FAQs

October 30th, 2009

To Start my ISO Project I Need a Gap Audit…Don’t I?

Good Question.

Conventional wisdom is that step one is to determine your current situation.  In larger and more complex organizations this is more valid than in simpler and smaller organizations.

A formal gap audit will be conducted very much like an ISO assessment audit.  Each process will be examined, details will be checked and a comprehensive report will be generated.  Perhaps it doesn’t need to be as long as a formal ISO audit but gap audits are still often quite lengthy.

In many cases it is easy to determine the current situation.  “We don’t do internal audits, we haven’t got a formal calibration program, we don’t have a management review meeting”.  Many of the supporting ISO requirements are not implemented in organizations and you don’t need a formal gap analysis to tell you that.

The primary processes in an organization – those that you do for a living, tend to be in good shape.  ISO is such a good standard that if you are successful then you are probably meeting ISO 80-90%.  Consequently it will take a really detailed gap audit to identify these issues and that may simply not be worth it.  Accept that some “tweaking” will be necessary during the project…..but not much.

In most instances, with  a project plan in place,  the gap analysis has a very short life as any gaps are fixed within a few week.

When we perform consulting projects we skip the formal gap analysis in favor of a project planning exercise.  We look at each process, ask some telling questions and focus on planning the solution.  Documenting findings which we are going to fix in a few weeks is just  “busy work”.  We do a basic review of the current situation, produce a project plan identifying the ISO processes and cross referencing to the requirements we expect (at this stage) to address.  During the project, we get into each process in detail and make sure that everything is adequately addressed.  Thus any gaps that might have been around at the start of the project are not very relevant.  Of course we also course this a gap analysis!!

 

FREE E-BOOK:
Five Easy Pieces: The Basic Steps to ISO 9000

Free e-BookNeed to begin implementing ISO 9000 but feeling overwhelmed and unsure where to start? Come get our free guide on the basic steps to ISO 9000:

Download Now

October 30th, 2009

How do I Become an ISO Auditor?

Anyone can be an ISO auditor.

Internal audits are conducted by employees who have been trained how to audit and they conduct audits within the company on behalf of the company. Contact your ISO representative and ask about opportunities for auditing.

Professional auditors work for the certification bodies. There are no mandatory qualifications to become an auditor but certification bodies are required to demonstrate that their auditors are competent. This is actually a very difficult task and a variety of techniques and records have been established by certification bodies to achieve it – to varying degrees of success. Further, just because a certification body has a lot of records in place, it doesn’t actually mean the auditor is any good. In practice, registrars insist or at least prefer that the people they hire (either as contractors or full time) are “registered” auditors. The two main auditor registration organizations are RABQSA based in Australia and America, and IRCA based in the UK. They both offer similar schemes – not surprisingly as they are governed by ISO standards.

RABQSA additionally offers a competency scheme that requires a comprehensive witnessed audit by an experienced skills examiner – although “who examines the examiner?” is a great question.

The other scheme more widely offered (and more popular) is a qualification scheme that requires you to pass a 5 day lead auditor class (with a 2 hour exam), demonstrate with a CV or resume that you have work experience of about 4 years, that you have more specific work experience of about 2 years (e.g. in quality or environmental sectors that you want to audit in) and then participate in audits to demonstrate audit experience.

Getting this audit experience is difficult for some. Some internal audits and supplier audits can count. Consulting audits can count too. If you don’t have access to this, then often a certification body will allow you to participate in audits but there is usually some payback associated with that. Some less than professional certification bodies will actually charge you to be part of a team that they are charging the client for.

You maintain a log of the audits that you have participated in and get the auditee or team leader to sign off on your logs. These, along with other evidence is submitted to the registration organization for review – and issue of your formal status as a registered auditor.

Once you have achieved lead auditor there is no guarantee that a certification body will contract with you or employ you. The work can be grueling, is not particularly well respected and not always well paid. You can use your qualification to set up as a consultant – but because many of us have had less than professional experiences of so-called professional auditors, the status doesn’t always mean much.

