9.8 Control Plan Development and Process Owner Handoff
Key Takeaways
- The Body of Knowledge defines the control plan's three jobs as maintaining improved performance, enabling continuous improvement, and transferring responsibility from the project team to the process owner.
- Control plan requirements became a standalone AIAG manual (CP-1, 1st edition) in March 2024, which added a fourth Safe Launch phase alongside prototype, pre-launch, and production, plus reaction-plan owner and change-level columns.
- Control plans are the third link in the core-tools chain: every significant failure mode in the PFMEA must map to a control-plan row, and every row should trace back to a failure mode.
- Control methods rank by robustness -- design elimination, preventing poka-yoke, automated detection, SPC with a reaction plan, sampling, 100% inspection, and procedure or training last; 'retrain the operators' is the weakest control and a standard exam distractor.
- Handover is evidenced, not announced: published standard work, verified training, capability sustained over roughly 30 days (Cpk >= 1.33 existing, >= 1.67 critical), controls executed by operators, and a signed agreement, followed by finance-validated audits at 30, 60, 90, and 365 days.
Improving a process creates value only if the improvement survives the team's departure. The Body of Knowledge states the task precisely (VIII.C.2): develop a control plan that maintains the improved performance, enables continuous improvement, and transfers responsibility from the project team to the process owner. All three clauses are examinable, and the third is the one projects fail.
What a control plan is, and the current standard
A control plan is a living document describing the systems and controls used to manage the process inputs ($X$'s) and outputs ($Y$'s) that determine the customer CTQs. It is a specification for how the process will be run and monitored, not a record of how it was improved.
The automotive sector supplies the reference format. Control plan requirements previously lived inside the AIAG APQP and Control Plan manual; since March 2024 the control plan is a standalone AIAG manual (CP-1, 1st edition), which added a fourth phase and extra data fields. The four phases:
| Phase | Applies to | Control intensity |
|---|---|---|
| Prototype | Dimensional, material, and performance evaluation on early builds | Highest; near-total measurement |
| Pre-launch | Pilot and trial production before full release | Elevated inspection frequency, extra containment |
| Safe launch | Early production immediately after launch (added in CP-1) | Temporary additional checks until stability is demonstrated |
| Production | Ongoing commercial operation | Steady-state sampling, SPC, and reaction plans |
Six Sigma teams outside automotive use the same structure, usually with pre-launch controls during the pilot and production controls at handover.
The core-tools chain
A control plan is never authored from a blank page. It is the third document in a chain, and each row of it should be traceable backwards:
Process flow diagram → PFMEA → control plan
The process flow names every step. The PFMEA (section 7.11) names the failure modes at each step and scores their risk. The control plan specifies the control for each significant failure mode the PFMEA identified. The audit test is a two-way one: every high-RPN or special-characteristic failure mode in the PFMEA must have a corresponding control-plan row, and every control-plan row should trace to a failure mode. A control with no failure mode behind it is usually inherited inspection nobody has questioned in years; a failure mode with no control is an uncontrolled risk that the improved process will eventually surface.
Anatomy of a control plan row
| Column | Purpose | Example |
|---|---|---|
| Process step / operation | Step number and name from the process map | Op 40: CNC shaft turning |
| Machine, jig, tooling | Equipment and fixture identity | CNC lathe #4 (asset EQ-402) |
| Product characteristic | The output ($Y$) being protected | Shaft outer diameter |
| Process characteristic | The input ($X$) that drives it | Spindle speed, feed rate, coolant temperature |
| Special characteristic | Safety or critical classification, if any | SC (significant characteristic) |
| Specification / tolerance | Nominal and limits | $25.000 \pm 0.025$ mm |
| Evaluation method | Gauge or inspection procedure, with its MSA status | Digital micrometer GM-12, GRR 8.4% |
| Sample size and frequency | Rational subgroup and interval | $n = 5$ every 2 hours |
| Control method | How the characteristic is actually controlled | $\bar{X}$ and $R$ chart |
| Reaction plan | What to do when the control signals | OCAP-04 |
| Owner | Named role accountable for the reaction (added in CP-1) | Cell team leader |
| Change level / revision | Version control for the row | Rev C, 2026-07-14 |
Choosing the control method: the robustness hierarchy
Selecting the control method is the judgment the exam tests. The options are not equivalent, and they rank in a fixed order of robustness:
| Rank | Control | Why it ranks here |
|---|---|---|
| 1 | Eliminate the failure mode by design | No failure mode, no control needed, no ongoing cost |
| 2 | Poka-yoke that prevents or shuts down | Error becomes physically impossible; independent of attention |
| 3 | Automated detection with alarm or lock-out | Catches the error immediately, but relies on a response |
| 4 | SPC chart with a reaction plan | Detects drift before nonconformance, but requires discipline |
| 5 | Sampling inspection | Detects after the fact; misses what falls between samples |
| 6 | 100% human inspection | Roughly 80% effective at best, fatiguing, expensive |
| 7 | Procedure and training alone | Depends entirely on memory and attention; weakest of all |
Two rules follow. Always select the highest feasible level, and treat any control plan whose rows are mostly at ranks 6 and 7 as a sustainment failure already in progress. And note the exam trap: "retrain the operators" is the most frequently proposed and least robust control there is. Training is a prerequisite for every level, never a control by itself.
