Search results

Guest

Guest

Create New Topic As guest or Sign in

HTML tags are not allowed

Assign topic to the user

  • 21 CFR 820 / ISO 13875

    I assume you meant ISO 13485. Yes, you are right, there are a lot of similarities between ISO 13485 and FDA 21 CFR 820. 

    The best ways to see what are similarities and differences between these two standards is on the following link:

    There is a proposal sent by FDA to transfer completely on the ISO 13485. This proposal was sent in 2018 and in 2020 decision was expecting. However, so far it is not legal yet. The main reason why the FDA was thinking of this transfer is that ISO 13485 is globally recognized as a quality management standard for medical device manufacturers.

    For more information, see:

    • FDA Update Transition to ISO 13485:2016 https://www.fda.gov/media/123488/download

    • IATF 16949 4.4.1.2 Product

      Product safety is an issue taken with the new version standard of IATF 16949: 2016. 4.4.1.2 The parts from "a" to "m" clause cover almost the entire standard. Article h) is more about responsibility, authority, knowledge, escalation process.

      I have listed the typical audit questions for clause "h" below, but are not limited to them.

      •  Who is the product safety officer defined and how and where was it documented?
      • Do all employees know their duties and authorities regarding product safety?
      • When the customer complaint is received, who and what to do, how has this subject been described in the organization, and are the relevant employees competent and knowledgeable about customer complaints?
      • How did the organization define the escalation process?
      • Is a document like escalation matrix or etc. defined in QMS structure?
      • Are all employees, including senior management, knowledgeable about product safety?
    • CE Marking and Major NCRs

      You are supposed to get this information from your Notify body. Usually, considering major NC it is necessary to send a CAPA plan and prove of solving it within one month.

      Here is some general guidance on how to deal with non-conformities:

      • How to deal with nonconformities in an ISO 9001 certification audit- https://advisera.com/9001academy/blog/2015/06/09/how-to-deal-with-nonconformities-in-an-iso-9001-certification-audit/

      • Role of an ISO Lead Auditor and Implementer

        1. What is the role of the lead auditor and lead implementer in ISO processes?

        First is important to note that ISO management system standards do not require a lead auditor and/or lead implementer to perform ISO processes, so the organizations are free to adopt these roles or not according to their needs.

        Considering that, the lead implementer's role is to guide the management system implementation, from the identification of requirements to implementation of corrective actions and opportunities for improvement identified in the management review.

        The role of the lead auditor is to define the audit program, perform audits, and elaborate audit reports, according to the requirements of the ISO management standard. In case there is more than one auditor involved, the lead auditor is the responsible person for the team.

        For further information about these roles, see:

        2. What should an organization have such persons?

        Lead implementers are not normally considered for regular positions in organizations, because in most cases management systems implementation are project-related activities, with a defined date to start and finish (it is best to hire than as consultants).

        On the other hand, internal audits are regular activities to be performed in a management system, and depending on the complexity of the audit program, when a single internal auditor is not enough to ensure a proper audit process, the presence of a lead auditor can bring benefits in terms or organizations and dissemination of competencies (they are qualified for training internal auditors).

        For further information, see:

        These materials will also help you regarding internal audit:

      • Warranty and Lifetime

        The company where I work is not very big and activity is related with the assembly of wire harnesses for automotive.

        Recently I was requested to give info for the Lifetime of the product and Warranty management to our OEM potential customer I have read of course IATF points related to this but it's still not very clear.What are obligations related to warranty management from the supplier side?

        As you know, the quality responsibility of the product belongs to the manufacturer and designer throughout the product lifetime. The solution to problems related to product design belongs to the product design responsibility. The production factory is responsible for the problems related to the production quality of the product.

        Complaints about the products produced by the supplier can come in 2 ways.

        • Directly from the factory where it sells the product
        • From vehicle service
        If the supplier receives complaints directly from services or from the factory; these issues must be addressed according to the complaint management clauses 10.2.3,10.2.4,10.2.5 and 10.2.6 of IATF 16949: 2016 standard.

        What info I have to collect to answer about a lifetime?

        Product lifetime information such as life, durability, replacement time, etc should come from the product design responsible. This information should come from the product technical drawings and/or technical specifications 

      • Adequacy under GDPR

        Yes, you can process data to a third country that is not considered adequate under GDPR. Article 46 GDPR allows Parties to transfer data with a legal and binding agreement adopting the Standard Contractual Clauses (SCC) as implemented by the EU Commission.These SCCs are requirements that Parties agree to implement voluntarly in order to provide adequate safeguards to the transfer of data. It concerns the protection of data subjects' rights, the security of transfers, and the processing of data accordingly with the EU GDPR provisions.

        Here you can find the template of Standard Contractual Clauses Annexes  (MS Word) as implemented by the EU Commission: https://info.advisera.com/eugdpracademy/free-download/standard-contractual-clauses-annexes

        Here you can find more information about data transfers.

        To have a deeper idea of the list of requirements of GDPR you can consider enrolling in our free online training EU GDPR Foundations Course: https://advisera.com/training/eu-gdpr-foundations-course//

      • Data Protection Officer

        Yes, you can appoint an internal Data Protection Officer (DPO) who should have knowledge in GDPR and data protection legislation. 

        Article 38 GDPR does not prescribe the position as internal or external, the choice is left up to the controller. It is important the person appointed has the independence from the board and the professional skills to perform tasks listed in Article 39 GDPR.Our course and the final exam can demonstrate that the appointed DPO has sufficient knowledge to perform the tasks.

        Here you can find more information on the role of DPO:

        To have a deeper idea of the list of requirements of GDPR and the role of DPO you can consider enrolling in our free online courses:

      • Management reviews (Option A)

        Morning Tracy, thank you very much.

      • Risk assessment

        General steps for risk assessment and treatment are:

        • Risk identification (i.e., identification of elements that compose the risk, and already implemented controls)
        • Risk analysis (i.e., the definition of risk value, considering any already implemented controls
        • Risk evaluation (i.e., comparing the risk value to risk acceptance criteria to decide if additional treatment is required)
        • Risk treatment (i.e., defining which treatment is to be applied, and its effect on the risk)

        Here is an example considering a scenario where a power generator is no longer needed, and possible power failures will be covered by UPS, and the use of the asset-threat-vulnerability approach:

        • Risk identification: assets would be any power dependable equipment (e.g., servers, desktops, routers, etc.), threat (power failure), vulnerability (lack of power generator), and implemented control (UPS)
        • Risk analysis: without any emergency power supply, your operations will run as long as the charges of your UPSs before the normal power supply is recovered, so the risk of operational disruption will increase with time (i.e., you have to consider how long your UPSs will last and how long it will be necessary to the normal power supply to be reestablished to value the risk).
        • Risk evaluation: considering your risk evaluation criteria you can decide how to treat (e.g., mitigate, transfer, accept, or avoid)
        • Risk treatment: for mitigation: you may decide to keep the power supply, for transfer you can decide to operate in a facility physically maintained by a third party, or you can do nothing and absorb the impact if the risk occurs.
          Please note that this analysis is valid only for this scenario. For example, if the asset to be removed is a notebook, you must take other considerations to take into account, like the information stored in the notebook.

        To see how documents for performing risk assessment and treatment compliant with ISO 27001 look like, please access the demo templates in this link: https://advisera.com/27001academy/iso-27001-22301-risk-assessment-toolkit/

        These materials will provide you afurther explanation about risk assessment and treatment:
        - The basics of risk assessment and treatment according to ISO 27001 [free webinar] https://advisera.com/27001academy/webinar/basics-risk-assessment-treatment-according-iso-27001-free-webinar-demand/
        - ISO 27001 risk assessment & treatment – 6 basic steps https://advisera.com/27001academy/knowledgebase/iso-27001-risk-assessment-treatment-6-basic-steps/

        These materials will also help you regarding risk assessment and treatment:
        - Diagram of ISO 27001:2013 Risk Assessment and Treatment process https://info.advisera.com/27001academy/free-download/diagram-of-iso-270012013-risk-assessment-and-treatment-process
        - Book ISO 27001 Risk Management in Plain English https://advisera.com/books/iso-27001-annex-controls-plain-english/
        - Free online training ISO 27001 Foundations Course https://advisera.com/training/iso-27001-foundations-course/

      • Risk assessment

        When you assess the impact and the likelihood of a set of asset-threat-vulnerability for which you already have implemented controls, you have to take into account the existing controls (because they decrease the probability of your risk). In such cases, you need to include in your assessment the information about the "existing controls" (e.g., you can use a plain description of the control, without referring to ISO 27001 or ISO 27002).

        For further information, see:
        - Why is residual risk so important? https://advisera.com/27001academy/knowledgebase/why-is-residual-risk-so-important/
        - Book ISO 27001 Risk Management in Plain English https://advisera.com/books/iso-27001-annex-controls-plain-english/
        - Free online training ISO 27001 Foundations Course https://advisera.com/training/iso-27001-foundations-course/

Page 242-vs-13485 of 1130 pages

Didn’t find an answer?

Start a new topic and get direct answers from the Expert Advice Community.

CREATE NEW TOPIC +