Methodology

A QA Process for Reports That Survives a Busy Month

Peer review is the first thing to go when three engagements land in the same week. What to check, who should check it, and how to make review a state the work moves through rather than a favour somebody does.

Pental12 min read

Every firm agrees that reports should be reviewed before delivery. Almost every firm skips it when the week gets ugly. The gap between the policy and the practice is not a discipline problem, it is a design problem: review is usually structured as a favour asked of a colleague rather than as a step the work has to pass through.

What Review Is Actually Catching

Worth being precise about, because a reviewer who does not know what they are looking for reads the whole document and catches typography.

Class of defectCost if it shipsCost to catch in review
Wrong client name or scope in the documentSevere. Instantly undermines everything else.Seconds
Severity inconsistent with the evidenceHigh. Invites an argument about the score instead of the fix.A minute per finding
Reproduction steps that do not reproduceHigh. The client tries, fails, and stops trusting the finding.Minutes, if the evidence is attached
Remediation that is not actionableModerate. Generates a support conversation.A minute
Evidence containing something it should notSevere. Another client’s hostname, a live credential, a personal record.Seconds, if somebody looks
Coverage gapsModerate to severe, depending on what was missed.A minute against the checklist
Typography and layoutLow.Should be zero, because it should be automated

Notice the last row. If reviewers are spending their attention on formatting, the process is spending its most expensive resource on its cheapest problem.

Make review a state the work moves through, with a queue and an owner, rather than a message asking whether somebody has a minute. Everything that can be checked mechanically should be, so human attention lands on judgement.

Who Should Review

Not the author, obviously. Beyond that there are three workable models and one that does not work.

  • Peer review. Another tester at the same level. Best at technical accuracy, weakest at house consistency, and the only model that scales in a small firm.
  • Senior review. A lead reviews everything. Strongest on consistency and client fit, and the first thing to break when the lead is busy, which is always.
  • Split review. A peer checks the technical content, a lead checks the summary and the client-facing framing. More overhead, and the best quality per hour spent once you are past three or four testers.
  • Rotating "whoever is free". The model that does not work. Nobody develops a reviewer’s eye, and standards drift because there are no standards, only preferences.

The Checklist a Reviewer Should Actually Use

  1. The obvious. Right client, right scope, right dates, right version of the template.
  2. Every finding against its evidence. Does the severity follow? Do the steps reproduce? Is the affected asset list complete?
  3. Evidence hygiene. Anything in a screenshot that should not leave your building, including other clients.
  4. Coverage. The checklist for each phase, complete or with a stated reason.
  5. The summary against the findings. The counts must match, and the themes must be visible in the detail.
  6. The client fit. Read the first page as the recipient. Does it tell them what to do on Monday?

A reviewer who reads the report from the front is reading a document. A reviewer who reads each finding against its evidence is reviewing.

Making It Survive the Bad Week

  • Give review a queue. Work sits in it, visibly, until somebody takes it. Invisible work is skippable work.
  • Time-box it. Twenty minutes per assessment for a competent reviewer with the evidence to hand. If it is taking two hours, the problem is upstream.
  • Comment in place. On the finding, not in an email. Feedback that has to be reconciled from a thread costs more than it saves.
  • Separate release from save. If nothing reaches a client until somebody releases it, skipping review requires a decision rather than an oversight.
  • Feed the library. A reviewer who rewrites a paragraph has produced the better version. Capture it, or you will pay for it again next quarter.

QA is a state rather than a favour: work moves into a review queue, comments land on the finding or the section they concern, and findings reach the client when they are released rather than when they are saved. Reports render deterministically from your own template, so nobody spends review time on layout, and a reviewer’s better wording can be saved straight into the knowledge base so the improvement survives the engagement.

The Measure Worth Watching

  • What proportion of assessments were reviewed before release last month? Anything under a hundred per cent is a process gap, not a people gap.
  • How long does a review take? Rising times mean the upstream work is getting worse.
  • What is being caught? If it is mostly formatting, automate it. If it is mostly severity, your scoring needs a house position.
  • What reached a client and came back? Every one of those is a review criterion you did not have.

The firms with the best reputation for report quality are rarely the ones with the best writers. They are the ones where nothing reaches a client without a second person having read it against the evidence.


Pental Is Built by the People Writing This

Engagement management for testing firms, on a database you own, under your brand, with the AI running on your key.