9.8 Control Plan Development and Process Owner Handoff

Key Takeaways

  • The Body of Knowledge defines the control plan's three jobs as maintaining improved performance, enabling continuous improvement, and transferring responsibility from the project team to the process owner.
  • Control plan requirements became a standalone AIAG manual (CP-1, 1st edition) in March 2024, which added a fourth Safe Launch phase alongside prototype, pre-launch, and production, plus reaction-plan owner and change-level columns.
  • Control plans are the third link in the core-tools chain: every significant failure mode in the PFMEA must map to a control-plan row, and every row should trace back to a failure mode.
  • Control methods rank by robustness -- design elimination, preventing poka-yoke, automated detection, SPC with a reaction plan, sampling, 100% inspection, and procedure or training last; 'retrain the operators' is the weakest control and a standard exam distractor.
  • Handover is evidenced, not announced: published standard work, verified training, capability sustained over roughly 30 days (Cpk >= 1.33 existing, >= 1.67 critical), controls executed by operators, and a signed agreement, followed by finance-validated audits at 30, 60, 90, and 365 days.
Last updated: August 2026

Improving a process creates value only if the improvement survives the team's departure. The Body of Knowledge states the task precisely (VIII.C.2): develop a control plan that maintains the improved performance, enables continuous improvement, and transfers responsibility from the project team to the process owner. All three clauses are examinable, and the third is the one projects fail.


What a control plan is, and the current standard

A control plan is a living document describing the systems and controls used to manage the process inputs ($X$'s) and outputs ($Y$'s) that determine the customer CTQs. It is a specification for how the process will be run and monitored, not a record of how it was improved.

The automotive sector supplies the reference format. Control plan requirements previously lived inside the AIAG APQP and Control Plan manual; since March 2024 the control plan is a standalone AIAG manual (CP-1, 1st edition), which added a fourth phase and extra data fields. The four phases:

PhaseApplies toControl intensity
PrototypeDimensional, material, and performance evaluation on early buildsHighest; near-total measurement
Pre-launchPilot and trial production before full releaseElevated inspection frequency, extra containment
Safe launchEarly production immediately after launch (added in CP-1)Temporary additional checks until stability is demonstrated
ProductionOngoing commercial operationSteady-state sampling, SPC, and reaction plans

Six Sigma teams outside automotive use the same structure, usually with pre-launch controls during the pilot and production controls at handover.


The core-tools chain

A control plan is never authored from a blank page. It is the third document in a chain, and each row of it should be traceable backwards:

Process flow diagram → PFMEA → control plan

The process flow names every step. The PFMEA (section 7.11) names the failure modes at each step and scores their risk. The control plan specifies the control for each significant failure mode the PFMEA identified. The audit test is a two-way one: every high-RPN or special-characteristic failure mode in the PFMEA must have a corresponding control-plan row, and every control-plan row should trace to a failure mode. A control with no failure mode behind it is usually inherited inspection nobody has questioned in years; a failure mode with no control is an uncontrolled risk that the improved process will eventually surface.


Anatomy of a control plan row

ColumnPurposeExample
Process step / operationStep number and name from the process mapOp 40: CNC shaft turning
Machine, jig, toolingEquipment and fixture identityCNC lathe #4 (asset EQ-402)
Product characteristicThe output ($Y$) being protectedShaft outer diameter
Process characteristicThe input ($X$) that drives itSpindle speed, feed rate, coolant temperature
Special characteristicSafety or critical classification, if anySC (significant characteristic)
Specification / toleranceNominal and limits$25.000 \pm 0.025$ mm
Evaluation methodGauge or inspection procedure, with its MSA statusDigital micrometer GM-12, GRR 8.4%
Sample size and frequencyRational subgroup and interval$n = 5$ every 2 hours
Control methodHow the characteristic is actually controlled$\bar{X}$ and $R$ chart
Reaction planWhat to do when the control signalsOCAP-04
OwnerNamed role accountable for the reaction (added in CP-1)Cell team leader
Change level / revisionVersion control for the rowRev C, 2026-07-14

Choosing the control method: the robustness hierarchy

Selecting the control method is the judgment the exam tests. The options are not equivalent, and they rank in a fixed order of robustness:

RankControlWhy it ranks here
1Eliminate the failure mode by designNo failure mode, no control needed, no ongoing cost
2Poka-yoke that prevents or shuts downError becomes physically impossible; independent of attention
3Automated detection with alarm or lock-outCatches the error immediately, but relies on a response
4SPC chart with a reaction planDetects drift before nonconformance, but requires discipline
5Sampling inspectionDetects after the fact; misses what falls between samples
6100% human inspectionRoughly 80% effective at best, fatiguing, expensive
7Procedure and training aloneDepends entirely on memory and attention; weakest of all

Two rules follow. Always select the highest feasible level, and treat any control plan whose rows are mostly at ranks 6 and 7 as a sustainment failure already in progress. And note the exam trap: "retrain the operators" is the most frequently proposed and least robust control there is. Training is a prerequisite for every level, never a control by itself.

