Quality Management Software: Costs, Recurrence, Threshold
Matteo Migliore

Matteo Migliore is an entrepreneur and software architect with over 27 years of experience developing .NET-based solutions and evolving enterprise-grade application architectures.

He has led enterprise projects, trained hundreds of developers, and helped companies of all sizes simplify complexity by turning software into profit for their business.

The quality manager of a company making turned and milled mechanical components, one hundred and twenty employees and customers in agricultural machinery and hydraulics, called me ten days before the ISO 9001 surveillance audit. His office, three people, had spent two weeks rebuilding the nonconformity register from three spreadsheets, email and a binder on the shop floor. When we lined up a whole year for the first time, there were four hundred and ten nonconformities and ninety seven per cent showed as closed. But thirty eight in a hundred concerned the same defect on the same part already recorded in the previous twelve months. A burr on the threaded hole of a valve body appeared twenty three times, and twenty three times the corrective action was the same: operator reminded. That is the problem quality management software is supposed to solve, and it is also the one no software solves on its own.

If you recognise the scene, this article gives you the real cost of poor quality, the single number that tells you whether a quality system will make you spend less or just get you through the audit with less effort, how to keep the cycle from nonconformity to effectiveness check tied together, how far a spreadsheet with the manual in a shared folder takes you, the three different things vendors all sell under the same name, the real price bands for the module of the ERP you already own, a subscription product and a custom system, and the threshold in euro beyond which the maths changes.

I have been writing software since 1999 and I have seen quality systems work, and fail, in many ways: certified machine shops living on customer audits, automotive suppliers with requirements that change with every specification, food companies where a nonconformity becomes a product recall, machine builders with acceptance tests to document part by part. I also built and sold a software product used by many companies, and I know what it takes to turn into a process the way people solve problems when nobody is watching.

What I learnt, and what no vendor says during the demo, is this: the number that decides is not how many modules the software has, it is how many of the nonconformities you close come back. The dashboard with colourful charts is the part that sells best and saves least: the auditor likes it, but it does not take a single part out of the scrap bin. The money is in the nonconformities that show as closed in the register while the shop floor keeps producing them.

What quality management software is, and what it is not

Quality management software is the system that holds the company's quality problems in a single place, from where they arise to how they are solved: it records internal, supplier and customer nonconformities, guides containment and root cause analysis, assigns corrective actions to a person with a date, checks that they worked and carries what was learnt into the documents people work with. Around this core sit the parts needed to keep the certification: controlled documents, internal audits, supplier evaluation, instrument calibration, staff training.

You will find it on the market under different names, and here too the confusion suits whoever is selling. Quality management system, ISO 9001 software, nonconformity management, CAPA, short for corrective and preventive action, 8D report software, quality control, SPC. They overlap only in part, cost very different amounts and solve different problems. A program collecting measurements from the test bench knows nothing about which corrective action was decided, and a procedure archive does not know whether that procedure has prevented a single defect.

The difference between recording a nonconformity and getting rid of it

Almost every certified company that writes to me already has part of the problem covered. They have a nonconformity form, almost always in Excel or Word, that the quality manual requires. They have the ERP, with customer returns and supplier lots. They have a shared folder with procedures, work instructions and control plans. And they have a good quality manager who knows every recurring defect by name, knows which machine produces it and which supplier delivers out of tolerance, and rebuilds everything by hand before every audit.

The point is that these pieces answer questions different from yours. The form answers what happened that day. The ERP answers how many parts came back. The folder answers how work should be done. Your question is another one: have we seen this defect before, what did we decide, did we actually do it, and why has it come back. None of the three pieces sees it, because the answer lies in the link between a nonconformity and the ones that came before it, and today that link lives in the quality manager's memory.

Then there is time. The scrapped part is reported by the shift supervisor on Tuesday with a note. The note reaches quality on Thursday, the nonconformity is opened the following week, and by then the tool has been changed and nobody remembers which lot of bar stock was running. The root cause analysis is done with what is left, meaning nothing, and the cause written on the form becomes the easiest one to write: operator error. Three months later the defect returns, with a different operator.

The three kinds of companies looking for it, and looking for different things

Companies that need to keep the certification. Companies certified ISO 9001 because customers ask for it, with a quality system born to pass the audit and a manager who often also handles safety and environment. The value lies in time that stops going into rebuilding data, in documents always at the right revision and in an audit prepared in two days instead of two weeks. Here even a simple system pays back quickly, as long as it does not become a second register to fill in.

Companies whose customers ask for more than the standard. Suppliers to automotive, medical, aerospace, food for large retail. Each customer has its own portal, its own 8D report format, its own response times, sometimes twenty four hours for containment and ten days for the cause. The value lies in answering on time, not losing supplier approval and turning complaints into causes actually found. It is the family where a nonconformity costs the most.

Companies inspecting the product in line. Acceptance tests, dimensional measurements, functional tests, statistical process control on critical dimensions. The value lies in measurement data arriving from the machine without being transcribed and in the alarm that goes off when the process drifts, before it produces scrap. Here the quality system has to talk to production, and the link is the one I described in production management software.