Most people who complete the lead auditor training course stop there claiming to be “ISO lead auditors” on their resume and most employers understand that and the value it brings.

October 30th, 2009

Can my Consultant attend my ISO Audit?

Of course they can!  The more relevant question is whether they can “get involved”.

Firstly there are NO accreditation rules that forbid consultants, registrars rarely have documented policies for consultants involvement and thus the auditor often makes the decision.

Not unreasonably nobody wants any interference in an audit.  A consultant who tries to answer questions asked of other people is interfering.  That is not acceptable and the auditor should talk to the consultant.  However, there is nothing restricting the consultant from being involved.  Perhaps the consultant has a formal role in managing corrective action, conducting audits or providing training.

There is nothing that bans auditors from opening or closing meetings (although some auditors try this) and you should stand your ground when an auditor restricts your access to your experts.  If you don’t involve them they will not be able to help you if things go wrong.

ISO 9001 requires the management representative to be part of the organizations “own management” but it is unlikely that ISO were commenting on the employment status of the person performing this role and that would mean that so long as the consultant has a management role in the organization they can in fact be the management representative.  If your auditor is adamant (many of them are) then simply appoint the consultant to the role of coordinator and assign an internal manager as the management representative.

A well behaved consultant will contribute with answers to difficult ISO type questions and point the auditor in the right direction.  A clever auditor will welcome the consultant and take advantage of his/her expertise and experience with the organization.  Bad auditors are scared of being embarrassed or just believe that ISO should be handled by the organization without any help (a little bit like going to court without your lawyer).

Before the audit, get a copy of your registrars policy for consultants (or at least an email confirming it will be acceptable).  Preferably do this before choose the registrar and only choose those that will allow you access to your experts.

October 30th, 2009

What Should I Do if I Am Not Happy With My Auditor?

You have two options.  Complain or don’t complain.

Most organizations avoid complaining because they are worried about that auditor coming back.  Even if you can ensure they don’t return, does your complaint affect the registrar organization who is, after all, sending the next auditor?  Worse than this, in our experience registrars simply don”t see anything wrong with what their auditors do.  They put it down to personality conflicts and misunderstandings and they seem completely miss the opportunity for corrective action.  That said an unofficial complaint or “challenge” of a finding is often reviewed favorably.

Of course you do have recourse to complain to the accreditation agencies (e.g. ANAB).  However, these too are rare.  You have to remember that while ANAB is independent, it is funded by the people they are investigating complaints against.  Since September 2006 (3 years) there have been 93 complaints against registrars (check out the ANAB website at ANAB.org).  That’s about 31 per year.  How many registered companies are there?  (figures are hard to tell because there is no one source).  In the US an estimate of 100,000 might be appropriate, all of which are audited for at least one day a year!

So while we would urge you to complain and correct auditors who are wrong, we are realistic.  Choose you battles.   If necessary ask “nicely” for findings to be reviewed.  If its a behavioral issue or once you realize that you deserve to get value for what you pay, the simplest route is to just change registrars.  A new registrar can take over your certification without any extra cost or effort – they simply take up where the last one left off.  When negotiating with the new one you can make your points clear and ensure follow up.

October 30th, 2009

Do I have to buy a copy of the ISO standard?

Technically no!  However, there is an argument, used by auditors that if you don’t have a copy, how can you achieve conformance.  Your “old” copies, checklists and other documents may contain the reqiurements but unless you can “prove” they are the same (for which you will need a copy of the standard) you are out of luck.  If you own a copy of the 2000 version of the standard your could try arguing that the 2008 version introduced no new requirements but we don’t think it will work.  In practice you need a copy of the standard.  Available at ASQ.org.

Submit a Question

Whatever your question we promise you personally a comprehensive, quick and correct response. We can't always publish every question, but will if it has wider appeal.

* = required field