A quality assurance program (QAP) is the complete, planned, and documented set of controls an organization uses to ensure that safety-related items and activities meet their requirements, and to demonstrate that they do with objective evidence. In the United States it must satisfy the eighteen criteria of 10 CFR 50 Appendix B, with ASME NQA-1 as the consensus standard that says how. In Canada it is built to the management-system requirements of CSA N286, with supplier programs graded through the CSA N299 series. Internationally, ISO 19443 defines equivalent expectations for the nuclear supply chain. Whatever the jurisdiction, every individual quality process in this glossary operates inside the QAP.

01

A system, not a document

The phrase "quality assurance program" is often confused with the QA manual that describes it. The manual is a document. The program is the living system of people, procedures, controls, and records that actually operates. A program that exists only on paper, described in a manual but not implemented in daily work, is one of the most common and most serious findings a regulator can issue.

A mature QAP is typically organized as a hierarchy. At the top sits the QA manual or program description, which states the organization's quality policy and commits to each applicable requirement. Below it are the implementing procedures that translate each commitment into a defined method: how documents are controlled, how suppliers are qualified, how nonconformances are dispositioned. At the base are the records, the objective evidence that each procedure was actually followed for each item and activity. The program is sound only when all three layers are aligned: the manual commits, the procedures implement, and the records prove.

The test of a program is demonstrability. A quality assurance program is not judged by how good its intentions are, but by whether an independent party can trace any safety-related activity from requirement to result and find the objective evidence at every step. If the evidence cannot be produced on demand, the program has failed regardless of how the work was actually performed.

02

What the program must contain

The eighteen criteria of 10 CFR 50 Appendix B, mirrored in the eighteen requirements of NQA-1, define the scope of a compliant program. They are not a checklist to be satisfied once, but a set of interlocking processes that must operate continuously. In practice they translate into the recognizable elements catalogued throughout this glossary.

Organization and controls up front: design control, document control, and procurement and supplier QA ensure that requirements are correctly defined, the right revision is in use, and purchased items carry the right quality obligations.

Execution and verification: inspection and test control, special process qualification, and calibration and control of measuring equipment govern the work itself and confirm it meets requirements.

Problem management and evidence: the non-conformance report and corrective action program handle conditions adverse to quality, while training and qualification, records management, and auditing and assessment establish competence, preserve the evidence, and independently confirm the whole system works.

03

Graded, and applied across the supply chain

A quality assurance program does not apply the same rigor to everything. Through the graded approach, the depth of control scales with the safety significance of the item or activity. Safety-related work carries the full weight of the program; work with no safety function does not. Grading is not a way to opt out of requirements, but a way to focus effort where the consequences of failure are highest.

The QAP also does not stop at the licensee's boundary. Requirements flow down to suppliers and their subtier suppliers through procurement documents, and each participant maintains a program appropriate to what it supplies. This is why the same underlying criteria appear in Appendix B for licensees, in the CSA N299 categories for Canadian suppliers, and in ISO 19443 for the international supply chain: a licensee's QAP depends on every supplier and subtier supplier that touches a safety-related item running a sound program of its own.

04

Demonstrating that the program works

Because the QAP is a regulatory obligation, it is subject to continuous oversight. Internal audits, supplier audits, and regulatory inspections all test whether the program described in the manual is the program actually operating. Increasingly, regulators expect this to be demonstrable at any time, not assembled in the weeks before a scheduled inspection. A program where audit readiness is a byproduct of normal operations, rather than a periodic scramble, is both cheaper to run and far less likely to generate findings.

This is where the structure of the program becomes an operational advantage or a liability. When the record of what was required and the record of what happened live in the same controlled system, tracing any activity end to end is straightforward. When they are scattered across document repositories, spreadsheets, and email, demonstrating the program works becomes a manual reconstruction every time it is asked for.


Forged Operations is the system of record for your quality assurance program. It keeps the requirement and the evidence in one place, so an auditor's question about any item is answered from one record instead of assembled from several systems.

References

  1. U.S. Nuclear Regulatory Commission. 10 CFR Part 50, Appendix B: Quality Assurance Criteria for Nuclear Power Plants and Fuel Reprocessing Plants. Washington, DC: NRC.
  2. American Society of Mechanical Engineers. ASME NQA-1-2022: Quality Assurance Requirements for Nuclear Facility Applications. New York: ASME, 2022.
  3. CSA Group. CSA N286:12(R2018): Management System Requirements for Nuclear Facilities. Toronto: CSA Group, 2018.
  4. International Organization for Standardization. ISO 19443:2018, Quality Management Systems: Specific Requirements for Organizations in the Supply Chain of the Nuclear Energy Sector. Geneva: ISO, 2018.