{"id":2027,"date":"2013-10-03T03:05:53","date_gmt":"2013-10-03T07:05:53","guid":{"rendered":"http:\/\/www.oxebridge.com\/emma\/?p=2027"},"modified":"2013-10-03T03:17:59","modified_gmt":"2013-10-03T07:17:59","slug":"value-added-auditing-may-be-illegal","status":"publish","type":"post","link":"https:\/\/www.oxebridge.com\/emma\/value-added-auditing-may-be-illegal\/","title":{"rendered":"&#8220;Value Added&#8221; Auditing May Be Illegal"},"content":{"rendered":"<p><span style=\"font-size: 1em; line-height: 1.5em;\">Despite only being accredited for &#8220;conformity assessments,&#8221; Conformity Assessment Bodies (see? <em>it&#8217;s in their name)<\/em> nevertheless market their services as &#8220;value added auditing&#8221; in order to distinguish themselves from competitors. Of course nowadays nearly every registrar uses the phrase, so they aren&#8217;t differentiating from anything, but the term has stuck.<\/span><\/p>\n<div id=\"attachment_2030\" style=\"width: 446px\" class=\"wp-caption alignright\"><a style=\"color: #b7322c; text-decoration: underline;\" href=\"http:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2013\/10\/UL_valueadded.jpg\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-2030\" class=\" wp-image-2030 \" style=\"width: 446px;\" title=\"UL_valueadded\" src=\"http:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2013\/10\/UL_valueadded.jpg\" alt=\"\" width=\"436\" height=\"113\" srcset=\"https:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2013\/10\/UL_valueadded.jpg 727w, https:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2013\/10\/UL_valueadded-150x39.jpg 150w\" sizes=\"(max-width: 436px) 100vw, 436px\" \/><\/a><p id=\"caption-attachment-2030\" class=\"wp-caption-text\">UL&#8217;s advertising blurb.<\/p><\/div>\n<p>The shift away from raw conformity assessment is defended by registrars who claim ISO 9001 now requires &#8220;continual improvement&#8221; and value added auditing not only assesses conformity, but can help the client meet the requirement for improvement. They ignore the fact that registrars should not have a role in crafting or influencing the quality system they audit, as that is a clear-cut violation of accreditation rules such as ISO 17021. The accreditation bodies, such as ANAB, look the other way, buying into the notion that registrars can magically improve a company by walking a complete stranger through a client&#8217;s plant for a week.<\/p>\n<p>But as annoying as it is to take advice from an unqualified, self-appointed expert with only 36 hours of auditor training, it may also be illegal.<\/p>\n<div id=\"attachment_2031\" style=\"width: 343px\" class=\"wp-caption alignright\"><a style=\"color: #b7322c; text-decoration: underline;\" href=\"http:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2013\/10\/BSI_added-value.jpg\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-2031\" class=\"wp-image-2031 \" style=\"width: 343px;\" title=\"BSI_added value\" src=\"http:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2013\/10\/BSI_added-value.jpg\" alt=\"\" width=\"333\" height=\"154\" srcset=\"https:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2013\/10\/BSI_added-value.jpg 416w, https:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2013\/10\/BSI_added-value-150x70.jpg 150w\" sizes=\"(max-width: 333px) 100vw, 333px\" \/><\/a><p id=\"caption-attachment-2031\" class=\"wp-caption-text\">BSI&#8217;s blurb<\/p><\/div>\n<p><strong>We Don&#8217;t Need No Stinkin&#8217; Badges<\/strong><\/p>\n<p><span style=\"font-size: 1em; line-height: 1.5em;\">I recently underwent an audit where the auditor &#8211; a former employee of Raytheon &#8211; spent weeks making suggestions to my client on how to adopt various Raytheon methods. Naturally, the auditor defended such consulting suggestions as being &#8220;just passing on best practices I&#8217;ve seen at other companies.&#8221;\u00a0The client was irked for two reasons: first, the auditor&#8217;s experience was from nearly 30 years prior, and no longer at all useful in a contemporary setting. Second, the client company was specifically built around a corporate culture that rejected the practices of &#8220;old guard&#8221; companies, and instead wanted to build a modern, from-the-ground-up QMS that was totally its own.<\/span><span style=\"font-size: 1em; line-height: 1.5em;\">What was the most troubling, however, is that it quickly became apparent that this auditor would then do the opposite: go to other clients and tell <\/span><em style=\"font-size: 1em; line-height: 1.5em;\">them<\/em><span style=\"font-size: 1em; line-height: 1.5em;\"> about the &#8220;best practices&#8221; of my client. <\/span><\/p>\n<p><span style=\"font-size: 1em; line-height: 1.5em;\">This is where the legal question comes into play. My client has\u00a0<\/span><span style=\"font-size: 1em; line-height: 1.5em;\">technology<\/span><span style=\"font-size: 1em; line-height: 1.5em;\">\u00a0that it guards fiercely, with ITAR regulation in place, a horde of security guards roaming the grounds, doors with electronic locks that can only be opened by individuals with proper clearance, and IT restrictions on what data can be seen by each employee. Competitors have <strong><em>appealed to the U.S. Congress<\/em><\/strong>\u00a0(unsuccessfully) to obtain information on my clients methods.