I get some version of this question from almost every aerospace supplier I sit down with in a gap analysis: "We're already ISO 9001 certified — how much more is AS9100 really?" The honest answer is that AS9100 Rev D is not a parallel standard sitting next to ISO 9001. It contains the entire text of ISO 9001:2015, clause for clause, and then layers aerospace-specific requirements on top of it. If you understand ISO 9001, you already understand roughly 80% of AS9100. This article walks through exactly what the other 20% consists of, why the aerospace industry decided it needed those additions, and what a realistic transition looks like for a manufacturer or supplier moving from one standard to the other.
What AS9100 Rev D Actually Is
AS9100 is published and maintained by the International Aerospace Quality Group (IAQG), whose member companies include Boeing, Airbus, and the major defense primes. IAQG operates through regional sector groups — SAE International in the Americas, ASD-STAN (part of ASD) in Europe, and SJAC in Asia/Pacific — which publish and maintain the 9100-series documents on IAQG's behalf. Rev D, released in 2016, was written to align with the Annex SL structure that ISO 9001:2015 introduced, which is why the two standards share identical clause numbering through clause 10. AS9100D did not invent a new framework — it inherited ISO 9001:2015's ten-clause structure and inserted additional sub-clauses and requirements at the points where aerospace risk is highest: design, purchasing, production control, and traceability.
That inheritance matters practically. An organization certified to AS9100 Rev D is, by definition, also compliant with ISO 9001:2015 — the aerospace standard is a strict superset. This is why most aerospace suppliers pursue a single combined audit rather than maintaining two separate certificates, and why a competent aerospace auditor is qualified to assess both standards in the same visit.
The Core Additions: Where AS9100 Diverges From ISO 9001
There are five areas where AS9100 Rev D adds substantive requirements that ISO 9001 does not contain. I'll take them in the order they appear in the standard, because that's also roughly the order clients ask about them.
Operational Risk Management (Clause 8.1.1)
ISO 9001:2015 asks organizations to apply risk-based thinking across the management system in clause 6.1. AS9100D goes further in clause 8.1.1, requiring a documented process for managing risk specifically in operations — the actual production and service delivery activities, not just the planning layer. The distinction is real: clause 6.1 is about how you plan the system; clause 8.1.1 is about how you manage risk on the shop floor, in real time, as parts move through operations.
Configuration Management (Clause 8.1.2)
This has no ISO 9001 equivalent at all. Configuration management requires organizations to control product configuration — the specific design, build standard, and modification history of a part or assembly — and to maintain traceability between the configuration and the product's conformity records. For an aftermarket part or a decades-old airframe program, this is the clause that keeps a 1987 design change from getting silently applied to a part built to the 1985 standard.
Product Safety (Clause 8.1.3)
AS9100D requires organizations to identify product safety risks and manage them throughout the product lifecycle. Product safety in this context means the risk that a failure could result in loss of life, not just customer dissatisfaction — a distinction ISO 9001 has no mechanism for because it doesn't assume flight-critical hardware. This clause is one reason aerospace auditors spend disproportionate time on FMEA records and failure-mode documentation compared to a general manufacturing ISO 9001 audit.
Prevention of Counterfeit Parts (Clause 8.1.4)
This clause exists because of a documented industry problem: counterfeit electronic components entering the defense and aerospace supply chain. The concern is serious enough that U.S. federal acquisition regulations address it directly — DFARS 252.246-7007 and 7008 require contractor counterfeit-part detection and avoidance systems for DoD suppliers. AS9100D requires organizations to have a process for preventing counterfeit parts from entering the product, including supplier controls, personnel training, and testing methods appropriate to the parts involved. ISO 9001 has nothing analogous because counterfeiting isn't a material risk in most of the industries ISO 9001 serves.
Purchasing Controls and Supply Chain Flow-Down (Clause 8.4)
ISO 9001 clause 8.4 covers control of externally provided processes, products, and services in fairly general terms. AS9100D adds three specific sub-requirements:
- Flow down applicable requirements, including customer requirements, to sub-tier suppliers
- Verify that purchased product conforms to specified requirements, using methods proportional to risk
- When required, obtain customer or regulatory authority approval before releasing product from a supplier the customer hasn't yet approved
This is the clause I spend the most time on in supplier quality engagements, because it's the one most often cited in nonconformities — aerospace primes have gotten specific about what "flow-down" has to look like on paper, and a purchase order that just says "comply with AS9100" usually doesn't satisfy it.
Production Process Equipment, Special Processes, and Process Verification (Clauses 8.5.1.1–8.5.1.3)
AS9100D expands ISO 9001's general production-control clause (8.5.1) into three aerospace-specific sub-clauses. Clause 8.5.1.1 covers control of production process equipment, tools, and numerical control (NC) machine programs, requiring validation before use and control of subsequent changes — a supplier can't quietly swap a fixture, tool, or NC program without evaluating the change. Clause 8.5.1.2, Validation and Control of Special Processes, requires processes whose results can't be fully verified by downstream inspection — welding, heat treating, and non-destructive testing are the usual examples — to be qualified and kept under documented control. Clause 8.5.1.3, Production Process Verification, requires periodic verification that a production process remains capable of producing conforming product. The broader requirement to evaluate and, where required, notify the customer before changing a production process at all lives in the general text of clause 8.5.1, carried forward from AS9100C's retired clause 7.5.1.2 rather than assigned its own sub-clause number.
Identification, Traceability, and Key Characteristics
AS9100D strengthens ISO 9001's traceability clause (8.5.2) with requirements around unique identification of product, especially for critical items and key characteristics — the specific dimensions or process parameters that most affect safety or performance. Combined with the First Article Inspection requirement (governed by the companion standard AS9102), this is how a supplier proves that the very first production part off a new or changed process actually matches the engineering definition, not just that its paperwork says it does.
ISO 9001 vs. AS9100 Rev D: Clause-by-Clause Comparison
| Requirement Area | ISO 9001:2015 | AS9100 Rev D |
|---|---|---|
| Base structure | 10-clause Annex SL framework | Identical 10-clause structure, inherited verbatim |
| Risk-based thinking | Clause 6.1, system-level planning | Clause 6.1 plus clause 8.1.1, operational risk management |
| Configuration management | Not addressed | Clause 8.1.2, required |
| Product safety | Not addressed | Clause 8.1.3, required |
| Counterfeit parts prevention | Not addressed | Clause 8.1.4, required |
| Purchasing / supplier flow-down | General controls, clause 8.4 | Clause 8.4 plus specific flow-down, sub-tier, and approval requirements |
| Production process equipment / special processes | General production control, clause 8.5.1 | Clauses 8.5.1.1–8.5.1.3: process equipment control, special-process validation, and process verification |
| First Article Inspection | Not addressed | Required per AS9102, referenced in clause 8.5.1 |
| Human factors | Not addressed | Addressed in clause 7.1.4 note and competence requirements |
| Certification body oversight | Standard accreditation | Additional IAQG OASIS database reporting via the AS9104 scheme |
Certification Body Oversight: The OASIS Database
One structural difference doesn't show up in the clause text at all: how certification is administered. ISO 9001 certificates are issued by any accredited certification body and generally aren't tracked in a shared public system. AS9100 certification data, by contrast, is uploaded by the certification body to OASIS (the Online Aerospace Supplier Information System), maintained by IAQG. Aerospace primes use OASIS to verify a supplier's certification status, scope, and audit history before awarding or continuing work. Certification bodies auditing to AS9100 must themselves be accredited under the AS9104 scheme, which is more prescriptive about auditor qualification and audit duration than general ISO 9001 accreditation rules. If your certification body can't point to OASIS reporting, that's worth asking about before you sign a contract with them.
Transitioning From ISO 9001 to AS9100 Rev D
For an organization that's already ISO 9001:2015 certified, the transition to AS9100D is a gap analysis exercise, not a rebuild. In my experience running these transitions, the work concentrates in four places: writing an operational risk process that goes beyond the system-level risk register most ISO 9001 shops already have, standing up configuration management if the organization has never formally controlled design baselines, rewriting purchase order templates and supplier agreements to carry the specific flow-down language clause 8.4 requires, and implementing First Article Inspection per AS9102 if the organization hasn't done FAI work before.
None of that is exotic. It is, however, easy to underestimate, particularly the supplier flow-down piece — I've seen organizations pass their own AS9100 audit cleanly and then get flagged in a customer supplier audit six months later because their own purchase orders to sub-tier machine shops never carried the required aerospace clauses. AS9100D holds the certified organization responsible for what its suppliers do, which means the paperwork discipline has to extend past your own four walls.
Timeline-wise, plan around two scenarios:
- Mature ISO 9001 system, no major gaps: four to six months, including a stabilization period before the certification audit
- Configuration management or counterfeit-parts prevention built from scratch: nine to twelve months before the certification audit
The certification cost itself follows the same drivers as any ISO 9001 project — headcount, site count, and process complexity — with AS9104's stricter audit-duration rules typically adding to the audit day count compared to a general ISO 9001 audit of comparable size.
Is AS9100 Worth Pursuing If You're Already ISO 9001 Certified?
If your customers are aerospace or defense primes, this usually isn't optional in practice even when it's technically voluntary — most Tier 1 and Tier 2 aerospace contracts require AS9100 certification as a condition of doing business, and OASIS makes verification of that status trivial for a buyer. For a shop that's ISO 9001 certified and considering whether to bid on aerospace work, the standard's added requirements are a reasonable proxy for what an aerospace customer is actually going to demand of you contractually anyway — flow-down, FAI, configuration control, and counterfeit-parts prevention show up in aerospace purchase orders whether or not you're certified to the standard that names them. Getting certified just means you've built the system before the customer asks for it instead of after.
Frequently Asked Questions
Does AS9100 Rev D replace ISO 9001 certification? No. AS9100 Rev D contains the full text of ISO 9001:2015 plus aerospace-specific additions, so an AS9100-certified organization is automatically compliant with ISO 9001:2015. Most organizations hold a single AS9100 certificate rather than two separate certificates.
What's the difference between AS9100, AS9110, and AS9120? AS9100 is for design, development, and production organizations. AS9110 applies to maintenance, repair, and overhaul (MRO) organizations. AS9120 applies to stockist distributors that don't design or manufacture product but handle, store, and distribute aerospace parts. All three share the same ISO 9001-based core structure.
Can a general ISO 9001 auditor perform an AS9100 audit? No. AS9100 audits must be performed by auditors qualified under the IAQG's AS9104 scheme, and the certification body itself must hold aerospace-specific accreditation. A standard ISO 9001 accreditation does not authorize a body to issue AS9100 certificates.
Do we need First Article Inspection if we're only ISO 9001 certified? First Article Inspection per AS9102 is an AS9100-specific requirement referenced in clause 8.5.1. ISO 9001 doesn't require it. That said, aerospace customers often require FAI contractually regardless of your certification status, so many ISO 9001-only suppliers to the aerospace sector perform it anyway.
How long does it take to add AS9100 to an existing ISO 9001 system? Organizations with mature ISO 9001 systems and no major gaps in configuration management or purchasing controls typically complete the transition in four to six months. Organizations building those processes from scratch should plan for nine to twelve months before the certification audit.
For a broader look at what ISO 9001 itself requires before layering on sector-specific additions, see our ISO 9001 overview. If you're weighing AS9100 against a different sector-specific standard, our IATF 16949 gap analysis guide walks through a comparable automotive case that follows the same "ISO 9001 plus sector additions" logic.
Jared Clark, JD, MBA, PMP, CMQ-OE, CQA, CPGP, RAC, is Principal Consultant at Certify Consulting, where he works with manufacturers and suppliers on ISO 9001, AS9100, and related quality management system certifications.
Last updated: 2026-09-01
Jared Clark
Principal Consultant, Certify Consulting
Jared Clark is the founder of Certify Consulting, helping organizations achieve and maintain compliance with international standards and regulatory requirements.