How to Reduce Risk When Qualifying Aerospace Machining Suppliers
One feature does not match the drawing. The inspection report does not clearly document the result. A finishing operation was performed outside the supplier’s facility, and tracing the paperwork takes another day.
The first article exposed the problems. Supplier qualification was the opportunity to identify the risks earlier.
This is not an unusual operating environment. According to Roland Berger’s 2025 aerospace supply-chain survey, 64 percent of companies were still experiencing supply-chain disruption, with increased lead times and constrained raw-material availability among the leading causes. An IATA and Oliver Wyman study estimated that supply-chain constraints added more than $11 billion to airline costs in 2025.
Those pressures are not entirely within a buyer’s control. Supplier qualification is.
You cannot eliminate aerospace supply-chain pressure, but you can reduce how much supplier risk you add to it.
The strongest qualification process looks beyond certifications and asks whether the systems behind them can hold up when schedule, quality, and production pressure increase.
Where Aerospace Manufacturing Risk Actually Originates
Supply-chain risk in aerospace machining generally falls into four areas. Understanding them separately matters because each requires a different evaluation approach.
Qualification risk.
AS9100D certification is an important qualification signal, but it is the starting point of supplier evaluation, not the end of it. A certificate confirms that an accredited certification body has assessed the supplier’s quality management system against the applicable standard. Supplier qualification still needs to determine whether the operation, capacity, inspection capability, and controls fit the requirements of your program.
First Article Inspection under AS9102 is a similar case. An AS9102 FAIR is more than a signed form. The supplier needs a disciplined process for documenting the applicable design characteristics, inspection results, material and process information, and required records. A supplier that treats FAIR primarily as a paperwork event is missing much of its value.
Process and outside-processing risk.
Precision machining suppliers often use outside processors for operations such as heat treatment, anodizing, plating, coatings, and nondestructive testing. Those operations are not risks by themselves. The risk is in how they are controlled.
When a part leaves a supplier’s facility for an outside process, the supplier’s quality system needs to follow it through approved supplier controls, applicable receiving and documentation controls, certification review, traceability through the outside operation, and defined nonconformance handling.
The question is not whether a supplier uses outside processors. The question is whether the supplier can explain how those processors are selected, approved, monitored, and incorporated into the job’s traceability requirements.
Capacity and continuity risk.
A technically capable supplier can still be a program risk. One machine capable of making the part, one programmer who understands the process, insufficient CMM or quality capacity, fragile outside-processing relationships, or no credible path from prototype to production can all create vulnerabilities.
Machine capacity is only part of that equation. Programming resources, skilled labor, inspection capacity, outside-processing capacity, and continuity of critical process knowledge can all become constraints as production demand increases.
A capable process with no capacity behind it is still a program risk.
This category can be underweighted because the supplier made the prototype successfully. A successful prototype demonstrates technical capability. It does not automatically demonstrate production readiness.
Compliance and data-security risk.
For DoD contracts that require CMMC Level 2, cybersecurity has become part of supplier eligibility, not simply an IT matter. Those requirements generally relate to the protection of Controlled Unclassified Information (CUI).
ITAR registration addresses different obligations. Buyers should establish the requirements that apply to the specific program and verify each separately rather than treating either credential as a substitute for the other.
Read a recent article on CMMC Level 2 requirements for defense work.
What Rigorous Supplier Evaluation Actually Looks Like
Certification tells you a system exists. Qualification determines whether that system fits your program.
The five evaluation areas below represent a working framework. They are not a substitute for a formal supplier audit when one is required, but they provide a better starting point than simply collecting certificates.
1. Verify the Certification—Don’t Just Collect the Certificate
For AS9100D, confirm the supplier’s current certification status and applicable scope through IAQG OASIS rather than relying only on a certificate supplied by the vendor.
For ITAR registration or CMMC requirements, establish what applies to the program first and then verify the supplier’s applicable credentials through the appropriate source.
The purpose is not to collect more documents. It is to confirm that the qualifications being used to approve the supplier are current and relevant to the work being sourced.
2. Follow the Inspection Path
tart by determining whether the supplier performs CMM inspection in-house or outsources it. Find out who develops the inspection approach, whether the supplier can support AS9102 FAIR requirements, how it maintains calibration records, and how inspection results remain tied to specific jobs.
Then ask the most important question: What happens when an inspection result is nonconforming?
Ask for specifics. A useful response should explain the actual process for controlling nonconforming material, documenting the issue, determining disposition, communicating with the customer when required, and initiating corrective action.
The point is not simply whether the supplier owns a CMM. It is whether inspection is integrated into manufacturing rather than treated as an activity at the end.
3. Follow the Part Outside the Building
Walk through what happens when a component goes to an outside processor.
