Jump to content

ISO 9000 family: Difference between revisions

From Wikipedia, the free encyclopedia
Content deleted Content added
No edit summary
Tag: blanking
m Reverting possible vandalism by 182.19.58.10 to version by Alkazzi. False positive? Report it. Thanks, ClueBot NG. (1894586) (Bot)
Line 1: Line 1:
{{Primary sources|article|date=March 2012}}
{{Primary sources|article|date=March 2012}}
'''ISO 9000''' is a series of standards, developed and published by the [[International Organization for Standardization]] (ISO), that define, establish, and maintain a quality assurance system for manufacturing and service industries.<ref>Margaret Rouse, [http://searchdatacenter.techtarget.com/definition/ISO-9000 ISO 9000], ''Search Data Center'', September 2005.</ref><ref>{{cite journal |doi=10.1108/09544780210439734 |title=The state of ISO 9000 certification: A study of Swedish organizations |year=2002 |last1=Poksinska |first1=Bozena |last2=Dahlgaard |first2=Jens Jörn |last3=Antoni |first3=Marc |journal=The TQM Magazine |volume=14 |issue=5
'''ISO 9000''' is a series of standards, developed and published by the [[International Organization for Standardization]] (ISO), that define, establish, and maintain a quality assurance system for manufacturing and service industries.<ref>Margaret Rouse, [http://searchdatacenter.techtarget.com/definition/ISO-9000 ISO 9000], ''Search Data Center'', September 2005.</ref><ref>{{cite journal |doi=10.1108/09544780210439734 |title=The state of ISO 9000 certification: A study of Swedish organizations |year=2002 |last1=Poksinska |first1=Bozena |last2=Dahlgaard |first2=Jens Jörn |last3=Antoni |first3=Marc |journal=The TQM Magazine |volume=14 |issue=5 |pages=297}}</ref> The standards are available through [[Standards organization#National standards bodies|national standards bodies]]. ISO 9000 deals with the fundamentals of quality management systems,<ref name="Tsim, Yeung, Leung 2002">{{cite journal |doi=10.1108/02686900210429669 |title=An adaptation to ISO 9001:2000 for certified organisations |year=2002 |last1=Tsim |first1=Y.C. |last2=Yeung |first2=V.W.S. |last3=Leung |first3=Edgar T.C. |journal=Managerial Auditing Journal |volume=17 |issue=5 |pages=245}}</ref> including the eight management principles upon which the family of standards is based.<ref name="Tsim, Yeung, Leung 2002" /><ref>{{cite journal |doi=10.1080/0954412998090 |title=Implementing ISO 9000: A study of its benefits among Australian organizations |year=1999 |last1=Beattie |first1=Ken R. |journal=Total Quality Management |volume=10 |pages=95}}</ref> ISO 9001 deals with the requirements that organizations wishing to meet the standard must fulfill.<ref>http://www.iso.org/iso/iso_9000_selection_and_use.htm{{full|date=November 2012}}</ref>

Third-party certification bodies provide independent confirmation that organizations meet the requirements of ISO 9001. Over a million organizations worldwide<ref>{{cite press release |title=ISO 9001 certifications top one million mark, food safety and information security continue meteoric increase |publisher=[[International Organization for Standardization]] |date=October 25, 2010 |url=http://www.iso.org/iso/pressrelease.htm?refid=Ref1363 |accessdate=March 24, 2012}}</ref> are independently certified, making ISO 9001 one of the most widely used management tools in the world today. Despite widespread use, the ISO certification process has been criticized<ref name="clifford">{{cite news |first=Stephanie |last=Clifford |date=May 1, 2005 |title=So many standards to follow, so little payoff |url=http://www.inc.com/magazine/20050501/management.html |work=[[Inc. (magazine)|Inc]]}}</ref><ref name="wilson">{{cite web |first=Ian |last=Wilson |url=http://james.westgard.com/the_westgard_rules/2010/06/iso-not-so.html |title=Is ISO the way to go? Some say, Not So |date=June 4, 2010}}{{Self-published inline|date=March 2012}}</ref> as being wasteful and not being useful for all organizations.<ref name="seddon">{{cite news |url=http://money.guardian.co.uk/work/story/0,,613363,00.html |title=The 'quality' you can't feel |first=John |last=Seddon |authorlink=John Seddon |work=The Observer |date=November 19, 2000}}</ref><ref name="seddon2">{{cite book |chapterurl=http://www.systemsthinking.co.uk/3-1-article.asp |chapter=A Brief History of ISO 9000: Where did we go wrong? |title=The Case Against ISO 9000 |edition=2nd |publisher=Oak Tree Press |year=2000 |isbn=978-1-86076-173-7}}</ref>

==Background==
ISO 9000 was first published in 1987.<ref>[http://www.bsieducation.org/Education/about/brief-history.shtml History of the BSI Group]</ref> It was based on the BS 5750 series of standards from [[BSI Group|BSI]] that were proposed to ISO in 1979.<ref>[http://www.bsigroup.com/en/About-BSI/News-Room/BSI-Fast-Facts2/ Fast Facts About BSI Group]</ref> However, its history can be traced back some twenty years before that, to the publication of the [[United States Department of Defense]] MIL-Q-9858 standard in 1959. MIL-Q-9858 was revised into the NATO AQAP series of standards in 1969, which in turn were revised into the BS 5179 series of guidance standards published in 1974, and finally revised into the BS 5750 series of requirements standards in 1979 before being submitted to ISO.

BSI has been certifying organizations for their quality management systems since 1978. Its first certification (FM 00001) is still extant and held by [[Tarmac Limited]], a successor to the original company which held this certificate.<ref>[http://www.tarmacbuildingproducts.co.uk/pdf/Tarmac%20Topfloor%20ISO%209001-2008%20Certificate.pdf Tarmac Certificate of Registration]</ref> Today BSI claims to certify organizations at nearly 70,000 sites globally.<ref>[http://www.bsigroup.com/en/About-BSI/About-BSI-Group/ More About BSI Group.]</ref>

==Reasons for use==
The global adoption of ISO 9001 may be attributable to a number of factors. A number of major purchasers require their suppliers to hold ISO 9001 certification. In addition to several stakeholders' benefits, a number of studies have identified significant financial benefits for organizations certified to ISO 9001, with a 2011 survey from the British Assessment Bureau showing 44% of their certified clients had won new business.<ref>[http://www.british-assessment.co.uk/news/iso-9001-proven-to-help-win-new-business] ISO 9001 proven to help win new business<!-- Bot generated title -->.</ref> Corbett ''et al.'' showed that certified organizations achieved superior [[return on assets]]<ref>http://www.bsi-emea.com/Quality/CaseStudies/Interstate.pdf{{full|date=November 2012}}</ref> compared to otherwise similar organizations without certification.<ref name="Corbett, Montes-Sancho, Kirsch 2005">{{cite journal |jstor=20110397 |doi=10.1287/mnsc.1040.0358 |title=The Financial Impact of ISO 9000 Certification in the United States: An Empirical Analysis |year=2005 |last1=Corbett |first1=Charles J. |last2=Montes-Sancho |first2=María J. |last3=Kirsch |first3=David A. |journal=Management Science |volume=51 |issue=7 |pmid=22037496 |pages=1607–16 |last4=Song |first4=CX |last5=Wu |first5=H |last6=Dai |first6=Q |last7=Irier |first7=H |last8=Upadhyay |first8=AK |last9=Gearing |first9=M |pmc=3292193}}</ref> Heras ''et al.'' found similarly superior performance<ref>http://neumann.hec.ca/cref/sem/documents/040923.pdf{{full|date=November 2012}}</ref> and demonstrated that this was statistically significant and not a function of organization size.<ref name="eps.udg.es">{{cite journal |doi=10.1108/02656710210429618 |title=ISO 9000 registration's impact on sales and profitability: A longitudinal analysis of performance before and after accreditation |year=2002 |last1=Heras |first1=Iñaki |last2=Dick |first2=Gavin P.M. |last3=Casadesús |first3=Martí |journal=International Journal of Quality & Reliability Management |volume=19 |issue=6 |pages=774}}</ref> Naveha and Marcus claimed that implementing ISO 9001 led to superior operational performance in the [[Automotive industry in the United States|U.S. automotive industry]].<ref>{{cite journal |doi=10.1016/j.aap.2006.11.004 |title=Financial performance, ISO 9000 standard and safe driving practices effects on accident rate in the U.S. Motor carrier industry |year=2007 |last1=Naveh |first1=Eitan |last2=Marcus |first2=Alfred |journal=Accident Analysis & Prevention |volume=39 |issue=4 |pages=731}}</ref> Sharma identified similar improvements in operating performance and linked this to superior financial performance.<ref name=Sharma2005>{{cite journal |doi=10.1016/j.intacc.2005.01.011 |title=The association between ISO 9000 certification and financial performance |year=2005 |last1=Sharma |first1=Divesh S. |journal=The International Journal of Accounting |volume=40 |issue=2 |pages=151}}</ref> Chow-Chua ''et al.'' showed better overall financial performance was achieved for companies in [[Denmark]].<ref>{{cite journal |doi=10.1108/02656710310493643 |title=Does ISO 9000 certification improve business performance? |year=2003 |last1=Chow-Chua |first1=Clare |last2=Goh |first2=Mark |last3=Wan |first3=Tan Boon |journal=International Journal of Quality & Reliability Management |volume=20 |issue=8 |pages=936}}</ref> Rajan and Tamimi (2003) showed that ISO 9001 certification resulted in superior stock market performance and suggested that shareholders were richly rewarded for the investment in an ISO 9001 system.<ref>{{cite journal |doi=10.3905/joi.2003.319536 |title=Payoff to ISO 9000 Registration |year=2003 |last1=Rajan |first1=Murli |last2=Tamimi |first2=Nabil |journal=The Journal of Investing |volume=12 |pages=71}}</ref>

While the connection between superior financial performance and ISO 9001 may be seen from the examples cited, there remains no proof of direct causation, though [[Longitudinal study|longitudinal studies]], such as those of Corbett ''et al.'' (2005)<ref name="Corbett, Montes-Sancho, Kirsch 2005"/> may suggest it. Other writers, such as Heras ''et al.'' (2002),<ref name="eps.udg.es"/> have suggested that while there is some evidence of this, the improvement is partly driven by the fact that there is a tendency for better performing companies to seek ISO 9001 certification.

The mechanism for improving results has also been the subject of much research. Lo ''et al.'' (2007) identified operational improvements (e.g., cycle time reduction, inventory reductions) as following from certification.<ref>{{Cite journal
| title = Impact of ISO 9000 on time-based performance: An event study
| url = http://www.waset.org/journals/waset/v30/v30-7.pdf
| year = 2007
| journal = World Academy of Science, Engineering and Technology
| pages = 35–40
| volume = 30
| issue = 7
| last1 = Lo | first1 = Chris K.Y.
| last2 = Yeung | first2 = Andy C.L.
| last3 = Cheng | first3 = T.C. Edwin}}</ref> Internal process improvements in organizations lead to externally observable improvements.<ref>{{cite journal |doi=10.1108/02656719710186867 |title=ISO 9000: Marketing motivations and benefits |year=1997 |last1=Buttle |first1=Francis |journal=International Journal of Quality & Reliability Management |volume=14 |issue=9 |pages=936–47}}</ref><ref>{{cite journal |doi=10.1108/02656710210415703 |title=Benefits of the ISO 9000:1994 system: Some considerations to reinforce competitive advantage |year=2002 |last1=Santos |first1=Leticia |last2=Escanciano |first2=Carmen |journal=International Journal of Quality & Reliability Management |volume=19 |issue=3 |pages=321–44}}</ref> The benefit of increased international trade and domestic market share, in addition to the internal benefits such as customer satisfaction, interdepartmental communications, work processes, and customer/supplier partnerships derived, far exceeds any and all initial investment.<ref name=Alcorn1995>{{cite journal |doi=10.1002/9780470314661.ch3 |chapter=The Benefits of ISO 9000 Certification |title=A Collection of Papers Presented at the 55th Conference on Glass Problems: Ceramic Engineering and Science Proceedings, Volume 16, Issue 2 |series=Ceramic Engineering and Science Proceedings |year=2008 |last1=Alcorn |first1=Janice E. |isbn=978-0-470-31466-1 |pages=15}}</ref>

==Global adoption==
The growth in ISO 9001 certification is shown in the table below. The worldwide total of ISO 9001 certificates can be found in the ISO Survey of 9001 in [http://www.iso.org/iso/survey2003.pdf 2003], [http://www.iso.org/iso/survey2007.pdf 2007], [http://www.iso.org/iso/survey2008.pdf 2008], [http://www.iso.org/iso/survey2009.pdf 2009], [http://www.iso.org/iso/iso-survey2010.pdf 2010], and [http://www.iso.org/iso/iso_survey2011_executive-summary.pdf 2011]

{| class="wikitable" style="text-align:center"
|+ Worldwide total of ISO 9001 - Quality Management Systems - Requirements certificates
! Dec 2000 !! Dec 2001 !! Dec 2002 !! Dec 2003 !! Dec 2004 !! Dec 2005 !! Dec 2006 !! Dec 2007 !! Dec 2008 !! Dec 2009 !! Dec 2010 !! Dec 2011
|-
| 457,834 || 510,349 || 561,767 || 497,919 || 660,132 || 773,867 || 896,929 || 951,486 || 982,832 || 1,064,785 || 1,118,510 || 1,111,698
|}Source: [http://www.iso.org/iso/home/standards/certification/iso-survey.htm ISO Survey 2011]

In recent years there has been a rapid growth in [[China]], which now accounts for approximately a quarter of the global certifications.

{| class="wikitable" style="text-align:right"
|+ Top 10 countries for ISO 9001 certificates (2010)
! scope="col" style="width:150px;"| Rank
! scope="col" style="width:150px;"| Country
! scope="col" style="width:150px;"| No. of certificates
|-
| 1 || China ||297,037
|-
| 2 || Italy ||138,892
|-
| 3 || Russian Federation || 62,265
|-
| 4 || Spain|| 59,854
|-
| 5 || Japan ||59,287
|-
| 6 || Germany || 50,583
|-
| 7 || United Kingdom || 44,849
|-
| 8 || India || 33,250
|-
| 9 || United States || 25,101
|-
| 10 || Korea, Republic of || 24,778

|}Source: [http://www.iso.org/iso/survey2010.pdf ISO Survey 2010]

<br>
{| class="wikitable" style="text-align:right"
|+ Top 10 countries for ISO 9001 certificates (2009)
! scope="col" style="width:150px;"| Rank
! scope="col" style="width:150px;"| Country
! scope="col" style="width:150px;"| No. of certificates
|-
| 1 || China || 257,076
|-
| 2 || Italy || 130,066
|-
| 3 || Japan || 68,484
|-
| 4 || Spain || 59,576
|-
| 5 || Russian Federation || 53,152
|-
| 6 || Germany || 47,156
|-
| 7 || United Kingdom || 41,193
|-
| 8 || India || 37,493
|-
| 9 || United States || 28,935
|-
| 10 || Korea, Republic of || 23,400
|}Source: [http://www.iso.org/iso/survey2009.pdf ISO Survey 2009]

==Contents of ISO 9001==
<!-- linked from redirect [[ISO 9001]] -->
[[File:ISO 9001 in Tsukiji.jpg|thumb|ISO 9001 certification of a fish wholesaler in [[Tsukiji]], [[Japan]].]]
'''''ISO 9001:2008 Quality management systems — Requirements''''' is a document of approximately 30 pages which is available from the national standards organization in each country. It is supplemented by two other standards: ISO 9000:2005 ''Quality management systems—Fundamentals and vocabulary'' and ISO 9004:2009 ''Managing for the sustained success of an organization—A quality management approach''. Only ISO 9001 is directly audited against for third party assessment purposes. The other two standards are supplementary and contain deeper information on how to sustain and improve quality management systems; they are therefore not used directly during third party assessment. Outline contents for ISO 9001 are as follows:

*Page iv: ''Foreword''
*Pages v to vii: Section 0 ''Intro''
*Pages 1 to 14: ''Requirements''
** Section 1: ''Scope''
** Section 2: ''Normative Reference''
** Section 3: ''Terms and definitions'' (specific to ISO 9001, not specified in ISO 9000)
** Section 4: ''Quality Management System''
** Section 5: ''Management Responsibility''
** Section 6: ''Resource Management''
** Section 7: ''Product Realization''
** Section 8: ''Measurement, analysis and improvement''
*Pages 15 to 22: Tables of Correspondence between ISO 9001 and other standards
*Page 23: ''Bibliography''

Before the certification body can issue or renew a certificate, the auditor must be satisfied that the company being assessed has implemented the requirements of sections 4 to 8. Sections 1 to 3 are not directly audited against, but because they provide context and definitions for the rest of the standard, their contents must be taken into account.

The standard specifies that the organization shall issue and maintain the following six documented procedures:
* Control of Documents (4.2.3)
* Control of Records (4.2.4)
* Internal Audits (8.2.2)
* Control of Nonconforming Product / Service (8.3)
* Corrective Action (8.5.2)
* Preventive Action (8.5.3)

In addition to these procedures, ISO 9001:2008 requires the organization to document any other procedures required for its effective operation. The standard also requires the organization to issue and communicate a documented [[quality policy]], a Quality Manual (which may or may not include the documented procedures) and numerous records, as specified throughout the standard.

