CPQ™ Quality Management System
The management umbrella connecting standards, credentialing and education while controlling audit, review and continual improvement.
1. Purpose & Basis
This document is presented as proposed CPQ™ policy for external review, extending the founding standards pack and drafted to align the CPQ™ ecosystem with ISO/IEC 17024 principles for bodies certifying persons. Any new procedural or numeric requirement remains Draft and does not become binding within CPQ until changed to Active through a documented governance decision; it is not a claim of accreditation or recognition by another body.
ISO/IEC 17024 expects a certification body to operate within a documented management system controlling documents and records, conducting internal audit and management review, addressing nonconformities through corrective action and supporting continual improvement. This document connects CPQ™ standards, credentialing, education and governance policies under one auditable management umbrella.
2. Quality Management System Elements
| Element | Reference requirement | Required evidence | Responsible function |
|---|---|---|---|
| Document control | Coding, issue, approval and review | CPQ-POLREG version registry | Standards & Ethics Committee |
| Records control | Retention, protection and retention periods | CPQ-DATA policy | Finance/Operations |
| Internal audit | Independent annual programme | Audit reports and minutes | Appointed internal auditor |
| Management review | Documented periodic review | Management review minutes | CEO and committees |
| Nonconformity | Root-cause analysis and corrective action | Nonconformity register | Process owner |
| Risks and opportunities | Periodic analysis and controls | Risk register | Governance Committee |
| Continual improvement | Performance indicators and initiatives | Annual improvement report | CEO |
3. Document & Record Control
Every normative document has a stable code, known status, identified owner and review date under CPQ-POLREG. Material published documents are not silently replaced; prior versions are retained. Personal and sensitive records are managed under CPQ-DATA, including retention periods, access permissions and secure deletion.
4. Internal Audit
- An annual internal-audit programme covers credentialing, assessment, education and governance operations.
- Auditors are independent from the work they audit.
- Findings are documented as conforming, observation or nonconformity, with nonconformities routed to corrective action.
- An audit summary is submitted to management review.
5. Management Review
Senior management and relevant committees conduct documented management review at least annually, considering audit results, complaints and appeals, assessor calibration, nonconformities, stakeholder feedback and emerging risks, and issuing documented improvement decisions.
6. Nonconformity & Corrective Action
- Describe the nonconformity and impact.
- Contain the effect where needed.
- Analyse root cause.
- Assign corrective action, owner and deadline.
- Verify effectiveness and close with evidence.
7. Risk Management & Continual Improvement
CPQ™ maintains a risk register covering threats to credential quality, impartiality and continuity, with proportionate controls and periodic review. Improvement indicators include application-cycle time, successful-appeal rate, assessor consistency and stakeholder satisfaction.
