ISO Certification



             


Saturday, March 1, 2008

ISO 9001 - 2000 -- Implement Your Quality Management System With Minimum Headaches

If you have been unlucky enough to have been saddled with the onerous task of achieving ISO 9001:2000 compliance for your company, this article may prove to be your big break. At the very least it will put you on a minimum fuss path to ISO 9001 certification. It may very well also rescue your career, because--as you already know--as a great deal is riding on your success.

ISO, of course, stands for the International Organization of Standardization, a worldwide organization responsible for the development of many different kinds of standards. ISO 9001:2000 is the most recent version of their Quality Management System Standard. It consists of a collection of documentation that describes how a company should implement their quality management system.

To achieve certification, a company must produce both a Quality Manual and a Quality Procedures Manual. This is no light undertaking. These manuals must be audited by a registrar for compliancy, and renewed at the end of each 3 year period. The larger and more complex your company, the more difficult the process will be.

So why would a company chose to conform to an ISO 9001 profile? Rarely is it because it seems like a good idea. Many companies are filled with bright people who can develop their own quality management system. The primary motivating force is market pressure. Your quality management system may well be up to scratch, but who is to say?

A potential customer surveying the marketplace, and presented with two or more competing companies he might choose to do business with, needs to feel good about his final choice. If the decision comes down to who has the best quality management system in place, common sense suggests he go with the company that has gone through the ISO 9001 certification process.

In the long run, an organization that implements an ISO 9001 system is likely to discover the company runs better, with improved performance and higher profitability. But for a company just getting started, such considerations are often seen as "ideals" that get short shrift as managers race to make the company profitable in the shortest amount of time. It therefore takes commitment and foresight, as well as an acute understanding of market vision in order to get to the ISO 9001 finish line.

If your company already has a decent quality management system in place, your main task will be to redesign the system so that it addresses all the sticking points of the ISO 9001 documentation. If your company is large, this may prove to be some not insignificant undertaking.

You might be tempted to hire ISO 9001 consultants. This will be expensive, and may not in fact lead to the desired result, which is a streamlined version of the Quality Manual and Quality Procedures Manual that you must submit for certification.

The reason for this is that consultants never fully appreciate the scope and depth of your company, and cannot be expected to share the urgency of your plight to get it right the first time. For this reason, choosing the right in-house person to head the job may be the best option for your company. Perhaps, even, that person is you. If so, you definitely have your work cut out for you, particularly if you work for a company of any real size.

The benefit, and it is a big one, of having been tasked with preparation for ISO 9001 certification is that your personal value to the company is going to be cemented--no, it will be cast in iron--by a successful conclusion to certification.

The trick then, is to find a way to achieve the desired result WITHOUT saddling yourself with all the headaches this job can provide. If you have already peeked at the ISO 9001:2000 documentation you can be forgiven for thinking that you may have bit off more than you can chew. Going from zero to sixty on this task can seem like a formidable proposition.

But it need not. If it seems like you are destined to begin dreaming that you personally will be taking the ISO 9001 certification test, night after restless night, instead of your quality management system, take heart. Because there is a way to get a jump start on the process, and avoid so much of the hassle that you have taken on.

To find out how to leverage the ISO 9001 proficiency of an already successfully certified company, and dramatically cut your expected ISO 9001 development costs by slashing the time it takes to achieve certification, get across to my Squidoo lens on Isom's Quality Handbook For ISO 9001 Certification. This may prove to be the best decision you have made this year!

Labels: , , , , ,

ISO 9001: The Three Components of the Implementation Process

The three components to implementing an ISO 9001 quality management system are: 1) documentation, 2) information management, and 3) operational changes.

Documentation

On the surface it may seem like developing the ISO 9001 documentation shouldn?t be that difficult. You must have a manual that includes a policy, objectives, scope, and the interaction of the processes; and you must have written instructions for:

  1. Managing the quality system documents
  2. Managing the quality system records
  3. Conducting internal audits
  4. Controlling nonconforming product
  5. Implementing corrective action
  6. Implementing preventive action

The standard also hints at the need for additional instructions, e.g., referring to the work instructions, section 7.1 states ?shall determine the following, as appropriate,? but technically, aside from the manual and these six instructions, anything more is optional.

The reality, however, is that in order to get the most out of a quality management system a significant amount of additional documentation is required. A primary function of the system is to establish consistency and eliminate misunderstandings, which is best facilitated with clear and unambiguous written instructions. Policies, which are a pervasive part of any system, have absolutely no value if they're not in writing, and enforcing accountability is extremely difficult if the responsibilities are not spelled out.

The ISO 9001 system documentation is normally organized into four sections, including:

  1. The Manual, which provides background information and explains how the system works;
  2. The Administrative Procedures, which include the procedures and policies that define how the company complies with the requirements of the standard and how it manages the processes that are unique to its operation;
  3. The Operating Instructions, which are the detailed instructions used to control manufacturing and service activities; and
  4. The Reference Documentation, which are documents like industry standards, equipment maintenance manuals, corporate auditing guidelines, employee policies, etc. that define practices, procedures, or performance criteria not covered by the other documents. These can either be externally or internally generated.

No two organizations have the same goals and objectives or do things exactly the same way, which means there are always some differences between the procedures and policies of different organizations. It also means that completely documented ?off-the-shelf? systems don?t exist and some document development is inevitable. The challenge is to minimize the effort without sacrificing value.

The Manual ? The administrative procedures are usually the more difficult and time-consuming of the four sections to develop. The manual, on the other hand, is relatively straightforward and probably the easiest part to develop. The standard suggests what should be included, and an example of a ?well written? manual can provide the format for organizing the material. Most of the work is in converting the ideas of the example into documents that describe your situation. Goals and objectives have to be established, processes defined, responsibilities established, the interaction of the processes explained, and the system parameters established.

Administrative Procedures ? The secret to developing administrative procedures is 1) using a format that creates readable documents, 2) finding examples of procedures that offer solutions that apply to your needs, and 3) organizing the documentation based a process list.

The ?process approach? is the system structure recommended by the authors of the standard and the process list is the starting point of the process approach.

Think of processes as objectives, i.e., maximizing employee output, making sure new products comply with customer requirements, or making sure working conditions adequately support the production objectives. A set of procedures that constitute a means for meeting an objective is what the standard refers to as an ?activity group?. Employee vetting, performance reviews, and training procedures is an examples of an activity group that maximizes employee output. The objectives are the outputs of the ?process approach? and the procedures (the activity groups) the inputs. Example:

Input = Policies and procedures for making sure employees are motivated, informed, and capable of performing the assigned responsibilities

Output = Maximum employee output

The process list is simply a list of those objectives that best represent the needs of your organization. They can be different for every organization and are rarely in sync with the outline of the standard.

The format used for developing the procedures, to a large extent, determines whether employees will embrace the system. It can be the difference between documents that are easy to read and ones that are not. The better formats include a clear propose, policies that are relevant to the purpose, and an explanation why things are done the way they are done. A good format also leaves no doubt as to who is accountable for the actions of the procedures.

Examples of procedures from other systems provide ideas on how to develop new procedures and how to improve existing procedures. The same examples can also provide formatting ideas. Don?t fall into the trap of thinking that there must be a procedure of every requirement of the standard, or that the documentation has to follow the outline of the standard. The authors of the standard have made it clear that this is not the case. You are encouraged to use a process approach, which is inherently unique to your operation, and to include processes that are important to you but may not included in the standard.

While individual examples can be helpful, continuous system templates that lock into the outline of the standard tend to complicate the implementation process. They depersonalize the system, limit the system to the scope of the standard, and make the process of writing procedures more difficult. Also, don?t go overboard on process mapping and flowcharting. Procedures should be clear to everybody, not just the primary users. A fundamental covenant of the system is continual improvement and some of best improvement ideas come from employees with unrelated responsibilities.

Operating Procedures ? The trick to developing operating procedures is in understanding the balance between training and documentation requirements, and in knowing how much information is needed. Too many companies develop too much unnecessary detail.

The standard requires employers to provide employees with the information needed to correctly perform their assigned responsibilities. Proof is either documentation showing that they have been provided the necessary instructions, or training records, which also verifies that they have been provided the necessary instructions. The value of written operating instructions is that they make it easier to hold employees accountable for their actions. From this standpoint, it is only necessary to document those aspects of an operation that are subject to misinterpretation or misunderstanding, which normally doesn?t require a great deal of detail.

Information Management

Managing information is a big part of the standard. The standard states that records shall be maintained in the case of management review meeting minutes (5.6.1); education, training, skills and experience (6.2.2); product validation and verification (7.1.d); inputs for product design and development (7.3.2); and calibration records (7.6). In addition, the standard also requires ?evidence of conformity?, which is either physical evidence or documented records, and in many cases records are preferable and sometimes the only alternative.

Records provide a means of confirming that the quality system is controlled, customer requirements are understood, audits are conducted, customers are heard, problems are found and corrected, non-conforming goods are managed, purchasing information is correct, products are traceable, and incoming goods are inspected.

The method of managing information is generally some combination of 1) a file management program, 2) database files such as Microsoft Access, or 3) hard copy files, i.e., binders, file cabinets and manila folders, all of which have advantages and disadvantages.

File Management Programs ? File management programs are typically tamper-proof and capable of handling a large volume of information. They?re designed to be paperless systems. Assignments, authorization levels, and additions and revisions to records are keyed into the program, which, under certain conditions, trigger action commands that are communicated via email. There are a few programs tailored to manage primarily ISO 9000 records, but most are universal in nature and designed to manage all types of records. The user is normally responsible for developing the forms and reports needed to manage specific types of records.

The programs are expensive; they come with annual and sometimes monthly maintenance fees; and there are usually costs associated with installation, the number of users, data migration, and training. Many have their own programming language, which makes the user dependent on people with that language skill. And some are web based, which means the program is running on someone else?s server. Generally, they are best suited for companies with a lot of people dealing with a large volume of information.

Database Files ? Database files are less expensive, more flexible, and easier to manage. You can either develop your own files or purchase files that have been programmed to deal with specific types of records.

The majority use Microsoft Access and run on a Microsoft Windows operating system. The cost is the cost of the files plus the cost of the Microsoft programs. (The 9000 Advisers offer individual Access files for all the ISO 9001 record keeping requirements.) The files are placed on a server and secured by whatever means is used to secure the server files. Changes and enhancements can be made by anyone who understands Microsoft Access. In most cases there are no user fees or reoccurring maintenance fees, and existing database files can be transferred into the files with the migration functions of the Access program.

Hard Copy Records ? Almost everyone ends up with some hard copy records: documents that can?t be scanned, documents with signatures, and documents that are available to all employees. However, building a record keeping policy completely around this approach is risky, even for small companies. It is too easy to misplace documents that move from one person to the next; and it is difficult to manage information that is located in various files, in different offices, and assigned to different people. Responsibilities change and individuals tend to change the way information is gathered and filed. Manual record keeping frequently results in unnecessary duplication, e.g., sales using a different customer list than the person keeping track of the customer complaints. It is also difficult to gather, analyze, and disseminate information. File cabinets are not as accessible as computers and don?t have the sorting, reporting, linking and analytical capabilities of database files.

Operational Changes

The final component of the implementation process is the operational changes, which are the changes needed in order to meet the procedural requirements of a system. They include both the things that are done in order to ensure that the products and services comply with the requirements specified by the customer, as well as the measure taken to in order to improve products and services and the processes used to produce the products and services.

Some of the more common ones include:

Administration ? 1) Conduct at least one management review meeting. 2) Communicate system developments to all employees. 3) Demonstrate that the key performance indicators are measured, evaluated, and communicated.

ISO Representative ? 1) Make sure that the auditors are adequately trained. 2) Develop an audit schedule and conduct audits on all of the system procedures. 3) Demonstrate that the corrective and preventive action processes are working. 4) Make system procedures and forms available to employees.

Human Resources ?1) Verify that all employees have a basic understanding of the ISO 9000 system. 2) Prove that all employees are capable of performing their respective work assignments, including the top-level executives. 2) Establish a training program for developing employee skills.

Purchasing ? 1) Demonstrate that all of the primary vendors are qualified and that their performance is routinely evaluated. 2) Prove that material specifications are verified before they are released to vendors.

Sales/Customer Service ? 1) Demonstrate that customer feedback is gathered and analyzed, including records of complaints. 2) Prove that processing capabilities are reviewed before orders for new products are confirmed.

Engineering ? 1) Demonstrate that the information released to production is current, accurate, and complies with customer requirements. 2) Demonstrate that product changes affecting form, fit, or function are not implemented without customer approval.

Production ? 1) Establish a calibration program that complies with the requirements of the standard. 2) Demonstrate that machinery capabilities have been validated. 3) Prove that nonconforming materials are not mixed in with satisfactory materials. 4) Prove that that shipments comply with the customer requirements. 5) Prove that incoming materials comply with purchase specifications. 6) Prove that operators are provided with the information required to produce products that conform to customer requirements. 7) Demonstrate how materials with shelf life are managed.

System documentation and information management are the paperwork part of the system. The operational changes are the action part and represent the part of the implementation process that makes the system work.

John is founder and president of http://9000advisers.com/ : a consulting firm specializing in implementing ISO quality management systems. He has over thirty years of manufacturing management experience in the metalworking industry and another six years of consulting experience implementing quality and costing systems. He has a BS in Metallurgical Engineering and an MBA.

Labels: , , , , , ,

Wednesday, February 27, 2008

History of ISO 9000

ISO 9000 grew out of BS 5750, a standard published by the British Standards Institution (BSI) in 1979. Initially, it was used only in manufacturing industries. ISO 9000 is now employed across a variety of other types of businesses. It is a set of international standards of quality management systems. ISO 9000 has been accepted by more than 100 countries as their national quality assurance standard by the end of 1997.

The history of ISO 9000 dates back to Mil-Q-9858a, the first quality standard for military procurement established in 1959 by the US. By 1962, NASA (National Aeronautics and Space Administration) developed its quality system requirements for suppliers. In 1965, NATO (North Atlantic Treaty Organization) accepted the AQAP (allied quality assurance procedures) specifications for the procurement of equipments.

During the 1970s, BSI published BS 9000 (the first UK standard for quality assurance) and BS 5179 (guidelines for quality assurance) norms. In 1979, it created BS 5750, a series of standards for use by manufacturing companies. They were enforced through assessments and audits. In 1988, ISO (International Standards Organization) adopted the BS 5750 standard without changes and published it globally under the name ISO 9000. The ISO adopted this standard with a view to create an international definition of the necessary characteristics of a quality system for all businesses, regardless of industry. In 1994, the ISO revised the ISO 9000 standard and published it globally.

In the beginning, ISO 9000 was implemented exclusively by large companies. But by mid-1990s, small and mid-sized companies began to increasingly implement these standards. In the United States, the total number of registrations increased from a little more than 2,200 in 1993 to more than 17,000 in 1998. Of these 17,000 registrations, almost 60 percent were held by businesses with annual sales of $100 million or less.

ISO 9000 provides detailed information on ISO 9000, ISO 9000 Standards, ISO 9000 Software, ISO 9000 Consulting and more. ISO 9000 is affiliated with Home Inspections.

Labels: , , , , , ,

Wednesday, November 28, 2007

ISO 9001 Registration - 8 Steps for Success

 

You’ve made the plans, built the quality system and conducted the audit. So how do you register your company as ISO 9001 conformant? And how can you be sure you’re getting the most value for your investment? Here’s how the process works.

Certifying Your Company and Quality System

After your company's ISO 9001 audit, you will want to register your company's quality system to show that you've met the requirements. And to do this effectively, you will need to follow eight essential steps.

1. Finding a Registrar

You’ll need to begin searching for an ISO registrar during the 2 to 3 months your company is still building its quality system. You can search the Registrar Accreditation Board (RAB) at http://www.rabnet.com to select the registrar right for you.

2. Selecting a Registrar

Select a registrar that has experience within the scope category of your specific industry, which you can also find on the RAB site. Keep in mind accreditation, scheduling issues, fees and comfort level when selecting the registrar right for you.

3. Creating an Application

A company and a registrar will agree on the application, contract. This defines the rights and obligations of both parties, and includes liability issues, confidentiality and access rights.

4. Conducting a Document Review

The registrar will require a copy of your quality manual and procedures to verify that all the requirements of the standard are addressed. Allow 2-4 weeks in advance for the registrar to fully review all of the necessary documents.

5. Determining Preassessment

Though optional, this 2-4 week initial review of the system identifies any significant omissions or weaknesses. It saves time and allows the registrar to assess any issues and resolve logistics before the actual assessment audit.

6. Issuing an Assessment

During the audit, or physical onsite inspection of procedures in action, the auditors will issue findings if they assess anything that doesn’t meet requirements, or nonconformities. The length of this step will depend on the scope of the audit and the size your organization.

7. Completing ISO Registration

After all of the findings are put into the audit report and nonconformities are addressed, your company has the option to register as ISO 9001 conformant. You will receive a certificate and can also be listed in a register, which the company can use to publicize its registration and use in advertising.

8. Checking with Surveillances

To ensure that the system is maintained and that changes don’t result in deficiencies in the system, registrars perform regular surveillances of the system. Over the three-year period of your certificate, auditors will perform one full and two partial checks of your system.

Considerations in Planning

The Document Review and Preassessment typically require 2-4 weeks each. However, the number of registrars and the number of days for each stage of the registration audit depends on the size and complexity of your organization. So set target dates accordingly to allow both you and the registrar time to fully prepare.

Strong Return on Your Internal Audit Investment

Always keep in mind, registration should provide you with valuable feedback to improve your system. So make sure to seek the appropriate registrar, and take full advantage of the entire audit process. After all, it’s your company, it’s your registration, and so make sure you get a strong return on YOUR investment.

Chris Anderson has over 18 years of sales, marketing and business management experience working with business process design, software and systems engineering. He is also co-author of policies and procedures manual products, producing the layout, process design and implementation to increase performance. He is currently the Managing Director of Bizmanualz, Inc. Visit: Bizmanualz, Inc.

Labels: , , , , , , ,