Determining scope of QMS considering context of the organization
Answer:
The requirements from clause 4.3 state that you need to define the scope of your QMS according to the internal and external issues which means that you need to define context of your organization and why you want to implement the standard and to align the scope with your own needs as a company. For example, if you want to apply to tenders with only one of your products, you can cover only one production line with the scope of the QMS and save money on certification because you will only certify this production line and not entire organization.
The same reason is behind the consideration of interested parties. For example, your customer might require you to implement ISO 9001 because he buys one of your products so you can again cover with the scope only this production line to save time and implement the standard faster and meet customer requirements.
Answer:
Yes, the standard that officially defines the maximum period between two surveillance audits is ISO 17021 (standard that defines requirements for bodies providing audit and certification of management system), and in accordance with this standard, surveillance audits shall be conducted at least once a year.
Since both ISO 14001 and ISO 13485 have new versions, it is best to conduct the transition for both standards at the same time. The problem is that the ISO 14001:2015 has adopted High Level Structure (with ten clauses) and ISO 13485:2016 is created according to ISO 9001:2008 so it kept the old clause numbering and this will make the transition and the integration more difficult that it should be.
The best toolkit for you is ISO 14001:2015 Documentation Toolkit (https://advisera.com/14001academy/de/iso-14001-2015-gap-analyse-tool/ 001-documentation-toolkit/) that contains all necessary documents together with some most frequently used ones. You can use your old Quality Manual and combine it with our new Environmental Manual that is a part of above mentioned toolkit. Practically you will need to identify common requirements of ISO 13485 and ISO 14001:2015 and merge them into joint sections and for different requirements you will have separate sections in the manual. We will also publish ISO 13485:2016 Documentation Toolkit soon so if you decide to purchase it later, you will get a big discount as our previous customer.
QMS in rice industry
Answer:
Implementation of ISO 9001 is the same for every industry, including rice production. You need to conduct gap analysis first to determine to what level your company is already compliant with ISO 9001 and what needs to be done to achieve full compliance.
Implementation of ISO 9001 is the same for any type of business including the hospitals, clinics or any other health institution.
You need to get the management buy in for the implementation first and then to assemble team for the implementation. Next step is to perform gap analysis to determine to what extent your company is already compliant with the standard and what needs to be done to achieve full compliance. Here you can find our free GAP analysis tool https://advisera.com/9001academy/iso-9001-gap-analysis-tool/
Then you need to start creating necessary documents and implement new processes and actions in order to be compliant with the standard. For more information, see: ISO 9001 Implementation Diagram https://advisera.com/9001academy/free-downloads/
Once you complete the implementation, you need to conduct internal audit and management review to ensure that your system is fully compliant with ISO 9001:2015 . Finally you can hire certification body to conduct certification audit and issue your company the certificate.
The standard does not define who will perform the calibration and what qualifications must the person to perform calibration have. It simply says in the clause 9.1 "The organization shall ensure that calibrated or verified monitoring and measurement equipment is used and maintained, as appropriate". However, the clause 7.2 states "The organization shall determine the necessary competence of person(s) doing work under its control that affects its
environmental performance and its ability to fulfil its compliance obligations".
This means that in case of internal calibration, the company itself may define requirements for competence of perople performing the calibration. If the company decides that no certificate is needed, than the person does no t need the certificate.
Great! And so to confirm, the standard does not require you to measure or monitor your training program?
Thanks!
The future of the cyber security
2. What Skill set should I gain to accomplish the domain knowledge
Answer:
Regarding the first question, from my point of view, the cyber security is the base for the protection of the future: IoT (Internet of Things), IIoT (Industrial Internet of Things), OT (Operational Technology), etc., so, careers related to cyber security will be very important, and currently they are on growth.
Regarding the second question, my recommendation is that you need courses, books, webinars, etc. about cyber security, although the information security is also fundamental for the cyber security, so our resources can be also interesting for you (it can be your first step to learn more about cyber security)
Before you hire the certification body you need to implement the standard first. Usual first step in implementation is to conduct gap analysis to determine to what level your company is already compliant with the standard and what needs to be done to achieve full compliance with the standard. Here you can find free GAP analysis tool https://advisera.com/9001academy/iso-9001-gap-analysis-tool/
Next step is to create a project plan and define activities that need to be done, documents to be created and responsibilities for each activity. In case of bigger company with lot of locations, hundreds of employees, you will have to form a QMS team that will implement the standard, in case of smaller company , one man can be enough. For more information, see: How to choose a project manager for your ISO 9001:2015 implementation https://advisera.com/9001academy/blog/2016/01/12/how-to-choose-a-project-manager-for-your-iso-90012015-implementation/
Then you start implementing new procedures and documents into your existing company processes and create new ones. Once the system is implemented, you need to conduct internal audit and management review to make sure that your quality management system is compliant with ISO 9001. Finally, you can hire certification body to conduct internal audit.