Start a new topic and get direct answers from the Expert Advice Community.
CREATE NEW TOPIC +Guest
Internal and external issues are relevant topics that can influence the future of an organization. For example, governments can issue legislation that will affect the activity of a recycling company. Socials trends can influence how consumers and households react to recycling practices. About internal issues you can have, for example, experienced workforce, inflexible machinery or lack of capacity.
You can find more examples in this free webinar on demand - ISO 9001:2015 clause 4 - Context of the organization, interested parties, and scope - https://advisera.com/9001academy/webinar/iso-90012015-clause-4-context-of-the-organization-interested-parties-and-scope-free-webinar-on-demand/ (it is about ISO 9001 but I think it may be useful)
The following material will provide you more information:
Providing a safety culture is critical to implementing ISO 45001, and the crucial step is in the example of top management. There is a saying that “management leads whether they mean to or not”, and this is equally important to a safety culture. If there is a rule that safety glasses need to be worn, but the president of the company never wears them in the area, then this tells people that the safety rules are not important; if top management tries to say safety is important in words, but not in actions, they the culture of safety will not happen. A culture of safety will only occur when the rules are known, understood, and equally applied to everyone; then you can work on maintaining and improving safety.
You can find out more about convincing top management about the OHSMS that are still applicable to ISO 45001 in the article: 4 crucial techniques for convincing your top management to implement OHSAS 18001, https://advisera.com/45001academy/blog/2017/08/30/4-crucial-techniques-for-convincing-your-top-management-to-implement-ohsas-18001/
Considering ISO 13485:2016, in requirement 4.2.5 Control of records is stated that organization will keep records for at least the lifetime of the medical device, or as specified by applicable regulatory requirements, but not less than two years. It means that if a lifetime of your medical device is six months or one year, you need to keep records for at least two years.
For more information, please read the following article:
You can also check out our book for more information:
Data Transfer Agreement template (Referenced in Cross Border Transfer Procedure):
DTA for Controller -> Controller
DTA for Controller -> Processor
When to use which one?
OHSAS is the acronym for Occupational Health and Safety Assessment Series. This is from a series of standards that were issued by the British Standards Institute (BSI) in 1999, which included 2 standards; OHSAS 18001:1999 & OHSAS 18002:1999. On the other hand, OHSMS is the acronym for Occupational Health & Safety Management System. The OHSMS is all of the rules, policies, processes and procedures that an organization puts in place to continually improve OH&S performance, fulfil legal and other OH&S requirements and achieve OH&S objectives for the company. While OHSAS 18001:2007 previously provided the requirements for an OHSMS, now that ISO 45001:2018 has been released as the internationally recognized requirements for an OHSMS, it will replace OHSAS 18001:2007.
You can find out more in the article: OHSAS vs. OHSMS: What is the difference, https://advisera.com/45001academy/blog/2019/10/16/ohsas-vs-ohsms-what-is-the-difference/
Thanks for your answer!
What formats should I use to comply with the clauses and controls of ISO27001. (For example, registration of the scope of the ISMS, SWOT - to know where the company is headed and determine its objectives and align them with the ISMS)
ISO 27001does not prescribe the format to be used to elaborate documents, so organizations are free to develop them as better fits their needs, provided the clauses and controls statements are fulfilled.
To see how documents compliant with ISO 27001 looks like, I suggest you take a look at the free demo of our ISO 27001 Documentation Toolkit at this link: https://advisera.com/27001academy/iso-27001-documentation-toolkit/
These articles will provide you a further explanation about developing documents:
These materials will also help you regarding developing documents:
Please note that "risk transfer" is the general approach to treat risk, and according to ISO 27001 you need to specify which controls you will apply to implement this option (e.g. controls from section A.15 for suppliers and control A.13.2.2 Agreements on information transfer for third parties in general).
These articles will provide you a further explanation about risk treatment:
This material will also help you regarding risk treatment:
Up to this moment, ISO 27701 is not mandatory, and as with any new standard, it remains to be seen if it will become popular, i.e. useful.
This article will provide you a further explanation about ISO 27701:
As per IATF 16949: 2016 standard; all system internal auditors must competent in the following.
If your current internal auditor is trained, competent, and your automotive customers do not have a special requirement in this regard; your internal auditor may provide this training to other employees.