When a project or part of the business starts to go wrong, a common response is to ask for more checking: another review, a fuller report, an outside consultant. Sometimes that helps. Often the underlying problem remains, because the business has not distinguished three different jobs that all get called “checking”: controlling the work, assuring the process used to control it, and independently reviewing whether the whole venture still makes sense. Blurring them produces duplicated checking in some places and dangerous gaps in others.
Each of the three answers a different question. Is this output right? Is the way we produce outputs reliable? Should we be doing this at all, and can we actually deliver it? A business can be strong on the first and blind on the third. A team can inspect every item meticulously while pursuing an expansion the business cannot support, or while the process that produces those items quietly degrades.
This article explains the three levels, why independence is a set of choices rather than a single property, how to match the intensity of checking to the stakes, and how to make sure findings change decisions rather than filling an action log. It is general information for owners and managers of growing businesses.
Three levels of checking
| Level | Examines | Typical question | Usually done by |
|---|---|---|---|
| Quality control | Outputs | Does this item, job or deliverable meet the requirement? | The people doing the work, or inspectors close to it |
| Quality assurance | Processes | Are our methods and checks suitable, and are they being followed? | Someone separate from the work being checked |
| Independent review | The venture as a whole | Is this still worth doing, and can our management system deliver it? | Someone outside the delivery chain, reporting to the owner or board |
Quality control inspects, tests and measures outputs. Quality assurance asks whether the processes that produce outputs are sound: whether inspections happen as designed, whether they catch what they should, whether people are trained. Independent review takes a wider view: whether the business case still holds, risks are understood, governance works and the business is ready for a commitment that will be hard to reverse.
A useful way to think about them is as three lines of confidence. The first line, management control, owns the result. The second line, specialist oversight, tests whether controls work. The third line gives the owner or board an independent view before major decisions. A small business may not have separate teams for each, but the functions still need to exist. A capable peer from another part of the business, an external specialist or a trusted adviser can provide the second or third line, as long as roles and conflicts are clear.
Common misreadings
- The three are interchangeable. They answer different questions. More inspections do not tell you whether an expansion is wise.
- Independence means distance. A reviewer who is structurally independent but lacks the technical or practical knowledge to understand the work may produce formal findings with little value.
- Checking can make up for weak management. Reviewers can identify problems and recommend action. If they start running the work, accountability blurs.
- Documents prove controls work. A checklist can exist without anyone using it properly; a risk list can exist without anyone managing risk. The gap between the documented process and what actually happens is often the most valuable finding.
Independence is several choices
Independence has several dimensions, and a review can be strong on some and weak on others:
- Structural: the reviewer does not report to the person whose work is being checked.
- Financial: the reviewer is not rewarded for the outcome being reviewed.
- Thinking: the review includes perspectives not shaped by the same assumptions.
- Evidence: conclusions are tested against original records, not just management summaries.
- Access: the reviewer can talk to the relevant people and see the relevant records and sites.
A review can be formally independent and still captured if everyone involved shares the same assumptions. Equally, an internal expert can provide valuable challenge if conflicts are declared and the owner keeps the decision.
Match intensity to stakes
Uniform checking wastes effort. Increase the intensity as stakes rise:
- the size of an irreversible commitment;
- safety, legal or regulatory consequences;
- novelty and technical uncertainty;
- strategic importance;
- dependence on a single supplier;
- how hard it would be to recover from failure;
- evidence that performance is deteriorating.
A familiar, low-value, reversible change may need only a peer’s quick look. A significant expansion, a new type of work or a major system change may need staged, independent review of the technical, commercial and operational aspects.
Timing matters as much as intensity. Independent challenge is worth most before a major contract, a design freeze, a system migration or a handover, when it can still change the decision. After the commitment is made, it can only describe the damage.
Every review should serve a decision
Before commissioning any significant review, define:
| Element | Question |
|---|---|
| Decision | What decision will this review inform? |
| Scope | Which claims, risks and controls will be examined, and what is out of scope? |
| Independence | How separate must the reviewer be for the result to be credible? |
| Competence | What expertise is needed? |
| Evidence | What original records and people must be available? |
| Thresholds | What finding would cause a pause, conditions, redesign or a stop? |
| Owner | Who decides what to do with the findings? |
An independent review should test two different things: is the venture still worth doing? and is the current management system capable of delivering it? A valuable initiative can be badly organised; a well-run project can pursue an outcome that no longer matters. Owners need both answers.
Defining what is out of scope matters too, so that the absence of a finding is not mistaken for reassurance about something nobody looked at. The tests that cannot fail article covers checking whether a review could have found the problem at all.
Conditional approval is often the right answer
Reviews are often framed as a choice between approving and stopping. A third option is usually more useful: approve with conditions. The review identifies what must be true for the commitment to succeed, such as a key hire, a finance facility, a completed test or a signed supply agreement, and the approval holds only once those conditions are met. Name who is responsible for each condition and by when, and decide in advance what happens if a condition is not met. Conditional approval keeps momentum without pretending the gaps are not there.
Avoid review overload
Checking consumes attention. If several people ask for similar evidence in different formats, the team spends its time satisfying oversight rather than improving the work. Once a year, list every recurring review, inspection and report, and ask what decision each serves and who uses it. Merge duplicates, drop reviews with no clear user and put the saved effort into the checks that protect against the most serious risks.
Write findings that support action
A useful finding states the expected standard, the evidence observed, the gap, the consequence and a recommended response. And not all findings are equal. Distinguish:
- non-conformance: something did not follow the agreed method;
- control weakness: the method itself is not good enough;
- emerging risk: something not yet a problem but heading that way;
- unsupported assumption: the plan relies on something nobody has tested;
- strategic concern: the venture’s purpose or viability is in question.
A long, undifferentiated list encourages quick closure of easy items and buries the ones that could change the decision. Strategic concerns and unsupported assumptions belong with the owner, not in a project manager’s action list. The from promise to proof article covers writing a short charter for audits so each one answers a real question.
The behavioural side
Announcing a review can improve discipline immediately, or it can trigger defensive reporting and tidied-up evidence. The difference lies in how the review is run and how findings are used:
- Assess the system, not just individuals. Many problems come from unclear authority, overload or weak support, not from one person.
- Invite factual correction before findings are final, without letting uncomfortable evidence be negotiated away.
- Keep reviewers advising, not doing. The owner and the team keep responsibility for deciding and acting.
- Make the response explicit. If the owner accepts a risk rather than following a recommendation, record that decision and the reason.
- Only commission reviews you are prepared to act on. Ignoring a credible review damages trust in the next one.
A worked example
This is an illustration. A residential renovation builder with 25 staff runs all three levels of checking, but has never thought of them separately.
Quality control is strong on paper: site supervisors complete a pre-plaster checklist on every job, covering framing, waterproofing and services. Yet the business still finds defects after plastering, about 14 last year at an average cost of around $1,800 each, or roughly $25,200 in rework.
The owner asks the operations manager, who does not supervise sites, to carry out quality assurance on the checklist process. Reviewing a sample of 40 checklists against site photos and talking to supervisors, she finds that about a third were signed without the required photographs, often at the end of a busy day, and that two common defects were not on the checklist at all. The control existed; the process behind it was weak. The checklist is revised, photos become mandatory before plastering can be booked, and the operations manager samples ten checklists a month.
Meanwhile, the owner is considering expanding into small multi-unit developments, a commitment of about $600,000 in working capital and new staff. Before committing, the owner asks an experienced builder from a non-competing region and the business’s accountant to conduct an independent review. Their brief has two questions: is the expansion worth doing, and can the current management system deliver it? The review finds the market case reasonable but identifies a strategic concern: the business has no one with multi-unit project management experience and its cash flow forecast assumes progress payments that are typical for renovations but not for developments. The owner approves the expansion with conditions: hire an experienced project manager first and secure a finance facility sized to the revised cash forecast.
How this applies to a small Australian business
- Map your current checking against the three levels.
- Strengthen quality assurance where outputs keep failing despite inspections.
- Arrange an independent review before major, hard-to-reverse commitments.
- Choose independence deliberately: structure, incentives, thinking, evidence and access.
- Match intensity to stakes, and time reviews before commitments.
- Define the decision each review serves, and what is out of scope.
- Classify findings, and send strategic ones to the owner.
- Act on findings, or record why you accepted the risk.
Signals worth watching
- Defects that keep appearing despite inspections.
- Checklists completed but not used.
- Reviews commissioned after decisions have effectively been made.
- Findings that sit in an action log without changing anything.
- Reviewers drifting into running the work.
- No independent view before the business’s largest commitments.
Common mistakes
- Treating more inspection as the answer to every problem.
- Equating document existence with control.
- Choosing reviewers for independence without competence.
- Reviewing too late to change the decision.
- Mixing strategic concerns with minor non-conformances.
- Commissioning reviews and ignoring them.
Frequently asked questions
Can a small business afford independent review? For major decisions, yes. A day or two from an experienced peer, adviser or accountant costs little compared with the commitment it informs.
Who should do quality assurance in a small team? Someone who does not perform the work being checked. Rotating the role between capable staff can work well.
How often should we review processes? In proportion to risk and change. Processes that protect against serious harm or are changing quickly deserve more frequent checks.
What if the owner disagrees with a review’s findings? The owner keeps the authority to decide. The value of the review is that the decision and its reasoning become visible.
Is certification the same as assurance? Certification checks conformance to a particular standard. It is one form of assurance, not a substitute for checking whether your own processes and plans are sound.
Should the same person do quality control and quality assurance? Preferably not. The value of assurance comes from someone who did not perform or inspect the work looking at whether the process is sound.
Questions to ask
- Which of our checks inspect outputs, which test processes and which question the venture itself?
- Where do problems keep getting through despite inspections?
- Who gave us an independent view before our last big commitment?
- How independent were they, and in which ways?
- What decision does each of our reviews serve?
- What happened to the findings from our last review?
Bringing it together
Quality control, quality assurance and independent review answer different questions: is this output right, is the process reliable, and should we be doing this at all? A business needs all three in proportion to its stakes. Choose independence deliberately, time reviews before commitments become hard to reverse, define the decision each review serves and classify findings so strategic concerns reach the owner. Run reviews as fair assessments of the system, and act on what they find. Checking adds value only when it changes what the business does.
Source: KEVOS notes, drawing on teaching material on quality control, quality assurance and project assurance, guidance on project audits, and the UK Government’s 2018 functional standard for project delivery (GovS 002) on assurance and decision points. Examples and figures in this article are illustrations. This article is general information.