Auditors are usually trying to confirm that you (1) define configurations, (2) control changes to them, and (3) can prove which configuration was actually built, tested, and delivered. The specific records required will depend on your QMS, standards (e.g. AS9100, ISO 9001, customer specs), and tools (PLM, ERP, MES, QMS), but the evidence set typically falls into the categories below.
1. Baseline configuration definition records
You need evidence of what the “approved” configuration actually is for the product, process, or system in scope:
- Controlled design data:
- Released drawings, CAD models, and associated lists
- Specifications and standards referenced on drawings
- Software baselines / firmware versions when applicable
- Bill of materials and components:
- Released BOMs (with part numbers, revisions, effectivity dates)
- Approved alternate/optional parts and their conditions of use
- Released process definitions:
- Approved routings / operation lists
- Released work instructions and standard work
- Released inspection and test plans
Auditors will often sample these documents to confirm they are controlled (unique IDs, revision levels, approval signatures, dates, and current/obsolete status).
2. Change control and configuration change records
To show you maintain control over changes, auditors expect a complete and traceable change history:
- Change requests and change approvals:
- Engineering change requests (ECR) or similar initiation records
- Engineering change orders (ECO/ECN) or formal change approvals
- Evidence of impact assessments (quality, reliability, risk, safety, supply chain)
- Evidence of required functional approvals (engineering, quality, operations, sometimes customer)
- Configuration change implementation records:
- Effectivity definitions (date, lot, serial number, tail number, unit, or contract where the change starts/stops)
- Workflow steps showing who implemented the change in each system (PLM, ERP, MES, document control)
- Links between the ECO/ECN and all affected items: drawings, models, BOMs, specs, routings, work instructions, test procedures
- Obsolescence and supersession records:
- Superseded part and document revisions with clear status (obsolete, legacy, archival)
- Rationales for obsoleting parts or documents
In a brownfield environment, these may be split across PLM, ERP, network drives, and paper. Auditors will pay attention to how you ensure the change is consistently reflected across all systems.
3. Configuration status accounting and traceability
Configuration status accounting is the ability to answer: “Which configuration did we actually build, test, and deliver for this serial number / lot / unit?” Records that support this include:
- As-built / as-maintained records:
- Production travelers or MES execution histories with operation results and timestamps
- Serial/lot-level component genealogy (which part numbers and revisions were actually installed)
- Software/firmware version history tied to each unit, where applicable
- Maintenance, repair, and overhaul records for fielded units
- Linkage between as-built and baseline:
- Evidence that each unit or lot can be tied to a specific revision of drawing, BOM, routing, and work instructions
- Effectivity logic applied correctly (e.g. ECO states change applies from serial 1200 onward, and records show which serials were built under each revision)
- Deviations, waivers, and concessions:
- Approved deviations from the baseline configuration (temporary or permanent)
- Concession / waiver approvals, especially when granted by customers or authorities
- Traceability of which specific units or lots were built under which deviation/waiver
Auditors often select specific serial numbers or lots and walk the full chain: baseline configuration, applicable changes, deviations, and evidence that what was built matches the defined configuration for that unit.
4. Document and record control supporting configuration management
Configuration control is usually backed by broader document/record control. Auditors typically look for:
- Document control procedures:
- Approved procedures describing how documents are created, reviewed, approved, revised, and retired
- Roles and responsibilities for configuration management and document control
- Record retention and integrity evidence:
- Retention periods and storage locations for configuration records (digital and paper)
- Audit trails on electronic systems: who changed what, when, and why
- Access control and permissions for configuration items
- Training and authorization records:
- Training records for personnel who approve configuration changes
- Evidence that only authorized individuals can make or release configuration changes
In mixed-system environments, you should be prepared to explain how control is maintained when some records are in PLM, others in ERP/MES, and some on shared drives or in physical binders.
5. Evidence showing use of the correct configuration on the floor
Auditors do not just look at design and change records; they also look for proof that operators and inspectors used the correct versions:
- Point-of-use documentation evidence:
- Production travelers or MES screens showing document revision levels at the time of execution
- Stamped or time-logged copies of work instructions and drawings used on the line when paper is still used
- Version checks in processes and systems:
- System logs or screenshots demonstrating that out-of-date instructions are blocked or flagged
- Layered process audits or shop-floor checks confirming correct revision in use
- Nonconformance and CAPA linkage:
- NCRs where configuration errors were detected
- Corrective actions that address configuration control gaps (e.g. missing revision verification step)
These records show that configuration control is not just a design-office activity but is enforced where value is created and risk is realized.
6. System coexistence and practical constraints
In most regulated plants, configuration records are scattered across legacy PLM, ERP, MES, network drives, and paper. Auditors will not expect a single system, but they will expect:
- Clear definition of the system of record for each configuration item type (e.g. design in PLM, BOM in ERP, routing/WI in MES, concessions in QMS)
- Evidence that interfaces and manual handoffs are controlled and validated, especially where data is re-entered between systems
- Change control that spans all impacted systems, not just the one where the change was initiated
Full replacement of legacy systems just to improve configuration control is often impractical due to validation burden, integration complexity, and downtime risk. In practice, many organizations instead layer stricter governance, clearer ownership, and targeted digitization (e.g. digital travelers, configuration-aware WIs) on top of existing infrastructure.
7. Tailoring to your specific auditors and standards
The exact record set auditors will expect depends on:
- The standards you are certified or assessed against (e.g. AS9100 vs. ISO 9001 vs. customer or regulatory requirements)
- Customer contracts that define specific configuration management expectations
- How your QMS describes configuration control and which systems and procedures you claim to use
- The maturity and validation of your PLM/ERP/MES/QMS stack
Before an audit, it is usually useful to perform an internal configuration management evidence review: pick a representative product, select a serial or lot, and ensure you can walk an auditor from requirements and design through changes, as-built records, deviations, and delivery documentation using the records listed above.