PDCA and ISO 9001 / AS9100 Clause 4: Defining the Problem Before You Solve It
- Adam Witthauer

- 4 days ago
- 8 min read
The last two posts covered why certification is worth pursuing and why independence is what makes it real. Now we get into the standards themselves, and we're going to start with the shape of the thing before we start reading the words.
The Standard Is a PDCA Loop
If you've been around manufacturing or continuous improvement at all, you've seen Plan-Do-Check-Act. Plan what you're going to do, do it, check whether it worked, act on what you learned, repeat. Deming popularized it, Toyota built an empire on it, and by now it's on a poster in half the conference rooms in America.
What a lot of people don't realize is that ISO 9001 and AS9100 are structured as a PDCA cycle. The clause numbering isn't arbitrary or bureaucratic, it walks you around the loop in order:
Phase | Clauses | What it covers |
Plan | 4 – 7 | Context, leadership, planning, and support (people, infrastructure, knowledge, documentation) |
Do | 8 | Operation — the actual work of making and delivering product |
Check | 9 | Performance evaluation — monitoring, measurement, internal audit, management review |
Act | 10 | Improvement — nonconformity, corrective action, continual improvement |
Once you see this, the standard stops reading like a list of arbitrary demands and starts reading like a project plan. It also explains something that confuses a lot of first-time implementers: the "Plan" phase takes up four of the seven clauses. More than half the standard, by clause count, is dedicated to setting up the work before any product gets made.
That's not an accident. It's the same reason a machinist spends more time on fixturing and setup than on the cut itself. Get the setup wrong and you'll make bad parts fast, which is worse than making no parts at all.
A Problem Well Defined Is a Problem Half-Solved
This brings us to Clause 4, the very first requirement in the standard, and the one most likely to get rushed through on the way to the "real" requirements.
There's an old engineering saying, usually attributed to Charles Kettering: a problem well stated is a problem half solved. It's one of those lines that sounds like a platitude until you've watched a team burn six weeks solving the wrong problem with impressive rigor.
ISO 9001 / AS9100 Clause 4 — Context of the Organization — is the standard's version of that principle. Before it asks you to do anything about quality, it asks you to define what you're actually trying to manage: who you are, who you serve, what could go wrong, what's in scope, and how your work actually flows. It's the framing step. Skip it and everything downstream is technically compliant and practically useless, like a beautifully executed corrective action on a problem you didn't have.

Clause 4 breaks into four parts. Let's take them in order.
4.1 — Understanding the Organization and Its Context
What's expected: You need to identify the internal and external issues that affect your ability to deliver conforming product and achieve the results you want from your QMS. External issues are things like customer industry trends, supply chain volatility, regulatory changes, competitive pressure, or export control obligations. Internal issues are things like workforce skills, equipment capability and age, facility constraints, or organizational knowledge concentrated in a few long-tenured people.
What conformance actually looks like: This does not require a 40-page strategic analysis. For most small and mid-sized shops, a single-page summary reviewed annually, often a simple SWOT, or a table of issues with their potential effect on the QMS — is entirely sufficient. What an auditor wants to see is evidence that you thought about it deliberately and that it connects to something. If your context analysis says "aging workforce, critical knowledge held by two senior operators," an auditor will reasonably expect that to show up again in your risk planning (6.1) and your organizational knowledge requirements (7.1.6). Context that leads nowhere is a red flag; context that threads through the rest of your system is exactly the point.
Why it matters to the customer: Your customer doesn't care about your SWOT analysis. They care that you saw the disruption coming. A supplier who identified single-source material risk before a mill shut down and qualified a second source is a supplier who ships on time. The one who didn't is the one making an apologetic phone call.
Where the operational payoff is: Context work is essentially cheap insurance. Every issue you identify in advance is one you get to address on your schedule and budget rather than during an emergency. It's the difference between replacing a CMM because it's reaching end of life and replacing one because it failed mid-inspection on a hot job.
4.2 — Needs and Expectations of Interested Parties
What's expected: Identify who has a stake in your QMS and what they require of it. The obvious one is customers, but the list is broader: regulators (FAA, ITAR/EAR, OSHA), your own employees, owners or investors, suppliers, and in aerospace, often the prime contractor sitting above your direct customer.
What conformance actually looks like: A simple list of interested parties, what each one requires, and how you monitor those requirements. The critical piece, and the one that gets missed, is that requirements change. A customer revises their supplier quality manual; a regulation gets updated. Conformance means having some mechanism for noticing, not just a list built once in 2019 and never touched.
Why it matters to the customer: Nearly every aerospace and defense contract carries flow-down requirements — terms the prime is contractually obligated to push down to you, and you to your suppliers. A shop that has systematically identified who imposes requirements on it is a shop that catches flow-downs. A shop that hasn't is a shop that discovers a missed requirement during a source inspection, which is the worst possible time.
Where the operational payoff is: Knowing what everyone actually requires lets you stop guessing and over-building. I've seen shops applying their most stringent customer's inspection requirements to every job across the board because nobody ever sorted out which requirement came from where. Mapping interested parties to their actual requirements lets you right-size the effort per job, meeting the demanding customer's needs precisely, without taxing every other order to do it.
4.3 — Determining the Scope of the QMS
What's expected: Define the boundaries of your quality management system — which sites, which products and services, which processes are covered. This must be maintained as documented information. If you determine that a requirement of the standard doesn't apply to you, you have to say so and justify why.
What conformance actually looks like: A clear scope statement, typically a short paragraph, naming your locations and the types of product and service covered. The most common scope question in machining is design: a build-to-print shop that does no product design can generally justify that Clause 8.3 (design and development) is not applicable. What you cannot do is exclude something because it isn't immediately obvious how it fits into your operations, or exclude a customer or regulatory requirement.
One example is clause 8.5.5, post delivery activities. Several of these could appear as non-applicable to contract manufacturers who build to print, but even for these manufacturers, many of these requirements can be fulfilled simply through regular communication with their customers and taking action when issues occur. Ultimately you just have to stand by your work; what 8.5.5 adds here are definitions to what that actually means.
Worth flagging: AS9100 is stricter here than ISO 9001. Its aerospace-specific additions (product safety, counterfeit part prevention, configuration management) aren't optional for organizations in scope, and attempting to scope your way out of them is a fast route to a major finding.
Why it matters to the customer: Your scope is what your customer is actually buying when they buy your certification. A certificate that covers your Wichita facility does nothing for the work you just moved to a second building down the road. Customers read scope statements closely, and a mismatch between your scope and your purchase order is the kind of thing that gets caught in supplier qualification, or worse, after the parts ship.
Where the operational payoff is: A well-drawn scope is a boundary that protects you. It tells your team, your auditors, and your customers exactly what the system governs. Vague scopes create endless arguments about whether a given process is "in the QMS," and those arguments consume real hours during every audit.
4.4 — Quality Management System and Its Processes
What's expected: This is the heart of Clause 4. You must determine the processes needed for your QMS, and for each one: its inputs and outputs, its sequence and interaction with other processes, the criteria and methods needed to make sure it works, the resources it needs, who's responsible, the risks associated with it, and how you'll measure and improve it. AS9100 adds an explicit expectation that the QMS address applicable customer and statutory/regulatory quality management system requirements.
What conformance actually looks like: Most shops handle this with a process map, often a single page showing the flow from quote through order entry, planning, purchasing, production, inspection, and shipping, with the supporting processes (calibration, training, internal audit, corrective action) shown alongside — backed by a turtle diagram or process definition sheet for each major process.
Here's the thing worth internalizing: the requirement is to define the processes you actually run, not to invent new ones to satisfy the standard. The single most common implementation mistake I see is a company documenting an idealized process that nobody follows, then spending years failing audits against their own fiction. Document what actually happens. If what actually happens is bad, fix it. But fix it deliberately, as an improvement, not by writing down what you think should be happening and hoping the floor catches up.
Why it matters to the customer: Customers experience your process interactions, not your individual processes. The failure that reaches them is almost never "machining was bad;" it's that the revision change never made it from order entry to planning, or that the inspection requirement on the traveler didn't match the one on the print. Defining the handoffs between processes is precisely how you catch those gaps. Every seam between two departments is a place where a requirement can fall on the floor.
Where the operational payoff is: This is where a QMS starts paying for itself operationally rather than just satisfying an auditor. When you map how work actually flows, you find the redundant approval nobody needs, the form that gets filled out and never read, the information that gets re-entered three times. I have never mapped a company's processes without finding waste, and the waste is usually sitting at the handoffs, invisible to everyone because no single department owns it. Clause 4.4 makes you look at exactly the places nobody's been looking.
ISO 9001 / AS9100 Clause 4: Pulling It Together
Clause 4 is where the standard makes you define the problem before it lets you solve it. Who you are, who you serve, what you're responsible for, and how work actually moves through your building. It's genuinely the least glamorous clause in the standard and the one most often treated as a formality on the way to the requirements that feel more "real."
That's a mistake, and it's an expensive one. Every clause that follows: risk planning, competence, operational control, internal audit, corrective action, inherits its usefulness from how honestly you answered Clause 4. Define the problem well and the rest of the standard has something real to work on. Define it carelessly and you'll build a technically conforming system around a business you don't actually run.
What's Next
Next up: Clause 5, Leadership — including why the standard puts the obligation on top management specifically, and what "customer focus" means as an auditable requirement rather than a slogan on a wall. I will also be giving a bit more weight to leadership's role in culture, as this has been identified as one of the more significant updates to ISO 9001:2026 which is expected to be released in about a month. Stay tuned!



Comments