Friday, November 5, 2010

The Difference Between Compliance Auditing and Systems Auditing In ISO 14001


Often however, there is confusion between regulatory compliance auditing and EMS auditing. This is because there are many elements of regulatory compliance that overlap with the EMS. Recall that the criteria in a compliance audit are the applicable regulations, whereas the criteria in an EMS audit would be ISO 14001. But does not ISO 14001 address compliance? The answer is yes, but from a system standpoint, not performance.
In other words, the standard requires that certain procedures exist regarding identification of legal and other requirements, that periodic compliance assessments be performed, that legal requirements be considered in setting objectives and targets, and that there be a commitment to compliance. However, actually being in compliance is a performance issue, and out of the purview of ISO 14001.
Of course, a system that is constantly out of compliance or does not identify and initiate action to correct noncompliances, will eventually fail due to system failure. The subtle, yet important point is that during an EMS audit, identified regulatory noncompliances are relevant only to the extent that they reflect a potential system problem. The finding therefore is not that the site is out of compliance with a given regulation, but that the noncompliance means some EMS element is not conformed to. For example, a regulatory noncompliance can be related to a problem with training, recordkeeping, or monitoring and measurement.
The EMS auditor is not to do a compliance audit as part of the EMS audit. If, as part of the statistical sampling to verify EMS element requirements, the auditor identifies a regulatory noncompliance, he or she treats it as any other evidence.
This point has been difficult to accept, especially in U.S. industry because of our long history of regulatory enforcement. The EMS auditor needs to constantly remember that compliance auditing is being done separately as part of the EMS requirements itself (4.5.1, paragraph 3) and to stay focused on the criteria at hand – ISO 14001 and the site’s EMS. There may be legal requirements regarding noncompliances encountered during the EMS audit, but this should be decided and addressed in the audit plan.
In summary, the goal of the compliance audit is to verify compliance with regulations, whereas the EMS audit’s goal is to verify that the EMS conforms to planned arrangements, including ISO 14001.

