QMSdesk

RegulationsRegulations, Medical devices

ISO 13485 requirements by clause, and the record behind each one

ISO 13485:2016 is the international standard for quality management systems at organizations that design, make, service or supply medical devices. ISO reviewed and confirmed the 2016 edition in 2025, so it remains current. Since February 2, 2026, the FDA's QMSR has incorporated it by reference, so FDA investigators now work from the same clauses that certification bodies and EU notified bodies audit. This page maps the ISO 13485 requirements by clause that generate records to the records QMSdesk™ keeps, and to the work that stays yours.

Bring one workflow. We'll show you QMSdesk running it. or download the ISO 13485 clause-by-clause checklist

Where QMSdesk stands on ISO 13485

QMSdesk is designed to support organizations working to ISO 13485:2016, and we'll demonstrate those capabilities on request. We hold no ISO 13485 certificate, and no software can hold one for you. Certification belongs to your organization, and a certification body grants it after auditing your quality system.

What QMSdesk gives you is the record trail. Complaints, nonconformances, CAPAs, supplier decisions, audits and management reviews become linked records, signed at each decision, that you can open in front of an auditor. The medical device profile adds vigilance and post-market surveillance events, UDI and serial number on nonconformances, and design and risk-file impact on each CAPA.

ISO 13485 requirements by clause: the records and controls

We paraphrase each clause we list here. The table covers the clauses that generate records, not every clause in the standard. Your copy of the standard has the exact text. The ISO 13485 records QMSdesk keeps are in the third column.

Requirement (clause, paraphrased) How QMSdesk supports it Evidence the system produces What you still own
§4.1.4. Evaluate changes to QMS processes before you make them. Change control from triage to verification. High-impact changes route to the Change Manager and the Quality Manager. The implementer can't verify their own work unless a signed, time-bound waiver allows it. Signed change records, with approvals and verification. Deciding what counts as a change to a QMS process.
§4.1.6. Document how you validate software used in the QMS. Validate it before first use and after changes, in proportion to risk, and keep records. QMSdesk's core platform is validated under a QA-approved Validation Summary Report, and every engagement includes a written validation scope. We'll walk you through the full record under a mutual NDA. Validating QMSdesk for your intended use, and revalidating after changes.
§4.2.4 Control of documents. Review and approve before issue, keep changes and current versions clear, control external documents, and stop obsolete use. Signed authoring, review and approval by different people. Effective dates, with training assigned on approval. External standards held as reference documents. Superseded and obsolete states. Signed versions, controlled-copy PDFs with every download logged, periodic review tasks. Document content, and your medical device files (§4.2.3).
§4.2.5 Control of records. Keep records legible, identifiable and retrievable, make changes traceable, and retain them for the required period. A SHA-256 hash-chained, insert-only audit trail, verified daily. Records raised in error are cancelled with a signed reason, never hard-deleted. Under the medical device profile, records are kept for at least 15 years from when they reach their final state, and your procedures can set a longer period. The audit trail, daily verification results and the retention clock. Setting the retention you need: ISO 13485 asks for at least the device lifetime you define, and no less than two years from release. EU MDR Article 10(8) asks for at least 10 years (15 for implantables) after the last device is placed on the market, for technical documentation.
§5.6 Management review. Review the QMS at planned intervals, from defined inputs, and record the decisions. A frozen, signed snapshot of the quality system as of the period end: CAPA aging, event trends, training, audit findings, risks, supplier scorecards and document status. Minutes and decisions signed at closure. The snapshot, signed minutes and follow-up actions tracked after closure. Running the review, inputs held outside QMSdesk, and the decisions.
§6.2 Human resources. Set competence, provide training, check it worked, and keep records. Training assigned on document approval, change, CAPA, new hire and role change. Acknowledgment, quizzes, practical assessments and external certificates. Competency assessments by qualified assessors. Completion records, signed for acknowledgments, practical assessments and external certificates. Competence criteria and training content.
§7.1 Planning of product realization. Plan product realization, with documented risk management throughout, and keep risk management records. A risk register built on ISO 14971 and ICH Q9(R1) principles. Implementing a control and verifying it are separate steps, and verification is signed. Signed assessments, verified controls and signed residual risk. Your risk management file for each device.
§7.3 Design and development. Outside QMSdesk's scope. Under the medical device profile, each CAPA records whether it affects the design. The CAPA's design-impact field. Your design and development records.
§7.4 Purchasing. Evaluate, select, monitor and re-evaluate suppliers by risk, and keep records. Risk tiers set qualification gates and 6, 12 or 24-month reviews. Signed status decisions. Certificate alerts at 90, 60 and 30 days. SCARs answered through a single-use link. The Approved Supplier List, signed decisions, scorecards and SCAR records. Purchasing information and verifying purchased product.
§7.5 Production and service provision. Outside QMSdesk's scope, except device identification: nonconformances carry UDI and serial number under the medical device profile. Nonconformance records with device identification. Production, process validation, servicing and traceability records.
§8.2.1 Feedback. Gather and monitor feedback from production and post-production. Anyone can report an event. The medical device profile adds post-market surveillance events. Attributed event records, linked to their follow-up. Your feedback and post-market surveillance procedures.
§8.2.2 Complaint handling. Receive, evaluate, investigate and close complaints on time, with records. Acknowledgment tracked against 3 business days, investigation and root cause, a signed reportability review, a signed CAPA decision, and the customer reply. The complaint record and a closure-record PDF. Which complaints you investigate, and why not when you don't.
§8.2.3 Reporting to regulatory authorities. The reportability review is a signed decision with its reasons. A reportable complaint records the authority and the reporting deadline you set. The signed decision, the authority and the deadline. Setting each deadline under the rule that applies, for example 30 calendar days or 5 work days under 21 CFR 803, or 15, 10 or 2 days under EU MDR Article 87, and filing each report, including corrections and removals under 21 CFR 806.
§8.2.4 Internal audit. Plan and run audits, keep auditors independent, and follow up findings. Audit program, calendar, templates and auditor profiles. Auditors are blocked from auditing their own department, and the lead auditor from approving their own report. Signed audit reports and a register of every finding. Audit scope, and the audits themselves.
§8.3 Control of nonconforming product. Identify, segregate, evaluate and disposition nonconforming product. A signed disposition: reject, rework, use as is, or return. Use as is requires a technical rationale. The nonconformance record and its signed disposition. Physical segregation, and notifying external parties.
§8.4 Analysis of data. Analyze quality data to show the QMS works. Command Center summaries, including CAPA aging, event trends, training, audit findings, risks and supplier scorecards. Figures link to the records behind them. PDF and Excel reports, and the figures behind them. Choosing the methods and drawing conclusions.
§8.5.2 Corrective action. Find the cause, act without undue delay, and review whether the action worked. CAPA as its own record: investigation, signed action-plan review, implementation and signed verification. Effectiveness is checked after closure, and a failed check raises a new linked CAPA. Signed CAPA records, action evidence and effectiveness results. Root-cause methods, and actions proportionate to risk.
§8.5.3 Preventive action. Act on potential problems before they occur. A CAPA can start from a trend, an audit, a management review, or nothing at all. A risk assessed at a level you set as a CAPA trigger raises its CAPA automatically, once. A CAPA linked to the trend or risk that prompted it. Deciding which potential problems need action.

ISO 13485 8.5.2 CAPA, in practice

Corrective action is where auditors spend their time, and where a gap in the chain shows first.

In QMSdesk, a CAPA is its own record. It isn't a stage inside a complaint. A signed CAPA decision on a complaint raises it, in the same transaction as the signature. The approved action plan raises the change control and training the fix needs. After closure, a scheduled check confirms the effect held, over an interval you configure. If a check fails, a new CAPA opens, linked to the first, and the signed record stays as it was.

Under the medical device profile, each CAPA also records whether the risk management file needs updating and whether the design is affected.

Kept current

What changed recently

Read the FDA side in full on our FDA QMSR page.

  1. February 2, 2026

    The FDA QMSR took effect. 21 CFR Part 820 now incorporates ISO 13485:2016, the 2016 edition specifically (§820.7). eCFR, 21 CFR Part 820

  2. February 2, 2026

    FDA's QMSR FAQ confirms it doesn't require or issue ISO 13485 certificates, and a certificate doesn't exempt a manufacturer from FDA inspection. FDA QMSR FAQ

  3. February 2, 2026

    Your ISO 13485 §5.6 and §8.2.4 records are now within reach of an FDA investigator, because the QMSR dropped the QSR's exception for management review and audit reports. FDA QMSR FAQ

Download the checklist

Take the clause-by-clause checklist with you: every row above, with space to note your own procedure and evidence.

PDF and Excel

Regulation checklist

The tables from this page, with a column for your own evidence. No form to fill in.

ISO 13485 FAQ

Does QMSdesk hold an ISO 13485 certificate?

No. Certification applies to your organization's quality system, and a certification body grants it. QMSdesk is designed to support organizations working to ISO 13485:2016, and we'll demonstrate those capabilities on request.

Which ISO 13485 records does QMSdesk keep?

Controlled documents, training, complaints, nonconformances, CAPAs, supplier decisions, internal audits, management reviews and risk assessments. Each one is linked, signed at its decision points, and held in a hash-chained audit trail.

How does QMSdesk support ISO 13485 8.5.2 CAPA?

A CAPA is its own record, with a signed action-plan review, signed verification, and an effectiveness check that can't be skipped. A failed check raises a new linked CAPA.

Does QMSdesk cover design and development under §7.3?

No. Design and development is outside QMSdesk's scope. Under the medical device profile, each CAPA records whether it affects the design, so the link to your design records is visible.

Do we still need to validate QMSdesk under §4.1.6?

Yes. QMSdesk's core platform is validated under a QA-approved Validation Summary Report. We'll walk you through the full record under a mutual NDA. Every engagement includes a written validation scope, and validating QMSdesk for your intended use, and after changes, stays with you. See validation.

How long does QMSdesk keep ISO 13485 records?

Under the medical device profile, for at least 15 years from when each record reaches its final state, and your procedures can set a longer period. Records are archived, never hard-deleted.

Reviewed by a practitioner

Abdul Azam, Founder & CEO, 25 years in regulated life-sciences quality. Last reviewed September 26, 2026. Next review December 2026. This guide is general information, not legal or regulatory advice.

See the records behind these clauses

Bring one ISO 13485 process, such as a complaint, a CAPA or a supplier review. We'll show you QMSdesk running it, record by record.

Bring one workflow. We'll show you QMSdesk running it. You can also download the ISO 13485 clause-by-clause checklist or see CAPA.