# Iatf 16949 Audit

> >- Conduct an IATF audit, check supplemental requirements, or prepare for a manufacturing process audit or IATF 16949:2016 third-party assessment. Covers customer-specific requirements (CSR), all 16 automotive supplemental clauses, and the three required audit types: QMS audit, manufacturing process audit, and product audit. Use for internal IATF audits or supplier quality audits at automotive organisations.

- Skill: `thedixitjain/iatf-16949-audit` (Agent Skill, multi-file: 2 files)
- Install (CLI): `npx skillmds add thedixitjain/iatf-16949-audit`
- Raw SKILL.md: https://api.skillmd.com/api/skills/thedixitjain/iatf-16949-audit/raw
- Safety review: pending
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: Security
- Author: thedixitjain (https://skillmd.com/u/thedixitjain)
- Updated: 2026-09-08
- Page: https://skillmd.com/skills/thedixitjain/iatf-16949-audit

---



# IATF 16949:2016 Internal Audit — Supplemental Requirements

## Goal

Audit the automotive-specific supplemental requirements of IATF 16949:2016, including CSR compliance and the three mandatory internal audit streams. Use in conjunction with [iso-9001-internal-audit](../iso-9001-internal-audit/) for a complete IATF audit.

---

## When to use

This skill covers the **IATF 16949 supplemental requirements** — the automotive additions to ISO 9001.

IATF 16949 requires three types of internal audit (§9.2.2.1). All three must be planned, executed, and recorded within the audit programme cycle:

1. **QMS audit** — covers the entire quality management system (ISO 9001 + IATF supplementals)
2. **Manufacturing process audit** — process-based, covers all manufacturing processes at least annually
3. **Product audit** — product-specific, verifies product conformance to specifications

All manufacturing processes must be audited at least annually, with increased frequency for high-risk or poor-performing areas.

---

## Required IATF Audit Checklist

☐ Verify all three audit streams are planned and executed within the programme cycle
☐ Confirm CSR register is current and that changes trigger QMS document updates
☐ Check contingency plans are documented, reviewed, and tested (not just written)
☐ Verify special characteristics are consistent across all documents (drawing, DFMEA, PFMEA, CP, WI)
☐ Confirm supplier monitoring and escalation are active with defined thresholds
☐ Check Control Plan ↔ PFMEA linkage is current
☐ Verify traceability and suspect material isolation capability (24-hour test)
☐ Review temporary deviations for approval, expiry, and active control
☐ Verify problem-solving methodology is applied with objective evidence of effectiveness
☐ Confirm management review includes all IATF supplemental inputs
☐ Do not accept verbal confirmation — verify by observing the process, interviewing personnel, and reviewing records

---

## Key IATF 16949 supplemental requirements — audit questions

### §4.3.2 — Customer-specific requirements (CSR)

This is the most commonly non-conforming IATF clause.

Questions:

- Is there a register of all applicable customer-specific requirements (CSRs)?
- For each OEM customer: have the latest CSRs been downloaded and reviewed?
- Are CSR requirements addressed in the QMS (procedures, control plans, work instructions)?
- Are personnel who deal with each customer aware of their specific requirements?
- CSR review must be revision-controlled and linked to implementation evidence in affected documents — is this traceable?
- *Evidence:* CSR register, evidence that each CSR has been reviewed and implemented, CSR revision dates vs. QMS document dates

**High-risk CSR areas:** PPAP requirements, problem-solving format requirements, special characteristics symbols, labelling specifications, sub-supplier approval requirements.

---

### §5.1.1.1 — Corporate responsibility

- Is there a documented corporate responsibility policy (ethics, anti-bribery)?
- Is there an escalation process for reporting ethical concerns?
- Are employees aware of how to report ethical concerns confidentially?
- *Evidence:* code of conduct, ethics policy, reporting mechanism (hotline or similar)

---

### §5.3.1 — Organisational roles, responsibilities, and authorities — supplemental

- Is there a person responsible for customer satisfaction?
- Are responsibilities for special characteristics defined?
- Is there a process for communicating customer requirements to all relevant functions?
- *Evidence:* roles matrix with customer satisfaction ownership identified

---

### §6.1.2.1 — Risk analysis (supplemental)

- Does the risk analysis consider lessons learned from similar products?
- Is warranty data, field returns, and customer complaints included as inputs?
- *Evidence:* risk analysis records with warranty/field data inputs

---

### §6.1.2.3 — Contingency plans

IATF requires documented contingency plans for:

- Key equipment failure
- Key supplier failure or disruption
- Labour shortages
- IT/infrastructure failure
- Natural disasters or site incidents affecting delivery

Questions:

- Are contingency plans documented for each of these scenarios?
- Are plans reviewed periodically (at least annually)?
- Are they tested or rehearsed?
- Does top management know who activates contingency plans?
- Do contingency plans include customer communication protocols and recovery priorities?
- *Evidence:* contingency plan document, last review date, test/simulation records

---

### §7.2.3 — Internal auditor competency

- Are internal auditors formally qualified or trained?
- Do auditors have process knowledge for the areas they audit?
- Is there evidence of auditor training (certification, OJT, qualification test)?
- Are auditors independent of the area they audit?
- Is auditor effectiveness periodically reviewed based on audit quality and finding accuracy?
- *Evidence:* auditor qualification records, audit schedule showing independence

---

### §7.2.4 — Second and third-party auditor competency

- For supplier audits: are supplier auditors trained and qualified?
- For customer audits: are there designated contacts?

