ISO 13485:2016 medical device quality management systems
The quality management system standard the medical device regimes lean on: the EU regulations expect a QMS aligned with it, the UK regime recognises it, and the US quality management system regulation incorporates it by reference. Design controls, the medical device file, purchasing controls, production and traceability, complaint handling, reporting to regulatory authorities and corrective action.
licensed text The requirement text and the evidence an inspector accepts sit behind this regime, licensed from a human-verified corpus.
What it expects in the file
- Technical file
The technical documentation: design, drawings, bill of materials, the standards applied, the conformity assessment route, and the evidence that the requirements are met. Kept for the retention period the regime sets, typically ten years from the last unit placed on the market. - Risk assessment
The documented hazard identification and risk assessment for the product across its lifecycle, updated when the design, the use or the field data changes. - Traceability records
Batch, lot or serial identification on the product, the records that tie a unit to its production and supply chain, and UDI where the device rules require it. - Post-market surveillance plan
The plan and the periodic reports for collecting and acting on field experience, complaints and incidents, in the form the device rules set. - Third-party certificate
A type-examination certificate, notified or approved body certificate, or listing from a recognised laboratory, with the scope and the expiry.
Duties that continue after sale
- Post-market surveillance and periodic reporting
Run the surveillance plan, analyse complaints, trends and field data, and produce the periodic safety update report the device rules require. - Incident reporting
Notify the authority when a product has caused, or could cause, an accident, injury or serious incident, through the channel the regime names (the Safety Business Gateway, the MHRA, the FDA, SaferProducts.gov) and within its clock. - Recall readiness
Be able to identify affected units, reach the customers who hold them, issue a notice in the required form, offer the remedy the rules require, and show the authority the effectiveness of the action. - Traceability records
Keep the records that identify which batch went to which customer, and the identification on the product that lets a unit be traced back, for the retention period the regime sets.
Every control, with the requirement text
67 controls. Requirement text and evidence artefacts from a human-verified corpus. Data licensed to Conformity Sheet by The Art of Service Pty Ltd, revocable, non-transferable. Framework page: compliance.theartofservice.com/frameworks/iso-13485-2016.
ISO 13485: 67 controls
ISO 13485 4.1 General requirementsThe organization documents a quality management system and maintains its effectiveness in line with the standard and applicable regulatory requirements, documenting the regulatory role or roles it undertakes (for example manufacturer, authorized representative, importer, distributor). It determines the processes the system needs and their application across those roles, applies a risk-based approach to the control of those processes, and determines their sequence and interaction. For each process it determines criteria and methods for effective operation and control, ensures the resources and information needed, implements the actions needed to achieve planned results, monitors, measures and analyses the process, and keeps the records that demonstrate conformity to the standard and compliance with regulatory requirements. Changes to processes are evaluated for their impact on the system and on the devices produced under it and are controlled. Any outsourced process affecting product conformity is monitored and controlled, with the organization retaining responsibility for conformity; controls are proportionate to the risk and to the external party's ability to meet requirements, and include written quality agreements. Procedures are documented for validating computer software used in the system, before initial use and after changes, with an approach proportionate to the risk of the software's use, and records of validation are kept.
Common gap: Regulatory role never stated, so applicable requirements are inferred rather than identified
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 4.2.1 GeneralThe quality management system documentation includes documented statements of a quality policy and quality objectives, a quality manual, the documented procedures and records the standard requires, the documents and records the organization determines it needs for effective planning, operation and control of its processes, and any other documentation specified by applicable regulatory requirements.
Common gap: Procedures the standard requires to be documented exist only as practice
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 4.2.2 Quality manualThe organization documents a quality manual that states the scope of the quality management system, including details of and justification for any exclusion or non-application, contains or references the documented procedures, and describes the interaction between the processes of the system. The manual outlines the structure of the documentation used in the system.
Common gap: Exclusion of design and development claimed without a justification tied to the regulatory role
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 4.2.3 Medical device fileFor each medical device type or family the organization establishes and maintains one or more files that contain or reference the documents generated to demonstrate conformity to the standard and compliance with applicable regulatory requirements. The file content includes at least a general description of the device, its intended use or purpose and labelling including instructions for use; product specifications; specifications or procedures for manufacturing, packaging, storage, handling and distribution; procedures for measuring and monitoring; and, as appropriate, installation requirements and servicing procedures.
