skills/iso-13485-certification/references/gap-analysis-checklist.md
Research basis: 2026-07-23. This checklist organizes evidence questions; it is not ISO text, an audit, a legal determination, or a compliance score.
Use only:
not-assessed — no authorized decision was recorded;evidence-missing — applicable/expected evidence was not supplied;evidence-incomplete — evidence is draft, unapproved, unsourced, stale, or
insufficiently linked;evidence-present-for-human-review — controlled evidence is available for
substantive review; no adequacy claim;not-applicable-approved — an authorized person approved a documented rationale.Never convert these states into a “compliance percentage.” Unequal, conditional, product-specific, and jurisdiction-specific evidence cannot be responsibly reduced to keyword counts.
| Field | Required content |
|---|---|
| Item ID | Stable unique identifier |
| Scope | Products, sites, processes, suppliers, systems, and period |
| Owner | Accountable role |
| Status | One value from the vocabulary above |
| Evidence | Controlled IDs, revisions/dates, and locations |
| Source/version | Official source, exact edition/version/date, access/currency review |
| Rationale | Evidence-based conclusion or approved not-applicable rationale |
| Action | Gap/change/CAPA ID, owner, due date, and status |
| Approval | Named authorized approver, decision, date, and record ID |
Blank, placeholder, inaccessible, stale, or unapproved fields fail closed.
As of this research date, QMSR is effective and FDA uses Compliance Program 7382.850. Review:
Use scripts/check_qmsr_transition.py; do not create a legacy-QSR clause map as the
current control framework.
Before final review, state which authorized party owns the next decision:
validate_scope_intake.py — accountable scope/applicability decisionsaudit_document_records.py — document, record, retention, and source registercheck_capa.py — CAPA/effectiveness closure gatescheck_traceability.py — risk/design/production/postmarket linkscheck_qmsr_transition.py — current post-effective-date QMSR evidencevalidate_evidence_manifest.py — bounded local readiness manifestcheck_supplier_controls.py — risk-based supplier evidencegap_analyzer.py — domain coverage without keyword or percentage scoringAll tools are local JSON/Markdown structural checks. Exit 0 means only that no structural finding was generated for the supplied data.