Rolling Out ISO 19011:2018 – Guidelines for Auditing Management Systems

Administrator business man financial inspector and secretary making report calculating or checking balance. Internal Revenue Service inspector checking document. Audit concept.

ISO 19011:2018 was released in July, and the new revisions have truly transformed the contents of the standard. The changes, including most significantly a new risk-based auditing approach, recognize the importance of managing risk in any management system, as well as the marketplace.

ISO 19011 provides guidelines for auditing management systems, enabling effective auditing across multiple systems at the same time. The document offers guidance regarding:

  • The principles of auditing
  • Managing an audit program
  • Conducting management system audits
  • Guidance on evaluating the competence of those involved in the audit process, including the managers, auditors and audit teams

It can be used by any organization that needs to conduct internal or external audits of management systems, including 2nd party and supplier audits.

The new standard revision puts an increased focus on risk – a Principle of Auditing has been added into Clause 4, and a series of new sub-clauses emphasizes the standard’s new risk-based approach principle, including calls for consideration of risk and opportunities when performing an audit and managing the audit program.  

Auditors are now advised to employ a Risk Based Approach, an audit approach that considers risks and opportunities. This risk-based approach, according to the new language, should “substantively influence the planning, conducting and reporting of audits in order to ensure that audits are focused on matters that are significant for the auditee and for achieving the audit program objectives.”

This Risk Based Approach joins Integrity, Fair Presentation, Due Professional Care, Confidentiality, Independence and Evidence Based Approach as ISO 19011’s expectations.  Your certification body will want to see your knowledge of the new standard, implementation plans and timing for your company to adopt this new approach to your internal audits.

Other revisions to the standard include:  

  • Additional guidance on managing an audit program
  • Expanded guidance on conducting an audit
  • An expansion of the generic competence requirements for auditors
  • Adjusted terminology to reflect the process and not the object
  • Removal of the annex providing competence requirements for auditing specific management system disciplines
  • An expansion of Annex A to provide guidance on auditing new concepts such as organizational context, leadership and commitment, virtual audits, compliance and supply chain.  

SimpleQuE’s auditors have extensive training and experience and follow ISO 19011’s guidelines for conducting audits, can you say the same for your auditors?  Contact us for more information about training your internal auditors or outsourcing your audits.

Sign Up For Our Newsletter

SimpleQuE Attends Toyota’s 2018 Power of Exchange

Diversity drives Toyota which is why simpleQuE’s VP, Deanne Sparr, is at Toyota’s 2018 Power of Exchange – a unique supplier diversity and development conference for diverse businesses. This is a targeted networking event to gain and share knowledge and build relationships with current Toyota Tier I Suppliers like Dana Incorporated. Dana has 100+ facilities and 29,000 employees in 34 countries making it one of the world’s most influential automotive suppliers.

Over the years, a relationship was developed with Dana and in 2013 simpleQuE won the opportunity to perform IATF 16949:2009 internal audits for the Dana site in Auburn Hills, MI. That opportunity has expanded to now include internal audits and/or IATF 16949:2016 transition consulting at 10 more Dana facilities in OH, PA, IN, TN and KY. Seven of the eleven sites have already successfully transitioned to IATF 16949!

At simpleQuE we like to challenge what looks to be impossible and make quality excellence “simple.”

Associate Spotlight – Kimberly Roan

We are excited to introduce one of our newest team members, Kimberly Roan, a simpleQuE consultant.  Kimberly brings not only years of experience, but a great curiosity and drive to find the best solutions for our customers.  Here’s more on Kimberly:

What is your position and what do you do for simpleQuE?
I am a consultant for simpleQuE and I consult with clients, perform internal audits, and teach on site training on automotive QMS topics.

What do you like most about working for simpleQuE?
This is an opportunity to make a difference.  Every day I get to help clients identify issues and improve processes.  Sustained process improvements lead to greater customer satisfaction and improved effectiveness and efficiency in the organizations we work for.

What is your favorite QMS standard and why?
My favorite QMS standard is ISO 9001:2015.  This standard builds the foundation of an effective QMS and is the cornerstone for a series of important industry QMS standards.

What attracted you to simpleQuE?
Top managers who understand QMS development and believe in simple, sustainable, and value added quality management solutions.

What expertise do you bring to simpleQuE’s clients?
I spent 17 years in automotive and was always involved in auditing both first and second party and spent many years participating in 3rd party audits and acting as the management rep. If I could draw you a picture, I would show you a pyramid that includes a 17 year work experience – base, and approximately 8 year formal education – middle, and a 3 year certified auditor – crown. The large sections of the pyramid underpin everything I knew to make me an effective auditor. With this balanced experience I can provide clients with answers from a company management perspective, an internal auditor perspective and a third party auditor perspective. Every day I use the whole pyramid but the biggest part of it will always be my work experience.

What was your first job?
My first automotive job was part time administrative assistant for an engineering team at Saturn.  My first job ever was doing office work for a neighbor in direct sales at the age of 12 to 13.

