Start a new topic and get direct answers from the Expert Advice Community.
CREATE NEW TOPIC +Guest
If I understand correctly, your question is for medical device software. For manufactures of medical device software, necessary is that ISO 13485:2016 must be implemented. The next important requirement is a validation of that software that needs to be in compliance with ISO IEC 62304:2006 Medical device software — Software life cycle processes.
If you do not own the product and are not responsible for placing the software on the market, you only have to have implemented ISO 13485:2016. Product owners also need to have implemented ISO 134895:2016, but also the manufacturer is responsible for preparing the Technical documentation in accordance with Medical device regulation (2017/745). Each medical device must be classified according to the rules stated in MDR Annex 8 – Classification rules - https://advisera.com/13485academy/mdr/classification-rules/.
Medical devices can be classified into the following 6 classes: Class I, Is (sterilized medical devices), Ir (reusable medical devices), IIa, IIb, and class III. Class, I medical devices can be placed on the market without Notify body, while other classes require to Notify body.
After preparing the Technical file, the manufacturer is responsible for certified medical device software with Notify body for class Is, Ir, IIa, IIb, and class III.
More information you can find on the following link:
For any other particular question, do not hesitate to contact me.
You asked About
1) techniques of extracting objective evidence in auditing
Objective evidence is obtained by starting with a well define purpose and scope for the specific audit. For each activity you should specify the audit criteria, meaning what the requirements are that you will compare your audit evidence to, in order to determine if audit criteria are met or not (finding of compliance or noncompliance). The techniques to obtain objective evidence involve making factual observations during a witnessing of a process; interviewing personnel to obtain statements; as well as document and record review by cross checking that stipulated data and information is available and controlled .
You also asked
2) how to improve on my auditing competency
You can improve you auditing skills and competency by the following means
You also asked
3) how do you relate ISO 9001 with other quality ISO like ISO 15189:2012?
The ISO 9001 principles (for example evidence based decision making, process approach) are incorporated into ISO 15189 and many other standards (including ISO 17025). Further more the management requirements such as corrective actions, are part of both standards.
You also asked
Do I need ISO 9001 to implement ISO 15189:2012?
No you do not, however a knowledge of the standard would be useful.
For more information on Auditing, see the Expert Advice Q&A to Auditing impartiality https://community.advisera.com/topic/auditing-impartiality/
The ISO 17025 toolkit at https://advisera.com/17025academy/iso-17025-documentation-toolkit/, covers the requirements for ISO 17025.
The separate ISO 17025 document templates and links to their related documents are available as follows:
Internal Audit Procedure is available at https://advisera.com/17025academy/documentation/internal-audit-procedure/
Addressing Risks and Opportunities Procedure is available at at https://advisera.com/17025academy/documentation/addressing-risks-and-opportunities-procedure/
ISO 17025:2017 addresses the topic of scope of accreditation in clause 5.3, Structural Requirements. A laboratory is required to have a defined and documented scope for ISO 17025 accredited laboratory activities, meaning those that they perform themselves on an ongoing basis (do not subcontract) and which conform to ISO 17025:2017.7
The ISO 17025 toolkit at https://advisera.com/17025academy/iso-17025-documentation-toolkit/, covers this requirement; specifically through the Quality Manual https://advisera.com/17025academy/documentation/quality-manual/
For such a small company you do not need a full-time ISMS manager (needed activities will take him/her perhaps 20% of the time), so this role can be given as an additional function to an already exiting role in your organization, probably someone from the top management, or someone which answer directly to them.
Since related activities must be performed at certain periodicity, you should avoid designate them on an ad-hoc basis, because of risk to lose information when the activities are transferred from one person to another.
These articles will provide you a further explanation about the IS manager role:
There is no mandatory requirement for the existence of a QMS manager.
However, during the implementation of the QMS it is important to have a Project Manager to conduct the project. If it is a full-time job or not depends on the investment in training and the ability to develop teamwork. Theoretically, it is not needed to have a QMS manager developing a Quality Control Plan if you have a team in your company that assumes the job: for example the warehouse responsible, the shift managers and one or two operators can design, request approval, train and implement the use of that Quality Control Plan.
You can find more information below:
I do not know if I’m understanding your question. So, what can be the needs and expectations for a Business Development Department of an EPC company. There is no technical answer, just a management answer according to strategic orientation and target customers. It can be about the volume of business for a certain period of time, it can be about the margins and/or types of demand. To whom thus the Business Development Department answers? What is success for that internal customer? That may be what will be nice set of need and expectations for the department.
The following material will provide you more information:
There is no general rule that one must follow. What we must bear in our mind is the need to clearly identify documents and allow an easy way of checking it they are updated. When I use annexes I call them annexes 1 or 2 or 3 of the document X, I don’t follow the same format, actually I use annexes to be free of using the most useful format for each situation. And I use a separate way of identifying versions to allow changing the main document without changing the annex and vice versa.
You can find more information about documents and records below:
Para implementar la norma ISO 9001 e ISO 14001 de forma integrada puede ayudarse de los siguientes materiales:
- How to integrate ISO 14001 and ISO 9001: https://advisera.com/14001academy/blog/2019/08/27/key-iso-14001-benefits-to-customers/nowledgebase/how-to-integrate-iso-14001-and-iso-9001/
- Cuadro comparativo - ISO 14001:2015 vs ISO 9001:2015 Matrix: https://info.advisera.com/14001academy/free-download/iso-4001-2015-vs-iso-9001-2015-matrix
- Webinar gratuito - Cómo integrar ISO 9001:2015 e ISO 14001:2015: https://advisera.com/9001academy/es/webinar/how-to-integrate-iso-90012015-and-iso-140012015-free-webinar-on-demand/
Además estos materiales también pueder ayudarle a entender los requisitos de las diferentes normas:
- Curso online gratuito - Curso de Fundamentos de la Norma ISO 9001:2015: https://advisera.com/es/formacion/curso-fundamentos-iso-9001/
- Curso online gratuito - Curso de Fundamentos de la Norma ISO 14001:2015: https://advisera.com/training/es/course/curso-fundamentos-iso-14001/
- Libro - Discover ISO 9001:2015 through practical examples: https://advisera.com/books/discover-iso-9001-2015-through-practical-examples/
- Libro - the ISO 14001:2015 companion: https://advisera.com/books/the-iso-14001-2015-companion/
Please note that usually objectives are set at two levels:
Regarding the Plan to achieve the objectives, you need the Risk Treatment plan, located on folder 07 Implementation Plan
For further information, see: