25% of AS9100D you already have
Authorised Economic Operator (AEO) Programmes already covers about 25% of AS9100D, leaving
46 of 61 controls as genuinely new work.
Already covered 7
Likely covered 8
New work 46
What is genuinely new work
Nothing in Authorised Economic Operator (AEO) Programmes reaches these. This is the list to scope.
8.3Statement of Applicability linkage
AS9100D-10.1General Improvement
AS9100D-10.3Continual Improvement
AS9100D-4.1Understanding the Organization and Its Context
AS9100D-4.2Understanding Needs and Expectations of Interested Parties
AS9100D-4.3Determining the Scope of the QMS
AS9100D-4.4Quality Management System and Its Processes
AS9100D-5.1.2Customer Focus and Product Safety
AS9100D-5.2Quality Policy
AS9100D-5.3Organizational Roles, Responsibilities, and Authorities
AS9100D-6.1Risk-Based Thinking and Operational Risk
AS9100D-6.2Quality Objectives and Planning to Achieve Them
AS9100D-6.3Planning of Changes
AS9100D-7.1.5Monitoring and Measuring Resources
AS9100D-7.1.6Organizational Knowledge
AS9100D-7.5Documented Information
AS9100D-8.1.2Operational Risk Management
AS9100D-8.1.3Product Safety
AS9100D-8.1.4Prevention of Counterfeit Parts
AS9100D-8.2.3Review of Requirements for Products and Services
AS9100D-8.3Design and Development of Products
AS9100D-8.5Production and Service Provision
AS9100D-8.5.1Control of Production and Service Provision
AS9100D-8.5.1.3Production Process Verification
AS9100D-8.5.4Preservation - Including FOD Prevention
AS9100D-8.5.6Control of Changes
AS9100D-8.6Release of Products and Services
AS9100D-8.7Control of Nonconforming Outputs
AS9100D-9.1Monitoring, Measurement, Analysis, Evaluation
AS9100D-9.2Internal Audit
AS9100D-9.3Management Review
ISO27003-4.1Understanding the Organization and Its Context
ISO27003-4.4Information Security Management System
ISO27003-5.2Information Security Policy
ISO27003-5.3Organizational Roles, Responsibilities, and Authorities
ISO27003-6.2Information Security Objectives and Planning to Achieve Them
ISO27003-7.5Documented Information
ISO27003-9.1Monitoring, Measurement, Analysis and Evaluation
ISO27003-9.2Internal Audit
ISO27003-9.3Management Review
Show the 15 you already have
AS9100D-8.1Operational Planning and Control
AS9100D-8.4Control of Externally Provided Processes, Products, Services
ISO27003-4.2Understanding Needs and Expectations of Interested Parties
ISO27003-6.1Actions to Address Risks and Opportunities
ISO27003-8.1Operational Planning and Control
ISO27003-8.2Information Security Risk Assessment
ISO27003-8.3Information Security Risk Treatment
8.5Control effectiveness review
AS9100D-10.2Nonconformity and Corrective Action
AS9100D-5.1Leadership and Commitment
ISO27003-10.1Continual Improvement
ISO27003-10.2Nonconformity and Corrective Action
ISO27003-4.3Determining the Scope of the ISMS
ISO27003-5.1Leadership and Commitment
ISO27003-7.4Communication
How this is calculated
Already covered means a mapping runs from a control in Authorised Economic Operator (AEO) Programmes to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition