If you went through AS9100 registration before 2016, you were working under Rev C. If you're coming in fresh or transitioning, you're dealing with AS9100D — and the differences aren't cosmetic. This guide covers what actually changed, what you'll need to update in your QMS, and how to structure your audit prep so you're not scrambling the week before the registrar shows up. See how we apply this for aerospace & defense manufacturers.
AS9100D added
over ISO 9001:2015
audits result in
at least one major NC
NC before registrar
suspends registration
Why AS9100 Revisions Happen
AS9100 revisions follow the ISO 9001 revision cycle with a lag. When ISO 9001 gets updated, the IAQG updates AS9100 to align — adding aerospace-specific requirements on top of the new ISO structure. AS9100D aligned with ISO 9001:2015, which introduced risk-based thinking as a core principle for the first time.
Revisions aren't cosmetic — they reflect real gaps the industry found in the previous version. Rev C was published in 2009; the aerospace supply chain changed dramatically between 2009 and 2016. Supply chain risk became a board-level concern. Digital thread concepts and model-based definition started showing up in major program requirements (Boeing's MBE initiative, Lockheed's digital transformation). The 2016 update was the IAQG's response to all of that.
For a machining shop, this means: if your QMS was built for Rev C, you're running an outdated standard. Primes have updated their quality requirements to reference AS9100D. Your registration is to Rev D — but if your documented procedures haven't caught up, you're one audit away from a finding.
AS9100C vs. AS9100D: What Actually Changed
The structural shift from Rev C to Rev D tracks the ISO 9001:2015 restructuring. Rev C followed the old Plan-Do-Check-Act ISO format with 10 clauses. Rev D follows the updated structure — but the changes that matter for a machining shop are substantive, not just renumbered:
1. Risk-based thinking (Clause 6.1)
This is the biggest conceptual shift. Rev C treated risk assessment as an add-on in certain clauses. Rev D makes risk-based thinking a foundational requirement across the entire QMS. For a machining shop, this means you need documented evidence that you're identifying risks in your processes and taking action to address them — not just react when something breaks. This shows up in operational planning, supplier evaluation, and equipment maintenance scheduling.
What this looks like on the shop floor
A machine that's had recurring calibration drift is a risk. Under Rev C, you'd fix it when it failed calibration. Under Rev D, the expectation is that you have a documented risk assessment for that machine, maintenance actions based on that risk, and records showing the risk was addressed. The auditor will look for: do you have a risk register? Have you evaluated your critical processes for risk? Are your preventive maintenance intervals based on risk, not just calendar time?
2. Organizational context (Clause 4.1)
Rev D requires you to identify internal and external issues that are relevant to your QMS purpose and strategic direction. This is a new requirement — you need to document your understanding of what your shop does, who your customers are, and what factors could affect your ability to deliver conforming parts consistently. For a small machining shop, this often takes the form of a brief SWOT-style assessment or a QMS scope statement that defines what you do, what you don't do, and who your target customers are.
3. Interested parties (Clause 4.2)
Rev D explicitly requires identifying "interested parties" — anyone with a stake in your QMS — and their requirements. Customers are the obvious ones. But it also includes regulatory bodies (FAA, DoD), primes as customers, and potentially sub-tier suppliers whose performance affects your output. You need to know who these parties are and what requirements they have that affect your QMS.
4. Enhanced supply chain controls (Clause 8.4)
Rev D tightened the requirements for controlling external providers significantly. The standard now explicitly requires risk-based evaluation of external providers, verification that purchased products and services meet requirements, and documented criteria for evaluation and re-evaluation. For machining shops, this means your raw material vendors, heat treat providers, and special process shops need documented evaluation files that are actively maintained — not just a vendor list from five years ago.
5. Manufacturing feasibility (Clause 8.1)
Rev D added explicit requirements for verifying manufacturing feasibility before production. This isn't new for most shops — it's been expected under Rev C as well — but Rev D tightened the documentation requirement. You need evidence that process planning reviewed the drawing, confirmed the shop had the capability and capacity to make the part, and that the work order was authorized before the machine touched material.
6. Counterfeit part prevention (Clause 8.1.4, AS9100 add-on)
Rev D explicitly added requirements for preventing the use of counterfeit or suspect parts. For a machining shop receiving raw bar, castings, or machined sub-assemblies, this means you need documented processes for verifying part authenticity, maintaining traceability, and reporting suspected counterfeit parts. This clause is often overlooked by small shops.
7. Work transfer requirements (Clause 8.1.2, Rev D change)
Rev D added explicit requirements for managing work transfers — when production moves between machines, shifts, or facilities. The standard requires documented processes for controlling these transfers and verifying that the receiving process maintains the same quality as the original. For a small shop, this typically means: when you move a job from one CNC to another, the work order documents the transfer and the new setup is verified before production continues.
Key insight: If your QMS documentation still has "Clause 4.1" as blank or "Not Applicable," you're already behind. Rev D organizational context and interested parties requirements are frequently cited as findings on registration audits for shops that haven't updated their quality manual since 2016.
The Rev C to Rev D Transition: What Your QMS Needs
If you're currently registered to AS9100C, your registrar will eventually require transition to AS9100D — the IAQG has sunset periods for revision transitions. Even if you're not yet registered, building to Rev D from the start saves you a transition audit later.
Gap assessment: where to start
The first step is a formal gap assessment. Go through each clause of AS9100D and compare it against your current QMS documentation. The most common gaps for machining shops moving from Rev C to Rev D:
- Risk-based thinking — No documented risk register, no evidence of risk assessment in operational planning, preventive maintenance based on calendar intervals rather than risk analysis
- Organizational context (4.1) — Quality manual doesn't define organizational context, no documented understanding of internal/external issues affecting QMS
- Interested parties (4.2) — No documented identification of interested parties or their requirements
- Supply chain risk (8.4) — Vendor evaluation records outdated or missing, no documented re-evaluation process
- Counterfeit parts (8.1.4) — No documented process for verifying part authenticity and reporting suspected counterfeit parts
- Work transfer (8.1.2) — No documented process for controlling work transfer between machines or shifts
Quality manual update checklist
Your quality manual needs to be updated to reflect the Rev D structure. Specifically, address these in your manual update:
- Reword the purpose and scope to reflect organizational context and interested parties
- Add or update the risk-based thinking section to describe how risks and opportunities are identified, assessed, and addressed
- Update Clause 4 to include organizational context and interested parties documentation requirements
- Revise Clause 8 operational planning section to include manufacturing feasibility documentation
- Update supply chain control section to include risk-based evaluation criteria
- Add counterfeit parts prevention procedure reference
- Add work transfer procedure reference
Typical timeline: Rev C to Rev D transition
For a small machining shop with an existing Rev C QMS: 2–4 months to complete gap assessment and documentation updates, 1–2 months to implement new procedures and train personnel, 1–2 months with your registrar for transition audit. Total: 4–8 months from decision to fully transitioned. Shops that skip the formal gap assessment almost always underestimate the timeline.
Running Internal Audits That Actually Work
Internal audits are your early warning system. If you're doing them right, the registrar audit is a formality — you're just showing an auditor what you already know. If you're doing them wrong (checking boxes, scheduling audits right before the registrar visit), they won't catch anything and you'll be fixing problems the auditor finds instead of problems you found yourself.
Audit schedule: risk-based, not arbitrary
Clause 9.2 doesn't require every process to be audited at the same frequency. The standard allows — and good practice demands — risk-based scheduling. For a typical machining shop, the risk ranking looks like this:
- Quarterly (highest risk): Work order control and document revision control — wrong drawing rev is the most common aerospace quality failure and the most common audit finding
- Every 6 months: Nonconforming material/NCR process, corrective action/car closure — these are the second and third most common audit findings
- Annually: CMM calibration and inspection equipment, material traceability in job packets, supplier control records, management review documentation, training records
Within each frequency, prioritize based on recent performance. If you had an NCR on the NCM process last month, audit it now — not on the scheduled 6-month cycle. Auditors look for evidence that you're running audits in response to actual conditions, not just a calendar.
Conducting the audit: the three-part method
Every internal audit has three components — document review, process observation, and personnel interviews. Skipping any of the three is the most common internal audit failure.
