For most machining shops pursuing AS9100 registration, the NCR and corrective action process is the area that gets them into trouble on audit. Not because they don't have nonconformances — every shop does — but because they don't document them correctly, don't isolate nonconforming material properly, and write corrective actions that address symptoms instead of root causes. This guide covers Clause 8.7 and 10.2 from the shop floor up. See how we apply this for aerospace & defense manufacturers.
nonconforming product
control
audit major NCs are
NCR/CAR process findings
closure window before
surveillance escalation
What Counts as a Nonconformance Under AS9100
A nonconformance under AS9100 is any failure to meet a specified requirement — whether that requirement is a dimensional tolerance on a drawing, a procedural step in a work instruction, or a documentation requirement in a job packet. The standard doesn't limit this to hardware failures. A missing inspection record is a nonconformance. A procedure that wasn't followed is a nonconformance. An operator who used an outdated revision of a setup sheet is a nonconformance.
The distinction between types matters for how you handle them:
Product nonconformances
These are hardware failures — a dimension that's out of tolerance, wrong material, a surface finish that didn't meet spec, a feature that's missing. Product nonconformances require physical disposition: the parts go to the NCM (nonconforming material) area, get tagged, and can't be shipped until they're dispositioned. These are the most visible type and the ones shops track most consistently.
Process nonconformances
These are procedural failures — a step that was skipped, a record that wasn't completed, a verification that was bypassed. Process nonconformances are frequently underreported because they don't produce a tangible bad part. If an operator set up a job without completing the required first-piece verification and the parts happened to be in tolerance, many shops would never write an NCR. AS9100 requires you to. The procedure was violated; that's a nonconformance regardless of part outcome.
Nonconformances vs. deviations and waivers
A deviation is a pre-production authorization to depart from a requirement — the customer approves a process or material change before work begins. A waiver is a post-production authorization for a specific lot of product that doesn't meet requirements — the customer agrees to accept parts that are technically out of spec. Both require documented customer approval. Neither is a substitute for an NCR — the deviation or waiver documents the authorization; the NCR documents what actually happened.
Clause 10.2 sets out the core requirements: detect, document, disposition, determine root cause, take corrective action, verify effectiveness. Each step must be documented. Skipping documentation even when the action was taken is a nonconformance in itself — the standard requires records, not just action.
Nonconforming Material Control: Clause 8.7
Clause 8.7 requires that nonconforming product be identified and controlled to prevent unintended use or delivery. For a machining shop, this translates to a physical process: parts that fail inspection or are identified as nonconforming must be moved to a designated NCM area, tagged, and held until dispositioned. They can't sit at a work cell, can't be on a shipping pallet, and can't be mixed with conforming parts.
Physical NCM area setup
The NCM area doesn't have to be elaborate, but it must be unambiguous. A dedicated shelf or bin with a clear visual identifier — a red placard, tape outline, or labeled container — is sufficient for a small shop. What matters is that any employee who walks past it can tell immediately that the parts in that area are on hold. Auditors walk the shop floor looking for physical evidence of NCM control — if your NCM area isn't immediately identifiable, that's a finding.
Tagging requirements
Every part or lot in the NCM area needs a physical tag or label that identifies: the job or work order number, the part number and revision, the quantity, the reason for rejection, and the date it was placed in NCM. Pre-printed NCM tags are inexpensive and significantly reduce the chance of an incomplete tag. A handwritten sticky note that says "bad part" is not compliant — it doesn't provide the traceability the standard requires.
The four dispositions
Once a part is in NCM, it must be formally dispositioned. AS9100 allows four options:
- Use As Is (UAI) — The part doesn't meet the drawing but will still function. This requires written customer approval. You cannot UAI a part unilaterally; the customer or their designated engineering representative must sign off. Some contracts prohibit UAI entirely.
- Rework to drawing — The part can be brought into conformance through additional machining, deburring, or other operations. After rework, the part must pass a full re-inspection and be re-documented. The NCR must record the rework operation and the re-inspection results.
- Scrap — The part is unusable and must be physically destroyed or mutilated to prevent inadvertent use. Mutilation (cutting, grinding, stamping SCRAP) is required for aerospace parts in most quality plans to ensure scrapped parts can't be reintroduced into the supply chain.
- Return to Supplier (RTS) — For raw material, purchased components, or sub-assemblies that arrived nonconforming. The supplier NCR process applies; the supplier typically issues a corrective action response to the shop before the next order is accepted.
What auditors look for in the NCM area
During a Stage 2 audit, the registrar will physically visit your NCM area. They're checking: Is it physically segregated from conforming parts? Are parts tagged with job numbers, part numbers, and rejection reason? Is your NCM log current — does it match what's physically in the area? Are all tagged parts documented in your NCR system? Any part in the NCM area that isn't in your NCR log is a finding. Any item in your NCR log that isn't physically tagged is a finding. The NCM area and the NCR log must reconcile exactly.
Writing an NCR That Actually Documents the Problem
Most NCR forms that fail an audit fail for the same reason: the description of the nonconformance is an opinion, not objective evidence. "Part bad" or "dimension off" or "doesn't look right" aren't NCR descriptions — they're annotations. An NCR must document objective evidence: measured values, observed conditions, the specific requirement that was violated.
Required fields on every NCR
- Date — when the nonconformance was detected
- Job/Work Order Number — ties the NCR to the job packet
- Part Number and Revision — the specific part and drawing revision that defines the requirement
- Quantity — how many parts are affected; if unknown, the lot quantity is documented as suspect
- Description of nonconformance — objective evidence: "OD measured 1.2487" per CMM, drawing requires 1.2500" ±0.0005", delta = −0.0008"" is a compliant description; "OD out of tolerance" is not
- Detected by — who found it (name and role) and where (incoming inspection, in-process, final inspection, customer return)
- Disposition decision — one of the four dispositions, with authorization
- Authorized by — the person with authority to disposition the nonconformance (QA Manager, QC Lead, or designated authority per your quality plan)
What makes a bad NCR
The most common NCR writing failure is describing the symptom, not the nonconformance. "Operator error" is not a nonconformance description — it's an implied cause. "Surface finish does not meet Ra 32 requirement" is a nonconformance description. The NCR documents what happened; the root cause section documents why. Don't conflate the two.
The second most common failure is missing measurement data. If the nonconformance is dimensional, the NCR must include the measured value, the specified value, and the tolerance. If it's a visual or workmanship issue, the NCR should reference the applicable specification and describe what was observed in specific, reproducible terms. A photo attached to the NCR is best practice for visual nonconformances.
NCR vs. CAR: don't conflate them on a single form. An NCR documents what happened — what was found, what was affected, how it was dispositioned. A CAR documents how the problem is fixed — root cause, corrective action, and verification. These are two distinct records. Some shops combine them on one form, which is fine — but the two sections must be clearly delineated. An NCR that jumps straight to "corrective action: retrain operator" without documenting the nonconformance with objective evidence isn't a compliant NCR, regardless of whether the corrective action was appropriate.
Root Cause Analysis: 5 Why, Fishbone, and 8D
Root cause analysis is where most machining shops fail the corrective action process. Not because they skip it, but because they stop too early. The standard requires that you identify the root cause of the nonconformance — not the proximate cause, not the immediate trigger, but the underlying systemic reason the nonconformance occurred and wasn't caught before it did.
5 Why — for most machining NCRs
Five Why analysis is the right tool for the majority of machining nonconformances: single-cause failures that trace back through a chain of contributing factors. It takes 10–15 minutes, requires no special training, and produces a defensible root cause for simple to moderate complexity NCRs. The method: start with the nonconformance statement and ask "why" repeatedly until you reach a systemic cause that a corrective action can address.
Example: Out-of-tolerance OD on a turned part.
- Why 1: The OD was machined 0.0008" undersize. Why? The tool offset was entered incorrectly at setup.
- Why 2: The wrong offset value was entered. Why? The operator read from the setup sheet, which didn't specify which offset register to use for the finish OD.
- Why 3: The setup sheet was ambiguous. Why? The setup sheet template doesn't have a dedicated field for finish OD offset — operators write it in the general notes section.
- Why 4: The template doesn't require a dedicated field. Why? The setup sheet was designed without input from QA; engineering and production never aligned on required data fields.
- Root cause: The setup sheet template lacks required fields for critical offset registers, leaving documentation to operator discretion with no procedural requirement for a second check.
The corrective action that follows addresses the systemic issue: update the setup sheet template to include required offset register fields, add a QC verification step before first-piece inspection sign-off.
Fishbone (Ishikawa) — for recurring or multi-cause unknowns
When you have a recurring nonconformance with unclear source, or when you know multiple factors contributed but can't isolate which is primary, a fishbone diagram is more appropriate than 5 Why. Fishbone analysis maps potential causes across the standard six categories: Machine, Method, Material, Measurement, Man (Personnel), Environment. It's a structured brainstorming tool that ensures you don't miss a category of cause. For a machining shop, it's most useful when you're getting sporadic dimensional failures that don't trace to a single setup event.
8D — for customer-required formal response
8D (Eight Disciplines) is the structured corrective action process required by many aerospace and defense primes when they issue a supplier corrective action request (SCAR). If you receive an 8D request from a customer, you must follow the 8D format — it's a contractual requirement. The eight disciplines are: D1 team formation, D2 problem description, D3 interim containment, D4 root cause analysis, D5 corrective action selection, D6 corrective action implementation, D7 recurrence prevention, D8 team recognition. The customer receives a formal 8D report, not just a CAR form.
The most common RCA failure: "operator error" as a root cause
AS9100 auditors will reject root cause statements like "operator error," "human error," or "operator did not follow procedure" as root causes. These are proximate causes — they describe what happened, not why the system allowed it to happen. A genuine root cause answers the question: what about the process, procedure, training, or design made it possible for a person to make this error, and what prevented it from being caught? If your root cause statement points at a person rather than a system, you've stopped too early. Corrective action that targets one person ("retrained operator") also fails this test — it doesn't address the systemic condition that made the error possible for any operator.
The Corrective Action Request (CAR) Process
A CAR is the formal record of your response to a nonconformance. Where the NCR documents what happened, the CAR documents what you did about it — and how you know the fix actually worked. CARs come in two types: internal (initiated by your own quality system) and customer-initiated (the customer sends you a SCAR or 8D request).
Required CAR fields
- NCR reference number — every CAR traces back to a specific NCR
- Root cause statement — the verified root cause from your RCA (not an interim hypothesis)
- Immediate containment action — what was done to stop the nonconformance from spreading (quarantine, hold on shipment, 100% inspection of in-process parts)
- Systemic corrective action — what change prevents recurrence (procedure update, training, tooling change, process control addition)
- Implementation evidence — documented proof that the corrective action was actually implemented (updated procedure revision, training record, inspection results)
- Responsible person — who owns the corrective action
- Target date — when the corrective action will be complete
- Effectiveness verification date — when you'll check whether the corrective action worked
Internal vs. customer-initiated CARs
Internal CARs are generated by your own quality system — from internal audit findings, management review actions, or NCRs from your shop floor. These are fully within your control to schedule and close. Customer-initiated CARs (often called SCARs — Supplier Corrective Action Requests) come with contractual response time requirements that take precedence over your internal schedule. Read the contract carefully: a typical aerospace SCAR requires an initial response (containment plan and preliminary root cause) within 10 business days and final CAR closure within 30 business days. Missing these deadlines is a contract compliance issue, not just a quality system issue.
Typical timelines
- Internal CAR closure target: 30 days from NCR date for product nonconformances; 45 days for process nonconformances involving procedure updates or training
- Customer SCAR initial response: typically 10 business days for preliminary root cause and containment plan
- Customer SCAR final closure: typically 30 business days for full corrective action documentation
- Effectiveness verification: 30–90 days after corrective action implementation, depending on process cycle frequency
Containment vs. corrective action: both are required
Containment stops the bleeding — it prevents nonconforming product from reaching the customer and ensures in-process parts are held and inspected. Corrective action prevents recurrence — it addresses the root cause so the same nonconformance can't happen again. Both are required under AS9100; many shops document only containment and call it a CAR. An auditor will ask: what systemic change did you make? If the answer is "we inspected the parts and they passed," that's containment — not corrective action. The corrective action must address why the nonconformance occurred in the first place, and the record must show that a systemic change was made.
Verifying Effectiveness: Closing the Loop
Effectiveness verification is the step most often skipped — and the most common reason CARs get flagged as incomplete on audit. The standard requires that after implementing a corrective action, you verify that it actually prevented recurrence. You don't close a CAR when the corrective action is implemented; you close it when you've confirmed it worked.
What "verified effective" means
Effectiveness verification means re-examining the same process or part type after the corrective action has been in place long enough to evaluate whether the nonconformance has recurred. The time window depends on the process cycle — if you run the affected part type weekly, 30 days is sufficient; if the affected process is triggered infrequently, 90 days is more appropriate. The verification check must be documented by someone other than the person who implemented the corrective action — this is the independence requirement that prevents self-certification bias.
Three outcomes of effectiveness verification
- Effective — close the CAR: No recurrence of the nonconformance in the review period. The corrective action is documented as verified effective, the CAR is closed, and the closed date is recorded. The management review at the next cycle notes the closure.
- Partially effective — extend with revised action: The nonconformance recurred, but at a reduced rate, or in a different form suggesting the root cause was only partially addressed. The CAR stays open; the root cause analysis is revisited; the corrective action is revised and a new effectiveness check is scheduled.
