Who Can Release a Nonconforming Roll? Electronic Signatures and Separation of Duties in AS9100 (8.6, 8.7)

Published 8 October 2026 · 7 minute read

It is the end of the month on a composite line. A roll has a lab result still outstanding, the customer is waiting, and someone senior says "release it, the result will be fine." On paper, that release is a signature in a box. Six months later, during an audit or a customer complaint, nobody can show what the signer knew, what was still open, or whether the signer was the same person who ran the job.

AS9100D clause 8.6 says product is released only after the planned arrangements are complete, and that the records show who authorised the release. Clause 8.7 says nonconforming output is identified and controlled so it is not used or delivered by accident. Both are easy to write into a procedure. Both are hard to enforce with paper and spreadsheets, because nothing stops the box from being signed.

The examples below use a prepreg roll because that is the most concrete case. The same rules apply to a cure load, a heat-treat batch or a serial-numbered part.

What a release signature has to carry

An electronic signature is only better than ink if it carries more information and is harder to misuse. A release signature should record:

Binding the signature to a specific version of the record matters more than it sounds. If the record can be rebuilt or edited after the release, and the release silently follows it, the signature is approving something the signer never saw. The safer design is the opposite: if the record changes, the release no longer matches it, and anything downstream (such as the certificate of conformance) is refused until it is signed again.

The blockers list, and why there is no override

The most useful thing a release screen can do is tell the signer, in plain words, everything that is still open. For a composite roll the list typically includes:

If anything is on the list, nothing is signed. There is no "release anyway" button, for a simple reason: an override turns a control into a suggestion. An auditor who sees an override button will ask how often it is used, and the honest answer for most plants is "when we are busy".

That does not mean a blocked roll is stuck forever. It means each blocker has an owner and a proper route: the engineer declares the missing limits, the lab enters the result, Quality closes the hold, and a failed roll goes to a nonconformance with a recorded disposition. Each of those steps is recorded and, where it matters, signed. The release only happens when the list is empty, and the check runs again at the moment of signing, not just when the screen opened.

Separation of duties: the preparer is never the approver

Most quality failures that reach a customer are not fraud. They are a capable, busy person checking their own work. Separation of duties is the cheapest defence there is, and software should enforce it rather than leave it to the procedure:

Releases themselves are limited to the Quality role. Roles are checked on the server for every request, so hiding a button in the interface is not the only thing standing between a user and a signature.

Rejected stays rejected

Clause 8.7 is about making sure nonconforming product cannot reach a customer by accident. The weakest point in most systems is that a rejection is just a status, and a status can be changed back.

A rejection should be a signed decision with a reason, under the same signature rules as a release, and it should be final for that unit: no certificate, no later release, no path into a shipment. If the material really can be used, that is a nonconformance disposition by the review board ("use as is" or "rework"), recorded and signed by two people, not someone quietly flipping a status back.

The same logic applies upstream. A material lot rejected at incoming inspection should never be bindable to a machine. A roll made from a lot that was over its out-time can only be rejected.

What the finished goods lot should show

Customers order lots, and a lot usually holds many rolls or parts. When some units are released, some rejected and some still waiting for a lab result, the lot view should show exactly that, unit by unit: released, rejected, awaiting QA. Shipping then picks only released units, and a rejected roll cannot be added to a shipment by mistake.

This is also what makes the certificate of conformance trustworthy. A certificate generated from the signed record, listing the roll identity, recipe revision, lab results, the instruments used and the person who released it, is evidence. A certificate typed into a word-processor template afterwards is a copy of someone's memory.

Not just composites

The rules are the same whatever the unit. For machined parts, release is per serial number or lot, behind an approved first article for the part number and calibrated gauges. For special processes such as heat treatment, plating and NDT, each furnace or bath load gets its own record and its own signed release. For assembly, a serial-numbered assembly is released with the lots of every component behind it. See the AS9100 manufacturing overview for the full flow.

How PulseMQ does it

In PulseMQ, Quality releases a unit from its record screen. The server checks every blocker listed above when the release card opens and again at signing; if any one fails, the reasons are listed and nothing is signed. The signature asks for the password, a code from an authenticator app and a reason, and it binds the exact stored record, by version and hash. A rejected unit gets no certificate and cannot be released later. The finished goods view shows released, rejected and awaiting QA per unit, and the certificate of conformance is generated from the signed record. Every action lands in a hash-chained audit trail.

The record being signed is the one described in roll-level traceability for composite lines, and the first article and calibration gates are covered in first article inspection and calibration. For the general case of lot genealogy outside aerospace, see batch tracking and traceability.

PulseMQ keeps the evidence for clauses 8.6 and 8.7. It does not make a plant compliant or certify it; that remains the manufacturer's, and PulseMQ is qualified on your own process during a pilot.

Design partner program. We are looking for AS9100 manufacturers to pilot PulseMQ on one line, with your own Quality team signing real releases on your own process.

See the design partner program

Frequently asked

What makes an electronic release signature trustworthy?
It identifies the person with more than one factor (for example a password and a code from an authenticator app), records a reason, and is bound to the exact version of the record that was reviewed, so a later change to the record breaks the match instead of inheriting the approval.

Should a quality release ever be overridable?
An override turns a control into a suggestion. If a release is blocked, the blocker should be fixed or the product dispositioned through the nonconformance process, which is itself recorded and signed. A release check with an override button is evidence that the check can be bypassed.

Can a rejected roll be released later?
It should not be. A rejection is a disposition under clause 8.7. If the decision is reversible by a later release, the plant cannot show that nonconforming product was kept from use or delivery.

Who should be allowed to release product?
An authorised Quality person who did not produce or prepare the record being approved. The operator who ran the job, the person who created it, and anyone who took it over should not be able to release its output.