The best way to implement the standard is to observe the implementation as a project. Define the responsibilities, deadlines and all activities that need to be performed.
I suggest you to start with Quality Policy, Quality Manual and mandatory procedures and then develop the procedures for your processes. Next step would be to ensure that the procedures are implemented and followed, this can be accomplished through internal audit and management review.
Once you create all necessary documents and ensure that they are implemented you will be ready for certification.
Before entering the certification process you must first implement the ISO 9001 standard, which means to document and implement all mandatory procedures and procedures you find necessary for your organization.
Once you document and implement your quality management system you are ready for certification. Some certification bodies expect you to conduct internal audit and management review before they come to perform certification audit.
The main role of the internal auditor is to acquire evidences that organization complies with requirements of the standard. Depending on whether you are part of internal auditors team or single auditor your roles and responsibilities can vary. Here I will explain the audit performed by a single auditor who has the same responsibilities as the lead internal auditor in case of internal auditor team.
Internal auditor must manage the internal audit process which means establishing internal audit plan (when and which processes will be audited) and the scope of the audit (in this case compliance with ISO 9001:2008). Than you should organize the opening meeting where you present to the auditees the schedule and the scope of the internal audit.
When you start auditing process by process, you need to look at the documents and procedures to see whether they are compliant with the standard or not and than to interview the process own ers and employees to determine whether they follow the defined procedures and do they keep records prescribed by procedures.
If you spot some nonconformity, you should present it during closing meeting at the end of the internal audit. The participants of the closing meeting should be process owners and higher management. Besides nonconformities, you can also present some good practices identified in processes and recommendations for improvements.
After closing meeting internal auditor creates internal audit report and delivers it according to procedure for internal audit.
Steps in Internal Audit
It is very important to follow your current Internal Audit Procedure, but here are some steps.
Once you start planning the internal audit, you'll need to identify the standard requirements that refers to each process. Using Internal Audit Checklist (https://advisera.com/9001academy/documentation/internal-audit-checklist/) can help you identify all requirements and prevent you from missing something out.An then you perform the internal audit by acquiring evidences that the processes are compliant with requirements of the standard.
You may also find these materials useful: Project Plan for ISO 9001 implementation (Word) and ISO 9001 Implementation Diagram (PDF) - you'll find both materials here: https://advisera.com/9001academy/free-downloads//
Form of writing procedures
The standard does not prescribe the way of writing procedures or some mandatory elements of procedure. In case of smaller company you can even insert the procedures into the Quality Manual.
There are some elements that are very common and logical, such as purpose, scope, users and reference documents. Take a look at free preview of our Procedure for Document and Record Control https://advisera.com/9001academy/documentation/procedure-document-record-control/
Here are some very informative articles that you can find interesting:
Configuration management (CM) is a systems engineering process for establishing and maintaining consistency of a product's performance, functional and physical attributes with its requirements, design and operational information throughout its life and it is just a part of Quality Management System since it refers only to product not the whole management system.
Control of records (and documents) covers not only the record requirements of Configuration Management but also the management system requirements for records. The principles are the same but the scope is different.
Can we manage them ( solve/eliminate the problem ) with the Process "Control of non conforming product/service" and carry on with the Process"Corrective / Preventive Actions" ?
Or we must determine a different process for controlling and problem solving of these two outsourced processes?
These two mentioned above mandatory processes, are only for our internal system services and control ?
Thank you for your time,
Answer:
There is no need you to manage nonconformities in outsource organization. If you find any irregularities in operation they perform in your behalf, you should file a complaint and request evidences that the nonconformity is removed.
There is no need to establish another process.
Yes, the control of nonconforming product and corrective and preventive ac tions are only for internal processes.
Here are some informative articles regarding the subject:
1) Should I do a documented procedure over this outsource process? (we do not perform this process, we just control and check them all the time and receive the job results that we demand)
2) We need to give Work Instructions. How should be done this? Within a process or not?
Answer:
We need to give Work Instructions to our outsource process.
There is no need you to write working instructions for your outsource partners, you only need to precisely define your requirements regarding the service they provide to you through contract.
1) Should I do a documented procedure over this outsource process? (we do not perform this process, we just control and check them all the time and receive the job results that we demand)
You can write procedure for managing outsourced processes, but it would be your internal procedure, not a procedure for your outsource partner. Here you can write methods and frequency of control of outsourced process.
2) We need to give Work Instructio ns. How should be done this? Within a process or not?
Again, you don't need to give work instructions. You need to ensure that your outsource partner is capable and competent to provide the service you requested. It can be done in several ways, you can inspect and approve the qualification of employees, activities, processes and equipment of your outsource partner or to request evidences of their capability to deliver the service.