VDA 6.3 vs IATF 16949: Which Audit You Are Actually Scheduling, and How We Keep Them Apart
Back to blog

VDA 6.3 vs IATF 16949: Which Audit You Are Actually Scheduling, and How We Keep Them Apart

VDA 6.3 and IATF 16949 both get called 'the automotive audit,' but one audits a process and rates it A, B, or C, and the other audits a management system against numbered clauses. Where each one sits in your audit calendar, what clause 8.4.2.4.1 says decides which second-party audit a supplier gets, and how QualityEngineer.ai schedules, plans, and tracks a VDA audit without pretending to be the VDA question catalog.

Daniel CrouseDaniel Crouse,September 23, 2026,9 min read

VDA 6.3 vs IATF 16949: Which Audit You Are Actually Scheduling, and How We Keep Them Apart

The email is two lines long. A customer's supplier quality group would like to confirm dates for a VDA 6.3 process audit of your stamping line, and could you send the last system audit report ahead of time.

So you open the audit calendar. There is a row that says "IATF audit, Q1." There is another that says "supplier audit, machining," and a third that says "process audit, assembly." You are fairly sure the first one covers this. You are less sure what the second and third are, because whoever built the calendar three years ago is now at a different plant. You start opening reports to find out which questions each one actually asked.

That afternoon of report archaeology is what this post is meant to save. VDA 6.3 and IATF 16949 are both called "the automotive audit," and they do overlap, but they are not the same audit. Scheduling one as if it were the other is a quiet way to arrive at an OEM process audit with a system audit's evidence in the folder.

Two audits that sound like one

Here is the short version, side by side.

IATF 16949 auditVDA 6.3 audit
What it auditsA management system, against numbered clausesA process, from planning through production and customer care
Question sourceThe clauses of the standardThe VDA 6.3 question catalog, organized into process elements P1 to P7
ResultNonconformities, graded major or minor, against a clauseA degree of fulfillment per element and overall, rated A, B, or C
Unit auditedThe QMS, sampled across processesOne product or process, followed end to end
Typical triggerCertification cycle, or your own internal audit programA customer requirement, or your own supplier risk decision

The standard itself does not tell you they are the same, and it does not tell you they are different. It just uses different clauses for different jobs, and the jobs are easy to blur. Three of those clauses are worth keeping straight.

What IATF 16949 actually asks for

Clause 9.2.2.1, internal audit program. Your organization audits itself, and the program has to cover a QMS audit, a manufacturing process audit, and a product audit. If you want the full walk through that clause, IATF 16949 Clause-by-Clause Audit Readiness goes through it.

Clause 9.2.2.3, manufacturing process audit. Each manufacturing process gets audited to determine its effectiveness. The clause does not name a method. VDA 6.3 is a widely used one, and it is often the one a customer's own requirements point to, but it is a way of meeting 9.2.2.3, not a separate clause you also have to satisfy.

Clause 8.4.2.4.1, second-party audits. This is the one that decides how a supplier gets audited by you. The clause asks you to document, from a risk analysis that considers product safety and regulatory requirements, the supplier's performance, and their QMS certification level, the criteria for the need, type, frequency, and scope of second-party audits. Read that list again, because it is the whole assignment: not "audit your suppliers," but "write down why this supplier gets this kind of audit, this often, this deep."

Clause 7.2.4 rounds it out. Whoever does the second-party audit has to be shown to be competent to do it, including knowing the automotive process approach and any customer-specific requirements that apply. That is a records question as much as a skills one, and it is worth deciding early where those records live.

What VDA 6.3 asks for instead

VDA 6.3 is a process audit standard. The auditor does not walk the clauses. The auditor picks a product or process and follows it through seven process elements: P1 potential analysis, P2 project management, P3 planning of product and process development, P4 carrying out product and process development, P5 supplier management, P6 process analysis and production, and P7 customer care and service.

Each question is scored, each element gets a degree of fulfillment as a percentage, and the overall result is classified. The commonly cited bands are A at 90 percent and above, B from 80 to under 90, and C below 80. There are also downgrade rules, so a critical question scored badly can pull a rating down even when the arithmetic looks comfortable. The exact scoring tables, and the questions themselves, are a VDA publication. Use the current edition your customer specifies.

Two practical consequences follow from the shape of it.

A VDA 6.3 result belongs to a process, not to a plant. An A on the stamping line says nothing about the machining line. If your audit calendar has one VDA row per supplier, you are probably losing the fact that the audit followed one specific product.

An IATF certificate is not a VDA rating. A certification body's audit and a customer's process audit ask different questions of different units. The certificate can support the supplier's story for a customer that asks, but it does not stand in for the rating.

Deciding which audit a supplier gets

This is where clause 8.4.2.4.1 turns into an actual Tuesday-morning decision. A supplier certified to IATF 16949 with clean delivery and a low-risk part may reasonably get a desktop review. A supplier with an ISO 9001 certificate only, on a safety-relevant part, is a different conversation, and it is the one where an onsite process audit against a recognized method like VDA 6.3 earns its cost.

In QualityEngineer.ai, the audit-required flag on a supplier's qualification works that way on purpose, and it is deliberately narrow. It arms automatically in two situations: the supplier is flagged as a critical vendor, or their risk tier is high or critical. When it arms, it records the reason in plain text next to the flag, so the answer to "why did this supplier get audited" is sitting on the record and not in someone's memory. It never clears itself. An assessor can override it in either direction by setting it explicitly, and their value wins.

That covers two of the risk inputs, not the full list in the clause. Delivery performance, certification level, and product safety weight still live in your documented criteria and in the assessor's judgment. What the flag gives you is the paper trail for the part that can be decided from data already on the supplier record.

Scheduling a VDA audit and what it does for you

Audit type is a field on the supplier audit, not a word in a title. The options are onsite, VDA, desktop review, remote, and supplier self-assessment. Pick VDA and a few things happen, some of them without being asked.

A questionnaire is generated in the background. Every audit type gets one when the audit is scheduled, titled for the type, so a VDA audit's questionnaire reads "VDA 6.3 Audit Questionnaire" for that supplier. At the default depth the sections are our standard set: quality management system, process control, document and record control, corrective action, supplier management, measurement equipment, and customer-specific requirements. It is a useful pre-audit conversation starter. It is not the VDA 6.3 question catalog, and we do not claim it is.

An audit plan can be drafted from what we already know about the supplier. Ask for one and the plan is built from the supplier's certification status (IATF, ISO), risk tier, quality score, completed audit history and latest result, open supplier corrective action requests, open corrective actions including any flagged blocking, and active risk flags. For a VDA audit the plan is told to organize its checklist around the VDA process elements. What comes back is a scope statement, three to five focus areas, a prioritized checklist, an opening meeting agenda, and an estimated duration. Items tied to open SCARs, blocking actions, failed prior audits, or expired certificates are prioritized high.

The plan is a draft for a person to read. Nothing is written to the audit's readiness checklist until someone applies it, so a plan you disagree with costs you one click to ignore.

Findings get their own records. A finding raised from the audit is a corrective action linked to that audit, with an owner and a due date, and it can be marked blocking. Those counts feed the next audit plan and the supplier's risk assessment, so a supplier that closed the last audit with two blocking findings still open looks that way to whoever plans the next one. One honest limit: the blocking flag informs the plan and the risk read today. It does not lock the supplier's approval button on its own, so if your process treats a blocking finding as a hold, that hold is still a decision a person makes.

The limits, stated plainly

The auditor enters the score, the GREEN, YELLOW, or RED band, and the pass, conditional, or fail result. We do not compute a VDA 6.3 degree of fulfillment or an A, B, or C classification, and the GREEN, YELLOW, RED band is our own supplier scale, not a translation of the VDA rating. If you run VDA 6.3 scoring in the customer's own template, that stays the record of the rating. Where we help is around it: scheduling the audit, drafting the plan from supplier history, holding the questionnaire and evidence together, and keeping the findings from becoming a footnote in a report nobody opens next year.

What to do with your own calendar

Whichever tool you use, three habits pay for themselves.

  1. Give each audit its own row and its own type. System audit, layered process audit, VDA process audit, and second-party supplier audit are four different things and should be four different lines.
  2. Write the audit to the process, not just the site. For VDA, name the product or process being followed on the schedule entry.
  3. Write down why. Clause 8.4.2.4.1 asks for documented criteria for need, type, frequency, and scope. A supplier record that says why the audit was triggered answers the first question an auditor asks about it.

If you manage suppliers in Supplier Quality, the audit type field, the plan, and the findings are all on the supplier's own page, so the audit history for one supplier reads as one thread. You can try it with a free 30-day trial, no card needed.


Related Reading

IATF 16949 Clause-by-Clause Audit Readiness covers 9.2.2.1 through 9.2.2.4 and the other automotive-specific adders. IATF 16949 Internal Audit Checklist covers the program structure. Supplier Risk Scoring covers the signals behind the risk tier that arms the audit flag. CAPA Closure Criteria covers what closed should mean for the findings an audit raises.

Related reading

Daniel Crouse
Daniel Crouse

Founder, QualityEngineer.ai

15+ years in supplier quality, PPAP, and manufacturing systems. Built QualityEngineer.ai because quality engineers deserve better tools than Excel.

View profile →
Built for quality engineers

Ready to automate your PPAP workflow?

QualityEngineer.ai handles the documentation-heavy parts of quality engineering: PPAP, supplier assessments, document analysis, CAPA, and more. Start with a free 30-day trial.