Skip to content

Evidence request lists

IATF 16949:2016 - Quality Management System for Automotive Production

Evidence request list. 10 controls, 10 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

IATF 16949 Clause 10 - Improvement

IATF16949-Clause10-Improvement-Nonconformity-CorrectiveAction-Problem-ErrorProof
IATF 16949 Clause 10 - Improvement + Nonconformity + Corrective Action + Problem Solving + Error Proofing + Continual Improvement

Clause 10 addresses improvement + nonconformity + corrective action + problem solving + error proofing + continual improvement. Conceptual coverage: 10.1 General Improvement (continual improvement of suitability + adequacy + effectiveness of QMS); 10.2 Nonconformity and Corrective Action (react + evaluate + implement + review + update + retain documented info); 10.2.1 General + 10.2.2 Documented Info + 10.2.3 Problem Solving (IATF supplemental - documented process(es) for problem solving - 8D / DMAIC / Six Sigma / lean methodology / cause analysis / containment + interim + permanent + verification + horizontal expansion to similar products/processes/facilities); 10.2.4 Error Proofing (IATF supplemental - documented process for error proofing - poka-yoke / mistake-proofing - identification + implementation + verification + maintenance + records); 10.2.5 Warranty Management Systems + 10.2.

Artefacts an auditor will ask for
  • Nonconformity register + identification + react + containment + correction
  • Corrective action methodology + 8D / DMAIC + root cause analysis + verification + closure
  • Problem solving register + horizontal expansion to similar products/processes/facilities + lessons learned
  • Error proofing (poka-yoke) inventory + implementation + verification + maintenance + change management
  • Continual improvement projects + KPIs + statistical tools + financial impact + customer satisfaction trend
Where this commonly fails
  • Nonconformity reaction stops at containment (no permanent fix)
  • Corrective actions not verified for effectiveness (recurrence)
  • Problem solving 8D done in isolation (no horizontal expansion)
  • Error proofing degraded over time (poka-yoke disabled for production speed)
  • Continual improvement only nominal (no measurable KPI or project portfolio)

IATF 16949 Clause 4 - Context of Organization

IATF16949-Clause4-Context-Scope-CustomerSpecific-ProductSafety
IATF 16949 Clause 4 - Context of Organization + QMS Scope + Customer Specific Requirements + Product Safety

Clause 4 establishes the context of the organisation + QMS scope + Customer Specific Requirements + Product Safety. Conceptual coverage per public IATF Wikipedia + AIAG + ISO 9001:2015 description (not full copyrighted text): 4.1 Understanding the organisation and its context (external + internal issues affecting QMS purpose + strategic direction); 4.2 Understanding the needs and expectations of interested parties (customers + employees + suppliers + regulators + community); 4.3 Determining the scope of the QMS (boundaries + applicability + justification for exclusions); 4.3.1 Determining the scope - supplemental; 4.3.2 Customer Specific Requirements (CSRs per OEM register + linkage to QMS scope + audit programme); 4.4 Quality Management System and its processes (process approach + sequence + interaction + inputs/outputs + responsibilities + risks/opportunities + documented info + monito

Artefacts an auditor will ask for
  • Context analysis (external + internal issues) + periodic review evidence
  • Interested parties register + needs and expectations + change tracking
  • QMS scope document + boundary + applicability + exclusion justification
  • Customer Specific Requirements register per OEM + compliance matrix + change management
  • Product Safety process per 4.4.1.2 + statutory/regulatory + customer notification + reaction plans + recall + senior management review
Where this commonly fails
  • Context analysis stale (no periodic review)
  • Interested parties register incomplete (missing regulators or community)
  • QMS scope too narrow (excluding key processes)
  • CSRs treated per customer separately without consolidated compliance matrix
  • Product Safety process generic (not adjusted to specific products + customer)

IATF 16949 Clause 5 - Leadership

IATF16949-Clause5-Leadership-Corporate-QualityPolicy-Roles
IATF 16949 Clause 5 - Leadership + Top Management Commitment + Corporate Responsibility + Quality Policy + Roles

Clause 5 establishes leadership requirements + top management commitment + corporate responsibility + quality policy + organisational roles. Conceptual coverage: 5.1 Leadership and Commitment (top management accountability for QMS effectiveness + customer focus + quality policy + responsibilities + integration with business processes + process approach + customer + applicable statutory + regulatory + risk-based thinking); 5.1.1 General Leadership and Commitment; 5.1.1.1 Corporate Responsibility (IATF supplemental - documented corporate responsibility policies covering anti-bribery + employee code of conduct + ethics escalation policy); 5.1.1.2 Process Effectiveness and Efficiency; 5.1.1.3 Process Owners; 5.1.2 Customer Focus; 5.2 Policy / Quality Policy (top management establishes + reviews + maintains + communicates + supports organisational direction + provides framework for objectives

