ISO 9001:2015 Risks and Opportunities

I actually found it quite difficult to form a clear opinion about this new requirement when all we had to go off was academic discussion and argument, now we have the benefit of a few concrete worked examples to play with, my thoughts are becoming clear and … it could work.

The New Definition of Risk

Redefining “risk” as the effect of uncertainty caused me both confusion and concern. Frankly I didn’t see the point in messing with a definition based on likelihood x severity – it actually works and is hard wired into so many business processes. But I’m now coming round to it …

The penny dropped when I was working with the API Q9 standard earlier in the year. This standard has risk treatment ingrained front to back, more or less, and requires that uncertainties (risks) are identified, assessed and covered with contingency as appropriate. That’s it. Deming said years ago that not all management information was known or even knowable and all the standard is asking is that companies take account for the unknown and unknowable in the form of planning contingencies. A company, let’s say, could be reliant on a single supplier – what happens if that supplier has problems or starts abusing its position? In this case a contingency of a back up supplier would be prudent. Do the distribution processes take account of transport infrastructure disruption or weather? Can the production facility cope with infrastructure failure or a loss of internet access?

Upside and Downside Risk

This thought process also helped me to get to grips with another concept I’d been struggling with – upside risk. I had no problem understanding that upside risk was a piece of good fortune, but I did struggle to understand how a management system could be expected to plan for it, but again here’s an example. Let’s say a company launches a new product. In basic terms things can go OK, or they can go less than OK, or they can go better than OK. Just as a management system is expected to apply appropriate contingency to account for undesirable events (downside risks), it naturally should also take reasonable account for better than desirable events, because that sometimes happens. In other words, if things go brilliantly well, how does the company cope? There’s your upside risk. I’ve actually had numerous clients that have found themselves victims of their own success when demand has outstripped their ability to supply. It isn’t uncommon.

And Opportunities?

The treatment of the requirement to manage “Opportunities” is a car crash waiting to happen, in my opinion. The reason I say this is because there is no normative reference for the term “Opportunity” in either Annex SL or ISO 9000:2015, so we are very much at the mercy of the linguistic interpretations of our auditor .. Oh dear.

How would I interpret it? Well, in my working life, the closest thing I’ve encountered to a systematic management of “Opportunities” has been an Investment Appraisal process. That’s a process by which, prior to any decisions being made at a high level, the management are presented with projections that usually outline best, worst and most probable case scenarios, along with projected costs, benefits, risks and obstacles. Management will then usually make a judgement based on that information, along with a few other considerations, such as whether the venture fits with current Policy or the Brand, whether the company has cash on hand to fund the project and so on. As an example, British Nuclear Group may spot an Opportunity to make a killing by opening a bakery on each of its major facilities. Financially that might make good sense, but is it something an organisation like that should be doing?

Often the result of discussion is the approval of a pilot or a controlled trial and error project, but it is a hugely complex decision making process, much more complex than weighing up cost versus benefit and seeing which is bigger.

Prediction?

What will happen as ISO 9001:2015 assessments begin in anger? My fear is that a lowest common denominator will be found. That is, what is the least a company need do to comply? If I were a betting man I would put a decent amount on that being a retitling of the the “Preventive Action” procedure to something like “Management of Risks” and a superficial and pointless SWOT analysis being pasted into the Management Review process. Let’s hope we’re better than that.

Shaun Sayers

You can find more ISO 9001:2015 articles here

And more articles on a range of risk management themes, techniques and approaches here

Find out more about Capable People, our work, and our fantastic clients at CapablePeople.net

IRCA Approved ISO 9001:2015 Transition Courses delivered worldwide.

Posted in 9001 Lead Auditor Study Group, ISO 14001, ISO 9000, ISO 9001:2015 | Tagged , , , , | 3 Comments

The Quality vs Price Dilemma

A LinkedIn contact of mine posted this quote yesterday.

“The bitterness of poor quality remains long after the sweetness of low price is forgotten”

I’m not normally a big fan of having LinkedIn cluttered up with quotes (especially the pseudo inspirational ones that actually make little sense when you analyse them), but this one strikes a chord. In the field of training there are cheaper providers, and it can be quite frustrating when customers try to evaluate your services on a like for like basis with cheaper providers – because it is rarely like for like. Cheap providers are usually cheap for a reason, and doing things both cheap and well are not always reconcilable. “You buy cheap, you buy twice” is something people often say to make a similar point.

But actually, when you analyse the above quote it is deadly accurate. If the job is a bad one, how often do you still find comfort that the price was a good one? Conversely, when the job is a good one, for how long does the higher price still sting?

Dealing with a price sensitive customer can be difficult. That is not to say that there is anything wrong with looking for a good deal, quite the opposite, but cheap prices often come with trade offs, and being prepared to accept those trade offs is important.

 

Posted in Quality Improvement | Tagged , , | Leave a comment

Audit Report Writing

The proof of the pudding is in the eating

An audit report is nothing more than a piece of management information. A piece of information for the benefit of management that will hopefully help them to make the right decisions in the future, mainly concerning about priorities for action and the allocation of resources.

As an auditor we want our reports to be useful. We want them to add value and we want them to be used. Whether or not the reports are used depends on two important things;

  1. Whether the audit was a good one or not
  2. Whether we have been able to express ourselves clearly in the written report

A good audit can be ruined by a badly constructed report, and many are, so we need to take care in the final stages of this process. Too many audit reports are rushed off in a bid by the auditor to get finished and move on to other things. You must make enough time available in your plan to do a decent job of it.

The psychology of positive reporting

There are ways that we can express ourselves that can make people receptive to our findings, even the negative aspects of it, and there are ways that we can express ourselves that will encourage defensive behaviour. Too many auditors think that the only important items for the report are the problems. Whilst these are important, and we should never chicken out of reporting problem areas, they will only ever, at best, be half the story. Management need to know about the strengths of the system. They need to know what is working, so they can hold the gains in those areas. It also helps with the allocation and reallocation of resources.

Based on the assumption that there will always be some positives to report, it is usually a good idea to highlight those early in the report and in the closing meeting. This is not a case of “softening up” management for the bad news, it just gives an early message that the report will be fair and credit will be given where credit is due. Once management have formed the opinion that the auditor will be fair with them, they will be more inclined to accept the findings that relate to problem areas

Care must be taken, however, when we are giving positive feedback that we don’t go too far. There are a few things to watch out for

  1. Don’t use subjective positive terminology such as “marvellous” or “excellent” – stick to objective terms such as “high level of conformance”
  2. Don’t over-sugar the pill. If the system is, on the whole, pretty poor, don’t feel obliged to give a 50/50 split to positive and negative findings as this will distort the true message relating to the overall health of the system
  3. Try to follow a similar discipline when reporting positives, as you would with non-conformances. All your findings should be supported by evidence and examples. Try to avoid vague and general positive statements as these have little use as pieces of management information

An audit report, ultimately, is just management information. They will ultimately do with it what they will. All the auditor can do is keep it relevant, keep it accurate and make sure it can be understood. After that it’s over to them …

Posted in 45001 Lead Auditor Study Group, 9001 Lead Auditor Study Group, Auditing | Tagged , , , | 1 Comment

The Benefits of Certification

 

Why become certified?

Companies seek certification for a range of reasons but primarily they will be motivated by one or more of the following external and externally facing motivational factors.

External motivators

The vast majority of certified companies seek certification because a major customer either requires it, or at least strongly favours suppliers that are certified. In other words it is a pre-selection criteria on more lucrative contracts. This applies most often in B2B supply chains. Companies supplying predominantly to domestic customers rarely come under such pressure to become certified by domestic customers. That said, the certification to ISO 9001 is usually used as more than a tick in the box in a tender scoring exercise, the certified company will usually seek to maximise the publicity value of certification and promote itself as a more “well-run company” on the strength of it. It is a differentiator in that respect.

Internal motivators

The application of an effective quality management system, certified or not, should generate value to the management of the company. The requirements of ISO 9001 promote best practice and offer an off-the-shelf structure around which to develop the approach. If implemented correctly it can deliver many, or even all, of the following benefits;

  • A standardised approach, meaning a reduction in the degree variation between the company’s good days and its bad days. Customers like to know what they are getting
  • Increased transparency – the monitoring and internal audit requirements promote the flow of information top down and bottom up. This delivers more accurate, timely and reliable management information, aiding a more informed decision making process on actions, targets, targeting of resources etc. This also reduces the opportunity for fraudulent behaviour. Managers can be more confident they have an accurate picture of what is going on (which most managers tend to like)
  • Removal of a “knowledge is power” culture – a documented, proceduralised management system reduces the opportunity for overtly political behaviour and selfish agendas by individual employees. The company is less vulnerable to the absence or resignation of key staff members as the knowledge does not leave with them
  • Staff involvement and ownership of work activities – the transparency created by the approach clarifies lines of communication, responsibilities, highlights gaps and identifies opportunities for improvement, leading to a more proactive improvement culture

Ultimately the implementation of a standardised, transparent approach can be considered to deliver benefits in three key areas;

  • Efficiency – by identifying gaps, duplication, bottlenecks and overlap
  • Effectiveness – by identifying things that are not quite working as they should
  • Risk management – by delivering accurate management information upon which more informed decisions can be made

When researching the benefits of certification, by the way, I’d recommend a hefty pinch of salt be applied to any list of benefits espoused by those with a financial interest in issuing certificates. Not all the benefits I’ve outlined above will be realised in every case, as there are a host of other variables to consider.

