Archive for July 27th, 2009

Auditing to ISO 9001:2008

Monday, July 27, 2009
posted by qicguru 8:00 AM

StudentThere are two types of auditing  required to become registered to the ISO 9001 standard: auditing by an external certification body (external audit) and audits by internal staff trained for this process (internal audits). The aim is a continual process of review and assessment, to verify that the system is working as it’s supposed to, find out where it can improve and to correct or prevent problems identified. It is considered healthier for the internal auditor to audit outside their usual management line, so as to bring a degree of independence to their judgments.

Under the 1994 standard, the auditing process could be adequately addressed by performing “compliance auditing”:

  • Tell me what you do (describe the business process)
  • Show me where it says that (reference the procedure manuals)
  • Prove that that is what happened (exhibit evidence in documented records)

How this led to preventive actions was not clear.

The 2000 standard uses the process approach. While auditors perform similar functions, they are expected to go beyond the mere iso audit for “compliance” by focusing on risk, status and importance. This means they are expected to make more judgments on what is effective, rather than merely adhering to what is formally prescribed. The difference from the previous standard can be explained thus:

Under the 1994 version, the question was broadly “Are you doing what the manual says you should be doing?”, whereas under the 2000 version, the question is more “Will this process help you achieve your stated objectives? Is it a good process or is there a way to do it better?”.

Videos, Slideshows and Podcasts by Cincopa Wordpress Plugin