Blog

14 Jul
Managing Food Safety Risks in Warehouse and Distribution Centers

Recent recalls tied to contaminated warehouse conditions show how quickly an outside storage or distribution failure can become a brand, consumer safety, and regulatory problem for any company whose products pass through that facility. Food safety and quality are not limited to food manufacturers. When a third-party logistics (3PL) provider, outside warehouse, wholesaler, or distribution center (DC) stores regulated products under unsanitary conditions, otherwise compliant products can become adulterated after they leave the manufacturer’s control.

The reality is that once products enter an outside warehouse, the product manufacturer still owns the consequences of how their products are stored, protected, and traced, which is why managing 3PLs, warehouses, and DCs like any other supplier is so important.

Why It Matters

Many companies treat warehousing and distribution as downstream logistics functions rather than as critical control points in the food safety supply chain system. But there are clear ramifications from doing so. Storage, handling, pest control, sanitation, segregation, temperature control, inventory rotation, and traceability can materially affect product safety and quality. A product that was manufactured safely can still become contaminated, damaged, misidentified, or rendered unsuitable for sale during storage or distribution.

Outsourcing logistics does not remove responsibility. Brand owners, manufacturers, importers, distributors, and retailers may still face recall costs, customer claims, regulatory scrutiny, reputational harm, and business interruption if a third-party facility fails. Many consumers and customers will associate a third-party facility recall with the product brand, not the warehouse or DC where the failure occurred.

Key Risks Created by Outside Warehouse and Distribution Suppliers

Outside warehouses and DCs can introduce risk in several ways. The most prevalent is exposure to unsanitary conditions from pests, standing water, damaged packaging, poor housekeeping, inadequate waste management, or commingled storage. However, the risk profile is broader than sanitation alone and can include the following:

  • Inadequate product traceability or lot-level visibility.
  • Weak recall support or slow access to records.
  • Inadequate temperature control and missing or incomplete temperature records.
  • Improper segregation of allergens, chemicals, or incompatible products.
  • Expired inventory, undocumented rework, or relabeling activity.
  • Poor contractor oversight and insufficient facility security controls.

The highest risk facilities tend to be those that handle mixed-product categories, high-inventory turnover, small-lot distribution, damaged or returned goods, and products from many unrelated manufacturers. In these environments, one sanitation failure can affect hundreds (or even thousands) of SKUs and create a complex recall that requires coordination across multiple brands, retailers, regulators, and consumers.

Material and Measurable Impacts

Like any recall event, the consequences associated with a contaminated warehouse event may be significant for the warehouse, but also for the brand owner and product manufacturer. A recall can trigger product holds, expanded traceability exercises, customer notifications, disposal costs, refund obligations, transportation expenses, legal review, insurance claims, and lost sales. It can also expose gaps in supplier approval programs, recall plans, and crisis communication procedures. If the company cannot quickly determine which lots were stored where, when, and under what conditions, the scope and potential impacts of the recall may quickly expand.

Key Controls for Reducing Recall Risk

Companies using 3PLs and outside storage and distribution suppliers need to employ active oversight; a simple, signed service agreement is not enough. The strongest programs qualify storage and distribution providers before use, define expectations in writing, verify controls onsite, monitor performance continuously, test recall readiness, escalate early, document decisions, and requalify when risk changes—just as they would any other supplier.

The following actions can help to reduce recall risks and create a robust program to maintain warehouse compliance:

  1. Treat warehouses and 3PLs as critical suppliers. Include outside warehouses, DCs, fulfillment centers, and cross-dock operations in a formal Supplier Approval Program. Risk-rank them based on product type, storage conditions, regulatory category, geography, history, volume, and whether they handle mixed-product categories.
  2. Conduct structured due diligence and onsite audits. Before onboarding a 3PL, evaluate regulatory status, inspection history, certifications, insurance coverage, facility conditions, sanitation and pest management records, temperature-control capabilities, recall history, subcontractor use, and ability to support lot-level traceability. Audits should verify conditions directly; desk reviews are not enough.
  3. Require documented pest prevention and sanitation controls. Service agreements should require pest control maps, service records, trend reports, sanitation schedules, inspection logs, corrective actions, and evidence that findings are investigated and closed. Recurring pest activity, unexplained droppings, damaged doors, open dock gaps, or poor housekeeping should trigger escalation.
  4. Strengthen traceability and lot-level visibility. Manufacturers need to know which products, lots, and dates were stored at each facility. Ensure warehouse management systems support rapid retrieval of receiving, storage, movement, shipping, hold, and destruction records. If the affected lots cannot be isolated quickly, recall scope and cost will increase.
  5. Build recall obligations into supplier agreements. Agreements should define notification timelines, record access, product hold authority, communication responsibilities, destruction documentation, refund or recovery provisions, and cooperation with regulators. Companies should test these requirements through mock recalls involving the 3PL or warehouse supplier.
  6. Monitor performance continuously. Regular supplier oversight should include audit performance, corrective action closure time, pest activity trends, sanitation findings, temperature deviations, damaged goods rates, inventory accuracy, customer complaints, shipping errors, product hold events, regulatory findings, and mock recall completion time. These indicators should drive supplier risk ratings, audit frequency, and escalation requirements.
  7. Re-evaluate suppliers and maintain alternatives. Reassess 3PLs annually and when they add facilities, change ownership, expand product categories, increase volume, add subcontractors, receive regulatory findings, or experience contamination, temperature, traceability, or security incidents. Prequalifying backup suppliers can help support faster recovery if a logistics partner fails.

Key Takeaways

Warehouse and distribution controls are product safety controls. Outsourcing logistics does not outsource responsibility for product safety, traceability, or recall readiness. One sanitation failure at a multi-brand warehouse can create a complex, expensive, and highly visible recall. As such, brand owners need to manage 3PLs with the same discipline applied to manufacturers, ingredient suppliers, and other critical suppliers. The most effective programs are proactive, documented, risk-based, and supported by evidence to remove recall risk before it becomes a liability.

13 Jul
Tech Corner: Electronic Standards Register

Functionality: What does it do?

Certification standards help assure customers, suppliers, regulators, and stakeholders that an organization’s products, services, and management systems meet recognized best practices. These standards are not static. Requirements continue to evolve as certification bodies respond to new risks, regulatory expectations, sustainability priorities, technology changes, and global benchmarking requirements. These updates can quickly create gaps if requirements are tracked manually or inconsistently, especially for companies certified to more than one overlapping scheme.

Recent and upcoming updates to SQF, FSSC 22000, ISO 14001, ISO 9001, and other ISO-based management system standards make it increasingly important for organizations to maintain a structured, current view of the requirements that apply to them. KTL’s electronic standards register organizes certification requirements into an online tool, allowing teams to track applicable clauses, map supporting documents, assign responsibilities, and monitor version changes across multiple standards.

Benefits: Why do you need it?

KTL’s electronic standards register is more than a document management tool. It provides the framework for monitoring change, assigning ownership, documenting implementation, and demonstrating that the organization has evaluated and responded to new or revised requirements in a timely, controlled manner. This is especially valuable during standards transitions to ensure the organization is complying with the most recent version.

An electronic standards register:

  • Maps the organization’s documents to specific certification standard requirements.
  • Identifies common requirements and allows documentation to be linked between standards, as needed.
  • Maintains version control by tracking the current standard, upcoming revisions, transition deadlines, and changes that may affect procedures, records, training, and audit evidence.
  • Supports proactive gap assessments when standards are revised, helping teams identify where policies, programs, forms, and responsibilities need to be updated before certification audits.
  • Reduces the risk of missed updates when an organization manages multiple certification schemes, sites, departments, or document owners.
  • Helps the internal audit team to complete and keep notes for the internal audit.
  • Supports management review, internal audit planning, corrective action tracking, and communication across functions.

Technology Used

  • Power Apps
  • SharePoint
17 Jul
second-party audit
The Business Case for Second-Party Audits

All types of organizations and operational processes demand a variety of audits and assessments to evaluate compliance with requirements—ranging from government regulations, to industry codes, to management system standards (e.g., ISO, GFSI), to internal obligations. Audits and assessments capture regulatory compliance status, management system conformance, supplier compliance, adequacy of internal controls, potential risks, and best practices.

