Showing posts with label legal requirements. Show all posts
Showing posts with label legal requirements. Show all posts

Thursday, January 29, 2026

Getting regulatory standards for free

How do you get a copy of a standard?

Let's say you need one for work. You want to check what ISO 14001 says about management review, to make sure you are doing it right. Or you want to know what the American Welding Society says in Z49.1 about "Safety in Welding and Cutting." Where do you find the document?

You could try the organization's website. Some standards (such as Z49.1, in fact) are available for free. But many of them are for sale. So someone—you, or the organization you work for—has to pony up cash to get a copy. 

That's the normal expectation. And the assumption has always been that if you don't want to pay for the standard, no one is forcing you. There's no law that you have to hold management review, after all. If your customers expect it from you—because your customers expect ISO 14001 certification—that's a cost of doing business. And you are free to choose whether it is better to pay for the certification (which includes paying for the standard) or to forego the chance to hang that diploma in your lobby.

But there's a catch. Sometimes there is a legal requirement to comply with one of these standards. And that complicates the calculation.

In what follows, I explain how this came about, and then I tell you how to get the documents you need for FREE. 

How can you be required to follow a "voluntary" standard?

Let's back up a minute. In the United States, many industries operate within guidelines defined by federal regulations. In some industries—the design and manufacture of medical devices is a prime example—those regulations became so numerous that they ended up covering the same scope as the relevant "voluntary" quality standards (in this case, ISO 13485, "Medical devices — Quality management systems — Requirements for regulatory purposes"). 

For a while, medical device companies had to comply to two complete sets of rules, those from the Food and Drug Administration (FDA) and those from ISO. This mandate was awkward, because there is no way that two different sets of rules can ever completely coincide. Finally, the FDA repealed those detailed individual regulations which duplicated the terms of the ISO standard, and replaced them all with a general regulation that medical device companies must comply to ISO 13485. Technically this means that Title 21 of the Code of Federal Regulations now "incorporates ISO 13485 by reference." (The same thing happens in other industries.)

Did that solve the problem?

Yes and no. It clarified the rules for medical device manufacturers. But ISO 13485 is a document sold by the International Organization for Standardization (ISO) for CHF196. On the other hand, it's a basic principle of American law that Federal regulations are made available for free. The idea is that it's not fair to hold someone accountable to a law and then charge him a fee to find out what the law says!

But if 21CFR Part 820 now incorporates ISO 13485 by reference, doesn't that mean that medical device companies should have access to the standard for free? And likewise for other industries whose regulations incorporate standards by reference?

What's the answer?       

In the end, the regulatory agency has to come to some kind of agreement with the standards-developing organization to make the standard "reasonably available" to persons who are affected by the law. For standards written by a dozen major organizations—including ISO and IEC (International Electrotechnical Commission)—there is a one-stop shop hosted online by the American National Standards Institute (ANSI) where you can download for free read-only copies of those standards which have been incorporated by reference into legislation or regulation.

Start here: https://ibr.ansi.org/Default.aspx 

Now to be clear, none of these organizations have relinquished their copyrights on the documents in question. And in order to respect those copyrights, ANSI's access is not exactly convenient

  • You cannot print the documents you download from this site. 
  • You cannot select text and copy it. 
  • You cannot highlight it or add notes. 
  • Before you can open any of these documents, you have to download a special plug-in for the Acrobat Reader, and then you have to open them in Acrobat (not in your browser). 
  • You have to register with your name and address for each document you download, each time you download it. 
  • There is a Frequently Asked Questions page with more information at https://ibr.ansi.org/Faq/Default.aspx. 

If you want access that doesn't suffer from all these limitations, you have to pay for the document like a regular customer.

But strictly speaking, you can get access to these standards for free—just like any other federal regulation.



      

Thursday, October 24, 2024

Outsourcing your evil deeds

Last week I wrote about the peculiar fact that multinational corporations seem able to avoid unwelcome regulation, at least in certain cases, by the expedient of quitting the country to go elsewhere. This approach is admittedly a bit extreme, so today I want to talk briefly about another—much more common—way that some companies try to get around rules that forbid them to do Bad Things: hire a scoundrel as an external supplier to do the Bad Thing for you. That way your hands are clean … well, more or less  and dealing with the regulators becomes his problem.

This approach has become so common in international trade that it almost passes without comment. If your company makes widgets, and if you are regularly undersold by competitors because wages in your country are so high or environmental regulations add extra costs, someone is sure to suggest that you relocate your factories to another country where neither of these considerations is in play. Alternatively you can outsource the actual manufacturing to a supplier in the other country. That way you aren't paying the low wages, and you aren't causing the adverse environmental effects; but you still get your widgets a lot cheaper than before.

