Blog

2026.09.02

Quality Assurance System: RFP and Acceptance Guide

Quality Assurance System: RFP and Acceptance Guide

Quality Assurance System: RFP and Acceptance Guide

When a customer or certification audit is approaching, does your team still reconstruct evidence from paper inspection sheets, spreadsheets, machine logs, and email approvals? A quality assurance system should do more than replace paper with PDFs. It should let authorized users reconstruct which material, equipment condition, operator, inspection, specification revision, exception, and approval applied to a particular lot or serial number—without losing the history of who changed what and why.

This guide is for manufacturing sites in Thailand and ASEAN that want to digitize quality records and trace manufacturing history. It translates the objective into an RFP, FAT/SAT acceptance tests, an audit evidence pack, and a practical 90-day rollout. It is deliberately written for a Do/Buy decision, not as another general introduction to ISO 9001.

Important: retrieval times, recovery objectives, clock tolerances, review frequency, and sample sizes in this article are recommended design values, not universal requirements of ISO, IATF, FDA, or NIST. Set the final values from customer-specific requirements, law, contracts, product risk, data classification, and a business-impact analysis.

A quality assurance system is not a document warehouse

Plants with slow audit responses do not necessarily lack records. Often, they have many records whose relationships have been lost. Incoming inspection is in Excel, process parameters sit in a machine PC, in-process inspection is on paper, deviations are approved by email, and nonconformance is in another application. When an auditor asks for the material lots, machine settings, inspection results, change approval, and disposition behind one shipment, people manually rebuild the chain.

The target operating model needs five capabilities working together:

  1. An identity model connecting product, lot, serial, material, equipment, person, inspection, and change.
  2. Provenance showing source, timestamp, revision, approval, and later correction.
  3. Exception management for missing, duplicate, delayed, out-of-order, or inconsistent records.
  4. Role-based rights to view, enter, approve, correct, administer, and export information.
  5. Search and controlled output that turn an audit question into a reproducible evidence package.

ISO describes ISO 9001 as a quality-management-system framework, and certification is voluntary. ISO/TC 176 guidance on documented information also explains that organizations have flexibility in deciding the documented information and media appropriate to their context. ISO does not require a named cloud product or a universal pack of electronic forms. Software supports the process and its evidence; it does not replace process ownership, competence, risk treatment, or improvement.

ISO 9000:2026 distinguishes concepts such as objective evidence, records, and audit evidence. Without reproducing the standard’s copyrighted wording, this article treats objective evidence as verifiable information supporting a fact, a record as information showing an activity performed or a result achieved, and audit evidence as relevant information that can be evaluated against audit criteria. Consult the official standard for normative terminology.

Design the data model backward from audit questions

Starting with feature checklists tends to make the selection about screens and reports. Start instead with the questions the system must answer:

  • Which material and component lots went into shipment lot A?
  • Where are their incoming inspections and supplier certificates?
  • Which machine, fixture, program revision, and parameter set were used?
  • Was the operator’s qualification valid at the time of production?
  • Which work instruction, drawing, and inspection-specification revisions applied?
  • If a deviation occurred, who assessed it, what evidence supported the decision, and who approved it?
  • Which units were affected by a 4M change?
  • If a value was corrected later, can we see the original value, reason, author, time, and approval?

Typical linking keys include product serial number or manufacturing lot, material lot, process and equipment, event time, specification revision, and the person or system acting. The challenge is not finding one perfect primary key. It is maintaining mappings across ERP production orders, MES lot IDs, machine work IDs, inspection filenames, and customer part numbers—and retaining the history of those mappings.

Quality Assurance System: RFP and Acceptance Guide - figure 1

Put forward and backward traceability in one model

Customer audit traceability needs both backward tracing from finished goods to inputs and forward tracing from a suspect material lot to work in process, finished goods, and shipments. Separate spreadsheets make splits, merges, re-entry, rework, and partial consumption easy to lose.

A useful event model records input objects, the process performed, output objects, time, location, actor, applicable specification, result, and linked evidence. Lot splits and merges should be appended as events instead of overwriting ancestry. Scrap, hold, reinspection, concession, and rework belong in the same genealogy. For a deeper treatment, see our guide to a forward and backward traceability system.

Audit trail and manufacturing genealogy are not synonyms

An audit trail shows who created, changed, approved, or cancelled an electronic record and when. Manufacturing genealogy shows the history and relationships among products, materials, operations, equipment, and inspections. They reinforce one another but solve different questions.

If a process value is corrected from 180 to 185, the audit trail should show both values, the reason, actor, time, and approval. The genealogy should show which lots or serial numbers used that value. Either alone leaves a gap between record trustworthiness and product impact.

Inventory evidence flows before digitizing forms

Do not begin by counting every paper form. Follow evidence from its creation and approval through storage, retrieval, disclosure, retention, and disposal.

Inventory itemWhat to establishRisk if omitted
PurposeWhich decision, obligation, or product risk the record supportsHigh storage volume but missing critical evidence
SourcePerson, machine, gauge, ERP, MES, or supplier documentUnclear responsibility for transcription and verification
Identity keysPart, order, lot, serial, machine, and timeInability to join the same object across systems
RevisionDrawing, instruction, inspection plan, and program versionInability to prove the criteria valid at the time
ApprovalCreation, review, approval, concession, and change authoritySelf-approval or uncontrolled delegation
RetentionLegal, customer, contractual, and internal basis by record classUnder-retention or indiscriminate over-retention
RetrievalWho may retrieve, with which filters, and in which formatDisclosure of personal, confidential, or other-customer data
ExceptionsMissing, duplicate, late, offline, resent, and corrected dataAn evidence chain that works only in ideal conditions

The output should be an “audit question–evidence–source–key–owner–retention basis–submission format” matrix, not merely a form register. Record the present retrieval time and manual steps; these become the baseline for acceptance.

RFP requirements for electronic quality records

Avoid phrases such as “supports traceability” or “audit ready.” Define the object, input, expected outcome, abnormal condition, verification, and required evidence.

IDRequirementMinimum conditionSupplier response requiredAcceptance evidence
R01Identity and genealogyPreserve split, merge, re-entry, and rework without overwriting historyData model, limits, and configurationQuery output for supplied scenarios
R02Record ingestionIdentify source for manual, CSV, API, and machine dataProtocols, retries, and deduplicationDisconnect/reconnect logs
R03Data completenessDetect missing keys, invalid formats, range breaches, and reversed timestampsRule management and exception queueResults from injected bad data
R04Revision controlReconstruct the specification effective at event timeEffective dating, approval, obsolescenceHistorical-lot query
R05Audit trailRetain actor, time, reason, and before/after valuesAppend behavior, tamper controls, accessCorrection scenario output
R06AuthorizationEnforce least privilege and separation of dutiesRole model, identity integration, reviewsPermission matrix and negative tests
R07SearchTrace product-to-material and material-to-shipmentFilters, performance conditions, limitsTimed results for ten representative questions
R08Evidence packExport scope, filters, version, author, and generation timePDF/CSV/API, masking, signaturesComplete sample and reproduction steps
R09RetentionPer-class retention, hold, disposal approval, and evidenceConfiguration units and backup behaviorRetention-and-hold test
R10ResilienceContinue records, recover, and reconcile after failureOffline process, RTO/RPO, disaster recoveryRestore exercise report
R11SecurityEncryption, secrets, vulnerability handling, and monitoringShared-responsibility model and notification targetsDesign, configuration, and test records
R12Language and timeThai/English input, UTC/local display, and character supportStorage and search behaviorMultilingual and time-boundary tests
R13MigrationRecord source, transformation, reconciliation, rejects, and rerunsMigration and rollback planCounts, hashes, and exception log
R14OperabilityLocal staff can manage master data, alerts, backup, and monitoringAdmin tools, training, and proceduresOperations rehearsal
R15ExitExport data, attachments, relationships, and history in readable formContract-end format, time, and costDemonstrated bulk export

Require suppliers to distinguish standard features, configuration, custom development, and unsupported requirements. Each answer should state assumptions, limitations, a screen or API reference, and how it will be tested. Run demos with your scenarios and imperfect data, not only the supplier’s polished sample.

Turn “fast retrieval” into an acceptance value

“Search must be fast” cannot be accepted objectively. A stronger starting statement is: “For ten project-defined trace queries, the components of the audit evidence pack shall be retrievable within three minutes at the 95th percentile.” That is a recommended design value, not a standard requirement. State the data volume, concurrent users, network, and query boundaries, then adjust it to the business risk.

The same applies to a ±1-minute clock difference among participating systems, an interface alert within five minutes, a pilot RTO of four hours and RPO of 15 minutes, and quarterly permission review. These are recommended design values to negotiate, not compliance claims.

Architecture: connect the evidence chain without stopping the plant

The solution need not be one monolith. ERP, MES, QMS, machines, inspection equipment, document control, identity services, and a data platform can share responsibility:

  1. Source layer: PLCs, sensors, inspection systems, terminals, and supplier evidence retain source value, unit, and quality state.
  2. Collection layer: gateways handle protocols, buffering, retries, deduplication, time normalization, and mappings.
  3. Business-context layer: orders, items, BOMs, routes, lots, serials, specifications, and approvals are linked.
  4. Evidence layer: records, attachments, audit trails, retention, integrity controls, and backup are managed.
  5. Use layer: search, genealogy, evidence packs, dashboards, and exception queues serve defined roles.

Do not assume direct machine-to-cloud connectivity. IT and OT should define zones, approved conduits, gateways, buffering, monitoring, and change control. NIST recommendations on manufacturing-data traceability and trustworthiness provide useful lifecycle concepts around provenance and integrity. NIST SP 800-171 Rev. 3 may be relevant when contracts require protection of controlled unclassified information in nonfederal systems; it is not automatically applicable to every factory.

Time, units, and master data become audit issues

If one machine uses local time, another UTC, and a gauge has a manually set clock, events may appear out of order. Store or distinguish event time, receipt time, processing time, and time zone. Monitor clock status. A cross-system difference within ±1 minute is a recommended design value and must reflect process speed and risk.

Retain both original and converted values and identify the conversion-rule revision. Effective dating and approval are needed for part, machine, process, and defect-code masters. A master-data error can attach thousands of correct measurements to the wrong context, so master changes are quality changes, not merely IT administration.

Roles and responsibilities

The process owner determines what evidence means. Quality should not become the sole owner of every digital record.

RoleCore responsibilityDecision or approval
Executive sponsorScope, priority, resources, cross-functional escalationPolicy and acceptance of major residual risk
Quality ownerAudit questions, evidence, retention basis, disclosure rulesEvidence pack and quality acceptance
Manufacturing process ownerShop-floor events, standard work, exceptionsValidity of process operation and change
Production engineering/OTMachine tags, connection, clock, buffer, changeEquipment-side FAT/SAT
IT/securityIdentity, network, monitoring, backup, recoverySecurity and operational handover
Data ownerKeys, masters, data rules, permitted useDefinitions and exception disposition
Internal auditIndependent check of evidence and operational effectivenessAudit findings, not self-approval of operation
Supplier/integratorDesign, configuration, tests, training, correctionContract deliverables and test evidence
Site key userDaily exception handling, first-line support, improvementShop-floor acceptance and feedback

Test negative separation-of-duty cases: an operator cannot finally approve the operator’s own deviation, an administrator cannot erase the audit trail, and a supplier support account is not permanently active. Emergency and delegated access should have purpose, expiry, approval, and after-the-fact review.

Quality Assurance System: RFP and Acceptance Guide - figure 2

Build the audit evidence pack before the audit

Standardize evidence packages for representative audit questions rather than creating a new folder every time. A package should include:

  • Cover: product or lot, filters, generation time, generator, and system version.
  • Genealogy: material, process, inspection, finished product, and shipment relationships.
  • Specifications: applicable drawings, instructions, inspection plans, and program revisions.
  • Execution: critical parameters, results, equipment, fixture, and qualification state at the time.
  • Exceptions: nonconformance, deviation, hold, reinspection, rework, concession, and approval.
  • Changes: relevant 4M change, effective boundary, impact assessment, and verification.
  • Record history: correction and approval audit trail.
  • Completeness statement: missing data, exclusions, exceptions, and extraction limitations.

The goal is not maximum disclosure. Templates and authorization should prevent unnecessary disclosure of personal information, another customer’s data, or machine intellectual property. An exported PDF should identify the filters and source-record IDs so the package is reproducible.

For rehearsals, have internal audit select an unannounced lot and question. “Ten representative questions with P95 retrieval within three minutes” is a recommended design value. Score completeness, revision correctness, authorized scope, and explainability as well as speed.

Link 4M approval to the actual change boundary, first-piece confirmation, enhanced inspection, training, machine conditions, and any customer approval. Our 4M change management system guide explains this connection in more detail.

FAT and SAT acceptance tests

FAT normally verifies agreed design, configuration, and functions in the supplier environment. SAT verifies the end-to-end purpose in the real factory, network, machines, users, data, and operating conditions. Contract terminology varies; make the test objective and environment explicit.

FAT scenarios

TestScenarioExample acceptance criterionEvidence
GenealogySplit, merge, re-entry, and reworkRelationships and states match the approved modelInput, UI capture, API output
CorrectionCorrect a value with reason and approvalOriginal/new values, reason, actor, and time remainAudit trail export
AuthorizationAttempt unauthorized view, approval, and exportAttempt is denied and loggedNegative-test log
InterfaceDuplicate, missing, unordered, disconnected, and resent messagesNo silent duplication; exceptions visibleMessage IDs and queue
RevisionProduce before and after an effective-date boundaryEach event links to the then-effective revisionRevision history and query
RetentionSimulate expiry, hold, and approved disposalOnly eligible records are processed, with evidenceJob and approval logs
ExitSimulate contract terminationData and relationships export in reusable formFiles, schema, count reconciliation

SAT scenarios

Include site realities: machine clock drift, network interruption, barcode failure, shift handover, Thai names, inconsistent legacy masters, and offline procedures. Testing one normal peak shift plus backlog recovery is a recommended design value.

For the audit pack, use a production-like test lot and combine backward/forward tracing, effective revision, exceptions, and corrections. A 100% presence rate for project-defined mandatory keys is a recommended design value; it proves presence, not truth. Reconcile sampled values with machine sources, temporary paper controls, and ERP quantities.

Classify defects by effect on evidence and product decisions, not raw count. Wrong-lot linkage, unauthorized history modification, undetected loss, and failed restoration are critical examples. A usability problem is also serious when it drives operators to create shadow records. Conditional acceptance needs a temporary control, owner, deadline, retest, and decision if unresolved.

A 90-day implementation roadmap

Do not promise to replace every record in every plant in 90 days. Prove one end-to-end slice in production-like operation. One product family, one line, and one audit evidence pack is a recommended design value.

Days 0–15: fix purpose and boundary

  • Select customer, product family, operations, equipment, records, and questions.
  • Identify customer-specific, legal, contractual, and internal retention obligations.
  • Demonstrate current retrieval and record time, missing links, transcription, and personal workarounds.
  • Agree identity keys, system boundaries, owners, success criteria, exclusions, and change control.

Days 16–35: specify and prototype

  • Anonymize representative data and prototype forward/backward tracing.
  • Create scenarios for exceptions, correction, revision, rights, retention, and output.
  • Give the same scenarios to Do and Buy candidates.
  • Agree interfaces and shared responsibility.
  • Draft FAT/SAT protocols and evidence templates before building.

Days 36–65: build, integrate, and migrate

  • Configure identities, roles, masters, and quality rules.
  • Add machine, ERP, MES, and inspection connections incrementally.
  • Implement buffering, retry, deduplication, exception queues, and monitoring.
  • Record migration counts, hashes, rejects, and reruns.
  • Prepare procedures, training, backup, and temporary offline records.

Days 66–90: test, parallel-check, and rehearse

  • Correct FAT defects and run SAT under site conditions.
  • Reconcile the new record with the current source for a defined period.
  • Let internal audit conduct unannounced retrieval.
  • Exercise restore, permission review, and offline recovery.
  • Decide residual issues, temporary controls, and expansion gates.

The day-90 outcome is not “software installed.” It is an approved evidence chain that answers defined audit questions under real operating conditions.

Quality Assurance System: RFP and Acceptance Guide - figure 3

Do/Buy decision criteria

Do and Buy are not binary. Standard controls such as identity, audit logging, retention, and backup can come from a product, while process-specific equipment integration and logic are configured or developed.

Buy tends to fit when standard document, training, nonconformance, CAPA, audit, and approval processes dominate; multiple sites need common updates; and the company wants ongoing support for shared controls. Do or strong customization tends to fit when equipment genealogy is a differentiator, standard models cannot represent splits/merges or continuous materials, network and data-location constraints are unusual, and the company can sustain product ownership, OT/IT, testing, security, and maintenance.

Compare lifecycle workload, not only license and initial development: upgrades, master data, connection changes, validation, training, audit support, migration, monitoring, and exit. Measure your current work instead of accepting unsupported percentage savings.

Ask every supplier:

  1. Who—including administrators—can view, alter, delete, or export audit trails?
  2. How are corrections, cancellations, re-approvals, and delegation recorded?
  3. How are disconnects, duplicates, delays, ordering, and clock drift detected and recovered?
  4. Can the standard model represent splits, merges, rework, and re-entry?
  5. What changes to data, APIs, reports, and trails occur during upgrades?
  6. How are attachments, relations, masters, and history returned at contract end?
  7. Who investigates and supplies evidence for incidents and vulnerabilities?
  8. Which local support hours, languages, and escalation routes are available in Thailand?
  9. Who reproduces, corrects, and retests FAT/SAT defects?
  10. What compensating control and residual risk remain for each unmet requirement?

Governance, security, retention, and backup

Do not set one retention value for everything. Link each record class to law, customer requirements, contracts, product life, warranty, legal hold, and internal policy. Retaining the related audit trail at least as long as the record is an initial recommended design value, unless a governing obligation requires more.

Test restoration, not merely backup creation. A four-hour RTO and 15-minute RPO for the pilot are recommended design values to be adjusted through business-impact analysis. After recovery, reconcile offline and system records and approve duplicates or gaps as exceptions.

Update access on joining, transfer, and termination. Quarterly review is a recommended design value. Avoid shared accounts; time-limit supplier access and require approval, multi-factor authentication, and activity logging.

FDA Part 11 is a primary source for electronic-record and electronic-signature controls in FDA-regulated contexts. It does not automatically apply to every record in general manufacturing. Confirm the relevant predicate rules and use of the record. If you voluntarily adopt its ideas outside scope, document the difference between a legal requirement and an internal control.

Handling 2026 IATF information correctly

Automotive suppliers should monitor official IATF communiqués, sanctioned interpretations, and FAQs. The July 2026 Stakeholder Communiqué SC-2026-005 says work on IATF 16949 Revision 2 centers on five priority themes and that publication was planned for mid-2027. That is a plan that may change; the second edition was not published at the time of writing.

Do not write an unpublished edition into the RFP as a fixed requirement. Require configurable controls, revision impact assessment, retesting, training, and contractual update responsibility. SC-2026-004 also demonstrates that sanctioned interpretations and FAQs are official update channels for Rules 6th Edition and IATF 16949 topics. Check the latest official publication before a decision.

FAQ: audit records and manufacturing traceability

What is a quality assurance system?

It is the controlled combination of quality processes, records, manufacturing genealogy, permissions, change history, search, and disclosure. It may include QMS, ERP, MES, machines, inspection systems, document control, and identity services. The decisive factor is the evidence relationship and ownership, not the product label.

Can paper be retired as soon as records are digitized?

Not automatically. The transition depends on customer, legal, and contractual requirements, electronic-record trustworthiness, offline continuity, migration reconciliation, and acceptance results. A scanned PDF may not provide structured search, effective revision, approval, correction history, or product linkage. Time-limit parallel entry and define its reconciliation purpose.

How quickly must customer-audit traceability be shown?

There is no universal time. Ten representative queries with P95 retrieval within three minutes is this article’s recommended design value. Adjust it and assess completeness, revision, and authorized disclosure along with speed.

Which quality records should be digitized first?

Prioritize by audit frequency, product risk, retrieval effort, missing-link risk, and connectivity to other evidence. Incoming material, critical process parameters, revisions, nonconformance/concessions, and 4M changes are common candidates. One product family, one line, and one pack is a practical recommended design value for a 90-day scope.

Should every machine signal be stored?

No. Define the values and granularity needed for product decisions, investigation, obligations, and process performance. For high-frequency data, distinguish raw, summarized, and event data and retain processing provenance. Indiscriminate retention increases cost, search burden, and security exposure.

Is a particular system required for ISO 9001 certification?

No. Certification is voluntary, and ISO does not prescribe a vendor. The organization determines suitable documented information and controls. Software supports execution and evidence but cannot replace accountability and improvement.

Is FDA Part 11 compliance sufficient for any manufacturing audit?

No. Applicability depends on FDA-regulated electronic records, electronic signatures, and associated predicate rules. Confirm industry and contract requirements first. Distinguish legal applicability from voluntarily adopted internal controls.

Is cloud or on-premises better for audits?

Deployment location alone does not decide. Compare identity, rights, change, audit trail, backup, restoration, outage continuity, data location, supplier management, and exit export with relationships intact.

How should RFP costs be compared?

Use the same period and assumptions for licenses, integration, data cleanup, migration, acceptance, training, operations, monitoring, upgrades, new sites, audit support, and exit. Validate proposed benefits against your measured baseline rather than unsupported ROI percentages.

Conclusion: make answerable audit questions the acceptance criterion

A quality assurance system is not primarily a paper-reduction project. It reconstructs a trustworthy relationship between product history and evidence. Design from audit questions, specify forward/backward genealogy, audit trails, revisions, exceptions, access, retention, and recovery, and make the evidence pack an acceptance deliverable. FAT should test functions and abnormal paths; SAT should prove the chain with real users, machines, and site conditions.

ISO 9001 certification is voluntary, ISO 10013 is guidance on documented information, IATF 16949 Revision 2 was still unpublished in September 2026, and mid-2027 was a changeable plan. FDA and NIST publications must also be used within their scope. Values such as three-minute retrieval, ±1-minute clock tolerance, four-hour RTO, 15-minute RPO, and a 90-day pilot are recommended design values, not standards.

TOMAS TECH can help structure the audit questions, identity model, RFP, and FAT/SAT boundary around your current forms, machines, ERP, and MES. If you are still defining the scope for quality-record digitization or customer-audit traceability in Thailand, you can contact us for an initial discussion with the target product, process, and the audit question that is hardest to answer today.

References

  1. ISO, ISO 9001 explained
  2. ISO/TC 176, Guidance on the requirements for Documented Information of ISO 9001:2015
  3. ISO Online Browsing Platform, ISO 9000:2026
  4. ISO, ISO 10013:2021
  5. IATF, Stakeholder Communiqué SC-2026-005
  6. IATF, Stakeholder Communiqué SC-2026-004
  7. U.S. FDA, Part 11, Electronic Records; Electronic Signatures — Scope and Application
  8. NIST, Recommendations for Ensuring Traceability and Trustworthiness in Manufacturing-Related Data
  9. NIST, SP 800-171 Rev. 3