ISO 13485 Documentation Requirements (2026)

Every document and record ISO 13485 requires — with clause references, document control requirements under Section 4.2, record retention rules, how QMSR changed the documentation landscape, and the seven gaps auditors find most consistently. Built as a reference document quality managers can use before their next audit.

Every document your QMS must have, what auditors check first, and why the gaps between your procedures and your records are where most findings live.

Last Updated: May 2026


Affiliate Disclosure: Some links in this article are affiliate links. If you purchase through them, The Standards Navigator may earn a commission at no additional cost to you.


📋 Free Download: ISO 13485 Gap Assessment Checklist — 64 items covering ISO 13485 clauses + all four FDA QMSR bridge requirements ISO 13485 certification alone does not cover.


The Binder on the Shelf Is Not a QMS

Years ago, working in a nuclear component facility, I watched a certification audit go sideways in the first thirty minutes. The quality manager had spent six months building what looked like a complete quality management system — binders, procedures, forms, the works. The auditor asked to see the document register. The quality manager pointed to the binder. The auditor asked how documents were controlled at the point of use. The quality manager pointed to the binder again.

The binder was the system. It sat on a shelf in the quality office. The machinists on the floor had printed copies of procedures from three years prior. Nobody had a current revision of anything. The audit did not go well.

ISO 13485 documentation is not about having paperwork. It is about having the right documents, in the right format, accessible to the right people, at the right time — and being able to prove all of that during an audit. The standard is specific about what must be documented, what must be retained as records, and what that documentation must demonstrate.

Under QMSR, which took effect February 2, 2026, FDA now evaluates ISO 13485 documentation requirements against the framework directly. Organizations that treat documentation as a filing exercise rather than a quality system function are finding that gap at inspection.

This article covers every documentation requirement ISO 13485 imposes, where auditors look first, and what a compliant documentation system actually looks like in practice.


In This Guide

  • The difference between documents and records under ISO 13485 — and why it matters for audits
  • Every mandatory document the standard requires
  • Every mandatory record the standard requires
  • Document control requirements under Section 4.2
  • Record retention rules under Section 4.2.5
  • The most common documentation gaps auditors find
  • How QMSR changed the documentation landscape for U.S. medical device manufacturers
  • Decision-stage guidance for organizations at different points in their documentation journey


Start Here (Top Resources)

🔖 Get ISO 13485:2016 → ANSI Webstore — ANSI is the official U.S. distributor of ISO standards, ensuring you receive the controlled, compliant version required for certification audits. Use coupon CC2026 for 5% off.

🔖 Build compliant QMS documentation → 9001Simplified — 9001Simplified provides ready-to-use documentation kits that dramatically reduce the internal labor required to build a compliant QMS from scratch.

🔖 Train your team on ISO 13485 documentation requirements → BSI Group — BSI Group is a founding member of ISO and one of the world’s largest providers of ISO training courses, recognized by certification bodies globally.

🔖 Pursue or maintain ISO 13485 certification → ISOQAR — ISOQAR is a UKAS-accredited certification body — one of the most recognized in the industry for ISO management system certification.

Browse the What Is ISO 13485? pillar article for full clause context, or use the ISO 13485 Gap Assessment Checklist to identify your specific documentation gaps before your next audit.


Documents vs. Records: The Distinction That Drives Compliance

ISO 13485 treats documents and records as separate categories with different requirements. Confusing them is one of the most consistent sources of documentation findings in surveillance audits.

Documents are instructions, procedures, specifications, and plans — the things that tell people what to do. They are living documents: they can be revised, updated, and superseded. Section 4.2.4 governs their control.

Records are evidence that something was done — completed forms, test results, inspection reports, calibration data, training sign-offs. They are fixed in time: once a record is created, it cannot be altered without creating a documented amendment. Section 4.2.5 governs their control.

The practical distinction matters for two reasons. First, the control requirements differ. Documents need revision control, approval, distribution, and obsolescence management. Records need legibility, identification, storage protection, retrieval, and defined retention periods. A documentation system that applies the same controls to both will have gaps in one or the other.

Second, auditors evaluate them separately. When an auditor asks for a procedure, they are asking for a document. When they ask for evidence, they are asking for a record. Handing an auditor a completed form when they asked for a procedure — or a procedure when they asked for evidence — signals a documentation system that does not understand its own structure.

At this point, most quality managers building or auditing a documentation system should: → Map your document inventory against your record inventory separately. If your document register includes completed forms alongside controlled procedures, your system architecture has a structural problem. 9001Simplified’s documentation kits include pre-structured document and record registers built for ISO 13485 compliance. 9001Simplified provides ready-to-use documentation kits that dramatically reduce the internal labor required to build a compliant QMS from scratch.


Mandatory Documents Under ISO 13485

ISO 13485 requires specific documented procedures and plans across multiple clauses. These are not optional — certification bodies audit for their existence and their content.

ISO 13485 documentation infographic illustrating mandatory quality management system documents with interconnected process icons for quality manuals, risk management, design planning, procedures, records retention, purchasing controls, and document control requirements.
Certification bodies expect documented procedures, controlled records, and defined plans that demonstrate the quality system operates consistently and remains audit ready — see the full list in the table below.
DocumentClauseWhat It Must Cover
Quality Manual4.2.2Scope of the QMS, exclusions with justification, documented procedures or references, description of QMS process interactions
Document Control Procedure4.2.4Approval, review, revision control, distribution, obsolescence management, external documents
Records Control Procedure4.2.5Identification, storage, protection, retrieval, retention periods, disposition
Management Review Procedure5.6Inputs, outputs, frequency, documentation requirements
Competence, Training & Awareness Procedure6.2How competence is determined, how training is delivered, how competence is evaluated and recorded
Infrastructure Procedure6.3Maintenance of buildings, equipment, and supporting services affecting product quality
Work Environment Procedure6.4Control of work environment conditions where required for product conformity
Risk Management Procedure7.1Risk management process across the product lifecycle, per ISO 14971
Customer-Related Processes Procedure7.2Requirements determination, review, and customer communication
Design & Development Procedure7.3Planning, inputs, outputs, review, verification, validation, transfer, changes (if design is not excluded)
Purchasing Procedure7.4Supplier evaluation, selection, monitoring, and purchasing information
Production & Service Controls Procedure7.5Control of production and service provision, cleanliness, installation, and servicing
Identification & Traceability Procedure7.5.3Product identification throughout realization and traceability requirements
Customer Property Procedure7.5.4Control and safeguarding of customer-supplied product or data
Preservation Procedure7.5.5Preservation of product during processing and delivery
Monitoring & Measurement Equipment Procedure7.6Calibration, verification, and control of measuring equipment
Feedback Procedure8.2.1Post-market surveillance and feedback collection
Complaint Handling Procedure8.2.2Complaint receipt, investigation, and regulatory reporting decisions
Internal Audit Procedure8.2.4Audit planning, conduct, reporting, and follow-up
Nonconforming Product Procedure8.3Identification, segregation, evaluation, and disposition
CAPA Procedure8.5.2 / 8.5.3Corrective and preventive action process, including root cause analysis and effectiveness verification

⚠️ If your organization excludes design and development under Clause 7.3, that exclusion must be justified in the Quality Manual and documented. Exclusions without documented justification are a consistent finding in initial certification audits.


📋 Free Download: ISO 13485 Gap Assessment Checklist — 64 items covering ISO 13485 clauses + all four FDA QMSR bridge requirements ISO 13485 certification alone does not cover.


Mandatory Records Under ISO 13485

Records are the evidence your QMS operated as documented. The standard specifies which records must be maintained — these are the minimum. Your procedures may require additional records.

RecordClauseWhat It Must Demonstrate
Management Review Minutes5.6.3Inputs reviewed, decisions made, actions assigned with owners and timelines
Education, Training, Skills & Experience6.2Competence evaluated, training completed, results recorded
Infrastructure Maintenance6.3Maintenance activities and results for quality-critical equipment
Risk Management Records7.1Risk analysis, risk evaluation, risk control, residual risk assessment, post-production monitoring
Customer Requirements Review7.2.2Requirements determined and confirmed before commitment
Design & Development Records7.3Inputs, outputs, reviews, verifications, validations, transfer, and changes (if not excluded)
Design & Development Changes7.3.9Change description, evaluation, verification, validation, approval
Supplier Evaluation Records7.4.1Evaluation criteria, results, and re-evaluation decisions
Production Process Validation7.5.2Validation protocols, results, equipment qualifications
Traceability Records7.5.3.2Unique device identification and traceability through production
Customer Property Records7.5.4Receipt, condition assessment, and disposition of customer property
Calibration Records7.6Equipment identification, calibration standard, results, next due date
Internal Audit Records8.2.4Audit plans, findings, nonconformances, corrective actions, follow-up
Product Monitoring & Measurement8.2.6Evidence of conformity and identification of release authority
Nonconforming Product Records8.3Nature of nonconformity, disposition decision, concession records if applicable
CAPA Records8.5.2 / 8.5.3Root cause analysis, action taken, effectiveness verification with criteria and evidence

➡️ 9001Simplified Documentation Kits — Pre-built ISO 13485 procedures, forms, and record templates covering every mandatory document and record listed above. 9001Simplified provides ready-to-use documentation kits that dramatically reduce the internal labor required to build a compliant QMS from scratch.


Document Control: What Section 4.2.4 Actually Requires

Section 4.2.4 sets out seven specific requirements for document control. Each one has a practical implementation implication — and each one is evaluated individually during audits.

1. Documents must be approved before use. Approval must be by authorized personnel. Your document control procedure must define who has approval authority for each document type. A document approved by someone outside that authority — or with no documented approval at all — is a nonconformance.

2. Documents must be reviewed, updated as necessary, and re-approved. Review frequency should be defined in your procedure. Documents that have never been reviewed since initial creation are a finding in surveillance audits — particularly if the regulatory environment or production process has changed.

3. Changes and current revision status must be identified. Every controlled document needs a revision identifier — a number, letter, or date — and your document register needs to reflect current revision status. Auditors check this against what is in use.

4. Relevant versions must be available at points of use. This is the binder-on-the-shelf failure. Current controlled versions must be accessible where work is performed. If people work from printed copies, you need a controlled printing process. If work is performed on a production floor, current procedures must be accessible there — not only in the quality office.

5. Documents must be legible and identifiable. This sounds obvious. It is consistently violated by organizations that allow handwritten annotations, informal updates, or degraded printed copies to remain in service.

6. External documents must be identified and controlled. This includes customer drawings, regulatory guidance documents, referenced standards, and supplier specifications. External documents that affect product quality must be listed in your document control system and their current version verified.

7. Obsolete documents must be prevented from unintended use. Obsolete documents must either be removed from all points of use or clearly marked as obsolete. Finding an active workstation with a superseded procedure is a major nonconformance — regardless of whether anyone was actually using it.

If you are under active FDA inspection pressure → BSI Group ISO 13485 Training covers document control implementation and audit preparation in depth. BSI Group is a founding member of ISO and one of the world’s largest providers of ISO training courses, recognized by certification bodies globally.


Record Retention: What Section 4.2.5 Actually Requires

Section 4.2.5 requires that records be retained for a period at least equal to the lifetime of the medical device, but not less than two years from the date of product release by the organization.

That two-year floor is the minimum. In practice, most medical device records should be retained significantly longer:

  • Implantable devices — the device lifetime may span decades. Records need to match.
  • Devices with long service lives — the same logic applies.
  • FDA QMSR requirements — align with ISO 13485 on the two-year minimum but your complaint handling procedure may require longer retention for MDR-related records.
  • Customer contractual requirements — OEM customers increasingly specify record retention periods in their supplier quality agreements. These requirements take precedence where they are more stringent than the standard’s minimum.

Your records control procedure must define retention periods for each record type. A blanket “two years” policy applied to all records — including design history files and risk management records for long-life devices — is not compliant.

ProviderWhat You GetBest For
ANSI WebstoreISO 13485:2016 official standardAny organization needing the controlled, compliant version of the standard
9001SimplifiedQMS documentation kits with record templatesOrganizations building documentation from scratch or rebuilding after a major finding
BSI GroupISO 13485 training coursesTeams implementing documentation systems or preparing for initial certification
ISOQARISO 13485 certificationOrganizations ready to pursue or maintain certification

Most organizations building documentation systems from scratch need all three:

This combination covers the standard, the knowledge, and the implementation infrastructure.


The Most Common Documentation Gaps

ISO 13485 documentation gaps infographic illustrating seven common audit findings, including outdated document registers, incomplete supplier records, weak CAPA evidence, missing procedures, and disconnected risk management records within medical device quality systems.
Documentation failures rarely appear as isolated findings. They create chains of audit problems across CAPA, supplier controls, training, management review, and risk management. The gap is usually discovered long after it was created.

These are the findings that appear most consistently in ISO 13485 surveillance audits and QMSR inspections. Each one points to a specific procedure or record requirement.

The Quality Manual references procedures that don’t exist. A common initial certification shortcut is writing a Quality Manual that references a full set of documented procedures — then discovering during the surveillance audit that several of those procedures were never finalized. The Quality Manual and the document register must be synchronized.

The document register is not current. Document registers that haven’t been updated in months, that show revision numbers inconsistent with what is in use, or that are missing entire document categories are a consistent finding. The register is the first thing many auditors check.

Risk management records stop at design transfer. ISO 14971 requires risk management across the product lifecycle. Design-phase risk files with no post-production updates — no connection to complaint data, service reports, or CAPA findings — are incomplete regardless of how thorough the original analysis was. See ISO 14971 vs ISO 13485 for the full lifecycle requirement.

CAPA records close without effectiveness verification evidence. A CAPA record that reads “action implemented — problem resolved” with no supporting data is not a closed CAPA — it is an open finding waiting to be issued. For the complete breakdown of what effectiveness verification requires, see CAPA Requirements in ISO 13485.

Supplier qualification records are incomplete or outdated. An approved supplier list without corresponding qualification evidence, or qualification records for suppliers whose scope has changed without requalification, are consistently cited findings under Clause 7.4.

Training records prove attendance, not competence. Sign-off sheets showing who attended a training session are not competence records. The record must show what competence was evaluated, by what method, and what the result was. See Common Mistakes in ISO 13485 QMS for the full breakdown of this finding.

Management review minutes record presentations, not decisions. Minutes that describe what was presented in management review without documenting what was decided are a major finding under Section 5.6.3. Every input reviewed must produce a documented output — a decision, an action, or a rationale for no action.


How QMSR Changed the Documentation Landscape

FDA’s Quality Management System Regulation, effective February 2, 2026, aligns U.S. medical device QMS requirements with ISO 13485:2016. For documentation, the practical changes are significant.

The Device Master Record (DMR) structure is now explicitly required. Under QMSR, the DMR — which must include device specifications, production process specifications, quality assurance procedures, packaging and labeling specifications, and installation and maintenance procedures — is a specific documentation requirement that ISO 13485 certification alone does not fully address.

Complaint files under 21 CFR 820.198 remain a separate requirement. ISO 13485 requires a complaint handling procedure. QMSR additionally requires that complaint files contain specific elements — including the decision on whether the complaint required investigation and, if so, the results of that investigation — that go beyond what most ISO 13485 complaint procedures specify.

MDR procedures must be documented separately. Medical Device Reporting obligations are a regulatory requirement that sits outside ISO 13485 but must be addressed in your QMS documentation under QMSR.

⚠️ FDA QMSR compliance date was February 2, 2026. If your documentation system has not been reviewed against the four QMSR-specific bridge requirements since that date, that review is overdue. The ISO 13485 Gap Assessment Checklist covers all four QMSR bridge requirements explicitly alongside the standard ISO 13485 clause requirements.

For the full regulatory alignment picture, see FDA QSR vs ISO 13485.

Infographic explaining the major operational and regulatory changes introduced under the FDA QMSR, including terminology alignment, expanded risk management, inspection changes, and ISO 13485 document control requirements.
The FDA’s QMSR transition introduced major changes beyond terminology — expanding risk management expectations, changing inspection structure, and aligning medical device quality systems directly with ISO 13485.

Why Organizations Delay Getting Documentation Right

“We’ll clean it up before the surveillance audit.”

This is the most common delay rationalization — and it consistently produces the worst outcomes. Documentation gaps that accumulate over 11 months cannot be credibly remediated in the 30 days before a surveillance visit. Auditors can identify recently created records. A CAPA file dated three weeks before the audit for a problem that complaint data shows has existed for eight months is not evidence of a functioning QMS — it is evidence of audit preparation, which auditors treat as a different category of finding.

“Our documentation was good enough for initial certification.”

Initial certification evaluates documentation at a point in time against a system that was built to be audited. Surveillance audits evaluate whether that system has been maintained — which means they look at records created since the last audit, not at procedures written before it. Organizations that passed initial certification and then stopped maintaining their documentation systems often face multiple major nonconformances at the first surveillance visit.

“We don’t have the internal resources to build this properly.”

This objection is real — but the cost of building documentation properly before certification is substantially lower than the cost of remediation after a major nonconformance. A documentation kit from 9001Simplified covers every mandatory document and record template in a ready-to-use format. 9001Simplified provides ready-to-use documentation kits that dramatically reduce the internal labor required to build a compliant QMS from scratch. The internal labor required to customize a pre-built kit is a fraction of what is required to build from scratch — and a fraction of what remediation costs after a finding.


Frequently Asked Questions

What documents are required by ISO 13485?

ISO 13485 requires documented procedures covering quality manual, document control, records control, management review, training and competence, risk management, customer requirements, purchasing, production controls, identification and traceability, calibration, feedback, complaint handling, internal audit, nonconforming product, and CAPA. The full list with clause references is in the Mandatory Documents table above.

What records are required by ISO 13485?

ISO 13485 requires records covering management reviews, training and competence evaluations, risk management activities, design and development (if not excluded), supplier evaluations, calibration, internal audits, product monitoring, nonconforming product dispositions, and CAPA activities. The full list with clause references is in the Mandatory Records table above.

How long must ISO 13485 records be retained?

The standard requires retention for at least the lifetime of the device, with a minimum of two years from product release. For implantable devices and devices with long service lives, the retention period is typically longer and should be defined in your records control procedure. FDA QMSR aligns with this minimum but specific record types — particularly MDR-related records — may require longer retention.

Does ISO 13485 require a Quality Manual?

Yes. Section 4.2.2 requires a Quality Manual that defines the scope of the QMS, documents or references procedures, and describes the interactions between QMS processes. The Quality Manual is one of the first documents an auditor requests.

Can we use electronic records to meet ISO 13485 requirements?

Yes — electronic records are acceptable provided your document control system ensures they are controlled, legible, retrievable, and protected from unauthorized modification. Electronic systems used to manage controlled documents must themselves be validated if they affect product quality.

What is the difference between a controlled document and a record under ISO 13485?

A controlled document is an instruction, procedure, or specification that tells people what to do — it can be revised and must be version-controlled. A record is evidence that something was done — it is fixed in time and must be retained according to your records control procedure. Section 4.2.4 governs controlled documents; Section 4.2.5 governs records. The distinction is fundamental to building a compliant documentation system.

Does design and development documentation apply to all medical device manufacturers?

Only if the manufacturer performs design and development activities. If your organization manufactures to customer specifications and does not perform design activities, you may be eligible to exclude Clause 7.3 — but that exclusion must be documented and justified in your Quality Manual. Contract manufacturers who claim a 7.3 exclusion without justification are consistently cited at initial certification.

How do FDA QMSR documentation requirements differ from ISO 13485?

QMSR aligns with ISO 13485 but adds four specific requirements: the Device Master Record structure, complaint files under 21 CFR 820.198, Medical Device Reporting procedures, and corrections and removals procedures. ISO 13485 certification alone does not cover these four requirements. The ISO 13485 Gap Assessment Checklist addresses all four explicitly.

What is the first thing an auditor looks at for ISO 13485 documentation?

Most auditors start with the document register — to verify that controlled documents are listed, revision levels are current, and the register reflects what is actually in use. From there they move to the Quality Manual to verify scope and procedure references. Gaps in either of those two items typically expand the audit’s scope significantly.


Free Resources

📋 Free Download: Manufacturing Compliance Checklist — ISO 9001, 14001, 45001 & OSHA — 50 items with gap scoring across all systems.

📋 Free Download: Supplier Quality Checklist — ISO 9001 Clause 8.4 — all supplier controls auditors evaluate, 45 items with scoring.

📋 Free Download: ISO 9001 Implementation Roadmap — The exact 5-phase process from gap assessment to Stage 2 audit clearance.

📋 Free Download: ISO 13485 Gap Assessment Checklist — 64 items — ISO 13485 clauses + all four FDA QMSR bridge requirements ISO 13485 certification alone does not cover.


Not Sure What to Do Next?

→ You need the official ISO 13485:2016 standard → ANSI Webstore — Use CC2026 for 5% off. ANSI is the official U.S. distributor of ISO standards.

→ You need to build ISO 13485 documentation from scratch → 9001Simplified Documentation Kits — ready-to-use procedures, forms, and record templates for every mandatory document.

→ You need to train your team on documentation requirements → BSI Group ISO 13485 Training — BSI Group is a founding member of ISO and one of the world’s largest providers of ISO training courses.

→ You are ready to pursue ISO 13485 certification → ISOQAR — UKAS-accredited, one of the most recognized certification bodies in the industry.

→ You need to assess your documentation gaps before your next audit → ISO 13485 Gap Assessment Checklist — free, 64 items.

→ You need to understand how QMSR changed your documentation obligations → FDA QSR vs ISO 13485

→ You need to understand CAPA record requirements in depth → CAPA Requirements in ISO 13485

→ You need to understand the most common documentation audit findings → Common Mistakes in ISO 13485 QMS

→ You need to understand how risk management documentation connects to your QMS → ISO 14971 vs ISO 13485

→ You need to understand the full ISO 13485 clause structure → What Is ISO 13485?

→ You want to buy ISO 13485 → Buy ISO 13485

→ You want to browse all medical device standards → explore standards by compliance area


Still figuring out where to start?

If you are not ready to commit to a documentation build yet — that is normal. Most organizations spend several weeks between identifying gaps and starting remediation.

The best next step: → Download the free ISO 13485 Gap Assessment Checklist — it takes 20 minutes and tells you exactly which documents and records you are missing before you spend anything.

Feature image promoting an ISO 13485 Gap Assessment Checklist for medical device manufacturers, contract manufacturers, and component suppliers preparing for certification and FDA QMSR compliance.
ISO 13485 Gap Assessment Checklist designed to help medical device manufacturers identify compliance gaps, prioritize actions, and prepare for certification and FDA QMSR requirements.

📋 Free Download: ISO 13485 Gap Assessment Checklist — 64 items — ISO 13485 clauses + all four FDA QMSR bridge requirements ISO 13485 certification alone does not cover.


The Binder Is Not the System

Documentation is not ISO 13485’s most technically demanding requirement. But it is the foundation every other requirement rests on. Without controlled documents, procedures cannot be consistently followed. Without records, there is no evidence that procedures were followed at all. Without a document control system that connects what is written to what people actually use, the gap between those two things grows quietly — until an auditor measures it.

The organizations that handle documentation audits well are not the ones with the most sophisticated quality management software or the thickest procedure binders. They are the ones whose documentation reflects how work actually gets done — current, accessible, and connected to the records that prove it.

That alignment takes discipline to build and discipline to maintain. It does not take complexity.

At The Standards Navigator, complex standards are translated into practical, real-world guidance you can act on.

Subscribe below to stay ahead.

Subscribe

* indicates required

Common Mistakes in ISO 13485 QMS (2026)

Seven ISO 13485 QMS mistakes that consistently produce major nonconformances — document control drift, management review gaps, supplier qualification failures, CAPA records closed without verification, risk management treated as a one-time activity, competence records that prove attendance not ability, and internal audits that never find anything. With clause references and fixes for each.

The audit findings that derail medical device manufacturers — and the fixes that prevent them.

Last Updated: May 2026


Affiliate Disclosure: Some links in this article are affiliate links. If you purchase through them, The Standards Navigator may earn a commission at no additional cost to you.


📋 Free Download: ISO 13485 Gap Assessment Checklist — 64 items covering ISO 13485 clauses + all four FDA QMSR bridge requirements ISO 13485 certification alone does not cover.


Your QMS Passed Initial Certification. Now the Surveillance Audit Found Three Major Nonconformances.

This scenario plays out more often than most quality managers expect.

Initial certification audits are thorough — but they happen at a fixed point in time, against a QMS that was built specifically to pass them. Surveillance audits arrive 12 months later and evaluate how the system actually operates day to day. That gap between what was built and what runs is where most findings live.

The mistakes in this article are not obscure edge cases. They are the findings that certification bodies issue most consistently, that FDA investigators flag most frequently under QMSR, and that experienced quality practitioners see repeated across organizations of every size. Some of them look like documentation failures. Most of them are process failures wearing documentation’s clothes.

If you are preparing for a first certification audit, a surveillance visit, or an FDA QMSR inspection, this list tells you where to look before the auditor does.


In This Guide

  • The most common mistakes in ISO 13485 QMS by clause
  • Why document control failures are almost never about documents
  • The management review gap that catches organizations by surprise
  • How supplier qualification problems compound over time
  • What auditors find when they look at CAPA records
  • The risk management connection most QMS procedures miss
  • Decision-stage guidance for organizations at different points in their compliance journey


Start Here (Top Resources)

🔖 Get ISO 13485:2016 → ANSI Webstore — ANSI is the official U.S. distributor of ISO standards, ensuring you receive the controlled, compliant version required for certification audits. Use coupon CC2026 for 5% off.

🔖 Build compliant QMS documentation → 9001Simplified — 9001Simplified provides ready-to-use documentation kits that dramatically reduce the internal labor required to build a compliant QMS from scratch.

🔖 Train your team on ISO 13485 → BSI Group — BSI Group is a founding member of ISO and one of the world’s largest providers of ISO training courses, recognized by certification bodies globally.

🔖 Pursue or maintain ISO 13485 certification → ISOQAR — ISOQAR is a UKAS-accredited certification body — one of the most recognized in the industry for ISO management system certification.

Browse the What Is ISO 13485? pillar article for full clause context, or use the ISO 13485 Gap Assessment Checklist to identify your specific gaps before your next audit.


Mistake 1: Document Control That Controls Nothing

The clause: ISO 13485 Section 4.2 — Document Control

What auditors find: Obsolete procedures still accessible in shared drives. Forms in use that don’t match the current controlled version. Employees working from printed copies with no revision date. Documents approved by someone whose role no longer includes that authority.

Document control failures are the most consistently cited finding in ISO 13485 surveillance audits — not because organizations don’t have document control procedures, but because those procedures don’t match how people actually access and use documents day to day.

The standard requires that documents be reviewed and approved before use, that current versions are available at points of use, and that obsolete documents are prevented from unintended use. Each of those three requirements has failed in organizations that had a document control procedure on file.

The fix: Document control is an access problem, not a paperwork problem. The question is not “do we have a procedure?” — it’s “can an employee working right now reach a document that has been superseded?” If the answer is yes, your document control system is not functioning regardless of what your procedure says.

Audit your access architecture — shared drives, QMS software, printed SOPs at workstations — before an auditor does. Every document a user can reach should be the current controlled version. Everything else should require deliberate action to retrieve.

At this point, most quality managers in this position should: → Pull your document control procedure and map it against actual employee access. If those two things don’t match, 9001Simplified’s documentation kits include document control templates built specifically for ISO 13485 compliance. 9001Simplified provides ready-to-use documentation kits that dramatically reduce the internal labor required to build a compliant QMS from scratch.


Mistake 2: Management Review Without Documented Outputs

The clause: ISO 13485 Section 5.6 — Management Review

What auditors find: Meeting minutes that record attendance and agenda items but contain no documented decisions. Review inputs listed without evidence they were actually analyzed. Action items described without owners, deadlines, or follow-up records. Reviews conducted annually when the organization’s risk profile warranted more frequent review.

ISO 13485 Section 5.6.3 is explicit: management review outputs must include decisions and actions related to improvement of the QMS, improvement of product to meet customer requirements, and resource needs. A management review that happened but produced no documented decisions is a nonconformance — regardless of what was discussed in the room.

This finding catches organizations off guard because the review itself felt thorough. Leadership reviewed quality objectives, discussed complaint trends, walked through audit results. But the meeting minutes read like a summary of what was presented, not a record of what was decided.

The fix: Management review outputs need to look like decisions, not summaries. For each input reviewed, the record should show: what the data indicated, what conclusion was reached, and what — if anything — will be done about it. “Complaint trend reviewed — no action required” is a decision. “Complaint data presented” is not.

⚠️ Under QMSR, FDA inspectors now evaluate management review as part of every inspection. Inspectors who find management reviews without documented outputs routinely cite this as a systemic QMS failure, not an administrative lapse.


Mistake 3: Supplier Qualification on Paper Only

ISO 13485 supplier qualification infographic illustrating risk-based supplier controls under Clause 7.4, featuring a supplier risk tier matrix, qualification lifecycle process, ongoing monitoring activities, and common supplier management mistakes.
Supplier qualification under ISO 13485 is not a one-time approval exercise. Risk classification, qualification activities, performance monitoring, and periodic re-evaluation must work as a continuous lifecycle.

The clause: ISO 13485 Section 7.4 — Purchasing / Supplier Controls

What auditors find: An approved supplier list that has not been updated in years. Suppliers qualified based on a questionnaire with no follow-up evaluation. Critical suppliers with no documented performance monitoring. Qualification records for suppliers whose scope of supply has expanded beyond what was originally evaluated.

Supplier qualification failures compound over time in a way that most other QMS failures don’t. A supplier that was qualified five years ago may have changed ownership, changed manufacturing processes, changed subcontractors, or expanded into new product categories — none of which triggered a requalification because the procedure didn’t require one.

ISO 13485 requires that purchasing controls be proportionate to the risk the supplier presents to product quality and patient safety. That proportionality has to be reflected in your qualification criteria, your monitoring frequency, and your records. An approved supplier list populated with names and no evaluation data is not a supplier qualification program.

The fix: Supplier qualification is a living process, not a one-time gate. Your procedure should define evaluation criteria by supplier risk tier, monitoring frequency, requalification triggers, and what happens when a supplier fails to meet performance criteria. If you are using the Supplier Quality Checklist, the ISO 13485 Clause 7.4 section identifies every supplier control element auditors evaluate — including the ones most procedures leave undocumented.


📋 Free Download: ISO 13485 Gap Assessment Checklist — 64 items covering ISO 13485 clauses + all four FDA QMSR bridge requirements ISO 13485 certification alone does not cover.


Mistake 4: CAPA Records That Close Without Verification

ISO 13485 CAPA infographic comparing incorrect and correct closure methods, showing the difference between closing corrective actions without effectiveness verification and closing them with documented objective evidence under Clause 8.5.2.
CAPA is not complete when action is implemented. Under ISO 13485 Clause 8.5.2, closure requires effectiveness verification supported by defined criteria, monitoring, objective evidence, and documented results.

The clause: ISO 13485 Section 8.5.2 — Corrective Action

What auditors find: CAPAs closed at implementation with no effectiveness check. Effectiveness verifications that consist of a single sentence — “action implemented, problem resolved” — with no supporting data. Criteria for effectiveness that were defined after the action was taken rather than before. The same problem recurring in a subsequent audit cycle.

Closing a CAPA without effectiveness verification is one of the most consistently cited major nonconformances in ISO 13485 audits. The standard requires that corrective actions be reviewed for effectiveness — and that review must be documented, must use defined criteria, and must be supported by evidence.

The pattern most organizations fall into is treating CAPA closure as an administrative step rather than a quality decision. Someone implements the action, marks the record complete, and moves on. The question “did this actually work?” never gets formally answered.

The fix: Effectiveness verification criteria must be established before the corrective action is implemented — not after. The criteria should be specific enough that a different person reviewing the record could objectively determine whether they were met. “No recurrence for 90 days” is a criterion. “Situation improved” is not.

For a complete breakdown of CAPA requirements under ISO 13485 Clause 8.5.2 — including the InfuTronix case study and the six mandatory data inputs under Section 8.4 — see CAPA Requirements in ISO 13485.


➡️ BSI Group ISO 13485 Training — Covers CAPA, supplier controls, management review, and all major ISO 13485 clauses. BSI Group is a founding member of ISO and one of the world’s largest providers of ISO training courses, recognized by certification bodies globally.


Mistake 5: Risk Management Treated as a One-Time Activity

The clause: ISO 13485 Section 7.1 / ISO 14971

What auditors find: Risk files created during design and never updated. Post-market surveillance data that has no documented connection to risk management. Field failures that triggered a CAPA but never prompted a review of the corresponding risk file. Risk management plans that reference ISO 14971 but contain no evidence of post-production monitoring.

Risk management documentation under Clause 7.1 is now the top QMSR inspection finding — 25 citations in the first three months of QMSR inspection data, ahead of CAPA. That displacement reflects a systematic failure in how most organizations treat risk: as a design-phase activity rather than a lifecycle responsibility.

ISO 14971 is explicit that risk management extends across the entire product lifecycle. Post-market surveillance data, complaint trends, service reports, and CAPA findings are all risk management inputs. When those data sources exist in separate systems with no documented connection to the risk file, the risk management process is incomplete — regardless of how thorough the original risk analysis was.

The fix: Your risk management procedure should define how post-production information feeds back into risk files. When a complaint trend reaches a defined threshold, when a CAPA is opened for a field failure, when a service report pattern emerges — each of those events should trigger a documented review of the relevant risk analysis. That review should produce a documented decision: residual risk is still acceptable, or risk control measures need updating.

For the full picture of how ISO 14971 and ISO 13485 interact at the clause level, see ISO 14971 vs ISO 13485.


Mistake 6: Training Records That Prove Attendance, Not Competence

The clause: ISO 13485 Section 6.2 — Human Resources / Competence

What auditors find: Training records that show who attended a session and when, with no evidence of what was covered or whether it was understood. Competence assessments that consist of a supervisor signature with no evaluation criteria. Personnel performing quality-critical tasks without documented evidence that they are qualified to do so. New employees signed off on procedures they completed training on — but with no record of how competence was evaluated.

ISO 13485 Section 6.2 requires that personnel performing work affecting product quality are competent — and that competence is evaluated and the results are recorded. Attendance is not competence. Completing a training module is not competence. Competence is the demonstrated ability to apply knowledge and skills to produce the required outcome.

This distinction becomes a major finding when an auditor pulls the training record for someone who made a quality-critical decision and finds a sign-off sheet.

The fix: Competence evaluation needs defined criteria for each quality-critical role — what knowledge and skill is required, and how it will be evaluated. That evaluation can be a practical demonstration, a written assessment, a supervised work period with documented sign-off, or another method appropriate to the task. The key is that the record shows what was evaluated and what the result was — not just that training occurred.

If you are building competence frameworks from scratch, BSI Group’s ISO 13485 training courses include role-based competency models that align with Section 6.2 requirements. BSI Group is a founding member of ISO and one of the world’s largest providers of ISO training courses, recognized by certification bodies globally.


Mistake 7: Internal Audits That Don’t Find Anything

The clause: ISO 13485 Section 8.2.4 — Internal Audit

What auditors find: Internal audit programs that audit the same low-risk processes repeatedly while avoiding the areas where problems actually exist. Audit reports that describe observations as “satisfactory” or “no issues found” across every clause. Internal auditors who have never issued a nonconformance. Audit findings that are consistently minor and never escalate to CAPA.

An internal audit program that finds nothing is either auditing the wrong things or auditing them incorrectly. Certification bodies and FDA investigators specifically look at the output of your internal audit program — not just whether audits were conducted on schedule. If your internal audit findings never trigger a CAPA and never surface anything your surveillance audit finds, that incongruence is a finding in itself.

ISO 13485 requires that the internal audit program take into account the status and importance of the processes to be audited and the results of previous audits. A risk-based audit program will allocate more frequency and depth to high-risk processes — CAPA, supplier controls, complaint handling, design controls — and less to lower-risk administrative processes.

The fix: Evaluate your internal audit program against what your surveillance audits and FDA inspections have actually found. If there is a consistent gap — if surveillance audits find things your internal audits missed — that gap is the finding. Your audit program needs to be harder on the areas that matter most, not easier.

If you need to develop your internal audit capability, ISOQAR offers ISO 13485 internal auditor training and certification support. ISOQAR is a UKAS-accredited certification body — one of the most recognized in the industry for ISO management system certification.

At this point, most quality managers preparing for their next audit should: → Cross-reference your last three internal audit reports against your last surveillance audit finding. If the surveillance audit found something your internal audits missed, that’s the gap to close first. Get the ISO 13485 Gap Assessment Checklist to run a structured review across all clauses.


Common Misconceptions About ISO 13485 QMS

ISO 13485 infographic illustrating common misconceptions about quality management systems, comparing myths versus reality around certification, QMSR alignment, and major nonconformances in medical device quality systems.
Some of the most expensive ISO 13485 mistakes begin as assumptions. Certification is not a finish line, ISO 13485 and QMSR are not identical, and a major nonconformance does not automatically mean certification loss.

“Passing initial certification means the QMS is compliant.”

Initial certification confirms that a QMS met the standard’s requirements at a specific point in time, as evaluated against a specific set of records. Surveillance audits evaluate whether the system continues to operate as documented. Organizations that build a QMS to pass initial certification and then don’t maintain it operationally consistently accumulate findings by the first surveillance audit. Certification is not a destination — it is a recurring obligation.

“ISO 13485 and FDA QMSR requirements are now the same thing.”

QMSR, which took effect February 2, 2026, aligns FDA’s device QMS requirements with ISO 13485 — but does not make them identical. Four FDA-specific requirements exist in QMSR that ISO 13485 certification alone does not cover: complaint files under 21 CFR 820.198, MDR procedures, corrections and removals, and the device master record structure. An organization that is ISO 13485 certified is not automatically QMSR compliant. The ISO 13485 Gap Assessment Checklist covers all four QMSR bridge requirements explicitly.

“A major nonconformance means we will lose certification.”

A major nonconformance means the certification body has identified a significant gap in the QMS — one that has the potential to affect product quality or patient safety. It does not automatically result in suspension or withdrawal of certification. It triggers a corrective action requirement with a defined response timeline. Organizations that respond with a documented root cause analysis and credible corrective action plan typically resolve major nonconformances without losing certification. The risk is not the finding — it is the failure to respond adequately.


Frequently Asked Questions

What is the most common ISO 13485 audit finding?

Document control failures under Section 4.2 are consistently the most common finding in surveillance audits. CAPA effectiveness verification failures and management review output gaps follow closely. Under QMSR inspections, risk management documentation under Clause 7.1 is now the leading finding.

How many nonconformances are typical in an ISO 13485 surveillance audit?

There is no typical number. A mature QMS with active internal audit and CAPA programs may receive zero nonconformances. A QMS that has been maintained administratively rather than operationally may receive multiple majors. What matters is whether findings from one audit cycle are genuinely closed before the next one.

What is the difference between a major and minor nonconformance in ISO 13485?

A major nonconformance indicates a systematic failure that has the potential to affect product quality or patient safety — or the complete absence of a required process. A minor nonconformance indicates an isolated lapse or a process weakness that does not constitute a systematic failure. Major nonconformances require a documented corrective action plan with a defined response timeline. Minor nonconformances are typically addressed at the next surveillance audit.

Can we self-declare ISO 13485 compliance without certification?

Self-declaration against ISO 13485 is not recognized in the medical device industry in the way it is sometimes used in other sectors. Customers, regulatory bodies, and OEMs expect third-party certification from an accredited body. Self-declaration provides no audit trail and no independent verification of compliance. If you are building toward certification, ISOQAR is a UKAS-accredited certification body — one of the most recognized in the industry for ISO management system certification.

How long does it take to fix a major nonconformance?

Certification bodies typically allow 30 to 90 days to respond to a major nonconformance with a documented corrective action plan, evidence of root cause analysis, and initial implementation evidence. Full closure — including effectiveness verification — may take longer depending on the nature of the finding. The timeline should be proposed by the organization and accepted by the certification body.

What is the best way to prepare for an ISO 13485 surveillance audit?

Run a structured internal audit against the clauses most likely to surface findings — Section 4.2 (document control), Section 5.6 (management review), Section 7.4 (supplier controls), Section 8.2.4 (internal audit), and Section 8.5.2 (CAPA). Pull a sample of CAPA records and verify that effectiveness verifications are complete. Review your management review minutes for documented outputs. Check that your approved supplier list reflects current qualification status. The ISO 13485 Gap Assessment Checklist covers all of this in 64 structured items.

Do these mistakes also apply under FDA QMSR?

Yes — and in some cases the stakes are higher. QMSR inspections evaluate every subsystem, every inspection. Document control failures, CAPA gaps, and management review deficiencies that might result in a minor nonconformance from a certification body can result in a 483 observation or warning letter from FDA. See FDA QSR vs ISO 13485 for the full regulatory alignment picture.


Free Resources

📋 Free Download: Manufacturing Compliance Checklist — ISO 9001, 14001, 45001 & OSHA — 50 items with gap scoring across all systems.

📋 Free Download: Supplier Quality Checklist — ISO 9001 Clause 8.4 — all supplier controls auditors evaluate, 45 items with scoring.

📋 Free Download: ISO 9001 Implementation Roadmap — The exact 5-phase process from gap assessment to Stage 2 audit clearance.

📋 Free Download: ISO 13485 Gap Assessment Checklist — 64 items — ISO 13485 clauses + all four FDA QMSR bridge requirements ISO 13485 certification alone does not cover.


Not Sure What to Do Next?

→ You need the official ISO 13485:2016 standard → ANSI Webstore — Use CC2026 for 5% off. ANSI is the official U.S. distributor of ISO standards.

→ You need to assess your QMS gaps before your next audit → ISO 13485 Gap Assessment Checklist — free, 64 items

→ You need to build or rebuild QMS documentation → 9001Simplified Documentation Kits — 9001Simplified provides ready-to-use documentation kits that dramatically reduce the internal labor required to build a compliant QMS from scratch.

→ You need to train your team on ISO 13485 requirements → BSI Group ISO 13485 Training — BSI Group is a founding member of ISO and one of the world’s largest providers of ISO training courses.

→ You are ready to pursue or maintain ISO 13485 certification → ISOQAR — UKAS-accredited, one of the most recognized certification bodies in the industry.

→ You need to understand CAPA requirements in depth → CAPA Requirements in ISO 13485

→ You need to understand how risk management connects to your QMS → ISO 14971 vs ISO 13485 and What Is ISO 14971?

→ You need to understand how QMSR changed your compliance obligations → FDA QSR vs ISO 13485

→ You need to understand what ISO 13485 covers at the clause level → What Is ISO 13485?

→ You need to understand the cost of ISO 13485 certification → How Much Does ISO 13485 Cost?

→ You want to buy ISO 13485 → Buy ISO 13485

→ You want to browse all medical device standards → explore standards by compliance area


Still figuring out where to start?

If you are not ready to invest in training or documentation yet — that is normal. Most organizations take several weeks to move from identifying gaps to committing to a remediation plan.

The best next step for most organizations at this stage: → Download the free ISO 13485 Gap Assessment Checklist — it takes 20 minutes and tells you exactly where your QMS has gaps before you spend anything.

📋 Free Download: ISO 13485 Gap Assessment Checklist — 64 items — ISO 13485 clauses + all four FDA QMSR bridge requirements ISO 13485 certification alone does not cover.


The Gap Between What Was Built and What Runs

Most ISO 13485 QMS failures are not failures of intent. The organizations that receive major nonconformances typically built their systems with genuine effort. What they built, however, was optimized for initial certification — not for the ongoing operational reality that surveillance audits and FDA inspections evaluate.

Document control systems that work at go-live drift as people find workarounds. CAPA programs that close records efficiently lose track of effectiveness. Management reviews that felt thorough produce minutes that record what was presented rather than what was decided. None of these failures are dramatic. They accumulate quietly, and they surface at the worst possible time.

The difference between a QMS that passes surveillance audits consistently and one that doesn’t is not sophistication. It is the discipline to evaluate what the system actually does — not just what the procedures say it does — on a regular basis.

At The Standards Navigator, complex standards are translated into practical, real-world guidance you can act on.

Subscribe below to stay ahead.

Subscribe

* indicates required

CAPA Requirements in ISO 13485 (2026)

CAPA under ISO 13485 is more than corrective action paperwork. Learn what auditors and FDA investigators actually evaluate, common CAPA failures, Clause 8.5 requirements, effectiveness verification expectations, and how CAPA now fits into modern QMSR inspection strategy.

What the FDA’s newest inspection data reveals about where medical device manufacturers are still getting it wrong — and how to close the gaps before your next audit.

Last Updated: May 2026


Affiliate Disclosure: Some links in this article are affiliate links. If you purchase through them, The Standards Navigator may earn a commission at no additional cost to you.


📋 Free Download: ISO 13485 Gap Assessment Checklist — 64 items covering ISO 13485 clauses + all four FDA QMSR bridge requirements ISO 13485 certification alone does not cover.


The FDA Just Changed How It Measures Your CAPA System — And Most Manufacturers Haven’t Noticed

CAPA was the undisputed number-one FDA 483 finding for years. Not close. Not rotating with other subsystems. Every year, far and away.

That changed in 2026.

Three months of QMSR inspection data is in. Risk management documentation under Clause 7.1 now sits at number one — 25 citations. CAPA-related findings come in at 19 combined. On paper, that looks like good news. It isn’t — at least not entirely.

Here’s the nuance that matters: the inspection model changed. Under the old QSIT system, abbreviated inspections hit CAPA almost every single time. Other subsystems cycled in less frequently. CAPA’s dominance was partly an artifact of inspection structure, not a clean picture of where the industry actually struggled.

The new model looks at everything — every subsystem, every inspection. The categorization changed too. Under the old QSR, all CAPA requirements bundled into one code. Now they fragment. Two separate 8.5.2 entries already appear in the first dataset. CAPA didn’t disappear. The field just got wider.

If you’re managing a QMS for a medical device manufacturer, that means more exposure, not less.


In This Guide

  • What ISO 13485 Clause 8.5.2 actually requires — and what most procedures miss
  • The six mandatory data inputs for your CAPA process under Section 8.4
  • Why the InfuTronix case is the most instructive FDA enforcement example in recent years
  • The difference between measurement and analysis — and why confusing them causes most failures
  • How horizontal analysis works and why auditors look for it specifically
  • Common misconceptions that lead to major nonconformances
  • What to do before your next surveillance audit


Start Here (Top Resources)

🔖 Get ISO 13485:2016 → ANSI Webstore — ANSI is the official U.S. distributor of ISO standards, ensuring you receive the controlled, compliant version required for certification audits. Use coupon CC2026 for 5% off.

🔖 Get ISO 13485 training → BSI Group — BSI Group is a founding member of ISO and one of the world’s largest providers of ISO training courses, recognized by certification bodies globally.

🔖 Build your CAPA documentation → 9001Simplified — 9001Simplified provides ready-to-use documentation kits that dramatically reduce the internal labor required to build a compliant QMS from scratch.

🔖 Pursue or maintain ISO 13485 certification → ISOQAR — ISOQAR is a UKAS-accredited certification body — one of the most recognized in the industry for ISO management system certification.

Browse the Standards Library to identify which standards apply to your compliance area, or view the most widely used standards in medical devices and manufacturing.


What Is CAPA Under ISO 13485?

CAPA cycle diagram showing ISO 13485 Clause 8.5.2 corrective action and Clause 8.5.3 preventive action steps: Identify, Prevent, Monitor, Improve, Correct, Root Cause
CAPA under ISO 13485 follows a closed-loop process: identify issues, determine root cause, implement corrective action, monitor effectiveness, and prevent recurrence through continual improvement.

CAPA — Corrective and Preventive Action — is the mechanism your QMS uses to identify problems, trace them to root cause, and prevent recurrence. Under ISO 13485:2016, CAPA spans two clauses: Clause 8.5.2 (corrective action) and Clause 8.5.3 (preventive action). They operate differently and auditors evaluate them separately.

Corrective action addresses a nonconformity that has already occurred. Preventive action addresses a potential nonconformity that has not yet materialized. The distinction matters because the procedures, triggers, and documentation requirements differ between them.

ISO 13485 places CAPA in the broader context of Clause 8.5, which also covers continual improvement. But the practical application of CAPA runs deeper — it pulls from data collected across Clause 8.4 (analysis of data) and connects to management review, internal audits, and post-market surveillance. A CAPA procedure that treats the clause as standalone almost always fails at audit.

Under the QMSR (Quality Management System Regulation), which took effect February 2, 2026, FDA now explicitly harmonizes its device QMS requirements with ISO 13485. CAPA requirements that previously lived in 21 CFR Part 820.100 now map directly to ISO 13485 Clause 8.5.2. FDA expects those requirements to be met — and QMSR inspections are actively evaluating them.


What Clause 8.5.2 Actually Requires

Clause 8.5.2 sets out six specific requirements for corrective action. Each one has a documentation implication.

1. Review nonconformities — including customer complaints. This means your CAPA trigger list must include complaint data, not just internal defect records. If complaints are logged in one system and CAPA is managed in another, there needs to be a formal connection between them. Auditors check that connection.

2. Determine the causes of nonconformities — root cause analysis is not optional. Documenting “operator error” or “process deviation” without supporting evidence of how that conclusion was reached is a common major nonconformance. You need a documented methodology — 5 Whys, fishbone, fault tree — and evidence it was applied.

3. Evaluate the need for corrective action — not every nonconformity requires a CAPA. The standard requires you to evaluate and document that decision. Organizations that open a CAPA for every minor deviation create administrative burden; organizations that never document the decision to not open a CAPA create audit vulnerability.

4. Determine and implement corrective action — the action must be proportionate to the effects of the nonconformity. This means documented implementation, not just a description of what was planned.

5. Record results of corrective action — effectiveness verification is required. You must demonstrate that the action you took actually resolved the problem. A corrective action record that closes without verification evidence is not compliant.

6. Review corrective action and its effectiveness — this step loops back into your data analysis process. If the same problem recurs, your record should capture that recurrence and the updated response.

The 2026 QMSR inspection data showing two separate 8.5.2 citations reflects how inspectors are now parsing these requirements individually. A finding against root cause determination is a different citation from a finding against effectiveness verification.

At this point, most quality managers in this position should: → Confirm your CAPA procedure addresses all six elements explicitly — and that your records can demonstrate compliance with each one. Get the ISO 13485 Gap Assessment Checklist to verify your current gaps across all 13485 clauses.


The Six Data Inputs for Section 8.4

Clause 8.4 requires you to analyze data from specific sources to drive CAPA and continual improvement. The standard names six:

Data SourceWhat It Covers
FeedbackCustomer complaints, post-market surveillance data, service reports flagged by users
Product conformityInspection results, test data, nonconforming product records
Process and product trendsStatistical process control, yield trends, recurring deviations
Supplier performanceSupplier nonconformances, delivery performance, qualification data
Audit resultsInternal audit findings, certification body findings, customer audits
Service reportsField service records, repair data, failure modes reported post-delivery

Your CAPA procedure must document how data from each of these sources is collected, reviewed, and used to make CAPA decisions. The piece most manufacturers skip entirely is what experienced quality practitioners call horizontal analysis — looking across your data sources, not just within them.


The Analysis Failure: What InfuTronix Got Wrong

The InfuTronix case is the most instructive CAPA enforcement example to come out of FDA inspection activity in recent years. It illustrates the most common failure mode — and it isn’t what most people expect.

InfuTronix had a rule written directly into their CAPA procedure: ten complaints in a rolling 12-month window triggers a CAPA. Simple enough. Documented. Auditable on its face.

Between September 2020 and August 2021, they received 80 complaints reporting power issues, 31 for battery failures, and 67 for leaking administration sets. Not one CAPA was opened.

This was not a data collection failure. The complaints were logged. The threshold was documented. The system simply never connected what was being measured to what that data actually meant.

That is an analysis failure — and it is the most common one FDA finds.

Measurement gets you the number. Analysis tells you what to do with it.

ISO 13485 Section 8.4 requires both, and your procedure needs to address the full cycle: collect the data, analyze it against defined criteria, and produce a documented decision. The decision can be: open a CAPA, escalate to management review, or continue monitoring. All three are defensible. No decision — or a decision made without documentation — is not.

FDA found all of this during inspection. The warning letter that followed cited failure to establish and maintain procedures for implementing corrective action under 21 CFR 820.100(a). Under QMSR, that same finding maps directly to ISO 13485 Clause 8.5.2.

Source: FDA Warning Letter, InfuTronix LLC, June 16, 2022. Available at fda.gov.

ISO 13485 Section 8.4 infographic showing the measurement and analysis cycle with a process flow from data collection to analysis, documented decision making, and outcomes including CAPA, management review, or continued monitoring.
Measurement gets you the number. Analysis determines the response. Under ISO 13485 Section 8.4, organizations must collect data, analyze it against defined criteria, and document a defensible decision.

📋 Free Download: ISO 13485 Gap Assessment Checklist — 64 items covering ISO 13485 clauses + all four FDA QMSR bridge requirements ISO 13485 certification alone does not cover.


Horizontal Analysis: The Step Most QMS Procedures Skip

Vertical analysis — reviewing data within a single source — is what most CAPA procedures are built around. You run through complaints. You run through audit findings. You check supplier nonconformances. Each in its own silo.

Horizontal analysis means looking across those sources simultaneously — specifically for patterns that only become visible when you connect the data.

A complaint spike in Q2 means something different when it aligns with a supplier nonconformance from the same quarter. A field failure pattern means something different when it correlates with a process change implemented three months prior. A rising service report trend means something different when internal inspection data for the same product shows clean numbers — because that combination suggests the problem is post-delivery, not in-process.

These cross-source connections are where real problems get caught before FDA finds them. They are also where most QMS procedures have no documented methodology whatsoever.

Your CAPA procedure should require a formal cross-source review at defined intervals — typically aligned with management review. The review should produce a documented output: either a CAPA trigger, a decision to continue monitoring with rationale, or escalation to a different quality subsystem.

Certification bodies increasingly audit for this specifically. The question is not just “do you have a CAPA procedure?” It’s “does your analysis process look across all six data sources and produce a documented decision?”


➡️ ANSI Webstore — Get ISO 13485:2016, the standard your CAPA procedure must align with. ANSI is the official U.S. distributor of ISO standards, ensuring you receive the controlled, compliant version required for certification audits. Use coupon CC2026 for 5% off.


Common CAPA Misconceptions

“A CAPA is only needed when something goes seriously wrong.”

The standard doesn’t set a severity threshold for opening a CAPA — it requires a documented decision about whether a nonconformity warrants one. The mistake isn’t opening too many CAPAs. It’s failing to document the evaluation. Auditors don’t penalize organizations for opening few CAPAs; they penalize organizations that can’t show they evaluated the data and made a deliberate decision.

“Closing the CAPA once the action is implemented is sufficient.”

Clause 8.5.2 requires effectiveness verification — evidence that the corrective action actually resolved the problem. Closing a CAPA at implementation is one of the most consistently cited findings in ISO 13485 surveillance audits. Effectiveness verification must be documented, must use defined criteria, and must happen at a point in time when there is enough post-implementation data to draw a conclusion.

“Our CAPA system is separate from complaint handling and that’s fine.”

It isn’t. The connection between complaint data and CAPA decisions must be explicit and documented. A complaint handling procedure that logs data and a CAPA procedure that never receives it create exactly the kind of system failure the InfuTronix case illustrates. If there is no formal handoff between your complaint system and your CAPA trigger evaluation, that gap will be found.


What Auditors Look For in CAPA Reviews

Whether the auditor is from a certification body or an FDA investigator conducting a QMSR inspection, the CAPA review follows a consistent pattern. Understanding it in advance is the most effective preparation.

They start with your procedure. They read it. They look for whether it covers all six elements of Clause 8.5.2 and whether it explicitly addresses the six data inputs from Clause 8.4. Gaps in the procedure are flagged before they look at a single record.

They pull a sample of CAPA records. Typically 3–5 for a surveillance audit, more for initial certification or for-cause inspections. They are looking for: documented root cause methodology, proportionality between the action and the finding, effectiveness verification with criteria and evidence, and closure only after verification.

They look for records that should exist but don’t. This is where analysis failures surface. If complaint data shows a spike and no CAPA was opened, the auditor will ask for the documented decision that concluded no CAPA was needed. If that document doesn’t exist, that is a finding — regardless of whether the decision was actually reasonable.

They check the connection between data sources. Does your management review input include CAPA status? Does your internal audit program look at CAPA effectiveness? Does complaint data flow into your trend analysis? These connections are evaluated systematically.

They review effectiveness verifications. A CAPA closed with “action implemented — problem resolved” and no supporting data is a major nonconformance. Effectiveness verification requires defined criteria established before the action is taken, a monitoring period, and data that demonstrates the criteria were met.

ISO 13485 CAPA audit review infographic showing the key areas auditors evaluate during certification and FDA inspections, including procedures, CAPA records, missing records, data connections, and effectiveness verification.
CAPA audits follow a predictable path. Auditors review procedures, sample records, process connections, and effectiveness evidence to determine whether your system is functioning as designed.

If you are preparing for a certification audit or a QMSR inspection, the FDA QSR vs ISO 13485 (QMSR Transition Guide) is the clearest resource available on how the two frameworks now align.

If you are building CAPA procedures from scratch or rewriting existing ones, the What Is ISO 13485? pillar article covers the full clause-by-clause context you need before the documentation work begins. For a complete breakdown of how ISO 13485 and FDA QMSR requirements interact at the clause level, see ISO 9001 vs ISO 13485.

If you are under active FDA inspection pressure → Get BSI Group ISO 13485 training and ISOQAR certification support immediately. BSI Group is a founding member of ISO and one of the world’s largest providers of ISO training courses, recognized by certification bodies globally. ISOQAR is a UKAS-accredited certification body — one of the most recognized in the industry for ISO management system certification.

ProviderWhat You GetBest For
ANSI WebstoreISO 13485:2016 official standard documentAny organization needing the controlled, compliant version of the standard
BSI GroupISO 13485 training coursesTeams preparing for implementation, audit readiness, or CAPA procedure development
9001SimplifiedQMS documentation kitsOrganizations building CAPA and QMS documentation from scratch
ISOQARISO 13485 certificationOrganizations ready to pursue or maintain certification

Most organizations at this stage need all three:

This combination covers the standard, the knowledge, and the implementation infrastructure.


Frequently Asked Questions

What does ISO 13485 require for CAPA?

ISO 13485 Clause 8.5.2 requires a documented procedure that covers reviewing nonconformities, determining root causes, evaluating the need for action, implementing corrective action proportionate to the problem, recording results, and verifying effectiveness. Preventive action under Clause 8.5.3 follows a parallel structure for potential — not actual — nonconformities.

What is the most common CAPA finding in ISO 13485 audits?

Failure to verify the effectiveness of corrective actions is consistently the most common major nonconformance in surveillance audits. The second most frequent is incomplete root cause analysis — particularly records that name a root cause without showing the methodology used to reach that conclusion.

How many CAPAs should a medical device manufacturer open per year?

There is no target number. A small manufacturer with a mature QMS might open fewer than ten CAPAs annually and pass every audit. What auditors evaluate is whether the documented decision-making process is defensible — not the volume of CAPAs opened. If you are in a situation where your data shows patterns and no CAPAs are being opened, the risk is high regardless of company size.

Does CAPA under QMSR differ from CAPA under the old QSR?

The substance is largely the same. The significant change is that QMSR now explicitly adopts ISO 13485 Clause 8.5.2 as the governing framework, and inspections evaluate every subsystem — not just CAPA, as abbreviated QSIT inspections frequently did. Two separate 8.5.2 citations already appear in early QMSR inspection data, reflecting more granular evaluation of individual requirements within the clause. Read the full FDA QSR vs ISO 13485 Transition Guide for a complete breakdown.

What is the difference between corrective action and preventive action in ISO 13485?

Corrective action (Clause 8.5.2) addresses a nonconformity that has already occurred. Preventive action (Clause 8.5.3) addresses a potential nonconformity that trend data or risk analysis suggests may occur. The distinction is more than semantic — auditors evaluate them separately, the documentation requirements differ, and the trigger criteria for each should be explicit in your procedure.

Can we use a single CAPA form for both corrective and preventive actions?

Yes — many organizations use a combined form with fields that distinguish the type of action. What matters is that the record clearly identifies whether the action is corrective or preventive, that the corresponding clause requirements are addressed, and that the effectiveness verification criteria are appropriate for the action type.

What data sources must feed our CAPA process under ISO 13485?

Clause 8.4 identifies six: feedback (including complaints), product conformity data, process and product trends, supplier performance, audit results, and service reports. Your CAPA procedure should document how each source is reviewed, at what frequency, and how that review produces documented CAPA decisions. If you are using the ISO 13485 Gap Assessment Checklist, the data analysis section will identify exactly where your current procedure has gaps.

How long do we need to keep CAPA records?

ISO 13485 Section 4.2.5 requires records to be retained for a period at least equal to the lifetime of the device, but not less than two years from the date of product release. FDA QMSR requirements align with this. For implantable devices or devices with extended service life, the retention period is typically longer and should be specified in your records control procedure.


Free Resources

📋 Free Download: Manufacturing Compliance Checklist — ISO 9001, 14001, 45001 & OSHA — 50 items with gap scoring across all systems.

📋 Free Download: Supplier Quality Checklist — ISO 9001 Clause 8.4 — all supplier controls auditors evaluate, 45 items with scoring.

📋 Free Download: ISO 9001 Implementation Roadmap — The exact 5-phase process from gap assessment to Stage 2 audit clearance.

📋 Free Download: ISO 13485 Gap Assessment Checklist — 64 items — ISO 13485 clauses + all four FDA QMSR bridge requirements ISO 13485 certification alone does not cover.


Not Sure What to Do Next?

→ You need the official ISO 13485:2016 standard → ANSI Webstore — Use CC2026 for 5% off. ANSI is the official U.S. distributor of ISO standards.

→ You need to understand how your CAPA requirements changed under QMSR → FDA QSR vs ISO 13485 Transition Guide

→ You need to train your team on ISO 13485 CAPA requirements → BSI Group ISO 13485 Training — BSI Group is a founding member of ISO and one of the world’s largest providers of ISO training courses.

→ You need to build CAPA documentation from scratch → 9001Simplified Documentation Kits — 9001Simplified provides ready-to-use documentation kits that dramatically reduce the internal labor required to build a compliant QMS.

→ You are ready to pursue ISO 13485 certification → ISOQAR — ISOQAR is a UKAS-accredited certification body — one of the most recognized in the industry for ISO management system certification.

→ You want to assess your full ISO 13485 gaps before spending anything → ISO 13485 Gap Assessment Checklist — free, 64 items

→ You need to understand what ISO 13485 covers before addressing CAPA specifically → What Is ISO 13485?

→ You need to understand how risk management connects to CAPA → What Is ISO 14971? and ISO 14971 vs ISO 13485

→ You need to compare ISO 13485 to ISO 9001 to understand CAPA differences → ISO 9001 vs ISO 13485

→ You want to buy ISO 13485 → Buy ISO 13485

→ You want to browse all medical device standards in one place → explore sector-specific standards or browse standards by compliance area


Still figuring out where to start?

If you are not ready to purchase yet — that is normal. ISO 13485 CAPA decisions typically take weeks from first research to implementation commitment.

The best next step for most organizations at this stage: → Download the free ISO 13485 Gap Assessment Checklist — it takes 20 minutes and tells you exactly where your CAPA and QMS gaps are before you spend anything.

📋 Free Download: ISO 13485 Gap Assessment Checklist — 64 items — ISO 13485 clauses + all four FDA QMSR bridge requirements ISO 13485 certification alone does not cover.


The Cost of an Analysis Failure

CAPA is not a form. It is not a procedure sitting in your document management system. It is the mechanism that connects everything your quality system measures to everything your quality system does about it. When that connection breaks — when data is collected, thresholds are documented, and no one asks what the numbers actually mean — FDA finds it. Certification bodies find it. And devices reach the field with problems that could have been caught.

The InfuTronix case isn’t an outlier. Organizations that receive 483 observations for CAPA failures almost always had a procedure. What they didn’t have was an analysis process that produced documented decisions. That gap is what inspection finds — and it’s the gap that costs the most to recover from after the fact.

Under QMSR, the inspection model is now broader. Every subsystem, every inspection. CAPA didn’t disappear from the top of the finding list — it fragmented into more specific citations. That means more exposure, not less.

At The Standards Navigator, complex standards are translated into practical, real-world guidance you can act on.

👉 Get updates on new standards, implementation strategies, and compliance insights 👉 Be first to access new guides, tools, and checklists

Subscribe below to stay ahead.

Subscribe

* indicates required