Start a free trial
Menu

AQAP-2020

AQAP-2020 quality assurance guide for acquisition project managers

Project managers and quality staff in the acquiring organisation who plan and run a defence acquisition

AQAP-2020 is NATO's reference guide showing an acquiring project manager which quality assurance service to draw on at each stage of an acquisition, from planning through delivery and payment.

Edition
A
Published
2015-01

What it is

AQAP-2020, "Project Managers' Guide to Quality Assurance Insight, Oversight and Intervention in the Acquisition Process," is a NATO Allied Quality Publication, Edition A, Version 1, promulgated in January 2015. It is not a requirements document. It is written for a project manager on the acquiring organisation's side, and it explains how to use quality assurance to support decisions through an acquisition, rather than setting out what a supplier's management system must contain.

A guide for the acquirer, not a requirement on the supplier

The document is explicit about its own status: it says it is "intended as a reference only," and that readers "may adopt that which they find useful and compatible with national practise." It binds no one directly. The NATO Letter of Promulgation records that its use is a recommendation to nations, tracked in STANREC 4753, not a ratified commitment. That puts it in a different category from AQAP-2110 or AQAP-2310, which a contract clause can invoke on a supplier: AQAP-2020 reaches a project manager because their own organisation or nation has chosen to use it as internal guidance, not because a contract requires it.

Three kinds of quality assurance service

Everything in the guide sorts into three categories. Quality Assurance Insight (QAI) is sharing information and advice to deepen understanding of quality-related risk. Quality Assurance Oversight (QAO) is planned, project-specific activity that provides targeted insight into whether requirements are being met. Quality Assurance Intervention (QAInt) is the response when an emerging issue during contract execution or product operation needs correcting. A fourth term, Government Quality Assurance (GQA), names the mechanism: a National Quality Assurance Authority (NQAA) delivering these services against a contract on the acquirer's behalf.

Working through the acquisition, stage by stage

The guide follows a generic acquisition model built on AAP-48, in five stages, plus a review. In Acquisition Planning, the question is whether the acquisition strategy itself is sound; in Request Preparation, whether the request for goods or services is clear, complete and traceable to stakeholder needs; in Solicitation and Supplier Selection, whether a supplier's assurance matches the risk in what is being bought; in Contract Execution, whether the supplier continues to meet its commitments once the acquirer's own role has narrowed; and in Delivery and Payment, whether enough evidence exists to accept the product and release payment. A seventh element, the After Action Review, closes each stage by capturing lessons learnt, following AAP-20's Deming-cycle recommendation, for use in the current and future acquisitions.

Where a QMS certificate does, and does not, help

Supplier selection is where the guide addresses ISO 9001 directly, and it is careful about the limit: a QMS certificate can be reviewed "quickly, without cost" as one input, but it "does not provide an indication of supplier capacity to fulfil a contract," and it does not mean the product itself meets any standard. Reviewing a certificate is a starting point for the acquirer's own assurance work, not a substitute for it.

What has to be in place first

The guide assumes an acquiring organisation is already running lifecycle management under AAP-48 and has established its own quality management system with a process approach; it does not explain how to build one. It also assumes programme- and organisational-level assurance is already established, since it addresses only the project and contract level, and it borrows its definitions from AQAP-2110 unless it says otherwise. Practically, using any of the services it describes needs an existing channel to a National Quality Assurance Authority.

What an auditor or reviewer actually looks at

Annex A sets out the mechanics behind Government Quality Assurance: QMS, process, product and project audits, each gathering objective evidence against a defined standard or plan, run on an intermittent schedule through the project's life rather than to a fixed calendar; and the equivalent reviews, evaluating suitability and effectiveness rather than auditing formally. A QMS audit can be run by the organisation itself, by a customer, or by an independent third party, and the guide notes these are frequently interchangeable in practice.

How we help

AQAP-2020 does not give ComplyTrain, or any product, anything to map to directly: it is guidance on sequencing and vocabulary, not a set of clauses a system can satisfy. What it does generate, at every stage it describes, is paperwork that has to survive scrutiny later: an acquisition quality plan and strategy, a record of which QA service was requested and why, the QMS, process, product and project audit or review records Annex A describes, and the lessons-learnt output of each after action review. ComplyTrain is a general-purpose auditable quality management system for exactly that kind of record-keeping: documented procedures, controlled documents, training records, and a trail of corrective and preventive actions that stays retrievable when a National Quality Assurance Authority, or your own next project, asks for it.

ComplyTrain does not perform Government Quality Assurance, is not a National Quality Assurance Authority, and does not run the audits or reviews Annex A describes or decide whether a delivered product should be accepted; those decisions and activities stay with the acquirer and the NQAA. In defence, which assurance regime actually applies to your acquisition, and which of the documents this guide points to are in play, is set by the contract and the customer's quality clause. Use the standards explorer to see what sits alongside AQAP-2020, and talk to us about the evidence trail behind it.

Standards it references

Questions

Is AQAP-2020 mandatory?

No. AQAP-2020 describes itself as a reference, and its use by nations is recorded as a recommendation, STANREC 4753, not a ratified obligation. A contract does not invoke it on a supplier the way it can invoke AQAP-2110 or AQAP-2310.

Can a company be certified to AQAP-2020?

No. It is a guide for the acquiring organisation's own project managers, not a requirements document an accredited body, or a National Quality Assurance Authority, assesses an organisation against.

What is the difference between AQAP-2020 and AQAP-2110?

AQAP-2110 sets the quality assurance requirements a contract can impose on a supplier's design, development and production activity. AQAP-2020 does not impose requirements; it guides the acquirer's project manager on when and how to use quality assurance services, including services that check a supplier's compliance with documents like AQAP-2110.

Does a supplier's ISO 9001 certificate satisfy AQAP-2020?

AQAP-2020 treats an ISO 9001 certificate as one useful, low-cost input to supplier selection, but it says directly that certification does not indicate a supplier's capacity to fulfil a contract or mean the product itself is certified. It expects further verification proportionate to the risk involved.

Who actually delivers the quality assurance services AQAP-2020 describes?

A National Quality Assurance Authority (NQAA), through Government Quality Assurance. AQAP-2020 tells a project manager what to ask for and when; the NQAA, sometimes another nation's NQAA under STANAG 4107 and AQAP-2070, delivers it.