Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

layered process audit explained

Layered Process Audit: A Clear IATF 16949 Guide to GM’s 9 Rules

A layered process audit is a short, frequent check of a manufacturing process carried out by successive layers of management — the supervisor daily, the plant manager weekly or monthly — using a fixed checklist, to confirm that the process is being run the way it was designed. IATF 16949 does not require one by name. General Motors and Stellantis do, through their customer-specific requirements, and GM’s version comes with nine numbered rules. This guide explains what a layered process audit is, what the OEMs actually require, how it differs from the manufacturing process audit in IATF 16949 clause 9.2.2.3, and how to build one that survives a certification body auditor reading the CSRs beside your records.

Layered process audit: three layers, three frequencies, one checklist
The layers: the closer to the process, the more often the audit runs; the further up, the more it checks the system that keeps the process standard.

What a layered process audit is, and is not

The reference document is AIAG’s CQI-8 Layered Process Audit Guideline, revised in a second edition in 2014 after further work with OEMs and tier-one suppliers. Its premise is simple: most nonconformances in a plant come not from a bad process design but from the process drifting away from its standard — a setting changed, a step skipped, a gauge missed. A layered process audit checks the inputs to the process against the standard, frequently, rather than inspecting the output after the fact.

Three features define it:

  • Layers. The same process is audited by people at different organizational levels. The first layer is the immediate supervisor or team leader, every shift or every day. The second is the area or department manager, weekly. The third is plant leadership, monthly. Higher layers audit less often but also check whether the lower layers are doing their audits and reacting to what they find.
  • A short, fixed checklist. Yes/no questions on the things that matter most to the process: the current work instruction is posted and followed, the gauges are calibrated and in use, the error-proofing device was verified at start of shift, the control plan reaction was followed. Ten to fifteen questions, ten minutes, is the common shape.
  • Immediate reaction. A “no” is corrected on the spot where possible; what cannot be corrected on the spot goes to an action plan. The audit is a coaching moment as much as a check.

It is not a product audit, which checks the part; not a system audit, which checks the quality management system; and not the IATF manufacturing process audit, which is a deeper, less frequent examination of a process’s effectiveness. It is the frequent, shallow, management-owned layer that sits underneath all three.

What IATF 16949 requires, and where the layered process audit comes from

IATF 16949:2016 clause 9.2.2.3, Manufacturing process audit, requires the organization to audit all manufacturing processes over each three-calendar-year period, using a customer-specific required approach where one exists, to determine their effectiveness and efficiency. The audit must include the effective implementation of the process risk analysis (the PFMEA), the control plan and associated documents, and must be conducted on all shifts including shift handover. Nothing in that clause says “layered”. The requirement enters through the words “customer-specific required approach” — and through the CSRs themselves, which IATF makes binding on any supplier certified to the standard. Our guide to customer-specific requirements for ten OEMs explains how CSRs attach to the certificate.

General Motors: nine numbered rules

GM’s Customer Specific Requirements for IATF 16949, effective 30 October 2025, place the requirement directly under 9.2.2.3: “The organization shall incorporate an internal layered process audit process to assess compliance to standardized processes, to identify opportunities for continuous improvement, and to provide coaching opportunities. The layered process audit is led by Management who are competent to conduct the audits.” The process shall include:

# GM requirement (9.2.2.3) What the evidence looks like
1 A schedule including frequency of audits and locations of planned audits A layer-by-layer calendar naming areas and dates
2 Audit layers must be used and include different levels of employees, including top management Completed audits signed by the plant manager, not only supervisors
3 Customer complaints (including SPPSs) or rejections trigger a layered audit on the process that was cause of the issue A complaint log cross-referenced to an unscheduled audit
4 All departments within the organization Layered audits in logistics, maintenance, the lab — not only production
5 All findings are recorded and measured for improvement A findings database with trend charts by question and area
6 Findings that cannot be corrected during the audit shall move to an action plan for monitoring to closure Open actions with owners, dates and closure evidence
7 Records of audits shall be maintained Retained completed checklists, paper or electronic
8 Layered audit questions shall be reviewed periodically and changed if needed to focus on the organization’s weaknesses Version history on the checklist with the reason for each change
9 Layered process audit shall be done as part of corrective action verification activities 8D reports whose verification step cites a layered audit

Item 9 has been in GM’s list since the November 2017 revision; the October 2025 revision widened item 3 to include SPPS (Supplier Practical Problem Solving) records. GM also requires, separately and in addition, annual assessments of specific manufacturing processes against the current CQI standards — heat treat, plating, coating, welding, brazing, rubber and the rest — uploaded to GM’s Supplier Certification Management System. Those are separate obligations.

Stellantis: operational managers, all shifts, all areas

Stellantis’s CSR for use with IATF 16949 (version 1, June 2025) requires under 9.2.2.3 that “the supplier must conduct Layered Process Audits (LPA), the aim of which is to ensure consistent application and execution of standards. LPA are to be performed by Operational Managers.” No specific auditor qualification is required, but performers must be trained in the LPA process. LPA must cover all operational manufacturing and logistics areas, all shifts must be audited, all management levels should be involved from team leader to top management — at minimum the management of operational teams — and reaction plans must be in place to respond immediately to nonconformances. The auditor’s checks are listed too: a specific checklist integrated into supplier processes, an established and regularly updated schedule, and regular review with top management.

Ford

Ford’s current CSR (effective 15 June 2026) does not use the term. Ford suppliers still need a 9.2.2.3 manufacturing process audit program, and many run layered audits because their other customers require it, but do not cite Ford as the source of a layered audit obligation.

Layered process audit vs the IATF manufacturing process audit

Certification body auditors regularly find plants that present their layered audits as the 9.2.2.3 manufacturing process audit. They are different instruments and the standard wants both.

Attribute Layered process audit Manufacturing process audit (IATF 9.2.2.3)
Frequency Every shift / daily at layer 1; weekly and monthly above Each process at least once per three calendar years
Duration About 10 minutes Hours; a full process walk
Who Line management, layered up to top management Trained internal auditors independent of the process
Checks Adherence to standard: settings, instructions, gauges, error-proofing Effectiveness and efficiency; PFMEA and control plan implementation; all shifts and handover
Output On-the-spot correction or an action-plan item Audit report, nonconformities, corrective action
Required by GM and Stellantis CSRs (and other customers by contract) IATF 16949 itself

The two connect at the point IATF cares about: the manufacturing process audit checks whether the control plan is implemented, and the layered audit is the daily evidence that it is. A layered audit question set built from the control plan’s reaction plans and the PFMEA’s prevention controls makes the three-year audit far easier to pass, because the adherence data already exists. Our guide to special characteristics covers the control plan entries the questions should be drawn from.

Building one that works

Write questions from the risk documents, not from memory

Start with the PFMEA’s highest-rated failure modes and the control plan’s special characteristics. Each becomes a binary question about the input that prevents it: “Is the torque tool set to the value on the control plan and verified this shift?” A question that cannot be answered with a glance at the station is the wrong question.

Define the layers and the calendar

Three layers is the CQI-8 shape and satisfies both GM’s “including top management” and Stellantis’s “from team leader to top management”. Put the calendar on the wall and in the system. Item 1 of GM’s list is a schedule with frequency and locations; a rota that names people but not areas does not meet it.

Cover every department and every shift

GM item 4 and Stellantis’s “all shifts” are the two most common findings. Night shift and the warehouse both need layered audits with the same frequency logic as day-shift assembly.

Record findings as data, not paper

GM item 5 says “recorded and measured for improvement”. A stack of completed sheets is a record; a chart showing which question fails most, by area, by month, is a measurement. The second is what drives item 8, the periodic review of the questions themselves.

Wire it to complaints and corrective action

Items 3 and 9 make the layered audit part of the problem-solving loop: a customer complaint triggers an unscheduled layered audit on the causal process, and the 8D’s verification step uses layered audit results as evidence that the fix held. Both need a written link in the procedure and a visible cross-reference in the records.

Train the auditors, briefly

GM wants management “competent to conduct the audits”; Stellantis wants performers “trained to LPA process”. A one-hour session covering the purpose, the checklist, how to react to a “no” and how to coach without blame, recorded as training, closes both.

Frequently asked questions

Does IATF 16949 require a layered process audit?
Not by name. Clause 9.2.2.3 requires a manufacturing process audit using a customer-specific required approach where one exists. GM and Stellantis require layered process audits in their CSRs, which are binding on their suppliers’ IATF certificates.

What is CQI-8?
AIAG’s Layered Process Audit Guideline, the reference document for LPA design. The second edition was published in 2014. GM’s CSR refers to CQI standards for its annual special-process assessments; the layered audit requirements themselves are written out in the CSR.

How many questions should a layered process audit have?
CQI-8 practice is a short binary checklist, commonly 10 to 15 questions taking about 10 minutes, drawn from the control plan and PFMEA. Longer checklists stop being done.

Who performs the audits?
Management at successive layers: supervisors or team leaders daily, area managers weekly, plant leadership monthly. Stellantis specifies operational managers; GM requires layers up to and including top management.

Can our layered audits replace the three-year manufacturing process audit?
No. The manufacturing process audit examines effectiveness, PFMEA and control plan implementation across all shifts and is performed by independent auditors. Layered audits are the frequent adherence check that feeds it.

Where this leaves you

Build it as the OEMs wrote it: a scheduled, layered, all-department, all-shift adherence check with questions drawn from your own risk documents, findings measured as data, and a written link to complaints and corrective action verification. Do that and GM’s nine items, Stellantis’s checklist and the IATF auditor’s 9.2.2.3 questions are all answered by the same records.

References

More on IATF 16949

Layered audit checklists, the audit calendar, the findings tracker and the control plan and PFMEA templates the questions are drawn from are in the IATF 16949 Toolkit, or start with the free templates.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.