Review and Revision of ISO/IEC 17021

Slides:



Advertisements
Similar presentations
1 IAF Working Group on FSMS Azusa Nakagawa-Inoue PAC TC meeting 16 June 2010.
Advertisements

ANSI/ASQ E Overview Gary L. Johnson U.S. EPA
ISO 9001: Countdown to 2015 Presented by Ellen Diggs Ellen Diggs Consulting February 11, 2015 It’s Not Just for Manufacturing Anymore!
Accreditation 1. Purpose of the Module - To create knowledge and understanding on accreditation system - To build capacity of National Governments/ focal.
Page 1 ISO Committee on conformity assessment. Page 2 ISO at a Glance.
IAQG OPMT OP Assessor Training Module 3 Preparing for the Face to Face Training: Instructions & Communication February 2015.
International Organization
ISO Current status of development
TEMPUS ME-TEMPUS-JPHES
RC14001 ® Update GPCA Responsible Care Committee September 23, 2013.
TS16949 requirements Subjects –Audit planning –Recertification audit requirements –Auditing Remote supporting functions.
Registration Management Committee Body of Knowledge (BoK) for Other Party (OP) Assessors David Day GE Aviation.
A Review ISO 9001:2015 Draft What’s Important to Know Now
ISO 9001:2015 Revision overview - General users
ISO 9001:2008: Key changes and transition process
TC176/IAF ISO 9001:2000 Auditing Practices Group.
ANSI-ASQ National Accreditation Board FQS Accreditation for forensic testing agencies Bob Cruse RMC Denver Co., September
ISO 9001:2015 Revision overview December 2013
ISO 9001:2015 Revision overview - General users
ISO STANDARDS TRAINING & CONSULTING
Company Confidential 1 Revisiting CB Use of AS9101 Rev D Tim Lee 12 March 2012.
Quick Guide to help your transition
ISO 9000:2015 Quality Management Systems — Fundamentals and Vocabulary
Introduction to the ISO series ISO – principles and vocabulary (in development) ISO – ISMS requirements (BS7799 – Part 2) ISO –
Conformity assessment – Standards and CEOC’s involvement Annual Conference 31 of May 2010 in Vienna Dipl.-Ing. Gerd-Hinrich Schaub CEOC International.
EMS Today: Emerging Issues Energy & Environmental Division National Conference San Antonio, Texas September 20, 2005.
ISO / IEC : 2012 Conformity assessment – Requirements for the operation of various types of bodies performing inspection.
Company Confidential Registration Management Committee OP Assessor Workshop, San Diego, CA - 17 January 2013 Body Of Knowledge for OP Assessors Will S.
ISO 9001:2008 to ISO 9001:2015 Summary of Changes
New ISO Standards Transition Workshop (Auditors)
Company Confidential Registration Management Committee (RMC) Other Party Management Team (OPMT) Resolutions San Diego, CA January 19, 2012 Stanley Faust.
Company Confidential Registration Management Committee RMC Auditor Workshop Charleston, SC July Supplemental Oversight AS9104/2A & Special.
ISO/IEC 17065:2012. Objective Identification of new/changed requirements in ISO/IEC 17065:2012 and the implications of these changes for certification.
Multi Site The assessment of multiple sites for a single Registration/Certificate shall be conducted by assessing each site to the complete and.
CSOC – Certification Structure Oversight Committee Application Guidance October 2015.
1 ISO/PC 283/N 197 ISO Current status of development November 2015.
Webinar FSSC audit report 7th september 2015
Company Confidential 1 AAQG RMC 9101:2009 Revision Workshop Prepared by IAQG 9101 Team 19 July, 2010 Atlanta Ga. “It’s All About Performing” Quality Management.
It was found in 1946 in Geneva, Switzerland. its main purpose is to promote the development of international standards to facilitate the exchange of goods.
Webinar Auditor Qualification. “To be the world’s leading, independent, GFSI recognized, ISO based food safety and quality management system for the entire.
Company Confidential Registration Management Committee 1 Audit Outcomes & Appropriate Conclusions July 16, 2014 Bob Cruse ANAB, Aerospace Program Manager.
1Presentation of CASCO SMA 5 June International Organization for Standardization.
TC176/IAF ISO 9001:2000 Auditing Practices Group.
Quality Management Systems Advice from ISO/TC 176 for Sector-specific applications.
ANAB AQMS Accreditation Programs Overall AQMS Accreditations  37 AS9100  6 AS9110  23 AS9120 AQMS Applicants  2 AS9100  8 AS9110  1 AS9120.
ISO 9001:2015/14001:2015 Certification Transition Process
The competence of management system auditors and the development of part 2 of ISO/IEC and its relationship with ISO/IEC19011 D Iain Muir ISO/CASCO.
Forum with Certification Bodies 2010 “Global Acceptance” 26 July 2010 Dewan Seri Seroja, Putrajaya Forum with Certification Bodies 2010 “Global Acceptance”
1Johannesburg South Africa SMA May International Organization for Standardization.
Final Rule Accredited Third-Party Certification 1.
ANAB Report to the AAQG RMC September CBs Per Program through 30 June 2006.
Lori Gillespie, ANAB Director of Accreditation
July 21, 2016 Susie Neal Director QMS Compliance UTC
IAF TC Report to PAC TC Summary of progress (June 2017)
Review and Revision of ISO/IEC 17021
Presented to <name> by <name> <date>
Introduction of ISO/IEC 17065: 2012
ISO 9001:2015 Auditor / Registration Decision Lessons Learned
Registration Decision Criteria
July 21, 2016 Susie Neal Director QMS Compliance UTC
Highlights of SR003 Rules for AS 9100, 9120 and 9110 Transition
Presented to <name>
Presented to <name> by <name> <date>
Presented to <name> by <name> <date>
Americas Aerospace Quality Group Registration Management Committee
ACCREDITATION PROCESS
ISO/IEC 17011:2017 Conformity Assessment – Requirements for accreditation bodies accrediting conformity assessment bodies Presentation on the updated.
Presentation transcript:

