrates such a process with the following components:

i) Plan – Has the manufacturer established the objectives and processes to enable the quality system to deliver the results in accordance with the regulatory requirements?

ii) Do – Has the manufacturer implemented the quality system and the processes?

iii) Check – Has the manufacturer checked process monitoring and measurement results against the objectives and the regulatory requirements? Does the manufacturer evaluate the effectiveness of the quality system periodically through internal audits and management reviews?

iv) Act – Has the manufacturer implemented effective corrective and preventive actions? Confirm that the company is committed to providing high quality safe and effective medical devices, and that the company is conforming with applicable laws and regulations.


Different Between Quality Assurance & Quality Control

QA: Quality Assurance is the process which are having their eyes on the process to provide the assurity of the quality. like doing the testing at the time of development, giving the review comments and forced the developers to fixed the defects of the requirement, designed, coding and testing phase is the Quality Assurance.

Quality Control: Before delivering the product to make sure that all the documentation are provided, product has meet with the requirement criteria, all the SDLC phase are met with the exit criteria is the Quality control.

Difference between Quality Control and Quality Assurance?

Quality ControlQuality Assurance
DefinitionQC is about checking at the end of some development process (e.g. – a design activity) that we have built quality in i.e. that we have achieved the required quality with our methods.QA is about having an overall development and management process that provides right environment for ensuring quality of final product.
DescriptionQC is like testing a module against requirement specification or design document, measuring response time, throughput etc.QA gives us added assurance that the whole producing or checking process is properly planned and executed and thus maintaining high quality.
What it doesTo check that the modern methods of software development are largely designed to ensure right quality is achieved. QC checks that these methods are in place and to discover where they are not then corrections are to be made.It gives us added assurance that the while producing / checking process is being properly planned and executed and hence is keeping high our chances of producing software of required quality.
StagesDefine features and levels Define feature check procedure Carrying out the check procedure Record the result take and record any corrective action taken.1. Determination of quality policy through Quality Management System 2. Checking that predetermined Quality control activities are being properly taken care off.
Best carried out onQC is best carried out on productsQA is best carried out on process.
Phase of implementationQC should take place at every stage of SDLC.QA should be done at end of every SDLC i.e. when product building is complete.
TechniqueStructured walkthrough, Fagan Techniques are some of QC techniques.Quality policy defined and generally implemented in the form of Quality Management System is used to carry out QA.

As per ISO 9000 Standards:

Quality Control means – The Operational Techique and activities that are used to fullfill requirements of Quality,

Quality Assurance means – All Those planned and systematic activites implemented already , to provide adequate confidence that an entity will fulfillrequirements of Quality.

The following table can explain in detail:

QC QA

Product Process

Reactive Pro-active

Line Function Staff Function

Find the defects Prevent the defects

e.g.

QC QA

Walkthrough Quality Audit

Testing Defining Process

Inspection Selection of tools

Checkpoint Review Trainings


Quality Assurance In ISO 9001 Standards

Quality assurance, according to the ISO 9001 Standard, is a way of managing that prevents non-conformance and thus “assures quality”. This is what makes ISO 9001 Standardsdifferent from other standards: it is a management standard, not a product standard. It goes beyond product standardisation: it is standardising not what is made but how it is made.

To use the ISO 9001 standards to dictate and control how organisations work was to extend the role of standards to new territory. To take such a step we might have firstly established that any such requirements worked — that they resulted in ways of working which improved performance. Yet the plausibility of this Standard, and the fact that those who had an interest in maintaining it were (and still are) leading opinion, prevented such enquiries. In simple terms the Standard asks managers to say what they do, do what they say and prove it to a third party. ISO 9000 (2008) paragraph 1: “The requirements specified are aimed primarily at achieving customer satisfaction by preventing non-conformity at all stages from design through servicing.” To put it another way, the Standard asserts that preventing non-conformance achieves customer satisfaction. But does it? Of course it matters to customers that a product works. But there is no guarantee that the Standard will ensure even that.

