Combating Contamination

Workplace safety, OHSAS 18001, work environments

Q: We want to ensure that we are receiving clean containers to package our products. How can we improve our incoming inspection process?

A: You should encourage your vendor to ship only clean containers. Then, be sure that the shipping and receiving process doesn’t cause contamination. If you can determine the source or sources of the contamination, the best fix is to remove the cause.

If that approach is not possible and you have incoming containers that may have some contamination, then consider the following elements in creating an efficient incoming inspection process.

1) How do you detect the contamination?

Apparently, you are able detect the container contamination prior to filling them, or are able to detect the effect of the contamination on the final product. Given that you are interested in creating an incoming test, let’s assume you have one or more ways to detect faulty units.

As you may already know, there are many ways to detect contamination. Some are faster than others, and some are non-destructive. Ideally, a quick non-destructive test would permit you to inspect every unit and to divert faulty units to a cleaning process. If the testing has to be destructive, then you’ll have to consider lot sampling of some sort.

There are many testing options. One is the optical inspection technique, which may find gross discoloration or large debris effectively. Avoid using human inspectors unless it’s only a short term solution, as we humans are pretty poor visual inspectors.

Another approach is using light to illuminate the contamination, such as a black light (UVA). Depending on the nature and properties of the contamination, you may be able to find a suitable light to quickly spot units with problems.

Another approach, which is more time consuming, is conducting a chemical swab or solution rinse and a chemical analysis to find evidence of contamination. If the contamination is volatile, you might be able to use air to “rinse” the unit and conduct the analysis. This chemical approach may require specialized equipment. Depending on how fast the testing occurs, this approach may or may not be suitable for 100 percent screening.

There may be other approaches for detecting the faulty units, yet without more information about the nature and variety of contamination, it’s difficult to make a recommendation. Ideally, a very fast, effective and non-destructive inspection method is preferred over a slow, error prone, and destructive approach. Cost is also a consideration, since any testing will increase the production costs. Finding the right balance around these considerations is highly dependent on the nature of the issue, cost of failure, and local resources.

2) How many units do you have to inspect?

Ideally, the sample size is zero as you would first find and eliminate the source of the problem. If that is not possible or practical, then 100 percent inspection using a quick, inexpensive, and effective method permits you to avoid uncertainties with sampling.

If the inspection method requires lot sampling, then all of the basic lot sampling guidelines apply. There are many references available that will assist you in the selection of an appropriate sampling plan based on your desired sampling risk tolerance levels.

Another consideration is the percentage of contaminated units per lot. If there is a consistent low failure rate per lot, then lot sampling may require relatively large amounts of tested units. You’ll have to determine the level of bad units permitted to pass through to production. Short of 100 percent sampling, it’s difficult (and expensive) to find very low percentages of “bad” units in a lot using destructive testing.

3) Work to remove original source(s) of contamination to permit you to stop inspections.

I stress this approach because it’s the most cost effective in nearly all cases. In my opinion, incoming inspection should be stopped as soon as possible since the process to create, ship and receive components should not introduce contamination and require incoming inspection to “sort” the good from the bad.

Fred Schenkelberg
Voting member of U.S. TAG to ISO/TC 56 on Reliability
Voting member of U.S. TAG to ISO/TC 69 on Applications of Statistical Methods
Reliability Engineering and Management Consultant
FMS Reliability
www.fmsreliability.com

For more on this topic, please visit ASQ’s website.

Can We Require ISO 9001 Certification?

Suppliers, supplier management

Q: My company has bought another company in Canada and we are outsourcing to them. They are not certified to ISO/ANSI/ASQ 9001:2008 Quality management systems–Requirements.  Do we have the legal right to require them to get certified since we are?

A: Thank you for contacting the ASQ Ask the Experts Program.  With regard to your question, there is no requirement in ISO 9001 that requires any organization or their suppliers to be certified by a third-party. Certification is only needed if it’s required by a customer contract/purchase order, or if an organization has opted to be ISO 9001 certified.

However, as an ISO 9001 certified organization, your quality management system must include controls to maintain control over outsourced processes. This requirement is stated in clause 4.1. The control over outsourced processes may include all or any of the following:

1.    Use of an approved suppliers list (see clause 7.4.1)

2.    An onsite supplier quality audit (see clause 7.4.3)

3.    Review and approval of equipment, processes, procedures, methods, and personnel qualifications for processes that require validation such as welding, nondestructive testing, heat treatment or others (see clause 7.5.2).

In summary, ISO 9001 certification is a management decision and not a requirement.  Organizations that follow the ISO 9001 requirements and have outsourced processes should have controls in place to manage those processes.

I hope this helps.

Bill Aston
ASQ Senior Member
Managing Director of Aston Technical Consulting Services
Kingwood, TX
www.astontechconsult.com

For more on this topic, please visit ASQ’s website.

“As Found” Calibration Data – Available for a Fee?

Automotive inspection, TS 16949, IATF 16949

Q: I have been an auditor of ISO/ANSI/ASQ 9001:2008 Quality management systems–Requirements since 1992 and recently began consulting hospitals who seek ISO 9001 certification.

My experience with auditing to ISO 9001 is mostly in the manufacturing sector. When I audited against ISO 9001 clause 7.6 control of monitoring and measuring equipment, I routinely included questions regarding the process for assessing the validity of previous measurement results when equipment did not conform to established limits. I found no real issues with this until lately.

Now, clients say that calibration service providers do not routinely provide “as found” data in the report that’s sent to clients/customers. I have been told that “as found” data only becomes available to the client/customer for an additional charge (and it’s not cheap).

Obviously, organizations cannot comply with the ISO 9001 requirement to perform the aforementioned assessment without this data. Since this has only come to my attention recently, I am wondering about the ethics and legality of withholding specific information in the calibration report – unless an additional fee is paid.

Could you please provide some insight or justification for this business practice?

A: It is always a good idea to evaluate one’s suppliers. This requirement is in ISO 9001 clause 7.4 purchasing. The May 2010 Quality Progress Measure for Measure column, “Supplier Demand,” provides guidance on evaluating and selecting calibration providers accredited to ISO/IEC 17025-2005: General requirements for the competence of testing and calibration laboratories. In addition, the ILAC-P14:12/2010 policy document requires ISO/IEC 17025 accredited laboratories to provide measurement uncertainty data with the measurement results as of December 1, 2011.

The customer should specify their requirements in their purchasing documents for calibration. ISO/IEC 17025 has contract review requirements that accredited laboratories must meet in order to to comply with clause 4.4 of ISO/IEC 17025.

In order for the laboratory to make an out of tolerance decision, it has to measure “as found” data. Even if the laboratory does not report it, it is required to retain it per ISO/IEC 17025 clause 5.10.4.2, second paragraph:

“When a statement of compliance with a specification is made omitting the measurement results and associated uncertainties, the laboratory shall record those results and maintain them for possible future reference.”

So, for a start, it is a good idea to use ISO/IEC 17025 accredited calibration providers and specify the customer’s requirements. Some provide “as found – as left” data routinely. Others may charge because they may claim that it takes extra time. But, if a competing laboratory provides it as part of the service, the other laboratories will follow suit or lose market share.

If the ISO/IEC 17025 accredited providers have to make a compliance decision on an item being calibrated, why would they not record the data? Even if it’s not provided, they are required to retain it for future reference in case of an inquiry. Calibration providers (whether accredited or not) that do not provide “as found – as left” data should probably be avoided. One does not know if they provided a legitimate calibration or they “stickered” the calibrated item and produced a generic certificate.

Other laboratories complying with ANSI Z540-1 or ANSI Z540.3 requirements are also required to provide “as found – as left” data. Otherwise, they are not fully complying with Z540 requirements.

The September 2010 Quality Progress Measure for Measure column, “Calibration Evaluation,” discusses evaluating non-accredited calibration providers and what to look for when assessing them.

Dilip A Shah
ASQ CQE, CQA, CCT
President, E = mc3 Solutions
Chair, ASQ Measurement Quality Division (2012-2013)
Secretary and Member of the A2LA Board of Directors (2006-2014)
Medina, Ohio
http://www.emc3solutions.com

For more on this topic, please visit ASQ’s website.

Remote Auditing

 

Audit, audit by exception

Q: I am a consultant and I have helped a dozen of companies receive certification to ISO 9001-2015: Quality management systems–Requirements. A recent client requested a specific registrar that is different than the one I have used before. That registrar states that per ANAB, the stage 1 audit must be conducted on site at the company being certified. My prior registrar claims that they do not know of this requirement. After a review of the documents and records sent to them, they conduct the stage 1 in a teleconference. Who is right?

A: No one can speak for ANAB and the requirements they have for certification bodies (CBs) for each standard except ANAB. For some standards, ANAB documents specifically state that stage 1 audits can be conducted on-site or remotely. However, in some cases, ANAB requires CBs to apply for accreditation to use Computer Assisted Auditing Techniques (CAAT).

