Friday, December 25, 2009

Revision Of Documents In ISO 9000 Standards


Revision Of Documents In ISO 9000 Standards
The ISO 9000 Standard requires that documents be updated as
necessary and re-approved following their review.
Following a document review, action may or may not be necessary. If the
document is found satisfactory, it will remain in use until the next review. If the
document is found unsatisfactory there are two outcomes.
The document is no longer necessary and should be withdrawn from use –
this is addressed by the requirement dealing with obsolescence.
The document is necessary but requires a change – this is addressed by this
requirement.
The standard implies that updating should follow a review. The term update
also implies that documents are reviewed only to establish whether they are
current when in fact document reviews may be performed for many different
reasons. A more appropriate term to update would be revise. Previously the
standard addressed only the review and approval of changes and did not
explicitly require a revision process. However, a revision process is executed
before a document is subject to re-approval.
This requirement responds to the Continual Improvement principle.
It is inevitable that during use a need will arise for changing documents and
therefore provision needs to be made to control not only the original
generation of documents but also their revisions.
The document change process consists of a number of key stages some of
which are not addressed in ISO 9001.
a. Identification of need (addressed by document review)
b. Request for change (not addressed in the standard)
c. Permission to change (not addressed in the standard)
d. Revision of document (addressed by document updates)
e. Recording the change (addressed by identifying the change)
f. Review of the change (addressed under quality planning)
g. Approval of the change (addressed by document re-approval)
h. Issue of change instructions (not addressed in the standard)
i. Issue of revised document (addressed by document availability)
As stated previously, to control documents it is necessary to control their
development, approval, issue, change, distribution, maintenance, use, storage,
security, obsolescence or disposal and we will now address those aspects not
specifically covered by the standard.
In controlling changes it is necessary to define what constitutes a change to a
document. Should you allow any markings on documents, you should specify
those that have to be supported by change notes and those that do not.
Markings that add comment or correct typographical errors are not changes
but annotations. Alterations that modify instructions are changes and need
prior approval. The approval may be in the form of a change note that details
changes that have been approved.
Anyone can review a document but approved documents should only be
changed/revised/amended under controlled conditions. The document
review will conclude that either a change is necessary or unnecessary. If a
change is necessary, a request for change should be made to the issuing
authorities. Even when the person proposing the change is the same as would
approve the change, other parties may be affected and should therefore be
permitted to comment. The most common method is to employ Document
Change Requests. By using a formal change request it allows anyone to request
a change to the appropriate authorities.
Change requests need to specify:
a. The document title, issue and date
b. The originator of the change request (who is proposing the change, his or her
location or department)
c. The reason for change (why the change is necessary)
d. What needs to be changed (which paragraph, section, etc. is affected and
what text should be deleted)
e. The changes in text required where known (the text which is to be inserted
or deleted)
By maintaining a register of such requests you can keep track of who has
proposed what, when and what progress is being made on its approval. You
may of course use a memo or phone call to request a change but this form of
request becomes more difficult to track and prove you have control. You will
need to inform staff where to send their requests.
On receipt of the request you need to provide for its review by the change
authority. The change request may be explicit in what should be changed or
simply report a problem that a change to the document would resolve.
Someone needs to be nominated to draft the new material and present it for
review but before that, the approval authorities need to determine whether
they wish the document to be changed at all. There is merit in reviewing
requests for change before processing in order to avoid abortive effort. You
may also receive several requests for change that conflict and before processing
you will need to decide which change should proceed. While a proposed
change may be valid, the effort involved may warrant postponement of the
change until several proposals have been received – it rather depends on the
urgency
Ensuring the availability of controlled documents
The standard requires that relevant versions of applica-
ble documents are available at points of use.
The relevant version of a document is the version
that should be used for a task. It may not be the latest
version because you may have reason to use a
different version of a document such as when
building or repairing different versions of the same
product. Applicable documents are those that are
needed to carry out work. Availability at points of use
means the users have access to the documents they
need at the location where the work is to be
performed. It does not mean that users should possess copies of the documents
they need, in fact this is undesirable because the copies may become outdated
and not withdrawn from use.
This requirement exists to ensure that access to documents is afforded when
required. Information essential for the performance of work needs to be
accessible to those performing it otherwise they may resort to other means
of obtaining what they need that may result in errors, inefficiencies and
hazards.
In order to make sure that documents are available you should not keep them
under lock and key (or password protected) except for those where restricted
access is necessary for security purposes. You need to establish who wants
which documents and when they need them. The work instructions should
specify the documents that are required for the task so that those documents
not specified are not essential. It should not be left to the individual to
determine which documents are essential and which are not. If there is a need
for access out of normal working hours, access has to be provided. The more
copies there are the greater the chance of documents not being maintained so
minimize the number of copies. A common practice is to issue documents to
managers only and not the users. This is particularly true of management
system documents. One finds that only the managers hold copies of the
Quality Manual. In some firms all the managers reside in the same building,
even along the same corridor and it is in such circumstances that one invariably
finds that these copies have not been maintained. It is therefore impractical to
have all the copies of the Quality Manual in one place. Distribute the
documents by location, not by named individuals. Distribute to libraries, or
document control centres so that access is provided to everyone and so that
someone has responsibility for keeping them up to date. If using an intranet,
the problems of distribution are less difficult but there will always be some
groups of people who need access to hard copy.
The document availability requirement applies to both internal and external
documents alike. Customer documents such as contracts, drawings, specifica-
tions and standards need to be available to those who need them to execute
their responsibilities. Often these documents are only held in paper form and
therefore distribution lists will be needed to control their location. If documents
in the public domain are required, they only need be available when required
for use and need not be available from the moment they are specified in a
specification or procedure. You should only have to produce such documents
when they are needed for the work being undertaken at the time of the audit.
However, you would need to demonstrate that you could obtain timely access
when needed. If you provide a lending service to users of copyrighted
documents, you would need a register indicating to whom they were loaned so
that you can retrieve them when needed by others.
A document that is not ready for use or is not used often may be archived.
But it needs to be accessible otherwise when it is called for it won’t be there. It
is therefore necessary to ensure that storage areas, or storage mediums provide
secure storage from which documents can be retrieved when needed. Storing
documents off-site under the management of another organization may give
rise to problems if they cannot be contacted when you need the documents.
Archiving documents on magnetic tape can also present problems when the
tape cannot be found or read by the new technology that has been installed!
Electronic storage presents very different problems to conventional storage and
gives rise to the retention of ‘insurance copies’ in paper should the retrieval
mechanism fail.
Ensuring documents are legible and identifiable
The standard requires documents to remain legible and
readily identifiable.
Legibility refers to the ease with which the informa-
tion in a document can be read or viewed. A
document is readily identifiable if it carries some
indication that will quickly distinguish it from
similar documents. Any document that requires a reader to browse through it
looking for clues is clearly not readily identifiable.
The means of transmission and use of documents may cause degradation
such that they fail to convey the information originally intended. Confusion
with document identity could result in a document being misplaced, destroyed
or otherwise being unobtainable. It can also result in incorrect documents
being located and used.
This requirement is so obvious it hardly needs to be specified. As a general
rule, any document that is printed or photocopied should be checked for
legibility before distribution. Legibility is not often a problem with electron-
ically controlled documents. However, there are cases where diagrams cannot
be magnified on screen so it would be prudent to verify the capability of the
technology before releasing documents. Not every user will have perfect
eyesight! Documents transmitted by fax present legibility problems due to the
quality of transmission and the medium on which the information is printed.
Heat sensitive paper is being replaced with plain paper but many organiza-
tions still use the old technology. You simply have to decide your approach.
For any communication required for reference, it would be prudent to use
photocopy or scan the fax electronically and dispose of the original.
Documents used in a workshop environment may require protection from oil
and grease. Signatures are not always legible so it is prudent to have a policy
of printing the name under the signature. Documents subject to frequent
photocopying can degrade and result in illegible areas.
Although a new requirement, it is unusual to find documents in use that carry
no identification at all. Three primary means are used for document
identification – classification, titles and identification numbers. Classification
divides documents into groups based on their purpose – policies, procedures,
records, plans, etc are classes of documents. Titles are acceptable providing
there are no two documents with the same title in the same class. If you have
hundreds of documents it may prove difficult to sustain uniqueness.
Identification can be made unique in one organization but outside it may not
be unique. However, the title as well as the number is usually sufficient.
Electronically controlled documents do not require a visible identity other than
the title in its classification. Classifying documents with codes enables their
