Control Plan: How to Sustain Process Improvements

Turn this article into takeaways for your work.
Each assistant summarizes the article only for you and suggests best practices for your work.
Every improvement project ends the same way. The team fixes the problem, the chart looks beautiful for six weeks, the sponsor moves on, then a new operator starts, a supplier changes resin lots, the fixture wears, and nobody notices until a customer does. The gain wasn't lost in one dramatic event. It leaked out, because nothing in the daily running of the process was changed to hold it.
A control plan closes that gap. It's a written record of what gets measured on a process, how, how often, by whom, and exactly what happens when the measurement comes back wrong. That last part is the whole point. Plenty of teams measure things. Far fewer have written down, in advance, what the operator does at 2am when the reading is out of spec and the supervisor is across the plant.
Key Facts: Control Plans
- The control plan no longer lives in the APQP manual. Effective 1 March 2024, AIAG published APQP 3rd Edition alongside a standalone Control Plan 1st Edition (AIAG), and the APQP manual's description now lists "the removal of Control Plan content, now a standalone document" (AIAG).
- AIAG's reason: "Decoupling the two documents also emphasizes the importance of control plans in product development and will facilitate more timely updates as systems evolve." Implementation was required by GM and Stellantis as of 1 September 2024, and by Ford as of 31 December 2024 (AIAG).
- The new manual added a "Safe Launch" requirement to control plan phases, plus guidance on managing control plans in software (AIAG).
- The standard itself has not moved. IATF 16949:2016 is still current, with a second edition planned for mid-2027 (Smithers, August 2026).
What a Control Plan Actually Is
A control plan is a structured summary of the controls applied to a process, written characteristic by characteristic. For each thing that matters, it records the specification, the method used to check it, the sample size and frequency, the mechanism keeping the characteristic where it belongs, and the reaction plan that fires when it doesn't.
It is not a procedure. It doesn't tell an operator how to run the machine. It tells the organization which few characteristics are load-bearing and what the agreed response is when one moves. It answers a single question asked of every process step: if this goes wrong, how would we know, how fast, and who does what?
Its place in sustaining improvements is structural. A DMAIC project has a Control phase for exactly this reason, and the control plan is usually its main deliverable. Improve produces the new setting, the new fixture, the new sequence. Control decides whether that change is still there next quarter. Without a document naming the new critical characteristic and assigning a check to it, the improvement lives only in the memory of the people who ran the project. Those people get reassigned.
Where Control Plans Come From, and What Changed in 2024
Control plans originated in the automotive supply chain as a core quality tool, alongside FMEA, MSA, SPC and PPAP. For three decades the requirements lived in a combined AIAG manual called APQP and Control Plan. That's where most training material still points, and it's now wrong.
Effective 1 March 2024, AIAG replaced the combined 2nd Edition with two documents: APQP 3rd Edition, and a standalone Control Plan 1st Edition (AIAG). Control plan content was pulled out of the APQP manual entirely, a change AIAG lists plainly in the APQP 3rd Edition description as "the removal of Control Plan content, now a standalone document" (AIAG). Writing in Quality, John Vandenbemden described the result as "a standalone Control Plan Reference Manual that maintains the linkages between the other core tools under APQP" (Quality, August 2024).
AIAG's explanation for the split tells you how the document is meant to be used: "Decoupling the two documents also emphasizes the importance of control plans in product development and will facilitate more timely updates as systems evolve" (AIAG). A control plan should change more often than the planning framework around it. The dates matter if you supply the industry: GM and Stellantis required implementation as of 1 September 2024, Ford as of 31 December 2024.
One thing did not change, and it gets misreported often enough to state flatly. The automotive quality standard is still IATF 16949:2016. Revision work begins after ISO 9001 is republished, with a second edition planned for mid-2027 and its transition aligned to the end of the ISO 9001 transition (Smithers). The manual moved; the standard did not, and that's the distinction auditors will test. The standard and your customer-specific requirements carry the obligation, and the AIAG manual is guidance for meeting it.
The Three Types, Plus the Phase That Got Added
Control plans are written per phase, because what you're protecting changes as a product matures: the design decision early on, a process nobody has run at volume at launch, then a known-good state against drift.

