Start a new topic and get direct answers from the Expert Advice Community.
CREATE NEW TOPIC +Guest
Conformio platform has basic Document Management System features that fulfill ISO 27001 document management requirements, so you can keep all your ISO 27001 related documents in Conformio.
This article will provide you a further explanation about the document management:
ISO 27001 does not prescribe roles to be defined, so organizations are free to define them according to their needs.
Regarding responsibilities, ISO 27001 only requires the definitions of these responsibilities:
Other responsibilities the organizations can define according to their needs.
These articles will provide you a further explanation about roles and responsibilities:
These materials will also help you regarding roles and responsibilities:
Try small blocks of time with very specific objectives linked to business results or business benefits.
Use different approaches: classroom training; games that people play and simultaneously test topics related with ISO 9001 – ISO 9001 comes as answer to a problem and not as something pushed; on-job training where you start with what people do, with the purpose of what they do, with what can go wrong and how ISO 9001 can help minimize wrongs and increase rights.
The following material will provide you more information:
Thank you a lot for this answer. The links are also very useful for implementation.
1. What is the requirement for laboratory recognition scheme in BIS?
The National Standards Body of India, the Bureau of Indian Standards (BIS), specifies the requirements for their laboratory recognition scheme on their website, available at https://bis.gov.in/wp-content/uploads/2020/06/LRS_23062020.pdf. This scheme recognizes laboratories in India or outside India as suitable for carrying out testing activities assign to it, performed on behalf of Bureau. This includes accreditation to ISO 17025:2017, along with other statutory provisions. For example, there are additional prescriptive requirements for impartiality, in addition to ISO 17025 where the laboratory has to submit a signed undertaking and a code of ethics a prescribed format that they supply.
2. Which way it has to be aligned with BIS?"
The national Indian standard (BIS) IS/ISO/IEC 17025:2017 General Requirements for the Competence of Testing and Calibration Laboratories is identical to ISO/IEC 17025:2017. It is a mandatory requirement of the BIS laboratory recognition scheme that a laboratory is accredited to ISO 17025:2017. All the test parameters of interest, prescribed in National Indian Standards must be included in the ISO 17025 scope of accreditation.
For further information on ISO 17025, these links may be of interest:
What is correlation about organization context & needs and expectations with environmental aspect?
Answer:
For example, an organization has determined these environmental aspects:
When that organization determined its internal issues registered this one:
When that organization determined its interested parties and their needs and expectations registered these two:
Can you see a risk emerging from that internal issue here? Can you see how the interested parties make that risk critical? And all that related with environmental aspects.
It is mandatory to synchronize? If yes, how to synchronize it?
Answer:
No, it is not mandatory to synchronize, only if you found relevant interactions that can affect your relationship with the environment in significant ways. I hope I demonstrated above how to do it.
And how about risk & opportunity? What is difference with environmental aspect?
I hope the example and figure above showed the difference. Environmental aspects is about how your organization interacts with the environment. Risks and opportunities are about a potential deviation from the expected due to the presence of uncertainty.
Does a risk and opportunity have to assessed (quantitative)?
Risks and opportunities should be evaluated but it is not mandatory to do it through a quantitative scale
Please check this information below with more detailed answers:
As far as I understand your question, it is preferable to keep an aspect and impact register per individual site. ISO 14001:2015 definition of environmental aspect states, “element of an organization’s activities or products” and when organizations want to evaluate the significance of a particular aspect and impact it is important to be aware of the specific situation. Different individual sites may have the same environmental aspects, but their significance can be very different.
Please check this information below with more detailed answers:
If I want to implement ISO 14001, how many % I need to have in legal requirements?
Answer:
Getting certification against ISO 14001:2015 requires complying with all applicable legal requirements?
Every single environmental aspect shall determine if can control or can influence?
Answer:
Yes, for every single environmental aspect an organization must determine if can control or influence.
Please check this information below with more detailed answers:
Yes, your company can apply ISO 9001 and be certified. Some of the benefits that normally accrue from certification and that are usually mentioned by organizations are: improvement of credibility and image; improvement of customer satisfaction and reducing costs due to unwanted variability.
The following material will provide you more information:
Determining environmental aspects is determining how an organization interacts with the environment. For example:
Determining risks and opportunities of an organization, according to ISO 14001:2015, is based on its environmental aspects, compliance obligations, and context and interested parties.
For example, concerning environmental aspects we can have:
Since organizations have to consider the lifecycle of its products and services, do not forget to consider risks and opportunities around your products and services during use or final disposal.
For example, concerning compliance obligations, and context and interested parties we can have for example, the above organization can realize that neighbors (an interested party) are pressuring local authorities to not allow its expansion (an external issue) due to non-compliance with wastewater discharging legislation (compliance obligations) translated into river pollution.
Please check risk definition (3.2.10) on ISO 14001:2015 (effect of uncertainty). With environmental aspects and impacts we are considering normal, expected situations, like startup and closing down operations, but also abnormal and emergency situations. Whenever there is uncertainty there is risk or opportunities, there is a potential deviation from the expected.
About determining risks based on environmental aspects and compliance obligations I see that different organizations follow different approaches:
1. There are organizations that determine their environmental aspects and use a risk and opportunities assessment to determine its significant environmental aspects. (Please see the end of the second paragraph of Annex A.6.1.1 of ISO 14001:2015)
2. There are organizations that determine their environmental aspects evaluate them and determine the significant ones and use a risk and opportunities assessment to determine which ones need an action plan, and which ones need only to be monitored.
3. There are organizations that only apply the risk-based approach to the context part. In a certain way they are following the same approach as 1 without explicitly mentioning it.
Please check this information below with more detailed answers: