Do I need to be certified, in some way, to help them design and implement a Quality management policy that will eventually be audited by an ISO auditor?”
Answer:
No, you do not need to be certified in any way. As long as you have project management skills, as long as you have communication skills and as long as you know the management system standard.
Answer:
When implementing a QMS I see it as a project with two work fronts A and B.
A is about modeling how the organization works based on what is called the process approach. Describing an organization as a set of interacting projects.
See this generic example:
Then, for each process look for what can go wrong and should be improved, look for opportunities to take advantage, and see if ISO 9001:2015 requirements are already being met. Describe those processes in order to standardize your work.
B is about where is the organization going to. It is about strategic orientation, objectives, and plans to meet them.
2. Is it beneficial that we already have SOP in place?
Answer: It is very beneficial. That means that there is a culture of organizing the work, there is already experience of having internal standards.
3. As a construction company, what part of physical construction work needs to be outlined and documented within the QMS?
Answer: One of the first activities in B, mentioned above, is defining the QMS scope. Your organization can do a lot of construction work and define that will be only about bridge construction, for example.
4. How is remove and replace construction work defined? Product or service?
Answer: Trust me that is not important. For example, there is a marketing approach called service-dominant logic that defends that everything is the service. When a customer contracts your organization they do not care about construction. They want the outcome of your organization's work
5. How do most construction companies define their organizations?
Answer: List a number of construction companies that you know and are certified and search the internet for their certificate and check what is their scope.
Does the medicinal product licence holder need to comply with ISO 13485 ?
Answer:
As a product license holder (with no manufacturing responsibilities including primary assembly of products), you are not required to comply with ISO 13485 however your contract manufacturer has to comply with ISO 13485.
Diagram of ISO 27001 Risk Assessment and Treatment Process
Answer:
This diagram was created as a visual practical example on how to perform risk assessment and treatment considering the asset-threat-vulnerability risk assessment approach, so unfortunately there are not other examples available
Thank you very much Carlos for your time and helpfull answers.
Articles and documents update
Answer:
Toolkit documents are updated more often than articles, because while articles aim to provide general examples on relevant topics of ISO 27001 and other standards covered by Advisera, documents must provide deeper information that must be compliant with standard's requirements.
Inputs/Outputs in a process
Answer:
Every organization consists of a set of interacting processes. Each process includes a series of activities that utilize certain resources transforming the inputs into outputs:
- Inputs are the resources used or needed in the execution of a process or process step. They can be information, raw materials, ect.
- Outputs are the results of a process or process step.
When determining the inputs and outputs of each process, you don´t need to get into much detail, since identifying each step of every process could be a task with no end. Your company just need to understand how the transformation is carried out through a process to create the product or service offered by the organization.
There are not specific requirements in ISO 9001:2015 for appointing a project manager in an organization. The company just need to make sure that the person hired is competent to perform the tasks related to the position.
What it is a requirement in the standard is having job descriptions, which specify daily tasks and objectives of a role. Basically this job description organize and describe the responsibilities and authorities of each role and states the external qualification (e.g. engineer, architect, ect.) and internal qualification (e.g. training on a certain work procedure) needed.
Answer:
When considering how to evaluate the overall environmental performance of a company I consider two criteria:
Alignment with the strategic orientation; and
Consistency with the results of the environmental assessment.
Considering the strategic orientation - for example:
if a company competes based on cost, I want to measure indicators that assess efficiency, reduction of wastes, reduction of unitary consumptions;
if a company competes based on service and interaction, I want to measure indicators that assess the progress of partnerships like shared resources, recycling and reusing;
if a company competes based on innovation, I want to measure the relationship of innovation with a lower environmental footprint.
Considering the results of the environmental assessment, I want to measure the progress of the interaction of the company with the environment. That is done through measuring indicators related with significant environmental impacts like: waste amount; quality and quantity of wastewater; unitary consumption of raw materials, water and energy, quality of air emissions, number of accidents or incidents.
2. What are the waste management requirements for ISO 14000?
Answer:
About waste management requirements of ISO 14001 I can list:
comply with law and regulations by working with legal waste operators;
comply with law and regulations in segregating, labeling, storing and transporting wastes;
prepare for emergencies, train people to handle wastes;
if it is a significant environmental aspect work to reduce waste generation, and or promote waste reuse or recycling
keep records.
Answer:
ISO 14001 does not set any retention time. I use two criteria to establish retention times:
Follow the retention time defined by law or regulations when that is the case;
Follow a retention time of 4 years to ensure that all records from one certification cycle are kept during the cycle.