RSC Cluster: Audit and Compliance Readiness (AS9100, LPAs and Process Audits)

The Audit and Compliance Readiness Cluster focuses on turning audit preparation into continuous evidence rather than episodic panic. It explains what auditors actually expect to see across training, revision control, traceability, and execution records. The content covers internal audits, layered process audits, and AS9100 expectations using real operational examples. This cluster helps organizations stay audit-ready by design, not by scramble.

  • How can MES help a small supplier respond to prime audits?

    An MES can help a small supplier respond to prime audits by making shop-floor evidence easier to find, link, and explain. It does not make the supplier audit-ready by itself, and it will not compensate for weak procedures, missing records, uncontrolled drawings, or poorly managed concessions. The practical value is reducing evidence hunting and making the relationship among work orders, revisions, operators, inspections, material lots, nonconformances, and approvals clearer.

    For small aerospace and defense suppliers, the biggest audit problem is often not that the work was never done. It is that the evidence is scattered across paper travelers, spreadsheets, ERP notes, inspection folders, email approvals, QMS records, and customer portals. MES can reduce that fragmentation if it is implemented with traceability and evidence retrieval in mind.

    Where MES commonly helps

    MES is most useful when a prime auditor asks for objective evidence tied to a specific job, part number, serial number, lot, operation, or operator. A well-configured MES can help show:

    • Which routing and work instruction revision was used for the order.
    • Who performed each operation and when.
    • Which inspection steps were completed, skipped, failed, or reworked.
    • Which material lots, batches, serial numbers, or kits were consumed.
    • Which equipment or tooling was used, where that data is captured.
    • Which nonconformances, deviations, MRB dispositions, or concessions were linked to the work.
    • Whether required approvals were captured before release or shipment.

    This can make an audit response faster and less dependent on a few experienced people who know where records are stored. It also helps reduce inconsistent answers between production, quality, and planning teams.

    It must coexist with ERP, QMS, and document control

    MES usually does not replace the systems a small supplier already relies on. ERP may remain the system of record for orders, inventory, costing, and shipments. QMS may remain the system of record for CAPA, supplier quality, formal nonconformance management, and audit findings. PLM or document control may remain the source for released drawings, specifications, and work instruction governance.

    In brownfield environments, MES should normally connect to these systems rather than force a full replacement. Full replacement is often unrealistic because of qualification burden, validation cost, downtime risk, integration complexity, traceability obligations, change control, and long equipment lifecycles. A small supplier should be careful not to create a second uncontrolled system of record that conflicts with ERP, QMS, or released engineering data.

    What primes usually care about

    Prime audits are not impressed by software alone. They typically care whether the supplier can show controlled, repeatable execution against contractual, engineering, and quality requirements. MES helps only if it supports that control.

    For example, MES may help demonstrate that operators used the correct instruction revision, that inspection data was captured at the required point in the process, and that nonconforming product did not quietly continue through production without disposition. But the underlying procedures still need to define what must happen, who can approve exceptions, how records are retained, and how changes are controlled.

    Common failure modes

    MES can create audit risk if it is implemented casually. Common problems include poor part and routing master data, uncontrolled work instruction changes, weak user access controls, missing e-signature rationale where required, incomplete integration with ERP or QMS, and unclear ownership of electronic records.

    Another common failure is digitizing a bad paper process without improving accountability. If operators still bypass steps, record results after the fact, or use informal workarounds, MES may only make those weaknesses more visible. That can be useful internally, but it may also expose process gaps during a customer audit.

    What a small supplier should prioritize first

    A small supplier does not need to digitize everything at once. The first scope should usually focus on high-risk or high-audit-value records, such as digital travelers, revision-controlled work instructions, required inspection capture, material and serial traceability, nonconformance links, and approval history.

    The implementation should also define how MES records map to the supplier’s quality procedures. Auditors will often ask how the electronic record is controlled, not just whether it exists. That means access control, audit trails, record retention, backup, validation or verification of intended use, and change control need to be addressed at a level appropriate to the supplier’s risk and customer requirements.

    Used well, MES gives a small supplier a more defensible evidence trail. It does not remove the need for disciplined quality management, trained operators, accurate master data, or clear ownership between production, quality, engineering, and IT.

  • Can we certify ISO 27001 and AS9100 at the same time?

    Yes, most organizations can pursue ISO 27001 and AS9100 certification in parallel, and many registrars are able to audit both. However, there is no guarantee that both certificates will be granted, or granted on the same date. Whether it is practical or advisable depends on your current system maturity, documentation, and audit capacity.

    What “at the same time” really means

    “At the same time” usually means one of the following:

    • A single integrated audit event where the registrar evaluates both your AS9100 QMS and ISO 27001 ISMS in the same visit.
    • Two audit streams scheduled back to back, potentially with the same registrar and some shared evidence.
    • A multi-stage plan where Stage 1/Stage 2 audits for both standards are aligned over a few months, with some combined activities.

    In practice, timing is constrained by registrar availability, your readiness, and the need to close findings from one standard before the registrar will recommend certification.

    Key dependencies and constraints

    • Registrar capability: Not all certification bodies are accredited to issue both AS9100 and ISO 27001. You may need a registrar that is accredited for both and willing to run an integrated program, or coordinate two registrars.
    • Scope definition: The scope of your QMS (AS9100) and ISMS (ISO 27001) may not be identical. AS9100 often covers design/production/maintenance processes; ISO 27001 may focus on information and OT/IT assets used in those processes. Misaligned scopes complicate a single combined audit.
    • System maturity: Running two first-time certifications in parallel is heavy. If your QMS is immature or your information security controls are still being implemented, a combined push usually increases audit findings rather than reducing effort.
    • Evidence and traceability: Both standards require demonstrable, traceable implementation over time (risk assessments, internal audits, management reviews, corrective actions). Trying to stand up both systems quickly just before an audit tends to surface gaps.
    • Regulated & aerospace context: Customers and primes may scrutinize AS9100 scope, exclusions, and how information security is handled. Trying to align both certifications without clear ownership and documentation can undermine customer confidence if findings are significant.

    Where combining efforts makes sense

    Even if the certifications are not literally granted on the same day, there are real synergies:

    • Integrated risk framework: AS9100 requires a risk-based approach for quality; ISO 27001 requires formal information security risk management. A single enterprise risk methodology can serve both, with different risk registers.
    • Shared governance processes: Management review, internal audit planning, corrective action, document control, and training can be shared across QMS and ISMS rather than duplicated.
    • Common controls for production IT/OT: Change control, access management, backup/restore, and incident response for MES, ERP, PLM, and OT assets can be governed by both standards with aligned procedures and records.
    • Efficiency in evidence management: A unified approach to records, log retention, and audit trails can support both standards, especially for digital work instructions, nonconformance workflows, and CAPA systems.

    Typical tradeoffs and risks

    • Complexity vs. speed: Pursuing both certifications together can reduce calendar time but usually increases complexity and risk of findings. A staged approach (e.g., stabilize AS9100 first, then extend to ISO 27001) is often easier to control.
    • Resource load: Engineering, operations, IT, and quality will all be drawn into both efforts. In high-mix, low-volume or heavily customized environments, this can conflict with program milestones and customer audits.
    • Brownfield realities: Legacy MES/ERP/PLM/QMS, old equipment, and partial segregation between OT and IT make it harder to show clean, ISO 27001-compliant information security while also meeting AS9100 traceability and change control expectations.
    • Change control burden: Both standards expect disciplined change management. Rapidly redesigning processes, tools, and organizational structures to “fit” both standards at once can overwhelm existing change control and validation practices.

    How to decide if simultaneous certification is sensible

    Before committing to a combined path, validate the following:

    • Your AS9100 QMS is either already certified or demonstrably close to readiness, with stable core processes and evidence over time.
    • Your information security baseline (policies, risk assessment, asset inventory, access control, incident management, business continuity) is designed and at least partially implemented, not just documented.
    • IT/OT, quality, and operations leadership agree on scope boundaries, ownership, and how shared systems (MES, ERP, PLM, QMS, data historians) will be governed under both standards.
    • You have enough internal audit capacity to run cross-functional audits that cover both QMS and ISMS requirements without slipping into a check-the-box exercise.
    • Selected registrars (or a single registrar) have confirmed that they can plan and deliver aligned audits within your operational and downtime constraints.

    Practical approach in long-lifecycle, regulated environments

    In aerospace, defense, and other long-lifecycle sectors, a staged but integrated strategy is often more robust than a fully simultaneous push:

    • Stabilize and, if needed, upgrade AS9100 practices around design control, special processes, configuration management, and production traceability.
    • Map information security requirements to existing QMS processes instead of replacing core systems; layer ISO 27001 controls onto current MES/ERP/PLM/QMS and OT infrastructure.
    • Treat ISO 27001 as an overlay on top of existing systems, with clear interface controls, rather than trying to swap out legacy platforms to “make certification easier.” Full replacement strategies often fail due to validation cost, downtime risk, and integration complexity.
    • Align management reviews, risk discussions, and audit programs so that both QMS and ISMS are reviewed together, even if formal certifications are obtained in sequence.

    Bottom line

    You can usually pursue ISO 27001 and AS9100 certification in parallel, and it can be efficient if your systems are mature, scopes are well defined, and your registrar supports an integrated plan. However, there is no guarantee of simultaneous certification, and forcing both at once in a complex, regulated, brownfield environment often increases risk. Many organizations in aerospace-grade contexts adopt a phased approach with integrated governance, rather than betting on truly concurrent certifications.

  • special process approval

    Special process approval commonly refers to the formal acceptance of a manufacturing process whose results cannot be fully verified by later inspection or testing alone. In these cases, confidence in product conformity depends on controlling the process itself, including the method, equipment, materials, parameters, personnel qualifications, and records.

    Typical examples include heat treating, welding, brazing, plating, coating, soldering, bonding, sterilization, and some cleaning or surface treatment operations. Whether a process is considered special can vary by industry, product, customer requirement, or quality system.

    Special process approval is not the same as approving a finished part, a work instruction, or a supplier in general. It focuses on the capability and control of a specific process under defined conditions. Approval may involve process qualification, documentation review, source approval, operator certification, equipment validation, test coupons, first-run evidence, or periodic reapproval, depending on the organization and applicable requirements.

    How it appears in operations

    In manufacturing and regulated environments, special process approval often appears as a controlled status in quality, MES, ERP, or supplier management workflows. For example, a routing step may require an approved outside processor, approved internal work center, current process specification revision, and evidence that the required qualifications remain in effect before work can proceed.

    Organizations also use the term when linking purchase orders, work orders, certificates, travelers, and traceability records to a process that requires tighter oversight than standard inspection-based operations.

    Common confusion

    • Special process approval vs. supplier approval: supplier approval concerns whether a supplier is authorized to provide goods or services. Special process approval concerns whether a specific process, at that supplier or internally, is accepted for use.

    • Special process approval vs. product approval: product approval concerns acceptance of the part or assembly. Special process approval concerns control of the process used to create certain characteristics.

    • Special process approval vs. validation: validation is often one component of approval, but the approval decision may also include procedural, contractual, qualification, and recordkeeping requirements.

    Why the term matters

    The term matters because some product characteristics cannot be reliably confirmed after the fact without destructive testing, impractical testing, or incomplete inspection coverage. In those cases, organizations commonly rely on approved process controls and objective evidence to manage risk and maintain traceability.

  • Guidance standard

    A guidance standard is a published document that provides recommended practices, explanations, and examples intended to help organizations understand and implement regulations, laws, or formal standards. It is typically advisory rather than mandatory, and is used to interpret or operationalize higher-level requirements.

    Key characteristics

    In industrial and regulated manufacturing environments, a guidance standard commonly refers to:

    • Non-mandatory status: It describes recommended approaches rather than binding requirements. Organizations may follow it fully, partially, or not at all, provided they still meet applicable laws and contractual standards.
    • Interpretive role: It clarifies how to apply high-level requirements (for example from regulations, ISO, aerospace, or cybersecurity standards) in real operations.
    • Best-practice focus: It often consolidates industry-accepted good practices for designing processes, documentation, and controls.
    • Reference use in audits: Auditors and internal quality teams may use guidance standards as a reference model, without treating them as formal criteria unless an organization has chosen to adopt them.

    Operational meaning in manufacturing

    In OT/IT, MES, and quality-system contexts, guidance standards often help organizations:

    • Translate requirements from formal standards (for example, quality management, data integrity, cybersecurity) into procedures, work instructions, and system configurations.
    • Structure documentation such as SOPs, electronic records, or audit trails in a way that aligns with recognized good practice.
    • Design governance for topics like document control, traceability, change management, or supplier oversight.
    • Benchmark internal practices against industry expectations without asserting formal certification.

    Examples include guidance documents that accompany sector standards, recommended practices published by industry groups, or technical reports explaining how to implement specific controls in MES, ERP, or OT environments.

    What a guidance standard is not

    To avoid confusion, a guidance standard typically does not:

    • Establish legally binding requirements by itself, unless explicitly incorporated into regulation or contracts.
    • Guarantee compliance or certification if followed.
    • Replace the need to understand and meet the underlying regulation or normative standard.

    Common confusion

    • Guidance standard vs. normative standard: A normative standard (or requirement standard) specifies criteria that must be met when it is adopted or mandated (for example through contracts or regulation). A guidance standard suggests how requirements could be met but usually does not introduce mandatory criteria.
    • Guidance standard vs. regulation: Regulations are issued by authorities and are legally enforceable. Guidance standards may help interpret regulations but do not have the same legal status unless referenced by those authorities or contracts.
    • Guidance standard vs. company procedure: A company procedure is an internal document that prescribes how work is done at a specific organization. A guidance standard is external and high level, and may be used as an input when drafting those procedures.
  • Do MRO organizations always need AS9100, or is AS9110 more suitable?

    MRO organizations do not always need AS9100. AS9110 is usually more suitable when your core business is aircraft or component maintenance, repair, and overhaul rather than design and new production. However, what you actually need is driven by customer contracts, regulatory expectations, and how your organization is scoped.

    How AS9100 and AS9110 differ for MRO

    At a high level:

    • AS9100 extends ISO 9001 for aerospace design and manufacturing organizations.
    • AS9110 extends ISO 9001 for aerospace maintenance organizations (MRO), including line, base, and component maintenance.

    AS9110 emphasizes topics that are critical in MRO environments, such as maintenance process control, configuration control of in-service assets, verification after maintenance, and release to service. AS9100 emphasizes design control and new production processes, which may be less central to a pure MRO facility.

    When AS9110 is usually more suitable

    AS9110 is often a better fit if:

    • Your organization does not design or manufacture new aerospace products, and instead focuses on inspection, overhaul, modification, and repair.
    • You operate primarily as a maintenance organization under aviation authorities (for example, EASA Part-145, FAA repair station), and your customers expect an MRO-focused aerospace quality standard.
    • Your processes center on workscoping, disassembly, inspection, repair/overhaul, reassembly, test, and release to service of aircraft and components.
    • You need a standard that directly addresses used parts, maintenance records, configuration control of in-service assets, and control of outsourced repairs.

    In those cases, AS9110 typically reflects reality in an MRO shop more directly than AS9100. It can make your quality system, documentation, and audits better aligned with day-to-day maintenance workflows instead of design and new build flows.

    When AS9100 may still be required or beneficial

    There are scenarios where AS9100 is required, or where organizations choose to maintain AS9100 in addition to, or instead of, AS9110:

    • Mixed operations: If your site both manufactures new components and performs MRO activities, some OEMs and primes may prefer AS9100 for the whole site to keep supplier qualifications simpler.
    • Design activity present: If you hold design authority (for example, repairs, modifications, STCs, DER/DOA/ODA work) or perform significant design and development, customers may insist on AS9100 or a combination of AS9100 and AS9110.
    • Customer mandates: Some OEMs and defense customers specify AS9100 in supplier qualification requirements and may not yet fully recognize AS9110 as equivalent for their risk model. In those cases, your choice is constrained by contract.
    • Corporate standardization: Large multi-site organizations sometimes adopt a single corporate standard (often AS9100) for consistency even if parts of the operation are primarily MRO.

    If you are in any of these categories, you should expect to map your actual processes carefully against the required standard and be explicit about scope in your quality manual. You may also need to justify to customers and auditors how MRO-specific risks are addressed if you rely only on AS9100.

    Scope definition and brownfield reality

    The decision is rarely a clean switch between standards, especially in brownfield environments that already have a certified system, legacy documentation, and integrated MES/ERP/QMS stacks.

    • Scope matters more than the label: Certification bodies certify a scope and site, not just an industry code. You can scope one site or unit as AS9110 and another as AS9100, as long as interfaces, hand-offs, and responsibilities are clearly defined and documented.
    • Mixed systems and lifecycles: If you are running older ERP/MES/QMS tools configured around AS9100, moving to AS9110 is not just changing the certificate. It impacts procedures, routing logic, work instructions, records, and approval flows. In regulated environments with long equipment and data lifecycles, this can be a multi-year change under strict change control.
    • Validation and qualification burden: Any significant QMS restructuring in a safety-critical or defense context affects training, validation, and often customer approvals. Full replacement of systems or standards at once is high risk and often fails due to downtime constraints, integration debt, and the cost of requalification.

    Many organizations therefore evolve incrementally: maintaining AS9100 where required, while introducing AS9110-aligned practices in MRO units and harmonizing procedures gradually.

    What actually drives the decision

    From a practical standpoint, your choice should be driven by a set of concrete factors rather than a generic preference:

    • Contractual requirements: What do your current and target customers specify: AS9100, AS9110, or both? Are there flow-down requirements from OEMs or defense agencies?
    • Regulatory environment: How does your QMS intersect with aviation authority approvals (for example, Part-145, Part-21, military equivalents)? Some authorities are familiar with both standards; others may have a de facto expectation.
    • Operational profile: What percentage of your work is new build vs. MRO vs. modification/design? Where is the higher risk and scrutiny?
    • Existing QMS and IT systems: Is your current QMS structure, electronic records, and system validation more aligned to production or maintenance? What is the realistic cost and risk of re-alignment?
    • Supplier and site structure: Do you have multiple sites with different functions, and can you scope certifications differently without breaking traceability or overcomplicating audits?

    In many cases, a pure MRO business without design or manufacturing responsibilities is well served, and often better served, by AS9110 if customers accept it. A hybrid organization may need AS9100, or a combination, to cover the full lifecycle from design and production through sustainment.

    Implications for digital systems and traceability

    Whether you align to AS9100 or AS9110, regulators and customers will expect robust traceability, controlled documentation, and auditable records across maintenance and modification activities.

    • Traceability and configuration control: MRO environments must show which parts were removed, replaced, or repaired, with full lineage, especially for life-limited and serialized items. Your systems (ERP, MES/MRO, QMS) need to support this regardless of the chosen standard.
    • Change control and long lifecycles: Procedures, digital travelers, and work instructions evolve slowly in heavily regulated MRO contexts because each change impacts training, approvals, and often external audits. Any shift between AS9100 and AS9110 needs a phased, controlled plan.
    • System coexistence: It is common to have separate but integrated solutions for production, engineering, and MRO. The standard you certify to does not replace the need to map interfaces carefully: how nonconformances, concessions, and maintenance data cross between systems.

    The standard should be one part of a coherent architecture for quality and traceability, not a stand-alone decision.

    Bottom line

    MRO organizations do not always need AS9100. AS9110 is often more appropriate for pure maintenance organizations, but customer and regulatory requirements, mixed operations, and existing systems often constrain the choice. The safest approach is to analyze your actual operations and contracts, define a clear scope, and then select or combine standards accordingly, recognizing the change-control and integration implications of any shift.

  • What are typical OEM expectations for supplier AS9100 certification?

    Typical OEM expectations around AS9100 fall into a few patterns, but there is no universal rule. What is “required” depends on the OEM, the specific program or prime contractor, the part criticality, and whether you are a direct supplier or a sub-tier.

    1. Common OEM patterns for AS9100 expectations

    Across large aerospace OEMs and primes, you will usually see one or more of these patterns in supplier requirements:

    • AS9100 required for production & special processes: For hardware, assemblies, and special processes (heat treat, coatings, NDT, etc.), AS9100 certification from an accredited CB is often a baseline requirement for approved supplier status.
    • AS9100 strongly preferred, ISO 9001 sometimes accepted: Some OEMs will accept ISO 9001 with additional controls (more incoming inspection, higher audit frequency, limited scope of work) for lower-risk commodities or early-stage suppliers.
    • Design-responsible work usually requires AS9100: If you hold design authority, do significant engineering changes, or are a build-to-spec supplier, AS9100 (or equivalent aerospace QMS standard) is typically non-negotiable.
    • Service and MRO suppliers: For repair and overhaul, AS9110 or OEM-specific repair station approvals may be required in addition to (or instead of) AS9100.
    • Distributor and stockist expectations: Distributors may be expected to hold AS9120, but some OEMs accept AS9100 or ISO 9001 with additional traceability and counterfeit-part controls.

    These expectations are normally written into the OEM’s supplier quality manual, purchase order quality clauses, and supplier approval criteria. They are often flowed down from customer or regulatory requirements on specific programs.

    2. Where AS9100 is typically non-negotiable

    AS9100 certification (or an equivalent aerospace QMS standard) is most commonly treated as mandatory in these situations:

    • Flight-critical or safety-critical components, including structures, control surfaces, critical fasteners, and engine/hot section hardware.
    • Special process providers where OEMs must demonstrate control of process quality, traceability, and personnel qualification.
    • Design-responsible or build-to-spec suppliers contributing to type design or major design changes.
    • Key or single-source suppliers on certified or defense programs where risk and oversight expectations are higher.

    Even here, OEMs sometimes grant temporary or limited approvals to non-certified suppliers when there is no immediate alternative, but these are normally tied to:

    • Formal corrective actions and QMS upgrades.
    • Defined timelines for achieving AS9100 certification.
    • Increased OEM surveillance and more restrictive scopes of work.

    3. Where OEMs may allow alternatives

    In some cases, OEMs will accept alternatives to full AS9100 certification, with additional controls:

    • ISO 9001 with enhanced controls: Often used for non-critical hardware, build-to-print machining, or indirect materials. This usually comes with more incoming inspection, tighter lot acceptance criteria, and higher audit frequency.
    • OEM audits in lieu of certification: Small or niche suppliers may be allowed to operate without a formal AS9100 certificate if they pass an OEM QMS audit and accept limited approval or probationary status.
    • Program- or customer-specific carve-outs: Some defense or space programs allow specific supplier sets with their own approval rules; in those cases, program control plans and data requirements can matter as much as core certification.

    None of these alternatives remove the requirement to actually implement effective processes. OEMs still expect documented procedures, risk-based thinking, configuration control, and robust nonconformance management, regardless of the certificate on the wall.

    4. How OEMs actually evaluate suppliers beyond the certificate

    Even when AS9100 is listed as a requirement, most OEMs treat it as necessary but not sufficient. They typically look at:

    • Audit results and objective evidence: Internal audits, OEM/prime audits, and how well your processes are implemented versus just documented.
    • Nonconformance, escapes, and RCCA depth: The strength of your 8D/RCCA, containment speed, and evidence of systematic fixes.
    • Traceability and configuration control: Ability to show complete build history, revision control, and change management tied to engineering and planning systems.
    • Integration with existing systems: How your QMS and production systems coexist with legacy ERP, MES, PLM, and customer-facing portals and whether that causes data gaps.
    • Responsiveness and stability: Capacity, lead-time adherence, supplier OTD, and how you manage changes and disruptions.

    For brownfield plants with mixed systems, OEMs are very aware that AS9100-certified suppliers can still have fragmented processes, manual travelers, and weak data integrity. Certification is one input into risk classification, not a guarantee.

    5. Tradeoffs and risks for both OEMs and suppliers

    From the OEM’s perspective:

    • Requiring AS9100 across the board simplifies policy but can shrink the supplier pool, limit innovation, and create capacity constraints.
    • Allowing non-certified suppliers can increase supply options but adds audit load, qualification burden, and escape risk.

    From the supplier’s perspective:

    • Achieving AS9100 opens access to more OEMs and higher-value work but requires investment, ongoing internal audits, and disciplined change control.
    • Staying non-certified may be viable in niche or low-risk areas but constrains growth and can keep you in “high-surveillance” status with customers.

    In long-lifecycle aerospace programs, OEMs are cautious about swapping suppliers simply for certification reasons because re-qualification, FAI/AS9102 updates, and potential configuration changes carry cost, downtime risk, and documentation overhead. That is why you often see conditional approvals and phased AS9100 adoption expectations rather than abrupt cutoffs.

    6. Practical guidance if you are a supplier

    If you are trying to understand what a specific OEM expects, you should:

    • Review the OEM’s supplier quality manual and purchase order quality clauses for explicit AS9100/AS9110/AS9120 language.
    • Clarify with the OEM supplier quality engineer (SQE) how expectations vary by commodity, part criticality, and program.
    • Ask whether ISO 9001 plus OEM audit is acceptable short term while you pursue AS9100.
    • Plan QMS upgrades with realistic timelines, accounting for validation, system integration, and documentation updates across ERP, MES, and PLM, not just the certification audit.

    AS9100 certification is widely expected for serious participation in aerospace supply chains, especially on critical work, but it is only one component of how OEMs assess risk, approve suppliers, and maintain ongoing oversight.

  • Transition period

    A transition period is a defined span of time during which an organization, process, system, or controlled activity moves from one state to another. In industrial and regulated environments, it commonly refers to the interval used to shift from an old method, version, supplier, equipment state, or compliance approach to a new one while maintaining continuity of operations and records.

    The term describes the time window itself, not the final target state and not the detailed plan used to get there. A transition period may be formal, with documented start and end conditions, or informal, but in controlled environments it is often tied to approvals, effective dates, training completion, document revisions, system cutover steps, or inventory depletion.

    How it appears in operations

    In manufacturing and quality workflows, a transition period may apply to:

    • changeover from one work instruction revision to another
    • migration from paper records to electronic records
    • cutover from a legacy MES, ERP, or quality system to a new platform
    • introduction of a new supplier, material, or process routing
    • phased enforcement of updated internal procedures or customer requirements

    During this interval, both old and new states may coexist under defined controls. For example, a plant may allow existing inventory labeled to an earlier specification to be consumed until a stated date while all newly released work orders use the updated revision.

    What it includes and excludes

    A transition period commonly includes timing boundaries, interim rules, and criteria for when the old state is no longer allowed. It may also include temporary controls such as dual documentation, added review steps, or restricted user access during a system rollout.

    It does not necessarily mean a shutdown, a maintenance outage, or a probationary period for personnel. It is also not the same as the change request, validation package, or project plan, although those may define or govern the transition period.

    Common confusion

    Transition period is often confused with implementation period. The implementation period is the time used to put a change in place, while the transition period focuses on the managed overlap or shift from old to new.

    It is also sometimes confused with grace period. A grace period usually emphasizes temporary tolerance after a deadline, while a transition period is broader and usually includes the controlled move before full adoption.

    In quality and compliance discussions, it can overlap with terms like effective date, cutover window, and phase-in period, but those are narrower. An effective date is a point in time, a cutover window is usually a short technical switchover interval, and a phase-in period emphasizes gradual adoption.

  • What MRO records are auditors most likely to request during a Part 145 inspection?

    The short answer is that auditors usually start with the records that let them reconstruct what work was done, who did it, what data and parts were used, what inspections occurred, and who approved return to service or maintenance release. They are generally looking for traceability, record completeness, and evidence that your documented system matches actual practice.

    The exact records requested vary by authority, ratings, capabilities, product types, subcontracting model, and any prior findings. A line station, component shop, engine shop, and avionics repair operation will not all be sampled the same way. But in most Part 145 environments, the records most likely to be requested include:

    • Work package and job records: work orders, task cards, travelers, discrepancy records, inspection steps, sign-offs, dates, and labor entries.

    • Maintenance release or return-to-service records: the completed release documentation and the basis used to support it.

    • Approved maintenance data used for the work: revision-controlled manuals, instructions for continued airworthiness, repair data, engineering authorizations where applicable, and evidence the current version was available at the time of work.

    • Personnel qualification and authorization records: training, recurrent training, certifications where applicable, authorization rosters, and records showing who was permitted to perform, inspect, and approve work.

    • Tooling and test equipment records: calibration status, due dates, out-of-tolerance investigations where relevant, and evidence the equipment used was controlled.

    • Parts and material traceability records: receiving inspection, shelf-life control where relevant, batch or serial traceability, source documentation, and segregation of serviceable versus unserviceable material.

    • Component history and serialized records: removal/installation history, life-limited status where relevant, prior maintenance history available to the station, and tag or status documentation.

    • Nonconformance, rework, and corrective action records: discrepancy disposition, repair versus scrap decisions, concession or deviation control where allowed by your system, and evidence that corrective actions were implemented and closed.

    • Contract review and customer authorization records: evidence the work performed matched approved capability, customer scope, and any accepted limitations.

    • Supplier and subcontract process records: outside processing approvals, supplier controls, incoming acceptance, and how outsourced steps were traced back into the maintenance record.

    • Manuals, procedures, and change control records: current repair station manual procedures, revisions, distribution control, and evidence that changes were reviewed and implemented in a controlled way.

    • Training, occurrence, and internal oversight records: internal audits, remedial training, incident follow-up, and management actions tied to prior findings.

    What auditors usually test inside those records

    In practice, auditors are often less interested in the presence of a document than in whether the record set is internally consistent. They will often sample a completed job and test questions like these:

    • Does the work order match the capability and approved data used?

    • Were the people who performed and inspected the work authorized at that time?

    • Was the equipment used in calibration when the work was done?

    • Can installed parts be traced to acceptable source and receiving records?

    • Do discrepancies, rework, and inspections line up with the final release?

    • Do timestamps, signatures, and revisions make sense, or were records completed late or reconstructed?

    • Does the electronic system audit trail support the sequence shown on the paperwork?

    That last point matters more in digital environments. If your MRO records are split across ERP, MRO software, QMS, document control, and spreadsheets, auditors may request records from several systems for one sample event. In brownfield operations, the issue is often not missing data but conflicting data, weak revision control, broken links between systems, or manual transcriptions that are hard to validate.

    What tends to trigger deeper scrutiny

    Certain conditions usually increase the chance that an auditor asks for more records or expands the sample:

    • Missing or illegible sign-offs

    • Backdated or bulk-entered transactions

    • Gaps in serial, batch, or lot traceability

    • Use of superseded maintenance data

    • Expired training or authorization records

    • Calibration lapses or unresolved out-of-tolerance events

    • Manual workarounds outside approved procedure

    • Inconsistent status tagging for parts or assemblies

    • Outsourced processing with weak evidence of control or acceptance

    If those issues exist, the inspection can shift from document sampling to a broader review of your control system. That does not automatically determine an outcome, but it does increase the effort needed to explain and defend the record trail.

    Paper versus digital records

    Electronic records are generally acceptable only to the extent that they are complete, attributable, retrievable, protected from uncontrolled change, and supported by your procedures and actual practice. A digital system does not reduce scrutiny by itself. In some shops it improves traceability; in others it exposes integration debt that paper had been hiding.

    Full replacement of legacy systems is often not the practical answer in a regulated MRO environment. Many organizations run mixed platforms because replacing ERP, MRO, QMS, and document control systems at once creates qualification burden, validation cost, downtime risk, retraining effort, and new traceability gaps during transition. A more realistic approach is usually to tighten evidence trails across existing systems, define system-of-record ownership clearly, and control handoffs and change management.

    How to prepare for likely requests

    A useful way to prepare is to pick several closed work orders and verify that a reviewer can move from intake through execution to release without asking for undocumented tribal knowledge. If that cannot be done quickly, your issue is usually retrieval discipline, integration quality, or record governance rather than lack of software.

    At minimum, be ready to produce a coherent sample package showing:

    • the initiating work scope and discrepancy

    • the approved data used and its revision status

    • personnel authorization and training status

    • tooling and test equipment control

    • parts and material traceability

    • inspection and rework evidence

    • the final release decision and supporting sign-offs

    No single checklist guarantees what an auditor will ask for, because surveillance focus and sampling differ. But if your organization can consistently produce those record sets, with clear traceability and controlled changes, you are usually prepared for the most common Part 145 inspection requests.