Fraud Alert
Quality Assurance Consulting: What a QA Maturity Assessment Actually Produces

Quality Assurance Consulting: What a QA Maturity Assessment Actually Produces

Share

Quality assurance consulting is advisory work on how a company tests: a consultant reads the testing already in place, rates it against a published maturity model, and hands back a written assessment with a dated plan for changing it. Two models are published to rate against, the TMMi Foundation's Test Maturity Model integration with its five levels running from Initial to Optimization, and ISO/IEC 33063:2015, which scores process capability against the test processes defined in ISO/IEC/IEEE 29119-2.

Many engagements deliver a deck of observations, a tooling list, and a proposal for delivery work. One question on a first call sorts the field: name the model you will score us against, and show me what evidence you collect for each rating.

The money behind the category is real. According to CISQ, poor software quality cost the United States $2.41 trillion in 2022, and accumulated software technical debt reached roughly $1.52 trillion on top. The expensive part is the defect class that keeps escaping because the process that let it through was never changed.

What does a quality assurance consultant actually do?

The work starts with reading, and the list is short enough to check against a proposal. The current test plan and whatever passes for a test strategy. The defect tracker, exported, covering at least the last three releases. The CI pipeline configuration and the last hundred build results. The automation repository, including the tests that are marked skip. The test data process, including how production data reaches a test environment and who signed that off. The last three release retrospectives.

Interviews should include the developers who fix escaped defects and the release managers who decide what ships.

Then measurement. QASource publishes the metric set on its own consulting page, describing the work as helping businesses "define and measure key quality metrics, such as defect density, defect escape rate, and test coverage". Escape rate decides most engagements, because it is the only one of the three a business stakeholder recognises without translation.

The person doing this is a management consultant with a testing background, and US labour statistics price the role that way. According to the Bureau of Labor Statistics, management analysts had a median annual wage of $101,860 in May 2025, with a bachelor's degree as the typical entry qualification.

Vendors publish roughly the same scope in their own words. DeviQA calls its first stage a review of "business goals, release workflows, test coverage, tools, metrics, documentation, and team responsibilities to identify QA gaps". KiwiQA names its consulting pillars Test Strategy and Governance, Test Process Crafting and Implementation, and Test Process Automation and Technology Solutions. Vervali splits the same ground across a process audit and maturity assessment, a strategy and roadmap, and an implementation and coaching phase, under QA strategy and process consulting; wider engineering advisory work sits under consulting and advisory. Read three of those pages and the scope converges. What varies is what lands on your desk.

What does a QA maturity assessment produce?

An assessment produces a rating, and the rating means something only if you know the scale.

The TMMi Foundation's model has five levels: Initial, Managed, Defined, Measured and Optimization. The wording of levels 2 and 3 is usually where a reader recognises their own company. At level 2, in the Foundation's own words, "the fundamental test approach is established and managed, which may vary from project to project". At level 3, "all projects/teams are following the same standards and procedures throughout the organization". Level 4 adds measurement applied at every stage and level 5 shifts the focus to defect prevention.

The word certified has a specific meaning here. The TMMi Foundation licenses its assessment method for use by accredited TMMi Assessors and Lead Assessors, and publishes a separate document, the TMMi Assessment Method Application Requirements, setting out what an assessment method must comply with to be accredited. Formal and informal assessments both run under that licence. A consultant who offers to assess you against TMMi is almost always doing the informal kind, which is a legitimate exercise and produces no certificate. Establish which one you are buying in the first hour.

The second published scale is ISO/IEC 33063:2015, Process assessment model for software testing. It rates process capability against the test processes in ISO/IEC/IEEE 29119-2, and was published in August 2015 and confirmed in 2021. It fits companies already running process assessments under the ISO 330xx family.

Very few firms hold a formal rating themselves. Kualitatem publishes one, stating on its TMMi services page that it "holds TMMi Level 5 certification". The same page asserts that "Most organizations sit at Level 1 or 2", which is the vendor's own claim with no published basis. Vervali describes the output of its process audit as "a clear maturity score and actionable insights for improvement", which is the informal shape.

Whichever scale is used, the report should carry a rating for each process area, the evidence behind each rating written next to it, a statement of what was examined and what was excluded, and a gap list ordered by something a stakeholder can defend. DeviQA describes its ordering as "a prioritized roadmap with recommended tools, actions, owners, timelines, and success metrics". Owners and timelines are the words to look for in the document you receive. Where the roadmap runs past one team and into how sprints are planned, the work becomes agile testing and QA transformation.

What does a quality assurance consulting engagement hand over on the last day? ISO/IEC/IEEE 29119-3:2021 specifies the test documentation templates for the processes in 29119-2, and its clause structure is the inventory a consulting engagement produces whether it names the standard or not.

At the organisational level sit the test policy (clause 6.2) and organizational test practices (6.3). The test policy is the one most teams have never written. Its own sub-clauses say what belongs in it: objectives of testing, test process, test organization structure, tester training, tester ethics, standards, other relevant policies, measuring the value of testing, test asset archiving and reuse, and test process improvement. A roadmap without a test policy leaves the existing governance unchanged.

At the management level there are the test plan (7.2), the test status report (7.3) and the test completion report (7.4). In the 2021 edition the test strategy sits inside the test plan at 7.2.7, alongside context of testing, assumptions and constraints, stakeholders, testing communication, a risk register, testing activities and estimates, staffing and schedule.

The test completion report is the one worth arguing over in the statement of work, because its clauses commit the vendor to things a sales document avoids: deviations from planned testing, factors that blocked progress, residual risks, reusable test assets, and lessons learned. Residual risks in writing is the clause that ends most disputes before they start.

Below those sit the execution documents, running from the test model specification (8.2) through test case and test procedure specifications, test data requirements, test environment requirements, the two readiness reports, the execution log and the test incident report.

One tell is worth carrying into a vendor call. The 29119 series subsumes IEEE 829 Test Documentation, IEEE 1008, BS 7925-1 and BS 7925-2, so a consultant who hands you an IEEE 829 test plan template in 2026 is working from material the current standard replaced.

The engagement should also leave metric definitions that outlive it: what counts as a defect, what counts as escaped, and what the denominator is for coverage. There is a longer treatment of QA metrics on this site.

What separates a quality assurance consulting engagement from a testing engagement?

Consulting engagement Delivery engagement
What you buy A judgement about your process and a plan to change it Test execution against your product
Who does the day to day work Your own team, after the engagement ends The vendor's engineers, while it runs
Where the knowledge ends up In your documents and your people In the vendor's team
Typical length Weeks Months to years
What arrives on the last day An assessment, a target process, a dated roadmap with named owners Defect reports and a test completion report
How you know it worked A metric that moved against a baseline taken before the work started Defects found before release
Priced against A fixed scope of analysis Time, or an agreed outcome
The usual failure The roadmap carries recommendations and no owner The defect reports pile up and nobody decides

Vervali publishes four to eight weeks for a QA strategy engagement, covering assessment, strategy definition, implementation planning and stakeholder alignment. Kualitatem publishes a shorter first step, a process review it says finishes in days. The spread tracks how much of the reading comes out of your tooling.

The implementation and coaching phase that follows a roadmap is a separate purchase and a longer one. That is where the roadmap turns into process rollout, CI/CD integration, training and a feedback loop, and it is the phase that quietly gets skipped. DeviQA describes its version as implementing the roadmap "independently or with your team, configure processes and tools, train employees, and document the new QA workflows".

Some roadmap lines are engineering projects in their own right. An automation strategy becomes automation testing work with a real backlog and a real maintenance bill. A recommendation to run the suite on every commit becomes DevOps consulting and CI/CD integration. Price both as projects while the roadmap is still being agreed, so nobody discovers in month three that the plan assumed a pipeline you do not have.

Which quality assurance consulting engagement do you actually need?

