RSC Topic: Audit Readiness & Evidence Management

Ongoing audit-proof documentation, approvals, and revision histories.

  • AS9100D

    AS9100D is the 2016 revision of the AS9100 aerospace quality management system (QMS) standard. It builds on ISO 9001:2015 and adds sector-specific requirements for organizations involved in aviation, space, and defense products and services.

    AS9100D commonly refers to the requirements published in revision D of the standard. The formal name of the standard remains “AS9100”; the letter suffix (B, C, D, etc.) designates the revision level, not a different standard.

    Scope and usage in industrial operations

    In manufacturing and regulated industrial environments, AS9100D is used to structure and document quality management practices across the value chain, including:

    • Design and development of aerospace components and systems
    • Production, assembly, and integration on the shop floor
    • Special processes, testing, and inspection activities
    • Configuration management and document control
    • Supplier management and purchasing controls
    • Nonconformance management, corrective action, and risk-based thinking

    Operationally, organizations may align MES, ERP, PLM, and quality systems (such as eQMS or LIMS) with AS9100D requirements to help ensure consistent process execution, traceability, and documented evidence. This often includes controlled work instructions, device and process qualification records, change control history, and product genealogy.

    Relationship to ISO 9001

    AS9100D is structurally based on ISO 9001:2015 and incorporates all ISO 9001:2015 clauses, then adds or modifies requirements specific to aviation, space, and defense. In practice:

    • An organization conforming to AS9100D is generally understood to address ISO 9001:2015 requirements plus additional aerospace-specific controls.
    • References in procedures or quality manuals may appear as “AS9100 (rev D)” or “AS9100D aligned with ISO 9001:2015.”

    Document control and revision identification

    Within quality manuals, procedures, and technical documentation, it is common to reference the standard as “AS9100” together with the current revision, for example:

    • “AS9100 rev D”
    • “AS9100D (based on ISO 9001:2015)”

    From a document and version governance perspective, maintaining clarity on which revision is being used is important. Organizations typically:

    • Specify the applicable revision of AS9100 in their quality manual or top-level procedures.
    • Review customer, regulatory, and contractual requirements to confirm which revision must be applied.
    • Update references as standards are revised, while preserving historical records that show which revision was in force at the time.

    Common confusion

    • AS9100 vs. AS9100D: The standard is still called “AS9100”; “D” is the revision. AS9100D is not a separate standard with a new name, but the current revision of AS9100 (superseding earlier revisions such as AS9100C).
    • AS9100D vs. certification status: AS9100D describes requirements for a quality management system. Whether a specific site or organization is certified or audited against AS9100D is a separate question and depends on external assessment activities, not on the definition of the term.
    • AS9100D vs. ISO 9001:2015: ISO 9001:2015 is a generic QMS standard for many sectors. AS9100D includes ISO 9001:2015 but adds aerospace-specific expectations such as additional risk, product safety, and configuration management controls.

    Tie to the provided context

    In the referenced context about “the new name for AS9100,” AS9100D is the current revision identifier of the AS9100 standard, not a replacement name. When updating documentation, organizations typically verify the latest valid revision and any customer or contract requirements before changing references from earlier revisions (such as AS9100C) to AS9100D.

  • FAI (First Article Inspection)

    First Article Inspection (FAI) is a formal, documented process used to verify that the first production run of a part or assembly meets all specified design, drawing, and process requirements. It is most commonly associated with aerospace and other highly regulated manufacturing sectors, but the concept is used across many industries.

    What FAI includes

    In a regulated manufacturing context, an FAI typically involves:

    • Inspecting a representative production part (or parts) produced using normal production tools, methods, and conditions
    • Verifying all defined characteristics, such as dimensions, tolerances, materials, finishes, and notes from the engineering drawing or model
    • Documenting inspection results in a structured report, often linked to ballooned drawings or characteristic lists
    • Capturing evidence of process controls, tooling, and key manufacturing steps used to produce the inspected article
    • Reviewing and signing off the results by appropriate quality and engineering personnel

    In aerospace, FAIs are commonly performed in accordance with the AS9102 standard, which defines a specific format and content for First Article Inspection Reports (FAIRs). Digital FAI solutions often integrate with MES, PLM, or QMS systems to pull design data, manage revisions, and store inspection evidence.

    When FAI is typically performed

    Although timing can vary by customer or internal procedure, an FAI is commonly required when:

    • Producing a new part number for the first time
    • Moving production to a new facility, line, or supplier
    • Making significant design or process changes that may affect form, fit, or function
    • Restarting production after a long interruption, if required by contract or procedure

    FAI is generally performed on production-intent hardware, not prototypes, and is distinct from routine in-process or final inspection. It serves as an initial validation that the manufacturing process, as set up, can consistently produce conforming parts.

    Operational use in manufacturing systems

    In industrial operations, FAI information may be:

    • Linked to work orders, routings, and travelers within an MES
    • Associated with specific part revisions in PLM or engineering systems
    • Managed in QMS or dedicated FAI software for document control and audit trails
    • Shared with customers or suppliers as part of qualification and source approval workflows

    Digital workflows can help control which lots or serial numbers require FAI, ensure the correct revision of drawings is inspected, and retain evidence for audits or customer reviews.

    Common confusion

    • FAI vs. FAIR: FAI refers to the inspection process itself. FAIR (First Article Inspection Report) is the resulting documented record of that inspection.
    • FAI vs. production inspection: FAI is a one-time or event-driven verification tied to initial production or significant change, while in-process and final inspections are ongoing checks during regular manufacturing.
    • FAI vs. PPAP: In automotive and some other sectors, Production Part Approval Process (PPAP) serves a similar qualification purpose but uses a different structured set of documents and requirements. FAI in aerospace is often governed by AS9102.

    Relation to AS9102 and aerospace

    In aerospace manufacturing, FAI commonly refers to the AS9102-defined process and forms. Under this usage, every design characteristic must be accounted for, typically using ballooned drawings and characteristic numbering, with results recorded on standardized AS9102 forms. Many organizations use digital tools and portals (such as Net-Inspect) to manage AS9102 FAIs, share data with customers, and maintain traceable records.

  • regulated industries

    Core meaning

    Regulated industries are sectors in which organizations must operate under formal laws, regulations, and standards that govern how products are designed, manufactured, tested, documented, released, and sometimes maintained or retired.

    In these industries, external authorities (such as government agencies, standards bodies, or notified organizations) define mandatory requirements. Companies must be able to demonstrate compliance through documentation, records, and auditable processes.

    Common examples include, but are not limited to:

    – Pharmaceuticals and biotechnology
    – Medical devices and diagnostics
    – Food and beverage manufacturing
    – Aerospace and defense
    – Nuclear and certain energy sectors
    – Automotive (especially safety- and emissions-related processes)

    Operational characteristics

    Regulated industries typically share several operational traits:

    – **Documented procedures and controls**: Manufacturing, quality, and IT/OT processes are described in controlled documents and standard operating procedures (SOPs).
    – **Traceability requirements**: Products, materials, and often equipment and operators must be traceable, sometimes down to individual batches, lots, or serial numbers.
    – **Change control**: Modifications to processes, systems, or master data follow formal change control, including impact assessment and documented approval.
    – **Records and data integrity**: Production and quality records must be complete, accurate, and tamper-evident, with controlled access and audit trails.
    – **Qualification and validation**: Facilities, equipment, and computerized systems may require documented qualification/validation before use and after significant changes.
    – **Audit and inspection readiness**: Processes and records must be organized so external auditors or inspectors can review them on demand.

    Use in manufacturing and operations

    In industrial and manufacturing contexts, the term is commonly used to describe environments where:

    – **Manufacturing execution systems (MES)**, LIMS, QMS, and ERP integrations must support audit trails, electronic signatures, and controlled master data.
    – **Standardization across sites** is constrained by regulatory expectations, local regulatory interpretations, and validated states of systems.
    – **IT/OT governance** must align with regulatory expectations on data integrity, cybersecurity, and system lifecycle management.
    – **Quality systems** (for example, deviation management, CAPA, batch release) are tightly coupled with production systems and must be demonstrably followed.

    Site context: MES and multi-site operations

    In the context of MES and multi-site manufacturing, regulated industries:

    – Often use MES to **enforce standardized workflows, work instructions, and data collection rules** at the shop-floor level.
    – Require **governance and change control** when rolling out master data or process changes to multiple plants, because these changes may impact validated states or filings.
    – May limit how far process standardization can be pushed, due to **local regulatory requirements, legacy systems, or brownfield constraints**.

    MES deployments in regulated industries typically must be configured and maintained so that any changes to recipes, parameters, or logic are controlled, documented, and, where required, tested or validated before use in production.

    Boundaries and exclusions

    The term **regulated industries**:

    – **Includes** sectors where compliance with specific external regulations is central to daily operations and to the design of manufacturing and quality systems.
    – **Does not automatically include** every industry that is subject to some general law (for example, labor law or basic environmental law); it refers more narrowly to sectors with detailed operational or product regulations.
    – **Does not mean** a particular regulatory framework by itself; it is an umbrella label for industries subject to such frameworks.

    Common confusion and related terms

    – **Regulated industries vs. regulated utilities**: Regulated utilities (such as water or electricity providers) are a subset of regulated industries, but the term “regulated industries” is broader and includes many types of manufacturing.
    – **Regulated industries vs. high-risk industries**: High-risk operations (for example, heavy construction) may be hazardous but are not always regulated in the same product- or process-specific way as pharmaceuticals or medical devices.
    – **Regulated industries vs. standards-driven industries**: Some sectors follow voluntary or customer-driven standards without a strong legal or regulatory mandate; these are not usually categorized as regulated industries in a strict sense.

  • Form 3 (Characteristic Accountability)

    Form 3 (Characteristic Accountability) is one of the three standard forms defined in AS9102 for First Article Inspection (FAI) in the aerospace and defense industry. It is used to list each design characteristic from the drawing or model and to record how that characteristic was verified, the results of the inspection, and whether it conforms to requirements.

    What Form 3 typically includes

    While exact layouts may vary by organization or software, Form 3 commonly contains:

    • A complete list of drawing or model characteristics (often linked to balloon numbers)
    • Reference to the associated drawing zone or feature ID
    • Specification or tolerance limits for each characteristic
    • Measurement or verification method and gage or instrument used
    • Actual measured values or pass/fail indication
    • Status of each characteristic (e.g., acceptable, nonconforming, not applicable)
    • Links or references to any approved deviations, concessions, or waivers

    In digital FAI workflows, Form 3 is often generated from ballooned drawings or 3D models, with each characteristic tied to an inspection record and, in some cases, to upstream routing steps or operation plans.

    Role in manufacturing and quality workflows

    Within an AS9102 FAI package, Form 3 connects design data to inspection evidence. It is used to:

    • Demonstrate that every required characteristic has been identified and accounted for
    • Provide traceable inspection results for each characteristic
    • Support internal and customer reviews of FAI completeness and accuracy
    • Feed nonconformance, MRB, or CAPA workflows if any characteristic does not meet requirements

    Operationally, Form 3 may be integrated with MES, QMS, or specialized FAI software so that inspection results, gage IDs, operator IDs, and timestamps are captured electronically, supporting traceability and audit readiness.

    What Form 3 is not

    • It is not the cover sheet for the FAI; that is typically Form 1 (Part Number Accountability).
    • It is not the record of material, special processes, or functional tests; those are normally captured on Form 2 or in attached certifications and reports.
    • It is not a process control plan or control chart, although information from Form 3 can be used to inform those documents.

    Common confusion

    • Form 3 vs. ballooned drawing: The ballooned drawing visually numbers each characteristic. Form 3 is the structured list and inspection record for those numbered characteristics.
    • Form 3 vs. inspection report: Many organizations use Form 3 as their primary FAI inspection report, but routine in-process or final inspection reports outside of FAI may use different formats.