<\/span><\/p>\n<p><strong>Wink-Wink, Say No More<\/strong><\/p>\n<div id=\"attachment_2032\" style=\"width: 452px\" class=\"wp-caption alignright\"><a href=\"http:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2013\/10\/dnv_valueadded.jpg\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-2032\" class=\"size-full wp-image-2032\" title=\"dnv_valueadded\" src=\"http:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2013\/10\/dnv_valueadded.jpg\" alt=\"\" width=\"442\" height=\"100\" srcset=\"https:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2013\/10\/dnv_valueadded.jpg 442w, https:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2013\/10\/dnv_valueadded-150x34.jpg 150w, https:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2013\/10\/dnv_valueadded-440x100.jpg 440w\" sizes=\"(max-width: 442px) 100vw, 442px\" \/><\/a><p id=\"caption-attachment-2032\" class=\"wp-caption-text\">DNV&#8217;s blurb<\/p><\/div>\n<p>Nevertheless, with permission of ANAB, a registrar auditor is free to spread verbal explanations of such process information to his other clients, including the same competitors who were defeated by Congress, provided he merely not mention my client by name. Such &#8220;anonymizing&#8221; of the &#8220;best practices&#8221; is perfectly acceptable under the current ANAB interpretation of the rules. But because my client is developing entirely new technologies, they are hardly concerned if the information is passed on under their name or not&#8230; <em><strong>they don&#8217;t want it passed at all<\/strong><\/em>. But there isn&#8217;t a thing they can do to stop the auditor from blabbing to anyone he comes in contact with.<\/p>\n<p>If this sounds far-fetched, it&#8217;s not. In fact, it&#8217;s already happened.<\/p>\n<div id=\"attachment_2033\" style=\"width: 473px\" class=\"wp-caption aligncenter\"><a href=\"http:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2013\/10\/NQA_valueadded.jpg\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-2033\" class=\"wp-image-2033 \" title=\"NQA_valueadded\" src=\"http:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2013\/10\/NQA_valueadded.jpg\" alt=\"\" width=\"463\" height=\"114\" srcset=\"https:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2013\/10\/NQA_valueadded.jpg 579w, https:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2013\/10\/NQA_valueadded-150x37.jpg 150w\" sizes=\"(max-width: 463px) 100vw, 463px\" \/><\/a><p id=\"caption-attachment-2033\" class=\"wp-caption-text\">Yes. NQA, too.<\/p><\/div>\n<p><strong>Hackers Get Arrested; Auditors Get Promoted<\/strong><\/p>\n<p>About two years ago an auditor with NSF-ISR conducted a Stage 1 certification audit of a company that later became a client of mine. He began providing consulting advice, under the usual guise of &#8220;value added auditing.&#8221; But he went further than normal, providing the client with &#8220;sample Quality Manuals.&#8221; \u00a0The manuals came from two of his other clients: Star Aviation (Mobile AL) and Lifesaving Systems Corp. (Apollo Beach FL). He also provided a sample Customer Survey Form from JC Machine Corporation.<\/p>\n<p>I called the three companies; only two replied (Star and Lifesaving) and they both were unaware that their Quality Manuals had been distributed publicly; they were, to put it mildly, furious. This was a clear breach of nondisclosure agreements in place, as well as copyright and trademark infringement.<\/p>\n<div id=\"attachment_2034\" style=\"width: 438px\" class=\"wp-caption alignright\"><a href=\"http:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2013\/10\/Smithers_valueadded.jpg\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-2034\" class=\"wp-image-2034 \" title=\"Smithers_valueadded\" src=\"http:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2013\/10\/Smithers_valueadded.jpg\" alt=\"\" width=\"428\" height=\"70\" srcset=\"https:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2013\/10\/Smithers_valueadded.jpg 594w, https:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2013\/10\/Smithers_valueadded-150x25.jpg 150w\" sizes=\"(max-width: 428px) 100vw, 428px\" \/><\/a><p id=\"caption-attachment-2034\" class=\"wp-caption-text\">Smithers, of course.<\/p><\/div>\n<p>(I notified NSF-ISR, but declined to provide them the name of the auditor, on the request of my client. I instead asked that NSF-ISR merely notify their entire auditor pool not to share client information. They declined to take action since I would not name the individual auditor.)