Assessment to ISO 9000 Standards Once all the requirements of ISO 9000 have been met, it is time for an external audit. This should be carried out by a third party, accredited certification body. In the UK, the body should be accredited by UKAS. The chosen certification body will review the quality manuals and procedures. This process involves looking at the companys evaluation of quality and ascertains if targets set for the management program are measurable and achievable. This is followed at a later date by a full on-site audit to ensure that working practices observe the procedures and stated objectives and that appropriate records are kept. After a successful audit, a certificate of registration to ISO 9000 will be issued. There will then be surveillance visits (usually once or twice a year) to ensure that the system continues to work.
Understanding the difference between ISO 9001 Standards and CMM means recognising a cultural understanding of quality. -Microsoft and many other software companies govern quality with the 80-20 rule,” said David Smith, vice president of Technology Futures, a technology forecasting company in Austin, TX. -The rationale is, ‘it’s a real product if 80 percent of the problem can be addressed and the remaining 20 percent is part of the business model.’ But the reality is the software industry’s business model is not a business model of total quality. And that is part of the challenge when you compare a CMM model against an ISO 9001 Standards model.”
The problem, as Smith sees it, is a conflict between the approaches to quality of ISO 9000 Standards and CMM programs, on the one hand, and the business model that corporations use on the other. -When you’re developing a product, the hardest problems to fix are the last 20 percent,” noted Smith.
Smith highlights three critical elements for understanding ISO 9001 and CMM:
Understanding and documenting the true requirements is a key element in both standards.
Document how you write the software code so other people can understand its value.
Understand the requirements outlined in the program management and business models. It means understanding the maximum payback from the ISO and CMM levels. This is difficult to achieve because it requires both management and supervisory hats.
Software in the original description of ISO 9001 is different from software that runs on a computer, explains Mark Paulk, a senior member of the technical staff at Carnegie Mellon’s SEI.
Paulk’s advice: Understand the essence of ISO 9001 so you can compare it to CMM. ISO 9001’s definition of software is more general and includes music, entertainment, or anything involving the creation of an intangible product.
-But the original bias of the standard was strongly toward the manufacturing environment, where all the historical work had been done,” said Paulk. -And that is one of the criticisms of the early releases of the standards. One of the objectives of the ISO 9000 revisions was it failed to make the standard more comfortable to users in other environments.”
In order to assist organizations to have a full understanding of the new ISO 9001:2008, it may be useful to have an insight on the revision process, how this revision reflects the inputs received from users of the standard, and the consideration given to benefits and impacts during its development.
Prior to the commencement of a revision (or amendment) to a management system standard, ISO/Guide 72:2001 Guidelines for the justification and development of management system standards recommends that a “Justification Study” is prepared to present a case for the proposed project and that it outlines details of the data and inputs used to support its arguments. In relation to the development of ISO 9001:2008 user needs were identified from the following:
-the results of a formal “Systematic Review” on ISO 9001:2000 that was performed by the members of ISO/TC 176/SC2 during 2003-2004
-feedback from the ISO/TC 176/Working Group on “Interpretations”
-the results of an extensive worldwide “User Feedback Survey on ISO 9001 and
The Justification Study identified the need for an amendment, provided that the impact on users would be limited and that changes would only be introduced when there were clear benefits to users.
The key focuses of the ISO 9001:2008 amendment were to enhance the clarity of ISO 9001:2000 and to enhance its compatibility with ISO 14001:2004.
A tool for assessing the impacts versus benefits for proposed changes was created to assist the drafters of the amendment in deciding which changes should be included, and to assist in the verification of drafts against the identified user needs. The following decision making principles were applied:
1) No changes with high impact would be incorporated into the standard;
2) Changes with medium impact would only be incorporated when they provided a correspondingly medium or high benefit to users of the standard;
3) Even where a change was low impact, it had to be justified by the benefits it delivered to users, before being incorporated.
The changes incorporated in this ISO 9001:2008 edition were classified in terms of impact into the following categories:
-No changes or minimum changes on user documents, including records
-No changes or minimum changes to existing processes of the organization
-No additional training required or minimal training required
-No effects on current certifications
The benefits identified for the ISO 9001:2008 edition fall into the following categories:
-Provides clarity
-Increases compatibility with ISO 14001.
-Maintains consistency with ISO 9000 family of standards.
1. Apply the concept of Plan Do Check Act (PDCA). This PDCA concept is applied at the Quality Management System and the process levels.
