SlideShare a Scribd company logo
1 of 22
Download to read offline
1
Guest Speaker
Rashid Hussain
Lead Auditor
www.gcerti.ca
www.gcerti.ca
An Overview of Risk-based Thinking in ISO 9001:2015
G-Certi Inc.- July 3, 2020
2
Welcome to G-Certi Inc.
Please keep social distance and stay safe. Thanks
Introduction of Guest Speaker – Rashid Hussain
Education MSc. TQM, MBA, MBE, B.Com
Designations
• Certified Human Resources Leader (CHRL), HRPA
• Certified Human Resources Professional (CHRP), HRPA
• Certified Quality Auditor (CQA), ASQ
Lead Auditor
Certifications
• QMS (ISO 9001 & IATF 16949)
• EMS (ISO 14001)
• OHS (ISO 45001 & OHSAS 18001)
Experience
• Leadership: President, CEO, Member of Leadership Committees
• Management: Quality, Human Resources, Environment, Health & Safety
• Consulting/Training/Internal Auditing: ISO 9001, IATF 16949, ISO 14001 & ISO 45001
• 3rd Party Auditing: ISO 9001, ISO 14001 & ISO 45001
Volunteer
• Program Chair: ASQ Kitchener Section (2020)
• Mentor: Guelph & District Human Resources Professional Association (GDHRPA)
• Member: Mentorship Committee, GDHRPA
Membership
• Human Resources Professional Association of Canada (HRPA)
• American Society of Quality (ASQ)
3
Learning Outcomes
4
What is Risk?
What is Risk-based-Thinking?
Is there any ISO standard for Risk Management?
What is ISO 31000?
Which clauses of QMS Standards require to identify and
manage the risk?
Why we need to identify and manage the risk?
What are the tools and techniques to identify and manage the
risk?
Can we use Risk-based-Thinking in Auditing?
Basis of QMS
Standards
Risk-based-Thinking
Process Approach
Principles of Quality Management
PDCA Cycle for Continual Improvement
Effectiveness
5
What is Risk?
Risk is defined as the effect of
uncertainty on an expected result, where:
An effect is a deviation from the expected
– positive or negative.
ISO 9000 Definition
6
What is Risk-
based-Thinking?
Risk-based Thinking requires organizations to identify, evaluate,
control and manage risk at stages of QMS i.e. establishment,
implementation, maintenance and improvement
The concept of Risk-based-Thinking was always in ISO 9001 i.e.
Preventive Actions but it was misused
Current revision has more focus on risk management by promoting
Risk-based-Thinking throughout the organization
The main goal of Risk-based-Thinking for an organization is to achieve
conformity and customer satisfaction
Clause 5.1.1 (d) requires leadership to promote the use of process
approach and Risk-based-Thinking throughout the organization
7
Is there any ISO Standard
for Risk Management?
There is no ISO standard for risk management but the
Guidelines.
8
What
is
ISO 31000?
ISO 31000 - Risk
Management Guidelines
First published in 2009 and
revised in 2018
Provides
principles, a framework
and a process for managing
risk
Provides guidance for
internal and external audit
programs
Can be used
by any organization
regardless of its size, activity
or sector
Cannot be used
for certification purpose
9
Which clauses of
QMS Standards
require to identify
and manage the risk?
Which clauses of QMS Standards require to identify and manage the risk?
CLAUSE # RISK MANAGEMENT REQUIREMENTS/EXPECTATIONS
4. Context of the
Organization
•Determine the risks which may affect its ability to achieve it’s intended results
•Organization is required to determine its QMS processes and address its risks and opportunities (4.4.1 f)
5. Leadership •Promote awareness of risk-based thinking
•Determine and address risks and opportunities that can affect product /service conformity
6. Planning Identify risks and opportunities related to QMS performance and take appropriate actions to address them
7. Resources Determine and provide resources to address risks and opportunities
8. Operations Plan, implement and control its processes to address the risks and opportunities
9. Performance
Evaluation
Monitor, measure, analyze and evaluate the effectiveness of actions taken to address risks & opportunities
10. Improvement Correct, prevent or reduce undesired effects to improve the QMS and update risks and opportunities
10
Why we need
to identify and
manage the
risk?
All clauses of ISO 9001:2015 directly or indirectly
requires to apply the Risk-based-Philosophy
The key objective of QMS is conformance to
applicable requirements and Customer Satisfaction
and these objectives can’t be achieved if risk is not
managed through the organization
Requirements of QMS are like a chain and chain always
break from the weakest link
11
What are the
tools and
techniques to
identify and
manage the
risk?
Process Turtle Diagram
Ishikawa Diagram (Cause & Effect Diagram)
SWOT / TOWS Analysis
Failure Mode and Effects Analysis (FMEA)
PESTLE Analysis
Brainstorming
Surveys/Interviews
On-Site Investigations
Using Professional Expertise
Most Common Tools/Techniques
12
Context
of
the
Organization
(4.1) SWOT Analysis - Risk Management Tool
INTERNAL STRENGTHS WEAKNESSES INTERNAL CONTEXT
• Years of Experience
• Business Knowledge
• Financial Strength
• Leveraged Technology
• State of the art Facility
• Patents
• Strong Customer Relationships
• Company Values/Culture
• Time to Market
• Employees don’t trust leadership
• Lack of Diversification
• Narrow Market
• Marketing
• Employee Turnover
• Anticipated Retirements
• Focus is Production not Quality
• Employee Knowledge
Consider issues related to:
• Values
• Culture
• Knowledge
• Performance of the organization
Ref. 4.1, Note 3, ISO 9001:2015
EXTERNAL
OPPORTUNITIES THREATS EXTERNAL CONTEXT
• Available Capacity
• New Markets
• Automation
• Employee Engagement
• High demand for Product
• Apprenticeship Programs
• Prevention based Quality
• Competition
• Changes of Industry Regulations
• Exchange Rate
• Environment
• Expiring patents
Consider issues arising from:
• Legal
• Technological
• Competitive
• Cultural, Social and Economic
Environments etc.
Ref. 4.1, Note 2, ISO 9001:2015
13
4.4/8.5. Turtle Diagram – A Tool for Process Risk Management
With What? (Material/Financial/Other Resources) Opportunities With Who? (Human Resources)
• Infrastructure (Building/Machinery/Utilities/Hardware etc.)
• Gauges (VC/Ink Scale/Lights)
• Software (Cyrious Control/Adobe Creative Suite)
• Work Order
• Master Docket
• Contingency Plans (Overtime, Safety Stock etc.)
• Training
• Effective Manpower Planning
• Preventive Maintenance
• Calibration of Gauges
• Internal Auditing
• Management Reviews
• Effective Communication
• Control of Documented Information
• Production Manager
• Production Supervisor
• Press Operators
• Screen Maker
• Planner
• Color Technician
Inputs Printing Process Output
• Raw Material (Vinyl /Polycarbonate/Polyester)
• Ink
• Screen
• Film
• Printed Product as per Customer Requirements
How? (Methods/Control/Documented Information) Risks Monitoring/Measuring (KPIs/Process Results)
• Documented Information (Procedures/Work Instructions)
• Calibration of Gauges
• Training of Employees
• Infrastructure Failure
• Lack of Training
• Shortage of Manpower
• Interruption of Raw Material Supply
• Expired / Broken Gauges
• Obsolete Documented Information
• Unscheduled Downtime
• Results of Scratch Test
• # of Adjustments (Color Verifications Checks)
• Color Registration (Alignment)
• Audit Nonconformities
• Effectiveness of Corrective Actions
14
Ishikawa Diagram – A Tool for Process Risk Management
Man Machine Material
Risk Specific Controls Risk Specific Controls Risk Specific Controls
• Ineffective Training
• Shortage of Manpower
• Review of Training
Effectiveness
• Overtime
• Multitasking
• Cross Training
• Effective Manpower
Planning
• Machine Breakdown
• Expired / Broken Gauges
• Production Interruption
• Preventive/Predictive
Maintenance
• Effective Calibration
Process
• Safety Stock of Finished
Goods
• Material Shortage
• Interruption of Raw
Material Supply
• Effective Material
Planning
• Safety Stock of Raw
Material
Printing Process
Environment Method Monitoring/Measuring
Risk Specific Controls Risk Specific Controls
• Audit Results
• Effectiveness of Corrective Actions
• Scratch Test Results
• # of Color Adjustments
• Management Reviews
• Effective Communication
• Customer Complaints
• Poor Working Conditions
• Stress/Burn Out
• Surveys
• Work-Life Balance
• Obsolete Documented Information
(Procedures/WIs/Forms etc.)
• Lack of Standardization
• Control of Documented Information
• Standardization
15
4.1 Context of the Organization – Risk Management
# Issue
Internal/
External
Risks
Risk Rating
(H/M/L)
Actions Opportunities
1 Hiring & Retention of
Drivers
Internal • Restricted Growth
• Late Deliveries
L • To provide technological advanced and comfortable fleet
for drivers
• To provide ELD installed fleet for driver's safety and easy
compliance
• To provide job stability
• To provide health care benefits
• To give performance bonus
• Effective Manpower Planning
• Organizational Branding
2 Maintenance of
Certifications
Internal • Customer Dissatisfaction
• Market Reputation
• Low business volume
• Loss of big customers
• Losing market competitiveness
L • Training of employees
• Maintaining/retaining documented information as per
requirement
• Conducting internal audits and inspections
• Consulting services from Safety Consultants
• Competitive advantage
• Attracting new customers and
retaining existing ones
3 Weather External • Late Deliveries
• Late Pickups
• Unsafe Driving Conditions
M • Effective Planning based on weather forecast
• Increased Customer communication on delivery/pick-up
status
• Winter season driving training to all drivers
• SOPs for winter driving
• Safety on Road
• Improved winter season
performance to satisfy the customer
16
4.2 Interested Parties & their Expectations – Risk Management
# Interested
Parties
Expectations Risks Risk Rating
(H/M/L)
Actions Opportunities
1. Customers • Services quality
• On-time delivery
• Response time to
enquiries and complaints
• Compliance with applicable
regulations
• Maintenance of required
certifications
• Late Deliveries
• Penalties
• Loss of business
• Customer Dissatisfaction
M
• To implement Quality Management System based on the
requirements of ISO 9001:2015
• Maintain compliance certifications
• To train office employees and drivers on compliance
requirements
• To improve level of communication with customers
• After-hours services
• Repeated & dedicated business from
existing customers
• Referrals
• New business from existing
customers
2. Suppliers • Clear specification of
products & services
• On time payment
• Products and Services
not meeting requirements
• Late Deliveries
L
• To provide clear specifications of products and services to all
suppliers
• To provide training to Owner Operators and develop other
suppliers
• To pay on time as per terms and conditions
• Dedicated services
3. Regulators • Compliance with applicable
requirements
• Market Reputation
• Fines/Penalties
• Shut Down
M
• To hire services of experienced compliance consultants
• To trained employees on applicable regulations
• Good Market Reputation
• Business Continuity
4. Employees
5. Leadership
17
Can we use
Risk-based-
Thinking in
Auditing?
There is no ISO standard for Management System
Auditing
There are Guidelines (ISO 19011) for Management
System Auditing mainly used for 3rd Party Auditing
but can be used for 1st & 2nd Party Auditing as well
ISO 19011 requires ISO Registrars to use Risk-based-
Thinking in 3rd party auditing
We must use Risk-based-Thinking for conducting
internal audits to demonstrate conformance
18
4.4./9.2 Turtle Diagram – A Tool for Process Risk Management
With What? (Material/Financial/Other Resources) Opportunities With Who? (Human Resources)
• Infrastructure (Hardware, Software, Office etc.)
• Time
• Resources for Audit (Financial/Materials/Others etc.)
• Use of Risk-based-Thinking in Auditing
• Effective Audit Planning
• Effective Training
• Maintaining adequate number of competent Auditors
• Qualified Auditors
• Lead Auditor
• Auditee
Inputs Internal Auditing Process Output
• Audit Plan /Schedule
• Audit Criteria (Req of QMS, ISO 9001 and Interested
Parties)
• Risks & Opportunities
• Importance and Criticality of Processes
• Changes affecting the Organization
• Results from previous audits
• Internal and external performance trends
• Customer complaints
• Audit Report
• Summary of Audit Findings
• Non-Conformity Report (if any)
How? (Methods/Control/Documented Information) Risks Monitoring/Measuring (KPIs/Process Results)
• Audit Planning
• Documented Information (Policies/Procedures)
• Audit Checklists
• Audit Frequency
• Audit Methods (Interviews, Observations and Review of
Documented Information)
• Poor Audit Planning (not based on Risk)
• Ineffective Audit Training
• Auditor’s Competence
• Availability of Competent Auditors
• Infrastructure Failure
• Lack of Resources
• Inadequate Frequency
• Internal/External Audit Results
• Timely completion of audits as per Schedule
• Effectiveness of CA
• # of IANCRs
• Maintenance of ISO 9001 Certification
19
Risk-based-
Thinking in
Auditing
Conducting more frequent audits in following circumstances may
help to reduce the risk and ensure product/service conformity
and customer satisfaction:
• QMS is new in the organization
• Process(s) is complex
• New product/service is launched
• Areas with more identified risks or nonconformities
• Areas with major nonconformities
• Areas where corrective actions were not effective
• Processes which are critical for product/service conformity
• Areas with more customer complaints and formal
rejections
Some Best
Practices
20
I wish you to stay
Safe.
21
22
Sorry, I couldn’t ask any question.
No Worries! Email at info@gcerti.ca

More Related Content

Similar to Risk-Management-in-ISO-9001.pdf

Internal Audit Best Practices for Safety, Environment, and Quality Audits
Internal Audit Best Practices for Safety, Environment, and Quality AuditsInternal Audit Best Practices for Safety, Environment, and Quality Audits
Internal Audit Best Practices for Safety, Environment, and Quality AuditsNimonik
 
Iso 9001 2015 Quality Transition ISO Consultant Implementation Certification...
Iso 9001 2015 Quality Transition  ISO Consultant Implementation Certification...Iso 9001 2015 Quality Transition  ISO Consultant Implementation Certification...
Iso 9001 2015 Quality Transition ISO Consultant Implementation Certification...Robert Jasper
 
Six Sigma Quality and IT Governance
Six Sigma Quality and IT GovernanceSix Sigma Quality and IT Governance
Six Sigma Quality and IT Governancelmgangi
 
Presentation Quality Management System.ppsx
Presentation Quality Management System.ppsxPresentation Quality Management System.ppsx
Presentation Quality Management System.ppsxSoniAditiaAbdullah1
 
ISO 9001 ultimate guide to the core quality management standard.pdf
ISO 9001 ultimate guide to the core quality management standard.pdfISO 9001 ultimate guide to the core quality management standard.pdf
ISO 9001 ultimate guide to the core quality management standard.pdfFaiz Alkhawlani
 
7 Key Elements for Operation Quality Improvement
7 Key Elements for Operation Quality Improvement7 Key Elements for Operation Quality Improvement
7 Key Elements for Operation Quality ImprovementQuEST Forum
 
ISO 90012008 Understanding and Internal Auditing.ppt
ISO 90012008 Understanding and Internal Auditing.pptISO 90012008 Understanding and Internal Auditing.ppt
ISO 90012008 Understanding and Internal Auditing.pptFirozKhan158275
 
Clc 5 day_licg_ver1
Clc 5 day_licg_ver1Clc 5 day_licg_ver1
Clc 5 day_licg_ver1AshokeHTyagi
 
Session 3B Quality Assurance and Building Effective Oversight System - Paul H...
Session 3B Quality Assurance and Building Effective Oversight System - Paul H...Session 3B Quality Assurance and Building Effective Oversight System - Paul H...
Session 3B Quality Assurance and Building Effective Oversight System - Paul H...International Federation of Accountants
 
S.Baktha-QA-Process-Audits-Security-Services- 25 Nov 2016 SR
S.Baktha-QA-Process-Audits-Security-Services- 25 Nov 2016 SRS.Baktha-QA-Process-Audits-Security-Services- 25 Nov 2016 SR
S.Baktha-QA-Process-Audits-Security-Services- 25 Nov 2016 SRBakthavatchalam Subramani
 
Certification Body Approach to ISO 9001:2015 by NQA
Certification Body Approach to ISO 9001:2015 by NQACertification Body Approach to ISO 9001:2015 by NQA
Certification Body Approach to ISO 9001:2015 by NQANQA
 
QMS_ISO 9001_Awareness by Management.pptx
QMS_ISO 9001_Awareness by Management.pptxQMS_ISO 9001_Awareness by Management.pptx
QMS_ISO 9001_Awareness by Management.pptxButchEnalpe
 
ISO 9001 2015 Overview presentation
ISO 9001 2015 Overview presentation ISO 9001 2015 Overview presentation
ISO 9001 2015 Overview presentation Govind Ramu
 
Game Changing Quality Strategies that Drive Organizational Excellence
Game Changing Quality Strategies that Drive Organizational ExcellenceGame Changing Quality Strategies that Drive Organizational Excellence
Game Changing Quality Strategies that Drive Organizational Excellencekushshah
 
Risk Based Thinking ISO 9001 Presentation.pdf
Risk Based Thinking ISO 9001 Presentation.pdfRisk Based Thinking ISO 9001 Presentation.pdf
Risk Based Thinking ISO 9001 Presentation.pdfHimanshuMishra203021
 
ISO 45001 018 . 2018 م.71-مبادرة#تواصل_تطوير-د.محمد عبدالمجيد-التعريف بمتطلبا...
ISO 45001 018 . 2018 م.71-مبادرة#تواصل_تطوير-د.محمد عبدالمجيد-التعريف بمتطلبا...ISO 45001 018 . 2018 م.71-مبادرة#تواصل_تطوير-د.محمد عبدالمجيد-التعريف بمتطلبا...
ISO 45001 018 . 2018 م.71-مبادرة#تواصل_تطوير-د.محمد عبدالمجيد-التعريف بمتطلبا...Egyptian Engineers Association
 

Similar to Risk-Management-in-ISO-9001.pdf (20)

Internal Audit Best Practices for Safety, Environment, and Quality Audits
Internal Audit Best Practices for Safety, Environment, and Quality AuditsInternal Audit Best Practices for Safety, Environment, and Quality Audits
Internal Audit Best Practices for Safety, Environment, and Quality Audits
 
Iso 9001 2015 Quality Transition ISO Consultant Implementation Certification...
Iso 9001 2015 Quality Transition  ISO Consultant Implementation Certification...Iso 9001 2015 Quality Transition  ISO Consultant Implementation Certification...
Iso 9001 2015 Quality Transition ISO Consultant Implementation Certification...
 
Six Sigma Quality and IT Governance
Six Sigma Quality and IT GovernanceSix Sigma Quality and IT Governance
Six Sigma Quality and IT Governance
 
Presentation Quality Management System.ppsx
Presentation Quality Management System.ppsxPresentation Quality Management System.ppsx
Presentation Quality Management System.ppsx
 
ISO 9001 ultimate guide to the core quality management standard.pdf
ISO 9001 ultimate guide to the core quality management standard.pdfISO 9001 ultimate guide to the core quality management standard.pdf
ISO 9001 ultimate guide to the core quality management standard.pdf
 
7 Key Elements for Operation Quality Improvement
7 Key Elements for Operation Quality Improvement7 Key Elements for Operation Quality Improvement
7 Key Elements for Operation Quality Improvement
 
ISO 90012008 Understanding and Internal Auditing.ppt
ISO 90012008 Understanding and Internal Auditing.pptISO 90012008 Understanding and Internal Auditing.ppt
ISO 90012008 Understanding and Internal Auditing.ppt
 
Clc 5 day_licg_ver1
Clc 5 day_licg_ver1Clc 5 day_licg_ver1
Clc 5 day_licg_ver1
 
Rashmi Nagaraja_QA
Rashmi Nagaraja_QA Rashmi Nagaraja_QA
Rashmi Nagaraja_QA
 
Session 3B Quality Assurance and Building Effective Oversight System - Paul H...
Session 3B Quality Assurance and Building Effective Oversight System - Paul H...Session 3B Quality Assurance and Building Effective Oversight System - Paul H...
Session 3B Quality Assurance and Building Effective Oversight System - Paul H...
 
S.Baktha-QA-Process-Audits-Security-Services- 25 Nov 2016 SR
S.Baktha-QA-Process-Audits-Security-Services- 25 Nov 2016 SRS.Baktha-QA-Process-Audits-Security-Services- 25 Nov 2016 SR
S.Baktha-QA-Process-Audits-Security-Services- 25 Nov 2016 SR
 
Certification Body Approach to ISO 9001:2015 by NQA
Certification Body Approach to ISO 9001:2015 by NQACertification Body Approach to ISO 9001:2015 by NQA
Certification Body Approach to ISO 9001:2015 by NQA
 
QMS_ISO 9001_Awareness by Management.pptx
QMS_ISO 9001_Awareness by Management.pptxQMS_ISO 9001_Awareness by Management.pptx
QMS_ISO 9001_Awareness by Management.pptx
 
The Essential Experience for CAEs - Audit Committee Need for Insight
The Essential Experience for CAEs - Audit Committee Need for InsightThe Essential Experience for CAEs - Audit Committee Need for Insight
The Essential Experience for CAEs - Audit Committee Need for Insight
 
Elevating IA
Elevating IAElevating IA
Elevating IA
 
ISO9001-2015 3-25-19
ISO9001-2015   3-25-19ISO9001-2015   3-25-19
ISO9001-2015 3-25-19
 
ISO 9001 2015 Overview presentation
ISO 9001 2015 Overview presentation ISO 9001 2015 Overview presentation
ISO 9001 2015 Overview presentation
 
Game Changing Quality Strategies that Drive Organizational Excellence
Game Changing Quality Strategies that Drive Organizational ExcellenceGame Changing Quality Strategies that Drive Organizational Excellence
Game Changing Quality Strategies that Drive Organizational Excellence
 
Risk Based Thinking ISO 9001 Presentation.pdf
Risk Based Thinking ISO 9001 Presentation.pdfRisk Based Thinking ISO 9001 Presentation.pdf
Risk Based Thinking ISO 9001 Presentation.pdf
 
ISO 45001 018 . 2018 م.71-مبادرة#تواصل_تطوير-د.محمد عبدالمجيد-التعريف بمتطلبا...
ISO 45001 018 . 2018 م.71-مبادرة#تواصل_تطوير-د.محمد عبدالمجيد-التعريف بمتطلبا...ISO 45001 018 . 2018 م.71-مبادرة#تواصل_تطوير-د.محمد عبدالمجيد-التعريف بمتطلبا...
ISO 45001 018 . 2018 م.71-مبادرة#تواصل_تطوير-د.محمد عبدالمجيد-التعريف بمتطلبا...
 

Recently uploaded

定制昆士兰大学毕业证(本硕)UQ学位证书原版一比一
定制昆士兰大学毕业证(本硕)UQ学位证书原版一比一定制昆士兰大学毕业证(本硕)UQ学位证书原版一比一
定制昆士兰大学毕业证(本硕)UQ学位证书原版一比一fjjhfuubb
 
(办理学位证)(Toledo毕业证)托莱多大学毕业证成绩单修改留信学历认证原版一模一样
(办理学位证)(Toledo毕业证)托莱多大学毕业证成绩单修改留信学历认证原版一模一样(办理学位证)(Toledo毕业证)托莱多大学毕业证成绩单修改留信学历认证原版一模一样
(办理学位证)(Toledo毕业证)托莱多大学毕业证成绩单修改留信学历认证原版一模一样gfghbihg
 
如何办理(UQ毕业证书)昆士兰大学毕业证毕业证成绩单原版一比一
如何办理(UQ毕业证书)昆士兰大学毕业证毕业证成绩单原版一比一如何办理(UQ毕业证书)昆士兰大学毕业证毕业证成绩单原版一比一
如何办理(UQ毕业证书)昆士兰大学毕业证毕业证成绩单原版一比一hnfusn
 
2024 TOP 10 most fuel-efficient vehicles according to the US agency
2024 TOP 10 most fuel-efficient vehicles according to the US agency2024 TOP 10 most fuel-efficient vehicles according to the US agency
2024 TOP 10 most fuel-efficient vehicles according to the US agencyHyundai Motor Group
 
2024 WRC Hyundai World Rally Team’s i20 N Rally1 Hybrid
2024 WRC Hyundai World Rally Team’s i20 N Rally1 Hybrid2024 WRC Hyundai World Rally Team’s i20 N Rally1 Hybrid
2024 WRC Hyundai World Rally Team’s i20 N Rally1 HybridHyundai Motor Group
 
call girls in Jama Masjid (DELHI) 🔝 >༒9953330565🔝 genuine Escort Service 🔝✔️✔️
call girls in Jama Masjid (DELHI) 🔝 >༒9953330565🔝 genuine Escort Service 🔝✔️✔️call girls in Jama Masjid (DELHI) 🔝 >༒9953330565🔝 genuine Escort Service 🔝✔️✔️
call girls in Jama Masjid (DELHI) 🔝 >༒9953330565🔝 genuine Escort Service 🔝✔️✔️9953056974 Low Rate Call Girls In Saket, Delhi NCR
 
