ConfirmedISO 9001:2026 publishes 16 September 2026. FDIS approved 7 August 2026.What it means →
← All insights

Core Tools

Control plans explained: what goes in one, how it links to the PFMEA, and a free template

26 August 2026

A control plan is the written summary of how a process is kept honest: for every step that matters, what gets checked, against what specification, with what gauge or method, how often, by whom — and what happens when the answer is wrong. One document, usually one page per part or part family, covering the whole route from incoming material to despatch.

It is the most useful document in a factory and the most commonly fictional. Auditors start there for exactly that reason: it is the only document in the system that makes a specific, testable claim about what happens on the floor. Everything else describes intent. The control plan says we check this feature every hour with that gauge, and a person standing at the machine can find out in ten minutes whether that is true.

A control plan is a promise about what happens on the floor. An audit is simply the check on whether the promise is kept — which is why a control plan describing checks nobody performs is worse than having no control plan at all. It is a documented commitment you are visibly failing.

What a control plan actually is — and what it is not

Four documents get confused with each other constantly, and the confusion is what produces control plans that are really inspection lists. Keep the jobs separate:

  • The process flow says what steps exist, in order.
  • The PFMEA asks what could go wrong at each step, how bad it would be, and how likely it is to reach the customer — the next article in this series builds one, starting from the process flow.
  • The control plan records the decision that came out of that analysis: given the risk, this is what we control, how, how often, and what we do when it fails.
  • The work instruction tells the person at the station how to do the job.

So the control plan is not a risk analysis and not a work instruction. It is the bridge between them — the point where risk becomes routine. If you can read a line of your control plan and not tell which failure mode it exists to catch, that line probably came from habit rather than analysis.

It is also not an automotive-only artefact, whatever the training courses imply. ISO 9001 clause 8.5.1 never uses the words "control plan", but it asks for production under controlled conditions: the characteristics defined, the results to be achieved defined, suitable monitoring at appropriate stages to verify criteria are met. A control plan is simply the tidiest possible evidence that you have done that thinking. Food, pharma, aerospace and medical devices all have their own name for the same page. Automotive just made the format explicit and then audited it.

The anatomy: every column, and what it is really asking

A control plan has a header block and a body. The header carries the identity — part number and name, part family if it covers one, the phase (more on that below), the plant and key contact, the original date and current revision, the cross-functional team that produced it, and the customer approval fields where those apply. The revision line is the one auditors read first, because it dates your last honest look at the process.

Then the body, one line per characteristic. The columns vary in name across customers; the questions behind them do not.

  1. Process step and operation number. Mirrors the process flow, using the same numbering as the flow and the PFMEA. When those three documents number their steps differently, every audit turns into a reconciliation exercise, and every revision risks updating two of the three.
  2. Machine, device, jig or tool. What actually does the work at that step. This is what lets you find every control plan affected when a machine is replaced or a tool is refurbished.
  3. The characteristic — and whether it is product or process. A product characteristic is a feature of the part: a diameter, a weld length, a torque value on the finished assembly, the presence of a label. A process characteristic is a setting that produces it: melt temperature, injection pressure, line speed, oven dwell time, welder current. Most weak control plans contain almost no process characteristics. Everything is measured on the part after the fact, which is inspection wearing a better title. The strongest lines in any control plan are the ones that control the parameter rather than sorting the output.
  4. Special characteristic classification. The symbol or class, where one applies. It has to match the drawing and the PFMEA exactly — see the correlation section below.
  5. Specification or tolerance. The real requirement, with its source, not a rounded version somebody remembered. If the drawing says 12.00 +0.05 / -0.00, the control plan does not say "12 mm nominal".
  6. Evaluation or measurement technique. The gauge or method, named specifically enough to identify the actual instrument or family. This is where measurement systems analysis hooks in: a control plan built on a gauge whose repeatability nobody has studied is a plan that produces confident numbers of unknown quality. IATF clause 7.1.5.1.1 makes MSA an explicit requirement on control plan measurement systems, and ISO 9001 7.1.5 asks for the same trustworthiness in gentler language.
  7. Sample size and frequency. The honest column, and the one most often written to look impressive. Every frequency printed here is a commitment you have made to your customer and your auditor. Which brings us to the point most people miss — see the reaction plan section.
  8. Control method. How the check is actually made: an SPC chart with rules, 100% automated in-process gauging, an error-proofing device with a challenge test, first-off and last-off approval, a visual comparison against a signed boundary sample. "Visual inspection" alone, on a characteristic that matters, is a control plan admitting it has no control.
  9. Reaction plan. What happens when the check fails. The most important column in the document and, almost universally, the emptiest.

