IATF 16949

Customer Specific Requirements in IATF 16949: What They Are and How to Audit Them

Customer Specific Requirements (CSRs) are additional requirements that individual automotive OEMs — Ford, GM, Stellantis, BMW, and others — publish independently and layer on top of the base IATF 16949 standard. Clause 4.3.2 requires organizations to identify and incorporate every applicable CSR into their quality management system, and Clause 9.2.2.2 requires internal audits to explicitly verify that compliance.

No other management system standard requires anything quite like customer specific requirements. Where ISO 9001, ISO 14001, and ISO 45001 apply uniformly regardless of which customer an organization sells to, IATF 16949 explicitly requires organizations to identify and comply with a growing library of individual, customer-published requirement documents — each maintained separately, each revised on its own schedule, and each legally binding once a supplier accepts a contract with that customer. This article explains what CSRs are, how major OEMs structure and publish them, and how internal auditors need to approach verifying conformance — drawing on the audit experience of Maria Falbo, a Lead Auditor with decades of IATF 16949 experience.

Maria Falbo|Lead Trainer, Logix ISO|July 2026|8 min read

What Customer Specific Requirements Are

Customer Specific Requirements are additional quality management system requirements that individual automotive OEMs publish and require their suppliers to identify and implement, on top of the base IATF 16949 standard. Ford, General Motors, Stellantis, BMW, Mercedes-Benz, Renault, and Volkswagen each maintain their own CSR document, hosted centrally on the IATF Global Oversight website but revised independently, each OEM working to its own schedule rather than any shared update cycle.

CSRs aren't optional supplementary guidance. Once a supplier's contract with an OEM references IATF 16949 certification and that customer's CSRs, compliance becomes a binding contractual obligation, verified both through the supplier's own internal audit program and through third-party IATF 16949 certification audits. For a broader overview of what IATF 16949 requires overall, see our IATF 16949 requirements explained.

Why IATF 16949 Requires Them

Customer specific requirements exist partly because of how IATF 16949 itself gets built. The standard is developed by consensus among its member automakers — but where those members couldn't reach agreement on a specific requirement during drafting, the objecting OEM built that requirement into its own customer document instead of holding up the shared standard. This is part of why CSR content varies so much between customers: it reflects the individual priorities and quality history of each automaker, not a single unified industry consensus.

Clause 4.3.2 formally requires organizations to identify the CSRs applicable to their products and customers and incorporate them into the QMS. Clause 9.2.2.2 goes further, explicitly requiring the internal audit program to consider CSR compliance — meaning CSR conformity isn't left to informal tracking, it's a formal, auditable requirement in its own right.

In Practice

An organization supplying three or four different OEMs isn't managing one set of additional requirements — it's managing three or four separately maintained documents, each potentially specifying different PPAP requirements, different APQP deliverables, or a different control plan format for the same underlying part. The complexity isn't theoretical; it's the single most common operational challenge I see when a supplier's customer base expands beyond one or two OEMs, and it's exactly why treating CSR management as a one-time exercise rather than an ongoing monitoring discipline is where most organizations fall behind.

How Major OEMs Structure Their CSRs

Each OEM structures its CSR document differently, and understanding those differences matters for anyone auditing against them.

Ford organizes its CSR document explicitly by IATF 16949 section, presenting a summary of Sections 1 through 10 with the customer-specific content layered directly under the corresponding clause — meaning a supplier can navigate Ford's CSR the same way they'd navigate the base standard itself, clause by clause.

Stellantis categorizes its CSR content by audit function. Category 1 requirements are interpretations of existing IATF clauses, included specifically to help an auditor apply those clauses correctly on Stellantis programs. Category 2 requirements are genuinely supplemental — additional requirements with their own stated rationale and specific instructions for what an auditor should check.

Some OEMs also maintain a distinctive escalation mechanism tied to supplier performance: controlled shipping, a special status a customer can invoke when a supplier's key performance indicators fall below acceptable levels, requiring additional inspection and containment activity above normal production controls until performance recovers.

For a step-by-step explanation of how these customer-specific elements need to be built into audit planning itself, see our guide on how to conduct an IATF 16949 internal audit.

Auditing CSR compliance credibly is a core skill every IATF 16949 internal auditor needs

Our IATF 16949 Internal Auditor course covers how to identify, incorporate, and audit against customer-specific requirements from major OEMs.

View Course

How Internal Auditors Verify CSR Conformance

Verifying CSR conformance starts before the audit itself — the auditor needs to know which specific OEM's CSRs apply to the product or process being audited, and needs to be working from the current version of that document, which should be built into quality system documentation.

During the audit, verification means checking two distinct things: whether the CSR has been formally identified and documented as applicable within the QMS, and whether the specific requirements it contains are genuinely being followed in practice — not just referenced. A CSR that's listed as applicable but never actually cross-referenced against the relevant work instructions, control plan, or audit checklist has been identified but not genuinely incorporated, which is a meaningful distinction an experienced auditor will be able to detect.

Findings involving a missed or outdated CSR carry particular weight, since they may indicate a gap not just in this specific instance but in the broader process the organization uses to monitor and update CSR documents as OEMs revise them. An auditor who finds one missed CSR update should ask a follow-up question: how would this organization know if a different customer's CSR changed next month?

FAQ

Frequently asked questions

Are customer specific requirements the same for every OEM?

No — each OEM (Ford, GM, Stellantis, BMW, Mercedes-Benz, and others) publishes and maintains its own separate CSR document, with different structure, different content, and its own independent revision schedule. An organization supplying multiple OEMs needs to track and comply with each one separately.

How often are CSRs updated?

This varies by OEM — there's no shared or universal update schedule. Each automaker revises its own CSR document on its own timeline, sometimes with several months between updates and sometimes longer. Organizations need an active monitoring process to catch these updates, since IATF Global Oversight hosts the current versions centrally but doesn't push notifications to every supplier automatically.

Where can I find an OEM's current CSR document?

Current CSR documents from IATF member OEMs are published on the IATF Global Oversight website. Organizations should always verify they're working from the current published version rather than a previously downloaded copy, given that OEMs revise these documents on their own independent timelines.

Do CSRs need to be included in the internal audit program specifically?

Yes — Clause 9.2.2.2 explicitly requires customer-specific requirements to be considered as part of the internal audit program, meaning CSR compliance is a formal, auditable requirement rather than something tracked informally outside the QMS.

What happens if a supplier fails to comply with a customer's CSR?

Consequences vary but can include audit nonconformities, customer notifications, and in more serious or repeated cases, a customer invoking special supplier status — such as controlled shipping — requiring additional inspection and oversight until performance is demonstrated to have recovered.

About the Author
Maria Falbo — Lead Trainer, Logix ISO
Maria Falbo
Founder & Lead Trainer, Logix ISO · 25+ Years Global Experience

Maria Falbo has over 25 years of experience working as a Lead Auditor for certification bodies worldwide. She founded Logix ISO with the mission of making expert-level ISO training accessible to organizations of all sizes. Her work spans Quality, Environmental, Occupational Health and Safety, Food Safety, Automotive, and Energy management systems.

Learn more about Maria →
IATF 16949 Internal Auditor Training
Ready to become a qualified IATF 16949 internal auditor?

Self-paced · 365-day access · Training certificate included

View Course