RSC Sphere: Quality, Compliance and Traceability

The Quality, Compliance and Traceability Sphere demonstrates how audit-grade credibility is built directly into execution workflows. It connects nonconformance, corrective action, inspection, traceability, and audit evidence into a continuous operational loop. The content emphasizes how quality systems must interact with live work rather than exist as parallel documentation processes. This sphere proves that compliance and execution can reinforce each other instead of competing for attention.

  • MRB (Material Review Board)

    Core meaning

    MRB (Material Review Board) is a cross-functional group formally assigned to review, assess, and disposition nonconforming material, components, or finished products. It operates under defined procedures to decide what happens to material that does not meet specified requirements.

    In industrial and regulated manufacturing environments, the MRB commonly includes representatives from quality, engineering, production, and sometimes supply chain or regulatory/compliance functions.

    Typical responsibilities

    An MRB process commonly includes:

    – **Reviewing nonconformances**: Evaluating nonconforming material identified through inspections, in-process checks, or customer returns.
    – **Root cause input**: Providing technical and quality perspectives to support or trigger root cause analysis by appropriate teams.
    – **Disposition decisions**: Assigning an allowed path forward for the material, such as:
    – Use as is (with justification and documentation)
    – Rework or repair
    – Regrade or downgrade
    – Scrap or destroy
    – Return to supplier
    – **Risk and compliance assessment**: Considering safety, reliability, regulatory, and contract requirements before disposition.
    – **Documentation**: Ensuring that decisions and justifications are documented in the applicable quality or manufacturing systems.

    How MRB is used in manufacturing workflows

    In many plants, MRB activity is integrated into quality and production workflows as follows:

    – Nonconforming material is **quarantined** or placed on **hold** (often in an MES, QMS, or ERP system) and physically moved to a designated area.
    – A **nonconformance record** is created, including defect description, lot or batch data, and inspection results.
    – The MRB team reviews the record, may request additional tests or inspections, and then records a **disposition** in the system.
    – The chosen disposition drives **subsequent system actions**, such as:
    – Updating inventory status
    – Generating rework orders
    – Triggering supplier corrective actions
    – Linking to CAPA or other corrective action processes

    In regulated industries (e.g., pharmaceuticals, medical devices, aerospace), MRB decisions are typically subject to strict documentation, traceability, and retention requirements.

    Boundaries and what MRB is not

    – **Not the same as general quality control**: MRB is a specific, formal decision process for nonconforming material, not all routine inspections or tests.
    – **Not always a standing physical committee**: In some organizations, MRB is a virtual or workflow-defined role set, but the function is still recognized as “the MRB.”
    – **Not a full root cause investigation process**: MRB may initiate or request investigations, but detailed root cause analysis and CAPA activities are usually managed through separate processes.

    Common variations and terminology

    Terms and structures that are closely related include:

    – **Material Review**: The process or activity; MRB is the governing body or function.
    – **MRB disposition**: The documented outcome (e.g., scrap, rework) resulting from the MRB review.
    – **Nonconforming material review**: Sometimes used interchangeably with MRB activity.

    Some organizations use MRB for **both incoming and in-process material**, while others maintain separate boards or processes (e.g., Supplier MRB vs. internal MRB).

    Relation to quality and risk management

    MRB is a key control point in quality management systems because it:

    – Provides a structured path to prevent unintended use of nonconforming material.
    – Links inspection and deviation records to downstream actions like rework orders or supplier feedback.
    – Supports traceability and auditability of how nonconformances were handled.

    It often interfaces with:

    – **QMS**: For nonconformance, deviation, and CAPA records.
    – **MES/ERP**: For inventory status, work order updates, and material traceability.
    – **Risk management processes**: For assessing potential impact on product performance, safety, or compliance when deciding to use as is, rework, or scrap.

    Common confusion and misuse

    – **MRB vs. NCR (Nonconformance Report)**: The NCR is the record describing the issue. The MRB is the body or function that reviews the nonconforming item and decides the disposition recorded on that NCR.
    – **MRB vs. CAPA**: MRB focuses on the immediate handling of the nonconforming material. CAPA addresses systemic causes and long-term corrective and preventive actions.
    – **MRB vs. Material Review Board in non-manufacturing contexts**: In some non-industrial settings, “material review” might mean document or content review. In manufacturing and industrial operations, MRB almost always refers to nonconforming physical materials or products.

