RSC Sphere: Quality, Compliance and Traceability

The Quality, Compliance and Traceability Sphere demonstrates how audit-grade credibility is built directly into execution workflows. It connects nonconformance, corrective action, inspection, traceability, and audit evidence into a continuous operational loop. The content emphasizes how quality systems must interact with live work rather than exist as parallel documentation processes. This sphere proves that compliance and execution can reinforce each other instead of competing for attention.

  • CMM

    CMM most commonly refers to a Coordinate Measuring Machine, a device used to capture precise dimensional measurements of parts and assemblies, typically in three dimensions. It is a core tool in manufacturing quality control and inspection.

    What a CMM is

    A coordinate measuring machine is a metrology system that determines the coordinates of points on a part surface and compares them to a defined geometry, such as a CAD model or drawing. It can be manual or CNC-controlled and usually operates with a probing system.

    Typical CMM characteristics include:

    • A mechanical structure (bridge, gantry, horizontal arm, or portable arm) that moves along defined axes
    • A probe system (contact or non-contact) that detects part surfaces or features
    • Control and analysis software that interprets probe data, calculates feature geometry, and reports deviations from nominal values
    • Integration with CAD, CAM, MES, and QMS systems for model-based inspection and electronic records

    In regulated and model-based manufacturing environments, CMMs are frequently used to:

    • Verify critical dimensions, geometric tolerances, and datum schemes
    • Support first article inspection and ongoing production inspection
    • Generate electronic inspection records tied to specific part numbers, revisions, and serial numbers
    • Validate model-based definition (MBD) and GD&T requirements directly from 3D models

    What a CMM is not

    A CMM is not a general-purpose CAD or CAM tool, and it does not machine or modify parts. It is a measurement and inspection device. It also is not limited to a specific industry; it is used across aerospace, automotive, medical device, electronics, and other precision manufacturing domains.

    Operational meaning in manufacturing systems

    In operations and manufacturing IT/OT stacks, CMMs often appear as part of the quality and inspection layer. They may be:

    • Connected to MES or QMS for automatic data collection and inspection plan execution
    • Driven by inspection programs that are generated from CAD or MBD files
    • Sources of measurement data used for process capability analysis, SPC, and nonconformance management

    When misaligned with CAD models, drawings, or tolerance schemes, CMM programs can contribute to hidden scrap and rework, such as when individual parts pass CMM inspection but still fail at assembly due to tolerance stacking or misinterpreted GD&T.

    Other meanings of CMM

    In some IT and process-improvement contexts, CMM may also refer to a Capability Maturity Model, a framework used to assess the maturity of processes (for example, software or quality processes). In the context of industrial metrology and manufacturing quality, however, CMM almost always means coordinate measuring machine.

    Common confusion

    • CMM vs. inline gauges or check fixtures: CMMs are flexible, programmable measurement systems, while gauges and fixtures are typically fixed, part-specific tools.
    • CMM vs. scanner-only systems: Many CMMs can use non-contact scanning probes, but not all scanners are part of a CMM. Handheld scanners may provide point clouds without full CMM-style feature analysis workflows.
    • CMM (machine) vs. CMM (maturity model): In operations and metrology discussions, clarify which meaning is intended, especially in cross-functional IT/OT meetings.

    Link to model-based definition and tolerance stacking

    When used with model-based definition, CMMs execute inspection plans derived from 3D models and associated GD&T. Misinterpretation of datums, modifiers, or feature control frames can lead to parts that appear “in spec” according to CMM reports but are not functionally interchangeable in assemblies. This can create hidden scrap and late discovery of fit and function problems, particularly when CMM data is not tightly integrated with MES, QMS, and CAD/CAM systems.

  • supplier quality

    Supplier quality commonly refers to the level of conformance, reliability, and regulatory compliance achieved by materials, components, and services delivered by external suppliers to a manufacturing organization. It focuses on whether purchased product consistently meets specified requirements and is supported by adequate controls, documentation, and traceability.

    What supplier quality includes

    In regulated industrial and manufacturing environments, supplier quality typically covers:

    • Qualification and onboarding of suppliers, including evaluation, audits, and approval against defined criteria.
    • Incoming quality control, such as receiving inspection, sampling, test verification, and documentation checks.
    • Ongoing performance monitoring, including defect rates, on-time delivery, responsiveness, and adherence to specifications.
    • Nonconformance management, including recording, investigating, and trending supplier-related defects or deviations.
    • Corrective and preventive actions (CAPA) raised to suppliers, with evidence that systemic issues are identified and addressed.
    • Compliance and documentation, such as certificates of analysis, material certifications, traceability records, and adherence to contractual and regulatory requirements.
    • Change control coordination, ensuring supplier process or design changes are evaluated, approved, and documented before implementation.

    Operational meaning in manufacturing systems

    Operationally, supplier quality shows up across multiple systems and workflows:

    • In ERP/MRP, through approved supplier lists, quality status of lots, and blocked or restricted suppliers.
    • In MES and shop-floor systems, via holds or additional inspections for certain suppliers or materials.
    • In quality management systems, as supplier audits, SCARs (supplier corrective action requests), CAPA records, and risk assessments.
    • In compliance and traceability records, linking final product to specific supplier batches, certificates, and change notices.

    Supplier quality management

    Supplier quality management is the systematic approach an organization uses to plan, control, and improve supplier quality. It often includes:

    • Defining requirements and quality agreements with suppliers.
    • Using risk-based criteria to determine audit frequency, inspection levels, and monitoring intensity.
    • Escalation paths for repeated or severe supplier nonconformances, including enhanced controls, formal supplier CAPA, or disqualification decisions.
    • Periodic review of supplier performance metrics and risk profiles.

    Common confusion

    • Supplier quality vs. procurement: Procurement focuses on sourcing, cost, and contracts. Supplier quality focuses on conformance, reliability, and compliance of what is supplied.
    • Supplier quality vs. incoming inspection: Incoming inspection is one operational control within a broader supplier quality program, which also covers qualification, audits, CAPA, and performance monitoring.
    • Supplier quality vs. overall product quality: Supplier quality is one contributor to overall product quality, alongside internal process controls, design, and production practices.

    Link to repeat nonconformances

    In the context of repeat nonconformances from the same supplier, supplier quality involves structured evaluation of whether issues stem from isolated events or systemic causes at the supplier. This typically leads to decisions about containment actions, formal supplier CAPA, adjustments to incoming inspection or process controls, and, if needed, reassessment of the supplier’s approved status.

  • Preventive Action

    Preventive action commonly refers to a structured activity taken to remove the causes of potential nonconformities, failures, or other unwanted situations before they occur. In industrial and regulated manufacturing environments, it is part of a formal quality and risk management approach that focuses on identifying and controlling risks proactively, not just reacting to issues after they happen.

    What preventive action includes

    In operations and quality systems, preventive action typically includes:

    • Systematically identifying potential failure modes, nonconformities, or compliance gaps (for example via risk assessments, FMEA, trend analysis, or audits)
    • Evaluating likelihood and potential impact on product quality, safety, delivery, data integrity, or regulatory compliance
    • Planning and implementing measures to remove or reduce the underlying causes (such as process redesign, control improvements, training, or automation)
    • Documenting rationale, actions, responsibilities, and effectiveness checks within the quality or risk management system
    • Reviewing the results and updating procedures, specifications, and digital systems (MES, ERP, LIMS, QMS) accordingly

    Preventive actions can be technical (e.g., adding in-process sensors), procedural (e.g., updating a work instruction), or organizational (e.g., role clarification, training schedules). They are usually driven by analysis of data and risks rather than by a specific defect or deviation that has already occurred.

    Operational use in manufacturing systems

    In integrated OT/IT and quality environments, preventive actions often appear as records or tasks in a QMS, CAPA, or risk management module that link to:

    • Risk registers or assessments for specific products, processes, or equipment
    • MES master data or routing changes to reduce process variability
    • ERP or planning changes that address known supply or capacity risks
    • Document control workflows to update SOPs, work instructions, or specifications
    • Training records to ensure personnel are qualified on new or revised controls

    Although some organizations group preventive actions under a combined CAPA process, preventive actions remain conceptually distinct because they are initiated by potential or emerging issues instead of confirmed nonconformities.

    Common confusion

    • Preventive action vs. corrective action: Corrective action addresses the cause of a problem that has already occurred. Preventive action targets the cause of a potential problem that has not yet occurred.
    • Preventive action vs. detection activity: Inspections and tests detect problems but do not by themselves remove the cause. Preventive actions are changes or controls intended to avoid the problem in the first place.
    • Preventive action vs. maintenance: Preventive maintenance is a specific type of preventive activity focused on equipment health. Preventive action is broader and can apply to processes, documentation, training, data flows, suppliers, and systems.

    Relationship to standards and quality systems

    Preventive action is widely referenced in quality and risk management frameworks. Many management system standards describe the need to address risks and opportunities proactively, often implemented via formal preventive action processes, integration with CAPA workflows, and linkage to manufacturing systems such as MES and ERP.

  • Material Review Board (MRB)

    A Material Review Board (MRB) is a formal, cross-functional body and process used in manufacturing to evaluate nonconforming materials or products and decide what should happen to them. MRB activity typically covers items that do not meet specifications, drawings, or requirements discovered during inspection, testing, or production.

    What a Material Review Board includes

    An MRB commonly includes representatives from functions such as:

    • Quality or quality engineering
    • Manufacturing or operations
    • Design or product engineering
    • Supply chain or procurement (for purchased parts)
    • Regulatory or compliance, when required

    In many plants, MRB is both:

    • A governance body that is authorized to decide how to handle nonconformances.
    • A defined workflow for logging, evaluating, approving, and closing dispositions in systems such as MES, QMS, or ERP.

    Typical MRB responsibilities

    Within industrial and regulated environments, MRB commonly:

    • Receives and reviews nonconformance records, hold tags, or quality notifications.
    • Assesses the severity and risk of the nonconformance, including potential impact on safety, performance, and compliance.
    • Determines and documents disposition decisions, such as:
    • Use as is (if still acceptable within defined criteria)
    • Rework to meet specification
    • Repair under defined limits and controls
    • Scrap or destroy
    • Return to supplier
    • Ensures appropriate approvals are captured according to procedures and regulations.
    • Triggers follow-up actions, such as corrective and preventive actions (CAPA) or design and process changes, when patterns are identified.
    • Verifies that dispositions are executed and closed in the relevant systems.

    Operational meaning in manufacturing systems

    From a systems and operations perspective, MRB is visible as a controlled workflow across OT and IT systems. Nonconforming units or lots are often placed on physical and system hold, then routed through MRB steps in systems like:

    • MES, for tracking affected units, routing, and rework instructions.
    • QMS, for nonconformance records, risk assessment, and approvals.
    • ERP, for material status, inventory value adjustments, and supplier interactions.

    MRB cycle time (the time from detection of a nonconformance to final disposition and release or removal of material) is frequently monitored as an indicator of operational health, inventory quality, and schedule risk.

    Scope and limits

    MRB typically focuses on:

    • Nonconforming raw materials, components, work in process (WIP), and finished goods.
    • Items where a deviation from requirements needs formal, documented decision and authorization.

    MRB does not usually cover:

    • Routine process adjustments that stay within established control limits.
    • Minor issues that can be corrected at the workstation following existing work instructions without formal disposition.

    Common confusion

    • MRB vs. nonconformance reporting: A nonconformance report records that something is out of specification. MRB is the structured evaluation and disposition process that follows, often using that report as input.
    • MRB vs. CAPA: MRB decides what to do with specific affected material. CAPA focuses on eliminating the underlying causes of recurring nonconformances. MRB outcomes may feed into CAPA, but they are not the same process.

    Link to the provided context

    In the referenced context, MRB is discussed in terms of cycle time. In that usage, the focus is on how quickly and consistently a plant detects, evaluates, and disposes of nonconformances through the MRB process, and how delays can create hidden work in process, schedule uncertainty, and compliance exposure.

  • nonconformity

    A nonconformity is a documented situation where a product, process, service, or management system does not meet a defined requirement. In industrial and regulated manufacturing environments, those requirements usually come from standards (such as ISO 9001 or AS9100), internal procedures, customer specifications, engineering documents, or regulatory obligations.

    Nonconformity is typically identified through inspections, in-process checks, testing, audits, or system monitoring. Each nonconformity is recorded and evaluated so that the organization can decide how to address the immediate issue and whether longer-term corrective or preventive actions are needed.

    What a nonconformity includes

    In an operational and quality management context, nonconformity commonly refers to:

    • Product characteristics outside specified limits (for example, a dimension out of tolerance or an incorrect material lot)
    • Process deviations (for example, a step skipped in a work instruction or an unauthorized process change)
    • System or QMS gaps (for example, missing required records, uncontrolled documents, or incomplete training against a procedure)
    • Supplier issues (for example, received parts that do not match purchase order or drawing requirements)

    Nonconformities can be classified in different ways, such as major or minor, based on their potential impact on safety, compliance, or fitness for use.

    What a nonconformity is not

    • It is not necessarily a defect in the customer-delivered product, although product defects are one type of nonconformity.
    • It is not the same as the root cause. The nonconformity describes what requirement was not met; root cause analysis explains why it occurred.
    • It is not, by itself, a corrective action. Corrective and preventive actions are follow-up activities taken in response to a nonconformity or risk.

    Operational use in manufacturing systems

    In manufacturing, nonconformities are usually tracked within quality systems, MES, ERP, or dedicated nonconformance management tools. Common elements include:

    • Reference to the violated requirement (standard clause, specification, drawing, or procedure)
    • Description of the issue and objective evidence (measurements, photos, records, system logs)
    • Classification and risk or severity assessment
    • Disposition decision (for example, rework, use-as-is under concession, scrap, return to supplier)
    • Links to corrective and preventive action (CAPA) records if a systemic issue is suspected

    In standards-based QMS environments, such as those aligned with ISO 9001 or AS9100, nonconformities can apply to both operational processes and the management system itself. For example, an internal audit might raise a nonconformity when a documented procedure is not followed or when required records are missing or incomplete.

    Common confusion

    • Nonconformity vs. noncompliance: “Nonconformity” is typically used in quality and QMS contexts to mean not meeting a specified requirement, which may be internal, customer, or standard-based. “Noncompliance” often refers more specifically to not meeting a legal or regulatory requirement. In practice, the terms are sometimes used interchangeably, but they may carry different implications in regulated industries.
    • Nonconformity vs. defect: A defect usually refers to a product that does not meet fitness-for-use or customer expectations. A nonconformity is broader and also covers process and system issues that may not yet have produced a defective item.

    Relation to aerospace and AS9100

    In aerospace and other highly regulated sectors, AS9100 and similar standards use the concept of nonconformity to structure how organizations identify, document, and control deviations from requirements. This typically includes controls for nonconforming product, requirements for documenting nonconformities found in audits, and expectations for linking significant or repeated nonconformities to formal corrective action processes.

  • AS 9100

    AS 9100 is a widely used quality management system (QMS) standard for organizations that design, develop, or produce products and services for the aviation, space, and defense sectors. It is based on ISO 9001 and adds aerospace-specific requirements related to safety, reliability, risk management, configuration control, and product traceability.

    What AS 9100 includes

    AS 9100 typically covers:

    • A documented quality management system aligned with ISO 9001 requirements
    • Controls for design and development of aerospace products and services
    • Process control for production and service provision, including special processes
    • Configuration management and change control for complex products and systems
    • Risk management and product safety considerations throughout the lifecycle
    • Requirements for supplier evaluation, control, and flowdown of requirements
    • Identification, traceability, and records retention for components and materials
    • Nonconforming product control, corrective action, and continual improvement

    In industrial operations, AS 9100 requirements often influence how MES, ERP, document control, and quality systems are configured. For example, traceability, revision control, and evidence of process verification may be implemented through integrated OT/IT workflows.

    How AS 9100 is used in manufacturing

    In regulated aerospace manufacturing environments, AS 9100 commonly serves as the reference framework for:

    • Defining and maintaining documented processes for production and inspection
    • Aligning quality plans, work instructions, and routing data across MES and ERP
    • Capturing and retaining production records and inspection data as quality evidence
    • Managing engineering changes, deviations, and concessions in a controlled way
    • Coordinating supplier quality requirements and incoming inspection processes

    Many aerospace manufacturers use AS 9100 as part of a broader stack of standards (such as core ISO standards and sector-specific guidelines) to structure quality, risk, and documentation practices.

