Quality Assurance vs. Quality Control in Medical Devices

Don't confuse QA and QC in your QMS. Discover the critical differences between Quality Assurance and Quality Control under ISO 13485, and learn how balancing both protects your device and your next audit.
Patient Guard hero image illustrating the difference between Quality Assurance (QA) and Quality Control (QC) in medical devices, highlighting how both support ISO 13485 compliance, product quality and patient safety.

Updated: 27th May 2026

Reviewed by: Alex Lewis BSc, BSI Qualified Lead Auditor (Quality Assurance Manager)

Quality Assurance vs Quality Control: Understanding the Difference

Quality Assurance (QA) and Quality Control (QC) are often used interchangeably, but they perform very different functions within a medical device Quality Management System (QMS). While both are essential for delivering safe, effective and compliant medical devices, they address quality from different perspectives.

Quality Assurance is a proactive, process-focused approach that aims to prevent quality issues before they occur. It establishes the systems, procedures and controls needed to ensure products are consistently designed and manufactured in accordance with ISO 13485 and regulatory requirements.

Quality Control, by contrast, is reactive and product-focused. It verifies that products meet defined specifications through inspection, testing and verification activities before they are released to customers.

Together, Quality Assurance and Quality Control form complementary parts of an effective Quality Management System. Understanding how they work together helps medical device manufacturers reduce risk, improve product quality and maintain compliance throughout the product lifecycle.

Why Understanding the Difference Matters

For medical device manufacturers, confusing Quality Assurance with Quality Control can lead to gaps within the Quality Management System. While Quality Control identifies defects after they occur, Quality Assurance focuses on preventing those defects by establishing robust processes, clear responsibilities and effective quality controls throughout the organisation.

Understanding the distinction enables organisations to:

  • Build stronger Quality Management Systems.
  • Reduce manufacturing defects and rework.
  • Improve regulatory compliance.
  • Simplify ISO 13485 certification audits.
  • Improve patient safety.
  • Reduce product recalls and complaints.
  • Support continual improvement.

Organisations that successfully integrate both Quality Assurance and Quality Control are better positioned to consistently deliver safe, compliant and high-quality medical devices.

What is Quality Assurance?

Quality Assurance is the systematic process of ensuring that quality is built into every stage of the medical device lifecycle. Rather than detecting problems after they occur, QA focuses on establishing documented processes, responsibilities and controls that prevent quality issues from arising in the first place.

Within an ISO 13485 Quality Management System, Quality Assurance influences virtually every business process, including design and development, supplier management, production, validation, internal auditing, risk management and post-market surveillance.

Typical Quality Assurance Activities

  • Developing and maintaining the Quality Management System.
  • Creating Standard Operating Procedures (SOPs).
  • Risk management.
  • Supplier qualification.
  • Internal audits.
  • CAPA management.
  • Employee training.
  • Document control.
  • Management Review.
  • Continual improvement.

What is Quality Control?

Quality Control focuses on verifying that products meet predetermined specifications before they are released. Unlike Quality Assurance, which prevents defects through controlled processes, Quality Control identifies defects through inspection, testing and verification activities.

Quality Control provides objective evidence that products conform to design requirements and regulatory expectations before reaching patients or healthcare professionals.

Typical Quality Control Activities

  • Incoming inspection.
  • In-process inspection.
  • Final product inspection.
  • Product testing.
  • Dimensional verification.
  • Acceptance sampling.
  • Laboratory testing.
  • Release approval.
  • Batch record review.
  • Non-conforming product management.

Key Differences At a Glance

Feature Quality Assurance (QA) Quality Control (QC)
Core Focus The Process: Preventing defects before they happen. The Product: Identifying defects after production.
Approach Proactive and preventative. Reactive and defensive.
Timing Ongoing throughout the entire product lifecycle. Conducted at specific milestones or post-production.
Goal To improve development and testing processes so the device is consistently safe. To identify and isolate specific non-conforming items before distribution.
Responsibility Everyone involved in the lifecycle (Designers, Engineers, Regulatory, Management). Dedicated QC inspectors, lab technicians, or automated testing software.
Key Standard Dictated by ISO 13485 and FDA 21 CFR Part 820 QMS frameworks. Executed via specific product testing standards (e.g., bioburden, electrical safety testing).

Why Quality Assurance and Quality Control Work Together

Quality Assurance and Quality Control are not competing approaches—they are complementary components of an effective Quality Management System.

Quality Assurance establishes the documented processes that minimise the likelihood of quality issues occurring, while Quality Control verifies that those processes consistently produce products that meet specified requirements.

Without Quality Assurance, organisations continually react to recurring quality issues rather than preventing them. Without Quality Control, defects may remain undetected before products reach customers.

Medical device manufacturers that successfully integrate both disciplines benefit from:

  • Improved product quality.
  • Greater regulatory compliance.
  • Reduced non-conformities.
  • More efficient manufacturing.
  • Increased customer confidence.
  • Stronger audit performance.

Together, QA and QC support the continual improvement philosophy at the heart of ISO 13485.

Patient Guard infographic comparing Quality Assurance (QA) and Quality Control (QC) within an ISO 13485 Quality Management System, highlighting the differences in focus, objectives, activities and how both work together to ensure medical device quality and regulatory compliance.

QA vs. QC: Real-World Medical Device Examples

To truly understand how these concepts operate on the manufacturing floor or within a software engineering environment, let’s look at how they apply to specific medical device scenarios:

Example 1: Physical Hardware Manufacturing (e.g., orthopedic implants or syringes)

  • The QA Process: Your team designs a cleanroom environment, establishes a rigorous supplier qualification protocol for raw titanium, and drafts Standard Operating Procedures (SOPs) for machine calibration. You are setting up a system to ensure every implant is made perfectly.

  • The QC Action: A quality inspector pulls one out of every 50 finished implants from the assembly line. They measure its dimensions with a digital micrometer to ensure it meets tolerance specifications and run a laboratory bioburden test to check for microbial contamination before packaging.

Example 2: Medical Device Software (SaMD)

  • The QA Process: You establish a software development lifecycle (SDLC) compliant with IEC 62304. This includes enforcing mandatory peer code reviews, automated unit testing frameworks, and clear version control protocols before a single line of code is written.

  • The QC Action: Before a software update drops, a dedicated validation engineer executes a penetration test to find security vulnerabilities and runs manual beta-testing scripts to intentionally try and crash the user interface.

The Regulatory Perspective: Why Notified Bodies Care

Medical device regulations and international standards place a strong emphasis on both Quality Assurance and Quality Control. ISO 13485 requires manufacturers to establish documented processes that ensure consistent quality throughout the medical device lifecycle while maintaining appropriate inspection and verification activities.

Similarly, regulations such as the EU Medical Device Regulation (EU MDR 2017/745), UK Medical Devices Regulations 2002 (as amended) and FDA Quality Management System Regulation (QMSR) all expect manufacturers to demonstrate that quality is embedded within organisational processes and verified through appropriate quality control activities.

Rather than viewing QA and QC as separate functions, regulators expect manufacturers to operate an integrated Quality Management System where preventive quality planning, risk management, inspection, testing and continual improvement work together to protect patient safety.

Total Quality Management (TQM)

The overarching organizational philosophy centered on long-term compliance and safety.

Quality Assurance (QA) Process-Oriented
Process Design SOPs & Work Instructions Staff Training Supplier Audits
Quality Control (QC) Product-Oriented
Batch Testing Visual Inspections Lab Verifications Product Audits

When an auditor reviews your technical documentation, they track the interplay between process and product:

1. The Audit Trail of a Failure

If a QC inspector catches a non-conforming batch of products (a QC event), the auditor will immediately look at your QA framework to find out why it happened. They will expect to see a logged CAPA (Corrective and Preventive Action) to update the manufacturing process so the error never repeats.

2. ISO 13485 Compliance

  • Clause 7 (Product Realization): This is heavily process-driven (QA). It requires you to plan the processes needed for product realization.

  • Clause 8 (Measurement, Analysis, and Improvement): This is where QC shines. It demands monitoring and measurement of the product characteristics to verify that product requirements have been met.

Auditor Mindset: A company with great QC but poor QA will constantly catch mistakes right before shipping, leading to high scrap rates and wasted revenue. A company with great QA but poor QC is blind—they assume their processes are perfect but have no physical proof that safe devices are leaving the building.

Quality Assurance and Quality Control: Both Are Essential

Quality Assurance and Quality Control play distinct but equally important roles within an ISO 13485 Quality Management System. While Quality Assurance focuses on preventing defects through effective processes and continual improvement, Quality Control verifies that products consistently meet defined quality requirements before they are released.

Medical device manufacturers should never view Quality Assurance and Quality Control as alternatives. Instead, they should be implemented together as complementary components of a mature Quality Management System that supports regulatory compliance, product quality and patient safety.

By understanding how QA and QC work together, organisations can build stronger quality systems, reduce risk and demonstrate ongoing compliance with international regulatory requirements.

Frequently Asked Questions About QA and QC

Yes, but it is a highly inefficient and risky way to operate. A company with only QC will constantly catch defects right before shipping. This leads to high scrap rates, wasted engineering hours, expensive re-work, and a massive bottleneck in delivery. Without QA to fix the underlying processes, the same production mistakes will happen repeatedly.

While ISO 13485 covers both, it heavily prioritizes Quality Assurance (QA). The standard is designed to help you build a proactive Quality Management System (QMS) where management responsibility, resource allocation, design controls, and continuous improvement prevent product failures. QC acts as the measurement and verification tool required by Clause 8 of the standard to prove your QA systems are working.

  • QA is an organization-wide responsibility. While a QA Manager oversees the framework, everyone from design engineers and software developers to supply chain managers must follow the established SOPs.

  • QC is an execution-specific responsibility. It is typically performed by designated Quality Control inspectors, laboratory technicians, or automated testing protocols whose sole job is to evaluate the output against technical specifications.

In Software as a Medical Device (SaMD), the line blurs slightly but the principles remain firm. Software QA involves setting up the compliant development lifecycle (like IEC 62304 frameworks), establishing coding standards, and scheduling peer reviews. Software QC involves the technical testing of the compiled build—such as automated unit testing, penetration testing for security vulnerabilities, and manual beta testing to verify features.

If you have excellent QA but poor QC, auditors will flag you for failing to adequately verify your products (non-conformance under testing and measurement criteria). If you have excellent QC but poor QA, auditors will see a history of product defects and ask for your CAPA (Corrective and Preventive Action) logs. If you cannot prove that you are actively updating your processes to prevent those defects from happening again, you risk failing the audit.

References

This guide is based on the following international standards and official guidance relating to Quality Assurance (QA), Quality Control (QC) and Quality Management Systems (QMS) for medical devices.

Organisation Reference Why it's relevant
International Organization for Standardization (ISO) ISO 13485:2016 – Medical Devices – Quality Management Systems – Requirements for Regulatory Purposes Defines the internationally recognised Quality Management System requirements that integrate Quality Assurance and Quality Control throughout the medical device lifecycle.
International Organization for Standardization (ISO) ISO 14971:2019 – Medical Devices – Application of Risk Management to Medical Devices Provides the internationally recognised framework for integrating risk management into Quality Management Systems, supporting proactive Quality Assurance activities and continual improvement.
American Society for Quality (ASQ) Quality Assurance vs. Quality Control Provides a widely recognised explanation of the differences between Quality Assurance and Quality Control, including their respective roles within a Quality Management System.
U.S. Food and Drug Administration (FDA) Quality Management System Regulation (QMSR) Explains the FDA's Quality Management System Regulation and reinforces the importance of integrated Quality Management Systems that encompass both Quality Assurance and Quality Control.

Quality management standards and regulatory expectations continue to evolve. Organisations should always consult the latest published standards and official guidance when developing, implementing and maintaining Quality Assurance and Quality Control processes for medical devices.

Alex Lewis, BSc, Qualified Lead Auditor

Alex Lewis, BSc, Qualified Lead Auditor

Reviewed by
Alex Lewis, BSc
Quality Assurance Manager | ISO 13485 Lead Auditor
15+ years in medical device regulatory affairs, ISO 27001, ISO 9001, MDR/IVDR compliance and quality systems.

Patient Guards Recent Posts

Cosmetic Product Safety Report (CPSR): A Complete Guide to UK Cosmetic Compliance

Before a cosmetic product can legally be placed on the UK market, manufacturers and Responsible Persons must demonstrate that it is safe for human use under normal or reasonably foreseeable conditions. The Cosmetic Product Safety Report (CPSR) is one of the most important regulatory documents required under the UK Cosmetics Regulation. This guide explains what a CPSR is, who can prepare one, what information it must contain, how it relates to the Product Information File (PIF) and how it supports legal cosmetic compliance.

Read More »

IVDR PMPF Explained: A Complete Guide to Post-Market Performance Follow-up

Post-Market Performance Follow-up (PMPF) is a fundamental requirement under the EU In Vitro Diagnostic Regulation (IVDR), ensuring that manufacturers continually monitor the scientific validity, analytical performance and clinical performance of their in vitro diagnostic medical devices after CE marking. This guide explains IVDR PMPF requirements, PMPF Plans, PMPF Reports, Annex XIII expectations and how ongoing performance monitoring supports continued regulatory compliance throughout the device lifecycle.

Read More »

IVDR Scientific Validity Explained: A Complete Guide for Manufacturers

Scientific Validity is the first pillar of IVDR Performance Evaluation and provides the scientific foundation demonstrating that an analyte or biomarker is associated with a specific clinical condition or physiological state. This guide explains Scientific Validity under Regulation (EU) 2017/746, including literature reviews, Scientific Validity Reports, Annex XIII requirements, evidence appraisal and how Scientific Validity supports successful CE marking.

Read More »

Patient Guards Related Services

Patient Guards Regulatory Tools

Check out Patient Guards Training Courses

Share this guide:
Posted on Google Google
Munna P profile picture
Munna P
51 days ago
Google star 1Google star 2Google star 3Google star 4Google star 5Trustindex verifies that the original source of the review is Google.
Working with the Patient Guard team has been a great experience throughout our MHRA and ISO 13485 documentation journey. Their expertise, structured approach, and practical guidance helped our team build a robust quality management system while keeping us aligned with regulatory expectations. The collaboration was professional, responsive, and focused on finding solutions rather than simply identifying issues. A special thank you to Alex and Steve for their outstanding coordination, responsiveness, and continuous support throughout the project. They were always approachable, provided valuable feedback, and worked closely with our team to resolve challenges efficiently. Their commitment made a significant difference in keeping our documentation effort on track. I highly recommend Patient Guard to any healthcare or MedTech organization looking for experienced regulatory and quality system partners for MHRA, ISO 13485, and broader medical device compliance initiatives. Thank you again to the entire Patient Guard team for being such reliable partners.
Posted on Google Google
Peter Reeve profile picture
Peter Reeve
78 days ago
Google star 1Google star 2Google star 3Google star 4Google star 5Trustindex verifies that the original source of the review is Google.
STEPPER design, manufacture & distribute eyewear across the globe. With the increasingly complex landscape concerning the placing of Mecial Devices onto the market, we realised we needed professional guidance. We found Patient Guard via a simple internet search and are delighted we did! They provide a pragmatic solution to our needs, are totally reliable & always available to answer our (often simplistic) questions. They are highly efficient & responsive to what is a changing picture in our world and nothing is too much trouble. We have a much better understanding of regulatory affairs and our responsibilities as manufacturers & distributors and they support us in navigating the requirements in different territories. Updating our Declaration of Conformity, ensuring our labelling is compliant and acting as our PRRC are the key areas of their service for us.
Posted on Google Google
Derek Timm profile picture
Derek Timm
78 days ago
Google star 1Google star 2Google star 3Google star 4Google star 5Trustindex verifies that the original source of the review is Google.
For those companıes lookıng to comply to ISO standards and ın partıcular ISO13485 whıch to be honest ıs a nıghtmare I would strongly suggest goıng to the professıonals as ındeed we dıd by joınıng forces wıth Patıent Guard Ltd The staff are fantastıc nothıng ıs too much trouble and as a medıcal supply company we sımply cannot lıve wıthout them Thanks ın partıcular to Alex and Steve for all the hard work and our best regards from Dan Medıca South Lımıted
Posted on Google Google
BMSCriticalCare profile picture
BMSCriticalCare
115 days ago
Google star 1Google star 2Google star 3Google star 4Google star 5Trustindex verifies that the original source of the review is Google.
Great service, very helpful and always willing to answer any questions we have,
Posted on Google Google
Thomson Software profile picture
Thomson Software
786 days ago
Google star 1Google star 2Google star 3Google star 4Google star 5Trustindex verifies that the original source of the review is Google.
Alex Lewis of PatientGuard guided us through the ISO13485 process in a thorough, systematic and efficient manner. He was friendly, patient and willing to go the extra mile. Excellent service.
Verified by Trustindex
Trustindex verified badge is the Universal Symbol of Trust. Only the greatest companies can get the verified badge who has a review score above 4.5, based on customer reviews over the past 12 months. Read more

Most Popular

Cosmetic Product Safety Report (CPSR): A Complete Guide to UK Cosmetic Compliance

Before a cosmetic product can legally be placed on the UK market, manufacturers and Responsible Persons must demonstrate that it is safe for human use under normal or reasonably foreseeable conditions. The Cosmetic Product Safety Report (CPSR) is one of the most important regulatory documents required under the UK Cosmetics Regulation. This guide explains what a CPSR is, who can prepare one, what information it must contain, how it relates to the Product Information File (PIF) and how it supports legal cosmetic compliance.

Read More »

IVDR PMPF Explained: A Complete Guide to Post-Market Performance Follow-up

Post-Market Performance Follow-up (PMPF) is a fundamental requirement under the EU In Vitro Diagnostic Regulation (IVDR), ensuring that manufacturers continually monitor the scientific validity, analytical performance and clinical performance of their in vitro diagnostic medical devices after CE marking. This guide explains IVDR PMPF requirements, PMPF Plans, PMPF Reports, Annex XIII expectations and how ongoing performance monitoring supports continued regulatory compliance throughout the device lifecycle.

Read More »

IVDR Scientific Validity Explained: A Complete Guide for Manufacturers

Scientific Validity is the first pillar of IVDR Performance Evaluation and provides the scientific foundation demonstrating that an analyte or biomarker is associated with a specific clinical condition or physiological state. This guide explains Scientific Validity under Regulation (EU) 2017/746, including literature reviews, Scientific Validity Reports, Annex XIII requirements, evidence appraisal and how Scientific Validity supports successful CE marking.

Read More »

IVDR Performance Evaluation Explained: A Complete Guide for Manufacturers

Performance Evaluation is one of the most important requirements under the EU In Vitro Diagnostic Regulation (IVDR). Every manufacturer must demonstrate that their in vitro diagnostic medical device achieves its intended purpose through robust scientific validity, analytical performance and clinical performance evidence. This guide explains every stage of IVDR Performance Evaluation, including Performance Evaluation Plans (PEPs), Performance Evaluation Reports (PERs), Post-Market Performance Follow-up (PMPF) and how Performance Evaluation supports successful CE marking under Regulation (EU) 2017/746.

Read More »
patient guard
Patient Guard

Sign up to our newsletter

Be the first to hear industry news and how Patient Guard can help you.

Get the latest updates on medical device regulation

Sign up to our newsletter and we’ll deliver news and insights straight to your inbox.

Get the Medical Device Technical Checklist

Thank you! The checklist is now ready to download.