When you submit an enquiry via our website, we use the personal data you supply to respond to your query, including providing you with any requested information about our products and services. We may also email you several times after your enquiry in order to follow up on your interest and ensure that we have answered your it to your satisfaction. We will do this based on our legitimate interest in providing accurate information prior to a sale. Your enquiry is stored and processed as an email which is hosted by Microsoft within the European Economic Area (EEA). We keep enquiry emails for two years, after which they are securely archived and kept for seven years, when we delete them.
When getting to grips with ISO (International Organization for Standardization) standards for the first time, you will notice that they are structured in clauses, a bit like a contract. This structure is common across all of the management system standards that ISO publishes, such as ISO9001, ISO14001 and ISO/IEC 27001, and is known as the “Annex SL” format or, more helpfully, the “High Level Structure”. So, what we’re about to say applies to all of these standards whether we’re interested in quality management (ISO9001), environmental management (ISO14000) or business continuity (ISO22301). Note however that the Annex SL wording has evolved over time, so the exact format and wording of each standard depends not only on its subject, but also on when it was last revised. Note also that Clause 8 is easily the clause with the most variation across standards, so although many of the headings are the same, the content (as you’d expect) is different.
In the context of ISO management systems, Clause 8 refers to the “Operation” of the management system. This clause is a fundamental part of ISO standards, such as ISO 9001 (Quality Management), ISO 14001 (Environmental Management), ISO 45001 (Occupational Health and Safety Management). The purpose of Clause 8 – Operation is to provide guidelines and requirements for effectively implementing the processes and activities necessary to achieve the organization’s objectives and deliver the products or services in line with its policies and plans. Clause 8 typically covers a range of topics related to the day-to-day operations of an organization and its management system. The specific content varies depending on the type of management system, but some common themes include:
In essence, Clause 8 – Operation guides organizations on how to execute their plans, deliver their products/services, and maintain the effectiveness of their management system in line with the defined requirements and policies. It emphasizes the practical implementation of the management system standards, helping organizations to achieve consistent and desirable outcomes while managing risks and opportunities.
Let’s look at the specifics of some of the common standards.
Clause 8 in ISO9001 requires you to plan, control and implement process necessary for your products and services to conform with your requirements and those of the standard. It also has the only mandatory procedure, which is clause 8.4 – Control of externally provided processes, products and services. ISO 9001 is an international standard that outlines the requirements for a quality management system (QMS) within an organization. Clauses 8.1 to 8.7 of ISO 9001 pertain to the planning and realization of products and services, which are crucial aspects of maintaining consistent quality throughout an organization’s processes. Here’s a brief explanation of each of these clauses:
These clauses collectively emphasize the significance of meticulous planning, effective control, and continuous monitoring to ensure that products and services consistently meet or exceed customer expectations. Adhering to these clauses helps organizations enhance their quality management systems and ultimately deliver better value to their customers.
It’s important to understand how the requirements in Clause 8 relate to other clauses within the standard. Alignment with other clauses is as follows:
With Clause 8 in ISO 14001, you are required to develop operational planning, emergency response, and environmental monitoring. ISO 14001 is an international standard that focuses on environmental management systems (EMS), helping organizations establish a framework to manage their environmental responsibilities effectively. Clauses 8.1 and 8.2 of ISO14001 are part of the “Operation” phase, which deals with the execution of the environmental management system.
Here’s a brief explanation of each of these clauses:
These clauses collectively guide organizations in aligning their operations with environmental objectives, minimizing negative environmental impacts, and being prepared to handle emergencies that might arise. This approach helps organizations demonstrate their commitment to sustainable practices and responsible environmental management.
As with ISO9001, the areas covered in Clause 8 of ISO14001 mesh with other parts of the standard in the following way:
Within Clause 8, ISO 45001 requires you to plan, control hazards and mitigation, manage change and procurement, and prepare emergency responses. ISO 45001 is an international standard that sets the requirements for occupational health and safety management systems (OHSMS). It provides a framework for organizations to manage and improve their occupational health and safety performance. Clauses 8.1 and 8.2 of ISO 45001 are part of the “Operation” section of the standard, focusing on the implementation and control of the OHSMS. Here’s a brief explanation of each of these clauses:
These clauses guide organizations in effectively managing their operational processes to ensure the health and safety of their workers. By identifying risks, implementing controls, and managing changes carefully, organizations can maintain a safe and healthy work environment and continuously improve their OHSMS performance.
Alignment with other clauses within ISO45001 is as follows:
Clause 8 in ISO 27001 requires the organisation to develop operational planning and control, information security risk assessments and treatments. This clause provides the framework to establish operational planning and control, risk assessment and treatment, business continuity planning and disaster recovery and monitoring, measurement, analysis and evaluation. Here’s a brief explanation of these clauses:
As with the other standards, there is a high degree of alignment with other clauses:
Clause 8 in each of these ISO management systems deals with operational aspects related to quality, environmental management, occupational health and safety, or information security, depending on the standard.
The alignment with other clauses ensures that the operational processes are well-integrated into the overall management system, thereby contributing to the achievement of organizational objectives and continuous improvement.
For some of the standards discussed (such as ISO27001), clause 8 is not a lengthy one, whereas for others it takes up many pages of the standard document. Consequently, the length of time you will spend on this clause will vary significantly according to the standard you are implementing.
Written by Ken Holmes and Ted Spiller.
Ken is CertiKit’s Managing Director and Lead Toolkit Creator. Ken is a CISSP-qualified security and data protection specialist who also holds the internationally-recognised Certified Information Privacy Professional – Europe (CIPP/E).
Ted is CertiKit’s Compliance Consultant, and an expert in many ISO management systems; he is a Lead Auditor for ISO27001, ISO9001 and ISO14001 and Auditor for ISO45001 and ISO22301.
CertiKit’s ISO Toolkits and ISO Services are available help you understand and implement your chosen ISO standard(s). The toolkits include easy to understand templates and guides, plus a perpetual licence with ongoing updates and support, so you’ve got help whenever you need it.
Click the links to find out more about the ISO Toolkits and ISO Services.