What should an automotive-parts plant in Thailand or ASEAN do about the IATF 16949 2nd Edition before the formal requirements are published? The answer is not to guess future clauses and hard-code them into a new system. It is to translate the five officially announced priority topics into digital evidence that people can retrieve, explain and approve, then turn that model into an RFP and acceptance specification within 90 days. This guide provides a practical Do/Buy path.
Important premise: the IATF communiqué issued in July 2026 describes the direction and indicative timing of the revision. It is not the final Revision 2 requirement text. The fields, workflows and 90-day plan in this article are preparation hypotheses designed to survive change, not claims about future mandatory requirements.
What is officially known about IATF 16949 2nd Edition
IATF Global Oversight’s Stakeholder Communiqué SC-2026-005 calls the revision “Revision 2” and identifies five priorities based on stakeholder feedback.
| Official priority | Direction stated by IATF | Preparation hypothesis for a plant |
|---|---|---|
| Simplification, clarity and efficiency | Make the standard easier to understand, implement and audit, reduce interpretive variation and avoid duplication with ISO 9001 | Stop copying the same evidence into several forms; identify one source, reference and accountable owner |
| Software quality assurance | Apply quality-management principles consistently across the embedded-software lifecycle | Connect requirements, versions, tests, approval, release and affected products |
| Tier N supply-chain management | Strengthen lower-tier management through risk-based methods, deployment of customer requirements and communication | Trace requirement delivery and response beyond Tier 1 for critical materials and processes |
| Launch management | Apply a more structured approach to new products, change and industrialization | Preserve gate decisions, open issues, temporary controls, Safe Launch and release approval in sequence |
| Customer-specific requirements (CSR) | Improve identification and management of applicable CSRs and consider common CSR content | Control customer, site, part, applicable version, effective date, deployment and implementation check |
The schedule is not final. The communiqué places working-draft development and external feedback in 2026; final validation, translation and supporting documents in 2027; and planned publication in mid-2027. It explicitly says the dates remain indicative and may be adjusted. It does not give a fixed IATF transition deadline; it says the end of the transition period will be aligned with the end of the ISO 9001 transition.
It would therefore be risky to declare that a plant is “Revision 2 compliant,” that a particular feature will be mandatory, or that a specific retention period will apply. Version control, approval, traceability and fast retrieval, however, are durable capabilities. Investment should target the evidence operating model, not a prediction of clause wording.

Convert five priorities into six evidence-design questions
Preparation is not primarily a project to digitize forms. It is the design of how the plant answers an audit or customer question: who retrieves which authoritative record, at which version, with which approval. Translate every priority into six questions.
- Evidence object: What is the authoritative record?
- Accountable owner: Who maintains it and closes exceptions?
- Approval: Who activates, changes or releases it, and against what criteria?
- Version control: How are requirement, document, process and software versions locked together?
- Retrieval time: How quickly can the plant present evidence for a specified customer, part, lot and period?
- Drill: Can the team reproduce the answer when records are missing, changed or inconsistent?
Evidence objects need relationships, not just PDF files
Saving PDFs, spreadsheets and emails in a shared folder can prove that files exist, but it rarely explains applicability. For this article’s 90-day pilot, consider the following identifiers and links as design candidates.
| Evidence object | Core identifiers | Main links | Typical exception |
|---|---|---|---|
| Requirement record | Customer, document, revision, effective date, applicable site and part | CSR, drawing, specification, internal standard | Applicability pending; obsolete revision referenced |
| Product/process definition | Part, route, equipment, tool, inspection and Control Plan revision | PFMEA, work instruction, inspection standard | Unapproved revision combination |
| Change record | Reason, 4M class, impact, approval and cutover time | Part, lot, equipment and supplier | Unapproved change; unclear cutover boundary |
| Software release | Software ID, revision, requirement, test, approval and target | ECU, inspection station, PLC, analytical tool | Target running the wrong version |
| Supplier evidence | Purchased item, manufacturing site, tier, requirement deployment, receipt, response and assessment | Purchased part, special process, material lot | Lower tier unknown; overdue response |
| Launch gate | Gate, date, entry criteria, open issues, temporary controls and exit criteria | APQP deliverables, trial lot and production approval | Conditional approval expired |
| Production/quality event | Serial/lot, time, process, machine, measurement, disposition and action | Material, WIP, finished item and shipment | Missing event, rework, split or merge |
Links between objects matter most. From a suspect lot, the plant should be able to traverse material, machine, program revision, inspection, operator qualification, the Control Plan effective at the time and associated 4M changes. In the other direction, it should be possible to see which parts, processes and suppliers received a CSR revision.
Our existing automotive-parts traceability and IATF 16949 guide covers lot granularity and audit design. This article deliberately builds on that foundation and concentrates on ownership, approval, version configuration, retrieval time and drills.
The owner closes exceptions; the owner is not merely the data-entry person
A RACI chart still fails when “Accountable” is only a department name. Define a role and delegation order, not just Quality, Purchasing or IT. The accountable owner’s job is to close exceptions such as an unapproved record, an overdue supplier response, a version mismatch or a missing event.
For CSR control, separate the person who downloads a document, the owner who assesses applicability, the person who deploys actions and the approver who reviews completion. Record the scope and expiry of delegated approval. Avoid shared approval accounts; preserve the person, time and reason for the decision.
Approval must preserve decision criteria, not merely an electronic stamp
An approval button does not show why an item was accepted. Capture entry criteria, reviewed revision, exceptions, due dates and release criteria. Conditional approval is especially important. If production starts with additional inspection, the temporary control needs an exit condition and an accountable release owner, or it can quietly become permanent.
Do not overwrite corrected approvals. Link the withdrawal reason, old decision, new decision and affected lots. An image of a signature is less useful than a queryable record of who decided what, when and under which conditions.
Version control must lock a configuration, not just individual documents
The effective state of a process is a combination of drawing, Control Plan, PFMEA, work instruction, inspection program, PLC/machine parameter set, software and customer requirement. Every document may individually be the latest revision while the combination remains unapproved.
Issue an effective configuration for each product and process. Use a cutover timestamp or starting lot as the boundary and lock the approved revision set. The goal is not to show today’s newest document, but to reproduce the configuration used to make the lot under review. The 4M change-management guide explains how to control the cutover boundary and detect mixed pre- and post-change lots.
Retrieval time is an operating KPI, not a database benchmark
“Searchable” is not a pass criterion. During a drill, log the time when the customer, part and lot question arrives and the time when the complete evidence package is ready. That package may include material-to-shipment genealogy, effective revisions, inspection, changes and deviation approval.
The target must reflect customer requirements and plant risk; this article does not impose a universal mandatory time. Measure the first-run median and maximum, then agree an internal target such as 30 minutes. Record not only averages but also missing items, manual handoffs and dependence on particular employees.
Drills must include failure cases
A search for a clean completed lot does not reveal the weak points. Include scenarios such as:
- A Tier 2 manufacturing site is unknown and Tier 1 does not respond.
- A CSR has changed while applicability for several parts is still pending.
- An inspection station runs a software revision outside the approved configuration.
- A defect is found during Safe Launch and shipped exposure must be isolated.
- The 4M cutover timestamp does not match the material-lot boundary.
- There is evidence that an obsolete Control Plan was used.
Do not record only pass/fail. Separate the question, start time, evidence path, gap, decision, containment and corrective action. Those findings become the next RFP requirements and improvement backlog.

A 90-day IATF 16949 transition-preparation roadmap
Because the formal requirements have not been published, a full enterprise rollout is less safe than proving the evidence model on one product family and one line. Divide 90 days into discovery, design, connection, procurement and drills.
Days 1–15: define scope and measure current retrieval time
Do not select a platform in the first two weeks. Inventory target customers, parts, processes, critical purchased items, software and CSR documents. Record where each piece of evidence currently resides.
Prepare at least three customer-like questions and time the search. Examples include the material certificate and inspection for a lot; the effective process parameters and software revision; and the associated change approval and supplier response. If an item cannot be found, record a gap rather than filling it with an assumption.
Deliverables are:
- A scope table covering customer, product family, line, critical process and supplier.
- A CSR applicability register covering document, revision, effective date, scope, owner and deployment state.
- An evidence-location map covering ERP, MES, QMS, file shares, email and paper.
- A retrieval baseline showing median, maximum, gaps and number of manual handoffs.
- A problem backlog with owner, severity, containment and due date.
The question-led method in our customer-audit traceability guide helps expose broken search paths that a document list will miss.
Days 16–30: define authority, ownership, approval and revision rules
Choose about seven evidence objects and create a data dictionary. For each field define its meaning, unit, source, edit rights, system of record, relationship key and missing-data response. A field called “lot number,” for example, may hide supplier, receipt, process and shipping lots.
Make one location authoritative for CSR and process standards; define email attachments and local files as reference copies. Design a workflow that turns a revision notice into impact assessment, applicability, actions, training and verification.
Do not over-design screens at this point. Confirm identifiers and state transitions. A CSR might move through received, review, applicability decision, deployment, implementation, verification and retired. A change might move through request, impact assessment, approval, preparation, cutover, verification and closed. A skipped state needs a reason and approval.
Days 31–60: connect the evidence on one pilot
Select a product with high customer importance and change frequency, and enough material, process, software and Tier N complexity to test the model. You do not need to integrate ERP, MES, QMS and every machine at once. Common IDs and controlled source links can be a valid first step.
Test exceptions rather than only clean messages: duplicates, latency, clock differences, unit conflicts, part mapping failures, machine outages, manual corrections, rework and lot split/merge. Never discard a failed interface event. Place it in an exception queue with owner and reprocessing result.
For Tier N, use risk to choose depth. Consider safety or regulatory impact, special characteristics, single sourcing, long lead time, past defects, change frequency and geographic concentration. A blanket demand that Tier 1 disclose every lower-tier entity is difficult to sustain. For critical materials, progressively confirm manufacturing site, process, certification, requirement receipt, change notification and alternatives.
Days 61–75: convert the RFP from features to scenario acceptance
Now define the external RFP. Checkboxes such as “traceability available” and “workflow available” can pass a demo and fail in operation. Package each requirement as a business scenario, input condition, expected result, evidence, performance and failure behavior.
| Acceptance scenario | Input given to the vendor | Example pass condition | Evidence retained |
|---|---|---|---|
| Reverse lot trace | Customer, part and shipment lot | Present material, process, machine revision, inspection and change as linked evidence | Search log, export, screen and elapsed time |
| CSR revision | Old/new revision and target customer/parts | Track comparison, applicability, deployment and incomplete actions | Revision history, approval, notice and open list |
| Software mismatch | Inspection station outside approved revision | Detect, hold affected product and assign exception | Detection time, containment range and correction trail |
| Tier N change | Tier 2 manufacturing-site change | Identify affected purchased items, products and customers; prevent pre-approval use | Impact assessment, approval and receipt control |
| Launch gate | Gate with open actions | Prevent unconditional pass; bind conditions, owner and deadline | Decision, exceptions and release approval |
| Network outage/replay | Duplicate and out-of-order equipment events | Recover without gaps or double counts and preserve reprocessing audit | Exception queue, replay ID and reconciliation |
Replace “fast” with data volume and concurrent-user conditions based on plant measurements. Evaluate availability, recovery, backup, time synchronization, audit log, segregation of duties, export, APIs, master synchronization, multilingual display and support coverage in Thailand.
Days 76–90: drill, correct and make the investment decision
Bring Quality, Manufacturing, Purchasing, IT/OT and Sales together for time-boxed drills. Use a facilitator other than the system builder and do not reveal answers in advance. At minimum, run customer inquiry, CSR change, lower-tier change, software release and launch deviation scenarios.
Measure retrieval time, gaps, wrong revisions, approval queues, manual work and person dependency. Classify failure beyond “system defect”: unclear ownership, missing decision rule and inconsistent master data are separate causes. At day 90, put four decisions to management:
- Scope that existing tools and process changes can close.
- Scope requiring a product or system integrator.
- Scope to defer until formal requirements appear.
- Open questions for customers, certification body or headquarters.
Decide Do/Buy by responsibility boundary, not by screen design
Do/Buy is not a binary choice between a package and custom development. A practical split is to own the data definitions and business accountability, buy configurable workflow, and use an integrator for equipment connections and migration.
What the plant must own
- Applicability by customer, product, process and supplier.
- Meaning and authoritative source of each evidence object.
- Approval rules, exception response and segregation of duties.
- Retrieval-time target and drill scenarios.
- CSR interpretation and questions to the customer.
- Final conformity judgment and operational accountability.
Delegating these to a vendor may produce working screens but not an explainable factory decision. CSR applicability in particular varies by customer, contract, product and site; no software product can universally decide it.
What is often suitable to buy or outsource
- Document/revision control with immutable history.
- Electronic approval, due-date alerts and delegation.
- APIs and connections to equipment, ERP, MES and QMS.
- High-volume search, genealogy visualization and exception monitoring.
- Backup, availability and security maintenance.
- Multi-site, multilingual and customer-portal integration.
Still, run an acceptance test with real data before deciding that a standard workflow fits. If it conflicts with actual responsibilities and causes Excel workarounds, evidence will become more fragmented.
An RFP scoring model
| Dimension | Question | Strong warning sign |
|---|---|---|
| Evidence integrity | Are before/after values and the reason for correction preserved? | An administrator can overwrite without history |
| Relationships | Can users traverse requirement to part, process and lot in both directions? | Only full-text file search is available |
| Exception operation | Who owns and closes missing, duplicate or late data? | Errors are merely written to a log |
| Version configuration | Can the system reproduce the approved set at manufacturing time? | It can display only the latest revision |
| Search performance | Can time be measured with realistic volume? | Performance is promised from a tiny demo |
| Openness | Are export, API, migration and end-of-contract data return defined? | Proprietary format and unknown exit cost |
| Support | Are Thai time-zone coverage, plant language and incident responsibility clear? | Only a sales contact is named |
Compare total cost, not the licence alone: master cleanup, interface, migration, training, validation, operation, change, audit support and contract-exit data return. A low initial price becomes expensive if every customer CSR change requires custom development.
Evidence and drills for each official priority
1. Simplification, clarity and efficiency
The preparation hypothesis goes beyond reducing the number of forms. When one inspection result is manually copied to a production report, quality record and customer form, preserve one source and generate purpose-specific views. Maintain a terminology dictionary to handle department naming differences.
During a drill, ask Production and Quality to answer the same lot question independently. If values, revisions or decisions differ, correct the authoritative source and transformation rule. Efficiency should not remove approval; it should route low-risk standard changes differently from high-risk ones.
2. Software quality assurance
SC-2026-005 explicitly centers software quality assurance on embedded software. As this article’s preparation hypothesis, a plant should also inventory inspection, vision, PLC, torque, label, metrology and analytical software that affects product disposition or traceability. The exact future Revision 2 scope is not yet published.
As preparation, keep a software register with owner, purpose, affected equipment/product, requirement, revision, change reason, validation environment, test result, approval, deployment and rollback. In a drill, place an unapproved revision on one test station and verify detection, stop or quarantine, affected-lot identification, recovery and restart approval.