I would recommend that a representative of the organization seeking certification formally ask for an explanation as to why remote auditing techniques cannot be used to conduct a stage 1 audit for conformity to ISO 9001:2015.

For more information about remote auditing techniques for internal and external audits you may want to consider reviewing material in the book eAuditing Fundamentals: Virtual Communication and Remote Auditing published by ASQ Quality Press.

J.P. Russell
ASQ Fellow, ASQ CQA
ASQ Quality Press Author
Member of the U.S. TAG to ISO/TC 176 on Quality Management and Quality Assurance
Quality WBT Center for Education/J.P. Russell and Associates
www.jp-russell.com

Related Content:

Find more about remote auditing on ASQ’s website.

Making Remote Work
Quality Progress

10 Auditing Rules
Quality Progress

FDA Regulation for Food and Beverage Labels

Inspection, FDA, Packaging, Requirements

Question
I have been asked to do a quality audit of a label manufacturer whose products are used on beverages and food packaging. They are currently asking to be audited using 21CFR211 (pharmaceuticals). Is there another standard that is more appropriate for their product?

Answer
21CFR211 is the FDA regulation for cGMP for finished pharmaceuticals. This regulation does not apply to the labeling of food and beverages. The proper FDA regulation is 21CFR101. I suggest that you first start on the FDA web page on food labeling and nutrition.

John G. Surak, PhD
Surak and Associates
Clemson, SC
A member of Stratecon International Consultants
www.stratecon-intl.com/jsurak.html

For more on this topic, please visit ASQ’s website.

Dock to Stock

Suppliers, supplier management

Q: I have been tasked with implementing a dock to stock policy. Does an expert have any advice or information to share towards forming a dock to stock policy?

A: To begin, here is a brief definition of dock to stock (DTS):

Dock to stock is a receiving method whereby materials are delivered directly to point of use (storage or manufacturing), skipping the normal receiving inspection.

For most organizations, parts which are given a DTS status are those which have been “proven” to be compliant. It is common practice to perform a receiving inspection on the parts for a minimum of five deliveries (some companies choose 10).

After a supplier has proven to deliver a compliant product five times, that individual item/part number is given DTS status. It is then general practice for production/assembly departments or line personnel to verify compliance as needed. If a product is found to be noncompliant, it is put on a contingency list and must prove its validity again — usually through five to 10 compliant shipments before it is returned to DTS status.

Keep in mind that the DTS process is rarely used in some industries/companies. For example, a company certified to ISO 13485 (medical devices) would not use DTS due to FDA regulations — here’s an excerpt from 21 CFR 820.80 (b):

“Receiving Acceptance Activities: Incoming product shall be inspected, tested or otherwise verified as conforming to specified requirements.”

In short, determining how many acceptable shipments to qualify a supplier for DTS status is up to the company. Requesting a certificate of compliance with each shipment can tend to encourage a supplier to ensure their own quality, as does a yearly audit of the supplier’s facilities (if appropriate).

I hope using the guidelines above will help lead you toward your goal.

Bud Salsbury
ASQ Senior Member, CQT, CQI

Related Content:

Chinese OEM Reduces Returns With Improved Product Testing, ASQ case study

Cost-Effectiveness Based Performance Evaluation for Suppliers and Operations, Quality Management Journal

Is it Legal to Require Certification to an ISO Standard?

Contract, requirement, legal, standard

Q: Can a contract include a requirement stating that the manufacturer of the materials to be installed as part of the job must be ISO 9001 and ISO 14000 listed? My question is in reference to a contract I received that is requiring this.

A: In general, contracts between business entities are enforceable unless they violate laws or are contrary to public policy. Private businesses entering into commercial contracts have a great deal of freedom in establishing contract terms.

One of the common uses of ISO standards is to clearly delineate requirements in commercial contracts.   This can, and often does, include requirements for third-party certification of suppliers to ISO 9001-2008: Quality management systems–Requirements and/or ISO 14001-2004: Environmental management systems – Requirements with guidance for use.

This requirement is usually met by providing a copy of the certificate issued by a third-party certification body (registrar) that lists the name of the organization certified and the scope of the certification.

Based on the information provided along with your question, it appears that the question actually relates to a material specification that was included as part of a request for proposal (RFP) from a governmental entity. Note: the contract has not been included with this post to protect the anonymity of the questioner and the governmental entity.

The authority of governmental contracting officers is more limited.  They must comply with applicable purchasing statutes and regulations.  Whether or not a requirement for certification to ISO 9001 and/or ISO 14001 is permissible would be determined by reviewing these contracting rules.  These rules also often provide mechanisms for contesting the award of a contract if it is believed to be unfair.

There are often opportunities to request clarification of information included in a government-issued RFP. This may be something to consider in this situation since the requirements in this RFP appear to be unclear, such as:

  •  There is no comprehensive “list” of certified companies so there is no mechanism for a manufacturer to be listed.
  • There is no ISO 14000 standard.  There are over 20 different standards in the ISO 14000 family – each with a different number.  I assume the RFP is referring to ISO 14001.
  • It is not clear which of the materials specified in the contract must be manufactured by an organization that is certified to the ISO 9001 and ISO 14001 standards.

(Note: the contract has not been included with this post to protect the anonymity of the questioner and the governmental entity).

I hope this helps.

Thea Dunmire, JD, CIH, CSP
Chair, ASC Z1-Audit Subcommittee
ENLAR Compliance Services, Inc.
Largo, FL
www.enlar.com

For more on this topic, please visit ASQ’s website.

Z1.4 Split Sampling

Chemistry, micro testing, chemical analysis, sampling

Q: I have two questions about Z1.4-2008: Sampling Procedures and Tables for Inspection by Attributes.

1. Does the plan allow one to “split” sampling plans among multiple items, or is only one item per plan intended?

2. The plan states a 95% confidence level, which means the findings of the sampling will statistically show that the findings (or number of defects) will be consistent with the findings of the entire inspected lot. So, if we split the sampling, how can you determine what happens to the confidence level?

A: Thank you for submitting your question to ASQ’s Ask the Experts Program. Answers to your inquiries follow.

1. In attempting to answer any given question, one needs to understand the question with respect to its gist and terms used.

Z1.4 uses the term “unit” to represent an individual “product” entity (unit here can represent a discrete fairly simple product, such as a bolt or nut), or it can represent a complex product (such as a computer, or a large piece of machinery, or even a square meter of cloth or other material, a length of wire or other material, etc.).

It is assumed here that the use of the term “item” in the question refers to a “unit.” It might, however, refer to a quality characteristic, and the explanation given here will attempt to explain either case.

Now, units can have a single principal quality characteristic or they can have many different quality characteristics.

Z1.4 allows for some of these quality characteristics to be of greater importance (severity for example, with respect to quality and/or economic effects) than others, whereby separate sampling is applied to each group with different sampling parameters (such as sample size, acceptance number, lot size). Hence, units with a single quality characteristic can be checked by sampling via Z1.4 and units with multiple quality characteristics can be checked by sampling via Z1.4.

In each case, the chosen Acceptable Quality Limit (AQL) and what it stands for applies to whatever is included in the inspection made on each unit. It is also assumed that this separate handling of units and quality characteristics is what the question means with respect to the term “split.”

Furthermore, it should also be understood that sampling inspection can be conducted with respect to two distinctly different statistics. One is the number of nonconforming units found in the sample. These are sometimes referred to as “defectives.” The second is the number (sum) of nonconformities found on all units in the sample, where any given single unit can have multiple nonconformities. These are often referred to as “defects.”

A “nonconforming unit” is defined as a unit with one or more nonconformities (defects) — but counted only as one “defective” unit. A “nonconformity” is any departure for any quality characteristic being considered in the inspection of each unit. In Z1.4, one can use either statistic as desired. The choice is largely dependent on the nature of product units and the reason for doing the sampling inspection — whether it is to control or oversee defective units or to control or oversee defects.

In the tables of Z1.4, note the top line above the range of AQLs: “Acceptance Quality Limits (AQLs), Percent Nonconforming Items and Nonconformities per 100 Items”. It should also be pointed out that Z1.4 is intended to be a sampling scheme or system, not just a selection of a given sampling plan. Please review the standard and any number of excellent books available on sampling inspection covering Z1.4, ISO 2859, and etc.

2. If one examines the Z1.4 standard from cover to cover, one will not encounter the term “confidence level.” Z1.4 contains no confidence intervals (or levels) related to any of its features.

Furthermore, the 95% figure is a very general figure associated with the expected “probability of acceptance” at the designated (selected) AQL. This is NOT a confidence level! In fact, the AQL is NOT a statistic!

Setting an AQL is generally an agreement/negotiation process between the customer and supplier. It is more of an index. Essentially, it refers to a level of nonconformity that is generally “acceptable” — a value of 0 being desired of course — but otherwise, a compromise figure.

And it is not by any means a constant, as can be seen by examining the Operating Characteristic (OC) Curves for the various code letters A through R using the same AQL in every table.

For example, for an AQL of 2.5% with the code letter C plan, incoming quality p must be 1.03% for Pa to be 95%, and Pa at 2.5% is less than 90%; for the code letter F plan, p must be 1.80% for Pa to be 95% and Pa at 2.5% is between 90% and 95%, etc.

If confidence intervals at chosen levels are desired for any given sampling plan, one most resort to the theory and methodologies of statistical inference with the available information provided by the sample statistics.

Kenneth Stephens
ASQ Fellow
ASQ Quality Press Author

For more on this topic, please visit ASQ’s website.

Terminology for Inspected Material (GMP, ISO 13485)

Pharmaceutical sampling

Q: There is often confusion with the labeling of purchased materials  after they have been “inspected, tested and/or verified” according to good manufacturing practice (GMP)
requirements.  Once out of quarantine, are purchased materials labeled as accepted, approved or released?  I’ve had auditors and inspectors tell me all three.

A: Either term (accepted, approved, or released) is appropriate and commonly used.  It would appear that the auditors are voicing an opinion and shouldn’t be. Neither ISO 13485:2003: Medical devices — Quality management systems — Requirements for
regulatory purposes or FDA’s quality system regulation (QSR) specify what language is to be used.

ISO 13485:2003, clause 7.5.3.3 status identification, states:

“The organization shall identify the product status with respect to monitoring and measurement requirements.  The identification of product status shall be maintained throughout production, storage, installation and servicing of the product to ensure that only product that has passed the required inspections and test … is dispatched, used or installed.”

FDA 21 CFR 820.86 acceptance status requires:

“Each manufacturer shall identify by suitable means the acceptance status of product, to indicate the conformance or nonconformance of product with acceptance criteria. The identification of acceptance status shall be maintained throughout manufacturing, packaging, labeling, installation, and serving of the product to ensure that only product which has passed the required acceptance activities is distributed, used, or installed.”

The requirement should be clear for purchased materials: identify so that only those materials that passed acceptance activities are allowed to be used.  Neither the standard or regulation states how the material is to be identified.  That is up to the manufacturer to define in its operating procedure(s).

My personal recommendation is to use the terms “accept/reject” at receiving and during in-process, then use the terms “release/hold” to mean the final product is or is not to be released for distribution.  But any similar terms are fine as long as they are consistently used throughout the quality system and personnel understand the requirement that they can only use product that passed their acceptance activities.

Jim Werner
Voting member to the U.S. TAG to ISO TC 176 Quality Management and Quality Assurance
Medical Device Quality Compliance (MDQC), LLC.
ASQ Senior Member
ASQ CQE, CQA, RABQSA Lead QMS Assessor

For more on this topic, please visit ASQ’s website.

ISO 9001 Electronic Records

Reviewing confidential files, training records, human resources files
Q: I have a few questions about employee training records.  My company is certified to ISO 9001:2008 Quality management systems–Requirements, and we are considering transitioning to electronic records. However, we don’t know what the requirements are from an ISO perspective. Specifically, we want to know:1. Do we need to retain hardcopy originals, or can we just keep the scanned electronic copies?

2. Does a record need to be in each individual’s file, or can there be a spreadsheet, cross reference-type matrix?

3. How long do they need to be retained?

4. Are there different requirements for environmental and safety type training records?

A: Thank you for contacting the ASQ Ask the Experts Program. Responses to your specific inquiries follow:

1.You may retain records in any format or media you desire.  You do not need both hardcopy and electronic.

2. You may use a spreadsheet matrix.

3. Retention times are your determination. Consult with the corporate attorney as to any requirements from the U.S. Equal Employment Opportunity Commission to protect yourself if there is a lawsuit (assuming your organization is located in the United States).

4. Check with the U.S. Occupational Safety and Health Administration (OSHA) and the U.S. Environmental Protection Agency (EPA) regarding requirements for these records.  These are outside the scope of ISO 9001.

George Hummel
Voting member of the U.S. TAG to ISO/TC 176 – Quality Management and Quality Assurance
Managing Partner
Global Certification-USA
www.globalcert-usa.com/
Dayton, OH

For more on this topic, please visit ASQ’s website.