AS9100 Documentation & Records Requirements

Introduction

Ask any AS9100D auditor what trips up the most suppliers, and documentation gaps come up almost immediately. Ask any AS9100D auditor what trips up the most suppliers, and documentation gaps come up almost immediately.

Smithers, which conducts AS9100 audits across the aerospace supply chain, lists outdated procedures, uncontrolled documents, and gaps in records among the most common findings auditors write up.

Part of the problem is a wording change. AS9100D dropped the term "documented procedure" in favor of "documented information." Many quality teams read that shift as permission to document less. That's not quite right, and misreading it creates real audit exposure.

This article breaks down exactly what's mandatory, what's optional, how Clause 7.5 governs control, and how to stay audit-ready without burying your team in paperwork nobody uses.

Key Takeaways

  • AS9100D merged "documents" and "records" into one term: documented information
  • Only about 7 documents and 19 record types are explicitly mandatory; everything else is your organization's call
  • Clause 7.5 controls how documented information is created, protected, and retained—in any format
  • Missing revisions and blank templates are top preventable findings a structured control system catches early

What Is "Documented Information" Under AS9100D?

When AS9100D adopted ISO 9001:2015's shared clause structure, the standards bodies collapsed separate references to "documents," "records," and "documented procedures" into one term. IAQG's own transition materials confirm the logic: information that's subject to change is maintained, while information that serves as evidence and typically doesn't change is retained.

That's a vocabulary fix, not a scope reduction. The functional distinction quality teams have always worked with still exists:

  • Documents guide how work should be performed — policies, procedures, work instructions, plans
  • Records provide evidence that work actually happened — inspection results, training logs, review outcomes

Required documented information falls into two buckets:

  • Whatever AS9100D explicitly names as mandatory
  • Whatever your organization determines it needs to run an effective QMS, scaled to size, process complexity, and how much your people already know

A five-person machine shop and a 500-person Tier 1 supplier will land on very different document counts. Both can be fully compliant.

Mandatory Documents & Records Required for AS9100D Certification

Here's where the confusion usually clears up. AS9100D names a relatively short list of documents and records as truly mandatory. Everything beyond this list is something the organization chooses to create.

Mandatory Documents by Clause

Clause What Must Be Documented
4.3 Scope of the QMS, including justified exclusions
4.4.2 Process descriptions, interactions, sequence, and responsibilities
5.2.2 Quality policy
6.2.1 Quality objectives and plans to achieve them
8.4.1 Control of externally provided processes, products, and services
8.7.1 Control of nonconforming outputs
10.2.1 Nonconformity and corrective action management process

That's the core seven. Some documents only become mandatory if you actually perform that process. Design and development documentation under Clause 8.3, for instance, only applies if your organization designs products. If you're a build-to-print supplier, those clauses simply don't trigger.

Mandatory Records by Process Area

The retained-evidence list is longer, roughly 19 categories, and groups naturally by function:

QMS evidence and competence:

  • Evidence processes are carried out as planned (4.4.2)
  • Calibration and maintenance records for measuring equipment (7.1.5.1)*
  • Employee competence records (7.2)

Customer requirements and design:

  • Requirement review results (8.2.3.2)
  • Design input, control, output, and change records (8.3.3–8.3.6)*

Production and service provision:

  • Product/service characteristics and results (8.5.1)
  • Production process validation results (8.5.1.3)
  • Traceability records (8.5.2)*
  • Customer property records (8.5.3)
  • Production/service change records (8.5.6)
  • Conformity and release evidence (8.6)

Nonconformity, performance, and improvement:

  • Nonconforming output records (8.7.2 and 10.2.2)
  • Monitoring and performance information (9.1.1)
  • Internal audit program and results (9.2.2)
  • Management review records (9.3)
  • Corrective action records (10.2.2)

*Asterisked records are conditional. They only apply if that clause fits your scope of operations. A supplier with no traceability requirement in its customer contracts doesn't need to fabricate traceability records to satisfy 8.5.2.

AS9100D mandatory documents and records breakdown by clause category

Document & Record Control Requirements Under Clause 7.5

Clause 7.5 is where AS9100D stops caring whether something is a "document" or a "record" and just calls it documented information. One set of rules governs both.

Identification, Availability, and Protection

Every piece of documented information needs proper identification and description, an appropriate format and media, and a review/approval step before it's released for use. From there, three things have to be true at all times:

  1. It's available where and when it's needed: accessible, retrievable, and usable at the point of work, not locked in someone's inbox
  2. It's protected against loss of confidentiality, misuse, or loss of integrity: this includes preventing edits to conformity evidence after the fact
  3. Version control prevents unintended use of obsolete versions: the current revision has to be unmistakably the current revision

IAQG's clarification guidance is blunt on one point here: pencil isn't acceptable on quality documentation, because it can be altered without a trace. That single line captures the spirit of the whole clause: evidence has to hold up.

Retention and Disposition

AS9100D deliberately doesn't set a universal retention period. That decision is left to the organization, shaped by contract terms and customer flow-down requirements.

Real-world aerospace examples show how wide that range gets:

  • Airbus's generic supply chain requirement sets a default of at least 15 years for quality records unless the purchaser and supplier agree otherwise
  • Some OEM quality codes tie retention to specific record types, ranging from a few years after final payment to more than a decade after delivery, with no destruction allowed without written customer approval

The takeaway: check your customer's flow-down clauses before you set a default retention policy. Whichever requirement is longer, wins.

AS9100D is media-neutral, meaning paper, spreadsheets, and cloud platforms are all fair game. But the standard expects controls scaled to complexity. This is where a lot of manual, binder-based systems fall apart: revision history gets lost, approval trails go missing, and nobody can prove which version was live on a given date.

Platforms built for this, like QMS Learning's Document Management System, handle it differently. Every revision is preserved in an append-only history alongside its review and release record, so a superseded version can never be mistaken for the live one.

Documents also map directly to the standards clauses they support. A receiving inspection procedure, for example, can link to AS9100D, AS9120, and any other applicable standard at once. That connection stays visible instead of something you reconstruct during an audit.

Document management system interface showing revision history and clause mapping

Non-Mandatory Documents Most Aerospace Programs Still Use

Most certified organizations document more than the mandatory list requires. Extra procedures are often the simplest way to prove conformity on clauses that never name a specific document but still expect evidence of a controlled approach.

Common non-mandatory procedures include:

  • Context of the organization and interested parties analysis
  • Risk and opportunity management procedures
  • Competence and training procedures
  • Document control procedures

Beyond those, most programs also formalize:

  • Sales and contract review procedures
  • Design and development procedures (where applicable)
  • Production and service provision work instructions
  • Warehousing and material handling procedures
  • Configuration management procedures
  • Operational risk procedures for process, product, and delivery

Start with the mandatory set only. Add non-mandatory documents incrementally as gaps surface during internal audits.

Over-documenting from day one creates more revisions to control, more training to track, and more places for inconsistencies to hide. A lean system that grows from real findings beats a comprehensive one nobody maintains.

Best Practices for Managing AS9100 Documentation & Staying Audit-Ready

Auditors don't just check whether a procedure exists. They check whether your team can pull the correct revision on demand and prove the process described in it was actually followed. That's the gap Smithers flags repeatedly — documents that exist on paper but don't hold up under scrutiny.

A few practices consistently close that gap:

  • Clause-map every document. Tie each mandatory document and record to its owning process and a named responsible role. No owner means a gap an external auditor will find first.
  • Never leave templates blank. A record only counts as evidence when it's signed, dated, and filled with real data. Empty forms are instant nonconformities, not gray areas.
  • Replace spreadsheet approval trails. Manual control loses revision history and blurs who approved what. Use segregation of duties, controlled versioning, and one-click evidence export instead.
  • Compile evidence in minutes, not days. QMS Learning's document system packages controlled documents, revision history, and acknowledgment logs into a single indexed Audit-Evidence Package.
  • Link competence records to revisions. Timestamped read-and-understand acknowledgments per person keep "who knew what, and when" with the organization — not walking out with a departing employee.

Five best practices checklist for AS9100 documentation audit readiness

Frequently Asked Questions

What are the mandatory documents required for AS9100D certification?

Seven documents are explicitly mandatory: QMS scope, process descriptions, quality policy, quality objectives, control of externally provided processes, control of nonconforming outputs, and the corrective action process. See the full breakdown above for exact clause references.

What are the AS9100 requirements?

AS9100D builds on ISO 9001:2015's 10-clause structure and adds aerospace requirements for risk, configuration management, product safety, and counterfeit parts prevention—with tighter documented information and traceability controls than ISO 9001 alone.

How long must AS9100 records be retained?

AS9100D doesn't set a universal retention period. Organizations define retention based on contract and program requirements, and customer flow-down clauses often extend that period for the life of the product or program.

Does AS9100D still require a quality manual?

Not by name. AS9100D doesn't mandate a standalone "quality manual," but the scope and process documentation required under Clauses 4.3 and 4.4.2 leads most organizations to compile one anyway for clarity and audit convenience.

What is the difference between a document and a record in AS9100?

Documents describe how a process should be performed and are proactive by nature. Records provide evidence that a process actually happened. Both fall under the umbrella term "documented information."

Can AS9100 documentation be maintained electronically?

Yes. AS9100D is media-neutral, so electronic documented information is fully acceptable as long as you have controls in place for access, protection, and retrieval.