All three buy products with the same name and use different parts of them. Before you watch any demo, decide which one you are, even though most companies are two. Most of what follows applies to all of them, because the nonconformity cycle is the same; I will flag where things change.

The real bill: what poor quality costs you

The five costs poor quality generates every year for a machining company with four hundred and ten nonconformities, from repeated scrap to customers putting you under watch, almost none of which appears as a line in the accounts

This is the calculation almost nobody does in full, because only some of these items have a line in the accounts: scrap is sometimes visible, the rest are people's hours, charges mixed into credit notes and risks written down nowhere. I take as a reference a machining company with twenty two million euro in revenue, one hundred and twenty employees, two production departments, a quality office of three, about four hundred and ten nonconformities a year: two hundred and sixty internal, ninety on supplier materials and sixty customer complaints. It is a very common size among the people who write to me, and the numbers scale reasonably well with the number of nonconformities.

A warning before we start. The cost of poor quality that matters here is not all scrap: some scrap is physiological, and no software removes it. What matters is the part that repeats, meaning what the company had already seen, already analysed and already declared solved. That is why I only use that part in the calculation, and stay low.

Scrap and rework that repeat

This is the largest item and, paradoxically, the one that looks under control, because scrap is weighed and put in a chart. In the reference company internal scrap and rework are worth about one and a half per cent of revenue, meaning three hundred and thirty thousand euro a year in material, machine hours and labour. If thirty eight per cent of nonconformities are repeats, and roughly the same share holds for value, the part the company pays twice for a problem it already knows sits around one hundred and thirty thousand euro a year.

Not all of that part can be recovered, and anyone who promises to eliminate scrap with software does not know a shop floor. Some defects return because the cause costs more than the defect, old machines that should be replaced, materials the market only offers that way. But almost always a good half of the repeats have a findable cause that nobody looked for, because the corrective action was written to close the form, not to close the problem.

Customer complaints and charges

Sixty complaints a year, and each has a cost well beyond the value of the parts. There is sorting, often done by an outside firm at the customer's site at sixty euro an hour. There is the charge for stopping the customer's line, which in automotive contracts can be worth thousands of euro an hour. There are travel, the 8D report, the hours of the salesperson and the quality manager. In the reference company the average cost of a complaint, all of this together, is about one thousand five hundred euro: up to ninety thousand euro a year.

There is an effect worth more than the money: a customer who receives the same defect twice stops looking at the part price and starts looking at your reliability. The third time they put you on a list, and you only get off the list with months of reinforced inspection paid by you.

Supplier material accepted and discovered in line

Ninety nonconformities on supplier materials, and about a third discovered not at incoming inspection but in line, after the part has been machined. Bar stock with hardness out of specification that breaks the tool, surface treatments that do not hold, castings with porosity that only shows after milling. When the defect emerges after machining, the value you added goes in the bin too, and the supplier refunds the material, not your hours. Thirty cases at about one thousand six hundred euro each make up to fifty thousand euro a year.

The cause, almost always, is that nobody knows which suppliers have already delivered out of specification and which lots need closer inspection. Supplier evaluation exists, but it is a yearly score filled in for the audit, not a rule telling the warehouse what to inspect today. The link with goods receiving is direct, and I covered it in warehouse management software.

The quality office chasing data

Three people, and in my experience about a third of their time goes into collecting, copying and reconciling data instead of analysing it: forms to retype, monthly indicators redone by hand, customer reports in different formats, the week before every audit. That is about one thousand eight hundred hours a year, which at a full cost of forty euro an hour comes to over seventy thousand euro. At least half of that work disappears when data is born once in the right place: up to forty thousand euro a year.

The real cost, though, is not the hour, it is what the quality office does not do while it copies. Root cause analyses done in a hurry, shop floor checks postponed, suppliers nobody goes to visit. A quality office spending its time on forms becomes an office that certifies problems instead of removing them.

Audits, findings and customers putting you under watch

The last item is the hardest to estimate and the most dangerous. There are the days preparing certification and customer audits, the findings to manage, the reinforced inspection imposed by a customer after a repeated complaint, with one hundred per cent of parts checked before shipping until you prove the problem is solved. In the reference company, between preparation, imposed inspection and travel, it comes to up to forty five thousand euro a year. And I do not count the real risk, losing approval with a customer worth fifteen per cent of revenue.

The total, for a company with four hundred and ten nonconformities, sits between sixty and three hundred and fifty five thousand euro a year, and no company takes all five items at the maximum. The range is wide because the real variable is not how many nonconformities you record: it is how many of them repeat. A company that records a lot and really solves sits low, a company that records little and closes everything with the same sentence sits high. Do the calculation with your own numbers, even roughly, on a single sheet. If your total is below twenty five thousand euro a year, software is not your most urgent problem, and further on I tell you what is.

The share of nonconformities that repeat: the number that decides

The four thresholds of the share of nonconformities that return on the same part with the same defect within twelve months, with what each threshold says about the company's quality system

If I had to keep a single number from the whole article, I would keep this one: how many of the nonconformities recorded over the last twelve months concern the same defect on the same part, or on the same material from the same supplier, already recorded in the previous twelve months. I call it the recurrence rate. It decides everything, because every function of quality management software, from root cause analysis to corrective actions to effectiveness checks, works to reduce that number, and if you do not know where you start you cannot know whether the system you buy is reducing it.

The reason this number matters more than the count of nonconformities, the average closing time and the dashboard charts is that it tells you whether the quality system learns. The count alone deceives: a company that starts recording properly sees nonconformities rise, and it is improving. Closing time deceives even more, because it drops by closing quickly with fake actions. The recurrence rate is hard to fake: a defect has either returned or it has not.

How to measure it, in a day

You need two things. The first is the list of nonconformities from the last year, better the last two, with date, part or material, supplier or customer where relevant, and a description of the defect. It almost certainly exists, even if scattered across a spreadsheet, the ERP and email. The second is the one that is almost always missing: a defect code, because "burr", "burr on thread", "thread with residue" and "non compliant deburring" are the same thing written by four people. The first job is to give each row a code from a catalogue of thirty or forty defects, and it takes one person who knows the product and a couple of afternoons.

If the data already sits in a database, the measurement is a query. This is the form I use on SQL Server. Table names in your system will differ, the substance will not:

-- Share of nonconformities that repeat: same part and same defect code
-- already recorded in the previous twelve months, split by origin (internal, supplier, customer)
WITH nc AS (
    SELECT NonconformityId,
           Origin,
           PartCode,
           DefectCode,
           OpenedOn,
           LAG(OpenedOn) OVER (PARTITION BY PartCode, DefectCode
                               ORDER BY OpenedOn) AS PreviousOpenedOn
    FROM Nonconformities
)
SELECT Origin,
       COUNT(*) AS Nonconformities,
       SUM(CASE WHEN PreviousOpenedOn >= DATEADD(MONTH, -12, OpenedOn) THEN 1 ELSE 0 END) AS Repeated,
       SUM(CASE WHEN PreviousOpenedOn >= DATEADD(MONTH, -12, OpenedOn) THEN 1 ELSE 0 END) * 100.0
         / COUNT(*) AS RecurrenceRatePercent
FROM nc
WHERE OpenedOn >= DATEADD(MONTH, -12, CAST(GETDATE() AS date))
GROUP BY Origin
ORDER BY RecurrenceRatePercent DESC;

Then do the second pass, which is the one that tells the truth: for the twenty most frequent repeats, read the cause and corrective action written the first time. You will almost always find one of these four sentences: operator error, operator reminded, inspections increased, supplier notified. None of the four is a cause, they are all descriptions of the symptom or promises of attention. Count how many repeats have one of these sentences as the action: that is the part a quality system, with the right method behind it, can recover. In the valve body company it was twenty nine repeats out of thirty.

And there is a third calculation, the most convincing when you need to explain the project to a partner: split closed nonconformities by closing time, within seven days, eight to thirty, over thirty, and compute the recurrence rate of each band. In companies where fast closing is one of the quality manager's targets, something counterintuitive almost always happens: nonconformities closed in under a week return more often than the others. It is the proof that the wrong indicator produces the wrong behaviour, with your own numbers rather than a vendor's.

Three clarifications, because the measurement is easy to distort without meaning to. Do not exclude small nonconformities because they are trivial: the burr on the thread was trivial, and it was the most expensive of the year because it kept repeating. Do not count only recorded ones, because on the shop floor some defects are reworked on the spot without anyone opening a form, and those are exactly the repeats nobody sees. And measure by origin, not in total: supplier nonconformities and customer complaints almost always have rates very different from internal ones, and the causes live in different places.

In certified companies that never measured it, the result often sits between twenty five and forty five per cent. For companies inspecting in line the measurement has a useful sibling: the share of process drifts flagged by statistical control that return on the same dimension of the same machine, and the gap between that share and zero does the job the recurrence rate does here.

The four thresholds, and what you can do at each

Below ten per cent: the quality system learns. You are in the minority, and you have already done the hardest part, even if you may not call it that: causes are looked for, actions are verified. Here software pays back mainly in the quality office's time, in documents always aligned and in audits prepared in a few days. You can skip much of what follows and go straight to the choice.

Between ten and twenty five per cent: corrective actions close the symptom. It is the most common band among companies that work well. The method is there, but root cause analysis stops at the first plausible answer, and nobody checks three months later whether the defect has returned. With effectiveness checks made mandatory and a shared defect catalogue, the rate usually drops below twelve per cent within a year.

Above twenty five per cent: the form is filled in for the auditor. With a rate this high no software works miracles, because the problem is not where the nonconformity is recorded but what happens next. The job is a different one: take the ten most expensive repeats, redo the root cause analysis on the floor with the people who work there, and discover that the cause is almost always maintenance that is not done, a parameter nobody fixed or a supplier nobody ever visited. Software comes afterwards, and costs less.

Never measured: you do not know. It is the most common case of all, and it is not a fault: nonconformities live in a register, defects are written in free text, and nobody was ever tasked with comparing this year's with last year's. The first job is not buying a quality system, it is doing this measurement once, over twelve months. One day from one person who knows the product is enough, and the result changes the conversation with any vendor.

The practical rule is just one: before buying a system to manage your nonconformities, get the number that system will have to bring down, because without a starting point nobody will be able to tell you whether it worked. Serious vendors ask you for it themselves. Those who do not will sell you the dashboard.

The nonconformity cycle: where software earns its keep and where it falls short

The six steps of a nonconformity cycle, from recording with a defect code to the lesson carried into the control plan, with what happens when the system leaves a step disconnected from the others

This is the heart of the trade, and the part where demos are most misleading. In the demo the vendor opens a nonconformity, fills in a tidy form with dropdown menus, assigns a corrective action, closes it and shows the updated chart. It is all true. Then the system reaches the shop floor, and the shift supervisor explains that at three in the morning he will not open a twelve field form for a scrapped part, that the cause is known by the maintenance technician and the technician has no login, and that the action "replace the tool every eight hundred parts" was followed for two weeks and then forgotten.

The difference between a system that records nonconformities and one that gets rid of them lies entirely in the link between the steps. Quality management software is worth exactly as much as its way of preventing a step from being skipped, above all the last one, which nobody feels like doing.

The six steps a system has to keep tied together, or the defect returns

Recording, with the defect code. At the moment the defect is seen, by whoever sees it, with part, lot, machine, shift and a code from the catalogue, plus a photo if needed. It must take under a minute, otherwise nobody on the floor does it and defects are reworked in silence. It is the step every system handles and the one where almost all of them ask for too many fields.

Containment. What is done immediately so no more defective parts ship: lot hold, sorting, one hundred per cent inspection on that dimension. It has a deadline, sometimes twenty four hours set by the customer, and it has an exit, the moment extraordinary inspection ends. When the system does not track it, extraordinary inspections become permanent and nobody knows any more why they are done.

Root cause analysis. Why it happened, and why inspection did not stop it. The five whys, the fishbone diagram, the 8D report: the method matters less than doing the analysis with the data from that moment and with the right people. The system helps if, on opening, it puts previous nonconformities with the same code and the actions already tried in front of you. It is the most useful function of the whole software, and few demos show it.

Corrective action. What changes, who does it and by when. A machine, a parameter, an instruction, a supplier, an inspection. An action without a person and a date is not an action, it is a wish, and an action like "remind the operator" should not be savable as the only action on a defect that has already occurred before.

Effectiveness check. After a set time, usually between thirty and ninety days, someone checks that the defect has not returned. If it has, the nonconformity reopens. It is the step that separates a register from a quality system, and the one always skipped, because it comes when everyone's mind is already elsewhere.

The lesson carried into the documents. What was learnt must end up in the control plan, in the process failure mode analysis, in the work instruction, in the machine's maintenance plan. Otherwise the next similar part is born with the same defect. When the cause was maintenance, the link is the one I described in maintenance management software.

The effectiveness check, and why it matters more than closing

Closing is visible, which is why everyone measures it. The effectiveness check is not, and that is where money is lost, because a nonconformity closed with an action that does not work produces a green chart and a shop floor that keeps scrapping. It is worth seeing how the rule is written, because it makes clear where the decision comes in. This is a C# example that compiles and runs: it finds defects repeating on the same part within twelve months and checks whether a corrective action held for ninety days.

using System;
using System.Collections.Generic;
using System.Linq;

public sealed record Nonconformity(int Id, string Part, string Defect, DateOnly OpenedOn, DateOnly? ClosedOn);

public sealed record Recurrence(string Part, string Defect, int Times, DateOnly Latest);

public static class RecurrenceAnalysis
{
    // Same defect on the same part, within twelve months of a nonconformity already closed
    public static IReadOnlyList<Recurrence> Find(IEnumerable<Nonconformity> items)
    {
        var result = new List<Recurrence>();

        foreach (var group in items.GroupBy(n => (n.Part, n.Defect)))
        {
            var ordered = group.OrderBy(n => n.OpenedOn).ToList();
            var repeats = 0;

            for (var i = 1; i < ordered.Count; i++)
            {
                var previous = ordered[i - 1];
                var closedBefore = previous.ClosedOn is { } closed && closed <= ordered[i].OpenedOn;

                if (closedBefore && ordered[i].OpenedOn <= previous.OpenedOn.AddMonths(12))
                {
                    repeats++;
                }
            }

            if (repeats > 0)
            {
                result.Add(new Recurrence(group.Key.Part, group.Key.Defect, repeats + 1, ordered[^1].OpenedOn));
            }
        }

        return result.OrderByDescending(r => r.Times).ToList();
    }

    // The action worked only if the defect did not return in the ninety days after closing
    public static bool ActionEffective(Nonconformity closed, IEnumerable<Nonconformity> later) =>
        closed.ClosedOn is { } date &&
        !later.Any(n => n.Part == closed.Part
                     && n.Defect == closed.Defect
                     && n.OpenedOn > date
                     && n.OpenedOn <= date.AddDays(90));
}

The interesting point is not the code, which is trivial: it is that it only works if the Defect field holds a code and not free text. With descriptions written by hand the same burr becomes four different defects, and the repeat vanishes from the count exactly when you need to see it. That is why the defect catalogue comes before any software. And that is why, when a vendor tells you their product analyses recurrences, the questions to ask are three: which field it recognises them on, who maintains the defect catalogue, and what happens to the nonconformity if the effectiveness check finds the defect back.

