Which Documents Can Be Provided During Customer Audits? —— A Five-Step Method for Document Classification and External Control

By: QTank Published: 10/2/2026 Views: 30
Current rating: ★★★☆☆ Rate this Equivalent to 8 ratings

"Send me a copy of your quality manual." "Pack the control plan, PFMEA, and work instructions, we need to conduct a supplier evaluation." "The tender document requires the provision of inspection data statistics for the past three years."

Quality professionals receive such requests multiple times a year. If you provide the documents, process parameters, yield levels, and cost structures will be leaked; if you don't, the customer auditor might issue a nonconformity for "lack of cooperation," and the company might lose points in the tender. One company once suffered a significant loss: after a customer audit, the quality engineer, to save time, sent the control plan along with the internal yield analysis page. Two months later, a competitor's quotation appeared with almost identical process routes. The documents were indeed sent, but from the beginning to the end, no one had established rules for "who can see this, who can receive it, and to what extent."

The real issue is not a binary choice between "confidentiality or cooperation." Most companies manage documented information in only two ways: approval and distribution. Whether the version is correct, whether there are old versions on-site, and whether the old versions have been accounted for can be managed; however, "who owns this document, and who can access it" is often a blank slate. ISO 9001 clearly states in 7.5.3.1 that the control of documented information should cover "distribution, access, retrieval, and use," and "prevent the unintended use of obsolete versions." In 8.4.3, it further requires that information communicated to external suppliers must be controlled. The annotation in 7.5.3 explicitly mentions "preventing leaks." In other words, classification and external control are not additional compliance actions outside ISO; they are inherent parts of documented information control that most companies overlook.

1. Before Grading, Clarify the "Three Can"

The goal of documented information control can be broken down into three parallel "cans":

  • Can Prove Effectiveness: The on-site version is the valid one, and old versions are not misused—this is the most familiar dimension.
  • Can Achieve Accessibility: The right people can always find, retrieve, and review the information—this determines whether the system is "alive."
  • Can Control Confidentiality: Unauthorized individuals cannot access the information, and uncontrolled external distribution is prevented—this is the most easily overlooked dimension.

There is a natural tension between these three "cans." If confidentiality is taken to the extreme, files are locked in cabinets, and electronic documents are accessible only to department heads, resulting in auditors waiting half an hour for three documents and engineers preferring to work according to old habits, turning the system documentation into "wall documents." Conversely, if "cooperation" is taken to the extreme, providing any requested document to anyone, the company's accumulated process know-how becomes an open course. The essence of classification and external control is to draw a line between these two extremes that is justified, explainable, and traceable.

The principle for drawing this line is need to know, not by level, seniority, or "we're all in the same family." To determine who should receive a document, ask three questions:

  1. What work does this person/organization need to complete using this information? Information unrelated to the work is not provided, even to internal employees.
  2. What are the consequences of a leak? The consequences determine the classification level, which in turn determines the control intensity.
  3. Can I bear the risk of providing this level? If not, escalate to a higher level or provide a desensitized version.

The value of these three questions lies in transforming the decision of "whether to provide" from a subjective, relationship-based judgment into a rule that can be written into procedures and clearly explained to customers. When a customer auditor asks, "Why don't you provide this document," you can respond, "This document contains process parameters and is classified as internal. The customer version is provided after desensitization based on the principle of minimum necessity," rather than simply saying, "The leader said not to provide it," which would yield very different results.

2. How to Determine Classification: A Four-Level Model and Criteria

Classification does not need to be overly complex; four levels are sufficient for most manufacturing companies. The key is not the attractiveness of the names but the clear criteria and accompanying carrier requirements for each level.