Step 1: Document review
Before you step on the shop floor, review the procedure and the records for the process. Ask: Does the procedure exist? Is it current (correct revision)? Are the most recent job records consistent with the procedure? What's in the last three NCR files for this process? Look at the actual job packets, not just the procedure text. The procedure tells you what should happen; the records tell you what actually happened.
Step 2: Process observation
Watch the process happen. Don't just ask the operator if they follow the procedure — watch them do it and compare their practice to the documented procedure. Note where they deviate, where the procedure is unclear, where the procedure specifies something that doesn't match how the work actually flows. Process observation is where most internal audit findings are actually generated.
Step 3: Personnel interview
Talk to the people doing the work. Ask open-ended questions: "Walk me through how you know which revision of the setup sheet to use." "What do you do if a part is out of tolerance?" "How do you know if a supplier's material cert is legitimate?" If the operator has to think hard about how to answer, that's often a training or procedure gap — even if they technically know what to do, the procedure isn't making it obvious enough.
Writing the audit report
Every audit finding needs: what was observed, which procedure or clause it violates, and evidence (photograph, record name, or statement from auditee). Categorize findings as major NC, minor NC, or Observation — the definitions matter for how you handle them. An Observation is not a nonconformance; it's a potential improvement. Don't call something a nonconformance if it doesn't actually violate a requirement.
Corrective actions must be assigned to a specific person with a due date. Track them to closure. Verify effectiveness before closing — this means running a follow-up check within 30–90 days, not just accepting the corrective action as complete when the action is taken.
Internal audit vs. registrar audit: the mindset difference
Internal audit is collaborative — you're trying to find problems before they become bigger problems. Registrar audit is evidential — the auditor is looking for documented proof that your QMS is working as you say it is. That means internal audit findings should be honest and action-oriented. If you're only finding minor observations on internal audit and then getting hit with majors by the registrar, your internal audit isn't probing deeply enough.
Management Review: What the Standard Actually Requires
Management review is the Clause 9.3 requirement that top management review the QMS at defined intervals to ensure its continuing suitability, adequacy, and effectiveness. For most machining shops, this is done quarterly — that's a good balance between staying on top of metrics and not creating bureaucracy that distracts from production.
What management review must cover (Clause 9.3.1)
AS9100D lists specific inputs that must be reviewed. These aren't optional:
- Results of audits — internal audit findings, status of corrective actions from previous management reviews, any external audit results
- Customer feedback — customer complaints, NCRs attributed to customer-found defects, feedback from primes on recent orders
- Process performance and QMS conformity — on-time delivery rate, first-pass yield, NCR rate, calibration compliance
- Nonconformities and corrective actions — open CAR age, recurrence patterns, trending analysis
- Follow-up from previous management reviews — what was decided last time, what's been acted on, what's still pending
- Changes that affect the QMS — new programs, new customers with specific quality requirements, new equipment, changes in organizational context or interested party requirements
- Resources — are you adequately resourced to maintain the QMS and meet customer requirements? This is where understaffing or equipment gaps need to be flagged
- Risks and opportunities — what risks have been identified since the last review? What actions have been taken?
Management review output (Clause 9.3.2)
The output of management review must include decisions and actions related to:
- Continual improvement opportunities
- Any need for changes to the QMS
- Resource needs
The output must be retained as a record — this means you need meeting minutes or a formal management review report, signed and dated, showing what was discussed and what was decided. "We talked about quality stuff" is not a management review record.
Running an effective management review meeting
For a small machining shop, the management review meeting doesn't need to be a formal multi-day session. It does need to be documented, consistent, and honest. A practical structure:
- Agenda shared 24 hours in advance — Quality manager sends agenda with metrics summary ahead of time. This gives management time to think, not just react in the meeting.
- Metrics review (15–20 minutes) — NCR rate by process type, CAR open count and age, on-time delivery, first-pass yield, calibration status. Use actual numbers, not general impressions.
- Customer and audit review (10 minutes) — Any open NCRs, customer complaints, results of recent internal or external audits.
- Open action items from previous review (5 minutes) — What was decided last time, what's been done, what's still pending.
- Discussion and decisions (20–30 minutes) — What needs to change, what resources are needed, what improvement actions should be prioritized.
- Action items recorded and assigned — Who is responsible for what, by when. These get reviewed at the next management review.
Common management review finding: The meeting happened but the output was documented as "Reviewed. No issues." That's not a management review record — it's a sign the review wasn't actually conducted to the standard. Auditors will flag this. A management review that didn't result in any decisions or actions is itself a finding: if the QMS is truly performing perfectly, that's fine — but you need documented evidence, not just an attendance sheet.
Registrar Audit Preparation: Stage 1 and Stage 2
Registration follows a two-stage audit process. Most shops fail Stage 1 not because their QMS is bad, but because they didn't prepare the documentation package properly. Stage 2 is where the auditor comes to your shop floor — that's where preparation matters most.
Stage 1 — Documentation Review
Stage 1 is a paper audit. The auditor reviews your QMS documentation — quality manual, procedures, work instructions, forms — and verifies you have documented responses to every AS9100D clause. They look for:
- Complete quality manual with all clauses addressed
- Documented procedures for every mandatory process
- Forms and records that capture required data
- Evidence that your QMS scope is correctly defined
- Quality policy and objectives that are documented and communicated
Stage 1 typically happens at your facility (or via video conference) and takes 1–2 days for a small machining shop. The outcome is either: you pass Stage 1 and proceed to Stage 2 within 6 months, or you receive findings that must be addressed before Stage 2 can be scheduled.
Stage 1 preparation checklist
- Quality manual review — Does every clause 4–10 have a documented response? Is it consistent with Rev D structure? Does it reflect your actual operations, not a template you copied from somewhere?
- Procedure cross-reference — Go through every procedure and verify that the records it references actually exist and are being completed. "We have a procedure for FAI" means nothing if you don't have actual FAI records in your job packets.
- Form completion sample — Pull three to five recent job packets and verify all forms are filled out completely. Auditors will ask to see recent records, not just templates.
- NCR/CAR log review — Pull your NCR log. Do all open NCRs have root cause and corrective action documented? Are closed CARs verified for effectiveness? Auditors look at NCR handling immediately.
- Management review records — Do you have documented management review records for the last 2–4 quarters? If you don't, that's a finding — management review is one of the first things auditors look at.
Stage 2 — Registration Audit
Stage 2 is the on-site audit. Auditors will be at your facility for 2–4 days. They'll interview personnel, observe shop floor operations, and review records. Here's how to prepare:
Week before Stage 2
- Brief all personnel on the audit — what it is, what auditors will ask, what to do if they don't know the answer (it's okay to say "I don't know, let me check and get back to you")
- Pull a "audit ready" job packet — the most recent completed job with a complete NCR file, FAI records, calibration records, and supplier certs. Auditors will often use the most recent complete package as their starting point.
- Verify document control — confirm the documents on the shop floor are current revisions. Walk the floor and spot-check: is the setup sheet on the work bench the current revision?
- Confirm NCM area is organized — any parts currently in NCM quarantine should be clearly tagged and the NCM log up to date
- Run a self-audit — your internal auditor should do a walk-through of the highest-risk processes (document control, NCM, calibration) 2–3 days before Stage 2
During the audit
- Don't volunteer more than asked — Answer the question, don't provide a full tour of everything you know about the process. Verbose responses give auditors more to probe.
- Stay calm on findings — If an auditor identifies a finding, acknowledge it, document it, and move on. Don't argue in the moment — you can discuss the finding in the closing meeting.
- Provide records promptly — Auditors will ask for specific job packets, NCR files, calibration records. Have someone assigned to pull records so production doesn't stop while you hunt for paperwork.
- Document what the auditor looked at — Keep a log of what records the auditor reviewed. This helps during the exit meeting and if there are disputes about what was examined.
Stage 2 exit meeting
At the end of Stage 2, the auditor will hold an exit meeting where they present findings. Findings can be:
- Major nonconformance — System-level failure that requires documented corrective action before registration can be granted. Typically 30–60 days to provide root cause and corrective action evidence.
- Minor nonconformance — An isolated failure or deviation from the standard. Must be corrected, but registration is typically granted with a plan to verify closure at the next surveillance audit.
- Opportunity for Improvement (OFI) — Not a nonconformance, but an observation the auditor documents. Address it — OFIs often become nonconformances at the next audit if not addressed.
