For most machining shops pursuing AS9100 registration, the NCR and corrective action process is the area that gets them into trouble on audit. Not because they don't have nonconformances — every shop does — but because they don't document them correctly, don't isolate nonconforming material properly, and write corrective actions that address symptoms instead of root causes. This guide covers Clause 8.7 and 10.2 from the shop floor up. See how we apply this for aerospace & defense manufacturers.

8.7
AS9100 clause for
nonconforming product
control
~30%
of initial registration
audit major NCs are
NCR/CAR process findings
30–90
days: typical CAR
closure window before
surveillance escalation
In this guide
  1. What Counts as a Nonconformance Under AS9100
  2. Nonconforming Material Control: Clause 8.7
  3. Writing an NCR That Actually Documents the Problem
  4. Root Cause Analysis: 5 Why, Fishbone, and 8D
  5. The Corrective Action Request (CAR) Process
  6. Verifying Effectiveness: Closing the Loop
  7. Frequently Asked Questions

What Counts as a Nonconformance Under AS9100

A nonconformance under AS9100 is any failure to meet a specified requirement — whether that requirement is a dimensional tolerance on a drawing, a procedural step in a work instruction, or a documentation requirement in a job packet. The standard doesn't limit this to hardware failures. A missing inspection record is a nonconformance. A procedure that wasn't followed is a nonconformance. An operator who used an outdated revision of a setup sheet is a nonconformance.

The distinction between types matters for how you handle them:

Product nonconformances

These are hardware failures — a dimension that's out of tolerance, wrong material, a surface finish that didn't meet spec, a feature that's missing. Product nonconformances require physical disposition: the parts go to the NCM (nonconforming material) area, get tagged, and can't be shipped until they're dispositioned. These are the most visible type and the ones shops track most consistently.

Process nonconformances

These are procedural failures — a step that was skipped, a record that wasn't completed, a verification that was bypassed. Process nonconformances are frequently underreported because they don't produce a tangible bad part. If an operator set up a job without completing the required first-piece verification and the parts happened to be in tolerance, many shops would never write an NCR. AS9100 requires you to. The procedure was violated; that's a nonconformance regardless of part outcome.

Nonconformances vs. deviations and waivers

A deviation is a pre-production authorization to depart from a requirement — the customer approves a process or material change before work begins. A waiver is a post-production authorization for a specific lot of product that doesn't meet requirements — the customer agrees to accept parts that are technically out of spec. Both require documented customer approval. Neither is a substitute for an NCR — the deviation or waiver documents the authorization; the NCR documents what actually happened.

Clause 10.2 sets out the core requirements: detect, document, disposition, determine root cause, take corrective action, verify effectiveness. Each step must be documented. Skipping documentation even when the action was taken is a nonconformance in itself — the standard requires records, not just action.

Nonconforming Material Control: Clause 8.7

Clause 8.7 requires that nonconforming product be identified and controlled to prevent unintended use or delivery. For a machining shop, this translates to a physical process: parts that fail inspection or are identified as nonconforming must be moved to a designated NCM area, tagged, and held until dispositioned. They can't sit at a work cell, can't be on a shipping pallet, and can't be mixed with conforming parts.

Physical NCM area setup

The NCM area doesn't have to be elaborate, but it must be unambiguous. A dedicated shelf or bin with a clear visual identifier — a red placard, tape outline, or labeled container — is sufficient for a small shop. What matters is that any employee who walks past it can tell immediately that the parts in that area are on hold. Auditors walk the shop floor looking for physical evidence of NCM control — if your NCM area isn't immediately identifiable, that's a finding.

Tagging requirements

Every part or lot in the NCM area needs a physical tag or label that identifies: the job or work order number, the part number and revision, the quantity, the reason for rejection, and the date it was placed in NCM. Pre-printed NCM tags are inexpensive and significantly reduce the chance of an incomplete tag. A handwritten sticky note that says "bad part" is not compliant — it doesn't provide the traceability the standard requires.

The four dispositions

Once a part is in NCM, it must be formally dispositioned. AS9100 allows four options:

What auditors look for in the NCM area

During a Stage 2 audit, the registrar will physically visit your NCM area. They're checking: Is it physically segregated from conforming parts? Are parts tagged with job numbers, part numbers, and rejection reason? Is your NCM log current — does it match what's physically in the area? Are all tagged parts documented in your NCR system? Any part in the NCM area that isn't in your NCR log is a finding. Any item in your NCR log that isn't physically tagged is a finding. The NCM area and the NCR log must reconcile exactly.

Writing an NCR That Actually Documents the Problem

Most NCR forms that fail an audit fail for the same reason: the description of the nonconformance is an opinion, not objective evidence. "Part bad" or "dimension off" or "doesn't look right" aren't NCR descriptions — they're annotations. An NCR must document objective evidence: measured values, observed conditions, the specific requirement that was violated.

Required fields on every NCR

What makes a bad NCR

The most common NCR writing failure is describing the symptom, not the nonconformance. "Operator error" is not a nonconformance description — it's an implied cause. "Surface finish does not meet Ra 32 requirement" is a nonconformance description. The NCR documents what happened; the root cause section documents why. Don't conflate the two.

The second most common failure is missing measurement data. If the nonconformance is dimensional, the NCR must include the measured value, the specified value, and the tolerance. If it's a visual or workmanship issue, the NCR should reference the applicable specification and describe what was observed in specific, reproducible terms. A photo attached to the NCR is best practice for visual nonconformances.

NCR vs. CAR: don't conflate them on a single form. An NCR documents what happened — what was found, what was affected, how it was dispositioned. A CAR documents how the problem is fixed — root cause, corrective action, and verification. These are two distinct records. Some shops combine them on one form, which is fine — but the two sections must be clearly delineated. An NCR that jumps straight to "corrective action: retrain operator" without documenting the nonconformance with objective evidence isn't a compliant NCR, regardless of whether the corrective action was appropriate.

Root Cause Analysis: 5 Why, Fishbone, and 8D

Root cause analysis is where most machining shops fail the corrective action process. Not because they skip it, but because they stop too early. The standard requires that you identify the root cause of the nonconformance — not the proximate cause, not the immediate trigger, but the underlying systemic reason the nonconformance occurred and wasn't caught before it did.

5 Why — for most machining NCRs

Five Why analysis is the right tool for the majority of machining nonconformances: single-cause failures that trace back through a chain of contributing factors. It takes 10–15 minutes, requires no special training, and produces a defensible root cause for simple to moderate complexity NCRs. The method: start with the nonconformance statement and ask "why" repeatedly until you reach a systemic cause that a corrective action can address.

Example: Out-of-tolerance OD on a turned part.

The corrective action that follows addresses the systemic issue: update the setup sheet template to include required offset register fields, add a QC verification step before first-piece inspection sign-off.

Fishbone (Ishikawa) — for recurring or multi-cause unknowns

When you have a recurring nonconformance with unclear source, or when you know multiple factors contributed but can't isolate which is primary, a fishbone diagram is more appropriate than 5 Why. Fishbone analysis maps potential causes across the standard six categories: Machine, Method, Material, Measurement, Man (Personnel), Environment. It's a structured brainstorming tool that ensures you don't miss a category of cause. For a machining shop, it's most useful when you're getting sporadic dimensional failures that don't trace to a single setup event.

8D — for customer-required formal response

8D (Eight Disciplines) is the structured corrective action process required by many aerospace and defense primes when they issue a supplier corrective action request (SCAR). If you receive an 8D request from a customer, you must follow the 8D format — it's a contractual requirement. The eight disciplines are: D1 team formation, D2 problem description, D3 interim containment, D4 root cause analysis, D5 corrective action selection, D6 corrective action implementation, D7 recurrence prevention, D8 team recognition. The customer receives a formal 8D report, not just a CAR form.

The most common RCA failure: "operator error" as a root cause

AS9100 auditors will reject root cause statements like "operator error," "human error," or "operator did not follow procedure" as root causes. These are proximate causes — they describe what happened, not why the system allowed it to happen. A genuine root cause answers the question: what about the process, procedure, training, or design made it possible for a person to make this error, and what prevented it from being caught? If your root cause statement points at a person rather than a system, you've stopped too early. Corrective action that targets one person ("retrained operator") also fails this test — it doesn't address the systemic condition that made the error possible for any operator.

The Corrective Action Request (CAR) Process

A CAR is the formal record of your response to a nonconformance. Where the NCR documents what happened, the CAR documents what you did about it — and how you know the fix actually worked. CARs come in two types: internal (initiated by your own quality system) and customer-initiated (the customer sends you a SCAR or 8D request).

Required CAR fields

Internal vs. customer-initiated CARs

Internal CARs are generated by your own quality system — from internal audit findings, management review actions, or NCRs from your shop floor. These are fully within your control to schedule and close. Customer-initiated CARs (often called SCARs — Supplier Corrective Action Requests) come with contractual response time requirements that take precedence over your internal schedule. Read the contract carefully: a typical aerospace SCAR requires an initial response (containment plan and preliminary root cause) within 10 business days and final CAR closure within 30 business days. Missing these deadlines is a contract compliance issue, not just a quality system issue.

Typical timelines

Containment vs. corrective action: both are required

Containment stops the bleeding — it prevents nonconforming product from reaching the customer and ensures in-process parts are held and inspected. Corrective action prevents recurrence — it addresses the root cause so the same nonconformance can't happen again. Both are required under AS9100; many shops document only containment and call it a CAR. An auditor will ask: what systemic change did you make? If the answer is "we inspected the parts and they passed," that's containment — not corrective action. The corrective action must address why the nonconformance occurred in the first place, and the record must show that a systemic change was made.

Verifying Effectiveness: Closing the Loop

Effectiveness verification is the step most often skipped — and the most common reason CARs get flagged as incomplete on audit. The standard requires that after implementing a corrective action, you verify that it actually prevented recurrence. You don't close a CAR when the corrective action is implemented; you close it when you've confirmed it worked.

What "verified effective" means

Effectiveness verification means re-examining the same process or part type after the corrective action has been in place long enough to evaluate whether the nonconformance has recurred. The time window depends on the process cycle — if you run the affected part type weekly, 30 days is sufficient; if the affected process is triggered infrequently, 90 days is more appropriate. The verification check must be documented by someone other than the person who implemented the corrective action — this is the independence requirement that prevents self-certification bias.

Three outcomes of effectiveness verification

The management review connection

Open CAR age and recurrence patterns are required management review inputs under Clause 9.3. At every management review, you must report: how many CARs are open, how old are the oldest open CARs, and has any corrective action been found not effective. Auditors use management review records to verify this — they'll ask to see the management review minutes and confirm that CAR status was discussed. If your management review records don't mention CARs, that's a finding against Clause 9.3, not Clause 10.2.

AS9100 Practical Guide Series
3 Quality Management System Guide 4 AS9100 Revisions & Audit Prep
5 Nonconformances & Corrective Action You are here

Frequently Asked Questions

A nonconformance is a failure that happened — a part that didn't meet the requirement as produced. A deviation is a pre-approved departure from a requirement before production begins — the customer authorizes a process change or material substitution before work starts. A waiver is a post-production authorization to accept a specific lot of product that technically doesn't meet spec. Deviations and waivers require documented customer approval; neither replaces the NCR, which documents what actually occurred. The distinction matters for how you disposition the product and what records you retain.

AS9100 doesn't specify a fixed closure timeframe — it requires that corrective actions be implemented and verified effective, with timelines appropriate to the risk. In practice, industry norms are: internal CARs within 30 days for product issues, 45 days for process-level changes. Customer-initiated SCARs are governed by the contract, typically 10 business days for initial response and 30 business days for full closure. Surveillance auditors will look at the age of open CARs — CARs open beyond 90 days without documented extension justification are typically cited as findings on surveillance audits.

Customer notification is required when: (1) nonconforming product was shipped before detection, (2) the customer is requesting a Use As Is disposition that requires their engineering approval, or (3) the contract specifically requires supplier notification of all nonconformances above a certain severity threshold. Most AS9100 contracts have a "suspect product" clause that requires notification within a defined timeframe (often 24–72 hours) when you discover a product quality issue that may affect delivered product. Check your specific contract. Failing to notify when required is a contract breach, not just a quality system finding.

For the majority of machining nonconformances, 5 Why is the right tool — it's fast, requires no special training, and produces a defensible root cause for single-cause failures. Use fishbone (Ishikawa) when you have a recurring issue with unclear cause, or when multiple potential causes exist and you need to evaluate them systematically. Use 8D only when a customer requires it — it's a formal structured process that takes significantly more time and resources than 5 Why. Don't over-engineer the RCA for simple nonconformances; the standard requires appropriate rigor, not maximum complexity.

Verified effective means you've confirmed that the corrective action prevented the nonconformance from recurring — not just that the action was implemented, but that it worked. Verification requires re-examining the same process or part type after the corrective action has been in place (typically 30–90 days, depending on process cycle). The verification must be performed by someone other than the person who implemented the corrective action — this independence requirement prevents self-certification. Document the verification date, who performed it, what they checked, and the outcome. If the CAR is closed without effectiveness verification, it's an open finding.

Yes — if multiple NCRs share the same root cause, it's appropriate to issue a single CAR that addresses all of them. This is common when a process change causes multiple related failures across different jobs or part numbers. In this case, all NCRs reference the common CAR, and the CAR documents each NCR as an instance of the underlying systemic issue. The advantage is that the corrective action and effectiveness verification are handled once, at the system level, rather than duplicated across multiple CARs. Most quality management systems allow this linkage; the key requirement is that every NCR has a documented disposition and corrective action path, even if that path runs through a consolidated CAR.

Immediate steps: (1) write the NCR for all potentially affected product — including delivered units, (2) notify the customer per your contract's suspect product clause (typically within 24–72 hours), (3) initiate containment for any remaining in-process or finished inventory, (4) work with the customer to determine disposition of delivered product (return, field inspection, UAI with engineering authorization). AS9100 requires a documented process for this scenario — often called a "suspect shipment" or "escape" procedure. The CAR that follows must address how the escape occurred (not just the nonconformance itself) and what change prevents a future escape from reaching the customer.

There's no absolute number — auditors look at age and trend, not count. A shop with 10 open CARs, all within 30 days of opening and all with documented corrective action plans, is in better shape than a shop with 3 open CARs, two of which have been open for 6 months without documented extension justification. The flags auditors look for: CARs open past 90 days without documented rationale for the extension, CARs with no documented root cause (just containment), and CARs where effectiveness verification was never performed. In management review records, auditors expect to see CAR aging discussed — if your management review minutes never mention open CAR count or age, that's a Clause 9.3 finding regardless of your actual CAR numbers.

Working on your NCR/CAR process for AS9100 registration?

We understand the documentation requirements. Upload your drawing and describe your requirements — we'll respond within 4 business hours.