Friday, March 17, 2017

How to Do Effective Quality Planning

      An organization’s quality management system cannot be effective without good planning. So how can an organization do an effective quality planning? One need stick to the following points:

1. It must be the top management who’s responsible for the quality planning.

      Quality planning shall always be coordinated and led by the top management. I have seen organizations which do the quality planning just by the management representative, who’s often the head of the quality department. In such organizations, the quality planning can seldom be effective. The quality management system must be well integrated into the organization’s business operation to make it effective and become a value adding system to the company. So the person leading the quality planning must fully understand the company’s strategy and the direction that the organization wants head to. This person must have integrated knowledge of the company’s overall performance, so that he/she can have a good perspective for what is expected to be achieved from the quality planning. So this role can hardly be replaced by anyone else.

2. Following things shall be done in quality planning according to ISO9001:2015

  • Understand the internal and external issues of the organization;
  • Understand the needs and expectations of the interested parties;
  • Establish the quality scope;
  • Identify the processes in the quality management system, establish the requirements and control of each process, and define the roles and responsibilities of each position in the processes;
  • Establish the quality policy;
  • Identify the risks and opportunities in the quality management system and propose actions to address these risks and opportunities;
  • Establish the quality objectives (the objectives for the whole organization, for each department, for each quality process, for the effectiveness evaluation of actions taken to address the risks and opportunities, etc.);
  • Propose the actions to ensure the achievement of the above objectives and allocate the necessary resources to support the effective implementation of these actions.


     Understanding of the internal and external issues of the organization, understanding of the needs and expectations of the interested parties, and risk & opportunities identifications can be done together, as explained in another article. Identification of processes is discussed here. Requirements and controls which shall be established for each process can also be found in my other blog.

      It must be emphasized here again that quality management system shall be integrated with the overall business operation of the company. So when doing the above planning, it shall not be a stand-alone event. It must serve for the achievement of the organization’s business targets. For example, when setting up quality objectives, the top management shall consider how the achievement of these quality objectives can help the achievement of the organization’s business targets. Otherwise, the quality objectives are meaningless.

3. Quality planning is not once a year event

      Quality planning shall not just be done once a year. An organization usually has multiple ways to review the effectiveness of its quality management system, such as management review, internal audit, customer satisfaction study, etc. Whenever such review is done, planning shall be done again, to see whether all the things done previously are effective, suitable and adequate, and to see whether objectives shall be adjusted and new actions shall be proposed.

How to Do Effective Management Review

How to Do Effective Management Review

ISO9001:2015 requires that management review shall be done at planned intervals to ensure the suitability, effectiveness and adequacy of the quality management system. Every organization does the management review if it wants to be ISO9001 certified, but probably not all management reviews are done effectively. So what shall the organization do to make the management review effective? This question can actually be divided into several questions as shown below. Let’s take a look one by one.

1.       Who shall attend the management review?
Management review must be attended by the top management team who has the authority to make the decisions about what shall be done next and what resources will be provided, because these decisions are the full purpose of doing management review. If the decision makers are not present in the management review, it will just end up in vain.

2.       How often and when shall the management review be conducted?
I have seen organizations have the so-called management review meeting once a year. If this is how often your organization does the management review, I dare say that the only purpose you do the management review is to have something to show to the external auditors from the certification body. In a real organization with good management, it must have regular manager meetings, normally held much often than once a year (probably once a month or even more often). In these meetings, the top management review how well the organization runs and what each department has done in the past period and also decide what shall be done next. So these meetings have already fulfilled the requirements of ISO9001 about management review, and they are management reviews! There is no need for the organization to have a separate meeting, with the designated name of “management review meeting”.
When determining the time and how often to have the manager meetings, one needs to consider following factors:
1)       When are the organization’s objectives set?
It is always needed to review the performance in the past to set up the new objectives. So before setting up a new target, it is desired to have a manager meeting. For example, if an organization sets up their objectives annually, then at the beginning of each year, a manager review must be held to review the performance in the past year, and then discuss and decide what new objectives should be set.
2)       How often is the achievement of the objectives reviewed?
After the establishment of objectives, manager meetings should be regularly held in order to review the achievement of these objectives up to this point. For example, an organization has set up some annual targets, and it has been decided that these targets shall be reviewed monthly to monitor their actual performance and to see whether additional actions or resources needed to support their achievement. In this case, manager meetings shall be held monthly.
3)       Are there any special event which needs support and decision from top management? 
In some cases, such as significant organizational changes, critical customer claims and legal issues, the awareness by the top management team is needed and resource is required for countermeasures to deal with these issues, manager meetings shall also be held to discuss the countermeasures and get the approval from the top management for resource needed.

