skills/iso-standards-readiness/references/evidence-architecture.md
Research basis: 2026-07-23, extended 2026-07-26 for laboratory lanes. This is a process-oriented planning reference, not a list of copyrighted ISO or IEC requirements.
The five-layer hierarchy below applies to every standard this skill covers. Where the
wording is device-specific, the laboratory equivalent is noted; for depth read
references/iso-17025.md or references/iso-15189.md.
ISO 13485 does not require one universal package of a fixed number of separately titled procedures for every organization. Document architecture depends on QMS scope, products, lifecycle activities, sites, outsourced processes, applicable regulatory requirements, and how controlled processes are combined or split.
Avoid:
Use an authorized copy of ISO 13485 and current jurisdiction/product sources to identify the documentation and records that actually apply. ISO publications are copyrighted; see ISO copyright.
Maintain:
Minimum fields: source ID, publisher, title, edition/version/date, authorized location, access date, owner, status, currency-review date, impact record, and approval.
Typical controlled documents and records:
The quality manual is not evidence that the processes operate. Link it to approved procedures and sampled implementation records.
An organization may combine or separate controlled procedures. Use titles that match actual work. At minimum, assess whether controlled documentation is needed for:
Each controlled process should identify purpose, scope, roles, inputs, outputs, methods, decision criteria, records, interfaces, measures, change controls, source/version basis, approval, and effective date.
Maintain a controlled file architecture for each applicable product/type/family. Depending on product and jurisdiction, evidence may include:
Do not claim that an ISO 13485 “medical device file” automatically replaces every FDA, EU, or other jurisdiction-specific file or record concept. Build a cross-reference that preserves each required record and its source/version.
Laboratory equivalent. For ISO/IEC 17025 and ISO 15189 the technical evidence layer is organized per scope item — per method, measurand, or examination — rather than per product family. Depending on the activity it may include:
An accredited scope schedule is not this layer — it is the output of the accreditation body. Keep the two apart in the register.
Procedures describe controls; records show what happened. Sample actual records for:
For every controlled document, capture:
For every record series, capture:
Unknown, placeholder, unapproved, uncontrolled, or inaccessible entries are gaps—not assumed evidence.
Maintain the authorized standard edition, certification scope, sites/activities, certification-body and accreditation-scope evidence, audit program, findings, and certificate status. A certificate is limited to its scope and is not a product or regulatory authorization.
Maintain the authorized standard edition, the scope of laboratory activities as declared and as accredited, per-location coverage, the accreditation body and its own recognition status, assessment history and findings with their closure evidence, and current accreditation status including any suspension or scope reduction.
Additional controls specific to this lane:
For ISO 15189 specifically, keep CLIA, licensure, and payer evidence in a separate
register. ISO 15189 accreditation does not satisfy CLIA, and blending the two produces
a register that implies an equivalence that does not exist. See
references/iso-15189.md.
Since 2026-02-02, use current 21 CFR Part 820, the incorporated ISO edition, current FDA supplemental provisions, and other applicable FDA regulations. FDA now uses Compliance Program 7382.850, not QSIT. Keep evidence for current complaint, servicing, labeling/packaging, and other FDA-specific requirements. Do not retain old QSR section numbers as the current control model.
FDA's QMSR FAQ states that investigators may review pre-effective-date QMS records and management, quality-audit, and supplier-audit reports. Prepare controlled retrieval without rewriting history or backdating records.
Use the current MDSAP AU P0002.010 Audit Approach, dated 2026-02-02, and the current MDSAP document library. Record participating jurisdictions, products, sites, recognized Auditing Organization, audit cycle, jurisdiction-specific evidence, findings, and action status. Do not substitute an ISO-only certificate or FDA inspection checklist.
Keep the current consolidated regulation, conformity-assessment route, device classification, technical documentation, QMS, clinical/performance, postmarket, vigilance, registration/UDI, economic-operator, and notified-body evidence as applicable. Verify notified-body designation and codes in NANDO. MDCG guidance is useful but nonbinding; record document number, revision, date, and impact.
For European standards, distinguish ISO publications from EN adoptions, corrigenda, and European A11 amendments. Verify current OJEU citations on the Commission's harmonised standards page.
Do not use generic “5–10 year” statements or “device lifetime” as a complete retention schedule. For each record type, authorized reviewers should reconcile:
Record the chosen period, start event, source/version, rationale, owner, approval, disposition method, and hold override.
A document or record is ready for substantive human review only when:
Use scripts/audit_document_records.py for structural checks and
scripts/validate_evidence_manifest.py for a bounded local manifest. Passing either
means only that the supplied fields passed deterministic checks.