3. Tier N supply-chain management
An email proves that a requirement was sent; it does not prove implementation. Track send, receipt acknowledgement, applicability response, evidence submission, review, rejection and completion separately. When contractual confidentiality restricts lower-tier names, agree on useful information such as manufacturing-site risk, special process, change notification, continuity and alternative approval.
Start a drill with a lower-tier site change for a critical material. Identify affected purchased parts, internal parts, customers, WIP, stock and shipments. Confirm authority for purchase stop, deviation, alternative qualification and customer notification if the supplier does not respond.
4. Launch management
AIAG says APQP 3rd Edition includes updates on sourcing, change management, program metrics, risk mitigation plans, gated management and part traceability. Control Plan is now a standalone first edition, and AIAG’s related materials discuss Safe Launch and highly automated manufacturing. These publications are not the IATF Revision 2 text, but they are useful inputs for building launch evidence.
At every gate, retain not only deliverable presence but also risk, open action, owner, due date and conditional approval. For Safe Launch, preserve additional controls, frequency, reaction plan, performance, exit criteria and exit approval. Drill a defect escape and determine the effective revision, material and machine condition from which exposure began.
5. Customer-specific requirements
The official IATF CSR page hosts documents by OEM. It lists both the Ford CSR for IATF 16949:2016 and Ford-specific PPAP requirements as effective 15 June 2026. The covers also limit them to programs using Ford’s SCCAF process. That does not make Ford requirements universal: applicability must be confirmed against the contract, program, site and product. The example illustrates why version and effective-date ownership are necessary.
The CSR register should include issuer, title, revision, issue/effective dates, official URL, site, customer code, part, requirement owner, affected internal document, training, implementation and verification. Monitoring a website can detect a change, but must not automatically declare implementation complete. A person evaluates the difference and approves scope and due dates.

Why this preparation matters now in Thailand
Thailand’s BOI/OSOS reported on 10 September 2026 that electric and hybrid vehicles together represented 55% of the new-car market in January–July 2026. It also reported that, as of 31 August 2026, BOI approvals across the EV ecosystem reached 189 projects and approximately THB 151.4 billion. Policy principles include high-value local content and local-supplier development.
Those figures do not prescribe the same investment for every plant. The following is our inference, not a BOI finding: when electrification, model variety, automation and localization develop together, the combinations of changed objects and related evidence tend to multiply, making impact analysis more complex. Plants whose quality evidence is split across departmental spreadsheets may take longer to establish impact.
Thai parts plants may serve Japanese headquarters, Western OEMs, Chinese OEMs and local suppliers, each with different document systems. English, Thai and Japanese naming differences can duplicate a CSR or leave an obsolete revision in use. Before buying software, establish stable document IDs, customer codes, part numbers and site codes that do not change with display language.
Common failures and how to avoid them
Freezing functionality before the formal requirements
If future clauses are guessed and many dedicated mandatory fields are built, the formal text can create costly rework. Prefer configurable fields, workflows and parallel revisions. Tag every hypothesis with its rationale, decision date and review trigger.
Starting with enterprise-wide master-data perfection
An attempt to complete an ideal global master first may never reach a drill in 90 days. Build customer, part, lot, machine, supplier and document mappings for the pilot; prove exception handling; then scale.
Mistaking a dashboard for evidence
Charts support awareness, but an aggregate without drill-down to source, revision and approval is not sufficient evidence. For every KPI, retain the formula, population, update time, exclusions and source links.
Accepting the vendor’s clean demo
Demo data has no gaps or duplicates. Supply real naming, Thai-language values, long part numbers, split lots, rework, machine disconnection and clock differences. Attach pass/fail criteria to the RFP and test feasibility before contract.
Treating certification and system deployment as the same outcome
A system helps evidence integrity and retrieval; it does not automatically certify conformity. Process ownership, competence, judgment, internal audit, corrective action and management review remain the organization’s responsibility. Ask for evidence and liability boundaries when a vendor claims that deployment “completes Revision 2 compliance.”