Review and Revision of ISO/IEC 17021 History—September 2000 to present ISO/IEC 17021:2006 ISO/IEC 17021:2011 Revision of ISO/IEC 17021 NWIP Discussion of progress Comments : None

History Developed by ISO/CASCO Working Group 21 Co-conveners Alister Dalrymple, France-AFNOR AFNOR, a Standards Development and Certification body Randy Dougherty, US-ANSI ANAB, an accreditation body for management system certification bodies Comments : None

ISO/IEC 17021:2006 Original intent of WG21 for 17021 To replace Guides 62 and 66 To be applicable to any management systems To incorporate IAF guidance To incorporate latest technology To be consistent with the common elements (WG23) Principles-based performance requirements (where possible) Comments : The extension of the scope of the document from Quality Management Systems (Guide 62) and Environmental Management Systems (Guide 66) was necessary to provide a set of generic requirements for all different types of Management Systems being developed by ISO

ISO/IEC 17021:2006 ISO/IEC 17021:2006 Conformity assessment—Requirements for bodies providing audit and certification of management systems Published 15 September 2006 Comments : None

ISO/IEC 17021:2011 Intent of WG21 for the revision of 17021 after 2006 References to ISO 19011 guidelines with requirements applicable to any third party MS audit Audit process CB management of competence, including the competence of audit teams Template for specific auditing requirements that can be applied to other ISO TCs TC 176 for ISO 9001, TC 207 for ISO 14001, TC 34 for ISO 22000, etc. Comment : The 2011 version reinforced the Competence Approach for the key certification functions, whereas it was mainly the competence of the auditor which had been the focus of the previous texts.

