0% found this document useful (0 votes)
25 views64 pages

Auditing Management Systems Guide

The document outlines the auditing process for management systems, detailing the ISO 19011:2018 standard, audit definitions, principles, and the roles of auditors and audit teams. It emphasizes the importance of audits for ensuring compliance, identifying improvements, and enhancing overall management system performance. Additionally, it describes the certification process, including steps for organizations to achieve ISO certification and the roles of certification and accreditation bodies.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PPTX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
25 views64 pages

Auditing Management Systems Guide

The document outlines the auditing process for management systems, detailing the ISO 19011:2018 standard, audit definitions, principles, and the roles of auditors and audit teams. It emphasizes the importance of audits for ensuring compliance, identifying improvements, and enhancing overall management system performance. Additionally, it describes the certification process, including steps for organizations to achieve ISO certification and the roles of certification and accreditation bodies.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PPTX, PDF, TXT or read online on Scribd

Quality Systems

Module 4
Auditing
Management System Documentation
Policy Statement / Objectives Statement

Manual

Management
Procedures/plans

Work Instruction

Forms / Records
ISO 19011:2018 Standard
• ISO 19011 (First edition 2002)

• ISO 19011 (Second edition 2011)

• Guidelines for management systems auditing.

• ISO 19011 was prepared jointly by Technical Committee ISO/TC 176, Quality management and

quality assurance, Subcommittee SC 3, Supporting technologies,


ISO 19011 Standard (Cont.)
• Clause 1 Scope
• Clause 2 Normative references
• Clause 3 terms and definitions
• Clause 4 principles of auditing.
• Clause 5 Managing an audit programme
• Clause 6 Conducting an audit
• Clause 7 Competence and evaluation of auditors.
Reasons for Conducting The Audit
Organization must review its Management System (MS) to:
1) Ensure the compliance with the applicable standard requirements.
2) Ensure the continuing suitability and success of the MS.
3) Reveal defects, danger spots or irregularities.
4) Suggest possible improvements.
5) Eliminate wastage or loss.
6) Check the effectiveness of management at all levels.
7) Ensure that managerial objectives and methods are effective and are capable of achieving
the desired result.
8) Continually improve the performance.

The audit process is considered as an important tool for self assessment


Definitions

1) Audit

systematic, independent and documented process for obtaining audit evidence and evaluating it

objectively to determine the extent to which the audit criteria are fulfilled.

NOTE 1 : Internal audits, sometimes called first-party audits, are conducted by, or on behalf of, the

organization itself for management review and other internal purposes, and may form the

basis for an organization's self-declaration of conformity.


Definitions (Cont.)
NOTE 2 External audits include those generally termed second- and third-party audits. Second-
party audits are conducted by parties having an interest in the organization, such as
customers, or by other persons on their behalf. Third-party audits are conducted by
external, independent auditing organizations, such as those providing registration or
certification of conformity to the requirements of ISO 9001 or ISO 14001.
NOTE 3 When a quality management system and an environmental management system are audited
together, this is termed a combined audit.

NOTE 4 When two or more auditing organizations cooperate to audit a single auditee ,this is termed

a joint audit.
Definitions (Cont.)
2) Audit Criteria
Set of policies, procedures or requirements used as a reference against which audit evidence is

compared.

3) Audit Evidence
Records, statements of fact or other information, which are relevant to the audit criteria and verifiable

NOTE :Audit evidence may be qualitative or quantitative.

4) Audit Findings
Results of the evaluation of the collected audit evidence against audit criteria .
NOTE: Audit findings can indicate either conformity or nonconformity with audit criteria or
opportunities for improvement
Definitions (Cont.)
5) Audit Conclusion
outcome of an audit ,provided by the audit team after consideration of the audit objectives and all

audit findings.

6) Audit Client
organization or person requesting an audit.

NOTE: The audit client may be the auditee or any other organization which has the regulatory or

contractual right to request an audit.

7) Auditee
Organization/ department/ person being audited
Definitions (Cont.)
8) Auditor
person with the competence to conduct an audit .

9) Audit Team

one or more auditors conducting an audit ,supported if needed by technical experts .

NOTE 1 One auditor of the audit team is appointed as the audit team leader.

NOTE 2 The audit team may include auditors-in-training.


Audit team (3.9) can include:

Audit team Technical


leader Auditors Auditors-in-training experts

1 Guides (3.12)
2 Observers (3.11)
Are not audit team members:
Definitions (Cont.)
10) Technical Expert
person who provides specific knowledge or expertise to the audit team.
NOTE 1: Specific knowledge or expertise is that which relates to the organization, the process
or activity to be audited, or language or culture.

NOTE 2: A technical expert does not act as an auditor in the audit team.

11) Audit Programme


Set of one or more audits planned for a specific time frame and directed towards a specific
purpose.
NOTE: An audit programme includes all activities necessary for planning, organizing and
conducting the audits.
Definitions (Cont.)
12) Audit Plan
Description of the activities and arrangements for an audit

13) Audit Scope


Extent and boundaries of an audit .
NOTE: The audit scope generally includes a description of the physical locations, organizational
units, activities and
processes, as well as the time period covered.

14) Competence

Demonstrated personal attributes and demonstrated ability to apply knowledge and skills.
Definitions (Cont.)

15) Conformity
Fulfillment of a requirement

16) Nonconformity
Non- fulfillment of a requirement

17) Correction
Action to eliminate a detected nonconformity.
NOTE 1 A correction can be made in conjunction with a corrective action.

NOTE 2 A correction can be, for example, rework or re-grade.


Definitions (Cont.)
18) Preventive Action
Action to eliminate the cause of a potential nonconformity or other undesirable potential

situation.

19) Corrective Action


Action to eliminate the cause of a detected nonconformity or other undesirable situation.
NOTE 1 Corrective action is taken to prevent recurrence whereas preventive action is taken to
prevent occurrence.
Audit Records
• Audit Plans
• Audit Reports
• Nonconformity Reports
• Corrective and Preventive Action Reports
• Audit Follow-up Reports.
• Auditor Competence
All the audit records shall be kept by the organization according to the record control process as an
evidence.
Principles of Auditing
1) Ethical Conduct

2) Fair Presentation

3) Due Professional Care

4) Independence

5) Evidence-based Approach

NOTE: Remember the auditor is attempting to prove the system compliance not to set out to fail the

system !
Auditor Personal Attributes
a) Ethical, i.e. fair, truthful, sincere, honest and discreet.
b) Open-minded, i.e. willing to consider alternative ideas or points of view.
c) Diplomatic, i.e. tactful in dealing with people.
d) Observant, i.e. actively aware of physical surroundings and activities.
e) Perceptive, i.e. instinctively aware of and able to understand situations.
f) Versatile, i.e. adjusts readily to different situations.
g) Decisive, i.e. reaches timely conclusions based on logical reasoning and analysis.
h) Self-reliant, i.e. acts and functions independently while interacting effectively with others
Auditor Knowledge and Skills
Auditors should have knowledge and skills in the following areas:
1) Management system and related documents
2) Interaction between the components of the management system
3) Organization situation
4) Applicable laws, regulations and other requirements
5) General business processes
6) Using sampling techniques
7) Information system applicable in the company and security requirements.
8) Terminology
Audit Team

• The audit team consists of team leader and team members

• The team leader shall consider the following when selecting members of his team:

a) Competence of potential auditors.

b) The size, type , product, processes, and the activities being audited.

c) The audit standard, language and the need for expert.

d) Any potential conflict of interest between the audit team members and the auditee.

e) Requirements of clients, certification and accreditation bodies.


Certification & Accreditation Bodies
Certification & Accreditation

• Certification:

Is the confirmation to satisfy the requirements by an organization to be certified against these

requirements

• Accreditation

Is the confirmation to satisfy the certification requirements by the certificate authority (certification

body) to certify an organization


Certification Bodies
• Management system certification bodies are involved to ensure an independent assessment of

company’s compliance with standard requirements.

• The most well-known bodies are SGS (Switzerland) ----- TUV (Germany) ----- Lloyd ( UK) -- Bureau

Veritas, (France),---- Russian Register Certification Association (Russia).


Accreditation Bodies & IAF
• The most well-known Accreditation bodies such as American Accreditation (ANAB) ,Dutch

Accreditation (RVA) supervise activities of certification bodies and use unified approaches that are

detailed in IAF guiding documents and ISO guidelines

• To establish a single certification system in 1998 there was an agreement related to establish the

International Accreditation Forum (IAF) which includes national accreditation bodies .

