RSC Sphere: Quality, Compliance and Traceability

The Quality, Compliance and Traceability Sphere demonstrates how audit-grade credibility is built directly into execution workflows. It connects nonconformance, corrective action, inspection, traceability, and audit evidence into a continuous operational loop. The content emphasizes how quality systems must interact with live work rather than exist as parallel documentation processes. This sphere proves that compliance and execution can reinforce each other instead of competing for attention.

  • AS9120

    AS9120 is an aerospace quality management system (QMS) standard specifically developed for stockist and distributor organizations that supply parts, materials, and assemblies to the aviation, space, and defense sectors. It tailors general quality management requirements to the needs of organizations that purchase, store, repackage, and distribute aerospace products, rather than design or build them.

    What AS9120 includes

    AS9120 is based on ISO 9001 and adds aerospace-specific requirements that typically address:

    • Control of purchased product, including verification of supplier quality and flowdown of aerospace requirements
    • Traceability and recordkeeping for parts, lots, and materials through the distribution chain
    • Control and prevention of counterfeit, suspect, or unapproved parts entering the supply chain
    • Handling, storage, packaging, preservation, and delivery of aerospace products
    • Documentation control, including certificates of conformity and airworthiness-related documents
    • Customer and regulatory requirements relevant to distributors (for example, shelf life, special storage conditions)

    AS9120 is typically implemented alongside other operational and information systems used by distributors, such as ERP, warehouse management systems, document control systems, and supplier quality management tools.

    Where AS9120 applies in industrial operations

    AS9120 commonly applies to:

    • Independent distributors and stockists supplying aerospace OEMs, MROs, and tiered suppliers
    • Internal distribution centers within larger aerospace manufacturers
    • Organizations that do not significantly modify products, but may perform activities such as kitting, repackaging, or labeling

    For these organizations, AS9120 shapes how quality processes are embedded in day-to-day operations, for example:

    • Supplier approval and monitoring workflows in ERP or supplier portals
    • Lot and serial traceability in inventory and warehouse systems
    • Controlled handling of nonconforming product and returns
    • Controlled issuance and retention of certificates and supporting records for audits

    Relationship to other aerospace quality standards

    AS9120 is part of the aerospace series of quality management standards, which commonly include:

    • AS9100 for organizations that design and/or manufacture aviation, space, and defense products.
    • AS9110 for organizations that perform maintenance, repair, and overhaul (MRO) of aerospace products.
    • AS9120 for stockist/distributor organizations in the aerospace supply chain.

    All three are aligned with ISO 9001 but include sector-specific requirements. They are often referenced in contracts and customer requirements, and their implementation interacts closely with quality management systems, document control, and traceability practices.

    Common confusion

    • AS9120 vs AS9100: AS9100 is generally for manufacturers and design organizations, while AS9120 focuses on distributors that do not significantly alter the product.
    • AS9120 vs ISO 9001: ISO 9001 is a generic QMS standard; AS9120 incorporates ISO 9001 and adds aerospace-specific expectations for distribution, such as enhanced traceability and counterfeit-part controls.

    Context in regulated manufacturing and supply chains

    In regulated aerospace environments, AS9120 provides a structured framework for how distributors manage quality, traceability, and documentation. It affects how data is captured in ERP or warehouse systems, how records are controlled for audit readiness, and how suppliers and customers interface around quality and compliance requirements.

  • quality assurance

    Quality assurance (QA) is the set of systematic, planned activities used to provide confidence that processes, systems, and outputs will consistently meet defined requirements. In industrial and regulated manufacturing environments, QA focuses on how work is organized, documented, and verified so that products and services are produced in a controlled and repeatable way.

    What quality assurance includes

    In manufacturing and other regulated operations, quality assurance commonly includes:

    • Defining and managing standard operating procedures (SOPs), work instructions, and specifications
    • Establishing process controls and checks within MES, ERP, LIMS, or QMS systems
    • Reviewing and approving documents, records, and changes (for example, change control workflows)
    • Ensuring training, qualification, and role-based access are defined and documented
    • Planning and overseeing internal audits, self-inspections, and periodic reviews
    • Supporting deviation handling, investigations, CAPA, and effectiveness checks
    • Monitoring quality metrics and compliance signals at process and system level

    QA activities typically operate across the product lifecycle, from design and process development through production, release, and post-market feedback. They are often coordinated by a dedicated Quality Assurance function or department, but rely on participation from operations, engineering, IT/OT, and supply chain.

    How quality assurance differs from quality control

    Quality assurance is focused on preventing issues by controlling and improving the processes and systems that produce a product. Quality control (QC), by contrast, focuses on detecting nonconformities in the product itself, usually through inspection, measurement, and testing of materials, intermediates, or finished goods.

    In practice, QA defines and governs how QC should be performed, how results are documented, and how nonconforming results trigger investigation, disposition, and corrective or preventive actions.

    Operational role in a Quality Management System

    Within a Quality Management System (QMS), quality assurance is often described as one of several core components, alongside quality planning, quality control, and quality improvement. QA activities help ensure that:

    • Processes and equipment are appropriately qualified or validated before use
    • Changes to processes, recipes, or systems are assessed and controlled
    • Electronic records, signatures, and data flows between MES, ERP, and QMS are governed
    • Released products and batches are supported by complete, traceable manufacturing and quality records

    QA also plays a central role in preparing for and supporting external inspections and audits by maintaining evidence that processes are defined, followed, and periodically reviewed.

    Common confusion

    • Quality assurance vs. quality management: Quality management is the broader system that covers policy, planning, assurance, control, and improvement. QA is one part of that system, mainly concerned with how processes and systems are defined and governed.
    • Quality assurance vs. testing: Testing is a quality control activity that evaluates specific units or lots. QA focuses on the design and oversight of the processes that make and test those units, not on individual test executions alone.

    Relation to the source context

    When a QMS is described in terms of four components (quality planning, quality control, quality assurance, and quality improvement), quality assurance is the component that ensures planned methods, procedures, and system configurations are in place and are being followed, especially across integrated MES, ERP, and QMS environments.

  • International Aerospace Quality Group

    The International Aerospace Quality Group (IAQG) is an industry association formed by major aviation, space, and defense companies and their trade associations to improve quality and reliability across the global aerospace supply chain. It focuses on harmonized quality management system (QMS) standards, guidance, and supporting materials used by organizations that design, produce, and support aerospace products and services.

    Role in aerospace quality management

    IAQG is widely known as the originating body behind the AS/EN/JISQ 9100-series standards, which extend ISO 9001 with aviation, space, and defense sector requirements. The group develops, maintains, and periodically revises:

    • AS9100-series QMS standards for aerospace organizations
    • Related quality standards for distributors, maintenance organizations, and other aerospace activities
    • Supporting guidance, deployment materials, and common documentation

    Its work is organized through regional sectors (for example, Americas, Europe, and Asia-Pacific) that coordinate on global standards while aligning with regional regulatory and industry practices.

    Relevance to manufacturing and regulated operations

    In industrial and manufacturing environments, IAQG standards are commonly used to define:

    • Requirements for quality management systems in aerospace production and assembly
    • Expectations for documentation, configuration management, and change control
    • Practices for supplier quality, risk management, and traceability across the aerospace supply chain

    Organizations that supply aerospace OEMs often structure their operational procedures, document control, and shop-floor quality processes to align with IAQG-developed standards and guidance.

    Common confusion

    IAQG is sometimes confused with the standards it develops, such as AS9100. IAQG is the industry group that coordinates and publishes the standards, while AS9100 and related documents are the quality management system requirements themselves. IAQG does not act as a certification body or regulator, and it does not issue approvals or certifications.

    Connection to AS9100 and ISO 9001

    AS9100 is an aerospace QMS standard developed under the IAQG framework. It builds on ISO 9001 by adding aviation, space, and defense-specific requirements. IAQG maintains the 9100-series so that aerospace organizations can use a common, sector-specific layer on top of general ISO 9001 quality principles.

  • Rework

    Core meaning

    Rework commonly refers to the activity of bringing a nonconforming item into conformance with defined requirements by performing additional work after an inspection, test, or use has identified a problem.

    In industrial and regulated manufacturing environments, this typically means:

    – Identifying a product, component, batch, or record that does not meet a specification
    – Performing defined additional operations (e.g., repair, reprocessing, re-testing) to correct the nonconformance
    – Verifying and documenting that the item now meets all applicable requirements

    Rework can apply to physical materials, digital records (e.g., batch records, quality documentation), and software configurations used in operations.

    Use in manufacturing workflows

    In manufacturing systems and quality processes, rework is usually handled through formal workflows:

    – **Detection:** A defect or deviation is found through in-process inspection, final inspection, automated checks, or system validations.
    – **Disposition:** The nonconforming item is evaluated and assigned a status such as rework, scrap, or use-as-is.
    – **Execution:** Rework instructions are followed (often defined in work instructions, SOPs, or MES routing steps).
    – **Verification:** The reworked item is re-inspected or re-tested to confirm that it now meets specifications.
    – **Documentation:** Rework actions, approvals, and results are recorded in MES, ERP, QMS, or electronic batch records.

    Operations and quality teams may monitor rework rates as an indicator of process stability and product quality.

    Boundaries and what rework is not

    Rework is distinct from several related activities:

    – **Not normal process steps:** The planned, standard production operations needed to create a conforming product are not considered rework.
    – **Not scrap:** Items that cannot be brought into conformance and are discarded are classified as scrap, not rework.
    – **Not regrade or concession:** Decisions to accept product outside normal specification under controlled conditions (e.g., concession or use-as-is) are different from rework because the product is not brought fully into original specification.
    – **Not routine maintenance:** Maintenance on equipment or IT/OT systems is separate from rework, unless the maintenance is specifically part of correcting a nonconforming batch or lot.

    Rework in quality and compliance contexts

    In regulated environments, rework is typically controlled through documented procedures that may cover:

    – Conditions under which rework is allowed or limited
    – Required approvals before starting rework
    – Validation or verification obligations if the rework changes critical characteristics
    – Traceability requirements (e.g., linking rework actions to specific lots, batches, or serial numbers)

    Quality management systems (QMS), MES, and ERP often include specific objects or transactions to:

    – Log nonconformances and rework orders
    – Track additional material and labor used in rework
    – Record inspection results after rework

    Common confusion and misuse

    Rework is sometimes confused with:

    – **Repair:** In many industries, repair refers to restoring functionality without necessarily meeting all original specifications, while rework implies full alignment to the original requirements. Usage, however, can vary by organization.
    – **Reprocessing:** Some sectors use reprocessing for repeating part or all of the normal manufacturing process, while using rework for more targeted corrective actions. In others, rework and reprocessing are used interchangeably. Local definitions in procedures or standards should be checked.

    In IT and data contexts, “rework” may informally refer to repeating configuration or data entry tasks due to earlier errors. In this site context, the term should be understood primarily as a controlled manufacturing and quality activity recorded in operational systems.

    Application in operations and manufacturing systems

    In OT/IT, MES, and ERP environments, rework is commonly represented by:

    – Additional operations or alternate routings in MES to handle nonconforming units
    – Rework production orders or work orders in ERP to account for cost and capacity
    – Quality notifications, deviations, or CAPA records in QMS referencing rework activities
    – Status changes in inventory management (e.g., from blocked to released after successful rework)

    Rework data is frequently analyzed for operations intelligence, including:

    – Identifying recurring process issues
    – Understanding impact on throughput and capacity
    – Supporting continuous improvement and problem-solving methods such as root cause analysis.

  • process interaction

    Process interaction commonly refers to the way individual processes within an organization influence, depend on, and exchange inputs and outputs with one another. In industrial and regulated manufacturing environments, it describes how operational, quality, engineering, supply chain, and support processes connect to form an overall system.

    What process interaction includes

    Process interaction typically covers:

    • Inputs and outputs passed between processes (for example, a sales order feeding production planning, or an in-process inspection feeding rework or release).
    • Sequence and flow of activities, such as which process must be completed before another can start.
    • Dependencies and constraints, including data, approvals, resources, and systems required for one process to operate.
    • Responsibilities and ownership at each interface, such as who reviews, approves, or records information when processes hand off work.
    • Information systems links between OT/IT, such as ERP to MES, MES to QMS, or PLM to shop-floor execution.

    In a quality management context (such as ISO 9001), organizations are expected to identify their key processes and describe how these processes interact. This can be documented in text, diagrams, flowcharts, or integrated process maps that show how work, information, and decisions move through the business.

    Operational meaning in manufacturing

    On the shop floor and in supporting functions, process interaction can be seen in:

    • Order-to-ship workflows, from quotation, order entry, and planning, through manufacturing, inspection, and shipping.
    • Engineering change flows, where design changes in PLM affect routings, work instructions, inspection plans, and ERP/MES data.
    • Nonconformance and CAPA processes, which interact with production, supplier management, document control, and training.
    • System integrations such as how a routing change in ERP updates MES operations, or how inspection results in MES update QMS records.

    Understanding process interaction helps organizations clarify handoffs, avoid gaps or overlaps in responsibility, and provide clear evidence of how the process approach is implemented across the organization.

    Common confusion

    • Process interaction vs. process flow: A process flow usually focuses on steps within a single process. Process interaction focuses on how multiple distinct processes connect to each other.
    • Process interaction vs. system integration: System integration refers to technical connections between software systems or equipment. Process interaction is broader and includes human tasks, responsibilities, physical flows, and information exchanges, whether or not they are automated.

    Relation to documented process maps

    In quality and compliance audits, organizations often use high-level process maps or interaction diagrams to show process interaction. These visualizations typically highlight core processes (such as sales, design, purchasing, production, and inspection) and illustrate how their inputs, outputs, and controls link together to form the quality management system.

  • NCR

    NCR in manufacturing and regulated operations

    NCR commonly stands for **Nonconformance Report** or **Non-Conformance Report**. It is a formal record used to document any product, material, process, service, or documentation that does not meet specified requirements.

    In industrial and regulated manufacturing environments, an NCR is part of the quality management and compliance record set. It captures what went wrong, how it was detected, the impact or suspected impact, and the immediate actions taken to contain the issue.

    Typical contents of an NCR

    While formats vary across organizations and systems, an NCR record commonly includes:

    – Unique NCR identifier and date
    – Description of the nonconformance (what failed and how it was detected)
    – Reference requirements (drawing, specification, SOP, work instruction, contract, or regulation)
    – Lot, batch, serial number, work order, or equipment reference
    – Classification or severity (for example: minor, major, critical)
    – Disposition decision (e.g., use-as-is, rework, repair, reject/scrap, return to supplier)
    – Responsibilities and approvals (originator, quality, engineering, customer where applicable)
    – Linkage to related records (deviations, waivers, CAPA, change controls, complaints)

    The NCR may also capture supporting evidence such as measurements, test results, photos, or attached documentation.

    Role of NCRs in operational workflows

    In practice, NCRs are used to:

    – Record nonconforming material or process events as they are detected on the shop floor, in incoming inspection, in-process inspection, final inspection, or field returns
    – Enable review and decision-making on product disposition by quality, engineering, and other responsible functions
    – Provide traceable evidence for audits and regulatory inspections
    – Feed trend analysis used to identify recurring issues and potential systemic problems

    NCRs often originate in systems such as MES, QMS, ERP, or supplier portals, and may be linked to work orders, production orders, purchase orders, or service records.

    Relationship to CAPA and deviations

    An NCR documents that **a specific nonconformance occurred**. It does not, by itself, guarantee investigation or corrective action beyond immediate containment.

    – **NCR vs. CAPA**: An NCR is an event record for a particular nonconformance. A CAPA (Corrective and Preventive Action) is a structured investigation and action plan intended to eliminate the cause of one or more nonconformances and prevent recurrence. One CAPA can be triggered by multiple NCRs showing a pattern.
    – **NCR vs. deviation/waiver**: A deviation or waiver is an approved, intentional departure from a requirement, usually requested **before** or during production. An NCR is normally raised **after** a nonconformance is detected. However, in some organizations, NCRs and deviation/waiver processes are tightly integrated or combined in the same workflow.

    Boundaries and exclusions

    The term NCR in this context:

    – **Includes**: records for nonconforming products, components, raw materials, documents, software builds, and manufacturing or test processes that do not meet defined requirements
    – **Includes**: NCRs raised internally (e.g., production, quality) or externally (e.g., supplier NCRs, customer-return NCRs) when managed through a formal quality process
    – **Excludes**: financial term “Net Cash Requirement” or vendor-specific product names unrelated to quality nonconformance

    An NCR is typically not the same as a general incident, near miss, or safety report, although nonconforming conditions can overlap with safety concerns.

    Use in digital manufacturing systems

    In OT/IT and MES/QMS/ERP integration, NCR records are usually:

    – Created automatically or manually when inspection or test results fall outside specification
    – Associated with material genealogy and traceability records (e.g., lot and serial tracking)
    – Used as triggers for workflow steps such as quality holds, additional inspections, rework routing, or engineering review
    – Queried and trended as part of quality metrics such as nonconformance rates, cost of poor quality (COPQ), and supplier performance

    Common confusion and alternative meanings

    “NCR” is also the name of a well-known technology company and may be used as a financial or banking acronym in other industries. In manufacturing and regulated operations:

    – **Correct usage** refers to Nonconformance Report / Non-Conformance Report
    – To avoid ambiguity, many organizations spell out “Nonconformance Report” in formal documents and use the acronym NCR mainly in internal systems and forms

    When systems or documents might be read by mixed audiences, it is common to define the term on first use (e.g., “Nonconformance Report (NCR)”).

  • Key Characteristic (KC)

    A Key Characteristic (KC) is a specific feature of a part, assembly, or manufacturing process whose variation has a significant impact on product performance, safety, reliability, fit, or compliance with requirements. KCs are identified so that they receive focused control, verification, and documentation throughout design, manufacturing, and inspection.

    What a Key Characteristic includes

    In industrial and regulated manufacturing, a KC commonly refers to:

    • A dimensional feature, geometric tolerance, surface condition, or material property that is critical to product function or safety.
    • A process parameter (such as torque, temperature, pressure, or cure time) whose stability is essential to achieving the required product characteristics.
    • Characteristics that drive risk in areas such as airworthiness, patient safety, structural integrity, or regulatory compliance.

    KCs are usually called out on engineering drawings, models, specifications, or control plans and often link to specific inspection or process-control requirements.

    What a Key Characteristic is not

    • It is not every dimension or requirement on a drawing. Only those with a defined high impact on function, safety, or compliance are treated as KCs.
    • It is not limited to aerospace or one standard, even though the term is heavily used in those sectors.
    • It is not the same as a general quality metric; it is tied to a concrete, measurable feature or parameter.

    Operational use in manufacturing systems

    In day-to-day operations, KCs influence how work is planned, executed, and documented:

    • Design & process planning: Engineering identifies KCs during design reviews and risk analyses, then defines how they will be manufactured and controlled.
    • Drawings & ballooning: KCs are often marked with specific symbols or flags on drawings and in ballooned inspection documents, including for first article inspection (FAI).
    • Inspection & measurement: KCs usually receive higher inspection frequency, tighter gage selection, and sometimes statistical process control (SPC) or capability studies.
    • MES/ERP/QMS integration: Execution systems may track KCs separately, enforce mandatory data collection at KC checkpoints, and maintain traceable records for audits.
    • Supplier management: Purchase orders and supplier quality requirements may explicitly call out KCs and required inspection or reporting for those features.

    Relationship to standards and FAI

    In aerospace and other regulated industries, KCs are often defined and managed with reference to sector standards and customer flowdowns. In contexts such as first article inspection (FAI), KCs are identified among all drawing characteristics and may be linked to additional evidence requirements, capability analysis, or ongoing monitoring. Digital FAI tools and MES commonly treat KCs as a distinct data category to support traceability and audit readiness.

    Common confusion

    • Key Characteristic vs. Critical-to-Quality (CTQ): CTQ is a broader quality term that may encompass performance expectations or customer needs that are not directly tied to a single measurable feature. A KC is always a specific, measurable characteristic or parameter.
    • Key Characteristic vs. Critical Characteristic: Some organizations use “critical characteristic” or “safety critical characteristic” with definitions specific to their standard or customer. These terms overlap heavily with KCs but may have different symbols, approval steps, or documentation rules. It is important to follow the definitions in the applicable customer or industry standard.
    • Key Characteristic vs. Key Process Input: A key process input (such as a machine setting) may be controlled because it affects a KC. The KC is the resulting product or process characteristic being assured.