    Link to AS9102 and characteristic accountability

    Within AS9102 workflows, Form 3 is the central instrument for characteristic accountability. It provides evidence that the manufacturer has identified all applicable design characteristics, verified them using defined methods and equipment, and recorded the results in a way that can be reviewed, retained, and traced for future builds, changes, or audits.

  • Stage 2 Audit

    A Stage 2 Audit is the second, formal phase of a management system certification audit. It is typically performed by an accredited third-party certification body to determine whether an organization’s management system has been fully implemented and is effective in meeting the requirements of a chosen standard, such as ISO 9001, ISO 13485, or ISO 27001.

    What a Stage 2 Audit Includes

    The Stage 2 Audit builds on the Stage 1 Audit (readiness and documentation review) and focuses on how the system works in practice. In industrial and manufacturing environments, it commonly includes:

    • Review of implemented processes on the shop floor, in quality, maintenance, and supporting functions
    • Verification that procedures, work instructions, and records are used as defined in the management system
    • Interviews with operators, engineers, supervisors, and management to confirm understanding of roles and processes
    • Sampling of records and data in MES, QMS, ERP, LIMS, and other OT/IT systems for traceability, change control, and deviation/CAPA handling
    • Evaluation of compliance with regulatory or customer requirements that are referenced in the management system
    • Assessment of monitoring, measurement, internal audits, and management review activities

    The outcome of a Stage 2 Audit typically includes documented findings such as conformities, nonconformities, and opportunities for improvement. These findings are used by the certification body to decide whether to recommend initial certification of the management system.

    Where It Fits in the Certification Cycle

    A Stage 2 Audit is part of the initial certification process and normally follows this sequence:

    1. Stage 1 Audit: Review of documented information, scope, and readiness.
    2. Stage 2 Audit: Evaluation of implementation and effectiveness across relevant sites and processes.
    3. Surveillance Audits: Periodic follow-up audits to confirm ongoing conformity.
    4. Recertification Audit: Broader review before the certification cycle renews.

    Operational Meaning in Manufacturing

    In manufacturing, a Stage 2 Audit commonly involves:

    • Walking production lines to see how standard work, digital work instructions, and change controls are applied
    • Checking batch records, device history records, or lot genealogy for completeness and traceability
    • Reviewing how nonconforming product, deviations, and CAPAs are identified, investigated, and documented
    • Confirming calibration and maintenance controls for production and test equipment
    • Validating that data in MES, QMS, and ERP systems is controlled, retrievable, and linked to the management system requirements

    Common Confusion

    • Stage 2 Audit vs. Stage 1 Audit: Stage 1 focuses on readiness and high-level design of the management system. Stage 2 focuses on actual operation and evidence of effectiveness.
    • Stage 2 Audit vs. internal audit: An internal audit is performed by or on behalf of the organization itself to assess its own system. A Stage 2 Audit is performed by an external certification body as part of initial certification.
    • Stage 2 Audit vs. regulatory inspection: A Stage 2 Audit assesses conformity to a voluntary or contractual standard. A regulatory inspection is performed by a regulator to assess compliance with laws or regulations.

    Use in Regulated and High-Risk Industries

    In regulated environments, such as pharmaceuticals, medical devices, aerospace, or food and beverage, Stage 2 Audits often place particular emphasis on:

    • Document control and version management of procedures, specifications, and electronic records
    • Data integrity and access control for OT and IT systems used as quality or production records
    • Risk management processes that connect design, process control, and production monitoring
    • Evidence that the organization identifies, investigates, and corrects systemic issues

    While Stage 2 Audits are frequently associated with ISO-based certifications, the general concept applies to other formal certification schemes that use a staged audit model.

  • audit scope

    Audit scope is the formally defined boundary of an audit, describing what will be evaluated and what is excluded. In industrial and regulated manufacturing environments, it typically specifies which sites, processes, product lines, departments, time periods, standards, and information systems are covered by a specific audit activity.

