Start a new topic and get direct answers from the Expert Advice Community.
CREATE NEW TOPIC +Guest
As for any management system activity, personnel must have suitable skills, adequate training and evidence of competency to perform a task.
Furthermore for internal auditing the auditors must be impartial and independent, meaning they cannot audit their own work and it is typically ineffective and risky if they audit processes their colleagues are responsible for. Internal auditors need not be certified auditors, but formal training is recommended, whether in house or through a service provider on site or remotely. Either way, management need to deem auditors suitable and competent through observation and against criteria such as professional approach, interview techniques, and outcome of an audit they performed under supervision. They need to have a good understanding of ISO 17025, risk-based thinking, the purpose of the quality management system and quality assurance activities. A technical auditor must, in addition, have a good technical working knowledge to audit the particular activity, including how to assess equipment, method validation, measurement uncertainty, calibration and metrological traceability needs.
The following ISO 17025 document templates may be of interest
Competence, Training and Awareness Procedure at https://advisera.com/17025academy/documentation/competence-training-and-awareness-procedure/
Internal Audit Procedure at https://advisera.com/17025academy/documentation/internal-audit-procedure/
Competence Approval and Authorization Record at https://advisera.com/17025academy/documentation/competence-approval-and-authorization-record/
Prefix ISO means that it is an international standard published by the ISO organization. When an ISO is adopted by the European Union, for example, it becomes an EN-ISO.
There is no difference in the requirements between those two standards.
1. As we are a low-risk class I one medical device manufacturer, if we want to declare our conformity according to MDR do we also need to comply with all the applicable harmonized standards like (ISO 13485, ISO 14971, IEC 60601-1-2) ? Or are these standards optional for class I?
2. Do we need ISO 13485 or other certification from an accredited body?
ISO 9001: 2015 did not prohibit the quality manual, what came was to remove its mandatory character.
Why did this happen?
Because of an effort to reduce the image of bureaucratization associated with ISO 9001: 2015 and, perhaps because many quality manuals have no value, they are limited to a template with blank spaces filled with the name of the organization. Personally, as an auditor, I am tired of seeing manuals that in a way summarize ISO 9001.
The following material will provide you information about the quality manual:
Some of the advantages can be:
You can find more information below:
Regarding data sharing, I suggest you take a look at these ISO standards:
An Information Asset Register is mandatory for ISO 27001 certification only if you have relevant risks or legal requirements (e.g., laws, contracts, regulations, etc.) demanding the implementation of control A.8.1.1 Inventory of assets.
In case such situations do not occur, then the Information Asset Register is not required for ISO 27001 certification.
This article will provide you a further explanation about the asset register:
If you check this article - List of mandatory documents required by ISO 9001:2015 - https://advisera.com/9001academy/knowledgebase/list-of-mandatory-documents-required-by-iso-90012015/ - you can see that the only mandatory records required by ISO 9001:2015 are evidence that the audit program is being implemented along with the audit results. As audit results, you can have audit reports, evidence of corrections, or corrective actions taken.
You can find more information in the following links: