Quantity Or Quality?

Jan 21 • 5 min read
What’s more important to you: Quantity or Quality?
At some point you’ve probably been asked which is better in comparison to something…quantity or quality? At face value, an overwhelming number of people would rightfully choose quality. After all, isn’t one great thing better than 10 that aren’t very good at all?
What is ISO 9001?

ISO 9001 is defined as the international standard that specifies requirements for a quality management system (QMS). Organizations use the standard to demonstrate the ability to consistently provide products and services that meet customer and regulatory requirements. It is the most popular standard in the ISO 9000 series and the only standard in the series to which organizations can certify. ISO 9001 was first published in 1987 by the International Organization for Standardization (ISO), an international agency composed of the national standards bodies of more than 160 countries. The current version of ISO 9001 was released in September 2015.

Who should use the ISO 9001:2015 revision?

ISO 9001:2015 applies to any organization, regardless of size or industry. More than one million organizations from more than 160 countries have applied the ISO 9001 standard requirements to their quality management systems. Organizations of all types and sizes find that using the ISO 9001 standard helps them:

  • Organize processes.
  • Improve the efficiency of processes.
  • Continually improve.
ISO 9001:2008 is obsolete now and all organization should have gone through the transition.
What topics does ISO 9001:2015 cover?

ISO 9001 is based on the plan-do-check-act methodology and provides a process-oriented approach to documenting and reviewing the structure, responsibilities, and procedures required to achieve effective quality management in an organization. Specific sections of the standard contain information on many topics, such as:

  • Requirements for a quality management system, including documented information, planning and determining process interactions.
  • Responsibilities of management.
  • Management of resources, including human resources and an organization’s work environment.
  • Product realization, including the steps from design to delivery.
  • Measurement, analysis, and improvement of the QMS through activities like internal audits and corrective and preventive action. ​
Previous versions of ISO 9001

Originally published in 1987, ISO 9001 underwent revisions in 1994, 2000, and again in 2008. The latest revision was published in September 2015.

  • ISO 9001:1994 included changes to improve the control of design and development clause, as well as provide other clarifications. The 1994 series also slightly modified the role of ISO 9002 and 9003.
  • The ISO 9001:2008 revision sought to clarify issues raised during the application of ISO 9001:2000.​

Changes introduced in the 2015 ISO 9001 revision are intended to ensure that ISO 9001 continues to adapt to the changing environments in which organizations operate. Some of the key updates in ISO 9001:2015 include:

  • The introduction of new terminology.
  • Restructuring some of the information.
  • An emphasis on risk-based thinking to enhance the application of the process approach.
  • Improved applicability for services.
  • Increased leadership requirements.​
What are the benefits of ISO 9001?

ISO 9001 helps organizations ensure their customers consistently receive high quality products and services, which in turn brings many benefits, including satisfied customers, management, and employees. Because ISO 9001 specifies the requirements for an effective quality management system, organizations find that using the standard helps them:

    • Organize a quality management system (QMS).
    • Create satisfied customers, management, and employees.
    • Save costs.
ISO 9001 certification

ISO 9001 is the only standard in the ISO 9000 series to which organizations can certify. Achieving ISO 9001:2015 certification means that an organization has demonstrated the following:

  • Follows the guidelines of the ISO 9001 standard.
  • Fulfills its own requirements.
  • Meets customer requirements and statutory and regulatory requirements.
  • Maintains documentation.​

Certification to the ISO 9001 standard can enhance an organization’s credibility by showing customers that its products and services meet expectations. In some instances or in some industries, certification is required or legally mandated. The certification process includes implementing the requirements of ISO 9001:2015 and then completing a successful registrar’s audit confirming the organization meets those requirements.

Organizations should consider the following as they begin preparing for an ISO 9001 quality management system certification:

  • Registrar’s costs for ISO 9001 registration, surveillance, and recertification audits.
  • Current level of conformance with ISO 9001 requirements.
  • Amount of resources that the company will dedicate to this project for development and implementation.
  • Amount of support that will be required from a consultant and the associated costs. ​

ISO 9001 Consultation in Jordan

If you are looking for ISO 9001 consultation in Jordan, you are at the right place! AAC MENA is one of the best providers to obtain the ISO 9001 certificate for your industry in Jordan at an affordable price. AAC MENA is known for ensuring customer satisfaction and business improvement.

Conclusion

As a leader in consultation services, AAC MENA offers unrivaled experience and expertise in ISO 9001 requirements. Our presence in the Middle East and harmonized approach give you access to the largest independent network of consultants and advisory services in the region.

Risk Takers Are Winners

Jan 21 • 10 min read
“Dealing with risk is part of governance and leadership, and is fundamental to how an organization is managed at all levels.”
We analyze and manage risks every day. From crossing the street, correctly preparing food, fastening seat belts, to coordinating a journey via public transit. Each of these is an example of a risk management process happening in our heads; sometimes the result of “common sense,” sometimes these decisions are made unconsciously. When it comes to business management, a more rigorous, formalized approach is needed. One such strategy for managing risk is to utilize standards for risk management, like ISO 31000. This approach is useful in pretty much any situation, for organizations of all shapes and sizes, to manage risk in their everyday operations. Risks affecting organizations can have consequences in terms of economic performance and professional reputation, as well as environmental, safety and societal outcomes. Therefore, managing risk effectively helps organizations to perform well in an environment full of uncertainty.
What is ISO 31000:2018?

Simply put, ISO 31000 is a standard for risk management. First published in 2009, with the most current version being 2018, it describes a set of guidelines intended to streamline risk management for organizations. ISO 31000:2018 is a single standard in a larger family of risk management standards, generally referred to as ISO 31000. The risk management standards of ISO 31000 are all designed to be used broadly, across various industries, niches, and business types, to provide the best practice structure and guidance to all operations seeking to use the principles of risk management. ISO 31000, Risk management – Guidelines, provides principles, framework and a process for managing risk. It can be used by any organization regardless of its size, activity or sector. Using ISO 31000 can help organizations increase the likelihood of achieving objectives, improve the identification of opportunities and threats and effectively allocate and use resources for risk treatment. However, ISO 31000 cannot be used for certification purposes, but does provide guidance for internal or external audit programmes. Organizations using it can compare their risk management practices with an internationally recognised benchmark, providing sound principles for effective management and corporate governance.

The ISO 31000 Family
Like many ISO standards, ISO 31000 refers to an umbrella of risk management standards. So far, the ISO 31000 family consists of:
  • ISO 31000:2018 (Principles and Guidelines on Implementation).
  • ISO/IEC 31010:2009 (Risk Assessment Techniques).
  • ISO Guide 73:2009 (Risk Management Vocabulary).
Each of these supplements one another; they’re all designed to provide a clear and universally applicable set of guidelines and best practice principles for risk management.
Risk Management Simplified With ISO 31000:2018
ISO 31000 aims to simplify risk management into a set of clearly understandable and actionable guidelines, that should be straightforward to implement, regardless of the size, nature, or location of a business. Risk for ISO 31000 is defined as “the effect of uncertainty” on business objectives. This effect can be both positive or negative. ISO 31000 is an effort to acknowledge that business operations always contain a degree of uncertainty, and therefore, risk. No matter what our business goals, there’s always a chance that things might go wrong. When you break down a business goal into a process, you can look at that process in terms of each step along the way, towards the eventual outcome of that process. Risk management involves looking at the element of risk present in each of those steps, and trying to manage it.

Benefits of ISO 31000

Why use ISO 31000 ? What can it do for your business? Well, aside from streamlining the implementation of a risk management framework by doing most of the structural and conceptual heavy lifting for you, it can also help with:
  • Giving you a competitive advantage because ISO is an internationally recognized symbol for quality standards.
  • Increasing employee awareness of organizational risks by including them in the management framework and giving them responsibility for the processes they commonly use.
  • Reduce the frequency of, and ultimately eliminate risks by educating employees and stakeholders on identified risks.
  • Improve trust of stakeholders by maintaining transparency and communicating risks (and demonstrating risk responsibility and mitigation).
  • Foster forward-thinking mentalities by encouraging employees to envision all potential outcomes of a given situation.
  • Improve company culture by bringing disparate departments together to exchange fresh perspectives, and consider how they might work together more effectively.
  • Improve success rate in all business operations by focusing on the process, thinking preemptively instead of reactively, and giving employees ownership of their work responsibilities.
Principles of ISO 31000
One of the core ideas of ISO 31000 is that risk management exists to create and protect value. This idea is expanded upon by the eight principles of ISO 31000 0, which are:
  1. Risk management must be integrated into all business operations and activities.
  2. The approach must be structured and comprehensive.
  3. Processes and the risk management framework should be customized to suit the organization’s goals and context.
  4. Stakeholders must be involved with the management framework; it must be inclusive.
  5. Risk management must be dynamic and robust; preemptive thinking, anticipating, detecting, acknowledging, and responding to changes.
  6. Risk management takes into account any limitations of available information.
  7. Human and cultural factors are paramount, and should be considered at all stages and aspects of risk management.
  8. The risk management framework is continuously improved through learning and experience.
ISO 13485 is in part designed to produce a management system that facilitates compliance to the requirements of customers and global regulators. Benefits can be reaped from being both 9001 and 13485 certified because 9001 focuses on business aspects not found in 13485 that are good for all businesses. If the proper management system framework is in place it should facilitate the identification and implementation of country-specific requirements for the management system of medical device manufacturers. ISO 13485 is not specific enough to contradict country-specific requirements and should serve as a baseline management system for all.
These principles clearly describe the most important factors for an effective and efficient risk management framework, according to ISO 31000.
Framework of ISO 31000
The term “framework” is thrown around a lot, especially when talking about any kind of standard. What exactly does it mean? ISO 31000 defines a risk management framework as: “a set of components that support and sustain risk management throughout an organization.”
More specifically, ISO 31000 defines six distinct areas that make up the total “framework” for risk management:
  • Leadership and communication.
  • Integration.
  • Design.
  • Implementation.
  • Evaluation.
  • Improvement.
The eight principles of risk management outlined above are closely related to the areas defined in the ISO 31000 framework. For example, the idea of a well-integrated risk management system is both one of the principles, as well as one of the core components of the framework. How do they relate to one another? The principles are like objectives, describing what needs to be achieved, and the framework is like the information about how to achieve those objectives.
Process of ISO 31000
Let’s start with the two most important building blocks:
  • Risk assessment.
  • Risk treatment.
These two areas form the core of risk management, according to ISO 31000 . We can zoom in a little further – risk assessment breaks down into:
  • Identification.
  • Analysis.
  • Evaluation.
Risk treatment, otherwise known as risk response, is simply the action taken in response to the identification, analysis, and evaluation of risks. It’s important to note that ISO 31000 does not outline a process for risk management in and of itself; rather, it is a set of guidelines intended to help you figure out or improve your own process.

