AS9120 Requirements Guide for Distributors: Ensuring Component Authenticity for OEM Buyers
Practical guide for buyers and engineers: AS9120 Requirements Guide for Distributors: Ensuring Component Authenticity for OEM Buyers. Sourcing, risk, and selection notes.
Why Counterfeit Components Are a Growing Sourcing Risk for OEMs
Counterfeit electronic components have moved from an occasional nuisance to a persistent, structural threat in high-reliability supply chains. For aerospace, defence, and medical OEMs, a single counterfeit microcontroller or aged-and-re-marked capacitor can trigger latent field failures, void certifications, and create liability that cascades through the entire product lifecycle. The sophistication of bad actors has grown in lockstep with global supply chain complexity — and the old habit of relying on supplier reputation alone is no longer defensible.
What changed is not just the volume of counterfeit parts but the attack surface. Long, multi-tier distribution channels, last-time-buy panic, and allocation-driven spot buying all create openings that counterfeiters exploit. A distributor that cannot demonstrate chain-of-custody control from the original component manufacturer (OCM) through to delivery becomes a single point of failure for an entire BOM. This is precisely why AS9120 certification has evolved from a nice-to-have credential into a de facto gatekeeper for approved vendor lists at major aerospace primes and Tier 1 integrators.
Industry guidance is unambiguous on this point. Smithers describes the AS9120 mandate for a counterfeit parts prevention program that starts with supplier verification and extends through procurement, receiving, and storage — requiring distributors to source parts only from approved or reputable origins [4]. Serendipity Electronics reinforces that product identification and traceability — using unique identifiers, barcoding, or RFID technology — is fundamental, not optional, for tracking components from origin to final destination [1]. AUVA Certification captures the distinction succinctly: AS9120 is designed for distributors, not manufacturers, and it emphasizes supply chain control, product authenticity, traceability, and precise documentation from suppliers to end-users [3].
The procurement reality is straightforward. When your approved vendor list includes a non-certified broker, your organization absorbs the verification burden that AS9120-certified distributors have already addressed through audited processes. For OEM buyers managing mixed BOMs — where a single line item sourced from an uncertified channel can compromise an entire assembly — the cost of that burden often exceeds the apparent savings on component unit price. The question has shifted from "can we trust this supplier?" to "can we verify their traceability end-to-end?" AS9120 provides a standardized, auditable framework for that verification, and OEMs are increasingly writing it into supplier quality manuals as a non-negotiable requirement.
Inside AS9120: Traceability, Documentation, and Counterfeit Prevention
AS9120 is not a light overlay on ISO 9001. It is a sector-specific quality management standard with over 100 aerospace-specific additions, purpose-built for organizations that distribute — rather than manufacture — aerospace components. The standard's architecture targets the exact points where counterfeit parts enter the supply chain, and it does so through three interdependent pillars: traceability, documentation integrity, and supplier management.
Traceability under AS9120 means that every component must be identifiable back to its OCM or authorized source through documented chain-of-custody records. This is not a batch-level approximation. AmtiVo clarifies that organizations must implement rigorous procedures for product identification, record keeping, and supplier management so that all parts are authentic, documented, and traceable from receipt through delivery [2]. When a distributor receives a reel of 3,000 MLCCs, the AS9120-compliant process does not simply log "3,000 capacitors from Supplier X." It records the OCM lot number, date code, country of origin, incoming inspection results, and the unique identifier — barcode or RFID — that links that specific reel to its procurement paperwork.
Documentation integrity extends this traceability through the entire dwell time at the distributor. TUV USA emphasizes that documentation must accurately reflect the journey of each component from the original equipment manufacturer to the end customer, which is crucial for verifying authenticity and ensuring compliance with aerospace standards [7]. This means that if a distributor re-packages, re-labels, or consolidates partial reels, every transformation is recorded in a way that preserves the link to the original OCM documentation. For the OEM buyer, this audit trail is what turns a component from an anonymous part into a documented, verifiable asset.
Supplier management and counterfeit prevention form the third pillar. AS9120 requires a documented counterfeit parts prevention program that governs how the distributor evaluates, approves, and monitors its own suppliers. This includes risk-based supplier categorization, periodic re-evaluation, and clear criteria for disqualifying suppliers that fail to maintain traceability standards. The program must be active, not cosmetic — auditors will sample incoming inspection records, trace specific parts back through the system, and verify that the distributor's supplier approval records match actual procurement practices.
Tip: When evaluating a distributor's AS9120 credentials, ask specifically about their counterfeit prevention program documentation. A distributor that hesitates to share the program outline or cannot describe their supplier re-evaluation cadence is signaling a gap you should investigate further.
The table below maps key AS9120 clauses to the authenticity value they deliver for OEM buyers. Each clause addresses a specific risk vector in the distribution chain.
| AS9120 Clause Area | Core Requirement | Authenticity Value for OEM Buyers |
|---|---|---|
| Product Identification & Traceability (8.5.2) | Unique identifiers (barcode/RFID) linking parts to OCM lot, date code, and procurement records throughout the distribution cycle | Eliminates anonymous parts; enables full chain-of-custody audit from OCM to your receiving dock |
| Supplier Management (8.4) | Risk-based supplier approval, periodic re-evaluation, and documented disqualification criteria; procurement only from approved sources | Reduces risk of parts entering through unauthorized or grey-market channels; documented supplier pedigree |
| Counterfeit Parts Prevention (8.1.4) | Mandatory documented program covering supplier verification, incoming inspection, part authentication methods, and quarantine procedures for suspect parts | Proactive barrier against re-marked, cloned, or salvaged components reaching your production line |
| Record Retention (7.5.3) | Comprehensive records maintained for defined retention periods, including all inspection reports, certificates of conformance, and traceability documentation | Supports your own audit and regulatory requirements; evidence chain available for failure investigations |
| Preservation of Product (8.5.4) | Controlled storage conditions, ESD protection, moisture sensitivity management, and shelf-life monitoring during distribution | Components arrive in manufacturer-specified condition; no degradation-induced latent failures from improper handling |
| Monitoring & Measurement (8.6) | Incoming and outgoing inspection protocols with defined acceptance criteria and documented test results | Independent verification gate between supplier shipment and your production; catches transit damage and labeling discrepancies |
| Control of Nonconforming Outputs (8.7) | Documented process for segregating, investigating, and dispositioning nonconforming parts, including root cause analysis and corrective action | Prevents nonconforming or suspect parts from being re-introduced into saleable inventory; systemic learning from each incident |
| Internal Audit & Management Review (9.2 / 9.3) | Regular internal audits plus annual surveillance audits by the certification body to verify ongoing compliance | Certification is not a one-time event; ongoing oversight ensures processes remain effective, not just documented |
What distinguishes the AS9120 framework is that these clauses operate as an integrated system, not a checklist. Traceability without supplier management leaves you with beautifully documented parts from unverified sources. Counterfeit prevention without rigorous record retention means you cannot prove authenticity when an auditor — or a failure analysis lab — asks for evidence. For the OEM buyer, the practical takeaway is that AS9120 certification signals a distributor has built the organizational infrastructure to deliver authenticity reliably, not just on the day of an audit.
Certified vs. Non-Certified Distributors: What the AS9120 Badge Actually Proves
The marketplace for electronic components spans a wide spectrum, from franchised distribution with direct OCM relationships through to independent brokers operating with minimal documented processes. Between these poles sits a large population of distributors that hold ISO 9001 certification but have not pursued the aerospace-specific AS9120 standard. Understanding what the AS9120 badge actually proves — and what gaps remain when you rely on ISO 9001-only suppliers — is essential for writing procurement specifications that match your product's reliability requirements.
J2 Sourcing's breakdown of AS9120B certification value highlights three dimensions that separate certified distributors from the rest: consistency through stringent quality control processes, compliance assurance through regular audits, and comprehensive documentation that supports customers during their own audits and inspections [5]. ISO 9001 addresses the first dimension — quality process consistency — but it does not require the aerospace-specific controls that make the second and third dimensions meaningful for high-reliability procurement.
The practical consequences of this gap become clear when you examine what Wintersmith Advisory identifies: OEMs and Tier 1 suppliers frequently require AS9120 certification for approved distributor status [6]. This requirement exists because aerospace primes have learned — through costly field returns and audit findings — that ISO 9001 alone does not mandate counterfeit prevention programs, full lot traceability to the OCM, or the supplier vetting rigor that AS9120 demands. An ISO 9001-certified distributor may be running a well-documented general quality system while simultaneously sourcing from unauthorized channels and lacking the traceability infrastructure to detect a re-marked lot before it ships.
AmtiVo adds another dimension: AS9120-certified organizations undergo annual surveillance audits to verify continued compliance [2]. ISO 9001 also includes surveillance, but the AS9120 audit scope specifically probes the aerospace-specific additions — counterfeit prevention, traceability, and supplier approval — that ISO 9001 auditors may never examine. A distributor that achieved AS9120 certification three years ago but cannot produce current surveillance audit reports is effectively operating on an expired credential.
The side-by-side comparison below highlights the operational differences that matter when you are qualifying a source for production BOMs.
| Comparison Metric | AS9120-Certified Distributor | ISO 9001-Only / Non-Certified Distributor | Risk Level & Verification Required |
|---|---|---|---|
| Counterfeit Prevention Program | Mandatory documented program with supplier verification, incoming inspection protocols, and quarantine procedures; audited annually | Not required; may have ad hoc incoming inspection but lacks formal counterfeit-specific controls | High risk gap. Without formal program, suspect parts may enter inventory and be shipped before detection |
| Lot Traceability to OCM | Full chain-of-custody from OCM/authorized source through all intermediate steps to customer delivery; unique identifiers maintained | May trace to immediate supplier only; OCM origin often undocumented or lost at intermediate handling points | Critical for aerospace/defence. Inability to trace to OCM invalidates part pedigree for high-reliability applications |
| Supplier Approval Process | Risk-based approval with documented criteria, periodic re-evaluation, and disqualification triggers; procurement restricted to approved suppliers | May have basic supplier evaluation but typically lacks aerospace-specific criteria and formal re-evaluation cadence | Moderate to high risk. Open-market sourcing without supplier vetting introduces grey-market exposure |
| Audit Frequency & Scope | Annual surveillance audits by accredited body (e.g., TUV, BSI, Amtivo) covering all aerospace-specific clauses; full re-certification every 3 years | ISO 9001 surveillance audits cover generic quality management; aerospace-specific risks not in scope | Verification gap. ISO 9001 audit does not confirm aerospace-grade traceability or counterfeit controls exist |
| Documentation Depth | Certificates of conformance with OCM lot/date code, incoming inspection reports, test data when specified, and full chain-of-custody records | May provide basic CoC with limited traceability data; batch-level documentation often incomplete or supplier-only | Audit exposure. Your own regulatory audits may fail if supplier documentation cannot demonstrate part authenticity |
| Industry Recognition | Recognized by aerospace primes, Tier 1 integrators, and government agencies as meeting approved supplier requirements | May be accepted for commercial/industrial applications but typically rejected at aerospace source inspection | Qualification barrier. Using non-certified sources may require customer waiver or additional incoming inspection |
The comparison underscores a procurement principle that experienced buyers apply routinely: match the supplier certification level to the end-product reliability class. For commercial IoT devices with field-replaceable modules, an ISO 9001 distributor with demonstrated process control may be an acceptable, cost-effective source. For flight-critical avionics, medical implantables, or defence systems where a single counterfeit component can create a safety-of-life hazard, AS9120 certification becomes the minimum bar — and many buyers supplement it with additional incoming inspection protocols such as X-ray, decapsulation, or electrical testing on sampled lots.