And there is a check that costs one day and that I always recommend: take the twenty most expensive nonconformities closed more than six months ago, and for each check whether the defect has returned. If more than five out of twenty have, the problem is not the tool you record them with, it is the method you close them with, and every system you buy will inherit that method. It is the same principle as reconciling operational data with the accounts that I described in management control software, applied to quality.

How far a spreadsheet with the manual in a shared folder takes you

Almost every certified Italian company has the system. A spreadsheet for nonconformities, one for corrective actions, one for supplier evaluation, one for instrument calibration, and a shared folder with the manual, procedures and work instructions, organised by revision. It is not a flaw: it is a system that costs nothing, has passed dozens of audits and is often better kept than software bought and never configured. I have seen companies with a recurrence rate below ten per cent working like this, and others above forty with a system costing one hundred thousand euro. The point is not whether the spreadsheet is enough, but when it stops being enough, because it stops silently: it does not break, it starts costing a little more every month.

The five conditions that bring it down

How many nonconformities you record. Up to a hundred or so a year, a well kept spreadsheet holds and the quality manager remembers almost all of them. Beyond two hundred, and above all with several departments or plants, nobody can see the repeats by reading rows any more, and analyses only happen before audits.

How many people open them. If only the quality office opens them, the spreadsheet is consistent but late, because every defect goes through a note or an email. If shift supervisors, purchasing and customer service open them too, the shared spreadsheet becomes a file locked by someone and a series of copies with different data.

Customers with their own requirements. As long as customers are satisfied with the certificate, the spreadsheet works. When two or three customers demand the 8D report in their format, with twenty four hour containment and access to their portal, every complaint becomes a transcription job in three places, and a late answer weighs more than the defect.

Documents in many revisions. As long as work instructions number a few dozen, a folder by revision holds. When they number hundreds, printed on the floor, and every corrective action changes some of them, at some point someone works with the old revision, and the auditor finds it before you do.

Measurement data coming from machines. If dimensional checks are written by hand on a form and then copied, the spreadsheet holds but the data arrives after the parts. When measuring machines and test benches produce thousands of values a day, the spreadsheet no longer contains them, and process drifts are discovered from scrap instead of from the chart.

My practical rule: if two of these five conditions hold, you are at the limit and have time to get organised. If three or more hold, the spreadsheet is already costing you more than a system, you just pay the cost in repeats, complaints and quality office hours instead of invoices. And I will add something no vendor will tell you: if none or one hold, stay where you are, measure the recurrence rate, write the defect catalogue and postpone the spend by a year.

What you take with you and what you throw away

When you move to a system, the spreadsheet is not thrown away: it is the best history you have. Three years of repeats are in there, even if written in free text, and the first serious job of a project is recoding them with the defect catalogue, so the new system starts knowing what has already been seen. You discover defects repeating for years under different names, and a few corrective actions nobody ever carried out.

What gets thrown away are the fields nobody fills in, the categories invented for an audit six years ago and actions open for three years that no longer concern any part in production. Every field on the new form must be justified by a question it answers. If the new system just reproduces the spreadsheet with nicer graphics and more mandatory fields, you have bought a more expensive spreadsheet, and the shop floor will stop using it within three months.

ERP, document control and quality platform: three different things with the same name

The three families of tools vendors sell as quality software: ERP with lots and returns, document control with revisions, platform for nonconformities and corrective actions, with the order in which to put them together

The three families of tools have three prices and three different returns, and the order in which you put them together decides whether they work. I line them up with what they really cover, because in quotes they arrive mixed together and comparing two offers becomes impossible.

The ERP answers which parts, which lots and which suppliers. Customer returns, incoming lots, goods on hold, traceability from material to shipped product. It almost always exists already and knows quantities very well; it knows defects poorly, because a return in the ERP is a stock movement with a reason code, not a problem with a cause. Without it, though, no nonconformity knows which lot it belongs to.

Document control answers how work should be done. Manual, procedures, work instructions, control plans, with revisions, approvals and distribution to the floor. It is the part the auditor checks first, and for that reason the one many companies spend most on. On its own, though, it does not know whether a procedure has prevented a defect: it preserves the right way of working, it does not check that it is followed. I covered it at length in document management software.

The real quality platform answers what went wrong and whether we got rid of it. Nonconformities, containment, root cause analysis, corrective actions with owner and date, effectiveness checks, supplier evaluation based on real defects, internal audits, complaints. It is the part that produces the result, and the only one working on the recurrence rate.

The sequence that works, and the one you see around

The sequence that works is: defect catalogue and a single nonconformity form, then the cycle with effectiveness checks, then the link with ERP lots, and well built document control last, connected to the actions that change documents. The sequence you see around starts with document control, because that is what the auditor looks at, and produces a typical result: procedures always at the right revision, audits passed without findings, and the same burr on the thread twenty three times a year. The vendor delivered what was promised, and the original question, why do we keep scrapping the same parts, is still unanswered.

There is one honest exception, when certification has just arrived or is about to, nonconformities are few and the real problem is not losing control of documents. In that case starting with document control costs little and has an immediate effect. But the result must be measured by the twelve month recurrence rate, not by the number of procedures uploaded.

What quality management software costs: module, product or custom

Cumulative five year cost of a subscription quality management platform for twenty five users compared with a custom system, showing the break-even point between year three and year four

The figures below are those I see in quotes from Italian companies between five and one hundred million euro in revenue. They are not price lists: they are the order of magnitude against which to compare what you receive, and they mostly help you recognise a quote that is low because it is incomplete.

The quality module of the ERP you already own

Many manufacturing ERPs have a quality module, sometimes called nonconformity management or quality control. Activating it costs between eight and thirty thousand euro, almost all configuration and training. It has an advantage that matters: the nonconformity is born already linked to the lot, the order and the supplier, with no connections to build. It is the route to evaluate first if nonconformities arise mostly at goods receiving and on returns, and if the people opening them already work inside the ERP.

The limit is almost always the cycle. ERP quality modules are designed to record and hold, not to analyse and verify: the effectiveness check is missing or is a date field, root cause analysis is a text box, and nobody on the shop floor opens the ERP. If your recurrence rate is low and the quality office handles nonconformities, it is perfectly fine. If it is high, the module will record the repeats with great precision and remove none of them.

The subscription quality product

These are specialised platforms sold on subscription, with nonconformities, corrective actions, 8D reports, audits, suppliers, documents and often calibration and training, in modules. The bands I see sit between twenty five and eighty euro per user a month, depending on the modules chosen. With twenty five users, across quality, production, purchasing and shift supervisors, that is between seven thousand five hundred and twenty four thousand euro a year in fees. On top comes setup between ten and forty thousand euro, and here is the point.

Setup is almost all workflow configuration, history migration and the ERP connection, and it is the item quotes squeeze to look competitive and that then grows, for two reasons that always repeat: history has to be recoded, and nobody had put that in the budget, and the link with ERP lots requires work the platform vendor does not do and the ERP vendor charges by the day. Then there is a cost that grows over the years: users. The quality system works when shift supervisors use it, and every shift supervisor is a fee. The two questions to ask are always the same: what do users who only open nonconformities cost, and what happens to my history if I stop after three years.

Custom

A quality system built around your company starts at thirty five thousand euro for the core, meaning internal, supplier and customer nonconformities with the defect catalogue, containment, root cause analysis, corrective actions with effectiveness checks, lots and suppliers read from the ERP you already have, and a monthly report. It reaches one hundred and fifty thousand with 8D reports in customers' formats, measurement data read from machines with statistical control, a supplier portal, document control with revisions and an app for the shop floor. Add fifteen to twenty per cent a year in maintenance, which keeps the system alive when you change ERP, when a customer arrives with new requirements or when the standard changes.

It makes sense in three cases, and outside these three it is almost always a waste. When the data needed for analysis lives in systems no product reads without customisation, for example measuring machines, the production system and the ERP together. When users are many, because every shift supervisor across several plants records quality, and the per user fee grows faster than the value. And when the ERP you have works and should be kept, building the missing cycle around it instead of buying a second master file of parts and suppliers to keep in sync, which is the most frequent and most underestimated situation.

The threshold, and the variable that is not financial

The practical rule I use is this: below twenty thousand euro a year of expected total spend, fees and setup included, the product or the ERP module almost always wins. Above it, the calculation has to be redone, because at that level fees plus users growing over five years reach the cost of building, and the difference is all maintenance, which you pay either way. In the chart, for twenty five users, the break-even point falls between year three and year four.

At that point a variable that is not financial matters: how many customers will ask you for something different over five years. If you work, or want to work, with customers who impose their own formats, deadlines and portals, or if you plan to open a second plant, the flexibility of your own system is worth the premium, because every new requirement in a product is a development request with its own timescale. If for ten years your customers have asked for the certificate and little else, the product is the rational choice and custom is a luxury.

Questions to ask before signing, and the ten nonconformity test

Quality software demos are all convincing, because they show a clean nonconformity, a clear action and a chart that updates. The way to come out with real information is to bring your difficult nonconformities and watch how the person in front of you reacts. It is three weeks of work, and worth more than any comparison of feature sheets.

Week one: pick your ten nonconformities

Take ten nonconformities closed in the last year. Five ordinary internal ones, the kind the quality office closes almost by heart. Two that repeated at least three times. One on supplier material discovered in line. One customer complaint with an 8D report in their format. And one finding from the last audit. For each, keep what was written, who opened it, how long it took and, where there was one, the following repeat.

These ten nonconformities have a useful property: the first five tell you whether the system does the easy work, the other five tell you whether it understands how your problems arise. Whoever knows the trade looks at the repeats first and asks how you code defects. Whoever only knows their product opens the five easy ones and shows you the dashboard.

Week two: the same questions for everyone

Ask all vendors in the same order, so the answers can be compared. What is the total cost in year three, with the users you will have in three years, shift supervisors included. How long does a shift supervisor need to open a nonconformity from a phone, with a photo, at the end of a shift. How does it show me, on opening, previous nonconformities with the same defect. What prevents closing without an effectiveness check, and what happens if the defect returns. How does it read lots and suppliers from the ERP I have, with name and version, and who builds the connection. How does it produce the 8D report in my most demanding customer's format. What happens if I stop after three years, in what format my history comes out and what the extraction costs. And can I talk to two companies like mine, without the salesperson present.

The most informative moment is when you ask something off script and watch the reaction. Whoever knows quality tells you straight away that the thing is done with the check, not with an extra field. Whoever does not promises, and then sends a development request after signing.

Week three: the test on nonconformities already closed

This is the test I always recommend and almost nobody does. Give the vendor the ten nonconformities and the defect catalogue, and ask them to load them and run the cycle again with someone from your quality office and a shift supervisor. Then look at three things: whether the system, on opening the second repeat, shows the first one by itself with the action that did not work; whether the shift supervisor manages to open a nonconformity in under a minute without help; whether the 8D report for the customer comes out in their format without being copied.

It is not a feature test, it is a method test: you watch how many questions they ask about how defects arise, which fields they propose removing and how long it takes. If the ten nonconformities pass the cycle and the shift supervisor manages alone, you have found your vendor. If they do not, you have found where the problem lies before paying for it, and the problem is almost never the software: it is a defect catalogue that does not exist or a corrective action nobody in the company has the authority to verify.

Three things to fix before buying anything

There are three jobs that cost little, take a few weeks and without which any quality management software delivers half: writing the defect catalogue, reducing the nonconformity to a single form, and choosing the five numbers you discuss. They must be done before, not after, because afterwards the project has already started and fields are decided by whoever configures, meaning a consultant who has never seen your shop floor at work.

The defect catalogue. Instead of free descriptions, a list of thirty or forty codes, grouped into families, dimensional, surface, material, assembly, documentation, each with a one line definition and a photo where needed. It is written in two or three afternoons with the quality manager, a shift supervisor and a technician, starting from last year's nonconformities. It is the most important of the three, and on its own produces part of the result, because repeats become visible even in the spreadsheet you have now.

The single nonconformity form. One form for internal, supplier and customer issues, with few mandatory fields on opening, part, lot, defect code, who saw it, containment, and the rest filled in at later steps by whoever is responsible. Written on paper, tried on the floor for a month, corrected. At that point you have the specification for any system, and a form shift supervisors actually fill in.

The five numbers you discuss. Choose five indicators and stop there for a year. In most manufacturing companies these work: recurrence rate by origin, cost of poor quality over revenue, customer complaints per million euro shipped, share of corrective actions with an effectiveness check done on time, and supplier nonconformities per hundred lots received. Five numbers looked at every month change the way people work; twenty indicators on a dashboard change nothing, and by the second month nobody looks at them.

I will add a way of starting that is not a job but a choice: begin with one department and internal nonconformities only, and run it for two months before adding suppliers and customers. Companies that start with every module, every department and every supplier at once reach month three with shift supervisors back to paper notes and a quality office copying the notes into the system. The second attempt is much harder, because by then everyone knows the thing did not work.

If your total of the five items was below twenty five thousand euro a year, here is your most urgent problem: these three jobs, not software. Do them, measure the recurrence rate again after six months, and only then look at products.

Where to start

You start with a small first release, because a quality system is not an IT project: it is a project that shifts attention from closing the nonconformity to checking that the defect does not return, and attention shifts well when it shifts a little at a time. The first release that almost always works is this. One department. The single form with the defect catalogue, openable from a phone on the floor in under a minute. Previous nonconformities with the same code shown on opening. Corrective actions with a person and a date. The effectiveness check at ninety days, without which the nonconformity does not close. Lots and suppliers read from the ERP. A single report, on the first Monday of the month, with the recurrence rate, the cost of repeats and overdue checks. Nothing else.

With that scope you are live in a few weeks with a product, in two or three months if you build custom. From then on you redo the recurrence rate measurement every month. If it drops, the project is working. If it does not, the problem is in the defect catalogue, in analyses done without the shop floor or in corrective actions nobody has the authority to enforce, and no extra feature will fix it. Everything else, suppliers on the portal, customer reports, statistical control from machines, document control, is built on a cycle you can trust, and costs less because by then you know what you really need.