The Audit Plan In ISO 14001

The Audit Plan In ISO 14001
The audit plan is the document that establishes the scope, objectives and criteria, and schedule of the audit. It also goes into specific details on what areas will be audited, when, and by whom.
Other details such as which checklists may be used, how the report is to be formatted and distributed, and how meetings will be conducted can also be included in the plan. In essence, the audit plan reflects the programs, procedures, and methodologies of the EMS audit process, in accordance with element 4.5.4 of ISO 14001. These planning items are usually described in the procedures for element 4.5.4 and do not need to be re-created every time an audit occurs. For example, it can be determined that the entire EMS will be audited once per year, but in four partial events. This schedule then becomes part of the procedure.
The audit scope defines what part of the organization will be audited. Obviously, this should coincide with the scope of the EMS itself, and is usually the site in question. If the full EMS audit is divided in smaller segments conducted throughout the year, then the scope of any given segment is what portion of the organization will be audited at that time. Typically, an organization will create a chart or matrix showing the various divisions of the site or activity and when it will be audited. A typical entry may show the maintenance department being audited in the first quarter and production in the fourth quarter, for example.
Also noted in the audit plan is the audit objective(s). The audit objective describes why an audit is being conducted. Typically the reason is to conform to ISO 14001 4.5.4 requiring that the EMS be periodically evaluated. Another reason is demonstrate conformance to others.
Although EMS audits may appear in their own right to be “good practice”, it is essential that auditors have a clear concept of what the general objectives of such audits are.
The definition of EMS audits highlights the need to confirm conformance with planned arrangements and to ensure that these arrangements are effective and suitable to achieve objectives. ISO 14011 expands this to form a number of general objectives for any type of EMS audit. Audits should be carried out to:
- determine conformance of an auditee’s EMS with the EMS audit criteria
- determine whether the auditee’s EMS has been properly implemented and maintained
- to identify areas of potential improvement in the auditee’s EMS
- assess the ability of the internal management review process to ensure the continuing suitability and effectiveness of the EMS
- evaluate the EMS of an organization where there is a desire to establish a contractual relationship, such as with a potential supplier or a joint-venture partner.
Using this definition and sources such as ISO 14010 and 14011, the following statement of the specific objectives of an internal EMS audit has been developed. Internal audits should be carried out to ensure that:
- The EMS continues to meet the needs of the business
- The necessary documented procedures that exist are practical and satisfy any specified requirements
- The necessary documented procedures are understood and followed by appropriately trained personnel
- Areas of conformity and nonconformity with respect to implementation of the EMS system are identified and corrective action implemented
- The effectiveness of the system in meeting the EMS objectives is determined and that a basis is created for identifying opportunities and initiating actions to improve the EMS system
The above objectives imply that internal audits are concerned with more than just the policing of an established system. If auditors and managers are to remain committed to the implementation of the EMS system, it must also contribute to the process of developing that system and seeking improvements.
Internal auditing must not be carried out in a way that results in the transfer of responsibility from the operating staff to the auditor or auditing organization, i.e., at all times the individual or department must retain and accept responsibility for his or her role in the EMS.
If the internal audit process is not designed and implemented to meet the objectives and to avoid the pitfalls described above, it is unlikely that the top management commitment essential to an effective audit process will be readily forthcoming.
The audit criteria define what the “rules” are. For the sake of this guide, the criteria will be the elements of ISO 14001. A subtle point to note however is that the site’s EMS requirements are also part of the criteria. This means that in addition to responding to the requirements of ISO 14001, the EMS must also respond to “planned arrangements”, or what the organization said it was going to do. In audits, a common response is “the standard does not require such and such detail”. However, if the site’s procedure does require some specific response, then it becomes part of the criteria. In essence, the auditors are verifying the system not only to ISO 14001, but also to what the EMS documentation states.
How the audit is divided and scheduled throughout the time interval is up to the organization and will be a function of minimizing disruption to site operations and resource needs. The only requirement is that the full audit be completed within the frequency established in the procedures under 14001, 4.5.4. One of the requirements regarding frequency is that how often an area is audited be in part a function of prior audit results. This means that the planned frequency may change with time based on what auditors are finding.
How long each audit takes again is a function of resource needs and operations. It is recommended, however, that any individual audit event not be protracted out over long time periods. The longer a task takes, the easier it is to get distracted and lose focus.
Much has been written about how to audit a system if the full audit is not completed in one event. Unlike other audits, including quality audits, where a more segmented approach can be taken, ISO 14001 systems tend to be very sensitive to consistency. For example, the emergency planning process may conform to the standard element 4.4.7 in that a procedure exists; however,
it may not reflect the potential significant impacts identified in element 4.3.1. Had the audit team focused only on element 4.4.7, they would not have noted the apparent nonconformance.
When developing an audit plan, it is wise to consider the three C’s of ISO 14001 EMS auditing:
