Incorrectly Performed ISO 9001:2008 Internal Audit

Q

QAMTY

Hi everybody

Could you please share thoughs in my case.
I have ISO 9001 2008, and we are running internal audits.

Im in the position of General Director, recently I revised one of
audits report of an audit performed by one internal auditor.

I noticed that really was not a good audit,it has several faults

Nc´s were incorrectly documented, lacking of enough evidences,
wrong document identifications, findings that seemed more OFI, than
real nc´s,etc.

The auditee, a recent hired boy in the audited process, accepted the report
and now is working on the CAs/PAs.


My question is:

What can I do in this case, Can I cancel the audit and repeat it with a new auditor, or just ignore the audit report and make CA´s only in findings which I consider really apply?

How to manage this issue?

I read ISO 19011 and I dont see anything about it?

Thanks
 
What can I do in this case, Can I cancel the audit and repeat it with a new auditor, or just ignore the audit report and make CA´s only in findings which I consider really apply?
Hi QAMTY,

Apart from making certain that coming audits are done properly, I suppose I would deal with the audit in question by going through the report and findings together with the auditee (helping him out, as he is a rookie), and set actions accordingly even if said findings are less than perfect. Of course, you may be forced to ask for more or better background data/evidence in the process, but that in itself is not uncommon. We all need clarification sometimes.

Obviously, judging from your description, some of the findings may or may not be dead ends, leading to "No further action". That should be ok, as long as you can explain how and why you reached that conclusion.
 
Q

QAMTY

Thanks Claes and Colin
Well, in the Audit process precedure I have included a survey which is filled up by the auditee every time an audit is carried out, where we evaluate the auditor performance on several points, at the end of year we gather all the surveys and take the needed actions to improve the audit process, but is done annually,
I wonder if its better to set it every 6 months and not to wait one year to take actions
Thanks
 

Ajit Basrur

Leader
Admin
Great points by Claes and Colin.

QAMTY, as part of your proposed action, you need to consider the following:

From your post, I could not figure how long ago did you identify the erroneous audit report? Is there any impact to process or product due to wrong categorization and/or actions taken subsequently?

How do you select your internal auditors and ensure their competence? I do not know your procedure but typically internal auditors get assigned to respective audits to ensure impartiality and that they have the required knowledge and skills to get the intended results.

You may also include a process to review the audit report before it is published.
 
Q

qualityfox

I have found over the years that internal auditors and auditees do not have the thorough understanding of ISO that I do. Although they've been trained, ISO is not their full time job, so auditors make mistakes and auditees accept poorly written NCs because they assume the auditor knows what they're doing. To ensure effective reports I hold a review meeting with the auditor before they issue their report. I also sit in on the closing meeting to ensure everyone understands what is expected. Our ISO certificate is relatively new so I consider these reviews to be an opportunity to help all concerned better understand the requirements. When our system becomes more mature, this close attention should no longer be necessary.
 

dsanabria

Quite Involved in Discussions
Hi everybody

Could you please share thoughs in my case.
I have ISO 9001 2008, and we are running internal audits.

Im in the position of General Director, recently I revised one of
audits report of an audit performed by one internal auditor.

I noticed that really was not a good audit,it has several faults

Nc´s were incorrectly documented, lacking of enough evidences,
wrong document identifications, findings that seemed more OFI, than
real nc´s,etc.

The auditee, a recent hired boy in the audited process, accepted the report
and now is working on the CAs/PAs.


My question is:

What can I do in this case, Can I cancel the audit and repeat it with a new auditor, or just ignore the audit report and make CA´s only in findings which I consider really apply?

How to manage this issue?

I read ISO 19011 and I dont see anything about it?

Thanks

AHHH!

What you are describing is an opportunity for Improvement in the audit team.

The audit is done - in your schedule you could reschedule the areas you think require additional oversight.

Next - partner up with each auditor and with a teaching heart - find the strength and areas for improvement of each auditor and go with each point that you see - as it happens.

Review the NCR with the auditors and try to find out if they understand the process of writhing NCR and other options available in describing the event.

Finally, a group refresher training would be nice. Please don't single out an auditor in public - you will loose that auditor.

Remember to support them, positive feedback and teaching moments
 

RoxaneB

Change Agent and Data Storyteller
Super Moderator
Thanks Claes and Colin
Well, in the Audit process precedure I have included a survey which is filled up by the auditee every time an audit is carried out, where we evaluate the auditor performance on several points, at the end of year we gather all the surveys and take the needed actions to improve the audit process, but is done annually,
I wonder if its better to set it every 6 months and not to wait one year to take actions
Thanks

People don't know what they don't know. :cool: In the case of the auditee, if he had limited or no knowledge of what to expect from the audit, how can he properly evaluate the process? And, let's be honest, it would not be a surprise to see auditees being "kind" in their survey responses in order to facilitate soft audits in the future. :notme:

If you wish to evaluate your audit process, you could...well...audit it. Or have someone on the team do spot checks on the reports and responses - in the medical field, we do spot audits on patient charts to assess the state of documentation from our clinical personnel.

It does sound like there could be an opportunity to refresh the knowledge of the auditors on the auditing process, including how to write a report, articulate findings, and work with auditees.
 
Thread starter Similar threads Forum Replies Date
M How to 'delist' a Class II device that was incorrectly registered as such? Medical Device and FDA Regulations and Standards News 2
K END CALIBRATION CANNOT BE PERFORMED Pharmaceuticals (21 CFR Part 210, 21 CFR Part 211 and related Regulations) 2
M Sample record for verification performed by importers before placing a device on the market EU Medical Device Regulations 0
M Sterile packing validation tests to be performed and protocol Other Medical Device and Orthopedic Related Topics 1
S Work performed in Canada on US patients using US device Canada Medical Device Regulations 1
A We're currently looking for any studies performed on various PPE materials Qualification and Validation (including 21 CFR Part 11) 1
M Routine testing of medical electrical systems - What specific electrical safety tests should be performed? IEC 60601 - Medical Electrical Equipment Safety Standards Series 5
S 510(K) change analysis - At what point should a 510(K) change analysis be performed? 21 CFR Part 820 - US FDA Quality System Regulations (QSR) 2
S Corrective Action from Internal Audits not performed ISO 9000, ISO 9001, and ISO 9004 Quality Management Systems Standards 24
S Internal Audits performed by another local business ISO 9000, ISO 9001, and ISO 9004 Quality Management Systems Standards 26
D When should the OHSMS certification audit be performed? Occupational Health & Safety Management Standards 9
D Should Biocompatibility Tests be performed on Production Samples? 21 CFR Part 820 - US FDA Quality System Regulations (QSR) 9
Ajit Basrur Is Biocompatibility study performed on medical devices for possible contaminants? Other Medical Device Related Standards 4
S No Audit Schedule and Internal Audit not Performed ISO 9000, ISO 9001, and ISO 9004 Quality Management Systems Standards 20
G Do Inspections need to be performed by QA/QC Personnel 21 CFR Part 820 - US FDA Quality System Regulations (QSR) 5
B Should EMC (Electromagnetic Compatibility) Testing be performed In-House CE Marking (Conformité Européene) / CB Scheme 10
V Is the CQI-9 Heat Treat Assessment performed by a 3rd Party Auditor APQP and PPAP 1
V Do I need dimensionals performed for PPAP for every revision change? APQP and PPAP 2
M Program of Internal Audits aren?t performed fully - Is it nonconformance? General Auditing Discussions 20
I Medical, Vacuum Heat Treat or Not if Subsequent Finishing Operations are Performed Benchmarking 3
T Resolution Analysis - Has anyone ever performed a Resolution Analysis? General Measurement Device and Calibration Topics 1
E First external audit coming up, do I need to have performed Internal Audits already? Internal Auditing 15
A Internal Audits - What if performed by consultant Internal Auditing 9
S Internal Audits not performed - Useful data from internal audit schedule Internal Auditing 31
W Gage R&R study frequency - How often should a Gage R&R be performed? Capability, Accuracy and Stability - Processes, Machines, etc. 8
D Are FIR's performed per AS9102, either at Tier 2 or from Tier 3's? AS9100, IAQG, NADCAP and Aerospace related Standards and Requirements 2
B SPC for any of the testing performed in a Metals Testing Laboratory... General Measurement Device and Calibration Topics 2
S TUV NCR No: 2 - Aseptic processing validation has not been performed ISO 13485:2016 - Medical Device Quality Management Systems 4
C Elevated work platforms - No evidence of inspection being performed - Clarification Various Other Specifications, Standards, and related Requirements 1
R Has anyone ever performed a MSA study on a profilometer? Gage R&R (GR&R) and MSA (Measurement Systems Analysis) 1
H How often is Attribute Gage R&R required to be performed? Gage R&R (GR&R) and MSA (Measurement Systems Analysis) 10
D Audits performed by Bosch ISO 9000, ISO 9001, and ISO 9004 Quality Management Systems Standards 1
S Clean Room Class ISO 8 EU Medical Device Regulations 3
S What is the relation between EU Annex 1 and ISO 14644 requirements? Manufacturing and Related Processes 2
A ISO 13485 CERTIFICATION WITH REGULATORY ISO 13485:2016 - Medical Device Quality Management Systems 1
P ISO 20243 vs. AS5553 vs. CISA ICT SCRM ISO 9000, ISO 9001, and ISO 9004 Quality Management Systems Standards 2
G ISO 17025.2017 Clause 7.8.4.3 Certificate of Calibration Label ISO 17025 related Discussions 5
R ISO 13485:2016 DESIGN TRANSFER Forum News and General Information 0
Donetta Notified Body Unresponsive - Cancelled ISO Cert Early Registrars and Notified Bodies 5
Y Environmental Monitoring in ISO 13485 production areas ISO 13485:2016 - Medical Device Quality Management Systems 2
A QMS Roll out with guidance from ISO 9001 Quality Management System (QMS) Manuals 8
B ISO 9001Exclusion of clause 8.5.3 ISO 9000, ISO 9001, and ISO 9004 Quality Management Systems Standards 14
A Merging two ISO systems ISO 9000, ISO 9001, and ISO 9004 Quality Management Systems Standards 10
cscalise ISO training and auditing resources for Korea MDA regulations Other Medical Device Regulations World-Wide 0
C Computerized System Validation in ISO 9001:2015 ISO 9000, ISO 9001, and ISO 9004 Quality Management Systems Standards 9
M What is meant by "operating criteria" at closed 8.1 of ISO 14001:2015 ISO 14001:2015 Specific Discussions 0
Q Experience Records - ISO 9001:2015 ISO 9000, ISO 9001, and ISO 9004 Quality Management Systems Standards 11
Sidney Vianna Informational ISO/TC 176/ TG4 Updated summary of emerging themes document ISO 9000, ISO 9001, and ISO 9004 Quality Management Systems Standards 2
A ISO 9001 & API Q1 Approved Supplier/Sole Agent ISO 9000, ISO 9001, and ISO 9004 Quality Management Systems Standards 2
R Can an organization be ISO certified if it doesn't comply with each clause? ISO 13485:2016 - Medical Device Quality Management Systems 1

Similar threads

Top Bottom