    What audit scope usually includes

    In practice, an audit scope description often covers:

    • Locations and entities: plants, warehouses, design centers, or legal entities included in the audit
    • Processes and activities: manufacturing, maintenance, calibration, purchasing, design, software validation, document control, etc.
    • Products and services: product families, part ranges, or service types that fall under the audit
    • Time period: the timeframe of records to be sampled (for example, the last 12 months of production)
    • Standards and criteria: the specific regulations, customer specifications, or management system standards being assessed (for example, ISO 9001, AS9100, IATF 16949, regulatory rules)
    • Systems and data: which IT/OT systems are in scope (MES, ERP, QMS, document control, maintenance systems) and related interfaces

    For certification or compliance audits, the audit scope is typically documented in the audit plan and on the certificate itself, and is agreed in advance between the auditee and the auditing body.

    Operational meaning in manufacturing

    In manufacturing operations, audit scope helps determine:

    • Which production lines, cells, or maintenance areas auditors will visit
    • Which records, logs, and data sets (for example, batch records, travelers, NCs, CAPAs, calibration records) must be prepared
    • Which suppliers, outsourced processes, or logistics flows need to be included
    • Which digital systems and integrations (for example, MES to ERP interfaces, data historians, PLM links) must be available for review

    When organizations maintain multiple schemes (for example, ISO 9001 plus AS9100 or IATF 16949), each certification or regulatory program can have its own audit scope and may involve separate sites, processes, and system boundaries. This affects planning, documentation, and the number and type of audits that must be performed.

    What audit scope is not

    Audit scope is related to, but distinct from:

    • Audit objectives: why the audit is being performed (for example, certification, surveillance, supplier qualification, internal process check)
    • Audit criteria: the specific requirements used as the benchmark (standards, procedures, contracts, regulatory clauses)
    • Audit plan or schedule: the timing, agenda, and sequence of audit activities

    Audit scope sets the boundary of what is examined; it does not define the detailed audit checklist or sampling method.

    Common confusion

    • Audit scope vs. organizational scope of certification: The scope of certification describes what the organization is certified for (for example, design and manufacture of aerospace components). An individual audit's scope might be narrower, covering only one site or subset of processes at a given time.
    • Audit scope vs. risk scope: Risk assessments may consider a wide range of potential issues, while an audit scope may intentionally focus on a subset of those areas, such as special processes or high-risk suppliers.

    Link to the derived context

    When moving between or adding standards such as ISO 9001, AS9100, or IATF 16949, organizations often need to manage expanded or overlapping audit scopes. This can mean including additional sites, processes, or regulatory interfaces in external certification audits and aligning internal audit programs so that each scheme's requirements are covered within the defined scopes.

  • Partial FAI

    Partial FAI commonly refers to a First Article Inspection that is intentionally limited in scope to selected characteristics, features, or operations rather than the entire part or assembly. It is used in regulated and aerospace manufacturing environments when only a portion of the design, process, or tooling has changed and a full, from-scratch FAI is not required by the applicable procedures.

    What a Partial FAI Includes

    A partial FAI typically focuses on:

    • Characteristics directly affected by a design change, drawing revision, or engineering change notice
    • Features impacted by changes to manufacturing methods, tooling, fixtures, material source, or key process parameters
    • Operations moved to a new machine, line, or supplier that require verification of conformity
    • Specific nonconforming dimensions or features that were previously corrected and now need re-verification

    In this context, only the affected characteristics are re-ballooned, inspected, and documented, while unchanged characteristics from the baseline (previous full FAI) are referenced rather than re-inspected.

    What a Partial FAI Does Not Include

    A partial FAI does not normally include:

    • Re-verification of every drawing characteristic from scratch
    • Re-documentation of unchanged processes, materials, or suppliers, except as required by internal or customer procedures
    • Replacement of the original full FAI record, which remains the baseline

    Instead, it supplements the original FAI by documenting the specific changes and their verification results.

    Operational Use in Manufacturing Systems

    In MES, QMS, and digital inspection tools, a partial FAI may appear as:

    • A follow-on FAI record linked to the original full FAI for the same part number or configuration
    • An inspection plan that reuses the prior FAI ballooning but only activates a subset of characteristics for re-measurement
    • A workflow triggered by a drawing or process change where the system flags only affected operations or features for FAI-level inspection

    In aerospace contexts aligned with AS9102 practices, partial FAIs are often documented using the same core forms or data structures as a full FAI, but with clear identification that the submission is partial and which characteristics or sections are being updated.

