What is the best way to manage non-conformance issues?

non conformance cartoonManaging non-conformance issues effectively is crucial for organizations aiming to maintain high standards of quality, safety, environmental management, and compliance. Non-conformances occur when processes, products, or services fail to meet predetermined standards or specifications. The best way to manage these issues involves a systematic approach that not only addresses immediate problems but also prevents recurrence. Here’s a comprehensive strategy:

1. Identification and Documentation

  • Early Detection: Implement processes and tools for early detection of non-conformances. This can include audits, inspections, and monitoring systems.
  • Document the Issue: Clearly document the non-conformance, including details about what happened, where, when, and the extent of the deviation from the standards.

2. Evaluation and Assessment

  • Assess Impact: Evaluate the impact of the non-conformance on operations, quality, safety, and compliance. This will help prioritize the response and resources needed.
  • Root Cause Analysis: Conduct a root cause analysis to understand why the non-conformance occurred. Techniques like the Five Whys, Fishbone Diagrams, or Failure Mode and Effects Analysis (FMEA) can be helpful.

3. Implementation of Immediate Corrective Actions

  • Containment Actions: Take immediate action to contain the issue and prevent further impact. This may involve quarantining affected products, stopping production lines, or revising processes.
  • Communicate: Inform relevant stakeholders about the non-conformance and the steps being taken to address it.

4. Development and Implementation of Corrective and Preventive Actions (CAPA)

  • Corrective Actions: Develop actions to correct the immediate issue. These actions should address the root cause identified during the assessment phase.
  • Preventive Actions: Identify and implement measures to prevent the recurrence of the non-conformance. This could involve changes in processes, training, or quality control measures.
  • Plan Implementation: Create a detailed action plan for both corrective and preventive measures, assigning responsibilities and deadlines.

5. Follow-Up and Monitoring

  • Monitor the Effectiveness: Regularly monitor the implemented actions to ensure they are effective in preventing recurrence of the non-conformance.
  • Record Keeping: Keep detailed records of non-conformances, actions taken, and results of those actions. This documentation is vital for audits, continuous improvement, and compliance.

6. Review and Continuous Improvement

  • Management Review: Periodically review non-conformance management processes and outcomes with management. Discuss patterns, systemic issues, and opportunities for improvement.
  • Continuous Improvement: Integrate lessons learned into continuous improvement processes, such as updating training programs, revising quality management systems, and enhancing monitoring tools.

7. Employee Training and Engagement

  • Training: Ensure all employees are trained on how to identify, report, and manage non-conformances.
  • Engagement: Engage employees in problem-solving and continuous improvement processes. Their input can provide valuable insights into potential solutions and preventive measures.

8. Utilize Technology

  • Software Solutions: Consider using quality management software to streamline the tracking, management, and analysis of non-conformances. This can improve efficiency, visibility, and compliance.

Effective non-conformance management is not just about solving problems as they occur but about building a culture of quality and continuous improvement. By systematically addressing non-conformances through a structured process, organizations can enhance their operations, reduce risks, and improve customer satisfaction.

How to define critical risks in your ISO Management System.

Defining critical risks in your ISO management system is an important step in effectively managing and mitigating potential issues that could impact your organization's performance and compliance with ISO standards. Here's a step-by-step guide on how to define critical risks within your ISO management system:

  1. Understand ISO Requirements: Start by thoroughly understanding the ISO standard(s) that apply to your organization. Different ISO standards (e.g., ISO 9001 for quality management, ISO 14001 for environmental management, ISO 27001 for information security, etc.) have specific requirements related to risk management. Review the relevant sections of the standard to gain a clear understanding of what is expected.

  2. Identify Relevant Risks: Identify all potential risks that could impact the effectiveness of your ISO management system. These risks can vary depending on your organization's size, industry, and specific context. Risks can include operational, financial, legal, compliance, strategic, environmental, and health and safety risks, among others.

  3. Assess and Prioritize Risks: Conduct a risk assessment to evaluate the likelihood and potential consequences of each identified risk. You can use various methods such as risk matrices, risk heat maps, or quantitative risk analysis techniques to assess and prioritize risks. Consider the following factors:

    • Probability: How likely is the risk to occur?
    • Impact: What would be the consequences if the risk materialized?
    • Velocity: How quickly could the risk escalate?
    • Detectability: How easily can the risk be detected and monitored?
  4. Define Critical Risks: Critical risks are those that have the potential to severely impact your ISO management system's objectives, compliance with ISO standards, and the overall success of your organization. They are the risks that require immediate attention and robust risk mitigation measures.

  5. Document Critical Risks: Document each identified critical risk in a risk register or risk management plan. Ensure that the documentation includes the following information:

EMS Auditor Knowledge & Skills - Sample Lesson

  bullet green arrow 25 Management System Training

bullet green arrow 25Internal Auditor Training

bullet green arrow 25Environmental Terminology

bullet green arrow 25Aspect / Impact evaluation & environmental performance evaluation

bullet green arrow 25Impact of Human Activities on the environment

Enbullet green arrow 25vironmental Media (Air, Water, Land…)
   
logo 
 


If this lesson was helpful, please visit online training site: Ingentius.com for all of the ISO courses. 

ISO 9001: The Definition of Risk within the Standard

Here is the definition of Risk in terms of the ISO 9001 Standard.  A risk can be a good thing or a challenge.  A risk can attract new customers, reduce waste, or improve efficiency. 


  0.3.3 Risk-based thinking

Risk is the effect of uncertainty and any such uncertainty can have positive or negative effects. A positive deviation arising from a risk can provide an opportunity, but not all positive effects of risk result in opportunities.

  Click Play to listen to Brandon Kerkstra  

 
 


If this lesson was helpful, please visit online training site: Ingentius.com for all of the ISO courses.

 


ISO 9001: How to Address Risk in Your QMS

How do you meet the requirements pertaining to risk in your ISO 9001 implementation.  Always be sure your stakeholders know about Risk Based Thinking 1) in your current QMS and 2) in the ISO 9001:2015 standard.


  bullet green arrow 25 Identify where you identify Risks in your organization

bullet green arrow 25Complete some training and process review with process owners

bullet green arrow 25Identify where you evaluate and address risks in your organization

bullet green arrow 25Document findings for the items above and brainstorm where you might want to add
  Click Play to listen to Brandon Kerkstra  

 
 

Was this helpful?  

If you would like to learn more about implementing Risk Based Thinking into your ISO 9001 based management system, consider taking a course on the subject.  Learn more at our online training site: Ingentius.com.

IATF 16949:2016 Lesson: Statistical Process Control

  bullet green arrow 25 STATISTICAL = Numbers and Data

bullet green arrow 25PROCESS = manufacturing processes that we can collect data (usually from the outputs)

bullet green arrow 25CONTROL = predictable behavior; with SPC results from a maintained process, the future outputs can be predicted within some boundaries

bullet green arrow 25NOTE: SPC can also tell us if a process outputs are “capable” and that means can meet requirements
   
   

Was this helpful?  

If you would like to learn more about implementing Risk Based Thinking into your ISO 9001 based management system, consider taking a course on the subject.  Learn more at our online training site: Ingentius.com.

IATF 16949:2016 Lesson - Five Phases of APQP

  bullet green arrow 25 Phases 1 through 5 represent the life cycle of product from conception through production

bullet green arrow 25Each phase has a milestone that marks the end of one phase and the beginning of the next phase

bullet green arrow 25Milestones are points of review

bullet green arrow 25Activities are on schedule

bullet green arrow 25Customer requirements are addressed
   
   

Was this helpful?  

If you would like to learn more about implementing Risk Based Thinking into your ISO 9001 based management system, consider taking a course on the subject.  Learn more at our online training site: Ingentius.com.

ISO 14001: Internal Auditor Lesson: Auditing 4.3 Scope (OE)

  bullet green arrow 25 Of the EMS Document controlled scope

bullet green arrow 25Available to interested parties

bullet green arrow 25Verify scope addresses items a through e

bullet green arrow 25Compare the Scope against the boundaries
   
   
 
Was this helpful?  

If you would like to learn more about implementing Risk Based Thinking into your ISO 9001 based management system, consider taking a course on the subject.  Learn more at our online training site: Ingentius.com.
 

IATF 16949:2016 Lesson - 0.3.1 Process Approach

Until IATF
Section 4,
the word
"SHALL"
is not
present.
 Understanding and managing interrelated processes as a system contributes to the organization’s effectiveness and efficiency in achieving its intended results. This approach enables the organization to control the interrelationships and interdependencies among the processes of the system, so that the overall performance of the organization can be enhanced.

The process approach involves the systematic definition and management of processes, and their interactions, so as to achieve the intended results in accordance with the quality policy and strategic direction of the organization. Management of the processes and the system as a whole can be achieved using the PDCA cycle (see 0.3.2) with an overall focus on risk-based thinking (see 0.3.3) aimed at taking advantage of opportunities and preventing undesirable results.
   
   


Was this helpful?  

If you would like to learn more about implementing Risk Based Thinking into your ISO 9001 based management system, consider taking a course on the subject.  Learn more at our online training site: Ingentius.com.

IATF 16949:2016 Lesson - The Context of the Orgaization (multipart lesson)

  bullet green arrow 25 External and internal issues that are relevant to its purpose and its strategic direction and that affect its ability to achieve the intended result(s) of its QMS

bullet green arrow 25Monitor and review information about these…issues.

bullet green arrow 25NOTE 1: Issues can include positive and negative factors or conditions…

bullet green arrow 25NOTE 2:  Can be  facilitated  by  considering  issues  arising  from  legal, technological, competitive, market, cultural, social and economic environments, whether international, national, regional or local.

bullet green arrow 25NOTE 3:  Understanding the internal context can be facilitated by considering issues related to values, culture, knowledge and performance of the organization.
   
 New-Arrow-Left  

Next Lesson about The Context of the Organization


  Context-of-the-Organization-Overview
  Click to play
   
 
Was this helpful?  

If you would like to learn more about implementing Risk Based Thinking into your ISO 9001 based management system, consider taking a course on the subject.  Learn more at our online training site: Ingentius.com.

Four Steps to Fix a Registrar's Non-Conformance

What do you do if you do not agree with a nonconformance written by your registrar?

4 Steps

msg non conformance area1. Take a step back and really consider the nonconformance
  • Are you overly attached to your management system or
  • Is it really Not Valid (No direct requirement in the standard) or not value added?
  • Is it really a requirement in the standard, (or your company’s defined Management System) or was the auditor auditing to their own opinion?
  • Ask the auditor to show you the requirement and explain what is missing or in conflict with the requirement. This will require the auditor to read the requirement and may give the auditor a different viewpoint on requirement and will often confirm that the issue is not a valid finding. Worst case, you will have a clearer understanding of the issue.

Define Root Cause - Sample Lesson

This is a short lesson about Root Cause and managing risks in your ISO management system.

 

purple-bullet-circleWhy did it happen

purple-bullet-circleWhy did we not catch it earlier in our system (As applicable)

purple-bullet-circleThere may be multiple root causes (See points above)

purple-bullet-circleMany methods, but the "5 Whys" is a very good standard process. Identifying the true root cause is absolutely critical to the entire process

purple-bullet-circleDo not just restate the nonconformance

purple-bullet-circleRoot Cause should be a statement of fact

purple-bullet-circleInitial versus mature system nonconformances


   

Was this helpful?  

If you would like to learn more about implementing Risk Based Thinking into your ISO 9001 based management system, consider taking a course on the subject.  Learn more at our online training site: Ingentius.com.

Effective Corrective Actions - Common Nonconformances - Sample Lesson

Review this sample Corrective Action Lesson.

 
 

purple-bullet-circleCorrective Action was not implemented, the language is all in future tense – we will...

purple-bullet-circleCorrective Action was not effective

astricks-30issue still exists or was repeated

astricks-30No evidence it was closed

purple-bullet-circleRoot cause just restates the problem

purple-bullet-circleRoot cause attempts to explain away / rationalizes issue

purple-bullet-circleOnly one of X Root Causes was addressed


   

 

Was this helpful?  

If you would like to learn more about implementing Risk Based Thinking into your ISO 9001 based management system, consider taking a course on the subject.  Learn more at our online training site: Ingentius.com.

Interviewing Techniques - 2 Minute Lesson

  bullet green arrow 25 Positive

bullet green arrow 25Prepared

bullet green arrow 25Maintain Control

bullet green arrow 25Stay out of Disputes

bullet green arrow 25Professional

bullet green arrow 25Casual

bullet green arrow 25Relaxed
 

Some Common Tips

1. Break the ice. Don't begin hammering the interviewee with questions. Everyone needs time to becom familiar with each other.  Start with something generic to build common ground with the interviewee.

