Thursday, July 1, 2021

Is Your Quality Policy Exceeding Your Abilities?

Policies. Every day we are governed by them. They provide direction to us on a wide variety of issues at work: the way we dress, the way we act, who gets hired, when/where we can eat, drink and smoke, or which websites we can access on our computers. These policies often are expressed in simple terms for everyone to understand and implement. “No smoking.” “Mask required.” “No open-toed shoes.” We are all familiar with these.

According to Wikipedia, a policy is, “a deliberate system of principles to guide decisions and achieve rational outcomes.” Although this definition sounds straightforward, many organizations struggle when it comes to creating a relevant Quality Policy statement, as defined in ISO 9001 Section 5.2.1. This requires organizations to fulfill the following conditions in their policies:

“Top management shall establish, implement and maintain a policy that: 

  1. Is appropriate to the purpose and context of the organization and supports its strategic direction
  2. Provides a framework for setting quality objectives
  3. Includes a commitment to satisfy applicable requirements
  4. Includes a commitment to continual improvement of the quality management system”

Knowing this, why is it that things often go awry when trying to establish and maintain a Quality Policy? To better understand this phenomenon, let’s consider common wording found in most quality policies: “We strive to meet and exceed customers’ needs and expectations.”

DIGGING DEEPER INTO ‘THE NEED TO EXCEED’
At first glance, this phrase appears to be appropriate to include in a Quality Policy. However, when compared closely to the requirements listed above, this might not be so true. In considering the first item of the requirement, the policy to “meet and exceed” may not always be “appropriate to the purpose of the organization,” however laudable the intention. Imagine this situation:

A customer orders a burger and fries at a fast food drive-thru. In response, the cashier asks over the speaker, “Would you like a glass of Merlot with your burger?” Is this congruent with the customers’ needs and expectations? Or the organization’s strategic direction? Probably not. The customer needs and expects just what they ordered – nothing more, nothing less.

Wikipedia goes on to mention that policies can have unintended effects: “The policy formulation process theoretically includes an attempt to assess as many areas of potential policy impact as possible, to lessen the chances that a given policy will have unexpected or unintended consequences.” Applied to the above example of “meeting and exceeding customer needs and expectations” at the drive-thru, it is possible to see how there might be some unexpected and unintended consequences.

Depending on where your business sits in the supply chain, just doing what the customer asks is fine for many organizations. Of course, through the sales processes of quoting and order taking, customers might be advised what is (commercially) achievable from an organization, so that the third item from the ISO 9001 policy requirements is followed – “satisfying applicable requirements.” However, care should be taken not to over-commit to something the organization is unprepared to deliver. Here, it is best to follow the motto of, “Under promise, over deliver.”

HOW ‘SMART’ IS YOUR POLICY?
Once the policy is effectively written according to the requirements, how can we be sure it’s being successfully adopted? Many policies are readily observed, for example the ‘no smoking’ policy, the personal protective equipment policy, equal opportunity employment, etc. How is a Quality Policy demonstrated as being effectively implemented?

One way to measure this is to apply SMART objectives, which are Specific, Measurable, Attainable, Realistic and Time-Based, in accordance with the Quality Policy, such as the second requirement listed:

b) Provides a framework for setting quality objectives

If an organization has a Quality Policy that is truly aligned with the needs and expectations of the customer, the fundamental principles of “On Time, In Specification,” or OTIS, can be applied across various functions and processes of the organization:

  • Sales – quotes are accurate (in spec.) and delivered to a customer on time
  • Manufacturing - processes produce product (in spec.) on time
  • Maintenance - keeping equipment running (in spec.) and performed on time
  • Training - ensuring people are competent to do their jobs (in spec.) when they need it (on time)
  • New Product Development - creating products (in spec.) released on time (time to market)
  • Shipping – delivering the right product (in spec.) on time

These SMART objectives provide a method for tracking and measuring performance to determine how successful the application of the Quality Policy really is. Targets may be established, for example, for 93% on time, 98% first pass yield, etc., for precise goal tracking as well.

THE FINAL STEP: KEEP IMPROVING
Peter Drucker, noted management consultant and author, often is credited with the quote, “If you can’t measure it, you can’t improve it.” This leads to the final requirement of ISO 9001’s Quality Policy:

  1. Includes a commitment to continual improvement of the quality management system

The established Quality Policy should drive the need for improvement. It has never been sufficient – in any sized business – to rest on the laurels of what brought success. There must be growth and improvement. Rarely are customers’ needs, let alone expectations, always met, so we should be driven to continuously analyze performance to look for ways to improve all business processes.

Sunday, June 21, 2020

Got No Time For ISO 9001 Quality Systems? Maybe You Need a Time Machine!

“Ticking away the moments that make up a dull day…” go the lyrics of Pink Floyd’s song “Time,” taken from the seminal album The Dark Side of the Moon. This iconic work of progressive rock music reflects on the negative effects of performing mundane or routine actions and how time can control one’s life.

The meaning behind the song’s lyrics, while strongly applicable to everyday life, also is an apt description for the way certain clauses of ISO 9001:2015 are implemented. Often, requirements including Management Reviews, Internal Audits and Calibration of Measuring Equipment are planned according to a misperception that they must be conducted at certain intervals, generally throughout a calendar year. 

However, an examination of the relevant clauses reveals there is zero mention of when to implement the requirements, as seen below. 

7.1.6 Monitoring and measuring resources
“…calibrated…at specified intervals…”
9.2 Internal audit
“…conduct internal audits at planned intervals…”
“…an audit program(s) including the frequency…”

9.3 Management review
“…at planned intervals…”

Of course, there may be external influences that impact when these parts of the Quality Management System (QMS) are implemented. Your contract with a Certification Body, for example, might set additional guidelines requiring you to audit the whole QMS in one year. However, in my experience, when organizations choose to adopt a simple time-based approach to implementing these requirements, significant opportunities are lost and costs incurred which may have otherwise been avoided.

In one situation, a company bought the best (and most expensive) torque wrenches they could find, sending them to an ISO/IEC 17025 accredited lab for calibration every year thereafter. A quick review of calibration results obtained over the next five years revealed no appreciable change in the “as found” condition compared to the previous “as received” condition. So, why bother sending them out at all? Aside from an arbitrary schedule telling them a calibration was due, there was no reason or need to continue having them calibrated in this way. 

Consider another instance where, due to the frequency of use, a thread plug gauge was becoming worn out of specification in a matter of a few months. But, because the organization only checked equipment on an annual basis, the worn out gauge was in use for eight or nine months longer than it should have been, with potentially damaging results in that period.

A further example is when an organization chose to internally audit their management system according to a 12-month calendar. In July, most assembly workers left for vacation and were back-filled with seasonal workers for the first two weeks of the month. The impact on product quality was predictable – resulting in increased rejections, rework and delays. Did the internal auditors ever audit the training process to see if it was actually used during this time? No! Because the schedule arbitrarily directed them to only audit Product Identification (which had never been an issue) in that month. Clearly, despite the audits being completed according to plan, they were almost a waste in determining the cause of the problems in July.

Management Review is a key function of the QMS and, as such, should be employed as a means to examine business operations, identifying the status of plans, related performance and actions needed to keep the organization on track. This is particularly important when encountering situations that are, by their very nature, not what was planned to occur. Since these perturbations in business performance are rarely experienced at a predictable point, management’s review shouldn’t be done to simply satisfy a calendar. 

If any organization implementing an ISO 9001:2015 compliant QMS finds themselves doing mundane things simply “because ISO says so,” there’s a good chance management should revisit their understanding of these ISO 9001 requirements. Otherwise, they are at risk of becoming just like the rest of the song:

“Fritter and waste the hours in an offhand way. 
Kicking around on a piece of ground in your home town, 
Waiting for someone or something to show you the way…”

Tuesday, April 30, 2019

All Internal Audits Are Process-based? Er, No...


Since ISO 9001:2000, it’s become increasingly common to consider that an organization’s Internal Quality Audits be performed using the so-called “Process Approach”. At the time of publication, that particular version of the International Standard for Management Systems contained no description of what the process approach was. The recently introduced 2015 version makes the “Process Approach” a lot clearer by describing what is envisaged, in section 0.3 of the Introduction to the Standard – and how it applies to the quality management system development, implementation and improvement. Reading further, the text goes on to describe the Process Approach involving the “systematic definition and management of processes, and their interactions, so as to achieve the intended results.” There’s no mention of anything to do with conducting internal audits in any particular fashion.

Perhaps the Internal Audit requirements, found in clause 9.2, will reveal something…

This particular clause states that “the organization shall:

a)       Plan, establish, implement and maintain an audit programme(s) including the frequency, methods, responsibilities, planning requirements and reporting, which shall take into consideration the importance of the process concerned, changes affecting the organization, and the results of previous audits;”

Interestingly, even this statement, which deals with the actual planning and implementation of the internal audits, doesn’t require that those audits shall (or even should) be conducted using the “process approach”.  In basic terms, it simply states that the audit programme has to consider the importance of the (quality management system) process concerned. Nothing requires an actual audit of a process! So, why has the mantra of “Process-based Internal Audits” become so pervasive?

Maybe “mission creep” has occurred from the influence of the Certification Body auditors who were required to change their approach to one of auditing process(es), around the time ISO/TS 16949 was published. This era ushered in the use (by CB auditors) of the “turtle” diagram for audit planning, which has become wide spread throughout their client base, too.

Although not advocating against the internal audits of (only) processes, a risk-based approach to the considerations of what to audit and when can be very useful. Empirically, we know that risks occur in business and they don’t always occur within a process. Traditionally, risks are associated with something new and/or changed or activities affecting an organization:

·         Product designs & specifications

·         Sources of supply

·         Personnel

·         Technology

By reference to the diagram below, adapted from James Reason’s “Managing the Risks of Organizational Accidents”, (ISBN-10: 1840141050), it can be seen that risks occur throughout an Operation.

Clearly, the selection of a specific process may help when considering what part(s) of the management system to audit, however, further planning may reveal that it’s not always the whole process which should fall under the audit spotlight… It may be a relatively simple activity contained within the process; Perhaps a review of a requirement (customer order) and a subsequent change to that requirement may mean that a second review isn’t as robust. In such a case, auditing the entire process may be unnecessary in determining where the change “slipped through the cracks”. Experience also shows that it can be the interaction between processes where issues manifest themselves – at the interface of 2 (or more) processes.

It follows then, that without a clear, specific requirement to audit (only) processes, an organization is free to choose a specific audit “scope” and “criteria” if those define something within the quality management system which represents risk to effectiveness in achieving intended results. In addition to considering a process as the scope of an audit, the following may also be used:

A customer or regulatory requirement - which might be implemented in select parts over one or more process;

A physical area or location - a warehouse, for example

A specific requirement of ISO 9001 - if it is new or changed

A project: improvement, product design, new technology etc

A specific activity as part of a bigger process.

It's quite reasonable - if there's a clear justification - for choosing any focus for your internal audit programme. After all, ISO 9001 does say process MUST be audited and external auditors can't dictate requirements. Try it! You might just like it and find it useful!

Saturday, March 30, 2019

WTH? A Useful Quality Manual?


One of the first things which comes to peoples’ minds when describing Quality Management Systems and “ISO 9000” is documentation, which often includes a Quality Manual. The background to Quality Management Systems started with (big) procurement organizations such as government agencies and Fortune 500 companies making Quality Systems a contractual requirement. Frequently, these requirements included the need for a document, which was often called a “Quality Manual”, a “Quality Plan” or similar. These were used, by a supplier, to describe the approach to be used to fulfil the contract requirements and assure the quality of the deliverables.

