Framework overlap

Does AS9100D:2016 cover AS9100D?

You hold AS9100D:2016 and have been told to do AS9100D. Here is how much overlaps, control by control.

43% of AS9100D you already have

AS9100D:2016 already covers about 43% of AS9100D, leaving 35 of 61 controls as genuinely new work.

Already covered 9 Likely covered 17 New work 35

What is genuinely new work

Nothing in AS9100D:2016 reaches these. This is the list to scope.

AS9100D-10.1
General Improvement
AS9100D-10.3
Continual Improvement
AS9100D-4.1
Understanding the Organization and Its Context
AS9100D-4.2
Understanding Needs and Expectations of Interested Parties
AS9100D-4.3
Determining the Scope of the QMS
AS9100D-4.4
Quality Management System and Its Processes
AS9100D-5.1.2
Customer Focus and Product Safety
AS9100D-6.1
Risk-Based Thinking and Operational Risk
AS9100D-6.3
Planning of Changes
AS9100D-7.1
Resources
AS9100D-7.1.5
Monitoring and Measuring Resources
AS9100D-7.1.6
Organizational Knowledge
AS9100D-7.2
Competence
AS9100D-7.3
Awareness
AS9100D-8.1.2
Operational Risk Management
AS9100D-8.1.3
Product Safety
AS9100D-8.1.4
Prevention of Counterfeit Parts
AS9100D-8.5.1.3
Production Process Verification
AS9100D-8.5.4
Preservation - Including FOD Prevention
AS9100D-8.5.6
Control of Changes
AS9100D-8.6
Release of Products and Services
AS9100D-9.1
Monitoring, Measurement, Analysis, Evaluation
AS9100D-9.2
Internal Audit
AS9100D-9.3
Management Review
ISO27003-4.1
Understanding the Organization and Its Context
ISO27003-4.4
Information Security Management System
ISO27003-5.2
Information Security Policy
ISO27003-6.2
Information Security Objectives and Planning to Achieve Them
ISO27003-7.1
Resources
ISO27003-7.2
Competence
ISO27003-7.3
Awareness
ISO27003-7.4
Communication
ISO27003-9.1
Monitoring, Measurement, Analysis and Evaluation
ISO27003-9.2
Internal Audit
ISO27003-9.3
Management Review
Show the 26 you already have
8.3
Statement of Applicability linkage
AS9100D-5.1
Leadership and Commitment
AS9100D-8.1
Operational Planning and Control
AS9100D-8.4
Control of Externally Provided Processes, Products, Services
AS9100D-8.5
Production and Service Provision
ISO27003-4.2
Understanding Needs and Expectations of Interested Parties
ISO27003-6.1
Actions to Address Risks and Opportunities
ISO27003-8.1
Operational Planning and Control
ISO27003-8.3
Information Security Risk Treatment
8.5
Control effectiveness review
AS9100D-10.2
Nonconformity and Corrective Action
AS9100D-5.2
Quality Policy
AS9100D-5.3
Organizational Roles, Responsibilities, and Authorities
AS9100D-6.2
Quality Objectives and Planning to Achieve Them
AS9100D-7.5
Documented Information
AS9100D-8.2.3
Review of Requirements for Products and Services
AS9100D-8.3
Design and Development of Products
AS9100D-8.5.1
Control of Production and Service Provision
AS9100D-8.7
Control of Nonconforming Outputs
ISO27003-10.1
Continual Improvement
ISO27003-10.2
Nonconformity and Corrective Action
ISO27003-4.3
Determining the Scope of the ISMS
ISO27003-5.1
Leadership and Commitment
ISO27003-5.3
Organizational Roles, Responsibilities, and Authorities
ISO27003-7.5
Documented Information
ISO27003-8.2
Information Security Risk Assessment

How this is calculated

Already covered means a mapping runs from a control in AS9100D:2016 to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition