ISO-IEC-TS-17012-presentation- Guidelines for the use of remote methods in auditing management systems

PrashanthBN7 147 views 16 slides Aug 26, 2024
Slide 1
Slide 1 of 16
Slide 1
1
Slide 2
2
Slide 3
3
Slide 4
4
Slide 5
5
Slide 6
6
Slide 7
7
Slide 8
8
Slide 9
9
Slide 10
10
Slide 11
11
Slide 12
12
Slide 13
13
Slide 14
14
Slide 15
15
Slide 16
16

About This Presentation

The scope of the document is to specify guidance in the use of remote methods for conducting audits of management systems and it is applicable to all organizations that need to plan and conduct all kinds of internal or external audits of management systems.


Slide Content

CD ISO/IEC TS 17012 Guidelines for the use of remote methods in auditing management systems Jasmin Omerovic

CD ISO/IEC TS 17012 Why this TS? This document is intended to strengthen confidence in the use of remote methods for auditing management systems among customers, regulators, accreditation bodies, certification bodies, scheme owners, industry, employees, consumers, suppliers and other interested parties. A combined guideline to cover risks, conditions to use remote methods, best practice etc. The use of remote methods for management systems audits is not intended to completely replace on-site audit method. 2

CD ISO/IEC TS 17012 Workplan Start in September 2022 1 meeting in 2022 2 meetings in 2023 CD ready in June 2023 CD consultation comments – 30. October 2023! 4th meeting October 2023 DTS ballot – December2023 5th meeting – February 2024 Editing&proofreading March/April 2024 Expected publication in 2024 3

CD ISO/IEC TS 17012 Structure This document is based on ISO 19011 “Guidelines for auditing management systems” Uses the same headings Starts each clause with references to the specific clause Complements by specifying guidelines for use of remote methods for each clause 4

CD ISO/IEC TS 17012 Contents Clause 5 Managing an audit programme Clause 6 Conducting an audit using remote methods Clause 7 Competence and evaluation of auditors Annex A: Remote auditing methods Annex B: Useful practices 5 Same as ISO 19011 Specific to ISO/IEC TS 17012

CD ISO/IEC TS 17012 Scope The scope of the document is to specify guidance in the use of remote methods for conducting audits of management systems and it is applicable to all organizations that need to plan and conduct all kinds of internal or external audits of management systems. 6

CD ISO/IEC TS 17012 Definitions A new definition: 3.2 remote auditing methods: “methods used for conducting audit activities at any place other than the location of the auditee” 7

CD ISO/IEC TS 17012 Principles of auditing Same principles in ISO 19011 apply. 8

CD ISO/IEC TS 17012 Managing an audit programme Risks and opportunities; information security and confidentiality issues of remote auditing methods; required information available to make judgment on application; acceptability of remote methods for scheme owners, regulators and other specifiers; ability to use remote auditing methods. 9

CD ISO/IEC TS 17012 Conducting an audit using remote methods Risks and opportunities to be considered to determine if modification of effort and/or resources is needed, even leading to changes in audit methods; Support personnel; Conducting opening/closing meeting; Collecting and verifying information. 10

CD ISO/IEC TS 17012 Competence and evaluation of auditors Personal behaviors, technical skills, and sensitivity to digital data privacy. Knowledge and skills related to confidentiality, information security, and remote auditing technologies. Ability to evaluate suitability and risk of remote methods. Adapting to new remote auditing methods and evolving technologies. 11

CD ISO/IEC TS 17012 Annex A - Remote auditing methods Types of audits using remote methods Fully remote : No onsite activity is planned with any auditor. Allowance is based on a risk assessment of the product and company based on the program being covered. Consideration for software as a device, virtual manufactures, etc. Hybrid/blended : using combination of methods where at least one part is conducted onsite; e.g : auditor conducts specific parts of the audit onsite, such as production and service; auditor conducts document review remotely using ICT 12

CD ISO/IEC TS 17012 Annex A - Remote auditing methods Technologies used List some technologies (share folders, ftp servers..) and some good practice (communicate protocols, ensure access to IT support, back up of use of mobile phones…) Examples of methods’ implementation When handling documents and records, when 1 auditor is remote, when auditing digital twins, when using surrogate auditors (technical person who attends the audit in-person and acts as eyes and ears for the audit team) Further methods for documents reviews, personnel interviews 13

CD ISO/IEC TS 17012 Annex B - Useful practices Generic best practice addition of an audit objective that addresses the suitability and effectiveness of the remote methods used in the audit activities. Managing the audit programme Process for investigation: e.g. identify and document risks and opportunities that can impact the audit for each of the remote methods; any methods being used to manage the identified risks; Selecting the audit team and ICT methods: e.g. consider to have at least one auditor who has participated in the previous audit and is familiar with the auditee's management system; 14

CD ISO/IEC TS 17012 Annex B - Useful practices Conducting the audit Reviewing information: Confirm the choice of methods being used or potentially used to review information during the audit planning process; During the opening and closing meetings confirm the arrangements for managing security and accessibility issues.. Collecting and verifying information: Consider any external resources related to regulatory performance as appropriate; Ensure the sampling includes the variety of levels, functions, activities and tasks represented… Opening meeting: Utilize the camera for the lead auditor, key organization representative, Set and communicate the meeting rules… 15
Tags