ISO/IEC 17021:2011 ISO/IEC 17021:2011 Conformity assessment—Requirements for bodies providing audit and certification of management systems Published 1 February 2011 Comment : The remit given to the Working Group 21 was to amend the 2006 version to include additional requirements but not to revise the 2006 text. Strictly speaking therefore, the 2011 text was not a revision of the 2006 standard.

Generic Requirements for 3rd Party Auditing & Management of Competence (based on 19011) ISO/IEC 17021 Part 2 Framework for Developing Specific Requirements for 3rd Party Auditing & Management of Competence QMS Competent e.g. ISO/TC176 EMS Competent Body, e.g. ISO/TC207 FSMS Competent Body, e.g. ISO/TC34 ISMS Competent Body e.g. ISO/TC178 xMS Competent Body Comment : ISO/IEC 17021 was developed as a generic foundation document to serve as the basis (a template) for the development of specific requirements relating to the certification of Quality Management, Information Security, etc. as necessary. QMS Specific Competence Requirements EMS Specific Competence Requirements FSMS Specific Competence Requirements ISMS Specific Competence Requirements xMS Specific Competence Requirements By other competent bodies with WG21 By WG21 and included in 17021

ISO/IEC 17021-1 and additional competence requirements ISO/IEC 17021-1 generic competence requirements for any MS ISO/IEC TS 17021-2 competence for EMS ISO/IEC TS 17021-3 competence for QMS ISO/IEC TS 17021-4 competence for event sustainability MS ISO/IEC TS 17021-5 competence for asset MS ISO/IEC TS 17021-6 competence for business continuity MS ISO/IEC TS 17021-7 competence for road traffic safety MS ISO TS 22003 includes competence for food safety MS ISO 28003 includes competence for supply chain security MS ISO 50003 includes competence for energy MS ISO/IEC 27006 includes competence for information security MS Comment : 17021 was used as the basis for the development of a series of specific certification and/or competence standards, some of which were published as “17021-xx”. In every case, these standards were drafted jointly by the relevant ISO Technical Committee in conjunction with ISO CASCO.

Revision of ISO/IEC 17021 NWIP—Rationale for the revision The 2011 version contains the whole of the 2006 version unchanged as well as additional clauses. It is necessary to determine if the unchanged 2006 clauses need alignment with the new clauses added in 2011. Several interpretation requests were addressed since the publication of the standard and should be taken into consideration in any revision. Experience gained with the implementation of the standard has highlighted the need for clarification of some of the clauses Comment : None

Revision of ISO/IEC 17021 Inputs considered Out-of-scope comments on revision of 2006 CASCO interpretation requests IAF application documents APG and AAPG papers Outcome of WG33—ISO/IEC TS 17022 Outcome of WG37—ISO/IEC TS 17023 CASCO PAS documents 17001-17005 Other CASCO documents—17020, 17024, 17065 Comment : None

Revision of ISO/IEC 17021 Meetings 27-29 November 2012 3-5 April 2013 25-27 June 2013 Goal of DIS not achieved 18-20 November 2013 Goal of DIS achieved 11-16 & 23 May 2014 DG via Webex 90% affirmative but 1023 comments-164 pages 11-13 June 2014 Decision for a DIS 2 January 2015 Decision for FDIS and a 2 year transition Comment : None

ISO/IEC 17021-1:2015 Key changes Re-organization of Section 9 Requirements now more in order of how certification audits and services are provided by a CB Comment : None

ISO/IEC 17021-1:2015 Key changes Improving control by CBs Requirement for a CB to demonstrate effective operational control of its remote offices and personnel regardless of their organizational structure (6.2) Requirement for a CB to demonstrate effective organizational control for persons making certification decisions (9.5) Comment : This control over the processes and personnel involved is all the more necessary as new aspects such as working through the Internet, dematerialization of documents, etc. become more common in the business environment not only of CBs’ customers but also of the CBs themselves.

ISO/IEC 17021-1:2015 Key Changes Allows a statement, but no mark, on product packaging (not on product) and accompanying literature that a company has a certified management system (8.3.3) cannot imply the product is certified by this means to include the name of the CB Comment : None

ISO/IEC 17021-1:2015 Key Changes Defined audit time from planning to reporting (3.16) Defined audit duration from opening to closing meeting (3.17) Focused requirements for justification on audit duration (9.1.4.3) Consistent with ISO/IEC TS 17023 guidelines Consistent with proposed revision of IAF MD5Defining audit time Comment : This clarification is important as it reinforced the existing requirement that the CB shall “determine the time needed to plan and accomplish a complete and effective audit” (9.1.4.1)

ISO/IEC 17021-1:2015 Other Changes Defining/Classifying nonconformities as major (3.12) and minor (3.13) Added one new principle for a risk-based approach (4.8) Adopted the approach in ISO/IEC 17065 and not require, but still allow, an impartiality committee (5.2.3) Comment : None

ISO/IEC 17021-1:2015 Other Changes Formalized a 2 year separation as a recognized mitigation of many threats to impartiality for internal audits (5.2.6) for relationships with consultancies (5.2.7) Persons that provide consultancy (5.2.10) Allowing a CB to certify another CB for a management system, except for a QMS (5.2.4) Comment : The “2-year Rule” is not a hard and fast requirement and needs to be implemented in the light of identified areas of concern and the various means that may be deployed to mitigate such threats. A CB may wish to implement a Management System (such as Information Security) or may even find it being imposed as a Contractual Requirement by a Customer . Current standards prohibit the formal recognition of any such Management System by an independent external body.

ISO/IEC 17021-1:2015 Other Changes Adopted the approach in ISO/IEC 17024 regarding public information with, or without, request (8.1) No longer requiring a public directory of certifications Comment : None

ISO/IEC 17021-1:2015 Other Changes New requirement for consideration of shifts in the audit program (9.1.3.5) New requirement on transfers requiring a CB to obtain and retain sufficient evidence such as reports and documentation on corrective actions for prior nonconformities(9.1.3.4) New requirement to plan for adequate auditing when certifying to multiple management systems standards (9.1.6) Comment : None

ISO/IEC 17021-1:2015 Other Changes If a CB is unable to verify effective correction and corrective action 6 months after an initial audit, another Stage 2 shall be conducted (9.5.3.2) Based on the change above, changed the requirement for the first surveillance audit after initial certification to be 12 months after the initial certification decision date (9.1.3.3) Comment : This change effectively aligns the normal audit cycle with the certification cycle to simplify certification administration for both the CBs and their customers.

ISO/IEC 17021-1:2015 Other Changes When recertification is completed prior to expiration, the expiration date can be based on the existing certification (so certification may be longer than 3 years) (9.6.3.2.3) If the recertification audit is not completed, or any major nonconformity not verified, by the expiration date, then recertification cannot be recommended and the validity of the certification cannot be extended (9.6.3.2.4) Six months allowed for recertification following expiration of certification; otherwise, a Stage 2 shall be conducted (9.6.3.2.5) Comment : None

Significant Proposed Revisions of ISO/IEC 17021 New requirement for the audit report requiring a statement of the conformity and effectiveness of the MS (9.4.8.3) from consideration of ISO/IEC TS 17022:2012 Conformity assessment—Requirements and recommendations for content of a third-party audit report on management systems Comment : None

Significant Proposed Revisions of ISO/IEC 17021 Normative Annex A revised to include expanded statements explaining competence requirements similar to approach in ISO/IEC TS 17021-2 or -3 Eliminated the X and X+ Comment : Apart form the elimination of the “X” and “X+” convention felt to have created some confusion for the users, the table A has been basically left unchanged, as it serves as a basis for a number of other ISO Standards dealing notably with competence issues for specific Management Systems (see slide 8)