Key Takeaway: The AS9120 badge does not merely signal a distributor's quality aspirations — it proves that an independent, accredited body has verified the existence and effectiveness of specific, aerospace-caliber authenticity controls. ISO 9001 alone leaves those controls as optional, and in high-reliability procurement, optional controls become uncontrolled risks.
How to Verify an AS9120-Certified Supplier and Write a Sourcing Spec
AS9120 certification is a powerful signal, but like any credential, it requires verification. A distributor that claims "certified to AS9120 standards" without a valid certificate from an accredited registrar is not equivalent to one that holds active certification with documented surveillance audits. Engineers and procurement professionals who incorporate AS9120 verification steps into their supplier qualification process close a common gap between assumed compliance and demonstrated compliance.
The verification process starts with the certificate itself. Every legitimate AS9120 certificate includes the distributor's legal name, scope of certification, issuing registrar (accreditation body), certificate number, issue date, and expiry date. The registrar's online database — whether TUV, BSI, Amtivo, or another International Aerospace Quality Group (IAQG)-recognized body — provides independent confirmation that the certificate is current and that the scope covers the component categories you are buying. A certificate that cannot be validated through the registrar's public database, or one that lists a scope unrelated to electronic component distribution, should trigger immediate escalation.
Serendipity Electronics' emphasis on product identification and traceability methods — unique identifiers, barcoding, RFID — provides a concrete verification lens [1]. When qualifying a distributor, request a sample traceability record for a recent shipment. The record should demonstrate linkage from the distributor's internal identifier back through receiving inspection to the OCM lot number and procurement documentation. If the distributor cannot produce this within a reasonable timeframe, the traceability system may exist on paper but not in practice.
AUVA's characterization of AS9120 as emphasizing product authenticity, traceability, and precise documentation from suppliers to end-users provides the framework for writing a sourcing specification that leaves no ambiguity [3]. The specification should make AS9120 compliance a contractual requirement, not a preference, and should define the documentation deliverables that accompany each shipment.
The table below outlines the RFQ elements that translate AS9120 requirements into verifiable, contractually enforceable sourcing specifications.
| RFQ / Contract Element | What to Specify | Verification Method & Red Flags |
|---|---|---|
| Certification Status | Distributor must hold active AS9120 certification from an IAQG-recognized registrar; specify certificate number and expiry date in the quotation response | Validate certificate against registrar's online database. Red flag: "self-certified" claims, expired certificates, or scope that excludes electronic components |
| Lot Traceability | Every line item must include OCM name, OCM part number, date code, lot/batch code, and country of origin; traceability must extend to the OCM or franchised/authorized source | Request a pre-shipment traceability sample. Red flag: traceability stops at an intermediate broker or consolidator; date codes are inconsistent with known OCM production windows |
| Counterfeit Avoidance Clause | Distributor warrants that all parts are authentic, sourced from OCM-authorized channels, and have not been re-marked, refurbished, or salvaged; suspect parts subject to return and root-cause investigation | Request the distributor's counterfeit prevention policy document. Red flag: distributor cannot produce the policy or it lacks supplier verification and quarantine procedures |
| Audit & Surveillance Reports | Require the most recent AS9120 surveillance audit report summary (non-conformities, observations, and corrective actions); specify that major non-conformities must be closed before shipment | Review for unresolved findings related to traceability or supplier management. Red flag: distributor refuses to share or claims audit reports are confidential |
| Incoming Inspection & Test Data | Specify any additional inspection requirements beyond standard AS9120 receiving inspection — for example, X-ray sampling, solderability testing, or electrical verification on date-code-sensitive parts | Define acceptance criteria and test report format in the RFQ. Red flag: distributor agrees to testing but cannot describe their test methodology or equipment |
| Change Notification | Distributor must notify you of any changes to OCM, lot, date code, or country of origin before shipment; shipment of alternate lots requires written approval | Include in purchase order terms. Red flag: shipment arrives with different date codes than quoted without prior notification — indicates inventory management gaps |
Beyond the RFQ table, there are additional verification practices that experienced procurement teams employ. Request a completed Supplier Quality Questionnaire that covers the distributor's ESD control program, moisture-sensitive device handling procedures, and shelf-life management for date-code-sensitive components. Visit the distributor's facility when the component value or production volume justifies the travel cost — a walk-through of the incoming inspection area and quarantine cage reveals more about process discipline than any document can. And maintain a periodic re-verification cadence: check certificate status and audit reports annually, not just at initial qualification.
Red flags that warrant immediate investigation include:
- Vague certification language: Phrases like "certified to AS9120 standards" or "AS9120 compliant" without a certificate number and registrar name often indicate self-assessment rather than independent certification.
- Reluctance to share audit findings: Legitimate distributors understand that aerospace customers need visibility into their quality system performance. A blanket refusal to share surveillance audit summaries is inconsistent with the transparency AS9120 promotes.
- Incomplete batch traceability: If a distributor cannot produce a clear, documented link from a specific component lot back to the OCM, the traceability system has either failed or does not exist in the form the standard requires.
- Certificate scope mismatch: A distributor certified for "distribution of aerospace fasteners" is not certified to distribute electronic components — the scope statement must match what you are buying.
- Unusually low pricing on allocation-sensitive parts: When a non-franchised distributor quotes significantly below market on parts that are allocation-constrained across authorized channels, the price advantage may reflect counterfeit or re-marked inventory rather than supply chain efficiency.
AS9120 Sourcing FAQs: What Engineers and Buyers Need to Ask
Engineers and procurement professionals navigating AS9120 requirements encounter recurring questions that go beyond standard definitions. The answers below draw on the research sources and reflect practical, senior-level guidance for integrating AS9120 into sourcing decisions.
Q: Is AS9120 certification mandatory for all aerospace component distributors?
AS9120 is not a legal mandate in the sense that regulations like ITAR or EAR carry statutory force. However, as a practical matter, many aerospace manufacturers, OEMs, Tier 1 suppliers, and government agencies require or strongly prefer their suppliers and distributors to be AS9120-certified as part of their approved supplier list [2]. If you are selling into aerospace or defence supply chains, your customers' supplier quality manuals likely specify AS9120 as a condition of approved status. Even when not contractually required, the certification effectively signals that a distributor has robust traceability and counterfeit prevention processes that meet industry expectations — and the absence of it shifts the verification burden onto your incoming inspection team.
Q: How can I verify that a distributor's AS9120 certificate is genuine and current?
Check the certificate number against the issuing registrar's online database. Registrars such as TUV, BSI, and Amtivo maintain publicly accessible certificate directories where you can confirm validity, scope, and expiry. The scope of certification is particularly important — it must cover the component types and distribution activities relevant to your procurement. Confirm that annual surveillance audit dates are current; a certificate without evidence of ongoing surveillance may have lapsed or been suspended. Distributors certified by IAQG-recognized bodies will appear in the Online Aerospace Supplier Information System (OASIS) database, which is the definitive source for aerospace certification status.
Q: Does AS9120 certification guarantee that a component is authentic?
No certification can guarantee zero counterfeits — such a guarantee would be commercially irresponsible to offer and technically impossible to fulfill. What AS9120 does is require a documented counterfeit parts prevention program, an approved supplier base, and full traceability documentation [4]. These controls dramatically reduce risk relative to uncertified channels, but they are risk-reduction mechanisms, not risk-elimination guarantees. Buyers should still perform incoming inspection and, for safety-critical components, consider additional testing such as X-ray inspection, decapsulation, or full electrical characterization on sampled lots. An AS9120-certified distributor should welcome this testing because its processes are designed to produce conforming, authentic parts that will pass such scrutiny.
Q: What is the difference between AS9120 and AS9100?
AS9100 is the aerospace quality management standard for manufacturers; AS9120 is specifically for distributors of aerospace parts [3]. The distributor standard focuses on supply chain control, part traceability, and documentation integrity rather than production process control, design authority, or configuration management — areas that are central to AS9100. Both standards include all ISO 9001 requirements plus aerospace-specific additions, but the additions diverge to reflect the fundamentally different risk profiles of manufacturing versus distribution. A distributor does not need AS9100; conversely, an AS9100-certified manufacturer that also distributes parts may not have the traceability and counterfeit prevention controls that AS9120 specifically mandates for distribution activities.
Q: Can a distributor with only ISO 9001 still be a reliable source for high-reliability components?
ISO 9001 covers generic quality management principles — process control, document management, corrective action — but it lacks the aerospace-specific counterfeit prevention and traceability requirements that define AS9120. While some ISO 9001 distributors maintain high-quality operations, the absence of mandatory supplier vetting, lot-level OCM traceability, and a documented counterfeit prevention program introduces avoidable risk for OEMs building high-reliability products. For commercial or industrial applications with benign failure consequences, an ISO 9001 distributor with demonstrated performance may be acceptable. For aerospace, defence, or medical applications where a single counterfeit can create a safety-of-life hazard, relying on ISO 9001 alone places an uncomfortable verification burden on your organization. The safest path is to confirm current availability and allocation via RFQ through AS9120-certified channels and treat alternative sources as requiring additional incoming verification.
Q: What should I include in an RFQ to ensure an AS9120-compliant supply chain?
Your RFQ should specify that the distributor must hold active AS9120 certification with a scope covering the component categories quoted, provide full lot traceability back to the OCM or authorized source, and comply with a counterfeit avoidance clause that warrants authenticity and chain-of-custody. Additionally, request copies of the distributor's counterfeit prevention policy and the latest surveillance audit report summary as part of the qualification package. Pre-shipment documentation requirements should include certificates of conformance with OCM part number, lot/date code, and country of origin for every line item. For allocation-sensitive parts, verify single-source risk through manufacturer and distributor documentation, and treat alternate sourcing proposals as candidates requiring full traceability verification before acceptance.
References & Further Reading
- AS9120 Certification: Ensuring Quality in Component Distribution — Serendipity Electronics
- AS9120 Certification — Part Storage & Distribution QMS — Amtivo
- AS9120 Certification Explained for Distributors — AUVA Certification
- The Role of AS9120 in Supply Chain Traceability — Smithers
- AS9120 Certification: Requirements for Aviation, Space & Defence Distributors — J2 Sourcing AB
- AS9120 Certification: Aerospace Distributor Requirements — Wintersmith Advisory
- AS9120 Certification: Aerospace Distributor Quality — TUV USA
- IC-Online: Electronic Component Sourcing & BOM Management Platform
For procurement teams managing mixed BOMs across commercial and high-reliability programs, qualifying AS9120-certified distribution is a foundational risk-reduction step — but it works best when paired with a sourcing platform that streamlines RFQ workflows, supplier qualification tracking, and traceability documentation management. Whether you are qualifying a new distributor, validating an existing supplier's certification status, or sourcing allocation-constrained parts where traceability is non-negotiable, the ability to consolidate requirements into a structured RFQ process reduces cycle time and closes verification gaps.
Next step: Upload your BOM or submit an RFQ through IC-Online to connect with certified distribution partners. Specify your AS9120 requirements directly in the RFQ documentation fields — mixed BOM, flexible MOQ, and allocation-sensitive lines are all supported. Confirm current availability and traceability documentation through the platform's structured quotation workflow, and let certified suppliers respond with the documentation package your quality team needs to approve the source.







