RSC Cluster: Audit and Compliance Readiness (AS9100, LPAs and Process Audits)

The Audit and Compliance Readiness Cluster focuses on turning audit preparation into continuous evidence rather than episodic panic. It explains what auditors actually expect to see across training, revision control, traceability, and execution records. The content covers internal audits, layered process audits, and AS9100 expectations using real operational examples. This cluster helps organizations stay audit-ready by design, not by scramble.

  • SAE International

    SAE International is a global professional association and standards development organization focused on aerospace, automotive, and commercial vehicle engineering. It develops, maintains, and publishes technical and quality standards that are widely used in regulated manufacturing and industrial operations.

    Role in standards and regulated manufacturing

    In industrial and aerospace contexts, SAE International commonly refers to the organization that:

    • Coordinates and publishes consensus-based engineering standards for materials, components, testing, and processes
    • Acts as an accredited standards body that works with industry groups and other standards organizations
    • Supports aerospace quality and compliance frameworks by publishing aerospace standards that align with ISO and other international norms
    • Provides reference documents used in design, manufacturing, maintenance, and quality assurance workflows

    For aerospace quality management, SAE International is one of the bodies that publishes the aerospace versions of ISO-based standards, such as those aligned with AS9100 and related documents, using text controlled by the relevant aerospace industry groups.

    How it shows up in operations

    Within manufacturing and operations, SAE International standards may appear as:

    • Referenced specifications in engineering drawings, bills of material, and work instructions
    • Requirements for material properties, fasteners, wiring, fluids, or testing methods
    • Normative references within aerospace quality management system documentation
    • Inputs to MES, PLM, and QMS configurations where standards codes or revisions must be controlled

    Organizations often integrate SAE standard identifiers into document control systems, digital work instructions, supplier requirements, and audit evidence, to demonstrate that products and processes follow recognized engineering practices.

    Common confusion

    SAE International is sometimes confused with:

    • IAQG (International Aerospace Quality Group), which develops and controls the aerospace quality system requirements (for example the content behind AS9100). SAE International acts as one of the publishing standards bodies, but it does not solely own or control the AS9100 requirements.
    • Certification bodies, which audit and certify organizations to standards. SAE International develops and publishes standards but does not act as the certification body that audits individual companies.

    Context from aerospace quality standards

    In the context of AS9100 and related aerospace quality standards, SAE International typically serves as one of the accredited organizations that publish the official text produced and controlled by the aerospace industry groups. Manufacturers, suppliers, and auditors reference the SAE-published editions as the authoritative documents for implementation and compliance interpretation.

  • High-Level Structure (HLS)

    High-Level Structure (HLS) commonly refers to the standardized framework used across modern ISO management system standards to align their structure, core text, and terminology. It is intended to make multiple management systems easier to integrate and manage within a single organization.

    What High-Level Structure (HLS) includes

    In the context of quality, environmental, and other management systems (such as ISO 9001, ISO 14001, ISO 45001 and related standards), HLS typically includes:

    • A common set and order of top-level clauses (for example, context of the organization, leadership, planning, support, operation, performance evaluation, improvement).
    • Harmonized core text and shared definitions across different ISO management system standards.
    • A consistent approach to risk-based thinking, documented information, and continual improvement.

    This common structure allows industrial and manufacturing organizations to align their quality management system (QMS), environmental management system (EMS), information security management system (ISMS), and other frameworks within a single integrated management system.

    Operational meaning in manufacturing and regulated environments

    In industrial operations, the High-Level Structure shows up as the organizing backbone for policies, procedures, and records that support compliance and certification efforts. Examples include:

    • Designing a QMS that uses the same clause headings and numbering as ISO 9001 or related standards, so internal procedures and work instructions can be mapped directly to specific clauses.
    • Structuring MES, QMS, and document control workflows so that audit evidence can be retrieved and reported according to HLS clauses, such as operation or performance evaluation.
    • Building an integrated management system that covers quality, environment, safety, or information security using one shared framework instead of separate, unrelated structures.

    HLS itself is not a software product or a specific digital architecture. It is a structural and textual framework that standards bodies apply and that organizations mirror in their management system documentation and supporting systems.

    Common confusion

    • Not a detailed process map: HLS defines top-level clauses and common text, but it does not dictate specific manufacturing processes, workflows, or system configurations.
    • Not limited to quality only: Although often referenced with ISO 9001, HLS is used across multiple types of ISO management system standards.
    • Different from system architecture: Some teams use “high-level structure” informally to describe the architecture of an IT, OT, or MES solution. In ISO terminology, HLS specifically refers to the standardized structure of management system standards, not an application or data architecture diagram.
  • Normative standard

    A normative standard is a formally approved document that specifies requirements, rules, or criteria intended to be used consistently as a reference for designing, operating, or assessing products, processes, or systems. In industrial and regulated manufacturing environments, normative standards are used to define what is expected or acceptable from an engineering, quality, safety, security, or compliance perspective.

    Key characteristics

    Normative standards typically:

    • Are issued by recognized bodies such as ISO, IEC, ASTM, SAE, or industry consortia, or by regulators and authorities.
    • Contain requirements, criteria, or test methods that can be applied and audited.
    • Provide a basis for contracts, procurement specifications, internal procedures, and qualification or validation activities.
    • May be adopted as legal or regulatory references, or cited in customer and supplier agreements.

    In manufacturing operations, examples of commonly referenced normative standards include quality management system standards, cybersecurity standards for OT/IT environments, and specifications for inspection, measurement, documentation, or data integrity.

    Normative vs. informative

    Many standards documents are structured into:

    • Normative sections, which define requirements or rules that “shall” be followed if the standard is applied.
    • Informative sections, such as annexes, examples, or guidance notes, which provide clarification or recommendations but are not requirements.

    When a document is described as a normative standard, it means it is primarily intended to set requirements, not only to provide guidance.

    Operational use in manufacturing and regulated environments

    Within industrial operations and manufacturing systems, normative standards commonly influence:

    • Quality management and compliance: defining how nonconformances, CAPA, audits, and documentation must be structured and controlled.
    • MES/ERP and IT/OT systems: specifying data integrity, traceability, cybersecurity controls, and interface expectations between systems.
    • Process and product definition: establishing required inspection methods, test acceptance criteria, material specifications, and documentation sets (for example, records needed for traceability and audit trails).
    • Document control: determining how procedures, work instructions, and records must be authored, reviewed, approved, versioned, and retained.

    Common confusion

    • Normative standard vs. regulation: A regulation is issued by a governmental or regulatory authority and may be legally binding. A normative standard is typically issued by a standards body and becomes binding only when referenced in law, contracts, or internal policies.
    • Normative standard vs. guideline or best practice: Guidelines and best practices are usually informative and advisory. A normative standard contains requirements that can be objectively checked for conformity.
    • Normative reference: Within a standard, a normative reference section lists other standards or documents that are considered part of the requirements. These are not separate from the concept of a normative standard but indicate external documents that are required to apply the standard correctly.

    Relevance to digital and integrated manufacturing systems

    As factories adopt MES, ERP, PLM, and other digital systems, normative standards often define:

    • Minimum acceptable controls for electronic records, electronic signatures, and audit trails.
    • Requirements for classification, protection, and exchange of technical data, including security baselines.
    • Standardized terminology and data structures that support interoperability and consistent reporting across systems.

    Organizations frequently align internal procedures, workflows, and system configurations with applicable normative standards, then use those standards as a reference point during internal audits, supplier assessments, and external reviews.

  • amendment

    An amendment is a formally approved, limited change to an existing document, standard, specification, or controlled record that does not replace the entire document. It typically adds, clarifies, or corrects specific clauses, sections, figures, or annexes while leaving the base edition in force.

    How amendments are used in regulated and industrial contexts

    In manufacturing and other regulated environments, amendments commonly apply to:

    • International and industry standards (for example, cybersecurity, safety, or quality standards)
    • Internal procedures, work instructions, and SOPs controlled by a document management process
    • Technical specifications and design documents shared across plants or with suppliers

    An amendment is typically identified by linking it to a specific base document and edition (for example, a particular part of a standard and its publication year). Organizations track which amendments are in effect, assess their impact, and decide if and when to adopt them through change control, validation, and training workflows.

    Amendment vs. revision

    • Amendment: A targeted update to selected portions of a document. The base edition remains valid and is read together with the amendment.
    • Revision: A full new edition that consolidates previous text and usually incorporates earlier amendments, often replacing the prior edition.

    In practice, a document may go through several amendments before a full revision is issued.

    Common confusion

    • Amendment vs. addendum: An addendum adds extra content (for example, an additional annex or example) without changing existing clauses, while an amendment can change existing text.
    • Amendment vs. correction/erratum: Corrections or errata usually address minor errors such as typos or misprints. Amendments typically reflect more substantive technical, procedural, or compliance-relevant changes.

    Link to standards work (for example, IEC 62443)

    Standards such as IEC 62443 may receive amendments when committees update specific requirements in response to technology shifts, new threat information, or industry feedback. Each amendment is published as a separate, traceable document that references the base part and edition. Operators and integrators then decide how to incorporate these changes into their cybersecurity, validation, and document control processes.

  • audit plan

    An audit plan is a documented description of the objectives, scope, criteria, methods, responsibilities, timing, and resources for a specific audit or series of audits. In industrial and regulated manufacturing environments, it typically covers internal audits, supplier audits, and external or certification audits related to quality, safety, environmental, cybersecurity, or regulatory standards.

    What an audit plan includes

    Although formats differ, an audit plan commonly specifies:

    • Objective: Why the audit is being performed, such as verifying compliance with a standard, internal procedure, or regulatory requirement.
    • Scope: Sites, departments, processes, products, time period, and systems to be audited, and what is explicitly out of scope.
    • Criteria: The standards, regulations, procedures, and contracts the audit will measure against.
    • Method: Techniques such as interviews, document review, records sampling, walkdowns, and system tests.
    • Schedule and frequency: Dates, duration, and recurrence of audits, including surveillance or follow-up audits.
    • Roles and responsibilities: Audit team members, auditees, and any required technical specialists.
    • Resources and logistics: Access to systems, records, areas, and any required tools, data, or escorts.
    • Reporting approach: How nonconformities, observations, and conclusions will be documented and communicated.

    How audit plans are used in manufacturing

    In manufacturing operations, an audit plan typically guides:

    • Internal audits of quality management systems, production processes, OT/IT controls, or data integrity.
    • Supplier and contractor audits to verify capability, quality, data handling, or compliance with technical and regulatory requirements.
    • Certification and surveillance audits conducted by external bodies, including the planned frequency and coverage of surveillance visits.
    • Regulatory inspections preparation by aligning required records, evidence, and responsible contacts with planned inspection focus areas.

    Operationally, the audit plan acts as a reference for aligning MES, ERP, document management, and quality systems so that required records and evidence can be accessed during the audit window.

    Common confusion

    • Audit plan vs. audit program: An audit plan usually applies to a specific audit or short series of audits. An audit program is broader and covers the overall strategy, schedule, and governance for multiple audits over time.
    • Audit plan vs. audit checklist: A checklist is a detailed set of verification points used during the audit. The audit plan defines the overall structure and conditions of the audit, which may reference one or more checklists.
    • Audit plan vs. quality plan: A quality plan describes how quality will be managed for a product, project, or process. An audit plan describes how conformance to requirements, including quality requirements, will be examined.

    Link to surveillance and certification audits

    For certification and surveillance audits, the audit plan typically outlines the surveillance cycle, planned audit days, sites and processes to be visited in each cycle, and how follow-up on previous nonconformities will be handled. The plan is usually agreed between the organization and the certification body and may be adjusted based on risk, multi-site scope, and audit history.

  • administrative controls

    Administrative controls are documented policies, procedures, and organizational practices that govern how people in an organization manage security, safety, and compliance risks. They define what must be done, by whom, and how often, rather than relying on technology or physical barriers alone.

    What administrative controls include

    In industrial and regulated environments, administrative controls commonly include:

    • Policies and standards, such as information security policies, acceptable use policies, and quality manuals
    • Procedures and work instructions that describe step-by-step actions for operating equipment, handling deviations, or responding to incidents
    • Roles, responsibilities, and segregation of duties, such as defining who can approve changes, release batches, or access certain systems
    • Training and awareness requirements, including onboarding, periodic refreshers, and qualification for specific tasks
    • Governance and oversight mechanisms, such as management reviews, risk assessments, and change control boards
    • Disciplinary, escalation, and incident response protocols defining how violations or events are handled
    • Documentation and recordkeeping rules covering how evidence is created, reviewed, approved, and retained

    These controls are often described as procedural or managerial controls and are typically enforced through training, supervision, audits, and supporting IT/OT workflows.

