Start a new topic and get direct answers from the Expert Advice Community.
CREATE NEW TOPIC +Guest
I have no specific examples from the cement industry.
What I can do is to invite you to develop your presentation considering three stages:

Look into the past and report past performance (ISO 14001:2015 clause 9.3 – a) c) d) f))
Look into the context and report trends (ISO 14001:2015 clause 9.3 – b) e) g))
Look into the future and list the outputs, decisions and actions, that should come out the management review.
According to my experience, consider sending in advance the presentation to all attendees. Make the meeting more about decisions and actions than about presentation and analysis.
The following material will provide you more information about management review:
Article – The importance of management review in the ISO 14001:2015 process – https://advisera.com/14001academy/blog/2019/08/27/key-iso-14001-benefits-to-customers/nowledgebase/the
Free webinar on demand – Free webinar – How to perform management review according to ISO 14001:2015 – https://advisera.com/14001academy/webinar/how-to-perform-management-review-according-to-iso-14001-2015-free-webinar/
Enroll for free in this course – ISO 14001:2015 Foundations Course – https://advisera.com/training/iso-14001-internal-auditor-course/
Book – The ISO 14001:2015 Companion – https://advisera.com/books/the-iso-14001-2015-companion/
Considering ISO 22301 requirements, which are the same for other ISO management systems, such as ISO 9001 and ISO 14001, you must perform internal audits at planned intervals, but random verification can also be used if the organization considers this as a good approach for its context.
These articles will provide you further explanation about internal audit (they are focused on ISO 27001, but the general concept also applies to ISO 22301):
- How to prepare for an ISO 27001 internal audit https://advisera.com/27001academy/blog/2016/07/11/how-to-prepare-for-an-iso-27001-internal-audit/
- How to make an Internal Audit checklist for ISO 27001 / ISO 22301 https://advisera.com/27001academy/knowledgebase/how-to-make-an-internal-audit-checklist-for-iso-27001-iso-22301/
ISO 9001:2015 does not require a Table of Contents.
However, as soon as you consider a Table of Contents as part of your set of manufacturing controlled documents, that Table of Contents becomes a document requiring control.
The following material will provide you more information about document control:
New approach to document and record control in ISO 9001:2015 – https://advisera.com/9001academy/blog/2015/06/30/new-approach-to-document-and-record-control-in-iso-90012015/
– Enroll for free course – ISO 9001:2015 Foundations Course – https://advisera.com/training/iso-9001-foundations-course/
- Book – Managing ISO Documentation: A Plain English Guide – https://advisera.com/books/managing-iso-documentation-plain-english-guide/
1. What package should we buy, if only one of our customers is asking us to be certified in ISO 27000, because they have access to an IBM SaaS that we sell them
Answer: Considering your stated context, the proper toolkit would be the ISO 27001 Documentation Toolkit, which you can see a demo of its templates at this link: https://advisera.com/27001academy/iso-27001-documentation-toolkit/
Many of our clients for that toolkit are SaaS companies.
2. Once purchased, on how much time according to your experience, we can obtain certification for this purpose
The duration of implementation project varies according many variables (e.g., available resources, experience with standard's requirements, top management involvement, etc.), but for small and medium-size organizations the implementation generally varies from 3 to 12 months.
To get an insight about the time duration for you organization, please access our ISO 27001/ISO 22301 Implementation Duration Calculator at this link: https://advisera.com/27001academy/free-tools/free-calculator-duration-of-iso-27001-iso-22301-implementation/
This article will provide you further explanation about implementation process:
Hello, I would like to know the following: can you explain the obtaining of the values of the different criteria: Financial, regulatory, at. customer, through a formula.
This must be considered under context of ISO 22301
I'm assuming you are referring to valuation of these criteria in the Business Impact Analysis.
Considering that, there is no definitive formula to value them, because each organization context may consider different variables. For example:
- Financial: cost of raw materials + cost of final products + cost of equipment, etc.
- Regulatory: fines + lawyers cost + costs of court proceedings, etc.
- Customers: contractual fines + loss of revenue, etc.
For further information, please read:
- How to implement business impact analysis (B IA) according to ISO 22301 https://advisera.com/27001academy/knowledgebase/how-to-implement-business-impact-analysis-bia-according-to-iso-22301/
You can ask them their certificate or get a copy. Check the name of the certification body and verify if its name is in any list of an accreditation body recognized by the International Accreditation Forum (IAF). If that certification body is working with an accreditation body recognized by the IAF you can contact them,and confirm if their certificate is valid or not.
The following material will provide you more information about solving doubts around a certificate validity:
Thak you Rhand Leal, now,
How can I cross or related the assets identified in the SOA with the Risk Treatment Plan? The order in which I should write each activity in the plan is the order in which they are in the SOA? Should I just write the asset name or rather the activity name to be done to decrease the risk ? and specify what, who, when, how, timing, status, etc.
Los documentos que requiere la norma ISO 9001:2015 en la cláusula 4 son los siguientes:
La diferencia entre los documentos y los registros, es que los documentos necesitan ser revisados, e incluyen por ejemplo, procedimientos, instrucciones de trabajo, manuales, checklists, etc. Sin embargo, los registros muestran el resultado de algo que ya se ha realizado, y son por ejemplo actas de reunión, formularios de datos, evidencias de auditorías, etc.
Para más información sobre los documento requeridos por la cláusula 4 vea los siguientes materiales:
The atmosphere accumulates pollutants whenever the input rate is superior to the output rate.
The output rate is basically due to two reasons: chemical and biological. If you look into a carbon cycle diagram for example, you can see carbon removed from the atmosphere through photosynthesis (biological) and you can see carbon removed from the atmosphere through ocean uptake, a slow process that ends with the deposition of limestone on the ocean floor.
The following material will provide you more information about aspects and impacts:
After the initial two-stage certification audit, organizations have surveillance audits. Surveillance audits have a smaller scope and are more focused on record checking to confirm that the implementation is working.
Normally, a re-certification audit, the first audit after a full three-year certification cycle, means changing the audit team completely. So, a new audit team will look with new pairs of eyes into your management system. The audit scope will again include all parts of the QMS.
For organizations there is no need to prepare the recertification differently than for the surveillance audits. Be sure documents are updated, processes are implemented, and records generated and stored.
The following material will provide you more information about certification versus surveillance audits: