AS9100 Internal Audit Process: A Step-by-Step Guide for 2026

AS9100 Clause 9.2 requires more than an ISO 9001 internal audit program — customer and regulatory requirements have to be built into your audit criteria, and results have to reach management. This guide breaks down the six-part audit workflow, what a real internal audit checklist should cover, how findings feed into management review and AS9101 reporting, and the objectivity gap that trips up small aerospace quality teams.

How aerospace suppliers plan, conduct, and close out a Clause 9.2-compliant internal audit program

Affiliate Disclosure: Some links in this article are affiliate links. If you purchase through them, The Standards Navigator may earn a commission at no additional cost to you.


Your Internal Audit Program Is What Helps Keep Your AS9100 Certification Credible

An AS9100 certificate doesn’t prove your QMS is working. Your AS9100 internal audit process helps prove that it is.

Most operations managers treat internal audits as a compliance formality — something to schedule before the registrar shows up, not something that actually finds problems. That approach works right up until a surveillance audit surfaces a nonconformance your own internal audit should have caught six months earlier. At that point, the registrar isn’t just questioning the finding. They’re questioning whether your internal audit program is real.

If you’re already certified and running audits on autopilot, or preparing for your first AS9100 certification and building this process from scratch, the standard is specific about what “real” looks like. Clause 9.2 lays out exactly what your internal audit program has to prove, and AS9100 Rev D adds requirements ISO 9001 doesn’t have.

From the Floor: I’ve sat in gap assessment meetings where the documented internal audit schedule looked airtight on paper — every process, every quarter, neatly assigned. Then you pull the actual audit records and half of them are checklist walk-throughs with no objective evidence attached, no findings, no closure dates. An auditor doesn’t need long to spot the difference between an internal audit program that’s running and one that’s just being logged.

👉 Before you build or rebuild your internal audit program, run the AS9100 Rev D Gap Assessment Checklist — a 74-item, clause-by-clause tool that shows you exactly where your current audit coverage has gaps before an external auditor finds them for you.


In This Guide

  • What Clause 9.2 actually requires, and where AS9100 goes beyond ISO 9001
  • The six-step internal audit process defined in Clause 9.2.2
  • How internal audit findings feed into management review and AS9101 reporting
  • A ready-to-use internal audit checklist structure
  • Common mistakes that turn a real audit program into a paperwork exercise
  • Where to buy the standard and where to get trained on running compliant audits


👉 Start Here (Top Resources)

  • AS9100D — ANSI Webstore — the current edition of the standard, including the exact Clause 9.2 language your audit program has to satisfy. Use coupon code CC2026 for 5% off through December 31, 2026.
  • ISO 19011:2018 — ANSI Webstore — the audit guidelines standard referenced directly by AS9100 internal audit resources; worth owning if you’re training internal auditors.
  • AS9100 Training — BSI Group — for teams that need to formally qualify internal auditors on AS9100-specific requirements, not just general ISO 9001 audit technique.

What Clause 9.2 Actually Requires

Clause 9.2.1 requires you to conduct internal audits at planned intervals to determine whether your quality management system conforms to three things: your own organization’s requirements, the AS9100 standard itself, and the QMS is effectively implemented and maintained. That’s the ISO 9001 baseline.

AS9100 Rev D builds directly on that clause text. Under the standard’s Annex L structure, the aerospace-specific language is written straight into Clause 9.2.1 itself: your organization’s requirements for internal audit purposes must explicitly include customer requirements and applicable statutory and regulatory requirements — not just your internal procedures. That’s not guidance layered on top of ISO 9001; it’s part of the clause language you’re audited against. Audit results also have to be reported to relevant management, not just filed.

Most common finding: Internal audit programs that check ISO 9001 conformance thoroughly but never verify against a specific customer’s flow-down requirements or purchase order quality clauses. That’s a Clause 9.2 gap I commonly see when aerospace suppliers transition from ISO 9001 to AS9100.

ISO 9001 Baseline (Clause 9.2)Aerospace-Specific Clause 9.2 Language (Annex L Addition)
Conformance to the organization’s own QMS requirementsMust explicitly include customer, statutory, and regulatory requirements
Conformance to the standardAS9100 Rev D requirements, including its aerospace-specific additions
Effective implementation and maintenanceResults must be reported to relevant management, feeding directly into management review

If you are preparing for your first AS9100 certification → build your audit criteria around customer and regulatory requirements from day one, not as an afterthought once ISO 9001 conformance is handled.

👉 Need to see the exact Clause 9.2 language for yourself before you build your audit program around it? Get the current AS9100D edition from the ANSI Webstore — use code CC2026 for 5% off through December 31, 2026.


The AS9100 Internal Audit Process: A Six-Part Workflow Built From Clause 9.2.2

AS9100 audit program showing risk-based planning, audit frequency, previous findings, and an annual internal audit schedule in an aerospace manufacturing facility
A risk-based AS9100 audit program considers process importance, changes, previous findings, and risk when establishing the internal audit schedule.

Clause 9.2.2 lays out the requirements your audit program has to satisfy — the audit program itself, planning and conduct, auditor objectivity, reporting, corrective action, and retained documented information. Read together, that maps cleanly onto six practical steps, and an auditor will ask about all six.

1. Audit Program

Establish, implement, and maintain an audit program that identifies frequency, methods, responsibilities, planning requirements, and reporting. This has to account for the importance of the processes involved, changes affecting your organization, and the results of previous audits — not a static calendar you set once and never revisit.

2. Audit Criteria and Scope

Define what standard, procedure, or requirement each audit is measured against, and how far that audit reaches — which processes, which shifts, which locations if you run more than one facility.

3. Auditor Selection

Select auditors and conduct audits in a way that ensures objectivity and impartiality. Nobody audits their own work. On a small quality team this is often the hardest requirement to satisfy on paper — it usually means cross-training auditors across departments so a floor supervisor never audits the process they run.

4. Reporting Results

Audit results go to relevant management — not just the quality manager’s file. If a finding touches production scheduling, engineering, or purchasing, that function’s management needs visibility into it.

5. Corrective Action

Take appropriate correction and corrective action without undue delay when nonconformities are found. “Without undue delay” is intentionally vague in the standard, but in practice, your corrective action process should establish a documented target closure date appropriate to the severity of the finding — an open-ended promise to “look into it” won’t hold up as objective evidence of an effective process.

6. Retained Documentation

Keep documented information as evidence of the audit program’s implementation and the audit results. These are among the first records an external auditor is likely to examine: not your procedure, but your actual audit records — schedules, checklists, findings, objective evidence, and closure dates.

👉 If your audit records are more calendar than evidence, that’s the gap that surfaces during a surveillance audit — not a certification audit. Run the gap assessment checklist against your current program before your next registrar visit, not after.

AS9100 internal auditor reviewing work instructions, actual work, inspection records, and objective evidence on an aerospace manufacturing floor
An effective AS9100 internal audit follows the evidence from documented procedures to actual work, inspection records, and process effectiveness.

What Should an AS9100 Internal Audit Checklist Include?

A checklist built only around ISO 9001 clause conformance misses the aerospace-specific scope Clause 9.2.1 actually requires. Use this as the framework for what each internal audit needs to cover:

Audit AreaWhat the Auditor Should Verify
Process requirementsApplicable AS9100 clauses and internal procedure requirements
Customer requirementsPurchase order and contract flow-down requirements
Regulatory requirementsApplicable statutory and regulatory obligations
Objective evidenceActual records and direct observations, not verbal confirmation
Process effectivenessWhether the process is achieving its intended result, not just running
FindingsNonconformities clearly supported by objective evidence
Corrective actionRoot cause analysis, corrective action, and verification of effectiveness
Follow-upClosure evidence and confirmation the fix actually worked

If your operation also carries program-specific deliverables under AS9145 (APQP and PPAP), extend your audit criteria to those documents too — see AS9145 Explained for what’s typically in scope. And if any of your special processes are already covered under NADCAP, coordinate your internal audit scope so you’re not duplicating external oversight — NADCAP vs AS9100 breaks down where the two programs overlap and where they don’t.

AS9100 corrective action workflow showing audit finding, containment, root cause analysis, corrective action, effectiveness verification, and closure
An AS9100 corrective action is not complete until the organization verifies that the action worked and documents the results.

How Internal Audit Results Feed Into Management Review

Internal audit findings aren’t the end of the process — Clause 9.3 requires them as an input into management review. Corrective actions from internal audits, along with trending data like recurring nonconformities, similar issues across multiple processes, and top process concerns, should show up as agenda items top management actually discusses. That requirement comes from your QMS’s management review clause, not from any external audit form.

Separately, when your registrar conducts your certification or surveillance audit, results get documented on AS9101 — the standardized audit report form referenced by SAE International and logged in the IAQG OASIS database. AS9101 doesn’t dictate what your internal management review has to look like. But an external auditor completing that form will ask to see your management review minutes, and if internal audit trends never make it into those minutes, that gap is easy to spot — not because AS9101 requires a specific format, but because the disconnect itself signals the management review process isn’t functioning as intended.

If you are already ISO 9001 certified and adding AS9100 → your internal audit process likely doesn’t need to change structurally. What changes is audit criteria — you now have to audit against customer and regulatory requirements your ISO 9001 program never had to touch, and management review needs a direct line from audit findings to those aerospace-specific requirements.


Objection: “We Don’t Have Staff to Audit Objectively”

This is the most common pushback on small aerospace shops — a 15-person quality team can’t realistically avoid people auditing processes adjacent to their own work.

It’s a real constraint, but it’s manageable without adding headcount. Cross-train two or three people across departments so each can audit outside their own process. A machinist trained as an internal auditor can objectively audit the receiving inspection process; the receiving inspector can objectively audit machining documentation. Registrars don’t require a dedicated audit department — they require evidence that whoever conducted the audit had no stake in the outcome. Document that logic in your audit program procedure, and it holds up.


Quick Internal Audit Readiness Checklist

✅ Audit program covers all applicable processes at a frequency justified by risk and past findings

✅ Audit criteria explicitly reference customer purchase order requirements, not just internal procedures

✅ Auditors are demonstrably independent of the process they’re auditing

✅ Findings include objective evidence — not just a pass/fail checkbox

✅ Corrective actions have documented target closure dates

✅ Audit results appear as a distinct agenda item in management review minutes

⚠️ If any of these are missing, that’s the gap a registrar finds before you do


Frequently Asked Questions

What does Clause 9.2 of AS9100 actually require?

Clause 9.2 requires organizations to run internal audits at planned intervals to confirm the QMS conforms to the organization’s own requirements — which under AS9100 must include customer, statutory, and regulatory requirements — conforms to the AS9100 standard itself, and is effectively implemented. Results must be reported to relevant management.

How often do AS9100 internal audits need to happen?

The standard doesn’t set a fixed interval. Frequency has to be justified by the importance of the process, the results of previous audits, and any changes affecting the organization. Higher-risk processes — special processes, product safety-critical operations — typically warrant more frequent audits than lower-risk administrative processes.

Can one person run the entire internal audit program on a small team?

Generally, yes, as long as objectivity is maintained. The requirement is independence from the process being audited, not a minimum team size. On very small teams this can require creative scheduling or occasionally bringing in an outside auditor for processes where no internal person can honestly claim independence.

Do internal audit findings have to be reported to the registrar?

No. Internal audit results are reported to your own relevant management, not to the certification body. The registrar reviews your internal audit records and evidence of corrective action during surveillance and recertification audits — they don’t need real-time reporting.

What’s the difference between an internal audit and the AS9101 certification audit?

Your internal audit program is something you run yourselves, on your own schedule, against your own and the standard’s requirements. AS9101 is the standardized form your registrar uses to document the results of your external certification and surveillance audits, which then get logged in the IAQG OASIS database. A strong internal audit program is largely what prepares you to pass the AS9101-documented external audit cleanly.

Can internal audits be conducted remotely?

The standard doesn’t prohibit it, and many quality teams do conduct document reviews and some process audits remotely. Physical, in-person audits are still strongly preferred for shop floor processes where objective evidence — traveler stamps, calibration tags, first article records — needs to be directly observed rather than described.

What happens if our internal audit program has gaps when the registrar shows up?

It depends on severity and pattern, and classification is ultimately the auditor’s call based on the evidence in front of them. An isolated missed audit interval on a low-risk process may be treated differently from a persistent systemic failure, depending on the evidence and the auditor’s assessment. A pattern of audits with no objective evidence, no findings ever recorded, or no connection to management review calls into question whether the QMS’s self-monitoring is functioning at all — which is the kind of gap that tends to draw closer scrutiny.

Is a documented procedure enough, or do we need to prove the audits actually happened?

A procedure alone isn’t enough. Registrars expect to see the records: audit schedules, completed checklists with objective evidence, documented findings, and closure evidence for corrective actions. The procedure describes what you’re supposed to do — the records prove you did it.


📥 Free Resources

  • AS9100 Rev D Gap Assessment Checklist — 74-item, clause-by-clause checklist for aerospace suppliers assessing their QMS, including internal audit coverage, before certification.
  • ISO 13485 Gap Assessment Checklist — free checklist for medical device manufacturers assessing their QMS against ISO 13485 requirements.
  • ISO 9001 Roadmap — step-by-step implementation guide for manufacturers building or improving a quality management system.
  • Manufacturing Compliance Checklist — practical compliance reference covering key ISO, OSHA, and quality requirements for production environments.
  • Supplier Quality Checklist — evaluation tool for assessing supplier quality controls and flow-down compliance before audits or new contracts.

Not Sure What to Do Next?

🔹 Still researching what AS9100 internal audits require? Start with the What Is AS9100? pillar guide, then read AS9100 vs ISO 9001 to see exactly which requirements are new to you if you’re already ISO 9001 certified.

🔹 Ready to build or fix your internal audit program? Run the AS9100 Rev D Gap Assessment Checklist against your current audit records, then check the AS9100 Implementation Timeline to see where audit program maturity fits into your certification schedule.

🔹 Need to buy the standard or get auditors trained? Get the current edition from the ANSI Webstore with code CC2026 for 5% off, and see AS9100 Certification Bodies: Ranked & Reviewed for AS9100 auditor training through BSI Group.


A weak internal audit program is one of the most common reasons a QMS that looks compliant on paper fails to hold up in front of a registrar. Build the six-step process the standard actually asks for, put real objective evidence behind every audit, and your surveillance audits stop being a surprise. That’s what The Standards Navigator’s AS9100 coverage is built around — the requirements as they’re actually enforced, not just as they’re written.


Before You Go

Most aerospace suppliers don’t lose points on AS9100 audits because they misunderstand Clause 9.2 — they lose points because their internal audit program looks good on paper and falls apart under objective evidence review.

Shops that treat internal audits as a real management tool catch their own nonconformances before a registrar does. Shops that treat them as a scheduling formality find out the hard way, usually during a surveillance audit, that “completed” and “effective” aren’t the same thing.

The Standards Navigator covers the AS9100 requirements aerospace suppliers actually get audited against — not just the clause text, but how registrars interpret it in practice.

👉 Get updates on AS9100 implementation and internal audit best practices

👉 Be first to access new aerospace gap assessment tools and checklists

Subscribe

* indicates required

Industrial Compliance. Clearly Explained.

AS9100 Traceability Requirements: What Clause 8.5.2 Demands in 2026

Meeting AS9100 traceability requirements takes more than basic ISO 9001 identification — it requires documented traceability driven by customer, regulatory, and risk requirements. This guide breaks down the five components of Clause 8.5.2, acceptance authority media controls, configuration management, and the audit findings that repeat most often.

A practical breakdown of identification, traceability, and acceptance authority media requirements for AS9100-certified suppliers

Affiliate Disclosure: Some links in this article are affiliate links. If you purchase through them, The Standards Navigator may earn a commission at no additional cost to you.


When a Traceability Gap Grounds an Audit

Meeting AS9100 traceability requirements isn’t about paperwork for its own sake — it’s about being able to answer, on the spot, where a part came from. A missing serial number on a routing traveler doesn’t sound like much. Until an auditor asks you to trace a fastener lot back to its heat certification, and nobody in the building can produce it in under an hour.

That’s not a paperwork problem. That’s a finding — and depending on the part, it can be a stop-ship finding.

Aerospace traceability isn’t optional documentation. It’s the mechanism that lets a supplier prove, on demand, that every part on the shelf can be tied to a specific material lot, a specific operator, a specific inspection result, and a specific disposition. If you’re already ISO 9001 certified, you have identification and traceability controls. AS9100 asks for more — and the “more” is exactly where suppliers get flagged.

If you’re evaluating whether your current system meets AS9100 Rev D Clause 8.5.2, or you’re building traceability from scratch ahead of a Stage 1 audit, this breaks down what the clause actually requires, what auditors look for beyond the paperwork, and where most QMS builds fall short. AS9100 is published and maintained by SAE International, so the full clause text is worth reading directly rather than relying on secondhand summaries — including this one.

From the Floor: I ran operations at Baker Hughes Jacksonville on the valve and energy manufacturing side — 500 employees, and every valve body that left that facility had to trace back to a heat lot and a material cert. We weren’t AS9100 certified, but the discipline is identical: if a customer or regulator asked which heat of steel went into a specific valve six months after shipment, we had to answer it in minutes, not days. The suppliers who struggle with AS9100 traceability today are usually the ones who built that system as a spreadsheet instead of a process. It falls apart the first time volume increases or someone leaves.

Most operations managers underestimate how much this costs them until an auditor tests it live. Before your next audit, run this gap check on your identification and traceability controls →

Get the AS9100 Rev D Gap Assessment Checklist — a 74-item, clause-by-clause checklist built specifically for aerospace suppliers preparing for certification or surveillance audits.


In This Guide

  • What AS9100 Clause 8.5.2 requires, in plain language
  • The five components of identification and traceability under Rev D
  • Acceptance authority media (AAM) controls and why auditors probe them
  • Configuration management’s role in traceability
  • Supplier and sub-tier traceability flow-down
  • Common findings auditors cite in this area
  • How traceability connects to counterfeit parts prevention
  • FAQ: traceability depth, record retention, and consumables


👉 Start Here (Top Resources)

  • Get the AS9100 Rev D Standard from ANSI Webstore — the official SAE/AS9100 document, required reading before you build or revise traceability procedures. Use code CC2026 for 5% off through December 31, 2026.
  • 9001Simplified ISO Documentation Kits — pre-built procedure templates for identification, traceability, and configuration management, so you’re not writing clause 8.5.2 procedures from a blank page.
  • BSI Group AS9100 Training — auditor-led training on Rev D requirements, useful if your internal auditor has never dug into traceability specifically.

AS9100 Traceability Requirements: What Clause 8.5.2 Actually Says

Infographic illustrating AS9100 traceability requirements with a complete aerospace traceability chain from raw material certification and heat lot identification to serialized finished components and customer delivery.
This infographic shows how AS9100 traceability requirements connect every stage of production, from raw material certification through final delivery, to maintain complete product traceability.

AS9100 Rev D Clause 8.5.2, Identification and Traceability, layers aerospace-specific requirements on top of the base ISO 9001:2015 clause. In plain terms: wherever it applies, the organization has to identify process outputs well enough to confirm they meet requirements, and it has to track the status of those outputs against inspection and testing milestones as production moves forward. Where stamps, electronic signatures, or passwords are used to indicate acceptance, those tools need documented controls governing who holds them and how they’re managed.

Where a customer or regulation makes traceability a requirement, the organization has to assign unique identification to process outputs and keep the records needed to maintain that traceability over time — not just at the point of manufacture, but for as long as the part or record needs to be reconstructable.

Put plainly: an auditor at a machine shop or a fabricator building to print doesn’t need to trace every part back to raw material by default. An AS9100-certified aerospace supplier more often does, because flight-safety and critical parts, customer contracts, and regulatory flow-downs frequently push the requirement that far — but the depth required is still driven by those specific requirements, not by the clause on its own. Two suppliers making different parts can have very different traceability depth and both be fully compliant.

If you are already ISO 9001 certified → the gap isn’t the concept of traceability. It’s the depth, and where that depth comes from. ISO 9001 asks you to identify outputs. AS9100 layers on the expectation that, wherever traceability is a customer, contractual, or regulatory requirement, you can document and reconstruct that chain from raw material through to the shipped part — for as long as your flow-down requirements demand it.


The Five Requirements of Identification and Traceability

AS9100 traceability requirements break down into five practical components auditors will test independently. Miss any one, and the finding lands on that specific element — not the clause as a whole.

RequirementWhat It MeansWhere Suppliers Miss It
Suitable identificationSerial numbers, part numbers, or lot codes marked on the physical product or its packagingMarking method not durable through the process (ink wears off before final inspection)
Status identificationClear indication of what monitoring/measurement stage a unit has passedTags or travelers not updated in real time on the shop floor
Acceptance authority media controlStamps, e-signatures, or passwords tied to a specific individual, with controlled assignment and retirementShared stamps, or no process for retiring a stamp when an employee leaves
Configuration managementTracking part revisions, process revisions, and design listing alignmentNo link between engineering change orders and what was actually built
Unique traceability identificationA documented, retrievable link from finished part back to raw material and process historyTraceability data exists but is scattered across paper travelers, spreadsheets, and supplier certs with no single retrieval path

Worth watching: auditors often pull a random serialized part and ask the supplier to produce the full traceability chain — material cert, heat lot, operator stamps, inspection records — on the spot. AS9100 doesn’t set a retrieval-time requirement, and an auditor can be satisfied with records that take a while to assemble as long as they’re complete and clearly demonstrate conformity. But in practice, a system that requires calling three different people and digging through file cabinets is a signal — to you, and often to the auditor — that the records exist without a real retrieval process behind them. That’s worth fixing on its own merits, separate from whether it triggers a finding.

Infographic illustrating the five core AS9100 traceability requirements, including suitable identification, status identification, acceptance authority media, configuration management, and unique traceability identification.
This infographic summarizes the five core AS9100 traceability requirements that aerospace suppliers must implement to maintain complete product identification, traceability, and audit-ready documentation under Clause 8.5.2.

Acceptance Authority Media Controls

Acceptance authority media (AAM) — stamps, electronic signatures, or passwords used to designate who performed or accepted a task — get their own line of scrutiny in Rev D. The requirement isn’t just that AAM exists. It’s that AAM is controlled: assigned to one individual, distinguishable from every other person’s media, and retired or reassigned in a documented way.

A stamp room with no log of who holds which stamp number is a finding waiting to happen. So is a digital sign-off system where a departed employee’s login credentials are still active six months later.

If you are under customer pressure to certify quickly → don’t skip the AAM control procedure to save time. It’s a small section of the standard and one of the easiest to fully close out, but it’s also one of the first things an experienced auditor tests, because it’s a fast way to gauge whether the whole QMS is disciplined or improvised.


Configuration Management and Traceability

Traceability without configuration management tells you what part number shipped. It doesn’t tell you what revision of that part number, or what revision of the manufacturing process, actually produced it.

Clause 8.5.2 requires organizations to maintain configuration — knowing what part revisions, process revisions, and design listings were actually in effect for a given build — so that as-built configuration can be compared against as-designed configuration whenever it matters. This becomes critical during engineering change activity, when older units in the field may be built to a prior revision while new production has moved on.

Objection: “We don’t have the software budget for a full configuration management system.” You don’t need one on day one. A controlled engineering change log, cross-referenced to serial number ranges, satisfies the requirement for most small and mid-size suppliers. The finding isn’t the absence of software — it’s the absence of a documented, followed process.


Supplier and Sub-Tier Traceability

Your traceability system is only as strong as your weakest supplier’s documentation. AS9100 expects flow-down of traceability requirements to sub-tier suppliers, meaning your purchase orders, supplier quality agreements, and receiving inspection process all need to confirm that incoming material or components arrive with adequate traceability documentation attached — not assumed.

This is where heat lot traceability on raw material becomes non-negotiable. A supplier that can’t produce a mill certification tying a specific heat lot to a specific shipment isn’t meeting the flow-down requirement, and that gap becomes your finding at your next audit, not theirs.

If you are preparing for your first AS9100 certification → verify your approved supplier list actually requires traceability documentation as a purchase order condition, not as an informal expectation. Auditors will pull supplier files and check for it directly.


Common Audit Findings

AS9100 traceability requirements illustrated during an aerospace audit with serialized components, material certifications, inspection records, configuration documents, and supplier traceability records.
An AS9100 audit often begins with a single serialized part and a request to reconstruct its complete traceability history using documented records from raw material through final acceptance.

Across AS9100 surveillance and certification audits, the traceability-related findings that repeat most often:

  • ✅ Serialization exists, but status identification (what stage of test/inspection a unit has passed) isn’t visible on the floor without asking someone
  • ⚠️ Acceptance authority media isn’t retired when an employee leaves or changes roles
  • ⚠️ Consumables and process materials (sealants, primers, fasteners) have no lot traceability, even though the standard’s guidance material expects a reasonable link where practical
  • ✅ Configuration records exist but aren’t cross-referenced to serial number ranges, so as-built vs. as-designed comparison takes hours instead of minutes
  • ⚠️ Supplier traceability documentation is collected but not verified at receiving inspection

Pattern to watch for: the disconnect between paper records and physical parts on the floor. In many audits, the documentation exists somewhere in the system — the weak point is retrieval and cross-referencing, not the absence of data. That’s not a violation of Clause 8.5.2 by itself, but it’s a strong predictor of where a genuine finding will surface once an auditor starts pulling threads.


Traceability and Counterfeit Parts Prevention

Traceability and counterfeit parts controls are two separate clauses in AS9100, but auditors increasingly test them together. The International Aerospace Quality Group (IAQG) oversees the AS9100 certification scheme and has published extensive guidance connecting traceability and counterfeit parts risk, since gaps in one area routinely surface problems in the other. A strong traceability system supports your counterfeit parts defenses, because it forces documented chain-of-custody from an authorized source through to your receiving dock — but traceability alone doesn’t satisfy AS9100’s counterfeit parts requirements on its own. Those require a broader system: approved supplier controls, verification methods for incoming parts, risk assessment on part criticality, obsolescence management, and a documented process for reporting suspect counterfeit parts. Traceability is one piece of that system, not a substitute for it.

If your traceability records show unexplained gaps — material that appears without a documented supplier link, or components sourced outside your approved supplier list without justification — that’s a signal worth escalating into your counterfeit parts risk process, not just a documentation cleanup item. We’ll cover the full counterfeit parts prevention requirements in depth in the next article in this series.

You can verify a supplier’s AS9100 certification status directly through the IAQG OASIS database, which is worth checking before adding any new supplier to your approved list — regardless of what documentation they present.


Quick Audit Checklist

✅ Every serialized part has a durable, legible identification marking through final inspection
✅ Status of monitoring/measurement is visible on the traveler or in the digital record without cross-referencing another system
✅ Acceptance authority media (stamps, e-signatures) is individually assigned, logged, and retired when no longer applicable
✅ Configuration records cross-reference serial number ranges to specific part and process revisions
✅ Purchase orders and supplier quality agreements require traceability documentation as a condition of acceptance
✅ Receiving inspection verifies traceability documentation is present before material is released to production
✅ As a best practice (not a clause requirement), a random part pulled without notice can have its traceability chain assembled quickly — slow retrieval isn’t itself a nonconformance, but it’s often where real gaps get found


FAQ

Does AS9100 require traceability for every single part and material?

Not universally. Clause 8.5.2 requires traceability where it’s applicable — meaning where the customer, regulatory requirement, or your own risk assessment determines it’s needed. Critical and flight-safety parts almost always require full traceability. Some consumables may not, unless a specific contract or regulation requires it.

What’s the difference between identification and traceability under AS9100?

Identification tells you what a part is and its current status. Traceability tells you where it came from — the material lot, the process history, the operator, and the supplier chain behind it. AS9100 requires both, but traceability is the more demanding requirement because it has to be reconstructable after the fact.

Do consumables like sealants and primers need lot traceability?

The standard itself doesn’t explicitly mandate lot-level traceability for every consumable unless your contract or a regulatory requirement specifies it. That said, auditor guidance material treats consumables tied to critical processes as worth tracking at minimum by date range, and most experienced suppliers do this as good practice regardless of the strict letter of the clause.

How long do we need to retain traceability records?

AS9100 requires retention of documented information necessary to maintain traceability, but specific retention periods are typically driven by your customer contracts and applicable regulatory requirements, which commonly extend well beyond the life of the product. Check your contract flow-down requirements directly rather than assuming a default period.

What triggers a nonconformance in this area during an audit?

One of the most common triggers isn’t missing data itself, but an inability to quickly and confidently reconstruct the required traceability chain. Auditors often discover actual conformity gaps while testing retrieval and cross-referencing — pulling a random serialized part and asking the team to produce the material, process, inspection, and acceptance history is how a real gap in the records gets surfaced, not something a slow filing system causes on its own.

Does traceability apply differently to Tier 1 vs. lower-tier suppliers?

The clause requirements are the same regardless of tier, but the depth of flow-down expectations often increases the closer a supplier sits to final assembly. Tier 1 suppliers are typically expected to demonstrate traceability flow-down through their entire sub-tier supply base, not just their own operations.

Can a digital traceability system replace paper travelers entirely?

Yes, and most growing suppliers move this direction. A digital system needs to meet the same requirements as paper — durable identification, controlled acceptance authority media, and retrievable records — but it typically improves audit performance because retrieval time drops from hours to seconds.

Is acceptance authority media required, or only if we choose to use stamps?

If you use stamps, electronic signatures, or passwords to indicate acceptance or task completion, then the control requirements apply. If you use none of these methods, the specific AAM control clause doesn’t apply — but you still need another suitable, controlled method of indicating conformity status.


📥 Free Resources

  • AS9100 Rev D Gap Assessment Checklist — a 74-item, clause-by-clause checklist for aerospace suppliers assessing their QMS before certification, including identification and traceability requirements.
  • ISO 9001 Roadmap — step-by-step implementation guide for manufacturers building or improving a quality management system.
  • Manufacturing Compliance Checklist — practical compliance reference covering key ISO, OSHA, and quality requirements for production environments.
  • Supplier Quality Checklist — evaluation tool for assessing supplier quality controls and flow-down compliance before audits or new contracts.
  • ISO 13485 Gap Assessment Checklist — free checklist for medical device manufacturers assessing their QMS against ISO 13485 requirements.

Not Sure What to Do Next?

🔹 Still researching what AS9100 traceability actually requires? Read our What Is AS9100? pillar guide for the full framework before diving into individual clauses.

🔹 Ready to build or fix your traceability procedures now? The 9001Simplified documentation kits include identification, traceability, and configuration management procedure templates so you’re not starting from a blank page.

🔹 Need to buy the standard itself to confirm exact clause language? Get the AS9100 Rev D standard from ANSI Webstore — use code CC2026 for 5% off through December 31, 2026.

Meeting AS9100 traceability requirements is the clause-level detail that quietly decides whether your audit goes smoothly or turns into a multi-day scramble. Get the chain documented, controlled, and retrievable now — before an auditor tests it for you.

The Standards Navigator breaks down AS9100 clause by clause so aerospace suppliers know exactly what “compliant” looks like in practice, not just in theory.


📬 Stay Ahead of Your Next Traceability Audit

Most traceability failures don’t show up until an auditor pulls a random part and asks your team to reconstruct its history on the spot.

Suppliers who treat traceability as a real-time system — serialized, cross-referenced, quickly retrievable — walk into audits with confidence. Suppliers who treat it as a paper trail assembled after the fact spend audit week scrambling through file cabinets and spreadsheets.

The Standards Navigator covers AS9100 requirements clause by clause, built from real shop floor and audit experience — not summarized from the standard alone.

👉 Get updates on AS9100 clause breakdowns and aerospace compliance
👉 Be first to access new gap assessment tools and documentation resources

Subscribe below to stay ahead.

Subscribe

* indicates required

The Standards Navigator — Industrial Compliance. Clearly Explained.

Aerospace Supplier Compliance Standards: What Every Supplier Needs to Know in 2026

Aerospace suppliers face a layered compliance landscape — AS9100 certification is the baseline, but NADCAP accreditation, First Article Inspection, counterfeit parts controls, and customer flow-down requirements are equally enforced. This guide covers every standard and program aerospace primes audit against, with practical checklists and implementation guidance for quality managers.

The complete guide to AS9100, NADCAP, FAI, and the quality requirements aerospace primes actually enforce

Affiliate Disclosure: Some links in this article are affiliate links. If you purchase through them, The Standards Navigator may earn a commission at no additional cost to you.


The Aerospace Supply Chain Has a Short Memory for Second Chances

You get one bad audit. One missed First Article Inspection. One nonconformance that reaches the flight line. That is all it takes to lose an aerospace contract you spent years building.

Aerospace primes — Boeing, Lockheed Martin, Raytheon, Northrop Grumman — do not operate on goodwill. They operate on documented, auditable evidence that every supplier in their chain meets a defined set of compliance requirements. Those requirements are not flexible. They are not negotiable. And they are layered — meaning AS9100 certification alone does not cover everything your customer may require.

This aerospace supplier compliance standards guide breaks down the full compliance landscape: the standards, the programs, the certification requirements, and what aerospace suppliers actually get audited against on the shop floor.

If you are preparing for your first aerospace contract, adding an aerospace customer to an existing customer base, or trying to understand why your customer’s supplier quality team keeps asking for documentation you did not know you needed — this is where to start.

Before your Stage 1 audit, know exactly where your QMS stands. Run a clause-by-clause gap assessment now — before your registrar does. Download the AS9100 Rev D Gap Assessment Checklist →


In This Guide

  • The AS9100 Rev D standard and what it requires beyond ISO 9001
  • NADCAP accreditation — what it is, which processes require it, and when it applies
  • First Article Inspection (AS9102) — scope, deliverables, and common findings
  • Counterfeit parts prevention and AS5553/AS6174
  • FOD control requirements
  • Customer-specific flow-down requirements and how to manage them
  • How to verify a supplier’s certifications before awarding a contract


👉 Start Here — Top Resources for Aerospace Suppliers

Before you read further, these are the resources aerospace suppliers actually use:


AS9100 Rev D: The Foundation of Aerospace Quality

Quality engineers review aerospace supplier compliance standards inside a modern aircraft manufacturing facility with a fuselage assembly, machining equipment, and inspection stations
Quality personnel review engineering documentation on the aerospace shop floor while aircraft structures and manufacturing operations continue in the background.

AS9100 is the non-negotiable baseline. Every organization supplying parts, assemblies, or services to the aerospace and defense industry — whether you are a Tier 1, Tier 2, or Tier 3 supplier — is expected to hold AS9100 certification or demonstrate that your QMS meets equivalent requirements.

AS9100 Rev D is the current revision, published in 2016. It incorporates all of ISO 9001:2015 verbatim and adds aerospace-specific requirements on top of the quality management foundation. The IAQG — International Aerospace Quality Group — governs the standard and maintains the OASIS certification database.

What AS9100 Adds Beyond ISO 9001

The standard adds requirements that reflect the risk profile of aerospace manufacturing — where a single nonconformance can have catastrophic consequences. Key additions include:

AS9100 RequirementISO 9001 EquivalentWhy It Matters in Aerospace
Risk management (beyond Clause 6.1)Risk-based thinkingFormal risk identification, mitigation, and tracking for each program
Configuration managementNot requiredEnsures part revisions are controlled and traceable across the supply chain
First Article Inspection (FAI)Not requiredRequired verification that first production part meets all design requirements
Product/process change controlChange managementAny deviation from approved baseline requires documented approval
Counterfeit parts preventionNot requiredDocumented controls to prevent unapproved or fraudulent parts from entering the supply chain
FOD preventionNot requiredForeign Object Damage/Debris programs with documented procedures
Customer-designated special requirementsNot requiredFlow-down and implementation of prime contractor requirements
Key characteristicsNot requiredIdentification and control of dimensions or features with elevated risk

Most common finding: Organizations that are ISO 9001 certified assume the gap to AS9100 is small. It is not. The configuration management, FOD, and counterfeit parts requirements alone require building procedures that do not exist in a typical ISO 9001 QMS.

If you are already ISO 9001 certified, the AS9100 vs ISO 9001 comparison breaks down every additional requirement clause by clause.

For complete scope on what AS9100 certification involves, what it costs, and how long it takes, the What Is AS9100? pillar article covers the full picture.


NADCAP: Special Process Accreditation

NDT technician performing ultrasonic testing on an aerospace aluminum component using an ultrasonic probe and portable inspection instrument displaying waveform data.
An NDT technician conducts ultrasonic inspection on an aerospace component to verify material integrity and identify potential internal defects.

NADCAP is separate from AS9100 — and your customer will require both.

NADCAP — National Aerospace and Defense Contractors Accreditation Program — is a special process accreditation program managed by the Performance Review Institute (PRI). It applies to organizations performing specific high-risk manufacturing processes where process control is critical to product integrity.

AS9100 certifies your quality management system. NADCAP accredits specific processes within that system. A machined airframe component supplier may need AS9100 certification. If that same supplier performs heat treating, NDT, or chemical processing in-house, NADCAP accreditation is required for those processes — regardless of AS9100 status.

Processes That Require NADCAP Accreditation

Process CategoryExamples
Heat TreatingAnnealing, aging, stress relief, case hardening
Non-Destructive Testing (NDT)Ultrasonic, radiographic, penetrant, magnetic particle, eddy current
Chemical ProcessingAnodizing, plating, passivation, conversion coating
WeldingFusion welding per aerospace specifications
CoatingsThermal spray, paint (where specified by prime)
CompositesLay-up, cure, bonding operations
Electrical/Electronic ProcessingSoldering, conformal coating
Fluid Distribution SystemsTube bending, assembly

What NADCAP Audits Cover

NADCAP audits are process-specific and technically rigorous. Auditors evaluate process parameters, equipment qualification, operator qualification, traceability of materials, and conformance to applicable customer and industry specifications.

A NADCAP audit is not a QMS audit — it is a process performance audit. Findings are classified as Critical, Major, or Minor. Critical findings result in immediate suspension of work.

If you are a supplier: Do not assume your customer will accept your subcontractor’s NADCAP accreditation for flow-down purposes without reviewing the approved scope. NADCAP accreditation is scope-specific. Heat treating accreditation for aluminum alloys does not cover titanium heat treating.

If your aerospace customer has asked for NADCAP compliance in your supplier requirements — and you are not sure what processes in your facility are in scope — your AS9100 QMS needs a process risk review before your next customer audit. Download the AS9100 Rev D Gap Assessment Checklist →


First Article Inspection: AS9102

First Article Inspection is one of the most frequently cited sources of supplier nonconformances in aerospace.

AS9102 — Aerospace First Article Inspection Requirement — defines the methodology for verifying that the first production article (or first article after a significant change) meets all engineering, design, and manufacturing requirements. The standard is separate from AS9100 but is required by AS9100 Rev D Clause 8.1.3.

What FAI Covers

A complete FAI under AS9102 includes three forms:

FormTitleScope
Form 1Design DocumentationVerification that the correct drawing revision, specifications, and notes are captured
Form 2Product AccountabilityBill of materials, materials certification, and raw material traceability
Form 3Characteristic AccountabilityMeasurement of every dimension and characteristic on the drawing — not a sample

Form 3 is where most suppliers get tripped up. Every characteristic on the engineering drawing — not a selected subset — must be measured and documented. This includes tolerances, surface finishes, thread forms, and any geometric dimensioning and tolerancing (GD&T) callouts.

When FAI Is Required

FAI is not a one-time event. AS9102 specifies that a new or updated FAI is required when:

  • A new part number is introduced to production
  • A drawing or specification is revised (full or partial FAI, depending on the scope of change)
  • A manufacturing process, facility, or tooling is changed in a way that could affect form, fit, or function
  • Production has been inactive for more than two years

Most common finding: Suppliers treat FAI as a drawing check rather than a full measurement event. Partial FAIs submitted without Form 2 material traceability or without measuring all Form 3 characteristics are rejected by customer quality teams and result in production holds.


Counterfeit Parts Standards: AS5553 and AS6174

Counterfeit parts are a documented safety risk in aerospace. The FAA, DoD, and aerospace primes have all implemented mandatory controls. Your QMS must address them explicitly.

Two SAE standards define the requirements:

AS5553 — Fraudulent/Counterfeit Electronic Parts: Avoidance, Detection, Mitigation, and Disposition. Applies to electronic components — integrated circuits, semiconductors, connectors, and any electronics where counterfeit substitution is a risk.

AS6174 — Counterfeit Materiel: Avoidance, Detection, Mitigation, and Disposition. Broader scope covering raw materials, fasteners, and other non-electronic hardware.

What Your QMS Must Include

A compliant counterfeit parts program under AS9100 Rev D requires documented procedures covering:

  • Approved supplier lists (ASL): Purchasing only from authorized manufacturers, franchised distributors, or approved aftermarket sources
  • Receiving inspection: Risk-based inspection criteria for parts that cannot be sourced from authorized channels
  • Traceability: Certificate of conformance, test reports, and chain of custody documentation for all parts
  • Suspect/confirmed counterfeit parts: Quarantine, reporting, and disposition procedures — including mandatory reporting to GIDEP (Government-Industry Data Exchange Program) for defense contracts
  • Training: Evidence that personnel involved in procurement and receiving inspection are trained to identify suspect parts

If you are a manufacturer and not a distributor, the most critical element is your approved supplier list and purchasing controls — because your customer’s AS9100 audit will verify that you are buying from controlled sources.


FOD Control Requirements

Aerospace tool control shadow board displaying torque wrenches, calipers, safety wire pliers, borescope, and precision hand tools with one tracked tool removed.
A structured tool control system helps aerospace manufacturers maintain accountability, prevent FOD incidents, and ensure every tool is tracked throughout production.

Foreign Object Damage and Debris is a zero-tolerance issue in aerospace.

FOD — Foreign Object Damage or Debris — refers to any substance, material, or item that could potentially damage equipment or endanger personnel. A loose fastener in a fuel system. A rag left in an aircraft cavity. Metal chips in a precision assembly. In aerospace, these are not housekeeping issues — they are quality system failures.

AS9100 Rev D Clause 8.5.1 requires documented controls to prevent FOD throughout manufacturing, assembly, and test operations. Customer-specific FOD requirements are typically more detailed and flow down through purchase order terms.

Minimum FOD Program Elements

✅ Written FOD prevention procedure specific to your facility and processes
✅ Designated FOD critical areas with defined access controls
✅ Tool control program — shadow boards, tool counts, calibrated tool tracking
✅ Contamination controls during assembly and inspection operations
✅ FOD walks and documented area inspections on defined frequency
✅ Employee training and awareness records
✅ FOD incident reporting and corrective action process
✅ Customer notification procedure when FOD is suspected or confirmed

Most common finding: FOD programs exist as a procedure document but are not operationally active. Auditors look for evidence — completed FOD walk records, tool control logs, training records — not just a written procedure. The procedure without the records is a Major finding.


Customer Flow-Down Requirements

Your prime contractor’s requirements are your requirements.

This is the element that surprises suppliers who are new to aerospace. AS9100 certification means you have a compliant quality management system. It does not mean your prime contractor’s specific engineering, quality, and documentation requirements are automatically met. Those flow down — meaning they are passed from the prime to you through purchase order terms, quality clauses, and source control documentation.

Common Flow-Down Requirements

CategoryExamples
Quality planFirst Article requirements, inspection frequencies, statistical process control
EngineeringSpecification compliance, drawing revision control, DER approvals
MaterialMaterial certifications, approved material sources, trace requirements
ManufacturingApproved process specifications (e.g. BAC, SPE, DPS), NADCAP process approvals
DocumentationRecord retention requirements (typically 10+ years for flight-critical parts)
Access and oversightRight-to-access for customer source inspection, government source inspection
ReportingGIDEP reporting, escape reporting, timelines for nonconformance notification

Managing Flow-Down in Your QMS

Your QMS must have a documented process for:

  1. Reviewing purchase orders for quality clauses before accepting the order
  2. Translating customer requirements into internal work instructions and inspection plans
  3. Verifying that sub-tier suppliers (your suppliers) receive applicable flow-down requirements
  4. Maintaining records that demonstrate compliance with customer-specific requirements

If you are receiving flow-down requirements you do not understand: Your customer’s supplier quality team is your first contact. Do not guess. Documenting a misunderstood requirement incorrectly is worse than asking for clarification — because the audit finding will be a major nonconformance, not a simple misunderstanding.

If you are evaluating whether your quality system is ready for AS9100 certification, start with the How Much Does AS9100 Certification Cost? article for a complete breakdown of what certification actually involves.

BSI Group offers AS9100 training specifically designed for suppliers building compliant QMS documentation — covering the clause requirements and flow-down obligations that come with aerospace contracts.


How to Verify Supplier Certifications

Never take a supplier’s word for AS9100 certification. Verify it directly.

The IAQG OASIS Database is the official global registry for AS9100, AS9110, and AS9120 certifications. Every accredited certification is listed with scope, effective date, expiration date, and the certification body that issued it. If a supplier claims AS9100 certification and they are not in OASIS, the certification is not valid.

What to Verify in OASIS

  • Certification status: Active, suspended, or withdrawn
  • Scope of certification: Does it cover the specific product category or process your supplier is performing?
  • Expiration date: AS9100 certificates expire and require surveillance audits — a certificate that has not been renewed is not valid
  • Certification body: Is the CB accredited by a recognized accreditation body (ANAB, DAkkS, UKAS)?

For NADCAP accreditation verification, the PRI supplier database at pri-network.org lists all accredited suppliers by commodity and scope.

If you are a quality manager building or updating an approved supplier list for an aerospace program — your supplier evaluation process needs to include OASIS verification as a mandatory step before award and at each annual review.


Compliance Checklist for Aerospace Suppliers

Use this checklist to assess your current compliance posture before a customer audit or certification audit.

Quality Management System
✅ AS9100 Rev D certification current and active in OASIS
✅ QMS manual and procedures documented and controlled
✅ Internal audit program covers all AS9100 clauses — not just ISO 9001 requirements
✅ Management review records demonstrate review of aerospace-specific metrics

First Article Inspection
✅ FAI procedure documented per AS9102
✅ Form 1, Form 2, and Form 3 completed for all active part numbers
✅ FAI triggers defined — changes that require new or partial FAI
✅ FAI records retained and retrievable

Counterfeit Parts
✅ Counterfeit parts prevention procedure in place
✅ Approved supplier list (ASL) current and controls defined
✅ Receiving inspection criteria address suspect parts
✅ Personnel training records current

FOD
✅ FOD prevention procedure active and specific to your facility
✅ FOD walk and inspection records maintained on required frequency
✅ Tool control program in place with records
✅ Employee training documented

Flow-Down
✅ Purchase order review process in place
✅ Customer quality clauses translated to internal requirements
✅ Sub-tier flow-down process documented and verified
✅ Record retention meets customer requirements (typically 10+ years)

NADCAP (if applicable)
✅ All in-scope special processes identified
✅ NADCAP accreditation current for each process
✅ Scope of accreditation matches actual work performed
✅ Sub-tier NADCAP requirements verified and documented


FAQ

What is the difference between AS9100 and NADCAP?

AS9100 Rev D is a quality management system standard that certifies your organization’s overall quality processes — planning, documentation, corrective action, customer satisfaction, and so on. NADCAP is a special process accreditation that applies to specific manufacturing processes such as heat treating, NDT, chemical processing, and welding. AS9100 certification is a QMS-level requirement. NADCAP is a process-level requirement. Aerospace suppliers performing special processes are typically required to hold both.

Do I need AS9100 certification to supply aerospace parts?

In most cases, yes — if you are a direct supplier (Tier 1 or Tier 2) to an aerospace prime or defense contractor. Some lower-tier commodity suppliers may not be required to hold AS9100 certification, but customer flow-down requirements and purchase order quality clauses will define the specific requirement. Review your customer’s supplier quality requirements before assuming certification is not needed.

How do I know if my process requires NADCAP accreditation?

Review your customer’s purchase order quality clauses and their approved supplier requirements document. Primes typically maintain a list of processes that require NADCAP accreditation for their programs. If you perform heat treating, NDT, chemical processing, or welding on aerospace parts and your customer has not specified NADCAP — ask. The absence of a requirement on the PO does not always mean the requirement does not exist.

What is a First Article Inspection and when is it required?

A First Article Inspection (FAI) is a formal verification process, defined by AS9102, that the first production article meets all design and engineering requirements. It is required for new part introductions, after drawing or specification revisions, after significant manufacturing process or tooling changes, and after production gaps of two or more years. A complete FAI requires documentation on three forms covering design documents, material traceability, and measurement of every drawing characteristic.

How long does AS9100 certification take?

For an organization with no existing quality management system, the implementation and certification process typically takes 9 to 18 months. Organizations already certified to ISO 9001 can typically close the gap to AS9100 in 6 to 12 months, depending on the number of additional requirements that need to be built out. The How Much Does AS9100 Certification Cost? article covers timelines and costs in detail.

What is the OASIS database and how do I use it?

OASIS — Online Aerospace Supplier Information System — is the IAQG-maintained database of all AS9100, AS9110, and AS9120 certifications worldwide. You can search by organization name, location, or CAGE code to verify a supplier’s certification status, scope, expiration date, and issuing certification body. Access it at oasis.sae.org. Verifying supplier certifications in OASIS should be a standard step in your approved supplier list maintenance process.

What are customer flow-down requirements in aerospace?

Flow-down requirements are the specific quality, engineering, documentation, and process requirements that a prime contractor passes down to their supply chain through purchase order terms and quality clauses. They are legally binding once accepted on a PO. Common examples include FAI requirements, material certification requirements, NADCAP requirements for special processes, record retention periods, and customer source inspection rights. Your QMS must have a documented process for reviewing, implementing, and flowing these requirements to your own sub-tier suppliers.

Can I use my ISO 9001 certification for aerospace customers temporarily while pursuing AS9100?

In most cases, no. ISO 9001 certification does not meet AS9100 requirements. Some customers may grant a temporary waiver for lower-risk commodity suppliers, but for any direct aerospace supply involving flight-critical parts or assemblies, AS9100 certification is typically required before production can begin. Discuss your timeline with your customer’s supplier quality team — do not assume a waiver will be granted.


📥 Free Resources

AS9100 Rev D Gap Assessment Checklist — 74-item clause-by-clause checklist for aerospace suppliers assessing their QMS before certification. Covers every AS9100-specific requirement beyond ISO 9001.

ISO 9001 Roadmap — Step-by-step implementation guide for manufacturers building or improving a quality management system. Useful as a foundation before layering AS9100 requirements.

Manufacturing Compliance Checklist — Practical compliance reference covering key ISO, OSHA, and quality requirements for production environments.

Supplier Quality Checklist — Evaluation tool for assessing supplier quality controls and flow-down compliance before audits or new contracts.

ISO 13485 Gap Assessment Checklist — Free checklist for medical device manufacturers assessing their QMS against ISO 13485 requirements.


Not Sure What to Do Next?

🔹 If you are new to aerospace and need to understand AS9100 from the ground up — start with What Is AS9100? for a complete overview of the standard, certification process, and supply chain requirements.

🔹 If you are ready to buy the AS9100 Rev D standard — purchase the official document through the ANSI Webstore. Use code CC2026 for 5% off through December 31, 2026. The standard is available in digital and print formats and ships internationally.

🔹 If you need AS9100 training for your team or are selecting a certification bodyBSI Group offers the full range of AS9100 courses from awareness through lead auditor, and serves as both a training provider and accredited certification body.

Aerospace compliance is not a project with a finish line. Certification is the beginning. The organizations that hold their approvals and grow within the supply chain are the ones that build compliance into operations — not just into audit prep.

The Standards Navigator covers the full aerospace compliance landscape, from AS9100 certification requirements to NADCAP process accreditation and FAI methodology. Use the resources above to make your next audit a confirmation of what you already know — not a discovery of what you missed.


Stay Ahead of Aerospace Compliance Changes

Losing an aerospace approval because a standard revision or customer requirement changed while you were focused on production is the most preventable kind of failure. Most organizations that fall behind on compliance don’t miss the requirement — they miss the update.

The suppliers who keep their approvals long-term are the ones who treat compliance information the same way they treat production scheduling: as an ongoing operational discipline, not a one-time project.

The Standards Navigator covers AS9100, NADCAP, FAI, and the full aerospace supplier compliance landscape — explained in plain language for quality managers and operations teams who need to act on the information, not just read it.

👉 Get updates when new aerospace compliance articles are published
👉 Be first to access new AS9100 implementation resources and checklists

Subscribe below to stay ahead.

Subscribe

* indicates required

The Standards Navigator — Industrial Compliance. Clearly Explained.