Call Girls Vastrapur 7397865700 Ridhima Hire Me Full Night
Call Girls Vastrapur 7397865700 Ridhima Hire Me Full NightCall Girls Vastrapur 7397865700 Ridhima Hire Me Full Night
Call Girls Vastrapur 7397865700 Ridhima Hire Me Full Nightssuser7cb4ff
 
(8264348440) 🔝 Call Girls In Shaheen Bagh 🔝 Delhi NCR
(8264348440) 🔝 Call Girls In Shaheen Bagh 🔝 Delhi NCR(8264348440) 🔝 Call Girls In Shaheen Bagh 🔝 Delhi NCR
(8264348440) 🔝 Call Girls In Shaheen Bagh 🔝 Delhi NCRsoniya singh
 
办理学位证(MLU文凭证书)哈勒 维滕贝格大学毕业证成绩单原版一模一样
办理学位证(MLU文凭证书)哈勒 维滕贝格大学毕业证成绩单原版一模一样办理学位证(MLU文凭证书)哈勒 维滕贝格大学毕业证成绩单原版一模一样
办理学位证(MLU文凭证书)哈勒 维滕贝格大学毕业证成绩单原版一模一样umasea
 
定制多伦多大学毕业证(UofT毕业证)成绩单(学位证)原版一比一
定制多伦多大学毕业证(UofT毕业证)成绩单(学位证)原版一比一定制多伦多大学毕业证(UofT毕业证)成绩单(学位证)原版一比一
定制多伦多大学毕业证(UofT毕业证)成绩单(学位证)原版一比一meq5nzfnk
 
UNOSAFE ELEVATOR PRIVATE LTD BANGALORE BROUCHER
UNOSAFE ELEVATOR PRIVATE LTD BANGALORE BROUCHERUNOSAFE ELEVATOR PRIVATE LTD BANGALORE BROUCHER
UNOSAFE ELEVATOR PRIVATE LTD BANGALORE BROUCHERunosafeads
 
What Causes DPF Failure In VW Golf Cars & How Can They Be Prevented
What Causes DPF Failure In VW Golf Cars & How Can They Be PreventedWhat Causes DPF Failure In VW Golf Cars & How Can They Be Prevented
What Causes DPF Failure In VW Golf Cars & How Can They Be PreventedAutobahn Automotive Service
 
Digamma - CertiCon Team Skills and Qualifications
Digamma - CertiCon Team Skills and QualificationsDigamma - CertiCon Team Skills and Qualifications
Digamma - CertiCon Team Skills and QualificationsMihajloManjak
 
VIP Kolkata Call Girl Kasba 👉 8250192130 Available With Room
VIP Kolkata Call Girl Kasba 👉 8250192130  Available With RoomVIP Kolkata Call Girl Kasba 👉 8250192130  Available With Room
VIP Kolkata Call Girl Kasba 👉 8250192130 Available With Roomdivyansh0kumar0
 
Beautiful Vip Call Girls Punjabi Bagh 9711199012 Call /Whatsapps
Beautiful Vip  Call Girls Punjabi Bagh 9711199012 Call /WhatsappsBeautiful Vip  Call Girls Punjabi Bagh 9711199012 Call /Whatsapps
Beautiful Vip Call Girls Punjabi Bagh 9711199012 Call /Whatsappssapnasaifi408
 
BLUE VEHICLES the kids picture show 2024
BLUE VEHICLES the kids picture show 2024BLUE VEHICLES the kids picture show 2024
BLUE VEHICLES the kids picture show 2024AHOhOops1
 
( Best ) Genuine Call Girls In Mandi House =DELHI-| 8377087607
( Best ) Genuine Call Girls In Mandi House =DELHI-| 8377087607( Best ) Genuine Call Girls In Mandi House =DELHI-| 8377087607
( Best ) Genuine Call Girls In Mandi House =DELHI-| 8377087607dollysharma2066
 
原版工艺美国普林斯顿大学毕业证Princeton毕业证成绩单修改留信学历认证
原版工艺美国普林斯顿大学毕业证Princeton毕业证成绩单修改留信学历认证原版工艺美国普林斯顿大学毕业证Princeton毕业证成绩单修改留信学历认证
原版工艺美国普林斯顿大学毕业证Princeton毕业证成绩单修改留信学历认证jjrehjwj11gg
 
FULL ENJOY - 9953040155 Call Girls in Sector 61 | Noida
FULL ENJOY - 9953040155 Call Girls in Sector 61 | NoidaFULL ENJOY - 9953040155 Call Girls in Sector 61 | Noida
FULL ENJOY - 9953040155 Call Girls in Sector 61 | NoidaMalviyaNagarCallGirl
 
Not Sure About VW EGR Valve Health Look For These Symptoms
Not Sure About VW EGR Valve Health Look For These SymptomsNot Sure About VW EGR Valve Health Look For These Symptoms
Not Sure About VW EGR Valve Health Look For These SymptomsFifth Gear Automotive
 

Recently uploaded (20)

定制昆士兰大学毕业证(本硕)UQ学位证书原版一比一
定制昆士兰大学毕业证(本硕)UQ学位证书原版一比一定制昆士兰大学毕业证(本硕)UQ学位证书原版一比一
定制昆士兰大学毕业证(本硕)UQ学位证书原版一比一
 
(办理学位证)(Toledo毕业证)托莱多大学毕业证成绩单修改留信学历认证原版一模一样
(办理学位证)(Toledo毕业证)托莱多大学毕业证成绩单修改留信学历认证原版一模一样(办理学位证)(Toledo毕业证)托莱多大学毕业证成绩单修改留信学历认证原版一模一样
(办理学位证)(Toledo毕业证)托莱多大学毕业证成绩单修改留信学历认证原版一模一样
 
