Friday, October 9, 2009

Reasons a Company Becomes Certified in ISO 9001 Standards

ISO 9000 certification or registration can be an expensive process. A company must consider the reasons and promised benefits for going through this process. If a company decides to seek certification, they should consider making sure their suppliers are certified or at least compliant to the ISO 9000 standards.
Major reasonsIn the early 1990s, companies seemed to be jumping on the certification bandwagon without seriously considering the rationale for doing so. Often they did so because competitors or “everybody else” is getting registered. Today companies seriously look at the reasons and benefits for becoming registered.
The major reasons that company leadership or management decides to seek ISO 9000 certification are to gain continued or increased business and to maintain effective operations.
Improved businessA company can maintain a relationship with customers, as well as get increased business through complying to the ISO 900 standards or becoming certified. This comes from satisfying customer demands, the desire for European business, and to advertise.
Finally, some companies want to become certified, so they can advertise that fact and give the impression of being better than their competitors.
You have seen ads with a logo stating the company is certified at some ISO 9000 level. It apparently gives those companies a leg up on competitors not registered.
Again, this seemed more important in the 1990s, but you don’t see that many companies using ISO 9000 certification as an advertising tool.
ISO 9000 is supposed to make sure your business is run in an orderly manner that will assure continued success.
One would think that a goal such as being run effectively and able to deliver goods consistently and reliably would also be desirable for a company’s own operation. Surprisingly, many companies do not consider that as a goal.

Transition from ISO 9001:2000 to ISO 9001:2008

Transition from ISO 9001:2000 to ISO 9001:2008
This reference guide was developed to help you understand the nature of the changes to the ISO 9001 standard.
Clause Change/Emphasis Not Auditable
0.1 General – Added language emphasizing statutory and regulatory requirements are a concern as it relates to products for this international standard.
0.4 Compatibility with Other Management Systems Standards - Emphasis was added on the consideration given to ISO 14001:2004 to ensure that the standards are compatible.
1.1 General
1.2 Application – “Statutory” was added in certain paragraphs to ensure the user is aware that these requirements must be taken into consideration. Additional notes were added to explain that where the word “product” appears, it refers to every stage of its existence, from raw material received to the final product being shipped to the customer.
2. Normative Reference – Reference to ISO 9000 (vocabulary and concepts) was updated to refer to the current revision (i.e. ISO 9000:2005).
3. Terms and Definitions – The supplier/organization/customer model was removed. These relationships, in reality, are not always linears.
The Auditable RequirementsClause Change/Emphasis4.1In 4.1 a, “identify” was replaced with “determine” to emphasize that an organization must give careful consideration to what processes are needed in order to fulfill requirements.A link is drawn to 7.4 in the additional note. This was done to show that the supplier approval, evaluation, and re-evaluation process is where evidence of controlled outsourced processes should be demonstrated.4.2.1References to records and documents were consolidated.Also, the organization can require records not specified in this international standard that are created and maintained.4.2.3Clarification is given to the requirement for outsourced documents. Only those needed for the planning and operation of the QMS need to be controlled. This could exclude documents related to occupational health and safety since ISO 9001 contains requirements only concerned with product (see 0.1).4.2.4Rephrased, but no additional clarifications or emphasis added. Editorial change only.5.5.2The management representative must be from the organization’s management. This would exclude consultants and other individuals external to the organization (e.g. a management representative from the corporate entity). The purpose of this is to ensure that this individual, entrusted with the responsibilities of championing the quality management system, is not “out of touch” with the organization.6.2.1The boundaries of competence only extend to individuals who impact product conformity. However, this does not just include those who are directly involved in production. The decisions made by management affect product conformity; therefore, they must be competent as well.
6.2.2If said personnel have not yet attained the competence needed to perform the assigned job, then the organization must provide training or some other remedy to ensure that competence is achieved. The organization must also have a mechanism to ensure that personnel have been evaluated based on how well they demonstrate their knowledge and skill (i.e. competence). It is not enough to merely provide training or consider an individual’s experience. The organization must prove to itself that this person can, in fact, perform.6.3Infrastructure also includes databases and information technology.6.4Emphasis is added in a note to highlight that the concept of “work environment” only extends to product quality.7.1 c“Measurement” is added.7.2.1“Post-delivery activity” is clarified in a note with examples.7.3.1A note emphasizes that design verification, validation, and review are different from one another and serve different purposes. Design review is where the organization evaluates if the design can meet requirements and if any changes need to be made. Design verification is where the organization has ensured that requirements have been met (e.g. is the widget blue and is it hexagonal?). Design validation is where the organization proves that the design can perform as required.However, the records of design verification, validation, and review do not have to be separate.7.3.3Production and service provisions also extend to how product is preserved, handled, etc., to ensure product conformity. See 7.5.1Design outputs must include requirements related to preservation. See 7.5.5.
7.5.2Notes were added to give examples of the types of processes where this requirement would apply along with a statement that service organizations should have additional considerations in the planning stages when deficiencies and conformity are not likely to be identified prior to delivery.7.5.3Product status must be identified throughout product realization, not just the final product. See 1.2.7.5.4Wording was modified to add clarity, but the intent of the requirement has not changed.7.5.5Again, emphasis is added that care must be given to preserving the product regardless of where it falls in the realization process.7.6An obsolete reference to another ISO document was replaced.The definition of “monitoring and measuring devices” has been clarified to include equipment and devices that are purposed for monitoring and measuring, regardless of their original or intended purpose.An additional note regarding software was added.8.2.2Document and record requirements were reworded and their placement modified to improve clarity.The reference to the auditing guidance document was updated (i.e. ISO 19011).
8.2.3Wording was modified to emphasize that correction and corrective actions are not only to be taken to preserve the conformity of the product, but also to preserve the quality management system. For example, internal rejection/scrap rates could show evidence that the organization is preserving product conformity and is taking intermediate action to prevent bad product from being shipped to their customers; however, it could also be a sign that the organization is not efficient since the higher rejection/scrap rates are undesirable.A note was added to clarify the meaning of “suitable methods” related to planning, monitoring and measurement processes. Suitability should be determined based on risk and the impact that nonconformity would have on the product or process.8.2.4Product can be released to other internal processes despite planned arrangements not being satisfactorily completed as long as it conforms prior to release to the customer. This relaxes requirements on intermediate inspection results and records.8.3Actions taken against nonconforming product must be proportional to its impact or potential impact. See 8.2.3 related to impact considerations for monitoring and measurement.This would mean that in the planning stages of a product, the organization needs to customize responses to nonconforming products based on the risk or potential risk to the organization.This requirement existed in ISO 9001:2000; however, its location has changed.
8.5.2Nonconformity can have multiple causes (“cause”; i.e. a singular reason, was used in the 2000 version); therefore, the organization must consider this when conducting root cause analysis.Also, it is not enough to simply review corrective action and ensure that procedures were changed, personnel have been re-trained, and that processes were amended. The organization must review whether or not the action(s) taken were effective; i.e. did they successfully eliminate the nonconforming condition?8.5.3Similar to the new emphasis on the effectiveness of corrective action, the organization must also document whether or not the preventive action(s) taken were effective in eliminating the risk of nonconformity.

