11.2 Quality Assurance vs Quality Control
Key Takeaways
- BoK7 defines assurance as the process of providing confidence to stakeholders that projects, programmes and portfolios will achieve their objectives and realise their benefits — for quality, that means confidence the project will satisfy the relevant quality standards.
- BoK7 defines quality control as inspection, measurement and testing to verify that the project outputs meet the acceptance criteria defined during quality planning.
- QA is executed through independent audits, compliance reviews, and peer checks, typically conducted by PMO or quality personnel outside the immediate delivery team.
- QC is performed directly by the project delivery team, technical specialists, and testers using unit tests, physical inspections, non-destructive evaluations, and snagging lists.
- The Cost of Quality (CoQ) balances conformance costs (prevention and appraisal) against non-conformance costs (internal and external failures), proving that upfront prevention is vastly cheaper than post-handover remediation.
11.2 Quality Assurance vs Quality Control
Definition (APM BoK7 glossary): Assurance is the process of providing confidence to stakeholders that projects, programmes and portfolios will achieve their objectives for beneficial change. Applied to quality, the purpose of quality assurance is to provide confidence that the project will satisfy the relevant quality standards. BoK7 (2.2.4) adds that assurance "focuses on ensuring that the governance, processes and controls that are planned are fit for purpose, and that they are implemented as planned", and that "assurance is not a decision-making function in its own right".
Quality control "consists of inspection, measurement and testing to verify that the project outputs meet the acceptance criteria defined during quality planning". BoK7 sums up the pairing in Figure 4.1.5 with two labels worth memorising: quality control is "verifying compliance"; quality assurance is "providing confidence".
A cornerstone of the APM Project Fundamentals Qualification (PFQ) syllabus is the ability to clearly distinguish between Quality Assurance (QA) and Quality Control (QC) (Learning Outcome 8, Assessment Criteria 8.4 and 8.5). Although practitioners often blur the two terms in casual workplace conversation—frequently treating them as interchangeable—they represent fundamentally distinct, complementary disciplines within quality management.
Understanding their differences in focus, objectives, orientation, timing, and execution is essential for effective project governance and for securing full marks on the PFQ examination.
Quality Assurance (QA): The Proactive, Process Focus
Quality Assurance is process-oriented, proactive, and preventative. Its primary mission is to provide confidence to the project sponsor, governance board, client, and wider stakeholders that the project's management systems, delivery processes, and workflows are robust, appropriate, and being executed correctly so that the final outputs will fulfill quality requirements.
Key Characteristics of Quality Assurance:
- Focus on Processes: QA does not examine individual physical or digital deliverables; instead, it investigates the processes, management systems, workflows, and procedures being used to create those deliverables.
- Proactive and Preventative: QA aims to prevent defects from occurring in the first place by ensuring that best practices are followed, staff are appropriately trained, tools are calibrated, and governance protocols are adhered to.
- Independent Execution: To maintain credibility and objectivity, QA is typically performed by individuals or entities independent of the immediate project delivery team. This includes the Project Management Office (PMO), internal quality assurance departments, external quality auditors, or third-party certifying bodies.
- Stakeholder Confidence: By verifying that sound processes are being systematically followed, QA provides executive leadership and the Project Sponsor with documented confidence that the project is capable of delivering acceptable outputs.
Core Techniques Deployed in Quality Assurance:
- Quality Audits: Formal, structured examinations of project processes to evaluate whether activities comply with organisational policies, the quality plan and contractual commitments. BoK7 states the key principle plainly: "the auditor is independent of the area being audited." Auditors are commonly deployed from a PMO, a wider internal audit function, or a third party.
- Process Compliance Reviews: Checking that the project team is following agreed change control, risk management, design validation, and configuration procedures.
- Peer Reviews: Independent subject matter experts examining engineering design methodologies and calculation workflows before physical construction or coding begins.
- Supplier Capability Assessments: Evaluating external vendors' quality management systems (such as ISO 9001 certifications) to ensure they possess the process maturity to deliver quality components.
Quality Control (QC): The Detective, Product Focus
Quality Control is product-oriented, reactive, and detective. Its primary mission is to inspect, test, measure, and verify the specific physical, technical, or digital deliverables produced by the project to detect errors, deviations, and non-conformances before they are released or handed over to the customer.
Key Characteristics of Quality Control:
- Focus on Deliverables (Products): QC evaluates the tangible outputs of the project—the code modules, physical structures, machinery, documentation, or operational systems.
- Reactive and Detective: QC operates by evaluating work that has already been performed or produced. BoK7 notes it "is focused on preventing problems being passed on to the internal or external customer", and that "configuration control of specifications and test plans is vital so that any modifications are formally authorised, coordinated and communicated".
- Executed by Delivery Teams: QC is carried out directly by the project delivery team, technical engineers, software testers, laboratory technicians, and site inspectors who are actively producing the work.
- Binary Evaluation (Pass / Fail): QC measures outputs against pre-defined acceptance criteria and technical tolerances established during quality planning. The outcome of a QC check is fundamentally binary: the deliverable either conforms to specification (Pass) or fails (Non-conformance requiring rework, repair, or scrap).
Core Techniques Deployed in Quality Control:
- Physical Inspections and Walkthroughs: Visual examinations of construction works, welds, mechanical assemblies, or finished surfaces against architectural and engineering blueprints.
- Software Testing: Executing unit tests, integration tests, automated regression test suites, system performance tests, and user acceptance testing (UAT).
- Destructive and Non-Destructive Testing (NDT): Stress-testing physical components to failure (destructive) or using ultrasound, radiography, and magnetic particle testing (non-destructive) to detect internal structural cracks without damaging the asset.
- Snagging / Punch Lists: Cataloging minor defects, omissions, and cosmetic imperfections on site that the contractor must rectify prior to formal handover and occupancy.
Comprehensive Comparison: Quality Assurance vs. Quality Control
The following table provides a comprehensive, multi-dimensional comparison between QA and QC aligned with APM BoK7:
| Evaluation Dimension | Quality Assurance (QA) | Quality Control (QC) |
|---|---|---|
| Core Focus | Process-oriented (Focuses on the management systems and delivery procedures). | Product-oriented (Focuses on the tangible deliverables and finished outputs). |
| Primary Objective | To prevent defects and provide confidence that requirements will be fulfilled. | To identify defects and verify that deliverables meet specific technical requirements. |
| Orientation & Nature | Proactive and preventative; designs quality into processes before mistakes occur. | Reactive and detective; inspects completed work to catch errors before handover. |
| Executed By | Independent reviewers, internal PMO, corporate quality managers, or external auditors. | Project delivery team, technical engineers, software testers, and site inspectors. |
| Core Techniques | Quality audits, process compliance reviews, maturity assessments, peer checks. | Unit testing, physical inspections, load testing, non-destructive testing, snagging. |
| Timing Across Lifecycle | Continuous and recurring throughout all phases of the project life cycle. | Event-driven and milestone-based; occurs as deliverables and work packages complete. |
| Primary Output | Audit reports, process improvement recommendations, assurance statements. | Test logs, defect tracking registers, snagging lists, signed inspection certificates. |
| Underlying Philosophy | "Are we following the right processes in the right way to deliver quality?" | "Does this specific deliverable satisfy its agreed specifications and tolerances?" |
The Cost of Quality (CoQ) Framework
A critical concept linking quality planning, QA, and QC is the Cost of Quality (CoQ). Originating in the pioneering work of quality theorists Philip Crosby, Joseph Juran, and Armand Feigenbaum, and embedded in APM BoK7, the Cost of Quality represents the total financial investment an organization makes to prevent, detect, and remediate defects.
The Cost of Quality is divided into two broad categories: Cost of Conformance and Cost of Non-Conformance.
+-----------------------------------------------------------------------------------------+
| THE COST OF QUALITY (CoQ) |
+-----------------------------------------------------------------------------------------+
| COST OF CONFORMANCE | COST OF NON-CONFORMANCE |
| (Money spent to achieve quality) | (Money spent because of failure) |
+------------------------------------------------+----------------------------------------+
| PREVENTION COSTS | APPRAISAL COSTS | INTERNAL FAILURES | EXTERNAL FAILURES|
| - Quality planning - QC testing & labs - Scrapping bad work - Warranty claims |
| - Staff training - Inspections - Rework & redesign - Product recalls |
| - Process design - Equipment calibration - Retesting flawed - Legal penalties |
| - Vendor evaluation - Independent audits deliverables - Lost reputation |
+-----------------------------------------------------------------------------------------+
1. Cost of Conformance (Investing in Success)
The Cost of Conformance includes all monies spent throughout the project life cycle to ensure that deliverables conform to requirements and avoid failure:
- Prevention Costs: Monies invested in proactively designing processes to avoid defects. Examples include: drafting the Quality Management Plan, training project staff on new engineering tools, supplier vetting, and conducting design reviews.
- Appraisal Costs: Monies spent evaluating, measuring, and testing deliverables and processes to verify compliance. Examples include: conducting software test cycles, hiring non-destructive testing apparatus, calibrating precision gauges, and paying independent QA auditors.
2. Cost of Non-Conformance (The Price of Failure)
The Cost of Non-Conformance includes all financial expenditures resulting from poor quality and defective deliverables:
- Internal Failure Costs: Costs incurred when defects are caught and fixed before the deliverable is handed over to the client or customer. Examples include: scrapping substandard manufactured parts, rewriting defective software code, repairing misaligned concrete shuttering, and conducting secondary retesting.
- External Failure Costs: Costs incurred when defects escape project testing and are discovered by the client, customer, or public after delivery and operational handover. Examples include: processing customer warranty claims, funding mandatory product recalls, paying contractually enforced liquidated damages, settling liability lawsuits, and enduring long-term brand and reputational damage.
The 1-10-100 Rule (The Rule of Ten)
In quality economics, the 1-10-100 Rule illustrates the compounding penalty of delaying defect detection:
- Spending $1 on prevention (robust quality planning and staff training) avoids spending:
- $10 on internal appraisal and rework (catching and fixing a defect during project testing), which in turn avoids spending:
- $100 (or more) on external failure (resolving a catastrophic operational failure in the field after commercial release).
Quality Assurance and Quality Control are not overhead burdens; they are essential commercial safeguards that protect project investments and ensure operational viability.
Which of the following activities is an example of Quality Assurance rather than Quality Control?
What is the primary operational distinction between Quality Assurance (QA) and Quality Control (QC) according to APM BoK7?
Under the Cost of Quality (CoQ) framework, how are customer warranty claims, product recalls, and contractual liquidated damages categorized?