Audit of essential QMS processes

G

glenn0004

Audit of essential QMS processes
Over the past 12 months we have undertaken a programme of System Audits across all departments who are involved within the process of product realization. Our system audits are designed to account for ISO 9001 and I4001 requirements and how the department is accommodating the stated requirements. This includes, Document Control, Record Control, Non-Conformance, Corrective and Preventative Actions and Internal Audit, in effect we are auditing the net results of the six required procedures, within all other requirements.
During our external surveillance audit we pick-up a minor NC for not auditing all of the QMS i.e. we hadn't directly audited our Document Control Process. Our past approach to internal audit has never directly audited Document Control and has always audited the net results.
Does our approach meet the requirements of the standard or will we have to make arrangements for an un-associated person(s) to directly audit the big six?
 
Last edited by a moderator:

dsanabria

Quite Involved in Discussions
If you could demonstrate that the results of Document control

"A documented procedure shall be established to define the controls needed a) to approve documents for adequacy prior to issue,
b) to review and update as necessary and re-approve documents,
c) to ensure that changes and the current revision status of documents are identified,
d) to ensure that relevant versions of applicable documents are available at points of use,
e) to ensure that documents remain legible and readily identifiable,
f) to ensure that documents of external origin determined by the organization to be necessary for the planning and operation of the quality management system are identified and their distribution controlled, and
g) to prevent the unintended use of obsolete documents, and to apply suitable identification to them if they are retained for any purpose."

were audited during the process then you have reason to appeal the ncr to the registrar. If not, then added to the processes for all your processes.
 

Jen Kirley

Quality and Auditing Expert
Leader
Admin
I agree with dsanabria.

I do agree with sampling documents in the process of auditing all over the site where controlled documents are used. That can help ensure you're not missing a place where controls fall apart.

But there's an expectation that the entire standard gets audited. Demonstrating the support process's coverage as samples in process audits might be easier if a table is used in which the auditor could check off that a) through f) were addressed with the sample. I do this for Management Review too, especially where different clauses are covered in different meeting venues.
 
G

GoKats78

We don't have Document Control identified as a process. Never been questioned by an auditor as to why not.

Document control happens across all processes and is audited as part of those audits. It is my long-help opinion that is NOT a process.
 

dsanabria

Quite Involved in Discussions
We don't have Document Control identified as a process. Never been questioned by an auditor as to why not.

Document control happens across all processes and is audited as part of those audits. It is my long-help opinion that is NOT a process.

You are correct - this is why competent auditors will not ask you for it - documents are there to support the process and it is / should be audited as part of the processes by internal and external auditors.
 

AndyN

Moved On
Audit of essential QMS processes
Over the past 12 months we have undertaken a programme of System Audits across all departments who are involved within the process of product realization. Our system audits are designed to account for ISO 9001 and I4001 requirements and how the department is accommodating the stated requirements. This includes, Document Control, Record Control, Non-Conformance, Corrective and Preventative Actions and Internal Audit, in effect we are auditing the net results of the six required procedures, within all other requirements.
During our external surveillance audit we pick-up a minor NC for not auditing all of the QMS i.e. we hadn't directly audited our Document Control Process. Our past approach to internal audit has never directly audited Document Control and has always audited the net results.
Does our approach meet the requirements of the standard or will we have to make arrangements for an un-associated person(s) to directly audit the big six?

Your auditor is making up requirements and has no clue about process based audits of a management system. Reject the nc back the the CB management and tell them you don't expect to have the same auditor back.
 

RoxaneB

Change Agent and Data Storyteller
Super Moderator
The way doc control was assessed at our organization was the individual departments to conformance to our documented doc control process...and the "owner" of the doc control process was assessed on the appropriateness of the doc control process.

It was two ways of looking at the process...(1) Are people following the process? (2) Is the established process appropriate?

I'm wondering if this is the approach taken by your auditor.
 
S

SmallBizDave

I'm always looking for ways to protect myself from bad auditors without expending any effort. When I create my audit scripts I note the reference for each question as to what section of the standard and what section of the QMS procedures is covered. For example, if I am checking a management review record for required outputs, that question addresses items in section 5 as well as 4.2.4 since it's a record. The record has to be legible, controlled, etc. as well as containing the right information.

There is no standalone Record Control audit but there are questions covering section 4.2.4 (and 4.2.3) scattered through all process audits. So when the auditor wants to see that I have audited records control I can provide traceability to a series of scattered questions proving its been covered. It's not in the format they like but it is certainly compliant.
 

John Broomfield

Leader
Super Moderator
I agree with Dave's approach.

When process auditing you bring any applicable clause to bear on reporting the effectiveness of the process, and how well it is served by the system while making sure the audit fulfills its objective.

The idea of conducting a separate document control audit is laughable.

