HomeResources › Consulting
Guide · Automotive Quality

IATF 16949 audit readiness: a practical checklist

What automotive suppliers actually need in place before a certification or surveillance audit — and the gaps that most often cause findings.

By Continuum Improvement · Updated 2026-07-03

Passing an IATF 16949 audit is less about having documents and more about proving your quality system works with evidence. Auditors want to see that your processes are defined, followed, measured, and improving — and that you have addressed your customers' specific requirements. This checklist walks through the areas that most often decide whether an audit goes smoothly.

Use this as a self-assessment. For each item, ask not just "do we have it?" but "can we show the auditor evidence it is used?"

1. Foundations from ISO 9001

IATF 16949 is built on ISO 9001, so the base requirements still apply. Confirm you have:

  • A defined quality policy and measurable quality objectives, with evidence they are tracked
  • Documented processes with owners, inputs, outputs, and performance metrics
  • Management review that actually reviews the required inputs and produces actions
  • Internal audits covering the full system on a planned schedule
  • A working corrective-action (CAPA) process with root-cause analysis, not just containment

2. The automotive core tools

This is where automotive audits get specific. Auditors expect the core tools to be in genuine use, tied to your products and processes:

  • APQP — advanced product quality planning, with evidence of phase reviews
  • PPAP — production part approval, complete and current for the parts in scope
  • FMEA — design and process FMEAs, ideally using the AIAG-VDA method, kept live as processes change
  • MSA — measurement systems analysis on the gauges that matter
  • SPC — statistical process control on identified special characteristics, with reaction plans

A common finding: FMEAs and control plans that were built once and never updated when the process changed. Auditors check that these documents move together.

3. Customer-specific requirements (CSRs)

Every OEM adds its own requirements on top of the standard. Ford, GM, Stellantis, and others each publish CSRs, and your system has to demonstrably meet the ones that apply to you. Confirm:

  • You have identified every applicable customer's current CSRs
  • Each requirement is mapped to where in your system it is satisfied
  • Your team can show the auditor that mapping on request

4. Evidence, traceability, and the "layered" audits

IATF 16949 emphasizes prevention and traceability. Make sure you can show:

  • Product and process traceability from raw material through shipment
  • Layered process audits being performed and acted on
  • Control of nonconforming product, including customer notification where required
  • Competence and training records for people doing quality-critical work

5. Run a mock audit before the real one

The single most effective way to avoid findings is a full internal dry run against the standard and your CSRs, with findings documented and closed like a real audit. It surfaces the gaps while you still have time to fix them — and it gets your team comfortable answering an auditor's questions.

The gaps we see most often

  • Control plans and FMEAs that don't match the current process
  • CSRs identified but not actually flowed into procedures
  • Corrective actions that contain the symptom but never fix the root cause
  • SPC charts collected but with no reaction when a point goes out of control
  • Records that exist but can't be produced quickly during the audit

If any of those sound familiar, that is exactly the work a pre-audit engagement is designed to close.

FAQ

Frequently asked

How far in advance should we prepare for an IATF 16949 audit?

Start at least a few months out. A gap assessment and a mock audit both take time to run and, more importantly, to close the findings they surface before the real audit.

What is the most common IATF 16949 finding?

Documents that no longer match reality — control plans and FMEAs that weren't updated when the process changed — and corrective actions that address symptoms rather than root cause.

Do customer-specific requirements really get audited?

Yes. CSRs are a required part of the system, and auditors check that applicable OEM requirements are identified and flowed into your processes.

Want a hand with this?

We help teams turn a checklist into a passing audit — practical, right-sized, and led by a Six Sigma Black Belt with 15+ years in regulated industries.

Talk to us about audit readiness