External Storage of Data - ISO 9001 Clause 7.5.2 Validation of Processes

F

FrameReader

Hello,

Our company archives some of its documents with a document storage company. Some of the information contained in these documents has some bearing on the service that we provide. I'm not a lawyer but the language in our contract with the document storage company strikes me as being fairly minimal. They commit to providing 'ordinary care' to our documents, and that's about it.

If our stuff gets lost or destroyed, they'll reimburse us for the cost of the actual hardware (digital storage media), which is nice I guess, but if any of our archived info was ever lost or destroyed, being reimbursed for the cost of some digital media would rank low on our list of concerns.

So anyways, we decided it would be a good idea to pay a visit to the site where they store our stuff. I've heard it said that clause 7.5.2 of the Standard, while called 'Validation of processes for service provision' could also be thought of as basically being a 'do what you reasonably can to control external processes'.

The storage of these documents is certainly an external process. According to part (a) of the clause, we should define criteria for reviewing and approving these processes. So I figure, we'll have a look around their site, maybe see if they have some kind of sprinkler system to control fires, good security measures, security cameras ...

Do the experts in the cove have any ideas regarding what else we might want to look for here?

Thank you,
FrameReader
 

pkost

Trusted Information Resource
Re: 7.5.2 Validation of Processes

You suggest that they store hardware for you - is it networked and active? or is it just a store where you throw in your old harddrives? Are there any paper documents?

If it is all electronic you may want to consider duplicating and using an additional company to reduce any risk.

Regardless, a decent company may have a business contingency/continuity plan which should list all the measures they take to protect their business and your property.
 
F

FrameReader

Re: 7.5.2 Validation of Processes

You suggest that they store hardware for you - is it networked and active? or is it just a store where you throw in your old harddrives? Are there any paper documents?

If it is all electronic you may want to consider duplicating and using an additional company to reduce any risk.

Regardless, a decent company may have a business contingency/continuity plan which should list all the measures they take to protect their business and your property.

It is all electronic - not networked, it is basically just old harddrives, but those harddrives contain information that we should be able to access in case one of our clients has a question about things that happened in the past.

I agree that using an additional company would greatly reduce risk, but I'm quite sure that we won't go that route / would be cost-prohibitive.

Asking for a contingency plan sounds like a good idea. thanks pkost!
 
T

The Specialist

Re: 7.5.2 Validation of Processes

You should be sure that your contract with the third party contains a list of requirements specific to your storage needs that you can 'validate' or 'audit' to...

Your storage requirements may include:

Fire protection storage (sprinkler system or fire retarded storage)
Electro-magnetic protective storage
Storage area temperature/humidity requirements
Accessibility (availability/notice of availability) requirements
File/document database and file location requirements
Confidentiality requirements (third party accessibility)
Security Requirements
File delivery/removal requirements
Company audit/review periods

Etc…

Of course, it will depend on the media being stored!
 

pkost

Trusted Information Resource
Re: 7.5.2 Validation of Processes

You might want to be careful with old harddrives...I'll give you an example of 5.25 discs and to an increasing extent 3.5in discs - how would you retrieve information from them now? A few years ago every computer had a discdrive for 3.5in. In my office we now only have one. try to find a 5.25 reader!

With hard drives although it is less of an issue legacy connections may still become a problem - PATA used to be standard now most PC's use SATA and some don't even have a socket for PATA drives. You could end up going to a lot of effort retrieving the data!

With the rate at which harddrive capacity increases it may be worth just bundling all archived data onto a couple of large capacity drives every now and then.
 

somashekar

Leader
Admin
Re: 7.5.2 Validation of Processes

It is all electronic - not networked, it is basically just old harddrives, but those harddrives contain information that we should be able to access in case one of our clients has a question about things that happened in the past.

I agree that using an additional company would greatly reduce risk, but I'm quite sure that we won't go that route / would be cost-prohibitive.

Asking for a contingency plan sounds like a good idea. thanks pkost!
If it is not networked, then you are better off renting some safe deposit lockers offered by many banks to deposit your hard drives, provided they have some temperature control etc, established in the strong room.
Your document storage company must do much more than just providing storage.
Can you see if you can get access to any of your associate company / office where you can keep some fireproof cabinets and store them for safe keeping as a disaster management step and store a backup copy in similar fireproof cabinet in a safe place within your organization.
You may run a periodic check on the media to ensure that are stored safe and the data is retreiveable.
 
Thread starter Similar threads Forum Replies Date
K 7.5.5 Identification of Stored Product - External auditor identified storage problem ISO 9000, ISO 9001, and ISO 9004 Quality Management Systems Standards 16
E VDA 6.3 External audit - opening meeting VDA Standards - Germany's Automotive Standards 4
Q Interpretation of "external part of implant" in 60601-1 in relation to EN-45502 IEC 60601 - Medical Electrical Equipment Safety Standards Series 0
S Calibration SOP and external vendors General Measurement Device and Calibration Topics 2
R Quality Agreements with external testing laboratories now mandatory? EU Medical Device Regulations 16
LincolnQA AS9100D, Clause 8.4.1.1d - actions to take when external providers do not meet requirements AS9100, IAQG, NADCAP and Aerospace related Standards and Requirements 18
P IATF16949 External Lab Calibration -CIPM MRA IATF 16949 - Automotive Quality Systems Standard 1
T OASIS and External Audits AS9100, IAQG, NADCAP and Aerospace related Standards and Requirements 8
T External Audit Notification List AS9100, IAQG, NADCAP and Aerospace related Standards and Requirements 2
T External Audit Plan Email Template AS9100, IAQG, NADCAP and Aerospace related Standards and Requirements 1
Q External providers assessment - ISO 14001 ISO 14001:2015 Specific Discussions 4
M External audit non conformity related to applicable regulations ISO 13485:2016 - Medical Device Quality Management Systems 7
O 61010-1 Annex D Protection between HAZARDOUS LIVE circuits and ACCESSIBLE external TERMINALS Other Medical Device Regulations World-Wide 0
M Gravimetric blender for resin in automotive industry - periodical calibration via external lab with certification Reliability Analysis - Predictions, Testing and Standards 0
T Company AS9100D External Audit Preparation AS9100, IAQG, NADCAP and Aerospace related Standards and Requirements 17
D IATF16949 7.1.5.3.2 External Laboratory IATF 16949 - Automotive Quality Systems Standard 17
J 7.1.3.5.2 External laboratory - CIPM MRA IATF 16949 - Automotive Quality Systems Standard 3
W 7.1.5.3.2. External laboratory Sanctioned Interpretation IATF 16949 - Automotive Quality Systems Standard 4
T Internal and external communication procedure for Food Safety Food Safety - ISO 22000, HACCP (21 CFR 120) 2
J Biocompatibility for endoscope external handle/grip US Food and Drug Administration (FDA) 3
D 8.5.1.2 Validation and control of special processes requirements for Heat Treat External Processor AS9100, IAQG, NADCAP and Aerospace related Standards and Requirements 4
D IATF16949 external audit plan IATF 16949 - Automotive Quality Systems Standard 3
H Regarding external surface temperature limit requirement for lab incubators. CE Marking (Conformité Européene) / CB Scheme 2
A How to monitor new versions of external standards in your business Various Other Specifications, Standards, and related Requirements 2
Quality Specialist Quick question on the sequence of ISO 17025 external audits ISO 17025 related Discussions 14
M IATF external audit NC closure IATF 16949 - Automotive Quality Systems Standard 4
dubrizo Good Documentation Practice (GDP) as it Applies to External Contractors or Vendors Document Control Systems, Procedures, Forms and Templates 4
qualprod External consultant into a QMS ISO 9000, ISO 9001, and ISO 9004 Quality Management Systems Standards 15
W External PSU Providing a MOOP -- Will This Necessitate Conducted Emissions Testing? IEC 60601 - Medical Electrical Equipment Safety Standards Series 1
L AS9100 Section 8.4.2 - External provider test reports AS9100, IAQG, NADCAP and Aerospace related Standards and Requirements 10
Mikey324 External calibration - Finding in our 3rd party audit General Measurement Device and Calibration Topics 58
D Help Me. Non conformitty in External Audit IATF 16949 - Automotive Quality Systems Standard 13
P Is the second factor authentication (2FA) required for external users? Qualification and Validation (including 21 CFR Part 11) 1
J State of the Art for Documents of External Origin ISO 13485:2016 - Medical Device Quality Management Systems 17
D IATF 16949 SI 10, External non-accredited lab IATF 16949 - Automotive Quality Systems Standard 4
S Recommended software to send Quality scorecards to suppliers (external providers) Supplier Quality Assurance and other Supplier Issues 3
J External Standard Services Document Control Systems, Procedures, Forms and Templates 12
Ed Panek External Standards List - Should this document include previously revised standards? ISO 13485:2016 - Medical Device Quality Management Systems 4
F Logistic/shipping companies as external providers AS9100, IAQG, NADCAP and Aerospace related Standards and Requirements 3
J External third party audits Registrars and Notified Bodies 1
J Help settle a disagreement: Should external providers of preventive maintenance be on your ASL? AS9100, IAQG, NADCAP and Aerospace related Standards and Requirements 5
J Requirement for Retention of Records of Withdrawn Documents of External Origin Document Control Systems, Procedures, Forms and Templates 3
M Calibration Certificate Result issued by an accredited external laboratory General Measurement Device and Calibration Topics 9
L IATF external audit virtual (remote) IATF 16949 - Automotive Quality Systems Standard 13
A IEC 62304 safety classification, External Controls and off-label use related risks IEC 62304 - Medical Device Software Life Cycle Processes 5
R External Audit and Certificate prorogation due to the pandemic General Auditing Discussions 10
N Audit non-compliance API Q1 - Use of External Documents 4.4.4 in Product Realization Oil and Gas Industry Standards and Regulations 8
J 510(k) for a control kit for an external IVD test kit 21 CFR Part 820 - US FDA Quality System Regulations (QSR) 1
R Is it required to have an SOP for external audits? Medical Device and FDA Regulations and Standards News 7
Pmarszal External Standards and Regulations Management Process Document Control Systems, Procedures, Forms and Templates 10

Similar threads

Top Bottom