AS9100 for small shops: what the audit checks (plus a checklist)
AS9100 requirements build directly on ISO 9001, then add a layer specific to aerospace: risk management tied to product safety, configuration management, counterfeit parts prevention, first article inspection, and traceability that has to survive a part recall investigation years later. A small shop chasing its first AS9100 certification doesn't need a consultant's black box. It needs a clear map of what the standard requires, what an auditor will physically check, and a checklist to work against before the auditor shows up.
This guide gives you a plain-English breakdown of what AS9100 requires beyond ISO 9001, what auditors look for in a stage 1 and stage 2 audit, and an AS9100 readiness checklist you can start working through today.
What AS9100 is
AS9100 (currently revision D, "AS9100D") is the quality management system standard for the aerospace, space, and defense industry, maintained by the International Aerospace Quality Group (IAQG). It incorporates the full text of ISO 9001:2015 and adds aerospace-specific clauses on top. You cannot certify to AS9100 without also satisfying ISO 9001. Think of AS9100 as ISO 9001 plus a set of requirements written by people who've had to trace a fatigue-cracked bracket back to a heat-treat lot.
An accredited third-party registrar issues certification following an audit against the standard; it isn't self-declared. Most primes and Tier 1 suppliers require AS9100 certification (or at minimum a customer-specific requirements flow-down referencing it) before they'll place a purchase order for flight or flight-critical hardware, which is why it functions as a de facto market-entry requirement for aerospace suppliers rather than a nice-to-have.
What AS9100 adds beyond ISO 9001
| Area | What ISO 9001 asks | What AS9100 adds |
|---|---|---|
| Risk management | General risk-based thinking | Formal risk assessment tied to product safety and delivery performance, at both the organizational and project level |
| Configuration management | Not addressed | Formal control of product configuration and design changes throughout the lifecycle |
| First article inspection | Not addressed | Required FAI per AS9102 for new or changed parts |
| Counterfeit parts | Not addressed | A documented prevention process, especially for electronic and hardware components |
| Critical items / key characteristics | Not addressed | Identification and control of special requirements, critical items, and key characteristics on drawings and routers |
| Human factors | Not addressed | Consideration of human factors in nonconformance and error-proofing |
| Product safety | Implied via customer satisfaction | Explicit requirement to address product safety throughout realization |
| Ethics | Not addressed | Requirement that personnel are aware of their contribution to product/service conformity and ethical behavior |
| Work transferred off-site | Not addressed | Control over work temporarily transferred to a location outside the organization's permanent facilities |
If you already run a solid ISO 9001 system, you're most of the way there. The gap is almost always in risk management formality, FAI discipline, and traceability depth, not in basic document control, which most shops already have reasonably well covered.
What the auditor checks
An AS9100 audit happens in two stages. Stage 1 is a documentation review: do your quality manual, procedures, and objectives map to every clause of the standard, and are you ready for an on-site audit. Stage 2 is the on-site audit, and it's where shops get caught off guard, because a competent auditor doesn't read your procedures in isolation. They trace a real job, end to end, and compare what happened against what your procedures say should happen.
In practice, expect the auditor to:
- Pull an actual customer order and follow it from contract review through purchasing, receiving inspection, production, in-process inspection, final inspection, and shipping, checking that every required record exists and matches.
- Check that special requirements, critical items, and key characteristics called out on the drawing are flagged and verified on the router and inspection records for that job.
- Review your FAI records for a part that required one, and check them against AS9102's form structure. See FAI & AS9102 forms for exactly what those records need to contain.
- Pull calibration records for the gauges and instruments used on that job and confirm they were in-cal at the time of use.
- Review open and closed nonconformance and corrective action records, and probe whether root cause analysis is genuine or a copy-pasted template answer repeated across every CAPA.
- Check your approved supplier list and confirm applicable requirements (including any customer flow-downs) were passed down to the supplier who made that part or performed a special process.
- Review internal audit records and management review minutes to confirm the QMS is being run, not only documented.
- Ask operators and inspectors questions on the floor, not to trick them but to confirm the documented process matches the practiced one.
The single biggest failure mode for small shops is a procedure that exists on paper but isn't what's happening on the floor, not a missing procedure. Auditors are trained to find that gap.
