Leave Your ISO or API Internal Audits with Us, Focus On Excellence.

Whether you are building a management system from scratch or maintaining an established one, our expert Auditors can take a load off your plate by conducting: 

ISO or API Internal Audits

Mireaux’s Auditing Services encompass the following types of audits:

Internal Audit Icon

Internal Audit

Organizations certified to an ISO or API standard, or in the process of certification, are required to conduct internal audits at periodic intervals. Internal audits can be conducted by employees internal to the organization, however, they can also be “outsourced” – to a competent organization like Mireaux.

All ISO and API standards require Internal Audits, including:

Mireaux Management Solutions can help your organization accomplish this continual improvement requirement by conducting your Internal Audits at the locations and dates required by your management system, your Internal Audit procedure, or ultimately your Internal Audit Schedule.

AUDITS CONDUCTED ON-SITE AND VIA REMOTE AUDITING

Analysis Icon

Gap Analysis

The purpose of the Gap Analysis or Gap Assessment is to find the gaps between an organization’s management system and the ISO or API criteria they are aiming to conform with or certify to.  The results of the Gap Analysis should outline, clause by clause, what requirements of the defined criteria are not being met or cannot be verified as being fulfilled; and what needs to be completed in order to meet those requirements.

A Gap Analysis is an exhaustive exercise, in which every clause of the ISO or API standard is checked for compliance. While a thorough Gap Analysis includes verification of implementation, it is highly focused on reviewing required documentation and records– usually performed from a desk or meeting room. This is why Gap Analyses are also called “Desktop Audits”.

AUDITS CONDUCTED ON-SITE AND VIA REMOTE AUDITING

Process Audit Icon

Process Audit

Process audits seek to improve selected processes by finding out how they perform against a defined criteria.One of the benefits is the intense focus on the selected process(es). This means the Auditor may spend 1, or more days on a single process, reviewing all aspects of it, from top to bottom, within the defined criteria. Such an exercise is bound to find several opportunities for improving the process in a significant way.

AUDITS CONDUCTED ON-SITE AND VIA REMOTE AUDITING

Product Audit Image

Product and Monogram Audits

Product Audits evaluate actual product, product family, parts, or product components against a certain specification(s), which is the criteria for the audit. Product Audits seek to find out if the product meets the exact requirements called out in the criteria used, or if the product performs as expected. Those requirements can be self-imposed, customer-driven, governmental, or industry requirements. Many products can also be certified to a specification, and therefore require an audit to verify compliance, such as the case of API monogrammed products.

AUDITS CONDUCTED ON-SITE AND VIA REMOTE AUDITING

Supplier Audit Icon

Supplier Audit

A Supplier/Vendor Audit seeks to verify physically or on-site at the supplier’s premises, that they are complying with certain criteria. This criteria can be dictated by your organization and may encompass the following but not limited to:

  • A specific ISO or API standard, such as ISO 9001 or API Q2
  • Your organization’s own requirements for Suppliers/Vendors
  • Product specification
  • Procurement requirements

In general, a Supplier/Vendor audit should provide certainty that the Supplier/Vendor has the capability to provide products and/or services to your organization, that meet your own Quality, Environmental, Safety, Information Security, On-Time Delivery, or other requirements as applicable.

AUDITS CONDUCTED ON-SITE AND VIA REMOTE AUDITING

Overwhelmed by Audit Findings?
Let’s explore the challenges you may face during your ISO or API Internal Audits.

We get it—ISO or API audits can be stressful and time-consuming. But imagine if you could skip the headache and focus solely on actionable insights that help you improve. That’s where we come in. 

Get Ready for Success: Our Auditors Have Your Back

Our auditors stay on top of their game by regularly conducting ISO and API Internal Audits across various industries and standards. This experience gives them the insights needed to dive deep into your processes and identify any potential nonconformities before the Registrar’s visit.

By partnering with us, you’ll not only streamline your compliance efforts but also lighten the load on your staff, allowing you to focus on what you do best.

ISO or API Gap Analysis

Our ISO and API Audit Approach

A successful ISO or API Internal Audit is the result of having competent Auditors following a structured audit approach. Our processes are certified to the ISO 9001 and ISO 27001 standards and we also adhere to the ISO 19011 Auditing Standard.

While our Audit approach may vary based on the type of audit being conducted, these are the general steps we follow for most types of ISO and API audits:

This includes a review of pertinent documentation appropriate to the type of audit to be carried out, and the standard or audit criteria being used.  Typical documents include:

This includes preparing an agenda that outlines the start and end times for each audit day as well as the allocation of time for each process/area.  If multiple Auditors are involved, this will also include the name of the Auditor and the process/area each of them will audit and when.

For optimal results, the Audit Agenda is issued 2 weeks in advance to allow sufficient time for review and distribution.

Executing the Audit means conducting the Audit as planned in the Audit Agenda, and as required by the standard or criteria used. An audit usually has the following elements:

The goal of our Auditors is to spend most of the time on the shop floor or interviewing personnel, rather than in an office filling out paperwork.

The Audit Report is perhaps the most important part of any Audit, as it is the only tangible deliverable that is generated from the auditing process. Regardless of how well the Audit was conducted, if the report is either late, poorly written, or lacking information; the organization may not fully benefit from the Audit.

Our goal is to have the report to you in 3-business days from the last day of the Audit. And if you are a Web QMS user, the report and findings will be delivered directly into your own Web QMS’ Audits app, thus leaving you with the task of assigning the findings for follow up -without the need to reentering all information.

What Standards Can We Audit Against

We have the capability to audit the following standards or specs: 

If the standard or specification you would like for us to audit is not listed, contact us and we can review. 

Frequently Asked Questions

Planning for the audit is essential in order to ensure the audit achieves the goals and objectives desired. Poor planning may turn the audit into wasted time and effort. We can assist your organization plan for the audit, by helping you determine the following:

In general, we use the following nomenclature for reporting findings:

1. Noteworthy Efforts

These are strengths and positive attributes that help an organization comply with the standard over and above what may be considered normal or what is typically seen. These type of findings do not require a response.

2. Opportunities for Improvement

Opinions made by the Auditor, about activities that can be done more effectively based on experience and best practices. Since the requirements of the standard are being met, albeit not efficiently as seen by the Auditor elsewhere, these type of findings do not require a response.

3. Observations or Concerns

Views made by the Auditor regarding areas of the process or management system which could become nonconforming should objective evidence become available or the right conditions appear. These could be treated as “near misses” and while some registrars do not require a response to them, Mireaux does encourage its Clients to document these findings and treat them as Preventive Actions in order to proactively resolve or prevent any future problems.

4. Minor Nonconformance

An isolated lapse of either discipline or control during the implementation of a management system element or procedural requirements is considered a minor nonconformity. A minor nonconformity also must not indicate a management system breakdown, and must not raise doubt that products or intended services will meet requirements. Overall the management system requirements are defined, implemented, and effective.

5. Major Nonconformance

The absence or lack of implementation of one or more required management system elements or clauses constitutes a major nonconformity.  These encompass situations which indicate that:

A Gap Analysis is an exhaustive exercise, in which every clause of the ISO or API standard is checked for compliance. While a thorough Gap Analysis includes verification of implementation by interviewing some employees, it is highly focused on reviewing required documentation and records– usually performed from a desk or meeting room. This is why Gap Analyses are also called “Desktop Audits”.

Yes, starting on April 1, 2020, we are able to conduct audits remotely. During remote audits, our Auditors review documentation or records made available electronically and conduct interviews via a Microsoft Teams.

The expectation nowadays is that a full cycle of Internal Audits be conducted “every 12 months”. This may be seen as contrasting the various definitions the standards, may have:

Therefore, even though the language may not be consistent among standards, the expectation is that you will conduct a full cycle of Internal Audits, EVERY 12 MONTHS.

Your Audit Plan, Program, or Schedule should outline when you will conduct the Internal Audits. We recommend pinpointing the month and year, rather than just the year, as this may be seen as too broad and not a good plan.

A full cycle of Internal Audits signifies that you have audited all of the processes in your management system within the 12-month period. Whether you audit one or more process per month, or all processes at once, you have to audit all of the processes that are part of your management system.

A full cycle of Internal Audits also implies that you have conducted the actual audit, issued the findings, and closed out all nonconformities appropriately.

Depending on how your Internal Audit Schedule is setup, we can help you meet this requirement. For efficiency reasons, we usually propose Internal Audits be conducted all at once, meaning your processes are audited in the same timeframe one after another.

There are a few consequences to be expected during your Registrar’s External Audit if you do not conduct your Internal Audit on time according to your Internal Audit schedule, or prior to your Registrar’s External Audit. Below are three possible outcomes based on your Internal Audit schedule’s modus operandi.

1. If you conduct one Internal Audit per year

If you only conduct one Internal Audit per year, meaning all of your processes are audited at once; missing an internal Audit should be cause for concern. More than likely, you will get a minor Nonconformity during your External Audit, which could possibly be a major nonconformity, especially if you do not even have it on the schedule.