Internal audits help identify problems so corrective/preventive actions can be put into place and then sustained and improved prior to third-party certification/compliance audits. Internal audits and assessments also help companies with continuous improvement initiatives.

Understanding the Internal Audit Process

Many organizations conduct internal audits with their own staff to assess conformance and identify opportunities for improvement. For companies large enough to have a dedicated internal audit team (with have no ties to the processes they audit), this may make perfect sense. However, it can take significant resources—time, personnel, money—to conduct all internal audits with internal resources.

It is easy to underestimate what goes into a successful audit and assume that it is more efficient and cost-effective to use internal resources. But that often isn’t the case. Let’s consider what an internal audit entails.

Pre-Audit Preparation

  • Research: Auditors must understand the standard they are assessing against (i.e., regulatory, management systems, internal, industry). Effective auditors will also understand industry best practices; related local, state, and/or country-based requirements; processing norms for new product areas; etc. that can impact operational compliance and risks.
  • Logistics: Logistics includes coordinating with the facility(ies) to schedule the audit and time with applicable personnel for interviews and, if travel is required, researching/booking flights, booking hotels, arranging for car transportation, etc.
  • Document Review: Prior to the onsite audit, auditors should review available documentation (e.g., procedures, policies, programs). This will better inform and guide them on where they should dig more deeply during the audit, as well as help them create effective audit protocol (see below). Pre-audit document review also allows the onsite portion of the audit to remain focused on observing operations, interviewing workers, and verifying physical requirements are being met.
  • Audit Protocol/Template: Auditors need to take the time to develop protocol/questions for conducting the audit, as well as standardized reporting templates, before the site visit. A standard protocol will make conducting multiple audits more efficient. Consistent protocols and templates also add value by allowing for direct year-over-year and site-to-site comparisons.

Onsite Audit

  • Technical Knowledge: To efficiently conduct an audit, auditors must have a thorough understanding of the standard they are assessing against. In many cases, auditors are asked to juggle multiple areas of focus at once. For example, in a foods facility, the auditor may simultaneously evaluate Food and Drug Administration (FDA), U.S. Department of Agriculture (USDA), Global Food Safety Initiative (GFSI), and facility-specific procedure requirements. For an environmental, health, and safety (EHS) audit, the auditor may simultaneously assess Environmental Protection Agency (EPA), Occupational Safety and Health Administration (OSHA), state agency, and facility-specific requirements. Deep technical knowledge of all the related standards and codes helps to ensure a thorough audit.
  • Audit Tools: Having the right tool for the job can make audits significantly more efficient. This includes the audit protocol and templates developed as part of pre-audit preparation, as well as audit tools that may be used to conduct and manage audits more efficiently and effectively.
  • Audit Management: Auditors are responsible for building a relationship of trust and openness with the facility quickly, while still maintaining control of the audit. This can be a challenge for internal auditors when interviewing colleagues and assessing internal systems.

Post-Audit Follow-up

  • Report: Auditors need to synthesize observations from the audit to create a report that concisely conveys all pertinent information, including nonconformances with the defined standard(s). Auditors provide additional value when they can leverage their industry experience to prioritize findings and identify opportunities for improvement and best practices. Reports are most valuable when finalized within a few weeks of the site visit when information is fresh to facility staff.
  • Corrective Actions: After an internal audit, facility staff will inevitably have questions regarding findings and what to do next. Auditors can provide valuable support by offering recommendations, building corrective action plans, and supplying technical guidance.

Many organizations do not have dedicated internal auditors—rather, internal auditing is an “add-on” responsibility—so time spent completing these internal audit activities takes time away from other business responsibilities. This often results in a post-audit period where the internal auditor has significant catchup to complete other work that has been put on the backburner while conducting the internal audit.

Value of a Second-Party Auditor

A second-party auditor can provide an objective assessment of overall compliance status and, in many cases, do it more efficiently than organizations are able to do with their own resources. A second-party auditor has the time required to conduct the audit, travel, review documents, and create a report. Beyond that, a second-party auditor also has audit tools and templates to create efficiencies when conducting the audit and reporting, can consolidate audit trips, and can spend dedicated time completing all audit activities as efficiently as possible without needing to factor in other business responsibilities.

Beyond saving significant resources, using a second party to conduct audits provides significant business value and additional return on investment:

  • Objectivity: Enlisting a qualified outside firm to conduct an audit provides a fresh set of unbiased eyes to assess aspects of your program internal staff may not consider or see. Second-party auditors offer broad perspective and knowledge of best management practices from conducting audits across industries and standards. They maintain ongoing, up-to-date awareness of current and pending regulatory requirements that the organization should consider.
  • Customizable: The audits themselves can be customized to fit the needs and goals of the organization. A second-party auditor can provide more direct coverage to evaluate specific program effectiveness and allow for a more focused understanding of existing strengths and improvement areas. Whether there is a desire to prepare for unannounced regulatory agency visits, review plans and programs, assess supplier compliance, or even verify applicability, second-party audits can be built to address the organization’s identified concerns and help manage risks.
  • Effective Tools: Second-party auditors often bring effective audit tools to help conduct and manage audits. These tools capture regulatory compliance status and certification system conformance more efficiently, track audit progress/completion status by subject, and generate reports that can be used by management to inform decision making. 
  • Efficiency: Audits performed internally can take resources away from normal business operations not only when conducting the audit, but also when catching up on daily responsibilities and work that is set aside during the audit. Second-party auditors work with the resources allocated to them to conduct an audit in a timely manner that does not negatively impact business functions. These audits minimize the overall disruption in business compared to internal audits.
  • Validation: Second-party auditors validate existing programs and identify areas where best practices can be implemented to further protect the company. They assist in identifying and prioritizing issues before they become violations—focusing on implementing and closing corrective actions. They also provide data and reports that can be shared internally with employees to improve performance or externally with communities or customers to bolster the company’s image.  
  • Consistency: Using the same second-party auditor to conduct your audits creates consistency across locations and over time. This allows the organization to establish a benchmark for performance that can be used to help ensure continuous improvement throughout the organization and its supply chain.

Second-party audits are not just about checking boxes—they are about building stronger partnerships, spotting issues early, and keeping your business running smoothly. Don’t wait for nonconformances to catch you off guard. Implementing second-party audits isn’t just a compliance tool, it is a strategic advantage.

20 Nov

Quality

Comments: No Comments

KTL Co-Authors Study on Expanding Pharmacy Roles in Treating OUD

Access to treatment for opioid use disorder (OUD) is a challenge in rural settings and communities of color due, in part, to the limited availability of healthcare providers equipped and willing to provide medications for opioid use disorder (MOUD). Recent discussion has explored the role of pharmacies in enhancing access to MOUD within underserved areas. However, pharmacies face multiple obstacles related to expanded responsibilities in dispensing MOUD, especially in rural and other communities.

To address this issue, the National Drug Abuse Treatment Clinical Trials Network (CTN) funded a study (CTN-0124) to examine the practicality of expanding pharmacy roles in treating OUD in underserved communities.

KTL helped to lead the nine-month engineering systems analysis, assessing the existing system, envisioning an ideal future state, identifying gaps, and highlighting improvement opportunities. The study, Delivering MOUD to the Underserved: How Can Pharmacies Really Helped?, was recently published in the October 15, 2024 edition of the Journal of Studies on Alcohol and Drugs.

18 Mar
Climate Change ISO Amendments
FAQs on ISO’s New Climate Change Amendments

Effective February 23, 2024, the International Organization for Standardization (ISO) is integrating climate change considerations into all management system standards through its Climate Change Amendments. These Amendments ensure climate change impacts are considered by all organizations in their management system design and implementation.

ISO’s recent action supports the London Declaration on Climate Change of September 2021, which establishes ISO’s commitment to combatting climate change through its standards and publications. The aim of the recent Amendments is to make climate change an integral part of management systems design and implementation to help guide organizational strategy and policy.

What are the changes?

The Climate Change Amendments explicitly require climate change considerations in all existing and future ISO management systems standards, as incorporated into the Harmonized Structure (Appendix 2 of the Annex SL in the ISO/IEC Directives Part 1 Consolidated ISO Supplement). More specifically, the Amendments add the following two new statements to Annex SL for organizations to consider the effects of climate change on the management system’s ability to achieve its intended results:

  • Clause 4.1: The organization shall determine whether climate change is a relevant issue, as it relates to understanding the organization and its context.
  • Clause 4.2: NOTE: Relevant interested parties can have requirements related to climate change, pertaining to understanding the needs and expectations of interested parties.

