Privacy and preparation
Supplier and customer names in NCRs and CAPAs
By SourceX Editorial · Reviewed by Noah Loul ·
Short answer
To anonymize quality records such as NCRs and CAPAs, replace supplier, customer and person names with stable codes, and keep the defect, root cause, containment, corrective action and verified outcome. Codes preserve patterns across records, such as one supplier's repeat escapes, without exposing who it was or breaching the confidentiality terms in quality and supply agreements.
Key takeaways
- Names in quality records are mainly a confidentiality problem: they expose supplier performance and customer relationships.
- Stable codes beat blanking, because they keep repeat patterns visible across NCRs, CAPAs and SCARs.
- Names hide in part numbers, lot numbers, attachments and pasted email, not only in the supplier and customer fields.
- Customer-owned drawings and export-controlled programs stay out of scope entirely.
- The engineering chain from defect to verified fix is the part worth licensing.
Why are names in quality records a confidentiality problem?#
Names in quality records are mainly a confidentiality problem because an NCR or CAPA says, in writing, that a named supplier shipped bad parts or that a named customer received them. A supplier's name next to a run of escapes is a performance judgment; a customer's name next to a complaint reveals both the relationship and the failure.
Quality agreements, supply agreements and NDAs often treat that information as confidential, and customers in regulated or competitive industries may restrict any disclosure of their programs. Personal names add a privacy layer on top: inspectors, operators, MRB members and the supplier quality engineer who signed the response.
None of those names helps an AI developer learn how defects are found, contained and fixed. That is what makes quality records good candidates for coding rather than exclusion.
QMS field treatment table#
The field treatment table below sets defaults for the fields a typical QMS, ERP quality module or spreadsheet-based NCR log contains. Adjust the defaults for your own forms, but keep the principle: parties become codes, people become roles, engineering content stays.
| Field | Treatment | Reason |
|---|---|---|
| Supplier name | Replace with stable code plus commodity | Keeps repeat-supplier patterns without naming |
| Supplier lot and heat numbers | Remove or re-key | Can be traced back to the supplier |
| Customer name | Replace with stable code plus industry | Protects the relationship and the program |
| Customer part number and PO | Replace with internal part family | Customer prefixes and PO formats identify the customer |
| Defect description | Keep after scrubbing names | Core content |
| Containment and disposition | Keep | Shows the decision under time pressure |
| Root cause and 8D or 5 Why narrative | Keep after scrubbing names | The reasoning AI developers value |
| Corrective and preventive action | Keep | Links cause to fix |
| Effectiveness verification | Keep | Shows whether the fix held |
| Originator, approvers, team members | Replace with role | Personal names add risk and no value |
| Cost of poor quality | Generalize to a band or remove | Commercially sensitive |
| Drawings, photos and supplier responses | Exclude unless reviewed one by one | Logos, labels, customer drawings |
Why do stable codes work better than blanking?#
Stable codes work better than blanking because quality data is about patterns over time. A blanked supplier field turns a chain of related escapes into isolated events; a code such as castings supplier B lets a reader see that the same source failed in several different ways before its CAPA finally held.
Keep the code map inside the company under restricted access, and build a new map for each license so separate packages cannot be combined to rebuild a supplier list. Avoid codes that hint at the real name, such as initials or the supplier's city.
Add descriptive attributes next to each code so the pattern stays interpretable. A commodity for suppliers, an industry for customers and a part family for parts let a reader compare like with like, for example castings suppliers against machined component suppliers, without any of them being named.
Where do names hide inside NCR and CAPA records?#
Names hide in the free text and the attachments far more than in the supplier and customer fields, which are easy to code. A methodical search of the places below catches most of them before a human review.
Run the search with a list built from your own masters: every active and former supplier name, customer name, plant name and common abbreviation from the ERP. Quality engineers write short forms and nicknames, so ask the quality manager to add the names people actually use on the floor before the search runs.
- 8D team member lists and sign-off blocks.
- Email chains pasted into the narrative, with signatures and letterheads.
- Photos of labels, packing slips, certs of conformance and part markings.
- Supplier corrective action responses on the supplier's own letterhead.
- Part numbers that carry a customer prefix or a supplier catalog code.
- Lot, heat and serial numbers that trace back to a supplier or an end customer.
- Ship-to locations and plant names in customer complaint records.
- Meeting notes from MRB and quality review boards that name attendees.
Which quality records stay out completely?#
Quality records tied to customer-owned designs or export-controlled programs stay out completely, regardless of how well names are coded. A drawing or a defect description can carry the customer's design intent, which is the customer's confidential information, and coding the customer's name does nothing to change who owns it.
Export-controlled work is a separate line. Under the ITAR, technical data may be released simply by letting a foreign person inspect it or by giving access information that lets them view unencrypted technical data, so quality records from those programs are not candidates for licensing. Confidentiality also protects your own processes: trade secret law asks whether the owner took reasonable measures to keep information secret, so licensing quality data without strong confidentiality terms could weaken that position for your own methods. Assess both questions with counsel.
Illustrative: a precision machining shop prepares its quality history#
Illustrative: a fictional precision machining shop keeps NCRs, CAPAs and SCARs in a QMS linked to its ERP, serving industrial and medical device customers. The plant manager wants to license years of NCR and CAPA history for quality analytics tools.
The Rights review first removes every record tied to customer-supplied drawings under restrictive terms and every medical device program whose quality agreement prohibits disclosure. For the remaining records, the team codes suppliers by commodity, codes customers by industry, replaces customer part numbers with internal part families and replaces people with roles.
A text search of narratives finds supplier names inside pasted emails and customer names in containment notes; those are scrubbed. Attachments are excluded except for a set of defect photos reviewed one by one. The package keeps every defect, cause, action and verification step, so a reader can follow a supplier code through repeated escapes to a fix that held.
How SourceX approaches quality records#
SourceX treats quality records in two passes of the SourceX five-step transaction. The Rights step identifies customer-owned and restricted material that must be carved out, and the Preparation step applies coding and scrubbing to what remains. The supplier approves the field treatments before Delivery.
The carve-outs and field rules are recorded in the SourceX Evidence Packet under licensing rights and the privacy record. In the SourceX Enterprise Data Value Framework, domain expertise and human-generated signal are drivers that increase value, and quality narratives carry both, which is why the narratives and verification steps are kept rather than reduced to codes.
Frequently asked questions
Can we keep a supplier's name if the supplier agrees?
Possibly, but there is rarely a reason to. A supplier's consent covers only its own name; the same records name your customers, your staff and sometimes other suppliers. Codes deliver the same analytical value with fewer approvals, so most companies code even willing suppliers.
Do quality certifications restrict sharing quality records?
Certification schemes such as ISO 9001 govern how you control records, not whether you can license them, but customer-specific requirements under those schemes often do restrict disclosure. Check each customer's quality agreement and supplier manual, which is where most restrictions live.
Should customer complaint records be included?
They can be, with care. Complaints carry the customer's voice and the failure mode, which are valuable, but they also carry end-user names, field locations and sometimes injury details. Code the customer, remove end-user details and exclude any complaint that involves harm to a person.
What about SCARs we sent to suppliers?
Supplier corrective action requests and responses are useful because they show the supplier's root cause and fix. Treat them like NCRs: code the supplier, scrub the people, and exclude the supplier's letterhead documents unless each one is reviewed and cleaned.
Does coding names reduce the value of quality data?
Very little. What developers use is the sequence from defect to containment, cause, action and verification, plus the ability to follow one supplier or part family over time. Stable codes preserve both, while names add risk without adding signal.
Sources
- 22 CFR 120.56(a) provides that technical data is released through visual or other inspection by foreign persons, oral or written exchanges with foreign persons, or the use of access information to enable a foreign person to access unencrypted technical data. Source
- Under 18 U.S.C. 1839(3), information qualifies as a trade secret only if the owner has taken reasonable measures to keep it secret and it derives independent economic value from not being generally known. Source
Related resources
- QuestionWho owns enterprise data?
- QuestionDo AI labs buy code?
- InsightHow do I de-identify images and inspection photos for AI training?
- InsightHow do I de-identify source code for AI training?
- InsightHow do I de-identify CAD and engineering drawings for AI training?
- SolutionData partnerships between businesses and AI developers
See if your company qualifies
A short company assessment. No data uploads are needed.