Example of procedure for use of External documents in Product Realization

1.0 PURPOSE

To define the methodology followed by XXX for the regular change, updating, maintenance and control of External documents. The documented procedure includes:

  • Standards, Directive, and Customer Specifications.
  • External specification requirements, including addenda, errata, and updates are used in the design or manufacture of the product.
  • Integration of these requirements into the product realization and other affected processes.

2.0 SCOPE

This procedure is applicable to all the following systems and standards

  • API Spec Q1, 9th edition/ ISO 29001: 2020
  •  API Spec ….
  • API Spec ……
  • API Spec ……
  • API Spec …..
  • API Spec ……

3.0 INPUTS

  • Drawings, Specifications
  • Purchase Orders
  • Customer Standards
  • International Standard
  • Document request form

4.0 RESPONSIBILITY:

  • Management Representative / Quality Systems Manager
  • All concerned process heads

5.0 RESOURCES:

Competent Manpower, Computers, Printer & Internet connection, Stationery, International standards & specifications, XXX Procedures          

6.0 TERMS AND DEFINITIONS

Document: Information (meaningful data) and supporting medium

Procedure: XXX’s documented method for performing an activity under controlled conditions to achieve conformity to specified requirements.

NOTE this definition was previously identified as a “control feature” in earlier editions of this specification.

Specifications: Document stating requirements

7.0 PROCEDURE

7.1 External Origin Standard

  • A Master list of External Origin Documents is maintained which is essential for the planning and operation of the Quality Management System.  The master list of external origin document is identified, controlled and updated as and when changes are made to the standard.
  • API product or other external specification requirements including addenda, errata & advisory details (revisions and updates) are updated and maintained by checking www.api.org website monthly wise
  • MR keeps tab on the versions of standards mentioned in master list of External origin standards on respective websites once in 6 months and updated if necessary.
  • Regarding revision of legal standards, once in three month, it is checked with authorized like PCB, Inspectorate of  Factories etc. and updated
  • Based on the Updation of External standards, the Technical Procedures are updated
  • All standards are collected by MR and review with Engineer – Design & Development, Operations, Quality Control in monthly basis
  • System related changes in Standards is identified and done by MR
  • Technical changes like design & development, Quality are identified by related Personnel (Engineer) and inform to MR
  • If any changes required from management side and those will be discussed in the Management Review Meeting and MR takes responsibility of it.

7.2 DOCUMENT CONTROL

  1. External Document are following,
    • Drawings
    • Specifications
    • Purchase Orders
    • Customer Standards
  2. Issue control of external documents lies with the QA/QC Engineer.
  3. Machine shop Manager/Operations Engineer shall ensure the latest editions of the drawings/specifications/other documents are available prior to the commencement of the work.
  4. If the copies of the Customer/OEM/Internal drawings are lost or damaged by the user departments, the department head makes a request to the QA/QC Engineer for issue of fresh copy of the drawings.
  5. Once the product realization process completed relevant documents shall be handed-over to the QA/QC Engineer.
  6. Copies of the external documents shall be disposed after use in controlled conditions and appropriate records shall be maintained.

8.0 OUTPUTS

Master List of External Origin Standards

9.0 Key performance indicator

All external origin documents available as per requirements & controlled.

10.0 ASSOCIATED DOCUMENTS & RECORDS

DESCRIPTIONFORMAT NUMBERRESPONSIBILITY
Master List of External Origin StandardsXXX/MR/D 04Management Representative

API Q1 6  Quality Management System Monitoring, Measurement, Analysis, and Improvement

6.1 General

The organization is responsible for planning and executing the processes for monitoring, measuring, analyzing, and improving the quality management system to ensure compliance with the requirements of this specification and to enhance the system’s effectiveness over time. This includes identifying appropriate methods, including data analysis techniques, and determining their utilization extent.

The organization must plan and implement the monitoring process, measurement process, analytical process, and improvement process to conform to the requirements of API Q1 and to continually improve the effectiveness of the quality management system. The process must include applicable methods, including techniques for the analysis of data, and the extent of their use. The organization must analyse the results of monitoring and measurement and confirm that the organization has considered what, how and when to measure and that the outcomes from decisions result are ensuring appropriate process control. It must monitor the performance and effectiveness of the organization’s quality management system. It must develop a process (method, techniques, format, etc.) to identify, collect and analyze various data and information from both internal and external sources, including:

  • Monitoring and measuring results;
  • Process performance results;
  • Meeting objectives;
  • Internal audit findings;
  • Customer surveys and feedback;
  • 2nd or 3rd party audit results;
  • Competitor and benchmarking information;
  • Product test results;
  • Supplier performance information.

This ‘input’ (information and data) should reflect upon the adequacy, suitability and effectiveness of the quality management system and its processes. The ‘output’ (the result of the analysis) must provide information (understanding, insight, awareness, confidence, knowledge of, etc.). The analysis output must provide insight to:

  • Customer satisfaction and perception
  • Product conformance.
  • Process performance
  • Product and process characteristics
  • Trends in products and processes
  • Opportunities for preventive action
  • Suppliers and subcontractors.

Other potential or useful options might include:

  • Need for corrective action
  • Opportunity for improvement
  • Competition.

It is important to document and retain as evidence the results of the evaluation of the performance of the quality management system. Monitoring and measuring QMS operations and activities will establish a mechanism to ensure that your organization is meeting its policies, objectives and targets. To meet this requirement, your organization must perform six steps:

  • Identify the activities that can have significant impacts and risks
  • Determine key characteristics of the activity to be monitored
  • Select the best way to measure the key characteristics
  • Record data on performance, controls and conformance with objectives and targets
  • Determine the frequency with which to measure the key characteristics
  • Establish management review and reporting.

Establish the monitoring and tracking criteria for each activity that has a significant impact or risk and review the action plan.

6.2 Monitoring, Measuring, and Improving

6.2.1 Customer Satisfaction

The organization must have a documented procedure for monitoring customer satisfaction, detailing the frequency and methods for assessing it, along with key performance indicators. Records of customer satisfaction data must be retained.

The organization must establish a documented procedure to measure customer satisfaction. The procedure shall address the frequency of measurement, obtaining customer feedback, key performance indicators (KPIs), and other information that the organization uses to determine whether the organization has satisfied customers in meeting identified requirements. The result customer satisfaction information must be recorded. Customer satisfaction should be monitored to determine to which degree their expectations and needs are being fulfilled. The methods for obtaining this information need to be determined by the QMS. Methods of measuring and monitoring the way customers perceive your company can be done through;

  • Physical customer feedback through meetings
  • Customer surveys
  • Warranty/Guarantee claims
  • Compliments/Complaints
  • Dealer reports

Producing high levels of customer satisfaction is an essential metric tool for gathering real-time information to improve the QMS system and product. Each customer will be different and present different needs and the organization will have to use additional measures and controls to measure and analyze the data.

Defining Customer Satisfaction Indicators: The procedure for customer satisfaction should have customer satisfaction indicators. This process should also include;

  • The frequency of data collection
  • The method of data collection
  • A summarization
  • A review of the data
  • An evaluation of the data
  • Actions on how to improve
  • The required timeline for the remedy
  • Whose responsibility it is and
  • The follow-up with the customer

To continuously improve customer satisfaction, customer feedback and trends must be constant. This will be the baseline to use for both internal and external customers.

6.2.2 Internal Audit

6.2.2 Internal Audit
6.2.2.1 General

The organization must conduct internal audits to assess the implementation, maintenance, and conformity of the quality management system to both this specification and the organization’s internal quality management system requirements. A documented procedure outlining responsibilities for planning, conducting, and documenting internal audits must be maintained. This procedure should identify audit criteria, scope, frequency, and methods, considering previous audit results, process criticality, and changes to the quality management system. All processes within the quality management system must undergo audits at least once every 12 months, with audits staggered throughout the year if necessary. Critical processes related to product realization must be audited to ensure compliance with requirements, including observation of activities and evaluation of conformity.

6.2.2.2 Performance of Internal Audit

Competent personnel, separate from those involved in or directly overseeing the audited activity, must conduct audits to ensure objectivity and impartiality. Audit records should offer objective evidence of the implementation and maintenance of the quality management system. Note: product specification requirements may be integrated into various quality management system processes and may be audited alongside one or more of these processes.

6.2.2.3 Audit Review and Closure

The organization must define timeframes for responding to identified nonconformities. Management accountable for the audited area must ensure that any required corrections and corrective actions adhere to the specifications outlined in section 6.4.2. Internal audit records must be retained.

Internal Audits are conducted to verify that the Organization’s QMS is effectively implemented and maintained and conforms to the requirements of the API Q1. The organization must establish a documented procedure for Internal audit. It must define the responsibilities for planning, conducting, and documenting internal audits. The results of previous audits and the criticality of the process being audited must be considered while planning for internal audits. While planning for the internal audit the organization must identify the audit criteria, scope, frequency, and methods of Internal audit. The procedure must ensure that all processes of the quality management system claiming conformity to the API Q1 requirements are audited at least once. every 12 months. All Outsourced activities that impact the quality of the product and that are performed at the organization’s facility must be part of the internal audit. All processes of the Organization’s QMS must be audited to claim conformance to the API Q1 requirements. Records of the audits provide objective evidence that the QMS is implemented and maintained. Independent, Competent personnel who do not perform or directly supervise the process being audited shall conduct the Audit. This is to ensure objectivity and impartiality of the audit process. Product specification requirements can be embedded throughout the quality management system processes and audited in conjunction with one or more quality management system processes. For the non-conformities identified during the internal audit, the responsible management must ensure necessary correction and corrective action. The organization must identify response times to address detected non-conformities. Records related to internal audits must be maintained. The results of internal audits and the status of corrective actions are to be reported in the management review.

Organizations should establish an internal audit plan to cover all requirements of the standards. In addition, consideration should be given to the status and importance of the processes that comprise the audit and the results of previous audits. Objective evidence should demonstrate information concerning the effective implementation of the audit plan, as well as a sample of audit results. The internal audit process should include the following activities:

  • The development of a program of internal audits which can be revised depending on the results of previous audits and the results of performance monitoring.
  • The identification, selection and training of internal auditors.
  • The analysis and evaluation of the results of internal audits.
  • The identification of the need for corrective or improvement measures.
  • The verification of the completion and effectiveness of these measures.
  • The documentation pertaining to the execution and results of audits.
  • The communication of the results of audits to the top management.

The internal audit process is part of the continual improvement feedback loop to evaluate and improve the effectiveness of the management system. It also highlights where processes and procedures are not addressing risks adequately and where changes are needed to improve efficiency or effectiveness. The audit process also serves as a method of compliance monitoring.

Planning for internal audit

During the early stages of implementing this standard, the internal audit often focuses on ensuring that any compliance issues or non-conformities are discovered and rectified before the assessment. However, once the organization is registered, the internal audit must evolve. The focus of the internal audit planning should be re-directed, away from compliance with standards, to an audit strategy that bases the audit frequency upon process performance data, feedback from customers, etc., to ensure that you are focusing on the risks and issues that should be on Top management’s radar. When planning the Internal audit organization should ensure that customer feedback, organizational changes and risks and opportunities are brought into consideration. Process importance as the degree of direct impact that process performance has on customer satisfaction should be considered i.e. could the process provide the customer with a defective product? One should consider process status in terms of maturity and stability; a more established, proven process will be audited less frequently than a newly implemented or recently modified process. Conversely; processes which are not performing to the planned arrangements should be audited more frequently. Support processes should be given a lower ranking than the manufacturing/service provision processes. In addition, the results of previous audits should be considered too. Processes that have been audited recently that have shown effectiveness and improvement should be audited less frequently. When applying risk-based thinking to select internal audits and their frequency, consider the following:

  • Processes that are critical to product and service quality;
  • Complex processes that require close monitoring and control to ensure conformity;
  • Balance across operational and non-operational processes;
  • Processes that utilize qualified personnel;
  • Activities or processes that occur across multiple locations;
  • Processes impacted by human factors;
  • Introduction of new or changed processes;
  • Changes affecting the organization;
  • Statutory and regulatory issues;
  • Process performance, e.g. process conformity/non-conformity, escapes to the customer, complaints, previous internal/external audit results, identified risk.

When planning your internal audit one should ensure that customer feedback, organizational changes, and risks and opportunities have been brought into consideration. Internal audits that are based on risk and customer feedback will help your organization to embark upon new methods of compliance in which risk-based thinking and continual improvement are the drivers, rather than compliance.

Determining the frequency of internal audits
Deciding the frequency of internal audits will depend on the perceived need for the audit and the size and complexity of your organization. The frequency of internal audits should depend on the criticality of each process and the perceived need to audit it, but all processes should be formally audited at least once during a 12-month audit cycle. Critical processes that directly affect process and product conformity and customer satisfaction should be audited more frequently, e.g. monthly, quarterly, or more regularly as required. When determining internal audit frequency, you should consider the following:

The level of risk associated with the activity, policy or procedure;
The priority of the specific element of the management system;
The results of previous audits; and
The significance of problems identified in the areas to be audited.

The basic requirement of the quality management system is that it is audited at least once per year. If any issues are found during audits, then additional audits can be undertaken to help get that part of the system working effectively again as soon as possible. Some audits are likely to be conducted every month to cover all manufacturing processes over the year. Unscheduled audits may be conducted at any time based upon:

Previous audit results;
Regulatory inspections;
Operational changes (planned or unplanned);
Management review concerns;
Identified non-conformances.

The frequency of internal audits should be reviewed and, where appropriate, adjusted based on the occurrence of process changes, internal and external nonconformities, and/or customer complaints. The effectiveness of the audit should be reviewed as a part of management review.

The internal audit checklist is just one of the many tools which are available from the auditor’s toolbox that help ensure your audits address the requirements. The checklist stands as a reference point before, during and after the audit, and will provide the following benefits:

  • Ensures the audit is conducted systematically;
  • Promotes audit planning;
  • Ensures a consistent audit approach;
  • Actively supports your organization’s audit process;
  • Provides a repository for notes collected during the audit process;
  • Ensures uniformity in the performance of different auditors;
  • Provides reference to objective evidence.

Before a new audit is started in a particular area, it is important to check the status of any outstanding issues since the last audit (if any) was performed in the area. If there are outstanding issues, then they may be carried forward into the current audit, and the previous audit could then be closed off. The system audits are best undertaken using an internal audit checklist. This type of audit focuses on the quality management system as a whole and compares the planning activities and broad system requirements to ensure that each clause or requirement has been implemented. A good summary report is the final output of the audit and deserves an appropriate amount of attention and effort. The audit report is the detail of what was found during the audit. It presents an overall summary of the audit findings, as well as any positive aspects noted during the audit. The audit report must also identify nonconformities identified during the audit and their associated corrective actions. The Internal Auditor should be responsible for finalizing the audit report, which should include:

  • The area and element/procedure/process audited;
  • Audit team composition, audit scope, persons interviewed;
  • Executive summary;
  • Observations and key findings (identified nonconformities);
  • Recommendations;
  • Opportunities for improvement, which are areas that may become nonconforming in the future;
  • Graphical representation of findings.

On completion of the audit, a closing meeting should be scheduled between the audit team and the organization or department being audited, to present the results of the audit and discuss any subsequent steps required to complete the audit. Observations may also be recorded for future consideration. The audit report needs to be signed by the lead auditor and the manager of the relevant department, and distributed as required to relevant persons. The findings and conclusions should be formally documented as part of the summary report. Too often, the audit report only recites back facts and data the managers already know. The value is in identifying issues and opportunities they do not know! This summary should be reviewed first with the lead auditor, then the Process Owner and Management Team. Make final revisions and file the audit report and all supporting audit materials and notes. The audit summary and the corrective action forms should be attached to the audit report, which now becomes the audit record. Only the summary report and corrective actions need be given to the Process Owner and a copy of the audit report should be given to Top management.

6.3 Analysis of Data

The output of data analysis should furnish insights, including trends, regarding:

  • a) Customer satisfaction.
  • b) Nonconformity to product requirements during product realization.
  • c) Instances of nonconformities and product failures detected post-delivery or post-use, provided there is accessible product documentation or evidence to facilitate root cause determination.
  • d) Process performance.
  • e) Supplier performance.
  • f) Attainment of quality objectives.

The organization must utilize data to assess areas where continual enhancement of the quality management system’s effectiveness is possible.

The organization must establish a documented procedure for the identification, collection, and analysis of data to demonstrate the suitability and effectiveness of the quality management system. The analysis includes data generated from monitoring and measurement, internal audits, management reviews, and other relevant sources. The data analysis output provides information relating to customer satisfaction, quality objectives, supplier performance and conformity to product requirements. The nonconformities and product failures identified after delivery or use provided the product or documented evidence is available to facilitate the determination of the cause. The characteristics and trends of processes and products including opportunities for preventive action. The organization must use data to evaluate where continual improvement of the effectiveness of the quality management system can be made.

Analysis of Data must include:

  • Levels of Customer satisfaction
  • Level of Supplier Performance
  • The results of product and process monitoring
  • Rates of non-conformances
  • Trends and opportunities for corrective and preventive action

Where the analysis shows unacceptable performance then those items should become Quality objectives and where appropriate, become subject to preventive or corrective action.

The purpose of analyzing data is to:

  • Assess organizational performance against established plans and stated quality objectives
  • Identify areas for improvement
  • Help determine the cause of problems
  • Guide for determining the most appropriate corrective or preventive action to take

Data collected for analysis includes:

  • Results from customer surveys
  • Results from employee surveys
  • Customer, supplier and employee feedback
  • Results from internal audits
  • Results from process monitoring and measurements
  • Results from product monitoring and measurements
  • Non-conformance reports
  • Warranty claims and returned products
  • How do I analyze data?

Effective data analysis is an essential part of any quality management system:

  • Use statistical techniques where appropriate (e.g. Statistical Process Control)
  • Data should be analyzed by designated, competent personnel
  • Use data feedback for continuous product and process improvement
  • Should I document our analysis of the data process?

It is not a mandatory requirement to document your analysis of the data process. However, you should always look to adequately define and control any operational processes that generate information on the performance of your quality management system. Therefore, the implementation of an analysis of data procedure will be appropriate for the majority of businesses. Develop and implement a procedure that defines the roles and responsibilities for analyzing quality management system data to drive continual improvement and to facilitate a factual approach to decision-making:

  • Data collection
  • Data analysis
  • Information output
  • Reporting
  • Looking for help documenting the process?

The effectiveness of the analysis of the data process is often determined by looking for evidence that the organization has sufficiently utilized data from the outputs of its activities and has used that data to drive continual improvement and enhance customer satisfaction.

6.4 Improvement

6.4.1 General

The organization is required to enhance the effectiveness of the quality management system continuously. This is achieved by assessing, selecting, and implementing improvement opportunities utilizing quality objectives, internal audits, data analysis, corrective actions, and management review.

The organization is expected to revise the quality system documentation and processes as the quality management system matures or when a new process is implemented. The organization must identify improvement opportunities and management system underperformance using the data output from its processes, such as data analysis and evaluation, internal auditing, management review, and the use of appropriate tools and methodologies to support and validate findings. The organization must implement the identified opportunities for improvement in a controlled manner. The organization should ensure that it has implemented a process, with appropriate methods, techniques, and formats for identifying areas of underperformance or opportunities for improvement. The organization should select the appropriate tools and techniques to investigate the causes thereby establishing and implementing a process for continual improvement. The impetus for continual improvement must come from the use of (as a minimum):

  1. Policies;
  2. Risks and opportunities;
  3. Objectives;
  4. Aspect and impacts
  5. Hazards and safety risks;
  6. Analysis and evaluation of data;
  7. Audit results;
  8. Management review;
  9. Non-conformity and corrective action.

Processes can always be made more efficient and effective, even when they are producing conforming products. A continual improvement programme aims to increase the odds of satisfying customers by identifying areas that need improvement. It requires the organization to plan improvement systems and to take into account many other activities that can be used in the improvement process. You will be required to ensure that you continually improve the degree to which your products and services meet customer requirements and to measure the effectiveness of your processes. To this end, the continual improvement principle implies that you should adopt the attitude that improvement is always possible and your organization should develop the skills and tools necessary to drive improvement.

6.4.2 Corrective Action

The organization must uphold a documented procedure to manage nonconformities, including those arising from customer complaints, and to implement corrective actions both internally and with suppliers. Corrective actions should correspond to the impact of the encountered nonconformity, which can pertain to both quality management system processes and trends in nonconforming products.

The procedure should cover:

  1. Criteria for initiating the corrective action process;
  2. Reviewing the nonconformity;
  3. Determining and implementing corrections;
  4. Identifying the root cause of the nonconformity and assessing the need for corrective actions;
  5. Implementing corrective action to minimize the likelihood of recurrence;
  6. Defining the timeframe and responsible parties for addressing corrections and corrective action;
  7. Verifying the effectiveness of the corrections and corrective action taken;
  8. Updating risks and opportunities identified during planning;
  9. Management of Change (MOC) when corrective actions necessitate new or modified controls within the quality management system; and
  10. Assessing similar potential nonconformities and implementing preventive actions as appropriate.

Records of corrective action process activities should be maintained, including activities conducted to confirm the effectiveness of the corrective actions taken.

The organization must establish a documented procedure to correct non-conformities and to take corrective actions appropriate to the effect of nonconformity to eliminate the causes of non-conformities to minimize the likelihood of its recurrence. Corrective action is to apply both internally and within the supply chain to both quality management system processes and nonconforming product trends. The procedure must identify requirements for reviewing a process nonconformity including customer complaints, determining and implementing corrections, identifying the root cause of the nonconformity and evaluating the need for corrective actions, implementing corrective action to reduce the likelihood that a nonconformity recurs, identifying the time frame and responsible persons for addressing corrections and corrective action, verification of the effectiveness of the corrections and corrective action taken and Management Of Change when the corrective actions require new or changed controls within the quality management system. Records of the activities for control of a nonconforming process shall be maintained. Records shall identify the activities performed to verify the effectiveness of the corrective actions taken.

Definition of correction
Correction (also referred to as immediate correction) is the action taken to eliminate a detected nonconformity or defect (adapted from ISO 9000). A correction can be made in conjunction with undertaking corrective action. For a product nonconformity, correction might include reworking the part, accepting the nonconformance through the concession process, replacing the product, or scrapping the product.

Definition of corrective action
Action implemented to address the root cause and contributing cause of the undesirable condition, situation, nonconformity, or failure; action taken to prevent recurrence. As part of the corrective action process, you must identify all the causes (root cause and contributing causes) that have or may have generated an undesirable condition, situation, nonconformity, or failure.

The decision to apply or not apply the corrective action process should be made by the appropriate level of management within the company, based on the level of risk. Many factors that can trigger the corrective action process, examples include:

  • A safety impact that affects the product or personnel;
  • Product performance and/or reliability issues;
  • High impact on production and/or maintenance operations;
  • Repetitive problems to one part of the activity/process, or similar problems across many activities/processes;
  • Difficulty in detecting the nonconformity;
  • By customer request;
  • Significant quality or management system issues;
  • Complex problems that cannot be solved without the assistance of others are not located where the problem occurred.

The analysis of nonconformities should not look for someone to blame, or a department that is ‘more responsible than another’, but rather for understanding and improving the organizational weaknesses that made them possible. Where internal audits identify that organization’s policy, objectives, standards and other requirements as outlined within their management system are either not implemented, or are improperly implemented, a nonconformance report should be raised and entered into the nonconformity log as appropriate. This should require an agreed response from the relevant Line Manager prior to closure. The root-cause must address the nonconformity and the corrective action must address the root-cause. Any nonconformities and subsequent actions to prevent their reoccurrence and the effectiveness of the corrective action(s), should be duly documented and retained.

Step 1. Identify the Problem
Once a problem has been identified through inspection, customer complaints, or audit results, it should be captured using non-conformity reports (NCRs) or corrective action reports (CARs) in order to identify who is affected by the problem and what the impact is. Considering the following:

  • What are the operations, products, materials, defects, malfunctions that may characterise the problem? What is it about?
  • Who is concerned with the problem? Who is reporting the problem? Who is rectifying the problem? Who is the problem affecting?
  • Where are all the places where the event takes place; shop floor, services, machine, process step?
  • Where is it seen? Where does it originate?
  • When does the event appear (time, date, when does it start, how long does it last, how often)
  • When is the problem reported defective? When is the problem repaired?
  • Has it occurred before? If yes, what is the history?
  • How do we know there’s a problem (how is it detected)?
  • How does the event appear, how does it stop?
  • How frequently is the problem experienced?
  • How is the effect of the problem being measured (costs, delays, scrap rate, customer complaints, return rate, concessions, reliability rate, etc)?
  • How is the problem currently addressed? How is it corrected?

This step helps to fully describe a situation, precisely analyse all its elements and gain a common understanding of them, allowing the definition of an action plan. Ensure that all team members agree about the definition of the issue and resulting impact. The problem description should describe the problems in terms of what, where, when, and how big. On a flip chart, presentation board, or even paper; write out a description of what you know about the problem. Try to document the problem and describe it as completely as possible. The description should contain facts; such as observations and documentary evidence and not assumptions. All information must be gathered before identifying the root-cause can begin. Make sure both of the above factors are true before you move to the next step. Consider any new information that the team may have gathered since completing the initial problem description. Describe the problem by identifying what is wrong and detail the problem in quantifiable terms. Define, verify and implement the interim containment action to isolate the effects of the problem from any internal/external customer until Permanent Corrective Actions (PCA) are implemented.

Step 2. Establish a Response Team
Identify representatives from functions that may have an influence on the corrective action process, including the identification of the root causes. Remember to assign responsibilities and objectives to the team members. Remember, those performing the job, such as operators, inspectors, drivers, etc., are the best people to help identify the real causes, don’t leave them out of the team! The size and composition of the team should depend on the complexity and the impact of the problem. The composition of the team is not fixed forever and may evolve depending on the analysis results and the required actions. New team members should join the team if analysis shows they are identified as being in the scope, some others will leave if their area is definitely identified as out of the scope. However, consideration should be made that expending the size of the core team over 6 to 8 members generally results in less efficiency. When more members or special skills are required, sub teams should be considered. Don’t forget, root-cause analysis must not be used for assigning blame or transferring responsibility. In summary, you should establish an investigation team with:

  • Process and/or product knowledge;
  • Allocated time and resources;
  • Authority to solve the problem and implement corrective actions;
  • Skill in the required technical disciplines;
  • A designated Team Leader.

Brainstorming sessions should be used to identify potential causes to investigate each potential cause. Coordinate parallel activities with different team members to help expedite the process of verification. Once you have reviewed the problem description, you can undertake a comparative analysis. A comparative analysis will help you identify relevant changes in a change-induced situation. Then you can reduce the number of possibilities that you must consider to determine root-cause. To complete a comparative analysis:

  • Ask yourself; what is unique, peculiar, different, or unusual about the symptoms?
  • Consider features such as people, processes, materials, machines and the environment;
  • List all facts without prejudice as to the possible cause;
  • Consider each difference you listed, and look for changes, ask yourself what has changed to give rise to this difference?
  • Keep in mind that each difference may not have a corresponding change;
  • List the changes next to the difference;
  • Look at the dates each change occurred;
  • Eliminate some changes if they occurred after the problem started;
  • Consider categories of people, machines, processes or measurements.

If the problem is change-induced, the root-cause must be the result of a change relative to one or more of the identified changes. It is important to remember that you have not yet moved from the ‘observations’ phase of the process. Any information you develop during the comparative analysis must be fact based, not opinion-based and must be true only for the symptom’s information. Do not rule out any facts that might be valid answers. If it is a fact and it answers the question, write it down. Your organization should first contain the problem by taking immediate corrective action (ICA) and then evaluating the need for initiating the formal problem-solving process. Where necessary, provide an emergency response action to protect the customer from the problem, protect the customer operations and the organisation (to stop the problem getting worse) and verify that problem does not degrade until the root-causes are known. An interim containment action is kept in place until a verified permanent corrective action can be implemented. In some cases, the interim containment action may be the same as or similar to the emergency response action. An interim containment action provides more opportunity for investigation. Conduct trial runs whenever possible. However, in some situations, your verification may simply be a matter of common sense. For example, if an interim containment action involves stopping the shipment of all products, you can be sure that customers will stop experiencing the problem. An interim containment action can be any action that protects the customer from the problem. However, before you implement an interim containment action, you need to verify that the interim containment action will work. To verify the interim containment action:

  • Prove before implementation it protects the customer from the problem;
  • Provide a before-and-after comparison;
  • Prove that the interim containment action will not introduce any new problems.

Methods of verification may include:

  • A test to determine the desired performance level;
  • A demonstration that changes eliminated the issue without creating a new problem;
  • A comparison between the interim containment action and similar proven actions;
  • A review to evaluate whether the interim containment action was effective;
  • Assurance that the interim containment action did not introduce a new problem.

Any interim containment action you implement must protect the customer from the problem without the introduction any new problems. Also, a single interim containment action may not be enough. You may need to implement more than one interim containment action to fully protect the customer.

Step 3. Identify the Root-Cause(s)
Root-cause analysis (RCA) is a class of problem-solving methods aimed at identifying the root-causes of problems or events. The practice of root-cause analysis is predicated on the belief that the problems are best solved by attempting to correct or eliminate root-causes, as opposed to merely addressing the immediately obvious symptom. Listed below are various root-cause analysis techniques, we recommend you use the 5-Whys (1st Why, 2nd Why, 3rd Why, 4th Why, and 5th Why – and the root-cause) technique to problem solving but you are free to undertake any of the following depending on the complexity of the problem:

  • 3-Ws (what, where, when);
  • 8D Eight Dimensions;
  • Failure Mode and Effects Analysis (FMEA & DFEMA);
  • Fish-bone Analysis;
  • Pareto Analysis;
  • Fault-tree Analysis;
  • Cause Mapping – draws out, visually, the multiple chains of interconnecting causes;
  • Barrier analysis – a technique often used in process industries;
  • Change analysis – an investigation technique often used for problems or accidents.

The 5-Whys technique offers some real benefits to organizations with varying degrees of management system maturity:

  • Simplicity. It is easy to use and requires no advanced mathematics or tools that allow you to dig deep and find underlying issues rather than using quick-fix solutions;
  • Effectiveness. It helps to separate the symptoms from the causes and identifies the root-cause of a problem using evidence-based analysis;
  • Comprehensiveness. It aids in determining the relationships between various problem causes and allows you to proactively eliminate problems for good;
  • Flexibility. It works well alone and when combined with other quality improvement and troubleshooting techniques such as the ones listed above;
  • Engaging. By building a culture that embraces progress, by its very nature, it fosters and produces teamwork within and outside of the organization, encourages the reporting of issues without fear or judgment;
  • Inexpensive. It is a guided, team-focused exercise that seeks to improve and adapt processes to ensure long-term success. There are no additional costs.

Launching a formal root-cause analysis and the problem-solving process should always be considered when an issue; such as undesirable conditions, defects and failures is detected. The decision not to apply the process must be made based on objective evidence of the absence of risks!

Step 4. Implement Corrective Action
When all root and contributing causes have been identified and their effects understood, implement all selected corrective actions. Verify that the planned actions were taken as scheduled and assess their effectiveness in permanently preventing the undesirable condition, situation, non-conformity or failure from recurring. Steps for corrective action (CA) implementation:

  • Implement the corrective action (CA);
  • Implement controls;
  • Evaluate the corrective action (CA) for the escape point;
  • Remove the immediate containment action ;
  • Perform validation;
  • Confirm with the customer that the symptom has been eliminated.

To ensure the most effective corrective actions to address the most likely, or critical root causes are taken in consideration of operational and business constraints such as costs, lead time, difficulty of implementation, and resources. Select solutions that optimise value and effectiveness for all stake-holders! Implement the solutions that have been selected, verify that all actions have been completed to schedule and that they have prevented the undesirable condition, situation, non-conformity or failure from recurring. Plan and implement selected permanent corrective actions. Remove the interim containment action and monitor the long-term results.

Step 5. Monitor Effectiveness
Establish a review process to ensure corrective actions are completed according to plan and that they continue to be effective over time by confirming you have done what you have planned. Try adjusting the type and number or frequency of additional checks and audits to check that the actions remain effective. When the same problem has been identified or is suspected to occur on the same or similar products, processes or data, the same corrective actions must be implemented and their effectiveness verified for all these additional products, processes or data. The owner of each corrective action, the team leader and all team members should verify the effectiveness of the actions taken to date, and when relevant, the customer. Examples of verification methods include:

  • Additional process monitoring until it is demonstrated that the process is stable and capable of consistently meeting requirements (recording and analysis of process parameters and/or product characteristics, SPC, etc.);
  • Additional internal audits to specifically verify the effectiveness of the corrective actions;
  • Associated metrics show significant improvement resulting from the corrective actions.
  • Examples of supporting evidence might include updated procedures, work instructions, control plans, etc. to show any changes were defined. Additionally, evidence of effective implementation of the changes is also required such as SPC data, inspection records, training records, audit records, etc.

If the corrective actions are effective, evaluate which containment actions may be eliminated (e.g. stop over inspection and overproduction, return to normal transportation means, etc.) without adversely affecting the product and process output. Record evidence of actions completed and associated results (what works and what does not). To document analysis results and changes to make the corrective action permanent, capture and share learning with all the stakeholders to prevent similar undesirable conditions, situations, non-conformity or failures occurring on other products, production lines, factories or suppliers. Identify all that can be shared from the experience that can be transferred across business units, production lines, factories or suppliers. Ensure that you get agreement from appropriate levels of management and other process owners and functions (internally and externally) to launch actions and verify they are implemented and effective. Keep lessons learned register which includes a summary of content and results of analyses, flow charts, databases, performance data, main actions and decisions, location where detailed data can be retrieved, difficulties encountered when managing the issue, etc. When the decision is made to implement actions in other business areas, such as; production lines, factories or suppliers, which are not under direct control of the response team, implementation and the verification of effectiveness is not necessarily the responsibility of the team. Escalation to top management or transfer to another function (procurement, engineering, etc.) may be required to ensure proper leverage and action follow-up.

6.5 Management Review
6.5.1 General

The organization’s management must conduct a review of the quality management system at least once every 12 months (by the end of the same calendar month as the previous year’s review) to assess its ongoing suitability, adequacy, and effectiveness. This review should encompass evaluations of opportunities for improvement, sufficiency of resources, and the necessity for adjustments to the quality management system, including the quality policy and objectives.

6.5.2 Input Requirements

The minimum inputs required for management review shall encompass:

  • a) Evaluation of the status and effectiveness of measures taken based on prior management reviews;
  • b) Findings from internal audits and audits conducted by external parties.
  • c) Identification of potential changes that may impact the quality management system, encompassing alterations to legal and other relevant requirements (e.g., industry standards), as well as shifts in internal and external factors pertinent to the quality management system.
  • d) Assessment of customer satisfaction.
  • e) Consideration of feedback received from customers and other concerned parties.
  • f) Evaluation of process performance.
  • g) Review of risk assessment outcomes and the effectiveness of risk mitigation measures. h) Status update on corrective actions.
  • i) Analysis of supplier performance.
  • j) Examination of product conformity analysis, including post-delivery or post-use nonconformities;
  • k) Comparison of actual performance with quality objectives; and
  • l) Proposals for improvement.

6.5.3 Output Requirements

The outcomes of the management review must comprise:

  1. A concise evaluation of the quality management system’s effectiveness,
  2. Any necessary modifications to processes,
  3. Determinations and ensuing actions,
  4. Essential resource allocations, and
  5. Enhancements aimed at better meeting customer needs.

Senior management is responsible for reviewing and endorsing the results of management reviews. Documentation of management reviews is mandatory, and records of such reviews must be retained.

The organization‘s quality management system shall be reviewed at least every 12 months by the organization’s management to evaluate the quality management system’s continuing suitability, adequacy, and effectiveness. This review shall include assessing opportunities for improvement and the need for changes to the quality management system, including the quality policy and quality objectives. The input to management review shall include, as a minimum:
– effectiveness of actions resulting from previous management reviews
– results of audits
– changes that could affect the quality management system, including changes to legal and other applicable requirements
– analysis of customer satisfaction, including customer feedback
– process performance
– results of risk assessment
– status of corrective and preventive actions
– analysis of supplier performance
– review of the analysis of product conformity, including nonconformities identified after delivery or use recommendations for improvement

The output from the management review shall include a summary assessment of the effectiveness of the quality management system. The assessment shall include any required changes (see 5.11) to the processes and any decisions and actions, required resources, and improvement to products in meeting customer requirements. Top management shall review and approve the output of management reviews. Management reviews shall be documented and records of these reviews shall be maintained,

The management review must address the possible need for changes to policy, objectives, targets, and other elements of the management system. Here’s what management systems standards are really all about: defining a policy and creating a plan with relevant objectives. You then implement the system according to the plan and begin auditing, monitoring and measuring performance against the plan and reacting to your findings. As such; management review meetings provide useful insight into the operation of the management system and its processes to enable Top management to respond to issues and to recommend improvements.

It is important that a member of Top management chairs the management review meetings. It is imperative that everyone involved with the management review process fully understand and appreciate the management review requirements. Other attendees at management review meetings should include functional management, line management, process owners, process champions, lead process users, and action owners within the scope of the quality management system, as appropriate, and the internal auditor(s) should also attend. The management review process must ensure that the necessary information is collected ahead of time to allow management to effectively carry out an evaluation prior to the meeting. Note taking and action recording is often undertaken by the Management Representative who will forward minutes of the management review meeting to those on the distribution list and to those with actions.

Critical management review agenda items, such as; process performance, customer feedback and monitoring and measuring results should be reviewed monthly, while less critical agenda items, such as reviewing the quality policy and objectives should be undertaken less frequently, perhaps every quarter. This approach minimizes the length of each management review meeting, covers all of the required management review inputs over the duration of the management review programme, and allows for the analysis of trends in data while the information is contemporary. Annual management reviews are insufficient in frequency to be able react to any issues effectively. Performance metrics should be monitored with varying frequencies, some hourly, some daily, some weekly and some monthly. Management cannot wait for six months to respond, if they do, it will be too late. Top management might conduct weekly meetings in which they review metrics and objectives to determine if any corrective action is required. The process owner is then responsible for reporting close out progress in the meeting a week later. Every time management convenes to review and react to performance, it is considered as a management review. Some companies have multiple review levels, whereby, each review may require multiple subjects and rely upon multiple metrics as inputs. Sometimes subjects are reviewed at more than one level, e.g. production numbers might be reviewed by the Production teams during daily production meetings and then by senior management, possibly weekly.

API Q1 5 Product Realization

5.1 Contract Review

5.1.1 General

The organization must uphold a documented procedure for reviewing requirements related to product provision. This procedure should cover determining requirements, reviewing requirements, and making changes to requirements.

5.1.2 Determination of Requirements

The organization must identify requirements outlined by the customer, legal regulations, and any other applicable criteria, as well as requirements not explicitly mentioned by the customer but deemed necessary by the organization for providing the product. In cases where the customer hasn’t provided documented requirements, the organization must confirm these requirements and keep records of the confirmation process.

5.1.3 Review of Requirements

The organization must assess the requirements regarding product provision. This assessment must occur before the organization commits to delivering the product to the customer. It should confirm that requirements are identified and documented, resolve any discrepancies from previously identified requirements, and ensure the organization can meet the documented requirements. If contract requirements change, the organization must update relevant documents and inform relevant personnel of the changes. Records of the review outcomes, including any resulting actions, must be kept.

The organization must establish a documented procedure for the Contract review that defines the process for the review of the requirements related to the provision of products and required servicing. The organization shall determine stated customer requirements, legal and other requirements, and requirements considered by the organization necessary for the provision of the products. When the customer requirements are not documented, the organization must confirm the requirements with the customer and record them. Before the organization‘s commitment to deliver products to the customer, the organization shall review the requirements related to the provision of products. The organization should ensure that requirements are identified and documented. The requirements differing from those previously identified are resolved and the organization can meet the documented requirements. Where contract requirements are changed, organizations must document all changes and amend all relevant documentation and the organizations must notify all affected personnel of changes The results of the review and the action taken must be recorded

The requirement states that the organization should now include a review of the requirements arising either from customer, legal or other requirements or the organization’s customer. The organization should seek and record evidence that these requirements are considered during product and service reviews. The sub-clause mandates that your organization should not issue a quotation or accept an order until it has been reviewed to ensure requirements are defined, and that the organization can meet the defined requirements. It goes on to require that records of the review and any subsequent actions be maintained. The organization should conduct a review of customer requirements before order acceptance. It can conduct a contract review checklist with the following headings as a minimum:

Necessary information is available:

  • Technical data;
  • Specifications and standards;
  • Drawings.
    Customer requirements are understood and can be met:
  • For product acceptance (e.g. Quality, inspections & tests, verification & validation, and any special monitoring);
  • For delivery expectations;
  • For post-delivery expectations.
    Related standards have been reviewed and can be met:
  • Statutory;
  • Regulatory;
  • International quality (e.g. ISO-9001:2015, API Q1);
  • Other necessary and applicable standards.
    Unclear or ambiguous requirements are resolved;
    Feasibility has been determined:
  • capability to meet order requirements;
  • have the equipment;
  • have the floor space;
  • have adequate resources;
  • have skilled personnel.
    Differences between the contract and quote are resolved;
    Methods of communicating with the customer are defined related to:
  • Product information;
  • Enquiries;
  • Feedback;
  • Concerns and complaints handling.
    Requirements that are not stated by the customer are defined.

If the customer does not provide their requirements in writing, the requirements must still be confirmed before they are accepted. Define your organization’s arrangements for the retention of documented information to capture the results of the review including any new requirements or changes e.g. record of contract review, including for example customer, reference, date, persons, resources, conventional/special requirements, risks outcome and changes.

5.2 Planning

The organization must identify and strategize the processes and documents necessary for product realization. During planning, the organization should address the following:

  1. Management of required resources and work environment.
  2. Product and customer-specified requirements.
  3. Legal and other applicable requirements.
  4. Design specifications.
  5. Contingency planning.
  6. Specific verification, validation, monitoring, measurement, inspection, and testing activities for the product, along with acceptance criteria.
  7. Management of change (MOC).
  8. Records are needed to demonstrate that product realization aligns with requirements.

The outcome of this planning must be documented and regularly updated to reflect changes. These plans should be organized in a structure suitable for the organization’s operations.

Planning is a critical requirement. During the discussion, participants will notice that sections (a) through (h) reference other parts of the API Spec Q1 10th edition specification. The organization must take the referenced sections into account during planning. Once the review of requirements has occurred, organizations can begin to plan for the manufacturing or servicing of products.

(a) Resources and Management
During planning, organizations must take into account resources and work environment management necessary for manufacturing or servicing products.

(b) Product and Customer Requirements
The organization must take into account Product and Customer-specified requirements (see 5.1).
Meeting customer-specified requirements at a minimum, must be achieved for the manufacturing or servicing of product to be accepted.

(c) Legal and Other Requirements
The expectation that organizations know and understand legal and other applicable requirements resonates throughout the API Spec Q1 10th edition. HSE, quality, and other requirements are included in this expectation. It is not possible to properly plan the manufacturing or servicing of products if the organization is not aware of the legal and other requirements that they are mandated to comply with.

(e) Contingency Planning
Based on the customer requirements for the manufacturing of the product, the organization shall identify the contingency plans for the identified risk found in the initial risk assessment to reduce and or eliminate the risk through the identified process or backup planning as well as developed employee competencies to manage the identified risk.

(f) Contingency Planning Based on Risks
Planning must include the initial risk assessments so that the risks can be mitigated.

(g) Design and Development Requirements
When planning under section 5.2 Planning, organizations must take into account section
5.4 Design and Development.

  • 5.4.1 Design and Development Planning
  • 5.4.2 Design and Development Inputs
  • 5.4.3 Design and Development Outputs
  • 5.4.4 Design and Development Review
  • 5.4.5 Design and Development Verification and Final Review
  • 5.4.6 Design and Development Validation and Approval
  • 5.4.7 Design and Development Changes.

(h) Verification, Validation & Test
Organizations must address the following for product acceptance:

  • Verification
  • Validation
  • Monitoring
  • Measurement
  • Inspection
  • Test activities

(i) Management of Change
Change is in manufacturing product. When things go wrong, or something unplanned occurs, the organization can refer to the contingency plan, which is still part of . However, when changes fall outside the scope of the contingency plan, an MOC is required. If changes initiated by the organization or the customer result in risks, the organization must notify the customer through the MOC process, as previously discussed.

(j) Records
Records are needed to provide evidence that the product realization processes meet requirements. This links to the following API Q1 elements:

  • 5.7.7 Inspection and Testing: Maintaining Records
  • 5.9 Product Release: Maintaining Records

5.3.2 Risk Assessment
5.3.2.1 Product Delivery

Risk assessment related to product delivery must consider factors such as facility and equipment availability, including maintenance, as well as supplier delivery performance and material availability/supply.

In API Specification Q1, risk assessment related to product delivery must indeed consider various factors to ensure the reliability and consistency of the supply chain. Assess the availability of production facilities, warehouses, and distribution centres. Consider factors such as capacity constraints, maintenance schedules, and potential downtime due to unforeseen events (e.g., equipment failure, natural disasters). Evaluate the availability and reliability of production equipment, machinery, and vehicles. Consider maintenance schedules, breakdown frequency, and the availability of spare parts to minimize the risk of production delays or disruptions. Assess the delivery performance of suppliers, subcontractors, and vendors. Evaluate factors such as lead times, on-time delivery rates, quality consistency, and reliability. Poor supplier performance could lead to delays in receiving essential materials or components, impacting product delivery schedules. Evaluate the availability and reliability of raw materials, components, and supplies required for production. Consider factors such as supplier reliability, inventory levels, lead times, and potential supply chain disruptions (e.g., geopolitical events, transportation delays, raw material shortages). Assess the transportation and logistics infrastructure used for product delivery. Consider factors such as transportation modes, routes, transit times, customs clearance processes, and potential transportation-related risks (e.g., accidents, strikes, fuel shortages). Evaluate the variability in customer demand and the accuracy of demand forecasting. Consider factors such as seasonality, market trends, customer order patterns, and the potential impact of unexpected changes in demand on production and delivery schedules. Consider regulatory requirements and quality standards that must be met throughout the product delivery process. Ensure compliance with relevant regulations, industry standards, and customer specifications to mitigate the risk of non-compliance-related delays or penalties. Develop contingency plans and risk mitigation strategies to address identified risks and uncertainties. Implement measures such as safety stock levels, alternative sourcing options, supplier diversification, and business continuity plans to minimize the impact of potential disruptions on product delivery. By considering these factors in the risk assessment process, organizations can proactively identify potential risks and vulnerabilities in the product delivery process and implement appropriate measures to enhance supply chain resilience, reliability, and performance by API Specification Q1 requirements.

5.3.2.2 Product Quality

Risk assessment concerning product quality must encompass factors such as the delivery of nonconforming products and the availability of competent personnel.

Absolutely, in API Specification Q1, risk assessment concerning product quality encompasses various factors to ensure that products meet the required standards and specifications. Evaluate the risk associated with the delivery of nonconforming products to customers. This includes assessing the potential impact of defects, deviations, or failures in products on customer satisfaction, safety, and regulatory compliance. Implement measures to prevent, detect, and address nonconformities throughout the production and delivery process. Assess the effectiveness of product inspection and testing procedures to ensure that products meet quality requirements before delivery. Consider factors such as the frequency of inspections, sampling methods, testing protocols, and the reliability of testing equipment and personnel. Identify potential gaps or weaknesses in inspection and testing processes that could increase the risk of delivering nonconforming products. Evaluate the quality performance of suppliers and subcontractors to minimize the risk of receiving nonconforming materials, components, or services. This includes assessing supplier capabilities, quality management systems, compliance with specifications, and past performance history. Establish clear criteria for selecting and evaluating suppliers, and implement measures to monitor and improve supplier quality over time. Assess the competence and proficiency of personnel involved in product manufacturing, inspection, testing, and delivery. Ensure that employees have the necessary knowledge, skills, training, and experience to perform their roles effectively and contribute to product quality. Provide ongoing training and professional development opportunities to enhance employee competence and awareness of quality requirements. Evaluate the effectiveness of process controls and monitoring mechanisms to prevent quality-related issues during product manufacturing and delivery. This includes implementing procedures for process validation, control of critical parameters, real-time monitoring of production processes, and corrective actions in response to deviations or abnormalities. Assess the potential impact of changes to processes, materials, equipment, or specifications on product quality. Implement robust change management procedures to evaluate, approve, and implement changes in a controlled manner while minimizing the risk of unintended consequences or quality-related issues. Monitor customer feedback, complaints, and returns to identify potential quality issues and trends. Implement procedures for promptly addressing customer concerns, investigating root causes of quality-related problems, and implementing corrective and preventive actions to prevent recurrence. Foster a culture of continuous improvement to enhance product quality and customer satisfaction over time. Encourage employees to identify opportunities for process optimization, quality enhancement, and innovation. Regularly review and update quality management processes based on lessons learned, best practices, and industry advancements. By considering these factors in the risk assessment process, organizations can effectively manage risks related to product quality and ensure that products consistently meet customer requirements and regulatory standards in accordance with API Specification Q1.

5.3.2.3 Changes Impacting Product Quality

If any of the listed alterations have the potential to adversely affect product quality, a risk assessment concerning product quality must be conducted:

  1. Changes in the organizational structure;
  2. Changes in key personnel;
  3. Alterations in the supply chain of critical products, components, or activities;
  4. Modifications to the management system scope or procedures; and
  5. Adjustments to the organization’s capacity to execute the processes needed for product realization.

Note: Changes may originate internally or externally.

The organization must establish a documented procedure to identify and control risks associated with the impact on the delivery and quality of the product. The procedure must identify the techniques and tools to be applied for risk identification, assessment, and mitigation. The risk assessment must include the availability of facilities, and availability of equipment. It must also include the maintenance of facilities and equipment. The supplier performance should be part of the risk assessment which must also include the supply/availability of material. Availability of competent personnel and delivery of nonconforming products must also be included. Record of Risk assessment and the management of risk should be available. A contingency plan may be developed as a result of risk assessment. Corrective action and /or preventive action can be taken as a result of risk assessment. Risk assessment includes consideration of severity, detection methods, and probability of occurrence.

The purpose of the procedure is to outline your organization’s risk management framework and the activities within. The risk management framework defines the current risk management process, which includes; methodology, risk appetite, methods for training and reporting. Risk Assessment and Management is fundamental to API Spec Q1, 9th edition success as well as aiding the organization to eliminate loss associated with its manufacturing products, processes and services. The API Spec Q1, foundation is about understanding and mitigating risks associated with its manufacturing processes, products and services. By design, this Specification does not detail the organization’s procedure for Risk Assessment and Management. Since there are many different methods and applications available to organizations, it will be up to the manufacturing or servicing providers to decide which procedure best fits their needs. Risk-Based Management is the identification, assessment, and prioritization of risks followed by coordinated and economical application of resources to minimize, monitor, and control the probability and/or impact of unfortunate events or to maximize the realization of opportunities.

  1. Identify the Risks :A lot will go into the identification of potential risks for a company. There are two distinct kinds of risk that a company may encounter: external and internal. External risk is the risk incurred from the environment in which the company operates. These can be legal, regulatory, financial, and cultural risks. Internal risk is the risk incurred from within an organization. This can be caused by an organization’s structure, resource deficiencies or allocation, and hierarchy. Risk needs to be determined within the context of the business, something that will lead to different definitions of each term for different organizations.
  2. Plan Your Response:As with any other part of the standard, companies are required to develop a plan for addressing the risks and opportunities they’ve identified. A company will need to do an in-depth assessment of the possible risks for this part. How likely are these risks? How disruptive would they be if they were to happen? What amount of resources is your company willing to dedicate to mitigating these risks? Can their likelihood be increased while mitigating the risk? Is the potential risk worth incurring for a chance at capitalizing on the opportunity? Once these assessments have been made, an organization can develop a plan for addressing the risks based on their stated strategies. Without properly assessing their risk appetite, an organization cannot properly plan to either mitigate it or capitalize on the opportunities it presents. These plans need to be laid out, with a plan for documenting the process and keeping clear records on it.
  3. Integrate the Response into Your QMS:This step requires a company to insert the plan they’ve developed for addressing risk and opportunity into the greater framework of the QMS that they already have in place. This step is critical, in that the plan needs to allow for the rest of a company’s QMS to remain seamless. As a standard that emphasizes universal application, nature will require that the process developed for addressing risk be compatible with all other procedures in the company. For this reason, keeping a company’s QMS in mind as it goes through the process of developing a plan for addressing risk and opportunity can prove to be helpful. Developing a plan only to find that it doesn’t integrate well into the larger process means time and energy have been wasted.
  4. Evaluate Effectiveness:As with any other procedure in a company, proper documentation and record-keeping processes will need to be put in place. This is where a company can record the outcomes and measure the effectiveness of its efforts. This stage in the process is also why it is crucial to develop a comprehensive assessment of the company’s willingness to take on risk and pursue potential opportunities. Without a detailed understanding of the company’s aims in regard to both risk and opportunity, it will be all but impossible to properly assess the effectiveness of the process that’s been implemented. As with any procedure, this step allows for the constant scanning of potential inefficiencies that can be improved upon. It should be noted that context is also a key factor in any risk assessment process. Risk at one juncture of the process might look different than the same risk at another juncture. This is why having a comprehensive strategy for risk assessment is critical. Preparing for and thinking about all the possibilities will help better prepare your company.

5.3.3 Contingency Planning

If the organization deems it necessary to have a contingency plan due to assessed risks, the plan must, at a minimum, outline actions needed to mitigate the impact of disruptive incidents, assign responsibilities and authorities, and establish controls for internal and external communication. These contingency plans must be documented, communicated to relevant personnel, and revised as necessary.

While contingency has been applied by the industry for years, the application has been inconsistent and has overlooked critical information to mitigate risks. The standard mandates that a documented procedure for contingency planning must be available. This requirement for the procedure will include risk mitigation for the delivery and quality of the product. Contingency planning is needed to address risk associated with the impact on:

  • Delivery and Product Quality.
  • Based on the assessed risk
  • Communicated to relevant personnel.

Contingency planning output must be documented and communicated to the relevant operational personnel and updated as required to minimize the likelihood or duration of disruption of manufacturing. The outputs of the contingency planning must be based on assessed risks that were discussed in section 5.3 of this specification. As mentioned in the dictation under 5.5.1, the better the Risk Assessment, the less disruption and the smaller the likelihood of an incident. If an incident does occur, it is more likely to be contained or controlled through contingency planning, thereby minimizing loss.

The contingency plan shall include, at a minimum:

  • Actions required in response to significant risk scenarios to mitigate effects of disruptive incidents;
  • Identification and assignment of responsibilities and authorities, and
  • Internal and external communications controls

Actions Required in Response to Significant Risks covers actions required in response to significant risk scenarios to mitigate effects of disruptive incidents. This is obvious and is what most manufactures often think of when doing contingency planning. This is how we prevent or mitigate the “Incident” we discussed in 5.5.1 of the specification. Here, the manufacture must review different real and potential risk scenarios and do the proper assessments to understand the in order to prevent and/or mitigate the loss. Most manufactures do this as it relates to HSE. However, API Spec Q1 requires this to be done to include delivery and product quality related incidents as well.                                        

The basic contingency planning process includes

1. Map out essential processes.

What processes are essential to your business and safely delivering your product or service to customers? If you’re a manufacturing company that ships directly to consumers, a simplified process list might look something like this:

  • Getting raw materials from suppliers
  • Manufacturing process
  • Freight and shipping
  • Packaging and warehousing
  • Last-mile delivery

Looking at this list, you can see how vulnerable it is to natural disasters or even minor human errors.

2.Create a list of risks for each process.
Once the process list is created, consider what might disrupt business continuity. What can go wrong with each of these critical processes? Let’s look at an example of what could go wrong with “last-mile delivery”

  • The driver can deliver single or multiple packages to the wrong address.
  • The package can be damaged during delivery.
  • The package could get lost at a distribution center.
  • A truck full of packages could be involved in an accident.
  • A flood could cripple the road system in a specific area.
  • The driver could get delayed because a moose wants to lick salt splatter off the car (seriously, it’s a thing).
  • And that’s only a preliminary list. Once you start thinking about it, you’ll realize how many things you rely on to avoid going wrong, even for fundamental processes.

Every business process is vulnerable to some sort of emergency or human error.

3. Evaluate the potential impact and likelihood of each risk.
Once the risks are identified, it’s essential to determine how they could impact your business. Are they likely to happen? How large will the impact on your business if they do occur? Most companies use “qualitative risk assessment” to do this.

4. Calculate costs and contingency reserves, and identify issues to mitigate.

The quantitative risk assessment approach is to assess the potential cost of each risk. This means you can make an educated decision when budgeting contingency reserves into project plans and yearly budgets. During the risk analysis, estimate the potential costs of the adverse event.

5. Create a response plan for prioritized events.

Create a response plan for events by exploring the following questions:

  • What can be done ahead of time to minimize any adverse effects on the event? For example, backing up data, carrying extra stock, or having more employees on call.
  • What can be done immediately after the event to minimize the impact? For example, ordering more from a secondary supplier, rerouting another vehicle, or bringing in on-call staff.

The specifics depend on your company’s unique processes and situation.

5.3.4 Records

Records documenting risk assessment and management, including the actions implemented, must be retained.

As per API Specification Q1, records documenting risk assessment and management, along with the actions implemented, must be retained by the organization. These records serve as evidence of compliance with the standard’s requirements and provide a historical record of the organization’s risk management efforts. The organization should maintain records of the risk assessment process, including the identification of potential risks, their likelihood and impact, and the criteria used to prioritize and evaluate risks. This documentation may include risk registers, risk matrices, risk assessment reports, and any supporting documentation used in the risk assessment process. Records should be kept of the actions taken to address identified risks and mitigate their potential impact. This includes documenting the specific measures implemented, responsible parties, timelines, and outcomes. For example, records may include copies of contingency plans, change management records, corrective and preventive action reports, and documentation of risk mitigation strategies. Records should document the decision-making process related to risk management, including discussions, evaluations, and approvals. This helps ensure transparency and accountability in the risk management process and provides a basis for reviewing and evaluating the effectiveness of risk management decisions over time. Records should be maintained of ongoing monitoring and review activities related to risk management. This includes tracking the status of identified risks, monitoring changes in risk factors, and assessing the effectiveness of risk mitigation measures. Records of management reviews, risk assessment updates, and audit findings related to risk management should be retained. The organization should establish a retention period for records related to risk assessment and management based on regulatory requirements, industry standards, and internal policies. Records should be retained for a sufficient period to demonstrate compliance with API Specification Q1 and to support future audits, assessments, or reviews. Ensure that records related to risk assessment and management are securely stored and protected from unauthorized access, alteration, or destruction. Implement appropriate controls to safeguard sensitive or confidential information contained in these records. At the same time, ensure that authorized personnel have access to the records as needed for business continuity and compliance purposes. Records related to risk assessment and management may be stored in various formats, including electronic or paper-based formats. Regardless of the format, ensure that records are legible, accurate, complete, and readily retrievable when needed.

5.4 Design
5.4.1 General

If the organization is accountable for product design, it must adhere to the requirements outlined in section 5.4. However, these design requirements do not apply if the product is involved in production activities, servicing, storage, distribution, or logistics.

In API Specification Q1, the requirements for product design apply specifically to organizations that are accountable for the design of products. However, these design requirements do not apply if the product is involved in production activities, servicing, storage, distribution, or logistics.

This distinction is important because not all organizations within the petroleum and natural gas industry are responsible for product design. For example, a company that primarily engages in production activities, such as drilling or refining, may not be directly involved in designing the products they produce. Instead, they may rely on suppliers or manufacturers to provide designed products, such as equipment or components, that are used in their production processes. On the other hand, organizations that are accountable for product design must adhere to the specific requirements outlined in the API Specification Q1 related to designing products. These requirements typically include:

  1. Establishing a design process that ensures products meet specified requirements and are suitable for their intended use.
  2. Identifying and documenting design inputs, including customer requirements, regulatory requirements, and any other relevant specifications.
  3. Performing design verification and validation activities to ensure that the designed product meets the specified requirements and performs as intended.
  4. Documenting the design process and maintaining records of design activities, decisions, and revisions.
  5. Implementing controls to manage changes to the design and ensure that changes are properly evaluated, approved, and communicated.

By adhering to these requirements, organizations accountable for product design can ensure that their designed products meet the necessary quality, safety, and performance standards. However, organizations that are not responsible for product design are exempt from these requirements and are instead expected to focus on other aspects of their operations, such as production, servicing, storage, distribution, or logistics, as specified in API Specification Q1.

5.4.2 Design Planning

The organization must uphold a documented procedure for planning and overseeing the design process. This procedure should cover:

a) Planning, including updates to the plan(s), used for design.
b) Various stages of the design process.
c) Allocation of resources, responsibilities, authorities, and their interactions.
d) Review, verification, and validation activities required for each design stage.
e) Requirements for a final review of the design.
f) Criteria and approval process for design changes.

When design activities are outsourced or carried out at different locations within the organization, the procedure should outline controls to ensure compliance with design requirements. If design activities are outsourced, the organization remains accountable for the design and must ensure that the supplier meets outsourcing requirements. Design review, verification, and validation serve distinct purposes but can be conducted and recorded separately or in any combination, as appropriate for the product and the organization.

The organization must maintain a documented procedure to plan and control the design and development of the product. The organization’s procedures are to identify:

  • Design and development plans and plan updates
  • The design and development stages
  • The resources, responsibilities, authorities, and their interfaces to ensure effective communication
  • The review, verification, and validation activities necessary to complete each design and development stage
  • The requirements for a final review of the design

Design and development for products will vary greatly in complexity. Some products present low risks while others may present significant risk, based upon their design and application. All product in the Petroleum, Oil and Gas Industry is expected to meet the requirements of 5.4 Design & Development. The organization shall maintain a documented procedure to plan and control the design and development of the product.

  • Plans and Updates: Plan and control procedure must include the design and development plans and plan updates.
  • D&D Stages: Under this Subpart, organizations are required to identify the D&D stage in its plan and control procedure.
  • Resources, Responsibilities & Authorities: Plan and control procedures must include the resources, responsibilities, authorities and their interfaces to ensure effective communication for the D&D activities
  • Review Activities: In addition to identifying the different D&D stages in the plan and control procedure, organizations must include the review, verification, and validation activities necessary to complete each design and development stage.
  • Final Review: The plan and control procedure the requirements for a final review of the design.

Design planning must specify the design and development stages, activities and tasks; responsibilities; timeline and resources; specific tests, validations and reviews; and outcomes. There are many tools available for planning ranging from a simple checklist to complex software. Control product design and development planning activities including:

  1. Scope of the design e.g. customer requirements design rationale, design assumptions, objectives, complexity, size, detail, timescales, criticality, constraints, risks, producibility, accessibility, maintainability;
  2. Stages of the design process, distinct activities and review e.g. work breakdown structure, work packages (tasks, resources, responsibilities, content, inputs/outputs), concept design, preliminary design, detail design, design review gates preliminary design review, detail design review, critical design review);
  3. Verification and validation activities comprising checks, trials, tests, simulations, and demonstrations are required to ensure requirements are met;
  4. Assignment of responsibilities and authorities e.g. job profiles, CVs, accountability statements, delegation of authority, levels of approval, register of authority and approvals, authorized signatories;
  5. Internal and external resources such as knowledge acquisition, people, competency, investment, funding, facilities, equipment, innovation, technology, interested parties (customers, external providers, research establishments), information (principles, standards, rules, codes of practice);
  6. Organizational interfaces such as personnel and functions e.g. sales, project management, production, procurement, quality, finance, customers, and end-users;
  7. Levels of control required or implied by interested parties (customers, regulators, end users etc.) e.g. customer acceptance, safety checks, risk management, verification/validation activity, product certification;
  8. Required documented information e.g. design plan, design reviews, design outputs (specifications, schemes, drawings, models, data, reports), control plans, certificates.

The design management plan typically includes specific quality practices, assessment methodology, record-keeping, documentation requirements, resources, etc., and usually references the sequence of activities relevant to a particular design or design category. The design management plan references applicable codes, standards, regulations and specifications. and describe the interfaces with different groups or activities that provide, or result in, input to the design and development process. Each design activity is planned, and divided into phases, and tasks are assigned to competent and skilled design personnel equipped with adequate tools and resources. Design management plans are documented and updated as the design evolves. As required, at the commencement of a design package, the Design Manager is required to complete a Design Management Plan (DMP) which will include at a minimum:

  1. Confirmation of the standards baseline used for the work being undertaken and an explanation of how compliance to this baseline will be demonstrated;
  2. An organisation chart with defined responsibilities for all staff with direct involvement in the design or with a potential impact on safety;
  3. Skills matrix to define the competence of individuals with ‘prepare’, ‘check’ and ‘approval’ duties;
  4. Scope definition and interface identification including key issues and operational requirements;
  5. Projected output, timelines, milestones, and defined deliverables;
  6. Stated processes and procedures to ensure acceptable quality assurance will be demonstrated and records maintained (specifically the formal Assurance Gates);
  7. Processes and procedures to be used to ensure compliance with the engineering safety management;
  8. The design review process, both single (SDR) and multi-design consultant (IDR) reviews and stakeholder intervention, before the Assurance Gate Reviews at 20%, 60% & 100% design completion stages;
  9. Explanation of how compliance with input requirements will be demonstrated.

5.4.2 Design and Development Inputs

5.4.3 Design Inputs

Inputs must be identified and assessed for adequacy, completeness, clarity, and absence of conflicts. Any identified issues must be resolved. Inputs may encompass functional and technical requirements, along with the following, if applicable:

  1. Customer-specified requirements;
  2. Requirements from external sources, including API product specifications;
  3. Environmental and operational conditions;
  4. Documentation of methodologies, assumptions, and formulas; e) Historical performance and other data from similar previous designs;
  5. Legal requirements; and
  6. Potential consequences of product failure, as required by legal mandates, industry standards, customer specifications, or deemed necessary by the organization.

Records of design inputs must be retained.

The organization must identify the Design Inputs and review them for adequacy, completeness, and lack of conflict. The functional and technical requirements of Design Inputs can be customer-specified, requirements provided from external sources, including API product specifications, environmental and operational conditions, methodology, assumptions, formulae documentations, historical performance and other information derived from previous similar designs, legal requirements and results from risk assessments. The design inputs must be recorded.

Define which design inputs are required to carry out the design and development process. The inputs should be determined according to the design and development activities. For example, which employees are required or what information is required for every step of the development process? When determining design input requirements, ensure the retention of documented information such as:

  • Statutory and regulatory requirements e.g. legislation, regulation, directives;
  • Standards or codes of practice e.g. policies, standards, specifications, rules and aids, protocols, guidance, industry codes
  • Functional and performance requirements informed by customer requirements, operational and performance characteristics, usability, reliability, availability, maintainability, and safety (e.g. Human factors and RAMS);
  • Knowledge exchange from others, similar proven designs, lessons learned, performance data, in-service data, customer feedback, external feedback, best practice, benchmarking;
  • Design assumptions and associated risks;
  • Methods of validation and verification;
  • Adequacy of inputs e.g. clear, complete, unambiguous, and authorized;
  • Conflicting inputs are resolved by communicating with interested parties/contract amendments.

Conceptual Design Statement (CDS)

The Conceptual Design Statement (CDS) includes a design statement that declares the inputs to be used in the design and the proposed design solution. A design statement illustrates the principles concepts and input data relevant to the design and allows relevant stakeholders to understand the thinking behind any chosen design solution. The Design Team will normally produce a Conceptual Design Statement that states the standards and requirements against which the design is to be developed, the processes to be applied and the level of independent checking to be carried out (if any) that is proportionate to the level of risk. The design activities are then carried out by the Design Team using the CDS as the basis. Design and development inputs are documented and controlled. Design and development inputs can be in any form, including data sheets, customer drawings and specifications, photographs, samples, references to standards, etc.

Design standards baseline

All designs are based on a list of approved design standards, referred to as the Standards Baseline. This list is owned and managed by the Engineering Manager. The Standards Baseline is made up of a combination of National and International Standards, National Engineering Specifications, and Approved Codes of Practice. The Standards Baseline should be reviewed monthly and any changes are controlled by the Engineering Manager. At the commencement of any given design package, the Design Team is required to specify the Standards Baseline that will be used in the design. The Engineering Manager should be responsible for checking that the correct design standards have been specified and for verifying that the design output complies with these standards and design requirements. Due to the continuous review and updating of standards, the baseline between different design instructions may vary so a strict configuration control is maintained and only agreed changes are used in the assurance process. Once a design package has been instructed, the baseline for that element of work becomes fixed and will not reflect any subsequent changes in standards.

Design assumptions

Assumptions will normally be statements to fill uncertainties in available information. They are generated by the Design Team to allow designs to continue in the early stages. The anticipation is that assumptions are temporary and are closed out either by obtaining data or updating documents to confirm or change the assumption. Assumptions have the potential to be incorrect and are therefore a source of risk, that requires management. Any associated risk is identified and raised through the Risk Register. The assumption management activity is coordinated by the Design Manager, with input from the Design Team. Assumptions regarding domain knowledge include facts about the application of the end product or service that allow requirements to be developed in a particular context. The assumptions are normally traceable to gaps or inconsistencies in the design inputs e.g. incomplete or conflicting functional requirements, inconsistencies between the applicable Standards, unclear scope of work, or demarcation issues. The Responsible Body; which might be another company, organisation, person, or team against which an assumption has been made or who are responsible for providing a feature or undertaking an action to resolve an assumption agreed by them. Qualifying criteria for design assumptions are based on the following:

  • Assumptions on scope and allocation;
  • The assumption regarding gap or conflict in the stated capabilities, systems or operational aspects;
  • Conflict between standards;
  • Assumptions due to missing design data;
  • Assumptions regarding a design decision;
  • Assumptions relating to interface issues.

Assumptions must not be raised on programme and cost-related matters. The requirements or the design statement will be verifiable against the raised assumption or the origin of the assumption. Assumptions are accepted by the Resolving Body; they may be turned into design requirements or project risks. The process for managing design assumptions is summarised as follows:

  • Assumptions are managed using an Assumptions Register;
  • The Design Team propose an assumption to fill an uncertainty;
  • The Engineering Manager reviews the suitability of the assumption against the criteria;
  • Once agreed with the Resolving Body, the Design Team updates the assumption register;
  • Action owner closes out assumption by the agreed date, this could be done either by establishing additional data or confirming a decision;
  • The Engineering Manager monitors that action owners are closing out assumptions and takes action to expedite if necessary;
  • Any assumption remaining at the end of the design phase must be clearly recorded in the Assumptions Register and transferred to the Risk Register.

Assumptions are considered closed when they are successfully resolved i.e. accepted by the Resolving Body and the Resolving Body has taken an action that is documented in a resolving document. This resolving document must be properly reviewed, verified and issued before the closure of an assumption is accepted. The respective Gate Review Authority are the final authority to accept or reject the closure of an assumption. The confirmation of closure is noted in the Assumptions Register and a reference to the resolving document with the relevant clause is provided for verification purposes.

Design requirements

The design management process is geared towards meeting customer requirements, while providing a product cost, which enables organizations to have a satisfactory return on investment. The physical and performance requirements of a product used as a basis for product design and development; includes user requirements, regulatory requirements, and system requirements. The customer and user requirements are translated into design requirements and may either be hardware or software (according to intended use) and included in the design specifications and other design documents.