| Type | When it applies | What it protects | Typical intensity |
|---|---|---|---|
| Prototype | Early builds, before the process is fixed | The design, and the data proving it works | Heavy dimensional and material checks, often 100% inspection |
| Pre-launch | After prototype, before production sign-off | A process that has not yet shown stability at volume | Tightened frequencies, added checks, extra containment |
| Production | Ongoing manufacture, after part approval | A validated process against drift, wear, turnover and supplier variation | Sampling and statistical monitoring, sized to capability |
The 2024 manual added a Safe Launch requirement to those phases (AIAG). Treat it as an extra, deliberately temporary layer of control around the start of production, with its own exit criteria, not a fourth permanent plan. If a customer imposes safe launch conditions, read their requirement rather than a summary of it, including this one.
The common mistake isn't picking the wrong type. It's never leaving pre-launch. Teams tighten controls for launch, the launch goes fine, and the tightened checks stay forever because nobody wrote down what would justify relaxing them. Define the exit criteria (consecutive stable subgroups, a demonstrated capability index, a defect-free volume) when you define the elevated check.
Reading a Control Plan Column by Column
A control plan is only as good as the discipline in each column. Here is what each column is really asking, and where teams go wrong.

| Column | What belongs in it | The common failure |
|---|---|---|
| Process step | Operation number and name, matching the flow and the process documentation | Numbering that drifts out of sync with the flow diagram, so nobody can trace a defect back |
| Characteristic | The product or process characteristic controlled, flagged if special or safety-related | Listing every dimension on the drawing, burying the handful that matter |
| Specification | The requirement and tolerance, in the units the operator reads | A spec the gauge on the floor cannot resolve |
| Measurement method | The named gauge, plus evidence the measurement system is trustworthy | No measurement systems analysis, so a gauge with more variation than the tolerance judges conformance |
| Sample size | How many pieces per check | A sample of one, presented as a statistical conclusion |
| Frequency | How often the check runs, and what events also trigger it | "Per shift" with no event triggers, so a material or tool change goes unchecked |
| Control method | The mechanism holding the characteristic in place: a chart, a poka-yoke device, an interlock, a setup approval | Naming a document instead of a mechanism, as in "per SOP" |
| Reaction plan | What happens when the check fails: containment, notification, correction, disposition | A single word, "adjust" |
Two columns carry more weight than the rest. Measurement method is where control plans quietly fail, because a bad measurement makes every downstream number meaningless. NIST/SEMATECH frames a gauge study's purpose as "to outline the steps that can be taken to characterize the performance of gauges and instruments used in a production setting in terms of errors that affect the measurements" (NIST/SEMATECH). If the gauge eats a large share of your tolerance, tightening the process won't help.
Sample size and frequency carry a statistical claim you may not have earned. Capability indices compare "the output of an in-control process to the specification limits," most estimates "are valid only if the sample size used is large enough," generally about 50 independent values, and they assume normally distributed data (NIST/SEMATECH). That rules out much of what gets reported as process capability.
A Filled-In Control Plan
Abstract columns are easy to nod along to. Here are two rows from a production-phase control plan for an injection-molded connector housing. The header above them carries the identification: part number and revision, phase (Production), the plant and process covered, the core team, the revision number and date, and customer approval where required.
| Process step | Characteristic | Specification | Measurement method | Sample | Frequency | Control method | Reaction plan |
|---|---|---|---|---|---|---|---|
| Op 30 Mold | Wall thickness at boss A (special characteristic) | 2.40 mm plus or minus 0.10 mm | Ultrasonic gauge, 5-position fixture, gauge study on file | 5 pieces | Every 2 hours, plus every resin lot and tool change | X-bar and R chart at the press | Quarantine back to the last conforming check, team leader in 10 minutes, adjust per WI-30-04, quality engineer dispositions held stock, 100% check until two conforming subgroups pass |
| Op 45 Weld | Weld pull strength | 350 N minimum | Destructive pull test on a sacrificial part | 1 piece | Start of shift, every horn change, every 4 hours | Weld energy window locked in the controller with alarm limits | Contain back to the last passing test, escalate to process engineering that shift, re-qualify with 3 passing tests |
Read the first row again with the sustaining question in mind. Nothing in it is clever. What it does is remove every decision from the moment of the problem. The operator doesn't judge how far back to quarantine, whether ten minutes is too soon to bother the team leader, or how many good checks are enough before resuming. Those judgments were made in a quiet room by people with more information, and written down. That's how an improvement survives contact with a Tuesday night shift. Notice too that the weld row's control is a locked parameter window rather than a chart. Plans get stronger as control moves upstream, from detection toward prevention.
From FMEA to Control Plan to Reaction Plan
This is the linkage most teams get wrong, and it separates a real control plan from a filled-in template. A failure mode and effects analysis already contains almost everything the control plan needs. If the two were built independently, one of them is wrong.
| FMEA output | Where it lands in the control plan | What breaks if the link is missing |
|---|---|---|
| Process function and step | Process step column | The plan controls a step the FMEA never analyzed for risk |
| Failure mode | The characteristic chosen for control | You control what is easy to measure instead of what can fail |
| Effect and severity rating | Whether the characteristic is flagged special, and how hard the controls are | High-severity failures get the same routine sampling as cosmetic ones |
| Cause and occurrence rating | Frequency, and what events trigger an extra check | Checks run on a clock unrelated to when the cause acts |
| Current prevention control | Control method column, the preventive half | Prevention lives only in the FMEA, so nobody maintains it |
| Current detection control | Measurement method plus control method | The FMEA claims detection credit for a check the floor never runs |
| Recommended action, once implemented | An updated row, and a re-scored FMEA | The fix stays an action item, never a standing control |
Run the two as one loop, not two deliverables. When a corrective action from a root cause analysis closes, three things change together: the FMEA scores, the control plan row, and the work instruction the operator reads. Update only the FMEA and you've documented a belief rather than a control. This is also the cleanest place to watch quality assurance and quality control meet in one artefact. ASQ, citing ISO 9000:2015, defines quality assurance as "part of quality management focused on providing confidence that quality requirements will be fulfilled" and quality control as "part of quality management focused on fulfilling quality requirements" (ASQ). The plan's planning half is assurance; its checks and reactions are control.
The Reaction Plan Does the Sustaining Work
Improve one column and make it this one. Every other column describes a state of the world; the reaction plan describes a decision, and decisions are what decay.

"Adjust process" is a wish. A usable reaction plan answers five questions before the problem happens.
| Element | The question it answers | What a usable answer looks like |
|---|---|---|
| Containment | What happens to product made since the last good check? | "Quarantine back to the last conforming check, red-tag the rack" |
| Notification | Who gets told, and how fast? | "Team leader within 10 minutes, quality engineer if unresolved at 30" |
| Correction | What adjustment is authorized, and by whom? | "Team leader may adjust barrel temperature within the WI-30-04 window; outside it requires process engineering" |
| Disposition | Who decides the fate of held product? | "Quality engineer dispositions held stock: scrap, rework per RW-12, or use-as-is with concession" |
| Resumption | What evidence justifies restarting? | "Two consecutive conforming subgroups before normal sampling resumes" |
The signal that triggers all of this has to be visible where the work happens, which is why the reaction plan and visual management belong to the same conversation. Toyota's description of its production system makes the mechanism explicit: "When equipment stops, the andon (problem display board) lights up to notify workers of the abnormality," and on lines without equipment "the andon is set to light up when the stop cord is pulled so that workers can call the person in charge" (Toyota). A reaction plan in a binder relies on someone remembering it exists. One wired to a light, a board, or an alarm limit gets executed.
The statistical trigger needs the same precision. If the control method is a control chart, name the rules that count as a signal, not just "out of spec." NIST's handbook puts it plainly: "If a data point falls outside the control limits, we assume that the process is probably out of control and that an investigation is warranted to find and eliminate the cause or causes" (NIST/SEMATECH). Out of control and out of specification are different events with different reactions, and real statistical process control is what makes that distinction operational rather than rhetorical.
Control Plan vs SOP vs Work Instruction
These three get conflated constantly, usually by someone trying to merge them to reduce paperwork. They answer different questions for different readers.

| Dimension | Control plan | Standard operating procedure | Work instruction |
|---|---|---|---|
| Question it answers | What do we monitor, how often, and what happens when it moves? | How is this process run end to end, and who owns it? | How does this person do this task at this station? |
| Scope | One process or product family, characteristic by characteristic | One process, including handoffs and roles | One task or operation |
| Primary audience | Quality, engineering, leadership, auditors, customers | The process owner and everyone in the process | The operator doing the work |
| Changes when | Risk, capability, customer requirement or performance changes | The process design changes | The method or tooling changes |
| Typical failure | Written once for approval, never revised | Describes an idealized process nobody runs | Written by someone who has never done the job |
They should reference each other, not repeat each other. A control plan row saying "correct per WI-30-04" is doing its job: it names the authorized correction without copying an instruction that will drift. The standard operating procedure sets out the process, standard work captures the agreed best method, and the control plan sits above both naming which characteristics are worth defending. Under ISO 9001 all three are slices of controlling production and service provision, which is why an auditor follows a thread from one to the next and expects them to agree.
Control Plans Outside Manufacturing
The tool travels further than most people expect. Its use spread beyond cars long ago, into "many other industries such as heavy equipment, medical devices, and aerospace" (Quality, 2024), and it survives translation into a service process because the question doesn't change. What matters here, how would we know it moved, and what happens then?

Translation is simple. Process step becomes the workflow stage, characteristic becomes whatever determines a good outcome there, specification becomes a service level or accuracy threshold, and control method becomes a validation rule, an approval gate, or a dashboard. The reaction plan stays exactly what it was.
| Process step | Characteristic | Specification | Measurement method | Frequency | Control method | Reaction plan |
|---|---|---|---|---|---|---|
| Invoice creation | Billing matches the signed contract | 100% match on rate, term and quantity | Automated variance report against the contract record | Every invoice, before release | System hard-stop on any variance | Hold the invoice, analyst reconciles within 1 business day, contract owner approves intended variances |
| Customer onboarding | Contract signed to first successful login | 5 business days or fewer | Timestamps from the onboarding system | Weekly, all accounts closed that week | Queue with age-based escalation visible to the team | Past day 4, escalate to the onboarding lead, who names an owner and a date; past day 5, weekly review with a cause code recorded |
| Ticket triage | Correct priority at first touch | 95% agreement with the priority matrix | Sampled audit of closed tickets | 20 tickets per week | Priority matrix as a required field in the ticket form | Coach the individual within 2 days; two weeks below 95% triggers a matrix review, not a coaching cycle |
That third reaction plan shows the discipline the tool imposes: it separates an individual miss from a systemic one and commits in advance to which response each gets. Two other habits carry over. Write the specification as a real threshold, not an aspiration (this is where service level agreements do the same job as a tolerance), and pick a few outcome measures such as first pass yield rather than instrumenting everything a system logs. The point of monitoring a process is to trigger a decision, and a measure with no reaction attached is just reporting.
Keeping It Alive: Revisions and Triggers
The difference between a live control plan and a dead one is whether anything other than the calendar can trigger a revision. Annual review alone leaves the plan, on average, six months out of date.
| Trigger | What to re-check | Who usually owns it |
|---|---|---|
| Customer complaint or field failure | Was the failure mode in the FMEA, the characteristic in the plan, and did the reaction plan run? | Quality engineer with the process owner |
| Internal defect escape or scrap spike | Detection controls and frequency for that characteristic | Process owner |
| Process, tooling, material or supplier change | Every row touching the change, plus the measurement system if the gauge moved | Process engineering |
| Capability shift, better or worse | Sample size and frequency, and whether elevated launch controls can be relaxed | Quality engineer |
| Layout, automation or software change | Whether the named control mechanism still physically exists | Process engineering |
| New customer requirement | Special characteristic designations and approval status | Quality manager |
| Corrective action closure | The row the action changed, plus the matching FMEA score and work instruction | Action owner |
Closing a corrective action without editing the control plan is the most common way a fix evaporates, so build the edit into the closure criteria.
Then audit it properly. Reviewing the document only proves the document exists. Walk the process with the plan in hand and check three things per row: does the named gauge exist and is it calibrated, does the check run at the stated frequency, and can the operator say what happens when it fails. The third question finds the dead reaction plans.
Limitations: A Control Plan Nobody Audits Is Paperwork
Being honest about the failure modes is what keeps the tool useful.

| Limitation | Why it matters |
|---|---|
| It documents controls, it does not perform them | A perfect plan and an unstaffed check produce the same parts as no plan at all |
| It inherits the FMEA's blind spots | A failure mode nobody imagined appears in no column, so the plan never replaces a real root cause investigation when something new happens |
| Over-inclusion dilutes it | A plan with sixty characteristics teaches the floor that none are special; the discipline is in what you leave out |
| Sampling can promise more than it supports | Capability and stability claims need enough data, an in-control process and a defensible distribution assumption (NIST/SEMATECH) |
| Detection-heavy plans are expensive and fragile | Every row that catches a defect instead of preventing one is a recurring cost that depends on human attention |
| The manual is guidance, not a template | AIAG's manual "provides guidance and is not prescriptive" (Quality, 2024), so copying another plant's format carries none of its risk thinking |
None of these argue against control plans. They argue against treating one as a deliverable rather than a working document. The plan earns its keep the day something goes wrong and nobody has to improvise.
Frequently Asked Questions about Control Plans
What is a control plan?
A control plan lists, characteristic by characteristic, what gets measured on a process, the specification, the measurement method, the sample size and frequency, the control method, and the reaction plan that runs when a check fails. Its job is to keep a process performing as designed long after the project that improved it ends.
Is the control plan still part of the AIAG APQP manual?
No. Effective 1 March 2024, AIAG published APQP 3rd Edition and a standalone Control Plan 1st Edition, and control plan content was removed from the APQP manual, listed by AIAG as "the removal of Control Plan content, now a standalone document." GM and Stellantis required implementation as of 1 September 2024, Ford as of 31 December 2024.
What are the three types of control plan?
Prototype, pre-launch, and production. Prototype plans protect the design during early builds. Pre-launch plans apply tighter, temporary controls to a process that hasn't proven itself at volume. Production plans defend a validated process against drift. The 2024 manual added a "Safe Launch" requirement to those phases.
What is a reaction plan?
The column stating what happens when a check fails. It covers containment of product made since the last good check, who is notified and how fast, what correction is authorized and by whom, who dispositions held material, and what evidence justifies resuming. It separates a plan that sustains an improvement from one that records intent.
How is a control plan different from an SOP?
An SOP describes how a process is run end to end. A control plan describes what is monitored inside that process, how often, and what happens when a measurement goes wrong. The SOP is the method; the control plan is the safety net over the characteristics that matter most.
Can you use a control plan outside manufacturing?
Yes. Replace the process step with a workflow stage, the characteristic with whatever determines a good outcome there, and the specification with a service level or accuracy threshold. Billing accuracy, onboarding cycle time and triage accuracy all fit. The reaction plan translates unchanged, and it is usually the part a service team is missing.
Control plans have a reputation for bureaucracy because so many were written to be approved rather than used. A good one is short, honest about which characteristics carry the risk, specific about who does what when a check fails, and revised the moment the process underneath it changes. Get those four right and the plan stops being documentation of an improvement and becomes the reason the improvement is still there.

Senior Operations & Growth Strategist
On this page
- What a Control Plan Actually Is
- Where Control Plans Come From, and What Changed in 2024
- The Three Types, Plus the Phase That Got Added
- Reading a Control Plan Column by Column
- A Filled-In Control Plan
- From FMEA to Control Plan to Reaction Plan
- The Reaction Plan Does the Sustaining Work
- Control Plan vs SOP vs Work Instruction
- Control Plans Outside Manufacturing
- Keeping It Alive: Revisions and Triggers
- Limitations: A Control Plan Nobody Audits Is Paperwork