AS9100 Software Requirements: What Your System Actually Has to Do

AS9100 does not certify software. It certifies your process. Here is what an auditor actually asks your system to prove, and where most ERPs fall short.

No software is AS9100 certified. Certification applies to your quality management system, not to a product you can buy. Any vendor claiming their ERP is AS9100 certified is describing something that does not exist.

What is true is narrower and more useful: certain things your process has to demonstrate are painful without the right system and straightforward with it. That is the real question behind "what are the AS9100 software requirements," and it is worth answering precisely, because buying against the wrong version of it is expensive.

AS9100 is the aerospace quality standard built on top of ISO 9001, with additional requirements for the things aerospace cares about: traceability, configuration control, counterfeit part prevention, and first article inspection. Your software does not satisfy the standard. It makes the evidence retrievable.

What an auditor is actually testing

Auditors do not review your software architecture. They pick a part, a lot, or a nonconformance, and they follow it. The question underneath every request is the same one: can you show me, from records, that the process you documented is the process you ran?

That reduces to five capabilities. Each one is a place where a spreadsheet-based process burns hours during an audit and a well-structured system does not.

1. Document control that survives a revision

The requirement is that people work from the current version of a document, that superseded versions are not in use, and that changes are reviewed and approved before they take effect.

The failure is familiar. A work instruction lives on a shared drive, someone saves a local copy, and six months later a station is running revision C while the QMS says E. The audit finding is not that a document changed. It is that you could not demonstrate which version was in use at the time the part was made.

What the system has to do: hold one authoritative copy per document, carry a version history with named authors and dated changes, record the review before a change takes effect, and make the effective date retrievable after the fact.

2. Traceability in both directions

You need to go forward from a raw material lot to every part that consumed it, and backward from a finished part to every input, operation, and operator that touched it.

Forward traceability is what a containment action depends on. When a supplier notifies you of a nonconforming lot, the time it takes to answer "where did that material go" is the difference between a contained problem and a recall.

What the system has to do: attach lot and serial identity at receipt, carry it through every operation, and let you query it from either end without reconstructing the chain by hand.

3. Configuration management

Aerospace parts change by design and the change is controlled. The system has to know which configuration of a part was authorized at the time it was built, which engineering change orders applied, and what the effectivity was.

This is where ERPs sold to general manufacturing most often fall short. Managing a part number is standard. Managing a part number whose approved configuration varies by effectivity date and customer authorization is not.

4. Nonconformance and corrective action with a closed loop

Finding a nonconformance is not the finding. Failing to show what happened next is. The record has to carry the disposition, the containment, the root cause, the corrective action, the verification that it worked, and the dates and owners for each.

Spreadsheet-based NCR logs almost always pass the first two columns and fail the last three, because verification happens weeks later and the person who did it did not go back to update the row.

5. First article inspection you can reproduce

FAI requires that every characteristic on the drawing has a corresponding measured result, and that the report ties back to the specific drawing revision it was performed against. AS9102 forms are the common format.

What makes this painful by hand is not the measuring, it is the bookkeeping: keeping the ballooned drawing, the characteristic list, and the results aligned through a revision. Systems that treat FAI as a document attachment rather than structured data force that alignment to be done manually every time.

Where the common options land

ApproachDocument controlTwo-way traceabilityConfiguration by effectivityAudit prep effort
Spreadsheets and shared driveManualReconstructed by handNoWeeks
General mid-market ERPUsuallyPartialRarelyDays
Aerospace-specific ERPYesYesYesHours
Standalone QMS beside an ERPYesOnly if integratedDependsDays
Partner-built on your stackBuilt to your processYesYes, if scopedHours

The row worth examining honestly is the fourth. A separate QMS solves document control cleanly and often leaves a gap between quality records and production records, which is exactly where two-way traceability lives. Two systems that each pass their own audit can still fail the question that spans them.

The part most vendors will not tell you

Buying an aerospace-specific ERP moves the problem rather than removing it. Those systems encode a model of how an aerospace shop runs, and if your operation does not match the model, you adapt to the software. For a shop with unusual processes, that adaptation is where the cost and the resistance show up, and it lands on the same people the standard makes responsible for the process.

There is also a sovereignty question underneath compliance. If your quality records live in a vendor cloud you cannot query directly, your ability to answer an auditor depends on their export tool and their uptime. Manufacturing data sovereignty covers why residency, ownership, portability, and extensibility all matter here, and for ITAR work the residency dimension is not optional.

A five-question audit of your current system

1. Can you produce, in minutes, the revision of a work instruction that was effective on a given date?
2. Given a raw material lot number, can you list every part that consumed it without opening a spreadsheet?
3. Does every NCR in the last year carry a verification record with a date and an owner?
4. Is your FAI data structured, or is it a PDF attached to a record?
5. If your software vendor went dark tomorrow, could you still produce your quality records?

Anything you answered by describing a person rather than a system is a finding waiting to happen, because that person is your control and controls have to be documented.

Questions we get

What is the best ERP software for the aviation industry? The systems that come up most for aerospace work are the shop-focused ones with real quality modules, because the differentiator in this sector is evidence rather than accounting. Judge them on the audit questions above rather than on the aerospace logo in the brochure. Every vendor selling into this market says aerospace on the homepage, and the useful test is whether the system produces the record an auditor asks for without a developer.

Is any ERP actually AS9100 certified? No. Certification applies to an organization's quality management system. A vendor may be certified as a company, and their software may be built for aerospace workflows, but neither makes the product itself certified.

Do we need an aerospace-specific ERP to pass? No. Shops pass on general systems and on custom builds. What matters is whether the five capabilities above are actually satisfied and whether the evidence is retrievable. Aerospace-specific systems get you there faster if your process fits their model.

Can we stay on spreadsheets and pass? Shops do pass this way. The cost is that audit preparation consumes weeks of your quality team, and the risk is a finding on document control, because manual version control fails silently. Passing and being efficient are different questions.

Where do most findings come from? In our experience, document control and closed-loop corrective action. Both fail for the same underlying reason: the record was correct when it was created and nobody updated it when reality moved.

How does AI fit into a regulated shop? Carefully, and only on top of a controlled record set. A retrieval system that cites a superseded SOP is a quality event, not a convenience feature. That is why a manufacturing RAG system has to track revisions and effective dates before it is allowed anywhere near the floor.

We are ISO 9001 and moving to AS9100. How big is the gap? The management system carries over. The additions that usually require new capability are configuration management by effectivity, first article inspection, counterfeit part controls, and tighter traceability. If your current system handles ISO document control well, the gap is narrower than it looks.

What is next

Before evaluating any software, run the five questions above against what you have now. The answers tell you whether you have a tooling problem or a process problem, and those need different fixes. A shop with a process problem will get the same findings on new software.

If document control and drift are where you are weakest, quality substrates for AS9100 shops goes deeper on what a controlled record set looks like in practice. If you are weighing systems, the honest comparison of building, buying, and partner-built covers the tradeoffs. If retrieval under audit pressure is the weak point, traceability and audit readiness is the engagement for it. Or tell us which of the five questions you cannot answer and we will start there.