Of course, any such gains are temporary. If you can save money by moving your manufacturing to Ruritania, so can your competitors. Then some other country comes into view, with even lower wages and even worse environmental protections, and everyone moves there instead. Soon countries are competing against each other in a "race to the bottom." As I have discussed in an earlier post, in the long run nobody wins such a race. But in the short run, some companies find it compelling; and after all, "In the long run we are all dead."*  

I assume that the same dynamic probably operates domestically as well. That is to say, I have no personal knowledge of any domestic companies who exist so that their clients can skirt inconvenient legal or ethical constraints, but it wouldn't surprise me. Some people don't mind sketchy work, and some people will do anything for a price. 

The good news is that ISO 9001 explicitly disallows this! Clause 8.4.2(a) of ISO 9001:2015 states clearly that:

The organization shall ensure that externally provided processes remain within the control of its quality management system; …. 

So if you design and sell a product, but you outsource its manufacture to someone else, you are still responsible for what they do.

Most of the time, this responsibility is for very practical reasons. Maybe you do much of your own manufacturing, but there's one specific process that you outsource. Well if you require that all your manufacturing equipment must be calibrated to a specific tolerance, don't you want to flow down that same requirement to the supplier who is executing this one special process? If you don't, their uncalibrated equipment might ruin all the exactitude you achieved with your carefully-calibrated equipment, and you'll have to scrap the whole lot. Nine times out of ten, or 99 times out of 100, this is the kind of "control" that really matters. Mostly ISO isn't afraid that you are going to try to do Bad Things in an underhanded way, because most people just don't do that. But ISO is concerned that when your process is executed, you get what you want.

To be clear, this clause does not mean that you have to know your supplier's business better than they do. It does not mean that you have to define the details of their operating procedures. The whole reason you are hiring them should be that they are experts in whatever you want them to do. 

Nor does it mean that if your company has to be certified to AS9100 because you are building aerospace parts, then the caterer that you hire to provide lunch has to be certified to AS9100 as well. (I hope that's obvious.)

But if you have any overall constraints that apply to all of the work inside your QMS—like the calibration example I just gave—then (where it is relevant and meaningful) you have to flow down those requirements to your supplier.

And if you happen to be the one case in 1000 who wants to get away with a Bad Thing by hiring a scoundrel to do it for you, … don't. Just don't.  

__________

* John Maynard Keynes, A Tract on Monetary Reform, 1923. Quoted many places around the Internet, for example here.       

     

Thursday, October 17, 2024

The Braganza gambit

And now, if I may digress momentarily from the main stream of this evening's symposium,* … I'd like to raise a question which relates more to regulatory compliance than to Quality per se, but which has bothered me from time to time, and which seems to lurk on the margins of other—more normal—Quality topics. (In fact I plan to discuss one of these next week, in a follow-on essay.)

The background is this: First, we all know there is such a thing as global trade. In fact, the whole point of international standards is to facilitate global trade. As I explained once in this forum a couple of years ago, "A standard is like a common language: it allows us to do business with strangers, because we know that we are both talking about the same thing."

Second, we all know there are global (or at any rate multinational) corporations. Over the course of my career I've worked for at least two companies headquartered in Europe (LM Ericsson and Robert Bosch), even though both times my local office was in southern California.

Third, we all understand more or less how companies are regulated. Some authority codifies a set of rules: those rules might be voluntary (like ISO 9001) or legally mandatory (like health and safety regulations). Then the company decides whether they want to abide by these rules. (In the case of mandatory legislation, we should assume that the answer is always Yes.) If yes, the company takes steps to implement the rules; and if they fail, there is some kind of system in place whereby someone can complain. When the authorities get a complaint they check the facts; and if the company has indeed failed to meet the requirements, the authorities react accordingly. In the case of ISO 9001, the responsible Certification Body can decertify the company; in the case of legal noncompliance, the relevant government can impose civil or criminal penalties.

Now finally here's the question: How do you regulate an international company?

I fear that the answer may be: Mostly you can't. I'll explain why, but I would be delighted if you can show me where I am wrong.

Let's say that some local company violates a local regulation. Government inspectors come out to check the status, and—depending on the severity of the issue—they might give the company written notice to correct the problem in a defined time, or they might padlock the doors. If company personnel try to interfere with the government inspectors, they can be arrested. And since it's a local company, that's all it takes to stop them doing whatever Bad Thing they were doing. Problem solved.

Suppose that the company has multiple branches in the same state: then, depending on the nature of the Bad Thing that Law Enforcement is trying to stop, they might have to take a heavier approach. Or they might leave the branches alone but target headquarters. If the company has branches all over the United States, Law Enforcement has to get more ambitious still, because sometimes state laws disagree (so the Bad Thing might be legal in another state). Also, local Law Enforcement is unlikely to have jurisdiction in another state, and so will have to coordinate with other agencies in order to stop the Bad Thing once and for all.

But if the company has offices all over the world, then what? The very most that American Law Enforcement authorities can possibly do is to arrest whichever company personnel happen to be located inside the United States. But they are powerless over the offices in Ruritania or Grand Fenwick.    

In the ordinary course of things, a multinational company will probably find it convenient to comply with routine local regulations, because they will see those regulations as just a cost of doing business. As long as the opportunities in a country are bigger than the costs, they are likely to cooperate. But this cooperation is strictly a voluntary choice on their part. In an extreme case, they can always shut down the local offices and leave.

This strategic departure from a country because you don't like the laws is what I call the Braganza gambit. The Braganza family ruled Portugal and the Portuguese Empire from 1640 until 1910. During the Napoleonic Wars in the early nineteenth century, Napoleon Bonaparte installed many of his relatives in thrones across Europe. His method—used for example in the Peninsular War against Spain—was to defeat a country and capture the royal family; then he could force them to abdicate in favor of one of his relatives and move on to the next country.

By Lumastan - Own work, CC BY-SA 3.0, Link

But not in Portugal. The Braganzas saw what Napoleon was doing and realized they were next. So they moved the entire royal court to Brazil, which was at that point part of the Portuguese Empire. When Napoleon conquered Lisbon, the royal family was nowhere to be found. (In the end they liked it in Brazil, and didn't move back until 1821—long after Napoleon was no longer a threat.)

So there you have it. Multinational corporations have the privilege—unavailable to local corporations—that they can (within limits) decide which legal regulations they feel like following. And in case any regulation is too burdensome for them to tolerate it, they have the option of leaving the country.** 

If a multinational corporation decides to use the Braganza gambit to avoid an onerous regulation, about the only leverage the abandoned country has is to close its markets. "If you won't abide by our rules, you can't sell your goods here." Whether that's a meaningful threat depends very much on the particular details, and of course sometimes the same maneuver plays out in reverse: a company might refuse to sell into a certain country until this or that policy is changed. It is hard to generalize about how effective either tactic is.*** 

What do you think? Am I wrong? Is there something I've neglected?

Or can multinational corporations escape troublesome regulation just by moving abroad? 

Please leave me a comment with your perspective. 

__________

* Tom Lehrer, introduction to "The Elements," Reprise/Warner Bros. Records, track 4 on An Evening Wasted With Tom Lehrer, 1959, LP record.  

** There's even a related line of thought that protects international organizations. Concretely, if you or I (as private citizens) feel wronged by some decision from an international organization like the WEF or the ISO, we may find it hard to sue them for redress because it's not at all clear which court—if any—has the appropriate jurisdiction.

*** Certainly this is the logic behind international economic sanctions, where—in this case—one government requires all the companies subject to it to avoid business in another country until that other country changes its policies. When small countries are subjected to coordinated sanctions, the effects can be crippling. When large countries are subjected to them, the results are not so immediate. Consider, for example, this recent video by a YouTube creator "Eli from Russia," who publishes travel information (and strictly avoids politics). She describes the impact of sanctions on Russia, and the results have been (to say the least) not uniform.


    

Thursday, May 30, 2024

Value-added auditing

Have you ever been at work when someone announced a new procedure that you knew right away was guaranteed to fail? What do you do about it? Of course if it's in your authority you can intervene immediately, but what if it's not? Is there any tool you can use to make your point?

Yes there is. Audits.

I used to work for a company who shipped products all over the world. Once we introduced a new product that had to be certified in each country where we shipped it, because one of the components was regulated as a communications device. This meant in each new market we had to supply a sample of the device, fill out a bunch of paperwork, and supply a fee; in exchange we got the right to import the product to that country for a certain period of time before we had to do it all again. But of course the expiration dates differed from country to country. So we had to keep track of the expiration dates for each country we shipped to, in order to make sure that we didn't inadvertently sell a product into a country where the certification had expired last week.

The design engineers were all in one office. The warehouse and the order-entry personnel were in a different facility, two time zones away. And when we recognized the problem posed by the need to certify this one component in country after country, someone proposed the following solution:

Let the Engineering Manager track the dates, because he's the one that has the specialized design knowledge to fill out all those government forms. He'll keep a big matrix that lists all the countries we ship to, and the current expiration date for each country. Then whenever he updates that list, he'll e-mail it to the Order-Entry Desk. That way they will always have a current list; and whenever they input an order for this product, they'll check the list to make sure we are really allowed to sell into that country. Foolproof!

Is it just me, or is it obvious to you, too, that this plan was guaranteed to fail? The most basic reason is that everything about this procedure was an exception. None of it was part of anyone's normal work routine.

The Engineering Manager had to remember to update the file in a timely way, even though that had almost nothing to do with the rest of his job. When he did update the file, he did it by hand.

The order-entry personnel had to check their emails in a timely way, and then fish out this file whenever it was updated. Then they had to put it somewhere, and remove the old outdated copies (to avoid confusion).  They did all of these steps by hand, with no system to guarantee even that the new files got stored in the same place where the old ones had been. (And of course if they accidentally stored different versions in different places, what would guarantee that they'd always find the latest one when they had to look for it?)

Finally, the Order Desk handled orders for thousands of different products. Among all those thousands of products, only this one had a rule that they had to stop everything and check a hand-built matrix to look up country and date before placing the order.

As I say, everything about the procedure was an exception. It was guaranteed to fail. But it was outside my area of responsibility, and it hadn't failed yet. So I couldn't really say anything.

What I did was to make notes to prepare for the next round of internal audits, which had already been scheduled for a few months later. When the time came, I asked the Engineering Manager for the latest copy of his matrix, and I scheduled an audit of the Order Entry Desk.

The people who operated the Order Entry Desk were really sharp, and we finished the routine part of the audit easily with no findings and lots of time to spare. So then I asked them for help. I reminded them of this procedure that was supposed to be in place—"Oh yes, we remember"—and then explained that I was afraid it was going to break down. Could they please help me? They opened the Order System in read-only mode, and searched for all orders for the product in question, starting with the latest one. For each order, they read me the country that it was shipped to and I checked it against the list. 

Within the first half dozen orders they read me, we found TWO that had shipped to a country where the certification had expired. Amazingly enough, that country's customs officials hadn't caught the shipments to reject them. But technically it was still a violation of a legal requirement. So I thanked the Order Entry auditees for their help, and wrote it up as a Major Nonconformity. I made a point to emphasize in the Closing Meeting that this finding was found while auditing the Order Desk, but it wasn't their fault: it was a system issue, and had to be addressed as such.

Soon after the company implemented a system of automated flags in the order tool itself, completely eliminating the manual exception-handling. It was a much better approach.

               

Thursday, November 10, 2022

So how DO you talk about ethics?

Last week I wrote about whether ISO 9001 should be revised to address questions of ethics. In reply, Krishna Gopal Misra of Qualitymeter.com published a detailed essay on LinkedIn about the role of ethics in relation to any management system. I am grateful for Mr. Misra's essay, which makes the important point that ethical principles are not so much a part of a management system as logically prior to it. A management system tells you how to organize in order to get what you want; but it cannot tell you what to want. That is the job of your Vision, and thereby of your strategy and policies. Without a Vision, the management system itself is blind,* and the organization is directionless. At that point there is nothing to stop the organization from doing very bad things, and Mr. Misra gives some chilling examples in his essay. 

What should you do instead? If you want to avoid the moral aimlessness that Mr. Misra warns against, how do you talk about ethical principles in your organization if not in the management system? Or to put the question another way, the management system defines a framework for how to run your organization: where in that framework do your ethical principles belong?

They have to come right at the beginning, so that they become ground rules to inform everything else. This means that your ethical principles have to be part of the Context of your Organization (COTO). They have to be among the fundamental requirements that you are in business to satisfy in the first place.

I used to work for Robert Bosch; and while I normally avoid discussing previous employers by name, I always admired Bosch's explicit and stated commitment to ethical behavior. This commitment grew out of the deep personal beliefs of Herr Bosch himself, back when he was still alive and steering the company personally. He once said—in a remark that every Bosch employee must surely know by heart—"I would rather lose money than trust." (If you are interested, you can find a copy of the Bosch Code of Business Conduct at this link here.)

And it has to be more than slogans. In order to be worth anything, a policy of corporate ethics has to be reinforced with action at every turn. Bosch promoted its ethical policies in several ways. One prominent way was through a corporate training program, which required every employee to take classes on specific topics. These classes repeated at stated intervals: some every year, or every two. The longest interval between repetitions was three years. The classes themselves covered topics like recognizing and avoiding conflicts of interests, or respecting the principle of legality in all daily work. Mr. Misra explained that sometimes companies resort to bribing government officials to get what they want; Bosch had a separate class all about how Bosch employees are strictly forbidden to engage in bribery. The instructors even explained that there are some countries in the world where bribery is expected as a normal part of doing business; and they freely admitted that Bosch's strict anti-bribery policies make it harder to compete in those markets. When someone asked "So what are we supposed to do in those countries?" the instructors just smiled and said the only thing to do was to make the products even better, so they would sell despite interference from disgruntled government officials who expected bribes but didn't get them.

No training program will ever turn men into angels. Somewhere along the line, somebody will make a mistake and do something wrong—even at Bosch. When that happens, it is important to take swift and visible action. You may remember back in 2015, when news broke about the Volkswagen emissions scandal (sometimes called "Dieselgate"). Volkswagen had been caught using software to circumvent laboratory emissions testing, so that their cars could be passed by the EPA and sold into the United States even though their NOx emissions in normal driving far exceeded the legal limits. Volkswagen was the company that perpetrated the illegal activities, not Bosch. But Bosch had sold them the software, a decade earlier. (Bosch even warned them not to use the software in the way Volkswagen used it, because that would be illegal.) 

When it became known what had happened, the Bosch Board of Directors addressed Bosch's (apparently peripheral) role in the scandal by issuing a new Product Development Code. This code had several parts; but among other things it prohibited Bosch from designing any product for any customer with features that a reasonable engineer could expect that customer to use illegally. If a customer asks for such features, even if the features themselves are (strictly speaking) perfectly legal, Bosch is now required to reply, "I'm sorry, Mr. Customer, but we can't do that for you. If that's what you want, we don't want your business." To implement this new Code, Bosch required training classes for every employee worldwide involved in product development, product management, project management, engineering, marketing, or sales. Bosch also required explicit changes to the product release process—enforced by an independent Quality organization—to ensure that the Code has been complied with before any product is released to the market. (This news article discusses Bosch's rollout of the new Product Development Code.)