The broad scope of these Amendments (i.e., impacting all standards) reflects ISO’s commitment to integrating climate considerations across diverse operational areas (e.g., environment, quality, safety, food safety, security, business continuity, etc.).

What do these changes require?

The original intent and requirements of Clauses 4.1 and 4.2 remain unchanged; however, the Amendments now require organizations to consider the relevance of climate change risks and impacts on the management system(s).

Potential climate change issues will likely differ for the various standards. The Amendments ensure these various risks are considered for each standard and, if actions are required, allow the organization to effectively plan for them in the management system.

What do certified organizations need to do?

Organizations that are certified—or are planning for certification—need to make sure they consider climate change aspects and risks in the development, maintenance, and effectiveness of their management system(s).

The Amendments specifically require these organizations to evaluate and determine whether climate change is a relevant issue within their management system(s). If the answer is yes, the organization then must consider climate change in a risk evaluation within the scope of their management systems. Where relevant, organizations are further encouraged to integrate climate change into their strategic objectives and risk mitigation efforts. The Amendments do not require organizations to do anything about climate change beyond considering the impacts on the management system’s ability to achieve its intended results.

What is the timeline?

The Amendments are effective as of the date of publication. There is no transition for implementation.

Certification bodies and auditors will cover the Amendments in audit activities when assessing this section of a management system. The audit will ensure climate change is considered and, if determined to be a relevant issue, included in company objectives and risk mitigation efforts. If climate change is deemed not relevant, the audit will assess the organization’s process for making this determination.

Will new certifications be issued?

Because the changes are considered a clarification, ISO issued them in the form of an amendment. New standards will not be republished until new versions are released; therefore, the publication year of each ISO standard will not change, and no new certifications will be issued.

What are the benefits of these changes?

The Climate Change Amendments underscore the importance of understanding and addressing the impacts of climate change. By publishing the Amendments in Annex SL, ISO is leveraging the widespread adoption of all ISO management system standards across operational areas to integrate environmental stewardship into organizational practices, promote sustainability, and drive climate change action on a global scale.

For certified organizations, the Amendments are intended to enhance organizational resilience and adaptability to climate-related risks. Considering climate change in this way can significantly contribute to business sustainability and long-term success by:

  • Ensuring regulatory compliance (e.g., emission limits, sustainability reporting, etc.).
  • Creating positive brand reputation as a sustainable company and associated customer loyalty.
  • Managing risks and opportunities associated with supply chain disruptions, energy efficiency initiatives, employee health and safety, natural disasters, etc.
  • Engaging employees and attracting new talent who prioritizes sustainability.
  • Providing access to markets and investors that have sustainability requirements.
26 May
Integrated Emergency Response Plans

The most effective way to respond to an emergency is to properly plan for it before it happens. That’s precisely why so many federal, state, and municipal laws and regulations require many facilities to develop and implement some sort of Emergency Response Plan (ERP).

Effective Emergency Response

An ERP is intended to outline the steps an organization needs to take in an emergency—and after—to protect workers’ health and safety, the environment, the surrounding community, and the business itself. The requirements developed by various agencies are important, as they establish the components that must be included in an ERP to comply with regulations and respond effectively.

Most ERPs contain the same basic information. However, it can get complicated when a facility is subject to more than one regulation requiring an ERP, because even though the various regulations share many similarities, they also contain important differences (e.g., command structures, training requirements, equipment needs, operating protocols). Often, facilities end up creating a different ERP to respond to the different regulatory requirements. In an actual emergency, this can create inconsistencies or, worse yet, an implementation nightmare trying to figure out which ERP to follow.

Importance of Integration

The solution lies in integration. For example, consider an integrated management system that allows organizations to align standards, find common management system components (e.g., terminology, policies, objectives, processes, resources), and add measurable and recognizable business value. The same can be done with the various ERPs required within a facility.