    Context in regulated manufacturing

    In regulated environments, identifying and controlling Key Characteristics supports risk-based thinking, inspection planning, and traceable evidence that critical features are consistently produced within specified limits. Digital systems often tag KCs to ensure required measurements are collected, contextualized (e.g., lot, serial number, operation), and retrievable for investigations, nonconformance analysis, and customer or regulatory audits.

  • ISO 9000 family

    The ISO 9000 family is a group of international standards that describe the principles, terminology, and requirements of quality management systems (QMS). It is used across many industries, including regulated manufacturing sectors such as aerospace, defense, and medical devices, to provide a common approach to managing and controlling quality-related processes.

    What the ISO 9000 family includes

    The ISO 9000 family commonly refers to several core standards, the most widely referenced being:

    • ISO 9000: Defines fundamental QMS concepts, vocabulary, and quality management principles.
    • ISO 9001: Specifies requirements for a QMS that an organization can implement and have independently assessed.
    • ISO 9004: Provides guidance for organizations seeking to go beyond the basic requirements and improve overall performance and maturity of their QMS.
    • ISO 19011 (often grouped with ISO 9000 family in practice): Provides guidelines for auditing management systems, including quality management systems.

    Other related or sector-specific standards sometimes used alongside the ISO 9000 family include AS9100 (aerospace QMS), IATF 16949 (automotive), and ISO 13485 (medical devices). These build on ISO 9001 concepts but add sector-specific requirements.

    Operational meaning in manufacturing and regulated environments

    In industrial and manufacturing operations, the ISO 9000 family provides a structured framework for how organizations document, control, and continually improve their processes. Typical operational elements influenced or structured by the ISO 9000 family include:

    • Defined quality policy, objectives, and responsibilities.
    • Documented and controlled procedures, work instructions, and records.
    • Process-based thinking across design, production, inspection, and support functions.
    • Risk-based approaches to planning and change management.
    • Internal audits, management review, and corrective actions.
    • Evidence of traceability, nonconformance handling, and CAPA workflows.

    In IT/OT and MES/ERP-integrated environments, the ISO 9000 family often influences how data is structured and managed, how version control and document control are implemented, and how quality events (such as nonconformances and deviations) are recorded and analyzed.

    What the ISO 9000 family is not

    • It is not a single standard; it is a collection of related standards.
    • It does not prescribe specific manufacturing methods or technologies; it focuses on management system requirements and practices.
    • It does not guarantee product quality by itself; it defines how an organization manages processes that affect quality.
    • It is not the same as sector-specific standards like AS9100, which incorporate ISO 9001 concepts but add industry requirements.

    Common confusion

    • ISO 9000 vs. ISO 9001: ISO 9000 defines principles and vocabulary. ISO 9001 defines the requirements for a QMS. When organizations say they are “certified,” they are usually referring to ISO 9001, not ISO 9000 in general.
    • ISO 9000 family vs. QMS software: The ISO 9000 family is a set of standards, not a software product. MES, QMS, and ERP systems may support compliance with ISO 9001 requirements, but they are separate from the standards themselves.
    • ISO 9000 family vs. sector standards: Standards such as AS9100, ISO 13485, or IATF 16949 are often based on ISO 9001 and used in combination with it, but they introduce additional requirements and should not be treated as identical to the core ISO 9000 family.

    Use in quality and compliance workflows

    In regulated manufacturing, the ISO 9000 family often shapes how organizations structure:

    • Quality manuals, procedures, and controlled documents.
    • Nonconformance, deviation, and CAPA processes.
    • Internal and supplier audit programs.
    • Training records and competence management.
    • Integration between QMS, MES, and ERP for traceability and record retention.

    These standards are frequently referenced in customer requirements, supplier quality agreements, and internal quality policies, and they provide a common language for quality expectations across global supply chains.