  • Concession

    Operational meaning

    In industrial and regulated manufacturing, **concession** commonly refers to a formal authorization to:

    – Accept and use nonconforming product, material, or component, or
    – Depart from specified requirements (e.g., drawings, specifications, procedures)

    under clearly defined conditions, usually for a limited quantity, time period, customer, or batch.

    A concession is normally based on an assessment that the nonconformity or deviation does not invalidate the intended function, safety, or regulatory requirements of the product or process, as judged by competent technical and quality authorities and, when required, by the customer.

    How concessions are used in manufacturing workflows

    In practice, a concession may be:

    – **Requested** when inspection or in-process checks detect a deviation from requirements and scrap or full rework is not considered necessary or feasible.
    – **Evaluated** by engineering, quality, and sometimes regulatory functions to determine impact on form, fit, function, safety, and compliance.
    – **Authorized** by defined roles (e.g., quality manager, design authority, customer quality representative) before the affected items move to the next process step or to shipment.
    – **Recorded** in quality systems, MES, or ERP as part of nonconformance and deviation management, often linked to specific lots, serial numbers, or work orders.
    – **Communicated** to downstream users and customers, sometimes via documented waivers, deviations, or customer approvals.

    In MES or ERP systems, concessions are often captured as:

    – A specific **nonconformance disposition** (e.g., “use-as-is with concession”), or
    – A **deviation record** tied to particular orders, material IDs, or configurations.

    Boundaries and what it is not

    A concession:

    – **Is** a controlled, documented exception to product or process requirements.
    – **Is usually temporary** or limited in scope (per batch, serial range, or time-bound).
    – **Is applied after** a deviation is known (reactive authorization for specific occurrences).

    A concession **is not**:

    – A permanent change to the specification, drawing, or process (that would be a design or process change, engineering change order, or specification revision).
    – A generic risk acceptance document unlinked to specific product or batch.
    – An informal verbal agreement without traceable documentation.
    – The same as routine tolerance variation that is already allowed by the specification.

    Common related terms and confusion

    The term **concession** is often confused or used interchangeably with:

    – **Deviation permit / production permit**: Frequently used for prior authorization to depart from requirements before production or before the nonconformity occurs. A concession is more commonly used when the nonconformity already exists, though some organizations treat the terms as equivalent.
    – **Waiver**: In some sectors, a waiver is used similarly to a concession (customer-approved acceptance of nonconforming product). Other organizations reserve “concession” for internal approval and “waiver” for customer approval.
    – **Nonconformance report (NCR)**: An NCR documents the nonconformity; a concession is one possible outcome (disposition) of that NCR (e.g., scrap, rework, regrade, or use-as-is under concession).

    When precision is needed, it is helpful to clarify whether “concession” means:

    – Acceptance of already-produced nonconforming items, or
    – A pre-approved deviation from requirements for upcoming production.

    Use in regulated and quality-managed environments

    In regulated industries and quality-managed environments (e.g., aerospace, pharmaceutical, medical devices, automotive, food and beverage), concessions are:

    – Managed through documented **nonconformance and deviation control processes**.
    – Subject to defined approval authorities and, where applicable, **customer or regulatory notification or approval** requirements.
    – Tracked for **traceability** to affected product, lots, and batches, supporting audits, recalls, or investigations.

    Quality systems may require that concessions be:

    – Linked to risk assessments, impact analyses, or technical justifications.
    – Reviewed periodically to identify recurring patterns that may warrant design or process changes instead of repeated concessions.

    Site context application

    Within the context of industrial operations, OT/IT integration, and MES/ERP environments, **concession** typically appears as:

    – A **disposition code** or record type for nonconforming material or in-process product.
    – A structured **workflow** that routes nonconformance records for evaluation and approval.
    – A data element used for **quality reporting**, trend analysis, and compliance evidence.

    Concession records in these systems provide traceable documentation that specific nonconforming or deviating products or processes were reviewed and deliberately accepted under controlled conditions.

