AS9100 requires an organization to plan, implement, and control the processes needed to assure product safety, as applicable to its products and services. It does not define a single universal product safety program, and it does not certify that a product is safe. The organization must determine what product safety means for its scope, customer requirements, regulatory context, and product risk, then maintain evidence that the related controls are defined, used, and kept under change control.
What AS9100 commonly expects
In practical terms, AS9100 product safety expectations usually include controls for identifying hazards, managing risks, controlling safety-critical items, communicating product safety concerns, and ensuring personnel understand their contribution to product safety.
The standard specifically points to activities such as:
- assessing hazards and managing associated risks;
- managing safety-critical items or characteristics where they apply;
- analyzing and reporting events that affect product safety;
- communicating product safety information internally and, where required, externally;
- training or awareness so personnel understand how their work can affect product safety.
These requirements are closely tied to operational planning, risk management, configuration control, nonconformance management, supplier control, and corrective action. They should not be treated as a stand-alone policy that is disconnected from how work is actually planned, built, inspected, released, and supported.
What is site-specific
The depth of product safety control depends heavily on the product, process, customer flowdowns, regulatory obligations, and contract requirements. A flight-critical assembly, maintenance process, software-controlled test process, or special process will generally require more formal controls than a low-risk noncritical component.
Common site-specific decisions include how safety-critical characteristics are identified, where they are controlled in routings or work instructions, how escapes are escalated, how suppliers are flowed down requirements, and how safety-related events are reported. These decisions need to be documented and consistently applied. Informal tribal knowledge is usually not enough in an AS9100 environment.
Evidence auditors commonly look for
Auditors typically look for objective evidence that product safety controls are embedded in the quality management system and execution processes. Examples may include risk assessments, control plans, design or process FMEAs, special characteristic controls, inspection records, nonconformance records, MRB decisions, CAPA records, training records, supplier flowdowns, and documented escalation paths.
The important point is traceability. If a safety-related requirement exists, the organization should be able to show how it is translated into planning, purchasing, production, inspection, release, and corrective action controls. Missing links between requirements, work instructions, inspection evidence, and nonconformance handling are common failure modes.
Interaction with MES, ERP, PLM, and QMS
In brownfield environments, product safety controls are often spread across PLM, ERP, MES, QMS, maintenance systems, spreadsheets, and legacy document repositories. AS9100 does not require one software platform, but fragmented systems increase the burden of proving traceability and control.
Replacing all systems just to address product safety is usually unrealistic in aerospace-grade environments. Qualification burden, validation cost, downtime risk, integration complexity, long equipment lifecycles, and existing customer approvals often make full replacement impractical. A more realistic approach is usually to define ownership, strengthen interfaces, control master data, and validate the workflows that carry safety-related requirements into execution and records.
What AS9100 does not do
AS9100 does not provide engineering safety approval, airworthiness approval, legal protection, or a guaranteed audit outcome. It requires a controlled management system for product safety-related processes. Whether the controls are adequate depends on the product, customer, applicable regulations, process maturity, and the quality of implementation.