Start a new topic and get direct answers from the Expert Advice Community.
CREATE NEW TOPIC +Guest
Clause 7.1.5 of ISO 9001:2015 is about:
Unfortunately, I have no experience with mask manufacturing.
You can find more information below:
Yes, the GDPR applies if your company offers goods or services in the EEA or processes personal data of EU individuals, even if it is located outside the EEA. Being in Canada, your organization can enjoy the adequacy decision of the EU Commission that simplifies the transfer between EEA and Canada.
Here you can find more information about the extraterritorial effect of GDPR
If you want to learn how personal data are processed under the EU GDPR you may consider enrolling in our free training EU GDPR Foundations course: https://advisera.com/training/eu-gdpr-foundations-course//
First, let us answer considering each process in isolation.
It is possible to consider 3 types of indicators:
For me, the most important is the effectiveness indicators, they measure if the purpose of the process is being met.
For example, for a company that has a strategic direction around innovation and has a process called “Develop new products” one can ask:
Effectiveness indicators will measure “Quickly” and “hits”. For example:
Efficiency indicators are the classic QCD indicators:
For example, for a company that installs wireless networks for telecom companies, with a process called “Install network”, efficiency indicators can be:
Quantity indicators give information about the need to manage resources accordingly. For example, a number of incoming calls at a call center is a way of evaluating the need to contract more people to handle more calls without raising waiting time.
Should effectiveness indicators be always the indicators to follow? An organization is made of a set of processes but not all processes contribute in the same way to execute a strategy. Some processes are critical for strategy execution and for those processes’ effectiveness is of paramount importance. Some processes must exist but are not critical for strategy execution. If an organization is excellent at those processes it will spend more resources and customers will not value the difference. However, if an organization fails to comply with the minimum, customers will be upset and will be dissatisfied. So, for these processes’ efficiency is the best.
In this free webinar on demand I develop the challenge of working with relevant indicators - Measurement, analysis, and improvement according to ISO 9001:2015 - https://advisera.com/9001academy/webinar/measurement-analysis-and-improvement-according-to-iso-9001-2015-free-webinar/
The following material will provide you more information:
From January 2021 the UK is no more part of the EU so you should comply with the UK GDPR instead of the EU GDPR if you are planning to offer services in the UK. Luckily, the UK GDPR is mirror legislation of the EU GDPR so regulation is pretty identical.One gap is encryption which is considered a common technical security measure, then you should inform the data subject and keep a register of processing activities, just to mention essential activities.
Here you can find more information on how to start implementing GDPR in your business:
If you want to learn how personal data are processed under the EU GDPR you may consider enrolling in our free training EU GDPR Foundations course: https://advisera.com/training/eu-gdpr-foundations-course//
In MDR there is a requirement for Technical documentation. It is covered in Annex 2 - Technical documentation and Annex 3 - Technical documentation on post-market surveillance.
For more details, please see:
Additionally, we have prepared the following procedures and associated templates, required by MDR:
Yes, ISO 9001 requirements are similar. Of course, each laboratory has different interested parties and clients (clauses 4.2 and 5.1.2) and have to comply with different standards and regulation (clause 7.5 about external documents). So, although the requirements are the same, the specific way of complying with them may vary from laboratory to laboratory.
You can find more information below:
Please note that before you start SoA you have some work to do (e.g., definition of the ISMS scope, Information security policy, risk assessment, and treatment methodology, etc.).
Considering that, we suggest you follow the order of folders and templates provided in the toolkit, so you minimize the complexity of your implementation and risks of rework.
Once you have completed the templates needed to support the SoA, you will have a better understanding of how to be filing it. In short, to start documenting the Statement of Applicability you need to perform a risk assessment and risk treatment, to identify the relevant risks and controls (from ISO 27001 Annex A or other sources) you will implement to treat them. Additionally, you need to identify legal requirements (e.g., laws, regulations, and contracts) which require the implementation of specific controls.
For further information, see:
Additionally, included in the toolkit you will buy you will have access to a video tutorial that will help you to fill in the Statement of Applicability.
Thank's for your response.
If you are transitioning from OHSAS 18001 to ISO 45001 during this year’s audit, then this is an ISO 45001 certification audit even if you were partially through your 3-year cycle on OHSAS 18001. This audit will confirm all of ISO 45001 implementation, and is therefore not the reduced audit you will see in a surveillance audit.
You can read a bit more on the certification process in the whitepaper: What to expect at the ISO certification audit: What the auditor can and cannot do, https://info.advisera.com/free-download/what-to-expect-at-the-iso-certification-audit
No, implementing a QMS according to ISO 9001:2015 is no bullet-proof vest against financial problems during pandemic Covid 19. However, I believe that having a QMS according to ISO 9001:2015 can help organizations in answer to the situation. In extreme situations, if your organization cannot operate due to mandatory shutdown from authorities, it is irrelevant being or not being ISO 9001 certified.
You can find more information below: