Setting Up Management Systems

Overview

Setting up management systems can be daunting but using the alphaZ documents package can greatly assist with the process and also ensure systems developed are useful and easy to understand.

The az-documents.co.uk website includes a selection of different documents that have been organised by type and although all documents can be used many of them may not be relevant or necessary and some review and analysis of current systems should be completed to determine what needs to be updated, what can be improved and what is currently missing.

The best approach for setting up management systems will depend on your organisation and what is already in place but the following guidance along with the other information available in the az-documents.co.uk/Help section is provided to assist with determining the best approach.

Stage 1 Review Current Systems

When setting up management systems it is important that consideration is given to all existing good practice, processes, procedures, policies and other relevant documentation or systems so that these can be incorporated or referenced.
Some form of gap analysis / review of existing systems should be completed to establish what systems relevant to the management system are already in place and whether currently compliant with applicable standards.

Ask yourself; What currently works well and is useful?

Then complete a review of everything;
Existing form templates, documented procedures and policy documents;
Any existing management system documentation;
Details of any additional standards, industry guidelines or applicable legislation;
Any existing guidance or procedures such as work instructions, method statements, operational procedures or policy procedures;
Any other documents that may include relevant guidance or procedures such as employee contracts, staff handbooks or other documents;
Overview of products / services / operations / activities i.e. details from web site / other marketing literature;
Details of management structure and responsibilities i.e. organisational chart or responsibilities matrix and any job descriptions;
Overview of Software and other operational systems used

Image Here

Most organisations will find that the systems that they have in place to effectively run and manage their operations are consistent with ISO standard requirements and it should just be a case of taking credit for these existing systems to demonstrate ISO compliance

Stage 2 Review alphaZ Documents

There are A LOT of documents available on the alphaz documents web site but only some of these documents will be relevant or useful to your organisation and it is recommended that a general review of the documents available is completed before setting anything up to better understand what is available, what might be useful and how everything is organised. Ask yourself; What is better than what we are currently using and what would be useful and improve how things are managed?

New Image Here

All the documents available on this web site have a description and some may have comments with additional information about what they are useful for or advice regarding their use and implementation. Also review all the relevant Help pages.

Stage 3 Initial Set Up of Management Systems

In most cases the initial setup of a new or updated management system will follow these simple steps :
Download IMS1 manual, the management system filing structure and IMS1 Manual Guidance
Download all the key IMS related files and other files required;
IMS Registers, IMS Implementation Checklists
Other relevant Registers
Form Templates
Policies and Procedures
Any other checklists or other files
Update and format the files
Update and implement the management systems (Ref. Stage 4 - Update and Implement Management Systems)
IMS Filing / Folder Setup - It is important that files used are organised and that everyone understands where everything is filed and has full appreciation of the documents being used.
To assist with this a filing structure has been written into the IMS1 document and a corresponding folder structure is available which includes a printable 10 section Index sheet for use with a lever arch file if intending to prepare a paper copy.

Filing System / Evidence Folders
A good filing system can be useful for ensuring everyone within the organisation is aware of where key forms, policies and other key documents are located and also demonstrates to an auditor effective document control. A correctly mapped out filing system also helps to prevent any misfiling and potential duplication where copies of the same file are saved in more than 1 location.

The initial setup is largely a downloading, sorting and organising exercise to get the key components of the management system in place. As well as resources from alphaZ documents there will be various other resources that are already in place within your organisation that can be transferred or signposted as key components in the management system.

Update the templates - before reviewing and amending the content of the template forms and policies an initial task may be to update the header on all the files to replace the #az-documents.co.uk# text with your company details.

All the resources provided are simple to use and have instructions included or additional guidance is available in the help page Using the site.

Note : When downloading the files it may be sensible to save files that have not been used yet into a 'draft' or 'sample' folder and then transfer into actual filing system when they are put in place for use.

Company Documentation

It is important to demonstrate that your company documents are adequately controlled and managed. To achieve this all the forms supplied as part of the alphaZ package are uniquely numbered, issue controlled and also include an information classification so that confidential, business use or public documents are all clearly marked.

Policies - the ISO standards include very specific requirements regarding policies and what they must cover - the supplied policies will meet the stipulated requirements and if you intend to amend these to better reflect your organisation care needs to not remove any content that is required for ISO compliance.

Stage 4 - Update and Implement Management Systems

The IMS1 Document is the key overview document for the management system and is designed to cover all the key areas that the business manages in a logical way so that the primary function is to be a useful management system overview while also ensuring ISO compliance.

This should be the key document for your organisation by providing an overview of how your organisation is organised, what the key activities are, what other processes need to be managed and who is responsible for these key processes. Someone new to the company, an auditor or any other interested party, should be able to read this document and understand how all the key activities are managed. IMS1 management system manual.

Implementation - the IMS1 document in itself can be used for gap analysis and as an implementation checklist; if everything covered in this document is completed and correct it will ensure ISO compliance. Alternatively, there are various implementation checklists available to assist with update and implementation of management systems.

If one of the gap analysis or implementation checklists has been completed this should have highlighted any gaps and areas where further development is required and may also detail the main steps to be followed when setting up the management systems.

Linking with existing systems – the IMS1 document is intended to act as a top-level overview of the management systems and the supplied content can be deleted and replaced with references / signposts to other documents / software / systems.

Note: An understanding of the minimum requirements for ISO compliance is required if you wish to omit or alter any sections of the IMS1 document. Avoid Duplication - if documented procedures have already been prepared it is not necessary to include these in IMS1 and a summary or signpost / Link to the other document may be an easier approach. When doing this it is important that all documents follow the document management procedure in IMS1.

When preparing other documents, it is recommended that all links point upwards to the relevant section in the IMS1 document rather than having one document referencing other documents. This will then allow documents to be added / removed / renamed without having to then locate and update multiple other references.

Links - IMS1 includes links to various other files supplied as part of the alpha-z package. If these files are not being used the links should be removed or if referencing other files or documents the links can be added with orange text. Various pages in IMS1 include reference boxes to summarise links to other files.

Stage 5 - Check and Maintain

Once the management systems have been prepared and implemented various checks then need to be completed to ensure that everything is correct and accurately reflects the activities and processes within the organisation.

The main document for review will be the IMS1 manual which will provide an overview of all the other documents including a filing structure and associated files and it is therefore important that this file is properly reviewed and updated and that ownership is taken of this document. Ref. IMS1-Manual-Guidance
As well as IMS1 there may be several other files needing reviewed and updated and to assist with this it may be useful to use one of the provided implementation checklists.

Where the management systems have been prepared for ISO compliance there will be the additional requirement to have completed and documented a programme of internal audits and the internal audits can be combined with this process of reviewing and checking the management systems; completing the internal audits will also confirm that everything is correct and ready for external audit.

To assist with internal audits there are various pre-prepared audit checklists covering the ISO standards, all the sections of IMS1 or even individual processes or activities in Audit Checklists.

A further requirement for ISO certification is to have completed and documented a management review and set and documented objectives. Completing a management review using the supplied F-Q3 Management Review Form will ensure all areas for ISO compliance are covered as well as completing a review of the recently implemented or updated management systems.

B1.1 The Update Log

The Update Log should be updated whenever a significant change is made to the IMS1 manual and any related documents. Significant changes include changes in operational procedures or in the organisation chart.

Where changes to the manual are identified the following must be undertaken on the log table: -
  • The section changed must be noted
  • The date of the change must be noted
  • A description of the change must be provided
It is essential that at least one update has been made to the update log prior to audit for ISO certification. Doing so will demonstrate that the document has been effectively managed and that changes to it have been communicated.

B1.2 Integrated Management System – Overview and Scope

The Overview and Scope section communicated that the context of the organisation has been considered throughout the development of the Integrated Management System. The Scope statement will identify which ISO standards your organisation seeks to comply with, what business operations you would like certified and any exclusions from the scope.

The Overview Section

  • Summarises of all the documents that makeup the integrated management system

The Applicability and Scope Section

  • Clarifies the purpose of the management system and states the ISO standard(s) that are applicable
  • The scope of registration should include information on the services or types of products your organisation provides and may also need to reference the location of your organisation, your market and other factors
  • If certain products or services are not to be covered by the management system or are not intended to be ISO certified then they must be excluded from the scope of registration
  • If you do not intend to use an external auditor to certify your management system then you should simply produce a short summary of your main business operations in order to outline the scope of your organisation
  • Exclusions

    • You should detail any sections of the ISO standards that are not applicable and explain why the associated requirements of the standard are not applicable to your scope
    • You should only claim a requirement as not applicable if it would not affect your ability to deliver your product or service

    Useful Resources

    B.1.3 Context, Company Profile and Scope of Operations

    This section is intended to allow the company to expand on the scope and context of its operations with a more detailed overview. Is should include any company vision or goals as this will help communicate that the context of the organisation has been considered.

