As 9100 2

The ISO 9000 family of quality management systems (QMS) is a set of standards that helps organizations ensure they meet customer and other stakeholder needs within statutory and regulatory requirements related to a product or service. ISO 9000 deals with the fundamentals of QMS, including the seven quality management principles that underlie the family of standards. ISO 9001 deals with the requirements that organizations wishing to meet the standard must fulfill.

Third-party certification bodies provide independent confirmation that organizations meet the requirements of ISO 9001. Over one million organizations worldwide are independently certified, making ISO 9001 one of the most widely used management tools in the world today. However, the ISO certification process has been criticized as being wasteful and not being useful for all organizations.

Background

ISO 9000 was first published in 1987 by the International Organization for Standardization (ISO). It was based on the BS 5750 series of standards from BSI that were proposed to ISO in 1979. However, its history can be traced back some twenty years before that, to the publication of government procurement standards, such as the United States Department of Defense MIL-Q-9858 standard in 1959, and the United Kingdom’s Def Stan 05-21 and 05–24. Large organizations that supplied government procurement agencies often had to comply with a variety of quality assurance requirements for each contract awarded, which led the defense industry to adopt mutual recognition of NATO AQAP, MIL-Q, and Def Stan standards. Eventually, industries adopted ISO 9000 instead of forcing contractors to adopt multiple—and often similar—requirements.

Reasons for use

The global adoption of ISO 9001 may be attributable to a number of factors. In the early days, the ISO 9001 (9002 and 9003) requirements were intended to be used by procuring organizations, such as contractors and design activities, as the basis of contractual arrangements with their suppliers. This helped reduce the need for subcontract supplier quality development by establishing basic requirements for a supplier to assure product quality. The ISO 9001 requirements could be tailored to meet specific contractual situations, depending on the complexity of the product, business type (design responsibility, manufacture only, distribution, servicing etc.) and risk to the procurer. If a chosen supplier was weak on the controls of their measurement equipment (calibration), and hence QC/inspection results, that specific requirement would be invoked in the contract. The adoption of a single quality assurance requirement also leads to cost savings throughout the supply chain by reducing the administrative burden of maintaining multiple sets of quality manuals and procedures.

A few years later, the UK Government took steps to improve national competitiveness following the publication of cmd 8621, and Third-Party Certification of Quality Management Systems was born, under the auspices of the National Accreditation Council of Certification Bodies (NACCB), which has become the United Kingdom Accreditation Service (UKAS).

In addition to many stakeholders’ benefits, a number of studies have identified significant financial benefits for organizations certified to ISO 9001, with an ISO analysis of 42 studies showing that implementing the standard does enhance financial performance. Corbett et al. showed that certified organizations achieved a superior return on assets compared to otherwise similar organizations without certification.

Heras et al. found similarly superior performance and demonstrated that this was statistically significant and not a function of organization size.  Naveha and Marcus claimed that implementing ISO 9001 led to superior operational performance in the U.S. automotive industry. Sharma identified similar improvements in operating performance and linked this to superior financial performance. Chow-Chua et al. showed better overall financial performance was achieved for companies in Denmark. Rajan and Tamimi (2003) showed that ISO 9001 certification resulted in superior stock market performance and suggested that shareholders were richly rewarded for the investment in an ISO 9001 system.

While the connection between superior financial performance and ISO 9001 may be seen from the examples cited, there remains no proof of direct causation, though longitudinal studies, such as those of Corbett et al. (2005), may suggest it. Other writers, such as Heras et al. (2002), have suggested that while there is some evidence of this, the improvement is partly driven by the fact that there is a tendency for better-performing companies to seek ISO 9001 certification.

The mechanism for improving results has also been the subject of much research. Lo et al. (2007) identified operational improvements (e.g., cycle time reduction, inventory reductions) as following from certification. Internal process improvements in organizations lead to externally observable improvements. The benefit of increased international trade and domestic market share, in addition to the internal benefits such as customer satisfaction, interdepartmental communications, work processes, and customer/supplier partnerships derived, far exceeds any and all initial investment.

