Friday, December 18, 2009

Establishing Quality Policy In ISO 9000 Standards

Establishing Quality Policy In ISO 9000 Standards

The standard requires that top management establish
the quality policy.
ISO 9001 defines a quality policy as the overall
intentions and direction of an organization related to
quality as formally expressed by top management. It
also suggests that the policy be consistent with the
overall policy of the organization and provide a
framework for setting quality objectives. Further-
more ISO 9001 advises that the eight quality manage-
ment principles be used as a basis for forming the quality policy. The quality
policy can therefore be considered as the values, beliefs and rules that guide
actions, decisions and behaviours. A value may be ‘integrity’ and expressed as:
We will be open and honest in our dealings with those inside and outside the
organization. A rule may be ‘confidentiality’ and expressed as Company
information shall not be shared with those outside the organization. Both these are
also beliefs because it might be believed that deceiving people only leads to
failure in the long run. It might also be believed that disclosing confidential
information fuels the competition and will drive the organization out of
business. Both values guide actions, decisions and behaviours and hence may
be termed policies. They are not objectives because they are not achieved – they
are demonstrated by the manner in which actions and decisions are taken and
the way your organization behaves towards others.
The detail of quality policy will be addressed later. What is important in this
requirement is an understanding of why a quality policy is needed, what is
required to establish a quality policy and where it fits in relation to other
policies.
Defining the purpose or mission of the business is one thing but without
some guiding policies, the fulfilment of this mission may not happen unless
effort is guided in a common direction. If every manager chooses his or her
direction, and policies, the full potential of the organization would not be
realized. A shared vision is required that incorporates shared values and
shared policies.
The purpose of corporate policies is to influence the short and long-term
actions and decisions and to influence the direction in which the mission will
be fulfilled. If there were policies related to the organization’s customers, they
could be fulfilled at the expense of employees, shareholders and society. If
there were policies related to profit, without other policies being defined, profit
is positioned as a boundary condition to all actions and decisions. Clearly this
may not direct the organization towards its mission.
As stated above, the quality policy is the corporate policy and such policies
exist to channel actions and decisions along a path that will fulfil the
organization’s purpose and mission. A goal of the organization may be the
attainment of ISO 9001 certification and thus a quality policy of meeting the
requirements of ISO 9001 would be consistent with such a goal, but goals are not
the same as purpose as indicated in the box to the right. Clearly no organization
would have ISO 9000 certification as its purpose because certification is not a
reason for existence – an objective maybe but not a purpose.
Policies expressed as short catchy phrases such as “to be the best” really do
not channel actions and decisions. They become the focus of ridicule when the
organization’s fortunes change. There has to be a clear link from mission to
policy.
Policies are not expressed as vague statements or emphatic statements using
the words may, should or shall, but clear intentions by use of the words ‘we will’
– thus expressing a commitment or by the words ‘we are, we do, we don’t, we
have’ expressing shared beliefs. Very short statements tend to become slogans
which people chant but rarely understand the impact on what they do. Their
virtue is that they rarely become outdated. Long statements confuse people
because they contain too much for them to remember. Their virtue is that they
not only define what the company stands for but how it will keep its
promises.
In the ISO 9001 definition of quality policy it is suggested that the eight
quality management principles be used as a basis for establishing the policy.
One of these principles is the Customer Focus principle. By including in the
quality policy the intention to identify and satisfy the needs and expectations
of customers and other interested parties and the associated strategy by which
this will be achieved, this requirement would be fulfilled. The inclusion of the
strategy is important because the policy should guide action and decision.
Omitting the strategy may not ensure uniformity of approach and direction.

The standard requires that top management establish the quality policy.

ISO 9001 defines a quality policy as the overall intentions and direction of an organization related to quality as formally expressed by top management. It also suggests that the policy be consistent with the overall policy of the organization and provide a framework for setting quality objectives. Furthermore ISO 9001 advises that the eight quality management principles be used as a basis for forming the quality policy. The quality policy can therefore be considered as the values, beliefs and rules that guide actions, decisions and behaviours. A value may be ‘integrity’ and expressed as:

We will be open and honest in our dealings with those inside and outside the organization. A rule may be ‘confidentiality’ and expressed as Company information shall not be shared with those outside the organization. Both these are also beliefs because it might be believed that deceiving people only leads to failure in the long run. It might also be believed that disclosing confidential information fuels the competition and will drive the organization out of business. Both values guide actions, decisions and behaviours and hence may be termed policies. They are not objectives because they are not achieved – they are demonstrated by the manner in which actions and decisions are taken and the way your organization behaves towards others.

The detail of quality policy will be addressed later. What is important in this requirement is an understanding of why a quality policy is needed, what is required to establish a quality policy and where it fits in relation to other policies.

Defining the purpose or mission of the business is one thing but without some guiding policies, the fulfilment of this mission may not happen unless effort is guided in a common direction. If every manager chooses his or her direction, and policies, the full potential of the organization would not be realized. A shared vision is required that incorporates shared values and shared policies.

The purpose of corporate policies is to influence the short and long-term actions and decisions and to influence the direction in which the mission will be fulfilled. If there were policies related to the organization’s customers, they could be fulfilled at the expense of employees, shareholders and society. If there were policies related to profit, without other policies being defined, profit is positioned as a boundary condition to all actions and decisions. Clearly this may not direct the organization towards its mission.

As stated above, the quality policy is the corporate policy and such policies exist to channel actions and decisions along a path that will fulfil the organization’s purpose and mission. A goal of the organization may be the attainment of ISO 9001 certification and thus a quality policy of meeting the requirements of ISO 9001 would be consistent with such a goal, but goals are not the same as purpose as indicated in the box to the right. Clearly no organization would have ISO 9000 certification as its purpose because certification is not a reason for existence – an objective maybe but not a purpose.

Policies expressed as short catchy phrases such as “to be the best” really do not channel actions and decisions. They become the focus of ridicule when the organization’s fortunes change. There has to be a clear link from mission to policy.

Policies are not expressed as vague statements or emphatic statements using the words may, should or shall, but clear intentions by use of the words ‘we will’ – thus expressing a commitment or by the words ‘we are, we do, we don’t, we have’ expressing shared beliefs. Very short statements tend to become slogans which people chant but rarely understand the impact on what they do. Their virtue is that they rarely become outdated. Long statements confuse people because they contain too much for them to remember. Their virtue is that they not only define what the company stands for but how it will keep its promises.

In the ISO 9001 definition of quality policy it is suggested that the eight quality management principles be used as a basis for establishing the policy.

One of these principles is the Customer Focus principle. By including in the quality policy the intention to identify and satisfy the needs and expectations of customers and other interested parties and the associated strategy by which this will be achieved, this requirement would be fulfilled. The inclusion of the strategy is important because the policy should guide action and decision.

Omitting the strategy may not ensure uniformity of approach and direction.


