Page 6 - Sept NL 2016a
P. 6

A2LA Updates

Continued from page 5                        its clients and potential clients. The     the changes have been communicated
                                             client then has an opportunity to object   to clients in some manner, and to take
ISO/IEC 17065 Explanations:                  to the use of external resources, or to    some action to verify that the changes
                                             request clarification on the matter.       have been implemented by its clients.
QUESTION: Per section 4.2.3 of               If clarification is requested, the         If the scheme specifies any further
ISO/IEC 17065, is our organization           certification body is expected to answer   actions, such as mandating immediate
required to keep records of all of           the client’s question, and identify the    re-evaluation of any certified product,
the risks to impartiality we have            potential entity that would be used        then the certification body has further
investigated, even those which were          before the evaluation activity takes       tasks to undertake.
determined not to be actual risks?           place in order to allow the customer the
                                             opportunity to object to the use of that   In the case of a scheme owner sending
RESPONSE: A2LA expects certification         particular external resource, while still  out email notifications, actions taken
bodies to keep records of any risks that     accepting the possible use of a different  by the CB to assure themselves that
have been identified, as well as records     external evaluation resource.              the communication has taken place
of the actions taken to mitigate the                                                    may be minimal (but caution should
risks identified. This information is        Records of correspondence are required     still be taken in the event that a client
required to be passed to the Mechanism       to demonstrate that the CB has given       is not receiving those notifications). In
for Safeguarding Impartiality (as            adequate notice to the client and, if      other cases, such as the CB being the
required by clause 4.2.4), which is then     necessary, has identified the specific     scheme owner, a notification blast (e.g.,
required to take this into account and       subcontractor if so requested.             via email or letter) to all clients could
provide feedback to the CB during its                                                   be submitted as evidence of the steps
management review (clause 8.5.2).            The critical idea in this clause is that   the CB has taken to comply with this
                                             the CB has given the client a reasonable   requirement.
While not required, it is recommended        opportunity to object to the use of
as a positive support to the principles of   outside evaluation resources, whether      With regard to actions taken to verify
certification to keep records of all areas   that be objecting to a specific entity     implementation, these will depend
where an investigation into risks took       (such as a chosen test lab) or objecting   on the instructions included (or not
place, even when no risk is ultimately       to the entire concept of outsourcing.      included) by the scheme owner. This
identified. These records may help                                                      might include re-evaluation of certified
to assure stakeholders that the CB’s         (Note that ISO/IEC 17065 does not          products (as mentioned previously), a
operations are transparent and               explicitly require the certification body  re-review of currently certified product
impartial, and may further help the          to receive a written approval from the     documentation and evaluation results
certification body in future risk analysis   client to initiate the subcontracting,     to verify that the product continues to
exercises in the event situations            but it may be beneficial for a             comply with certification requirements,
with its personnel or organizational         certification body to attempt to obtain    an audit of client facilities, or even a
relationships change.                        this documented approval)                  simple evaluation of products at the
                                                                                        next scheduled certification renewal
QUESTION: My organization issues             QUESTION: Our organization is              point without taking immediate action.
a blanket statement on our contracts         considering operating a scheme
which states “your product may be sent       where the scheme owner notifies the        However, in the event that the scheme
to an outside laboratory for testing in      clients of changes to the certification    or scheme owner is silent on actions to
the event we are unable to perform           requirements themselves, and does not      be taken, the certification body is still
timely evaluation” – does this meet          require any re-verification of compliance  required to take some action of their
the requirements of section 6.2.2.4(f) of    until the current certification expires.   own choosing to verify implementation
ISO/IEC 17065?                               Does clause 7.10.1 of ISO/IEC 17065        of the changes by the client. This could
                                             still apply to our organization, and if    include (for example) an analysis of the
RESPONSE: Clause 6.2.2.4(f) requires         so, how?                                   changes to determine whether or not re-
the certification body to notify the client                                             evaluation is necessary, with a record
in advance of subcontracting in order        RESPONSE: Clause 7.10.1 is required        of this analysis being kept. If any action
for the client to have the opportunity to    to be implemented by all certification     is necessary, as per clause 7.10.3, it
object to that action. A2LA understands      bodies, regardless of what changes         shall be performed in accordance with
that certification bodies may not always     and subsequent action (or inaction) is     the appropriate part of section 7 of the
immediately know what outside entity         stated by the scheme.                      standard, with records kept of those
will be used to perform evaluation tasks                                                activities as required by section 7.12.
when taking on an application.               In all cases of certification changes,
                                             it remains the responsibility of the                                                 Continued on page 7
At a minimum, the certification body         accredited certification body to be aware
may issue a blanket statement (or            of these changes, to gain assurance that
make known in some other clear
manner) of possible subcontracting to

6
   1   2   3   4   5   6   7   8   9   10   11