Module 18 · Control

Control plans and sustaining gains

Every tool in Modules 13 through 17 exists to produce a change: a redesigned process, a new fixture, a control chart proving a fix worked. None of that survives contact with a production floor for long without two unglamorous documents: a control plan that says exactly what gets checked, how, how often, and by whom, and a reaction plan that says exactly what to do when a check signals a problem. This module covers both, how they hand a stabilized process off to production, and how to tell a real capability shift from ordinary month-to-month noise once that handoff is months in the past.

Learning objectives

Why this matters

No public, data-backed case of a specific control-plan failure was found for this course; the scenario below is a constructed illustration, not a real event.

A DMAIC team fixes a real problem, runs the improvement, proves the gain with a hypothesis test and a control chart (Module 14), and celebrates. Eight months later, someone asks whether the fix is still in effect, and the honest answer is nobody knows: the chart the team built during the project was never handed to production, the operators who ran the pilot have moved to other lines, and the people running the process today were never told why a particular fixture setting matters. The reject rate has quietly drifted back most of the way to where it started, one small undocumented "fix" of a "fix" at a time. Nothing in this story required negligence. It only required a project to end without leaving behind a document that survives staff turnover, shift changes, and time — which is exactly what a control plan and a reaction plan are for. AIAG's standalone Control Plan manual exists as its own document, separate from APQP, specifically because this handoff step is substantial enough to deserve one.[1]

Control plans

A control plan is a structured table, one row per characteristic, documenting how a process keeps that characteristic in check on an ongoing basis: the characteristic itself, its specification, the measurement method and gauge, the sample size and frequency, the control method (a chart, a check, a poka-yoke), and the reaction plan if it signals. AIAG's Control Plan manual (1st edition, March 2024, now standalone rather than a chapter of APQP) documents the current structure, its linkage back to APQP's process flow and PFMEA, and a "Safe Launch" phase of heightened monitoring immediately after a new or changed process starts production, before settling into the ongoing control plan.[1][2] A control plan without a PFMEA behind it (Module 10) is just a list of measurements someone thought to write down; the PFMEA is what justifies which characteristics made the list and why.

Standardization and documentation

Module 14's standard work (takt time, work sequence, standard in-process stock) is what a control plan assumes is already in place: a control chart's control limits describe a process running one documented way, and if the work sequence itself varies operator to operator, the chart is measuring method variation as if it were process noise. Work instructions, visual standards, and the control plan itself all need to say the same thing, updated together whenever the process changes — a control plan that documents a setting the work instruction no longer specifies is worse than no documentation, because it looks authoritative while being wrong.

Handoff to production

A project team's job is not finished when the data prove the fix works; it is finished when someone outside the project team can run, monitor, and react to the process correctly without the team in the room. That means training the people who will actually own the process day to day, not just the shift that happened to be running during the pilot; a sign-off that names who now owns the control plan and who owns escalation when it signals; and a real handoff meeting, not just an emailed document, because the reaction plan's value depends entirely on whether the person watching the chart at 2 a.m. actually knows what it says.

Linking to PPAP and IATF 16949

A control plan is one of PPAP's required submission elements, expected to be consistent with the process flow diagram and PFMEA submitted alongside it.[3] IATF 16949 clause 9.1.1.1, on monitoring and measurement of manufacturing processes, requires process studies for new manufacturing processes (including new or changed characteristics affecting fit, function, durability, or regulatory requirements) to verify process capability, requires a reaction plan when a process is not statistically stable or not capable, and requires significant process events to be recorded in the control plan.[4][5] None of this is optional paperwork layered on top of good practice; it is the same practice, written down in a form an auditor (and, more usefully, the next engineer who inherits the process) can actually check.

