A supplier running a single plant with two press lines can govern acceptance sampling through one quality engineer and a spreadsheet. That same supplier opening a second site, adding a third product family, and doubling shipment volume discovers that the sampling system does not scale. Each new site interprets the ANSI/ASQ Z1.4 plan slightly differently. Each customer interface applies its own escalation triggers. The statistical logic holds; the organisational discipline collapses.

I have audited multi-site operations where the corporate quality manual specified Level II, AQL 2.5, yet each plant executed it with different lot definitions, different sampling frequencies, and different interpretations of what constituted a defect. The headquarters believed it had a standardised system. In reality, it had three isolated fiefdoms producing paperwork that looked identical and concealed completely different risk profiles. Volume exposed what single-site simplicity had hidden.

The scaling problem is not statistical. It is procedural. When a sampling plan is applied across multiple sites, product families, and customer specifications without a governed architecture, the plan degrades into a paperwork ritual. The customer receives lots from different plants with identical AQL stamps on the inspection reports, but the underlying defect risk varies by an order of magnitude depending on which site ran the job and how that site defined its lot boundary.

Lot Definition Fractures Under Mixed-Model Volume

ANSI/ASQ Z1.4 ties sample size to lot size. At a single site running one product, the lot definition is straightforward: one shift, one part number, one press. Under mixed-model production across multiple sites, the lot boundary becomes a negotiating position. I have seen plants define a lot as a full day's production across three machines to inflate the lot size and reduce the sampling rate per unit. Other plants define a lot as each individual machine cycle to minimise the sample entirely. Both are technically defensible; both produce wildly different consumer risk.

When volume grows and product mix diversifies, the lot definition must be governed centrally. A supplier shipping 50,000 units across three sites must specify whether the lot is defined per machine, per shift, per part number, or per shipment. Each definition produces a different OC curve. If the corporate quality function does not lock this definition, each site will optimise for inspection labour rather than statistical validity, and the customer will absorb the variance.

The customer never sees the lot definition. They see a shipment of 500 parts with a certificate stating AQL 2.5, Level II, sample size 32, accept on 2. What they do not know is whether those 32 parts were drawn from a homogenous lot of 500 or a composite sample across 2,000 parts spanning two shifts and three machines. The latter is statistically meaningless. It provides the customer with a probability statement that has no connection to the physical lot they received.

The Operating Characteristic Curve in Multi-Site Governance

The Operating Characteristic curve is the tool that makes sampling risk visible. In a multi-site operation, it becomes the governance instrument that aligns disparate plants to a common risk standard. If corporate quality mandates AQL 2.5 at Level II, the OC curve specifies exactly what every site is permitted to pass: lots at 2.5% defects accepted 95% of the time, lots at 5% defects accepted roughly 65% of the time, lots at 10% defects accepted approximately 20% of the time. These numbers are the same regardless of which plant runs the job.

The scaling failure occurs when each site selects its own sampling parameters. Plant A runs Level II; Plant B, under cost pressure, drops to Level I and halves its sample sizes. Plant C, serving a demanding aerospace customer, escalates to Level III without informing the others. The corporate quality manual says AQL 2.5. The actual consumer risk varies by site. When a customer receives lots from multiple plants, they are absorbing a composite risk profile that nobody has calculated.

The Operating Characteristic Curve in Multi-Site Governance — where the principle meets the process.
The Operating Characteristic Curve in Multi-Site Governance — where the principle meets the process.

The remedy is a centralised sampling register. Every sampling plan, at every site, for every product family, must be documented in a single matrix that includes the lot definition, the inspection level, the AQL, and the resulting OC curve parameters. When a customer or auditor asks what your sampling system delivers, you produce the register. If the register does not exist, your multi-site quality system is running on assumption.

OC Curve Risk at AQL 2.5, Level II, Sample Size 32

95%Lots at 2.5% defectsNear-certain passage of marginal product — the definition of AQL
~65%Lots at 5% defectsTwo thirds of significantly defective lots still ship to customer
~20%Lots at 10% defectsOne in five grossly nonconforming lots reaches assembly
1.67Cpk retirement targetProcess capability at which sampling should give way to periodic verification
The acceptance probabilities that every site in a multi-site network must understand and align to, regardless of which plant runs the job.

Switching Rules Across a Distributed Supplier Network

The switching rules in ANSI/ASQ Z1.4 and ISO 2859 are the only self-correcting mechanism in the standard. If two of five consecutive lots are rejected, the supplier must escalate to tightened inspection, which increases sample sizes and lowers acceptance numbers. If ten consecutive lots pass under normal inspection, reduced inspection is permitted. This dynamic feedback loop gives the plan its statistical integrity. Without it, the plan is a static lookup table with no memory.

In a multi-site operation, switching rules fail in a specific way. Plant A rejects two lots and escalates to tightened inspection. Plant B, running the same part number for the same customer, continues under normal inspection because its own lot sequence is clean. The corporate quality system has no visibility into the combined performance. The customer receives product from both plants under the same AQL stamp, but one plant is running under tightened rules and the other is not. Nobody has calculated the composite consumer risk.

The fix requires a centralised lot history that aggregates rejection data across all sites producing the same part number. When Plant A triggers tightened inspection, Plants B and C must also escalate if they are running the same process for the same customer. The switching rule must operate at the part-number level across the network, not at the individual line level within a single plant. This is the governance mechanism that most multi-site suppliers lack entirely.

During supplier audits, I have asked quality managers to show me their switching rule log. In twenty years, I can count on one hand the number who produced one. The answer is invariably that the plan says Level II, AQL 2.5, and that is what they have always done. When I ask what happens if two consecutive lots fail, the response is usually a promise to investigate. The standard requires escalation, not investigation. The absence of a governed switching rule log is a declaration that the supplier has no intention of self-correcting.

Customer Escalation When Volume Masks Degradation

At single-site volumes, a degrading process is visible quickly. The plant rejects three lots in a week, the quality manager walks the floor, and the problem is addressed. At multi-site volumes, the same degradation is invisible because the defect signal is distributed. Plant A sees one reject. Plant B sees one. Plant C sees one. No individual site triggers the switching rule, but the customer, receiving lots from all three plants, sees three defective shipments in a week and initiates a supplier concern notice.

This is the scaling trap. The sampling system was designed for a single inspection point with a single lot sequence. Distributed across multiple sites, the feedback loop breaks. Each site's sampling plan operates in isolation, and no one monitors the aggregate. The customer becomes the integration point—the most expensive place in the supply chain to discover that the sampling system failed to detect a degrading process.

A lot that passes acceptance sampling has not been verified as good — it has been not-rejected.

The remedy is a corporate-level rejection dashboard that aggregates lot results across all sites by part number and customer. If three sites each reject one lot in a five-lot window for the same customer, the system must trigger a network-wide escalation. The customer must never be the first party to identify a trend that the supplier's own sampling data already contained. If your quality system requires the customer to connect the dots across your sites, your governance is failing.

Transitioning the Network From Sampling to Capability

The correct trajectory for acceptance sampling is retirement. When a process demonstrates stable SPC charts with a Cpk above 1.67 across multiple sites, sampling should give way to periodic verification. The customer receives capability data instead of an AQL stamp. The supplier reduces inspection labour across the network. Both parties share a common statistical understanding of process performance. This is the end state that IATF 16949 and AS9100 are driving toward.

In a multi-site operation, the transition must be governed centrally. Plant A achieves Cpk 1.67 and discontinues sampling. Plant B, running the same process, hovers at Cpk 1.15 and continues under AQL 2.5. The customer receives product from both plants under the same part number. Without a centralised capability register, the customer cannot distinguish which shipments are backed by process control and which are backed by a probability gamble. The supplier must make that distinction visible.

The mechanism is a capability matrix maintained at the corporate level. Every part number, every site, every critical characteristic—indexed by current Cpk and the sampling plan under which it ships. When a customer audits the supplier, the matrix is the evidence that the quality system knows the difference between a controlled process and an inspected one. A supplier who cannot produce this matrix is telling the customer that all product is equal. It is not, and the customer will discover the difference on their own line.

Network-Level Sampling Retirement Sequence

  1. 01BaselineEvery site documents lot definition, inspection level, AQL, and OC curve in a centralised register
  2. 02Aggregate switchingLot rejection triggers escalation across all sites producing the same part number, not just the affected line
  3. 03Capability assessmentSPC charts and Cpk data collected network-wide for each critical characteristic
  4. 04Phased retirementSites achieving Cpk above 1.67 transition from sampling to periodic verification
  5. 05Customer evidenceCapability matrix replaces AQL stamps as the primary quality evidence at the customer interface
The governed path from acceptance sampling to process capability across a multi-site supplier network.

The Economic Reckoning at Scale

The cost argument for sampling looks different at scale. A single site inspecting 32 parts per lot instead of 500 saves labour and appears economically rational. Across five sites running 200 lots per week, those savings are substantial. But the cost of a defect reaching the customer also scales. A single defective lot from one site triggers a customer concern. A pattern of defective lots across multiple sites triggers a supplier escalation, a source inspection mandate, or a decision to dual-source.

Deming's kp rule applies directly: if the cost of inspecting one unit is less than the cost of a defect escaping to the customer, inspect 100%. At multi-site volumes, the cost of a defect escaping includes not only the customer's line downtime but the reputational damage of an escalated concern across the entire account. The supplier who saved inspection labour across five sites loses the entire contract over defects that the sampling plan was designed to let through.

The supplier who scales acceptance sampling without scaling governance is building a liability that grows with every new site, every new product family, and every new customer. The AQL stamp that worked at one plant becomes a statistical fiction across five. The customer who accepts it at first will eventually audit it, and the audit will reveal that the supplier cannot produce a switching rule log, cannot show an OC curve, and cannot name the capability threshold at which sampling will be retired. That is the moment the relationship changes.