What documentation do small aerospace suppliers need to consistently pass AS9100 audits?

Written by

in

Small aerospace suppliers can pass AS9100 audits with a lean documentation set, but it must be coherent, controlled, and consistent with actual practice. You will be audited on alignment between your documented system, what people do, and the records you keep. The specific documents and level of detail depend on your scope, complexity, customers, and certification body expectations.

1. Core QMS documentation required by AS9100

At a minimum, most small suppliers need:

  • Quality manual or equivalent description of the QMS
    • Scope of certification, including exclusions/justifications.
    • High-level process map (order to shipment, including special processes and external providers).
    • References to supporting procedures and records.
  • Documented procedures or defined methods for key AS9100 processes (can be separate procedures, integrated work instructions, or software workflows, as long as they are controlled and understood):
    • Documented information control (document and record control).
    • Risk-based thinking / operational risk management (including configuration and delivery risks).
    • Contract review and requirements management.
    • Design and development, if in scope.
    • Purchasing and supplier management.
    • Production and service provision (routing/travelers, work instructions, inspection).
    • Control of nonconforming outputs, including MRB and concessions, where applicable.
    • Corrective action and continual improvement.
    • Internal audits.
    • Management review.
  • Documented quality policy and measurable quality objectives that are relevant to your size and work (for example, customer OTD, escapes, rework, or scrap rates).

AS9100 will not dictate your format. You can combine topics in fewer documents, provided that intent and responsibilities are clear and people are actually using them.

2. Product realization and shop-floor documentation

Auditors will expect clear, controlled documentation for how you convert requirements into parts and assemblies. For small suppliers in a brownfield environment, this may be a mix of paper travelers, ERP/MES screens, and stand-alone work instructions.

  • Contract review and requirements capture
    • Procedure or defined method for reviewing RFQs, POs, and drawing packages.
    • Evidence that technical requirements, quality clauses, key characteristics, FAI, and special process needs are identified and flowed down.
  • Configuration and revision control
    • Process for ensuring the right drawing, model, and specification revisions are used.
    • Controls for customer digital data sets and controlled specs.
  • Work instructions and travelers/routings
    • Traveler or routing that ties PO, part number, lot/serial, and operations together.
    • Work instructions where risk, complexity, or customer requirements justify them (for example, critical machining, heat treatment, assembly, torque sequences).
    • Clear identification of required inspections, hold points, and buy-offs.
  • Inspection and test documentation
    • Inspection plans and sampling plans (or defined methods that can be consistently applied).
    • Inspection records for incoming, in-process, and final inspections.
    • FAI documentation when AS9102 or equivalent is required by contract.
  • Equipment, tooling, and gage control
    • Calibration procedure and calibrated equipment list.
    • Calibration certificates and traceability records.
    • Evidence that only calibrated equipment is used where required.
  • Control of customer property and materials
    • Procedure or rules for handling, storing, and tracking customer-supplied material, tooling, and data.
    • Records for receipt, use, and status of customer property.
  • Traceability and batch / serial control
    • Defined approach for traceability (lot-based or serial), aligned with customer and contract.
    • Physical and system records showing material heat lots, serialization, and routing history.

The specific depth depends on risk. A simple, low-volume machined bracket will not need the same documentation detail as a safety-critical hydraulic body, but the logic and consistency of your controls must be clear.

3. Supplier management and external processes

Even the smallest supplier is expected to control its own supply chain. Typical documentation includes:

  • Approved supplier list and qualification records (including special processors such as heat treat, NDT, coatings).
  • Purchasing procedure that covers:
    • How supplier capability and risk are evaluated.
    • How requirements (technical, quality, flowdown clauses) are communicated.
    • Verification activities, including receiving inspection and source inspection when applicable.
  • Supplier performance records (on-time delivery, quality, and any escalations).
  • Records of certifications, special process approvals, and changes at key suppliers.

In brownfield environments these records often live partly in ERP, partly in spreadsheets, and partly in email. That is acceptable if you can reliably show the current state, maintain version control on key lists, and retrieve evidence quickly during audits.

4. Nonconformance, corrective action, and improvement

Auditors focus heavily on how you handle escapes and systemic issues. You will need:

  • Nonconformance procedure that defines:
    • Identification, segregation, and disposition of nonconforming material.
    • MRB authority and limits, including when customer approval is needed.
    • Rework vs repair, and how these are documented and approved.
  • NCR records and evidence of containment actions, including communication to customers where required.
  • Corrective action procedure with clear triggers (customer complaints, internal trends, audit findings) and timelines.
  • Corrective action records that actually show root cause analysis, implemented actions, verification of effectiveness, and closure.
  • Continual improvement evidence (can be practical: scrap reduction projects, process changes, training upgrades) linked back to data and risk.

The failure mode auditors see most often in small suppliers is a stack of corrective actions that are formally closed but not effectively implemented on the floor. Documentation must show that changes were communicated, trained, and checked, not just written in a report.

5. Competence, training, and awareness

For small organizations where people wear multiple hats, auditors will look closely at how competence is defined and maintained:

  • Competence and training process, including criteria for critical roles (e.g., welders, inspectors, programmers, planners, MRB signatories).
  • Training records for employees, including on-boarding, process changes, and any customer-specific training.
  • Authorization records for special tasks (e.g., visual weld inspection, NDT interpretation, final acceptance sign-off).
  • Awareness evidence that personnel know the quality policy, relevant objectives, and their role in meeting requirements (often verified through interviews).

If you rely heavily on tribal knowledge, it is important to make at least the critical parts explicit in work instructions, qualification matrices, or standard work documents. Otherwise the system is fragile and will be challenged in audits.

6. Internal audits and management review documentation

AS9100 puts strong emphasis on “checking” and leadership oversight. You will need:

  • Internal audit program that covers the full QMS scope and AS9100 clauses over a defined cycle.
  • Internal audit procedure describing planning, execution, reporting, and follow-up.
  • Internal audit records (plans, checklists if used, reports, and evidence of corrective actions for findings).
  • Management review procedure that defines inputs, frequency, and outputs.
  • Management review records (agenda, data reviewed, decisions, and actions), including follow-up evidence.

A common gap in small suppliers is “paper” management review with little traceable follow-through. Auditors will test whether management review actions align with actual resource allocation, investments, and changes on the floor.

7. Data integrity, document control, and mixed-system realities

In most small aerospace suppliers, documentation is spread across:

  • ERP or MRP for orders, routings, and inventory.
  • File shares, PLM, or simple network drives for drawings, models, and specifications.
  • Paper travelers and inspection sheets on the floor.
  • Email chains and spreadsheets for supplier communication and metrics.

Auditors generally accept this brownfield reality if you can show:

  • Clear ownership and revision control for each type of document and record.
  • Defined interfaces between systems (for example, how updated drawings are pushed from customer or PLM to ERP route and then to the traveler or digital work instruction).
  • Access control and backup practices that are appropriate for the sensitivity of the data and your contractual obligations.
  • Robust change control so that operators are not using obsolete work instructions or travelers.

Full replacement of legacy systems just to “look modern” for audits is rarely justified. It adds qualification and validation burden, increases downtime risk, and can actually damage traceability during transition. Incremental improvements that strengthen evidence trails and reduce manual re-entry are generally more sustainable.

8. Practical tips for small suppliers to keep documentation lean and effective

  • Start from your processes, not the clause list. Map how work actually flows, then map AS9100 requirements onto that reality.
  • Combine documents where sensible. Small companies can often use integrated procedures (for example, one document for sales/order review/planning) as long as roles and records are unambiguous.
  • Define minimum required records per process step. For each key process, be explicit: what record proves this was done, where it lives, who owns it, and how long it is kept.
  • Keep versions visible on the floor. Whether digital or paper, operators must be able to see that they are using current revisions.
  • Treat customer-specific requirements as first-class citizens. Maintain a simple summary of major customer requirements and how they are implemented in your QMS, so you can show consistent flowdown during audits.

9. Minimum viable documentation set for consistent AS9100 audits

The exact list will vary, but as a rule of thumb, a small aerospace supplier should be able to immediately produce, at any time:

  • QMS description (manual or equivalent), quality policy, and quality objectives.
  • Controlled procedures or defined methods for document control, contract review, purchasing, production, inspection, NCR/MRB, corrective action, internal audit, and management review.
  • Representative travelers/routings, work instructions, and inspection records for recent orders.
  • Sampling or inspection strategy, calibration system records, and equipment lists.
  • Supplier list with evidence of qualification and performance monitoring.
  • NCRs, corrective actions, and evidence of implemented changes.
  • Training/competence records and authorizations for key roles.
  • Internal audit schedule, reports, and associated corrective actions.
  • Recent management review records and follow-up actions.

If these documents are consistent with each other and with what actually happens at the machine, bench, and inspection station, you have the essential foundation to pass AS9100 audits on a reliable basis.

Content classification

Visible verification fields for authorship, dates, taxonomy, and ST assignments.

Author:

Published:

Updated:

Tags:

FAQ category:

FAQ tag:

Glossary category:

Glossary tag:

Colour:

Channel:

Content type:

Location:

Audience:

Intent:

Dev-only relationship debug

Content relationships

Rendered from saved content and bridge metadata. Nothing in this panel writes back to WordPress.

Inline glossary links

No inline glossary links found in saved content.

Attached glossary terms

No glossary bridge terms attached.

Attached FAQs

No FAQ bridge items attached.

Diagnostics

Inline glossary links
0
Attached glossary terms
0
Attached FAQs
0
  • No glossary or FAQ relationships found for this item.