IATF 16949:2016 Internal Audit — Supplemental Requirements
Goal
Audit the automotive-specific supplemental requirements of IATF 16949:2016, including CSR compliance and the three mandatory internal audit streams. Use in conjunction with iso-9001-internal-audit for a complete IATF audit.
When to use
This skill covers the IATF 16949 supplemental requirements — the automotive additions to ISO 9001.
IATF 16949 requires three types of internal audit (§9.2.2.1). All three must be planned, executed, and recorded within the audit programme cycle:
- QMS audit — covers the entire quality management system (ISO 9001 + IATF supplementals)
- Manufacturing process audit — process-based, covers all manufacturing processes at least annually
- Product audit — product-specific, verifies product conformance to specifications
All manufacturing processes must be audited at least annually, with increased frequency for high-risk or poor-performing areas.
Required IATF Audit Checklist
☐ Verify all three audit streams are planned and executed within the programme cycle
☐ Confirm CSR register is current and that changes trigger QMS document updates
☐ Check contingency plans are documented, reviewed, and tested (not just written)
☐ Verify special characteristics are consistent across all documents (drawing, DFMEA, PFMEA, CP, WI)
☐ Confirm supplier monitoring and escalation are active with defined thresholds
☐ Check Control Plan ↔ PFMEA linkage is current
☐ Verify traceability and suspect material isolation capability (24-hour test)
☐ Review temporary deviations for approval, expiry, and active control
☐ Verify problem-solving methodology is applied with objective evidence of effectiveness
☐ Confirm management review includes all IATF supplemental inputs
☐ Do not accept verbal confirmation — verify by observing the process, interviewing personnel, and reviewing records
Key IATF 16949 supplemental requirements — audit questions
§4.3.2 — Customer-specific requirements (CSR)
This is the most commonly non-conforming IATF clause.
Questions:
- Is there a register of all applicable customer-specific requirements (CSRs)?
- For each OEM customer: have the latest CSRs been downloaded and reviewed?
- Are CSR requirements addressed in the QMS (procedures, control plans, work instructions)?
- Are personnel who deal with each customer aware of their specific requirements?
- CSR review must be revision-controlled and linked to implementation evidence in affected documents — is this traceable?
- Evidence: CSR register, evidence that each CSR has been reviewed and implemented, CSR revision dates vs. QMS document dates
High-risk CSR areas: PPAP requirements, problem-solving format requirements, special characteristics symbols, labelling specifications, sub-supplier approval requirements.
§5.1.1.1 — Corporate responsibility
- Is there a documented corporate responsibility policy (ethics, anti-bribery)?
- Is there an escalation process for reporting ethical concerns?
- Are employees aware of how to report ethical concerns confidentially?
- Evidence: code of conduct, ethics policy, reporting mechanism (hotline or similar)
§5.3.1 — Organisational roles, responsibilities, and authorities — supplemental
- Is there a person responsible for customer satisfaction?
- Are responsibilities for special characteristics defined?
- Is there a process for communicating customer requirements to all relevant functions?
- Evidence: roles matrix with customer satisfaction ownership identified
§6.1.2.1 — Risk analysis (supplemental)
- Does the risk analysis consider lessons learned from similar products?
- Is warranty data, field returns, and customer complaints included as inputs?
- Evidence: risk analysis records with warranty/field data inputs
§6.1.2.3 — Contingency plans
IATF requires documented contingency plans for:
- Key equipment failure
- Key supplier failure or disruption
- Labour shortages
- IT/infrastructure failure
- Natural disasters or site incidents affecting delivery
Questions:
- Are contingency plans documented for each of these scenarios?
- Are plans reviewed periodically (at least annually)?
- Are they tested or rehearsed?
- Does top management know who activates contingency plans?
- Do contingency plans include customer communication protocols and recovery priorities?
- Evidence: contingency plan document, last review date, test/simulation records
§7.2.3 — Internal auditor competency
- Are internal auditors formally qualified or trained?
- Do auditors have process knowledge for the areas they audit?
- Is there evidence of auditor training (certification, OJT, qualification test)?
- Are auditors independent of the area they audit?
- Is auditor effectiveness periodically reviewed based on audit quality and finding accuracy?
- Evidence: auditor qualification records, audit schedule showing independence
§7.2.4 — Second and third-party auditor competency
- For supplier audits: are supplier auditors trained and qualified?
- For customer audits: are there designated contacts?
§8.3.2.1 — Design and development — supplemental
- Are special characteristics (SC) identified and documented in DFMEA and drawings?
