Knowledge base
ISO 13485:2016: documentation and compliance requirements
Everything ISO 13485:2016 requires you to document, clause by clause, with what an auditor asks to see for each. Written as requirements rather than as a checklist.
Prem Kumar Dvivedi · 12 September 2026
This is what ISO 13485:2016 requires you to have, clause by clause, and what an auditor will ask to see for each of it. It covers 85 requirements across 5 areas.
It is deliberately not a checklist. A checklist asks whether you have something; this says what is required and what counts as evidence, which is the question that matters when you are building a system rather than testing one. If you would rather find out where you stand first, the same ground is covered by our free ISO 13485:2016 readiness assessment, which scores you out of 100.
4 The quality system and your paperwork
Clauses 4.1.1, 4.1.2, 4.1.6, 4.2.1, 4.2.2, 4.2.3, 4.2.4, 4.2.5.
You must have written down what role you play under the regulations — manufacturer, authorised representative, importer or distributor.
Evidence: A written statement of your role for each product and market. Your obligations depend on it.
You must know which regulations apply in each market you sell into.
Evidence: A register by market — EU MDR or IVDR, US FDA, India CDSCO, Saudi SFDA and others. Device classification for each. Registrations and licences held.
You must have written down what your quality system covers, and justified anything you have left out.
Evidence: A scope statement. Justification for any requirement of sections 6, 7 or 8 that does not apply, based on the regulations, not on convenience. Sections 4 and 5 can never be left out.
You must know what your processes are, how they connect, and how you control the ones you outsource.
Evidence: A process map. Agreements with anyone doing work on your behalf, and evidence you monitor them.
Where you use software in the quality system or in production, you must have checked it works properly before using it.
Evidence: Validation records for each piece of software, matched to how much risk it carries. This includes spreadsheets used for calculations and label printing systems.
You must have the documents the standard asks for, including a quality manual.
Evidence: A list of documents and records held.
The quality must manual describe the scope, the procedures, and how the processes interact.
Evidence: The manual, with the structure of your documentation described in it.
You must hold a file for each product or product family, containing or pointing to everything about it.
Evidence: A medical device file per device: description and intended use, labelling and instructions for use, specifications, manufacturing and packaging procedures, storage and handling, measuring and monitoring, and installation and servicing where relevant.
That file must be kept up to date through the life of the product.
Evidence: Revision history showing it is maintained, not created once at launch.
Documents must be checked and approved before use, and re-approved when changed.
Evidence: Approval records. Change review by the same function that approved the original, or one with the same information.
People must be able to find the current version where they need it, and are old versions kept out of use.
Evidence: Distribution records. Evidence obsolete copies are removed. At least one controlled obsolete copy retained, as the standard requires.
Records must be kept for at least the lifetime of the device, and for as long as the regulations require.
Evidence: A retention schedule stating the device lifetime you have defined and the retention derived from it. Regulatory retention periods by market. Records kept legible and retrievable for the whole period, including electronic ones.
Records must be containing health information kept confidential.
Evidence: Access controls over patient or user health data.
5 Management responsibility
Clauses 5.1, 5.2, 5.3, 5.4.1, 5.4.2, 5.5.1, 5.5.2, 5.5.3, 5.6.1, 5.6.2, 5.6.3.
Senior management must be able to show they are committed — with resources provided and requirements communicated.
Evidence: Management review notes. Money and people provided. Evidence regulatory and customer requirements are communicated through the organisation.
You must make sure customer and regulatory requirements are identified and met.
Evidence: Requirement records per product and market.
You must have a quality policy, appropriate to what you do, promising to comply and to keep the system effective.
Evidence: The policy, signed and dated, communicated and reviewed.
You must have set measurable quality objectives at the relevant levels.
Evidence: Objectives with targets and numbers, consistent with the policy.
You must plan the quality system, and keep it whole when you change something.
Evidence: Quality planning records. Change records showing the system stayed intact through the change.
It must be clear who is responsible for what, and it must be communicated.
Evidence: Organisation chart. Job descriptions or responsibility list.
You must have appointed a member of management to look after the quality system.
Evidence: The appointment with defined responsibility, including making sure people are aware of regulatory and customer requirements, and reporting on the system to senior management.
You must have arrangements for communicating within the organisation about the quality system.
Evidence: Meeting structure. Briefings. Evidence information moves between functions.
Senior management must review the system at intervals you have written down.
Evidence: A documented procedure stating the frequency. Review dates and attendance.
The review must cover every input the standard lists.
Evidence: An agenda covering: feedback, complaint handling, reporting to authorities, audits, process and product monitoring, corrective and preventive actions, follow-up from previous reviews, changes affecting the system, improvement recommendations, and new or changed regulatory requirements.
The review must produce recorded decisions and actions.
Evidence: Outputs on improvement, changes needed, and resources. An action list with owners and dates.
6 Resources
Clauses 6.1, 6.2, 6.3, 6.4.1, 6.4.2.
You must provide the resources needed to run the system and meet regulatory and customer requirements.
Evidence: Budget. Staffing. Equipment.
You must know what competence each job affecting product quality requires.
Evidence: Documented competence criteria per role, covering education, training, skills and experience.
You must be able to show the people have it, and that any training you gave actually worked.
Evidence: Records per person. Evidence effectiveness was checked, in a way proportionate to the risk of the work — not just an attendance sheet.
People must know why their work matters and how it affects quality objectives.
Evidence: Awareness records. Ask staff.
You must have written down what buildings, equipment and support services you need, and you must maintain them.
Evidence: Documented infrastructure requirements. Planned maintenance with defined intervals, and the records showing it was done.
You must have written down the working environment conditions needed, and you must control them.
Evidence: Documented requirements covering health, cleanliness and clothing of personnel where these can affect product. Monitoring records.
Where contamination matters, you must have arrangements to prevent it.
Evidence: Contamination control. Cleanroom or controlled area arrangements with monitoring. Special arrangements for sterile devices, including particulate control. Answer N/A with a reason if it genuinely does not apply.
7 Making the product
Clauses 7.1, 7.2.1, 7.2.2, 7.2.3, 7.3.1, 7.3.3, 7.3.4, 7.3.5, 7.3.6, 7.3.7, 7.3.8, 7.3.9, 7.3.10, 7.4.1, 7.4.2, 7.4.3, 7.5.1, 7.5.2, 7.5.3, 7.5.4, 7.5.5, 7.5.6, 7.5.7, 7.5.8, 7.5.9.1, 7.5.9.2, 7.5.10, 7.5.11, 7.6.
You must plan how each product will be made, with the checks, records and acceptance criteria needed.
Evidence: Product realisation planning records. Quality plans or equivalent.
Risk management must be applied right across product realisation, and are the records kept for the life of the product.
Evidence: A documented risk management process aligned with ISO 14971. A risk management plan and file per device. Hazard identification, analysis, evaluation, controls and residual risk. Evidence the controls were verified as effective. Production and post-production information fed back into the file — a file closed at launch is a finding.
You must determine what the customer requires, including delivery, regulatory requirements and any user training needed.
Evidence: Requirement records. Requirements not stated but necessary for safe use. User training needs identified where they exist.
You must review those requirements before you commit, and record the result.
Evidence: Contract or order review records with the outcome and any actions.
If requirements change afterwards, you must update the documents and tell the people affected.
Evidence: Amendment records.
You must have arrangements for communicating with customers — enquiries, orders, feedback, complaints and advisory notices.
Evidence: Communication arrangements and records.
If you design, the must be design work planned, with stages, reviews, verification, validation, transfer and change control.
Evidence: A design and development plan with responsibilities and traceability methods. Answer N/A with a justification if you do no design — but note the justification must rest on the regulations.
You must write down the design inputs, including function, performance, safety, regulatory requirements and the outputs of risk management.
Evidence: Design input records, reviewed for adequacy and approved.
The design must outputs meet the inputs, and they must state the acceptance criteria and what is essential for safe use.
Evidence: Design output records, approved before release.
Design reviews must be held at planned stages, with the right people present and the results recorded.
Evidence: Review records with participants and outcomes.
You must verify that the design outputs meet the inputs, with a documented plan and recorded results.
Evidence: Verification plans, methods, acceptance criteria and results.
You must validate the design — show it meets the needs of the intended use — including clinical or performance evaluation where required.
Evidence: Validation plans and results. Clinical evaluation or performance evaluation where the regulations require it. Validation on representative product.
The must be design transferred to manufacturing in a controlled way, with the outputs verified as suitable for production.