<\/p>\n<p><span style=\"font-size: 1em; line-height: 1.5em;\">In <a href=\"http:\/\/www.oxebridge.com\/emma\/?p=464\">another infamous case<\/a>, an auditor with SGS gave a 90-minute training presentation during an audit (a violation in itself) using a presentation stolen from a competing registrar, BVQi, going so far as to falsely add his name as the author. When alerted BVQi was livid.<\/span><\/p>\n<div id=\"attachment_2037\" style=\"width: 462px\" class=\"wp-caption aligncenter\"><a style=\"color: #b7322c; text-decoration: underline;\" href=\"http:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2013\/10\/QMI_valueadded.jpg\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-2037\" class=\"wp-image-2037 \" style=\"border: 0px none; padding: 0px; margin: 0px; -webkit-user-drag: none; width: 575px;\" title=\"QMI_valueadded\" src=\"http:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2013\/10\/QMI_valueadded.jpg\" alt=\"\" width=\"452\" height=\"121\" srcset=\"https:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2013\/10\/QMI_valueadded.jpg 565w, https:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2013\/10\/QMI_valueadded-150x40.jpg 150w\" sizes=\"(max-width: 452px) 100vw, 452px\" \/><\/a><p id=\"caption-attachment-2037\" class=\"wp-caption-text\">QMI gets into the act<\/p><\/div>\n<p><strong>Adding Value&#8230; to Your Competitors<\/strong><\/p>\n<p>Accreditation Bodies could crack down on &#8220;value added auditing&#8221; by merely enforcing existing rules against registrars providing consulting\u00a0<span style=\"font-size: 1em; line-height: 1.5em;\">services. It requires a strict reading of the requirement, rather than the lax interpretation under which they currently operate; but it&#8217;s feasible, and would help stop the flood of bad advice perpetrated by auditors, enabling them to focus on conformity assessment. In addition, it would stop exposing registrars to potential lawsuits, and help maintain the secrecy of ISO 9001 client organization&#8217;s intellectual property.<\/span><\/p>\n<p>Will they? It&#8217;s unlikely. ANAB is paid by the certification bodies, and they are terrified of cutting off their primary source of revenue by applying too much pressure. But one wonders what any of these CB&#8217;s or AB&#8217;s would do if someone started leaking <em>their<\/em> intellectual property. (Don&#8217;t tempt me.)<\/p>\n<p>So the next time your ISO 9001 auditor starts to say, &#8220;here&#8217;s what I&#8217;ve seen in other companies,&#8221; you may want to stop him, knowing that in the next few days it&#8217;s likely that he will be revealing all <em>your<\/em> secrets to your competitors.<\/p>\n<div style=\"width: 614px\" class=\"wp-caption aligncenter\"><a style=\"color: #b7322c; text-decoration: underline;\" href=\"http:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2013\/10\/PJ_valueadded.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\" wp-image-2035 \" style=\"width: 614px;\" title=\"PJ_valueadded\" src=\"http:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2013\/10\/PJ_valueadded.jpg\" alt=\"\" width=\"604\" height=\"52\" srcset=\"https:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2013\/10\/PJ_valueadded.jpg 604w, https:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2013\/10\/PJ_valueadded-150x13.jpg 150w\" sizes=\"(max-width: 604px) 100vw, 604px\" \/><\/a><p class=\"wp-caption-text\">PJ, natch.<\/p><\/div>\n<div><\/div>","protected":false},"excerpt":{"rendered":"<p>Despite only being accredited for &#8220;conformity assessments,&#8221; Conformity Assessment Bodies (see? it&#8217;s in their name) nevertheless market their services as &#8220;value added auditing&#8221; in order to distinguish themselves from competitors. Of course nowadays nearly every registrar uses the phrase, so they aren&#8217;t differentiating from anything, but the term has stuck. The shift away from raw [&hellip;]<\/p>","protected":false},"author":2,"featured_media":2061,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_et_pb_use_builder":"","_et_pb_old_content":"","_et_gb_content_width":"","mc4wp_mailchimp_campaign":[],"footnotes":""},"categories":[5],"tags":[],"class_list":["post-2027","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-opinion","et-has-post-format-content","et_post_format-et-post-format-standard"],"_links":{"self":[{"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/posts\/2027","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/comments?post=2027"}],"version-history":[{"count":16,"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/posts\/2027\/revisions"}],"predecessor-version":[{"id":2048,"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/posts\/2027\/revisions\/2048"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/media\/2061"}],"wp:attachment":[{"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/media?parent=2027"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/categories?post=2027"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/tags?post=2027"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}