• Currently, accreditation bodies of the majority of world countries are IAF members to improve the

level of trust to issued certificates


Selecting the Certification Body

• The selection factors including

1) Cost (which can vary widely),

2) Recognition (by your customers, both present and potential),

3) Familiarity with the organization industry (it helps if you and the registrar speak the same

language), and

4) Integrity.
Certification Process
The Certification Process Normative Documents

The Certification Process is based on the following normative documents:

 ISO 19011:2018 – Guidelines for Auditing Management Systems

 ISO/IEC 17021-1:2015 Conformity assessment -- Requirements for bodies providing audit

and certification of management systems

 IAF MD5:20015 Mandatory Document


The Certification Process Steps
The certification process shall include the following steps (by the organization) :
1. Decision by the organization to conform to ISO standard requirement and to seek registration
2. Internal preparation by the organization to achieve conformance
3. Internal determination that the organization has achieved conformance and that the MS is
implemented (internal audit)
4. Selection of accredited ISO standard certification body to certify the organization
5. Preliminary assessment and application review by the certification body
6. Formal MS audit and certification assessment, by the certification body
7. Elimination of nonconformance's preventing certification by the organization
8. Certification awarded by the certification body
Certification Process Steps (Cont.)
• Certification to ISO Standard is not a requirement and organization can use the standard to improve
the way it works without being certified
• Under ISO/IEC 17021-1 the certification process shall include the following activities (by the
certification body) :
1. Review of customer application
2. Initial certification audit including:
2-1 Document Review
2-2 First Stage Audit
2-3 Second Stage Audit
------------------------------------------------------------------------------------------------------------------------
• Surveillance of the Management System --------(Supervision of the certified MS)
• Recertification Audit .
• Additional special audits
1- Review of Customer Application
• During the review of a customer’s application and signing the certification contract the following
aspects shall be considered, analyzed and agreed upon:
1) Standards or other requirements to which the organization is planning to be certified to;
2) The management system application scope (the certification scope)
3) Aspects which impact the certification process (the language, safety, audit terms, location of
audited sites, etc.)
4) Whether there is sufficient information about the organization and its management system to
start the certification process;
5) Whether the certification body can deliver the certification process to the organization;
6) Composition of the audit team
• Selecting auditors into the audit team shall take into account:

a) The organization’s size


b) Number of sites to be audited
c) The audit scope;
d) Is the audit combined, or joint?
• At least one team member shall be experienced in the specific field of the audited organization and If
the certification body has none of such specialists, then the team shall include a technical expert
• Areas of auditors’ competence and their independence from the auditee shall be also taken into
account.
• The certification body shall provide the auditee in advance with information on auditors and technical
experts it included into the team and to agree the team composition.
2- Initial Certification Audit
 The initial certification audit consists of 2 stages.
 Audit team leader makes the 1st and the 2nd stage audit plans which approved by certification
body and agreed with auditee.
 The duration of the initial certification audit depends on the size of the organization and is
determined according to a method used by the certification body.
 For successful objectives achievement of the 1st stage audit, auditor shall work partly on the
client territory.
2-1- Document Review
• Documentation review should be conducted during the 1st and the 2nd stage audit.
• The audit team leader and audit team members are responsible for reviewing the documents.
• During the 1st stage audit documents are reviewed to:

1) Meet and assess documents compliance with the requirements of the applicable standard;
2) Plan the 2nd audit stage.
3) Ensure that any exclusion and the stated certification scope is clear.
• For the 2nd stage audit the documentation review allow to get more information and evidence of
compliance
2-2- First Stage Audit

 Audit plan should be made

 The objectives from the 1st stage audit are :

1. To review the auditee’s management system documentation on the territory of the auditee

2. To prove audit scope

3. To assess how the auditee plans, performs the internal audits and top management review;

and the level of the management system implementation

4. To assess the overall readiness of the organization to the 2nd stage audit.

5. To plan the 2nd audit stage including (the resources needed for the 2nd audit stage - resolve

transportation and accommodation arrangements - safety arrangements).


• Audit client shall be informed about the conclusion and objectives achievement of the 1st stage

audit and preparedness to the 2nd stage audit, including identification of any problems which can

be classified as nonconformities during the 2nd stage audit.


2-3- Second Stage Audit
• The second stage audit is to assess the implementation and the effectiveness of the management
system.
• How the organization ensures continuous improvement of its performance.
• To be sure that problems which were found in previous audit were eliminated.
Conducting the Audit
Audit Techniques

• Forward Trace - An audit which follows the natural flow of a product or service process

• Backward Trace - An audit which traces records back through the system

1. Ask questions
2. Examine objective evidence
3. Observe activities
4. Listen to reactions
5. Record findings
Process Elements Under the Audit

WHAT?
Equipment
WHO?
Infrastructure Competence
Material Responsibility

OUTPUTS
INPUTS
Production
Information or materials PROCESS Performance of
Customer requirements
requirements

HOW?
HOW MANY?
Instructions and
Effectiveness indexes
technologies
Documentation Measurement system

41
Sources of Information
The sources of information may include the following:
a) Interviews with employees and other persons.
b) Observations of activities and the surrounding work environment and conditions.
c) Documents, such as policy, objectives, plans, procedures, standards, instructions, licenses and
permits, specifications, drawings, contracts and orders.
d) Records, such as inspection records, minutes of meetings, audit reports, records of monitoring
programmes and the results of measurements.
e) Data summaries, analyses and performance indicators.
f) Reports
g) Computerized databases and web sites.
Findings
 Major
 Minor
 Audit evidence audit criteria
Observations
 OFI audit findings
 Positive points conformity
nonconformity

opportunity for improvement

Nonconformities and their supporting audit evidence should


be recorded.
Nonconformities may be graded
Non Conformity Reporting
• nonconformity audit findings has to be reported .

