Manufacturing Defect and Quality System Failure
How engineers distinguish a unit that deviated from its own approved design specification from one built correctly to a flawed design, with quality-management tools and the Therac-25 software defect as a case study.
Last updated:
A manufacturing defect is a deviation in a specific production unit from the manufacturer's own approved design specification, occurring during manufacturing, assembly, or handling before sale. It is analytically distinct from a design defect: the design is sound, but this particular unit was not built to it. Proving the claim requires the approved specification, evidence that this unit departed from it, and a causal link between that departure and the failure. Quality management records, including SPC charts, calibration certificates, nonconformance reports, and in-process inspection data, are the primary evidentiary sources.
Two products leave the same assembly line. The design is sound, the engineering drawings specify a good product. But one unit was not built to those drawings: a fastener torque was too low, a weld did not fully fuse, a heat-treatment cycle was interrupted. That deviation is a manufacturing defect, and it is analytically distinct from a design defect in ways that determine the entire investigation.
Establishing a manufacturing defect requires evidence. Not just the broken part in front of you, but the specification the manufacturer approved, the process records that should show how the unit was made, the quality checks that should have caught any deviation, and the inspection data that would confirm or deny that the system worked. This is where the quality management infrastructure of a modern manufacturer becomes central to the litigation.
Software makes all of this harder. Software has no dimensions to measure, no microstructure to examine under SEM, no torque value to compare against a specification. Yet software defects can be manufacturing defects in the legal sense, as the Therac-25 radiation machine demonstrated with lethal clarity in the mid-1980s. A software process that introduced a race condition into a released version of safety-critical code was a failure of the quality system that governed software development, and its consequences were overdoses that killed and seriously injured patients who came for cancer treatment.
By the end of this topic you will be able to:
- Distinguish a manufacturing defect from a design defect and explain why the distinction determines which evidence is relevant.
- Outline the four analytical steps required to establish a manufacturing defect claim: specification, examination, departure, and causation.
- Identify which ISO 9001 clauses generate litigation-relevant records and explain what the engineer looks for in each.
- Explain how Statistical Process Control charts serve as evidence and what an out-of-control signal around the production date means for a case.
- Describe the Therac-25 race condition, the quality system failures that surrounded it, and why the hardware-interlock principle remains foundational in safety-critical design.
- Manufacturing defect
- A deviation in a specific production unit from the manufacturer's approved design specification, occurring during manufacturing, assembly, or handling before sale. The design itself is sound; this unit was not built to it.
- Statistical Process Control (SPC)
- A method of monitoring a manufacturing process in real time using control charts that distinguish normal process variation (common cause) from signals of an out-of-control process (special cause). SPC records become evidence of process state at the time of manufacture.
- ISO 9001
- The international standard for quality management systems published by the International Organization for Standardization. Certification means the organisation has documented and implemented systematic quality processes; it does not guarantee zero defects.
- In-process inspection
- Quality checks performed during production rather than only at final inspection. Dimensional checks, pull-tests, and visual inspection at critical process stages detect non-conformances before they are incorporated into finished products.
- Conforming unit
- A unit that was manufactured in accordance with the approved design specification. A conforming unit may still be involved in an injury if the design itself is defective, but it cannot support a manufacturing defect claim.
- Race condition (software)
- A software defect in which the program's behaviour depends on the timing or sequence of events, such as two processes accessing shared data in an order the programmer did not anticipate. Race conditions are notoriously difficult to detect during testing because they may only appear under specific real-world input sequences.
The manufacturing defect claim: what the engineer must prove
A manufacturing defect is, by definition, a deviation from the manufacturer's own specification. The engineer's task is to show two things in sequence. First, what was the specification? Second, how did this unit depart from it?
- Establish the design specificationObtain engineering drawings, material specifications, assembly procedures, and tolerance tables through discovery. These documents define what a conforming unit should be. Without them, the deviation cannot be measured.
- Examine the unit at issueMeasure, test, and if necessary destructively section the unit to determine its actual properties. Hardness tests, tensile tests, dimensional measurement, metallographic section, and SEM examination all serve to characterise what this unit actually was, as opposed to what the drawing said it should be.
- Identify the departureState specifically how the unit deviates: the weld penetration was 40% of the required depth; the fastener torque was 12 N·m against the specification of 28 N·m; the material hardness was in the wrong range. Specific departures from specific requirements are what courts and juries can evaluate.
- Link the departure to the failureShow causation: this departure, not some other cause, produced the failure mode that injured the plaintiff. The analysis must rule out user abuse, ordinary wear, or damage occurring after the incident to isolate the manufacturing defect as the operative cause.
Process control records as evidence
Modern manufacturing processes generate substantial records. Heat treatment charts record the temperature profile and time of every batch. Welding logs capture current, voltage, and wire feed rate. CMM printouts record measured dimensions of each part. Torque wrench logs show the setting used on each assembly shift. These records are the factual backbone of any manufacturing defect investigation, and they are obtained through discovery or regulatory disclosure.
Statistical Process Control (SPC) records are particularly valuable. A manufacturer running SPC will have control charts plotting a key process variable over time. The rules for these charts, developed by Walter Shewhart and refined by W. Edwards Deming and the ISO 7870 series, identify signals that the process has moved outside its natural variation. If the control chart for the relevant process shows an out-of-control signal on or around the date the plaintiff's unit was manufactured, it is direct evidence that the process was not in specification at that time.
When records are missing or incomplete, courts have drawn adverse inferences in some jurisdictions. A manufacturer that is required by its own quality plan to retain SPC data for five years but cannot produce the records for the relevant period must explain why. The absence of records that should exist is itself a fact that the engineer should flag, not simply note as a limitation.
ISO 9001 and quality management systems in litigation
ISO 9001 is the world's most widely adopted quality management standard. Its current version (ISO 9001:2015) requires organisations to establish documented processes for design, production, measurement, customer complaint handling, corrective action, and management review. Certification by an accredited body confirms that an auditor found the system in place and operating; it does not guarantee that every product leaving the factory is defect-free.
| ISO 9001 element | Litigation relevance | What the engineer looks for |
|---|---|---|
| Design controls (Clause 8.3) | Establishes the approved design specification that defines conformance for manufacturing defect analysis | Design review records, approved drawings, change history, FMEA outputs |
| Production process controls (Clause 8.5) | Shows what process parameters were required and monitored during manufacture | Work instructions, process sheets, monitoring records, SPC charts |
| Measurement and calibration (Clause 7.1.5) | Ensures inspection instruments were accurate when used to pass the plaintiff's unit | Calibration certificates for measurement equipment used on the production date |
| Nonconformance control (Clause 8.7) | Records instances where the process produced out-of-spec product | Nonconformance reports (NCRs), disposition records, concessions and waivers |
| Corrective action (Clause 10.2) | Documents how previously identified defects were addressed | Prior complaints similar to the plaintiff's failure; closed vs. open corrective actions |
In practice, the engineer reviews the quality management system documentation not to evaluate the system in the abstract but to identify what records should exist and then determine whether those records for the plaintiff's unit are present, complete, and consistent with the claimed specification compliance.
Software as a manufactured product: the Therac-25
The Therac-25 was a computer-controlled linear accelerator built by Atomic Energy of Canada Limited (AECL) and introduced in 1982 for radiation therapy. It was designed to operate in two modes: a low-energy electron mode and a high-energy X-ray mode that required a metal target and a beam flattener to be positioned in the beam path. The Therac-25 differed from its predecessors (the Therac-6 and Therac-20) in a critical way: the hardware interlocks that physically prevented the high-energy beam from firing when the target was absent were removed, with software checks substituted instead.
Between June 1985 and January 1987, at least six patients in Canada and the United States received massive radiation overdoses from Therac-25 machines. Three died. The injuries, severe radiation burns, neurological damage, and death, resulted from the machine delivering its high-energy beam in electron mode, without the target assembly in place, at doses orders of magnitude above the therapeutic level. The patients experienced what felt like electric shocks and reported intense heat; many did not understand what had happened to them until days or weeks later when radiation damage became apparent.
The root cause, meticulously documented by Nancy Leveson and Clark Turner in a 1993 IEEE Computer case study, was a race condition in the software controlling the machine. The code included a variable called DATENT that tracked whether the collimator (the beam-shaping assembly) was in the correct position. When a radiotherapy technician entered a treatment mode and then edited it within a narrow time window, the multitasking operating system could set the beam output to high-energy mode before the DATENT flag was correctly updated. The safety check then passed on stale data, and the beam fired at high energy with the target absent.