The valve body quality manager, in the end, passed that audit with the register rebuilt by hand and bought nothing for the first two months. With a shift supervisor and a technician he wrote a catalogue of thirty six defects, recoded the year's four hundred and ten nonconformities, and redid on the floor the analysis of the ten most expensive repeats. The burr on the thread was not the operators' fault: the deburring tool was replaced on a calendar instead of by part count, and with the extra night shift it wore out sooner. The system came afterwards, built around the ERP the company already had, for one department. In eight months the recurrence rate dropped from thirty eight to fourteen per cent, and the following year's audit was prepared in two days. The nonconformity spreadsheet is still in the shared folder, and nobody opens it.

If you are doing this calculation right now and want to understand which side of the threshold you are on before spending anything, send me two pages: how your departments and quality office are organised today, which customers ask for more than certification and which systems lots, returns and documents come out of, plus the two numbers from the test, meaning nonconformities over the last twelve months and how many of them concern a defect already seen on the same part. In half an hour I will tell you whether yours is a problem of a defect catalogue to write, a method to change, a subscription product, the module of the ERP you already own or custom. In cases where the problem is the method and not the software I will tell you anyway, because a customer who buys the wrong thing comes back angry. You can get in touch to run that calculation together.

If instead you are still framing the problem, three readings that sit around this one. Where repeating defects arise, meaning cycle times and process drifts on the floor, is in production management software. Machines producing scrap because maintenance runs on a calendar instead of when needed are in maintenance management software. And if you want to know how much poor quality really weighs on the margin of each product before deciding where to start, the answer is in management control software.

Frequently asked questions

It depends on the route. The quality module of the ERP you already own costs between eight and thirty thousand euro, almost all configuration. A subscription quality platform costs between twenty five and eighty euro per user a month, plus setup between ten and forty thousand euro that is almost all workflows, history and the ERP connection. A custom system starts at thirty five thousand euro for nonconformities, corrective actions and effectiveness checks connected to the ERP, and reaches one hundred and fifty thousand with customer 8D reports, measurement data from machines, a supplier portal and document control, plus fifteen to twenty per cent a year in maintenance.

No. The standard requires nonconformities to be managed, corrective actions to be verified and documents to be controlled, not the use of software. Many companies have passed audits for years with well kept spreadsheets and a shared folder. Software becomes necessary when nonconformities exceed two or three hundred a year, when people from different departments open them, when customers demand reports in their own formats and deadlines, or when the same defect returns without anyone noticing.

Take the list of nonconformities from the last twelve months, better twenty four, with part or material, supplier or customer and a description of the defect, and give each row a code from a catalogue of thirty or forty defects. Count those with the same code on the same part already recorded in the previous twelve months and divide by the total. Then read the corrective actions of the most frequent repeats: those closed with operator error or operator reminded are the part a quality system with the right method can recover.

The nonconformity is the fact: a part, a lot or a service that does not meet a requirement. The corrective action is what gets changed to remove the cause, with a responsible person and a date, and should not be confused with containment, which only prevents more defective parts from shipping. The effectiveness check is the verification, thirty or ninety days later, that the defect has not returned. It is the step skipped most often and the one that separates a register from a quality system.

When at least three of these five conditions hold: nonconformities exceed two hundred a year or span several departments and plants, people outside the quality office open them, two or more customers demand 8D reports in their own formats and deadlines, work instructions number in the hundreds and change often, or measurement data comes from machines in volumes the spreadsheet cannot hold. With two conditions you are at the limit and have time; with none or one it is better to stay where you are, measure the recurrence rate and write the defect catalogue.

With three jobs that come before any purchase: the defect catalogue, meaning thirty or forty codes with a definition instead of free text descriptions; a single nonconformity form for internal, supplier and customer issues, tried on the shop floor for a month; and five indicators kept unchanged for a year. Then a small first release in one department only, with opening from a phone in under a minute, previous repeats shown on opening and a mandatory effectiveness check at ninety days. Suppliers, customers and documents come after two months.

Below twenty thousand euro a year of total spend the product or the ERP module almost always wins. Custom makes sense in three cases: when the data needed for analysis lives in systems no product reads without customisation, such as measuring machines, production and ERP together; when users are many because shift supervisors across several plants record quality and the per user fee grows faster than the value; and when the ERP you have works and should be kept, building the missing cycle around it. With twenty five users the break-even between the two routes usually falls between year three and year four.

Leave your details in the form below

Matteo Migliore

Matteo Migliore is an entrepreneur and software architect with over 27 years of experience developing .NET-based solutions and evolving enterprise-grade application architectures.

Throughout his career, he has worked with organizations such as Cotonella, Il Sole 24 Ore, FIAT and NATO, leading teams in developing scalable platforms and modernizing complex legacy ecosystems.

He has trained hundreds of developers and supported companies of all sizes in turning software into a competitive advantage, reducing technical debt and achieving measurable business results.

Stai leggendo perché vuoi smettere di rattoppare software fragile.Scopri il metodo per progettare sistemi che reggono nel tempo.