Artefacts an auditor will ask for
  • Top management commitment evidence + business plan integration + KPI ownership + management review participation
  • Corporate Responsibility policy + anti-bribery + employee code of conduct + ethics hotline + whistleblower
  • Quality Policy document + signed by top management + communicated + posted + acknowledged by all employees
  • Organisational chart + role definitions + RACI matrix + Quality Management Representative + Customer Representative + Process Owners
  • Customer Representative appointment + responsibilities + communication channels
Where this commonly fails
  • Top management commitment nominal (sign quality policy without engagement)
  • Corporate Responsibility policy missing or generic (no anti-bribery specifics)
  • Quality Policy not communicated below management level
  • RACI matrix absent or not maintained (role confusion)
  • Customer Representative role unclear or inactive

IATF 16949 Clause 6 - Planning

IATF16949-Clause6-Planning-Risk-Contingency-Objectives-Change
IATF 16949 Clause 6 - Planning + Risks and Opportunities + Contingency Plans + Quality Objectives + Change

Clause 6 establishes planning requirements + risk-based thinking + contingency plans + quality objectives + planning of changes. Conceptual coverage: 6.1 Actions to address risks and opportunities (consider context + interested parties + risk-based thinking + plan actions + integrate + evaluate); 6.1.1 General; 6.1.2 Risk Analysis - IATF supplemental (documented process for risk analysis based on past + product/process changes + new business + regulatory); 6.1.2.1 Risk Analysis; 6.1.2.2 Preventive Action; 6.1.2.3 Contingency Plans (IATF supplemental - identify + evaluate internal + external risks; define contingency plans per risk; include disruption to delivery to customer; periodic review + test + update; specific examples key equipment failure + supply interruption + recurring natural disaster + fire + utility failure + cyber attack + labor shortage + infrastructure disruption); 6.2 Q

Artefacts an auditor will ask for
  • Risk register + analysis methodology + treatment + monitoring per 6.1.2
  • Contingency plans per disruption scenario (equipment + supply + utility + cyber + labor + disaster) + tabletop tests
  • Quality objectives per process + SMART + KPI tracking + management review
  • Change management process + impact assessment + validation + customer notification
  • Pandemic + cyber + supply chain disruption recent specific scenarios + lessons learned
Where this commonly fails
  • Risk analysis only at start of contract (not ongoing)
  • Contingency plans generic without scenario-specific actions or tested
  • Quality objectives not measurable or tied to QMS performance
  • Change planning skips validation step (production starts before validation)
  • Cyber risk excluded from 6.1.2.3 contingency plans

IATF 16949 Clause 7 - Support

IATF16949-Clause7-Support-Resources-MSA-Calibration-Competence-Documents
IATF 16949 Clause 7 - Support + Resources + Measurement Systems Analysis (MSA) + Calibration + Competence + Documented Info

Clause 7 establishes support requirements + resources + competence + awareness + communication + documented information. Conceptual coverage: 7.1 Resources (general + people + infrastructure + environment + monitoring/measuring resources + organizational knowledge); 7.1.5 Monitoring and Measuring Resources (general + measurement traceability) + 7.1.5.1 General + 7.1.5.1.1 Measurement Systems Analysis (MSA - IATF supplemental - statistical study to analyse variation present in results of each type of inspection + measurement + test equipment + system per AIAG MSA reference manual or equivalent VDA approach; Gage R&R + linearity + stability + bias + accuracy); 7.1.5.2 Measurement Traceability + 7.1.5.2.1 Calibration / Verification Records (IATF supplemental - documented evidence of conformity of measurement equipment + internal/external calibration + traceability to national/international

Artefacts an auditor will ask for
  • MSA studies per measurement equipment + Gage R&R + linearity + stability + bias + acceptance criteria
  • Calibration register + internal/external + traceability + uncertainty + out-of-tolerance actions
  • Competence matrix per role + training records + qualification + on-the-job training evidence
  • Awareness training + quality policy/objectives communication + non-conformance impact + employee motivation evidence
  • Document control system + version + approval + distribution + obsolete control
Where this commonly fails
  • MSA done at equipment introduction only (no periodic re-evaluation)
  • Calibration records incomplete (missing internal calibration justification or out-of-tolerance actions)
  • Competence matrix stale (not reflecting role changes or training)
  • Awareness perfunctory (annual sign-off only, no engagement)
  • Documents controlled in folder but obsolete versions still accessible

IATF 16949 Clause 8 - Nonconforming + PPAP

IATF16949-Clause8-Nonconforming-Concession-PPAP-Submission
IATF 16949 Clause 8 - Control of Nonconforming Outputs + Customer Concession + Production Part Approval Process (PPAP)

Clause 8.7 addresses control of nonconforming outputs + customer concession + Production Part Approval Process (PPAP). Conceptual coverage: 8.7 Control of Nonconforming Outputs (general - identify + control + prevent unintended use + delivery; documented information); 8.7.1 General + 8.7.1.1 Customer Authorization for Concession (process required when customer concession applies + obtain authorization in writing prior to production/shipment + tracking + customer notification); 8.7.1.2 Control of Nonconforming Product - Customer-Specified Process; 8.7.1.3 Control of Suspect Product; 8.7.1.4 Control of Reworked Product; 8.7.1.5 Control of Repaired Product; 8.7.1.6 Customer Notification (statutory + regulatory + customer-specific notification + recall + corrective action). Production Part Approval Process (PPAP) per AIAG PPAP Manual 4th edition (or 5th edition published 2023) - automotive-s

Artefacts an auditor will ask for
  • Nonconforming output identification + segregation + disposition + documentation
  • Customer concession approval in writing + tracking + duration + closure
  • Rework + repair + suspect product process + traceability + customer notification
  • PPAP submission per customer level + 18 elements + PSW + approval + retention
  • Customer notification + recall + corrective action + closure + lessons learned
Where this commonly fails
  • Nonconforming product mixed with conforming (no segregation)
  • Customer concession granted verbally without written authorization
  • Reworked product shipped without re-validation
  • PPAP elements incomplete or stale (not updated on process change)
  • Customer notification delayed or missing on field issue

IATF 16949 Clause 8 - Operation (APQP + Design + Production)

IATF16949-Clause8-Operation-APQP-Design-Production-ControlPlan-SpecialChars
IATF 16949 Clause 8 - Operation Planning + APQP + Design + Special Characteristics + Production + Control Plan + Set-Up Verification

Clause 8 establishes operation requirements + APQP + Design + Production. Conceptual coverage: 8.1 Operational Planning and Control + 8.1.1 Operational Planning and Control - Supplemental (use of risk-based methodology + APQP/PPAP-compliant process); 8.2 Requirements for Products and Services (customer communication + determining + reviewing + changes); 8.2.3.1.2 Customer Designated Special Characteristics (process control + documentation + verification + treatment per customer requirements); 8.3 Design and Development (planning + inputs + controls + outputs + changes); 8.3.1 General + 8.3.2 Planning + 8.3.2.1 Planning Supplemental (multidisciplinary approach per APQP/AIAG-VDA FMEA); 8.3.3 Inputs + 8.3.3.3 Special Characteristics (identify + document + assess process capability + control); 8.3.4 Controls + 8.3.5 Outputs + 8.3.5.2 Manufacturing Process Design Output (FMEA + Control Plan +

Artefacts an auditor will ask for
  • APQP project plan per new product + cross-functional team + milestones per AIAG APQP
  • Customer Designated Special Characteristic identification + documentation + Cpk/Ppk monitoring
  • Control Plan per prototype + pre-launch + production phase + periodic review
  • Set-up verification first-off + last-off + statistical methods + retention
  • Temporary change of process control approval + monitoring + return to standard procedure
Where this commonly fails
  • APQP shortened or skipped under time pressure
  • Special Characteristics identified at design but not flowed to production control
  • Control Plan generic across products (not phase-specific)
  • Set-up verification visual only (no statistical confirmation)
  • Temporary changes become permanent without re-validation

IATF 16949 Clause 8 - Supplier

IATF16949-Clause8-Supplier-QMS-Development-Externally-Provided
IATF 16949 Clause 8 Supplier - Control of Externally Provided Processes + Type and Extent + Supplier QMS Development

Clause 8.4 addresses control of externally provided products + services + processes + supplier quality management system development. Conceptual coverage: 8.4 Control of Externally Provided Processes, Products and Services (general + type and extent of control + information for external providers); 8.4.1 General + 8.4.1.1 General Supplemental (supplier selection process + monitoring); 8.4.1.2 Statutory and Regulatory Requirements (supplier compliance with conflict minerals + RoHS + REACH + safety + environmental); 8.4.1.3 Directed-Source Process (when customer mandates specific supplier - additional requirements); 8.4.2 Type and Extent of Control + 8.4.2.1 Type and Extent of Control - Supplemental (risk-based supplier control + criteria + approval status + delivery + verification); 8.4.2.2 Statutory and Regulatory Requirements + 8.4.2.3 Supplier QMS Development (require suppliers to be 3

Artefacts an auditor will ask for
  • Supplier selection process + qualification + approved supplier list + risk classification
  • Type and extent of control matrix per supplier category + risk + approval status
  • Supplier QMS development plan + ISO 9001 / MAQMSR / IATF 16949 progression tracking
  • Second-party audit programme + auditor qualification + report + follow-up + closure
  • Directed-source agreements + customer-mandated supplier additional control
Where this commonly fails
  • Supplier selection price-driven only (no QMS or risk assessment)
  • Type and extent of control identical regardless of risk
  • Supplier QMS development plan missing (suppliers stuck at non-conformant)
  • Second-party audits irregular or auditors not qualified
  • Directed-source suppliers not given customer-mandated additional control

IATF 16949 Clause 9 - Performance Evaluation

IATF16949-Clause9-Performance-Monitoring-InternalAudit-ManagementReview
IATF 16949 Clause 9 - Performance Evaluation + Monitoring + Internal Audit + Manufacturing Process Audit + Management Review

Clause 9 addresses performance evaluation + monitoring + measurement + analysis + evaluation + internal audit + management review. Conceptual coverage: 9.1 Monitoring, measurement, analysis and evaluation (general + customer satisfaction + analysis); 9.1.1 General + 9.1.1.1 Monitoring and Measurement of Manufacturing Processes (per AIAG SPC Statistical Process Control - process capability Cpk + Ppk + process performance + control limits + reaction plans); 9.1.1.2 Identification of Statistical Tools + 9.1.1.3 Application of Statistical Concepts; 9.1.2 Customer Satisfaction + 9.1.2.1 Customer Satisfaction Supplemental (delivered product quality + customer disruptions + customer scorecards + warranty + field returns); 9.2 Internal Audit (general + audit programme + scope + impartiality + competent auditors + results); 9.2.1 General + 9.2.2 Internal Audit Programme + 9.2.2.1 Quality Manageme

Artefacts an auditor will ask for
  • Manufacturing process monitoring + Cpk/Ppk + control charts + reaction plans per AIAG SPC
  • Customer satisfaction tracking + scorecards + warranty + field returns + corrective actions
  • Internal audit programme + 3 audit types (QMS + Manufacturing Process + Product) + competent auditors + schedule
  • Manufacturing Process Audit per VDA 6.3 + per process + per shift + findings + closure
  • Management review minutes + supplemental inputs (warranty + scorecards + COPQ + risk + non-conformance)
Where this commonly fails
  • Manufacturing process monitoring with insufficient sampling or stale Cpk
  • Customer satisfaction tracked but not actioned (scorecards filed)
  • Internal audit programme only QMS clause-based (missing manufacturing process + product audits)
  • Manufacturing Process Audit per VDA 6.3 not performed per shift
  • Management review missing supplemental inputs (cost of poor quality + warranty trends)

IATF 16949 Scope + IATF Members + ISO 9001 Integration

IATF16949-Scope-IATF-Members-ISO9001-Annex-SL-Sector-CSR
IATF 16949:2016 - Scope + IATF Member OEMs + ISO 9001:2015 Annex SL Integration + Automotive Sector + Customer Specific Requirements

IATF 16949:2016 Quality Management System for Automotive Production and Relevant Service Parts Organizations - published October 2016 by International Automotive Task Force (IATF) - sector-specific extension of ISO 9001:2015 for automotive supply chain. Replaces ISO/TS 16949 (originally 1999, last edition 2009). IATF Member OEMs (5 vehicle manufacturers): BMW Group + Stellantis (FCA US LLC + PSA Group, formerly FCA + Peugeot Citroen) + Ford Motor Company + General Motors + Mercedes-Benz Group (formerly Daimler) + Renault. National automotive trade associations (5): AIAG American Automotive Industry Action Group (USA) + ANFIA Italian Automotive Industry Association + FIEV French Vehicle Equipment Industries Federation + SMMT Society of Motor Manufacturers and Traders (UK) + VDA German Association of the Automotive Industry. Adopts Annex SL High Level Structure (HLS) shared with ISO 9001 +

Artefacts an auditor will ask for
  • IATF 16949 applicability assessment per site + supplier tier + customer requirements
  • ISO 9001:2015 baseline + IATF 16949 supplemental requirements mapping
  • Customer Specific Requirements (CSRs) per OEM (BMW + Ford + GM + Stellantis) compliance matrix
  • IATF-recognised CB certification + 3-year cycle + annual surveillance audit report
  • Annex SL 10-clause adoption + integration with other management systems (14001 + 45001)
Where this commonly fails
  • IATF 16949 sought without CB IATF recognition (non-conformance certificate)
  • ISO 9001 baseline not fully integrated (IATF supplemental treated as bolt-on)
  • CSRs per OEM not consolidated (gaps per customer)
  • Surveillance audit slipped causing certification suspension or withdrawal
  • Annex SL HLS not leveraged for IMS efficiency
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.