ISO 9000 Standards – Conducting Management Reviews


ISO 9000 Standards – Conducting Management Reviews

The ISO 9000 standards requires that top management conduct
management reviews.
The term review is defined in ISO 9001 as an activity
undertaken to ensure the suitability, adequacy, effective-
ness and efficiency of the subject matter to achieve
established objectives. The addition of the term manage-
ment means that the management review can be
perceived as a review of management rather than a
review by management, although both meanings are conveyed in the standard.
The rationale for this is that the examples given in ISO 9000 such as design
review and nonconformity review clearly indicate it is design and non-
conformity that is being reviewed. If the system was to be reviewed then the
action should be called a system review. It is no doubt unintentional in the
standard but, if the management system is perceived as the way in which the
organization’s objectives are achieved, a review of management is in fact a
review of the way achievement of objectives is being managed because the
organization exists to achieve objectives and so both meanings are correct.
Top management will not regard the management review as important unless
they believe it is essential to running the business. The way to do this is to treat
it as a business performance review. This is simpler than it may appear. If the
quality policy is now accepted as corporate policy and the quality objectives
are accepted as corporate objectives, any review of the management system
becomes a performance review and no different to any other executive
meeting. The problem with the former management reviews was that they
allowed discussion on the means for achieving objectives to take place in other
management meetings leaving the management review to a review of errors,
mistakes and documentation that no one was interested in anyway. The
management system is the means for achieving objectives therefore it makes
sense to review the means when reviewing the ends so that actions are linked to
results and commitment secured for all related changes in one transaction.
The requirement emphasizes that top management conduct the review – not
the quality manager, not the operational manager – but top management – those
who direct and control the organization at the highest level. In many ISO 9000
registered organizations, the management review is a chore, an event held once
each year, on a Friday afternoon before a national holiday – perhaps a cynical
view but nonetheless often true. The reason the event has such a low priority
is that management have not understood what the review is all about. Tell
them it’s about reviewing nonconformities, customer complaints and internal
audit records and you will be lucky if anyone turns up. The quality manager
produces all the statistics so the others managers are free of any burden. By
careful tactics, these managers may come away with no actions, having
delegated any in their quarter to the quality manager.
In order to provide evidence of its commitment to conducting management
reviews, management would need to demonstrate that it planned for the
reviews, prepared input material in the form of performance results, metrics
and explanations, decided what to do about the results and accepted action to
bring about improvement.

The ISO 9000 standards requires that top management conduct management reviews.

The term review is defined in ISO 9000 Standards as an activity undertaken to ensure the suitability, adequacy, effectiveness and efficiency of the subject matter to achieve established objectives. The addition of the term management means that the management review can be perceived as a review of management rather than a review by management, although both meanings are conveyed in the standard.

The rationale for this is that the examples given in ISO 9000 Standards such as design review and nonconformity review clearly indicate it is design and non-conformity that is being reviewed. If the system was to be reviewed then the action should be called a system review. It is no doubt unintentional in the standard but, if the management system is perceived as the way in which the organization’s objectives are achieved, a review of management is in fact a review of the way achievement of objectives is being managed because the organization exists to achieve objectives and so both meanings are correct.

Top management will not regard the management review as important unless they believe it is essential to running the business. The way to do this is to treat it as a business performance review. This is simpler than it may appear. If the quality policy is now accepted as corporate policy and the quality objectives are accepted as corporate objectives, any review of the management system becomes a performance review and no different to any other executive meeting. The problem with the former management reviews was that they allowed discussion on the means for achieving objectives to take place in other management meetings leaving the management review to a review of errors, mistakes and documentation that no one was interested in anyway. The management system is the means for achieving objectives therefore it makes sense to review the means when reviewing the ends so that actions are linked to results and commitment secured for all related changes in one transaction.

The requirement emphasizes that top management conduct the review – not the quality manager, not the operational manager – but top management – those who direct and control the organization at the highest level. In many ISO 9000 registered organizations, the management review is a chore, an event held once each year, on a Friday afternoon before a national holiday – perhaps a cynical view but nonetheless often true. The reason the event has such a low priority is that management have not understood what the review is all about. Tell them it’s about reviewing nonconformities, customer complaints and internal audit records and you will be lucky if anyone turns up. The quality manager produces all the statistics so the others managers are free of any burden. By careful tactics, these managers may come away with no actions, having delegated any in their quarter to the quality manager.

In order to provide evidence of its commitment to conducting management reviews, management would need to demonstrate that it planned for the reviews, prepared input material in the form of performance results, metrics and explanations, decided what to do about the results and accepted action to bring about improvement.

ISO 9000 Standards – Document control procedures


ISO 9000 Standards – Document control procedures
The ISO 9000 Standards requires that a documented procedure be established to define the controls needed.

This requirement means that the methods for performing the various activities required to control different types of documents should be defined and documented.