- Are customer-specific SC symbols used correctly?
- Are SC characteristics flowed down to PFMEA, Control Plan, and work instructions?
- Evidence: drawing with SC marked, DFMEA with SC, PFMEA with SC, Control Plan with SC, WI with SC
§8.3.3.3 — Special characteristics
- Is there a process to identify, document, and control all special characteristics?
- Do all documents (drawing, DFMEA, PFMEA, CP, WI) use consistent SC symbols?
- Are operators aware of which characteristics are special?
- Any inconsistency in SC identification across documents must be treated as a significant audit finding due to control failure — is SC consistency actively verified?
- Evidence: SC registry or matrix cross-referencing all documents
§8.4.1.2 — Customer-directed sources (directed buy)
- When the customer directs a specific supplier (directed buy), is this documented?
- Is the directed supplier included in the approved supplier list?
- Is quality monitoring applied even if the customer selected the supplier?
§8.4.2.3 — Supplier monitoring
IATF requires active supplier monitoring with specific actions for non-performing suppliers.
Questions:
- Is there a supplier performance monitoring system (PPM, on-time delivery, quality issues)?
- Is supplier performance reviewed at a defined frequency (minimum quarterly)?
- Are supplier development or escalation actions triggered based on defined performance thresholds?
- For poor performers: is there a documented escalation and improvement process?
- Are suppliers assessed for delivery of conforming product (not just quality level)?
- Evidence: supplier scorecards, last 4 quarters of performance data, improvement plans for poor performers
§8.5.1.1 — Control plan
Questions:
- Is there a control plan for each production part?
- Does it cover: pre-launch, production, and reaction plan?
- Are all special characteristics in the control plan with specific control methods?
- Is the control plan linked to the PFMEA (detection controls match)?
- Are reaction plans in the Control Plan understood and applied at the point of use — not only documented?
- Was it updated after the last process or product change?
- Evidence: control plan, PFMEA (verify linkage), latest revision date vs. last process change date
§8.5.2.1 — Identification and traceability — supplemental
- Is full traceability from raw material to finished product maintained?
- Can suspect material be isolated within 24 hours?
- Is there a procedure for handling suspect material?
- Are lot sizes defined to limit the scope of recalls?
- Evidence: traceability records, suspect material handling procedure, sample traceability exercise (ask for a part and trace it backwards)
§8.5.6.1.1 — Control of changes — supplemental (temporary change)
IATF requires that temporary process changes (deviations) be strictly controlled.
Questions:
- Is there a process for managing temporary deviations (substituting a process step or material)?
- Are deviations approved in writing with defined expiry dates?
- Is there a register of all open temporary deviations?
- Are expired deviations actively closed or extended — not left open silently?
- Is the customer notified when required by their CSR?
- Evidence: deviation register, sample open deviation with expiry date and approval
§8.7.1.1 — Customer notification
- Is there a procedure for notifying the customer when suspect material may have been shipped?
- Does it define when notification is required (not just when the customer asks)?
- Does the procedure specify notification timelines (e.g., 24 hours for safety-related escapes per CSR)?
- Has the procedure been triggered recently? Were notifications timely?
- Evidence: notification procedure, last notification records (if any)
§9.2.2.1 — Internal audit programme — supplemental
IATF requires three audit streams — most organisations fail by only conducting clause-based audits:
- QMS audit — covers clauses; must cover entire QMS within the audit programme cycle
- Manufacturing process audit — process-based, all manufacturing processes annually minimum; uses VDA 6.3 or equivalent scoring
- Product audit — product/shipment audits at defined frequency
Questions:
- Are all three audit types in the programme?
- Is the manufacturing process audit process-based (turtle diagram approach)?
- Are all processes and products covered within the audit cycle?
- Is the audit programme risk-based (higher risk = higher audit frequency)?
- Low process audit scores must trigger corrective action, management review, and re-audit planning — is this in place?
- Evidence: annual audit programme, audit reports for all three types, process audit records (not just clause audits)
§9.3.2.1 — Management review — supplemental inputs
IATF management review must include (in addition to ISO 9001 §9.3.2):
- Cost of poor quality (COPQ)
- Warranty performance (if applicable)
- Customer satisfaction and field performance review
- Status of CSR compliance
- Manufacturing feasibility assessments
Questions:
- Are these topics covered in the management review agenda?
- Is there data for each topic?
- Are decisions from these IATF-specific inputs translated into actions with owners and due dates?
- Evidence: management review minutes with IATF-required topics explicitly addressed
§10.2.3 — Problem solving
- Is there a documented problem-solving methodology (8D or equivalent)?
- Is the methodology applied consistently across all quality escapes?
- Does the 8D identify root cause of occurrence AND root cause of escape?
- Is effectiveness verified before closure?
- Evidence: problem-solving procedure, sample 8D reports, verification of effectiveness records
§10.2.4 — Error proofing
- Is there a documented approach to applying error-proofing (poka-yoke)?
- Are poka-yoke devices tested at defined intervals (IATF requires: minimum at every start of production)?
- Are test records maintained?
- Are failed or bypassed error-proofing checks treated as production stop / reaction plan triggers where applicable?
- Are poka-yoke failures treated as non-conformances requiring CAPA?
- Evidence: poka-yoke register, test frequency, test records, last test date vs. interval
§10.3.1 — Continual improvement plan
- Is there a formal, documented continual improvement plan?
- Does it include manufacturing process effectiveness (not just quality KPIs)?
- Is it reviewed at management review?
- Evidence: CI plan document, last review, evidence of CI activities
Product audit — §9.2.2.3
A product audit verifies that finished products meet all requirements before shipment. It is one of the three mandatory IATF audit streams.
Focus areas for product audit:
- Product conformity to drawing and specification (dimensional, functional, visual)
- Packaging and labelling compliance (OEM label format, part number, revision, quantity)
- Traceability and release status (is the product formally released and traceable to its records?)
- Audit frequency based on risk, customer issues, and product criticality
Evidence required: product audit reports, measurement records, packaging inspection records, release documentation.
Manufacturing process audit — turtle diagram approach
A manufacturing process audit (required annually for each process) uses a turtle diagram to assess:
| Input |
Question |
| Who (Man) |
Qualification requirements, training, availability |
| With what (Machine) |
Equipment capability, maintenance, calibration |
| Using what method |
Work instructions, current, at point of use |
| With what material |
Incoming material control, traceability |
| With what measurement |
Gauges, MSA, SPC |
| Environment |
Cleanroom, temperature, ESD, contamination |
| Process output |
First-pass yield, defect rate, scrap |
| Customer feedback |
PPM, complaints, warranty |
For each element: is it adequate? Is it controlled? Is there objective evidence?
Each turtle element should be verified by direct observation, interview, and record review — not by document review alone.
A process audit must result in a process audit score (VDA 6.3 uses a percentage score by process element P1-P7). Low scores must trigger corrective action, management review input, and re-audit planning.
Common IATF audit failures
- CSR register not updated when customer publishes new CSR revision
- No manufacturing process audits — only clause-based audits in the programme
- Contingency plans exist but were never tested
- Temporary deviations without expiry dates or expired deviations not closed
- SC not consistently marked across drawing, PFMEA, control plan, and work instruction
- Error-proofing not tested at every start of production (frequency not defined or records not kept)
- Problem-solving procedure exists but CARs in practice skip root cause or VOE
Output Format
At the start of each use, ask the user:
"How would you like to receive the output?
A — Structured Markdown (formatted tables and sections, ready to copy)
B — Plain tables (simplified structure for Excel or Word)
C — Narrative report (flowing text for a formal document or email)
Default: A."
Adapt all output sections to the chosen format. If the platform or session context already defines a format preference, skip this question.
