Iso Iec17021revisionbyrad20150204

3
The Revision of ISO/IEC 17021—from ISO/IEC 17021:2011 to ISO/IEC 170211:2015 Written by Randy Dougherty for the IAAR I am writing this article at the request of the Independent Association of Accredited Registrars (IAAR) in the US to inform its members of the important changes to ISO/IEC 17021. I am the vice president of the management systems accreditation programs at ANSIASQ National Accreditation Board (ANAB), as well as the chair of IAF and coconvener for ISO/CASCO WG21. History As a brief history, ISO/CASCO WG21 was formed in 2000 to develop what became ISO/IEC 17021. Among the goals of WG21 was for this new document to replace ISO/IEC Guide 62 for QMS CBs and ISO/IEC Guide 66 for EMS CBs, and to be applicable to all types of management systems. The standard was published six years later as ISO/IEC 17021:2006. All management system certification bodies (CBs) accredited by IAF MLA signatories were required to conform to this standard 2 years after publication. However, in response to concerns by several stakeholder groups, WG21 initiated a revision focused on competence. This was accomplished with the publication of ISO/IEC 17021:2011. Again, all CBs accredited by IAF MLA signatories were required to conform to the revised standard 2 years after publication. Since then, a host of new standards, considered parts of ISO/IEC 17021, have now been published which add to the generic competence requirements in ISO/IEC 17021:2011 for specific types of management systems, as follows: ISO/IEC TS 170212 for environmental management systems ISO/IEC TS 170213 for quality management systems ISO/IEC TS 170214 for event sustainability management systems ISO/IEC TS 170215 for asset management systems ISO/IEC TS 170216 for business continuity management systems ISO/IEC TS 170217 for road traffic safety management systems. There are also some additional standards that include additional competence requirements: ISO TS 22003 for food safety management systems ISO/IEC 27006 for information security management systems ISO 28003 for supply chain management systems ISO 50003 for energy management systems. The review and revision of ISO/IEC 17021:2011 was initiated in 2012. Inputs for the revision included: Outofscope comments on revision of 2006 CASCO interpretation requests IAF application documents APG and AAPG papers Outcome of WG33—ISO/IEC TS 17022 Outcome of WG37—ISO/IEC TS 17023 CASCO PAS documents 1700117005 Other CASCO documents—17020, 17024, 17065 What are the changes? To those familiar with ISO/IEC 17021:2011, the most obvious change will be to Section 9 which has been restructured. It now reads more in order of how certification services are delivered by a CB.

description

ISO 17021

Transcript of Iso Iec17021revisionbyrad20150204

  • TheRevisionofISO/IEC17021fromISO/IEC17021:2011toISO/IEC170211:2015WrittenbyRandyDoughertyfortheIAAR

    IamwritingthisarticleattherequestoftheIndependentAssociationofAccreditedRegistrars(IAAR)intheUStoinformitsmembersoftheimportantchangestoISO/IEC17021.IamthevicepresidentofthemanagementsystemsaccreditationprogramsatANSIASQNationalAccreditationBoard(ANAB),aswellasthechairofIAFandcoconvenerforISO/CASCOWG21.

    HistoryAsabriefhistory,ISO/CASCOWG21wasformedin2000todevelopwhatbecameISO/IEC17021.AmongthegoalsofWG21wasforthisnewdocumenttoreplaceISO/IECGuide62forQMSCBsandISO/IECGuide66forEMSCBs,andtobeapplicabletoalltypesofmanagementsystems.ThestandardwaspublishedsixyearslaterasISO/IEC17021:2006.Allmanagementsystemcertificationbodies(CBs)accreditedbyIAFMLAsignatorieswererequiredtoconformtothisstandard2yearsafterpublication.However,inresponsetoconcernsbyseveralstakeholdergroups,WG21initiatedarevisionfocusedoncompetence.ThiswasaccomplishedwiththepublicationofISO/IEC17021:2011.Again,allCBsaccreditedbyIAFMLAsignatorieswererequiredtoconformtotherevisedstandard2yearsafterpublication.Sincethen,ahostofnewstandards,consideredpartsofISO/IEC17021,havenowbeenpublishedwhichaddtothegenericcompetencerequirementsinISO/IEC17021:2011forspecifictypesofmanagementsystems,asfollows:

    ISO/IECTS170212forenvironmentalmanagementsystems ISO/IECTS170213forqualitymanagementsystems ISO/IECTS170214foreventsustainabilitymanagementsystems ISO/IECTS170215forassetmanagementsystems ISO/IECTS170216forbusinesscontinuitymanagementsystems ISO/IECTS170217forroadtrafficsafetymanagementsystems.

    Therearealsosomeadditionalstandardsthatincludeadditionalcompetencerequirements: ISOTS22003forfoodsafetymanagementsystems ISO/IEC27006forinformationsecuritymanagementsystems ISO28003forsupplychainmanagementsystems ISO50003forenergymanagementsystems.

    ThereviewandrevisionofISO/IEC17021:2011wasinitiatedin2012.Inputsfortherevisionincluded:

    Outofscopecommentsonrevisionof2006 CASCOinterpretationrequests IAFapplicationdocuments APGandAAPGpapers OutcomeofWG33ISO/IECTS17022 OutcomeofWG37ISO/IECTS17023 CASCOPASdocuments1700117005 OtherCASCOdocuments17020,17024,17065

    Whatarethechanges?

    TothosefamiliarwithISO/IEC17021:2011,themostobviouschangewillbetoSection9whichhasbeenrestructured.ItnowreadsmoreinorderofhowcertificationservicesaredeliveredbyaCB.

  • ThefollowingarewhatIconsidertobethreemostimportantchanges.Thisismypersonalopinion.1. ImprovingeffectivenessofoperationalandorganizationalcontrolbyCBsofremoteoffices

    regardlessoftheirorganizationalstructure2. Allowingastatement,butnomark,onproductpackaging(notonproduct)andaccompanying

    literaturethatacompanyhasacertifiedmanagementsystema. cannotimplytheproductiscertifiedbythismeansb. toincludethenameoftheCB

    3. Definingaudittimeandauditduration,andthenfocusingrequirementsforjustificationonauditduration,whichisthetimefromtheopeningtotheclosingmeeting.(OurgoalistohaveISO/IEC170211:2015consistentandharmoniouswithISO/IEC17023andIAFMD5.)

    Otherchangesareasfollows:

    Addingonenewprincipleforariskbasedapproach AdopttheapproachinISO/IEC17065andnotrequire,butstillallow,acommitteefor

    safeguardingimpartiality AdopttheapproachinISO/IEC17024regardingpublicinformationwith,orwithout,request Defining/classifyingnonconformitiesasmajorandminor Nolongerrequiringapublicdirectoryofcertifications AllowingaCBtocertifyanotherCBtoamanagementsystemstandard,exceptforaQMS IfaCBisunabletoverifyeffectivecorrectionandcorrectiveaction6monthsafteraninitial

    audit,anotherStage2shallbeconducted Sixmonthsallowedforrecertificationfollowingexpirationofcertification;otherwise,aStage2

    shallbeconducted.Whenthereisagapincertification(uptosixmonths),makingsurethecertificationdocumentsclearlyidentifythegap.

    Whenrecertificationiscompletedpriortoexpiration,theexpirationdatecanbebasedontheexistingcertification(socertificationmaybelongerthan3years)

    Iftherecertificationauditisnotcompleted,oranymajornonconformitynotverifiedbytheexpirationdate,thenrecertificationcannotberecommendedandthevalidityofthecertificationcannotbeextended

    Newrequirementforconsiderationofshiftsintheauditprogram Newrequirementwhencertifyingtomultiplemanagementsystemsstandards NewrequirementontransfersrequiringtheacceptingCBtoobtainsufficientinformationfor

    makingacertificationdecision Newrequirementfortheauditreportrequiringastatementoftheconformityandeffectiveness

    oftheMS NormativeAnnexArevisedtoincludeexpandedstatementsexplainingcompetence

    requirements,similartotheapproachinISO/IECTS170212or3.DoingthisallowedustoeliminatetheXandX+inthetable.

    WG21alsoexpandedtherequirementsfortheauditreporttakingintoconsiderationtherequirementsofISO/IECTS17022:2012ConformityassessmentRequirementsandrecommendationsforcontentofathirdpartyauditreportonmanagementsystems,andonthisbasisisrecommendingthatISO/IEC17022bewithdrawn.Forthosethatliketonumericallycharacterizechanges,RobDyewhoisanANABaccreditationassessorandinstructor,madethefollowingsummaryanalysisofchanges:

    7Newdefinitions

  • 1Modifieddefinition 1RemovedDefinition 1Newprincipal 4Modifiedprincipals 54Newrequirements* 85Modifiedrequirements* 27Removedrequirements*

    *Thisisclauses,subclausesandnotes

    Sowhat?SowhatdoesthismeantoaCBcurrentlyaccreditedtoISO/IEC17021:2011?InmyopinionitwillbeeasyforanycurrentCBtoconformtothechanges.VeryfewCBswillneedtomakeanysignificantchangestotheirprocesses.ButIalsothinknearlyallofthechangesareimprovementsandwilladdtothecredibilityandintegrityofcertification.ThelastfacetofacemeetingofWG21wasinJanuary2015.Atthismeeting,therewasalsoconsensusamongWG21memberstosupporttheIAFResolutionthatthetransitionperiodbe2yearsfrompublication.ItisanticipatednowthatanFDIS(FinalDraftInternationalStandard)willbeballotedinMarchandAprilandthatISO/IEC170211:2015willbepublishedinMayorJuneof2015.Onceissued,theFDISwillbeavailableforpurchasethroughASQ,ANSIorISO.