3.       What shall be reviewed in the manager meetings?
In Clause 9.3.2 of ISO9001:2015, it is specified what shall be reviewed in the manager meetings (the input of the management review). It is a long list. To summarize, they can be divided into two categories:
A.       What are the objectives? What have been done to achieve the objectives? Have the objectives been achieved? If not, why and what corrective actions will be taken?
B.       What will be done next?

Let’s link the above three items with the input requirements for the management review in 9.3.2.
Input for Management Review as Specified in 9.3.2
Category
Note
a)        the status of actions from previous management reviews
A

b)       changes in external and internal issues that are relevant to the quality management system
A & B
Here the changes in the organization shall be reviewed, and actions taken or to be taken to response the changes shall be presented or proposed respectively. Decisions shall be made in the meeting on the proposed actions whether they are approved, as the output of the meeting. If they are approved, the needed resources shall be provided by the top management.
c)        information on the performance and effectiveness of the quality management system, including trends in
1)       customer satisfaction and feedback from relevant interested parties
A
Here the achievement of the objectives in the past can be reviewed. If the objectives are not achieved, root cause analysis shall be done, and countermeasures shall be proposed. Decisions shall be made in the meetings whether these countermeasures are approved, as the output of the meeting. If they are approved, the needed resources shall be provided by the top management.
2)       the extent to which quality objectives have been met
A
3)       process performance and conformity of products and services
A
4)       nonconformities and corrective actions
A
5)       monitoring and measurement results
A
6)       audit results
A
7)       the performance of external providers
A
d)       the adequacy of resources
A
In the root cause analysis for the underachieved objectives and ineffective actions, it can be discussed whether the resources provided is adequate or note.
e)       the effectiveness of actions taken to address risk
A

f)        opportunities for improvement.
B
More challenging objectives may be set if the previous objectives were achieved, meanwhile actions shall be proposed to ensure the achievement of new objectives. Decisions shall be made in the meeting whether the new objectives and corresponding actions are approved, as the output of the meeting. If the actions are approved, the needed resources shall be provided by the top management.

4.       There must be output from the management review and they should be followed up until they’re closed.
Any management review is meaningless without output. The actions to be taken in the future, either as correction for underachieving targets, or as improvement for achieved targets, or as the response to the changes, must be decided as noted in the above table. The resources shall be allocated by the top management accordingly for the approved actions. These actions shall be followed up until they are properly closed. 

Monday, March 13, 2017

How to Do Employees Training to Fulfill the Requirements of ISO9001:2015

      Clause 7.2 outlines the requirements of ISO9001:2015 in employees training. To fulfill the requirements, the training process shall be conducted in the following sequence:

1. Define each post and their duties
      An organization should have clearly defined job posts and the duties that the employees need to perform on these posts. 

2. Determine the competency needed for each post according to its duties, and determine the way to evaluate the competency
      The competency needed for each post is determined by its duties. For each duty the post needs to perform, there must be corresponding competency available. Also, there must be a evaluation method to determine whether the competency is really gained. A table can be established for each post as shown below:

3. Determine the competency and training needed for an employee according to posts he/she is assigned to
      An employee can be assigned to only one or multiple posts. If he’s on multiple posts, he/she must have the competency to perform the duties of all these posts. Accordingly training should be provided to meet the competency needs of all these post. 

5. Set up a training plan according to the training needs
      After the training needs are identified for all employees of the organization, a training plan of the company can be set up.

6. Conduct the training as planned
      Training shall be conducted according to the training plan, so that all the employees can obtain the competency needed to perform his/her duties.

7. Evaluate the competency of the employees after the training
      It must be ensured that the competency is gained by the employee after the training so that he/she can perform his/her duty as required. Usually, exams all required for the employees after the training. Only if the employee passes all the exams, he/she is qualified for his/her post and he/she can perform his/her duty on this post individually.

8. Evaluate the effectiveness of the training
      The effectiveness of the training shall be assessed. This can be done in multiple ways. For example, a survey can be done on the employees to evaluate the trainer, training materials or training facilities. Quality objectives can also be set for the employees. If the quality objectives are met, it means the training provided to the employees are effective.

9. Keep all the above records

      It is important to remember that whenever an employee is assigned to a new post or transferred to a new post, the above Steps 2-8 shall be repeated again. 

      It is also suggested that re-training and re-evaluation shall be provided to an employee if he/she is away from his/her posts for a long time (e.g. an employee is transferred from Post A to Post B, and then transferred back to Post A after half a year) to ensure he/she is still able to perform his/her job.

      It is also often desired that regular re-training and re-evaluation (e.g. once a year) are performed, even if an employee never leaves his/her post, to refresh his/her memory.

      Whenever the duties of a post is changed (e.g. additional duties are assigned to a post), or the skills required is changed (e.g. a manual machine is replaced by an automated one, or a work instruction is updated with new requirements), the training needs shall be identified again, and Steps 3-8 shall be performed again.  

      It is suggested to keep one file for each employee's training records. The records can contain a master list like below. All the relevant records, such as the evaluation records can be attached to this master list. With such a file, the training records of any employee has good readability, so whenever someone wants to see whether an employee is qualified, or to see what other training he/she needs, there will be no confusion.


      Finally, it's highly recommended to each organization to have a office automation system for training management. With paper records, it can become tedious and messy when the employees number goes up. 


How to Do Supplier Management as Required in ISO9001:2015

      Clause 8.4 of ISO9001:2015 requires control over external service providers. In this article, all the external service providers will just be called suppliers, a term which is more familiar to most people.

      One organization may have hundreds or even thousands of suppliers, but not all suppliers should be controlled to fulfill the requirements of ISO9001:2015. Only three types of suppliers shall be controlled as stated in Clause 8.4.1 of ISO9001:2015:
  1. Suppliers whose products and services are intended for incorporation into the organization’s own products and services. Raw material suppliers belong to this type.
  2. Suppliers whose products and services are provided directly to the customer(s) on behalf of the organization.
  3. Suppliers by which a process, or part of a process, is provided as a result of a decision by the organization. Logistic service providers, calibration institution and subcontractors who are responsible for some steps of the manufacturing process of the organization's products belong to this type.
      Now let's discuss what shall be done to fulfill the requirements of ISO9001:2015 in supplier management. 

      First, a criteria to evaluate and select the suppliers shall be established. Only suppliers which meet these criteria can be qualified as the organization's suppliers. An approved vendors list (AVL) can be established for these qualified suppliers. All purchasing orders should only be issued to suppliers in this list. The criteria to evaluate a supplier may include but are not limited to:
  • Whether the supplier meets all the legal requirements;
  • Whether the supplier has the ISO certificates (An on site audit can be conducted to see whether the supplier has a solid quality management system established);
  • Whether the supplier's price for the products is competitive;
  • Whether the supplier's product specifications meet the requirements (If necessary, samples may be requested from the suppliers for evaluation);
      Second, the performance of these qualified suppliers shall be monitored. It is often monitored according to four aspects: quality, delivery, cost and support. A scoring criteria is usually needed so that the supplier's performance can be objectively determined. Based on their performance, the suppliers shall be re-evaluated, and proper actions shall arise from the re-evaluation. For example, corrective actions can be requested from suppliers, or the suppliers shall be removed from AVL if their performance continuously miss the target and business should be suspended with them.  

      Third, the requirements of the organization shall be passed to the suppliers. These requirements may include but are not limited to:
  • Requirements for the products or service provided;
  • Approval of the products and service; 
  • Communication requirements (i.e. the contact window, language requirements for communication);
  • Quality objectives to the suppliers, the criteria to monitor their performance and the actual performance of the suppliers. 
      At last, I want to add one point here which is not a specified requirement in ISO9001:2015, but often required by customers: the organization shall have multiple suppliers for each kind of material to ensure the continuity in the supply chain. It should be part of the contingency plan or risk management of the organization, to address the risk of materials shortage. 

Sunday, March 12, 2017

What Quality Processes Can be Identified in a Quality Management System

As explained in the previous article, one needs to identify the processes in the quality management system as the first step to implement the process approach methodology.

Depending on the nature of the organization, its quality processes which should be identified in the quality management system can vary a lot. This article will give an example of the quality processes in a manufacturing organization with design and development function.  

A widely employed approach in processes identification is to divide them into three groups: customer oriented processes, supporting processes and management processes:

1.      Customer Oriented Processes
            The customer oriented processes are the processes related to product realization, from the point when the organization receives customers’ contracts or orders to the point when the products are shipped to the customers. These processes may include:

1)      Contract review process
            When a new customer wants to buy a product from the organization or an existing customer wants to buy a new product from the organization, the customer usually signs contracts with the organization to specify its requirements (such as the technical specifications, the price, the requirements in green purchasing, etc.). The organization shall review these requirements and take actions to conform these requirements if necessary. The purpose of this process is to ensure that all the customer requirements are fully understood and can be fulfilled before accepting the customer’s contract. 

2)      Design and development process:
            This process transfers the customer requirements on a product (e.g. how the product looks like, what its functions are) to the mass production of the product. The purpose of this process is to ensure that the product and process designed can fulfill the intended requirements for the products.     

3)      Order handling process
            When an actual order for the delivery of products is received from a customer, the requirements in the order, which is a contract usually specifying the quantity, the product and the desired delivery date, shall be reviewed, to see whether the organization has the capability to meet the requirements:
l  Is there enough stock of finished products?
l  Is there enough manufacturing capacity?
l  Are there enough raw materials?
            Actions should be taken to meet the order requirements if necessary (e.g. increasing the manufacturing capacity by adding new lines).
            The purpose of this process is to ensure that the requirements of customer orders are fully understood and that the organization has the capability to fulfill customer orders before accepting them.

4)      Production planning process
            When an order is accepted by the organization, a production plan should be established accordingly to fulfill the order requirements. Meanwhile, a good production plan should also fulfill the requirements of JIT (just-in-time), to minimize the inventory of raw materials, WIP and finished goods. The purpose of this process is to fulfill the customer orders and meanwhile to mitigate the inventory and stock up of materials and WIPs in the production line.

5)      Purchasing process
            This is the process in which purchasing requirements are identified based on the production planning, and purchasing orders are issued and followed up to fulfill these requirements.

6)      Production process
            This is the process in which the raw materials are transferred to finished goods, according to the production plan and the technical specifications.

7)      Storage process:
            The raw materials, WIP and finished goods shall be stored properly in the warehouse and the production site. For a good storage management, it must ensure that stored items are properly identified, specified storage conditions (e.g. temperature, humidity, ESD & stacking height) are fulfilled, the expiration date are monitored, the quantity is right, and FIFO is guaranteed.  

8)      Packing and delivery process:
             This is the process in which the finished goods are packed and delivered to the customers.

2.      Supporting processes
            The supporting processes are those processes to ensure the effective operation of the customer oriented processes. They include:

1)      Document control process
            This is the process to ensure that
l  The documents used for quality management are adequate and suitable;
l  The documents distributed to the uses are the most updated ones and they’re available for the users who need them;
l  The documents are protected from loss and damage, and safeguarded from leaking of confidential information.

2)      Employees management process
            This is the process to equip the organization with competent and motivated employees. The skills and experience needed for each job post must be clearly identified, and trainings shall be provided accordingly to ensure that the people on each post are competent to perform their duty. Also the employees shall be motivated. Their satisfaction and loyalty to the organization shall be monitored and actions shall be taken if necessary to promote the employees satisfaction and loyalty.

3)      Organizational knowledge management process
            Knowledge management is a new requirement in ISO9001:2015. The purpose of this process is to ensure that the knowledge needed for employees or the organization to ensure the conformity of products is identified, maintained, updated if necessary, and made available for the relevant persons. This process can be combined with the employees management process or the document control process if the process owners are the same.

4)      Infrastructure & equipment management process
            This process is to ensure that
l  Necessary infrastructure and equipment are provided to meet the organization’s needs;
l  The infrastructure and the equipment are maintained so that they do not cause negative impact to the on time deliver and products’ quality.

5)      Measuring equipment management process
            This process is to ensure that
l  Necessary measuring equipment is provided to verify the conformity of the products;
l  Measuring equipment are calibrated or verified to ensure that they meet the purpose of the measuring activities performed.

6)      Work environment management process
            This process is to ensure that proper work environment are established and maintained. The work environment includes
l  Physical environment, such as temperature, humidity, illumination, etc., which should be appropriate for products preservation and for employees to perform their duties;
l  Social and mental environment, such as no discrimination, no physical abuse, etc., which should be appropriate so that employees social rights are protected and ensured, and they feel no mental pressure when performing their duties.

7)      Suppliers management process
            This process is to ensure that the organization’s suppliers meet the desired requirements, and their performance is monitored and corrective or improvement actions are requested from suppliers when needed.

8)      Incoming inspection process
    This process is to ensure that the purchased materials meet the specified requirements in quality, quantity and etc. It serves as a monitoring process for the effectiveness of the supplier management process.

9)      Inspection and testing process
This process is to ensure that appropriate inspection and testing activities are conducted so that
l  The products shipped to the customers always meet the customers’ requirements
l  The nonconformities or improvement opportunities in the production process are identified so that corrective and improvement actions can be implemented. 

10)   Customer claims handling process
            This process is to ensure that any quality issues arising from the products shipped to the customers are properly resolved and their recurrences are well prevented.

3.      Management processes
            The management processes are those processes which need the involvement of the top management team and they’re the reviewing, planning and action taking processes to ensure the customer oriented processes and supporting processes are effective. They can include:

1)      Management review process
            This process is a review process which must be conducted by the top management team. It is to review the overall suitability, effectiveness and adequacy of the quality management system. The resources needed, the need for changes and improvement opportunities are identified and actions are taken accordingly.

2)      Internal audit process
            Internal audit is conducted by internal auditors. It is another review process to monitor
l  Whether the established requirements of the quality management system conforms to the international standards and organization’s own needs;
l  Whether the implementation of the quality management system conforms to the established requirements;
l  Whether the requirements are effective, suitable and adequate.
Actions shall be taken to correct the nonconformities found during internal audit.

3)      Customer satisfaction monitoring process
            This process is to review the effectiveness of the quality management system through the monitoring of the customer satisfaction. Actions shall be taken accordingly based on the monitoring result to improve customer satisfaction.

4)      Quality planning process
            This is the overall planning process for the quality management system. It should be led by the top management team, and supported by all the senior and junior managers in the each department of the organization. Based on the requirements of ISO9001:2015, following things shall be done for a good quality planning:
l  Understanding of the internal and external issues of the organization;
l  Understanding the needs and expectations of the interested parties;
l  Establish the quality scope;
l  Identify the processes in the quality management system, establish the requirements and control of each process, and define the roles and responsibilities of each position in the processes;
l  Establish the quality policy;
l  Identify the risks and opportunities in the quality management system and propose actions to address these risks and opportunities;
l  Establish the quality objectives (the objectives for the whole organization, for each department, for each quality process, for the effectiveness evaluation of actions taken to address the risks and opportunities, etc.).
            The actions arising from review processes above may cause changes in the quality planning. So they’re always inter-linked. 

Monday, March 6, 2017

How to Do Document Control to Fulfill the Requirements of ISO9001:2015

    Before starting this article, I want to point out here that in this article, I will use “document(s)” following the convention, though ISO9001:2015 standard now calls it “documented information”.

    In the earlier versions of ISO9001 (or ISO9000 for even earlier versions) standards, much emphasis was given to set up documented procedures, because ISO9001 was originally established as a guide to assess suppliers, and auditors always wanted to see that suppliers had clearly documented procedures for the operators to follow and to avoid misoperation. The emphasis on the documents, however, resulted into a significant burden for organizations to fulfill the requirements of ISO9001. A pile of documents were established, and needed to be reviewed and updated promptly and properly to ensure their suitability and adequacy. To reduce this burden, ISO has been gradually reducing the mandatory requirements on the documented procedures. In ISO9001:2008, only a quality manual and 6 documented procedures were mandatorily required. In ISO9001:2015, even these documents are no longer necessary. This is one of the key changes in the ISO9001:2015. It now only requires that an organization shall have documented quality scope, quality policy and quality objectives. Organizations can just choose to have or not have any other documented procedure based on their own needs.