Reference files
- IATF supplemental requirements checklist
Changelog
| Version |
Date |
Author |
Change |
| 1.0 |
2026-06-01 |
@RBraga01 |
Initial release |
| 1.1 |
2026-06-03 |
@migmcc |
Added supplemental requirements reference and CSR audit coverage |
Source: hashgraph-online/awesome-codex-plugins → plugins/RBraga01/Quality-Engineering-Skills/skills/audit/iatf-16949-audit/SKILL.md
1---2name: iatf-16949-audit3description: >- Conduct an IATF audit, check supplemental requirements, or prepare for a manufacturing process audit or IATF 16949:2016 third-party assessment. Covers customer-specific requirements (CSR), all 16 automotive supplemental clauses, and the three required audit types: QMS audit, manufacturing process audit, and product audit. Use for internal IATF audits or supplier quality audits at automotive organisations.4---567# IATF 16949:2016 Internal Audit — Supplemental Requirements89## Goal1011Audit the automotive-specific supplemental requirements of IATF 16949:2016, including CSR compliance and the three mandatory internal audit streams. Use in conjunction with [iso-9001-internal-audit](../iso-9001-internal-audit/) for a complete IATF audit.1213---1415## When to use1617This skill covers the **IATF 16949 supplemental requirements** — the automotive additions to ISO 9001.1819IATF 16949 requires three types of internal audit (§9.2.2.1). All three must be planned, executed, and recorded within the audit programme cycle:20211. **QMS audit** — covers the entire quality management system (ISO 9001 + IATF supplementals)222. **Manufacturing process audit** — process-based, covers all manufacturing processes at least annually233. **Product audit** — product-specific, verifies product conformance to specifications2425All manufacturing processes must be audited at least annually, with increased frequency for high-risk or poor-performing areas.2627---2829## Required IATF Audit Checklist3031☐ Verify all three audit streams are planned and executed within the programme cycle32☐ Confirm CSR register is current and that changes trigger QMS document updates33☐ Check contingency plans are documented, reviewed, and tested (not just written)34☐ Verify special characteristics are consistent across all documents (drawing, DFMEA, PFMEA, CP, WI)35☐ Confirm supplier monitoring and escalation are active with defined thresholds36☐ Check Control Plan ↔ PFMEA linkage is current37☐ Verify traceability and suspect material isolation capability (24-hour test)38☐ Review temporary deviations for approval, expiry, and active control39☐ Verify problem-solving methodology is applied with objective evidence of effectiveness40☐ Confirm management review includes all IATF supplemental inputs41☐ Do not accept verbal confirmation — verify by observing the process, interviewing personnel, and reviewing records4243---4445## Key IATF 16949 supplemental requirements — audit questions4647### §4.3.2 — Customer-specific requirements (CSR)4849This is the most commonly non-conforming IATF clause.5051Questions:5253- Is there a register of all applicable customer-specific requirements (CSRs)?54- For each OEM customer: have the latest CSRs been downloaded and reviewed?55- Are CSR requirements addressed in the QMS (procedures, control plans, work instructions)?56- Are personnel who deal with each customer aware of their specific requirements?57- CSR review must be revision-controlled and linked to implementation evidence in affected documents — is this traceable?58- *Evidence:* CSR register, evidence that each CSR has been reviewed and implemented, CSR revision dates vs. QMS document dates5960**High-risk CSR areas:** PPAP requirements, problem-solving format requirements, special characteristics symbols, labelling specifications, sub-supplier approval requirements.6162---6364### §5.1.1.1 — Corporate responsibility6566- Is there a documented corporate responsibility policy (ethics, anti-bribery)?67- Is there an escalation process for reporting ethical concerns?68- Are employees aware of how to report ethical concerns confidentially?69- *Evidence:* code of conduct, ethics policy, reporting mechanism (hotline or similar)7071---7273### §5.3.1 — Organisational roles, responsibilities, and authorities — supplemental7475- Is there a person responsible for customer satisfaction?76- Are responsibilities for special characteristics defined?77- Is there a process for communicating customer requirements to all relevant functions?78- *Evidence:* roles matrix with customer satisfaction ownership identified7980---8182### §6.1.2.1 — Risk analysis (supplemental)8384- Does the risk analysis consider lessons learned from similar products?85- Is warranty data, field returns, and customer complaints included as inputs?86- *Evidence:* risk analysis records with warranty/field data inputs8788---8990### §6.1.2.3 — Contingency plans9192IATF requires documented contingency plans for:9394- Key equipment failure95- Key supplier failure or disruption96- Labour shortages97- IT/infrastructure failure98- Natural disasters or site incidents affecting delivery99100Questions:101102- Are contingency plans documented for each of these scenarios?103- Are plans reviewed periodically (at least annually)?104- Are they tested or rehearsed?105- Does top management know who activates contingency plans?106- Do contingency plans include customer communication protocols and recovery priorities?107- *Evidence:* contingency plan document, last review date, test/simulation records108109---110111### §7.2.3 — Internal auditor competency112113- Are internal auditors formally qualified or trained?114- Do auditors have process knowledge for the areas they audit?115- Is there evidence of auditor training (certification, OJT, qualification test)?116- Are auditors independent of the area they audit?117- Is auditor effectiveness periodically reviewed based on audit quality and finding accuracy?118- *Evidence:* auditor qualification records, audit schedule showing independence119120---121122### §7.2.4 — Second and third-party auditor competency123124- For supplier audits: are supplier auditors trained and qualified?125- For customer audits: are there designated contacts?126127---128129### §8.3.2.1 — Design and development — supplemental130131- Are special characteristics (SC) identified and documented in DFMEA and drawings?132- Are customer-specific SC symbols used correctly?133- Are SC characteristics flowed down to PFMEA, Control Plan, and work instructions?134- *Evidence:* drawing with SC marked, DFMEA with SC, PFMEA with SC, Control Plan with SC, WI with SC135136---137138### §8.3.3.3 — Special characteristics139140- Is there a process to identify, document, and control all special characteristics?141- Do all documents (drawing, DFMEA, PFMEA, CP, WI) use consistent SC symbols?142- Are operators aware of which characteristics are special?143- Any inconsistency in SC identification across documents must be treated as a significant audit finding due to control failure — is SC consistency actively verified?144- *Evidence:* SC registry or matrix cross-referencing all documents145146---147148### §8.4.1.2 — Customer-directed sources (directed buy)149150- When the customer directs a specific supplier (directed buy), is this documented?151- Is the directed supplier included in the approved supplier list?152- Is quality monitoring applied even if the customer selected the supplier?153154---155156### §8.4.2.3 — Supplier monitoring157158IATF requires active supplier monitoring with specific actions for non-performing suppliers.159160Questions:161162- Is there a supplier performance monitoring system (PPM, on-time delivery, quality issues)?163- Is supplier performance reviewed at a defined frequency (minimum quarterly)?164- Are supplier development or escalation actions triggered based on defined performance thresholds?165- For poor performers: is there a documented escalation and improvement process?166- Are suppliers assessed for delivery of conforming product (not just quality level)?167- *Evidence:* supplier scorecards, last 4 quarters of performance data, improvement plans for poor performers168169---170171### §8.5.1.1 — Control plan172173Questions:174175- Is there a control plan for each production part?176- Does it cover: pre-launch, production, and reaction plan?177- Are all special characteristics in the control plan with specific control methods?178- Is the control plan linked to the PFMEA (detection controls match)?179- Are reaction plans in the Control Plan understood and applied at the point of use — not only documented?180- Was it updated after the last process or product change?181- *Evidence:* control plan, PFMEA (verify linkage), latest revision date vs. last process change date182183---184185### §8.5.2.1 — Identification and traceability — supplemental186187- Is full traceability from raw material to finished product maintained?188- Can suspect material be isolated within 24 hours?189- Is there a procedure for handling suspect material?190- Are lot sizes defined to limit the scope of recalls?191- *Evidence:* traceability records, suspect material handling procedure, sample traceability exercise (ask for a part and trace it backwards)192193---194195### §8.5.6.1.1 — Control of changes — supplemental (temporary change)196197IATF requires that temporary process changes (deviations) be strictly controlled.198199Questions:200201- Is there a process for managing temporary deviations (substituting a process step or material)?202- Are deviations approved in writing with defined expiry dates?203- Is there a register of all open temporary deviations?204- Are expired deviations actively closed or extended — not left open silently?205- Is the customer notified when required by their CSR?206- *Evidence:* deviation register, sample open deviation with expiry date and approval207208---209210### §8.7.1.1 — Customer notification211212- Is there a procedure for notifying the customer when suspect material may have been shipped?213- Does it define when notification is required (not just when the customer asks)?214- Does the procedure specify notification timelines (e.g., 24 hours for safety-related escapes per CSR)?215- Has the procedure been triggered recently? Were notifications timely?216- *Evidence:* notification procedure, last notification records (if any)217218---219220### §9.2.2.1 — Internal audit programme — supplemental221222IATF requires **three audit streams** — most organisations fail by only conducting clause-based audits:2232241. **QMS audit** — covers clauses; must cover entire QMS within the audit programme cycle2252. **Manufacturing process audit** — process-based, all manufacturing processes annually minimum; uses VDA 6.3 or equivalent scoring2263. **Product audit** — product/shipment audits at defined frequency227228Questions:229230- Are all three audit types in the programme?231- Is the manufacturing process audit process-based (turtle diagram approach)?232- Are all processes and products covered within the audit cycle?233- Is the audit programme risk-based (higher risk = higher audit frequency)?234- Low process audit scores must trigger corrective action, management review, and re-audit planning — is this in place?235- *Evidence:* annual