Skip to main content
Industry Best Practices

QA Isn't a Team: Why You're Confusing Prevention with Inspection

Think QA and QC are the same? Blunt truth: QA prevents, QC detects. Here's how to stop myth-busting and start building a quality system that actually works.

Imagine you're the quality manager at a mid-sized parts manufacturer. Your boss just told you to 'get us ISO 9001 certified by December.' You've got a stack of process maps, a team that thinks auditing is a four-letter word, and a production manager who swears 'we've been doing fine without all this paperwork for 20 years.' Sound familiar? If you're nodding, you've already hit the first wall: quality isn't a department—it's a discipline. And the biggest mistake you can make is confusing quality assurance with quality control. Let's clear that up right now.

What's the actual difference between QA and QC?

Quality assurance (QA) is proactive. It's everything you do to make sure a product is built right the first time—planning, process design, training, preventive maintenance. Quality control (QC) is reactive. It's the inspection, testing, and measurement you do after the fact to catch what slipped through (ASQ). Think of QA as designing a road that doesn't have potholes; QC is driving a truck over it to see if it rattles. If you're only doing QC, you're playing whack-a-mole. If you're only doing QA, you're flying blind. You need both, but they're not interchangeable. And here's the kicker: QC is actually a subset of QA (ASQ). That means if your QA is solid, your QC should be less painful—not because you inspect less, but because you have less to find.

Isn't verification the same as validation?

No, and this one trips up more people than it should. Verification asks: 'Did we build the thing right?' Validation asks: 'Did we build the right thing?' The ASQ Quality Glossary puts it this way: verification is determining whether products and services conform to specific requirements, while validation is confirming that the product or service meets the requirements for which it was intended (ASQ). Think of a car seat. Verification checks that the harness straps are stitched to spec. Validation asks whether that seat actually protects a child in a crash. You can verify a product to death and still fail validation if you built the wrong thing. Quality professionals who skip validation are like archers who perfect their draw but never check if they're aiming at the target.

Does 'quality' mean 'expensive'?

This is the myth that won't die. The old-school view is that quality costs money—more inspection, more rework, more scrap. But the cost of quality (COQ) framework flips that on its head. COQ has two sides: the cost of good quality (prevention and appraisal) and the cost of poor quality (COPQ), which includes internal failures (defects found before the customer sees them) and external failures (defects found after delivery) (ASQ). External failures are the killer—warranty claims, recalls, lost customers. A 2023 study found that ISO 9001 certification is still the world's most widely held management system certificate, with 837,052 valid certificates covering over 1.2 million sites (ISO Survey 2023). Why do so many organizations bother? Because the cost of doing nothing is usually higher. The real question isn't whether quality costs—it's whether you're paying for prevention or paying for failure. And prevention is almost always cheaper.

Should I get certified in ISO 9001 or just 'do quality'?

If you want a system that's actually used, not just filed away, get certified. ISO 9001 is the world's most widely used quality management standard, with over a million certifications in more than 170 countries (ASQ). The 2022 ISO Survey counted 1,265,216 valid ISO 9001 certificates worldwide (ISO Survey 2022). That's not a coincidence. Certification forces you to document what you do, do what you document, and prove it when an auditor shows up. But don't treat the certificate as a trophy. The standard is built on the Plan-Do-Check-Act (PDCA) cycle—Plan a change, Do it, Check the results, Act on what you learned (ASQ). If you're not using PDCA to improve, you're just paying for a plaque. And remember: ISO 9001 is the only standard in the ISO 9000 series you can get certified against (ASQ). The rest—ISO 9000, ISO 9004, ISO 19011—are guides and tools, not certifications.

What's the deal with Six Sigma? Is it just for statisticians?

Six Sigma sounds intimidating, but at its core it's a disciplined way to reduce variation. The goal is a process that produces only 3.4 defects per million opportunities (ASQ). That's a stretch target, not a daily reality for most. But the methodology—define, measure, analyze, improve, control (DMAIC)—is just a structured problem-solving loop (ASQ). You don't need a black belt to think statistically. You do need to understand the difference between common cause variation (inherent in the process) and special cause variation (something external and assignable). Control charts, originally developed by Walter Shewhart in the early 1920s, help you tell the two apart (ASQ). If you're not using data to decide when to act, you're guessing. And guessing is not a quality strategy.

What about all the sector-specific standards? Do I need AS9100 or IATF 16949?

If you're in aerospace, automotive, or medical devices, the answer is usually yes—your customers will demand it. AS9100 is the aerospace QMS standard; it contains all of ISO 9001's requirements plus extra aviation, space, and defense requirements (ANAB). IATF 16949 is the automotive standard; it's not standalone—it supplements ISO 9001:2015 (IATF). And in the US, the FDA now requires most medical device manufacturers to follow ISO 13485, with the Quality Management System Regulation (QMSR) effective February 2, 2026 (Federal Register). These standards are not just ISO 9001 with a different logo. They add rigor around traceability, risk, and supplier control. If you're in a regulated industry, don't try to bolt on a generic QMS and hope it passes. The auditors know the difference.

Is auditing a waste of time?

Only if you do it wrong. The revised ISO 19011:2026, published in 2026, is the go-to guide for auditing management systems (CQI). It emphasizes remote auditing methods, which is handy in a post-pandemic world. But here's the trap: many organizations treat audits as a paperwork exercise—check the box, file the report, move on. That's not auditing; that's theater. A good audit finds gaps before they become costly failures. It looks at processes, not just documents. And it should be independent—the standard says auditors should be independent of the function being audited, if practicable (CQI). If you're auditing your own work, you're just admiring your own handwriting.

How do I get started without boiling the ocean?

Start with the customer. The seven quality management principles in ISO 9001 put customer focus first (ASQ). Ask: what does the customer actually need? Then map your core processes—not every tiny step, just the ones that touch the product or service. Use the seven QC tools—cause-and-effect diagrams, check sheets, control charts, histograms, Pareto charts, scatter diagrams, and stratification—to analyze data (ASQ). And don't forget mistake proofing (poka-yoke): design your process so errors are impossible or immediately obvious (ASQ). One small win: implement 5S—sort, set in order, shine, standardize, sustain—to create a workplace that's easy to keep clean and controlled (ASQ). You don't need a grand rollout. You need a first step that demonstrates value. Then do PDCA again.

So what's the single most important thing to remember?

Quality is not a department. It's not a checklist. It's not a certificate on the wall. It's a habit of asking 'what could go wrong?' before it does, and 'what did we learn?' after it doesn't. If you take away one thing, make it this: prevention beats inspection, every time. Stop inspecting quality into your product and start building it in.

Sources

  • ASQ - https://asq.org/quality-resources/quality-assurance-vs-control
  • ASQ (Six Sigma) - https://asq.org/quality-resources/six-sigma
  • ISO Survey 2023 (Intercertifica) - http://intercertifika.ru/images/PDF/ISO-Survey-2023.pdf
  • ASQ (ISO 9000) - https://asq.org/quality-resources/iso-9000
  • Federal Register (FDA QMSR) - https://www.federalregister.gov/documents/2024/02/02/2024-01709/medical-devices-quality-system-regulation-amendments

Share this article:

Comments (0)

No comments yet. Be the first to comment!