Back to Claude Scientific Skills

Quality Manual Development Guide

skills/iso-13485-certification/references/quality-manual-guide.md

2.55.010.3 KB
Original Source

Quality Manual Development Guide

Research basis: 2026-07-23. This guide explains an evidence-controlled authoring process. It does not reproduce ISO 13485 text or prescribe a universal manual format.

A quality manual template cannot establish an effective QMS, conformity, certification, FDA compliance, MDSAP acceptance, EU conformity, or legal applicability. It cannot replace authorized management, RA/QA, legal, notified-body, regulatory-authority, MDSAP Auditing Organization, or certification-body decisions.

ISO publications are copyrighted. Obtain ISO 13485 from ISO, a national member, or an authorized source. Do not paste standard text into the manual. Summarize the organization's actual processes and reference its controlled authorized copy.

Purpose of a manual

A useful manual or equivalent policy architecture:

  • identifies the approved QMS scope;
  • identifies controlled processes and their interactions;
  • states governance, authorities, and responsibilities;
  • explains the documentation/evidence hierarchy;
  • points to organization-specific controlled procedures and records; and
  • distinguishes the applicable standard, regulatory, audit, and product sources.

The manual should be the length and structure needed for the organization. Page count, a fixed procedure list, or mirroring standard headings does not prove adequacy.

Development workflow

1. Establish an authorized source baseline

Create a controlled source ledger before drafting. At minimum record:

  • ISO 13485:2016, Edition 3, and authorized location;
  • the applicable EN adoption/amendment/corrigendum if European harmonisation is being used;
  • current FDA QMSR/eCFR sources if U.S. operations are in declared scope;
  • current MDSAP Audit Approach if MDSAP is in declared scope;
  • current consolidated MDR or IVDR, OJEU harmonised-standard decisions, and relevant MDCG guidance if EU work is in declared scope;
  • ISO 14971/EN A11 and product-specific standards where applicable; and
  • current product/jurisdictional regulations and guidance.

For each source, capture publisher, title, edition/version/date, official URL or authorized location, access date, owner, currency-review date, impact assessment, status, and approval.

2. Freeze purpose and scope

Record:

  • legal entities and sites;
  • product types/families and controlled intended-use references;
  • lifecycle activities performed at each site;
  • outsourced processes and interfaces;
  • markets being considered;
  • organizational and physical boundaries;
  • assurance purpose (ISO certification, FDA, MDSAP, EU, internal); and
  • limitations and unresolved applicability decisions.

Do not let an agent decide applicability. Undetermined remains a blocker until an authorized human approves a decision and rationale.

3. Map actual process interactions

Interview accountable process owners and inspect actual records. Build a process map from the organization's work—not from copied standard headings.

For each process record:

  • inputs and outputs;
  • owner, authority, delegate, and escalation;
  • controlled procedure/system;
  • implementation records;
  • interfaces to risk and change control;
  • measures and review method;
  • source/version basis;
  • status and approval.

Include management, support, product lifecycle, assurance, feedback, and improvement processes. Show how complaints/postmarket data update risk, design, production, suppliers, CAPA, and management review.

4. Build a controlled cross-reference

Create a matrix that links manual statements to:

  • controlled procedure IDs and revisions;
  • forms and record series;
  • product/device/technical files;
  • risk and traceability evidence;
  • system/software validation;
  • process owners and approvals;
  • source/version criteria; and
  • open gaps/change/CAPA records.

Do not describe a referenced document as effective until its approval, effective date, training, and availability are evidenced.

5. Draft policy-level content

Use the fail-closed template in assets/templates/quality-manual-template.md. Keep statements factual and organization-specific:

  • “The approved process is defined in <controlled ID/revision>.”
  • “Evidence is retained in <controlled record series/location>.”
  • <role> owns the decision, with approval in <record ID>.”
  • “Applicability remains undetermined pending <authorized review>.”

Avoid:

  • “The organization is compliant” or “audit ready”;
  • “This template satisfies ISO/FDA/EU requirements”;
  • generic quality policies presented as approved;
  • fixed timelines or retention periods without source/risk basis;
  • unsupported “not applicable” statements;
  • old QSR clause maps presented as current QMSR; and
  • claims that an ISO certificate covers FDA, MDSAP, or EU product conformity.

6. Review against evidence

Perform independent review in two directions:

  1. Manual to evidence: every material statement points to a current controlled source, procedure, owner, and record set.
  2. Evidence to manual: sampled implementation records match the described scope, roles, interactions, and controls.

Sample across products, sites, shifts/time periods, suppliers, systems, changes, and risk as justified. Record limitations and open gaps.

7. Approve, train, release, and maintain

Before release:

  • resolve placeholders;
  • obtain technical, RA/QA, document-control, and authorized management approvals;
  • complete source and applicability reviews;
  • close or formally control open document/process gaps;
  • approve process map and cross-reference;
  • complete affected-person training;
  • verify controlled point-of-use access;
  • assign effective date and obsolete prior revisions; and
  • record maintenance/currency-review triggers.

Review when products, sites, roles, processes, suppliers, systems, standards, regulations, audit programs, certificates, or postmarket evidence change—not only on an arbitrary calendar date.

Suggested content architecture

Controlled-document front matter

Include document ID, revision, owner, status, effective date, confidentiality, controlled location, change record, superseded revision, reviewers, approvers, dates, and approval evidence.

Purpose, limits, and definitions

State the intended organizational use and hard boundaries. Use definitions from approved organizational and regulatory sources; do not copy protected standard text.

QMS scope and applicability

State entities, sites, products, activities, outsourced processes, and interfaces. Reference the approved scope/applicability intake. List unresolved decisions as blockers.

Source/version basis

Identify exact ISO, FDA, MDSAP, EU, and product sources separately. Include owner and currency-review controls.

Governance and roles

Describe top-management authority, authorized management representative, RA/QA, process owners, document/record control, release authorities, audit independence, complaint/reportability roles, CAPA/change approval, delegates, and escalation.

Process architecture

At a policy level, describe and cross-reference:

  • document/record/external-source control;
  • risk management;
  • design/development and transfer/change;
  • suppliers and outsourced processes;
  • production, service, acceptance/release, and traceability;
  • process/equipment/test/software validation;
  • feedback, complaints, postmarket, and vigilance;
  • nonconformity, CAPA, and effectiveness;
  • internal audit and management review;
  • competence/training; and
  • integrated change control.

Product evidence architecture

Explain how product/family files point to requirements, specifications, risk, design, validation, production, release, distribution, clinical/performance, postmarket, complaint, vigilance, and change evidence. Preserve jurisdiction-specific records rather than claiming one file concept replaces another.

Appendices

Use controlled appendices or references for:

  • procedure/record index;
  • source ledger;
  • scope/product/site register;
  • organization chart/authorities;
  • process interaction map;
  • risk-design-production-postmarket traceability matrix;
  • supplier/outsourced-process register;
  • validation/software inventory;
  • open gap/change/CAPA register; and
  • certificate/audit scope and status register.

Regime-specific cautions

FDA QMSR

QMSR became effective 2026-02-02. Describe current Part 820 and relevant FDA processes; do not present the former QSR/QSIT structure as current. Link to current 21 CFR Part 820 and Compliance Program 7382.850. An ISO certificate does not exempt a manufacturer from FDA inspection.

MDSAP

Reference current MDSAP AU P0002.010 (2026-02-02) and declared participating jurisdictions. Do not describe an ISO-only audit as MDSAP or an FDA inspection as using the MDSAP plan.

EU MDR/IVDR

Reference the current consolidated regulation, applicable conformity-assessment route, technical documentation, postmarket/vigilance, economic-operator, and notified-body evidence separately. Verify notified-body designation scope in NANDO. MDCG guidance is nonbinding and must be version-controlled.

Certification and accreditation

Record the certification body's scope and, if accredited certification is sought, the accreditation scope relevant to ISO 13485 technical areas. This does not establish notified-body designation or product conformity.

Review questions

  • Does the scope match actual sites, products, and activities?
  • Are all applicability decisions owned and approved by authorized humans?
  • Does every statement link to current controlled evidence?
  • Are records sampled, not just procedures listed?
  • Are risk, design, production, suppliers, validation/software, and postmarket connected?
  • Are complaint/vigilance and CAPA decisions owned by authorized roles?
  • Do changes link to validation, training, source/version, and product impacts?
  • Are ISO, FDA, MDSAP, EU, and product-specific claims clearly separated?
  • Are certificate, notified-body, and accreditation scopes accurately bounded?
  • Does the manual avoid compliance, conformity, certification, and readiness claims?

Use scripts/gap_analyzer.py and scripts/validate_evidence_manifest.py only to identify structural gaps before substantive human review.