How to design traceable records for configuration, monitored inputs, alarms, interventions, independent inspections and batch release
SAE’s public scope describes AMS2432 as establishing requirements for computer-monitored shot peening and states that AMS2430 forms an integral part. Computer monitoring is intended to observe process input settings in real time, support traceability and provide a response route throughout the peening process. The exact data fields, limits, sampling, retention and approval rules must come from the complete revision invoked by the contract, the drawing, customer supplements and the approved procedure—not from a generic checklist.

What is computer-monitored shot peening?
It is a controlled peening route in which a qualified monitoring system observes defined process inputs and operating states during execution and preserves objective records. The system should make it possible to connect the actual part or lot to the approved configuration, recorded cycle, events, reactions and release decision.
Computer monitoring is not merely a screen showing current pressure or wheel speed. A controlled implementation addresses sensors, calibration, data acquisition, time and state context, alarm logic, access, programme versions, record protection, review, retention and failure response.
What must be recorded?
The normative answer is the list in the complete contractually invoked AMS2432 revision and all customer flow-down. SAE’s public abstract does not expose enough detail to publish a universal field list. The following record architecture is therefore an implementation framework, not a substitute for the standard.
| Record group | Representative content | Control question |
|---|---|---|
| Part and order identity | Part number, drawing revision, order, lot or serial range, quantity and processing route | Can every record be assigned to the actual processed parts? |
| Released configuration | Machine, programme or recipe revision, fixture, nozzle or wheel arrangement, media route and software or control version when relevant | Was the approved configuration active? |
| Monitored execution | Defined setpoints and actual values with units, time base, state and data-quality indication | Were required inputs observed for the entire controlled cycle? |
| Events and actions | Start, stop, pause, alarm, limit excursion, acknowledgement, manual intervention, restart and disposition | Can the effect on part exposure and status be reconstructed? |
| Independent process evidence | Applicable Almen, media, coverage, surface and inspection records | Do separate required controls conform? |
| Release and retention | Review status, deviations, approvals, certificate, user identity, timestamps, record version and retention route | Is the record complete, protected and retrievable? |
Table 1. A useful record connects identity, configuration, execution, exceptions, independent evidence and release.
Why must AMS2430 be read with AMS2432?
SAE expressly identifies AMS2430 as integral to AMS2432. Computer monitoring adds real-time observation, traceability and response for defined process inputs; it does not remove the base process controls for media, Almen intensity, coverage, equipment, treatment boundaries, inspection and acceptance.
The contract can also invoke customer-specific documents, approved-source requirements, part qualification or the current Nadcap Surface Enhancement criteria. Build a document matrix showing which requirement controls each setting, record, inspection and reaction.
Which inputs may be monitored?
| Process family | Potential monitored inputs | Why exact selection is route-specific |
|---|---|---|
| Pneumatic peening | Air pressure, air flow where measured, media mass flow, nozzle or lance state, part and nozzle motion | Pressure alone does not define media velocity or Almen intensity |
| Wheel peening | Wheel speed, media feed, wheel state, part travel, indexing or rotation and stream gate state | Wheel geometry and media distribution influence the actual stream |
| Common motion and handling | Axis position or speed, rotation, traverse, fixture identity, doors, interlocks and cycle state | A valid stream can still miss the specified surface when motion or fixture is wrong |
| Media system | Media identity, feed state, replenishment or classification status and alarms when included in the qualified architecture | Electronic signals do not replace physical media inspection and working-mix control |
| Environmental or auxiliary controls | Temperature, ventilation, dust collection, cleaning or other signals only when technically invoked | Monitoring every available signal creates noise rather than controlled evidence |
Table 2. Monitor the inputs and states that belong to the qualified process—not every signal available in the controller.
The selected input set depends on air-blast or wheel equipment, number of nozzles or wheels, part and fixture motion, critical geometry, control architecture and contract. For pneumatic peening, pressure, air flow and media mass flow are distinct quantities. Pressure alone is not intensity. For wheel peening, wheel speed alone does not describe media feed, stream geometry or part motion.

How should setpoints and actual values be handled?
A command or recipe value states what the system requested. A measured value states what an identified sensor observed. Preserve units, channel identity, applicable state, time base and quality status so the difference can be assessed. An average without extremes, duration or state can hide a short excursion that matters.
Resolution, sampling, filtering, deadband, alarm delay and storage method should be justified against process risk and the invoked requirements. Excessive sampling without control logic creates data volume, not evidence. Insufficient sampling can miss a significant event. Do not assign a universal rate without the full standard and qualified architecture.
How should limits, alarms and reactions work?
A monitored limit must have a defined source, unit, active process state and response. The record should allow the reviewer to identify the actual value, start and duration of the event, affected cycle or parts, acknowledgement, automatic and manual action, investigation, disposition and release authority.
A system that only displays a red alarm but permits uncontrolled continuation does not close the risk. Interlock, pause, stop, containment and restart logic must match the potential effect on exposure and component status. Additional exposure or re-peening after an interruption is a controlled disposition, not an operator convenience.

How should interruptions be recorded?
Capture normal completion, planned pause, emergency stop, power loss, communication loss, sensor failure, media-feed interruption, motion fault and other relevant states. Preserve which surfaces had been treated, whether the cycle can be resumed and who authorized the decision.
If the system cannot reconstruct exposure at the critical feature, the part status remains unresolved until the approved nonconformance process makes a disposition. A later conforming interval does not erase an earlier data gap.
What is the difference between monitoring and acceptance?
Computer monitoring observes defined inputs and states. Almen intensity verifies the peening stream under the applicable standardized arrangement. Media inspection verifies physical media condition. Coverage accepts treatment completeness on the specified component surface. Surface, dimensional and component-performance tests answer further questions only when invoked.
These layers are correlated through qualification but remain distinct. A perfect electronic chart cannot prove complete coverage of a shadowed fillet. A conforming coverage result cannot prove that a required monitored input remained in range. Neither result directly measures residual stress or fatigue life.
How is the monitoring system qualified?
Use the complete invoked requirements and customer procedure. A defensible plan identifies sensor range, accuracy, location, calibration, data path, acquisition logic, states, limits, interlocks, record format, security, review and failure modes. Tests should challenge high and low limits, signal loss, communication interruption, power recovery, alarm response, programme revision and record retrieval as applicable.
Qualification belongs to the defined hardware, software, configuration and process route. A controller replacement, sensor type change, software update, recipe logic change, data-storage migration or altered alarm delay can require documented review, test or requalification.
How should electronic-record integrity be protected?
- Assign unique users and role-based permissions; avoid shared release credentials.
- Keep original data, timestamps, units, channel identity and cycle context.
- Record programme and configuration revisions used for the batch.
- Restrict edits and preserve the original value, reason, user, time and approval.
- Protect records against silent deletion, overwrite and uncontrolled export.
- Verify backup, retention, readability, search and retrieval for the required period.
- Document clock synchronization and system behavior after power or network loss.
| Failure mode | Required design response | Release risk if absent |
|---|---|---|
| Missing or corrupted data | Detect, flag, protect part status and route to authorized evaluation | A visually complete chart conceals an unobserved interval |
| Sensor out of calibration | Define calibration status, validity, reaction and affected-record review | Accurate-looking values have no metrological basis |
| Clock or sequence mismatch | Synchronize the relevant time base and preserve cycle-state order | Events cannot be assigned to the correct part exposure |
| Alarm or limit excursion | Capture value, duration, state, acknowledgement, action and disposition | Automatic restart adds uncontrolled exposure |
| Programme or software change | Version, authorize, test and review against qualification and customer rules | Serial data belongs to an unapproved configuration |
| Manual override or edit | Restrict access and retain original data, user, reason, approval and audit trail | The released record no longer shows what actually occurred |
Table 3. Data integrity is part of process control because the release decision depends on trustworthy records.