Global adoption

The increase in ISO 9001 certification is shown in the tables below.

200020012020032004200520062007
409,421510,616561,747567,985660,132773,867896,929951,486
2008200920102011201220132014
982,8321,064,7851,118,5101,111,6981,096,9871,126,4601,138,155
RankCountryNo. of certificates
1China342,801
2Italy168,960
3Germany55,363
4Japan45,785
5India41,016
6United Kingdom40,200
7Spain36,005
8United States33,008
9France29,122
10Australia19,731
RankCountryNo. of certificates
1China297,037
2Italy138,892
3Russian Federation62,265
4Spain59,854
5Japan59,287
6Germany50,583
7United Kingdom44,849
8India33,250
9United States25,101
10Korea, Republic of24,778

Top 10 countries for ISO 9001 certificates (2009) RankCountryNo. of certificates1China257,0762Italy130,0663Japan68,4844Spain59,5765Russian Federation53,1526Germany47,1567United Kingdom41,1938India37,4939United States28,93510Korea, Republic of23,400

ISO 9000 series Quality Management Principles

The ISO 9000 series are based on seven quality management principles (QMP)

The seven quality management principles are:

Contents of ISO 9001:2015

A fish wholesaler in Tsukiji, Japan, advertising its ISO 9001 certification

ISO 9001:2015 Quality management systems — Requirements is a document of approximately 30 pages available from the national standards organization in each country. Only ISO 9001 is directly audited against for third-party assessment purposes.

Contents of ISO 9001:2015 are as follows:

  • Section 1: Scope
  • Section 2: Normative references
  • Section 3: Terms and definitions
  • Section 4: Context of the organization
  • Section 5: Leadership
  • Section 6: Planning
  • Section 7: Support
  • Section 8: Operation
  • Section 9: Performance evaluation
  • Section 10: Continual Improvement

Essentially, the layout of the standard is similar to the previous ISO 9001:2008 standard in that it follows the Plan, Do, Check, Act cycle in a process-based approach but is now further encouraging this to have risk-based thinking (section 0.3.3 of the introduction). The purpose of the quality objectives is to determine the conformity of the requirements (customers and organizations), facilitate effective deployment, and improve the quality management system.

Before the certification body can issue or renew a certificate, the auditor must be satisfied that the company being assessed has implemented the requirements of sections 4 to 10. Sections 1 to 3 are not directly audited against, but because they provide context and definitions for the rest of the standard, not that of the organization, their contents must be taken into account.

The standard no longer specifies that the organization shall issue and maintain documented procedures, but ISO 9001:2015 requires the organization to document any other procedures required for its effective operation. The standard also requires the organization to issue and communicate a documented quality policy, a quality management system scope, and quality objectives. The standard no longer requires compliant organizations to issue a formal Quality Manual. The standard does require the retention of numerous records, as specified throughout the standard. New for the 2015 release is a requirement for an organization to assess risks and opportunities (section 6.1) and to determine internal and external issues relevant to its purpose and strategic direction (section 4.1). The organization must demonstrate how the standard’s requirements are being met, while the external auditor’s role is to determine the quality management system’s effectiveness. More detailed interpretation and implementation examples are often sought by organizations seeking more information in what can be a very technical area.

