Welcome!

Welcome!
Please also visit following blogs:
- 'EMS Awareness' Blog

Academic comments are invited.

Encouragement Support - National Centre for Quality Management. Please become a member of NCQM.

Keshav Ram Singhal

Various information, quotes, data, figures used in this blog are the result of collection from various sources, such as newspapers, books, magazines, websites, authors, speakers etc. Unfortunately, sources are not always noted. The editor of this blog thanks all such sources.

People from more than 145 countries/economies have visited this blog: Afghanistan, Albania, Algeria, Angola, Argentina, Aruba, Australia, Austria, Azerbaijan, Bahrain, Bangladesh, Belarus, Belgium, Belize, Benin, Bhutan, Bosnia and Herzegovina, Botswana, Brazil, Brunei, Bulgaria, Burundi, Cameroon, Cambodia, Canada, Chile, China, Colombia, Costa Rica, Croatia, Cyprus, Czech Republic, Denmark, Dominican Republic, Ecuador, Egypt, El Salvador, Estonia, Ethiopia, European Union, Fiji, Finland, France, Georgia, Germany, Ghana, Gibraltar, Greece, Guatemala, Guyana, Haiti, Honduras, Hong Kong S. A. R. (China), Hungary, Iceland, India, Indonesia, Iraq, Ireland, Israel, Italy, Ivory Coast, Jamaica, Japan, Jersey, Jordan, Kazakhstan, Kenya, Kuwait, Laos, Latvia, Lebanon, Lesotho, Libya, Lithuania, Luxembourg, Macao S. A. R. (China), Macedonia, Malawi, Malaysia, Maldives, Malta, Manila, Mauritius, Mexico, Moldova, Mongolia, Montenegro, Morocco, Mozambique, Myanmar, Namibia, Nepal, Netherlands, New Zealand, Nigeria, Niue, Norway, Oman, Pakistan, Palestinian Territory, Panama, Papua New Guinea, Peru, Philippines, Poland, Portugal, Puerto Rico, Qatar, Rwanda, Romania, Russia, Saint Lucia, Samoa, Saudi Arabia, Saint Kitts and Navis, Serbia, Seychelles, Singapore, Slovakia, Slovenia, Somalia, South Africa, South Korea, Spain, Sri Lanka, Sudan, Swaziland, Sweden, Switzerland, Syria, Taiwan, Tanzania, Thailand, Trinidad and Tobago, Tunisia, Turkey, Turks and Caicos Islands, UAE, Uganda, UK, Ukraine, USA, Uzbekistan, Venezuela, Vietnam, Zambia, Zimbabwe etc. Total visitors number crossed 100,000 on 14. 02. 2013. Total visitors number crossed 145,000 on 30. 09. 2013. Total visitors > 200,000 (from 01.08.2014)

Wednesday, September 28, 2011

Need to look afresh on ‘quality’



We have seen various quality improvement concepts – Six Sigma, TQM, 5-S, ISO 9001, ISO 9004, JIT, Zero defect, TPM, …. and so on. All these concepts have played a major and relevant role in improving the quality of a product (including service). In recent years we have also witnessed a number of standards, such as, ISO 14001 EMS, OHSAS 18001, SA8000, ISO 50001 EnMS, ISO 26000 SR, ISO 22000, ISO/IEC 27000 ISMS, being implemented by organizations.

Many quality gurus had defined the concept ‘quality’ in the previous millennium, i.e. in the 1900s. You may see the definitions written by Philip Crosby, Walter A Shewhart, Joseph M Juran, W Edwards Deming, A V Feigenbaum and many other quality gurus, most of those definitions are more than fifty years old, when organizations were not asked to comply requirements related with environment, social responsibility, energy, health, safety, information security etc.




ISO 9000:2005, an international standard on ‘Quality management systems – Fundamentals and vocabulary’ defines ‘quality’ as ‘degree to which a set of inherent characteristics fulfills requirements.’

It is now time to rethink with a focus on a return to the basics of quality and sound business management. Please re-examine the basics of quality and derive a new definition of ‘quality’ that remains for more than a decade. ‘Quality’ needs a definition afresh looking to the following:
- Fulfilling requirements
- Cost
- Effectiveness
- Environmental protection and performance
- Impact on society
- Human rights
- International norms of behaviour
- Risk
- Health
- Safety
- Energy efficiency
- Security
- Success (of the product/service, organization and user)


My new definition on QUALITY - I define quality as “a degree to which the product has a set of inherent distinguishing features (existing in the product as a permanent characteristics) that fulfill implied requirements of the product and also stated and obligatory (statutory and regulatory) requirements including customer requirements and those requirements: that protect and save environment, that have affordable cost for the customer, that has positive impact on society, that respect human rights, that respect international norms of behaviour, that safeguard health and safety, that conserve energy and that maintain security requirements so as to achieve and enhance satisfaction and success of the organization and its customer.”
Note –
1. Product also means service.
2. The term ‘quality’ can be used with adjectives.
© September 2011 - Keshav Ram Singhal, Ajmer, India.

I posted my above new definition on ‘quality’ for discussion with quality professional fraternity in some groups at linkedin.com (a social site of professionals) and I am overwhelmed with some reactions from a few professionals that are as under:

- John Outram, an associate at Qualimpex Inc. Canada says, “You should submit your new definition for quality to TC 176 though your National Committee.” (in Management Systems Professionals and Users group)
- Issoufou Trare, a consultant in Senegal, says, “I like this definition. But the very important challenge is to transform it to reality in numerous companies. Thanks for this fresh look.” (in Management Systems Professionals and Users group)
- Peddina Satyanarayana, Assistant General Manager at Steel Authority of India Ltd, Rourkela Steel Plant, says, “If any organization transforms KRS definition in to reality, the organization can continue to be at top. Quality is inner beauty with conformance to the requirements of customer.” John Outram liked the comment made by Peddina Satyanarayana.
- Ms. Cathleen N (National Director of Quality Assurance at Garda, Ottawa, Canada) and Ms. Farjana Ahmed (QMS Executive at ACME Laboratories Ltd., Bangladesh) have liked the discussion.

What do you think? Will you help me in defining quality with a new look by supporting my new definition or suggesting some improvement?


With best wishes,

Keshav Ram Singhal

Thursday, September 22, 2011

ISO 19011:2011

ISO 19011:2011 – Guidelines for auditing management systems – Expected to be published soon

Keshav Ram Singhal (Email - krsinghal@rediffmail.com)




International Organization for Standardization released ISO/FDIS 19011:2011 – Guidelines for auditing management systems in July 2011 to ISO members. It is expected that international standard ISO 19011:2011 will be published in October 2011.

ISO 19011:2002 is the current auditing standard that provides guidelines for auditing quality and/or environmental management system. This standard was long due for revision and since the initial publication of ISO 190011 in 2002 a number of new management system standards have been published. This has resulted in a need to consider a broader scope of management system auditing as well as providing guidance that is more generic. This is now reflected in ISO 19011:2011 that has the revised title “Guidelines for auditing management systems” instead of “Guidelines for auditing quality and/or environmental management systems” as mentioned in the existing standard ISO 19011:2002. ISO 19011:2011 will be useful for auditing any management system and also it will be useful for auditing integrated management as it will –
- Provide guidance on auditing all types of management systems, and
- Facilitate combined (integrated) audit of two or more management systems implemented by an organization.

ISO 19011:2011 will provide guidance for all users, including small and medium sized organizations and will concentrates on what are commonly termed internal (first party) and second party audits as often conducted by customers on their suppliers.
International Organization for Standardization (ISO) has already published ISO 17021:2011, a standard for conformity assessment that provides requirements for bodies providing audit and certification of management systems. After publication of ISO 19011:2011, there will be two relevant standards –
- ISO 17021:2011, Conformity assessment – Requirements for bodies providing audit and certification of management systems
- ISO 19011:2011, Guidelines for auditing management systems

The publication of ISO 19011:2011 will provide auditors, organizations implementing management systems and organizations (including certification bodies) needing to conduct audits of management systems an opportunity to re-assess their own practices and identify improvement opportunities in conducting audits.

What are the changes within ISO 19011:2011?

