Answer:
If your certification body raised negative audit findings (nonconformities) you have first to correct those nonconformities, remove what is wrong. Then, you have to search the root cause behind each nonconformity. After identifying each root cause, you can implement corrective actions, actions to remove the root causes. Normally, certification bodies specify the time frame for answering to them with a description of the correction and of the corrective action.
The following material will provide you information about answering to audit findings:
Answer:
The surveillance audit, like the certification audit, is an on-site audit done by the certification body. The difference is the number of hours devoted to processes in the audit.
For the certification audit, the certification body auditors will look at the implementation of every process within your management system to check for conformance to the applicable standards, as well as your organization documentation, process effectiveness, and continual improvement.
However, the surveillance audit will spend less time on only some portions of your management system. Surveillance audits will take less time to perform than the original certification audit. I cannot tell you what auditors will ask but I can assure you that they will start each time by looking at your key activities (such as management review, internal audit, corrective actions and co mplains treatment), and will then only look at some of the remaining parts within your management system.
The following material will provide you information about surveillance audits:
Answer:
I would like to know first what the strategic orientation of your company is, and who is the target-customer of your organization. Some target-customers want the lowest price others prefer service and customization or flexibility, others still prefer innovation or the best product or service.
This is important because what satisfies a target-customer group is different from what satisfies other target-customers. Normally, successful companies try to be the best for one particular type of target-customer.
I have no experience on “Metal Fabrication” but if my company is working with customers they want the lowest price, for example, I would choose objectives around QCD: Quality, Cost and Delivery. (% of defects, Productivity; Production Breakdowns, delivery delays, for example)
The following material will provide you information about quality objectives:
Answer:
I believe that there will be no exclusions and all clauses of ISO 9001 are applicable to your organization. Considering that your business is general and wholesale trading of medical equipment, perhaps ISO 13485 is more appropriate (medical devices).
I would start the implementation of a management system by:
Assembling a project team;
Developing a project plan with a timetable;
Basic training on ISO 9001 for project team members;
Define the scope of the management system;
Perform a Gap Analysis;
Determine internal and external context;
Determine interested parties;
Map your processes;
Define quality policy, objectives and plans to meet them;
Determine risks and opportunities and define action plans to act upon the most important;
Document your processes;
Start measuring performance;
Perform internal audits;
Do a management review and decide if you are ready for certification.
Answer:
While we at Advisera do not have an ISO45001 auditing or implementing course to offer, there are many available. I would suggest checking some of the main registrars in your area as they often provide training as well (for instance BSI, SGS and TUV). Remember that for internal auditing it is not necessary to take a certified course as the competence for auditor is determined by the company, and you can gain this competence in many different ways (including self study).
For a better understanding of the standard and how it transitions form OHSAS 18001, see this whitepaper: https://info.advisera.com/45001academy/free-download/twelve-step-transition-process-from-ohsas-18001-to-iso-45001
Non-EU medical services providers and the GDPR
Answer:
The EU GDPR would be applicable only if you provide “tele medicine” type services to EU customers. If you provide “classic” medical services and examine the patients in the US and do not specifically target EU data subjects, it is most likely that it will not apply to you.
ISO management standards are designed to be applicable to organizations of any size and industry, so if you are thinking about dedicating your career totally to ISO standards you should consider first to develop some work in fields other than IT, so you can gain some additional experience (e.g., you can work on projects focused on administrative or operational areas of your current job).
Once a year is not enough. You should update SoA at least once a month or more often, considering how changes in the ISMS environment and new and modified risks affect the implemented controls, so the SoA can keep reflecting the way the organization handles its information security.
On July the 5th, the European Parliament passed a non-binding resolution, asking the European Commission, the EU’s executive body, to suspend the Privacy Shield framework. As the resolution is not binding the EU Commission did not enforce it, thus Privacy Shield still stands.
Desde mi experiencia siempre recomiendo llevar a cabo todos los análisis de la forma más sencilla, en este caso la identificación del contexto de la organización. Lo más simple sería organizar una reunión con la gente relevante de la organización, por ejemplo, los directores de los departamentos, y llevar a cabo un análisis DOFA (debilidades, oportunidades, fortalezas, amenazas) para poder determinar las cuestiones internas y externas de la organización. Este mismo acta de reunión puede ser válido para demostrar que cumplimos con el requisito correspondiente.