For suppliers who are already certified
Your certificate documents one capability. The rest of the business is still running on memory.
AS9100D certifies a quality management system, but it does not actually tell your purchase team what to do on a Monday morning, it does not define who is authorised to approve a deviation, and it will simply not survive the day the one person who always handled it leaves. Most certified suppliers have one function properly documented and eight others running on tribal knowledge — which works fine for a while, until growth turns those undocumented eight into the real bottleneck.
This engagement is meant exactly for that moment: standard operating procedures (SOPs), role and authority matrices, process flows, key performance indicator (KPI) definitions and approval–escalation matrices, built across the whole organisation — as tools your team actually uses day to day, rather than just paperwork kept ready for the auditor.
The Suriyavaan method: capability first, department second
Most consultants document a company one department at a time — Purchase, then Stores, then Production, then Quality. That is essentially eight or nine separate exercises resulting in eight or nine separate files.
That approach tends to age badly. In a growing company, departments are the one thing that simply refuses to sit still. They split, they merge, they get renamed, and reporting lines keep shifting. When an experienced person moves on, the knowledge of the job moves on with them. Within a couple of years, the files on record describe a company that no longer exists in practice.
Suriyavaan starts one level below the org chart. Rather than first asking who does the work, we settle what your business must be able to do — reliably, every single time. Accept only the orders you can genuinely deliver on. Prove that what you shipped is exactly what was designed. Bring in genuine material, on time, with its paperwork intact. Catch a defect, contain it, and make sure it does not come back.
These are your capabilities, and they do not shift merely because the org chart shifts. We map them first. Then we show where each one currently sits, who owns it, and which clause of AS9100D it answers. Your SOPs, role sheets, authority matrix and KPI definitions are all built on this base — so that when you add a second shift, open a new unit, or lose a key person, the system continues to function.
This is not something invented from scratch. It applies TOGAF, the enterprise-architecture standard published by The Open Group and used by large defence, aerospace and technology organisations to stay coherent through decades of reorganisation. TOGAF's business-capability layer rests on one simple idea: what an organisation must be able to do outlasts whoever happens to be doing it at present. Suriyavaan essentially brings that discipline down to the shop floor and joins it with AS9100D.
| Capability — the stable layer | The question it answers | Usually sits in | AS9100D clause |
|---|---|---|---|
| Demand assurance | Can we commit to what we accept? Enquiry review, feasibility, risk and special-requirement capture before a promise is made. | Sales & Business Development | 8.2 · 8.2.3 |
| Design assurance | Will the design do what it must, and can we prove which baseline was built? Design control, change control, configuration identity. | Design & Engineering | 8.3 · 8.1.2 |
| Supply reliability | Will the right material arrive, genuine, on time, with its requirements flowed down? Supplier control and counterfeit-part prevention. | Purchase & Supply Chain | 8.4 · 8.1.4 |
| Material custody | Is what we hold identified, traceable, preserved and fit to use? Lot identity, shelf life, segregation, FOD control. | Stores & Inventory | 8.5.2 · 8.5.4 |
| Production integrity | Is what we build what was specified, every time? Work instruction control, first article, change control, product safety. | Production | 8.5.1 · 8.5.6 · 8.1.3 |
| Quality conformance | Do we detect it, contain it, and fix the structure rather than the symptom? Nonconformity, internal audit, corrective action. | Quality Assurance | 8.7 · 9.2 · 10.2 |
| Competence & authority | Do people know what they may decide, and are they qualified to decide it? Competence, awareness, training evidence. | Human Resources & Admin | 7.2 · 7.3 |
| Resource & cost control | Is the work resourced, and is the cost of poor quality visible enough to act on? | Accounts & Finance | 7.1 · 9.1 |
| Governance & improvement | Does leadership see enough to steer? Risk and opportunity, operational risk, management review. | Management, cross-function | 5 · 6.1 · 8.1.1 · 9.3 |
Capabilities frequently span more than one department, and that is exactly the point — the handovers between them are where undocumented systems tend to fail first. The working set is confirmed against your certificate scope, your customer flow-downs and your current findings before anything is written — this table is really the frame for that conversation, rather than a fixed template.
What is driving this matters more than the deliverable list
Four different situations tend to produce four different documents. The first question in any scoping call is essentially which one you are in, because it changes how the SOPs, role definitions and KPIs get structured.
| Driver | What changes about the work |
|---|---|
| Surveillance or recertification audit | Evidence sequencing leads the way. Documentation is ordered so that the clauses under examination are demonstrable first, and the rest follows behind the audit date. |
| New OEM or customer requirement | Flow-down leads the way. The customer’s specific requirements are traced into the capabilities they touch before any internal procedure is drafted, so that nothing has to be rewritten once the requirement is audited. |
| Scaling operations | Authority and handover lead the way. New headcount, a second shift or a new site tends to fail at decision rights and interfaces long before it fails at procedure detail. |
| Internal maturity push | Capability baseline leads the way. The work starts from an honest read of what the organisation can actually do repeatably today, and builds the measurement layer that shows real movement. |
What gets delivered
| Deliverable | What it actually resolves |
|---|---|
| Capability map | What the organisation must be able to do, and where each capability currently lives. Built before any procedure is drafted. |
| Workflow maps | End-to-end flow across capabilities and the departments they sit in. The gaps are usually at the handovers, not really inside the departments. |
| SOPs | Procedures a new joiner can follow without having to ask anyone — each one carrying the capability it serves and the clause it satisfies. |
| Role sheets | Responsibility, competence and training expectation per position, feeding clause 7.2 evidence directly. |
| Authority matrix | Who is authorised to approve, deviate, release, reject and escalate. Most process ambiguity is really decision-rights ambiguity wearing a process costume. |
| Process flow diagrams | The visual that both the auditor and the shop floor can read — one artefact, two audiences. |
| Forms, checklists, templates | The records that make a procedure provable rather than merely written down. |
| KPI definitions | Indicators that feed clause 9.1 monitoring and management review, rather than a dashboard nobody actually opens. |
| Approval & escalation matrices | What happens when the normal path fails, defined well before it fails. |
| Rollout & training | Phased implementation measured by adoption, rather than by document count. |
Why this is not generic SOP consulting
Generic SOP engagement
- Documents what people say they do, department by department.
- Nine standalone manuals with essentially no traceability to any clause.
- Handover gaps stay invisible, simply because each department was documented in isolation.
- Goes stale at the very next restructure, because it was written against an org chart rather than the underlying business.
- Aerospace-specific requirements simply absent — nobody thought to ask about configuration management, product safety or counterfeit parts.
- KPIs picked out from a generic library.
Capability-based, clause-traceable
- Capabilities mapped first, so that the documentation actually survives a reorganisation.
- Every procedure carries the clause it satisfies — operating guidance and audit evidence in one single artefact.
- Interfaces documented deliberately, because that is precisely where undocumented systems tend to fail.
- AS9100D-specific requirements built in where a general consultant would simply not know to look: configuration management (8.1.2), product safety (8.1.3), counterfeit-part prevention (8.1.4).
- Authority matrix written before the procedures, because decision rights are what actually determine process behaviour.
- KPIs designed to feed clause 9.1 and management review directly.
Where this experience comes from
This is not a methodology put together for a proposal document. It is essentially how a certified system was built and sustained at scale, well before it was ever offered as advisory work.
Engagements are led personally, hands-on. Suriyavaan is an advisory practice, not a body-shop — the scale comes from the method, rather than from headcount placed on your site.
How the engagement runs
| Phase | What happens | Typical |
|---|---|---|
| 0 · Scope | What is actually driving this, a current-state read, certificate scope and open findings reviewed. Output is a written scope and a phasing order. | 1–2 weeks |
| 1 · Capability map | What the organisation must be able to do, where each capability sits today, and which handovers are still undefined. | 2–3 weeks |
| 2 · Structure | Role sheets and the authority matrix, plus the document architecture and clause map that everything else hangs from. | 2–3 weeks |
| 3 · Write | SOPs, flow diagrams, forms, checklists, KPI definitions and escalation matrices — released for use progressively, rather than in one final drop. | 4–8 weeks |
| 4 · Roll out | Training, implementation support, and an adoption check against what has already been released. | Phased |
These durations are typical for a single-site organisation. Multi-site, multi-certificate or multi-customer flow-down scope changes the shape of the work and is priced separately. Nothing here is a firm commitment until it is written into a scope document.
Who this is for, and who it is not
This fits if
- You already hold AS9100D, AS9110C or AS9120B and are growing past the point where memory alone can scale.
- Key processes depend on specific individuals, and onboarding a new manager takes months.
- The same audit findings keep coming back after being closed out.
- You are adding headcount, a shift or a site faster than you are able to write anything down.
- A customer or OEM has asked how your organisation actually operates, and the honest answer is “it depends who you ask.”
This is not the right engagement if
- You are not certified yet — start with the position finder instead, because the certificate follows the position.
- You want documentation produced without any departmental participation. Procedures written off a template and never actually discussed do not get followed in practice.
- You need a document pack simply to present at an audit. That is not what this is, and it will not survive contact with an auditor.
- The real problem is a single unresolved finding — approval recovery is the narrower, cheaper engagement for that.
Questions suppliers ask first
| Question | Answer |
|---|---|
| Will this get us certified? | No. Certification decisions are made only by an accredited certification body. This builds the operating system underneath the certificate you already hold, and makes the evidence much easier to produce when the auditor asks for it. |
| Do you write the documents, or do we? | Both, really. Documents written entirely by an outsider tend not to get followed; documents written entirely in-house during a growth phase tend to never get finished. The workable split is drafted here, then reviewed and owned by your department heads. |
| Can you do only some areas? | Yes, and it is often actually the right way to start. The capability map still covers the interfaces, because an area documented in isolation ends up reproducing the same handover gap you are paying to remove. |
| We are not aerospace-only. Does that matter? | No, and it usually helps rather than hinders. The capability layer and authority matrix are shared across defence, automotive, semiconductor or energy customers; only the clause map and the flow-downs differ. |
| How is this priced? | By scope and phasing, agreed in writing after the scoping call. What actually moves the price is the number of capabilities in scope and the number of customer flow-downs to reconcile — not the page count. |
Start with the scoping call
Fifteen minutes, no document pack required. Just bring your certificate scope, your last audit report if you have one, and an honest answer to what is actually driving this.
Suriyavaan is an independent advisory practice. It is not a certification body and does not issue certificates. Certification decisions are made by accredited certification bodies, and approval decisions are made by customers and OEMs. Timelines are typical patterns, not commitments. AS9100, AS9110, AS9120, Nadcap and CMMI are the marks of their respective owners; reference to them describes scope of advisory work and implies no endorsement or affiliation. TOGAF is a registered trademark of The Open Group. Suriyavaan applies TOGAF's published business-architecture principles in its own advisory method; it is not affiliated with, accredited by, or endorsed by The Open Group.