ISO 19011 is being revised to provide persons involved in management system auditing with good audit practice guidance relevant to the present environment. Presently there are many organizations implement management system covering multiple disciplines, for example quality (ISO 9001), environment (ISO 14001), occupational health and safety (OHSAS 18001) and information security (ISO 27000) etc.
The Principles of auditing on which the guidance is based are being revised and expanded to include the new auditing principle of ‘Confidentiality – security of information’. This will be a principle that will require auditors to be prudent in the use and protection of information acquired in the course of their duties during auditing management systems..

The main body of ISO 19011:2011 will set out good practice for Managing an Audit Programme and Performing an Audit. It will update to reflect current thinking and in parts expanded significantly. These sections will provide detailed guidance; intended to be used flexibly according to the size, level of maturity of an organization’s management system, the nature and complexity of the organization to be audited. The concept of risk in auditing is being introduced. Some guidance will be provided on combined audits, where two or more management systems of different disciplines are audited together (for example QMS and EMS, EMS and OHSAS, QMS and OHSAS). Also, the use of technology in remote auditing will be acknowledged.
Changes are being introduced in the guidance on Competence and evaluation of auditors. ISO 19011:2011 will address auditing management system covering multiple disciplines some of these may be wide ranging. The significant changes include:

- ISO 19011:2011 will identify that necessary auditor competence comprises generic knowledge and skills of management systems, plus discipline specific (for example, QMS) and sector specific (for example, aerospace) knowledge and skills. Annex A (informative) of the standard will provide examples of discipline-specific knowledge and skills of auditors, including:
- Transportation safety management
- Environmental management
- Quality management
- Records management
- Resilience, security, preparedness and continuity management
- Information security
- Occupational health and safety

ISO 19011:2011 will not include guidance on sector specific knowledge and skills of auditor. These may be developed later and published separately by the International Organization for Standardization (ISO).

The existing standard ISO 19011:2002 provides guidance on education, work experience, auditor training and audit experience that contribute to development of the knowledge and skills needed to perform audits and lead audit teams. ISO 19011:2011 will also provide guidance on knowledge and skills of management system auditors and an audit team leader but it will not make reference to auditors having completed education, work experience, auditor training and audit experience. This change will recognize that education, work experience, training and audit experience are enablers to competence, which ISO 19001:2011 and ISO 17021:2011 define as ‘ability to apply knowledge and skills to achieve intended results’. ISO 19011:2011 will recognize evaluation of competence needs, which may be carried out in a variety of ways, for example a combination of testing and examination, interview and observed audits.

1. Scope – There will be no significant changes.

2. Informative references – There will be no previous reference to terms and definitions given in ISO 9000 (QMS) and ISO 14050 (EMS).

3. Terms and definitions – New definitions for Observer, Guide and Risk are being introduced. The term risk will be used in ISO 19011:2011 in context of “risk-based auditing” and also “audit programme risks”. The definition of competence is being revised and although the change in wording appears slight it will require organizations to determine competence to achieve intended results. The starting point for which will be to define the intended results for the various activities involved in managing an audit programme and performing audits. This change will be consistent with ISO 17021:2011, a standard on conformity assessment.

4. Principles of auditing – There will be six principles in ISO 19011:2011 instead of five in ISO 19011:2002. Principles (a) – (d) will relate to auditors and the person managing the audit programme. Principles (e) and (f) will relate to the audit.

(a) Integrity – The principle of integrity will replace and expand the principle of ethical conduct mentioned in ISO 19011:2002. The principle of integrity is the foundation of professionalism.

(b) Fair presentation – There will be minor expansion that will include the obligation to report truthfully and accurately.

(c) Due professional care – the application of diligence and judgement in auditing. ‘Having the necessary competence is an important factor’ (in ISO 19011:2002) will be replaced with ‘An important factor in carrying out their work with due professional care is having the ability to make reasoned judgement in all audit situations’ in ISO 19011:2011.

(d) Confidentiality – security of information. It will be a new auditing principle, which will address the need for auditors to exercise discretion in the use and protection of information acquired in the course of their duties. The principle will refer to inappropriate use of such information for personal gain or in a manner detrimental to the legitimate interests of the auditee.

(e) Independence – the basis for the impartiality of the audit and objectivity of audit conclusions. ISO 19011:2011 will provide more specific guidance on the extent of independence that needs to be achieved, whilst recognizing that in small organizations it may be difficult for internal auditors to be fully independent. ISO 19011:2011 will refer to internal auditors being independent from the operating managers of the function being audited. ISO 19011:2011 will reflect the interpretation of independence that certification bodies generally apply.

(f) Evidence-based approach –There will be minor rewording in ISO 19011:2011 that will include the rational method for reaching reliable and reproducible audit conclusions in a systematic way.


5. Managing an audit programme – In this section ISO 19011:2011 will have considerable revision. The language of guidelines in this section will be easy to understand. There will be more clarity. Managing an audit programme guidelines will be structured in the following clauses:

5.1 - General

5.2 – Establishing the audit programme objectives

5.3 – Establishing the audit programme

5.4 – Implementing the audit programme

5.5 – Monitoring the audit programme

5.6 – Reviewing and improving the audit programme

5.1 General – This clause of the ISO 19011:2011 will recognize that an organization may implement a number of management system standards. Where the existing issue of ISO 19011:2002 refers to an organization establishing one or more audit programmes, ISO 19011:2011 will refer to an audit programme that can include audits considering one or more management system standards. Practically there will be little difference.

In this clause 5.1 of ISO 19011:2011 there will be guidance to allocate audit resources to audit those matters of significance within the management system. This concept is known as risk-based auditing.

5.2 Establishing the audit programme objectives – Title of this clause is being revised and also guidelines for structuring the content to follow the process flow guidance on the extent of an audit programme is being transferred to section 5.3.3.

5.3 Establishing the audit programme – ISO 19011:2002 states the title ‘Audit programme responsibilities, resources and procedures’ and this is being revised as new title ‘Establishing the audit programme.’. New to this issue is guidance on ‘Competence of the person managing the audit programme’. ISO 19011:2011 will add new guidance on ‘Identifying and evaluating audit programme risks’.

5.4 Implementing the audit programme – ISO 19011:2011 will provide more extensive guidance.

There will be sub-clause ‘Define the objectives, scope and criteria for an individual audit’. The sub-clause guidelines will identify that each audit should have a clear objective. This section will also highlight issues to consider when two or more management systems of different disciplines are audited together.
There will be a new sub-section ‘Selecting the audit methods’ and additional guidance on this issue will be provided in Annex B of ISO 19011.

Other sub-clauses will include: Selecting the audit team members, Assigning responsibilities for an individual audit to the team leader, Managing the audit programme outcome, Managing and maintaining audit programme records

In short we can conclude that section 5.4 of ISO 19011:2002 is being revised to provide comprehensive guidance to what was previously a list of headline topics that needed to be addressed when implementing the audit programme. Section 5.5 of ISO 19011:2002 – Audit programme records will be part of section 5.4

5.5 – Monitoring the audit programme and 5.5 – Reviewing and improving the audit programme - These two sections will replace what is stated in ISO 19011:2002 in clause 5.6 – Audit programme monitoring and reviewing. There will be minor expansion and reference to consider, such as, evaluate the performance of audit team members, consider as part of a review, alternative or new auditing methods, review the effectiveness of the measures to address the risks associated with the audit programme, review confidentiality and information security issues relating to the programme

6. Performing an audit – The clause title in ISO 19011:2002 is ‘Audit activities’ which is being revised. In this clause of ISO 19011:2011 you will find improved guidance. The section will be structured to follow the audit process flow, as under:

6.1 General

6.2 Initiating the audit

6.3 Preparing audit activities

6.4 Conducting the audit activities

6.5 Preparing and distributing the audit report

6.6 Completing the audit

6.7 Conducting audit follow-up

There will be few changes in the guidelines in ISO 19011:2011.

