Aviation AS9100 Quality vs ISO 13485: Shared DNA and Different Proofs

Quality inspector reviewing a traveler beside an aircraft wing in a hangar

AS9100 and ISO 13485 both grew from ISO 9001. Both demand a documented quality management system, risk-based thinking, competent people, controlled documents, purchased-product control, nonconformity, and CAPA. If you have run one, the other will feel familiar for about two weeks. Then the proofs diverge.

This is a field guide for quality leaders who already speak one language and need to brief executives, auditors, or a dual-use plant on what transfers and what does not.

Shared DNA: the ISO 9001 skeleton

AS9100D (the current widely implemented aviation, space, and defense QMS standard published by the IAQG) is ISO 9001:2015 plus aviation-specific requirements. ISO 13485:2016 is a standalone medical-device QMS standard. It is not a pure ISO 9001 overlay, but it still uses the process approach, documented information, management responsibility, resource management, product realization, and measurement.

Shared expectations you can reuse almost verbatim:

  • Context, interested parties, and QMS scope (9001/AS9100 clause 4; 13485 clause 4)
  • Leadership, policy, roles (clause 5 in both families)
  • Risk-based thinking at the system level
  • Competence, awareness, infrastructure, work environment
  • Documented information control, including retention and retrieval
  • Operational planning, purchasing, identification and traceability, preservation
  • Internal audit, management review, nonconformity and corrective action
  • Control of nonconforming product / nonconforming outputs

If your document-control SOP already requires unique IDs, revision, approval, and obsolete-copy control, do not rewrite it for the other standard. Add the extra retention and record types. Keep one procedure.

Different proof #1: who the customer of safety is

Aviation quality exists so an aircraft part does not fail in service in a way that the airworthiness system did not already accept. The "customer" includes the OEM, the operator, and the civil aviation authority (FAA, EASA, and others). AS9100 leans hard on product safety, counterfeit parts, configuration management, and special requirements / critical items / key characteristics.

ISO 13485 exists so a medical device is safe and performs as intended for patients and users. The "customer" includes the manufacturer’s quality system, competent authorities, and, for many firms, FDA. Proof lives in design controls, risk management per ISO 14971, clinical or performance evaluation as applicable, and post-market surveillance.

A first-article inspection packet that satisfies AS9100 and an AS9102 form will not satisfy 820.30 design validation. A design history file will not satisfy an aerospace customer’s FAIR and configuration accounting. Do not force one evidence pack to wear both hats. Map the overlapping records (traceability, calibration, NCR, CAPA) and keep the unique packs unique.

Different proof #2: configuration and change

AS9100 clause 8.1.2 (and related notes on configuration management) expects you to plan, identify, and control configuration throughout the product lifecycle, including changes. Aerospace customers often flow down specific CM requirements, effectivity, and embodied-mod status.

ISO 13485 clause 7.3.9 controls design and development changes. Clause 7.5.3 covers identification and traceability. For devices, a change may also trigger regulatory reporting or a new premarket submission. The proof is impact assessment against design inputs, risk, V&V, labeling, and regulatory status, plus approval before implementation.

Dual-use plants get into trouble when an ECO form built for aerospace effectivity is reused for a device without the regulatory impact block, or when a device change form has no configuration effectivity for a shared machining cell. Use one change workflow if you must. Require two impact checklists.

Different proof #3: special processes vs process validation

Aerospace lives on NADCAP and special process control: heat treat, NDT, welding, chemical processing. The proof is often a qualified process, a qualified operator, and a certificate from a special-process source.

ISO 13485 clause 7.5.6 (validation of processes for production and service provision) and FDA process validation guidance expect IQ/OQ/PQ or an equivalent documented rationale when the output cannot be fully verified by subsequent inspection. Sterilization, aseptic fill, and many software-controlled processes sit here.

A heat-treat cert is not an IQ/OQ/PQ. An IQ/OQ/PQ is not a NADCAP audit. If the same oven serves both, you still need both evidence types, or a written decision that one product family does not use that process.

Different proof #4: purchased product and counterfeit / supplier controls

AS9100 puts explicit weight on counterfeit part prevention, unapproved parts, and flow-down to external providers, including the right of access for the organization, its customers, and regulatory authorities. OASIS and customer portal scorecards are part of the lived system.

ISO 13485 clause 7.4 and FDA purchasing controls expect evaluation, selection, monitoring, and written quality requirements. For devices, supplier files often include quality agreements, change-notification clauses, and process validation evidence at the supplier when the supplier process cannot be fully verified incoming.

Shared: approved supplier list, incoming inspection or verification activities, SCAR/CAPA when they fail you.

Different: counterfeit-part training and AS6174-style controls versus device supplier process validation and UDI/labeling change notification.

Different proof #5: nonconformity, concessions, and advisory notices

Aerospace concessions and production permits are common and tightly controlled. You may use a nonconforming part with customer engineering approval and documented effectivity.

Device firms can also justify use-as-is, but the bar is risk to patient and user, not only customer engineering. ISO 13485 clause 8.2.3 (complaint handling), 8.2.2 (feedback), 8.3 (advisory notices / field actions in many implementations), and FDA's correction and removal / MDR framework sit next to CAPA.

Do not copy an aerospace "use as is" stamp onto a device traveler. The approval authority and the risk analysis are different documents.

Personnel and culture

AS9100 awareness includes product safety and ethical behavior (the 2016 revision made this explicit). ISO 13485 competence includes regulatory requirements applicable to the work. Both need training records that match actual tasks.

The cultural mismatch is real. Aerospace quality often grew up around traveler discipline, stamps, and customer source inspection. Device quality often grew up around DHF/DMR/DHR (or medical device file / production records under ISO language) and design control meetings. Cross-trained auditors should not mock either culture. They should translate.

A practical dual-certification map

If you are adding the second certificate:

  1. Keep one QMS manual with two applicability matrices (which clauses apply to which product lines and sites).
  2. Share document control, training, calibration, internal audit program, management review agenda (with both standards as standing inputs), and CAPA.
  3. Split design/development, configuration/change impact, process validation vs special process, post-market / in-service feedback, and customer-specific aerospace portals.
  4. Train internal auditors on the proof, not only the clause number. An auditor who asks for a DHF on a bracket that is build-to-print aerospace will waste a day. An auditor who asks for a FAIR on a 510(k) device will do the same.

IAQG materials and ISO 13485:2016 plus ISO 14971 are the primary texts. Read them. Flow-down from your largest aerospace customer and your device regulatory submissions will fill the gaps no overview article can.

Production records: traveler vs DHR

Aerospace production often runs on a traveler or work order with stamp fields, split lots, and customer source-inspection hold points. Device production runs on a Device History Record (or production record under ISO 13485 7.5) that must show the DMR was followed, the quantity, acceptance records, and the primary identification label.

If a cell builds both, do not force one form. Use a common header (part, lot, operator, equipment) and two body templates. Mixing stamp culture into a DHR without the required acceptance data, or mixing DHR language onto a traveler that a DCMA QAR expects to see, creates findings in both directions.

Calibration and measurement systems

Both standards require calibrated monitoring and measuring resources. AS9100 customers often flow down specific recall systems and MSA expectations on key characteristics. ISO 13485 and FDA expect the same instruments that release product to be in a controlled program, with impact assessment when they are found out of tolerance.

A shared calibration SOP works. Add: out-of-tolerance impact includes aerospace key characteristics and device acceptance criteria; both product families get assessed. Do not let the metrology lab close an OOT with "no aerospace impact" while a device lot used the same micrometer.

Internal audit sampling

Audit aerospace product lines against AS9100 additional requirements (8.1.1 operational risk, 8.1.2 configuration, 8.1.3 product safety, 8.1.4 prevention of counterfeit parts, 8.1.5 operational planning extras, 8.4.1.1 external provider control extras, 8.5.1.1 control of equipment, tools and software programs, 8.7 control of nonconforming outputs extras). Audit device lines against 7.3 design, 7.5.6 process validation, 8.2.1 feedback, 8.2.2 complaint, and the regulatory post-market pieces your procedure claims.

A combined audit that only samples ISO 9001 clauses will certify neither culture. Plan two sampling lists even if one auditor walks both halls in one week.

Management review inputs that keep both certificates honest

Put on the same agenda, labeled:

  • Customer scorecards and escapes (aerospace) next to complaints and MDRs or equivalent (device)
  • On-time FAIRs and concession aging next to open design changes and overdue V&V
  • OASIS or customer portal status next to inspection readiness and field-action status
  • Special-process / NADCAP findings next to process-validation deviations

If leadership only hears the louder certificate, the quieter one fails next year.

When not to dual-certify a cell

Some work should stay single-standard: a build-to-print bracket with no design authority does not need a DHF theater. A 510(k) device with software and sterilization does not need a FAIR theater. Shared infrastructure (calibration, document control, training) can still be one QMS. Forcing unique proofs into the wrong cell wastes auditors and confuses operators.

Write the applicability matrix at the part-family level, not only at the site level. Auditors read the matrix. Operators need it posted where the work happens.

The shared DNA is real. The proofs are not interchangeable. Treat them that way and a dual-use plant can run one quality organization without lying to either auditor.

Emma Johnson
QA Consultant

About Cloudtheapp

Cloudtheapp is an AI-Powered Configurable Validated Cloud Platform built to provide the most configurable, easy-to-use Quality Management and Regulatory Compliance SaaS software on the market.

We believe that having a single platform to manage compliance and transformation needs is essential for businesses in the modern world. We've created an innovative configurable cloud platform built for the compliance world so you can easily implement ready-made applications with no additional installs or infrastructure required – and without writing a single line of code!

Our experienced professionals have over three decades of software development experience between them, giving us unparalleled insight into how to build powerful solutions to address real challenges.

We have created an interconnected ecosystem where everyone involved in this process can collaborate successfully while minimizing disruption of any sort as well as ensuring entire organization's data remains visible always for better use making sure businesses always stay compliant.

We excelled in creating the most configurable, easy-to-use Quality Management and Regulatory Compliance SaaS software that requires light administration, so your staff has time to focus on streamlining their compliance process, innovate faster and minimize risk associated with non-compliance.

We will continue to strive towards engineering smarter tools for administrative staff so they can focus on building safe and quality products.

With years of experience in the industry, we are committed to providing our customers with reliable and secure solutions enabling them to be agile and move ahead confidently.

Request a Demo Now
AS9100 vs ISO 13485: Shared DNA, Proofs · Cloudtheapp