Knowledge base

ISO 13485:2016: Documentation and Compliance Requirements

A simple, clause-by-clause guide to what ISO 13485:2016 requires you to document and what an auditor may ask to see as evidence.

Prem Kumar Dvivedi · ١٢ سبتمبر ٢٠٢٦

This guide explains the requirements rather than simply providing a checklist.

1. How to Use This Guide

This guide explains what ISO 13485:2016 requires organisations to have and maintain, clause by clause, and the type of evidence an auditor may review.

It covers the main requirements across five key areas:

• Quality Management System

• Management Responsibility

• Resources

• Product Realisation

• Measurement, Analysis and Improvement

This is intentionally more than a checklist. A checklist only asks, “Do you have this?” This guide explains “What is required and what evidence shows that the requirement has been met?”

If you want to understand your current level of readiness first, you can also use an ISO 13485:2016 readiness assessment to identify gaps and areas for improvement.

________________________________________

4. Quality Management System and Documentation

Relevant clauses: 4.1.1, 4.1.2, 4.1.6, 4.2.1, 4.2.2, 4.2.3, 4.2.4 and 4.2.5

Define your regulatory role

You must clearly define your role for the products you handle, such as:

• Manufacturer

• Authorised Representative

• Importer

• Distributor

Evidence an auditor may ask for:

A written statement identifying your role for each product and market.

Identify applicable regulations

You must know which medical device regulations apply in every market where you sell your products.

Evidence:

A regulatory register covering applicable requirements, such as EU MDR/IVDR, US FDA, India CDSCO, Saudi SFDA and others, along with product classifications, registrations and licences.

Define the scope of your quality management system

You must clearly state what your quality management system covers and explain any requirements that do not apply.

Evidence:

A documented scope statement and justification for any exclusions. The justification should be based on regulatory or product requirements, not simply convenience.

Define and control your processes

You must understand your processes, how they work together and how outsourced activities are controlled.

Evidence:

Process maps, agreements with external providers and records showing that outsourced processes are monitored.

Validate software used in the quality system

If software is used for quality management, production or other important activities, you must confirm that it works correctly before using it.

Evidence:

Software validation records based on the level of risk. This may include spreadsheets, calculation tools and labelling systems.

Maintain required documents

You must maintain the documents required by ISO 13485:2016, including a quality manual.

Evidence:

A list or register of controlled documents and records.

Maintain a quality manual

Your quality manual should explain:

• The scope of the quality system

• Applicable procedures

• How the different processes interact

Evidence:

The current quality manual and documentation structure.

Maintain a medical device file

You must maintain a file for each medical device or product family.

It should include or reference information such as:

• Product description and intended use

• Labelling and instructions for use

• Product specifications

• Manufacturing and packaging procedures

• Storage and handling requirements

• Monitoring and measurement requirements

• Installation and servicing information, where applicable

Keep product files updated

The medical device file must be maintained throughout the product's life.

Evidence:

Revision history and updated records showing that the file is actively maintained.

Control documents before use

Documents must be reviewed and approved before they are used. Changes must also be reviewed and approved.

Evidence:

Approval records and documented review of changes.

Make sure people use the correct documents

Employees must be able to access the latest approved version of documents. Obsolete versions must be prevented from accidental use.

Evidence:

Document distribution records and evidence showing obsolete documents are controlled.

Define record retention periods

Records must be retained for at least the lifetime of the device and for any additional period required by applicable regulations.

Evidence:

A documented retention schedule and records showing that information remains legible and retrievable.

Protect confidential health information

Health and patient information must be kept confidential.

Evidence:

Access controls and other measures protecting personal and health information.

________________________________________

5. Management Responsibility

Relevant clauses: 5.1, 5.2, 5.3, 5.4.1, 5.4.2, 5.5.1, 5.5.2, 5.5.3, 5.6.1, 5.6.2 and 5.6.3

Demonstrate management commitment

Top management must demonstrate commitment to the quality management system by providing resources and communicating applicable requirements.

Evidence:

Management review records, staffing and budget information, and evidence that customer and regulatory requirements are communicated.

Identify customer and regulatory requirements

You must identify the requirements applicable to your products and ensure they are met.

Evidence:

Documented requirements for each relevant product and market.

Establish a quality policy

You must have a quality policy that is appropriate to your organisation and commits to meeting applicable requirements and maintaining an effective quality management system.

Evidence:

An approved, dated and communicated quality policy that is periodically reviewed.

Set measurable quality objectives

You must establish measurable quality objectives at appropriate levels of the organisation.

Evidence:

Objectives with clear targets or measurements that support the quality policy.

Plan and maintain the quality system

You must plan your quality management system and ensure that changes do not negatively affect its effectiveness.

Evidence:

Quality planning records and change-management records.

Define responsibilities

Everyone must clearly understand their responsibilities and authority.

Evidence:

• Organisation chart

• Job descriptions

• Responsibility and authority records

Appoint a management representative

Management must appoint someone with responsibility for the quality management system.

Evidence:

A formal appointment defining responsibilities, including reporting on the quality system and ensuring awareness of customer and regulatory requirements.

Establish internal communication

You must have suitable arrangements for communication about the quality management system.

Evidence:

Meeting structures, internal briefings and records showing communication between relevant functions.

Conduct management reviews

Top management must review the quality management system at planned intervals.

Evidence:

A documented management review procedure, review schedule, meeting records and attendance.

Cover required management review inputs

Management reviews should consider relevant information, including:

• Customer feedback

• Complaints

• Regulatory reporting

• Internal and external audits

• Process and product monitoring

• Corrective and preventive actions

• Previous management review actions

• Changes affecting the quality system

• Improvement opportunities

• New or changed regulatory requirements

Record management review outputs

The review must result in documented decisions and actions.

Evidence:

Improvement decisions, resource requirements, changes and action plans with responsible persons and deadlines.

________________________________________

6. Resources

Relevant clauses: 6.1, 6.2, 6.3, 6.4.1 and 6.4.2

Provide adequate resources

You must provide the people, infrastructure, equipment and other resources needed to operate the quality system and meet customer and regulatory requirements.

Evidence:

Budgets, staffing records and equipment information.

Define employee competence

You must define the competence required for jobs that can affect product quality.

Evidence:

Competence criteria covering education, training, skills and experience.

Maintain training and competence records

You must demonstrate that employees are competent and that training has been effective.

Evidence:

Individual training and competence records, together with evidence that training effectiveness has been evaluated.

Ensure employee awareness

Employees should understand why their work is important and how it affects product quality and quality objectives.

Evidence:

Awareness records and discussions with employees.

Maintain infrastructure

You must identify and maintain the buildings, equipment and support services needed for your operations.

Evidence:

Infrastructure requirements, maintenance plans and completed maintenance records.

Control the working environment

You must define and control environmental conditions that can affect product quality.

Evidence:

Requirements relating to cleanliness, health, protective clothing and environmental monitoring.

Control contamination

Where contamination could affect the product, suitable controls must be established.

Evidence:

Contamination-control procedures, cleanroom or controlled-area monitoring and relevant records.

If the requirement genuinely does not apply, the reason should be documented.

________________________________________

7. Product Realisation

Relevant clauses: 7.1 through 7.6, as applicable

Plan product realisation

You must plan how each product will be produced, including required checks, records and acceptance criteria.

Evidence:

Quality plans or product realisation planning records.

Apply risk management

Risk management must be applied throughout product realisation and maintained throughout the product lifecycle.

Evidence:

A documented risk management process aligned with ISO 14971, including:

• Risk management plan

• Risk management file

• Hazard identification

• Risk analysis and evaluation

• Risk controls

• Residual risk

• Verification of risk controls

• Production and post-production information

The risk management file should not simply be closed at product launch.

Identify customer requirements

You must identify customer requirements, including:

• Delivery requirements

• Regulatory requirements

• User training requirements

• Other requirements necessary for safe and effective use

Evidence:

Documented product and customer requirements.

Review requirements before accepting an order

Requirements must be reviewed before you commit to supplying the product.

Evidence:

Contract or order review records and documented actions.

Control changes to requirements

If requirements change, relevant documents must be updated and affected employees must be informed.

Evidence:

Amendment and change records.

Communicate with customers

You must have processes for communicating with customers about:

• Enquiries

• Orders

• Product information

• Feedback

• Complaints

• Advisory notices

Evidence:

Communication procedures and related records.

________________________________________

Design and Development

Where your organisation is responsible for design, you must control the design and development process.

Plan design and development

Design activities should cover:

• Planning

• Design stages

• Reviews

• Verification

• Validation

• Design transfer

• Change control

Evidence:

A documented design and development plan with responsibilities and traceability methods.

If design is genuinely not applicable, the reason should be documented and supported by applicable requirements.

Define design inputs

Design inputs must include relevant requirements for:

• Function

• Performance

• Safety

• Regulatory requirements

• Risk management

Evidence:

Approved and reviewed design input records.

Define design outputs

Design outputs must meet the design inputs and include appropriate acceptance criteria and information needed for safe use.

Evidence:

Approved design output records.

Conduct design reviews

Design reviews must be carried out at planned stages with appropriate personnel.

Evidence:

Design review records showing participants, findings and decisions.

Verify the design

You must confirm that design outputs meet the specified design inputs.

Evidence:

Verification plans, methods, acceptance criteria and results.

Validate the design

You must demonstrate that the final design meets intended use and user needs.

Where required, this may include clinical or performance evaluation.

Evidence:

Validation plans and results, including clinical or performance evaluation where applicable.

Control design transfer

Design information must be transferred to production in a controlled manner.

Evidence:

Records showing that manufacturing methods are suitable and capable of consistently producing the product.

Control design changes

Design changes must be reviewed for their effect on:

• Product components

• Existing products

• Products already in the field

• Risk management

• Regulatory requirements

Evidence:

Change records, approvals and regulatory notifications where required.

Maintain design records

You must maintain a design and development file for each applicable device or product family.

Evidence:

A complete design history showing the design process and related records.

________________________________________

Supplier and Purchasing Controls

Evaluate suppliers

Suppliers must be evaluated and selected using documented criteria based on their potential impact on product quality.

Evidence:

• Supplier evaluation criteria

• Approved supplier list

• Initial evaluation records

• Re-evaluation records

• Quality agreements where appropriate

Control supplier changes

Suppliers should be required to notify you before making changes that could affect your requirements.

Evidence:

Supplier agreements and records of supplier change notifications.

Communicate purchasing requirements

You must clearly communicate your requirements to suppliers.

These may include:

• Product specifications

• Competence requirements

• Quality system requirements

• Inspection requirements

Evidence:

Purchase specifications and supplier communication.

Verify purchased products

Purchased products and services must be verified before use where required.

Evidence:

Incoming inspection records, certificates and other verification records.

________________________________________

Production and Service Provision

Control production

Production must be carried out under controlled conditions.

This includes having the necessary:

• Procedures

• Work instructions

• Specifications

• Equipment

• Monitoring methods

• Labelling requirements

• Production records

Control product cleanliness

Where cleanliness affects product safety or performance, cleanliness requirements must be defined and controlled.

Evidence:

Cleanliness requirements and relevant records.

Control installation

Where installation is required, installation instructions and acceptance criteria must be documented.

Evidence:

Installation instructions and verification records.

Control servicing

Where servicing is provided, servicing procedures and service records must be maintained.

Service information should also be reviewed for complaints or trends.

Control sterilisation

For sterile products, sterilisation parameters must be recorded for each applicable batch.

Validate special processes

Processes where the result cannot be fully verified through later inspection must be validated.

Examples may include:

• Sterilisation

• Sealing

• Welding

• Moulding

• Cleaning

• Aseptic filling

Evidence:

Validation protocols, acceptance criteria, validation reports, equipment qualification and revalidation records.

Validate sterilisation and sterile barrier processes

Sterilisation and sterile barrier systems must be validated before use and after relevant changes.

Identify products

Products must remain identifiable throughout production, and their inspection status must be clear.

Evidence:

Identification systems, status labels and controls for returned products.

Maintain traceability

You must have a documented traceability process that defines how far product traceability must extend.

Evidence:

Batch or serial number records and Unique Device Identification records where required.

Additional traceability for implantable devices

For implantable devices, records should allow traceability of relevant components, materials and environmental conditions.

Distribution records should also identify the consignee where necessary for recall purposes.

Protect customer property

Customer property must be protected while under your control.

This may include:

• Physical property

• Intellectual property

• Confidential information

• Health information

Any loss or damage must be reported.

Preserve products

Products must be protected during:

• Processing

• Storage

• Handling

• Packaging

• Distribution

Special conditions such as temperature and humidity must be controlled where required.

Control monitoring and measuring equipment

Measuring equipment must be calibrated or verified against suitable standards.

Evidence:

• Equipment register

• Calibration records

• Traceability information

• Calibration intervals

• Equipment status identification

Act when equipment is out of calibration

If equipment is found to be out of calibration, you must determine whether previously measured products may have been affected.

Evidence:

Impact assessment and records of actions taken.

________________________________________

8. Measurement, Analysis and Improvement

Relevant clauses: 8.1 through 8.5.3

Plan monitoring and measurement

You must plan the monitoring, measurement, analysis and improvement activities needed for your quality system.