That's what I mean by "swift and visible action." And it was taken, remember, to respond to a scandal where Bosch was only peripherally involved—so that in the future the company can avoid even the appearance of illegal or unethical behavior.

It's not easy, but it's possible. However, to come back to the original point, these commitments belong in your COTO, along with information about the kind of work that you do and who your major customers are. These commitments are part of the content that is managed by the management system, and not part of the structure of the management system itself.     

__________

* This pun was not exactly intended, but I think it is pretty much inevitable in the present discussion.            .

Thursday, October 6, 2022

"A gang with a logo ...."

Back in April I wrote about how the current Russo-Ukrainian war could lead to the unraveling of the system of global certification. Just recently I got the chance to discuss this very issue live, with Kyle Chambers of Texas Quality Assurance and Christopher Paris of Oxebridge International. It was a lot of fun. Kyle brings an infectious energy to any conversation he's a part of, and Chris has a wealth of knowledge about the international certification scheme; so the two of them together fleshed out my original thesis in ways I hadn't expected. (The fun quote in the title is an adaptation of something Chris says, but you have to listen to the podcast to find out who he's describing and what his actual words are!)

So please check us out, and leave a comment!

You can find the podcast version here: #QualityMatters episode 151.

Or there's a version on YouTube that also includes video, which you can find here:


I look forward to hearing your feedback!

     

Thursday, April 7, 2022

Will this be the end of global certification?

Map of Ukraine showing the military situation as of 6 April 2022
Military situation as of 6 April 2022
Things happen fast in wartime.

On 24 February 2022 — that's six weeks ago today — Russia invaded Ukraine in a major escalation of the Russo-Ukrainian War, which has been going on at greater or lesser intensity since 2014. More than forty nations reacted to this invasion by imposing a wide range of economic sanctions against Russia. The nations imposing these sanctions include the European Union and other nations in Europe, the United States, Canada, Australia, New Zealand, and Japan — which is to say that this list of nations includes many of the largest economies of the world. The hope was that these sanctions would hurt the Russian economy and encourage a quick end to the war.

The ISO, the IAF, and Grand Fenwick

What does any of this have to do with Quality? It has to do with standardization. The International Organization for Standardization (ISO) and the International Accreditation Forum (IAF) sit at the center of a network of technical and organizational standards and certifications that enable global trade. The idea is that the ISO should write standards which should be applicable around the world, and then the IAF should accredit certification or registration bodies around the world to validate that organizations or their products meet these standards.

But the ISO and the IAF don't sit in the clouds. They are embodied as real organizations on earth. The ISO is coordinated by a central office in Geneva, Switzerland. The IAF is registered as a Delaware corporation in the United States. They interact with regional or national organizations across the globe, and the legal form that interaction takes is the form of commerce. In other words, when the ISO issues a standard to be used by the national standards board of some country, for example Grand Fenwick, then the Grand Fenwick Standards Board becomes a customer of the ISO. When the ISO accredits the Grand Fenwick Registration Board, giving them the right to certify companies in Grand Fenwick to international standards (like ISO 9001, for example), then the Grand Fenwick Registration Board becomes a customer of the IAF.

Sanctions, decertification, and the Russian response

But wait. The ISO secretariat functions as a Swiss company, and Switzerland has imposed economic sanctions against Russia. The IAF is legally an American company, and the United States has imposed economic sanctions against Russia. In principle this should mean that neither the ISO nor the IAF should have Russian customers any more. But all the Russian certification bodies that have been accredited under this scheme, and all the individual Russian companies holding certificates from those CB's, are ultimately customers of the ISO and the IAF. So in principle all those accreditations and certificates are ... what? Null and void?

You'd think so, although up till now ISO and IAF have avoided saying it. (See for example this statement where the IAF says how sad they are about the "situation" in Ukraine while insisting that they have a policy of "neutrality.") But where they have been silent, other players in the global certification scheme have stepped in. For example, three weeks ago the ANSI National Accreditation Board (ANAB) issued a statement as follows:

As of 18 March 2022, ANAB required our accredited CABs to immediately halt all ANAB-accreditation activity in the Russian Federation and Belarus and to immediately remove all references to ANAB and ANAB-accreditation symbols associated with Russian or Belarusian entities, sites, products, and systems. ANAB-accredited CABS have been notified directly.

Nor is ANAB the only one. A week earlier, the Dutch Accreditation Council Raad voor Accreditatie (RvA) issued a statement denouncing the Russian invasion of Ukraine, and followed it by suspending their accreditation of the CB Russian Register

Two days ago, Christopher Paris of Oxebridge International reported that Russia finally responded to these measures by calling them "politically motivated" and insisting that they could get along just fine without ANAB and RvA anyway. So there! And in the short term it's hard to imagine that they could have said anything else.

The optimistic view

What does the future hold? In principle I think there are two possibilities: call them the optimistic view and the pessimistic view.

The optimistic view is easy to describe. If events follow this path, then Russia and Ukraine will make peace very soon; and after some conferences and other measures, the world will fall back into the status quo ante bellum. From the perspective of the global certification scheme we'll be right back where we were a year ago, let's say, and there will be no long term impact. That, as I say, is the optimistic view, and in principle I guess it should be possible. I do not have the expertise to estimate its likelihood.

The pessimistic view

The pessimistic view takes a little longer to describe, and it can start in either of two ways. 

War and distrust

One possibility is that the war will last longer than we expect, or longer than we hope. Another is that after the war is over, the Russians will be left with a deep and abiding distrust of the nations who sanctioned them. Either way, the likelihood of restoring the status quo ante bellum with respect to global certification vanishes almost to nothing. 

If the war continues for a long time, Russian companies cannot be expected to function for years without some kind of certification scheme. Since presumably they will not have access to Western accreditation and certification bodies during all that time, they will establish and use domestic ones.

If the war ends with the Russians feeling deep distrust for the West, the same thing will happen. Doubtless the Western AB's and CB's will make overtures to Russian companies as soon as peace is declared, reminding them of the benefits of global certification and asking them to come back as customers once more. But if we assume the level of distrust that I imagine here, then we must also guess that the Russian response will be, "Why should we be your customers again? So that you can decertify us a second time, the next time you get mad at us? Why should we let ourselves be dependent on you again? What's in it for us?" And so, again, we should assume that Russian companies will work with Russian AB's and CB's, not Western ones.

Separate schemes

On the surface, this doesn't sound very different from what we have today. For simple reasons of convenience, most Russian companies are already certified by Russian CB's, of course. What is crucial, though, is that in the scenario I describe here, the Russian AB's and CB's would belong to their own accreditation scheme and not the "global" one.

In other words: up until the invasion six weeks ago, every international standard used in Russia could be traced back to the ISO; and every certification could be traced back — sometimes through many steps — to the IAF. Under the pessimistic scenario I describe here, that would stop. For whatever reason — either because of the exigencies of war, or because of an abiding distrust of the West (or both, of course) — the actors in the Russian economy would, in this view, make it a point of principle never again to depend on "foreign" institutions like the ISO and the IAF. So the apex of the Russian certification pyramids would be Russian entities, not Swiss or American ones. Instead of the ISO, standards would be issued by the Russian Federal Agency on Technical Regulating and Metrology, the entity now responsible for issuing the GOST-R standards. Instead of the IAF, accreditations would be traceable back to Rosakkreditatsiya, the Russian Federal Service for Accreditation. 

Instead of one global standardization scheme, we would have two.    

Divergent standards

It doesn't stop there. Today, the GOST-R standards are strictly aligned with their ISO counterparts. They are translated into the Russian language, but there is scrupulous attention paid to keeping the standards uniform worldwide.

But once the standards are fully owned by a Russian authority, once they are understood to be Russian standards and not Russian translations of international standards, ... where is the incentive to keep them aligned in the future? Everyone who has ever managed documents knows that unless all updates are centralized, different copies of documents that start out the same inevitably drift apart over time. And we don't have to assume any malicious intention on the part of any of the actors involved. One year the ISO will change a standard, and the GOST-R agency won't be able to get a copy of the changes. Another year, they'll review the changes and decide that in good conscience they disagree. Both times the ISO standard will change while the "corresponding" GOST-R standard won't. Then there will be a year in which the Russian agency decides they have to make some other kind of change to address an urgent issue facing local companies; but they may feel themselves under no obligation even to report that change to ISO, and in any event ISO might not take it up. 

One way or another, after a few years the existence of two parallel standardization schemes will result in the existence of two parallel and incompatible sets of standards. 

A world divided

What are the consequences of having two incompatible sets of standards in the world? Obviously it will make it harder — and, incrementally, ever harder still — to do business across the divide. Companies that use one set of standards will find it hard to work with companies that use the other set. At a product level, spare parts might not fit; and at an organizational or process level, expectations will not be uniform.

But won't this mostly affect Russian companies? If Russia pushes to have its own, independent standardization and certification scheme in the wake of the current war, won't that just make it harder for Russian companies to do business with the rest of the world? Won't it just isolate Russian companies inside their own internal market? Does anybody outside of Russia need to care?

There is a short-term answer, and a long-term answer.

In the short term — the very short term — yes, measures like this would isolate Russian companies, by making it harder for them to trade in world markets. But the story doesn't stop there.

Plenty of countries are still interested in doing business with Russia. And even if a country (like China, for example) chooses to maintain trade relations at a national level with both Russia and the West, each individual company inside China will have to decide for themselves which set of standards to use. If a company does business predominantly with the West, it will probably continue to align itself with the ISO product and management system standards. But if a company does business predominantly with Russia, we should expect it to align itself with the GOST-R standards instead.

