Frequently Asked Questions

We have a large selection of frequently asked questions organised by subject area.
Select a category a below to filter out relevant questions or search here.

If you can't find what you're looking for you can ask us a question here.

The ISO/IEC 27001:2013 standard can be purchased from the ISO website here. The standard is available in hard copy or to download as a PDF. The standard is available in English, French and Arabic.

Additional standards from the ISO 27000 family, including ISO 27000 ISMS overview and vocabulary and ISO 27002 code of practice for information security controls, can be purchased here.

All delegates attending our certified ISO 27001 Lead Auditor course or ISO 27001 Auditor Conversion course require a copy of the standard.

 

ISO 27001:2017 recommends for organisations to undertake internal audits at planned intervals (Clause 9.2). Information security management system (ISMS) internal audits are undertake to ensure the organisation conforms to its own ISMS requirements and the requirements of ISO 27001. Internal auditing ensures the management system is implemented and maintained. Internal auditing also allows organisations to identify any nonconformities and opportunities for improvement. To learn more about auditing an ISMS please view our ISO 27001 Internal Auditor training course which provides delegates with the skills to plan, conduct, report and follow up an ISMS internal audit.

With hybrid working now a way of life for many organisations, Bywater’s flexible training options enable all delegates to participate in a course, regardless of their location. We can:

  • Run the course at one of your locations and invite all delegates to attend
  • Run the course at a convenient offsite location for all delegates
  • Deliver the course online in our Virtual Classroom, enabling those working from home and at the office to join the class

Just contact us to discuss your specific requirements.

Clause 5.2 of ISO 14001:2015 details the requirements for the environmental policy which shall be established, implemented and maintained by top management.

The environmental policy should be relevant to the organisation, for example considering the size of the organisation and its impacts on the environment. The policy should provide a framework for identifying environmental objectives and include a commitment to protect the environment. When writing the environmental policy the organisation should consider compliance obligations and be committed to the continual improvement of the environmental management system (EMS). The environmental policy should be documented, communicated within the organisation and be made available to interested parties.

To learn more about ISO 14001 please click here to view our ISO 14001 training courses.

A Lean Leader drives improvement activities, typically working with local management to identify and drive improvement. They also coach Lean Practitioners on process improvement methods and activities and deliver Lean training.

This 2-day course delivers all the content of the ISO 14971 Risk Analysis for Medical Devices, and on the 2nd day offers greater detail about Failure Mode and Effects Analysis (FMEA).

FMEA is a Core Tool for anticipating and preventing defects in design and manufacture. If you are interested in Core Tools, including FMEA, you may like to look at our programme of Core Tools training.

A dedicated training course is run specifically for your organisation, at a time and place of your choice. If you have a number of employees to train, this can be a convenient and cost-effective option for your business.

You may, for example, have several new staff members who need training in a specific skill set, or you would like all team members to receive a refresh of their knowledge. It may even be that a client has requested your whole team receives training to demonstrate your commitment to a standard.

Providing dedicated training gives Bywater the opportunity to tailor the content of the course to your particular business, enabling delegates to start applying their new skills quickly and effectively.

We can also work with you to design and deliver a programme of training across a range of skills that reflects the needs of your employees, such as lead and internal auditing together with business improvement techniques.

Organisations from many areas of industry and commerce have taken advantage of our dedicated training offering, including manufacturers, retailers, transport organisations, government agencies, police forces, local authorities, energy companies, healthcare providers, engineering organisations, pharmaceutical companies, construction companies, and research institutes.

Auditing is important to ensure your system conforms to your own requirements and, where relevant, the requirements of international standards such as ISO 9001, ISO 14001 and ISO 45001. Auditing also helps to ensure the management system is effectively implemented and maintained. During audits opportunities for improvement may be identified, in turn supporting the continual improvement of your management system.

 

ISO 9000:2015 describes the fundamental concepts and principles of quality management and specifies the terms and definitions that apply to all quality management and quality management system standards. ISO 9000 is regularly referenced in ISO 9001:2015. It is important to be familiar with ISO 9000 if you are auditing a quality management system. Copies of ISO 9000:2015 are available here.

If you are an internal or external auditor working to the requirements of ISO 9001:2008, then this course will update your knowledge and skills to the latest version of the standard – ISO 9001:2015. It will also be of value to anyone, including senior managers, for whom it would be useful to understand the changes needed to upgrade their QMS.

The course will enable you to understand the differences between the versions of the standard in terms of structure, terminology and approach, and plan necessary changes in your organisation.

Up-to-date knowledge of ISO 9001 and quality management systems will benefit your organisation, and enable you to meet the IRCA upgrade requirements for registered auditors.

    Ask Us A Question