FAQ: IATF 16949 revision 2026 and transition preparation
When will IATF 16949 2nd Edition be published?
SC-2026-005 says planned publication is mid-2027, while explicitly stating that the dates are indicative and may be adjusted. Do not treat this as a confirmed publication date. Continue monitoring official IATF Global Oversight communiqués.
Will starting now create rework?
Hard-coding unpublished clause numbers or mandatory fields would create rework. Establishing authoritative records, ownership, approval, version control, retrieval measurements and failure drills improves current quality management as well. Use configurable data and workflow so the model can be adjusted when the formal text appears.
Can a plant complete certification transition in 90 days?
The 90-day plan in this article is not a certification-transition promise. It proves evidence operations for a selected product/line and produces an RFP, acceptance specification and investment decision. Update the gap and transition plan once formal transition rules, customer requirements and certification-body guidance are available.
Does Tier N management require disclosure of every lower-tier company?
Formal Revision 2 requirements are not yet published, so no universal disclosure depth can be asserted. Begin with material/process risk and trace requirement deployment, manufacturing site, change notice, response and evidence for critical paths. Agree the level considering contracts, confidentiality and customer requirements.
Are APQP 3rd Edition and Control Plan 1st Edition the IATF Revision 2 standard?
No. AIAG Core Tools publications and the IATF standard revision are separate documents. APQP topics such as sourcing, change management, program metrics, risk mitigation, gated management and part traceability are nevertheless useful for preparing launch evidence.
Do Ford CSR and PPAP requirements effective 15 June 2026 apply to every plant?
The covers identify the documents as applying to programs using Ford’s SCCAF process. Applicability therefore depends on the contract, program, product and site, not merely on having Ford in the customer chain. Their listing on the official IATF CSR page is an example of why plants need revision and effective-date control. Your customer interface and quality owner should confirm applicability.
What is the highest-priority RFP requirement?
Reproducibility of your operating scenarios, not the number of features. Test reverse lot trace, CSR change, version mismatch, Tier N change, launch gate and network replay with real data. Make retrieval time, history, exception response and end-of-contract data return measurable pass criteria.
Conclusion: use the waiting period to build an explainable factory
IATF 16949 2nd Edition currently has five announced priorities and an indicative schedule, while the formal requirements are not yet published. Do not build around guessed clauses. Establish six durable capabilities: evidence objects, accountable owners, approval, version control, retrieval time and drills. In 90 days, a plant can measure its baseline, design the model, connect a pilot, issue a scenario-based RFP and run failure drills. When the formal edition arrives, the gap analysis can then be based on facts. Set Do/Buy boundaries through responsibility and acceptance evidence, not through product labels.
TOMAS TECH can help Thai plants inventory evidence across ERP, MES, QMS and equipment data, then translate a one-product/one-line pilot into an RFP and acceptance test without claiming unpublished requirements. You are welcome to contact us even at the early stage of measuring one evidence-retrieval scenario.
External sources
- IATF Global Oversight — Stakeholder Communiqué SC-2026-005: IATF 16949 2nd edition update information, July 2026.
- IATF Global Oversight — IATF Stakeholder Communiques.
- IATF Global Oversight — Customer Specific Requirements.
- AIAG — Advanced Product Quality Planning (APQP), 3rd Edition.
- AIAG — Control Plan, 1st Edition.
- AIAG — APQP & Control Plan are here.
- Thailand BOI / OSOS — Thailand Overhauls Vehicle Excise Tax as EVs Capture 55% of New Car Market, 10 September 2026.
- Ford Motor Company — Customer Specific Requirements for IATF 16949:2016, effective 15 June 2026.
- Ford Motor Company — Ford-Specific Requirements for PPAP, effective 15 June 2026.