Reaction plans

A reaction plan answers one specific question: what does the person watching the chart actually do when it signals? A good reaction plan names the trigger (a specific Western Electric or Nelson rule, Module 16), the immediate containment action, who investigates, and the escalation path if the cause is not found within a stated time. What a reaction plan must never say, however phrased, is "adjust the process toward nominal." Module 2's funnel experiment already demonstrated, in a fully controlled simulation, that adjusting a stable process in response to its own ordinary noise (Rules 2, 3, and 4) increases variation rather than reducing it. A control chart's entire purpose is to tell the difference between a point that is ordinary noise (within control limits, no rule triggered: do nothing) and a point that is a real signal (a rule triggered: investigate and find the assignable cause, then decide whether action is needed). An operator who "corrects" every reading that drifts slightly toward a spec limit, chart or no chart, is running the funnel experiment's Rule 2 on a real process, by hand, indefinitely.

Ongoing capability monitoring: control limits vs. specification limits, a third time

This course has now made the point that control limits and specification limits are never the same thing, and never belong on the same chart, twice: once when capability indices were introduced (Module 7), once when control charts were built by hand (Module 16). The third angle, here, is what that distinction means over months, not within a single chart. A monthly (or quarterly) capability check produces one Ppk estimate per period, and that estimate has its own sampling uncertainty — the 95 % confidence interval this course has carried on Ppk since Module 7. Two months' point estimates can differ noticeably while their confidence intervals overlap heavily, in which case the honest conclusion is that nothing has necessarily changed; reacting to that difference as if it were a real trend is the same overreaction the funnel experiment warns against, just measured monthly instead of point to point. A real shift is one where the new period's confidence interval no longer overlaps the established band at all. Worked example 3 below shows both patterns on the computed intervals.

A note on the letters, because a monitoring report has to pick one. This module reports Pp and Ppk throughout. Under the current AIAG & VDA convention, the Cp and Cpk labels are reserved for a process that has been demonstrated statistically stable over the period being reported, and Pp and Ppk are used otherwise; one month's snapshot of 30 readings is a performance estimate, not a demonstration of stability across that month.[6] Legacy supplier reports and much software still print the 2005 labels instead, where Cpk is computed from the within-subgroup sigma and Ppk from the overall sample standard deviation (Module 7).[7] Whichever convention your organization uses, state it beside the number, and state which sigma estimate produced it.

Project closure and reporting

A DMAIC project closes with a short, specific report, not a retrospective essay: the problem statement and charter (Module 3) restated against what was actually achieved; the verified before-and-after result with its hypothesis test (Module 14); the control plan and reaction plan, handed to the named process owner; and a stated date (typically 3 to 6 months out) for a follow-up capability check, using exactly the confidence-interval comparison this module teaches, to confirm the gain actually held rather than assuming it did because nobody complained.

Worked examples

Worked example 1: a control plan row for the bore diameter

The data below reuses Module 7's bore-diameter example and Module 4's gauge R&R example directly, rather than inventing new numbers for this module's purpose.

The reamed bore Ø12.000 ± 0.025 mm this course has followed since Module 7 (stable, Ppk = 1.040 on that module's 125 readings, mean 12.0039 mm) gives a complete, traceable example for a control plan row.

Table 1. Control plan row, bore diameter (constructed control plan, reusing verified capability and MSA data).
FieldEntry
CharacteristicBore diameter (reamed)
SpecificationØ12.000 ± 0.025 mm
Measurement methodBore micrometer, resolution 0.001 mm
Measurement system status%GRR (%Tolerance) = 29.8 % (AIAG "conditional" band, 10–30 %), ndc = 5 (meets the guideline minimum) — acceptable for now, flagged for gauge improvement before the next PPAP cycle
Sample size / frequency5 consecutive parts every 30 minutes
Control methodX̄-R chart, limits from the data (Module 16), never the 0.025 mm spec
Reaction planSee Worked example 2

Every number in this row is either a specification already fixed at design time or a measured result already computed and verified elsewhere in this course (Modules 4 and 7); a control plan does not introduce new statistics, it collects and documents ones that already exist.

Worked example 2: the reaction plan for that row, and the failure mode it prevents

Constructed example, illustrating the principle stated above.

Table 2. Reaction plan, bore diameter X̄-R chart (constructed).
TriggerImmediate actionInvestigateEscalate if unresolved in
Western Electric Rule 1 (point beyond 3σ)Hold the last 30 minutes of parts, do not adjust the processOperator checks tooling wear, fixture seating, recent changeovers2 hours, to shift lead
Nelson Rule 2 (9 in a row on one side of centre)Continue running, increase sampling frequency to every 15 minutesProcess engineer checks for a shift (tool change, material lot, ambient temperature)1 shift, to process engineer
Any point outside spec (11.975–12.025 mm)Hold the part, quarantine the subgroupFull investigation regardless of chart status; a spec violation is a containment issue even if the chart has not yet signalledImmediate, to quality

The middle column of every row is an investigation, never an adjustment. Consider the operator who instead nudges the fixture half a turn every time a reading drifts toward 12.010 mm, chart or no chart, reasoning that "it's getting close." If the process is actually stable at its current centring, this is Deming's funnel experiment's Rule 2, run by hand: treating ordinary noise as a signal and reacting to it adds variation that was not there before, and after enough shifts of this, the chart shows a process with real variation and nobody can say why, because the true cause was the well-intentioned nudging itself. A reaction plan that says "investigate the assignable cause" instead of "adjust toward nominal" is the entire defense against this failure mode.

Worked example 3: five months of ongoing capability, real shift vs. noise

The data below is a constructed example, not a real production history. Setting: the same bore feature as Worked example 1, 6 subgroups of 5 sampled once per month for five months.

Table 3. Monthly Ppk with its 95 % confidence interval, five months (constructed data).
MonthMean (mm)s (mm)Ppk95 % CI on Ppk
112.00330.007031.029(0.739, 1.320)
212.00290.007101.037(0.745, 1.330)
312.00100.007431.077(0.775, 1.379)
412.00360.005761.237(0.897, 1.577)
512.01240.008130.517(0.338, 0.695)

Months 1 through 4 wander from 1.029 to 1.237, and it would be easy to read that as a trend (steadily improving, even) if only the point estimates are looked at. Their confidence intervals tell a different story: every one of the four overlaps every other one heavily (month 4's interval alone spans 0.897 to 1.577, comfortably covering all three earlier point estimates). Nothing in months 1 through 4 is distinguishable from a single stable process sampled four times with ordinary noise, and the right reaction to that variation is exactly none. Month 5 is a different case entirely: Ppk drops to 0.517, and its interval, 0.338 to 0.695, does not overlap month 4's lower bound of 0.897 at all — nor, for that matter, any of the four earlier months' lower bounds, all of which sit at 0.739 or above. That is a real, statistically distinguishable shift (here, both the mean moved further from target and the spread widened, consistent with a tool-wear story), and it is precisely the pattern that should trigger the reaction plan in Worked example 2, not a quiet note in a monthly report.

Show the five months of bore-diameter readings (6 subgroups of 5 per month, 150 readings)
Table A1. Month 1: bore diameter (mm), six subgroups of five (constructed data).
Subgroup12345
111.99711.98912.00712.00812.001
212.00512.01412.0112.00812.007
311.99712.00911.99112.012.0
411.99112.00212.01412.011.994
512.00212.00912.00412.00311.993
612.00612.00612.01212.01312.007
Table A2. Month 2: bore diameter (mm), six subgroups of five (constructed data).
Subgroup12345
112.01711.99911.98911.99812.015
212.00512.00212.00512.00612.01
312.00412.01212.012.00312.0
412.00412.01711.99211.99311.999
512.01112.00511.99812.00411.994
611.99511.99812.00712.00112.004
Table A3. Month 3: bore diameter (mm), six subgroups of five (constructed data).
Subgroup12345
112.00511.99211.9911.99612.002
211.99112.00612.012.00211.997
312.012.00111.97912.00812.003
411.99912.01412.00512.00911.998
512.00812.00311.99912.00612.002
611.98912.00212.00312.01112.01
Table A4. Month 4: bore diameter (mm), six subgroups of five (constructed data).
Subgroup12345
111.99712.00312.00911.99612.0
211.99212.00812.01112.00612.003
312.01412.00511.99912.00411.999
412.00512.00311.99312.00711.992
512.00212.00512.01512.00312.008
612.00512.00612.00612.00512.008
Table A5. Month 5: bore diameter (mm), six subgroups of five (constructed data).
Subgroup12345
112.01512.00912.0111.99312.027
212.02212.0112.01912.01512.009
312.02112.01112.0112.00712.017
412.01212.01712.00812.01412.006
512.0212.01512.01612.01612.005
612.01912.02912.011.99912.001

Common mistakes

Exercises

Exercise 1: a control plan row for the leak test

Constructed example, reusing Module 3's charter data.

The charter baseline (Module 3) is a 100 % helium leak test at final inspection on brazed heat-exchanger cores, 42 rejects per 1000 units tested (an attribute characteristic, not a measured dimension).

Tasks. Using the same seven fields as Table 1, draft a control plan row for the leak test. In particular: (a) what control method fits an attribute (pass/fail) characteristic like this one, rather than the X̄-R chart Table 1 used? (b) What would the reaction plan's first trigger reasonably be?

Show one reasonable answer

(a) A p chart (Module 17), not an X̄-R chart — the leak test result is pass/fail per core, not a measured continuous value, and a p chart tracks the proportion rejected per lot the same way Module 14's pilot p charts did.

(b) A reasonable first trigger is a point beyond the p chart's own control limits (computed from the data, never from a target reject rate) — for example, a lot with a reject rate clearly above the established average, the same signal Module 14's Worked example 3 discussion of a floored lower limit shows is not always available in the other direction. A complete row would also specify: measurement method (100 % helium leak test), sample size/frequency (every core, every lot), and a reaction plan entry for "any single confirmed leak escape past the test" as an immediate, chart-independent containment trigger, the same way Table 2's "any point outside spec" row worked for a chart-based characteristic.

Exercise 2: real shift or noise?

The data below is a constructed example, not a real production history. Setting: wall thickness (mm) of an injection-moulded housing, target 2.50 ± 0.15 mm, 25 individual readings per month.

Table 4. Monthly Ppk with its 95 % confidence interval, three months (constructed data).
MonthMean (mm)s (mm)Ppk95 % CI on Ppk
A2.50080.039271.266(0.885, 1.648)
B2.49180.045681.034(0.714, 1.355)
C2.54210.079830.450(0.268, 0.633)

Tasks. (a) Do months A and B's confidence intervals overlap? What does that mean for whether anything changed between them? (b) Does month C's interval overlap month B's? (c) Should month C trigger the reaction plan?

Show the worked solution

(a) Yes: A's interval (0.885 to 1.648) and B's (0.714 to 1.355) overlap substantially. Nothing here is distinguishable from ordinary month-to-month sampling noise on a single stable process; A's higher point estimate (1.266 vs. 1.034) is not evidence of a real difference.

(b) No: month C's interval (0.268 to 0.633) sits entirely below month B's lower bound of 0.714, with no overlap at all.

(c) Yes. Both the mean (2.4918 mm → 2.5421 mm) and the spread (s: 0.04568 mm → 0.07983 mm) moved between B and C, and the non-overlapping confidence intervals confirm this is a real, statistically distinguishable shift, not noise — exactly the pattern that should trigger an investigation under the reaction plan, the same reasoning Worked example 3 applied to month 5.

Show the three months of wall-thickness readings for Exercise 2
Table A6. Month A: injection-moulded wall thickness (mm), 25 parts (constructed data).
Part12345678910
1–102.5032.562.5552.482.4892.4792.5262.52.5342.423
11–202.5692.4982.5312.4962.4862.5222.5372.4932.4952.531
21–252.4652.4372.5192.4732.419
Table A7. Month B: injection-moulded wall thickness (mm), 25 parts (constructed data).
Part12345678910
1–102.5292.462.4852.5262.5842.4372.4472.5142.4432.443
11–202.5352.5042.4632.5082.4842.4672.3952.532.4652.488
21–252.442.5212.542.5682.518
Table A8. Month C: injection-moulded wall thickness (mm), 25 parts (constructed data).
Part12345678910
1–102.5312.4562.4952.6722.5012.4982.5232.4932.5152.449
11–202.5752.6022.4762.5772.6142.3962.492.5422.582.62
21–252.6832.7032.6112.432.521

Quiz

Ten questions. Score 70 % or more to mark the module complete on this device.