---

### §8.3.2.1 — Design and development — supplemental

- Are special characteristics (SC) identified and documented in DFMEA and drawings?
- Are customer-specific SC symbols used correctly?
- Are SC characteristics flowed down to PFMEA, Control Plan, and work instructions?
- *Evidence:* drawing with SC marked, DFMEA with SC, PFMEA with SC, Control Plan with SC, WI with SC

---

### §8.3.3.3 — Special characteristics

- Is there a process to identify, document, and control all special characteristics?
- Do all documents (drawing, DFMEA, PFMEA, CP, WI) use consistent SC symbols?
- Are operators aware of which characteristics are special?
- Any inconsistency in SC identification across documents must be treated as a significant audit finding due to control failure — is SC consistency actively verified?
- *Evidence:* SC registry or matrix cross-referencing all documents

---

### §8.4.1.2 — Customer-directed sources (directed buy)

- When the customer directs a specific supplier (directed buy), is this documented?
- Is the directed supplier included in the approved supplier list?
- Is quality monitoring applied even if the customer selected the supplier?

---

### §8.4.2.3 — Supplier monitoring

IATF requires active supplier monitoring with specific actions for non-performing suppliers.

Questions:

- Is there a supplier performance monitoring system (PPM, on-time delivery, quality issues)?
- Is supplier performance reviewed at a defined frequency (minimum quarterly)?
- Are supplier development or escalation actions triggered based on defined performance thresholds?
- For poor performers: is there a documented escalation and improvement process?
- Are suppliers assessed for delivery of conforming product (not just quality level)?
- *Evidence:* supplier scorecards, last 4 quarters of performance data, improvement plans for poor performers

---

### §8.5.1.1 — Control plan

Questions:

- Is there a control plan for each production part?
- Does it cover: pre-launch, production, and reaction plan?
- Are all special characteristics in the control plan with specific control methods?
- Is the control plan linked to the PFMEA (detection controls match)?
- Are reaction plans in the Control Plan understood and applied at the point of use — not only documented?
- Was it updated after the last process or product change?
- *Evidence:* control plan, PFMEA (verify linkage), latest revision date vs. last process change date

---

### §8.5.2.1 — Identification and traceability — supplemental

- Is full traceability from raw material to finished product maintained?
- Can suspect material be isolated within 24 hours?
- Is there a procedure for handling suspect material?
- Are lot sizes defined to limit the scope of recalls?
- *Evidence:* traceability records, suspect material handling procedure, sample traceability exercise (ask for a part and trace it backwards)

---

### §8.5.6.1.1 — Control of changes — supplemental (temporary change)

IATF requires that temporary process changes (deviations) be strictly controlled.

Questions:

- Is there a process for managing temporary deviations (substituting a process step or material)?
- Are deviations approved in writing with defined expiry dates?
- Is there a register of all open temporary deviations?
- Are expired deviations actively closed or extended — not left open silently?
- Is the customer notified when required by their CSR?
- *Evidence:* deviation register, sample open deviation with expiry date and approval

---

### §8.7.1.1 — Customer notification

- Is there a procedure for notifying the customer when suspect material may have been shipped?
- Does it define when notification is required (not just when the customer asks)?
- Does the procedure specify notification timelines (e.g., 24 hours for safety-related escapes per CSR)?
- Has the procedure been triggered recently? Were notifications timely?
- *Evidence:* notification procedure, last notification records (if any)

---

### §9.2.2.1 — Internal audit programme — supplemental

IATF requires **three audit streams** — most organisations fail by only conducting clause-based audits:

1. **QMS audit** — covers clauses; must cover entire QMS within the audit programme cycle
2. **Manufacturing process audit** — process-based, all manufacturing processes annually minimum; uses VDA 6.3 or equivalent scoring
3. **Product audit** — product/shipment audits at defined frequency

Questions:

- Are all three audit types in the programme?
- Is the manufacturing process audit process-based (turtle diagram approach)?
- Are all processes and products covered within the audit cycle?
- Is the audit programme risk-based (higher risk = higher audit frequency)?
- Low process audit scores must trigger corrective action, management review, and re-audit planning — is this in place?
- *Evidence:* annual audit programme, audit reports for all three types, process audit records (not just clause audits)

