Updated: 27th May 2026
Reviewed by: Alex Lewis BSc, BSI Qualified Lead Auditor (Quality Assurance Manager)
Quality Assurance vs Quality Control: Understanding the Difference
Quality Assurance (QA) and Quality Control (QC) are often used interchangeably, but they perform very different functions within a medical device Quality Management System (QMS). While both are essential for delivering safe, effective and compliant medical devices, they address quality from different perspectives.
Quality Assurance is a proactive, process-focused approach that aims to prevent quality issues before they occur. It establishes the systems, procedures and controls needed to ensure products are consistently designed and manufactured in accordance with ISO 13485 and regulatory requirements.
Quality Control, by contrast, is reactive and product-focused. It verifies that products meet defined specifications through inspection, testing and verification activities before they are released to customers.
Together, Quality Assurance and Quality Control form complementary parts of an effective Quality Management System. Understanding how they work together helps medical device manufacturers reduce risk, improve product quality and maintain compliance throughout the product lifecycle.
Why Understanding the Difference Matters
For medical device manufacturers, confusing Quality Assurance with Quality Control can lead to gaps within the Quality Management System. While Quality Control identifies defects after they occur, Quality Assurance focuses on preventing those defects by establishing robust processes, clear responsibilities and effective quality controls throughout the organisation.
Understanding the distinction enables organisations to:
- Build stronger Quality Management Systems.
- Reduce manufacturing defects and rework.
- Improve regulatory compliance.
- Simplify ISO 13485 certification audits.
- Improve patient safety.
- Reduce product recalls and complaints.
- Support continual improvement.
Organisations that successfully integrate both Quality Assurance and Quality Control are better positioned to consistently deliver safe, compliant and high-quality medical devices.
What is Quality Assurance?
Quality Assurance is the systematic process of ensuring that quality is built into every stage of the medical device lifecycle. Rather than detecting problems after they occur, QA focuses on establishing documented processes, responsibilities and controls that prevent quality issues from arising in the first place.
Within an ISO 13485 Quality Management System, Quality Assurance influences virtually every business process, including design and development, supplier management, production, validation, internal auditing, risk management and post-market surveillance.
Need a Complete Introduction to ISO 13485?
Quality Assurance and Quality Control both operate within a wider medical device Quality Management System. If you need a complete overview of the standard, including QMS requirements, certification, risk management, design controls, supplier management and continual improvement, read our Complete Guide to ISO 13485.
Typical Quality Assurance Activities
- Developing and maintaining the Quality Management System.
- Creating Standard Operating Procedures (SOPs).
- Risk management.
- Supplier qualification.
- Internal audits.
- CAPA management.
- Employee training.
- Document control.
- Management Review.
- Continual improvement.
Explore the Core Elements of an Effective Quality Management System
Quality Assurance and Quality Control are just two components of a successful Quality Management System. Discover how the core elements of a Quality Management System work together, including leadership, document control, risk management, design controls, supplier management, validation, CAPA, internal audits and continual improvement.
What is Quality Control?
Quality Control focuses on verifying that products meet predetermined specifications before they are released. Unlike Quality Assurance, which prevents defects through controlled processes, Quality Control identifies defects through inspection, testing and verification activities.
Quality Control provides objective evidence that products conform to design requirements and regulatory expectations before reaching patients or healthcare professionals.
Typical Quality Control Activities
- Incoming inspection.
- In-process inspection.
- Final product inspection.
- Product testing.
- Dimensional verification.
- Acceptance sampling.
- Laboratory testing.
- Release approval.
- Batch record review.
- Non-conforming product management.
Key Differences At a Glance
| Feature | Quality Assurance (QA) | Quality Control (QC) |
|---|---|---|
| Core Focus | The Process: Preventing defects before they happen. | The Product: Identifying defects after production. |
| Approach | Proactive and preventative. | Reactive and defensive. |
| Timing | Ongoing throughout the entire product lifecycle. | Conducted at specific milestones or post-production. |
| Goal | To improve development and testing processes so the device is consistently safe. | To identify and isolate specific non-conforming items before distribution. |
| Responsibility | Everyone involved in the lifecycle (Designers, Engineers, Regulatory, Management). | Dedicated QC inspectors, lab technicians, or automated testing software. |
| Key Standard | Dictated by ISO 13485 and FDA 21 CFR Part 820 QMS frameworks. | Executed via specific product testing standards (e.g., bioburden, electrical safety testing). |
Why Quality Assurance and Quality Control Work Together
Quality Assurance and Quality Control are not competing approaches—they are complementary components of an effective Quality Management System.
Quality Assurance establishes the documented processes that minimise the likelihood of quality issues occurring, while Quality Control verifies that those processes consistently produce products that meet specified requirements.
Without Quality Assurance, organisations continually react to recurring quality issues rather than preventing them. Without Quality Control, defects may remain undetected before products reach customers.
Medical device manufacturers that successfully integrate both disciplines benefit from:
- Improved product quality.
- Greater regulatory compliance.
- Reduced non-conformities.
- More efficient manufacturing.
- Increased customer confidence.
- Stronger audit performance.
Together, QA and QC support the continual improvement philosophy at the heart of ISO 13485.
QA vs. QC: Real-World Medical Device Examples
To truly understand how these concepts operate on the manufacturing floor or within a software engineering environment, let’s look at how they apply to specific medical device scenarios:
Example 1: Physical Hardware Manufacturing (e.g., orthopedic implants or syringes)
The QA Process: Your team designs a cleanroom environment, establishes a rigorous supplier qualification protocol for raw titanium, and drafts Standard Operating Procedures (SOPs) for machine calibration. You are setting up a system to ensure every implant is made perfectly.
The QC Action: A quality inspector pulls one out of every 50 finished implants from the assembly line. They measure its dimensions with a digital micrometer to ensure it meets tolerance specifications and run a laboratory bioburden test to check for microbial contamination before packaging.
Example 2: Medical Device Software (SaMD)
The QA Process: You establish a software development lifecycle (SDLC) compliant with IEC 62304. This includes enforcing mandatory peer code reviews, automated unit testing frameworks, and clear version control protocols before a single line of code is written.
The QC Action: Before a software update drops, a dedicated validation engineer executes a penetration test to find security vulnerabilities and runs manual beta-testing scripts to intentionally try and crash the user interface.
The Regulatory Perspective: Why Notified Bodies Care
Medical device regulations and international standards place a strong emphasis on both Quality Assurance and Quality Control. ISO 13485 requires manufacturers to establish documented processes that ensure consistent quality throughout the medical device lifecycle while maintaining appropriate inspection and verification activities.
Similarly, regulations such as the EU Medical Device Regulation (EU MDR 2017/745), UK Medical Devices Regulations 2002 (as amended) and FDA Quality Management System Regulation (QMSR) all expect manufacturers to demonstrate that quality is embedded within organisational processes and verified through appropriate quality control activities.
Rather than viewing QA and QC as separate functions, regulators expect manufacturers to operate an integrated Quality Management System where preventive quality planning, risk management, inspection, testing and continual improvement work together to protect patient safety.
The overarching organizational philosophy centered on long-term compliance and safety.
When an auditor reviews your technical documentation, they track the interplay between process and product:
1. The Audit Trail of a Failure
If a QC inspector catches a non-conforming batch of products (a QC event), the auditor will immediately look at your QA framework to find out why it happened. They will expect to see a logged CAPA (Corrective and Preventive Action) to update the manufacturing process so the error never repeats.
2. ISO 13485 Compliance
Clause 7 (Product Realization): This is heavily process-driven (QA). It requires you to plan the processes needed for product realization.
Clause 8 (Measurement, Analysis, and Improvement): This is where QC shines. It demands monitoring and measurement of the product characteristics to verify that product requirements have been met.
Auditor Mindset: A company with great QC but poor QA will constantly catch mistakes right before shipping, leading to high scrap rates and wasted revenue. A company with great QA but poor QC is blind—they assume their processes are perfect but have no physical proof that safe devices are leaving the building.
Ready for Your Next ISO 13485 Audit?
A strong Quality Assurance process and effective Quality Control activities are essential for successful ISO 13485 certification and surveillance audits. Read our ISO 13485 Audit Readiness Guide to discover what Certification Bodies look for, common audit findings and practical steps to help you pass with confidence.
Quality Assurance and Quality Control: Both Are Essential
Quality Assurance and Quality Control play distinct but equally important roles within an ISO 13485 Quality Management System. While Quality Assurance focuses on preventing defects through effective processes and continual improvement, Quality Control verifies that products consistently meet defined quality requirements before they are released.
Medical device manufacturers should never view Quality Assurance and Quality Control as alternatives. Instead, they should be implemented together as complementary components of a mature Quality Management System that supports regulatory compliance, product quality and patient safety.
By understanding how QA and QC work together, organisations can build stronger quality systems, reduce risk and demonstrate ongoing compliance with international regulatory requirements.
Build a Lean Quality Management System That Drives Continuous Improvement
Quality Assurance and Quality Control are most effective when supported by a streamlined, efficient Quality Management System. Learn how to build a lean ISO 13485 Quality Management System that reduces unnecessary bureaucracy, strengthens regulatory compliance, improves operational efficiency and keeps your organisation audit ready throughout the medical device lifecycle.
Frequently Asked Questions About QA and QC
Can a company have Quality Control without Quality Assurance?
Yes, but it is a highly inefficient and risky way to operate. A company with only QC will constantly catch defects right before shipping. This leads to high scrap rates, wasted engineering hours, expensive re-work, and a massive bottleneck in delivery. Without QA to fix the underlying processes, the same production mistakes will happen repeatedly.
Is ISO 13485 focused more on QA or QC?
While ISO 13485 covers both, it heavily prioritizes Quality Assurance (QA). The standard is designed to help you build a proactive Quality Management System (QMS) where management responsibility, resource allocation, design controls, and continuous improvement prevent product failures. QC acts as the measurement and verification tool required by Clause 8 of the standard to prove your QA systems are working.
Who is responsible for QA vs. QC in a medical device company?
QA is an organization-wide responsibility. While a QA Manager oversees the framework, everyone from design engineers and software developers to supply chain managers must follow the established SOPs.
QC is an execution-specific responsibility. It is typically performed by designated Quality Control inspectors, laboratory technicians, or automated testing protocols whose sole job is to evaluate the output against technical specifications.
How does QA/QC differ for Medical Device Software (SaMD)?
In Software as a Medical Device (SaMD), the line blurs slightly but the principles remain firm. Software QA involves setting up the compliant development lifecycle (like IEC 62304 frameworks), establishing coding standards, and scheduling peer reviews. Software QC involves the technical testing of the compiled build—such as automated unit testing, penetration testing for security vulnerabilities, and manual beta testing to verify features.
What happens during a BSI or MHRA audit if QA and QC are unbalanced?
If you have excellent QA but poor QC, auditors will flag you for failing to adequately verify your products (non-conformance under testing and measurement criteria). If you have excellent QC but poor QA, auditors will see a history of product defects and ask for your CAPA (Corrective and Preventive Action) logs. If you cannot prove that you are actively updating your processes to prevent those defects from happening again, you risk failing the audit.
Alex Lewis, BSc, Qualified Lead Auditor
Reviewed by
Alex Lewis, BSc
Quality Assurance Manager | ISO 13485 Lead Auditor
15+ years in medical device regulatory affairs, ISO 27001, ISO 9001, MDR/IVDR compliance and quality systems.
Patient Guards Recent Posts

10 Common Technical Documentation Deficiencies Found During EU MDR and IVDR Notified Body Reviews
Preparing technical documentation for EU MDR or IVDR certification is only half the challenge. Successfully passing a Notified Body review depends on demonstrating consistency across your Quality Management System, Clinical Evaluation, Risk Management, Biological Evaluation, Performance Evaluation and Post-Market Surveillance activities. Discover ten of the most common technical documentation deficiencies identified during MDR and IVDR conformity assessments—and learn how to reduce the likelihood of costly review cycles and certification delays.

EU Authorised Representative Services for Medical Device & IVD Manufacturers
Selling medical devices or IVDs in Europe? If your company is based outside the EU, appointing an EU Authorised Representative (EC Rep) is a legal requirement under EU MDR 2017/745 and IVDR 2017/746. Patient Guard provides expert EU Authorised Representative services, EUDAMED support, regulatory guidance, and ongoing compliance management to help manufacturers access and maintain the European market with confidence.

Predetermined Change Control Plans (PCCPs): The Future of Agile Compliance for Medical Device Software
Learn how PCCPs help medical device software manufacturers manage updates, support AI systems, and enable agile compliance under evolving MDR and UKCA frameworks.