ISO 9001: 2015 Tools for Auditors and Risk Based Thinking

Mr. Pareto Head and ISO 9001 audit

Question

In addressing clause 4 of ISO 9001:2015 regarding organization context and interested parties, what type of tool (spreadsheet, diagram, flowchart, etc), would you recommend to use to simplify the practice and to give a proper  understanding for auditors ?  I understand that risk evaluation (ISO 9001:2015) should be accomplished not only at a high level of establishing and planning objectives, but also at the processes level. If this is right, could organization use some criteria to select processes to be evaluated?

Answer

Thanks for contacting ASQ’s Ask the Experts program.  Regarding your inquiry, your selection of tools such as spreadsheets, diagrams, flowcharts and etc., should be driven by whatever best fits your organization’s context, QMS scope and requirements of interested parties.  However, before proceeding with tool selection to “simplify” practices as mentioned in your inquiry, it is essential that the changes and new requirements of ISO 9001:2015 are fully understood and communicated throughout the organization.  As you know, transitioning from ISO 9001:2008 to ISO 9001:2015 will require much more than providing understanding to Auditors.  The transition process should begin with top management and then flow down to the process owners and others throughout the organization.  If a gap analysis hasn’t already been completed, consider doing so to identify those processes that must be improved to meet ISO 9001:2015 certification requirements.

As you know, risk based thinking (RBT) must be a part of an every organization’s process approach, to ensure risks and opportunities are identified and addressed.  Although RBT is not new, it is a changed approach.  ISO 9001:2015 supports the scalability of quality management systems which allows them to be specific to an organization’s  processes, products, and services.  The landscape of today’s quality management systems has changed.  It’s not a “one size fits all” situation.  For this reason, it’s essential for top management, process owners as well as the QMS Auditors to develop a thorough understanding of ISO 9001:2015 and its requirements.  Also of equal importance is the familiarization of top management, process owners, and Auditors with the principals of risk assessment, management and related terminologies (i.e., ISO 31000:2009).

The effectiveness of future QMS audits will depend upon Auditors that can apply their collective knowledge of ISO 9001:2015, risk assessment, and management requirements, as well as their in-depth knowledge of the industries, processes, products, and systems, audited.  Exemplar Global and other accredited ISO 17024 personnel certification bodies have developed online training courses for the purpose of explaining the requirements of ISO 9001:2015.  Other information about transitioning to ISO 9001:2015 is available on the International Accreditation Form’s (IAF) website at www.iaf.nu.  Click this link to read about the recent publication of ISO 9001:2015 http://www.iaf.nu/articles/Publication_of_ISO_90012015/443

About the second part of your inquiry (item b.), it’s important to be aware that RBT applies to every process that comprises your organization’s quality management system.  RBT should be integrated into your organization’s QMS and product planning processes to ensure risks and opportunities are identified and addressed.

A few key questions to consider include, how will your Registrar verify your organization’s conformance with ISO 9001:2015 requirements?  What is your Registrar’s timeline for transitioning existing clients to ISO 9001:2015 requirements?  What type of support will be provided to assist clients through the transition process?

I hope this helps.

Best regards,

Bill

Bill Aston, Managing Director
Aston Technical Consulting Services, LLC
Kingwood, TX 77339
Office: (281) 359-ATCS (2827)

For more information about this topic, please visit ASQ’s website.

Sample Size and Z1.4

Data review, data analysis, data migration

Question

My question is if I’m trying to determine the sample size of migrated data to see if it migrated correctly to the target database, is the Z1.4 table applicable to that?

The scenario is data is being transferred from an old system to a new system and I want to do a quality check on the data in the new database to make sure everything was transferred correctly. I’m hoping to use the Z1.4 table to determine the sample size if its applicable. Is it applicable and if not, do you know of other standards that I should be looking into that is more applicable?

Answer

The movement of a database from one system to another certainly may introduce errors and it may also carry over errors that already exist. In some cases the move may also find and repair errors, yet that generally is done by design.

So, let’s say it’s just a move and you are checking for any new errors that are introduced.

Since you have access to the entire population, the database, in a before (old system) and after the move (new system) and I’m assuming you do not want to check every entry, instead just a sample, then I would recommend using an hypothesis test approach rather than a lot sampling approach.

A hypothesis test based on the binomial distribution may be appropriate as you are checking field entries to determine if they are correct or not (pass/fail).

You can set a threshold defect rate that you want to check the new system is at least this good or better, or you can measure the old system and compare to the new system – it should be equal to the old system as null hypothesis.

You can find a bit more information about a p-test in a good stats book or online at a short tutorial I wrote at https://creprep.wordpress.com/2013/06/01/hypothesis-tests-for-proportion/

The Z1.4 standard would require you to artificially define a lot or consider the entire database as one lot. The standard lot testing approach does not provide the control and statistical power of hypothesis testing, thus my recommendation. With the p-test you can define the confidence, defect rate to detect, and sample size to fit your needs concerning ability to make measurements, cost, and risk.

Cheers,

Fred

Fred Schenkelberg
Reliability Engineering and Management Consultant
FMS Reliability
(408) 710-8248
fms@fmsreliability.com
www.fmsreliability.com
@fmsreliability

For more on this topic, please visit ASQ’s website.

Sampling Schemes

Inventory, Inspection, Review, Suppliers, Supplies

Question

Is there a sampling plan for determining the number of cases to pull in a batch from which you perform the ANSI/ASQ sampling of individual products?  For example: you receive 550 cases with 145 product vials/case.  Is it proper to sample a total of 500 vials from 25 cases (using square root of n+1) or would applying the ANSI/ASQ single level II be more appropriate?  We would then need to pull 500 vials from 80 cases.  Or is there a better statistical method?

Answer

There are two ways to answer this. One is to follow the standard and take samples from 80 cases until you get 500. It is assumed that the samples are random so that you do not always take the samples from the same location in the case.  That is following the standard.

The second is that you take a sample from 25 cases in a random manner.  That is fine also.  There are no standards for sampling from cases so either way will work.  Years ago, I developed a sampling scheme similar to what is proposed at the employer I was working with at the time.  Sometimes you have to be creative.

Jim Bossert

SVP Process Design Manger, Process Optimization
Bank of America
ASQ Fellow, CQE, CQA, CMQ/OE, CSSBB, CSSMBB
Fort Worth, TX

For more on this topic, please visit ASQ’s website.

ISO 17025 and Business Changes

ISO/IEC 17025:2017 General requirements for the competence of testing and calibration laboratoriesQuestion

My organization has just been recently accredited to ISO/IEC 17025:2005. Shortly thereafter, changes were made to the organization’s structure and business operations.  I would like to know:

1) When should these changes be reflected in the Quality Manual?

2) Do I need to advise the local registrar about the changes?

3) Are these changes time-sensitive that need to be reported to the certifying body to maintain certification or, should I just wait for the next surveillance audit coming in about six (6) months?

Answer

Thank you for your question.  Updates to your Quality Management System and Quality Manual should be made as soon as they are implemented.  I would suggest notifying your CB of the changes now and let them plan for auditing these changes.  They will likely want to roll that into your next surveillance and not make a special visit.  That decision, of course, would be up to them.

Denis

Denis J. Devos, P.Eng
A Fellow of the American Society for Quality
Devos Associates Inc.
(519) 476-8951
www.DevosAssociates.com

For more on this topic, please visit ASQ’s website.

Six Sigma Black Belt

Chef, Six Sigma Black Belt

Question

I am currently an Executive Chef working that has been taking online classes for Green & Black Belt Six Sigma.  I am about halfway through my Black Belt classes and would like to pursue my certifications.  However, my company does not have a Six Sigma department and seem to be getting no where on working on a Six Sigma project so I could qualify for the Black Belt certification.  Do you have any advice or guidance that could help.

Answer

This is not an uncommon issue with a number of people.  What he should look into is to work as a volunteer at some non-profit organization on a Black Belt improvement project.  These organizations are always looking for help and this is a win-win for both him and the organization.  He will need to talk to them about what Six Sigma is and the type of project he is interested in doing.

Another possibility is to look at his place of work and if there is a part of the job that has to be done but no one likes doing it. If it is a process, then he could follow the DMAIC process and show improvement.  This could also serve as BB project if he can show the time savings was greater than 50%.

Jim

Jim Bossert
SVP Process Design Manger, Process Optimization
Bank of America
ASQ Fellow, CQE, CQA, CMQ/OE, CSSBB, CSSMBB
Fort Worth, TX

For more on this topic, please visit ASQ’s website.

Writing ISO 9001:2015 Procedures

architecture building city concrete

Question

I am in the process of implementing ISO 9001:2015 at a heavy civil construction company. I do not have any prior experience implementing but did work in an ISO environment for 13 years. I am looking for assistance on how to go about writing procedures to ensure that they incorporate the ISO requirements.

Answer

Thanks for contacting ASQ’s Ask the Experts program.  Concerning writing procedures, there are a few things to consider.  In general, a procedure should be structured to define its purpose or scope.  If the procedure is intended to address an identified risk or opportunity, it should be stated.  Likewise, consider including specific references to customer, industry standards, and internal requirements that are being addressed in the procedure.

Other key points to consider include structuring the procedure to be consistent with the flow of the process or activities controlled by the procedure.  Also, if appropriate, include reference to acceptance criteria, identify who, when, and how these activities will be conducted.  References to any required records to be maintained to provide evidence of conformance should also be a part of the procedure.  The importance of ensuring the participation of the process owner as well as others responsible for performing the activities identified in the procedure can’t be overstated.  If possible, the process owner and other interested parties should be involved in the development, review and approval of the procedure.

I hope this helps.

Best regards,

Bill

Bill Aston, Managing Director
Aston Technical Consulting Services, LLC
Kingwood, TX 77339
Office: (281) 359-2827

For more on this topic, please visit ASQ’s website.

Dual Certifications

Drill, oil, petroleum

Question

Our company currently holds dual certifications to API Q1 and ISO 9001:2008 that are not set to expire until November 2017. When making the transition to ISO 9001:2015 and re-certifying in November 2017, will we be able to do dual certifications or will we have to do API Q1 separate from ISO 9001:2015?

