Video summary

NQA Webinar: Back to Basics - ISO 9001 (2nd September 2022)

Main summary

Key takeaways

Business

Business-specific summary (ISO 9001 “Back to Basics” webinar)

Core business meaning of ISO 9001

  • Quality (definition): the degree to which inherent/assigned characteristics of a product or service fulfill requirements.
  • Quality Management System (QMS): a set of interrelated/interacting organizational elements (policies, objectives, and processes) designed to achieve intended outcomes and consistently meet requirements—not merely paperwork.

Quality assurance vs. quality control (execution mindset)

  • Quality control: often stigmatized as “inspect/test at the end” (e.g., 100% inspection).
  • ISO 9001 approach (assurance): build planning and controlled processes upfront so the organization can have confidence that outputs will meet requirements consistently.
  • Practical implication: don’t “wait for failures”; build mechanisms that prevent them.

Frameworks / playbooks emphasized

PDCA cycle embedded in ISO 9001

  • Plan:
    • context
    • interested parties
    • scope
    • leadership involvement
    • risks/opportunities
    • resources
  • Do: operational planning and control (deliver/manage the work).
  • Check: internal audits, quality/control monitoring, management review.
  • Act: corrective/improvement actions—QMS should not stand still.

Process approach (system thinking)

  • Map and manage end-to-end interrelated processes (e.g., design, procurement, production/operations, inspection, delivery, aftersales).
  • Optimize the system using process performance information to improve interdependencies and outcomes.

Risk-based thinking

  • Risk = risk of not achieving intended outcome.
  • Treat risk as threats to:

    • policy/objectives
    • customer satisfaction
    • compliance
    • improvement (not only health & safety)
  • Take actions to mitigate risks and pursue opportunities (efficiency, effectiveness, investment cases).


Intended outcomes of a QMS (what leadership is ultimately trying to achieve)

  • Achieve the quality policy (policy deployed and implemented across the organization).
  • Fulfill objectives:
    • customer satisfaction
    • regulatory/contract compliance
    • improvement
    • better consistency/communication
    • performance
  • Commercial gain: many organizations pursue ISO 9001 for commercial/contractual reasons.
  • Reduce risks: explicitly connect system design to “what can trip us up” and mitigate it.

Key management system principles highlighted (7 principles)

  • Customer focus
  • Leadership
  • Engagement of people
  • Process approach
  • Continual improvement
  • Evidence-based decision making (using audit/control evidence, supplier performance, complaints, etc.)
  • Relationship management / management of interested parties (internal, customer, suppliers, subcontractors, regulators, etc.)

“Misunderstood / often missed” requirements (action-oriented guidance)

1) Context = relevance (not a generic documentation exercise)

  • “Context” should be relevant to the organization and kept the right size/shape.
  • Include internal/external issues and keep it up to date as conditions change.
  • Avoid a “sausage-machine” generic QMS that loses relevance deeper inside.

2) Interested parties

  • Don’t be forced into maintaining a huge list; ensure the QMS identifies needs/expectations that matter to outcomes.
  • Document where required by the standard—don’t record everything “just because.”

3) Leadership involvement is mandatory (but not necessarily day-to-day)

  • Top management must support, set objectives, ensure resources, and participate in management review decisions.
  • Leadership shouldn’t treat the QMS as “certificate on the wall” or a box dusted off for audits.

4) Design, procurement, and outsourcing liability

  • Design/development is broader than “widgets”:
    • includes design of services and the means by which products/services are provided
    • organizational changes affecting subsequent provision can trigger design development requirements
  • Procurement:
    • externally provided processes/products/services must be controlled via criteria/methodologies
    • key principle: you can’t outsource liability—the QMS must provide assurance to customers that requirements are met

5) Internal audits are not for “auditor satisfaction only”

  • Internal audits must check:
    • implementation
    • maintenance
    • effectiveness of the management system
  • Findings/nonconformities are not inherently bad—they indicate the system is being challenged and improved.
  • Build competence in auditors and include peer challenge/review.

6) Management review outputs must include actions/decisions

  • Management review isn’t just minutes—it must produce:
    • decisions
    • actions
    • resource conclusions (system effectiveness/fitness-for-purpose)
  • “No actions” is effectively abnormal and can be a nonconformity.

Practical recommendations repeated throughout

  • Don’t overthink / overread clauses: ask “What is the standard asking me to do?” and translate it into business execution.
  • Reverse-engineer from current operations:
    • start with “what we do,” then show how it satisfies ISO requirements
    • avoid creating forms just to satisfy clauses
  • Keep it integrated:
    • embed the QMS in how the business actually runs
    • interlink processes (no silos)
  • Allow changes:
    • update forms/processes as needed in a planned way
    • the QMS may evolve; it doesn’t need annual static reinvention

Audit & certification process notes (high-level operational implications)

  • Stage 2 vs surveillance (initial certification context)
    • Stage 2 covers every applicable clause (often longer).
    • Surveillance visits are shorter and sampled, typically ensuring coverage of “bread-and-butter” themes (e.g., context, interested parties, audits, management review, objectives, risks/opportunities, complaints) while sampling other areas over the cycle.
  • Nonconformance definition (practical test)
    • If a requirement (standard/contract/regulation) is not met, that’s a nonconformance.
    • Use a binary view: if you can “hang your hat on a requirement,” failure is a nonconformance.

Metrics / KPIs / targets mentioned

  • No specific numeric KPIs, targets, timelines, or financial metrics (revenue/margin/CAC/LTV/churn figures) were provided.
  • Performance monitoring was discussed conceptually via:
    • process performance indicators
    • audit/control evidence
    • supplier approvals
    • customer satisfaction/complaints
    • continual improvement and effectiveness of actions

Presenter / sources

  • Presenter: Martin Graham, Principal Quality Assessor, NQA
  • Webinar: “ISO 9001 – Back to Basics”
  • Date: 2 September 2022
  • Source: NQA Webinar

Original video