Which records still sit outside the computer monitor?
Depending on the contract, the release package can also require drawing and order review, material or part traceability, media receipt and working-mix evidence, Almen results, coverage records, masking and inspection records, calibration status, operator and inspector authorization, maintenance, deviations, customer forms and certificate of conformity. Link them to the same part and batch identity.
How should Nadcap be referenced?
Use the current Nadcap Surface Enhancement audit criteria and applicable supplemental checklists available through PRI EAN when the contract invokes Nadcap. Verify the exact processing site’s scope. AS7117A is withdrawn and must not be presented as the current Nadcap audit criterion.
Common implementation mistakes
- Recording only recipe setpoints without measured values or process state.
- Storing values without units, channel identity, timestamps or part assignment.
- Averaging data so short excursions and interruptions disappear.
- Allowing automatic restart without preserving exposure and part status.
- Treating computer monitoring as a substitute for Almen, media or coverage evidence.
- Editing, exporting or reformatting records without a protected audit trail.
- Changing software, sensors, alarm logic or recipes without review against qualification.
Frequently asked questions
What is AMS2432?
SAE’s public scope describes AMS2432 as a specification for computer-monitored shot peening of part surfaces and states that AMS2430 forms an integral part. The complete contractually invoked revision is required for implementation.
Which exact data does AMS2432 require?
The authoritative list must be taken from the complete invoked revision, drawing, customer supplements and approved procedure. A public abstract does not justify attributing a universal field list, limits, sampling rate or retention period to the standard.
Does computer monitoring replace Almen intensity verification?
No. Monitoring defined machine inputs and states does not replace the applicable Almen system and procedure. Both belong to the controlled route when invoked.
Does a complete electronic chart prove coverage?
No. Coverage is accepted on the specified component surface with the approved method. Correct machine inputs do not by themselves prove that every critical zone received complete impact evidence.
Should setpoints or actual values be recorded?
Use the full invoked requirements. A defensible monitoring design normally distinguishes commands or setpoints from measured actual values, state, units, time base and data-quality status so execution can be reconstructed.
What happens after an alarm or interruption?
Protect the affected part status, preserve the complete event record and apply the approved reaction and disposition route. Restart, continuation or reprocessing must not be improvised.
Can an operator edit a computer-monitored record?
Access and corrections must follow the approved data-integrity procedure. Preserve the original value, user, time, reason, authorization and audit trail; never overwrite history invisibly.
Does AMS2432 automatically require Nadcap?
No. Nadcap accreditation and its current checklist scope apply only when invoked by customer, contract or programme. Verify the exact site and current PRI scope separately; do not use withdrawn AS7117A as the current audit criterion.
Key takeaways
- Use the complete invoked AMS2432 and AMS2430 document set.
- Link part identity, released configuration, actual execution, events and disposition.
- Distinguish setpoints from measured values and preserve units, time and state.
- Make alarms and interruptions reconstructable and protect affected part status.
- Keep electronic monitoring separate from Almen, media, coverage and part acceptance.
- Protect data integrity, configuration and changes through the entire retention period.
Related SP Center guides
- AMS2430 for Shot Peening
- Shot Peening Repeatability and Monitored Variables
- Almen Intensity in Shot Peening
- Shot Peening Coverage
Primary sources
1. SAE AMS2432E: Shot Peening, Computer Monitored, revised October 2022
2. SAE AMS2430U: Shot Peening, revised April 2018
3. Performance Review Institute, Nadcap accreditation
Standards note: This guide does not reproduce the standard. The complete revisions and customer-specific requirements invoked by the contract govern.
Author: Paweł Kmieć
Discuss a computer-monitored process: +48 519 772 773 | [email protected]




