skills/iso-13485-certification/references/quality-manual-guide.md
Research basis: 2026-07-23. This guide explains an evidence-controlled authoring process. It does not reproduce ISO 13485 text or prescribe a universal manual format.
A quality manual template cannot establish an effective QMS, conformity, certification, FDA compliance, MDSAP acceptance, EU conformity, or legal applicability. It cannot replace authorized management, RA/QA, legal, notified-body, regulatory-authority, MDSAP Auditing Organization, or certification-body decisions.
ISO publications are copyrighted. Obtain ISO 13485 from ISO, a national member, or an authorized source. Do not paste standard text into the manual. Summarize the organization's actual processes and reference its controlled authorized copy.
A useful manual or equivalent policy architecture:
The manual should be the length and structure needed for the organization. Page count, a fixed procedure list, or mirroring standard headings does not prove adequacy.
Create a controlled source ledger before drafting. At minimum record:
For each source, capture publisher, title, edition/version/date, official URL or authorized location, access date, owner, currency-review date, impact assessment, status, and approval.
Record:
Do not let an agent decide applicability. Undetermined remains a blocker until an
authorized human approves a decision and rationale.
Interview accountable process owners and inspect actual records. Build a process map from the organization's work—not from copied standard headings.
For each process record:
Include management, support, product lifecycle, assurance, feedback, and improvement processes. Show how complaints/postmarket data update risk, design, production, suppliers, CAPA, and management review.
Create a matrix that links manual statements to:
Do not describe a referenced document as effective until its approval, effective date, training, and availability are evidenced.
Use the fail-closed template in
assets/templates/quality-manual-template.md. Keep statements factual and
organization-specific:
<controlled ID/revision>.”<controlled record series/location>.”<role> owns the decision, with approval in <record ID>.”<authorized review>.”Avoid:
Perform independent review in two directions:
Sample across products, sites, shifts/time periods, suppliers, systems, changes, and risk as justified. Record limitations and open gaps.
Before release:
Review when products, sites, roles, processes, suppliers, systems, standards, regulations, audit programs, certificates, or postmarket evidence change—not only on an arbitrary calendar date.
Include document ID, revision, owner, status, effective date, confidentiality, controlled location, change record, superseded revision, reviewers, approvers, dates, and approval evidence.
State the intended organizational use and hard boundaries. Use definitions from approved organizational and regulatory sources; do not copy protected standard text.
State entities, sites, products, activities, outsourced processes, and interfaces. Reference the approved scope/applicability intake. List unresolved decisions as blockers.
Identify exact ISO, FDA, MDSAP, EU, and product sources separately. Include owner and currency-review controls.
Describe top-management authority, authorized management representative, RA/QA, process owners, document/record control, release authorities, audit independence, complaint/reportability roles, CAPA/change approval, delegates, and escalation.
At a policy level, describe and cross-reference:
Explain how product/family files point to requirements, specifications, risk, design, validation, production, release, distribution, clinical/performance, postmarket, complaint, vigilance, and change evidence. Preserve jurisdiction-specific records rather than claiming one file concept replaces another.
Use controlled appendices or references for:
QMSR became effective 2026-02-02. Describe current Part 820 and relevant FDA processes; do not present the former QSR/QSIT structure as current. Link to current 21 CFR Part 820 and Compliance Program 7382.850. An ISO certificate does not exempt a manufacturer from FDA inspection.
Reference current MDSAP AU P0002.010 (2026-02-02) and declared participating jurisdictions. Do not describe an ISO-only audit as MDSAP or an FDA inspection as using the MDSAP plan.
Reference the current consolidated regulation, applicable conformity-assessment route, technical documentation, postmarket/vigilance, economic-operator, and notified-body evidence separately. Verify notified-body designation scope in NANDO. MDCG guidance is nonbinding and must be version-controlled.
Record the certification body's scope and, if accredited certification is sought, the accreditation scope relevant to ISO 13485 technical areas. This does not establish notified-body designation or product conformity.
Use scripts/gap_analyzer.py and scripts/validate_evidence_manifest.py only to
identify structural gaps before substantive human review.