1. A control plan row is built primarily from
2. A reaction plan's middle step (after the trigger and immediate action) should always be
3. An operator who nudges a fixture setting every time a stable process's reading drifts slightly toward a spec limit is, in effect,
4. IATF 16949 clause 9.1.1.1 requires, among other things,
5. In Worked example 3, months 1 through 4's Ppk point estimates ranged from 1.029 to 1.237. The right conclusion, given their confidence intervals, is
6. In Worked example 3, month 5's Ppk confidence interval (0.338 to 0.695) compared with month 4's (0.897 to 1.577) shows
7. This module's treatment of "control limits are not specification limits" is described in this course as
8. A control plan is linked to PPAP because
9. Closing a DMAIC project without scheduling a follow-up capability check mainly risks
10. In Exercise 2, months A and B's overlapping confidence intervals, followed by month C's non-overlapping one, illustrate that
Answer key
  1. b. Built from the PFMEA's identified risks.
  2. c. Investigate a specific assignable cause.
  3. d. Running the funnel experiment's Rule 2 by hand.
  4. a. A reaction plan when unstable/not capable, and recording significant events.
  5. b. Heavily overlapping intervals mean no distinguishable change.
  6. c. No overlap: a real, statistically distinguishable shift.
  7. a. The third of three times, applied across months.
  8. d. One of PPAP's required, consistent submission elements.
  9. b. A real gain can erode unnoticed without a scheduled follow-up.
  10. c. The same logic applies regardless of the specific characteristic.

Key takeaways

References

All web sources accessed 2026-09-09 or 2026-09-10 (Phase A) unless noted.

  1. AIAG. Control Plan, 1st ed., March 2024. https://www.aiag.org/training-and-resources/manuals/details/CP-1 (catalogue-level: existence and edition; the standalone structure, APQP linkage, and "Safe Launch" phase confirmed at this depth)
  2. AIAG. Advanced Product Quality Planning (APQP), 3rd ed., March 2024. https://www.aiag.org/training-and-resources/manuals (catalogue-level: existence and edition; control plan now a separate manual)
  3. AIAG. Production Part Approval Process (PPAP), 4th ed., 2006 (Nov 2009 printing). https://www.aiag.org/training-and-resources/manuals/details/PPAP-4 (catalogue-level: existence and edition; the control plan as a required submission element)
  4. Biswas, P. "IATF 16949:2016 Clause 9.1.1.1 Monitoring and measurement of manufacturing processes." 6 Aug 2023. https://preteshbiswas.com/2023/08/06/iatf-169492016-clause-9-1-1-1-monitoring-and-measurement-of-manufacturing-processes/ (verified, full: commentary on clause 9.1.1.1's requirements, cited as a commentary with the standard itself as the primary reference, see [5])
  5. IATF 16949:2016. Quality management system requirements for automotive production and relevant service parts organizations. IATF. Clause 9.1.1.1, summarized via [4]. (secondary: standard not read directly, not available online; requirement for process studies, capability verification, reaction plans when unstable or not capable, recording significant process events)
  6. DQS. "New AIAG & VDA SPC Manual 1st Edition released." 2026. https://www.dqsglobal.com/en/explore/blog/release-of-aiag-vda-spc-manual-1st-edition (verified, full: Cp/Cpk only for statistically stable processes, Pp/Ppk otherwise, the convention this module's ongoing Ppk tracking follows)
  7. AIAG. Statistical Process Control (SPC) Reference Manual, 2nd ed., 2005 (superseded by the AIAG & VDA SPC Manual, 1st ed., 2026). (secondary: the legacy convention many supplier reports and software still print; see [6] for the current standard)