And in the very long run, this division cannot help but to make the Western economies weaker, because we will no longer be able to do business worldwide. Any time you restrict a market, you weaken the players who are confined to that market.

Maybe it sounds funny that I use words like "confined" to describe the West, since back at the beginning of this post I pointed out that the nations which have sanctioned Russia represent some of the largest economies in the world. But they do not represent all the large economies in the world, nor the fastest-growing ones.

  • Of the 10 countries with the largest GDP, only 2 did not sanction Russia. (China, India)
  • Of the 20 countries with the largest GDP, 8 did not sanction Russia. (China, India, Russia itself, Brazil, Mexico, Indonesia, Iran, Saudi Arabia)
  • Of the 50 countries with the largest GDP, at least 25 — that's half — did not sanction Russia. That list of 25 includes some of the fastest-growing economies in the world: China and India, but also Vietnam, the Philippines, Bangladesh, and others. 
We in the West will not be "confined" or "isolated" by our standardization scheme today, nor tomorrow. But there is a possibility that things won't look so rosy in another twenty years, to say nothing of longer terms than that. As above, I do not have the expertise to estimate the likelihood of this scenario.

Conclusion

Don't misunderstand me. I'm not criticizing the sanctions. I think the invasion of Ukraine is appalling, and I don't for a minute expect the nations of the world to sit around doing nothing while it goes on.

My only point is that every time we act, there are unforeseen consequences that propagate out like ripples on a pond. Some of those consequences may affect the worldwide standardization and certification schemes that we have come to take for granted. At the very least, maybe we can avoid being taken by surprise. 

Photo by Koen Emmers on Unsplash

     

   

Thursday, January 20, 2022

Keep your root cause analysis out of the courtroom!

Over the last several weeks, we have talked a lot about how to do a good root-cause analysis. But of course the first step to doing a good root-cause analysis is making sure you do one at all.

Wait, what? Why wouldn't you?

Suppose the worst happens and somebody gets hurt using one of your products. Somewhere along the line, as you start the investigation, somebody is bound to ask, "Why are we doing a root-cause analysis at all? If we find out the real root-cause for the problem and take steps to fix it, doesn't that just mean some hot-shot attorney can subpoena all our files and then use them to prove our original design was at fault? Won't he sue us for everything we've got? Aren't we safer just closing our eyes and hoping it doesn't happen again?"

Yes that sounds crazy -- how could it ever be better not to know what caused an accident? -- but it's also true that an ambitious plaintiff's attorney can do a lot of damage when a company is innocently trying to do the right thing. Where do you draw the line?

There's some good news here. It turns out that if you do an accident investigation that results in taking steps which would have made some past injury less likely, the results of that investigation are not admissible in U.S. federal court to prove negligence, culpable conduct, a product or design defect, or a need for a warning instruction. Note the restrictions. There are other cases where the results of your investigation are admissible — for example, in intellectual property cases, or if the court is trying to determine whether any improvement is possible. But they cannot be used to hang you for your old design.

As I mentioned in an earlier post, I am not an attorney and nothing in this blog constitutes legal advice. Please consult with your own legal counsel.

On the other hand, you can look up the background information on the Internet. The rule in question is called Federal Rule of Evidence 407. And you can find discussions of it in several places. I based this blog post on:

But if you search for FRE 407, I'm sure you can find other sources of your own.

       

Tuesday, August 17, 2021

Off-cycle post: Can "lying to the public" be part of your process?

This post falls entirely outside my regular, planned sequence (the next of which is going to be Part 3 on process management -- Part 2 is here), and also outside the two-week cadence that I defined back in the beginning. (Is two weeks too long to wait between posts? Leave me a comment either way.) But I want to comment in a timely way on Christopher Paris's recent blogpost as follows:

Caspian Pipeline, Responsible for Falsifying Reports Related to Oil Spill, Holds ISO 14001 Environmental Certifications - Oxebridge Quality Resources

By all means read the whole story for the juicy details, as well as the story from the Moscow Times on which it is based. But the gist is in this one-sentence summary:

The Caspian Pipeline company responsible for falsifying the size of a recent Black Sea oil spill "guaranteed" its environmental safety capabilities by pointing to ISO 14001 certificates issued by Bureau Veritas Group and accredited by UKAS.

Of course the environmental damage is appalling, and the firm's mendacity is morally reprehensible. But I have to admit that when I first read the article, a small contrarian voice in the back of my head asked, "But what if they were following their internal processes? What if one of their processes says, 'In case of an environmental disaster, lie to the press.'? Could that make them still compliant to ISO 14001 after all?"

So I had to go check the standard. Turns out the answer is "No, your process can't tell you to lie to the public," but it's not as obvious as you would hope. The ISO 14001:2015 standard contains 25 instances of the word "communicate" or "communication" in the normative clauses 4-10. Of those 25 instances, three say that communication has to take into account the organization's compliance obligations (7.4.1, 7.4.3, and 9.1.1), and only one (in 7.4.1) requires the organization to "ensure that environmental information communicated is consistent with information generated within the environmental management system, and is reliable." But yes, that should be enough to prohibit lying to the public. Also, if the organization's compliance obligations happen to include truthful reporting then those three references apply as well.

What about other standards? ISO 9001:2015 references "communicate" or "communication" 17 times, but nowhere does it explicitly say those communications have to be truthful. Clause 7.4 gives the most guidance, but all it says is:

The organization shall determine the internal and external communications relevant to the quality management system, including: 
a) on what it will communicate; 
b) when to communicate; 
c) with whom to communicate; 
d) how to communicate 
e) who communicates.

ISO 45001:2018 takes the same approach as ISO 14001, requiring that:

When establishing its communication process(es), the organization shall:
-- take into account its legal requirements and other requirements;
-- ensure that OH&S information to be communicated is consistent with information generated within the OH&S management system, and is reliable.

In other words, standards that regulate topics where people might get hurt and around which there are probably legal regulations say something about keeping your communications "reliable."

Does this incident prove the system of certification and accreditation to be corrupt? Not by itself. In the absence of other information, it's always possible that someone went crazy five minutes before his press conference began, and therefore went completely off-script. No process can prevent isolated instances of non-compliance. What matters is how the organization responds to the situation after the fact, and whether Bureau Veritas follows up this paper trail during their next audit to ensure that the organization's response was meaningful and appropriate. Inquiring minds want to know....

Maybe Christopher Paris will be able to follow up on this news later. If you haven't seen his Oxebridge blog yet, by all means check it out.

    

Thursday, June 10, 2021

Design reviews and product liability

In my last couple of posts I talked about documented artifacts: that you should keep them only when you need them, but also that sometimes you need ones you didn't expect. Today I'd like to talk about one special case: design review minutes.

Whenever I've audited engineers (or almost), they've expressed resistance to having to keep written design review minutes – except in those few cases where the project made them use an automated design tool that required design review comments from somebody else before they could check in their work. In general the sentiment seems to be, "Look, I'm an experienced engineer. I know what I'm doing. Besides, I did ask Fred to look it over and we discussed some of the more interesting parts over lunch. Do I really have to write it down too?"

Of course I understand. At the time, it seems like an extra step, and a needless one. Who is ever going to care why you decided to use a 5 ohm resistor in that spot instead of a 10 ohm resistor? 

But let me tell you what a product liability attorney once told me, years ago. And then think about it.

Before I go on, it is important that I make a number of critical disclaimers. I am not a lawyer. It is not the purpose of this blog to offer legal advice, and no statement that I make here may be construed as legal advice. I might have misunderstood what this man told me, or the rules might have changed since then because it really was quite a few years ago. Before you rely on any of the concepts explained here, consult with professional legal counsel on your own. 

Also: Do not try this at home. Take only as directed. Do not bend, fold, spindle, or mutilate. And do not back up: severe tire damage.

Now, all of those things having been said ….

He started off by explaining that product safety law in the United States is a moving target. The general requirement for product safety is that you have to make a product as safe as the technology reasonably allows you to. So when there are improvements in safety technology, new products are held to a higher standard. But there is no requirement to retrofit older products that are already in the field. When anti-lock brakes were finally perfected, that did not trigger a recall of every car in the United States in order to replace the brakes.

Therefore, if somebody gets hurt while using your product and decides to sue the company, the plaintiff has to prove that you neglected to take some safety precaution that everyone else in the same industry was taking, during the time when that product was released. Maybe in the rare case this is obvious, but often it's not.

What happens next? 

Someone from the Engineering department has to testify in court. Now, the design engineer responsible for the product retired to the Bahamas twenty years ago, and died of old age fifteen years after that. So whoever shows up in court really doesn't know the history behind the product design. In particular, he can't answer the question, "Did the design engineer take into consideration all the currently-available knowledge about safe product design when working on this product?" 

What happens next?

Well, if the company can produce one sheet of paper with the words "Design Review Minutes" across the top, a date, a list of attendees, and some notes about the product design, then according to this attorney the Court is likely to rule that the responsible engineers "probably" discussed safety topics as well, since it is clear they were reviewing the design and the safety requirements in force at the time would have been common knowledge to all affected engineers. Therefore the Court is likely to rule that the plaintiff is forbidden to pursue a line of inquiry that vaguely accuses the engineers of some generalized carelessness or negligence. If the plaintiff has something concrete to go after, or some other line of inquiry to pursue, the case can proceed. If not, the case is dismissed and the company is off the hook.

Naturally we all hope that nobody ever gets hurt using your product. And, as noted in the disclaimers above, I can't actually promise it will be so easy in case someone does. But think about saving some basic design review minutes, just in case.

           

Five laws of administration

It's the last week of the year, so let's end on a light note. Here are five general principles that I've picked up from working ...