If you're buying CNC-machined parts for an aerospace or defense program, AS9100 certification isn't a nice-to-have. It's the entry gate. This guide breaks down what the standard actually requires — not a marketing summary, but the specific clauses that show up on audit checklists. See how we apply this for aerospace & defense manufacturers.
lose their certification
on first surveillance audit
nonconformances
in machining shops
for a machine shop to
achieve AS9100 registration
- What Is AS9100 and Where Does It Come From?
- Why CNC Machining Suppliers Need AS9100
- Key AS9100 Requirements for CNC Machining
- How ApexMetal Meets AS9100D Requirements
- Quality Management System Guide (Guide 3 of 5)
- 3.1 — Quality Policy
- 3.2 — Document Control
- 3.3 — Process Mapping
- 3.4 — Audit Protocols
- 3.5 — Corrective Action Procedures
- What an AS9100 Audit Actually Looks Like
- Frequently Asked Questions
What Is AS9100 and Where Does It Come From?
AS9100 is a quality management system (QMS) standard for the aerospace industry, built on top of ISO 9001. It was developed by the International Aerospace Quality Group (IAQG) to create a common, auditable quality baseline for suppliers across the global aerospace supply chain.
The current version is AS9100D Rev D (released 2016, with the IAQG rolling out transition guidance). The "D" revision tightened requirements around risk-based thinking, supply chain management, and manufacturing feasibility — which hit machining shops particularly hard, since process planning and tooling verification are explicitly in scope.
AS9100 sits at the top of a family of aerospace QMS standards:
- AS9100 — for aerospace design and/or manufacturing organizations (this is what most machining suppliers pursue)
- AS9110 — for aerospace repair stations (engines, components)
- AS9120 — for aerospace distributors and brokers
If a machine shop designs and manufactures CNC parts, AS9100 is the right standard. AS9100C (earlier version) is still seen in some legacy supply chains, but IAQG has formally transitioned to AS9100D and most primes have updated their quality requirements accordingly.
Why CNC Machining Suppliers Need AS9100
Three reasons come up in every prime contractor conversation:
1. It's a hard gate for aerospace programs
Boeing, Lockheed Martin, Northrop Grumman, Raytheon, and most major primes won't put a non-AS9100 shop on an approved supplier list for new programs. Some existing contracts require registration within 12 months of award. For commercial aerospace customers (Honeywell, Collins, Safran), AS9100 is often contractually required before a PO is issued.
2. ITAR and DFARS flow-down requirements
Defense programs that flow down 252.246-7004 (Work Breakdown Structures) and 252.244-7000 (Quality Management System requirements) typically tie back to AS9100 as the accepted QMS framework. A shop that's chasing ITAR registration without an AS9100 QMS is building on sand — auditors will flag the gap.
3. AS9100 registration signals operational maturity
The standard requires documented procedures for everything from work order authorization to nonconforming material disposition. That paperwork isn't bureaucracy — it's the traceable proof that a machined part was made to spec by a repeatable process. Procurement teams at primes and subs use AS9100 registration as a first-pass filter to separate suppliers who have their act together from shops running on tribal knowledge.
Bottom line: If you're quoting aerospace or defense CNC work and don't have AS9100, expect the conversation to stall at the quality review. It's not a question of "if" you need it — it's a question of timing.
Key AS9100 Requirements for CNC Machining
AS9100D contains 52 numbered clauses (compared to ISO 9001's 10). For a CNC machining supplier, these are the clauses that generate the most audit findings:
Clause 8.1 — Operational Planning and Control
This is where most machining shops get tripped up. Clause 8.1 requires that you have documented requirements for planning and controlling production — and that the planning addresses manufacturing feasibility before work starts. That means your process planning (travel cards, setup sheets, CNC programs) must be reviewed and approved against the drawing before the first part runs.
Clause 8.1.2 (AS9100 add-on)
Critical for machining: The shop must verify that manufacturing processes, tooling, and CNC programs are capable and properly released before production runs. Any process that isn't defined in an approved work order — including one-off prototypes — falls under this clause.
Clause 8.3 — Design and Development (if the shop qualifies parts)
Not all machining shops do design work. But if you're creating part geometry, drafting production drawings, or generating toolpaths from customer models, AS9100's Clause 8.3 requires a controlled design process: design inputs, design outputs, design review, design verification, and design validation before the part goes to production.
Clause 8.4 — Control of Externally Provided Processes, Products, and Services
AS9100 tightened purchasing controls versus ISO 9001. Machining shops need to evaluate and approve their raw material suppliers, heat treat vendors, and special process suppliers (anodizing, plating, NDT). For raw material, this means material certs (AS9100 typically requires material trace to a primary mill or distributor with test reports that tie back to heat/lot numbers).
Clause 8.5.1 — Control of Production Service Information
Work orders, router sheets, CNC programs, and setup sheets must be controlled documents — revision-controlled, approved before use, and updated when drawings change. Shop travelers that don't reflect current rev levels are a common finding on AS9100 audits.
Clause 8.5.2 — Validation of Processes for Production and Service Provision
This covers special processes that produce results which can't be fully inspected afterward — like heat treatment, welding, or aging. If your shop performs these, you need documented process validation and periodic re-validation.
Clause 8.5.5 — Control of Inspection, Measuring, and Test Equipment
CMM calibration to NIST-traceable standards, gauge calibration schedules, and documented calibration records. Most AS9100 audit findings in this area involve CMM calibration frequency (too infrequent for measurement uncertainty reasons) and inadequate calibration certificates from third-party cal labs.
Clause 8.7 — Control of Nonconforming Outputs
The Nonconforming Material (NCM) process needs to be documented: how nonconforming parts are identified, segregated, dispositioned (rework, repair, scrap, use-as-is), and who has authority to disposition each type. For aerospace, "use-as-is" disposition typically requires customer approval.
Clause 8.7.2 (AS9100 add-on)
For machining, NCM documentation must include the root cause of the nonconformance and the corrective action taken. This isn't just paperwork — it's the corrective action log that auditors review to verify systemic issues are being addressed, not just patched over.
Clause 10.2 — Nonconformity and Corrective Action
Corrective actions must be documented, verified for effectiveness, and reviewed by management. AS9100 auditors will look for evidence that the same NC keeps appearing — if you had a tooling repeatability issue in March and the same issue appears in August, that's a finding because the corrective action wasn't effective.
Clause 8.5.4 (AS9100 add-on) — First Article Inspection (FAI)
AS9100 requires first article inspection for product realizations where the customer has specified the requirement (which is most aerospace programs). FAI per AS9102 verifies that the first-off part matches the engineering drawing before production continues. For a CNC shop, FAI typically involves CMM inspection of the first part, comparison to all drawing dimensions, and documentation on AS9102 Forms 1, 2, or 3.
How ApexMetal Meets AS9100D Requirements
ApexMetal operates a quality management system built to AS9100D specifications. Here's how we address the clauses that matter most for CNC machining suppliers:
Process Planning & Work Order Control
Every job gets a reviewed and approved work order before the machine runs. Our process planning includes setup sheets, approved tooling lists, and CNC program revision control. Programming changes require a formal revision and re-approval — no informal hot-fixes on the shop floor.
Material Traceability
We receive raw material with heat/lot traceability to primary mill certifications. Material certs are retained in the job packet and linked to the work order. For aerospace-grade materials (Ti-6Al-4V, 4130, 15-5PH), we verify mill certs against material specifications (AMS, ASTM) before the material enters production.
CMM Inspection & Calibration
Our CMM is calibrated on a scheduled basis by a NIST-traceable third-party calibration lab with reported measurement uncertainty. Calibration certificates are on file and available for customer review or audit. In-process inspection is performed at setup, first-off, and periodic intervals during production runs.
Nonconforming Material Process
Any out-of-tolerance part is immediately tagged, segregated, and entered into our NCM log. Disposition (rework, return to supplier, use-as-is) requires quality manager review. For aerospace programs requiring customer notification, we contact the buyer before any disposition is finalized.
First Article Inspection
We perform FAI on all first-off production parts for aerospace programs. AS9102 Forms 1/2/3 documentation is provided with the job — or per the customer's preferred format. FAI data is retained for the program duration per contract requirements.
Corrective Action
Root cause analysis and corrective action are documented for every NCR. We track NCR trends to identify systemic issues and verify corrective action effectiveness before closing the NCR. Management reviews the NCR log quarterly.
Supplier Control
All heat treat, plating, and special process suppliers are pre-approved, periodically reviewed, and held to documented requirements. Sub-tier supplier certificates (NADCAP accreditation where applicable) are on file.
AS9100 Quality Management System: Practical Guide for CNC Machinists
This is Guide 3 of 5 in the AS9100 practical series. This section walks through the day-to-day QMS components a machining shop actually needs to build, document, and maintain — quality policy, document control, process maps, internal audit protocols, and corrective action procedures. If you're preparing for Stage 1 documentation review or working through your first surveillance audit, start here.
3.1 — Quality Policy
The quality policy is the foundation of your AS9100 QMS. It's a public commitment to your customers and your organization — it defines what "quality" means at your shop, who is responsible for it, and how everyone knows you're living up to it.
What AS9100 requires: Clause 5.2 mandates a quality policy that is appropriate to your organization, commits to meeting applicable requirements, and provides a framework for establishing quality objectives. It must be communicated to all personnel, maintained as a controlled document, and reviewed at defined intervals (typically annually during management review).
What a machinist's quality policy should contain
- Commitment statement — one to two sentences stating the shop's commitment to meeting customer and regulatory requirements. Example: "ApexMetal is committed to delivering machined parts that conform to customer specifications, regulatory requirements, and our own quality standards — on time, every time."
- Applicability — explicitly scope the policy to CNC machining operations, raw material procurement, and special process coordination.
- Improvement commitment — the policy should commit to continual improvement, which in practice means the NCR/CAR system, management review, and internal audit results are fed back into process changes.
- Objectives framework — the policy is the source document for quality objectives. Objectives flow from the policy; the policy doesn't need to state specific numbers, but it must commit to setting and reviewing them.
Common finding: Quality policy isn't reviewed
AS9100 auditors routinely find that quality policies haven't been reviewed in years, or were signed by someone no longer at the company. The policy must be reviewed at management review and re-signed when it changes — and it needs to reflect your actual current operations, not a boilerplate template from registration. Keep a signature log showing who authorized it and when.
Quality objectives
Quality objectives translate the policy into measurable goals. For a machining shop, these typically include:
- On-time delivery rate — e.g., "95% of jobs shipped on or before the committed ship date"
- First-pass yield — e.g., "90% of jobs pass final inspection on first submission, no rework required"
- Customer complaint response time — e.g., "all customer complaints acknowledged within 24 hours, resolved within 5 business days"
- Nonconformance rate — e.g., "NCR rate below 1.5% of parts produced, by process type"
- Calibration compliance — e.g., "100% of inspection equipment calibrated on schedule, zero missed calibrations"
Objectives should be documented, communicated to relevant personnel, monitored (typically quarterly at management review), and updated when they're met or when conditions change.
3.2 — Document Control (Clause 7.5)
Document control is where most machining shops feel the most friction — and where most first-time audit findings live. AS9100 requires that every document that governs how you make parts be revision-controlled, approved before use, and accessible to the people who need it.
What counts as a controlled document in a machining shop
- Quality Manual — top-level QMS document describing your organization's quality policy and the QMS structure
- Procedures — documented work instructions for QMS processes (NCM procedure, corrective action procedure, internal audit procedure, etc.)
- Work orders / router sheets — production-authorizing documents that must reference the correct drawing revision
- CNC programs — revision-controlled, approved before production use
- Setup sheets / process travelers — approved before the job runs; linked to the work order
- Inspection plans — controlled by revision number, referencing the applicable drawing rev
- Calibration records — retained as controlled records (different from controlled documents, but still auditable)
- Customer drawings — received under document receipt control; current revision identified and maintained
The document control procedure: what you actually need
A documented procedure doesn't need to be complex — but it must cover the full lifecycle of every controlled document:
- Creation and approval — Who creates the document? Who approves it? For work orders, the quality manager and production supervisor typically sign. For CNC programs, the programmer and a second reviewer sign off. The procedure defines who has approval authority for each document type.
- Revision control — Documents get a revision number (e.g., Rev A, Rev B, Rev 1, Rev 2). Any change to a document — even a small tooling update on a setup sheet — requires a revision bump and re-approval before the revised document goes into use.
- Distribution and access — How do personnel on the shop floor access current revisions? This is where many shops fail: a machinist running a job with a setup sheet that shows an old drawing rev is a nonconformance. The procedure must define the distribution method (shared drive with access control, physical binder with revision status page, etc.) and ensure obsolete revisions are removed.
- Retention and disposal — Controlled documents must be retained for the period required by the customer or contract (typically 10 years for aerospace programs). The procedure defines retention periods and how obsolete documents are archived or destroyed.
Version control in practice: The most common document control failure in a machining shop is an operator running a job from a setup sheet that was updated after the work order was released, but the setup sheet revision wasn't bumped. Solution: any document that changes after release must go through the formal revision process. No informal "I'll just update it on the spot" revisions — even if the change is trivial.
Records retention
Records are different from controlled documents. Records are the evidence that a process was completed correctly — inspection reports, calibration certificates, NCM dispositions, CAR forms, training records. AS9100 requires records to be legible, retrievable, protected from damage, and retained for the specified period. For most aerospace programs, records must be retained for a minimum of 10 years after the end of the program or contract.
Records vs. Documents: The Practical Test
Ask: "Is this a document that tells people what to DO, or is this a record of what was DONE?" A work order tells people what to do — it's a controlled document. An inspection report records what was done — it's a record. Both need control, but different controls. Records get filled out and filed; they don't get revised, they get replaced with new entries. Documents get revised; they're controlled by version number.
3.3 — Process Mapping (Clause 4.4)
AS9100 requires organizations to identify, sequence, and interact with the processes that make up the QMS (Clause 4.4). For a machining shop, this means mapping the key processes that affect product quality — from quote through delivery — and documenting how they connect and interact.
Why process mapping matters for a machine shop
Process mapping isn't a compliance exercise — it exposes gaps. When you walk through your operation on a process map, you find steps that aren't defined, handoffs where information gets lost, and approval points that don't have documented authority. It's also the tool auditors use to understand your shop floor: if you can walk them through your process map and show them exactly where each control happens, the audit goes faster and you look more competent.
Core processes for a CNC machining shop
A typical machining shop QMS has these interacting processes:
- Customer order / quote receipt — Review RFQ for technical completeness, program requirements (ITAR, AS9100 flow-down), and feasibility. Document acceptance criteria. This is where Clause 8.2.1 (review of requirements) happens.
- Process planning / programming — Create work order, setup sheets, CNC programs. Perform manufacturing feasibility review per Clause 8.1.2. Approved before production starts.
- Procurement / material receipt — Verify material certs against spec (AMS/ASTM), check traceability to heat/lot number, inspect material condition. Retain certs in job packet.
- Production / CNC machining — Execute work order, perform in-process inspection at defined intervals, document any deviations.
- Final inspection / FAI — CMM inspection against drawing. First-off vs. in-process vs. final inspection points defined per job traveler. AS9102 documentation for FAI.
- Nonconforming material / NCR — Tag, segregate, disposition. Root cause and corrective action documented. Customer notification if required.
- Corrective action / CAR — Document root cause, implement corrective action, verify effectiveness, close CAR.
- Delivery / shipment — Verify all documentation complete (traveler, certs, inspection reports, AS9102 forms), pack per requirements, ship.
Process interactions: the input-output model
AS9100 asks you to view processes as interacting inputs and outputs. A useful mental model for your shop:
- Process planning receives a drawing (input) and produces an approved work order and CNC program (output)
- Material receipt receives raw material (input) and produces a verified, traceable material lot (output)
- CNC machining receives a work order + approved material + CNC program (input) and produces a machined part (output)
- Inspection receives a machined part (input) and produces an inspection report (output)
Where the outputs of one process feed into the inputs of another is where control points belong — and where auditing verifies the handoff is working.
Process flows for AS9100D
Your quality manual should include process flow diagrams or descriptions that cover the core manufacturing processes. These don't need to be Visio masterpieces — a clear text-based flowchart or swim-lane diagram is fine for a small shop. The key requirement is that the flow shows: decision points (the diamond shapes), approval points, inspection points, and the outputs of each process.