2. Convert the question to requirement raised by QMR or the QMS Committee which derived from the ISO 9001 standards. In this case, several questions can lead to one single requirement.
3. To edit those questions to suit the process that is to be audited. For example, you are going to audit the Purchasing/Procurement Department and you’re sitting down with the Audit Team trying to come up with relevant questions.
The main objective in auditing any process is to extract adequate information and evidence in order to verify that the process is conformant to the ISO 9001 requirements and that, it is effective in achieving its objectives. As an auditor, you need to be able to investigate, assess and verify the conformity and effectiveness of a given process, in terms of its planning, implementation, monitoring & measurement and improvement. As a Lead Auditor, preparing your Audit Team for the actual audit is crucial in ensuring success of the audit excercise. There is no better way to do that than by developing the audit questions with them.
There are many issues that must be addressed in moving the QMS from the initial state to the desired state. For example, all organizations implementing ISO 9001 will need to consider the unique culture within the organization, its size, and the resources available. Beyond those widely discussed points, three issues that merit particular attention are (1) consideration of the QMS as a parallel function, (2) training, and (3) auditing. Key points associated with these issues are discussed below.
In the case of all of the transitions depicted, real benefits from the QMS are more
likely to be experienced if the QMS is implemented directly into the core structure of the organization. SMEs must be cautious against establishing a QMS that is run separately in parallel to its other systems. In SMEs, the parallel subsystem most commonly exhibits itself as a separate Quality Assurance, or in some cases, ISO 9001 department. Possible reasons for this may include the existence of rigid departmental boundaries in some SMEs or overemphasis on core activities. As Yauch and Steudel [10] note, SMEs tend to focus their attention on “…necessary routine activities (such as sales, production, shipping, etc.) rather than activities aimed at improving processes or systems.” If a SME insists on establishing a separate quality department, its level of effectiveness can be increased by embedding the QMS in widely-used organizational systems where practical. The integration is largely a function of how well the QMS manages to share information with other subsystems and its ability to align with the policies, norms, goals, and values in place throughout the organization.
In SMEs, training and staff development is more likely to be ad hoc and small scale because of modest human and financial resources and the absence of a specific training budget. To prevent the problems arising from lack of education and training, two things must be done:
1. Education of Top Management: The centralization of decision-making processes within many SMEs means that the management can either be the main stumbling block to change or the main catalyst for change. Therefore, any approach to ISO 9001implementation must involve considerable education for the top management of the organization to create awareness and understanding of the implementation process as a change initiative. Implementing a fully functional and documented QMS requires motivation by top management to appreciate, achieve, and implement the necessary measures to meet the standards’ criteria.
2. Education and Training of Employees: SMEs are often under pressure to quickly gain ISO 9001 registration. Meeting the requirements of the standard in a short period of time can prove a formidable obstacle for a small company. Since most SMEs do not possess the needed expertise internally, they may be inclined to hire external experts to provide the necessary technical expertise and manpower. However, having a functioning and documented QMS requires more than that. It requires ensuring that all employees in the organization clearly know what is expected of them and how they can contribute to the attainment of their organizations’ goals. This will likely require the preparation and implementation of a training plan tailored specifically to the unique characteristics and maturity level of the SME.
As emphasized throughout the paper, a QMS is not going to produce the expected results unless it is fully functional. While auditing must therefore verify the existence of the necessary documentation, it must also focus on the functionality of the QMS. The measurement of the functionality and the qualitative and financial impacts of a QMS have been the subject of several studies, including Kaynak. Among the categories used to measure functionality and performance improvement, two are particularly noteworthy for our purposes: management commitment and employee involvement. A QMS cannot be functional in the absence of those two characteristics. Therefore, as a minimum, internal and external auditors should continually verify top management’s commitment to increased company-wide quality awareness and improvement in addition to employee involvement in the design, implementation, operation, and improvement of quality related processes and procedures.
ISO 9001 Standard is also perceived as a label given to the family of standards and the associated certification scheme. However, certification was never a requirement of any of the standards in the ISO 9000 family this came from customers. Such notions as We are going for ISO 9001 imply ISO 9001 Standards is a goal like a university degree and like a university degree there are those who pass who are educated and those who merely pass the exam. You can purchase degrees from unaccredited universities just as you can purchase ISO 9001 Standards. certificates from unaccredited certification bodies. The acceptance criteria is the same, it is the means of measurement and therefore the legitimacy of the certificates that differ.
