10.1 Receipt and review of Audit report

The team leader is responsible for submission of audit report documents and can be given in electronic media to the client and the office. This contains at least corrective action plan for non-conformances, where ever applicable and assessor notes.

All audit reports (Stage 1, Stage 2, routine surveillances, follow-up, special audit, recertification etc) are reviewed at multiple stages.

Stage 1

includes administrative review. The submitted set of documents is reviewed for completion (also called administrative review) by AE. Audit report review checklist (F101) is used to record the review in case of Stage 1, Stage 2, Follow Up, Scope Extension, Special Audit, Recertification Audit and any cases where a certificate change is involved. AE issues a deviation note against the team leader (F102 Deviation note) if he / she finds one while administration review. AE submits his findings to Director Ops.

Stage 2

includes technical review. The audit report (corrected if possible) along with audit report review checklist (F101) in case of Stage 1, Stage 2, Follow Up, Scope Extension, Special Audit, Recertification Audit and any cases where a certificate change is involved is submitted to Certification committee member for technical review which includes review of the information provided by the audit team is sufficient with respect to certification requirements, scope of accreditation and effectiveness of corrections and corrective actions are effective for all non conformances raised during the audit. Stage 2 Review shall be carried out by the auditor qualified for the specific EAC sector, provided he has not participated in the audit and has not declared any conflict w.r.t. the client. Technical reviewer will be allotted who does not have a conflict of interest. It is the responsibility of the auditor to pro-actively declare of any conflict. The technical review may lead to a deviation note (F102), which is issued against the team leader, if a deviation is found. All auditors are trained for the review process. In cases where technical expert is used for the audit, the technical reviewer may discuss with the technical expert on the NC / observations used. The reviewer may also discuss any particular part of the report with the team leader / specific auditor. The reviewer also identifies if correction to deviation note (F102) issued needs to be completed prior to Stage 3. In case the audit report does not require review by certification committee chairman, the report is returned to AE for Stage 4.

Stage 3

includes decision making by certification committee chairman. Any audit report requiring issue of certificate (Stage 2 audit, change in scope or address, triennial audit etc) requires review and approval by certification committee chairman. For routine surveillance, the review by certification committee chairman is not required and the reviewer records his / her signature on the Report Reviewed by column of the audit report. The technical reviewer shall decide whether the report needs submission to certification committee chairman. Certification committee chairman reviews the findings of Stage 1 and 2 in addition to review of audit report prior to taking the decision. Correspondence related to the client (e.g. Complaints received against the client, changes in scope, media reports etc) are also reviewed during recertification decision. The decision taken is recorded on F101 form. For stage 1 audit, the stage 2 audit may be planned after technical review, however the certification committee chairman shall review the stage 1 audit report along with stage 2 audit before making his decision. The certification committee may ask for specific inputs from the client or send any auditor to the client to verify any part of the report.

In case Certification committee chairman is involved in the audit or is not available or has declared conflict w.r.t. any client, any other director reviews the audit report and takes the decision.

Note:

Involvement of the decision maker / technical reviewer / admin reviewer in audit means any type of audits which includes Stage 01, Stage 02, Surveillance, Renewal, and Special Audits. Report Reviewers (Admin and Technical), Certification Decision Makers should not be involved in any of these audits

Stage 4

includes further action by Account Executive. AE reviews the decision taken by technical review member and / or certification committee chairman for the following

10.2 Certificate preparation and issue

This involves preparation and review of certificate, certificate signature by Managing Director and updating the registrar of firms. In absence of Managing Director, Executive Director / Operations Director can sign the certificate.

Certificates are issued to clients following initial audit, extension to accredited scope, triennial audit, upgrade on surveillance or change in company details (name, address etc).

Certification documents are normally sent to the certified client in paper format though the postal system, however provision exists for the certificate to be sent electronically in a format that prevents alteration.

The certificates will be numbered sequentially starting with I001 followed by the global client code of ICS

AE prepares the certificate:

Client database shall be amended as per the database management process. The completed certificate with the audit report is reviewed by Director Ops for correctness and completeness of the certificate.

The certificate with all attachments like logo rules, cover letter etc is submitted to Managing Director / Technical Director / Operations Director for his signature.

Managing Director has no authority to reject / deny the issue of certificate. He may return the certificate to Chairman of Certification Committee clearly stating the reason for holding the issue. Chairman of Certification Committee shall review the reason and investigate on the same. However, if the Chairman has satisfied himself and re-sends the certificate to MD for approval, MD shall sign the certificate. A computer generated signature may also be used. The above process can be carried out by ED in absence of MD.