3.4 — Audit Protocols (Clause 9.2)
Internal audits are AS9100's primary mechanism for verifying that your QMS is actually working as documented. Clause 9.2 requires a documented internal audit procedure, a risk-ranked audit schedule, trained auditors, and documented audit results.
The internal audit schedule: where to focus
You don't audit everything at the same frequency. AS9100 allows (and good practice requires) risk-based scheduling — processes with higher quality risk get audited more frequently. A typical small machining shop audit schedule:
- Work order control / process planning — every 6 months. High risk: wrong drawing rev is the most common aerospace quality failure.
- NCM / NCR process — every 6 months. Auditors look at open NCRs, closed NCR files, and whether root cause and corrective action are complete.
- CMM calibration / inspection equipment — every 12 months. Check calibration certificates, calibration labels, calibration frequency compliance.
- Material traceability — every 12 months. Spot-check recent job packets for complete material certs and traceability back to mill heat/lot number.
- Corrective action / CAR closure — every 6 months. Verify CARs are closed and effectiveness has been confirmed.
- Supplier control — annually for approved suppliers; triggered review when issues arise.
- Document control — every 12 months. Spot-check work orders for correct revision levels.
- Management review records — every 12 months. Verify management review is being conducted and action items are tracked.
Audit frequency for critical processes: If you had an NCR in the last 90 days involving a critical process (CMM calibration, NCM disposition, work order control), run a follow-up audit on that process within 30 days of the NCR. Auditors look for evidence that systemic issues are being actively monitored — a triggered audit in response to an NCR is exactly the right behavior.
Auditor qualifications
AS9100 doesn't require auditors to have a formal certification, but they must be trained on internal audit methodology and must be independent of the process being audited. A shop owner auditing their own quality manager's work is not independent. Common arrangements for a small machining shop:
- Quality manager conducts audits on production floor processes (independent of the production manager, if roles are separate)
- Production supervisor audits quality management processes
- Third-party consultant conducts one internal audit per year as a gap assessment before the registrar audit
- Cross-functional auditors — trained personnel from different departments audit each other's processes
All auditors should be trained on AS9100 Clause 9.2 requirements and internal audit methodology. Training records (sign-in sheets, course completion certificates) are auditable evidence.
Audit process: opening, conducting, closing
- Audit planning — Issue an audit plan at least one week before the audit. The plan names the process to be audited, the auditor(s), the date, and the scope. Auditees should have time to prepare.
- Opening meeting — Brief meeting with the process owner to review the scope, confirm access to records, and set expectations.
- Document review — Auditor reviews the procedure, work instructions, and previous audit records for the process.
- Shop floor / process observation — Auditor observes the process in action, compares actual practice to the procedure, and interviews personnel.
- Finding documentation — Any deviation from the procedure or standard is documented as a nonconformance or observation. NCs are categorized (major, minor, opportunity for improvement). Evidence is attached to the audit record.
- Closing meeting — Auditor presents findings to the process owner. Corrective action assignments are made with due dates. The process owner signs the audit report acknowledging the findings.
- Follow-up — Corrective actions are tracked to closure. Auditor verifies effectiveness before closing the finding.
Internal audit records
Every audit produces an audit report containing: audit scope, auditor(s), date, findings (with evidence), corrective action assignments, and closure status. These records are subject to AS9100 document control and must be retained for the required period. Management review should include a summary of audit findings and corrective action status.
3.5 — Corrective Action Procedures (Clause 10.2)
Corrective action (also called CAR — Corrective Action Request) is where the PDCA cycle closes. AS9100 Clause 10.2 requires that nonconformities and corrective actions be documented, that root cause is identified (not just symptoms), that corrective action is implemented and verified, and that management reviews the effectiveness of corrective actions.
When does a CAR get opened?
CARs are triggered by:
- Internal NCR — a nonconforming part or process that can't be dispositioned as-is without root cause analysis
- Customer complaint — a defect found at the customer or downstream in the supply chain
- Internal audit finding — a systemic nonconformance identified during an internal audit
- Registrar audit finding — a major or minor nonconformance raised during the external audit
- Regulatory or program requirement — a finding from a government or prime contractor audit
- Trend analysis — if the same type of NCR appears two or more times in a quarter, a CAR should be opened regardless of severity
The CAR lifecycle: six steps
Step 1 — CAR initiation and description
The CAR form is opened with: CAR number (auto-incremented), date opened, source (NCR #, customer complaint, audit finding), product/part affected, job number, and a clear description of the nonconformance. The description should state the symptom, not the cause — "Dimension X out of tolerance on part 1234, Job 5678" not "Machine calibration issue caused part to be out of spec."
