Skip to content

Evidence request lists

AS9100D:2016 - Quality Management Systems for Aviation, Space, and Defence

Evidence request list. 27 controls, 27 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Context

AS9100D2016-4.4
QMS and Its Processes

Establish, implement, maintain, and continually improve the QMS including the processes needed and their interactions.

Artefacts an auditor will ask for
  • Process map
  • Process owners list
  • Interaction matrix
  • Documented info index
Where this commonly fails
  • No process owners assigned
  • Interactions implied not documented

Improvement

AS9100D2016-10.1
Improvement

Determine and select opportunities for improvement and implement actions to enhance customer satisfaction.

Artefacts an auditor will ask for
  • Improvement projects
  • Kaizen records
  • Benefits realisation
  • Lessons learned
Where this commonly fails
  • No proactive improvement projects
  • Benefits not measured
AS9100D2016-10.2
Nonconformity and Corrective Action

React to NC, evaluate cause, implement actions, review effectiveness, update risks.

Artefacts an auditor will ask for
  • CAR records
  • RCA evidence
  • Effectiveness verification
  • Customer/regulatory NC submissions
Where this commonly fails
  • RCA superficial
  • No effectiveness check

Leadership

AS9100D2016-5.1
Leadership and Commitment

Top management demonstrates leadership and commitment to the QMS including product safety and conformity.

Artefacts an auditor will ask for
  • Town hall minutes
  • Quality policy
  • Resource allocation evidence
  • Executive attendance at reviews
Where this commonly fails
  • No visible top mgmt presence
  • Policy not communicated
AS9100D2016-5.2
Quality Policy

Establish, communicate, and maintain a quality policy appropriate to the organisation context.

Artefacts an auditor will ask for
  • Signed quality policy
  • Communication records
  • Display photos
  • Review history
Where this commonly fails
  • Policy unchanged for years
  • Staff cannot articulate it
AS9100D2016-5.3
Roles, Responsibilities, Authorities

Assign and communicate responsibility and authority for relevant QMS roles including product safety.

Artefacts an auditor will ask for
  • Org chart
  • Job descriptions
  • RACI matrix
  • Quality manager appointment
Where this commonly fails
  • No designated product safety lead
  • Authority limits unclear

Operation

AS9100D2016-8.1
Operational Planning and Control

Plan, implement, and control processes needed to meet requirements; control planned changes.

Artefacts an auditor will ask for
  • Production plans
  • Capacity analysis
  • Resource allocation records
  • Change control
Where this commonly fails
  • Capacity not analysed pre-commit
  • Outsourced processes not planned
AS9100D2016-8.1.1
Operational Risk Management

Plan and implement risk management processes including risk assessment criteria during operations.

Artefacts an auditor will ask for
  • Project FMEA
  • Mitigation evidence
  • Acceptance approvals
Where this commonly fails
  • No risk criteria defined
  • Mitigations not verified
AS9100D2016-8.1.2
Configuration Management

Plan, implement, control configuration management process to ensure product configuration identification and traceability.

Artefacts an auditor will ask for
  • CM plan
  • Baselines
  • ECN/ECO records
  • As-built vs as-designed reconciliation
  • Traceability matrix
Where this commonly fails
  • No CM plan
  • Configuration drift in field
AS9100D2016-8.1.3
Product Safety

Plan, implement, control processes needed to assure product safety throughout the product life cycle.

Artefacts an auditor will ask for
  • Safety hazard log
  • Safety critical characteristics list
  • Safety reporting procedure
  • Field safety bulletins
Where this commonly fails
  • No SCC identification
  • Field events not analysed
AS9100D2016-8.1.4
Prevention of Counterfeit Parts

Plan and implement processes to prevent the use of suspect/counterfeit parts in product.

Artefacts an auditor will ask for
  • Counterfeit prevention plan
  • OCM/franchised distributor list
  • Authentication/test records
  • GIDEP alerts review
  • Quarantine and reporting
Where this commonly fails
  • Independent distributors used without authentication
  • No GIDEP monitoring
AS9100D2016-8.2
Requirements for Products and Services

Determine, review, and change requirements for products and services with customers.

Artefacts an auditor will ask for
  • RFQ/contract reviews
  • Statutory/regulatory check
  • Change communications
Where this commonly fails
  • Spec changes not reviewed
  • Statutory check not documented
AS9100D2016-8.3.4
Design and Development Controls

Apply controls to design and development process including reviews, verification, validation, transfer.

Artefacts an auditor will ask for
  • Design reviews
  • V&V plans/reports
  • Transfer to manufacturing records
  • Test reports
Where this commonly fails
  • V vs V confused
  • No design transfer record
AS9100D2016-8.4.1
Supplier Selection and Approval

Determine and apply criteria for evaluation, selection, monitoring, and re-evaluation of external providers.