It shouldn’t come as a surprise that in 1996, the U.S. National Response Team (NRT) published initial guidance for consolidating multiple ERPs into one core document. The Integrated Contingency Plan (ICP or One Plan) is a single, unified ERP intended to help organizations comply with the various emergency response requirements of the Environmental Protection Agency (EPA), U.S. Coast Guard, Occupational Safety and Health Administration (OSHA), Department of Transportation (DOT), and Department of Interior (DOI). The ICP Guidance does not change any of the existing requirements of the regulations it covers; rather, it provides a format for consolidating, organizing, and presenting the required emergency response information.

While the ICP does not currently incorporate all federal regulations addressing emergency response, it does establish a basic framework for organizations to pull in ERPs for any applicable regulations. And the benefits of doing so are many:

  • Streamlined planning process. A single document simplifies the planning, development, and maintenance process. When plans are integrated, it minimizes duplication of effort, eliminates discrepancies and inconsistencies, and helps the organization identify and fill in gaps.
  • Improved emergency response. It is much easier—and faster—for emergency responders and employees to navigate one plan rather than multiple separate ones. One plan allows for a single command structure with defined roles rather than potentially conflicting responsibilities. This all allows responders to act quickly and decisively to minimize potential disruption to the organization and public.
  • Greater compliance. An integrated ERP provides improved visibility to all parts of the organization’s emergency response and helps reveal gaps that could prove costly and/or dangerous. This is especially important for organizations that must comply with several regulations.
  • Potential cost savings. Streamlined and simplified planning reduces the resources required to build the plan. An integrated ERP may also help eliminate regulatory fines and minimize the need for and associated costs of emergency response/cleanup efforts.

Find Your Format

The goal of an integrated ERP is not to create new requirements but to consolidate existing concepts into a single functional plan structure. Regardless of what the plan looks like, it should start with:

  1. An assessment of the facility’s vulnerabilities to various emergency situations.
  2. An understanding of the various applicable emergency planning laws and regulations to determine which specific requirements must be incorporated. For example, food emergency response has different implications that must be integrated, particularly when it comes to recovery. A food production facility that is ordered or otherwise required to cease operations during an emergency may not reopen until authorization has been granted by the regulatory authority. Food facilities also have strict guidelines to follow for salvaging, reconditioning, and/or discarding product.

With this understanding, the ERP should then comprise step-by-step guidelines for addressing the most significant emergency situations. The core plan should be straightforward and concise and outline fundamental response procedures. More detailed information can be included in the annex. Most ERPs should include the following basic elements:

  • Facility information. Consolidate common elements required in various plans, including site description, statement of purpose, scope, drawings, maps, roster of emergency response personnel, emergency response equipment, key contacts for plan development and maintenance, etc.
  • Steps to initiate, conduct, and terminate a response. Outline essential response actions and notification procedures, with references to the annex for more detailed information. Provide concise and specific information that is time-critical in the earliest stages of the response and a framework to guide responders through key steps to deliver an effective response.
  • Designated emergency responders. Develop a single command structure for all types of emergencies. Assign qualified, high-level individuals who are familiar with emergency procedures to fill emergency roles. In addition, list the appropriate authorities for specific emergencies, as well as their contact information.
  • Evacuation plan/routes and rally points. Clearly mark evacuation routes and identify rally points where employees should meet upon exiting. Do not allow employees to leave designated rally points until it has been documented they have safely left the building.
  • Data and information backup technology. Develop provisions for data backup to secondary/off-site systems, as well as alternate options for communications and power.  
  • Designated plan for communication. Outline who is communicating what, when they are communicating it, and how it is being communicated. This includes internal communication, as well as communication to customers/clients/suppliers/vendors that may be impacted, the media, and the appropriate regulatory authorities.
  • Supporting materials. The annex should provide detailed support information based on the procedures outlined in the core plan and required regulatory compliance documentation. Importantly, facilities should create a table that cross-references individual regulatory requirements with the plan to ensure there are no gaps and to demonstrate compliance.

Ensuring Success

The goal of emergency response planning is to minimize impacts to the environment and workers’ health and safety, as well as disruptions to operations. An integrated ERP has the potential to significantly reduce the number of decisions required to respond in an emergency, eliminate confusion and disagreement regarding roles and responsibilities, and enable a timelier, more coordinated response.

That all being said, an integrated ERP will only be effective if it is thoroughly and consistently communicated to all employees. These best practices will help ensure that the integrated ERP functions not only on paper, but also in practice:

  • Periodic training is vital to ensure employees understand the ERP and are fully aware of emergency response procedures. It is especially important in an integrated ERP that first responders are trained to handle all potential emergencies rather than more narrowly trained on response for a single regulation.
  • Routine drills significantly improve understanding of the ERP, clarify employee roles, test procedures to ensure they work, and diminish confusion during an emergency.
  • Posting an abbreviated version of the ERP throughout the plant provides easy access to all employees if an emergency occurs. This summary version of the ERP should highlight the most vital information for quick response: recognized hazards, high-level emergency procedures, evacuation routes, and key contacts.

23 May
Benefits of an Integrated Management System

According to the International Organization for Standardization (ISO), are currently more than 80 Management System Standards (MSS)—80 different standards designed to help companies improve their performance across a diverse range of areas and sectors.

Most companies these days have some sort of management system, whether formal (e.g., ISO, Global Food Safety Initiative (GFSI)-benchmarked standard, industry-specific) or informal. And, because most companies have various aspects and functions to their operations, many actually may have more than one system to organize processes and business objectives.

While management systems by ISO’s definition are designed to “help organizations improve their performance by specifying repeatable steps that organizations consciously implement to achieve their goals and objectives,” having multiple systems to manage often overlapping requirements (i.e., regulatory, certification, supply chain, internal) can create redundancies, inefficiencies, extra work, and overall confusion.

Integrated Management Systems: The Basics

A management system is the organizing framework that enables companies to achieve and sustain their operational and business objectives through a process of continuous improvement (i.e., Plan-Do-Check-Act). It is designed to identify and manage risks through an organized set of policies, procedures, practices, and resources that guide the enterprise and its activities to maximize business value.

A management system should be a means to better align operational quality, safety, environment, food safety, security, energy, etc. with the business. An integrated management system does just this. It aligns an organization’s various systems and processes into one complete framework, enabling the organization to work as a single unit to implement specific best practices organization-wide, fulfill the requirements of multiple standards, and meet a unified set of business objectives.

Integration Business Benefits

Ultimately, the various MSS have many common points—and all work towards the goal of making the organization more effective and efficient. Developing an integrated management system allows organizations to align the standards, find common management system components (e.g., terminology, policies, objectives, processes, resources), and add measurable and recognizable business value, including the following:

Greater consistency. An integrated approach creates greater consistency across business facets when it comes to terminology, processes, procedures, expectations, etc., and, in turn, greatly improved focus on a common set of business objectives. With an integrated system, organizations can ensure that processes, methods, and practices are in place, documented, and consistently applied across the entire organization. A common documented framework such as this helps alleviate duplication of efforts, allows for a more complete view of the functional needs of the entire organization, and reduces variability in performance.

Optimized processes and resources. Integrated systems allow companies to optimize processes and resources and, subsequently, reduce the time it takes to do certain activities. Integrated management systems help organizations to maintain requirements and associated documents concurrently—particularly through use of an information system—streamlining the process and allowing the organization to focus on improvements rather than maintaining multiple systems. A common system enables better use of resources and better collaboration and communication across the company.

More strategic approach. Organizations can take a more strategic approach with an integrated management system because it focuses on managing all aspects of the business, not just one area. It provides clear methods and processes to identify and prioritize risks, set and monitor goals, communicate risks to employees and management, and allocate appropriate resources to mitigate them. It also establishes a common language among managers, executives, and employees, which enables better goal setting, priority ranking, and allocation of resources. As a bonus, integrated systems also make it much easier to implement an organization-wide information system capable of tracking and reporting on common activities and key performance metrics.

Forward-thinking. More and more organizations are expecting more from the companies they work with—and that includes management systems. The push for best practices over just regulatory compliance is a growing trend. Reliable and effective regulatory compliance is commonly an outcome of consistent implementation of a management system. Beyond that, an integrated management system allows organizations to more effectively manage those risks (i.e., compliance, financial, legal liability, brand reputation) that can significantly impact the entire supply chain.

