Auto Parts Sourcing Guide
Quality & Certifications

Checklist: Verifying IATF 16949 Certification Claims

Published 9 min read

Auditor checking quality management records at supplier facility
Quick answer

This guide provides a practical checklist for verifying IATF 16949 certification claims. It covers certificate scope, audit frequency, and document checks to ensure a supplier's quality management standards align with your sourcing needs.

Key takeaways
  • Verify the certificate scope matches the specific parts and processes you are sourcing.
  • Check the audit date and expiry to confirm the certificate is current.
  • Review the certificate status for any restrictions or non-conformances.
  • Request supporting documents like process capability reports.
  • Confirm the certification body is recognized by the IATF.

Why IATF 16949 Verification Matters for Sourcing

Verifying IATF 16949 certification is a standard step in supplier qualification. OEMs and Tier 1s rely on this standard to ensure suppliers can manage quality, traceability, and customer-specific requirements. But a certificate on a wall does not guarantee current compliance. You need to confirm the scope, date, and status before releasing purchase orders.

This checklist helps you move from a verbal claim to a documented verification. It covers the certificate itself, the certification body, the audit scope, and supporting evidence. You can use it during supplier onboarding or for periodic re-audits.

Section 1: Certificate Identity and Scope

Start with the physical or digital certificate. Check the following items to confirm the document is genuine and matches the supplier’s actual operations.

  1. Certificate number and unique identifier.
  2. Supplier legal name and registered address.
  3. Certification body name and contact details.
  4. Issue date and expiry date.
  5. Scope of certification as written in the certificate.

The scope is the most common point of failure. A certificate may cover “automotive brake components” but your purchase order might be for “brake assembly lines” or “metal casting for brake calipers.” If the process is not explicitly or implicitly included in the scope, the certificate does not apply to that part.

Read the scope carefully. It often lists specific processes like “machining,” “stamping,” or “coating.” If you are buying a finished assembly that includes a sub-process, ensure the assembly process is covered. If it is not, the supplier may be relying on a sub-tier certificate.

Consider a supplier that manufactures stamped brackets. Their certificate might list “stamping” and “surface treatment.” If you order those brackets, the certificate applies. If you order the brackets after they have been welded into a sub-assembly at a second site, the welding process must also be covered. If the second site is a subcontractor, you need to verify that the subcontractor holds its own valid certification.

Red flags to watch for:

  • Scope lists “general manufacturing” without specific processes.
  • Address on the certificate differs from the supplier’s production site.
  • Certificate is a scan with low resolution or missing digital signature.
  • Scope excludes specific materials like “carbon fiber” or “aluminum alloy.”

Section 2: Certification Body and Accreditation

Not all certification bodies are equal. You need to confirm the body is accredited by a recognized IATF member.

  1. Check the certification body’s IATF member number.
  2. Verify the body is listed on the IATF official website.
  3. Confirm the body is accredited by an accredited body (like ANAB, UKAS, or equivalent).
  4. Check for any public complaints or disciplinary actions.

The IATF website lists all approved certification bodies. If the body is not listed, the certificate is not IATF 16949. It may be ISO 9001 only, which is a different standard.

A certification body may issue an ISO 9001 certificate and a supplier may market it as IATF compliant because the management systems overlap. This is a critical distinction. ISO 9001 is a general management system standard. IATF 16949 adds specific automotive requirements, such as risk-based thinking, advanced process capability, and containment processes. If the body is not IATF accredited, the supplier has not undergone the specific audits required for the automotive sector.

Check the accreditation body. ANAB, UKAS, and other national accreditation agencies verify that the certification body has the competence to audit against IATF 16949. If the body is new, ask for their audit history. A body with no completed audits has not demonstrated the ability to identify non-conformances in a real-world setting.

Red flags to watch for:

  • Certification body cannot provide its accreditation number.
  • The body is new and has no audit history.
  • The certificate logo does not match the IATF standard logo.
  • The body offers “IATF 16949” but the certificate says “ISO 9001”.

