Part of our work on aerospace and defense
Aerospace and Defense
Why AS9100 Documentation Is the Most Automatable Process in Aerospace and the Last One Anyone Touches
Big Sky Consulting Group · September 14, 2026 · 7 min read

The shared drive that passed the audit
You are an AS9100 certified shop. You may already pay for a quality management system. And your controlled documents still live in a folder tree on a shared drive, with revision letters in the filenames, an approval matrix in a spreadsheet, and a quality manager who knows which copy is real.
Ask a vendor why, and you will hear that you have not found the right software yet. Page one of any search on AS9100 documentation is QMS vendors: QT9, Arena, Intellect, Interfacing, Visure, Deltek. Every one of them treats the question as a product choice. None of them asks why a shop that already owns a QMS keeps running document control by hand.
We think the answer is not tooling. It is ownership. And until that is addressed, a new system tends to become a second place where documents live, not the only one.
Why this is the obvious candidate
Start with the part the vendors get right. AS9100 documentation is close to the ideal profile for automation.
Clause 7.5 of AS9100D requires you to identify, review, approve, distribute, protect and retain documented information. It layers aerospace controls on top of ISO 9001: configuration management, traceability, and tighter control of documents shared with customers and suppliers. Gaps in document control are among the most frequently cited findings in aerospace audits.
Look at the work that clause generates:
- Document control. Every controlled document needs an identifier, a revision, an owner and a current status.
- Revision and approval routing. A change goes to defined approvers in a defined order, and superseded versions are archived, not deleted.
- Internal audit scheduling. Audits recur on a calendar tied to process risk and past findings.
- Supplier corrective action. A SCAR opens, gets a response, gets verified, and closes, with dates at every step.
Each of those is rule-driven. Each produces evidence as a side effect. Each has a clear right answer that does not depend on judgment at the moment of execution. That is exactly what automation handles well, and exactly what a person with a spreadsheet handles badly on a busy Thursday.
The scale of the category is not small, either. The IAQG's OASIS directory showed 21,457 AS9100 certifications worldwide as of May 2023, 9,044 of them in the United States. Thousands of those sites are small and mid-sized suppliers running some version of the shared drive described above.
So the question is not whether this can be automated. It is why it so rarely is.
The person who signs is the person who decides
In most certified shops, one person carries the audit. The quality manager stands in front of the registrar, answers the finding, and owns the corrective action. If a superseded drawing reaches the floor, it is their nonconformance. Informally, it is their reputation.
That person has built a system that works. It is not elegant. It relies on their memory, their naming conventions and their habit of checking the folder before an audit. But they understand every failure mode it has, because they created all of them.
Now someone proposes replacing it with a platform they did not configure. The approval workflow was set up by an implementation consultant. The permission model was set up by IT. The migration was done by a contractor who did not know that two folders held different revisions of the same work instruction.
From the quality manager's chair, this is not a productivity gain. It is a transfer of control over the one thing they personally answer for, to a system whose failure modes they cannot see. The rational response is to keep the shared drive running "just in case." Once that happens, you have two systems, and the question at audit becomes which one is authoritative.
That is the pattern we see. The software gets bought. The folder never gets retired. Six months later, the QMS holds the documents that were easy to migrate and the drive holds the ones that matter.
Governance wearing a software costume
Calling this a software problem hides the decisions that actually have to be made. None of them are technical:
- Who owns the configuration? Not who administers the tool. Who decides what an approval route is, and who has authority to change it.
- What counts as the controlled copy? If the answer is "whatever is in the system," someone has to be willing to say that out loud to a registrar.
- Who is accountable when the automation routes wrongly? A missed approval caused by a misconfigured rule is still a finding against the organization.
- When does the old system stop existing? Not "wind down." Stop.
A shop that answers those questions first can automate document control with almost any competent tool. A shop that skips them can buy the best tool on the market and still find a revision C drawing taped to a machine. The software does not fix that. It only moves where the drawing came from.
This is also why the vendor framing is unhelpful even when the product is good. A demo shows an approval route firing cleanly. It cannot show you whether your quality manager will trust that route enough to delete the folder.
This is the general shape of the problem. Which parts apply to your process depends on answers only your systems can give.
Put us on it, from $5,000Why the pressure is rising anyway
Leaving document control on a shared drive has always carried risk. That risk is getting harder to defend.
Clause 7.5.3 already expects electronic records to be protected against loss, unauthorized change and corruption. The next revision of the standard, being developed by the IAQG as IA9100, adds an explicit information security requirement for the QMS and strengthens those electronic record controls. A permissions model that amounts to "everyone on the quality team can edit the folder" is a harder story to tell under that language.
Defense suppliers feel a second pull. If you handle controlled unclassified information, the same drive that holds your work instructions may be in scope for NIST SP 800-171 and CMMC, which we covered in what DFARS compliance actually costs a 200-person subcontractor. Evidence of access control and change history is not optional there, and a shared drive produces very little of it on its own.
Neither change forces automation. Both make the manual version more expensive to defend each year, and that cost lands on the same person who is refusing to hand over control.
What automating it well actually looks like
We will stay at the level of the pattern here, because the specifics depend on your certificate scope, your customers and your people.
The shops that get this right treat it as a change in who holds authority, with software as the mechanism. The quality manager is not a stakeholder consulted during implementation. They are the owner of the configuration, with the time to learn it and the authority to refuse go-live.
They also sequence by risk, not by volume. The documents that reach the shop floor and the documents a customer audits get migrated and verified first. Supplier corrective actions and internal audit schedules, which are mostly dates and status, are often the easiest early win because nobody's drawing is at stake.
And they set a retirement date for the old system before they start. A migration without an end date is just a second filing cabinet with a subscription fee. (We would call it a cabinet reshuffle, but the revision history would never let us live it down.)
This is the same sequencing question that shows up elsewhere in aerospace operations. In whether an MRO shop should automate intake before fixing its parts master, the real constraint was usually narrower than the vendors claimed. Here, the constraint is usually one person's confidence, and it is narrower still.
When not to do it
Sometimes the honest answer is to wait.
If your quality manager is leaving within the year, automating document control now means configuring a system around someone who will not be there to own it. If your certificate scope is changing, you will configure it twice. If the documents themselves are not settled, with work instructions that contradict each other and procedures that describe how things worked three owners ago, automation will route a mess faster.
In those situations, the better investment is the governance work: settle ownership, clean the document set, decide what is controlled. That work is useful whether or not software follows. We make the broader version of this argument in when not to use AI in business, and it applies just as well to plain workflow automation.
Where writing stops
An article can tell you why AS9100 documentation stays manual. It cannot tell you whether, in your shop, the blocker is the quality manager's trust, an unsettled document set, a scope change, or a tool that was configured by the wrong people.
That takes sitting with your quality team, looking at what lives in the drive and what lives in the system, and finding out which one your auditor actually saw. If your certified shop is paying for a QMS and still running document control from a folder, talk to us about what is keeping it there and what it would take to retire it.
