skills/iso-13485-certification/references/mandatory-documents.md
Research basis: 2026-07-23. This is a process-oriented planning reference, not a list of copyrighted ISO requirements.
ISO 13485 does not require one universal package of a fixed number of separately titled procedures for every organization. Document architecture depends on QMS scope, products, lifecycle activities, sites, outsourced processes, applicable regulatory requirements, and how controlled processes are combined or split.
Avoid:
Use an authorized copy of ISO 13485 and current jurisdiction/product sources to identify the documentation and records that actually apply. ISO publications are copyrighted; see ISO copyright.
Maintain:
Minimum fields: source ID, publisher, title, edition/version/date, authorized location, access date, owner, status, currency-review date, impact record, and approval.
Typical controlled documents and records:
The quality manual is not evidence that the processes operate. Link it to approved procedures and sampled implementation records.
An organization may combine or separate controlled procedures. Use titles that match actual work. At minimum, assess whether controlled documentation is needed for:
Each controlled process should identify purpose, scope, roles, inputs, outputs, methods, decision criteria, records, interfaces, measures, change controls, source/version basis, approval, and effective date.
Maintain a controlled file architecture for each applicable product/type/family. Depending on product and jurisdiction, evidence may include:
Do not claim that an ISO 13485 “medical device file” automatically replaces every FDA, EU, or other jurisdiction-specific file or record concept. Build a cross-reference that preserves each required record and its source/version.
Procedures describe controls; records show what happened. Sample actual records for:
For every controlled document, capture:
For every record series, capture:
Unknown, placeholder, unapproved, uncontrolled, or inaccessible entries are gaps—not assumed evidence.
Maintain the authorized standard edition, certification scope, sites/activities, certification-body and accreditation-scope evidence, audit program, findings, and certificate status. A certificate is limited to its scope and is not a product or regulatory authorization.
Since 2026-02-02, use current 21 CFR Part 820, the incorporated ISO edition, current FDA supplemental provisions, and other applicable FDA regulations. FDA now uses Compliance Program 7382.850, not QSIT. Keep evidence for current complaint, servicing, labeling/packaging, and other FDA-specific requirements. Do not retain old QSR section numbers as the current control model.
FDA's QMSR FAQ states that investigators may review pre-effective-date QMS records and management, quality-audit, and supplier-audit reports. Prepare controlled retrieval without rewriting history or backdating records.
Use the current MDSAP AU P0002.010 Audit Approach, dated 2026-02-02, and the current MDSAP document library. Record participating jurisdictions, products, sites, recognized Auditing Organization, audit cycle, jurisdiction-specific evidence, findings, and action status. Do not substitute an ISO-only certificate or FDA inspection checklist.
Keep the current consolidated regulation, conformity-assessment route, device classification, technical documentation, QMS, clinical/performance, postmarket, vigilance, registration/UDI, economic-operator, and notified-body evidence as applicable. Verify notified-body designation and codes in NANDO. MDCG guidance is useful but nonbinding; record document number, revision, date, and impact.
For European standards, distinguish ISO publications from EN adoptions, corrigenda, and European A11 amendments. Verify current OJEU citations on the Commission's harmonised standards page.
Do not use generic “5–10 year” statements or “device lifetime” as a complete retention schedule. For each record type, authorized reviewers should reconcile:
Record the chosen period, start event, source/version, rationale, owner, approval, disposition method, and hold override.
A document or record is ready for substantive human review only when:
Use scripts/audit_document_records.py for structural checks and
scripts/validate_evidence_manifest.py for a bounded local manifest. Passing either
means only that the supplied fields passed deterministic checks.