SlideShare a Scribd company logo
1 of 40
Process based auditing
Presenter – David S Smart
What is an audit?
The 6 step approach to process auditing
Step 1 – define your products
What does your
organisation do?
What is “product?
ISO9001:2015 - defines “product” as
“the result of a process”
The four kinds of product
• Manufactured goods (oil rigs, cars, fridges,
etc)
• Processed items (chemicals, food)
• Software programmes
• Service activities (transport, taxis, solicitors,
etc)
What services (products) does a bank provide?
Manages Money
 Receives/Makes cash
transactions
Processes cheques
Provides statements
Makes Loans
 Provides Business loans
Provides Personal loans
Step 2 – define your processes by
flowcharting them
How do they make it?
What is a process?
• A Process is: a sequence of related tasks
triggered by an “event” and intended to
achieve an objective.
• It also uses resources and is subject to
influences
Generic Process Model
Milk Grass
 
Outputs Input
PROCESS MODEL EXAMPLE – Dairy Cow
Cowpats
Measure of cow’s efficiency = amount of grass
eaten/quantity & quality of milk produced
Transformation – cow masticates
grass in its stomach
What is a process group?
A bank’s “money managing” group
processes
Linking products with their associated
processes
• Take the “money managing” process and
tease it out into its individual processes
Selection of a single process
The “receiving of funds” process
Is there an easier way of doing this?
• The simple four-box approach requires a
significant amount of concentration
• What about tapping into previous work on
how processes behave?
(e.g. cause & effect diagrams)
The process affecters - 8 M’s
Process affecters – definitions 1
• Methods: The instructions provided for doing
the task
• Materials: The raw materials used within the
processes
• Mother nature: The environmental
influences that have an impact on the
processes
• Money: The money allocated to the process
for wages, equipment, machines etc.
Process affecters – definitions 2
• Machinery: The equipment used within the
processes
• Manpower: The human competences
needed to perform the task
• Measurement: The checks that are done
within the processes
• Maintenance: The policies on maintenance
along with competences of operators &
engineers
Example Subassembly checklist – 8 M’s
The 3 kinds of business processes: -
• Factory processes
• Business support
processes
• External interface
processes (Customers &
Suppliers)
Factory processes
Typical Examples: -
•Assembling
• Cleaning
• Coating
• Inspecting
• Testing
• Machining
• Fabricating
• Welding
Business support processes
“They are all the production
support functions”
Departmental examples: -
• Maintenance
• Accounting
• Information technology
• Purchasing
• Human resources
• Product Designing
• Quality Assurance
• Production planning
External interface processes
“They are the departments that
interface with customers &
suppliers”
Typical department examples: -
•Marketing
• Sales
• Customer support
• Finished product shipping
• Equipment/Raw material
purchasing
The 2 process types: -
• Continuous – factory
production line
• Transactional – sales
order process
RECAP – PROCESSED BASED
AUDITING STEP 1
RECAP – PROCESSED BASED
AUDITING STEP 2 -1
RECAP – PROCESSED BASED
AUDITING STEP 2 - 2
Step 3 – Study your processes using
turtle diagrams
Defining your
information needs
Turtle diagram - generic
Turtle diagram - example
Subassembly process – equipment checklist
Step 4 – Gathering the facts together
Collect “objective
evidence” from your
processes
Analyse your facts by sorting them
Equipment is not being routinely maintained
• Jig storage area – a number of jigs
were observed to be dismantled and
others had parts missing from them (5)
(14)
•There were 6 fluorescent tubes not
working out of 30 in production line 1
area (6)
 There were a significant number of
service requests raised this month for
equipment breakdown (20)
Portable appliance testing had not
been done in the last year on fans used
to cool operators. (5)
The operator’s thermometer used to
test the solder bath temperature was
not in the calibration scheme (1)
Step 5 – Reporting the findings
• Be precise
•Have the evidence to hand
Don’t be argumentative
Be firm but fair
Don’t let the session drift on
Step 6 – Addressing the findings through
effective corrective actions
• Investigate to find the
root cause, don’t just
treat the symptoms
•Invest in training staff in
problem solving tools
See it as an opportunity
to improve the processes
Conclusions !!!!!
• Firstly you have to understand the business
processes you are going to audit and how they
relate to the objectives of the business
• Next you have to gather the objective evidence
on how these processes are being controlled (or
otherwise)
• Lastly you must present your findings in a
manner that shows how the various strengths
and weaknesses impact on the business (i.e.
showing a balanced picture)
THANK YOU FOR YOUR TIME
EMAIL: D.SMART18@YAHOO.CO.UK

More Related Content

What's hot

ISO 9001:2015
ISO 9001:2015   ISO 9001:2015
ISO 9001:2015 aristian
 
Iqa training -manufacturing[1]
Iqa training -manufacturing[1]Iqa training -manufacturing[1]
Iqa training -manufacturing[1]Jitesh Gaurav
 
Iso Internal Auditor
Iso Internal AuditorIso Internal Auditor
Iso Internal AuditorDanyah Hejaij
 
PPT Presentation on IATF 16949 Documentation
PPT Presentation on IATF 16949 DocumentationPPT Presentation on IATF 16949 Documentation
PPT Presentation on IATF 16949 DocumentationGlobal Manager Group
 
PECB Webinar: Overview of the PECB ISO 55001 Training and Certification course
PECB Webinar: Overview of the PECB ISO 55001 Training and Certification coursePECB Webinar: Overview of the PECB ISO 55001 Training and Certification course
PECB Webinar: Overview of the PECB ISO 55001 Training and Certification coursePECB
 
IATF 16949 2016 implementation phases
IATF 16949 2016 implementation phasesIATF 16949 2016 implementation phases
IATF 16949 2016 implementation phasesAmit Mishra
 
General Employee Training Presentation ISO 9001 - rev 0.pptx
General Employee Training Presentation ISO 9001 - rev 0.pptxGeneral Employee Training Presentation ISO 9001 - rev 0.pptx
General Employee Training Presentation ISO 9001 - rev 0.pptxDannyRamos58
 
An Integrated Management System Standard
An Integrated Management System StandardAn Integrated Management System Standard
An Integrated Management System StandardRalph Reid
 
ISO 19011-2018.pptx
ISO 19011-2018.pptxISO 19011-2018.pptx
ISO 19011-2018.pptxSmppMondha
 
Quality Awareness Session.pptx
Quality Awareness Session.pptxQuality Awareness Session.pptx
Quality Awareness Session.pptxssuser7e363f
 
ISO 9001:2015 - Greendot Management Solutions
ISO 9001:2015 - Greendot Management Solutions ISO 9001:2015 - Greendot Management Solutions
ISO 9001:2015 - Greendot Management Solutions Nirav Trivedi
 
Internal Auditing Checklist.pdf
Internal Auditing Checklist.pdfInternal Auditing Checklist.pdf
Internal Auditing Checklist.pdfHerry739753
 
Process Audit and ISO
Process Audit and ISOProcess Audit and ISO
Process Audit and ISOSadafhazel
 
The role of the new ISO 9001:2015 leadership requirements in companies
The role of the new ISO 9001:2015 leadership requirements in companiesThe role of the new ISO 9001:2015 leadership requirements in companies
The role of the new ISO 9001:2015 leadership requirements in companiesPECB
 
ISO 9001-2015 Revision Training Presentation
ISO 9001-2015 Revision Training PresentationISO 9001-2015 Revision Training Presentation
ISO 9001-2015 Revision Training PresentationDQS Inc.
 

What's hot (20)

ISO 9001:2015
ISO 9001:2015   ISO 9001:2015
ISO 9001:2015
 
Iqa training -manufacturing[1]
Iqa training -manufacturing[1]Iqa training -manufacturing[1]
Iqa training -manufacturing[1]
 
KAIZEN BY RAIJUL HAQUE
KAIZEN BY RAIJUL HAQUEKAIZEN BY RAIJUL HAQUE
KAIZEN BY RAIJUL HAQUE
 
Iso Internal Auditor
Iso Internal AuditorIso Internal Auditor
Iso Internal Auditor
 
PPT Presentation on IATF 16949 Documentation
PPT Presentation on IATF 16949 DocumentationPPT Presentation on IATF 16949 Documentation
PPT Presentation on IATF 16949 Documentation
 
Introduction to ISO 9001:2015
Introduction to ISO 9001:2015Introduction to ISO 9001:2015
Introduction to ISO 9001:2015
 
PECB Webinar: Overview of the PECB ISO 55001 Training and Certification course
PECB Webinar: Overview of the PECB ISO 55001 Training and Certification coursePECB Webinar: Overview of the PECB ISO 55001 Training and Certification course
PECB Webinar: Overview of the PECB ISO 55001 Training and Certification course
 
IATF 16949 2016 implementation phases
IATF 16949 2016 implementation phasesIATF 16949 2016 implementation phases
IATF 16949 2016 implementation phases
 
General Employee Training Presentation ISO 9001 - rev 0.pptx
General Employee Training Presentation ISO 9001 - rev 0.pptxGeneral Employee Training Presentation ISO 9001 - rev 0.pptx
General Employee Training Presentation ISO 9001 - rev 0.pptx
 
Iatf 16949 training
Iatf 16949 trainingIatf 16949 training
Iatf 16949 training
 
An Integrated Management System Standard
An Integrated Management System StandardAn Integrated Management System Standard
An Integrated Management System Standard
 
Iso 9001
Iso 9001Iso 9001
Iso 9001
 
ISO 19011-2018.pptx
ISO 19011-2018.pptxISO 19011-2018.pptx
ISO 19011-2018.pptx
 
Quality Awareness Session.pptx
Quality Awareness Session.pptxQuality Awareness Session.pptx
Quality Awareness Session.pptx
 
Internal auditor 9001 day 1
Internal auditor 9001 day 1Internal auditor 9001 day 1
Internal auditor 9001 day 1
 
ISO 9001:2015 - Greendot Management Solutions
ISO 9001:2015 - Greendot Management Solutions ISO 9001:2015 - Greendot Management Solutions
ISO 9001:2015 - Greendot Management Solutions
 
Internal Auditing Checklist.pdf
Internal Auditing Checklist.pdfInternal Auditing Checklist.pdf
Internal Auditing Checklist.pdf
 
Process Audit and ISO
Process Audit and ISOProcess Audit and ISO
Process Audit and ISO
 
The role of the new ISO 9001:2015 leadership requirements in companies
The role of the new ISO 9001:2015 leadership requirements in companiesThe role of the new ISO 9001:2015 leadership requirements in companies
The role of the new ISO 9001:2015 leadership requirements in companies
 
ISO 9001-2015 Revision Training Presentation
ISO 9001-2015 Revision Training PresentationISO 9001-2015 Revision Training Presentation
ISO 9001-2015 Revision Training Presentation
 

Viewers also liked

Input process output
Input process outputInput process output
Input process outputNuch Nalinee
 
Makadco Brochure - Web Development Pakistan
Makadco Brochure - Web Development PakistanMakadco Brochure - Web Development Pakistan
Makadco Brochure - Web Development PakistanShafaat Ashraf
 
Best Practices in Medical Device Auditing
Best Practices in Medical Device AuditingBest Practices in Medical Device Auditing
Best Practices in Medical Device AuditingJoe Hage
 
ทฤษฎีระบบ
ทฤษฎีระบบทฤษฎีระบบ
ทฤษฎีระบบwiraja
 
World's No. 1 School Management Information system Software
World's No. 1 School Management Information system SoftwareWorld's No. 1 School Management Information system Software
World's No. 1 School Management Information system Softwareguest2ce6683
 
ISO 9001:2008 training
ISO 9001:2008 trainingISO 9001:2008 training
ISO 9001:2008 trainingTechnoSysCon
 
HR indicators (ตัวชี้วัดการบริหารทรัพยากรมนุษย์ในองค์กร)
HR indicators (ตัวชี้วัดการบริหารทรัพยากรมนุษย์ในองค์กร)HR indicators (ตัวชี้วัดการบริหารทรัพยากรมนุษย์ในองค์กร)
HR indicators (ตัวชี้วัดการบริหารทรัพยากรมนุษย์ในองค์กร)Suntichai Inthornon
 
Business Process Improvement by Kaizen
Business Process Improvement by KaizenBusiness Process Improvement by Kaizen
Business Process Improvement by KaizenNukool Thanuanram
 
Internal Audit Methodology
Internal Audit MethodologyInternal Audit Methodology
Internal Audit MethodologyManoj Agarwal
 
Guide to implement AS9100 Rev C
Guide to implement AS9100 Rev CGuide to implement AS9100 Rev C
Guide to implement AS9100 Rev CAshish Michael
 

Viewers also liked (13)

Iqa iso9001 dark style
Iqa iso9001 dark styleIqa iso9001 dark style
Iqa iso9001 dark style
 
Input process output
Input process outputInput process output
Input process output
 
Basic it
Basic itBasic it
Basic it
 
Makadco Brochure - Web Development Pakistan
Makadco Brochure - Web Development PakistanMakadco Brochure - Web Development Pakistan
Makadco Brochure - Web Development Pakistan
 
Best Practices in Medical Device Auditing
Best Practices in Medical Device AuditingBest Practices in Medical Device Auditing
Best Practices in Medical Device Auditing
 
