I've been the person who walks into a plant three weeks after a bad launch, gets handed a stack of customer escalations, and is told to fix it without stopping the line. You inherit the quality debt someone else booked to hit a date on a calendar. Then you spend two quarters paying it back with interest.

So when I read that Rivian's R2 has logged five separate quality issues within six weeks of customer deliveries, I recognise the pattern. This isn't a plant problem. It's a gate problem.

Five distinct escapes — different systems, different failure modes — surfacing within weeks of customer handover tells you the process was never proven stable. It was launched anyway, and now it's revealing what the APQP gates failed to contain. When the defect pattern is broad rather than deep, you're looking at systemic launch readiness failure. Not a single supplier. Not a single station.

Five escapes in 47 days is not bad luck

I've felt this pressure in automotive plants — investors watching a start-of-production date, Run@Rate not hitting its numbers. The temptation is to declare readiness, sign the PPAP warrant, and trust the team to stabilise on the fly. They can't. Not at this volume, not at this complexity, and not when customers are photographing every defect and posting it within hours of delivery.

The aerospace side works differently. It has to. At Airbus, the gate reviews I participate in are genuine checkpoints, not rubber stamps. In my first cycle we cut EASA audit findings by 50%. Not by working harder — by holding gates that blocked immature processes from advancing until the evidence supported the move. The quarter that followed: zero critical customer escalations. That wasn't luck. It was refusal to launch instability.

PPAP doesn't validate your process — it validates your paperwork

PPAP was designed to answer a simple question: can this process repeatedly produce parts that meet specification? Somewhere along the way it became a documentation exercise. The Level 3 submission gets bound, the warrant gets signed, everyone nods at the gate review. Meanwhile the capability study was run on a shift with a hand-picked crew. The MSA passed because the parts were pre-selected. The Run@Rate was declared successful after four clean hours on a Tuesday afternoon.

If the underlying capability data is soft, the warrant is fiction. Everyone in the room knows it.

At Witte Automotive I inherited exactly this kind of quality debt. The A3 reports from previous launches told the story — issues caught post-shipment that the PFMEA had predicted but the gate had ignored. We put QRQC on the floor and stopped treating containment as a strategy. The objective was to catch defects before they left the building, not after the customer found them. Substantial failure-cost reduction followed. All of it avoidable if the upstream gates had functioned as designed.

The compounding cost of launching before stability

Each escape widens the scope of the next.

When you launch an unstable process, your quality team shifts from prevention to firefighting. Engineering capacity that should be improving the process gets consumed by containment actions. The 8D reports pile up. Each corrective action is rushed, and rushed fixes create secondary failure modes that weren't in the original PFMEA. Field data returns faster than your team can close loops, and the warranty reserve — already thin for a new programme — starts bleeding.

In aerospace, a single escape can ground a fleet. The cost calculus is brutal enough that gate discipline is non-negotiable. In consumer automotive the consequences feel softer at first. A forum post. A service visit. A replacement component. That softness is precisely what makes the problem worse — it breeds the false confidence that escapes are manageable. Five in 47 days means the failure modes are outrunning your containment capacity, and each one costs more to fix than the last.

A gate that doesn't have the authority to say "not yet" isn't a gate. It's a corridor with a stamp.

The gate that matters most is the one nobody wants to hold

Every APQP manual describes five phases. The gate that matters most — and receives the least respect — sits between process validation and launch. That's where someone with authority looks at the capability data, the PFMEA risk reduction evidence, the MSA results, and the Run@Rate output, and makes a binary call: ready, or not yet.

"Not yet" is the most expensive two-word sentence in manufacturing. Until you compare it to the alternative.

I held that gate during the SNOP greenfield ramp. Nine hundred employees, new equipment, new processes, a customer base watching every move. The pressure to launch was enormous. We held where the data demanded it, advanced where the evidence supported it, and reached 98% customer satisfaction with zero critical escalations in the launch quarter. Not cautious. Disciplined. BMW is now investing in VR-based process training and AI-driven battery production at their Woodruff plant — treating launch readiness as something you engineer upstream, not something you hope for downstream. The technology is irrelevant if the gate is decorative.

Key takeaways

  • Broad defect patterns in early production mean launch readiness was graded on optimism, not capability evidence. A signed PPAP warrant means nothing if the underlying studies were run under best-case conditions.
  • Each quality escape compounds the next. Firefighting consumes engineering capacity, rushed fixes introduce secondary failure modes, and warranty reserves deplete faster than containment can absorb.
  • The APQP gate between process validation and launch is where the real decision lives. If it lacks the authority to block advancement, the organisation is launching on hope dressed up as data.
  • Six weeks of pre-launch delay costs a fraction of what a safety recall, a stock correction, and five public quality failures cost in the first month of deliveries.

The cheapest recall is the launch you delayed by six weeks. The most expensive is the one your shareholders fund — in warranty costs, in engineering hours diverted from the next programme, and in a brand that now has to prove reliability to a customer base that was already sceptical. Five escapes in 47 days didn't begin on the assembly floor. It began in a gate review where someone with authority looked at incomplete evidence and called it sufficient.

It never is.