When to engage independent QA/QC in Engineering: risks, scope, authority, inspections, audits, H/W/R Points, NCRs, and support for Owner acceptance.

Check it out!

Independent QA/QC is the work of a technical party that does not execute the scope and that independently verifies whether processes, materials, equipment, documents, inspections, tests, and evidence meet the project requirements. Instead of relying exclusively on the contractor’s self-control, the Owner creates an additional layer of confidence between what was specified, what was executed, and what will be accepted.

This independence does not mean duplicating the contractor’s work, replacing formal supervision, or assuming the technical responsibility of the executing party. Its role is to establish a second line of verification: assess whether the quality system is functioning, whether critical points are being controlled, whether the evidence is sufficient, and whether the condition presented as “compliant” can actually support an acceptance decision.

The need increases when there is a high consequence of failure, interfaces among multiple suppliers, components that will become concealed, off-site manufacturing, irreversible tests, regulatory requirements, a history of nonconformities, or low maturity in the contractor’s quality system. In these scenarios, independence stops being a bureaucratic layer and becomes a mechanism for protecting the Owner’s technical interests.

What independent QA/QC means

The term combines two complementary functions. Quality Assurance focuses primarily on confidence in the process: procedures, responsibilities, planning, audits, qualification, controls, and the ability to produce compliant results. Quality Control focuses on verification of the product or service: inspections, measurements, tests, results, records, rejections, and releases.

In an independent structure, these functions are performed or supervised by a team with no direct interest in accelerating production at the expense of technical criteria. This reduces a classic execution conflict: the same organization that must meet schedule and cost targets is also responsible for declaring whether its own work is acceptable.

DimensionContractor controlOwner’s independent QA/QC
primary objectiveproduce and demonstrate complianceverify whether declared compliance is reliable
relationshipexecuting partyOwner, lender, or independent stakeholder
focusprocess and product under its responsibilityproject risk and sufficiency of evidence
authorityaccording to contract and internal systemaccording to the Owner’s mandate and authority matrix
samplingdefined by the contractor’s planalso based on criticality and residual risk
nonconformityrecord and address its own deviationverify classification, disposition, correction, retest, and closure
acceptanceprepare evidence for submissionsupport the Owner’s decision without replacing the party holding contractual authority

The most important point is to separate technical independence from contractual authority. An independent team may issue an opinion, recommend rejection, request additional evidence, or technically block progress when the contract so provides. Even so, the formal decision on acceptance, measurement, or receipt belongs to the role defined in the project’s governance.

Camadas de confiança entre execução, QA/QC da contratada e verificação independente do Owner

Requisitos do Owner

Execução da contratada

QA/QC da contratada

Evidências de conformidade

QA/QC independente

Recomendação técnica

Aceite pelo Owner

Camadas de confiança entre execução, QA/QC da contratada e verificação independente do Owner

Why the contractor’s self-control may not be sufficient

When the same organization that executes the work is also solely responsible for declaring its own compliance, the Owner assumes an information risk. In critical systems, a second line of verification reduces the likelihood that acceptance occurs with incomplete evidence or relaxed criteria.

Learn about A3A Engenharia’s Owner’s Engineering services

Self-control is essential. No third party can compensate for a contractor without processes, supervision, inspection, documentation, and a quality culture. The problem arises when the Owner treats self-control as the only source of confidence in higher-criticality scopes.

The contractor has legitimate incentives related to productivity, schedule, and cost. These incentives can come into tension with decisions such as stopping a work front, rejecting a batch, dismantling an installation, repeating a test, or admitting that a stage must be redone. A mature quality system manages this tension. A weak system tends to postpone discovery of the problem.

There is also a limit of perspective. The contractor normally controls what is within its own scope. The Owner needs visibility across contract interfaces, discipline compatibility, operational impact, asset requirements, final documentation, and integration risks. An activity may be “compliant” in isolation and still produce an inadequate interface for the project.

Situations where a third party adds the most value

The decision should not be based solely on contract size. Small projects may contain high-criticality items, while large projects may include standardized low-risk portions. The best criterion is the combination of failure consequence, difficulty of detection, and cost of late correction.

Critical systems

Data centers, substations, generation, protection, automation, electronic security, telecommunications, critical HVAC, industrial utilities, and protection systems may require independent verification when a failure causes downtime, safety risk, operational loss, or high recovery cost.

Concealed or irreversible elements

Concrete placement, waterproofing, buried infrastructure, embedded cables, welds that will later become inaccessible, internal connections, seals, and other elements need to be verified before physical closeout. After that stage, missing evidence may require opening, demolition, or indirect testing.

Off-site manufacturing

Equipment manufactured by third parties requires control of documentation, materials, processes, testing, FAT, and shipment release. Vendor Inspection allows the Owner to intervene while deviations can still be corrected at the source. If the Owner’s first technical contact occurs only upon receiving, correction costs increase significantly.

Interfaces among multiple suppliers

A supplier may correctly deliver its package and still have a failure at the interface with another supplier. Independent QA/QC can work with interface matrices, boundary criteria, responsibilities, and integrated evidence.

