Control Plan: How to Sustain Process Improvements

A caliper checks a connector beside a red stop tab in a control plan illustration.

Turn this article into takeaways for your work.

Each assistant summarizes the article only for you and suggests best practices for your work.

Every improvement project ends the same way. The team fixes the problem, the chart looks beautiful for six weeks, the sponsor moves on, then a new operator starts, a supplier changes resin lots, the fixture wears, and nobody notices until a customer does. The gain wasn't lost in one dramatic event. It leaked out, because nothing in the daily running of the process was changed to hold it.

A control plan closes that gap. It's a written record of what gets measured on a process, how, how often, by whom, and exactly what happens when the measurement comes back wrong. That last part is the whole point. Plenty of teams measure things. Far fewer have written down, in advance, what the operator does at 2am when the reading is out of spec and the supervisor is across the plant.

Key Facts: Control Plans

  • The control plan no longer lives in the APQP manual. Effective 1 March 2024, AIAG published APQP 3rd Edition alongside a standalone Control Plan 1st Edition (AIAG), and the APQP manual's description now lists "the removal of Control Plan content, now a standalone document" (AIAG).
  • AIAG's reason: "Decoupling the two documents also emphasizes the importance of control plans in product development and will facilitate more timely updates as systems evolve." Implementation was required by GM and Stellantis as of 1 September 2024, and by Ford as of 31 December 2024 (AIAG).
  • The new manual added a "Safe Launch" requirement to control plan phases, plus guidance on managing control plans in software (AIAG).
  • The standard itself has not moved. IATF 16949:2016 is still current, with a second edition planned for mid-2027 (Smithers, August 2026).

What a Control Plan Actually Is

A control plan is a structured summary of the controls applied to a process, written characteristic by characteristic. For each thing that matters, it records the specification, the method used to check it, the sample size and frequency, the mechanism keeping the characteristic where it belongs, and the reaction plan that fires when it doesn't.

It is not a procedure. It doesn't tell an operator how to run the machine. It tells the organization which few characteristics are load-bearing and what the agreed response is when one moves. It answers a single question asked of every process step: if this goes wrong, how would we know, how fast, and who does what?

Its place in sustaining improvements is structural. A DMAIC project has a Control phase for exactly this reason, and the control plan is usually its main deliverable. Improve produces the new setting, the new fixture, the new sequence. Control decides whether that change is still there next quarter. Without a document naming the new critical characteristic and assigning a check to it, the improvement lives only in the memory of the people who ran the project. Those people get reassigned.

Where Control Plans Come From, and What Changed in 2024

Control plans originated in the automotive supply chain as a core quality tool, alongside FMEA, MSA, SPC and PPAP. For three decades the requirements lived in a combined AIAG manual called APQP and Control Plan. That's where most training material still points, and it's now wrong.

Effective 1 March 2024, AIAG replaced the combined 2nd Edition with two documents: APQP 3rd Edition, and a standalone Control Plan 1st Edition (AIAG). Control plan content was pulled out of the APQP manual entirely, a change AIAG lists plainly in the APQP 3rd Edition description as "the removal of Control Plan content, now a standalone document" (AIAG). Writing in Quality, John Vandenbemden described the result as "a standalone Control Plan Reference Manual that maintains the linkages between the other core tools under APQP" (Quality, August 2024).

AIAG's explanation for the split tells you how the document is meant to be used: "Decoupling the two documents also emphasizes the importance of control plans in product development and will facilitate more timely updates as systems evolve" (AIAG). A control plan should change more often than the planning framework around it. The dates matter if you supply the industry: GM and Stellantis required implementation as of 1 September 2024, Ford as of 31 December 2024.

One thing did not change, and it gets misreported often enough to state flatly. The automotive quality standard is still IATF 16949:2016. Revision work begins after ISO 9001 is republished, with a second edition planned for mid-2027 and its transition aligned to the end of the ISO 9001 transition (Smithers). The manual moved; the standard did not, and that's the distinction auditors will test. The standard and your customer-specific requirements carry the obligation, and the AIAG manual is guidance for meeting it.

