8. Operation
8.1 Operational Planning and Control
- The processes themselves
- The products and services they produce
- Show processes ran as planned
- Demonstrate the outputs meet their requirements
Key Control Requirements:
- Planning Output: Suitable for the organization's operations
- Change Control: Control planned changes and review unintended changes
- Mitigation: Take action to mitigate adverse effects as necessary
- Outsourcing: Ensure outsourced processes are controlled
- Multi-employer: Coordinate SHEQ management system with other organizations
The most effective control - completely remove the hazard from the workplace
Replace with safer alternatives
Design solutions that control exposure
Policies, procedures, and training programs
Last line of defense - individual protection
- Locations and surroundings
- How work is organised
- Working conditions
- Equipment
- Workforce composition
Change Management Framework:
- Change Request: Formal process for requesting changes
- Risk Assessment: Evaluate SHEQ impacts of proposed changes
- Authorization: Approval process with appropriate authority levels
- Implementation: Controlled rollout with monitoring
- Review: Post-implementation evaluation of effectiveness
Procurement coordinates with contractors to identify hazards and assess SHEQ risks across three directions:
Contractors and their workers operate inside the organisation's SHEQ requirements. Selection criteria are defined upfront, applied consistently, and include occupational health and safety performance — not just price.
Outsourced functions and processes stay under control. The arrangement is structured to satisfy legal and other obligations and to deliver the OH&S management system's intended outcomes — handing work to a third party does not hand over accountability.
Both the process and the response plans themselves are maintained as controlled documents.
8.2 Requirements for Products and Services
Before offering a product or service, the organisation confirms that:
- Applicable statutory and regulatory obligations
- Anything else the organisation itself considers necessary
Additional Requirements:
- Conflict Resolution: Contract or order requirements differing from those previously defined must be resolved
- Confirmation: Customer requirements confirmed before acceptance when no documented statement provided
- Practical Reviews: For internet sales, review can cover relevant product information such as catalogues
- Documentation: Retain documented information on review results and new requirements
8.3 Design and Development of Products and Services
Stages and controls are sized to the work. Planning factors include:
Inputs are pinned down before design starts. Typical sources:
Input requirements:
- Adequacy: Inputs are sufficient to drive the design forward
- Completeness: Complete and unambiguous
- Conflicts: Conflicting inputs are reconciled before they reach the team
- Documentation: Inputs are retained as records
Controls applied to the design and development process make sure:
Outputs of the design process:
Records cover:
Change Control Best Practices:
- Impact Assessment: Evaluate potential effects on conformity
- Authorization: Proper approval processes for changes
- Traceability: Clear documentation trail
- Communication: Inform relevant stakeholders of changes
8.4 Control of Externally Provided Processes, Products and Services
Controls on external providers apply when:
- How much the external work affects the ability to meet customer, statutory and regulatory requirements
- How effective the provider's own controls are
External providers receive clear instructions on:
- Products and services
- Methods, processes and equipment
- Release of products and services
8.5 Production and Service Provision
Controlled conditions cover, where applicable:
- What the product, service or activity is supposed to look like
- The results expected at the end
Post-delivery obligations are met. In sizing the post-delivery effort, the organisation considers:
Change Control Elements:
- Change Request: Formal documentation of proposed changes
- Impact Assessment: Evaluation of effects on conformity
- Authorization: Approved authority for changes
- Implementation: Controlled rollout of changes
- Verification: Confirmation that changes achieve intended results
8.6 Release of Products and Services
Release records cover, at minimum:
Release Process Best Practices:
- Stage Gates: Clear checkpoints throughout the process
- Verification Methods: Testing, inspection, and review procedures
- Authorization Levels: Defined authority for different types of releases
- Documentation: Complete records of release decisions
- Exception Handling: Process for emergency or special releases
8.7 Control of Nonconforming Outputs
Non-conforming outputs are handled by one or more of:
Records of every non-conformity capture:
Nonconformity Management Process:
- Detection: Systematic identification of nonconformities
- Assessment: Evaluation of impact and severity
- Containment: Immediate action to prevent further issues
- Investigation: Root cause analysis
- Correction: Fix the immediate problem
- Corrective Action: Prevent recurrence
- Verification: Confirm effectiveness of actions