Showing posts with label management review. Show all posts
Showing posts with label management review. Show all posts

Thursday, October 3, 2024

How do you prove "consideration"?

How many times have you seen departments do things that don't help them any, just because it's easier for the auditor once a year? I've seen it too often to count, and it's never the right thing to do. Oh sure, in a sense I appreciate it when I'm the auditor. But also, it's really unnecessary. I've audited a lot of departments over the years, and they've done things a lot of different ways. If it works better for you the other 364 days of the year to do this rather than that, … well, as long as it meets the rules I can probably figure it out.

I was thinking about this recently while talking to someone about the rules for management review. Right now, ISO 9001:2015, clause 9.3.2 states, "The management review shall be planned and carried out taking into consideration"—and then there follows a long list of topics, (a) through (f), where item (c) is further divided into seven subtopics. It's a comprehensive list. Anyway, my friend was saying he wishes the ISO would change this requirement to say that management review must explicitly include all these topics, because "How are you supposed to prove consideration to an auditor?" What he meant, of course, was that if the agenda for management review were required to include every one of these topics and subtopics, it would be easy to show that you had "considered" them all.

Long-time readers may remember that I think this is a terrible idea! The biggest risk in any management review is that the participants are likely to get bored. To avoid boring them, cut out everything you can. Discuss only the pain points that have to be resolved by the specific participants of this meeting. That means that if your internal audits or your supplier evaluations are all green, it's enough to wave your hand and say so; you don't have to drag the attendees through an itemized list of each one. Spend your time instead explaining that it's time to buy a new widget-stamping machine, because the old one slides out of alignment once a month like clockwork and the rework costs are eating you alive. 

But of course you still have to pass that audit once a year, so how are you going to do it? It's all very well for me to say that you shouldn't rearrange your whole management review just for the convenience of the auditor, but you are going to have to show some kind of objective evidence. What will it be?

Do it like this.

First, as you prepare the meeting, go through every single one of those topics listed in clause 9.3.2, and document where it stands right now. (You have to do that anyway in order to find out where your pain points are, since those are the topics you will discuss.)  

Second, while you are conducting the meeting, keep all this material handy where you can reach it. Maybe this means it's stored electronically just one click away, or maybe it's on paper in a notebook on the desk next to you. But just in case someone brings up a question about one of those topics you thought you could afford to skip, make sure the data is immediately available.

Third, store all this data as a permanent Quality record, together with the minutes from the management review meeting that it supported.

Fourth, ask your internal auditors to look for this data when they audit the management review process, just to keep you honest. 😃 Naturally whoever audits the Quality function doesn't work for you—do they??—so if you make a mistake they won't be shy about writing it up.

And finally Fifth, when the external auditor visits, pull out all this stored data as proof that you really did consider all the topics listed in the standard. Then you can explain why you tailored the agenda to address the problems that really needed management attention, and why you skipped over all the topics that were functioning smoothly because they were just business as usual. 

Simple. Straightforward. And you don't need to "include" all those topics in the review in order to "consider" them. 

      

Thursday, March 9, 2023

How do you comply with MANY standards at once?

Since the beginning of the year I've been writing about management systems; and for the last three weeks I've specifically discussed management review. Before I shift to talking about something else, let me touch on one more question. What do you do when you have to comply with several different management system standards all at once?

This is not uncommon. Many companies whose Quality systems are certified to ISO 9001 (for example) also have Environmental systems certified to ISO 14001; many also have Health and Safety systems certified to ISO 45001. And there are many more management system standards than these. Depending on your line of work, there might be yet another—or even several—that apply to you. How do you keep up?

The first step is to simplify. And to my mind that means folding all your multiple management system standards into one Integrated Management System.

After all, there are several features that every management system standard requires. They all require some way to manage documents and records; they all require some definition of management responsibility; they all require training; they all require an internal audit program; and yes, they all require management review. So if you have to comply with three different standards that all require document control, do you set up three different document control systems? I hope not! Whenever requirements overlap, just do it once. Then if there are special details that apply to one standard but not the others, introduce it as a feature of the common system.

This means that you set up one employee training system, but then you can have a matrix to identify which employees need which classes. Everyone gets trained on company policies and fundamentals; but only these people have to get trained on calibration, and only those people have to get trained on how to analyze environmental aspects and impacts.

It means that you set up one document control system, with a simple indexing method that allows you to retrieve the documents you need for this or that special purpose.

It means that you plan out one master audit schedule for the year. The individual auditors might have to change depending on their respective specialties. But with one master schedule you know that you've covered the whole organization, and you minimize the risk that some department has all their internal audits accidentally cluster in the same month.

And it means that you plan for one program of management reviews. Here you might balk. Doesn't management review have to be focused? Don't we need to have different people in the room to review the QMS than we need for the EMS? If we merge all the management reviews together, won't that waste the time of people who are only needed for one part but have to sit through all the rest?

No. If you design your management review in the ways I've already described, it will be fine.

Of course the technical details out of the QMS will be different from those out of the EMS or some other system. But for the most part you shouldn't bring technical details into the meeting in the first place! If your systems are running correctly, the technical details should (mostly) all have been handled as part of routine operations. And I've already said that you shouldn't bring to the meeting anything that can be handled by routine operations.

The only issues that you have to address in the meeting are things that aren't working, and that cannot be handled anywhere else. These are the topics that require the action of senior management to resolve them. And as long as the topics genuinely require the attention of senior management, it doesn't matter that this topic relates to the QMS and that topic relates to the EMS. Senior management is already used to addressing topics all across the organization, from marketing strategy to financial performance to personnel legislation. They can handle variety here too, so long as you are careful not to swamp them with unnecessary details. Let them deal with the forest; there are plenty of other people who can tackle the trees.

And so far as possible, give yourself one Integrated Management System to follow, not a truckload of special-topic systems for this and that. Keep it simple.

           

Thursday, March 2, 2023

What should you LEAVE OUT of Management Review?

Last week we asked why Management Review gets such bad press. While the activity is fundamental to any Quality Management System, many people in many organizations will do seemingly anything to get out of it. And I summarized the points of a discussion by Bill Hackett of QBD Strategies that listed several common failings. But there is one that didn't make Bill's list, and I think it is important enough to give it a post of its own.

You don't have to report everything you know. Let me explain what I mean.

The ISO 9001:2015 standard identifies in clause 9.3.2 a long list of mandatory topics, issues that have to be considered during management review. You know the list as well as I do, right? Status of actions from previous reviews; changes in internal and external issues; trends in customer satisfaction; quality objectives; process performance; product conformance ... I'm not even halfway through the list yet. It goes on and on.

And many organizations, in order to make things simple for their auditors, use this list verbatim as an agenda for their management review meetings. That way the auditors can quickly check that yes indeed, the organization really did consider all these topics. And to be fair, the list truly is comprehensive. Reviewing all those topics really does ensure that you have gotten a systematic look at your QMS.
Image by Magnet.me from Pixabay

The problem is that it is also mind-numbingly dull. And it is totally unnecessary.

Wait, what? That list comes from the standard. How can it be unnecessary?

Simple. The standard never says that you have to report on all these issues. All it says is that "The management review shall be planned and carried out taking into consideration ... [blah, blah, blah]."

What does that mean?

Well to start with, you have to know where each of these issues actually stands. Is it green or red? On-track or off? So when you are preparing the meeting, you still have to do all the same work you do today.

More than that, you have to check: if a metric is red, or if some process is off-track, is it already being handled in the normal course of business? Did your existing systems already pick up the deviation and address it? Again, make sure you know the status of every single point. 

Collect all this data and file it somewhere as the background to the meeting. That way you can show it to your auditor to prove that yes, you really did "take into consideration" each of the required topics.

But when you plan the actual meeting itself, don't waste your time reporting any metric that's green, and don't waste your time explaining any deviation that's already been handled by your regular business operations. You should have the data at your fingertips, of course. If anybody asks about it, you should be able to answer the question with a single mouse click. And if any of that data shows disturbing trends (that haven't been handled yet), naturally you want to bring those trends forward to discuss them.

But the only topics you should plan to address during your management review meeting are topics that cannot be handled anywhere else: topics that are going badly, and that require the intervention of senior management to set them right. 

Yes, you have to "take into consideration" the entire scope of your QMS, to make sure you don't miss something. But there is no law that says you have to give valuable meeting time to things that are going fine. Focus where it hurts.