Although the ISO 9000 standards implies that a single procedure is required, should you choose to produce several different procedures for handling the different types of documents it is doubtful that any auditor would deem this noncompliant. Where this might be questionable is in cases where there is no logical reason for such differences and where merging the procedures and settling on a best practice would improve efficiency and effectiveness.

Documents are recorded information and the purpose of the document
control process is to firstly ensure the appropriate information is available
where needed and secondly to prevent the inadvertent use of invalid
information. At each stage of the process are activities to be performed that
may require documented procedures in order to ensure consistency and
predictability. Procedures may not be necessary for each stage in the process.

Every process is likely to require the use of documents or generate documents and it is in the process descriptions that you define the documents that need to be controlled. Any document not referred to in your process descriptions is therefore, by definition, not essential to the achievement of quality and not required to be under control. It is not necessary to identify uncontrolled documents in such cases. If you had no way of tracing documents to a governing process, a means of separating controlled from uncontrolled may well be necessary.

The procedures that require the use or preparation of documents should also specify or invoke the procedures for their control. If the controls are unique to the document, they should be specified in the procedure that requires the document. You can produce one or more common procedures that deal with the controls that apply to all documents. The stages in the process may differ depending on the type of document and organizations involved in its preparation, approval, publication and use. One procedure may cater for all the processes but several may be needed.
The aspects you should cover in your document control procedures, (some
of which are addressed further in this chapter) are as follows
Planning new documents, funding, prior authorization, establishing need
etc.

- Preparation of documents, who prepares them, how they are drafted,
conventions for text, diagrams, forms etc.
- Standards for the format and content of documents, forms and diagrams.
- Document identification conventions.
- Issue notation, draft issues, post approval issues.
- Dating conventions, date of issue, date of approval or date of distribution.
- Document review, who reviews them and what evidence is retained.
- Document approval, who approves them and how approval is denoted.
- Document proving prior to use.
- Printing and publication, who does it and who checks it.
- Distribution of documents, who decides, who does it, who checks it.
- Use of documents, limitations, unauthorized copying and marking.
- Revision of issued documents, requests for revision, who approves the
request, who implements the change.
- Denoting changes, revision marks, reissues, sidelining, underlining.
Amending copies of issued documents, amendment instructions, and
amendment status.
- Indexing documents, listing documents by issue status.
- Document maintenance, keeping them current, periodic review.
- Document accessibility inside and outside normal working hours.
- Document security, unauthorized changes, copying, disposal, computer
viruses, fire and theft.
- Document filing, masters, copies, drafts, and custom binders.
- Document storage, libraries and archive, who controls location, loan
arrangements.
- Document retention and obsolescence.

With electronically stored documentation, the document database may provide many of the above features and may not need to be separately prescribed in your procedures. Only the tasks carried out by personnel need to be defined in your procedures. A help file associated with a document database is as much a documented procedure as a conventional paper based procedure.


Documents That Ensure Effective Planning, Operation And Control

Documents That Ensure Effective Planning, Operation And Control

The ISO 9000 standard requires management system documentation to include documents required by the organization to ensure the effective planning, operation and control of its processes.
The documents required for effective planning, operation and control of the processes would include several different types of documents. Some will be
product and process specific and others will be common to all processes. Rather than stipulate the documents that are needed, ISO 9000 Standards now provides for the organization to decide what it needs for the effective operation and control of its processes. This phrase is the key to determining the documents that are needed.
There are three types of controlled documents, namely:
- Policies and practices (these include process descriptions, control procedures, guides, operating procedures and internal standards)
- Documents derived from these policies and practices, such as drawings,
specifications, plans, work instructions, technical procedures and reports
- External documents referenced in either of the above
There will always be exceptions to this model but in general the majority of
documents used in a management system can be classified in this way.
Derived documents are those that are derived by executing processes;
for example, audit reports result from using the audit process, drawings result from using the design process, procurement specifications result from using the procurement process. There are, however, two types of derived document:
prescriptive and descriptive documents. Prescriptive documents are those that prescribe requirements, instructions, guidance etc. and may be subject to change. They have issue status and approval status, and are implemented in doing work. Descriptive documents result from doing work and are not
implemented. They may have issue and approval status. Specifications, plans, purchase orders, drawings are all prescriptive whereas audit reports, test reports, inspection records are all descriptive. This distinction is only necessary because the controls required will be different for each class of documents.


Create a Documented Implementation Plan In ISO 9000 Standards

Create a Documented Implementation Plan In ISO 9000 Standards

Once the organization has obtained a clear picture of how its quality management system compares with the ISO 9001:2008 standard, all non-conformances must be addressed with a documented implementation plan. Usually, the plan calls for identifying and describing processes to make the organization’s quality management system fully in compliance with the standard.

The implementation plan should be thorough and specific, detailing:

a. Quality documentation to be developed

b. Objective of the system

c. Pertinent ISO 9001:2008 section

d. Person or team responsible

e. Approval required

f. Training required

g. Resources required

h. Estimated completion date

These elements should be organized into a detailed chart, to be reviewed and

approved. The plan should define the responsibilities of different departments and personnel and set target dates for the completion of activities. Once approved, the Management Representative should control, review and update the plan as the implementation process proceeds.

Typical implementation action plan is shown in Figure 2. Use ISO 10005:1995 for guidance in quality planning.


Document Review In ISO 9000 Standards


Document Review In ISO 9000 Standards
The ISO 9000 Standard requires that documents be reviewed.
Previously the implication was that the review was a
check by potential users that the document was fit
for purpose before it was offered for approval. It
could be construed that for a document to receive
approval it must be checked and therefore ‘review
and approval’ in this context are one and the same
and the requirement is in this instance enhanced
rather than relaxed.
A review is another look at something. Therefore
document review is a task that is carried out at any
time following the issue of a document.
This requirement responds to the Continual Improvement principle.
Reviews may be necessary when:
- Taking remedial action (i.e. Correcting an error)
- Taking corrective action (i.e. Preventing an error recurring)
- Taking preventive action (i.e. Preventing the occurrence of an error)
- Taking maintenance action (i.e. Keeping information current)
- Validating a document for use (i.e. When selecting documents for use in
connection with a project, product, contract or other application)
- Taking improvement action (i.e. Making beneficial change to the
information)
Reviews may be random or periodic. Random reviews are reactive and arise
from an error or a change that is either planned or unplanned. Periodic reviews
are proactive and could be scheduled once each year to review the policies,
processes, products, procedures, specification etc. for continued suitability. In
this way obsolete documents are culled from the system. However, if the
system is being properly maintained there should be no outdated information
available in the user domain. Whenever a new process or a modified process
in installed the redundant elements including documentation and equipment
should be disposed of.
The ISO 9000 Standard requires that documents be reviewed.
Previously the implication was that the review was a
check by potential users that the document was fit
for purpose before it was offered for approval. It
could be construed that for a document to receive
approval it must be checked and therefore ‘review
and approval’ in this context are one and the same
and the requirement is in this instance enhanced
rather than relaxed.
A review is another look at something. Therefore
document review is a task that is carried out at any
time following the issue of a document.
This requirement responds to the Continual Improvement principle.
Reviews may be necessary when:
- Taking remedial action (i.e. Correcting an error)
- Taking corrective action (i.e. Preventing an error recurring)
- Taking preventive action (i.e. Preventing the occurrence of an error)
- Taking maintenance action (i.e. Keeping information current)
- Validating a document for use (i.e. When selecting documents for use in
connection with a project, product, contract or other application)
- Taking improvement action (i.e. Making beneficial change to the
information)
Reviews may be random or periodic. Random reviews are reactive and arise
from an error or a change that is either planned or unplanned. Periodic reviews
are proactive and could be scheduled once each year to review the policies,
processes, products, procedures, specification etc. for continued suitability. In
this way obsolete documents are culled from the system. However, if the
system is being properly maintained there should be no outdated information
available in the user domain. Whenever a new process or a modified process
in installed the redundant elements including documentation and equipment
should be disposed of.