There are a number of sources of information on the ISO 9000 quality management system standards, including
ISO’s web site (www.iso.org), which carry information on the standards. Your National Standards Body should be
able to provide copies of the standards, and registrars/certification bodies will be able to provide guidance on
registration arrangements.
Why are the standards being revised?
ISO’s formal review process:
- Requires continual review to keep standards up to date. Must be initiated within 3 years of publication of a standard.
User inputs from:
- A global user questionnaire/survey
- A market Justification Study
- Suggestions arising from the interpretation process
- Opportunities for increased compatibility with ISO 14001
- The need for greater clarity, ease of use, and improved translation
Current trends:
- Keeping up with recent developments in management system practices.
Who is responsible for revising the standards?
The revision process is the responsibility of ISO Technical Committee no.176, Sub-committee no.2 (ISO/TC 176/SC 2) and is conducted on the basis of consensus among quality and industry experts nominated by ISO Member bodies, and representing all interested parties.
When will the revised standards be available?
The revised quality management system standards (ISO 9000, 9001 and 9004) are scheduled as follows:
- ISO 9000:2005 already published – no major changes expected for 2009
- Current plan is for small changes to ISO 9001 (an “amendment”) to be published in November 2008.
- More significant changes are planned for ISO 9004 (a “revision”) to be published in mid 2009.
How much is the implementation of the new standard going to cost?
One of the goals of ISO/TC 176/SC 2 is to produce standards that will minimize any potential costs during a smooth implementation. Any additional costs may be considered as a value-adding investment. A key factor in the development of ISO 9001:2008 was to limit the impact of changes on users.
Will my organization have to re-write all its documentation?
No. ISO 9001:2008 doesn’t introduce major changes to the requirements, when compared to ISO 9001:2000. However, to benefit from the changes, we suggest you get acquainted with the new version of the standard and the clarifications introduced. If, during your analysis of the clarifications you find there are differences from your current interpretation of ISO 9001:2000, then you should analyse the impact on your current documentation and make the necessary arrangements to update it. It is intended that the amendment of ISO 9001 will have minimal or no impacts on documentation.
Will the revised standards address financial issues?
Financial issues are not addressed in ISO 9001:2008, which is a requirements standard. The ISO 10014:2006 and ISO 9004:2000, Guidelines for performance improvements standards will emphasize the financial resources needed for the implementation and improvement of a quality management system.
What are the benefits of the revised standards?
For ISO 9001:2008 the major benefits are:
- Simple to use
- Clear in language
- Readily translatable and easily understandable
- Compatibility with other management systems such as ISO 14001.
For ISO 9004:
- Facilitates improvement in users’ quality management systems.
- Provides guidance to an organization for the creation of a quality management system that:
- creates value for its customers, via the products it provides
- creates value for all other interested parties
- balances all interested-party viewpoints.
- Provides guidance for managers on leading their organization towards sustained success.
- Forward compatibility to allow organizations to build on existing quality management systems.
ISO 9001:2008 has been developed in order to introduce clarifications to the existing requirements of ISO 9001:2000 and changes that are intended to improve compatibility with ISO 14001:2004. ISO 9001:2008 does not introduce additional requirements nor does it change the intent of the ISO 9001:2000 standard.
Certification to ISO 9001:2008 is not an “upgrade”, and organizations that are certified to ISO 9001:2000 should be afforded the same status as those who have already received a new certificate to ISO 9001:2008
What are the main benefits to be derived from implementing an ISO 9000 quality management system?
The ISO 9000 standards give organizations an opportunity to increase value to their activities and to improve their performance continually, by focusing on their major processes. The standards place great emphasis on making quality management systems closer to the processes of organizations and on continual improvement. As a result, they direct users to the achievement of business results, including the satisfaction of customers and other interested parties.
The management of an organization should be able to view the adoption of the quality management system standards as a profitable business investment, not just as a required certification issue.
Among the perceived benefits of using the standards are:
- The connection of quality management systems to organizational processes
- The encouragement of a natural progression towards improved organizational performance, via:
- the use of the Quality Management Principles
- the adoption of a “process approach”
- emphasis of the role of top management
- requirements for the establishment of measurable objectives at relevant functions and levels
- being orientated toward “continual improvement” and “customer satisfaction”, including the monitoring of information on “customer satisfaction” as a measure of system performance.
- measurement of the quality management system, processes, and product
- consideration of statutory and regulatory requirements.
- attention to resource availability
How will the implementation of the amended standard help my organization to improve its efficiency?