- Not effective — reopen the RCA: The nonconformance recurred at the original rate, or in the same form, indicating the root cause was misidentified. The CAR is reopened as a major finding, a new root cause analysis is required, and management is notified. This also triggers a management review input under Clause 9.3.
The management review connection
Open CAR age and recurrence patterns are required management review inputs under Clause 9.3. At every management review, you must report: how many CARs are open, how old are the oldest open CARs, and has any corrective action been found not effective. Auditors use management review records to verify this — they'll ask to see the management review minutes and confirm that CAR status was discussed. If your management review records don't mention CARs, that's a finding against Clause 9.3, not Clause 10.2.
Frequently Asked Questions
A nonconformance is a failure that happened — a part that didn't meet the requirement as produced. A deviation is a pre-approved departure from a requirement before production begins — the customer authorizes a process change or material substitution before work starts. A waiver is a post-production authorization to accept a specific lot of product that technically doesn't meet spec. Deviations and waivers require documented customer approval; neither replaces the NCR, which documents what actually occurred. The distinction matters for how you disposition the product and what records you retain.
AS9100 doesn't specify a fixed closure timeframe — it requires that corrective actions be implemented and verified effective, with timelines appropriate to the risk. In practice, industry norms are: internal CARs within 30 days for product issues, 45 days for process-level changes. Customer-initiated SCARs are governed by the contract, typically 10 business days for initial response and 30 business days for full closure. Surveillance auditors will look at the age of open CARs — CARs open beyond 90 days without documented extension justification are typically cited as findings on surveillance audits.
Customer notification is required when: (1) nonconforming product was shipped before detection, (2) the customer is requesting a Use As Is disposition that requires their engineering approval, or (3) the contract specifically requires supplier notification of all nonconformances above a certain severity threshold. Most AS9100 contracts have a "suspect product" clause that requires notification within a defined timeframe (often 24–72 hours) when you discover a product quality issue that may affect delivered product. Check your specific contract. Failing to notify when required is a contract breach, not just a quality system finding.
For the majority of machining nonconformances, 5 Why is the right tool — it's fast, requires no special training, and produces a defensible root cause for single-cause failures. Use fishbone (Ishikawa) when you have a recurring issue with unclear cause, or when multiple potential causes exist and you need to evaluate them systematically. Use 8D only when a customer requires it — it's a formal structured process that takes significantly more time and resources than 5 Why. Don't over-engineer the RCA for simple nonconformances; the standard requires appropriate rigor, not maximum complexity.
Verified effective means you've confirmed that the corrective action prevented the nonconformance from recurring — not just that the action was implemented, but that it worked. Verification requires re-examining the same process or part type after the corrective action has been in place (typically 30–90 days, depending on process cycle). The verification must be performed by someone other than the person who implemented the corrective action — this independence requirement prevents self-certification. Document the verification date, who performed it, what they checked, and the outcome. If the CAR is closed without effectiveness verification, it's an open finding.
Yes — if multiple NCRs share the same root cause, it's appropriate to issue a single CAR that addresses all of them. This is common when a process change causes multiple related failures across different jobs or part numbers. In this case, all NCRs reference the common CAR, and the CAR documents each NCR as an instance of the underlying systemic issue. The advantage is that the corrective action and effectiveness verification are handled once, at the system level, rather than duplicated across multiple CARs. Most quality management systems allow this linkage; the key requirement is that every NCR has a documented disposition and corrective action path, even if that path runs through a consolidated CAR.
Immediate steps: (1) write the NCR for all potentially affected product — including delivered units, (2) notify the customer per your contract's suspect product clause (typically within 24–72 hours), (3) initiate containment for any remaining in-process or finished inventory, (4) work with the customer to determine disposition of delivered product (return, field inspection, UAI with engineering authorization). AS9100 requires a documented process for this scenario — often called a "suspect shipment" or "escape" procedure. The CAR that follows must address how the escape occurred (not just the nonconformance itself) and what change prevents a future escape from reaching the customer.
There's no absolute number — auditors look at age and trend, not count. A shop with 10 open CARs, all within 30 days of opening and all with documented corrective action plans, is in better shape than a shop with 3 open CARs, two of which have been open for 6 months without documented extension justification. The flags auditors look for: CARs open past 90 days without documented rationale for the extension, CARs with no documented root cause (just containment), and CARs where effectiveness verification was never performed. In management review records, auditors expect to see CAR aging discussed — if your management review minutes never mention open CAR count or age, that's a Clause 9.3 finding regardless of your actual CAR numbers.
Working on your NCR/CAR process for AS9100 registration?
We understand the documentation requirements. Upload your drawing and describe your requirements — we'll respond within 4 business hours.