2. If you conduct several Internal Audits per year

If you conduct several Internal Audits per year, each focusing on a few processes of your overall management system, then missing one Internal Audit may not be as serious. Nevertheless, expect a minor Nonconformity during your External Audit.

3. If this is your first Internal Audit

If you missed conducting an Internal Audit prior to your initial certification or Stage 2 Audit, then this is serious. Having an Internal Audit prior to your certification audit is a critical requirement and definitely a showstopper:

A Gap Analysis is beneficial when an organization has implemented some elements of the ISO or API standard desired. In this case, a thorough Gap Analysis will provide a clear indication of how close or how far the organization’s management system is in relationship to the ISO or API standard being sought.

However, if the organization does not have any elements of a management system in place, and has not worked much towards meeting any of the requirements of the ISO or API standard desired; then a Gap Analysis is not recommended. In fact, having a Gap Analysis in this situation, is likely to yield a huge gap –as you are lacking just about everything – which may already be evident to your team. If this is your case, save your money and put it towards resources for implementation.

A Gap Analysis may be conducted once or twice while the organization prepares for their certification audit – to get reassurance that their implementation efforts are moving them closer to meeting all requirements of the ISO or API standards being sought.

Having a Gap Analysis at the onset of the certification journey is worthwhile. It should provide clear guidance on the direction to take and provide assurance that you are (or are not) in the right track.

If time and budget allows, a second Gap Analysis could also be helpful before the External Audit or Certification Audit. At this point, the results of the Gap Analysis should provide confirmation that the organization is indeed ready for certification.  A type of audit called Pre-Assessment – often conducted by the Registrar or Certification Body themselves – can be equated to this Gap Analysis.

We can help your organization tremendously towards achieving your desired ISO or API goals, by conducting a thorough Gap Analysis that can provide a clear roadmap to certification. Having Mireaux conduct your Gap Analysis also provides a chance for your team to discuss face to face with an expert, areas that may need attention in order to close the gaps.

Additionally upon completion of the Gap Analysis, Mireaux issues a comprehensive Gap Analysis Report that contains a detailed clause-by-clause analysis of the ISO or API standards being sought, providing for each clause:

  1. Details of the Gap
  2. Recommended actions to close the Gap
  3. Evaluation compliance on a scale of 1 to 5

Mireaux’s Gap Analysis Report also provides an overall percent of compliance, to give the organization a good idea of their “grade” and the road ahead.

There are many reasons that can spark the need to conduct a Supplier/Vendor Audit. Among them are the following:

  1. Your organization requires it for Supplier/Vendor approval
  2. Your organization requires it for Supplier/Vendor re-approval
  3. The Supplier/Vendor has shown a negative trend in the number of NCRs (product or service nonconformances)
  4. The Supplier/Vendor has been issued a Corrective Action and you would like to verify implementation and effectiveness
  5. A customer complaint was received, where the root cause was attributed to a failure or breakdown in the supplier/vendor processes
  6. Your organization wants to give the Supplier/Vendor additional work and wants to verify capabilities and capacity
  7. An information security incident, environmental impact, or safety incident occurred and it is evident that an error in the supplier/vendor’s processes, contributed to the problem.

In essence, reasons for conducting a Supplier/Vendor Audit abound. If your organization practices the ISO principle of “Relationship Management” formerly known as “Mutually beneficial Supplier Relationships”, then being able to audit your Supplier/Vendor should be welcomed as an opportunity for furthering the ties between you and your supplier/vendor.

The ISO management system standards do not require Suppliers/Vendors Audits as part of the evaluation/reevaluation of supplier or vendors. API however, is more prescriptive in its requirements for Suppliers/Vendors’ initial evaluation and selection, as shown on the following API Q2 excerpt:

The requirement above is clear in that an assessment of the supplier needs to be done at their facility (the facility from where the supplier is providing their product or service); however, the assessment can be conducted by your organization, an organization you outsourced to, or a third-party. Whichever method you decide, it should be part of your supply chain program and be documented as part of your management system requirements.

Audits should never be confrontational or offensive.  If you have a management system in place that follows the ISO principle of “Relationship Management” formerly known as “Mutually beneficial Supplier Relationships”, then the relationship between you and your supplier/vendor should be one of mutual cooperation and improvement.

In general, Mireaux discourages use of surprise audits or similar scare tactics. We like to send Audit Agendas in advance and make sure that the organization is fully aware of our visit. However, if you truly believe that there are major discrepancies that need to be verified, it is up to your organization to bypass early notification and just show up.

Free Essential Guide

The Essential Steps to Jumpstart your ISO/API Certification Journey!

These are the same steps our own Consultants use to successfully guide our clients to achieve ISO/API certification