Evidence: Design transfer records confirming production methods can consistently make the product.
Design changes must be reviewed for their effect on parts, product already made, product in the field, the risk file and regulatory notification — and approved before use.
Evidence: Change records with all of that assessed. Approval before implementation. Regulatory notification where the change is significant.
You must keep a design file for each device or family.
Evidence: The design and development file, covering the whole design history.
You must evaluate and select suppliers on written criteria, matched to how much the purchased item affects device quality.
Evidence: Selection criteria. Approved supplier list. Evaluation and re-evaluation records. Quality agreements where appropriate.
Your suppliers must agree to tell you before they change anything.
Evidence: The notification requirement in the agreement, and evidence changes have been notified.
You must tell suppliers exactly what you need, including any qualification of their people and any quality system requirements.
Evidence: Purchasing information. Specifications sent.
You must verify what suppliers deliver before you use it.
Evidence: Incoming inspection or other verification records. Certificates checked, not just filed.
Production must be carried out under controlled conditions, with the right documents, equipment, monitoring and labelling.
Evidence: Documented procedures, work instructions, specifications, reference materials and measurement procedures available at the point of work. Production records per batch or unit.
It must be defined where the product must be clean, or cleaned before use, are the requirements documented and met.
Evidence: Cleanliness requirements and records. Answer N/A with a reason if not applicable.
Where the device is installed, installation requirements and acceptance criteria must be documented, and installation records kept.
Evidence: Installation instructions and verification records. N/A with a reason if you do not install.
Where the device is serviced, servicing procedures must be documented and service records kept and analysed.
Evidence: Servicing procedures. Service records reviewed to see whether they reveal a complaint or a trend. N/A with a reason if you do not service.
For sterile devices, the sterilisation process parameters must be recorded for each batch.
Evidence: Sterilisation records per batch, traceable to the device. N/A with a reason if not applicable.
Where you cannot verify the result afterwards, the process been validated — and revalidated when it changes must have been done.
Evidence: A list of processes needing validation, such as sterilising, sealing, welding, moulding, cleaning and aseptic filling. Validation protocols with acceptance criteria, and reports. Revalidation criteria and records. Equipment qualification.
For sterilisation and sterile barrier systems, the process been validated before use and after change must have been done.
Evidence: Validation records for sterilisation and the sterile barrier. N/A with a reason if not applicable.
Product must be identified throughout, and is its inspection status clear.
Evidence: Identification method. Status labelling showing what has been checked and what has not. Returned product identified and separated.
You must have a documented traceability procedure, and it must define how far traceability must go.
Evidence: The procedure and the records it requires. Batch or serial records. Unique device identification where required.
For implantable devices, the records must go far enough to trace components, materials and conditions that could make the device unsafe.
Evidence: Component, material and environment records for implantables. Distribution records naming the consignee so a recall can reach them. N/A with a reason if you make no implantables.
You must look after property belonging to customers, and report it if it is lost or damaged.
Evidence: Records of customer property held, including intellectual property and confidential health information. Reports of loss or damage.
You must preserve the product through processing, storage, handling and distribution.
Evidence: Preservation arrangements covering contamination, damage and deterioration. Special conditions such as temperature or humidity, monitored and recorded. Shelf life and stock rotation.
Measuring equipment must be calibrated or verified against a traceable standard, protected from tampering, and its status identified.
Evidence: Equipment register. Calibration records traceable to national or international standards, or the basis recorded where none exists. Calibration intervals. Status labelling.
When equipment is found to be out of calibration, you must assess the product measured with it and act.
Evidence: Records of the assessment and the action taken on affected product. Validation of any software used for monitoring and measurement.
8 Measurement, analysis and improvement
Clauses 8.1, 8.2.1, 8.2.2, 8.2.3, 8.2.4, 8.2.5, 8.2.6, 8.3.1, 8.3.2, 8.3.3, 8.3.4, 8.4, 8.5.1, 8.5.2, 8.5.3.
You must have planned the monitoring, measurement, analysis and improvement you need, including the statistical methods you will use.
Evidence: The plan and the rationale for the methods chosen.
You must gather feedback from production and after the product is on the market.
Evidence: A documented feedback process. Feedback from users, service and installation reports, returns, market and literature information. Evidence it feeds back into risk management and into how you make the product.
You must have a documented complaint handling process, and are complaints handled promptly.
Evidence: The procedure. Complaint records with dates and timeliness.
Every must be complaint assessed to decide whether it must be reported to a regulator.
Evidence: The reportability assessment recorded for each complaint.
If a complaint is not investigated, the must be reason recorded.
Evidence: The recorded justification. This is a specific requirement and it is often missed.
You must have arrangements for notifying regulators of reportable events, within the required time.
Evidence: Vigilance procedures with reporting timeframes per market. Submitted reports and authority correspondence. Contact details for each authority.
You must audit your own system, with a documented procedure, a risk-based programme, and independent auditors.
Evidence: The procedure. An audit programme reflecting the importance of processes and previous results. Audit plans, criteria, scope and reports. Auditor competence and independence.
You must be able to answer: Is action taken without undue delay, and is the action verified?
Evidence: Corrective actions closed. Evidence of verification and of reporting the verification results.
You must monitor and measure your processes, and act when planned results are not achieved.
Evidence: Process monitoring records. Action taken when a process did not deliver.
You must monitor and measure the product against acceptance criteria, and record who released it.
Evidence: Inspection records at the stages your plan requires. The identity of the person authorising release.
Nonconforming product must be identified and controlled so it cannot be used or delivered by mistake.
Evidence: A documented procedure defining who may review and decide. Quarantine or system hold. Nonconformity records.
The must be decision on what to do with it recorded, with a justification and the name of who authorised it.
Evidence: Disposition records. Concession records naming the authoriser. Customer agreement where needed.
If nonconforming product has already been delivered, you must act on it — including issuing an advisory notice where needed.
Evidence: Records of action taken after delivery. Advisory notices and field safety corrective actions with their effectiveness checked.
Where product is reworked, the must be rework instruction approved to the same level as the original, and is the effect on the product assessed.
Evidence: Rework instructions with equivalent approval. An assessment of any adverse effect of the rework.
You must analyse data from feedback, complaints, conformity, trends, suppliers, audits and service reports.
Evidence: A documented procedure with the methods and the reason for choosing them. Analysis outputs covering all those sources.
That analysis must show whether the system is suitable and effective, and it must lead to action.
Evidence: Conclusions drawn. Actions raised. Analysis presented at management review.
You must use the policy, objectives, audits, analysis, corrective and preventive action and management review to keep the system effective.
Evidence: Evidence of changes made to maintain effectiveness.
You must have a documented corrective action procedure, and you must find the cause rather than just fixing the symptom.
Evidence: The procedure. Corrective action records with cause analysis.
You must check that the corrective action has not made the product less able to meet safety or regulatory requirements.
Evidence: The verification recorded. This is specific to ISO 13485 and is often missed.
You must verify the action was effective, and is action taken without undue delay.
Evidence: Effectiveness review with a date. Closure timeliness data.
You must have a separate preventive action procedure, dealing with problems that have not happened yet.
Evidence: The procedure and preventive action records. Evidence these are genuinely proactive, not corrective actions with a different label. Preventive action still exists in ISO 13485, unlike ISO 9001.
Using this document
Nothing above asks for a manual, a template pack, or a filing system. It asks for decisions that have been taken deliberately and can be shown to have been taken — which is a far smaller job than most organisations expect, and a different one.
Length is not compliance. A procedure nobody follows is worse than no procedure, because an auditor finds the gap between the two. The test we apply is whether the person who has to do the job recognises their own work in what is written down.
What this covers
See how this looks as a working system
Reading about a requirement and seeing the documentation that satisfies it are different things. In a short demo we open the actual manual, procedures and records set for ISO 13485, show you how each clause is answered and where your existing way of working already fits. You will know what implementation involves before you commit to it.
More reading
- FDA's QMSR replaced the Quality System Regulation in February
21 CFR Part 820 now incorporates ISO 13485:2016 by reference. For device manufacturers outside the US, the gap just narrowed considerably.
12 September 2026
- Certification for Indian exporters: what buyers actually ask for
Which standard an Indian exporter needs is decided by the buyer, the destination market and the sector — not by which certificate is cheapest to obtain.
12 September 2026
- Management system consulting across six markets
The clauses do not change between India, Mongolia, Australia, Nigeria, South Africa and the United States. Almost everything around them does.
30 August 2026