Section 3: Audit Frequency and Status

The IATF 16949 standard requires surveillance audits and a recertification audit. The frequency depends on the supplier’s risk level.

  1. Check the last surveillance audit date.
  2. Check the next scheduled surveillance audit date.
  3. Verify the recertification audit date (usually every 3 years).
  4. Check the current status: active, suspended, or withdrawn.

A certificate with a status of “active” means the supplier passed the last audit. A status of “suspended” means there are serious non-conformances that must be resolved before the certificate is reinstated. If you see “suspended” on a certificate, stop the sourcing process immediately.

Surveillance audits are typically annual. They check if the supplier is maintaining the quality system identified in the initial certification. Recertification happens every three years and involves a full audit of the entire system. If the recertification audit is due in less than 30 days, the supplier is in a transition period. During this time, they may be scrambling to prepare for the audit. This is a high-risk period for new business.

If the surveillance audit is more than 12 months overdue, the certificate is technically invalid. The certification body should have issued a notice and started the process to reinstate or withdraw the certificate. Do not assume the supplier is in the process of scheduling the audit. Verify the status directly with the certification body if possible.

Red flags to watch for:

  • Surveillance audit is more than 12 months overdue.
  • Recertification audit is due in less than 30 days.
  • Status is not clearly stated as “active”.
  • The audit date is in the future relative to the issue date.

Section 4: Supplier Quality System Evidence

The certificate is a snapshot. You need to verify the quality system is functioning in daily operations. Request the following documents during your supplier audit.

  1. Quality plan or quality manual.
  2. Control plan for the specific part number.
  3. Process capability studies (Cpk/Ppk).
  4. First Article Inspection reports.
  5. Non-conformance report summary for the last 12 months.
  6. Corrective action reports for major customer complaints.

The control plan is the heart of IATF 16949. It should match your drawing and specification. Check that it includes critical and special characteristics. If the control plan is generic and not part-specific, the supplier may not be applying the standard to your product.

A control plan is a living document. It should detail the control method, frequency, and acceptance criteria for each operation. For a stamped part, it might include the stamping pressure, die wear check frequency, and surface roughness measurement. If the control plan is a one-page document that applies to all parts, it is not meeting the IATF 16949 requirement for specific process control.

Process capability studies (Cpk/Ppk) show if the process is capable of producing parts within specification. For critical characteristics, Cpk must be at least 1.67. If the data is older than 12 months, it may not reflect the current state of the equipment. New tooling, new operators, or material changes can shift capability. Request recent data.

First Article Inspection reports verify that the first lot of production meets the drawing. If the FAI report does not match the current drawing revision, the supplier may be building to an old version. This is a major risk for new programs or after engineering changes.

Red flags to watch for:

  • Control plan is missing critical characteristics.
  • Process capability data is older than 12 months.
  • First Article Inspection report does not match the current drawing revision.
  • Non-conformance reports are closed without documented corrective action.
  • Corrective action is “rework” without root cause analysis.

Section 5: Customer-Specific Requirements (CSR)

IATF 16949 requires suppliers to identify and meet customer-specific requirements. These vary by OEM and Tier 1.

  1. Check if the supplier has a CSR matrix.
  2. Verify the CSR matrix includes your company’s requirements.
  3. Check if the CSR matrix is reviewed annually.
  4. Confirm the supplier has a process for communicating changes in CSR.

If you are a Tier 2 supplier to an OEM, your customer (Tier 1) may have specific requirements. The supplier must show they understand and meet these. If you are a Tier 1, you need to show your OEM’s requirements are met.

CSR matrices are the primary tool for managing this. They list each requirement, the source (e.g., a specific OEM standard or a Tier 1 quality agreement), and the supplier’s method of compliance. If you are a Tier 1 buying from a Tier 2, you need to see their matrix to ensure they are meeting your requirements, which often flow down from your OEM customer.

Check the date of the last review. If the matrix was last updated three years ago, it likely misses recent changes in your quality agreements or your OEM’s standards. A supplier who does not update their CSR matrix is not meeting the IATF 16949 requirement to maintain compliance with customer-specific requirements.

Also check how they manage changes. If your requirements change, do you have a formal process to notify them? Do they have a process to confirm receipt and implementation? If the communication is informal, such as a phone call, there is no audit trail. Use written change orders and require written confirmation of implementation.

Red flags to watch for:

  • CSR matrix is missing or outdated.
  • Supplier cannot explain how they meet your specific requirements.
  • CSR changes are not communicated to the supplier.
  • Supplier does not have a process for managing customer complaints.

Section 6: Traceability and Traceability Records

IATF 16949 emphasizes traceability. You need to verify the supplier can track parts through the manufacturing process.

  1. Check the supplier’s lot or serial number system.
  2. Verify lot numbers are recorded in the ERP or quality system.
  3. Check if lot numbers are traceable to raw material certificates.
  4. Confirm the supplier can provide traceability for 30 days or more.

Traceability is critical for recalls. If a part fails in the field, you need to know which lot it came from and what raw materials were used. If the supplier cannot trace a part to its raw material, the certification claim is weak.

Ask for a specific example. Pick a part number from your current production. Ask the supplier to pull up the lot number for a specific shipment. Check if that lot number links to the raw material receipt. Check if the raw material receipt has a certificate of conformance from the raw material supplier. Check if the lot number is unique. If the same lot number is used for different materials or different dates, the system is flawed.

For heat-treated parts, traceability is even more complex. The heat treatment batch number must be traceable to the raw material and the heat treat log. If the supplier cannot provide the heat treat log for a specific part, they cannot prove the part received the correct thermal treatment.

Red flags to watch for:

  • Lot numbers are not unique or are reused.
  • Traceability stops at the assembly stage.
  • Raw material certificates are missing or outdated.
  • Supplier cannot provide traceability for more than 7 days.

Section 7: Red Flags and Common Errors

Before signing off, check for these common errors that indicate a weak certification claim.

  1. Certificate scope does not match the part you are buying.
  2. Certification body is not IATF approved.
  3. Surveillance audit is overdue.
  4. Control plan is generic and not part-specific.
  5. Traceability records are incomplete.

If you find any of these, do not accept the certificate as valid. Request a revised certificate or a new audit. Do not rely on verbal assurances.

A common mistake is accepting a certificate for a supplier’s headquarters when the production is at a plant. The certificate must cover the actual production site. If the supplier has multiple sites, each site with production capability must be listed in the scope. If your part is manufactured at Site A, but the certificate only lists Site B, the certification does not apply to your part.

Another mistake is assuming that a valid IATF 16949 certificate guarantees the part is good. It guarantees the supplier has a system to manage quality. It does not guarantee that every part is perfect. You still need incoming quality checks, control plans, and production monitoring. The certification is the baseline. Your quality system is what makes it work.

If the supplier resists providing these documents or gives vague answers, that is a red flag. A legitimate IATF 16949 supplier should be able to provide these records quickly and without effort. If they struggle, their quality system is likely not as strong as the certificate suggests.

Table: Quick Reference for IATF 16949 Verification

Check Item What to Verify Red Flag
Certificate Scope Matches part and process Generic scope
Certification Body IATF approved Not listed on IATF site
Audit Status Active and current Suspended or overdue
Control Plan Part-specific and current Generic or outdated
Traceability Lot to raw material Gaps in traceability

Frequently asked questions

Can a supplier claim IATF 16949 if they only have ISO 9001?

No. IATF 16949 is a different standard with specific automotive requirements. ISO 9001 is not sufficient for IATF 16949 claims.

How often should I re-verify a supplier's IATF 16949 certification?

Check the certificate expiry and surveillance audit dates. Re-verify annually or when the supplier changes processes or sites.

What if the certificate scope is broader than my part?

That is acceptable. The supplier's scope can be broader, but it must include your specific part and process.

Do I need to see the actual audit report?

You do not need to see the full report, but you should request a summary of non-conformances and corrective actions.

Can a supplier provide a digital certificate?

Yes, digital certificates are acceptable if they are verifiable and match the physical certificate. Check for a digital signature or QR code.