Error-proofing levels
Within rank 2 and 3, poka-yoke (Shigeo Shingo) appears in three forms: prevention devices that make the error physically impossible, such as asymmetric connectors that cannot be inserted reversed; shutdown devices that stop the machine on detection, such as light curtains; and warning devices that signal with a beacon or buzzer and require acknowledgment. The lean tooling behind these is developed in section 8.8; here the question is only which of them earns a row in the plan.
Reaction plans and the OCAP
The reaction-plan column is where control plans are thinnest. "Notify supervisor" is not a reaction plan. A usable out-of-control action plan (OCAP) is a short decision tree answering six questions:
- Trigger -- exactly which signal starts it (a point beyond a control limit, seven-point run, gauge alarm)?
- Containment -- what stops immediately, and what is quarantined?
- Suspect material -- which units are suspect, back to which last known-good check, and who dispositions them?
- Diagnosis -- the ordered checks to perform, and by whom.
- Escalation -- who is called if the first checks do not resolve it, and within what time.
- Record -- where the event, cause, and action are logged so the data feeds continuous improvement.
Point 3 is the one that saves the recall: without a defined lookback, nobody knows which product is affected. Point 6 is how the plan satisfies the BoK's "enables continuous improvement" clause -- the log of control-plan reactions is the input to the next improvement cycle.
Transactional and service processes
The columns translate directly; only the vocabulary changes.
| Manufacturing | Transactional equivalent |
|---|---|
| Operation and machine | Process step and system or queue |
| Product characteristic | Output attribute: accuracy, completeness, cycle time |
| Process characteristic | Input attribute: field completeness, queue depth, staffing |
| Gauge and MSA | Audit checklist with attribute agreement analysis |
| Sample size and frequency | Daily audit of $n$ transactions |
| Control chart | $p$ chart on error rate, individuals chart on cycle time |
| Poka-yoke | Mandatory fields, validation rules, workflow lock-outs |
Equipment, measurement, and maintenance entries
Three sustainment mechanisms belong in the plan as rows rather than as separate initiatives. Maintenance tasks that protect a controlled characteristic -- the autonomous and planned maintenance routines of TPM (section 9.6) -- are written in with their own frequency and owner, because equipment deterioration reintroduces variation invisibly. Where equipment availability itself drives the CTQ, an OEE target (section 8.10) is entered as a monitored measure. And every gauge named in the evaluation column carries a calibration interval and an MSA re-analysis trigger (section 9.7), since a measurement system adequate for the old process may be inadequate for the improved one.
Revision and document control
A control plan is living, which means it has revision triggers rather than a review calendar alone: an engineering or specification change, a new failure mode discovered in production, a capability shift, a gauge or measurement-system change, equipment relocation or replacement, and any customer complaint traced to an uncontrolled characteristic. Each revision is versioned, re-approved, and re-issued to the floor; an obsolete copy at the workstation is a finding in any audit.
Handover to the process owner
Transfer of responsibility is a gate, not an email. The process owner should receive a defined package: the approved control plan and OCAPs, updated SOPs and work instructions, training records for every affected operator and shift, evidence of sustained capability, the monitoring plan with named leading and lagging indicators, and the benefit-tracking basis agreed with finance.
Readiness is demonstrated, not asserted:
- Standard work published -- SOPs, work instructions, and visual management updated to the new method.
- Training completed -- all shifts trained and competency verified, not merely briefed.
- Capability sustained -- typically $C_{pk} \ge 1.33$ for an existing characteristic and $\ge 1.67$ for a new or critical one, demonstrated over a monitoring period of about 30 days rather than a single study.
- Controls executing -- charts being plotted and reactions logged by the operators, not the project team.
- Formal sign-off -- a handover agreement signed by Black Belt, process owner, sponsor, and where applicable the Master Black Belt.
After sign-off the team audits rather than operates: finance-validated savings checks at 30, 60, 90, and 365 days against the charter baseline, hard and soft benefits reported separately, then documentation archived and lessons circulated (section 9.9). A project closed without the sign-off and the first audit is closed on paper only.
An automated assembly cell operates during an 8-hour planned shift (480 minutes) with 30 minutes of planned downtime for lunch and maintenance. Unplanned equipment breakdowns total 45 minutes. During the operating time, the machine produces 3,600 total parts against an ideal rate of 10 parts per minute (600 parts/hour). Out of 3,600 parts produced, 72 parts are rejected as defective. What is the Overall Equipment Effectiveness (OEE) of this cell?
In a formal Control Plan, what key requirement must be specified in the 'Reaction Plan' column?
What critical action must be completed by the Black Belt and Process Owner before a Six Sigma DMAIC project can be officially closed?