AS9100D:2016 Aerospace Audit Checklist
Objective Evidence
- Documented context analysis that identifies aerospace-specific external issues — airworthiness authority regulations (FAA, EASA, TCCA, ANAC), prime contractor requirements, export control obligations (ITAR/EAR), and industry standards beyond AS9100D
- Internal issue assessment addressing workforce competency for safety-critical work, facility capabilities for controlled environments, and capacity constraints affecting on-time delivery
- Evidence that context analysis is reviewed and updated — look for revision history or management review inputs that reference changes in regulatory landscape or customer base
Common Nonconformities
- Context analysis is a generic template that does not reference any aerospace-specific regulatory authorities, customer flow-down requirements, or export control obligations — the same document could apply to any manufacturing company (Minor NC).
- Organization holds multiple customer approvals (Boeing D1-4426, Airbus AQSF) but these are not identified as relevant external issues that affect QMS requirements (Observation).
- No evidence that the context analysis has been reviewed since initial certification — the document references organizational structures and customer relationships that no longer exist (Minor NC).
Auditor Tips
In aerospace, the context is uniquely complex. The organization must demonstrate awareness of the regulatory hierarchy — AS9100D certification body, airworthiness authority (FAA/EASA), prime contractor quality requirements, and end-customer operational requirements. Ask which airworthiness authorities have jurisdiction over their products. If they cannot answer, the context analysis is likely superficial. Check whether ITAR/EAR applicability has been assessed — many aerospace suppliers handle controlled technical data without realizing it.
Follow-Up Questions
- Which airworthiness authorities have jurisdiction over the products you manufacture, and how do their requirements flow into your QMS?
- Have you assessed your obligations under ITAR or EAR, and where is that assessment documented?
- What changes in your customer base or regulatory environment have you identified in the last 12 months?
What to Sample
Review the context analysis document. Cross-reference against the organization's actual customer list and applicable regulatory registrations. Verify that at least the top 3 customers' specific quality requirements are identified.
Objective Evidence
- Interested party register that includes aerospace-specific stakeholders — airworthiness authorities (FAA, EASA), accreditation bodies (ANAB, UKAS), prime contractors with approved supplier list requirements, Nadcap Management Council (if special processes are performed), and applicable government/military procurement agencies
- Documented requirements and expectations for each interested party — not just listed but with specific obligations identified (e.g., Boeing D1-4426 quality clauses, Airbus AQSF requirements)
- Evidence of monitoring changes in interested party requirements — such as updated customer quality manuals, revised airworthiness directives, or new regulatory guidance
Common Nonconformities
- Interested party analysis lists 'customers' and 'regulators' generically without identifying specific aerospace primes, airworthiness authorities, or their distinct requirements — the analysis lacks actionable specificity (Minor NC).
- Organization supplies to military programs but has not identified the Defense Contract Management Agency (DCMA) or equivalent national defense quality authority as an interested party (Minor NC).
- No process exists to monitor when interested parties update their requirements — the organization was unaware that a major customer revised their quality clauses 6 months ago (Observation).
Auditor Tips
Aerospace interested parties are not abstract — they have specific, documented requirements that the organization must comply with. Ask to see actual customer quality requirement documents (Boeing D1-4426, Airbus AQSF, Lockheed Martin CorpDocs, etc.) and verify the organization has current versions. Check whether Nadcap is identified if special processes are performed. For defense suppliers, verify government quality assurance agencies are identified.
Follow-Up Questions
- Can you show me the current versions of your top three customers' quality requirement documents?
- How do you learn when an interested party — such as a prime contractor or regulatory body — changes their requirements?
- Have any interested party requirements changed in the past year, and how did you respond?
What to Sample
Select 2 prime contractor customers from the approved customer list. Verify the organization has current copies of their quality requirement documents and can demonstrate how those requirements are addressed in the QMS.
Objective Evidence
- QMS process map or turtle diagram set showing all processes with named process owners who have defined authority and accountability — verify process owners can articulate their responsibilities when interviewed
- Matrix mapping customer and regulatory requirements to specific QMS processes — verify coverage of aerospace-specific requirements (product safety, configuration management, counterfeit prevention, FAI, special processes)
- Evidence that process interactions account for aerospace-unique workflows — such as the link between design change control and configuration management, or between receiving inspection and counterfeit prevention
- Management review records showing QMS process performance is evaluated including aerospace-specific metrics (OTD, quality escapes, customer scorecards)
Common Nonconformities
- QMS process map does not include aerospace-specific processes required by AS9100D — configuration management, counterfeit parts prevention, and operational risk management are absent from the process landscape (Major NC).
