Answer:
Quality Control results allow verification of Quality Assurance effectiveness. Independently of your operation size, your company should plan the required Quality Control since raw materials reception, production and final product. What to control, by whom, with what frequency, with what specifications, and with which monitoring resources. Required means required by your company’s experience; or by clients; or by standards; or by regulation; or by competition performance.
Quality Assurance and Quality control are interrelated. Quality Assurance is about how a process is performed or how a product is made, Quality Control is about the inspection aspect.
Answer: ISO 27001 does not prescribe who must be responsible for internal audit, so considering the size of the organization, the CEO can be the owner of internal audit process.
2. Can intern perform internal audit in that case who will become owner of internal audit?
Answer: The main criteria to perform internal audit is competence, which can be evidenced by means of knowledge (e.g., certificates), education (e.g., training) or experience (e.g., records of previous performed audits), and impartiality (an auditor cannot audit his own work). If you can demonstrate that the intern has the necessary competence, and he does not audit his own work, he can perform internal audit. Regarding the ownership of the internal audit audit process, in this case, considering the person is an intern, you should consider a full time employee to be the owner (including the CEO as stated in the first answer).
Your understanding is correct. The "deadline"column refers to the date by which your organization will have to be compliant with the identified requirement (in your example, the date by which your organization will have to be compliant with requirements related to GDPR).
Supporting ISO 27001 certification
Answer:
To support an ISO 27001 implementation you should consider these certifications:
- ISO 27001 Lead Implementer – this certification recognizes people who have competency on the ISO 27001 implementation process.
- ISO 27001 Internal Auditor – this certification recognizes people who have competency on auditing an ISMS against ISO 27001 requirements, thus providing more confidence to an organization for being certified.
- ISO 27001 Lead Auditor – this certification recognizes people who have competency on auditing an ISMS against ISO 27001 requirements, and want to become certification auditors (work for certification bodies)
For ISO 27001 there is no such role as "implementer auditor".
So, considering your customer needs, you should consider the ISO 27001 Lead Implementer course, which will provide you more information about the whole implementation process.
Answer:
The ISO 45001:2018 requirements do not dictate how you will file documentation; this is something that you decide for yourself to best meet the needs of your company. You are not required to match your documentation formatting or numbering to match the standard, and there is nothing saying how you will identify or format your filing system. You do not even need to change from what you are doing already. The important thing is to make sure that you file everything that is needed in a manner that is best for your company to use and improve. The OHSMS is there for your company to benefit from, so organize it in the manner that is best for you.
For a better understanding of the transition process, see the whitepaper: Twelve-step transition process from OHSAS 18001 to ISO 45001, https://info.advisera.com/45001academy/free-download/twelve-step-transition-process-from-ohsas-18001-to-iso-45001
ISO 45001: SWOT for risks and opportunities
Answer:
A sample SWOT analysis is difficult because this tool is very specific to the organization. The strengths, weaknesses, opportunities and threats change form company to company and industry to industry. Even the format of this tool is not common since it can be a table, or even just a listing for the 4 sections. It is also important to remember that the ISO 45001 standard does not require a SWOT analysis, just an assessment of risks and opportunities. This is only one tool to identify the risks and opportunities for your OHSMS.
So, while you need to decide the information for each section of the analysis for your organization, some examples could include:
Strengths: You have a highly engaged workforce focused on OH&S
Weaknesses: You have a lot of accidents/incidents which you need to work to preventing.
Opportunities: You have a supplier that has developed a new chemical which is less hazardou s, and could be used in your process.
Threats: A supplier is discontinuing a chemical you need, and the easy replacement is more hazardous.
Answer:
If an organization publishes a performance spec for a product it must validate its ability to comply with it. Check ISO 9001:2015 clauses 8.3.3, 8.3.5 and 8.6.
In situations where you cannot change service conditions presented by the provider you should evaluate if your organization can accept the risks not properly covered by the provided service agreement,and if there are alternative providers you can consider.