• Must be factual.

• Must be understandable and traceable.

• Raise formal notification of any issues at the time of finding.

• The auditee is requested to sign signifying an understanding and acceptance of the non-

compliance.

• Ask the auditee to identify and implement the corrective action.


Non Conformity Reporting(Cont.)

• What is the Problem ?


– describe clearly, concisely and factually
• Why is it a Non Compliance ?
– i.e. against what requirement
• Where did it occur ?
– i.e. which department or activity
• Who ? - avoid apportioning blame
– (i.e. naming individuals)
Nonconformity/finding report
№ 2/15 date 13.04.2016
PART 1:
Auditing department/process: ____Production department № 3_________
Standard ____ISO 9001:2015_________, Standard clause _____8.5.1.c___
Category: MAJOR/ MINOR

PART 2:
NONCONFORMITY/ FINDING:
Organization doesn’t provide control conditions of production (audit evidence)
Records in J-15 «Register of technologies parameter control» register are lacked during 01.10.2015 and
other evidences of parameter Z control ( audit evidence),
that does not conform the requirements 3.8 clause of B11 instruction «Technologies parameter control» ,
according to that, the results of parameter Z control shall be daily registered in J-15 «Register of
technologies parameter control» register (internal requirement).
Nonconformity the requirements 8.5.1.c clause ISO 9001:2015, according to that «The organization shall
the implementation of monitoring and measurement activities at appropriate stages to verify that criteria
for control of processes or outputs, and acceptance criteria for products and services, have been me»
(standard requirement).
Auditor: _____Ivanov I.I.________________ Date: ___13.04.2016
Organization representative: _ Petrov P.P.____ Date: ___13.04.2016
Verify The Corrective Actions
 The audit team leader agrees the deadlines for submitting and implementing corrective actions and

also evaluates whether the proposed corrective action is aimed at eliminating the nonconformity

cause.

 The auditor should verify the effective implementation of the Corrective Actions

 This is to be through:.

• Acceptance of a written response.

• Evaluation of submitted evidence.

• Verification of corrective action at the audit location (Site visit)

• Insuring improving the customer satisfaction if it was related to the customer complaint

• Lab test results.


Corrective Action Responsibilities
Nonconformity Report at
Sign
Raise NCR agreement Categorise Closing
Auditor Meeting
Auditee Lead Auditor Auditor

Propose Accept/Reject Implement


C/A proposed C/A C/A
Auditee Auditor Auditee

Monitor Review Reject action


Complete action
effective action taken or close
taken section
action taken NCR
Auditee Auditee Auditor Auditor

48
Audit Plan
The plan of every audit stage identified in Audit Program shall specify:
• Audit objectives and criteria
• Audit date
• Audit duration
• Location (s) ------ sites and processes to be audited.
• Time of events related to the audit such as opening and closing meetings
• Attendants such as observers and translators
• Auditors
• It should be establish for stage 1and stage 2 audit
Time Action / process/ department Auditors Clause of standard

1st audit day


10.00-10.30 Opening meeting Meeting room
10.30-11.30 Top management: Leadership and commitment, Customer focus, QMS Ivanov I.I. 5.1; 5.1.2; 5.2.1;
policy, responsibility and authority. Continual improvement Petrov P.P. 5.3; 10.3

11.30-13.00 Suppliers department: Purchasing Ivanov I.I. 8.4

11.30-13.00 Marketing department. Customer communication Petrov P.P. 8.2; 9.1.2

13.00-14.00 Break
14.00-15.00 Human recourses Petrov P.P. 5.3; 7.1.2; 7.2;
7.5.3
17.30- 18.00 1st audit day analyze Work place of audit
team

