Most semiconductor manufacturers running both ISO 9001 and ITAR compliance programs treat them as entirely separate workstreams. Separate documentation, separate internal audits, separate evidence packages, separate prep timelines. The result is twice the work, twice the stress, and — ironically — higher risk, because siloed compliance programs tend to develop gaps where the two frameworks intersect.
The good news: ISO 9001 and ITAR share significant structural overlap. A compliance manager who maps that overlap can build a unified evidence package that satisfies both programs simultaneously — and walk into either audit with one organized binder instead of two.
Where ISO 9001 and ITAR Overlap
The overlap is more substantial than most compliance teams realize.
Document control is the most obvious example. ISO 9001 Clause 7.5 requires documented information to be controlled, version-managed, and accessible to authorized personnel. ITAR requires controlled technical data to be restricted to authorized users and maintained for five years. A single document management system with proper access controls and version history satisfies both requirements — if it’s set up correctly.
Supplier management is another major overlap. ISO 9001 Clause 8.4 requires evaluation and monitoring of external providers. ITAR requires screening suppliers against denied party lists and ensuring that controlled technology shared with suppliers is covered by appropriate authorizations. A unified supplier qualification and monitoring process can address both simultaneously.
Training and competency records are required by both frameworks — ISO 9001 Clause 7.2 for general competency, ITAR for export control awareness. Combined training programs with unified completion records cut the administrative burden in half.
Internal audit programs under ISO 9001 Clause 9.2 and ITAR’s expectation of periodic self-assessments can be run as a single integrated audit if your internal audit team is trained on both frameworks.
Building a Unified Evidence Package
The practical goal is a single evidence package that an ISO registrar and a DDTC auditor could both review without modification. Here’s how to structure it:
Section 1: Organization and Governance
- Quality management system scope (ISO 9001)
- ITAR compliance program summary with named compliance officer
- Organizational chart showing QMS and export control reporting lines
Section 2: Document Control
- Document management system description with access control methodology
- Sample controlled documents showing version history and authorization records
- Technical data inventory with USML/ECCN classifications mapped to documents
Section 3: Supplier and Customer Records
- Supplier qualification records (ISO 9001 Clause 8.4)
- Denied party screening logs for all suppliers and customers
- Active export licenses with end-user and end-use documentation
Section 4: Training and Competency
- ISO 9001 competency matrix by role
- ITAR training completion records by employee
- Combined new hire onboarding checklist showing both requirements
Section 5: Internal Audit Records
- Last three years of internal audit reports (ISO 9001 and ITAR)
- Corrective action records with closure evidence
- Management review minutes addressing both QMS and export control performance
Section 6: Nonconformance and Incident Records
- ISO 9001 nonconformance log with root cause and corrective action
- ITAR incident log including any voluntary disclosures filed with DDTC
- Evidence of systematic process improvement in response to findings
The Gaps That Auditors Find at the Intersection
Despite the overlap, there are specific areas where ISO 9001 and ITAR requirements diverge — and where auditors consistently find problems.
Foreign national access to controlled technical data is rarely addressed in ISO 9001 quality management systems, but is a primary ITAR concern. A QMS that doesn’t incorporate access controls based on citizenship status and visa classification is incomplete from an ITAR perspective — even if it satisfies ISO 9001 fully.
Export license conditions don’t map to any ISO 9001 requirement. License conditions — reporting deadlines, end-use restrictions, quantity limitations — need their own tracking system that sits outside the QMS structure.
ITAR recordkeeping periods (five years) differ from ISO 9001 retention requirements, which are determined by the organization. If your document retention policy was set by your QMS team without ITAR input, you may be retaining export records for an insufficient period.
Voluntary disclosure obligations under ITAR have no ISO 9001 equivalent. Your nonconformance process needs a branch specifically for potential ITAR violations that triggers an export counsel review — not just a corrective action.
Practical Steps to Align Your Programs
- Map your ISO 9001 procedures to ITAR requirements — identify which procedures partially or fully satisfy ITAR, and which ITAR requirements have no ISO 9001 coverage
- Assign dual ownership to shared processes — your QMS manager and your export compliance officer should both sign off on document control, supplier management, and training procedures
- Run a combined internal audit annually — train at least one internal auditor on both ISO 9001 and ITAR so a single audit cycle produces findings for both programs
- Unify your evidence repository — a single indexed folder structure accessible to both your registrar and your compliance officer eliminates the last-minute scramble of pulling records from two different systems
- Review annually after regulatory changes — both ISO 9001 (last revised 2015, with ongoing guidance updates) and ITAR (revised multiple times since 2020) change; your alignment map needs an annual refresh
The Bottom Line
Running ISO 9001 and ITAR as two separate compliance programs is expensive, error-prone, and unnecessary. The frameworks were designed for different purposes, but they share enough infrastructure that a well-designed compliance program can satisfy both with a single set of procedures, records, and audit cycles.
AUDITPROOF maps your process records and documentation against both ISO and ITAR requirements simultaneously — flagging gaps, identifying overlaps, and producing a unified evidence package your team can walk into any audit with.