Step 2 — Containment (immediate action)
Before root cause is determined, immediate containment actions must be taken to prevent additional nonconforming parts from reaching the customer. In a machining shop, containment typically includes: quarantine of suspect parts, 100% inspection of parts in the same lot, and verification that shipped parts from the affected batch are identified and contacted if necessary.
Containment is not corrective action — it's damage control. Document it on the CAR form but don't confuse it with root cause correction.
Step 3 — Root cause analysis
This is the most important step and the most commonly short-cutted. AS9100 requires identification of the root cause (and, if applicable, the contributing cause). Symptoms don't count. "Operator error" is not a root cause — it's a symptom of a system that allowed the error to happen.
For machining shops, common root cause categories:
- Process / procedure — the documented process didn't specify the control needed, or the procedure wasn't followed
- Training / competency — the operator wasn't adequately trained on the process or the requirement
- Equipment / tooling — machine, tool, or fixture was not capable or was in poor condition
- Material / input — raw material or outsourced process didn't meet specification
- Work order / document control — wrong revision of drawing, setup sheet, or work order was used
- Measurement / inspection — inspection method was inadequate or measuring equipment was out of calibration
Use a structured method: the 5 Whys (ask "why" five times to trace from symptom to root cause) or Fishbone/Ishikawa diagram are both acceptable for AS9100. Document which method was used — the root cause analysis methodology is itself auditable.
AS9100 Clause 10.2: Root Cause vs. Symptom
Example of a symptom-only root cause: "Tool holder had excessive runout." Correct root cause: "Tool holder had excessive runout because the drawbar torque was not verified at the start of shift, and the procedure does not specify drawbar torque verification. Runout exceeded the tolerance specified in the setup sheet, causing dimensional nonconformance on features 3, 4, and 5."
The difference matters: fixing "tool holder runout" fixes one instance. Fixing the procedure to require drawbar torque verification eliminates the entire category of failure.
Step 4 — Corrective action definition and implementation
Corrective action addresses the root cause — not just the symptom. Define the specific action that will prevent recurrence, assign it to a responsible person, and set a due date. Examples of corrective actions in a machining context:
- Procedure change — Add drawbar torque verification to the machine start-up procedure
- Work instruction update — Revise the setup sheet to specify the torque value and verification method
- Training — Train all CNC operators on the updated procedure; document training in personnel records
- Equipment change — Replace the worn drawbar; add torque wrench to the calibration program
- Document control — Update the work order revision to reference the new procedure revision; remove old setup sheets from circulation
Step 5 — Effectiveness verification
Before closing the CAR, verify that the corrective action actually worked. This means: observe that the new procedure is in use, check that the nonconformance hasn't recurred in the same process within a defined period (typically 30–90 days), and confirm with a second inspection or audit. Document the verification evidence on the CAR form.
Common mistake: Closing a CAR immediately after implementing corrective action, without waiting to see if it held. AS9100 auditors will look for evidence of a verification period. If you closed the CAR on day 3 and the corrective action was implemented on day 2, that's not enough time to verify it's holding.
Step 6 — CAR closure and management review
CAR closure requires: root cause documented, corrective action implemented, effectiveness verified, and approval by the quality manager (or designated authority). Closed CARs are retained in the CAR log and reviewed at management review to identify trends. If the same root cause appears in multiple CARs in a quarter, that's a systemic issue — escalate to management review and consider a process audit of that area.
