Video summary
NQA Webinar: Back to Basics - ISO 9001 (2nd September 2022)
Main summary
Key takeaways
Business-specific summary (ISO 9001 “Back to Basics” webinar)
Core business meaning of ISO 9001
- Quality (definition): the degree to which inherent/assigned characteristics of a product or service fulfill requirements.
- Quality Management System (QMS): a set of interrelated/interacting organizational elements (policies, objectives, and processes) designed to achieve intended outcomes and consistently meet requirements—not merely paperwork.
Quality assurance vs. quality control (execution mindset)
- Quality control: often stigmatized as “inspect/test at the end” (e.g., 100% inspection).
- ISO 9001 approach (assurance): build planning and controlled processes upfront so the organization can have confidence that outputs will meet requirements consistently.
- Practical implication: don’t “wait for failures”; build mechanisms that prevent them.
Frameworks / playbooks emphasized
PDCA cycle embedded in ISO 9001
- Plan:
- context
- interested parties
- scope
- leadership involvement
- risks/opportunities
- resources
- Do: operational planning and control (deliver/manage the work).
- Check: internal audits, quality/control monitoring, management review.
- Act: corrective/improvement actions—QMS should not stand still.
Process approach (system thinking)
- Map and manage end-to-end interrelated processes (e.g., design, procurement, production/operations, inspection, delivery, aftersales).
- Optimize the system using process performance information to improve interdependencies and outcomes.
Risk-based thinking
- Risk = risk of not achieving intended outcome.
-
Treat risk as threats to:
- policy/objectives
- customer satisfaction
- compliance
- improvement (not only health & safety)
-
Take actions to mitigate risks and pursue opportunities (efficiency, effectiveness, investment cases).
Intended outcomes of a QMS (what leadership is ultimately trying to achieve)
- Achieve the quality policy (policy deployed and implemented across the organization).
- Fulfill objectives:
- customer satisfaction
- regulatory/contract compliance
- improvement
- better consistency/communication
- performance
- Commercial gain: many organizations pursue ISO 9001 for commercial/contractual reasons.
- Reduce risks: explicitly connect system design to “what can trip us up” and mitigate it.
Key management system principles highlighted (7 principles)
- Customer focus
- Leadership
- Engagement of people
- Process approach
- Continual improvement
- Evidence-based decision making (using audit/control evidence, supplier performance, complaints, etc.)
- Relationship management / management of interested parties (internal, customer, suppliers, subcontractors, regulators, etc.)
“Misunderstood / often missed” requirements (action-oriented guidance)
1) Context = relevance (not a generic documentation exercise)
- “Context” should be relevant to the organization and kept the right size/shape.
- Include internal/external issues and keep it up to date as conditions change.
- Avoid a “sausage-machine” generic QMS that loses relevance deeper inside.
2) Interested parties
- Don’t be forced into maintaining a huge list; ensure the QMS identifies needs/expectations that matter to outcomes.
- Document where required by the standard—don’t record everything “just because.”
3) Leadership involvement is mandatory (but not necessarily day-to-day)
- Top management must support, set objectives, ensure resources, and participate in management review decisions.
- Leadership shouldn’t treat the QMS as “certificate on the wall” or a box dusted off for audits.
4) Design, procurement, and outsourcing liability
- Design/development is broader than “widgets”:
- includes design of services and the means by which products/services are provided
- organizational changes affecting subsequent provision can trigger design development requirements
- Procurement:
- externally provided processes/products/services must be controlled via criteria/methodologies
- key principle: you can’t outsource liability—the QMS must provide assurance to customers that requirements are met
5) Internal audits are not for “auditor satisfaction only”
- Internal audits must check:
- implementation
- maintenance
- effectiveness of the management system
- Findings/nonconformities are not inherently bad—they indicate the system is being challenged and improved.
- Build competence in auditors and include peer challenge/review.
6) Management review outputs must include actions/decisions
- Management review isn’t just minutes—it must produce:
- decisions
- actions
- resource conclusions (system effectiveness/fitness-for-purpose)
- “No actions” is effectively abnormal and can be a nonconformity.
Practical recommendations repeated throughout
- Don’t overthink / overread clauses: ask “What is the standard asking me to do?” and translate it into business execution.
- Reverse-engineer from current operations:
- start with “what we do,” then show how it satisfies ISO requirements
- avoid creating forms just to satisfy clauses
- Keep it integrated:
- embed the QMS in how the business actually runs
- interlink processes (no silos)
- Allow changes:
- update forms/processes as needed in a planned way
- the QMS may evolve; it doesn’t need annual static reinvention
Audit & certification process notes (high-level operational implications)
- Stage 2 vs surveillance (initial certification context)
- Stage 2 covers every applicable clause (often longer).
- Surveillance visits are shorter and sampled, typically ensuring coverage of “bread-and-butter” themes (e.g., context, interested parties, audits, management review, objectives, risks/opportunities, complaints) while sampling other areas over the cycle.
- Nonconformance definition (practical test)
- If a requirement (standard/contract/regulation) is not met, that’s a nonconformance.
- Use a binary view: if you can “hang your hat on a requirement,” failure is a nonconformance.
Metrics / KPIs / targets mentioned
- No specific numeric KPIs, targets, timelines, or financial metrics (revenue/margin/CAC/LTV/churn figures) were provided.
- Performance monitoring was discussed conceptually via:
- process performance indicators
- audit/control evidence
- supplier approvals
- customer satisfaction/complaints
- continual improvement and effectiveness of actions
Presenter / sources
- Presenter: Martin Graham, Principal Quality Assessor, NQA
- Webinar: “ISO 9001 – Back to Basics”
- Date: 2 September 2022
- Source: NQA Webinar