You are on page 1of 3

ANNEX SL ANNEX SL

A
HARMONISED
APPROACH TO
MANAGEMENT
SYSTEM
STANDARDS

The International Standards Organization (ISO) has recently undertaken


a limited revision of Annex SL, which forms the basis for nearly all its
management system standards. The latest version, published in May 2021
as part of the ISO Supplement to Part 1 of the ISO/IEC Directives, applies
to all new ISO Management System Standards as well as the revision
of existing ones. Nigel Croft, CQP FCQI, Chair of the ISO Joint Technical
Coordination Group (JTCG) for Management System Standards, and Dick
Hortensius, Senior Standardization Consultant Management Systems,
from the Netherlands Standardization Institute and Secretary of the JTCG,
share details of the revisions

Republished with permission from the CQI & IRCA (quality.org). This article first appeared in the Summer 2021 edition of the CQI’s Quality World
magazine.
46 | QUALITY WORLD | SUMMER 2021 QUALITY.ORG | 47
ANNEX SL ANNEX SL

immediate impact on users. However,


the “Guidance for MSS writers”
NEW SITUATION: FULLY ALIGNED STANDARDS
in Annex SL Appendix 2 has been
significantly improved, which should ISO 14001:2015 ISO 45001:2018
result in enhanced alignment and ENVIRONMENT OCCUPATIONAL HEALTH
AND SAFETY
harmonisation of “discipline-specific”
requirements as the changes filter
down into the various MSS over time.
ISO 9001:2015 ISO 55001:2015
The revised Annex SL has now been QUALITY ASSETS
incorporated into the latest version of

T
the Directives, published on 1 May 2021,
and will apply to the development of
all new MSS (such as the new ISO 42001
he ISO Supplement • Appendix 3 contains guidance on for Artificial Intelligence, which is still
to the ISO/IEC the use of terminology. in its early stages) and any revision of
Directives defines existing standards, such as ISO 9001
ISO 22301: 2014
the requirements The ISO’s Joint Technical Coordination (Quality), ISO 14001 (Environment), BUSINESS
ISO 22000:2018
that have to Group (JTCG) was established in 2007 ISO 45001 (Occupational Health and FOOD SAFETY CONTINUITY
A
be followed by and comprises representatives from all Safety) and others. However, it should NN L
EX S
ISO Technical of the ISO technical committees with be emphasised that this will occur
Committees for one or more MSS. over time, and the standards are not
all ISO standards required to be revised simply as a result
(more than 20,000 Review of Annex SL of the revision to Annex SL.
of them). “Annex
SL” of the Directives is an all-embracing
All ISO standards are periodically
subjected to a systematic review The main changes
$ ISO 37001:2016
ISO/IEC 27001:2017 ANTI-BRIBERY
term used to describe the criteria that for their relevance and topicality. Scope – link with intended results
INFORMATION
have to be met in order to ensure a Although Annex SL is not a “standard” The scope of all MSS (Clause 1) must SECURITY
consistent and a harmonised approach as such, this review was carried out in indicate the intended results of the

© Nigel H Croft 2021


to writing the 40-plus MSS that are 2018 by consultation with the various management system that is specified ISO 19600:2015
now within the ISO portfolio. ISO Committees (and their constituent in the standard. For example, ISO ISO 50001:2018 COMPLIANCE
Annex SL will apply to the
First published in 2012, and now members) with a MSS in their portfolio, 14001:2015 states that it is about development of all new standards
ENERGY
applied by the vast majority of ISO and National Standards Bodies improving environmental performance, and revision of existing ones.
MSS, Annex SL comprises several (including feedback from users of the meeting compliance obligations and
components, which in the latest standards). That assessment showed achieving environmental objectives.
edition are: that the overall acceptance of Annex ISO 9001:2015 is clear that the
SL among standards developers and intended results are to consistently into each MSS, supplemented, if
• The “body” of Annex SL, which users had been good, and that there desired, with the specific terms and
describes among other things the
“harmonized approach” to the
was no need for a major overhaul.
However, there were enough points for
“THE REVISED ANNEX definitions applicable to that standard.
This is a change for ISO 9001,
development of MSS, including the improvement that justified an update. SL HAS NOW BEEN overall effectiveness of a management for example, which so far has not
level of autonomy and flexibility
that can be exercised by individual
As a result, a new task force of the
JTCG (TF14) was set up at the end of
INCORPORATED INTO system. “Effectiveness” is defined in
Appendix 2 of Annex SL as being “the
included definitions, instead making
a normative reference to ISO 9000
ISO Technical Committees when 2018 to prepare a limited review of the THE LATEST VERSION extent to which planned activities (the Fundamentals and Vocabulary
developing their discipline-specific high-level structure, as part of a wider OF THE DIRECTIVES … are realised and planned results are standard). This is important for all
standards.
• Appendix 1, which specifies the
revision of Annex SL.
AND WILL APPLY TO THE achieved”. While an organisation might
have other additional expectations
users of standards, including auditors,
because it has been shown time and
justification studies that are required The revision process DEVELOPMENT OF ALL for its management system, the again that a good understanding of
when a proposal is made to develop
a new MSS (to avoid overlaps and/
Almost 100 representatives of ISO’s
Technical Committees and National
NEW MSS” MSS will define the minimum that
should be achieved as part of the
terminology is essential for a good
understanding of a standard as
or potential conflicts with existing Member Bodies participated in the provide conforming products and concept that “Output Matters”. This is a whole.
standards). revision process, under the leadership services, thereby improving customer described further in the joint ISO/IAF/
• Appendix 2 contains the harmonized of Dr Nigel Croft (Brazilian National satisfaction, and so on. This provides ILAC document “Expected outcomes Removal of “outsourcing” and
structure (HS), formerly known as Standards Organization) and a basis on which organisations for accredited certification to ISO “control of outsourced processes”
Cover courtesy of ISO

the high-level structure, with the Dick Hortensius (the Netherlands can consider the relevant risks and management system standards” The concepts of “outsourcing” and
identical core text, common terms Standardization Institute). TF14 tried opportunities they need to control or (https://www.iaf.nu/upFiles/CASCO_ “control of outsourced processes” will
and core definitions that MSS writers to avoid making changes for change’s exploit in order to achieve or exceed Expected_Outcomes2018final.pdf). no longer be used. In practice, there
are required to follow, together with sake, and applied a benefit/impact the goals of the management system. has often been discussion about what
guidance on how to use it (aimed rationale to every individual change. For auditors and those involved Terms and definitions always exactly outsourced processes are
primarily at the standards writers The changes to the high-level structure in accredited certification, these included in the standard and what is the difference with (the
Annex SL is the result of an extensive
themselves, but which can also be (now renamed the HS) are therefore intended results are an important revision process, with a benefit/rationale From now on, the terms and definitions control of) purchasing and working
useful to MSS users). quite small and will not have an reference point for determining the impact applied to every change. from Appendix 2 must be incorporated with outsourced service providers.

48 | QUALITY WORLD | SUMMER 2021 QUALITY.ORG | 49


ANNEX SL ANNEX SL

That is why it has now been decided cannot, or chooses not, to meet. By using different verbs, such as too much emphasis on “learning Risk Management (TC262), which Transition to the new HS
in clause 8 to set requirements for Such needs and expectations become “maintaining” documented information from mistakes” by taking corrective participated in the work, has since The new core text for MSS prescribed
the externally provided processes, “applicable requirements” for the (eg, procedures or work instructions) action on identified nonconformities. approached ISO to recommend by Appendix 2 of Annex SL applies from
products and services that are relevant quality management system only if and “retaining” documented This has resulted in the order of the a strategic high-level review on 1 May 2021, after which all new MSS and
to the management system. This now the organisation offers or accepts an information (for records), some MSS subclauses in clause 10 now being how all ISO and IEC (International revisions of existing standards must be
also requires these processes to be order for products and services that are hung on to the old concepts in a reversed so it now starts with a short Electrotechnical Commission) based on this new version of the HS.
controlled (typically via purchasing), based on them. roundabout way. section on “continual improvement” standards (not only MSS) define and A few standards are already ahead of
which has not been the case so far. This is consistent with the concept This has led to endless discussions in general. This change is unlikely to address risk. the game, such as the aforementioned
of “compliance obligations” as about when a document or have a significant impact on users, but As a result, neither the definition of ISO 37301:2021, published in April 2021.
The organisation determines which defined in the newly published ISO record is involved and what it is in line with standards such as ISO risk nor the text on how to deal with However, there is no requirement for
stakeholder requirements will be 37301:2021 standard for Compliance specific requirements apply to its 9001 and ISO 14001, in which a separate risks and opportunities in clause 6.1 published MSS to transition to the new
complied with Management Systems. management and control, while in “general” paragraph on improvement is of Appendix 2 has been changed. This HS within a specified time period, so it
In Appendix 2 of Annex SL, the term modern practice there are all kinds of already included. was considered to be the best option is likely that the 2012 and 2021 versions
“requirement” is defined as a need Management of change hybrid forms of making information available within the project time frame will co-exist for some time. However,
or expectation that is stated, generally Clause 6 now includes the new available in an effective and agile way. Risks and opportunities – no change – to have made any “quick-fix” changes since there are no fundamental
implied or obligatory. Clause 4.2 subclause 6.3, which states that the Therefore, the new version of Annex The question of “risk” and the ways in ahead of the significant discussions differences between the two, this is not
has always required an organisation changes to the management system, SL adopts the idea that documented which the various MSS address “risks that are being initiated at the ISO expected to become a major issue.
