AS9100 affects supplier quality management by making control of external providers an explicit, auditable part of the quality management system. It does not automatically qualify suppliers, guarantee supplier performance, or prescribe a specific portal or software tool. It requires the organization to define how suppliers are approved, how requirements are flowed down, how supplied product or services are verified, how supplier performance is monitored, and how issues are contained, corrected, and recorded.
What changes in practice
Under AS9100, supplier quality is not just a purchasing activity. It typically involves quality, engineering, operations, procurement, and sometimes customer or regulatory representatives, depending on the product, process, and contract requirements.
Common expectations include:
- criteria for supplier evaluation, selection, approval, and reapproval;
- clear flow-down of drawings, specifications, quality clauses, key characteristics, export control requirements, and customer-specific requirements;
- risk-based verification of externally provided products, processes, and services;
- control of special processes, delegated inspection, source inspection, and subcontracted operations where applicable;
- monitoring of supplier performance, such as escapes, delivery performance, nonconformances, corrective actions, and audit results;
- defined handling of nonconforming supplier material, including disposition authority and traceability;
- records that show what was required, what was received, what was accepted, who approved it, and what changed.
What is site-specific
The depth of supplier controls depends on the product, customer contract, regulatory context, safety risk, and the maturity of the organization’s quality system. A supplier providing standard packaging will not usually be controlled the same way as a supplier performing a special process on a flight-critical component.
Customer flow-downs can also be stricter than the baseline AS9100 requirement. In aerospace and defense work, supplier management may need to account for customer-approved supplier lists, first article requirements, source inspection, material traceability, counterfeit part prevention, export control handling, and specific corrective action formats.
System implications
AS9100 does not require a single integrated supplier quality platform, but weak system integration often becomes a practical problem. Supplier status may live in the ERP, drawings and revisions in PLM, inspections in MES, corrective actions in QMS, and purchase order clauses in procurement systems. If those systems disagree, supplier controls become difficult to defend.
In brownfield environments, full replacement is usually unrealistic. Qualification burden, validation cost, downtime risk, integration complexity, traceability obligations, and long asset lifecycles often make coexistence the only practical path. The more realistic goal is usually controlled data ownership, reliable interfaces, consistent supplier master data, and clear procedures for exceptions.
Common failure modes
Supplier quality programs often fail AS9100 scrutiny when the written process looks stronger than actual execution. Typical gaps include approved supplier lists that are not current, purchase orders missing required flow-downs, supplier corrective actions closed without evidence of effectiveness, inspection records that cannot be tied back to the correct revision, and manual workarounds that are not controlled.
Another common issue is treating supplier scorecards as sufficient control. Performance metrics are useful, but they do not replace risk-based verification, documented approval criteria, traceable records, and escalation when supplier performance degrades.
AS9100 therefore raises the discipline required for supplier quality management. It does not remove judgment. Organizations still need to define risk categories, assign ownership, validate digital workflows where needed, maintain change control, and ensure the supplier record matches what actually happened.