Archive for the ‘ISO9001:2000 blog’ Category

Why having ISO9001:2008 is more important than ever

Thursday, February 18th, 2010

Some companies I’ve worked with view ISO9001:2008 as a necessary evil, and as just one more cost of doing business. These companies are typically short-sighted, and often short-lived.

When taken seriously, an ISO9001-2008 quality management system will not only save your company money, it will help you make more money. Aren’t these good things to hear in this depressed economy?

Consider these:

1. ISO9001:2008 can be thought of as a set of good business practices. Don’t you think it would be a good idea to check out your vendors before you buy from them? After all, what you buy usually is reflected by what you sell, and you want to sell only the best. And if a vendor screws up repeatedly, wouldn’t it be good to keep track of these screw ups, and weed out the bad vendors? ISO9001 will help you with this.

2. Having your ISO9001:2008 certificate sets you apart from your competition. Worldwide, knowledgeable buyers will tend to think that you have your act together, and that your quality is probably better than your non-ISO competitors.

3. Isn’t it a good idea to keep track of your company’s screw-ups, and fix them so that they never happen again? How many hours and dollars has your company spent dealing with the same problem over and over? Wouldn’t it be nice to deal with it just once? ISO9001 will help you with this.

4. Do you really know where you stand with your customers? Wouldn’t it be good to have a formal process to measure customer satisfaction? How can you know where to best focus your improvement efforts if you don’t have data on what areas need fixing?

5. Do you have complete and up-to-date training records for your people? With fewer people on your payroll, you really don’t want to take it for granted that someone has been adequately trained for a particular job. Isn’t it a good idea to periodically evaluate how effective their training has been?

There are so many reasons why having an ISO9001:2008 quality management system is an advantage in today’s economy. I’ve just touched the tip of the iceberg here. I’m sure readers of this blog (all 3 of ‘em!) can provide many more examples of why its so good for your company to have an effective ISO9001 quality system.

Why the very first ISO9001-2008 audit is the easiest you’ll ever have.

Friday, January 15th, 2010

This past week I participated in the very first accreditation audit for Company F to the ISO9001-2008 standard. We had a lot of things going for us. I was familiar with the auditor, we had worked together before. Conversely, the auditor was familiar with my consulting work which, hopefully, gave him a certain sense of confidence. Company F passed the audit with no serious issues. A couple of “opportunities for improvement” were written in the final report, but no nonconformances were written. The looks of relief and happiness were really something to experience. Of course I have been through many audits as a quality manager and as a consultant, so this is nothing new to me. Company F’s management, however, had never been through an ISO9001 audit before and were understandably nervous.

Although the initial preparation for the first audit can be quite time consuming and laborious, the first audit itself is probably the easiest one this company will ever have.

Company F’s ISO9001:2008 quality management system has been in place only for the past 4 months. There has not been much time to create lots of records, lots of evidence that they’re using the system. Auditors that I’ve worked with usually understand this about first-time auditees, and so are not so picky about having tons of records.

Also, since the quality management system has only been in place for a short time, there hasn’t really been much time to allow a good sample for measuring quality objectives. In the four months since Company F started their ISO9001:2008 quality management system, their quality objective measurements show they’re doing a fantastic job. So fantastic that they’ve exceeded all of the quality objectives they set at the start.

I advised Company F that these quality objectives would probably not be sufficient for very long, in fact I thought it would be a good idea to revise them before the registration audit. Management wanted to keep the quality objectives as they were, citing that the sample of data was pretty small, and they wanted to give their quality system more time to gather data before revising their quality objectives. I didn’t have a big problem with this, so the quality objectives remained as they were. The third-party auditor also had no problem with the objectives, for the same reason.

For these reasons, I think the first registration audit is probably the easiest. For future audits, Company F is going to have to demonstrate continual improvement. The quality objectives will be measured prior to management review meetings, and it’s very likely the quality objectives will have to be revised upwards as the company exceeds the goals set earlier.

Jitters about first ISO9001:2008 registration audit

Wednesday, December 30th, 2009

Though I’ve been through this many times, I’m a little nervous. In about 2 weeks I will be participating in the first ISO9001:2008 registration audit for a medium sized manufacturing company in Southern California. I’m the consultant, and we’ve worked for several months to get the documentation written and revised (many times!) and the people trained.

There’s always the possibility of a surprise. Even though we’ve conducted several internal audits of the entire quality system, audits can’t possibly find everything. I don’t have any serious doubts about passing the audit, but you just never know what kind of thing the auditor might find.

The company being audited was on a very aggressive schedule due to the owner’s wishes. I was, and am, a little uncomfortable with the rapid pace of everything. I like to see a company living with their completed quality system for at least 2 months before their registration audit. There are always unexpected things that pop up during those two months. Plus it gives everyone a chance to become familiar with any new procedures. Everything should be somewhat routine by the time of the registration audit, you certainly don’t want people forgetting stuff when the auditor is standing in front of them.

That being said, I’m 97% confident this company will pass their ISO9001:2008 registration audit on the first attempt.

Differences between ISO9001:2000 and ISO9001:2008

Friday, November 27th, 2009

I’ve covered this topic before, but so many people continue to ask about the differences in the revised standard that I feel compelled to write again.

As most reading this probably know, the ISO9001 quality system standard is revised periodically. There was a version in 1994, another in 2000, and the latest revision came late in 2008. Hence the updated standard is now called ISO9001:2008.

Here are some things to know about the latest revision.

There are no new requirements for 2008. Yay! The bad news is…..well, there isn’t any bad news! The 2008 revision includes additional text to clarify some sections of the standard.
The changes to the quality standard include the following:
Clause 0.2 – Process approach: Text added to emphasize the importance of processes being capable of achieving the desired outputs.
Clause 1.1 – Scope: Clarification that “product” also includes intermediate product. Explanation regarding statutory, regulatory and legal requirements.
Clause 4.1- General Requirements: Additional explanation about outsourcing. Types of control that may be applied to oursourced processes. Relationship to clause 7.4 – Purchasing. Clarification that outsourced processes are the responsibility of the organization and must be included in the quality management system.
Clause 4.2.1 – Documentation: Clarification on needed records. Explanation about combining required documents. Explanation about ISO9001 requirements being covered by more than one procedure.
Clause 4.2.3 – Document Control: Clarification regarding controlling external documents.
Clause 4.2.4 – Records Control: Editorial changes only.
Clause 5.5.2 – Management Representative: Clarification regarding Management Representative being a member of the organization’s own management.
Clause 6.2.1 – Human Resources: Clarification regarding competency requirements for personnel involved in the quality management system.
Clause 6.4 – Work Environment: Clarification regarding working conditions.
Clause 7.2.1- Customer Related Processes: Clarifies post-delivery activities, warranty provisions, contractual obligations, supplemental services.
Clause 7.3.1- Design and Development: Clarification regarding purposes of design and development review, verification and validation. Review, verification and validation may be conducted and recorded separately or in combination as appropriate to the organization.
Clause 7.3.3 – Design and Development Outputs: Clarifies information needed for production and service provision includes preservation of product.
Clause 7.5.3- Customer Property: Explanation regarding intellectual property and personal data.
Clause 7.6- now retitled Control of Monitoring and Measuring Equipment: Explanation regarding use of computer software.
Clause 8.2.1 – Customer Satisfaction: Notes added to explain monitoring of customer perception.
Clause 8.2.3 – Monitoring and Measurement of Processes: Notes added to clarify appropriate methods, and that the organization should consider the impact on conformity to product requirements and on the effectiveness of the quality management system.

One year after the publication of ISO9001:2008 all accredited certifications issued, whether they be new certifications or recertification, will be to the 2008 standard.

Your ISO9001:2000 certification will be valid for 24 months after publication of the ISO9001:2008 standard. After that, it will not be valid.

If you already have ISO9001:2000 certification, you should have no problem getting recertified to the new 2008 standard, as there are effectively no differences.

ISO9001:2008 clause 7.5.3 how do you identify your products?

Thursday, October 15th, 2009

In clause 7.5.3 of the ISO9001:2008 quality standard it states a requirement (where appropriate, of course) to identify your products by suitable means throughout your production process. I read this to mean that from the moment goods hit your door (or maybe sooner) those goods must be easily and accurately identified.

Recently I ran across a gentleman who believes that if the very experienced employees “just know” what an item is, sitting on an unmarked shelf, that’s good enough. This doesn’t seem like a great idea to me, and the ISO9001 standard doesn’t think so either. His system (no, he’s not ISO registered) is working for him now, as it has for the past 15 years. But it’s easy to find potential problems with a lack of product identification. People make mistakes. People forget things. People quit their jobs or are let go. People get ill or have accidents. Relying on an experienced employee to “just know” what your products are, without any sort of identification, will most certainly cause problems that could be easily avoided by using a simple method of identification.

I realize its not always easy to identify every component throughout every process. For example, you don’t want to attach an ID tag to a part that’s going through a paint process. The paint will cover up the tag, and the tag could mask a section of the part, ruining the paint job. In a case like this, how about having some kind of traveling document that stays “with” the part throughout the process? Maybe the tag, or traveler, could be on a hook labeled “rack 1″ while its associated part or parts are on paint rack 1. Or you could use a barcode and scanner system, with a bar code on the part or paperwork, and that barcode is scanned at the beginning of each process.

If the same part is always stored on the same shelf location, identification could be as simple as a piece of duct tape attached to the shelf face, with the part number written on it with a Sharpie. We’re talking about a 4 to 5 dollar investment in your identification process, it doesn’t have to be complicated or expensive. And even if this simple identification system saves just one mis-shipment down the road, isn’t it worth it?

There are undoubtedly many ways of identifying your parts. What method do you use?

How much can you tailor ISO9001:2008 to your company?

Tuesday, September 22nd, 2009

One of the beautiful features of the ISO9001:2008 quality standard is that it gives users a lot of leeway in how to structure your quality system. ISO9001 might say “you shall evaluate training effectiveness”, but it doesn’t tell you how you have to do it. You can try to figure out the best way that works for you.

While its true that an ISO9001 quality system can be and should be tailored to your operation, there is such a thing as carrying it too far.

I recently met a man who read a little bit about ISO9001 and is positive that he can configure his quality system any way he wants, using a very loose interpretation of the quality standard, and still pass an ISO9001 audit. For example, the need to identify product throughout the production process is pretty clear in the standard, but my new friend believes that because his experienced people “just know what those things are”, and have not had any problems, that he can ignore the standard on this issue. And other issues.

The ISO9001:2008 quality standard was created to help businesses standardize and improve their practices. Not every part of the ISO9001 standard will be helpful to every organization out there in the world. Some people might think certain provisions of the standard don’t apply to them because no added value to their organization is perceived. They’d like to pick and choose elements of the standard to suit their needs, add value to their organization, and not create needless busywork.

Of course that’s fine, and I totally understand that way of thinking. If you’re simply trying to create a quality system for your own improvement, then kudos to you for doing so. However if you’re also trying to achieve ISO9001:2008 certification, then I’m afraid you can’t pick and choose which elements of the standard you like. They all apply to you and everyone else who wants to be registered to the ISO9001 quality standard.

There are exceptions, of course. ISO9001:2008 allows you exclusions, as long as you can justify them. For example, if you make pot holders for clients based strictly on customer-supplied drawings, you can probably justify excluding ISO9001 clause 7.3 Design and Development. And if you’re a car wash service, you don’t really have a tangible product that needs to be identified, so you can probably exclude clause 7.5.3.

But if you design products, you can’t exclude 7.3. And if you have products and materials in your shop, you can’t exclude 7.5.3.

It will be interesting to see how far my new friend goes through the ISO9001 registration process, and what things he learns along the way.

Why I think Santa Claus uses ISO9001-2008

Friday, December 19th, 2008

So many people I talk to think ISO9001-2008 (formerly ISO9001-2000) is a rather serious, and let’s face it, rather boring topic. I can’t really argue with them, but what I can do is try to enlighten people about how an ISO9001 quality system can truly relate to real life, and can truly improve your business. It doesn’t have to be painful and boring.

I’m always looking for ways to relate ISO9001-2008 with real world situations, and as strange and dorky as this may sound, I try to live my life following some of the basic guidelines of ISO. Truth be told, I lived my life like this way before I ever heard of ISO9001, which is probably one of the reasons why I got into this line of work. Much of ISO9001-2008 is simply common sense and good business practices anyway, and life seems to go more successfully, with less drama, when you follow good practices. But that’s not the purpose of this post.

With Christmas coming up soon, it occurs to me that Santa must have a good quality system. Here are some reasons why:

1. The naughty and nice list should be a controlled document. This list is the deciding factor on what kids get gifts, and which ones get a lump of coal. And of course we’re talking about a list with billions of names. Chaos would surely ensue if this list were not carefully controlled. We don’t want unauthorized reindeer or elves making changes to the list. And Santa absolutely wants to be sure to use the most current copy of the list, as kids can change their behavior over time to try to switch to the “nice” list.

2. Santa’s quality policy? How about “to bring joy to the children of the world”. If you’ve got a better one, please let us know.

3. Santa’s quality objectives? 100 percent of the kids of the world (well, the ones who believe in Santa anyway) get a visit from Santa. 100 percent of Santa’s visits must be completed on Christmas morning. The reindeer department performance must be 100 percent, but only for one day of the year. In the toy-making department, the quantity of toys produced must match the number of names on the “nice” list, with zero deviation. Too few toys will result in lower customer satisfaction. Too many toys produced is inefficient and wasteful, detracting from the bottom line.

I can only guess that all of Santa’s toys are produced in house, with no outside services provided. But if the North Pole uses outside vendors to purchase products or services, I’m sure Santa would have an approved vendor list, and an effective method of ensuring that vendors provide sufficient quality goods in a timely manner. Again, we want to make sure customer satisfaction continually improves.

Information on ISO9001:2008 – its almost here!

Wednesday, September 10th, 2008

Yes, I know it’s going to be nearly 2009 before the 2008 ISO9001 revision comes out. No one ever said a bureaucracy moves quickly.

After a lot of rumors, speculation and innuendo, the new ISO9001:2008 revision is almost here. Here’s the good news: THE 2008 REVISION CONTAINS NO NEW REQUIREMENTS! That’s right…you won’t have to rewrite your manual.

You can’t get a new certificate that says “2008″ until the standard is actually issued, which will be late in 2008. However any registration or surveillance audits done after it’s issued can be done to the 2008 standard….which is essentially the same thing as the 2000 standard.

The 2008 revision contains clarifications of the existing standard, but no new requirements. Yay!

So you’ve got your new ISO9001:2000 certificate. Now what?

Friday, July 4th, 2008

For the umpteenth time I’m working with a company that has just recently passed their first ISO9001:2000 registration audit. Needless to say there was considerable excitement, and lots of high-fives around the office when we found out we passed the audit. After many months of work, a few arguments, some compromises, and a lot of hand-holding, it was finally time to celebrate.

The temptation is definitely there to abandon everything they were taught, and go back to the familiar old ways. Knowing there are 11 months before the next “real” audit, its easy for people to forget they have to keep the ISO thing going.

Obviously it is important to keep some of the momentum going. Employees and management were certainly all fired-up in the months leading up to the registration audit. If we don’t relax TOO much, its easier to keep at least a little of that pre-audit energy going into the rest of the year.

I will have to say the really tough part is over. Creating a brand new ISO9001:2000 quality management system from scratch takes a lot of time and effort. Once it’s done, (is it ever really done?) it’s relatively easy to maintain.

At this point in the quality system’s life, it is extremely important to maintain an effective system of internal auditing. People have to know that the ISO quality system is not going away. Frequent, small internal audits are my choice to keep people on their toes, and to make sure nothing slips too far.

How many Corrective Action Requests are enough in ISO9001:2000?

Monday, May 5th, 2008

If you’ve read many of my posts compared them to most other ISO9001 consultants, you will probably notice that I’m a little more cynical than others. Many ISO types like to extoll the virtues of the quality management system and how it will increase customer satisfaction, decrease failures, etc. I don’t disagree with those benefits of ISO9001:2000. But the stark reality for most companies is that they MUST get ISO9001 certified in order to keep doing business. They don’t want to, mind you, but they must.

Keeping that in mind, one of the added tasks of an ISO quality system is to write, deal with, and record corrective action. I call them CAR’s, for Corrective Action Requests. CAR’s are a requirement of ISO9001:2000, and while certainly a valuable tool, they can be a pain in the rear to deal with.

You’ve got to do them if you want to keep your ISO9001:2000 certificate. So how many should you do? If you’ve got full time quality nazis on staff, they could easily turn corrective actions into a full time gig. I don’t think anyone wants that. Too many corrective action requests wastes everyone’s time, and pisses people off. Most people just want to do their jobs, not fill out extra paperwork because some quality person has a nit to pick.

It all depends on the size and complexity of your organization, of course. And also keep in mind this is only my opinion. I’m sure other ISO9001 professionals will tell you differently, and that’s fine with me. But for a company of under 20 people, I’d say that 1 or 2 CAR’s per month is sufficient. For a company of 21 to 100 people I would recommend at least 2 or 3 CAR’s per month. Only for much larger companies, with dedicated quality staff, would I recommend more than 3 corrective action requests per month. After all, you want to actually get work done, don’t you?

Notes on ISO9001:2000 Management Review

Monday, April 21st, 2008

Your ISO9001:2000 quality management system requires you to perform a management review at planned intervals. In practical terms, the minimum is once per year. For a new quality management system I’d recommend you have management review meetings from 2 to 4 times per year. They don’t necessarily have to take all that long, unless you have some particularly long-winded people in your organization. After 3 or 4 years, once your quality management system has matured and people know their roles, you might think about reducing the frequency of management reviews to once or twice per year.

Its up to you to decide who attends your management review meeting. Members of top management should attend, along with relevant quality people and possibly department heads.

You must keep records of your management review meetings, including who attended.

You should have an agenda going into the meeting. Inputs to your meeting should include, at the mimimum:
-follow-up on previous management review meeting
-results of previous audits
-process performance and product conformity
-customer feedback
-status of preventive and corrective actions
-changes to your company that could affect the quality management system
-recommendations for improvement

One person, usually the quality manager or the management representative to the quality system, should prepare the agenda, notify everyone who should attend, and conduct the meeting.

Once you’ve gone thru all the items on your agenda, you’ll have generated some outputs. Management review outputs typically include:
-a record of the meeting
-corrective and/or preventive actions
-resource needs
-any other improvements to the effectiveness of the quality system, its processes, and/or your product or service.

Management review meetings may sound like some ominous burden, but in reality they may take as little as 30 minutes. It all depends on how prepared the people are, the complexity of your company, and the effectiveness of the person running the meeting.

ISO9001:2000: Is An Easy Auditor a Good Thing?

Saturday, April 5th, 2008

In the world of ISO9001:2000, I divide organizations into 2 camps. The first, and far more popular, are the companies that need to get certified due to customer pressure. They look at ISO9001 as a necessary evil, a royal pain in the ass, but they have to do it. The second camp, not quite so common, are the companies that want ISO9001 for the organizational and efficiency benefits that can be derived from following the standard.

Not long ago I consulted with a company that wanted to get their ISO9001:2000 certificatation for the usual reason- customer pressure. They were a pretty good group of people, but clearly they thought they had better things to do than follow some silly quality standard, keeping unnecessary records, having more boring meetings, conducting useless audits. Anyway, we got through the process without too much trouble, and scheduled a visit from our friendly auditor.

The auditor, Al, turned out to be a very nice man, obviously with many years of experience. Al had a lot of wisdom to share with us, and wasn’t afraid to chat endlessly on topics ranging from the Dodgers and home repair to travels in Europe and antique car restoration. Oh, yeah, there was some talk about the ISO9001 standard too.

Al didn’t seem all that interested in getting up out of his comfortable chair, and would ask someone to get certain files for him. This, of course, allowed the audited person to pick and choose which files he brought to the auditor. In fact, Al didn’t even check quite a few records that I sure would have if I were lead auditor.

This got me to thinking, is an easy auditor a good thing? Sure the company is happy that they got through the audit easily, and I’m happy that my consulting skills resulted in another ISO9001 :2000 certification. But has the easy auditor really done them any favors? Will this company be prepared in the future if a tougher auditor visits?

Now I had done my best to prepare my client company for a “real” ISO9001 audit. I thought they were in pretty good shape. During the audit, however, two of the employees unwittingly sabotaged my efforts by creating forms for their own department’s use, and not informing anyone outside the department. While I spotted this, our easy auditor didn’t seem to notice.

I’d like to think that, maybe, that it was immediately obvious to the auditor that I had done a great job preparing this company for ISO9001, and that actually checking records was not needed. Maybe the auditor, with his years of experience, quickly spotted a company that had its act together, so decided to take it easy for a few days. Maybe.

ISO9001:2000 Frequently Asked Questions – FAQ’s part 1

Monday, February 18th, 2008

What is ISO 9001?

ISO 9001 is a Quality Management System standard that helps organizations to get better organized, to produce and ship fewer discrepant products, and to help ensure they are meeting customer requirements. The ISO9001 standard was created to help the organization’s management is to implement systems to better run your business.

When I tell people about ISO9001:2000, many managers will say to me “Oh, that’s like a “best practices” kind of program”. Which is correct.

The ISO9001:2000 standard offers a more structured approach for various processes intended to help your business, such as:
Reviewing and meeting customer requirements;
Realization of your products and/or services;
How employees are hired and their competency determined;
Control of important company documents to make sure only current versions are used;
Periodic review of the quality system by company management;
Correction of unintended results, and prevention of their recurrence;
and other areas of business management.

The ISO9001:2000 standard is a 23 page document, and provides guidance in many areas of business. It does not deal with accounting issues such as A/P and A/R or payroll. The ISO9001:2000 standard can be purchased from ANSI (www.ANSI.org) the American National Standards Institute, or directly from the International Organization for Standardization in Switzerland (www.ISO.org) ISO9001:2000 can be applied to any business – no matter the industry or size.

What does ISO stand for?

The International Organization for Standardization is based in Geneva, Switzerland, and is comprised of standards organizations from 158 countries, including ANSI (the American National Standards Institute) in the United States. Because an acronym for their organization would be different in different languages, they used the word “ISO,” derived from the Greek word “isos” meaning “equal.” Standards of all types are intended to act as an equalizer for companies doing business around the world.

The ISO organization promulgates many different types of standards, from the popular business management system ISO9001:2000, to standards dealing with other issues such as food production, medical device inspection, and pollution emissions.

Why get ISO9001:2000 certification?

There are two primary benefits to implementing an ISO9001:2000 quality management system. The first is the organizational benefits derived from greater efficiencies, fewer discrepant products made, possible reduction of costs, and greater customer satisfaction. The second is that lovely little certificate that you can proudly show to potential customers in the hopes of convincing them you are a good company to do business with. In some industries, major players will not even consider purchasing from you unless you have your ISO9001:2000 certification.

The standard is based on best practices for organizations. It provides management with tools to objectively decide where things are working well and where to apply resources to make improvements. ISO9001:2000 helps to maximize the effectiveness of your business, enhancing growth through increased customer satisfaction, and reducing cost. It can give potential and existing customers confidence that you have an organization that can consistently meet their needs.

What will it cost?

It depends on the size and type of your business, and how much time you have to implement the standard. If you have some time and want to tackle it yourself (which is often feasible), the only real costs will be in the time dedicated to the implementation process by you and/or your staff, doing research, writing documents, and training personnel. If you don’t have much experience with quality systems, or if you don’t have a lot of time available, you might consider hiring some professional help, in the form of a consultant. Consultants range in cost from $300 to $600 per day, and the time needed will totally depend on the size and complexity of your company.

There is also the cost of the registrar, which is the company that will be performing independent audits of your quality system. Most registrars charge a certain rate per day to be on-site at your facility. These days registrars charge about $1,100 – $1,500 per day per auditor. Small companies of 2 to 15 people might expect one auditor on site for 2-3 days; larger companies may require several auditors for an extended site visit. Please note you CAN negotiate with registrars for their days and fees. ISO9001 registars are businesses just like you, and they want your business. They are often flexible in their quotes.

There will be an initial registration audit, and then surveillance audits. You might choose annual surveillance audits, or possibly semi-annual audits. Ask your registrar about your choices and how they’ll work best for you. Surveillance audit costs will be less than the original registration audit, as the time spent will be shorter. Once every three years the registrar’s auditors will return to audit your entire system.

More on this later.

To Calibrate or Not to Calibrate Devices in ISO9001:2000

Monday, February 4th, 2008

One recent consulting gig was done at a company that wanted to have the ISO9001:2000 certificate, but wasn’t too thrilled at the prospect of actually doing everything needed to actually implement an ISO9001 quality management system. Unfortunately there are far too many companies like this out in the world.

One major area of concern was calibrating the company’s measuring equipment. They have about 50 employees, and over 100 various gauges and test equipment that you’d think would need to be calibrated. You’d think so, but the company quality manager didn’t.

About 20 of the measuring devices were used in the inspection department, and the rest used by production people in the course of their job. The quality manager wanted to control and calibrate only the devices in the inspection department, and label the rest “for reference only”. The reason given for this is that only the inspection department devices are actually used to sign off the various processes. The production devices are only used for “monitoring”, and to get the piece “in the ballpark”. No nonconforming material could make it to the customer without a final inspection by the inspection department, so no problem there. The worst thing that could happen is that a small number of products might be made out of tolerance and would have to be reworked, or produced again.

This didn’t fly with me.

It seemed that they had way too many guages in the company, many of which were rarely or never used. The “for reference only” argument doesn’t make sense to me. I see it as a pretty much black-or-white issue. Either the measurement matters, and you calibrate the equipment, or the measurement does not matter, and you should not make it. Why complicate things if the measurement doesn’t matter? What value is added to your process by performing measurements with out-of-calibration instruments? Not much.

My advice- if there’s value added by performing a measurement, then do it right and calibrate your equipment. If you don’t think a particular measurement is important enough to warrant regular calibration of your device, then I’d say you ought to seriously consider deleting that measurement from your process.

ISO9001:2000 section 5.5 Responsibility, Authority, Communication

Sunday, January 6th, 2008

According to section 5.5 of the ISO9001:2000 standard, to be in compliance with the ISO standard you must ensure that responsibilities are well defined. documented, and communicated throughout your organization.

One task you must do is appoint a management representative to the quality system, which we’ve discussed recently in another post.

Today we’ll go into the “internal communication” part of the requirements.

Your company’s top management must ensure that there are established and documented methods of communication within your company, and that communication actually takes place regarding the effectiveness of your quality system. Of course, in order to prove to an auditor that communication actually takes place, you must have records. Sorry, it’s not enough for you to simply tell your auditor something like “yeah, sure, we talk about the effectiveness of the quality system all the time!”.

As with most things relating to ISO9001:2000, the standard tells you what you must do, but leaves it up to you how you should accomplish the task. As long as your methods are effective for your particular situation, and they pass the scrutiny of an ISO auditor, you’re good to go.

One highly effective method of internal communication regarding the effectiveness of the quality system is the management review meeting. Periodic management review is another requirement of ISO9001:2000, so in a way you’re killing two birds with one stone by conducting management review meetings. Of course you’re recording your management review meetings, their input and output, etc, so this is one way to prove to your auditor that you have a method of communication and you’re actually communicating. The minimum frequency for management review meetings is once per year, but I highly recommend having them more frequently while your new quality management system matures. If you’re actively using your new quality management system, you’ll likely have to make quite a few changes in the first couple of years.

The management review process should not be the only method of internal communication used regarding the effectiveness of the quality management system. You can use things like memos, signs, other scheduled and non-scheduled meetings, training programs, and whatever other kinds of communication you can think of. Just be sure your methods of communication are well documented in your quality manual and/or procedures, and that there are records of these communications taking place.

Do you post ISO9001:2000 related signs around your office?

Monday, December 24th, 2007

What do you think of the practice of posting your company’s quality policy on signs posted around your office and/or plant? Do you do it? Do you think it helps your employees remember the quality policy? Would it help during an audit? Do your employees really care?

If your quality policy is brief and to the point, you might want to consider posting signs stating your quality policy around your office and plant. While no one would suggest that posting signs will cause your employees to suddenly start caring about a vague quality system that they’ve heard about, signs certainly don’t hurt your cause.

If you decide to post your actual quality policy as controlled in your ISO9001:2000 quality management system, you must make sure that any changes in your quality policy are immediately reflected on your signs. It’s probably not the best idea to frequently change your quality policy, but having signs up gives you a bit more work to do, if you decide to change your quality policy.

I’ve heard it suggested to post small signs at everyone’s desk, or put your quality policy on everyone’s computer as a screen saver. Frequent, small reminders of your company’s quality policy are a good thing, but don’t push it too far. Being too pushy with your preaching can turn people against you, and you don’t want that.

One company I’ve worked with has a fairly convoluted quality policy. It’s not easily remembered by English speaking personnel, and completely unintelligible to the Spanish speaking folks who constitute a large percentage of the workforce here in lovely Southern California. In this case I would not recommend posting signs stating the quality policy word for word. Instead I would post signs reminding everyone that the company strives to increase customer satisfaction, and we want to continually improve our quality.

During an ISO9001:2000 audit, I don’t expect company employees to repeat their company’s quality policy verbatim. If they can tell me the essence of their quality policy, in their own words, that’s good enough for me. And if the employee can give me a personal example of what the quality system means to them, or how it affects the way they do their job, so much the better.

Who is the best management representative to your ISO9001:2000 quality system?

Tuesday, December 11th, 2007

During the planning stages of your ISO9001:2000 quality management syste, one of the fairly crucial decisions to make is choosing the management representative to the quality system.

OK, I’ll back up a bit.

Section 5.5 of our favorite quality standard covers “responsibility, authority and communication”. Your company’s management “shall” define and document who is responsible for the quality system, and “shall” properly communicate this throughout your organization.

You must choose who is going to be the “management representative” to the quality system. That is, who’s gonna be in charge of your quality system. So, who’s it gonna be?

A recent client, with no quality system experience whatsoever, had a bit of a struggle trying to figure out who should be in charge of the quality system. With only a dozen people in his company, and no one really in charge of quality, it wasn’t an easy decision.

If you have the type of company where quality is a serious issue, such as an aircraft parts company, medical devices, food products, that type of thing, well your choice is probably obvious. You probably already have someone in charge of quality, and this person is most likely the best person for the job.

If, say, you’re running a florist shop without a dedicated quality engineer, then your choice may not be so easy.

If your choice isn’t obvious, then your management representative to the quality system should be someone in your company who is smart, detail oriented, and not afraid to make a few waves. The company owner is probably not the best choice, although sometimes it might be the the only choice.

Your top management should appoint someone who has management authority, and can get things done. The management representative must have the ability and authority to establish, implement and maintain the quality sytem.

The management representative has the responsibility of reporting to top management on how the quality system is performing, recommending improvements, and promoting awareness of customer requirements to all members of your organization.

Being the management representative to the quality system is not necessarily a full time job. It may take only a few hours a month, depending on your particular situation.

How to satisfy section 8.4 Analysis of Data in ISO9001:2000

Monday, November 26th, 2007

Your ISO9001:2000 quality management system requires you to gather certain kinds of data, and periodically analyze this data to see how you’re doing. ISO9001:2000 is all about “continuous improvement”, after all. In order to show that you’re continually improving, you have to be able to measure certain objective parameters.

You must be able to show, through your data, that your quality management system is effective, and you also must be able to evaluate where improvements can be made. Data used for these purposes can be gathered from within your organization, and also from external sources. Every company is, of course, different, and the data you gather will be unique to your situation.

ISO does give some specific guidelines about what kind of data you must gather.

First of all, you have to gather information that allows you to objectively measure customer satisfaction. How you do this is up to you. Some people use customer surveys. You might have your outside salespeople fill out a report every time they visit a customer. You can have your inside sales or customer service people keep a log of customer comments, both good and bad. Keep in mind that you have to come up with some kind of objective measurement, so however you do it, it’ll be easier to deal with if you can turn your data into numbers.

You have to gather data that shows conformity to product requirements. This might take the form of inspection records, testing reports, rejection reports, etc. Nonconforming material reports might be used to keep track of how many rejections occur. Maybe you will compare the number of rejections versus the number of parts that pass, and come up with a percentage. Maybe one of your quality objectives is to have 99.9 percent of products pass inspection, and you currently have 99.2 percent. Now you have a concrete objective to work towards. Hopefully you can come up with ways to improve your product and/or processes so that over the next year you’ll reach 99.3 percent of products that pass inspection. It’s not much, but its improvement, and this is what your ISO auditor will be looking for. Quality objectives should be, in my opinion, slightly out of reach. You always want to be able to show improvement, but the moment you actually hit your goals, well now you’ve got to set your goals higher!

ISO9001:2000 requires you to gather data that show characteristics and trends of your processes and products, including opportunities for preventive action. This requirement has always seemed a little vague to me, and I’ve never heard a great way to accomplish this. Fortunately most auditors I’ve worked with apparently also think it’s vague, as I’ve never had to deal with this during an audit. As long as you have documented a system that includes preventive action, and you keep track of trends in your processes, you should be fine.

The last bit of data that ISO requires you to monitor is your suppliers. You must maintain records on your suppliers, showing their performance. Again, how you do this is up to you. Keep records of each supplier, and go thru and approve them at least once per year to show that you monitor their performance. If possible, keep track of your suppliers’ delivery and quality performance.

In an ISO9001:2000 quality system, how do you write work instructions?

Monday, November 12th, 2007

Work instructions are an optional part of an ISO9001:2000 quality management system. No, you don’t need them, they’re not required. Yes, they are often a good idea, and there’s a really good chance that you should have them.

If your people have lots of processes that would benefit from having documented instructions, and these instructions affect the quality of your product or service, then voila! you need work instructions.

Work instructions are another tier of your quality system documentation. So what are the requirements for constructing your work instructions?

Actually, there are no requirements for how you construct your work instructions.

There are various items that you might want to include in your work instructions, and these are similar to what you’d write an ISO procedure. Some of the items you might include in work instructions are: 1) purpose, 2) scope, 3) responsibilities, 4) definitions, 5) work instruction steps, 6) safety & environmental information, 7) associated documents, 8) document revision history.

But don’t feel compelled to include all of the above in your work instructions. In its essence, a work instruction pertains to a signle activity within a larger process. Keep your work instructions concise, to the point. You want to describe the who and the what and in which sequence things happen. Its a good idea to first write down all the necessary steps in carrying out that activity and then break it up into individual tasks. You’ll probably find it easiest to format your work instructions in a manner similar to your ISO procedures.

Keep in mind, though, that you don’t need to write your work instructions so detailed that a moron could follow them. It is reasonable to assume that the people who use the instructions have a fair degree of intelligence and experience, and your work instructions are written for them. So don’t go nuts.

Also keep in mind that work instructions can take many forms. A picture on a wall, a flow chart, a cartoon, a video, a set of example parts glued to a piece of wood, these are all forms of work instructions.

Ultimately you have to ask yourself “Can the worker do the job correctly, based on the work instruction?” If you can’t honestly say “yes”, then try, try again.

How do you get people to cooperate with ISO9001:2000?

Monday, October 22nd, 2007

You’re a quality person, working for a company, doing your job. The company doesn’t really have any serious problems, but one day someone gets a bug in their ear that the company should have an ISO9001:2000 quality management system. Or, even worse, your company’s biggest and best customer has decided that you need to implement ISO. And you’re handed a due date. Yikes!

Whether you’re a quality professional working on ISO9001:2000 for the first time, or a quality consultant hired to get a company certified, you can’t do it alone. You will need help.

I recently started working with a customer who wants to get ISO9001:2000 mostly due to customers’ mandating it. The company isn’t perfect, they have a few organizational issues, but they don’t have any serious problems, and they produce high quality products with very few returns. They are recognized as the leader in their industry, and the people working there are mostly long term, dedicated employees. It’s obvious that top management has fostered an atmosphere of teamwork and cooperation.

The company has been trying to get ISO9001:2000 certification for a few years. Fortunately they have not had a customer deadline….yet. The main reason, in my opinion, why they haven’t been able to get registered is because they did not have the right person driving the quality program.

The last person charged with driving the ISO program was apparently an older curmudgeon who rubbed people the wrong way. Instead of listening to the people who already do a good job, he alienated people with his insistence that it was his way or the highway.

The employees already working at the company don’t really know much about ISO, and they don’t really care. They know the company needs it and wants it, but they are already very busy trying to do the best job they can at their position. For someone to come in and tell them they’re doing things the wrong way, and they have to change to satisfy ISO, well, this is not a great way to get people on your side.

While you certainly may need to implement some new records, maybe change around a few procedures, I am a huge proponent of avoiding large-scale changes at any organization just for ISO’s sake. Chances are that if a company is successful and well-established, they’re already doing a lot of very good things. Why mess with that?

ISO9001:2000 is somewhat malleable, and has some gray areas, as we all know. The ISO9001:2000 quality standard was intentionally written this way so it can apply to all sorts of different organizations.

I’ve run into many people who only know a little bit about ISO9001:2000, and they’re a little intimidated by it. They believe ISO will dictate exactly how their company must be run, and they’re afraid that with all the forms, procedures and records that they won’t be able to get any actual work done.

I think one sign of a successful ISO quality consultant, or a good quality professional of any kind just coming into a new company, is that he/she is a good listener. It’s amazing how much you can learn about a company just by listening to people. And by listening at first, you will probably find that people are much more receptive to what you have to offer later.

You will need help from others to implement a new ISO9001:2000 quality management system. No one can do it alone, unless its just a one person company.

The first two things I’d recommend to any person trying to implement ISO are:
1. Realize that you can tailor ISO to the company. If the company is already doing well, try to change company procedures as little as possible.
2. Listen to the people who work there. This will pay you huge dividends in the future.

We all joke about needing a whip to get people in line, but the reality is that you want people on your side in order to have an effective quality system. If you make a bunch of enemies at first, you’ll never be successful.

Management Responsibility in an ISO9001:2000 Quality Management System

Monday, October 1st, 2007

It’s clear that without solid management commitment, you will not have a successful ISO9001:2000 quality management system.

Some of the items that are required under section 5 of the ISO9001:2000 standard include:

Your top management must be able to provide evidence of its commitment to your quality system, and its continual improvement.

Top management must communicate to the organization that it is of the utmost importance that the company meet customer requirements, as well as any applicable government regulatory requirements.

Top management must establish a quality policy. This is usually a few sentences at the beginning of your quality manual. Think of it as a high level direction. If you were commanding an ocean liner, the equivalent would be to say “we’re going to New York”. The rest of your quality manual and procedures will give everyone detailed instructions on how you’re going to get there.

Top management must see that quality objectives are created, and that quality measurements are taken and recorded and compared against those objectives. One of the driving goals of ISO9001:2000 is “continual improvement”. You must be able to demonstrate continual improvement. This is done by establishing quality objectives (or goals) that are just slightly above where you are at now. A year from now, after a year’s worth of measurements, you should have evidence of improvement. If you don’t, you’re doing something wrong. Having your quality measurements (records) compared against where you were, and where you want to be, is a really good place to start figuring out how to improve your system.

Top management must conduct periodic management reviews. That is, management must review the quality system and make changes if necessary. And, of course, you have to be able to show evidence of your management reviews, so records are necessary.

Top management is also charged with the responsibility of ensuring that adequate resources are available to people within your organization. This means all resources, from adequate personnel (both quality and quantity of those personnel) an adequate environment to accomplish the work, the necessary tools, computers, paper clips…..everything needed to run the company, accomplish your goals, and continually improve.

Review of product requirements in an ISO9001:2000 Quality Management System

Tuesday, September 25th, 2007

The ISO9001:2000 quality standard says that you must review product requirements prior to your organization commiting to supply the product to your customer. Different companies handle this in wildly different ways, it all depends on what kind of company you are, and what your product is.

For some companies this is easy. You get a request for quote (RFQ) from your customer, which specifies their requirements. You prepare a bid or tender that states what you will supply. Your bid can simply reiterate your customer’s requirements, or you can state you own product specifications and how they might be different from your customer’s RFQ. Either way, you’ve got to let them know what you intend to supply.

Or it might be a lot more simple. If your organization sells consumer products such as, let’s say motorcycle brake levers, then life is a little easier. You make your product specifications known to your customers by way of advertising, catalogs, web sites, etc. Its a standard, well known product that is the same for every customer. The customer merely lets you know the part number they want to order.

Even in a case like the above mentioned brake lever company, you want to have procedures in place to make sure your sales people get the customer requirements right. Since many orders are placed verbally over the phone, you’ve got a couple of options to consider.

You could require all your customers to fax or email a copy of their PO to you. Of course, you would not be able to ship their order until they do so, as you’d need a confirming copy of their order on file. This is not practical for many companies.

Another thing you might consider is having your sales people follow a procedure to confirm the customer’s verbal order. You could require your people to repeat the complete order to the customer as confirmation. And as a record of this this confirmation you can have the salesperson sign the sales order. Maybe you could include some verbage on the sales order form that states “confirmed entire order with customer”, with the salesperson’s signature next to it. This way you are holding the salesperson responsible for making sure the order is correct. If problems arise due to alleged “communication errors”, you should be able to narrow down the problem to one person in your organization, and take appropriate corrective actions.

Control of Monitoring and Measuring Devices in an ISO9001:2000 Quality Management System

Tuesday, September 18th, 2007

In chapter 7 of the ISO9001:2000 quality standard there is a requirement that you control devices you use for monitoring or measuring your product. Like so many parts of the ISO quality standard, you have a fair amount of flexibility in how you accomplish this.

First of all you should determine if you actually have monitoring and measuring devices. You might not. If, for example, you are a distributor of automotive distributor caps, and all you do is receive and ship boxes of distributor caps, this section of ISO probably does not apply to you. It is perfectly fine to claim you are exempt from this section of the ISO9001:2000 standard, as long as it’s true. If all you’re doing is visually verifying part numbers, and counting quantities, then you should make a note in your ISO quality manual that this section does not apply to you. However, be warned that if an auditor finds a calipers or a micrometer in your facility, you could have some explaining to do. If you’re going to exclude the “control of monitoring and measuring devices” section of ISO, then it would be best to make sure such devices are not to be found on your premises.

You may also be able to exclude individual devices, but again you’d better have a really good reason for doing so. One company I worked with has a company owner who rarely participates in the business, leaving the company operation to his partner. This owner still comes into the office each day, but works on personal projects that have nothing to do with the company. He’s a gadget freak, too, and has lots of cool little tools laying around. Again, his personal tools have nothing to do with the company, but they are on the premises and would certainly arouse the curiosity of an auditor.

What we did in this case was specifically exclude the owner’s personal tools and devices. We also had to label the devices as “uncontrolled” and instruct everyone in the company not to use those devices. It was an unusual situation, but it worked out fine.

The ISO standard states that “where necessary” your measuring and monitoring equipment must be periodically checked and calibrated to verify accuracy of your measurements. ISO gives you the flexibility to decide for yourself what kind of calibration is necessary, and how often. On one end of the spectrum, a yardstick is a measuring device that most likely does not need periodic calibrating. On the other end, a micrometer should probably be calibrated at least annually.

Calibration of measuring devices should be done by qualified technicians, and records must be kept. If a measuring device is found to be out of calibration, you should take steps to ensure that products measured with that device are rechecked. In extreme cases you may wish to consider a recall of products that already shipped.

ISO wants you to calibrate your measuring devices against measurement standards traceable to national or international measurement standards. If, however, there are no such standards for what you’re measuring, you must have records of what basis you use for calibrating your devices.

You should be able to quickly identify the calibration status of all measuring devices in your organization. A label on each device is usually sufficient.

More on this later.

Does Your Company Take Its Quality Policy Seriously?

Tuesday, September 11th, 2007

ISO9001:2000 section 4.2 states the requirement to have a documented quality policy. Cynical people might look at the quality policy as a bunch of horse dung. And lord knows I’ve seen quite a few companies that don’t take any part of their quality system seriously. So its not surprising that some folks might not take their quality policy to heart.

Unfortunately, in many companies the quality policy is effectively meaningless. Empty words written just to be in compliance with the standard.

Part of the reason why you need a wll written quality policy is to make your employees understand that their job affects product quality, and therefore the success or failure of the company. Your people must be made aware that their individual contribution is vitally important to the company’s overall success.

If your quality policy is simply written to satisfy the requirements of ISO9001:2000, then it might be worthless. You should keep it simple and keep it relevant to your organization. Make it meaningful to the people in your organization.

Your quality policy can also be thought of as making a commitment to quality. If management doesn’t take it seriously, then employees won’t either. However if management demonstrates an actual willingness to improve product quality without throwing people under a bus, then maybe the employees will also get on board.

In many cases the quality policy is just a bunch of words that management agonizes over to get the wording just right. It gets printed in your quality manual, posted on some walls, and then it is promptly forgotten about. Until the next audit, that is.

Your people don’t need a bunch of fancy hogwash to know what good quality is. Everyone knows when your quality policy isn’t worth the paper its printed on. It is up to management to show everyone the way by their actions, not merely by their words.

Control of Nonconforming Product in an ISO9001:2000 Quality

Wednesday, September 5th, 2007

The ISO9001:2000 Quality Standard states, in essence:

1. Your organization must ensure that any material or product that does not conform to your specifications is properly identified and controlled so that it can not be used or shipped to a customer.

2. You must have a documented procedure for dealing with nonconforming products or materials.

You may deal with nonconforming product in one of the following ways:

1. Do whatever is necessary to eliminate the nonconformity. (Repair, rework, etc.)

2. Get documented approval from the appropriate person or organization (such as the company owner or your customer) to accept the product as-is. You’d better make sure you have accurate documentation if you do this. You don’t want your customer or your boss coming back to you later with a problem.

3. Do something to prevent the product or material from being used for its original purpose. Destroying the item is one example of this.

You must keep records of nonconformities, and how you dealt with them.

If you’ve done something to correct the nonconformity, you must re-verify that the item meets your requirements.

For example, let’s say you’re making aircraft windows that go through a polishing process, then are visually inspected to make sure there are no defects such as scratches or hazy spots. After polishing, one window is accidentally dropped and scratched. This defective (or nonconforming) window must immediately be segregated from good production, to prevent it from being shipped to the customer. At some point (perhaps immediately) the defective window will be examined to determine if it can be reworked or if it must be destroyed.

There must be an authorized person (or persons) who will inspect the defective window and decide if it can be reworked, or must be scrapped. If the decision is to rework it, once the unit has been repaired it must go through an inspection process to determine (and document) that the unit meets your requirements.

If the unit can not be repaired, it should be destroyed. Perhaps in this case it could be melted down to make a new unit.

No matter how you resolve the nonconformity, you must keep records of each nonconformity and how you resolved it. Records of product nonconformity should be periodically reviewed to determine if you have a chronic problem with your production process. ISO9001:2000, after all, is about “continuous improvement”. By keeping records of your nonconformities it is easier to spot negative trends, examine the root cause, and eliminate the cause of your problems. This, in turn, should result in fewer defective products, happier customers, increased sales, a happier boss, and a nice healthy pay raise during your next review!

We can dream, can’t we?

How to live with ISO9001:2000 when customer requirements are poorly defined?

Monday, August 27th, 2007

ISO9001:2000 section 7.2 states that your organization must determine product requirements specified by the customer, requirements not stated by the customer but necessary for the intended use of the product, any legal, statutory or regulatory requirements, and any other requirements as determined by your organization.

In a machine shop type of organization, frequently you get poorly defined product requirements from the customer. I’ve seen customers draw an item on a napkin…literally. Dimensions are crude. Customers often don’t know what kind of tolerances are able to be held during manufacture.

Asking your customer to fix their tolerances can be tricky business, as customers are often entreprenurial types and not engineers.

How can you take on new work, with poorly defined product requirements, and still meet the requirements of your ISO9001:2000 quality management system?

It is often a matter of educating the customer, and requires a bit of patience. ISO demands that you have product characteristics nailed down in advance, and when you think about it, this makes perfect sense. Even if it seems like a bit of an annoyance right now, taking a little time now could save you and your customer both time and money down the road.

If you’re in a position like this, it is imperative that you get your customer to agree to specifications before you start production. If your customer unwittingly specifies some outrageously small tolerances for a product that doesn’t really require them, tell the customer that he can save money by specifying larger tolerances as these will require less manufacturing time. This is, of course, assuming the part does not really require the tight tolerances. If you’re manufacturing spars for the F-22 Raptor, well, you probably need the tight tolerances, and you’re undoubtedly charging a lot. However if you’re making motorcycle exhaust hanger brackets, the tolerances don’t need to be quite so small.

Thinking of “buying” your ISO9001:2000 quality manual and procedures?

Tuesday, August 21st, 2007

Numerous websites are out there claiming you can fork over your hard earned cash….or credit card number….and receive a ready-to-roll, plug-and-play ISO9001:2000 quality management system. Nothing could be further from the truth.

With about 20 years of quality management experience, and 13 of those years working with ISO9000 and ISO9001, I’ve looked at a bunch of off-the-shelf products that seem to claim you can have your quality management system up and running in a day or 2. AAAARRRRGGGGHHHH!!! these products drive me crazy!!!!!!!!!!!!!!!!!!!!! Anyone who believes this bullcrap is either ignorant of ISO quality systems, or just plain stupid. Yes, I know I shouldn’t be so hard on those who don’t know any better…I’ll try to calm down…really…I will….OK, there..that’s better.

Let me state this clearly: There is no way that you can purchase your quality system documentation and implement it into your company without a lot of work on your part. There’s no free lunch. If it’s too good to be true, it probably is. You know the drill. Why do you think ISO quality system consultants get paid so much? BECAUSE THEY’RE WORTH IT! Well, usually.

If you go the consultant route, which most people do, you’ll likely spend $5000 to $10,000 on consultant’s fees. And this is before ever having an audit. Depending on the size of your company, you might have to spend much more than that.

Spending a few hundred bucks on quality system documents may seem like a bargain, but be aware that your work has only begun.

Now I’m not saying that you should not purchase quality system documentation from a website. In fact, if you’re intent on creating your own ISO9001:2000 quality management system, I’d go so far as to say you should purchase sample documents from somewhere, to give you a guide to follow. But don’t spend a lot of money. You can find sample quality system documentation online for less than $50.00. There’s no need to spend more than that.

You can save a tremendous amount of money by doing it yourself. However the process will take a lot longer. If you have a customer deadline to get certified within, say, 60 days, then you have no option other than to hire a consultant, or hire an ISO experienced employee dedicated to the project. If you have more time, tho, you can save a bundle and do it yourself.

I have no doubt that most ISO9001:2000 documents you buy online are well intentioned and will be of great value to you. But think of these documents as samples of what you’re going to write yourself. There’s no such thing as plugging your company name into a few places and letting it rip. Sorry.

No two organizations are exactly alike, therefore no two quality systems can be exactly alike. You’ll want to tailor your manual, procedures and forms to your company, not the other way around. Remember, you’ll be audited by an independent ISO auditor. Whatever your manual, procedures and forms state, you’ll have to be doing. And how on Earth is someone at a website going to know what procedures are appropriate for your company? They’re not.

By taking on ISO9001:2000, of course you’ll probably have to make a few changes in your organization, and probably have to implement some new procedures, keep some new records, etc. But ISO gives you tremendous flexibility in how you achieve those requirements. You need to decide yourself how you will go about meeting the requirements of ISO. No way can some document bought online be exactly right for your company.

If you want to create your own ISO9001:2000 quality management system, here’s what you need to do:.
1. Buy a couple of good books on the subject, and actually read them. Take your time until you understand what’s going on here. It’s slightly complicated, but it ain’t brain surgery.
2. Go ahead and buy some sample quality system documents online, but don’t spend more than 50 bucks.
3. Use your newfound knowledge to write your own manual, procedures, forms, and work instructions. Use the manual you’ve bought as a kind of template, but realize you’re going to write your own manual. Use the purchased document as a guide for formatting, wording, etc. But don’t use it word for word.

Using a purchased set of documents without extensive modification is asking for trouble. It is extremely unlikely the purchased documents will have any correlation to what your company is actually doing. It will be very difficult for you and your employees to follow along. This will lead to people forgetting to follow those purchased procedures, which will further ensure the quick demise of your quality management system.

By using a purchased set of documents word-for-word, you’re ensuring a disastrous audit for yourself. Your auditor, who’s been around the block a few times, will quickly discover that you are claiming to conform to a set of documents written by someone who has never set foot in your building. Believe me, it will be painfully obvious to the auditor.

Good luck!

More on Document Control for an ISO9001:2000 Quality Management System

Tuesday, August 21st, 2007

Documents required by your ISO9001:2000 quality management system must be controlled. This is a requirement of ISO9001. See Section 4 of the quality standard. No ifs, ands or buts about it. But like most elements of ISO9001:2000, you have tremendous leeway in how you accomplish it.

By quality system documents, I mean your quality manual, quality procedures, and any work orders and forms you may have that are part of your quality system.

As you can tell from my previous posts, I’m a big fan of electronic document control where possible. With computers so reliable and prevalent, most companies should be able to control their documents electronically. This will save you lots of paper and avoid some headaches too.

Some old-school companies are still around, not fully computerized. Paper hard-copy quality documents might be the only option for such companies.

There must be a method of approving documents prior to issue. And, of course, you have to be able to prove that your documents were approved by the appropriate person in your organization.

There must be a method of updating your documents and re-approving them. Yes, you have to have a way to prove they were re-approved.

You must have a way to ensure that any document changes are identified, and a way to know the current revision status.

Your controlled, updated, current quality documents must be available to people who need them. You must have a way to ensure that obsolete documents are not used. If you have some reason to retain obsolete documents, they must be identified as such to prevent accidental use.

Your quality system documents must be legible, and easily identifiable.

Any documents from external origin (drawings from a customer, for example) must be identified and their distribution controlled.

An electronic document control system has several advantages. You can easily protect an electronic document with a password known only to authorized personnel. As long as the password is secure, it would be quite difficult for an unauthorized person to change a document.
And as long as you can prove you have a secure password system, you can prove that only authorized people have made any changes. And if changes were made only by an authorized person, you’ve also accomplished “approval for adequacy” at the same time.

In an electronic system there are no controlled paper copies of documents. I recommend you state “uncontrolled if printed” on every document, informing any reader that if they’re looking at a paper copy, it may not be the current revision. Every user has immediate access to the latest revision within seconds of the revision being made. No having to wait for copies to be made and distributed. No more going through reams of copy paper every time a small revision is made. No more trying to track down a binder that’s supposed to be in a particular place in your factory, but always gets lost. No more trying to read documents through coffee and jelly-doughnut stains.

You must also have a written procedure for occasional review of your documentation. I suggest you include this during your periodic management review. On your management review agenda (one of your controlled forms) include on your checklist “review quality system documentation and re-approve for adequacy, or identify changes that must be made”. Something to that effect.

Should you buy an ISO9001:2000 quality manual on the internet?

Monday, August 13th, 2007

If you’ve looked into an ISO9001:2000 quality management system, you’ve probably found dozens of online companies offering to sell you your ISO documentation. What do you think about that? Ever wonder what you get for your money? Would “bought” documents work for you?

I’m going to answer this with a definite “it depends”. I strongly do not believe that you can purchase your quality manual, procedures and forms and implement your quality system quite so easily. It may sound nice, but only to people who are not terribly familiar with the ISO registration process.

However some so called “do-it-yourself” ISO quality systems might be worth looking into.

Here’s the deal: Don’t spend a lot of money on do-it-yourself documentation. You can find perfectly good documentation for less than 50 bucks online. This is far, far cheaper than even one hour of a consultant’s time, and might be worth your time. Keep in mind, tho, that just like a free lunch, there is no such thing as a turn-key ISO quality management system.

You can purchase ISO documentation online for several hundred dollars, and the sellers may lead you to believe that all you have to do is plug in your company name and you’re good to go. This is highly unlikely. No matter how much you spend on documentation, in order to get a quality system that works for your company, you’re going to have to do a lot of modifications yourself. No two companies are exactly alike, therefore no two ISO quality systems will be exactly alike.

If you’ve decided you want to have a go at creating your own ISO quality management system, I applaud your decision. For a small to medium sized company, you can definitely do it yourself. Keep in mind this is going to take some time, and quite a bit of effort. And buying some sample ISO documentation for under $50.00 might be a good investment. I wouldn’t spend any more than that, though.

Go ahead and buy the 50.00 documentation, and also buy one or 2 books on the subject of ISO9001:2000 quality systems. With a little reading and writing, and some sample documentation to give you some guidance, you can definitely do this.

But please don’t spend hundreds of dollars “buying” your quality manual. You can get the same information for less than $50.00, and you’ll save enough to buy some books. I also recommend you purchase a copy of the actual ISO9001:2000 quality standard, either from www.iso.ch, or www.ansi.org.

What is Product Realization in an ISO9001:2000 quality system?

Tuesday, August 7th, 2007

One of the somewhat nebulous and confusing terms in ISO is “product realization”. It took me a while to understand this concept, and I know I’m not alone. The reality is that it is an extremely simple concept.

Product Realization is simply realizing your product. OK, maybe that’s a little too simple.

Here is Webster’s definition:

realization: 1) the action of realizing; the state of being realized

realize: 1a) to bring into concrete existence: ACCOMPLISH – as in “they finally realized their goal”

Product realization means making your product – the activities and processes necessary for you to bring your product into existence.

OK, so let’s say you are a Home Inspector who wants to get ISO certification…hey, it could happen. Your “product” is not a tangible object, it is a service. That’s OK, in the eyes of ISO9001:2000 a service can be considered as your “product”. Whatever processes you use to accomplish your final product or service is your process of product realization.

Chances are your product realization process is actually a series of several processes. I’ve never seen one business that has only one process needed to achieve product realization.

Product realization is simply doing whatever it takes to get your product (or service) to your customer.

Root analysis for someone who makes repeated mistakes

Wednesday, August 1st, 2007

One question that I’ve struggled with over the years…and still struggle with…is how to properly address the problem of an employee who makes the same mistake over and over. Sure, in the magical fairy tale land of ISO9001:2000, it’s easy to blame it on “insufficient training” and be done with it. But there are times when you can “train” someone until you’re blue in the face and it doesn’t make any difference. The person may appear to be competent and seems to understand your words. And for a day or two after training everything is OK. But then the same problem pops up.

Cultural differences between management and employees complicates the situation. I, being your typical college-educated white male, have a hard time understanding the motivation…or lack of it…among members of the Hispanic community that pervade workplaces here in Southern California. You can repeatedly ask an employee to do something, or not do something, and the employee will repeatedly tell you “OK, I understand”. Then the next day the same problem occurs. I just want to tear my hair out sometimes, but that obviously is not the solution.

I do believe that disciplinary measures are an effective last resort to resolving chronic misbehavior. This is assuming that top company management goes along with your assessment. If not, well then you may be screwed in your attempt to address a Corrective Action Request.

If there is an employee who appears competent, but continually repeats the same mistake, you might want to look at other factors.

There might be a medical condition, which you can’t really ask about, and most people won’t readily tell you about even if you do ask. Does the employee have dyslexia or another learning disability? This is a tough area to deal with, due to the aforementioned privacy issues. But if you suspect there may be medical factors to blame, you’ll either have to deal with it or move the employee to another area, if that’s an option.

There might be some other factor other than general employee disinterest. Does the mistake always happen at the same time? On the same day? Are there any other events that occur at that time? Does the mistake happen at the same time the cute UPS delivery lady arrives? You might look at a bigger picture of events surrounding the mistake to see if other factors are at work here, and take appropriate action.

Later we will discuss other possible ways to address repeat mistake makers.

When is the next revision to the ISO 9001 quality standard?

Wednesday, August 1st, 2007

According to reliable sources, it looks like ISO9001:2009 will be the next revision. The ISO Quality Standard has been undergoing much debate over how much to change it, and what kind of changes to make. There was a lot of speculation that 2008 would be the year, but it has been delayed until, most likely, 2009.

ISO9001:2000 Registration

Thursday, July 26th, 2007

Here are some useful tips on what you and your organization should do, and NOT do, during your ISO9001:2000 registration audit:

1. Make sure everyone has been trained and knows as much as possible about what their areas of responsibility.

2. Don’t lie.

3. If you don’t know the answer to a question, tell the auditor you don’t know the answer, and offer to go find it.

4. If the auditor asks “what did your management tell you not to tell me?”, employees should say NOTHING! Of course, management should never tell employees things that they shouldn’t tell an auditor in the first place.

5. Answer the auditor’s questions directly and succinctly. Do not offer anecdotes or stories.

6. Don’t read more into the question than is there.

7. Don’t tell the auditor about things that are wrong with the company.

8. Don’t divulge company secrets without prior permission from top management.

9. Relax, don’t worry. Most nonconformances will be minor and can be fixed.

10. No one should take any questions personally. The auditor is checking on company processes, not any individual’s performance.

11. Be polite, pleasant, and honest.

Do you really need ISO9001:2000?

Saturday, July 14th, 2007

OK, so you’ve heard a little bit about ISO9001:2000, or just ISO9000 as some people incorrectly call it. If you’re not in the aerospace or quality management industries, chances are you don’t know too much about it. But if you’re a small business owner, you might be wondering if an ISO9001:2000 quality management system would help you.

The answer is a definite “maybe”.

If you supply to companies like Boeing or Airbus, or the military, chances are you are required to have ISO or something similar like AS9100. But then you probably wouldn’t be reading this. You don’t really have too much choice if you want to continue doing business.

But what about all the companies out there that don’t have a customer requirement to be certified to a particular quality standard? Are there benefits to be derived from a documented quality management system? Are the hassles outweighed by the benefits?

Again….maybe.

If you are not required to have ISO, I would still encourage you to look into it. Unless you want the prestige and bragging rights of having a nice plaque on the wall, and if you have enough self-discipline to manage the quality system internally, you don’t really need to go thru the trouble and expense of dealing with an independent auditor. Depending on the size of your organization, having an audit can cost from $4000.00 or more. Not to mention a day or 3 of your time babysitting the auditor while he checks out your company. Some business owners figure that if they have gone to the trouble of creating and maintaining an ISO9001:2000 quality system, they want to be able to show this to the world. ISO can be a wonderful selling point for many companies, if your customers are aware of what it is. That is up to you to decide.

There are certainly internal benefits to having an ISO9001:2000 quality management system, other than being able to tell customers you have it. We’ll discuss this more later.

ISO9001:2000 minimum requirements for one person shop

Friday, July 13th, 2007

Let’s say you own a small shop that manufactures spare parts. It is a sole proprietorship with you as the sole full time employee. You want to streamline your manual and procedures as much as possible, to include only the bare essentials to conform to ISO9001:2000. You’re the only person there, you need to maximize time making your product, but still have a quality system that satisfies customer requirements. What are the minimum requirements and how best to achieve them?

There are six required procedures in ISO9001:2000. They are as follows:
1. Document control
2. Control of Records
3. Control of non-conforming material
4. Internal audit
5. Corrective Actions
6. Preventive Actions

Beyond these, any additional procedures are optional. Sometimes you can get away with satisfying a requirement in your manual, without writing a separate procedure for it. For example, while it is a requirement that you have a periodic management review, it is not a requirement that you have a separate procedure for management review. You can document your management review method in your manual.

You have to make sure you follow all the requirements of the ISO9001:2000 quality standard. I assume you have a copy of the standard, or a good book that tells you all the requirements. If not, I recommend a book by Charles Cianfrani titled “ISO9001:2000 Explained”. This book contains all the elements of the quality standard, with very good explanations. It’s easy to read and I have found it invaluable for new clients.

There are many ways to keep it as simple as possible. For one thing, your quality manual sections and procedures should probably be 2 to 3 pages maximum. Any more than that and I’d guess you’re doing too much work.

I would also recommend you combine Corrective Actions and Preventive Actions, since they are so similar. You can use one form for both procedures, with just a check box on the form to denote whether it is a “corrective” or “preventive” action request. You may find that you can streamline other forms in a similar manner.

Without knowing your particular operation it is difficult to give any more specific recommendations. If you have a question about a specific area of your business, please feel free to post it here.

Quality Manual Prep: How Long Does It Take?

Tuesday, July 10th, 2007

If you’re under the gun from a customer’s demand that you get ISO9001:2000 registered, and you have lots of personnel resources at your disposal, you might be able to get it done in a couple of months. If you’re trying to implement the quality standard while you’re learning it, and you have no time constraint, I’d expect it to take you up to 6 or 7 months.

If your operations are complicated it will take longer, if you run a rather simple business, it will be quicker, of course. There is no correct answer here, everyone takes as long as they have.

Tell us about your particular situation. How long do you think it should take?

4.1 General Requirements of an ISO9001:2000 Quality Management System

Monday, July 2nd, 2007

Continuing this blog, we know that some of the general requirements of an ISO9001:2000 quality management system include:

  • identifying and documenting the processes and procedeures used in your quality management system
  • determining and documenting the sequence of your processes, and how they interact with one another.
  • determining and documenting your criteria needed to show your processes are effective and what methods you use to accomplish this.

If you choose to outsource any process that affects your product’s (or service’s) quality,
then you must also take steps to make sure that outsourced process is under your control.

For example, let’s say you produce an NAS- standard aluminum washer to be used on a military aircraft. In your shop you’ve got the machines needed to stamp out bolts and put threads on them. But the military specification calls for a hard anodizing, and you don’t have capability to perform plating in your shop. No problem, just find an anodizing shop, right?

It’s not quite that simple. Who are your customers for that washer? What are their requirements? If you want to sell the washer to Boeing, you probably have to use a plating shop that is also approved by Boeing. In addition to customer requirements, you have to go thru the process (there’s that word again…) of finding and approving the plating shop you’ll use. Are they also ISO9001:2000 certified? How about AS9100? Have you inspected their facility? Can you be reasonably certain they are not farming the work out to another vendor that isn’t approved?

Once you’ve followed your process and approved the plating shop as your vendor, there’s more work to do to ensure your product meets YOUR requirements. The military specification calls for a total thickness of .085 inches, and your company specifications and drawings do the same. It is not ultimately your vendor’s responsibility to ensure your product is in conformance with your specifications. This is YOUR responsibility. Every shipment of washers should be inspected upon receipt from your vendor. I’m not saying that every washer should be inspected, but a reasonable sampling should be measured before any parts can be used or sold.

Remember that you want to make sure your product conforms to your specifications, and also your customer requirements. Many industries and products require documentation to prove that the various processes used are also in conformance and were done by approved sources.

Not only does the product have to conform to satisfy your customer, but you’ve also got to satisfy your ISO auditor. Have you taken reasonable steps to ensure your product is always in conformance? Is it possible that, even tho your products so far are in conformance, that maybe you’ve just been lucky? How likely is it that something could go wrong? Will your process stand up to the scrutiny of an outside auditor?

ISO9001:2000 Section 4.1 General Requirements Part 2

Tuesday, June 26th, 2007

This is the second part of an occasional series on ISO9001:2000 Section 4.1, General Requirements.

Keep in mind that when the ISO9001:2000 quality standard uses the word “shall”, then whatever they’re referring to is a requirement, not a suggestion.

We’ve already written about how your company must identify and document all the processes that affect your quality management system. In addition to identifying and documenting them, you must also document how they interrelate with each other, and in what sequence. You’re basically writing an operational manual for how your company works. After all, you want all your people to be “rowing the boat” in the same direction, so its very helpful if they’re all looking at the same map.

You must also determine the criteria and methods needed to make sure that the operation and control of your processes are effective. If you’re turning out small, large, and medium widgets, what is your criteria for determining if they are good widgets? What size constitutes small, medium and large? How do you ensure that your criteria are being met? Who’s responsible for determining what is acceptable and unacceptable?

Another requirement in ISO is that you have available sufficient resources and information needed to support the operation and monitoring of your processes. Do you have adequate machinery? A sufficient quantity of adequately trained personnel? A sufficient quantity and quality of measuring devices?

More on this later.

Your comments are encouraged.

ISO9001:2000 Section 4.1 General Requirements Part 1

Thursday, June 21st, 2007

This is part one of a primer on the general requirements of the ISO9001:2000 quality management system. You can find these in section 4.1 of the standard.

1. Your organization or company must identify the processes needed for your quality management system, and you must also decide how these processes will be applied in your company.

What processes do you use (or will you use) in your quality management system? Do you have a procedure for handling sales orders? Purchase orders? You’ll probably need a written procedure on how to choose vendors, and a system of recording which vendors are approved. You might have an inspection at time of receiving, another in-process, and yet another at final shipment.

You must identify ALL of the processes used in your quality management system. It’s likely that you’ll have to create one or two processes to meet the requirements of the ISO9001:2000 quality standard. You might have no existing system for approving vendors, for example. Under ISO, you’ll not only have to develop a procedure for approving vendors, but you’ll also have to keep records of which vendors are approved, which have been disapproved, and you’ll also have to keep records of your vendors’ performance. There are a lot of records needed in an ISO9001:2000 quality system, get used to it!

Can you have defined objectives that are not measurable?

Tuesday, June 19th, 2007

One company owner I worked with took a while to understand what ISO9001:2000 is all about. At one point he wanted to include quality objectives that were not measurable. They were subjective evaluations.

He asked me if every objective needed to be measurable. Couldn’t they just have as an objective something to the effect of “better quality”, or “more satisfied customers”? The short answer is “no”. I suspect that while he was excited about getting the nice certificate on the wall, he wasn’t too keen on actually following the requirements if ISO9001:2000.

ISO9001:2000 is all about continual improvement. In order to steer a ship you need to know where you are, and where you want to go. It’s the same with a quality management system. Without concrete numbers, its difficult to know where you are, and how you are progressing.

How would you implement an ISO9001:2000 quality system for your website?

Friday, June 15th, 2007

Let’s say you’ve got a website that is a forum with news and reviews on a particular topic, such as motorcycles. You intend to have advertising on your site, so it is a profit making venture. How would you implement an ISO9001:2000 quality management system for such a business?

Your “product” would be your website. Your customers are the good people who will hopefully send you checks to advertise on your site. Would the ISO requirement for Design and Development apply? Probably. You are, after all, continually designing and developing your website. I think it would be fairly easy to document a process of how your website is designed and written. Maybe there could be a process whereby any new content is reviewed and must be approved by the company owner, or some person other than the writer. You could have an electronic signature on the document to provide proof that the process was followed.

How would you measure customer satisfaction? Since you don’t have a physical product, you can’t count the number of returns. There are a myriad of other ways you can measure customer satisfaction here.

You could always ask your customer how you’re doing and document the results. Hopefully you would format your questions so they’re in the form of objective numbers, which would be easy to quantity and track. Over time, hopefully, your customer satisfaction numbers should increase.

You could also count the number of clicks from your readers to the advertisers’ websites. I guarantee your advertisers are keeping track of this, you should too.

In a weird way it’s kind of interesting to think about esoteric little businesses and how ISO9001:2000 may or may not work out. I’ve yet to find a business where ISO doesn’t apply.

Customer Related Processes

Thursday, June 14th, 2007

Your ISO9001:2000 quality management system (QMS) should be tailored to your organization. The Customer Related Process discussed here is one process that may be used by quite a few companies, but may not necessarily relate to your situation. You have to decide for yourself.

The Cycle Guys is a company that sells motorcycle parts. Orders are called in, or sent via a website. Occasionally a customer might call back to add something, change an item, or cancel their order. Obviously if the customer has waited too long, and the order has shipped, then there’s not too much Cycle Guys can do about it.

However there are times when the customer calls with changes before the order has shipped. The Cycle Guys must devise a way to control their order process so that the correct order is shipped to the customer. How to do this?

At The Cycle Guys, when a sales order is entered into their computer, a copy of the order is printed out for shipping.

The Cycle Guys quality procedure states that the salesperson taking the customer call must immediately walk out to the warehouse to find the physical copy of the order. If the order has already been picked, the salesperson must notify the shipping person that the order will be changed. Whether or not the order has already been picked, the salesperson must find the physical copy of the order and destroy it. Only after the physical sales order is destroyed is the salesperson to then enter the new sales order.

This system depends on the salesperson doing his job and following the procedure. There might be a better way to do this depending on software capabilities of the company, how many people work there, and a variety of other issues. But for a small, 4 person company such as The Cycle Guys, this procedure seems to be working fine.

Do you need a formal purchase order to satisfy ISO9001:2000?

Wednesday, May 23rd, 2007

A lot of people think they need a formal purchase order from their customers in order to satisfy the requirements of ISO9001:2000 section 7.2.2.

I do believe its a really good idea to have such a purchase order, but if you’ve had a long lasting relationship with your customers, and have done business for years verbally or by e-mail, there are ways to continue such business while still satisfying the requirements if ISO9001:2000.

Please realize that this, like most every part of ISO9001:2000, is subject to interpretation by your auditor. Most (but not all) auditors I’ve met are reasonable people, and chances are you’ll be able to make your system work to the satisfaction of your auditor, as long as you’ve made a good effort to satisfy ISO’s requirements.

For example, if you’ve always done business with a particular customer verbally, and your customer does not wish to start sending you formal PO’s, I have a couple of recommendations for you. First of all, your customer might be OK with sending you an e-mail PO. As long as the e-mail is identifiable as to who sends it, and contains the pertinent information such as part number, condition, quantity, price, etc, this should suffice. Be sure to write in your quality procedures that e-mail customer purchase orders are acceptable as long as they include the specific information you need.

Let’s say your customer orders only one thing from you, but orders regularly and includes only quantity and price, for example. To work around this, you might draw up a letter that your customer acknowledges with a signature. The letter, a one-time document, could spell out the customer’s requirements for quality, delivery, condition, description, etc. Having such a letter would go a long way toward satisfying an ISO audit when it comes time to look at 7.2.2.

If the customer only wishes to purchase verbally (yes, there are still a few of these people around) you could have your salespeople fill out a sales order form, with a checklist format. The form would include all the pertinent information, and maybe your procedure could state that the salesperson complete the form, read it back to the customer for their confirmation, check all the requirements on the form and sign it. Maybe you could even fax a copy to your customer for good measure.

There are usually ways to make any legitimate and reasonable style of business work with ISO9001:2000. If in doubt, ask your consultant or registrar, they’re usually very helpful in matters where you may be in doubt.

Incorporating your Employee Manual into your Quality Manual?

Saturday, May 12th, 2007

Is it necessary to incorporate your employee manual into your ISO9001:2000 quality manual? Would you want to do this? What are the pros and cons?

First of all, it is not a requirement of the ISO9001:2000 quality standard. Other than determining competency of employees, ISO9001 does not delve deeply into personnel issues.

I’ve heard a few (very few) people claim that the employee handbook should be a controlled document, and should be included in their quality system. And I suppose this point of view has some merit. You do want to make sure that only authorized personnel are able to make changes in your employee manual, to be sure. And you want to ensure that all your people have access to the latest version of your employee manual. In this regard, controlling this document as you would control quality documents makes sense.

If your company uses the employee manual as part of training related to your quality system (I hope you’re not really doing this) then yes, your employee manual should be included as a controlled document in your quality system. Hopefully you’re not doing this, and you’re keeping your training documentation separate from your employee manual.

Also, if you’re responsible for quality at your organization, you’ve got plenty of time on your hands, and you want to enlarge your personal little kingdom within the company to enhance your job security, you probably will want to incorporate your company’s employee manual into your quality documents. After all, the more complicated you can make things, the better for you.

However, if you are like most companies I know of, with never enough time to run the freakin’ business let alone deal with excessive documentation, then I believe you should not incorporate your employee manual into your quality manual. There’s no requirement for doing this, and very few practical reasons for doing it.

Measuring Top Management Committment to your ISO9001:2000 Quality Management System

Monday, April 30th, 2007

No, it is not a requirement of ISO9001:2000 to measure top management’s commitment to the quality system. It would be kind of interesting if such a measurement was required, tho. Maybe it would weed out those company’s who are really interested in having the nice plaque on the wall, but not so interested in actually improving quality.

This is a topic that quality people often discuss, and I do find it interesting. Although, really, there’s not a lot you can really do if your company’s owner isn’t interested in quality.

One measurement might be something like this: How often does your company owner/president look at sales figures versus how often he/she looks at quality performance? Does company management EVER look at quality performance outside of your annual Management Review meeting? Ever?? I’ve known several who never did. Actually, now that I think about it, I can’t think of one who ever actively wanted to know how the company’s quality performance was doing. All of them only begrudgingly participated in Management Review meetings, at my insistence.

Have you ever met a company owner/president who was actually interested in quality performance? Do you think there are many out there who are? I’d guess they’re in a very small minority. What do you think?

Controlling external documents in your ISO9001:2000 Quality Management System

Wednesday, April 25th, 2007

Do you use external documents? External documents are those generated and (usually) updated by organizations outside your company. Documents such as government standards, MIL-SPEC documents, Federal Aviation Regulations, drawings created by your customers or vendors, etc. are considered external documents. Chances are your organization is not responsible for, or allowed to, modify external documents.

If you don’t want to control external documents, you must specifically state in your quality manual, and on the documents themselves, that they are “For Reference Only” and are not updated.

External documents that you depend on, and are updated occasionally, must be controlled in your quality management system. Revision is usually controlled by the publisher. You are responsible to ensure that you have a means to receive updates from the publisher (such as a current subscription) and that you periodically check to make sure that you have the latest revisions.

As part of your document control, you must also devise a way to withdraw the obsolete documents and prevent their accidental use, and also issue the new updated documents to the necessary personnel in your organization. Whatever process you use to make sure you have the latest revisions, you must document this in your quality manual.

Vendor Evaluations

Tuesday, April 17th, 2007

A potential client once told me that a previous auditor recommended the client improve his vendor evaluation process. The client’s vendor evaluations only pertained to product vendors, not to services such as the building cleaning service, electrical contractor, and even the ISO auditor who provided the service.

I’ve also heard a few others in the ISO world proclaim that it would be a good thing to include service providers in the vendor evaluation process. However I don’t agree with this. Some ISO auditors and consultants seem to think that business people have all the time in the world to work on little details such as formal evaluation of service vendors. Personally I believe that section 7.4.1 applies to products and services that you use in goods or services that you sell to your customers, not necessarily vendors you use to maintian your building, or other vendors where YOU are the final customer.

While it sure would be nice to have the time and energy to perform a formal vendor evaluation on such vendors, I believe most business owners and employees would much rather spend their time trying to make their company profitable.

I would be interested to hear the justification from someone who feels otherwise.

Tim

Customer Focus

Friday, April 13th, 2007

If you’re considering writing an ISO9001:2000 quality manual for your organization, it’s good to include a section on “Customer Focus”. ISO is all about satisfying your customer. No matter what kind of organization you have, in one way or another there is some sort of “customer” that you want to satisfy.

A necessary part of your ISO quality system is to describe how you determine customer requirements.

It may or may not be readily apparent how you determine customer requirements. You might have a formal process, such as hiring a marketing research firm to survey potential customers as to what they are looking for. Automobile manufacturers do this all the time. Or, you might have a less formal process. If you’re a small company developing motorcycle products, you might not have the budget for formal market research. Maybe you talk to motorcycle enthusiasts at races and other gatherings.

Think about how it is that you decide what your customers want, which is, of course, the same as deciding what it is you’re going to supply. Write it down. You may not realize that you already do this process. Simply thinking about it and writing down will give you food for thought about how you might improve this process, increase customer satisfaction, which will lead to increase sales.

Is Design and Development a part of your QMS?

Wednesday, April 4th, 2007

Is it necessary for you to include Design and Development in your Quality Management System? Being a huge fan of keeping things as simple as possible, I would encourage you to closely look at your processes and see if you truly must include Design and Development in your quality system.

Look at your product. Do you truly design it, or do you produce items based on customer drawings and specifications? Or are you a sales organization or a distributor, with no manufacturing or design processes?

Don’t let an ISO consultant or anyone else tell you that you should include Design and Development in your QMS, just because they think you should. I’ve met a couple of people in the ISO world who just can’t believe than anyone would want to exclude Design and Development from their quality management system. These people strangely believe that just about any company has some design processes, and therefore should include this in their manual and procedures. Don’t let them bully you into this.

Competence, Awareness and Training

Wednesday, March 28th, 2007

As part of your quality management system, your organization should identify training needs, provide training, and periodically evaluate the effectiveness of that training. Employees should be made aware of the relevance and importance of their activities and how they contribute to the overall achievement of quality objectives and company goals.

One or two people in your organization should be made responsible for ensuring that personnel are adequately trained and are competent in their role.

Training needs may be identified at any time, from initial hiring to a changing role, or perhaps due to a corrective/preventive action request.