Artefacts an auditor will ask for
  • Supplier qualification records
  • Approved Supplier List
  • Risk-based supplier audits
  • Performance scorecards
Where this commonly fails
  • No re-evaluation cycle
  • Risk-based oversight not applied
AS9100D2016-8.4.2
Type and Extent of Control of Suppliers

Determine controls based on risk to ensure externally provided processes/products meet requirements.

Artefacts an auditor will ask for
  • Source inspection plans
  • Receiving inspection sampling
  • Supplier audit reports
  • Delegated product release evidence
Where this commonly fails
  • No source inspection on critical parts
  • Delegation criteria missing
AS9100D2016-8.4.3
Information for External Providers (Flowdown)

Communicate to external providers requirements for processes, products, qualifications, key characteristics, traceability.

Artefacts an auditor will ask for
  • PO quality clauses
  • Specification flowdown matrix
  • Key characteristic call-outs
  • Right of access clauses
Where this commonly fails
  • DPD/MBD reqs not flowed
  • Regulatory reqs missed
AS9100D2016-8.5.2
Identification and Traceability

Use suitable means to identify outputs and maintain traceability throughout production.

Artefacts an auditor will ask for
  • Lot/serial control
  • Travelers
  • Receiving tags
  • Recall/genealogy records
Where this commonly fails
  • Lost traceability at assembly
  • No CoC retention
AS9100D2016-8.5.3
Property Belonging to Customers/External Providers

Identify, verify, protect, and safeguard customer or external provider property under organisation control.

Artefacts an auditor will ask for
  • Customer property log
  • Damage/loss notifications
  • Tooling/IP register
Where this commonly fails
  • No notification on damage
  • IP not segregated
AS9100D2016-8.5.5
Post-Delivery Activities

Meet requirements for post-delivery activities including warranty, maintenance, and field support.

Artefacts an auditor will ask for
  • Warranty records
  • Field service reports
  • Customer complaint log
  • Field returns analysis
Where this commonly fails
  • No feedback loop from field
  • Warranty data not analysed

Operation (Clause 8)

AS9100D-8.3
Design and Development of Products

Establish, implement, maintain design and development process appropriate for aerospace products.

Artefacts an auditor will ask for
  • Design plans
  • Inputs/outputs records
  • Design reviews
  • V&V records
  • Design changes
Where this commonly fails
  • No verification vs validation distinction
  • Late changes uncontrolled
AS9100D-8.4
Control of Externally Provided Processes, Products, Services

Ensure suppliers meet requirements; manage supplier selection, monitoring, and flowdown.

Artefacts an auditor will ask for
  • AVL/ASL
  • Supplier audits
  • Performance scorecards
  • Flowdown PO clauses
  • Source inspection records
Where this commonly fails
  • No flowdown of customer reqs
  • Supplier de-listing not executed
AS9100D-8.7
Control of Nonconforming Outputs

Identify and control nonconforming outputs to prevent unintended use, including dispositions.

Artefacts an auditor will ask for
  • NCR log
  • MRB minutes
  • Quarantine evidence
  • Customer concession requests
  • Scrap controls
Where this commonly fails
  • No MRB for use-as-is
  • Scrap not physically destroyed

Performance

AS9100D2016-9.1.2
Customer Satisfaction

Monitor customer perceptions including OASIS feedback, scorecards, and complaints.

Artefacts an auditor will ask for
  • Survey results
  • OASIS scorecards
  • Complaint log
  • Corrective actions on complaints
Where this commonly fails
  • No closed-loop on complaints
  • OASIS not reviewed
AS9100D2016-9.2
Internal Audit Program

Plan, establish, implement, and maintain audit program covering frequency, methods, responsibilities.

Artefacts an auditor will ask for
  • Audit schedule
  • Auditor qualification
  • Audit reports
  • CAR follow-up
Where this commonly fails
  • Audit not risk-based
  • Process audits omitted

Planning

AS9100D2016-6.1
Actions to Address Risks and Opportunities

Plan actions to address risks and opportunities affecting QMS outcomes and product safety.

Artefacts an auditor will ask for
  • Risk register
  • Opportunity log
  • Action plans
  • Risk acceptance records
Where this commonly fails
  • Opportunities not tracked
  • No risk appetite defined
AS9100D2016-6.2
Quality Objectives and Planning

Establish measurable quality objectives consistent with policy at relevant functions and levels.

Artefacts an auditor will ask for
  • Objective KPI cascade
  • Targets and baselines
  • Quarterly review records
Where this commonly fails
  • Objectives not measurable
  • Not cascaded to functions

Support

AS9100D2016-7.5
Documented Information

Control documented information required by QMS and the standard including external origin docs.

Artefacts an auditor will ask for
  • Master document list
  • Revision history
  • Access control
  • Specification library (customer/regulatory)
Where this commonly fails
  • Obsolete docs on floor
  • No control of external standards
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.