Search results

Guest

Guest

Create New Topic As guest or Sign in

HTML tags are not allowed

Assign topic to the user

  • External audit duration and indicators


    Answer:
    Let us start by the external auditing. I believe you are speaking about “IAF Mandatory Document for Duration of QMS and EMS Audits”. When you look into an organization you ask how many persons effectively work there. The effective number of personnel is used as a basis for the calculation of audit duration. What does “effective person” means? According to the IAF document, “The effective number of personnel consists of all full-time personnel involved within the scope of certification including those working on each shift. Non- permanent (seasonal, temporary, sub-contractors and contracted personnel) and part time personnel who will be present at the time of the audit shall be included in this number.” That means if a hotel is audited during the high season will have more workers and so, the certification audit will take more time. Based on the number of effective persons working in the organization, table from Annex B of the IAF document relates Effective Number of Personnel, Complexity and Audit Duration. For example, an organization with 40 effective persons and medium complexity to audit will take 5.5 audit days. If you have 2 auditors that will take for example an auditor 3.5 days and another auditor 2 days.

    About measurement and monitoring, consider indicators related with your environmental management system objectives, with your relevant interested parties perceptions, and your environmental performance.

    The following material will provide you information about monitoring and measurent:

    - ISO 14001- How to Use Good Environmental Objectives - https://advisera.com/14001academy/blog/2019/08/27/key-iso-14001-benefits-to-customers/nowledgebase/how-to-use-good-environmental-objectives/
    - free online training ISO 14001:2015 Foundations Course - https://advisera.com/training/iso-14001-internal-auditor-course/
    - book - THE ISO 14001:2015 COMPANION – A A Straightforward Guide to Implementing an EMS in a Small Business - https://advisera.com/books/the-iso-14001-2015-companion/
  • Benefits of certifying a quality management system


    Answer: Implementing a quality management system and certification is not mandatory, there is no universal law requiring that.
    However, certain important customers in several economic sectors require that their suppliers get certification. Recently, I learned with a customer that they want to get certification in order to be able to sell to some countries with lower customs duties. For example, in order to sell some construction materials in Europe companies must have products with CE marking and that requires the implementation of some parts of a quality management system.

    2. Which one is more important?

    Answer:
    The answer depends upon each particular situation. If you have customers that demand it, certification is very important. I do not feel comfortable to say that one is more important than another because obtaining the certification implies at the outset to have the quality management system implemented.

    3. What's the importance of the ISO certificate if the standards are implemented/complied with?

    Answer:
    If your organization has a quality management system implemented, getting the certification can be useful in terms of credibility and image and that can be translated in terms of more customers and more opportunities to bid.

    The following material will provide you with information about selling the benefits of having a quality management system:
    - ISO 9001 – Six Key Benefits of ISO 9001 Implementation - https://advisera.com/9001academy/knowledgebase/six-key-benefits-of-iso-9001-implementation/
    - free online training ISO 9001:2015 Foundations Course - https://advisera.com/training/iso-9001-foundations-course/
    - book - Discover ISO 9001:2015 Through Practical Examples - https://advisera.com/books/discover-iso-9001-2015-through-practical-examples/
  • Scope determination - a management not a technical decision

    Hi, did you map your organization (Operations Department) as a set of interrelated processes? With what outside parties do those processes interact? Some of those outside parties will be suppliers, other regulators, other maybe partners. Can any of the remaining outside parties be considered as customers? Unzoom yourself from the detail and answer yourself to the question: Who does my organization (Operations Department) serve?

    And if they are insiders, and those whom we serve, in turn, who do they serve?

    Follow the mission of your organization, perhaps that can help find one or more groups of customers, internal and external.

    Does this help you? Let me know.
  • Monitoring and measuring and customer satisfaction


    Answer:
    Each organization is an individual case. However, when working with organizations implementing ISO 9001:2015 I follow, as general rules, this framework:

    Quality objectives;
    Customer and other interested parties satisfaction objectives;
    Product or service objectives;
    Process performance objectives.

    For each objective I want to know what the actual value is and the trend. I always use graphics, and compare results with the target. Whenever possible I like to use control charts in order to help decide if the system should be changed or not in order to meet targets.
    Personally I prefer to link performance and processes, but my experience is that most organizations prefer to link with departments.

    About measuring customer satisfaction I see organizations using surveys, using interviews with customers, using experts opinion in magazines, using consumer evaluation in websites.

