AQAP-2070
AQAP-2070 mutual government quality assurance (GQA) process
A GQA participant (delegator, delegatee or supplier) involved in NATO mutual Government Quality Assurance on a defence contract
AQAP-2070 sets out how NATO nations request, perform and close mutual Government Quality Assurance surveillance on each other's behalf under STANAG 4107, driven by shared risk assessment rather than a fixed inspection schedule.
- Edition
- C
- Published
- 2025-06
- Evaluated by
- government-surveillance
What it is
AQAP-2070 is the NATO Allied Quality Assurance Publication that describes how NATO nations perform mutual Government Quality Assurance (GQA): one nation asking another to have its Government Quality Assurance Representative (GQAR) carry out surveillance against a defence contract, on the requesting acquirer's behalf. It is implemented "by authority of NATO Standardisation Agreement 4107 that has been ratified by each of the participating NATO nations," and the agreement of nations to use it is recorded in that same STANAG. The current edition is Edition C, Version 1, promulgated 4 June 2025 and effective on receipt, superseding Edition B, Version 4.
The document does not set quality requirements of its own. It describes a process built around a shared, ongoing risk assessment: the requesting nation (the delegator) identifies what might go wrong on a contract, decides whether GQA is needed, and if so raises a request to the nation performing the surveillance (the delegatee), whose GQAR plans and carries out GQA proportionate to those risks. The whole exchange only starts once a contract or subcontract has already been issued and a risk assessment concludes GQA is necessary - AQAP-2070 is not something a supplier signs up to directly, since the underlying quality requirement being assured, such as AQAP-2110, comes from elsewhere.
The five stages of mutual GQA
AQAP-2070 structures the process into five linked stages, each with its own instructions and guidance: Risk Identification, Assessment and Communication; GQA Request; Response to GQA Request; GQA Planning; and GQA Performance, ending in GQA Closure. Throughout the document, "shall" marks an instruction tied directly to the STANAG 4107 commitment, while "should" marks guidance or a recommendation - a distinction worth noticing, because not every line carries the same weight.
Risk sits at the centre of all five stages. The delegator writes a risk statement describing "what might go wrong on this contract," and where possible the risk causes explaining why. Risk is scored for impact and likelihood, each High, Medium or Low, and multiplied into a risk index that drives how much GQA effort is applied - except that a risk touching a critical safety item, a submarine first-level part, a vital part or a flight safety item can never score below the top band, whatever the assessment otherwise suggests. All of this is recorded on the Risk Identification, Assessment and Communication (RIAC) form, which travels with every request and is kept updated for the life of the delegation. Risk information is treated as commercially sensitive and is not shared outside the mutual GQA participants without agreement from the acquirer, supplier and GQAR.
Requesting and responding to GQA
The delegator raises a Request for GQA (RGQA) that spells out what it needs: whether a copy of the GQA plan is wanted, whether a signed Statement of GQA is required, product release instructions, how much authority the GQAR has over the supplier's deviation permits and concessions, and any reporting or sub-delegation requirements. A Facility Wide Delegation lets a single delegation cover several contracts for the same equipment and risks at one supplier, which avoids raising a fresh RGQA every time. In an urgent situation the delegator can request GQA immediately by phone or email, but a formal RGQA has to follow within 15 working days.
On the receiving side, the delegatee's focal point has to acknowledge the RGQA within 5 working days, and the GQAR has to respond - accepting, partially accepting, or rejecting it - within 20 working days, on the Response to GQA Request (RGQAR) form, alongside a reviewed RIAC. Partial acceptance and rejection are meant to be exceptions rather than routine outcomes, unless the nation involved has a relevant reservation posted against STANAG 4107.
Planning and performing the surveillance
The GQA Plan the GQAR produces is a living document, not a one-off. As a minimum it has to reference every risk being monitored, identify the specific systems, processes or products that need GQA, set out the activities planned against each risk, a schedule, and how intensive the surveillance will be - how often, how much sampling, whether a facility-wide approach applies. Some activities happen regardless of what is specifically requested on the RGQA: reviewing the supplier's quality management system documentation, maintaining GQA records, raising and processing Quality Deficiency Reports (QDRs) including verifying corrective action, and following up the supplier's investigation of any customer complaints.
The type of surveillance is meant to scale with the risk: a quality-system review can be enough where the impact is low, process review and verification come in at medium impact, and for high-impact risk the GQAR is expected to monitor the supplier's own product verification directly, particularly for key characteristics. Frequency scales with likelihood rather than impact - the more likely a risk is to occur, the more often GQA activity has to happen. Where the GQAR finds a nonconformity, they ask the supplier for corrective action and have to raise a formal QDR if it affects product performance or the delivery schedule.
