| name | iatf-16949-audit |
| description | Conduct an IATF audit, check supplemental requirements, or prepare for a manufacturing process audit or IATF 16949:2016 third-party assessment. Covers customer-specific requirements (CSR), all 16 automotive supplemental clauses, and the three required audit types: QMS audit, manufacturing process audit, and product audit. Use for internal IATF audits or supplier quality audits at automotive organisations. |
| license | MIT |
| metadata | {"author":"RBraga01","version":"1.1","iatf-16949":"9.2.2","domain":"quality-engineering","subdomain":"audit","industries":"automotive,electronics","status":"approved","created":"2026-06-01","last_updated":"2026-06-03","updated_by":"migmcc","reviewed_by":"RBraga01","standard_edition":"IATF 16949:2016"} |
IATF 16949:2016 Internal Audit — Supplemental Requirements
Goal
Audit the automotive-specific supplemental requirements of IATF 16949:2016, including CSR compliance and the three mandatory internal audit streams. Use in conjunction with iso-9001-internal-audit for a complete IATF audit.
When to use
This skill covers the IATF 16949 supplemental requirements — the automotive additions to ISO 9001.
IATF 16949 requires three types of internal audit (§9.2.2.1). All three must be planned, executed, and recorded within the audit programme cycle:
- QMS audit — covers the entire quality management system (ISO 9001 + IATF supplementals)
- Manufacturing process audit — process-based, covers all manufacturing processes at least annually
- Product audit — product-specific, verifies product conformance to specifications
All manufacturing processes must be audited at least annually, with increased frequency for high-risk or poor-performing areas.
Required IATF Audit Checklist
☐ Verify all three audit streams are planned and executed within the programme cycle
☐ Confirm CSR register is current and that changes trigger QMS document updates
☐ Check contingency plans are documented, reviewed, and tested (not just written)
☐ Verify special characteristics are consistent across all documents (drawing, DFMEA, PFMEA, CP, WI)
☐ Confirm supplier monitoring and escalation are active with defined thresholds
☐ Check Control Plan ↔ PFMEA linkage is current
☐ Verify traceability and suspect material isolation capability (24-hour test)
☐ Review temporary deviations for approval, expiry, and active control
☐ Verify problem-solving methodology is applied with objective evidence of effectiveness
☐ Confirm management review includes all IATF supplemental inputs
☐ Do not accept verbal confirmation — verify by observing the process, interviewing personnel, and reviewing records
Key IATF 16949 supplemental requirements — audit questions
§4.3.2 — Customer-specific requirements (CSR)
This is the most commonly non-conforming IATF clause.
Questions:
- Is there a register of all applicable customer-specific requirements (CSRs)?
- For each OEM customer: have the latest CSRs been downloaded and reviewed?
- Are CSR requirements addressed in the QMS (procedures, control plans, work instructions)?
- Are personnel who deal with each customer aware of their specific requirements?
- CSR review must be revision-controlled and linked to implementation evidence in affected documents — is this traceable?
- Evidence: CSR register, evidence that each CSR has been reviewed and implemented, CSR revision dates vs. QMS document dates
High-risk CSR areas: PPAP requirements, problem-solving format requirements, special characteristics symbols, labelling specifications, sub-supplier approval requirements.
§5.1.1.1 — Corporate responsibility
- Is there a documented corporate responsibility policy (ethics, anti-bribery)?
- Is there an escalation process for reporting ethical concerns?
- Are employees aware of how to report ethical concerns confidentially?
- Evidence: code of conduct, ethics policy, reporting mechanism (hotline or similar)
§5.3.1 — Organisational roles, responsibilities, and authorities — supplemental
- Is there a person responsible for customer satisfaction?
- Are responsibilities for special characteristics defined?
- Is there a process for communicating customer requirements to all relevant functions?
- Evidence: roles matrix with customer satisfaction ownership identified
§6.1.2.1 — Risk analysis (supplemental)
- Does the risk analysis consider lessons learned from similar products?
- Is warranty data, field returns, and customer complaints included as inputs?
- Evidence: risk analysis records with warranty/field data inputs
§6.1.2.3 — Contingency plans
IATF requires documented contingency plans for:
- Key equipment failure
- Key supplier failure or disruption
- Labour shortages
- IT/infrastructure failure
- Natural disasters or site incidents affecting delivery
Questions:
- Are contingency plans documented for each of these scenarios?
- Are plans reviewed periodically (at least annually)?
- Are they tested or rehearsed?
- Does top management know who activates contingency plans?
- Do contingency plans include customer communication protocols and recovery priorities?
- Evidence: contingency plan document, last review date, test/simulation records
§7.2.3 — Internal auditor competency
- Are internal auditors formally qualified or trained?
- Do auditors have process knowledge for the areas they audit?
- Is there evidence of auditor training (certification, OJT, qualification test)?
- Are auditors independent of the area they audit?
- Is auditor effectiveness periodically reviewed based on audit quality and finding accuracy?
- Evidence: auditor qualification records, audit schedule showing independence
§7.2.4 — Second and third-party auditor competency
- For supplier audits: are supplier auditors trained and qualified?
- For customer audits: are there designated contacts?
§8.3.2.1 — Design and development — supplemental
- Are special characteristics (SC) identified and documented in DFMEA and drawings?
- Are customer-specific SC symbols used correctly?
- Are SC characteristics flowed down to PFMEA, Control Plan, and work instructions?
- Evidence: drawing with SC marked, DFMEA with SC, PFMEA with SC, Control Plan with SC, WI with SC
§8.3.3.3 — Special characteristics
- Is there a process to identify, document, and control all special characteristics?
- Do all documents (drawing, DFMEA, PFMEA, CP, WI) use consistent SC symbols?
- Are operators aware of which characteristics are special?
- Any inconsistency in SC identification across documents must be treated as a significant audit finding due to control failure — is SC consistency actively verified?
- Evidence: SC registry or matrix cross-referencing all documents
§8.4.1.2 — Customer-directed sources (directed buy)
- When the customer directs a specific supplier (directed buy), is this documented?
- Is the directed supplier included in the approved supplier list?
- Is quality monitoring applied even if the customer selected the supplier?
§8.4.2.3 — Supplier monitoring
IATF requires active supplier monitoring with specific actions for non-performing suppliers.
Questions:
- Is there a supplier performance monitoring system (PPM, on-time delivery, quality issues)?
- Is supplier performance reviewed at a defined frequency (minimum quarterly)?
- Are supplier development or escalation actions triggered based on defined performance thresholds?
- For poor performers: is there a documented escalation and improvement process?
- Are suppliers assessed for delivery of conforming product (not just quality level)?
- Evidence: supplier scorecards, last 4 quarters of performance data, improvement plans for poor performers
§8.5.1.1 — Control plan
Questions:
- Is there a control plan for each production part?
- Does it cover: pre-launch, production, and reaction plan?
- Are all special characteristics in the control plan with specific control methods?
- Is the control plan linked to the PFMEA (detection controls match)?
- Are reaction plans in the Control Plan understood and applied at the point of use — not only documented?
- Was it updated after the last process or product change?
- Evidence: control plan, PFMEA (verify linkage), latest revision date vs. last process change date
§8.5.2.1 — Identification and traceability — supplemental
- Is full traceability from raw material to finished product maintained?
- Can suspect material be isolated within 24 hours?
- Is there a procedure for handling suspect material?
- Are lot sizes defined to limit the scope of recalls?
- Evidence: traceability records, suspect material handling procedure, sample traceability exercise (ask for a part and trace it backwards)
§8.5.6.1.1 — Control of changes — supplemental (temporary change)
IATF requires that temporary process changes (deviations) be strictly controlled.
Questions:
- Is there a process for managing temporary deviations (substituting a process step or material)?
- Are deviations approved in writing with defined expiry dates?
- Is there a register of all open temporary deviations?
- Are expired deviations actively closed or extended — not left open silently?
- Is the customer notified when required by their CSR?
- Evidence: deviation register, sample open deviation with expiry date and approval
§8.7.1.1 — Customer notification
- Is there a procedure for notifying the customer when suspect material may have been shipped?
- Does it define when notification is required (not just when the customer asks)?
- Does the procedure specify notification timelines (e.g., 24 hours for safety-related escapes per CSR)?
- Has the procedure been triggered recently? Were notifications timely?
- Evidence: notification procedure, last notification records (if any)
§9.2.2.1 — Internal audit programme — supplemental
IATF requires three audit streams — most organisations fail by only conducting clause-based audits:
- QMS audit — covers clauses; must cover entire QMS within the audit programme cycle
- Manufacturing process audit — process-based, all manufacturing processes annually minimum; uses VDA 6.3 or equivalent scoring
- Product audit — product/shipment audits at defined frequency
Questions:
- Are all three audit types in the programme?
- Is the manufacturing process audit process-based (turtle diagram approach)?
- Are all processes and products covered within the audit cycle?
- Is the audit programme risk-based (higher risk = higher audit frequency)?
- Low process audit scores must trigger corrective action, management review, and re-audit planning — is this in place?
- Evidence: annual audit programme, audit reports for all three types, process audit records (not just clause audits)
§9.3.2.1 — Management review — supplemental inputs
IATF management review must include (in addition to ISO 9001 §9.3.2):
- Cost of poor quality (COPQ)
- Warranty performance (if applicable)
- Customer satisfaction and field performance review
- Status of CSR compliance
- Manufacturing feasibility assessments
Questions:
- Are these topics covered in the management review agenda?
- Is there data for each topic?
- Are decisions from these IATF-specific inputs translated into actions with owners and due dates?
- Evidence: management review minutes with IATF-required topics explicitly addressed
§10.2.3 — Problem solving
- Is there a documented problem-solving methodology (8D or equivalent)?
- Is the methodology applied consistently across all quality escapes?
- Does the 8D identify root cause of occurrence AND root cause of escape?
- Is effectiveness verified before closure?
- Evidence: problem-solving procedure, sample 8D reports, verification of effectiveness records
§10.2.4 — Error proofing
- Is there a documented approach to applying error-proofing (poka-yoke)?
- Are poka-yoke devices tested at defined intervals (IATF requires: minimum at every start of production)?
- Are test records maintained?
- Are failed or bypassed error-proofing checks treated as production stop / reaction plan triggers where applicable?
- Are poka-yoke failures treated as non-conformances requiring CAPA?
- Evidence: poka-yoke register, test frequency, test records, last test date vs. interval
§10.3.1 — Continual improvement plan
- Is there a formal, documented continual improvement plan?
- Does it include manufacturing process effectiveness (not just quality KPIs)?
- Is it reviewed at management review?
- Evidence: CI plan document, last review, evidence of CI activities
Product audit — §9.2.2.3
A product audit verifies that finished products meet all requirements before shipment. It is one of the three mandatory IATF audit streams.
Focus areas for product audit:
- Product conformity to drawing and specification (dimensional, functional, visual)
- Packaging and labelling compliance (OEM label format, part number, revision, quantity)
- Traceability and release status (is the product formally released and traceable to its records?)
- Audit frequency based on risk, customer issues, and product criticality
Evidence required: product audit reports, measurement records, packaging inspection records, release documentation.
Manufacturing process audit — turtle diagram approach
A manufacturing process audit (required annually for each process) uses a turtle diagram to assess:
| Input | Question |
|---|
| Who (Man) | Qualification requirements, training, availability |
| With what (Machine) | Equipment capability, maintenance, calibration |
| Using what method | Work instructions, current, at point of use |
| With what material | Incoming material control, traceability |
| With what measurement | Gauges, MSA, SPC |
| Environment | Cleanroom, temperature, ESD, contamination |
| Process output | First-pass yield, defect rate, scrap |
| Customer feedback | PPM, complaints, warranty |
For each element: is it adequate? Is it controlled? Is there objective evidence?
Each turtle element should be verified by direct observation, interview, and record review — not by document review alone.
A process audit must result in a process audit score (VDA 6.3 uses a percentage score by process element P1-P7). Low scores must trigger corrective action, management review input, and re-audit planning.
Common IATF audit failures
- CSR register not updated when customer publishes new CSR revision
- No manufacturing process audits — only clause-based audits in the programme
- Contingency plans exist but were never tested
- Temporary deviations without expiry dates or expired deviations not closed
- SC not consistently marked across drawing, PFMEA, control plan, and work instruction
- Error-proofing not tested at every start of production (frequency not defined or records not kept)
- Problem-solving procedure exists but CARs in practice skip root cause or VOE
Output Format
At the start of each use, ask the user:
"How would you like to receive the output?
A — Structured Markdown (formatted tables and sections, ready to copy)
B — Plain tables (simplified structure for Excel or Word)
C — Narrative report (flowing text for a formal document or email)
Default: A."
Adapt all output sections to the chosen format. If the platform or session context already defines a format preference, skip this question.
Reference files
Changelog
| Version | Date | Author | Change |
|---|
| 1.0 | 2026-06-01 | @RBraga01 | Initial release |
| 1.1 | 2026-06-03 | @migmcc | Added supplemental requirements reference and CSR audit coverage |