The Three Types, Plus the Phase That Got Added

Control plans are written per phase, because what you're protecting changes as a product matures: the design decision early on, a process nobody has run at volume at launch, then a known-good state against drift.

Prototype, pre-launch, and production connectors progress through checks on a workbench.

Type When it applies What it protects Typical intensity
Prototype Early builds, before the process is fixed The design, and the data proving it works Heavy dimensional and material checks, often 100% inspection
Pre-launch After prototype, before production sign-off A process that has not yet shown stability at volume Tightened frequencies, added checks, extra containment
Production Ongoing manufacture, after part approval A validated process against drift, wear, turnover and supplier variation Sampling and statistical monitoring, sized to capability

The 2024 manual added a Safe Launch requirement to those phases (AIAG). Treat it as an extra, deliberately temporary layer of control around the start of production, with its own exit criteria, not a fourth permanent plan. If a customer imposes safe launch conditions, read their requirement rather than a summary of it, including this one.

The common mistake isn't picking the wrong type. It's never leaving pre-launch. Teams tighten controls for launch, the launch goes fine, and the tightened checks stay forever because nobody wrote down what would justify relaxing them. Define the exit criteria (consecutive stable subgroups, a demonstrated capability index, a defect-free volume) when you define the elevated check.

Reading a Control Plan Column by Column

A control plan is only as good as the discipline in each column. Here is what each column is really asking, and where teams go wrong.

A critical connector feature, caliper, clock, and quarantine tray show control plan checks.

Column What belongs in it The common failure
Process step Operation number and name, matching the flow and the process documentation Numbering that drifts out of sync with the flow diagram, so nobody can trace a defect back
Characteristic The product or process characteristic controlled, flagged if special or safety-related Listing every dimension on the drawing, burying the handful that matter
Specification The requirement and tolerance, in the units the operator reads A spec the gauge on the floor cannot resolve
Measurement method The named gauge, plus evidence the measurement system is trustworthy No measurement systems analysis, so a gauge with more variation than the tolerance judges conformance
Sample size How many pieces per check A sample of one, presented as a statistical conclusion
Frequency How often the check runs, and what events also trigger it "Per shift" with no event triggers, so a material or tool change goes unchecked
Control method The mechanism holding the characteristic in place: a chart, a poka-yoke device, an interlock, a setup approval Naming a document instead of a mechanism, as in "per SOP"
Reaction plan What happens when the check fails: containment, notification, correction, disposition A single word, "adjust"

Two columns carry more weight than the rest. Measurement method is where control plans quietly fail, because a bad measurement makes every downstream number meaningless. NIST/SEMATECH frames a gauge study's purpose as "to outline the steps that can be taken to characterize the performance of gauges and instruments used in a production setting in terms of errors that affect the measurements" (NIST/SEMATECH). If the gauge eats a large share of your tolerance, tightening the process won't help.

Sample size and frequency carry a statistical claim you may not have earned. Capability indices compare "the output of an in-control process to the specification limits," most estimates "are valid only if the sample size used is large enough," generally about 50 independent values, and they assume normally distributed data (NIST/SEMATECH). That rules out much of what gets reported as process capability.

A Filled-In Control Plan

Abstract columns are easy to nod along to. Here are two rows from a production-phase control plan for an injection-molded connector housing. The header above them carries the identification: part number and revision, phase (Production), the plant and process covered, the core team, the revision number and date, and customer approval where required.