ISO 9001:2008 aims at guaranteeing the effectiveness (but not necessarily the efficiency) of the organization. For improved organizational efficiency, however, the best results can be obtained by using ISO 9004 in addition to ISO 9001:2008. The guiding quality management principles are intended to assist an organization in continual improvement, which should lead to efficiencies throughout the organization.
What benefits are there to an organization implementing ISO 9004 ?
If a quality management system is appropriately implemented, utilizing the eight Quality Management Principles, and in accordance with ISO 9004, all of an organization’s interested parties should benefit. For example:
Customers and users will benefit by receiving the products (see ISO 9000:2005, Fundamentals and vocabulary) that are:
- Conforming to the requirements
- Dependable and reliable
- Available when needed
- Maintainable
People in the organization will benefit by:
- Better working conditions
- Increased job satisfaction
- Improved health and safety
- Improved morale
- Improved stability of employment
Owners and investors will benefit by:
- Increased return on investment
- Improved operational results
- Increased market share
- Increased profits
Suppliers and partners will benefit by:
- Stability
- Growth
- Partnership and mutual understanding
Society will benefit by:
- Fulfilment of legal and regulatory requirements
- Improved health and safety
- Reduced environmental impact
- Increased security
Are the standards compatible with national quality award criteria?
The standards are based on 8 Quality Management Principles, which are aligned with the philosophy and objectives of most quality award programs. These principles are:
- Customer focus,
- Leadership,
- Involvement of people,
- Process approach,
- System approach to management,
- Continual improvement,
- Factual approach to decision making, and
- Mutually beneficial supplier relationships.
ISO 9004 recommends that organizations perform self-assessments as part of their management of systems and processes, and includes an annex giving guidance on this approach. This is similar to many quality awards programmes.
Why is the requirement for monitoring “customer satisfaction” included in ISO 9001?
“Customer satisfaction” is recognized as one of the driving criteria for any organization. In order to evaluate if a product meets customer needs and expectations, it is necessary to monitor the extent of customer satisfaction.
Improvements can be made by taking action to address any identified issues and concerns.
Can the standards improve “customer satisfaction”?
The quality management system details that are described in the standards are based on Quality Management Principles that include the “process approach” and “customer focus”. The adoption of these principles should provide customers with a higher level of confidence that products will meet their needs and increase their satisfaction.
What is meant by “continual improvement”?
Continual improvement is the process focused on continually increasing the effectiveness and/or efficiency of the organization to fulfil its policies and objectives. Continual improvement (where “continual” highlights that an improvement process requires progressive consolidation steps) responds to the growing needs and expectations of the customers and ensures a dynamic evolution of the quality management system.
What is a process?
Any activity or operation, which receives inputs and converts them to outputs, can be considered as a process. Almost all activities and operations involved in generating a product or providing a service are processes. For organizations to function, they have to define and manage numerous inter-linked processes. Often the output from one process will directly form the input into the next process. The systematic identification and management of the various processes employed within an organization, and particularly the interactions between such processes, may be referred to as the ‘process approach’ to management.
What is the “process approach”?
The “process approach” is a way of obtaining a desired result, by managing activities and related resources as a process. The “process approach” is a key element of the ISO 9000 standards. For further guidance, please refer to the ISO 9000 Introduction and Support Package module: Guidance on the Concept and Use of the Process Approach for management systems.
Can the “process approach” be applied to other management systems?
Yes. The “process approach” is a generic management principle, which can enhance an organization’s effectiveness and efficiency in achieving defined objectives.
How can the PDCA cycle be used in the “process approach”?
The PDCA cycle is an established, logical, method that can be used to improve a process.
This requires:
(P) planning (what to do and how to do it),
(D) executing the plan (do what was planned),
(C) checking the results (did things happened according to plan) and
(A) act to improve the process (how to improve next time).
The PDCA cycle can be applied within an individual process, or across a group of processes.
Can any organization apply the “process approach”?
Yes. Many organizations already apply a “process approach” without recognizing it. They could achieve additional benefits by understanding and controlling it.
Why should an organization apply the “process approach”?
By applying the “process approach” an organization should be able to obtain the following types of benefits:
- The integration and alignment of its processes to enable the achievement of its planned results.
- An ability to focus effort on process effectiveness and efficiency.
- An increase in the confidence of customers and other interested parties as to the consistent performance of the
organization.
- Transparency of operations within the organization.
- Lower costs and shorter cycle times through effective and efficient use of resources.
- Improved, consistent and predictable results.
- The identification of opportunities for focused and prioritized improvement initiatives.
- The encouragement and involvement of people, and the clarification of their responsibilities.
- The elimination of barriers between different functional units and the unification of their focus to the objectives
of the organization.
- Improved management of process interfaces.
What is meant by the “sequence” of processes and their “interactions”?
The “sequence” of processes shows how the processes follow, or link, to each other to result in a final output.
For example, the output from one process may become the input of the next process or processes.
The “interactions” show how each process affects or influences one or more of the other processes. For example,
the monitoring or controlling of a process may be established in a separate process.
How can the processes in an organization be determined?
Identify the organization’s intended outputs, and the processes needed for achieving them. These will need to
include processes for Management, Resources, Realization and Measurement and Improvement.
- Identify all process inputs and outputs, along with the suppliers and customers, who may be internal or
external.
- Identify the sequence and interactions of the processes.
Should an organization define and document all its processes?
The main purpose of documentation is to enable the consistent and stable operation of an organization’s
processes.
Although statutory, standards’ or customer requirements may require certain documentation, there is no defined
“catalogue”, or list of processes that has to be documented in ISO 9001, apart from the 6 indicated ones.
The organization should determine which processes are to be documented on the basis of:
- The size of the organization and type of its activities,
- The complexity of its processes and their interactions,
- The criticality of the processes and
- Availability of competent personnel.
A number of different methods can be used to document processes, such as graphical representations, written
instructions, checklists, flow charts, visual media, or electronic methods.
How much detail is required in process documentation?
The extent of detail is likely to depend upon factors such as:
- the size of an organisation and its types of activities,
- the complexity of its processes and their interactions, and
- the competence (level of education, training, skills and experience) of its personnel.
What is the difference between a “process” and a “procedure”?
A “process” may be explained as a set of interacting or interrelated activities, which are employed to add value. A
“procedure” is a method of describing the way or How in which all or part of that process activities shall/should be
performed.
ISO 9000:2005 defines a procedure as a “specified way to carry out an activity or a process”, which does not
necessarily have to be documented.
An organization has a well-established set of procedures. Can these procedures be used to help
describe its processes?
Yes, if the procedures describe inputs and outputs, appropriate responsibilities, controls and resources needed to satisfy customer requirements.
What documentation is required by ISO 9001?
ISO 9001:2008 refers specifically to only 6 documented procedures; however, other documentation (including more documented procedures not specifically mentioned in ISO 9001:2008) may be required by an organization, in order to manage the processes that are necessary for the effective operation of the quality management system. This will vary depending on the size of the organization, the kind of activities in which it is involved and their complexity. For further guidance, please also refer to the ISO 9000 Introduction and Support Package module “Guidance on the Documentation Requirements of ISO 9001:2008″
What does an organization need to do to comply with ISO 9001?
When initially starting to use ISO 9001, an organization should familiarize its personnel with the Quality Management Principles, analyze the standards (especially ISO 9000 and ISO 9004), and consider how their guidance and requirements may affect your activities and related processes. If it then wishes to proceed to registration/certification, it should perform a gap analysis against the requirements of ISO 9001 to determine where its current quality management system does not address the applicable ISO 9001:2008 requirements, before developing and implementing additional processes to ensure that compliance will be achieved.
ISO 9001:2008 will supersede ISO 9001:2000 However, noting the IAF/ISO-CASCO/ISO TC176 agreement that accredited certification to the 2000 edition should remain possible for up to 2 years after the publication of ISO 9001:2008, copies of the 2000 edition will still be available on request from ISO and the national standards bodies during that period, and possibly for even longer.
Can organizations remain certified/registered to the 2000 version?
Yes. Certification to ISO 9001:2008 is not an “upgrade”, and organizations that are certified to ISO 9001:2000 should be afforded the same status as those who have already received a new certificate to ISO 9001:2008. However, certificates to ISO 9001:2000 will only remain valid until 2 years after the publication of ISO 9001:2008. Contact your certification/registration body to get details on the certificates transition process.
What will happen to the other standards and documents in the current (2000) ISO 9000 family?
The four primary standards of the current ISO 9000 family are the following:
- ISO 9000:2005 already published – no major changes expected for 2009
- ISO 9001:2000 to be superseded by ISO 9001:2008
- More significant changes are planned for ISO 9004 with a planned publication date of late 2009.
- ISO 19011:2002 is currently beginning the revision process, with a new version expected in 2011.
The other standards and documents will be reviewed and updated as necessary