  • escape

    In industrial quality and nonconformance management, an escape commonly refers to a defect or nonconforming condition that passes through defined inspection or process controls and is only detected at a later stage in the value stream, or by the end customer.

    Core meaning in manufacturing and regulated environments

    An escape is a failure of the quality system to detect a nonconformance at the point where it should reasonably have been identified and contained. The key aspect is that the nonconformance moves beyond its intended control boundary.

    Typical cases include:

    • Nonconforming parts that move from one manufacturing operation to the next without detection
    • Defective assemblies that pass final inspection and reach an OEM, integrator, or end customer
    • Documentation errors, missing certifications, or incorrect configuration that are discovered after shipment or installation

    Operational usage

    In operations, escapes are usually tracked and analyzed as part of nonconformance and corrective action processes. Common uses include:

    • Escape rate: a KPI expressing the number of escaped defects relative to total units produced, shipped, or inspected.
    • Escape classification: categorizing escapes by severity, safety impact, or where in the process the defect should have been detected.
    • Root cause analysis: investigating why existing controls, inspections, or test coverage did not prevent or detect the nonconformance.
    • Containment and recall: identifying lots, serial numbers, or configurations that may have escaped and initiating reinspection, rework, or field actions.

    Escapes are often distinguished from internal nonconformances that are detected and contained before the product leaves a work center, plant, or organization.

    Common confusion

    • Escape vs. defect: a defect is any departure from requirements; an escape is specifically a defect that passes beyond its intended control point.
    • Escape vs. rework: rework can happen for defects caught internally and on time; escapes highlight a breakdown in detection, which may or may not later require rework or repair.
    • Escape vs. field failure: not all field failures are due to escapes (some are due to wear-out or misuse), but quality-related field failures often indicate an earlier escape.

    Context: nonconformance KPIs

    In KPI discussions, especially in sectors such as aerospace, the term escape rate is frequently used as a measure of nonconformance management effectiveness. Lower and stable escape rates suggest that inspection plans, process controls, and documentation checks are detecting issues before they move to downstream operations or customers.

  • Effectiveness Verification

    Effectiveness verification is the documented evaluation of whether a corrective or preventive action has achieved its intended result and sustainably addressed the original problem or nonconformity. It is a distinct step after implementation of actions, focused on confirming outcomes rather than re-checking completion of tasks.

    What effectiveness verification includes

    In regulated and manufacturing environments, effectiveness verification commonly involves:

    • Defining clear, measurable success criteria when planning the action (for example, defect rate thresholds, audit findings, or downtime levels)
    • Allowing a defined period of operation after implementation so that data can be collected
    • Reviewing objective evidence such as production data, quality metrics, deviations, complaints, or audit results
    • Documenting whether criteria were met, partially met, or not met
    • Escalating to additional root cause analysis or follow up actions if the change is not effective

    Effectiveness verification is usually tied to CAPA, deviation management, change control, or process improvement workflows within QMS, MES, or related systems.

    What effectiveness verification is not

    • It is not just confirming that tasks are completed or that documents are updated.
    • It is not a one-time sign-off immediately after implementation with no operating history.
    • It is not the same as ongoing process monitoring, although monitoring data is often used as evidence.

    Operational use in manufacturing systems

    Within digital systems, effectiveness verification may appear as a required step or status in CAPA records, deviations, nonconformance reports, or change requests. Typical elements include:

    • A responsible owner for the verification
    • A planned verification date or time window
    • Linked data sources such as batch records, SPC charts, downtime logs, or inspection results
    • A documented conclusion and justification, often with attachments or references

    Some organizations require independent review of the verification to reduce bias, especially in highly regulated environments.

    Common confusion

    • Verification vs. validation: Effectiveness verification checks that a specific corrective or preventive action worked as intended in operation. Process validation evaluates whether a process, system, or method can consistently produce results meeting requirements.
    • Closure vs. effectiveness: Marking a CAPA or deviation as “implemented” or “closed” only confirms completion of planned activities. Effectiveness verification confirms the impact on the underlying issue.

    Relation to quality and risk management

    Effectiveness verification is a common requirement in quality management frameworks and risk-based approaches. It helps demonstrate that identified risks, nonconformities, or root causes are not only addressed administratively but are also controlled in practice, based on evidence from actual operations.