Where it is requested on the RGQA and required by the contract, the GQAR signs a Statement of GQA. That signature only attests that the planned GQA has been carried out - it explicitly does not mean the supplies have been accepted on the acquirer's behalf, that individual items have been inspected, or that any certification, such as airworthiness or seaworthiness, has been granted. AQAP-2070 draws that boundary itself: acceptance of product and any kind of product certification are stated plainly to be outside the mutual GQA process, and remain the exclusive responsibility of the acquirer and the supplier under the contract.
Records, closure and disputes
GQA records have to include, at minimum, the RGQA, the RIAC, the GQA Plan, the results of GQA activities with critical items highlighted, how nonconforming product was handled, and the GQA reports themselves - retained at least until the contract is complete, unless the RGQA agrees otherwise. Closure comes with a GQA Closure Report the GQAR must send within 20 working days of finishing the work, and delegation feedback on the service provided is mandatory whenever it has been formally requested on the RGQA or RGQAR.
A deviation or concession from a supplier is classed as major if the nonconformity could affect performance, environment, safety, interchangeability, maintainability, reliability, service life, appearance, cost or delivery - everything else is minor, and only minor requests fall within a GQAR's own authority to decide; major ones go to the acquirer, with GQAR comment if asked for. Where the GQAR has exhausted the usual channels to resolve a dispute over how GQA is being conducted, escalation runs through the national GQA focal point to the AC/327 NATO Working Group 2 national representatives, without overriding any binding national law.
What the document does not cover
AQAP-2070 is explicit about what falls outside its scope. It does not set the quality requirements a supplier has to meet - that comes from the contract and whichever AQAP it invokes. It does not cover product acceptance or product certification of any kind, which stay with the acquirer and supplier directly. And it does not replace or duplicate the supplier's own quality activities, including their internal inspection and QMS auditing: GQA is there to provide confidence that those activities are working, not to perform them.
How we help
AQAP-2070 does not describe something a supplier implements as a management system; it describes government-to-government surveillance, and what it generates for a supplier is a stream of documentation requests, reviews and, where something does not conform, corrective-action work. ComplyTrain's role sits in that evidence trail rather than in the surveillance itself: keeping Quality Deficiency Reports and their corrective actions in one traceable place, recording deviation permit and concession decisions with their authorisations, and holding Certificates of Conformity for the retention period the document itself sets - at least until the contract is complete. It also means the underlying quality management system documentation and training records a GQAR asks to see are ready to produce quickly rather than assembled after the request lands.
What ComplyTrain does not do: it does not carry out Government Quality Assurance surveillance, sign a Statement of GQA, decide whether a deviation is major or minor, or grant any certification - AQAP-2070 itself rules certification out of scope for this process.
Which AQAPs a specific defence contract invokes, and whether mutual GQA applies at all, is set by the acquirer's contract and quality clause, not by us. See what else sits alongside AQAP-2070 in a NATO quality assurance package in the standards explorer, and talk to us about the evidence trail behind it.
Questions
Is AQAP-2070 a certification?
No. AQAP-2070 describes Government Quality Assurance, carried out directly by a national GQAR on the acquirer's behalf against a specific contract. The document states plainly that product acceptance and any kind of product certification, including airworthiness or seaworthiness, are not part of the mutual GQA process.
What is the difference between AQAP-2070 and AQAP-2110?
AQAP-2110 sets the quality management requirements a supplier's design, development and production work has to meet. AQAP-2070 does not set requirements at all - it describes the process by which one NATO nation asks another to surveil a supplier's compliance with requirements like AQAP-2110 on the acquirer's behalf.
Does AQAP-2070 apply to us?
That depends on whether the two nations involved in a contract have raised a request for GQA between themselves, not on the standard existing. AQAP-2070 only starts running once a delegator's risk assessment, made after a contract is issued, concludes that GQA is needed.
What does a Statement of GQA actually mean?
It means the planned GQA activity was carried out as agreed - nothing more. AQAP-2070 is explicit that a GQAR's signature does not mean the supplies have been accepted, that individual items have been inspected, or that any certification has been granted.
What forms does AQAP-2070 require?
Four are mandatory: the Risk Identification, Assessment and Communication form (RIAC), the Request for GQA (RGQA), the Response to GQA Request (RGQAR), and the GQA Closure Report (GQACR). A further set, including Delegation Feedback and an example Certificate of Conformity, is recommended but optional.