如何办理(UQ毕业证书)昆士兰大学毕业证毕业证成绩单原版一比一
如何办理(UQ毕业证书)昆士兰大学毕业证毕业证成绩单原版一比一如何办理(UQ毕业证书)昆士兰大学毕业证毕业证成绩单原版一比一
如何办理(UQ毕业证书)昆士兰大学毕业证毕业证成绩单原版一比一
 
2024 TOP 10 most fuel-efficient vehicles according to the US agency
2024 TOP 10 most fuel-efficient vehicles according to the US agency2024 TOP 10 most fuel-efficient vehicles according to the US agency
2024 TOP 10 most fuel-efficient vehicles according to the US agency
 
2024 WRC Hyundai World Rally Team’s i20 N Rally1 Hybrid
2024 WRC Hyundai World Rally Team’s i20 N Rally1 Hybrid2024 WRC Hyundai World Rally Team’s i20 N Rally1 Hybrid
2024 WRC Hyundai World Rally Team’s i20 N Rally1 Hybrid
 
call girls in Jama Masjid (DELHI) 🔝 >༒9953330565🔝 genuine Escort Service 🔝✔️✔️
call girls in Jama Masjid (DELHI) 🔝 >༒9953330565🔝 genuine Escort Service 🔝✔️✔️call girls in Jama Masjid (DELHI) 🔝 >༒9953330565🔝 genuine Escort Service 🔝✔️✔️
call girls in Jama Masjid (DELHI) 🔝 >༒9953330565🔝 genuine Escort Service 🔝✔️✔️
 
Call Girls Vastrapur 7397865700 Ridhima Hire Me Full Night
Call Girls Vastrapur 7397865700 Ridhima Hire Me Full NightCall Girls Vastrapur 7397865700 Ridhima Hire Me Full Night
Call Girls Vastrapur 7397865700 Ridhima Hire Me Full Night
 
(8264348440) 🔝 Call Girls In Shaheen Bagh 🔝 Delhi NCR
(8264348440) 🔝 Call Girls In Shaheen Bagh 🔝 Delhi NCR(8264348440) 🔝 Call Girls In Shaheen Bagh 🔝 Delhi NCR
(8264348440) 🔝 Call Girls In Shaheen Bagh 🔝 Delhi NCR
 
办理学位证(MLU文凭证书)哈勒 维滕贝格大学毕业证成绩单原版一模一样
办理学位证(MLU文凭证书)哈勒 维滕贝格大学毕业证成绩单原版一模一样办理学位证(MLU文凭证书)哈勒 维滕贝格大学毕业证成绩单原版一模一样
办理学位证(MLU文凭证书)哈勒 维滕贝格大学毕业证成绩单原版一模一样
 
定制多伦多大学毕业证(UofT毕业证)成绩单(学位证)原版一比一
定制多伦多大学毕业证(UofT毕业证)成绩单(学位证)原版一比一定制多伦多大学毕业证(UofT毕业证)成绩单(学位证)原版一比一
定制多伦多大学毕业证(UofT毕业证)成绩单(学位证)原版一比一
 
UNOSAFE ELEVATOR PRIVATE LTD BANGALORE BROUCHER
UNOSAFE ELEVATOR PRIVATE LTD BANGALORE BROUCHERUNOSAFE ELEVATOR PRIVATE LTD BANGALORE BROUCHER
UNOSAFE ELEVATOR PRIVATE LTD BANGALORE BROUCHER
 
What Causes DPF Failure In VW Golf Cars & How Can They Be Prevented
What Causes DPF Failure In VW Golf Cars & How Can They Be PreventedWhat Causes DPF Failure In VW Golf Cars & How Can They Be Prevented
What Causes DPF Failure In VW Golf Cars & How Can They Be Prevented
 
Digamma - CertiCon Team Skills and Qualifications
Digamma - CertiCon Team Skills and QualificationsDigamma - CertiCon Team Skills and Qualifications
Digamma - CertiCon Team Skills and Qualifications
 
VIP Kolkata Call Girl Kasba 👉 8250192130 Available With Room
VIP Kolkata Call Girl Kasba 👉 8250192130  Available With RoomVIP Kolkata Call Girl Kasba 👉 8250192130  Available With Room
VIP Kolkata Call Girl Kasba 👉 8250192130 Available With Room
 
Beautiful Vip Call Girls Punjabi Bagh 9711199012 Call /Whatsapps
Beautiful Vip  Call Girls Punjabi Bagh 9711199012 Call /WhatsappsBeautiful Vip  Call Girls Punjabi Bagh 9711199012 Call /Whatsapps
Beautiful Vip Call Girls Punjabi Bagh 9711199012 Call /Whatsapps
 
BLUE VEHICLES the kids picture show 2024
BLUE VEHICLES the kids picture show 2024BLUE VEHICLES the kids picture show 2024
BLUE VEHICLES the kids picture show 2024
 
( Best ) Genuine Call Girls In Mandi House =DELHI-| 8377087607
( Best ) Genuine Call Girls In Mandi House =DELHI-| 8377087607( Best ) Genuine Call Girls In Mandi House =DELHI-| 8377087607
( Best ) Genuine Call Girls In Mandi House =DELHI-| 8377087607
 
原版工艺美国普林斯顿大学毕业证Princeton毕业证成绩单修改留信学历认证
原版工艺美国普林斯顿大学毕业证Princeton毕业证成绩单修改留信学历认证原版工艺美国普林斯顿大学毕业证Princeton毕业证成绩单修改留信学历认证
原版工艺美国普林斯顿大学毕业证Princeton毕业证成绩单修改留信学历认证
 
FULL ENJOY - 9953040155 Call Girls in Sector 61 | Noida
FULL ENJOY - 9953040155 Call Girls in Sector 61 | NoidaFULL ENJOY - 9953040155 Call Girls in Sector 61 | Noida
FULL ENJOY - 9953040155 Call Girls in Sector 61 | Noida
 
Not Sure About VW EGR Valve Health Look For These Symptoms
Not Sure About VW EGR Valve Health Look For These SymptomsNot Sure About VW EGR Valve Health Look For These Symptoms
Not Sure About VW EGR Valve Health Look For These Symptoms
 