    The following material will provide you information about data analysis:
    - ISO 9001 – Analysis of data obtained from Monitoring and Measurement - https://advisera.com/9001academy/blog/2014/04/22/analysis-data-obtained-monitoring-measurement/
    - free online training ISO 9001:2015 Foundations Course - https://advisera.com/training/iso-9001-foundations-course/
    - book - Discover ISO 9001:2015 Through Practical Examples - https://advisera.com/books/discover-iso-9001-2015-through-practical-examples/
  • Getting top management support

    And I agree with that fact-based approach. However, many times this is an egg-chicken problem because many organizations before implementing ISO 9001 don’t have enough data. If your organization has data, perhaps you can use figures to support this claim:

    We can reduce the cost of quality problems by X% = Y currency units;
    We can reduce customers lost due to quality complaints by X% = X% = Y currency units;
    We can gain customers that demand ISO 9001 certified suppliers and increase revenue by X% = Y currency units;
    We can improve productivity due to better planning and reduce unit production cost by X% = Y currency units;
    We can improve our brand awareness in the market and increase our unit price by X% = Y currency units
    We can have savings of X% = Y currency units due to better planning and buying with suppliers

    Do you think this can help?
  • Internal audits and auditor competence


    Answer:
    To keep your certification, you will be audited annually by the certification body, what is called a surveillance audit. To avoid a major nonconformity at that audit your organization should perform an internal audit to the environmental management system at least annually.

    2. Must it be by someone who is certified or just knowledgeable?

    Answer:
    Your internal auditor should be someone considered competent according to your organization’s own requirements. It is your organization that establishes the required competence needed for an internal auditor.

    The following material will provide you with information about internal audits:
    - ISO 14001 – Internal Audits in the EMS: Five Main Steps - https://advisera.com/14001academy/blog/2019/08/27/key-iso-14001-benefits-to-customers/nowledgebase/internal-audits-in-the-ems-five-main-steps/
    - Creating an ISO 14001 internal audit plan - https://advisera.com/14001academy/blog/2017/01/16/creating-an-iso-14001-internal-audit-plan/
    - free online training ISO 14001:2015 Internal Auditor Course
    https://advisera.com/training/iso-14001-internal-auditor-course/
    - book - The ISO 14001:2015 Companion - https://advisera.com/books/the-iso-14001-2015-companion/
  • Toolkit content

    4.1 Understand organization and context
    4.2 understanding the needs and expectations of stakeholders
    Please inform where I can find this to be able to implement as required by the standard.)

    Answer:

    ISO 27001 does not require the documentation of organizational context, only that you consider them to identify needs and expectations of stakeholders.

    To cover requirements from section 4.2 you can use the "Procedimiento para identificación de requisitos" and the "Apéndice: Lista de requisitos legales, normativos, contractuales y de otra índole" templates, which are located on folder 2 "02_Procedimiento_para_identificacion_de_requisitos"

    These articles will provide you further explanation about organizational context and needs and expectations of stakeholders:
    - How to define context of the organization according to ISO 27001 htt ps://advisera.com/27001academy/knowledgebase/how-to-define-context-of-the-organization-according-to-iso-27001/
    - How to identify ISMS requirements of interested parties in ISO 27001 https://advisera.com/27001academy/blog/2017/02/06/how-to-identify-isms-requirements-of-interested-parties-in-iso-27001/
  • EU GDPR controller vs. processor


    Answer:

    This depends on what activities you perform. If you process personal data on behalf of the Controller and if you process data based on the controller`s instructions, you are a data processor.

    A controller is an entity who, alone or jointly with others, determines the purposes and means of the processing of personal data. In other words, the controller decides “what” personal data will be processed for and “how” it will be done.

    A processor is an entity who processes personal data on behalf of a controller. An example might be a company that processes your payroll or a cloud provider that offers data storage. Ho wever, in more complex relationships it can be difficult in practice to work out if someone acts as controller or processor.

    To find out more about controllers and processors check out this article EU GDPR controller vs. processor – What are the differences? (https://advisera.com/eugdpracademy/knowledgebase/eu-gdpr-controller-vs-processor-what-are-the-differences/)
  • Best Lead Auditor course for food safety


    Answer:

    Your question really comes down to what aspects of business you have expertise in and what you want to audit as a lead auditor. ISO 22000 is a standard for Food Safety Certification, where as ISO 27001 is the standard requirements for an Information Security Management System (in other words IT management). Within the food safety and hygiene environment you need to ask yourself where your experience and knowledge lie, the aspect of IT or food safety.

    For more information on what Iso 27001 is, feel free to look at our website "What is ISO 27001?”, https://advisera.com/27001academy/what-is-iso-27001/

Didn’t find an answer?

Start a new topic and get direct answers from the Expert Advice Community.

CREATE NEW TOPIC +