Answer:
Each organization has the authority to set the requirements for their internal auditors. Only your organization has the legitimacy to set the requirements applicable to your internal auditors. Even ISO 19011 removed the word competence from the definition of auditor. That said, it is wise to set as minimum requirements for internal auditors that they should know the standard (ISO 9001:2015) and they should know auditing practices. Your organization can ask for any evidence that they know, or studied ISO 9001:2015.
The following material will provide you information about internal audits:
Respuesta: El principal objetivo de ISO 27001 es la protección de la información, por tanto, cualquier empresa, de cualquier sector, puede implementar y certificar este estándar, porque todas las compañías tienen información y tienen que protegerla, incluyendo las empresas de servicios y soporte. ¿Por qué? Pues porque este estándar puede proporcionar beneficios a tu negocio, algunos de ellos, por ejemplo: Cumplimiento, marketing, reducción de costes, estándarización de procesos. Para más información sobre los beneficios que aporta este estándar, puedes leer este artículo “Four key benefits of ISO 27001 implementation” : https://advisera.com/27001academy/knowledgebase/four-key-benefits-of-iso-27001-implementation/
You don´t need to follow any format, just comply with the requirements of the standard regarding the policy document, among them to be appropiate to the purpose and context of the organization and aligned with the strategic direction of the organization.
2nd one is, should i maintain individual files for each policy??
Answer:
Policy for ISO 9001:2015 should be just one for the whole organization, unless you implement other standards, so you can have a policy for each one.
3rd one is, for risk-based thinking, will I also preserve the papers of the meetings, we attended to discuss on RBT???
You can keep the minutes of the meetings as a record that validates that you carried out a risk-ba sed assessment, athough this is not a mandatory requirement in ISO 9001:2015.
ISO 9001:2015 doesn´t require a Business Continuity Plan to the organizations. That being said, a BCP can help organizations to recognize, mitigate and address risks to your business. Also some customers may require a BCP to their suppliers so it will depend on the company to satisfy this expectation/need.
If you already are a qualified ISO 9001 lead auditor you only have to evidence competence on ISO 27001 to be able to audit an ISMS, and implementing an ISMS is one way to evidence such competency.
Validation and Verification of Design and Development
The previous provided answer is still applicable in your case.
Use of ISO 45001 Toolkit in transition
Should we use the document sequentially when we have some procedures existing?
Answer:
If you are migrating from OHSAS 18001 to ISO 45001 using our toolkit then you are correct, if you already have existing procedures in place then reviewing these first before using the toolkit procedures. There is a helpful whitepaper on the transition process that can help you to organize the steps you will go through during the transition, including review of existing documents.
ISO 45001, like all ISO management system standards, does not cover the specifics of what legal requirements are to be met, or how to meet them. That being the case the requirements of ISO 45001 are that you identify what compliance obligations your organization has (including legal obligations), and then to determine how to comply with these obligations. So, your first step is to determine what are the legal compliance obligations in the dental college environment.
The Standard requires a documented procedure for the Management Review. It will be recommended to supplement the Management Review procedure with a SOP if the procedure stated in the Quality Manual is brief.