Prompt

How do I ensure my engineering change management with a quality management system is compliant with AS9100 requirements?

Latest observation

Jul 29, 2026 · OpenAI APIWeb search: off

To ensure your engineering change management aligns with AS9100 and your Quality Management System (QMS) stays compliant, you need a controlled process that covers planning, review, approval, implementation, verification, and recordkeeping for all changes that could affect product, process, software, configuration, or compliance.

What AS9100 expects

AS9100 does not give you one single “engineering change” clause, but it requires that changes be controlled across several areas, especially:

  • 8.5.6 Control of changes
  • 8.3 Design and development (if you design products/services)
  • 8.4 Control of externally provided processes/products/services
  • 7.5 Documented information
  • 8.7 Control of nonconforming outputs
  • 9.1 / 9.2 / 9.3 for monitoring, internal audit, and management review
  • 6.3 Planning of changes and risk-based thinking concepts

Core elements of a compliant change management process

1. Define the scope of change control

Your procedure should clearly state what is controlled, such as:

  • Design changes
  • Process changes
  • Material or supplier changes
  • Tooling changes
  • Software/firmware changes
  • Inspection/test method changes
  • Drawing/specification changes
  • Temporary deviations and concessions, if applicable

Also define what triggers a change request:

  • Customer requirement changes
  • Engineering corrections
  • Nonconformance investigations
  • Obsolescence
  • Supplier changes
  • Cost or manufacturability improvements

2. Require formal change requests

Every change should start with a documented request that includes:

  • Unique change number
  • Description and reason for change
  • Affected part numbers, documents, processes, or software
  • Classification of change severity
  • Proposed implementation date
  • Originator and owner

3. Perform impact and risk assessment

AS9100 expects you to assess the effect of changes before approval. Evaluate:

  • Fit, form, function, safety, and reliability
  • Regulatory and customer requirements
  • Product conformity and performance
  • Configuration control and traceability
  • Required verification/validation activities
  • Manufacturing and inspection impacts
  • Supplier and subcontractor impacts
  • Cyber/software impacts if applicable
  • Risk to on-time delivery and inventory/WIP

Document the risk analysis and mitigation actions.

4. Route for multidisciplinary review and approval

Approvals should include the right functions based on impact, such as:

  • Engineering
  • Quality
  • Operations/manufacturing
  • Supply chain
  • Configuration management
  • Program/customer representative, if required
  • Regulatory/compliance, if applicable

Do not implement changes until all required approvals are obtained.

5. Control customer and regulatory notifications

If the change affects a customer-controlled requirement, drawing, specification, form, or special process, verify whether:

  • Customer approval is required
  • First article inspection is required
  • Delta qualification or revalidation is required
  • External notification is required by contract or flow-down requirements

Make sure your procedure addresses contract review and customer-specific requirements.

6. Update all affected documented information

After approval, ensure revision-controlled updates to:

  • Drawings
  • BOMs
  • Work instructions
  • Inspection plans
  • Test procedures
  • Router/traveler
  • Software versions
  • Control plans
  • FMEAs, PFMEAs, risk registers
  • Training materials
  • Supplier specs or purchase orders

AS9100 expects documented information to be current, controlled, and available where needed.

7. Define implementation rules

Your process should specify:

  • Effective date or serial/lot cutoff
  • Disposition of existing inventory, WIP, and fielded product
  • Use of old revision vs new revision
  • Rework/retest requirements
  • Segregation to prevent mix-ups
  • Identification and traceability rules

8. Verify and validate the change

Before full release, confirm the change works as intended:

  • First article inspection
  • Prototype or pilot build
  • Test/validation evidence
  • Requalification where needed
  • Review of nonconformance trends after change

Keep objective evidence of verification and validation.

9. Maintain configuration and traceability

You should be able to demonstrate:

  • What changed
  • Why it changed
  • Who approved it
  • When it became effective
  • Which units/serial numbers are impacted
  • Which revision was built, tested, shipped, or maintained

This is especially important in aerospace due to configuration management expectations.

10. Preserve records

Keep records for:

  • Change request
  • Risk assessment
  • Approvals
  • Customer notifications/approvals
  • Validation evidence
  • Updated documents
  • Training completion
  • Implementation records
  • Effectivity and disposition records

Records should be protected, retrievable, and retained per your retention requirements.

Good AS9100 audit questions to ask yourself

Auditors often look for evidence that:

  • Changes are reviewed before implementation
  • Risks are assessed and controlled
  • Product conformity is not compromised
  • Customer/regulatory requirements are addressed
  • Configuration is maintained
  • Documents are updated and controlled
  • Personnel are trained on the new revision
  • Effectivity is clear and followed
  • Evidence exists for validation and release

Common pitfalls

Avoid these frequent nonconformities:

  • Implementing changes without approval
  • Not assessing downstream impacts
  • Missing customer approval requirements
  • Failure to update travelers, drawings, or inspection instructions
  • Weak traceability of revision/effectivity
  • No validation evidence after changes
  • Inconsistent handling of temporary changes or deviations

Practical way to build compliance

A simple compliant workflow is:

  1. Raise change request
  2. Assess impact/risk
  3. Obtain cross-functional approval
  4. Obtain customer approval if required
  5. Update documents and training
  6. Validate/verify change
  7. Release with controlled effectivity
  8. Record implementation and retain evidence

Best practice

Create a single integrated procedure for:

  • Engineering change control
  • Configuration management
  • Document control
  • Risk management
  • Customer notification/approval

That makes it much easier to show auditors a consistent system.

If you want, I can also provide:

  1. a sample AS9100 engineering change procedure,
  2. a change request form template, or
  3. a clause-by-clause AS9100 compliance checklist.

Observation history

Unlock observation history

Create a free Obsurfable account to unlock historical responses, model comparisons, and deeper brand intelligence.

How did Obsurfable measure this prompt?

Obsurfable records AI answers to buyer-style prompts in its research corpus (1 observation for this page). Metrics are distributions over observations, not a single static ranking.

Which AI systems does Obsurfable collect answers from?

OpenAI, ChatGPT, Google, Gemini, Google AI Mode, Anthropic, Claude, Perplexity, Grok, DeepSeek, Mistral, Copilot, and Meta AI.