Search results

Guest

Guest

Create New Topic As guest or Sign in

HTML tags are not allowed

Assign topic to the user

  • The most relevant tools supporting PPAP processes

    PPAP requirements should be determined according to customer-specific requirements. If you do not have a special customer requirement then you can use the PPAP rev 4 blue books written by AIAG as a reference manual. There are generally 19 main topics in PPAP. Some of those are given below. 

     

    • Process Flow Chart
    • FMEA
    • Control Plan
    • Part Drawing
    • Tool Drawing
    • Tool Approval 
    • Part Measurement Report
    • Part Test Reports
    • Part History Document 
    • Capability Studies
    • MSA Studies
    • Sample Part
    • Supplier Part Approval Reports 
    • Appearance Approval Report
    • Engineering Change Approval
    • IMDS Approval
    • PSW Document 
    • Etc...
       
  • Lab activities

    In ISO 17025; "laboratory activities" are one of three types of work taking place in a laboratory, i.e. either testing, calibration or sampling, (when the sample is going to be tested or calibrated). That means that the range of lab activities is the testing, calibration or sampling that is to be, or is accredited. Laboratories must define and document (i.e. decide and put in writing) a list of what testing, calibration or sampling activities conform to ISO 17025, as this will be listed on the accreditation certificate; and is what can be claimed as accredited.

    I will give you two testing laboratory examples:

    • Heavy Metals (ICP-MS) in Water for Arsenic, Cadmium, Lead, Mercury
    • Fat in Animal Feed, Cereal Foods, Cocoa products, Dairy products.

    Laboratories must perform the work themselves on an ongoing basis, and not “contract out” such work unless under controlled temporary arrangements due to an emergency.

    For more information on ISO 17025 see

  • Lists of potential risks for a 100% digital market place

    Every company has a different set of risks because of different products, technology, processes, people, etc. so it is is not possible to develop a generic list of risks. 

    However, in the ISO 27001/27017/27018 Toolkit you purchased, in the folder 05 you have a document called Risk Assessment Table where you will find catalogs of assets, threats and vulnerabilities you can take into account - these will speed up significantly the identification of risks in your company. 

    Further, you have also received access to video tutorial which show a couple of examples of how to identify risks using this document. 

    To learn more about the risk management, sign up for this free online training: ISO 27001 Foundations Course https://advisera.com/training/iso-27001-foundations-course/ 

  • OLA vs Technical Service Catalog

    OLA is an internal agreement (two different parts, e.g. departments, of the same organization) where you define activities in scope with related parameters, e.g. response time). More about OLA in this document "SLAs, OLAs and UCs in ITIL and ISO 20000“ https://advisera.com/20000academy/knowledgebase/slas-olas-ucs-itil-iso-20000/
    OLA can be a formal document but can be also e.g. ticket forwarded to another department.
    The technical service catalogue is part of the Service catalogue and describes the service in technical parameters. More about Service catalogue in the article "Service Catalogue – a window to the world“ https://advisera.com/20000academy/blog/2013/03/19/service-catalogue-window-world/ and "Service Catalogue – Defining the service“ https://advisera.com/20000academy/blog/2014/03/11/service-catalogue-defining-service/ or in this free webinar " ITIL Service Catalogue from scratch“ https://advisera.com/20000academy/webinar/itil-service-catalogue-from-scratch-free-webinar-on-demand/

  • ISO Quality management for service giving public institutions

    Yes, you can. ISO 9001:2015 is a standard that can be used to design and implement a quality management system in all kinds of organizations. In a service giving public institution, you may not use the word customer, but you will certainly use the words interested party.

    The following material will provide you more information:

  • How to implement QMS?

    When I started implementing quality systems, I started with the standard and then took pieces of the company and associated them with each clause in the standard. Later, I realized that this approach made it difficult for other people to understand QMS in addition to sounding very artificial. The process approach helped me to overcome this difficulty. Instead of starting with the standard, start with the company: How does the company work? How does the workflow circulate from a customer in need to the customer served?

    So, think about your organization as a set of daily activities and at the same time a whole in search of meeting a purpose, a strategic intent.

    For the first part, the daily activities, use the process-approach, you can see this free webinar on demand – The Process Approach – What it is, why it is important, and how to do it – https://advisera.com/9001academy/webinar/iso-9001-process-approach-free-webinar-on-demand/ - then you can ask people in your organization to describe how they do their activities, what kind of documents they use as guidance or to record, and who participates. After this, you can use ISO 9001:2015 clauses to check if anything is missing. For example, clause 8.2 can be used to check a commercial process, clause 8.3 can be used to check how to develop a new service and clause 8.4 can be used to check a purchasing process.

    Mistakes, nonconformities may happen in each process, you can see this free webinar on demand - How to implement risk management in ISO 9001:2015 - https://advisera.com/9001academy/webinar/how-to-implement-risk-management-in-iso-90012015-free-webinar/ - with the risk-based approach you can determine what needs to be done to improve or control performance in each process.

    For the second part, you need to see your organization as an entity immersed in a context, working for and with interested parties following a strategic orientation to meet desired objectives. For this part let us apply ISO 9001:2015 clauses 4.2, 4.1 and 6.1.

    4.2 - What is the organization’s purpose? Why does it exist in the first place? Whom does it serve? What are their needs and expectations? An organization, like any other organization has to serve its “customers” (even if they are not the ones who pay). These groups also have need and expectations. And the service may have to be provided under a set of regulations that act as constraints. So, list the more relevant needs and expectations. You see, after all the noise and bells and whittles, the organization exists to provide, to answer, to deliver on those needs and expectations.

    From here you can define and characterize the set of services that are provided by the organization, and their outcomes, their service specifications.

    4.1 – Is it easy to deliver on those needs and expectations? While answering this question reality sets in. The organization is placed in a certain context with internal and external issues. Perhaps there is not enough money, perhaps there is lack of staff, perhaps “customers” don’t collaborate, perhaps there are voluntaries that can be called to help, …

    6.1 – when you confront the relevant needs and expectations of the relevant interested parties with the internal and external issues from the context you can determine risks and opportunities. What can help you or hinder you in meeting the desired outcomes according to specifications? You can use the most relevant risks to develop a Quality Plan – what needs to be controlled, what needs to have work instructions, what needs to be recorded, what kind of training is needed, … this way you are starting to design your quality management system not based on mambo jambo, but in what really matters to the purpose of the organization and its interested parties.

    You can find more information below:

     

  • Risks posed by third party’s or suppliers

    Different types of suppliers will have very different risks - e.g. with providers of telecom equipment you will have the risks of equipment breakdown, eavesdropping, etc.; with providers of specialized security services you will have the risk of unauthorized access to sensitive data, unauthorized change of sensitive data, industrial espionage, etc. 

    To learn more about handling third parties and related risks, see these materials: 

    This online course will also teach you about handling third-party risks: ISO 27001 Foundations Course https://advisera.com/training/iso-27001-foundations-course/ 

  • ISO 9001:2015 kurulumu

    Merhaba,

    bir işletmeye KYS ISO 9001:2015 kurulumu yapılacak veya var olan dokümanlar kontrol edilecek. 

    Danışmanlık almadan izlenecek metodlar belirli midir ?
    Yani bir iş akışı var mıdır yapılacak işlerin listesi gibi ?

    ISO standart maddeleri belirli ve anlaşılmıştır ancak istenilen "net doküman adı ve içeriği" nedir diye bakılacak bir metod var mıdır ?

     

    Yani kurumun verilerinin izlenmesini takibini ister yerine "Yıllık Veri Tablosu" ister içerik olarak ay ay hurdalar, üretimler vs bilgileri girmeniz gerekir örneğinde olduğu gibi. 

     

    Teşekkürler

  • Documents for biofertilizer NAB lab

    The generic ISO 17025 mandatory requirements are covered in the documents of the ISO 17025 Toolkit, applicable to any testing and calibration laboratory applying for ISO 17025 accreditation with their national accreditation body. To meet the specific requirements for your sector, namely biofertilizers; as for any other sector or program, you would need to determine what the requirements are and either expand on the toolkit documents or add additional procedures and records. Contact your accreditation or regulatory body or look at their website and establish what you need to implement; in addition to the mandatory ISO 17025 documents. These should be easily added to the toolkit documents.

    For further information see the following:

  • Procedures for suppliers to cover the control of External Providers

    1. In addition to my 27th of December question, 8.6 paragraph demands evaluations of the business continuity capabilities of relevant partners and suppliers;
    Where in the package can I find a format for conducting evaluation for partners and suppliers according to ISO 22301:2019

    You can use the same procedure and checklist used for your internal audit. Both procedure and checklist can be found in folder 10 from your ISO 22301 Toolkit.

    For additional information, see (the same concept applies to ISO 22301):

    2. And another question please. Where can i find a format to record business continuity objectives and actions and evaluation of them as 6.2.1 and 6.2.2 states
    Thank you once again.

    You can use your own document usually used for planning for documenting business continuity objectives and methods to measure them, and if you do not have such, then you can use the blank template provided in the root folder of your toolkit.

    For further information, see:

    And another question, please.
    Where in the package can i find a document to describe external and internal issues that are relevant to its purpose and that affect its ability to achieve the intended outcome such as Pandemic in the territory, Earthquakes, and risk appetite in general and according the site territory;

    The information required by ISO 22301 clause 4.1 is addressed by the following templates:

    • Organization's activities (from clause 4.1 a)) and potential impact from disruptive incidents are addressed by template Business Impact Analysis Questionnaire (located at folder 04 Business Impact Analysis Methodology)
    • The organization's functions (from clause 4.1 a)) are addressed in all templates when an activity to be performed is required (by means of the field [job title]). Functions related specifically to the BCMS are defined in the template Business Continuity Policy, section 3.5, (located at folder 03 Business Continuity Policy)
    • Organization's product and services (from clause 4.1 a)) are addressed by template Business Continuity Policy, section 3.5, (located at folder 03 Business Continuity Policy)
    • Relations with suppliers, partners, and interested parties (from clause 4.1 a)) are addressed by template Business Continuity Strategy (located at folder 05 Business Continuity Strategy)
    • Relationships between the Business Continuity Policy and other organization's policies, objectives, and general risk management strategy (from clause 4.1 b)) are addressed by template Business Continuity Policy, section 2, (located at folder 03 Business Continuity Policy)
    • Organization's risk appetite (from clause 4.1 c)) is addressed by template Business Impact Analysis Questionnaire, section 6 (maximum acceptable outage) (located at folder 04 Business Impact Analysis Methodology)  

    This article will provide you a further explanation (the same concept applies to ISO 22301):

    This material will also help you regarding ISO 22301:

Page 234-vs-13485 of 1127 pages

Didn’t find an answer?

Start a new topic and get direct answers from the Expert Advice Community.

CREATE NEW TOPIC +