Loading...

Certification Decision & Audit

 

View Certification Decision & Audit Document

1. PURPOSE:

This procedure establishes system of the certification decision process for organization’s management system activities. The procedure covers grant/continuation of certification, modification of an organization’s scope, evaluation of management system changes of a certified organization, reassessment/renewals, suspension and withdrawal of certificates.

2. SCOPE:

This procedure is applicable for management system certification.

3. RESPONSIBILITY:

Certification Committee is responsible for executing this procedure and Director shall monitor this activity.

 

 

4. FORMAL RULES FOR APPOINTMENT FOR CERTIFICATION COMMITTEE (CC):

 

CERTIFICATION COMMITTEE Members (DIRECTOR/CM/TC) and Coded Auditor-If required

QUALIFICATION CRITERIA

Degree/Diploma in Engineering (any discipline) and (or) Business Management.

Qualified Lead Auditor for any one of Management System.

EXPERIENCE

  1. Minimum 5 years of experience in a Senior Managerial position in any organization.
  2. Minimum 2 years of work field experience in Quality Management System.
  3. Auditing Experience – Min 10 Man Days.
  4. Must have knowledge about  ISO 17021-1:2015, ISO 9001:2015 & ISO 14001:2015, ISO 45001:2018, ISO  22000:2018, ISO 20000-1-2018, ISO 27001:2022, ISO 42001:2023, ISO 27701:2019, ISO 50001:2018, ISO 13485:2016, ISO 55001: 2024, ISO 37001 :2016, ISO 22301:2019, ISO 21001:2018, ISO 41001:2018 & ISO 18788:2015 the certification process

Note:  Experience in (a) and (b) can be concurrent also.

KNOWLEDGE & SKILLS FOR SPECIFIC FUNCTIONS

Must be aware of Business Management Practices, audit principles, techniques and practices, IMS Standards, certificate issuance criteria, business sector, product, process and related requirements, report review skills   and Knowledge of ISO/IEC TS 17021-3:2013 Checklist, ISO/IEC TS 17021-2:2012 Checklist, ISO/IEC 17021-10:2018, ISO/IEC TS 17021-5:2014(E), ISO/IEC TS 17021-9:2016(E), ISO/IEC TS 17021-6:2014(E), ISO/IEC TS 27006-2:2021(E), IAF MD 9:2022, ISO/TS 21030:2023(E), ISO/IEC 27006-1:2024(en), ISO 50003:2021(E), ISO 22003-1:2022(E), ISO/IEC 17021-1:2015(E), ISO_IEC_DIS_42006(en), ISO/IEC TS 17021-11:2018(E),  ISO/IEC 20000-6 & AB requirements for audit & certification of occupational health and safety management system

Note: Certification Committee comprises of  DIRECTOR, CM, TC and Coded Auditor if Required.  CM will take the decisions on the advices of  all concerned in the Committee.

Note: It may not be possible for a single person (CERTIFICATION MANAGER/TC) to have all the competences required under different management scheme. In such case, the competence shall be supplemented by another coded person to fulfilled the criteria.

 

CERTIFICATION COMMITTEE WILL BE CONSISTING OF:

 

DIRECTOR/ CERTIFICATION MANAGER/ /Technical Coordinator (Coded Auditor/TE if needed)

 

     

 

 

4.1 OPERATIONS  OF CERTIFICATION COMMITTEE (CC):

The Lead Auditor sends the Audit report with its supporting documents to the Office Coordinator (OC) of PDCA immediately after the Audit.  The OC of Certification submits this report to the Certification committee, shall be reviewed by the certification committee, for ISO 9001:2015 & ISO 14001:2015, ISO 45001:2018, ISO  22000:2018, ISO 20000-1-2018, ISO 27001:2022, ISO 42001:2023, ISO 27701:2019, ISO 50001:2018, ISO 13485:2016, ISO 55001: 2024, ISO 37001 :2016, ISO 22301:2019, ISO 21001:2018, ISO 41001:2018 & ISO 18788:2015 consisting of  TC , CM and Directors, and if all members of Certification committee does not have the company audited IAF code then CC will take the services of auditor competent in relevant IAF code.

 

The Audit report is reviewed by the Certification Committee in order to verify that –

 

  1. the information provided by the audit team is sufficient with respect to the certification requirements and the scope for certification
  2. the audit team has reviewed, accepted and verified the effectiveness of correction and corrective actions, for all nonconformities that represent failure to fulfil one or more requirements of the management system standard, or any situation that has raised significant doubt about the ability of the client’s management system to achieve its intended outputs.
  3. The audit team has  reviewed and accepted the client's planned correction and corrective action for any other nonconformities

 

 It is ensured that auditors/ Technical experts involved in audit process do not sit in the certification committee, to review the same audit and audit report in which they had participated.  The certification committee enquires about any clarification with the Audit team, if not satisfied it can ask for short re-audit or full audit by other auditors.  About potential short comings if any, the committee educates the concerned lead auditor/ auditor. While taking certification decision, the certification committee also takes into consideration information about the organization available in public and also the Clients feedback about the quality of the audit. If every thing is found OK, the Certification committee takes decision (see PDCA-F-33) to accept Lead Auditors recommendations and issues certificate of conformity under the sign of Director.

 

 

4.2. DESCRIPTION:

4.2.1 Grant of certification and certificate issuance

4.2.2 After completion of the Certification audit of a client’s management system. Audit Team Leader shall review the audit package containing Audit plan, Audit report and relevant correspondence and submit his findings on form ‘Approval by Audit Team Leader. The completed audit pack shall be submitted to CM. CM shall examine and review the Certification documentation package within 5 days after certification audit for adequacy of documents requirements for grant of certification.

4.2.3 Certification Committee shall have collectively an appropriate level of knowledge and experience in all areas under review. Certification Committee may take assistance from experts or experienced auditors in specific areas where additional expertise may be required.

4.2.4 While reviewing the scope IAF guidance on the applications of ISO 9001:2015 & ISO 14001:2015, ISO 45001:2018, ISO  22000:2018, ISO 20000-1-2018, ISO 27001:2022, ISO 42001:2023, ISO 27701:2019, ISO 50001:2018, ISO 13485:2016, ISO 55001: 2024, ISO 37001 :2016, ISO 22301:2019, ISO 21001:2018, ISO 41001:2018 & ISO 18788:2015 are considered.

4.2.5 Conditions for grant of certification:

a) The client has established facilities for the manufacture of product or providing service.

b) The assessment meets the appropriate Management Standard for which certification was sought.

c) The client shall have completed at least one cycle of IA and MRM to indicate the effective installation of the system.

d) Scope / activities of client are covered under accredited scope of PDCA

e) The assessment was conducted by qualified competent Auditors/Technical Experts

f) The client shall pay the necessary charges.

g) All findings are reviewed, accepted and verified the effectiveness of correction and corrective actions for 

1. Failure to fulfill one or more requirements of the management system standard, or

2. A situation that raises significant doubt about the ability of the client's management system to achieve its intended outputs

h) In case the audit report needs clarifications/ further investigation the Certification Committee shall revert back to the client.

i) All completed documentation required for Certification shall be maintained.

j) The implementation period of applicable Management Systems shall be minimum 2 months.

k) PDCA ensures the competence of the group or individuals responsible for making certification decisions related to ISO 37001, including but not limited to initial certification, scope expansions, recertification, and suspension decisions

4.2.6

Upon successful examination by CM, the details regarding the audit report are recorded on Certificate Issue Checklist form (PDCA-F-33). Certification Committee will examine the audit record and record his comments and recommendation for the certification in the Certificate Issue Checklist form (PDCA/F/32). The persons who form the audit team shall not be involved in the decision-making process.

4.2.7

Upon technical approval from Certification Committee, CM forwards the file to Technical Coordinator for issuance of Draft Certificate. After getting the confirmation about the payment from the client and approval of draft certificate, final certificate is prepared by the TC.

Certificate identifies the following:

1. Certificate number;

2. PDCA Certification Body mark

3. Company name;

4. Accreditation Body Mark;

 5. Company location (s) (including office address / other sites if necessary);

6. Management System Standard;

7. Scope of Certification;

8. Original Certification date; (On or after the date on which certification decision is taken)

9. Current certificate issue date (applicable to registrants scope modifications or revisions to certificates); 

10. Certification expiry date;

11. Validity period.

12. Surveillance Due Date

13. Signature of Director (Any One)

4.2.8

After issuing the certificate TC will update the Certificate Issue Register (PDCA/F/38) and PDCA website.

4.2.9

Recording and numbering for each Certificate of Registration issued by PDCA shall be as below:

QMS: PDCA/QMS/Any Alphabet YEAR/XXXX,           

Company Name - PDCA

QMS – Quality Management System

One Alphabet YEAR – Year of Certificate Issued

XXXX – Unique Series number

EMS: : PDCA/EMS/Any Alphabet YEAR/XXXX,

Company Name: PDCA

EMS – Environment  Management System

YEAR – Year of Certificate Issued

XXXX – Unique Series number

OHSMS: PDCA/OHS/Any Alphabet YEAR/XXXX

Company Name: PDCA

OHS – Occupational Health & Safety 

YEAR – Year of Certificate Issued

XXXX – Unique Series number

 

FSMS: PDCA/FSMS/Any Alphabet YEAR/XXXX

Company Name: PDCA

FSMS – Food Safety Management System

YEAR – Year of Certificate Issued

XXXX – Unique Series number

 

ISMS: PDCA/ISMS/Any Alphabet YEAR/XXXX

Company Name: PDCA

ISMS – Information Security Management System

YEAR – Year of Certificate Issued

XXXX – Unique Series number

 

ITSMS: PDCA/ITSMS/Any Alphabet YEAR/XXXX

Company Name: PDCA

ITSMS – Information Technology Service Management System

YEAR – Year of Certificate Issued

XXXX – Unique Series number

AIMS: PDCA/AIMS/Any Alphabet YEAR/XXXXX

Company Name: PDCA

AIMS –Artificial intelligence Management System

YEAR – Year of Certificate Issued

XXXX – Unique Series number

 

EnMS: PDCA/EnMS/Any Alphabet YEAR/XXXX

Company Name: PDCA

EnMS –Energy Management System

YEAR – Year of Certificate Issued

XXXX – Unique Series number

 

MDQMS: PDCA/MDQMS/Any Alphabet YEAR/XXXX

Company Name: PDCA

MDQMS –Medical Device Quality Management System

YEAR – Year of Certificate Issued

XXXX – Unique Series number

 

EOMS: PDCA/EOMS/Any Alphabet YEAR/XXXXX

Company Name: PDCA

EOMS – Management System for Educational Organizations

YEAR – Year of Certificate Issued

XXXX – Unique Series number

 

 

AMS: PDCA/AMS/Any Alphabet YEAR/XXXXX

Company Name: PDCA

AMS – Asset Management System

YEAR – Year of Certificate Issued

XXXX – Unique Series number

 

 

 

 

ABMS: PDCA/ABMS/Any Alphabet YEAR/XXXXX

Company Name: PDCA

ABMS – Anti-Bribery Management System

YEAR – Year of Certificate Issued

XXXX – Unique Series number

 

BCMS: PDCA/ABMS/Any Alphabet YEAR/XXXXX

Company Name: PDCA

ABMS – Business Continuity Management System

YEAR – Year of Certificate Issued

XXXX – Unique Series number

 

FMS: PDCA/FMS/Any Alphabet YEAR/XXXXX

Company Name: PDCA

FMS – Facility Management System

YEAR – Year of Certificate Issued

XXXX – Unique Series number

 

PIMS: PDCA/PIMS/Any Alphabet YEAR/XXXXX

Company Name: PDCA

PIMS – Privacy Information Management System

YEAR – Year of Certificate Issued

XXXX – Unique Series number

 

PSO: PDCA/PSO/Any Alphabet YEAR/XXXXX

Company Name: PDCA

PSO – Management system for private security operations

YEAR – Year of Certificate Issued

XXXX – Unique Series number

 

In case of Revision in a Certificate suffix R01, R02 etc are added to the certificate number depending upon revision of the certificate and the Date of issue is changed to the date when the change is granted and the expiry remains the same.

This number shall be recorded in the Registers of certified companies by the Technical Coordinator.

4.2.10

TC shall keep a copy of the issued certificate in the client file along with the Complete Audit report & signed Certificate Issue Checklist.

5.0 CONTINUATION OF ASSESSMENT

5.1       TC shall inform the client about due date of surveillance audit but sometimes the client also approaches PDCA either through a formal communication or verbally.

5.2       An invoice shall be raised in respect of the continual assessment and sent to the client together with the letter indicating the audit schedule and names of auditors including the Team Leader.

5.3       The audit shall be conducted in accordance with the Procedure for conduct of Surveillance Audit and assessment reports reviewed by CC. A communication shall be sent to the client based on the recommendations of the Audit Team Leader.

 

6.0 CHANGES/MODIFICATIONS:

6.1       A Certified Company may request changes to their certificate due to a number of reasons such as change of address, change of company name etc.

6.2       If the reason for required change(s) is adequately explained in writing by the company, the CM shall review the same. Additional information/ clarifications may be sought from the client in case any ambiguity is observed during review. Based on the information Change of Company Details Form shall be filled up and put up to CC for approval of issuance of a revised certificate.

6.3       Where the change is at the request of the client, an administrative fee is payable. The invoice raised shall be sent to the client for receipt of payment.

6.4       On receipt of payment from the client, revised Certificate of Registration shall be prepared and issued to the client. Records of issuance of new certificate shall be maintained. A copy of the revised certificate shall be kept in the file.  Earlier copy of the certificate shall be marked Obsolete to avoid its inadvertent use later.

6.5       The client shall be requested to return the previous certificate to PDCA.  On receipt the same shall also be marked Obsolete.

6.6   PDCA shall ensure that revised certification documents are clearly distinguishable from obsolete versions by implementing the following measures:

Revision Numbering and revision Control:

  • revision number (e.g., Rev. 01 after first revision).
  • Clearly indicate the issue and revision dates.
  • Maintain a revision history within the document.
  • If any changes are made to the issued certificate, the certificate number will remain the same; only the revision number will change.

PDCA shall ensure that All obsolete certification documents must be clearly marked and removed from circulation to prevent any misuse.

7.0       CHANGES PROPOSED BY PDCA:

7.1       The primary reasons for PDCA proposing amendment to certificate usually relate to registered scope of the company.  This is due to findings during an assessment/surveillance activity. Same shall be communicated to the client for acceptance. On acceptance, revised certificate shall be issued as per procedure state in above paras.

 7.2      If extension/curtailment of scope is requested during the opening meeting in Pre-Assessment/Final Audit/Surveillance Audit, the Audit team leader will conduct the audit according to the amended scope and mention the revised scope in the report to PDCA.

7.3       Amendments to scope may also be considered at the company's request for which and  PDCA will normally verify the compliance with the amended scope during the Surveillance Audit. Any commercial implications shall be suitable taken up with the client and settled.

 

8.0       CANCELLATION OF CERTIFICATE:

8.1       If a company requests cancellation of its Certification, the details shall be recorded on the Cancelled Certificate form by the CM, for approval by the Director. CM shall advise the client to return the Original Certificate to PDCA and instruct them not to use the certificate, reference thereof in any activity of the company.

8.2       On receipt, the original certificate shall be marked Obsolete and kept in the file for records.

8.3       Director shall ensure that the name of the organizations is deleted from the list of certified companies of PDCA and the Directory of Certified companies is amended suitably.

 

9.0       SUSPENDING, WITHDRAWING OR REDUCING THE SCOPE OF CERTIFICATION:

 

9.1  All suspensions will be authorized by the Director, and the client shall be notified in writing of said suspension. The conditions necessary under which the suspension will be revoked will be notified to the client. During suspension the client shall not abuse the logo and marketing brochures shall not imply the validity of the certificate. Examples which may prompt suspension are:

1. Non-Payment in accordance with the requirements of the agreement;

2. Significant areas of non-conformance with applicable Management Standards;

3. Ineffective or delayed correction of observed non-conformities;

4. Ineffective completion and implementation of program revisions required to meet        revised Management Standards;

5. Misuse of the Accreditation Body marks, logos and symbols.

6. Certified client has voluntarily requested for suspension.

7. In the event of certified organization not accepting PDCA to conduct surveillance audit even after three months of its due date.

On fulfillment of the indicated conditions and confirmation by the client, such changes shall be reviewed by Director and his recommendations are forwarded to CM for removal of suspension. Client shall be informed of the decision.

9.2 Requirements for withdraw of certificate are:

1. Under the relevant provisions of Clause 9.1

2. At the request of the Organization;

3. If the Management System Rules are changed and the Organization either will not or cannot ensure conformance to the new requirements within the agreed time frames;

4. If the Organization fails to meet financial obligations as agreed with PDCA

5. Closure of a company or facility;

6. Noncompliance or failure to execute PDCA contractual requirements;

7. Falsification of any nature

8. Other conditions deemed appropriate or formally agreed between PDCA and and the organization.

 

9.3 Under suspension, the client’s management system certification becomes temporarily invalid. Director ensures the enforceable arrangements with its client to ensure that in case of case of suspension the client refrains from further promotion of its certifications per Agreement. PDCA specify the subsequent actions taken by him.

9.4 Director ensures that the suspended status of the certification is publicly accessible on the website and also communicated to the client in writing.

9.5 Director ensures, if within 6 months of suspension or the time limit set by PDCA (but less than 6 months) the issues are not resolved that have resulted in the suspension, then the Director takes decision of withdrawal or reduction of the scope of the certification and communicates in writing to the client and the list is updated on the website.

9.6 Upon verification of audit reports and subsequent on-site verification, the Director may reduce the client’s scope of certification to exclude the parts not meeting the requirements, when the client has persistently or seriously failed to meet the certification requirements for those parts of the scope of certification. Director ensures the reduction shall be in the line with the requirements of the standards used for certification.

9.7 Director ensures that there is enforceable arrangements with the certified client concerning conditions of

withdrawal ensuring upon notice of certification that the client discontinues its use of all advertising matter that contains any reference to a certified status as per contract.

9.8 Director ensures through TC, it correctly state the status of certification of a client’s management system as being suspended, withdrawal or reduced in PDCA website. PDCA may publish status of certification in newspaper as necessary.

 

10.0     SHORT NOTICE AUDIT:

The Director can request an audit on short-term notice to verify handling of customer’s complaints, important modification within the organization or any reason leading to withdrawal or suspension of the certificate.

The Director, based on the nature of complaint, shall take decision on the time frame within which the audit is to be conducted. In case of Short Notice Audit because of Customer Complaint, the audit team shall not disclose the name of the complainant.

The CM shall assign an auditor (LA or AD) to perform the short notice audit and informs the organization about the identity of the auditor. The organization may refuse the appointed auditor and request once for a substitute.

After the audit, the auditor shall report about the results of his investigation and shall make his recommendation to the Director.

11.0     RECERTIFICATION:

11.1 Upon completion of the recertification audit (as per PDCA-SOP-12), an evaluation as per procedure given under clause 4.1of this procedure is followed.

In addition the following shall be considered for granting the recertification  1. Results of the review of the system over the period of certification

2. Complaints received from users of certification, if any

12.1 It shall be ensured that the client’s management program continues to comply with all the requirements under which the original Certificate was issued.

12.2 On satisfactory completion of the process, the certificate shall be issued. This recertification shall be for an additional three years. The same recertification procedure shall be adopted at each subsequent recertification.

12.3 Original certification date shall remain same. Current certification date shall be on or after the date of recertification decision is taken. Certification expiry date will be three years after the date of recertification.