ISO 55001:2014 – ISO 55001:2024 – Revised

8.1 Operational planning and control including life cycle management
8.1

The organisation shall plan…

establishing criteria for the…

implementing the control of…

keeping documented information to…

treating and monitoring risks….

Note

Organisations need to have evidence of a range of processes in place. From a(n):

  • risk management perspective, organisations need to be able to demonstrate the risk management processes and tools exist and that they are being applied appropriately and consistently. This includes:

providing the agreed enterprise approach to risk management from both a process and tolerable level of risk perspective; and

a formal risk register that is updated and applied as both part of ‘business as usual’ and as part of the planning cycle for specific events/projects;

  • asset management perspective, objective setting is done in a structured way with reference to stakeholder The process is performed and requirements are gathered from stakeholders and formally agreed to, and there is a clear linkage between the organisation’s objectives and the asset management objectives. The outcomes of this objective setting should be evident in the organisation’s financial management plans;
  • nonconformity and corrective action perspective, there are tools and systems accessible by all relevant parties that support the identification of nonconformities and a defined nonconformance identification process. The process ensures that all nonconformities are reviewed and assessed against the enterprise risk criteria and that actions are set accordingly; and
  • preventive action perspective, appropriate measures and the measurement frequencies have been established to identify potential failures and have sufficient time to react. These measures should be being reviewed with sufficient frequency to ensure corrective action can be implemented in a timely

2024 Now addresses life cycle processes (creation, acquisition, utilization, maintenance, improvement, renewal, and disposal of assets). It also incorporates managing risks and implementing opportunities as identified in 6.1 as essential parts of operational planning and control. Additionally, a requirement for documented information is introduced.

Evidence Example

Examples of the processes needed to meet these requirements include:

  • a corporately accepted risk management approach which reflects the organisation’s tolerance for risk across a range of risk categories;
  • demonstrable evidence of cases where outcomes of the application of the risk process has necessitated changes in the asset management system e.g. a highly undesirable situation was identified through the risk management process and an asset management plan was subsequently modified;
  • examples of where the development of an asset management plan has translated into another aspect of the business management system, such as a budget;
  • examples of where the application of a nonconformance

    identification process has necessitated changes in the asset management system. This may include where a systemic issue was identified by expanding the scope of an ad-hoc investigation resulting from a nonconformance;

    • an online nonconformance identification tool through which all relevant employees can raise a nonconformance exists and is utilised by employees; and
    • the business performance measurement and technical performance measurement measures report and meetings are run, actions identified and minutes taken and actioned.
    Or similar.
ISO Artefact

No artefact is specified