Home > ISO Systems > ISO 9001 > Operation

8. Operation

8.1 Operational Planning and Control

8.1.1 General
Operational processes — the ones that produce products and deliver services — are planned, run and controlled around five anchors:
1 Defining what the products and services have to do
2 Setting acceptance criteria for:
  • The processes themselves
  • The products and services they produce
3 Identifying the resources needed to deliver against those requirements
4 Running the processes against the criteria — not around them
5 Capturing and retaining records that:
  • Show processes ran as planned
  • Demonstrate the outputs meet their requirements

Key Control Requirements:

  • Planning Output: Suitable for the organization's operations
  • Change Control: Control planned changes and review unintended changes
  • Mitigation: Take action to mitigate adverse effects as necessary
  • Outsourcing: Ensure outsourced processes are controlled
  • Multi-employer: Coordinate SHEQ management system with other organizations
8.1.2 Eliminating Hazards and Reducing SHEQ Risks
Hazard control follows a fixed hierarchy. Higher options are tried first; PPE is the last line of defence, not the first answer.
Eliminate the hazard

The most effective control - completely remove the hazard from the workplace

Substitute with less hazardous processes, operations, materials or equipment

Replace with safer alternatives

Use engineering controls and reorganization of work

Design solutions that control exposure

Use administrative controls, including training

Policies, procedures, and training programs

Use adequate personal protective equipment

Last line of defense - individual protection

8.1.3 Management of Change
A defined change process governs both temporary and permanent changes that touch SHEQ performance. Triggers include:
1 New or modified products, services and processes — covering:
  • Locations and surroundings
  • How work is organised
  • Working conditions
  • Equipment
  • Workforce composition
2 Changes in legal or other applicable requirements
3 New knowledge or evidence about hazards and SHEQ risks
4 Advances in knowledge or technology

Change Management Framework:

  • Change Request: Formal process for requesting changes
  • Risk Assessment: Evaluate SHEQ impacts of proposed changes
  • Authorization: Approval process with appropriate authority levels
  • Implementation: Controlled rollout with monitoring
  • Review: Post-implementation evaluation of effectiveness
8.1.4 Procurement
8.1.4.1 General
Procurement is run as a controlled process — what comes in from suppliers has to conform to the SHEQ management system, not just to commercial terms.
8.1.4.2 Contractors

Procurement coordinates with contractors to identify hazards and assess SHEQ risks across three directions:

1 What contractor activities do to the organisation
2 What the organisation's activities do to contractor workers
3 What contractor activities do to other parties on site
Contractor control:
Contractors and their workers operate inside the organisation's SHEQ requirements. Selection criteria are defined upfront, applied consistently, and include occupational health and safety performance — not just price.
8.1.4.3 Outsourcing
Outsourcing control:
Outsourced functions and processes stay under control. The arrangement is structured to satisfy legal and other obligations and to deliver the OH&S management system's intended outcomes — handing work to a third party does not hand over accountability.
8.1.5 Emergency Preparedness and Response
Emergency preparedness is run as a defined process. Seven elements anchor it:
1 A planned response to credible emergency scenarios, including first aid provision
2 Training so the planned response can actually be executed
3 Drills and exercises run on a defined cadence
4 Performance review and revision — particularly after a drill or a real event
5 Communication to all workers about their duties when something goes wrong
6 Communication to contractors, visitors, emergency services, authorities and — where relevant — the surrounding community
7 Building the response with input from interested parties whose capability or involvement matters
Documentation:
Both the process and the response plans themselves are maintained as controlled documents.

8.2 Requirements for Products and Services

8.2.1 Customer Communication
Customer communication is structured to cover, at minimum:
1 Information about products and services
2 Enquiries, contracts and orders — including changes
3 Feedback and complaints
4 Handling and control of customer property
5 Contingency arrangements where the situation calls for them
8.2.2 Determining the Requirements for Products and Services

Before offering a product or service, the organisation confirms that:

1 The requirements are clearly defined — covering both:
  • Applicable statutory and regulatory obligations
  • Anything else the organisation itself considers necessary
2 It can actually deliver on the claims it is making
8.2.3 Review of the Requirements for Products and Services
8.2.3.1 Before committing to supply, the organisation runs a review to confirm it can meet the requirements. The review covers:
1Requirements stated by the customer — including delivery and post-delivery
2Requirements the customer didn't state but that are needed for the intended use, where known
3Requirements the organisation itself adds
4Applicable statutory and regulatory requirements
5Any contract or order terms that differ from earlier discussions

Additional Requirements:

  • Conflict Resolution: Contract or order requirements differing from those previously defined must be resolved
  • Confirmation: Customer requirements confirmed before acceptance when no documented statement provided
  • Practical Reviews: For internet sales, review can cover relevant product information such as catalogues
  • Documentation: Retain documented information on review results and new requirements
8.2.4 Changes to Requirements for Products and Services
When product or service requirements change, the related documents are updated and the people who need to act on the change are told — informally drift in requirements is not allowed to take hold.

8.3 Design and Development of Products and Services

8.3.1 General
A design and development process is in place — sized appropriately for the products and services that will follow it — and is maintained over time.
8.3.2 Design and Development Planning

Stages and controls are sized to the work. Planning factors include:

Nature, duration and complexity of the design work
Required stages and the design reviews built into them
Verification and validation activities the design needs to pass
Responsibilities and authorities across the team
Internal and external resources required
How handoffs between contributors will be controlled
Whether and how customers and users get involved
Requirements for the production and delivery that will follow
Level of oversight customers and other interested parties expect
Records needed to prove the requirements were met
8.3.3 Design and Development Inputs

Inputs are pinned down before design starts. Typical sources:

Functional and performance requirements
Lessons from previous similar designs
Statutory and regulatory requirements
Standards or codes of practice the organisation has signed up to
Potential consequences of failure given the nature of the product or service

Input requirements:

  • Adequacy: Inputs are sufficient to drive the design forward
  • Completeness: Complete and unambiguous
  • Conflicts: Conflicting inputs are reconciled before they reach the team
  • Documentation: Inputs are retained as records
8.3.4 Design and Development Controls

Controls applied to the design and development process make sure:

The intended outcomes are clearly defined
Reviews check whether the outputs are on track to meet requirements
Verification confirms outputs match the inputs
Validation confirms the result works for the specified application or intended use
Issues raised in any of these activities get acted on
Records of these activities are kept
Note: Reviews, verification and validation each do different jobs. They can be run separately or combined — whatever fits the product or service.
8.3.5 Design and Development Outputs

Outputs of the design process:

Meet the input requirements
Are adequate for the production and delivery processes that will use them
Include or reference acceptance criteria and any monitoring/measurement needed
Specify the characteristics that matter for intended use and for safe, proper provision
Documentation: Design and development outputs are retained as records.
8.3.6 Design and Development Changes
Changes made during or after design and development are identified, reviewed and controlled — at enough depth to keep conformance intact.

Records cover:

The change itself
The results of the review
Who authorised it
Any action taken to prevent knock-on issues

Change Control Best Practices:

  • Impact Assessment: Evaluate potential effects on conformity
  • Authorization: Proper approval processes for changes
  • Traceability: Clear documentation trail
  • Communication: Inform relevant stakeholders of changes

8.4 Control of Externally Provided Processes, Products and Services

8.4.1 General
Anything brought in from outside — process, product or service — has to meet requirements before it crosses the boundary into operations.

Controls on external providers apply when:

1External outputs are built into the organisation's own products or services
2The provider supplies directly to the customer on the organisation's behalf
3A process — or part of one — is delivered by an external provider by deliberate decision
Provider evaluation: Defined criteria govern how providers are evaluated, selected, monitored and re-evaluated — based on whether they can deliver against requirements, not on relationships.
8.4.2 Type and Extent of Control
1Externally provided processes stay inside the management system's reach
2Both the controls applied to the provider and those applied to the output are defined upfront
3The decision factors in:
  • How much the external work affects the ability to meet customer, statutory and regulatory requirements
  • How effective the provider's own controls are
4Verification or other activities are defined to confirm the external output actually meets requirements
8.4.3 Information for External Providers

External providers receive clear instructions on:

1What processes, products or services they are providing
2Approval requirements for:
  • Products and services
  • Methods, processes and equipment
  • Release of products and services
3Competence, including any required qualifications
4How they interact with the organisation
5How their performance will be monitored and controlled
6Any verification or validation the organisation or its customer plans to do on the provider's premises

8.5 Production and Service Provision

8.5.1 Control of Production and Service Provision
Production and service delivery happen under controlled conditions, not by improvisation.

Controlled conditions cover, where applicable:

Documented information that defines:
  • What the product, service or activity is supposed to look like
  • The results expected at the end
1Suitable monitoring and measuring resources, available where they're needed
2Monitoring and measurement carried out at the right stages to confirm process and acceptance criteria are met
3Suitable infrastructure and work environment in place
4Competent people — with any required qualifications — assigned to the work
5Process validation (and periodic revalidation) where outputs cannot be fully verified after the fact
6Active controls that reduce the chance of human error
7Defined release, delivery and post-delivery activities
8.5.2 Identification and Traceability
Outputs are identified by suitable means whenever identification is needed to ensure conformance
The monitoring and measurement status of each output is visible throughout production and service delivery
Where traceability is required, outputs are uniquely identified and the records that support traceability are retained
8.5.3 Property Belonging to Customers or External Providers
Property belonging to customers or external providers — while it sits inside the organisation's control — is treated with the same care as the organisation's own assets.
Such property is identified, verified, protected and safeguarded while in use or being incorporated into the deliverable
If property is lost, damaged or otherwise unfit for use, the customer or provider is told, and the event is recorded
Note: A customer's or external provider's property can include materials, components, tools and equipment, premises, intellectual property and personal data.
8.5.4 Preservation
Outputs are preserved during production and service delivery — to the extent needed to keep them conforming.
Preservation Methods: Preservation can include identification, handling, contamination control, packaging, storage, transmission or transportation, and protection.
8.5.5 Post-delivery Activities

Post-delivery obligations are met. In sizing the post-delivery effort, the organisation considers:

Statutory and regulatory requirements
The potential undesired consequences associated with its products and services
The nature, use and intended lifetime of its products and services
Customer requirements
Customer feedback
Examples: Post-delivery activities can include actions under warranty provisions, contractual obligations such as maintenance services, and supplementary services such as recycling or final disposal.
8.5.6 Control of Changes
Changes to production or service delivery go through review and control — at the depth needed to keep outputs conforming.
Records describe the result of the review
Records identify who authorised the change
Records capture any actions that came out of the review

Change Control Elements:

  • Change Request: Formal documentation of proposed changes
  • Impact Assessment: Evaluation of effects on conformity
  • Authorization: Approved authority for changes
  • Implementation: Controlled rollout of changes
  • Verification: Confirmation that changes achieve intended results

8.6 Release of Products and Services

Verification arrangements are built into the workflow at the right stages — checks happen at the points where they actually catch problems.
Release authorisation: Products and services are not released to the customer until the planned verification has been completed satisfactorily — unless an authorised party (and, where required, the customer) explicitly approves an exception.

Release records cover, at minimum:

1 Evidence that acceptance criteria were met
2 Traceability back to the person who authorised the release

Release Process Best Practices:

  • Stage Gates: Clear checkpoints throughout the process
  • Verification Methods: Testing, inspection, and review procedures
  • Authorization Levels: Defined authority for different types of releases
  • Documentation: Complete records of release decisions
  • Exception Handling: Process for emergency or special releases

8.7 Control of Nonconforming Outputs

8.7.1 Outputs that don't meet requirements are identified, segregated and controlled — so they can't be shipped or used by accident.
Action: The response is sized to the nature of the non-conformity and the impact on the customer. The same principle applies to non-conforming products and services found after delivery, or during/after a service has been provided.

Non-conforming outputs are handled by one or more of:

1 Correction
2 Segregation, containment, return, or suspending supply
3 Informing the customer
4 Obtaining authorisation for acceptance under concession
Verification: Once a non-conforming output is corrected, it is re-verified against the original requirements before it goes anywhere.
8.7.2 Documentation Requirements

Records of every non-conformity capture:

1 What the non-conformity was
2 What action was taken
3 Any concessions obtained
4 Who authorised the disposition

Nonconformity Management Process:

  • Detection: Systematic identification of nonconformities
  • Assessment: Evaluation of impact and severity
  • Containment: Immediate action to prevent further issues
  • Investigation: Root cause analysis
  • Correction: Fix the immediate problem
  • Corrective Action: Prevent recurrence
  • Verification: Confirm effectiveness of actions