Start a new topic and get direct answers from the Expert Advice Community.
CREATE NEW TOPIC +Guest
Yes, you can outsource a person as a management representative. A management representative should be someone who is knowledgeable, trained, and have experience in dealing with the Quality Management System according to ISO 13485 of the company as well as familiar. Also, it would be preferable that that person has experience with your type of medical devices and technologies. This person must be available upon your request.
With an outsourced Management representative, you need to have a contract where mutual obligations will be defined.
For more information, please see the following articles:
During the certification audit, auditors confirmed that your quality management system was designed according to ISO 9001 requirements.
During surveillance audits auditors' main concern is to verify that your organization complies with the rules (internal and from the standard) and improves the system. So, I recommend you to check if your quality management system records are being filled correctly, performance is being analyzed and evaluated and improvement actions implemented.
You can find more information below:
The main purpose of the stage 1 audit is to verify whether your environmental management system is designed and compliant with the requirements of the standard. Anything can be audited in terms of documentation. Stage 1 audits are not for auditing implementation. So, do not expect stage 1 audit to go audit operations, for example.
Documents to be reviewed during this stage of the audit are all the documents that belong to the scope of your management system, this includes documents required by the standard itself and the ones that the organization determined as necessary for effective maintenance of the management system.
For more information, see:
Please check this picture:
ISO 14001:2015 requires that an organization determines its compliance obligations and keep them updated (clause 6.1.3). ISO 14001:2015 requires that an organization periodically evaluates its compliance obligations status.
For both of these activities, ISO 14001:2015 does not recommend any particular frequency. It is up to each organization to determine the most suitable frequency. Some economic sectors and some countries are more prone to legal changes than others. Each organization determines its frequency and can evaluate its effectiveness by checking if between consecutive determinations many changes are found.
Besides these clauses, ISO 14001:2015 requires that an organization audits its environmental management system at least once a year (actually, ISO 14001:2015 does not set the yearly requirement, the early requirement is set by the certification bodies in their contract with organizations.
Please consider the following information:
Document control involves ISO 17025 mandatory documents as well as those you develop. It is not just about the unique identifiers (document name, number) and revision number. The purpose of document control is that plus to make sure the correct documents are in use, obsolete version are taken out of use. Furthermore, to make sure all documents are reviewed periodically and have been approved.
For more information see
a similar question at https://community.advisera.com/topic/document-control-6/
the ISO 17025 toolkit document template: Document and Record Control Procedure at https://advisera.com/17025academy/documentation/document-and-record-control-procedure/
the article List of mandatory documents required by ISO 17025:2017 at https://advisera.com/17025academy/blog/2019/08/30/list-of-mandatory-documents-required-by-iso-170252017/
the whitepaper Checklist of mandatory documents required by ISO 17025:2017 available from https://advisera.com/17025academy/free-downloads/
Please note that ISO 27001 and ISO 20000 have different objectives, and core requirements, so only one of them is not enough to fulfill the criteria for both certifications. However, they share many requirements, which makes implement them together easier.
Now, regarding the necessity, this only can be evaluated based on your organization’s strategies and objectives. For example, if your core business is related to the provision of IT services and you have a clear demand for information protection, then both certifications would help.
These articles will provide you a further explanation about ISO 27001 and ISO 20000 integration:
These materials will also help you regarding ISO 27001 and ISO 20000 integration:
If I understand your question correctly, you are asking do notify bodies to recognize standard ISO 13485:2016 as a quality management standard.
According to the MDD, all manufacturers must be in compliance with applicable harmonized standards. Harmonized standards are standards published by the European Commission in the Official Journal of the European Union. On that list, ISO 13485 is the only standard that covers the quality management system.
Considering the MDR, there is still no list of harmonized standards published that will answer MDR requirements. It is expected that a new list of harmonized standards will be published by May 2021. Therefore, ISO 13485:2016 is still not harmonized to the MDR.
For more information, please see the following articles:
Let´s evaluate it considering S.M.A.R.T. concepts:
These articles will provide you a further explanation about Objectives in ISO 27001:
These materials will also help you regarding Objectives in ISO 27001:
I’m assuming you are referring to a security dashboard.
Considering that, ISO 27001 does not prescribe the development of dashboards, only that objectives be defined.
To build information security indicators I suggest you see these materials:
- Key performance indicators for an ISO 27001 ISMS https://advisera.com/27001academy/blog/2016/02/01/key-performance-indicators-for-an-iso-27001-isms/
- Measurement Report https://advisera.com/27001academy/documentation/measurement-report/
These articles will also help you:
- How to perform monitoring and measurement in ISO 27001 https://advisera.com/27001academy/blog/2015/06/08/how-to-perform-monitoring-and-measurement-in-iso-27001/
- ISO 27001 control objectives – Why are they important? https://advisera.com/27001academy/blog/2012/04/10/iso-27001-control-objectives-why-are-they-important/
This material may also help you:
- Measurement Report https://advisera.com/27001academy/documentation/measurement-report/