The three phases — and why controls should be heaviest when you know least

A control plan is not one document that lives forever. The convention, and what customers expect to see, is three:

  • Prototype. The checks that apply while parts are being built to prove the design: dimensional layouts, material and performance tests, usually near-total measurement because nothing is known yet.
  • Pre-launch. After the prototype phase, before full production is signed off. This one is deliberately heavier than the eventual production plan: higher frequencies, extra containment checks, more measurement, sometimes 100% inspection on the features that worry you. It exists because a new process has no history, and history is what earns the right to sample.
  • Production. The steady state, once capability and stability have been demonstrated. Controls step down to what the evidence supports.

More recently the industry has formalised a fourth idea inside those phases: safe launch — a defined period of enhanced controls around start of production (and often after a major change, a launch of a new tool, or a serious escape), with written exit criteria that say when the extra controls come off. AIAG's standalone Control Plan manual, effective March 2024, puts safe launch explicitly into the phase structure rather than leaving it to each customer's own programme.

The underlying principle is worth more than the labels: controls should be heaviest when the process knows the least about itself. Most plants do exactly the opposite. They run the same plan from day one, sample lightly because the process is "fine", and tighten only after a complaint — which means the controls arrive precisely when the risk has already been realised. A common audit finding is simply that a launch happened and no pre-launch control plan was ever used.

Where the control plan comes from: the PFMEA link

The chain runs flow diagram → PFMEA → control plan, and it should run in that direction only. The PFMEA finds the risks; the control plan records what you decided to do about them. Two tests will tell you whether yours is genuinely linked:

  • Take any high-risk failure mode in the PFMEA. Is there a corresponding control in the control plan, at that step?
  • Take any line in the control plan. Can you name the failure mode it exists to prevent or detect?

If either test fails, the two documents were written separately — usually one by engineering during launch and one by quality afterwards — and they will drift further apart at every revision.

The second correlation is the one that catches people out at audit: special characteristics. Where a characteristic is designated special, whether by the customer or by your own risk analysis, it has to appear consistently across the drawing, the PFMEA, the control plan and the work instruction, with the same symbol, and the controls at those points have to be visibly tighter than for ordinary features — capability studies, error-proofing, higher frequency. IATF clause 8.3.3.3 is the requirement; the practical defence is one special-characteristic correlation matrix per part, and a rule that any document change touching a special characteristic triggers a matrix check. That single habit prevents the most common finding in the automotive audit world.

There is also a trap worth naming. If your PFMEA lists "visual inspection" as the detection control for a serious failure mode, and your control plan faithfully records "visual inspection" at that step, the two documents agree perfectly and nothing has been improved. Correlation is necessary. It is not sufficient. The point of the analysis was to change the process, and error-proofing is where that usually ends up.

The reaction plan is the part that gets audited

Look at your control plan now. If the reaction plan column says "quarantine suspect product and inform supervisor" on every line, you do not have reaction plans. You have a slogan.

A reaction plan that survives contact with a real failure answers four questions, and the answers differ line by line:

  1. What stops, and who has the authority to stop it? The station, the line, the shipment. If the answer is "the operator calls someone", name the role and what that person is empowered to do.
  2. What happens to everything made since the last good check? This is the containment window, and it is the question that decides how many parts you scrap, sort or recall. It is also the question that makes the frequency column suddenly serious.
  3. Who decides to restart, and on what evidence? A restart based on "it looks fine now" is how the same defect reaches the customer twice.
  4. What gets recorded, and who is told? Internally, and — where the customer's requirements say so — externally.

Now put that second question together with the frequency column, because they are the same decision written in two places. Your sample frequency is your containment window. If you check a critical dimension every two hours, you have decided, in writing, that a failure costs you up to two hours of production. If that is 40 parts, fine. If it is 4,000 parts, or a shift's worth of a component that goes straight into a customer's assembly line, then somebody has quietly accepted a very expensive risk while filling in a form. Almost nobody makes that trade-off deliberately, and it is the single most valuable half-hour you can spend on an existing control plan: for each significant characteristic, multiply the frequency by the production rate and ask whether you would happily contain that quantity.

Two related requirements sit next to this one. IATF 9.1.1.1 expects the reaction plan to be genuinely executed when a process goes unstable or falls below its capability target — including containment and, where the customer requires it, notification. And IATF 8.5.6.1 expects that when a primary control fails — the error-proofing device breaks — you fall back to a pre-approved alternative control, manage the added risk, trace the product made during the deviation, and restore the primary within a defined time. Building that list of approved alternatives before the failure, rather than improvising at 2am, turns the worst moment of an audit into one of the best.

What IATF 16949 clause 8.5.1.1 expects, in plain English

For automotive suppliers the control plan is not good practice, it is a named requirement with its own annex of content. Quote the wording from your licensed copy when you write a finding or a procedure; described in plain English, clause 8.5.1.1 asks for five things:

  • Plans at the right level, covering everything you supply. System, subsystem, component or material level as appropriate — including bulk materials — for all products supplied. Family plans are allowed where the parts and processes genuinely are alike; "alike" means the same process route and the same risks, not merely a similar shape.
  • Content driven by the risk analysis. The controls used for manufacturing, taken from the PFMEA; the special characteristics with the methods used to control them; the monitoring and measurement systems; and the reaction plans.
  • Customer approval where their requirements call for it, and evidence you have applied the customer-specific requirements rather than your own house format.
  • Review and update after change. Not on a calendar — after events: a process or equipment change, a revised FMEA, a customer complaint or warranty issue, an MSA result that changes how you measure, a process that has proved incapable.
  • Reality. The clause does not use that word, but every auditor does. What the plan says is happening must be happening, at the stated frequency, recorded as stated.

That last point is worth understanding as a sequence, because it is exactly how an experienced auditor works the clause. First, conformance: stand at the station with the plan and check that the named check is being done, at the named frequency, with the named gauge, and that the record exists. Then coherence: does it agree with the PFMEA, are the special characteristics present and consistent, are the reaction plans real? Then currency: you had a customer complaint in April and a tooling change in June — where do they show up in the revision history?

If you are certified to ISO 9001 only, none of this is mandatory in that form, and you do not need to adopt the automotive paperwork to satisfy 8.5.1. But the questions still apply to your process, and a one-page control plan remains the easiest way to answer them all at once.

What changed in 2024: the control plan got its own manual

For decades the control plan lived as a section of the AIAG APQP manual, which meant its guidance aged at the speed of a much bigger document. That changed in 2024: AIAG published the Control Plan as a standalone reference manual (CP-1, 1st edition, effective 1 March 2024) and removed control plan content from APQP, which was reissued as its 3rd edition. What the new manual adds:

  • A common set of definitions, aimed at ending the customer-by-customer argument about what the columns mean.
  • Safe launch written into the phase structure rather than existing only inside individual customer programmes.
  • Worked examples for highly automated processes — where "sample frequency" and "operator check" stop describing what actually happens.
  • Guidance on managing control plans in software rather than as circulated spreadsheets, which is where most revision-control failures come from.

Two practical points. First, none of this changes your certification requirement: the auditable requirement is still IATF 16949 clause 8.5.1.1 with its annex, plus your customers' own requirements. Second — and this is the action worth taking this month — check which edition your customers actually require in their customer-specific requirements, because that is what your auditor will hold you to, and different customers moved at different speeds.

Keeping it alive: the update triggers

A control plan is a living document or it is decoration. These are the events that should force somebody to open it:

  • A process, equipment, tooling or layout change — including one your supplier makes.
  • A new or revised PFMEA, or a new special characteristic.
  • A customer complaint, warranty return or field issue.
  • An internal scrap, rework or repeat-defect trend.
  • An MSA result that changes the gauge or the method.
  • A process that has fallen below its capability target.
  • A temporary deviation or approved alternative control being used.
  • An internal or external audit finding at that process.
  • A new part, a new material, or a new supplier for an existing one.

One rule keeps all of this honest without a new procedure: every customer complaint and every process change ends with the written question "does the control plan change?" — answered on the corrective action report or the engineering change note, yes or no, with a name against it. A "no" that somebody signed is defensible. Silence is not. It also produces exactly the revision history an auditor is hoping to find: changes that follow real events, at plausible dates.

This is the same discipline ISO 9001 clause 6.3 is driving at for planned changes generally — and in the 2026 edition, change planning gains an explicit expectation that you monitor and review whether the change actually worked, not merely that it was made.

Seven ways control plans fail an audit

  1. It describes checks nobody performs. The fastest finding in the book, and self-inflicted: you wrote the requirement yourself.
  2. The frequencies were invented for the paperwork. Hourly on the document, per-shift in practice. Write the frequency you will genuinely sustain, then justify it with the containment maths above.
  3. The reaction plan is a slogan. Same sentence on every line, no containment window, no restart authority.
  4. Special characteristics missing or mismatched. Present in the PFMEA, absent from the control plan; different symbols on the drawing; identical controls to ordinary features.
  5. No pre-launch plan was ever used. The launch ran on the production plan, so the extra scrutiny arrived only after the first complaint.
  6. It was not updated after the complaint. The complaint is dated April, the control plan revision is dated two years ago. Currency failures are the most common finding on this clause.
  7. It names a gauge with no MSA, or one that is out of calibration. The check is being done faithfully with an instrument nobody has validated.

An eighth, less common but more expensive: one family control plan stretched across parts that do not really share a process. Family plans are legitimate; they stop being legitimate the moment a part in the family has a step, a risk or a special characteristic the others do not.

Start this week

Take one part — ideally one that has had a customer complaint in the last year — and print its control plan. Walk it, station by station, with the person actually doing the work. Ask at each line: is this check happening, at this frequency, with this gauge, recorded here? Then ask the containment question: if this check fails, how many parts are between here and the last good one, and who decides?

You will find three or four lines that need to change, and at least one frequency that nobody would defend once the arithmetic is on the table. That hour is worth more than a year of document reviews.

The free Control Plan Template below is that page as a working Excel file — a blank production control plan in the standard column set, a filled worked example line by line, and a 12-point health check for the plans you already have. If the characteristics you are controlling need real statistical control rather than a check-and-hope frequency, the Control Charts Masterclass is free and takes about twenty minutes, and the clause explorer has the full IATF and ISO clause set behind every requirement mentioned here.

Frequently asked questions

Do I need a control plan if we are only certified to ISO 9001? Not by name. ISO 9001 asks for controlled conditions and monitoring at appropriate stages; it does not prescribe the document. A control plan is the most efficient way to demonstrate it, and many customers now ask for one regardless of your certificate.

What is the difference between a control plan and a PFMEA? The PFMEA is the analysis — what could go wrong, how bad, how likely, how detectable. The control plan is the decision that came out of it — what we actually do at each step. One is thinking, the other is the operating instruction that thinking produced.

Can one control plan cover a family of parts? Yes, where the parts genuinely share the same process route and the same risks. List the covered part numbers explicitly, and split the plan the moment one member needs a different step, tolerance or special characteristic.

Do I need a prototype control plan if the customer never asks for one? If you build prototypes, you are already making the decisions a prototype plan records — writing them down costs an hour and protects the launch. If you do not build prototypes, mark it not applicable and say why.

Who should approve a control plan? The cross-functional team that produced it, at minimum quality and manufacturing engineering, plus the customer where their requirements demand it. What matters more than the signature list is that the people who own the process have read it, because they are the ones who will be asked to defend it at the station.

How often should a control plan be reviewed if nothing has changed? The requirement is event-driven, not calendar-driven — but "nothing changed" is rarely true, and an annual look at every plan against its scrap, complaint and capability history usually finds something. Reviewing on a schedule is fine. Reviewing only on a schedule is what produces two-year-old plans after a complaint.

Should control plans live in Excel? They can, if revision control is genuinely enforced — one master, a revision table, and no uncontrolled copies at the machines. The failure mode is well known: a spreadsheet emailed round, edited locally, and printed at three stations in three different versions. The same rules that govern any controlled document apply here, and this is exactly why the 2024 manual added guidance on managing plans in software.

Does ISO 9001:2026 change anything for control plans? There is no new control plan requirement. The strengthened change-planning clause does reinforce the discipline, though: a change is not finished when it is made, but when somebody has confirmed it worked — which for a process change usually means the control plan, and the data behind it.

Interpretive guidance only — not a substitute for ISO 9001, IATF 16949 or the AIAG reference manuals. Quote requirements from your licensed copies. Clause numbering follows ISO 9001:2015 and IATF 16949:2016; we re-verify against the published ISO 9001:2026 text on 16 September 2026.

Get the free Control Plan Template (a blank production control plan, a filled worked example, and a 12-point control plan health check)

Free, instant download. We'll only email you the occasional practical quality update — no spam, unsubscribe anytime.

Put this into practice

The PFMEA Toolkit is the analysis engine of the chain — the AIAG-VDA 7-step form as a working Excel workbook, with Action Priority calculated for you from the full S-O-D logic, a linked process flow tab, and the control plan handoff mapped out on the same worked example as the free templates. For the characteristics the PFMEA then sends to real statistical control, the SPC Control Chart Toolkit is X-bar/R, capability and the out-of-control rules in the same working style.

More in this series

Want to put this to work in your own system? The templates, toolkits and free masterclasses are built on the same guidance.

Browse templates