Manufacturing
Data inventory for manufacturers: ERP, MES and QMS records
By SourceX Editorial · Updated
Short answer
A data inventory for a manufacturing company lists every record family by system, years of accessible history, owner, export route, linking keys and restriction flags. Start from pre-filled rows for ERP, MES, QMS and CMMS records, and flag customer-owned designs and export-controlled work first, because those two flags decide what can ever be reused or licensed.
Key takeaways
- Inventory record families, not systems: one ERP holds orders, costs, quality and service records with very different rights.
- Every row needs a system, years of accessible history, an owner, an export route, linking keys and restriction flags.
- Customer-owned designs and export-controlled work are flagged in the first pass and excluded from any license.
- Linking keys such as job, lot, serial and asset numbers decide whether rows can be joined into a useful package.
- A data inventory is metadata only, so building one requires no exports or samples.
What should a manufacturing data inventory capture?#
A manufacturing data inventory captures, for each record family, where it lives, how far back it goes, who owns it, how it can be exported and what restricts its use. It is a map of records, not a copy of them, and it should fit on one worksheet.
Keep entries short and factual, and write unknown where nobody knows. A wrong history depth or a missed flag costs more later than an honest gap now.
- Record family: quotes, sales orders, NCRs, maintenance work orders and so on.
- System of record, plus any retired systems that hold older years.
- Years of accessible history and known gaps.
- Record owner: the manager who can explain the fields.
- Export route: standard report, API, database query or vendor export.
- Linking keys: part, job, lot, serial, asset or customer numbers.
- Restriction flags: customer-owned design, export-controlled, personal data, supplier confidential, legal hold.
- Notes: code changes, past migrations and how complete the free-text fields are.
Pre-filled rows for ERP records#
ERP rows form the backbone of a manufacturing inventory because part, job and order numbers tie every other system together. The flags below are defaults to confirm for your plant, not conclusions.
| Record family | Typical module | Linking keys | Default flags |
|---|---|---|---|
| Quotes and estimates | Sales or estimating | Quote, customer, part | Customer pricing; customer drawings often attached |
| Sales orders and shipments | Order management | Order, customer, part, lot | Customer names |
| Jobs and work orders | Production or shop floor | Job, part, routing | Customer-owned part designs |
| Bills of materials and routings | Engineering | Part, revision | Customer-owned designs; possible export-controlled items |
| Purchase orders and receipts | Purchasing | PO, supplier, part, lot | Supplier pricing confidential |
| Standard and actual costs | Costing | Part, job | Internal confidential |
| Returns and RMAs | Service or quality | RMA, order, serial | End-user personal details |
Pre-filled rows for MES, QMS and CMMS records#
MES, QMS and CMMS rows hold most of the decision-and-outcome history in a plant: why a lot was held, how a defect was dispositioned, what failed on a machine and how it was fixed. Expect older years of these records to sit in retired systems, spreadsheets and paper.
| Record family | System | Linking keys | Default flags |
|---|---|---|---|
| Operation start, stop and quantities | MES | Job, operation, machine | Operator names |
| Downtime events and reason codes | MES | Machine, shift, reason code | Operator notes may name people |
| Electronic travelers and work instructions | MES | Job, part, revision | Customer-owned designs embedded |
| NCRs and dispositions | QMS | NCR, part, lot, customer or supplier | Customer names; customer drawings attached |
| CAPAs and 8D reports | QMS | CAPA, NCR, customer | Customer complaint text |
| Inspection, CMM and SPC results | QMS, CMM or SPC software | Part, lot, characteristic | Characteristics taken from customer drawings |
| Calibration records | QMS | Gauge ID | Usually none |
| Maintenance work orders and PM history | CMMS | Asset, work order | Technician names; copyrighted OEM manuals |
| Spare parts and stores | CMMS or ERP | Part, asset | Supplier pricing |
How to flag customer-owned designs and export-controlled work#
Customer-owned designs and export-controlled work are flagged on every row they touch, because both are excluded from licensing and both hide inside ordinary records. A job record may carry a customer drawing as an attachment, an NCR may include a photo of a customer's part, and a work instruction may embed controlled technical data.
The definitions are broad, which is why the flag hides in ordinary records. ITAR technical data under 22 CFR 120.33 includes information required for the design, production, manufacture, assembly, testing, maintenance or modification of defense articles, including blueprints, drawings, photographs, plans and instructions. Under the EAR, 'technology' (defined in 15 CFR 772.1) is information necessary for the development, production, use, operation, maintenance or repair of an item. A work instruction, a process sheet or an NCR photo can fall inside either definition.
If export-controlled work runs through most of a site, excluding whole systems or sites is often cleaner than separating records line by line. Your export compliance lead or counsel makes that call, not the inventory team.
- Flag customer-owned design when a row contains or attaches drawings, models, specifications or inspection plans supplied by a customer, or when purchase terms give the customer ownership of designs or tooling.
- Flag export-controlled when a row relates to programs, parts or technical data your compliance lead has classified as controlled, and also when nobody is sure.
- Note which fields or attachments carry the restricted content, so the rest of the record family is not written off.
- Send every flagged row to export compliance or counsel before any scoping discussion.
How do you run the inventory without moving any data?#
A manufacturing data inventory runs entirely on metadata gathered from the people who own each system. Short conversations with the ERP administrator, quality manager, maintenance lead and MES owner can fill most rows, and IT then confirms export routes and how deep history goes. Nobody needs to run an export or pull a sample to answer these questions.
Work in order of decision richness: QMS and CMMS first, then ERP orders and jobs, then MES events and machine data. Give each retired system its own row with its location and whether it can still be opened, because older systems often hold the longest history and are the first to be switched off.
Illustrative: an electronics contract manufacturer maps its records#
Illustrative: a fictional contract manufacturer builds printed circuit board assemblies and box builds for industrial and instrumentation customers. It runs a cloud ERP, an MES that tracks boards by serial number, a QMS for NCRs and CAPAs, and automated optical inspection and X-ray stations that save images.
The inventory shows that nearly every bill of materials, Gerber file and assembly drawing is customer-owned, and that one customer program involves export-controlled work. Both are flagged and excluded. What remains is distinctive: NCRs and rework records linked to serial numbers, optical inspection defect calls with operator confirmations, and maintenance history on reflow ovens and placement machines.
The COO takes those record families into a fit check with customer names removed and the controlled program left out entirely. The inspection images stay out for now, because almost every image shows a customer's board.
How SourceX uses a manufacturing inventory#
SourceX uses the inventory as the input to a metadata-only fit check. Rows flagged as customer-owned or export-controlled stay out. The strongest remaining rows, those with linked outcomes, accessible history and clear rights, are then rated qualitatively against the SourceX Enterprise Data Value Framework on drivers including uniqueness, domain expertise, rights, preparation cost and privacy burden.
Rows that clear that review go through the SourceX five-step transaction of Supply, Rights, Preparation, Approval and Delivery, and the manufacturer signs off at each step. Large exports, such as years of inspection images, remain on the manufacturer's own servers or travel on encrypted drives.
Frequently asked questions
How detailed should a first inventory be?
Detailed enough to rank record families, not to describe every field. System, years of history, owner, linking keys and flags are enough for a first pass. Field-level data dictionaries come later, and only for the record families that look worth pursuing.
Should spreadsheets and shared drives be in the inventory?
Yes. Plants often keep 8D reports, inspection sheets, SPC charts and maintenance logs in spreadsheets and folders outside any system. List them as rows with location, owner and how they link to a part, job or asset. Unlinked files rank lower, but they still belong on the map.
Who should fill in each row?
The COO or IT lead coordinates, but record owners fill in their own rows: the quality manager for QMS records, the maintenance lead for CMMS, the controller for costing and the ERP administrator for orders and jobs. Export compliance or counsel reviews every restriction flag.
Where do machine data and historians fit?
Include them as rows. Historian tags and PLC data are useful context when they can be tied to jobs, assets or quality events. On their own they describe machine states rather than decisions, so they usually rank below NCRs, CAPAs and work orders in a first pass.
Can software find personal details in free-text fields for us?
It can help, but not alone. Open-source tools such as Presidio detect names and contact details in text, and the project itself says automated detection offers no assurance that every sensitive detail will be found. Treat automated scanning as a first filter and add human review of NCR notes, work order comments and complaint text.
When does the inventory need a refresh?
Update it when a system is added, migrated or retired, when a customer program with design ownership terms starts or ends, and when export classifications change. A quick review of the flags before any licensing conversation keeps the inventory honest and avoids scoping records that have since become restricted.
Sources
- Presidio's own documentation warns that because it is using automated detection mechanisms, there is no guarantee that Presidio will find all sensitive information, so additional systems and protections should be employed. Source
- 22 CFR 120.33(a)(1) defines ITAR technical data to include information required for the design, development, production, manufacture, assembly, operation, repair, testing, maintenance, or modification of defense articles, including blueprints, drawings, photographs, plans, instructions or documentation. Source
- BIS describes EAR 'technology' (15 CFR 772.1) as information necessary for the development, production, use, operation, installation, maintenance, repair, overhaul, or refurbishing of an item. Source
Related resources
See if your company qualifies
A short company assessment. No data uploads are needed.