What is a quality management system?
A quality management system is how an organisation makes sure work is done correctly, that mistakes are found and fixed, and that it learns from them. It is not a binder and not a piece of software – it is a way of working. The software is simply the tool that makes the way of working practical.
What must it contain?
Whatever the industry or size, a working quality system rests on five things. Remove one and the others fall apart.
- Governing documents. How work is to be done: policy, routines, procedures and an emergency plan – current, approved and available to the people who need them. Document control.
- Risk assessment. What can go wrong, how likely is it, and how serious would it be – with measures, an owner and a deadline. Risk assessment.
- Verification that routines are followed. Checklists, safety rounds and internal audits. Checklists.
- Deviation handling. When something goes wrong: record it, find the cause, take action, close it. Deviation management.
- Systematic follow-up. Recurring activities through the year, and a review where management genuinely assesses whether the system works. Annual plan and internal control.
Quality, HSE and internal control – what is the difference?
The terms are used interchangeably in everyday speech, and that is rarely a problem. But they are not quite the same thing:
| Term | Concerns | Anchored in |
|---|---|---|
| Quality management system | That the delivery is right: product, service, documentation, customer satisfaction | ISO 9001, contractual requirements |
| HSE system | That nobody is injured or made ill by the work, and the environment is protected | Working Environment Act, ISO 45001 |
| Internal control | That the organisation systematically complies with the rules that apply to it | Norwegian Internal Control Regulation |
In practice they overlap so much that running three systems makes little sense. Deviation handling, document control, risk assessment and follow-up are the same mechanisms with different content. That is why one system is the right answer, not three.
What does Norwegian internal control regulation require?
It applies to every organisation covered by the Working Environment Act – including one with two employees. The requirements are the same, but the scope should be proportionate to size and risk. In short, the organisation must be able to document that it:
- knows the requirements that apply to it
- has set health, safety and environment objectives
- has a clear allocation of responsibility and authority
- maps hazards and assesses risk, with plans and measures to reduce it
- has routines to detect, correct and prevent breaches
- monitors and reviews the system systematically
- involves employees and safety representatives
That last point is the one most often missing in practice. A risk assessment written at a desk without anyone who does the work being involved is not a risk assessment – it is a document.
What does ISO 9001 involve?
ISO 9001 is an international standard for quality management. Certification means an independent body has verified that the organisation works according to the standard. It is often a requirement in public tenders and larger private contracts. Among other things the standard requires documented information to be controlled and traceable to the version in force, risks and opportunities to be assessed, deviations to be handled with root cause analysis, internal audits to be carried out, and management to review the system at least annually.
No software can certify an organisation – an auditor does that. But a system built around the requirements turns the audit into a review rather than a project. Internal audits.