Quality Assurance System: RFP and Acceptance Guide
When a customer or certification audit is approaching, does your team still reconstruct evidence from paper inspection sheets, spreadsheets, machine logs, and email approvals? A quality assurance system should do more than replace paper with PDFs. It should let authorized users reconstruct which material, equipment condition, operator, inspection, specification revision, exception, and approval applied to a particular lot or serial number—without losing the history of who changed what and why.
This guide is for manufacturing sites in Thailand and ASEAN that want to digitize quality records and trace manufacturing history. It translates the objective into an RFP, FAT/SAT acceptance tests, an audit evidence pack, and a practical 90-day rollout. It is deliberately written for a Do/Buy decision, not as another general introduction to ISO 9001.
Important: retrieval times, recovery objectives, clock tolerances, review frequency, and sample sizes in this article are recommended design values, not universal requirements of ISO, IATF, FDA, or NIST. Set the final values from customer-specific requirements, law, contracts, product risk, data classification, and a business-impact analysis.
A quality assurance system is not a document warehouse
Plants with slow audit responses do not necessarily lack records. Often, they have many records whose relationships have been lost. Incoming inspection is in Excel, process parameters sit in a machine PC, in-process inspection is on paper, deviations are approved by email, and nonconformance is in another application. When an auditor asks for the material lots, machine settings, inspection results, change approval, and disposition behind one shipment, people manually rebuild the chain.
The target operating model needs five capabilities working together:
- An identity model connecting product, lot, serial, material, equipment, person, inspection, and change.
- Provenance showing source, timestamp, revision, approval, and later correction.
- Exception management for missing, duplicate, delayed, out-of-order, or inconsistent records.
- Role-based rights to view, enter, approve, correct, administer, and export information.
- Search and controlled output that turn an audit question into a reproducible evidence package.
ISO describes ISO 9001 as a quality-management-system framework, and certification is voluntary. ISO/TC 176 guidance on documented information also explains that organizations have flexibility in deciding the documented information and media appropriate to their context. ISO does not require a named cloud product or a universal pack of electronic forms. Software supports the process and its evidence; it does not replace process ownership, competence, risk treatment, or improvement.
ISO 9000:2026 distinguishes concepts such as objective evidence, records, and audit evidence. Without reproducing the standard’s copyrighted wording, this article treats objective evidence as verifiable information supporting a fact, a record as information showing an activity performed or a result achieved, and audit evidence as relevant information that can be evaluated against audit criteria. Consult the official standard for normative terminology.
Design the data model backward from audit questions
Starting with feature checklists tends to make the selection about screens and reports. Start instead with the questions the system must answer:
- Which material and component lots went into shipment lot A?
- Where are their incoming inspections and supplier certificates?
- Which machine, fixture, program revision, and parameter set were used?
- Was the operator’s qualification valid at the time of production?
- Which work instruction, drawing, and inspection-specification revisions applied?
- If a deviation occurred, who assessed it, what evidence supported the decision, and who approved it?
- Which units were affected by a 4M change?
- If a value was corrected later, can we see the original value, reason, author, time, and approval?
Typical linking keys include product serial number or manufacturing lot, material lot, process and equipment, event time, specification revision, and the person or system acting. The challenge is not finding one perfect primary key. It is maintaining mappings across ERP production orders, MES lot IDs, machine work IDs, inspection filenames, and customer part numbers—and retaining the history of those mappings.

Put forward and backward traceability in one model
Customer audit traceability needs both backward tracing from finished goods to inputs and forward tracing from a suspect material lot to work in process, finished goods, and shipments. Separate spreadsheets make splits, merges, re-entry, rework, and partial consumption easy to lose.
A useful event model records input objects, the process performed, output objects, time, location, actor, applicable specification, result, and linked evidence. Lot splits and merges should be appended as events instead of overwriting ancestry. Scrap, hold, reinspection, concession, and rework belong in the same genealogy. For a deeper treatment, see our guide to a forward and backward traceability system.
Audit trail and manufacturing genealogy are not synonyms
An audit trail shows who created, changed, approved, or cancelled an electronic record and when. Manufacturing genealogy shows the history and relationships among products, materials, operations, equipment, and inspections. They reinforce one another but solve different questions.
If a process value is corrected from 180 to 185, the audit trail should show both values, the reason, actor, time, and approval. The genealogy should show which lots or serial numbers used that value. Either alone leaves a gap between record trustworthiness and product impact.
Inventory evidence flows before digitizing forms
Do not begin by counting every paper form. Follow evidence from its creation and approval through storage, retrieval, disclosure, retention, and disposal.
| Inventory item | What to establish | Risk if omitted |
|---|---|---|
| Purpose | Which decision, obligation, or product risk the record supports | High storage volume but missing critical evidence |
| Source | Person, machine, gauge, ERP, MES, or supplier document | Unclear responsibility for transcription and verification |
| Identity keys | Part, order, lot, serial, machine, and time | Inability to join the same object across systems |
| Revision | Drawing, instruction, inspection plan, and program version | Inability to prove the criteria valid at the time |
| Approval | Creation, review, approval, concession, and change authority | Self-approval or uncontrolled delegation |
| Retention | Legal, customer, contractual, and internal basis by record class | Under-retention or indiscriminate over-retention |
| Retrieval | Who may retrieve, with which filters, and in which format | Disclosure of personal, confidential, or other-customer data |
| Exceptions | Missing, duplicate, late, offline, resent, and corrected data | An evidence chain that works only in ideal conditions |
The output should be an “audit question–evidence–source–key–owner–retention basis–submission format” matrix, not merely a form register. Record the present retrieval time and manual steps; these become the baseline for acceptance.
RFP requirements for electronic quality records
Avoid phrases such as “supports traceability” or “audit ready.” Define the object, input, expected outcome, abnormal condition, verification, and required evidence.
| ID | Requirement | Minimum condition | Supplier response required | Acceptance evidence |
|---|---|---|---|---|
| R01 | Identity and genealogy | Preserve split, merge, re-entry, and rework without overwriting history | Data model, limits, and configuration | Query output for supplied scenarios |
| R02 | Record ingestion | Identify source for manual, CSV, API, and machine data | Protocols, retries, and deduplication | Disconnect/reconnect logs |
| R03 | Data completeness | Detect missing keys, invalid formats, range breaches, and reversed timestamps | Rule management and exception queue | Results from injected bad data |
| R04 | Revision control | Reconstruct the specification effective at event time | Effective dating, approval, obsolescence | Historical-lot query |
| R05 | Audit trail | Retain actor, time, reason, and before/after values | Append behavior, tamper controls, access | Correction scenario output |
| R06 | Authorization | Enforce least privilege and separation of duties | Role model, identity integration, reviews | Permission matrix and negative tests |
| R07 | Search | Trace product-to-material and material-to-shipment | Filters, performance conditions, limits | Timed results for ten representative questions |
| R08 | Evidence pack | Export scope, filters, version, author, and generation time | PDF/CSV/API, masking, signatures | Complete sample and reproduction steps |
| R09 | Retention | Per-class retention, hold, disposal approval, and evidence | Configuration units and backup behavior | Retention-and-hold test |
| R10 | Resilience | Continue records, recover, and reconcile after failure | Offline process, RTO/RPO, disaster recovery | Restore exercise report |
| R11 | Security | Encryption, secrets, vulnerability handling, and monitoring | Shared-responsibility model and notification targets | Design, configuration, and test records |
| R12 | Language and time | Thai/English input, UTC/local display, and character support | Storage and search behavior | Multilingual and time-boundary tests |
| R13 | Migration | Record source, transformation, reconciliation, rejects, and reruns | Migration and rollback plan | Counts, hashes, and exception log |
| R14 | Operability | Local staff can manage master data, alerts, backup, and monitoring | Admin tools, training, and procedures | Operations rehearsal |
| R15 | Exit | Export data, attachments, relationships, and history in readable form | Contract-end format, time, and cost | Demonstrated bulk export |
Require suppliers to distinguish standard features, configuration, custom development, and unsupported requirements. Each answer should state assumptions, limitations, a screen or API reference, and how it will be tested. Run demos with your scenarios and imperfect data, not only the supplier’s polished sample.
Turn “fast retrieval” into an acceptance value
“Search must be fast” cannot be accepted objectively. A stronger starting statement is: “For ten project-defined trace queries, the components of the audit evidence pack shall be retrievable within three minutes at the 95th percentile.” That is a recommended design value, not a standard requirement. State the data volume, concurrent users, network, and query boundaries, then adjust it to the business risk.
The same applies to a ±1-minute clock difference among participating systems, an interface alert within five minutes, a pilot RTO of four hours and RPO of 15 minutes, and quarterly permission review. These are recommended design values to negotiate, not compliance claims.
Architecture: connect the evidence chain without stopping the plant
The solution need not be one monolith. ERP, MES, QMS, machines, inspection equipment, document control, identity services, and a data platform can share responsibility:
- Source layer: PLCs, sensors, inspection systems, terminals, and supplier evidence retain source value, unit, and quality state.
- Collection layer: gateways handle protocols, buffering, retries, deduplication, time normalization, and mappings.
- Business-context layer: orders, items, BOMs, routes, lots, serials, specifications, and approvals are linked.
- Evidence layer: records, attachments, audit trails, retention, integrity controls, and backup are managed.
- Use layer: search, genealogy, evidence packs, dashboards, and exception queues serve defined roles.
Do not assume direct machine-to-cloud connectivity. IT and OT should define zones, approved conduits, gateways, buffering, monitoring, and change control. NIST recommendations on manufacturing-data traceability and trustworthiness provide useful lifecycle concepts around provenance and integrity. NIST SP 800-171 Rev. 3 may be relevant when contracts require protection of controlled unclassified information in nonfederal systems; it is not automatically applicable to every factory.
Time, units, and master data become audit issues
If one machine uses local time, another UTC, and a gauge has a manually set clock, events may appear out of order. Store or distinguish event time, receipt time, processing time, and time zone. Monitor clock status. A cross-system difference within ±1 minute is a recommended design value and must reflect process speed and risk.
Retain both original and converted values and identify the conversion-rule revision. Effective dating and approval are needed for part, machine, process, and defect-code masters. A master-data error can attach thousands of correct measurements to the wrong context, so master changes are quality changes, not merely IT administration.
Roles and responsibilities
The process owner determines what evidence means. Quality should not become the sole owner of every digital record.
| Role | Core responsibility | Decision or approval |
|---|---|---|
| Executive sponsor | Scope, priority, resources, cross-functional escalation | Policy and acceptance of major residual risk |
| Quality owner | Audit questions, evidence, retention basis, disclosure rules | Evidence pack and quality acceptance |
| Manufacturing process owner | Shop-floor events, standard work, exceptions | Validity of process operation and change |
| Production engineering/OT | Machine tags, connection, clock, buffer, change | Equipment-side FAT/SAT |
| IT/security | Identity, network, monitoring, backup, recovery | Security and operational handover |
| Data owner | Keys, masters, data rules, permitted use | Definitions and exception disposition |
| Internal audit | Independent check of evidence and operational effectiveness | Audit findings, not self-approval of operation |
| Supplier/integrator | Design, configuration, tests, training, correction | Contract deliverables and test evidence |
| Site key user | Daily exception handling, first-line support, improvement | Shop-floor acceptance and feedback |
Test negative separation-of-duty cases: an operator cannot finally approve the operator’s own deviation, an administrator cannot erase the audit trail, and a supplier support account is not permanently active. Emergency and delegated access should have purpose, expiry, approval, and after-the-fact review.

Build the audit evidence pack before the audit
Standardize evidence packages for representative audit questions rather than creating a new folder every time. A package should include:
- Cover: product or lot, filters, generation time, generator, and system version.
- Genealogy: material, process, inspection, finished product, and shipment relationships.
- Specifications: applicable drawings, instructions, inspection plans, and program revisions.
- Execution: critical parameters, results, equipment, fixture, and qualification state at the time.
- Exceptions: nonconformance, deviation, hold, reinspection, rework, concession, and approval.
- Changes: relevant 4M change, effective boundary, impact assessment, and verification.
- Record history: correction and approval audit trail.
- Completeness statement: missing data, exclusions, exceptions, and extraction limitations.
The goal is not maximum disclosure. Templates and authorization should prevent unnecessary disclosure of personal information, another customer’s data, or machine intellectual property. An exported PDF should identify the filters and source-record IDs so the package is reproducible.
For rehearsals, have internal audit select an unannounced lot and question. “Ten representative questions with P95 retrieval within three minutes” is a recommended design value. Score completeness, revision correctness, authorized scope, and explainability as well as speed.
Link 4M approval to the actual change boundary, first-piece confirmation, enhanced inspection, training, machine conditions, and any customer approval. Our 4M change management system guide explains this connection in more detail.
FAT and SAT acceptance tests
FAT normally verifies agreed design, configuration, and functions in the supplier environment. SAT verifies the end-to-end purpose in the real factory, network, machines, users, data, and operating conditions. Contract terminology varies; make the test objective and environment explicit.
FAT scenarios
| Test | Scenario | Example acceptance criterion | Evidence |
|---|---|---|---|
| Genealogy | Split, merge, re-entry, and rework | Relationships and states match the approved model | Input, UI capture, API output |
| Correction | Correct a value with reason and approval | Original/new values, reason, actor, and time remain | Audit trail export |
| Authorization | Attempt unauthorized view, approval, and export | Attempt is denied and logged | Negative-test log |
| Interface | Duplicate, missing, unordered, disconnected, and resent messages | No silent duplication; exceptions visible | Message IDs and queue |
| Revision | Produce before and after an effective-date boundary | Each event links to the then-effective revision | Revision history and query |
| Retention | Simulate expiry, hold, and approved disposal | Only eligible records are processed, with evidence | Job and approval logs |
| Exit | Simulate contract termination | Data and relationships export in reusable form | Files, schema, count reconciliation |
SAT scenarios
Include site realities: machine clock drift, network interruption, barcode failure, shift handover, Thai names, inconsistent legacy masters, and offline procedures. Testing one normal peak shift plus backlog recovery is a recommended design value.
For the audit pack, use a production-like test lot and combine backward/forward tracing, effective revision, exceptions, and corrections. A 100% presence rate for project-defined mandatory keys is a recommended design value; it proves presence, not truth. Reconcile sampled values with machine sources, temporary paper controls, and ERP quantities.
Classify defects by effect on evidence and product decisions, not raw count. Wrong-lot linkage, unauthorized history modification, undetected loss, and failed restoration are critical examples. A usability problem is also serious when it drives operators to create shadow records. Conditional acceptance needs a temporary control, owner, deadline, retest, and decision if unresolved.
A 90-day implementation roadmap
Do not promise to replace every record in every plant in 90 days. Prove one end-to-end slice in production-like operation. One product family, one line, and one audit evidence pack is a recommended design value.
Days 0–15: fix purpose and boundary
- Select customer, product family, operations, equipment, records, and questions.
- Identify customer-specific, legal, contractual, and internal retention obligations.
- Demonstrate current retrieval and record time, missing links, transcription, and personal workarounds.
- Agree identity keys, system boundaries, owners, success criteria, exclusions, and change control.
Days 16–35: specify and prototype
- Anonymize representative data and prototype forward/backward tracing.
- Create scenarios for exceptions, correction, revision, rights, retention, and output.
- Give the same scenarios to Do and Buy candidates.
- Agree interfaces and shared responsibility.
- Draft FAT/SAT protocols and evidence templates before building.
Days 36–65: build, integrate, and migrate
- Configure identities, roles, masters, and quality rules.
- Add machine, ERP, MES, and inspection connections incrementally.
- Implement buffering, retry, deduplication, exception queues, and monitoring.
- Record migration counts, hashes, rejects, and reruns.
- Prepare procedures, training, backup, and temporary offline records.
Days 66–90: test, parallel-check, and rehearse
- Correct FAT defects and run SAT under site conditions.
- Reconcile the new record with the current source for a defined period.
- Let internal audit conduct unannounced retrieval.
- Exercise restore, permission review, and offline recovery.
- Decide residual issues, temporary controls, and expansion gates.
The day-90 outcome is not “software installed.” It is an approved evidence chain that answers defined audit questions under real operating conditions.

Do/Buy decision criteria
Do and Buy are not binary. Standard controls such as identity, audit logging, retention, and backup can come from a product, while process-specific equipment integration and logic are configured or developed.
Buy tends to fit when standard document, training, nonconformance, CAPA, audit, and approval processes dominate; multiple sites need common updates; and the company wants ongoing support for shared controls. Do or strong customization tends to fit when equipment genealogy is a differentiator, standard models cannot represent splits/merges or continuous materials, network and data-location constraints are unusual, and the company can sustain product ownership, OT/IT, testing, security, and maintenance.
Compare lifecycle workload, not only license and initial development: upgrades, master data, connection changes, validation, training, audit support, migration, monitoring, and exit. Measure your current work instead of accepting unsupported percentage savings.
Ask every supplier:
- Who—including administrators—can view, alter, delete, or export audit trails?
- How are corrections, cancellations, re-approvals, and delegation recorded?
- How are disconnects, duplicates, delays, ordering, and clock drift detected and recovered?
- Can the standard model represent splits, merges, rework, and re-entry?
- What changes to data, APIs, reports, and trails occur during upgrades?
- How are attachments, relations, masters, and history returned at contract end?
- Who investigates and supplies evidence for incidents and vulnerabilities?
- Which local support hours, languages, and escalation routes are available in Thailand?
- Who reproduces, corrects, and retests FAT/SAT defects?
- What compensating control and residual risk remain for each unmet requirement?
Governance, security, retention, and backup
Do not set one retention value for everything. Link each record class to law, customer requirements, contracts, product life, warranty, legal hold, and internal policy. Retaining the related audit trail at least as long as the record is an initial recommended design value, unless a governing obligation requires more.
Test restoration, not merely backup creation. A four-hour RTO and 15-minute RPO for the pilot are recommended design values to be adjusted through business-impact analysis. After recovery, reconcile offline and system records and approve duplicates or gaps as exceptions.
Update access on joining, transfer, and termination. Quarterly review is a recommended design value. Avoid shared accounts; time-limit supplier access and require approval, multi-factor authentication, and activity logging.
FDA Part 11 is a primary source for electronic-record and electronic-signature controls in FDA-regulated contexts. It does not automatically apply to every record in general manufacturing. Confirm the relevant predicate rules and use of the record. If you voluntarily adopt its ideas outside scope, document the difference between a legal requirement and an internal control.
Handling 2026 IATF information correctly
Automotive suppliers should monitor official IATF communiqués, sanctioned interpretations, and FAQs. The July 2026 Stakeholder Communiqué SC-2026-005 says work on IATF 16949 Revision 2 centers on five priority themes and that publication was planned for mid-2027. That is a plan that may change; the second edition was not published at the time of writing.
Do not write an unpublished edition into the RFP as a fixed requirement. Require configurable controls, revision impact assessment, retesting, training, and contractual update responsibility. SC-2026-004 also demonstrates that sanctioned interpretations and FAQs are official update channels for Rules 6th Edition and IATF 16949 topics. Check the latest official publication before a decision.
FAQ: audit records and manufacturing traceability
What is a quality assurance system?
It is the controlled combination of quality processes, records, manufacturing genealogy, permissions, change history, search, and disclosure. It may include QMS, ERP, MES, machines, inspection systems, document control, and identity services. The decisive factor is the evidence relationship and ownership, not the product label.
Can paper be retired as soon as records are digitized?
Not automatically. The transition depends on customer, legal, and contractual requirements, electronic-record trustworthiness, offline continuity, migration reconciliation, and acceptance results. A scanned PDF may not provide structured search, effective revision, approval, correction history, or product linkage. Time-limit parallel entry and define its reconciliation purpose.
How quickly must customer-audit traceability be shown?
There is no universal time. Ten representative queries with P95 retrieval within three minutes is this article’s recommended design value. Adjust it and assess completeness, revision, and authorized disclosure along with speed.
Which quality records should be digitized first?
Prioritize by audit frequency, product risk, retrieval effort, missing-link risk, and connectivity to other evidence. Incoming material, critical process parameters, revisions, nonconformance/concessions, and 4M changes are common candidates. One product family, one line, and one pack is a practical recommended design value for a 90-day scope.
Should every machine signal be stored?
No. Define the values and granularity needed for product decisions, investigation, obligations, and process performance. For high-frequency data, distinguish raw, summarized, and event data and retain processing provenance. Indiscriminate retention increases cost, search burden, and security exposure.
Is a particular system required for ISO 9001 certification?
No. Certification is voluntary, and ISO does not prescribe a vendor. The organization determines suitable documented information and controls. Software supports execution and evidence but cannot replace accountability and improvement.
Is FDA Part 11 compliance sufficient for any manufacturing audit?
No. Applicability depends on FDA-regulated electronic records, electronic signatures, and associated predicate rules. Confirm industry and contract requirements first. Distinguish legal applicability from voluntarily adopted internal controls.
Is cloud or on-premises better for audits?
Deployment location alone does not decide. Compare identity, rights, change, audit trail, backup, restoration, outage continuity, data location, supplier management, and exit export with relationships intact.
How should RFP costs be compared?
Use the same period and assumptions for licenses, integration, data cleanup, migration, acceptance, training, operations, monitoring, upgrades, new sites, audit support, and exit. Validate proposed benefits against your measured baseline rather than unsupported ROI percentages.
Conclusion: make answerable audit questions the acceptance criterion
A quality assurance system is not primarily a paper-reduction project. It reconstructs a trustworthy relationship between product history and evidence. Design from audit questions, specify forward/backward genealogy, audit trails, revisions, exceptions, access, retention, and recovery, and make the evidence pack an acceptance deliverable. FAT should test functions and abnormal paths; SAT should prove the chain with real users, machines, and site conditions.
ISO 9001 certification is voluntary, ISO 10013 is guidance on documented information, IATF 16949 Revision 2 was still unpublished in September 2026, and mid-2027 was a changeable plan. FDA and NIST publications must also be used within their scope. Values such as three-minute retrieval, ±1-minute clock tolerance, four-hour RTO, 15-minute RPO, and a 90-day pilot are recommended design values, not standards.
TOMAS TECH can help structure the audit questions, identity model, RFP, and FAT/SAT boundary around your current forms, machines, ERP, and MES. If you are still defining the scope for quality-record digitization or customer-audit traceability in Thailand, you can contact us for an initial discussion with the target product, process, and the audit question that is hardest to answer today.
References
- ISO, ISO 9001 explained
- ISO/TC 176, Guidance on the requirements for Documented Information of ISO 9001:2015
- ISO Online Browsing Platform, ISO 9000:2026
- ISO, ISO 10013:2021
- IATF, Stakeholder Communiqué SC-2026-005
- IATF, Stakeholder Communiqué SC-2026-004
- U.S. FDA, Part 11, Electronic Records; Electronic Signatures — Scope and Application
- NIST, Recommendations for Ensuring Traceability and Trustworthiness in Manufacturing-Related Data
- NIST, SP 800-171 Rev. 3