Operational Governance Knowledge Flashcards No. 12/19

ISO 9001

From the Operational Governance flashcard deck; today this discipline goes by BizOps. The original card is republished here as a field note.

01 What is it

ISO 9001 is a standard (“normativa”) for certifying quality management systems that conform to a required set of principles. It belongs to the ISO 9000 family of standards.

The latest version, ISO 9001:2015, emphasizes risk management as opposed to risk avoidance.

02 When is it useful

  • When you want to transmit trust to someone — that’s what standards are for.
  • When you want to display the world’s most widespread (1M+ companies) quality stamp.
  • When you need a generic and broad framework in which to document and measure a company’s processes.

03 How to use it

  1. A specialist oversees the creation of a documented body describing the company’s processes pertaining to quality of service management and delivery (flowcharts, inputs/outputs).
  2. Each of these processes must comply with the Standard.
  3. Each process must be regularly measured for performance, in a way that is documented and demonstrable.
  4. A third party (i.e. not the ISO) audits your processes and certifies your company complies with ISO 9001:2015.

04 What the certification asks you to show

  • PDCA + risk management
  • Stakeholders, business model
  • Evidence of commitment
  • SWOT and PREN
  • Targets (OKRs are more than fine)
  • “Processes” KPIs
  • Process sheets (“fichas de procesos”) — e.g. onboarding, customer service, procurement…

05 Common pitfalls

  • An “ISO façade” to get the certification, not really representative of how the company works.
  • Thinking that being certified means you’re perfect. No — this is usually a bare minimum.
  • Thinking that ISO will tell you how to do things. It doesn’t: it is a generic set of principles that can be met in many ways.

06 References and resources