Answer

Hello,

Thank you for contacting ASQ’s Ask the Experts program.  In response to your inquiry, the timing for transitioning your existing QMS from ISO 9001:2008 to ISO 9001:2015 is dependent upon your Registrar’s timeline to begin issuing ISO 9001:2015 certifications.  I highly recommend that you discuss this subject with your Registrar to determine how and when this transition will take place.  In my professional opinion, this transition process may be similar to the recent move from API Q1, 8th edition to API Q1, 9th edition.

Since your current certification expires November 2017, transitioning sooner rather than later is recommended.  Especially since unlike API Q1, the ISO 9001 certification expiration date cannot be extended.

I hope this helps.

Best regards,

Bill

Bill Aston, Managing Director
Aston Technical Consulting Services, LLC
800 Rockmead, Suite 170, Kingwood, TX 77339
Office: (281) 359-2827
Website: www.astontechconsult.com

For more on this topic, please visit ASQ’s website.

Internal Audits

Reporting, best practices, non-compliance reporting

Question

If 2nd or 3rd party performs full system audit on my QMS, can it be used as to satisfy requirement for Internal Audit of that year?

Answer

Thank you for sending your question to ASQ’s Ask The Experts program.

My first response to your question would simply be, no you cannot use a 2nd or 3rd party audit to satisfy the requirement for Internal Audits.

The thing to consider is, who will the final Audit Report go to? That is, who is the customer?  An Internal Audit is conducted to your QMS and to your criteria. The final report would generally be directed to senior management.

A second or third party audit is most often performed by a customer or by a registrar. They would be guided by different criteria. A customer audit would not be of your entire QMS or give evidence of its overall efficacy. It would be inspired by what would be pertinent to the product or service you provide to them. A registrar audit would be to verify your facility’s compliance to standards but not necessarily the entire QMS.

You can see how this would be leading down a path one wouldn’t want to follow.  Therefore, Internal Audits should remain . . . internal.

Bud Salsbury, CQT, CQI

For more on this topic, please visit ASQ’s website.

Sample Size

Manufacturing, inspection, exclusions

Question

If we have a lot size of 27 and we are using a normal inspection level II with an AQL of 2.5. What is the sample size?

Answer

Assuming an attribute is being measured, we use ANSI ASQ Z1.4.2013 to find the sample size.

Given a lot size of 27 we first find in Table I. Sample Size Code Letter that Code letter D represents the sampling plan code letter for lot sizes between 26 and 50 for normal sampling (General Inspection Level II).

The move to Table II-A Single sampling plans for normal inspection to find the row for code letter D and under column for ASQ 2.5 find an up arrow. This indicates that we should use the code letter C which suggests a sampling plan of 5 samples and accept the lot if there are zero defect and reject the lot with one or more rejects.

Hope that helps.

Cheers,

Fred

Fred Schenkelberg
Reliability Engineering and Management Consultant
FMS Reliability
(408) 710-8248
fms@fmsreliability.com
www.fmsreliability.com
@fmsreliability

For more on this topic, please visit ASQ’s website.

Risk Based Thinking in ISO 9001:2015

Reporting, best practices, non-compliance reporting, analysis

Question

In 0.3.3 clause of the standard – it is said that “A positive deviation of the risk can provide an opportunity, but not all positive effects of risk result in opportunities.”  Can you please clarify this statement?

Answer

Thanks for contacting ASQ’s Ask the Experts program.  Good question! As mentioned, ISO FDIS 9001:2015, Clause 0.3.3, which states, “A positive deviation of the risk can provide an opportunity, but not all positive effects of risk result in opportunities”.

In my opinion, this highlights an important point.  That is, not every positive deviation or change of a risk will include opportunity.  Consider the recent changes that have occurred in the Oil and Gas industry.  When the demand for crude oil was high, the availability of various materials and services providers was low, and prices were high.  This situation (availability of materials, services providers and costs) may have been identified as a supply chain risk.

However, the oversupply of crude oil drove prices down.  Crude oil production has dropped to stabilize pricing at the pumps.  This positive deviation of risk has provided an opportunity to crude oil producers, which includes the improved availability of materials, greater selection of services providers as well as more competitive pricing.  So dependent upon where you sit, this deviation of risk may be considered a negative that has decreased product demand and lowered pricing or a positive that has lowered consumer pricing and increased availability.

Consider companies that are providers of upstream services to crude oil producers.  Their risk based thinking may have identified the supply of qualified personnel to perform upstream servicing as a risk.  The decrease in demand for upstream services has increased the pool of qualified personnel.  However, this positive deviation of risk does not represent an opportunity.  The scenarios mentioned above are basic and intended to highlight the point of ISO FDIS 9001:2015, Clause 0.3.3.  There are far more dynamics that should be considered when assessing the deviation of risk versus opportunity.

I hope this helps.

Best regards,

Bill

Bill Aston, Managing Director
Aston Technical Consulting Services, LLC
Kingwood, TX 77339
Office: (281) 359-ATCS (2827) or Toll Free: (888) 968-9891
Website: www.astontechconsult.com

For more on this topic, please visit ASQ’s website.