7. Competence and evaluation of auditors – Some significant changes are being introduced in ISO 19011:2011. The new standard will address auditing management system covering multiple disciplines. New guidance will include: Determining auditor competence to fulfill the needs of the audit programme, Personal behaviour, Knowledge and skills. The clause ‘Knowledge and skills’ will comprise: Generic knowledge and skills of management system auditors, Discipline and sector specific knowledge and skills of management system auditor. ISO 19011:2002 provides guidance for quality management system and/or environmental management system auditors, each having its own section providing guidance on auditor knowledge and skill requirements. In ISO 19011:2011 these two sections of ISO 19011:2002 will be replaced by one that will identify knowledge and skills that need to be applied to all management systems, for example, knowledge of: Legal requirements relevant to the specific discipline, fundamentals of the discipline and the application of business and technical discipline-specific methods, techniques, processes and practices sufficient to enable the auditor to examine the management system and generate appropriate audit findings and conclusions, risk management principles, methods and techniques relevant to the discipline and sector to enable the auditor to evaluate and control the risks associated with the audit programme.

ISO 19011:2011 Annex A will provide guidance on discipline-specific knowledge and skills of auditors for: Transportation safety management, Environmental management, Quality management, Records management, Resilience, security, preparedness and continuity management, Information security, Occupational health and safety.

ISO 19011:2011 will provide guidance on Generic knowledge and skills of an audit team leader, that will include knowledge and skills to: balance the strengths and weaknesses of the individual audit team members, develop a harmonious working relationship among the audit team members, manage the uncertainty of achieving audit objectives

ISO 19011:2011 will provide guidance on knowledge and skills for auditing management systems addressing multiple disciplines, achieving auditor competence.

Clause 7.6 of ISO 19011:2002 provides guidance on auditor evaluation, having sub-clauses, 7.6.1 – General and 7.6.2 – Evaluation process. ISO 19011:2011 will provide more clear guidance on auditor evaluation specifying guidance on establishing the auditor evaluation criteria, selecting the appropriate auditor evaluation method, conducting auditor evaluation, maintaining and improving auditor competence.

Thus we will find ISO 19011:2011 as a useful guidance document that will enable auditors to have more clear guidelines on auditing any management systems. The whole process of revising and preparing ISO 19011:2011 is under auspices of the ISO Joint Technical Co-ordination Group and administered by the ISO Technical Committee ISO/TC 176, ISO subcommittee ISO/TC 176/SC3 and also included interested parties for example ISO/TC 207, ISO/TC 34. ISO 19011:2011 will be the second edition of ISO 19011. The second edition of ISO 19011 will cancel and replace ISO 19011:2002 upon its publication.

Additional comments - This article written before publication of ISO 19011:2011. Please note that International Organization for Standardization (ISO) has published ISO 19011:2011 standard on 11 November 2011.

Courtesy:
- ISO Website
- ISO 19011:2002
- ISO/FDIS 19011:2011
- IRCA Website

Friday, September 16, 2011

Top management role for quality policy



Article for review – Comments and suggestions invited

Quality policy is an important aspect of quality management implementation in an organization. According to BuisnessDictionary.com, Quality Policy is top management's expression of its intentions, direction, and aims regarding quality of its products and processes.

Quality policy means what is the overall intention and direction within an organization related to quality.1

A reader asked us about signing of Quality Policy. We add a counter question - Is it really needed to sign a quality policy? If you go through the requirements you will notice that ISO 9001:2008 QMS Standard does not mention any requirements about signing of the quality policy.

Clause 5.3 of ISO 9001:2008 QMS Standard mentions requirements for quality policy to be ensured by the top management of the organization.
Here two important related phrases are required to understand – (i) Top Management, and (ii) Quality policy.

Top management is defined as ‘person or group of people who directs and control an organization at the highest level’ and a quality policy is defined as ‘overall intentions and direction of an organization related to quality as formally expressed by top management.’

On perusal of the documentation requirements as mentioned in clause 4.2.1 of ISO 9001:2008 QMS Standard, it is observed that a documented statement of a quality policy is a part of the ISO 9001:2008 QMS documentation, so what is further required (in addition to the above) with regard to quality policy is that as a document it must be duly approved for adequacy prior to issue as per organization’s documented procedure for control of documents. In this regard, the requirements mentioned in clause 4.2.3 are relevant.

The Standard requires the top management to ensure the following2:
- Quality policy is appropriate to the purpose of the organization
- Quality policy includes a commitment to comply with requirements and continually improve the effectiveness of the quality management system
- Quality policy provides a framework for establishing and reviewing quality objectives
- Quality policy is communicated and understood within the organization
- Quality policy is reviewed for continuing suitability

Quality policy may be communicated by issuing a documented statement of quality policy, which is approved for adequacy prior to issue as per organization’s documented procedure on ‘control of documents’.

Top management is required to ensure such a quality policy that is appropriate to the purpose of the organization, that includes a commitment to comply with requirements and continually improve the effectiveness of the quality management system, and that provides a framework for establishing and reviewing quality objectives. The top management must ensure those activities that improve communication and understanding of quality policy within the organization. In most organizations, QMS documentation (including quality policy statement) are generally developed by a team of people and then approved for adequacy prior to issue. Here it is immaterial who signs the quality policy or the quality policy is signed or unsigned. Even a quality policy verbally expressed by the top management in a meeting with staff or board of directors or annual general meeting may be termed as formally expressed overall intentions and direction of the organization related to quality by the top management.

Where a duly approved ‘quality policy’ statement is communicated and understood within the organization, that will serve the purpose and intent of quality management system as per ISO 9001:2008 QMS Standard. So take such steps that improve internal communication and understanding of the quality policy within the organization.

(Please send your comments to divyagim@gmail.com and/or keshavsinghalajmer@gmail.com)

1. http://qiblog.blogspot.com/2011/05/what-is-quality-policy.html
2. Singhal and Singhal (2008) Implementing ISO 9001:2000 QMS: A reference Guide, Prentice Hall India

- Dr. Divya Singhal & Keshav Ram Singhal

Monday, August 22, 2011

Aligning Quality Policy and Quality Objectives



Article for review – Comments and suggestions invited

ISO 9001:2008 QMS Standard mentions that an organization's quality policy must provide a framework for establishing and reviewing the company's quality objectives. The quality policy should give an overall direction for the organization, and its quality objectives should flow in that direction. The top management of the organization needs to establish quality objectives. Top management of the organization must ensure that quality objectives (including those needed to meet requirements for the product) are established at relevant functions and levels within the organization. The quality objectives must be measurable and consistent with the quality policy of the organization.

Clause 7.1 (a) of ISO 9001:2008 QMS Standard lays down that in planning product realization, the organization must determine quality objectives and requirements for the product. It is evident from this clause that the ISO 9001:2008 Standard now calls for objectives not only for the quality management system but also for the product. Many factors (such as changes in customer requirements, market conditions, business compulsions) may often put such situation where the organization have to think to change the policy and/or objectives, which may lead to weakening in the alignment between quality policy and quality objectives. To deal such situation continually, ISO 9001:2008 QMS standard requires that top management periodically review changes to both the policy and objectives. An organization's objectives must be measurable and its quality management system processes designed to meet those objectives.

Just after the publication of ISO 9001:2000 QMS Standard (earlier version of the standard), John E. (Jack) West (a famous quality excellence business consultant from USA) stated in an article ‘Three strategies for aligning quality policies, objectives and processes’ published in the Quality Digest (USA) that aligning the quality policy, quality objectives and QMS processes should further top management's intent with regard to quality. There's only one small, potential difficulty: ISO 9001 standard doesn't address aligning the quality policy and objectives with other business goals. Here it is important to mention that organization's overall business goals, quality objectives and quality policy are all interrelated and must work together to achieve business improvement. The purpose of quality management system is to create such management system where an organization is able to consistently provide product that meet customer and applicable legal requirements with aim to enhance customer satisfaction.

Clause 5.4.2 of ISO 9001:2008 QMS standard requires that an organization plan its quality management system to meet both the quality objectives and the general requirements of quality management system as mentioned in clause 4.1. Here it is important to note that clause 4.1 of ISO 9001:2008 QMS standard requires an organization to determine its quality management system processes and their application. The organization also needs to determine how processes interact, determine the criteria and methods needed for effectively operating and controlling the processes, and provide the resources to do so. The organization needs to monitor and, where applicable, measure the processes. And this information must also be analyzed to determine further actions needed to achieve planned results and improvement.

