10
USING ISO CERTIFICATION AS A FRAMEWORK to Ensure Global Quality

M3University Using ISO Certification€¦ · ISO and GDPR M3 Global Research’s ISO certification helped greatly with preparing for the General Data Protection Regulation (GDPR)

  • Upload
    others

  • View
    2

  • Download
    0

Embed Size (px)

Citation preview

Page 1: M3University Using ISO Certification€¦ · ISO and GDPR M3 Global Research’s ISO certification helped greatly with preparing for the General Data Protection Regulation (GDPR)

USING ISO CERTIFICATION AS A FRAMEWORKto Ensure Global Quality

Page 2: M3University Using ISO Certification€¦ · ISO and GDPR M3 Global Research’s ISO certification helped greatly with preparing for the General Data Protection Regulation (GDPR)

CERTIFIED QUALITY

Compliance, in a nutshell, is following the rules. There are quite a few diff erent types of rules that businesses like M3 Global Research must follow. There are laws, such as data protection laws, and guidelines, like the EphMRA Code of Conduct. You will also have your own company rules and policies that you need to follow. Oft en, what you fi nd is that many of these rules and guidelines are designed to ensure quality, or that quality becomes a byproduct of those rules and guidelines. Either way, quality ends up going hand-in-hand with compliance. Obtaining quality without compliance would be quite a challenge.

2

Page 3: M3University Using ISO Certification€¦ · ISO and GDPR M3 Global Research’s ISO certification helped greatly with preparing for the General Data Protection Regulation (GDPR)

3www.M3GlobalResearch.com • © 2019 M3 USA Corporation. All rights reserved. • Last updated on 21 June 2019

Compliance

At M3 Global Research, ensuring compliance on a global level is at the heart of everything we do, which can be seen here:

North America Compliance

� First ISO 26362 Certifi ed by CIRQ� US Sunshine Act� Canadian Anti-Spam Law (CASL)� EU-US Privacy Shield� US IRS Income Reporting Law � US HIPAA Law � Physician Verifi cation � Bank Teller Verifi cation � IA Professional Researcher Certifi cation

Asia Compliance

� Japan Privacy Mark� Japan PII � China Data Collection License � China Internet Survey License� China PII � South Korea PII � Physician Verifi cation

Global Compliance

� Model Clauses � Patented Survey Router � Triple Verifi cation � Post-survey Duplicate Check � Zero Cost Data Cleaning � Russian Federal Law on Personal Data

Europe Compliance

� First ISO 26362 Certifi ed by CIRQ � Registered with the European Data

Protection Authority (DPA)� EphMRA Code of Ethics� BHBIA Adverse Events Training� French Loi Bertrand and Loi Anti-

Cadeaux (Sunshine Act)� General Data Privacy Regulation (GDPR) � Physician Verifi cation

First physician panel to be ISO26362 certifi ed by CIRQ (Certifi cation Institute of Research Quality)First US market research company ISO27001 certifi ed

M3 Audits and Quality Standards Certifi cations M3 is a Proud Member and Supporter of

Page 4: M3University Using ISO Certification€¦ · ISO and GDPR M3 Global Research’s ISO certification helped greatly with preparing for the General Data Protection Regulation (GDPR)

4

WHY ARE WE TALKING ABOUT THIS?

Why did M3 Global Research get ISO certified?

Quality:

� International Recognition

� Global Management

� Risk Mitigation

� Increased Revenue

� Increased Efficiency

� Employee Morale and Training

� Supplier Relationships and Control

AN UNDERSTANDING OF WHAT ISO 26362 ENTAILS

This certification provides a framework to ensure quality. Having this framework in place has helped M3 Global Research adapt to new challenges over the years since becoming certified. There are many benefits to this certification, one being that there’s a solid focus to confidently and transparently answer any queries about our processes and secondly, to empower our employees to deliver certified quality to our clients. This also translates to any partners we work with. This certification allows M3 to manage expectations while maintaining flexibility.

Page 5: M3University Using ISO Certification€¦ · ISO and GDPR M3 Global Research’s ISO certification helped greatly with preparing for the General Data Protection Regulation (GDPR)

5www.M3GlobalResearch.com • © 2019 M3 USA Corporation. All rights reserved. • Last updated on 21 June 2019

Purchase and review standard(s)

Receive and review Certification Report

Allow 3 months to run these processes

Get audited by CIRQ or another

certification body annually

Conduct internal audit to ensure

compliance

Appoint quality manager or team

If any concerns or improvements noted in the report, work on

implementing solutions

Train employees

Conduct annual training sessions

Complete self-assessment

questionnaire, submit to CIRQ or another certification body

Document all current processes followed

and compare to requirements of

standard(s)

Review processes and conduct frequent

internal audits

Develop quality manual

Identify gaps if any and implement

solutions

Get certified

Identify gaps

Review existing processes, develop

new processes to close out the gaps

Steps to Achieving ISO Certification

This is an overview of the process M3 Global Research went through to become ISO 26362 certified.

Steps after Achieving ISO Certification

Page 6: M3University Using ISO Certification€¦ · ISO and GDPR M3 Global Research’s ISO certification helped greatly with preparing for the General Data Protection Regulation (GDPR)

6

HOW M3 GLOBAL RESEARCH ENSURES QUALITY FOR ITS CLIENTS

Panel Recruitment and Management

M3’s ISO certification has quite an impact on how the company manages its panel.

� All members:

• Recruited from documented source

• Provide appropriate information for initial confirmation of identity

• Give explicit consent to participate in research surveys according to the terms and conditions of panel membership agreement

M3 has a proprietary data system where all of these points are tracked and have safeguards in place that prevent the company from inviting anyone to participate in research who does not fit the verification criteria in place.

� Engagement: To qualify to participate in research with M3, members must be active and have engaged in a two-way interaction with M3 within the past 365 days. This improves quality because more engaged panelists provide better responses. M3 invests in a large panel team to ensure that panelists are active and engaged through several different methods:

• Pulse mini surveys, of which we share the results with panel members

• Blog

• Member updates

� Reprofiling

� Reactivation

C L E A R B E N E F I T

� Confidence in responses, and full transparency

� Avoidance of fatigue as benefit of engaging all members

Page 7: M3University Using ISO Certification€¦ · ISO and GDPR M3 Global Research’s ISO certification helped greatly with preparing for the General Data Protection Regulation (GDPR)

7www.M3GlobalResearch.com • © 2019 M3 USA Corporation. All rights reserved. • Last updated on 21 June 2019

Project Management

M3 clearly documents its standard operating processes and procedures and adheres to them across our global offices. It’s important to note that these procedures often need to evolve, to stay current with new technology, new requirements, etc. M3 has the flexibility to improve processes as needed.

� Pre-field

� In-field

� Post-field

� Standard operating procedures

• Covering all PM aspects

Data Collection and Quality Control

� All deliverables are quality checked

• Number-checking

• Format-checking

• Proofreading

• Fact-checking

� Once all deliverables have passed quality control, the documents are delivered in accordance with project requirements

C L E A R B E N E F I T

C L E A R B E N E F I T

Clients can work with any PM in a global company and expect the same service level & experience

Having a quality first approach allows you to pause and take the sufficient amount of time needed – quality should never be an afterthought

Page 8: M3University Using ISO Certification€¦ · ISO and GDPR M3 Global Research’s ISO certification helped greatly with preparing for the General Data Protection Regulation (GDPR)

8

Working with Partners

ISO influences how M3 Global Research works with partners. Partners are fully vetted and only used when there is complete confidence in their procedures and capability to meet M3’s quality standards.

� M3 Global Research retains overall responsibility for all services carried out in connection with the project whether they are outsourced/subcontracted

� M3 Global Research has precisely defined procedures for selecting subcontractors, establishing contractual relations, and controlling the quality of the services provided

� All subcontractors are evaluated on a project by project basis and M3’s procurement team evaluates this and performs regular partner audits

� All sample runs through our own de-duplication and fraud protection checks

IT and Data Security

� Fixed standards and regular trainings, including refresher courses

� Documentation of on-boarding process for all new staff, with a clear training plan

� Continuous control, review, and investment

� Commitment to security for all sides (members and clients)

ISO and GDPR

M3 Global Research’s ISO certification helped greatly with preparing for the General Data Protection Regulation (GDPR).

� GDPR requires documentation – already in place

� Panel engagement builds trust with panelists

C L E A R B E N E F I T

C L E A R B E N E F I T

C L E A R B E N E F I T

Responsibility lies with M3 and having clearly defined standards and procedures avoids “knee jerk” reactions

Focusing on the importance of IT, validating investments in these areas

Documentation and security were already thought about and built in – meaning they didn’t have to be created for GDPR purposes

Page 9: M3University Using ISO Certification€¦ · ISO and GDPR M3 Global Research’s ISO certification helped greatly with preparing for the General Data Protection Regulation (GDPR)

9www.M3GlobalResearch.com • © 2019 M3 USA Corporation. All rights reserved. • Last updated on 21 June 2019

ISO 20252

2019 Market, opinion and social research, including insights and data analytics

� In February 2019, Insights Association (CIRQ as subsidiary) announced a new ISO Standard – ISO 20252: 2019

� It replaces the older ISO 20252 and ISO 26362 standards

• Includes improved relevance to current market research stakeholder needs

• Eliminated duplicative clauses and subclauses from 26362 and the previous version of 20252

• Reflects new data practices, ethical requirements, and data management security that align with the EU’s GDPR

� M3 Global Research will be audited in April 2020 against the Clause 4 Core Requirements for Market, opinion and social research and at least one of the following 6 Annexes:

• Annex A – Sampling including access panels

• Annex B – Fieldwork

• Annex C – Physical Observation

• Annex D – Digital Observation

• Annex E – Self-completion

• Annex F – Data Management

� December 2020 to transition to and audit under the new standard

CONCLUSION

The best things about certification:

� Standardized processes and uniform consistency across all M3 Global Research offices

� Internal and external audits to ensure processes are working as intended and provide the opportunity to adjust and make improvements

Page 10: M3University Using ISO Certification€¦ · ISO and GDPR M3 Global Research’s ISO certification helped greatly with preparing for the General Data Protection Regulation (GDPR)

www.M3GlobalResearch.com

© 2019 M3 USA Corporation. All rights reserved.