sorting by class.
The ISO 9000 Standard requires that documents be updated as
necessary and re-approved following their review.
Following a document review, action may or may not be necessary. If the
document is found satisfactory, it will remain in use until the next review. If the
document is found unsatisfactory there are two outcomes.
The document is no longer necessary and should be withdrawn from use –
this is addressed by the requirement dealing with obsolescence.
The document is necessary but requires a change – this is addressed by this
requirement.
The standard implies that updating should follow a review. The term update
also implies that documents are reviewed only to establish whether they are
current when in fact document reviews may be performed for many different
reasons. A more appropriate term to update would be revise. Previously the
standard addressed only the review and approval of changes and did not
explicitly require a revision process. However, a revision process is executed
before a document is subject to re-approval.
This requirement responds to the Continual Improvement principle.
It is inevitable that during use a need will arise for changing documents and
therefore provision needs to be made to control not only the original
generation of documents but also their revisions.
The document change process consists of a number of key stages some of
which are not addressed in ISO 9000 Standards.
a. Identification of need (addressed by document review)
b. Request for change (not addressed in the standard)
c. Permission to change (not addressed in the standard)
d. Revision of document (addressed by document updates)
e. Recording the change (addressed by identifying the change)
f. Review of the change (addressed under quality planning)
g. Approval of the change (addressed by document re-approval)
h. Issue of change instructions (not addressed in the standard)
i. Issue of revised document (addressed by document availability)
As stated previously, to control documents it is necessary to control their
development, approval, issue, change, distribution, maintenance, use, storage,
security, obsolescence or disposal and we will now address those aspects not
specifically covered by the standard.
In controlling changes it is necessary to define what constitutes a change to a
document. Should you allow any markings on documents, you should specify
those that have to be supported by change notes and those that do not.
Markings that add comment or correct typographical errors are not changes
but annotations. Alterations that modify instructions are changes and need
prior approval. The approval may be in the form of a change note that details
changes that have been approved.
Anyone can review a document but approved documents should only be
changed/revised/amended under controlled conditions. The document
review will conclude that either a change is necessary or unnecessary. If a
change is necessary, a request for change should be made to the issuing
authorities. Even when the person proposing the change is the same as would
approve the change, other parties may be affected and should therefore be
permitted to comment. The most common method is to employ Document
Change Requests. By using a formal change request it allows anyone to request
a change to the appropriate authorities.
Change requests need to specify:
a. The document title, issue and date
b. The originator of the change request (who is proposing the change, his or her
location or department)
c. The reason for change (why the change is necessary)
d. What needs to be changed (which paragraph, section, etc. is affected and
what text should be deleted)
e. The changes in text required where known (the text which is to be inserted
or deleted)
By maintaining a register of such requests you can keep track of who has
proposed what, when and what progress is being made on its approval. You
may of course use a memo or phone call to request a change but this form of
request becomes more difficult to track and prove you have control. You will
need to inform staff where to send their requests.
On receipt of the request you need to provide for its review by the change
authority. The change request may be explicit in what should be changed or
simply report a problem that a change to the document would resolve.
Someone needs to be nominated to draft the new material and present it for
review but before that, the approval authorities need to determine whether
they wish the document to be changed at all. There is merit in reviewing
requests for change before processing in order to avoid abortive effort. You
may also receive several requests for change that conflict and before processing
you will need to decide which change should proceed. While a proposed
change may be valid, the effort involved may warrant postponement of the
change until several proposals have been received – it rather depends on the
urgency
Ensuring the availability of controlled documents
The ISO 9000 standards requires that relevant versions of applica-
ble documents are available at points of use.
The relevant version of a document is the version
that should be used for a task. It may not be the latest
version because you may have reason to use a
different version of a document such as when
building or repairing different versions of the same
product. Applicable documents are those that are
needed to carry out work. Availability at points of use
means the users have access to the documents they
need at the location where the work is to be
performed. It does not mean that users should possess copies of the documents
they need, in fact this is undesirable because the copies may become outdated
and not withdrawn from use.
This requirement exists to ensure that access to documents is afforded when
required. Information essential for the performance of work needs to be
accessible to those performing it otherwise they may resort to other means
of obtaining what they need that may result in errors, inefficiencies and
hazards.
