MFLRC - MF License & Regulatory Consultants

September 23, 2025 · Quality Assurance

What Are the Four Types of Quality Assurance?

By Mussarat Fatima

Quality AssuranceGMP
What Are the Four Types of Quality Assurance?

Search for the four types of quality assurance and you will find the same list everywhere: process, product, system and people. It is a tidy answer, it is genuinely useful, and almost nobody who repeats it mentions the important part.

No Canadian regulation defines four types of quality assurance. Neither does ISO, ICH, the FDA or the European Commission. The four types are a teaching model drawn from quality management literature, not a legal classification. That does not make the model wrong. It makes it a lens rather than a rulebook, and knowing the difference matters the first time someone asks you to show where your obligations sit.

This guide does three things. It explains each of the four types properly and ties each one to the specific Canadian requirement it maps onto. It then sets out a different four, the four elements of ICH Q10, which regulators do recognize. Finally it covers what the four types model quietly leaves out, because the gaps are where inspection findings tend to accumulate.

Executive Summary

  • The four types of quality assurance are process QA, product QA, system QA and people-based QA. They describe how quality work is organized, not what any regulation requires.
  • The model is a teaching device. It has no standing in the Food and Drug Regulations, the Cannabis Regulations, ISO standards or ICH guidelines. Use it to structure your thinking, not to answer an inspector.
  • Each type does map onto real Canadian obligations: SOPs and sanitation for process, testing and release for product, quality management systems for system, and named individuals and training for people.
  • If you want an authoritative four, ICH Q10 defines four elements of a pharmaceutical quality system: process performance and product quality monitoring, CAPA, change management, and management review. That is the four to quote.
  • The model omits supplier control, data integrity, change control, risk management and post-market activity. Those omissions are not academic. They are where findings cluster.

What Are the Four Types of Quality Assurance?

The four types of quality assurance are process quality assurance, product quality assurance, system quality assurance and people-based quality assurance. Process QA asks whether the work is done the same way every time. Product QA asks whether the output meets specification. System QA asks whether the organization as a whole is in control. People-based QA asks whether the individuals doing the work are competent, trained and accountable. Together they form four layers, and a failure in any one of them will eventually surface in the others.

TypeThe question it answersWhat it examinesExample Canadian hook
Process QAIs the work done the same way every time?SOPs, sanitation, manufacturing control, validationCannabis Regulations s. 80 and s. 87; Food and Drug Regulations C.02.011 to C.02.012
Product QADoes the output meet its specification?Testing, specifications, stability, release, retained samplesCannabis Regulations ss. 89 to 92; Food and Drug Regulations C.02.018 to C.02.019
System QAIs the organization in control of itself?QMS, internal audit, change control, management reviewMedical Devices Regulations and ISO 13485; ICH Q10 for drugs
People QAAre the right people competent and accountable?Training, qualifications, named roles, hygiene, cultureCannabis Regulations s. 19 (QAP); Food and Drug Regulations C.02.006

Why the Caveat Matters

The four types model is a lens, not a compliance framework. It helps a team see that quality work happens at four different altitudes, which is a real insight and one that many organizations miss. What it cannot do is tell you what you are legally required to have.

This becomes a practical problem in two ways. First, the model implies a symmetry that does not exist in law. Product QA is heavily prescribed in Canadian regulations, with named tests and specifications. System QA is barely prescribed at all outside medical devices. Treating them as four equal quarters of one job leads teams to over-invest in the parts that are already well controlled and under-invest in the parts nobody is checking until an auditor arrives.

Second, the model has no traceability. You cannot write "type 3" in a gap assessment and expect it to mean anything to Health Canada. Compliance is demonstrated section by section, which is the subject of our companion article on what compliance in quality assurance actually means. Use the four types to design your thinking and the regulation to document it.

Type 1: Process Quality Assurance

Process QA is the discipline of making sure work is performed the same way, by everyone, every time, and that the way is written down before it is used. It is the layer regulators lean on hardest, because a controlled process is the only credible explanation for a consistent product.

In Canada the hooks are explicit. Section 80 of the Cannabis Regulations requires that cannabis be produced, packaged, labelled, distributed, stored, sampled and tested in accordance with standard operating procedures designed to ensure those activities meet Part 5 and Part 6. Section 87 requires a sanitation program setting out cleaning procedures for the building and equipment, procedures for handling substances used, and hygiene requirements for personnel. For drugs, C.02.011 and C.02.012 impose manufacturing control obligations that do equivalent work. For food, the preventive control plan under the Safe Food for Canadians Regulations plays the same role, built on hazard analysis.

What it looks like when it works: procedures are reviewed on a defined cycle and revised when they drift from reality. Deviations are documented in a report that records the reason, whether the deviation was planned, and an assessment of the impact. Training on a new or revised SOP is delivered and documented before the procedure takes effect, not after. Validation provides the evidence that the process actually does what the procedure claims, rather than the claim standing alone.

How it fails: the SOP describes an aspiration and the floor does something else. This is the most common finding we write in mock audits, and it is entirely self-inflicted. An SOP that describes a better process than the one you run does not improve the process, it just converts a workmanship problem into a documentation problem. Write what you do, then change what you do deliberately, with change control, and update the document as part of that change.

Type 2: Product Quality Assurance

Product QA is the verification that the thing you made meets its specification before it reaches anyone. It covers specifications, sampling, testing, stability, retained samples and the release decision itself.

This is the most heavily prescribed layer in Canadian law. Section 89 of the Cannabis Regulations states that a holder of a licence must not sell or export a cannabis product unless the applicable requirements set out in sections 90 to 92 have been met. Section 92 requires a portion of each lot or batch to be retained for at least one year after the date of the last sale of any portion of that lot or batch. For drugs, C.02.018 and C.02.019 cover finished product testing, C.02.025 and C.02.026 cover samples, and C.02.027 and C.02.028 cover stability.

The release decision is where product QA becomes personal. Under section 88(1)(e) of the Cannabis Regulations, every lot or batch must be approved by the quality assurance person before it is made available for sale. Health Canada's guidance is unambiguous about the corollary: if a test result is outside the identified specification, the product must not be approved for sale or export. An out of specification result is not a negotiation. It is an investigation, and our guidance on root cause and CAPA covers what that investigation has to establish.

The trap: product QA feels like the most important layer because it is the most visible and the most measurable. It is actually the last line of defence, and the weakest one. Testing does not create quality, it detects the absence of it, and it does so on a sample. A company that relies on final testing to catch problems is running a process it does not control and finding out about it a few units at a time. If your quality strategy is mostly laboratory, you have a process problem you have not diagnosed yet.

Type 3: System Quality Assurance

System QA steps back from any single product or process and asks whether the organization is in control of itself. It covers the quality management system: document control, internal audit, change control, supplier qualification, management review and continual improvement.

Here Canadian law is uneven, and it is worth being precise. Medical devices require a quality management system conforming to ISO 13485, and in the United States the FDA's Quality Management System Regulation, effective 2 February 2026, incorporates ISO 13485:2016 by reference. Drug manufacturers are expected to operate a pharmaceutical quality system in line with ICH Q10. But Part 5 of the Cannabis Regulations does not require a quality management system at all. It contains no requirement for a quality policy, management review, an internal audit programme, change control or continual improvement. Cannabis licence holders who assume their licence implies a QMS are frequently surprised, usually at the worst possible time.

Internal audit is the engine of system QA, and the reference standard is ISO 19011. The fourth edition, ISO 19011:2026, was published in May 2026 and formally integrates remote and hybrid auditing practices, which matters for multi-site operations and for supplier audits conducted at distance. Note that ISO 19011 is guidance: organizations are not certified to it, and it contains no auditable requirements. It describes recognized good practice. Our view on why internal audits earn their keep sets out how to run them so they find things.

The element most often missing is management review. It is the one part of a QMS that cannot be delegated downward, and it is the first to be skipped when the quarter gets busy. A quality system with no management review is a filing system: it records what happened and changes nothing.

Type 4: People-Based Quality Assurance

People-based QA is the recognition that systems are executed by individuals, and that competence, accountability and culture determine whether the other three layers function or merely exist on paper. It covers training, qualification, named roles and the willingness of staff to report a problem rather than absorb it.

Canadian regulations personalize this more than most people realize. Section 19 of the Cannabis Regulations requires a holder of a licence for processing to retain the services of one individual as a quality assurance person who has the training, experience and technical knowledge related to the requirements of Parts 5 and 6 applicable to the class of cannabis involved. That person is responsible for assuring the quality of the cannabis before it is made available for sale. Different licence classes name different people: cultivators have a master grower, and analytical testing licence holders have a head of laboratory. Our cannabis and hemp practice spends a great deal of time on exactly this point, because the wrong assumption here is a licensing problem, not just a quality one. For drugs, C.02.006 requires personnel with the necessary training and experience.

Delegation is permitted but accountability is not transferable. A quality assurance person may assign duties to someone with the relevant knowledge, training and experience, and following the March 2025 amendments certain activities may be conducted under that person's responsibility. The QAP nonetheless remains responsible for the quality of the cannabis produced and for investigating complaints. Naming someone on a form does not move the duty to them, and it does not move it to a consultant either.

A word about human error. It is the most over-used root cause in the industry and it is almost always a sign that an investigation stopped too early. People make mistakes at a fairly stable rate. When the same mistake keeps happening, the interesting question is not who did it but what allowed it: an ambiguous SOP, a form that invites the error, a workload that makes the shortcut rational, or training that was delivered as a signature rather than a competency check. Retraining an operator closes a finding and schedules its return.

The Four That Actually Carry Regulatory Weight: ICH Q10

If you want a set of four that a regulator will recognize, use the four elements of ICH Q10. ICH Q10, Pharmaceutical Quality System, reached Step 4 on 4 June 2008 and describes a model for a pharmaceutical quality system across the product lifecycle, from development through technology transfer and commercial manufacturing to product discontinuation. Unlike the four types, it is a real, adopted, internationally harmonised guideline.

The popular four typesThe four elements of ICH Q10
Process QAProcess performance and product quality monitoring system
Product QACorrective action and preventive action (CAPA) system
System QAChange management system
People-based QAManagement review of process performance and product quality
Status: teaching model, no regulatory standingStatus: adopted ICH guideline, referenced by regulators

The rows are placed side by side for comparison only. They are not equivalents, and that is the point. The two sets of four are answering different questions. The popular four describe where quality work sits. The Q10 four describe what a quality system must be able to do. Notice what Q10 treats as first class and the popular model omits entirely: CAPA and change management, two of the four.

Two further parts of Q10 are commonly conflated with the elements, so it is worth separating them. Q10 sets out three objectives: achieve product realisation, establish and maintain a state of control, and facilitate continual improvement. It also identifies two enablers: knowledge management and quality risk management. Quality risk management is addressed in its own right by ICH Q9, now at revision Q9(R1), adopted under Step 4 on 18 January 2023. Three objectives, two enablers, four elements. If someone quotes you Q10's "four" and includes quality risk management in it, they have not read it.

What the Four Types Model Leaves Out

The model's real weakness is not that it is unofficial. It is that the omissions are systematic, and they line up almost exactly with where modern findings cluster. Five things fall through the gaps.

  • Suppliers and outsourced activities. None of the four types points outward. Yet a large share of quality risk now sits with contract manufacturers, contract laboratories and ingredient suppliers. Your quality system ends at your fence line, but your legal responsibility does not.
  • Data integrity. The model predates the problem. Audit trails, electronic record controls and the question of whether your data is attributable, legible, contemporaneous, original and accurate are now central to inspections, and audit trail review in particular has become a focal point. Falsification of data sits in the most serious observation class Health Canada has.
  • Change control. ICH Q10 makes change management one of its four elements. The popular model does not mention it. Uncontrolled change is how a validated process quietly stops being the process you validated.
  • Risk management. Not a type, but an enabler that runs through all of them. It also has teeth: Health Canada states that a failure to apply good pharmaceutical quality system principles, including quality risk management principles, is considered when assigning risk to an observation. Weak risk management makes every other finding worse.
  • Post-market activity. Complaints, recalls and adverse reaction reporting sit outside all four types. For cannabis these obligations live in Part 11 rather than Part 5, and serious adverse reactions must be reported to the Minister within 15 days of the licence holder becoming aware of them. Quality does not stop at release.

Quality Assurance Checklist

Use the four types as the structure and this list as the test.

  • Process: every activity has a current SOP, and what the SOP says matches what the floor does.
  • Process: deviations are reported with the reason, whether they were planned, and an impact assessment.
  • Process: sanitation covers the building, the equipment, the substances used and personnel hygiene, and its effectiveness is monitored rather than assumed.
  • Product: specifications are approved before use and every required test is performed against them.
  • Product: out of specification results are investigated to a documented conclusion and never released around.
  • Product: retained samples are held for the prescribed period and are actually retrievable.
  • System: internal audits run to a schedule, findings are tracked to closure, and closure is verified for effectiveness.
  • System: change control exists and is applied to processes, equipment, suppliers and documents, not just to documents.
  • System: management review happens on a defined cycle and produces decisions, not minutes.
  • People: the individual the regulation names is appointed, qualified, and can demonstrate the training, experience and technical knowledge required.
  • People: training on new or revised SOPs is delivered and documented before the effective date.
  • People: staff can report a problem without it costing them anything, and you can point to a case where that happened.