AS9100 readiness checklist
Work through this before you schedule stage 1:
- Quality manual mapped clause-by-clause to AS9100D, with clear ownership of who is responsible for each clause.
- Documented risk management process applied at both the organizational level and the individual job/project level, tied to product safety and delivery risk.
- Configuration management procedure covering how design changes and revisions are controlled and communicated to production.
- AS9102-compliant FAI process for new parts, new suppliers, tooling changes, process changes, and any natural break in production.
- Counterfeit parts prevention procedure, especially for purchased electronic components and hardware.
- Special requirements, critical items, and key characteristics identified on drawings and flowed down onto routers and inspection plans.
- Calibration program with current records for every piece of measurement and test equipment in use.
- Internal audit schedule that covers every clause of the standard at least annually, with objective evidence of findings and closure.
- Nonconformance and corrective action (CAPA) process with genuine root cause analysis, not template answers.
- Approved supplier list with documented flow-down of applicable requirements (including customer-specific and regulatory requirements) to each supplier and special-process source.
- Training records tied to competency requirements for every role that affects product conformity.
- Lot and serial traceability from raw material or purchased part through final shipment. See Lot & serial traceability, explained for what a defensible traceability chain needs to contain.
- Management review meeting minutes that address quality objectives, audit results, customer feedback, and risk, on a defined cadence.
- Control of monitoring and measuring equipment, including out-of-tolerance investigation procedures.
- Documented contract review process before order acceptance, confirming the shop can meet the requirements it's agreeing to.
Work down that list honestly. Where you find a gap, that's your pre-audit corrective action, not something to paper over before the auditor arrives.
How Carbon supports AS9100 readiness
AS9100 is a records and traceability problem as much as a process problem. The standard doesn't only ask you to do the right things, it asks you to prove you did them, on the specific job an auditor picks up at random. That's much harder when quality records, work orders, purchasing, and inspection data live in disconnected systems (a paper traveler, a spreadsheet for NCRs, a separate calibration log). Carbon's QMS runs on the same data model as production and purchasing, so:
- Nonconformance, CAPA, and inspection records link directly to the work order, lot, and supplier that produced them, so an auditor tracing a job sees one connected record instead of four disconnected systems.
- Special requirements and key characteristics live on the router itself, so what the drawing calls out and what the operator is required to verify stay in sync.
- Lot and serial genealogy is native to the data model, supporting the traceability an auditor will test by picking a shipped part and tracing it backward.
- FAI records and approved supplier data are structured records, not free-text attachments, which makes stage 2 evidence retrieval fast instead of a scramble through file folders.
- Open source: because the full source is available on GitHub, your quality team can verify exactly how records are structured and retained before betting a certification on it.
Frequently asked questions
What's the difference between ISO 9001 and AS9100?
AS9100 incorporates the entire ISO 9001 standard and adds aerospace-specific requirements on top: risk management tied to product safety, configuration management, first article inspection, counterfeit parts prevention, and control of critical items and key characteristics.
How long does it take a small shop to get AS9100 certified?
It varies widely by how mature your existing QMS is, but most small shops moving from an informal quality system spend several months to a year building out documentation, records, and evidence before a realistic stage 1 audit, followed by stage 2 and any corrective actions from findings.
Do I need AS9100 if I only sell to a Tier 2 or Tier 3 aerospace supplier?
Often yes. Many primes require their entire qualified supply chain to hold AS9100, not just direct Tier 1 suppliers, and flow that requirement down contractually regardless of your tier.
What's the most common reason small shops fail an AS9100 audit?
Traceability and record gaps found when an auditor traces a job end to end: a missing calibration record, an FAI that doesn't match AS9102's form structure, or a CAPA with root cause analysis that's a template rather than genuine investigation.
Is AS9100 the same everywhere in the world?
The standard itself is global (maintained by IAQG), but it's published under regional numbering (AS9100 in the Americas, EN 9100 in Europe, JISQ 9100 in Japan) with equivalent technical content.
Build your AS9100 evidence trail into your ERP
If you're preparing for certification, it's worth evaluating a system where quality records, traceability, and production data live in one place instead of four. Try Carbon free for 30 days at https://app.carbon.ms, or explore the QMS data model on GitHub.
