Open almost any incoming inspection procedure and you will find an AQL. It will be written into the SOP, referenced in the quality agreement, and cited in the audit response. What you will rarely find is the number that actually bounds how much defective product can reach a patient.

That number is the RQL, and in most procedures nobody has calculated it.

Two numbers, two different people being protected

Every attribute sampling plan has an operating characteristic curve — the probability of accepting a lot, PaP_a, as a function of the lot’s true defect rate pp. Two points on that curve get names.

AQL, the Acceptable Quality Level, is the defect rate the plan will almost always accept. It is paired with the producer’s risk: the probability that a lot genuinely at AQL quality gets rejected anyway. Convention sets this at 5 percent, so Pa=0.95P_a = 0.95 at the AQL.

RQL, the Rejectable Quality Level — also called the LTPD, or the limiting quality in ISO 2859-2 — is the defect rate the plan will almost always reject. It is paired with the consumer’s risk: the probability that a lot at RQL quality gets accepted anyway. Convention sets this at 10 percent, so Pa=0.10P_a = 0.10 at the RQL.

Read those definitions again with a device in mind. The AQL governs how often a supplier is wrongly penalised for good product. It is a commercial parameter. The RQL governs how often genuinely bad product is released to the field, and in a medical device the consumer on the receiving end of that risk is the patient.

One of these is a negotiating position. The other is a safety claim. The industry writes the first into its procedures and leaves the second implicit.

The same AQL, very different odds for the patient

Here is why that matters. These two plans have essentially the same AQL — near 1 percent:

True defect raten = 5, c = 0n = 125, c = 3
0.5%0.9750.996
1.0%0.9510.963
2.0%0.9040.759
5.0%0.7740.124
10.0%0.5900.001
20.0%0.3280.000

At the AQL the two are indistinguishable — 0.951 against 0.963. That is the only place they agree.

Let the process degrade to 5 percent defective and the small plan still accepts about three lots in four, while the larger plan accepts about one in eight. At 10 percent defective, the small plan waves through more than half of all lots; the larger plan essentially never does.

The AQL described both plans correctly and told you nothing whatsoever about the case you care about. It characterises behaviour when the process is behaving. Patient harm comes from the other end of the curve, and only the RQL speaks to it.

An eighteen-fold range hiding behind one number

Fix the AQL at exactly 1.0 percent and solve for the plans that deliver it. Every row below is a legitimate “AQL 1.0%” plan:

Acceptance numberSample sizeAQL (Pa=0.95P_a = 0.95)RQL (Pa=0.10P_a = 0.10)
c = 0n = 51.02%36.90%
c = 1n = 361.00%10.38%
c = 2n = 821.00%6.36%
c = 3n = 1371.00%4.81%
c = 5n = 2631.00%3.50%
c = 10n = 6191.00%2.48%
c = 15n = 1,0061.00%2.11%

Same AQL in every row. The RQL ranges from 2.1 percent to 36.9 percent — a factor of eighteen. Specifying an AQL alone does not constrain patient exposure at all. It constrains only how often you will annoy your supplier.

If a procedure says “sample per AQL 1.0%” and stops there, it has not made a safety statement. It has made a commercial one and left the safety statement to whichever row of the table the sample size happened to land on.

Zero acceptance number does not mean zero defects

The c = 0 plans deserve particular attention, because their name misleads people. “Zero acceptance number” sounds like zero tolerance for defects. What it means is zero defects in the sample:

Sample size (c = 0)AQL (Pa=0.95P_a = 0.95)RQL (Pa=0.10P_a = 0.10)
n = 130.394%16.23%
n = 290.177%7.63%
n = 590.087%3.83%
n = 1160.044%1.97%
n = 2990.017%0.77%

A lot running at 3.8 percent defective passes an n = 59, c = 0 plan one time in ten. On a lot of 10,000 units, that is 380 defective units released, with the plan performing exactly as designed.

This is the same arithmetic that governs zero-failure reliability claims: finding no defects in a sample is weak evidence that the defect rate is low, and how weak depends entirely on the sample size. We covered the general form in putting numbers on risk — with zero failures in nn units the upper bound on the true rate is roughly 3/n3/n, which at n = 59 is about 5 percent. A clean sample and a 5 percent defect rate are entirely compatible.

Choosing an RQL is a risk decision

Because the RQL is the patient-protection parameter, it should be derived from the severity of the harm a defect could cause — not from a sampling table, and certainly not from whatever the previous procedure happened to say.

Risk sets the claim; the claim sets the sample size. A defect that could cause serious injury demands a low RQL and therefore a large sample, or — far better — a process capable enough that you are not leaning on the sample at all.

A defensible procedure states both numbers and both risks: this plan has an AQL of X at 5 percent producer’s risk and an RQL of Y at 10 percent consumer’s risk, and Y was selected because the associated harm is Z. If you cannot write that sentence, you have a sampling table, not a sampling rationale.

What acceptance sampling cannot do

Here is the point that matters most, and the one most often violated in practice.

A sampling plan cannot put quality into a lot. It is a decision rule applied to product that already exists. Every defective unit in that lot was made, paid for, and finished before anyone drew a sample. Sampling can sort, and it can inform, but it creates nothing. Deming made this his third point: cease dependence on inspection to achieve quality.

Even a plan working exactly as intended ships defective product. The average outgoing quality limit makes this concrete — for an n = 125, c = 3 plan it is 1.55 percent, reached when incoming quality sits around 2.3 percent. That is the worst average defect level the plan allows through over the long run, by design, with nothing malfunctioning.

Which brings us to the failure mode worth naming. When a process starts producing defects, the reflex is to tighten the sampling — a bigger sample, a lower acceptance number, a “100 percent inspection” interim measure. None of that is a corrective action. It does not change the defect rate; it changes how many defects you find and how much you pay to find them. Tightened sampling applied to an incapable process is a more expensive way of shipping the same product.

Acceptance sampling is a filter with known and calculable leakage. It belongs downstream of a capable, controlled process, as confirmation. A sampling plan written to compensate for a process that cannot hold its specification is a documented decision to ship defects at a rate someone has calculated but nobody has acknowledged.

Writing a plan you can defend

  1. State the RQL and the consumer’s risk first, and tie the RQL to the severity of harm. This is the patient-protection claim, and it should drive the plan.
  2. State the AQL and the producer’s risk as the commercial parameter it is.
  3. Show the OC curve, or at minimum PaP_a at several defect rates spanning the AQL and the RQL. A reviewer who sees only the AQL cannot evaluate the plan.
  4. Note the lot-size assumption. These figures use the binomial, which assumes the lot is large relative to the sample. Below roughly ten times the sample size the hypergeometric is the correct model and is slightly more forgiving.
  5. Never tighten a sampling plan in response to a capability problem. Fix the process, and let the plan go back to confirming what you already know.

The AQL answers a question about commercial fairness. The RQL answers a question about how much harm can escape. Both belong in the procedure — but only one of them belongs in the risk file, and it is not the one that is usually written down.

Which raises an awkward question for anyone sampling to a standard table, where the AQL is the only number you choose: what RQL are you actually getting? That is the subject of the next article.

Try it on your own plan

You can work all of this out — the AQL, the RQL, the AOQL and the full OC curve — for any combination of nn and cc in our free OC Curve & Sampling Plan Explorer. Enter the plan from your own procedure and read off the RQL it actually delivers. It will also design a plan from a pair of risk points, and put two plans on one axis so the difference between them is visible rather than argued.


Need a sampling plan with a defensible RQL, an OC curve, and a rationale that ties it to risk? See our acceptance sampling services or book a call.

Acceptance SamplingAQLRQLSampling PlansQuality Control