Certification[edit]

The International Organization for Standardization (ISO) does not certify organizations themselves. Numerous certification bodies exist, which audit organizations and upon success, issue ISO 9001 compliance certificates. Although commonly referred to as “ISO 9000” certification, the actual standard to which an organization’s quality management system can be certified is ISO 9001:2015 (ISO 9001:2008 expired around September 2018). Many countries have formed accreditation bodies to authorize (“accredit”) the certification bodies. Both the accreditation bodies and the certification bodies charge fees for their services. The various accreditation bodies have mutual agreements with each other to ensure that certificates issued by one of the accredited certification bodies (CB) are accepted worldwide. Certification bodies themselves operate under another quality standard, ISO/IEC 17021, while accreditation bodies operate under ISO/IEC 17011.[

An organization applying for ISO 9001 certification is audited based on an extensive sample of its sites, functions, products, services, and processes. The auditor presents a list of problems (defined as “nonconformities”, “observations”, or “opportunities for improvement”) to management. If there are no major nonconformities, the certification body issues a certificate. Where major nonconformities are identified, the organization presents an improvement plan to the certification body (e.g., corrective action reports showing how the problems will be resolved); once the certification body is satisfied that the organization has carried out sufficient corrective action, it issues a certificate. The certificate is limited by a certain scope (e.g., production of golf balls) and displays the addresses to which the certificate refers.

An ISO 9001 certificate is not a once-and-for-all award but must be renewed, in accordance with ISO 17021, at regular intervals recommended by the certification body, usually once every three years. There are no grades of competence within ISO 9001: either a company is certified (meaning that it is committed to the method and model of quality management described in the standard) or it is not. In this respect, ISO 9001 certification contrasts with measurement-based quality systems.

1987 version

ISO 9000:1987 had the same structure as the UK Standard BS 5750, with three “models” for quality management systems, the selection of which was based on the scope of activities of the organization:

  • ISO 9001:1987 Model for quality assurance in design, development, production, installation, and servicing was for companies and organizations whose activities included the creation of new products.
  • ISO 9002:1987 Model for quality assurance in production, installation, and servicing had basically the same material as ISO 9001 but without covering the creation of new products.
  • ISO 9003:1987 Model for quality assurance in final inspection and test covered only the final inspection of finished product, with no concern for how the product was produced.

ISO 9000:1987 was also influenced by existing U.S. and other Defense Standards (“MIL SPECS”), and so was well-suited to manufacturing. The emphasis tended to be placed on conformance with procedures rather than the overall process of management, which was likely the actual intent.

1994 version

ISO 9000:1994 emphasized quality assurance via preventive actions, instead of just checking final product, and continued to require evidence of compliance with documented procedures. As with the first edition, the down-side was that companies tended to implement its requirements by creating shelf-loads of procedure manuals, and becoming burdened with an ISO bureaucracy. In some companies, adapting and improving processes could actually be impeded by the quality management system.

2000 version

ISO 9001:2000 replaced all three former standards of 1994 issues, ISO 9001ISO 9002, and ISO 9003. Design and development procedures were required only if a company does, in fact, engage in the creation of new products. The 2000 version sought to make a radical change in thinking by actually placing front and center the concept of process management (the monitoring and optimization of a company’s tasks and activities, instead of just inspection of the final product). The 2000 version also demanded involvement by upper executives in order to integrate quality into the business system and avoid delegation of quality functions to junior administrators. Another goal was to improve effectiveness via process performance metrics: numerical measurement of the effectiveness of tasks and activities. Expectations of continual process improvement and tracking customer satisfaction were made explicit.

SO 9000 Requirements include:

  • Approve documents before distribution;
  • Provide correct version of documents at points of use;
  • Use your records to prove that requirements have been met; and
  • Develop a procedure to control your records.

2008 version

ISO 9001:2008 in essence re-narrates ISO 9001:2000. The 2008 version only introduced clarifications to the existing requirements of ISO 9001:2000 and some changes intended to improve consistency with ISO 14001:2004. There were no new requirements. For example, in ISO 9001:2008, a quality management system being upgraded just needs to be checked to see if it is following the clarifications introduced in the amended version.

ISO 9001 is supplemented directly by two other standards of the family:

  • ISO 9000:2005 “Quality management systems. Fundamentals and vocabulary”
  • ISO 9004:2009 “Managing for the sustained success of an organization. A quality management approach”

Other standards, like ISO 19011 and the ISO 10000 series, may also be used for specific parts of the quality system.