Start a new topic and get direct answers from the Expert Advice Community.
CREATE NEW TOPIC +Guest
First, ISO 9001:2015 does not make mandatory having a quality manual. However, keeping a quality manual can be useful as a collection of high level documents that present and explain how the quality system works and what are its priorities – Please check this article - The future of the Quality Manual in ISO 9001:2015 - https://advisera.com/9001academy/knowledgebase/the-future-of-the-quality-manual-in-iso-90012015/
Second, quality manual is not a quality system procedure – Please check this article about quality system documentation structure - How to structure quality management system documentation - https://advisera.com/9001academy/knowledgebase/how-to-structure-quality-management-system-documentation/
Third, there is no mandatory structure for a quality system procedure, you may use a flow chart.
Since 2012 ISO management systems share many requirements (e.g., documents and records control, internal audit, management review, etc.), so the individual documents for each system still area applicable, and they can be combined in single documents. For documents covering specifics of each standard (e.g., information security risk assessment and treatment, product planning), it is still better to keep them separated
This article will provide you a further explanation about integrated ISO systems:
This material can also help you:
With the AWS ISO 27001 certification, AWS complies with a broad, comprehensive security standard and follows best practices in maintaining a secure environment. ... AWS reports, certifications and third party attestations are discussed in more detail later in this document.
There is not a universal answer. Different organizations choose different certification bodies based on issues like market preferences; client’s preferences and sector experience. You can find a comprehensive analysis in the following articles - How should you pick an ISO 9001 certification body? - https://advisera.com/blog/2021/01/11/how-to-choose-an-iso-certification-body/ and - How to choose a certification body - https://advisera.com/blog/2021/01/11/how-to-choose-an-iso-certification-body/
To improve your knowledge about putting ISO27001 in practice I suggest you read our blog posts and papers because most of them include real examples on how to fulfill requirements of the standard or apply controls. A good general guide is these free download:
Besides the explanation in the papers themselves, they include links to detailed articles.
Regarding your example, please note that the Statement of Applicability is part of the risk management process required by ISO 27001, and it is created after risk analysis and risk treatment. The correct sequence of your example is:
These articles will provide you a further explanation about risk management according to ISO 27001 and implementation steps:
These materials will also help you regarding ISO 27001:
Perhaps the approach represented in this picture can help you:
Think about the not-adherence to the procedure as a rationale decision. Surprised?
After listening to their side present your side not as imposed rules but as a need to minimize business pain and increase success rate:
You can find more information in the following links:
First, you need to define what is the classification of your product. Then you need to make technical documentation for the medical device requested by MDR 2017/745, and documentation for the quality management system, which is mostly done by ISO 13485:2016.
This documentation you can do by yourself, hiring a consultant, or by buying a documentation toolkit. Buying a documentation toolkit is the fastest way because there you have all the documents requested by the standard prepared and you only need to adjust it to your company, product, and processes.
For more information, please see MDR Annex VIII – Classification rules: https://advisera.com/13485academy/mdr/classification-rules/
What is the content of the ISO 13485:2016 & MDR toolkit you can find on the following link: https://advisera.com/13485academy/iso-13485-eu-mdr-documentation-toolkit/
After you prepare all necessary documentation, you need to find a certification body for the certification according to the ISO 13485:2016. If your medical device is Class I, then it does not need to be certified by a Notified body. Class I medical devices need to be registered in the local agency for medical devices. If your medical device is a higher class (Is, Im, IIa, or Iib, III) than the certification process under the Notified body is required.
For more information about the certification process, please see the following links:
For the decision are all of these standards applicable to your specific type of ventilators, I do not have enough data. Are there some other standards that are also applicable, the manufacturer must decide.
For more details, please see:
For more information on determining regulatory requirements according to ISO 13485:2016, see the following article:
ISO 9001:2015 have generic requirements and is intended to be applicable to any organization, regardless of its type or size, or the products and services it provides.
ISO 16949 was developed for the Automotive industry, and is based on ISO 9001, with several additional requirements to satisfy Automotive Industry Quality Management System requirements.
You can find more information in the following links:
Start with a self-assessment compliance checklist to list the initial gaps between ISO 14001:2015 requirements and your organization’s current environmental practices and performance. As long as you have top management support, any sound environmental management system starts with a clear identification of environmental aspects and impacts and its evaluation, and with an identification of any compliance obligations. Then, you have to plan your implementation project about how to improve and control environmental aspects situations and meet your environmental objectives aligned with an environmental policy.
Please check this information below with more detailed answers: