AS9100 Documentation Requirements: What Auditors Actually Check (2026)

This guide breaks down what AS9100 Rev D actually requires in documented information — from first article inspection and traceability records to counterfeit parts prevention and configuration management. It explains which records auditors pull first, where most aerospace suppliers fall short, and how AS9100 documentation differs from a standard ISO 9001 system.

A clause-by-clause breakdown of what your aerospace QMS documentation needs — and where most suppliers fall short

Affiliate Disclosure: Some links in this article are affiliate links. If you purchase through them, The Standards Navigator may earn a commission at no additional cost to you.


The Documentation Gap That Fails Aerospace Audits

AS9100 documentation requirements cover the documented information needed to operate and demonstrate an aerospace QMS, along with aerospace-specific records and controls in areas such as configuration management, traceability, counterfeit parts prevention, first article inspection, and FOD control. The exact documents and records an organization maintains depend on its processes, applicable requirements, and customer flow-downs.

AS9100 documentation isn’t ISO 9001 paperwork with an aerospace label stuck on it. Traceability records, first article inspection (FAI) data, and configuration management records aren’t background paperwork — auditors use them as objective evidence that aerospace parts were manufactured and controlled according to applicable requirements.

Most suppliers assume a quality manual and a stack of procedures covers it. Then an auditor selects a part number, asks for the traceability record behind its FAI, and finds the two don’t connect — what looked like a minor gap becomes a major nonconformance.

Whether you’re mapping documentation before your first Stage 1 audit or checking an existing system against Rev D, this breaks down exactly what auditors pull first — and where the gaps usually are.

FROM THE SHOP FLOOR: I’ve sat across the table from an AS9100 auditor who skipped the quality manual entirely and went straight for first article inspection records on a part we’d shipped eight months earlier. We had the FAI — what we didn’t have was the linked traceability record showing which material heat lot went into it. That gap alone became a major finding. Auditors aren’t grading your paperwork; they’re testing whether your records actually trace back to the part in front of them.

👉 Most AS9100 documentation gaps don’t surface until an auditor asks for a specific record — by then it’s too late to fix quietly. Run the AS9100 Rev D Gap Assessment Checklist before your next audit and find out exactly where your documentation stands.

In this guide:

  • What AS9100 documented information actually requires — and where it goes beyond ISO 9001
  • Whether you still need a quality manual under Rev D
  • The core records auditors pull first: FAI, traceability, counterfeit parts, FOD
  • Two documentation areas most suppliers underbuild
  • Common findings and how to close them before your audit
  • Where to buy the standard and find training if you’re building this from scratch


👉 Start Here


What “Documented Information” Actually Means Under AS9100

AS9100 Rev D uses the same “documented information” language as ISO 9001 — but the aerospace-specific clauses layer on requirements that don’t exist in a standard ISO 9001 system at all.

AS9100 Rev D does not explicitly require a document called a quality manual. The practical takeaway is that eliminating a document called a “quality manual” does not eliminate the need to document and communicate how your QMS is structured.

Many aerospace organizations continue to use a quality manual because it provides a practical way to describe the QMS and its relationship to the applicable requirements — and it’s the document reviewers commonly use to navigate everything else.

Where AS9100 genuinely goes further than ISO 9001 is in the aerospace-specific documented information requirements: first article inspection, more extensive material and process traceability, counterfeit parts prevention, foreign object debris (FOD) control, and configuration management. None of these have a real equivalent in a baseline ISO 9001 system — see What Is AS9100? for the full standard overview if you’re still mapping out scope.

If you’re building this documentation structure from scratch rather than adapting an existing ISO 9001 system, the ISO Documentation Kits for Manufacturers page is a reasonable starting point for the underlying procedures and forms — just plan to adapt anything generic to AS9100’s aerospace-specific requirements before relying on it for certification.


AS9100 documentation requirements showing an aerospace auditor reviewing FAI, traceability, counterfeit parts prevention, FOD control, and process records
AS9100 documentation requirements include objective evidence showing that aerospace parts and processes were controlled as required.

The Core Records Auditors Pull First

First Article Inspection Records

A common audit approach is to select a specific part number and request the FAI record supporting it, along with the traceability behind it. FAI reporting itself is governed by AS9102, published by SAE International. Full requirements — including what counts as a valid FAI and when a re-FAI is triggered — are covered in First Article Inspection Requirements.

Traceability Records

Traceability records should allow applicable material, batch/lot, and process information to be traced through the product lifecycle to the shipped part, based on the organization’s processes and applicable requirements — not just exist as separate records. See AS9100 Traceability Requirements for what Clause 8.5.2 actually demands.

Counterfeit Parts Prevention Records

Documented controls for counterfeit parts prevention are required under Clause 8.1.4 — and auditors check whether they’re actually followed, not just written. Full breakdown in AS9100 Counterfeit Parts Standards.

FOD Control Records

AS9100 expects documented controls and evidence appropriate to the organization’s processes for preventing foreign object debris — the specific form that takes varies by operation. See FOD Control Standards for what Clause 8.5.4 requires.

A recurring pattern I’ve seen: these four record types exist independently but aren’t cross-referenced. An auditor pulls an FAI, asks for the traceability record behind it, and finds no clear link between the two documents — even though both technically exist. In practice, that kind of disconnect often draws more scrutiny than a missing document, because it suggests the system isn’t actually being used to trace parts, just to generate paperwork.

The Audit Trail: Part Number → Revision → Material Lot → Process Route → FAI → Final Record

An auditor doesn’t just want to see that each record in that chain exists individually. They want to see how the records relate to each other and to the specific part in front of them. (This makes a strong visual for the published page — worth building as a simple graphic rather than just text.)

👉 If your traceability records and FAI paperwork don’t reference each other by part number and revision, that’s a gap worth closing before an audit tests it. Download the Manufacturing Compliance Checklist and confirm your records connect.

AS9100 documentation requirements audit trail showing part number, drawing revision, material heat lot, process routing, FAI, and shipped product
AS9100 documentation requirements connect the part number, revision, material, process, inspection, and final shipment into a traceable audit trail.

Two Documentation Areas Most Suppliers Underbuild

Configuration Management Documentation (Clause 8.1.2)

Configuration management — tracking exactly which design revision, engineering change, and customer-approved deviation applies to a given part — gets far less attention than FAI or traceability, but auditors increasingly check it as a standalone item. If your documentation doesn’t clearly show which configuration was in effect at the time of manufacture, that’s a gap worth closing before it becomes a finding. This is dense enough to deserve its own dedicated breakdown — flagging it here as a topic to watch.

Risk-Based Documentation for Special Processes

Special processes — such as welding, heat treating, and nondestructive testing — carry their own documented risk requirements under AS9100’s risk-based thinking clauses. Nadcap accreditation may apply separately when required by a customer or applicable supply-chain requirements; that accreditation question is covered in NADCAP vs AS9100. The documentation angle specifically — how you document special-process risk decisions, distinct from whether you’re Nadcap-accredited — is underserved content-wise and worth a dedicated piece.


How AS9100 Documentation Differs from ISO 9001

CategoryISO 9001AS9100
Quality ManualNot explicitly mandatedNot explicitly mandated, but commonly used in practice
First Article InspectionNo aerospace-specific FAI requirementIncorporated through AS9100 and applicable customer requirements; AS9102 (SAE) governs FAI reporting
TraceabilityGeneral requirement, scope flexibleMore extensive material/process traceability, including customer- and product-specific requirements where applicable
Counterfeit Parts PreventionNo equivalent requirementDocumented controls required (Clause 8.1.4)
Configuration ManagementNo equivalent requirementRequired (Clause 8.1.2)
FOD ControlNo equivalent requirementDocumented controls and evidence appropriate to the organization’s processes and applicable requirements

For the full standard-by-standard comparison beyond documentation specifically, see AS9100 vs ISO 9001.

👉 Building this documentation structure without a consultant is realistic — but only if you’re working from the current edition. Buy the AS9100 Rev D standard through ANSI Webstore and use code CC2026 for 5% off.


What Happens When Documentation Doesn’t Hold Up

A documentation gap doesn’t automatically fail an audit — but an auditor who finds one disconnected record set often digs deeper, and what started as a single finding turns into a pattern of findings across the whole system. That’s the real cost: not the first gap, but what it triggers.

The cost objection: it’s fair to wonder whether this level of documentation rigor is overkill for a small shop with a handful of part numbers. When FAI and traceability requirements apply, a five-person shop and a five-hundred-person supplier may need to maintain the same core record types for a given part number; the difference is the complexity of the system used to manage them.

If you’re deciding whether your existing system is ready, AS9100 Internal Audit Process walks through running that check yourself before a registrar does it for you. And if you haven’t picked a certification body yet, AS9100 Certification Bodies — Ranked & Reviewed is a good next stop — worth confirming the body you choose is itself accredited by a recognized accreditor such as ANAB.

In practice, traceability is a significant part of aerospace QMS auditing because auditors need objective evidence that product and process records can be connected to the requirements they support.


Quick Documentation Checklist

✅ Quality manual (or equivalent scope document) references all applicable Rev D clauses

✅ FAI records exist and cross-reference traceability records by part number and revision

✅ Traceability records identify applicable material heat/lot/batch information for shipped parts, based on customer, product, and process requirements

✅ Documented controls for counterfeit parts prevention are in place and actively followed, not just written

✅ FOD controls are documented and supported by evidence appropriate to the organization’s processes and applicable requirements

✅ Configuration management records show which design revision applied at time of manufacture

✅ Special process records (welding, heat treat, NDT, etc.) are retained per customer and registrar requirements


AS9100 documentation requirements showing the difference between controlled documents and records used as objective audit evidence
AS9100 documentation requirements distinguish controlled information from records that provide objective evidence processes were performed.

FAQ

Is a quality manual required under AS9100 Rev D?

Not explicitly by the standard’s own wording — but many aerospace organizations continue to use one because it provides a practical way to describe the QMS and map it to the standard’s structure. Skipping it entirely can create more audit friction than it saves in paperwork, since certification bodies commonly expect some document that fills that role.

What documents does an AS9100 auditor ask for first?

A common audit approach is to select a specific part number and request the first article inspection record supporting it, followed by the traceability record behind that FAI. Auditors use this pairing to test whether your documentation system actually connects, not just exists.

What’s the difference between documented information and records under AS9100?

Documented information is the broader AS9100 term covering anything required to be created, maintained, and controlled — procedures, work instructions, and forms all count. Records are a specific type of documented information that provide evidence of results, like a completed FAI or a calibration record. Every record is documented information, but not everything documented is a record.

How long do AS9100 records need to be retained?

Retention periods vary by customer contract and registrar requirement rather than a single fixed AS9100 rule — many aerospace customers require retention well beyond typical ISO 9001 timeframes, sometimes for the life of the program. Check your specific customer flow-down requirements rather than assuming a default period applies.

Do I need separate documentation for each customer?

Not necessarily separate systems, but you likely need customer-specific supplemental requirements layered onto your core AS9100 documentation — most aerospace OEMs have their own flow-down requirements beyond the base standard.

What is a common AS9100 documentation finding?

One recurring documentation problem is records that exist individually but aren’t cross-referenced — an FAI with no linked traceability record, or a traceability record that doesn’t tie back to the part it supports. The documents technically exist; they just don’t function as a connected system.

Can I use the same documentation system for ISO 9001 and AS9100?

Largely yes for the shared core structure, but AS9100-specific records (FAI, counterfeit parts prevention, configuration management, FOD control) have no ISO 9001 equivalent and need to be built as additions, not substitutions.

Do I need software to manage AS9100 documentation, or can spreadsheets work?

Spreadsheets can work for a small shop with limited part numbers, but the risk grows with volume — the more parts and revisions you’re tracking, the easier it becomes for records to silently disconnect from each other, which is the exact failure pattern auditors catch most often.

How much documentation does a small aerospace supplier actually need?

The same core record types as a larger supplier — a small shop doesn’t get a reduced list of required records. What differs is the complexity of the system used to manage them; a simpler operation can often meet the same requirements with a leaner, more manual system than a high-volume supplier needs.


📥 Free Resources


Not Sure What to Do Next?

🔹 Still researching what AS9100 documentation actually requires? Start with What Is AS9100? for the full standard overview.

🔹 Ready to build your documentation structure? Buy the current AS9100 Rev D standard through ANSI Webstore — you can’t build compliant documentation from an outdated edition.

🔹 Need training to get your team up to speed? BSI Group’s AS9100 training courses cover documentation requirements clause by clause.

🔹 Want a professional gap assessment first? Download the free AS9100 Rev D Gap Assessment Checklist.

Documentation is where AS9100 audits are actually won or lost — not in the quality manual, but in whether your records connect to the parts they’re supposed to trace. Get the structure right from the beginning, and maintaining audit-ready evidence becomes far easier. That’s the standard The Standards Navigator holds every AS9100 guide to.


Stay Ahead of Your Next AS9100 Audit

Most aerospace suppliers don’t fail audits because they lack documentation — they fail because their documentation doesn’t connect. FAI records that don’t reference traceability. Traceability that doesn’t tie to configuration. Individually complete, collectively disconnected.

Suppliers who struggle treat documentation as a checklist exercise, built once and left alone. Suppliers who succeed build cross-referencing into every record from day one, so nothing has to be reconstructed under audit pressure.

The Standards Navigator covers AS9100 implementation for aerospace suppliers building audit-ready quality systems from the ground up.

👉 Get updates on AS9100 and aerospace compliance

👉 Be first to access new gap assessment checklists and documentation templates

Subscribe

* indicates required

Industrial Compliance. Clearly Explained.

AS9100 Counterfeit Parts Standards: What Clause 8.1.4 Actually Requires in 2026

AS9100 Clause 8.1.4 requires aerospace suppliers to prevent counterfeit and suspect counterfeit parts from entering their supply chain. This guide breaks down how AS5553, AS6174, and AS6081 apply, where DFARS counterfeit clauses raise the bar for defense work, and what a right-sized prevention program looks like for suppliers of every size.

AS5553, AS6174, and AS6081 explained for aerospace suppliers building a counterfeit parts prevention program

Affiliate Disclosure: Some links in this article are affiliate links. If you purchase through them, The Standards Navigator may earn a commission at no additional cost to you.


A Counterfeit Part Doesn’t Announce Itself

A relabeled transistor looks identical to the real thing until it fails in the field. A remarked fastener passes visual inspection until someone pulls the cert and finds the lot number doesn’t trace back to anywhere real. That’s what makes counterfeit parts different from every other nonconformance you deal with — the part isn’t defective, it’s fraudulent, and your normal inspection process was never built to catch it. Closing that gap is exactly what AS9100 counterfeit parts controls exist to do.

If you’re certified to AS9100, you already know Clause 8.1.4 exists — if you’re still working through what AS9100 actually requires at a higher level, this clause is one piece of a much larger operational planning section. What trips up a lot of suppliers is figuring out how much program they actually need to build, which of the SAE standards apply to their specific supply chain, and whether their customer’s flow-down requirements go further than the base AS9100 clause does.

This guide breaks down what 8.1.4 requires, how AS5553, AS6174, and AS6081 fit together, where DFARS counterfeit clauses come into play for defense work, and what a right-sized prevention program looks like for a supplier that isn’t building satellites.

From the Floor: I’ve sat across the table from a supplier during a corrective action review after a customer audit flagged a raw material lot with no traceable mill certification — not a counterfeit electronic part, but the same root failure: nobody had a documented process for verifying the source before it hit the shop floor. The fix wasn’t complicated. It was a two-page procurement control procedure and a supplier approval list that didn’t exist before. Most operations managers assume counterfeit prevention means expensive testing equipment. Most of the time, it means closing the gap between what you assume your buyer is checking and what’s actually written down.

Before you build or rebuild a counterfeit parts prevention procedure, most operations managers are working from the wrong starting point — assuming their existing purchasing controls already cover it. Run a clause-by-clause AS9100 gap check before you touch your procurement procedure — most gaps show up in 8.1.4 first. Get the free AS9100 Rev D Gap Assessment Checklist and see exactly where your documentation stands against all 74 clause-level requirements, including counterfeit parts control.


In This Guide

  • What AS9100 Clause 8.1.4 requires — and what it deliberately leaves open
  • Why traceability is the foundation of counterfeit prevention
  • What qualifies as a suspect counterfeit part
  • AS5553, AS6174, and AS6081: which standard applies to your supply chain
  • DFARS 252.246-7007 and 252.246-7008 for defense-flow-down contractors
  • The three control points every prevention program needs: purchasing, receiving, inspection
  • GIDEP and why registrars ask about it during audits
  • Building a right-sized program if you don’t handle electronic parts
  • Common audit findings and how to close them


👉 Start Here (Top Resources)

  • AS9100 Rev D Gap Assessment Checklist — free 74-item clause-by-clause checklist to find where your counterfeit parts documentation stands today
  • 9001Simplified — pre-built AS9100 documentation packages that include a counterfeit parts prevention procedure template, so you’re not starting from a blank page
  • SAE/AS9100 Standard — ANSI Webstore — the current edition, needed as your baseline reference for Clause 8.1.4
  • BSI AS9100 Training — if your team needs a working understanding of how counterfeit prevention integrates into your broader QMS audit prep

What Clause 8.1.4 Actually Says

Quick Answer: AS9100 Clause 8.1.4 requires organizations to establish processes that prevent counterfeit or suspect counterfeit parts from entering their product, addressing supplier controls, traceability, inspection, personnel training, reporting, and management of obsolete parts.

AS9100 is maintained by the International Aerospace Quality Group (IAQG). AS9100D introduced Clause 8.1.4, “Prevention of Counterfeit Parts,” as a standalone requirement inside the operational planning and control section. In plain terms, it requires your organization to plan, implement, and control processes appropriate to your organization and product to prevent the use of counterfeit or suspect counterfeit parts, and to minimize the impact if one is discovered.

Here’s the part that surprises people: the clause itself doesn’t name AS5553, AS6174, or AS6081 directly. It leaves the “how” open, which is deliberate — a machine shop making titanium brackets and a Tier 1 avionics integrator face completely different counterfeit exposure, and a one-size-fits-all mandate wouldn’t work for either.


The Five Areas AS9100 Counterfeit Parts Controls Must Address

What it does require, at minimum, is that your process address:

  • Personnel training on counterfeit part risks and detection
  • Application of methods for detection appropriate to the parts you purchase
  • Maintaining traceability of parts and components to their original or authorized manufacturer — the same traceability backbone covered in Clause 8.5.2, which is why weak traceability records are a common thread behind both types of findings
  • A process for reporting counterfeit or suspect counterfeit parts to appropriate authorities
  • Control of parts that reach obsolescence or are no longer supported by the original manufacturer

If you are already ISO 9001 certified → this is one of the requirements with no direct ISO 9001 equivalent, which means you can’t repurpose an existing procedure — you need something built specifically for this clause.


Why Traceability Is the Foundation of Counterfeit Prevention

Every control in a counterfeit prevention program eventually comes back to one question: can you trace this part to its original manufacturer? That’s not a coincidence — it’s why registrars frequently write findings against Clause 8.1.4 and Clause 8.5.2 together during the same audit. A gap in one is almost always a gap in the other.

A working traceability chain for counterfeit prevention typically covers:

  • Original manufacturer traceability — a documented path from the part in your hands back to the OEM or an authorized aftermarket manufacturer, not just to whichever distributor you bought it from
  • Lot traceability — the ability to isolate every unit affected by a specific lot if a counterfeit or nonconforming condition is discovered after the fact
  • Mill certification traceability — for raw material and hardware, a cert that actually matches the heat or lot number stamped on the material, not just a document that arrived alongside it
  • Serialization where applicable — for high-consequence or flight-critical parts, unit-level identification that survives the part through receiving, inspection, and installation

Most counterfeit investigations don’t start with a lab test — they start when someone tries to trace a part backward and hits a dead end. Auditors treat 8.1.4 and 8.5.2 as connected for exactly that reason: a counterfeit part is, by definition, a traceability failure somewhere upstream. If your organization can’t demonstrate an unbroken chain back to an authorized source, no amount of visual inspection at receiving closes that gap. If you’re building or revising your counterfeit prevention procedure, do it alongside your traceability procedure rather than treating them as two separate audit prep exercises — most of the objective evidence a registrar wants overlaps between the two.


What Qualifies as a Suspect Counterfeit Part?

AS9100 counterfeit parts decision flow infographic showing the process for verifying traceability, quarantining suspect parts, investigating suppliers, reporting findings, and completing corrective actions.
This AS9100 counterfeit parts workflow shows the recommended process for handling suspect counterfeit parts, from documentation review through quarantine, investigation, reporting, and corrective action.

Before your team can detect a suspect counterfeit part, they need a working definition of what one looks like. In practice, a part gets flagged as suspect counterfeit when one or more of these conditions shows up:

  • Altered certifications — a certificate of conformance or test report that’s been modified, or that doesn’t match the part it accompanies
  • Relabeled or remarked materials — physical evidence of resurfacing, re-etching, or blacktopping to hide the original part marking
  • Missing or inconsistent traceability records — no documented path back to an authorized source, or documentation that doesn’t align with the physical part
  • Incorrect manufacturer markings — logos, date codes, or lot numbers that don’t match known authentic formatting for that manufacturer
  • Mismatched lot or date code information — a cert referencing one lot while the physical part is marked with another
  • Unauthorized substitutions — a part that performs the intended function but wasn’t sourced through an approved or franchised channel

None of these alone proves a part is counterfeit — but any one of them is enough to trigger quarantine and further investigation under a properly scoped 8.1.4 procedure. Training personnel to recognize these indicators, rather than assuming counterfeit detection requires lab equipment, is often the single highest-value control in a right-sized program.


The Three SAE Standards Behind Counterfeit Prevention

Registrars auditing Clause 8.1.4 don’t expect you to have memorized these standards, but they do expect your procedure to reflect the intent behind them. All three are published by SAE International, the same standards body responsible for the AS9100-series documents. Three matter most:

StandardScopeWho Needs It
AS5553Counterfeit electronic parts — avoidance, detection, mitigation, dispositionAny organization that procures or integrates electrical, electronic, or electromechanical (EEE) parts
AS6174Counterfeit materiel more broadly — not limited to electronicsOrganizations sourcing raw material, hardware, and non-electronic components with counterfeit risk
AS6081Prescriptive avoidance requirements for independent distributors buying from the open marketDistributors and brokers, not manufacturers buying direct from OEMs

If your organization operates as an independent distributor or broker rather than buying direct from OEMs, AS6081 is written specifically for your position in the supply chain — it sets prescriptive avoidance requirements for open-market purchases that AS5553 and AS6174 don’t fully address.

AS5553 has gone through several revisions since it was first published in 2009, reflecting how counterfeit detection techniques and supply chain risk have evolved. The current edition is AS5553E, published in 2025 — always confirm you’re referencing this edition rather than an older one sitting in a binder from your last certification cycle. Get the current AS5553E standard through ANSI Webstore — it’s the source document for the avoidance, detection, mitigation, and disposition requirements referenced throughout this section. The same discipline applies to the AS9100 standard itself: buy from an authorized source and confirm you’re working from the current revision before you build a procedure around it.

AS9100 counterfeit parts infographic comparing authorized aerospace supply chains with high-risk open market sourcing, highlighting traceability, supplier approval, and counterfeit prevention.
This comparison illustrates how authorized suppliers, complete traceability, and approved sourcing reduce AS9100 counterfeit parts risk compared to open-market purchasing and broken documentation.

If your shop doesn’t touch electronic components at all — pure machining, fabrication, or coatings work — AS6174 is the more relevant reference, since it covers materiel counterfeiting broadly rather than EEE parts specifically. Don’t assume “no electronics” means “no counterfeit exposure.” Counterfeit and mismarked raw material, fasteners, and castings are a documented problem in the fabrication supply chain too.

⚠️ Most common finding: Suppliers write a counterfeit parts procedure that references AS5553 by name but only handles electronic components — leaving raw material and hardware purchasing completely uncovered. If you’re under customer pressure to certify quickly → prioritize scoping your procedure correctly before you invest time drafting it.


DFARS: When Defense Contracts Raise the Bar

If any part of your supply chain touches a Department of Defense contract, two DFARS clauses may apply on top of your AS9100 obligations: DFARS 252.246-7007 (Contractor Counterfeit Electronic Part Detection and Avoidance System) and DFARS 252.246-7008 (Sources of Electronic Parts).

What the Two Clauses Actually Require

These clauses apply specifically to contractors subject to Cost Accounting Standards, and they require a documented system addressing a defined set of risk areas — training, inspection and testing criteria, traceability from the original manufacturer through to Government acceptance, supplier qualification, reporting and quarantining, and monitoring of industry alert databases for suspect parts. The requirement traces back to Section 818 of the 2012 National Defense Authorization Act, which was the original legislative response to counterfeit electronic parts turning up in military hardware.

Flow-Down Applies Regardless of Contract Size

If you supply into the defense industrial base — even as a sub-tier supplier several layers removed from the prime contractor — these requirements can flow down contractually regardless of contract size. Don’t assume flow-down doesn’t apply to you because you’re small. Check your purchase order terms and conditions directly.


The Three Control Points Auditors Check

AS9100 counterfeit parts infographic showing the three critical control points of purchasing, receiving inspection, and final inspection for counterfeit prevention.
The three primary control points for AS9100 counterfeit parts prevention are purchasing, receiving inspection, and final inspection, each playing a critical role in protecting the aerospace supply chain.

Regardless of which standards you reference, a workable counterfeit prevention program controls three points in your process:

Purchasing — Your procedure needs to define authorized sources: original component manufacturers, authorized distributors, or franchised sources. Any purchase from the open market or an unfranchised broker should trigger additional scrutiny, not the same approval as a direct-from-OEM buy. If a prospective supplier claims AS9100 certification, verify it against the IAQG OASIS database rather than taking the certificate at face value.

Receiving — Incoming inspection needs criteria specific to counterfeit detection, not just dimensional and functional acceptance. This can be as simple as visual inspection for remarking or resurfacing on lower-risk parts, up to X-ray or decapsulation testing for high-consequence electronic components.

Final inspection — A last check before parts move into production or assembly, catching anything that slipped through receiving inspection or that entered through an internal process gap.

If you are preparing for your first AS9100 certification → start with these three control points before you draft a single page of procedure text, and map them against your overall AS9100 implementation timeline so counterfeit prevention isn’t the piece you scramble to finish in the final weeks. Registrars will trace your process through all three during the stage 2 audit — the same receiving and final inspection points also show up in First Article Inspection requirements, so it’s worth aligning both procedures rather than building them in isolation. Gaps at any one point are a common nonconformance.


👉 Not Sure This Applies to You?

Before you decide your counterfeit exposure is low → verify it against your actual purchasing data, not your assumption. Download the AS9100 Rev D Gap Assessment Checklist and run your procurement records against the clause 8.1.4 criteria in under 45 minutes.


GIDEP and Reporting Obligations

The Government-Industry Data Exchange Program (GIDEP) is the primary clearinghouse where confirmed and suspect counterfeit parts get reported across the aerospace and defense industry. It isn’t mentioned by name inside AS9100 itself, but registrars routinely ask during audits whether your organization monitors GIDEP alerts and has a documented process for screening incoming reports against your active part numbers.

Reporting works both directions. If you discover a suspect counterfeit part, your procedure should define who reports it, to whom, and on what timeline — both internally and, where required by contract, externally to GIDEP or your customer’s designated reporting channel. A procedure that only covers detection and not reporting is incomplete against both AS9100’s intent and most customer flow-down requirements.


Right-Sizing Your Program

Not every AS9100-certified supplier needs a full electronic parts testing lab. If you’re a small or mid-size fabrication or machining operation with limited electronic content in your product mix, a right-sized program typically includes:

  • A documented supplier approval list limited to OEMs, authorized distributors, or franchised sources
  • A written procedure defining what triggers additional scrutiny — any open-market or broker purchase
  • Incoming inspection criteria that specifically call out counterfeit indicators, not just dimensional checks
  • A process for screening GIDEP alerts relevant to your part numbers, even if that’s a manual monthly check rather than an automated feed
  • A defined reporting and quarantine process for suspect parts

Quick Audit Checklist

  • ✅ Counterfeit parts procedure exists and is controlled as a quality document
  • ✅ Approved supplier list distinguishes OEM/franchised sources from open-market sources
  • ✅ Receiving inspection includes counterfeit-specific criteria
  • ✅ Personnel who approve purchases have received counterfeit awareness training
  • ✅ GIDEP monitoring process is documented, even if manual
  • ✅ Reporting and quarantine process defines responsible roles and timelines
  • ✅ Obsolete part sourcing is addressed separately from standard procurement

Common Audit Findings

The objection I hear most from operations managers building this out for the first time is cost — the assumption that counterfeit prevention means investing in testing equipment they can’t justify for their volume. That’s rarely what triggers a nonconformance. The findings that actually show up during AS9100 audits are almost always documentation and scope gaps, not technical capability gaps:

  • A counterfeit parts procedure exists but was never updated after the organization started sourcing a new part category
  • Training records don’t show counterfeit awareness training was actually delivered, even though the procedure references it
  • The approved supplier list doesn’t distinguish franchised distributors from open-market brokers
  • No evidence of GIDEP monitoring, even informally
  • Reporting process is undefined — the procedure says “report suspect parts” without naming who, how, or within what timeframe

If you are already ISO 9001 certified → the good news is your document control and corrective action processes already exist. You’re not building a new management system, just a new procedure that plugs into the one you have — see our full breakdown of AS9100 vs ISO 9001 for the other clauses in the same category. Counterfeit prevention is also just one piece of the broader aerospace supplier compliance picture, which is worth reviewing if you’re building out your quality system section by section.


FAQ

Does AS9100 require a separate written procedure for counterfeit parts?

AS9100 Clause 8.1.4 doesn’t explicitly mandate a standalone written procedure, but in practice nearly every registrar expects to see one as objective evidence that your organization has planned, implemented, and controlled the required processes. A reference buried inside a general purchasing procedure rarely satisfies an auditor looking for a documented, controllable process.

Do I need AS5553 certification to pass an AS9100 audit?

No. AS5553 is a standard your counterfeit prevention procedure can be built around, but AS9100 doesn’t require separate certification to it. Some customers request AS5553 alignment or certification as a flow-down requirement, which is different from what your registrar checks during your AS9100 surveillance or recertification audit.

What’s the difference between AS5553 and AS6174?

AS5553 covers counterfeit electrical, electronic, and electromechanical (EEE) parts specifically. AS6174 covers counterfeit materiel more broadly, including raw material, hardware, and non-electronic components. If your product mix includes both, your procedure should reference both.

Does a machine shop with no electronic components need a counterfeit parts program?

Yes. Clause 8.1.4 applies to counterfeit and suspect counterfeit parts generally, not just electronics. Fabrication and machining operations should scope their program around AS6174’s materiel-focused guidance rather than assuming AS5553’s electronic parts focus is the only relevant reference.

What is GIDEP and do I have to use it?

GIDEP (the Government-Industry Data Exchange Program) is the industry clearinghouse for counterfeit and nonconforming part alerts. AS9100 doesn’t name it directly, but registrars commonly expect evidence that your organization monitors relevant GIDEP alerts as part of your detection process, and reports confirmed or suspect counterfeit parts through it when required by contract.

Do DFARS counterfeit parts clauses apply to me if I’m not a prime defense contractor?

Possibly. DFARS 252.246-7007 and 252.246-7008 apply to contractors subject to Cost Accounting Standards, but the requirements can flow down contractually to sub-tier suppliers regardless of your direct relationship with the government. Check your purchase order terms rather than assuming your distance from the prime contractor exempts you.

How often should the approved supplier list be reviewed for counterfeit risk?

There’s no fixed interval mandated by AS9100 itself, but most effective programs review the approved supplier list at least annually, and immediately whenever a new part category or supplier is added — particularly if that supplier isn’t a franchised distributor or the original manufacturer.

What’s the most common reason suppliers fail this clause during an audit?

Scope gaps, not missing technology. A procedure that names AS5553 but never addresses non-electronic materiel, or a training program that exists on paper but has no records showing it was delivered, are the findings that show up most often — not a lack of expensive test equipment.


📥 Free Resources


Not Sure What to Do Next?

🔹 Still researching what your program needs to look like? Download the free AS9100 Rev D Gap Assessment Checklist and map your current procurement controls against all 74 clauses before you draft anything.

🔹 Ready to build the documentation? 9001Simplified’s AS9100 packages include a counterfeit parts prevention procedure template built to satisfy Clause 8.1.4 — a faster starting point than drafting from scratch. Not sure if a documentation kit is worth it? Read our honest 9001Simplified review first.

🔹 Need to reference the standard itself while you write your procedure? Get the current SAE/AS9100 standard through ANSI Webstore — use code CC2026 for 5% off through December 31, 2026.

🔹 Need your team trained on how this fits into your broader QMS? BSI’s AS9100 training courses cover counterfeit prevention alongside the rest of the AS9100 clause set. Weighing BSI against another registrar? Compare BSI vs ISOQAR before you commit.

Clause 8.1.4 isn’t the hardest requirement in AS9100 — it’s the one most suppliers underestimate because it looks like a paperwork exercise until an auditor asks to see a GIDEP screening process that doesn’t exist. The Standards Navigator will keep tracking this requirement as counterfeit risk across the aerospace supply chain continues to shift.


Stay Ahead of Aerospace Compliance Requirements

Suppliers that treat Clause 8.1.4 as an afterthought find out the hard way, mid-audit. Suppliers that build the procedure early, with clear supplier approval criteria and a documented GIDEP screening process, walk into that same audit with one less place for a nonconformance to hide. That’s the gap The Standards Navigator exists to close for aerospace suppliers working through AS9100.

👉 Get updates on AS9100 clause interpretation and aerospace compliance
👉 Be first to access new aerospace gap assessment tools and documentation resources

Subscribe

* indicates required

The Standards Navigator — Industrial Compliance. Clearly Explained.