    How administrative controls relate to other security controls

    In risk and security frameworks, administrative controls are one of several categories of controls:

    • Administrative controls define the rules, processes, and responsibilities.
    • Technical (logical) controls use technology, such as authentication, firewalls, or application permissions, to enforce rules.
    • Physical controls use physical measures, such as locks, guards, and environmental monitoring.
    • Compensating controls are alternate measures used when standard controls cannot be fully implemented.

    In practice, effective risk management in manufacturing often combines administrative controls (for example, a formal access management procedure) with technical and physical controls (for example, role-based access in MES and locked control rooms).

    Operational context in manufacturing and regulated environments

    In industrial operations, administrative controls typically appear as:

    • Standard operating procedures (SOPs) for batch release, change control, or maintenance
    • Quality, safety, and cybersecurity policies aligned with corporate and regulatory requirements
    • Documented workflows in MES, ERP, QMS, and EHS systems that mirror approved procedures
    • Formal training and qualification records for operators, engineers, and maintenance staff
    • Approval matrices and sign-off rules for deviations, CAPA, and configuration changes

    These controls are often validated or periodically reviewed to confirm that documented procedures match actual shop floor practices and that records provide suitable evidence for audits.

    Common confusion

    • Administrative vs. technical controls: Administrative controls describe how people should act and how processes are governed. Technical controls are implemented through systems or devices (for example, automated account lockout).
    • Administrative controls vs. documentation alone: A written policy or SOP counts as an administrative control only when it is formally adopted, communicated, and used to guide behavior. Draft or unused documents are not usually treated as effective controls.

    Link to security control categories

    In the context of the four common security control categories (physical, technical, administrative, and compensating), administrative controls provide the procedural framework that defines how people manage and monitor all other controls, especially in brownfield plants where technology and physical protections may vary by asset and age.

  • Assessment Objective

    An assessment objective is a specific, documented goal or target that an audit, test, or evaluation activity is intended to measure and verify. It states what the assessment is trying to determine or demonstrate, such as whether a process, system, or control is designed, implemented, and operating as intended.

    In industrial and regulated manufacturing

    In manufacturing operations, assessment objectives commonly appear in:

    • Internal and external audits (for example, AS9100, ISO 9001, or cybersecurity assessments) where objectives describe which requirements, processes, or controls are being evaluated.
    • Process and layered process audits where objectives specify what aspects of process performance, standard work adherence, or risk control are to be checked.
    • Quality system assessments such as CAPA effectiveness checks, where objectives define what evidence is needed to judge whether an action resolved the underlying issue.
    • OT/IT, MES, or cybersecurity assessments where objectives identify which systems, data flows, or security controls are being validated against defined criteria or standards.

    Well-defined assessment objectives are usually:

    • Specific: focused on a particular process, control, requirement, or outcome.
    • Measurable: tied to observable evidence, data, or test results.
    • Aligned to requirements: derived from standards, internal procedures, or risk analyses.
    • Documented: stated in audit plans, test plans, or assessment scopes.

    Operational usage

    Practically, assessment objectives guide how assessments are planned, executed, and documented:

    • In an audit plan, each objective leads to specific questions, sampling plans, and required records.
    • In system or control testing (for example, MES access control or traceability checks), objectives determine what must be demonstrated in test scripts.
    • In continuous improvement reviews, objectives frame what success looks like when verifying process changes or risk mitigations.

    Common confusion

    • Assessment objective vs. audit scope: Scope defines the boundaries of what will be covered (sites, processes, time period). Assessment objectives state what the assessment is trying to conclude or verify within that scope.
    • Assessment objective vs. assessment criteria: Objectives describe the purpose of the assessment. Criteria are the standards, requirements, or specifications used to judge conformity or effectiveness.

    Relation to cybersecurity and control assessments

    In cybersecurity and regulatory frameworks used in industrial and defense environments, such as NIST 800-171 or similar standards, each control often has one or more associated assessment objectives. These detail the discrete elements that must be examined (for example, presence of policies, technical configuration, and implementation evidence) to determine whether the control is adequately addressed in practice. This same pattern is often applied when designing internal control assessments for MES, OT networks, and data governance in regulated manufacturing.

  • Gap Assessment

    A gap assessment is a structured review used to compare the current state of processes, systems, controls, or documentation against defined requirements or target conditions. In industrial and regulated manufacturing environments, it commonly refers to evaluating operations against standards, regulations, internal policies, or reference models to identify where requirements are not fully met.