Process step Characteristic Specification Measurement method Sample Frequency Control method Reaction plan
Op 30 Mold Wall thickness at boss A (special characteristic) 2.40 mm plus or minus 0.10 mm Ultrasonic gauge, 5-position fixture, gauge study on file 5 pieces Every 2 hours, plus every resin lot and tool change X-bar and R chart at the press Quarantine back to the last conforming check, team leader in 10 minutes, adjust per WI-30-04, quality engineer dispositions held stock, 100% check until two conforming subgroups pass
Op 45 Weld Weld pull strength 350 N minimum Destructive pull test on a sacrificial part 1 piece Start of shift, every horn change, every 4 hours Weld energy window locked in the controller with alarm limits Contain back to the last passing test, escalate to process engineering that shift, re-qualify with 3 passing tests

Read the first row again with the sustaining question in mind. Nothing in it is clever. What it does is remove every decision from the moment of the problem. The operator doesn't judge how far back to quarantine, whether ten minutes is too soon to bother the team leader, or how many good checks are enough before resuming. Those judgments were made in a quiet room by people with more information, and written down. That's how an improvement survives contact with a Tuesday night shift. Notice too that the weld row's control is a locked parameter window rather than a chart. Plans get stronger as control moves upstream, from detection toward prevention.

From FMEA to Control Plan to Reaction Plan

This is the linkage most teams get wrong, and it separates a real control plan from a filled-in template. A failure mode and effects analysis already contains almost everything the control plan needs. If the two were built independently, one of them is wrong.

FMEA output Where it lands in the control plan What breaks if the link is missing
Process function and step Process step column The plan controls a step the FMEA never analyzed for risk
Failure mode The characteristic chosen for control You control what is easy to measure instead of what can fail
Effect and severity rating Whether the characteristic is flagged special, and how hard the controls are High-severity failures get the same routine sampling as cosmetic ones
Cause and occurrence rating Frequency, and what events trigger an extra check Checks run on a clock unrelated to when the cause acts
Current prevention control Control method column, the preventive half Prevention lives only in the FMEA, so nobody maintains it
Current detection control Measurement method plus control method The FMEA claims detection credit for a check the floor never runs
Recommended action, once implemented An updated row, and a re-scored FMEA The fix stays an action item, never a standing control

Run the two as one loop, not two deliverables. When a corrective action from a root cause analysis closes, three things change together: the FMEA scores, the control plan row, and the work instruction the operator reads. Update only the FMEA and you've documented a belief rather than a control. This is also the cleanest place to watch quality assurance and quality control meet in one artefact. ASQ, citing ISO 9000:2015, defines quality assurance as "part of quality management focused on providing confidence that quality requirements will be fulfilled" and quality control as "part of quality management focused on fulfilling quality requirements" (ASQ). The plan's planning half is assurance; its checks and reactions are control.

The Reaction Plan Does the Sustaining Work

Improve one column and make it this one. Every other column describes a state of the world; the reaction plan describes a decision, and decisions are what decay.

A stopped production belt holds suspect parts before verification and restart.

"Adjust process" is a wish. A usable reaction plan answers five questions before the problem happens.

Element The question it answers What a usable answer looks like
Containment What happens to product made since the last good check? "Quarantine back to the last conforming check, red-tag the rack"
Notification Who gets told, and how fast? "Team leader within 10 minutes, quality engineer if unresolved at 30"
Correction What adjustment is authorized, and by whom? "Team leader may adjust barrel temperature within the WI-30-04 window; outside it requires process engineering"
Disposition Who decides the fate of held product? "Quality engineer dispositions held stock: scrap, rework per RW-12, or use-as-is with concession"
Resumption What evidence justifies restarting? "Two consecutive conforming subgroups before normal sampling resumes"

The signal that triggers all of this has to be visible where the work happens, which is why the reaction plan and visual management belong to the same conversation. Toyota's description of its production system makes the mechanism explicit: "When equipment stops, the andon (problem display board) lights up to notify workers of the abnormality," and on lines without equipment "the andon is set to light up when the stop cord is pulled so that workers can call the person in charge" (Toyota). A reaction plan in a binder relies on someone remembering it exists. One wired to a light, a board, or an alarm limit gets executed.

The statistical trigger needs the same precision. If the control method is a control chart, name the rules that count as a signal, not just "out of spec." NIST's handbook puts it plainly: "If a data point falls outside the control limits, we assume that the process is probably out of control and that an investigation is warranted to find and eliminate the cause or causes" (NIST/SEMATECH). Out of control and out of specification are different events with different reactions, and real statistical process control is what makes that distinction operational rather than rhetorical.

