IRCA Auditor Transition Training: ISO 9001 & 14001:2015

At what stage are the ISO 9001 & 14001 standards at?

Both ISO 9001 and ISO 14001 were reissued in September 2015. That does not mean that ISO 9001:2008 and ISO 14001:2004 have been withdrawn or that they are redundant. Certified organisations will be required to transition to the new standards before September 2018. If past transitions are anything to go by, relatively few will transition in year one. Most certification audits in 2016 will continue to be against the older standards. Obviously the ratio will start to change as the three year period progresses. ISO 9001:2008 and ISO 14001:2004 will be withdrawn for certification purposes at the end of September 2018.

 

What about transition training?

The format of IRCA approved transition training will be modular. Both ISO 14001 and ISO 9001 have adopted the Annex SL format (as will ISO 45001 when it is issued next year). Transition training for each standard will involve attendance of a 1 day Annex SL module. In addition, transition training will require attendance of a 1 day standard specific module (i.e. on ISO 9001 or ISO 14001). So effectively we are looking at a 2 day duration for transition training to a single standard. As the Annex SL module is common, it is applicable to both ISO 9001 and ISO 14001 standards. That means a person wishing to transition to both ISO 9001 and ISO 14001 will be required to attend 3 days worth of transition training in total. That is, 1 day for Annex SL, 1 day for ISO 9001:2015 and 1 day for ISO 14001:2015.

The same will apply to OHSAS 18001/ISO 45001 transition when those changes take place in 2016.

Capable People transition training will be available from December 2015. Dates and prices for transition training starting in December can be found by following this link. TRAINING SCHEDULE

Here’s a link to the course descriptions for each new transition course on CapablePeople.net;

ISO 9001:2015 Transition Course Description

ISO 14001:2015 Transition Course Description

If you have any questions, you know where to contact me.

Shaun Sayers

Posted in Auditing, IRCA, ISO 14001, ISO 9000 | Tagged , , , , , | 2 Comments

API Q1 Revision 9 and the Risk Based Approach

The extent that the “risk based approach” will affect the nature of ISO 9001 certification is a hot discussion topic at the moment. Obviously, with the actual standard still months away (we haven’t yet, at the time of writing, even seen the FDIS) the debates are academic and hypothetical. However lately I have had some exposure to how the risk based approach may impact the QMS in a very practical way, having just started an API Q1 revision 9 project.

Now, for those of you that don’t know, the API Q1 revision 9 standard is based upon ISO 9001. It is assessed and awarded directly by the American Petroleum Institute (i.e. not any approved certification body) and it applies to organisations that provide design and fabrication services within the petroleum industry. An industry specific variation of ISO 9001 in other words. A bit like AS 9100, ISO 13485 or TS 16949. Revision 9 has already integrated the risk based approach and, along with my client, I have been able to have a little play with it.

Obviously there are a few things that are as they are. Document and Records Control, Policy, Objectives and so on, however the API standard has not only ADDED the risk based approach to its standard, it has INTEGRATED it. What I mean by that is that you can’t simply bolt on a “risk management” procedure, or maybe retitle your Preventive Action procedure as “Risk Management” – you have to integrate it.

The authors of that standard have taken care to cross refer the approach WITHIN other requirements – Contract Review, Production and Planning for example. Risk has to be considered at organisational level (matters such as adverse weather, power outage, geopolitical disruption, for example) and also on a more day to day level on specific production runs (considering matters such as supplier reliability, non-availability of key personnel, machine outage).

Moreover there is a more high profile MANAGEMENT OF CHANGE requirement. It has to be done in a more integrated and specific way. Again, this can’t simply be kicked into the long grass with a generic “management of change” procedure – it has to be INTEGRATED. What does this mean? Well, as an example, the assessment of action resulting from a non-conformation must assess whether the corrective action requires a systematic management of change (as opposed to a more mundane correction, update to a document or repair). In the event that an NC requires a system change, the the MoC procedure will define the consideration for assigning responsibility, tracking, verifying close and also for systematic and recorded communication of that change throughout the organisation.

It is a challenging standard to work with because its quite hard to get away with bluffing anything, but I suppose that makes it a GOOD standard. I’ll be interested to see just how much ISO 9001:2015 adopts the model and process. I hope it takes a great deal of it because, at this stage, it feels like a big step in the right direction.

The Risk Based Approach is the new Continual Improvement.

If you have any questions about this approach or my experiences with API Q1, you know where to contact me.

 

Shaun Sayers

Posted in API Q1, ISO 9000, Risk & Assurance | Tagged , , , , , | 2 Comments

The Challenges of Cyber Security

This is a guest post by Chris Rogan from Unleashed

From ISO 9001 to ISO 27001  … and beyond

I’ve known Shaun at Capable People for many years, in a past life, I was lucky enough to be trained as a lead auditor in a number of standards and have kept in touch ever since.  When we recently caught up, he asked whether I’d write a guest post and I jumped at the chance.

Like Shaun, I’m also a rather prolific blogger over at my company, Unleashed.  One of the many things that interest me is the use of IT in the successful standardisation, implementation and ongoing improvement of business processes.

Around the time I was trained to be a Lead Auditor by Shaun, I was an IT Manager of a highly successful Nuclear Construction business at Sellafield.  My role evolved – fusing what I knew about IT with Management standards, we accelerated a programme that achieved triple ISO accreditation for the business in ISO 9001, ISO 14001 and OHSAS 18001.

How IT can help ISO standards

My first experiences of businesses working with ISO 9001 were in a glazing factory, the work was very much paper based.  The system was, of course not mine. It was cumbersome, funded by the old Business Links and EU grants and really wasn’t followed.  The ideal was to eventually go for kite marking of glazed units, which never quite moved forward.

The systems I developed were all based on the fact that we’d invested in ERP tools.  Don’t let the Three Letter Acronym (TLA!) worry you, what ERP stands for is less important than what it does.  Imagine if you had one piece of software in your organisation that managed your accounts, your production scheduling, deliveries, resources (both human and other) and payroll.

We essentially had one integrated piece of IT that the standards could be written to, and tools such as Microsoft SharePoint covered issues that the ERP couldn’t hoover up.  It was no wonder that for a 300 employee origination we achieved accreditation in less than 12 months.

How ISO standards now help IT

I recently implemented an ISO 27001 for Information Security Management – at my old employer no less.  It’s a relative no-brainer that in the nuclear sector, you’ll need this level of management standard to even just tender for work and show the supply-chain you’re serious about confidentiality.

My take on 27001 though, is still very much from the practical side of the implementation – the actual IT controls that you need to build in order to successfully implement the ISO 27001 standard and achieve successful accreditation.

Working in a responsive business is frustration as an IT department, quite often we didn’t get notice of leavers and starters – I even got ‘attitude’ when I asked what people were starting as, even though I needed to know for setting up security permissions.

ISO 27001 in many respects allows you to professionalise your IT and make things more professional and brings in specific controls that require discipline to be enforced inside the company that smooth along the IT operations.

ISO 27001 and the developing cyber security standards

You’re probably reading this thinking that you don’t need anything, your IT contractor or your IT department takes care of this.  However, as an owner or director you have both a fiduciary and legal duty to take care of the information you hold.

Legislation such as the Data Protection Act means that if you work with personal data then you have to take necessary, reasonable steps to protect it and it’s not the IT guys or IT company who are liable.  It’s you.

Now, I don’t say this to scare you – it’s a new fact of life.  Everyone talks about cyber warfare, Russian crime syndicates and all sorts of other global issues that don’t seem to affect SME’s in Blighty.

I remember the first time I was hacked. The servers that I had built with my own fair hands became a dumping ground for an Italian hacker who used our ISDN connection (yes it was a while ago) to get into our server and set up a file sharing site.  We had a lot of PlayStation games, Italian movies and dubious quality porn.

I quickly deleted two thirds of that, and patched up the problem, (Microsoft’s fault, not mine).  But it was a stark reminder that the risk is real, has been there for a long time, and the only reason I noticed the problem was because the hacker had filled up our hard drive to the point where the backup tapes were full.

More recently I’ve been involved in helping out with cases of bank fraud, employees steeling company data and worse.  You’ve probably already been compromised but the hackers have been relatively benign and your awareness will only be raised when one of your employees experiences a bank fraud and investigations eventually lead back to the employers databases.

It’s fair also to say that the Information Commissioner recently has not only developed teeth, but also fangs especially for those who don’t take basic steps for Cyber Security.  Fines have been largely growing in nature and are probably at the point where they could kill off an SME.

The standards mean you don’t need to be a geek to know the right questions are being asked, the whole point of ISO 27001 means that information security becomes a part and routine of what you do.  If you don’t want to go that far, the government is starting to push Cyber Essentials and Cyber Essentials Plus.

Cyber Essentials Plus is also eventually going to find some integration with ISO 27001.  Word from those in the know is that these standards are going to become prerequisites for any public sector supply-chain work.

Moving forward, businesses that have been proactive about adopting these standards, like those who adopted 9001, 14001 and 18001 early received the benefit of kudos, being the safe pair of hands and ultimately being able to prequalify for work where others couldn’t.  The same will undoubtedly occur for Information Security.

If you want to learn more about the issues discussed in this blog, Chris Rogan can be contacted at Unleashed www.weareunleashed.com

Posted in ISO 27001 | Tagged , , , , | Leave a comment

Risk Velocity

This is another guest post by Karel Simpson, Corporate Risk Manager at GardaWorld. You can read Karel’s previous posts On risk management and ISO 31000, browse the “Risk & Assurance” category in the left hand margin of this page

Risk velocity as a part of risk management

I have discussed the various elements involved with evaluating risk before but I have just recently come across the term ‘risk velocity’. It attracted my attention enough to make me do a little research and talk to other professionals about it.

My initial research identified “risk velocity” as an element within risk management. It is most often applied in the realms of financial risk but not from what I can gather in any other risk management disciplines, whether that is enterprise risk, safety or whatever.

What is risk velocity?

If we google “velocity” the search results suggest the following is the most widely applied definition;

‘the speed of something in a given direction’

If we extrapolate this definition, and apply it to the velocity of the risk, we are therefore trying to assess how fast it can be felt or soon it can cause the impact we have identified.

I have found a few examples – it must be noted that I am just scratching the surface with my initial research that I have so far conducted into this matter – of this terminology being used outside of financial risk circles but they seemed to be more like individual businesses coming up with something that suits their own purposes rather than an actual standard approach.

Stripping down to the basics of risk, it is most commonly expressed as the combination of Likelihood x Severity.  In other words we are trying to work out ‘How likely is it to happen?’ and ‘If it did happen what is the end of result?’. Risk velocity introduces into this equation ‘how fast will this risk develop and/or how fast will the impact be felt?’. There are certainly situations where this additional focus is quite important.

Imagine that you are presenting to your board or senior management team on your corporate risks, you have a total of 10 risks identified (to keep it simple), 3 risks are deemed low, 4 identified as a medium risk and 3 stand out as being of a high risk to the business. Considering risk velocity could offer additional benefits.  Imagine, for example, you have identified risk to the reputation of the business and your current mitigation would be to engage an external company PR company to deal with it.  Does this reaction account for how fast the impact can be felt these days with the effect of social media?  Taking into consideration “risk velocity”  may lead you to re-evaluate a “low risk” because your existing control (the use of a PR agent) is not sufficiently rapid to stop things getting out of control. Thinking about risk in this way could also, for example, lead you to re-consider your selection criteria for some suppliers. Can they respond quickly enough? What sort of contact hours do they offer? etc.

Also, financial budgets are commonly restrained in all businesses and you need to focus on what you spend money on, AND IN WHAT SEQUENCE, based on risk and priorities. Consideration of risk velocity as an additional part of your risk calculations could allow you to have a practical means of differentiating between 3 high risks.  One risk may take weeks or months to develop, another one days to weeks and the third hours to days.

As you’d expect, risk velocity is easier to think about in conceptual terms than it is to actually incorporate into your risk assessment process.  One example I have encountered that simplifies the process was to score Likelihood x Severity then + Velocity so if you use a 5 x 5 matrix and the likelihood and severity was a 4, your initial score would be 16. Rating velocity as Hours to Days = 3, Days to weeks = 2, and Weeks to months = 1, we now then add in “velocity” to the calculation giving respective scores of 17, 18 and 19.  This differentiates the risks and allows us to evaluate our course of action, priority and sequence of our response measures.

I would personally recommend looking at risk velocity as I really think that this will push through into the main stream of risk management in the coming years and more importantly will provide a key tool in focusing and managing the subject of risk.

Posted in 45001 Lead Auditor Study Group, Risk & Assurance | Tagged , , , | Leave a comment

ISO 9001, ISO 14001 and ISO 45001 Transition Training Update

I feel the need to write this update because of the amount of interest, ignorance and willful misinformation circulating at the moment regarding ISO 9001:2015, ISO 14001:2015 and ISO 45001 lead auditor training and auditor transition training.

Current status (as at March 2015)

At this current moment in time, none of the above mentioned standards have been issued. Whilst draft documents have been issued for comment, these are NOT the final documents and they may well change following consultation. Consequently training courses purporting to train people on “the new standards” are not training people on the new standards as they have not been published. These courses do not carry approval from IRCA or IEMA, RAB or anybody else. There is nothing illegal about training people on the draft, but as these are unaccredited courses and they work on the assumption that the current drafts will be the same as, or close to, the actual final versions, the principle of buyer beware applies. Capable People will not be offering transition training until we know the content of the actual documents, and that will not be prior to their issue.

Validity of ISO 9001:2008, ISO 14001:2004 and OHSAS 18001:2007

As organisations will likely have a three year transition period FROM THE POINT THE NEW STANDARDS ARE ISSUED, you must bear in mind that many organisations will remain certified to the older standards for some years yet, and auditing to the old standards will not become obsolete any time soon. In fact it will take the certification bodies a short while after the standards are issued to put their auditors in a position where they can credibly audit to the new versions. In short, THERE IS NO RUSH.

What will the transition arrangements be?

This week the IRCA published some information that outlines the likely arrangements for auditor transition. As most companies take their lead from the IRCA on matters like this, it is probably useful to listen to what they have to say;

“To ensure IRCA-approved training organisations can maximise the business opportunities stemming from updates to ISO 9001 and ISO 14001, we’re releasing new course criteria and exams together with the transition training courses. The precise schedule will be dependent on the release of the Final Draft International Standard (FDIS).

The new criteria will follow a modular approach, incorporating both an Annex SL structure and standard-specific changes”

Here is a link to further details, what it means to auditors and potential timelines.

As you can see, the IRCA have confirmed that no specific arrangements can be made until we know the content of the respective FDIS. At the moment we do not.

What should I do next?

Only you can make that decision. Current IRCA/IEMA approved Lead Auditor training remains the most valid option for anyone needing to be trained in the meantime. Employers, generally, do not regard unaccredited training as having the same value as an indicator of training and competence. Keep an eye on the capablepeople.co.uk and this blog for updates. We have a keen interest in getting things right and also in doing the right things. So far as transition training goes, sit tight and wait. There is no rush and (in our opinion) unaccredited training based on a draft standard will not give you any advantage but it could be a waste of money.

I’ll keep you posted as and when more details emerge.

Shaun Sayers

Posted in IRCA, ISO 14001, ISO 9000, OHSAS 18001 | Tagged , , , , , , , | 5 Comments