- Process owners are named but cannot describe their authority over the process or the metrics by which process performance is measured — ownership is nominal rather than functional (Minor NC).
- Process interactions do not reflect the actual flow of work — the documented sequence shows design output feeding directly to production, with no configuration management, FAI, or production planning process between them (Minor NC).
Auditor Tips
AS9100D requires process owners to be identified — this is an addition to ISO 9001. Interview at least two process owners and ask them to explain their process inputs, outputs, controls, and performance metrics. If a process owner cannot describe these without referring to documentation, the process ownership is likely ceremonial. Check that aerospace-specific processes (8.1.1 through 8.1.4) appear on the process map — organizations that upgraded from ISO 9001 frequently omit these.
Follow-Up Questions
- Who is the process owner for configuration management, and what authority do they have to stop production if a configuration discrepancy is found?
- How do you ensure that changes to one process — such as a supplier change — trigger reviews of dependent processes?
- Walk me through how a customer-initiated engineering change flows through your QMS processes from receipt to implementation.
What to Sample
Interview 2 process owners. Ask each to explain their process boundaries, inputs, outputs, risks, and current performance. Cross-reference their answers against the documented process descriptions.
Objective Evidence
- QMS scope statement identifying all products, product types, and sites included within the scope of the AS9100D certificate
- Documented justification for any excluded requirements (e.g., clause 8.3 Design excluded for build-to-print operations) — verify the justification is valid and that the excluded requirements genuinely do not apply
- Verification that the scope aligns with the actual work performed — the scope should not be broader than the organization's actual capabilities or narrower than its actual product range
Common Nonconformities
- QMS scope excludes design and development (clause 8.3) but the organization performs tooling design and process development activities that constitute design (Minor NC).
- QMS scope references only one facility but production also occurs at a secondary site that is not included in the scope or certificate (Major NC).
- No documented justification exists for excluding clause 8.3 — the exclusion is stated but the rationale is not documented (Minor NC).
Auditor Tips
Check the scope against reality. Walk the facility and verify that all activities and product types are represented in the scope. Common issues include: organizations performing design activities while excluding 8.3, secondary production sites not covered, and scopes that are too vague to be meaningful. Also verify that any customer-required processes (e.g., design authority for repairs, engineering support) are within scope if the organization performs them.
Follow-Up Questions
- Are there any products, processes, or sites that are not included in your QMS scope? If so, why?
- Do you perform any design, engineering, or product development activities? How are these addressed in your scope?
- Has your scope changed since your last certification audit, and what triggered the change?
What to Sample
Compare the QMS scope statement to the organization's actual product range and site locations. Verify any exclusions have documented justification.
Objective Evidence
- Documented product safety process or procedure that defines how safety requirements are identified, controlled, and verified throughout the product lifecycle — not just a policy statement but an operational process with roles, triggers, and records
- Organization chart or responsibility matrix showing who has authority and accountability for product safety decisions — verify this person has direct access to top management
- Records of product safety reviews or safety risk assessments conducted for current products — at minimum for products with safety-critical characteristics
- Evidence that top management is informed of product safety issues — management review minutes, safety review meeting records, or escalation records
Common Nonconformities
- Product safety is addressed only in the quality policy as a general statement — no operational process exists for identifying, documenting, or controlling product safety requirements (Major NC).
- Product safety accountability is assigned to a junior quality engineer with no authority to stop shipment or escalate to top management — the accountability structure does not match the criticality (Minor NC).
- Organization manufactures flight-critical structural components but has not conducted any product safety risk assessment — safety requirements are assumed to be covered by customer drawings without independent analysis (Major NC).
Auditor Tips
This is one of the most important AS9100D additions. Product safety is not the same as product quality — a part can meet all dimensional requirements but still have a safety concern (e.g., material substitution, process deviation). Ask top management directly: 'What is your role in product safety?' and 'Give me an example of a product safety issue that was escalated to you.' If they cannot provide an example, probe whether the escalation mechanism has ever been tested. Look for evidence that safety requirements flow from customer requirements or airworthiness regulations into design and production controls.
Follow-Up Questions
- Can you give me a specific example of a product safety concern that was identified and how it was resolved?
- Who in this organization has the authority to stop a shipment based on a product safety concern, and has that authority ever been exercised?
- How are product safety requirements communicated to production floor personnel?
What to Sample
Select a safety-critical product. Trace product safety requirements from customer/regulatory input through design, production, and final inspection. Verify that safety requirements are explicitly identified and controlled at each stage.
Objective Evidence
- Documented policy on reporting quality and safety concerns — verify it explicitly states protection from reprisal and is communicated to all employees (posted, included in onboarding, referenced in training)
- Reporting mechanism available to all personnel — anonymous hotline, suggestion system, direct reporting chain, or equivalent — verify it is accessible and known to employees
- Records of concerns reported through the mechanism in the past 12 months — if zero reports exist, this may indicate the mechanism is not trusted or not promoted
- Evidence of management response to reported concerns — closed-loop follow-up showing that reports were investigated and outcomes communicated back to the reporter
Common Nonconformities
- No documented policy or procedure exists for reporting quality and safety concerns — employees are expected to report through their supervisor, but no alternative channel exists if the supervisor is the source of the concern (Major NC).
- A reporting policy exists but no reports have been received in the past 2 years across 200+ employees — this suggests the mechanism is either unknown, inaccessible, or not trusted (Observation).
- Reports have been submitted but there is no evidence of investigation or follow-up — the reporting mechanism functions as a suggestion box with no closed-loop response process (Minor NC).
Auditor Tips
This requirement is about culture, not just documentation. Interview 3-4 floor-level employees separately and ask: 'If you saw a quality problem, how would you report it? Have you ever reported one? What happened?' If employees hesitate, cannot describe the process, or express doubt about management response, the mechanism is not effective regardless of what the documentation says. Also ask whether anyone has ever stopped production or refused to ship based on a quality concern — and whether there were consequences for doing so.
Follow-Up Questions
- If an operator on the shop floor noticed a part that looked wrong but had been approved by inspection, what would they do?
- Has anyone in this organization ever raised a safety concern that resulted in a stop-ship or production halt? What happened to that person?
- How do you communicate back to employees what happened with their reported concern?
What to Sample
Interview 3 shop floor personnel individually. Ask each how they would report a quality or safety concern, whether they have ever done so, and whether they believe management would support them. Compare answers against the documented process.
Objective Evidence
- On-time delivery (OTD) metric tracked at the organizational level — verify the metric definition (on-time to customer request date vs. on-time to promise date), calculation method, and data source
- OTD trend data for the past 12 months showing target vs. actual performance — verify the data is current and reviewed regularly
- Evidence of action taken when OTD targets are missed — corrective actions, capacity adjustments, expediting plans, or customer communication records
- Management review records showing OTD performance is discussed as an input — verify top management is aware of delivery performance trends
Common Nonconformities
- On-time delivery is tracked only as a percentage without distinguishing between on-time to customer request date and on-time to the organization's own promise date — the metric may mask late deliveries that were 'resolved' by negotiating a later date with the customer (Minor NC).
- OTD performance has been below the target for 6 consecutive months but no corrective action or improvement plan has been initiated — performance is reported but not acted upon (Minor NC).
- OTD data is not presented to top management in management review — delivery performance is managed by operations without leadership visibility (Observation).
Auditor Tips
AS9100D specifically requires on-time delivery monitoring — this goes beyond ISO 9001's general customer satisfaction requirement. Verify how OTD is measured. The most meaningful metric is on-time to the customer's original requested date, not to a renegotiated promise date. Ask to see the actual delivery performance data in the ERP system and compare it to what is reported in management review. Discrepancies may indicate the metric is being 'managed' rather than measured. Also check whether late deliveries trigger any root cause analysis.
Follow-Up Questions
- When a delivery is late, what is the process for determining why and preventing recurrence?
- Do you track on-time delivery to the customer's original request date or to your committed ship date?
- What was your OTD performance last quarter, and what are the top three causes of late delivery?
What to Sample
Pull 10 recent shipments from the ERP system. For each, compare the customer's original requested delivery date to the actual ship date. Calculate the true OTD rate and compare against the reported metric.
Objective Evidence
- Organization chart and job descriptions showing designated personnel with authority to make disposition decisions on nonconforming product — verify this authority is documented and understood
- Evidence that stop-ship or production-halt authority has been communicated to relevant personnel — training records, posted authorities, or quality system procedure references
- Records of any instance where stop-ship authority was exercised — if never exercised, verify through interviews that personnel understand they have this authority and would use it
- Quality assurance independence — verify that QA personnel report through a quality chain, not through production management who may have schedule pressure conflicts
Common Nonconformities
- Quality assurance function reports to the production manager — the organizational structure creates a conflict of interest where the person responsible for schedule also controls the resources that could stop shipment (Major NC in some CB interpretations, Observation in others).
- No individual has documented authority to stop shipment — disposition authority is vested in a Material Review Board that meets weekly, creating a gap where nonconforming product could ship before the next MRB meeting (Minor NC).
- Stop-ship authority exists on paper but production personnel interviewed are unaware of it or express doubt that it would be supported by management (Observation).
Auditor Tips
AS9100D explicitly requires authority for personnel to stop processes to address quality issues. This is not just about having a procedure — it is about having real, exercisable authority. Interview the person with stop-ship authority and ask for the last time they used it. If they have never used it in years of production, explore why. Either the authority is effective as a deterrent (good) or it is symbolic and would not actually be exercised under schedule pressure (bad). Also verify QA independence — QA personnel who report to production managers face inherent conflicts.
Follow-Up Questions
- Who has the authority to stop a shipment, and what would happen to them professionally if they exercised that authority on a critical delivery?
- Does your QA manager report to the plant/operations manager or to a separate quality chain?
- Describe the last time production was stopped for a quality reason — who made the call and how did management respond?
What to Sample
Review the organization chart to verify QA reporting structure. Interview the QA manager and 1 production supervisor about stop-ship authority and its practical exercise.
Objective Evidence
- Risk and opportunity register that includes aerospace-specific risks: airworthiness compliance, product safety, customer-specific requirements changes, regulatory authority findings, supply chain single-source dependencies, and technology obsolescence
- Planned actions for identified risks — verify each significant risk has a defined action, responsible owner, and timeline
- Evidence that actions have been implemented and evaluated for effectiveness — verify at least 3 risk mitigation actions have been carried out with documented results
- Proportionality assessment — verify that higher-impact risks (product safety, airworthiness) receive more robust mitigation than lower-impact risks
Common Nonconformities
- Risk register is a static document created during initial certification that has not been updated — new customer programs, supplier changes, and regulatory updates in the past 2 years are not reflected (Minor NC).
- Risks are identified but no actions are planned — the register lists 15 risks but only 3 have defined mitigation actions (Minor NC).
- Risk assessment does not distinguish between product safety risks and operational efficiency risks — all risks are assessed on the same scale without weighting for safety consequences (Observation).
Auditor Tips
The clause 6.1 risk assessment is the strategic-level complement to clause 8.1.1 operational risk management. Verify the organization understands the difference. If the risk register looks like it could belong to any manufacturing company without modification, it likely does not adequately address the aerospace context.
Follow-Up Questions
- What are your top 3 strategic risks to delivering conforming products, and what are you doing about them?
- How do you differentiate the response between a risk that could affect product safety versus a risk that could affect administrative efficiency?
- When was the last time you added a new risk to this register, and what triggered it?
What to Sample
Review the risk register. Verify aerospace-specific risks are included. Select 3 risks and verify: actions are defined, implemented, and evaluated for effectiveness.
Objective Evidence
- Quality objectives document or matrix — verify objectives are specific, measurable, achievable, relevant, and time-bound (SMART), not just aspirational statements
- Objectives include aerospace-specific metrics — on-time delivery target, product conformity target (scrap rate, FPY, customer rejection PPM), customer satisfaction target
- Evidence of monitoring progress against objectives — verify objectives are tracked at defined intervals with actual vs. target data
- Action plans for objectives that are not being met — verify that when an objective is behind target, specific improvement actions are defined
Common Nonconformities
- Quality objectives are not measurable — 'improve on-time delivery' is stated but no specific target percentage, baseline, or timeline is defined (Minor NC).
- No quality objective addresses on-time delivery — product quality objectives exist but delivery performance is not covered (Minor NC).
- Quality objectives are tracked but no action is taken when targets are missed — OTD has been below the 95% target for 6 consecutive months with no improvement plan (Minor NC).
Auditor Tips
Quality objectives in aerospace should reflect the metrics that matter to customers and regulators: OTD, product conformity, and customer satisfaction. Verify objectives are truly measurable with specific numeric targets.
Follow-Up Questions
- Which quality objectives are you currently behind on, and what actions are you taking?
- How did you establish the target values for your quality objectives?
- When do you review and update quality objectives, and what triggers a change?
What to Sample
Review the quality objectives matrix. Verify at least 1 OTD objective, 1 product conformity objective, and 1 customer satisfaction objective exist with measurable targets.
Frequently Asked Questions
Get the Full 60-Item Checklist
Download the complete AS9100D:2016 aerospace audit checklist with all 60 expert items, objective evidence requirements, common nonconformities, auditor tips, and a professional scoring rubric.
This checklist is an educational resource for audit preparation. It does not constitute professional regulatory advice. Always consult qualified auditors for certification decisions.