audit programme, audit reports for all three types, process audit records (not just clause audits)236237---238239### §9.3.2.1 — Management review — supplemental inputs240241IATF management review must include (in addition to ISO 9001 §9.3.2):242243- Cost of poor quality (COPQ)244- Warranty performance (if applicable)245- Customer satisfaction and field performance review246- Status of CSR compliance247- Manufacturing feasibility assessments248249Questions:250251- Are these topics covered in the management review agenda?252- Is there data for each topic?253- Are decisions from these IATF-specific inputs translated into actions with owners and due dates?254- *Evidence:* management review minutes with IATF-required topics explicitly addressed255256---257258### §10.2.3 — Problem solving259260- Is there a documented problem-solving methodology (8D or equivalent)?261- Is the methodology applied consistently across all quality escapes?262- Does the 8D identify root cause of occurrence AND root cause of escape?263- Is effectiveness verified before closure?264- *Evidence:* problem-solving procedure, sample 8D reports, verification of effectiveness records265266---267268### §10.2.4 — Error proofing269270- Is there a documented approach to applying error-proofing (poka-yoke)?271- Are poka-yoke devices tested at defined intervals (IATF requires: minimum at every start of production)?272- Are test records maintained?273- Are failed or bypassed error-proofing checks treated as production stop / reaction plan triggers where applicable?274- Are poka-yoke failures treated as non-conformances requiring CAPA?275- *Evidence:* poka-yoke register, test frequency, test records, last test date vs. interval276277---278279### §10.3.1 — Continual improvement plan280281- Is there a formal, documented continual improvement plan?282- Does it include manufacturing process effectiveness (not just quality KPIs)?283- Is it reviewed at management review?284- *Evidence:* CI plan document, last review, evidence of CI activities285286---287288## Product audit — §9.2.2.3289290A product audit verifies that finished products meet all requirements before shipment. It is one of the three mandatory IATF audit streams.291292Focus areas for product audit:293294- Product conformity to drawing and specification (dimensional, functional, visual)295- Packaging and labelling compliance (OEM label format, part number, revision, quantity)296- Traceability and release status (is the product formally released and traceable to its records?)297- Audit frequency based on risk, customer issues, and product criticality298299Evidence required: product audit reports, measurement records, packaging inspection records, release documentation.300301---302303## Manufacturing process audit — turtle diagram approach304305A manufacturing process audit (required annually for each process) uses a turtle diagram to assess:306307| Input | Question |308|-------|---------|309| **Who** (Man) | Qualification requirements, training, availability |310| **With what** (Machine) | Equipment capability, maintenance, calibration |311| **Using what method** | Work instructions, current, at point of use |312| **With what material** | Incoming material control, traceability |313| **With what measurement** | Gauges, MSA, SPC |314| **Environment** | Cleanroom, temperature, ESD, contamination |315| **Process output** | First-pass yield, defect rate, scrap |316| **Customer feedback** | PPM, complaints, warranty |317318For each element: is it adequate? Is it controlled? Is there objective evidence?319320Each turtle element should be verified by direct observation, interview, and record review — not by document review alone.321322A process audit must result in a process audit score (VDA 6.3 uses a percentage score by process element P1-P7). Low scores must trigger corrective action, management review input, and re-audit planning.323324---325326## Common IATF audit failures3273281. **CSR register not updated** when customer publishes new CSR revision3292. **No manufacturing process audits** — only clause-based audits in the programme3303. **Contingency plans exist but were never tested**3314. **Temporary deviations without expiry dates** or expired deviations not closed3325. **SC not consistently marked** across drawing, PFMEA, control plan, and work instruction3336. **Error-proofing not tested** at every start of production (frequency not defined or records not kept)3347. **Problem-solving procedure exists** but CARs in practice skip root cause or VOE335336## Output Format337338At the start of each use, ask the user:339340> "How would you like to receive the output?341> **A** — Structured Markdown (formatted tables and sections, ready to copy)342> **B** — Plain tables (simplified structure for Excel or Word)343> **C** — Narrative report (flowing text for a formal document or email)344>345> Default: A."346347Adapt all output sections to the chosen format. If the platform or session context already defines a format preference, skip this question.348349## Reference files350351- [IATF supplemental requirements checklist](references/supplemental-requirements.md)352353## Changelog354355| Version | Date | Author | Change |356|---------|------|--------|--------|357| 1.0 | 2026-06-01 | @RBraga01 | Initial release |358| 1.1 | 2026-06-03 | @migmcc | Added supplemental requirements reference and CSR audit coverage |359360---361362**Source:** [`hashgraph-online/awesome-codex-plugins`](https://github.com/hashgraph-online/awesome-codex-plugins) → `plugins/RBraga01/Quality-Engineering-Skills/skills/audit/iatf-16949-audit/SKILL.md`