What you can observe What to ask for What to hold them to
Releases slip and nobody can say which stage ate the time A process audit with cycle time measured per stage A stage by stage breakdown pulled from your own tooling
The same class of defect keeps reaching production A defect escape analysis across the last three releases A named root cause per class, and the process change that closes it
A large automation suite nobody trusts An automation audit covering flake rate, run time and skipped tests The skipped test count on day one and on the last day
Every environment is blocked waiting on test data A test data assessment covering masking, refresh and ownership A written data flow with a named owner at each step
An auditor or a regulator has a date in the calendar A gap assessment against the standard named in the audit scope The clause list, with your evidence mapped to each clause
QA reports no numbers at all Metric definitions and a baseline measurement The baseline, taken before any change is made
You are about to hand testing to an outside firm An assessment of what you have today A scope written by someone who will not be bidding for the delivery work

The test data row is the one that surprises buyers. It is the most common reason an assessment produces nothing actionable, because a consultant cannot redesign a process that stalls before it starts. Where production data is involved a legal question sits underneath the testing question, which is test data management and compliance work; the rules are covered at length in the piece on GDPR-compliant test data management.

An assessment written against a named standard requires a documented method and traceable results. An assessment written against a named standard has to be produced in a way an auditor will accept, which is a question about documented method and traceable results. That is compliance testing ground, and the accreditation that speaks directly to it is ISO/IEC 17025:2017, for testing and calibration laboratory competence. Vervali holds it, alongside CMMI Maturity Level 3, ISO 9001:2015 and ISO/IEC 27001.

Some rows carry a tooling decision inside them. The automation row usually ends in a tool comparison, and there is one on this site covering Selenium, Playwright and Cypress. The slipping releases row often ends somewhere the assessment did not expect, in performance testing that was never scheduled or web application testing coverage that was never built.

How do you tell a real assessment from a sales document?

These checks work on the proposal, and again on the report when it arrives.

Does it name the model. A report that scores you at maturity level 3 without naming TMMi, ISO/IEC 33063 or a model the firm has published itself is scoring you against nothing.

Does it show the evidence behind each rating. A rating is a claim. The evidence is the interview note, the exported query, the pipeline log. Ask for the evidence appendix by name.

Does it state what was excluded. An assessment with no exclusions section is claiming it examined everything, which nobody manages in four weeks.

Do the recommendations carry owners and dates. Every recommendation requires a named individual as the owner.

Does it recommend anything the firm cannot sell you. Every consultancy's roadmap drifts toward the services it happens to sell. A report that tells you to change how your product managers write acceptance criteria, or to stop automating a suite the firm would have been paid to automate, has survived that pull.

What does a quality assurance consultant earn?

According to the Bureau of Labor Statistics, the median annual wage for software quality assurance analysts and testers was $104,300 in May 2025. The lowest 10% earned less than $61,440 and the highest 10% earned more than $167,010. Consulting work sits toward the upper end of that spread, and the closest occupational match for the advisory role, management analysts, carried a median of $101,860 in the same month.

Demand for the underlying skill holds up in the same data. According to the Bureau of Labor Statistics, overall employment of software developers, quality assurance analysts and testers is projected to grow 10 percent from 2025 to 2035, with about 106,100 openings a year across that group.

Salary pages for QA auditors cover two occupations that share three letters. According to the Bureau of Labor Statistics, quality control inspectors, the manufacturing role, had a median annual wage of $48,570 in May 2025, against $104,300 for software quality assurance analysts and testers in the same survey. Check which occupation a salary page describes before pricing a hire against it.

For a buyer the spread has one practical use. A firm quoting a consulting rate that works out below the tenth percentile for a QA analyst is staffing the engagement with delivery people, and the assessment will read like it.

Does quality assurance consulting mean the same thing in life sciences?

No, and the search results for the phrase mix the two professions on one page. One of the firms competing for this exact phrase, The FDA Group, sells quality assurance consulting to life science companies. Its published service areas are GxP audits, QMS process and procedure development, gap assessments, QMS remediation and quality unit resourcing, together with non-conformance and CAPA management, regulatory observation responses and pre-approval inspection readiness.

That profession audits a quality management system against what a regulator expects to see. Software quality assurance consulting assesses a testing process against a test maturity model. The two share a phrase. If the case studies on a vendor page are about batch records and deviations, you are reading a life sciences page and the call will waste an hour.

The seven pillars question comes from the same crossover. The number comes from ISO 9001:2015, which names seven quality management principles, and those are written for a business of any kind.

