Friday, December 25, 2009

Document Review In ISO 9000 Standards


Document Review In ISO 9000 Standards
The ISO 9000 Standard requires that documents be reviewed.
Previously the implication was that the review was a
check by potential users that the document was fit
for purpose before it was offered for approval. It
could be construed that for a document to receive
approval it must be checked and therefore ‘review
and approval’ in this context are one and the same
and the requirement is in this instance enhanced
rather than relaxed.
A review is another look at something. Therefore
document review is a task that is carried out at any
time following the issue of a document.
This requirement responds to the Continual Improvement principle.
Reviews may be necessary when:
- Taking remedial action (i.e. Correcting an error)
- Taking corrective action (i.e. Preventing an error recurring)
- Taking preventive action (i.e. Preventing the occurrence of an error)
- Taking maintenance action (i.e. Keeping information current)
- Validating a document for use (i.e. When selecting documents for use in
connection with a project, product, contract or other application)
- Taking improvement action (i.e. Making beneficial change to the
information)
Reviews may be random or periodic. Random reviews are reactive and arise
from an error or a change that is either planned or unplanned. Periodic reviews
are proactive and could be scheduled once each year to review the policies,
processes, products, procedures, specification etc. for continued suitability. In
this way obsolete documents are culled from the system. However, if the
system is being properly maintained there should be no outdated information
available in the user domain. Whenever a new process or a modified process
in installed the redundant elements including documentation and equipment
should be disposed of.
The ISO 9000 Standard requires that documents be reviewed.
Previously the implication was that the review was a
check by potential users that the document was fit
for purpose before it was offered for approval. It
could be construed that for a document to receive
approval it must be checked and therefore ‘review
and approval’ in this context are one and the same
and the requirement is in this instance enhanced
rather than relaxed.
A review is another look at something. Therefore
document review is a task that is carried out at any
time following the issue of a document.
This requirement responds to the Continual Improvement principle.
Reviews may be necessary when:
- Taking remedial action (i.e. Correcting an error)
- Taking corrective action (i.e. Preventing an error recurring)
- Taking preventive action (i.e. Preventing the occurrence of an error)
- Taking maintenance action (i.e. Keeping information current)
- Validating a document for use (i.e. When selecting documents for use in
connection with a project, product, contract or other application)
- Taking improvement action (i.e. Making beneficial change to the
information)
Reviews may be random or periodic. Random reviews are reactive and arise
from an error or a change that is either planned or unplanned. Periodic reviews
are proactive and could be scheduled once each year to review the policies,
processes, products, procedures, specification etc. for continued suitability. In
this way obsolete documents are culled from the system. However, if the
system is being properly maintained there should be no outdated information
available in the user domain. Whenever a new process or a modified process
in installed the redundant elements including documentation and equipment
should be disposed of.

BACKGROUND TO THE ISO 9001:2008 REVISION PROCESS

BACKGROUND TO THE ISO 9001:2008 REVISION PROCESS
In order to assist organizations to have a full understanding of the new ISO 9001:2008, it may be useful to have an insight on the revision process, how this revision reflects the inputs received from users of the standard, and the consideration given to benefits and impacts during its development.
Prior to the commencement of a revision (or amendment) to a management system standard, ISO/Guide 72:2001 Guidelines for the justification and development of management system standards recommends that a “Justification Study” is prepared to present a case for the proposed project and that it outlines details of the data and inputs used to support its arguments. In relation to the development of ISO 9001:2008 user needs were identified from the following:
-the results of a formal “Systematic Review” on ISO 9001:2000 that was performed by the members of ISO/TC 176/SC2 during 2003-2004
-feedback from the ISO/TC 176/Working Group on “Interpretations”
-the results of an extensive worldwide “User Feedback Survey on ISO 9001 and
The Justification Study identified the need for an amendment, provided that the impact on users would be limited and that changes would only be introduced when there were clear benefits to users.
The key focuses of the ISO 9001:2008 amendment were to enhance the clarity of ISO 9001:2000 and to enhance its compatibility with ISO 14001:2004.
A tool for assessing the impacts versus benefits for proposed changes was created to assist the drafters of the amendment in deciding which changes should be included, and to assist in the verification of drafts against the identified user needs. The following decision making principles were applied:
1) No changes with high impact would be incorporated into the standard;
2) Changes with medium impact would only be incorporated when they provided a correspondingly medium or high benefit to users of the standard;
3) Even where a change was low impact, it had to be justified by the benefits it delivered to users, before being incorporated.
The changes incorporated in this ISO 9001:2008 edition were classified in terms of impact into the following categories:
-No changes or minimum changes on user documents, including records
-No changes or minimum changes to existing processes of the organization
-No additional training required or minimal training required
-No effects on current certifications
The benefits identified for the ISO 9001:2008 edition fall into the following categories:
-Provides clarity
-Increases compatibility with ISO 14001.
-Maintains consistency with ISO 9000 family of standards.
-Improves translatability.