First steps

If a company chooses to follow an ISO 9001 agenda, what does it need to do? Well, first it needs to know to what extent its current arrangements meet (or otherwise) the requirements. This means that a gap analysis is required.

The gap analysis

A gap analysis is a top to bottom review of the current arrangements by a competent person. The gap analysis will identify the gaps. The gaps will generate the action plan.

The action plan and implementation

The action plan is the statement of how the company will address its current gaps, it will identify the sequence, timelines, responsibilities and, also, the costs. Typical actions will involve drafting procedures, staff training and awareness and establishing systems for monitoring and measuring. Obviously if the gap analysis identifies that there is a lot of work to do, then the implementation stage will probably take a while, unless the company is prepared to throw a large resource at the project.

To certify or not?

Once the gaps are addressed, the company will then have the option of seeking formal external certification. This carries an additional cost that the company will need to make a judgement on, taking into consideration whether it will secure any additional competitive advantage for the company either through positive publicity or in tendering processes.

You can find more ISO 9001:2015 articles here

Find out more about Capable People, our work, and our fantastic clients at CapablePeople.net

IRCA Approved ISO 9001:2015 Transition Courses delivered worldwide.

Posted in 45001 Lead Auditor Study Group, 9001 Lead Auditor Study Group, Auditing, Certification schemes, ISO 9000 | Tagged , , , | 4 Comments

ISO 9001:2015 Exclusions to Scope

 

Does ISO 9001:2015 FDIS permit exclusions in the same way as ISO 9001:2008?

The simple answer to that question is “yes”. Initially, before the FDIS was issued, I was concerned that the rumours of “no permissible exclusions” were going to be true – and many people are still maintaining that it is true, but I don’t think it is. They are, by the way, now known as “non-applicable” clauses, rather than exclusions.

In ISO 9001:2008, the statement relating to permissible exclusions is defined with clause 1.2 Application of Scope. It is quite clear. Exclusions are permitted, they are limited to clause 7, must be justified and can only apply where the requirement doesn’t affect the company’s ability to meet its output requirements (I’ve paraphrased). Therefore, when I received my copy of the FDIS of ISO 9001:2015 I went straight to section 1 (Scope) to see if there was an equivalent statement – there wasn’t. Quite the reverse in fact, instead there was the following statement

“All the requirements of this international standard are generic and are intended to be applicable to any organisation, regardless of its type or size, products or services”

Nothing about exclusions. So what about clause 8.3 Design and Development? This clause is pretty similar to clause 7.3 of ISO 9001:2008 – no major changes – what about a company that has no design function? A warehouse for example? Surely a company that has no design function wouldn’t be forced to develop contrived “design” procedures for the purpose of ticking a box? It was my understanding that ISO 9001:2015 was looking to move further away from that approach?

After a while my concerns were alleviated, however. Whilst the clarification regarding applicability (or exclusions) is not defined in Section 1 (Scope), it is defined somewhere else, and when you read it carefully it leaves us not too far away from where ISO 9001:2008 is on the matter. My assumption is that those people who maintain the position of “no exclusions in ISO 9001:2015 FDIS” have simply checked Section 1 (Scope) and nowhere else.

Context of the Organisation

The guidance relating to applicability of requirements ( and non-applicability, exclusions in other words) has moved. It is no longer mentioned in the Scope. It is outlined in Section 4.3 Determining the Scope of the Quality Management System. In that section we receive the following advice;

“The organisation shall apply all the requirements of this international standard if they are applicable within the determined scope of the quality management system …. and provide justification for any requirement of this international standard that the organisation determines is not applicable to the scope of its quality management system”

Now that, I would argue, is pretty close to where we were on the topic of exclusions in ISO 9001:2008. The matter of applicability is addressed (i.e. not all requirements will be applicable to every organisation) and where a requirement is not applicable, it has to be consistent with the defined scope and justified by the organisation. The only material differences, so far as I can tell, is that the requirement has moved and the actual word “exclusions” is no longer used.

Limitations

One thing that has changed, however, is the limitation of non-applicable clauses to a particular section of the standard (in ISO 9001:2008 that is section 7). That means, in theory, an organisation can cite a non-applicable clause from any part of the standard, provided it can be justified. In practice, that’s not going to happen. To a large extent the more common exclusions from ISO 9001:2008 (design, preservation, customer property) map across on to clauses in section 8 of ISO 9001:2015, but we need to be careful. There are a couple of obvious clauses that fall outside of section 8 that will be justifiably excluded by many. The Calibration and Measurement Traceability requirements in Section 7 of ISO 9001:2015 are the most obvious.

So, to summarise, in my opinion, we are pretty much where we were. So panic over.

You can find more ISO 9001:2015 articles here

Find out more about Capable People, our work, and our fantastic clients at CapablePeople.net

IRCA Approved ISO 9001:2015 Transition Courses delivered worldwide.

Posted in ISO 9000, ISO 9001:2015 | Tagged , , | 8 Comments