Prompt
How do I ensure my engineering change management with a quality management system is compliant with AS9100 requirements?
Latest observation
To ensure your engineering change management aligns with AS9100 and your Quality Management System (QMS) stays compliant, you need a controlled process that covers planning, review, approval, implementation, verification, and recordkeeping for all changes that could affect product, process, software, configuration, or compliance.
What AS9100 expects
AS9100 does not give you one single “engineering change” clause, but it requires that changes be controlled across several areas, especially:
- 8.5.6 Control of changes
- 8.3 Design and development (if you design products/services)
- 8.4 Control of externally provided processes/products/services
- 7.5 Documented information
- 8.7 Control of nonconforming outputs
- 9.1 / 9.2 / 9.3 for monitoring, internal audit, and management review
- 6.3 Planning of changes and risk-based thinking concepts
Core elements of a compliant change management process
1. Define the scope of change control
Your procedure should clearly state what is controlled, such as:
- Design changes
- Process changes
- Material or supplier changes
- Tooling changes
- Software/firmware changes
- Inspection/test method changes
- Drawing/specification changes
- Temporary deviations and concessions, if applicable
Also define what triggers a change request:
- Customer requirement changes
- Engineering corrections
- Nonconformance investigations
- Obsolescence
- Supplier changes
- Cost or manufacturability improvements
2. Require formal change requests
Every change should start with a documented request that includes:
- Unique change number
- Description and reason for change
- Affected part numbers, documents, processes, or software
- Classification of change severity
- Proposed implementation date
- Originator and owner
3. Perform impact and risk assessment
AS9100 expects you to assess the effect of changes before approval. Evaluate:
- Fit, form, function, safety, and reliability
- Regulatory and customer requirements
- Product conformity and performance
- Configuration control and traceability
- Required verification/validation activities
- Manufacturing and inspection impacts
- Supplier and subcontractor impacts
- Cyber/software impacts if applicable
- Risk to on-time delivery and inventory/WIP
Document the risk analysis and mitigation actions.
4. Route for multidisciplinary review and approval
Approvals should include the right functions based on impact, such as:
- Engineering
- Quality
- Operations/manufacturing
- Supply chain
- Configuration management
- Program/customer representative, if required
- Regulatory/compliance, if applicable
Do not implement changes until all required approvals are obtained.
5. Control customer and regulatory notifications
If the change affects a customer-controlled requirement, drawing, specification, form, or special process, verify whether:
- Customer approval is required
- First article inspection is required
- Delta qualification or revalidation is required
- External notification is required by contract or flow-down requirements
Make sure your procedure addresses contract review and customer-specific requirements.
6. Update all affected documented information
After approval, ensure revision-controlled updates to:
- Drawings
- BOMs
- Work instructions
- Inspection plans
- Test procedures
- Router/traveler
- Software versions
- Control plans
- FMEAs, PFMEAs, risk registers
- Training materials
- Supplier specs or purchase orders
AS9100 expects documented information to be current, controlled, and available where needed.
7. Define implementation rules
Your process should specify:
- Effective date or serial/lot cutoff
- Disposition of existing inventory, WIP, and fielded product
- Use of old revision vs new revision
- Rework/retest requirements
- Segregation to prevent mix-ups
- Identification and traceability rules
8. Verify and validate the change
Before full release, confirm the change works as intended:
- First article inspection
- Prototype or pilot build
- Test/validation evidence
- Requalification where needed
- Review of nonconformance trends after change
Keep objective evidence of verification and validation.
9. Maintain configuration and traceability
You should be able to demonstrate:
- What changed
- Why it changed
- Who approved it
- When it became effective
- Which units/serial numbers are impacted
- Which revision was built, tested, shipped, or maintained
This is especially important in aerospace due to configuration management expectations.
10. Preserve records
Keep records for:
- Change request
- Risk assessment
- Approvals
- Customer notifications/approvals
- Validation evidence
- Updated documents
- Training completion
- Implementation records
- Effectivity and disposition records
Records should be protected, retrievable, and retained per your retention requirements.
Good AS9100 audit questions to ask yourself
Auditors often look for evidence that:
- Changes are reviewed before implementation
- Risks are assessed and controlled
- Product conformity is not compromised
- Customer/regulatory requirements are addressed
- Configuration is maintained
- Documents are updated and controlled
- Personnel are trained on the new revision
- Effectivity is clear and followed
- Evidence exists for validation and release
Common pitfalls
Avoid these frequent nonconformities:
- Implementing changes without approval
- Not assessing downstream impacts
- Missing customer approval requirements
- Failure to update travelers, drawings, or inspection instructions
- Weak traceability of revision/effectivity
- No validation evidence after changes
- Inconsistent handling of temporary changes or deviations
Practical way to build compliance
A simple compliant workflow is:
- Raise change request
- Assess impact/risk
- Obtain cross-functional approval
- Obtain customer approval if required
- Update documents and training
- Validate/verify change
- Release with controlled effectivity
- Record implementation and retain evidence
Best practice
Create a single integrated procedure for:
- Engineering change control
- Configuration management
- Document control
- Risk management
- Customer notification/approval
That makes it much easier to show auditors a consistent system.
If you want, I can also provide:
- a sample AS9100 engineering change procedure,
- a change request form template, or
- a clause-by-clause AS9100 compliance checklist.
Observation history
Unlock observation history
Create a free Obsurfable account to unlock historical responses, model comparisons, and deeper brand intelligence.
How did Obsurfable measure this prompt?
Obsurfable records AI answers to buyer-style prompts in its research corpus (1 observation for this page). Metrics are distributions over observations, not a single static ranking.
Which AI systems does Obsurfable collect answers from?
OpenAI, ChatGPT, Google, Gemini, Google AI Mode, Anthropic, Claude, Perplexity, Grok, DeepSeek, Mistral, Copilot, and Meta AI.