I have signed off PPAP packages that were spotless. Clean control plans, capable processes, every gate document filed in triplicate. Launch PPM in the low single digits. Six months later the phone rings and a customer is screaming about a field failure nobody modelled. That phone call is not a quality failure. It is a temporal failure. Your APQP was scoped to validate a moment in time, not a life in service.
Ford markets "New Found Quality" while recalling over 900,000 vehicles in a single week across two unrelated critical defects. Broncos catching fire. Rear seats failing in ways that put occupants at risk. These vehicles launched with full PPAP packages. IATF gates cleared. Launch quality metrics green. None of that infrastructure was designed to see what happens at 80,000 miles — after 400 under-bonnet heat cycles, after the polymer has aged, the bracket fatigued, the connector corroded past its contact threshold.
The APQP didn't miss the defect. It was never scoped to look for it.
Your DFMEA scores occurrence at launch. The failure mode shows up at 80,000 miles.
This is the structural blind spot nobody in automotive wants to discuss. Your DFMEA asks: what is the likelihood of this failure mode occurring? The occurrence scoring reflects the design as validated during PV testing. The component is fresh. Materials within nominal spec. Assembly torque perfect because it was applied six minutes ago by a process that was just capability-studied.
Score that same component at four years of thermal cycling. After 300 heat events pushing it twenty degrees above its rated glass transition temperature. After vibration has worked the crimp terminal loose by a fraction of a millimetre. The occurrence number is different. Severity might be unchanged. Detection? Your detection methods stopped at the end of the PV window and restarted when warranty claims began clustering.
I spent years in IATF 16949 environments. The standard is rigorous about launch discipline. Its time horizon is a launch horizon. APQP is a gate system — it asks whether you are ready to produce. It does not ask what this product becomes after three years of abuse by a customer who never reads the manual, pressure-washes the engine bay, and ignores the service indicator for eight thousand miles.
PV testing ends where most warranty claims begin
Production validation testing proves the process is capable and the product meets specification at the moment of manufacture. It does not simulate the ownership cycle. Test durations are finite. Conditions controlled. Sample sizes statistically valid for the population at launch — not for the population at year four, after real-world ageing has selected for failure modes your protocol never exercised.
I saw this repeatedly in automotive supply chains. A component passes PV. The team celebrates. PPAP filed. Launch review closes with handshakes. Then at 60,000 miles the field data tells a different story. Warranty claims cluster around a failure mode nobody modelled because the PV protocol did not extend into the degradation curve. Polymer embrittles. Adhesive delaminates. Spot weld fatigues along a path invisible under static load. These are not random defects. They are predictable physical processes that begin exactly where your test protocol ended.
The cost structure makes this worse. Automotive funds warranty reserves as a financial instrument — a bet that historical failure rates will predict future ones. Historical data does not capture new failure modes introduced by new materials, new supply bases, new electronic architectures, or weight-saving decisions that pushed structural components closer to their fatigue limits. The Bronco fire risk and the rear-seat failure are unrelated systems. They share a root cause at the quality-system level: nobody owned the question of what happens to these components after the PV window closed and the launch dashboard turned green.
Aerospace runs continuing airworthiness. Automotive runs warranty reserves.
I have lived the transition from IATF 16949 to AS9100. The structural difference is stark.
At Airbus, the 50% reduction in EASA audit findings in a single cycle did not come from better gate discipline at launch. It came from treating quality as a lifecycle practice. We monitored process drift across quarters, not just at gate sign-off. We tracked leading indicators that told us something was changing before it became a finding or an escalation. At SNOP, zero critical customer escalations within a quarter came from the same philosophy — continuous surveillance, not celebration of the launch milestone.
Aerospace has a concept automotive structurally lacks: continuing airworthiness. Regulatory and organisational infrastructure — airworthiness directives, operator reporting loops, in-service reliability programmes — dedicated to understanding how products degrade and acting before the pattern becomes a safety event. The system assumes the product will change in service and builds mechanisms to respond.
Automotive has TSBs, recalls, and warranty reserves. The recall is the primary reactive mechanism. It fires after the failure pattern is in the field, after customers have experienced the defect, after the cost is incurred and the brand has taken the hit. The system is not designed to prevent degradation failures. It is designed to pay for them.
The gap between your APQP sign-off and the customer's 80,000th mile is not empty space. It is where your quality system went blind by choice.
Key takeaways
- Extend your DFMEA occurrence scoring across the realistic ownership cycle, not just the PV window. Score the component as it will exist at 80,000 miles, not as it leaves the line.
- Treat warranty reserves as a leading signal, not a settled forecast. If claims are clustering, your degradation model is wrong — fix the engineering, not the reserve math.
- Build process drift monitoring that runs across quarters. Launch metrics tell you about the process on day one. Sustained surveillance tells you what the process is becoming.
- Assign explicit engineering ownership for in-service degradation. If nobody owns the question of what happens after PV, the recall notice will own it for you.
Stop treating launch PPM as the finish line. The recall is the invoice for degradation you decided not to model.