2nd audit day

15.30-16.00 Audit results discussion Work place of audit


team
16.00-16.30 Conclusion meeting Meeting room

50
Audit Checklists
• It is an audit trace record
• Work documents help auditors in collecting objective evidences
• Be built on the basis of audit criteria
• It should be clear
• Be formulated in logical sequence
• Number of questions must be Minimum , but sufficient for audit object
• Checklist advantages :

a)Guide an auditor’s work;

b)Allow to manage auditor’s time

c)Serve as a procedure for collecting objective evidence,

d)Structural approach to audit (Are a structured list of audited objects)

e)Can be an auditor’s record.

f)Memory aid

g)Control audit depth


• Checklist disadvantages :

a)Guide an auditor’s work;

b)Does Not consider concrete situations

c)Risk of doubling information Audited Department Auditor Date


………………………………… …………………. …………….
d)Risk of formal approach
ISO 9001:2015 Question Mark on Comments
Clause Compliance
e)Standard checklist
with
Requirements
7.5.2 How does your department
identify reporting documents?
Appointment of Guides

• Guides and observers may accompany the audit team but they are not its members and shall not
be asked during the audit.
• Guides are appointed by the auditee, shall help the audit team and act on request of the audit team
leader.
• Guides responsibilities may include:
1. To maintain contacts and set up time for interviews;
2. To arrange visits to places within the organization;
3. To ensure that members of the audit team follow safety and information protection rules;
4. To act as a witness on behalf of the auditee;
5. To provide explanations or assistance during data gathering.
Opening Meeting
 Every stage of any audit starts with an opening meeting
 The opening meeting shall be attended by the audit team, auditee’s management, if applicable,
persons responsible for processes (functions) which should be audit.
 Record of attendance
 The meeting shall cover the following topics:

1. Introduction of audit team members;


2. Information about conditions when the audit can be stopped;
3. Information on the system of appeals with regard to the conducted audit or its conclusions;
4. Grading of nonconformities and how such nonconformities will impact the audit conclusion;
5. Confirmation of the following:

Audit scope; the audit plan and other audit-related events, like the closing meeting,

meetings between the audit team and the auditee’s management; Audit methods and

procedures; the resources and equipment needed to the audit team (i.e., transportation,

equipment, personal protection equipment, etc….) , confidentiality , safety , emergency

and security procedures on behalf of the audit team; guides’ availability; and the audit

language
Closing Meeting

 To thank the management and personnel of the auditee for their hospitality and assistance

 To confirm the audit scope, objective and methods.

 To inform about a sample nature of the audit process,

 To confirm confidential treatment of any information obtained during the audit.

 To summarize audit results and present identified facts and comments to raised nonconformities

and observations

 To present the audit team conclusion and recommendations to the auditee’s management
 To agree deadlines for submitting corrective actions for identified nonconformities

 To inform about deadlines of submitting the audit report

 To inform about terms of issuing the certificate and its validity term

 Information about claims and appeals

 To answer questions of the audience.


Audit Report
 The audit team leader is responsible for writing the audit report
 The audit report shall include (or reference) the following:
• Name of certification body.
• Name of organization.
• Type of audit.
• Audit scope , Audit objectives, criteria, audit team, and auditee representatives.
• Dates and location of conducting the audit.
• Audit findings ,
• Audit conclusion and agreed plans of follow-up audits.
 Usually the audit report is to be sent to the management of the certification body and the auditee.
Surveillance Audit

• A surveillance audit is also performed by the certification body to verify continued conformance

with ISO standard and the organization's MS.

• These audits, are conducted at six or twelve month intervals.

• Satisfactory surveillance findings will result in continued registration of the organization.


Special Audits

Certification bodies can present special audits for the MS of a certified organization if:

1. The organization applied to enhance its certification scope (the audit can be combined with

the surveillance audit);

2. There were significant changes in the organization management system;

3. To verify a complaint against the certified organization;

4. There is a follow up audit after having suspended the certificate.


Suspended, Canceled or Scope-Restricted Certificates
• The certification body can suspend the certificate if:

a) The management system of a certified organization shows chronic or significant violations


of certification requirements
b) The certified organization failed to arrange for a surveillance or re-certification audit within
the required timeframe;
c) If the certified organization voluntary requested to suspend its certificate.
Non-constructive Behavior of The Auditee

There are a number of tricks which can be used to take the auditor off the audit trail:
• A LONG DETOUR that the guide leads the auditor to the audit site loosing time;
• SIGHT-SEEING when the guide virtually shows the production to the auditor in all details;
• A LEFT DOCUMENT which has to be fetched from the other end of the site;
• A key figure in the department IS LATE;
• LONG LUNCH BREAK;
• A CLOSED ROOM: the door to the room to be audited is closed and there is no key;

Auditors shall be ready to any such situation and find a way out using the Auditor Code
64

You might also like