===Numbering===

*4.2 Documentation requirements
*5 Management responsibility
*5.1 Management commitment
*5.2 Customer focus
*5.3 Quality policy
*5.4 Planning
*5.5 Responsibility, authority and communication
*5.6 Management review
*6.0 Resource management
*6.1 Provision of resources
*6.2 Human resources
*6.3 Work environment
*7 Product realization
*7.1 Planning of product realization
*7.2 Customer-related processes
*7.3 Design and development
*7.4 Purchasing
*7.5 Production and service provision
*7.6 Control of monitoring and measuring equipment
*8 Measurement, analysis and improvement
*8.1 General
*8.2 Monitoring and measurement
*8.3 Control of nonconforming product
*8.4 Analysis of data
*8.5 Improvement

===Summary of ISO 9001:2008 in informal language===
{{Multiple|
{{Original research|section|date=May 2013}}{{unreferenced|section|date=May 2014}}
}}

* The quality policy is a formal statement from management, closely linked to the business and marketing plan and to customer needs.
* The quality policy is understood and followed at all levels and by all employees. Each employee works towards measurable objectives.
* The business makes decisions about the quality system based on recorded data.
* The quality system is regularly [[auditing|audited]] and evaluated for conformance and effectiveness.
* Records show how and where raw materials and products were processed to allow products and problems to be traced to the source.

* The business determines customer requirements.
* The business has created systems for communicating with customers about product information, inquiries, contracts, orders, feedback, and complaints.
* When developing new products, the business plans the stages of development, with appropriate testing at each stage. It tests and documents whether the product meets design requirements, regulatory requirements, and user needs.
* The business regularly reviews performance through internal audits and meetings. The business determines whether the quality system is working and what improvements can be made. It has a documented procedure for internal audits.
* The business deals with past problems and potential problems. It keeps records of these activities and the resulting decisions, and monitors their effectiveness.
* The business has documented procedures for dealing with actual and potential nonconformances (problems involving suppliers, customers, or internal problems).
* The business:
*# Makes sure no one uses a bad product;
*# Determines what to do with a bad product;
*# Deals with the root cause of problems; and
*# Keeps records to use as a tool to improve the system.

==Certification==
[[International Organization for Standardization|ISO]] does not certify organizations itself. Numerous certification bodies exist, which audit organizations and, upon success, issue ISO 9001 compliance certificates. Although commonly referred to as "ISO 9000" certification, the actual standard to which an organization's quality management system can be certified is ISO 9001:2008. Many countries have formed [[accreditation]] bodies to authorize ("accredit") the certification bodies. Both the accreditation bodies and the certification bodies charge fees for their services. The various accreditation bodies have mutual agreements with each other to ensure that certificates issued by one of the [[Accredited Certification Bodies]] (CB) are accepted worldwide. Certification bodies themselves operate under another quality standard, ISO/IEC 17021,<ref>ISO/IEC 17021: "Conformity assessment. Requirements for bodies providing audit and certification of management systems" (2011)</ref> while accreditation bodies operate under ISO/IEC 17011.<ref>ISO/IEC 17011: "Conformity assessment. General requirements for accreditation bodies accrediting conformity assessment bodies" (2004).</ref>

An organization applying for ISO 9001 certification is audited based on an extensive sample of its sites, functions, products, services and processes. The auditor presents a list of problems (defined as "nonconformities", "observations", or "opportunities for improvement") to management. If there are no major nonconformities, the certification body will issue a certificate. Where major nonconformities are identified, the organization will present an improvement plan to the certification body (e.g., corrective action reports showing how the problems will be resolved); once the certification body is satisfied that the organization has carried out sufficient corrective action, it will issue a certificate. The certificate is limited by a certain scope (e.g., production of golf balls) and will display the addresses to which the certificate refers.

An ISO 9001 certificate is not a once-and-for-all award, but must be renewed at regular intervals recommended by the certification body, usually once every three years. There are no grades of competence within ISO 9001: either a company is certified (meaning that it is committed to the method and model of quality management described in the standard) or it is not. In this respect, ISO 9001 certification contrasts with measurement-based quality systems.

==Evolution of ISO 9000 standards==
The ISO 9000 standard is continually being revised by standing technical committees and advisory groups, who receive feedback from those professionals who are implementing the standard.

===1987 version===
ISO 9000:1987 had the same structure as the UK Standard BS 5750, with three "models" for quality management systems, the selection of which was based on the scope of activities of the organization:
*ISO 9001:1987 ''Model for quality assurance in design, development, production, installation, and servicing'' was for companies and organizations whose activities included the creation of new products.
*ISO 9002:1987 ''Model for quality assurance in production, installation, and servicing'' had basically the same material as ISO 9001 but without covering the creation of new products.
*ISO 9003:1987 ''Model for quality assurance in final inspection and test'' covered only the final inspection of finished product, with no concern for how the product was produced.
''ISO 9000:1987'' was also influenced by existing U.S. and other [[Defense Standard]]s ("MIL SPECS"), and so was well-suited to manufacturing. The emphasis tended to be placed on conformance with procedures rather than the overall process of management, which was likely the actual intent.{{Citation needed|date=July 2007}}

===1994 version===
''ISO 9000:1994'' emphasized [[quality assurance]] via preventive actions, instead of just checking final product, and continued to require evidence of compliance with documented procedures. As with the first edition, the down-side was that companies tended to implement its requirements by creating shelf-loads of procedure manuals, and becoming burdened with an ISO bureaucracy. In some companies, adapting and improving processes could actually be impeded by the quality system.{{Citation needed|date=July 2007}}

===2000 version===
<!-- Deleted image removed: [[File:apcer.png|250px|thumb|right|The Portuguese [[ISO 9001]] certification image]] -->
''ISO 9001:2000'' replaced all three former standards of 1994 issue, ''ISO 9001'', ''ISO 9002'' and ''ISO 9003''. Design and development procedures were required only if a company does in fact engage in the creation of new products. The 2000 version sought to make a radical change in thinking by actually placing the concept of [[process management]] front and center ("Process management" was the monitoring and optimisation of a company's tasks and activities, instead of just inspection of the final product). The 2000 version also demanded involvement by upper executives in order to integrate quality into the business system and avoid delegation of quality functions to junior administrators. Another goal was to improve effectiveness via process performance metrics: numerical measurement of the effectiveness of tasks and activities. Expectations of continual [[process improvement]] and tracking customer satisfaction were made explicit.

ISO 9000 Requirements include:
* Approve documents before distribution;
* Provide correct version of documents at points of use;
* Use your records to prove that requirements have been met; and
* Develop a procedure to control your records.

===2008 version===

ISO 9001:2008 in essence re-narrates ISO 9001:2000. The 2008 version only introduced clarifications to the existing requirements of ISO 9001:2000 and some changes intended to improve consistency with [[ISO 14000|ISO 14001:2004]]. There were no new requirements. For example, in ISO 9001:2008, a quality management system being upgraded just needs to be checked to see if it is following the clarifications introduced in the amended version.

ISO 9001 is supplemented directly by two other standards of the family:

* ISO 9000:2005 "Quality management systems. Fundamentals and vocabulary"
* ISO 9004:2009 "Managing for the sustained success of an organization. A quality management approach"
Other standards, like [[ISO 19011]] and the ISO 10000 series, may also be used for specific parts of the quality system.

===Forthcoming 2015 version===
A next version of the standard is expected to be published in December 2015, if the ISO members vote favorably in March 2015.<ref>{{cite web
|url=http://www.iso.org/iso/home/news_index/news_archive/news.htm?refid=Ref1633
|title=ISO 9001:2015 and beyond - Preparing for the next 25 years of quality management standards |publisher=ISO |author=Nigel H. Croft |year=2012 }}</ref>

==Auditing==
Two types of [[auditing]] are required to become registered to the standard: auditing by an external [[certification body]] ([[External Audit|external audit]]) and audits by internal staff trained for this process ([[internal audit]]s). The aim is a continual process of review and assessment to verify that the system is working as it is supposed to; to find out where it can improve; and to correct or prevent problems identified. It is considered healthier for internal auditors to audit outside their usual management line, so as to bring a degree of independence to their judgments.

Under the 1994 standard, the auditing process could be adequately addressed by performing "compliance auditing":

* Tell me what you do ''(describe the business process)''
* Show me where it says that ''(reference the procedure manuals)''
* Prove that this is what happened ''(exhibit evidence in documented records)''

The 2000 standard uses a different approach. Auditors are expected to go beyond mere auditing for rote compliance by focusing on risk, status, and importance. This means they are expected to make more judgments on what is effective, rather than merely adhering to what is formally prescribed. The difference from the previous standard can be explained thus:

:Under the 1994 version, the question was broad: "Are you doing what the manual says you should be doing?", whereas under the 2000 version, the questions are more specific: "Will this process help you achieve your stated objectives? Is it a good process or is there a way to do it better?"

==Industry-specific interpretations==
The ISO 9001 standard is generalized and abstract; its parts must be carefully interpreted to make sense within a particular organization. [[Software development process|Developing software]] is not like making [[cheese]] or offering [[counseling]] services, yet the ISO 9001 guidelines, because they are business management guidelines, can be applied to each of these. Diverse organizations&mdash;police departments (United States), professional [[soccer]] teams (Mexico), and city councils (UK)&mdash;have successfully implemented ISO 9001:2000 systems.

Over time, various industry sectors have wanted to standardize their interpretations of the guidelines within their own marketplace. This is partly to ensure that their versions of ISO 9000 have their specific requirements, but also to try and ensure that more appropriately trained and experienced auditors are sent to assess them.

* The '''[[TickIT]]''' guidelines are an interpretation of ISO 9000 produced by the UK Board of Trade to suit the processes of the information technology industry, especially software development.
* '''[[AS9000]]''' is the Aerospace Basic Quality System Standard, an interpretation developed by major aerospace manufacturers. Those major manufacturers include AlliedSignal, Allison Engine, Boeing, General Electric Aircraft Engines, Lockheed-Martin, McDonnell Douglas, Northrop Grumman, Pratt & Whitney, Rockwell-Collins, Sikorsky Aircraft, and Sundstrand. The current version is '''[[AS9100|AS9100C]]'''.
* '''PS 9000''' * '''QS 9000''' is an interpretation agreed upon by major automotive manufacturers (GM, Ford, Chrysler). It includes techniques such as [[failure mode and effects analysis|FMEA]] and [[Advanced Product Quality Planning|APQP]]. QS 9000 is now replaced by ISO/TS 16949.
* '''[[ISO/TS 16949|ISO/TS 16949:2009]]''' is an interpretation agreed upon by major automotive manufacturers (American and European manufacturers); the latest version is based on ISO 9001:2008. The emphasis on a process approach is stronger than in ISO 9001:2008. ISO/TS 16949:2009 contains the full text of ISO 9001:2008 and automotive industry-specific requirements.
* '''[[TL 9000]]''' is the Telecom Quality Management and Measurement System Standard, an interpretation developed by the telecom consortium, [http://www.questforum.org QuEST Forum]. In 1998 QuEST Forum developed the TL 9000 Quality Management System to meet the supply chain quality requirements of the worldwide telecommunications industry. The TL 9000 standard is made up of two handbooks: the QMS Requirements Handbook, and the QMS Measurement Handbook. The current versions of the Requirements and Measurements Handbooks are 5.0. Unlike ISO 9001 or other sector-specific standards, TL 9000 includes standardized product and process measurements that must be reported into a central repository, which allow organizations to benchmark their performance in key process areas against peer organizations. It is important to note that TL 9000 R5.0 contains the full text of ISO 9001:2008.
* '''[[ISO 13485:2012]]''' is the medical industry's equivalent of ISO 9001:2008. Whereas the standards it replaces were interpretations of how to apply ISO 9001 and ISO 9002 to medical devices, ISO 13485:2003 is a stand-alone standard. Because ISO 13485 is relevant to medical devices manufacturers (unlike ISO 9001, which is applicable to any industry), and because of the differences between the two standards relating to continual improvement, compliance with ISO 13485 does not necessarily mean compliance with ISO 9001:2008 (and vice versa).
* '''[[ISO/IEC 90003:2004]]''' provides guidelines for the application of ISO 9001:2000 to computer software.
* '''[[ISO/TS 29001]]''' is quality management system requirements for the design, development, production, installation, and service of products for the petroleum, petrochemical, and natural gas industries. It is equivalent to API Spec Q1 without the Monogram annex.

==Effectiveness==
{{Original research|section|date=May 2013}}

The debate on the effectiveness of ISO 9000 commonly centers on the following questions:
#Are the quality principles in ISO 9001:2000 of value? (Note that the version date is important; in the 2000 version ISO attempted to address many concerns and criticisms of ISO 9000:1994).
#Does it help to implement an ISO 9001:2000-compliant quality management system?
#Does it help to obtain ISO 9001:2000 certification?

Effectiveness of the ISO system being implemented depends on a number of factors, the most significant of which are:
#Commitment of senior management to monitor, control, and improve quality. Organizations that implement an ISO system without this desire and commitment often take the cheapest road to get a certificate on the wall and ignore problem areas uncovered in the audits.
#How well the ISO system integrates into current business practices. Many organizations that implement ISO try to make their system fit into a cookie-cutter quality manual instead of creating a manual that documents existing practices and only adds new processes to meet the ISO standard when necessary.
#How well the ISO system focuses on improving the customer experience. The broadest definition of quality is "Whatever the customer perceives good quality to be." This means that a company doesn't necessarily have to make a product that never fails; some customers will have a higher tolerance for product failures if they always receive shipments on-time or have a positive experience in some other dimension of customer service. An ISO system should take into account all areas of the customer experience and the industry expectations, and seek to improve them on a continual basis. This means taking into account all processes that deal with the three stakeholders (customers, suppliers, and organization); only then will a company be able to sustain improvements in the customer's experience.
#How well the auditor finds and communicates areas of improvement. While ISO auditors may not provide consulting to the clients they audit, there is the potential for auditors to point out areas of improvement. Many auditors simply rely on submitting reports that indicate compliance or non-compliance with the appropriate section of the standard; however, to most executives, this is like speaking a foreign language. Auditors that can clearly identify and communicate areas of improvement in language and terms executive management understands facilitate action on improvement initiatives by the companies they audit. When management doesn't understand why they were non-compliant and the business implications associated with non-compliance, they simply ignore the reports and focus on what they do understand.

===Advantages===
It is widely acknowledged that proper quality management improves business, often having a positive effect on investment, market share, sales growth, sales margins, competitive advantage, and avoidance of litigation.<ref name="sroufe">Sroufe, Robert and Sime Curkovic, "An examination of ISO 9000:2000 and supply chain quality assurance." Journal of Operations Management, Volume 26, Issue 4, July 2008, Pages 503-520</ref> The quality principles in ISO 9000:2000 are also sound, according to Wade <ref name="wade"/> and Barnes, who says that "ISO 9000 guidelines provide a comprehensive model for quality management systems that can make any company competitive".<ref name="barnes"/> Sroufe and Curkovic, (2008) found benefits ranging from registration required to remain part of a supply base, better documentation, to cost benefits, and improved involvement and communication with management.<ref name="sroufe"/> Implementing ISO often gives the following advantages:

#Creates a more efficient, effective operation
#Increases customer satisfaction and retention
#Reduces audits
#Enhances marketing
#Improves employee motivation, awareness, and morale
# Promotes international trade
#Increases profit
#Reduces waste and increases productivity
#Common tool for standardization

===Criticisms of ISO 9000===

A common criticism of ISO 9000 and 9001 is the amount of money, time, and paperwork required for registration.<ref name="clifford" /> Dalgleish cites the "inordinate and often unnecessary paperwork burden" of ISO, and says that "quality managers feel that ISO's overhead and paperwork are excessive and extremely inefficient".<ref name= "dalgleish 2003">Scott Dalgleish, "[http://www.qualitymag.com/Articles/Column/562979be55c38010VgnVCM100000f932a8c0 ISO 9000: More Hindrance than Help]" ''Quality Magazine'' May 5, 2003 (accessed 24 Mar 2012).</ref>

According to Barnes, "Opponents claim that it is only for documentation. Proponents believe that if a company has documented its quality systems, then most of the paperwork has already been completed".<ref name="barnes">[http://www.allbusiness.com/specialty-businesses/713376-1.html "Good Business Sense Is the Key to Confronting ISO 9000"] Frank Barnes in ''Review of Business'', Spring 2000.</ref> Wilson suggests that ISO standards "elevate inspection of the correct procedures over broader aspects of quality", and therefore, "the workplace becomes oppressive and quality is not improved".<ref name="wilson" />

One study showing reasons for not adopting this standard include the risks and uncertainty of not knowing if there are direct relationships to improved quality, and what kind and how many resources will be needed. Additional risks include how much certification will cost, increased bureaucratic processes and risk of poor company image if the certification process fails.<ref name="sroufe"/> According to [[John Seddon]], ISO 9001 promotes specification, control, and procedures rather than understanding and improvement.<ref name="seddon" /> Wade argues that ISO 9000 is effective as a guideline, but that promoting it as a standard "helps to mislead companies into thinking that certification means better quality, ... [undermining] the need for an organization to set its own quality standards".<ref name="wade">[http://www.bin.co.uk/IMS_May_2002.pdf "Is ISO 9000 really a standard?"] Jim Wade, ISO Management Systems – May–June 2002.</ref> In short, Wade argues that reliance on the specifications of ISO 9001 does not guarantee a successful quality system.

The standard is seen as especially prone to failure when a company is interested in certification before quality.<ref name="seddon"/> Certifications are in fact often based on customer contractual requirements rather than a desire to actually improve quality.<ref name="barnes"/><ref name="henricks"/> "If you just want the certificate on the wall, chances are you will create a paper system that doesn't have much to do with the way you actually run your business", said ISO's Roger Frost.<ref name="henricks">[http://www.entrepreneur.com/magazine/entrepreneur/2001/december/46342.html "ISO a GO-Go."] Mark Henricks. ''Entrepreneur Magazine'' Dec 2001.</ref> Certification by an independent auditor is often seen as the problem area, and according to Barnes, "has become a vehicle to increase consulting services".<ref name="barnes"/>

Dalgleish argues that while "quality has a positive effect on return on investment, market share, sales growth, better sales margins and competitive advantage", that "taking a quality approach is unrelated to ISO 9000 registration".<ref name= "dalgleish 2005">Scott Dalgleish, [http://www.qualitymag.com/CDA/Archives/17062620c7c38010VgnVCM100000f932a8c0 "Probing the Limits: ISO 9001 Proves Ineffective"], ''Quality Magazine'' April 1, 2005 (accessed 24 Mar 2012).</ref> In fact, ISO itself advises that ISO 9001 can be implemented without certification, simply for the quality benefits that can be achieved.<ref name=isosurvey>[http://www.iso.org/iso/en/iso9000-14000/pdf/survey2005.pdf ''The ISO Survey – 2005''] (abridged version, PDF, 3 MB), ISO, 2005.</ref>

Abrahamson argues that fashionable management discourse such as [[Quality Circles]] tends to follow a [[Enterprise life cycle|lifecycle]] in the form of a [[Normal distribution|bell curve]], possibly indicating a [[management fad]].<ref>{{cite journal |jstor=258636 |pages=254–285 |last1=Abrahamson |first1=E. |title=Management Fashion |volume=21 |issue=1 |journal=The Academy of Management Review |year=1996 |doi=10.5465/amr.1996.9602161572}}</ref>

Pickrell argues that ISO systems merely gauge whether the processes are being followed. It does not gauge how good the processes are or whether the correct parameters are being measured and controlled to ensure quality. Furthermore, when unique technical solutions are involved in the creation of a new part, ISO does not validate the robustness of the technical solution which is a key part of advanced quality planning. It is not unheard of for an ISO-certified plant to display poor quality performance due to poor process selection and/or poor technical solutions.

==See also==
* [[Conformity assessment]]—Containing [[International Organization for Standardization|ISO]] published standards
* [[ISO 10006]]—Quality management—Guidelines to quality management in projects
* [[ISO 14001]]—Environmental management standards
* [[ISO 19011]]—Guidelines for quality management systems auditing and environmental management systems auditing
* [[ISO/TS 16949]]—Quality management system requirements for automotive-related products suppliers
* [[ISO/IEC 27001]]—Information security management
* [[ISO 39001]]—Road traffic safety management
* [[ISO 50001]]—Energy Audit
* [[AS 9100]] - aerospace industry implementation of ISO 9000/1
* [[List of ISO standards]]
* [[ISO/TC 176]]
* [[Quality management system]]
* [[Test management]]
* [[Verification and Validation]]
* [[International Organization for Standardization]]

==References==
{{reflist|colwidth=30em}}

==Further reading==
*Bamford, Robert; Deibler, William (2003). ''ISO 9001: 2000 for Software and Systems Providers: An Engineering Approach'' (1st ed.). CRC-Press. ISBN 0-8493-2063-1, ISBN 978-0-8493-2063-7
*{{cite journal |doi=10.1109/TEM.2004.830864 |title=When Does the ISO 9000 Quality Assurance Standard Lead to Performance Improvement? Assimilation and Going Beyond |year=2004 |last1=Naveh |first1=E. |last2=Marcus |first2=A. |journal=IEEE Transactions on Engineering Management |volume=51 |issue=3 |pages=352}}
*http://www.iso.org/iso/survey2007.pdf - An abstract
Boohe 2007's ISO survey of certificates.
*http://www.iso.org/iso/survey2008.pdf - An abstract of the 2008's ISO survey of certificates.

==External links==
<!-- Please, no commercial links here. Thanks! -->
<!--======================== {{No more links}} ============================
| PLEASE BE CAUTIOUS IN ADDING MORE LINKS TO THIS ARTICLE. Wikipedia |
| is not a collection of links nor should it be used for advertising. |
| |
| Excessive or inappropriate links WILL BE DELETED. |
| See [[Wikipedia:External links]] & [[Wikipedia:Spam]] for details. |
| |
| If there are already plentiful links, please propose additions or |
| replacements on this article's discussion page, or submit your link |
| to the relevant category at the Open Directory Project (dmoz.org) |
| and link back to that category using the {{dmoz}} template. |
======================= {{No more links}} =============================-->
*{{dmoz|Science/Reference/Standards/Individual_Standards/ISO/ISO_9000|ISO 9000}}.
*[http://www.iso.org/iso/iso_catalogue/management_and_leadership_standards.htm ISO Management and leadership standards].
*[http://www.iso.org International Organization for Standardization].
*[http://www.iso.org/iso/home/standards/management-standards/iso_9000.htm General information on ISO 9000 and ISO 9001]
*[http://www.9001council.org Information on ISO 9001 Implementation]
*[http://www.tc176.org/ ISO's Technical Committee 176] on Quality Management and Quality Assurance.
**[http://www.iso.org/tc176/sc2 Technical Committee No. 176, Sub-committee No. 2], which is responsible for developing ISO 9000 standards.
**[http://www.tc176.org/About176.asp Basic info] on ISO 9000 development.
**[http://www.tc176.org/FAQ.asp ISO 9000 FAQs].

{{ISO standards}}


{{DEFAULTSORT:Iso 9000}}
{{DEFAULTSORT:Iso 9000}}

Revision as of 04:37, 7 July 2014

ISO 9000 is a series of standards, developed and published by the International Organization for Standardization (ISO), that define, establish, and maintain a quality assurance system for manufacturing and service industries.[1][2] The standards are available through national standards bodies. ISO 9000 deals with the fundamentals of quality management systems,[3] including the eight management principles upon which the family of standards is based.[3][4] ISO 9001 deals with the requirements that organizations wishing to meet the standard must fulfill.[5]

Third-party certification bodies provide independent confirmation that organizations meet the requirements of ISO 9001. Over a million organizations worldwide[6] are independently certified, making ISO 9001 one of the most widely used management tools in the world today. Despite widespread use, the ISO certification process has been criticized[7][8] as being wasteful and not being useful for all organizations.[9][10]

Background

ISO 9000 was first published in 1987.[11] It was based on the BS 5750 series of standards from BSI that were proposed to ISO in 1979.[12] However, its history can be traced back some twenty years before that, to the publication of the United States Department of Defense MIL-Q-9858 standard in 1959. MIL-Q-9858 was revised into the NATO AQAP series of standards in 1969, which in turn were revised into the BS 5179 series of guidance standards published in 1974, and finally revised into the BS 5750 series of requirements standards in 1979 before being submitted to ISO.

BSI has been certifying organizations for their quality management systems since 1978. Its first certification (FM 00001) is still extant and held by Tarmac Limited, a successor to the original company which held this certificate.[13] Today BSI claims to certify organizations at nearly 70,000 sites globally.[14]

Reasons for use

The global adoption of ISO 9001 may be attributable to a number of factors. A number of major purchasers require their suppliers to hold ISO 9001 certification. In addition to several stakeholders' benefits, a number of studies have identified significant financial benefits for organizations certified to ISO 9001, with a 2011 survey from the British Assessment Bureau showing 44% of their certified clients had won new business.[15] Corbett et al. showed that certified organizations achieved superior return on assets[16] compared to otherwise similar organizations without certification.[17] Heras et al. found similarly superior performance[18] and demonstrated that this was statistically significant and not a function of organization size.[19] Naveha and Marcus claimed that implementing ISO 9001 led to superior operational performance in the U.S. automotive industry.[20] Sharma identified similar improvements in operating performance and linked this to superior financial performance.[21] Chow-Chua et al. showed better overall financial performance was achieved for companies in Denmark.[22] Rajan and Tamimi (2003) showed that ISO 9001 certification resulted in superior stock market performance and suggested that shareholders were richly rewarded for the investment in an ISO 9001 system.[23]

While the connection between superior financial performance and ISO 9001 may be seen from the examples cited, there remains no proof of direct causation, though longitudinal studies, such as those of Corbett et al. (2005)[17] may suggest it. Other writers, such as Heras et al. (2002),[19] have suggested that while there is some evidence of this, the improvement is partly driven by the fact that there is a tendency for better performing companies to seek ISO 9001 certification.

The mechanism for improving results has also been the subject of much research. Lo et al. (2007) identified operational improvements (e.g., cycle time reduction, inventory reductions) as following from certification.[24] Internal process improvements in organizations lead to externally observable improvements.[25][26] The benefit of increased international trade and domestic market share, in addition to the internal benefits such as customer satisfaction, interdepartmental communications, work processes, and customer/supplier partnerships derived, far exceeds any and all initial investment.[27]

Global adoption

The growth in ISO 9001 certification is shown in the table below. The worldwide total of ISO 9001 certificates can be found in the ISO Survey of 9001 in 2003, 2007, 2008, 2009, 2010, and 2011

Worldwide total of ISO 9001 - Quality Management Systems - Requirements certificates
Dec 2000 Dec 2001 Dec 2002 Dec 2003 Dec 2004 Dec 2005 Dec 2006 Dec 2007 Dec 2008 Dec 2009 Dec 2010 Dec 2011
457,834 510,349 561,767 497,919 660,132 773,867 896,929 951,486 982,832 1,064,785 1,118,510 1,111,698

Source: ISO Survey 2011

In recent years there has been a rapid growth in China, which now accounts for approximately a quarter of the global certifications.

Top 10 countries for ISO 9001 certificates (2010)
Rank Country No. of certificates
1 China 297,037
2 Italy 138,892
3 Russian Federation 62,265
4 Spain 59,854
5 Japan 59,287
6 Germany 50,583
7 United Kingdom 44,849
8 India 33,250
9 United States 25,101
10 Korea, Republic of 24,778

Source: ISO Survey 2010


Top 10 countries for ISO 9001 certificates (2009)
Rank Country No. of certificates
1 China 257,076
2 Italy 130,066
3 Japan 68,484
4 Spain 59,576
5 Russian Federation 53,152
6 Germany 47,156
7 United Kingdom 41,193
8 India 37,493
9 United States 28,935
10 Korea, Republic of 23,400

Source: ISO Survey 2009

Contents of ISO 9001

ISO 9001 certification of a fish wholesaler in Tsukiji, Japan.

ISO 9001:2008 Quality management systems — Requirements is a document of approximately 30 pages which is available from the national standards organization in each country. It is supplemented by two other standards: ISO 9000:2005 Quality management systems—Fundamentals and vocabulary and ISO 9004:2009 Managing for the sustained success of an organization—A quality management approach. Only ISO 9001 is directly audited against for third party assessment purposes. The other two standards are supplementary and contain deeper information on how to sustain and improve quality management systems; they are therefore not used directly during third party assessment. Outline contents for ISO 9001 are as follows:

  • Page iv: Foreword
  • Pages v to vii: Section 0 Intro
  • Pages 1 to 14: Requirements
    • Section 1: Scope
    • Section 2: Normative Reference
    • Section 3: Terms and definitions (specific to ISO 9001, not specified in ISO 9000)
    • Section 4: Quality Management System
    • Section 5: Management Responsibility
    • Section 6: Resource Management
    • Section 7: Product Realization
    • Section 8: Measurement, analysis and improvement
  • Pages 15 to 22: Tables of Correspondence between ISO 9001 and other standards
  • Page 23: Bibliography

Before the certification body can issue or renew a certificate, the auditor must be satisfied that the company being assessed has implemented the requirements of sections 4 to 8. Sections 1 to 3 are not directly audited against, but because they provide context and definitions for the rest of the standard, their contents must be taken into account.

The standard specifies that the organization shall issue and maintain the following six documented procedures:

  • Control of Documents (4.2.3)
  • Control of Records (4.2.4)
  • Internal Audits (8.2.2)
  • Control of Nonconforming Product / Service (8.3)
  • Corrective Action (8.5.2)
  • Preventive Action (8.5.3)

In addition to these procedures, ISO 9001:2008 requires the organization to document any other procedures required for its effective operation. The standard also requires the organization to issue and communicate a documented quality policy, a Quality Manual (which may or may not include the documented procedures) and numerous records, as specified throughout the standard.

Numbering

  • 4.2 Documentation requirements
  • 5 Management responsibility
  • 5.1 Management commitment
  • 5.2 Customer focus
  • 5.3 Quality policy
  • 5.4 Planning
  • 5.5 Responsibility, authority and communication
  • 5.6 Management review
  • 6.0 Resource management
  • 6.1 Provision of resources
  • 6.2 Human resources
  • 6.3 Work environment
  • 7 Product realization
  • 7.1 Planning of product realization
  • 7.2 Customer-related processes
  • 7.3 Design and development
  • 7.4 Purchasing
  • 7.5 Production and service provision
  • 7.6 Control of monitoring and measuring equipment
  • 8 Measurement, analysis and improvement
  • 8.1 General
  • 8.2 Monitoring and measurement
  • 8.3 Control of nonconforming product
  • 8.4 Analysis of data
  • 8.5 Improvement

Summary of ISO 9001:2008 in informal language

  • The quality policy is a formal statement from management, closely linked to the business and marketing plan and to customer needs.
  • The quality policy is understood and followed at all levels and by all employees. Each employee works towards measurable objectives.
  • The business makes decisions about the quality system based on recorded data.
  • The quality system is regularly audited and evaluated for conformance and effectiveness.
  • Records show how and where raw materials and products were processed to allow products and problems to be traced to the source.
  • The business determines customer requirements.
  • The business has created systems for communicating with customers about product information, inquiries, contracts, orders, feedback, and complaints.
  • When developing new products, the business plans the stages of development, with appropriate testing at each stage. It tests and documents whether the product meets design requirements, regulatory requirements, and user needs.
  • The business regularly reviews performance through internal audits and meetings. The business determines whether the quality system is working and what improvements can be made. It has a documented procedure for internal audits.
  • The business deals with past problems and potential problems. It keeps records of these activities and the resulting decisions, and monitors their effectiveness.
  • The business has documented procedures for dealing with actual and potential nonconformances (problems involving suppliers, customers, or internal problems).
  • The business:
    1. Makes sure no one uses a bad product;
    2. Determines what to do with a bad product;
    3. Deals with the root cause of problems; and
    4. Keeps records to use as a tool to improve the system.

Certification

ISO does not certify organizations itself. Numerous certification bodies exist, which audit organizations and, upon success, issue ISO 9001 compliance certificates. Although commonly referred to as "ISO 9000" certification, the actual standard to which an organization's quality management system can be certified is ISO 9001:2008. Many countries have formed accreditation bodies to authorize ("accredit") the certification bodies. Both the accreditation bodies and the certification bodies charge fees for their services. The various accreditation bodies have mutual agreements with each other to ensure that certificates issued by one of the Accredited Certification Bodies (CB) are accepted worldwide. Certification bodies themselves operate under another quality standard, ISO/IEC 17021,[28] while accreditation bodies operate under ISO/IEC 17011.[29]

An organization applying for ISO 9001 certification is audited based on an extensive sample of its sites, functions, products, services and processes. The auditor presents a list of problems (defined as "nonconformities", "observations", or "opportunities for improvement") to management. If there are no major nonconformities, the certification body will issue a certificate. Where major nonconformities are identified, the organization will present an improvement plan to the certification body (e.g., corrective action reports showing how the problems will be resolved); once the certification body is satisfied that the organization has carried out sufficient corrective action, it will issue a certificate. The certificate is limited by a certain scope (e.g., production of golf balls) and will display the addresses to which the certificate refers.

An ISO 9001 certificate is not a once-and-for-all award, but must be renewed at regular intervals recommended by the certification body, usually once every three years. There are no grades of competence within ISO 9001: either a company is certified (meaning that it is committed to the method and model of quality management described in the standard) or it is not. In this respect, ISO 9001 certification contrasts with measurement-based quality systems.

Evolution of ISO 9000 standards

The ISO 9000 standard is continually being revised by standing technical committees and advisory groups, who receive feedback from those professionals who are implementing the standard.

1987 version

ISO 9000:1987 had the same structure as the UK Standard BS 5750, with three "models" for quality management systems, the selection of which was based on the scope of activities of the organization:

  • ISO 9001:1987 Model for quality assurance in design, development, production, installation, and servicing was for companies and organizations whose activities included the creation of new products.
  • ISO 9002:1987 Model for quality assurance in production, installation, and servicing had basically the same material as ISO 9001 but without covering the creation of new products.
  • ISO 9003:1987 Model for quality assurance in final inspection and test covered only the final inspection of finished product, with no concern for how the product was produced.

ISO 9000:1987 was also influenced by existing U.S. and other Defense Standards ("MIL SPECS"), and so was well-suited to manufacturing. The emphasis tended to be placed on conformance with procedures rather than the overall process of management, which was likely the actual intent.[citation needed]

1994 version

ISO 9000:1994 emphasized quality assurance via preventive actions, instead of just checking final product, and continued to require evidence of compliance with documented procedures. As with the first edition, the down-side was that companies tended to implement its requirements by creating shelf-loads of procedure manuals, and becoming burdened with an ISO bureaucracy. In some companies, adapting and improving processes could actually be impeded by the quality system.[citation needed]

2000 version

ISO 9001:2000 replaced all three former standards of 1994 issue, ISO 9001, ISO 9002 and ISO 9003. Design and development procedures were required only if a company does in fact engage in the creation of new products. The 2000 version sought to make a radical change in thinking by actually placing the concept of process management front and center ("Process management" was the monitoring and optimisation of a company's tasks and activities, instead of just inspection of the final product). The 2000 version also demanded involvement by upper executives in order to integrate quality into the business system and avoid delegation of quality functions to junior administrators. Another goal was to improve effectiveness via process performance metrics: numerical measurement of the effectiveness of tasks and activities. Expectations of continual process improvement and tracking customer satisfaction were made explicit.

ISO 9000 Requirements include:

  • Approve documents before distribution;
  • Provide correct version of documents at points of use;
  • Use your records to prove that requirements have been met; and
  • Develop a procedure to control your records.

2008 version

ISO 9001:2008 in essence re-narrates ISO 9001:2000. The 2008 version only introduced clarifications to the existing requirements of ISO 9001:2000 and some changes intended to improve consistency with ISO 14001:2004. There were no new requirements. For example, in ISO 9001:2008, a quality management system being upgraded just needs to be checked to see if it is following the clarifications introduced in the amended version.

ISO 9001 is supplemented directly by two other standards of the family:

  • ISO 9000:2005 "Quality management systems. Fundamentals and vocabulary"
  • ISO 9004:2009 "Managing for the sustained success of an organization. A quality management approach"

Other standards, like ISO 19011 and the ISO 10000 series, may also be used for specific parts of the quality system.

Forthcoming 2015 version

A next version of the standard is expected to be published in December 2015, if the ISO members vote favorably in March 2015.[30]

Auditing

Two types of auditing are required to become registered to the standard: auditing by an external certification body (external audit) and audits by internal staff trained for this process (internal audits). The aim is a continual process of review and assessment to verify that the system is working as it is supposed to; to find out where it can improve; and to correct or prevent problems identified. It is considered healthier for internal auditors to audit outside their usual management line, so as to bring a degree of independence to their judgments.

Under the 1994 standard, the auditing process could be adequately addressed by performing "compliance auditing":

  • Tell me what you do (describe the business process)
  • Show me where it says that (reference the procedure manuals)
  • Prove that this is what happened (exhibit evidence in documented records)

The 2000 standard uses a different approach. Auditors are expected to go beyond mere auditing for rote compliance by focusing on risk, status, and importance. This means they are expected to make more judgments on what is effective, rather than merely adhering to what is formally prescribed. The difference from the previous standard can be explained thus:

Under the 1994 version, the question was broad: "Are you doing what the manual says you should be doing?", whereas under the 2000 version, the questions are more specific: "Will this process help you achieve your stated objectives? Is it a good process or is there a way to do it better?"

Industry-specific interpretations

The ISO 9001 standard is generalized and abstract; its parts must be carefully interpreted to make sense within a particular organization. Developing software is not like making cheese or offering counseling services, yet the ISO 9001 guidelines, because they are business management guidelines, can be applied to each of these. Diverse organizations—police departments (United States), professional soccer teams (Mexico), and city councils (UK)—have successfully implemented ISO 9001:2000 systems.

Over time, various industry sectors have wanted to standardize their interpretations of the guidelines within their own marketplace. This is partly to ensure that their versions of ISO 9000 have their specific requirements, but also to try and ensure that more appropriately trained and experienced auditors are sent to assess them.

  • The TickIT guidelines are an interpretation of ISO 9000 produced by the UK Board of Trade to suit the processes of the information technology industry, especially software development.
  • AS9000 is the Aerospace Basic Quality System Standard, an interpretation developed by major aerospace manufacturers. Those major manufacturers include AlliedSignal, Allison Engine, Boeing, General Electric Aircraft Engines, Lockheed-Martin, McDonnell Douglas, Northrop Grumman, Pratt & Whitney, Rockwell-Collins, Sikorsky Aircraft, and Sundstrand. The current version is AS9100C.
  • PS 9000 * QS 9000 is an interpretation agreed upon by major automotive manufacturers (GM, Ford, Chrysler). It includes techniques such as FMEA and APQP. QS 9000 is now replaced by ISO/TS 16949.
  • ISO/TS 16949:2009 is an interpretation agreed upon by major automotive manufacturers (American and European manufacturers); the latest version is based on ISO 9001:2008. The emphasis on a process approach is stronger than in ISO 9001:2008. ISO/TS 16949:2009 contains the full text of ISO 9001:2008 and automotive industry-specific requirements.
  • TL 9000 is the Telecom Quality Management and Measurement System Standard, an interpretation developed by the telecom consortium, QuEST Forum. In 1998 QuEST Forum developed the TL 9000 Quality Management System to meet the supply chain quality requirements of the worldwide telecommunications industry. The TL 9000 standard is made up of two handbooks: the QMS Requirements Handbook, and the QMS Measurement Handbook. The current versions of the Requirements and Measurements Handbooks are 5.0. Unlike ISO 9001 or other sector-specific standards, TL 9000 includes standardized product and process measurements that must be reported into a central repository, which allow organizations to benchmark their performance in key process areas against peer organizations. It is important to note that TL 9000 R5.0 contains the full text of ISO 9001:2008.
  • ISO 13485:2012 is the medical industry's equivalent of ISO 9001:2008. Whereas the standards it replaces were interpretations of how to apply ISO 9001 and ISO 9002 to medical devices, ISO 13485:2003 is a stand-alone standard. Because ISO 13485 is relevant to medical devices manufacturers (unlike ISO 9001, which is applicable to any industry), and because of the differences between the two standards relating to continual improvement, compliance with ISO 13485 does not necessarily mean compliance with ISO 9001:2008 (and vice versa).
  • ISO/IEC 90003:2004 provides guidelines for the application of ISO 9001:2000 to computer software.
  • ISO/TS 29001 is quality management system requirements for the design, development, production, installation, and service of products for the petroleum, petrochemical, and natural gas industries. It is equivalent to API Spec Q1 without the Monogram annex.

Effectiveness

The debate on the effectiveness of ISO 9000 commonly centers on the following questions:

  1. Are the quality principles in ISO 9001:2000 of value? (Note that the version date is important; in the 2000 version ISO attempted to address many concerns and criticisms of ISO 9000:1994).
  2. Does it help to implement an ISO 9001:2000-compliant quality management system?
  3. Does it help to obtain ISO 9001:2000 certification?

Effectiveness of the ISO system being implemented depends on a number of factors, the most significant of which are:

  1. Commitment of senior management to monitor, control, and improve quality. Organizations that implement an ISO system without this desire and commitment often take the cheapest road to get a certificate on the wall and ignore problem areas uncovered in the audits.
  2. How well the ISO system integrates into current business practices. Many organizations that implement ISO try to make their system fit into a cookie-cutter quality manual instead of creating a manual that documents existing practices and only adds new processes to meet the ISO standard when necessary.
  3. How well the ISO system focuses on improving the customer experience. The broadest definition of quality is "Whatever the customer perceives good quality to be." This means that a company doesn't necessarily have to make a product that never fails; some customers will have a higher tolerance for product failures if they always receive shipments on-time or have a positive experience in some other dimension of customer service. An ISO system should take into account all areas of the customer experience and the industry expectations, and seek to improve them on a continual basis. This means taking into account all processes that deal with the three stakeholders (customers, suppliers, and organization); only then will a company be able to sustain improvements in the customer's experience.
  4. How well the auditor finds and communicates areas of improvement. While ISO auditors may not provide consulting to the clients they audit, there is the potential for auditors to point out areas of improvement. Many auditors simply rely on submitting reports that indicate compliance or non-compliance with the appropriate section of the standard; however, to most executives, this is like speaking a foreign language. Auditors that can clearly identify and communicate areas of improvement in language and terms executive management understands facilitate action on improvement initiatives by the companies they audit. When management doesn't understand why they were non-compliant and the business implications associated with non-compliance, they simply ignore the reports and focus on what they do understand.

Advantages

It is widely acknowledged that proper quality management improves business, often having a positive effect on investment, market share, sales growth, sales margins, competitive advantage, and avoidance of litigation.[31] The quality principles in ISO 9000:2000 are also sound, according to Wade [32] and Barnes, who says that "ISO 9000 guidelines provide a comprehensive model for quality management systems that can make any company competitive".[33] Sroufe and Curkovic, (2008) found benefits ranging from registration required to remain part of a supply base, better documentation, to cost benefits, and improved involvement and communication with management.[31] Implementing ISO often gives the following advantages:

  1. Creates a more efficient, effective operation
  2. Increases customer satisfaction and retention
  3. Reduces audits
  4. Enhances marketing
  5. Improves employee motivation, awareness, and morale
  6. Promotes international trade
  7. Increases profit
  8. Reduces waste and increases productivity
  9. Common tool for standardization

Criticisms of ISO 9000

A common criticism of ISO 9000 and 9001 is the amount of money, time, and paperwork required for registration.[7] Dalgleish cites the "inordinate and often unnecessary paperwork burden" of ISO, and says that "quality managers feel that ISO's overhead and paperwork are excessive and extremely inefficient".[34]

According to Barnes, "Opponents claim that it is only for documentation. Proponents believe that if a company has documented its quality systems, then most of the paperwork has already been completed".[33] Wilson suggests that ISO standards "elevate inspection of the correct procedures over broader aspects of quality", and therefore, "the workplace becomes oppressive and quality is not improved".[8]

One study showing reasons for not adopting this standard include the risks and uncertainty of not knowing if there are direct relationships to improved quality, and what kind and how many resources will be needed. Additional risks include how much certification will cost, increased bureaucratic processes and risk of poor company image if the certification process fails.[31] According to John Seddon, ISO 9001 promotes specification, control, and procedures rather than understanding and improvement.[9] Wade argues that ISO 9000 is effective as a guideline, but that promoting it as a standard "helps to mislead companies into thinking that certification means better quality, ... [undermining] the need for an organization to set its own quality standards".[32] In short, Wade argues that reliance on the specifications of ISO 9001 does not guarantee a successful quality system.

