Showing posts with label ISO 9001:2008. Show all posts
Showing posts with label ISO 9001:2008. Show all posts

Wednesday, June 17, 2009

Internal Auditing Tips

On this page we will be adding tips to assist you in your auditing efforts.

Free Tip #1:
Contact auditees at least four times about their scheduled audit. The first contact would come when the annual audit schedule is generated. The second should be about one month prior to the audit. This allows the auditee time to prepare for any additional resources necessary (They shouldn't need extra time to "get their areas squared away".). The third contact should be about a week before the audit. At this time, you can give the auditee a detailed schedule about exact times, and locations of audit activities. For example, you will be auditing receiving inspection at 10:45. Each of these contacts should be in writing (email is just as good). The day before the audit, place a quick phone call (or voicemail) to verify the audit.

Of course, you still need to have an opening meeting, and that is in addition to the above. The reason for the multiple contacts is simply, we tend to forget things due to our work load. Audits should never be a surprise, this ensures the auditee has every chance to prepare.

Free Tip #2:
When preparing the audit schedule take into account such things as:

:: Available resources
:: Audit Scope
:: Sample Size

The key is not to bite off more than your auditors can chew [Translation: Don't over-commit your resources]. Smaller, but more frequent audits may be better than comprehensive three-day audits. Inadequate resources may indicate lace of Executive Management commitment.

Free Tip #3:
One of the hardest things to do is get a quick turn-around time on corrective actions. Auditors are frequently frustrated by lower and mid-management's foot dragging on responding to audit findings. One way to get faster action is to have executive management place effective corrective action turn-around time in management's performance appraisals. By tying in corrective actions to performance appraisals, bonuses, etc., you virtually force management into timely, effective corrective actions. This could also work with audits completed on time, etc. It also shows lower and mid-management that executive management is committed to the process.

Free Tip #4:
If you company has email…try to set up a paperless audit system where the only thing you would need to "print out" and hand write would by your audit worksheet, which you take withy you to collect your evidence/samples. We have a paperless system here - we are able to email out notification forms and audit summaries without ever printing a sheet. It works EXCELLENTLY! We even File our paperless paperwork electronically for when our third -party auditors come to audit!
Write your procedures in Flowchart style. This helps to make the workflows appear that much clearer for new and veteran auditors alike. By having all of our procedures in flowchart style, we have cut down on our audit time by half and increased audit accuracy tremendously!
Jill Chavanne, Internal Audit Program Manager, Weiss-aug. Co

Free Tip #5:
Auditors are frequently frustrated by lower and mid-management's foot dragging on responding to audit findings. One way to improve the timeliness of audit finding responses is to issue reminder notifications. Our audit finding response due dates are normally two weeks from the issue date of the finding. I typically issue two "Reminder of Approaching due date" notifications, one at 50% of allotted response time and the other at 75%. This method can be modified to fit your particular system, i.e. issuing only one notice for lessor response time allotments. This documentation can be in the form of a manual memorandum/form or the more efficient e-mailed memorandum/form. Issuing reminder notifications demonstrates a monitored system and can also prove useful if elevation of the finding becomes necessary.
David A. Wimer, BAE SYSTEMS

Free Tip #6:
"Be sure to follow-up on corrective actions from previous audits: don't only audit to see the corrective actions have been implemented. Make sure the corrective action corrected the problem that caused the corrective action in the first place."

Betsy Hsiao, Quest Analytical

Editor's note: One theme Internal-Auditor.com has pushed over and over again is the output of audit nonconformances should be effective corrective actions. My good friend Betsy is absolutely correct. This is one area where many internal audit programs are weak. We don't want to upset the auditee when the corrective action is ineffective, so we overlook the situation. Read the observation again, study it, and do it!

Free Tip #7:
In order to have an effective Corrective Action, Nonconformities must have three attributes:

They must be Understandable: If the auditee does not understand the nonconformity, they will not know how to deal with it.
They must be Actionable: If there is no action that can be taken, the Corrective Action cannot be achieved.
They must be Unarguable (that is not a word, but it fits): If an auditee can argue ANY part of a nonconformity, they will argue rather than correct.

Free Tip #8:
Auditing is all about asking questions. As an auditor, you have to make sure you ask the right person, the right question. You also have to make sure YOU understand the question you are about to ask. If you don't understand the question, how can you expect to understand the answer. You must also ask questions in a manner that the auditee will understand them.

Source: www.internal-auditor.com/tips.htm

Tuesday, May 26, 2009

ISO 9000 Essentials

The ISO 9000 family of standards represents an international consensus on good quality management practices. It consists of standards and guidelines relating to quality management systems and related supporting standards.

ISO 9001:2008 is the standard that provides a set of standardized requirements for a quality management system, regardless of what the user organization does, its size, or whether it is in the private, or public sector. It is the only standard in the family against which organizations can be certified – although certification is not a compulsory requirement of the standard.

The other standards in the family cover specific aspects such as fundamentals and vocabulary, performance improvements, documentation, training, and financial and economic aspects.

Why an organization should implement ISO 9001:2008
Without satisfied customers, an organization is in peril! To keep customers satisfied, the organization needs to meet their requirements. The ISO 9001:2008 standard provides a tried and tested framework for taking a systematic approach to managing the organization's processes so that they consistently turn out product that satisfies customers' expectations.

How the ISO 9001:2008 model works
The requirements for a quality system have been standardized - but many organizations like to think of themselves as unique. So how does ISO 9001:2008 allow for the diversity of say, on the one hand, a "Mr. and Mrs." enterprise, and on the other, to a multinational manufacturing company with service components, or a public utility, or a government administration?

The answer is that ISO 9001:2008 lays down what requirements your quality system must meet, but does not dictate how they should be met in any particular organization. This leaves great scope and flexibility for implementation in different business sectors and business cultures, as well as in different national cultures.

Checking that it works
  • The standard requires the organization itself to audit its ISO 9001:2008-based quality system to verify that it is managing its processes effectively - or, to put it another way, to check that it is fully in control of its activities.
  • In addition, the organization may invite its clients to audit the quality system in order to give them confidence that the organization is capable of delivering products or services that will meet their requirements.
  • Lastly, the organization may engage the services of an independent quality system certification body to obtain an ISO 9001:2008 certificate of conformity. This last option has proved extremely popular in the market-place because of the perceived credibility of an independent assessment.
The organization may thus avoid multiple audits by its clients, or reduce the frequency or duration of client audits. The certificate can also serve as a business reference between the organization and potential clients, especially when supplier and client are new to each other, or far removed geographically, as in an export context.

Source: iso.org/iso/iso_catalogue/management_standards

Thursday, May 14, 2009

Abstract ISO 9001:2008

ISO 9001:2008 specifies requirements for a quality management system where an organization.
  • needs to demonstrate its ability to consistently provide product that meets customer and applicable statutory and regulatory requirements, and
  • aims to enhance customer satisfaction through the effective application of the system, including processes for continual improvement of the system and the assurance of conformity to customer and applicable statutory and regulatory requirements.
All requirements of ISO 9001:2008 are generic and are intended to be applicable to all organizations, regardless of type, size and product provided.
Where any requirement(s) of ISO 9001:2008 cannot be applied due to the nature of an organization and its product, this can be considered for exclusion.
Where exclusions are made, claims of conformity to ISO 9001:2008 are not acceptable unless these exclusions are limited to requirements within Clause 7, and such exclusions do not affect the organization's ability, or responsibility, to provide product that meets customer and applicable statutory and regulatory requirements.
Source : iso.org