CAR metrics: what auditors look for
AS9100 auditors evaluate the CAR system by looking at:
- Open CAR age — CARs open longer than 30–60 days without a documented reason get flagged
- Recurrence rate — If the same NCR type appears twice in six months and two separate CARs are opened, auditors will ask why the first CAR didn't prevent recurrence — a finding on corrective action effectiveness
- Root cause quality — "Operator error" and "material issue" without further analysis are common findings
- Management review — CAR metrics (open CAR count, age, recurrence) should be a standing agenda item at management review
What an AS9100 Audit Actually Looks Like
AS9100 audits are conducted by an accredited registrar (body). The most common path for a machining shop:
Stage 1 — Documentation Review
A registrar reviews your QMS documentation: quality manual, procedures, work instructions, forms. They verify you have documented responses to every AS9100 clause. This is a paper audit — no shop floor visit. Most shops spend 3–6 months building this documentation before Stage 1.
Stage 2 — Registration Audit
A two- to four-day on-site audit. Auditors interview personnel, review records, and observe shop floor operations. They'll look at recent job packets, NCR files, calibration records, and purchasing documents. Common focus areas in a machining shop: work order revision control, NCM disposition, CMM calibration, and corrective action closure.
Surveillance Audits (Annual)
Once registered, you undergo annual surveillance audits — typically 1–2 days — to verify the QMS is being maintained. Every three years, a recertification audit re-validates the entire system.
Ongoing commitment: AS9100 registration isn't a one-time project. Maintaining it means keeping records current, closing NCRs on time, training personnel, and running internal audits. Most shops budget 0.5–1 FTE dedicated to QMS maintenance after registration.
Frequently Asked Questions
AS9100 is based on ISO 9001 but adds aerospace-specific requirements. Think of it as ISO 9001 + aerospace tailwind. The base ISO 9001 clauses are there, but AS9100 adds about 110 additional requirements specific to aerospace (risk-based thinking, manufacturing feasibility, FAI, supplier control, etc.). A shop can be ISO 9001 certified but not AS9100 certified — and most aerospace primes know the difference.
AS9100 requires first article inspection when the customer specifies it (which most aerospace programs do). AS9102 is the standard form set for FAI. For high-volume or repetitive production runs, many programs allow reduced frequency FAI after initial qualification — but the initial FAI is non-negotiable on new programs. Whether or not FAI is required, the shop needs a documented procedure describing their FAI process.
Most machining shops spend 12–18 months from decision to registration audit. The timeline breaks down roughly as: 3–6 months building the QMS documentation, 2–3 months running internal audits and addressing gaps, 2–4 months with the registrar for Stage 1 and Stage 2 audits. Shops with existing ISO 9001 registration typically move faster (6–12 months) because they already have a QMS foundation.
Registrar fees vary by organization and scope, but typical costs for a small machining shop (under 50 employees, one location) are: documentation review and Stage 1: $3,000–$6,000; Stage 2 registration audit: $6,000–$12,000; annual surveillance: $4,000–$8,000 per year. Additional costs include internal audit time, consultant fees (if used), and the labor to build and maintain the QMS. Total first-year cost is typically $15,000–$30,000 for a small shop.
It flows down. Most DFARS contracts and defense program quality requirements reference AS9100 as the expected QMS framework. If you're a sub-tier supplier to a prime on a defense contract, the prime's purchasing quality requirements likely require AS9100 or equivalent. For ITAR-controlled programs, AS9100 is almost universally specified. The practical impact: if you're in the defense supply chain and don't have AS9100, your customer will require it before issuing a PO.
A major nonconformance (system-level failure) requires documented corrective action before the registrar will issue or maintain registration. The shop typically has 30–90 days to provide evidence of root cause analysis and corrective action implementation. A major NC on a critical clause (8.1, 8.5.5, 10.2) can delay or prevent registration. Surveillance audit findings that aren't addressed can escalate to suspension of registration. The audit process is collaborative — auditors want to see you're taking it seriously, not just paper-correcting the issue.
No — they're different accreditations. NADCAP (National Aerospace and Defense Contractors Accreditation Program) covers special processes: heat treatment, non-destructive testing, chemical processing, etc. AS9100 is a QMS standard that covers overall organizational quality management. A shop can be AS9100 registered without NADCAP accreditation (if they don't perform NADCAP-scope processes), and vice versa. For most CNC machining shops, AS9100 registration is the baseline; NADCAP is added when the shop performs heat treat or NDT in-house.
Ready to quote your aerospace CNC part?
Upload your drawing and we'll respond within 4 business hours.