The standard is seen as especially prone to failure when a company is interested in certification before quality.[9] Certifications are in fact often based on customer contractual requirements rather than a desire to actually improve quality.[33][35] "If you just want the certificate on the wall, chances are you will create a paper system that doesn't have much to do with the way you actually run your business", said ISO's Roger Frost.[35] Certification by an independent auditor is often seen as the problem area, and according to Barnes, "has become a vehicle to increase consulting services".[33]

Dalgleish argues that while "quality has a positive effect on return on investment, market share, sales growth, better sales margins and competitive advantage", that "taking a quality approach is unrelated to ISO 9000 registration".[36] In fact, ISO itself advises that ISO 9001 can be implemented without certification, simply for the quality benefits that can be achieved.[37]

Abrahamson argues that fashionable management discourse such as Quality Circles tends to follow a lifecycle in the form of a bell curve, possibly indicating a management fad.[38]

Pickrell argues that ISO systems merely gauge whether the processes are being followed. It does not gauge how good the processes are or whether the correct parameters are being measured and controlled to ensure quality. Furthermore, when unique technical solutions are involved in the creation of a new part, ISO does not validate the robustness of the technical solution which is a key part of advanced quality planning. It is not unheard of for an ISO-certified plant to display poor quality performance due to poor process selection and/or poor technical solutions.

See also

References

  1. ^ Margaret Rouse, ISO 9000, Search Data Center, September 2005.
  2. ^ Poksinska, Bozena; Dahlgaard, Jens Jörn; Antoni, Marc (2002). "The state of ISO 9000 certification: A study of Swedish organizations". The TQM Magazine. 14 (5): 297. doi:10.1108/09544780210439734.
  3. ^ a b Tsim, Y.C.; Yeung, V.W.S.; Leung, Edgar T.C. (2002). "An adaptation to ISO 9001:2000 for certified organisations". Managerial Auditing Journal. 17 (5): 245. doi:10.1108/02686900210429669.
  4. ^ Beattie, Ken R. (1999). "Implementing ISO 9000: A study of its benefits among Australian organizations". Total Quality Management. 10: 95. doi:10.1080/0954412998090.
  5. ^ http://www.iso.org/iso/iso_9000_selection_and_use.htm[full citation needed]
  6. ^ "ISO 9001 certifications top one million mark, food safety and information security continue meteoric increase" (Press release). International Organization for Standardization. October 25, 2010. Retrieved March 24, 2012.
  7. ^ a b Clifford, Stephanie (May 1, 2005). "So many standards to follow, so little payoff". Inc.
  8. ^ a b Wilson, Ian (June 4, 2010). "Is ISO the way to go? Some say, Not So".[self-published source?]
  9. ^ a b c Seddon, John (November 19, 2000). "The 'quality' you can't feel". The Observer.
  10. ^ "A Brief History of ISO 9000: Where did we go wrong?". The Case Against ISO 9000 (2nd ed.). Oak Tree Press. 2000. ISBN 978-1-86076-173-7. {{cite book}}: External link in |chapterurl= (help); Unknown parameter |chapterurl= ignored (|chapter-url= suggested) (help)
  11. ^ History of the BSI Group
  12. ^ Fast Facts About BSI Group
  13. ^ Tarmac Certificate of Registration
  14. ^ More About BSI Group.
  15. ^ [1] ISO 9001 proven to help win new business.
  16. ^ http://www.bsi-emea.com/Quality/CaseStudies/Interstate.pdf[full citation needed]
  17. ^ a b Corbett, Charles J.; Montes-Sancho, María J.; Kirsch, David A.; Song, CX; Wu, H; Dai, Q; Irier, H; Upadhyay, AK; Gearing, M (2005). "The Financial Impact of ISO 9000 Certification in the United States: An Empirical Analysis". Management Science. 51 (7): 1607–16. doi:10.1287/mnsc.1040.0358. JSTOR 20110397. PMC 3292193. PMID 22037496.
  18. ^ http://neumann.hec.ca/cref/sem/documents/040923.pdf[full citation needed]
  19. ^ a b Heras, Iñaki; Dick, Gavin P.M.; Casadesús, Martí (2002). "ISO 9000 registration's impact on sales and profitability: A longitudinal analysis of performance before and after accreditation". International Journal of Quality & Reliability Management. 19 (6): 774. doi:10.1108/02656710210429618.
  20. ^ Naveh, Eitan; Marcus, Alfred (2007). "Financial performance, ISO 9000 standard and safe driving practices effects on accident rate in the U.S. Motor carrier industry". Accident Analysis & Prevention. 39 (4): 731. doi:10.1016/j.aap.2006.11.004.
  21. ^ Sharma, Divesh S. (2005). "The association between ISO 9000 certification and financial performance". The International Journal of Accounting. 40 (2): 151. doi:10.1016/j.intacc.2005.01.011.
  22. ^ Chow-Chua, Clare; Goh, Mark; Wan, Tan Boon (2003). "Does ISO 9000 certification improve business performance?". International Journal of Quality & Reliability Management. 20 (8): 936. doi:10.1108/02656710310493643.
  23. ^ Rajan, Murli; Tamimi, Nabil (2003). "Payoff to ISO 9000 Registration". The Journal of Investing. 12: 71. doi:10.3905/joi.2003.319536.
  24. ^ Lo, Chris K.Y.; Yeung, Andy C.L.; Cheng, T.C. Edwin (2007). "Impact of ISO 9000 on time-based performance: An event study" (PDF). World Academy of Science, Engineering and Technology. 30 (7): 35–40.
  25. ^ Buttle, Francis (1997). "ISO 9000: Marketing motivations and benefits". International Journal of Quality & Reliability Management. 14 (9): 936–47. doi:10.1108/02656719710186867.
  26. ^ Santos, Leticia; Escanciano, Carmen (2002). "Benefits of the ISO 9000:1994 system: Some considerations to reinforce competitive advantage". International Journal of Quality & Reliability Management. 19 (3): 321–44. doi:10.1108/02656710210415703.
  27. ^ Alcorn, Janice E. (2008). "A Collection of Papers Presented at the 55th Conference on Glass Problems: Ceramic Engineering and Science Proceedings, Volume 16, Issue 2". Ceramic Engineering and Science Proceedings: 15. doi:10.1002/9780470314661.ch3. ISBN 978-0-470-31466-1. {{cite journal}}: |chapter= ignored (help); Cite journal requires |journal= (help)
  28. ^ ISO/IEC 17021: "Conformity assessment. Requirements for bodies providing audit and certification of management systems" (2011)
  29. ^ ISO/IEC 17011: "Conformity assessment. General requirements for accreditation bodies accrediting conformity assessment bodies" (2004).
  30. ^ Nigel H. Croft (2012). "ISO 9001:2015 and beyond - Preparing for the next 25 years of quality management standards". ISO.
  31. ^ a b c Sroufe, Robert and Sime Curkovic, "An examination of ISO 9000:2000 and supply chain quality assurance." Journal of Operations Management, Volume 26, Issue 4, July 2008, Pages 503-520
  32. ^ a b "Is ISO 9000 really a standard?" Jim Wade, ISO Management Systems – May–June 2002.
  33. ^ a b c d "Good Business Sense Is the Key to Confronting ISO 9000" Frank Barnes in Review of Business, Spring 2000.
  34. ^ Scott Dalgleish, "ISO 9000: More Hindrance than Help" Quality Magazine May 5, 2003 (accessed 24 Mar 2012).
  35. ^ a b "ISO a GO-Go." Mark Henricks. Entrepreneur Magazine Dec 2001.
  36. ^ Scott Dalgleish, "Probing the Limits: ISO 9001 Proves Ineffective", Quality Magazine April 1, 2005 (accessed 24 Mar 2012).
  37. ^ The ISO Survey – 2005 (abridged version, PDF, 3 MB), ISO, 2005.
  38. ^ Abrahamson, E. (1996). "Management Fashion". The Academy of Management Review. 21 (1): 254–285. doi:10.5465/amr.1996.9602161572. JSTOR 258636.

Further reading

  • Bamford, Robert; Deibler, William (2003). ISO 9001: 2000 for Software and Systems Providers: An Engineering Approach (1st ed.). CRC-Press. ISBN 0-8493-2063-1, ISBN 978-0-8493-2063-7
  • Naveh, E.; Marcus, A. (2004). "When Does the ISO 9000 Quality Assurance Standard Lead to Performance Improvement? Assimilation and Going Beyond". IEEE Transactions on Engineering Management. 51 (3): 352. doi:10.1109/TEM.2004.830864.
  • http://www.iso.org/iso/survey2007.pdf - An abstract

Boohe 2007's ISO survey of certificates.