Have met…
John Glenn, in an elevator at a Marriott hotel.  We talked about Harley Davidsons and how he wouldn’t get one now because he promised his wife he was done with high risk activities.

Where did you go to college?
Baker College of Flint for my Mechanical Engineering degree and The Chicago School of Professional Psychology for a Masters in Psychology with an emphasis in organizational leadership.

What is your hometown?
Cadillac, MI

Would love…
To visit the hometowns of my great grandparents in Germany.

My hidden talent is…
Slow racing my VT1100

What is your favorite sports team?
Let’s go Red Wings!!!

What advice would you give to a new college graduate entering the technology industry?
Learn something new every day and do something good with what you learn as often as you can.

Explain how simpleQuE is different from their competition.

SimpleQuE is different because they focus on simple solutions to meeting complex QMS requirements.  The company supports a value added approach to meeting requirements.

Where do you see simpleQuE the next five years?
SimpleQuE will grow to become the leading QMS consulting firm and they will continue to support the success of their clients.

How would other people describe you in three words?
Independent, tenacious, and helpful.

VEGA Americas – Where Quality and Measurement go Hand in Hand

From left:  Ron Foltz, Manufacturing Manager; Bob Herbst, QC Technician; John Kronenberger, COO; Gretchen Lisi, Quality Manager; and Nickie White, RIG Champion.

VEGA Grieshaber KG is a global manufacturer of process instrumentation. Its product portfolio includes sensors for measurement of level, point level, pressure as well as equipment and software for integration into process control systems.  Its subsidiary, VEGA Americas, focuses on the design, manufacturing and servicing (including Radiation Safety Training) of Nuclear Measurement Systems.  The facility also manufactures, tests and services the full range of VEGA Measurement Systems.

Because quality and measurement go hand in hand, VEGA has been ISO 9001 certified since 1997. When the company needed to transition to the new standard, they utilized the expertise of simpleQuE quality consultant, Don Milinkovich, to conduct a gap analysis.  Following an action plan to close any gaps, VEGA Americas achieved ISO 9001:2015 recertification through Eagle Certification Group.   Congratulations to the VEGA team where they know how to Run, Improve and Grow (and even have a designated champion just for that purpose)!

SimpleQuE on the Go and in the Know


This week, while Vice President, Deanne Sparr, is attending AIAG’s 2018 Southern Automotive Quality Summit in Birmingham, AL,  President, Jim Lee, has immersed himself in everything space and defense at ASQ’s Collaboration on Quality in the Space and Defense Industries conference and NASA’s Quality Leadership Forum.

These types of industry conferences and training keeps us at the forefront of the latest rules, regulations, trends and best practices to share with our consultants and clients across the aerospace, defense and automotive industries.

For example: At the NQA Global session, it was reported that as of mid-February only 29 percent of aerospace businesses had transitioned to the AS9100:2016 standard, however, as of last week it was up to 41% with a target of 50% by the end of March.  Deadline for all to transition is September 14, 2018.

From Exploring Space – Is It Safe? presented by Astronaut Bill McArthur, to NASA conducted Counterfeit Parts Awareness and Inspection Training, quality is the topic interwoven throughout the conference and the critical piece that all in the industry rely on to launch us into space.  Check back for more news as we process all of the great information we’ve gathered from the sessions.

When Should You Hire a Quality Management System Consultant?

business, architecture, construction, teamwork and people concept - happy group of architects with tablet pc computer discussing blueprint at office

Whether your company is in the manufacturing or service industry, if you were considering implementing a new accounting or software system, which was completely outside of your staff’s expertise, wouldn’t you consider contracting with someone considered an expert in that particular area?

The same principle applies when it comes to ISO, AS or IATF certification. Hiring a consultant to prepare your company for certification can be well worth the investment, whether you’re going through certification for the first time or transitioning to a new quality standard (for instance, changing from ISO 9001:2008 to ISO 9001:2015).

Often, business owners, and sometimes even quality managers, don’t have the time or adequate knowledge of the standard to do a gap analysis and prepare an action plan themselves. An experienced consultant has gone through the implementation process in a variety of industries, and will be able to quickly understand your company’s processes and how to most effectively recognize gaps in the requirements. Going with an experienced consultant who has a significant track record in planning, developing and implementing systems greatly increases the likelihood of a successful certification.

It’s certainly possible for a company to implement a system on its own. However, doing so can prove to be detrimental to other areas of the business as resources are often stretched too thin. The employees responsible for implementing the system could fall behind on other obligations, and these setbacks can quickly outweigh any money saved by not hiring a consultant from the start.

An often overlooked benefit to hiring a consultant is objectivity. An outside consultant can bring a fresh and unbiased perspective to your company and systems. You’ll often find that a consultant provides simple and sustainable solutions that may have been overlooked by your own team.

Additionally, by hiring a consultant you’ll ensure you’re putting the right person in charge of the project. Implementing ISO, AS or IATF standards requires a strong leader who can oversee a coordinated effort. Most consultants are natural leaders able to energize all parties involved and keep the project moving forward at a good pace. Depending on the complexity of your processes, a consultant can help you focus on only what is required for certification, often finishing the project in less time than it would take using your company’s own resources.

In seeking a consultant you’ll want to make sure they have the skills relevant to your organization and industry.  SimpleQuE  consultants have educational backgrounds and work experience that make them experts in their fields.  In addition, many are current or former 3rd party auditors and ready to serve in an advisory role or for implementation, project management, training or internal auditing. SimpleQuE can assist in first-time systems development for certification; upgrading certification to a new standard; simplifying a cumbersome quality system and documentation; defining processes and process mapping; documentation and systems implementation; internal audits and gap analysis for improving your quality or environmental management system.

No matter the size of your company or the industry, having ISO or other certification will distinguish you from the competition. Hiring a consultant can help you achieve certification with ease, after all, it’s what simpleQuE is known for – Simple Quality Excellence.

SimpleQuE has consultants throughout the Eastern U.S. that can guide you through the certification process in ISO 9001, ISO 14001, IATF 16949, and the AS9100 series of standards.

WRWP Makes the Calculated Jump to ISO 9001:2015

WRWP, LLC (Western Reserve Wire Products) has been designing, building and distributing wire harnesses since 1987.  Through the years they have evaluated and implemented more efficient means of production with state of the art equipment and manufacturing plants in China to reduce time and costs for their customers, while maintaining a high standard of quality.

The engineers at WRWP often work with their customers’ engineers in the design phase of new products to produce the best possible fit and function for the wire harness that will be needed, thus reducing unnecessary changes down the road.  And with that approach, in 2015 WRWP searched for a consulting firm that was the best fit and function to review their quality management system and develop a customized implementation plan to achieve ISO 9001:2008.  They selected simpleQuE, and with consulting and training support, achieved their certification.

Due to that success, when it was time to transition to ISO 9001:2015, they again turned to the experts at simpleQuE who utilized a Fast Track approach and developed an action plan while utilizing a detailed gap checklist to identify where WRWP was already compliant and where gaps existed.  Over the next several months with the guidance of simpleQuE consultants, their quality team worked hard to close the gaps while maintaining their quality system and improving internal processes. That preparation resulted in zero findings and certification to the new standard by Smithers Quality Assessments.  Congratulations to the team at WRWP!

Not ready for IATF Certification? MAQMSR May Be an Option

worker with protective mask welding metal. in Industrial automotive part. in car production factory.

For automotive suppliers who are having a difficult time meeting the requirements of the new IATF 16949 quality standard, Minimum Automotive Quality Management System Requirements for Sub-Tier Suppliers (MAQMSR) may be an option you want to consider in conjunction with ISO 9001 certification.  With initial audit results coming in from certification bodies, it is evident that companies are failing to comply and in some cases IATF certification can’t be achieved.

IAOB released the top IATF 16949 findings based on 3,172 audits conducted as of August 2017 – the top 5 non-conformances overall were written against:

  • 5.1.5 Total productive maintenance
  • 5.1.1 Control plan
  • 1.2.3 Contingency plans
  • 5.1 Control of production and service provision
  • 2.3 Internal auditor competency

As an option for suppliers, the Minimum Automotive Quality Management System Requirements for Sub-Tier Suppliers (MAQMSR) was released in September 2017 as a possible intermediate step for a supplier’s Quality Management System (QMS) under the authorization of IATF 16949, Section 8.4.2.3.c and Sanctioned Interpretation, SI #8.

Conformance to MAQMSR helps a lower tiered supplier transition to IATF 16949 by allowing many of the key Automotive Requirements to be met while developing the remainder of the QMS. The ultimate goal of the supplier development process is to achieve 3rd party registration to IATF 16949.  It is important to note that the customer determines the path and steps, so approval must first be obtained before proceeding.  The suggested steps of supplier development referencing 8.4.2.3 are as follows:

  1. Certification to ISO 9001 through 3rd party audits
  2. Certification to ISO 9001 + compliance to MAQMSR through 2nd party audits* (suppliers who did not achieve upgrade transition may consider this)
  3. Certification to ISO 9001 + compliance to IATF 16949 through 2nd party audits*
  4. Then finally certification to IATF 16949 through third party audits

MAQMSR aligns the Automotive QMS Requirements with the corresponding IATF 16949:2016 section(s); however, it is not certifiable or a third party auditable standard, though the guideline may be referenced during a second party audit *(by customer or with a qualified 2nd party like simpleQuE).

SimpleQuE consultants have been assisting companies to understand their options and make the change to drop IATF 16949 and prepare for ISO 9001:2015 certification.  Upon receiving  customer approval to use 2nd party audits to be compliant with MAQMSR, our consultants can provide guidance for that process and perform the audits.  For more information on MAQMSR, contact us.