    Common Confusion

    • Partial FAI vs. Full FAI: A full FAI covers all drawing requirements for a defined configuration of a part or assembly. A partial FAI covers only the characteristics affected by changes, with the original full FAI still serving as the baseline.
    • Partial FAI vs. Routine Production Inspection: Routine inspections or in-process checks may sample features to control quality. A partial FAI is a formal, documented verification tied to a change event and typically controlled under customer or standard requirements, not just internal sampling plans.

    Context in Regulated and Aerospace Environments

    In aerospace and other highly regulated sectors, partial FAIs are often used to maintain traceability of design and process changes without repeating a full qualification of the part each time. Organizations typically define when a partial FAI is allowed, how it must reference the baseline FAI, and how to manage records so that auditors can trace which configuration each FAI (full or partial) applies to.

  • control assessment

    A control assessment is a structured evaluation of how well defined controls are implemented, operating, and producing appropriate evidence. In industrial and regulated manufacturing environments, it commonly refers to assessing technical, procedural, and administrative controls related to cybersecurity, quality, safety, and compliance.

    What a control assessment includes

    In most regulated operational technology (OT) and information technology (IT) contexts, a control assessment typically covers:

    • Control design: Whether the control, as specified in policies, standards, or procedures, is suitable to address the identified risk or requirement.
    • Control implementation: Whether the control is actually deployed and configured as intended in systems, processes, and documentation.
    • Control operation: Whether the control functions consistently over time in day-to-day operations (for example, alarms triggering, access checks being applied, batch checks being executed).
    • Evidence and records: Whether logs, reports, batch records, audit trails, or other artifacts exist to demonstrate the control’s execution and traceability.

    Control assessments may be performed internally (self-assessments, internal audits) or by external parties (second-party supplier assessments, third-party audits). They can focus on cybersecurity controls, quality controls, environmental health and safety (EHS) controls, data integrity controls, or other control sets defined by standards and regulations.

    Operational context in manufacturing

    In manufacturing, a control assessment can involve examining both IT and OT layers, including:

    • Configuration and hardening of industrial control systems, HMIs, and network segments.
    • Access control and change control around MES, historians, and recipe management.
    • In-process quality checks, line clearance steps, and electronic batch record approvals.
    • Monitoring of alarms, interlocks, and safety functions, along with maintenance records.

    The assessment often relies on three basic techniques: reviewing documentation, examining configurations or process execution, and interviewing personnel responsible for the controls.

    Relation to standards and frameworks

    Many organizations base their control assessments on external frameworks and catalogs, such as cybersecurity control sets or quality system standards. For example, in information security and privacy, a control assessment may use procedures derived from a control assessment guideline that defines how to test, examine, and interview to determine control effectiveness and evidence needs. In regulated manufacturing, such documents are often used as reference models and tailored to fit legacy systems, integration constraints, and validation practices.

    What a control assessment is not

    A control assessment is not the same as:

    • A full risk assessment: A risk assessment identifies and analyzes risks. A control assessment focuses on controls that address those risks and how they perform.
    • A certification or approval: A control assessment produces findings and evidence, but does not itself guarantee compliance, certification, or regulatory acceptance.
    • A one-time test: While assessments are often periodic, they are usually part of an ongoing cycle of monitoring, remediation, and re-assessment.

    Common confusion

    The term “control assessment” is sometimes used interchangeably with:

    • Audit: An audit is typically a formal, scoped evaluation against specific requirements. A control assessment can be less formal and may be focused on control operation rather than overall system compliance.
    • Gap analysis: A gap analysis compares current practices to a target state or standard. A control assessment is more focused on the actual existence, implementation, and performance of controls, not just presence or absence.

    In practice, organizations may blend these activities, but separating the concepts helps clarify objectives and outputs.