Start a free trial
Menu

AQAP-2131

AQAP 2131 final inspection and test

Defence suppliers whose NATO contract flows down final inspection and test requirements, and who host a Government Quality Assurance Representative.

AQAP 2131 is NATO's quality assurance requirement set for final inspection and test. ComplyTrain ships its full requirement tree and document set, so the Certificate of Conformity you sign is backed by traceable evidence.

Edition
C
Published
2017-12
Evaluated by
government-surveillance
THIS DOCUMENT Agreement Holds requirements Organisation certificate Product or design assessed ALLIED QUALITY ASSURANCE PUBLICATION · EDITION C · 2017-12 AQAP-2131 NATO quality assurance requirements for final inspection and test AQAP-2131 sets NATO's quality assurance requirements for a supplier's final inspection, test and release of product, applying once a contract names it. AGREEMENT STANAG 4107 The agreement that puts this publication into force. WHERE THE REQUIREMENTS LIVE AQAP-2131 AQAP-2131 sets NATO's quality assurance requirements for a supplier's final inspection, test and release of product, applying once a contract names it. A supplier meets AQAP-2131 when a contract or national instruction names it, usually via STANAG 4107. Addressed to supplier, acquirer. Covered by STANAG 4107. The document describes Government Quality Assurance access and evaluation rights for the GQAR and/or Acquirer against the contract; it names no accredited certi. Reaches a supplier when a contract, tender or national instruction names it. Nobody is certified against this document. Nations report ratification; they do not issue a company certificate.

What it is

AQAP-2131 is the NATO Allied Quality Assurance Publication that sets out quality assurance requirements for a Supplier's final inspection and test of a product delivered under a defence contract. It is Edition C, Version 1, promulgated December 2017, and it superseded the previous Edition 2. Like every AQAP, it has no force by itself: it is "for use in a contract between two or more parties," and "when referenced in a contract, this publication shall apply to all of the processes necessary for the Supplier to fulfil the contractual requirements." Where the contract and the publication disagree, the contract wins. Compliance with AQAP-2131 is defined narrowly, as the fulfilment of the requirements in its Chapter 2 and Chapter 3, which makes it a focused document rather than a full quality-management-system standard.

Who it involves

The Supplier is the "organization that acts in a contract as the provider of products to the Acquirer," and the Acquirer is "governmental and/or NATO organizations, that enter into a contractual relationship with a Supplier, defining the product and quality requirements." A Government Quality Assurance Representative (GQAR) can act on the Acquirer's behalf, and the document uses "GQAR and/or Acquirer" throughout so the Acquirer becomes the default wherever no GQAR is appointed or delegated. External Providers, meaning the Supplier's own subcontractors and vendors, are also reached indirectly, through the flow-down duty in Chapter 2.

Final inspection and test

The core requirement is that the Supplier performs all inspection and testing needed to demonstrate conformity with contract requirements, and retains documented information sufficient to prove that conformity. That work runs under documented procedures that include acceptance criteria, applied through processes and communication that capture and deliver the contractual requirements accurately. The test status of a product has to be recognisable at any stage of inspection, so a walk-through of the shop floor should show, without asking, what has and has not been tested.

Two requirements are easy to under-scope. First, every device used for tests and final inspection has to be metrologically confirmed, and if a piece of measuring equipment is found out of calibration and affected products exist, the GQAR and/or Acquirer has to be told and given details of the affected products, "including products already delivered." That duty reaches backwards, into product that has already shipped. Second, the Supplier has to maintain documented information on the competence of the personnel who actually perform inspection and test, not just on the procedures they follow.

The purchasing chain and external providers

Requirements flow downhill. The Supplier must reference the applicable contractual requirements, including any relevant AQAPs, in its dealings with External Providers, and every purchasing document has to carry a specific clause: that all requirements of the contract may be subject to Government Quality Assurance, and the External Provider will be notified of any GQA activity to be performed. On request, the Supplier has to produce copies of subcontracts or orders to the GQAR and/or Acquirer, flag any subcontract or order that carries risk, and retain verification and validation records for purchased products. Where a product supplied by the Acquirer itself turns out to be unsuitable, the Supplier has to report and coordinate on corrective action immediately, tell the GQAR on request, and treat the item as nonconforming until the matter is resolved.

Traceability, preservation and release

Traceability has to run through production, inspection and delivery, and separately has to be sufficient to support a product recall. Storage conditions such as temperature, dust and humidity have to be identified, complied with through storage, shipping and transport, and communicated to the Acquirer. Products with a limited shelf life have to be identified at final inspection with expiry dates marked, and only product with acceptable remaining shelf life may go out the door. Packaging has to protect against deterioration and damage and meet any contractual packaging and labelling requirements.

At release, only acceptable product intended for delivery may be released, and the GQAR and/or Acquirer keep the right to reject anything nonconforming. A Certificate of Conformity has to accompany release unless the contract says otherwise, and where the Supplier is not the manufacturer of the product, an OEM or Authorized Manufacturer Certificate of Conformity has to be provided instead. The Supplier stays solely responsible for the conformance of what it delivers, and where the GQAR or Acquirer is to witness final inspection or formal acceptance, it is owed a minimum of ten working days' notice unless the contract states a different figure.

Nonconforming products, including counterfeit material

Nonconforming products have to be identified, controlled and segregated, and that duty explicitly extends to Counterfeit Material. The definition is broader than the everyday sense of the word: it covers a product whose origin, age, composition, configuration, certification status or other characteristic has been falsely represented, whether by misleading marking, misleading documentation, or any other means "including failing to disclose information," with the only exception being where the misrepresentation is shown not to result from the Supplier's or an External Provider's dishonesty. The GQAR and/or Acquirer can reject any rework, repair or use-as-is disposition, records of those dispositions have to be retained, and the GQAR and/or Acquirer has to be notified of nonconformities and the corrective action required.

Access and support for Government Quality Assurance

Chapter 3 sets out what the Supplier owes the GQAR and/or Acquirer to let GQA activity actually happen: access to the facilities where contracted work is performed, information relevant to meeting contract requirements, an unrestricted opportunity to evaluate the Supplier's compliance with the publication, and an unrestricted opportunity to verify product conformity with contract requirements. Beyond access, it covers practical support: accommodation and equipment for performing GQA, personnel to operate that equipment, access to information and communication facilities, and copies of the necessary documents, including on electronic media.

What the document does not cover

AQAP-2131 does not establish a Supplier's quality management system; that is the role of AQAP-2110 and, ultimately, ISO 9001. It names no accredited certification body and describes no scheme for certifying an organisation or a product against this publication. It also sets no fixed audit frequency of its own: the access and evaluation rights in Chapter 3 apply throughout the contract, not on a stated cycle.

Where to get it

AQAP-2131 is published by the NATO Standardization Office and, like all NATO standardization documents, it is free of charge. The Standardization Document Database is the authoritative source; we credit NATO for the catalogue and do not sell or host a copy of the document ourselves.

Put AQAP-2131 on a system that keeps the evidence

Documents, training, risks and evidence in one place, with the trail an auditor asks for.

How we help

The AQAP 2131 requirement tree and its document set are prebuilt. They ship with the standard rather than being written for you during an implementation project. What is yours is the scope, the content and the evidence.

  • All 36 requirements, structured by clause, with the criticality of each - Requirements Management
  • A generated document set: a Final Inspection and Test Quality Manual, six procedures, a Certificate of Conformity form, an inspection checklist and a nonconformance report - Document Control
  • A dedicated GQA Access and Support procedure, mapped to the eleven access requirements - Document Control
  • Evidence attached to each requirement, so a claim of conformity points at something - Requirements Management
  • Gap analysis over the tree, so you know what is unevidenced before a visit rather than during one - QMS
  • Nonconformance and corrective action tracked to closure, including the NATO CAPA workflow - QMS

Scope is a decision you make and record. Requirements can be scoped selectively and by business unit, with the justification kept alongside, so a supplier delivering one product line under AQAP 2131 is not carrying the whole publication across the organisation.

ComplyTrain is not certified against AQAP 2131 and does not need to be. It is the system you run your own AQAP 2131 obligations in, and where the evidence for them lives.

AQAP 2131 is one publication in NATO's family of Allied Quality Assurance Publications, and a contract rarely cites it on its own. That overview sets out how 2110, 2131, 2210, 2310 and 2105 relate, and which one applies to what.

Standards it references

Request access to this standard

Tell us how you need to work with AQAP-2131 and what you need from it. We will come back to you about what ComplyTrain can do.

Questions

Can a company be certified to AQAP 2131?

No. AQAP 2131 is a contractual requirement set, not a certification scheme. Conformity is demonstrated to the acquirer and their Government Quality Assurance Representative under a specific contract, not to a certification body, and there is no certificate to hang on a wall.

What is a GQAR, and why does the standard care so much about them?

The Government Quality Assurance Representative acts for the acquiring nation. Eleven of the 36 requirements concern their access and support: unrestricted access to relevant areas including production, inspection, storage and external provider facilities, and documentation available when asked. Restrictions or delays are themselves reportable, which is why the obligation needs a written policy rather than goodwill.

We do not manufacture the product ourselves. Does AQAP 2131 still apply?

Yes, and it addresses the case directly. Where you are not the manufacturer, the Certificate of Conformity from the OEM or authorised manufacturer has to be provided and controlled. The obligation moves from making the product to evidencing the chain behind it, which makes external provider control and traceability the load-bearing parts.

What has to be on a Certificate of Conformity?

The publication specifies minimum content, and a CoC that omits it is a finding regardless of whether the product is good. ComplyTrain ships a CoC form template built to that content, and holds issued certificates against the requirement they satisfy so a sample review has something to review.

How much of this is prebuilt, and how much do we write?

The requirement tree and the document templates are prebuilt and approved, and arrive complete. What you supply is the scope, your own facts and processes inside each document, and the evidence. The documents are drafted from the templates against your content, and a named person in your organisation approves every change.

Can we start on our own?

Not for this standard. AQAP 2131 is provisioned by our team rather than switched on from a signup form, so the first step is a conversation about your contract and scope. What arrives afterwards is a finished requirement tree and document set, not a consulting engagement.