Risk Management and Continuous Improvement

Continuous improvement is another significant concept to understand for ISO 31000. Without a company culture strongly aligned with principles of continuous improvement, organizations will struggle to implement, let alone maintain successful risk management programs. This can be challenging in practice, as cultivating a risk management attitude within a company involves aligning risk initiatives with existing company values, policies, and, to put it simply, convincing everyone involved that risk management is worthwhile. However, improving risk culture is possible and, like many things, it becomes a lot easier when you have a process for it. Such a process can be separated into three stages:
  • Cultural awareness.
  • Cultural change.
  • Cultural refinement.
Revision of ISO 31000
The revision work follows a distinct objective: to make things easier and clearer. This is achieved by using a simple language to express the fundamentals of risk management in a way that is coherent and understandable to users. The standard provides guidelines on the benefits and values of effective and efficient risk management, and should help organizations better understand and deal with the uncertainties they face in the pursuit of their objectives. To avoid weighing down the standard and making it too complex, it was decided to reduce the terminology of ISO 31000 to the barebone concepts and move certain terms to ISO Guide 73, Risk management – Vocabulary, which deals specifically with risk management terminology and is intended to be read alongside ISO 31000. Strengthened by its generic quality, the standard provides the basis for renewed confidence between experts and end users, who each face specific challenges in terms of risk but need to understand and communicate with others stakeholders. As such, the clause on building a risk management framework, which contains guidance that is relevant for every possible user, has since been augmented with additional concepts or examples that are specific to countries and industries.

ISO 31000:2018 update, which replaced the prior version from ISO 31000:2009, provides:

  • Updated and simplified language and reference structures.
  • A renewed focus on the key leadership role that boards and top management must play in ensuring that risk management is fully integrated at all levels of the organization.
  • Greater attention to the cyclical and iterative nature of risk management, which underscores the notion that organizations must evaluate their risk management process in light of new information or in response to feedback about gaps that might be present in the current risk process or associated controls.
Summary

ISO 31000 can be invaluable for preparing a business for all eventualities; by understanding the worst-case scenario, a business is better equipped to make the most of the resources and opportunities currently available to them. While ISO 31000 is certainly one of many guideline documents for implementing risk management, one of its stand-out strengths is its concise format. You’d have a hard time finding a more comprehensive document that succeeds in condensing so much information into such a coherent and concise set of guidelines. Without a doubt, ISO 31000 is one of the foremost documents for those who want to waste no time in getting started with risk management, without sacrificing quality or integrity.

ISO 31000 Consultation in Jordan

If you are looking for ISO 31000 consultation in Jordan, you are at the right place! AAC MENA is one of the best providers to obtain the ISO 31000 certificate for your industry in Jordan at an affordable price. AAC MENA is known for ensuring customer satisfaction and business improvement.

Conclusion

As a leader in consultation services, AAC MENA offers unrivaled experience and expertise in ISO 31000 requirements. Our presence in the Middle East and harmonized approach give you access to the largest independent network of consultants and advisory services in the region.

Don’t Worry, You’re Safe Now

Jan 21 • 4 min read
Safety and quality are non-negotiables in the medical devices industry. Regulatory requirements are increasingly stringent throughout every step of a product’s life cycle, including service and delivery. Increasingly, organizations in the industry are expected to demonstrate their quality management processes and ensure best practice in everything they do.
What is the ISO 13485 standard?
ISO 13485 , Medical devices – Quality management systems – Requirements for regulatory purposes, is an internationally agreed standard that sets out the requirements for a quality management system specific to the medical devices industry. It has recently been revised, with the new version published in March 2016.
What is a medical device?
A medical device is a product, such as an instrument, machine, implant or in vitro reagent, that is intended for use in the diagnosis, prevention, and treatment of diseases or other medical conditions.
Who is ISO 13485 for?
ISO 13485 is designed to be used by organizations involved in the design, production, installation, and servicing of medical devices and related services. It can also be used by internal and external parties, such as certification bodies, to help them with their auditing processes.
Certification to ISO 13485
Like other ISO management system standards, certification to ISO 13485 is not a requirement of the standard, and organizations can reap many benefits from implementing the standard without undergoing the certification process. However, third-party certification can demonstrate to regulators that you have met the requirements of the standard.
Why was ISO 13485 revised?
ISO 13485 was finally revised after 13 years and has many significant changes. The three main reasons for the updates are:
  • The medical device regulatory environment has evolved since 2003.
  • Risk management and risk-based decision-making processes have become the main focus of the entire medical device industry.
  • ISO 13485:2016 no longer aligns with the current version of ISO 9001 but rather aligns with the previous revision, ISO 9001:2008.
ISO 13485:2016 is designed to respond to the latest quality management system practices, including changes in technology and regulatory requirements and expectations. The new version has a greater emphasis on risk management and risk-based decision making, as well as changes related to the increased regulatory requirements for organizations in the supply chain.
Why do you need to get ISO 13485 certified?
Whether you are looking to operate internationally or expand locally, ISO 13485 Certification can help you improve overall performance, eliminate uncertainty, and widen market opportunities. Companies with this certification communicate a commitment to quality to both customers and regulators.
  • Increase access to more markets worldwide with certification.
  • Outline how to review and improve processes across your organization.
  • Increase efficiency, cut costs and monitor supply chain performance.
  • Demonstrate that you produce safer and more effective medical devices.
  • Meet regulatory requirements and customer expectations.
ISO 13485 is in part designed to produce a management system that facilitates compliance to the requirements of customers and global regulators. Benefits can be reaped from being both 9001 and 13485 certified because 9001 focuses on business aspects not found in 13485 that are good for all businesses. If the proper management system framework is in place it should facilitate the identification and implementation of country-specific requirements for the management system of medical device manufacturers. ISO 13485 is not specific enough to contradict country-specific requirements and should serve as a baseline management system for all.
ISO 13485 Consultation in Jordan
If you are looking for ISO 13485 consultation in Jordan, you are at the right place! AAC MENA is one of the best providers to obtain the ISO 13485 certificate for your industry in Jordan at an affordable price. AAC MENA is known for ensuring customer satisfaction and business improvement.
Conclusion
As a leader in consultation services, AAC MENA offers unrivaled experience and expertise in ISO 13485 requirements. Our presence in the Middle East and harmonized approach give you access to the largest independent network of consultants and advisory services in the region.

Solve Your Problems Like A Pro!

Jan 20 • 4 min read

Root Cause Analysis / Problem-Solving training course is based on the Eight Disciplines (8D) approach to structured problem-solving. Having a disciplined methodology creates a foundation for learning, measuring problem-solving progress, and helping to manage expectations during crisis situations, large or small. This training course will spend time on root cause analysis using some common quality tools and techniques.

Learning Objectives

  • Understand the importance of performing root cause analysis.
  • Identify the root cause of a problem using the problem-solving process.
  • Understand the application of basic quality tools in the problem-solving process.
  • Compare results from a structured problem-solving approach versus past practice.
  • Streamline your problem-solving process while improving relationships with your internal and external customers.
  • Learn a standardized approach that you can apply across an entire organization for fixing problems permanently.

Team-Based Problem Solving

Addresses Complicated Problems:
  • The team approach works best when the problem as well as its associated information, is complicated and beyond what one member is reasonably capable of knowing.
Addresses Special Cause and Common Cause Problems:
  • The 8-D process was designed to work best with special cause problems. However, it can also be associated with common cause problems and improvement actions like those associated with a QOS.
Uses Cross-functional Inputs:
  • Working in a cross-functional team means that each problem solver no longer needs to know all the technical details about how things work. Necessary information is available from a variety of team members.
Promotes Standardization:
  • A team approach to problem-solving leads to a common language. This promotes effectiveness, consistency, time savings, and change control.
Designed for Problems with Unknown Root Causes:
  • The problem-solving process is used to identify the root causes of problems and provide corrective action.

The 8-D Problem Solving Process

The Eight Disciplines (8-D) comprise a method of resolving a problem when the cause of the problem is unknown.

Encompasses the Entire Process:
  • As a Problem-Solving Process, it is a sequence of events that should be followed from the moment a problem or improvement opportunity is evident.
Facilitates Timely Solutions
  • When correctly followed, it helps to facilitate a timely resolution to the problem.
Provides a Reporting Format
  • 1. The 8-D Report is a living document.
  • 2. Progress to date.
  • 3. An action plan for completion.
  • 4. The 8-D Report is used to communicate progress on resolving a problem. It may serve as a reference for future efforts.
Establishes a Standard Practice
  • 1. An emphasis on facts, where problem-solving, decision making, planning are driven and monitored by hard factual data.
  • 2. A commitment to solving the origin of the problem, not just masking the effects of the problem.
  • 3. An enforced discipline.​

Team Problem Solving Objectives

Form the Team:
  • ​Establish a small group of people with the process/product knowledge, allocated time, authority, and skill in the required technical disciplines to solve the problem and implement corrective actions. The group must have a designated champion.
Describe the Problem:
  • ​Specify the internal/external customer problem by identifying in quantifiable terms the who, what, when, where, why, how, how many(5W2H) for the problem.
Implement and Verify Interim (Containment) Actions:
  • ​Define and implement containment actions to isolate the effect of a problem from any internal/external customer until corrective action is implemented. Verify the effectiveness of the containment action.
Find and Verify Root Causes:
  • ​Identify all potential causes which would explain why the problem occurred. Isolate and verify the root cause by testing each potential cause against the problem description and test data. Identify alternative corrective actions to eliminate the root cause.
Select Permanent Corrective Actions:
  • ​Though test programs quantitatively confirm that the selected corrective actions will resolve the problem for the customer, and will not cause undesirable side effects. Define contingency actions, if necessary, based on risk assessment.
Implement Permanent Corrective Actions:
  • ​Define and implement the best permanent corrective actions. Choose on-going controls to ensure that the root cause is eliminated. Once in effect, monitor the long term impact and implement contingency actions, if necessary.
Prevent System Problems:
  • ​Modify the management systems, operating systems, practices, and procedures to prevent recurrence of these and any other similar problems.
Congratulate the Team:
  • ​​Recognize the collective efforts of the team and learn from what they did.