    What a gap assessment includes

    In practice, a gap assessment typically involves:

    • Clarifying the reference requirements or targets, such as regulations, standards, corporate procedures, or system specifications
    • Documenting the current state of processes, technologies, organizational roles, and records
    • Comparing current practices and controls to each requirement or expectation
    • Identifying gaps, partial compliance, and unclear or conflicting practices
    • Summarizing findings in a structured way, often with risk, impact, and priority indicators

    In manufacturing, gap assessments are often applied to areas such as:

    • Manufacturing execution systems (MES) capabilities versus ISA-95 style functional models
    • Quality management processes versus internal quality system procedures
    • Data integrity and electronic records practices versus regulatory expectations
    • Cybersecurity controls in OT environments versus a chosen security framework
    • Document control and change control practices versus policy requirements

    Operational meaning in manufacturing environments

    Operationally, a gap assessment provides a structured list of where current operations or systems do not align with required or desired practices. The output is usually:

    • A set of documented gaps, each linked to a specific requirement or expectation
    • Evidence or observations that support each identified gap
    • High-level recommendations or considerations for remediation, often used as input to a remediation plan or roadmap

    Gap assessments are descriptive rather than prescriptive. They describe where misalignments exist but do not, by themselves, implement changes or guarantee any specific compliance or certification outcome.

    What a gap assessment is not

    A gap assessment is not the same as:

    • An implementation project or remediation program. It precedes and informs those activities.
    • A full formal audit in the regulatory or certification sense, although the methods and documentation can be similar.
    • A root cause analysis. It may highlight where requirements are not met without determining the underlying causes.

    Common confusion

    Gap assessment vs. gap analysis: In many organizations the terms are used interchangeably to describe the comparison of current state to a target. Some practitioners use “assessment” to emphasize a structured, documented review and “analysis” for the deeper examination of causes and options, but this distinction is not universal.

    Gap assessment vs. risk assessment: A gap assessment focuses on alignment to defined requirements or targets. A risk assessment focuses on identifying and evaluating risks, which may include but are not limited to compliance gaps. Gap assessment results often feed into risk assessment activities.

    Use in regulated and integrated manufacturing systems

    In regulated manufacturing and integrated OT/IT environments, gap assessments frequently address:

    • MES and ERP integration practices versus defined data integrity, traceability, or interoperability requirements
    • Quality system processes (for example, CAPA, change control, batch record management) versus internal or external expectations
    • Audit readiness, especially identifying missing or incomplete evidence needed to demonstrate adherence to procedures
    • Cybersecurity controls on shop floor assets relative to a chosen security baseline for industrial control systems

    The output of these assessments is often used to prioritize system enhancements, process redesign, documentation updates, training, and governance changes.

  • Certification audit

    A certification audit is a formal, independent assessment performed by an external body to determine whether an organization’s management system conforms to the requirements of a specific published standard. In industrial and regulated manufacturing environments, this often relates to standards such as ISO 9001, AS9100, ISO 13485, ISO 14001, or information security and cybersecurity standards.

    The outcome of a certification audit is typically a recommendation to grant, maintain, suspend, or withdraw a certificate that states the management system is in conformity with the audited standard. The audit focuses on documented processes, implementation on the shop floor and in supporting functions, and objective evidence that requirements are consistently met.

    Key characteristics

    • External and independent: Conducted by a third-party certification body, not by the organization itself.
    • Standard-specific: Evaluates conformity against a defined standard (for example, ISO 9001 for quality management or AS9100 for aerospace quality).
    • Evidence-based: Uses interviews, document reviews, records, and on-site observations to verify practices match documented procedures and standard requirements.
    • Certificate-focused: The primary purpose is to support a decision on issuing or continuing an official certificate, often required by customers or contracts.
    • Recurring cycle: Usually follows a multi-year certification cycle with an initial audit followed by periodic surveillance and recertification audits.

    How it appears in manufacturing operations

    In industrial and regulated manufacturing, a certification audit typically includes:

    • Review of quality management system documentation, process maps, procedures, and work instructions.
    • Sampling of production, inspection, maintenance, calibration, and traceability records from MES, ERP, QMS, LIMS, and document control systems.
    • Interviews with operators, supervisors, engineers, and quality personnel to confirm understanding and consistent application of procedures.
    • Walkthroughs of production lines, test labs, and material handling areas to verify that actual practices align with documented processes and standard requirements.
    • Verification that nonconformances, CAPA, MRB decisions, and audit findings are recorded, analyzed, and closed according to defined processes.

    Certification audits often require organized evidence from systems such as MES, ERP, and electronic document control, including revision histories, training records, change control documentation, and audit trails.

    Types of certification audits

    • Initial certification audit: A comprehensive, often two-stage audit conducted when an organization first seeks certification to a standard.
    • Surveillance audit: Periodic, usually annual or semi-annual, audits that sample parts of the management system to confirm continued conformity.
    • Recertification audit: A more extensive audit performed at the end of a certification cycle (often every three years) to determine whether to renew certification.
    • Scope extension audit: Conducted when an organization wants to extend the scope of its existing certificate to new sites, processes, or products.

    Common confusion

    • Certification audit vs. internal audit: An internal audit is performed by or on behalf of the organization itself to assess its own processes and readiness. A certification audit is carried out by an external certification body and is directly linked to issuing or maintaining a certificate.
    • Certification audit vs. customer (second-party) audit: Customer audits are performed by a customer or their representative to evaluate a supplier’s capability or compliance with contract requirements. Certification audits focus on conformity to a published standard, not to a specific customer contract.

    Relation to audit readiness and evidence management

    For organizations operating in regulated manufacturing, certification audits drive requirements for structured documentation, record retention, and traceability across systems. Digital tools such as MES, electronic DHR or DMR, QMS, and document control platforms are frequently used to organize evidence, demonstrate version control, and provide audit trails that support certification decisions.

  • Annex A Mapping

    Annex A mapping commonly refers to the activity of aligning an organization’s existing controls, processes, or system functions to the detailed control list or requirements found in “Annex A” of a formal standard or framework. In industrial and regulated manufacturing environments, this is typically used for cybersecurity, quality, or information security standards that publish a structured control catalogue in an annex section labeled “Annex A”.

    The mapping is usually documented in a structured form (for example, a matrix or checklist) that shows how each Annex A requirement is addressed by policies, procedures, OT/IT systems, MES configurations, or other internal controls. It is used to support internal governance, audits, and regulatory inspections, but does not itself constitute proof of compliance.

    How Annex A mapping is used in operations

    In industrial and manufacturing settings, Annex A mapping may include:

    • Linking each Annex A control to specific SOPs, work instructions, or quality procedures
    • Referencing MES, ERP, or OT system functions that implement or support the control
    • Identifying evidence sources, such as electronic records, logs, or batch documentation
    • Highlighting control owners and responsible departments (e.g., IT, OT, Quality, Engineering)
    • Identifying gaps where Annex A requirements are only partially addressed

    Operationally, Annex A mapping is often maintained as a living document, updated when processes, systems, or standards change. It can be used during readiness assessments, vendor evaluations, or when integrating new sites into a corporate control framework.

    Common contexts for Annex A

    Many standards and frameworks in regulated and industrial environments include an Annex A that lists controls or detailed requirements. While specific content differs, the concept of Annex A mapping is similar across them: aligning internal controls to the annex’s structure.

    Typical contexts include:

    • Information security or cybersecurity standards that define a catalog of controls in Annex A
    • Quality or risk management standards where Annex A provides a structured set of practice areas
    • Sector-specific guidelines where Annex A lists technical or operational safeguards

    What Annex A mapping is not

    Annex A mapping is:

    • Not the standard itself; it is an internal representation of how the standard’s Annex A is addressed
    • Not an official certification result or regulatory approval
    • Not a substitute for risk assessment, validation, or testing of controls

    Common confusion

    Annex A mapping is sometimes confused with:

    • Gap assessment: A gap assessment may use Annex A mapping, but also evaluates control design and effectiveness. Annex A mapping by itself often just shows alignment and coverage.
    • Control implementation: Mapping documents which controls should be implemented and where, but does not guarantee that they are implemented or effective.
    • Single-standard scope: Some organizations use the term only for one specific standard, but the general concept applies to any framework that uses an Annex A control catalog.

    Relation to manufacturing systems

    In manufacturing and OT/IT environments, Annex A mapping often crosses functional boundaries. A single Annex A control can be implemented through a combination of:

    • Plant-floor systems such as MES, historians, or SCADA
    • Enterprise systems such as ERP, QMS, PLM, or document management
    • Organizational processes like change control, access management, and training

    This cross-mapping helps organizations trace how standards-based requirements are realized in day-to-day operations, including how evidence is generated across digital and paper-based records.