The requirements are reviewed for adequacy by a cross-functional, multidisciplinary team involving Design, Engineering, Sales, Manufacturing, Procurement, Sales and Quality to ensure the requirements are complete, unambiguous and not in conflict with each other. The Design Team notifies the Engineering Manager if the requirements are ambiguous or conflict with each other. The Design Team produces evidence of the capture of and compliance with the requirements. This evidence is presented in the Requirements Register. The Design Team should provide compliance matrices and verification reports to demonstrate how the designs meet the requirements, supported by the compliance rationale, evidence, models and analysis as required, whilst ensuring that:

  • All requirements are traceable to the identifier, author, rationale, source, requirement owner, allocation and stakeholder;
  • All requirements have been validated and approved by identified personnel;
  • All requirements have been reviewed and agreed upon with the customer;
  • Are requirements are recorded into the project applicable database;
  • All allocated requirements are understood and accepted by all the recipients.

In order to progress their close-out and acceptance, compliance statements are prepared and allocated to each requirement, commensurate to the design stage e.g. Gate 1, 2, or 3. Links and references to supporting drawings and documents are provided as the design progresses.

Customer-supplied user requirements are transferred to the Requirements Review Checklist and additional requirements are addressed with the customer. The Marketing Manager and the Sales Manager should identify and document the markets’ need for new solutions in a requirement statement which serves as the input for design and development work. The requirement statement includes the following:

  • What is required (features/functions, etc.);
  • Why it is needed (customer demand);
  • When it is needed;
  • Assumptions needed to progress the design;
  • Risk and opportunity, and hazard analysis;
  • Requirements for performance, reliability, safety, statutory and regulatory, etc.;
  • Pricing targets and design project milestones.

When a product is designed or modified to meet specific customer requirements, the Engineering Manager receives from Marketing Manager and the Sales Manager an outline design order with customer requirements and specifications. The Design Team translates the needs and expectations from the requirements and design statements to technical specifications for materials, products, services and processes.

Design interfaces

Where necessary, the Design Team should form working groups to develop interface control documents and record agreements for interfacing stakeholders in order to elicit their requirements and to provide feedback that may be important to your designs. Their emphasis should be on the identification and co-ordination of the important characteristics, parameters and configurations that need to be developed to deliver effective interface designs. The level of detail documented must be proportionate with the level of detail being developed in the design outputs.

  1. Identify, specify and manage interfaces;
  2. Assist in the resolution of interface issues relating to commercial or contractual issues;
  3. Assist in the production of and agree on interface documents with interfacing parties;
  4. Ensure that the process of interface management is fully supported during the development of detailed designs;
  5. Review and monitor the development of interface identification.

Design documentation

The established document numbering system must be used by the Design Team. All documents produced to support the design and the design assurance process should be listed in the Master Design Document List, which is a list of all plans, processes and procedures to be used to control the safety, quality and efficiency of the design output.

All design documents must follow the ‘Prepare’, ‘Check’, and ‘Approve’ process, evidenced by the signatures of competent individuals. All design documents should be signed off in the three categories:

  1. Prepared – by a competent person who produces the design document, checking their own work complies with codes and standards governing that work.
  2. Checked – by a competent person able to undertake a formal detailed check/review of design methods, codes and standards used, deliverables, calculations, drawings and specifications produced by another member of the Design Team. This role is undertaken by a competent person of the same discipline, not the Preparer, but can be a member of the same team.
  3. Approved – by a competent person of the same discipline, but not a member of the same team, able to undertake a review of the design output after detail checking has taken place to validate that the design is consistent with requirements, is fully integrated and satisfies interface requirements.

Design reference materials (e.g. standards, catalogues, etc.) should be available and maintained by the Engineering Manager. Only current issues and revisions of reference material must be used. All documents produced to support the design and the design assurance process must be listed in the Master Design Documents List.

5.4.4 Design Outputs

The documentation of outputs must enable verification against the requirements outlined in the design inputs. These outputs should:

  • Meet the requirements specified in the design inputs.
  • Provide information for purchasing, production, inspection, testing, and servicing, as applicable.
  • Identify or reference design acceptance criteria (DAC).
  • Include identification of, or reference to, products, components, and/or activities considered critical to the design.
  • Incorporate the results of relevant calculations.
  • Specify the characteristics of the product essential for its intended purpose and safe and proper function.

Records of design outputs must be retained. Identification of criticality of products, components, and/or activities may be managed separately from the design process.

The outputs of Design should meet the input requirements for design and development. It must provide appropriate information for purchasing, production, and servicing. It must identify or must design acceptance criteria (DAC). It must identify or refer to products and/or components which are critical to the design. It must include results of applicable calculations and must specify the characteristics of the product that are essential for its safe and proper use. The organization must document its Design outputs for verification against the design and development input requirements. The design output must be recorded. Identification of criticality of products and/or components can be maintained outside of the design and development process. The design and development output is the result of the design and development process. The output is a clear description of the product, containing detailed information for production. The organization’s design and development outputs reconcile with its design and development inputs by:

  1. Ensuring outputs meet input requirements e.g. checklists, design review records, authorization to proceed, customer acceptance, and product certification;
  2. Ensuring outputs are adequate for product and service provision e.g. standards, specifications, schemes, drawings, models, part lists, materials, methods, manufacturing instructions, technical packages, tooling, machine programs, preservation, handling, packaging, specialist training, user instructions, service manuals, repair schemes, and external provision;
  3. Reference to monitoring and measuring equipment e.g. inspection equipment, gages, instruments, environment;
  4. Acceptance criteria e.g. product/service specification, limits, tolerances, and quality acceptance standards;
  5. Product/service characteristics e.g. key characteristics, customer critical features, interface features, inspections, service intervals, and operating characteristics;
  6. Critical items such as identification, key characteristics, special handling, service intervals, component lifting, cyclic life, life management plans, source and method change, and traceability;
  7. Outputs are approved prior to release e.g. scope of authorization, authorized persons, levels of authorization, method of authorization and documented information is retained.

Outputs of the detailed design are the final technical documents used for purchasing, production, installation, inspection and testing, and servicing. Design output includes production specifications as well as descriptive materials which define and characterize the finished design and include drawings and documents used to procure components, fabricate, test, inspect, install, maintain, and service the product. Design and development outputs are in the form of documented information that defines the product, including its characteristics that affect safety, fitness for use, performance, and reliability are provided for the manufacturing phase:

  1. Schematics, assembly drawings and wiring diagrams.
  2. Component and material specifications.
  3. Production and process specifications.
  4. Software design specifications.
  5. Bills of materials.
  6. User operation and maintenance instructions.
  7. Results of risk analysis and transfer of residual risk.
  8. Software source code and software machine code.
  9. Results of verification and validation activities.
  10. Quality assurance specifications and procedures.
  11. Installation and servicing procedures.
  12. Packaging and labeling specifications, including methods and processes.
  13. Details of new or revised procedures, work instructions, or processes.
  14. Applicable workmanship standards.
  15. Inspection and test criteria.

Specifications and procedures for product packaging and labelling are also part of the design and development output. Support documentation (e.g. calculations, risk analysis, test results, verification and validation reports, etc.) is also part of the design and development output. The transfer of a design to production typically involves review and approval of specifications and procedures and, where applicable, the proving of the adequacy of the specification, methods and procedures through process validation including the testing of finished product under actual or simulated use conditions. The design transfer phase ensures that the design is correctly translated into production specifications, such as assembly drawings, component procurement specifications, workmanship standards, manufacturing instructions, and inspection and test specifications. They may also be:

  1. Documentation (in electronic format as well as paper);
  2. Training materials (e.g. manufacturing processes, assembly, and test and inspection methods);
  3. Digital data files (e.g. computer-aided manufacturing (CAM) programming files);
  4. Manufacturing jigs and other aids (e.g. moulds or templates).

The Engineering Manager should ensure that the design transfer process addresses the following basic elements:

  1. Undertaking a qualitative assessment of the completeness and adequacy of the production specifications;
  2. Ensuring that all documents and articles that constitute the production specifications are reviewed and approved;
  3. Ensuring that only approved specifications are used for manufacture and production.

Prior to execution of a work transfer, analysis of any regulatory or contractual requirements are reviewed and flowed down through the supply chain to ensure compliance of any established requirements. Outputs may also include product preservation methods, identification, packaging, service requirements, etc. as appropriate.

5.4.5 Design Review

At appropriate stages, evaluations must be conducted to assess the suitability, adequacy, and effectiveness of the outcomes of design stages in meeting specified requirements, and to identify any issues and recommend required actions. These reviews must involve representatives from relevant functions associated with the design stages under review. Records of the review outcomes and any subsequent actions must be retained.

Periodically at suitable stages of Design, the organization must review its Design. The review is performed to identify any problems and take necessary actions. The organization must evaluate the suitability, adequacy, and effectiveness of the results of design stages to meet specified requirements. Representatives of concerned functions should be part of the review. The result of review and any necessary action should be recorded. Design reviews should be carried out after the initial concept stage and again after the detailed design stage and finally, before the design is released. The design review function is carried out at various stages of the design process in order to check that the design solution is in accordance with the original design inputs and objectives and includes identification of concerns, issues and potential problems with the design. Design review meetings should be held at pre-defined points during the development process, with reviews held on an as-needed basis, depending upon the complexity of the design. Participants of design review meetings are competent to evaluate the design stage and discipline under review to permit them to examine the design and its implications.

Assurance reviews: The Design Manager should ensure that design reviews are carried out by the Design Management Plan when the design has progressed by 20%, 60% and 100%. A cross-functional, multidisciplinary team (including at least one individual who does not have direct responsibility for the design stage under review) undertake a documented, comprehensive, systematic examination of the design to evaluate its adequacy, to determine the capability of the design to meet the requirements, and to identify problems, whilst ensuring that:

  1. The input for the Design Reviews is captured from all stakeholders;
  2. All open actions from previous Design Reviews are tracked through to closure;
  3. All areas of concern are highlighted for further discussion and risk mitigation;
  4. All design reviews are documented and shared with stakeholders promptly.

The following elements are considered during design reviews:

  1. Customer needs and expectations versus technical specifications;
  2. Ability to perform under expected conditions of use and environment;
  3. Safety and potential liability during unintended use and misuse;
  4. Safety and environmental considerations;
  5. Compliance with applicable regulatory requirements, national, and international standards;
  6. Comparison with similar designs for analysis of previous quality problems and possible recurrence;
  7. Reliability, serviceability, and maintainability;
  8. Product acceptance/rejection criteria, aesthetic specifications and acceptance criteria;
  9. Ease of assembly, installation, and safety factors;
  10. Packaging, handling, storage, shelf life, and disability;
  11. Failure modes and effects analysis;
  12. Ability to diagnose and correct problems;
  13. Identification, warnings, labelling, traceability, and user instructions;
  14. Manufacturability, including special processes;
  15. Capability to inspect and test;
  16. Materials and components specifications;
  17. Review and use of standard parts.

The reviewers are responsible for raising any comments, while the Design Manager should be responsible for capturing comments using the Design Review Meeting Minutes. Conclusions drawn during design reviews are considered and implemented as appropriate. Not all identified concerns result in corrective actions, the Engineering Manager should decide whether the issue is relevant, or the issue is erroneous or immaterial. In most cases, however, resolution involves a design change, a change in requirements, or a combination of the two. Records of design review meetings are retained and identify those present at the meeting and the decisions reached.

Single-consultant Design Review (SDR): The Single-consultant Design Review (SDR) is a presentation of the design to relevant stakeholders. These reviews are carried out by the Design Manager when the design has progressed by 20%, 60% and 100%. The purpose of the review is to present evidence at each of these stages to confirm that the design is compliant with the standards and requirements defined in the Conceptual Design Statement. The reviewers are responsible for raising any comments, while the Design Manager should be responsible for capturing comments using the Design Review Meeting Minutes, and referencing the document upon which they are commenting along with their name. If a reviewer cannot attend a session it is their responsibility to ensure adequate cover or to issue their comments the Design Manager for inclusion. The minutes of SDR meetings are recorded. Meeting minutes include a detailed listing of all the documents that have provided the basis of the review. Issues raised may be addressed in the following design stage. Any outstanding issues are recorded in the Design Issues Log (or similar), presented at the Assurance Gate Review meeting as issues for the next design stage and subsequently confirmed as being closed out at the subsequent Gate.

Inter-consultant Design Review (IDR): The Inter-consultant Design Review (IDR) is a presentation of the design of a work package or packages to interfacing Design Teams. These are carried out by the Design Manager when the design has progressed by 20%, 60% and 100%. Its primary purpose is to seek evidence that all interfaces have been agreed and that the design integrates to deliver the requirements. At each IDR an Inter-consultant Design Review Certificate is produced to evidence that all interfacing Design Teams are satisfied with the design under consideration. It should be signed by accepted representatives of the interfacing Design Teams and contain a list of any actions required to close out any exceptions raised but not deemed a bar to acceptance. The reviewers are responsible for issuing any comments in writing using the Design Review Meeting Minutes, and referencing the document upon which they are commenting along with their name. If a reviewer cannot attend a session it is their responsibility to ensure adequate cover. The minutes of IDR meetings are recorded and include a detailed listing of all the documents that have provided the basis of the review. Issues raised may be addressed in the following design stage. Any outstanding issues are recorded in the Design Issues Log (or similar), presented at the Assurance Gate Review Meeting as issues for the next design stage and subsequently confirmed as being closed out at the subsequent Gate. Other instances of design reviews may be required when the Engineering Manager has identified significant design change that requires a review to revalidate the design.

Assurance gate reviews: The Assurance Gate Reviews 1 to 3 are the primary control mechanism that provides progressive assurance when evidence is reviewed at defined stages to confirm that the designs produced meet the design project’s objectives, requirements, obligations and that the risks associated with the engineering are identified and fully understood.

  1. Gate 1 – (Initial concept (20% complete) The details will be outline only but will define the character, limit and form of manufacture, fabrication or construction.
  2. Gate 2 – (Functional design (60% complete) At this stage the design has progressed to an intermediate position (progress check at 60% complete) This Gate is a check point at about the mid-point between Gate 1 and the final design. At the outset of a design project, the target deliverables at Gate 2 are clearly defined so that it provides an interim way point to confirm progress.
  3. Gate 3 – (Detailed design ready for manufacture, fabrication or construction (100% complete) At this stage the design is complete and ready to be issued for manufacture, fabrication, or construction. Design details are finalised and fully integrated with other interfaces.

The purpose of the Assurance Gate Review process is to provide progressive assurance during the design stage that the objectives of the design intent can be achieved and that the design can progress successfully to the next stage. The next stage of the design process can only proceed when the Assurance Gate Review is successfully passed. If the evidence submitted at the Assurance Gate Review demonstrates that the design meets the objectives, it will be approved. If the Gate Review Panel decides that the submitted deliverables fall short of the requirements, the design will not pass through the Assurance Gate Review and is therefore prevented from proceeding to the next stage. The Gate Review Panel also known as the ‘Approval Authority’ has the responsibility to make the appropriate decision at each Assurance Gate Review. The Gate Review Panel is a multi-discipline committee formed of members from various departments and stakeholders throughout the organization. The Gate Review Panel members should be selected based on perceived risks, applicable regulatory or legal requirements, technical complexity, financial repercussions and criticality of the product. Department representation should include Quality, Manufacturing, Engineering, Sales, Planning, Purchasing, Business Development, Contract, Legal, or others as deemed necessary. Formal, documented design and development Assurance Gate Reviews should be held at appropriate stages of the design and development cycle and include representatives from all concerned functions and stakeholders. Each Assurance Gate Review focuses on assessing whether the design deliverables meet all the objectives and appropriate criteria. The minimum approval criteria used for determining whether the design meets the intent are set out below. In addition to these minimum requirements, the Engineering Manager may specify further criteria at the outset of each design stage. The Gate Review Panel is responsible for managing the Gates Review process thereby ensuring that:

  1. The design progress and the design status have successfully reached a stage of development appropriate to the Gate being assessed;
  2. Cost and programme issues have been agreed and align with budget constraints;
  3. The assurance evidence presented to the panel is sufficient to support the Gate requirements;
  4. The risks are either designed out, have appropriate mitigation or have been identified and agreed that they can proceed to the next stage;
  5. All the necessary deliverables and other legal have been identified and complied with and the design is compliant with any including undertakings and assurances;
  6. After the Gate Review Panel and the Gates Chair Person shall confer, taking full account of the views of the other Panel Members, and decide whether or not the design submission and presentation meets the Assurance Gate Review objectives and consequently can be given a pass or is prevented from passing the Gate.
  7. If the Gates Chair Person decides that missing deliverables or evidence do not impact on the ability of the project to proceed, then a conditional pass may be given, subject to the remaining deliverables being completed within a specified time.
  8. The conditions and timescales are conveyed to the Design Manager at the Review;
  9. Where conditions are raised that are potentially of a significant risk, consideration shall be given to the inclusion of the conditions;
  10. The Gate Review Panel’s findings and decisions are recorded, together with any supporting data.

The Design Review Meeting Minutes should capture the results of the Gate Review Panel’s review. It serves as a record of the review and summarises the findings. The key aspects of the report are recording the evidence presented to satisfy the approval criteria and using this to support the decision regarding pass or re-submission. It is the Design Manager’s responsibility to assemble and present to the Gate Review Panel sufficient evidence, see table of deliverables below, when the design has progressed to 20%, 60% and 100%, to enable the Gate Review Panel to discharge their duties. Key design deliverables that are associated with the Assurance Gate Review are provided to the Gate Review Panel at least 5 working days prior to the scheduled review date

5.4.6 Design Verification and Final Review

To confirm that the design outputs meet the design input requirements, design verification and a final review must be carried out and documented according to the organization’s procedure. Records of design verification, any required actions, and the final review must be preserved.

By planned arrangements the design and development verification and a final review must be conducted and documented to ensure that the design and development outputs meets the design and development input requirements. Design and development verification and the final review must be recorded. Design verification is confirmation by examination and provision of objective evidence that the specified input requirements have been fulfilled. Any approach which establishes conformance with a design input requirement is an acceptable means of verifying the design concerning that requirement. Complex designs require more and different types of verification activities. The nature of verification activities varies according to the type of design output. Design verification is carried out to check that the outputs from each design phase meet the stated requirements for the phase. Requirements traceability verification is undertaken to ensure that the design fulfils the design concept while expressing the necessary functional and technical requirements. This process was verified throughout the Assurance Gate Reviews. In most cases, verification activities are completed before each design review, and the verification results are submitted to the reviewers along with the other design deliverables to be reviewed. The results of the design verification, including identification of the design, method(s), date, and the individual performing the verification, shall be documented and retained.

5.4.7 Design Validation and Approval

The organization’s procedure must include conducting design validation to ensure that the resulting product can fulfil the specified requirements. Whenever feasible, validation must be concluded before product delivery. After validation, the finalized design must be approved by competent individuals other than those who developed the design. Records of design validation, approval, and any required actions must be retained.

Design and development validation shall be performed by planned arrangements to ensure that the resulting product is capable of meeting the specified requirements. Validation shall be completed before the delivery of the product, when possible. The completed design shall be approved after validation. A competent individual other than the person or persons who developed the design shall approve the final design. Records of the design and development validation, approval, and any necessary actions shall be maintained. Design and development validation shall be performed by planned arrangements to ensure that the resulting product is capable of meeting the specified requirements. Validation shall be completed before the delivery of the product, when possible. Design validation is similar to verification, except this time you should check the designed product under conditions of actual use. If you are designing dune buggies, you might take your creation for a spin on the beach. If you are making beverages, you might conduct a consumer taste test. Verification is a documentary review while validation is a real-world test. Perform design and development validation by ensuring the product meets the specified requirements. Maintain records of validation activities and approvals. Design validation follows successful verification, and ensures, by examination and provision of objective evidence, that each requirement for a particular use is fulfilled. The performance characteristics that are to be assessed are identified, and validation methods and acceptance criteria are established. At the commencement of the design project, the requirements received from the previous design phase form the initial baseline. During design reviews, the requirements are considered to ensure that the right requirements and any assumptions have been captured, to identify missing requirements and to ensure that the design intent will meet those requirements. The results of the design validation, including identification of the design, method, date, and the individual(s) performing the validation, should be documented and retained. The organization shall have records that the product designed will meet defined user needs before delivery of the product to the customer, as appropriate. Methods of validation could include simulation techniques, proto-type build and evaluation, comparison to similar proven designs, beta testing, field evaluations, etc. Irrespective of the methods used, the validation activity should be planned, and executed with records maintained as defined in the planning activity. Retain documented information to demonstrate that any test plans and test procedures have been observed, that their criteria have been met and that the design meets the specified requirements for all identified operational conditions e.g. reports, calculations, test results, data, and reviews.

5.4.8 Design Changes

Design changes must be identified and subjected to review, verification, and validation as necessary before being approved for implementation. The review of design changes must assess their impact on the product and its component parts at relevant stages of product realization, including already delivered products. Additionally, the review must evaluate whether customer notification is necessary if the changes adversely affect the specified performance capability of the product. All design changes, including modifications to design documents, must adhere to the organization’s procedure. Records of design changes, reviews, and any required actions must be documented and maintained.

Any changes for Design and Development must be identified, reviewed, verified, and validated, as appropriate, and approved before implementation. The review of design and development changes includes evaluation of the effect of the changes on products and/or their constituent parts already delivered. Design and development changes must have all the controls as with the original design and development. This includes changes in the design documents. The design and development changes, their review and any necessary action must be recorded. It is important to control design changes throughout the design and development process and it should be clear how these changes are handled and what affects they have on the product. The organization has retained documented information concerning:

  • Design and development changes;
  • The results of reviews;
  • The authorization of changes;
  • Actions taken to prevent adverse impacts.

The organization should begin identifying, reviewing and controlling of design changes including the implementation of a process to notify the customer when changes affect the customer requirement e.g. customer communication, notifications of change, requests for deviation, and contract amendments. The Engineering Manager in conjunction with the Design Manager is responsible for evaluating the risks and the impact of design changes against the criteria. The Engineering Manager logs all change requests in the Design Change Request Log, performs an evaluation and either approves or denies the request. Major changes are also evaluated by any affected stakeholders. All change requests serve as design and development inputs for design and development changes. Design documentation is updated to accurately reflect the revised design.

It is as important to control design changes throughout the design and development process and it should be clear how these changes are handled and what effects they have on the product. Ensure control over design and development changes, design changes must be:

  • Identified.
  • Recorded.
  • Reviewed.
  • Verified.
  • Validated.
  • Approved.

Configuration control can be managed via alteration requests, a notice of the change, amendments, deviations, waivers, concessions, part revision changes, part number changes, change categories, service bulletins, modification bulletins, airworthiness directives, engineering communication notice, and product change boards. Design and development changes (after the original verification and validation) have to be ‘verified and validated as appropriate’ (as well as reviewed) and to ‘include evaluation of the effect of changes on constituent parts and products already delivered’. If the organization chooses not to perform re-verification and re-validation on every design change, then the auditor should expect to see some very well-defined criteria as to when the activity needs to occur. Retain documented information that includes design change history, evaluation of change results, authorization of change and actions taken about subsequent activities that are impacted by the change.

5.5 Purchasing
5.5.1 Purchasing Control
5.5.1.1 Procedure

The organization must maintain a documented procedure for purchasing products, components, and/or activities necessary for product realization. This procedure should cover:

  1. Identifying critical products, components, and/or activities.
  2. Initial assessment and selection of suppliers.
  3. Using identified risks to determine the initial assessment method of the supplier’s capability for critical purchases.
  4. Determining the type and extent of control applied to the supply chain for critical products, components, or activities. Note: Additional requirements for outsourced activities are specified in section 5.5.1.7.
  5. Establishing criteria, scope, frequency, and methods for re-evaluating suppliers.
  6. Identifying approved suppliers and defining the scope of approval.
  7. Identifying customer-specified suppliers and suppliers limited by proprietary and/or legal requirements when section 5.5.1.3 applies.

Procurement and the controls of materials, products and suppliers is one of the most critical elements of API Q1. The organization must maintain a documented procedure to ensure that purchased product or outsourced activities conform to specified requirements and must address:
a) the determination of the criticality of activities or products as they are applicable to conformance to product or customer specifications
b) Initial evaluation and selection of suppliers based on their ability to supply products or activities in accordance with the organization’s requirements
c) type and extent of control applied to the supplier based on the criticality of product or activity
d) criteria, scope, frequency, and methods for reassessment of suppliers
e) maintaining a list of approved suppliers and scope of approval, and
f) type and extent of control applied to outsourced activities

a) Determination of Criticality: The determination of the criticality of the activities or products as they are applicable to conformance to product or customer specifications. This is an important requirement to both ensure that all incoming raw materials, components and finished product(s) meet specification. It is also important factor for determining which suppliers may or may not be critical as well.
b) Initial Evaluation of Suppliers: Initial evaluation and selection of suppliers based on their ability to supply products or activities in accordance with the organization’s requirements
Some things to consider here include:
o Suppliers ability to meet the organizational requirements
o Suppliers ability to meet customer requirements
o The supplier’s actual capacity and capability of meeting organization requirements.
c) Applied Control: This mandates that organizations include in the procedures, the type and extent of control applied to the supplier and activities or products based on the of the activities or products. The term “criticality” is important. The criticality of the activities or products as well as the supplier’s risks, determines the type and extent of controls that the organization provides for the supplier, activities or products.
d) Reassessment of Suppliers: The procedure shall address:
o Criteria
o Scope
o Frequency
o For supplier reassessments
e) Approved Supplier Listing: The procedure shall address:
o List of approved suppliers
o Scope of approval
f) Control Over Outsourced Activities: The procedure shall address the type and extent of control to be applied to outsourced activities. The amount of control normally takes the suppliers performance into account. Some performance criteria include:

  1. Quality of product and service
  2. On-time delivery
  3. Reporting & documentation
  4. Budget
  5. Risk(s)

Supplier approval
Approved suppliers must have satisfactorily demonstrated their ability to meet your business’s requirements, as well as customer and legal requirements, as determined and evidenced by the initial supplier evaluation process. Suppliers are often approved, or not approved, on the basis of financial standing, preferred cost, product expertise, past performance, technology, logistics, supply chain integrity, business risk, and any known significant environmental, or health and safety compliance issues. If the supplier is acceptable, they should be added to your approved supplier list. Signed approval must be given by an authorized representative, typically the Quality Manager or Contracts Manager have the authority sign off on supplier approvals. The approval status of each supplier must be clearly authorized on your approved supplier list.

5.5.1.2 Initial Supplier Evaluation—Critical Purchases

For critical products, components, or activities, the initial evaluation of suppliers who have not been previously approved must consider the scope of supply and be specific to each supplier. This evaluation must include:

  1. Verifying the implementation of the supplier’s quality management system and its conformity to the organization’s specified quality system requirements for suppliers.
  2. Verifying the type and extent of control applied by the supplier internally and throughout their supply chain to meet the organization’s requirements.
  3. Assessing the supplier’s capability to meet the organization’s specified requirements. This can be done through one or more of the following methods based on identified risks:
    • Conducting an on-site assessment to verify that process controls perform relevant product realization processes and effectively achieve conformity to requirements.
    • Conducting a remote assessment to verify that relevant product realization processes are performed using process controls and effectively achieve conformity to requirements.
    • Performing inspection, testing, or verification of relevant characteristics of received products.

For suppliers of critical purchases with high-risk severity, identified by the organization for which an on-site assessment is not conducted, the evaluation of the supplier’s capability must include a remote assessment and inspection, testing, or verification. When conducting a remote assessment, it must include verification of objective evidence through real-time audio/visual observation of required activities and documentation using information and communication technology. Additionally, any additions to a supplier’s scope of approval or change from an approved site to a new site of supply must also undergo evaluation as per the requirements outlined in this section.

For purchases of critical products, components or activities, the criteria for the initial evaluation of suppliers by the organization shall be site-specific for each supplier. For purchases of critical products, components or activities, the criteria for the initial evaluation of suppliers by the organization shall be site-specific for each supplier and shall include verification that the supplier’s quality management system conforms to the quality system requirements specified for suppliers by the organization. Assessment of the supplier to ensure its capability to meet the organization’s purchasing requirements by performing an on-site evaluation of relevant activities, or performing first article inspection to ensure conformance to stated requirements, or identifying how the supplied product conforms to stated requirements when limited by proprietary, legal, and/or contractual arrangements.

A critical vendor is one that you rely on heavily to support the most important activities within your organization – oftentimes called ‘critical activities’. While critical activities will differ between organizations, examples of critical vendors might include those who:

Inspection Companies– Non-Destructive Testing, Magnetic Particle Inspection, thread inspection, etc. 3rd party inspection companies could be considered a critical supplier.
Calibration Companies – The organization requires certificates published from the 3rd party vendors. This makes calibration companies a critical supplier.
Material –Product and Raw Material Supplier– The Supplier for material would be considered a critical supplier to our needs since many of the products are supplied because if we would stop buying from them our operation would simply crumble
Trucking and delivery – These are suppliers are crucial to the end result as we depend on them to get it to the rigs, so they would definitely be considered critical.
O-rings, seals, and gasket suppliers – Anytime product requires O-rings, seals and gaskets they can be classified as critical.

Defining your critical vendors begins with being clear about your own critical activities. A good place to start is with your company’s business continuity/disaster recovery plan, which defines critical activities within your own operations. Knowing those activities will help you determine which vendors support those critical operational areas. Here are a few things you should do to get started to identify critical vendors:

  • Inquire of your Procurement department if they maintain a listing of all vendor contracts.
  • Review your user listings to critical systems. You should already perform periodic user access reviews, but doing so will give you an understanding of what vendors have access to your network or sensitive data.
  • Once you have performed these tasks, you may be able to better categorize your critical vendors, according to the following classifications and how they rate within your own organization:
    • Vendor type
    • Regulatory requirements
    • Specific services provided
    • Business disruption factors
    • Data type and volume

5.5.1.3 Initial Supplier Evaluation – Critical Purchases – Customer Specified, Proprietary, and/or Legal Limited

For critical products, components, or activities where the supplier is specified by the customer or involves proprietary and/or legal requirements that restrict the application of Initial Supplier Evaluation, the initial evaluation process shall involve verifying the implementation of the supplier’s quality management system and its conformity to the quality system requirements specified by the organization and/or the customer’s requirements and identifying how the supplied product, component, or activity conforms to specified requirements. The scope of approval for customer-specified suppliers shall be restricted to the relevant customer contract in cases where an assessment has not been conducted.

In API Specification Q1, for critical products, components, or activities where the supplier is specified by the customer or involves proprietary and/or legal requirements that restrict the application of Initial Supplier Evaluation, the initial evaluation process involves several key steps:

  1. Verification of Supplier’s Quality Management System (QMS): The organization must verify the implementation of the supplier’s quality management system. This includes assessing whether the supplier has established and effectively implemented processes, procedures, and controls to ensure product quality and conformity to requirements. The verification process may involve reviewing documentation, conducting audits, and evaluating the supplier’s QMS effectiveness.
  2. Conformity to Quality System Requirements: The organization must verify that the supplier’s quality management system conforms to the quality system requirements specified by the organization and/or the customer’s requirements. This entails comparing the supplier’s QMS practices, procedures, and controls against the organization’s quality system requirements and any additional customer-specific requirements.
  3. Identification of Product Conformity: The organization must identify how the supplied product, component, or activity conforms to specified requirements. This involves assessing the product’s characteristics, performance, and adherence to technical specifications, standards, and contractual agreements. The organization may use various methods such as inspection, testing, validation, and certification to verify product conformity.
  4. Documentation and Record-Keeping: The results of the initial evaluation process, including verification of the supplier’s QMS, conformity to quality system requirements, and product conformity assessments, must be documented. The organization should maintain records of these evaluations, findings, and any corrective actions taken.
  5. Communication with the Customer: If the supplier is specified by the customer or if customer-specific requirements apply, the organization must ensure that relevant information regarding the supplier’s QMS, quality system conformity, and product conformity is communicated to the customer as appropriate.
  6. Continuous Monitoring and Improvement: Following the initial evaluation, the organization should establish mechanisms for ongoing monitoring and oversight of the supplier’s performance. This may include periodic audits, performance reviews, and communication channels to address any issues or deviations promptly. Additionally, the organization should continuously seek opportunities for improvement in supplier performance and product quality.

5.5.1.4 Initial Supplier Evaluation—Noncritical Purchases

For the procurement of noncritical products, components, or activities that influence product realization or the final product, the organization’s criteria for evaluating suppliers must either meet the requirements of Initial Supplier Evaluation—Critical Purchases or fulfil one or more of the following:

  1. Verifying that the supplier’s quality management system aligns with the quality system requirements specified for suppliers by the organization.
  2. Assessing the supplier’s ability to meet the organization’s purchasing requirements.
  3. Evaluating the product or component upon delivery, or activity upon completion.

Even for purchase of noncritical products, components, or activities that impact product realization or the final product, the criteria for evaluation of suppliers by the organization must either meet the requirements of criteria of evaluation of critical suppliers or satisfy verification that the supplier’s quality management system conforms to the quality system requirements specified for suppliers by the organization or assessment of the supplier to meet the organization’s purchasing requirements or assessment of the product upon delivery or activity upon completion. A non-critical vendor is one that does not undergo the same level of examination as critical vendors. Non-critical vendors simply offer support to the operations that allow employees to do their jobs efficiently, effectively and in comfort. They do not, however, have any impact on the final product or service. These vendors may affect productivity but they do not affect the product or service provided itself. The main difference in treatment between a critical and non-critical vendor lies in the frequency between reviews and assessments. Critical vendors generally undergo reviews once a year while non-critical vendors only face reviews once every two-to-three years.

5.5.1.5 Supplier Reevaluation

For suppliers previously approved for products, components, or activities, the organization must determine the frequency of supplier reevaluation based on identified risk and supplier quality performance. For the reevaluation of suppliers providing critical products, components, or activities, the provisions of section 5.5.1.2 shall be followed. For the reevaluation of suppliers providing critical products, components, or activities specified by the customer or restricted by proprietary and/or legal requirements, the requirements outlined in section 5.5.1.3 shall be adhered to. For the reevaluation of suppliers providing non-critical products, components, or activities that affect product realization or the final product, the guidelines detailed in section 5.5.1.4 shall be followed.

For re-evaluation of all suppliers weather critical or noncritical, the requirements of 5.6.1.3 shall apply. The criteria for re-evaluation of suppliers by the organization must either meet the requirements of criteria of evaluation of critical suppliers or satisfy verification that the supplier’s quality management system conforms to the quality system requirements specified for suppliers by the organization or assessment of the supplier to meet the organization’s purchasing requirements or assessment of the product upon delivery or activity upon completion. A typical supplier evaluation and reevaluation might include:

  • Gathering and analysis of data (such as technological and operational capabilities, logistics, quality, technical risks) about the supplier.
  • An on-site assessment of the quality system or compliance review by your Audit staff.
  • Completing and signing a quality agreement or contract.
  • Businesses often assess the supplier’s facilities, quality system, and process controls to determine if there is potential impact on their own manufacturing or service provision processes.
  • Assign risk levels on parts/materials, as appropriate:
    • Determine if there is a potential product or regulatory risk.
    • Confirm the capability of the supplier to supply or manufacture to requirements.

5.5.1.6 Records

Records of evaluation results, comprising objective evidence and any subsequent actions, must be retained. Additionally, records of approved suppliers, customer-specified suppliers, and suppliers bound by proprietary and/or legal requirements must be kept.

Records of the results of all evaluations and any necessary actions arising from the evaluations shall be maintained. All suppliers should be given an overall performance rating between 0-100%. Set the minimum performance threshold or benchmark to 95% for example. The resulting performance rating is an indication of a supplier’s performance ability and their ability to meet your requirements. Retain records of supplier evaluations and the related actions.

5.5.1.7 Outsourcing

When an organization decides to delegate a process or activity from its quality management system to an external supplier, it must ensure that the supplier meets the relevant requirements of the organization’s quality management system. If an organization opts to outsource a process or activity related to product realization, it must retain accountability for ensuring that the product meets specified requirements, which may include relevant API or other external specifications. Documentation of outsourced activities must be retained, including evidence of conformity.

When an organization choose to outsource any activity within the scope of its quality management system, the organization shall ensure that all applicable elements of its quality management system are satisfied and shall maintain responsibility for product conformance to specified requirements, including applicable API product specifications associated with product realization. Records of outsourced activities shall be maintained.

Monitoring Outsourcing performance
The performance of outsourced processes must be consistently monitored by the Quality Manager or Contracts Manager. Various ways include the review of measures, targets, KPIs, scorecards, dashboards, scored ratings, or survey results. The ongoing monitoring commonly uses some of the following criteria to rate performance:

  • An assessment of the quality and quantity of products, services or materials provided.
  • On-time delivery performance.
  • responsiveness/communication.
  • Total number of corrective actions.
  • response time.
  • Defective parts per million (PPM).
  • Total cost.
  • A review of receiving records, inspection records, or acceptance records.

Organizations should periodically communicate these results to their vendors as appropriate. On-site audits and process audits at the vendor’s premises are deemed necessary by the Quality Manager and the Purchasing, or Contracts Manager. Issues or conditions which might initiate a vendor’s audit include quality issues, engineering changes, process changes, plant location changes or the criticality of the part or service. When an audit is necessary, you should contact the vendor to schedule an on-site visit and confirm the agenda.

5.5.2 Purchasing Information

The organization must verify the adequacy of specified purchasing information before transmitting it to the supplier. Purchasing information provided to the supplier must be documented and clearly outline the product, component, or activity to be procured. This documentation should include, as appropriate:

  1. Acceptance criteria;
  2. Requirements for approving the supplier’s procedures, processes, and equipment;
  3. Relevant technical data such as specifications, drawings, process requirements, inspection instructions, and traceability requirements;
  4. Criteria for qualifying the supplier’s personnel;
  5. Requirements related to the quality management system;
  6. Conditions for approving product release; and
  7. If either the organization or its customer intends to conduct verification at the supplier’s premises, the intended verification arrangements.

Applicable specifications may encompass or derive from customer requirements, API specifications, design output, and/or industry standards.

The organization must ensure before communicating with the supplier the adequacy of the purchasing information must be adequate and documented. Purchasing information must describe the product or activity to be purchased, including acceptance criteria, and where appropriate requirements for approval of supplier’s procedures, processes, equipment, applicable version of specifications, drawings, process requirements, inspection instructions, traceability, and other relevant technical data. It must also describe any supplier personnel’s qualifications and QMS requirements. Purchase orders for items that are essential to fulfil customer requirements and directly affect the quality of your products and services should only be raised by the Purchasing Manager, or the Accounts Department (at the request of the Purchasing Manager). Purchase orders may be raised by the use of the computerized purchasing system or soft-backed purchase order books. Purchase orders should contain:

  • Supplier;
  • Originator;
  • Date;
  • Purchase Order Number;
  • Items required;
  • Quantities;
  • Required delivery date;
  • Quoted prices where applicable or known;
  • Any other information deemed critical for the supply of the material should also be noted.

Ensure that purchase orders or purchasing specifications include, where appropriate the requirements for the approval and acceptance of products, services, procedures, processes or equipment. Purchasing documentation should also define the requirements for approval of the supplier’s personnel, verification arrangements, or quality management system requirements as necessary. All purchase orders or purchasing specifications must be reviewed and approved before they are released to the supplier. Where appropriate, ensure the requirements for certification, inspection reports, statistical data, approval of samples, etc. are included in purchasing documents. Some purchasing documents may include an agreement obligating your suppliers to give notification of changes to their products or services. When notification is received, the Quality Manager and the Purchasing, or Contracts Manager should evaluate how, and whether the changes affect the quality of your completed products or services.

The organization must where appropriate, communicated not just the products or services they wish to receive but also any processes they want the external provider to undertake on their behalf. To ensure the adequacy of specified purchasing information before their communication to the supplier, the supplier is usually requested to quote on price and availability. All pertinent purchasing information, as determined by your organization and customer requirements; should be included in the request for a quote (RFQ). The purchase order should be created after the review and acceptance of a supplier’s quote and must contain the same content as the request for a quote. Describe the product to be purchased by:

  • Defining product approval requirements, e.g.; certificate of conformity;
  • Defining intended verification arrangements, e.g.; witness testing or certification;
  • Defining personnel qualifications and quality, environmental, and safety requirements;
  • Maintaining records.

Where activities are wholly outsourced, or subcontracted; your organization maintains responsibility for product conformance to all specified requirements. Purchasing information should include acceptance criteria, and where appropriate, state the requirements for the approval of supplier’s procedures, processes, and equipment. Applicable versions of specifications, drawings, process requirements, inspection instructions, traceability, relevant technical data, and requirements for qualification/competence of the supplier’s personnel, and quality management system must be specified and communicated.

5.5.3 Verification of Purchased Products, Components or Activities
5.5.3.1 General

The organization must uphold a documented procedure outlining the verification needed to ascertain whether purchased products, components, or activities adhere to specified purchase requirements.

The organization must establish a documented procedure for the verification or other activities necessary for ensuring that purchased products or activities meet specified purchase requirements. Where the organization or its customer intends to perform verification at the supplier‘s premises, the organization shall state the intended verification arrangements and method of product release in the purchasing information. The organization must ensure and provide evidence that purchased products and activities conform to specified requirements. The organization shall maintain records of verification activities.

The documented procedure must ensure that items, which are essential to fulfilling customer requirements and which directly affect the quality of products and services, are verified upon product receipt or service delivery to verify they conform to:

  • QMS requirements;
  • Competency of external personnel;
  • Purchase orders;
  • Purchasing specification;
  • Purchasing agreements;
  • Delivery notes;
  • Release certificates;
  • Certificates of conformity;
  • Inspection and acceptance tests;
  • Product specifications;
  • National or international standards.
  • Receiving inspection

On receipt of incoming materials, the receiving personnel must identify and inspect the items, goods and materials and match them against the delivery note. The delivery note is compared to the corresponding purchase order and any related documentation. This inspection should include but not be limited to:

  • Confirmation of identification using purchase order number, drawing numbers, material markings etc.;
  • Confirmation of adherence to delivery schedule;
  • Confirmation of conformance to purchase order requirements;
  • Confirmation of correct quantities;
  • Visual examination for obvious defects;
  • Measurement comparison to drawings where required;
  • Specified certification/documentation as required.

For large numbers of identical items, visual and dimensional checks should be undertaken on a minimum of 5% of the total quantity. No material is released for further processing until receiving inspection has been completed and goods accepted. All accepted materials passing immediate inspection can be allocated a storage area. Any non-compliant goods must be placed in a separate area, and identified. Further investigation should determine whether the items, materials or goods are to be:

  • Scrapped;
  • Returned to Supplier;
  • Reworked to a useable condition.

When inspecting materials that include specified certification or documentation should only be accepted when such certification and documentation has been viewed and approved by the Quality Manager or the Purchasing Manager.

5.5.3.2 Critical Purchases

For critical products, components, or activities, the organization’s verification procedure should cover:

  1. Reviewing the required documentation provided by the supplier;
  2. Ensuring that the correct versions were utilized when specifying specifications, drawings, process requirements, inspection instructions, traceability requirements, and other relevant technical data as outlined in section 5.5.2 item c;
  3. Defining the inspection, testing, and/or verification requirements, including methods, frequency, and the responsible party. The organization should determine these aspects based on identified risks and supplier quality performance.

In API Specification Q1, the verification procedure for critical products, components, or activities involves several key steps to ensure that the organization’s requirements are met and that risks are appropriately managed. The organization should review all required documentation provided by the supplier. This documentation may include quality management system documentation, product specifications, drawings, process requirements, inspection instructions, traceability records, and other relevant technical data. The purpose of this review is to verify that the supplier has provided complete, accurate, and up-to-date documentation that meets the organization’s requirements. It’s essential to ensure that the correct versions of specifications, drawings, process requirements, inspection instructions, and other technical data are utilized. This verification helps prevent errors, discrepancies, or misunderstandings that could lead to nonconforming products or components. The organization should establish procedures for verifying the currency and accuracy of all technical documentation provided by the supplier. The organization must define the inspection, testing, and/or verification requirements for critical products, components, or activities. This includes specifying the methods, frequency, acceptance criteria, and responsible parties for conducting inspections, tests, and verifications. These requirements should be based on identified risks, supplier quality performance, regulatory requirements, and customer specifications. The organization should determine the inspection, testing, and verification requirements based on identified risks associated with the product, component, or activity. Higher-risk items may require more rigorous inspection and testing procedures, while lower-risk items may require less intensive verification. By applying a risk-based approach, the organization can allocate resources effectively and prioritize efforts where they are most needed to ensure product quality and conformity. The organization should also consider the supplier’s quality performance history when defining inspection, testing, and verification requirements. Suppliers with a demonstrated track record of high quality and reliability may warrant less intensive scrutiny, while suppliers with a history of quality issues may require more stringent oversight. Performance metrics such as on-time delivery, defect rates, and corrective action responsiveness can inform decisions about the level of verification required.

5.5.3.3 Noncritical Purchases

The organization’s documented procedure must verify noncritical products, components, or activities.

For non-critical products, components, or activities, the organization’s documented procedure for verification should still be robust and systematic, even if the level of scrutiny may be less intense compared to critical items. Similar to critical items, the organization should review the documentation provided by the supplier for noncritical products, components, or activities. This includes specifications, drawings, process requirements, inspection instructions, and any other relevant technical data. While the level of detail and scrutiny may be less than for critical items, ensuring that the documentation is complete and accurate is still important. Just as with critical items, it’s essential to verify that the correct versions of specifications, drawings, and other technical documents were utilized. This helps prevent errors and misunderstandings that could lead to non-conformities. The organization should define the inspection, testing, and verification requirements for noncritical products, components, or activities. While the level of scrutiny may be less rigorous compared to critical items, it’s still important to specify the methods, frequency, acceptance criteria, and responsible parties for conducting inspections, tests, and verifications. While noncritical items may not pose as significant risks as critical items, it’s still advisable to take a risk-based approach to determine the level of verification required. Consider factors such as the impact of nonconformities, the likelihood of occurrence, and the supplier’s quality performance history when defining verification requirements. Even for noncritical items, it’s important to consider the supplier’s quality performance history when determining verification requirements. While the level of scrutiny may be less intense compared to critical items, suppliers with a history of quality issues may still require additional oversight. The organization should maintain records of all verification activities conducted for noncritical products, components, or activities. This includes documentation of the review of supplier documentation, verification of correct versions, and any inspection, testing, or verification results. As with all quality management processes, the organization should continuously monitor and evaluate the effectiveness of its verification procedures for non-critical items. Seek feedback from stakeholders, track performance metrics, and make adjustments as necessary to improve efficiency and effectiveness. By implementing a documented procedure for verifying noncritical products, components, or activities, organizations can ensure consistency, reliability, and compliance with quality requirements, even for items that may not pose significant risks to product quality or safety.

5.5.3.4 Records

Documentation of verification activities and evidence demonstrating conformity to specified requirements must be retained.

Documentation of verification activities and evidence demonstrating conformity to specified requirements must be retained by the organization. These records serve as evidence of compliance with quality management system requirements and provide a documented history of product verification processes. The organization should maintain records documenting all verification activities conducted for products, components, or activities. This includes documentation of reviews of supplier documentation, verification of correct versions, inspection, testing, and any other verification activities performed to ensure conformity to specified requirements. Records should include evidence demonstrating conformity to specified requirements. This may include inspection reports, test results, certificates of compliance, supplier documentation, and any other relevant documentation that demonstrates that the product, component, or activity meets the specified requirements. The organization should establish a retention period for records of verification activities and evidence of conformity based on regulatory requirements, industry standards, and internal policies. Records should be retained for a minimum period of 10 years to demonstrate compliance with API Specification Q1 and to support future audits, assessments, or reviews. Ensure that records of verification activities and evidence of conformity are securely stored and readily accessible when needed. This may involve maintaining electronic or paper-based records in a centralized location or document management system that allows for easy retrieval and reference. Implement appropriate controls to ensure the security and integrity of records, protecting them from unauthorized access, alteration, or destruction. This may include password protection, encryption, backup procedures, and restricted access to sensitive information. Maintain an audit trail of verification activities and changes to records, documenting the date, time, and identity of individuals who performed or approved verification activities. This helps ensure accountability and transparency in the verification process. Periodically review and verify the accuracy and completeness of records of verification activities and evidence of conformity. This ensures that records are up-to-date, accurate, and reflective of the organization’s verification processes.

5.6 Control of Product Realization
5.6.1 General

The organization must uphold a documented procedure outlining controls related to product realization. This procedure should cover:

  1. Establishing and applying manufacturing acceptance criteria (MAC);
  2. Identifying and documenting critical processes involved in product realization;
  3. Executing the quality plan, if applicable;
  4. Ensuring compliance with design requirements and associated modifications, if applicable;
  5. Utilizing and ensuring the availability of product realization equipment and TMMDE (unless excluded);
  6. Following relevant work instructions;
  7. Employing process control documents;
  8. Maintaining identification and traceability requirements throughout the product realization process;
  9. Executing monitoring and measurement activities.

The organization must establish a documented procedure that describes controls associated with the product realization. The procedure shall address the availability of information that describes the characteristics of the product, when applicable implementation of the product quality plan, when applicable ensuring design requirements and related changes are satisfied, when applicable, the availability and use of suitable production, testing, monitoring, and measurement equipment, when applicable the availability of work instructions, process control documents, implementation of monitoring and measurement activities, and implementation of product release including applicable delivery and post-delivery activities.

The procedure shall address the following the availability of information that describes the characteristics of the product. A product characteristic is an attribute or property of the product that describes the product’s ability to satisfy its purpose in a larger system. Examples of product characteristics are size, shape, weight, colour, quality, hardness, etc. The list of product characteristics depends on your product and how its functional design requirements have been defined. Some product characteristics are more significant than others in terms of reliability, quality and safety. Thus, it can be important to identify those that are most critical. The procedure shall address the following implementation of the product quality plan, when applicable. The procedure shall address ensuring design requirements and related changes are satisfied, when applicable. Changes to the Product Quality Plan design requirements and related changes may affect the application or other risk associated with the changes therefore a review of the Design and Development process is required to ensure associated with the changes related to product quality, delivery and meeting customer requirements are affected. The availability and use of suitable Production, Testing, Monitoring and Measurement Equipment. Manufacturing in the process must ensure that production equipment required for the manufacturing process is available, based on capacity and suitability for the application required as well as having properly calibrated TMME suitable for monitoring the manufacturing process to ensure the product meets the stated specifications. The availability of work instructions, when applicable. While not stated in the specification, processes especially critical processes should have work instructions describing critical steps and include what risks to Quality, Health & Safety that could affect product quality/delivery and where employee’s health and safety are at risk. This is linked to their competencies. The procedure shall address process control documents. Process control documents includes those documents demonstrating to the stated requirements (Customer, API, product standards/ codes etc.) and listed within the product quality plans, if applicable. These documents include routing, travelers, checklists, process sheets, or equivalent controls required by the company. The procedure shall address the implementation of monitoring and measurement activities. The procedure shall address the implementation of product release, including applicable delivery and post-delivery activities. Product release cannot proceed until the product meets the agreed-upon planned arrangement or is approved by a relevant authority and, where applicable, by the customer.

  1. Establishing and Applying Manufacturing Acceptance Criteria (MAC): The organization should establish clear manufacturing acceptance criteria (MAC) that define the acceptable quality standards for products. These criteria should be based on customer requirements, regulatory standards, and internal quality objectives. The procedure should outline how MAC are established, communicated, and applied throughout the product realization process.
  2. Identifying and Documenting Critical Processes: Critical processes involved in product realization should be identified and documented. This may include processes such as material procurement, production, assembly, testing, and packaging. The procedure should specify how critical processes are identified, documented, and controlled to ensure consistent product quality and conformity.
  3. Executing the Quality Plan: If applicable, the organization should execute a quality plan that outlines the specific quality objectives, activities, and responsibilities for product realization. The procedure should describe how the quality plan is developed, implemented, and monitored to ensure that quality requirements are met throughout the product realization process.
  4. Ensuring Compliance with Design Requirements: If applicable, the organization should ensure compliance with design requirements and any associated modifications during product realization. This may involve reviewing design specifications, drawings, and technical documentation to verify that manufacturing processes align with design intent. The procedure should outline how design requirements are communicated, controlled, and verified during product realization.
  5. Utilizing Product Realization Equipment and TMMDE: Unless excluded, the organization should utilize and ensure the availability of product realization equipment and tools, machinery, measuring, and test equipment (TMMDE). The procedure should specify how equipment and TMMDE are selected, calibrated, maintained, and used to ensure accurate and reliable measurements and inspections.
  6. Following Relevant Work Instructions: Employees should follow relevant work instructions, procedures, and standard operating practices during product realization. The procedure should outline how work instructions are developed, approved, communicated, and updated to ensure consistency and adherence to quality requirements.
  7. Employing Process Control Documents: Process control documents should be employed to specify the methods, parameters, and controls required to maintain product quality and consistency. This may include control plans, standard operating procedures, and inspection plans. The procedure should describe how process control documents are developed, maintained, and implemented to control critical processes.
  8. Maintaining Identification and Traceability Requirements: The organization should maintain identification and traceability requirements throughout the product realization process to ensure the ability to trace products back to their source and track their movements. This may involve assigning unique identifiers, labeling products, and maintaining records of material, components, and processes. The procedure should outline how identification and traceability requirements are implemented and verified.
  9. Executing Monitoring and Measurement Activities: Monitoring and measurement activities should be executed to verify that product realization processes are performing as intended and meeting quality objectives. This may include in-process inspections, testing, and monitoring of key performance indicators. The procedure should specify how monitoring and measurement activities are planned, conducted, and recorded to ensure product quality and process effectiveness.

By establishing a documented procedure that covers these aspects of product realization controls, organizations can ensure consistent and reliable manufacturing processes, adherence to quality requirements, and continuous improvement in accordance with API Specification Q1 requirements.

5.6.2 Quality Plan

When stipulated by contract, the organization must create a quality plan delineating the processes of the quality management system, including product realization, and the resources allocated to a product. This plan should cover the following minimum aspects:

  1. Description of the product or the quality plan’s scope;
  2. Required processes and documentation, encompassing necessary inspections, tests, and record-keeping to ensure compliance with requirements;
  3. Identification of outsourced activities and references to their management;
  4. Identification of each procedure, specification, or document referenced or utilized in each activity;
  5. Specification of the required hold points, witnessing, monitoring, and document review stages.

The quality plan, along with any modifications, must be documented and endorsed by the organization. Additionally, the quality plan and its revisions should be communicated to the customer. A quality plan may consist of one or more documents and may be known by various terms, such as product quality plan (PQP), inspection and test plan (ITP), manufacturing process specification (MPS), process control plan (PCP), or quality activity plan (QAP).

The organization must develop a quality plan [ can also be called as Product quality plan (PQP), inspection and test plan (ITP), manufacturing process specification (MPS), process control plan (PCP), and quality activity plan (QAP)] which specifies the processes of QMS including the product realization process and resources to be applied to products when required by contract. The product quality plan must description of the product to be manufactured, required processes and documentation, including required inspections, tests, and records, for conformance with requirements, identification and reference to control of outsourced activities, identification of each procedure, specification, or other document referenced or used in each activity and identification of the required hold, witness, monitor, and document review points. These product quality plans must ensure customer requirements are met and must be communicated to customer. The quality plans and any revisions must be approved by the organization and documented. A product quality plan may be comprised of one or several different documents. A quality plan often makes references to parts of the quality manual or to procedure documents. A Quality Plan (QP) is a tool that will allow you to effectively communicate what you expect from your suppliers, your in-house workforce, or external contractors. It covers all areas of the production process from first concepts to the finished product. A quality plan is a document that specifies quality standards, practices, resources, specifications, and the sequence of activities relevant to a particular product.  An example of this can be a manufacturing company that machines metal parts. Its quality plan consists of applicable procedures, applicable workmanship standards, the measurement tolerances acceptable, the description of the material standards, and so forth. These may all be separate documents. Work orders specify the machine setups and tolerances, operations to be performed, tests, inspections, handling, storing, packaging, and delivery steps to be followed. An operating-level quality plan translates the customer requirements into actions required to produce the desired outcome and couples this with applicable procedures, standards, practices, and protocols to specify precisely what is needed, who will do it, and how it will be done. Quality Plan shows the techniques and procedures for controlling the product. Quality Plan need to consider the goals of reliability and quality. Reliability goals are established based on the needs and expectations of end users. Quality goals should be based on metrics that are gained from company production or past experience. The Product Quality Plan may be as simplistic as a one-page document or as complex as a 5” binder document set. The complexity of an Quality Plan varies depending on the complexity of the product.

The Quality plan should cover the following:

  • Description of the Product or Scope of the Quality Plan: The quality plan should provide a clear description of the product, service, or project to which it applies. This includes defining the scope of work, identifying deliverables, and specifying any special requirements or considerations relevant to quality management.
  • Required Processes and Documentation: The quality plan should outline the required processes and documentation necessary to ensure conformance with requirements. This includes specifying the procedures, methods, inspections, tests, and records needed to verify that products or services meet quality standards. The plan should detail the sequence of activities, responsibilities, and acceptance criteria for each process.
  • Identification of Outsourced Activities: If any activities are outsourced to external suppliers or contractors, the quality plan should identify these activities and reference their control. This includes specifying the criteria for selecting, evaluating, and monitoring outsourced suppliers, as well as outlining the responsibilities and expectations for ensuring quality in outsourced work.
  • Identification of Referenced Documents: The quality plan should identify each procedure, specification, or other document referenced or used in each activity. This ensures that all relevant documents and standards are properly integrated into the quality management process and followed consistently throughout the project lifecycle.
  • Identification of Hold, Witness, Monitor, and Document Review Points: The quality plan should identify the required hold points, witness points, monitor points, and document review points throughout the project or product lifecycle. Hold points indicate stages at which work must be stopped until certain conditions are met or approvals are obtained. Witness points require the presence of a designated individual to observe and verify specific activities. Monitor points involve ongoing surveillance or oversight of critical processes or activities. Document review points involve reviewing and approving documents, reports, or records to ensure accuracy, completeness, and compliance with requirements.

5.6.3 Process Control Documents

The organization is required to document process controls, which must encompass or make reference to Criteria for verifying compliance with relevant quality plans, API product specifications, customer requirements, and/or other pertinent product standards/codes; Instructions and criteria for processes, tests, inspections, and; When relevant, points designated for the customer’s inspection hold, witnessing, monitoring, and document review. Process controls may take the form of routings, travelers, checklists, process sheets, or similar controls, and may be electronic or hard copy.

Process controls are be documented in routing, travelers, checklists, process sheets, or equivalent controls as required by the organization including requirements for verifying conformance with applicable product quality plans, API product specifications, customer requirements, and/or other applicable product standards/codes. The process control documents also include or have reference to instructions and acceptance criteria for processes, tests, inspections, and required customer’s inspection hold or witness points. Process control is about monitoring and controlling all aspects of a manufacturer’s production and operation. It’s part of the larger supply chain management and it works in conjunction with other operation management functions such as inventory control and quality control. The purpose of production control is to balance the output of a facility to guarantee that the specifications of the products being produced are met. It does this by applying specific actions and making insightful decisions to predict, plan and schedule work. Some of the activities that are regulated in production control include labor, the availability of materials and any restrictions on capacity and cost. The end result of production control is to achieve the expected quality and demanded quantity while monitoring the production schedule to ensure that the production plan is being met. The production control process varies from industry to industry and even business to business. That said, there are some fundamental steps that are common in any production control process. They are as follows.

  • Routing: The first step of any production control process is the definition of your operation, from beginning to end. This includes what raw materials you’ll need for production, other resources, such as labor and equipment, the needed quantity, quality expectations and where the production will take place. This process is to determine the most efficient and cost-effective step-by-step manufacturing process through scheduling.
  • Traveller: It is a document that contains all of the details about the materials and processes that went into the production of a given item. When a manufacturer receives an order, they create a work order to begin the production process. In addition to the work order, a traveller is created and moves along with the product as it flows through the production facilities. The traveller contains information about what items are necessary for the given product, what tools will be needed, and what steps the product will need to go through to be assembled.
  • Checklist for Manufacturing: A control checklist for manufacturing includes all the requirements for a product, both visual and physical. It is a beneficial tool to ensure all parties are on the same page about the demands for the parts, materials, and final product. It outlines the standards your suppliers and manufacturers should meet and describes the “ideal” product that your customer expects from you. You can think of a checklist as guidelines for all teams to follow when making and selling your products. It streamlines the cooperation process and helps eliminate any possible errors occurring along your entire manufacturing workflow.
  • Process sheet: A process sheet is a document that provides all the steps for manufacturing products. Process sheets are also processed records, production documents, or shop orders. A process sheet consists of manufacturing instructions for a specific batch, lot, or run. It describes the operating parameters and settings for the equipment and facilities used and associated tooling or supplies. It contains part information, routing information, and operation detail information. A process sheet is a set of instructions that can be followed to achieve the desired goal.

5.7.1.5 Validation for Production & Servicing

5.6.4 Validation of Processes

The organization is obligated to validate processes in cases where the resulting output cannot be verified through subsequent monitoring or measurement, leading to the detection of deficiencies after product delivery or during its usage. Validation must demonstrate these processes’ capability to achieve planned outcomes. Process validation shall adhere to either of the following:

  1. If a product specification specifies particular processes necessitating validation, only those specified processes shall require validation for the relevant product. (Note: The organization may, at its discretion, opt to validate additional processes beyond those outlined in a product specification.)
  2. If there is no applicable product specification or the specification does not identify processes requiring validation, processes necessitating validation for the product, if applicable, shall include, at a minimum: nondestructive examination (NDE)/nondestructive test (NDT), welding, heat treating, and coating and plating (when deemed critical to product performance by the product specification or the organization).

The organization must maintain a documented procedure for process validation, detailing the review and approval methods. This procedure should cover required equipment; personnel qualification; specific methods, including defined operating parameters; identification of process acceptance criteria; record-keeping requirements; and revalidation criteria. In cases where the organization outsources a process requiring validation, it must retain evidence confirming compliance with the stipulations outlined in section 5.6.4.

This section reviews the validation of process for production and servicing. All those process of production and servicing has to be validated where the resulting output cannot be verified by subsequent monitoring or measurement, and as a consequence, deficiencies become apparent only after the product is in use or the servicing has been delivered. The organization shall maintain a documented procedure to address methods for review and approval of the processes including:

o Required equipment
o Qualification of personnel
o Use of specific methods
o Identification of acceptance criteria
o Requirements for records
o Re-validation

The organization shall validate those processes identified by the applicable product specification as requiring validation. If these processes are not identified, or there is no product specification involved, the processes requiring validation shall include, as a minimum, nondestructive examination, welding, and heat treating, if applicable to the product. Process validation is the act of controlling a process and actually performing the necessary tests to ensure that the process can, in fact, perform according to the requirements it is designed to meet. The monitoring and measuring of the characteristic of the been designed, implemented and executed in a way that enables fulfillment of the planned results. Each organization with the implemented quality management system need validate each of their production and delivery services processes where these processes operate without exhaustive monitoring or measurement. A process needs to be validated if you will not be able to check if the product or service is compliant with input requirements. An example might be a soldering process or welding process where you cannot check the strength of every weld during your regular production without damaging or destroying the parts. Not every process is required to undergo a validation so if you have a process where validation is not required you can still choose to validate the process. For instance, you may want to validate a process in order to reduce a complex or costly inspection of the product or service after the process, even if you could check that the outputs meet the input requirements. Which processes you validate is determined by you and your needs.

5.6.5 Identification and Traceability

The organization is responsible for establishing and preserving identification throughout product realization, encompassing relevant delivery and post-delivery activities. This entails acknowledging traceability requirements outlined by the organization, the customer, and/or pertinent product specifications. The organization must uphold a documented procedure for identification and traceability while the product remains within its control, covering the following:

  1. Methods employed for identification.
  2. Necessary information for traceability, if mandated.
  3. Criteria for maintaining and/or reinstating identification and/or traceability.
  4. Measures to rectify instances of lost identification and/or traceability.

Records documenting traceability must be retained. Please note that “product” may encompass components or raw materials.

The organization must establish a documented procedure for identification and traceability while the product is under control of the organization as required by the organization, the customer, and/or the applicable product specifications throughout the product realization process, including applicable delivery and post-delivery activities. The procedure shall include requirements for maintenance or replacement of identification and/or traceability marks. Identification and traceability must be recorded. Where traceability is a requirement, the organization should control and records the unique identity of the product throughout the production process to ensure that only products that have passed the required inspections and tests are utilized. The process for the identification and traceability of outputs, in terms of the monitoring and measurement requirements at all stages of production, to enable the demonstration of conformity to requirements, e.g. physical part marking, labeling, tags, bar codes, signage, visual indicators, part segregation, lay down areas, storage racks. There are several ways of identifying products to prevent them becoming mixed with other parts, components, or orders. The most obvious is using tags or stickers with a unique traceability identifier, such as a lot or batch number included on the product labels. The identification may be engraved in the product itself, or the product may simply be marked by a color. Establish and implement a procedure to identify the product through the design, development, manufacture and delivery stages. The established a traceability system should track components from raw material through inspection, test, and final release operations, including rework:

  1. Establish the identity and status of products;
  2. Maintain the identity and status of products;
  3. Maintain records of serial or batch numbers.

5.6.6 Inspection/Test Status

The organization is required to uphold a documented procedure for maintaining the identification of inspection and/or test status throughout product realization, clearly indicating whether the product conforms or exhibits nonconformity.

The organization must establish a documented procedure for the identification of product inspection and/or test status throughout the product realization process that indicates the conformity or nonconformity of product with respect to inspections and/or tests performed. The organization shall ensure that only product that meets requirements or that is authorized under concession is released. Product inspection & test status are conducted for the product identification, and all the quality requirements managed in it. Product inspection and test status documentation is managed to recording information of the quality inspection and quality test that conducted, progress of the test and its status records are managed in the documents, the quality inspection and test status is maintained for the product identification. The documentation of the Product inspection & test status are maintained each process stages that required for the manufacturing, producing materials with quality as per customer requirements. The documents covered materials and its identification method that used to product realization with detailed information is managed in the quality inspection and test status. Management of the quality concern issues and its concern methods are also maintained in details. The stages of the product management are conducted incoming materials to final product and its concern information that used for the product identification. The documentation for inspection and test status is the part of the product identification, and the records are managed by quality manager, and quality manager is responsible for the managing records and its concern activities that help to determine actions for improvement for particular stages and its methods that handled during the process.

5.6.7 Externally Owned Property

The organization must uphold a documented procedure for managing externally owned property, including customer property, incorporated into the product while under the organization’s control. This property encompasses intellectual property and non-publicly available data. The procedure should cover identification, verification, safeguarding, preservation, maintenance, and reporting loss, damage, or unsuitability for use to the external owner. Records concerning the control and disposition of externally owned property must be retained.

The organization must a documented procedure for the identification, verification, safeguarding, preservation, maintenance, and control of Externally owned property, including intellectual property and data, while under control of the organization. The procedure includes requirements for reporting to the customer any loss, damage, or unsuitability for use of Externally owned property. The control and disposition of Externally owned property must be recorded.

This contains the requirement for organizations to have documented procedures for the identification, verification, safeguarding, preservation, maintenance, and control of Externally owned property property. Check that your organization communicates with its External provided including customers in regard to the handling and treatment of their property. You should also check that contingency plans and, where relevant, actions are undertaken when non-conformities occur with Externally provider property. Good sources of information often include the following examples:

  • Goods returned by the customer;
  • Warranty claims;
  • Revised invoices;
  • Credit notes;
  • Articles in the media;
  • Consumer websites;
  • Direct observation of, or communication with, the customer.

If there are any products, materials, or tools on your organization’s premises that are owned by External provider, customer, all employees must exercise care with this property. This means they must ensure that the product is not lost or damaged. If External provided property is lost or damaged, this needs to be recorded and the External provider needs to be notified. Establish and implement a process to manage property supplied by External provider:

  • Establish the identity and status of External provided supplied product;
  • Maintaining records.

5.6.8 Preservation of Product

The organization must uphold a documented procedure outlining the approaches employed to maintain the integrity of the product and its component parts during product realization and delivery. This procedure should cover identification and traceability marking, storage procedures (including designated storage areas or stock rooms), periodic condition assessments as specified by the organization, transportation, handling, packaging, and protection. Records of assessment results must be retained.

The organization must establish a documented procedure for preservation of product and its constituent parts, It must describe the methods used to preservation throughout product realization and delivery to the intended destination in order to maintain conformity to requirements. It must include identification and traceability marks, transportation, handling, packaging, and protection as applicable. The preservation process must include packaging, storage and other product specific handling methods.

  1. Identification and traceability– Ensure that products are properly identified and do not become mixed with other orders. You should expect to see that all products are clearly identified. This is relative to identification and traceability however for preservation of product it is a requirement and not ‘as applicable’;
  2. Handling – This may include bulk handing using moving equipment or physical contact where handling may influence product conformity. You should verify that suitable handling methods are implemented throughout the processes.
  3. Packaging – Ensure that labeling and marking of shipped products are sufficient to enable adequate identification and traceability back through your QMS. This should include ensuring that labeling and marking maintains its integrity and remains affixed throughout the shipping process. You should expect to see that methods have been established for packaging the product to preserve its integrity. Package products appropriately for shipping in order to preserve the product’s integrity throughout the shipping process;
  4. Protection – Raw materials, in-process materials, inspected product, nonconforming product and product ready for shipping should also be identified with its status and protected from any unintended alteration. You should verify that appropriate measures are in place to protect product. This will vary depending on the product.

The procedure must also identify the requirements for storage and assessment of the and its constituent parts . There must be designated storage areas or stock rooms to prevent damage or deterioration of product before its use or delivery. To check for deterioration, the condition of product or constituent parts in stock has to be assessed at specified intervals . The interval will be appropriate to the products or constituent parts being assessed. The organization must use designated storage areas or stock rooms to prevent damage or deterioration of product, pending use or delivery. Appropriate methods for authorizing receipt to and dispatch from such areas shall be stipulated. The storage facilities, should not only be physical security but also the environmental conditions (e.g., temperature and humidity). In order to detect deterioration, the condition of product in stock shall be assessed at appropriate intervals. It may be appropriate to check periodically items in storage to detect possible deterioration. The methods for marking and labeling should give legible, durable information in accordance with the specifications. Consideration may need to be given to administrative procedures for expiration dates, and stock rotation and lot segregation.

5.6.9 Inspection, Testing, and Verification
5.6.9.1 General

The organization must maintain a documented procedure for inspecting, testing, and/or verifying the product to ensure that requirements have been met. This procedure should cover:

  1. Methods and application of in-process inspection, testing, and/or verification.
  2. Methods and application of final inspection, testing, and/or verification.
  3. Creation and retention of records.

It’s important to note that in-process and final inspection may be combined into one or more activities, and certain product characteristics may necessitate final inspection/verification during product realization.

A product inspection is the process of examining your goods against a list of pre-set criteria to ensure they meet your quality standards. The process might include packaging and labeling checks, visual examination, functionality checks, and measurement taking.Product testing typically involves using advanced equipment in a laboratory setting to verify product safety, compliance, or performance. You might test your products to check for harmful chemicals, comply with regulations, or simulate repeated use.The key differences between inspection and testing in manufacturing are:

  • Inspections typically take place at the factory where the goods are produced, while testing occurs in a specialized lab.
  • Inspections typically use basic equipment that an inspector can carry with them, while testing involves advanced equipment.
  • Inspections are typically focused on maintaining quality standards, while testing is focused on regulatory compliance and performance standards.

Types of inspection / verification:

  • Quantity
  • Description: size, weight, diameter, length
  • 100% or sampling
  • Visual inspection
  • Gaging
  • Dimensional inspection
  • Nondestructive examination
  • Hardness testing
  • Positive material identification
  • Document review (inspection reports, material test reports)

organizations must maintain a documented procedure for inspecting, testing, and/or verifying the product to ensure that requirements have been met. Here’s how the procedure should cover each aspect:

  1. Methods and Application of In-Process Inspection, Testing, and/or Verification:
    • The procedure should detail the methods used for in-process inspection, testing, and/or verification during the manufacturing or assembly process.
    • It should specify the points in the production process where in-process inspections or tests are conducted, as well as the acceptance criteria for each inspection or test.
    • The procedure should outline how the results of in-process inspections or tests are documented, communicated, and used to make decisions about product acceptance or further processing.
  2. Methods and Application of Final Inspection, Testing, and/or Verification:
    • The procedure should describe the methods used for final inspection, testing, and/or verification of the finished product before release or delivery.
    • It should specify the criteria and procedures for conducting final inspections or tests, including sampling plans, test methods, and acceptance criteria.
    • The procedure should outline how the results of final inspections or tests are documented, evaluated, and used to determine product acceptability and readiness for release.
  3. Creation and Retention of Records:
    • The procedure should define the requirements for creating, maintaining, and retaining records of inspection, testing, and verification activities.
    • It should specify the information to be included in inspection, test, and verification records, such as the date and time of the activity, the identity of the inspector or tester, the results of the inspection or test, and any actions taken as a result of the findings.
    • The procedure should outline the retention period for inspection, test, and verification records, as well as the storage and retrieval requirements to ensure that records are maintained in a secure and accessible manner.

By covering these aspects in the documented procedure for inspecting, testing, and verifying the product, organizations can ensure consistency, accuracy, and reliability in their quality control processes, leading to the production of products that meet specified requirements and customer expectations by API Specification Q1 requirements.

5.6.9.2 In-process Inspection, Testing, and Verification

The organization must conduct inspections, tests, and/or verifications of products at predetermined stages as specified by the quality plan, process control documents, and/or documented procedures. Evidence demonstrating conformity with the acceptance criteria must be retained.

The organization must inspect/verify and test the product at planned stages as per the product quality plan, process control documents, and/or documented procedures. Evidence of conformity with the acceptance criteria must be maintained. In-process inspections seek to examine workflow to reduce cycle time and Work-in-Process (WIP), while increasing capacity. Resources are evaluated to ensure proper training. Environmental factors are taken into consideration and products are inspected directly on the shop floor. The inspections can be performed by both manufacturing and inspection personnel.

5.6.9.3 Final Inspection, Testing, and Verification

The organization must conduct final inspection, testing, and/or verification of the product by the quality plan, process control documents, and/or documented procedures to ascertain and document conformity of the completed product with the specified requirements. Unless conducted by an automated system, individuals other than those involved in or directly overseeing the product realization process shall carry out the final acceptance inspection at the scheduled stages of the product realization process.

The organization must perform all final inspections and testing as per the product quality plan and/or documented procedures to validate and document the conformity of the finished product to the specified requirements. Personnel who have not performed or directly supervised the production must conduct a final acceptance inspection.  For single-step manufacturing processes (e.g. threading), in-process and final inspection and testing may be the same. Final inspections take place when production is complete. The overall product is measured against engineering, customer requirements, and standards. Final inspections and device approvals play an integral role in the decision to move items to stock or shipment. An inspection report is run before final device approval to ensure there are no open items. A final inspection report will validate that all required operations are complete, all non-conformances have been resolved, and required traceability has been recorded.

Usually, the Quality Manager determines the scope of the inspection and testing. This will be thoroughly communicated to all personnel. This procedure usually includes

  • Holding back products until all inspections have been finalized
  • The work order is reviewed to ensure all first-part inspections, processes, and specified operations have been completed—the relevant supervisor signs off the sheet
  • Check that all documents are traceable to each product and made available for inspection
  • Do a visual inspection to verify all specified operations have been completed. This is also done to detect any visible damage or defects
  • Goods are released for packaging and shipping after the final inspection has been completed

5.6.9.4 Records

Records documenting all necessary inspection, testing, verification, and final acceptance activities must be preserved.

Records documenting all necessary inspection, testing, verification, and final acceptance activities must be preserved by the organization. These records serve as evidence that products have been adequately inspected, tested, and verified to ensure they meet specified requirements before being released to customers or used in further processes. Inspection, testing, verification, and final acceptance records provide documented evidence that the organization has complied with its quality management system requirements and procedures. This documentation demonstrates that products have undergone appropriate evaluation and have met the necessary standards and criteria. Preserved records allow for traceability and accountability throughout the production and quality assurance processes. They enable the organization to track the history of each product, including who conducted inspections or tests, when they were performed, and what the results were. This traceability helps identify potential issues, track trends, and assign responsibility if problems arise.

5.6.10 Preventive Maintenance

The organization must uphold a documented procedure for conducting preventive maintenance on equipment utilized for product realization. This procedure should outline the equipment types subject to maintenance, the frequency of maintenance tasks, and the individuals responsible for carrying them out. Records detailing preventive maintenance activities must be retained. Preventive maintenance protocols can be devised based on various factors such as risk assessment, system reliability, usage patterns, historical data, industry best practices, applicable regulations, manufacturer recommendations, or other relevant criteria.

The organization must establish a documented procedure for preventive maintenance of equipment used in product realization. The procedure shall identify the type of equipment to be maintained, frequency and personnel responsible for preventive maintenance. Record for Preventive maintenance must be maintained. Preventive maintenance can be based on risk, system reliability, usage history, experience, industry-recommended practices, relevant codes and standards, original equipment manufacturer’s guidelines, or other applicable requirements.

Preventive maintenance consists of regular, scheduled maintenance activities that are performed on equipment to reduce the chance of failure and extend uptime. Preventive maintenance can be defined as the “systematic inspection, detection, correction, and prevention of incipient failures before they become actual or major failures.”

a) This specification requires that the type of equipment used in the process realization process be identified and maintained.

(b) Frequency Identifying the frequency of the preventive maintenance to be performed. This may include:

  • Daily/weekly
  • Monthly/Quarterly
  • Semi-Annually
  • Annually

(c) Identifying the responsible personnel to perform the preventive maintenance. This may include:

  • Operator
  • Maintenance Personnel
  • Manufacture/ 3rd Party

5.7 Product Release

The organization must retain a documented procedure concerning the release of products to customers. Product release should not occur until all planned arrangements have been satisfactorily fulfilled. Only products that conform to requirements or have been authorized under concession shall be released by the organization. Records must be kept to facilitate the identification of the individual responsible for authorizing product release.

The organization must establish a documented procedure to ensure release of product to the customer shall not proceed until all the planned arrangements have been satisfactorily completed, unless otherwise approved by a relevant authority and, where applicable, by the customer. Records to enable identification of the individual releasing the product must be maintained. The release of the product must not be completed until the planned requirements have been met. The release of a product may include, according to product planning and the verification stages; release to the next operation, release to an internal customer, or release to the final customer, etc. Planned arrangements can include design verification and design validation, which can involve modelling, simulations, experiments, trials, prototypes, functional testing, performance testing; inspections comprising, in-process, first article and final inspection; thorough examination through destructive and non-destructive testing; customer acceptance testing, product certification/qualification, third party qualification from a regulator, recognized society, or independent testing body etc. For product release, the planning requirements may be waived but must be approved by the relevant authority and by the customer as appropriate. Monitor and measure product characteristics to ensure they can demonstrate:

  1. Product characteristics are continually met;
  2. Evidence of conformity with product requirements.

Retain records to provide evidence that acceptance criteria have been met might include: e.g. certificate of conformity, release certificate, and regulatory certificate. Ensure traceability to the person(s) authorizing the release such as name, authorized signatories, user identification, stamp impression etc., including their authority status (release signatory, certifying staff, scope of authorization etc.).

5.8 Testing, Measuring, Monitoring, and Detection Equipment (TMMDE)

5.8.1 General

The organization must establish the testing, measuring, monitoring, and detection requirements necessary to demonstrate conformity to specified standards. This includes the necessary Test, Measurement, Monitoring, and Detection Equipment (TMMDE). TMMDE, whether owned and maintained by the organization, owned by employees, or obtained from external sources such as third-party vendors, proprietary sources, or customers, must be controlled. Calibration of TMMDE must occur at specified intervals, with documentation of the date of first use when the calibration interval is determined based on this date.

5.8.2 Procedure

The organization must uphold a documented procedure for controlling Test, Measurement, Monitoring, and Detection Equipment (TMMDE). This procedure must encompass specific equipment types and include:

  1. Unique identification;
  2. Calibration status;
  3. Traceability to international or national measurement standards. If such standards are absent, the basis for calibration must be recorded;
  4. Calibration method and acceptance criteria;
  5. Calibration frequency and the commencement of calibration intervals;
  6. Documentation of calibration measurements before and after adjustments, known respectively as ‘as-found’ and ‘as-left’ measurements. If no adjustments are made, ‘as-found’ and ‘as-left’ measurements are the same;
  7. Measures to prevent unintended use of TMMDE identified as out-of-calibration, beyond calibration intervals, or out-of-service;
  8. Assessment of the validity of previous measurements and actions to be taken on the TMMDE and product if TMMDE is found to be out of calibration, including maintaining records and evidence of customer notification if the suspect product has been shipped;
  9. Utilization of third-party, proprietary, employee-owned, and customer-owned TMMDE;
  10. Maintenance; and
  11. Suitability for planned monitoring and measurement activities.

5.8.3 Equipment

TMMDE identified in 5.8.1 must adhere to the following:

  • a) Undergo calibration;
  • b) Have its calibration status identifiable by the user before and during use;
  • c) Be safeguarded from adjustments or modifications that could invalidate the measurement result or calibration status;
  • d) Be protected from damage and deterioration during handling, maintenance, and storage; and
  • e) Be utilized under environmental conditions suitable for the calibrations, inspections, measurements, and tests being performed.

When utilized in testing, monitoring, measurement, or detection to meet specified requirements, the suitability of computer software to fulfil the intended application must be confirmed before initial use and reconfirmed as necessary.

5.8.4 TMMDE Equipment from Other Sources

When utilizing TMMDE that is third-party, proprietary, or customer-owned, the organization must ensure the equipment is calibrated before use. If constrained by customer, contract, or licensing agreement limitations, the requirements outlined in 5.8.2, Item c), 5.8.2, Item d), 5.8.2, Item e), 5.8.2, Item f), 5.8.2, Item j), and 5.8.2, Item k) shall not be applicable.

The organization must determine the testing, monitoring, and measurement required and the associated equipment needed to provide evidence of conformity to those requirements. The organization must establish a documented procedure for maintenance and calibration of the testing, measurement, and monitoring equipment and that the equipment is used as per the monitoring and measurement requirements. The procedure shall include unique identifier, calibration status, equipment traceability to international or national measurement standards. If no such standards exist, the basis used for calibration or verification must be recorded. It must also include frequency of calibration prior to use and also at specific intervals. The calibration or verification method, including adjustments and readjustments as necessary, the acceptance criteria and control of equipment identified as out-of-calibration in order to prevent unintended use should be included in the procedure. When the equipment is found to be out of calibration, an assessment of the validity of previous measurements must be undertaken. Actions to be taken on the equipment and product. If any suspect product has been shipped, there must be evidence of notification to the customer. Records must be maintained. Test, Measurement, Monitoring, and Detection Equipment (TMMDE) must be calibrated or verified, or both, against measurement standards. Verification against identified acceptance criteria is performed on nonadjustable equipment. TMMDE must have the calibration status identifiable by the user for the activities being performed at all times. It must be safeguarded from adjustments that would invalidate the measurement result or the calibration status. It must be protected from damage and deterioration during handling, maintenance, and storage. It must be used under environmental conditions that are suitable for the calibrations, inspections, measurements, and tests being carried out. When used in the testing, monitoring, or measurement of specified requirements, the ability of computer software to satisfy the intended application must be confirmed prior to initial use and reconfirmed as necessary. When the equipment is provided from either third-party, proprietary, employee- and customer-owned equipment, the organization must verify that the equipment is suitable and provide evidence of conformity to the requirements. The organization must maintain a registry of the required TMME which must include a unique identification, specific to each piece of equipment. Record of results calibration and verification must be maintained.

TMMDE are subject to the following controls:

  • Devices are calibrated at intervals or before use, based on recognized standards;
  • Devices are adjusted as necessary according to the manufacturer’s instructions;
  • Devices are identified to enable calibration status to be determined;
  • Devices are safeguarded from adjustment, which may invalidate results;
  • Devices are protected from damage during handling, maintenance or storage;
  • The validity of results from a non-confirming device is re-checked with a conforming device;
  • Devices are calibrated by external providers certified to ISO 17025;
  • Records of calibration and verification are maintained;
  • Computer software which is used for monitoring/measuring is validated before initial use;
  • Computer software used for monitoring and measuring is re-validated where necessary.

If measurement traceability is not required, verify that those monitoring and measuring resources used by your organization are suitable. You should ensure that record is maintained in order to demonstrate the suitability of monitoring and measuring equipment. While this is not required, all equipment requiring calibration must be identified and must be:

  1. Calibrated or verified at specific intervals, or prior to being used. Equipment must be calibrated using measurement standards traceable to international or national measurement standards. Where there is no standard available for the device the basis for calibration or verification must be recorded. A Certification Auditor would expect to see that traceable standards are used and where applicable have not expired. Where calibration is completed by an outsourced process i.e. vendor, the records of traceability must be reviewed.
  2. Adjusted or readjusted as necessary. There must be evidence that equipment found to be out of calibration are adjusted/re-adjusted by qualified personnel and the validity of the previous measuring results are accessed when equipment is found to be out of calibration and appropriate action is taken (may include recall of product). A process must be in place to provide traceability of each piece of equipment to the process/product that the equipment was used on. The calibration and verification results must be maintained as quality records.
  3. Identified to show calibration status. Each piece of equipment must be identified in such a way that the user can determine that the device has current calibration, this may be accomplished by the equipment’s unique serial number traceable to the calibration record however, the calibration status label is a good practice. Other methods may be used however must identify the calibration status. Where the environment is not conducive to the use of stickers, the status may be identified by colour-coding, identification number with associated calibration record, and/or calibrated before every use.
  4. Safeguarded from adjustment. A process must be in place to ensure that users outside the calibration process do not adjust equipment. Equipment may be verified before use however any adjustments made to equipment must meet all requirements of this section. Methods to safeguard may include; locking materials for setscrews, tamper-proof seals, limited entrance to calibration areas, and other methods.
  5. Protected from damage during handling, maintenance and storage. The measuring equipment must be handled and stored in a manner to protect the equipment from damage.

5.9 Control of Nonconforming Product
5.9.1 Procedure
5.9.1.1 General

The organization must uphold a documented procedure that outlines controls, along with the corresponding responsibilities and authorities, for managing nonconforming products throughout product realization and post-delivery.

5.9.1.2 Nonconforming Product During Product Realization

The procedure for handling a nonconforming product discovered during product realization must encompass guidelines for product identification and control to avoid unintended use or delivery, addressing the identified nonconformity, implementing measures to prevent its initial intended use or delivery, and obtaining authorization for its use, release, or acceptance under concession from the appropriate authority and, if necessary, from the customer.

5.9.1.3 Nonconforming Product After Delivery

The procedure for handling a nonconforming product discovered during product realization must encompass guidelines for product identification and control to avoid unintended use or delivery, addressing the identified nonconformity, implementing measures to prevent its initial intended use or delivery, and obtaining authorization for its use, release, or acceptance under concession from the appropriate authority and, if necessary, from the customer.

5.9.2 Nonconforming Product

The organization shall manage nonconforming products by executing one or more of the following actions:

  • a) Conducting repair or rework followed by subsequent inspection to ensure compliance with specified requirements;
  • b) Re-grading for alternative applications;
  • c) Releasing under concession;
  • d) Rejecting or scrapping the product.

5.9.3 Release of Nonconforming Product Under Concession

Nonconforming products that do not meet manufacturing acceptance criteria (MAC) may be released under concession if authorized by the organization’s relevant authority, given that:

  1. The products still meet the applicable design acceptance criteria (DAC) and customer criteria;
  2. It is determined that the violated MAC is unnecessary to meet the applicable DAC and/or customer criteria; or
  3. The DAC has been modified, and the affected products comply with the revised DAC and associated MAC requirements. If the DAC was previously agreed upon with the customer, any changes to the DAC must be authorized by the customer.

The organization is not permitted to release products that do not conform to DAC or contract requirements without authorization from the customer.

5.9.4 Customer Notification of Nonconforming Product

The organization is required to inform customers of any delivered product that does not meet the agreed design acceptance criteria (DAC) or contractual requirements. The organization must maintain records of such notifications.

5.9.5 Records

Records documenting nonconformities must be retained, encompassing details of the nonconformity, actions taken thereafter including any concessions secured, the reasoning behind approving product release under concession, and the pertinent authority involved.

The organization must establish a documented procedure to identify the controls including the responsibilities and authorities for nonconforming product. The procedure for nonconforming product identified during product realization must includes controls for product identification to prevent unintended use or delivery, address the detected nonconformity, take action to preclude its original intended use or delivery and authorizing its use, release, or acceptance under concession by relevant authority and, where applicable, by the customer. The procedure for nonconforming product identified after delivery must include identifying, documenting, and reporting nonconformances or product failure identified after delivery. It must ensure the analysis of product nonconformance or failure, provided the product or documented evidence supporting the nonconformity is available to facilitate the determination of the cause. It must take action appropriate to the effects, or potential effects, of the nonconformance when nonconforming product is detected after delivery. The organization shall address nonconforming product by repair or rework with subsequent inspection to meet specified requirements; and /or re-grade for alternative applications; release under concession and/or reject or scrap.

The evaluation and release under concession of nonconforming product that does not satisfy manufacturing acceptance criteria (MAC) can be permitted when the organization’s relevant authority and the customer (where applicable) have authorized the release provided that products continue to satisfy the applicable Design acceptance criteria (DAC) and/or customer criteria; or the violated MAC are categorized as unnecessary to satisfy the applicable DAC and/or customer criteria or the DAC are changed and the products satisfy the revised DAC and associated MAC requirements. The organization shall notify customers of product not conforming to DAC or contract requirements, that has been delivered. The organization shall maintain records of such notifications. The nature of nonconformities and any subsequent actions taken, including concessions obtained, must be recorded. The organization must keep records of each nonconformance or defect and how it was dealt with. Records of product nonconformity should be periodically reviewed to determine if a chronic problem exists with the production process. The product should then be subject to further inspection to verify that it is now correct. As for records, if you documented the nonconforming product there should normally be somewhere to verify that you successfully (or not) cured the problem and that it is now conforming. Re-verification simply means that you cannot assume that because someone tells you they have corrected the problem then it is ok. The clause is asking you to re-verify by whatever means you originally chose. If you used inspection as a method of verification then re-inspect in the same method. If not, use whatever method suits you (or your customer). Just make sure it is ok before it leaves. The re-verification after remedial work might involve testing as well as inspection. The reason is not just to verify that the defect has been removed, but also to assure that fresh defects have not been introduced by the rework. Records would be as appropriate for the re-inspection or re-testing performed. Re-verification is equivalent to re-inspection and records could include a signature of approval or a more formal test report. Whichever format is chosen, it must be defined in the nonconformity procedure. You may need to supply new evidence of conformance to your customer along with corrective action documentation if requested. The method that you use in either of these situations should be defined in your procedures, that way you relieve yourself and your auditor from guessing how you would address them. Where necessary, any product or process outputs that do not conform to specified requirements should be properly identified and controlled to prevent unintended use or delivery. Improvements are then implemented to ensure the nonconformance does not reoccur. Control defective products by:

  • Defining how nonconforming products and processes are identified;
  • Defining how nonconforming products and processes are dealt with;
  • Removing or correcting nonconformities;
  • Preventing the delivery or use of nonconforming products and processes;
  • Verifying how nonconforming products and processes were corrected;
  • Providing evidence that corrected products and processes now conform to requirements;
  • Keeping records that catalogue nonconforming products and processes.

There may be instances where it is impossible to completely eliminate the cause of the nonconformity, so in these instances, the best you can do is to reduce the likelihood or the consequences of a similar problem happening again in order to reduce the risk to an acceptable level. Where applicable any corrective action taken and controls implemented to eliminate the cause of nonconformity should be applied to other similar processes and products.

Handling Nonconforming Products
Documented procedure should indicate the plan of action for controlling products. Nonconforming product is identified and separated from other conforming products. Nonconforming product must be reviewed and approved before release. Details of nonconformity must be documented. If nonconformity is identified after delivery, separate actions taken. Re-processed nonconforming products should be re-validated before release. When it comes to controlling and handling non conforming products , there is a specific procedure that must be carefully followed to ensure that the wrong product is not given out to consumers. First and foremost, the organization should already have a documented procedure that indicates the method they will use or plan of action that will be taken in order to control the products in question.

Upon the removal of the non conforming products , the organization will ensure that it does not get mixed up with the quality products that are on their way to be distributed to the masses. Once the product has been effectively identified and removed from the others, it must be properly reviewed and approved before it can be released. The release of a nonconforming product can be made under concession by an authorized person. Any release of this kind should be properly documented after it has been completed. The other details of the nonconformity must also be documented in detail. This should include the exact non-conforming characteristics that were identified, as well as the procedures that were followed in order to get rid of it and prevent it from happening in the future. From the documentation of the nonconforming product, all company personnel should be able to understand the nature of the event, why the product did not conform to the specified standards, and what was done to eliminate the issue. In the event that a nonconforming product is identified after it has already been distributed or delivered, there will be a separate set of actions that must be taken to solve the problem at hand. These actions will depend on the severity of the nonconformity, and will be determined by the discretion of the company leaders. When a nonconforming product has been identified and a plan of action has been established to solve the problem, it can either be permanently removed or possibly altered in order to fit the guidelines and be considered a qualifying product. When any nonconforming product is reprocessed, it must go through a revalidation process by someone of proper authority in order to be approved for release.

5.10 Management of Change (MOC)
5.10.1 General

The organization is required to uphold a documented procedure for Management of Change (MOC) to ensure the integrity of the quality management system amid changes. This MOC procedure shall cover:

  1. a) Description and justification of the change;
  2. b) Allocation and availability of resources, including personnel;
  3. c) Assessment of potential risks associated with the change;
  4. d) Review, approval, and execution of the change;
  5. e) Notifications regarding the change;
  6. f) Verification of the completion of MOC activities and assessment of their impact on the Quality Management System (QMS).

5.10.2 MOC Application

The organization must utilize Management of Change (MOC) for alterations that could adversely affect the product’s quality.

5.10.3 MOC Notification

The organization must inform pertinent internal staff about the change and its associated risks. If mandated by contract, the organization must also notify the customer of the change and its associated risks. Documentation of MOC notifications is required.

5.10.4 Records

Records of MOC activities must be maintained

Changes are intended to be beneficial but they need to be carried out when determined by your organization as relevant and achievable. In addition, consideration of newly introduced risks and opportunities should also be taken into account. To achieve the benefits associated with changes, your organization should consider all types of change that may occur. These changes may be generated, for example, in:

  1. Processes and procedures;
  2. Quality manual;
  3. Documented information;
  4. Infrastructure;
  5. Tooling;
  6. Process equipment;
  7. Employee training;
  8. Supplier evaluation;
  9. Stakeholder management;
  10. Interested party requirements.

Whenever quality management system changes are planned, Top management should ensure that all personnel are made aware of any changes which affect their process, and that subsequent monitoring is undertaken to ensure that QMS changes are effectively implemented. The organization must consider

  • The purpose of the changes and their potential risk and opportunities.
  • The integrity of the management system.
  • The availability of resources.
  • The allocation or reallocation of responsibilities and authorities

Decide on Disposition Option
This is the step where you decide what to do with the non-conforming products. There are several options that you can choose from:

  1. Eliminate the non-conformance: By applying rework to the product , you can bring it back to fully meeting the requirements. The main difference between a rework and a repair is that the non-conformance is fully eliminated to be compliant with a rework, but it is only eliminated enough to make it usable with a repair. Finding a bracket with holes that were too small and drilling them bigger to meet a drawing would be an example of a rework.
  2. Authorizing use: If there is a concession from the requirements and the product or service is useable, although not fully compliant, then you can accept to use the product or service as is. Sometimes a repair to the product will be required to change the product enough to make it usable, although it will not fully meet the requirements. If a bracket has holes out of position, you could make the holes into slots so that the part fits in place. This would be an example of a repair.
  3. Preclude original use: This is when you decide to either scrap the product or to re-grade the product or service (such as product sold as seconds).
  4. Correct per Disposition: This is simply doing the actions you decided to do . If you are accepting the product or service as is, then allow it to continue. If you are reworking or repairing something, have the steps carried out to do so as planned (and make sure it is re-verified afterwards). If you are using the unit to sell as a second, how do you identify it so that it ends up being used properly at the end of the process?
  5. Corrective Action: Finally, after deciding how to fix the product , take a look at why the non-conformance happened, and try to find and fix the cause so that it doesn’t happen again. If there is an error in the instructions that caused the problem, get the instructions fixed. If a program bug caused a service error, fix the program. If you have found that a part of the machine is wearing out, implementing a preventive maintenance check on that machine could go a long way toward helping prevent similar problems in the future. If this is a recurring problem, then maybe switching the investigation over to the Corrective Action process would allow for greater improvements. Often, the Non-conforming Product process is the biggest input to the Corrective Action process.

API Q1 4 Quality Management System Requirements

4 Quality Management System Requirements

4.1 Quality Management System

4.1.1 General

The organization must always plan, set up, record, put into action, and keep up a quality management system in line with this specification’s demands for the product within the organization’s defined scope. Additionally, the organization needs to assess and enhance the effectiveness of this quality management system.

The Process-Based Management System Model supports all of the other API and ISO management system standards and specifications. The model starts with an understanding of the Organization’s Customer Requirement, this is an INPUT to the organization’s Product Realization is where the product/service takes place producing an OUTPUT (Product/Service) to Customer satisfaction. Product Realization must be constantly measured, analyzed and when needed, improved to ensure customer requirements and satisfaction are maintained. The results of the analysis go to Top management, which is responsible for acting upon the results and properly allocating resources to the organization to ensure that Products and services will continue to keep up with Customer requirements.

4.1.2 Quality Policy

The organization’s commitment to quality must be clearly outlined, documented, reviewed, and endorsed by top management. The quality policy should align with the organization’s goals and guide its strategic path. It must serve as a foundation for setting quality objectives. It must be effectively communicated, understood, put into practice, and upheld within the organization. It must be accessible to relevant stakeholders as determined by the organization, and include a pledge to meet requirements and consistently enhance the efficiency of the quality management system.

The quality policy must be appropriate to its purpose and there is a commitment to continually improving the quality management system, and the quality objectives are consistent with the quality policy. The policy does not have to include objectives but should create a framework for establishing them. The policy should be stated in such a way that it aims toward continual improvement. It should be reviewed and possibly revised to meet higher aspirations. Develop and implement a policy that is consistent with the company’s codes of conduct and business practices. The policy should be signed by senior management and committed to:

  • Preventing process loss or quality impacts;
  • Complying with obligations and legal requirements;
  • Promoting continual improvement;
  • Adopting best practices;
  • Creation of measurable and achievable targets for performance improvement;
  • Providing resources to achieve targets;
  • Communicating and consulting with all stakeholders regarding the QMS;
  • Meeting customer requirements.

Tell everyone about it.

  • Make sure it is written.
  • Making sure people know it and understand it.
  • Give it to people who have an interest in your business (e.g. clients/suppliers/manufacturers/staff).
  • Publishing it on your website.

The Examples include written Quality policy, company induction, basic training, and toolbox talks.

4.1.3 Quality Objectives

Quality objectives, including those necessary to fulfil product and customer needs, must be set at appropriate functions and levels within the organization by management, with approval from top management. These objectives should be measurable, communicated, and aligned with the quality policy.

No quality plan can be completed without having measurable quality objectives. An objective should include a description of who is responsible, what is the target, and when is it planned to be achieved. Progress must be monitored. Also, requires objectives to be set for relevant processes. Ensure that whatever objectives you implement are SMART

  • Specific
  • Measurable
  • Achievable
  • Realistic
  • Time-bound

Some  key rules are as follows:

  • Make sure they comply with the law and industry standards.
  • Make sure they conform with the products and services to make them better.
  • Monitor your objectives periodically to check what you are doing.
  • Tell the staff what they are and what you expect of them.
  • Updated when the management changes something.

Keep records of this. This should be included in the customer SLA and planning should be in place to ensure you can resource this response rate. An example could be Understanding the total number of planned maintenance, and the number of reactive maintenance to ensure you calculate the appropriate levels of resources. Organizations need to clearly understand how these will be realized. For example, if you aim to provide national coverage, how will this be achieved? What resources will you allocate, recruiting staff to cover the nation, training your staff etc.

4.1.4 Planning the Quality Management System

4.1.4.1 General

The planning of the quality management system must be conducted. While planning, the organization must specify the scope of the quality management system, including the products covered and any limitations or exclusions. The organization must recognize external and internal factors relevant to the organization’s long-term objectives and goals. Identify relevant stakeholders and their requirements for the quality management system. The organization must establish the sequence and interaction between the processes of the quality management system. The organization must determine and oversee the criteria and methods necessary for the efficient operation and control of quality management system processes. The organization must set quality objectives, detailing actions, resources, responsibilities, timeframes, and methods for monitoring and evaluation. It must address identified risks. It addresses opportunities for improvement. It must identify key personnel involved in the quality management system.

To meet the requirements for the delivery of products and services, the organization needs to plan, implement, and control its processes. The first step is to determine the requirements for products and services, meaning what features the product or service will have. Then, the organization needs to define how processes will be performed and what criteria the product or service needs to meet to be accepted for release. Finally, the organization needs to determine the resources needed for the processes and the records needed to demonstrate that the processes were carried out as planned. Once they have done their planning for what they are going to sell, they then must plan the details of how this can be done operationally. The organization may need to :

  • Set up supplier accounts/trade accounts.
  • Purchase stock.
  • Ensure staff have the correct skills and understand the process.
  • Purchase tools and vehicles.
  • Make sure you have enough staff.
  • Issue clear instructions, drawings, procedures risk assessments to enable them to do the job.

The organization needs to show clear control of the process. They will be expected to check that delivery is as expected and when there are deviations that this is managed and negative impacts controlled. The same control should be applied to subcontractors.

4.1.4.2 Exclusions

If an organization carries out activities covered by API Q1, whether internally or through outsourcing, it cannot claim the exclusion of those activities. Excluding certain activities should not impact the organization’s capability or obligation to deliver products that meet customer and legal standards. If any exclusions are made, the reasoning behind them must be documented. When an organization performs activities addressed by this specification, no claims to exclusion of those activities are permitted. When exclusions are permitted, they are limited to the following sections:

API Q1 ClausesSections
 5.4Design
 5.6.4Validation of Processes
 5.6.7Externally Owned Property
 5.8Testing, Measuring, Monitoring, and Detection Equipment (TMMDE)

4.1.5   Communication

4.1.5.1 Internal

The organization must set up internal communication processes. These processes should involve communicating, at appropriate levels and functions within the organization the significance of meeting customer, legal, and other relevant requirements; and the outcomes of data analysis.

4.1.5.2 External Communications

The organization must create and put into action a procedure for communicating with external entities, including customers. This process should cover:

  1. Handling inquiries, contracts, or order processing, and any modifications;
  2. Understanding and meeting requirements during contract execution and product creation;
  3. Providing product details, including any non-conformities;
  4. Addressing feedback and customer complaints;
  5. Sharing quality plans and any subsequent adjustments; and
  6. Communicating changes and associated risks.

This clause includes both internal and external communication about the QMS. Processes for internal and external communication need to be established within the QMS. The key elements of Communication that an organization must establish are

  • what needs to be communicated.
  • when it needs to be communicated?
  • how it should be done?
  • who needs to receive the communication? and
  • who will communicate?

It should be noted here that any communication outputs should be consistent with related information and content generated by the QMS for the sake of consistency. This is a straightforward clause and is simply about effectively communicating to all those within the organization and those affected by it. Internal communications  can include briefings to staff on:

  • new policies;
  •  new or amended objectives;
  •  new or  amended strategies;
  • new clients;
  • new or amended technology;
  • new products;
  • issues with suppliers;
  •  anything that will have an impact on them.

Designate a person responsible for updates may be the department head.

To understand the requirements and other external organizations throughout contract execution and product realization, the organization must determine and implement a process for communicating with the customers and other external organizations. The communication process must address the execution of inquiries, contracts, or order handling and amendments, feedback and customer complaints. The organization must also provide product information, including product nonconformities identified after delivery to the customer. When it’s required by contract, the organization must provide information required by product quality plans and subsequent changes to those plans. An organization may choose to communicate with other interested parties, but the requirements under 4.1.5.2 were targeted and mandated to occur between the manufacturer and the operator (customer). It was also intended to go from manufacture to affected suppliers. External communication is to manage risk that occurs throughout the execution of the contract. Many will do this upfront, but this occurs during tendering, contract review, and execution.

4.2 Management Responsibility

4.2.1 General

Top management must show leadership and dedication to setting up, implementing, maintaining, and enhancing the quality management system by endorsing the creation of quality objectives at relevant functions and levels within the organization. Top management must allocate the necessary resources for the quality management system. These resources can encompass human resources, specialized skills, organizational infrastructure, financial assets, and technology. Top management must involve and back personnel in implementing and sustaining the quality management system and designating responsibilities and authorities to ensure that processes achieve intended outcomes.

This section focuses more on the roles and responsibilities of management and top management. This section focuses more on the roles and responsibilities of management and top management Top management must ensure essential resources are available necessary for establishing, implementing, maintaining, and improving the quality management system. Resources can include human resources and specialized skills, organizational infrastructure, financial resources, and technology. The responsibility of management within the organization is to provide evidence of its commitment to the development and implementation of the quality management system. Management continually improves its effectiveness by ensuring that quality objectives are established including key performance indicators for use in data analysis. The management must conduct management reviews.

Responsibilities of Top Management in API Q1 standard

  1. Approval of Quality policy
  2. Review of Quality policy
  3. Approval of Quality objectives
  4. Availability of Resources
  5. Appointment of Management Representative
  6. taking reports from the Management representative on the performance of the quality management system
  7. Review and approve the output of Management Review

Responsibilities of Management in API Q1 standard

  1. Establishment of quality objectives at relevant functions and levels
  2. criteria and methods needed for the operation and control of all quality management system processes are determined, managed, and effective
  3. planning of the quality management system is carried out to meet the requirements of this specification.
  4. ensure that appropriate communication processes are established
  5. the effectiveness of the quality management system is communicated
  6. provide evidence of its commitment to the development and implementation of the quality management system
  7. Review of the Organization’s Quality Management System

4.2.2 Responsibility and Authority

The duties, powers, and responsibilities of personnel within the organization’s quality management system must be clearly outlined, documented, and communicated across the organization.

Responsibilities, authorities, and accountabilities of personnel within the scope of this document shall be defined, documented, and communicated throughout the organization. The organization must ensure that responsibilities are allocated across the organization to maintain the management system to make sure what is supposed to happen is happening. While allocating Roles, Responsibilities, and authorities, the organization must remember the customer at all times the outcome of the business processes, and how they can be improved. Remembering to update the system as and when you change how you work or the intended process is amended. The organization must define job roles before recruitment, allocate job descriptions to personnel, and link this to the processes within the business. For eg, A sales administrator might be expected to have 12 months of experience in writing quotations. When they join there would be a period of training and reinforcing this through a written job description. The output would be a more senior colleague reviewing quotes, confirming they are correct, and ensuring that the customer is being quoted for what they asked for. If a form or process is amended along the way advise the sales administrator and ensure the new versions are applied.

4.2.3 Management Representative

Top management must appoint and retain a member of the organization’s management who, regardless of other duties, holds responsibility and authority that involves guaranteeing compliance of the quality management system with the requirements of this specification. Establishing, implementing, and maintaining processes necessary for the quality management system. Providing reports to top management regarding the performance of the quality management system and any areas requiring improvement. Initiating actions to rectify nonconformities. Ensuring the promotion of awareness of customer requirements throughout the organization.

Management Representatives must be appointed by the Top management. Management Representative must be a member of the organization’s management. The Top management must always maintain the Management Representative. Irrespective of the other responsibilities the Management Representative may have, He/She shall also have the responsibility and authority to ensure that processes needed for the quality management system are established, implemented, and maintained. Report to top management on the performance of the quality management system.Report for any need for improvements. Ensuring of initiation of action(s) to minimize the likelihood of the occurrence of nonconformities and ensuring the promotion of awareness of customer requirements throughout the organization. The management representative ensures that the QMS processes are established, implemented, and maintained. This may involve review and planning of internal audits, discussion with process owners, or even review of the processes in person to ensure they are properly maintained. If this were not the responsibility of the management representative, then it would be a responsibility distributed among the process owners, and when this happens no one has the responsibility at all. By having a focal point for the overall processes, the management representative can not only ensure that each process is functioning, but that the interaction of the processes is maintained. By doing this, the interactions can then start to be optimized, because it is not always the case that optimization in one process is the best thing for the overall system.

The management representative has a second responsibility to report to top management on how well, or poorly, the QMS is performing. Identifying any needs for improvement to top management is also part of this responsibility. As has already been said, top management needs to be fully supportive of the Quality Management System implementation if it is going to provide true benefit to the company. For this to function, there needs to be a point of focus for top management to use when reviewing the resource needs of the QMS, and how best to support the improvement needed. Being the voice of the QMS for top management can be the critical factor in a QMS providing a return on investment for the company, or not.

The management rep will gather this sort of information from the monitoring and measurement activities in the organization, as well as the results of the internal audits, and when the company uses a management review meeting, this is the sort of information that is presented.

The last responsibility is to ensure that people are aware of customer requirements throughout the organization. Since one of the main thrusts of an ISO 9001 Quality Management System is customer satisfaction, all employees must understand what the customer needs, and how they can affect how well the company satisfies these needs. Customer focus is one of the main Seven Quality Management Principles behind ISO 9001 requirements, and as such needs to have an advocate in the company. By being the “voice of the customer” in the organization, the quality management representative can make great strides in how satisfied customers are. If the company implemented a quality management system to improve customer satisfaction, it only makes sense that someone is responsible for promoting the customer needs in the company, and the management rep is the leader of this initiative.

The quality management representative becomes the one name that the Auditing organization (like API) can call, or the customer can contact with complaints. It is often these optional responsibilities that are seen as the main role of the management rep, but in fact, these could be done by one of many other people without affecting the effectiveness and success of the QMS.

4.3 Organization Capability

4.3.1 Resources and Knowledge

4.3.1.1 Resources

The organization must identify and allocate the necessary resources to implement, maintain, and enhance the effectiveness of the quality management system.

The organization shall determine and provide the resources needed to implement, maintain, and improve the effectiveness of the requirements of the quality management system. The organization must have the resources it needs to ensure the effective operation of the QMS. Resources may include raw materials, infrastructure, finance, personnel, and IT, all of which can be either internally or externally provided. The organization must have a clear understanding of:

  • what an organization has in-house and whether this is sufficient/fit for purpose to achieve its goals and objectives.
  • what additional support might be needed externally?

For example, Specialist skills are better outsourced due to the size of the organization (e.g. security screening, health, and safety advice).

4.3.1.2 Knowledge

The organization must identify the expertise required to sustain the operation of its processes and ensure the consistent conformity of its products. This knowledge should be preserved and accessible at the organization’s discretion. Knowledge may be gained through experience, study, training, lessons learned, best practices, or other means.

To identify the expertise required to sustain operations and ensure consistent product conformity while preserving and making knowledge accessible, the organization must identify critical areas of expertise required for sustaining operations and ensuring product conformity. Document this knowledge systematically, including key processes, procedures, best practices, and lessons learned. Map out the expertise needed across various roles and functions within the organization. This involves identifying specific skills, qualifications, experience levels, and certifications required for each role involved in sustaining operations and ensuring product conformity. Establish a knowledge management system to store, organize, and make knowledge accessible within the organization. This system could include a combination of databases, intranet portals, wikis, document repositories, and collaboration tools. Implement access controls and permissions within the knowledge management system to ensure that sensitive information is protected and accessible only to authorized personnel as per the organization’s discretion. This may involve role-based access control mechanisms. Encourage continuous learning and development among employees to acquire and enhance the required expertise. Provide training programs, workshops, seminars, and access to educational resources to support ongoing skill development. Facilitate knowledge transfer mechanisms such as mentorship programs, cross-functional training sessions, job rotations, and communities of practice. These initiatives help disseminate expertise among employees and ensure continuity in operations. Regularly update and review the documented knowledge to ensure its relevance and accuracy. Encourage employees to contribute their insights, experiences, and lessons learned to enrich the knowledge base. Identify potential risks associated with knowledge loss or expertise gaps and develop contingency plans to mitigate these risks. This may involve succession planning, knowledge retention strategies, and cross-training initiatives. Establish feedback mechanisms to gather input from employees regarding the effectiveness of knowledge management processes and identify areas for improvement. Ensure that knowledge management practices comply with relevant regulations, standards, and quality assurance requirements. Regular audits and assessments can help verify adherence to these standards. By implementing these strategies, the organization can effectively identify, preserve, and make accessible the expertise required to sustain operations and ensure consistent product conformity while safeguarding sensitive information as per its discretion.

4.3.2           Human Resources

4.3.2.1        Personnel Competence

Personnel involved in the organization’s quality management system responsibilities must be competent. The organization should uphold a documented procedure concerning personnel competence. This procedure should cover:

  1. Identifying and documenting required competencies.
  2. Identifying necessary education, training, experience, or other actions to attain competence.
  3. Evaluating the effectiveness of measures taken to acquire competencies.
  4. Establishing criteria and methods for assessing, maintaining, and re-assessing competencies.
  5. Designating personnel responsible for assessing competency.

Records of personnel competence must be retained.

In the Four Levels of Learning In adult learning, there are four stages of learning to reach mastery. Three of the four have been incorporated into the term competent in API Spec Q1, 10th edition. The organization shall establish a documented procedure for determining the competency of its employees and other personnel. The procedure must also identify training requirements or other actions to achieve the necessary competency of these employees and other personnel. The procedure must also determine and document the effectiveness of the training or other actions taken toward the achievement of required competency. Personnel shall be competent based on the appropriate education, training, skills, and experience needed to meet product and customer requirements. Evidence of the determination of competence of personnel shall be recorded and maintained.

The organization needs to determine the necessary competence of its employees and ensure those employees are competent based on appropriate education, training, and experience. The organization must have a process for determining the necessary competence and achieving it through training or other means. Determining competence is a necessity in any organization. Working out on the skills your team has the skills they don’t yet have and the skills they will need to achieve the company’s objectives. For example to achieve the objective of “Increase in sales”, you need to improve the competency of your sales team by training them.

4.3.2.2 Training

The organization must establish and uphold a training procedure. The organization must identify the content and frequency of necessary training. The organization must provide training on the quality management system. It must provide job-specific training, including raising awareness among personnel about the significance of their tasks and their contribution to achieving the organization’s quality objectives. It must offer customer-specified or customer-provided training when necessary. It must assess the effectiveness of the training. It must document the required training records. Records of personnel training must be retained.

The organization must provide quality management system training and job training. They must also ensure that customer-specified training and/or customer-provided training, when required, is included in the training program. They must ensure that the frequency and content of training are identified. They must ensure that their personnel are aware of the relevance and importance of their activities and how they contribute to the achievement of quality objectives and maintain appropriate records of education, training, skills, and experience. The content of awareness training may include items covered in induction training, specific training, toolbox talks or any other quality, environmental, or health and safety issues that affect several employees in the workplace. You should seek evidence to confirm that this requirement has been applied by your organization to ensure that the people who need to be made aware now include all the people who work on your organization’s behalf that affect the conformity of your organization’s management system or products. You ensure that these people are aware of:

  1. The quality policies;
  2. Relevant quality objectives;
  3. Their contribution to the effectiveness of the management system;
  4. Benefits of improved performance;
  5. The implications of not conforming to management system requirements.

This also is to take into account all legal and other requirements that it subscribes to or is required to comply with. Not having an understanding of these “legal and other applicable requirements” not only puts employees at risk, but it has a potential negative impact on organizational processes and the environment,

Awareness training

The awareness training does not need to follow the format of long classroom sessions. Training techniques can include short training segments supplemented with videos and hands-on demonstrations that address key elements of the management system. Other methods to promote and reinforce awareness training sessions include communication via electronic bulletin boards, posters, newsletters and informational meetings. The requirements for general awareness training apply to all employees including those whose work may cause impacts on customer/product or service requirements. Awareness training is intended to provide an overview of the organization’s policy, objectives and targets, and overall management system. Your organization must ‘establish and maintain procedures to make its employees and members at each relevant function and level aware of’:

  1. The importance of conformance with the policy and the management system procedures and requirements;
  2. The actual and the potentially significant impacts and risks of the activities, products, and/or services;
  3. The benefits of improved personal performance;
  4. The employees’ roles and responsibilities in achieving conformance with policies and procedures;
  5. The employees’ roles and responsibilities towards emergency preparedness and response;
  6. The potential consequences of departure from specified operating procedures.

The awareness training materials may also include additional elements that address:

  1. The organization’s objectives and targets;
  2. The employees’ actions to minimize/eliminate impacts and risks and how they can contribute;
  3. The importance of compliance with operational and regulatory requirements;
  4. The overall improvement of the management system performance and the potential financial return;
  5. The importance to interested parties.

Induction training

General awareness training should be undertaken by task demands. All recruits (workers, contractors and temporary staff) must receive induction briefings and periodic Quality management system awareness training appropriate to the duration of their responsibilities to ensure they are aware of the importance of ethical behaviour e.g. codes of conduct, internal management, working relationships, fair treatment, confidential reporting mechanisms, protecting anonymity, no-blame-culture, awareness campaigns, notice boards, posters, training programs including:

  • Core values and policies;
  • Company overview;
  • History of the company;
  • The people and structure;
  • Contract of employment;
  • Induction pack;
  • Health, safety and environmental briefing.

The induction record should be completed, signed by each participant and sent to the Human Resources Manager.

4.3.3  Work Environment

The organization must identify, furnish, oversee, and sustain the work environment necessary to ensure product conformity. This work environment encompasses Facilities, workspaces, and related utilities; Process equipment, including both hardware and software; Ancillary services (e.g., transportation, communication, information systems); and Work conditions, covering physical, environmental, or other influencing factors.

The organization must determine, provide, manage, and maintain the work environment needed to achieve conformity applicable to the manufacture of the product. Work environment includes buildings, workspace, and associated utilities,  process equipment and its maintenance (both hardware and software), supporting services (e.g. transport, communication, information systems); and conditions under which work is performed such as physical, environmental, or other factors. The environment for the operation of processes clause ensures that the organization determines, provides, and maintains an environment necessary for the operation of its processes and to achieve conformity. The term environment refers to the work environment and is used to describe the set of conditions in which employees perform their work and under which products and services are produced. Conditions can include physical, social, psychological, and environmental factors (such as temperature, lighting, recognition schemes, social and occupational stress, ergonomics, etc). It can also relate to conditions on how work is done (complex, repetitive, creative, interactive, team, etc.) in work processes and procedures. The environment that you work in may include the following:

  • Equality Opportunities, whistle-blowing, the anti-bullying policy.
  • Violence at work, counselling support, lone working.
  • Office-based risk assessment, space, noise levels.

The manufacturer (organization) is responsible for identifying and knowing the different types of servicing and SRP that they will produce or support. They are also responsible for ensuring that the work environment needed to meet those requirements has been provided, is managed, and maintained to ensure conformity requirements are met. This includes the organization’s facilities, workspace, utilities, process equipment, and physical and environmental conditions where servicing and SRP are produced. The work environment includes the organization’s facilities,  mobile work environments, and the well sites where services and SRP are utilized. Besides understanding what is considered the work environment, the organization also needs to understand the servicing and product conformity requirements.

4.4 Documentation Requirements

4.4.1 General

The documentation of the quality management system should consist of:

  1. An outline of the quality management system’s scope, defining the products covered and providing reasons for any exclusions;
  2. Declarations of the quality policy and quality objectives;
  3. Listing legal and other relevant requirements that the organization must adhere to to ensure product conformity;
  4. Explanation of how the quality management system fulfils each requirement outlined in this specification;
  5. Identification of processes requiring validation; and
  6. Procedures, documents, and records necessary for planning, executing, and controlling processes, as well as for meeting specified requirements.

Traditionally, some of this documentation has been incorporated into a quality manual, but it can take various formats and may be presented as either a single document or multiple documents.

The quality management system documentation must include statements of Quality policy, statements of Quality objectives and. documented procedures. It must also include documents and records required for effective planning, operation, and control of its processes and compliance with specified requirements. Legal and other applicable requirements needed for product conformity must also be identified. The quality manual describes the quality management system by the stated quality policy and objectives, while the procedures describe the processes and activities required to implement the quality management system. Organizations can address the requirements of the standards by preparing a management system manual and by implementing procedures to control processes. The quality manual, the policies, processes and procedures are all about what the organization has decided is important to ensure they can provide the services and products that continually meet customer requirements, deliver satisfaction and for the business to meet its targets and objectives. The quality manual provides the scope of the management system. Also, the manual contains an overview of management’s and employee responsibilities as well as conformity statements applicable to the Q1 causes that are contained and supported by your management system. The management system processes and procedures provide detailed requirements for each of your key processes with the intent to specify who does what, when, where, how the process, action, or task is performed, and what documentation is used to verify that all required the quality-related activities have been executed as required.

4.4.2 Procedures

Every procedure mandated by this specification must outline the organization’s approach to conducting an activity. These procedures must be documented, put into action, and upheld to ensure ongoing appropriateness. One procedure can encompass the requirements for one or more documented procedures. Likewise, multiple procedures can fulfil any requirement for a documented procedure.

All procedures mentioned in the API Q1 standard must be established, documented, implemented, and maintained for continued suitability. One or more procedures can be contained in a single document or the requirement of a documented procedure can be contained in one or more documents.

Documented Procedure Required by API Q1 standard

  1. defining personnel competency and identifying training requirements
  2. identification, distribution, and control of documents
  3. integration of external specification requirements into the product realization process and any other affected processes
  4. the identification, collection, storage, protection, retrieval, retention time, and disposition of records
  5. review of requirements related to the provision of products and required servicing (Contract Review)
  6. identify and control risks associated with impact on delivery and quality of product.
  7. plan and control the design and development of the product.
  8. contingency planning
  9. procedure to ensure that purchased products or outsourced activities conform to specified requirements.
  10. the verification or other activities necessary for ensuring that purchased products or activities meet specified purchase requirements
  11. controls associated with the production of products.
  12. controls associated with the servicing
  13. Validation of Processes for Production and Servicing
  14. identification and traceability
  15. product inspection and/or test status
  16. Customer-supplied Property
  17. Preservation of Product
  18. Inspection and Testing
  19. preventive maintenance of equipment
  20. Calibration and Maintenance of testing, measurement, and monitoring equipment.
  21. release of product
  22. Control of non-conforming product
  23. customer satisfaction
  24. Internal audit
  25. Analysis of data
  26. correct nonconformities and to take corrective actions,

4.4.3 Control of Internal Documents

The organization must maintain a documented procedure for managing internal documents required by the quality management system and this specification, including revisions, translations, and updates. This procedure must cover:

  1. Responsibilities for approval and re-approval;
  2. Review and approval for adequacy before issuance and use;
  3. Periodic reviews for ongoing suitability and necessary revisions;
  4. Identification of changes and current revision status;
  5. Ensuring legibility and proper identification of documents;
  6. Availability of documents at locations where activities are carried out.

Obsolete documents must be removed from all points of distribution or use, or appropriately marked to prevent unintended usage if retained for any purpose. Procedures, work instructions, and forms mandated by the quality management system must be controlled.

The organization must establish a documented procedure for the identification, distribution, and control of its documents or those of external origin. The procedure shall specify responsibilities for approval and re-approval of the documents. It must identify the controls needed to ensure that the documents are reviewed and approved for adequacy before issue and use. It must identify changes and revision status. Document must remain legible and readily identifiable, and are available where the activity is being performed. Documents of external origin must be controlled to ensure that the relevant versions are used and maintained. The organization must ensure against unintended use of obsolete documents and remove them from all points of issue or use, or otherwise identified if they are retained for any purpose. All Procedures, work instructions, and forms must be controlled. The organization must control the documents required by its QMS. A suitable process must be implemented to define the controls needed to; approve, review, update, identify changes, identify revision status and provide access. The procedure should define the scope, purpose, method and responsibilities required to implement these parameters. To comply with the document requirements, all personnel must understand what types of information should be controlled and more importantly, how this control should be exercised. To get the most out of your procedure it must communicated to ensure that staff and other users of the documentation information understand what they must do to manage that information effectively and efficiently. Demonstrate the organization’s arrangements for controlling documents required by API Q1 and your organization’s own requirements, including

  • Availability e.g. document accessibility (hard copy, electronic media), readily available at the point of use;
  • Suitability e.g. format, media suitable to the environment, ease of understanding, language, interpretation;
  • Protection e.g. document authentication, document markings (official, secret, restricted, confidential, private, sensitive, classified, unclassified), access controls (individual, role-specific),
  • Physical security (master documents, server rooms, libraries) IT security (User ID, password, servers, download, back up, encryption, ‘read-only’, ‘read/write’), protection from corruption and unintended alterations.
  • Demonstrate the organization’s arrangements for document retention e.g. organization/legal/contractual retention periods, storage, preservation, back up, retention of knowledge, disposal, obsolescence e.g. withdrawal, replacement, legacy archive and suitable identification (‘for information only’, ‘not to be used after….’, ‘uncontrolled copy’, ‘for reference purposes only’, etc.

Ensure your organization protects electronic data, e.g. security policy, system access profiles, password rules, storage and backup policy including protection from loss, unauthorized changes, unintended alteration, corruption, and physical damage. Access can imply a decision regarding the permission to view the documented information only, or the permission and authority to view and change the document.

4.4.4 Control and Use of External Documents

The organization must uphold a documented procedure for managing documents from external sources necessary for product realization and use, including API or other external specifications. This procedure should cover:

  1. Identifying and documenting the necessary external documents;
  2. Managing access to and distribution of required documents, including relevant versions;
  3. Incorporating requirements from external documents into product realization and any affected processes;
  4. Establishing a process for identifying changes to required documents, such as addenda, errata, and updates;
  5. Assessing the impact of changes;
  6. Incorporating relevant changes.

Normative references specified within API products or other external specifications, essential during product realization, may also be regarded as external documents.

The organization must establish a documented procedure for the integration of the requirements coming from external specifications such as API products including addenda, errata, and updates into the product realization process and any other affected processes when such requirements are used in the design or manufacture of the product. External documents are the documents relevant to the quality management system (QMS) and issued by an external entity. Examples of those issuers can be customers, suppliers, legislators, regulators, standardization bodies, or business partners. Documents of external origin relevant to the QMS can be, for example, Product Specifications, Logistics Specifications, Material Safety Data Sheets, Legislation, Permits, Standards, Platform Rules, or Work Instructions. Organizations must determine what relevant documents of external origin are used in the design and manufacture of the products. The organization must ensure that external document is still updated. If the document was changed, what are the implications on the specification of the product? Do the changes in the document imply changes in the manufacturing process? The procedure must include:

  • what are the relevant documents of external origin
  • who is responsible for checking, with what frequency,
  • who is going to do what when there are changes or new documents;
  • get new versions or new document
  • update register
  • distribute new versions or new document
  • check if it is applicable
  • plan changes
  • implement changes
  • confirm that changes were implemented

4.5 Control of Records

Records, including those originating from outsourced activities, must be established and managed to demonstrate conformity to requirements and the organization’s quality management system. The organization must maintain a documented procedure outlining the controls and responsibilities for managing records. This procedure should cover:

  1. Identifying records;
  2. Collecting records;
  3. Ensuring legibility of records;
  4. Correcting records when necessary;
  5. Storing records securely;
  6. Safeguarding records from unintended alteration, damage, or loss;
  7. Retrieving records as needed;
  8. Determining retention periods;
  9. Disposing of records when appropriate.

Records must be retained for a minimum of ten years or as required by customer, legal, and other relevant requirements, whichever is longer.

The organization must establish a documented procedure for control of Records. The procedure must identify the controls and responsibilities needed for the identification, collection, storage, protection, retrieval, retention time, and disposition of records. Records should remain legible, identifiable, and retrievable. The retention of records should be based on customer, legal, and other applicable requirements or 5 years whichever is more. The records including those of outsourced processes must be e established and controlled to provide evidence of conformity to requirements and the organization’s quality management system.

Records Required by API Q1 standard

  1. records of education, training, skills, and experience
  2. records to ensure the effective planning, operation, and control of its processes and compliance with specified requirements
  3. record of customer requirements, when the customer provides no documented statement of requirements
  4. Records of contract review including resulting actions
  5. records needed to provide evidence that the product realization processes meet requirements (for eg inspection record)
  6. Records of risk assessment and management including actions taken
  7. Contingency plan
  8. Records of design inputs
  9. Records of design outputs
  10. Records of design review
  11. Records of design and development verification and the final review
  12. Records of the design and development validation, approval, and any necessary actions
  13. Records of design and development changes,
  14. Records of supplier evaluation
  15. Records of outsourced activities
  16. Records of verification of Purchased Products or Activities
  17. Records of product realization plan
  18. records of review/verification, validation, monitoring, measurement, inspection, and test activities, including criteria for product acceptance
  19. Records of validation of Processes for Production and Servicing
  20. Records of identification and traceability
  21. Records for the control and disposition of customer-supplied property
  22. Records of the results of assessments of products kept in storage
  23. Records of required inspection and testing
  24. Records of preventive maintenance
  25. Records of assessment of the validity of previous measurements and actions to be taken on the equipment and product, when the equipment is found to be out of calibration.
  26. Records of the results of calibration and verification
  27. Records shall be maintained to enable identification of the individual releasing the product
  28. Records of notification to customers of products not conforming to DAC or contract requirements
  29. Records of the nature of nonconformities of non-conforming products and any subsequent actions taken
  30. Records of MOC activities
  31. Records of customer satisfaction
  32. Records of internal audit
  33. Records of the Corrective Action
  34. Records of Management Review

ISO 29001:2020 Petroleum,Petrochemical and Natural gas industries Sector specific Quality Management System

Understanding ISO 29001:2022 Quality Management System.

ISO/TS 29001, as an international standard, is the result of the collaboration between ISO and the international oil and gas industry, which is primarily focused on the oil and gas supply chain. It specifies the Quality Management Systems requirements for the layout, establishment, production, and implementation of products and services for the petroleum, petrochemical and natural gas industries.. This standard is a supplement to ISO 9001:2015. The supplementary requirements and guidance to ISO 9001:2015 have been developed to manage supply chain risks and opportunities associated with the petroleum, petrochemical and natural gas industries and to provide a framework for aligning requirements with complementary standards employed within the industries. Since 29001 is also based on ISO 9001, which contains requirements on error prevention, reduction of variation and waste management from the service provider. These requirements have been written separately in order to ensure clarity and perceptibility. ISO 29001 is suitable for all companies within the oil and gas industry as it was developed to ensure quality and improvement within this particular sector. ISO 29001 provides the basis for continuous improvement by emphasizing the prevention of errors and reducing deviations and wastes in the supply chain and service providers. This standard, along with the specific requirements of the customer, defines the basic requirements of the quality management system for those who have accepted this certificate. The Oil and gas industry is one of the critical industries that need to follow heavy regulations and scrutiny. Even a single failure could mean disaster for the environment in addition to the harms and impacts on the other connected sectors of the industry. The industry needs a quality management system with an emphasis on compliance that can provide them comprehensive insights into processes and product quality to identify the scope of improvements going forward. ISO 29001 meets the specific needs of the oil & gas industry by developing a quality management system that, with a view to continuous improvement, seeks several benefits, including:

  • preventing and/or managing operational risks
  • business continuity in the face of adverse situations (e.g. accident/downtime of sections of a plant or service disruptions)
  • reducing costs
  • improving staff safety and environmental protection
  • reducing product waste and inefficient use of the supply chain.

All ISO management system standards are subject to a regular review under the rules by which they are written. Following a substantial user survey the committee decided that a review was appropriate and created the following objectives to maintain its relevance in today’s marketplace:

  • Integrate with other management systems
  • Provide an integrated approach to organizational management
  • Provide a consistent foundation for the next 10 years
  • Reflect the increasingly complex environments in which organizations’ operate
  • Ensure the new standard reflects the needs of all potential user groups
  • Enhance an organization’s ability to satisfy its customers

The structure is based on the mandate that Annex SL from the ISO Directives is applied to management system standards. The clause structure in ISO 9001:2015 is being aligned with other management system standards. The structure is to provide a presentation of requirements. It is not a model for the document for documenting the organization’s policies, objectives, and processes. There is no requirement for the structure of an organization’s quality management system documentation to mirror that of this International Standard.

 Structure of ISO 29001:2020

Since ISO 29001:2020 is based on ISO 9001:2015 it has the same structure as that of ISO 9001:2015. ISO 29001:2022 like ISO 9001:2020 is based on Annex SL – the high-level structure. This is a common framework for all ISO management systems. This helps to keep consistency, align different management system standards, offer matching sub-clauses against the top-level structure, and apply common language across all standards. It becomes easier for organizations to incorporate their QMS into core business processes and get more involvement from senior management. The Plan-Do-Check-Act (PDCA) cycle can be applied to all processes and to the quality management system as a whole. SO 29001:2020, based on Annex SL, has 10 sections four of which also approximate to “PLAN, DO, CHECK, ACT.” All management system standards will have this common structure. Here is the structure:

Clause 1.Scope

This section describes the scope of the management system standard and will be unique to the individual standard. Clause 1 details the scope of the standard

Clause 2. Normative References

This section references other relevant standards, which are indispensable for the application of the document and will also be unique.ISO 9000, Quality Management System – Fundamental, and vocabulary is referenced and provides valuable guidance.

Clause 3. Terms and Definitions

Section three contains definitions, and while some of these are common terms related to Annex SL, other definitions will be unique to the management system standard. All the terms and definitions are contained in ISO 9000:2015 – Quality Management – Fundamentals and vocabulary.

Some additional Terms not available on ISO 9001:2015 but included in ISO 29001:2020 are

3.1 quality specification level (QSL)
level defining the extent of control activities, typically including testing, inspection, verification and validation, undertaken by the provider to demonstrate conformance with requirements based on the determination of operational risk and/or obligations

3.2 Competence

3.2.1 competence catalogue
hierarchical structured list of the competences required to perform a task

3.2.2 competence profile
skills and behaviour, each specified at a level of proficiency, required to perform a role or activity in line with the associated risk or opportunity


3.2.3 proficiency level
level of ability and behaviour attributes within a specific skill

3.3 inspection and test plan
tabular presentation of a quality plan, typically used for process or product applications, to define the specific sequence of operational activities, instructions, acceptance criteria, information to be maintained and retained, and associated provider, customer and independent conformity assessment activities

Clause 4: Context of the Organization

4.1 Understanding the organization and its context.

This requirement requires a greater union between the QMS and wider business planning activities. it requires organizations to ascertain, monitor, and review both internal and external issues that are relevant to its purpose and strategic direction, and have the ability to impact the QMS and its intended results.  The organization should determine external and internal issues for the organization relevant to its purpose, strategic planning, and which affect the organization’s ability to achieve its objectives. The Organization should monitor and review the information about external and internal issues. Management Review required the monitoring of external and internal issues. The organization must consider issues related to values, cultural knowledge, and performance of the organization for the understanding of internal issues. The organization must consider issues related to arising from legal, technological, competitive, market, cultural, social, and economic environments, whether international, national, regional, or local for the understanding of external context. The internal context may include, but is not limited to:

  • Product and service offerings
  • Governance, organizational structure, roles, and accountability.
  • Regulatory requirements
  • Policies and goals, and the strategies that are in place to achieve them.
  • Assets like facilities, property, equipment, and technology
  • Capabilities understood in terms of resources and knowledge like capital, time, people, processes, systems, and technologies.
  • Information systems, information flows, and decision-making processes (both formal and informal).
  • Relationships of the staff/volunteers/members and the perceptions and values of their internal stakeholders including suppliers and partners.
  • Organization’s culture.
  • Standards, guidelines, and models adopted by the organization and
  • Form and extent of the organization’s contractual relationships.

The external context’s micro-environment consists of the organization’s immediate operations and how they affect its performance and decision-making. Some of the micro-environmental context factors

  • Customers – Organizations must attract and retain customers by offering products services that meet their needs along with providing excellent customer service

  • Employees/Members/Volunteers – There must be the availability of people with the motivation to remain as contributing members of the organization and develop the skills necessary to provide a competitive edge

  • Suppliers – Suppliers provide organizations with the resources they need to carry out their activities. If a supplier provides bad service, this affects the way the organization operates. Close supplier relationships are an effective way to remain competitive and secure the resources needed

  • Investors – All organizations require investment to grow. They may borrow the money from a bank or have people invest in their work. Relationships with investors need to be managed carefully as problems can detrimentally affect the long term success of the organization

  • Media – Positive media attention can bring success to the organization by maintaining its reputational strength. Managing the media (including the presence in social media) is a challenge.

  • Competitors – Members of the organization need to have a sense of belonging. Can the organization offer benefits that are better than those offered by the competitors? Is there a strong value proposition? Competitor analysis and monitoring are crucial if an organization is to maintain or improve its position in the competitive landscape of the community. The organization must always be aware of its competitor’s activities. The landscape can change quickly.

To be read along with clause 4.1 of ISO 9001 Please click hear for clause 4.1 of ISO 9001. The organization must have records as an evidence of its understanding of its context, The records must identify external and internal issues. There must be records of monitoring and review of these external and internal issues.The record must identify if the issues have positive or negative factors or their condition for consideration. The record must also identify how the external issues are arising , whether it is arising from legal, technological, competitive, market, cultural, social and economic environments, whether international, national, regional or local. The record must also identify how the internal issues are arising , whether it is related to values, culture, knowledge and performance of the organization.

Rationale for this supplement as per ISO : Organizational context constantly evolves and informs the ongoing development of objectives, strategies and the quality management system. It is considered essential that organizations retain documented information of their understanding of the organization and its context as input to their planning and performance evaluation processes and as objective evidence for internal and interested party conformity assessment activities.

4.2 Understanding the needs and expectations of interested parties.

A broadening of scope beyond just customers. Requires the organization to determine “the relevant requirements” of “relevant interested parties” e.g. a person or organization that can affect, be affected by, or perceive themselves to be affected by a decision or activity.

The organization shall determine relevant interested parties and the requirements of relevant interested parties. Interested parties include Customers, Partners, Persons in the organization, External providers. Relevant interested parties to be considered are those that potentially could impact the organization’s ability to provide products and services that meet requirements. Monitor and review information related to interested parties and relevant requirements. Management Review requires the monitoring of relevant interested parties.

To be read along with clause 4.2 of ISO 9001 Please click hear for clause 4.2 of ISO 9001.The organization must have records as an evidence that it understood the needs and expectation of interested parties. There must be records of the interested parties relevant to QMS, their requirements relevant to QMS. The record must also include monitor and review of these interested parties and their relevant requirements.

Rationale for this supplement as per ISO: The needs and expectations of stakeholders (interested parties) constantly change either through changes in organizational context and objectives or changing social, customer or regulatory expectations and obligations. It is considered essential that organizations retain documented information of their understanding of stakeholder expectations and obligations as input to their planning and performance evaluation processes and as objective evidence for internal and stakeholder conformity assessment activities. NOTE Normally, ‘stakeholder’ is the preferred term in the petroleum, petrochemical and natural gas industries instead of ‘interested party’.

4.3 Determining the scope of the QMS.

The scope statement must state the products and services covered. The organization must establish the scope of the quality management system by determining the boundaries and applicability of the quality management system. While determining the scope the organization must consider the internal and external issues determined in 4.1., the requirements of relevant interested parties in 4.2. and the products and services of the organization.

Requirements that can be applied by the organization shall be applied. Requirements that cannot be applied cannot affect the organization’s ability to provide products and services that meet requirements. The organization must maintain scope as documented information stating the Products and services covered by the QMS and any Justification where a requirement cannot be applied. Any interested party which is not relevant to the quality management system need not be considered and similarly, any requirement of the interested party need not be considered. Determining what is relevant or not relevant is dependent on whether or not it has an impact on the organization’s ability to consistently provide products and services that meet customer and applicable statutory and regulatory requirements or the organization’s aim to enhance customer satisfaction. The organization can decide to determine additional needs and expectations that will meet its quality objectives. However, it is at the organization’s discretion whether or not to accept additional requirements to satisfy interested parties beyond what is required by this Standard.

 Applicability

The focus is on the application and not just the exclusions. There are no limits to which clauses where the application can be determined. Justification will be required as documented information to ensure that limited application does not affect the organization’s ability to provide for the provision of products and services. The application of requirements may vary. Where a requirement can be applied within the scope of its quality management system, the organization cannot decide that it is not applicable. Where a requirement cannot be applied (for example where the relevant process is not carried out) the organization can determine that the requirement is not applicable. However, this non-applicability cannot be allowed to result in failure to achieve conformity of products and services or to meet the organization’s aim to enhance customer satisfaction. A manufacturing organization that does not have any monitoring and measuring resources could determine requirements in 7.1.5 do not apply. Organizations that build from a customer-provided design could determine requirements for design in 8.3 do not apply. Organizations could not determine that requirements such as competence are not applicable since this directly affects the ability to provide a product that meets requirements.

To be read along with clause 4.3 of ISO 9001 Please click hear for clause 4.3 of ISO 9001.If any of the interested parties as mentioned in clause 4.2 makes a request, then the organization can advice the interested parties of any requirements of ISO 29001:2020 which is not applicable to the scope of its quality management system

Rationale for this supplement as per ISO : Requirement formalizes the principle that when required by regulatory obligation or contractual condition organizations shall inform stakeholders when requirements in this document and as such the organization’s quality management system is not considered within the scope of activities.

4.4 Quality Management System and its processes.

This specifies the number of factors to be considered when planning the processes that make up the QMS. The standard requires the organization to establish a process-based management system. This is required to be maintained and continually improved. The clause sets out high-level requirements for the design of such a process-based management system.  These processes are integral and also there are support processes that underpin the operation of the entire QMS.

To be read along with clause 4.4 of ISO 9001 Please click hear for clause 4.4 of ISO 9001.The Organization must define the extent of Documents including of procedure and records required to meet the requirement of relevant interested as mentioned in clause 4.2 and clause 4.3

Rationale for this supplement as per ISO : Requirement formalizes the principles that organizations shall clearly define the scope boundaries and exclusions of the quality management system and its processes and the associated extent of maintained and retained documented information

5. Leadership

5.1 Leadership and commitment.

Greater emphasis is placed on the role of top management. Requires top management to “demonstrate leadership and commitment”, and suggests that a more hands-on approach is expected. ISO 29001:2020 requires top management to be much more “hands-on” with respect to their QMS. Where the word “ensuring” is used in sub-clause 5.1.1, top management may still assign this task to others for completion. Where the words “promoting”, “taking”, “engaging” or “supporting” appear, these activities cannot be delegated and must be undertaken by top management themselves. Top management must:

  • have accountability for the effectiveness of their organization’s quality management system;
  • ensure that their organization’s quality policy and quality objectives are consistent with the organization’s overall strategic direction and the context in which the organization is operating;
  • work alongside their people in the organization in order to ensure that the quality objectives are achieved;
  • ensure that the quality policy is communicated, understood and applied across the organization;
  • make sure that the quality management system is achieving the results that are intended;
  • lead people to contribute to the effective operation of the system;
  • drive continual improvement and innovation and develop leadership in their managers.

The top management is required to ensure that:

  • the requirements set out in ISO 29001:2020 are met;
  • QMS processes are delivering their intended outcomes;
  • reporting on the operation of the QMS and identifying any opportunities for improvement is taking place;
  • a customer focus is promoted throughout the organization;
  • whenever changes to the QMS are planned and implemented, the integrity of the system is maintained.

Customer focus

The top management should ensure that the organization should have knowledge of the law and is aware of the customer’s expectations and is delivering. Knowing what can go wrong with what you are selling and providing and what opportunities you also have when you deliver this; opens doors, for example, to other work streams; They should be making sure that the customer is happy.  Understanding customer specifications/ needs. Ensure you know exactly what the customer wants and documenting this from the initial inquiry to commissioning paperwork.

To be read along with clause 5.1 of ISO 9001 Please click hear for clause 5.1 of ISO 9001.

Rationale for this supplement as per ISO

5.2  Policy.

Policy requirements are enhanced. A requirement is introduced that the quality policy is appropriate to the context of the organization and that it is applied throughout the organization. Write the policy to include:

  • making sure it reflects your business size, ethos and what you are trying to achieve;
  • how you will decide what you are going to achieve and how you will check this;
  • committing to doing it the right way (e.g. in line with standards and best practice);
  • committing to try to continually improve.

Tell everyone about it.

  • Making sure it is written.
  • Making sure people know it and understand it.
  • Giving it to people who have an interest in your business (e.g. clients/suppliers/manufacturers/staff).
  • Publishing it on your website.

The example includes written Quality policy, company induction, basic training, toolbox talks.

To be read along with clause 5.2 of ISO 9001 Please click hear for clause 5.2 of ISO 9001.

5.3 Organizational roles, responsibilities, and authorities.

The requirement for a Management representative is no longer specified. The duties previously assigned to that role may now be assigned to any role or split across several roles. The top Management must ensure that responsibilities are allocated across the organization to maintain the management system to make sure what is supposed to happen is happening. While allocating Roles, Responsibilities, and authorities, the organization must remember the customer at all times and the outcome of the business processes, and how they can be improved. Remembering to update the system as and when you change how you work or the intended process is amended. The organization must be defining job roles prior to recruitment, allocating job descriptions to personnel, and linking this to the processes within the business. For eg A sales administrator might be expected to have 12 months’ experience in writing quotations. When they join there would be a period of training and reinforcing this through a written job description. The output would be a more senior colleague reviewing quotes, confirming they are correct, and ensuring that the customer is being quoted for what they asked for. If a form or process is amended along the way advising the sales administrator and ensuring the new versions are applied.

To be read along with clause 5.3 of ISO 9001 Please click hear for clause 5.3 of ISO 9001.The organization must define the roles at all relevant function, levels and process. The organization must have a procedure for establishing the responsibilities and authorities to ensure that QMS conform to the requirement of the ISO 29001:2020 std, all process are delivery their intended output, promotion of customer focus through out the organization, integrity of QMS is maintained when changes to QMS is planned and implemented, and reporting the performance of QMS as well as the opportunities of improvement to the top Management . The organization must have record of these roles , and responsibilities and authorities of these roles.

Rationale for this supplement as per ISO : Requirements for defining roles and documented information for responsibilities and authorities related to these roles are added as these elements are considered essential to be documented, also in view of conformity assessment activities.

6.0 Planning

Risk-based Thinking

The main objectives of ISO 29001 are to provide confidence in the organization’s ability to consistently provide customers with conforming Products and services and to enhance customer satisfaction. The concept of “risk” in the context of ISO 29001 relates to the uncertainty in achieving these objectives. ISO 29001 incorporates risk-based thinking in its requirements for the establishment, implementation, maintenance, and continual improvement of the quality management system. Organizations may choose to implement a formal risk management program such as ISO 31000, ISO/TR 31004 and IEC 31010 provide guidance on risk management principles, framework and generic processes, and risk assessment techniques . In these ISO and IEC deliverables, risk includes opportunity. The concept of risk is built into the whole management system. Risk-based thinking is also part of the process approach.  Risk-based thinking can also help to identify opportunities. For risk-based thinking, the organization must understand any external and internal issues as given in clause 4 context of the organization. Risks and opportunities are determined in clause 6.1. Implementing Risk-based thinking also assures preventive action. One of the key purposes of a quality management system is to act as a preventive tool. ISO 9001:2015 does not have a separate clause titled preventive action. The concept of preventive action is controlled through risk-based thinking by managing risks and opportunities identified in clause 6.1

6.1 Actions to address risks and opportunities.

This sub-clause requires a risk-based approach. In addition to this clause, the reference to the terms ‘risk’ and ‘opportunity’ are made throughout the standard. Consider the issues determined in clause 4.1 and the needs and expectations of interested parties in clause 4.2 to determine your risk and opportunity. The organization should determine risks and opportunities to assure that that the quality management system can achieve its objective, prevent or reduce undesired effects, and for continual improvement. The organization shall plan actions to address risks and opportunities. The actions identified should be appropriate to its potential impact on the QMS. The action of risk and opportunities must be integrated and implemented into the QMS processes. The effectiveness of these actions must be evaluated.
Actions to address the risks – First, the organization should identify the risks and opportunities it wants to address. Then the organization must determine the severity of each risk and opportunity. Understanding the severity, the organization must plan action to address the risk and opportunity. This can be captured in the Risk plan. Plan how all the elements can come together,  and how it will be run, and a means of checking them, and that the plan is on track. Use risk methodologies to ensure that you apply things appropriately.  The greater the risk and the impact on the organization, the greater the control measures, planning, management, etc. If necessary, have a Plan B. Consider how an understood risk can be used in a positive way to look at other ways of doing things or other products.

To be read along with clause 6.1 of ISO 9001 Please click hear for clause 6.1 of ISO 9001.The organization must establish a procedure to support and demonstrate the establishment of process of management of risks and opportunities. The procedure must define the tool, technique and their application for the identification and identification of risk and opportunities, and also prevention and mitigation of risk. It must identify relevant interested parties, sources of risk and opportunity, areas of impacts, events and their causes, and their potential consequences, The procedure must also include analyses for potential risk and opportunity by determining its consequences and likelihood, evaluation of risk and opportunity and to develop controls for them, and application of appropriate risk treatments and opportunity realization plans. The organization must also have record as an evidence of support and demonstration of the management of risks and opportunities as per the process established.

Rationale for this supplement as per ISO: Requirements for processes for managing risks and opportunities are added in view of the (potential) high risk associated with operations in the petroleum, petrochemical and natural gas industries, including the supply chain which can contain several providers following a ‘cascading model’ (e.g. contractors and sub-contractors), and to align the activities with the risk management methodology as described in ISO 31000.

6.2 Quality objectives and planning to achieve them.

No quality plan can be complete without having measurable quality objectives. An objective should include a description of who is responsible, what is the target, when is it planned to be achieved. Progress must be monitored. Also, requires objectives to be set for relevant processes. Ensure that whatever objectives you implement are SMART

  • Specific
  • Measurable
  • Achievable
  • Realistic
  • Time-bound

Some  key rules are as follows:

  • Make sure they comply with the law and industry standards.
  • Make sure they conform with the products and services to make them better.
  • Monitor your objectives periodically to check what you are doing.
  • Tell the staff what they are and what you expect of them.
  • Updated when the management changes something.

Keep records of this. This should be included in the customer SLA and planning should be in place to ensure you can resource this response rate. An example could be Understanding the total number of planned maintenance, the number of reactive maintenance to ensure you calculate the appropriate levels of resources. Organizations need to clearly understand how these will be realized. For example, if your aim is to provide national coverage, how will this be achieved? What resources will you allocate, recruiting staff countrywide? Who will manage it? Have you understood when it needs to be achieved and what will you do to check it is effective?

To be read along with clause 6.2 of ISO 9001 Please click hear for clause 6.2 of ISO 9001.

6.3 Planning of changes.

The clause lists items to be considered in change management. When some changes need to be made in the organization either in the product, service, or process, the impact of the change needs to be considered before a change is made. You will need to demonstrate that you have:
a) considered why are you changing it and what could happen when you make the change;
b) ensured that the QMS doesn’t get affected negatively, e.g. something can’t be done any longer once you have changed a process like you stop recording the number of quotes you are doing and therefore you don’t have an ability to review conversion rates;
c) thought about what you need to achieve it (e.g. people/technology, etc.);
d) considered what changes need to be made in the organization to make it happen.

To be read along with clause 6.3 of ISO 9001 Please click hear for clause 6.3 of ISO 9001.Any risk and opportunities which are associated with proposed change management must be managed as per as the procedure or Process of management of Risk and opportunities as mentioned in clause 6.1 . The organization must establish a procedure to manage the process of change. The organization must have records as an evidence of the implementation of change management.

Rationale for this supplement as per ISO : Requirement for management of risks and opportunities associated with proposed changes is added as management of change is core principle in the petroleum, petrochemical and natural gas industries and underpins key frameworks, notably process safety. Requirement for documented information is added as management of changes is considered essential to be documented, also in view of conformity assessment activities.

7.0 SUPPORT

7.1 Resources.

7.1.1 General

The organization must determine and provided the resources needed for the establishment, implementation, maintenance, and continual improvement of the QMS. The organization must have the resources it needs to ensure the effective operation of the QMS. Resources may include raw materials, infrastructure, finance, personnel, and IT, all of which can be either internally or externally provided. The organization must have a clear understanding of:

  • what an organization has in house and whether this is sufficient/fit for purpose to achieve its goals and objectives.
  • what additional support might be needed externally.

For example Specialist skills that are better outsourced due to the size of the organization (e.g. security screening, health, and safety advice).

To be read along with clause 7.1.1 of ISO 9001 Please click hear for clause 7.1.1 of ISO 9001

7.1.2 People

This standard expects an organization to determine and provide the appropriate number of personnel to effectively implement the QMS and for the operation and control of its processes. Allocation of staff in order to achieve the required outcome. This means determining that you have someone to carry out a specific process e.g. recruitment, screening, and training of staff. Dependent on the size of the organization this may be one or two people or a team. The senior management will need to determine the resource needed and maintain this. This will be about ensuring you have the right number of engineers or security officers to provide the service that you have quoted. This will depend on the specifics set out in the contract and terms. e.g. ensuring you have sufficient engineers to respond within 24 hours. Ensuring you have sufficient trained security officers to replace those who may be sick or on holiday.

To be read along with clause 7.1.2 of ISO 9001 Please click hear for clause 7.1.2

7.1.3 Infrastructure

Essentially a company needs to consider all the things they will need in order to deliver a service and product to the customer. This may  be :

  • buildings, water,  gas, electricity, etc.
  • equipment such as e computers, operating systems, printers, software, monitoring equipment, etc
  •  vehicles that may be needed for engineers, managers, sales and survey staff;
  • information such as standards that have to be applied, the internet, mobile phones, tablets, etc.

To be read along with clause 7.1.3 of ISO 9001 Please click hear for clause 7.1.3 of ISO 9001. The organization must have a procedure to establish a process for identifying Infrastructure and their usage to achieve conformity of the product and services. The organization must retain records as evidence implementation of the procedure for identification and usage of infrastructure. The procedure and record must include infrastructure to be maintained, method of maintaining including frequency and monitoring for the infrastructure to ensure infrastructure integrity for performance requirements. It must also include outcome of maintenance, including applicable testing methods and acceptance criteria and responsible personnel. For service related infrastructure such as equipment or Machines it must include usage history, repairs or redress, modifications, re manufacturing, inspection, and test activities that allow direct verification for reuse of infrastructure as well as list of critical spare parts as recommended by the original equipment manufacturer or customer or technical requirement or combination of three. The organization can apply risk based maintenance which includes the concept of

— preventive and predictive maintenance;
— reliability centred maintenance;
— mean time between failures;
— system, design and process failure mode and effects analysis;
— failure mode and criticality effects analysis;
— process control plans; and
— others that are in context of the organization and its risks.

Rationale for this supplement as per ISO: Requirements for documented information are added as infrastructure related products and services are considered essential to be documented, also in view of conformity assessment activities. The possibility of applying risk-based maintenance is added to enhance user’s understanding of the concepts that are part of risk-based maintenance, which will be supportive in maintaining the infrastructure.NOTE Lessons learned from industry events demonstrate the need to maintain and retain documented information.

7.1.4 Environment for the operation of processes

The environment for the operation of processes clause ensures that the organization determines, provides, and maintains an environment necessary for the operation of its processes and to achieve conformity. The term environment refers to the work environment and is used to describe the set of conditions in which employees perform their work and under which products and services are produced. Conditions can include physical, social, psychological, and environmental factors (such as temperature, lighting, recognition schemes, social and occupational stress, ergonomics, etc). It can also relate to conditions on how work is actually done (complex, repetitive, creative, interactive, team, etc.) in work processes and procedures. The standard makes reference to the environment that you work in and may include the following:

  • Equality Opportunities, whistleblowing, the anti-bullying policy.
  • Violence at work, counseling support, lone working.
  • Office-based risk assessment, space, noise levels.

To be read along with clause 7.1.4 of ISO 9001 Please click hear for clause 7.1.4 of ISO 9001

7.1.5 Monitoring and measuring resources

7.1.5.1 General

The organization needs to decide what tools it uses to measure organization performance. It also needs to consider whether these tools will give them everything they need as a result. You may use commissioning paper trail and or electronic processes. For eg to monitor Customer Service, you may take feedback after installing via phone call. Other organizations may have a CRM in place. Some of the Suitable measuring tools may be equipment that is used to test and commission systems such as multimeters, insulation testers, sound pressure level meters, etc. You may be required to do calibration of all the test equipment that you use.

To be read along with clause 7.1.5.1 of ISO 9001 Please click hear for clause 7.1.5.1 of ISO 9001. The organization must establish a procedure that defines the processes and controls to manage monitoring and measurement resources (equipment). The procedure must have mechanism to ensure equipment are suitable for he specific type of monitoring and measurement activities being undertaken. Their maintenance for their continuing fitness. The organization must also have record as an evidence of fitness for purpose of the monitoring and measurement resources

Rationale for this supplement as per ISO: Requirement for documented information is added as defining processes and controls related to monitoring and measuring resources is considered essential to be documented, also in view of conformity assessment activities. NOTE Although ISO 29001 cannot impose that laboratories are accredited to ISO/IEC 17025, it is common practice to require accreditation when performing laboratory activities, either internally or externally.

7.1.5.2 Measurement traceability

Measurement traceability is the process of validating the equipment that will be used to measure products and resources. This will give the organization confidence that all measurements are completely correct. You need to establish whether this is relevant to you and meeting all applicable requirements for the product and services.

  • Is it required to be calibrated?
  • Allocated unique reference numbers and listed on a register of some sort.
  • Allocated to personnel as and when needed and a clear process in place to ensure all staff knows how to use it properly.
  • Able to identify calibration status
  • Protected from an adjustment that could affect results of measurement
  • Protected from damages during moving, repairs, or storage
  • Non-conforming devices are checked against a conforming device

To be read along with clause 7.1.5.2 of ISO 9001 Please click hear for clause 7.1.5.2 of ISO 9001. Organization must have a procedure and all relevant records as an evidence of the procedure being followed for the measurement traceability. The procedure must demonstrate the conformance and measurement traceability of the measuring equipment used to determine product conformity to requirements. Organizations are expected to check results from calibration to ensure they are comfortable and have not been tampered with. You may have a measuring equipment register Register. The procedure must include a unique identification, specific to each piece of equipment. The procedure must establish as mechanism for calibration or verification of the measuring equipment or both, at specified intervals, or prior to use, against measurement standards traceable to international or national measurement standards When no such standards exist, the procedure must establish the basis used for calibration or verification. It must include the identification for determining their status. It must establish mechanism for safe guarding the measuring equipment from adjustments, damage or deterioration that would invalidate the calibration status and subsequent measurement results. The procedure must establish a mechanism for action to be taken when validity of previous measurement results has been affected when a instrument is found to be defective during its planned verification or calibration or when in use. It must also establish a mechanism for customer notification.

Rationale for this supplement as per ISO: Requirements for documented information are added as traceability of measuring equipment and actions taken in cases of inappropriate measurements are considered essential to be documented, also in view of conformity assessment activities.

7.1.6 Organizational knowledge

The organization shall determine the knowledge necessary for the operation of the QMS, ensure the conformity of products and services, enhance customer satisfaction. As necessary the organization is responsible for maintaining, protecting, and making sure the knowledge is available. Knowledge is to be considered when making changes to the organization. Knowledge required depends on the size and complexity of the organization, the risks and opportunities it needs to address, accessibility of knowledge, the process for considering and controlling past, existing, and additional knowledge. As long as the conformity of products and services can be achieved, the balance between knowledge held by competent people and knowledge made available by other means is at the discretion of the organization. Consideration can be given to whether competent employees have this knowledge

To be read along with clause 7.1.6 of ISO 9001 Please click hear for clause 7.1.6 of ISO 9001

7.2 Competence.

The organization needs to determine the necessary competence of its employees, and ensure those employees are competent on the basis of appropriate education, training, and experience. The organization must have a process for determining the necessary competence and achieving it through training or other means. Determining competence is a necessity in any organization. Working out on the skills your team has and the skills they don’t yet have and the skills they will need to achieve the company’s objectives. For example to achieve the objective of “Increase in sales”, you need to improve the competency of your sales team by training them.

To be read along with clause 7.2 of ISO 9001 Please click hear for clause 7.2 of ISO 9001. The organization must establish a procedure and all relevant records as an evidence of implementation of procedure for competence. The procedure must define the practices employed to manage competence requirements of personnel whose responsibilities influence the achievement of quality objectives. The procedure must include the determination of necessary competence of its employees whether staff ,workers, contract workers, full time or part time or outsourced, on the basis of appropriate education, training, or experience. In case gaps are identified in the competence the procedure must include actions to be taken to acquire necessary competency and evaluation of the effectiveness of the actions taken .The procedure must also validate the competence to the risk level associated to the above mentioned task as per procedure as given in clause 6.1. Competency Matrix/ catalogue, proficiency levels, criteria for attaining and maintaining proficiency, competence profiles can be part of the competency model as a part of the procedure. Validation of proficiency levels can include technical interviews, assessments and on job/ classroom/online training.

Rationale for this supplement as per ISO : Requirement for validation of competency is added in view of the (potential) high risk associated with operations in the petroleum, petrochemical and natural gas industries, including the supply chain which can contain several providers following a ‘cascading model (e.g. contractors and sub-contractors). Requirement for documented information is added as managing competencies is considered essential to be documented, also in view of conformity assessment activities.

7.3 Awareness.

The clause of Awareness is closely related to the clause of competence. Employees must be made aware of the Quality Policy and its contents. They must also be aware of how their personal performance currently impacts QMS and its objectives or may impact it in the future. They must understand the implications of positives or improved performance, and poor performance may be to the QMS. There is a greater focus on not just communicating the policy but to ensure that it is understood by all the employees and how it affects their work, especially if they deviate from it. They must understand what they contribute and how this can make the organization better. From a QMS point of view, the organization should look to explain policies more clearly so that the staff understands their meaning. It may useful to capture this on a training record,
For Quality Policy the employees:

  • Read and understood = insufficient
  • Understand companies aim = Yes
  • Understand the company’s processes in which they are involved = Yes
  • Understand their impact = Yes
  • Understand they can have a positive effect = Yes
  • Understand they can have a negative effect = Yes

To be read along with clause 7.3 of ISO 9001 Please click hear for clause 7.3 of ISO 9001. The organization must also ensure that its employees whether staff ,workers, contract workers, full time or part time or outsourced are aware of related to their work the customer requirement, regulations, the process of risk mitigation, the requirements of conformity assessment.

Rationale for this supplement as per ISO : Requirement for awareness of specified regulated and customer quality requirements, risk mitigation and verification requirements related to work is added to align with with API Spec Q1 and API Spec Q2.

7.4 Communication.

This clause includes both internal and external communication about the QMS. Processes for internal and external communication need to be established within the QMS.

The key elements of Communication that an organization must establish are

  • what needs to be communicated?
  • when it needs to be communicated?
  • how it should be done?
  • who needs to receive the communication? and
  • who will communicate?

It should be noted here that any communication outputs should be consistent with related information and content generated by the QMS for the sake of consistency. This is a straightforward clause and is simply about effectively communicating to all those within the organization and those affected by it. Internal communications  can include briefings to staff on:

  • new policies;
  •  new or amended objectives;
  •  new or  amended strategies;
  • new clients;
  • new or amended technology;
  • new products;
  • issues with suppliers;
  •  anything that will have an impact on them.

Designate a person responsible for updates that may be either department heads or Top Management.

To be read along with clause 7.4 of ISO 9001 Please click hear for clause 7.4 of ISO 9001

7.5 Documented information.

7.5.1 General

The term “documented information” in the ISO 29001 is basically a combination of the two terms “documents” and “records”. “Documents”, “Documentation” and “Records” are combined to become “Documented information”. It refers to all of the important information within the organization that must be kept organized and controlled. It is a requirement to determine, make available, and maintain knowledge.  It mentions issues such as confidentiality, access, and data integrity. The organization may adopt information security due to the increasing use of electronic documents/data. Documented procedures (e.g. to define, control, or support a process) are now expressed as a requirement to maintain documented information. and records are expressed as a requirement to retain documented information.

7.5.2 Creating and updating

When documented information is created or updated, organization should ensure that it is appropriately identified and described (e.g. title, date, author, reference number). It must be in an appropriate format (e.g. language, software version, graphics) and on appropriate media (e.g. paper, electronic). Confirm that documented information is reviewed and approved for suitability and adequacy. When documented information is created or updated, Organization should ensure that it is appropriately identified and described (e.g. title, date, author, reference number). It must be in an appropriate format (e.g. language, software version, graphics) and on appropriate media (e.g. paper, electronic). Documented information should be reviewed and approved for suitability and adequacy.

7.5.3 Control of documented information

A robust document control process invariably lies at the heart of any compliant management system; almost every aspect of auditing and compliance verification is determined through the scrutiny of documented information. With this in mind, it becomes apparent that the on-going maintenance of an efficient document management system must not be overlooked. Organization must control the documented information required by the QMS. A suitable process must be implemented to define the controls needed to; approve, review, update, identify changes, identify revision status and provide access. The documented information process should define the scope, purpose, method and responsibilities required to implement these parameters. In order to comply with the documented information requirements, it is essential that all personnel understand what types of information that should be controlled and more importantly, how this control should be exercised. To get the most out of your documented information process, it must communicated to ensure that staff and other users of the documentation information understand what they must do in order to manage that information effectively and efficiently. Demonstrate the organization’s arrangements for controlling documented information required by ISO 29001 and your organizations own requirements, including:

  • Availability e.g. document accessibility (hard copy, electronic media), readily available at the point of use;
  • Suitability e.g. format, media suitable to the environment, ease of understanding, language, interpretation;
  • Protection e.g. document authentication, document markings (official, secret, restricted, confidential, private, sensitive, classified, unclassified), access controls (individual, role specific),
  • Physical security (master documents, server rooms, libraries) IT security (User ID, password, servers, download, back up, encryption, ‘read only’, ‘read/write’), protection from corruption and unintended alterations.
  • Demonstrate the organization’s arrangements for document retention e.g. organization/legal/contractual retention periods, storage, preservation, back up, retention of knowledge, disposal, obsolescence e.g. withdrawal, replacement, legacy archive and suitable identification (‘for information only’, ‘not to be used after….’, ‘uncontrolled copy’, ‘for reference purposes only’, etc.

Ensure your organization protects electronic data, e.g. security policy, system access profiles, password rules, storage and back-up policy including protection from loss, unauthorized changes, unintended alteration, corruption, physical damage. Access can imply a decision regarding the permission to view the documented information only, or the permission and authority to view and change the documented information.

To be read along with clause 7.5 of ISO 9001 Please click hear for clause 7.5 of ISO 9001. The organization must establish a procedure for Control of Documented Information. The procedure must include mechanism for distribution, access, retrieval and use of the Documented Information (Documents and Records.). It must include storage and preservation, including preservation of legibility, ) control of changes (e.g. version control), retention and disposition. It must also include the process for preventing unintended alteration of Records. It must Include process for identification and control of Documented Information (Documents and Records.) of External origins (Example can include standards, equipment manual, Tender document, Purchase order, Invoice, etc ). It must also include the practice of integrating external specification requirements, including addenda, errata, and updates that are used in manufacturing and designing of product or services into related operating processes.

Rationale for this supplement as per ISO: Requirements for documented information are added as defining processes and controls for documented information and defining practices to integrate external specifications in their own operating processes are considered essential to be documented, also in view of conformity assessment activities.

8.0 Operation

8.1 Operational planning and control.

In order to meet the requirements for the delivery of products and services, the organization needs to plan, implement, and control its processes. The first step is to determine the requirements for products and services, meaning what features the product or service will have. Then, the organization needs to define how processes will be performed and what criteria the product or service needs to meet to be accepted for release. Finally, the organization needs to determine the resources needed for the processes and the records needed to demonstrate that the processes were carried out as planned. Once they have done their planning for what they are going to sell, they then must plan the detail of how this can be done operationally. The organization may need to :

  • Set up supplier accounts/trade accounts.
  • Purchase stock.
  • Ensure staff have the correct skills and understand the process.
  • Purchase tools and vehicles.
  • Make sure you have enough staff.
  • Issue clear instructions, drawings, procedures risk assessments to enable them to do the job.

The organization needs to show clear control of the process. They will be expected to check that delivery is as expected and when there are deviations that this is managed and negative impacts controlled. The same control should be applied to subcontractors.

To be read along with clause 8.1 of ISO 9001 Please click hear for clause 8.1 of ISO 9001. The organization must take into account the customer’s scope when determining the requirements for the products and services. The organization can establish a quality plan, service quality plan or inspection and test plan which specifies the processes of QMS and the resources to be applied to a specific product, service, project or contract. This and all relevant records, as an evidence of implementation must be controlled as per procedures given 6.1 and 7.5. While planning the operation base on the risk of achieving requirement and improvement opportunities the organization must apply change management process as per the procedure given in clause 6.3. When contingency plans are established as a risk treatment it must include at minimum roles and responsibility for response, communication and immediate actions.

Rationale for this supplement as per ISO : Requirements related to operational planning and control are added to link these activities with risk treatments, including contingency plans where appropriate, and change management processes when planning the operations to ensure that product or service outcomes meet the requirements or obligations. Explanation is provided that documented information in this context is (better) known as quality plan, service quality plan or inspection and test plan.

8.2 Requirements for products and services.

Requirements for products and services are closely related to communication with customers. This communication must include information related to the products or services, handling inquiries, contracts or orders, customer feedback, handling and controlling customer property, and, if needed, establishing specific requirements for contingency actions. Before offering the product or service to the customer, the organization needs to ensure that the requirements for the products and services are defined and that the organization is able to deliver such products or services. Requirements for products and services include any applicable legislation and the requirements that the organization considers being necessary. After receiving the order, the organization must, prior to delivery, review the requirements related to the product and keep records about the review. If the customer changes its requirements, these also must be reviewed and recorded. In case of changes, the organization must ensure that all documented information is amended and all relevant persons are aware of the changes.

8.2.1 Customer communication

This is essentially about how you relate to the customer, to include:
a) what you are selling;
b) how they can expect to be dealt with (e.g. formal quote/email/letter/terms you will work under/within);
c) getting feedback from the customer;
d) looking after their property (e.g. premises whilst you are in there);
e) what plans you put in place for if something goes wrong.

Ensuring the customer has a clear written quotation and specification relating to the services they want. Allocating a specific person/manager to the customer so that they have one key contact for all communication; that way, positive and negative feedback is captured and dealt with. you must give useful information about your products/services. you must provide some mechanism to have your customers ask about the products/services and e a way for customers to inquire about your invoices and fees. The customer must have a way to ask about changes. There should be a way to collect customer complaints and a way to collect feedback. If your customers provide their property as a part of your product/service, they must be able to understand how it is handled. If there are any risks associated with your product or service, your customer must be told of them and how they are handled

To be read along with clause 8.2.1 of ISO 9001 Please click hear for clause 8.2.1 of ISO 9001.

8.2.2 Determining the requirements for products and services

Organizations need to be clear about what is required in order to sell their products and services. You must review customer requirements before committing to supply the product or service. You need to take into account a few things here. You must consider:

  • Delivery
  • Installment
  • Service
  • Warranty
  • Applicable acts and regulations
  • What to do when providing verbal contracts.
  • for legal and industry norm;
  • elements the organization determines as necessary for their own needs.

Once all that is considered and reviewed, you need to formally accept the requirements with confirmation back to the customer of what you are going to deliver and when. You need to keep documented information on this review. The organization must be able to deliver what it is selling. Liaise with suppliers, attend open days, read the product literature.

To be read along with clause 8.2.2 of ISO 9001 Please click hear for clause 8.2.2 of ISO 9001.

8.2.3 Review of the requirements for products and services

Organizations are expected to review whether they can provide what they intend to sell. This review must include taking into account:
a) what the customer orders, the install and any after work, e.g. maintenance / follow up / servicing;
b) elements that need to be completed to ensure the job is fitted correctly – meter reading tests / commissioning forms / standard operational check;
c) anything else the company need to implement;
d) legal and industry standards
e) any variations. If the customer has changed their order, this needs to be defined and the customer must accept this change if they haven’t already confirmed it in writing.

Reviews must be documented. If they want to use new products and services, this must be recorded. Customers should be made aware of the impact of changing products and services, etc. Organizations may choose to do a contract review either using paper or electronic documents, confirmation emails, quote proposals, etc. It must also record any change in technology you might use.

To be read along with clause 8.2.3 of ISO 9001 Please click hear for clause 8.2.3 of ISO 9001. The organization must establish a procedure for Contract Review that defines the process for the review of requirements related to the provision of products or services before committing to the customer.

Rationale for this supplement as per ISO: Requirement for documented information is added as defining processes for reviewing requirements related to the provision of products or services is considered essential to be documented, also in view of conformity assessment activities.

8.2.4 Changes to requirements for products and services

If there is any change in the Customer order, this needs to be tracked and documented. Someone in the organization who is responsible for executing the customer order must ensure that all related departments related to executing the order are aligned. You should seek and record evidence that your organization has ensured that all relevant documented information relating to changed product or service requirements, is amended and that relevant personnel is made aware of the changed requirements.  Define your organization’s arrangements for amending documented information and communication of changed requirements e.g. updated contract review records, amended orders/contracts, memos, change notices, quality plans, meeting minutes, together with communication to relevant interested parties (persons within or outside the organization that may be impacted by the change).

To be read along with clause 8.2.4 of ISO 9001 Please click hear for clause 8.2.4 of ISO 9001.

8.3 Design and development of products and services.

8.3.1 General

This clause refers to design and development management, from the initial idea to the final acceptance of the product. The definition of design is “a plan or drawing produced to show the look and function or workings of a building, garment, or another object before it is made.” Putting it simply if the organization is creating something be it a tangible product or intangible service, there will certainly be an element of Design. ISO 9000 explains that the terms “design” and “development” are often used as synonyms, and defines the different phases of overall design and development. This means that design can’t be used apart from development and that they represent one single process. During design and development planning, all its phases must be defined with appropriate activities of review, verification, and validation for each phase. ISO 29001 refers to the design and development of the product and not to the design and development of processes. Design and development inputs requirements relate to the product include:

  • Functional requirements and product performance requirements
  • Legal and regulatory requirements for product
  • Information from previous similar projects
  • Other requirements relevant to design and development, usually customer requirements, market information, package, etc.

Design and development outputs must be in a form suitable for verification related to input elements and must be approved before acceptance. They can be in the form of a drawing, engineering documentation, plans, etc. The organization also needs to define design and development review activities. The purpose of these activities is to determine whether the design and development process goes in the intended direction. The review must be done in appropriate phases and at the end of the project. The review identifies problems during design and development and suggests actions to resolve them. It can include other interested parties. The design and development review must be recorded. Also, the company needs to identify, review, and control changes during the design and development of products and services. A record should be kept regarding the changes, results of reviews, authorization of the change, and actions taken to prevent adverse effects.

To be read along with clause 8.3.1 of ISO 9001 Please click hear for clause 8.3.1 of ISO 9001.

8.3.2 Planning

The organization must have a plan on how to do the design and development. A design and development plan which will have the project timescales, deliverables, responsibilities of team & individuals, persons of authority for sign-off for an internal, or external customer, design reviews at a relevant phase in the project e.g. start, confirmation of inputs, post verification, post validation, finish, etc., resources required throughout the project, communication with subsequent process owners, and required controls throughout the project and intended use of the output.

To be read along with clause 8.3.2 of ISO 9001 Please click hear for clause 8.3.2 of ISO 9001.The organization must establish a procedure for Design and development of products and services that defines the processes used to plan and control design and development activities of products and/or services. During the planning stage the organization must ensure that the process of managing risks and opportunities are incorporated in the design development process as per the procedure given in clause 6.1

Rationale for this supplement as per ISO :Requirement for activities for managing risks and opportunities is added to ensure coherence with the organizational and operational planning processes, also in view the (potential) high risk associated with operations in the petroleum, petrochemical and natural gas industries, including the supply chain which can contain several providers following a ‘cascading model’ (e.g. contractors and sub-contractors). Requirement for documented information is added as defining processes for planning and controlling design and development activities of products and/or services is considered essential to be documented, also in view of conformity assessment activities.

8.3.3 Inputs

There are many inputs to the process. The inputs may be:

  • The requirements from the customer like what do they want to achieve and what are their needs & expectations
  • The parameters & constraints of designs e.g. materials, dimensions, functionality, life cycle, sustainability, etc.
  • The statutory and regulatory requirements or codes of practice like product and safety directives, building regulations, etc
  • Availability of information from previous designs like a review of learnings – good/bad/potential improvements, etc.

To be read along with clause 8.3.3 of ISO 9001 Please click hear for clause 8.3.31 of ISO 9001.The input to the Design and Development should also include output o process of managing risks and opportunities are incorporated in the design development process as mentioned 8.3.2 and can also include environmental and safety conditions as part of performance requirement.

Rationale for this supplement as per ISO :Statement related to performance requirements is added to enhance user’s consideration of environmental and safety conditions as part of the performance requirements. Requirement for output of processes of managing risks and opportunities is added to ensure that this source is also considered in design and development inputs, also in view the (potential) high risk associated with operations in the petroleum, petrochemical and natural gas industries, including the supply chain which can contain several providers following a ‘cascading model (e.g. contractors and sub-contractors).

8.3.4 Controls

It is a critical step in Design and Development. It helps the organization to determine how the results to be achieved such as what are the project deliverables, how will they be achieved and how will they be measured (acceptance criteria). The reviews have to be conducted throughout the project as mentioned above at the relevant phase in order to meet the input requirements.

To be read along with clause 8.3.4 of ISO 9001 Please click hear for clause 8.3.4 of ISO 9001.

8.3.5 Outputs

It is the outcome of the Design and Development process. Typical examples of outputs include conceptual designs, technical/engineering drawings, product specifications, manufacturing instructions, bill of materials, information for purchasing, and other subsequent processes.  The output must meet the input requirements ie it has achieved the intended results. The organization must determine that they can move forward in the project using the outputs, and must confirm any necessary equipment for measuring and/or testing and the acceptance criteria.

To be read along with clause 8.3.5 of ISO 9001 Please click hear for clause 8.3.5 of ISO 9001.

8.3.6 Changes

The organization must have an established formal process for controlling design and development changes throughout the project and during reviews. The changes have to be documented and the results of design and development reviews communicated. There has to a person of authority to authorize the changes. The process must include a mechanism to identify the most up-to-date revisions and mitigate the risk of using superseded versions, Examples of this can be version no /revision no /authorization control on drawings, a design/drawing register, engineering change notes, etc.

To be read along with clause 8.3.6 of ISO 9001 Please click hear for clause 8.3.6 of ISO 9001.

