1. What are the reasons for replacing OHSAS 18001?
2. Which approach is perfect for the implementation of 45001, functional or systematic? Why that approach?
Answer:
1. OHSAS 18001 was not an international ISO standard, but was instead maintained by BSI. As such it was not agreed upon by the member countries of ISO as the internationally recognized benchmark for an OH&SMS. With the release of ISO 45001 this is now the case, and in the near future you should expect to see BSI stop updating OHSAS 18001 and then making it obsolete.
2. As ISO 45001 is a management system then the approach of looking at your implementation as a system is important. This does not mean that understanding what certain functions need to do is unimportant, and assigning the roles and responsibilities of functions needs to be done. If you already have your management system in place, it does help to look at how the requirements for the system have changed, and then focus on how each functional responsibility needs to change within your system to meet the new requirements.
Answer:
The Standard does not state how long the sample product should be kept. Generally, it should follow applicable regulatory guidelines or the projected useful life of the medial device depending on whichever is the longest.
Plan to address this, e.g.
- in a specially tailored Documentation Toolkit or
- in a "Delta package" to the "general ISO 27000 standard"?
Or what would you recommend at the "Target TISAX Certification" regarding the use of your toolkit? Do you already have customer companies or experience here?
Answer: TISAX is based on ISO 27001, so my recommendation is to use the ISO 27001 documentation toolkit the same way you would use for an ISMS implementation.
Unfortunately, we do not have a toolkit that is adapted for TISAX, but we are considering to start developing it.
In case the QMS is not certified, you still can use the shared documentation for your ISMS, since during the ISMS certification audit they also will be audited as if they were developed exclusively for the ISMS.
3. Can we pass the ISO 270001 audit with Office 365 cloud based solution?
Answer: Probably yes, but you have to evaluate carefully the SoA for Office 365 to verify if the way the controls are implemented will fulfill your needs.
It is important to note that for the certification audit it is much m ore important how an organization controls their service providers than which certificates do service providers have.
Answer:
If your organization considers some information as confidential and does not want to share it with a customer or a potential customer there is no clause in ISO 9001 that makes it mandatory. For example, you may have all reasons to not showing your organization’s prices with customer A if their competitor, customer B, request it.
Customers are, naturally, one of the most relevant interested parties. Please check the last phrase of Annex A.3 of ISO 9001:2015
The following material will provide you information about ISO 9001 customer satisfaction:
Answer:
ISO 9001:2015 no longer requires the existence of procedures, different from forbidding procedures, mandates the existence of some documents and records. Whenever ISO 9001:2015 refers to “retain documented information” it is referring what was known before as record. Whenever ISO 9001:2015 refers to “maintain documented information” it is referring what was known before as document.
The following material will provide you information about documentation for an ISO 9001:2015 quality management system: