Supply Chain Traceability: What to Send Suppliers and What to Get Back
The Essential Guide to Requirements Management and Traceability
Chapters
- 1. Requirements Management
- Overview
- 1 What is Requirements Management? A Complete Guide
- 2 Why do you need Requirements Management?
- 3 Four Stages of Requirements Management Processes
- 4 Adopting Agile Requirements Management Tools
- 5 Status Request Changes
- 6 Conquering the 5 Biggest Challenges of Requirements Management
- 7 Three Reasons You Need a Requirements Management Solution
- 8 Guide to Poor Requirements: Identify Causes, Repercussions, and How to Fix Them
- 9 What Is a Requirements Management Plan? A Practical Guide
- 10 Enterprise Requirements Management: Keeping Traceability Current
- 2. Writing Requirements
- Overview
- 1 Functional requirements examples and templates
- 2 What Is a Product Requirements Document? A Complete PRD Guide
- 3 What Is a User Requirement Specification (URS)? How to Write and Manage One
- 4 Identifying and Measuring Requirements Quality
- 5 How to Write a System Requirements Specification (SRS) Document
- 6 The Fundamentals of Business Requirements: Examples of Business Requirements and the Importance of Excellence
- 7 Adopting the EARS Notation to Improve Requirements Engineering
- 8 What Is a Compliance Risk Assessment? Steps, Framework, and Examples
- 9 Jama Connect Advisor™
- 10 Frequently Asked Questions about the EARS Notation and Jama Connect Advisor™
- 11 How to Write an Effective Product Requirements Document (PRD)
- 12 Functional vs. Non-Functional Requirements
- 13 What Are Nonfunctional Requirements and How Do They Impact Product Development?
- 14 What Is a Software Design Specification? Key Components + Template
- 15 Characteristics of Effective Software Requirements and Software Requirements Specifications (SRS)
- 16 8 Do’s and Don’ts for Writing Requirements
- 17 Project Requirements: Types, Process, and Best Practices
- 18 INCOSE Guide to Writing Requirements
- 19 How to Write Technical Requirements That Survive Verification
- 3. Requirements Gathering and Management Processes
- Overview
- 1 Requirements Engineering
- 2 Requirements Analysis
- 3 A Guide to Requirements Elicitation for Product Teams
- 4 Requirements Gathering Techniques for Agile Product Teams
- 5 Requirements Gathering in Software Engineering: Process, Techniques, and Best Practices
- 6 Defining and Implementing a Requirements Baseline
- 7 Managing Project Scope — Why It Matters and Best Practices
- 8 Requirements Decomposition and How AI Supports It
- 9 How Long Do Requirements Take?
- 10 How to Reuse Requirements Across Multiple Products
- 11 Requirements Prioritization Techniques: 7 Methods for Engineers
- 12 How to Run a Requirements Gathering Workshop
- 4. Requirements Traceability
- Overview
- 1 What Is Traceability in Product Development? A Guide for Regulated Teams
- 2 Tracing Your Way to Success: The Crucial Role of Traceability in Modern Product and Systems Development
- 3 Bidirectional Traceability: What It Is and How to Implement It
- 4 Change Impact Analysis (CIA): A Short Guide for Effective Implementation
- 5 What is Engineering Change Management (ECM)? A Complete Guide
- 6 What is Meant by Version Control?
- 7 Key Traceability Challenges and Tips for Ensuring Accountability and Efficiency
- 8 The Role of a Data Thread in Product and Software Development
- 9 Unraveling the Digital Thread: Enhancing Connectivity and Efficiency
- 10 What is a Traceability Matrix? A Guide to Requirements Traceability
- 11 How to Create and Use a Requirements Traceability Matrix (RTM)
- 12 Requirements Traceability Matrix Pros and Cons: A Practical Guide
- 13 Live Traceability vs. After-the-Fact Traceability
- 14 Overcoming Barriers to Live Requirements Traceability™
- 15 Requirements Traceability, What Are You Missing?
- 16 Requirements Traceability: Links in the Chain
- 17 What Are the Benefits of End-to-End Traceability During Product Development?
- 18 Requirements Volatility: 7 Essential Management Strategies
- 19 FAQs About Requirements Traceability
- 20 What Is AI Traceability? How to Implement It
- 21 Product Traceability for Regulated Industries: A Complete Guide to Audit-Ready Compliance
- 22 What Is the Traceability Information Model?
- 23 Supply Chain Traceability: What to Send Suppliers and What to Get Back
- 24 What Is an Engineering Change Order (ECO)?
- 5. Requirements Management Tools and Software
- Overview
- 1 Selecting the Right Requirements Management Tools and Software
- 2 Why Investing in Requirements Management Software Makes Business Sense During an Economic Downturn
- 3 Why Word and Excel Alone is Not Enough for Product, Software, and Systems Development
- 4 Can You Track Requirements in Excel?
- 5 What Is Application Lifecycle Management (ALM)?
- 6 Is There Life After DOORS®?
- 7 Requirements Management Tools Jira
- 8 Checklist: Selecting a Requirements Management Tool
- 6. Requirements Validation and Verification
- 7. Meeting Regulatory Compliance and Industry Standards
- Overview
- 1 Understanding ISO Standards
- 2 Understanding ISO/IEC 27001: A Guide to Information Security Management
- 3 What is DevSecOps? A Guide to Building Secure Software
- 4 Compliance Management
- 5 What Is Functional Safety (FuSa)? Standards, Lifecycle, and Where Programs Fail
- 6 Failure Mode and Effects Analysis (FMEA) Explained
- 7 TÜV SÜD: Ensuring Safety, Quality, and Sustainability Worldwide
- 8 What is IEC 62443? A Guide to Industrial Cybersecurity
- 9 DFARS Compliance: A Guide for Defense Contractors
- 10 CMMC vs FedRAMP: What’s Different and Which One Applies to You
- 11 Automotive SPICE (ASPICE) 4.0: A Complete Guide
- 12 Restriction of Hazardous Substances (RoHS) Compliance Guide
- 13 MISRA C and MISRA C++ Explained: Rules for Safer Embedded Code
- 14 REACH Compliance for Product Engineering Teams
- 15 Radio Equipment Directive (RED) Cybersecurity Requirements
- 8. Systems Engineering
- Overview
- 1 What is Systems Engineering? A Guide for Modern Engineering Teams
- 2 How Do Engineers Collaborate? A Guide to Streamlined Teamwork and Innovation
- 3 The Systems Engineering Body of Knowledge (SEBoK)
- 4 What Is MBSE? Model-Based Systems Engineering Explained
- 5 Digital Engineering Between Government and Contractors
- 6 Digital Engineering Tools: The Key to Driving Innovation and Efficiency in Complex Systems
- 7 What Is Bill of Materials (BOM) Management? A Guide to Controlling Product Data
- 9. Automotive Development
- Overview
- 1 Understanding IATF 16949: A Quick Guide to Automotive Quality Management
- 2 What Is ISO 21434? Automotive Cybersecurity Engineering Explained
- 3 What Is ISO 26262? A Guide to Functional Safety in Automotive
- 4 What Is ASIL? A Guide to Automotive Safety Integrity Levels in ISO 26262
- 5 What Is SOTIF? A Guide to ISO 21448 for ADAS Safety
- 10. Medical Device & Life Sciences Development
- Overview
- 1 The Importance of Benefit-Risk Analysis in Medical Device Development
- 2 Software as a Medical Device: Revolutionizing Healthcare
- 3 What’s a Design History File, and How Are DHFs Used by Product Teams?
- 4 Navigating the Risks of Software of Unknown Pedigree (SOUP) in the Medical Device & Life Sciences Industry
- 5 What Is ISO 13485? A Guide to Medical Device Quality Management Systems
- 6 What Is a Device Master Record (DMR)? Definition and FDA Requirements
- 7 What Is IEC 62304? Medical Software Guide
- 8 ISO 13485 vs ISO 9001: Understanding the Differences and Synergies
- 9 What You Need to Know: ANSI/AAMI SW96:2023 — Medical Device Security
- 10 Failure Modes, Effects, and Diagnostic Analysis (FMEDA) for Medical Devices: What You Need to Know
- 11 Embracing the Future of Healthcare: Exploring the Internet of Medical Things (IoMT)
- 12 What Is General Safety and Performance Requirements (GSPR)? What You Need To Know
- 13 What Is IEC 62366? Usability Engineering for Medical Devices
- 14 What Is the Quality Management System Regulation (QMSR)?
- 15 510(k) vs PMA: Differences in FDA Device Approval and Clearance
- 16 EU MDR Compliance Requirements and Timeline
- 17 Essential Performance Requirements and How to Identify Them
- 18 DHF vs DMR vs DHR: What Changed Under the FDA QMSR
- 19 Computer Software Assurance for Production and Quality Systems
- 20 IVDR Compliance: What Manufacturers Need to Know
- 21 IEC 60601-1 Guide for Medical Devices
- 22 A Guide to Medical Device Requirements Management
- 11. Aerospace & Defense Development
- Overview
- 1 What is ITAR Compliance? What Engineering Teams Need to Know
- 2 What Is DO-278A? A Guide for Compliance Teams
- 3 ARP4754B Explained: Changes, Recognition, and Compliance
- 4 What Is a Safety Integrity Level (SIL)? How to Calculate and Apply It
- 5 A Guide to Aerospace Requirements Management
- 6 What Is ARP4754A? A Complete Guide to Civil Aircraft and Systems Development Assurance
- 7 Understanding ARP4761A: Guidelines for System Safety Assessment in Aerospace
- 8 What Is DO-254? A Complete Guide to Airborne Hardware Design Assurance
- 9 What Is DO-178C? A Guide to Airborne Software Certification
- 12. Architecture, Engineering, and Construction (AEC industry) Development
- 13. Industrial Manufacturing & Machinery, Automation & Robotics, Consumer Electronics, and Energy
- 14. Semiconductor Development
- 15. AI in Product Development
- Overview
- 1 What Is AI in Product Development? A Complete 2026 Guide
- 2 AI Test Case Generation: A Complete Guide for Regulated QA Teams
- 3 Using AI to Write Software Requirements: What Works and What Doesn’t
- 4 What Is the Model Context Protocol (MCP) for Requirements Management?
- 5 AI for Systems Engineering: Benefits, Risks, and How to Start
- 6 How to Automate Requirements Management
- 7 Artificial Intelligence in Requirements Management
- 16. Risk Management
- 17. Product Development Terms and Definitions
Chapter 4: Supply Chain Traceability: What to Send Suppliers and What to Get Back
Chapters
- 1. Requirements Management
- Overview
- 1 What is Requirements Management? A Complete Guide
- 2 Why do you need Requirements Management?
- 3 Four Stages of Requirements Management Processes
- 4 Adopting Agile Requirements Management Tools
- 5 Status Request Changes
- 6 Conquering the 5 Biggest Challenges of Requirements Management
- 7 Three Reasons You Need a Requirements Management Solution
- 8 Guide to Poor Requirements: Identify Causes, Repercussions, and How to Fix Them
- 9 What Is a Requirements Management Plan? A Practical Guide
- 10 Enterprise Requirements Management: Keeping Traceability Current
- 2. Writing Requirements
- Overview
- 1 Functional requirements examples and templates
- 2 What Is a Product Requirements Document? A Complete PRD Guide
- 3 What Is a User Requirement Specification (URS)? How to Write and Manage One
- 4 Identifying and Measuring Requirements Quality
- 5 How to Write a System Requirements Specification (SRS) Document
- 6 The Fundamentals of Business Requirements: Examples of Business Requirements and the Importance of Excellence
- 7 Adopting the EARS Notation to Improve Requirements Engineering
- 8 What Is a Compliance Risk Assessment? Steps, Framework, and Examples
- 9 Jama Connect Advisor™
- 10 Frequently Asked Questions about the EARS Notation and Jama Connect Advisor™
- 11 How to Write an Effective Product Requirements Document (PRD)
- 12 Functional vs. Non-Functional Requirements
- 13 What Are Nonfunctional Requirements and How Do They Impact Product Development?
- 14 What Is a Software Design Specification? Key Components + Template
- 15 Characteristics of Effective Software Requirements and Software Requirements Specifications (SRS)
- 16 8 Do’s and Don’ts for Writing Requirements
- 17 Project Requirements: Types, Process, and Best Practices
- 18 INCOSE Guide to Writing Requirements
- 19 How to Write Technical Requirements That Survive Verification
- 3. Requirements Gathering and Management Processes
- Overview
- 1 Requirements Engineering
- 2 Requirements Analysis
- 3 A Guide to Requirements Elicitation for Product Teams
- 4 Requirements Gathering Techniques for Agile Product Teams
- 5 Requirements Gathering in Software Engineering: Process, Techniques, and Best Practices
- 6 Defining and Implementing a Requirements Baseline
- 7 Managing Project Scope — Why It Matters and Best Practices
- 8 Requirements Decomposition and How AI Supports It
- 9 How Long Do Requirements Take?
- 10 How to Reuse Requirements Across Multiple Products
- 11 Requirements Prioritization Techniques: 7 Methods for Engineers
- 12 How to Run a Requirements Gathering Workshop
- 4. Requirements Traceability
- Overview
- 1 What Is Traceability in Product Development? A Guide for Regulated Teams
- 2 Tracing Your Way to Success: The Crucial Role of Traceability in Modern Product and Systems Development
- 3 Bidirectional Traceability: What It Is and How to Implement It
- 4 Change Impact Analysis (CIA): A Short Guide for Effective Implementation
- 5 What is Engineering Change Management (ECM)? A Complete Guide
- 6 What is Meant by Version Control?
- 7 Key Traceability Challenges and Tips for Ensuring Accountability and Efficiency
- 8 The Role of a Data Thread in Product and Software Development
- 9 Unraveling the Digital Thread: Enhancing Connectivity and Efficiency
- 10 What is a Traceability Matrix? A Guide to Requirements Traceability
- 11 How to Create and Use a Requirements Traceability Matrix (RTM)
- 12 Requirements Traceability Matrix Pros and Cons: A Practical Guide
- 13 Live Traceability vs. After-the-Fact Traceability
- 14 Overcoming Barriers to Live Requirements Traceability™
- 15 Requirements Traceability, What Are You Missing?
- 16 Requirements Traceability: Links in the Chain
- 17 What Are the Benefits of End-to-End Traceability During Product Development?
- 18 Requirements Volatility: 7 Essential Management Strategies
- 19 FAQs About Requirements Traceability
- 20 What Is AI Traceability? How to Implement It
- 21 Product Traceability for Regulated Industries: A Complete Guide to Audit-Ready Compliance
- 22 What Is the Traceability Information Model?
- 23 Supply Chain Traceability: What to Send Suppliers and What to Get Back
- 24 What Is an Engineering Change Order (ECO)?
- 5. Requirements Management Tools and Software
- Overview
- 1 Selecting the Right Requirements Management Tools and Software
- 2 Why Investing in Requirements Management Software Makes Business Sense During an Economic Downturn
- 3 Why Word and Excel Alone is Not Enough for Product, Software, and Systems Development
- 4 Can You Track Requirements in Excel?
- 5 What Is Application Lifecycle Management (ALM)?
- 6 Is There Life After DOORS®?
- 7 Requirements Management Tools Jira
- 8 Checklist: Selecting a Requirements Management Tool
- 6. Requirements Validation and Verification
- 7. Meeting Regulatory Compliance and Industry Standards
- Overview
- 1 Understanding ISO Standards
- 2 Understanding ISO/IEC 27001: A Guide to Information Security Management
- 3 What is DevSecOps? A Guide to Building Secure Software
- 4 Compliance Management
- 5 What Is Functional Safety (FuSa)? Standards, Lifecycle, and Where Programs Fail
- 6 Failure Mode and Effects Analysis (FMEA) Explained
- 7 TÜV SÜD: Ensuring Safety, Quality, and Sustainability Worldwide
- 8 What is IEC 62443? A Guide to Industrial Cybersecurity
- 9 DFARS Compliance: A Guide for Defense Contractors
- 10 CMMC vs FedRAMP: What’s Different and Which One Applies to You
- 11 Automotive SPICE (ASPICE) 4.0: A Complete Guide
- 12 Restriction of Hazardous Substances (RoHS) Compliance Guide
- 13 MISRA C and MISRA C++ Explained: Rules for Safer Embedded Code
- 14 REACH Compliance for Product Engineering Teams
- 15 Radio Equipment Directive (RED) Cybersecurity Requirements
- 8. Systems Engineering
- Overview
- 1 What is Systems Engineering? A Guide for Modern Engineering Teams
- 2 How Do Engineers Collaborate? A Guide to Streamlined Teamwork and Innovation
- 3 The Systems Engineering Body of Knowledge (SEBoK)
- 4 What Is MBSE? Model-Based Systems Engineering Explained
- 5 Digital Engineering Between Government and Contractors
- 6 Digital Engineering Tools: The Key to Driving Innovation and Efficiency in Complex Systems
- 7 What Is Bill of Materials (BOM) Management? A Guide to Controlling Product Data
- 9. Automotive Development
- Overview
- 1 Understanding IATF 16949: A Quick Guide to Automotive Quality Management
- 2 What Is ISO 21434? Automotive Cybersecurity Engineering Explained
- 3 What Is ISO 26262? A Guide to Functional Safety in Automotive
- 4 What Is ASIL? A Guide to Automotive Safety Integrity Levels in ISO 26262
- 5 What Is SOTIF? A Guide to ISO 21448 for ADAS Safety
- 10. Medical Device & Life Sciences Development
- Overview
- 1 The Importance of Benefit-Risk Analysis in Medical Device Development
- 2 Software as a Medical Device: Revolutionizing Healthcare
- 3 What’s a Design History File, and How Are DHFs Used by Product Teams?
- 4 Navigating the Risks of Software of Unknown Pedigree (SOUP) in the Medical Device & Life Sciences Industry
- 5 What Is ISO 13485? A Guide to Medical Device Quality Management Systems
- 6 What Is a Device Master Record (DMR)? Definition and FDA Requirements
- 7 What Is IEC 62304? Medical Software Guide
- 8 ISO 13485 vs ISO 9001: Understanding the Differences and Synergies
- 9 What You Need to Know: ANSI/AAMI SW96:2023 — Medical Device Security
- 10 Failure Modes, Effects, and Diagnostic Analysis (FMEDA) for Medical Devices: What You Need to Know
- 11 Embracing the Future of Healthcare: Exploring the Internet of Medical Things (IoMT)
- 12 What Is General Safety and Performance Requirements (GSPR)? What You Need To Know
- 13 What Is IEC 62366? Usability Engineering for Medical Devices
- 14 What Is the Quality Management System Regulation (QMSR)?
- 15 510(k) vs PMA: Differences in FDA Device Approval and Clearance
- 16 EU MDR Compliance Requirements and Timeline
- 17 Essential Performance Requirements and How to Identify Them
- 18 DHF vs DMR vs DHR: What Changed Under the FDA QMSR
- 19 Computer Software Assurance for Production and Quality Systems
- 20 IVDR Compliance: What Manufacturers Need to Know
- 21 IEC 60601-1 Guide for Medical Devices
- 22 A Guide to Medical Device Requirements Management
- 11. Aerospace & Defense Development
- Overview
- 1 What is ITAR Compliance? What Engineering Teams Need to Know
- 2 What Is DO-278A? A Guide for Compliance Teams
- 3 ARP4754B Explained: Changes, Recognition, and Compliance
- 4 What Is a Safety Integrity Level (SIL)? How to Calculate and Apply It
- 5 A Guide to Aerospace Requirements Management
- 6 What Is ARP4754A? A Complete Guide to Civil Aircraft and Systems Development Assurance
- 7 Understanding ARP4761A: Guidelines for System Safety Assessment in Aerospace
- 8 What Is DO-254? A Complete Guide to Airborne Hardware Design Assurance
- 9 What Is DO-178C? A Guide to Airborne Software Certification
- 12. Architecture, Engineering, and Construction (AEC industry) Development
- 13. Industrial Manufacturing & Machinery, Automation & Robotics, Consumer Electronics, and Energy
- 14. Semiconductor Development
- 15. AI in Product Development
- Overview
- 1 What Is AI in Product Development? A Complete 2026 Guide
- 2 AI Test Case Generation: A Complete Guide for Regulated QA Teams
- 3 Using AI to Write Software Requirements: What Works and What Doesn’t
- 4 What Is the Model Context Protocol (MCP) for Requirements Management?
- 5 AI for Systems Engineering: Benefits, Risks, and How to Start
- 6 How to Automate Requirements Management
- 7 Artificial Intelligence in Requirements Management
- 16. Risk Management
- 17. Product Development Terms and Definitions
Supply Chain Traceability: What to Send Suppliers and What to Get Back
In February 2026, a United Kingdom court sentenced the director of AOG Technics to four years and eight months in prison. Between January 2019 and July 2023 his company sold over 60,000 aircraft engine parts, most of them for the CFM56, with forged Authorised Release Certificates. Groundings cost airlines and manufacturers an estimated £39.3 million. Every buyer in that chain took a release certificate at face value. The fraud came to light when an airline checked a certificate with the engine manufacturer.
Traceability holds up inside one company and breaks where two companies meet. No file format carries everything the receiving side needs, and the contracts and change notifications meant to cover the difference are agreed before anyone knows which attributes will move. Supplier audit reports lost their exemption from a United States device inspection on February 2, 2026, and defense electronics suppliers came under a new record-retention standard in November 2025.
This guide covers what medical device and aerospace inspectors now expect of supplier controls, how requirements cross the original equipment manufacturer (OEM) to supplier boundary, and where the chain breaks.
What Supply Chain Traceability Means for Requirements
In regulated product development, supply chain traceability is an engineering question about whether the thing a supplier delivered satisfies the requirement allocated to it, and whether anyone verified that it did. Product traceability in regulated industries answers the unit-level question of where a lot or serial number went, and this guide answers the requirements question that runs alongside it.
Forward and Backward Links Across the Chain
Forward links run from every requirement to its implementation, including the design element and component that satisfy it, and then to the applicable test. ISO/IEC/IEEE 29148 prescribes that chain, a requirements engineering standard published jointly by the International Organization for Standardization (ISO), the International Electrotechnical Commission (IEC) and the Institute of Electrical and Electronics Engineers (IEEE). Backward traceability links connect each artifact to the source requirement that justifies it.
Four Kinds of Artifact the Chain Covers
For a regulated product with suppliers, the chain covers four kinds of artifact:
- Requirements: User needs flowed down through system and subsystem layers to components, with the allocation recorded on both sides.
- Parts and lots: Records cover physical components and material certifications, and they are what survives a counterfeit-part inquiry.
- Software components: Software of Unknown Provenance (SOUP), commercial off-the-shelf (COTS) code and open-source libraries are identified by name, version and manufacturer.
- Test evidence: Verification and validation records that link back to the specific requirement and version they verified.
Which Standards Require Traceable Links
Software Considerations in Airborne Systems and Equipment Certification (DO-178C) requires bidirectional traceability across requirements and source code, with links to test evidence. Design Assurance Guidance for Airborne Electronic Hardware (DO-254) carries the same obligation on the hardware side.
ISO 26262, the road-vehicle functional safety standard, expects traceable links running from safety goals through technical safety requirements to verification. Under IEC 62304, the medical device software lifecycle standard, and the Quality Management System Regulation (QMSR) that now governs United States device manufacturers, software requirements and risk analysis need traceable links to design outputs.
What Inspectors and Auditors Now Expect From Supplier Controls
Records that used to sit outside a United States device inspection are now inside it, and in aerospace and defense the duty to prove where a part came from reaches every tier by contract. Both changes landed within the last two years.
Medical Devices Under the QMSR
The QMSR took effect on February 2, 2026, and amends Title 21 of the Code of Federal Regulations Part 820 by incorporating ISO 13485:2016 by reference. ISO 13485:2016 Clause 7.4 now carries the supplier duties. It requires documented selection and re-evaluation criteria, verification proportionate to risk, and a written agreement that the supplier notify the manufacturer of changes affecting the purchased product before implementing them.
A one-time qualification record doesn’t satisfy the ongoing monitoring obligation, and approval needs reassessment when enforcement action, an ownership change, or new critical subcontracting alters the supplier’s risk profile. Between them, those requirements pull a supplier inside the manufacturer’s own change management process.
FDA retired the Quality System Inspection Technique on the same date and replaced it with Compliance Program 7382.850. Investigators review a manufacturer’s risk management documentation throughout an inspection to understand product risks and controls. The QMSR also removed the exemption at 820.180(c) that used to keep supplier audit reports, quality audits and management reviews out of an FDA inspection.
Aerospace and Defense Part Provenance
AS9100 Rev D’s purchasing flow-down clause requires primes to pass counterfeit-part prevention, nonconformance and change notification, and right-of-access terms down to every tier of the supply chain. For electronic parts on defense contracts, Defense Federal Acquisition Regulation Supplement (DFARS clause 252.246-7007) requires a detection and avoidance system that tracks electronic parts from the original manufacturer to government acceptance. The requirement flows down to subcontractor tiers that buy, sell or authenticate electronic parts or assemblies containing them.
SAE International AS5553E, current since November 2025, extends the same flow-down to companies that procure and integrate electrical, electronic, and electromechanical parts and adds record retention requirements. A provenance chain connects the received part to its manufacturer and purchasing records, and links the inspection or authentication evidence to the assembly the part went into.
How Requirements and Evidence Cross the OEM-to-Supplier Boundary
An interface agreement between the two companies defines which requirements and evidence the OEM sends and which the supplier returns.
Interface Agreements Assign the Work Products
The Development Interface Agreement (DIA) in ISO 26262 assigns responsibility for each work product exchanged between customer and supplier. When the OEM allocates safety requirements, the supplier’s verification evidence needs to trace through a shared or linked requirements traceability matrix to the OEM’s safety goals. ISO/SAE 21434 does the same for cybersecurity with the Cybersecurity Interface Agreement (CIA). A useful CIA names the allocated activities, the evidence, the responsibilities and the contacts.
A supplier test report that cites a requirement identifier without the revision cannot be matched to the baseline it verified. The OEM has no way to tell whether the test predates the last change. Naming the identifier and the revision on returned evidence is part of what the agreement assigns.
ReqIF Mechanics and Where They Fail
Requirements Interchange Format (ReqIF) is the usual file format for OEM-to-supplier exchanges when the two companies run different requirements tools. ReqIF carries requirement text and attributes while preserving the document hierarchy, and identifies each item with a globally unique identifier so the same item can be recognized across rounds.
Two companies working in separate repositories have no shared state to fall back on, so a reliable round trip depends on two controls both sides agree before the first file changes hands. Attribute mapping settles the common data model, covering attribute types, link types, allowed values and formatting, before the first exchange. Baseline and write-back control comes next, with each exchange recording the approved baseline and the recipient confirming the revision before continuing work. The write-back rule names the attributes the supplier may edit, then filters returned data so OEM-controlled fields cannot be changed unintentionally.
Miss either control and the failure is quiet. The supplier works from a superseded baseline, or an attribute the OEM owns comes back overwritten. Neither shows up until someone reconciles the two repositories. Automotive SPICE 4.0 merged traceability and consistency into a single base practice. On programs running Automotive Software Process Improvement and Capability Determination (Automotive SPICE or ASPICE) alongside ISO 26262, a trace matrix whose links nobody has read for meaning no longer satisfies an assessment.
Inherited Software Components: SOUP and Software Bill of Materials (SBOM) Obligations
IEC 62304 requires manufacturers to identify each SOUP item by name, version and manufacturer, and to document its requirements and prerequisites. Published anomaly lists have to feed into risk analysis, and monitoring has to continue after release for new anomalies and security vulnerabilities. The depth of that work scales with the software safety class, Class A through Class C.
SBOM regimes ask for much of the same inventory in a different form. A useful component record covers commercial, open-source and off-the-shelf software, and stays connected to risk, anomaly, vulnerability and release information.
The European Union (EU) Cyber Resilience Act begins applying Article 14 vulnerability and incident reporting on September 11, 2026, including to products already on the market. From December 11, 2027, the same regulation requires a machine-readable SBOM covering at least the product’s top-level dependencies, kept current through the support period. A team selling a connected device in multiple regulated markets can hold one governed component inventory that supplies SOUP records, SBOM output and vulnerability monitoring evidence without reconciling separate lists by hand.
Where Supply Chain Traceability Breaks in Practice
Traceability breakdowns appear first in documentation, and audit sampling is what finds them. Under the EU Medical Device Regulation (EU MDR), notified bodies apply stricter documentation scrutiny than the directives it replaced required. An audit can follow a sampled product back through its design and post-market record. One broken chain there reduces confidence in every chain outside the sample.
The four patterns below each start somewhere ordinary:
- Quality agreement as the monitoring record: The signed agreement gets filed as if it proves that supplier monitoring occurred, while current performance and risk evidence remain absent.
- Retroactive matrix assembly: A traceability matrix assembled at the end of a design program leaves the intervening changes undocumented, and unexplained holes suggest a program-wide problem.
- Stale procedure references: Supplier procedures that still cite superseded regulatory provisions after a transition tell an investigator the document hasn’t been reviewed.
- Identification failures at recall: If component records do not connect affected lots or serial numbers to finished products, the manufacturer cannot reliably define the recall population.
The first pattern is what made AOG Technics possible. Buyers held release certificates that had nothing connected back to the engine manufacturer named on them, and the certificate was the only evidence anyone asked for.
The last pattern can create the largest bill because uncertain identification expands the population that must be investigated, contained, notified, or recalled. Connecting supplier records and received material to production history and the final product identifier has to happen before a field event.
How Jama Connect Supports Supply Chain Traceability
In Jama Connect®, the Traceability Information Model defines which relationships a program requires between requirements, design elements, code, tests and verification results. Enforced relationships flag a required downstream item that does not exist. When an upstream requirement changes, Live Traceability™ spreads a suspect flag across every degree of separation downstream, and the engineer either updates the affected item or clears the flag. Each of those actions leaves the auditable decision trail ISO 13485 Clause 7.4 and the DIA described on paper.
Requirements and verification evidence in the chain sit inside that model. Parts, lots and software components stay in the systems that own them, with trace links pointing outward to those records instead of duplicating them. Pre-built frameworks for medical device and Aerospace and Defense development arrive with the item types, relationship rules and review workflows each regime expects, so supplier controls start from a structure aligned to ISO 13485, DO-178C and DO-254 rather than a blank project. Out-of-the-box export templates then build the traceability matrix and the audit artifacts a submission needs out of live project data, which is the evidence an inspector asks to see. Cloud and self-hosted deployments carry the same trace structure, which matters for programs under data sovereignty or air-gapped constraints.
Why One Supplier Baseline Beats an Audit Readiness Review
One supplier baseline, taken through a complete change cycle, tells you more than an audit readiness review does. Follow it from the change notification arriving to the returned verification evidence landing against the revised requirement, and see whether anyone had to rebuild anything by hand. A baseline that comes through intact shows the process can carry a change without manual reconstruction, and one that stalls shows you where.
Jama Connect supports that cycle by keeping the trace links between supplier requirements, changes and verification evidence current as work moves, so the audit reads an existing record. If your supplier evidence only comes together in the week before an inspection, you can start a free 30-day trial today.
Frequently Asked Questions About Supply Chain Traceability
Who owns traceability when the OEM and the supplier use different requirements tools?
The OEM owns the trace to its own safety goals and cannot delegate it, which is why the interface agreement names a responsible party for each exchanged work product. On the supplier side, ownership covers the evidence it produces and the attributes the agreement lets it edit. Where the two tools disagree, the agreed baseline decides, not whichever repository was written to last. In Jama Connect, the agreed baseline and its trace links sit in one repository, so both sides read the same revision.
Do suppliers need their own cybersecurity certification under United Nations Regulation No. 155 (UN R155)?
Tier-1 and Tier-2 suppliers do not need their own certificate. UN R155 puts the Cybersecurity Management System certificate on the vehicle manufacturer, and that certificate stays valid for a maximum of three years before it has to be renewed. The manufacturer does have to demonstrate how its management system handles the dependencies it carries with contracted suppliers, service providers and its own in-house teams. ISO/SAE 21434 is the standard that puts the supplier assessment itself on the customer, covering management system maturity, past threat analysis work and vulnerability handling.
How long do aerospace suppliers have to keep traceability records?
Retention periods are set by the prime contractor’s supplier quality requirements and the contract, and they differ by record type. Check both of those before you design a retention schedule. Custody is the harder problem, because a record that outlives the company holding it needs a named owner and a plan for staying accessible through an ownership change or a closure. Without that, a component’s provenance cannot be reconstructed for an audit, an investigation or a continued-airworthiness decision years later.
This article was authored by Mario Maldari and published on September 14, 2026.
Book a Demo
See Jama Connect in Action!
Our Jama Connect experts are ready to guide you through a personalized demo, answer your questions, and show you how Jama Connect can help you identify risks, improve cross-team collaboration, and drive faster time to market.