    Common confusion

    • AS 9100 vs ISO 9001: ISO 9001 is a generic QMS standard for any industry. AS 9100 incorporates ISO 9001 and adds aerospace-specific requirements. It is not a separate or unrelated standard.
    • AS 9100 vs AS 9110 / AS 9120: AS 9100 generally applies to organizations involved in design and production. AS 9110 focuses on maintenance and repair organizations, and AS 9120 focuses on distributors. All are related aerospace sector QMS standards.

    Relation to ISO standards for manufacturing

    AS 9100 is not an ISO standard itself but is built on the ISO 9001 framework. In aerospace manufacturing, it is often implemented alongside other ISO and sector standards that address topics such as measurement management, documentation control, and risk management. Selection and scope depend on the organization's role in the aerospace supply chain and product risk profile.

  • nonconforming outputs

    Nonconforming outputs are products, services, or process results that do not meet specified requirements. In industrial and regulated manufacturing environments, the term commonly refers to any output from a process that fails to conform to customer, regulatory, engineering, or internal specification criteria.

    Nonconforming outputs can occur at any stage of the value stream, including incoming material inspection, in-process operations, final inspection and test, and post-delivery service or repairs.

    What nonconforming outputs include

    In a manufacturing and quality management context, nonconforming outputs commonly include:

    • Physical product that fails dimensional, functional, cosmetic, or performance requirements
    • Assemblies or subassemblies built with incorrect or unapproved parts or configurations
    • Documentation or records that do not meet required content, completeness, or revision status
    • Process outcomes that do not meet defined parameters or control limits, when those are treated as formal requirements
    • Services or field work that do not meet agreed work scope, technical requirements, or acceptance criteria

    Nonconforming outputs are not limited to scrap. They also include items that may later be reworked, repaired, used as-is under concession, or regraded for a different application, provided this is formally evaluated and authorized.

    How nonconforming outputs are controlled

    Quality management systems typically require that nonconforming outputs be:

    • Identified and documented with clear description of the nonconformance, applicable requirements, and traceability data
    • Segregated or otherwise controlled to prevent unintended use, processing, or delivery
    • Evaluated and dispositioned (for example: scrap, rework, repair, return to supplier, use-as-is under deviation, or regrade)
    • Approved by authorized personnel according to defined roles, including customer or regulatory approval when required
    • Recorded so data can be used for trend analysis, risk assessment, and potential corrective action

    Operationally, nonconforming outputs are often managed through nonconformance reports (NCRs) or similar records in MES, QMS, ERP, or PLM systems. These records link the nonconformance to affected batches, serial numbers, lots, work orders, and suppliers to maintain traceability.

    Relationship to standards and regulated environments

    Quality and aerospace standards such as ISO 9001 and AS9100 use the term “nonconforming outputs” to describe items that must be identified and controlled when they do not meet requirements. Control of nonconforming outputs is typically associated with clauses on product realization, control of nonconformity, and corrective action, and it interacts with related topics such as configuration management, risk management, and traceability.

    Common confusion

    • Nonconforming outputs vs. nonconformities in the QMS: Nonconforming outputs are failures to meet product, service, or process output requirements. QMS nonconformities are failures of the management system itself (for example a missing procedure). One may lead to the other, but they are not the same.
    • Nonconforming outputs vs. defects: “Defect” is often used informally for any failure. “Nonconforming output” is a formal term in many standards and includes all outputs that do not meet specified requirements, whether or not they are visible defects.
    • Nonconforming outputs vs. scrap: Scrap is one possible disposition of a nonconforming output. A nonconforming output is not automatically scrap until formally dispositioned as such.

    Link to the source context

    In the context of AS9100 and similar aerospace requirements, nonconforming outputs are controlled under specific clauses on nonconformance control. Effective control usually involves additional clauses, such as those related to risk, configuration management, supplier control, and corrective action, but the core concept remains any product or process result that does not meet specified requirements and must be formally managed.