Included with the toolkit you bought you have the access to video tutorials that can help you fill in the content of a business plan. The tutorials show how real data is filled out into the templates.
Regarding other companies plans content, we do not have authorization to share them, even without identifiable details.
ISO 9001 and Construction
(1) Where should we start?
(2) Is it beneficial that we already have SOP in place?
(3) As a construction company, what part of physical construction work needs to be outlined and documented within the QMS?
(4) How is remove and replace construction work defined? Product or service?
(5) How do most construction companies define their organizations?”
Answer:
(1) Do a Gap Analysis, map your processes, establish a quality policy and develop action plans to meet them. Consider also the context, the interested parties and risks and opportunities.
(2) Yes, that means that your organization is used to follow internal standards
(3) After a contract you have to plan resources use (materials, equipments, people and time), you have to plan quality control and you have to evidence progress and quality control
(4) That is not relevant, some can consider your business as a product and others as a service
(5) That will depend on your organization’s market positioning.
Medical Device File are basically a set of documentation to demonstrate the safety and performance of the device as per the intended use. There is no specific format to comply to but you should provide what is stated under clause 4.2.3 of ISO 13485.
Example of document that should be in medical device file includes but not limited to instructions for use , product labeling and product specification sheet.
Normalmente para una empresa de 10 personas el paquete básico sería suficiente para poder implantar la norma de manera satisfactoria en su organización. Tenga en cuenta que en este paquete de documentos se incluyen todos los documentos obligatorios con los que necesita cumplir. No obstante, tiene que llevar a cabo todos los pasos necesarios de la implementación para dar cumplimiento a los requisitos de la ISO 9001:2015 y así poder pasar la auditoria de certificación realizada por parte de la entidad certificadora.
Basics of implementation of IATF is for sure quality management system or implementation of ISO 9001. IATF or former TS 16949 was the technical specification for ISO 9001 which means that standard requirements were higher and more specific for the automotive industry. Core Tools this standard requires are Advanced Product Quality Planning (APQP); Failure Mode and Effects Analysis (FMEA), Measurement Systems Analysis (MSA), Statistical Process Control (SPC) and Product Part Approval Process (PPAP). Implementation of core tools can help business to improve and achieve continual improvement if they are used in good way.
The EU GDPR states that is compulsory for a legal entity to appoint a DPO only if (a) the processing is carried out by a public authority or body, except for courts acting in their judicial capacity; or (b) the core activities of the legal entity consist of processing operations which, by their nature, their scope and/or their purposes, require regular and systematic monitoring of data subjects on a large scale; or (c) the core activities of the legal entity of processing on a large scale of special categories of data pursuant to Article 9 of the EU GDPR and personal data relating to criminal convictions and offences referred to in Article 10 of the EU GDPR.
Also since the organization is in Sri Lanka and India, you first need to identify if the EU GDPR is applicable. The key to understanding when EU GDPR is applicable is understanding the meaning of “in the Union.” The EU GDPR will only apply to personal data regarding individuals within the Union, while the nationality or habitual residence of those individuals is irrelevant. For example, a company based in the EU which is processing the data of Japanese individuals located in Japan will still need to comply with the EU GDPR. Consequently, the Japanese individuals will be benefiting from all rights according to the EU GDPR, even if these rights do not exist in their own nation’s laws.
When the data is processed outside of the EU by companies which are also outside the EU, then this is not considered to be “in the Union”. For example, the EU GDPR will not be applicable for a school which is based in the United States just because there is a possibility that one or several of its students would be EU citizens. In this case, the processing does not take place “in the Union,” nor is the individual “in the Union”.
If your customer falls under both criteria above it would need to appoint a representative in the EU and the competent Supervisory Authority would be the one where the representative is established.
Answer: The ISO 45001:2018 standard does not have a specific requirement to have a workers’ representative assigned for the OH&SMS. Throughout the standard, the term ‘workers’ representatives’ is used, but always with the addition of the term ‘where they exist’. This is done because legal requirements in some jurisdictions require workers’ representatives for OH&S and if these representatives do exist they need to be included into the OH&SMS processes.
2. We made a survey to ask workers about the way that they preferred to communicate with them and they select E-mail, is it enough for participation with workers to use E-mail for asking them or informing?
Answer: Clause 5.4 on consultation and participation of workers is clear that a process needs to be put in place to meet certain requirements about getting the input of workers for the OH&SMS as well as informing them of OH&SMS information, telling you what needs to be done and not how to do it. So, if the email process you i dentified meets the requirements that are identified in clause 5.4 then this is an acceptable way of defining this process.
Answer:
There is no particular “official” or legal requirements for someone to become an ISO 9001 consultant. Having said that, put yourself in the shoes of a potential customer. Would you prefer to work with someone without a CV, without any references, or would you prefer to work with someone with some experience or study about the job? I believe that a potential customer prefers to work with a consultant with a certification.
That is why Advisera developed such course for ISO 9001, ISO 14001 and ISO 27001 consultants. Course with a part based on the standard and the more important part based on good practices for developing, executing and controlling a management system implementation project. For example, for ISO 9001, check - free online training ISO 9001:2015 Lead Implementer Course - https://advisera.com/training/iso-9001-lead-implementer-course/