    Context of the organization

    • This section should provide a comprehensive summary of the scope and context of the management system
    • When writing about the context of the management system, reference ought to be made to other key IMS documents. This serves to demonstrate the continual review and documentation of the organisation’s context

    Company Profile

    This section should include information on the company including but not limited to: -
    • Introduction to the company
    • Company background
    • Number of sites (address of main site / headquarters)
    • What services / products provided
    • Overview of the requirements for your products/services/activities
    • Company vision / mission statement / goal
    • Interested parties and their requirements
    • Any other key internal / external issues

    Useful Resources

    B1.4 Interaction of Processes

    This section provides an overview of the key processes within the business and how the documentation correlates to the ISO standard. You should fill in the blanks and add boxes for your business processes to tailor this to your own business operations. This should act as a roadmap that outlines the key business processes, supporting processes and their relation to one another. In this way you can demonstrate that you understand the Process approach and the Plan – Do – Check – Act approach required of the ISO standards.

    Image Here

    B1.5 Management of Documented Information and Data

    This procedure details how documented information critical to the success of the IMS is controlled and managed. It covers how new documentation is approved to prevent the use of unauthorised documents and details the process for managing changes within documents and the process of version control. This procedure also covers data protection and backup and may be used as evidence of control measures if loss of key data has been identified as a risk for the business.

    This section provides an overview of how IMS documentation and other forms, files and documentation are managed and controlled. There is also an overview of data backup and the management of electronic information which should be updated / expanded as required. The procedure should be checked to ensure that all the information is relevant to your organisation. Some essential content related to management and retention of records is included on F-IMS20 Document Register. If this file is not to be used the records management and retention content should be covered elsewhere.

    Data Classification

    This section is only required if a risk register has identified information classification and labelling as a necessary control measure, or for ISO 27001 compliance.

    The reference to F-IMS25 Information Assets Register can be removed if completing this register is not deemed necessary or beneficial.

    Useful Resources

    B.1.6 Legal Compliance

    This section has been designed to document the legal requirements and industry codes of practice that are applicable to your organisation. It should cover at least the basic requirements for your organisation while a separate register can also be used to list applicable legislation if preferred.

    The legislation tables should be updated with key legal requirements that have been determined to be relevant. If you are unsure about the applicability of legislation or your compliance with it, you should seek competent advice for the completion of this section. #

    ISO 9001 does not specifically require you to maintain a documented legal register so the legislation listed can be simplified or removed if legal compliance can be demonstrated in other ways. If the IMS also covers Environmental and / or Health & Safety the relevant legislation should be retained.

    Useful Resources

    B.2.1 Company Policies and Objectives

    The ISO standards require that you implement relevant policies and associate d objectives. This section confirms that the company has prepared policies and objectives and references the location where they can be found and how objectives will be monitored. Policies do not need to be signed by senior management, but senior management approval is important and a signature on the policies is one way of demonstrating this.

    This page provides a summary of company policies with details of how they have been prepared where they have been stored and how they are shared with interested parties. We recommend that relevant policies should be completed and approved by senior management to demonstrate commitment to the management system and then filed centrally in the designated policies folder. The sections in yellow in the procedure should be checked and amended to show where your organisation will store and display policies.

    Objectives

    It is important for ISO compliance that relevant, measurable objectives are documented and that arrangements are in place to ensure that these objectives are being reviewed and managed effectively. The recommended minimal approach towards demonstrating this is to include the setting and review of objectives as part of management review but this section can be updated if alternative or additional processes are in place for the management of objectives.

    Useful Resources

    • Management Review
    • Company Objectives
    • Worker-Red-Understood


    • Company policies:

      B.2.2 Responsibilities

      This section provides an overview of the key responsibilities within the organisation in terms of specific people and job roles. Review the responsibilities and ensure titles such as IMS Lead and Managing Director are correct. Amend if necessary.

      Any other key roles or job descriptions relevant for the IMS should be included in this section as required.

      This section is important in showing that you have considered responsibilities with regards to the management system and have determined who will act as the IMS Lead and have overall responsibility for ensuring the ISO standards are met and the management system is maintained. This section also commits your top management to being responsible for the success of your IMS which is a key focus of the ISO standards.

      To meet the ISO standard requirements, top management must be responsible for the following:
      • The effectiveness of the IMS
      • Ensuring the policies and objectives are established (and appropriate for the company)
      • Ensuring the ISO requirements for the IMS are integrated into business processes
      • Encouraging risk-based thinking within the organisation and the use of the process approach
      • Making arrangements to ensure the IMS has adequate resources
      • Communicating the importance of running an effective IMS and meeting the ISO requirements
      • Ensuring the IMS achieves its intended and planned results
      • Engaging, directing and supporting people working with the IMS
      • Promoting improvement
      • Supporting other management roles necessary for the IMS
      • Maintaining the focus on enhancing customer satisfaction throughout the organisation
      • Communicating responsibilities and authorities within the organisation and ensuring these are understood

      Useful Resources



      B.2.3 Organisational Chart

      The Organisational Chart outlines who is responsible for specific issues and who the designated IMS lead is. The chart communicates the levels of authority within the organisation and any specific responsibilities that employees have (e.g., Quality Representative).

      Image Here



      The organisation chart should provide an overview of the key roles within your organisation. If you already have an organisation chart you can replace this chart with a reference to its location or copy it into this section. Any employees with specific responsibilities (e.g. Customer Liaison Officer or Quality Representative) can be highlighted on the chart if not already detailed in 2.2.

      It is important that the roles and responsibilities displayed on the organisational chart are communicated and understood within your organisation. Ensuring your employees are aware of your organisation chart will help meet this requirement. The chart could be displayed on a notice board within the office, communicated to workers during their induction or the company could ensure the IMS1 Manual is made available to all workers.

      B.2.4. Management Review Procedure



      This procedure provides an overview of the management review process and may not need any amendment or additional information added. Follow this procedure regarding your management review to ensure that you are compliant with the ISO standards.

      A management review does not necessarily involve holding a single meeting with all management at the same place and time and can be completed remotely or over a longer period. The ISO standards only stipulate that such a review must be documented.

      It is important to note that the management review is very important for ISO compliance and not just to satisfy the clauses relating to management review. It may be seen from the correlation documents that the management review is used as evidence of compliance with a wide range of ISO clauses.

      It is also worth noting that suppliers can be reviewed annually during your management review unless they have already been appraised. This should include a review of the controls you have on your suppliers and an assessment of whether these controls are effective.

      B.2.5. Risk Management

      This procedure provides an overview of the overall risk management processes in operation within the organisation. This section should be amended to reflect the actual processes in operation, or entirely removed if not required.

      B.3.1 Management of Staff and Company Personnel

      This procedure outlines how you will manage staff and labour-only sub -contractor competence in your company. In essence this means how you will demonstrate that people working for the organisation or on its behalf will have the necessary competence and skills to do the jobs that are required of them.

      ISO Awareness

      Using the referenced forms will provide evidence that all workers have been given training in the integrated management systems. If they are not used then consideration must be given as to how this can be evidenced.

      This procedure covers new employees’ induction, how training records will be retained and how training will be delivered and reviewed. Sub-contractors completing work on your behalf can be added to the training matrix – ER2 Training Matrix -and their competence monitored similarly to directly employed staff.

      Data Protection

      Some of the forms referenced in this section will include personal data and it is important that information classification and labelling of these forms and the protection of personal data is completed as per this procedure and 1.5 Management of Documented Information and Data.

      Useful Resources

      B.3.2 Management of Equipment and Premises

      This section provides an overview of how any equipment or facilities are managed. You should add any other categories of equipment to the list that are applicable to your organisation. If you have a large quantity of equipment or equipment requiring calibration it is recommended that an overview register such as the ER4 Equipment Register is completed to ensure that dates for checks are well managed and that this can be readily demonstrated during audit.

      All the references on this page can be removed if they are not required or this section can be updated to reference any existing equipment checklists, software or systems that are in place. Additionally, the procedure also includes a reference to a checklist for logging ongoing checks and inspections. Use of ongoing documented checks of emergency equipment, security and other checks may be useful evidence for ISO 14001, ISO 45001, or ISO 27001 compliance. Reference to IT Equipment and logins register can be removed unless required for ISO 27001 compliance.

      Ensuring that equipment is well maintained can prevent problems with them that could affect operations. Checking equipment and maintaining records that demonstrate this can also be a legal requirement.

      It is important to ensure that the content in this section is consistent with any requirements listed on 1.6 Legal Compliance. Furthermore, equipment used for monitoring or measuring should be maintained as required by the ISO standards. Calibrated equipment must be identifiable so you can determine its status with regards to calibration. The equipment must also be protected from unintended adjustments, deterioration, or damage – if any of these happen, it could affect the measurement results you take and possibly invalidate its calibration.

      Useful Resources

      B.3.3 Management System Communication

      This section documents how communication on the management system (and its requirements) will be managed. The table outlines: what should be communicated; to whom this should be communicated; how this should be communicated; and who is responsible for ensuring this communication is achieved. It should be reviewed and updated to reflect how communications are managed within your organisation. Edit the responsibility column if you wish to change who is responsible for certain internal and external communications.

      While this section is intended to formally clarify and document how communications are managed it is also important for ISO compliance. There is a reference to Communications Policy which should be in place, or the reference removed and you must ensure that details for any external communications and legal obligations for communications are updated and consistent with 1.6 Legal Compliance.

      Communication with your customers and suppliers must include information on: -
      • Your products/services
      • How your products/services will be approved – including any approval of methods/equipment and product release
      • Necessary competence of workers
      • How you will interact with the supplier (e.g., communication frequency)
      • How you will monitor and control their performance
      • If you plan to verify or validate anything

      Useful Resources

      B.4.1 Control of Enquiries & Sales

      This procedure should be reviewed in detail and amended to match the current processes within your organisation for managing initial customer contact and sales, or replaced with your own procedure.

      All the registers and forms on this page can be removed / replaced with references to existing processes for managing enquiries and sales.

      Additional Information

      Many companies will have a department or person responsible for managing customer enquiries, most of which may be sales enquiries. This procedure provides the basics, or more an example, of how to handle customer enquiries.

      Enquiry Conversion rate – enquiry conversion rate can potentially be used as a measurable objective i.e. % of enquiries converted, % of enquiries responded to within stipulated time frame etc... The referenced ER7 Enquiry / Quote Register includes analysis of enquiries to assist with this.

      When processing your enquiries you must check that organisational and other requirements can be met. To meet ISO requirements this includes checking:
      • Any requirements stated by the customers, for example regarding delivery and any activities after delivery
      • Any requirements needed for the use/purpose of product/service (if not stated by the customer)
      • Your own organisational requirements
      • Legal, statutory, or regulatory requirements that apply to your products/services
      • Useful Resources

        B.4.2 Control of Purchasing

        This is an outline procedure that should be reviewed and amended to detail your organisation’s procedure for controlling purchasing and Goods-In checks.

        The key components of this procedure are that you need to communicate: -
        • How you control your outsourced services (suppliers) – what criteria you use to select them and how their performance is monitored and reviewed
        • Where products / components are bought
        • An overview of the Goods-In checking process, highlighting the quality control points within this procedure to show that products are checked to satisfy that quality standards have been met

        Approved Suppliers List

        This procedure outlines the basic process for the management of purchasing, from selecting suppliers to receiving goods / services and any quality checks. Any company that purchases goods that are incorporated into the company’s own products / services or uses an external provider (third party / sub-contractor) for any of their operational processes should ensure they have a purchasing procedure in place to show how they are controlling this. It is not necessary to prepare a new or separate approved suppliers list for ISO compliance. As such, this section can be updated to reflect where an approved supplier listing is currently held, including within accounts software.

        It is important that if using other systems that this procedure reflects how suppliers are managed including: -
        • initial approval and ongoing review
        • monitoring and how supplier issues are logged and managed


        If accounts software does not facilitate management of all information pertaining to supplier capabilities, performance or required certification(s) or insurance(s) then an additional ‘key supplier’ register may be required.

        Some key elements of supplier management are included on ER3 Key Supplier / Contractor Register which provides additional details on requirements for suppliers and any additional checks required for key suppliers or sub-contractors. If ER3 is not being used this file should be reviewed to ensure these requirements are incorporated or already covered elsewhere.

        Reference to OH&S appraisal can be removed if not required (may be required for ISO 45001 and if certain activities are outsourced). If no incoming materials inspection is completed this section can be amended / removed. Information Security in supplier relationships section can be removed if not meeting ISO 27001 requirements.

        Useful Resources

        If your organisation does not have accounts software you can use the ER6 Purchase Order Register to generate purchase orders.

        B.4.3 Control of Operations

        This procedure provides a basic template for documenting the overall provision of products / services or a specific operational process.

        First determine the operational processes you undertake that would benefit from having a documented procedure. Documented procedures covering every process and function are not required. However, we recommend that procedures are prepared for the main operational processes to highlight the key quality checks and controls in place. After the main operational processes have been determined, this procedure can be used as a starting point for you to create your own procedure.

        If you are unsure about this process, we recommend that you appoint an external consultant to assist you with creating operation procedures. Any changes in the provision of your products or services should be controlled and reviewed and done so at the level to ensure you meet your conformity requirements. You should also ensure that documented information is maintained on the results arising from the review of the changes that have been completed along with the identity of the person who authorised the change. If any actions result from the review this should also be documented. You must ensure that you have included adequate detail of any in-process or final inspection and any documentation requirements are detailed in this procedure.

        Operational Procedures

        If more detail is required or you are documenting multiple procedures, covering different activities then this can be documented by referencing separate operational procedures from section 4.3.2. Operational procedures can be prepared using the OP-0-00 Operational Procedure template . Procedures can be listed in the table below box 4.3.2. The advantage of using this approach is that the individual procedures can then be written and managed by the responsible person who may not have permission to make updates to the IMS1 document. There is no limit to how many procedures can be added.

        Some things that you should ensure you include in this section: -
        • Information on the controls you will put in place on product release, delivery and post-delivery activities (where applicable)
        • Information on how you will identify your outputs if this is required to check for conformity. Also, if traceability is a requirement within your organisation, you should control the unique identification of your outputs (and retain documented information of this). This should be detailed in section 4 if applicable
        • If you handle customer property (e.g., tools, materials) you should outline in one of your operational procedures how you handle it – it must be identified, verified, protected and safeguarded
        • Information on how you make sure products are received by customers intact and as intended, for example how you package, store, identify and transport goods
        • Information on post-delivery activities where relevant – this includes things like issuing warranties, providing maintenance services or supplying recycling/take back services for end of use products
        • Useful Resources

        • Operational Procedure

        B.4.4 Management of Change, Variations and Design

        Management of change and variations overview should be updated to reflect how this is managed within your organisation. There are various ISO requirements for demonstrating that change is effectively managed, and consideration of risks should be detailed for ISO 45001 compliance.

        Design

        In some companies there is no control over design or any design activities – in these cases this section may not be applicable, can be removed and section 1.2 of IMS1 should be updated to detail that “Design is not Applicable”. If your organisation deals with design, then this procedure should be reviewed and amended to ensure that it reflects your design and development processes. Any existing design form you have should be issue controlled and referenced withing this procedure where relevant. If you currently have your own design procedure, this can replace it if you feel confident that it meets the ISO requirements.

        Useful Resources

        B.5.1 Customer Satisfaction

        This procedure provides an overview of how customer feedback is collected, and satisfaction monitored. You should review the procedure and detail any informal or formal methods used to gather feedback from customers / service users.

        It is not necessary to use the referenced form (F-Q12 Customer Questionnaire). However, if feedback is collected using different methods or forms then the procedure should be amended to detail this process. It is important that the procedure by which you collect feedback details the process that is followed if negative feedback is received i.e., ensure there is a reference to 5.2 Control of Nonconforming Outputs, Problems and Complaints and the criteria for classifying feedback as negative.

        Useful Resources

        B.5.2 Control of Nonconforming Outputs, Problems and Complaints

        This procedure outlines the process for managing problems. Problems can arise from internal issues, customer complaints, supplier and other external issues and nonconforming products or process outputs. Significant problems should be logged and resolved and this procedure outlines how this should be done. You should review the procedure and ensure that it is appropriate for your business operations and current practices regarding the management of problems and issues.

        The procedure makes several references to ER1 Issues Actions Register which is central to how issues are logged, managed, and reviewed in IMS1. If you currently use another system to record issues then the procedure should be amended to show this but care should be taken to ensure that all areas covered by this procedure and required by the ISO standards are covered.

        There is no requirement to use ER1 but it may be a useful tool in keeping track of issues and demonstrating that identified issues are being dealt with and reviewed. It is also worth considering the benefits of using ER1: -
        Root Cause Analysis
        Although the ISO 9001 standard doesn't specifically mention root-cause-analysis many certification bodies will expect to see further review and root-cause-analysis of problems. ER1 includes a section specifically for completion of root cause analysis.
        Analysis of problems
        ER1 also includes analysis of problems by category and significance which could be used as a measurable objective.

