Glossary Tag: risk detection

  • Use-As-Is Disposition

    Use-As-Is Disposition commonly refers to a formal decision to accept a nonconforming material, component, or product for its intended use without rework, repair, or scrap. It means the item is released in its current condition after review determines that the observed nonconformance does not prevent acceptable use within the applicable requirements or approved decision process.

    In manufacturing and quality workflows, this disposition appears as one possible outcome of nonconformance review. It is typically recorded in an NCR, deviation, concession, or MRB-related process, along with the reason for acceptance, scope, affected items or lots, and required approvals. The term refers to the decision status itself, not to the investigation or corrective action process that may exist alongside it.

    What it includes and excludes

    • Includes: acceptance of an item in its current state for defined use, with documented review and disposition.
    • Excludes: changing the item to meet requirements. If work is performed to bring the item into conformance, that is rework or repair, not use-as-is.
    • Excludes: automatic acceptance of defects. A use-as-is decision is typically exception-based and documented.

    Common confusion

    Use-as-is vs rework: Rework changes the item so it fully meets the original requirement. Use-as-is accepts the item without making that change.

    Use-as-is vs repair: Repair changes the item so it becomes acceptable for use, but not necessarily fully conforming to the original specification. Use-as-is involves no physical correction.

    Use-as-is vs scrap: Scrap removes the item from intended use. Use-as-is keeps it in use.

    Use-as-is vs deviation or concession: A deviation or concession is commonly the authorization mechanism or record; use-as-is is the disposition outcome.

    How it shows up in systems

    In MES, QMS, ERP, or integrated NCR workflows, use-as-is may be stored as a disposition code tied to the affected serial number, lot, batch, work order, or material record. Related data can include review notes, approval history, attachments, traceability links, and any downstream restrictions or customer communication requirements.

  • Nonconforming Material (NCM)

    Nonconforming Material (NCM) commonly refers to raw material, components, subassemblies, or finished goods that do not meet one or more specified requirements. Those requirements may come from drawings, specifications, purchase requirements, process criteria, inspection results, labeling rules, or approved manufacturing instructions.

    NCM is a status or condition of material, not a root cause and not a disposition by itself. Once identified, the material is typically controlled so it is not used, shipped, or mixed with acceptable stock until an authorized review determines what happens next.

    What it includes

    • Incoming material that fails receiving inspection
    • Work-in-process that does not meet dimensional, visual, functional, or documentation requirements
    • Finished product found out of specification before release or after internal review
    • Material with incorrect identification, lot traceability, revision status, or labeling when those are required attributes

    What it does not mean

    NCM does not automatically mean scrap. Nonconforming material may be reworked, repaired where allowed, used under an approved deviation or concession where applicable, returned to supplier, or scrapped, depending on the defined review and disposition process. It also does not mean every production issue is a material issue. Equipment faults, documentation errors, and process deviations may create nonconforming output, but they are not themselves material.

    How it appears in operations and systems

    In manufacturing workflows, NCM is often identified during receiving, in-process inspection, final inspection, testing, or stockroom review. In MES, ERP, or QMS environments, it is commonly linked to a hold status, quarantine location, nonconformance record, lot or serial traceability, and a disposition workflow. The objective of those controls is to maintain visibility and prevent unintended use while the issue is being evaluated.

    Example: a batch of machined parts that fails a diameter tolerance check would be treated as nonconforming material until the parts are reviewed and dispositioned.

    Common confusion

    Nonconforming Material (NCM) is often confused with nonconformance or NCR. NCM refers to the affected material itself. A nonconformance is the condition or event in which a requirement is not met. An NCR, if used by the organization, is the record used to document and manage that condition.

    It may also be confused with scrap. Scrap is only one possible final disposition for NCM, not a synonym for it.

  • Back-testing

    Back-testing is the evaluation of a model, decision rule, forecast method, or detection logic against historical data to estimate how it would have performed if used in the past. In industrial and manufacturing settings, it commonly refers to testing analytics, alert thresholds, predictive rules, or planning logic on prior production, quality, maintenance, or supply chain data.

    It is a retrospective method. It uses existing records rather than live operation. Because of that, back-testing can help assess whether a rule appears stable, sensitive, or overly noisy before it is used in production workflows. It does not prove future performance, and it is not the same as real-time validation in current operations.

    Where it appears in manufacturing systems

    Back-testing may be used in systems and workflows such as:

    • quality analytics, for example testing whether a signal would have detected past drift or nonconformance earlier

    • maintenance analytics, for example checking whether a predictive rule would have flagged equipment issues before failure events

    • planning and inventory models, for example comparing forecast logic against historical demand and supply outcomes

    • alerting and monitoring, for example tuning thresholds against prior process, machine, or historian data

    • risk scoring or exception management, for example testing whether a scoring method would have identified past high-risk lots, orders, or suppliers

    What it includes and excludes

    Back-testing commonly includes historical input data, the rule or model being evaluated, and a comparison between predicted or triggered results and known outcomes. The historical data may come from MES, ERP, QMS, SCADA, historians, CMMS, or related systems.

    It does not by itself include model training, live deployment, or operational change control, although it may support those activities. It also does not guarantee that a model is suitable for current conditions if equipment, materials, routing, product mix, or business rules have changed since the historical period being tested.

    Common confusion

    Back-testing is often confused with simulation, validation, and benchmarking.

    • Back-testing uses real historical data and known outcomes.

    • Simulation uses assumed or generated scenarios, which may or may not match actual past conditions.

    • Validation is broader and may include back-testing, live testing, and review of data quality and assumptions.

    • Benchmarking compares performance against a reference or peer, rather than replaying history through a model.

    In finance, back-testing is strongly associated with investment strategy evaluation. In manufacturing and industrial analytics, the term more commonly refers to replaying historical operational data to evaluate detection logic, forecasts, or decision rules.

  • Spurious correlation

    Spurious correlation commonly refers to an apparent relationship between two variables that looks statistically meaningful but does not reflect a true underlying connection. The pattern may appear in charts, reports, or analytics outputs even when one variable does not meaningfully influence the other.

    In manufacturing and industrial operations, spurious correlation can appear when teams compare process, quality, maintenance, or production data and find a pattern that is coincidental, indirect, or caused by an unobserved third factor. For example, a plant may see a correlation between operator shift and defect rate, but the real driver could be product mix, machine condition, inspection timing, or missing data.

    A spurious correlation is not the same as proven causation. It also does not automatically mean the data is wrong. It means the observed association may be misleading if used without validation, domain context, or control for confounding factors.

    How it shows up in operations and systems

    • BI dashboards showing two KPIs moving together over time

    • MES, ERP, or historian data merged without enough context about timing, routing, or lot structure

    • Quality investigations that rely on trend matching alone

    • Predictive analytics or machine learning models that select variables with statistical signal but low operational meaning

    Common causes include small sample sizes, seasonal patterns, shared time trends, poor data alignment, hidden variables, and repeated slicing of data until a pattern appears.

    Common confusion

    Spurious correlation is often confused with correlation in general. Correlation only describes that variables move together; it does not explain why. It is also different from a root cause. A root cause is a validated explanation for an observed effect, while a spurious correlation is an association that may not hold up under deeper analysis.

    It can also be confused with confounding. Confounding is one common reason a correlation becomes spurious, but the terms are not identical. Confounding refers specifically to a third factor that distorts the observed relationship.

    Why the term matters

    In regulated and quality-sensitive environments, decisions based on spurious correlation can distort investigations, escalation priorities, process adjustments, and reporting. The term is commonly used as a caution in analytics, continuous improvement, and performance monitoring to distinguish observed signal from validated operational cause.

  • ISO/IEC 27001:2022

    ISO/IEC 27001:2022 is the 2022 edition of the international standard that specifies requirements for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS). It provides a structured framework for managing information security risks for all types of organizations, including manufacturers operating regulated production and OT/IT environments.

    The standard covers how an organization defines the scope of its ISMS, assesses information security risks, selects and applies controls, and monitors performance and improvement. It is technology neutral and can be applied to on-premises systems, cloud services, operational technology (OT), and integrated IT/OT architectures.