to identify the relevant requirements for whatever reason, shall be carried information needs to “be available”, and opportunities” varies significantly and IEC level could have caused more
of relevant interested parties out in a pre-planned manner. Clause rather than prescribing how exactly between different disciplines and confusion than clarity. Summary – socially responsible
or stakeholders. 8 elaborates on this by requiring that it should happen. sectors (most notably those that However, TF14 did succeed in business operations
This definition of a requirement the changes that are being planned operate in a regulated environment). developing significantly improved In light of this updated version of
indicates that it encompasses more in clause 6.3 are carried out in a Improvement Therefore, it was not surprising that guidance for MSS writers, which Annex SL, the ISO has indicated that
than what is mandatory for an controlled manner. This means that There were a number of comments these topics were the subject of much should provide some flexibility in the the path taken in 2012 to improve
organisation, eg, complying with the basics of Management of Change made about clause 10 of the Appendix debate during the revision process. application of Appendix 2 when needed the alignment and consistency of
legal requirements. However, it has have become an explicit part of Annex 2 text (“Improvement”), for instance The ISO’s Technical Committee on within a discipline-specific MSS. its portfolio of management system
been unclear how an organisation SL. This will not affect users of ISO standards is irreversible, and the
should deal with the other needs and 9001 (there is already a requirement millions of users of MSS can expect
expectations of stakeholders. in ISO 9001 to this effect), but this will “THERE IS NO that further steps will be taken in
This was already clarified in standards
such as ISO 14001 and ISO 45001, and
need to be addressed by all MSS in
the future. REQUIREMENT the coming years to support such
an approach that facilitates their
now a similar wording has been added FOR PUBLISHED adoption within a single (“integrated”)
in clause 4.2 (Understanding the needs
and expectations of interested parties)
Documented information
One important feature in the 2012
MSS TO management system.
Societal change can be facilitated
of Annex SL, to make it applicable to version of Annex SL was the departure TRANSITION by the adoption of the appropriate
all MSS. Namely, that the organisation from the well-known concepts of TO THE NEW MSS. Examples include business

HARMONIZED
“documents, procedures and records”, continuity and crisis management
“FROM NOW ON, and the introduction of the idea (highlighted by Covid-19), resource

THE TERMS AND of “documented information”. The STRUCTURE scarcity, adaptation to climate change,

DEFINITIONS FROM
purpose of this was to emphasise that
it is the information that is important
WITHIN A digital transformation, Industry 4.0,
the circular economy, sustainability,

APPENDIX 2 MUST BE for the effective functioning of the SPECIFIED TIME the sustainable development goals

INCORPORATED INTO
management system, and not so much
the way in which that information is
PERIOD, SO IT IS (SDGs), and others. All of these bring
both business opportunities and risks
EACH MSS” captured or documented. LIKELY THAT THE that can be addressed within a single,
In any case, the JTCG has been 2012 AND 2021 robust, business management model.
shall determine which of the identified
requirements of stakeholders will be
very reluctant to include specific
requirements for documentation in VERSIONS WILL The new Annex SL provides the
basic elements for this, so that any
addressed in the management system. Annex SL to provide the maximum CO-EXIST FOR organisation can easily understand
It is logical that these would then
become the “applicable requirements”
flexibility for individual MSS writers to
define this for their specific discipline,
SOME TIME” and embed the relevant MSS into its
business operations in a way that
that the organisation commits to with the minimum of bureaucracy. best fit its strategy and goals, core
meet, as expressed in the policy in The extent of documentation is a processes, products and services, and
accordance with clause 5.2 (XXX Policy), choice that an organisation makes the context in which it operates.
where “XXX” refers to the specific itself (based on the analysis of its
Getty.com/Creative-Touch

discipline of the MSS, such as quality, own needs for things like process
environment, etc. control, knowledge management, The latest version of
An example in the case of ISO demonstration of conformity and any Annex SL is available to
9001 might be where a potential requirements imposed by relevant view online at:
customer has a series of needs and interested parties), and not because bit.ly/3wAzyRT
expectations that the organisation “ISO requires it to be documented”.

50 | QUALITY WORLD | SUMMER 2021 QUALITY.ORG | 51

You might also like