AS9100 Rev D Audit Readiness Checklist
This free AS9100 audit readiness checklist helps aerospace and defense manufacturers prepare for Rev D certification, surveillance, or recertification audits. Thirty checkpoints span the full standard - QMS documentation, leadership and risk, production control, supply chain, competence, and improvement - and are weighted toward the aerospace-specific clauses where certification body auditors write the most findings: first article inspection, counterfeit parts prevention, product safety, FOD, and nonconforming product control. Use it as a pre-audit self-check with your quality team, or as the working agenda for your internal audit program in the quarter before the CB arrives.
0 of 34 items complete
9 critical items still open - these are the highest-risk gaps.
QMS Documentation and Context
Leadership, Planning, and Risk
Operations and Production Control
Supply Chain and Counterfeit Prevention
Support, Competence, and Awareness
Performance Evaluation and Improvement
Certification bodies write the majority of aerospace findings against document control, risk-based thinking in operations, FAI, nonconforming product control, and calibration - the critical-flagged items above. Any unchecked critical item is a likely major or minor finding; treat more than three unchecked criticals as a signal to delay your audit date and remediate first.
Get your full AS9100 readiness report
We will email you a personalized gap analysis mapped to AS9100 Rev D clauses with a pre-audit remediation sequence, and an aerospace quality specialist will follow up to review it with you.
No spam. Your results stay private. Unsubscribe anytime.
How to use this checklist before an audit
Work through the checklist eight to twelve weeks before your audit date, with evidence in hand rather than from memory - if you cannot point to the record, the auditor cannot either, and 'we do it but do not document it' is a finding. Assign each group to its process owner: quality for documentation and improvement, operations for production control, purchasing for supply chain, HR for competence. Then re-verify the critical items two weeks out, because these are the areas where a single lapse (an uncalibrated gauge on the floor, an obsolete drawing at a workstation, an unsegregated nonconforming part) produces findings regardless of how good your system looks on paper. Auditors sample reality, not intentions.
Where AS9100 audits generate the most findings
Certification body data and registrar experience are consistent about where aerospace audits go wrong, and this checklist flags those areas as critical:
- Document and configuration control - wrong revisions at point of use remains the most common finding category in aerospace audits
- Operational risk management (8.1.1) applied as a living process rather than a static risk register created for the last audit
- FAI completeness under AS9102, especially delta FAIs after process or source changes that teams forget to trigger
- Corrective action quality - containment mislabeled as root cause, and no effectiveness verification after closure
Interpreting your gaps and deciding whether you are ready
Score pragmatically: unchecked non-critical items are audit risk you can manage with a documented action plan, and auditors generally respond well to self-identified issues already in your CAPA system. Unchecked critical items are different - each maps to clauses where findings are most frequently classified as major, and a major finding in certification stage 2 can delay certification by months while you remediate and the CB verifies. If more than three critical items are unchecked, the economically rational move is usually to push the audit date rather than absorb a failed stage 2, because remediating under a finding clock with customer visibility is more expensive than remediating on your own schedule. Feed every gap into your internal audit and CAPA processes so closure is itself evidenced.
How Netray helps you pass and stay certified
A large share of AS9100 findings trace back to the ERP layer: travelers that do not match routings, revision control gaps between engineering and the floor, supplier performance data nobody trends, and traceability that breaks at receiving. Netray specializes in making Infor SyteLine, LN, and Baan do the QMS heavy lifting - enforced revision control, FAI triggers on new and changed items, supplier scorecards fed by live OTD and quality data, and full lot/serial traceability. We also deploy on-prem AI that drafts corrective actions, mines nonconformance trends, and audits traveler-versus-routing consistency automatically, so your quality team spends its time on prevention instead of paperwork before every audit.
Frequently Asked Questions
How is AS9100 different from ISO 9001, and do auditors really focus on the differences?
AS9100 Rev D contains all of ISO 9001:2015 plus roughly 100 aerospace-specific additions: product safety, counterfeit parts prevention, operational risk management, configuration management, FOD, first article inspection, and stricter supplier control. Auditors absolutely concentrate on these additions, because that is what distinguishes an aerospace audit - a company that is solid on generic ISO clauses but weak on FAI, counterfeit prevention, or MRB authority will still accumulate findings quickly.
What happens if we get a major finding during the audit?
A major finding - a total breakdown of a process, or a minor left unresolved - must be closed with root cause analysis, corrective action, and objective evidence before certification is granted or maintained, typically within 60-90 days depending on the CB. In a certification audit, majors delay the certificate; in surveillance, an unclosed major can lead to suspension, which many aerospace customers treat as disqualifying. Self-identifying issues before the audit and having them in your CAPA system is the best protection.
How often should we run internal audits against this checklist?
AS9100 requires internal audits at planned intervals covering the whole QMS; most manufacturers run a rolling program that touches every process at least annually, with high-risk processes audited more often. A practical rhythm is quarterly internal audits covering a quarter of the checklist each cycle, plus a full-system pass 8-12 weeks before each CB visit. Frequency matters less than evidence quality - trained auditors, documented findings, and CAPAs verified for effectiveness.
Work through the checklist with your process owners now, so your next AS9100 audit is a verification exercise instead of a discovery exercise.
Related Tools
First Article Inspection (AS9102) Checklist
A 30-point checklist for complete, first-pass-acceptable AS9102 FAIs - planning, Form 1/2/3 completeness, characteristic accountability, and the delta FAI triggers teams miss.
Aerospace & DefenseCounterfeit Parts Risk Assessment (AS5553)
A 10-question assessment of your counterfeit electronic parts exposure, aligned to AS5553 and DFARS counterfeit prevention requirements, with a risk band and mitigation plan.
Aerospace & DefenseAerospace Supplier Scorecard
Rate a supplier across 10 criteria - OTD, quality escapes, AS9100 status, FAI performance, CAPA responsiveness, compliance flowdown, and financial health - for an instant risk rating.
Go Deeper
DoD AI Adoption in 2026: What It Means for Defense Manufacturers
DoD AI adoption in 2026: what CDAO programs, budget priorities, and new acquisition rules mean for defense manufacturers planning their own AI investments now.
CMMC-Compliant AI Deployment: What Level 2 Contractors Must Know
CMMC-compliant AI deployment explained: how Level 2 defense contractors can run AI on CUI without expanding assessment scope. Controls, enclaves, and costs.