An anonymised engagement: what a process roadmap changed at a bank

Vervali ran a vulnerability-management transformation for a leading Indian private-sector bank, delivered through a partner relationship. What the engagement changed was the process: how findings were prioritised, the remediation workflow, SLA tracking, the approval path, and centralised reporting. Coverage was 100% of agreed in-scope work.

On the client's own reported figures:

  • Vulnerability noise fell 68%

  • Remediation time improved 30%

  • Mean time to remediate went from over 40 days to under 16

  • Audit-preparation effort fell 80%, from roughly 5 days to 5 hours

  • The high-risk closure rate improved 3.5 times

Read that list as an advisory buyer and the last two lines describe the deliverable. Audit preparation moving from five days to five hours is a reporting change: the evidence an auditor asks for now sits in one place and is generated on demand. A 68% fall in noise is a prioritisation change, and prioritisation is the first item in the engagement scope.

The figure that makes the rest of the list usable is the one taken at the beginning. Mean time to remediate was measured at over 40 days before the engagement and under 16 after it. Put that baseline in the statement of work, and specify that it comes out of your tooling in week one.

A second engagement shows the other common advisory outcome. A UAE SME finance-management platform had its manual and automation testing restructured and reported a 40% reduction in testing time through automation, alongside 98% user satisfaction. Testing time is the metric a QA lead can move without asking anyone else for budget, which makes it a workable first milestone.

Coaching is a deliverable in its own right, and the accessibility work is where that is easiest to see. For NEOGOV, a US provider of on-demand HR software serving more than 6,000 public-sector and education organizations, the engagement audited and remediated over 2,000 URLs and closed over 5,000 accessibility gaps against WCAG 2.0 and Section 508, and the client certified at AA level on the first attempt inside the committed 90-day window. What stayed behind is the part that belongs here: WCAG 2.0 and Section 508 training for the client's own production and QA teams, custom training material, and a self-help capability the client could run afterwards. That is accessibility testing work, and the training is what stops the same gaps reopening two releases later.

Further engagements sit on the case studies page, the banking and payments work under fintech and banking, and the technical half of the bank engagement under security testing.

Where quality assurance consulting engagements fail

The recommendation with no owner. A roadmap addressed to a role produces nothing. Every line needs a person, a date, and a manager who has agreed to release that person's time. The manager's agreement is the part that gets skipped, because it happens outside the engagement and the consultant has no authority to obtain it.

The assessment that never watched a release. Reading artefacts and interviewing people produces a picture of the process a team believes it runs. Watching one release from code freeze to production shows the process it actually runs. The distance between those two pictures is usually where the escaped defects come from, and an assessment that never spent a day in the release channel will miss it. There is a wider piece on this site about why testing fails.

The roadmap that assumes engineering capacity you do not have. Much of a typical roadmap is engineering work: a pipeline that can run the suite, an environment that can be rebuilt from scratch, a data set that can be refreshed on demand. When none of that is costed, month three is when the roadmap stops moving.

The tool line with no adoption plan. Generative AI now appears on nearly every QA roadmap and in very few production pipelines. According to the World Quality Report 2025-26 from Capgemini and Sogeti, a survey of more than 2,000 senior executives across 22 countries, 89% of responding companies are piloting or deploying Gen AI augmented workflows, 37% have any of it in production, and 15% have reached enterprise-wide implementation. Half report that their company lacks AI and machine learning expertise. A roadmap line reading "adopt AI-assisted test generation" with no owner, no pilot scope and no exit criterion will still be open next year.

When quality assurance consulting is the wrong thing to buy

You have no testing to assess. A team with no test plan, no automation and no defect history has nothing to score. Buy execution, run it for two release cycles, then assess what got built.

You already know the answer. If the team already knows the root cause of a gap, spend the budget on the remediation work. Buy the fix.

You cannot get the other managers in a room. A QA roadmap changes what developers, product managers and release managers do all day. If the sponsor's authority stops at the QA team, the lines outside QA sit untouched, and those are usually the lines that were going to move the escape rate.

Your engagement is smaller than the firm's floor. Vervali publishes a $25,000 minimum project size on its Clutch profile, so a short assessment for a small team is work it will decline. Firms with lower published floors take work that size. The same profile reads 4.6 from 11 reviews, a smaller review book than several firms competing on this search, and it is worth reading before a shortlist is drawn up.

If a QA function needs assessing before anything else is decided, Vervali's QA strategy and process consulting practice is where that starts, and the contact page routes to a scoping call.

Frequently Asked Questions

Quick answers to common questions about this article.

Quality assurance consulting is advisory work on how a company tests. A consultant reviews the testing already in place, rates it against a published maturity model such as the TMMi Foundation's five-level Test Maturity Model integration or ISO/IEC 33063:2015, and delivers a written assessment with a prioritised roadmap. The engagement produces documents and decisions, and the testing itself stays with the team that owns the product.

A quality assurance consultant reads your test plan, defect history, CI configuration, automation repository and test data process, interviews the people around the release, measures a small set of quality metrics, and writes an assessment with a roadmap. QASource names the metric set on its own consulting page as defect density, defect escape rate and test coverage. Test execution during the engagement is unusual, because the job is to score the process that produces the tests.

Vervali publishes four to eight weeks for a QA strategy engagement covering assessment, strategy definition, implementation planning and stakeholder alignment. A narrower process review can finish in days. The implementation and coaching phase that follows the roadmap is a separate purchase and runs longer, because it involves process rollout, CI/CD integration and training.

A QA maturity assessment rates a testing function against a published scale. The TMMi Foundation's Test Maturity Model integration has five levels: Initial, Managed, Defined, Measured and Optimization. ISO/IEC 33063:2015 rates process capability against the test processes in ISO/IEC/IEEE 29119-2. A formal TMMi assessment can be run only by an accredited TMMi Assessor or Lead Assessor using the licensed TMMi Assessment Method, and informal assessments use the same model and produce no certificate.

No published software testing standard defines seven pillars of QA. The seven that the question usually points at are the quality management principles named in ISO 9001:2015: customer focus, leadership, engagement of people, process approach, improvement, evidence-based decision making, and relationship management. They govern how a business manages quality of any kind, and a software test strategy still has to be written on top of them.

Two occupations get called QA and the pay differs sharply. According to the Bureau of Labor Statistics, the median annual wage for software quality assurance analysts and testers was $104,300 in May 2025, with the lowest 10% under $61,440 and the highest 10% over $167,010. Quality control inspectors, the manufacturing role, had a median of $48,570 in the same survey. The closest occupational match for consulting work, management analysts, had a median of $101,860.

The pay range is wide because the job spans two very different levels of difficulty. Running a test case is straightforward. Deciding what is worth testing on a product with a fixed release date, and defending that decision to a release manager who wants to ship, takes years to learn. According to the Bureau of Labor Statistics, employment across software developers, quality assurance analysts and testers is projected to grow 10 percent from 2025 to 2035.

ISO/IEC/IEEE 29119-3:2021 gives the document inventory: a test policy and organizational test practices at the organisational level, and a test plan, test status report and test completion report at the management level. Insist on the test completion report, because its clauses commit the vendor to deviations from planned testing, factors that blocked progress, residual risks, reusable test assets and lessons learned. Ask as well for the metric definitions and the baseline measurement taken at the start.

TMMi suits companies that want a recognised maturity level and a defined path between levels, and it has an accreditation scheme behind it. ISO/IEC 33063:2015 suits companies already running process assessments under the ISO 330xx family, because it uses the same measurement framework. Most commercial engagements run an informal assessment against TMMi and never seek certification.

No. Regulatory quality assurance consulting serves life science companies and covers GxP audits, quality management system procedure development, gap assessments, CAPA management and inspection readiness. Software quality assurance consulting assesses a testing process against a test maturity model and hands back a roadmap. The two professions share a phrase and turn up on the same search results, so read the case studies on a vendor page before booking a call.

Need Expert QA or
Development Help?

Our Expertise

contact
  • AI & DevOps Solutions
  • Custom Web & Mobile App Development
  • Manual & Automation Testing
  • Performance & Security Testing
contact-leading

Trusted by 150+ Leading Brands

contact-strong

A Strong Team of 275+ QA and Dev Professionals

contact-work

Worked across 450+ Successful Projects

Collaborate with Vervali