        Useful Resources

        B.5.3 Management System Audits

        This procedure documents how internal audits will be managed including the development of an audit schedule / plan, completion of audits, reporting on the success of audits and review of findings from audits. Following this procedure will ensure compliance with the ISO requirements with regards to internal audits. It is important to note that there are two versions of the audit schedule referenced and this should be amended to detail which audit schedule you are using. While this procedure may not require additional information or amendment from you it is essential that you ensure that it is clear on how the findings from audits are reported and how you will manage activities associated with the auditing process.

        • Audit Schedule
        • Audit Checklist
        • B.5.4 Continual Improvement

          Continual improvement is an ISO requirement but it is not necessary to have a documented procedure detailing how this is achieved. Regardless, this procedure will provide an overview of the various mechanisms for achieving continual improvement and you should amend it to reflect the actual processes your organisation utilises. Alternatively, you can remove the procedure if you if intend to communicate the processes for continual improvement in your organisation in another way.

          Useful Resources

          B.6.1 Commitment to Environmental Protection

          This section documents the key elements that must be considered as part of your IMS to meet ISO 14001:2015. It also points to other sections in the manual where certain ISO 14001 requirements have already been covered.

          This section should be reviewed to add any additional information relevant to your commitment to protecting the environment in this section or reference any other relevant environmental forms/procedures. You should ensure that the section relation to environmental updates is followed / amended to reflect how updates are received.

          Useful Resources

          B.6.2 Environmental Assessment

          Aspects and Impacts Significance Procedure

          You should amend this procedure to detail the process for the identification and assessment of environmental aspects. There are two forms referenced and either or both can be used or amended to reference where this is documented.

          In some circumstances it may be necessary to assess each environmental aspect in detail (e.g. if there are few aspects to consider or a wish to document more information on a specific aspect). In these cases form F-ENV3 Environmental Aspect Assessment should be used. However, some companies may prefer a register format to assess and detail all environmental aspects in one document and the F-IMS60 Environmental Aspects Register has been designed for this purpose. Significant aspects that have been identified can be listed within the table at the bottom of the procedure or the table can be deleted if its not required.

          Life Cycle Perspective

          This is a requirement of the ISO 14001 standard and the F-ENV6-Environmental Life Cycle form should be completed to demonstrate compliance. Alternatively, this section should be amended to detail how life cycle perspective is reviewed in your organisation.

          Useful Resources

          B.6.3 Environmental Incident Prevention & Management

          Follow this procedure to ensure you are controlling potential environmental incidents and know how to respond if a potential environmental incident occurs. Communicating how you will respond to a potential emergency demonstrates a level of environmental preparedness that is required by ISO 14001.

          You should ensure that any ongoing inspection and checks are detailed and remove the reference to F-Q26 Premises Monthly Checklist if this document is not being used. Furthermore, the contact numbers listed should be reviewed and amended or this section can be removed if this is not necessary or has already been covered elsewhere such as in a disaster recovery plan.

          Useful Resources

          B.6.4 Environmental Procedures and Arrangements

          The purpose of this section is to allow all relevant procedures and other files relating to environmental management to be listed and summarised while allowing these separate procedure documents to be held and managed elsewhere.

          This section should be amended to detail any environmental policy-procedures or other documents, records or registers that are relevant to environmental management. You should amend the listing and add anything else that is relevant and remove references to anything that is not required.

          Useful Resources

          • Policy-Procedures
          • Waste Matrix
          • COSHH Register
          • B.7.1 Commitment to Health & Safety at Work

            This section provides an overview of the overall Occupational Health and Safety (OH&S) arrangements in place within the organisation as well as an overview of the main elements within the Integrated Management System that relate to OH&S. Update the listing / references to other OH&S documentation to ensure that this details all the relevant OH&S documentation and systems and update the statement of intent to reflect OH&S priorities within your organisation.

            Health and Safety Policy

            Since having a health & safety policy is a legal requirement many companies will already have a policy in place. Often this ‘policy’ may take the form of a large document detailing arrangements, procedures, and other OH&S activities. If this is the case and this document is to be retained it may be necessary to prepare an additional ‘Health & Safety Policy Statement’ which can cover the ISO 45001 requirements, and IMS1 will need to be updated to remove any duplicate content and to point at the other policy. Some modification of the other policy may also be necessary to ensure the document conforms with all the document control and other requirements detailed in IMS1.