2. Communicate the Objectgive. Tell the employee the objective of the audit and the purpose of the interview.  Let them know what the expectations are and ask him if he has any questions.

3. Get any background information. Letting the interviewee a chance to tell you about himself goes a long way to reducing concerns. Ask:
  • Job title
  • Scope of responsibility
  • Tenure
4. Questioning.  Start to get answers to your your questions. Try using some open ended ones. It makes the interview more conversational and less like an interrogation.

5. Summarize and paraphrase what you hear. This will:
  • let the interviewee know that you have respect
  • confirms you have "gotten it”
  • provides a chance to change the story
6. Close. After completing the interrogation and summary, you are ready to leave. But don’t just stand up and walk out the door. A little ritual is necessary here to maintain happy client relations. Before you leave, you need to:
  • Explain what happens next
  • Leave the door open for follow-up
  • Ask if the interviewee has any questions
  • Leave your business card
  • Say “Thank you”

Was this helpful?  

If you would like to learn more about implementing Risk Based Thinking into your ISO 9001 based management system, consider taking a course on the subject.  Learn more at our online training site: Ingentius.com.

Release of AIAG & VDA FMEA

Release of AIAG & VDA FMEA Handbook

The Automotive Industry Action Group (AIAG) announces the global rollout of the highly anticipated new AIAG & VDA FMEA Handbook and training.

The new AIAG & VDA FMEA Handbook for global release in Q2 2019.  It harmonizes AIAG and VDA FMEA methodologies, aligning OEM requirements, including new severity, occurrence and detection criteria within the ranking tables.

It also includes a seventh step for communicating actions taken to reduce risks. The new AIAG & VDA FMEA Handbook is a critical update for the industry.

Was this helpful?  

If you would like to learn more about implementing Risk Based Thinking into your ISO 9001 based management system, consider taking a course on the subject.  Learn more at our online training site: Ingentius.com.

The Value of a Scorecard

If you do not have a scorecard you’re missing the boat.

If you are not sure what a scorecard is go online and search for what is commonly called a “balanced scorecard.” The balance scorecard includes four elements:
  • Learning and Growth is centered on improving and growing value from your people, information, and organization.
  • Internal Business Processes to identify issues with and improve your quality and efficiency
  • Customer feedback and particularly complaints that will help you focus on customer satisfaction, new orders, etc.
  • Financial performance of your company including profit targets, budget, scrap, and cost-saving measures.
Small businesses may want to hold financial measurements “close to the vest.” Feel free to customize the scorecard to make it your own and for internal consumption throughout the company.

It’s easy to post the latest measurements on Conformance Portal for all employees to see and think about. Show them the goals and performance. Keep them informed and they will help you reach your goals. Compare the current month of your key issues to goals, previous months, and cumulative data over 12 -18 months.

As a minimum you need to have the key issues facing your company to monitor in a group setting on a monthly basis with your quality management team which should include the President, CFO, HR, Operations Manager and Quality Manager.   It may sound complicated, but it’s really not. It’s easy to set up and administer in Conformance Portal.

The value of a scorecard will show up in your bottom line.

xlsClick here to see a sample Scorecard.


Was this helpful?  

If you would like to learn more about implementing Risk Based Thinking into your ISO 9001 based management system, consider taking a course on the subject.  Learn more at our online training site: Ingentius.com.

What’s Inside AIAG / VDA’s FMEA First Edition?

This will be the first of 3 articles covering:

A high-level overview of the new AIAG / VDA FMEA Handbook
The Challenges that suppliers will encounter when working to implement the new requirements
Suggestions for implementing processes to meet the new requirements in a way that adds value, and not just additional resources and work. Overall Benefits of the new requirements and process

Today’s article features highlights of the main changes to FMEA including new requirements and potential benefits of the rewritten FMEA tool. Subsequent articles feature significant challenges faced by organizations to realign their FMEA process, and how implemented changes can add value to an organization.

Organizations performing the FMEA analysis will find this new set of requirements and process developed by AIAG and VDA to be a more global and system-based approach to the application of FMEA. This systemic approach requires an understanding and identification of the relationship between a component, subsystems, and the system.

Some of the more significant changes applicable to DFMEA and PFMEA are outlined below, though the details may be slightly different for design or process:
  • New Seven Step Process
  • Structure and Function Analysis
  • More detailed Failure Analysis
  • Ranking (RPN) replaced with Risk analysis (Action Priority)
  • Risk Analysis and Optimization versus RPN and Recommended Actions
  • Risk Communication
  • Old Form vs. New Form
  • Work Element 4M approach to Process FMEA
Other changes….

  1. Supplemental FMEA for Monitoring and System Response (FMEA-MSR)
  2. Totally revised Severity, Occurrence and Detection Tables that determine an Action Priority (AP) methodology replacing the old RPN.
  3. New form sheets (spreadsheet users) and software report views (software users) and change point highlights from both the AIAG 4th Edition FMEA Manual and the VDA Volume 4 FMEA Manual.
For DFMEAs - if an organization has good 4th Edition FMEA documentation of their existing system and subsystem, it should greatly expedite the development of the structure and function analysis portion of the new FMEA.

For the PFMEA - the 4M “Process Work Element” addresses the reviewing of failure cases due to Man, Machine, Material, or EnvironMent, which can assist in identifying more complete failure causes

FMEA work teams will find forms greatly modified with team members likely in need of training to fully understand and effectively walk through the respective new FMEA process.

A new FMEA section - Monitoring and System Response (FMEA-MSR) considers whether failure causes or modes are detected by the system or whether failure effects are detected by the vehicle driver or end user. This new section addresses Risk as it is applied to:
  • Severity of harm, any regulatory noncompliance situations, degraded or loss of functionality, or unacceptable quality.
  • Estimated frequency of a failure cause in an operational situation.
  • Possibilities to avoid or limit the failure effect via diagnostic detection & automated response, combined with human possibilities to avoid or limit the failure effect.
Benefits - the general potential benefits of this new approach to FMEA include:
  • More potential alignment of the FMEA process (Design and Process) with an organization’s overall business goals.
  • Enhanced understanding of component impacts on the larger system for DFMEA.
  • Increase in the relative understanding on the process’ effect on the larger process for PFMEA.
  • Deeper understanding of prediction and detection controls.
  • An expanded continual improvement tool & methodology that deepens understanding and knowledge of the cause and effects compared to the old method.
  • A more informed and useful lessons learned tool.
Next month, the significant challenges suppliers face are explored as they align their existing FMEA process with the new AIAG/VDA FMEA First Edition.

Was this helpful?  

If you would like to learn more about implementing Risk Based Thinking into your ISO 9001 based management system, consider taking a course on the subject.  Learn more at our online training site: Ingentius.com.

Challenges for Internal Auditors during COVID-19

internal audits during covid 192020 Challenges: What should I be focusing on with my Management Systems (Quality, Environmental, Safety, Laboratory, Information Security…)

  • What should I do to make sure my 3rd party audit goes well?
  • What should I do to help my company through these challenging times?

With the pandemic and staff working from home, the management systems (ISO 9001, ISO 14001, ISO 45001 etc.) follow through can be a challenge, as well as the internal audit and improvement processes.  Many organizations are working in smaller groups, performing more of the basic functions, and skipping some of the important documentation due to other important organizational needs. This does not leave us without opportunities to accomplish important tasks.  Here are a few suggestions that will not only create improvements and risk reduction, but will also continue to support a management system’s requirements:

  • Conduct internal audits focused on documentation and records. This can be done remotely and can also identify outdated language, redundant documentation that may not be consistent, and areas for improvement. These audits can be followed up with documentation and records process improvements. Future audits can always include increased production or manufacturing floor audits as a focus.
  • Focus the audit and risk identification processes on contingency plans. This can allow an organization to document lessons learned and improve the organizations processes and contingency plans going forward. It will likely be some time before things in most organizations really return to normal, so improvements in these areas can be valuable for an organization.
  • Management system staff and internal auditors can also assist departments and areas of the company organize and improve their processes in a changing environment. These staff are typically more trained and focused on this aspect of the work which can be of great value to many areas of an organization.
  • Some specific areas to watch:
    • IATF Temporary Change requirements
    • Automotive PPAP requirements for internal changes
    • IATF Shutdown and Startup requirements, where applicable
    • Scheduling processes where order quantities are changing
    • Changes to workflow and security requirements for staff working remotely
    • Supplier management and development – many of the above items would also apply to the organization’s suppliers, and to protect your organization, you may want to ensure you are reviewing suppliers to determine if they are proactively addressing these changes and associated risks

Environmental Regulatory Change Notification?

EPA Regulation changeThe EPA has released the Hazardous Generator Improvement Rule, Federally Implemented starting May 30, 2017, and adopted by states thereafter (Typically July 1, 2018 or July 1, 2019 or later) and Michigan as of August 1, 2020. Note that this does not only apply to organization that are ISO 14001 Certified, but any organization with any wastes. The EPA estimates, based on regular inspections, that up-to 30% of all organizations are noncompliant with these rules. One of the goals of this revision was to make the rules more understandable.

This article is not intended to be a full review of the requirements, just some highlights of the changes that affect the large number service and manufacturing organizations. There is a lot of free information available on the web. If you have any specific questions just contact us and we will assist you or point you in the correct direction for details.

Some of the changes that affect a lot of our clients are:

Common Audit Non-Conformances

Click play to listen to the Expert Brandon Kerkstra.

  • Special characteristics called out on the print are not called out in the FMEA

  • Recalculated AP based on an increased inspection frequency

  • Severity reduced on DFMEA or PFMEA without a corresponding design change

  • PFMEA recommended action with a target date of 12/01/2019 has not been implemented





  • No actions established to reduce failure modes with high APs

  • Corrective actions to customer complaints and internal audits not incorporated into the FMEAs

  • Recalculated AP is not lower than original AP

  • Permanent Corrective Action is not recorded for a reduction of the AP






  • Design and Process FMEAs not being developed per Launch process requirements

  • FMEA development has no evidence of cross functional participation (Exclusively engineering staff is not cross functional)

  • Foundation (aka Baseline) FMEAs are not updated with project specific items

  • FMEA’s and Control plans are not consistent






Was this helpful?  

If you would like to learn more about implementing Risk Based Thinking into your ISO 9001 based management system, consider taking a course on the subject.  Learn more at our online training site: Ingentius.com.

Auditing 10.2 Non-Conformance and Corrective Action (Objective Evidence)

  Verify corrective actions are verified for effectiveness

Verify records for:

bullet green arrow 25The nature of nonconformities and any subsequent actions taken

bullet green arrow 25The results of any corrective action

bullet green arrow 25Documented Problem solving & error proofing processes

bullet green arrow 25Warranty management process (Where applicable)

bullet green arrow 25Customer complaint and field failure tests analysis and communication (Includes embedded software if app.)
   
   



Was this helpful?  

If you would like to learn more about implementing Risk Based Thinking into your ISO 9001 based management system, consider taking a course on the subject.  Learn more at our online training site: Ingentius.com.

Reviewing Completed Corrective Action and Follow-up

  bullet green arrow 25 Did the containment address the objective    evidence?

bullet green arrow 25Did root cause analysis use problem solving tools such as 5 Why diagram or IS/IS Not?

bullet green arrow 25Did the Corrective Action address system   rather than incident (objective evidence)?
   
   



Was this helpful?  

If you would like to learn more about implementing Risk Based Thinking into your ISO 9001 based management system, consider taking a course on the subject.  Learn more at our online training site: Ingentius.com.

Key Characteristics with the Applying Process Approach


Click the play icon to start the audio.

Applying Process Approach - Key Characteristics


star-bulletLinks between process mapped & understood (use as audit tool)

star-bullet


Process capabilities known & tracked - not just for manufacturing (measurable, chart/data)

star-bullet


Continual improvement approaced from process perspective (top management reviews processes)

star-bullet


Processes clearly tied to strategic objectives and reviewed


Was this helpful?  

If you would like to learn more about implementing Risk Based Thinking into your ISO 9001 based management system, consider taking a course on the subject.  Learn more at our online training site: Ingentius.com.

Classifying Non-Conformances

This course takes about 45 minutes and is very useful to learn how to classify non-conformances between Major and Minor.


Slide01

Click here to download the decision tree.





Was this helpful?  


If you would like to learn more about implementing Risk Based Thinking into your ISO 9001 based management system, consider taking a course on the subject.  Learn more at our online training site: Ingentius.com.