On the basis of the requirements mentioned in clause 5.4.1, some people may think that establishing quality objectives at relevant functions and levels within the organization is a one-time activity; however it is now clear that such thinking opposes the intent of the quality management system. There is also a need to integrate continual improvement activities in the quality management system. ISO 9001:2008 QMS standard requires continually improve the effectiveness of the quality management system through the use of the quality policy, objectives, audit results, data analysis, corrective and preventive actions, and management review. Accordingly, there is a need to continually review alignment between the quality policy and quality objectives and take necessary steps.

- Divya Singhal and Keshav Ram Singhal

(Please send your comments to divyagim@gmail.com and keshavsinghalajmer@gmail.com)

Sunday, June 19, 2011

Control of documents and control of records

Dr. Divya Singhal and Keshav Ram Singhal

First, it is necessary to understand the difference between records and documents. A document provides information in written, printed, or electronic form. A record relates to an activity or transaction that has happened in the past; it is a record of history. A record can consist of one or more documents, which all relate to a single event in time. The difference between a document and a record is that a document can change over time, while a record should not change.

Clause 4.2.3 of ISO 9001:2008 QMS Standard deals with control of documents, and clause 4.2.4 deals with control of records. Now we give below details regarding control of documents and control of records.

Control of documents

All documents required by the quality management system of the organization need to be controlled. Records are also required to be controlled as per requirements mentioned in clause 4.2.4 of the ISO 9001:2008 standard. This is separately addressed in this article under the heading „Control of records‟. For control of documents, a procedure is required to be documented. The documented procedure needs to define the controls needed:

- To approve documents for adequacy prior to issue
- To review and update as necessary and re-approve documents
- To ensure that changes and the current revision status of documents are identified
- To ensure that relevant versions of applicable documents are available at points of use
- To ensure that documents remain legible (clearly readable) and readily identifiable
- To ensure that documents of external origins are determined (which are necessary for the planning and operation of the quality management system)
- To ensure that distribution of determined external origin documents are controlled
- To prevent the unintended use of obsolete documents
- To apply suitable identification to obsolete documents if they retained for any purpose

Approval of document for adequacy prior to issue means that some authority (with responsibility to manage and direct quality management system affairs of the organization) has agreed the document before being made available for use (i.e. approval before the document is distributed, or published or made available to the users).

Reviewing document means another look at the document and this is a task, which should be carried out at the time following the issue of the document by the management representative or by the person, who is linked with the affairs mentioned in the document. Review of documents may be carried out randomly or periodically. Periodic review is proactive action and it is better if the management representative carries out periodic review (at least once in a year) of the issued document. If a document is updated with any change, then the same is required to be approved for adequacy prior to issue.

Changes to documents may be identified by mentioning a change record within the document that denotes the nature of change. Current revision status of document may be identified by issue number, revision number or date of the document.
To ensure that document is available at the point of use, the organization needs to establish who needs which document at what time. The document access should be available to persons who need it for better work performance. To ensure that documents remain legible and readily identifiable, it is required that contents of the documents are readable and documents can be identified easily. Document identification can be done by classification, titles or identification numbers of documents.

In order to control the distribution of external documents, the organization should establish appropriate process or mechanism for identification, classification, distribution and availability of such external documents.

Obsolete documents should not be available at the point of use. Use of obsolete documents may lead to errors, failures or hazards, which become an evidence of nonconformity. Sometime superseded or obsolete documents need to be retained by the organization for a variety of reasons (e.g. legal or reference purpose) and for this the organization must have a method of identifying the status of such documents to prevent their accidental use in place of current documents. In practice, organizations put stamp as „OBSOLETE DOCUMENT‟ in red ink on the face of the obsolete document.

For effective document control, following points should also be taken due care:

- The documents (manual, procedures, and work-instructions) should be written as a value-added proposition, not only as required step in the compliance process of the ISO 9001:2008 standard.
- The documents style, format, vocabulary and language should be easy to understand.
- The process owners should be included in writing relevant procedures or in reviewing the documents. Make sure that the people who use the document are involved in writing and reviewing them.
- The change (revision of documentation) process should be accessible to the people most affected by document inadequacies.
- Developing an effective value-added controlled document requires planning and regular monitoring.
- Write processes as they exist.
- Developing reliable and consistent process execution is critical for effective production planning.
- Make sure that documents are available at the point of use. Providing electronic access to documents at the point of use may be one good solution.
- Manage document changes efficiently.
- Documents should be reviewed regularly for accuracy. Failing to review documents for accuracy is one of the bigger mistakes organization does.
- Keep documents content current and accurate.


Control of records

Records established must be controlled. The purpose to maintain records is to provide evidence of conformity to requirements and of the effective operation of the quality management system. Records must remain:
- Legible
- Readily identifiable
- Retrievable

For control of records, a procedure is required to be documented. The documented procedure needs to define the controls needed for the:
- Identification of records
- Storage of records
- Protection of records
- Retrievable of records
- Retention of records
- Disposition of records

Why managing and controlling records necessary? Records exist in every organization. Records provide with information to help people to manage processes of the organization effectively. Records are the evidence of the past performance. Records provide with information of results achieved or evidence of activities performed.

Appropriate ways to control records include indexing, filing, proper keeping so that the risk of deterioration, damage or loss of record is minimized. It is better to decide who will have access to which records and how readily available and identifiable. Proper indexing, filing and safe keeping facilitate retrieval of records. It is better that records are not destroyed or disposed of before the end of their usefulness. While deciding the retention time of a particular record, also look into the legal requirements in this regard, so as to avoid forthcoming problems. Control on disposition of records should ensure that records are not destroyed prior authorization and organization should specify the method of disposal.

Records serve three purposes: (i) Records provide evidence of conformity with the requirements of the ISO 9001:2008 standard, (ii) Records demonstrate that the organization has an effective quality management system, and (iii) Records document continual improvement.

DS & KRS

Tuesday, July 13, 2010

Small changes having opportunities for improvement


Article for review – Comments and suggestions invited

Transition to ISO 9001:2008 QMS – Small changes having opportunities for improvement
Dr. Divya Singhal
and
Keshav Ram Singhal


ISO 9001 QMS standard has been popular among organizations all over the world during the last two decades. ISO 9000 QMS family standards were first published in 1987 and thereafter there was a revision in 1994. In the year 2000, there had been a major revision in the QMS standards and revised ‘ISO 9001:2000, Quality management systems – Requirements’ standard was published on 15 December 2000. On 15 November 2008, fourth edition – ISO 9001:2008 has been issued and published. Changes in the revised standard, ISO 9001:2008, are mostly editorial giving more clarity to the right interpretation of requirements. Users, such as organizations implementing ISO 9001 QMS, QMS auditors, etc., will find the new standard useful for right interpretation of standard’s requirements.

On careful reading of the revised ISO 9001:2008 standard and the earlier ISO 9001:2000 standard, we find that both standards used same numbering system to organize the standard and also there is no change in the intent, but the meaning is more clarified by the revision. On reading the standard at the macro level, we find no new requirements, but reading the same at micro-level, we find changes to the wording of a few clauses and additions of notes at the end of requirements. As such, organizations have opportunity to review their quality management system and to check the need for any change. Although the changes in the standard are small, but changes to the wording of the clauses (without adding any new requirements) provide great opportunity for organizations to review their quality management system for its better effectiveness.

We may apply three approaches to the revision. First, there are no new requirements in ISO 9001:2008 standard, so we do not need to do anything or change the documentation. Second, we will look to the changes in ISO 9001:2008 and compare our quality management system whether we need any revision or modification in QMS documentation to remain in compliance with the new standard. Third, we have a big opportunity and we must critically review our quality management system and thus make improvements. The first approach is incorrect or sleepy approach, second one can be termed as minimalist approach, an approach that only to revise quality management system documentation and other efforts. The third approach is a proactive approach that provides real benefits. So, we need to have a proactive approach.

Objective of ISO 9001:2008 standard is to provide consistent and conforming product. Clause 1.1 mentions scope of the standard on the basis of a performance-based objective that ISO 9001:2008 standard specifies quality management system requirements to:
• demonstrate ability to consistently provide product that meets customer and applicable legal (= statutory and regulatory) requirements, and
• enhance customer satisfaction

What are we looking for, while implementing ISO 9001:2008 standard? We must look to the evidence how we are planning our management system to meet the (i) customers requirements, (ii) applicable legal requirements, (iii) standard’s requirements, and (iv) any additional requirements determined in the organization’s quality manual. It is always better to concentrate on the processes, not more on documents. Think cause and effect of every process employed in the organization. Look at the results for which we should critically review system effectiveness and apply PDCA (Plan-do-check-act) approach. If this approach is applied by the internal auditors during their internal audit process then this proactive approach will bring good results for improvement.

There have been three objectives of the revision (i.e., development of ISO 9001:2008 standard):
• to improve the existing standard (i.e., ISO 9001:2000),
• to provide more clarity to the interpretation to requirements to enable ease of use, and
• to improve compatibility with ISO 14001:2004 standard

Now a few important points related to the changes are as under:

1. Clause 0.1 (introduction – general) now refers to organizational environment, changes in that environment and associated risks. Here is an opportunity to the user to check to ensure that the quality management system continues to be relevant to the changing business environment in which the organization is operating.
2. Clause 0.1 (introduction – general) confirms that the intent of the standard is not to imply uniformity in the structure of the QMS or uniformity of documentation. Here is an opportunity to the user to become the owner of its quality management system and its documentation.
3. Clause 0.1 (introduction – general) mentions meeting applicable statutory and regulatory requirements. Here is an opportunity to the user to determine which statutory and regulatory requirements are applicable to the quality management system of the organization.
4. Editorial change and text added to clause 0.2 (process approach) emphasizes the importance of processes of being capable of achieving desired outcome. Here is an opportunity to the user to apply process approach in achieving consistent and conforming product and review whether the system is producing desired results. In case answer to the review come in negative then the user has an opportunity to look at the why and what needs to be changed.
5. Clause 0.3 (relationship with ISO 9004) speaks about the relationship with ISO 9004. New ISO 9004:2009 standard has also been published, as such there is an opportunity to the user to read the latest version of ISO 9004 and get a sense how it might apply to its quality management system to manage the sustained success.
6. Some editorial changes to clause 0.4 (compatibility with other management systems) have introduced for the better alignment with other management systems. Here is an opportunity to the user to think for an integrated approach, if implementing other management systems (such as ISO 14001 EMS, OHSAS etc).
7. Clause 1.1 (scope – general) re-emphasizes that the objective of the quality management system should be to provide confidence in the organization’s ability to consistently provide conforming product (product that meet customer and applicable legal requirements). Here is an opportunity to the user to always keep in mind the objective mentioned in clause 1.1.
8. Throughout the new standard (ISO 9001:2008), the text has been modified to address statutory and regulatory requirements (which can be expressed as legal requirements as per note 2 added to clause 1.1). Here is an opportunity to the user to ensure to think what legal requirements are applicable to the organization.
9. Note 1 in clause 1.1 (scope – general) clarifies that the term ‘product’ refers to any intended output resulting from the product realization processes. Here is an opportunity to the user to ensure that organization’s system addresses the requirements of purchased product, intermediate product (resulting from different realization processes) and the final product. This will help eliminate nonconforming product during realization process.
10. Clause 1.1 (scope – general) reminds to think the scope of the organization’s quality management system and application of ISO 9001:2008 requirements in the organization. Here is an opportunity to the user to check and make sure that the requirements of the standard are properly applied and exclusions to any requirements have valid reasons.
11. Clause 1.2 (application) has been edited by adding statutory to applicable regulatory requirements. Here is an opportunity to the user to think the exclusions that do not affect resulting product meeting customer and applicable statutory and regulatory requirements.
12. Clause 2 (normative reference) now refers to ISO 9000:2005 standard as a normative reference document. Here is an opportunity to the user to consult quality management principles and terminology given in ISO 9000:2005 standard to understand the requirements of ISO 9001:2008 standard more clearly.
13. Clause 3 (terms and definitions) refers to ISO 9000 for terms and definitions and also confirms that the term ‘product’ also mean ‘service’.
14. Note 1 to clause 4.1 (QMS – general requirements) clarifies that the processes needed for the quality management system include processes for management activities, provision of resources, product realization, measurement, analysis and improvement. Processes for analysis and improvement have been added in the note of the revised standard (although necessary earlier also in clause 8 requirements), as such there is an opportunity to the user to check and make sure to manage analysis and improvement processes along with other processes.
15. Clause 4.1 (e) now clarifies that measurement process may not be applicable in all cases, however monitoring all processes being necessary. Here is an opportunity to the user to re-evaluate the need for measurement.
16. Notes have been added to clause 4.1 (QMS – general requirements) that explain more about outsourcing – (i) meaning of ‘outsourced process’, (ii) responsibility of conformity, and (iii) ensuring control to outsourced process. Here is an opportunity to the user to review and define the type and extent of control to be applied to the outsourced process.
17. Note to clause 4.2.1 (QMS – documentation requirements – general) now clarifies that a single document may address the requirements for one or more procedures. Also, a requirement (of ISO 9001:2008 standard) may be covered by more than one document. Accordingly, here is an opportunity to the user to re-evaluate quality management system documentation. The user may choose to address, for example, - (i) ‘Control of document’ and ‘control of records’ in a single procedure, provided that the procedure covers all requirements of clause 4.2.3 and 4.2.4, and (ii) ‘control of nonconforming product’, ‘corrective action’ and ‘preventive action’ in a single procedure , provided that the procedure covers all requirements of clause 8.3, 8.5.2 and 8.5.3.
18. Clause 4.2.1 (c) and (d) include records as a type of documentation required for the quality management system. Here is an opportunity to the user to re-evaluate the need for any new records to ensure effective planning, operation and control of processes.
19. Clause 4.2.3 (control of documents) explains that external origin documents determined by the organization are identified and their distribution controlled. Hence, distribution control not required to all external documents that are used in the organization. Here is an opportunity to the user to be flexible in controlling documents of external origin.
20. Sequence of clause 4.2.4 (control of records) has been changed for more clarity and better alignment with ISO 14001 EMS standard. There is no change in requirements of this clause, however, here is an opportunity to the user to achieve better integration of records generated by quality management system, environmental management system and other management systems (such as OHSAS 18001).
21. No change in the requirements of clause 5.1 (management commitment), clause 5.2 (customer focus), clause 5.3 (quality policy) and clause 5.4 (Planning).
22. Clause 5.5.2 (management representative) clarifies that the management representative has to be a member of organization’s management. Where an organization has appointed outside part-time personnel (such as consultant) as management representative, there is an opportunity to the user to remove such personnel as management representative and appoint organization’s own management member as management representative to take the ownership of the quality management system of the organization.
23. There is no change in the requirements of clause 5.6 (management review).
24. There is no change in the requirements of clause 6.1 (provision of resources).
25. There is editorial change in clause 6.2.1 and addition of a new note, which clarifies that competence requirements relate to personnel whose work directly affects conformity to product requirements and also where it indirectly affects conformity to product requirements. If an organization has limited its attention to competence requirements for personnel directly involved in production (or service delivery) processes, then there is an opportunity to the user to assess competence requirements for personnel involved in other activities (such as purchasing, supplier evaluation, internal audit etc.).
26. In clause 6.2.2 (competence, training and awareness), there is change in sequence of the title to bring the title in line with the similar clause in ISO 14001 EMS standard.
27. There is no new requirement in clause 6.3 (infrastructure), however this clause has now recognized information technology as an example of infrastructure, so there is an opportunity to the user to review dependence on information technology and its maintenance.
28. Although there is addition of a new note to clause 6.4 (work environment) that explains the term ‘work environment’, but this does not change any requirements of this clause. However, there is an opportunity to the user to consider the conditions under which work is performed.
29. Clause 7.1 (planning of product realization) has been reframed being editorial change and there is an addition of the word ‘measurement’, accordingly, there is an opportunity to the user during product realization planning to think and determine measurement activities to ensure proper control.
30. Requirements in clause 7.2.1 (determination of requirements related to the product) have been slightly reworded and a new note has been added that clarifies the post delivery activities to include actions under warranty provisions, contractual obligations (such as maintenance services) and supplementary services (such as recycling or final disposal). Here is an opportunity to the user to think about post delivery activities that can enhance customer satisfaction.
31. There is no change in the requirements of clause 7.2.2 (review of requirements related to the product).
32. There is no change in the requirements of clause 7.2.3 (customer communication).
33. A note has been added to clause 7.3.1 (design and development planning) explaining that design and development review, verification and validation have distinct purposes. As such, they may be conducted and recorded separately or in any combination as suitable for the product and the organization. Here is an opportunity to the user to have flexibility in addressing design and development review, verification and validation. For complex design and development process, distinct activities for review, verification and validation are recommended and for simple design and development process, all activities for review, verification and validation may be carried out at the same time.
34. There is editorial change in the wording of the requirements in clause 7.3.2 (design and development inputs), however there is no change in the requirements.
35. There are editorial changes in clause 7.3.3 (design and development outputs) and also a new note has been added explaining that design and development output can include details for the preservation of products. Here is an opportunity to the user to look to design outputs that addresses product packaging and handling information.
36. There is no change in the requirements of clause 7.3.4 (design and development review).
37. There is no change in the requirements of clause 7.3.5 (design and development verification).
38. There is no change in the requirements of clause 7.3.6 (design and development validation).
39. There is no change in the requirements of clause 7.3.7 (design and development changes), no text change, however Paras now merged.
40. There is no change in the requirements of clause 7.4 (purchasing).
41. There are editorial changes in clause 7.5.1 (control of production and service provision) that the word ‘equipment’ has been used instead of ‘devices’ and the word ‘product’ has been added prior to the word ‘release’. Hence, there are no changes in the requirements of this clause.
42. There are editorial changes in clause 7.5.2 (validation of processes for production and service provision), however no changes in the requirements of this clause.
43. The wording in clause 7.5.3 (identification and traceability) has been changed to clarify that identification may be needed throughout the product realization process – not only for the final product. Here is an opportunity to the user to identify the product by suitable means throughout product realization process.
44. There are editorial changes in clause 7.5.4 (customer property) and a new note has been added to this clause explaining that both intellectual property and personal data of the customer are customer property. Here is an opportunity to the user to also think and take care with the intellectual property and personal data of the customer.
45. The wording in clause 7.5.5 (preservation of product) has been changed to clarify the requirements in a better way; however there is no change in requirements of this clause.
46. There are a number of minor editorial changes in clause 7.6 (control of monitoring and measuring equipment), the word ‘devices’ has been replaced by ‘equipment’. An additional note has been added regarding the use of computer software that states verification and configuration management as typical methods to satisfy intended application and maintain suitability for use. The editorial changes in this clause will have no impact, however, here is an opportunity to the user to look and consider the extent to which computer software is used during monitoring and measuring activities. The user should be able to know the impact of computer software on the accuracy of results. The software should be up-to-date and suitably protected against virus, system crash etc.
47. There is minor editorial change in clause 8.1 (measurement, analysis and improvement – general), however this does not change the intent of the requirements.
48. A note has been added to clause 8.2.1 (customer satisfaction) explaining that monitoring customer perception can include input from sources such as customer satisfaction surveys, customer data on delivered product quality, user opinion surveys, lost business analysis, compliments, warranty claims and dealers report. There is no new requirement in this clause, however, here is an opportunity to the user to review the way top monitor customer perception.
49. There are editorial changes in clause 8.2.2 (internal audit) and this clause now expects management responsible for the area being audited to ensure that correction and corrective actions are addressed without undue delay as appropriate with respect to detected nonconformities. Here is an opportunity to the user to do a root cause analysis and correction of detected nonconformity without loss of time.
50. A note has been added to clause 8.2.3 (monitoring and measurement of processes), which clarifies that when deciding on appropriate monitoring and measurement methods, consider both impact on product conformity and on the effectiveness of the quality management system of the organization. Here is an opportunity to the user to look to all processes of the organization.
51. There are editorial changes in clause 8.2.4 (monitoring and measurement of product), but no new requirements.
52. There are editorial changes in clause 8.3 (control of nonconforming product), but no new requirements.
53. There are editorial changes in clause 8.4 (analysis of data), but no new requirements.
54. There is no change in the requirements of clause 8.5.1 (continual improvement).
55. Clause 8.5.2 (corrective action) now makes it clear that effectiveness of the corrective action must also be reviewed. Here is an opportunity to the user to look carefully at the corrective actions that they are achieving desired results.
56. Clause 8.5.3 (preventive action) now makes it clear that effectiveness of the preventive action must also be reviewed. Here is an opportunity to the user to look carefully at the preventive actions that they are achieving desired results.

ISO 9001:2008 Implementation Policy
International Organization for Standardization (ISO) and International Accreditation Forum (IAF) have agreed an implementation plan to ensure smooth migration of accredited certification to ISO 9001:2008, which is summarized as under:
• 15 November 2008 – date of publication of ISO 901:2008. Before this date, no accredited certificates to ISO 9001:2008 were allowed.
• On or after 15 November 2008, new certificates only after a routine surveillance or recertification audit against ISO 9001:2008.
• Up to 15 November 2009, certification and renewal to ISO 9001:2000 (old version) were permitted.
• Beginning 15 November 2009, no new certificates to ISO 9001:2000 (old version) are allowed. All audits to be conducted to ISO 9001:2008.
• From 15 November 2010, ISO 9001:2000 (old version) certificates will no longer be valid.

Transition to ISO 9001:2008
If we look to the changes in ISO 9001:2008 standard, there are no new requirements, so the transition to ISO 9001:2008 is simple, but not automatic. Organizations should take advantage of the changes to re-assess the value of their quality management system and accordingly, they should revise their quality management system documentation. Internal auditors need to be aware of the changes. They should use ISO 9001:2008 Annex B. Time is running fast, so ISO 9001:2000 certified organizations are required to act fast.

What is needed from existing internal auditor trained for ISO 9001:2000 QMS auditing?
The internal auditor should undergo a training to understand the underlying philosophy and principles, concepts and requirements of ISO 9001:2008 standard, and how to apply them within an audit context and also understand the key differences between the revised series of standards and the 2000 and 2008 versions, and understand the implications of these differences for effective auditing against the revised standard.


Do not forget
Consistent, conforming product (meeting customer and applicable statutory and regulatory requirements) and also enhancement of customer satisfaction and that should be the aim of your quality management system.

Thanks

The END ???
Learning is a process that never ends.

Wednesday, March 24, 2010

Publication Series प्रबंध प्रणाली बोध 'MANAGEMENT SYSTEMS AWARENESS'


Please see details on publication series being published by National Centre for Quality Management, Ajmer Centre. Please click the photo attached and see details. We seek your publication support contribution. Thanks.

Saturday, August 22, 2009

INCREASING THE POWER OF YOUR QMS – ACHIEVE PERFORMANCE EXCELLENCE THROUGH CONTINUAL IMPROVEMENT





K. R. Singhal

Hariharan Jairam once writes in the ‘Quality World’ – “Quality! Call it a concept, an approach, a way of life, a tool for achievement or merely a word. Whatever definition you give or whatever approach you take, this subject has made people think and think in a big way.” Girdhar J. Gyani says, “Quality today has many dimensions. Gone are the days when quality was identified with product alone.” Dr. R. H. G. Rau opines, “Management of quality is not a one-shot affair. It covers all transactions. Continuous creation of value addition is possible only when we manage change; that too proactively.” Continuous creation of value addition has now become the expectation of consumers. Presently ‘constant’ quality is no longer good enough and ‘continual improvement’ is needed.

There is a need of continual improvement in the effectiveness of the quality management system because:
- ‘Continual improvement’ is needed by customers because of their changing expectations
- ‘Continual improvement’ is one of the quality management principles on which your quality management system is based
- ‘Continual improvement’ is one of the requirements of ISO 9001:2008 QMS Standard and you are required to comply with it. Organizations, implementing ISO 9001:2008 QMS, must understand that continual improvement is a must requirement of the Standard.

‘Continual improvement’ is a recurring (step-by-step) activity followed by: (i) identifying opportunities for improvement and their justification, (ii) deciding how to improve on the available resources, and (iii) implementing (carrying out) improvement.