Common gap: No file exists per device family; documents are scattered across engineering and production systems with no index
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 4.2.4 Control of documentsDocuments required by the quality management system are controlled under a documented procedure that reviews and approves documents for adequacy before issue, reviews, updates and re-approves them, identifies current revision status and changes, makes relevant versions available at points of use, keeps documents legible and identifiable, identifies documents of external origin the organization needs and controls their distribution, prevents deterioration or loss, and prevents unintended use of obsolete documents by identifying them. Changes are reviewed and approved by the original approving function or another designated function with access to the pertinent background. The organization defines the period at least one copy of an obsolete document is retained, which covers at least the lifetime of the device as the organization defines it, is not shorter than the retention of any resulting record, and meets regulatory requirements.
Common gap: Obsolete manufacturing documents discarded before the device lifetime has ended
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 4.2.5 Control of recordsRecords are maintained as evidence of conformity to requirements and of effective operation of the quality management system. Documented procedures define the controls for identification, storage, security and integrity, retrieval, retention time and disposition of records. The organization defines and implements methods for protecting confidential health information in records according to applicable regulatory requirements. Records remain legible, identifiable and retrievable, and changes to a record remain identifiable. Records are retained for at least the lifetime of the device as the organization defines it, or as regulatory requirements specify, and never less than two years from the device's release by the organization.
Common gap: Retention set at a flat number of years that is shorter than the device lifetime
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 5.1 Management commitmentTop management provides evidence of its commitment to developing and implementing the quality management system and maintaining its effectiveness by communicating the importance of meeting customer and applicable regulatory requirements, establishing the quality policy, ensuring quality objectives are established, conducting management reviews and ensuring resources are available.
Common gap: Commitment asserted in the manual with no evidence of communication or resourcing
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 5.2 Customer focusTop management ensures that customer requirements and applicable regulatory requirements are determined and met.
Common gap: Regulatory requirements of export markets not identified before supply
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 5.3 Quality policyTop management ensures the quality policy is applicable to the organization's purpose, includes a commitment to comply with requirements and to maintain the effectiveness of the quality management system, provides a framework for establishing and reviewing quality objectives, is communicated and understood within the organization, and is reviewed for continuing suitability.
Common gap: Policy carries a generic customer-satisfaction commitment with no commitment to maintain effectiveness of the system
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 5.4.1 Quality objectivesTop management ensures quality objectives, including those needed to meet applicable regulatory requirements and requirements for product, are established at relevant functions and levels in the organization, and that they are measurable and consistent with the quality policy.
Common gap: Objectives set only at company level
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 5.4.2 Quality management system planningTop management ensures that planning of the quality management system is carried out to meet the general requirements of 4.1 and the quality objectives, and that the integrity of the system is maintained when changes to it are planned and implemented.
Common gap: Major changes (site move, system migration) executed with no plan for maintaining the system during the transition
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 5.5.1 Responsibility and authorityTop management ensures responsibilities and authorities are defined, documented and communicated within the organization. It documents the interrelation of all personnel who manage, perform and verify work affecting quality and ensures the independence and authority needed to perform those tasks.
Common gap: Release authority held by a production role with no independence from the work being released
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 5.5.2 Management representativeTop management appoints a member of management who, whatever other responsibilities they hold, has responsibility and authority for ensuring the processes needed for the quality management system are documented, reporting to top management on the effectiveness of the system and any need for improvement, and ensuring awareness of applicable regulatory requirements and quality management system requirements is promoted throughout the organization.
Common gap: Representative named but reports nothing to top management outside the annual review
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 5.5.3 Internal communicationTop management ensures that appropriate communication processes are established in the organization and that communication takes place about the effectiveness of the quality management system.
Common gap: Quality performance known only to management
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 5.6.1 GeneralThe organization documents procedures for management review. Top management reviews the quality management system at documented planned intervals to ensure its continuing suitability, adequacy and effectiveness, including assessing opportunities for improvement and the need for changes to the system, the quality policy and the quality objectives. Records of management reviews are maintained.
Common gap: Interval not documented, so reviews drift
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 5.6.2 Review inputManagement review input includes at least information arising from feedback, complaint handling, reporting to regulatory authorities, audits, monitoring and measurement of processes, monitoring and measurement of product, corrective action, preventive action, follow-up actions from previous reviews, changes that could affect the quality management system, recommendations for improvement, and applicable new or revised regulatory requirements.
Common gap: Regulatory reporting and regulatory change absent from the inputs
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 5.6.3 Review outputManagement review output is recorded and includes the input reviewed and any decisions and actions related to improvement needed to maintain the suitability, adequacy and effectiveness of the quality management system and its processes, improvement of product related to customer requirements, changes needed to respond to applicable new or revised regulatory requirements, and resource needs.
Common gap: Minutes record attendance and topics but no decisions
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 6.1 Provision of resourcesThe organization determines and provides the resources needed to implement the quality management system and maintain its effectiveness, and to meet applicable regulatory and customer requirements.
Common gap: Resource decisions taken without reference to regulatory obligations (for example post-market surveillance staffing)
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 6.2 Human resourcesPersonnel performing work affecting product quality are competent on the basis of appropriate education, training, skills and experience. The organization documents the processes for establishing competence, providing needed training and ensuring awareness. It determines the competence needed for work affecting product quality, provides training or takes other action to achieve or maintain it, evaluates the effectiveness of the action taken (with a method proportionate to the risk of the work), ensures personnel are aware of the relevance and importance of their activities and how they contribute to the quality objectives, and maintains records of education, training, skills and experience.
Common gap: Effectiveness of training recorded as attendance only
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 6.3 InfrastructureThe organization documents the requirements for the infrastructure needed to achieve product conformity, prevent product mix-up and ensure orderly handling of product, covering as appropriate buildings, workspace and utilities, process equipment (hardware and software) and supporting services such as transport, communication and information systems. It documents maintenance requirements, including maintenance intervals, where maintenance or its absence can affect product quality, applying them as appropriate to production equipment, work environment control and monitoring and measurement equipment, and maintains records of that maintenance.
Common gap: Maintenance intervals undefined for equipment that affects quality
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 6.4.1 Work environmentThe organization documents the requirements for the work environment needed to achieve product conformity. Where work environment conditions can adversely affect product quality it documents the requirements and the procedures to monitor and control the environment. It documents requirements for health, cleanliness and clothing of personnel where contact between personnel and product or environment could affect device safety or performance, and ensures anyone working temporarily under special environmental conditions is competent or supervised by a competent person.
Common gap: Controlled-area requirements exist but monitoring records show no action when limits are exceeded
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 6.4.2 Contamination controlAs appropriate, the organization plans and documents arrangements for controlling contaminated or potentially contaminated product so it does not contaminate the work environment, personnel or product. For sterile medical devices it documents requirements for controlling contamination with microorganisms or particulate matter and maintains the required cleanliness during assembly or packaging.
Common gap: Returned devices handled in the same area as new product with no segregation
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 7.1 Planning of product realizationThe organization plans and develops the processes needed for product realization, consistent with the other processes of the quality management system. It documents one or more processes for risk management in product realization and maintains records of risk management activities. In planning it determines, as appropriate, the quality objectives and requirements for the product; the need for product-specific processes, documents and resources including infrastructure and work environment; the verification, validation, monitoring, measurement, inspection and test, handling, storage, distribution and traceability activities specific to the product together with product acceptance criteria; and the records needed to show the realization processes and the product meet requirements. The planning output is documented in a form suited to the organization's way of operating.
Common gap: Risk management confined to design and not applied to production and post-production processes
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 7.2.1 Determination of requirements related to productThe organization determines the requirements specified by the customer including delivery and post-delivery activities, requirements not stated by the customer but necessary for the specified or intended use as known, applicable regulatory requirements related to the product, any user training needed to ensure specified performance and safe use of the device, and any additional requirements the organization determines.
Common gap: Regulatory requirements of each destination market not determined at the product level
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 7.2.2 Review of requirements related to productThe organization reviews product requirements before committing to supply (tender submission, acceptance of a contract or order, acceptance of a change) and ensures product requirements are defined and documented, differences from those previously expressed are resolved, applicable regulatory requirements are met, any user training identified is available or planned, and the organization can meet the defined requirements. Records of the review and resulting actions are maintained. Where the customer provides no documented statement the requirements are confirmed before acceptance. When product requirements change, relevant documents are amended and relevant personnel informed.
Common gap: Standard catalogue orders accepted with no review of the destination market's regulatory requirements
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 7.2.3 CommunicationThe organization plans and documents arrangements for communicating with customers about product information, enquiries, contracts and order handling including amendments, customer feedback including complaints, and advisory notices. It communicates with regulatory authorities in accordance with applicable regulatory requirements.
Common gap: Advisory notice communication channels undefined until a recall is needed
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 7.3.1 GeneralThe organization documents procedures for design and development. The procedures carry the requirements of 7.3.2 to 7.3.10: how design is planned, how inputs are set and approved, what outputs contain and how they are approved, how reviews, verification, validation and transfer are conducted and recorded, how changes are controlled, and how the design and development file is kept for each device type or family.
Common gap: Design work done to a project management method with no quality management system procedure
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 7.3.2 Design and development planningThe organization plans and controls the design and development of product, maintaining and updating planning documents as the work progresses. The planning documents the design and development stages, the reviews needed at each stage, the verification, validation and design transfer activities appropriate to each stage, responsibilities and authorities, the methods for ensuring traceability of design outputs to design inputs, and the resources needed including the competence of personnel.
Common gap: Plan written at project start and never updated
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 7.3.3 Design and development inputsInputs relating to product requirements are determined and recorded, including functional, performance, usability and safety requirements according to the intended use, applicable regulatory requirements and standards, applicable outputs of risk management, information from previous similar designs as appropriate, and other requirements essential to the design of the product and its processes. Inputs are reviewed for adequacy and approved, and requirements are complete, unambiguous, able to be verified or validated, and not in conflict with each other.
Common gap: Usability requirements absent from inputs
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 7.3.4 Design and development outputsDesign and development outputs meet the input requirements, provide appropriate information for purchasing, production and service provision, contain or reference product acceptance criteria, and specify the product characteristics essential for its safe and proper use. Outputs are in a form suitable for verification against the inputs and are approved before release, and records of the outputs are maintained.
Common gap: Essential characteristics for safe use not identified, so production controls do not prioritise them
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 7.3.5 Design and development reviewAt suitable stages, systematic reviews of the design and development are performed according to planned and documented arrangements to evaluate the ability of the results to meet requirements and to identify and propose necessary actions. Participants include representatives of the functions concerned with the stage under review and other specialist personnel. Records of the reviews and actions include the identification of the design reviewed, the participants and the date.
Common gap: Reviews held by the design team alone
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 7.3.6 Design and development verificationDesign and development verification is performed according to planned and documented arrangements to confirm the outputs meet the input requirements. The organization documents verification plans that include methods, acceptance criteria and, as appropriate, statistical techniques with a rationale for sample size. Where the intended use requires the device to be connected to or interfaced with other devices, verification confirms the outputs meet the inputs when so connected. Records of the results, conclusions and necessary actions are maintained.
Common gap: Sample sizes chosen without a documented rationale
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 7.3.7 Design and development validationDesign and development validation is performed according to planned and documented arrangements to ensure the resulting product can meet the requirements for the specified application or intended use. The organization documents validation plans with methods, acceptance criteria and, as appropriate, statistical techniques with a sample-size rationale. Validation uses representative product (initial production units, batches or equivalents) with the rationale for the choice recorded. As part of validation the organization performs clinical evaluations or performance evaluations in accordance with applicable regulatory requirements, and a device used for such evaluation is not considered released to the customer. Where the intended use requires connection or interface with other devices, validation confirms the requirements are met when so connected. Validation is completed before release of the product for use to the customer, and records of results, conclusions and actions are maintained.
Common gap: Validation performed on prototypes rather than representative production units without a recorded rationale
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 7.3.8 Design and development transferThe organization documents procedures for transferring design and development outputs to manufacturing, ensuring the outputs are verified as suitable for manufacturing before becoming final production specifications and that production capability can meet product requirements. Results and conclusions of the transfer are recorded.
Common gap: Transfer is a hand-over meeting with no verification of manufacturability
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 7.3.9 Control of design and development changesThe organization documents procedures to control design and development changes and determines the significance of each change to function, performance, usability, safety and applicable regulatory requirements for the device and its intended use. Changes are identified and, before implementation, reviewed, verified, validated as appropriate and approved. Review of a change includes evaluating its effect on constituent parts, on product in process or already delivered, on risk management inputs and outputs and on product realization processes. Records of changes, their review and any necessary actions are maintained.
Common gap: Significance assessed only for regulatory notification, not for safety or usability
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 7.3.10 Design and development filesThe organization maintains a design and development file for each medical device type or family. The file includes or references the records generated to demonstrate conformity to the design and development requirements and the records of design and development changes.
Common gap: File closed at launch and not updated with subsequent design changes
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 7.4.1 Purchasing processThe organization documents procedures to ensure purchased product conforms to specified purchasing information. It establishes supplier evaluation and selection criteria based on the supplier's ability to provide product meeting the organization's requirements, the supplier's performance, the effect of the purchased product on device quality, and proportionate to the risk associated with the device. It plans supplier monitoring and re-evaluation, monitors supplier performance against purchasing requirements with results feeding re-evaluation, and addresses non-fulfilment with the supplier proportionate to the risk of the purchased product and to regulatory compliance. Records of evaluation, selection, monitoring, re-evaluation and resulting actions are maintained.
Common gap: Every supplier evaluated identically regardless of the risk of what they supply
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 7.4.2 Purchasing informationPurchasing information describes or references the product to be purchased, including as appropriate product specifications, requirements for product acceptance, procedures, processes and equipment, requirements for qualification of supplier personnel, and quality management system requirements. The organization ensures the adequacy of purchasing requirements before communicating them to the supplier. Purchasing information includes, as applicable, a written agreement that the supplier notifies the organization of changes to the purchased product before implementing changes that affect its ability to meet purchase requirements. To the extent needed for traceability, relevant purchasing information is retained as documents and records.
Common gap: No written change-notification agreement with critical suppliers
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 7.4.3 Verification of purchased productThe organization establishes and implements the inspection or other activities needed to ensure purchased product meets purchasing requirements, with the extent of verification based on supplier evaluation results and proportionate to the risk of the purchased product. When it becomes aware of changes to purchased product it determines whether they affect the realization process or the device. Where the organization or its customer intends to verify at the supplier's premises, the intended verification activities and product release method are stated in the purchasing information. Records of verification are maintained.
Common gap: Same inspection level for every supplier regardless of performance
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 7.5.1 Control of production and service provisionProduction and service provision are planned, carried out, monitored and controlled so that product conforms to specification. As appropriate, production controls include documented procedures and methods for production control, qualification of infrastructure, monitoring and measurement of process parameters and product characteristics, availability and use of monitoring and measuring equipment, defined labelling and packaging operations, and product release, delivery and post-delivery activities. The organization establishes and maintains a record for each device or batch that provides traceability to the extent specified in 7.5.9 and identifies the amount manufactured and the amount approved for distribution, and that record is verified and approved.
Common gap: Batch record does not reconcile quantity manufactured against quantity released
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 7.5.2 Cleanliness of productThe organization documents requirements for cleanliness of product or contamination control of product where product is cleaned by the organization before sterilization or use; where product is supplied non-sterile for cleaning before sterilization or use; where product cannot be cleaned before sterilization or use and its cleanliness is significant in use; where product is supplied for non-sterile use and its cleanliness is significant in use; or where process agents are to be removed during manufacture. Where product is cleaned before sterilization or use under the first two cases, the work environment requirements of 6.4.1 do not apply before the cleaning process.
Common gap: Case applicability never determined, so requirements are absent for non-sterile devices where cleanliness matters
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 7.5.3 Installation activitiesAs appropriate, the organization documents requirements for medical device installation and acceptance criteria for verifying installation. Where agreed customer requirements allow installation by an external party other than the organization or its supplier, the organization provides documented installation and verification requirements. Records of installation and verification performed by the organization or its supplier are maintained.