This way the meetings are shorter, and each topic has an urgency. That makes each topic meaningful. Your attendees will care, and they will listen. It's better this way.

           

Thursday, February 23, 2023

What's so bad about Management Review?

Last week I argued that Management Review is the key element of a Quality Management System, because feedback is what turns any phenomenon into a system, and Management Review is the highest and most comprehensive feedback mechanism in the organization.

But Management Review has, to put it gently, a mixed reputation in most businesses. For every Quality practitioner who (like me) insists that it is the heart of things, you can find several who concede grudgingly that yes, it is required; but who also know that most managers in their organizations will do anything to get out of attending.

How can this be? The problem is that there are many ways management reviews can go wrong. If you avoid them, the meetings are engaging and productive, but it's a high-wire act. Slip just a bit, and you miss the target in a big way. As I wrote once in another context, there are many ways to make management reviews boring and over the years (before I finally learned better) I've used most of them.

A couple of years ago, Bill Hackett of QBD Strategies posted a discussion on myASQ that nicely summarized the weaknesses he has most often seen in management reviews. It's a good list, so I'd like to abbreviate it here.

Senior management not present

The whole point of the meeting is to assess whether your QMS is working, and then—in case it's not—to take decisions that will put it back on course. If senior management is missing, you can't take fundamental decisions and the meeting becomes pointless. (The absence of senior management is also a formal failure, because [for example] ISO 9001:2015, clause 9.3.1, defines the whole activity by saying that, "Top management shall review the organization's quality management system, at planned intervals, ...." But next to the pragmatic problem, that's almost beside the point.)

Reviews occurring infrequently

Yup. If the reviews are few and far between, you spend the meeting time rehashing ancient history. The issues were resolved months ago, but here are more slides about the same subjects, just because. Pretty soon people are checking their phones and the meeting is dead.

No established agenda

I don't know how you can hold a meeting without an agenda, but Hackett says he's seen it plenty of times in audits. No agenda increases the chance of missing something important, and it means you can't ask participants to be prepared ahead of time. So how can you get anything done?

Lack of process ownership when reporting

Without a clear owner for each process, you can't tell whose job it is to fix something when it goes off the rails. I talk about process ownership at some length here, and it all applies.

Insufficient or irrelevant information presented

Heavens, yes. When you are close to a problem, you see all the details and you know intimately why they are important. But when you generate your PowerPoint slides to explain the problem to management, it's easy to leave out the parts that you think are "so obvious" you don't have to mention them. Bad news—these points aren't obvious to top management, and you do have to mention them. When you are urgently explaining that "The glitzenhammer has to be refrangulated right away!" and they stare back at you in bafflement, it's a sign you might have left out something important.

Lack of support for management review facilitator

I might phrase this as "lack of support for the management review process," but we mean the same thing. You can't possibly put on the whole meeting yourself. You need the input and cooperation of the functional areas. Also, as Hackett points out, it helps to use templates (so the information is all presented the same way); it helps to collect it all beforehand (so that the presentation is smoother, and so you can check if some of the results look wrong); and so on. Every step of the way you need the support of others.

The good part is that if you can make the meeting run smoothly and productively, then the process owners and functional specialists that you have to rely on will be happy to cooperate. At least that has been my experience. It's almost as if addressing the first five on this list buys you the sixth one for free. Of course, nothing is really free. But addressing these gaps is the first step to creating a dynamic culture for management reviews. It's possible. And it's worth it.

   

Friday, February 17, 2023

Try This Today: From Reactive to Proactive

Following up on yesterday's post about management review, here's an article that I published in Quality Progress back in June 2020. It's called "Try This Today: From Reactive to Proactive." The article belongs to ASQ now, so I won't repost the text of it here. But you can find it by following the link. 

You need an ASQ login to read the article itself; without that, all you can access is the bibliographic information. Still, I offer it here in case you can access it.


  

Thursday, February 16, 2023

The key to your management system

A few weeks ago, Etienne Nichols of Greenlight Guru posted a question on LinkedIn:

"What is the most important part of a Quality Management System?"  

He listed several candidates:

  • Purchasing?
  • Quality Policy?
  • Customer Focus?
  • Design & Development?
  • Management Responsibility?
  • Documentation and Traceability?
  • Corrective Action / Preventive Action (CAPA)?

It will surprise none of you that I disagreed with all of these choices. Here's what I told him.

Management Review. No question.

Of course the reality is that they are all important, like [your other respondents] have already said. But the other reality is that you'll never get it right the first time around, no matter what. So it's critical that you have a mechanism for evaluating what went wrong, and then assigning actions to make it better.

Most management systems have several of these mechanisms, at different levels and with different frequencies of recurrence. But Management Review is (so to speak) the master evaluative mechanism, that incorporates all the others. Therefore Management Review is ultimately what makes the difference between just having a heap of rules and having a true management system.

That prompted a bit of a discussion. Among other things, he asked me how often a startup should schedule Management Review for maximum effectiveness. I answered:

Goodness, there's probably no one-size-fits-all answer. And it depends what you have in mind.

There will be some things you try to implement, and on the first day it becomes obvious you missed something important. If that happens, and you can see how to patch it so it's functional again, don't wait. At the same time you don't want to second-guess yourself every single week.

I'd probably settle on suggesting that you schedule a regular Management Review once a quarter: that gives you long enough to make progress on (for example) the risks and opportunities you've identified as part of the Context of your organization, but it's not so long that you waste time reviewing ancient history. (Holding these reviews once a year is WAY too infrequent.) 

Of course, if you hold them that often you also have to optimize the meeting so that it takes not one minute longer than you really need. There are ways to do this, but they all take a lot of focus. 

If you're looking for more opinions, I could talk for hours. 😀 

That last sentence, too, should surprise none of you.

      

Thursday, September 22, 2022

Things change

A few weeks ago I was writing about the Context of the Organization (COTO), and there's one final point I'd like to make before I drop the subject. Your analysis is not a one-time exercise, because your context will change. Therefore you have to review the results and update them from time to time.

Image by Gerd Altmann from Pixabay
Intuitively this should make sense. Things change around you, and it's only natural that you will change to accommodate them. In 2019, only the smallest percentage of American companies had emergency plans in place to address a global pandemic; and the fraction of office jobs that could be done from home was tiny. By the dawn of 2021, every business in the country had figured out how to respond to a pandemic (regardless whether they had formalized the results in a document); and work-from-home had become a lot more common.

You can expect smaller changes, too. One of the outputs from your COTO analysis, after all, is a list of risks for your business. Then once you have a risk list, the basic principles of risk management say that you go to work addressing the most important ones: either take action to prevent them, or to mitigate them, or at least to define contingency actions after the fact in case one of them takes place.

But those very actions themselves now change the risk profile that you face. Maybe when you did your COTO-and-risk analysis you found five high-priority risks. But over the next few months you took steps to prevent two of them outright; you made two of the others a lot less likely (even if still possible); and you defined a recovery plan in case the last one happens. Are you still facing five high-priority risks? Of course not. The list has dropped to three, and (depending how you evaluate the likelihood and impact of those three after the measures you put in place) they might not all be high-priority any more.

Or you might have changed your company's strategy to focus on different products for a different market. Many years ago I worked for a small startup in the B2B space: we made products that we sold to other businesses. But one year we saw an opening and reoriented the company towards making smaller, individual-sized products for the home office market. That was some years before we got ISO 9001 certification, so we didn't have a written scope statement at the time. But if we'd had one, it would have changed. And COTO is directly tied to scope.

So set up a regular schedule to review and re-evaluate your COTO. It's simplest to make this part of your periodic Management Review, since the ISO 9001 requirements for Management Review include checking most of the elements of your COTO anyway. And then, based on the results of your review, propagate the changes to your risk lists and scope statement as well.

Bear in mind that it's a lot less work to revise your COTO than to set it up in the first place. Yes, things change; but mostly they don't all change at once. So it should be pretty simple to read through what you've already got and look for the places you have to edit.

__________

P.S.: This is probably not a burning concern of yours; but one consequence of the foregoing is that, since your QMS is based on your COTO and your COTO changes, there is no such thing as the perfect or final QMS. Everything can change, because everything depends on what you need—under changing conditions—in order to get what you want.    

          

Five laws of administration

It's the last week of the year, so let's end on a light note. Here are five general principles that I've picked up from working ...