We need to improve the effectiveness of the quality management system, but how can we do such improvement, that’s a relevant question. In this regard ISO 9001:2008 QMS Standard mentions use of quality policy, quality objectives, audit results, analysis of data, corrective and preventive actions and management review to continually improve the effectiveness of the quality management system. Clause 8.5 of the ISO 9001:2008 QMS Standard specially deals with the requirements for improvement. Continual improvement is a defined requirement of the Standard. (Clause 8.5.1)

If you wish to improve the power of your quality management system, achieve performance excellence through continual improvement.

General requirements (Clause 4.1) of ISO 9001:2008 QMS Standard stipulate that the organization must continually improve the effectiveness of its QMS in accordance with the requirements of the Standard. The Standard also stipulates to ensure top management to include a commitment to comply with requirements and continually improve the effectiveness of the quality management system. (Clause 5.3)

Clause 5.5.2 of ISO 9001:2008 stipulates responsibility and authority of the management representative to report to the top management on the performance of the quality management system and any need for improvement. The requirements for management review (Clause 5.6.1) stipulate that management review must include assessing opportunities for improvement and need for changes to the quality management system, including the quality policy and quality objectives. Review input requirements (Clause 5.6.2) include information on recommendations for improvement. Review output requirements (Clause 5.6.3) include any decisions and actions related to improvement of the following:
- the effectiveness of the quality management system,
- the effectiveness of the processes, and
- product related to customer requirements.

ISO 9001:2008 QMS Standard takes care to determine and provide resources needed to continually improve the effectiveness of the quality management system. (Clause 6.1) The Standard also stipulates the requirements (Clause 8.1) for the organization to plan and implement monitoring, measurement, analysis and improvement processes. This is required to demonstrate conformity of the product, to ensure conformity of the quality management system and to continually improve the effectiveness of the quality management system.

Clause 8.5 of ISO 9001:2008 Standard specially deals with requirements for improvement. Continual improvement is a defined requirement of the standard (Clause 8.5.1). Accordingly, the organization is required to improve the effectiveness of the quality management system through the use of quality policy, quality objectives, audit results, analysis of data, corrective action, preventive action and management review.

Use of Quality Policy and Quality Objectives: Quality policy must include a commitment to comply with requirements and continually improve the effectiveness of the quality management system. It must also provide a framework for establishing and reviewing quality objectives. Quality objectives must be measurable and consistent with the quality policy of the organization. The organization must also ensure to review quality policy for continuing suitability. Framework for reviewing provides a way for improvement as review include assessing opportunities for changes to the quality management system, including quality policy and quality objectives. (Relevant Clauses of ISO 9001:2008 QMS Standard – 5.3, 5.4.1, 8.5.1)

Use of audit results: QMS audit is a systematic process and conducted at defined intervals. Audit evidences are input to QMS audit process and audit results are its output. Audit results become the input to management review process, which provides opportunities for improvement. When any nonconformity are detected during QMS audit, ISO 9001:2008 QMS Standard requires to eliminate such nonconformities and their causes. (Relevant Clauses of ISO 9001:2008 QMS Standard – 5.6.2, 8.2.2, 8.5.1)

Use of analysis of data: One purpose of analysis of data is to evaluate where continual improvement in the quality management system can be made. The organization is required to determine, collect and analyze appropriate data relating to customer satisfaction, conformity to product requirements, characteristics and trends of processes and products (including opportunities for preventive action), and suppliers. Analysis of data helps organization to solve problems and also helps to improve effectiveness and efficiency. Analysis of data can help organizations to determine the root cause of existing and potential problems, and therefore guide decisions about corrective and preventive actions needed for improvement. (Relevant Clauses of ISO 9001:2008 QMS Standard – 8.4, 8.5.1)

Use of corrective action: ISO 9001:2008 QMS Standard requires to take action eliminate the causes of nonconformities in order to prevent recurrence. Corrective action is a major tool in the quality management system to achieve improvement. It should be noted that corrective action is agenda item for management review. (Relevant Clauses of ISO 9001:2008 QMS Standard – 8.5.1, 8.5.2)

Use of preventive action: ISO 9001:2008 QMS Standard requires to take action to eliminate the causes of potential nonconformities in order to prevent their occurrence. Preventive action is a major improvement tool in the quality management system. (Relevant Clauses of ISO 9001:2008 QMS Standard – 8.5.1, 8.5.3)

Use of management review: Management review is conducted at defined intervals to ensure continuing suitability, adequacy and effectiveness of the quality management system. Management review includes assessing opportunities for improvement and need for changes to the quality management system. Output to management review to include any decisions and actions relating to – (i) improvement of the effectiveness of the quality management system, (ii) improvement of the effectiveness of the processes of the organization, (iii) improvement of product related to customer requirements, and (iv) resources needs of the organization. (Relevant Clauses of ISO 9001:2008 QMS Standard – 5.6, 8.5.1)

ISO 9000:2005, Quality management systems – Fundamental and vocabulary, identifies eight quality management principles to be used by the top management of the organization in order to lead the organization towards improved performance. Among eight principles stated in this fundamentals and vocabulary standard, continual improvement is one of the quality management principles. It states that continual improvement of the organization’s overall performance should be a permanent objective of the organization.

What is the aim of continual improvement? ISO 9000:2005 provides the answer. According to Clause 2.9 of ISO 9000:2005, the aim of continual improvement of the quality management system is to increase the probability of enhancing customer satisfaction and also satisfaction of other interested parties. Following actions are needed for improvement:
- Identifying areas of improvement through analysis and evaluation of the existing situation
- Establishing objectives for improvement
- Searching for and evaluating possible solutions to achieve the objectives
- Making a selection from the possible solutions and implementing the selected solution
- Measuring, verifying, analyzing and evaluating results of the implementation to determine whether the objectives have been met, and
- Formalizing changes

Results should be reviewed to determine further opportunities for improvement. Accordingly, improvement is a continual activity to be undertaken by the organization and the top management has the important role to play in this regard. To identify opportunities for improvement, following actions may be useful:
- Obtaining feedback from customers and other interested parties
- Audit results, and
- Review of the quality management system

Process for continual improvement is given in Annex B of ISO 9004:2000, a QMS guidelines Standard for performance improvement. It briefly describes the distinction between breakthrough improvement and small-step ongoing improvement. The distinction between the two may be understood as under:
(i) In small-step ongoing improvement there remains involvement of people working in the process, while in breakthrough improvement there remains involvement of cross-functional teams outside routine operation (such as managers, engineers, consultants)
(ii) In small-step ongoing improvement size of changes remain small, while these are big in breakthrough improvement.
(iii) In small-step ongoing improvement results show small improvements, while the results show big jump in performance in breakthrough improvement.
(iv) Cost is low (within operating budget) in small-step ongoing improvement, while cost is high (may involve additional capital investment) in breakthrough improvement.
(v) Types of changes in small-step ongoing improvement include modification in practices, procedures, equipment, elimination and simplification of activities, while types of changes in breakthrough improvement include process reengineering, major process upgrades, change in technology and addition of new equipment.

ISO 9004:2000 Standards provides steps involved in the method of continual improvement that include:
- Identification of a process problem
- Selection of area of improvement
- Noting the reason for improvement
- Evaluating effectiveness and efficiency of the existing process
- Collecting relevant data
- Analyzing relevant data to discover the generally occurring problems
- Selecting a specific problem
- Setting objective for improvement for such specific problem
- Identifying and verifying the root causes of the problem
- Identifying possible solutions as well as exploring alternative solutions
- Evaluating effects to conform that the problem and its root causes have been eliminated or their effects reduced
- Implementing and standardizing new solutions by replacing old process with improved process as a preventive action
- Evaluating effectiveness and efficiency of the process

Since the above steps provide improvement solution to a specific process problem, so the above steps should be repeated on remaining other identified problems, thereby making the improvement as real and effective.

John E. (Jack) West in his article ‘Continuous Improvement and Your QMS’ says, “Piecemeal improvements are no improvements at all.” He also suggests, “First, let’s review what continual improvement is and what it’s not. Continual improvement isn’t necessarily improving everything in the organization. However, it does not entail identifying and planning changes to those products, processes or systems that will improve the organization performance.”

John E. (Jack) West correctly opines, “Sometimes sustained improvement isn’t achievable unless several processes are changed. In the case of improving a product design, it might be necessary to change not only the design and development process but also the process for hiring designer’s, the capital allocation process and the process for understanding customer requirements. In such a case, overall systems changes are needed; just starting a new product design project may be the organization’s worst approach.”