Risk-Management-in-ISO-9001.pdf

  • 1. 1 Guest Speaker Rashid Hussain Lead Auditor www.gcerti.ca www.gcerti.ca An Overview of Risk-based Thinking in ISO 9001:2015 G-Certi Inc.- July 3, 2020
  • 2. 2 Welcome to G-Certi Inc. Please keep social distance and stay safe. Thanks
  • 3. Introduction of Guest Speaker – Rashid Hussain Education MSc. TQM, MBA, MBE, B.Com Designations • Certified Human Resources Leader (CHRL), HRPA • Certified Human Resources Professional (CHRP), HRPA • Certified Quality Auditor (CQA), ASQ Lead Auditor Certifications • QMS (ISO 9001 & IATF 16949) • EMS (ISO 14001) • OHS (ISO 45001 & OHSAS 18001) Experience • Leadership: President, CEO, Member of Leadership Committees • Management: Quality, Human Resources, Environment, Health & Safety • Consulting/Training/Internal Auditing: ISO 9001, IATF 16949, ISO 14001 & ISO 45001 • 3rd Party Auditing: ISO 9001, ISO 14001 & ISO 45001 Volunteer • Program Chair: ASQ Kitchener Section (2020) • Mentor: Guelph & District Human Resources Professional Association (GDHRPA) • Member: Mentorship Committee, GDHRPA Membership • Human Resources Professional Association of Canada (HRPA) • American Society of Quality (ASQ) 3
  • 4. Learning Outcomes 4 What is Risk? What is Risk-based-Thinking? Is there any ISO standard for Risk Management? What is ISO 31000? Which clauses of QMS Standards require to identify and manage the risk? Why we need to identify and manage the risk? What are the tools and techniques to identify and manage the risk? Can we use Risk-based-Thinking in Auditing?
  • 5. Basis of QMS Standards Risk-based-Thinking Process Approach Principles of Quality Management PDCA Cycle for Continual Improvement Effectiveness 5
  • 6. What is Risk? Risk is defined as the effect of uncertainty on an expected result, where: An effect is a deviation from the expected – positive or negative. ISO 9000 Definition 6
  • 7. What is Risk- based-Thinking? Risk-based Thinking requires organizations to identify, evaluate, control and manage risk at stages of QMS i.e. establishment, implementation, maintenance and improvement The concept of Risk-based-Thinking was always in ISO 9001 i.e. Preventive Actions but it was misused Current revision has more focus on risk management by promoting Risk-based-Thinking throughout the organization The main goal of Risk-based-Thinking for an organization is to achieve conformity and customer satisfaction Clause 5.1.1 (d) requires leadership to promote the use of process approach and Risk-based-Thinking throughout the organization 7
  • 8. Is there any ISO Standard for Risk Management? There is no ISO standard for risk management but the Guidelines. 8
  • 9. What is ISO 31000? ISO 31000 - Risk Management Guidelines First published in 2009 and revised in 2018 Provides principles, a framework and a process for managing risk Provides guidance for internal and external audit programs Can be used by any organization regardless of its size, activity or sector Cannot be used for certification purpose 9
  • 10. Which clauses of QMS Standards require to identify and manage the risk? Which clauses of QMS Standards require to identify and manage the risk? CLAUSE # RISK MANAGEMENT REQUIREMENTS/EXPECTATIONS 4. Context of the Organization •Determine the risks which may affect its ability to achieve it’s intended results •Organization is required to determine its QMS processes and address its risks and opportunities (4.4.1 f) 5. Leadership •Promote awareness of risk-based thinking •Determine and address risks and opportunities that can affect product /service conformity 6. Planning Identify risks and opportunities related to QMS performance and take appropriate actions to address them 7. Resources Determine and provide resources to address risks and opportunities 8. Operations Plan, implement and control its processes to address the risks and opportunities 9. Performance Evaluation Monitor, measure, analyze and evaluate the effectiveness of actions taken to address risks & opportunities 10. Improvement Correct, prevent or reduce undesired effects to improve the QMS and update risks and opportunities 10
  • 11. Why we need to identify and manage the risk? All clauses of ISO 9001:2015 directly or indirectly requires to apply the Risk-based-Philosophy The key objective of QMS is conformance to applicable requirements and Customer Satisfaction and these objectives can’t be achieved if risk is not managed through the organization Requirements of QMS are like a chain and chain always break from the weakest link 11
  • 12. What are the tools and techniques to identify and manage the risk? Process Turtle Diagram Ishikawa Diagram (Cause & Effect Diagram) SWOT / TOWS Analysis Failure Mode and Effects Analysis (FMEA) PESTLE Analysis Brainstorming Surveys/Interviews On-Site Investigations Using Professional Expertise Most Common Tools/Techniques 12
  • 13. Context of the Organization (4.1) SWOT Analysis - Risk Management Tool INTERNAL STRENGTHS WEAKNESSES INTERNAL CONTEXT • Years of Experience • Business Knowledge • Financial Strength • Leveraged Technology • State of the art Facility • Patents • Strong Customer Relationships • Company Values/Culture • Time to Market • Employees don’t trust leadership • Lack of Diversification • Narrow Market • Marketing • Employee Turnover • Anticipated Retirements • Focus is Production not Quality • Employee Knowledge Consider issues related to: • Values • Culture • Knowledge • Performance of the organization Ref. 4.1, Note 3, ISO 9001:2015 EXTERNAL OPPORTUNITIES THREATS EXTERNAL CONTEXT • Available Capacity • New Markets • Automation • Employee Engagement • High demand for Product • Apprenticeship Programs • Prevention based Quality • Competition • Changes of Industry Regulations • Exchange Rate • Environment • Expiring patents Consider issues arising from: • Legal • Technological • Competitive • Cultural, Social and Economic Environments etc. Ref. 4.1, Note 2, ISO 9001:2015 13
  • 14. 4.4/8.5. Turtle Diagram – A Tool for Process Risk Management With What? (Material/Financial/Other Resources) Opportunities With Who? (Human Resources) • Infrastructure (Building/Machinery/Utilities/Hardware etc.) • Gauges (VC/Ink Scale/Lights) • Software (Cyrious Control/Adobe Creative Suite) • Work Order • Master Docket • Contingency Plans (Overtime, Safety Stock etc.) • Training • Effective Manpower Planning • Preventive Maintenance • Calibration of Gauges • Internal Auditing • Management Reviews • Effective Communication • Control of Documented Information • Production Manager • Production Supervisor • Press Operators • Screen Maker • Planner • Color Technician Inputs Printing Process Output • Raw Material (Vinyl /Polycarbonate/Polyester) • Ink • Screen • Film • Printed Product as per Customer Requirements How? (Methods/Control/Documented Information) Risks Monitoring/Measuring (KPIs/Process Results) • Documented Information (Procedures/Work Instructions) • Calibration of Gauges • Training of Employees • Infrastructure Failure • Lack of Training • Shortage of Manpower • Interruption of Raw Material Supply • Expired / Broken Gauges • Obsolete Documented Information • Unscheduled Downtime • Results of Scratch Test • # of Adjustments (Color Verifications Checks) • Color Registration (Alignment) • Audit Nonconformities • Effectiveness of Corrective Actions 14