Error-proofing levels

Within rank 2 and 3, poka-yoke (Shigeo Shingo) appears in three forms: prevention devices that make the error physically impossible, such as asymmetric connectors that cannot be inserted reversed; shutdown devices that stop the machine on detection, such as light curtains; and warning devices that signal with a beacon or buzzer and require acknowledgment. The lean tooling behind these is developed in section 8.8; here the question is only which of them earns a row in the plan.


Reaction plans and the OCAP

The reaction-plan column is where control plans are thinnest. "Notify supervisor" is not a reaction plan. A usable out-of-control action plan (OCAP) is a short decision tree answering six questions:

  1. Trigger -- exactly which signal starts it (a point beyond a control limit, seven-point run, gauge alarm)?
  2. Containment -- what stops immediately, and what is quarantined?
  3. Suspect material -- which units are suspect, back to which last known-good check, and who dispositions them?
  4. Diagnosis -- the ordered checks to perform, and by whom.
  5. Escalation -- who is called if the first checks do not resolve it, and within what time.
  6. Record -- where the event, cause, and action are logged so the data feeds continuous improvement.

Point 3 is the one that saves the recall: without a defined lookback, nobody knows which product is affected. Point 6 is how the plan satisfies the BoK's "enables continuous improvement" clause -- the log of control-plan reactions is the input to the next improvement cycle.


Transactional and service processes

The columns translate directly; only the vocabulary changes.

ManufacturingTransactional equivalent
Operation and machineProcess step and system or queue
Product characteristicOutput attribute: accuracy, completeness, cycle time
Process characteristicInput attribute: field completeness, queue depth, staffing
Gauge and MSAAudit checklist with attribute agreement analysis
Sample size and frequencyDaily audit of $n$ transactions
Control chart$p$ chart on error rate, individuals chart on cycle time
Poka-yokeMandatory fields, validation rules, workflow lock-outs

Equipment, measurement, and maintenance entries

Three sustainment mechanisms belong in the plan as rows rather than as separate initiatives. Maintenance tasks that protect a controlled characteristic -- the autonomous and planned maintenance routines of TPM (section 9.6) -- are written in with their own frequency and owner, because equipment deterioration reintroduces variation invisibly. Where equipment availability itself drives the CTQ, an OEE target (section 8.10) is entered as a monitored measure. And every gauge named in the evaluation column carries a calibration interval and an MSA re-analysis trigger (section 9.7), since a measurement system adequate for the old process may be inadequate for the improved one.


Revision and document control

A control plan is living, which means it has revision triggers rather than a review calendar alone: an engineering or specification change, a new failure mode discovered in production, a capability shift, a gauge or measurement-system change, equipment relocation or replacement, and any customer complaint traced to an uncontrolled characteristic. Each revision is versioned, re-approved, and re-issued to the floor; an obsolete copy at the workstation is a finding in any audit.


Handover to the process owner

Transfer of responsibility is a gate, not an email. The process owner should receive a defined package: the approved control plan and OCAPs, updated SOPs and work instructions, training records for every affected operator and shift, evidence of sustained capability, the monitoring plan with named leading and lagging indicators, and the benefit-tracking basis agreed with finance.

Readiness is demonstrated, not asserted:

  1. Standard work published -- SOPs, work instructions, and visual management updated to the new method.
  2. Training completed -- all shifts trained and competency verified, not merely briefed.
  3. Capability sustained -- typically $C_{pk} \ge 1.33$ for an existing characteristic and $\ge 1.67$ for a new or critical one, demonstrated over a monitoring period of about 30 days rather than a single study.
  4. Controls executing -- charts being plotted and reactions logged by the operators, not the project team.
  5. Formal sign-off -- a handover agreement signed by Black Belt, process owner, sponsor, and where applicable the Master Black Belt.

After sign-off the team audits rather than operates: finance-validated savings checks at 30, 60, 90, and 365 days against the charter baseline, hard and soft benefits reported separately, then documentation archived and lessons circulated (section 9.9). A project closed without the sign-off and the first audit is closed on paper only.

Loading diagram...
DMAIC Control Phase Handover and Closure Workflow
Test Your Knowledge

An automated assembly cell operates during an 8-hour planned shift (480 minutes) with 30 minutes of planned downtime for lunch and maintenance. Unplanned equipment breakdowns total 45 minutes. During the operating time, the machine produces 3,600 total parts against an ideal rate of 10 parts per minute (600 parts/hour). Out of 3,600 parts produced, 72 parts are rejected as defective. What is the Overall Equipment Effectiveness (OEE) of this cell?

A
B
C
D
Test Your Knowledge

In a formal Control Plan, what key requirement must be specified in the 'Reaction Plan' column?

A
B
C
D
Test Your Knowledge

What critical action must be completed by the Black Belt and Process Owner before a Six Sigma DMAIC project can be officially closed?

A
B
C
D