← All postsHow-to

Quality management system: what a small company actually needs

A quality management system is the way you make results repeatable. Certification is a separate decision, and most of the value arrives long before it.

How-toQ

A quality management system is the set of processes, records and habits by which a company delivers the same result reliably and improves when it does not. It is often confused with certification, which is a separate thing: a certificate says an auditor found your system conforming to a standard on a given day. The system is what actually reduces defects, rework and lost customers.

Small companies usually acquire one for a specific reason — a customer requires it, a regulator requires it, or the cost of rework became visible. Any of those is a good reason. "We should probably have quality processes" is not, and produces a folder of documents nobody uses.

The parts that do the work

  • A short statement of what quality means for your product, in terms a customer would recognise.
  • Documented processes for the work that must be repeatable, at the level of detail the people doing it need.
  • Records that prove the work was done as described — the evidence layer, and the part most often missing.
  • A nonconformity log: what went wrong, where, when, and what was done about it.
  • Corrective action with root causes, not just fixes. A log full of "reminded the team to be careful" is a log of symptoms.
  • Supplier control proportionate to risk — approved suppliers, incoming checks where they matter.
  • Competence records: who is trained to do what, and when that was last confirmed.
  • Internal audits on a schedule, and a management review that actually reads the outputs.
  • Measures you look at: defect rate, rework hours, on-time delivery, complaints — a handful, reviewed regularly.

The nonconformity log is where a quality system earns or loses its keep. A team that records problems honestly — including embarrassing ones — gets a map of where the process is weak. A team that records only what cannot be hidden gets a tidy log and the same defects next quarter. Whether people log honestly is decided by how the first few entries are received.

Building it in the right order

  1. Start from failures, not from a standard. List what went wrong in the last year, what it cost, and where it happened.
  2. Fix the processes behind the biggest few, and write those processes down as you fix them.
  3. Add the record that proves each one happened — a check, a sign-off, a log entry — and nothing more.
  4. Start the nonconformity log immediately, before any of the documentation is finished. It is the input everything else depends on.
  5. Introduce root-cause analysis on the recurring items, and accept that most root causes are process design rather than individual error.
  6. Add internal audits once processes exist to audit against, quarterly on a rotation.
  7. Review the measures monthly with the log open, and change something as a result — a review that changes nothing trains people to stop preparing for it.
  8. Only then, if a customer or regulator requires it, map what you have onto the standard and consider certification.

Certification, honestly

Certification against a recognised standard costs money, consultant time and an annual audit cycle, and it opens doors in sectors where customers demand it. What it does not do is create quality — plenty of certified companies ship defects, and plenty of uncertified ones are excellent. Decide it commercially: if it wins or protects work, it is worth the cost; if nobody is asking, spend the same money on the nonconformity log and the corrective actions and you will get more back.

Ettex Records is a good home for the register side of this: custom tables with typed fields and no code, so a nonconformity log, a corrective-action register, an approved-supplier list and a competence matrix are four tables rather than four spreadsheets; relations between tables so a corrective action points at the nonconformity it came from; grid, kanban and gallery views with saved filters — open findings by owner, overdue actions, defects by product; formulas and rollups across related rows; revision history where every cell change is tracked and restorable; row comments for queries; and CSV import to bring an existing spreadsheet in. The processes themselves belong in Ettex Docs, the audit checklists in Ettex Forms, and the audit and review schedule in Ettex Calendar.

Plainly: Ettex is not an eQMS. There is no certified quality module, no CAPA workflow with enforced stages, no document control in the compliance sense, no training or calibration reminders, no supplier scorecards, and using Ettex does not contribute to certification against any standard. It is a set of general tools you can shape into the registers and records a small quality system needs. If you are being audited against a standard at any scale, buy software built for it.

Why quality systems become paperwork

  • Built from a standard rather than from your own failures, so it documents someone else's business.
  • Processes written at a level of detail nobody doing the work would read.
  • A nonconformity log that only records what could not be concealed.
  • Corrective actions that are reminders rather than changes to how the work is done.
  • Audits performed to satisfy the schedule, with findings nobody follows up.
  • Management review as a ritual with the same slides and no decisions.
  • Certification pursued first, so the system is designed to pass an audit rather than to make the product good.

Frequently asked

What is a quality management system?

The documented processes, records, measures and review habits by which a company delivers consistent results and corrects itself when it does not.

Does a small company need one?

It needs the working parts — repeatable processes, a nonconformity log and real corrective action — whenever rework, defects or complaints are costing money. The formal apparatus is worth it when a customer or regulator asks.

Is a quality management system the same as ISO 9001 certification?

No. The system is how you actually work; certification is an auditor's confirmation that it conforms to a standard. You can have either without the other, though only one of them improves the product.

What should be built first?

The nonconformity log. It costs nothing, starts producing information immediately, and tells you which processes are worth documenting first.

What is the difference between a correction and a corrective action?

A correction fixes the instance — remake the part, resend the order. A corrective action changes the process so the cause stops recurring. Logs full of corrections explain why the same defects return.

How often should internal audits happen?

On a rotation that covers your key processes over a year — quarterly audits of one or two processes suits most small companies better than an annual audit of everything.

A quality management system starts with an honest log of what went wrong and a genuine change to the process that caused it. Documents, audits and certificates are scaffolding around that — useful in order, useless before it.

AS
Written by Alex S.

Part of the Ettex team — writing about product, engineering and the future of work.

More posts
Get the best of the Ettex blogProduct news, guides and tips — straight to your inbox, no spam.