How does the supplier select and approve the processor? How do you identify and verify the part when it returns? Who reviews the required certifications? How does the supplier maintain traceability through the external operation? What does the supplier do if material returns nonconforming?
These questions reveal whether outside-process management is integrated into the supplier’s quality system or handled primarily as a purchasing transaction.
4. Test Production Readiness
Ask what changes when the part moves from five pieces to 250.
Does the process require different fixtures? What is the bottleneck operation? Does inspection capacity scale with production volume? Are outside processors capable of supporting higher quantities on the required schedule? What happens when a program accelerates?
Specific answers about fixtures, machine capacity, inspection throughput, outside processing, staffing, and scheduling provide considerably more evidence of production readiness than a general assurance that the shop can scale.
5. Test How the Supplier Communicates Bad News
Ask directly:
What happens when a part does not conform or a delivery date is at risk?
The response should reveal whether escalation, containment, customer communication, corrective action, and recovery are defined processes or improvised after a problem occurs.
Finding a shop that claims it never has problems does not eliminate supplier risk. The more useful question is how problems are identified, communicated, controlled, and prevented from recurring.
What Strong and Weak Supplier Responses Sound Like
The framework becomes more useful when the questions get specific. These three are worth asking directly during a supplier qualification conversation.
“How do you manage a part that leaves your facility for heat treatment or finishing?”
A strong response describes the process: approved supplier controls, purchase-order flow-downs containing applicable requirements, traceability through the operation, applicable receiving and documentation controls, certification review, and a defined path for handling nonconformances.
A warning sign sounds more like:
“We have a plating shop we use all the time.”
Familiarity is not a quality system.
“What changes when this part moves from ten pieces to 250?”
A useful response identifies the specific constraints: fixtures, machine capacity, outside-processing capacity, inspection throughput, scheduling adjustments, and how the supplier would communicate if something in that transition created a risk.
A general assurance that the shop can scale tells you very little. Look for specific discussion of what changes as volume increases and what could constrain production.
“What happens if you discover a nonconformance that could affect delivery?”
A strong response describes immediate containment, control of the affected material, customer notification when required, disposition, corrective action, and the approach to schedule recovery.
A warning sign is a response focused entirely on fixing the part without discussing customer communication.
Delayed notification can compound the schedule impact by reducing the customer’s available recovery options.
Why Supplier Risk Is Easier to Address Before Production
A quality escape in aerospace is rarely just a rework line item. When a nonconforming part surfaces mid-program, the consequences can extend well beyond the cost of remaking the component.
Containment consumes engineering and quality resources. Reinspection of material already in process or delivered adds time. Corrective action requires investigation, documentation, root-cause analysis, and preventive measures. Schedule recovery may require additional resources or changes elsewhere in the production plan.
The later a problem surfaces, the more operations, material, documentation, scheduling, and engineering work may already be affected.
Supplier qualification is one of the earliest opportunities to identify those risks.
The questions above are not difficult to ask. They are often missed because the supplier appears adequate on paper, the sourcing schedule is pressing, or qualification becomes a certificate-collection exercise.
A certificate is useful evidence. It should not be the entire evaluation.
What Supplier Risk Management Looks Like in a Precision Machining Environment
At Borg Design, these principles show up in practical manufacturing and quality controls.
Experienced mechanical engineers support drawing and manufacturability review during the quoting process. That creates an opportunity to identify potential tolerance, inspection, workholding, or outside-process concerns before production begins.
Borg Design supports AS9102 First Article Inspection requirements with in-house CMM inspection and the applicable dimensional and manufacturing records required by the program.
Borg Design is DDTC/ITAR registered and CMMC Level 2, C3PAO assessed. Applicable security controls are incorporated into technical-data handling, access control, documentation, and program processes.
AS9100D and ISO 9001:2015 certifications provide the quality-management foundation supporting those manufacturing and inspection processes.
Approved outside suppliers are managed through Borg Design’s quality system, with applicable purchase-order requirements, documentation, traceability, and receiving controls.
Borg Design has operated in Hudson, Massachusetts since 1945 and today supports aerospace CNC machining and defense manufacturing programs.
The programs change. The qualification requirements get more demanding. The fundamentals of supplier quality management remain familiar:
Document the process. Follow the part. Verify the result. Communicate early when something is at risk.
A Starting Point for Supplier Evaluation
Supplier qualification cannot remove every source of aerospace supply-chain risk. It can determine how much avoidable risk enters the program with the supplier.
The Borg Design Aerospace Supplier Confidence Checklist provides a practical starting point: certifications to verify, inspection capabilities to examine, documentation signals to look for, and questions to ask before approving a precision machining supplier.
Use it with Borg Design or any supplier you are evaluating.