In order to make sure that documents are available you should not keep them
under lock and key (or password protected) except for those where restricted
access is necessary for security purposes. You need to establish who wants
which documents and when they need them. The work instructions should
specify the documents that are required for the task so that those documents
not specified are not essential. It should not be left to the individual to
determine which documents are essential and which are not. If there is a need
for access out of normal working hours, access has to be provided. The more
copies there are the greater the chance of documents not being maintained so
minimize the number of copies. A common practice is to issue documents to
managers only and not the users. This is particularly true of management
system documents. One finds that only the managers hold copies of the
Quality Manual. In some firms all the managers reside in the same building,
even along the same corridor and it is in such circumstances that one invariably
finds that these copies have not been maintained. It is therefore impractical to
have all the copies of the Quality Manual in one place. Distribute the
documents by location, not by named individuals. Distribute to libraries, or
document control centres so that access is provided to everyone and so that
someone has responsibility for keeping them up to date. If using an intranet,
the problems of distribution are less difficult but there will always be some
groups of people who need access to hard copy.
The document availability requirement applies to both internal and external
documents alike. Customer documents such as contracts, drawings, specifica-
tions and standards need to be available to those who need them to execute
their responsibilities. Often these documents are only held in paper form and
therefore distribution lists will be needed to control their location. If documents
in the public domain are required, they only need be available when required
for use and need not be available from the moment they are specified in a
specification or procedure. You should only have to produce such documents
when they are needed for the work being undertaken at the time of the audit.
However, you would need to demonstrate that you could obtain timely access
when needed. If you provide a lending service to users of copyrighted
documents, you would need a register indicating to whom they were loaned so
that you can retrieve them when needed by others.
A document that is not ready for use or is not used often may be archived.
But it needs to be accessible otherwise when it is called for it won’t be there. It
is therefore necessary to ensure that storage areas, or storage mediums provide
secure storage from which documents can be retrieved when needed. Storing
documents off-site under the management of another organization may give
rise to problems if they cannot be contacted when you need the documents.
Archiving documents on magnetic tape can also present problems when the
tape cannot be found or read by the new technology that has been installed!
Electronic storage presents very different problems to conventional storage and
gives rise to the retention of ‘insurance copies’ in paper should the retrieval
mechanism fail.
Ensuring documents are legible and identifiable
The standard requires documents to remain legible and
readily identifiable.
Legibility refers to the ease with which the informa-
tion in a document can be read or viewed. A
document is readily identifiable if it carries some
indication that will quickly distinguish it from
similar documents. Any document that requires a reader to browse through it
looking for clues is clearly not readily identifiable.
The means of transmission and use of documents may cause degradation
such that they fail to convey the information originally intended. Confusion
with document identity could result in a document being misplaced, destroyed
or otherwise being unobtainable. It can also result in incorrect documents
being located and used.
This requirement is so obvious it hardly needs to be specified. As a general
rule, any document that is printed or photocopied should be checked for
legibility before distribution. Legibility is not often a problem with electron-
ically controlled documents. However, there are cases where diagrams cannot
be magnified on screen so it would be prudent to verify the capability of the
technology before releasing documents. Not every user will have perfect
eyesight! Documents transmitted by fax present legibility problems due to the
quality of transmission and the medium on which the information is printed.
Heat sensitive paper is being replaced with plain paper but many organiza-
tions still use the old technology. You simply have to decide your approach.
For any communication required for reference, it would be prudent to use
photocopy or scan the fax electronically and dispose of the original.
Documents used in a workshop environment may require protection from oil
and grease. Signatures are not always legible so it is prudent to have a policy
of printing the name under the signature. Documents subject to frequent
photocopying can degrade and result in illegible areas.
Although a new requirement, it is unusual to find documents in use that carry
no identification at all. Three primary means are used for document
identification – classification, titles and identification numbers. Classification
divides documents into groups based on their purpose – policies, procedures,
records, plans, etc are classes of documents. Titles are acceptable providing
there are no two documents with the same title in the same class. If you have
hundreds of documents it may prove difficult to sustain uniqueness.
Identification can be made unique in one organization but outside it may not
be unique. However, the title as well as the number is usually sufficient.
Electronically controlled documents do not require a visible identity other than
the title in its classification. Classifying documents with codes enables their
sorting by class.