  • 15. Ishikawa Diagram – A Tool for Process Risk Management Man Machine Material Risk Specific Controls Risk Specific Controls Risk Specific Controls • Ineffective Training • Shortage of Manpower • Review of Training Effectiveness • Overtime • Multitasking • Cross Training • Effective Manpower Planning • Machine Breakdown • Expired / Broken Gauges • Production Interruption • Preventive/Predictive Maintenance • Effective Calibration Process • Safety Stock of Finished Goods • Material Shortage • Interruption of Raw Material Supply • Effective Material Planning • Safety Stock of Raw Material Printing Process Environment Method Monitoring/Measuring Risk Specific Controls Risk Specific Controls • Audit Results • Effectiveness of Corrective Actions • Scratch Test Results • # of Color Adjustments • Management Reviews • Effective Communication • Customer Complaints • Poor Working Conditions • Stress/Burn Out • Surveys • Work-Life Balance • Obsolete Documented Information (Procedures/WIs/Forms etc.) • Lack of Standardization • Control of Documented Information • Standardization 15
  • 16. 4.1 Context of the Organization – Risk Management # Issue Internal/ External Risks Risk Rating (H/M/L) Actions Opportunities 1 Hiring & Retention of Drivers Internal • Restricted Growth • Late Deliveries L • To provide technological advanced and comfortable fleet for drivers • To provide ELD installed fleet for driver's safety and easy compliance • To provide job stability • To provide health care benefits • To give performance bonus • Effective Manpower Planning • Organizational Branding 2 Maintenance of Certifications Internal • Customer Dissatisfaction • Market Reputation • Low business volume • Loss of big customers • Losing market competitiveness L • Training of employees • Maintaining/retaining documented information as per requirement • Conducting internal audits and inspections • Consulting services from Safety Consultants • Competitive advantage • Attracting new customers and retaining existing ones 3 Weather External • Late Deliveries • Late Pickups • Unsafe Driving Conditions M • Effective Planning based on weather forecast • Increased Customer communication on delivery/pick-up status • Winter season driving training to all drivers • SOPs for winter driving • Safety on Road • Improved winter season performance to satisfy the customer 16
  • 17. 4.2 Interested Parties & their Expectations – Risk Management # Interested Parties Expectations Risks Risk Rating (H/M/L) Actions Opportunities 1. Customers • Services quality • On-time delivery • Response time to enquiries and complaints • Compliance with applicable regulations • Maintenance of required certifications • Late Deliveries • Penalties • Loss of business • Customer Dissatisfaction M • To implement Quality Management System based on the requirements of ISO 9001:2015 • Maintain compliance certifications • To train office employees and drivers on compliance requirements • To improve level of communication with customers • After-hours services • Repeated & dedicated business from existing customers • Referrals • New business from existing customers 2. Suppliers • Clear specification of products & services • On time payment • Products and Services not meeting requirements • Late Deliveries L • To provide clear specifications of products and services to all suppliers • To provide training to Owner Operators and develop other suppliers • To pay on time as per terms and conditions • Dedicated services 3. Regulators • Compliance with applicable requirements • Market Reputation • Fines/Penalties • Shut Down M • To hire services of experienced compliance consultants • To trained employees on applicable regulations • Good Market Reputation • Business Continuity 4. Employees 5. Leadership 17
  • 18. Can we use Risk-based- Thinking in Auditing? There is no ISO standard for Management System Auditing There are Guidelines (ISO 19011) for Management System Auditing mainly used for 3rd Party Auditing but can be used for 1st & 2nd Party Auditing as well ISO 19011 requires ISO Registrars to use Risk-based- Thinking in 3rd party auditing We must use Risk-based-Thinking for conducting internal audits to demonstrate conformance 18
  • 19. 4.4./9.2 Turtle Diagram – A Tool for Process Risk Management With What? (Material/Financial/Other Resources) Opportunities With Who? (Human Resources) • Infrastructure (Hardware, Software, Office etc.) • Time • Resources for Audit (Financial/Materials/Others etc.) • Use of Risk-based-Thinking in Auditing • Effective Audit Planning • Effective Training • Maintaining adequate number of competent Auditors • Qualified Auditors • Lead Auditor • Auditee Inputs Internal Auditing Process Output • Audit Plan /Schedule • Audit Criteria (Req of QMS, ISO 9001 and Interested Parties) • Risks & Opportunities • Importance and Criticality of Processes • Changes affecting the Organization • Results from previous audits • Internal and external performance trends • Customer complaints • Audit Report • Summary of Audit Findings • Non-Conformity Report (if any) How? (Methods/Control/Documented Information) Risks Monitoring/Measuring (KPIs/Process Results) • Audit Planning • Documented Information (Policies/Procedures) • Audit Checklists • Audit Frequency • Audit Methods (Interviews, Observations and Review of Documented Information) • Poor Audit Planning (not based on Risk) • Ineffective Audit Training • Auditor’s Competence • Availability of Competent Auditors • Infrastructure Failure • Lack of Resources • Inadequate Frequency • Internal/External Audit Results • Timely completion of audits as per Schedule • Effectiveness of CA • # of IANCRs • Maintenance of ISO 9001 Certification 19
  • 20. Risk-based- Thinking in Auditing Conducting more frequent audits in following circumstances may help to reduce the risk and ensure product/service conformity and customer satisfaction: • QMS is new in the organization • Process(s) is complex • New product/service is launched • Areas with more identified risks or nonconformities • Areas with major nonconformities • Areas where corrective actions were not effective • Processes which are critical for product/service conformity • Areas with more customer complaints and formal rejections Some Best Practices 20
  • 21. I wish you to stay Safe. 21
  • 22. 22 Sorry, I couldn’t ask any question. No Worries! Email at info@gcerti.ca