Furthermore, customers take a total view of an organisation — how easy it is to do business with — in respect of all things of importance to each and every customer. ISO 9000 requires managers to “establish and maintain a documented quality system as a means of ensuring that product conforms to specified requirements”. Loosely translated this is “say what you do”. Management is supposed to “define and document its policy for quality . . . including its commitment to quality”. What management would not declare its commitment to quality? But would they know what it means? Would they argue (as they should) that quality management is a different and better way to do business, or would they believe that ISO 9001 Standardswill take care of quality?

The ISO 9000 Standards encourages managers to think of “quality” and “business as usual” as separate and distinct. It helps managers avoid the revelation that quality means a wholly different view of management. Instead, the organisation “shall appoint a management representative who, irrespective of other responsibilities, shall have defined authority and responsibility” [for ISO 9000]. At a practical level this means only one executive might decide he or she had better learn a thing or two about quality.

However, would being responsible for ISO 9001 standards lead to learning about quality or simply enforcing the ISO 9000 regime in an organisation? Key to the regime is auditing. The Standard requires organisations to conduct internal quality audits to “verify whether quality activities comply with planned arrangements”. This can be loosely translated as “do you do as you say?” and the purpose of the audit is to see that you do. It was not until the 1994 review that the words were changed to “quality activities and related results”. It was a Standard which was rooted in the philosophy of inspection: fifteen years after its initial promulgation the promoters sought to extend the focus to results. But results or improvements assessed by what means? Inspection. By the time the Standard was adopted world-wide, quality thinking had moved a long way from the philosophy of inspection. It is now understood, at least by a few, that quality is achieved through managing the organisation as a system and using measures which enable managers to improve flow and reduce variation (which we explore in chapters 5 and 7).

The defenders argue that there is nothing stopping a company having ISO 9000 and implementing methods for managing flow and reducing variation, but where are such companies? Few of the companies we researched, formally and informally, knew anything about this thinking. The Standard does not talk about it; moreover, the Standard effectively discourages managers from learning about it by representing quality in a different way. According to ISO 8402 (quality vocabulary), quality is: “The totality of features and characteristics of a product or service that bear on its ability to satisfy stated or implied needs.” Everything we have learned about ISO 9000 suggests that the people who created this definition were thinking about the things which need to be controlled, those things which “bear on its ability . . .”. The builders of the Standard assumed that customer needs would be listed in contractual agreements between the supplier and customer. ISO 9000 has a “make” logic — procedures for “how you do what you do” — and a “control” logic — check to see that it is done. It is a relic of the era when contractual agreements were perceived to be an important device for regulating the behaviour of suppliers.

In these ways, ISO 9000 standards encouraged “planning for quality”. Planning for quality sounds plausible, but it assumes many things: that the plan is the right plan, that it is feasible, that people will “do it”, that performance will improve. It is an approach which, paradoxically, leads to poor decisions. Planners of quality systems, guided by ISO 9000 standards , start with a view of how the world should be as framed by the Standard. Understanding how an organisation is working, rather than how someone thinks it should, is a far better place from which to start change of any kind.


Best Ways Of Implementing ISO 9001 Standards

Best Ways Of Implementing ISO 9001 Standards

While each implementation is dependent on the company, the industry, customers, etc., here’s a good starting point:

1.) Identify what your customer expects of your company. Consider both sales and after-sales aspects, from the customer’s point of view.

2.) Develop a philosophy (Quality Policy) that addresses (1). This means clause 5.3.

3.) Identify your processes, keeping in mind the importance of each as compared to (1) above. This means clause 4.1.

4.) Identify your management structure, being sure it supports and does not conflict with (1), (2) or (3). This means the rest of Clause 5 in the standard.

5.) Figure out resource issues. This means all of Clause 6.

7.) From there, work on clauses 7 & 8. This part is particularly hard to define as a generic plan, because how it is done is unique to each company, and the results of (1) through (6) above.

Tips:

(a) Keep documentation to the absolute minimum.