ISO 9001 Standards Check List


ISO 9001:2008 include these checklists as follows:

1. ISO 9001 General Requirements

Has the organization established, documented, implemented and maintained a quality management system in accordance with the requirements of ISO 9001?

2. General Documentation Requirements
Does the quality management system documentation include documented procedures and records required ensuring effective operation and control of its processes?

3. Quality Manual
Has a quality manual been established and maintained that includes:

4. Control of Documents
Are documents required for the quality management system controlled?

5. Control of Records
Have records been established and maintained to provide evidence of conformity to requirements and of the effective operation of the quality management system?

6. Management Commitment
How has top management demonstrated commitment to the development and improvement of the quality management system?

7. Quality Policy
Organization has top management ensured that the quality policy:

8. System Planning
1. Quality Objectives
a. What are the quality objectives that have been established at relevant functions and levels within the organization?

9. Responsibility, authority and Communication
Responsibility, authority and Communication Audit Checklist
1. Responsibility and authority

10. Resource Management
Resource Management Audit Checklist

1. Provision of resources

11. Planning of Product/Service Realization
Planning of Product/Service Realization Audit Checklist
Is planning of the realization processes consistent with the other requirements of the organization’s quality management system?

12. Management Review
Management Review Audit Checklist
1. General checklist
a) Does the top management review the quality management system, at planned intervals, to ensure its continuing suitability, adequacy and effectiveness?

13. Product review
Determination of Requirements Related to the Product (7.2.1)

14. Design and Development Planning and Design and Development Inputs
What is the design and development planning methodology described in the design procedure?

15. Design and Development Outputs Audit
Are the outputs of the design and/or development process documented in a manner that enables verification against the design and/or development inputs?

16. Design and Development Review Audit
Are systematic reviews of design and/or development conducted at suitable stages?

17. Design and/or Development Verification
Is design and/or development verification performed to ensure the output meets the design and/or development inputs?

18. Design and/or Development Validation
Is design and/or development validation performed to confirm that resulting product is capable of meeting the requirements for the intended use?

19. Control of Design and Development Changes
Are design and/or development changes identified, documented, and controlled?

20. Purchasing Process
Does the organization control its purchasing processes to ensure purchased product conforms to requirements?

21. Purchasing Information
Do purchasing documents contain information describing the product to be purchased?

22. Verification of Purchased Product
Have the inspection or other activities necessary for ensuring that purchased product meets specified purchase requirements been established and implemented?

23. Control of Production and Service
Are the production and service provision planned and carried out under controlled conditions including:

24. Validation of Processes for Production and Service Provision
Have processes where deficiencies may become apparent only after the product is in use or the service has been delivered been validated?

25. Identification and Traceability
Is the product identified by suitable means throughout product realization?

26. Customer Property
How does the organization exercise care with customer property while it is under the
organization’s control or being used by the organization?

27. Preservation of Product
Is conformity of product preserved during internal processing and delivery to the intended destination?

28. Audit Checklist of Control of Measuring and Monitoring Devices
Has the organization determined the monitoring and measurement to be undertaken and the monitoring and measurement devices needed to provide evidence of conformity of product to determined requirements?

29. Customer Satisfaction
Are measurement and monitoring activities needed to assure conformity and achieve improvement been identified and included in the product quality plan?

30. Internal Audit Checklist
Are periodic internal quality audits conducted to determine whether the quality management system has been effectively implemented and maintained?

31. Monitoring and Measurement of Processes
Are suitable methods applied for monitoring and where applicable, measurement of the quality management system processes necessary to meet customer requirements?

32. Monitoring and Measurement of Product
Are product characteristics monitored and measured to verify that product requirements are met?

33. Control of Nonconforming Product Checklist
Is nonconforming product identified and controlled to prevent unintended use or delivery?

34. Analysis of Data
Is appropriate data determined, collected and analyzed to demonstrate the suitability and effectiveness of the quality management system and to evaluate where continual improvement of the effectiveness of the quality management system can
be made?

35. Corrective Action
How is corrective action taken to eliminate the cause of nonconformities in order to prevent recurrence?

36 Continual Improvement
Are processes necessary for the continual Improvement of the quality management system planned and managed?

37. Preventive Action
Has the organization determined actions to eliminate the causes of potential nonconformities in order to prevent occurrence?

These checklists also called ISO 9000 audit checklist.