ISO 9001 Standards Requirement – Product Realization

ISO 9001 Standards Requirement – Product Realization
Planning of Product RealizationPlan and develop the processes needed for product realization. Keep the planning consistent with other requirements of the quality management system and document it in a suitable form for the organization. Determine through the planning, as appropriate, the:Quality objectives and product requirementsNeed for processes, documents, and resourcesVerification, validation, monitoring, measurement, inspection, and test activitiesCriteria for product acceptanceRecords as evidence the processes and resulting product meet requirements
Customer-Related Processes
Determination of Requirements Related to the ProductDetermine customer requirements:Specified for the product (including delivery and post-delivery activities)Not specified for the product (but needed for specified or intended use, where known)Determine:Statutory and regulatory requirements applicable to the productAny additional requirements considered necessary by the organization
Review of Requirements Related to the ProductReview the product requirements before committing to supply the product to the customer in order to:Ensure product requirements are definedResolve any requirements differing from those previously expressedEnsure its ability to meet the requirementsMaintain the results of the review, and any subsequent follow-up actions. When the requirements are not documented, they must be confirmed before acceptance.If product requirements are changed, ensure relevant documents are amended and relevant personnel are made aware of the changed requirements.NOTE: In some situations, such as internet sales, a formal review is impractical for each order. Instead, the review can cover relevant product information such as catalogs or advertising material.
Customer CommunicationDetermine and implement effective arrangements for communicating with customers on:Product informationInquiries, contracts, or order handling (including amendments)Customer feedback (including customer complaints)

