You are standing on the shop floor during a customer audit when the auditor says, “Please show me the production records for this lot.” Somebody sprints to the document room. The records exist — that is not in question. But while one person flips through a binder, another opens a spreadsheet on a shared drive, and a third phones the person responsible, the search stretches into tens of minutes. When traceability comes up in a customer audit, what is really being evaluated is not whether the records exist. It is whether you can put them on the table the moment they are asked for. That response time is read as a proxy for how well the plant is actually controlled. This article walks through the records an IATF 16949 audit examines, what clause 8.5.2.1 actually requires, how to design internal traceability and digitize quality records so evidence surfaces quickly, and what changes on the day of the audit itself — with the specifics of Japanese-owned plants in Thailand in mind.
Why records cannot be produced during a customer audit
The records are not missing — they are unfindable
Most plants that get written up in a customer audit were not neglecting their records. The daily production logs are filled in. Inspection results are recorded. Equipment check sheets are signed. Operators take this seriously. The reason nothing surfaces during the audit is that the records were never stored in a form that ties them to one specific product.
Suppose the auditor opens with, “This part number, this lot, shipped on June 12.” What you now need is the molding conditions for that lot, the material lot that went into it, the equipment check results for that day, the operator who ran it, the inspection judgment, and — if there was a re-inspection — how that was decided. But the plant stores those records in entirely different buckets. Daily logs are filed by date. Check sheets are filed by machine. Incoming inspection records sit with purchasing. Final inspection records sit with quality assurance. Threading a single product through all of them is a manual cross-referencing job, and you are being asked to do it live, in front of the auditor. That is what “we cannot produce it” actually means.
Paper, spreadsheets, and systems living side by side
The second structural reason is mixed media. Shop floor forms are on paper. Summaries are in Excel. Orders and inventory live in the core business system. Equipment data sits inside software supplied by the machine vendor. Each of these works well enough on its own. What is missing is a shared key that lets you move between them. The classic mismatch is a paper daily log that carries the lot number while the Excel inspection summary carries only the date and part number — so there is no way to join the two without a human interpreting both.
Research published outside Japan makes the same point: organizations still relying on paper, spreadsheets, and siloed systems are likely to struggle to deliver traceability at the level now being demanded of them. The problem is not that different media exist. It is that no common key was designed to follow one product across them.
Only the person who wrote it knows what it means
The third reason is tacit knowledge. Handwritten notes in the margin of a form. Private abbreviations. Unwritten practice such as “when this reading runs high we re-measure it.” These are genuine shop-floor intelligence, but in an audit they become records nobody can explain. When the auditor asks what an entry means and the person who wrote it has resigned or rotated back to headquarters, there is no answer available.
None of these three is a problem with how records are written. All three come from the absence of a mechanism that connects records at the product level. In other words, they are traceability design problems.
What traceability actually means
It covers both directions
Traceability is the condition in which records let you follow when a product was made, where, from which materials, under which conditions, and where it went afterwards. It runs in two directions. Tracking follows the flow downstream, from raw material to finished goods to the customer who received them. Tracing runs upstream, from a problem found in the field or at a customer back to the manufacturing conditions and the raw materials involved.
A customer audit almost always probes both. “Show me the incoming inspection record for the resin used in this lot” is tracing. “Which other products used that same incoming lot, and where were they shipped?” is tracking. Plants that have built only one direction reliably hit a wall in the second half of the audit.
Internal and external traceability
Traceability is also divided by scope. Internal traceability covers tracking and tracing within your own processes — from the moment material enters your plant to the moment finished goods ship. External traceability covers the links that cross company boundaries, from supplier to you and from you to your customer.
The two are continuous, and external traceability only functions when each company’s internal traceability holds. If you cannot say inside your own four walls which incoming lot became which product, you cannot even formulate a meaningful question to send upstream to your supplier. So when a customer audit asks you to demonstrate external traceability, what is genuinely being assessed is the maturity of your internal traceability.
For the broader picture — process design through to sustained operation — our traceability implementation guide covers the full rollout sequence. This article narrows in on one situation, the customer audit.
The six record categories checked in an IATF 16949 audit
If you supply automotive parts, IATF 16949 is the standard underneath most customer audits. It builds on ISO 9001 and adds automotive-specific requirements, coming to roughly 280 requirements in total — about twice the volume of ISO 9001. The added portion puts weight on product safety, risk management, and traceability.
The records examined in an audit sort into six broad categories.
| # | Record category | What is actually inspected |
|---|---|---|
| 1 | QMS documents | Policies, procedures, work instructions, and form templates |
| 2 | Execution records | The evidence actually left on those forms |
| 3 | Audit records | Internal, process, and product audits, plus effectiveness of corrective action |
| 4 | Nonconformity and corrective action | Nonconformity records, corrective actions, and change control |
| 5 | Customer satisfaction | How satisfaction is captured and fed back |
| 6 | Process validation | FMEA and PPAP |
What stands out is that categories 1 and 2 are a pair. Having a procedure and having evidence that the procedure was followed are two different claims, and the auditor checks both. Categories 3 and 4 pair up the same way — finding a nonconformity matters less than being able to show the corrective action was effective.
The “30 seconds” benchmark
Beyond whether records exist, audits weigh how quickly they appear. A practical rule of thumb used in the field is that a record should be retrievable in about 30 seconds.
That number is not a call to hold a sprint relay with paperwork. Being able to produce a record in 30 seconds means three things are true at once: the location of records is systematically organized, an index exists that resolves uniquely from a product or a date, and someone other than the original owner can operate it. Put another way, a plant that needs 30 minutes to find a record most likely has its index stored in one person’s memory. That is exactly what the auditor is probing.
One more point on going digital. Where records are held electronically, they are expected to carry timestamps and to have tamper-prevention in place. An Excel file dropped into a shared folder does not meet that bar, because there is no way to establish who changed what and when. Confirm these two properties first, before evaluating anything else about a system.

The illustration above shows where the three practices covered in the next section — identification, segregation, and response time — sit on the physical flow of material through the plant. From here, we look at what IATF 16949 specifically requires on traceability.
What IATF 16949 clause 8.5.2.1 requires
Which products the clause covers
Clause 8.5.2.1, “Identification and traceability — supplemental,” requires a traceability system to be established. The products it explicitly names are those accepted by the customer and those that may contain nonconformities affecting quality or safety in the field. For such products, the requirement is that the start point and stop point can be clearly identified.
Identifying the start and stop point means being able to state which lot the problem began with and which lot it ended with. A plant that cannot do this has no choice but to draw the suspect boundary wide. In practice, this is the usual reason scope balloons in a recall or a concession. Our article on recall traceability and mock recalls covers scope design, acceptance criteria, and what to put in an RFP.
The five elements in practical terms
Translated into shop-floor language, the requirements of 8.5.2.1 come down to five elements.
| Element | What is required | What the auditor looks at |
|---|---|---|
| a) | Rigorous identification of conforming product, nonconforming product, and inspection status | Can anyone tell from the tag or travel card whether a part has been judged or not? |
| b) | Segregation that keeps nonconforming and conforming product from mixing | Is the quarantine area physically separated, locked or partitioned so material cannot drift back? |
| c) d) | Verification that you can meet the response time stated in the customer’s SQM (supplier quality manual), with the verification recorded | Do you know each customer’s response-time requirement, and do you have evidence you actually tested it? |
| e) | Serial number control, mandatory where the customer or a regulatory authority explicitly requires it | Did you confirm whether such a requirement exists before choosing unit-level or lot-level control? |
Element a), identification, is the most basic of the five and also one of the most frequently cited. A pallet of parts awaiting judgment sitting unlabeled beside a pallet of accepted parts undermines the credibility of every record you produce afterwards.
Element b), segregation, is the physical means that makes a) stick. Simply designating a nonconforming-material area is not enough; the auditor looks at whether the operating flow makes it impossible to pull material back out. If someone could set a part down temporarily and a different operator could return it to the line the next morning, the material is not segregated.
How to read the “24 hours” response time
Elements c) and d) attract more misunderstanding than any other part of the clause, so it is worth being precise. IATF 16949 does not impose a blanket 24-hour figure. Response time is a requirement stated in the customer’s SQM (supplier quality manual), and 24 hours is one example of what an SQM may state. The duration differs by customer, and some customers do not specify one at all.
That leaves the plant with three concrete jobs.
- Review the SQM for each customer and establish whether a response-time requirement is stated
- Where one is stated, actually verify that you can present the affected lot range and the supporting records within that window
- Retain the record of that verification so it can be shown during an audit
The third item is the one most often missing. A verbal assurance that “we could do it if we had to” is not what is being asked for. What is required is a document showing that you ran the exercise and how long it took. The practical method is to run a mock exercise on one lot, assemble the full record set, time it, and file the result.
Choosing between serial control and lot control
Element e) has direct capital-expenditure consequences. Serial number control — assigning a unique number to every individual unit — is mandatory where the customer or a regulatory authority explicitly requires it. The corollary is that where no such explicit requirement exists, lot control is sufficient.
Plants sometimes reason that “if we are serious about traceability, we should go all the way to unit-level control on single-piece flow,” and start scoping a large investment before checking what is actually required. Widening the scope without confirming the requirement level drives cost into marking equipment, readers, and the data volume that follows. Read the customer requirement documents first and separate out which product families carry an explicit serial requirement. Then build it in stages — unit-level control only for those families, lot control everywhere else. Our article on automotive parts traceability and IATF 16949 works through how to scope this in more detail.
How to build a system that produces records in 30 seconds
It starts with choosing a common key
Designing for fast retrieval does not begin with selecting a system. It begins with deciding what single key will run through every record. In most plants, the manufacturing lot number takes that role.
Once the key is fixed, inventory every record you currently create and check whether each one carries that key. Some will not — that is guaranteed. Equipment check sheets carry only a date and a machine number. Incoming inspection records are filed against the delivery note number. Deciding how to attach these keyless records to the key is the actual substance of internal traceability design.
There are three ways to make the link. The first is to add a lot number field to the record itself. The second is to link indirectly through time and equipment — if the production record says “this lot ran on machine 3 between 10:00 and 11:00 on June 12,” you can join it to machine 3’s equipment data for that window. The third is to link through material issue records back to the incoming lot. Forcing every record into the first method piles writing work onto operators, so combining the second and third is the more workable approach.
Where to start digitizing quality records
Attempting to digitize every quality record simultaneously is the most common way these projects stall. Converting existing paper and spreadsheet records is regarded as one of the most time-consuming activities in the early stage of an IATF 16949 rollout — not only because of volume, but because digitizing forces you to redesign both the form layout and the operating rules behind it.
Sequence the work by how often a record is asked for in audits and how much linking value it unlocks. In concrete terms, three records come first: production records (when, on which equipment, which lot, by whom), inspection records (judgment and measured values), and material issue records. Once those three are digital and joinable on the lot number, the combination asked for most often in audits — the manufacturing conditions, the inspection results, and the materials used for this lot — becomes something you can put on screen immediately.
Equipment check sheets and training records can wait for the next phase. That is not a statement about their importance; it means they rank lower on the specific axis of lot-level responsiveness.

The illustration above shows digitized records joined on the lot number, with manufacturing conditions, inspection results, and material lots all reachable from a single screen. What an audit needs is exactly this — one entry point.
Making defect root cause identification faster
Once records are connected, the benefit extends well past audit day into everyday defect investigation. Research published in 2026 finds that connected record systems help accelerate defect investigation, narrow recall scope, and demonstrate control during customer and regulatory audits. The reasoning is that pulling production events, material movements, quality inspections, operator actions, and equipment data into one digital record supports faster investigation, more precise recalls, and greater confidence in compliance.
The accurate way to frame this is not that you need to buy a separate defect root cause identification system. It is that if your internal traceability is joined up, the data required for root cause work is already assembled. You compare lots that produced defects against lots that did not, across molding conditions, material lots, operators, and equipment state. Whether that comparison is a manual cross-referencing exercise or a data filtering exercise is what determines how many days root cause identification takes.
Meeting the requirements for electronic records
As noted earlier, electronic records are expected to carry timestamps and tamper-prevention. Four implementation points follow from that.
- Creation date, time, and author are applied automatically by the system rather than entered by hand
- When a value is corrected, the prior value, the person who changed it, and the reason are retained as history
- Records cannot be deleted, or deletion is itself retained as history
- Permissions define who may enter, approve, and view each record
When you show electronic records during an audit, being able to explain these four points before showing the content itself shortens the exchange considerably. The practical move is to prepare a single-page summary of the permission model and the audit-trail function, and walk through it before opening the application.
The flow on the day of a customer audit
What to do before the day
The quality of your answers on the day is largely settled in advance. Between receiving notice of the audit and the day itself, do the following.
First, if the audit scope — part numbers, period, processes — has been shared in advance, select several lots inside that scope yourself and actually assemble the full record set. This dry run tells you which records are hard to surface. Where you find one, document its location before the day.
Second, decide who explains. Separating the person operating the system from the person explaining the content prevents the situation where the explanation stops because the presenter is absorbed in navigating a screen. In a Thai plant, also settle the split between the local staff operating the system and the Japanese expatriate explaining in Japanese.
Third, put the previous audit’s findings and their corrective status onto a single sheet. Verification of prior findings is close to guaranteed to come up.
Principles for the day
A few habits keep the day moving.
| Situation | Preferred response | Response to avoid |
|---|---|---|
| A record is requested | State where it is and open it on the spot | Repeating “we will bring it later” |
| A record cannot be found | State plainly that it cannot be found and when you will present it | Continuing to search and burning time |
| Practice differs from the procedure | Acknowledge the gap, explain the reality and your corrective thinking | Insisting the procedure was followed |
| The intent of a question is unclear | Ask what is being verified before answering | Guessing and answering broadly |
| A nonconformity is raised | Confirm the facts and agree a corrective deadline | Declaring the root cause on the spot |
The fourth row deserves the most attention. Every auditor question sits on top of a requirement they are trying to verify. Answering broadly without establishing that intent means presenting records nobody asked for, and new findings tend to emerge from exactly those records.
A morning checklist
Running a short checklist on the morning of the audit reduces gaps.
- For lots in scope, can production records, inspection records, and material lots be called up immediately?
- Can the previous audit’s findings and corrective completion status be explained from a single sheet?
- Is the nonconforming material area in a state you would be comfortable having inspected right now?
- Do tags and travel cards clearly distinguish judged from unjudged material?
- Can you explain the permission model and correction history function of the electronic records while showing them on screen?
- Are the response-time verification records filed somewhere they can be produced for each customer?
- Are the explanation and operation roles assigned, and is interpreting support arranged?

The photograph above shows an example of a meeting space prepared for audit day. Keeping physical product and the terminal used to call up records in the same room lets you explain by comparing the part in front of you against the record on the screen.
What is different for Japanese-owned plants in Thailand and ASEAN
The number of sites, and who sits on the receiving end of audits
There are reported to be 6,083 Japanese companies registered in Thailand, based on registration data such as that of the Department of Business Development under Thailand’s Ministry of Commerce. That figure covers far more than vehicle manufacturers and large set makers — it includes the wide base of parts suppliers beneath them. In other words, most Japanese-owned plants in Thailand are on the receiving end of audits rather than conducting them.
An audit from the Japanese parent company. A second-party audit from a Thai customer. The IATF 16949 audit from the certification body. And for food or electronic components, further audits against other standards on top. A single plant is asked to present records several times a year, by different parties. Assembling records ad hoc each time becomes a heavier and heavier tax as the frequency rises.
Multilingual floors erode the meaning of records
A typical Thai plant runs in three languages — operators in Thai, managers in English and Thai, expatriates in Japanese. Some plants add workers from Myanmar or Cambodia. Running paper forms in that environment lets the meaning of each field drift a little at every language boundary.
A field labeled “record any abnormality,” for instance, gets used without a shared definition of what counts as abnormal, and ends up almost always blank. Then the auditor asks whether there has genuinely never been an abnormality, and there is no comfortable answer.
Digitization pushes against that drift. Replace free text with selection lists. Increase the number of items recorded automatically when a threshold is crossed. Allow the display language to switch to the operator’s first language. Each of these reduces the portion of the record that depends on the writer’s interpretation.
Expatriate rotation removes the person who can explain
A situation particular to Japanese-owned plants is that expatriate managers rotate every few years. Where audit experience and knowledge of where records live have accumulated in one individual, capability drops at every handover. It is not unusual for a newly arrived expatriate to face an audit without being able to explain the intent behind the practices their predecessor put in place.
The countermeasure for that key-person risk is nothing exotic. Systematize where records live so that anyone following the same steps arrives at the same record. The “30 seconds” condition described earlier is a statement about audit response speed, but it is equally a statement about whether the capability survives a change of personnel.
External traceability with local suppliers
As local sourcing expands in Thailand, the record maturity of upstream suppliers varies more widely. Japanese-owned suppliers often use record formats close to your own, while local suppliers may define incoming lots differently or retain records in a different form altogether.
If your internal traceability holds, you can at minimum state with confidence which incoming lot became which product — which means you can pinpoint who to ask upstream, and in what unit. Improving external traceability is easier to sequence if you firm up your own linkage before issuing requirements to your suppliers.
Frequently asked questions
What is traceability?
It is the condition in which records let you follow when a product was made, where, from which materials, under which conditions, and where it went. It covers both directions — tracking downstream from raw material to the shipping destination, and tracing upstream from a field problem back to manufacturing conditions and raw materials. Customer audits probe both, so building only one direction is not sufficient.
What is the difference between internal and external traceability?
Internal traceability covers tracking and tracing within your own processes, from material arriving at your plant to finished goods shipping out. External traceability covers the links across company boundaries, supplier to you and you to customer. Because external traceability only functions when each company’s internal traceability holds, internal comes first in sequence.
Where should we start when digitizing quality records?
Start with three records — production records, inspection records, and material issue records. Once those three can be joined on the lot number, the combination most frequently asked for in audits, namely the manufacturing conditions, inspection results, and materials used for a given lot, can be presented immediately. Equipment check sheets and training records can follow in the next phase. Note that electronic records are expected to carry timestamps and tamper-prevention, so an Excel file in a shared folder does not satisfy the requirement.
Do customer audits always require a response within 24 hours?
IATF 16949 does not impose a blanket 24-hour figure. Response time is a requirement stated in the customer’s SQM (supplier quality manual), and 24 hours is one example of what an SQM may state. What is asked of the plant is to check the response-time requirement in each customer’s SQM, verify that it can respond within that window, and retain the record of that verification. Both the duration and whether a requirement exists at all vary by customer.
Is serial number control mandatory?
It is mandatory where the customer or a regulatory authority explicitly requires it. Where no explicit requirement exists, lot control is sufficient. Moving to unit-level control without confirming whether the requirement exists front-loads cost into marking equipment, readers, and increased data volume. Check the customer requirement documents first and separate out the product families that genuinely need serial control.
Do we need a dedicated system to speed up defect root cause identification?
Before evaluating a dedicated system, check whether your records are joined. Comparing lots that produced defects against lots that did not — across manufacturing conditions, material lots, operators, and equipment state — can be executed as a data filtering task once internal traceability is connected. Installing an analytics tool while the underlying records remain unjoined leaves the manual cross-referencing work exactly where it was.
Summary
Records fail to appear during customer audits not because they were never taken, but because they were never joined around the product. As long as records are filed by department and by document type, the audit turns into a live manual cross-referencing exercise.
The records examined in an IATF 16949 audit sort into six categories — QMS documents, execution records, audit records, nonconformity and corrective action, customer satisfaction, and process validation. Auditors weigh not only whether records exist but how quickly they appear, and a practical rule of thumb in the field is retrieval within about 30 seconds. Where records are electronic, timestamps and tamper-prevention are the baseline requirements.
Clause 8.5.2.1 requires a traceability system in which the start and stop points can be identified. Its elements are rigorous identification, segregation of nonconforming product, verification and record retention regarding the response time stated in the customer’s SQM, and serial number control where explicitly required. Note again that the 24-hour figure is one example of what an SQM may state, not a number the standard imposes uniformly.
Building the mechanism starts with choosing the common key that runs through every record. Once production records, inspection records, and material issue records can be joined on the lot number, the combination audits ask for most often is available from a single entry point. Connected records also help accelerate defect investigation, narrow recall scope, and demonstrate control during audits. In Japanese-owned plants in Thailand, multilingual floors and expatriate rotation add further pressure, so systematizing where records live and reducing key-person dependency feeds directly into the continuity of your audit response.
Which of your existing records are already joined on the lot number, and where does the chain break? That diagnosis can usually be sketched out quickly from a look at your current forms and how they are stored. At TOMAS TECH we start by working backwards from what audits actually ask for, mapping which records deliver the most visible benefit when digitized first. If you are still at the stage of weighing up customer audit readiness or the digitization of quality records, we are happy to talk it through — our contact page is the easiest way to reach us.