What Is Quality Assurance: Why Building Quality Into the Process Is a Different Job From Catching Defects at the End, and What Each One Can Prevent

The Two Jobs Everyone Calls Quality

Published 2026-09-09 · EuroQuest International

Quick summary

  • Assurance builds the process, control checks the output. Quality assurance works on how the work is done so defects are less likely; quality control examines what came out so defects are caught before a customer sees them.
  • Inspection is a control activity, not a third discipline. It is the most visible part of control and the easiest to mistake for the whole of quality.
  • You cannot inspect quality into a product. Sorting good units from bad ones does not change the rate at which bad ones are produced, which is why control alone plateaus.
  • The cost order is fixed. Preventing a defect costs less than finding it, which costs less than shipping it. Recall and enforcement figures are what the last option looks like.
  • Neither is the same as a standard or a certificate. A management system standard sets requirements for the framework; assurance and control are the work done inside it.

Walk into most organizations and ask who owns quality, and the answer will point at a team that checks things. That team is doing quality control, and it is doing something genuinely necessary. But the reason the same defects keep arriving at their bench, week after week, is that nobody upstream is working on the process that produces them. That upstream work is quality assurance, and the difference between the two is not a matter of vocabulary. It decides where an organization spends its money and whether its defect rate ever falls.

The confusion is understandable, because the two words are used interchangeably in job titles, in tenders and in everyday speech. This guide sets out what each one actually is, how inspection and testing fit, why an organization that only does control tends to plateau, what evidence of both looks like, and where the boundary sits against the standards, methodologies and audit functions the two are routinely confused with.

On this page

  1. What quality assurance actually means
  2. How quality control differs, and where inspection sits
  3. Why control alone stops working
  4. What each one costs, and what escapes
  5. How it differs from standards, Six Sigma and audit
  6. How to tell which one your organization is actually doing
  7. Frequently asked questions
602,000
Quality control inspectors were employed in the United States in 2025, with about 66,700 openings projected each year, per the Bureau of Labor Statistics
4,671
Alerts were raised through the EU rapid warning system in 2025, up 13 percent and the highest on record, with follow-up actions up 35 percent, on European Commission figures
314
Warning letters were issued by the US Food and Drug Administration in 2025, alongside 321 classified recall events covering 755 products, in its compliance annual report
2,396
Notifications were recorded on the United Kingdom product safety database in the year to March 2026, covering 3,368 notified products, per official statistics

What Quality Assurance Actually Means

Quality assurance is the set of planned activities that make a good outcome likely before any work is done. It operates on the process rather than on the product. Writing a specification that is unambiguous, qualifying a supplier before the first order rather than after the first failure, training an operator to a defined competence, validating that a machine can hold the tolerance it is being asked to hold, controlling which revision of a drawing is on the floor: none of those examine a finished unit, and all of them change the probability that finished units will be acceptable.

The defining test is timing and object. If the activity happens before or during the work and changes how the work is done, it is assurance. If it happens after and judges what came out, it is control. A written procedure is assurance; checking that a batch conforms to it is control. Training a welder is assurance; radiographing the weld is control. Both are needed, and only one of them changes tomorrow's defect rate.

Assurance Is Mostly Unglamorous Paperwork, and That Is the Point

The activities that prevent defects are rarely interesting: version control on documents, a competence matrix that is actually current, a change-control step before a process is altered, a supplier qualification file, calibration records for the instruments that decide whether something passes. None of it produces a satisfying moment of discovery. All of it removes a category of failure permanently rather than one unit at a time.

This is also why assurance is the first thing cut under pressure. It has no visible output on a bad week, and skipping it produces no immediate consequence, only a slightly higher failure rate three months later that nobody attributes to the skipped step. Organizations that treat it as an operational discipline rather than a filing exercise usually build it through structured quality control and assurance in operations work rather than by writing more procedures.

How Quality Control Differs, and Where Inspection Sits

Quality control is the examination of output against requirements: measuring, testing, sampling, reviewing, and deciding whether what was produced can go forward. It answers a question about a specific unit or batch, and its answer is binary in effect even when the measurement is continuous. This one passes, that one does not.

Inspection is the most familiar control activity and is often mistaken for the whole of quality. It is one method among several. Statistical sampling, functional testing, first-article verification, in-process measurement and final review are all control, and they differ mainly in when they happen and how much of the population they cover. The scale of the activity is easy to underestimate: in the United States alone, quality control inspectors held about 602,000 jobs in 2025, with roughly 66,700 openings projected each year over the decade.

