Back to the blog

TOOLS & METHODS

Quality tools in a small shop: two well maintained beat four on principle

In short

FMEA, process capability, internal audits, supplier evaluation: the quality toolbox is well stocked, and a thirty-person shop always ends up being told it should have all of it. A customer demands one, a consultant writes another into the action plan, a standard suggests a third. So they get adopted — on principle.

Here is what fourteen years in small manufacturing companies taught me: every quality tool presupposes a foundation, and adopted before that foundation exists, it produces a record instead of an effect. Two tools genuinely maintained beat four merely declared. The question is which two, and in what order.


A quality tool is never free

That is the starting point, and it gets forgotten because the cost appears on no invoice. A quality tool is not paid for in licences: it is paid for in attention. In a thirty-person shop the quality manager is also the buyer, often the methods engineer, sometimes the inspector, and he is the one who picks up when a customer calls. His attention is the scarcest resource in the company — scarcer than cash, because you can borrow money and you cannot borrow weeks.

Every tool adopted draws on that same budget. An FMEA kept current means meetings. A capability study means measurements in series and a calculation redone. An internal audit programme means planning, conducting, writing and following up. Supplier evaluation means collecting incoming-inspection data that does not exist yet. Four tools is not four times a little work: it is a part-time position nobody created.

And that is the real risk — not missing a tool, but having all of them in appearance and none in truth. A system where four tools exist on paper and not one changes a decision is more fragile than a system with only two, because it has also lost the trust of the people filling it in.

The right question: what does this tool presuppose?

No quality tool works in a vacuum. Each rests on data or facts that must exist before it. That is the only question worth asking before adopting one — and the one no action plan ever asks.

ToolWhat it presupposesWhat it produces without that foundation
FMEADescribed processes and a real failure historyA table of imagined risks, rated by feel, never reopened
Capability (Cp, Cpk)A stable process and a trustworthy measurement systemAn index that is numerically right and physically wrong, reassuring for no reason
Internal auditProcedures that describe the actual workAn exercise where auditor and auditee both know which shelves stay closed
Supplier evaluationNon-conforming receipts recorded, with datesA score that reflects the mood left by the latest incident

Let's take them one at a time, because in each case the waste mechanism is specific — and instructive.

FMEA presupposes a memory

An FMEA is mechanically simple: you list the possible failure modes of a process or product and rate each on three axes — the severity of the effect, how often it occurs, how likely you are to detect it before it ships. The product of the three gives a criticality that ranks the actions.

The method is excellent. Its weakness lies elsewhere: it produces nothing better than what you give it to rate. Occurrence and detection are not opinions, they are measurements. They are read off the history: how many times did this defect ship last year, how many times did we catch it in inspection rather than at the customer.

A shop without that history — because non-conformities get settled over the phone and noted, at best, in a notebook — does what I have seen done everywhere: half a day in a meeting room, six people around a table, ratings assigned by feel. Since nobody wants to underrate a risk, everything ends up between 3 and 5. The criticalities look alike, the ranking the exercise was supposed to produce does not emerge, and the table is filed. It will come back out next year for the audit, unchanged.

One point worth making: ISO 9001 does not require an FMEA. Clause 6.1 asks you to determine risks and opportunities without mandating a method. It is IATF 16949 in automotive, and aerospace requirements, that make FMEA effectively mandatory. Many shops adopt it believing they are answering ISO, when they are answering a requirement that does not apply to them.

An FMEA fed by real history is one of the best tools in quality. Without that history, it is a collective imagination workshop.

Cp/Cpk presupposes stability — and that is where it is decided

This is the subject where I see the most errors, and the most expensive ones, because the result has the appearance of rigour: a number to two decimal places.

A capability index compares the natural spread of a process to the tolerance interval. Cp measures whether the process is tight enough to fit inside the tolerance; Cpk additionally accounts for its centring. A high Cp with a low Cpk says something precise and useful: your process is capable, but it is off-centre — you are producing accurately, beside the target.

The trap sits upstream of the calculation. A capability index only means something on a statistically stable process. Capability describes the spread of a process that does not change behaviour while you observe it. If the tool was wearing, if the machine drifted as it warmed, if the operator changed midway through the lot, then the spread you measured is not the process's: it is a blend of several states. The calculation still completes — that is the danger — and returns a number that predicts nothing.

Three conditions must therefore hold before calculating anything. Stability, verified on a run of consecutive parts rather than a hand-picked sample. Enough measurements for the spread to be estimated honestly: common practice is at least thirty consecutive parts, and fewer than that yields an index that will move on the next lot. And a trustworthy measurement system — because an uncalibrated caliper, or a method that varies between inspectors, injects its own spread into the result. You then measure the instrument's capability as much as the machine's, with no way to separate the two.

Hence the situation so many shops face: a customer demands a Cpk on a dimension, often at the 1.33 threshold that has become the convention. The shop has no characterized process, so it produces thirty parts under the best possible conditions — best operator, freshly set machine, new tool — measures, calculates, and sends back a conforming index. The number is arithmetically true. It does not describe actual production. That is not a capability, it is an attachment.

What comes before capability, then: being able to measure repeatably, with instruments whose calibration is current and demonstrable, and keeping measured values instead of discarding them with the report. A shop that keeps its readings is unknowingly building the raw material of a capability study. A shop that archives PDFs never will.

Internal audit presupposes true procedures

The internal audit — clause 9.2 of ISO 9001 — is the one on this list I would defend most readily, because it is the only one whose direct output is information about yourself. It too has a precondition, and a brutal one: an audit compares a practice to a written reference. If the reference describes work nobody does any more, the audit can learn nothing.

That is the most widespread situation in certified small companies. The procedures were written to obtain the certificate, often with a consultant, in vocabulary that is not the shop's. The real work has moved on since — for the better, usually — but the documents have not. The internal audit then faces a choice nobody states aloud: record a gap between procedure and reality, which means writing a non-conformity against a document you know to be wrong, or look the other way. In most shops, people look the other way. Auditor and auditee both know which shelves will stay closed.

The precondition is therefore not audit competence, it is documentary housekeeping: procedures that describe what actually happens, even if that is less elegant than what is written. A short true procedure can be audited; a long obsolete one cannot, it can only be worked around. And an internal audit that found not a single gap is not proof of a good system — it is proof of an audit that looked for nothing.

Supplier evaluation presupposes incoming data

Clause 8.4 asks you to control externally provided processes, and many shops translate that into an annual scoring grid: quality, delivery, responsiveness, price, a mark out of five for each.

The precondition is almost always missing. A supplier quality score means something only if you know how many lots were rejected, out of how many received, and when. Those figures exist only if non-conforming receipts are recorded as they happen — with the date, the supplier, the reason. Yet in most shops a doubtful lot is settled by a phone call: the supplier replaces it, you re-sort, you move on. Nothing gets written down, because the problem is solved.

A year later, the grid is filled in from memory. And memory is structurally unfair: it keeps the most recent and the loudest incident. The supplier who put you behind schedule last month gets 2 out of 5; the one who has been delivering mediocre work for three years without ever causing a crisis keeps his 4. The grid is complete, the requirement is met, and no purchasing decision will change.

What comes first, then, is recording incoming non-conformities. Not a grid: a habit. Once it exists, the score is calculated instead of estimated — and it becomes arguable with the supplier, which is the whole point.

Why adding a tool often changes nothing

There is a structural reason for all of this, and I have set it out before in writing about quality system maturity: a system's level is the minimum of its axes, never their average. A shop that detects well but does not prevent is not "moderately mature": it sits at the level of its prevention, because that is where problems get out.

The practical consequence is sharp. Adopting a sophisticated tool on an already solid axis changes nothing at all. Running FMEA when non-conformity traceability is absent means reinforcing the prevention axis by building it on nothing — both axes stay at the bottom. The only investment that moves the overall level is the one aimed at the weakest axis. That order is not given by the standard's table of contents, nor by a vendor's catalogue: it is imposed by the actual state of your shop, and it differs from one shop to the next.

It is also why an action plan listing all four tools in parallel is almost always a bad plan. They are not parallel: three of them consume data the fourth produces.

The six-month test

Here is the question I would put to any quality system, mine very much included. For every tool you maintain: what decision changed because of it in the last six months?

A decision is concrete. A setting changed, a supplier dropped, an inspection frequency revised, an investment delayed or brought forward, a training course booked. If the tool produced a document and no decision, it is not a tool: it is a record. It may stay — a certificate has value, and satisfying a customer requirement is a legitimate reason. But it should be filed honestly, in the cost column rather than among the means of steering. A shop that knows which of its tools are records is already more mature than a shop that believes it has them all.

The two I would keep

If I took over quality in a thirty-person shop tomorrow morning, with the time I would realistically have, I would maintain only two — and they are not the flattering ones.

First, recording every non-conformity, internal ones included. Not just customer returns: the reworked part, the re-sorted lot, the doubtful receipt settled on the phone. With a date, a cause, a quantity. It is thankless, it impresses no auditor, and it is the bedrock of everything else: without that history, FMEA is imagination, the supplier score is a recollection, and steering is intuition. It is the only tool on the list that produces data rather than consuming it.

Second, control of the instruments: which instruments exist, which are calibrated, which are overdue, and which instrument a given measurement was taken with. It is the credibility condition for every number the shop produces — including capability figures, if they ever come. A measurement whose instrument cannot be named is not a measurement, it is an assertion.

Those two, held seriously for a year, make the others possible and, more importantly, useful. The other way round never works.

What this means in practice

This is not a plea for doing less. FMEA, capability, internal audit and supplier evaluation are good tools — I would defend all four in front of anyone. It is a plea for adopting them in order, each once its foundation exists, and for being willing to tell a consultant or a customer that the third one will wait.

A shop that maintains two tools and knows why it does not maintain four has a quality system. A shop that has all four in appearance and believes none of them has a binder. The difference does not show in a certification audit. It shows on the day an expensive decision has to be made and you look for something to lean on.

So the question to ask is not "what are we missing?". It is: which of our axes is the weakest, and what is the one tool that genuinely strengthens it? A single tool, carried through to the end, will change your shop more than four launched in the same quarter.

The convictions defended in this article are the ones that guided the development of Asterion Solutions, a suite of trade-specific applications built for small manufacturers who want to structure their quality without piling on administrative work.

Free resource

Checklist: passing your ISO 9001 audit as an SME

Clause by clause, what an auditor will actually ask — plus the 3 questions they almost always ask.