(b) Put “required procedures” and process maps in your Quality Manual, instead of subordinate documents. This makes the QM useful, instead of just a throwaway restatement of the standard. Limits documentation overall.

(c) Spend a lot of time on process identification and definition, so that you understand them and can manage them

(d) Develop an internal audit program (process!) that reflects your company needs, not a checklist method used by registrars

10 steps on the implementation of ISO 9001 Standards are as below:

1. Analyze your businesses’ core process(es) for converting customer needs into cash at a high level to show the sequence and interaction of the key processes within the core process (one page).

2. Identify (and assign a code) each of the key processes within your system (as-is) and the new ones necessary for the system to be used to add value faster and prevent loss sooner (the chosen system standard is very helpful for listing the missing processes). Expect 20 to 50 key processes.

3. Analyze each of the key processes by working with the process owner to determine each processes’ objective, team, inputs, value-adding steps (tasks, meetings, decisions), outputs; then link the procedure to the other controls and process with which it interacts (one page each).

4. Leaders explain their policy, the obligations of the system (already 85% or so implemented) and its benefits.

5. Train process teams in any new processes so they are working effectively from day one.

6. Describe the system and how it works, the policy and objectives in a less than 10 page manual.

7. Launch the system and invite lots of suggested improvements.

8. Gather and analyze data to become information for use by decision makers to improve products, processes and the system.

9. Audit the performance of the system independently of any other process control to provide impartial information on how well the system is helping employees to do their jobs.

10. Use and improve the system, its processes and your products so your organization adds value faster and prevent loss sooner.

ISO 9001 Standards & ISO 14001 Standards

In order to assist organizations to have a full understanding of the new ISO 9001:2008, it may be useful to have an insight on the revision process, how this revision reflects the inputs received from users of the standard, and the consideration given to benefits and impacts during its development.

Prior to the commencement of a revision (or amendment) to a management system standard, ISO/Guide 72:2001 Guidelines for the justification and development of management system standards recommends that a “Justification Study” is prepared to present a case for the proposed project and that it outlines details of the data and inputs used to support its arguments. In relation to the development of ISO 9001:2008 user needs were identified from the following:

-the results of a formal “Systematic Review” on ISO 9001:2000 that was performed by the members of ISO/TC 176/SC2 during 2003-2004
-feedback from the ISO/TC 176/Working Group on “Interpretations”
-the results of an extensive worldwide “User Feedback Survey on ISO 9001 and
The Justification Study identified the need for an amendment, provided that the impact on users would be limited and that changes would only be introduced when there were clear benefits to users.

The key focuses of the ISO 9001:2008 amendment were to enhance the clarity of ISO 9001:2000 and to enhance its compatibility with ISO 14001:2004.

A tool for assessing the impacts versus benefits for proposed changes was created to assist the drafters of the amendment in deciding which changes should be included, and to assist in the verification of drafts against the identified user needs. The following decision making principles were applied:

1) No changes with high impact would be incorporated into the standard;

2) Changes with medium impact would only be incorporated when they provided a correspondingly medium or high benefit to users of the standard;

3) Even where a change was low impact, it had to be justified by the benefits it delivered to users, before being incorporated.

The changes incorporated in this ISO 9001:2008 edition were classified in terms of impact into the following categories:

-No changes or minimum changes on user documents, including records

-No changes or minimum changes to existing processes of the organization

-No additional training required or minimal training required

-No effects on current certifications

The benefits identified for the ISO 9001:2008 edition fall into the following categories:

-Provides clarity

-Increases compatibility with ISO 14001.

-Maintains consistency with ISO 9000 family of standards.

-Improves translatability.


ISO 9000 Document Control System

The ISO 9000 Document Control Software is developed & designed to control the ISO 9000 Quality Manual, Operating Procedure, Forms & Documents digitally. System will track the all ISO 9000 Documents by ISO Document No. through out the system.

The ISO 9000 Document Control Software Provides:-

• Tracking of Documents
• Efficiency Document Control
• Revision Control
• Multiple File Location
• Centralize Of Document Control
• Security