Why Every Business Should Consider ISO 27701 Compliance For Their Vendors

Jan 20 • 4 min read
Maintaining privacy and protecting personal information of the customers and the employees is important for all organizations. Privacy management should go beyond mere regulatory requirements since it not only impacts an organization’s reputation but can lead to financial losses due to loss of revenue and litigation.
What is ISO 27701?
ISO/IEC 27701:2019 is a data privacy extension to ISO 27001. This newly published information security standard provides guidance for organizations looking to put in place systems to support compliance with GDPR and other data privacy requirements. ISO 27701 , also abbreviated as PIMS (Privacy Information Management System) outlines a framework for Personally Identifiable Information (PII) Controllers and PII Processors to manage data privacy. Privacy information management systems are sometimes referred to as personal information management systems.
Who should use ISO/IEC 27701?
ISO/IEC 27701 is applicable to all types and sizes of organizations, including public and private companies, government entities and not-for-profit organizations. It provides guidance for organizations who are responsible for PII processing within an information security management system (ISMS), specifically PII controllers (including those who are joint PII controllers) and PII processors. ISO 27701 has been designed to be used by all data controllers and data processors. Like ISO 27001 , it advocates a risk-based approach so that each conforming organization addresses the specific risks it faces, as well as the risks to personal data and privacy.
Benefits of ISO/IEC 27701
  • Builds trust in managing personal information.
  • Provides transparency between stakeholders.
  • Facilitates effective business agreements.
  • Clarifies roles and responsibilities.
  • Supports compliance with privacy regulations.
  • Reduces complexity by integrating with the leading information security standard ISO/IEC 27001.
Why was ISO 27701 developed?
Both the EU GDPR (General Data Protection Regulation) and UK DPA (Data Protection Act) 2018 require organizations to take measures to ensure the privacy of any personal data that they process. However, neither regulation provides much guidance on what those measures should look like. The ISO (the International Organization for Standardization) and the IEC (International Electrotechnical Commission) have therefore developed this new standard to provide that guidance.
​How do ISO 27001 and ISO 27701 integrate with each other?
ISO 27001 sets out the requirements for an ISMS (information security management system), a risk-based approach that encompasses people, processes and technology. Independently accredited certification to ISO 27001 provides stakeholders with assurance that data is being appropriately secured. Organizations that have implemented ISO 27001 will be able to use 27701 to extend their security efforts to cover privacy management – including their processing of personal data/PII (personally identifiable information) – which can help them demonstrate that reasonable measures have been taken to comply with data protection laws such as the GDPR. Organizations without an ISMS can implement ISO 27001 and ISO 27701 together as a single implementation project.
Is ISO 27701 certification right for me?
This standard is essential for organizations worldwide that are responsible for Personally Identifiable Information (PII). It provides a framework on how to manage and process data and safeguard privacy. ISO 22701 enhances an already implemented information security management system to address privacy requirements and put in place the systems and infrastructure to support compliance to legislation including GDPR .
How to get certified to ISO 27701
If you already have accredited certification to ISO 27001 you will find applying the information risk management principals to personal information fairly straightforward. The standards require that organizations with certification to ISO 27001 must include privacy management, this means reviewing the organization’s contextual analysis, risk assessment, and control environment to ensure that privacy management is incorporated. The privacy information management system then needs to be documented. Organizations that are less confident in their GDPR compliance will find ISO 27001 particularly helpful as it provides specific recommendations for actions to comply with the regulation. We can assess your compliance with ISO 27001 as an addition to your ISO 27001 assessment. We will ensure our approach follows the same method as the standard – looking at one system supporting information security and personal information management.
ISO 27701 Consultation in Jordan
If you are looking for ISO 27701 consultation in Jordan, you are at the right place! AAC MENA is one of the best providers to obtain the ISO 27701 certificate for your industry in Jordan at an affordable price. AAC MENA is known for ensuring customer satisfaction and business improvement.
Conclusion
As a leader in consultation services, AAC MENA offers unrivaled experience and expertise in ISO 27701 requirements. Our presence in the Middle East and harmonized approach give you access to the largest independent network of consultants and advisory services in the region.

What Should Business Continuity Professionals Do In Response To The Coronavirus?

Jan 20 • 11 min read
As governments try to grapple the spread of the virus, the question that applies to organizations of all sizes is, how can they effectively respond to such a situation? We are dealing with a threat to business operations or disruption of business. Since 2012 the ISO 22313 Business Continuity Management System standard, now in its revised version of 2019, describes requirements for implementing a management system to reduce the impact of disruptive events. This sleek requirements document is accompanied by a rich guidance document ISO 22313 , which offers practical information on how to prepare for, respond to and recover from disruptions. The COVID-19 developments are unfolding at an accelerated pace and organizations may have a lot of gaps to cover in their Business Continuity Plan(s). Factors such as operational agility and employee morale are just some of the main points at play. Organizations of all sizes have a very significant role to play during a virus outbreak, especially when it comes to implementing good practices and communicating hygiene protocol advice, personal protective equipment, as well as behavioral changes (i.e., properly washing hands, social distancing and avoiding handshaking in meetings). Within organizations, the team responsible for the business continuity plan can use a variety of proactive strategies in order to try and take control of the virus outbreak within their organization.
As business continuity professionals, there are four main things that you can do to prepare your organization for the potential impacts caused as a result of the coronavirus:
  • Talk to your organization’s leadership about the situation.
  • Assess your dependence on China.
  • Review and update plan documentation.
  • Socialize precautionary and business continuity-related strategies and procedures.​

Talk to your organization’s leadership

It can be hard to have a conversation related to business practices when an incident threatens to affect the health and wellbeing of so many people. Common hesitations include coming off as crass and focusing on an issue that is not currently present. However, if your organization uses Chinese-based employees or suppliers or is dependent on global supply chains and the movement of people, it is critical to have this conversation.

Asses your dependence on China

It is important to work with your organization to determine areas with the highest risk of interruption due to the coronavirus. Major considerations include the risk of your suppliers (and their suppliers), personnel, customers, and supply chain systems being impacted. For each of these areas you should:
  • Identify Current and Future Impacts
    • Consider how the previously mentioned stakeholders and systems are being impacted and where likely disruptions may occur in the future.
    • These disruptions may be a direct result of the disease or as a result of government-imposed policies and regulations.
    • Of note, the World Health Organization is tracking high-risk and affected areas.
  • Communicate Impacts
    • After the current and potential threat of the disease is determined, the organization should draft communications regarding the impacts.
    • These communications should be streamlined and approved by Human Resources and Legal.
    • Messaging may contain information on how the organization has been impacted and what it is doing to respond effectively.
    • The designated team or individual identified with leadership should continue to track the spread and impacts of the coronavirus until the threat of the disease is mitigated.
Contingency planning and disaster recovery were largely information technology-led responses to natural disasters and terrorism that affected businesses during the 1980s and early 1990s.
There was a growing recognition, however, that this needed to become a business-led process and encompass preparing for many forms of disruption. In light of this, the discipline became known as business continuity management (BCM). As governments and regulators began to recognize the role of business continuity in mitigating the effects of disruptive incidents on society, they increasingly sought to gain assurance that key players had appropriate business continuity arrangements in place. Similarly, businesses recognized their dependence on each other and sought assurance that key suppliers and partners would continue to provide key products and services, even when incidents occurred.
ISO 22301 Explained
ISO 22301 is the second published management systems standard that has adopted the new high-level structure and standardized text agreed in ISO. This will ensure consistency with all future and revised management system standards and make integrated use easier with, for example, ISO 9001 (quality), ISO 14001 (environmental) and ISO/IEC 27001 (information security). The standard is divided into 10 main clauses, starting with scope, normative references, and terms and definitions. Following these are the standard’s requirements:
Clause 4 – Context of the Organization:
  • Emphasize appropriate leadership for Business Continuity Management (BCM).
  • Ensure top management provides adequate resources.
  • Establish policy and appoint individuals to implement and maintain the BCMS.
Clause 5 – Leadership:
  • ISO 22301 places particular emphasis on the need for appropriate leadership of BCM. This is so that top management ensures appropriate resources are provided, establishes policy and appoints people to implement and maintain the BCMS.
Clause 6 – Planning:
  • This requires the organization to identify risks to the implementation of the management system and set clear objectives and criteria that can be used to measure its success.
Clause 7 – Support:
  • Since resources are required for implementation, Clause 7 introduces the important concept of competence. For business continuity to be successful, people with appropriate knowledge, skills and experience must be in place to both contribute to the BCMS and respond to incidents when they occur. It is also important that all staff are aware of their own role in responding to incidents and this clause deals with all of these areas. The need for communication about the BCMS – for instance in telling customers that the organization has appropriate BCM in place – and preparedness to communicate following an incident (when normal channels may be disrupted) is also covered here.
Clause 8 – Operations:
  • This section contains the main body of business continuity-specific expertise. The organization must undertake business impact analysis to understand how its business is affected by disruption and how this changes over time. Risk assessment seeks to understand the risks to the business in a structured way and these inform the development of business continuity strategy. Steps to avoid or reduce the likelihood of incidents are developed alongside steps to be taken when incidents occur. As it is impossible to completely predict and prevent all incidents, the approach of balancing risk reduction and planning for all eventualities is complementary. It might be said, “hope for the best and plan for the worst.”
ISO 22301 emphasizes the need for a well-defined incident response structure. This ensures that when incidents occur, responses are escalated in a timely manner and people are empowered to take the necessary actions to be effective. Life safety is emphasized and a particular point is made that the organization must communicate with external parties who may be affected, for instance, if an incident poses a noxious or explosive risk to surrounding public areas.
Exercises and tests are fundamental in ISO 22301: it is only through structured exercises – which should stretch the individuals and teams involved – that an organization can achieve objective assurance that its arrangements will work as anticipated and when required.
Clause 9 – Evaluation:
  • For any management system, it is essential to evaluate performance against plan. ISO 22301, therefore, requires that the organization select and measure itself against appropriate performance metrics. Internal audits must be conducted and there is a requirement that management reviews the BCMS and act on these reviews.
Clause 10 – Improvement:
  • No management system is perfect at the outset, and organizations and their environments are constantly changing. Clause 10 defines actions to take to improve the BCMS over time and ensure that corrective actions arising from audits, reviews, exercises and so on are addressed.​
SUCCESSFUL IMPLEMENTATION?
To work well, ISO 22301 will need organizations to have thoroughly understood its requirements. Every line and word has meaning and the relative importance is not necessarily reflected by the number of words devoted to a topic. Rather than being simply about a project or developing “a plan”, BCM is an ongoing management process requiring competent people working with appropriate support and structures that will perform when needed.
Business continuity management standard ISO 22301 revision
The ability of an organization to continue operating during a disruption has never been more important. So it’s no surprise that ISO 22301 , the internationally recognized standard for a business continuity management system (BCMS) , is being updated to make sure it remains relevant to today’s business environment.
As the first ISO standard based on the High-Level Structure (HLS), it has a strong foundation that now aligns with many other internationally recognized management system standards such as ISO 9001 quality management and ISO/IEC 27001 information security management. However, there are areas of improvement highlighted by users, particularly around less prescriptive procedures and updated terms and definitions, that need considering to ensure it remains relevant in a changing business landscape.
Key changes to ISO/FDIS 22301
  • Content in clause 8 has been reordered, duplication removed, and terminology is simplified and more consistent.
  • References to risk appetite have been removed.
  • Introductory guidance information has been removed and placed in ISO 22313, the BCMS guidance document.
  • More specific focus on planning for changes to the BCMS.
  • Less prescriptive procedures and documentation requirements.
  • Business continuity strategy is more clearly expressed as “Business continuity strategy and solutions.”
  • Business continuity plans now clearly link to supporting the teams and people that will respond to a disruption.
So, why should you care about 22301?
Because of the additional benefits to your organization can be significant, including:
  1. Increased sales and business: Today, more and more business partners (customers, suppliers, subcontractors, etc.) are demanding proof that their partners are prepared for unforeseen events. In many cases, this requirement is written into RFPs and service contracts. Proof of a robust business continuity program can mean the difference between winning a bid and closing a deal, or not. I can speak from personal experience, having headed the business continuity program for a Fortune 100 international supplier, that our program continued to come under closer and closer scrutiny, and demonstrating its capability was a stipulated requirement to obtain many large business contracts.
  2. Time and Cost Savings: I can also speak from personal experience that the time, costs, and resources necessary to demonstrate to business partners that all of their business continuity requirements of our company were met became increasingly burdensome. Some wanted to see IT recovery capabilities. Some wanted to evaluate the emergency response and crisis management. Some wanted to look at logistics redundancies. Each of these individual requests took time and resources to address. Being able to point to a single standard became a hugely efficient mechanism to address all of these obligations.
  3. Enhanced Reputation: If you are reading this Newsletter, you probably already know the value of adhering to ISO standards in general. It immediately designates an organization as willing to do what is necessary to ensure superior quality and achievement against the highest measurements. In business continuity, adherence to a standard also shows a commitment to protect its employees, shareholders, and other stakeholders from unforeseen catastrophic events.
  4. Integration within the Business: If an organization has already become certified to other ISO standards, then they are familiar with and, presumably adept, at executing management systems. So, it is not as difficult as starting from scratch to implement an additional management system such as business continuity. Integrating business continuity into existing business systems gives the organization a simpler, more unified operation, such that various management systems work in harmony.
  5. Management Involvement: One of the “knocks” on business continuity programs is that they simply pay lip service to “checking the boxes,” and don’t really get to the heart of what is necessary to protect the organization and prepare to respond to catastrophic events. An indicator of such failure is when top management is not involved in setting strategies and following up on implementation. ISO management systems simply do not allow this to happen. Lack of management involvement is immediately flagged as a possible major non-conformity. So standards, particularly the ISO standards, have fail-safe mechanisms for ensuring management involvement.
ISO 22301 Consultation in Jordan
If you are looking for ISO 22301 consultation in Jordan, you are at the right place! AAC MENA is one of the best providers to obtain the ISO 22301 certificate for your industry in Jordan at an affordable price. AAC MENA is known for ensuring customer satisfaction and business improvement.
Conclusion
As a leader in consultation services, AAC MENA offers unrivaled experience and expertise in ISO 22301 requirements. Our presence in the Middle East and harmonized approach give you access to the largest independent network of consultants and advisory services in the region.

How Important Is Educational Management And Organization?

Jan 20 • 5 min read
Educational management refers to the administration of the education system in which a group combines human and material resources to supervise, plan, strategize, and implement structures to execute an education system.
ISO 21001:2018 specifies requirements for a management system for educational organizations (EOMS) when such an organization:
  • Needs to demonstrate its ability to support the acquisition and development of competence through teaching, learning, or research.
  • Aims to enhance the satisfaction of learners, other beneficiaries, and staff through the effective application of its EOMS, including processes for improvement of the system and assurance of conformity to the requirements of learners and other beneficiaries.
What is ISO 21001?
ISO 21001 provides a common management tool for organizations providing educational products and services capable of meeting the needs and requirements of learners and other customers. It is a stand-alone management system standard, aligned with other ISO management system standards (such as ISO 9001, ISO 14001, etc.) through the application of the high-level structure.
To whom does this standard apply?
All requirements of ISO 21001 are generic and intended to be applicable to educational organizations that provide, share and facilitate the construction of knowledge through teaching, training or research, regardless of type, size and the product and service provided. The standard, therefore, applies to the management system of any organization utilizing a curriculum to provide, share and transfer knowledge.
Why is ISO 21001 important?
There is a critical and continuous need for educational organizations to evaluate the degree to which they meet the requirements of learners and other customers, in order to improve their ability to continue to do so. ISO 21001 focuses on the specific interaction between an educational organization, the learner and other customers. Current educational processes are becoming increasingly focused on co-creation where the traditional customer-supplier relationship is refined into a collaborative partnership. This standard will give guidance on how to deliver quality in this challenging new environment. Education differs from many other sectors in that a successful educational process maximizes the chance that a learner will succeed, though it cannot guarantee that outcome. The effort and capability of both the learner and educational organization are crucial variables for the educational process to be successful. Learning involves the internalization of knowledge, methods, and skills. The educational organization stimulates this internalization and provides the framework, input, processes and learning resources for it to take place. However, it is the effort and capability of the learner that ultimately determines the success of the educational process.
Who can benefit from ISO 21001?
Although learners and educational organizations worldwide are the main beneficiaries of this new management system standard, all stakeholders (i.e. everyone) will benefit from the output of standardized management systems in educational organizations. Educational organizations that will benefit from the standard include pre-school, primary, elementary, middle schools and high schools, colleges, universities, adult education, special education schools, vocational education and training, tutoring or coaching centers, training organizations, education/training departments, consultants, and non-formal educational service providers. This is true regardless of the funding source, which can be public (subsidized), private (commercial), self-sufficient (internally generated revenue) or not for profit (sponsored).
What benefits can ISO 21001 provide?
The potential benefits to an organization of implementing an EOMS based on this International Standard are :
  • Better alignment of objectives and activities with policy.
  • Enhanced social responsibility by providing inclusive and equitable quality education for all.
  • More personalized learning and effective response to all learners, particularly those with special education needs and distance learners.
  • Consistent processes and evaluation tools to demonstrate and increase effectiveness and efficiency.
  • Increased credibility of the educational organization.
  • Ability to demonstrate a commitment to effective quality management practices.
  • Development of a culture for organizational improvement.
  • Harmonization of regional, national, open, and proprietary standards within an international framework.
  • Widened participation of interested parties.
  • Stimulation of excellence and innovation.
ISO 21001 principles
Implementing an EOMS draws on the following principles:
  • Focus on learners and other beneficiaries
  • Visionary leadership
  • Engagement of people
  • Process approach
  • Continual improvement
  • Evidence-based decisions
  • Relationship management
  • Social responsibility
  • Accessibility and equity
  • Ethical conduct
  • Data security and protection
ISO 21001 Consultation in Jordan
If you are looking for ISO 21001 consultation in Jordan, you are at the right place! AAC MENA is one of the best providers to obtain the ISO 21001 certificate for your industry in Jordan at an affordable price. AAC MENA is known for ensuring customer satisfaction and business improvement.

Conclusion

As a leader in consultation services, AAC MENA offers unrivaled experience and expertise in ISO 21001 requirements. Our presence in the Middle East and harmonized approach give you access to the largest independent network of consultants and advisory services in the region.

Working From Home Goes Viral In The Time Of Coronavirus

Dec 08 • 5 min read

Google, Microsoft, Twitter, Apple and Amazon from the UK to the US, Japan to South Korea, these are all global companies that have, in the last few days, rolled out mandatory work-from-home policies amid the spread of Covid-19.

It’s realistic to assume that shifting to the ‘home office’ will become the new normal for many of us for a while, given the announcement by the World Health Organization that the coronavirus has officially reached ‘pandemic’ status. ​The coronavirus outbreak has triggered an anxious trial run for remote work on a grand scale. What we learn in the next few months could help shape a future of work that might have been inevitable, with or without a once-in-a-century public-health crisis.

Google, Microsoft, Twitter, Apple and Amazon from the UK to the US, Japan to South Korea, these are all global companies that have, in the last few days, rolled out mandatory work-from-home policies amid the spread of Covid-19.

It’s realistic to assume that shifting to the ‘home office’ will become the new normal for many of us for a while, given the announcement by the World Health Organization that the coronavirus has officially reached ‘pandemic’ status. ​The coronavirus outbreak has triggered an anxious trial run for remote work on a grand scale. What we learn in the next few months could help shape a future of work that might have been inevitable, with or without a once-in-a-century public-health crisis.

In the midst of the new coronavirus pandemic, many companies are implementing voluntary or mandatory work-from-home policies. That means lots of us are dealing with an unusual challenge: working from home for the first time, full-time. Even if you’ve done it before, working from home because of coronavirus might feel like a whole new world: It’s probably sudden. It might be for an extended period of time rather than a day here and there (and you’re not at all sure how long it’ll last). Your whole company is involved. And you can’t necessarily socialize in person outside of work. These tips will help you make sure that you’re successful, both at getting your work done and at maintaining your mental well-being:

  • Designate a workspace or home office: One of the big challenges when it comes to working remotely is keeping your work and home lives separate. If you never fully disconnect from work, your work productivity will suffer and your home life can take a hit as well.
  • Keep clearly defined working hours: Just as you designate and separate your physical workspace, you should be clear about when you’re working and when you’re not. You’ll get your best work done and be most ready to transition back to the office if you stick with your regular hours. Plus, if your role is collaborative, being on the same schedule as your coworkers makes everything much easier.
  • Build transitions into (and out of) work: Your morning commute not only gets you to work—from one physical location to another—but it also gives your brain time to prepare for work. Just because you’re not traveling doesn’t mean you shouldn’t carve out equivalent routines to help you ease into your workday.
  • Don’t get too overwhelmed by the news: Distraction is one of the big challenges facing people who work from home—especially people who aren’t used to it. “Your home is right in front of you,” Berger says. That means that whatever you’re usually thinking about getting home to after work is now with you. It’s human to get distracted. But you need to be wary of how much you let yourself get distracted.
  • Communicate, communicate, communicate: If you don’t usually work from home, chances are there will be some bumps in the road if you have to suddenly go fully remote. The key to steering through these bumps is communication—especially with your manager and direct reports. Either before you make the switch or as soon as you know it’s happening, come up with a plan that lays out expectations for how often you should check in and how you’ll convey any changes or new assignments to one another.
  • Don’t forget to socialize: When the whole office suddenly starts working from home, you’re cutting off a lot of the casual social interactions you’re used to having throughout the day that help you feel less lonely and break up the monotony of work.

Some of the biggest challenges for employers include workers struggling with loneliness, managing their time, and communication among staff members. What’s more, as schools and colleges shut down across the world, working parents must juggle company and family priorities. Here are four simple tips for implementing an effective work-from-home set-up with your kids:

  1. Create a schedule.
  2. Set boundaries with your children.
  3. Take breaks.
  4. Alternate shifts with your partner.