Quality Escape Containment Across Logistics Guide

supplier-quality-escape-containment-software

Containment is a quality decision executed almost entirely by logistics. When a defect escapes, the requirement is not to stop production — it is to immediately contain all suspect material at the supplier, at the customer, in transit, and at the customer's customer. Two of those four locations are moving or already inside somebody else's site, and neither is visible from a quality system. That is the real problem with escape containment: identifying the affected lot takes hours, and physically arresting it across four locations takes days you do not have. Meanwhile the clock that matters has already started, because release from controlled shipping is decided by documentation rather than by how clean the parts have become. Book an architecture review to see how fast your records could scope an affected lot today.

Supplier Quality · Escape Containment

Quality Escape Containment Across Logistics

Scoping the affected lot in both directions, arresting stock in four places at once including the two you cannot see, and assembling the evidence that actually ends controlled shipping.

Escalation ladder EscapeDefect reaches the line CS1100% redundant inspection, your cost, your people CS2Accredited third party, still your cost Business at riskPlatform awards blocked, unannounced audits

Four Places, Two of Them Invisible

The containment requirement is explicit about scope. Where operations struggle is that each location has a different owner, a different mechanism and a different clock.

Swipe to see all columns
Location Who has to act What actually stops the stock Why it fails
At the supplier Your own plant and warehouse Hold status applied at lot level, quarantine bins, picking excluded Rarely — this is the location everyone contains first and best
In transit Logistics and the carrier Intercepting or diverting shipments already released, and flagging containers en route Nobody knows which despatches contained the affected lot without querying the shipment records
At the customer The customer's receiving and line-side stores Notification precise enough that they can find it — container references, not just a date range A vague scope forces them to quarantine far more than was affected, at your cost and their disruption
At the customer's customer Beyond your direct relationship entirely Escalation through your customer, with identifiers they can act on You have no visibility and no authority — only the quality of your identifiers travels that far
Notice what determines success in rows two through four. It is not containment capability — it is whether your records can name exactly which containers and shipments carried the affected lot. Precision in the identifiers is what makes remote containment possible; without it, containment becomes a request for somebody else to search their own site on your behalf.

Scoping Runs in Two Directions

Both are needed, and most operations can do one of them quickly.

Forward From a suspect input to everywhere it went Start with the material batch or process window under suspicion and establish which parts it produced, which shipments carried them, and where those shipments went. This is what defines the containment perimeter, and it has to be answerable in hours rather than days.
Backward From a returned part to what went into it Start with the failed unit and reconstruct its inputs — which material batch, which machine and station, what the process parameters were, and whether other parts from the same window behaved similarly. This is what finds the root cause and, critically, what tells you whether the initial perimeter was too narrow.
The failure mode is the same in both directions and it is described plainly in traceability guidance: without reliable records, either direction becomes a manual investigation across production logs, databases and spreadsheets. With them, you query the identifiers and the affected scope returns directly. The difference between those two experiences is measured in days, during which the affected material keeps moving.
“
Distinguish the cause of the defect from the cause of the escape. Both need irreversible actions.
This is the sentence most containment programmes are missing. Something produced a bad part — and something separately allowed it past inspection, through packing, onto a truck and into a customer's plant. Fixing the first without the second means the next defect escapes exactly the same way. Bring a recent escape to a 30-minute review and we'll work through both root causes with the records you actually hold.

What Quarantine Has to Do Mechanically

Applying a hold status is the easy part. These six behaviours are what make the hold real rather than advisory.

01Default to hold on receiptIncoming lots sit in quarantine pending inspection rather than being available and later restricted. The default position determines what happens on the days nobody is watching.
02Block directed putaway to released locationsHeld stock is steered to quarantine zones, so physical segregation follows the system status automatically instead of relying on someone reading a flag.
03Exclude held stock from pickingDirected picking skips quarantined material entirely. This is the control that actually prevents an escape becoming a second escape, because it operates without anyone making a decision.
04Refuse to print labels for held itemsIf a label cannot be produced, the material cannot be despatched. A simple and unusually effective backstop against a manual override further down the line.
05Let containers inherit the holdContainer-level identifiers should inherit quarantine status from their contents and synchronise on release, so a held part inside a released container is not a possibility that exists.
06Log every blocked attemptBlocked pick and ship attempts recorded as a metric. These are evidence the containment held under pressure — and a rising count tells you the hold is being tested by people who need the parts.

CS1 and CS2, and What Separates Them

Understanding the escalation matters because the cost profile changes completely at the second level.

Swipe to see all columns
Controlled Shipping Level 1 Controlled Shipping Level 2
Who inspects Your own employees, or a third party you choose — the decision usually driven by cost and staff availability An accredited third-party provider from the customer's approved vendor list, mandated rather than chosen
What it requires Containment plus redundant 100% inspection, root cause identified, irreversible corrective actions, then verification that they worked The same, executed and independently verified by the external agency inspecting every outgoing part
Who pays You You — with third-party inspection costs reported to run into hundreds of thousands per month on larger programmes
Typical trigger A confirmed defect reaching the line, a line-down or stop-ship traced to your part, repeat defects, or a PPM spike CS1 failing to demonstrably contain the problem, or an issue judged high-risk from the outset
Exit criteria Commonly 20 to 30 working days of data verifying that normal production controls are effective Comparable clean-day evidence, independently verified, with an audit typically scheduled
Two things about the escalation worth knowing before it happens. Notification protocol is deliberately formal — communicated live rather than by voicemail, then confirmed in writing setting out the process. And the trigger is described as a loss of customer confidence rather than a single event: you do not land in controlled shipping for one random miss with a strong system behind it.

Documentation Decides the Release

The most expensive misunderstanding in containment, stated as directly as the industry states it.

What suppliers assume That controlled shipping ends when the parts are clean. Twenty to thirty days of good product, and the restriction lifts on the evidence of the parts themselves.
What actually happens Weak paperwork keeps a supplier in controlled shipping even after the parts have gone clean. Release is granted on proof that the defect can no longer escape — which is a documentation artefact, not a production one. The clean days are necessary and not sufficient.
Charted inspection dataControl charts and Pareto analysis from the containment activity, not raw counts — the customer needs to see that the process is in control, not merely that defects were absent.
A completed 8D with two root causesVerified root cause for the defect and for the escape, each with irreversible corrective action. Error-proofing carries far more weight than added inspection, because inspection is what already failed.
Contemporaneous records, not reconstructed onesEvidence needs to be attributable, contemporaneous and complete. A record assembled after the fact to satisfy an auditor is visibly different from one captured as the work happened, and reviewers are practised at spotting the difference.
An agreed communication rhythmFrequency and format of reporting to the customer, agreed at the outset. Inconsistent reporting during containment is itself read as evidence that the process is not under control.
Launch-phase discipline where applicableWhere the part is still in launch, early-production containment needs to align with the controlled shipping evidence rather than running as a parallel exercise with its own paperwork.

The Signal That Means the Fix Did Not Hold

One pattern is described as the clearest available indicator, and it is worth watching for on your own suppliers as much as guarding against on your own site.

The pattern
The same defect returns after a verified 8D closureA formal corrective action is submitted, the customer accepts it, and the identical defect reappears in serial production within roughly thirty to sixty days.
What it means
The containment discipline cannot hold a fixWhatever the root cause analysis says on paper, a recurrence in that window indicates the corrective action was not irreversible — usually because it depended on people behaving consistently rather than on the process making the failure impossible.
The threshold
Eight weeks in CS2 is the lineA plant unable to exit second-level containment within roughly that window is described as having lost control of its quality system rather than having met a difficult defect. Beyond the direct inspection cost, it blocks future platform awards and invites further unannounced audits.
20–30 Working days of clean, charted, independently verifiable data commonly required to exit containment
Every one of those days needs evidence captured as it happened
Which is difficult if inspection results, containment actions and shipment records live in three systems and a shared drive. Fleet Rabbit holds inspection outcomes, hold status, corrective actions and the shipment history on one asset and lot record — so the exit package is assembled from what was recorded rather than reconstructed from memory in week four.

Preparing Before You Need It

Containment speed is decided by work done months earlier. Five things to establish while nothing is wrong.

1Time a mock scoping exercisePick a material batch at random and measure how long it takes to list every shipment that carried it and every location those shipments reached. That figure is your containment speed, and most operations have never measured it.
2Link lot identity to shipment identityThe single most valuable connection in containment. If lot records and despatch records cannot be joined, in-transit and customer-side containment become a request rather than an instruction.
3Test the hold controlsPlace a lot on hold and attempt to pick, label and ship it. If any of the three succeeds, your quarantine is advisory. Better to discover that on a Tuesday than during an escape.
4Agree the notification template in advanceWhat a containment notice to a customer contains — identifiers, quantities, shipment references, suspect window. Drafting it under pressure produces the vague scope that causes over-quarantine.
5Decide who owns escape root causeDefect root cause has an obvious owner in quality. Escape root cause spans inspection, packing and despatch, and is usually the analysis nobody is accountable for — which is why it keeps being skipped.

Frequently Asked Questions

Where does suspect material have to be contained?

In four places simultaneously: at the supplier, at the customer, in transit, and at the customer's customer. The first is straightforward because you control it. The remaining three depend entirely on how precisely you can identify which containers and shipments carried the affected lot — because remote containment is only as good as the identifiers you can give someone else to act on.

How do we scope the affected lot quickly?

In both directions. Forward traceability starts from a suspect input and establishes everywhere it went — which parts, which shipments, which destinations — and defines the containment perimeter. Backward traceability starts from the failed part and reconstructs its inputs, machine, station and process parameters, which finds root cause and reveals whether the initial perimeter was too narrow. Without reliable records, either becomes a manual investigation across logs and spreadsheets while the material keeps moving.

What is the difference between CS1 and CS2?

At level one you contain and run redundant 100% inspection using your own people or a third party you select, identify root cause, implement irreversible corrective actions and verify they worked. At level two an accredited third-party provider from the customer's approved list executes and verifies that containment, inspecting every outgoing part — mandated rather than chosen, and still at your expense, with costs reported to reach hundreds of thousands per month on larger programmes.

What actually gets us released?

Documentation, not clean parts alone. Weak paperwork can keep a supplier in controlled shipping even after production has gone clean, because release is granted on proof that the defect can no longer escape. Expect to need charted inspection data, a completed 8D with verified root cause and irreversible actions, and typically 20 to 30 working days of evidence that normal production controls are effective. Error-proofing carries more weight than added inspection, since inspection is what failed.

Why do we need two root causes?

Because something produced the defect and something separately allowed it to escape — past inspection, through packing, onto a truck. Guidance is explicit that both need distinguishing and both need irreversible actions. Fixing only the production cause leaves the escape route open, which is why the next defect reaches the customer the same way. Escape root cause spans inspection, packing and despatch, and is frequently the analysis nobody owns.

What makes a quarantine real rather than advisory?

Six mechanical behaviours: lots default to hold on receipt, directed putaway is blocked from released locations, picking excludes held stock automatically, label printing is refused for held items, containers inherit hold status from their contents and synchronise on release, and blocked pick or ship attempts are logged. Test it — place a lot on hold and try to pick, label and ship it. If any succeeds, the hold is a flag rather than a control.

What does a repeat defect indicate?

That the corrective action was not irreversible. The same defect reappearing in serial production within roughly thirty to sixty days of a verified 8D closure is described as the clearest available signal that containment discipline cannot hold a fix, whatever the analysis says on paper. Failure to exit second-level containment within about eight weeks is treated similarly — as loss of control of the quality system rather than a difficult defect. Start free with three assets and build the record before you need it.

Contain in Four Places, Prove It in Two Root Causes
Time a mock scoping exercise before an escape forces one, join lot identity to shipment identity so remote containment becomes an instruction rather than a request, test that your hold controls actually block picking and labelling, and analyse the escape route separately from the defect — because release is granted on documentation, and the paperwork you can produce in week four is the paperwork you captured in week one.
Controlled shipping levels, exit criteria and cost figures vary by manufacturer and programme, and the terminology differs between customers — work from the supplier quality manual and containment notice issued by each customer rather than from general descriptions.
September 10, 2026 By Sam Parker
All Articles

Share This Story, Choose Your Platform!

Latest Articles

Scroll