The Therac-25 case is used in software engineering education worldwide because it illustrates several quality system failures simultaneously. The race condition itself was a software manufacturing defect in the sense that it was a deviation from correct behaviour that the design intent required. But surrounding it were deeper quality system failures: the reliance on a single software check in place of independent hardware interlocks; the absence of adequate testing for timing-dependent failure modes; an error-reporting system that displayed cryptic codes rather than actionable alarms; and an initial investigation process that attributed the first injuries to operator error rather than machine malfunction, delaying identification of the systemic problem.
Connecting quality system analysis to the legal standard
Quality management records are technically dense and procedurally unfamiliar to non-engineers. The forensic engineer's report must translate them into a clear narrative: this is what the specification required; these are the records that should document compliance; here is the specific record that shows non-compliance; and here is how that non-compliance caused the failure that harmed the plaintiff.
- Specification: always anchor the analysis to the manufacturer's own documents. Arguing deviation from an external standard the manufacturer did not adopt is weaker than arguing deviation from the company's own drawing or quality plan.
- Process records: identify which records were required by the quality plan for this product and compare them against what was actually produced. Missing records, records with corrected values, or records outside specification tolerance are all significant.
- Inspection records: in-process and final inspection data show whether the non-conforming feature was checked. If it was checked and passed, either the inspection was performed incorrectly or the measurement equipment was out of calibration, both of which are additional quality system failures.
- Nonconformance reports: prior NCRs for the same feature or process show whether the manufacturer knew this was a recurring issue. A pattern of NCRs is evidence that the quality system identified the problem and the corrective action was ineffective.
For software, the equivalent of process control records are version control logs, test results, code review records, and defect tracking system entries. The question is whether the software release process included adequate testing for timing-dependent and concurrency failure modes, and whether the scope of testing was appropriate for a safety-critical application where the consequences of a software error were lethal.
Distinguishing manufacturing defect from design defect: practical guidance
In many cases the distinction between manufacturing and design defect is blurred at the outset of the investigation. The engineer should resist reaching a conclusion before examining both the failed unit and the specification. A useful initial diagnostic is to ask: if we built another unit exactly to the drawings and tested it under the same conditions, would it fail the same way?
| Indicator | Points toward manufacturing defect | Points toward design defect |
|---|---|---|
| Conforming exemplars tested | Exemplars do not replicate failure under same conditions | Exemplars replicate the failure under similar conditions |
| Physical examination | Specific local deviation found (weld underrun, wrong hardness, missing feature) | No deviation from specification; unit conforms throughout |
| Field failure rate | Isolated failure; no pattern in product line | Pattern of failures across multiple units from same design |
| Prior complaints | No prior complaints for this failure mode | Prior complaints about the same failure mode |
| Design standard review | Product design meets applicable standards | Product design falls below applicable standards or a SAD exists |
In the Therac-25 context, the initial attribution of injuries to operator error is a classic example of prematurely ruling out a manufacturing (software quality) defect. The first technicians to encounter the malfunction reported the error to AECL and were told the machine passed all safety checks. It was only when multiple independent incidents occurred at different facilities that the pattern of a systemic quality failure became undeniable.
A machine part is tested and found to have a hardness significantly above the specification maximum. Which defect theory is most directly applicable?
Key Takeaways
- A manufacturing defect is a deviation of a specific unit from the manufacturer's own approved specification; it is analytically distinct from a design defect, where every conforming unit is unreasonably dangerous.
- Establishing the claim requires three things: the specification the manufacturer approved, evidence of how this unit departed from it, and a causal link between the departure and the failure that harmed the plaintiff.
- SPC charts, calibration certificates, NCRs, and in-process inspection records are the primary evidence sources; missing records that should exist are as significant as records that show out-of-specification results.
- ISO 9001 certification shows a quality management system existed; the forensic investigation determines whether the system was followed and whether it was adequate for the hazard.
- The Therac-25 demonstrates that removing independent hardware safety interlocks and substituting software checks creates catastrophic vulnerability when the software has a race condition, a lesson that remains foundational in safety-critical system design.
What distinguishes a manufacturing defect from a design defect?
What role does Statistical Process Control play in manufacturing defect litigation?
What happened with the Therac-25 radiation machine?
Does ISO 9001 certification guarantee a product is defect-free?
Test yourself on Forensic Engineering with free, timed mocks.
Practice Forensic Engineering questionsSpotted an error in this page? Report a correction or read our editorial standards.