Dimension Quality assurance Quality control
Object The process that produces the work The output the process produced
Timing Before and during the work After a unit, batch or deliverable exists
Question it answers Are we set up so that failure is unlikely? Did this particular thing meet the requirement?
Typical activities Specifications, supplier qualification, training, validation, change control, document control Inspection, testing, sampling, measurement, final review
What it changes The rate at which defects are created Whether a created defect reaches the customer
Who usually owns it Process owners, engineering, and the quality function together A dedicated inspection or test function, or the operator

Key terms, used precisely

  • Verification. Confirming the thing was built the way it was specified. A control question.
  • Validation. Confirming the specification produces something that actually works for its purpose. An assurance question, and the one skipped most often.
  • Nonconformity. A departure from a requirement. It is a finding, not yet a cause, and treating the two as the same is how the same nonconformity recurs.
  • Escape. A defect that passed every control and reached the customer. Recalls, safety alerts and enforcement letters are the public record of escapes.
  • Acceptance criteria. The written line between pass and fail. If it is not written before the work starts, control becomes negotiation.

Why Control Alone Stops Working

An organization that invests only in control improves quickly at first and then stops. The reason is arithmetic rather than attitude. Sorting acceptable units from unacceptable ones does not alter the rate at which unacceptable ones are produced, so the scrap and rework bill stays where it is while the inspection bill grows. Adding a second check catches some of what the first missed, then a third catches a little of what the second missed, and the returns fall away sharply.

There is a second, less obvious effect. When an inspection function is visibly responsible for quality, the people doing the work stop treating it as theirs. Defects become somebody else's problem to find, which raises the defect rate and increases the load on the very function that was supposed to reduce it. That is the loop most quality departments are stuck inside, and no amount of additional checking gets an organization out of it.

Sampling Has Limits Nobody Reads

Most control is sampled rather than total, because inspecting everything is usually impossible and sometimes destructive. Sampling plans carry a stated confidence level and an acceptable quality limit, and both are frequently treated as though they promised zero defects. They do not. A plan designed to catch a two percent defect rate will let a population with a one percent rate through routinely, which is exactly correct behavior and still a surprise to whoever receives the complaint.

Even total inspection is imperfect. Human inspectors miss a measurable proportion of defects, particularly on repetitive visual tasks, and automated systems miss whatever they were not configured to see. Building the discipline into how work is planned rather than only into how it is checked is the substance of quality assurance in project execution, where the deliverable is one of a kind and there is no batch to sample.

What Each One Costs, and What Escapes

The cost order is consistent across industries: preventing a defect costs less than detecting it, and detecting it costs far less than shipping it. The first two appear in a budget. The third appears in a recall notice, a regulator's letter, or a customer who does not return, and it is the only one large enough to be visible from outside the company.

The public record of escapes is substantial and growing. In the European Union, alerts through the rapid warning system rose 13 percent in 2025 to 4,671, the highest level on record, with a 35 percent increase in reported follow-up actions including withdrawals, recalls, border stops and removal of listings from online marketplaces. Cosmetics and toys accounted for over half of the reported cases. In the United Kingdom, 2,396 notifications were received on the product safety database between April 2025 and March 2026, covering 3,368 notified products, although the publishing body states plainly that the release does not support year-on-year comparison because market surveillance authorities do not yet use the database consistently.

In regulated sectors the same picture appears through enforcement rather than alerts. The United States Food and Drug Administration reported issuing 314 warning letters during 2025 and classifying 321 recall events covering 755 recalled products. Each of those figures is one jurisdiction and one regulator, so they are not a global defect rate. What they establish is that escapes are common enough to be counted annually, and that most of them began as a process nobody assured rather than as a unit nobody checked. A large share of them also originate outside the company that ships the product, which is why supplier quality management belongs to assurance rather than to incoming inspection.

How It Differs From Standards, Six Sigma and Audit

Three neighboring things get used as synonyms for quality assurance, and each is something else.

A Management System Standard Is a Requirement Set, Not the Work

A quality management system standard specifies what a framework must contain: documented processes, defined responsibilities, control of records, management review, action on nonconformity. Certification says an independent body found that framework present and functioning on the days it looked. It does not say the product is good, and it is not itself assurance. Assurance is what the organization does inside that framework every day, and a certificate obtained by writing procedures nobody follows is the standard failure mode. Teams implementing the framework properly generally treat ISO 9001 implementation as the scaffolding and the assurance activities as the thing being built.

Six Sigma Is an Improvement Methodology

Six Sigma is a structured way of reducing variation in a process that is already running, using data to find and remove causes. It overlaps with assurance because both work on the process, but it is a project-shaped intervention aimed at a defined problem rather than the standing set of controls that keeps ordinary work in order. An organization can run improvement projects and still have no assurance, and it can have solid assurance and no improvement program. A culture that carries both continuously is closer to what total quality management describes.

Internal Audit Checks Whether the Controls Exist and Work

Internal audit is independent assurance over the control environment, and its object is the organization's own arrangements rather than the product. A quality audit asks whether the documented process is being followed and whether it is capable; a product inspection asks whether this unit conforms. Both are useful and neither substitutes for the other. The distinction that matters in practice is independence: an audit function that reports to the manager whose area it audits is producing comfort rather than assurance, and the same principle applies whether the subject is quality, finance or safety. Embedding that thinking across operational risk is what operations risk management and quality assurance sets out to do.

How to Tell Which One Your Organization Is Actually Doing

The honest test is not what the department is called. It is where the effort goes and what happens after a defect is found.

Seven questions that separate assurance from control

  1. What happens after a defect is found? If the answer is that the unit is scrapped or reworked and the line continues, that is control operating alone.
  2. Is the acceptance criterion written down before the work starts? If it is agreed at the point of dispute, control has become negotiation.
  3. Who qualified the supplier, and against what? If the answer is incoming inspection, the qualification never happened.
  4. Can you show the current revision of the procedure in use on the floor? Document control is assurance in its plainest form.
  5. Are the instruments that decide pass and fail calibrated on a schedule? An uncalibrated gauge makes every control record meaningless.
  6. Is there a change-control step before a process is altered? Undocumented process change is the most common source of a sudden defect cluster.
  7. Does the same nonconformity appear more than twice? If it does, the organization is finding defects rather than removing their causes.

A useful rule when the two are being confused in a meeting: ask whether the activity would still be worth doing if this particular batch did not exist. If yes, it is assurance. If no, it is control.

Where Teams Build This Capability

Quality is learned best in mixed rooms, because the argument the subject exists to settle runs between the people who make the thing and the people who check it. Practitioners take this work in Vienna, Madrid, Dubai, Amman and Zurich, and the wider field sits under quality management, governance and audit.

Frequently Asked Questions

What is the difference between quality assurance and quality control?

Assurance works on the process before and during the work so that defects are less likely; control examines the output after it exists so that defects are caught before a customer sees them. Assurance includes specifications, supplier qualification, training, validation, change control and document control. Control includes inspection, testing, sampling and final review. The practical test is whether the activity would still be worth doing if this particular batch did not exist: if yes it is assurance, if no it is control. Both are necessary, and only assurance changes tomorrow's defect rate.

Is inspection the same as quality control?

Inspection is one method of quality control, not a synonym for it. Control also covers functional testing, statistical sampling, first-article verification, in-process measurement and final review, which differ in when they happen and how much of the population they cover. Inspection is simply the most visible of these, which is why it is often mistaken for the whole of quality. Treating it that way is expensive, because adding inspection steps produces sharply falling returns while leaving the rate at which defects are created completely unchanged.

Does an ISO certificate mean a company has quality assurance?

It means an independent body found a documented management system present and functioning on the days it looked. A management system standard specifies what the framework must contain: defined processes and responsibilities, control of records, management review, action on nonconformity. It does not certify the product, and the framework can be satisfied by procedures nobody follows, which is the standard failure mode. Certification is best read as evidence that the scaffolding exists. Whether assurance is actually being practiced inside it is a separate question, answered by looking at document control, calibration, competence records and what happens after a defect is found.

Can you inspect quality into a product?

No, and this is the single most useful idea in the subject. Sorting acceptable units from unacceptable ones does not change how many unacceptable ones get produced, so scrap and rework costs stay flat while inspection costs rise. A second check catches part of what the first missed and a third catches very little, which is why organizations that invest only in control improve quickly and then plateau. There is also a behavioral cost: when a separate function is visibly responsible for finding defects, the people doing the work stop treating quality as theirs.

Who should own quality assurance in an organization?

Ownership sits with the people who own the processes, supported rather than replaced by a quality function. A quality department that owns assurance outright becomes a bottleneck and is treated as an obstacle by everyone else, which is the condition in which procedures get written and ignored. The quality function's proper role is to define the framework, maintain the records that make it auditable, and hold the authority to stop work that does not meet the criteria. The engineering, production and procurement owners hold the rest, because they are the only ones who can actually change how the work is done.

Move the effort upstream, where it changes the defect rate

EuroQuest International runs practitioner training in quality assurance and control, quality management systems, and supplier quality across Europe, the Gulf and Asia.

Explore quality management and audit programs