Tuesday, December 22, 2009

Establishing Quality Objectives In ISO 9000 Standards

Establishing Quality Objectives In ISO 9000 Standards
The ISO 9000 Standard requires that top management ensure that quality objectives are established.
ISO 9001 defines quality objectives as results sought or aimed for related to quality. It also suggests that these
objectives be based on the quality policy and be specified at different levels in the organization, being
quantified at the operational level. As with quality policy the details will be addressed later and here we
will focus on what it means to establish qualityobjectives and how they relate to other objectives.
As the quality policy equates to the corporate policy, it follows that quality objectives equate to corporate objectives. All of the organization’s objectives should in some way serve to fulfil requirements of customers and other interested parties. It is also interesting to note that inISO 9001, the term requirement is defined as a need or expectation that is stated, customarily implied or obligatory. While an investor may not specify a requirement for growth in share value, it would certainly be an expectation. While an employee does not express requirements for salary increases when profits rise, it would certainly be an expectation and while society has no way other than to protest or invoke the law to impose its desires upon an organization, it certainly has the power to make organization’s comply and even change the law in extreme cases. So quality objectives do equate to corporate objectives.
Management needs to ensure that the objectives are established as a basis for action. All work serves an objective and it is the objective that stimulates action.
The reason for top management setting the objectives is to ensure that everyone channels their energies in a positive direction that serves the organizations purpose and mission.
For an objective to be established it has to be communicated, translated into action and become the focus of all achievement. Objectives are not wish lists. The starting point is the purpose and mission statement and the factors
identified as affecting the ability of the organization to accomplish its mission. It is in these areas the organization needs to excel and therefore they become the focus for action and consequently the setting of objectives. Although ISO 9001 suggests that the quality objectives should be based on the quality policy, it is more likely to be current performance, competition and opportunities arising from new technology that drive the objectives.
An objective is a result that is aimed for and is expressed as a result that is to be achieved. Objec-
tives are therefore not policies. The requirement should also not be interpreted as applicable only to
organizational functions and levels. Objectives are required at levels within the organization not levels
within the organization structure. This is clarified by the requirement for objectives to include those
needed to meet requirements for product. There are therefore five levels at which control and improve-
ment objectives need to be established:
Corporate level where the objectives are for the whole enterprise to enable it to fulfil its vision
Process level where the objectives are for specific processes to enable them to fulfil corporate goals
Product or service level where the objectives are for specific products/services or ranges of products/services to enable them to fulfil or create customer needs and expectations
Departmental or function level where the objectives are for an organizational component to enable it to fulfil corporate goals Personal level where the objectives are for the development of individual competency
A management system is not a static system but a dynamic one and if properly designed and implemented can drive the organization forward towards world class quality. All managerial activity is concerned either with maintaining performance or with making change. Change can retard or advance performance. That which advances performance is beneficial. In this regard, there are two classes of quality objectives, those serving the control of quality
(maintaining performance) and those serving the improvement of quality (making beneficial change).
maintain or to prevent from deteriorating. To maintain your performance and your position in the market you will have to continually seek improvement.
Remaining static at whatever level is not an option if your organization is to survive. Although you will be striving for improvement it is important to avoid slipping backwards with every step forwards. The effort needed to prevent
regression may indeed require innovative solutions. While to the people working on such problems, it may appear that the purpose is to change the status quo, the result of their effort will be to maintain their present position not raise it to higher levels of performance. Control and improvement can therefore be perceived as one and the same thing depending on the standards being aimed for and the difficulties in meeting them.
The statements of objectives may be embodied within business plans, product development plans, improvement plans, process descriptions and even procedures.
Achievable objectives do not necessarily arise from a single thought even when the policies provide a framework. There is a process for establishing objectives.
At the strategic level, the subjects that are the focus for setting objectives are the factors that affect the organization’s ability to accomplish its mission – the critical success factors such as marketing, innovation, human resources,
physical and financial resources, productivity and profit. There may be other factors such as the support of the community, of unions, of the media as certain businesses depend on continued support from society. Customer needs, regulations, competition and other external influences shape these objectives and cause them to change frequently. The measures arise from an analysis of current performance, the competition and there will emerge the need for either improvement or control. The steps in the objective setting process are as follows:
Identifying the need
Drafting preliminary objectives
Proving the need to the appropriate level of management in terms of:
whether the climate for change is favourable
the urgency of the improvement or controls
the size of the losses or potential losses
the priorities
Identifying or setting up the forum where the question of change or control is discussed Conducting a feasibility study to establish whether the objective can be achieved with the resources that can be applied Defining achievable objectives for control and improvement
Communicating the objectives
The standard does not require that objectives be achieved but it does require that their achievement be planned and resourced. It is therefore prudent to avoid publishing objectives for meeting an unproven need and which has not
been rigorously reviewed and assessed for their feasibility. It is wasteful to plan for meeting objectives that are unachievable and it diverts resources away from more legitimate uses.
Objectives are not established until they are understood and therefore communication of objectives must be part of this process. Communication is incomplete unless the receiver understands the message but a simple yes or no is not an adequate means of measuring understanding. Measuring employee understanding of appropriate quality objectives is a subjective process. Through the data analysis carried out to meet the requirements of clause 8.4 you will have produced metrics that indicate whether your quality objectives are being achieved. If they are being achieved you could either assume your employees understand the quality objectives or you could conclude that it doesn’t matter. Results alone are insufficient evidence. The results may have been achieved by pure chance and in six months time your performance may have declined significantly. The only way to test understanding is to check the decisions people make. This can be done with a questionnaire but is more effective if one checks decisions made in the work
place. Is their judgement in line with your objectives or do you have to repeatedly adjust their behaviour?
For each objective you should have a plan that defines the processes involved in its achievement. Assess these processes and determine where critical decisions are made and who is assigned to make them. Audit the
decisions and ascertain whether they were contrary to the objectives. A simple example is where you have an objective of decreasing dependence upon inspection. By examining corrective actions taken to prevent recurrence of
nonconformities you can detect whether a person decided to increase the level of inspection in order to catch the nonconformities or considered alternatives.
Any person found increasing the amount of inspection has clearly not understood the objective.

ISO 9000 Standards – Quality Management Principles


ISO 9000 Standards – Quality Management Principles
A quality management principle is defined by ISO/TC 176 as a comprehensive and fundamental rule or belief, for leading and operating an organization, aimed at continually improving performance over the long term by focusing on customers while addressing the needs of all other interested parties. Eight principles have emerged as fundamental to the management of quality.

All the requirements of ISO 9001:2008 are related to one or more of these principles. These principles provide the reasons for the requirements and are thus very important. The quality management principles can be listed as below:

1. Customer focus
Organizations depend on their customers and therefore should understand current and future customer needs, meet customer requirements and strive to exceed customer expectations.
The customer focus principle is reflected in ISO 9000 Standards through the requirements addressing:
a. Communication with the customer
b. Care for customer property
c. The determination of customer needs and expectations
d. Appointment of a management representative
e. Management commitment

2. Leadership
Leaders establish unity of purpose and direction for the organization. They should create and maintain the internal environment in which people can become fully involved in achieving the organization’s objectives.
The leadership principle is reflected in ISO 9000 Standards through the requirements addressing:
a. The setting of objectives and policies
b. Planning
c. Internal communication
d. Creating an effective work environment

3. Involvement of people
People at all levels are the essence of an organization and their full involvement enables their abilities to be used for the organization’s benefit.
The involvement of people principle is reflected in ISO 9000 Standards through the requirements addressing:
a. Participation in design reviews
b. Defining objectives, responsibilities and authority
c. Creating an environment in which people are motivated
d. Internal communication
e. Identifying competence needs

4. Process approach
A desired result is achieved more efficiently when related resources and activities are managed as a process.
The process approach principle is reflected in ISO 9000 Standards through the requirements addressing:
a. The identity of processes
b. Defining process inputs and outputs
c. Providing the infrastructure, information and resources for processes to
function

5. System approach to management
This principle is expressed as follows:
Identifying, understanding and managing interrelated processes as a system contributes to the organization’s effectiveness and efficiency in achieving its objectives.
The system approach principle is reflected in ISO 9001 through the requirements addressing:
a. Establishing, implementing and maintaining the management system
b. Interconnection, interrelation and sequence of processes
c. The links between processes
d. Establishing measurement processes

6. Continual improvement
This principle is expressed as follows:
Continual improvement of the organization’s overall performance should be a permanent objective of the organization.
The continual improvement principle is reflected in ISO 9000 Standards through the requirements addressing:
a. Improvement processes
b. Identifying improvements
c. Reviewing documents and processes for opportunities for improvement

7. Factual approach to decision making
This principle is expressed as follows:
Effective decisions are based on the analysis of data and information.
The factual approach principle is reflected in ISO 9000 Standards through the requirements addressing:
a. Reviews, measurements and monitoring to obtain facts
b. Control of measuring devices
c. Analysis to obtain facts from information
d. Records for documenting the facts
e. Approvals based on facts

8. Mutually beneficial supplier relationships
This principle is expressed as follows:
An organization and its suppliers are interdependent and a mutually beneficial relationship enhances the ability of both to create value.
The mutually beneficial supplier relationships principle is reflected in ISO 9000 Standardsthrough the requirements addressing:
a. Control of suppliers
b. Evaluation of suppliers
c. Analysis and review of supplier data


ISO 9000 Standards – Document Approval

ISO 9000 Standards – Document Approval

The ISO 9000 Standards requires that documents be approved for adequacy prior to issue.

Approval prior to issue means that designated authorities have agreed the document before being made available for use. Whilst the term ade-
quacy is a little vague it should be taken as meaning that the document is judged as fit for the intended purpose. In a paper based system, this means approval before the document is distributed. With an electronic system, it means that the documents should be approved before they are published or made available to the user community.

The ISO 9000 Standards document control process needs to define the process by which documents are approved. In some cases it may not be necessary for anyone other than the approval authority to examine the documents. In others it may be necessary to set up a panel of reviewers to solicit their comments before approval is given.
It all depends on whether the approval authority has all the information
needed to make the decision and is therefore ‘competent’. One might think that the CEO could approve any document in the organization but just because a person is the most senior executive does not mean he or she is competent to perform any role in the organization.

Users should be the prime participants in the approval process so that the
resultant documents reflect their needs and are fit for the intended purpose. If the objective is stated in the document, does it fulfil that objective? If it is stated that the document applies to certain equipment, area or activity, does it cover that equipment, area or activity to the depth expected of such a document? One of the difficulties in soliciting comments to documents is that you will gather comment on what you have written but not on what you have omitted. A useful method is to ensure that the procedures requiring the document specify the acceptance criteria so that the reviewers and approvers can check the document against an agreed standard.

To demonstrate documents have been deemed as adequate prior to issue,
you will need to show that the document has been processed through the
prescribed document approval process. Where there is a review panel, a simple method is to employ a standard comment sheet on which reviewers can indicate their comments or signify that they have no comment. During the drafting process you may undertake several revisions. You may feel it
necessary to retain these in case of dispute later, but you are not required to do so. You also need to show that the current issue has been reviewed so your comment sheets need to indicate document issue status.


Preparing The ISO 9000 Standards Quality Manual

Preparing The ISO 9000 Standards Quality Manual

The standard requires a quality manual to be established and maintained that includes the

scope of the quality management system, the documented procedures or reference to them

and a description of the sequence and interaction of processes included in the quality

management system.

ISO 9000 defines a quality manual as a document specifying the quality management

system of an organization.

It is therefore not intended that the manual be a response to the requirements of ISO 9001.

As the top-level document describing the management system it is a system description

describing how the organization is managed.

Countless quality manuals produced to satisfy ISO 9000 :2008, were no more than 20

sections that paraphrased the requirements of the standard.

Such documentation adds no value. They are of no use to managers, staff or auditors.

Often thought to be useful to customers, organizations would gain no more confidence

from customers than would be obtained from their registration certificate.

This requirement responds to the System Approach Principle.

A description of the management system is necessary as a means of showing how all

the processes are interconnected and how they collectively deliver the business outputs.

It has several uses as :

a means to communicate the vision, values, mission, policies and objectives of the

organization

a means of showing how the system has been designed

a means of showing linkages between processes

a means of showing who does what

an aid to training new people

a tool in the analysis of potential improvements

a means of demonstrating compliance with external standards and regulations

When formulating the policies, objectives and identifying the processes to achieve

them, the manual provides a convenient vehicle for containing such information.

If left as separate pieces of information, it may be more difficult to see the linkages.

The requirement provides the framework for the manual. Its content may

therefore include the following:

1 Introduction

(a) Purpose (of the manual)

(b) Scope (of the manual)

(c) Applicability (of the manual)

(d) Definitions (of terms used in the manual)

2 Business overview

(a) Nature of the business/organization – its scope of activity, its products

and services

(b) The organization’s interested parties (customers, employees, regulators,

shareholders, suppliers, owners etc.)

(c) The context diagram showing the organization relative to its external

environment

(d) Vision, values

(e) Mission

3 Organization

(a) Function descriptions

(b) Organization chart

(c) Locations with scope of activity

4 Business processes

(a) The system model showing the key business processes and how they are interconnected

(b) System performance indicators and method of measurement

(c) Business planning process description

(d) Resource management process description

(e) Marketing process description

(f) Product/service generation processes description

(g) Sales process description

(h) Order fulfilment process description

5 Function matrix (Relationship of functions to processes)

6 Location matrix (Relationship of locations to processes)

7 Requirement deployment matrices

(a) ISO 9001 compliance matrix

(b) ISO 14001 compliance matrix

(c) Regulation compliance matrices (FDA, Environment, Health, Safety, CAA etc.)

8 Approvals (List of current product, process and system approvals)


Develop Quality Management System Documentation In ISO 9000 Standards

Develop Quality Management System Documentation In ISO 9000 Standards

Documentation is the most common area of non-conformance among organizations

wishing to implement ISO 9000 quality management systems. As one company

pointed out: “When we started our implementation, we found that documentation

was inadequate. Even absent, in some areas. Take calibration. Obviously it’s

necessary, and obviously we do it, but it wasn’t being documented. Another area

was inspection and testing. We inspect and test practically every item that leaves

here, but our documentation was inadequate”.

Documentation of the quality management system should include:

1. Documented statements of a quality policy and quality objectives,

2. A quality manual,

3. Documented procedures and records required by the standard ISO 9001:2008, and

4. Documents needed by the organization to ensure the effective planning, operation and control of its processes.

Quality documentation is generally prepared in the three levels indicated below that follows. Use ISO 10013:1995 for guidance in quality documentation.

Level A: Quality manual

States the scope of the quality management system, including exclusions and

details of their justification; and describes the processes of the quality

management system and their interaction. Generally gives an organization

profile; presents the organizational relationships and responsibilities of persons

whose work affects quality and outlines the main procedures. It may also

describe organization’s quality policy and quality objectives.

Level B: Quality management system procedures

Describes the activities of individual departments, how quality is controlled in

each department and the checks that are carried out.

Level C: Quality documents (forms, reports, work instructions, etc.)

1. Work instructions describe in detail how specific tasks are performed; include

drawing standards, methods of tests, customer’s specifications, etc.

2. Presents forms to be used for recording observations, etc.