Today, a hall mark of ISO 9001 Quality Management Systems documentation is a Quality Manual – one has been a requirement of the International Standard since 1987. Manuals produced by many organizations emulate the format and content of the ISO 9001:2008 clauses (4 through 8) to the extent that the words “The organization shall” have simply been replaced by the name of the company! This often leads to documents which run into 25 or more pages, written in arcane terminology which has little relevance to the business of the organization. The result? People rarely read the document, it’s often only rubber stamped by auditors and it gathers dust on an office shelf somewhere…

Amazingly, the 2015 edition of ISO 9001 dropped the requirement for a quality manual – indeed any type of traditional quality documentation, such as procedures, work instructions etc -  leaving it up to the organization itself to determine what it needs, based on understanding customer, regulatory expectations and its own requirements for documentation.

Based on their experience with Quality Manuals, it might be tempting to an organization to discard theirs, after all, it only sees the light of day when the Registrar auditor is on site – and no-one else reads it!

But wait! Before that particular baby is discarded with the bath water, why is it that no-one reads the Quality Manual? Maybe it’s because it’s not helpful, uses arcane language and is formatted on an ISO document no-one has reason to read!

There’s a better model on which we can base our Quality Manual which might bring some help to users: The “Quick-Start Guide” you get with some items of house hold electrical equipment etc is a clue. These guides cover the basics of what the (new) user needs to know to get “up and running”. For more detailed descriptions, including navigating the complete set of functions, features and also for fault finding etc, reference can be made to the more comprehensive manual which is also included.
Will your upgrade to the 2015 ISO 9001 requirements be heralded by a new, useful Quality Manual “Quick Guide to the Quality System”?

People Got Talent!


Competency is all around us. It pervades our lives. We see competency on t.v, - for example “America’s Got Talent” – talented people, regardless of their age, gender or social background.  performing all manner of stage acts that wow the show’s judges and viewers. “How did they do that?”, we often ask ourselves…

ISO 9001 includes a requirement for an organization’s people, involved in the Quality Management System, to be competent in their work responsibilities. The normative reference (vocabulary) document, ISO 9000, defines competence as “the demonstrated ability to apply skills and knowledge”. Those t.v show contestants could certainly demonstrate skills and knowledge, but how did they become so competent? They weren’t likely to be born with some “gift”, therefore, their performance is most likely to have been the result of combination of factors…

Practice, Practice, Practice…

 Zig Ziglar is credited with this: “Repetition is the mother of learning, the father of action, which makes it the architect of accomplishment.” Most of those performers will likely attribute their abilities to a combination of education (performance “theory”), training (master classes or similar) and practice, practice, practice… Competent performers can usually demonstrate a specific part of their act, and describe the reason and purpose for it, often including some portion of the related theory.

It is the same with many work related activities in manufacturing. A journeyman machining center setter, for example, would be able to demonstrate competencies in terms of:

·         Blueprint reading

·         Geometric Dimensioning and Tolerancing (GD&T)

·         Machine feeds and speeds

·         Material properties

·         CNC Programming

If we analyze these, we can see that some knowledge aspects are going to be education based – for example material properties which affect the way a part is machined, or CNC programming. Some knowledge aspects may be training derived, either from a classroom event and/or “on-the-job”. Furthermore, a significant proportion of competency is experiential – which comes from practice, practice, practice.

When an organization is determining competencies, it’s worth breaking down the required records into these three categories:

·         Education

·         Training

·         Experience

Then, creating some criteria against which a person can then be evaluated, for the job they do, should be relatively straightforward. Creating a record of these criteria and that they were demonstrated would meet the ISO 9001:2015 requirements stated in section 7.2.

Management must prepare themselves, however, to discover that some employees may not be at the same level of competency they were considered to have reached. From Burch’s Learning Model of the 1970s, we can see there are 4 distinct stages of competency:
·         Unconscious Incompetence

·         Conscious Incompetence

·         Conscious Competence

·         Unconscious Competence

It’s important to recognize, however, that these stages are not concrete and changes can affect the person such that they regress from unconscious competence right back to unconscious incompetence. Anyone who has encountered a MS Windows update will attest to experiencing that. 

Tuesday, November 10, 2015

What Will The ISO Auditor Ask?

It seems that, since Third Party Certification became an option to demonstrate compliance to a standard such as ISO 9001, ISO 14001 etc., it's been common for organizations to try and determine what a Certification Body (aka "Registrar) will ask during their audits. As a consultant, I've been asked many many times, "What will the auditor ask for?" or "How will they interpret this requirement?"

The simple - but unhelpful - answer is: "Who knows?"

The fact is, each auditor has their own unique approach to the auditing process, so it's very difficult to predict what any individual is going to ask about the management system.

It has been common, since Certification audits began, to prepare employees to answer a Certification auditor's questions. This preparation might include strict instructions:


  • Answer only the question you're asked
  • Don't elaborate
  • Don't try to answer if you don't understand the question
  • Don't give your opinion
  • If you don't know, refer the auditor to your supervisor
These "rules of engagement with the auditor" are often seen at work stations, posted in office cubes and so on. In a previous career as a Certification Auditor, I can tell you that when this approach is adopted, it can make employees overly anxious and nervous - and frankly - a good auditor will be totally able to overcome this apparent "stone-walling". In many cases, it can bring down what could have been an effective audit because communication becomes ineffective. It really is playing games, whether it's understood that way or not. And even the best of auditors will struggle to keep a smile on their face. Let's face it, this is not supposed to be an interrogation where the Geneva Convention rules apply: "Name, rank and serial number..."

A far better way to answer the imponderable question "What will they ask" and avoid any negativeness from a Certification auditor, by "stonewalling", is to do the following:

  • Take control of the audit, take the auditor to a person to...
  • Have people explain what they do, then
  • Have them demonstrate how they do it
  • Describe how the process is controlled through any applicable documents
  • Explain what they do when things might go wrong (if applicable)
  • What records are generated (if applicable)
  • If the process is performing as planned to the established goals (if applicable)
  • Their contribution to customer satisfaction and improvements
I'm not a big fan of people being able to whip out a card and recite the quality policy - it's often trite and meaningless (the policy, I mean) so what does it prove?

By taking control of the audit in this manner, the outcome of the audit will become more predictable, the auditor doesn't get to ask (obviously) dumb questions, it makes it easier for them to just audit (which is, after all, a listening activity for which they need to remain silent). As a result, the auditor gets a good feeling that this isn't going to be "one of those audits", where people don't answer freely. This automatically raises the auditor's perception in a positive way. They are able to listen, take vital notes and the pressure to be thinking of the "next question" become less of a burden.

In fact, it's less to do with "passing the audit" and more about the organization actually confirming that it has competent people, who know how to control their processes, what to do when something unplanned happens and so on - vitally important to any organization, whether they are going for ISO Certification or not. Every manager and supervisor should have confidence that their employees know their stuff!

I'd suggest that if your organization has prepared for a Certification audit, that you seriously rethink why you are doing it at all. You are probably avoiding a real issue - that of demonstrating leadership and confidence in your process controls. Imagine if a customer was hearing your people answer "just the question asked", instead of confidently describing what's done, why and how it meets their needs. I know which I'd be more impressed with, in all three roles - auditor, manager and customer.

Thursday, October 29, 2015

ISO 9001:2015 Is here! New Myths Being Created While You Read!

Back in September, the latest revision of ISO 9001 was published (technically, September 15th). Since social media is used much more than it was back when the previous revision - the year 2000 - there's been a greater amount of discussions on various platforms such as LinkedIn, Twitter, Youtube etc about what's in each iteration of the drafts, prior to publication than we had back in 1999.

The standard has been revised heavily and now looks quite different when compared to the previous edition, ISO 9001:2008. This is due to the adoption, by the writing committee ISO/TC 176, of the so-called "Annex SL" High Level Structure.

Annex SL


This is the title of the internal-to-ISO document which defines the structure or format of standards and helps with the alignment of topics or requirements across a range of management systems requirements, such as ISO 14001 (Environmental), ISO 27001 (Information Security) and so on. Instead of hunting through the clauses, it's a lot easier to locate, for example, the internal audit requirement. (9.2.2). The adoption of the Annex SL is primarily intended to allow for easier integration of management systems' requirements. An example would be the merging of a product Quality Management System, with an Environmental Management System.

Annex SL is structured around 10 headings, whereas the 2008 edition of ISO 9001 has 8. One thing that's also notable is that the heading names are quite different.




MYTH ALERT!


"We'll have to renumber our Quality Manual to map to the new structure, to show the CB auditors how we address each ISO requirement"



MYTH BUSTED:


Although the new edition doesn't make a quality manual a requirement (keep an eye open for another blog post on this topic) if an organization decides for one reason or another, to have or retain a quality manual, it doesn't need to follow the format of the 1-10 headings or clauses of ISO 9001. Indeed, even the supporting Quality Management Documents don't need to reference the new clauses of the international standard, either. It's a lot of work, doesn't add any value in real terms for the users and, more importantly, the mapping of requirements to the Quality Management System can be done much simpler and without involving a lot of work.

If a table or document tree is created (in Excel or similar) to cross reference the various documents which currently exist or have been (newly) created to meet the various clauses and sub clauses, it can be used by anyone who needs to know what's been mapped to what ISO 9001 requirement.

While we're on the topic of the Quality Manual, it's gone! Yes! There's no longer a stated requirement for the organization to have a Quality Manual. What were the Technical Committee thinking when they dreamed THAT one up?

If we reflect, for a minute, it may not have been such a bad thing. Let's face it. Most organizations have something which slavishly emulates the layout and content of the actual ISO standard itself. In many cases, just a simple substitution for key words and phrases has been made - for example replacing "The Organization" with "Company X" or something similar. Who wouldn't want to get rid of it?

MYTH ALERT!


WooHoo! We can get rid of the Quality manual. No-one reads it anyway, except for the CB auditor".

MYTH BUSTED:


Whoa there! Before you go consigning the Quality Manual to the recycling/bonfire/shredder, consider this:

Is it the Quality Manual which is the problem? Maybe it's the content which puts people off reading it. After all, if it's 30+ pages long, or uses terminology of the standard maybe THAT's the issue to address. After all, what organization calls their Engineering or Operations functions "Product Realization"? On top of that, there's some weasel words in the standard, too. "Where applicable" and similar terms are scattered throughout, so how is a reader to determine when it is applicable?

Let's revisit the whole idea of a Quality Manual for a minute - with a clean slate.


The "Context of the Organization" is key.


If we consider for one minute, a new requirement of the "Annex SL", which is termed the "Context of the Organization", we might give some thought to the position the organization holds in the market and what they have identified as the needs/expectations of their so-called "interested parties". These might include:
  • Customers and their representatives
  • Regulatory bodies and their representatives
  • Employees
  • Stakeholders
There may well be an expectation or need for some kind of quality manual to be maintained to satisfy one or more of the above. Long before ISO 9001 and certification by 3rd parties came along, it was common practice to create and maintain a document which was very like a quality manual, even if it wasn't actually called that. Furthermore, employees might find one useful, too!

Conclusion


If the context of the organization is properly understood, then creating and maintaining a document - call it a Quality Manual if you wish - which describes the organization, key processes, links to common organization-wide processes and much more may well be seen as a value proposition and not something done "to keep an external auditor happy".

ISO 9001 Myth Busters Blog

 Welcome to my blog! Since its publication, in 1987, ISO 9001 has been a popular standard to implement. With that popularity has come a lot ...