  • Risk-Based Sampling

    Risk-based sampling is an inspection and testing approach in which the size, frequency, and rigor of sampling are determined by the assessed level of risk associated with a product, process, supplier, or batch. Instead of applying a uniform sampling plan to all situations, organizations adjust how much they sample based on factors such as criticality, historical performance, process capability, and potential impact on safety, quality, or compliance.

    Key characteristics

    In industrial and regulated manufacturing environments, risk-based sampling commonly includes:

    • Risk assessment as a driver: Sampling plans are informed by formal or semi-formal risk assessments (for example using severity, occurrence, and detectability) rather than only by fixed AQL tables.
    • Variable sample sizes: Higher-risk items (such as safety-critical features, new processes, or high-defect suppliers) receive larger sample sizes or 100% inspection, while lower-risk items may be sampled at reduced rates.
    • Dynamic adjustment: Sampling intensity can be increased or decreased over time based on nonconformance trends, process capability, audit findings, or changes in design or process.
    • Integration with quality systems: The approach is often documented within quality plans, control plans, supplier quality requirements, or inspection plans in MES/QMS systems.
    • Focus on critical characteristics: Particular emphasis is placed on critical-to-quality or safety-related characteristics, which may be sampled more heavily than non-critical features in the same lot.

    Operational usage in manufacturing

    Operationally, risk-based sampling shows up in:

    • Incoming inspection: Adjusting sampling levels per supplier, part family, or risk classification, often linked to supplier scorecards and historical defect data.
    • In-process checks: Setting higher sampling frequencies at process steps with higher failure risk, new tooling, or recent changes, and lower frequencies on stable, capable operations.
    • Final inspection and release: Applying enhanced sampling for high-criticality assemblies, new product introductions, or parts with recent nonconformances.
    • Electronic systems: Encoding different sampling rules in MES, LIMS, or SPC systems so that inspection plans are automatically adjusted based on part, process, or supplier risk attributes.

    What risk-based sampling is not

    • It is not the same as simple random sampling without regard to risk.
    • It is not a guarantee of compliance to any specific standard, although some standards and guidance documents encourage risk-based thinking.
    • It does not remove the need for documented rationale; sampling decisions are typically supported by written risk assessments and quality procedures.

    Common confusion

    • Risk-based sampling vs. AQL sampling: AQL (Acceptance Quality Limit) sampling uses predefined statistical plans based mainly on lot size and acceptable defect rates. Risk-based sampling may use AQL tables as inputs, but adjusts them according to risk factors such as criticality, process history, and supplier performance.
    • Risk-based sampling vs. 100% inspection: For very high-risk situations, a risk-based approach may justify 100% inspection, but risk-based sampling also supports reduced sampling where risk is demonstrably lower.

    Relation to risk and quality management

    Risk-based sampling is typically part of a broader risk and quality management strategy. It supports prioritization of inspection resources toward areas with higher potential impact on product quality, regulatory compliance, or customer requirements. In regulated sectors, documented risk-based sampling rationales are often referenced during audits or inspections to show how inspection controls are aligned with identified risks.

  • CAPA (Corrective and Preventive Action)

    CAPA (Corrective and Preventive Action) is a structured quality management process used to identify, investigate, and address actual or potential problems in products, processes, or systems. In regulated manufacturing environments, CAPA is a central element of the quality management system and is typically documented, risk-based, and traceable.

    Corrective action vs. preventive action

    Although often discussed together, corrective and preventive actions address different situations:

    • Corrective action focuses on problems that have already occurred, such as nonconforming product, repeated process failures, or audit findings. It targets both fixing the immediate issue and eliminating its root cause to prevent recurrence.
    • Preventive action focuses on potential problems that have not yet occurred but are identified through risk assessments, trend analysis, near-miss events, or process monitoring. It aims to reduce the likelihood of future issues.