Common gap: Installation verified by the field engineer's sign-off with no acceptance criteria
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 7.5.4 Servicing activitiesWhere servicing of the device is a specified requirement, the organization documents servicing procedures, reference materials and reference measurements as necessary to perform servicing and verify product requirements are met. It analyses records of servicing performed by the organization or its supplier to determine whether the information is to be handled as a complaint and, as appropriate, as input to improvement. Records of servicing are maintained.
Common gap: Service reports never reviewed for complaints
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 7.5.5 Particular requirements for sterile medical devicesThe organization maintains records of the sterilization process parameters used for each sterilization batch, and those records are traceable to each production batch of medical devices.
Common gap: Contract sterilizer's parameter records not retained by the organization
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 7.5.6 Validation of processes for production and service provisionThe organization validates any production or service process whose output cannot be, or is not, verified by subsequent monitoring or measurement, so that deficiencies would only appear after the product is in use or the service delivered. Validation demonstrates the process can achieve planned results consistently. Documented validation procedures cover criteria for review and approval of the process, equipment qualification and personnel qualification, use of specific methods, procedures and acceptance criteria, statistical techniques with a sample-size rationale as appropriate, record requirements, revalidation including its criteria, and approval of process changes. Procedures are documented for validating computer software used in production and service provision before initial use and after changes, proportionate to the risk including the effect on product conformity. Records of results, conclusions and actions are maintained.
Common gap: Processes such as welding, moulding, sealing or software builds treated as verifiable when they are not
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 7.5.7 Particular requirements for validation of processes for sterilization and sterile barrier systemsThe organization documents procedures for validating processes for sterilization and for sterile barrier systems. These processes are validated before implementation and following product or process changes as appropriate. Records of results, conclusions and actions from the validation are maintained.
Common gap: Sterile barrier system validated for packaging materials but not for the sealing process
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 7.5.8 IdentificationThe organization documents procedures for product identification and identifies product by suitable means throughout product realization. It identifies product status with respect to monitoring and measurement requirements throughout production, storage, installation and servicing so that only product that has passed the required inspections and tests, or is released under authorized concession, is dispatched, used or installed. Where regulatory requirements require it, the organization documents a system to assign unique device identification. It documents procedures to ensure returned devices are identified and distinguished from conforming product.
Common gap: Status identification relies on location alone
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 7.5.9.1 GeneralThe organization documents procedures for traceability that define the extent of traceability in accordance with applicable regulatory requirements and the records to be maintained.
Common gap: Extent of traceability never defined against regulatory requirements
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 7.5.9.2 Particular requirements for implantable medical devicesFor implantable medical devices, traceability records include records of the components, materials and work environment conditions used where these could cause the device not to satisfy its specified safety and performance requirements. The organization requires suppliers of distribution services or distributors to maintain records of distribution that allow traceability and to make them available for inspection. Records of the name and address of the shipping package consignee are maintained.
Common gap: Work environment conditions not captured in the device history record for implants
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 7.5.10 Customer propertyThe organization identifies, verifies, protects and safeguards customer property provided for use in or incorporation into the product while it is under the organization's control or in use by the organization. If customer property is lost, damaged or found unsuitable for use the organization reports it to the customer and maintains records.
Common gap: Customer-supplied components accepted without verification
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 7.5.11 Preservation of productThe organization documents procedures for preserving the conformity of product during processing, storage, handling and distribution, applying preservation to the constituent parts of a device. It protects product from alteration, contamination or damage under expected conditions and hazards during processing, storage, handling and distribution by designing and constructing suitable packaging and shipping containers and by documenting requirements for special conditions where packaging alone cannot provide preservation. Where special conditions are required they are controlled and recorded.
Common gap: Cold-chain or humidity requirements documented but not controlled through distribution
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 7.6 Control of monitoring and measuring equipmentThe organization determines the monitoring and measurement to be undertaken and the equipment needed to provide evidence of product conformity, and documents procedures to ensure monitoring and measurement can be and are carried out consistently with the requirements. As necessary for valid results, measuring equipment is calibrated or verified at specified intervals or before use against standards traceable to international or national standards (with the basis recorded where none exist), adjusted as necessary with adjustments recorded, identified to show calibration status, safeguarded from adjustments that would invalidate results, and protected from damage and deterioration. Calibration and verification follow documented procedures. When equipment is found nonconforming the organization assesses and records the validity of previous results and takes appropriate action on the equipment and any affected product. Calibration and verification records are maintained. Procedures are documented for validating computer software used for monitoring and measurement, before initial use and after changes, proportionate to the risk including the effect on product conformity, with records of validation results, conclusions and actions.
Common gap: Out-of-tolerance findings closed by recalibration with no impact assessment on product measured since the last good calibration
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 8.1 GeneralThe organization plans and implements the monitoring, measurement, analysis and improvement processes needed to demonstrate product conformity, ensure conformity of the quality management system and maintain its effectiveness, including determining appropriate methods, statistical techniques among them, and the extent of their use.
Common gap: Sampling plans used with no statistical rationale
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 8.2.1 FeedbackAs one measure of quality management system effectiveness, the organization gathers and monitors information on whether it has met customer requirements, with documented methods for obtaining and using it. It documents procedures for a feedback process that gathers data from production and post-production activities. Feedback information serves as potential input to risk management for monitoring and maintaining product requirements and to the realization and improvement processes. Where regulatory requirements require specific experience to be gained from post-production activities, review of that experience forms part of the feedback process.
Common gap: Feedback limited to complaints, with no proactive post-production data gathering
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 8.2.2 Complaint handlingThe organization documents procedures for timely complaint handling in accordance with applicable regulatory requirements, covering at least the requirements and responsibilities for receiving and recording information, evaluating whether feedback constitutes a complaint, investigating complaints, determining the need to report to regulatory authorities, handling complaint-related product, and determining the need for corrections or corrective actions. Where a complaint is not investigated the justification is documented, and any correction or corrective action arising is documented. Where an investigation finds that activities outside the organization contributed, relevant information is exchanged with the external party. Complaint handling records are maintained.
Common gap: Feedback evaluated for complaint status by sales or service staff with no defined criteria
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 8.2.3 Reporting to regulatory authoritiesWhere applicable regulatory requirements require notification of complaints that meet specified reporting criteria for adverse events, or issuance of advisory notices, the organization documents procedures for notifying the appropriate regulatory authorities and maintains records of that reporting.
Common gap: Reporting criteria and timelines for every market the device is sold in not identified
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 8.2.4 Internal auditThe organization conducts internal audits at planned intervals to determine whether the quality management system conforms to planned and documented arrangements, the standard, the organization's own requirements and applicable regulatory requirements, and is effectively implemented and maintained. A documented procedure describes responsibilities and requirements for planning and conducting audits and recording and reporting results. The audit programme is planned considering the status and importance of processes and areas and previous audit results; criteria, scope, interval and methods are defined and recorded; auditor selection and audit conduct ensure objectivity and impartiality, and auditors do not audit their own work. Records of audits and results, identifying the processes and areas audited and the conclusions, are maintained. Management of the audited area ensures corrections and corrective actions are taken without undue delay, and follow-up verifies the actions and reports the verification results.
Common gap: Audit criteria cover the standard but not applicable regulatory requirements
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 8.2.5 Monitoring and measurement of processesThe organization applies suitable methods for monitoring and, as appropriate, measuring the quality management system processes, which demonstrate the processes' ability to achieve planned results. When planned results are not achieved, correction and corrective action are taken as appropriate.
Common gap: Process measures exist for production only
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 8.2.6 Monitoring and measurement of productThe organization monitors and measures product characteristics to verify product requirements are met, at the applicable stages of product realization, according to planned and documented arrangements and documented procedures. Evidence of conformity to acceptance criteria is maintained, the identity of the person authorizing release is recorded, and as appropriate records identify the test equipment used. Product release and service delivery do not proceed until the planned arrangements are satisfactorily completed. For implantable medical devices the identity of personnel performing any inspection or testing is recorded.
Common gap: Release approved before all planned tests are complete (for example before sterilization results are back)
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 8.3.1 GeneralThe organization ensures product that does not conform to requirements is identified and controlled to prevent unintended use or delivery. A documented procedure defines the controls and the responsibilities and authorities for identification, documentation, segregation, evaluation and disposition of nonconforming product. Evaluation of a nonconformity includes determining the need for investigation and for notifying any external party responsible. Records of the nature of nonconformities and subsequent action, including the evaluation, any investigation and the rationale for decisions, are maintained.
Common gap: Rationale for disposition decisions not recorded
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 8.3.2 Actions in response to nonconforming product detected before deliveryThe organization deals with nonconforming product by eliminating the detected nonconformity, precluding its original intended use or application, or authorizing its use, release or acceptance under concession. Nonconforming product is accepted by concession only where justification is provided, approval obtained and applicable regulatory requirements met, and records of the concession and the identity of the person authorizing it are maintained.
Common gap: Concessions granted without an assessment against regulatory requirements
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 8.3.3 Actions in response to nonconforming product detected after deliveryWhen nonconforming product is detected after delivery or after use has started, the organization takes action appropriate to the effects or potential effects of the nonconformity and maintains records of the action. It documents procedures for issuing advisory notices in accordance with applicable regulatory requirements; the procedures can be put into effect at any time, and records of actions relating to advisory notices are maintained.
Common gap: Advisory notice procedure depends on staff or data available only in business hours
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 8.3.4 ReworkThe organization performs rework in accordance with documented procedures that take into account the potential adverse effect of the rework on the product, and those procedures undergo the same review and approval as the original procedure. After rework, product is verified to ensure it meets applicable acceptance criteria and regulatory requirements, and records of rework are maintained.
Common gap: Rework performed to informal instructions
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 8.4 Analysis of dataThe organization documents procedures to determine, collect and analyse appropriate data to demonstrate the suitability, adequacy and effectiveness of the quality management system, including determining appropriate methods, statistical techniques and the extent of their use. Analysis includes data from monitoring and measurement and other relevant sources and at minimum input from feedback, conformity to product requirements, characteristics and trends of processes and product including improvement opportunities, suppliers, audits and, as appropriate, service reports. Where the analysis shows the system is not suitable, adequate or effective, it is used as input to improvement under 8.5. Records of the results of analyses are maintained.
Common gap: Data collected and reported with no analysis or trending
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 8.5.1 GeneralThe organization identifies and implements any changes needed to ensure and maintain the continued suitability, adequacy and effectiveness of the quality management system and the safety and performance of the medical device, using the quality policy, quality objectives, audit results, post-market surveillance, analysis of data, corrective actions, preventive actions and management review.
Common gap: Improvement limited to closing audit findings
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 8.5.2 Corrective actionThe organization takes action to eliminate the causes of nonconformities to prevent recurrence, without undue delay and proportionate to the effects of the nonconformities. A documented procedure defines requirements for reviewing nonconformities including complaints, determining their causes, evaluating the need for action to prevent recurrence, planning, documenting and implementing the action including updating documentation as appropriate, verifying the action does not adversely affect the ability to meet regulatory requirements or the safety and performance of the device, and reviewing the effectiveness of the action. Records of investigation results and action taken are maintained.
Common gap: Corrective action closed on implementation with no effectiveness review
ISO 13485:2016 on compliance.theartofservice.com
ISO 13485 8.5.3 Preventive actionThe organization determines action to eliminate the causes of potential nonconformities to prevent their occurrence, proportionate to the effects of the potential problems. A documented procedure describes requirements for determining potential nonconformities and their causes, evaluating the need for action to prevent occurrence, planning, documenting and implementing the action including updating documentation as appropriate, verifying the action does not adversely affect the ability to meet regulatory requirements or the safety and performance of the device, and reviewing the effectiveness of the action as appropriate. Records of investigations and action taken are maintained.
Common gap: Preventive action register empty because potential problems are never sought
ISO 13485:2016 on compliance.theartofservice.com
Product categories that engage it
See which of your products engage it
Paste the list and every product that engages ISO 13485 in the markets you sell to shows it as a chip, with the documents it expects ticked against what you hold. Five products free, no account.
Build my conformity sheet