Knowledge base
ISO 13485:2016: Documentation and Compliance Requirements
A simple, clause-by-clause guide to what ISO 13485:2016 requires you to document and what an auditor may ask to see as evidence.
Prem Kumar Dvivedi · 12 septembre 2026
This guide explains the requirements rather than simply providing a checklist.
1. How to Use This Guide
This guide explains what ISO 13485:2016 requires organisations to have and maintain, clause by clause, and the type of evidence an auditor may review.
It covers the main requirements across five key areas:
• Quality Management System
• Management Responsibility
• Resources
• Product Realisation
• Measurement, Analysis and Improvement
This is intentionally more than a checklist. A checklist only asks, “Do you have this?” This guide explains “What is required and what evidence shows that the requirement has been met?”
If you want to understand your current level of readiness first, you can also use an ISO 13485:2016 readiness assessment to identify gaps and areas for improvement.
________________________________________
4. Quality Management System and Documentation
Relevant clauses: 4.1.1, 4.1.2, 4.1.6, 4.2.1, 4.2.2, 4.2.3, 4.2.4 and 4.2.5
Define your regulatory role
You must clearly define your role for the products you handle, such as:
• Manufacturer
• Authorised Representative
• Importer
• Distributor
Evidence an auditor may ask for:
A written statement identifying your role for each product and market.
Identify applicable regulations
You must know which medical device regulations apply in every market where you sell your products.
Evidence:
A regulatory register covering applicable requirements, such as EU MDR/IVDR, US FDA, India CDSCO, Saudi SFDA and others, along with product classifications, registrations and licences.
Define the scope of your quality management system
You must clearly state what your quality management system covers and explain any requirements that do not apply.
Evidence:
A documented scope statement and justification for any exclusions. The justification should be based on regulatory or product requirements, not simply convenience.
Define and control your processes
You must understand your processes, how they work together and how outsourced activities are controlled.
Evidence:
Process maps, agreements with external providers and records showing that outsourced processes are monitored.
Validate software used in the quality system
If software is used for quality management, production or other important activities, you must confirm that it works correctly before using it.
Evidence:
Software validation records based on the level of risk. This may include spreadsheets, calculation tools and labelling systems.
Maintain required documents
You must maintain the documents required by ISO 13485:2016, including a quality manual.
Evidence:
A list or register of controlled documents and records.
Maintain a quality manual
Your quality manual should explain:
• The scope of the quality system
• Applicable procedures
• How the different processes interact
Evidence:
The current quality manual and documentation structure.
Maintain a medical device file
You must maintain a file for each medical device or product family.
It should include or reference information such as:
• Product description and intended use
• Labelling and instructions for use
• Product specifications
• Manufacturing and packaging procedures
• Storage and handling requirements
• Monitoring and measurement requirements
• Installation and servicing information, where applicable
Keep product files updated
The medical device file must be maintained throughout the product's life.
Evidence:
Revision history and updated records showing that the file is actively maintained.
Control documents before use
Documents must be reviewed and approved before they are used. Changes must also be reviewed and approved.
Evidence:
Approval records and documented review of changes.
Make sure people use the correct documents
Employees must be able to access the latest approved version of documents. Obsolete versions must be prevented from accidental use.
Evidence:
Document distribution records and evidence showing obsolete documents are controlled.
Define record retention periods
Records must be retained for at least the lifetime of the device and for any additional period required by applicable regulations.
Evidence:
A documented retention schedule and records showing that information remains legible and retrievable.
Protect confidential health information
Health and patient information must be kept confidential.
Evidence:
Access controls and other measures protecting personal and health information.
________________________________________
5. Management Responsibility
Relevant clauses: 5.1, 5.2, 5.3, 5.4.1, 5.4.2, 5.5.1, 5.5.2, 5.5.3, 5.6.1, 5.6.2 and 5.6.3
Demonstrate management commitment
Top management must demonstrate commitment to the quality management system by providing resources and communicating applicable requirements.
Evidence:
Management review records, staffing and budget information, and evidence that customer and regulatory requirements are communicated.
Identify customer and regulatory requirements
You must identify the requirements applicable to your products and ensure they are met.
Evidence:
Documented requirements for each relevant product and market.
Establish a quality policy
You must have a quality policy that is appropriate to your organisation and commits to meeting applicable requirements and maintaining an effective quality management system.
Evidence:
An approved, dated and communicated quality policy that is periodically reviewed.
Set measurable quality objectives
You must establish measurable quality objectives at appropriate levels of the organisation.
Evidence:
Objectives with clear targets or measurements that support the quality policy.
Plan and maintain the quality system
You must plan your quality management system and ensure that changes do not negatively affect its effectiveness.
Evidence:
Quality planning records and change-management records.
Define responsibilities
Everyone must clearly understand their responsibilities and authority.
Evidence:
• Organisation chart
• Job descriptions
• Responsibility and authority records
Appoint a management representative
Management must appoint someone with responsibility for the quality management system.
Evidence:
A formal appointment defining responsibilities, including reporting on the quality system and ensuring awareness of customer and regulatory requirements.
Establish internal communication
You must have suitable arrangements for communication about the quality management system.
Evidence:
Meeting structures, internal briefings and records showing communication between relevant functions.
Conduct management reviews
Top management must review the quality management system at planned intervals.
Evidence:
A documented management review procedure, review schedule, meeting records and attendance.
Cover required management review inputs
Management reviews should consider relevant information, including:
• Customer feedback
• Complaints
• Regulatory reporting
• Internal and external audits
• Process and product monitoring
• Corrective and preventive actions
• Previous management review actions
• Changes affecting the quality system
• Improvement opportunities
• New or changed regulatory requirements
Record management review outputs
The review must result in documented decisions and actions.
Evidence:
Improvement decisions, resource requirements, changes and action plans with responsible persons and deadlines.
________________________________________
6. Resources
Relevant clauses: 6.1, 6.2, 6.3, 6.4.1 and 6.4.2
Provide adequate resources
You must provide the people, infrastructure, equipment and other resources needed to operate the quality system and meet customer and regulatory requirements.
Evidence:
Budgets, staffing records and equipment information.
Define employee competence
You must define the competence required for jobs that can affect product quality.
Evidence:
Competence criteria covering education, training, skills and experience.
Maintain training and competence records
You must demonstrate that employees are competent and that training has been effective.
Evidence:
Individual training and competence records, together with evidence that training effectiveness has been evaluated.
Ensure employee awareness
Employees should understand why their work is important and how it affects product quality and quality objectives.
Evidence:
Awareness records and discussions with employees.
Maintain infrastructure
You must identify and maintain the buildings, equipment and support services needed for your operations.
Evidence:
Infrastructure requirements, maintenance plans and completed maintenance records.
Control the working environment
You must define and control environmental conditions that can affect product quality.
Evidence:
Requirements relating to cleanliness, health, protective clothing and environmental monitoring.
Control contamination
Where contamination could affect the product, suitable controls must be established.
Evidence:
Contamination-control procedures, cleanroom or controlled-area monitoring and relevant records.
If the requirement genuinely does not apply, the reason should be documented.
________________________________________
7. Product Realisation
Relevant clauses: 7.1 through 7.6, as applicable
Plan product realisation
You must plan how each product will be produced, including required checks, records and acceptance criteria.
Evidence:
Quality plans or product realisation planning records.
Apply risk management
Risk management must be applied throughout product realisation and maintained throughout the product lifecycle.
Evidence:
A documented risk management process aligned with ISO 14971, including:
• Risk management plan
• Risk management file
• Hazard identification
• Risk analysis and evaluation
• Risk controls
• Residual risk
• Verification of risk controls
• Production and post-production information
The risk management file should not simply be closed at product launch.
Identify customer requirements
You must identify customer requirements, including:
• Delivery requirements
• Regulatory requirements
• User training requirements
• Other requirements necessary for safe and effective use
Evidence:
Documented product and customer requirements.
Review requirements before accepting an order
Requirements must be reviewed before you commit to supplying the product.
Evidence:
Contract or order review records and documented actions.
Control changes to requirements
If requirements change, relevant documents must be updated and affected employees must be informed.
Evidence:
Amendment and change records.
Communicate with customers
You must have processes for communicating with customers about:
• Enquiries
• Orders
• Product information
• Feedback
• Complaints
• Advisory notices
Evidence:
Communication procedures and related records.
________________________________________
Design and Development
Where your organisation is responsible for design, you must control the design and development process.
Plan design and development
Design activities should cover:
• Planning
• Design stages
• Reviews
• Verification
• Validation
• Design transfer
• Change control
Evidence:
A documented design and development plan with responsibilities and traceability methods.
If design is genuinely not applicable, the reason should be documented and supported by applicable requirements.
Define design inputs
Design inputs must include relevant requirements for:
• Function
• Performance
• Safety
• Regulatory requirements
• Risk management
Evidence:
Approved and reviewed design input records.
Define design outputs
Design outputs must meet the design inputs and include appropriate acceptance criteria and information needed for safe use.
Evidence:
Approved design output records.
Conduct design reviews
Design reviews must be carried out at planned stages with appropriate personnel.
Evidence:
Design review records showing participants, findings and decisions.
Verify the design
You must confirm that design outputs meet the specified design inputs.
Evidence:
Verification plans, methods, acceptance criteria and results.
Validate the design
You must demonstrate that the final design meets intended use and user needs.
Where required, this may include clinical or performance evaluation.
Evidence:
Validation plans and results, including clinical or performance evaluation where applicable.
Control design transfer
Design information must be transferred to production in a controlled manner.
Evidence:
Records showing that manufacturing methods are suitable and capable of consistently producing the product.
Control design changes
Design changes must be reviewed for their effect on:
• Product components
• Existing products
• Products already in the field
• Risk management
• Regulatory requirements
Evidence:
Change records, approvals and regulatory notifications where required.
Maintain design records
You must maintain a design and development file for each applicable device or product family.
Evidence:
A complete design history showing the design process and related records.
________________________________________
Supplier and Purchasing Controls
Evaluate suppliers
Suppliers must be evaluated and selected using documented criteria based on their potential impact on product quality.
Evidence:
• Supplier evaluation criteria
• Approved supplier list
• Initial evaluation records
• Re-evaluation records
• Quality agreements where appropriate
Control supplier changes
Suppliers should be required to notify you before making changes that could affect your requirements.
Evidence:
Supplier agreements and records of supplier change notifications.
Communicate purchasing requirements
You must clearly communicate your requirements to suppliers.
These may include:
• Product specifications
• Competence requirements
• Quality system requirements
• Inspection requirements
Evidence:
Purchase specifications and supplier communication.
Verify purchased products
Purchased products and services must be verified before use where required.
Evidence:
Incoming inspection records, certificates and other verification records.
________________________________________
Production and Service Provision
Control production
Production must be carried out under controlled conditions.
This includes having the necessary:
• Procedures
• Work instructions
• Specifications
• Equipment
• Monitoring methods
• Labelling requirements
• Production records
Control product cleanliness
Where cleanliness affects product safety or performance, cleanliness requirements must be defined and controlled.
Evidence:
Cleanliness requirements and relevant records.
Control installation
Where installation is required, installation instructions and acceptance criteria must be documented.
Evidence:
Installation instructions and verification records.
Control servicing
Where servicing is provided, servicing procedures and service records must be maintained.
Service information should also be reviewed for complaints or trends.
Control sterilisation
For sterile products, sterilisation parameters must be recorded for each applicable batch.
Validate special processes
Processes where the result cannot be fully verified through later inspection must be validated.
Examples may include:
• Sterilisation
• Sealing
• Welding
• Moulding
• Cleaning
• Aseptic filling
Evidence:
Validation protocols, acceptance criteria, validation reports, equipment qualification and revalidation records.
Validate sterilisation and sterile barrier processes
Sterilisation and sterile barrier systems must be validated before use and after relevant changes.
Identify products
Products must remain identifiable throughout production, and their inspection status must be clear.
Evidence:
Identification systems, status labels and controls for returned products.
Maintain traceability
You must have a documented traceability process that defines how far product traceability must extend.
Evidence:
Batch or serial number records and Unique Device Identification records where required.
Additional traceability for implantable devices
For implantable devices, records should allow traceability of relevant components, materials and environmental conditions.
Distribution records should also identify the consignee where necessary for recall purposes.
Protect customer property
Customer property must be protected while under your control.
This may include:
• Physical property
• Intellectual property
• Confidential information
• Health information
Any loss or damage must be reported.
Preserve products
Products must be protected during:
• Processing
• Storage
• Handling
• Packaging
• Distribution
Special conditions such as temperature and humidity must be controlled where required.
Control monitoring and measuring equipment
Measuring equipment must be calibrated or verified against suitable standards.
Evidence:
• Equipment register
• Calibration records
• Traceability information
• Calibration intervals
• Equipment status identification
Act when equipment is out of calibration
If equipment is found to be out of calibration, you must determine whether previously measured products may have been affected.
Evidence:
Impact assessment and records of actions taken.
________________________________________
8. Measurement, Analysis and Improvement
Relevant clauses: 8.1 through 8.5.3
Plan monitoring and measurement
You must plan the monitoring, measurement, analysis and improvement activities needed for your quality system.
Where statistical methods are used, the method and reason for its selection should be documented.
Collect product feedback
You must collect feedback during production and after products reach the market.
Sources may include:
• Customers
• Users
• Service reports
• Installation reports
• Product returns
• Market information
• Relevant literature
Feedback should be considered in risk management and product improvement.
Control complaints
You must have a documented complaint-handling process and ensure complaints are handled in a timely manner.
Evidence:
Complaint procedure and complaint records showing dates and actions taken.
Assess complaint reportability
Each complaint must be assessed to determine whether it needs to be reported to a regulatory authority.
Evidence:
A documented reportability assessment for each complaint.
Record reasons for not investigating complaints
If a complaint is not investigated, the reason must be documented.
Report regulatory events
You must have a process for reporting events to regulators within the required timeframe.
Evidence:
Vigilance procedures, market-specific reporting requirements, regulatory reports and authority correspondence.
Conduct internal audits
You must audit your quality management system using a documented and risk-based audit programme.
Auditors should have appropriate competence and independence.
Evidence:
• Internal audit procedure
• Audit programme
• Audit plans
• Audit criteria and scope
• Audit reports
• Auditor competence records
• Evidence of auditor independence
Take corrective action
Corrective actions must be taken without unnecessary delay and their effectiveness must be verified.
Evidence:
Corrective action records, effectiveness checks and closure records.
Monitor processes
You must monitor and measure your processes and take action when planned results are not achieved.
Monitor product conformity
Products must be checked against defined acceptance criteria.
Evidence:
Inspection and testing records, including identification of the person who authorised product release.
Control nonconforming products
Nonconforming products must be identified and controlled so they cannot be accidentally used or delivered.
Evidence:
• Nonconformity procedure
• Quarantine or system hold
• Nonconformity records
• Authorised disposition decisions
Document the decision on nonconforming products
The decision about what happens to a nonconforming product must be documented and authorised.
Possible decisions may include:
• Rework
• Rejection
• Scrap
• Concession, where permitted
Act on nonconforming products already delivered
If a nonconforming product has already been supplied, appropriate action must be taken.
This may include advisory notices or field safety corrective actions where necessary.
Control rework
If a product is reworked, the rework instructions must be properly approved and the effect of the rework on the product must be assessed.
Analyse quality data
You must analyse information from areas such as:
• Feedback
• Complaints
• Product conformity
• Trends
• Suppliers
• Audits
• Service reports
Evidence:
Documented analysis methods and records showing the results of analysis.
Use analysis to improve the system
The analysis should help determine whether the quality management system remains suitable and effective and should lead to appropriate actions.
Maintain system effectiveness
You must use information from:
• Quality policy
• Quality objectives
• Audits
• Data analysis
• Corrective actions
• Preventive actions
• Management reviews
to maintain and improve the effectiveness of the quality management system.
Correct the root cause of problems
You must have a documented corrective action process that addresses the root cause rather than simply fixing the immediate problem.
Evidence:
Corrective action records with documented cause analysis.
Check the effect of corrective action
Corrective action must not negatively affect product safety or regulatory compliance.
Evidence:
Documented verification of the action.
Verify corrective action effectiveness
You must confirm that corrective actions were effective and completed without unnecessary delay.
Maintain preventive action
ISO 13485:2016 also requires a separate preventive action process for identifying and addressing potential problems before they occur.
Evidence:
Preventive action procedures and records showing proactive action.
________________________________________
How to Use This Guide
ISO 13485:2016 is not simply about creating many documents, templates or forms.
The key requirement is to demonstrate that important decisions and activities have been properly planned, documented, implemented and maintained.
More documentation does not automatically mean better compliance.
A procedure that is very detailed but is not followed can create a bigger gap than a simple procedure that accurately reflects how the organization actually works.
The important question is:
Does the documented system reflect what people actually do, and can the organization provide objective evidence that the requirements are being met?
That is what an auditor will ultimately look for when assessing the effectiveness of an ISO 13485:2016 quality management system.
What this covers
See how this looks as a working system
Reading about a requirement and seeing the documentation that satisfies it are different things. In a short demo we open the actual manual, procedures and records set for ISO 13485, show you how each clause is answered and where your existing way of working already fits. You will know what implementation involves before you commit to it.
More reading
- FDA Implements QMSR as the New Quality Management Standard in February
The FDA now incorporates ISO 13485:2016 into 21 CFR Part 820, reducing the compliance gap for international medical device manufacturers.
12 septembre 2026
- Certification for Indian exporters: what buyers actually ask for
Which standard an Indian exporter needs is decided by the buyer, the destination market and the sector — not by which certificate is cheapest to obtain.
12 septembre 2026
- Management system consulting across six markets
The clauses do not change between India, Mongolia, Australia, Nigeria, South Africa and the United States. Almost everything around them does.
30 août 2026