History of NCRs or low maturity

Recurring nonconformities, incomplete documents, rework, traceability failures, tests without protocols, materials without certification, or large volumes of open items are signs that confidence in self-control needs to be reinforced.

How to decide whether independence is necessary

CriterionLow needIncreasing need
failure consequencelocal and reversible effectsafety, operation, major CAPEX, or downtime
detectabilityfailure easily visiblehidden failure or detectable only in final tests
reversibilitysimple correctiondismantling, demolition, or complex replacement
supplier maturityconsistent track recordnew supplier, irregular performance, or recurring NCRs
interface complexityisolated packagemultiple disciplines and contracts
document criticalitysimple documentationData Book, certification, traceability, configuration
Owner distancedirect follow-upremote manufacturing or multiple simultaneous work fronts
impact of incorrect acceptancelowrisk transferred to operations

The matrix does not need to result in “inspect everything”. The most efficient concept is risk-based QA/QC. The greater the risk, the greater the review depth, presence frequency, sampling coverage, and authority at intervention points.

Independence does not mean 100% inspection

A mistaken interpretation is to assume that an independent third party should repeat all inspections performed by the contractor. This increases project cost and may even dilute responsibility.

The most robust design uses process review, intervention points in critical activities, criticality-driven sampling, and escalation when results indicate loss of control. If a sample shows repeated failures, coverage can increase; if a supplier maintains consistent performance, presence can be reduced without abandoning governance.

Typical scope of independent QA/QC

The scope may range from a one-time audit to full follow-up throughout the procurement lifecycle. In a comprehensive structure, it may include review of requirements, the Quality Plan, PIT/ITP, audits, inspections, tests, NCR management, document verification, and support for technical acceptance.

Review of requirements and contractual documents

Before mobilization, the team assesses whether the specifications define objective criteria, applicable standards, deliverables, responsibility for inspections, traceability requirements, final documentation, and acceptance rules.

Review of the Quality Plan and PIT/ITP

The Quality Plan must reflect the specific contract. The PIT must convert critical activities into controllable points and define method, frequency, criterion, record, and H/W/R points consistent with risk.

Audits and process verification

Audits assess whether the defined system is actually being applied. ISO 19011:2026 provides guidance on audit principles, management of audit programs, performance of audits, and auditor competence.

Inspections, tests, and nonconformities

The team may participate in manufacturing inspections, receiving inspections, field execution, FAT, SAT, functional tests, and integrated tests. For NCRs, it verifies the requirement, disposition, correction, retest, and closeout evidence.

Document verification and acceptance

MDR/VDR, certificates, reports, inspection records, FAT/SAT, NCRs, as-built documentation, and final dossiers need to converge with the physical condition. At closeout, the third party consolidates evidence and reservations to support the Owner’s decision.

How to define the third party’s authority

Without an authority matrix, the independent team becomes a consultancy with no ability to intervene or creates blocks without contractual basis. The contract and Quality Plan must clarify who comments, classifies NCRs, places an activity on Hold, releases a Hold Point, approves deviations, authorizes shipment, accepts documents, and formalizes receipt.

Fluxo de decisão para escalonamento de QA/QC independente

Sim

Não

Não

Sim

Verificação independente

Conforme?

Registrar evidência

Liberar conforme autoridade

Classificar desvio

Impacto crítico?

Correção e reteste

Hold e escalonamento

Engenharia do Owner

Disposição técnica

Verificar fechamento

Fluxo de decisão para escalonamento de QA/QC independente

What distinguishes independent QA/QC from supervision

Technical supervision follows contractual compliance during execution and may include measurement, evidence, progress, documentation, and acceptance. Independent QA/QC focuses on the reliability of the quality system and compliance evidence. In some contracts, the same team performs both functions; in others, they are separate.

FunctionDominant question
technical supervisionis the service being executed according to the contract, design, and measurement conditions?
QAis the planned process capable of producing a compliant result, and is it being followed?
QCdoes the verified item meet the objective criterion?
auditdoes the system or process have sufficient evidence and comply with the audit criteria?
Owner’s Engineeringdo technical decisions and interfaces protect the Owner’s interests?

What the third party should not do

It should not perform the control the supplier should perform, complete records on behalf of the contractor, approve engineering outside its authority, change criteria without formal change management, assume responsibility for physical execution, or accept exceptions without a technical and documentary basis.

How to structure an independent QA/QC contract

Independent QA/QC does not have to mean full-time field presence. Coverage can be defined by criticality, risk triggers, H/W/R Points, audits, and milestones such as FAT, SAT, and technical acceptance.

Structure a risk-based supervision plan

A generic scope such as “monitor construction quality” is insufficient. Terms of Reference should define the object and systems, reviewed documents, disciplines, activities requiring presence, H/W/R Points, frequency, reports, NCRs, interfaces with supervision and commissioning, authorities, indicators, Data Book, and response times.

When risk is concentrated in a few milestones, continuous presence is not necessary. An on-demand model can combine remote document review, scheduled inspections, participation in FAT/SAT, and mobilization based on risk triggers.

Qualification criteria for the independent team

Competence must be compatible with the systems being verified. Assess education and professional registration, experience with the type of system, standards knowledge, inspection and commissioning experience, ability to interpret design documents, experience with NCRs, organizational independence, evidence methodology, and the ability to mobilize specialists.

Useful indicators for the Owner

IndicatorInterpretation
NCRs by period and disciplineconcentration of problems
NCR recurrenceeffectiveness of corrective actions
first-inspection approvalexecution maturity
punch list by systemcommissioning readiness
pending critical documentsacceptance/handover risk
H/W Points performed on scheduleprocess discipline
FAT approved on first executionmanufacturing quality and preparation
average NCR closeout timeresponse capability

When independence should begin

The best time is before contracting execution, when specifications, acceptance criteria, mandatory documents, PIT/ITP and responsibilities can still be reviewed. The later the team enters, the greater the chance of encountering irreversible conditions.

Independent QA/QC and risk management

The economic justification lies in avoided cost. A failure detected during design tends to be less expensive than the same failure found after manufacturing or installation. The principle is to position verification before the points at which the defect becomes more costly or difficult to detect.

ISO 10005:2018 addresses quality plans applicable to processes, products, services, projects and contracts; ISO 10006:2017 addresses quality management in projects. Together with ISO 9001, they help structure process, evidence and improvement, without replacing discipline-specific technical standards.

Phased operating model

  1. Preparation: requirements, document matrix, Quality Plan, PIT/ITP and acceptance criteria.
  2. Suppliers: qualification, Vendor Inspection, H/W/R Points, FAT, NCRs and release.
  3. Construction: critical inspections, traceability, interfaces and pending items.
  4. Commissioning: readiness, testing, deviation closure and punch list.
  5. Handover: Quality Dossier, Data Books, as-built documentation, manuals and recommendation for acceptance.

How to know whether the service is adding value

Value should not be measured by the number of inspections, but by clearer requirements, earlier deviation detection, lower recurrence, reliable evidence, improved commissioning readiness and well-supported acceptance decisions.

Final considerations

Independent QA/QC is a governance tool for projects in which the consequence of accepting an inadequate condition exceeds the cost of additional verification. Its purpose is not to create bureaucracy or distrust the contractor by default; it is to build a chain of technical confidence between requirement, execution, evidence, and acceptance.

The most efficient model is risk-based, with clearly defined authority, integration with supervision and Owner’s Engineering, and selective use of H/W/R Points, audits, inspections, and document review. The contractor remains responsible for producing quality. The independent third party verifies whether that quality can be demonstrated consistently and sufficiently to protect the Owner’s decision.

When the project already shows recurring NCRs, rework, weak evidence, or doubts about the executed condition, the approach stops being preventive and begins to require an independent diagnosis of the actual condition.

Assess the technical condition with an Engineering Audit

Technical references

[1] INTERNATIONAL ORGANIZATION FOR STANDARDIZATION. ISO 9001:2015 — Quality management systems — Requirements. Geneva: ISO, 2015. Available at: https://www.iso.org/standard/62085.html

[2] INTERNATIONAL ORGANIZATION FOR STANDARDIZATION. ISO 10005:2018 — Quality management — Guidelines for quality plans. Geneva: ISO, 2018. Available at: https://www.iso.org/standard/70398.html

[3] INTERNATIONAL ORGANIZATION FOR STANDARDIZATION. ISO 10006:2017 — Quality management — Guidelines for quality management in projects. Geneva: ISO, 2017. Available at: https://www.iso.org/standard/70376.html

[4] INTERNATIONAL ORGANIZATION FOR STANDARDIZATION. ISO 19011:2026 — Guidelines for auditing management systems. Geneva: ISO, 2026. Available at: https://www.iso.org/standard/19011

Frequently asked questions
What is independent QA/QC?

It is a layer of technical verification performed by a party that does not produce the scope and that assesses whether processes, inspections, tests, documents, and evidence are sufficient to demonstrate compliance to the Owner.

Does independent QA/QC replace the contractor’s quality control?

No. The contractor remains responsible for performing its own QA/QC. The third party verifies the effectiveness of that system and the reliability of the evidence.

When is it worthwhile to engage a third party?

When there is a high consequence of failure, low detectability, irreversible elements, remote manufacturing, multiple interfaces, recurring NCRs, or insufficient in-house technical staff.

Is independent QA/QC the same as supervision?

Not necessarily. Supervision follows contractual compliance and execution; independent QA/QC focuses on the reliability of the quality system and evidence.

Can the third party block an activity?

Only when that authority is defined in the contract, PIT/ITP, Quality Plan, or authority matrix.

Is it necessary to inspect 100% of the items?

No. An efficient model combines process review, H/W/R Points, risk-based sampling, and increased coverage according to performance.

Additional technical materials

Related solutions

Related services

Main content on the topic

Related technical content