John
 
Thread starter Similar threads Forum Replies Date
C The 10 Essential ISO 9001:2000 Audit Questions General Auditing Discussions 36
P Customer ISO13485 Audit - Changing Agenda ISO 13485:2016 - Medical Device Quality Management Systems 11
E VDA 6.3 External audit - opening meeting VDA Standards - Germany's Automotive Standards 4
Q Leveraging Audit Report from Previous Job ISO 13485:2016 - Medical Device Quality Management Systems 14
K Need Help With IATF 16949 Audit NC IATF 16949 - Automotive Quality Systems Standard 6
D Opinions on internal audit schedule adjustment Internal Auditing 19
T What should be considered or asked to certified body auditors before selecting them for AS9100 Audit? AS9100, IAQG, NADCAP and Aerospace related Standards and Requirements 4
K Length of a Combined 13485 and 9001 Surveillance Audit? ISO 13485:2016 - Medical Device Quality Management Systems 4
L Counting contractors for determining AS9100 audit days AS9100, IAQG, NADCAP and Aerospace related Standards and Requirements 4
T AS9100 Internal Audit (Quality System) Program AS9100, IAQG, NADCAP and Aerospace related Standards and Requirements 4
T Guiding document or resource to process AS9100 audit findings AS9100, IAQG, NADCAP and Aerospace related Standards and Requirements 8
K VDA6.3 as internal audit tool VDA Standards - Germany's Automotive Standards 8
H Internal Audit on Third-Party Logistics (3PL) Warehouse ISO 13485:2016 - Medical Device Quality Management Systems 4
I Internal Audit Questionnaire Oil and Gas Industry Standards and Regulations 16
J Remote location IATF audit IATF 16949 - Automotive Quality Systems Standard 3
P Increase in audit days for multi-site companies based on the new AS9104-1 2022 AS9100, IAQG, NADCAP and Aerospace related Standards and Requirements 0
G 8D on Audit Non Conformance -- Incomplete Document Nonconformance and Corrective Action 23
G MDR critical supplier audit checklist EU Medical Device Regulations 0
S Audit Duration Calculation - ISO9001 + EN9100 with different scope General Auditing Discussions 2
T Audit Objective Evidence Photos AS9100, IAQG, NADCAP and Aerospace related Standards and Requirements 7
L How to prepare Top Management for IMS Surveillance Audit ISO 9000, ISO 9001, and ISO 9004 Quality Management Systems Standards 5
J Response time from API for review of responses to audit findings Oil and Gas Industry Standards and Regulations 7
T External Audit Notification List AS9100, IAQG, NADCAP and Aerospace related Standards and Requirements 2
T External Audit Plan Email Template AS9100, IAQG, NADCAP and Aerospace related Standards and Requirements 1
R Do I need to get calibration certificate from ISO 17025 for IATF Audit IATF 16949 - Automotive Quality Systems Standard 8
kys123 Implications of failing an Anvisa Audit for ISO 13485 Certification ISO 13485:2016 - Medical Device Quality Management Systems 4
T Operator Acceptance Audit Standard AS9100, IAQG, NADCAP and Aerospace related Standards and Requirements 1
T New Quality Manager Audit Preparation Quality Manager and Management Related Issues 10
rivariva MDSAP audit QMS preparation Other Medical Device Regulations World-Wide 10
L Evaluation of Readiness of Organization for 3rd Party Audit ISO 9000, ISO 9001, and ISO 9004 Quality Management Systems Standards 14
L ISO 9001, 14001, 45001 Audit Questions for a Security & Corporate Affairs Department ISO 9000, ISO 9001, and ISO 9004 Quality Management Systems Standards 10
Moncia Full system pre certification audit ISO 50001 Other ISO and International Standards and European Regulations 8
M External audit non conformity related to applicable regulations ISO 13485:2016 - Medical Device Quality Management Systems 7
D Preparing for IATF 16949 Letter of Conformance Stage 1 audit IATF 16949 - Automotive Quality Systems Standard 4
A Establishing an initial audit schedule for Pharma Suppliers General Auditing Discussions 2
B AS9100 Certification Audit Accounting for Additional Customer QMS Requirements AS9100, IAQG, NADCAP and Aerospace related Standards and Requirements 15
B Surveillance audit nonconformity ISO 13485:2016 - Medical Device Quality Management Systems 5
R Live Audit disasters AS9100, IAQG, NADCAP and Aerospace related Standards and Requirements 6
R Audit Closure - Assigned actions AS9100, IAQG, NADCAP and Aerospace related Standards and Requirements 7
T Company AS9100D External Audit Preparation AS9100, IAQG, NADCAP and Aerospace related Standards and Requirements 17
T AS9100D Risk-Based Internal Audit Schedule AS9100, IAQG, NADCAP and Aerospace related Standards and Requirements 10
Crusader Missed Annual Audit… Registrars and Notified Bodies 8
S Minimum Retention Time for Records of internal audit results as per AS9100 AS9100, IAQG, NADCAP and Aerospace related Standards and Requirements 5
B Establishing topics for IATF internal audit processes Internal Auditing 9
I API Q1 5.7.1.5.a and API 6A10.4.2.12.2 AAR in API audit Oil and Gas Industry Standards and Regulations 0
D Unannounced Audit - Remote ISO 13485:2016 - Medical Device Quality Management Systems 6
L 3rd party audit issues - No audit agenda received a week before the audit Registrars and Notified Bodies 7
T Calculate FPY for Audit Results AS9100, IAQG, NADCAP and Aerospace related Standards and Requirements 9
D Critical Supplier will not allow us to audit Plant floor US Food and Drug Administration (FDA) 12
E Calibration Records during AS9100 Audit AS9100, IAQG, NADCAP and Aerospace related Standards and Requirements 8

Similar threads

Top Bottom