Help from the Standards

Standards organizations such has ISO are making it as easy as possible to implement an integrated management system—whether formal or informal—because, plain and simple, it just makes business sense. For example, ISO has adopted a Harmonized Structure (formerly known as High-Level Structure) to make sure every ISO MSS is structured in the same way with ten universal sections. The ISO MSS also use Annex SL, which dictates how the MSS should be written and, again, is consistent across the various MSS. These efforts simplify use, streamline protocol, and encourage standardization across the ISO MSS.

Beyond that, ISO has published a Guide to Integrating Management System Standards (revised in 2018) to help organizations implement integrated management system design—ISO or not. According to Michael McLean, Convenor or the ISO working group that developed the handbook, “Many organizations benefit from multiple management systems to help them ensure their systems and processes are in line with their objectives and help them maintain their business model through ever-changing environments. This handbook provides a practical guide for organizations to effectively align their management systems with their strategies, plans, and operations.”

Taking the Next Steps

If you are operating with multiple management systems—or even if you have no management system at all—there are some basic steps to creating an integrated management system:

  1. Invest the time to understand the current scope of operations, functional departments, compliance requirements, governance structure, etc. across the entire organization as a whole, not just siloed departments.
  2. Conduct a gap assessment to evaluate the current (“as-is”) condition of any formal or informal management system(s) against the desired (“to-be”) condition (e.g., ISO, GFSI, industry-specific).
  3. Create a development and implementation plan outlining tasks and resources required to close any identified gaps and achieve those objectives.
    • Determine key components of the integrated management system required to achieve business objectives.
    • Identify common elements to be standardized and incorporated into an integrated system (e.g., policies, procedures, processes, metrics, training).
    • Determine what information technology can support and streamline an integrated management system.
  4. Provide relevant training to all interested parties to truly operationalize the management system across the organization.

Whether formal or informal, integrated management systems provide organizations—both big and small, in any industry—a pillar for sustainable growth. By developing and implementing an aligned management system, organizations can achieve more consistent, reliable, and efficient performance across many areas, while adding measurable and recognizable business value.

01 Dec
BioForward Member Blog: KTL Building Scalable Systems to Help Businesses

BioForward Wisconsin closely follows news stories about its members and invites them to contribute blogs and profiles to inform and advance the Wisconsin biohealth community. Read the recent BioForward Wisconsin member blog on KTL’s scalable systems for helping companies manage compliance business processes more efficiently and effectively.

19 Apr
Webinar: Challenges of EHS Compliance in the U.S.

Current Challenges of Technical Compliance in the U.S.:
Focus on Occupational Health & Safety and Environment
May 17, 2021 | 4 pm – 5 pm CT

Technical compliance regarding EHS has seen tremendous changes over the last couple of years and is likely to change even more in the foreseeable future. EHS regulatory enforcement will undoubtedly regain momentum in the next few years. Achieving and maintaining EHS compliance requires great management and expertise to ensure all aspects of a company’s technical compliance have been identified and are being actively managed.

KTL’s Sarah Burton will be joining Martin Mantz Compliance Solutions, our German alliance partner, to discuss the challenges of technical EHS compliance and to provide an up-to-date understanding of technical compliance in the U.S. today.

19 Apr
Demonstrating Compliance in a Socially Distanced World

Don’t miss this free American Bar Association event on April 22, 2021 — Demonstrating Compliance in a Socially Distanced World: Virtual Auditing.

In the time of COVID-19, virtual auditing has become increasingly necessary and valuable to organizations as they seek to achieve environmental compliance while facing worldwide travel restrictions and remote work policies that have disrupted routine in-person audits. With this shift, comes the need for both regulated entities and regulators to develop new approaches and procedures to ensure the effectiveness of audits conducted remotely. Practitioners, including auditors and legal counsel, must consider new dynamics related to security, data protection, and audit integrity-on top of the usual audit considerations. This session will highlight some of these new challenges and provide real-world solutions to aid attendees form new practice skills to apply in the (virtual) field.

Panelists–including KTL’s Sarah Burton–will explore the new world of remote auditing, focusing on real-world solutions to the challenges that virtual auditing presents.

Register online.

Sidebar: