Conformity Sheet
Every regime ยท Every market

ISO 13485:2016 medical device quality management systems

The quality management system standard the medical device regimes lean on: the EU regulations expect a QMS aligned with it, the UK regime recognises it, and the US quality management system regulation incorporates it by reference. Design controls, the medical device file, purchasing controls, production and traceability, complaint handling, reporting to regulatory authorities and corrective action.

licensed text The requirement text and the evidence an inspector accepts sit behind this regime, licensed from a human-verified corpus.

Documents

What it expects in the file

After sale

Duties that continue after sale

Licensed text

Every control, with the requirement text

67 controls. Requirement text and evidence artefacts from a human-verified corpus. Data licensed to Conformity Sheet by The Art of Service Pty Ltd, revocable, non-transferable. Framework page: compliance.theartofservice.com/frameworks/iso-13485-2016.

ISO 13485: 67 controls
ISO 13485 4.1 General requirements

The organization documents a quality management system and maintains its effectiveness in line with the standard and applicable regulatory requirements, documenting the regulatory role or roles it undertakes (for example manufacturer, authorized representative, importer, distributor). It determines the processes the system needs and their application across those roles, applies a risk-based approach to the control of those processes, and determines their sequence and interaction. For each process it determines criteria and methods for effective operation and control, ensures the resources and information needed, implements the actions needed to achieve planned results, monitors, measures and analyses the process, and keeps the records that demonstrate conformity to the standard and compliance with regulatory requirements. Changes to processes are evaluated for their impact on the system and on the devices produced under it and are controlled. Any outsourced process affecting product conformity is monitored and controlled, with the organization retaining responsibility for conformity; controls are proportionate to the risk and to the external party's ability to meet requirements, and include written quality agreements. Procedures are documented for validating computer software used in the system, before initial use and after changes, with an approach proportionate to the risk of the software's use, and records of validation are kept.

Evidence an inspector accepts: Documented statement of the regulatory role(s) the organization undertakes and the jurisdictions concerned; Process map or register showing sequence and interaction of quality management system processes with a risk-based rationale for their control; Process criteria, methods and monitoring results per process
Common gap: Regulatory role never stated, so applicable requirements are inferred rather than identified
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 4.2.1 General

The quality management system documentation includes documented statements of a quality policy and quality objectives, a quality manual, the documented procedures and records the standard requires, the documents and records the organization determines it needs for effective planning, operation and control of its processes, and any other documentation specified by applicable regulatory requirements.

Evidence an inspector accepts: Quality policy and quality objectives as controlled documents; Quality manual; Index of documented procedures mapped to the clauses of the standard that require them
Common gap: Procedures the standard requires to be documented exist only as practice
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 4.2.2 Quality manual

The organization documents a quality manual that states the scope of the quality management system, including details of and justification for any exclusion or non-application, contains or references the documented procedures, and describes the interaction between the processes of the system. The manual outlines the structure of the documentation used in the system.

Evidence an inspector accepts: Quality manual with a scope statement; Justification for each exclusion (clause 7.3 for example) or non-application of a particular requirement; Process interaction diagram or description
Common gap: Exclusion of design and development claimed without a justification tied to the regulatory role
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 4.2.3 Medical device file

For each medical device type or family the organization establishes and maintains one or more files that contain or reference the documents generated to demonstrate conformity to the standard and compliance with applicable regulatory requirements. The file content includes at least a general description of the device, its intended use or purpose and labelling including instructions for use; product specifications; specifications or procedures for manufacturing, packaging, storage, handling and distribution; procedures for measuring and monitoring; and, as appropriate, installation requirements and servicing procedures.

Evidence an inspector accepts: Medical device file index per device type or family; Device description, intended use and labelling including instructions for use; Product, manufacturing, packaging, storage, handling and distribution specifications
Common gap: No file exists per device family; documents are scattered across engineering and production systems with no index
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 4.2.4 Control of documents

Documents required by the quality management system are controlled under a documented procedure that reviews and approves documents for adequacy before issue, reviews, updates and re-approves them, identifies current revision status and changes, makes relevant versions available at points of use, keeps documents legible and identifiable, identifies documents of external origin the organization needs and controls their distribution, prevents deterioration or loss, and prevents unintended use of obsolete documents by identifying them. Changes are reviewed and approved by the original approving function or another designated function with access to the pertinent background. The organization defines the period at least one copy of an obsolete document is retained, which covers at least the lifetime of the device as the organization defines it, is not shorter than the retention of any resulting record, and meets regulatory requirements.

Evidence an inspector accepts: Document control procedure; Approval and revision records for controlled documents; Master list or system showing current revision and distribution
Common gap: Obsolete manufacturing documents discarded before the device lifetime has ended
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 4.2.5 Control of records

Records are maintained as evidence of conformity to requirements and of effective operation of the quality management system. Documented procedures define the controls for identification, storage, security and integrity, retrieval, retention time and disposition of records. The organization defines and implements methods for protecting confidential health information in records according to applicable regulatory requirements. Records remain legible, identifiable and retrievable, and changes to a record remain identifiable. Records are retained for at least the lifetime of the device as the organization defines it, or as regulatory requirements specify, and never less than two years from the device's release by the organization.

Evidence an inspector accepts: Records control procedure with retention schedule; Retention periods justified against defined device lifetime and regulatory minima; Method for protecting confidential health information in complaint, clinical and servicing records
Common gap: Retention set at a flat number of years that is shorter than the device lifetime
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 5.1 Management commitment

Top management provides evidence of its commitment to developing and implementing the quality management system and maintaining its effectiveness by communicating the importance of meeting customer and applicable regulatory requirements, establishing the quality policy, ensuring quality objectives are established, conducting management reviews and ensuring resources are available.

Evidence an inspector accepts: Records of top management communication on customer and regulatory requirements; Quality policy approved by top management; Management review records showing top management participation
Common gap: Commitment asserted in the manual with no evidence of communication or resourcing
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 5.2 Customer focus

Top management ensures that customer requirements and applicable regulatory requirements are determined and met.

Evidence an inspector accepts: Process for identifying customer and regulatory requirements for each device and market; Evidence top management reviews whether they are met (management review inputs on feedback, complaints, regulatory reporting)
Common gap: Regulatory requirements of export markets not identified before supply
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 5.3 Quality policy

Top management ensures the quality policy is applicable to the organization's purpose, includes a commitment to comply with requirements and to maintain the effectiveness of the quality management system, provides a framework for establishing and reviewing quality objectives, is communicated and understood within the organization, and is reviewed for continuing suitability.

Evidence an inspector accepts: Quality policy document with the required commitments; Evidence of communication (training records, display, induction); Evidence of periodic review for suitability (management review record)
Common gap: Policy carries a generic customer-satisfaction commitment with no commitment to maintain effectiveness of the system
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 5.4.1 Quality objectives

Top management ensures quality objectives, including those needed to meet applicable regulatory requirements and requirements for product, are established at relevant functions and levels in the organization, and that they are measurable and consistent with the quality policy.

Evidence an inspector accepts: Documented quality objectives at relevant functions and levels; Measures and targets for each objective; Evidence objectives include regulatory and product requirements
Common gap: Objectives set only at company level
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 5.4.2 Quality management system planning

Top management ensures that planning of the quality management system is carried out to meet the general requirements of 4.1 and the quality objectives, and that the integrity of the system is maintained when changes to it are planned and implemented.

Evidence an inspector accepts: Quality management system plans or the planning record within the manual; Change plans for system changes (new site, new eQMS, reorganization) with an assessment of integrity during transition; Evidence the plan links to 4.1 processes and to the quality objectives
Common gap: Major changes (site move, system migration) executed with no plan for maintaining the system during the transition
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 5.5.1 Responsibility and authority

Top management ensures responsibilities and authorities are defined, documented and communicated within the organization. It documents the interrelation of all personnel who manage, perform and verify work affecting quality and ensures the independence and authority needed to perform those tasks.

Evidence an inspector accepts: Organization chart and role descriptions covering quality-affecting work; Documented interrelation of personnel who manage, perform and verify work; Evidence of independence for verification and release roles
Common gap: Release authority held by a production role with no independence from the work being released
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 5.5.2 Management representative

Top management appoints a member of management who, whatever other responsibilities they hold, has responsibility and authority for ensuring the processes needed for the quality management system are documented, reporting to top management on the effectiveness of the system and any need for improvement, and ensuring awareness of applicable regulatory requirements and quality management system requirements is promoted throughout the organization.

Evidence an inspector accepts: Appointment record naming the management representative and their authority; Reports from the representative to top management on system effectiveness; Evidence of awareness promotion on regulatory requirements (briefings, training, communications)
Common gap: Representative named but reports nothing to top management outside the annual review
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 5.5.3 Internal communication

Top management ensures that appropriate communication processes are established in the organization and that communication takes place about the effectiveness of the quality management system.

Evidence an inspector accepts: Defined communication channels for quality management system matters (meetings, dashboards, bulletins); Records showing effectiveness information (complaints, audit results, objectives) communicated to relevant personnel
Common gap: Quality performance known only to management
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 5.6.1 General

The organization documents procedures for management review. Top management reviews the quality management system at documented planned intervals to ensure its continuing suitability, adequacy and effectiveness, including assessing opportunities for improvement and the need for changes to the system, the quality policy and the quality objectives. Records of management reviews are maintained.

Evidence an inspector accepts: Management review procedure stating the planned interval; Management review records at that interval; Evidence top management assessed suitability, adequacy and effectiveness and considered changes to policy and objectives
Common gap: Interval not documented, so reviews drift
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 5.6.2 Review input

Management review input includes at least information arising from feedback, complaint handling, reporting to regulatory authorities, audits, monitoring and measurement of processes, monitoring and measurement of product, corrective action, preventive action, follow-up actions from previous reviews, changes that could affect the quality management system, recommendations for improvement, and applicable new or revised regulatory requirements.

Evidence an inspector accepts: Management review agenda or input pack covering every listed input; Evidence that regulatory reporting and new or revised regulatory requirements were reviewed; Status of actions from the previous review
Common gap: Regulatory reporting and regulatory change absent from the inputs
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 5.6.3 Review output

Management review output is recorded and includes the input reviewed and any decisions and actions related to improvement needed to maintain the suitability, adequacy and effectiveness of the quality management system and its processes, improvement of product related to customer requirements, changes needed to respond to applicable new or revised regulatory requirements, and resource needs.

Evidence an inspector accepts: Management review minutes recording the inputs reviewed and decisions and actions with owners and dates; Actions on regulatory change and on resource needs; Follow-through of actions in subsequent reviews
Common gap: Minutes record attendance and topics but no decisions
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 6.1 Provision of resources

The organization determines and provides the resources needed to implement the quality management system and maintain its effectiveness, and to meet applicable regulatory and customer requirements.

Evidence an inspector accepts: Resource planning records (budget, headcount, equipment) linked to quality management system and regulatory needs; Management review decisions on resource needs and their implementation
Common gap: Resource decisions taken without reference to regulatory obligations (for example post-market surveillance staffing)
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 6.2 Human resources

Personnel performing work affecting product quality are competent on the basis of appropriate education, training, skills and experience. The organization documents the processes for establishing competence, providing needed training and ensuring awareness. It determines the competence needed for work affecting product quality, provides training or takes other action to achieve or maintain it, evaluates the effectiveness of the action taken (with a method proportionate to the risk of the work), ensures personnel are aware of the relevance and importance of their activities and how they contribute to the quality objectives, and maintains records of education, training, skills and experience.

Evidence an inspector accepts: Documented competence, training and awareness process; Competence requirements per role affecting product quality; Training records with effectiveness evaluation proportionate to risk
Common gap: Effectiveness of training recorded as attendance only
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 6.3 Infrastructure

The organization documents the requirements for the infrastructure needed to achieve product conformity, prevent product mix-up and ensure orderly handling of product, covering as appropriate buildings, workspace and utilities, process equipment (hardware and software) and supporting services such as transport, communication and information systems. It documents maintenance requirements, including maintenance intervals, where maintenance or its absence can affect product quality, applying them as appropriate to production equipment, work environment control and monitoring and measurement equipment, and maintains records of that maintenance.

Evidence an inspector accepts: Documented infrastructure requirements for buildings, equipment and supporting services; Maintenance plan with defined intervals for equipment whose maintenance affects product quality; Maintenance records
Common gap: Maintenance intervals undefined for equipment that affects quality
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 6.4.1 Work environment

The organization documents the requirements for the work environment needed to achieve product conformity. Where work environment conditions can adversely affect product quality it documents the requirements and the procedures to monitor and control the environment. It documents requirements for health, cleanliness and clothing of personnel where contact between personnel and product or environment could affect device safety or performance, and ensures anyone working temporarily under special environmental conditions is competent or supervised by a competent person.

Evidence an inspector accepts: Documented work environment requirements (temperature, humidity, particulate, ESD as applicable); Monitoring and control procedures and monitoring records; Health, cleanliness and clothing requirements for personnel
Common gap: Controlled-area requirements exist but monitoring records show no action when limits are exceeded
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 6.4.2 Contamination control

As appropriate, the organization plans and documents arrangements for controlling contaminated or potentially contaminated product so it does not contaminate the work environment, personnel or product. For sterile medical devices it documents requirements for controlling contamination with microorganisms or particulate matter and maintains the required cleanliness during assembly or packaging.

Evidence an inspector accepts: Documented arrangements for handling contaminated or potentially contaminated product (returns, reprocessed devices); For sterile devices, bioburden and particulate control requirements and cleanliness monitoring during assembly and packaging; Environmental monitoring records for cleanrooms
Common gap: Returned devices handled in the same area as new product with no segregation
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 7.1 Planning of product realization

The organization plans and develops the processes needed for product realization, consistent with the other processes of the quality management system. It documents one or more processes for risk management in product realization and maintains records of risk management activities. In planning it determines, as appropriate, the quality objectives and requirements for the product; the need for product-specific processes, documents and resources including infrastructure and work environment; the verification, validation, monitoring, measurement, inspection and test, handling, storage, distribution and traceability activities specific to the product together with product acceptance criteria; and the records needed to show the realization processes and the product meet requirements. The planning output is documented in a form suited to the organization's way of operating.

Evidence an inspector accepts: Documented risk management process for product realization (typically aligned with ISO 14971) and risk management file records; Quality plans, device master records or equivalent planning output per product; Defined verification, validation, inspection, handling, storage, distribution and traceability activities with acceptance criteria
Common gap: Risk management confined to design and not applied to production and post-production processes
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 7.2.1 Determination of requirements related to product

The organization determines the requirements specified by the customer including delivery and post-delivery activities, requirements not stated by the customer but necessary for the specified or intended use as known, applicable regulatory requirements related to the product, any user training needed to ensure specified performance and safe use of the device, and any additional requirements the organization determines.

Evidence an inspector accepts: Product requirement records per device or order covering customer, intended-use, regulatory and organization-determined requirements; Determination of user training needs for safe use; Post-delivery activity requirements (installation, servicing, support)
Common gap: Regulatory requirements of each destination market not determined at the product level
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 7.2.2 Review of requirements related to product

The organization reviews product requirements before committing to supply (tender submission, acceptance of a contract or order, acceptance of a change) and ensures product requirements are defined and documented, differences from those previously expressed are resolved, applicable regulatory requirements are met, any user training identified is available or planned, and the organization can meet the defined requirements. Records of the review and resulting actions are maintained. Where the customer provides no documented statement the requirements are confirmed before acceptance. When product requirements change, relevant documents are amended and relevant personnel informed.

Evidence an inspector accepts: Contract or order review procedure and records including tender and change review; Evidence regulatory requirements and user training availability were checked in the review; Confirmation records for undocumented customer requirements
Common gap: Standard catalogue orders accepted with no review of the destination market's regulatory requirements
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 7.2.3 Communication

The organization plans and documents arrangements for communicating with customers about product information, enquiries, contracts and order handling including amendments, customer feedback including complaints, and advisory notices. It communicates with regulatory authorities in accordance with applicable regulatory requirements.

Evidence an inspector accepts: Documented customer communication arrangements covering product information, orders, feedback and complaints, and advisory notices; Documented arrangements for communication with regulatory authorities (registrations, reporting, notices); Records of advisory notice communication
Common gap: Advisory notice communication channels undefined until a recall is needed
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 7.3.1 General

The organization documents procedures for design and development. The procedures carry the requirements of 7.3.2 to 7.3.10: how design is planned, how inputs are set and approved, what outputs contain and how they are approved, how reviews, verification, validation and transfer are conducted and recorded, how changes are controlled, and how the design and development file is kept for each device type or family.

Evidence an inspector accepts: Design and development procedure(s) covering planning, inputs, outputs, review, verification, validation, transfer, change control and the design file
Common gap: Design work done to a project management method with no quality management system procedure
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 7.3.2 Design and development planning

The organization plans and controls the design and development of product, maintaining and updating planning documents as the work progresses. The planning documents the design and development stages, the reviews needed at each stage, the verification, validation and design transfer activities appropriate to each stage, responsibilities and authorities, the methods for ensuring traceability of design outputs to design inputs, and the resources needed including the competence of personnel.

Evidence an inspector accepts: Design and development plan per project with stages, reviews, verification, validation and transfer activities; Responsibilities and authorities for design; Traceability method (trace matrix) from outputs to inputs
Common gap: Plan written at project start and never updated
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 7.3.3 Design and development inputs

Inputs relating to product requirements are determined and recorded, including functional, performance, usability and safety requirements according to the intended use, applicable regulatory requirements and standards, applicable outputs of risk management, information from previous similar designs as appropriate, and other requirements essential to the design of the product and its processes. Inputs are reviewed for adequacy and approved, and requirements are complete, unambiguous, able to be verified or validated, and not in conflict with each other.

Evidence an inspector accepts: Design input specification covering functional, performance, usability, safety, regulatory and standards requirements; Risk management outputs incorporated as inputs; Record of input review for adequacy and approval
Common gap: Usability requirements absent from inputs
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 7.3.4 Design and development outputs

Design and development outputs meet the input requirements, provide appropriate information for purchasing, production and service provision, contain or reference product acceptance criteria, and specify the product characteristics essential for its safe and proper use. Outputs are in a form suitable for verification against the inputs and are approved before release, and records of the outputs are maintained.

Evidence an inspector accepts: Design output documents (drawings, specifications, software, labelling, manufacturing and service instructions); Product acceptance criteria; Identification of characteristics essential for safe and proper use
Common gap: Essential characteristics for safe use not identified, so production controls do not prioritise them
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 7.3.5 Design and development review

At suitable stages, systematic reviews of the design and development are performed according to planned and documented arrangements to evaluate the ability of the results to meet requirements and to identify and propose necessary actions. Participants include representatives of the functions concerned with the stage under review and other specialist personnel. Records of the reviews and actions include the identification of the design reviewed, the participants and the date.

Evidence an inspector accepts: Design review records per planned stage identifying the design, participants and date; Evidence of cross-functional participation and specialist input; Actions raised and their closure
Common gap: Reviews held by the design team alone
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 7.3.6 Design and development verification

Design and development verification is performed according to planned and documented arrangements to confirm the outputs meet the input requirements. The organization documents verification plans that include methods, acceptance criteria and, as appropriate, statistical techniques with a rationale for sample size. Where the intended use requires the device to be connected to or interfaced with other devices, verification confirms the outputs meet the inputs when so connected. Records of the results, conclusions and necessary actions are maintained.

Evidence an inspector accepts: Verification plans with methods, acceptance criteria and sample-size rationale; Verification reports and records of actions; Interface or connected-use verification where applicable
Common gap: Sample sizes chosen without a documented rationale
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 7.3.7 Design and development validation

Design and development validation is performed according to planned and documented arrangements to ensure the resulting product can meet the requirements for the specified application or intended use. The organization documents validation plans with methods, acceptance criteria and, as appropriate, statistical techniques with a sample-size rationale. Validation uses representative product (initial production units, batches or equivalents) with the rationale for the choice recorded. As part of validation the organization performs clinical evaluations or performance evaluations in accordance with applicable regulatory requirements, and a device used for such evaluation is not considered released to the customer. Where the intended use requires connection or interface with other devices, validation confirms the requirements are met when so connected. Validation is completed before release of the product for use to the customer, and records of results, conclusions and actions are maintained.

Evidence an inspector accepts: Validation plans with methods, acceptance criteria and sample-size rationale; Rationale for the representative product used; Clinical evaluation or performance evaluation records meeting regulatory requirements
Common gap: Validation performed on prototypes rather than representative production units without a recorded rationale
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 7.3.8 Design and development transfer

The organization documents procedures for transferring design and development outputs to manufacturing, ensuring the outputs are verified as suitable for manufacturing before becoming final production specifications and that production capability can meet product requirements. Results and conclusions of the transfer are recorded.

Evidence an inspector accepts: Design transfer procedure; Transfer records showing outputs verified as manufacturable and production capability demonstrated (process validation, capability studies, pilot runs); Approval of final production specifications
Common gap: Transfer is a hand-over meeting with no verification of manufacturability
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 7.3.9 Control of design and development changes

The organization documents procedures to control design and development changes and determines the significance of each change to function, performance, usability, safety and applicable regulatory requirements for the device and its intended use. Changes are identified and, before implementation, reviewed, verified, validated as appropriate and approved. Review of a change includes evaluating its effect on constituent parts, on product in process or already delivered, on risk management inputs and outputs and on product realization processes. Records of changes, their review and any necessary actions are maintained.

Evidence an inspector accepts: Design change procedure with a significance assessment covering function, performance, usability, safety and regulatory impact; Change records showing review, verification, validation and approval before implementation; Evaluation of effect on parts, product in process, delivered product, risk management and realization processes
Common gap: Significance assessed only for regulatory notification, not for safety or usability
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 7.3.10 Design and development files

The organization maintains a design and development file for each medical device type or family. The file includes or references the records generated to demonstrate conformity to the design and development requirements and the records of design and development changes.

Evidence an inspector accepts: Design and development file index per device type or family; Records or references for planning, inputs, outputs, reviews, verification, validation, transfer and changes; File maintained through the life of the design including post-release changes
Common gap: File closed at launch and not updated with subsequent design changes
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 7.4.1 Purchasing process

The organization documents procedures to ensure purchased product conforms to specified purchasing information. It establishes supplier evaluation and selection criteria based on the supplier's ability to provide product meeting the organization's requirements, the supplier's performance, the effect of the purchased product on device quality, and proportionate to the risk associated with the device. It plans supplier monitoring and re-evaluation, monitors supplier performance against purchasing requirements with results feeding re-evaluation, and addresses non-fulfilment with the supplier proportionate to the risk of the purchased product and to regulatory compliance. Records of evaluation, selection, monitoring, re-evaluation and resulting actions are maintained.

Evidence an inspector accepts: Purchasing procedure; Supplier evaluation and selection criteria with a risk-based rationale; Approved supplier list with evaluation records
Common gap: Every supplier evaluated identically regardless of the risk of what they supply
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 7.4.2 Purchasing information

Purchasing information describes or references the product to be purchased, including as appropriate product specifications, requirements for product acceptance, procedures, processes and equipment, requirements for qualification of supplier personnel, and quality management system requirements. The organization ensures the adequacy of purchasing requirements before communicating them to the supplier. Purchasing information includes, as applicable, a written agreement that the supplier notifies the organization of changes to the purchased product before implementing changes that affect its ability to meet purchase requirements. To the extent needed for traceability, relevant purchasing information is retained as documents and records.

Evidence an inspector accepts: Purchase specifications and purchasing documents with the applicable requirements; Review of purchasing requirements before release to the supplier; Written supplier change-notification agreements
Common gap: No written change-notification agreement with critical suppliers
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 7.4.3 Verification of purchased product

The organization establishes and implements the inspection or other activities needed to ensure purchased product meets purchasing requirements, with the extent of verification based on supplier evaluation results and proportionate to the risk of the purchased product. When it becomes aware of changes to purchased product it determines whether they affect the realization process or the device. Where the organization or its customer intends to verify at the supplier's premises, the intended verification activities and product release method are stated in the purchasing information. Records of verification are maintained.

Evidence an inspector accepts: Incoming inspection plans with a risk-based and supplier-performance-based extent of verification; Verification records; Assessment records for supplier-notified changes
Common gap: Same inspection level for every supplier regardless of performance
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 7.5.1 Control of production and service provision

Production and service provision are planned, carried out, monitored and controlled so that product conforms to specification. As appropriate, production controls include documented procedures and methods for production control, qualification of infrastructure, monitoring and measurement of process parameters and product characteristics, availability and use of monitoring and measuring equipment, defined labelling and packaging operations, and product release, delivery and post-delivery activities. The organization establishes and maintains a record for each device or batch that provides traceability to the extent specified in 7.5.9 and identifies the amount manufactured and the amount approved for distribution, and that record is verified and approved.

Evidence an inspector accepts: Production procedures and work instructions; Infrastructure qualification records; Process parameter and product characteristic monitoring records
Common gap: Batch record does not reconcile quantity manufactured against quantity released
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 7.5.2 Cleanliness of product

The organization documents requirements for cleanliness of product or contamination control of product where product is cleaned by the organization before sterilization or use; where product is supplied non-sterile for cleaning before sterilization or use; where product cannot be cleaned before sterilization or use and its cleanliness is significant in use; where product is supplied for non-sterile use and its cleanliness is significant in use; or where process agents are to be removed during manufacture. Where product is cleaned before sterilization or use under the first two cases, the work environment requirements of 6.4.1 do not apply before the cleaning process.

Evidence an inspector accepts: Documented cleanliness or contamination control requirements for product, stating which of the five cases apply; Cleaning process specifications and validation where cleaning is performed; Process agent residue limits and verification records
Common gap: Case applicability never determined, so requirements are absent for non-sterile devices where cleanliness matters
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 7.5.3 Installation activities

As appropriate, the organization documents requirements for medical device installation and acceptance criteria for verifying installation. Where agreed customer requirements allow installation by an external party other than the organization or its supplier, the organization provides documented installation and verification requirements. Records of installation and verification performed by the organization or its supplier are maintained.

Evidence an inspector accepts: Installation requirements and acceptance criteria per device; Installation and verification records where performed by the organization or its supplier; Documented installation instructions provided to third-party installers
Common gap: Installation verified by the field engineer's sign-off with no acceptance criteria
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 7.5.4 Servicing activities

Where servicing of the device is a specified requirement, the organization documents servicing procedures, reference materials and reference measurements as necessary to perform servicing and verify product requirements are met. It analyses records of servicing performed by the organization or its supplier to determine whether the information is to be handled as a complaint and, as appropriate, as input to improvement. Records of servicing are maintained.

Evidence an inspector accepts: Servicing procedures, reference materials and reference measurements; Servicing records; Analysis of servicing records for complaint determination and improvement input
Common gap: Service reports never reviewed for complaints
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 7.5.5 Particular requirements for sterile medical devices

The organization maintains records of the sterilization process parameters used for each sterilization batch, and those records are traceable to each production batch of medical devices.

Evidence an inspector accepts: Sterilization batch records with process parameters; Traceability from each sterilization batch to the production batches it contained; Release records showing parameter review
Common gap: Contract sterilizer's parameter records not retained by the organization
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 7.5.6 Validation of processes for production and service provision

The organization validates any production or service process whose output cannot be, or is not, verified by subsequent monitoring or measurement, so that deficiencies would only appear after the product is in use or the service delivered. Validation demonstrates the process can achieve planned results consistently. Documented validation procedures cover criteria for review and approval of the process, equipment qualification and personnel qualification, use of specific methods, procedures and acceptance criteria, statistical techniques with a sample-size rationale as appropriate, record requirements, revalidation including its criteria, and approval of process changes. Procedures are documented for validating computer software used in production and service provision before initial use and after changes, proportionate to the risk including the effect on product conformity. Records of results, conclusions and actions are maintained.

Evidence an inspector accepts: Register of processes with a decision on whether each needs validation; Process validation procedure covering all listed elements including revalidation criteria and change approval; Validation protocols and reports (IQ/OQ/PQ or equivalent) with sample-size rationale
Common gap: Processes such as welding, moulding, sealing or software builds treated as verifiable when they are not
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 7.5.7 Particular requirements for validation of processes for sterilization and sterile barrier systems

The organization documents procedures for validating processes for sterilization and for sterile barrier systems. These processes are validated before implementation and following product or process changes as appropriate. Records of results, conclusions and actions from the validation are maintained.

Evidence an inspector accepts: Sterilization validation procedure and validation reports (for example to the relevant sterilization standard for the modality); Sterile barrier system validation procedure and reports covering packaging process, seal integrity and shelf life; Revalidation records after product or process changes
Common gap: Sterile barrier system validated for packaging materials but not for the sealing process
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 7.5.8 Identification

The organization documents procedures for product identification and identifies product by suitable means throughout product realization. It identifies product status with respect to monitoring and measurement requirements throughout production, storage, installation and servicing so that only product that has passed the required inspections and tests, or is released under authorized concession, is dispatched, used or installed. Where regulatory requirements require it, the organization documents a system to assign unique device identification. It documents procedures to ensure returned devices are identified and distinguished from conforming product.

Evidence an inspector accepts: Identification procedure; Inspection and test status identification on product and in records; Unique device identification system documentation where required
Common gap: Status identification relies on location alone
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 7.5.9.1 General

The organization documents procedures for traceability that define the extent of traceability in accordance with applicable regulatory requirements and the records to be maintained.

Evidence an inspector accepts: Traceability procedure stating the extent of traceability per device and jurisdiction; Records supporting traceability from components and batches to distributed product; Evidence of a traceability exercise (mock recall) demonstrating the records work
Common gap: Extent of traceability never defined against regulatory requirements
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 7.5.9.2 Particular requirements for implantable medical devices

For implantable medical devices, traceability records include records of the components, materials and work environment conditions used where these could cause the device not to satisfy its specified safety and performance requirements. The organization requires suppliers of distribution services or distributors to maintain records of distribution that allow traceability and to make them available for inspection. Records of the name and address of the shipping package consignee are maintained.

Evidence an inspector accepts: Traceability records for implantable devices covering components, materials and relevant work environment conditions; Distributor agreements requiring distribution records and their availability for inspection; Consignee name and address records per shipping package
Common gap: Work environment conditions not captured in the device history record for implants
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 7.5.10 Customer property

The organization identifies, verifies, protects and safeguards customer property provided for use in or incorporation into the product while it is under the organization's control or in use by the organization. If customer property is lost, damaged or found unsuitable for use the organization reports it to the customer and maintains records.

Evidence an inspector accepts: Procedure or controls for customer-supplied materials, tooling, data or devices returned for servicing; Verification and identification records for customer property; Reports to customers and records of loss, damage or unsuitability
Common gap: Customer-supplied components accepted without verification
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 7.5.11 Preservation of product

The organization documents procedures for preserving the conformity of product during processing, storage, handling and distribution, applying preservation to the constituent parts of a device. It protects product from alteration, contamination or damage under expected conditions and hazards during processing, storage, handling and distribution by designing and constructing suitable packaging and shipping containers and by documenting requirements for special conditions where packaging alone cannot provide preservation. Where special conditions are required they are controlled and recorded.

Evidence an inspector accepts: Preservation procedure covering processing, storage, handling and distribution; Packaging and shipping container design and qualification records; Documented special condition requirements (temperature, humidity, orientation, shelf life) and monitoring records
Common gap: Cold-chain or humidity requirements documented but not controlled through distribution
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 7.6 Control of monitoring and measuring equipment

The organization determines the monitoring and measurement to be undertaken and the equipment needed to provide evidence of product conformity, and documents procedures to ensure monitoring and measurement can be and are carried out consistently with the requirements. As necessary for valid results, measuring equipment is calibrated or verified at specified intervals or before use against standards traceable to international or national standards (with the basis recorded where none exist), adjusted as necessary with adjustments recorded, identified to show calibration status, safeguarded from adjustments that would invalidate results, and protected from damage and deterioration. Calibration and verification follow documented procedures. When equipment is found nonconforming the organization assesses and records the validity of previous results and takes appropriate action on the equipment and any affected product. Calibration and verification records are maintained. Procedures are documented for validating computer software used for monitoring and measurement, before initial use and after changes, proportionate to the risk including the effect on product conformity, with records of validation results, conclusions and actions.

Evidence an inspector accepts: Monitoring and measuring equipment register with calibration status and intervals; Calibration procedures and records with traceability to national or international standards; Out-of-tolerance investigation records assessing previous results and affected product
Common gap: Out-of-tolerance findings closed by recalibration with no impact assessment on product measured since the last good calibration
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 8.1 General

The organization plans and implements the monitoring, measurement, analysis and improvement processes needed to demonstrate product conformity, ensure conformity of the quality management system and maintain its effectiveness, including determining appropriate methods, statistical techniques among them, and the extent of their use.

Evidence an inspector accepts: Plan of monitoring, measurement, analysis and improvement processes; Documented determination of methods including statistical techniques and where they apply (sampling plans, SPC, trend analysis)
Common gap: Sampling plans used with no statistical rationale
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 8.2.1 Feedback

As one measure of quality management system effectiveness, the organization gathers and monitors information on whether it has met customer requirements, with documented methods for obtaining and using it. It documents procedures for a feedback process that gathers data from production and post-production activities. Feedback information serves as potential input to risk management for monitoring and maintaining product requirements and to the realization and improvement processes. Where regulatory requirements require specific experience to be gained from post-production activities, review of that experience forms part of the feedback process.

Evidence an inspector accepts: Feedback procedure covering production and post-production data sources; Feedback records and analysis; Evidence feedback is used as input to risk management and to improvement
Common gap: Feedback limited to complaints, with no proactive post-production data gathering
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 8.2.2 Complaint handling

The organization documents procedures for timely complaint handling in accordance with applicable regulatory requirements, covering at least the requirements and responsibilities for receiving and recording information, evaluating whether feedback constitutes a complaint, investigating complaints, determining the need to report to regulatory authorities, handling complaint-related product, and determining the need for corrections or corrective actions. Where a complaint is not investigated the justification is documented, and any correction or corrective action arising is documented. Where an investigation finds that activities outside the organization contributed, relevant information is exchanged with the external party. Complaint handling records are maintained.

Evidence an inspector accepts: Complaint handling procedure with timeliness requirements; Complaint records showing receipt, evaluation, investigation, reportability decision, product handling and correction or corrective action decisions; Documented justification where a complaint was not investigated
Common gap: Feedback evaluated for complaint status by sales or service staff with no defined criteria
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 8.2.3 Reporting to regulatory authorities

Where applicable regulatory requirements require notification of complaints that meet specified reporting criteria for adverse events, or issuance of advisory notices, the organization documents procedures for notifying the appropriate regulatory authorities and maintains records of that reporting.

Evidence an inspector accepts: Regulatory reporting procedure covering adverse event reporting criteria and advisory notice notification for each jurisdiction; Records of reports submitted, with timelines against the regulatory deadline; Decision records for events assessed as not reportable
Common gap: Reporting criteria and timelines for every market the device is sold in not identified
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 8.2.4 Internal audit

The organization conducts internal audits at planned intervals to determine whether the quality management system conforms to planned and documented arrangements, the standard, the organization's own requirements and applicable regulatory requirements, and is effectively implemented and maintained. A documented procedure describes responsibilities and requirements for planning and conducting audits and recording and reporting results. The audit programme is planned considering the status and importance of processes and areas and previous audit results; criteria, scope, interval and methods are defined and recorded; auditor selection and audit conduct ensure objectivity and impartiality, and auditors do not audit their own work. Records of audits and results, identifying the processes and areas audited and the conclusions, are maintained. Management of the audited area ensures corrections and corrective actions are taken without undue delay, and follow-up verifies the actions and reports the verification results.

Evidence an inspector accepts: Internal audit procedure; Audit programme showing the basis for frequency and coverage of regulatory requirements; Audit records with criteria, scope, methods, areas audited, conclusions and auditor independence
Common gap: Audit criteria cover the standard but not applicable regulatory requirements
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 8.2.5 Monitoring and measurement of processes

The organization applies suitable methods for monitoring and, as appropriate, measuring the quality management system processes, which demonstrate the processes' ability to achieve planned results. When planned results are not achieved, correction and corrective action are taken as appropriate.

Evidence an inspector accepts: Defined monitoring methods and measures per quality management system process; Process performance records against planned results; Correction and corrective action records where planned results were not met
Common gap: Process measures exist for production only
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 8.2.6 Monitoring and measurement of product

The organization monitors and measures product characteristics to verify product requirements are met, at the applicable stages of product realization, according to planned and documented arrangements and documented procedures. Evidence of conformity to acceptance criteria is maintained, the identity of the person authorizing release is recorded, and as appropriate records identify the test equipment used. Product release and service delivery do not proceed until the planned arrangements are satisfactorily completed. For implantable medical devices the identity of personnel performing any inspection or testing is recorded.

Evidence an inspector accepts: Inspection and test plans per product and stage with acceptance criteria; Inspection and test records showing conformity, releasing authority and test equipment used; Release records showing all planned arrangements completed before release
Common gap: Release approved before all planned tests are complete (for example before sterilization results are back)
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 8.3.1 General

The organization ensures product that does not conform to requirements is identified and controlled to prevent unintended use or delivery. A documented procedure defines the controls and the responsibilities and authorities for identification, documentation, segregation, evaluation and disposition of nonconforming product. Evaluation of a nonconformity includes determining the need for investigation and for notifying any external party responsible. Records of the nature of nonconformities and subsequent action, including the evaluation, any investigation and the rationale for decisions, are maintained.

Evidence an inspector accepts: Nonconforming product procedure defining responsibilities and authorities; Nonconformance records covering identification, segregation, evaluation, investigation decision, external notification decision, disposition and rationale; Evidence of physical segregation or equivalent control
Common gap: Rationale for disposition decisions not recorded
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 8.3.2 Actions in response to nonconforming product detected before delivery

The organization deals with nonconforming product by eliminating the detected nonconformity, precluding its original intended use or application, or authorizing its use, release or acceptance under concession. Nonconforming product is accepted by concession only where justification is provided, approval obtained and applicable regulatory requirements met, and records of the concession and the identity of the person authorizing it are maintained.

Evidence an inspector accepts: Disposition records for each nonconformance; Concession records with justification, approval, regulatory assessment and the authorizing person's identity; Evidence concession approval authority is defined
Common gap: Concessions granted without an assessment against regulatory requirements
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 8.3.3 Actions in response to nonconforming product detected after delivery

When nonconforming product is detected after delivery or after use has started, the organization takes action appropriate to the effects or potential effects of the nonconformity and maintains records of the action. It documents procedures for issuing advisory notices in accordance with applicable regulatory requirements; the procedures can be put into effect at any time, and records of actions relating to advisory notices are maintained.

Evidence an inspector accepts: Records of post-delivery nonconformities and actions taken proportionate to their effect; Advisory notice and field action procedure capable of execution at any time (contacts, distribution records, communication templates); Records of advisory notices issued and actions taken
Common gap: Advisory notice procedure depends on staff or data available only in business hours
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 8.3.4 Rework

The organization performs rework in accordance with documented procedures that take into account the potential adverse effect of the rework on the product, and those procedures undergo the same review and approval as the original procedure. After rework, product is verified to ensure it meets applicable acceptance criteria and regulatory requirements, and records of rework are maintained.

Evidence an inspector accepts: Rework procedures with an assessment of adverse effects on the product; Review and approval records for rework procedures equivalent to the original procedure; Post-rework verification records against acceptance criteria
Common gap: Rework performed to informal instructions
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 8.4 Analysis of data

The organization documents procedures to determine, collect and analyse appropriate data to demonstrate the suitability, adequacy and effectiveness of the quality management system, including determining appropriate methods, statistical techniques and the extent of their use. Analysis includes data from monitoring and measurement and other relevant sources and at minimum input from feedback, conformity to product requirements, characteristics and trends of processes and product including improvement opportunities, suppliers, audits and, as appropriate, service reports. Where the analysis shows the system is not suitable, adequate or effective, it is used as input to improvement under 8.5. Records of the results of analyses are maintained.

Evidence an inspector accepts: Data analysis procedure identifying data sources, methods and statistical techniques; Analysis records covering feedback, product conformity, process and product trends, suppliers, audits and service reports; Evidence analysis outcomes fed improvement actions
Common gap: Data collected and reported with no analysis or trending
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 8.5.1 General

The organization identifies and implements any changes needed to ensure and maintain the continued suitability, adequacy and effectiveness of the quality management system and the safety and performance of the medical device, using the quality policy, quality objectives, audit results, post-market surveillance, analysis of data, corrective actions, preventive actions and management review.

Evidence an inspector accepts: Evidence of changes made to the system or to devices arising from audits, post-market surveillance, data analysis, corrective and preventive action and management review; Improvement actions tracked to completion
Common gap: Improvement limited to closing audit findings
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 8.5.2 Corrective action

The organization takes action to eliminate the causes of nonconformities to prevent recurrence, without undue delay and proportionate to the effects of the nonconformities. A documented procedure defines requirements for reviewing nonconformities including complaints, determining their causes, evaluating the need for action to prevent recurrence, planning, documenting and implementing the action including updating documentation as appropriate, verifying the action does not adversely affect the ability to meet regulatory requirements or the safety and performance of the device, and reviewing the effectiveness of the action. Records of investigation results and action taken are maintained.

Evidence an inspector accepts: Corrective action procedure covering all listed elements; Corrective action records with cause analysis, action plan, verification of no adverse effect on regulatory compliance or device safety and performance, and effectiveness review; Timeliness evidence proportionate to the effect of the nonconformity
Common gap: Corrective action closed on implementation with no effectiveness review
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 8.5.3 Preventive action

The organization determines action to eliminate the causes of potential nonconformities to prevent their occurrence, proportionate to the effects of the potential problems. A documented procedure describes requirements for determining potential nonconformities and their causes, evaluating the need for action to prevent occurrence, planning, documenting and implementing the action including updating documentation as appropriate, verifying the action does not adversely affect the ability to meet regulatory requirements or the safety and performance of the device, and reviewing the effectiveness of the action as appropriate. Records of investigations and action taken are maintained.

Evidence an inspector accepts: Preventive action procedure; Preventive action records showing the potential nonconformity, cause, action, verification of no adverse effect and effectiveness review; Sources used to identify potential nonconformities (trend analysis, feedback, risk management, industry information)
Common gap: Preventive action register empty because potential problems are never sought
ISO 13485:2016 on compliance.theartofservice.com
Categories

Product categories that engage it

See which of your products engage it

Paste the list and every product that engages ISO 13485 in the markets you sell to shows it as a chip, with the documents it expects ticked against what you hold. Five products free, no account.

Build my conformity sheet