skills/iso-standards-readiness/references/gap-analysis-checklist.md
Research basis: 2026-07-23, extended 2026-07-26 for laboratory lanes. This checklist organizes evidence questions; it is not ISO or IEC text, an audit, an assessment, a legal determination, or a compliance score.
Sections up to "Training, competence, and change control" apply to the device QMS lanes
(iso-13485, iso-14971). The laboratory sections near the end apply to iso-17025
and iso-15189. Use the sections your declared profile covers; do not report on a
domain you did not sample.
Use only:
not-assessed — no authorized decision was recorded;evidence-missing — applicable/expected evidence was not supplied;evidence-incomplete — evidence is draft, unapproved, unsourced, stale, or
insufficiently linked;evidence-present-for-human-review — controlled evidence is available for
substantive review; no adequacy claim;not-applicable-approved — an authorized person approved a documented rationale.Never convert these states into a “compliance percentage.” Unequal, conditional, product-specific, and jurisdiction-specific evidence cannot be responsibly reduced to keyword counts.
| Field | Required content |
|---|---|
| Item ID | Stable unique identifier |
| Scope | Products, sites, processes, suppliers, systems, and period |
| Owner | Accountable role |
| Status | One value from the vocabulary above |
| Evidence | Controlled IDs, revisions/dates, and locations |
| Source/version | Official source, exact edition/version/date, access/currency review |
| Rationale | Evidence-based conclusion or approved not-applicable rationale |
| Action | Gap/change/CAPA ID, owner, due date, and status |
| Approval | Named authorized approver, decision, date, and record ID |
Blank, placeholder, inaccessible, stale, or unapproved fields fail closed.
As of this research date, QMSR is effective and FDA uses Compliance Program 7382.850. Review:
Use scripts/check_qmsr_transition.py; do not create a legacy-QSR clause map as the
current control framework.
iso-17025, iso-15189)iso-17025, iso-15189)iso-17025, iso-15189)iso-15189)Before final review, state which authorized party owns the next decision:
validate_scope_intake.py — accountable scope/applicability decisions (--standard)audit_document_records.py — document, record, retention, and source registercheck_capa.py — CAPA/effectiveness closure gatescheck_traceability.py — risk/design/production/postmarket links; device lanes only,
and not metrological traceabilitycheck_qmsr_transition.py — current post-effective-date QMSR evidence; US device lanevalidate_evidence_manifest.py — bounded local readiness manifest (--standard)check_supplier_controls.py — risk-based supplier and external-provider evidencegap_analyzer.py — domain coverage without keyword or percentage scoring
(--standard)Pass --standard iso-13485|iso-14971|iso-17025|iso-15189 to the three profile-aware
checks so the domain vocabulary matches the standard under review. An unlisted value is
refused rather than defaulted.
All tools are local JSON/Markdown structural checks. Exit 0 means only that no structural finding was generated for the supplied data.