Common Mistakes

  • Presenting the four types as a regulatory framework. It is a teaching model. Quoting it in a submission or an audit response signals that the quality function is working from a blog post rather than the regulation.
  • Equating product QA with quality assurance. Testing is quality control. It is one input, it happens last, and it works on a sample. A laboratory cannot compensate for an uncontrolled process.
  • Assuming a cannabis licence implies a quality management system. Part 5 does not require one. The gap appears the moment you pursue EU-GMP or supply a pharmaceutical partner.
  • Building the four layers in isolation. Strong SOPs with untrained staff produce nothing. Trained staff with no system produce heroics that do not survive turnover.
  • Closing investigations at human error. If retraining is your standard corrective action, your CAPA system is a queue, not a control.
  • Forgetting the fence line. None of the four types looks at your suppliers, and a growing share of your risk lives there.

Frequently Asked Questions

Are the four types of quality assurance an official standard?

No. The four types, process, product, system and people, come from quality management literature and teaching practice. No Canadian regulation, ISO standard or ICH guideline defines them. The model is a useful way to organize thinking about where quality work happens, but it has no legal standing and should not be used as the structure of a gap assessment or an audit response.

What is the difference between quality assurance and quality control?

Quality control is the testing and inspection that measures whether output meets specification. Quality assurance is the broader system that builds control into the process so the output is right in the first place, and that verifies the system is working. In the four types model, quality control maps closely onto product QA. Quality assurance covers all four layers. Quality control is a subset, not a synonym.

Which of the four types matters most?

The one you are weakest at, which is rarely the one you are measuring. In practice most Canadian sites are strongest at product QA, because it is prescribed in detail and easy to count, and weakest at system QA, because outside medical devices very little of it is legally mandated. If you want a single diagnostic, look at whether management review produces decisions. Sites that cannot answer that question usually have problems in the other three layers too.

Do the Cannabis Regulations require all four types?

Not as such. Part 5 requires SOPs and a sanitation program, which map to process QA. Sections 89 to 92 require testing and release, which map to product QA. Section 19 requires a named quality assurance person for processing licences, which maps to people QA. There is no requirement corresponding to system QA: no quality policy, management review, internal audit programme or change control. Many licence holders build those anyway, and for anyone contemplating export it is a sound decision, but it is a commercial choice rather than a regulatory obligation.

What are the four elements of ICH Q10?

A process performance and product quality monitoring system, a corrective action and preventive action (CAPA) system, a change management system, and management review of process performance and product quality. These are distinct from Q10's three objectives, which are achieving product realisation, establishing and maintaining a state of control and facilitating continual improvement, and from its two enablers, knowledge management and quality risk management. ICH Q10 reached Step 4 on 4 June 2008.

Is ISO 9001 enough for a regulated manufacturer?

No. ISO 9001 is a voluntary management system standard and it is not evidence of compliance with the Food and Drug Regulations or the Cannabis Regulations. It can be a useful discipline and customers may ask for it, but a certificate is not a defence to a regulator. Medical devices are the exception, where ISO 13485 conformity is central to the quality system expectation and is incorporated by reference into the FDA's QMSR.

Can the quality assurance person delegate their duties?

Tasks yes, accountability no. A quality assurance person may assign quality assurance duties to someone with the relevant knowledge, training and experience, and following the March 2025 amendments certain activities may be conducted under that person's responsibility rather than personally by them. The QAP nonetheless remains responsible for the quality of the cannabis produced and for investigating complaints. Retaining a consultant does not transfer the duty either, and the licence holder remains responsible throughout.

How MFLRC Can Help

MFLRC is a Canadian regulatory consultancy led by Mussarat Fatima, who brings more than twenty years in quality assurance, quality control and regulatory affairs across pharmaceuticals, food and cannabis. We build quality functions that work across all four layers, and we are candid about which layer is letting you down.

If you want a fast way to see where you stand, our cannabis QA compliance checklist is a reasonable starting point, and we are happy to talk through what it surfaces.

Conclusion

The four types of quality assurance, process, product, system and people, are a good way to think and a poor way to comply. They describe four altitudes at which quality work happens, and any organization that is honest about all four will find at least one it has been neglecting. That is the value of the model, and it is real.

Its limits are equally real. It is not law, it maps unevenly onto Canadian requirements, and it is silent on suppliers, data integrity, change control, risk management and everything that happens after release. Use it as a lens. Then put it down, open the regulation that binds you, and work section by section. That is the document an inspector will hold, and it is the only one that decides the outcome.

Sources and References

Share with others

Tags

Quality Management SystemHealth CanadaQAP (Quality Assurance Person)Good Production Practices
Book a consultation