Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

Customer-specific requirements document for OEMs from Governance Docs.

Customer-Specific Requirements: A Clear Guide for 10 OEMs

Customer-specific requirements are the part of IATF 16949 that no amount of reading
the standard will prepare you for. The standard is one document. The customer-specific requirements
sitting on top of it are a different document per OEM, revised on the OEM’s own schedule, and you are
audited against every one that applies to you.

Customer-specific requirements: the 10 OEMs publishing CSRs through IATF in 2026
The OEMs publishing customer-specific requirements through IATF, plus the two listed as under development.

What customer-specific requirements are, and why they bind you

IATF 16949 is a common baseline agreed between vehicle manufacturers. It deliberately does not
contain everything any individual OEM wants. Each publishes its own additional and interpretive
requirements — its CSRs — and those become part of what your certification body audits
once that OEM is your customer.

This is the mechanism that makes two suppliers with identical certificates genuinely different
organisations. One selling to a single OEM carries one CSR document. One selling to five carries five,
each with its own revision history, its own terminology and its own additions to the same clauses.

IATF publishes the current set centrally. As at August 2026 the OEMs with published
customer-specific requirements are BMW Group, Ford, Zhejiang Geely Holding Group, General
Motors, IVECO Group, Mercedes-Benz Group, Renault Group, Stellantis, Volkswagen AG and Volvo
Group
, with BYD Group and Jaguar Land Rover listed as under development.

Two consequences follow immediately. If you supply BYD or JLR today, watch that page — a
document appearing there changes your audit scope. And if you supply anyone not on that list, their
requirements reach you through the contract and the purchase order rather than through IATF, but they
still reach you.

Why customer-specific requirements are the hardest part of the standard

Three structural problems make CSRs disproportionately painful, and none of them is about effort.

They change without telling you. An OEM revises its CSR document on its own cycle.
Nothing in your management system fires when that happens. Suppliers routinely discover a revision
during a surveillance audit, which is the worst possible moment.

They are written against clause numbers, not against your processes. A CSR will add
a requirement to clause 8.3.3.3 or interpret 9.2.2.3, and your organisation does not run on clause
numbers. Somebody has to translate each addition into a change to a real procedure, and that
translation is where things get lost.

They conflict. Two OEMs can impose different retention periods, different escalation
thresholds or different definitions for what looks like the same thing. The resolution is normally to
work to the strictest, but that decision has to be made deliberately and recorded, not left to whoever
writes the procedure.

IATF itself acknowledges the scale of the problem. Its July 2026 stakeholder communiqué names
customer-specific requirements as one of the five priorities driving the
IATF 16949 second edition, calling
them “one of the most discussed topics within the IATF 16949 scheme” and something
stakeholders “consistently identify as a significant challenge.” One stated goal is to
identify common CSRs and, where possible, pull them into the standard itself.

How to track customer-specific requirements so an audit is boring

The mechanism that works is a single matrix, maintained as a controlled document, with one row per
requirement rather than one row per customer. It is unglamorous and it is the difference between a
half-day CSR discussion and a nonconformity.

Column Why the auditor cares
Customer Establishes which CSRs are in scope for this site
Source document and revision Proves you are working to the current version, not last year’s
IATF 16949 clause affected Lets the auditor trace from the standard to your response
The requirement, in one sentence Forces someone to have actually read and understood it
Where it is satisfied Names the procedure, form or record — the evidence trail
Owner Someone is accountable for it staying true
Conflict note Records where you work to the strictest of two customers, and why
Last verified Shows the matrix is maintained rather than written once

Put a revision check on a calendar

The single highest-value habit in CSR management costs about twenty minutes a quarter: open the
IATF customer-specific requirements page and your customer portals, compare the published revision
against the revision in your matrix, and record that you checked. That record is what turns
“we monitor customer requirements” from an assertion into evidence.

Deploy them down the supply chain

Requirements that reach you frequently have to reach your suppliers. If an OEM mandates a
particular approach to special characteristics or a specific escalation route, and your sub-supplier
knows nothing about it, the gap is yours. This is precisely the weakness IATF has named as the Tier N
priority for the next edition, so expect it to be audited harder rather than more gently.

Start from a matrix, not from a blank spreadsheet.

The IATF 16949 Toolkit ships 250+ editable MS Office templates including a customer-specific requirements matrix, supplier evaluation and development files, 33 turtle diagrams and the full APQP, PPAP, FMEA, control plan, MSA and SPC set — so the structure exists and the work is filling it in.

Explore the IATF 16949 Toolkit →

Catch them at contract review, not at the audit

The cheapest moment to absorb a new set of requirements is before you have quoted. The most
expensive is after you have tooled up. Most organisations discover the difference the hard way, because
their contract review process checks commercial and technical feasibility and says nothing about the
customer’s quality requirements.

A contract review that works asks four questions of every new customer and every new programme with
an existing one:

  1. Does this customer publish a CSR document, and have we read the current revision?
    Not “do we have it on file” — have we read it, this revision, against what we
    do.
  2. What does it add that we do not already do? The gap, itemised, with an owner and a
    date against each item.
  3. What does it cost? Additional inspection, additional records, a specific software
    system, a particular escalation route, a mandated training course. This belongs in the quote.
  4. Does anything conflict with an existing customer? Better to find the collision at
    quotation than in a procedure two years later.

That last question is the one organisations skip, and it is the one that compounds. Conflicts between
customer-specific requirements do not resolve themselves; they accumulate quietly in procedures until
somebody has to explain to an auditor why the retention period in the procedure matches neither
customer.

Onboarding a new OEM

Treat a new OEM as a project rather than as an update. Read the CSR document end to end before
mapping anything, because requirements interact — a demand about special characteristics changes
how you handle the control plan, the PPAP submission and the training records together. Piecemeal
mapping produces a matrix that is complete row by row and incoherent as a whole.

Then decide deliberately whether to run a common system to the strictest requirement or to run
customer-specific variants. Both are legitimate. Running to the strictest is simpler to maintain and
more expensive to operate; variants are cheaper to operate and much easier to get wrong. Whichever you
choose, write down which one you chose and why, because the auditor’s question is not which approach
you took — it is whether you took it on purpose.

Frequently asked questions

Where do I find my customers’ customer-specific requirements?
IATF publishes the CSRs of participating OEMs centrally on its own site. Everything else arrives
through the customer’s supplier portal, the contract or the purchase order.

Are customer-specific requirements audited by my certification body?
Yes. Once an OEM is your customer, its CSRs form part of what you are audited against alongside the
standard itself.

What if two customers’ requirements contradict each other?
Work to the stricter of the two unless doing so would breach the other, and record the decision and
its reasoning in the matrix. An auditor is looking for a deliberate, documented resolution, not for
the absence of conflict.

Do customer-specific requirements apply if I only make a small component?
Applicability follows the contract, not the part size. Some requirements are scoped to particular
product categories, which is exactly why the matrix records applicability per requirement rather than
per customer.

Will the second edition make customer-specific requirements simpler?
That is the stated intention — better identification and management of applicable CSRs, and
possible incorporation of common ones into the standard. Publication is planned for mid-2027, and
IATF describes its own dates as indicative.

Where this leaves you

The organisations that find CSRs painful are almost always the ones holding them as a folder of PDFs
and a shared understanding. The ones that find them routine hold a single controlled matrix, check
revisions on a schedule, and resolve conflicts deliberately and in writing. The work is not
intellectually difficult and it does not take long; it takes doing before the audit rather than during
it. Whatever the second edition eventually does to simplify this, the matrix you build now is the
artefact it will simplify.

References

More on IATF 16949

All of these are covered by the IATF 16949 Toolkit, or start with the free ISO templates.

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.