Control Plan vs SOP vs Work Instruction

These three get conflated constantly, usually by someone trying to merge them to reduce paperwork. They answer different questions for different readers.

A monitoring gauge, process scroll, and fastening tool distinguish three operating documents.

Dimension Control plan Standard operating procedure Work instruction
Question it answers What do we monitor, how often, and what happens when it moves? How is this process run end to end, and who owns it? How does this person do this task at this station?
Scope One process or product family, characteristic by characteristic One process, including handoffs and roles One task or operation
Primary audience Quality, engineering, leadership, auditors, customers The process owner and everyone in the process The operator doing the work
Changes when Risk, capability, customer requirement or performance changes The process design changes The method or tooling changes
Typical failure Written once for approval, never revised Describes an idealized process nobody runs Written by someone who has never done the job

They should reference each other, not repeat each other. A control plan row saying "correct per WI-30-04" is doing its job: it names the authorized correction without copying an instruction that will drift. The standard operating procedure sets out the process, standard work captures the agreed best method, and the control plan sits above both naming which characteristics are worth defending. Under ISO 9001 all three are slices of controlling production and service provision, which is why an auditor follows a thread from one to the next and expects them to agree.

Control Plans Outside Manufacturing

The tool travels further than most people expect. Its use spread beyond cars long ago, into "many other industries such as heavy equipment, medical devices, and aerospace" (Quality, 2024), and it survives translation into a service process because the question doesn't change. What matters here, how would we know it moved, and what happens then?

Service envelopes pass a timing gate while an exception waits in a separate tray.

Translation is simple. Process step becomes the workflow stage, characteristic becomes whatever determines a good outcome there, specification becomes a service level or accuracy threshold, and control method becomes a validation rule, an approval gate, or a dashboard. The reaction plan stays exactly what it was.

Process step Characteristic Specification Measurement method Frequency Control method Reaction plan
Invoice creation Billing matches the signed contract 100% match on rate, term and quantity Automated variance report against the contract record Every invoice, before release System hard-stop on any variance Hold the invoice, analyst reconciles within 1 business day, contract owner approves intended variances
Customer onboarding Contract signed to first successful login 5 business days or fewer Timestamps from the onboarding system Weekly, all accounts closed that week Queue with age-based escalation visible to the team Past day 4, escalate to the onboarding lead, who names an owner and a date; past day 5, weekly review with a cause code recorded
Ticket triage Correct priority at first touch 95% agreement with the priority matrix Sampled audit of closed tickets 20 tickets per week Priority matrix as a required field in the ticket form Coach the individual within 2 days; two weeks below 95% triggers a matrix review, not a coaching cycle

That third reaction plan shows the discipline the tool imposes: it separates an individual miss from a systemic one and commits in advance to which response each gets. Two other habits carry over. Write the specification as a real threshold, not an aspiration (this is where service level agreements do the same job as a tolerance), and pick a few outcome measures such as first pass yield rather than instrumenting everything a system logs. The point of monitoring a process is to trigger a decision, and a measure with no reaction attached is just reporting.

Keeping It Alive: Revisions and Triggers

The difference between a live control plan and a dead one is whether anything other than the calendar can trigger a revision. Annual review alone leaves the plan, on average, six months out of date.

Trigger What to re-check Who usually owns it
Customer complaint or field failure Was the failure mode in the FMEA, the characteristic in the plan, and did the reaction plan run? Quality engineer with the process owner
Internal defect escape or scrap spike Detection controls and frequency for that characteristic Process owner
Process, tooling, material or supplier change Every row touching the change, plus the measurement system if the gauge moved Process engineering
Capability shift, better or worse Sample size and frequency, and whether elevated launch controls can be relaxed Quality engineer
Layout, automation or software change Whether the named control mechanism still physically exists Process engineering
New customer requirement Special characteristic designations and approval status Quality manager
Corrective action closure The row the action changed, plus the matching FMEA score and work instruction Action owner

Closing a corrective action without editing the control plan is the most common way a fix evaporates, so build the edit into the closure criteria.

Then audit it properly. Reviewing the document only proves the document exists. Walk the process with the plan in hand and check three things per row: does the named gauge exist and is it calibrated, does the check run at the stated frequency, and can the operator say what happens when it fails. The third question finds the dead reaction plans.

Limitations: A Control Plan Nobody Audits Is Paperwork

Being honest about the failure modes is what keeps the tool useful.

A magnifying glass checks an operating lever beside a control folder and caliper.

Limitation Why it matters
It documents controls, it does not perform them A perfect plan and an unstaffed check produce the same parts as no plan at all
It inherits the FMEA's blind spots A failure mode nobody imagined appears in no column, so the plan never replaces a real root cause investigation when something new happens
Over-inclusion dilutes it A plan with sixty characteristics teaches the floor that none are special; the discipline is in what you leave out
Sampling can promise more than it supports Capability and stability claims need enough data, an in-control process and a defensible distribution assumption (NIST/SEMATECH)
Detection-heavy plans are expensive and fragile Every row that catches a defect instead of preventing one is a recurring cost that depends on human attention
The manual is guidance, not a template AIAG's manual "provides guidance and is not prescriptive" (Quality, 2024), so copying another plant's format carries none of its risk thinking

None of these argue against control plans. They argue against treating one as a deliverable rather than a working document. The plan earns its keep the day something goes wrong and nobody has to improvise.

Frequently Asked Questions about Control Plans

What is a control plan?

A control plan lists, characteristic by characteristic, what gets measured on a process, the specification, the measurement method, the sample size and frequency, the control method, and the reaction plan that runs when a check fails. Its job is to keep a process performing as designed long after the project that improved it ends.

Is the control plan still part of the AIAG APQP manual?

No. Effective 1 March 2024, AIAG published APQP 3rd Edition and a standalone Control Plan 1st Edition, and control plan content was removed from the APQP manual, listed by AIAG as "the removal of Control Plan content, now a standalone document." GM and Stellantis required implementation as of 1 September 2024, Ford as of 31 December 2024.

What are the three types of control plan?

Prototype, pre-launch, and production. Prototype plans protect the design during early builds. Pre-launch plans apply tighter, temporary controls to a process that hasn't proven itself at volume. Production plans defend a validated process against drift. The 2024 manual added a "Safe Launch" requirement to those phases.

What is a reaction plan?

The column stating what happens when a check fails. It covers containment of product made since the last good check, who is notified and how fast, what correction is authorized and by whom, who dispositions held material, and what evidence justifies resuming. It separates a plan that sustains an improvement from one that records intent.

How is a control plan different from an SOP?

An SOP describes how a process is run end to end. A control plan describes what is monitored inside that process, how often, and what happens when a measurement goes wrong. The SOP is the method; the control plan is the safety net over the characteristics that matter most.

Can you use a control plan outside manufacturing?

Yes. Replace the process step with a workflow stage, the characteristic with whatever determines a good outcome there, and the specification with a service level or accuracy threshold. Billing accuracy, onboarding cycle time and triage accuracy all fit. The reaction plan translates unchanged, and it is usually the part a service team is missing.

Control plans have a reputation for bureaucracy because so many were written to be approved rather than used. A good one is short, honest about which characteristics carry the risk, specific about who does what when a check fails, and revised the moment the process underneath it changes. Get those four right and the plan stops being documentation of an improvement and becomes the reason the improvement is still there.

About the author

Tara Minh

Tara Minh

Senior Operations & Growth Strategist

Tara Minh is Senior Operations & Growth Strategist at Rework, helping B2B SaaS leaders scale without breaking their teams. With 8+ years in revenue operations and process optimization, Tara turns messy workflows into systems people actually follow. Readers get practical frameworks they can use to cut waste, align teams, and grow on purpose.