SBS - The best value in QMS software

Information Technology in IATF 16949 audit scope

Sidney Vianna

Post Responsibly
Staff member
Admin
#11
Just only audit the data back up system and cyber attack is enough. Is that true?
Welcome to The Cove, Fahsai.

As the standard is kind of non-granular concerning the aspect of infrastructure, what includes IT, use the risk based thinking mind set and previous past performance to determine the scope and focus areas of that part of your business system. For example, if parts have been manufactured using obsoleted NC programs because operators uploaded the software from a hard disk drive instead of the server due to previous, network outages, audit your system taking that into account and how the risk is being mitigated.

In the lack of granular requirements, use the "freedom" of determining the scope of the audit to your advantage. If an external auditor ever questions the scope and comprehensiveness of the internal audit, don't vere be afraid of challenging him/her with the "show me the shall" approach.

Good luck.
 
Elsmar Forum Sponsor

Mr.Ruiz

Starting to get Involved
#12
Hello all,

This is my first time post in the COVE. I have question regarding internal audit for IT dept that need your advise.

I used Turtle diagram when commencing the audit. When we go through the "IT Infrastructure" part, I asked about the server room and the required control condition.

Not only the authorized access, I mean temperature and humidity requirements in the server room. The answer is 25 degree Celsius without reference. "Someone" told them a long time ago !

In case the air conditioning broken down and start to blow warm air, there will be a notification email to IT team, then they will take appropriate actions. Not actions are defined as well. Also, no need to calibrate/verify the temp monitoring system. To add on, there's no company global requirements about it. These are all the answers from our IT team.

My question is what is the scope of auditing IT according to IATF 16949? How deep the auditor should go? There are many comments from our internal auditor team that IATF has no specific requirements about IT and the server room. Just only audit the data back up system and cyber attack is enough. Is that true?

Thanks
Fahsai
Well, when I first came to my current job, they used to have an IT Process declared in their Quality Manual and all the iterations. I choose to cut that process from our QMS, but, I let an IT Procedure, this procedure states all the appropriate and required controls to have a good IT response, for equipment, communication, software and hardware, and of course all the contingency plans for cyber attacks, system failure etc.

As many of the guys already said, IT rely on Clause 7.1.3 infrastructure and 6.1.2.3 Contingency Plans. Think of IT as an add-on more within your plant, at least that the generation of your product has to carry a kind of programming (embedded software) then, a more detailed control you might need, in such case, perhaps if it would be convenient to name it as a process or inside of production process, but, if IT is just like regular IT for all of us, you don't need to dig deeper.

As far as I know, IT already has a numeral of regulations to comply, like Sarbanes Oxley and more, so, if IT is not that big deal, I suggest to cut it from your Processes.
 

Rameshwar25

Quite Involved in Discussions
#13
1. I wonder why IT will not be considered as supporting process and will not be audited like other processes. ISO 9001 clauses 7.1.3 has given very clear explanation for IT. It is part of infrastructure. If we have to audit maintenance, stores, logistics; we shall also have to audit IT.
2. The initiator of this post Mr Fahsai was not asking whether IT should be audited or not. His question is 'How IT may be audited and what may be input questions'.
I will appreciate if someone posts some questions which may be asked during internal audit of IT process.
 
