игры https://mailsco.online/ развлечение помогают развитию аналитического мышления, оптимизируют навыки взаимодействия.
ISO 27000:2016
Answer:
Yes, you are right, ISO has published recently the ISO 27000:2016, but the structure of the standard is very similar to the previous ISO 27000:2014 (by the way, the clause 2 Terms and definitions includes the same terms in both standards). The main change that I have seen is that in the clause 0.2 ISMS family of standards, the new ISO 27000:2016 references to new standards like ISO 27009, ISO 27017 or ISO 27018.
Anyway, from my point of view, the formal recommendation is that you always need to have the latest version of all standards, but in this case if you do not work with these new standards (ISO 27009, ISO 27017, ISO 27018), maybe the last revision of ISO 27000 will be not relevant for you.
Depending on your processes, some of the requirements of the standard won't apply to your organization. Since you don't have warehousing as a process, you may exclude this procedure from your QMS documentation.
But, production procedure can't be excluded because it doesn't refer only to the production processes, but also to service provision processes and this is something that your company does. It wouldn't be called "Procedure for Production" but "Procedure for Service Provision" and here you need to describe how your service provision process is carried out, who is responsible for which steps in the process, what resources and additional documents and records are used, etc.
On the other hand, I would suggest you consider exclusion of the following clauses of the standard since they probably don't apply to your quality management system:
- 7.1.5 Monitoring and measuring resources
- 8.3 Design and development
- 8.5.3 Property belonging to customers or external providers
The best way of ISO 9001 implementation is to set it up as a project, meaning to define the activities, responsibilities, resources and deadlines.
The first step is to conduct GAP analysis to determine to what extent you already meet the requirements and what needs to be done to achieve the full compliance.
Once you determine all the activities, you need to create all the documents, establish new processes and adapt the existing processes. When everything is done, the company must conduct internal audit to check whether all the requirements of the standard are met and to conduct the management review.
After all the activities are executed and internal audit and management review are conducted, the company may hire certification body to conduct certification audit.
Naming the actions to address risks and opportunities
I would like to know your opinion on a question I asked during the webinar (not answered because of shortage of time).
How could you define in your QMS the actions coming out from a "risk assesment / evaluation activity":Preventive actions (no nonconformity has occurred yet), even if the term "preventive action" is not mentioned in the new ISO 9001) or "Corrective actions" assuming for instance that a risk exceeding a certain level (eg FMEA risk weight) is considered a nonconformity in your QMS ?
Answer:
The standard, doesn't define how this actions should be called, but I think the best title for them should be "actions to address risks and opportunities". The reason for that is to avoid the term "preventive" and they are not always "corrective", on the other hand, they need to be reviewed during the management review and it will be much easier to systematize them if they all have the same title, like corrective actions.
In order to properly assess the risk and opportunities, you need first to determine the scope of your assessment. The standard requires organization to address risks and opportunities emerging from the context of the organization regarding quality management system and ability of the organization to achieve its objectives, so you only need to identify risks and opportunities regarding context of the organization, QMS and the objectives of the organization.
Once you determine the scope of your assessment and identify risks and opportunities, you need to evaluate them to define what risks and opportunities are the most important and require actions to be addressed.
Next step is to plan actions to address the risks and opportunities, this includes defining responsibilities, resources and deadlines for addressing risks and opportunities. Once the actions are planed and executed, the results of the actions need to be reviewed to determine whether the risks and opportunitie s are address and to see if there is a need for additional actions. This is usually done during the management review.
ISO 19011 - - Guidelines for auditing management systems is not a standard as ISO 9001 in therms that the organization can't be certified against it. The ISO 19011 standard includes the requirements for auditing a management system, and is used to train the people who certify that companies have met the requirements of standards such as ISO 9001, ISO 14001 and the like. ‚
The standard offers four resources to organizations to "save time, effort and money":
- A clear explanation of the principles of management systems auditing.
- Guidance on the management of audit programmes.
- Guidance on the conduct of internal or external audits.
- Advice on the competence and evaluation of auditors.
The only relation between ISO 9001 and ISO 19011 is that the ISO 19011 can be used for auditing ISO 9001, but it is not mandatory especially for internal audits. On the other hand certification auditors must be familiar with ISO 19 011 in order to perform proper certification audit.
The best way to get the company on board for ISO 9001 implementation is to present to the top management the benefits of the implementation. As you already stated, the major clients often require companies to be ISO 9001 certified in order to ensure quality product or service, but there are also a lot of other benefits from getting ISO 9001 certificate.