---

### §9.3.2.1 — Management review — supplemental inputs

IATF management review must include (in addition to ISO 9001 §9.3.2):

- Cost of poor quality (COPQ)
- Warranty performance (if applicable)
- Customer satisfaction and field performance review
- Status of CSR compliance
- Manufacturing feasibility assessments

Questions:

- Are these topics covered in the management review agenda?
- Is there data for each topic?
- Are decisions from these IATF-specific inputs translated into actions with owners and due dates?
- *Evidence:* management review minutes with IATF-required topics explicitly addressed

---

### §10.2.3 — Problem solving

- Is there a documented problem-solving methodology (8D or equivalent)?
- Is the methodology applied consistently across all quality escapes?
- Does the 8D identify root cause of occurrence AND root cause of escape?
- Is effectiveness verified before closure?
- *Evidence:* problem-solving procedure, sample 8D reports, verification of effectiveness records

---

### §10.2.4 — Error proofing

- Is there a documented approach to applying error-proofing (poka-yoke)?
- Are poka-yoke devices tested at defined intervals (IATF requires: minimum at every start of production)?
- Are test records maintained?
- Are failed or bypassed error-proofing checks treated as production stop / reaction plan triggers where applicable?
- Are poka-yoke failures treated as non-conformances requiring CAPA?
- *Evidence:* poka-yoke register, test frequency, test records, last test date vs. interval

---

### §10.3.1 — Continual improvement plan

- Is there a formal, documented continual improvement plan?
- Does it include manufacturing process effectiveness (not just quality KPIs)?
- Is it reviewed at management review?
- *Evidence:* CI plan document, last review, evidence of CI activities

---

## Product audit — §9.2.2.3

A product audit verifies that finished products meet all requirements before shipment. It is one of the three mandatory IATF audit streams.

Focus areas for product audit:

- Product conformity to drawing and specification (dimensional, functional, visual)
- Packaging and labelling compliance (OEM label format, part number, revision, quantity)
- Traceability and release status (is the product formally released and traceable to its records?)
- Audit frequency based on risk, customer issues, and product criticality

Evidence required: product audit reports, measurement records, packaging inspection records, release documentation.

---

## Manufacturing process audit — turtle diagram approach

A manufacturing process audit (required annually for each process) uses a turtle diagram to assess:

| Input | Question |
|-------|---------|
| **Who** (Man) | Qualification requirements, training, availability |
| **With what** (Machine) | Equipment capability, maintenance, calibration |
| **Using what method** | Work instructions, current, at point of use |
| **With what material** | Incoming material control, traceability |
| **With what measurement** | Gauges, MSA, SPC |
| **Environment** | Cleanroom, temperature, ESD, contamination |
| **Process output** | First-pass yield, defect rate, scrap |
| **Customer feedback** | PPM, complaints, warranty |

For each element: is it adequate? Is it controlled? Is there objective evidence?

Each turtle element should be verified by direct observation, interview, and record review — not by document review alone.

A process audit must result in a process audit score (VDA 6.3 uses a percentage score by process element P1-P7). Low scores must trigger corrective action, management review input, and re-audit planning.

---

## Common IATF audit failures

1. **CSR register not updated** when customer publishes new CSR revision
2. **No manufacturing process audits** — only clause-based audits in the programme
3. **Contingency plans exist but were never tested**
4. **Temporary deviations without expiry dates** or expired deviations not closed
5. **SC not consistently marked** across drawing, PFMEA, control plan, and work instruction
6. **Error-proofing not tested** at every start of production (frequency not defined or records not kept)
7. **Problem-solving procedure exists** but CARs in practice skip root cause or VOE

## Output Format

At the start of each use, ask the user:

> "How would you like to receive the output?
> **A** — Structured Markdown (formatted tables and sections, ready to copy)
> **B** — Plain tables (simplified structure for Excel or Word)
> **C** — Narrative report (flowing text for a formal document or email)
>
> Default: A."

Adapt all output sections to the chosen format. If the platform or session context already defines a format preference, skip this question.

## Reference files

- [IATF supplemental requirements checklist](references/supplemental-requirements.md)

## Changelog

| Version | Date | Author | Change |
|---------|------|--------|--------|
| 1.0 | 2026-06-01 | @RBraga01 | Initial release |
| 1.1 | 2026-06-03 | @migmcc | Added supplemental requirements reference and CSR audit coverage |

---

**Source:** [`hashgraph-online/awesome-codex-plugins`](https://github.com/hashgraph-online/awesome-codex-plugins) → `plugins/RBraga01/Quality-Engineering-Skills/skills/audit/iatf-16949-audit/SKILL.md`