ISO 9001 Standards Requirements – Design and Development

ISO 9001 Standards Requirements – Design and Development
Design and Development PlanningPlan and control the product design and development. This planning must determine the:Stages of design and developmentAppropriate review, verification, and validation activities for each stageResponsibility and authority for design and developmentThe interfaces between the different involved groups must be managed to ensure effective communication and the clear assignment of responsibility. Update, as appropriate, the planning output during design and development.NOTE: Design and development review, verification, and validation have distinct purposes. They can be conducted and recorded separately or in any combination, as deemed suitable for the product and the organization.
Design and Development InputsDetermine product requirement inputs and maintain records. The inputs must include:Functional and performance requirementsApplicable statutory and regulatory requirementsApplicable information derived from similar designsRequirements essential for design and developmentReview these inputs for adequacy. Resolve any incomplete, ambiguous, or conflicting requirements.
Design and Development OutputsDocument the outputs of the design and development process in a form suitable for verification against the inputs to the process. The outputs must:Meet design and development input requirementsProvide information for purchasing, production, and serviceContain or reference product acceptance criteriaDefine essential characteristics for safe and proper useBe approved before their release
Design and Development ReviewPerform systematic reviews of design and development at suitable stages in accordance with planned arrangements to:Evaluate the ability of the results to meet requirementsIdentify problems and propose any necessary actionsThe reviews must include representatives of the functions concerned with the stage being reviewed. Maintain the results of reviews and subsequent follow-up actions.
Design and Development VerificationPerform design and development verification in accordance with planned arrangements to ensure the output meets the design and development input requirements. Maintain the results of the verification and subsequent follow-up actions.
Design and Development ValidationPerform validation in accordance with planned arrangements to confirm the resulting product is capable of meeting the requirements for its specified application or intended use, where known. When practical, complete the validation before delivery or implementation of the product. Maintain the results of the validation and subsequent follow-up actions.
Control of Design and Development ChangesIdentify design and development changes and maintain records. Review, verify, and validate (as appropriate) the changes and approve them before implementation. Evaluate the changes in terms of their effect on constituent parts and products already delivered. Maintain the results of the change review and subsequent follow-up actions.

What is a “document” In ISO 9001 Standard?

What is a “document” In ISO 9001 Standard?
The following are some of the main objectives of an organization’s documentation, independent of whether or not it has implemented a formal QMS;a) Communication of Information as a tool for information transmission and communication. The type and extent of the documentation will depend on the nature of the organization’s products and processes, the degree of formality of communication systems and the level of communication skills within the organization, and the organizational culture.b) Evidence of conformity provision of evidence that what was planned, has actually been done.c) Knowledge sharing to disseminate and preserve the organization’s experiences. A typical example would be a technical specification, which can be used as a base for design and development of a new product.A list of commonly used terms relating to documentation is presented in Annex A (taken from ISO 9000:2005). It must be stressed that, according to ISO 9001:2008 clause 4.2 Documentation requirements documents may be in any form or type of medium, and the definition of “document” in ISO 9000:2005 clause 3.7.2 gives the following examples:papermagneticelectronic or optical computer discphotographmaster sample

Organizations preparing to implement a QMS For ISO 9001

Organizations preparing to implement a QMS For ISO 9001
For organizations that are in the process of implementing a QMS, and wish to meet the requirements of ISO 9001:2008, the following comments may be useful.For organizations that are in the process of implementing or have yet to implement a QMS, ISO 9001:2008 emphasizes a process approach. This includes:- Identifying the processes necessary for the effective implementation of the quality management system- understanding the interactions between these processes.- documenting the processes to the extent necessary to assure their effective operation and control. (It may beappropriate to document the processes using process maps. It is emphasized, however, that documented process maps are not a requirement of ISO 9001:2008.)These processes include the management, resource, product realization and measurement processes that are relevantto the effective operation of the QMS.Analysis of the processes should be the driving force for defining the amount of documentation needed for the quality management system, taking into account the requirements of ISO 9001:2008. It should not be the documentation that drives the processes.

Outsourced Processes In ISO 9001 Standards

Outsourced Processes In ISO 9001 Standards
One of the changes in ISO 9001:2008 is clarification of the role of outsourced processes in a quality management system. Guidance on ‘Outsourced processes’ helps clarify the intent and shows the linkage between Clause 4.2, where outsourced processes appear, and the purchasing controls in clause 7.4.An outsourced process is a process that the organization needs for its quality management system and is performed by an external party. This party could be another company, a corporate service, another division, etc.The organization needs to ensure the outsourced process is conducted in accordance with ISO 9001:2008 and other requirements of the quality management system. This brings in the purchasing controls of 7.4. The service may not be purchased in the traditional sense of a monetary transaction. The guidance document explains that the controls in clause 4.2 and 7.4 apply. For example, a “no charge” service from a corporate head office requires documentation of supplier selection and, most importantly, control.The guidance document addresses two important cases and gives guidance on the appropriate level of control. The cases are:• The organization has the competence and ability to carry out a process, but chooses to outsource it (for commercial or other reasons).• The organization does not have the competence to carry out the process itself, and chooses to outsource it.