            Useful Resources

            B.7.2 Health and Safety at Work – Guidance and Arrangements

            This section provides a more detailed overview of the OH&S arrangements in place and covers areas that may be necessary for compliance with health and safety law and to meet ISO 45001 requirements. Care should be taken when updating this section as all the content has been compiled to ensure compliance. Competent advice should be sought for all legal compliance related content and the ISO correlation / ISO standard referenced.

            Whistleblowing / Right to refuse work policies

            These policies are important for ISO 45001 compliance and should be in place or an overview of arrangements for reporting unsafe practices and employees’ right to stop work if unsafe should be detailed.

            Emergency Arrangements

            This should detail what emergency equipment, checks and other arrangements are in place.

            Consultation and Participation

            It is important for ISO 45001 compliance that there is evidence of effective consultation and participation and this section should provide an overview of how this is achieved, including an overview of health and safety committee arrangements. It is also worth amending any existing documentation used to log training with workers to add a section for feedback / comments from workers to demonstrate that all interactions, including training, facilitate 2-way communication.

            Useful Resources

            B.7.3 Health and Safety Procedures

            This section provides a short overview of the health and safety arrangements in the form of a procedure to detail the actions that are required where essential requirements are not being met. This procedure should be reviewed and can be amended or removed if not required. Forms referenced should be in place or references removed if not required.

            Toolbox Talks

            The term ‘toolbox talks’ is usually used to refer to the provision of guidance / training on work or construction sites. The key principle is that when guidance / training is provided to workers they should sign the sheet to acknowledge that this training / guidance has been received and understood. The provided F-Q7 Training Talk Attendance form also includes a section to collect comments / feedback which is useful for demonstrating consultation / participation.

            PPE issue

            It is important that records are retained for the issue of health and safety equipment and the relevant form should be completed and retained.

            Useful Resources

            B.7.4 Accident, Incident and Near Miss Reporting

            This section provides an overview of the arrangements in place for the reporting of accidents, incidents and near misses. You should amend this procedure to reflect the actual processes within your organisation. Alternatively, if you have detailed your processes elsewhere you should amend this section and signpost to where you have laid out your processes. It is worth using this section to ensure that all the areas it lists are covered in your documentation. In addition, you must ensure that you clearly define and communicate the documents and processes that are to be utilised and followed in reporting incidents, accidents and near misses to all workers. You may also have legal obligations in response to certain types of incidents and should detail this.

            Logging of accidents

            Many organisations make use of an accident book for logging accidents and this book usually kept in a central location so that all workers can access it. It is important that there is a clear process in place for what needs to be done once an accident has been logged as the completed report will be data protected and further follow up may be required.

            Accident Statistics

            It may be necessary to compile accident statistics and this can also be useful as a measurable health and safety objective. A register for logging and analysing accident - ER18 Accident Statistics - statistics is available to assist with this.

            Near Miss Reporting

            This can be a useful as evidence of effective preventative action and various schemes can be considered to encourage or facilitate near-miss reporting.

            Useful Resources

            • Accident and Incident Reporting Training Talk
            • Accident Report Form
            • Accident Statistics Register
            • Accident Reporting Procedure
            • Near Miss Reporting Form
            • Significant Problem/Incident/Complaint Form
            • B.7.5 Hazard Identification and Risk Assessment

              This section provides an overview of the various processes in operation for the identification and mitigation of hazards and risks. The operation of, and compliance with, these processes is reliant on the use of the supplied Risk Assessment forms and ER14 Hazard Risk Assessment register. If you choose not to use these files then it is important that they are reviewed and that all considerations are incorporated into existing systems to ensure compliance with ISO 45001.

              Risk Review and Consultation

              It is important that the Hazard and Risk Assessment process includes participation and consultation with workers or those affected and that there are mechanisms for review or risks when anything is changed or in advance where changes are planned.

              Useful Resources

              B.7.6. Health & Safety Procedures and Policies

              This section should be amended to detail any Health & Safety policy procedures or other documents, records or registers that are relevant to OH&S. You should amend the listing, add anything else that is relevant and remove references to anything that is not required.

              The purpose of this section is to allow all relevant procedures and other files relating to environmental management to be listed and summarised while allowing these separate procedure documents to be held and managed elsewhere.

              Useful Resources

payment logos