    Once an organization decides to establish and maintain a documented procedure, it shall follow and meet the document control requirements as specified in 7.5 of ISO9001:2015.  Before discussing what shall be done to fulfill these requirements, let's first ask one question: why did ISO set up the requirements for document control? It has the following purposes:

  1. To ensure that all the documented procedures followed by the employees are suitable and adequate. Otherwise, it may cause disruption or mistakes in the company's operation.
  2. To ensure that the documented procedures are always available for their users to refer to when they are needed.
  3. To ensure that the commercial confidentiality and intellectual properties of the organization and its related parties are well guarded.
    Now let's see how to meet the requirements in 7.5 of ISO9001:2015. As a short summary, one can follow the flow chart shown below for the document control procedure:

    Let's discuss the steps above one by one in more details.

1. Identification of needs to create a new documented procedure or update an existing documented procedure

    As mentioned in the beginning of this article, it is not mandatory to have written documents other than the quality scope, quality policy and quality objectives according to ISO9001:2015. So it is really up to the organization to decide whether it's needed to create a document. If a process is well understood by the relevant parties and it achieves the intended results, it is OK not to establish a document to specify how the process should be carried out. On the other hand, if there's any ambiguity, it's better to create a document to clarify the flow and the relevant responsibility of the process. If the organization has frequent customer audits, it's also suggested to have documents to describe the flows of each process. Based on personal experience, customers usually like to see the evidences in black and white.

    After documented procedures are established, the organization shall identify the needs to update them to keep them suitable and adequate. The needs can come from events such as internal changes, corrective actions, improvements, new customer requirements, new standards, new legal requirements, etc. In all these events, the coordinators (e.g. the owner to review customer requirements) should identify what documents should be updated, and then notify the document owners to update them. The above events should not be closed until all the relevant documents are updated properly. In real life, people often fail to identify and update all the documents related to these events. Therefore, other than the events-triggered mechanism, the organization shall also require the document owners to have a regular review of each existing document (e.g. once a year) to see whether it is still suitable and adequate and update it as needed.

2. Drafting of the document and application for review and approval
 
    An owner of each document must be clearly assigned. When a documented procedure needs to be created and updated, the owner should draft the document according to the following requirements:
  1. The document must have a proper identification. Generally the document must have a document number, a title and a revision number. 
  2. The document must have a clearly specified effective date.
  3. The revision history of the document must be clearly described. 
  4. The document shall contain the other necessary information for the effective implementation of a process, such as the responsibilities and the competency of relevant persons, the flow of the process, the communication within the process or with other processes, etc.
    A template of a documented procedure will be provided at the end of the article.
The drafter of the document shall submit the document for review and approval before publishing, to ensure that the document is suitable and adequate.

3. Document review and approval
 
    The reviewer and approver must have solid knowledge and understanding of the process, so that he/she can tell any mistake and inadequacy in the document. Their responsibility is to ensure that all the necessary information for the effective implementation of the process is specified in the document and there's no ambiguity or incorrect instruction in the document.
The organization can decide based on the document scope who should be reviewer and approver. For example, if the document is applicable in the whole company, it's usually reviewed by the department head of the process owner, and then approved by a member of the top management team (e.g. management representative if your company still keeps this position). If the document is applicable only in a department, it just needs to be reviewed by a junior supervisor and then approved by the department head.

4. Publishing & distribution of the new document and retrieval of obsoleted revision

    After the approval of the newly created/updated document, it's officially published. It should then be distributed to the users of the document. For an updated document, the original revision must be obsoleted and retrieved as well to prevent misuse.

    The above steps can be done in paper or electronically. If the users of the documents do not require hard copies, it is highly recommended to use an electronic system to go through above steps.

    The above steps also apply to the process to obsolete an existing document. The only difference is that in the 4th step, no publishing and distribution is needed. Instead, a notice should be sent out for the obsoleting of the document.


    All the documents published and in use shall be properly stored and protected. If they’re in soft copies, they should be safeguarded from unauthorized copy, edit and deletion. If they're in hard copies, they should be protected from loss, damage and deterioration, and they should also be prevented from unauthorized duplication. A common way to identify unauthorized copies and prevent their use is to have a “controlled copy” stamp on the paper documents (please refer to the template of the document in the end of this article) before distributing them, so that employees know that any document without the original stamp is not authorized and should not be followed.

    If the documents are confidential, they should also be safeguarded from unauthorized access, copy and distribution. The organization may set up some criteria to define the confidentiality level of documents, and define the persons with authority to access, copy and distribute these documents. Unauthorized persons should not have the opportunity to access, copy and distribute the confidential documents.

    Finally, let me give one template of a documented procedure. What shall be written in each section of this document is explained in the words highlighted in blue. The “effective date” of the document needs special attention. It is the date when the document becomes effective and should be followed. It is not the date when the document is published. “Effective Date” should be later or same as the publishing date.


Thursday, March 2, 2017

How to Fulfill the Requirements of Risk Based Thinking in ISO9001:2015

    A concept or methodology which is introduced in ISO9001:2015 for the first time is the risk based thinking. To employ this methodology in an organization, one can refer to another international standard - ISO31000:2009 Risk management – Principles and guidelines and follow the requirements specified there, but it is not mandatory that ISO31000 has to be followed in order to fulfill the requirements of risk based thinking of ISO9001:2015.
    To meet the minimum requirements of the risk based thinking as specified in Clause 6.2.1 and 6.2.2 of ISO9001:2015, an organization should at least do the following things:

  • Step 1: Identify the risks and opportunities in its quality management system
  • Step 2: Take the necessary actions to address these risks and opportunities
  • Step 3: Evaluate the effectiveness of the above actions taken

Now let's look into these steps one by one.

Step 1: Identify the risks and opportunities in its quality management system
    When ISO9001:2015 talks about the risk based thinking, it's not just about managing the risks which have negative results, but also the opportunities which can be taken advantage of. The organization should identify both the risks and opportunities in its quality management system.
As required in 6.1.1 of ISO9001:2015, when identifying the risk and opportunities, the organization needs at least to consider two aspects:

  • Internal and external issues of the organization (4.1 of ISO9001:2015)
  • Needs and expectations of the interested parties (4.2 of ISO9001:2015)

    The internal issues of the organization include but are not limited to the company's culture, employees’ ability, company’s financial status (it determines how many resources can be provided), etc. The external issues include but are not limited to the overall economic situation, market trend, technology level of the industry, etc.
    Needs and expectations of the interested parties include but are not limited to legal requirements from government, requirements from customers, needs of employees, expectations from suppliers, etc. In terms of each department in the organization, needs of expectations of interested parties also include needs and expectations from other departments. It should be noted here that Clause 4.2 of ISO9001:2015 is talking about the needs and expectations from, not for the interested parties.
    By analyzing the above issues, the organization should assess the associated risks and opportunities, and determine whether actions are needed to

  • eliminate, mitigate, prevent or take the risks
  • take advantage of the opportunities   

Step 2: Take the necessary actions to address these risks and opportunities
    If it is determined that necessary actions are needed to address the risks or opportunities as identified above, actions should be proposed and implemented. As always, when actions are proposed, the owner of each action and the due date must be clearly defined.

Step 3: Evaluate the effectiveness of the above actions taken
    The effectiveness of the actions taken must be evaluated to ensure that the corresponding risks and opportunities are properly addressed. So for identified risk or opportunity, an objective should be set up for the actions taken and the result of actions should be reviewed against the objective. Such review must be included in the management review meetings, as required in 9.3.2 of ISO9001:2015.

Owner of Risk Identification
    So far, it has been discussed the steps which should be followed to fulfill the requirements of 6.2.1 and 6.2.2 of ISO9001:2015. An important question here is who should be responsible for it. It should be the top management of the company, who of course must be supported by the owners of the quality processes. Each owner of a process first identify the risks and opportunities associated with his/her process and propose the actions to address them, and then submit to the top management for review and consolidation. As the owner of each process can only understand the internal and external issues and the needs and expectations of the interested parties from the perspective of the process he/she owns, it is necessary for the top management team to review what submitted by the process owners, provide their opinion and summarize them from the perspective of the whole quality management system.

Template for Risk Identification
    So much has been said about what should be done, and now let's see one example to have some idea how it can actually be done. As a good start, the organization can use the template as shown below to identify the risks/opportunities and propose the corresponding actions to address them. In the column of “Context of the Organization”, internal and external issues of the organization are identified one by one, and in the column of “needs and expectations of interested parties”, the need, expectation or requirement of interested parties is also identified one by one. The risks and opportunities associated are then analyzed and identified in the column of “Risks” and “Opportunities” respectively. The actions to address these risks and opportunities are then proposed in the next column. The due date and owner of each action are specified in the next two columns. And in the final column, the objectives are defined, against which the effectiveness of the actions taken will be reviewed.