8.4 Control of externally provided processes, products, and services.

8.4.1 General

This clause refers to purchasing. The purchasing includes products and services you acquire from suppliers and outsourced processes. ISO 9001:2015 expresses “suppliers” and “Outsourcing” as external providers of products and services. “Purchasing” and “Purchased products” are referred to as “Externally provided products and services”. Clause 8.4 Control of externally provided products and services addresses all forms of external provision, whether it is by purchasing from a supplier, through an arrangement with an associate company, through the outsourcing of processes and functions of the organization, or by any other means. The organization needs to establish and document criteria for suppliers’ selection, which includes how crucial the purchased product or service is to the quality of your product. The results of the supplier evaluation must be recorded.  The organization is required to take a risk-based approach to determine the type and extent of controls appropriate to particular external providers and externally provided products and services. In order to ensure that externally provided processes, products, and services do not have an adverse effect on the conformance of the organization’s products and services, the organization needs to establish controls including verification and other activities. As part of the controls, the organization needs to communicate to external providers its requirements for:

  • the processes, products, and services to be provided
  • the approval of methods, processes, and equipment
  • Competence
  •  verification or validation of the activities that the organization intends to perform

To be read along with clause 8.4.1 of ISO 9001 Please click hear for clause 8.4.1 of ISO 9001.

8.4.2 Type and extent of control

The organization must evaluate the critical suppliers against a fixed set of criteria. The criteria can include technology, Quality, Responsiveness, Delivery, Cost, Environmental impact. As they use these suppliers they will need to monitor their performance against its requirements. It takes some effort to ensure that the suppliers are performing, but it is time and resources very well spent. As they regularly talk with critical suppliers about the issues and requirements a relationship will be built, one which will be mutually beneficial in the long-term. The organization must ensure outsourced processes are controlled. It must define the controls for the supplier. These controls could be defined through purchase orders, in agreements, or in contracts. In addition, it needs to control the actual product or service they purchase. It could ask for a certificate of conformance, or a test report, or a third-party test. The organization doesn’t require to have “one-size-fits-all” controls for all suppliers. For the critical suppliers that have a significant risk to the organization, they need to put tighter controls in place. For others – not so much. Also, they must ensure that suppliers meet local laws and regulations. Also, they need to inspect the product or service from the supplier.

To be read along with clause 8.4.2 of ISO 9001 Please click hear for clause 8.4.2 of ISO 9001.The organization must establish a procedure for control of externally provided processes, products, and services. The procedure must ensure that externally provided processes, products and services do not adversely affect the organization’s ability to consistently deliver conforming products and services to its customers and remain within the control of its QMS. It must define controls that it intends to apply to an external provider (suppliers/vendors/ contractors etc.) and those it intends to apply to the purchase product or services by taking into consideration their potential impact of their processes, products and services consistently meeting customers and legal requirements and the effectiveness of those controls. The procedure must determine the necessary verification, to ensure that the externally provided processes, products and services meet requirements. The organization must have the records as an evidence of the effectiveness of the verification activity. The procedure must include the planned assessment of the performance of external provider to be periodically so as to adjust the type and extent of controls to manage associated risks and opportunities. The procedure should address the risks to the achievement of specified requirements and improvement opportunities for the products and/or services

Rationale for this supplement as per ISO :Requirement for assessing external provider performance is added as to ensure that changes in risk profiles are taken into account in defining and adjusting the type and extent of controls for externally provided processes, products and services, also in view the (potential) high risk associated with operations in the petroleum, petrochemical and natural gas industries, including the external providers following a ‘cascading model (e.g. contractors and sub-contractors). Requirements for documented information are added as defining processes and controls for documented information and defining practices to integrate external specifications in their own operating processes are considered essential to be documented, also in view of conformity assessment activities.

8.4.3 Information for external providers

This is about ensuring that third-party suppliers and subcontractors have a clear understanding of what they are expected to supply. This is typically done with a purchase order but it could also be by contract or agreement. Other methods of spelling out requirements for suppliers can be inspection and test plans, work briefs, statements of work, and even forecasts.

To be read along with clause 8.4.3 of ISO 9001 Please click hear for clause 8.4.3 of ISO 9001.

8.5 Production and service provision.

An expansion on previous requirements e.g. documented information to specify intended results and to determine the nature and extent of any post-delivery (after-sales) activities. The production and services provision process needs to be performed under controlled conditions that will ensure that the product or service delivered is compliant with initial requirements. This includes a sufficient level of documentation, like procedures, work instructions, and records, monitoring and measurement equipment, appropriate infrastructure, etc. The organization must use suitable means to identify outputs when it is necessary to ensure products and services conformance. When traceability is a requirement, the organization needs to control the unique identification of outputs and retain documented information necessary to enable traceability. In cases when the organization uses property belonging to a customer or external provider, it is required to identify, verify, protect, and safeguard this property. When the property of the customer or external provider is lost or damaged, the organization will have to report to the owner and retain documented information on what has occurred. The decision on the extent of post-delivery activities will be affected by the following:

  • statutory and regulatory requirements
  • potential undesired consequences related to products and services
  •  lifetime, use, and the nature of the products and services
  •  customer requirements and feedback.

In case of changes in the production and service provision process, the organization must review and control the changes in order to ensure continuing conformity with the requirements.

8.5.1 Control of production and service provision:

The organization must carry out the activities to provide products or services under controlled conditions. The common controlled conditions that should be used include documented information for products and services, suitable monitoring and measurement resources (including equipment), suitable infrastructure and environment, competent persons, validation of the ability to achieve results, actions to prevent human error, and activities controlling product release, delivery, and post-delivery. As with all other processes, these do not need to be documented procedures unless non-conformance would occur if the procedure was not written down.

To be read along with clause 8.5.1 of ISO 9001 Please click hear for clause 8.5.1 of ISO 9001. The organization must establish a procedure that defines the controls used to meet the requirements of of production and/ or service provision. The Control conditions must include the special characteristics of the product , services or the activities of the organization, the results that needs to be achieved, availability of monitoring and measuring equipment, ensuring of monitoring and measuring activities (inspection) takes places at different stages of production/service to have the confidence that both the processes themselves and the process outputs (product/service) meet the organization’s acceptance criteria. Suitable infrastructure and work environment. Competent personal with required qualification.Product and service release, delivery and post-delivery activities are implemented. action to prevent human error like use of work instruction and training of employees. The organization must also establish a procedure for validation of processes , where the results cannot be verified by subsequent monitoring or measurement. The process itself is initially validated and then periodically re-evaluated. The procedure must include required equipment, competence of personnel, use of specific methods, including identified operating parameters, identification of acceptance criteria and re validation. The organization must have all relevant records as an evidence of the procedures being followed and to demonstrate the control effectiveness.

Rationale for this supplement as per ISO : Requirement for the methods to be considered in the validation methods is added to align with API Spec Q1 and API Spec Q2. Requirement for documented information is added as defining controls for meeting the production and service provision requirements is considered essential to be documented, also in view of conformity assessment activities.

8.5.2 Identification and traceability

Organization should seek and record evidence that product is identified (as appropriate) and its status with regards to monitoring and measuring (conforming or not) is identified throughout the manufacturing processes. Where traceability is a requirement, Organization should be controlling and recording the unique identity of the product throughout the production process to ensure that only products that have passed the required inspections and tests are utilized. organization must have a process in place for the identification and traceability of outputs, in terms of the monitoring and measurement requirements at all stages of production, to enable the demonstration of conformity to requirements, e.g. physical part marking, labeling, tags, bar codes, signage, visual indicators, part segregation, lay down areas, storage racks. There are several ways of identifying products to prevent them becoming mixed with other parts, components, or orders. The most obvious is using tags or stickers with a unique traceability identifier, such as a lot or batch number included on the product labels. The identification may be engraved in the product itself, or the product may simply be marked by a colour. Establish and implement a procedure to identify the product through the design, development, manufacture and delivery stages. The established a traceability system should track components from raw material through inspection, test, and final release operations, including rework:

  • Establish the identity and status of products;
  • Maintain the identity and status of products;
  • Maintain records of serial or batch numbers.

To be read along with clause 8.5.2 of ISO 9001 Please click hear for clause 8.5.2 of ISO 9001. The organization must establish a procedure and all relevant records as an evidence of implementation of procedure for Identification and traceability. The procedure defines the processes for use of suitable means for the identification and traceability of outputs (product and services)  to enable the demonstration of conformity to requirements. It also defines the process for the identification of status of outputs (product and services) to enable the demonstration of conformity to requirements through out the manufacturing/ servicing process. Where traceability is a requirement, Organization must controlling and record the unique identity of the product throughout the production process to ensure that only products that have passed the required inspections and tests are utilized.

Rationale for this supplement as per ISO: Requirement for documented information is added as defining processes to meet the identification and traceability requirements is considered essential to be documented, also in view of conformity assessment activities.

8.5.3 Property belonging to customers or external providers:

This requirement is very important if the organization uses the customer or supplier property. It can come in many forms such as piece parts that will become part of the delivered product, special equipment to perform specific testing for the customer, or even proprietary information that is needed to use to design and deliver the product or service. When a customer or other party has given any property to use in supplying their needs, it is needed to control that property from unintended use and have a way of dealing with that property with external party involvement should there be a problem with it. Records of this activity need to be maintained to show accurate records of customers or external property. In fact, personal data that is provided by the customer and supplier would also need protection.

To be read along with clause 8.5.3 of ISO 9001 Please click hear for clause 8.5.3 of ISO 9001. The organization must establish a procedure and all relevant records as an evidence of implementation of procedure for Control of Customer /External provider property. The procedure defines the processes for the care the organization must exercise with property belonging to customers or external providers while it is under the organization’s control or use by identifying, verifying, protecting and safeguarding it. If property is lost or damaged or found to be unsuitable, this needs to be recorded and the customer needs to be notified.

Rationale for this supplement as per ISO : Requirement for documented information is added as defining processes to meet the requirements of property belonging to customers or external providers is considered essential to be documented, also in view of conformity assessment activities.

8.5.4 Preservation:

Adequate measures must taken to protect and preserve the product during internal processing and delivery to the intended destination. The preservation process must include packaging, storage and other product specific handling methods, the requirements for which are likely to be an output of the design process.

  • Identification – The organization must ensure that products are properly identified and do not become mixed with other orders. All products are clearly identified. This is relative to identification and traceability however for preservation of product it is a requirement and not ‘as applicable’;
  • Handling – This may include bulk handing using moving equipment or physical contact where handling may influence product conformity. Suitable handling methods should be implemented throughout the processes.
  • Packaging – The organization must ensure that labeling and marking of shipped products are sufficient to enable adequate identification and traceability back through QMS. This should include ensuring that labeling and marking maintains its integrity and remains affixed throughout the shipping process. The methods must be established for packaging the product to preserve its integrity. Package products appropriately for shipping in order to preserve the product’s integrity throughout the shipping process;
  • Storage – This should include storage conditions to prevent the deterioration, damage or loss. The product should be stored in a manner to safe guard product;
  • Protection – Raw materials, in-process materials, inspected product, nonconforming product and product ready for shipping should be identified with its status and protected from any unintended alteration. Appropriate measures are in place to protect product. This will vary depending on the product.

To be read along with clause 8.5.4 of ISO 9001 Please click hear for clause 8.5.4 of ISO 9001. The organization must establish a procedure and all relevant records as an evidence of implementation of procedure for risk based Preservation. The procedure defines the methods used to preserve products and constituent parts throughout operations up to the delivery to its destination and or service delivery in order to maintain conformity to requirements. The procedure must also consider preservation of work environment controls. The procedure must also define the process for preservation of product and constituent parts kept in storage area before use or delivery to prevent damage or deterioration . It must also include type and frequency of assessment of products and constituent parts to detect deterioration. The procedure must also address identification and traceability marks, transportation, handling, packaging, and protection requirements, as applicable

Rationale for this supplement as per ISO : Requirement for documented information is added to ensure that essential information for risk-based preservation is defined and maintained, also to align with API Spec Q1 and API Spec Q2.

8.5.5 Post-delivery activities:

Sometimes there is a need to perform activities on the product or service after it has been delivered to the customer. While the requirements for what needs to be done can vary greatly from one product or service to another. organization must meet requirements for post-delivery activities associated with the products and services. When determining the extent of post-delivery activities that are required, Organization should consider:

  • Statutory and regulatory requirements;
  • The potential undesired consequences associated with its products and services;
  • The nature, use and intended lifetime of its products and services;
  • Customer requirements;
  • Customer feedback.

Taking these into account will give you an idea of what needs to be done after delivery, such as warranty provisions, maintenance services, or even recycling and final disposal services.

To be read along with clause 8.5.5 of ISO 9001 Please click hear for clause 8.5.5 of ISO 9001.

8.5.6 Control of changes:

The organization must implement a process for responding to unplanned changes that are considered essential in order to ensure that products or services continue to meet their specified requirements, in such a way that conformity with requirements is maintained. Changes should be documented and information retained about the changes, including who authorized the change and the actions arising from the change. The organization should make changes in a thoughtful manner and to consider the potential impact to other process, products and possibly the customer. Key items to consider are:

  • Is the impact of the change evaluated to determine its affects to work in process or products already delivered?
  • What process control documentation (procedures, travellers, forms, etc.) will need updating as the result of change to be implemented?
  • Was the change approved prior to implementation including, where applicable, approval by the customer, statutory or regulatory authority?
  • Does retained documented information indicate the source of change and information on necessary actions and approvals?

Organization must implement a process to control unplanned changes in accordance with the requirements set out above.

To be read along with clause 8.5.6 of ISO 9001 Please click hear for clause 8.5.6 of ISO 9001. The organization must review and control the unplanned changes of the product and service provision which includes changes in the organizational structure, key or essential personnel, critical providers, design, the management system in order to ensure that products or services continue to meet their specified requirements, in such a way that conformity with requirements is maintained. The organization must also review the changes due to the assessment of risk and opportunities and corrective action. The organization must notify the customers when these changes impact its product or services. Where specified the customer must also be notified of the effect of changes on residual or new risks.

Rationale for this supplement as per ISO: Requirements for control of changes in production or service provision, and possible communication for effect of these changes, are added to align with API Spec Q1 and API Spec Q2.

8.6 Release of products and services.

The organization must have a process (method, techniques, formats, etc.) is in place to monitor and measure the characteristics of product to verify that requirements are being met. This must be accomplished at appropriate stages of the design and development process. Records must be maintained to provide evidence of conformity and indicate the person(s) authorizing the release of products. The release of product or delivery of service must not be completed until the planned requirements defined in Clause 8.1 have been met. The release of product may include, according to product planning and the verification stages; release to the next operation, release to an internal customer, or release to final customer, etc. Planned arrangements can include design verification and design validation, which can involve modelling, simulations, experiments, trials, prototypes, functional testing, performance testing; inspections comprising, in-process, first article and final inspection; thorough examination through destructive and non-destructive testing; customer acceptance testing, product certification/qualification, third party qualification from a regulator, recognized society, or independent testing body etc. For product release or service delivery, the planning requirements may be waived, but must be approved by relevant authority and by the customer as appropriate. Monitor and measure product characteristics to ensure they are able to demonstrate:

  • Product characteristics are continually met;
  • Evidence of conformity with product requirements.

Retain records to provide evidence that acceptance criteria have been met might include: e.g. certificate of conformity, release certificate, regulatory certificate. Ensure traceability to the person(s) authorizing the release such as name, authorized signatories, user identification, stamp impression etc., including their authority status (release signatory, certifying staff, scope of authorization etc.).

To be read along with clause 8.6 of ISO 9001 Please click hear for clause 8.6 of ISO 9001. The organization must establish a procedure and all relevant records as an evidence of implementation of procedure for Release of products and services.The procedure defines the process for implementation of planned arrangements, at appropriate stages, to verify that the product and service requirements have been met. The product or service should not be release until all the arrangements and complete and requirements being met or being approved by customer or relevant authorities. On the release of product and service the organization must have records of evidence that acceptance criteria have been met including person authorizing the release.

Rationale for this supplement as per ISO : Requirement for documented information is added as defining processes to meet the requirements of release of products and services is considered essential to be documented, also in view of conformity assessment activities.

8.7 Control of nonconforming outputs.

Nonconforming outputs must be prevented from unintended use or delivery, so the organization must identify and control nonconforming outputs that emerge from any phase of production or service delivery. Depending on the nature of the nonconformity, the organization can take one or more of the following actions:

  • correction
  • segregation, containment, return, or suspension of the provision of products and services
  • informing the customer
  • obtaining authorization for acceptance under concession

Conformity to the requirements must be verified when the nonconforming output is corrected. The organization also needs to keep documented information that describes the nonconformity, the action taken, concessions obtained, and the authority deciding the action with respect to the nonconformity. You do not need a documented procedure any longer to detail how you will deal with things that go wrong but you do need to do the following:

  1. Fix it.
  2. Remove it if necessary.
  3. Tell the customer.
  4. Ask them to accept it.

You should record what you do when things go wrong:

  1. About what is wrong.
  2. what you did as a result.
  3. What concessions you gave? (e.g. did the customer accept it but you altered the cost)
  4. Who had the authority to make the change?

To be read along with clause 8.7 of ISO 9001 Please click hear for clause 8.7 of ISO 9001. The organization must establish a procedure and all relevant records as an evidence of implementation of procedure for control of non conforming output. The procedure ensure that non conforming output including those nonconforming products and services that are detected after delivery of products, during or after the provision of services are identified and controlled to prevent their unintended use or delivery. Based on the nonconformity and its effect on the conformity of products and services, the organization shall take appropriate action which can be correction, segregation, containment, return or suspension of provision of products and services, informing the customer and obtaining authorization for acceptance under concession. Once nonconforming outputs are corrected, Conformity to the requirements shall be verified.

Rationale for this supplement as per ISO : Requirement for documented information is added as defining processes to meet the requirements of control of nonconforming outputs is considered essential to be documented, also in view of conformity assessment activities.

9.0 Performance Evaluation

9.1 Monitoring, measurement, analysis, and evaluation.

9.1.1 General

Organization must develop a process (method, techniques, format, etc.) to identify, collect and analyze various data and information from both internal and external sources, including:

  • Monitoring and measuring results;
  • Process performance results;
  • Meeting objectives;
  • Internal audit findings;
  • Customer surveys and feedback;
  • 2nd or 3rd party audit results;
  • Competitor and benchmarking information;
  • Product test results;
  • Supplier performance information.

This ‘input’ (information and data) should reflect upon the adequacy, suitability and effectiveness of the quality management system and its processes. The ‘output’ (result of the analysis) must provide information (understanding, insight, awareness, confidence, knowledge of, etc.). The analysis output must provide insight to:

  • Customer satisfaction and perception;
  • Product conformance;
  • Process performance;
  • Product and process characteristics;
  • Trends in products and processes;
  • Opportunities for preventive action;
  • Suppliers and subcontractors.

Other potential or useful options might include:

  • Need for corrective action;
  • Opportunity for improvement;
  • Competition.

It is important to document and retain as evidence the results of the evaluation of the performance of the quality management system. The quality objectives and the related KPIs established under Clause 6.2 provides useful input into addressing this clause.

Monitoring and measuring QMS operations and activities will establish a mechanism to ensure that your organization is meeting its policies, objectives and targets. In order to meet this requirement, your organization must perform six steps:

  • Identify the activities that can have a significant impacts and risks;
  • Determine key characteristics of the activity to be monitored;
  • Select the best way to measure the key characteristics;
  • Record data on performance, controls and conformance with objectives and targets;
  • Determine the frequency with which to measure the key characteristics;
  • Establish management review and reporting.

To be read along with clause 9.1.1 of ISO 9001 Please click hear for clause 9.1.1 of ISO 9001.

9.1.2 Customer satisfaction

The organization must have a consistent and systematic approach to deal with customer feedback and is obtaining information on customer perception. Just collecting data on customer perceptions is not sufficient, it must seek and record evidence that it has analyzed and evaluated customer data and that conclusions have been made with regard to the effectiveness of the management system.

  • Are there any trends?
  • Is the situation stable, improving, or deteriorating?
  • Are customer needs and expectations changing?

A consistent and systematic approach has to be implemented to deal with customer complaints. This approach would typically include defined responsibilities for logging and tracking complaints, clearing technical issues, determining problem causes and actions to address them. Specific examples of complaints must be sampled. The link between the customer complaint process and corrective action also requires special scrutiny. Determine appropriate methods for monitoring and measuring customer satisfaction by:

  • Using customer satisfaction surveys;
  • Providing methods for receiving and dealing with customer feedback;
  • Providing suitable processes to monitoring trends in, and reviewing customer data.

To be read along with clause 9.1.2 of ISO 9001 Please click hear for clause 9.1.2 of ISO 9001. The organization must establish a procedure and all relevant records as an evidence of implementation of procedure to measure customer satisfaction. The procedure defines the process employed to monitor customers’ perceptions of the degree to which their needs and expectations have been fulfilled. The procedure must include the methods for obtaining, monitoring and reviewing this information.

Rationale for this supplement as per ISO : Requirement about documented information is added as defining processes to meet the customer satisfaction requirements is considered essential to be documented, also in view of conformity assessment activities.

9.1.3 Analysis and evaluation

 The organization must analyse and evaluate data and information, obtained either internally about the QMS and its operational process, or externally about its suppliers. Organization must develop a process (method, techniques, format, etc.) to identify, collect and analyze and evaluate data and information from both internal and external sources (i.e. quality records, monitoring and measuring results, process performance results, objectives, internal audit findings, customer surveys and feedback, 2nd or 3rd-party audit results, competitor and bench marking information, product test results, complaints, supplier performance information, etc.). This ‘input’ (information and data) should reflect upon the adequacy, suitability and effectiveness of the quality management system and its processes. The ‘output’ (result of the analysis) must provide information (understanding, insight, awareness, confidence, knowledge of, etc.). The analysis output must provide insight to:

Customer satisfaction and perception;
Product conformance;
Process performance;
Product and process characteristics;
Trends in products and processes;
Opportunities for preventive action;
Suppliers and subcontractors.
Need for corrective action;
Opportunity for improvement;
Competition.

Any record with data that is an established part of the management system may be considered relevant for analysis. Records are evidence of system performance and should be analyzed for potential improvements. 

To be read along with clause 9.1.3 of ISO 9001 Please click hear for clause 9.1.3 of ISO 9001. The organization must establish a procedure and all relevant records as an evidence of implementation of procedure for the identification, collection and analysis of data to demonstrate the suitability and effectiveness of the quality management system. Analysis must be conducted to evaluate

a)conformity of products and services;
b) the degree of customer satisfaction;
c) the performance and effectiveness of the quality management system;
d) if planning has been implemented effectively;
e) the effectiveness of actions taken to address risks and opportunities;
f) the performance of external providers;
g) the need for improvements to the quality management system

The analysis must also include data generated from monitoring and measurement, internal audits, management reviews, and other relevant sources.

Rationale for this supplement as per ISO : Requirement about documented information is added as defining processes for the identification, collection and analysis of data to demonstrate the suitability and effectiveness of the quality management system is considered essential to be documented, also in view of conformity assessment activities.

9.2 Internal Audit.

There continues to be a need to carry out internal audits and to do it effectively. The goal of an internal audit is not to determine nonconformity; its goal is to check whether your QMS:
a) complies with the requirements of ISO 29001 and the requirements of your organization
b) is effectively implemented and maintained
There is no need for an internal audit procedure but it may be useful to keep it. You do need to define audit criteria. There is more emphasis on how they are done, how feedback should be taken, and audits being corrected in a reasonable time to fix non-conformances identified. Ensuring that all the right people are included in the audit outcome. At the end of the audit, you will get audit results by evaluating the data you collected during the audit. Audit results can be manifested as positive, recommendations for improvements, and nonconformities (major and minor). Verification of actions taken to fix the non-conformity may be needed, and in that case, the next step is a follow-up audit. The audit schedule must take customer feedback into account. The organization can determine the technique of doing internal audits and the length of the intervals between the two audits is up to you. They can decide how the organization conforms to the requirement of QMS and that of ISO 29001. The organization can determine the manner by which it can maintain the system. To conduct the audit the organization must:

  1. Plan approach to internal audits based on the importance of the processes.
  2. For each audit, work out the scope of what will be covered. You can’t audit 100% of the process, but you do need to cover enough to be satisfied that the important issues have been captured.
  3. Make sure the auditors are independent of the process under audit.
  4. Report all findings to the relevant managers so there aren’t any surprises.
  5. Ensure that the corrective actions from the audit are dealt with.
  6. Retain the audit results in a document.

To be read along with clause 9.2 of ISO 9001 Please click hear for clause 9.2 of ISO 9001. While planning for the interval for the internal audit, the organization must consider the risks and opportunities and the the results of performance evaluation of the processes to be audited. The planned internal can be monthly, quarterly, annually, or according to a schedule that differs for areas or processes over the course of a year.

Rationale for this supplement as per ISO : Requirement related to planned intervals of internal audits is added to ensure that risks associated with the process and the results of performance evaluation are considered, also in view the (potential) high risk associated with operations in the petroleum, petrochemical and natural gas industries, including the supply chain which can contain several providers following a ‘cascading model (e.g. contractors and sub-contractors).

9.3 Management review.

A Management Review is a formal, structured meeting that involves top management and takes place at regular intervals throughout the year. They are a critical and required part of running an ISO 9001 Management System. The purpose of a Management Review meeting is to review and evaluate the effectiveness of your Management System, helping you to determine its continued suitability and adequacy.  At least once a year, the top-level management must review the QMS in order to determine its:

  • Appropriateness – does it serve its purpose and satisfy the needs of the organization?
  • Adequacy – does the QMS conform to standard requirements?
  • Applicability – are activities performed according to procedures?
  • Effectiveness – does it accomplish the planned results?

This review must evaluate possibilities for improvement and needs for changing the QMS, Quality Policy, and objectives. Considering the inputs for the management review, such as the results of the previous management reviews, changes in the context, customer satisfaction survey results, performance of the QMS and suppliers, etc., the top management must make decisions regarding opportunities for improvement, need for changes in the QMS, and resources needed for the upcoming period. A Management Review also ensures that all levels of management are made aware of any changes, updates, revisions, etc. to the day-to-day workings of the Management System itself. The organization will need to decide when it will take place, what will be discussed, and who should attend. You must document when the meetings have occurred and what has been discussed. A Management Review should cover the following topics:

  • Discussion on the status of any issues from the previous meeting.
  • Changes to external and internal issues that affect the Management System.
  • Examination of the performance of the Management System.
  • Review of available resources and their adequacy.
  • Examination of how effective the actions are taken towards identified risks and opportunities were.
  • Identification of further opportunities for improvement.

The inputs to the Management review should be:

  • Minutes of previous Management Review meeting
  • Management System documentation
  • Internal and External Audit Reports
  • Relevant records (including customer feedback, corrective action log, etc.)
  • Register of Legal and other requirements
  • Complaints analysis
  • Corrective and preventive actions and close-out of Management Information Reports
  • Policies review

In order to keep improving your Management System, you need to be looking for trends both inside and outside of the organization.  Consider looking for trends in the following areas:

  • The requirements of external interested parties
  • Compliance to legislation, regulations, and other requirements
  • Changes to products, services, and processes
  • Customer satisfaction and complaint records
  • Non-conformances and the effectiveness of any corrective actions taken in response

The output to the management review includes decisions and actions related to:

  • Any opportunities for improvement within the organization
  • Any changes to the Management System, processes, or policies that are required
  • Any revisions to company objectives or Key Performance Indicators (KPIs)
  • Any amendments to business plans or budgets
  • Any changes to the resources that are needed for the smooth running of the Management System

These types of changes affect day-to-day operations so it is important to keep staff informed of these changes as this will ensure that your Management System is operating effectively.

To be read along with clause 9.3 of ISO 9001 Please click hear for clause 9.1.1 of ISO 9001.

10.0 Improvement

10.1 General.

Your organization should actively seek out and realize improvement opportunities that will better enable it to achieve the intended outcomes of its management system. Potential sources of improvement opportunities include the results of analysis and evaluation of quality performance, compliance, internal audits, and management reviews. The actions for improvement can be in the form of corrective actions, training, reorganization, innovation, and so on. Improvement can be achieved through corrective actions. It can be achieved incrementally over time by a step change. It can be a breakthrough process achieved through innovation or by reorganization and transformation. There is now a requirement for organizations to focus clearly on customer satisfaction and customer needs, not only that but to look for ways to improve:
a) products and services, now and for the future.
b) fixing and controlling issues to reduce things going wrong.
c) improving the QMS.
No requirement for a procedure on preventive action. This term is removed.

To be read along with clause 10.1 of ISO 9001 Please click hear for clause 10.1 of ISO 9001.

10.2 Nonconformity and corrective action.

Any nonconformity needs to be reacted upon by taking actions to control it and deal with the consequences. Once identified, a nonconformity should trigger a corrective action in order to remove the cause of the nonconformity and prevent its recurrence. The effectiveness of actions taken must be evaluated and documented, along with the originally reported information about the nonconformity / corrective action and the results achieved. We must also record the nature of nonconformities. On discovering a nonconformity, an explicit requirement is introduced for organizations to determine whether other similar nonconformities actually exist, or could potentially exist.

When something goes wrong you must:

  1. react to it by
    • do something / take action / fix it;
    • deal with the impact it had (e.g. upset customer).
  2. evaluate what went wrong to prevent it from happening again and check there are no other similar issues that could happen.

The Key now is to update risks and opportunities. Keep records of all non-conformities, what you did to resolve them, implement additional measures, etc.

To be read along with clause 10.2 of ISO 9001 Please click hear for clause 10.2 of ISO 9001. The organization must establish a procedure and all relevant records as an evidence of implementation of procedure for non conformity and corrective action.

Rationale for this supplement as per ISO : Requirement about documented information is added as defining processes for implementing the nonconformity requirements is considered essential to be documented, also in view of conformity assessment activities.

10.3 Continual improvement.

Continual improvement is a key aspect of the QMS, to achieve and maintain the Quality Management System’s suitability, adequacy, and effectiveness regarding the organization’s objectives. There is now a clearer expectation for organizations to use data from monitoring and measuring to review the organization’s performance and that of the QMS. Organizations should use this information, analyzing it and ensuring that the QMS is adequate for the organization. The impetus for continual improvement must come from the use of as a minimum:

  • Policies;
  • Risks and opportunities;
  • Objectives;
  • Analysis and evaluation of data;
  • Audit results;
  • Management review;
  • Non-conformity and corrective action.

Consider using the PDCA cycle (Plan, Do Check, Act) to guide your continuous improvement efforts. Once you’ve identified the improvement action to take, you cycle through the PDCA phases by planning the action (plan), implementing what is planned (do), monitoring the process and reporting results (check), and taking any further actions to improve if necessary (act).

To be read along with clause 10.3 of ISO 9001 Please click hear for clause 10.3 of ISO 9001. The organization must establish a procedure and all relevant records as an evidence of implementation of procedure for Continual improvement. The implementation of improvements shall be subject to management of change as per the procedure give in clause 6.3

Rationale for this supplement as per ISO: Requirement about considering implementation of improvement as a management of change process is added to ensure that this kind of implementations are taken into account as part of the plan-do-check-act cycle. Requirement about documented information is added as defining processes for implementing the continual improvement requirements is considered essential to be documented, also in view of conformity assessment activities.

Back to Home Page

If you need assistance or have any doubt and need to ask questions contact me at preteshbiswas@gmail.com. You can also contribute to this discussion and I shall be happy to publish them. Your comment and suggestion are also welcome.

Example of Procedure for QMS continual improvement

1.0 PURPOSE

The purpose of this procedure is to identify any possible failures or breakdowns, as well as opportunities for improvement.

2.0 SCOPE

This procedure applies to continual improvement in the QMS for all identified processes

3.0 Process

3.1 Responsibilities

  • Management Representative
  • Document Controller
  • Process Owner
  • Departmental Head

3.2 Identification and Basis of areas of Improvement

The Management Representative and the respective departmental heads identify the areas for improvement based on the policy and objective of the company. The areas of improvement shall also be based on:

• Corrective Action Requests
• Management review meeting output
• Audit reports
• Analysis of data

3.3 Documentation, Action Plan & Summary of Implementation

The departmental heads and where required the Management Representative shall sum-up all the areas of improvement and shall document the same in Continual Improvement Plan F 005 and the same shall be distributed to all concerned departmental heads. Respective departmental heads shall brainstorm in the departmental meetings the methodology to be adapted and the same shall be implemented and ensured that continual improvement is achieved. Respective departmental personnel shall make an action plan for the areas of continual improvement and the same shall be followed to complete the assignment on time. Respective departmental heads shall sum-up the methodology and the benefit that has been achieved by adapting the continual improvement assignment and the same shall be presented to the management during Management Review Meetings. The continual improvement shall be identified in all areas of operation and effort shall be taken to ensure that the continual improvement is on continual basis.

3.4 Training & Monitoring of Progress/ Effectiveness

Training shall be imparted to all concerned on the concept of continual improvement and the tools to be used to achieve the improvement. Effectiveness of continual improvement assignments shall be monitored and revised periodically and the same shall be discussed in MRM.

4.0 Related Documents

Continual Improvement Plan

Example of Procedure for Monitoring & Measurement of Customer Satisfaction

1. SCOPE

This procedure covers activities from the planning stage of the survey up to the presentation of survey results to Top Management and monitoring performance.

2. PURPOSE

To measure customer satisfaction in relation to the company’s quality services by conducting the Customer Satisfaction Survey at planned intervals and ensure continual customer delight.

3. REFERENCE DOCUMENTS

3.1 XXX Quality Manual,
3.2Customer Related Processes.
3.3 Procedure for Correction and Corrective Action.
3.4 Procedure for Control of Documented Information
3.5 Procedure for Handling of Customer Complaints.
3.6 Procedure for Review of Customer Requirement

4. TERMS & DEFINITIONS
a. Customer Satisfaction – customer’s perception of the degree to which the customer’s requirements have been fulfilled.
b. CA – Corrective Action
c. MR – Management Representative

5. RESPONSIBILITY AND AUTHORITY

Sales Manager is responsible for monitoring & measurement of Customer satisfaction.

6. DETAILS OF PROCEDURE

6.1 General

6.1.1 Determine, list customers for submission of the survey based on revenue contribution.
6.1.2 Attach covering letter along with the forms for distribution every 6 months (for discussion with Mgt)Encourage customers to return a response.
6.1.3 Each Customer Survey is assigned a unique number (i.e. Year-XX or 06-01, 06-02, etc.)
6.1.4 Monitor timeliness of response and response rate. Collect all accomplished survey forms after two weeks
6.1.5 Analyzes data by customer, by category, and by rating. The sales Manager gives input in the analysis.
6.1.6 Sales Manager prepares a summary report of the Customer Survey and presents it in the Management Review Meeting.

6.2 Customer Feedback/ Rating :

6.2.1 List all areas rated below satisfaction and set meeting with different Divisions to identify the cause of the problem and prepare action plans and agree on the implementation date of corrective actions
6.2.2 Customer response obtained from customers is reviewed to find out opportunities for improvements. These shall be obtained once a year. Quality rating feedback is also received from customers.
6.2.3 Level of customer satisfaction can be judged through the feedback/rating obtained, also reviewing customer’s perception captured during the visit by/to customers.
6.2.4 Get commitment from concerned divisions to implement necessary action and monitor the effectiveness of each action done.
6.2.5 Decisions and actions must be agreed upon by all parties concerned.
6.2.6 Determine if performance targets were achieved. For unmet targets, corrective/preventive actions shall be initiated to improve customer rating as per Procedure of Correction and  Corrective Action.
6.2.7 Submit complete monthly accomplishment report and performance report to immediate superior every first week of the month

6.4  Delivery Performance Monitoring

6.4.1 Summary of delivery performance shall be prepared monthly.
6.4.2 In case of delivery performance is below target reasons shall be identified.
6.4.3 Necessary actions for improving delivery performance shall be identified & follow-up shall be done.

7. RETAINED DOCUMENTED INFORMATION

7.1 Summary of delivery performance(QMS F 021)
7.2 Customer rating (QMS F 020)
7.3 Customer satisfaction survey (QMS F 026)
7.4Corrective Action Report(QMS F 023)