    Typical CAPA workflow in manufacturing

    In industrial and regulated environments, a CAPA process commonly includes:

    • Initiation: Logging a CAPA record in a QMS, MES, or other quality system, often triggered by nonconformances, complaints, audit findings, deviations, or process trends.
    • Containment / immediate actions: Short-term steps to control or limit impact (for example, blocking suspect lots, issuing rework instructions, or updating inspection frequency).
    • Investigation and root cause analysis: Structured analysis to understand what happened or could happen and why, often using tools such as 5 Whys, fishbone diagrams, or 8D / RCCA methods.
    • Action planning: Defining specific corrective and/or preventive actions, owners, due dates, and required approvals.
    • Implementation: Executing changes, which may include updated work instructions, process parameters, training, supplier changes, or system configuration updates.
    • Effectiveness check: Verifying that actions removed or reduced the issue or risk, typically by monitoring quality metrics, audits, or subsequent nonconformance data.
    • Documentation and closure: Final review, documenting evidence and approvals, and formally closing the CAPA record for future traceability and audits.

    CAPA in systems and data flows

    In modern operations, CAPA records often integrate with other systems:

    • QMS: Holds the primary CAPA records, workflows, and approvals.
    • MES / shop-floor systems: Provide source data such as nonconformance reports, process parameters, and genealogy, and enforce updated process controls or work instructions.
    • ERP: Connects CAPA-related decisions to inventory, cost tracking, and supplier actions.
    • Document control: Manages revisions to procedures, work instructions, and forms resulting from CAPA actions.

    What CAPA includes and excludes

    CAPA typically includes:

    • Systematic handling of significant quality or process issues.
    • Documented root cause analysis and risk assessment.
    • Changes to processes, documentation, training, and controls.

    CAPA typically does not include:

    • Routine day-to-day adjustments that do not address a defined problem or risk.
    • Isolated corrections without analysis of underlying causes or systemic impact.

    Common confusion

    • CAPA vs. correction: A correction fixes an immediate defect (for example, reworking a part). CAPA goes further by addressing why the defect occurred and how to prevent it or reduce its likelihood.
    • CAPA vs. NCR: A nonconformance report (NCR) documents an out-of-spec condition. A CAPA may be opened as a result of one or more NCRs when the issue is systemic, recurring, or high risk.
    • CAPA vs. continuous improvement: Continuous improvement can include many small, proactive changes. CAPA is a formal, traceable process typically reserved for issues with compliance, safety, or significant quality impact.
  • AS9110

    AS9110 is an aerospace quality management system (QMS) standard specifically tailored for organizations that perform maintenance, repair, and overhaul (MRO) services for aviation products. It adapts and extends ISO 9001 and the aerospace-focused AS9100 requirements to address risks and controls unique to maintenance environments, such as configuration control of repaired items, component traceability, and release-to-service processes.

    The standard commonly applies to organizations that maintain, repair, or overhaul aircraft, aircraft components, and related equipment. In industrial operations, it influences how work instructions, documentation, inspection records, and service histories are controlled and how digital systems such as MES, ERP, and maintenance management systems are configured to support quality and regulatory expectations.

    Scope and key characteristics

    AS9110 typically includes requirements related to:

    • Establishing and maintaining a documented quality management system for maintenance activities
    • Managing work orders, maintenance data, and technical publications
    • Controlling configuration, parts, and materials used in repairs and overhauls
    • Ensuring personnel competence and authorization for maintenance tasks
    • Managing inspection, testing, and release-to-service documentation
    • Handling nonconforming items, rework, and corrective actions
    • Maintaining traceability for safety-critical and regulated components

    In regulated aerospace environments, AS9110 requirements often drive how electronic records, approvals, and audit trails are implemented, and how maintenance organizations interface with customers, regulators, and OEMs.

    Common confusion

    • AS9110 vs AS9100: AS9100 is a general aerospace QMS standard for design and manufacturing organizations. AS9110 focuses on maintenance and overhaul organizations and includes additional requirements specific to MRO activities.
    • AS9110 vs AS9120: AS9120 is oriented toward aerospace stockist and distributor organizations. AS9110 is for organizations performing maintenance, repair, and overhaul work.

    Context in aerospace manufacturing and operations

    Within the wider aerospace quality landscape, AS9110 commonly appears alongside AS9100 and AS9120 as part of a family of standards for aviation, space, and defense. While adoption itself is voluntary, compliance with AS9110-based requirements may be embedded in contracts or customer quality clauses. Operational systems on the shop floor and in maintenance facilities are often configured to support AS9110-aligned processes for documentation, traceability, and quality records management.