Conformance, Consistency, and Continual Improvement. Conformance relates to addressing each of the requirements of the standard, i.e., the “shalls”. Consistency relates to how well each procedure or process of the EMS relates to the others. In other words, do objectives and targets reflect the policy commitments? Are personnel trained on the correct legal and other requirements? Finally, Continual Improvement requires that the system lead to improvements in the system itself as well as with environmental performance. A system that has all the prerequisite procedures, but remains static, is not in conformance.
The concepts of consistency and continual improvement are more subtle because they are through-running threads of the standard and not always a definitive statement. The required commitment to continual improvement and the text of the standard itself however do go some way towards reminding the auditor.
With the three C’s in mind, one now sees why it is best to audit all applicable elements of the standard in a given area at one time, rather that tracing any one standard element throughout various areas. For example, during the first quarter audit event, Company X may audit all of ISO 14001 in maintenance. During the second quarter event, all of ISO 14001 will be audited in the production area, and so on. This is in contrast to auditing only a certain element, i.e., corrective action, across several site areas in one audit event.
Now we know what is being audited, when it is being audited, and to what “rules” it is being audited. The remainder of the plan is simply then the logistics of the audit. The logistics include identification of team members, noting if and what checklists will be used, schedule and formats of meeting to name a few. Below is the full list of recommended audit plan elements as described in ISO 14011:
• the audit objectives and scope;
• the audit criteria;
• identification of the auditee’s organizational and functional units to be audited;
• identification of the functions and/or individuals within the auditee’s organization having significant direct responsibilities regarding the auditee’s EMS;
• identification of those elements of the auditee’s EMS that are of high audit priority;
• the procedures for auditing the auditee’s EMS elements as appropriate for the auditee’s organization;
• the working and reporting languages of the audit;
• identification of reference documents;
• the expected time and duration for major audit activities;
• the dates and places where the audit is to be conducted;
• identification of audit team members;
• the schedule of meetings to be held with the auditee’s management;
• confidentiality requirements;
• report content and format, expected date of issue and distribution of the audit report;
• document retention requirements.
If the internal audit is to proceed smoothly, it is helpful for the internal auditor to establish a dialogue prior to the actual audit with the person responsible for the area being audited. This dialogue may be conducted by memo, telephone, or during a formal or informal meeting. The main factor that should influence the auditor’s choice of method for setting up this dialogue should be the organization’s normal style or culture. Irrespective of the method of communication the auditor adopts, the following points should be established:
• The overall duration of the proposed audit
• The starting location and time
• The proposed scope and areas to be covered by the audit
• A timetable for approximate progress of the audit where applicable, e.g., if a number of different departments or geographical areas are to be included in the scope of the audit
• The arrangements for any close out meeting where the findings of the audit can be agreed and corrective action requirements discussed
• The personnel liable to be involved at each stage of the audit
If an auditor does not give sufficient attention to ensuring that clear agreement is reached with respect to the above points, the potential for misunderstandings that can affect the conduct of the audit is greatly increased. However, these initial communications with the personnel of the area being audited not only affect the “tone” of the forthcoming audit, but they can significantly influence the commitment and level of cooperation shown by that area throughout the audit process and for many subsequent audits.
Prior to commencing the audit, but once the plan is prepared, the audit team assignments are made, and working documents are defined. Working documents are those documents such as observation logs and checklists that are used during the audit to collect evidence, but are not necessarily retained as records. In other words, they may be discarded after the audit is complete and the report prepared.
Of these, only the checklist should require an input at this stage from the auditor. However, before compiling a checklist, the auditor must determine if the function and format of the checklist are prescribed by the audit procedure or whether personal preference can be exercised.
The format of the checklist may vary considerably, depending on whether it is intended to act as an aide or as a part of audit records showing the scope and conduct of the audit. The former may consist only of general topics to be covered during the audit, whereas the latter may be an extensive and detailed questionnaire on which details of sampling and answers to the questions are to be recorded.
The need for checklists and the type appropriate will vary according to other experience of the auditors and the culture of the company. It is recommended that for purposes of internal audits, checklists, even if limited, should always be developed. However, standard questionnaire type checklists not prepared by the auditor that must be slavishly followed and completed, should be
avoided. This latter type is likely to result in an unnecessary restriction in the scope of the audit and a stifling of auditor initiative.
Although an auditor should always work within the scope defined for the audit, the working documents must not be designed so that they restrict additional audit activities or investigations that may become necessary as a result of information gained during the audit. There are differences of opinion over whether it is preferable to create the checklist anew or whether a previously developed checklist can be used. Although the former is desirable in principle, it is not always practical in terms of the best use of the resources available. The best compromise is to utilize whatever available checklists are already in existence, but to review these critically
against the relevant documents previously identified. In this way, time can be saved in using them as a foundation without detracting from effectiveness.

The Audit Report In ISO 14001


Once agreement has been reached, both among the audit team and with the auditee, it is time to prepare the audit report. Note that ISO 14001 does not require a documented audit report. However, it is very difficult to verify that the auditing requirement has been satisfied without a supporting record, which is typically a documented audit report.
The audit report is prepared by the lead auditor, although he or she may have other team members prepare portions. The content of the audit report is determined by the audit plan and the organization’s EMS audit procedures. Having completed the examination phase and evaluated the collected data observations, etc., the assessor is faced with the problem of documenting any deficiencies he or she may have found. There are many different methods of documenting deficiencies, ranging from inclusion in the body of the audit report to producing non-conformance notes or corrective action requests. Irrespective of which method is adopted, the basic principles to be followed are similar. ISO 14001 does not dictate what should be in the report, and ISO 14011 only suggests contents. ISO 14011 indicates that at a minimum, the findings need to be in the report. The findings appear as a statement that the EMS is or is not in conformance with the criteria, and states what the criteria and supporting evidence are for the statement. ISO 14011 also lists other optional items to include such as:
• the identification of the organization audited and of the client;
• the agreed objectives, scope and plan of the audit;
• the agreed criteria, including a list of reference documents against which the audit was conducted;
• the period covered by the audit and the date(s) the audit was conducted;
• the identification of the auditee’s representatives participating in the audit;
• the identification of the audit team members;
• a statement of the confidential nature of the contents;
• the distribution list for the audit report;
• a summary of the audit process including any obstacles encountered;
• audit conclusions such as:
- EMS conformance to the EMS audit criteria;
- whether the system is properly implemented and maintained;
- whether the internal management review process is able to ensure the continuing suitability and effectiveness of the EMS.
The format of such reports can vary considerably and may range from completion of a simple pro-forma to expansive documents describing all aspects of the audit performance and findings. However, irrespective of the style and format, the audit report should cover the key topics already identified as being essential for discussion and presentation at the opening and closing meetings. In constructing the report two specific objectives must be borne in mind.
(1) The report has to provide objective evidence of effective implementation of the audit procedure.
(2) The report has to allow for corrective action to be addressed and that the follow-up requirements can be established and initiated.
Where there are non-conformances, there are various options regarding deficiency reporting. One option is to describe each of the deficiencies identified in the main body of the report along with any supporting evidence, and if requested, corresponding recommendations. Although this may result in a comprehensive report of audit findings, it has the disadvantage that the individual
deficiencies are often difficult to locate, particularly when trying to monitor follow-up actions.
This can be partly overcome by writing separate corrective action requests for this purpose. A useful alternative that is less time consuming is to restrict the description of deficiencies in the body of the report to general summaries only. Details of deficiencies can then be included in non-conformance notes. Ideally, the non-conformance note should also provide space for agreeing corrective actions and recording subsequent monitoring of that corrective action. In this manner, any duplication of effort with respect to audit reporting is minimized, thus producing a more easily managed system. It is important that however non-conformances are handled, it be constant with the EMS correction action process (ISO 14001, Section 4.5.2).
Before considering the steps in preparing the non-conformance note we must be clear about their purpose.
• To convey to the auditee the findings in a clear and accurate manner so that they know what to do next.
• To advise the EMS personnel or other auditors what you have found so that he can follow it up.
• To present a record that can be reviewed remotely from the scene and be understood.
All non-conformance notes must contain certain basic information.
• The physical area being audited.
- Failure to record this often results in great confusion 3 to 6 months later when a follow up visit is carried out to review corrective action implementation.
• The specific clause(s) of the assessment standard(s) against which the non-conformance is issued.
- If the auditor is unable to readily identify the applicable section of the EMS manual or the procedure against which to issue the non-conformance, he must question whether or not he is justified in writing the non-conformance. It is good practice to re-read the
requirements of the relevant system documentation to confirm that these can be interpreted as supporting the non-conformance. If they do not, then the non-conformance cannot be issued.
• The detailed nature of the non-conformance including the specific identity of documents/procedures/material, etc.
Earlier we considered the requirements for recording observations during the assessment and emphasized the need for them to be factual and to contain objective evidence that the system requirements were not being satisfied. Although this appears to be fairly straightforward, in practice this is often not the case. It is not unusual for inexperienced auditors to identify a deficiency only to fail to communicate the findings in a manner that facilitates implementation of the appropriate corrective action. The non-conformance note, while not being over long, must contain sufficient information to enable a person not present during the audit to be able to gauge the seriousness or otherwise of the observation.
The use of descriptive terms such as extensive, several, isolated, etc… is essential to communicate accurately the nature and extent of the deficiency, but care must be taken to ensure that their use does not result in a lack of objectivity; e.g., the term extensive can only be included if there is irrefutable evidence to justify its use. The auditor must also take care to ensure that the description is not only accurate but it is also fair, e.g., a statement that 50% of manifests were incorrectly signed may be accurate but is hardly fair if only two manifests were sampled.
Having documented the nature of the deficiency, some audit systems require the auditor to grade the deficiency or non-conformance, e.g., major and minor. It is not intended to discuss grading systems in detail since there are many potential variations that companies may wish to adopt. Irrespective of what system is being adopted, the auditor must ensure that the grading given and
the text describing the deficiency are completely compatible.
Distribution of the audit report and nature of documentation are decided between the auditor and auditee, although this too is usually addressed in the audit plan. An audit is considered successful when the auditee and client feel that they have useful, constructive feedback that allows them to improve the system.

Sunday, August 29, 2010

How Quality Management System is implemented?

How Quality Management System is implemented?

The terms ‘establish’, ‘document’, ‘implement’, ‘maintain’ and ‘improve’ are used in the ISO 9000 Standard as though this is a sequence of activities when in reality, in order to establish a system it has to be put in place and putting a system in place requires two separate actions:
- Design the Quality Management System using a process that transforms the system requirements into specific characteristics that results in a clear definition of all the processes that meet the system requirements.
- Construct the system using a process that documents, installs, commissions and integrates the processes to deliver the required business outputs.
The way in which these phases of quality system development are related is
illustrated in the management system process model shown in Figure 4.1. This diagram has some important features. Note that the design input to the system comprises internal and external requirements. On the right side there are four improvement routes:
- Improvements in conformity during operation of the system arise through
enforcing policy and practices – doing what you say you do
- Improvements in conformity during system construction arise through
enforcing policy and design rules on the system – reworking the system to
comply with the established policies and objectives
- Improvements in efficiency during system construction arise through
finding better ways of implementing the system design – shorter, less
wasteful routines, less complexity, lower skill levels, fewer resources
- Improvements in effectiveness arise as a result of identifying different
policies and objectives – higher targets, new objectives, new requirements,
regulations, and new technologies.
As indicated above, establishing a system means designing and constructing it, which can be referred to as system development. System design is dealt with under Identifying processes. Constructing the system covers documentation, resourcing, installation, commissioning, qualification and integration.

Documenting A Quality Management System

Documenting A Quality Management System

The ISO 9000 Standards requires the organization to document a quality management system in accordance with the requirements of ISO 9001. A document (according to ISO 9000 clause 2.7.1) is information and its supporting medium. A page of printed information, a CD ROM or a computer file is a document, implying that recorded information is a document and verbal information is not a document.
Clause 4.2 requires the management system documentation to include certain types of documents and therefore does not limit the management system documentation to the types of documents listed.
As a management system is the means to achieve the organization’s objectives, and a system is a set of interrelated processes, it follows that what has to be documented are all the processes that constitute the system.
While there is a reduction in emphasis on documentation in ISO 9001:2008 compared with the 1994 version, it does not imply that organizations will need less documentation to define their management system. What it does mean is that the organization is left to decide the documentation necessary for effective operation and control of its processes. If the absence of specific documentation does not adversely affect operation and control of processes, such documentation is unnecessary.
Before ISO 9000 came along, organizations prospered without masses of
documentation and many still do. Those that have chosen not to pursue the
ISO 9000 path often only generate and maintain documents that have a useful purpose and will not produce documents just for auditors unless there is a legal requirement. Most of the documentation that is required in ISO 9000 came about from hindsight – the traditional unscientific way organizations learn and how management systems evolve.
ISO 9000 contains a list of valid reasons for why documents are necessary as below:
- To communicate requirements, intentions, instructions, methods and results effectively
- To convert solved problems into recorded knowledge so as to avoid having
to solve them repeatedly
- To provide freedom for management and staff to maximize their contribution to the business
- To free the business from reliance on particular individuals for its effectiveness
- To provide legitimacy and authority for the actions and decisions needed
- To make responsibility clear and to create the conditions for self-control
- To provide co-ordination for inter-departmental action
- To provide consistency and predictability in carrying out repetitive tasks
- To provide training and reference material for new and existing staff
- To provide evidence to those concerned of your intentions and your actions
- To provide a basis for studying existing work practices and identifying
opportunities for improvement
- To demonstrate after an incident the precautions which were taken or which should have been taken to prevent it or minimize its occurrence
If only one of these reasons make sense in a particular situation, the
information should be documented. In some organizations, they take the
view that it is important to nurture freedom, creativity and initiative and
therefore feel that documenting procedures is counterproductive. Their view is that documented procedures hold back improvement, forcing staff to follow routines without thinking and prevent innovation. While it is true that blindly enforcing procedures that reflect out-of-date practices coupled with bureaucratic change mechanisms is counter productive, it is equally shortsighted to ignore past experience, ignore decisions based on valid evidence and encourage staff to reinvent what were perfectly acceptable methods.
Question by all means, encourage staff to challenge decisions of the past, but
encourage them to put forward a case for change. That way it will cause
them to study the old methods, select the good bits and modify the parts that are no longer appropriate. It is often said that there is nothing new under the sun – just new ways of packaging the same message.