The signed certificate shall be sent to the client at his address or any other address he has specifically requested. The certificate shall not be issued to any other person without a written approval from the client. The certificate docket shall contain at least the following

A copy of the certificate together with all other documents supporting the approval shall be placed in the client's file or scanned in and stored on the doc server.

ICS International Certification will verify in subsequent audits the usage of logo to ascertain incorrect references to certification status or misleading use of certification documents, marks or audit reports.

Actions which can include requests for correction and corrective action, suspension, withdrawal of certification, publication of the transgression and, if necessary, legal action.

10.3 Change in Certificate

The client may request for change in certificate. This may be due to

Client shall request for change in certificate or reduction / expansion in scope to Director Ops. Director Ops shall review the request and decide for a special audit if the next audit is not due in near future or if the next audit cannot be preponed. Director Ops shall also determine if the changed scope is within accreditation scope of ICS.

In case of change in name of company or location without any change in management, the client shall submit ROC approval / any other regulatory approval for the change. Where the management has changed, the details of M&A and ROC approval / any other regulatory approval shall be submitted along with the request.

The duration for the special visit shall be decided by Director Ops and communicated to the client. The lead auditor submits a descriptive report detailing the changes, justification for reduction / expansion of scope and review of the impact of change in the scope (use of logos etc). Where expansion of scope is requested, the compliance to QMS for the respective activities and impact on other processes is verified. In case the special visit is carried out as a part of routine surveillance, the descriptive report is added to the surveillance report.

The report is reviewed as detailed in 10.1 and 10.2 above. A new certificate is issued with the reissue date (this distinguishes the revised certificate) but having the same expiry date on successful completion of the above process. Director Ops shall review the contract to determine change in contract w.r.t. duration for further visits etc.

Refusing Certification

Certificates will be refused if there are any major non-conformances identified at time of certification or recertification audit until the time the corrections and corrective actions are verified.

Client will be informed about this at the time of opening and closing meeting.

Refusal to take business:

The Director Ops assesses a prospective client with respect to the risk of supplying services. Director Ops may refuse to provide the service for any of the following reasons

10.4 Suspension and withdrawal or cancellation of certificates

This instruction covers suspension procedures through withdrawal or cancellation of the certification certificate and revision of the register of approved firms.

The following reasons are considered grounds for suspension:

An intimation (verbal / written) will be sent to the client fifteen days prior to suspending and issuing the suspension letter

Suspension period will be maximum of six months.

If the client has taken actions for the reasons they were suspended then these actions will be reviewed and if found satisfactory the certificate will again be restored.

The following reasons are considered grounds for de registration:

An intimation (verbal / written) will be sent to the client fifteen days prior to deregistration and issuing the deregistration letter

The suspension or deregistration can be initiated if the client does not allow the routine surveillance to be conducted at the required frequency. The first surveillance audit is carried out not more than 12 months from the certification decision date. The subsequent routine surveillance is carried out not more than 12 months from the last surveillance audit with a grace period of one month given under special circumstances. In case the audit is not done as per above defined time lines the certificate is suspended and a suspension letter is sent to the client and also requesting him to agree for the audit. In case of client not conducting the surveillance audit within the suspension period, then the client is de registered. Successful completion of the audit within the suspension period shall not impact the certification and the suspension is revoked.

In case the audit is not done within within the suspension period, the certificate is deregistered / cancelled and the client shall be considered as a fresh case for certification. In this scenario the Operations Director will study such cases and make a decision whether a Stage 01 Audit again needs to be conducted or not.

Special circumstances might be like strike, natural calamities, business operations (case to case basis) etc.

Conditions for Suspension or Cancellation of Client Certification*

Subject to actions by the client, the following steps will be taken leading to possible suspension or cancellation of the client's certification:

ICS International Certification India shall wherever applicable and as requested by the certified organization expand the scope of certification if during the time of routine surveillance audits / Re approval or Renewal audits it finds that the certified client has added more parts to the existing scope of certification. This will be done after the successful completion onsite audit at time of routine surveillance audits / Re approval or Renewal or as a special scope extension audit if required by the client. The expansion in scope will be approved by the Director Ops.

ICS International Certification India shall wherever applicable reduce the scope of certification if during the time of routine surveillance audits / Re approval or Renewal audits it finds that the certified client has continually / seriously failed to meet the certification requirements for those parts of the scope of certification. The reduction in scope will be approved by the Director Ops.

10.6

List of Registered Firms / Suspended Firms / De Registered Firms is updated as and when any new certificate or revised certificate is issued, revoking of suspension, any certificate is suspended or de registered and these are available upon request to ICS International Certification Office by any party .