Resources · Quality management

Quality management: a practical guide

Quality management is the coordinated set of activities an organisation uses to make sure its products and services consistently meet requirements and keep getting better.

Quality management is how an organisation makes good outcomes repeatable rather than lucky. It joins up the way you set requirements, the way you check work against them, and the way you respond when something falls short, so that the same problem does not keep coming back. Done well, it is less about paperwork and more about a steady habit of noticing, fixing and learning.

This guide explains what quality management actually involves, untangles the terms people use interchangeably, and shows how reporting and dashboards turn a quality system from a folder of documents into something that improves the work week by week. It is written for quality leads, operations managers and anyone who has inherited a quality system and wants to understand what good looks like.

What is quality management?

Quality management is the set of activities that direct and control an organisation in relation to quality. In plain terms, it is everything you do to make sure that what you deliver meets the requirements your customers, regulators and your own standards have set, and that it does so consistently.

It is usually described as having a few connected parts: setting a quality policy and objectives, planning how you will meet them, controlling the work as it happens, assuring yourself that the controls are working, and improving the system over time. The international reference point for this is ISO 9001, which frames the whole thing around understanding customer requirements, managing your processes and using evidence to improve. The important idea is that quality is a property of your processes, not a final inspection bolted on at the end. If the process is sound, good output follows. If it is not, no amount of checking at the door will save you.

Quality management is the work of making good outcomes repeatable: define what “good” means, build processes that deliver it, check honestly, and act on what you find.

Quality management vs quality assurance vs quality control

These three terms are often used as if they mean the same thing. They do not, and keeping them apart makes the whole subject clearer. Quality management is the umbrella. Quality assurance and quality control sit underneath it and do different jobs.

TermWhat it isThe question it answersExample
Quality management (QM)The whole coordinated system for directing quality across the organisationHow do we make quality consistent and improving?A quality policy, objectives, audits, the improvement loop, leadership ownership
Quality assurance (QA)The proactive activities that build confidence requirements will be metAre our processes set up to produce good work?Process design, training, supplier approval, document control, internal audits
Quality control (QC)The reactive checks that detect problems in actual outputDid this specific thing meet the spec?Inspection, testing, measurement, sampling a batch before it ships

The shorthand many people use is that quality assurance is about preventing defects and quality control is about detecting them. Assurance asks whether the process is right; control asks whether the product is right. You need both, but a mature quality system leans on assurance, because catching problems early in the process is cheaper and kinder than catching them at the end. Quality management is the layer that connects the two and makes sure the lessons from control feed back into assurance.

What is a non-conformance, and what is a defect?

A non-conformance is any failure to meet a requirement. A defect is a non-conformance in a product or service that affects its intended use. The two overlap, but a non-conformance is the broader idea: it can be a missing signature on a record, a process step done out of order, or a part that is out of tolerance. A defect specifically means the thing does not do what it is supposed to do.

The distinction matters because it shapes your response. A documentation non-conformance might need a corrected record and a tweak to a checklist. A safety-critical defect might need the affected stock quarantined, customers notified and a full investigation. What both have in common is that they are signals. Logged consistently, they tell you where your processes are weak and which problems keep returning. Captured nowhere, they are just bad days that nobody learns from. For a fuller treatment, see what a non-conformance is, with types and examples.

The CAPA loop: corrective and preventive action

CAPA stands for corrective and preventive action, and it is the engine of improvement in most quality systems. A corrective action deals with a problem that has already happened and stops it recurring. A preventive action deals with a problem that has not happened yet but could, based on a trend or a risk you have spotted. Both go beyond the quick fix.

The crucial discipline in CAPA is separating the immediate fix from the underlying cause. If a customer receives the wrong part, the correction is to send the right one. The corrective action is to find out why the wrong part was picked and change the process so it cannot happen the same way again. Skipping straight to “we told the operator to be more careful” is the most common reason the same non-conformance reappears three months later. A proper loop runs: contain the problem, investigate the root cause, decide and implement an action, then verify that the action actually worked before you close it. We cover the full method, with a step table and worked examples, in CAPA explained.

Internal audits: checking the system honestly

An internal quality audit is a planned, independent check that your processes are being followed and are working. It is carried out by people from inside the organisation, but ideally not by the people who own the process being audited, so the look is fair. The point is not to catch individuals out. It is to find the gaps between how work is supposed to happen and how it actually happens, while there is still time to fix them quietly.

ISO 9001 requires internal audits at planned intervals, and there is a practical reason beyond the standard: an audit is one of the few moments where you deliberately go looking for problems instead of waiting for them to find you. A good audit produces clear findings, each with an owner and a date, and those findings feed straight into the CAPA loop. A weak audit produces a tidy report that nobody reads. The difference is almost entirely in what happens to the findings afterwards. For how to run and prepare for one, see internal quality audits.

ISO 9001 in plain terms

ISO 9001 is the world’s most widely used standard for quality management systems, published by the International Organization for Standardization. It sets out requirements for how an organisation should manage quality, and it can be independently certified. You do not have to be certified to use it. Many organisations follow its structure simply because it is sensible.

Stripped of jargon, ISO 9001 asks you to do a handful of connected things: understand who your customers and interested parties are and what they need; have leadership genuinely own quality rather than delegate it; identify your processes and the risks to them; resource and run those processes properly; check performance with evidence, including internal audits and management review; and improve continually, often described as the Plan-Do-Check-Act cycle. The standard is deliberately broad so it can fit a software firm, a food manufacturer or a hospital. The detail of how you meet each requirement is left to you. That flexibility is the point, and it is also why two certified organisations can look very different.

A common misconception is that ISO 9001 guarantees a high-quality product. It does not. It gives you a consistent, evidence-based system for managing quality, which makes good output far more likely and far more repeatable. The quality of what you actually make still depends on the standards you set and the seriousness with which you run the loop.

How reporting and dashboards support a quality system

A quality system runs on the records it captures, so the easier those records are to create, the better the system works. This is where structured digital reporting changes things. When anyone on the line can log a non-conformance or a defect in seconds, on a phone, with a photo, you capture far more of what is really happening than a paper form pinned to a noticeboard ever will. Logincident exists to make exactly that capture effortless, through digital reporting that works on any channel and even offline.

Capture is only half of it. The other half is seeing the pattern. A single non-conformance is an event; fifty of them sorted by cause, line, supplier and severity is intelligence. Dashboards turn the stream of reports into trends you can act on: which defect type is rising, which corrective actions are overdue, whether the same root cause keeps recurring across different sites. That is the job of data visualisation, and it is what lets a quality lead spend less time chasing forms and more time fixing causes. If you want to see how this fits a specific quality operation, Logincident’s quality solution tracks every non-conformance and defect from capture through corrective action to closure.

The honest version of this is simple. A quality management system is a loop: notice, fix, learn, repeat. Software does not replace the judgement in that loop, but it removes the friction that usually breaks it. Most quality systems fail not because the method is wrong but because capturing and tracking everything by hand is too slow to keep up. Take the friction out of capture and tracking, and the loop can actually turn.

Frequently asked questions

What is the difference between quality assurance and quality control?

Quality assurance is proactive and process-focused: it builds confidence that requirements will be met, through things like process design, training and audits. Quality control is reactive and product-focused: it detects problems in actual output through inspection, testing and measurement. Assurance prevents defects; control detects them. Both sit inside quality management.

Is a non-conformance the same as a defect?

Not quite. A non-conformance is any failure to meet a requirement, which could be a process or documentation issue as well as a product one. A defect is specifically a non-conformance in a product or service that affects its intended use. Every defect is a non-conformance, but not every non-conformance is a defect.

What does CAPA stand for?

CAPA stands for corrective and preventive action. Corrective action addresses a problem that has already occurred and stops it recurring. Preventive action addresses a potential problem before it happens. Both look past the immediate fix to the underlying cause.

Do we need ISO 9001 certification to manage quality well?

No. ISO 9001 is a widely used reference for how to structure a quality management system, and certification can be valuable for customer and regulatory confidence. But you can adopt its principles, such as understanding requirements, managing processes and improving with evidence, without being certified.

How often should we run internal quality audits?

ISO 9001 requires internal audits at planned intervals, but it does not fix a frequency. Most organisations audit higher-risk or more variable processes more often, and stable ones less often. The schedule should be driven by risk and by where past problems have appeared, not by habit.

How does software help a quality management system?

Software removes the friction that usually breaks the quality loop. Easy digital capture means more non-conformances and defects are actually logged, and dashboards turn that stream of reports into trends you can act on, such as rising defect types, overdue actions and recurring root causes. The judgement stays human; the admin gets lighter.

Sources

  1. International Organization for Standardization, ISO 9001:2015 Quality management systems: Requirements. https://www.iso.org/standard/62085.html
  2. International Organization for Standardization, ISO 9000 family: Quality management. https://www.iso.org/iso-9001-quality-management.html

See your quality data in one place

Capture every non-conformance and defect, track each one to closure, and watch the trends that drive improvement.

Book a demo