AS9100D:2016 aerospace audit checklist
Practising auditors wrote these 60 audit questions, covering the full standard. Each item names the objective evidence to request, the nonconformities most often raised against it, and what to sample. It is free to read, with no sign-up required.
Download the PDF
Includes all 60 items, formatted for a clipboard.
You will get one email with the file. We will not send anything else.
What each item gives you
This is what an auditor needs at each item. You already hold the standard itself.
Phrases it the way you would ask it in the room.
Names the specific artefacts that satisfy the item, and how to tell a real one from a placeholder.
Lists the findings most often raised here, in the words they get written up in.
Shows where the item usually goes wrong, and what a mature answer sounds like against a rehearsed one.
Explains how many to take, how to choose them, and what to cross-reference them against.
Gives the second and third questions to ask when the first answer is too smooth.
All 60 items on this page
Questions below are grouped by section, and you can check items off as you go — this browser remembers your progress. Open any row for its evidence, common nonconformities and auditor tips.
§4 Context of the organization
4.1 Has the organization identified external and internal issues relevant to its aerospace, space, or defense context, including applicable airworthiness authority requirements, customer-specific requirements, and defense contract obligations?
- Documented context analysis that identifies aerospace-specific external issues — airworthiness authority regulations (FAA, EASA, TCCA, ANAC), prime contractor requirements, export control obligations (ITAR/EAR), and industry standards beyond AS9100D
- Internal issue assessment addressing workforce competency for safety-critical work, facility capabilities for controlled environments, and capacity constraints affecting on-time delivery
- Evidence that context analysis is reviewed and updated — look for revision history or management review inputs that reference changes in regulatory landscape or customer base
- Context analysis is a generic template that does not reference any aerospace-specific regulatory authorities, customer flow-down requirements, or export control obligations — the same document could apply to any manufacturing company (Minor NC).
- Organization holds multiple customer approvals (Boeing D1-4426, Airbus AQSF) but these are not identified as relevant external issues that affect QMS requirements (Observation).
- No evidence that the context analysis has been reviewed since initial certification — the document references organizational structures and customer relationships that no longer exist (Minor NC).
In aerospace, the context is uniquely complex. The organization must demonstrate awareness of the regulatory hierarchy — AS9100D certification body, airworthiness authority (FAA/EASA), prime contractor quality requirements, and end-customer operational requirements. Ask which airworthiness authorities have jurisdiction over their products. If they cannot answer, the context analysis is likely superficial. Check whether ITAR/EAR applicability has been assessed — many aerospace suppliers handle controlled technical data without realizing it.
Review the context analysis document. Cross-reference against the organization's actual customer list and applicable regulatory registrations. Verify that at least the top 3 customers' specific quality requirements are identified.
- Which airworthiness authorities have jurisdiction over the products you manufacture, and how do their requirements flow into your QMS?
- Have you assessed your obligations under ITAR or EAR, and where is that assessment documented?
- What changes in your customer base or regulatory environment have you identified in the last 12 months?
4.2 Has the organization identified all relevant interested parties specific to the aviation, space, and defense industry, including airworthiness authorities, certification bodies, prime contractors, and regulatory agencies?
- Interested party register that includes aerospace-specific stakeholders — airworthiness authorities (FAA, EASA), accreditation bodies (ANAB, UKAS), prime contractors with approved supplier list requirements, Nadcap Management Council (if special processes are performed), and applicable government/military procurement agencies
- Documented requirements and expectations for each interested party — not just listed but with specific obligations identified (e.g., Boeing D1-4426 quality clauses, Airbus AQSF requirements)
- Evidence of monitoring changes in interested party requirements — such as updated customer quality manuals, revised airworthiness directives, or new regulatory guidance
- Interested party analysis lists 'customers' and 'regulators' generically without identifying specific aerospace primes, airworthiness authorities, or their distinct requirements — the analysis lacks actionable specificity (Minor NC).
- Organization supplies to military programs but has not identified the Defense Contract Management Agency (DCMA) or equivalent national defense quality authority as an interested party (Minor NC).
- No process exists to monitor when interested parties update their requirements — the organization was unaware that a major customer revised their quality clauses 6 months ago (Observation).
Aerospace interested parties are not abstract — they have specific, documented requirements that the organization must comply with. Ask to see actual customer quality requirement documents (Boeing D1-4426, Airbus AQSF, Lockheed Martin CorpDocs, etc.) and verify the organization has current versions. Check whether Nadcap is identified if special processes are performed. For defense suppliers, verify government quality assurance agencies are identified.
Select 2 prime contractor customers from the approved customer list. Verify the organization has current copies of their quality requirement documents and can demonstrate how those requirements are addressed in the QMS.
- Can you show me the current versions of your top three customers' quality requirement documents?
- How do you learn when an interested party — such as a prime contractor or regulatory body — changes their requirements?
- Have any interested party requirements changed in the past year, and how did you respond?
4.3 Does the QMS scope explicitly identify all products, services, and sites covered, including any exclusions with documented justification — and does the scope address all applicable aviation, space, and defense customer and regulatory requirements?
- QMS scope statement identifying all products, product types, and sites included within the scope of the AS9100D certificate
- Documented justification for any excluded requirements (e.g., clause 8.3 Design excluded for build-to-print operations) — verify the justification is valid and that the excluded requirements genuinely do not apply
- Verification that the scope aligns with the actual work performed — the scope should not be broader than the organization's actual capabilities or narrower than its actual product range
- QMS scope excludes design and development (clause 8.3) but the organization performs tooling design and process development activities that constitute design (Minor NC).
- QMS scope references only one facility but production also occurs at a secondary site that is not included in the scope or certificate (Major NC).
- No documented justification exists for excluding clause 8.3 — the exclusion is stated but the rationale is not documented (Minor NC).
Check the scope against reality. Walk the facility and verify that all activities and product types are represented in the scope. Common issues include: organizations performing design activities while excluding 8.3, secondary production sites not covered, and scopes that are too vague to be meaningful. Also verify that any customer-required processes (e.g., design authority for repairs, engineering support) are within scope if the organization performs them.
Compare the QMS scope statement to the organization's actual product range and site locations. Verify any exclusions have documented justification.
- Are there any products, processes, or sites that are not included in your QMS scope? If so, why?
- Do you perform any design, engineering, or product development activities? How are these addressed in your scope?
- Has your scope changed since your last certification audit, and what triggered the change?
4.4 Does the QMS address all applicable aviation, space, and defense customer and regulatory requirements, including product safety, airworthiness, and the need for process accountability through identified process owners?
- QMS process map or turtle diagram set showing all processes with named process owners who have defined authority and accountability — verify process owners can articulate their responsibilities when interviewed
- Matrix mapping customer and regulatory requirements to specific QMS processes — verify coverage of aerospace-specific requirements (product safety, configuration management, counterfeit prevention, FAI, special processes)
- Evidence that process interactions account for aerospace-unique workflows — such as the link between design change control and configuration management, or between receiving inspection and counterfeit prevention
- Management review records showing QMS process performance is evaluated including aerospace-specific metrics (OTD, quality escapes, customer scorecards)
- QMS process map does not include aerospace-specific processes required by AS9100D — configuration management, counterfeit parts prevention, and operational risk management are absent from the process landscape (Major NC).
- Process owners are named but cannot describe their authority over the process or the metrics by which process performance is measured — ownership is nominal rather than functional (Minor NC).
- Process interactions do not reflect the actual flow of work — the documented sequence shows design output feeding directly to production, with no configuration management, FAI, or production planning process between them (Minor NC).
AS9100D requires process owners to be identified — this is an addition to ISO 9001. Interview at least two process owners and ask them to explain their process inputs, outputs, controls, and performance metrics. If a process owner cannot describe these without referring to documentation, the process ownership is likely ceremonial. Check that aerospace-specific processes (8.1.1 through 8.1.4) appear on the process map — organizations that upgraded from ISO 9001 frequently omit these.
Interview 2 process owners. Ask each to explain their process boundaries, inputs, outputs, risks, and current performance. Cross-reference their answers against the documented process descriptions.
- Who is the process owner for configuration management, and what authority do they have to stop production if a configuration discrepancy is found?
- How do you ensure that changes to one process — such as a supplier change — trigger reviews of dependent processes?
- Walk me through how a customer-initiated engineering change flows through your QMS processes from receipt to implementation.
§5 Leadership
5.1.1 Has top management ensured that a product safety process is established and maintained, with defined accountability for product safety decisions?
- Documented product safety process or procedure that defines how safety requirements are identified, controlled, and verified throughout the product lifecycle — not just a policy statement but an operational process with roles, triggers, and records
- Organization chart or responsibility matrix showing who has authority and accountability for product safety decisions — verify this person has direct access to top management
- Records of product safety reviews or safety risk assessments conducted for current products — at minimum for products with safety-critical characteristics
- Evidence that top management is informed of product safety issues — management review minutes, safety review meeting records, or escalation records
- Product safety is addressed only in the quality policy as a general statement — no operational process exists for identifying, documenting, or controlling product safety requirements (Major NC).
- Product safety accountability is assigned to a junior quality engineer with no authority to stop shipment or escalate to top management — the accountability structure does not match the criticality (Minor NC).
- Organization manufactures flight-critical structural components but has not conducted any product safety risk assessment — safety requirements are assumed to be covered by customer drawings without independent analysis (Major NC).
This is one of the most important AS9100D additions. Product safety is not the same as product quality — a part can meet all dimensional requirements but still have a safety concern (e.g., material substitution, process deviation). Ask top management directly: 'What is your role in product safety?' and 'Give me an example of a product safety issue that was escalated to you.' If they cannot provide an example, probe whether the escalation mechanism has ever been tested. Look for evidence that safety requirements flow from customer requirements or airworthiness regulations into design and production controls.
Select a safety-critical product. Trace product safety requirements from customer/regulatory input through design, production, and final inspection. Verify that safety requirements are explicitly identified and controlled at each stage.
- Can you give me a specific example of a product safety concern that was identified and how it was resolved?
- Who in this organization has the authority to stop a shipment based on a product safety concern, and has that authority ever been exercised?
- How are product safety requirements communicated to production floor personnel?
5.1.1 Has top management established a policy and process that enables personnel to report nonconformities and safety concerns without fear of reprisal, and does this reporting mechanism function in practice?
- Documented policy on reporting quality and safety concerns — verify it explicitly states protection from reprisal and is communicated to all employees (posted, included in onboarding, referenced in training)
- Reporting mechanism available to all personnel — anonymous hotline, suggestion system, direct reporting chain, or equivalent — verify it is accessible and known to employees
- Records of concerns reported through the mechanism in the past 12 months — if zero reports exist, this may indicate the mechanism is not trusted or not promoted
- Evidence of management response to reported concerns — closed-loop follow-up showing that reports were investigated and outcomes communicated back to the reporter
- No documented policy or procedure exists for reporting quality and safety concerns — employees are expected to report through their supervisor, but no alternative channel exists if the supervisor is the source of the concern (Major NC).
- A reporting policy exists but no reports have been received in the past 2 years across 200+ employees — this suggests the mechanism is either unknown, inaccessible, or not trusted (Observation).
- Reports have been submitted but there is no evidence of investigation or follow-up — the reporting mechanism functions as a suggestion box with no closed-loop response process (Minor NC).
This requirement is about culture, not just documentation. Interview 3-4 floor-level employees separately and ask: 'If you saw a quality problem, how would you report it? Have you ever reported one? What happened?' If employees hesitate, cannot describe the process, or express doubt about management response, the mechanism is not effective regardless of what the documentation says. Also ask whether anyone has ever stopped production or refused to ship based on a quality concern — and whether there were consequences for doing so.
Interview 3 shop floor personnel individually. Ask each how they would report a quality or safety concern, whether they have ever done so, and whether they believe management would support them. Compare answers against the documented process.
- If an operator on the shop floor noticed a part that looked wrong but had been approved by inspection, what would they do?
- Has anyone in this organization ever raised a safety concern that resulted in a stop-ship or production halt? What happened to that person?
- How do you communicate back to employees what happened with their reported concern?
5.1.2 Has top management ensured that on-time delivery performance is monitored and that actions are taken when planned delivery commitments are not met?
- On-time delivery (OTD) metric tracked at the organizational level — verify the metric definition (on-time to customer request date vs. on-time to promise date), calculation method, and data source
- OTD trend data for the past 12 months showing target vs. actual performance — verify the data is current and reviewed regularly
- Evidence of action taken when OTD targets are missed — corrective actions, capacity adjustments, expediting plans, or customer communication records
- Management review records showing OTD performance is discussed as an input — verify top management is aware of delivery performance trends
- On-time delivery is tracked only as a percentage without distinguishing between on-time to customer request date and on-time to the organization's own promise date — the metric may mask late deliveries that were 'resolved' by negotiating a later date with the customer (Minor NC).
- OTD performance has been below the target for 6 consecutive months but no corrective action or improvement plan has been initiated — performance is reported but not acted upon (Minor NC).
- OTD data is not presented to top management in management review — delivery performance is managed by operations without leadership visibility (Observation).
AS9100D specifically requires on-time delivery monitoring — this goes beyond ISO 9001's general customer satisfaction requirement. Verify how OTD is measured. The most meaningful metric is on-time to the customer's original requested date, not to a renegotiated promise date. Ask to see the actual delivery performance data in the ERP system and compare it to what is reported in management review. Discrepancies may indicate the metric is being 'managed' rather than measured. Also check whether late deliveries trigger any root cause analysis.
Pull 10 recent shipments from the ERP system. For each, compare the customer's original requested delivery date to the actual ship date. Calculate the true OTD rate and compare against the reported metric.
- When a delivery is late, what is the process for determining why and preventing recurrence?
- Do you track on-time delivery to the customer's original request date or to your committed ship date?
- What was your OTD performance last quarter, and what are the top three causes of late delivery?
5.3 Has top management assigned the responsibility and authority for ensuring that products and services conform to requirements, including the authority to stop production and shipment when nonconformities are identified?
- Organization chart and job descriptions showing designated personnel with authority to make disposition decisions on nonconforming product — verify this authority is documented and understood
- Evidence that stop-ship or production-halt authority has been communicated to relevant personnel — training records, posted authorities, or quality system procedure references
- Records of any instance where stop-ship authority was exercised — if never exercised, verify through interviews that personnel understand they have this authority and would use it
- Quality assurance independence — verify that QA personnel report through a quality chain, not through production management who may have schedule pressure conflicts
- Quality assurance function reports to the production manager — the organizational structure creates a conflict of interest where the person responsible for schedule also controls the resources that could stop shipment (Major NC in some CB interpretations, Observation in others).
- No individual has documented authority to stop shipment — disposition authority is vested in a Material Review Board that meets weekly, creating a gap where nonconforming product could ship before the next MRB meeting (Minor NC).
- Stop-ship authority exists on paper but production personnel interviewed are unaware of it or express doubt that it would be supported by management (Observation).
AS9100D explicitly requires authority for personnel to stop processes to address quality issues. This is not just about having a procedure — it is about having real, exercisable authority. Interview the person with stop-ship authority and ask for the last time they used it. If they have never used it in years of production, explore why. Either the authority is effective as a deterrent (good) or it is symbolic and would not actually be exercised under schedule pressure (bad). Also verify QA independence — QA personnel who report to production managers face inherent conflicts.
Review the organization chart to verify QA reporting structure. Interview the QA manager and 1 production supervisor about stop-ship authority and its practical exercise.
- Who has the authority to stop a shipment, and what would happen to them professionally if they exercised that authority on a critical delivery?
- Does your QA manager report to the plant/operations manager or to a separate quality chain?
- Describe the last time production was stopped for a quality reason — who made the call and how did management respond?
§6 Planning
6.1 Has the organization identified risks and opportunities arising from the aerospace context — including product safety, airworthiness, supply chain, and regulatory risks — and planned actions to address them that are proportionate to their potential impact on product conformity?
- Risk and opportunity register that includes aerospace-specific risks: airworthiness compliance, product safety, customer-specific requirements changes, regulatory authority findings, supply chain single-source dependencies, and technology obsolescence
- Planned actions for identified risks — verify each significant risk has a defined action, responsible owner, and timeline
- Evidence that actions have been implemented and evaluated for effectiveness — verify at least 3 risk mitigation actions have been carried out with documented results
- Proportionality assessment — verify that higher-impact risks (product safety, airworthiness) receive more robust mitigation than lower-impact risks
- Risk register is a static document created during initial certification that has not been updated — new customer programs, supplier changes, and regulatory updates in the past 2 years are not reflected (Minor NC).
- Risks are identified but no actions are planned — the register lists 15 risks but only 3 have defined mitigation actions (Minor NC).
- Risk assessment does not distinguish between product safety risks and operational efficiency risks — all risks are assessed on the same scale without weighting for safety consequences (Observation).
The clause 6.1 risk assessment is the strategic-level complement to clause 8.1.1 operational risk management. Verify the organization understands the difference. If the risk register looks like it could belong to any manufacturing company without modification, it likely does not adequately address the aerospace context.
Review the risk register. Verify aerospace-specific risks are included. Select 3 risks and verify: actions are defined, implemented, and evaluated for effectiveness.
- What are your top 3 strategic risks to delivering conforming products, and what are you doing about them?
- How do you differentiate the response between a risk that could affect product safety versus a risk that could affect administrative efficiency?
- When was the last time you added a new risk to this register, and what triggered it?
6.2 Has the organization established measurable quality objectives that address product conformity, on-time delivery, and customer satisfaction — with defined targets, timelines, and assigned responsibility?
- Quality objectives document or matrix — verify objectives are specific, measurable, achievable, relevant, and time-bound (SMART), not just aspirational statements
- Objectives include aerospace-specific metrics — on-time delivery target, product conformity target (scrap rate, FPY, customer rejection PPM), customer satisfaction target
- Evidence of monitoring progress against objectives — verify objectives are tracked at defined intervals with actual vs. target data
- Action plans for objectives that are not being met — verify that when an objective is behind target, specific improvement actions are defined
- Quality objectives are not measurable — 'improve on-time delivery' is stated but no specific target percentage, baseline, or timeline is defined (Minor NC).
- No quality objective addresses on-time delivery — product quality objectives exist but delivery performance is not covered (Minor NC).
- Quality objectives are tracked but no action is taken when targets are missed — OTD has been below the 95% target for 6 consecutive months with no improvement plan (Minor NC).
Quality objectives in aerospace should reflect the metrics that matter to customers and regulators: OTD, product conformity, and customer satisfaction. Verify objectives are truly measurable with specific numeric targets.
Review the quality objectives matrix. Verify at least 1 OTD objective, 1 product conformity objective, and 1 customer satisfaction objective exist with measurable targets.
- Which quality objectives are you currently behind on, and what actions are you taking?
- How did you establish the target values for your quality objectives?
- When do you review and update quality objectives, and what triggers a change?
§7 Support
7.1.5 Does the organization maintain a calibration program that ensures all monitoring and measuring equipment is calibrated or verified at defined intervals, traceable to international or national measurement standards, and that calibration status is identifiable on or with the equipment?
- Calibration procedure and master equipment list — verify all monitoring and measuring equipment affecting product acceptance is included with defined calibration intervals and required accuracy/tolerance
- Calibration records for at least 5 instruments selected from the production floor — verify each is within its calibration interval, traceable to national/international standards, and that the calibration label matches the calibration record
- Out-of-calibration response process — verify a documented process exists for assessing the impact on product accepted using equipment found out of calibration, including notification to affected customers if product may have been incorrectly accepted
- Calibration environment — verify calibration is performed in conditions appropriate for the accuracy required (temperature-controlled areas for precision metrology)
- Equipment found in use on the production floor with an expired calibration date — the calibration sticker shows the due date was 3 months ago (Major NC).
- Out-of-calibration condition discovered during periodic calibration but no assessment was performed to determine whether product measured since the last calibration is affected — no customer notification considered (Minor NC).
- Calibration is performed in-house but no traceability to national measurement standards is established for the reference standards used (Minor NC).
- Employee-owned tools (calipers, micrometers) are used for product acceptance measurements but are not included in the calibration program (Minor NC).
Calibration is fundamental to aerospace quality because every acceptance decision is only as good as the measurement that supports it. Walk the floor and check calibration stickers on instruments in use. If any are overdue, it is a finding. Also check the out-of-calibration response process — when an instrument is found out of tolerance during calibration, the organization must assess the impact on all product measured since the last known good calibration. This assessment is frequently inadequate or missing. Ask about employee-owned tools — if operators use their personal calipers for product measurements, those tools must be in the calibration program.
Select 5 instruments from the production floor. Verify each: (1) is on the master list, (2) has a current calibration sticker, (3) calibration record shows traceability to standards, (4) is within its calibration interval.
- What happens when an instrument is found out of tolerance during calibration — how do you assess the impact on product already shipped?
- Are any employee-owned measuring tools used for product acceptance measurements? If so, are they in the calibration program?
- How do you determine calibration intervals — is it based on historical data, manufacturer recommendation, or a fixed schedule?
7.1.6 Has the organization determined, maintained, and made available the organizational knowledge necessary for aerospace operations, including lessons learned from nonconformities, corrective actions, and product safety events?
- Organizational knowledge repository or system — lessons learned database, engineering standards library, process knowledge documentation, or equivalent — verify it is accessible to personnel who need it
- Records of lessons learned captured from internal nonconformities, customer returns, corrective actions, and product safety events — verify entries are specific and actionable, not generic statements
- Evidence that organizational knowledge is used in practice — for example, lessons learned referenced during process planning, FMEA updates based on field experience, or new employee training incorporating historical knowledge
- Process for capturing knowledge from departing employees, especially those with critical process expertise or institutional knowledge about specific programs
- Organization has a lessons learned database but it has not been updated in over 18 months despite ongoing production and multiple corrective actions — knowledge capture is not integrated into the CAPA process (Minor NC).
- Critical process knowledge resides with a single subject matter expert (key person dependency) and no documented plan exists to capture and transfer that knowledge — if the individual left, the organization could not reproduce the process (Observation).
- Lessons learned are captured but there is no process to apply them — the database exists but is not referenced during production planning, FMEA reviews, or new program launches (Minor NC).
In aerospace, organizational knowledge is a strategic asset. Products with 20-40 year lifecycles require institutional memory. Focus on whether lessons learned are actually used, not just stored. Ask to see a recent FMEA or control plan and check whether it references any lessons learned from previous programs. Also probe key person dependencies — if only one person knows how to set up a critical machine or run a specific process, that is a significant risk. AS9100D adds emphasis on knowledge from external sources as well — industry alerts, airworthiness directives, and customer bulletins.
Select a recent corrective action. Verify that the lessons learned were captured in the knowledge system. Then select a recent production planning package and check whether any lessons learned were referenced.
- How do you capture knowledge when a long-tenured employee with critical expertise leaves the organization?
- Show me an example where a lesson learned from one program was applied to prevent a problem on a different program.
- How do you incorporate external knowledge — such as industry alerts, airworthiness directives, or customer quality bulletins — into your operations?
7.2 Can the organization show that everyone whose work affects product conformity is competent, qualified through the right blend of education, training, skill, and hands-on experience, with particular rigor for safety-critical and special-process roles (e.g., NAS 410 NDT, AWS D17.1 welding)?
- Competence requirements defined for each role affecting product conformity — not just generic job descriptions but specific competence criteria including required certifications (e.g., NAS 410 for NDT, AWS D17.1 for aerospace welding, CWI for weld inspection)
- Training records demonstrating that personnel meet the defined competence requirements — verify qualifications are current and have not expired
- Special process operator qualifications — Nadcap-required personnel certifications for heat treat, NDT, welding, plating, painting, and other special processes
- Evidence of competence evaluation — not just 'attended training' but demonstrated ability through practical tests, supervised work periods, or periodic requalification
- Records for temporary workers, contract personnel, and new hires showing competence was verified before they performed work affecting product conformity
- NDT personnel certifications have expired — Level II inspector's certification lapsed 4 months ago but they continued performing inspections, and no process exists to track certification expiration dates (Major NC).
- Competence requirements for production operators are limited to 'on-the-job training' with no defined criteria for what constitutes competence — the training record shows a date and supervisor signature but no evidence of what was taught or how competence was evaluated (Minor NC).
- Temporary agency personnel are placed on the production line after a brief orientation but without the same competence verification applied to permanent employees — no evaluation of their skills or experience against defined competence criteria (Minor NC).
- Special process operators do not hold the certifications required by the applicable Nadcap checklist — heat treat operator has no metallurgical training or pyrometry certification (Major NC).
Competence in aerospace goes well beyond generic training records. For special processes, verify that operator certifications align with Nadcap requirements (even if the organization is not Nadcap accredited — the AS9100D requirement for special process validation still applies). Check that competence is evaluated, not just assumed from attendance. Ask an operator to explain the acceptance criteria for the product they are currently working on — if they cannot, competence is questionable regardless of what the training record says. Pay particular attention to inspectors, NDT personnel, and anyone performing first article inspection.
Select 3 personnel from the production floor — 1 machine operator, 1 inspector, and 1 special process operator (if applicable). Review their training and qualification records against defined competence requirements for their roles.
- How do you track certification and qualification expiration dates, and what happens when one expires?
- Walk me through how a new hire on the production floor is qualified to perform work — what do they need to demonstrate before they work unsupervised?
- For your special process operators, what industry certifications are required and how do you verify they are current?
7.3 Are personnel aware of the consequences of nonconformity to product requirements, including the potential impact on product safety and end-user safety?
- Training materials or awareness communications that explain the consequences of nonconformity in the context of the organization's specific products — not generic quality awareness but product-specific safety implications (e.g., 'this bracket supports the wing spar; a crack here could cause structural failure')
- Records of safety awareness training that covers the end-use application of the products — verify personnel know whether their products are safety-critical, flight-critical, or mission-critical
- Signage, visual management, or work instructions that reinforce safety consequences at the point of production — especially at workstations producing safety-critical items
- Evidence that awareness training is refreshed periodically — not just at initial hire but ongoing reinforcement
- Personnel on the production floor cannot describe the end-use application of the parts they manufacture or the consequences if the parts were defective — operators report 'making parts' without understanding the safety context (Minor NC).
- Awareness training is conducted at hire but never refreshed — employees hired 5 years ago have no record of subsequent safety awareness reinforcement (Observation).
- Awareness training materials are generic and do not reference the organization's actual products or their applications — the same training slides could be used at any manufacturing company (Minor NC).
This is a critical AS9100D addition. ISO 9001 requires awareness of the 'relevance and importance' of activities; AS9100D explicitly adds product safety consequences. The test is simple: ask 3 production floor employees 'What do the parts you make go into, and what would happen if your part failed?' If they cannot answer, awareness training is ineffective. The most effective organizations tie awareness to specific products — 'this fitting goes on the engine pylon; if it fails, the engine separates from the aircraft.' Generic 'quality is important' training does not satisfy this requirement.
Interview 3 production operators at their workstations. Ask each what their product is used for and what would happen if it failed. Compare their awareness against what the training records claim was taught.
- What would happen if the part you are working on right now had a defect that was not caught?
- How often do you receive training or communication about the safety implications of the products you work on?
- Can you give me an example of a quality concern on this product line that had safety implications?
7.5 Does the organization's documented information control system ensure that only current revision documents are available at points of use, with particular attention to engineering drawings, specifications, and customer-supplied technical data?
- Document control procedure addressing aerospace-specific document types — engineering drawings, customer specifications, material specifications, process specifications, and customer-supplied data — with defined processes for revision control and obsolete document withdrawal
- Verification at 3 workstations that current-revision drawings and specifications are available and match the master document list — check for pencil marks, unauthorized annotations, or outdated revisions
- Process for incorporating customer-initiated engineering changes — from receipt of the change notice through impact assessment, implementation, and verification that obsolete documentation is withdrawn
- Control of electronic documents — verify access controls, version management, and backup procedures for digital engineering data including CAD models and CNC programs
- Superseded revision of an engineering drawing is in use at a workstation — the master list shows Revision D as current but Revision C is posted at the CNC machine and the operator is producing parts to the obsolete revision (Major NC).
- Customer-supplied specifications are stored locally on individual computers without version control — no process exists to verify that the most current customer specifications are being used (Minor NC).
- CNC programs have no revision control — programs are modified by operators without documentation of what changed, when, or why, and no backup copies of previous validated versions exist (Minor NC).
Document control failures in aerospace can have catastrophic consequences — producing parts to the wrong drawing revision is a common root cause of nonconforming product. Walk the shop floor and physically check documents at workstations against the master list. Pay special attention to CNC programs, which are often the weakest link in document control — they are functionally equivalent to work instructions but frequently managed outside the formal document control system. Also verify how customer-furnished data (drawings, specs, models) enters the system and how revisions are controlled.
Select 3 workstations. At each, verify: (1) the drawing revision matches the master list, (2) no unauthorized mark-ups exist, (3) the CNC program revision (if applicable) corresponds to the current drawing revision.
- How do you ensure that when a customer issues a new drawing revision, the old revision is withdrawn from all points of use including CNC programs?
- Walk me through the last engineering change you received from a customer — how was it processed and implemented?
- How are CNC programs controlled, and can you show me the revision history for the program currently running on this machine?
§8.1 Operational planning and control
8.1.1 Has the organization established and implemented a formal operational risk management process that addresses risks to product conformity, on-time delivery, and product safety — as distinct from the strategic risk assessment required by clause 6.1?
- Documented operational risk management procedure — verify it is separate from or clearly extends beyond the clause 6.1 risk assessment, addressing operational-level risks such as supply chain disruption, process capability loss, key person dependency, and equipment failure
- Operational risk register or FMEA covering current production programs — verify risks are assessed with likelihood and consequence ratings, mitigation actions are defined, and residual risk is accepted by appropriate authority
- Evidence that operational risk assessments are performed for new programs, new processes, and significant changes — not just a one-time exercise but triggered by defined events
- Records showing risk mitigations have been implemented and their effectiveness verified — verify at least 2 mitigations from the risk register have evidence of implementation
- Organization has a clause 6.1 risk register that addresses strategic risks (market, competition, regulatory changes) but no operational risk management process exists for production-level risks such as machine breakdown, single-source supplier dependency, or process capability drift (Major NC).
- Operational risk assessment exists but has not been updated since initial creation — new programs, supplier changes, and process modifications have been introduced without risk assessment (Minor NC).
- Risk mitigations are identified on paper but not implemented — the risk register shows 'implement backup supplier' as a mitigation but no action has been taken in 12 months (Minor NC).
- No clear criteria exist for what level of residual risk is acceptable and who has authority to accept it — risk assessments show varying levels of residual risk but no documented acceptance decisions (Observation).
This is one of the most frequently misunderstood AS9100D requirements. Organizations often believe their clause 6.1 risk assessment satisfies 8.1.1 — it does not. Clause 6.1 addresses strategic and QMS-level risks; clause 8.1.1 addresses operational risks at the process and product level. Ask to see both and compare. A good operational risk assessment should be dynamic and specific — 'Machine X is our only 5-axis mill and if it goes down we cannot produce parts for Program Y within lead time' is operational risk. 'Loss of market share' is strategic risk. Also check that risk assessments are performed when planning for new work, not just maintained for existing programs.
Select 2 current production programs. For each, verify that an operational risk assessment exists, is current, and that at least 1 identified mitigation has been implemented with evidence.
- How does your operational risk management differ from your clause 6.1 strategic risk assessment?
- Show me a risk assessment that was triggered by a specific event — such as a new program award, supplier change, or process modification.
- What is your process for accepting residual risk, and who has that authority?
8.1.1 Does the operational risk management process assign responsibility for risk management across the organization, including criteria for escalation and risk acceptance at appropriate levels of authority?
- Defined risk ownership — each identified risk has an assigned owner with responsibility and authority to manage the risk and implement mitigations
- Risk escalation criteria documented and understood — thresholds for when a risk must be escalated to management (e.g., risks rated 'high' or above require management review and acceptance)
- Evidence of risk escalation in practice — records showing at least one risk was escalated per the defined criteria and management made a documented acceptance or additional mitigation decision
- Integration of operational risk into existing management processes — risk status reported in management review, production meetings, or program reviews
- Operational risks are identified in a register but no risk owners are assigned — risks are collectively 'owned' by the quality department with no individual accountability (Minor NC).
- No escalation criteria exist — all risks are treated equally regardless of severity, and there is no process for bringing high-severity risks to top management attention (Minor NC).
- Risk register shows several 'high' rated risks but management review records do not reference any operational risks — the risk management process is disconnected from management decision-making (Minor NC).
Effective operational risk management requires integration into daily operations, not a standalone document. Check whether operational risks appear in production planning meetings, program reviews, or shift handover briefings. If the risk register is only reviewed during internal audits or management reviews, it is likely a compliance artifact rather than a living management tool. Ask a production supervisor about their top 3 operational risks — if their answers do not align with the risk register, the system is not embedded in operations.
Compare the top 5 risks in the operational risk register against what production supervisors identify as their top concerns. Alignment indicates an effective process; misalignment indicates a paper exercise.
- Ask a production supervisor: What are the top 3 risks to meeting your delivery commitments this month?
- When was the last time a risk was escalated from the shop floor to management, and what happened?
- How does your risk register inform daily production planning decisions?
8.1.2 Has the organization established a configuration management process that ensures product configuration is identified, controlled, and maintained throughout the product lifecycle — including tracking as-designed, as-planned, as-built, and as-maintained configurations?
- Configuration management plan or procedure — verify it addresses configuration identification (baseline definition), configuration change control (engineering change process), configuration status accounting (tracking current configuration), and configuration audit (verifying as-built matches as-designed)
- Configuration baselines for current products — defined and documented sets of approved design documents, specifications, and drawings that constitute the product definition at specific milestones
- Engineering change control process with evidence of implementation — select 2 recent engineering changes and verify the full cycle: change request, impact assessment, approval, implementation, verification, and baseline update
- As-built records or configuration status accounting records — verify the organization can determine the exact configuration of any shipped product by serial number or lot
- Bill of materials (BOM) accuracy — verify the BOM matches the current drawing revision and that changes to one are reflected in the other
- Engineering changes are implemented in production but the configuration baseline documents (BOMs, drawing lists) are not updated to reflect the changes — as-built configuration diverges from documented configuration over time (Major NC).
- No configuration status accounting exists — the organization cannot determine the as-built configuration of products shipped 6 months ago because individual change records are not linked to specific serial numbers or production lots (Minor NC).
- Engineering change process exists but effectivity points are not defined — changes are implemented 'when convenient' rather than at a defined unit, lot, or date, creating mixed-configuration inventory (Minor NC).
- Configuration audits (comparing as-built to as-designed) are not performed — the organization assumes that if the engineering change was processed, the configuration is correct, without independent verification (Minor NC).
Configuration management is where many aerospace suppliers struggle, especially smaller organizations. The four pillars are: identification (what is the baseline?), control (how are changes managed?), status accounting (what is the current configuration of a specific unit?), and audit (does the actual product match the documented configuration?). Most organizations have reasonable change control but weak status accounting and no configuration audits. Ask them to tell you the exact configuration of a product they shipped 3 months ago — if they cannot reconstruct it from records, status accounting is inadequate. Also check the link between engineering changes and affected BOMs, work instructions, and inspection plans.
Select 1 product by serial number. Request the as-built configuration record. Verify it includes drawing revisions, specification revisions, material certifications, and process records. Cross-reference at least 2 elements against source documents.
- If I give you a serial number from a product shipped last year, can you tell me the exact drawing revisions, material specifications, and process revisions that were used to produce it?
- Walk me through the last engineering change — from request through implementation. How do you verify the change was correctly implemented in production?
- How do you manage effectivity — when does a change take effect, and how do you handle mixed-configuration work-in-process?
8.1.2 Does the organization perform configuration audits — comparing the as-built product configuration against the as-designed configuration baseline — to verify that products conform to the approved design definition?
- Configuration audit procedure defining when functional configuration audits (FCA) and physical configuration audits (PCA) are performed — verify triggers include new product release, major design changes, and periodic verification
- Records of configuration audits performed — verify at least 1 configuration audit was conducted in the past 12 months comparing as-built records to the design baseline
- Discrepancies found during configuration audits and their resolution — verify that any differences between as-built and as-designed were investigated and corrected
- Evidence that configuration status accounting records accurately reflect the current product configuration
- No configuration audits have been performed — the organization maintains configuration status records but never verifies them against the actual product (Minor NC).
- Configuration audit found discrepancies between the as-built record and the actual product but no corrective action was taken (Minor NC).
- Configuration status accounting records are not kept current — engineering changes from the past 6 months are not reflected in the status records (Minor NC).
Configuration audits close the loop between documentation and reality. Most organizations have reasonable configuration identification and change control but never verify that the product they built actually matches the documented configuration. Ask the organization to demonstrate the as-built configuration of a recently shipped product — if they cannot reconstruct it from records, configuration status accounting is inadequate.
Select 1 product from recent production. Request the as-built configuration record. Compare at least 3 elements (drawing revision, material specification, process specification) against the design baseline.
- When was the last time you compared the as-built configuration of a product against the design baseline?
- If I selected a product from your finished goods area, could you tell me the exact configuration right now?
- How do you verify that engineering changes are correctly reflected in the as-built records?
8.1.3 Has the organization identified product safety requirements — including those from airworthiness regulations, customer specifications, and the organization's own risk analysis — and are these requirements documented, controlled, and verified throughout the product lifecycle?
- Product safety requirements register or matrix — listing safety requirements by source (regulatory, customer, internal risk analysis) with traceability to design outputs, production controls, and verification activities
- Safety-critical characteristics identified on drawings and specifications — verify these are flagged with appropriate symbols (inverted delta, critical safety item marking per customer requirements) and flow through to inspection plans
- Product safety risk analysis — DFMEA, PFMEA, or equivalent that identifies potential failure modes with safety consequences and defines controls to mitigate risk
- Verification records demonstrating that product safety requirements are verified — inspection results, test results, or analysis reports for safety-critical characteristics
- Process for managing product safety events — nonconformities affecting safety-critical characteristics, customer safety alerts, and mandatory reporting to airworthiness authorities
- Customer drawings identify safety-critical characteristics with inverted delta symbols but the organization's inspection plan does not distinguish these from other characteristics — safety-critical dimensions receive the same inspection frequency and method as non-critical dimensions (Major NC).
- No product safety risk analysis has been performed — the organization relies entirely on customer drawings to identify safety requirements without performing its own assessment of manufacturing process risks that could affect safety (Minor NC).
- Product safety nonconformities are processed through the standard NCR system without any differentiated handling — nonconformities on safety-critical features are dispositioned using the same process and authority levels as cosmetic defects (Major NC).
- Organization manufactures safety-critical structural components but has no process for reporting product safety events to the airworthiness authority or customer — mandatory reporting obligations have not been identified (Major NC).
Product safety in AS9100D goes beyond having a safety policy. Verify the full chain: safety requirements are identified (from regulations, customer, and internal risk analysis), flowed into design and production documentation (drawings, work instructions, inspection plans), verified during production (with appropriate method and frequency), and managed with heightened controls when nonconformities occur. The most common gap is in differentiated handling — safety-critical nonconformities should receive more scrutiny, faster containment, and higher-level disposition authority than general nonconformities. Also check that the organization knows its mandatory reporting obligations under applicable airworthiness regulations.
Select a product with known safety-critical characteristics. Trace 2 safety-critical features from the customer drawing through the work instruction, inspection plan, and inspection records. Verify enhanced controls exist at each stage.
- How do you distinguish a nonconformity on a safety-critical characteristic from a nonconformity on a non-critical characteristic in your NCR process?
- What are your mandatory reporting obligations to airworthiness authorities, and when was the last time you had to report a product safety event?
- Show me how safety-critical characteristics flow from the customer drawing through your work instructions and inspection plan.
8.1.4 Has the organization established a documented process to prevent counterfeit or suspect counterfeit parts from entering the supply chain, addressing all procurement channels including brokers and independent distributors?
- Counterfeit parts prevention plan or procedure — verify it addresses: authorized sourcing, receiving inspection and authentication, personnel awareness training, reporting and quarantine procedures, and flow-down requirements to sub-tier suppliers
- Approved supplier list distinguishing between OEM/authorized distributors and independent/broker sources — verify that procurement from non-authorized sources triggers additional authentication controls
- Receiving inspection records for high-risk parts showing authenticity verification steps — visual inspection, part marking verification, lot/date code verification, and where applicable, electrical testing or destructive testing
- Training records showing personnel responsible for procurement and receiving are trained on counterfeit part identification and awareness — including awareness of GIDEP, ERAI, or other industry reporting systems
- Records of any suspect counterfeit part events — investigation records, quarantine actions, and reports to industry databases (GIDEP/ERAI) and customers
- Organization procures electronic components from independent distributors and brokers without any additional authentication testing or verification beyond standard receiving inspection — the counterfeit prevention process does not differentiate risk based on procurement source (Major NC).
- Counterfeit parts prevention procedure exists but does not address all procurement channels — raw material procurement, hardware (fasteners, bearings), and externally processed items are excluded from the scope (Minor NC).
- No personnel have been trained on counterfeit part identification — purchasing agents and receiving inspectors are unaware of common counterfeit indicators or industry reporting databases (Minor NC).
- Organization has no process for reporting suspect counterfeit parts to industry databases (GIDEP, ERAI) or to affected customers — suspect parts are scrapped without external notification (Minor NC).
Counterfeit parts are a real and growing threat in aerospace, particularly for electronic components, fasteners, and bearings. The most critical audit point is whether the organization distinguishes between authorized and unauthorized procurement sources. Buying from the OEM or an authorized distributor provides chain-of-custody traceability; buying from a broker does not and requires additional authentication. Ask to see the approved supplier list and check whether it identifies which suppliers are OEM-authorized. Then verify that purchases from non-authorized sources receive enhanced receiving inspection. Also check whether the organization participates in industry counterfeit reporting systems — this is increasingly expected by primes and regulatory bodies.
Review 5 recent purchase orders. For each, verify the supplier is on the approved supplier list and identify whether the source is OEM-authorized or independent. For any purchases from non-authorized sources, verify enhanced authentication controls were applied at receiving.
- Do you ever procure parts or materials from independent distributors, brokers, or non-authorized sources? If so, what additional controls do you apply?
- What would happen if your receiving inspector identified a suspect counterfeit part — walk me through the process.
- Are you registered with GIDEP or ERAI, and have you ever submitted or received a counterfeit alert?
8.1.4 Are counterfeit parts prevention requirements flowed down to sub-tier suppliers and external providers, and does the organization verify compliance with these requirements?
- Purchase order quality clauses or supplier quality requirements document that includes explicit counterfeit parts prevention requirements — verify these are applied to sub-tier suppliers, not just the organization's internal process
- Supplier audit checklists or assessment questionnaires that include counterfeit parts prevention evaluation criteria — verify at least 2 supplier audits included this topic
- Evidence of supplier corrective actions related to counterfeit prevention — supplier nonconformities, audit findings, or quality alerts addressing traceability or authenticity concerns
- Contractual requirement for sub-tier suppliers to report suspect counterfeit findings — verify the flow-down clause requires notification to the organization
- Purchase orders reference 'AS9100D requirements apply' generically but do not specifically flow down counterfeit parts prevention requirements — sub-tier suppliers are not explicitly required to have a counterfeit prevention process (Minor NC).
- Supplier audits do not evaluate counterfeit parts prevention — the audit checklist covers quality system elements but omits questions about sourcing controls, authentication, and counterfeit awareness (Observation).
- No contractual requirement exists for sub-tier suppliers to report suspect counterfeit parts — if a Tier 2 supplier discovers a counterfeit, there is no defined obligation to notify the organization (Minor NC).
Counterfeit prevention is only effective if it extends through the supply chain. An organization with a robust internal process can still receive counterfeit parts if sub-tier suppliers lack equivalent controls. Check purchase orders for specific counterfeit prevention clauses — a generic 'AS9100D applies' reference is insufficient because sub-tier suppliers may not know which specific requirements to implement. Also verify that the organization monitors its supply chain for counterfeit risk, particularly when sub-tier suppliers change sources or when parts are in allocation.
Select 2 purchase orders to sub-tier suppliers. Verify each includes specific counterfeit prevention flow-down requirements. Review the most recent audit of one of these suppliers and verify counterfeit prevention was evaluated.
- Show me the specific quality clauses on a purchase order to a sub-tier supplier — where is the counterfeit prevention requirement?
- During your last supplier audit, what did you evaluate regarding the supplier's counterfeit prevention controls?
- If a sub-tier supplier discovered they received counterfeit material, how would you be notified?
§8.2 Requirements for products and services
8.2.1 Does the organization's customer communication process ensure that all applicable requirements — including product requirements, contract requirements, customer quality clauses, and regulatory requirements — are identified and understood before production begins?
- Contract review procedure addressing identification of all applicable requirements — customer technical requirements, customer quality clauses (Boeing D1-4426, Airbus AQSF, etc.), applicable regulatory requirements, special process requirements, and delivery/packaging requirements
- Contract review records for at least 2 recent orders — verify all applicable requirements were identified and ambiguities were resolved before acceptance
- Process for identifying changes in customer requirements after initial contract
- Contract review focuses on commercial terms but does not systematically identify technical and quality requirements — customer quality clauses on the PO are not reviewed or flowed down (Major NC).
- Customer specification was updated 6 months ago but the organization is still producing to the previous revision (Minor NC).
- Customer requirements are documented in sales but not communicated to production planning or quality (Minor NC).
In aerospace, customer requirements extend far beyond the drawing. Most primes have quality clause documents imposing dozens of additional requirements. Verify that the contract review process identifies these and communicates them to the functions that must implement them.
Select 2 recent customer orders from different customers. For each, verify all applicable requirements were identified during contract review and communicated to production and quality.
- How do you identify all the quality and technical requirements associated with a new customer order — beyond just the drawing?
- Can you show me a recent order and walk me through how the customer's quality clauses were identified and implemented?
- How do you monitor for changes to customer requirements on existing long-term contracts?
8.2.2 Does the contract review process include an assessment of the organization's capability to meet all requirements — including manufacturing capability, capacity, delivery timeline, special process capability, and risk associated with new products or processes?
- Contract review records that include capability and capacity assessment
- Risk assessment for new products or processes — orders involving new manufacturing processes or tight tolerances receive a risk evaluation
- Delivery feasibility assessment — organization evaluates whether the requested delivery date can be met given current backlog and resource availability
- Contract review does not assess manufacturing capability — orders accepted for processes or tolerances never produced without risk assessment (Minor NC).
- Delivery feasibility is not assessed — orders accepted based on customer's requested date without evaluating achievability (Minor NC).
- New product introduction does not include risk assessment — first-time part with complex geometry accepted without manufacturing feasibility study (Major NC).
The contract review is the organization's first opportunity to identify risks. If the organization has chronic OTD problems, one root cause may be accepting orders without adequate delivery feasibility assessment.
Select 1 order for a part the organization had not produced before. Verify that a capability assessment was performed during contract review.
- How do you evaluate whether you can manufacture a new part before accepting the order?
- Walk me through a recent order where you identified a capability gap during contract review.
- How do you assess delivery feasibility?
8.2.3 When customer requirements change after order acceptance — including drawing revisions, specification updates, and quantity or schedule changes — does the organization review the impact, update affected documentation, and communicate changes to all relevant functions before implementation?
- Change management process for customer requirement changes after order acceptance
- Records of recent customer-initiated changes — impact assessed, affected documents updated, and changes communicated before implementation
- Traceability of which products were produced to which revision of requirements
- Customer issued a drawing revision but the production work instruction was not updated before the next production run (Major NC).
- No formal process exists for managing changes to customer requirements after order acceptance (Minor NC).
- Purchase orders to suppliers were not updated to reflect a customer specification change (Minor NC).
Customer-initiated changes must propagate through the entire production system. The most common failure is a change being received by engineering but not flowing to the shop floor before the next production run.
Identify a customer-initiated change from the past 6 months. Trace it from receipt through impact assessment, documentation updates, production implementation, and purchasing updates.
- Walk me through the last customer-initiated engineering change — how was it received, assessed, and implemented?
- How do you ensure work-in-process is managed during a change?
- How quickly can you implement a customer-initiated change?
§8.3 Design and development
8.3.2 Does design planning include identification of design review stages (PDR, CDR), verification and validation activities, and consideration of product safety, key characteristics, and configuration management requirements?
- Design and development plan defining: design phases, review milestones (PDR, CDR, TRR), verification activities (analysis, inspection, test), and validation activities
- Product safety requirements addressed in design planning — safety risk assessment (DFMEA) and verification of safety requirements
- Key characteristics identified in the design plan
- Configuration management integration — baseline establishment, change control, and status accounting during design
- Design plan does not include formal design review milestones — reviews occur informally without entry/exit criteria (Minor NC).
- Product safety is not addressed in design planning — no DFMEA is planned or performed (Major NC for safety-critical products).
- Key characteristics are identified at the end of the design process rather than during design (Observation).
Design planning in aerospace is significantly more structured than in general manufacturing. Verify that the design plan includes the classic aerospace review gates (PDR, CDR) with defined entry/exit criteria.
Select a current or recent design project. Review the design plan for: defined review stages, safety risk assessment, key characteristic identification, and configuration management integration.
- Walk me through the design review milestones for a current project.
- At what point in the design process do you identify safety-critical and key characteristics?
- How is configuration management integrated into your design process?
8.3.5 Do design outputs include identification of safety-critical characteristics, key characteristics, and any specific manufacturing, inspection, or testing requirements needed to ensure product conformity and safety?
- Design output documents (drawings, specifications) identify: safety-critical characteristics (with appropriate symbols), key characteristics, material specifications, special process requirements, and acceptance criteria
- Safety-critical characteristics flagged on drawings per customer requirements
- Design outputs include manufacturing considerations — producibility, inspectability, and testability considered
- Design outputs do not identify safety-critical or key characteristics (Minor NC).
- Design outputs do not specify special process requirements — drawing calls for heat treatment but does not reference the applicable specification (Minor NC).
- Design outputs lack sufficient manufacturing information (Observation).
Design outputs are the interface between engineering and manufacturing. Key characteristics and safety-critical characteristics must be explicitly identified — if the drawing does not distinguish them, production has no basis for applying enhanced controls.
Select 2 design output packages. Verify: safety-critical and key characteristics are identified, material and process specifications are referenced with revisions, and manufacturing requirements are defined.
- How do you identify and mark safety-critical and key characteristics on your design outputs?
- How do you ensure your designs are producible?
- Show me a drawing output and walk me through the specification callouts.
8.3.6 Are design changes controlled through the configuration management process, including impact assessment, approval by appropriate authority (including customer approval where required), and verification that changes do not adversely affect product safety or conformity?
- Design change control procedure integrating with configuration management — defines change request, impact assessment (safety, performance, producibility, interchangeability), approval authority, implementation, and verification
- Recent design change records — impact assessment performed including safety evaluation, customer approval obtained where required, verification completed
- Configuration baseline updated after design change
- Design changes implemented without formal impact assessment (Major NC).
- Customer approval not obtained for a design change affecting customer-specified requirements (Major NC).
- Design change incorporated but configuration baseline not updated (Minor NC).
Design changes are where configuration management, product safety, and customer requirements intersect. The most critical check is whether safety impact was assessed. Also verify interchangeability implications for spare parts.
Select 2 recent design changes. For each, verify: impact assessment (including safety), appropriate approvals, verification, and configuration baseline update.
- Walk me through the last design change — how was the safety impact assessed?
- How do you determine whether a design change requires customer approval?
- When a design change is incorporated, how do you manage spare parts and products already in service?
§8.4 Control of external providers
8.4 When work is transferred between external providers — or between an external provider and the organization's own facilities — is there a defined process to ensure product conformity is maintained during and after the transfer?
- Work transfer procedure or plan defining the process for transferring production between suppliers, between facilities, or from a supplier to in-house (or vice versa) — verify it addresses risk assessment, validation, and customer notification
- Records of recent work transfers — risk assessment, transfer validation plan, first article inspection at the receiving location, comparison of product quality before and after transfer, and customer approval if required
- Evidence that key process parameters, tooling, work instructions, and inspection criteria were transferred and verified at the new location — not just documents but actual process capability demonstrated
- Customer notification and approval records where required by contract — many primes require notification and approval before production can be moved
- Production was transferred from an external supplier to in-house manufacturing without a formal work transfer plan — no risk assessment, no first article inspection at the new location, and no comparison of product quality before and after transfer (Major NC).
- Work transfer process exists but does not require customer notification or approval — production was moved to a different facility without informing the customer, violating contractual requirements (Major NC).
- Work was transferred but the special process qualifications at the new location were not verified — heat treat qualification at the receiving facility had expired at the time of transfer (Major NC).
- No process exists for work transfer — the organization has no defined approach for managing the transition when production moves between locations or suppliers (Minor NC).
Work transfer is one of the highest-risk activities in aerospace manufacturing. When production moves — whether from a supplier to in-house, between facilities, or between suppliers — every aspect of the process must be revalidated at the new location. The most common failure is treating work transfer as a logistics exercise rather than a quality event. Ask whether any work transfers have occurred in the past 24 months. If yes, audit the transfer records thoroughly. If no, verify that a documented process exists for when it does occur. Also check whether the work transfer process includes customer notification requirements — most prime contracts require this.
If a work transfer has occurred, review the complete transfer package: risk assessment, validation plan, FAI results at new location, quality comparison data, and customer approval records. If no transfer has occurred, review the documented procedure for completeness.
- Have you transferred any production work in the past 24 months — either to or from a supplier, or between your own facilities?
- What would trigger a work transfer, and what approvals are required before it can proceed?
- How do you validate that the receiving location can produce conforming product before releasing production from the originating location?
8.4.1 Does the organization apply risk-based criteria for the evaluation, selection, monitoring, and re-evaluation of external providers, considering the effect of the externally provided product or service on the organization's ability to deliver conforming product?
- Supplier evaluation and selection procedure that defines risk-based criteria — verify criteria are tiered based on the criticality of the supplied item (e.g., safety-critical raw materials receive more scrutiny than office supplies)
- Approved Supplier List (ASL) with defined evaluation status for each supplier — verify status categories (approved, conditional, probationary, suspended) and the criteria for each
- Initial supplier evaluation records for at least 2 recently approved suppliers — verify evaluations considered quality system certification (AS9100D, ISO 9001, Nadcap), facility audit results, financial stability, and capacity
- Re-evaluation records or supplier scorecards — verify suppliers are periodically re-evaluated and that re-evaluation results affect their ASL status
- All suppliers are evaluated using identical criteria regardless of the criticality of what they supply — a fastener supplier providing safety-critical hardware is evaluated with the same questionnaire as a janitorial supplies vendor (Minor NC).
- Supplier evaluation records consist of a self-assessment questionnaire only — no verification audit, on-site visit, or objective evidence review was performed for suppliers providing critical or special-process services (Minor NC).
- Suppliers have been on the approved list for 5+ years without any re-evaluation — the initial evaluation was performed when AS9100C was current and no reassessment against AS9100D requirements has been conducted (Minor NC).
- Several suppliers on the ASL have been flagged for poor delivery or quality performance in scorecards but remain in 'approved' status with no action taken — the monitoring data is collected but not used for re-evaluation decisions (Major NC).
The risk-based approach means the depth and frequency of evaluation should match the risk of the supplied item. A supplier providing flight-critical forgings should receive a more thorough evaluation (including on-site audit) than a supplier providing packaging materials. Ask to see the risk classification criteria and then select one 'high risk' and one 'low risk' supplier — verify the evaluation depth differs. Also check whether customer-approved supplier requirements are maintained — many primes require use of their approved suppliers for certain commodities.
Select 1 high-risk and 1 low-risk supplier from the ASL. Compare the depth of their initial evaluations and frequency of re-evaluations. Verify evaluation depth is proportional to risk.
- How do you classify suppliers by risk, and what different evaluation criteria apply to each risk level?
- Show me a supplier that was downgraded or suspended based on performance data — what triggered the action?
- Do any of your customers require you to use their approved suppliers for certain commodities? If so, how do you manage that requirement?
8.4.1 Does the organization monitor external provider performance, including on-time delivery and quality metrics, and take action when performance targets are not met?
- Supplier performance monitoring system — scorecards, dashboards, or reports tracking at minimum: on-time delivery (OTD), incoming quality (lot acceptance rate, PPM), and corrective action responsiveness
- Supplier performance data for the past 12 months — verify data is current, trended, and reviewed at defined intervals
- Evidence of action taken on underperforming suppliers — corrective action requests (SCARs), improvement plans, increased inspection, probation notices, or supplier development activities
- Evidence that supplier performance data is used in re-evaluation and ASL status decisions — performance below threshold triggers defined consequences
- Supplier scorecards are generated quarterly but there is no evidence they are communicated to suppliers or that poor scores trigger any action — monitoring exists but the management loop is not closed (Minor NC).
- Supplier on-time delivery is not tracked — only incoming quality is monitored, despite delivery performance being a specific AS9100D requirement (Minor NC).
- A critical supplier has delivered below the quality target for 3 consecutive quarters but no Supplier Corrective Action Request has been issued — the organization continues to use the supplier without improvement action (Major NC).
- Supplier performance monitoring covers only direct material suppliers — calibration service providers, special process providers (heat treat, plating, NDT), and test laboratories are not monitored (Minor NC).
AS9100D specifically requires monitoring of external provider OTD and quality performance — this is not optional. The most common gap is collecting data without acting on it. Ask to see the supplier with the worst performance in the past year and verify what actions were taken. If the answer is 'nothing,' the monitoring system is a data collection exercise, not a management tool. Also verify that special process providers and calibration labs are included in monitoring — organizations frequently limit supplier performance tracking to direct material suppliers.
Review supplier performance data for the past 12 months. Identify the 3 worst performers by OTD and quality. For each, verify what actions were taken and whether performance improved.
- What is the OTD and quality performance of your worst-performing supplier over the past 12 months, and what actions have you taken?
- How do you monitor the performance of your special process providers (heat treat, plating, NDT)?
- At what performance threshold do you escalate from monitoring to corrective action?
8.4.1 Does the organization maintain a process for managing the risk of supply chain disruption, including identification of single-source and sole-source dependencies, and development of contingency plans for critical suppliers?
- Supply chain risk assessment identifying single-source and sole-source dependencies
- Contingency plans for critical suppliers addressing alternative sourcing, safety stock, or in-house capability development
- Evidence that supply chain risk is monitored through leading indicators
- Organization has not identified single-source and sole-source dependencies (Minor NC).
- Supply chain risk is identified but no contingency plans are developed (Minor NC).
Supply chain resilience is increasingly important in aerospace. For each sole-source supplier, ask what would happen if they could not deliver.
Request the list of sole-source suppliers. For the top 3 critical dependencies, verify whether contingency plans exist.
- How many of your suppliers are sole-source?
- What would you do if your sole-source heat treat provider could not process your parts for 3 months?
- Have you experienced a supply chain disruption in the past 2 years?
8.4.2 Are applicable requirements — including customer and regulatory requirements — flowed down to external providers, and does the flow-down include right of access for the organization, customer, and regulatory authorities?
- Purchase order quality clauses or supplier quality requirements document — verify it includes: applicable standard requirements (AS9100D, customer specs), flow-down of customer requirements, right of access provisions, notification of changes, and record retention requirements
- Specific flow-down items verified on at least 2 purchase orders: notification of nonconforming product, notification of changes to product or process, requirement to flow down applicable requirements to sub-tiers, and right of access for customer and regulatory authority representatives
- Evidence that flow-down is verified in practice — supplier audit records showing flow-down effectiveness was evaluated, or receiving inspection records showing supplier certifications reference the correct specifications
- Customer-specific quality clauses that must be flowed down — verify the organization has identified which customer requirements require flow-down and has implemented them in purchasing documents
- Purchase orders reference 'applicable specifications per drawing' but do not flow down customer-specific quality clauses, AS9100D requirements, or right-of-access provisions — the supplier receives technical requirements but not quality system requirements (Major NC).
- Right of access for customer representatives and regulatory authorities is not included in purchasing documents — the organization cannot guarantee its customer can audit sub-tier suppliers (Minor NC).
- Flow-down to sub-tier suppliers stops at Tier 1 — the organization's suppliers are not required to flow down applicable requirements to their own suppliers, creating a gap in the supply chain (Minor NC).
- Customer requirement to notify the organization of process or product changes is not flowed down to suppliers — a supplier changed their heat treat source without notification (Major NC).
Flow-down is one of the highest-finding areas in AS9100D audits. Pull 3 purchase orders and review the quality clauses line by line. Verify that each required flow-down item is present. The most commonly missed items are: right of access for customer and regulatory authorities, requirement to notify of process or product changes, requirement to use customer-designated sources, and requirement to flow down applicable requirements to sub-tiers. Also check whether customer-specific quality clauses (Boeing D1-4426 Q-clauses, Airbus AQSF clauses, etc.) are flowed down where applicable.
Pull 3 purchase orders to different suppliers. For each, verify the presence of: (1) applicable specification flow-down, (2) right of access clause, (3) change notification requirement, (4) sub-tier flow-down requirement, and (5) customer-specific quality clauses where applicable.
- If your customer wanted to audit one of your sub-tier suppliers, is there a contractual basis for that access? Show me the clause.
- What happens when a supplier changes a process — such as switching NDT providers or relocating production? How would you be notified?
- How do you verify that your Tier 1 suppliers flow down applicable requirements to their sub-tiers?
8.4.3 Does the organization communicate all applicable requirements to external providers, including requirements for the approval of products, processes, methods, equipment, and the release of products and services — and does this include customer-required source inspection?
- Purchase orders that specify: applicable product requirements (part number, revision, specification), process requirements (special process specifications, qualification requirements), required certifications and test reports to be provided with the product, and any customer-required source inspection or witness points
- Evidence that customer-required source inspection requirements are flowed down — where customers require source inspection at sub-tier suppliers, verify the requirement appears on the purchase order
- Process for communicating changes in requirements to suppliers — verify that when a customer issues a revised specification or drawing, the change is communicated to affected suppliers in a timely manner
- Evidence of supplier receipt acknowledgment — verify suppliers confirm receipt and understanding of requirements, especially for new or changed requirements
- Purchase orders specify the part number but not the applicable specification revisions — the supplier is producing to 'latest revision' without the organization controlling which revision is current (Minor NC).
- Customer requires source inspection at a sub-tier special process provider but this requirement is not communicated to the supplier — the customer arrives for inspection with no advance notification and no arrangements in place (Major NC).
- When engineering changes are issued, updated specifications are sent to affected suppliers but no verification of receipt or acknowledgment is obtained — the organization cannot confirm suppliers are aware of the change (Minor NC).
Check the specificity of purchase orders — vague references like 'per drawing' or 'per specification' without revision levels are common and create risk. Also verify that when the organization receives a customer engineering change, the impact on purchased items is assessed and changes are communicated to affected suppliers with evidence of communication. For source inspection requirements, trace from the customer contract through to the sub-tier purchase order to verify the requirement is preserved.
Select 2 purchase orders for different commodities. Verify specification revisions match current customer requirements. If customer source inspection is required for either commodity, verify the requirement is communicated on the PO.
- How do you ensure that the specification revisions on your purchase orders match the current customer requirements?
- Walk me through how a customer engineering change affecting a purchased component is communicated to the affected supplier.
- Which of your customers require source inspection at your facility or at your sub-tier suppliers, and how is this managed?
§8.5 Production and service provision
8.5.1 Does the organization perform First Article Inspection (FAI) in accordance with customer requirements — including after design changes, process changes, tooling changes, facility relocations, and extended production breaks — and are FAI records maintained per AS9102 or equivalent?
- FAI procedure defining when FAI is required — verify triggers include: new part, design change (drawing revision), process change, tooling change, material source change, facility relocation, production gap exceeding the defined interval, and customer request
- Completed FAI reports (AS9102 forms or equivalent) for at least 3 parts — verify all three forms are present: Form 1 (Part Number Accountability), Form 2 (Product Accountability — Raw Material, Special Processes, Functional Testing), Form 3 (Characteristic Accountability — all dimensions and notes)
- Evidence that FAI results show 100% characteristic conformity — all numbered balloon dimensions inspected with actual measured values, not just pass/fail notation
- FAI records traceable to the specific serial number or lot of the first article — verify the actual inspected part is identified, not a generic 'representative' part
- Evidence that partial FAI is used appropriately when changes affect only a portion of the design — verify the scope of partial FAI is justified and documented
- FAI was not performed after a drawing revision change — production continued on the new revision without first article verification, and the organization's procedure does not identify drawing revision changes as a FAI trigger (Major NC).
- FAI forms are incomplete — Form 3 (Characteristic Accountability) lists dimensions as 'conforming' without recording actual measured values, making it impossible to assess margins or trends (Minor NC).
- FAI was performed but not all characteristics on the drawing were included — the ballooned drawing is missing numbered callouts for several dimensions and notes, so the characteristic accountability is incomplete (Minor NC).
- No FAI was performed after a production gap of 18 months — the organization's procedure defines a 24-month trigger but the customer contract specifies a 12-month trigger that was not identified (Major NC).
- Partial FAI is used but the justification for limiting the scope is not documented — it is unclear which characteristics were affected by the change and why others were excluded (Minor NC).
FAI is one of the most tangible and auditable AS9100D requirements. Pull the ballooned drawing and the AS9102 forms side by side. Every numbered characteristic on the drawing should have a corresponding entry on Form 3 with an actual measured value. Check that the FAI was performed on an actual production part (not a prototype), using production tooling, production personnel, and production processes. Verify the FAI trigger matrix — the most commonly missed triggers are material source changes and production gaps. Also check whether customer-specific FAI requirements (number of samples, specific characteristics to highlight, submission requirements) have been identified and addressed.
Select 2 parts with recent FAI — 1 full FAI (new part) and 1 partial FAI (change-driven). For each, verify: ballooned drawing completeness, Form 1-3 completeness, actual measured values recorded, traceability to the inspected part, and that the FAI trigger was appropriate.
- Walk me through your FAI trigger criteria — what events require a new or partial FAI?
- How do you handle a FAI when the first article has nonconforming characteristics — what is the process for resolution?
- Do any of your customers require FAI submissions for review and approval before production release? How do you manage that?
8.5.1 Has the organization identified key characteristics of the product and manufacturing process, and are key characteristics subject to specific controls including process capability measurement and enhanced monitoring?
- Key characteristics identified on engineering drawings, specifications, or control plans — verify key characteristics are distinguished from other characteristics with appropriate symbols or designations (customer-defined key characteristic symbols, KC flags)
- Process capability data (Cpk/Ppk) for key characteristics — verify studies have been performed using a statistically valid sample size and that capability indices meet minimum requirements (typically Cpk ≥ 1.33)
- SPC charts or enhanced monitoring plans for key characteristics in current production — verify data is collected at the defined frequency and analyzed for trends, shifts, and out-of-control conditions
- Reaction plans for out-of-control conditions on key characteristics — documented response when SPC signals or capability deterioration are detected, including containment, investigation, and corrective action
- Evidence that key characteristics flow through from design to production to inspection — verify the inspection plan gives key characteristics enhanced attention (100% inspection, tighter sampling, SPC)
- Customer drawings identify key characteristics but the organization's control plan and inspection plan do not distinguish them from other characteristics — key characteristics receive the same sampling rate and inspection method as general dimensions (Minor NC).
- Process capability studies have not been performed for key characteristics — the organization inspects 100% but does not know whether the process is capable, which means they are inspecting quality in rather than building quality in (Minor NC).
- SPC charts are maintained for key characteristics but there is no documented reaction plan for out-of-control signals — operators do not know what to do when a point falls outside control limits (Minor NC).
- Key characteristics are identified on customer drawings but the organization has not identified its own manufacturing process key characteristics — the connection between product key characteristics and the process parameters that control them is not made (Observation).
Key characteristics (KCs) bridge design intent and manufacturing reality. The auditor should verify that KCs flow from the customer drawing through the organization's work instructions, control plan, and inspection records. Check that KCs receive enhanced attention — if a KC is inspected with the same method and frequency as a non-critical dimension, the system is not differentiating. Ask to see Cpk data for at least one KC and verify the organization knows whether their process is capable. If Cpk is below 1.33, verify what actions have been taken. Also check whether the organization distinguishes between customer-identified KCs and internally identified KCs — both should be managed.
Select a product with identified key characteristics. Verify: (1) KCs are flagged on the work instruction and inspection plan, (2) Cpk data exists and meets the minimum, (3) SPC or enhanced monitoring is active in current production, (4) a reaction plan exists and has been followed at least once.
- How do you identify key characteristics, and where are they documented in your production system?
- What is the current Cpk for the key characteristic on the product you are running right now?
- Show me what happens when an SPC chart for a key characteristic goes out of control — walk me through the last occurrence.
8.5.1 Has the organization implemented actions to prevent human error in production, including error-proofing (poka-yoke), visual controls, and process design that reduces dependence on operator attention?
- Human error prevention strategy or program — documented approach to identifying and mitigating human error risks in production processes, beyond just training
- Error-proofing devices or techniques implemented at workstations — poka-yoke fixtures, go/no-go gauges, color coding, asymmetric tooling, barcode scanning for part verification, or other mistake-proofing methods
- Evidence that human error is considered in PFMEA — verify that FMEAs identify potential human error failure modes and that recommended actions include error-proofing, not just 'retrain operator'
- Records showing response to human error events — when an operator error causes a nonconformity, verify the corrective action goes beyond retraining to address systemic causes (process design, visual controls, workstation layout)
- Corrective actions for operator errors consistently default to 'retraining' without addressing the process conditions that enabled the error — 5 of the last 8 operator-error CAPAs have 'retrain operator' as the sole corrective action (Minor NC).
- No error-proofing devices or techniques are implemented despite repetitive human error nonconformities on the same operation — the organization has not applied poka-yoke or equivalent methods (Observation).
- PFMEA does not consider human error as a failure mode — all failure modes are process- or equipment-related, and the human element of each operation is not assessed (Observation).
AS9100D explicitly requires actions to prevent human error — this goes beyond ISO 9001. The most telling indicator is the organization's response to operator errors. If the corrective action is always 'retrain,' the system is reactive rather than preventive. Look for evidence of genuine error-proofing: poka-yoke fixtures, go/no-go gauges, visual aids, barcode verification, or process redesign. Ask to see the last 5 operator-error nonconformities and evaluate whether the corrective actions address root causes or just blame the operator. Also check whether workstation design considers human factors — lighting, ergonomics, clutter, and distraction potential.
Review the last 5 nonconformities attributed to human error. Evaluate whether corrective actions include systemic improvements (error-proofing, process redesign, visual controls) or default to retraining only. Walk the floor and look for poka-yoke devices at high-risk operations.
- Can you show me an example of a poka-yoke or error-proofing device on the shop floor?
- When an operator makes an error that results in a nonconformity, what types of corrective actions do you typically implement beyond retraining?
- How do you identify which operations have the highest risk of human error?
8.5.1 Does the organization control production processes using control plans or equivalent documents that define the production steps, in-process verification points, inspection criteria, and the sequence of operations — including customer-required verification hold points?
- Control plans, manufacturing process plans, or travelers/routers for current production parts — verify they define: operation sequence, workstation/equipment, inspection points and methods, acceptance criteria, and required tooling
- Customer-required hold points or witness points identified in production documentation — verify these are flagged and that production cannot proceed past a hold point without the required authorization (customer inspection sign-off, QA verification)
- Evidence of in-process verification at defined stages — inspection records, SPC data, or operator verification stamps at each required verification point along the traveler/router
- Process change control — evidence that changes to production processes (sequence, parameters, methods) are evaluated and approved before implementation, including assessment of impact on FAI validity
- Manufacturing traveler does not identify customer-required hold points — the customer contract specifies source inspection before plating, but this is not reflected in the production documentation and parts proceed through plating without notification (Major NC).
- Control plan specifies in-process inspection at operation 30 but production records for the last 3 lots show no evidence of in-process inspection — the inspection was either not performed or not recorded (Minor NC).
- Production sequence was changed (operations reordered) without engineering review or impact assessment — the change was made by a production supervisor to improve throughput without evaluating the effect on product quality (Minor NC).
- No control plan or equivalent exists for a production part — work instructions exist for individual operations but no document defines the end-to-end sequence, inspection points, and acceptance criteria (Minor NC).
Follow a traveler through the shop. At each operation, verify that the work is being performed as documented — the right equipment, the right tools, the right parameters, the right inspection. Pay particular attention to customer-required hold points — if a customer contract specifies a witness point and the production documentation does not flag it, parts may be processed past the hold point before the customer is notified. Also check for undocumented process changes — interview operators and ask 'Do you ever do this operation differently than what the work instruction says?' The answer often reveals informal process changes that have not been evaluated or approved.
Select 1 active production order. Follow the traveler from the first operation to the current operation. Verify at each completed operation: inspection records exist where required, operator stamps/signatures are present, and hold points were observed. Verify the production sequence matches the control plan.
- Does this customer require any source inspection, hold points, or witness points? If so, show me where they appear in the production documentation.
- Walk me through this traveler — at which points is in-process inspection required, and what happens if a part fails at that point?
- Has the sequence of operations for this part ever been changed? If so, was the change reviewed and approved?
8.5.1 Has the organization implemented a Foreign Object Debris/Damage (FOD) prevention program appropriate to the product and processes, including FOD awareness training, clean-as-you-go practices, tool control, and defined clean zones?
- FOD prevention procedure or program document — verify it defines: FOD risk areas, clean-as-you-go requirements, tool accountability, hardware accountability, personal item controls, and FOD inspection requirements at defined production stages
- FOD training records for production personnel — verify training covers FOD awareness, prevention methods, and reporting requirements
- FOD control zone designations and signage on the shop floor — verify zones are defined, maintained, and monitored (clean manufacturing areas, assembly areas, final packaging areas)
- Tool control records — shadow boards, tool inventories, or equivalent systems that account for all tools at the beginning and end of each operation, particularly for work inside assemblies or cavities
- FOD incident records — any FOD events documented with investigation, containment, and corrective action
- No formal FOD prevention program exists despite the organization assembling products with enclosed cavities where FOD could cause functional failure — ad hoc cleaning is performed but no systematic controls are in place (Major NC).
- Tool control is inconsistent — shadow boards are present at some workstations but tools are not accounted for at the end of each shift, and there is no defined process for reporting a missing tool (Minor NC).
- FOD training was last conducted 3 years ago for current employees, and new employees have not received FOD training as part of onboarding — the training program is not maintained (Minor NC).
- Assembly area is not designated as a FOD-controlled zone — food, drinks, and personal items are present at workstations where enclosed assemblies are being built (Observation).
FOD is one of the leading causes of in-service failures in aerospace. Walk the shop floor and observe — is the area clean? Are tools accounted for? Are there loose fasteners, debris, or personal items in work areas? Check tool shadow boards and ask an operator to demonstrate the end-of-shift tool inventory process. For assembly operations (especially those involving enclosed structures like fuel tanks, wing boxes, or engine housings), verify that FOD checks are performed before closeout. Ask about the last FOD incident and how it was handled — if no incidents have ever been documented, the program may lack the reporting culture to detect FOD events.
Walk the production floor, focusing on assembly areas. Verify: (1) tool shadow boards are complete (no missing tools), (2) workstations in FOD-controlled zones are clean, (3) FOD inspection is documented before any closeout or sealing operation, (4) personnel can describe FOD prevention requirements for their area.
- Walk me through your end-of-shift tool accountability process — how do you ensure no tools are left inside an assembly?
- When was the last FOD event, and what corrective actions were implemented?
- How do you control access and cleanliness in your final assembly and packaging areas?
8.5.1 Does the organization control temporary changes to production processes — such as temporary deviations, rework instructions, or process workarounds — to ensure they are authorized, time-limited, documented, and reverted when no longer needed?
- Procedure for managing temporary process changes defining authorization, documentation, time limits, and reversion
- Log of active and recently closed temporary changes with authorization, expiration, and evidence of reversion
- Verification that expired temporary changes have been reverted
- Temporary process deviations implemented by production supervisors without engineering approval or documentation (Minor NC).
- Temporary rework instructions have no defined expiration date (Minor NC).
- Active temporary changes are not logged (Observation).
Temporary process changes are a common source of uncontrolled variation. Ask the production supervisor whether any temporary changes are currently in effect.
Request the temporary change log. Verify at least 3 entries have authorization, scope, expiration date, and evidence of reversion or incorporation.
- Are any temporary process deviations currently in effect on the shop floor?
- How long can a temporary change remain active before it must be formally incorporated or reverted?
- Show me the log of temporary changes — are any past their expiration date?
8.5.1 Does the organization ensure that product marking and labeling comply with customer and regulatory requirements, including permanent identification marking methods, marking location, marking content, and any restrictions on marking methods for specific materials?
- Part marking procedure defining approved marking methods (laser etch, vibro-peen, ink stamp, electro-etch) and any restrictions by material type — verify that marking methods that could cause stress concentration or material degradation are controlled
- Customer-specific marking requirements identified and implemented — verify markings include required content (part number, serial/lot number, supplier code, material heat number where required)
- Marking verification at final inspection — verify that part marking is checked as part of the final inspection process
- Evidence that marking methods are validated for durability and legibility — markings must survive the product's intended service environment
- Part marking method is not approved for the material type — vibro-peen marking used on a thin-wall titanium component without customer approval, creating a potential stress concentration (Major NC).
- Required marking content is incomplete — parts are marked with part number only but the customer requires serial number, heat number, and supplier code (Minor NC).
- Marking legibility is not verified at final inspection — parts are shipped with illegible or partially visible markings (Minor NC).
Part marking in aerospace is both a traceability requirement and a potential source of product nonconformity. Some marking methods (vibro-peen, electro-etch) can create stress concentrations on thin or high-strength materials. Verify that the marking method is appropriate for the material and that any customer restrictions on marking methods are known and followed. Check a few parts at final inspection and verify markings are legible, complete, and in the correct location.
Select 3 parts at final inspection or finished goods. Verify: marking is legible, content matches requirements (part number, serial/lot, heat number where required), marking method is approved for the material, and marking location matches the drawing.
- How do you determine which marking method is appropriate for each material type?
- Do any of your customers restrict specific marking methods on certain materials?
- How do you verify marking legibility and completeness at final inspection?
8.5.1.2 Does the organization identify and validate every special process (any process whose output cannot be fully confirmed by later inspection or test), and maintain the related controls: equipment qualification, operator certification, and ongoing process-parameter monitoring?
- List of special processes performed by the organization — typically includes heat treating, welding, brazing, soldering, plating/coating, painting, NDT (nondestructive testing), shot peening, chemical processing, composite layup, and adhesive bonding
- Process validation records for each special process — equipment qualification (e.g., furnace surveys per AMS 2750 for heat treat), process capability data (Cpk studies where applicable), and defined process parameters with tolerances
- Personnel qualification records for special process operators — certifications per applicable standards (NAS 410 for NDT, AWS D17.1 for aerospace welding, etc.) that are current and maintained
- Ongoing process monitoring records — pyrometry records for heat treat, weld parameter logs, plating thickness measurements, or equivalent evidence that process parameters are controlled during production
- Nadcap accreditation certificates (where applicable) — verify scope covers the specific processes performed and accreditation has not lapsed
- Heat treat furnace has not had a temperature uniformity survey (TUS) per AMS 2750 within the required interval — the survey is 2 months overdue and parts have been processed during this period (Major NC).
- NDT personnel certifications are managed by individual employees rather than the organization — no centralized tracking system exists, and one Level II inspector's certification expired 3 months ago without detection (Major NC).
- Welding process validation was performed 8 years ago but the procedure, equipment, and materials have changed since then — no revalidation has been performed after changes (Minor NC).
- Special process parameters are specified in the work instruction but there is no evidence of monitoring during production — the instruction says 'heat treat at 1850°F ±25°F for 2 hours' but no time/temperature recording exists for recent lots (Major NC).
- Organization performs adhesive bonding as a special process but it is not identified as such — no validation, no process parameter controls, and no operator qualification exists for this process (Major NC).
Special processes are consistently the highest-risk area in aerospace manufacturing. The key question is: 'Can you verify the output of this process after the fact?' If not, it is a special process and must be validated. Walk the shop floor and identify all processes where the output cannot be fully verified by final inspection — these must all appear on the special process list. Common omissions include adhesive bonding, crimping, torquing to yield, and cleaning processes. For each special process, verify the three pillars: equipment is qualified, personnel are certified, and process parameters are monitored. If the organization outsources special processes, verify the sub-tier provider meets the same requirements.
Select 2 special processes (1 in-house, 1 outsourced if applicable). For the in-house process, verify equipment qualification, operator certification, and parameter monitoring records for the most recent production lot. For the outsourced process, verify the provider's Nadcap accreditation (scope and expiry) or equivalent qualification evidence.
- How did you determine which processes are special processes? Show me the analysis.
- For heat treatment, show me the most recent temperature uniformity survey and the production records showing time/temperature recording during the most recent batch.
- How do you ensure that special process parameter monitoring equipment (thermocouples, recorders, gauges) is calibrated and functioning correctly?
8.5.2 Does the organization maintain traceability from raw material through all manufacturing processes to the finished product, including traceability of acceptance authority (who accepted what and when)?
- Traceability procedure defining what must be traceable (serial numbers, lot numbers, heat numbers, process lot assignments) and at what level of granularity — verify the procedure addresses both product traceability and process traceability
- Traceability demonstration — select 1 finished product by serial or lot number and trace backward: material certification (heat number, mill test report), incoming inspection results, manufacturing records (operation logs, process records), in-process inspection results, final inspection and test results, and acceptance authority at each stage
- Acceptance authority identification — verify that inspection records identify who performed each inspection and who authorized acceptance, using personal stamps, electronic signatures, or employee identification numbers — not generic 'QA approved' stamps
- Traceability of special process records to product — verify heat treat certifications, plating thickness records, NDT results, and other special process records are traceable to the specific parts or lots processed
- Material certifications (mill test reports) are on file but cannot be linked to specific production lots — the organization receives material in bulk, assigns an internal lot number, but does not maintain the linkage between the internal lot and the material certification heat number (Major NC).
- Inspection records use a generic 'QA' stamp without identifying which inspector performed the inspection — when a question arises about a specific acceptance decision, it is not possible to determine who made it (Minor NC).
- Special process certifications (heat treat, plating) reference batch or load numbers but these cannot be traced to specific part serial numbers or production lots — the link between the processed parts and the process record is broken (Minor NC).
- Traceability is maintained through production but ends at final packaging — shipping records do not link serial numbers or lot numbers to specific customer purchase orders, preventing field traceability in case of recall (Minor NC).
Traceability in aerospace must be complete and bidirectional — from raw material to finished product AND from finished product back to raw material. The strongest test is to select a finished product (by serial or lot) and try to trace it backward through every stage. At each link in the chain, verify the traceability data is actually there, not theoretically possible. The most common break points are: (1) raw material to production lot, (2) production lot to special process batch, and (3) finished product to shipping/customer. Also verify acceptance authority traceability — AS9100D requires knowing who accepted the product at each verification point, which means generic stamps are insufficient.
Select 1 finished product from recent production. Trace backward through every stage: final inspection → in-process inspection → special process certifications → material certification. At each stage, verify the traceability link is documented and the acceptance authority is identified.
- Give me a serial number from a recent shipment — can you trace it back to the raw material certification right now?
- How do you maintain traceability when material from different heats is combined in the same production lot?
- If a customer reported a failure on serial number X, how long would it take to identify all other serial numbers from the same material lot and process lot?
8.5.4 Does the organization preserve products during production and delivery, including identification, handling, packaging, storage, and protection — with particular attention to shelf-life-limited materials, ESD-sensitive components, and environmentally sensitive items?
- Preservation procedure addressing aerospace-specific requirements — shelf-life-limited materials (adhesives, sealants, prepregs, chemicals), ESD-sensitive components, corrosion prevention, humidity-controlled storage, and temperature-sensitive items
- Shelf-life management system — verify materials with limited shelf life are tracked, FIFO (first in, first out) is practiced, expired materials are segregated and disposed, and re-test or re-certification protocols exist where allowed
- Storage area inspection records — verify storage areas are maintained per defined conditions (temperature, humidity, cleanliness) and inspected at defined intervals
- Packaging and shipping specifications that address product protection during transit — verify packaging methods prevent damage, corrosion, contamination, and ESD exposure
- Shelf-life-limited materials are in use in production with expired shelf life — adhesive in a dispenser at an assembly workstation has a shelf life that expired 2 months ago and there is no tracking system to detect this (Major NC).
- ESD-sensitive components are stored and handled without ESD protection — components in the production area lack ESD bags or grounding straps, and workstations are not equipped with ESD mats (Minor NC).
- FIFO is not practiced for raw materials — older stock is stored behind newer deliveries and there is no system to ensure the oldest material is used first (Minor NC).
- Finished products are stored in an uncontrolled warehouse exposed to temperature extremes and humidity — corrosion has been identified on stored parts awaiting shipment (Major NC).
Walk the storage areas — raw material, WIP, and finished goods. Look for shelf-life expiration dates, FIFO compliance, proper handling and protection, environmental controls, and cleanliness. Check the freezer for prepreg and adhesive materials — verify temperature monitoring records are current and within range. At workstations, check dispensers and containers for shelf-life expiration. In shipping, verify that packaging protects the product for the anticipated transit conditions. Preservation failures are visible — you should not need to ask for records to identify basic preservation issues.
Walk raw material storage, WIP areas, and finished goods storage. Check 3 shelf-life-limited materials for current status. Verify FIFO in at least 1 material storage area. Check 2 workstations for preservation compliance (ESD, cleanliness, handling).
- How do you track shelf-life-limited materials, and what happens when one reaches its expiration date?
- Show me your ESD control program — how do you verify grounding and protection at workstations?
- What packaging specifications do you follow for products shipped to customers, and who validates that the packaging is adequate?
8.5.5 Does the organization address post-delivery activities as required by customer contracts and regulatory requirements, including warranty obligations, maintenance and repair support, spare parts supply, and airworthiness directive compliance?
- Documented post-delivery obligations identified from customer contracts and regulatory requirements — verify the organization has identified and documented its specific obligations (warranty, in-service support, spare parts provisioning, airworthiness directive response)
- Process for responding to in-service issues — customer complaints, warranty claims, field returns, and requests for technical support — verify defined response timelines and responsibilities
- Records of post-delivery activities in the past 12 months — warranty claims processed, spare parts orders fulfilled, technical bulletins issued, or airworthiness directive responses
- Record retention adequate for product lifecycle — in aerospace, records must typically be retained for the life of the product (often 20-40 years for aircraft), verify the retention schedule reflects this obligation
- Post-delivery obligations are not documented — the organization responds to warranty claims and spare parts orders reactively but has not identified all contractual post-delivery obligations in a systematic way (Minor NC).
- Record retention period is defined as 7 years but customer contracts require retention for the life of the aircraft — records for products shipped more than 7 years ago have been destroyed, violating contractual requirements (Major NC).
- No process exists for responding to airworthiness directives or mandatory service bulletins that may affect the organization's delivered products — the organization does not monitor for AD applicability (Minor NC).
Post-delivery activities in aerospace extend far beyond warranty. Products in aerospace often remain in service for decades, and the manufacturer's obligations persist throughout that lifecycle. Verify the organization understands the full scope of its post-delivery obligations. The most common gap is record retention — if the organization destroys records per a generic 7-year policy, they may be in violation of customer or regulatory requirements that mandate life-of-product retention. Also check whether the organization monitors for airworthiness directives and service bulletins that could affect their products in the field.
Review 2 customer contracts for post-delivery requirements. Verify the organization has identified and can demonstrate compliance with these requirements. Check the record retention schedule against the longest contractual or regulatory retention requirement.
- What post-delivery obligations do you have under your current customer contracts?
- How long do you retain production and inspection records, and how did you determine that retention period?
- Do you monitor for airworthiness directives or service bulletins that could apply to products you have delivered?
8.5.6 Does the organization control changes to production and service provision to ensure continued conformity, including review and approval of changes before implementation, and retention of records describing the change and its effects?
- Production change control procedure defining what constitutes a change requiring approval, approval authority, implementation verification, and record retention
- Records of recent production changes with impact assessment, approval, and post-change verification including re-FAI where applicable
- Evidence that production changes trigger FAI assessment
- Production process parameter changed without formal evaluation or approval (Minor NC).
- Tooling replaced without assessing the impact on product conformity — no first article performed after the change (Minor NC).
- Material sourced from a new supplier without triggering a production change review (Minor NC).
Production changes are a leading cause of quality escapes in aerospace. Walk the floor and ask operators: 'Has anything changed recently?' This often reveals informal changes that did not go through formal channels.
Ask production management to identify 3 production changes in the past 12 months. For each, verify: change documented, impact assessed, approved, and post-change verification performed.
- What types of production changes require formal approval?
- Has any tooling, equipment, or material source changed in the past 6 months?
- How do you determine whether a production change requires a new FAI?
§8.6 Release of products and services
8.6 Does the product release process ensure that all planned verification activities are satisfactorily completed before products are authorized for delivery, including resolution of all nonconformities, completion of all documentation, and authorized sign-off?
- Product release procedure defining the sequence of verifications required before release is authorized — verify it includes: all inspection points completed, all NCRs resolved, all certifications received, documentation package complete, and authorized release signature
- Final inspection records for 3 recent shipments — verify all planned inspection points were completed with passing results, or that any nonconformities were properly dispositioned before release
- Documentation package completeness check — for at least 1 shipment, verify the delivery documentation includes all customer-required elements (C of C, material certs, special process certs, inspection data, traceability records)
- Evidence of authorized release — identify who signed the release authorization and verify they have documented authority to do so
- Product was released for shipment with an open nonconformity report — a pending NCR existed at the time of release but the shipment proceeded without disposition of the nonconformity (Major NC).
- Final inspection record is signed but the inspector did not perform all verifications listed in the inspection plan — 3 of 15 inspection points are not initialed, and there is no evidence the verifications were performed (Minor NC).
- Certificate of Conformity was issued before all special process certifications were received — the C of C was signed on a Monday but the plating certification was not received until Wednesday, meaning the conformity statement was made without complete evidence (Minor NC).
- Release authority is exercised by production personnel — the shipping supervisor signs the release authorization, but there is no documented delegation of this authority from the quality function (Minor NC).
Product release is the last gate before the product reaches the customer. Pull 3 recent shipment packages and audit them as if you were the customer receiving the product. Check: Is every inspection point completed? Are all certifications present and traceable? Is every nonconformity resolved? Is the C of C signed by an authorized individual? If any element is missing, the release process has failed. Also verify the independence of the release function — production should not release its own product without QA verification. The C of C is a legal document in aerospace — signing it without verifying completeness has serious implications.
Pull the complete shipment documentation package for 3 recent deliveries. For each, verify: all inspection points completed, all certifications present, all NCRs resolved, and release signed by authorized personnel.
- What is your process for ensuring all documentation is complete before signing the Certificate of Conformity?
- What happens if a nonconformity is discovered during final inspection — can the product still be shipped on schedule?
- Who has release authority, and how is that authority formally delegated and controlled?
8.6 Do Certificates of Conformity (C of C) include all customer-required and regulatory-required content, including part identification, specification compliance declarations, traceability data, and authorized signature?
- Certificate of Conformity template and procedure — verify the C of C format includes: organization name and address, customer name and PO number, part number and revision, quantity, serial/lot numbers, specification compliance statement, manufacturing date or lot date, authorized representative signature and title, and any customer-specific content requirements
- Completed C of C documents for 3 recent shipments — verify each contains all required content fields and that the information is accurate and traceable
- Customer-specific C of C requirements — verify the organization has identified any unique C of C content requirements from customers (some primes require specific declarations, chemical compliance statements, or traceability data on the C of C)
- C of C does not include specification compliance declarations — the certificate identifies the part but does not state which specifications the product conforms to, making it impossible for the customer to verify compliance scope (Minor NC).
- Serial numbers on the C of C do not match the serial numbers on the packing slip or the actual parts — a data entry error resulted in incorrect traceability information on a legal compliance document (Minor NC).
- C of C is a generic pre-printed form with no customer-specific content — a customer requires a REACH/RoHS compliance declaration on the C of C but it is not included (Observation).
The C of C is a legal declaration that the product conforms to requirements. Treat it as a critical document. Compare the C of C content against customer requirements — many primes have specific C of C content mandates in their quality clauses. Also verify accuracy — spot-check that serial numbers, lot numbers, and specification revisions on the C of C match the actual product and production records. An inaccurate C of C is worse than an incomplete one because it provides false assurance.
Review C of C documents for 3 recent shipments to 3 different customers. For each, compare the C of C content against customer quality clause requirements. Spot-check 1 serial number from each C of C against production records to verify accuracy.
- How do you verify that the information on the C of C is accurate before it is signed?
- Do any of your customers have specific requirements for what must appear on the Certificate of Conformity?
- Who reviews the C of C before it is signed, and what checklist or verification do they follow?
§8.7 Control of nonconforming outputs
8.7 Does the organization identify, segregate, and control nonconforming product to prevent its unintended use or delivery, with documented disposition authority defined for each type of disposition?
- Nonconformance procedure defining identification (tagging/marking), segregation (physical separation and secured MRB area), documentation (NCR with defect description, affected quantity, serial/lot numbers), and disposition requirements
- MRB (Material Review Board) or equivalent disposition authority — documented membership, quorum requirements, and authority levels for each disposition type (scrap, rework, repair, use-as-is/accept-as-is)
- Segregation area (MRB cage/area) on the shop floor — verify it is secured, clearly marked, and that access is controlled to prevent unauthorized removal of nonconforming product
- Sample of 5 recent NCRs — verify each has: clear defect description, affected quantity and identification, proper disposition with justification, and evidence of completed disposition action
- Nonconforming product is not physically segregated — tagged parts remain in the production flow area and could be inadvertently used in the next operation (Major NC).
- Disposition authority is not defined — NCRs are dispositioned by the inspector who found the defect, with no MRB or engineering review for use-as-is or repair dispositions (Major NC).
- NCR does not document the engineering justification for a use-as-is disposition — the disposition says 'accept as is' but there is no analysis showing why the nonconformity does not affect form, fit, or function (Minor NC).
- NCRs are opened and dispositioned but the disposition action is not verified — reworked parts are returned to production flow without re-inspection to verify the rework brought the part into conformity (Major NC).
Visit the MRB area. Is it secured? Is there product in it? Check the tags — are NCR numbers current or have parts been sitting there for months without disposition? Then pull 5 recent NCRs and audit the full lifecycle of each: identification, segregation, investigation, disposition decision (with justification), disposition action, verification of completed action, and closure. For any use-as-is or repair dispositions, verify that engineering analysis or customer concession exists. The most common failure is incomplete disposition — the NCR says 'rework' but there is no evidence the rework was performed and verified.
Visit the MRB area and verify controls. Pull 5 recent NCRs representing different disposition types (at least 1 scrap, 1 rework, and 1 use-as-is). For each, verify the complete lifecycle from identification through verified closure.
- Walk me through the last use-as-is disposition — who approved it and what engineering analysis supported the decision?
- How do you prevent nonconforming product from being used before disposition is complete?
- What is the average age of open NCRs, and do you have any NCRs that have been open for more than 30 days?
8.7 When nonconforming product is dispositioned as use-as-is or repair, does the organization obtain customer concession or deviation approval when the nonconformity deviates from customer requirements, and is the concession documented?
- Procedure defining when customer concession is required — verify criteria include: deviation from customer drawing requirements, deviation from customer-specified specifications, and any nonconformity on safety-critical or key characteristics
- Concession request and approval records for recent use-as-is and repair dispositions — verify the customer approved the deviation before the product was shipped
- Evidence that concession requests include sufficient technical justification — engineering analysis, dimensional data, stress analysis, or equivalent supporting the acceptability of the deviation
- Records showing concession number or deviation authorization is referenced on shipping documentation and C of C — verify the customer can identify which delivered items were accepted under concession
- Product with dimensions outside customer drawing tolerances was dispositioned as use-as-is and shipped without customer concession — the MRB determined the parts were functionally acceptable but did not notify the customer (Major NC).
- Concession request process exists but the organization does not distinguish between deviations from internal specifications (no concession required) and deviations from customer specifications (concession required) — internal dispositions are applied to customer-specified requirements without external approval (Minor NC).
- Concession approval was obtained verbally from the customer but not documented — no written authorization exists for a use-as-is disposition on 200 parts with an out-of-tolerance condition (Minor NC).
- Concession-accepted parts are not identified on shipping documentation — the customer receives parts under concession but the C of C and packing slip do not indicate which parts or lot numbers were accepted under deviation (Minor NC).
Customer concession is a contractual and ethical requirement — the organization cannot decide on behalf of the customer that a deviation is acceptable. For every use-as-is and repair disposition in your sample, determine whether the nonconformity affects a customer-specified requirement. If it does, verify that documented customer approval was obtained before shipment. Check the timeline — was the concession obtained before the product shipped, or was it requested retroactively after the customer discovered the deviation? Also verify that concession-accepted product is traceable — if a customer needs to identify which in-service products were accepted under deviation, the traceability must exist.
Review all use-as-is and repair dispositions from the past 6 months. For each, determine whether the nonconformity affected a customer-specified requirement. Where it did, verify documented customer concession was obtained before shipment.
- How do you determine whether a nonconformity requires customer concession versus an internal disposition only?
- Show me the last concession request submitted to a customer — what information was included and how long did approval take?
- How do you identify and track products that were accepted under customer concession after they ship?
8.7 When nonconforming product is discovered after delivery to the customer, does the organization take appropriate action including customer notification, containment, and corrective action — and does the process address mandatory reporting obligations to airworthiness authorities?
- Escaped defect process or procedure — defining the response when a nonconformity is discovered on product already delivered to the customer, including notification timelines, containment actions, and corrective action requirements
- Records of escaped defect events in the past 24 months — verify the organization notified the affected customer(s), assessed the scope of potential exposure (lot/serial number analysis), and implemented containment and corrective action
- Process for determining whether an escaped defect requires mandatory reporting to an airworthiness authority (FAA, EASA, etc.) — verify criteria are defined and someone is responsible for making the reporting determination
- Evidence that escaped defect data is trended and analyzed — verify escaped defects are counted, categorized, and reviewed in management review as a specific metric
- No defined process exists for responding to escaped defects — when a customer notifies the organization of a nonconforming product, the response is handled ad hoc without a standard process, timeline, or escalation criteria (Minor NC).
- An escaped defect was identified by a customer but the organization did not assess whether other customers received product from the same lot — the containment was limited to the complaining customer without broader exposure analysis (Major NC).
- Organization has no process for evaluating whether an escaped defect requires mandatory reporting to an airworthiness authority — no one in the organization is responsible for making this determination, and the regulatory reporting criteria are not documented (Minor NC).
- Escaped defect data is not trended — individual events are addressed but there is no analysis of whether escaped defects are increasing, decreasing, or concentrated in specific product lines or processes (Observation).
Escaped defects — nonconformities discovered after delivery — are one of the most critical quality events in aerospace. The response must be swift, systematic, and thorough. Check whether the organization has a defined response process with timelines. Verify that when an escape occurs, the exposure analysis considers all potentially affected customers and serial/lot numbers, not just the customer who reported it. Also probe the mandatory reporting question — in aerospace, certain defects must be reported to airworthiness authorities (e.g., FAA Service Difficulty Reports per 14 CFR 21.3). If the organization cannot describe their mandatory reporting obligations, this is a significant gap.
Review all escaped defect events in the past 24 months. For each, verify: customer notification, exposure analysis (lot/serial scope), containment actions, root cause analysis, corrective action, and reporting determination (whether mandatory reporting was required and whether it was made).
- Walk me through the last escaped defect — from customer notification through containment and corrective action. How long did each step take?
- What are your mandatory reporting obligations to airworthiness authorities, and who in the organization is responsible for determining when a report is required?
- How do you analyze escaped defect trends, and what does the data show over the past 2 years?
§9 Performance evaluation
9.1.1 Does the organization monitor and measure process performance against defined targets, including manufacturing process capability (Cpk/Ppk), first-pass yield, and cycle time adherence — and are out-of-target conditions acted upon?
- Process performance metrics dashboard with targets (Cpk >= 1.33, FPY targets, cycle time targets)
- Process capability data for at least 3 key manufacturing processes
- Evidence of action taken when performance falls below target
- Measurement system analysis (GR&R) for critical measurement processes
- Process capability has not been assessed for any manufacturing process (Minor NC).
- First-pass yield is not tracked (Observation).
- Cpk below 1.0 for a key characteristic with no improvement action (Minor NC).
If the organization cannot provide Cpk data for key processes, they are relying on inspection to catch defects rather than preventing them.
Request Cpk data for 3 key manufacturing processes. Verify statistical validity. If any below 1.33, verify improvement actions.
- What is the Cpk for your most critical manufacturing process?
- What percentage of production passes through all operations without rework?
- Have you performed gauge R&R studies?
9.1.2 Does the organization monitor customer satisfaction including on-time delivery performance, product quality performance (rejections, returns, concessions), and customer scorecard ratings — and are these metrics acted upon when targets are not met?
- Customer satisfaction monitoring system that goes beyond periodic surveys — verify it includes objective performance metrics: on-time delivery percentage (to customer request date), customer quality rejections (PPM or lot rejection rate), customer scorecard ratings where provided, warranty/return data, and concession frequency
- Customer scorecard data from major customers — many aerospace primes provide periodic scorecards rating supplier performance; verify the organization tracks and responds to these ratings
- Trend data for at least 12 months — verify customer satisfaction metrics are trended and that trends are analyzed, not just reported
- Action plans for performance below target — where OTD, quality, or scorecard ratings fall below defined targets, verify corrective or improvement actions are documented and implemented
- Customer satisfaction is measured solely by an annual survey with a 15% response rate — no objective performance metrics (OTD, quality rejections, concessions) are tracked, and the survey results are not actionable (Minor NC).
- Customer scorecards are received from 3 major customers but are not reviewed or responded to — scorecards show declining performance trends but no improvement actions have been initiated (Minor NC).
- On-time delivery to customer request date is not monitored — the organization tracks on-time to internal promise date only, which masks late deliveries where the promise date was renegotiated after the original request (Minor NC).
- Product quality rejections by customers have increased 40% year-over-year but no corrective action program has been initiated — the data is collected but not analyzed or acted upon (Major NC).
AS9100D requires monitoring customer perception of the degree to which requirements have been met, with specific emphasis on on-time delivery and product quality. Annual surveys alone are insufficient in aerospace — objective performance data should be the primary measure. Ask to see customer scorecards from the 3 largest customers. If the organization does not track these, ask why. If they do track them but scores are declining with no action, the monitoring system is not effective. Also check the OTD definition — measuring to promise date rather than request date can hide chronic delivery problems.
Request customer scorecards from 3 major customers. Review OTD and quality metrics for the past 12 months. Identify any downward trends and verify what actions were taken.
- How do you define and measure customer satisfaction — what specific metrics do you track?
- Show me the scorecard ratings from your top 3 customers for the past 12 months — what trends do you see?
- When a customer scorecard shows declining performance, what is the process for responding?
9.1.3 Does the organization analyze and evaluate data on product and process conformity, including first-pass yield, scrap rates, rework rates, and supplier quality performance — and are the results used to identify improvement opportunities?
- Data analysis reports or dashboards showing product conformity metrics — first-pass yield (FPY), scrap rate, rework rate, NCR volume and Pareto analysis by defect type, and process capability indices for key processes
- Supplier quality performance analysis — incoming inspection acceptance rates, supplier PPM, SCAR closure rates, and trend analysis by supplier and commodity
- Evidence that data analysis drives improvement — verify at least 2 improvement actions that were initiated based on data analysis (e.g., a Pareto analysis of NCRs identified the top defect type and a corrective action was initiated to address it)
- Data analysis presented in management review — verify conformity data is an input to management review and that management makes decisions based on the analysis
- Data is collected (NCR count, scrap rate) but not analyzed — monthly reports show raw numbers without Pareto analysis, trend analysis, or statistical evaluation to identify patterns and root causes (Minor NC).
- First-pass yield is not tracked — the organization knows how many parts were scrapped or reworked but does not measure what percentage of production passes through all operations right the first time (Observation).
- Supplier quality data is not analyzed at the commodity or supplier level — total incoming rejection rate is reported but there is no breakdown to identify which suppliers or which commodities drive the majority of rejections (Minor NC).
- Data analysis is performed but does not lead to improvement — the same defect type has been the #1 Pareto item for 3 consecutive quarters but no improvement project or corrective action has been initiated (Minor NC).
The key question is not 'Do you collect data?' but 'What have you done with the data?' Verify the complete cycle: data collection → analysis → identification of patterns → improvement action → verification of improvement. If the organization produces beautiful reports but cannot point to a single improvement that was driven by data analysis, the analysis is a compliance artifact. Also check whether analysis is granular enough to be actionable — a plant-wide scrap rate of 3% tells you nothing; scrap by defect type, by operation, by part number tells you where to focus.
Review the most recent quality data analysis report. Identify the top 3 issues by Pareto. For each, verify whether an improvement action was initiated. Check that data analysis is an input to the last management review.
- What is your top quality issue based on the data — the #1 defect type, operation, or product line driving nonconformities?
- Show me an improvement that was initiated based on data analysis — what data triggered it and what was the result?
- How do you use supplier quality data to make sourcing and supplier development decisions?
9.2 Does the internal audit program cover all AS9100D requirements including aerospace-specific clauses (8.1.1 through 8.1.4, FAI, special processes, key characteristics, work transfer), and are auditors independent of the areas they audit?
- Internal audit schedule for the current audit cycle — verify all AS9100D clauses are included, with particular attention to aerospace-specific requirements that are frequently omitted: 8.1.1 (operational risk management), 8.1.2 (configuration management), 8.1.3 (product safety), 8.1.4 (counterfeit prevention)
- Internal audit reports for the most recently completed cycle — verify audit depth is adequate (not just 'clause reviewed — no findings' for complex requirements), and that findings have objective evidence
- Auditor qualification records — verify internal auditors are trained, and that each audit was conducted by an auditor independent of the function being audited
- Audit finding follow-up — verify all findings from the previous cycle have been closed with verified corrective actions
- Internal audit schedule does not include AS9100D-specific clauses 8.1.1, 8.1.2, 8.1.3, and 8.1.4 — the audit program was designed for ISO 9001 and was not updated when the organization upgraded to AS9100D (Minor NC).
- Internal audit reports show no findings for any clause in 3 consecutive audit cycles — while possible, this is statistically unlikely and suggests audits lack sufficient depth (Observation).
- Auditor independence is not maintained — the production manager audited the production process because 'they know it best' (Minor NC).
- Audit findings from the previous cycle have open corrective actions that are past due — 4 of 7 findings remain open 6 months after the completion date (Minor NC).
Internal audit is one of the most important self-assessment tools in the QMS. Check whether the audit program genuinely covers AS9100D requirements — many organizations upgraded from ISO 9001 but never updated their internal audit checklist or schedule. Also evaluate audit depth: if every clause says 'satisfactory — no findings,' the audits may lack rigor. A healthy internal audit program should find things. Also verify auditor independence — in smaller organizations where everyone wears multiple hats, this can be challenging but must still be maintained.
Review the internal audit schedule for AS9100D-specific clause coverage. Pull 2 internal audit reports — 1 for a production area and 1 for an AS9100D-specific clause (8.1.1-8.1.4). Evaluate audit depth and finding quality. Verify auditor independence for each.
- How do you ensure your internal audit checklist covers AS9100D-specific requirements that go beyond ISO 9001?
- Your last audit cycle reported zero findings across all clauses — how confident are you that reflects reality rather than insufficient audit depth?
- How do you maintain auditor independence in areas where you have limited personnel?
9.3 Does management review include all AS9100D-required inputs — including on-time delivery performance, product safety issues, product conformity trends, operational risk management effectiveness, and actions from previous management reviews?
- Management review procedure defining required inputs and outputs — verify it includes all AS9100D additions beyond ISO 9001: on-time delivery performance, product safety, configuration management effectiveness, counterfeit prevention program effectiveness, and operational risk management status
- Most recent management review minutes — verify all required inputs were addressed with actual data (not just agenda items listed but not discussed), and that outputs include specific decisions and action items with owners and due dates
- Evidence that actions from the previous management review were followed up — verify action items from the prior review are tracked and their status is reported in the current review
- Attendance record — verify top management (not just the quality manager) participated in the review
- Management review does not include AS9100D-specific inputs — on-time delivery performance, product safety events, and operational risk management effectiveness are not addressed in the most recent management review record (Minor NC).
- Management review record shows agenda items were listed but no data was presented or discussed — the record says 'customer satisfaction — discussed' but contains no actual performance data, trends, or analysis (Minor NC).
- Actions from the previous management review are not tracked — 5 action items from the prior review have no status update and it is unclear whether they were completed (Minor NC).
- Management review is conducted by the quality manager alone — top management did not attend and the review is a paper exercise rather than a strategic management activity (Major NC).
Management review is where the entire QMS comes together for strategic assessment. Verify that it is a genuine management activity, not a quality department exercise. Check the attendance — top management must participate. Review the data — it should include actual metrics and trends, not just statements that topics were 'discussed.' The AS9100D additions (OTD, product safety, risk management) should be addressed with the same depth as core ISO 9001 topics. Also verify the output side — decisions should be specific and actionable, not generic statements like 'continue to improve quality.'
Review the last 2 management review records. Verify: (1) all required inputs are addressed with data, (2) AS9100D-specific topics are included, (3) outputs include specific actions with owners and dates, (4) actions from the prior review are tracked to closure, (5) top management attended.
- What were the most significant decisions or actions from the last management review, and have they been implemented?
- How does management review address product safety — is it a standing agenda item with reported data?
- Who attends management review, and how do you ensure top management is meaningfully engaged — not just signing the minutes?
§10 Improvement
10.2 Does the corrective action process include root cause analysis using defined problem-solving methods, determine whether similar nonconformities exist or could occur elsewhere, and verify the effectiveness of corrective actions after implementation?
- Corrective action procedure referencing defined problem-solving methodologies — verify the procedure specifies acceptable methods (8D, 5-Why, fishbone/Ishikawa, A3, DMAIC) and requires their use based on the significance of the nonconformity
- Sample of 5 recent corrective actions — verify each includes: clear problem statement, containment action, root cause analysis using a defined method (not just a narrative), corrective action addressing the root cause (not just the symptom), effectiveness verification with objective evidence, and assessment of applicability to other products/processes
- Evidence of effectiveness verification — verify that corrective actions are checked after implementation to confirm the problem did not recur, using objective data (not just 'no further complaints')
- Horizontal deployment evidence — verify that when a root cause could affect other products or processes, the organization assessed and addressed those areas (not just the specific instance where the problem was found)
- Root cause analysis is superficial — the '5-Why' analysis stops at 'operator did not follow procedure' without exploring why the procedure was not followed (training gap? unclear instruction? production pressure? poor workstation layout?) (Minor NC).
- Corrective action addresses the symptom rather than the root cause — a recurring defect is addressed by adding an inspection step rather than fixing the process that creates the defect (Observation).
- No effectiveness verification is performed — corrective actions are implemented and closed without any subsequent check to confirm the problem did not recur; 'closed' means 'action completed,' not 'problem solved' (Minor NC).
- No horizontal deployment assessment — a root cause identified in one product line (e.g., incorrect torque due to uncalibrated torque wrench) could affect other product lines using the same equipment, but no assessment of broader applicability was performed (Minor NC).
- Problem-solving methods are not applied — 8D or 5-Why is referenced in the procedure but the actual CAPA records contain only a narrative description with no structured analysis methodology (Minor NC).
AS9100D specifically requires 'defined problem-solving methods' — this is an addition over ISO 9001. Verify that the corrective action procedure names specific methods and that actual CAPA records use them. The most common failures are: shallow root cause analysis that stops at the human error level, corrective actions that add inspection rather than fix the process, and missing effectiveness verification. Pull 5 CAPAs and read them critically. Ask: 'Would this corrective action prevent the problem from happening again if the same conditions occurred?' If the answer is no, the CAPA is inadequate. Also check closure timelines — CAPAs open for 6+ months without resolution indicate a systemic problem with the corrective action process itself.
Pull 5 recent CAPAs. For each, evaluate: (1) problem-solving method used, (2) root cause depth (does it go beyond human error?), (3) corrective action addresses root cause (not just adds inspection), (4) effectiveness verification with objective data, (5) horizontal deployment assessment documented.
- Walk me through a recent CAPA where the root cause analysis changed your understanding of the problem — where the initial assumption about the cause was wrong.
- How do you verify that a corrective action is effective — what data do you look at, and how long do you wait before declaring effectiveness?
- Show me a CAPA where the root cause assessment led you to check other products or processes — what did you find?
10.2 Does the organization ensure timely and effective corrective action in response to customer-reported nonconformities and customer corrective action requests (SCARs), including flow-down of corrective actions to suppliers when the root cause lies in the supply chain?
- Customer corrective action request (SCAR) log — verify all customer-issued CARs are tracked with response deadlines, current status, and closure dates
- Response time compliance — verify the organization responds to customer CARs within the customer-specified timeframe (typically 30-60 days for initial response, 90 days for full closure)
- Quality of customer CAR responses — verify at least 2 recent customer CARs include adequate root cause analysis, corrective actions, and effectiveness verification — not boilerplate responses
- Supply chain corrective action — when the root cause of a customer complaint lies with a supplier, verify that a SCAR was issued to the supplier and the supplier's response was incorporated into the customer CAR response
- Evidence that customer CAR trends are analyzed — verify repeat CARs from the same customer for the same issue trigger escalated response
- Customer corrective action requests are overdue — 3 of 8 open customer CARs have passed their response deadlines with no communication to the customer about the delay (Minor NC).
- Customer CAR response is a boilerplate '8D report' that does not address the specific nonconformity described by the customer — the root cause analysis is generic and the corrective action is 'reinforce operator training' for a systemic process issue (Minor NC).
- Root cause of a customer complaint lies with a sub-tier supplier but no supplier corrective action request was issued — the organization's response to the customer does not address the supply chain root cause (Minor NC).
- Same customer has issued 3 CARs for the same defect type in the past 18 months — the corrective actions from the first 2 CARs were clearly ineffective but no escalated response or different approach was taken for the third occurrence (Major NC).
Customer CARs are a direct measure of how well the corrective action system works under external pressure. Pull the customer CAR log and check for overdue responses — late responses damage the customer relationship and may affect scorecard ratings. Read the actual responses and evaluate whether the root cause analysis and corrective actions are specific and adequate. If the same customer has issued multiple CARs for the same issue, the corrective action system has failed. Also check whether supplier-related issues are flowed down — if the root cause is supplier material but the corrective action is 'additional incoming inspection,' the systemic cause has not been addressed.
Review the customer CAR log for the past 12 months. Verify response time compliance. Read 2 customer CAR responses in detail and evaluate root cause depth and corrective action adequacy. Check for repeat CARs from the same customer.
- How many customer CARs are currently open, and how many are past due?
- Show me a customer CAR where the root cause was traced to a supplier — what actions were taken with the supplier?
- Has any customer issued you multiple CARs for the same type of defect? If so, what did you do differently the second time?
10.2 Does the organization analyze escaped defect data to identify systemic causes — including deficiencies in inspection methods, process controls, or human factors — and implement improvements to prevent recurrence?
- Escaped defect log or register — verify all customer-reported nonconformities and internal discoveries of shipped nonconforming product are tracked as escaped defects
- Analysis of escaped defects by category — verify defects are categorized (defect type, product, process, inspection point missed) and Pareto analysis is performed to identify systemic patterns
- Root cause analysis for each escaped defect that includes evaluation of why the defect was not detected before shipment — not just why the defect occurred, but why the detection system failed
- Improvement actions targeting the detection system — verify that corrective actions address the inspection or verification gap, not just the manufacturing process that created the defect
- Escaped defects are treated as individual corrective actions without systemic analysis — each is investigated independently but no aggregate analysis is performed to identify patterns across escapes (Minor NC).
- Root cause analysis addresses why the defect was created but not why it escaped detection — the inspection method, sampling plan, or verification process that should have caught the defect is not evaluated (Minor NC).
- Escaped defect rate is increasing year-over-year but no improvement program targets the detection system — the same inspection methods and sampling plans remain unchanged despite repeated escapes (Minor NC).
Every escaped defect represents two failures: a process failure (the defect was created) and a detection failure (the defect was not caught). Most organizations investigate the process failure but not the detection failure. Ask specifically: 'Why did your inspection system not catch this defect before it shipped?' If the answer is 'the inspector missed it,' push further — was the inspection method adequate? Was the sampling plan sufficient? Was the inspector trained and competent for that inspection? Escaped defect trend data is one of the most important metrics for evaluating QMS effectiveness.
Review escaped defect data for the past 12 months. Verify: each escape has root cause analysis covering both creation and detection failure, systemic analysis is performed across escapes, and improvement actions target the detection system.
- How many escaped defects have you had in the past 12 months, and what is the trend?
- For the last escaped defect, why did your inspection system not detect it before shipment?
- Have you changed any inspection methods or sampling plans in response to escaped defects?
10.3 Does the organization pursue continual improvement of QMS effectiveness using defined improvement methodologies, and can it demonstrate measurable improvement in product quality, on-time delivery, customer satisfaction, or process performance?
- Continual improvement plan or program — documented approach to improvement that goes beyond reactive corrective action to include proactive improvement projects (lean manufacturing, Six Sigma, Kaizen, automation, process optimization)
- Measurable improvement results — verify at least 2 improvement projects completed in the past 12 months with before/after data showing quantified improvement (e.g., scrap reduction from 4.2% to 2.1%, OTD improvement from 88% to 95%)
- Improvement metrics trended over time — verify key performance indicators show improvement trajectories, not just maintenance of the status quo
- Improvement objectives aligned with business priorities and management review outputs — verify the improvement program addresses the organization's most significant quality and delivery challenges
- No evidence of continual improvement beyond reactive corrective actions — the organization addresses problems as they arise but has no proactive improvement program, projects, or measurable improvement objectives (Minor NC).
- Improvement objectives are defined but not measurable — 'improve quality' is stated as an objective but no specific target, timeline, or measurement method is defined (Minor NC).
- Improvement projects are initiated but not completed or measured — 3 improvement projects were started in the past year but none have completion data or quantified results (Observation).
- The same quality and delivery metrics have been flat for 3 years despite an active improvement program — the improvement activities are not translating into measurable results (Observation).
AS9100D requires continual improvement — not just problem fixing. Look for evidence that the organization is getting better, not just staying the same. Ask for trended data over 2-3 years. If KPIs are flat, ask what improvement efforts are underway and why they have not moved the metrics. The most effective organizations can point to specific improvement projects with before/after data. If the only improvement evidence is the corrective action system, the organization is reactive. Also check alignment — are improvement efforts directed at the organization's biggest challenges (as identified in management review), or are they scattered and disconnected from strategic priorities?
Request trended KPI data for the past 2-3 years (scrap rate, OTD, customer satisfaction, first-pass yield). Identify areas of improvement and areas of stagnation. For at least 1 improvement achievement, verify before/after data. For areas of stagnation, ask what improvement efforts are underway.
- What are your most significant improvement achievements in the past 12 months, and how did you measure the improvement?
- How do you decide which improvement projects to pursue — what prioritization criteria do you use?
- Looking at your quality and delivery metrics over the past 3 years, what trends do you see?
Each item shows its evidence, common nonconformities and auditor tips. The PDF holds the same content, formatted for a clipboard.