Classification Level Criteria (Meeting Any One) Typical Objects Visible Scope Carrier and External Distribution Requirements
Public Does external publication pose a risk? No Company introduction, quality policy, publicly disclosed system certificates Anyone Can be provided directly without approval
Internal Will a leak allow competitors to replicate practices? Yes Procedure documents, work instructions, general inspection specifications, training materials All employees (access based on position) Internal circulation; external distribution requires department head approval
Secret Will a leak expose process know-how, capability levels, or customer information? Yes Control plans, PFMEAs, process parameter tables, yield and capability data, customer drawings, cost/quote-related files Position-related individuals + department head External distribution requires joint approval from quality and technical heads; must be desensitized, numbered, and traceable
Confidential Will a leak impact the company's core competitiveness or constitute a breach of contract? Yes Formulas, core process windows, full parameters of special characteristics, content covered by confidentiality agreements with customers, and materials of unreleased projects Designated authorized individuals (list-based) Generally not distributed externally; if necessary, must be approved by the general manager + confidentiality agreement + traceable watermark

When classifying, it is recommended to follow two principles. First, classify higher rather than lower, and document it. The classification conclusion must be recorded in the "Classification Level" column of the Documented Information List, not just in someone's mind. The list should also record the document number, version, controlled status, storage location, responsible person, and classification level—this table serves as the basis for all subsequent external distribution approvals. Second, the classification results should be understandable to customers but not reset by them. Customers often request, "Send us your complete system documents for review." The correct response is not to refuse but to break down the request: public and internal procedure documents can be provided, secret control plans can be provided in a desensitized version based on the actual needs of the customer audit, and confidential content can be reviewed on-site without being taken away. This approach meets the substantive purpose of the audit without handing over the company's entire information asset.

Incidentally, customer drawings and process files provided by customers fall under 8.5.3 Customer Property. They should be managed separately, labeled, and archived according to the customer's specified classification level. Losing or leaking such information is a breach of contract for the customer and a liability for the company.

3. Five-Step Method for External Control

Classification is just about drawing the line; the real prevention of information leakage lies in the actions taken during external distribution. The following five steps, when followed in sequence, typically complete the first round in 4 to 6 weeks.

Step One: Inventory and Classification, Produce the Documented Information List. Collect from three sources: the main list of controlled documents, documents currently in use by departments but not yet controlled (these are often the most problematic), and the directory tree in the electronic shared drive. Mark each document with its classification level, responsible person, and storage location. The inventory does not need to be perfect from the start; covering the five high-risk categories—control plans, PFMEAs, process documents, drawings, and inspection data—can prevent the majority of leakage scenarios.

Step Two: Define Export and Authorization Matrix. Clearly define "who can approve and to what level," and allow only one external export point—usually set in the quality department or technical management position—to avoid departments independently distributing documents and no one being aware afterward. The authorization matrix is best presented in a table:

Requester Public Internal Secret Confidential
Customer (Audit/Production Needs) Position directly provides Department head Joint approval by quality and technical heads, desensitized version provided General manager approval, on-site review primarily
Customer (Quotation/Business Stage) Directly provided Department head Generally not provided Not provided
External Supplier Directly provided Department head Controlled copies provided as needed Not provided
Certification/Audit Agency Directly provided Directly provided On-site review On-site review
Tender/Bid Requirements Directly provided Department head + business co-signature Desensitized version provided Item-by-item assessment

Step Three: Desensitization and Creation of External Distribution Copies. External versions must not be "Save As" versions of internal documents. The standard actions are fourfold: delete—remove pages unrelated to the request (cost pages, yield pages, other customer information, internal notes columns); generalize—convert precise parameters to ranges or levels (e.g., "Cpk≥1.33" instead of the actual 1.72); label—add a unique number and "external provision, no forwarding" to each external document, and add a watermark (recipient name + date) to electronic documents; limit—specify the purpose and validity period in the document or email, such as "for this supplier evaluation only, feedback within 30 days." One company turned these actions into a Desensitization Checklist for External Documents, requiring all five items to be checked before distribution, significantly reducing the risk of leakage.

Step Four: Traceability and Ledger. Every external distribution must leave a traceable record: requester and reason, document number and version, classification level, desensitization status, delivery method (email/paper/system download link), delivery date, agreed purpose, and return requirements. The value of the ledger is twofold: first, it allows immediate response to customer inquiries about when a specific version of a control plan was provided; second, it helps quickly narrow down the scope and identify specific batches in case of abnormal leakage.

Step Five: Recovery, Exit, and Destruction Loop. Paper documents must be recovered and reconciled after the agreed-upon matters are completed. If recovery is not possible, the disposal method must be confirmed in writing. Electronic documents must have download links closed and copies withdrawn upon expiration. More crucial are the two types of "exit": when an employee leaves, their document access permissions must be revoked, local copies cleared, and a confidentiality confirmation signed if necessary; when external supplier cooperation ends, they must return or destroy the controlled documents provided by the company and provide written confirmation. If these two points are not sealed, the efforts of the previous four steps will be negated within six months.

4. Six Common Pitfalls

Pitfall One: Equating "Confidential" with "Not Providing." During customer audits, all document requests are blocked with "internal materials." In the short term, this protects information, but in the long term, it pushes customer relationships to the opposite side. The purpose of classification is precise authorization, not a complete lockdown.

Pitfall Two: Only One Classification Level. All documents are either "internal materials" or "confidential pending approval," resulting in all documents following the same approval path. Important documents are not approved, and unimportant ones get stuck halfway, leading everyone to bypass the process and distribute privately.

Pitfall Three: Uncontrolled External Distribution Versions. The customer receives a three-month-old control plan, conducts incoming inspection based on the old version, and rejects a batch of qualified materials, sending a claim directly to the company. External documents must be labeled with the version and date in both the file name and the header of the document and archived to correspond with the internal valid version.

Pitfall Four: Electronic Permissions Follow Positions, Not Revoked Upon Departure. Shared drive permissions are granted once and remain valid indefinitely. Employees can still access all documents from their original departments after a job transfer, and accounts remain active for six months after departure. Permissions should be reviewed at least annually, and "permission revocation" should be a mandatory step in the departure process.

Pitfall Five: Watermarks and Numbers Only on Paper Documents. Paper documents are strictly controlled, but PDFs and Excel files are distributed without controls, allowing a screenshot to bypass all controls. The external control intensity for electronic documents should not be lower than that for paper documents.

Pitfall Six: Only Approval, No Ledger. Approval forms are signed, but no one knows who received what. When a customer complains about information leakage, the company cannot trace the source or provide evidence that "we have fulfilled our control obligations," leaving it completely passive in negotiations.

5. A Case Study: Two Days to Block an Export

A car parts company with over 400 employees and a Tier 2 supplier faced two nonconformities after a customer process audit: one for "failure to provide evidence of control over the distribution and access of documented information," and another for "external information not verified for sufficiency." The audit leader also requested that the control plan and process documents be bundled and provided for the customer's supplier capability assessment.

The company's initial reaction was to comply fully—since the audit was already underway, the customer would get whatever they asked for. The quality manager changed the course: he spent half a day reviewing the documents to be distributed, discovering that the compressed file contained not only the control plan but also detailed process parameters, process capability data from the past three months, and an internal meeting minutes document (which mentioned the actual yield of two production lines and the main customer share).

Over the next two days, the company took three actions. First, they broke down the request into three categories: procedure documents and work instructions were provided in their original versions; the control plan had internal notes and capacity information removed, retaining only the characteristics, specifications, occurrence, and reaction plans needed for the customer audit; process parameters and yield data were not provided, but the quality manager and customer engineer discussed key control strategies in an online meeting, followed by a one-page summary. Second, they established a unique number and ledger for this external distribution, recording the scope of provision, version, delivery date, and agreed purpose, and specified in the email, "for this supplier capability assessment only." Third, they solidified these actions into a Desensitization Checklist for External Documents and an authorization matrix, incorporating them into the document control procedure as evidence for the corrective actions for the two nonconformities.

Audit Result: Both nonconformities were closed as planned. The customer was not dissatisfied with the narrowed scope but instead listed the company as a "more standardized document management" example in the next round of reviews. The company subsequently found that the proportion of externally distributed documents containing internal parameters dropped from about 70% before the rectification to less than 20%, without a significant increase in the time required for audit cooperation—because the inventory, desensitization, and traceability processes were streamlined, making it faster than the previous "last-minute search and casual distribution."

The highest level of document control is not locking everything away but ensuring that any document can clearly state "who it belongs to, who can see it, and who has seen it"—controlling the entry point through classification, the exit point through external control, and the traceability through a ledger.


Document control starts with classification and defining the export point

Knowledge code: 2.3.1

Version: v20261002

Author: QTank QTank is dedicated to providing systematic knowledge, methodologies, and practical tools for quality management professionals, helping companies continuously improve their quality capabilities.