How to Audit a Medical Device QMS: The ISO 13485 Internal Audit Process (2026 Guide)

This guide walks medical device manufacturers through the ISO 13485 Clause 8.2.4 internal audit requirement — including audit program design, the six-step audit process, and the five most common findings auditors cite. It also covers what changed under the FDA QMSR and the new ISO 19011:2026 audit guidance.

A clause-by-clause guide to planning, conducting, and closing out ISO 13485 internal audits under the new FDA QMSR

Affiliate Disclosure: Some links in this article are affiliate links. If you purchase through them, The Standards Navigator may earn a commission at no additional cost to you.


The Internal Audit That Used to Be Private Isn’t Anymore

For years, medical device manufacturers treated the internal audit report as an internal document — useful for finding problems, but shielded from FDA inspectors under the confidentiality provision in the old 21 CFR 820.180(c). That protection is gone.

Since February 2, 2026, the FDA’s Quality Management System Regulation (QMSR) has been in effect, and it incorporates ISO 13485:2016 by reference rather than running a parallel U.S.-specific standard alongside it. FDA’s own Final Rule FAQ is direct about what that means for audits: “The QMSR gives the FDA the authority to inspect management review, quality audits, and supplier audit reports. The exceptions that existed in the QS regulation at § 820.180(c) are not maintained in the QMSR.” That’s not a third-party interpretation — it’s FDA’s own published position.

So this isn’t limited to internal audit reports. Management review minutes and supplier audit reports lost the same protection. A checklist you run through once a year to satisfy Clause 8.2.4 on paper is no longer a low-risk approach — it’s now a document an inspector may read line by line, and so are the meetings where leadership reviewed it.

From the Floor: I’ve built and run internal audit programs at facilities with 500-plus employees, and the finding that costs organizations the most isn’t a missing procedure — it’s a corrective action that gets closed on paper before the root cause is actually fixed. As a certified ISO 9001 Internal Auditor, I’ve sat across the table from auditors who catch that in about ninety seconds. Whether you’re auditing to ISO 9001 or ISO 13485, the internal audit only works if it’s harder on you than the external one will be.

Before your next surveillance audit, most quality teams don’t fail because they misunderstand Clause 8.2.4 — they fail because their audit program looks complete on paper but hasn’t been stress-tested against real objective evidence. Run your QMS through the free ISO 13485 Gap Assessment Checklist before an inspector or a Notified Body does it for you.


In This Guide

  • What ISO 13485 Clause 8.2.4 actually requires
  • How internal audits differ from supplier and certification audits
  • What Clause 6.2 actually requires of your auditors — and what “competent” really means
  • Building a risk-based annual audit program
  • The audit process: planning, evidence, reporting, and CAPA follow-up
  • A real finding-to-CAPA example, start to finish
  • The five most common internal audit findings — and how to avoid them
  • What changes if you’re audited under MDSAP
  • What changed under the FDA QMSR and ISO 19011:2026
  • Whether you need outside help or can run this internally


👉 Start Here (Top Resources)


What Clause 8.2.4 Actually Requires

ISO 13485 requires internal audits under Clause 8.2.4 to verify that QMS processes are implemented and effective, catch nonconformities, and surface QMS deficiencies early enough that they don’t become product-safety or regulatory problems. That sounds close to ISO 9001’s internal audit clause, and it is — but ISO 13485 asks for more.

Clause 8.2.4 requires that internal audits determine conformity to planned arrangements, the requirements of the standard, the organization’s own QMS requirements, and applicable regulatory requirements — and unlike ISO 9001, ISO 13485 explicitly requires the audit program to account for regulatory requirements such as FDA 21 CFR Part 820, EU MDR, or MDSAP alongside the standard itself. Teams that build their audit program purely off the ISO 13485 clause structure, without folding in the regulatory layer, are the ones who get flagged.

Most common finding: auditors treat Clause 8.2.4 as a documentation-review exercise and skip the regulatory cross-reference entirely. If your audit checklist doesn’t ask “does this also satisfy 21 CFR Part 820 or MDR Article 10?” it isn’t finished.

Audits must assess conformity across critical processes — design and development under Clause 7.3, corrective action under Clause 8.5.2, preventive action under Clause 8.5.3, production under Clause 7.5, and document control under Clause 4.2 — using objective evidence like device history records, audit trails, and validation records. Auditors must be trained, qualified, and independent of the area they’re auditing, with that competence documented under Clause 6.2.

If you are already ISO 9001 certified → your internal audit infrastructure transfers directly, but your checklist needs a regulatory column added for every process area, not just a conformity column.


Internal Audits vs. Supplier Audits vs. Certification Audits

Comparison infographic showing internal audits, supplier audits, and certification audits under ISO 13485.
Understanding the differences between internal, supplier, and certification audits improves audit planning and regulatory compliance.

Manufacturers frequently conflate these three, and an auditor will notice immediately if your procedure does too.

Audit TypeGoverning ClausePerformed ByPrimary Purpose
Internal AuditClause 8.2.4Trained internal personnel, independent of the area auditedVerify your own QMS conforms to the standard and your own procedures
Supplier AuditClause 7.4.1Quality or supplier quality personnelVerify external providers meet quality and regulatory requirements
Certification AuditISO/IEC 17021-1Accredited third-party Notified Body or registrarDetermine whether the full QMS meets ISO 13485 for certification

ISO 13485 requires internal audits, just as its sister standard ISO 9001 does, and they exist for two reasons: to confirm the QMS meets the standard’s requirements, and to confirm the organization actually follows its own rules. A strong internal audit program is what makes a certification audit uneventful instead of a fire drill.


Auditor Competence: What Clause 6.2 Actually Requires

This is the section most audit programs get thin on, and it’s where a surprising number of otherwise solid internal audit programs fall apart under scrutiny.

Clause 6.2 requires that anyone doing work affecting product quality — and that includes auditors — be competent based on appropriate education, training, skills, and experience. ISO 13485 doesn’t spell out a fixed list of required knowledge areas the way a checklist would, but three areas consistently show up when a Notified Body reviews auditor files:

  • The standard itself. A working knowledge of ISO 13485:2016 clause structure, not just the SOPs written to satisfy it.
  • Audit methodology. Understanding of the audit cycle — planning, evidence gathering, reporting, follow-up — along with the difference between a minor observation and a major nonconformity. ISO 13485’s own note under Clause 8.2.4 points auditors toward ISO 19011 for this.
  • Applicable regulatory context. Basic familiarity with the regulations that apply to your product and markets — 21 CFR Part 820, EU MDR, MDSAP — not full legal mastery, but enough to recognize when a finding also touches a regulatory requirement.

Competence is not the same thing as certification. ISO 13485 does not require a certified internal auditor credential, and ISO 19011 doesn’t mandate formal training either — the standard’s actual requirement is that the audit process ensure objectivity and impartiality, and that competence be evaluated and documented. In practice, though, “read and understand the internal procedure” is not evidence Notified Bodies accept as sufficient. An auditor who can’t produce a training record, a completed course certificate, or documented on-the-job evaluation showing how their competence was assessed is a finding waiting to happen — even if that person is, in fact, good at the job.

What acceptable training records look like in practice:

  • A certificate of completion from an ISO 13485 internal auditor course (typically covering the standard itself plus ISO 19011 audit methodology) — see BSI vs. ISOQAR if you’re deciding where to send your team for that training
  • Internal on-the-job qualification records — a documented mentored audit or two, signed off by a qualified lead auditor
  • A training matrix that ties each auditor to the specific processes and clauses they’re qualified to audit, refreshed when the QMS or the standard changes

Auditor independence gets checked alongside competence. The most frequent failure here isn’t a skills gap — it’s a quality manager who owns a process auditing that same process, or an auditor rotation that never actually rotates the highest-risk areas like design controls.

If you are not confident your auditor files would hold up to this list → that’s a fifteen-minute file review, not a project, and it’s worth doing before your next Notified Body visit rather than during it.


Building a Risk-Based Audit Program

The audit program must cover every process, department, and site within your QMS scope, with audit frequency determined by the status and importance of each process along with the results of prior audits. High-risk processes — design and development, production, CAPA, and complaint handling — typically need at least annual coverage, while lower-risk support functions can be audited less frequently if previous results were consistently clean.

Most manufacturers get the frequency question backwards. They audit everything on a flat annual calendar instead of weighting toward where the last audit found something. If your CAPA process had a finding last year, auditing it again on the same twelve-month clock as your HR training records is a scheduling decision an inspector will question.

If you are preparing for your first surveillance audit under the new QMSR → build your program around the regulatory cross-reference first, then layer the standard’s clause structure on top of it — not the other way around.


The Internal Audit Process, Step by Step

Infographic illustrating the ISO 13485 internal audit process from planning through CAPA verification for medical device quality management systems.
The six-step ISO 13485 internal audit process helps medical device manufacturers identify nonconformities and verify corrective actions.

Prepare a checklist based on the relevant clauses of ISO 13485, your documented procedures, and applicable regulatory requirements — a good checklist prompts investigation rather than simply confirming what’s already assumed to be true.

1. Scope and schedule. Define which processes, sites, and clauses are in scope for this audit cycle.

2. Documentation review. Analyze the quality manual, procedures, and prior audit reports before setting foot on the floor — this is where checklists get mapped to specific clauses.

3. Opening meeting. Confirm scope, objectives, and methodology with the auditee before evidence-gathering begins — this sets the tone for the entire audit.

4. Evidence gathering. Collect objective evidence through interviews, direct observation, and document/record review — no finding should be written down without evidence behind it.

5. Reporting. Findings get written up, classified by severity, and routed to the process owner and management.

6. CAPA follow-up. Every corrective action needs documented root cause analysis appropriate to the significance of the nonconformity, with effectiveness verified before the CAPA is closed.

Most teams execute steps 1 through 5 competently. Step 6 is where programs fall apart — a CAPA gets marked closed the day the immediate fix is implemented, with no verification that the fix actually held.

Trigger: If your last three internal audits found the same category of nonconformity in different words each time, that’s not three separate findings — that’s one root cause your CAPA process never actually reached.

Before your next audit cycle, check your CAPA closure process against what auditors actually verify — most teams don’t realize how thin their effectiveness checks are until someone else reviews them.


A Real Finding, Start to Finish

Steps on a page are easy to nod along with. Here’s what a properly closed finding actually looks like end to end, using one of the most common design-control gaps auditors find.

StageWhat It Looked Like
FindingDuring a design and development audit, three of twelve design verification records sampled were missing the reviewer’s signature. Work was completed and dated, but sign-off wasn’t captured.
Objective EvidenceDesign History File records DHF-114, DHF-119, and DHF-122, cross-referenced against the design review meeting minutes showing the reviews occurred.
Nonconformity Statement“Design verification records DHF-114, DHF-119, and DHF-122 lack the required reviewer signature per QMS-SOP-014, Section 6.2. Design and development control per ISO 13485:2016 Clause 7.3.6 requires verification results, including necessary actions, to be recorded.”
Root CauseInvestigation traced it to a recent SOP revision that moved the sign-off step later in the workflow. Staff hadn’t been retrained on the updated sequence — the procedure changed, but the training that should have accompanied it under Clause 6.2 didn’t happen.
CorrectionThe three records were completed retroactively with the reviewer’s signature and a note explaining the delay, reviewed and accepted by the quality manager.
Corrective Action (CAPA)Retrain design team on the revised sign-off sequence; add a mandatory signature field to the design review template so records can’t be filed incomplete.
Effectiveness CheckSample the next ten design verification records over the following quarter. Zero missing signatures required to close the CAPA as effective.

Notice what makes this closeable rather than cosmetic: the root cause isn’t “people forgot” — it’s a training gap tied to a specific procedure change, and the corrective action addresses the system, not just the three records. That’s the difference between a finding that stays closed and one that reappears with different reference numbers next year.


The Five Most Common Findings

Infographic highlighting the five most common ISO 13485 internal audit findings in medical device quality management systems.
The most common ISO 13485 internal audit findings often involve documentation, CAPA effectiveness, auditor competence, and risk-based planning.

Incomplete audit records — missing reports, plans, or linked CAPAs — is one of the most frequently cited internal audit issues. A close second is failing to apply a risk-based approach to audit planning, or simply not maintaining the internal audit schedule at all. Beyond that, auditors regularly find no timely follow-up on actions from internal audits, no records showing auditor competence against the applicable regulations, and auditors who weren’t actually impartial — reviewing work they had a hand in.

Design and development controls remain the single most frequently cited nonconformity area globally — incomplete design inputs, missing verification or validation records, undocumented design changes, or no formal design transfer procedure. See Validation & Verification Requirements for how this plays out in practice.

⚠️ If your auditor rotation lets the same person audit design controls year after year without ever being audited themselves on that same process, that’s an impartiality gap that a Notified Body will flag before you do.

If you are not confident your last internal audit would hold up under this list → that’s exactly what a structured gap assessment is for, not a guess.

Check your program against these five findings before your next audit — most gaps take under 45 minutes to identify →


MDSAP: What Changes for Multi-Market Audits

If your devices sell into more than one of the five MDSAP markets — the U.S., Canada, Australia, Brazil, or Japan — your internal audit program needs to account for a different audit model, not just an extra regulatory reference.

The Medical Device Single Audit Program lets one audit by an accredited Auditing Organization satisfy the requirements of all five participating regulators at once, in place of separate national audits. It’s built on ISO 13485:2016, but it isn’t a straight overlay — MDSAP uses a process-based audit model with a defined sequence, rather than working straight down the ISO clause list, and it maps every audit task to both the relevant ISO 13485 clause and each country’s specific regulatory requirement.

The grading system is the biggest practical difference. Where an ISO 13485 certification audit typically classifies findings as minor or major, MDSAP uses a points-based Grade 1–5 scale: nonconformities affecting clauses with indirect QMS impact start lower, direct-impact clauses start higher, and points are added for repeat findings or for a nonconforming product that was actually released. Grade 4 and 5 findings must be resolved before a certificate is issued or maintained — there’s no ambiguity about severity once the math is run.

What this means for your internal audit program: if you’re pursuing or maintaining MDSAP, your internal audits should follow the MDSAP process sequence — not just walk through ISO 13485 clauses in order — so that gaps surface in the same structure an Auditing Organization will use. The recurring findings across published MDSAP audits track closely with the same weak points internal audits should already be hunting for: open CAPAs left unclosed past a reasonable window, supplier and purchasing controls that don’t demonstrate follow-through, and root cause analysis that’s thin enough to not survive a second look.

One benefit worth knowing about: MDSAP audit reports can substitute for the FDA’s routine biennial device inspections. A well-run MDSAP program isn’t just multi-market efficiency — it can reduce how often FDA shows up separately.


What Changed: QMSR and ISO 19011:2026

Two regulatory shifts affect how internal audits get run in 2026, and both are recent enough that older internal procedures may not reflect them.

Since February 2, 2026, the FDA’s QMSR has incorporated ISO 13485:2016 by reference, replacing the former Quality System Regulation, and FDA inspections now run under Compliance Program 7382.850 rather than the old QSR framework. As covered above, the practical effect for internal audits is direct: the confidentiality safe harbor that used to apply to internal audit reports, management review records, and supplier audit reports under the old 21 CFR 820.180(c) has been removed, and FDA’s own FAQ confirms it in plain language.

Separately, ISO published the fourth edition of ISO 19011 — Guidelines for auditing management systems — on May 27, 2026, replacing the 2018 edition that had guided audit programs for nearly eight years. ISO 13485 doesn’t mandate ISO 19011 compliance directly — Clause 8.2.4 references audit principles in its own language — but Notified Bodies and experienced auditors widely treat ISO 19011 as the authoritative reference for structuring an audit program, so if your internal audit SOPs still cite the 2018 edition, expect your Notified Body to ask why.

Neither change requires rebuilding your program from scratch. Both are reasons to review your internal audit SOP this year rather than next.


Quick Audit-Readiness Checklist

✅ Audit program covers every process, site, and department in your QMS scope ✅ Audit frequency is risk-weighted, not a flat annual calendar
✅ Every checklist item maps to a specific ISO 13485 clause and the applicable regulatory requirement
✅ Auditors are independent of the area they’re reviewing, with Clause 6.2 competence records on file — not just “read and understand” sign-offs
✅ Findings are backed by objective evidence — interviews, observation, or documented records
✅ CAPA effectiveness is verified before closure, not assumed
✅ If pursuing MDSAP, internal audits follow the MDSAP process sequence, not just the ISO clause order
✅ Internal audit SOP references ISO 19011:2026, not the 2018 edition
✅ Design and development records are current — this is the single most-cited finding category


FAQ

How often does ISO 13485 require internal audits?

The standard doesn’t specify a fixed interval — it requires audits “at planned intervals” based on process risk and prior audit history. Most manufacturers audit high-risk processes like design controls and CAPA annually at minimum, with lower-risk support functions audited less frequently if history is clean.

Can the same person who performs a process also audit it?

No. Clause 8.2.4 requires auditors to be independent of the area being audited. A quality manager who owns the CAPA process, for example, shouldn’t be the one auditing CAPA compliance.

Do internal auditors need a formal certification?

No. ISO 13485 requires documented competence — education, training, skills, and experience — but doesn’t mandate a specific certification. In practice, most Notified Bodies expect more than an internal read-and-understand sign-off, so a course certificate or documented mentored-audit record is the safer standard to work toward.

Does the FDA QMSR require a separate internal audit program from ISO 13485?

No. Since the QMSR incorporates ISO 13485:2016 by reference, there isn’t a separate U.S.-specific internal audit requirement layered on top — your Clause 8.2.4 program is the audit program the FDA now expects, with the regulatory cross-reference built in.

Are internal audit reports confidential from FDA inspectors?

Not anymore. FDA’s own QMSR Final Rule FAQ confirms the confidentiality exceptions under the old 21 CFR 820.180(c) — covering internal audits, management review, and supplier audits — are not maintained under the QMSR.

What’s the difference between an internal audit and a supplier audit under ISO 13485?

Internal audits (Clause 8.2.4) evaluate your own QMS. Supplier audits (Clause 7.4.1) evaluate external providers’ ability to meet your quality and regulatory requirements. Both are required, but they’re separate programs with separate scopes.

Does MDSAP replace our ISO 13485 internal audit requirement?

No, but it changes the structure. MDSAP is built on ISO 13485 and layers in country-specific regulatory requirements from up to five markets, using a process-based sequence and a points-based Grade 1–5 nonconformity system rather than the minor/major classification used in standard certification audits.

What’s the most common reason internal audit programs fail a certification audit?

Incomplete records — missing audit reports, plans, or linked CAPAs — combined with no evidence of a risk-based approach to scheduling. Both are findings a Notified Body catches quickly because they’re procedural gaps, not technical ones.

Should we hire a consultant to run our internal audits, or can we do it ourselves?

Either can work if the auditor is properly trained and genuinely independent of the process. Many manufacturers use in-house auditors for most cycles and bring in an outside auditor periodically to test whether their internal program is actually rigorous or just familiar with its own blind spots.


📥 Free Resources


Not Sure What to Do Next?

🔹 Still researching your audit obligations? Start with ISO 13485 Documentation Requirements to understand what your QMS needs on paper before you audit it.

🔹 Ready to build or strengthen your audit program? 9001Simplified’s documentation templates can shortcut the SOP-writing process without a consultant retainer.

🔹 Need the standard itself to build your checklist against? Get ISO 13485:2016 from ANSI Webstore — code CC2026 takes 5% off through the end of 2026.


An internal audit program that only exists to satisfy Clause 8.2.4 on paper was already a risk before the QMSR removed the confidentiality safe harbor. Now it’s a document an inspector can read directly. The Standards Navigator will keep tracking what QMSR enforcement and ISO 19011:2026 mean for how medical device manufacturers actually run their audit programs — not just what the clause says.


Subscribe for Medical Device Compliance Updates

Most manufacturers don’t lose a certification over one bad audit finding — they lose it over a pattern of findings their own internal audit program should have caught first. Organizations that treat Clause 8.2.4 as a paperwork requirement get surprised at surveillance. Organizations that treat it as their first line of defense rarely do.

The Standards Navigator tracks how ISO 13485, the FDA QMSR, and the standards that govern medical device audits actually work in practice — not just what the clause text says.

👉 Get updates on ISO 13485 audit requirements and QMSR enforcement changes 👉 Be first to access new medical device compliance checklists and gap assessment tools

Subscribe below to stay ahead.

Subscribe

* indicates required

The Standards Navigator — Industrial Compliance. Clearly Explained.

Aerospace Supplier Compliance Standards: What Every Supplier Needs to Know in 2026

Aerospace suppliers face a layered compliance landscape — AS9100 certification is the baseline, but NADCAP accreditation, First Article Inspection, counterfeit parts controls, and customer flow-down requirements are equally enforced. This guide covers every standard and program aerospace primes audit against, with practical checklists and implementation guidance for quality managers.

The complete guide to AS9100, NADCAP, FAI, and the quality requirements aerospace primes actually enforce

Affiliate Disclosure: Some links in this article are affiliate links. If you purchase through them, The Standards Navigator may earn a commission at no additional cost to you.


The Aerospace Supply Chain Has a Short Memory for Second Chances

You get one bad audit. One missed First Article Inspection. One nonconformance that reaches the flight line. That is all it takes to lose an aerospace contract you spent years building.

Aerospace primes — Boeing, Lockheed Martin, Raytheon, Northrop Grumman — do not operate on goodwill. They operate on documented, auditable evidence that every supplier in their chain meets a defined set of compliance requirements. Those requirements are not flexible. They are not negotiable. And they are layered — meaning AS9100 certification alone does not cover everything your customer may require.

This aerospace supplier compliance standards guide breaks down the full compliance landscape: the standards, the programs, the certification requirements, and what aerospace suppliers actually get audited against on the shop floor.

If you are preparing for your first aerospace contract, adding an aerospace customer to an existing customer base, or trying to understand why your customer’s supplier quality team keeps asking for documentation you did not know you needed — this is where to start.

Before your Stage 1 audit, know exactly where your QMS stands. Run a clause-by-clause gap assessment now — before your registrar does. Download the AS9100 Rev D Gap Assessment Checklist →


In This Guide

  • The AS9100 Rev D standard and what it requires beyond ISO 9001
  • NADCAP accreditation — what it is, which processes require it, and when it applies
  • First Article Inspection (AS9102) — scope, deliverables, and common findings
  • Counterfeit parts prevention and AS5553/AS6174
  • FOD control requirements
  • Customer-specific flow-down requirements and how to manage them
  • How to verify a supplier’s certifications before awarding a contract


👉 Start Here — Top Resources for Aerospace Suppliers

Before you read further, these are the resources aerospace suppliers actually use:


AS9100 Rev D: The Foundation of Aerospace Quality

Quality engineers review aerospace supplier compliance standards inside a modern aircraft manufacturing facility with a fuselage assembly, machining equipment, and inspection stations
Quality personnel review engineering documentation on the aerospace shop floor while aircraft structures and manufacturing operations continue in the background.

AS9100 is the non-negotiable baseline. Every organization supplying parts, assemblies, or services to the aerospace and defense industry — whether you are a Tier 1, Tier 2, or Tier 3 supplier — is expected to hold AS9100 certification or demonstrate that your QMS meets equivalent requirements.

AS9100 Rev D is the current revision, published in 2016. It incorporates all of ISO 9001:2015 verbatim and adds aerospace-specific requirements on top of the quality management foundation. The IAQG — International Aerospace Quality Group — governs the standard and maintains the OASIS certification database.

What AS9100 Adds Beyond ISO 9001

The standard adds requirements that reflect the risk profile of aerospace manufacturing — where a single nonconformance can have catastrophic consequences. Key additions include:

AS9100 RequirementISO 9001 EquivalentWhy It Matters in Aerospace
Risk management (beyond Clause 6.1)Risk-based thinkingFormal risk identification, mitigation, and tracking for each program
Configuration managementNot requiredEnsures part revisions are controlled and traceable across the supply chain
First Article Inspection (FAI)Not requiredRequired verification that first production part meets all design requirements
Product/process change controlChange managementAny deviation from approved baseline requires documented approval
Counterfeit parts preventionNot requiredDocumented controls to prevent unapproved or fraudulent parts from entering the supply chain
FOD preventionNot requiredForeign Object Damage/Debris programs with documented procedures
Customer-designated special requirementsNot requiredFlow-down and implementation of prime contractor requirements
Key characteristicsNot requiredIdentification and control of dimensions or features with elevated risk

Most common finding: Organizations that are ISO 9001 certified assume the gap to AS9100 is small. It is not. The configuration management, FOD, and counterfeit parts requirements alone require building procedures that do not exist in a typical ISO 9001 QMS.

If you are already ISO 9001 certified, the AS9100 vs ISO 9001 comparison breaks down every additional requirement clause by clause.

For complete scope on what AS9100 certification involves, what it costs, and how long it takes, the What Is AS9100? pillar article covers the full picture.


NADCAP: Special Process Accreditation

NDT technician performing ultrasonic testing on an aerospace aluminum component using an ultrasonic probe and portable inspection instrument displaying waveform data.
An NDT technician conducts ultrasonic inspection on an aerospace component to verify material integrity and identify potential internal defects.

NADCAP is separate from AS9100 — and your customer will require both.

NADCAP — National Aerospace and Defense Contractors Accreditation Program — is a special process accreditation program managed by the Performance Review Institute (PRI). It applies to organizations performing specific high-risk manufacturing processes where process control is critical to product integrity.

AS9100 certifies your quality management system. NADCAP accredits specific processes within that system. A machined airframe component supplier may need AS9100 certification. If that same supplier performs heat treating, NDT, or chemical processing in-house, NADCAP accreditation is required for those processes — regardless of AS9100 status.

Processes That Require NADCAP Accreditation

Process CategoryExamples
Heat TreatingAnnealing, aging, stress relief, case hardening
Non-Destructive Testing (NDT)Ultrasonic, radiographic, penetrant, magnetic particle, eddy current
Chemical ProcessingAnodizing, plating, passivation, conversion coating
WeldingFusion welding per aerospace specifications
CoatingsThermal spray, paint (where specified by prime)
CompositesLay-up, cure, bonding operations
Electrical/Electronic ProcessingSoldering, conformal coating
Fluid Distribution SystemsTube bending, assembly

What NADCAP Audits Cover

NADCAP audits are process-specific and technically rigorous. Auditors evaluate process parameters, equipment qualification, operator qualification, traceability of materials, and conformance to applicable customer and industry specifications.

A NADCAP audit is not a QMS audit — it is a process performance audit. Findings are classified as Critical, Major, or Minor. Critical findings result in immediate suspension of work.

If you are a supplier: Do not assume your customer will accept your subcontractor’s NADCAP accreditation for flow-down purposes without reviewing the approved scope. NADCAP accreditation is scope-specific. Heat treating accreditation for aluminum alloys does not cover titanium heat treating.

If your aerospace customer has asked for NADCAP compliance in your supplier requirements — and you are not sure what processes in your facility are in scope — your AS9100 QMS needs a process risk review before your next customer audit. Download the AS9100 Rev D Gap Assessment Checklist →


First Article Inspection: AS9102

First Article Inspection is one of the most frequently cited sources of supplier nonconformances in aerospace.

AS9102 — Aerospace First Article Inspection Requirement — defines the methodology for verifying that the first production article (or first article after a significant change) meets all engineering, design, and manufacturing requirements. The standard is separate from AS9100 but is required by AS9100 Rev D Clause 8.1.3.

What FAI Covers

A complete FAI under AS9102 includes three forms:

FormTitleScope
Form 1Design DocumentationVerification that the correct drawing revision, specifications, and notes are captured
Form 2Product AccountabilityBill of materials, materials certification, and raw material traceability
Form 3Characteristic AccountabilityMeasurement of every dimension and characteristic on the drawing — not a sample

Form 3 is where most suppliers get tripped up. Every characteristic on the engineering drawing — not a selected subset — must be measured and documented. This includes tolerances, surface finishes, thread forms, and any geometric dimensioning and tolerancing (GD&T) callouts.

When FAI Is Required

FAI is not a one-time event. AS9102 specifies that a new or updated FAI is required when:

  • A new part number is introduced to production
  • A drawing or specification is revised (full or partial FAI, depending on the scope of change)
  • A manufacturing process, facility, or tooling is changed in a way that could affect form, fit, or function
  • Production has been inactive for more than two years

Most common finding: Suppliers treat FAI as a drawing check rather than a full measurement event. Partial FAIs submitted without Form 2 material traceability or without measuring all Form 3 characteristics are rejected by customer quality teams and result in production holds.


Counterfeit Parts Standards: AS5553 and AS6174

Counterfeit parts are a documented safety risk in aerospace. The FAA, DoD, and aerospace primes have all implemented mandatory controls. Your QMS must address them explicitly.

Two SAE standards define the requirements:

AS5553 — Fraudulent/Counterfeit Electronic Parts: Avoidance, Detection, Mitigation, and Disposition. Applies to electronic components — integrated circuits, semiconductors, connectors, and any electronics where counterfeit substitution is a risk.

AS6174 — Counterfeit Materiel: Avoidance, Detection, Mitigation, and Disposition. Broader scope covering raw materials, fasteners, and other non-electronic hardware.

What Your QMS Must Include

A compliant counterfeit parts program under AS9100 Rev D requires documented procedures covering:

  • Approved supplier lists (ASL): Purchasing only from authorized manufacturers, franchised distributors, or approved aftermarket sources
  • Receiving inspection: Risk-based inspection criteria for parts that cannot be sourced from authorized channels
  • Traceability: Certificate of conformance, test reports, and chain of custody documentation for all parts
  • Suspect/confirmed counterfeit parts: Quarantine, reporting, and disposition procedures — including mandatory reporting to GIDEP (Government-Industry Data Exchange Program) for defense contracts
  • Training: Evidence that personnel involved in procurement and receiving inspection are trained to identify suspect parts

If you are a manufacturer and not a distributor, the most critical element is your approved supplier list and purchasing controls — because your customer’s AS9100 audit will verify that you are buying from controlled sources.


FOD Control Requirements

Aerospace tool control shadow board displaying torque wrenches, calipers, safety wire pliers, borescope, and precision hand tools with one tracked tool removed.
A structured tool control system helps aerospace manufacturers maintain accountability, prevent FOD incidents, and ensure every tool is tracked throughout production.

Foreign Object Damage and Debris is a zero-tolerance issue in aerospace.

FOD — Foreign Object Damage or Debris — refers to any substance, material, or item that could potentially damage equipment or endanger personnel. A loose fastener in a fuel system. A rag left in an aircraft cavity. Metal chips in a precision assembly. In aerospace, these are not housekeeping issues — they are quality system failures.

AS9100 Rev D Clause 8.5.1 requires documented controls to prevent FOD throughout manufacturing, assembly, and test operations. Customer-specific FOD requirements are typically more detailed and flow down through purchase order terms.

Minimum FOD Program Elements

✅ Written FOD prevention procedure specific to your facility and processes
✅ Designated FOD critical areas with defined access controls
✅ Tool control program — shadow boards, tool counts, calibrated tool tracking
✅ Contamination controls during assembly and inspection operations
✅ FOD walks and documented area inspections on defined frequency
✅ Employee training and awareness records
✅ FOD incident reporting and corrective action process
✅ Customer notification procedure when FOD is suspected or confirmed

Most common finding: FOD programs exist as a procedure document but are not operationally active. Auditors look for evidence — completed FOD walk records, tool control logs, training records — not just a written procedure. The procedure without the records is a Major finding.


Customer Flow-Down Requirements

Your prime contractor’s requirements are your requirements.

This is the element that surprises suppliers who are new to aerospace. AS9100 certification means you have a compliant quality management system. It does not mean your prime contractor’s specific engineering, quality, and documentation requirements are automatically met. Those flow down — meaning they are passed from the prime to you through purchase order terms, quality clauses, and source control documentation.

Common Flow-Down Requirements

CategoryExamples
Quality planFirst Article requirements, inspection frequencies, statistical process control
EngineeringSpecification compliance, drawing revision control, DER approvals
MaterialMaterial certifications, approved material sources, trace requirements
ManufacturingApproved process specifications (e.g. BAC, SPE, DPS), NADCAP process approvals
DocumentationRecord retention requirements (typically 10+ years for flight-critical parts)
Access and oversightRight-to-access for customer source inspection, government source inspection
ReportingGIDEP reporting, escape reporting, timelines for nonconformance notification

Managing Flow-Down in Your QMS

Your QMS must have a documented process for:

  1. Reviewing purchase orders for quality clauses before accepting the order
  2. Translating customer requirements into internal work instructions and inspection plans
  3. Verifying that sub-tier suppliers (your suppliers) receive applicable flow-down requirements
  4. Maintaining records that demonstrate compliance with customer-specific requirements

If you are receiving flow-down requirements you do not understand: Your customer’s supplier quality team is your first contact. Do not guess. Documenting a misunderstood requirement incorrectly is worse than asking for clarification — because the audit finding will be a major nonconformance, not a simple misunderstanding.

If you are evaluating whether your quality system is ready for AS9100 certification, start with the How Much Does AS9100 Certification Cost? article for a complete breakdown of what certification actually involves.

BSI Group offers AS9100 training specifically designed for suppliers building compliant QMS documentation — covering the clause requirements and flow-down obligations that come with aerospace contracts.


How to Verify Supplier Certifications

Never take a supplier’s word for AS9100 certification. Verify it directly.

The IAQG OASIS Database is the official global registry for AS9100, AS9110, and AS9120 certifications. Every accredited certification is listed with scope, effective date, expiration date, and the certification body that issued it. If a supplier claims AS9100 certification and they are not in OASIS, the certification is not valid.

What to Verify in OASIS

  • Certification status: Active, suspended, or withdrawn
  • Scope of certification: Does it cover the specific product category or process your supplier is performing?
  • Expiration date: AS9100 certificates expire and require surveillance audits — a certificate that has not been renewed is not valid
  • Certification body: Is the CB accredited by a recognized accreditation body (ANAB, DAkkS, UKAS)?

For NADCAP accreditation verification, the PRI supplier database at pri-network.org lists all accredited suppliers by commodity and scope.

If you are a quality manager building or updating an approved supplier list for an aerospace program — your supplier evaluation process needs to include OASIS verification as a mandatory step before award and at each annual review.


Compliance Checklist for Aerospace Suppliers

Use this checklist to assess your current compliance posture before a customer audit or certification audit.

Quality Management System
✅ AS9100 Rev D certification current and active in OASIS
✅ QMS manual and procedures documented and controlled
✅ Internal audit program covers all AS9100 clauses — not just ISO 9001 requirements
✅ Management review records demonstrate review of aerospace-specific metrics

First Article Inspection
✅ FAI procedure documented per AS9102
✅ Form 1, Form 2, and Form 3 completed for all active part numbers
✅ FAI triggers defined — changes that require new or partial FAI
✅ FAI records retained and retrievable

Counterfeit Parts
✅ Counterfeit parts prevention procedure in place
✅ Approved supplier list (ASL) current and controls defined
✅ Receiving inspection criteria address suspect parts
✅ Personnel training records current

FOD
✅ FOD prevention procedure active and specific to your facility
✅ FOD walk and inspection records maintained on required frequency
✅ Tool control program in place with records
✅ Employee training documented

Flow-Down
✅ Purchase order review process in place
✅ Customer quality clauses translated to internal requirements
✅ Sub-tier flow-down process documented and verified
✅ Record retention meets customer requirements (typically 10+ years)

NADCAP (if applicable)
✅ All in-scope special processes identified
✅ NADCAP accreditation current for each process
✅ Scope of accreditation matches actual work performed
✅ Sub-tier NADCAP requirements verified and documented


FAQ

What is the difference between AS9100 and NADCAP?

AS9100 Rev D is a quality management system standard that certifies your organization’s overall quality processes — planning, documentation, corrective action, customer satisfaction, and so on. NADCAP is a special process accreditation that applies to specific manufacturing processes such as heat treating, NDT, chemical processing, and welding. AS9100 certification is a QMS-level requirement. NADCAP is a process-level requirement. Aerospace suppliers performing special processes are typically required to hold both.

Do I need AS9100 certification to supply aerospace parts?

In most cases, yes — if you are a direct supplier (Tier 1 or Tier 2) to an aerospace prime or defense contractor. Some lower-tier commodity suppliers may not be required to hold AS9100 certification, but customer flow-down requirements and purchase order quality clauses will define the specific requirement. Review your customer’s supplier quality requirements before assuming certification is not needed.

How do I know if my process requires NADCAP accreditation?

Review your customer’s purchase order quality clauses and their approved supplier requirements document. Primes typically maintain a list of processes that require NADCAP accreditation for their programs. If you perform heat treating, NDT, chemical processing, or welding on aerospace parts and your customer has not specified NADCAP — ask. The absence of a requirement on the PO does not always mean the requirement does not exist.

What is a First Article Inspection and when is it required?

A First Article Inspection (FAI) is a formal verification process, defined by AS9102, that the first production article meets all design and engineering requirements. It is required for new part introductions, after drawing or specification revisions, after significant manufacturing process or tooling changes, and after production gaps of two or more years. A complete FAI requires documentation on three forms covering design documents, material traceability, and measurement of every drawing characteristic.

How long does AS9100 certification take?

For an organization with no existing quality management system, the implementation and certification process typically takes 9 to 18 months. Organizations already certified to ISO 9001 can typically close the gap to AS9100 in 6 to 12 months, depending on the number of additional requirements that need to be built out. The How Much Does AS9100 Certification Cost? article covers timelines and costs in detail.

What is the OASIS database and how do I use it?

OASIS — Online Aerospace Supplier Information System — is the IAQG-maintained database of all AS9100, AS9110, and AS9120 certifications worldwide. You can search by organization name, location, or CAGE code to verify a supplier’s certification status, scope, expiration date, and issuing certification body. Access it at oasis.sae.org. Verifying supplier certifications in OASIS should be a standard step in your approved supplier list maintenance process.

What are customer flow-down requirements in aerospace?

Flow-down requirements are the specific quality, engineering, documentation, and process requirements that a prime contractor passes down to their supply chain through purchase order terms and quality clauses. They are legally binding once accepted on a PO. Common examples include FAI requirements, material certification requirements, NADCAP requirements for special processes, record retention periods, and customer source inspection rights. Your QMS must have a documented process for reviewing, implementing, and flowing these requirements to your own sub-tier suppliers.

Can I use my ISO 9001 certification for aerospace customers temporarily while pursuing AS9100?

In most cases, no. ISO 9001 certification does not meet AS9100 requirements. Some customers may grant a temporary waiver for lower-risk commodity suppliers, but for any direct aerospace supply involving flight-critical parts or assemblies, AS9100 certification is typically required before production can begin. Discuss your timeline with your customer’s supplier quality team — do not assume a waiver will be granted.


📥 Free Resources

AS9100 Rev D Gap Assessment Checklist — 74-item clause-by-clause checklist for aerospace suppliers assessing their QMS before certification. Covers every AS9100-specific requirement beyond ISO 9001.

ISO 9001 Roadmap — Step-by-step implementation guide for manufacturers building or improving a quality management system. Useful as a foundation before layering AS9100 requirements.

Manufacturing Compliance Checklist — Practical compliance reference covering key ISO, OSHA, and quality requirements for production environments.

Supplier Quality Checklist — Evaluation tool for assessing supplier quality controls and flow-down compliance before audits or new contracts.

ISO 13485 Gap Assessment Checklist — Free checklist for medical device manufacturers assessing their QMS against ISO 13485 requirements.


Not Sure What to Do Next?

🔹 If you are new to aerospace and need to understand AS9100 from the ground up — start with What Is AS9100? for a complete overview of the standard, certification process, and supply chain requirements.

🔹 If you are ready to buy the AS9100 Rev D standard — purchase the official document through the ANSI Webstore. Use code CC2026 for 5% off through December 31, 2026. The standard is available in digital and print formats and ships internationally.

🔹 If you need AS9100 training for your team or are selecting a certification bodyBSI Group offers the full range of AS9100 courses from awareness through lead auditor, and serves as both a training provider and accredited certification body.

Aerospace compliance is not a project with a finish line. Certification is the beginning. The organizations that hold their approvals and grow within the supply chain are the ones that build compliance into operations — not just into audit prep.

The Standards Navigator covers the full aerospace compliance landscape, from AS9100 certification requirements to NADCAP process accreditation and FAI methodology. Use the resources above to make your next audit a confirmation of what you already know — not a discovery of what you missed.


Stay Ahead of Aerospace Compliance Changes

Losing an aerospace approval because a standard revision or customer requirement changed while you were focused on production is the most preventable kind of failure. Most organizations that fall behind on compliance don’t miss the requirement — they miss the update.

The suppliers who keep their approvals long-term are the ones who treat compliance information the same way they treat production scheduling: as an ongoing operational discipline, not a one-time project.

The Standards Navigator covers AS9100, NADCAP, FAI, and the full aerospace supplier compliance landscape — explained in plain language for quality managers and operations teams who need to act on the information, not just read it.

👉 Get updates when new aerospace compliance articles are published
👉 Be first to access new AS9100 implementation resources and checklists

Subscribe below to stay ahead.

Subscribe

* indicates required

The Standards Navigator — Industrial Compliance. Clearly Explained.