What is the difference between AQAP-2131 and AQAP-2110?

AQAP-2110 sets requirements for a Supplier's design, development and production quality management system as a whole, built on ISO 9001. AQAP-2131 is narrower: it covers only final inspection and test, the control of externally provided products, traceability, preservation, release, and nonconforming product, and defines compliance as meeting its own Chapters 2 and 3.

How much notice do we owe a GQAR before a witnessed final inspection?

AQAP-2131 sets a minimum of ten working days' notice of a final inspection or formal acceptance event that the GQAR or Acquirer is to witness, unless the contract states a different figure.

Does AQAP-2131's nonconforming-product requirement cover counterfeit material?

Yes, explicitly. Its definition of Counterfeit Material is broad: any false representation of a product's origin, age, composition, configuration or certification status, including by failing to disclose information, unless the misrepresentation is shown not to result from dishonesty on the part of the Supplier or an External Provider.

The process

From contract clause to a defensible Certificate of Conformity

AQAP 2131 ends at a signature: the Certificate of Conformity says the product conforms. Everything before it exists to make that signature safe to give.

  1. Declare what is in scope

    Record which requirements apply to which product line or business unit, and why. Scope decided and justified up front is the thing an assessor asks about first, and the thing hardest to reconstruct later.

  2. Generate the document set

    The manual, the six procedures, the CoC form and the checklist are drafted from approved templates against your own facts. A named person approves each one, so the document set has an owner rather than an origin.

  3. Evidence each requirement

    Attach the inspection records, traceability data and release approvals that show a requirement operating. Sample tracing a delivered product back through its production history is a routine check, and it only works if the records connect.

  4. Be ready for the GQAR

    Access has to be unrestricted and documentation readily available. Hold the access policy, the arrangements and the record of visits in one place, so support for the representative is a process rather than a scramble.

If you need to get there and have no quality function

A standard usually arrives as a contract condition rather than a project anyone planned for, and often at a company with no quality manager. Software is half the answer. Skylen's consultants are the other half, and because they build on ComplyTrain from day one you keep a live system your team owns rather than a binder and a departed consultant.

  • Gap assessment

    A clause-by-clause read of where you stand against the standard your contract cites, turned into a prioritised plan you could act on with us or alone.

    What an assessment covers
  • Guided implementation

    Our consultants build the system with your team - procedures, document control, the records you need to keep and the review cadence - and prepare you for the certification audit.

    How an engagement works
  • Full-service quality function

    We run and maintain the quality system for you, so a small team can reach and hold a standard without hiring a quality manager.

    What full-service means

Talk to us about AQAP 2131

AQAP 2131 is provisioned by our team rather than self-served, so the conversation comes first. Book a 30-minute demo and we will walk the requirement tree and the document set on your own product line, or get in touch and we will tell you honestly whether it fits.

What ComplyTrain does

One system for the whole compliance programme. Start with the module you need most.

  • Forms & Follow-up

    Collect information the same way every time, and decide in advance what happens next.

  • Controls & Assurance

    Know whether your controls are operating, not just whether a policy says they exist.

  • Project Planner

    Turn the compliance work you already know about into a plan with owners, dependencies and dates.

  • Product Compliance

    Know what you can offer, and hold the evidence behind every configuration you offer it in.

  • Reporting & Analytics

    Eight built-in reports across every module, scheduled, delivered, and filed where the evidence lives.

  • Media Monitoring

    The sector news that matters to your organisation - read and rated by AI, and delivered as a scheduled digest in your own language.

  • Grants & Tenders

    AI reads the tender pack and pulls out the requirements, deadlines and rules - then helps you draft the response from your own approved content, with you reviewing every step.

  • Stakeholder/Vendor Management

    One current register of the suppliers and partners you depend on - each risk-assessed, re-assessing itself on schedule, and wired straight into your risk register.

  • Requirements Management

    See every requirement you face - across every standard, plus your own contracts and policies - traced to the documents, evidence and processes that satisfy it.

  • Risk Management

    Identify, score, treat and review your risks in one place - with AI to help anyone run a proper assessment, and a defensible trail behind every decision.

  • Training Management

    Assign training, prove it was understood, and hold the competence records an auditor asks for.

  • Document Control

    Draft compliance documents with AI, keep every version under control, and export them beautifully branded - all in one place.

  • Quality Management

    Audits, corrective actions, processes and approvals in one quality system, organised around ISO 9001.

Latest from ComplyTrain

Other standards in Life-cycle management and quality assurance

  • AACP-02AACP-02 guidelines for mutual provision of contract audits
  • AAP-20AAP-20 NATO programme management framework
  • AAP-48AAP-48 NATO system life cycle processes
  • ACMP-2000ACMP-2000 policy on configuration management
  • ACMP-2009ACMP-2009 guidance on configuration management
  • ACMP-2100ACMP-2100 configuration management contractual requirements

Compliance work does not have to live in documents and spreadsheets

See ComplyTrain on your own processes in a 30-minute demo, with your quality or compliance lead.