Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

Diagram illustrating the NQA-1 graded approach for safety standards.

NQA-1 Graded Approach: A Clear Guide to Quality Levels in 2026

The NQA-1 graded approach is the mechanism that stops a nuclear quality assurance
programme collapsing under its own weight. Applied well, it directs the heaviest controls at the items
whose failure matters most and lets everything else be governed proportionately. Applied badly, it
becomes the justification for doing less — which is how organisations end up with a finding
against the one item they graded down.

NQA-1 graded approach: how controls vary by safety significance under Part I Requirement 2
How controls differ by safety significance under the NQA-1 graded approach, Part I Requirement 2.

What the NQA-1 graded approach actually says

It sits in Part I, Requirement 2, Quality Assurance Program, alongside the
requirement to establish the programme itself. That placement is deliberate and worth pausing on: the
graded approach is not an exemption bolted onto the standard. It is part of how the programme is
required to be designed.

The principle is that the controls applied to an item, service or activity should be commensurate
with its importance to safety — with the consequences of its failure. A pressure boundary
component and a general-purpose office procedure do not warrant the same design verification, the same
inspection regime or the same records retention, and a standard that demanded otherwise would be
ignored in practice.

The corresponding regulatory hook is 10
CFR 50 Appendix B
Criterion II, Quality Assurance Program, which requires the programme to take
into account the need for special controls and the importance to safety of what is being controlled.
For DOE work the equivalent expectation runs through 10 CFR 830 and DOE O 414.1.

What the NQA-1 graded approach is not

Three misreadings account for most of the trouble.

  • It is not a way to remove requirements. Grading changes the rigour with
    which a requirement is met — the depth of verification, the level of independence, the extent of
    documentation. It does not delete the requirement.
  • It is not a per-document decision. Grading is applied to items, services and
    activities based on safety significance, then flows into the controls. An organisation that grades
    document by document, according to how much effort each would take, is not applying a graded approach
    — it is rationalising.
  • It is not undocumented judgement. The basis for each grading decision has to be
    recorded and reviewable. “We considered it low safety significance” is not a basis; the
    reasoning that led there is.

The asymmetry matters. Grading something up costs you effort. Grading something down and being wrong
costs you a finding, a corrective action, and potentially a re-examination of everything else graded on
the same reasoning. That asymmetry should show in how carefully the downgrades are argued.

How to apply the NQA-1 graded approach in practice

  1. Classify by safety function, not by cost or complexity. The question is what
    happens if this fails, not how expensive or difficult it is.
  2. Define your quality levels explicitly. Two or three levels, each with a written
    definition, and a stated set of controls attached to each. Levels without defined controls are
    labels.
  3. Say what varies by level. Design verification method and independence, inspection
    and test coverage, supplier oversight, records retention, audit frequency. Make that a table, not a
    paragraph.
  4. Record the basis for every classification. One line of reasoning per item, held
    where the auditor can find it.
  5. Review classifications when the design changes. An item’s safety significance is a
    function of the design, and designs change.
  6. Have someone independent challenge the downgrades. If nobody has ever pushed back
    on a grading decision, the process is not working.
Control Higher safety significance Lower safety significance
Design verification Independent review or qualification testing, formally documented Checking by a competent second person, proportionate record
Supplier oversight Audit, source verification, dedication where commercial Evaluation and receipt inspection
Inspection and test Hold points, witness points, full documentation Sampling against defined criteria
Records retention Lifetime records, retrievable for the life of the facility Non-permanent, defined retention period
Software Full Subpart 2.7 lifecycle controls, or dedication Proportionate verification and configuration control

The table is illustrative, not a template to copy. The point is the shape: every row names a control
and says how it differs by level, which is exactly what an auditor will ask you to produce.

Where the graded approach interacts with the rest of the programme

Grading is not a standalone procedure. It sets the input to almost everything else — which
suppliers get audited, which items need
commercial grade dedication,
which software falls under the full weight of
Subpart 2.7, and which
records are lifetime records. If your grading procedure does not name those downstream processes, the
classifications are being made in one place and ignored in another.

Grading, written as a procedure rather than as an intention.

The NQA-1:2024 Nuclear Quality Assurance Toolkit ships 100+ editable MS Office templates including the Graded Approach to Quality Application Procedure, the Quality Assurance Program document it hangs from, and the design control, procurement, inspection, dedication and records procedures the grading feeds — each mapped to its NQA-1 requirement and 10 CFR 50 Appendix B criterion.

Explore the NQA-1 Toolkit →

How auditors test the NQA-1 graded approach

Nobody audits grading in the abstract. An auditor picks an item that has been graded down and works
backwards, and the sequence is predictable enough that you can rehearse it internally.

  1. Show me the classification. Where is it recorded, and is that record controlled?
  2. Show me the basis. What reasoning led to this level, and who was qualified to make
    that call?
  3. Show me the controls that follow. Does what you actually did to this item match
    what your procedure says a level of that classification receives?
  4. Show me another item at the same level. Is the treatment consistent, or is the
    classification being applied differently by different people?
  5. Show me a reclassification. Has anything ever moved level, and did the controls
    move with it?

Question four finds more problems than the rest combined. Inconsistency between two items at the
same level indicates that the classification is a label applied after the fact rather than a decision
that drives behaviour, and that undermines every other grading decision in the programme.

Findings that recur

  • Grading applied to documents rather than to items and activities, which produces
    a procedure hierarchy with no connection to safety significance.
  • Levels defined but controls not differentiated — three quality levels that
    receive identical treatment in practice.
  • The basis recorded as a conclusion. “Quality Level 3” with no
    reasoning is a classification, not a justification.
  • Classifications never revisited after a design change altered what the item
    does.
  • Suppliers graded on commercial importance rather than on the safety significance
    of what they supply — a substitution that feels reasonable and is not defensible.

Where the NQA-1 graded approach saves real money

The point of all this rigour is not paperwork; it is that a well-argued graded approach is what makes
a nuclear quality programme affordable. Supplier audit programmes are the clearest case. Auditing every
supplier annually is unaffordable for most organisations, and auditing them by spend rather than by
safety significance is indefensible. A documented grading that puts audit effort where failure would
matter most gives you a programme that is both cheaper and easier to justify than either alternative
— which is why the NQA-1 graded approach repays being done properly rather than being treated as
a formality.

Frequently asked questions

Where is the graded approach in NQA-1?
Part I, Requirement 2, Quality Assurance Program. It is part of how the programme is designed, not an
exemption applied afterwards.

Can the NQA-1 graded approach remove a requirement entirely?
No. It varies the rigour with which requirements are applied — depth of verification, level of
independence, extent of documentation and records — not whether they apply.

How many quality levels should we define?
Two or three is typical and workable. More levels than you can meaningfully differentiate by control
produce classification arguments rather than proportionate control.

Who approves grading decisions?
Whoever your Quality Assurance Program document says, with the qualification to make the safety
judgement, and with someone independent able to challenge downgrades. The route needs to be written
down before it is used.

Does the graded approach apply to suppliers?
Yes, and it is one of its most useful applications. The oversight applied to a supplier should reflect
the safety significance of what they provide, which is what makes an audit programme affordable.

Where this leaves you

Grading is a design decision about your programme, made once and then honoured everywhere. Define
two or three levels, attach real differences in control to each, record the reasoning behind every
classification, and let someone independent argue with the downgrades. Do that and the programme
becomes both defensible and affordable. Skip the reasoning and you have a set of labels that will not
survive the first auditor who asks why.

References

More on nuclear quality assurance

All of these are covered by the NQA-1 Toolkit, or start with the free ISO templates.

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.