Quality Assurance vs Quality Control: What's the Difference?
QA and QC are often used interchangeably, but they describe two distinct disciplines in a life sciences quality management system. Here's how they differ — and how they work together under FDA and ISO 13485.
By IntelaSolve™ Editorial

Walk into almost any life sciences company and you'll hear the terms "quality assurance" and "quality control" used as if they're synonyms. They're not. Under FDA's Quality System Regulation (21 CFR Part 820), ISO 13485, and ICH Q10, QA and QC describe two different sets of activities — with different objectives, different owners, and different evidence trails. Conflating them is one of the most common reasons early-stage teams get burned during their first audit.
This guide breaks down the difference in plain language, shows where each lives in a modern QMS, and explains why both are required to ship a regulated product.
The short answer
Quality assurance is process-oriented and prevents defects. Quality control is product-oriented and detects defects.
QA is what you do before and during manufacturing to make sure the process is capable of producing a compliant product. QC is what you do to the product itself to confirm it meets specification.
Quality assurance (QA): building the system
QA is the set of planned and systematic activities that give confidence a product will meet quality requirements. It is upstream, proactive, and lives inside the QMS itself.
Typical QA activities include:
- Writing and maintaining standard operating procedures (procedures)
- Training records and competency assessments
- Document and change control
- Internal audits and management review
- Supplier qualification and ongoing monitoring
- CAPA, deviation, and complaint handling workflows
- Design and development controls and the Medical Device File (per QMSR / ISO 13485)
The output of QA is not a tested unit — it's evidence that the system that produces units is under control. Auditors from the FDA, Notified Bodies, or MHRA spend most of their time inside QA records because a controlled process is what separates a compliant manufacturer from a lucky one.
Quality control (QC): inspecting the output
QC is the operational set of techniques used to verify that a specific batch, lot, or unit meets defined acceptance criteria. It is downstream, reactive, and lives on the shop floor or in the lab.
Typical QC activities include:
- Incoming inspection of raw materials and components
- In-process checks during manufacturing
- Finished product testing against release specifications
- Environmental and microbial monitoring
- Stability testing for pharmaceuticals
- Calibration and verification of test equipment
QC produces measurable data — a pass/fail result, a numeric reading, a certificate of analysis. That data becomes the evidence that a particular batch can be released to market.
How they work together
QA defines the rules and creates the framework. QC executes a subset of those rules on physical product and feeds the results back into QA. When QC detects a recurring out-of-spec result, QA opens a CAPA, investigates root cause, and updates the underlying process. The loop is what regulators call a "state of control."
A concrete example
A Class II medical device manufacturer ships sterile single-use instruments. QC tests each lot for sterility and endotoxin levels before release. Three lots in a row come back with elevated endotoxin results — still passing, but trending upward. QA's job is to recognize the trend through data review, trigger an investigation under CAPA, identify that a supplier changed a cleaning agent, update the supplier agreement, retrain the receiving team on the revised incoming inspection procedure, and verify the trend reverses. QC's job is to keep measuring and reporting accurately.
Where teams get this wrong
The most common mistakes we see in early-stage life sciences companies:
- Treating QC as the whole quality function. A team with rigorous batch testing but no document control, no training records, and no CAPA process is one audit away from a Warning Letter.
- Treating QA as paperwork. Procedures that nobody follows are worse than no procedures at all — they create documented evidence of non-compliance.
- Putting the same person in charge of both without independence. ISO 13485 §5.5.2 requires that the management representative have authority independent of production. Combining QA ownership with manufacturing ownership creates a structural conflict of interest.
- Manual data flow between QC and QA. When test results live in spreadsheets and CAPAs live in a different system, trend detection is nearly impossible. Modern eQMS platforms close this loop automatically.
What this looks like in a modern eQMS
In a connected QMS, QA and QC don't live in separate silos. Document control, training, supplier records, CAPAs, and audit trails sit alongside batch records, inspection results, and equipment calibrations. When a QC result is recorded, the system checks it against the controlled specification, routes deviations to the right owner, and links every action back to a controlled procedure.
That connection is what makes a QMS "audit-ready" rather than just "documented." The goal isn't more paperwork — it's a system where the evidence of compliance is a natural byproduct of doing the work.
Key takeaways
- QA prevents defects by controlling the process; QC detects defects in the product.
- Both are required under 21 CFR 820, ISO 13485, and ICH Q10.
- QA is upstream, systemic, and audit-facing. QC is downstream, operational, and batch-facing.
- The two must be connected by a feedback loop — usually through CAPA — for the QMS to function.
- Independence between QA and production is a structural requirement, not a nice-to-have.