Thread starter Similar threads Forum Replies Date
D Preservation of Electronic Data / Information Technology ISO 13485:2016 - Medical Device Quality Management Systems 5
E ISO 9001:2015 for Information Technology Department Human Factors and Ergonomics in Engineering 2
V Information Technology Dashboard - IT Department Performance Metrics IEC 27001 - Information Security Management Systems (ISMS) 2
P Seeking Information on ISO 15504 - Information Technology Process Assessment Other ISO and International Standards and European Regulations 3
Richard Regalado ISO/IEC 27000:2014 - Information technology - Overview and vocabulary (FREE download) IEC 27001 - Information Security Management Systems (ISMS) 4
S Information Technology Department (IT) Checklist for ISO 9001:2008 ISO 9000, ISO 9001, and ISO 9004 Quality Management Systems Standards 3
B ITIL (Information Technology Infrastructure Library) Foundation Certificate Career and Occupation Discussions 1
A Information Technology Process Mapping per ISO 13485 - example wanted Process Maps, Process Mapping and Turtle Diagrams 1
S External Documents in the I.T. (Information Technology) Field ISO 9000, ISO 9001, and ISO 9004 Quality Management Systems Standards 7
A Non Conforming Product in an IT (Information Technology) Company ISO 9000, ISO 9001, and ISO 9004 Quality Management Systems Standards 10
Q What ISO 9001:2008 procedures apply for IT (Information Technology)? ISO 9000, ISO 9001, and ISO 9004 Quality Management Systems Standards 21
A ISO 20001 (ITIL) Information Technology Infrastructure Library IT (Information Technology) Service Management 2
L Auditing Information Technology (IT) in the ISO 9001 workplace Internal Auditing 15
M Information Technology Record Retention time best practices Quality Management System (QMS) Manuals 2
D Internal Audit of Information Technology Internal Auditing 8
D Information Technology Process Audit - Suggestions for Auditing IT IATF 16949 - Automotive Quality Systems Standard 12
C Understanding Concepts of Information Technology & Infrastructure Library (ITIL) Misc. Quality Assurance and Business Systems Related Topics 1
netwizard Looking for an ISO 9001:2000 Internal Audit Checklist - UOP (Information Technology) ISO 9000, ISO 9001, and ISO 9004 Quality Management Systems Standards 5
A QMS For IT (information Technology) Sector ISO 9000, ISO 9001, and ISO 9004 Quality Management Systems Standards 6
A Can a organization use a disclaimer "pending AS9100 Certification" in Marketing Information? AS9100, IAQG, NADCAP and Aerospace related Standards and Requirements 4
D FDA Information - Revising the Instructions for Use US Food and Drug Administration (FDA) 0
M Need Help With Information Security Asset Risk Register IEC 27001 - Information Security Management Systems (ISMS) 2
S Mechanical Test Under FDA Freedom of Information Act Medical Device and FDA Regulations and Standards News 5
Watchcat Summary of De Novo Biocompatibility Information, 2015-2018 Other US Medical Device Regulations 0
Q Self-assessment audit information Quality Management System (QMS) Manuals 6
Sidney Vianna Release of ISO 10013:2021, Quality management systems – Guidance for documented information Other ISO and International Standards and European Regulations 0
W How long do you keep information about equipment no longer used? Document Control Systems, Procedures, Forms and Templates 2
L Documented Information in Internal Audits Process (9.2) ISO 9000, ISO 9001, and ISO 9004 Quality Management Systems Standards 4
R What information do i need to get from the device manufacturer 21 CFR Part 820 - US FDA Quality System Regulations (QSR) 0
T Types of confidential information ISO 17025 related Discussions 8
S API Spec.Q1 Standards Version in Purchasing Information Oil and Gas Industry Standards and Regulations 1
eule del ayre Documented Information - Periodic Review of Documents? IATF 16949:2016 / ISO 9001:2015 IATF 16949 - Automotive Quality Systems Standard 34
R Information on obtaining a market authorization for China China Medical Device Regulations 2
B SN95 Respirator Approval Information Other Medical Device Related Standards 0
R Risk assessment on IT containers and the information they contain IEC 27001 - Information Security Management Systems (ISMS) 4
O EN 301 489-1 and EN 301 489-17 - Where do we get the information of the Published versions? CE Marking (Conformité Européene) / CB Scheme 1
K Article 18: Implant Card and information to be communicated. EU Medical Device Regulations 5
K EU MDR Annex 1 Chapter III: Information in the Instructions for Use-23.4 (e) the performance characteristics of the device; EU Medical Device Regulations 1
A GMDN Registration Basic preliminary Information EU Medical Device Regulations 0
J Controlled information versus defined documents / records ISO 13485:2016 - Medical Device Quality Management Systems 3
A Medical device Reporting : Good Faith Effort for Additional information Other US Medical Device Regulations 2
P Cenelec updated standard information CE Marking (Conformité Européene) / CB Scheme 1
Richard Regalado Automotive News TISAX - VDA ISA (information security assessment) VDA Standards - Germany's Automotive Standards 5
JoCam False information provided for Medical Device Registration - What are the implications? Other Medical Device Related Standards 3
adir88 Information of safety can reduce risk now? ISO 14971 - Medical Device Risk Management 12
Richard Regalado What could go wrong with information: Ransomware statistics and facts (2018 to present) IEC 27001 - Information Security Management Systems (ISMS) 0
Q LOT or Serial Number Symbol not used when the information is contained in the UDI? 21 CFR Part 820 - US FDA Quality System Regulations (QSR) 1
A Information about Medical Device Test Laboratories Other Medical Device and Orthopedic Related Topics 4
C Missing routers/documented information Nonconformance and Corrective Action 5
MrTetris Unacceptable risk and information for safety ISO 14971 - Medical Device Risk Management 16

Similar threads

Top Bottom