Document Review In ISO 9000 Standards


Document Review In ISO 9000 Standards
The ISO 9000 Standard requires that documents be reviewed.
Previously the implication was that the review was a
check by potential users that the document was fit
for purpose before it was offered for approval. It
could be construed that for a document to receive
approval it must be checked and therefore ‘review
and approval’ in this context are one and the same
and the requirement is in this instance enhanced
rather than relaxed.
A review is another look at something. Therefore
document review is a task that is carried out at any
time following the issue of a document.
This requirement responds to the Continual Improvement principle.
Reviews may be necessary when:
- Taking remedial action (i.e. Correcting an error)
- Taking corrective action (i.e. Preventing an error recurring)
- Taking preventive action (i.e. Preventing the occurrence of an error)
- Taking maintenance action (i.e. Keeping information current)
- Validating a document for use (i.e. When selecting documents for use in
connection with a project, product, contract or other application)
- Taking improvement action (i.e. Making beneficial change to the
information)
Reviews may be random or periodic. Random reviews are reactive and arise
from an error or a change that is either planned or unplanned. Periodic reviews
are proactive and could be scheduled once each year to review the policies,
processes, products, procedures, specification etc. for continued suitability. In
this way obsolete documents are culled from the system. However, if the
system is being properly maintained there should be no outdated information
available in the user domain. Whenever a new process or a modified process
in installed the redundant elements including documentation and equipment
should be disposed of.
The ISO 9000 Standard requires that documents be reviewed.
Previously the implication was that the review was a
check by potential users that the document was fit
for purpose before it was offered for approval. It
could be construed that for a document to receive
approval it must be checked and therefore ‘review
and approval’ in this context are one and the same
and the requirement is in this instance enhanced
rather than relaxed.
A review is another look at something. Therefore
document review is a task that is carried out at any
time following the issue of a document.
This requirement responds to the Continual Improvement principle.
Reviews may be necessary when:
- Taking remedial action (i.e. Correcting an error)
- Taking corrective action (i.e. Preventing an error recurring)
- Taking preventive action (i.e. Preventing the occurrence of an error)
- Taking maintenance action (i.e. Keeping information current)
- Validating a document for use (i.e. When selecting documents for use in
connection with a project, product, contract or other application)
- Taking improvement action (i.e. Making beneficial change to the
information)
Reviews may be random or periodic. Random reviews are reactive and arise
from an error or a change that is either planned or unplanned. Periodic reviews
are proactive and could be scheduled once each year to review the policies,
processes, products, procedures, specification etc. for continued suitability. In
this way obsolete documents are culled from the system. However, if the
system is being properly maintained there should be no outdated information
available in the user domain. Whenever a new process or a modified process
in installed the redundant elements including documentation and equipment
should be disposed of.

Tuesday, December 22, 2009

ISO 9000 Standards – Conducting Management Reviews


ISO 9000 Standards – Conducting Management Reviews

The ISO 9000 standards requires that top management conduct
management reviews.
The term review is defined in ISO 9001 as an activity
undertaken to ensure the suitability, adequacy, effective-
ness and efficiency of the subject matter to achieve
established objectives. The addition of the term manage-
ment means that the management review can be
perceived as a review of management rather than a
review by management, although both meanings are conveyed in the standard.
The rationale for this is that the examples given in ISO 9000 such as design
review and nonconformity review clearly indicate it is design and non-
conformity that is being reviewed. If the system was to be reviewed then the
action should be called a system review. It is no doubt unintentional in the
standard but, if the management system is perceived as the way in which the
organization’s objectives are achieved, a review of management is in fact a
review of the way achievement of objectives is being managed because the
organization exists to achieve objectives and so both meanings are correct.
Top management will not regard the management review as important unless
they believe it is essential to running the business. The way to do this is to treat
it as a business performance review. This is simpler than it may appear. If the
quality policy is now accepted as corporate policy and the quality objectives
are accepted as corporate objectives, any review of the management system
becomes a performance review and no different to any other executive
meeting. The problem with the former management reviews was that they
allowed discussion on the means for achieving objectives to take place in other
management meetings leaving the management review to a review of errors,
mistakes and documentation that no one was interested in anyway. The
management system is the means for achieving objectives therefore it makes
sense to review the means when reviewing the ends so that actions are linked to
results and commitment secured for all related changes in one transaction.
The requirement emphasizes that top management conduct the review – not
the quality manager, not the operational manager – but top management – those
who direct and control the organization at the highest level. In many ISO 9000
registered organizations, the management review is a chore, an event held once
each year, on a Friday afternoon before a national holiday – perhaps a cynical
view but nonetheless often true. The reason the event has such a low priority
is that management have not understood what the review is all about. Tell
them it’s about reviewing nonconformities, customer complaints and internal
audit records and you will be lucky if anyone turns up. The quality manager
produces all the statistics so the others managers are free of any burden. By
careful tactics, these managers may come away with no actions, having
delegated any in their quarter to the quality manager.
In order to provide evidence of its commitment to conducting management
reviews, management would need to demonstrate that it planned for the
reviews, prepared input material in the form of performance results, metrics
and explanations, decided what to do about the results and accepted action to
bring about improvement.

The ISO 9000 standards requires that top management conduct management reviews.

The term review is defined in ISO 9000 Standards as an activity undertaken to ensure the suitability, adequacy, effectiveness and efficiency of the subject matter to achieve established objectives. The addition of the term management means that the management review can be perceived as a review of management rather than a review by management, although both meanings are conveyed in the standard.

The rationale for this is that the examples given in ISO 9000 Standards such as design review and nonconformity review clearly indicate it is design and non-conformity that is being reviewed. If the system was to be reviewed then the action should be called a system review. It is no doubt unintentional in the standard but, if the management system is perceived as the way in which the organization’s objectives are achieved, a review of management is in fact a review of the way achievement of objectives is being managed because the organization exists to achieve objectives and so both meanings are correct.

Top management will not regard the management review as important unless they believe it is essential to running the business. The way to do this is to treat it as a business performance review. This is simpler than it may appear. If the quality policy is now accepted as corporate policy and the quality objectives are accepted as corporate objectives, any review of the management system becomes a performance review and no different to any other executive meeting. The problem with the former management reviews was that they allowed discussion on the means for achieving objectives to take place in other management meetings leaving the management review to a review of errors, mistakes and documentation that no one was interested in anyway. The management system is the means for achieving objectives therefore it makes sense to review the means when reviewing the ends so that actions are linked to results and commitment secured for all related changes in one transaction.

The requirement emphasizes that top management conduct the review – not the quality manager, not the operational manager – but top management – those who direct and control the organization at the highest level. In many ISO 9000 registered organizations, the management review is a chore, an event held once each year, on a Friday afternoon before a national holiday – perhaps a cynical view but nonetheless often true. The reason the event has such a low priority is that management have not understood what the review is all about. Tell them it’s about reviewing nonconformities, customer complaints and internal audit records and you will be lucky if anyone turns up. The quality manager produces all the statistics so the others managers are free of any burden. By careful tactics, these managers may come away with no actions, having delegated any in their quarter to the quality manager.

In order to provide evidence of its commitment to conducting management reviews, management would need to demonstrate that it planned for the reviews, prepared input material in the form of performance results, metrics and explanations, decided what to do about the results and accepted action to bring about improvement.


ISO 9000 Standards – Document control procedures


ISO 9000 Standards – Document control procedures
The ISO 9000 Standards requires that a documented procedure be established to define the controls needed.

This requirement means that the methods for performing the various activities required to control different types of documents should be defined and documented.

Although the ISO 9000 standards implies that a single procedure is required, should you choose to produce several different procedures for handling the different types of documents it is doubtful that any auditor would deem this noncompliant. Where this might be questionable is in cases where there is no logical reason for such differences and where merging the procedures and settling on a best practice would improve efficiency and effectiveness.

Documents are recorded information and the purpose of the document
control process is to firstly ensure the appropriate information is available
where needed and secondly to prevent the inadvertent use of invalid
information. At each stage of the process are activities to be performed that
may require documented procedures in order to ensure consistency and
predictability. Procedures may not be necessary for each stage in the process.

Every process is likely to require the use of documents or generate documents and it is in the process descriptions that you define the documents that need to be controlled. Any document not referred to in your process descriptions is therefore, by definition, not essential to the achievement of quality and not required to be under control. It is not necessary to identify uncontrolled documents in such cases. If you had no way of tracing documents to a governing process, a means of separating controlled from uncontrolled may well be necessary.

The procedures that require the use or preparation of documents should also specify or invoke the procedures for their control. If the controls are unique to the document, they should be specified in the procedure that requires the document. You can produce one or more common procedures that deal with the controls that apply to all documents. The stages in the process may differ depending on the type of document and organizations involved in its preparation, approval, publication and use. One procedure may cater for all the processes but several may be needed.
The aspects you should cover in your document control procedures, (some
of which are addressed further in this chapter) are as follows
Planning new documents, funding, prior authorization, establishing need
etc.

- Preparation of documents, who prepares them, how they are drafted,
conventions for text, diagrams, forms etc.
- Standards for the format and content of documents, forms and diagrams.
- Document identification conventions.
- Issue notation, draft issues, post approval issues.
- Dating conventions, date of issue, date of approval or date of distribution.
- Document review, who reviews them and what evidence is retained.
- Document approval, who approves them and how approval is denoted.
- Document proving prior to use.
- Printing and publication, who does it and who checks it.
- Distribution of documents, who decides, who does it, who checks it.
- Use of documents, limitations, unauthorized copying and marking.
- Revision of issued documents, requests for revision, who approves the
request, who implements the change.
- Denoting changes, revision marks, reissues, sidelining, underlining.
Amending copies of issued documents, amendment instructions, and
amendment status.
- Indexing documents, listing documents by issue status.
- Document maintenance, keeping them current, periodic review.
- Document accessibility inside and outside normal working hours.
- Document security, unauthorized changes, copying, disposal, computer
viruses, fire and theft.
- Document filing, masters, copies, drafts, and custom binders.
- Document storage, libraries and archive, who controls location, loan
arrangements.
- Document retention and obsolescence.

With electronically stored documentation, the document database may provide many of the above features and may not need to be separately prescribed in your procedures. Only the tasks carried out by personnel need to be defined in your procedures. A help file associated with a document database is as much a documented procedure as a conventional paper based procedure.


Documents That Ensure Effective Planning, Operation And Control

Documents That Ensure Effective Planning, Operation And Control

The ISO 9000 standard requires management system documentation to include documents required by the organization to ensure the effective planning, operation and control of its processes.
The documents required for effective planning, operation and control of the processes would include several different types of documents. Some will be
product and process specific and others will be common to all processes. Rather than stipulate the documents that are needed, ISO 9000 Standards now provides for the organization to decide what it needs for the effective operation and control of its processes. This phrase is the key to determining the documents that are needed.
There are three types of controlled documents, namely:
- Policies and practices (these include process descriptions, control procedures, guides, operating procedures and internal standards)
- Documents derived from these policies and practices, such as drawings,
specifications, plans, work instructions, technical procedures and reports
- External documents referenced in either of the above
There will always be exceptions to this model but in general the majority of
documents used in a management system can be classified in this way.
Derived documents are those that are derived by executing processes;
for example, audit reports result from using the audit process, drawings result from using the design process, procurement specifications result from using the procurement process. There are, however, two types of derived document:
prescriptive and descriptive documents. Prescriptive documents are those that prescribe requirements, instructions, guidance etc. and may be subject to change. They have issue status and approval status, and are implemented in doing work. Descriptive documents result from doing work and are not
implemented. They may have issue and approval status. Specifications, plans, purchase orders, drawings are all prescriptive whereas audit reports, test reports, inspection records are all descriptive. This distinction is only necessary because the controls required will be different for each class of documents.


Create a Documented Implementation Plan In ISO 9000 Standards

Create a Documented Implementation Plan In ISO 9000 Standards

Once the organization has obtained a clear picture of how its quality management system compares with the ISO 9001:2008 standard, all non-conformances must be addressed with a documented implementation plan. Usually, the plan calls for identifying and describing processes to make the organization’s quality management system fully in compliance with the standard.

The implementation plan should be thorough and specific, detailing:

a. Quality documentation to be developed

b. Objective of the system

c. Pertinent ISO 9001:2008 section

d. Person or team responsible

e. Approval required

f. Training required

g. Resources required

h. Estimated completion date

These elements should be organized into a detailed chart, to be reviewed and

approved. The plan should define the responsibilities of different departments and personnel and set target dates for the completion of activities. Once approved, the Management Representative should control, review and update the plan as the implementation process proceeds.

Typical implementation action plan is shown in Figure 2. Use ISO 10005:1995 for guidance in quality planning.