ISO 55001:2014 – ISO 55001:2024 – Revised
| 8.1 Operational planning and control including life cycle management |
| 8.1 |
The organisation shall plan…
establishing criteria for the…
implementing the control of…
keeping documented information to…
treating and monitoring risks….
|
| Note |
Organisations need to have evidence of a range of processes in place. From a(n):
- risk management perspective, organisations need to be able to demonstrate the risk management processes and tools exist and that they are being applied appropriately and consistently. This includes:
providing the agreed enterprise approach to risk management from both a process and tolerable level of risk perspective; and
a formal risk register that is updated and applied as both part of ‘business as usual’ and as part of the planning cycle for specific events/projects;
- asset management perspective, objective setting is done in a structured way with reference to stakeholder The process is performed and requirements are gathered from stakeholders and formally agreed to, and there is a clear linkage between the organisation’s objectives and the asset management objectives. The outcomes of this objective setting should be evident in the organisation’s financial management plans;
- nonconformity and corrective action perspective, there are tools and systems accessible by all relevant parties that support the identification of nonconformities and a defined nonconformance identification process. The process ensures that all nonconformities are reviewed and assessed against the enterprise risk criteria and that actions are set accordingly; and
- preventive action perspective, appropriate measures and the measurement frequencies have been established to identify potential failures and have sufficient time to react. These measures should be being reviewed with sufficient frequency to ensure corrective action can be implemented in a timely
2024 Now addresses life cycle processes (creation, acquisition, utilization, maintenance, improvement, renewal, and disposal of assets). It also incorporates managing risks and implementing opportunities as identified in 6.1 as essential parts of operational planning and control. Additionally, a requirement for documented information is introduced.
|
| Evidence Example |
Examples of the processes needed to meet these requirements include:
|
| ISO Artefact |
No artefact is specified
|