My personal understanding of internal audits in special equipment manufacturing units (please share your opinions if this is original work)
Thread Content
A Brief Discussion on Internal Audits in Special Equipment Manufacturing Units As is well known, regarding the management systems of special equipment manufacturing units, the Special Equipment Administration under the General Administration of Quality Supervision, Inspection and Quarantine has issued the mandatory safety technical specification TSG Z0004-2007 \"Basic Requirements for Quality Assurance Systems in the Manufacturing, Installation, Modification, and Maintenance of Special Equipment\" (hereinafter referred to as 0004). All special equipment production must comply with these specifications. (Note: This standard applies only to the production phase and does not cover filling; according to Document No. 910, the Rules for On-site Inspections of Special Equipment, filling falls under the usage phase.) This article offers opinions only on the internal audit section of this standard; any errors are welcome to be pointed out. I. Basis for internal audits Since the provisions regarding internal audits in 0004 are quite brief, and no further standards have been issued concerning internal audits for manufacturers of special equipment, some such manufacturers do not know what to do – how should internal audits be conducted to meet the requirements? I recommend that internal audits be conducted in accordance with the requirements of GB/T19011-2003 \"Guidelines for auditing quality and (environmental) management systems\". (Note: The draft version of 2012 for this standard has been released, with the title changed to Guidelines for Management System Auditing.) The reason is as follows: The introduction to the 2003 version of the standard states clearly that although this standard is applicable to the audit of quality and (environmental) management systems, users may consider adapting the provided guidelines through appropriate modifications or extensions to apply them to audits in other areas, including audits of other management systems. The 2012 version makes it clearer: the scope is expanded directly from audits of quality and environmental management systems to audits of any management system. II. Requirements of 0004 for internal audit: The requirements regarding internal audit in this standard are quite simple; they are described in element 15, Quality Improvement and Services. The relevant text reads as follows: An annual internal audit must be conducted at least once on a comprehensive basis, the reasons for any issues identified during the audit should be analyzed, corrective actions should be taken, and their effectiveness should be verified. This sentence has several implications: 1. It mandatorily stipulates the frequency of internal audits. 2. It specifies the implementation and follow-up verification of corrective actions. 3. Auditing is a management tool for examining activities and processes, and the results of audits provide information for managers to take action. III. Objectives and characteristics of internal audits in special equipment manufacturing units. In my opinion, there are 7 objectives: 1. To verify whether the policies and objectives are being implemented. 2. A management method was established. 3. It provides a management guarantee. 4. Prepare for the certificate renewal. 5. The need for self-improvement. 6. Ensure that the safety performance of special equipment is effectively controlled. 7. Evaluate compliance with laws and regulations, particularly safety technical specifications. There are 5 features: 1. It focuses on the system itself rather than the product, 2. Safety performance is of top priority. 3. Top management must provide support; otherwise it is meaningless. 4. It is a coherent systematic activity. 5. Audit activities must be independent. IV. Principles and scope of the audit: The principle is that it is necessary to ensure the objectivity, independence, and systematic approach of the audit. Objectivity: The audit evidence obtained must be records, factual statements, or other information that are relevant to the system requirements or audit criteria and can be verified. Audit evidence refers to the objective facts that exist, the statements made by the person under audit, and the existing document records. Independence: First of all, auditing is authorized, and this authorization stems from decisions by the company’s management, or from company policies, contracts, as well as legal and regulatory requirements. Secondly, auditors must possess auditing skills, and the process must be fair; when it cannot be proven that the person being audited is at fault, they should be deemed correct. Systematic approach: Audits are mainly divided into two categories, one is document audit, and the other is on-site audit. After confirming that the documents are in order, a on-site audit is conducted. The focus of document review is the compliance, suitability, operability, and adequacy of the system documents. The focus of on-site audits is the compliance, adequacy, effectiveness, and efficiency of the implementation of system documents. Audit scope: For an integrated system, a full-term audit is conducted; for a separately established system, an audit of 18 elements is carried out, with elements that are not necessary being excluded from the audit. V. Formulation of the review plan: The regulations stipulate that this should be done once a year; however, in my opinion, it is necessary to do so if the following circumstances exist. Increase the frequency of internal audits: 1. Apply for multiple certifications, such as ISO9000, ISO14000, OHSAS18001, etc., simultaneously. 2. Internal audit of the supplier. 3. Customer evaluations of the company. 2. Small and medium-sized enterprises hardly engage in this, but I think it must be mentioned. The audit plan should include at least the following elements: 1. Policies and objectives; 2. Audit scope – 18 specific elements for ad-hoc audits, while a comprehensive audit is conducted for integrated systems; 3. Audit time and location; 4. Procedures – the specific procedures for the audit must be clearly specified. 5. Composition of the review panel. IV. Formulation of audit objectives In addition to the policy and objectives originally set for the audit, the following aspects are also taken into consideration as key elements. 1. Changes in policies and objectives. 2. Adopt new processes and technologies to carry out new design and development. 3. System update. 4. Updates to regulatory standards. 5. Re-select the supplier. 6. The customer has a request. V. The process of internal audit: The internal audit process is essentially a PDCA cycle. (1) Preparation stage: P: 1. The quality assurance engineer or the person in charge issues an audit order, preferably one week in advance. 2. Appoint a team leader and several teams; it is best to organize them according to departmental structure for mutual evaluation. 3. Establish audit objectives and scope. 4. The team leader prepares the plan and distributes it. 5. Each group prepares a checklist. 6. The department under audit prepares resources and documents. (II) Implementation Phase D1. Hold the first meeting.
2. Conduct on-site audits in groups to gather information.
3. Identify nonconformities and then discuss them.
4. Hold the final meeting and announce the results.
(III) Summary Phase C
1. Issue nonconformity reports.
2. The responsible departments carry out corrective actions.
3. The team leader prepares a report, which is signed by supervisors and distributed.
(IV) Follow-up Phase A
1. Departments that have completed corrective actions notify the management department.
2. The management department re-verifies the situation; upon confirmation of compliance, it signs off.
3. The nonconformities are then closed.
VI. Issuance of Nonconformity Reports
(I) Definition of nonconformities
A nonconformity refers to a situation where requirements are not met. (Requirements are explicit, usually implicit, or necessary needs and expectations.) Explicit requirements are usually prescribed requirements, and are generally expressed in documents. Typically implied requirements refer to the management or general practices of organizations, customers, and other interested parties. The relevant needs and expectations are self-evident. Such implied requirements usually pertain to those that are widely recognized and acceptable, and they generally do not need to be explicitly stated in documents. The requirements that must be met are usually stipulated by laws and regulations. ) The main categories of non-conformities are as follows: A: Failure to meet standard or safety technical specification requirements (standards refer to product standards or the provisions of GB/T19001; safety technical specifications have defined criteria and usually refer to TSG regulations). B: Non-compliance with document requirements, which refers to QMS or QA documents such as manuals, procedures, and work instructions. C: Not in compliance with contract provisions, which usually refers to sales contracts or purchase contracts. D: Not meeting societal requirements: including obligations related to laws, regulations, standards, energy protection, environmental protection, and occupational health systems. E: Other regulations, common-sense requirements, requirements from top management. F: Customer Complaints (II) Classification of non-conformities 1. Non-conformity of documents: the documents do not meet the requirements, or the established documents are not implemented, or they are implemented but prove ineffective. 2. The equipment is substandard; in terms of resource conditions, the production and testing equipment does not meet the management requirements, such as failing to undergo calibration. 3. The products are substandard. The product does not meet the standards or safety technical specifications, nor does it satisfy the requirements of customers or society (Note: in the system for manufacturers of special equipment, regulatory requirements take precedence): 4. The personnel are unqualified; for positions that require certification, those without such certification or those who have it but lack the necessary skills are not capable of performing the job. 5. The environment does not meet the requirements; products, equipment, personnel, materials, production processes, management practices, etc., do not conform to the requirements of the environmental management system. 6. Non-compliance with occupational health standards refers to failure to meet the requirements of the occupational health management system. 7. Non-compliance with the required elements refers to failure to meet the 18 specified elements. 8. Other. (III) Principles for identifying non-conformities: For a non-conformity to be identified, the following requirements must be met: 1. It must fall within the specified scope; 2. It must have been reviewed; 3. There must be objective and conclusive evidence; 4. Insufficient evidence cannot be considered as a non-conformity. (IV) Classification of non-conformities: 1. Serious non-conformities: (1) Problems exist in the formulation of system documents, such as the lack of necessary element controls. What is often easily forgotten includes: non-destructive testing control, physical and chemical testing control, heat treatment control, and other controls (specifically defined in 0004). The reason is that it wasn’t examined carefully or there was a misunderstanding of the permission rules for that device. (2) There are outsourcing and subcontracting steps, but no relevant documents specifying them; these steps are most common in the design and manufacturing phases. (2) The key control elements, control points, and control stages were not effectively implemented. 2. It is quite common for the documents formulated to not match the actual situation – what is written down on paper is one thing, while the reality is another. 3. It violates the provisions of safety technical specifications or standards. (II) General non-conformities: 1. Non-conformities that have no impact on product quality, such as random signing, absence or confusion in document numbering, lack of indication as to whether a document is invalid, and absence of dates on documents. 2. The standards have been updated, but the system has not been updated in a timely manner. (V) Preparation of non-conformity reports: 1. The description should be objective, clear, and accurate; more importantly, it must be confirmed by the party being audited. 2. Objective evidence must be conclusive and traceable; one’s own subjective opinions cannot be used as direct evidence, and there should be no issue of the audited party not accepting it. 3. If the party being audited presents contrary evidence or objective facts that the auditor deems to be correct and valid, such evidence should be accepted, and the previously identified non-conformities should be revoked. 4. The report must not be exaggerated; it should be filled out truthfully. 5. Auditors shall not arbitrarily raise standards or document requirements. For example, in the case of filling mobile pressure vessels, the documents need only meet the requirements of relevant regulations; yet auditors insist that enterprises prepare them in accordance with GB/T190001 or TSGZ0004. In my opinion, this is a typical example of raising document requirements. 6. When issuing non-conformities, corrective and preventive actions should be considered. VII. Correction and Prevention of Non-conformities 1. Differences among correction, prevention, and improvement. Correction—measures taken to eliminate the problems that have actually occurred. Prevention—elimination measures taken against potential problems. Improvement—measures taken to enhance the effectiveness or efficiency of various activities or processes. 2. Proposal of measures: The focus of internal audit work is to propose and implement corrective, preventive, and improvement measures. The proposal of corrective actions is the joint responsibility of the audit team and the audited party; for all non-conformities listed in the audit report, corrective, preventive, and improvement actions must be proposed. The proposed corrective and preventive action plans should specify the reasons for the non-conformities. The measures suggested must be targeted and feasible, with a clear and reasonable allocation of tasks; they should also exhibit a high degree of systematicity and depth in order to effectively prevent the recurrence of such problems. 3. Review and confirmation of measures: The proposed measures must be reviewed and confirmed to ensure their effective implementation. 3. Implementation and evaluation of measures: The main implementation process and outcomes must meet the requirements of the proposed measures, and new situations or problems that arise during implementation can be addressed through new measures.