Design work
Design workDesign work
Design work
 
ทฤษฎีระบบ
ทฤษฎีระบบทฤษฎีระบบ
ทฤษฎีระบบ
 
World's No. 1 School Management Information system Software
World's No. 1 School Management Information system SoftwareWorld's No. 1 School Management Information system Software
World's No. 1 School Management Information system Software
 
ISO 9001:2008 training
ISO 9001:2008 trainingISO 9001:2008 training
ISO 9001:2008 training
 
HR indicators (ตัวชี้วัดการบริหารทรัพยากรมนุษย์ในองค์กร)
HR indicators (ตัวชี้วัดการบริหารทรัพยากรมนุษย์ในองค์กร)HR indicators (ตัวชี้วัดการบริหารทรัพยากรมนุษย์ในองค์กร)
HR indicators (ตัวชี้วัดการบริหารทรัพยากรมนุษย์ในองค์กร)
 
Business Process Improvement by Kaizen
Business Process Improvement by KaizenBusiness Process Improvement by Kaizen
Business Process Improvement by Kaizen
 
Internal Audit Methodology
Internal Audit MethodologyInternal Audit Methodology
Internal Audit Methodology
 
Guide to implement AS9100 Rev C
Guide to implement AS9100 Rev CGuide to implement AS9100 Rev C
Guide to implement AS9100 Rev C
 

Similar to PECB Webinar: Process based auditing

Quality Course 1
Quality Course 1Quality Course 1
Quality Course 1Fin1
 
00 Lean Concepts Foundations 23 Pgs
00 Lean Concepts Foundations 23 Pgs00 Lean Concepts Foundations 23 Pgs
00 Lean Concepts Foundations 23 Pgsfreelean
 
Kingsleys Power Point Presentation on Operations Management.pptx
Kingsleys Power Point Presentation on Operations Management.pptxKingsleys Power Point Presentation on Operations Management.pptx
Kingsleys Power Point Presentation on Operations Management.pptxKingsley Aduma
 
Iso9001standard 181004074727
Iso9001standard 181004074727Iso9001standard 181004074727
Iso9001standard 181004074727SantiKhamtree
 
Internal qms audits
Internal qms auditsInternal qms audits
Internal qms auditscye001
 
production and operations management(POM) Complete note
production and operations management(POM) Complete note production and operations management(POM) Complete note
production and operations management(POM) Complete note kabul university
 
Lean manufacturing overview
Lean manufacturing overviewLean manufacturing overview
Lean manufacturing overviewPruek Pinyo
 
Introduction To Operations Management.pptx
Introduction To Operations Management.pptxIntroduction To Operations Management.pptx
Introduction To Operations Management.pptxRiadHasan25
 
Lean Six Sigma Overview (presentation version)
Lean Six Sigma Overview (presentation version)Lean Six Sigma Overview (presentation version)
Lean Six Sigma Overview (presentation version)Corey Campbell
 
Comprehensive Compliance for Environmental, Safety, Quality Requirements in C...
Comprehensive Compliance for Environmental, Safety, Quality Requirements in C...Comprehensive Compliance for Environmental, Safety, Quality Requirements in C...
Comprehensive Compliance for Environmental, Safety, Quality Requirements in C...Nimonik
 
Internal Audit 03-03-16
Internal Audit 03-03-16Internal Audit 03-03-16
Internal Audit 03-03-16Lisa Barnes
 
Measuring Long-Run and Nonfinancial Organizational Performance
Measuring Long-Run and Nonfinancial Organizational PerformanceMeasuring Long-Run and Nonfinancial Organizational Performance
Measuring Long-Run and Nonfinancial Organizational Performancenarman1402
 
Fundamentals of Auditing PTC
Fundamentals of Auditing PTCFundamentals of Auditing PTC
Fundamentals of Auditing PTCcarroll sams
 
Improving productivity through Lean and Total Productive Maintenance
Improving productivity through Lean and Total Productive MaintenanceImproving productivity through Lean and Total Productive Maintenance
Improving productivity through Lean and Total Productive MaintenanceTim Hopper
 
Lean Six Sigma Overview (print version)
Lean Six Sigma Overview (print version)Lean Six Sigma Overview (print version)
Lean Six Sigma Overview (print version)Corey Campbell
 
Tqm review-lecture-2010
Tqm review-lecture-2010Tqm review-lecture-2010
Tqm review-lecture-2010Rhea Dela Cruz
 

Similar to PECB Webinar: Process based auditing (20)

Quality Course 1
Quality Course 1Quality Course 1
Quality Course 1
 
00 Lean Concepts Foundations 23 Pgs
00 Lean Concepts Foundations 23 Pgs00 Lean Concepts Foundations 23 Pgs
00 Lean Concepts Foundations 23 Pgs
 
Kingsleys Power Point Presentation on Operations Management.pptx
Kingsleys Power Point Presentation on Operations Management.pptxKingsleys Power Point Presentation on Operations Management.pptx
Kingsleys Power Point Presentation on Operations Management.pptx
 
Iso 9001 standard
Iso 9001 standardIso 9001 standard
Iso 9001 standard
 
Iso9001standard 181004074727
Iso9001standard 181004074727Iso9001standard 181004074727
Iso9001standard 181004074727
 
Internal qms audits
Internal qms auditsInternal qms audits
Internal qms audits
 
production and operations management(POM) Complete note
production and operations management(POM) Complete note production and operations management(POM) Complete note
production and operations management(POM) Complete note
 
Lean manufacturing overview
Lean manufacturing overviewLean manufacturing overview
Lean manufacturing overview
 
Introduction To Operations Management.pptx
Introduction To Operations Management.pptxIntroduction To Operations Management.pptx
Introduction To Operations Management.pptx
 
Lean Six Sigma Overview (presentation version)
Lean Six Sigma Overview (presentation version)Lean Six Sigma Overview (presentation version)
Lean Six Sigma Overview (presentation version)
 
Comprehensive Compliance for Environmental, Safety, Quality Requirements in C...
Comprehensive Compliance for Environmental, Safety, Quality Requirements in C...Comprehensive Compliance for Environmental, Safety, Quality Requirements in C...
Comprehensive Compliance for Environmental, Safety, Quality Requirements in C...
 
Internal Audit 03-03-16
Internal Audit 03-03-16Internal Audit 03-03-16
Internal Audit 03-03-16
 
Measuring Long-Run and Nonfinancial Organizational Performance
Measuring Long-Run and Nonfinancial Organizational PerformanceMeasuring Long-Run and Nonfinancial Organizational Performance
Measuring Long-Run and Nonfinancial Organizational Performance
 
Fundamentals of Auditing PTC
Fundamentals of Auditing PTCFundamentals of Auditing PTC
Fundamentals of Auditing PTC
 
Improving productivity through Lean and Total Productive Maintenance
Improving productivity through Lean and Total Productive MaintenanceImproving productivity through Lean and Total Productive Maintenance
Improving productivity through Lean and Total Productive Maintenance
 
Quality Management Systems
Quality Management SystemsQuality Management Systems
Quality Management Systems
 
CPI Training overview
CPI Training overviewCPI Training overview
CPI Training overview
 
materials info
materials infomaterials info
materials info
 
Lean Six Sigma Overview (print version)
Lean Six Sigma Overview (print version)Lean Six Sigma Overview (print version)
Lean Six Sigma Overview (print version)
 
Tqm review-lecture-2010
Tqm review-lecture-2010Tqm review-lecture-2010
Tqm review-lecture-2010
 

More from PECB

DORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of Cybersecurity
DORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of CybersecurityDORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of Cybersecurity
DORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of CybersecurityPECB
 
Securing the Future: ISO/IEC 27001, ISO/IEC 42001, and AI Governance
Securing the Future: ISO/IEC 27001, ISO/IEC 42001, and AI GovernanceSecuring the Future: ISO/IEC 27001, ISO/IEC 42001, and AI Governance
Securing the Future: ISO/IEC 27001, ISO/IEC 42001, and AI GovernancePECB
 
ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...
ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...
ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...PECB
 
ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...
ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...
ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...PECB
 
ISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks Effectively
ISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks EffectivelyISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks Effectively
ISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks EffectivelyPECB
 
Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...
Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...
Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...PECB
 
ISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital Transformation
ISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital TransformationISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital Transformation
ISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital TransformationPECB
 
Managing ISO 31000 Framework in AI Systems - The EU ACT and other regulations
Managing ISO 31000 Framework in AI Systems - The EU ACT and other regulationsManaging ISO 31000 Framework in AI Systems - The EU ACT and other regulations
Managing ISO 31000 Framework in AI Systems - The EU ACT and other regulationsPECB
 
Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?
Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?
Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?PECB
 
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...PECB
 
How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...
How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...
How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...PECB
 
Student Information Session University KTMC
Student Information Session University KTMC Student Information Session University KTMC
Student Information Session University KTMC PECB
 
ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...
ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...
ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...PECB
 
Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...
Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...
Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...PECB
 
Student Information Session University CREST ADVISORY AFRICA
Student Information Session University CREST ADVISORY AFRICA Student Information Session University CREST ADVISORY AFRICA
Student Information Session University CREST ADVISORY AFRICA PECB
 
IT Governance and Information Security – How do they map?
IT Governance and Information Security – How do they map?IT Governance and Information Security – How do they map?
IT Governance and Information Security – How do they map?PECB
 
Information Session University Egybyte.pptx
Information Session University Egybyte.pptxInformation Session University Egybyte.pptx
Information Session University Egybyte.pptxPECB
 
Student Information Session University Digital Encode.pptx
Student Information Session University Digital Encode.pptxStudent Information Session University Digital Encode.pptx
Student Information Session University Digital Encode.pptxPECB
 
Cybersecurity trends - What to expect in 2023
Cybersecurity trends - What to expect in 2023Cybersecurity trends - What to expect in 2023
Cybersecurity trends - What to expect in 2023PECB
 
ISO 28000:2022 – Reduce risks and improve the security management system
ISO 28000:2022 – Reduce risks and improve the security management systemISO 28000:2022 – Reduce risks and improve the security management system
ISO 28000:2022 – Reduce risks and improve the security management systemPECB
 

More from PECB (20)

DORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of Cybersecurity
DORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of CybersecurityDORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of Cybersecurity
DORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of Cybersecurity
 
Securing the Future: ISO/IEC 27001, ISO/IEC 42001, and AI Governance
Securing the Future: ISO/IEC 27001, ISO/IEC 42001, and AI GovernanceSecuring the Future: ISO/IEC 27001, ISO/IEC 42001, and AI Governance
Securing the Future: ISO/IEC 27001, ISO/IEC 42001, and AI Governance
 
ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...
ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...
ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...
 
ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...
ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...
ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...
 
ISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks Effectively
ISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks EffectivelyISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks Effectively
ISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks Effectively
 
Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...
Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...
Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...
 
ISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital Transformation
ISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital TransformationISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital Transformation
ISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital Transformation
 
Managing ISO 31000 Framework in AI Systems - The EU ACT and other regulations
Managing ISO 31000 Framework in AI Systems - The EU ACT and other regulationsManaging ISO 31000 Framework in AI Systems - The EU ACT and other regulations
Managing ISO 31000 Framework in AI Systems - The EU ACT and other regulations
 
Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?
Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?
Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?
 
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...
 
How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...
How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...
How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...
 
Student Information Session University KTMC
Student Information Session University KTMC Student Information Session University KTMC
Student Information Session University KTMC
 
ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...
ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...
ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...
 
Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...
Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...
Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...
 
Student Information Session University CREST ADVISORY AFRICA
Student Information Session University CREST ADVISORY AFRICA Student Information Session University CREST ADVISORY AFRICA
Student Information Session University CREST ADVISORY AFRICA
 
IT Governance and Information Security – How do they map?
IT Governance and Information Security – How do they map?IT Governance and Information Security – How do they map?
IT Governance and Information Security – How do they map?
 
Information Session University Egybyte.pptx
Information Session University Egybyte.pptxInformation Session University Egybyte.pptx
Information Session University Egybyte.pptx
 
Student Information Session University Digital Encode.pptx
Student Information Session University Digital Encode.pptxStudent Information Session University Digital Encode.pptx
Student Information Session University Digital Encode.pptx
 
Cybersecurity trends - What to expect in 2023
Cybersecurity trends - What to expect in 2023Cybersecurity trends - What to expect in 2023
Cybersecurity trends - What to expect in 2023
 
ISO 28000:2022 – Reduce risks and improve the security management system
ISO 28000:2022 – Reduce risks and improve the security management systemISO 28000:2022 – Reduce risks and improve the security management system
ISO 28000:2022 – Reduce risks and improve the security management system
 

Recently uploaded

call girls in Kamla Market (DELHI) 🔝 >༒9953330565🔝 genuine Escort Service 🔝✔️✔️
call girls in Kamla Market (DELHI) 🔝 >༒9953330565🔝 genuine Escort Service 🔝✔️✔️call girls in Kamla Market (DELHI) 🔝 >༒9953330565🔝 genuine Escort Service 🔝✔️✔️
call girls in Kamla Market (DELHI) 🔝 >༒9953330565🔝 genuine Escort Service 🔝✔️✔️9953056974 Low Rate Call Girls In Saket, Delhi NCR
 
ISYU TUNGKOL SA SEKSWLADIDA (ISSUE ABOUT SEXUALITY
ISYU TUNGKOL SA SEKSWLADIDA (ISSUE ABOUT SEXUALITYISYU TUNGKOL SA SEKSWLADIDA (ISSUE ABOUT SEXUALITY
ISYU TUNGKOL SA SEKSWLADIDA (ISSUE ABOUT SEXUALITYKayeClaireEstoconing
 
Gas measurement O2,Co2,& ph) 04/2024.pptx
Gas measurement O2,Co2,& ph) 04/2024.pptxGas measurement O2,Co2,& ph) 04/2024.pptx
Gas measurement O2,Co2,& ph) 04/2024.pptxDr.Ibrahim Hassaan
 
ACC 2024 Chronicles. Cardiology. Exam.pdf
ACC 2024 Chronicles. Cardiology. Exam.pdfACC 2024 Chronicles. Cardiology. Exam.pdf
ACC 2024 Chronicles. Cardiology. Exam.pdfSpandanaRallapalli
 
ECONOMIC CONTEXT - PAPER 1 Q3: NEWSPAPERS.pptx
ECONOMIC CONTEXT - PAPER 1 Q3: NEWSPAPERS.pptxECONOMIC CONTEXT - PAPER 1 Q3: NEWSPAPERS.pptx
ECONOMIC CONTEXT - PAPER 1 Q3: NEWSPAPERS.pptxiammrhaywood
 
Karra SKD Conference Presentation Revised.pptx
Karra SKD Conference Presentation Revised.pptxKarra SKD Conference Presentation Revised.pptx
Karra SKD Conference Presentation Revised.pptxAshokKarra1
 
INTRODUCTION TO CATHOLIC CHRISTOLOGY.pptx
INTRODUCTION TO CATHOLIC CHRISTOLOGY.pptxINTRODUCTION TO CATHOLIC CHRISTOLOGY.pptx
INTRODUCTION TO CATHOLIC CHRISTOLOGY.pptxHumphrey A Beña
 
Proudly South Africa powerpoint Thorisha.pptx
Proudly South Africa powerpoint Thorisha.pptxProudly South Africa powerpoint Thorisha.pptx
Proudly South Africa powerpoint Thorisha.pptxthorishapillay1
 
ECONOMIC CONTEXT - LONG FORM TV DRAMA - PPT
ECONOMIC CONTEXT - LONG FORM TV DRAMA - PPTECONOMIC CONTEXT - LONG FORM TV DRAMA - PPT
ECONOMIC CONTEXT - LONG FORM TV DRAMA - PPTiammrhaywood
 
Procuring digital preservation CAN be quick and painless with our new dynamic...
Procuring digital preservation CAN be quick and painless with our new dynamic...Procuring digital preservation CAN be quick and painless with our new dynamic...
Procuring digital preservation CAN be quick and painless with our new dynamic...Jisc
 
What is Model Inheritance in Odoo 17 ERP
What is Model Inheritance in Odoo 17 ERPWhat is Model Inheritance in Odoo 17 ERP
What is Model Inheritance in Odoo 17 ERPCeline George
 
Science 7 Quarter 4 Module 2: Natural Resources.pptx
Science 7 Quarter 4 Module 2: Natural Resources.pptxScience 7 Quarter 4 Module 2: Natural Resources.pptx
Science 7 Quarter 4 Module 2: Natural Resources.pptxMaryGraceBautista27
 
AMERICAN LANGUAGE HUB_Level2_Student'sBook_Answerkey.pdf
AMERICAN LANGUAGE HUB_Level2_Student'sBook_Answerkey.pdfAMERICAN LANGUAGE HUB_Level2_Student'sBook_Answerkey.pdf
AMERICAN LANGUAGE HUB_Level2_Student'sBook_Answerkey.pdfphamnguyenenglishnb
 
Choosing the Right CBSE School A Comprehensive Guide for Parents
Choosing the Right CBSE School A Comprehensive Guide for ParentsChoosing the Right CBSE School A Comprehensive Guide for Parents
Choosing the Right CBSE School A Comprehensive Guide for Parentsnavabharathschool99
 
Judging the Relevance and worth of ideas part 2.pptx
Judging the Relevance  and worth of ideas part 2.pptxJudging the Relevance  and worth of ideas part 2.pptx
Judging the Relevance and worth of ideas part 2.pptxSherlyMaeNeri
 
THEORIES OF ORGANIZATION-PUBLIC ADMINISTRATION
THEORIES OF ORGANIZATION-PUBLIC ADMINISTRATIONTHEORIES OF ORGANIZATION-PUBLIC ADMINISTRATION
THEORIES OF ORGANIZATION-PUBLIC ADMINISTRATIONHumphrey A Beña
 

Recently uploaded (20)

call girls in Kamla Market (DELHI) 🔝 >༒9953330565🔝 genuine Escort Service 🔝✔️✔️
call girls in Kamla Market (DELHI) 🔝 >༒9953330565🔝 genuine Escort Service 🔝✔️✔️call girls in Kamla Market (DELHI) 🔝 >༒9953330565🔝 genuine Escort Service 🔝✔️✔️
call girls in Kamla Market (DELHI) 🔝 >༒9953330565🔝 genuine Escort Service 🔝✔️✔️
 
ISYU TUNGKOL SA SEKSWLADIDA (ISSUE ABOUT SEXUALITY
ISYU TUNGKOL SA SEKSWLADIDA (ISSUE ABOUT SEXUALITYISYU TUNGKOL SA SEKSWLADIDA (ISSUE ABOUT SEXUALITY
ISYU TUNGKOL SA SEKSWLADIDA (ISSUE ABOUT SEXUALITY
 
Gas measurement O2,Co2,& ph) 04/2024.pptx
Gas measurement O2,Co2,& ph) 04/2024.pptxGas measurement O2,Co2,& ph) 04/2024.pptx
Gas measurement O2,Co2,& ph) 04/2024.pptx
 
ACC 2024 Chronicles. Cardiology. Exam.pdf
ACC 2024 Chronicles. Cardiology. Exam.pdfACC 2024 Chronicles. Cardiology. Exam.pdf
ACC 2024 Chronicles. Cardiology. Exam.pdf
 
ECONOMIC CONTEXT - PAPER 1 Q3: NEWSPAPERS.pptx
ECONOMIC CONTEXT - PAPER 1 Q3: NEWSPAPERS.pptxECONOMIC CONTEXT - PAPER 1 Q3: NEWSPAPERS.pptx
ECONOMIC CONTEXT - PAPER 1 Q3: NEWSPAPERS.pptx
 
Raw materials used in Herbal Cosmetics.pptx
Raw materials used in Herbal Cosmetics.pptxRaw materials used in Herbal Cosmetics.pptx
Raw materials used in Herbal Cosmetics.pptx
 
FINALS_OF_LEFT_ON_C'N_EL_DORADO_2024.pptx
FINALS_OF_LEFT_ON_C'N_EL_DORADO_2024.pptxFINALS_OF_LEFT_ON_C'N_EL_DORADO_2024.pptx
FINALS_OF_LEFT_ON_C'N_EL_DORADO_2024.pptx
 
Karra SKD Conference Presentation Revised.pptx
Karra SKD Conference Presentation Revised.pptxKarra SKD Conference Presentation Revised.pptx
Karra SKD Conference Presentation Revised.pptx
 
INTRODUCTION TO CATHOLIC CHRISTOLOGY.pptx
INTRODUCTION TO CATHOLIC CHRISTOLOGY.pptxINTRODUCTION TO CATHOLIC CHRISTOLOGY.pptx
INTRODUCTION TO CATHOLIC CHRISTOLOGY.pptx
 
Model Call Girl in Tilak Nagar Delhi reach out to us at 🔝9953056974🔝
Model Call Girl in Tilak Nagar Delhi reach out to us at 🔝9953056974🔝Model Call Girl in Tilak Nagar Delhi reach out to us at 🔝9953056974🔝
Model Call Girl in Tilak Nagar Delhi reach out to us at 🔝9953056974🔝
 
Proudly South Africa powerpoint Thorisha.pptx
Proudly South Africa powerpoint Thorisha.pptxProudly South Africa powerpoint Thorisha.pptx
Proudly South Africa powerpoint Thorisha.pptx
 
ECONOMIC CONTEXT - LONG FORM TV DRAMA - PPT
ECONOMIC CONTEXT - LONG FORM TV DRAMA - PPTECONOMIC CONTEXT - LONG FORM TV DRAMA - PPT
ECONOMIC CONTEXT - LONG FORM TV DRAMA - PPT
 
Procuring digital preservation CAN be quick and painless with our new dynamic...
Procuring digital preservation CAN be quick and painless with our new dynamic...Procuring digital preservation CAN be quick and painless with our new dynamic...
Procuring digital preservation CAN be quick and painless with our new dynamic...
 
What is Model Inheritance in Odoo 17 ERP
What is Model Inheritance in Odoo 17 ERPWhat is Model Inheritance in Odoo 17 ERP
What is Model Inheritance in Odoo 17 ERP
 
Science 7 Quarter 4 Module 2: Natural Resources.pptx
Science 7 Quarter 4 Module 2: Natural Resources.pptxScience 7 Quarter 4 Module 2: Natural Resources.pptx
Science 7 Quarter 4 Module 2: Natural Resources.pptx
 
OS-operating systems- ch04 (Threads) ...
OS-operating systems- ch04 (Threads) ...OS-operating systems- ch04 (Threads) ...
OS-operating systems- ch04 (Threads) ...
 
AMERICAN LANGUAGE HUB_Level2_Student'sBook_Answerkey.pdf
AMERICAN LANGUAGE HUB_Level2_Student'sBook_Answerkey.pdfAMERICAN LANGUAGE HUB_Level2_Student'sBook_Answerkey.pdf
AMERICAN LANGUAGE HUB_Level2_Student'sBook_Answerkey.pdf
 
Choosing the Right CBSE School A Comprehensive Guide for Parents
Choosing the Right CBSE School A Comprehensive Guide for ParentsChoosing the Right CBSE School A Comprehensive Guide for Parents
Choosing the Right CBSE School A Comprehensive Guide for Parents
 
Judging the Relevance and worth of ideas part 2.pptx
Judging the Relevance  and worth of ideas part 2.pptxJudging the Relevance  and worth of ideas part 2.pptx
Judging the Relevance and worth of ideas part 2.pptx
 
THEORIES OF ORGANIZATION-PUBLIC ADMINISTRATION
THEORIES OF ORGANIZATION-PUBLIC ADMINISTRATIONTHEORIES OF ORGANIZATION-PUBLIC ADMINISTRATION
THEORIES OF ORGANIZATION-PUBLIC ADMINISTRATION
 

PECB Webinar: Process based auditing

  • 2. What is an audit?
  • 3. The 6 step approach to process auditing
  • 4. Step 1 – define your products What does your organisation do?
  • 5. What is “product? ISO9001:2015 - defines “product” as “the result of a process”
  • 6. The four kinds of product • Manufactured goods (oil rigs, cars, fridges, etc) • Processed items (chemicals, food) • Software programmes • Service activities (transport, taxis, solicitors, etc)
  • 7. What services (products) does a bank provide? Manages Money  Receives/Makes cash transactions Processes cheques Provides statements Makes Loans  Provides Business loans Provides Personal loans
  • 8. Step 2 – define your processes by flowcharting them How do they make it?
  • 9. What is a process? • A Process is: a sequence of related tasks triggered by an “event” and intended to achieve an objective. • It also uses resources and is subject to influences
  • 11. Milk Grass   Outputs Input PROCESS MODEL EXAMPLE – Dairy Cow Cowpats Measure of cow’s efficiency = amount of grass eaten/quantity & quality of milk produced Transformation – cow masticates grass in its stomach
  • 12. What is a process group?
  • 13. A bank’s “money managing” group processes
  • 14. Linking products with their associated processes • Take the “money managing” process and tease it out into its individual processes
  • 15. Selection of a single process
  • 16. The “receiving of funds” process
  • 17. Is there an easier way of doing this? • The simple four-box approach requires a significant amount of concentration • What about tapping into previous work on how processes behave? (e.g. cause & effect diagrams)
  • 19. Process affecters – definitions 1 • Methods: The instructions provided for doing the task • Materials: The raw materials used within the processes • Mother nature: The environmental influences that have an impact on the processes • Money: The money allocated to the process for wages, equipment, machines etc.
  • 20. Process affecters – definitions 2 • Machinery: The equipment used within the processes • Manpower: The human competences needed to perform the task • Measurement: The checks that are done within the processes • Maintenance: The policies on maintenance along with competences of operators & engineers
  • 22. The 3 kinds of business processes: - • Factory processes • Business support processes • External interface processes (Customers & Suppliers)
  • 23. Factory processes Typical Examples: - •Assembling • Cleaning • Coating • Inspecting • Testing • Machining • Fabricating • Welding
  • 24. Business support processes “They are all the production support functions” Departmental examples: - • Maintenance • Accounting • Information technology • Purchasing • Human resources • Product Designing • Quality Assurance • Production planning
  • 25. External interface processes “They are the departments that interface with customers & suppliers” Typical department examples: - •Marketing • Sales • Customer support • Finished product shipping • Equipment/Raw material purchasing
  • 26. The 2 process types: - • Continuous – factory production line • Transactional – sales order process
  • 27. RECAP – PROCESSED BASED AUDITING STEP 1
  • 28. RECAP – PROCESSED BASED AUDITING STEP 2 -1
  • 29. RECAP – PROCESSED BASED AUDITING STEP 2 - 2
  • 30. Step 3 – Study your processes using turtle diagrams Defining your information needs
  • 31. Turtle diagram - generic
  • 32. Turtle diagram - example
  • 33. Subassembly process – equipment checklist
  • 34. Step 4 – Gathering the facts together Collect “objective evidence” from your processes
  • 35. Analyse your facts by sorting them
  • 36. Equipment is not being routinely maintained • Jig storage area – a number of jigs were observed to be dismantled and others had parts missing from them (5) (14) •There were 6 fluorescent tubes not working out of 30 in production line 1 area (6)  There were a significant number of service requests raised this month for equipment breakdown (20) Portable appliance testing had not been done in the last year on fans used to cool operators. (5) The operator’s thermometer used to test the solder bath temperature was not in the calibration scheme (1)
  • 37. Step 5 – Reporting the findings • Be precise •Have the evidence to hand Don’t be argumentative Be firm but fair Don’t let the session drift on
  • 38. Step 6 – Addressing the findings through effective corrective actions • Investigate to find the root cause, don’t just treat the symptoms •Invest in training staff in problem solving tools See it as an opportunity to improve the processes
  • 39. Conclusions !!!!! • Firstly you have to understand the business processes you are going to audit and how they relate to the objectives of the business • Next you have to gather the objective evidence on how these processes are being controlled (or otherwise) • Lastly you must present your findings in a manner that shows how the various strengths and weaknesses impact on the business (i.e. showing a balanced picture)
  • 40. THANK YOU FOR YOUR TIME EMAIL: D.SMART18@YAHOO.CO.UK

Editor's Notes

  1. Comparison: In simple terms you are comparing the “observed practice” against the “documented procedures” . If there is a difference its called a non-conformance. Lagging Non-conformance: happens because either a the “observed practice” is lagging behind the “documented procedure”. This happens because of complacency (doing the job repeatedly,) de-motivation, or being pressured into doing the job quicker and taking short-cuts. Another way is a new manager deliberately circumventing the QMS and imposing his ideas on everybody Leading Non-conformance: happens when a better way of doing the job has been found, (the observed practice is in advance of the documented procedure). The problem is that either the person does not know how to ask for a change or is just lazy and can’t be bothered.
  2. Product example : I have taken this service example as everyone is familiar with it and has dealings with a bank . Process definition (Broad brush approach): this is the first level trawl showing the two main functions “Managing Money” & “Making Loans” , then drilling down into the sub-functions cash transactions, processing cheques, providing statements, providing both business & personal loans Organisation’s function: This is simplified to illustrate the method of determining what an organisation does. In the next slide we will take the top header “Managing Money” and see how the “money management processes” tie together as a process group
  3. Process triggers (i.e. events): An event can be an action, a thought, a decision or a diary date – so the process can be both reactive and proactive. Reactive example - responding to a sales enquiry Proactive example – recruiting new staff (by seeing the need beforehand) Process Resources & Influences: All processes consume resources and are subject to being influenced by a number of factors Resource: – People, Influencer: Policies
  4. Inputs/Outputs: - Every process has at least one input and one output Transformations: Between the inputs and outputs something is transformed into something else, value is added to the product (or should be) Controls: - We can also see that the process has controls over it. Examples of controls are checks & balances, documents – e.g. route card, work order etc, drawing dimensions. Resources: - Finally we have the associated resources. One way to look at resources is to use the 4 M’s – Men, Money, Machines & Materials. We then take them one at a time and break them down into sub-categories – Men (present competencies, induction to job, future training needs). This is followed by compiling a checklist of questions around each sub-category to ask during the audit interview
  5. I usually base this on the cow model as it is easily understood by lay people. I talk about us being in the country linking into green issues. I also say if the boy racers in the room want to think of it as an internal combustion engine then fine. I also use the opportunity to point out how inefficient the internal combustion engine is hoping they will relate it to the QMS. I start of by saying any process has an input, any process has a transformation and any process has an output
  6. Process Group: Consists of a number of single processes (operations) linked together. If the output from the previous process is not as it should be, then there will be a knock-on effect to the next process. This concept is called the “internal customer” concept where you don’t pass on your task until it is in a state that you would have like to receive it. Put yourself in the receiver’s position and define a set of criteria (contract conditions you impose on yourself) that you would be proud to be associated with, then work to them. Too often especially when people are under pressure or in an incentive scheme environment the work is just “lobbed over the shoulder” for someone else to inherit and fix.
  7. Money managing process: As I said in the previous slide we have only taken the “money managing processes” and teased them out. We could have done exactly the same for the “Loans processes” Onion principle: we peel of each layer to expose what is below it Next layer: We have drilled down and teased out the “money managing processes” showing where the sources of inputs are, the various transformations and how the funds are dispersed. The reporting side has also been covered
  8. Isolating the “receive funds” process: We have gone on to drill down to the next layer, taking the receive funds processes and defining the inputs, outputs controls and resources being utilised by it
  9. Single process development: We can see that in the money managing process the receive funds were inputs into the managing the accounts process. We have isolated the receive funds process and can see that it has inputs/outputs controls and resources in its own right.
  10. Simple 4 box approach: It is very demanding to keep your concentration going to drill down into each process and completely define it. Alternative approach: We can take the work of professor Ishikawa who developed cause and effect diagrams to solve process problems in the Japanese car industry. We will see in the next slide how the things that have an influence on the process are defined and use this as an alternative to the simple four box approach
  11. Process affecters: We can use the 8 M’s taken from cause and effect diagrams to think about the impacts each one has on the processes under audit.
  12. Methods: these are not just what is written down, but verbal instructions given by experienced hands, supervisors or process engineers or habits that have been picked up along the way especially bad ones and supposed short-cuts Materials: how material issued from stores, how it is stored on the lines , transported, controlled at every stage within the processes under audit Mother nature: any environmental factors which can impact on the process temperature, humidity, noise etc. Money: if insufficient funds are available to replace equipment or there is insufficient capacity to produce the requirements the process will suffer. Likewise if wages are below the accepted going rate moral will suffer with all sorts of associated problems
  13. Machinery: downtime, reliability, utilisation, cleanliness, tool storage are all areas that have a direct impact on the process Manpower: training, competence, utilisation, attitudes, knowledge Measurement: If you don’t measure you don’t control. Where are the checks carried out, are they in the right place, is all the criteria to measure the parts known either by knowledge (e.g. apprenticeship) or written down (critical dimensions highlighted on drawings). Sampling techniques and training in their use also come into play. This also involves equipment calibration. Maintenance: Is there a planned maintenance policy or is equipment left till it breaks down. Are operators encouraged to clean up their work station, take care of their tools. How competent are the engineers who maintain the equipment
  14. Process checklist: I have used the process of an electronic subassembly to show how a checklist could be developed taking the things that affect a process and asking questions to verify whether it is performing as it should be. This has deliberately been kept to two questions per affecter so that the diagram does not become too cluttered
  15. Differences: - you can’t see “transactional processes”, you can see and hear the production line running from the time it starts up, but if you walk into an accounts office you are likely to see a number of random people sitting at computer keyboards or working with pieces of paper. “Transactional processes” tend to be “discontinuous” The second difference is that people involved in “transactional processes” often choose to do bits of different processes (and different instances of the same process) at different times. “Transactional processes” are also selective in the way they are sometimes progressed. Sometimes “transactional processes” run alongside other instances of the same process (e.g. dealing with a number of sales enquiries) whilst other are maybe only performed once a year (preparing the annual business plan) Flowcharting & Auditing difficulties with transactional processes: It can be difficult when trying to produce a transactional process flow-line or observe a transactional process (System) from end to end during audits. One way round this during audits is to check completed work or work held in in trays and combine the various steps in the process from different periods of time with your observations on the part of the process the person is currently doing. As far as flowcharting is concerned you can interview someone familiar with the process to chart it and verify each step by observing it when the person is performing the task. You can also cross check it together.
  16. Processed based auditing recap Last week we covered the first 2 steps of the 6 step process Step 1 summary Defining your products What is a product – ISO9000 definition – “the result of a process” The 4 kinds of products Manufactured goods Processed items Software programmes Service activities
  17. Process based auditing presentation recap Step 2 summary Worked example – we used the services a bank provides – two categories Manages money Makes loans Flowcharting the processes Process definition – sequence of related tasks triggered by an event which uses resources and has influences on it Generic 4 box process model – inputs/outputs, transformations, controls ,resources Example – Dairy cow Process group – number of single processes linked into internal customer concept Flowcharting High level group of processes – i.e. Money managing processes, then drilling down using “onion principle” (i.e. peeling the layers back) – developing the “receiving of funds” process  
  18. Process based auditing presentation recap Step 2 summary continued….  Alternative approach – Cause and effect diagrams  Process affecters – 8 M’s – methods, Materials, Mother nature, Money, Machinery, Man-power, Measurement, Maintenance Worked example – simplified cause & effect diagram using the 8M’s as the headers 3 kinds of business processes – Factory, business support & external interfaces with suppliers and customers Examples: factory processes – Assembling, inspecting, machining business support processes – Maintenance, HR, production planning interface processes – Product distribution, Marketing, Purchasing Process types – continuous, transactional Differences – Can’t see a transactional process in operation because of discontinuous steps and operatives are selective in how steps are performed Auditing transactional processes – prior flowcharting interviewing departmental staff, tracing back checking completed work from different jobs, checking in-tray work combining various steps to provide you with an overall picture
  19. Turtle diagrams: We are going to use them in defining what information is required from a process so that it functions correctly. We are going to use the information from the turtle diagrams to produce checklist quests that we can use during the audit to test and verify if the processes under examination are performing as intended
  20. Electronic subassembly building: In this example an electronic subassembly process has been selected. Input: - Kit of parts Output: - Process indicator - correctly assembled subassembly Box significance: - The four yellow boxes have then had their categories expanded e.g. the materials and equipment could again be broken down into Materials (jigs) : -route card, Equipment (tools) : - magnifiers, inspection mirrors, soldering irons, work station etc. As you can see the other 3 categories have also been broken down into their subcategories. The four brown boxes break the process down even further into its component parts Process Audit Concept: - The point here is to not just look at the procedure and compare it against the observed practice, which is a procedure or system audit. The idea (concept) of process audits is to take an overall look at the whole business and see how it performs. A single process is examined at a time. Always think of the customer and what the objectives of the organisation are, then look at the processes to see if they match with the customer needs and the organisation’s objectives
  21. Equipment checklist: We have gone a stage further taking the first box from the previous slide and developed questions we can ask when we do our audit. Process checklist completion: We would then gone on and take the other 3 boxes - (1 - Competences, skills & training), (2 - Support procedures and methods) and end with questions to check (3 – the process indicators )
  22. Objective evidence: This is a term we use when we are determining the facts. The audit interview should be like an interview for a job. Your checklist is similar to the candidate’s CV where you have previously highlighted points you want to discuss with them during interview on either their experiences or job knowledge
  23. Data chunking: The term used when we are collating the facts together. As we go along during your audit we will be gathering facts. These facts build together to show a much bigger picture. By analysing and sorting the facts, you have gathered you will see patterns emerging. Trends: will then become evident, where you show there is a general breakdown, not just one process, but across many processes. It snowballs, the knock-on effects from one process present themselves in the other processes. These trends may be trends you have seen before from other audits or they may be new ones.
  24. The Bigger Picture: The above findings are arrived at by analysing and data chunking of facts and shows examples of a similar problem i.e. “lack of routine maintenance” manifesting itself in more than one area.
  25. Be precise: Make your most important point first to grab the attention Have the facts to hand: support your claims with supporting evidence either by photocopied documentation or copious notes taken during the interview Don’t be argumentative: keep your composure, remain calm and don’t be drawn into projected discussions. You are only there to present the evidence not to offer suggestions on how to sort the problem. They should know their procedures inside out and also know the requirements of the standard under audit. Be firm but fair: If you have got it wrong by the company’s representative presenting more evidence then accept it and hold your hand up and admit it. Don’t try to waffle your way out of it, your credibility will be damaged if you do. Don’t let session drift on: Say your piece and close the meeting, it’s not a debating society, as an auditor you should know if there is a NCR, so should they. If you have presented your evidence in a nonbiased way then it should be self evident. You are not there to get into a points scoring session.
  26. Root cause analysis: All too often the audit findings are given the minimum of attention to clear down. One way to help get to the bottom of the problem and stop it recurring is to use the 5 why’s technique. Q. – Why was the postman late in delivering my mail this morning Why – he had too many letters to deliver Why – because there used to be two postmen doing the round Why – The royal mail went on an economy drive because it was losing money Why – Pressure is being put on it by the government to make it profitable Why – It’s a politically sensitive issue. Training Investment: Training budgets are usually the first thing that gets cut in tough economic times. There is an attitude of I’m not going to spend money on training people they will leave and get a better job. This is false economy firstly all you have to do is make it more attractive for them to stay or build a clause into their contract to stay for say 2 years. Also a lot of training can be done in house, investing in training managers to train their staff is very cost effective. Purchasing books, videos etc are all low cost. It starts with a change in attitude of a manager’s role “controlling & directing” or “coaching & mentoring” Improvement opportunity: The idea is to save money making the processes more efficient. A costing system driven by the accounts function should be put in place to standardise and cost the savings made in the deficient process