Where statistical methods are used, the method and reason for its selection should be documented.

Collect product feedback

You must collect feedback during production and after products reach the market.

Sources may include:

• Customers

• Users

• Service reports

• Installation reports

• Product returns

• Market information

• Relevant literature

Feedback should be considered in risk management and product improvement.

Control complaints

You must have a documented complaint-handling process and ensure complaints are handled in a timely manner.

Evidence:

Complaint procedure and complaint records showing dates and actions taken.

Assess complaint reportability

Each complaint must be assessed to determine whether it needs to be reported to a regulatory authority.

Evidence:

A documented reportability assessment for each complaint.

Record reasons for not investigating complaints

If a complaint is not investigated, the reason must be documented.

Report regulatory events

You must have a process for reporting events to regulators within the required timeframe.

Evidence:

Vigilance procedures, market-specific reporting requirements, regulatory reports and authority correspondence.

Conduct internal audits

You must audit your quality management system using a documented and risk-based audit programme.

Auditors should have appropriate competence and independence.

Evidence:

• Internal audit procedure

• Audit programme

• Audit plans

• Audit criteria and scope

• Audit reports

• Auditor competence records

• Evidence of auditor independence

Take corrective action

Corrective actions must be taken without unnecessary delay and their effectiveness must be verified.

Evidence:

Corrective action records, effectiveness checks and closure records.

Monitor processes

You must monitor and measure your processes and take action when planned results are not achieved.

Monitor product conformity

Products must be checked against defined acceptance criteria.

Evidence:

Inspection and testing records, including identification of the person who authorised product release.

Control nonconforming products

Nonconforming products must be identified and controlled so they cannot be accidentally used or delivered.

Evidence:

• Nonconformity procedure

• Quarantine or system hold

• Nonconformity records

• Authorised disposition decisions

Document the decision on nonconforming products

The decision about what happens to a nonconforming product must be documented and authorised.

Possible decisions may include:

• Rework

• Rejection

• Scrap

• Concession, where permitted

Act on nonconforming products already delivered

If a nonconforming product has already been supplied, appropriate action must be taken.

This may include advisory notices or field safety corrective actions where necessary.

Control rework

If a product is reworked, the rework instructions must be properly approved and the effect of the rework on the product must be assessed.

Analyse quality data

You must analyse information from areas such as:

• Feedback

• Complaints

• Product conformity

• Trends

• Suppliers

• Audits

• Service reports

Evidence:

Documented analysis methods and records showing the results of analysis.

Use analysis to improve the system

The analysis should help determine whether the quality management system remains suitable and effective and should lead to appropriate actions.

Maintain system effectiveness

You must use information from:

• Quality policy

• Quality objectives

• Audits

• Data analysis

• Corrective actions

• Preventive actions

• Management reviews

to maintain and improve the effectiveness of the quality management system.

Correct the root cause of problems

You must have a documented corrective action process that addresses the root cause rather than simply fixing the immediate problem.

Evidence:

Corrective action records with documented cause analysis.

Check the effect of corrective action

Corrective action must not negatively affect product safety or regulatory compliance.

Evidence:

Documented verification of the action.

Verify corrective action effectiveness

You must confirm that corrective actions were effective and completed without unnecessary delay.

Maintain preventive action

ISO 13485:2016 also requires a separate preventive action process for identifying and addressing potential problems before they occur.

Evidence:

Preventive action procedures and records showing proactive action.

________________________________________

How to Use This Guide

ISO 13485:2016 is not simply about creating many documents, templates or forms.

The key requirement is to demonstrate that important decisions and activities have been properly planned, documented, implemented and maintained.

More documentation does not automatically mean better compliance.

A procedure that is very detailed but is not followed can create a bigger gap than a simple procedure that accurately reflects how the organization actually works.

The important question is:

Does the documented system reflect what people actually do, and can the organization provide objective evidence that the requirements are being met?

That is what an auditor will ultimately look for when assessing the effectiveness of an ISO 13485:2016 quality management system.

What this covers

See how this looks as a working system

Reading about a requirement and seeing the documentation that satisfies it are different things. In a short demo we open the actual manual, procedures and records set for ISO 13485, show you how each clause is answered and where your existing way of working already fits. You will know what implementation involves before you commit to it.

Ask us about this

Tell us what is being asked of you and by whom.

What are you looking for?

We reply within one working day. Your details stay with our consultants.

More reading

All articles