It is necessary to create people awareness in the organization on continual improvement and this may be created by forming small groups, selecting their group leaders, allowing people to control and improve their workplace and developing people’s knowledge, experience and skills.

The role of the top management and management representative are important in continual improvement of the effectiveness of the quality management system and they should take effective steps to do so.


Courtesy Source References

- ISO 9001:2008 QMS Standard
- ISO 9004:2000
- ISO 9001 for small businesses – What to do (Joint publication from International Organization for Standardization and International Trade Centre UNCTAD / WTO)
- ISO 9001:2000 – A workbook for service organizations (Joint publication from International Organization for Standardization and International Trade Centre UNCTAD / WTO)
- ISO 9001 Fitness Checker – A practical, easy to use checklist designed to help SMEs assess their readiness for ISO 9001 certification
- Implementing ISO 9001:2000 Quality Management System – A Reference Guide, Dr. Divya Singhal and K. R. Singhal (Publication from PHI Learning Pvt. Ltd., New Delhi)
- Article ‘Standard Approach – Continuous Improvement and Your QMS’, John E. (Jack) West, Quality Digest, USA, April 2006
- Article ‘Increasing the power of quality management system: Performance excellence through continual improvement’, Publication series ‘Management Systems Awareness’ – Issue 5, August 2006
- Quality World, New Delhi
- Quality Striving for Excellence, NCQM, Mumbai

Note

Author’s profile may be seen at http://www.linkedin.com/in/krsinghal

Tuesday, August 18, 2009

INTERNAL AUDIT OF QUALITY MANAGEMENT SYSTEM



K. R. Singhal

Conducting internal audit is a vital tool to assess organization’s quality management system. The organization gets information in a planned way by conducting internal audit from a variety of sources. The purpose of conducting internal audit is to find out the answers to following questions:
- Is quality management system of the organization conformed to the planning of product realization carried out in the organization?
- Is the quality management system of the organization conformed to the requirements of ISO 9001:2008 QMS Standard?
- Is the quality management system of the organization conformed to the quality management system requirements established by the organization?
- Is the quality management system of the organization effectively implemented and maintained?

An internal audit is a tool to monitor and determine the health of the quality management system of the organization. For an organization, a properly conducted audit is beneficial and we need to conduct value added internal audit that is useful to the organization, auditee department, management representative and top management.

Clause 8.2.2 of ISO 9001:2008 QMS Standard deals with internal audit requirements. As per requirements of ISO 9001:2008 QMS Standard, an organization needs to conduct internal audit at planned intervals. An audit process should include the following aspects:
- Planning of internal audit – such as planning of audit schedule, assignment of auditors, auditee area, and scope of audit, status and importance of processes, results of previous audits.
- Examining and reviewing the quality management system documentation of the organization,
- Examining and reviewing other relevant information of the organization, such as production reports, failure trends, customer complaints, customer survey reports etc.
- Examining and reviewing the quality management system procedures and processes by visiting the audit area spot, interviewing relevant personnel and looking to relevant processes.
- Reporting the internal audit results (including corrective action requests from auditors).
- Verifying corrective actions taken.

An organization should have a documented procedure for conducting internal audit that define and narrate the following aspects:
- Audit criteria
- Scope of the audit
- Frequency of audit
- Audit methods
- Responsibilities and requirements for planning and conducting internal audit
- Relevant audit records (including results of audit) to be established and maintained
- Reporting results of the audit.


Chandrakant Agrawal, Manager (Risk and Compliance team), points out the following to add the value of internal audit:
(i) One more item that would be added is usage of checklist as a tool to make sure all aspects are covered. Also focus on documentation and continuous improvement should be there.
(ii) The Corrective action log would be the most valuable source to support the focus on Quality from the team's perspective.
(iii) The team awareness on policies and procedures and the feel of Quality should also be part of the audit process.
(iv) Sharing of Best practices should also be output of audit so that all involved are benefited.



Does ISO 9001:2008 QMS Standard mention specific frequency of internal audit? How frequently does an organization need to perform internal audits? Is it fair to conduct internal audit once in two years?
ISO 9001:2008 QMS Standard does not mention specific frequency of internal audit. Requirements of ISO 9001:2008 QMS Standard say conducting internal audit at planned intervals. As such the Standard binds the organization to conduct internal audit at planned intervals. It is up to the organization to decide the frequency of internal audit.

How frequently does an organization need to perform internal audits? It is very relevant question. Internal audits need to be performed to cover all quality management system activities the organization undertake and all the ISO 9001:2008 Standard requirements. In deciding the frequency of internal audits, the organization should consider following factors:
- Complexity of procedures and processes
- Maturity level of the organization’s quality management system
- Nature of business activity
- Problematic aspects and areas as per history
- Organization approach for monitoring and improvement
- Frequency of management review

Jan A. de Ridder, Senior Consultant, QA en Lean professional, says, “Frequency depends on many things. In my opinion it is fair to audit Clause 5.5 every two years, unless there are changes in the organization. Clause 8.3 should be audited more or less continuously. When requirements are not met, frequency should increase. I used to audit the whole system and every area in a 3 year cycle. Some places were visited more often than others. One should wonder how audits can be performed effectively, but also efficiently. I used to discuss frequency with the responsible manager. Is he/she happy with the outcome and the number of audits? After all he is the internal customer of the auditor.”

Richard Sledgister, an Engineer, says, “The frequency of a company’s internal audits should accomplish the following goals: 1) assess standard conformance, 2) drive RCCA (Root Cause Corrective Action) and 3) drive continuous improvement. Audits should measure the overall effectiveness of a QMS (Quality Management System) in a company and or a specific facility within a company. Audits should also focus on specific areas in which the planned method (standard work) is not being executed properly, high warranty costs are being incurred, a high scrap rate exists, processes are not in statistical control and or other performance metrics are not being achieved. These are all signs of poor quality. The audit frequency should be adjusted to focus on areas needing continuous improvement as this is an efficient use of resources. The cost of poor quality will be reduced and profitability will be enhanced.”

Sandeep Sharma, a Quality engineer, says, “I think it must be finished just before the external audit, if we will get the NC's, there will be time to resolve all the issues.”


On considering above points, it is now clear that it will be unfair to conduct internal audit once in two years as the time gap between two internal audits will be too long.

What should be done after getting results of internal audit?
The organization gets information about the areas which need correction and/or improvement from the results of internal audit. The information from internal audit results becomes input for the management review.

Who should perform internal audits?
Internal QMS auditors should perform internal audits. ISO 9001:2008 QMS Standard has two relevant important requirements:
- Selection of auditors must ensure objectivity and impartiality of the audit process
- An auditor must not audit his/her own work.

Clause 6.2.1 of ISO 9001:2008 QMS Standard mentions the requirement of competent personnel performing work affecting conformity to product requirements on the basis of appropriate education, training, skills and experience. Accordingly, the personnel conducting internal audit must be competent to audit for which the organization should refer to the relevant guidelines as mentioned in ISO 19011 Standard and take appropriate steps to provide appropriate training to personnel selected as auditors for internal audit.

Suggested Reading: Chapter 12 – Value Added Audit, Implementing ISO 9001:2000 Quality Management System – A Reference Guide, Dr. Divya Singhal and K. R. Singhal (Published by PHI Learning Pvt. Ltd., New Delhi – 110001, India)

Courtesy Source References
- ISO 9001:2008 QMS Standard
- ISO 9004:2000
- ISO 9001 for small businesses – What to do (Joint publication from International Organization for Standardization and International Trade Centre UNCTAD / WTO)
- ISO 9001:2000 – A workbook for service organizations (Joint publication from International Organization for Standardization and International Trade Centre UNCTAD / WTO)
- ISO 9001 Fitness Checker – A practical, easy to use checklist designed to help SMEs assess their readiness for ISO 9001 certification
- Implementing ISO 9001:2000 Quality Management System – A Reference Guide, Dr. Divya Singhal and K. R. Singhal (Publication from PHI Learning Pvt. Ltd., New Delhi)
- Discussion at Linkedin.com Groups



Note
Author’s profile may be seen at http://www.linkedin.com/in/krsinghal