Home > ISO Systems > ISO 9001 > Support

7. Support

7.1 Resources

7.1.1 General
The organisation works out what resources the SHEQ management system actually needs — to set up, run, maintain and improve — and makes sure those resources are in place.

The picture is built from two sides:

1 What internal resources can deliver, and where the constraints are
2 Where external providers need to fill the gap
7.1.2 People
The right people, in the right numbers, are in place to run the SHEQ management system and keep its processes under control.

Key Considerations for Human Resources:

  • Staffing Levels: Adequate number of personnel for all processes
  • Skill Sets: Appropriate competencies and qualifications
  • Succession Planning: Backup personnel for critical roles
  • Training Needs: Ongoing development requirements
  • External Support: When to use contractors or consultants
7.1.3 Infrastructure
Infrastructure that processes depend on — and that drives product and service conformance — is identified, provided and kept fit-for-purpose over time.

Infrastructure typically covers:

1 Buildings and associated utilities
2 Equipment, including hardware and software
3 Transportation resources
4 Information and communication technology

Infrastructure Management Best Practices:

  • Preventive Maintenance: Regular maintenance schedules
  • Capacity Planning: Future infrastructure needs assessment
  • Security Measures: Physical and cyber security protocols
  • Backup Systems: Redundancy for critical infrastructure
  • Environmental Controls: HVAC, lighting, safety systems
7.1.4 Environment for Operation of Processes
The work environment that processes need — and that conformance depends on — is identified, provided and maintained.

A workable environment combines human and physical factors. Examples:

1 Social: Non-discriminatory, calm, non-confrontational
2 Psychological: Stress-reducing, burnout prevention, emotionally protective
3 Physical: Temperature, heat, humidity, light, airflow, hygiene, noise

Note: These factors can differ substantially depending on the products and services provided.

Environmental Factors to Consider:

  • Workplace Design: Ergonomic workstations and layouts
  • Air Quality: Ventilation and pollution control
  • Noise Control: Acoustic management for concentration
  • Lighting: Adequate illumination for tasks
  • Temperature Control: Comfortable working conditions
  • Safety Features: Emergency exits, first aid facilities
7.1.5 Monitoring and Measuring Resources
7.1.5.1 General
Where monitoring or measurement is used to verify conformance, the resources behind it have to deliver valid, reliable results — anything less makes the data worthless.

The resources provided are:

1 Matched to the specific type of monitoring or measurement being done
2 Maintained so they stay fit-for-purpose over time
Documentation:
Records are retained as proof that the monitoring and measurement resources are fit-for-purpose.
7.1.5.2 Measurement Traceability

Where traceability is required — or where it underpins confidence in the result — measuring equipment is:

1 Calibrated or verified, or both, at specified intervals, or prior to use, against measurement standards traceable to international or national measurement standards
2 Identified in order to determine their status
3 Safeguarded from adjustments, damage or deterioration that would invalidate the calibration status and subsequent measurement results
Invalid equipment protocol:
When equipment is found to be out of spec, the organisation works back through earlier measurements to determine which results may be compromised — and acts on what it finds.
7.1.6 Organizational Knowledge
The organisation identifies the knowledge its processes depend on — the know-how that drives conformance — and makes sure that knowledge stays available.
Knowledge is maintained and made accessible to the extent the work requires it
When needs and trends shift, the organisation looks at what it already knows, then plans how to close the gap — buying it in, hiring it, training it, or learning it

Definition: Organizational knowledge is knowledge specific to the organization; it is generally gained by experience. It is information that is used and shared to achieve the organization's objectives.

Organizational knowledge can be based on:

Internal Sources:

  • Intellectual property
  • Knowledge gained from experience
  • Lessons learned from failures and successful projects
  • Capturing and sharing undocumented knowledge and experience
  • Results of improvements in processes, products and services

External Sources:

  • Standards
  • Academia
  • Conferences
  • Knowledge from customers or external providers

7.2 Competence

Competence is managed deliberately:
1 Define the competence each role needs — for anyone doing work that affects SHEQ system performance
2 Confirm people meet that bar through education, training or experience
3 Where there's a gap, close it — and check that the action actually worked
4 Retain records as evidence of competence

Competence Management Framework:

  • Competence Mapping: Define required skills for each role
  • Gap Analysis: Identify competence gaps
  • Training Programs: Develop targeted training interventions
  • Competence Assessment: Regular evaluation of competence levels
  • Record Keeping: Maintain competence records and certifications
  • Continuous Development: Ongoing professional development

7.3 Awareness

Everyone doing work under the organisation's control — employees, contractors, on-site partners — knows:
1 The SHEQ policies
2 The SHEQ objectives that touch their role
3 How their work contributes to system performance — and what improving it unlocks
4 What happens when system requirements aren't met

Awareness Building Strategies:

  • Orientation Programs: Comprehensive introduction for new employees
  • Regular Communication: Updates through meetings, newsletters, and bulletins
  • Visual Displays: Posters, digital displays, and signage
  • Training Sessions: Specific awareness training programs
  • Toolbox Talks: Short, focused safety discussions
  • Performance Feedback: Regular updates on SHEQ performance

7.4 Communication

7.4.1 General
Internal and external communication is run as a defined process. The process answers four basic questions:
1 What gets communicated
2 When
3 Who the audience is:
  • Internally — across levels and functions
  • Contractors and visitors on site
  • Other interested parties
4 By what channel and in what format

Communication Considerations:

  • Diversity Aspects: Gender, language, culture, literacy, disability
  • External Views: Consider external interested parties' perspectives
  • Legal Requirements: Comply with communication-related legal obligations
  • Information Consistency: Ensure reliable and consistent SHEQ information
  • Response Protocol: Respond to relevant communications on SHEQ system
  • Documentation: Retain evidence of communications as appropriate
7.4.2 Internal Communication
1 SHEQ-relevant information — including system changes — flows across the organisation's levels and functions
2 The communication process gives employees a way to contribute ideas back into continual improvement
7.4.3 External Communication
External communication runs through the same defined process and respects the organisation's legal and other obligations on disclosure, reporting and stakeholder engagement.

7.5 Documented Information

7.5.1 General
The SHEQ management system carries two layers of documented information:
1 Documents the standard explicitly requires
2 Documents the organisation itself decides are needed for the system to work

Note: The extent of documented information for a SHEQ management system can differ from one organization to another due to:

  • The size of organization and its type of activities, processes, products and services
  • The complexity of processes and their interactions
  • The competence of persons
7.5.2 Creating and Updating

When documents are created or updated, the basics are covered:

1 Identification — title, date, author, reference number
2 Format and media — language, software version, graphics, paper or electronic
3 Review and sign-off for suitability and adequacy
7.5.3 Control of Documented Information
7.5.3.1 Controlled documents are managed so that:
1 They are available and usable, where and when needed
2 They are protected — against loss of confidentiality, misuse and loss of integrity
7.5.3.2 Document control covers the full lifecycle, as applicable:
1 Distribution, access, retrieval and use
2 Storage and preservation — including keeping content legible
3 Change control — version management and approvals
4 Retention and disposal

Additional documentation requirements:

  • External documents: External documents the organisation relies on for planning or operation are identified and brought under document control
  • Evidence protection: Records kept as evidence of conformity are protected against unintended changes