What Should Be Documented In Quality Management System?

What Should Be Documented In Quality Management System?

Clause 4.2.1 in ISO 9000 Standards requires quality management system documentation to include 5 types
of document:
(a) Quality policy and objectives
(b) Quality manual
(c) Documented procedures
(d) Documents needed to ensure the effective planning, operation and control of processes
(e) Records
Other than the requirements in clause 4 for documentation, there are 14 other references requiring documentation. These are as follows:
(a) The output of the planning
(b) The quality manual
(c) A documented procedure for document control
(d) A documented procedure for the identification, storage, retrieval, protection, retention time and disposition of records.
(e) Planning of the realization processes
(f) Inputs relating to product requirements
(g) The outputs of the design and development process
(h) Design and development changes
(i) The results of the review of changes and subsequent follow up actions
(j) A documented procedure for conducting audits that includes the responsibilities and requirements
(k) Evidence of conformity with the acceptance criteria characteristics of the product
(l) A documented procedure for nonconformity control activities
(m)A documented procedure for corrective action
(n) A documented procedure for preventive action
This list is somewhat inadequate for documentation purposes because it does not tell us what types of things we should document or provide criteria to enable us to decide what we need to document. ISO 9000 clause 2.7.2 includes a more useful list of document types that are classified as follows:
(a) Quality manuals
(b) Quality plans
(c) Specifications
(d) Guidelines
(e) Procedures, work instructions and drawings
(f) Records
This list is similar to that in clause 4.2.1 with some notable differences. The
policy and objective could form part of the quality manual and the quality plans, work instructions, guidelines, drawings and specifications could be the documents needed to ensure the effective planning, operation and control of processes.
Obviously the size, type and complexity of the organization and the competency of personnel will have an effect on the depth and breadth of the
documentation but the subject matter other than that which is product, process or customer specific is not dependent on size, type and complexity of the organization etc. There is no single method that will reveal all the things that should be documented but there are several approaches that can be used to reveal the documentation necessary.

Wednesday, July 14, 2010

ISO 14001 Standard & Environmental Issues

ISO 14001 Standard & Environmental Issues

ISO 14001 is a systematic tool that enables an organization in any market sector to focus on their situation, identify the relevant environmental issues and to lessen their impact to their benefit and the environment. It is part of a global response to the recognition that we are damaging the environment in which we all live. The cause and effect of the foremost world environmental issues, which are all due to mankind, are generally too vast and too intangible for us to grasp and so the slightly cliché expression ‘think global, act local’ is very relevant. Once the EMS is implemented and to become registered to ISO 14001, the external auditor will assess your EMS in two separate stages, on site. The first stage to understand your business activities and determine formal readiness for assessment and the second to check practical compliance with ISO 14001. After registration he will return at regular intervals every year to verify continual improvement and regulatory compliance, against your set objectives and your EMS. The external auditor should be seen as a wise friend, not a policeman. He should certainly explain his findings and assist the company to find ISO 14001 registration is not a cure for all environmental problems but I hope I’ve demonstrated that it is a worthwhile, if not essential business initiative that could enable your management to better manage your business, gain commercial advantage and minimize its environmental impact.