What happens after a major nonconformance
After a major NC, the registrar will typically give you 30–90 days to provide root cause analysis and corrective action evidence. You'll submit your CAR documentation, and the registrar will review it (sometimes requiring a follow-up visit or document submission). If the corrective action is accepted, registration proceeds. If you don't respond within the deadline, or if the corrective action is deemed inadequate, registration is delayed or suspended. Most shops that receive a major NC during Stage 2 successfully resolve it within 60 days — the registrar isn't looking to fail you, they're looking for evidence that you take findings seriously and fix them properly.
Post-registration: what surveillance looks like
Once you're registered, annual surveillance audits keep the registrar engaged. Surveillance is typically 1–2 days per year, focusing on different aspects of the QMS each visit (they won't audit everything every year, but they will cover the highest-risk areas). Recertification audits happen every three years and re-validate the entire QMS.
The key to maintaining registration: treat surveillance as an opportunity, not a threat. Keep your internal audit schedule current, close NCRs on time, run management reviews consistently, and update your QMS when your operation changes. Shops that treat registration as a one-time project rather than an ongoing commitment almost always end up with findings on their second or third surveillance audit.
Frequently Asked Questions
Technically, yes — some shops registered to AS9100C may still have active registrations if their transition deadline hasn't passed. However, the IAQG transition period for AS9100C to AS9100D has closed in most sectors. Most primes have updated their quality requirements to specify AS9100D. If you're starting a new registration, you must pursue AS9100D. If you're already registered to Rev C, your registrar will have communicated your transition deadline — past that date, the Rev C registration is no longer valid.
Risk-based thinking and organizational context. Rev D requires documented evidence of both — a risk register and an organizational context document. Shops that built their QMS under Rev C often have neither. These are easy to add and most shops can close these gaps within 4–8 weeks of focused work. They're also the gaps most likely to show up as findings on a transition audit.
There's no fixed number — it depends on your risk profile and audit findings. A typical small machining shop runs 10–15 internal audits per year across all processes. High-risk processes (document control, NCM, work order control) are audited quarterly or semi-annually. Lower-risk processes (training records, facilities, purchasing) can go annually. If you have an NCR or customer complaint in a specific area, run a triggered audit within 30 days — don't wait for the scheduled cycle.
AS9100 requires auditors to be independent of the process being audited — you can't audit your own work. For a small shop with five to ten people, this means cross-functional auditing: the quality manager audits production floor processes (work order control, machining, inspection), and a production supervisor or senior machinist audits quality management processes (calibration records, management review, training). An external consultant can supplement once a year for a pre-assessment before the registrar audit.
Ask yourself three questions after every management review: Did we look at actual performance data (not just gut feeling)? Did we make decisions and assign action items? Do we have a documented record (meeting minutes, signed report) that shows what was discussed and what was decided? If the answer to any of these is no, the management review isn't meeting the standard — regardless of whether an auditor has flagged it yet. The most common management review finding is "no documented output" — a meeting happened but nothing was recorded.
Walk the floor and do a document revision check — confirm all work orders, setup sheets, and CNC programs on the floor are current revisions. Pull your most recent complete job packet and verify it's fully documented. Review your NCR/CAR log and ensure open items are documented with action plans. Brief anyone who might be interviewed (machinists, QC techs, QA manager). Get sleep — the audit will be long and your ability to respond clearly matters.
Typically 30–90 days, depending on the nature of the NC and the registrar's requirements. Root cause analysis and corrective action must be documented and submitted to the registrar. The registrar reviews the documentation — if it's adequate, the finding is closed. If it isn't, they request additional information. Most major NCs from a Stage 2 audit are closed within 60 days. The key is not just to fix the immediate problem, but to demonstrate that the corrective action addresses the root cause so it can't happen again.
For a small machining shop going through initial registration: yes. A consultant or registrar pre-assessment costs $2,000–$5,000 and typically finds 5–15 gaps that the real auditor would also find. Fixing those gaps before Stage 2 saves time, stress, and potentially avoids a major NC that delays registration. The ROI is clear if the pre-assessment catches even one major NC — that 30–90 day delay costs more than the pre-assessment. For shops transitioning from Rev C to Rev D, a pre-assessment is strongly recommended.
Need a QMS gap assessment for AS9100D?
We can help. Upload your drawing and describe your quality requirements — we'll respond within 4 business hours.