Search results

Guest

Guest

Create New Topic As guest or Sign in

HTML tags are not allowed

Assign topic to the user

  • Writing quality manual and nominating quality manager when we implement ISO 17025:2017

    Indeed, although ISO 17025:2017 does not specifically require an appointment of a Quality Manager, nor a documented Quality Manual; it does not imply you cannot do so. You can include a quality manual as part of your documented management system and you can nominate a quality manager.

    ISO 17025 specifies general requirements, to ensure competency. Your laboratory must establish a management system that suites your needs, to meet your objectives. In identifying suitable management, authorities and responsibilities, you can have one or more personnel performing the Quality Management functions. Likewise, when you establish processes and documents to meet ISO 17025 mandatory requirements, you could also include information in a quality manual, to describing the organization’s structure, the general requirements of impartiality and confidentiality and other processes that do not specifically require documented procedures. It is also a central place to reference mandatory documented procedures. A Quality Manual is included in the ISO 17025 toolkit. Have a look at the ISO 17025 document template: Quality Manual at https://advisera.com/17025academy/documentation/quality-manual/

    It is important to understand the intent behind the revision, to help you implement ISO 17025 effectively. Have a look at the article ISO/IEC 17025:2005 vs. ISO/IEC 17025:2017 revision: What has changed? at https://advisera.com/17025academy/blog/2019/11/13/iso-17025-2017-vs-iso-17025-2005-key-changes-infographic/

  • Minimum time frame to implement ISO 13485 to Stage 1

    The time necessary for the implementation of ISO 13485:2016 depends on the number of the employees, how many and how complex your processes are; and what your medical device is (is it low-risk medical device, do you have sterilization process, is it software). Usually, for the company with 10 employees, it is necessary some 2-3 months for companies, and for companies with up to 50 employees, it takes some 6-8 months. 

    Here you can find a Checklist of ISO 13485 implementation and certification steps:

    Although this article is written for ISO 27001, the content is universal, so maybe you will find it useful:

    • The documentation myth – Why the templates are not enough? https://advisera.com/27001academy/blog/2012/04/24/the-documentation-myth-why-the-templates-are-not-enough/

    • ISO 9001 vs ISO 22000

      I’m not an expert on ISO 22000 and Advisera does not provide services about ISO 22000. However, I invite you to check that both standards have a common structure (the so-called High Level Structure) and it is straightforward to integrate clauses 4, 5, 6, 7, 9 and 10.

      Major differences are around clause 8 in both standards.

      With ISO 9001:2015 you are working with:

      8.2 – handling customers’ orders
      8.3 – developing new products
      8.4 – purchasing materials, services and processes
      8.5 – manufacturing the products
      8.6 – controlling quality
      8.7 – treating non-conforming product
       

      With ISO 22000:2018 you are working with food safety:

      8.1 Operational planning and control
      8.2 Prerequisite programmes (PRPs)
      8.3 Traceability system
      8.4 Emergency preparedness and response
      8.5 Hazard control
      8.6 Updating the information specifying the PRPs and the hazard control plan
      8.7 Control of monitoring and measuring
      8.8 Verification related to PRPs and the hazard control plan
      8.9 Control of product and process
       

      Please check this article - Similarities and differences between ISO 9001 and ISO 22000 - https://advisera.com/9001academy/blog/2018/11/20/similarities-and-differences-between-iso-9001-and-iso-22000/

    • ISMS roles and responsibilities

      This is not sufficient, because not only the ISMS champions must know about their information security responsibilities, but also all personnel included in the ISMS scope, so they can know who to look for in case of a situation related to information security.

      In  this case, you must also consider:

      • Document information security roles and responsibilities in the policies and procedures used by the organization.
      • Provide awareness and training sessions for all personnel included in the ISMS scope.

      This article will provide you a further explanation about documenting roles and responsibilities:

      These materials will also help you regarding roles and responsibilities:

    • ISO 22301 gap analysis

      Please note that ISO 22031 does not require a gap analysis to be performed, and it is not recommended for smaller companies, because, in general, it is not worth the effort due to their size and complexity. As an alternative, you can use the internal audit checklist, located on folder 10 Internal Audit, to make a quick assessment of your situation.

    • Ecosystem degradation cause

      Environmental changes that cause ecosystem degradation are based on many factors including:

      • Urbanization
      • Population growth
      • Economic growth
      • Intensification of agriculture
      • Increase in energy use
      • Increase in transportation


      You can find more information about ISO 14001 below:

    • Internet Access

      Although ISO 27001 does not prescribe access to the Internet only through the organization as mandatory, what happens in real life is that this is more a common sense for business practice, as survival and competitive question than a standard's requirement (most of the businesses and their relations go through the Internet).

      Considering that, when organizations resources, like email services, are available through direct access to the Internet (e.g., to allow remote work), a common practice is the usage of access through Virtual Private Networks (VPNs), where the organizations implement controls such as protected communication, and access control to limit external access to authorized users, only to needed information, and also can monitor activities and information flow.

      A third important point is awareness activities, so employees can understand the importance to access the Internet only through the organization, and the consequences on direct access.

      This article will provide you a further explanation about network controls:

      This material will provide you further information about employee awareness:

    • Procedure for clinical trials

      Yes, you are right. Unfortunately, in our toolkit there is no procedure for clinical trials because, in MDR 2017/745, requirements for documents for clinical investigation are very detailed described in Article 63, Article 72, and in Annex XV (Chapter II and III). Further on, clinical trials must be performed according to harmonized standard ISO 14155:2011 Clinical investigation of medical devices for human subjects — Good clinical practice. In most cases, clinical trials are conducted by specialized companies. 

      Which documents are necessary for medical devices you can find in the following material: 

Page 384-vs-13485 of 1127 pages

Didn’t find an answer?

Start a new topic and get direct answers from the Expert Advice Community.

CREATE NEW TOPIC +