Guidance on Clause 4.2 of ISO 9001:2008

Guidance on Clause 4.2 of ISO 9001:2008

The following comments are intended to assist users of ISO 9001:2008 in understanding the intent of the general documentation requirements of the International Standard.

a) Documented statements of a quality policy and objectives:

Requirements for the quality policy are defined in clause 5.3 of ISO 9001:2008. The documented quality policy has to be controlled according to the requirements of clause 4.2.3.

Note: Organizations that are revising their quality policy for the first time, or in order to meet the amended requirements in ISO 9001:2008, should pay particular attention to clause 4.2.3 (c), (d) and (g).

Requirements for quality objectives are defined in clause 5.4.1 of ISO 9001:2008. These documented quality objectives are also subject to the document control requirements of clause 4.2.3.

b) Quality Manual:

Clause 4.2.2 of ISO 9001:2008 specifies the minimum content for a quality manual. The format and structure of the manual is a decision for each organization, and will depend on the organization’s size, culture and complexity. Some organizations may choose to use the quality manual for other purposes besides that of simply documenting the QMS

A small organization may find it appropriate to include the description of its entire QMS within a single manual, including all the documented procedures required by the standard.

Large, multi-national organizations may need several manuals at the global, national or regional level, and a more complex hierarchy of documentation.

The quality manual is a document that has to be controlled in accordance with the requirements of clause 4.2.3.

c) Documented procedures:

ISO 9001:2008 specifically requires the organization to have “documented procedures” for the following six activities:

4.2.3 Control of documents

4.2.4 Control of records

8.2.2 Internal audit

8.3 Control of nonconforming product

8.5.2 Corrective action

8.5.3 Preventive action

These documented procedures have to be controlled in accordance with the requirements of clause 4.2.3 Some organizations may find it convenient to combine the procedure for several activities into a single documented procedure (for example, corrective action and preventive action). Others may choose to document a given activity by using more than one documented procedure (for example, internal audits). Both are acceptable.

Some organizations (particularly larger organizations, or those with more complex processes) may require additional documented procedures (particularly those relating to product realization processes) to implement an effective QMS.

Other organizations may require additional procedures, but the size and/or culture of the organization could enable these to be effectively implemented without necessarily being documented. However, in order to demonstrate compliance with ISO 9001:2008, the organization has to be able to provide objective evidence (not necessarily documented) that its QMS has been effectively implemented.

d) Documents needed by the organization to ensure the effective planning, operation and control of its processes:

In order for an organization to demonstrate the effective implementation of its QMS, it may be necessary to develop documents other than documented procedures. However, the only documents specifically mentioned in ISO 9001:2008 are:

- Quality policy (clause 4.2.1.a)

- Quality objectives (clause 4.2.1.a)

- Quality manual (clause 4.2.1.b)

There are several requirements of ISO 9001:2008 where an organization could add value to its QMS and demonstrate conformity by the preparation of other documents, even though the standard does not specifically require them. Examples

may include:

- Process maps, process flow charts and/or process descriptions

- Organization charts

- Specifications

- Work and/or test instructions

- Documents containing internal communications

- Production schedules

- Approved supplier lists

- Test and inspection plans

- Quality plans

All such documents have to be controlled in accordance with the requirements of clause 4.2.3 and/or 4.2.4, as applicable

e) Records:

Examples of records specifically required by ISO 9001:2008 are presented in Annex B.

Organizations are free to develop other records that may be needed to demonstrate conformity of their processes, products and quality management system.

Requirements for the control of records are different from those for other documents, and all records have to be controlled according to those of clause 4.2.4 of ISO 9001:2008.