    Key elements

    ISO/IEC 27001:2022 commonly refers to:

    • ISMS requirements: Clauses that define management-system practices such as context, leadership, planning, support, operation, performance evaluation, and improvement.
    • Annex A reference controls: A catalog of information security controls organized into themes such as organizational, people, physical, and technological controls. These are references for risk treatment, not a mandatory checklist.
    • Risk-based approach: The requirement to identify information security risks, define risk criteria, choose treatments, and document decisions in a statement of applicability.
    • Continuous improvement: Expectations for monitoring, internal audits, management review, and corrective actions to keep the ISMS effective and up to date.

    Use in industrial and regulated manufacturing environments

    In manufacturing, ISO/IEC 27001:2022 is commonly used to structure information security around systems such as MES, ERP, historians, lab systems, and OT networks. Typical applications include:

    • Defining how access to production and quality systems is governed and logged.
    • Aligning network segregation, remote access, and patching practices for OT assets with formal risk assessments.
    • Coordinating information security with quality management, document control, and audit readiness processes.
    • Supporting supplier and customer expectations around information security governance, without implying any specific certification outcome.

    Relation to other ISO/IEC 27000-series documents

    ISO/IEC 27001:2022 sits within the broader ISO/IEC 27000 family of information security standards. For example:

    • ISO/IEC 27002 provides guidance on implementing controls conceptually aligned with the Annex A controls of ISO/IEC 27001:2022.
    • Other 27000-series documents address topics such as OT security, incident management, and sector-specific guidance.

    Organizations often use 27001 as the management-system core and reference additional 27000-series standards for more detailed practices.

    Common confusion

    • Standard vs. certification: ISO/IEC 27001:2022 is a written standard. Certification is a separate process conducted by external bodies. The term “ISO 27001” is often used loosely to mean both, which can cause misunderstanding.
    • “Four categories” of controls: Training materials sometimes group Annex A controls into a small number of categories for teaching purposes. ISO/IEC 27001:2022 itself defines its own control structure and naming; it does not formally define a “four category” model.
    • 27001 vs. 27002: ISO/IEC 27001:2022 defines ISMS requirements and references control themes. ISO/IEC 27002 provides detailed implementation guidance for controls. They are related but not interchangeable.

    Context of the 2022 edition

    The 2022 edition updates and replaces earlier editions of ISO/IEC 27001. It aligns its Annex A controls with the revised ISO/IEC 27002 structure, streamlines and renames several controls, and reflects current practices in areas such as cloud services and modern networked environments. When organizations refer to “ISO 27001” in current projects or contracts, they often mean ISO/IEC 27001:2022 unless an earlier edition is explicitly specified.

  • Manufacturing work instructions

    Manufacturing work instructions are controlled documents that describe, step by step, how to perform specific production, inspection, or test activities to make a defined product or component. They translate higher-level process descriptions and product specifications into clear, executable tasks for operators and technicians on the shop floor.

    Manufacturing work instructions typically include the sequence of operations, required tools and materials, key parameters and setpoints, inspection or measurement steps, and acceptance or rejection criteria. In regulated or quality-critical environments, they are subject to document control, version management, and formal review and approval.

    How manufacturing work instructions are used

    In industrial and regulated manufacturing environments, manufacturing work instructions commonly:

    • Guide operator actions for assembly, machining, mixing, packaging, testing, or inspection
    • Reference related documents such as drawings, specifications, recipes, bills of materials, and standard operating procedures
    • Capture critical quality steps, sign-offs, and required checkpoints
    • Provide visual aids such as diagrams or photos to clarify tasks
    • Serve as a basis for training and qualification on specific operations
    • Record production data or confirmations when implemented digitally through MES or electronic work instruction systems

    What manufacturing work instructions are not

    • They are not high-level policies or quality manuals, which describe overarching requirements.
    • They are not full process descriptions or SOPs when those focus on broader procedures rather than task-level steps.
    • They are not engineering drawings or specifications, although they often reference those documents.

    Common confusion

    The term “manufacturing work instructions” is sometimes used interchangeably with:

    • Standard operating procedures (SOPs): SOPs usually describe how to perform a class of activities at a procedural level. Manufacturing work instructions tend to be more detailed and operation-specific.
    • Work orders or production orders: These authorize and schedule work for specific quantities and time periods. Manufacturing work instructions describe how to do the work but do not schedule or authorize it.
    • Digital work instructions: Digital work instructions are an electronic implementation of manufacturing work instructions within MES or other systems, but the underlying concept of task-level guidance is the same.

    Context: MWI acronym

    In many manufacturing environments, the acronym “MWI” is commonly used to mean “manufacturing work instructions.” Sites may use different acronyms or document types, so the meaning should be verified against local document control practices and system configuration.

  • Concession Volume

    Concession volume commonly refers to the quantity of material, parts, assemblies, or finished units covered by an approved concession. In manufacturing and quality contexts, a concession is a documented acceptance of a specified nonconformance under defined conditions, and the concession volume sets the numerical scope of that acceptance.

    This term helps define boundaries. It indicates how many affected items may be shipped, used, processed, or accepted under the concession. It does not, by itself, describe the technical deviation, the reason for acceptance, or the disposition decision criteria. Those details are usually recorded elsewhere in the concession or related quality records.

    How it is used in operations

    In practice, concession volume may appear as a count of pieces, batches, serial-numbered units, lots, or another controlled quantity measure. The exact unit depends on how the product is identified and controlled in the organization.

    • For discrete manufacturing, it may be the number of parts or assemblies covered.

    • For lot-controlled material, it may be a lot, batch, or a defined subset of that lot.

    • For serialized products, it may refer to specific serial numbers rather than a general count.

    Systems such as QMS, MES, or ERP may reference concession volume when tracking nonconforming product, release decisions, genealogy, and downstream use restrictions.

    What it includes and excludes

    Concession volume includes only the quantity explicitly authorized by the approved concession. It does not automatically extend to future production, similar parts, or additional nonconforming units unless those are also documented and approved.

    It also should not be confused with broader production volume, shipment volume, rework volume, or scrap volume. The term is limited to the quantity within the approved scope of concession treatment.

    Common confusion

    Concession volume is often confused with concession rate or concession frequency. Concession volume is the amount of product covered by a specific concession, while concession rate refers to how often concessions occur or what share of output they represent.

    It can also be confused with deviation quantity. In some organizations the terms are used similarly, but a deviation often refers to permission before manufacture or processing, while a concession commonly refers to acceptance of a known nonconformance after it exists. Usage varies by company and industry.

    Example

    If 25 parts in a lot have a minor documented nonconformance and quality approval allows those 25 specific parts to be accepted for use, the concession volume is 25 parts, not the full lot unless the full lot is explicitly included.

  • Mapping table

    A mapping table is a structured list that shows how one set of values, fields, identifiers, or codes corresponds to another set. In manufacturing and enterprise systems, it commonly refers to configuration or reference data used to translate information between applications, data models, or process steps.

    A mapping table can be as simple as linking an ERP item code to an MES material identifier, or as detailed as converting defect codes, unit-of-measure values, work center names, status codes, or supplier IDs across systems. It is used to support consistent data exchange, reporting, and system interoperability.

    What it includes

    • Field-to-field relationships between systems

    • Code translations, such as status, reason, defect, or location codes

    • Value normalization rules, such as standard names or approved abbreviations

    • Cross-reference records used in integrations, migrations, or reporting layers

    What it does not mean

    A mapping table is not the same thing as the integration logic itself. It usually holds the reference relationships that the integration, ETL process, middleware, MES, ERP, or analytics layer uses. It is also not necessarily a full data model, master data record, or transaction history.

    Operational meaning in manufacturing systems

    In regulated and multi-system environments, mapping tables often appear wherever data must stay aligned across MES, ERP, PLM, QMS, LIMS, or warehouse systems. Examples include mapping part revisions between PLM and ERP, associating shop-floor equipment IDs with enterprise asset records, or translating nonconformance codes into reporting categories.

    Because mapping tables influence how records are interpreted, they are often treated as controlled configuration data. Changes to them can affect traceability, reporting consistency, interface behavior, and downstream business rules.

    Common confusion

    Mapping tables are commonly confused with lookup tables, crosswalks, and master data:

    • Lookup table: usually provides allowed values or descriptive labels within one system.

    • Crosswalk: often means a direct correspondence list between two coding schemes and may be used as a synonym for mapping table.

    • Master data: is the authoritative business data itself, while a mapping table links or translates between representations of that data.