ISO 13485 Clauses Explained: A Complete Clause-by-Clause Breakdown (2026)

ISO 13485:2016 has eight clauses, but only five carry auditable requirements. This ISO 13485 clauses explained guide breaks down Clauses 4 through 8 in practical terms, corrects the common DHF-to-Medical-Device-File mapping error, and explains how FDA’s Compliance Program 7382.850 — which replaced QSIT on February 2, 2026 — reorganizes inspections around six QMS Areas and four Other Applicable FDA Requirements.

What every section of ISO 13485:2016 actually requires — and where auditors dig deepest

Affiliate Disclosure: Some links in this article are affiliate links. If you purchase through them, The Standards Navigator may earn a commission at no additional cost to you.


The Standard Reads Like a Checklist. It Isn’t One.

ISO 13485:2016 has eight clauses. Five of them carry actual requirements. That structure looks simple on the page — and it’s exactly why so many quality teams underestimate how much interpretation each clause demands once an auditor starts asking “show me.” This ISO 13485 clauses explained guide breaks down what each section requires, where the requirements overlap, and what auditors and FDA investigators may look for.

The FDA’s Quality Management System Regulation (QMSR) took effect February 2, 2026, incorporating ISO 13485:2016 by reference into 21 CFR Part 820. That changes what this clause structure means in practice. FDA also replaced its inspection methodology the same day — the Quality System Inspection Technique (QSIT) is gone, replaced by Compliance Program 7382.850. Getting the clause boundaries right now has a direct line to how an FDA investigator scopes an inspection, not just how a certification body audits.

Regulatory affairs and quality professionals reading this already know ISO 13485 exists. What’s harder to find is a breakdown that goes past the clause titles and into what each section demands in practice — where the audit findings cluster, where risk management threads through clauses that don’t mention risk in their title, and where the standard’s lack of an Annex SL high-level structure changes how it should be read compared to ISO 9001.

My perspective on this comes from 25+ years in operations leadership, an ISO 9001 Internal Auditor certification, and a Six Sigma Green Belt — a lot of that time spent on both sides of the table, building QMS documentation and sitting in CAPA reviews when a gap in that documentation turned into a finding. The pattern holds across every regulated QMS I’ve worked with: teams don’t fail because they misread a clause. They fail because they treated clause boundaries as more rigid than the standard actually intends, and missed how much cross-referencing an auditor expects between clauses 4 through 8.

If you haven’t run a structured gap check against the current clause set, that’s the place to start — not a full documentation rewrite.

👉 Run the ISO 13485 Gap Assessment Checklist before you touch your quality manual — a free, structured way to see exactly which clauses your QMS already satisfies and which ones need real work before an auditor finds the gap for you.


In This Guide

  • How ISO 13485:2016 is structured, and why it doesn’t follow ISO’s Annex SL format
  • A clause-by-clause breakdown of Clauses 4 through 8
  • How FDA’s current inspection program, Compliance Program 7382.850, reorganizes inspections around six QMS Areas
  • The most common audit findings tied to specific sub-clauses
  • Where risk management actually appears throughout the standard
  • How ISO 13485 clause numbering compares to ISO 9001
  • FAQs on structure, exclusions, and transition timing


👉 Start Here (Top Resources)


ISO 13485 Clauses Explained: How the Standard Is Structured

ISO 13485 clauses explained with an eight-clause map covering the standard’s foundational and QMS requirement clauses
ISO 13485 clauses explained through an eight-clause map showing the foundational clauses and the five clauses containing QMS requirements.

ISO 13485:2016 is built around eight clauses. The first three are introductory — they define scope, point to normative references, and set terminology. They carry no auditable requirements on their own, but skipping them is a mistake most teams make once and then correct the hard way.

Clauses 4 through 8 are where the requirements live. This is the part of the standard your certification body actually audits against, clause by clause, sub-clause by sub-clause.

Here’s something worth knowing before you go further: ISO 13485 does not follow the Annex SL high-level structure that ISO 9001:2015, ISO 14001, and ISO 45001 all share. Those three standards align clause-for-clause at the top level, which is why integrated management systems work so cleanly across them. ISO 13485 kept its own structure when it was revised in 2016, specifically so it could stay independent of ISO 9001 revision cycles — a deliberate choice by the technical committee to protect regulatory stability for device manufacturers. If you’re coming from an ISO 9001 background, this is the first adjustment to make: don’t assume clause 7 means the same thing in both standards. It doesn’t.


Clauses 1 Through 3: No Requirements, But Don’t Skip Them

Clause 1 (Scope) defines what the standard covers and, critically, how exclusion and non-application work. ISO 13485 doesn’t let an organization simply skip a requirement that seems inconvenient — where a clause is excluded or considered non-applicable (say, you don’t perform installation), the scope and justification have to be documented in the quality manual under Clause 4.2.2, and be prepared to defend that justification during an audit.

Clause 2 (Normative References) points to ISO 9000:2015 for terms and definitions. You don’t need to buy ISO 9000 to comply, but auditors do expect your team to be using its vocabulary consistently — “nonconformity,” “corrective action,” and “verification” all carry specific meanings your documentation should match.

Clause 3 (Terms and Definitions) establishes the vocabulary used throughout the standard, including specific definitions for concepts like medical device, complaint, risk, and post-market surveillance. Getting comfortable with this terminology matters more than it looks like it should — auditors expect your documentation to use these terms precisely, not colloquially.

📥 Before diving into clauses 4-8: if your QMS documentation predates 2020, run it against the current ISO 13485 Documentation Requirements breakdown first. Most gaps trace back to documentation structure, not missing procedures.


Clause 4: Quality Management System

Clause 4 sets the general requirements for the QMS itself — and it’s where most audit programs start, because everything downstream depends on it.

4.1 General Requirements requires you to identify your QMS processes, map their sequence and interaction, and — this is the part that trips up contract manufacturers — maintain control over any process you outsource. Most common finding: outsourced processes (contract sterilization, contract testing, third-party calibration) that exist operationally but were never formally brought into QMS scope. If a supplier touches your product or your data, your QMS has to account for it.

4.2 Documentation Requirements covers the quality manual, the Medical Device File (Clause 4.2.3), document control, and record control. This requirement is specific to this standard — it’s not something ISO 9001 asks for. It’s a defined set of documents and references demonstrating a device meets its requirements throughout its lifecycle, and auditors will ask to see it assembled, not scattered across a dozen disconnected folders.

If your documentation still uses FDA’s old terminology, this is worth getting precise about. As of February 2, 2026, the terms Device Master Record, Device History Record, and Design History File no longer appear in 21 CFR Part 820. Those legacy record concepts weren’t simply eliminated; their applicable requirements are now addressed through the QMSR framework and ISO 13485’s own structure. Most of what a Device Master Record covered lives in the Medical Device File at Clause 4.2.3, while the Design History File corresponds to the Design and Development File at Clause 7.3.10. These aren’t simple one-for-one renamings: the Medical Device File in particular is a broader requirement than the DMR it replaced, so a straight terminology swap in your documentation will likely leave gaps a crosswalk exercise would catch.

Sub-clause 4.2.4 (control of documentation) and 4.2.5 (control of records) get their own scrutiny. Auditors typically check three things here: are documents reviewed and approved before use, is there a mechanism to prevent use of outdated versions, and are records retained for a defined, justified period. If you’re preparing for your first audit under this clause → build your document control procedure before you build anything else. Everything else in the QMS references it.


Clause 5: Management Responsibility

Clause 5 puts specific, named accountability on top management — not “the quality department,” but leadership itself.

This clause requires a documented quality policy, measurable quality objectives, evidence of planning for QMS changes, and a sub-clause I’ve seen come up repeatedly in audit findings — management review. Clause 5.6.2 is unusually prescriptive for an ISO standard: it names twelve required inputs, and a compliant management review record has to address all of them or document why one doesn’t apply — feedback, complaint handling, reporting to regulatory authorities, audits, monitoring and measurement of processes, monitoring and measurement of product, corrective action, preventive action, follow-up actions from previous reviews, changes that could affect the QMS, recommendations for improvement, and applicable new or revised regulatory requirements. A management review that skips several of these, or that doesn’t produce documented outputs and action items, is a finding waiting to happen — and under the current FDA inspection framework, it’s no longer just a certification-audit concern (more on that below).

If you are already ISO 9001 certified, this clause will feel familiar structurally — but ISO 13485 expects a tighter link between management review and regulatory requirements specifically, not just general business objectives.


Clause 6: Resource Management

Clause 6 covers human resources, infrastructure, and work environment — including contamination-control requirements under 6.4.2 that go considerably further than ISO 9001’s general treatment of work environment.

6.2 Human Resources requires documented competence for anyone whose work affects product quality — not just “trained,” but competence tied to education, skills, and experience, with evidence. 6.3 Infrastructure requires maintenance records for equipment critical to product conformity. 6.4 Work Environment and Contamination Control is where device manufacturers doing anything sterile, implantable, or otherwise contamination-sensitive get the most detailed scrutiny — cleanroom classifications, gowning procedures, and environmental monitoring data all trace back here.


Clause 7: Product Realization

Clause 7 is the largest clause in the standard, and it’s where design controls, purchasing, production, and servicing all live.

7.1 Planning of Product Realization is where ISO 13485 explicitly requires documented risk management processes within product realization, with records maintained throughout. The clause’s note points readers to ISO 14971 for further guidance on structuring that risk management activity — it’s a reference, not a formal incorporation, though in practice most organizations end up using ISO 14971’s framework to satisfy this requirement.

7.3 Design and Development is one of the sub-clauses most commonly identified as non-applicable by contract manufacturers who don’t design product — but where it applies, it can’t be excluded lightly, and the justification has to hold up to the same Clause 4.2.2 scrutiny as any other exclusion. If it applies to you, this is the densest technical section of the standard: design inputs, outputs, review, verification, validation, transfer, and change control, each with its own documented evidence trail. Most common finding: design changes made without running them back through the full verification/validation cycle, especially late in development when schedule pressure is highest.

7.4 Purchasing requires supplier evaluation criteria proportionate to risk, and re-evaluation triggers when supplier performance changes. 7.5 Production and Service Provision covers process validation for anything that can’t be fully verified by downstream inspection — sterilization is the textbook example, which is why it gets its own dedicated body of standards. 7.6 Control of Monitoring and Measuring Equipment ties directly into your calibration program.

If you are under customer or FDA pressure to show design control maturity quickly → prioritize closing out 7.3 documentation gaps before anything else in this clause. In my experience, it’s one of the first sections a regulatory reviewer or auditor asks to see in depth.


Clause 8: Measurement, Analysis and Improvement

Clause 8 is where the QMS proves it’s actually working — and where CAPA lives.

8.2 Monitoring and Measurement covers feedback, complaint handling, and internal audit. Complaint handling under this clause has to interface with FDA’s separate adverse-event reporting requirements — a complaint that may represent a reportable event under Medical Device Reporting (21 CFR Part 803) can’t remain solely an internal QMS record; it has to be evaluated independently against those reporting obligations.

8.3 Control of Nonconforming Product requires documented procedures for identifying, segregating, and dispositioning nonconforming product, including for product discovered nonconforming after delivery — which is where recall-adjacent procedures connect back into the standard.

8.5 Improvement is where corrective and preventive action requirements sit. CAPA under ISO 13485 requires root cause investigation, verification that the action taken was effective, and — a detail I’ve seen auditors check for specifically — evidence that you evaluated whether the same nonconformity could exist elsewhere in the organization before closing the CAPA. A CAPA record that fixes one instance without documenting that broader check is incomplete by this clause’s own standard, regardless of whether the immediate fix worked.

For a deeper breakdown of this clause specifically, see our full guide to CAPA requirements in ISO 13485.


Where ISO 13485 and FDA’s QMSR Overlap by Clause

FDA’s Quality Management System Regulation took effect February 2, 2026, incorporating ISO 13485:2016 by reference into 21 CFR Part 820. That’s the headline most coverage stopped at. What matters more for how you prepare is what happened on the inspection side the same day: FDA retired the Quality System Inspection Technique (QSIT), the inspection methodology it had used since 1999, and replaced it with a new compliance program manual — CP 7382.850, Inspection of Medical Device Manufacturers.

ISO 13485 clauses explained through the 2026 FDA QMSR inspection framework, including six QMS Areas and four OAFRs
ISO 13485 clauses explained in the context of the FDA QMSR and CP 7382.850 inspection framework effective February 2, 2026.

QSIT organized inspections around four subsystems. CP 7382.850 reorganizes them around six QMS Areas, each mapped to ISO 13485 clauses with FDA-specific requirements layered in:

  • Management Oversight — the QMS itself, management review, the medical device file, and product realization planning
  • Design and Development — design inputs, outputs, review, verification, validation, software validation, and transfer
  • Production and Service Provision — production planning, process validation, and servicing
  • Measurement, Analysis, and Improvement — complaint handling, feedback, internal audits, corrective and preventive action, and control of nonconforming product
  • Outsourcing and Purchasing — supplier evaluation and control
  • Change Control — how changes to product or process are managed and documented

Alongside the six QMS Areas, inspections also evaluate four Other Applicable FDA Requirements (OAFRs) that sit outside ISO 13485’s text entirely: Medical Device Reporting (21 CFR Part 803), Corrections and Removals reporting (21 CFR Part 806), Medical Device Tracking (21 CFR Part 821), and Unique Device Identification (21 CFR Part 830). This is where the clause structure above stops covering everything — these four areas are FDA-specific regulatory obligations, not ISO 13485 requirements. They’re evaluated during routine surveillance, compliance follow-up, and PMA postmarket inspections; a narrow exception can apply to certain PMA preapproval inspections when the manufacturer hasn’t yet introduced the device to the U.S. market.

The change that affects Clause 5 most directly: under the prior QSR, management review records were categorically exempt from FDA review under §820.180(c). Under CP 7382.850, that exemption is gone. Management review now sits squarely inside the Management Oversight QMS Area, and an investigator can ask to see it — which means the twelve required Clause 5.6.2 inputs covered above aren’t just a certification-audit concern anymore.

One caution worth stating plainly: ISO 13485 certification and FDA QMSR compliance are related but not identical. A QMS built cleanly against Clauses 4 through 8 covers the ISO 13485 core that QMSR incorporates, but it doesn’t automatically satisfy the four OAFRs — those require their own documented processes regardless of how strong your clause-by-clause QMS is.

If you’re not sure whether your current documentation satisfies both frameworks → our FDA QSR vs ISO 13485 comparison and MDSAP vs ISO 13485 breakdown both walk through this in more detail than fits here.

ISO 13485 vs ISO 9001: Same Numbers, Different Weight

ElementISO 13485:2016ISO 9001:2015
Structure8 clauses, own structure (not Annex SL)10 clauses, Annex SL high-level structure
Risk managementDocumented risk management required in product realization (7.1); note references ISO 14971Risk-based thinking, less prescriptive
Customer satisfaction monitoringNo direct ISO 9001-style requirement; feedback/complaints addressed via Clause 8.2Explicit requirement (Clause 9.1.2)
DocumentationMedical device file required (Clause 4.2)No equivalent requirement
Design controlsDetailed, mandatory unless justified exclusionLess detailed by comparison
Regulatory linkDirectly referenced in FDA QMSR (21 CFR 820)Not tied to a specific regulation

The clause numbers look similar enough to cause real confusion — both standards use “Clause 7” for a large operational section, but the content underneath diverges substantially. If your organization holds both certifications, don’t assume a clause 7 audit finding under one standard tells you anything about your standing under the other. For the full comparison, see ISO 9001 vs ISO 13485.

The objection I hear most on this topic: “We’re already ISO 9001 certified — how much of this is actually new work?” Realistically, expect Clauses 5 and 6 to require the least rework, since management responsibility and resource management overlap heavily in intent. Clauses 4, 7, and 8 are where the medical device-specific requirements add real documentation and process work — the medical device file, design control rigor, and CAPA’s broader-impact evaluation aren’t things a general ISO 9001 QMS already has built in.


Most teams don’t fail an ISO 13485 audit because they misunderstood a clause. They fail because they assumed a documented procedure was enough without checking whether it actually produces the evidence an auditor will ask to see.

👉 Run a structured check before that assumption gets tested in front of an auditor → ISO 13485 Gap Assessment Checklist


Quick Clause Reference Checklist

A clause tells you what’s required. It doesn’t tell you what to hand an auditor when they ask for proof. Below is a quick translation — clause by clause, requirement to evidence.

ISO 13485 clauses explained through an audit evidence checklist showing objective evidence for Clauses 4, 5, 7, and 8
ISO 13485 clauses explained through the objective evidence auditors may review for Clauses 4, 5, 7, and 8.

✅ Clause 4 — QMS scope defined, outsourced processes controlled, medical device file assembled
✅ Clause 5 — Quality policy documented, management review covering all required inputs
✅ Clause 6 — Competence records current, contamination controls documented where applicable
✅ Clause 7 — Risk management documented within product realization; ISO 14971 provides further guidance; design control records complete, supplier evaluation criteria defined
✅ Clause 8 — Complaint handling tied to regulatory reporting, CAPA records show broader-impact evaluation

⚠️ Clauses 1–3 — Exclusions and non-applicability justified in the quality manual, not just left blank

For implementation sequencing beyond the checklist above, our ISO 13485 Implementation Roadmap and ISO 13485 Gap Assessment: Step-by-Step Guide walk through the order to tackle these in.


FAQ

How many clauses does ISO 13485:2016 have?

Eight. Clauses 1 through 3 are introductory and carry no auditable requirements. Clauses 4 through 8 contain the substantive quality management system requirements that certification bodies audit against — and since February 2026, FDA investigators evaluate the same core requirements under Compliance Program 7382.850.

Does ISO 13485 follow the same structure as ISO 9001?

No. ISO 13485 does not use ISO’s Annex SL high-level structure, which ISO 9001, ISO 14001, and ISO 45001 all share. The technical committee kept ISO 13485 independent specifically to protect regulatory stability for device manufacturers, so clause numbers that look similar between the two standards often cover different scope.

Can I exclude clauses from ISO 13485?

Only with documented justification. Under Clause 4.2.2, the scope and justification for any exclusion or non-application have to be recorded in the quality manual, and you need to be prepared to defend that justification during an audit.

Which ISO 13485 clause covers risk management?

Clause 7.1 (Planning of Product Realization) is where documented risk management is explicitly required, and its note points to ISO 14971 for further guidance. But risk-related requirements aren’t confined to one clause — they surface throughout Clauses 4 through 8 rather than sitting in a single isolated section.

What’s the difference between ISO 13485 and the FDA’s QMSR?

As of February 2, 2026, FDA’s QMSR incorporates ISO 13485:2016 by reference into 21 CFR Part 820, and FDA’s inspection methodology changed to match — Compliance Program 7382.850 replaced QSIT the same day. The two frameworks are far more tightly aligned than before, but they’re not identical: four Other Applicable FDA Requirements (Medical Device Reporting, Corrections and Removals, Medical Device Tracking, and UDI) sit outside ISO 13485’s text and are evaluated in applicable inspection types, with a limited exception for certain PMA preapproval inspections when the device has not yet been introduced to the U.S. market.

What is CP 7382.850?

CP 7382.850 (Inspection of Medical Device Manufacturers) is FDA’s current compliance program manual for device inspections, effective February 2, 2026 alongside the QMSR. It replaced the Quality System Inspection Technique (QSIT) and reorganizes inspections around six QMS Areas — Management Oversight, Design and Development, Production and Service Provision, Measurement/Analysis/Improvement, Outsourcing and Purchasing, and Change Control — plus four Other Applicable FDA Requirements evaluated in most inspection types.

Do I need to buy ISO 9001 to understand ISO 13485’s terminology?

You don’t need to purchase it, but ISO 13485 does reference ISO 9000:2015 for its terms and definitions, and auditors expect consistent use of that vocabulary in your documentation.

Which clauses deserve the closest audit preparation?

In practice, Clause 4.2 (documentation control), Clause 7.3 where applicable (design and development), and Clause 8.5 (CAPA effectiveness) tend to draw sustained attention, largely because each requires ongoing documented evidence rather than a one-time procedure. The exact focus varies by organization, device type, and regulatory scope — under the current FDA inspection framework, Management Oversight and Measurement, Analysis, and Improvement are evaluated on every inspection regardless of device type.

Is a documentation kit enough to get ISO 13485 clause requirements right?

A kit gives you a starting structure, but clause-by-clause compliance depends on evidence specific to your processes — training records, design and development records, CAPA effectiveness checks. Our ISO Documentation Kits for Manufacturers page breaks down what a kit does and doesn’t cover.


📥 Free Resources


Not Sure What to Do Next?

🔹 Still researching how the clauses fit together? Start with What Is ISO 13485? for the foundational overview before working through this clause breakdown a second time.

🔹 Ready to assess where your QMS actually stands? Run the ISO 13485 Gap Assessment Checklist against the clause list above — it’s built to map directly to Clauses 4 through 8.

🔹 Need the official standard text to cite exact clause language? Purchase ISO 13485:2016 through ANSI Webstore — use code CC2026 for 5% off through December 31, 2026. International-language editions are available for teams managing documentation across multiple regulatory regions.

🔹 Need your internal auditors trained on this clause structure before your next surveillance audit? ISO 13485 training through BSI Group covers the structure clause by clause with a certification body’s own instructors.

The Standards Navigator breaks down what these clauses actually demand — not just what they’re titled — so your team can walk into an audit knowing which sub-clause the finding will land on before it does.


Stay Ahead of Clause-Level Changes

Most QMS documentation doesn’t fail because a team ignored ISO 13485. It fails because someone mapped a procedure to the wrong clause once, early on, and every review since has confirmed the wrong thing.

Organizations that treat the clause structure above as a living reference — checked against actual audit findings, updated as FDA’s QMSR enforcement approach becomes clearer — walk into surveillance audits with far fewer surprises than organizations treating their quality manual as a document they wrote once and filed away.

The Standards Navigator tracks ISO 13485, QMSR, and the surrounding medical device standards landscape as they develop, not just at certification time.

👉 Get updates on ISO 13485 and medical device QMS requirements
👉 Be first to access new gap assessment tools and clause-mapping resources

Subscribe

* indicates required

Industrial Compliance. Clearly Explained.

Validation & Verification Requirements: What ISO 13485 and the New FDA QMSR Actually Demand (2026 Guide)

ISO 13485 Clause 7.3 requires distinct verification and validation evidence — and the FDA’s new QMSR, effective February 2, 2026, makes the distinction matter more than ever. This guide breaks down design verification, design validation, process validation, and software validation requirements, and shows manufacturers how to build a traceability matrix that survives an audit or inspection.

ISO 13485 verification and validation requirements explained for medical device manufacturers navigating the QMSR transition

Affiliate Disclosure: Some links in this article are affiliate links. If you purchase through them, The Standards Navigator may earn a commission at no additional cost to you.


The Documentation Gap That Fails Design History Files

A design verification report that confirms the device meets its own specifications is not the same thing as a validation report that confirms the device meets the user’s actual needs. Auditors know the difference. Regulatory affairs teams sometimes don’t find out until an FDA inspector or notified body assessor pulls the Design History File and asks for both — and only one exists.

That gap has gotten more consequential, not less. The FDA’s Quality Management System Regulation took effect February 2, 2026, formally incorporating ISO 13485:2016 into 21 CFR Part 820 by reference. Verification and validation records that used to satisfy QSR expectations are now being evaluated against ISO 13485 Clause 7.3 directly — and the two frameworks don’t document V&V identically.

From the Floor: As a certified ISO 9001 Internal Auditor, I’ve sat across the table from teams who could produce a stack of test reports but couldn’t answer a simple question: which of these prove the design meets the specification, and which prove it meets the user’s need? Verification and validation get treated as interchangeable paperwork until an auditor separates them — and by then it’s a finding, not a conversation. The QMS documentation discipline that catches this before an audit is the same discipline that catches it before a submission.

If your last internal audit didn’t clearly separate verification evidence from validation evidence, that’s the gap worth closing first.

Run a clause-by-clause gap check before your next surveillance audit or FDA inspection — the ISO 13485 Gap Assessment Checklist below is built for exactly this kind of documentation review. Most teams miss the verification/validation split until it’s flagged.

👉 ISO 13485 Gap Assessment Checklist


In This Guide

  • What verification and validation mean under ISO 13485 Clause 7.3, and why they are not interchangeable
  • How process validation (Clause 7.5.6) differs from design validation
  • Software validation requirements for devices and manufacturing/QMS software
  • What changed under the FDA QMSR effective February 2, 2026
  • The most common V&V documentation failures found in audits and inspections
  • How to structure a verification and validation plan that survives scrutiny


👉 Start Here (Top Resources)

If you’re building or auditing a verification and validation process, these are the two resources worth starting with:


Verification vs. Validation: The Core Distinction

Comparison infographic explaining the differences between ISO 13485 verification and validation requirements under ISO 13485:2016, including design inputs, intended use, testing methods, timing, applicable clauses, and common audit findings.
This comparison illustrates how verification and validation serve different purposes under ISO 13485 and why both are required for compliant medical device design controls.

Verification confirms that design outputs meet design inputs. Validation confirms that the finished device meets user needs and intended use. That one-sentence distinction is where most documentation failures start, because the two activities can look procedurally similar — testing, measuring, comparing results against criteria — while answering completely different questions.

ElementDesign VerificationDesign Validation
Question answeredDid we build the design correctly?Did we build the correct design?
Compared againstDesign inputs / specificationsUser needs / intended use
Typical methodsBench testing, inspection, analysis, comparison to similar designsClinical evaluation, simulated use testing, human factors studies
TimingThroughout design and developmentUnder defined operating conditions, on initial production units or equivalent
ISO 13485 clause7.3.67.3.7
Common failureTesting against internal spec only, no traceability to inputValidating on prototypes instead of production-equivalent units

Most common finding: auditors and FDA investigators repeatedly cite validation performed on non-representative units — bench prototypes, early builds, or units built on equipment that doesn’t match production. ISO 13485 Clause 7.3.7 specifically requires validation on production or production-equivalent units, under defined operating conditions.


Verification and Validation in Practice: An Infusion Pump Example

Take a manufacturer developing an infusion pump. Design verification confirms the device meets its own engineering specifications:

  • ✅ Flow rate accuracy within the specified tolerance
  • ✅ Battery life meets the stated runtime under load
  • ✅ Alarm volume meets the decibel specification

Design validation confirms something different — that the device works safely in the hands of the people who will actually use it:

  • ✅ Nurses can operate the pump correctly and safely during simulated or actual clinical use
  • ✅ The alarm is audible and distinguishable in a realistic hospital environment, not a quiet test lab
  • ✅ Labeling and instructions for use are understood by the intended users without additional training

A pump can pass every verification test and still fail validation — accurate flow rate and long battery life mean nothing if a nurse under time pressure misreads the alarm or misinterprets the instructions. That’s the gap Clause 7.3.7 is built to catch, and it’s why validation has to happen on production-equivalent units under conditions that resemble actual use.


Design Verification Requirements

Clause 7.3.6 requires that design verification confirms outputs meet input requirements, with results and conclusions recorded, including the methods, dates, and individuals performing the verification. In practice, that means every design input needs a traceable verification activity — not a general statement that “the device was tested.”

If you are building a Design History File from scratch → start with a traceability matrix that maps every design input to its verification method and result before writing a single test protocol. Retrofitting traceability after testing is where most rework happens.

If you are already ISO 9001 certified and adding ISO 13485 → your existing design control process likely covers verification structurally, but it almost certainly lacks the input-to-output traceability rigor ISO 13485 auditors expect. That’s the gap to close first, not the documentation format.

👉 Before You Build Another Test Protocol

Most verification failures aren’t testing failures — they’re traceability failures. Run your design inputs against your current verification records now and find the gaps before an assessor does. →


Design Validation Requirements

Design validation under Clause 7.3.7 must be performed on production or production-equivalent units, under defined operating conditions, and must include risk analysis where applicable — which is where ISO 14971 risk management intersects directly with design controls. Validation isn’t complete until it addresses actual clinical or user-environment conditions, not lab conditions that approximate them.

Objection: “Our device is low-risk — do we really need formal simulated-use validation?” Even Class I and low-risk Class II devices need validation evidence proportional to risk, and “proportional” still means documented, traceable, and tied to intended use. A shorter validation plan is defensible. No validation plan is not.

Clinical evaluation, when required, and human factors/usability testing both fall under validation, not verification — a distinction that matters for regulatory submissions referencing FDA guidance on human factors engineering.


Process Validation Under Clause 7.5.6

Infographic explaining the three phases of process validation under ISO 13485, including Installation Qualification (IQ), Operational Qualification (OQ), and Performance Qualification (PQ), with key activities, outputs, and compliance requirements.
This infographic explains the roles of IQ, OQ, and PQ in process validation, helping manufacturers understand how each qualification stage supports ISO 13485 and FDA QMSR compliance.

Separate from design validation, ISO 13485 Clause 7.5.6 requires validation of processes where the resulting output cannot be verified by subsequent monitoring or measurement — sterilization, certain sealing and bonding processes, injection molding parameters, and software used in production are the classic examples.

Process validation requires:

  • ✅ Defined criteria for review and approval of the process
  • ✅ Approval of equipment and qualification of personnel
  • ✅ Use of specific methods, procedures, and acceptance criteria
  • ✅ Requirements for records (Clause 4.2.5)
  • ✅ Revalidation criteria, including criteria for triggering revalidation

Most auditors and FDA investigators expect this evidence structured around three stages: Installation Qualification (IQ), Operational Qualification (OQ), and Performance Qualification (PQ).

Installation Qualification (IQ) confirms that equipment and supporting systems are installed correctly, according to the manufacturer’s specifications and the site’s own installation requirements — including verified utilities, calibration status, and documentation of the as-installed configuration, not just a checklist that the equipment arrived and was plugged in.

Operational Qualification (OQ) confirms that the equipment operates as intended across its full specified operating range, not just at a single nominal setting. For a sterilization process, that means testing at the upper and lower bounds of temperature, time, and pressure defined in the process specification — not only the target parameters.

Performance Qualification (PQ) confirms that the process consistently produces conforming output under actual production conditions, typically across multiple runs and, where risk warrants it, multiple operators, shifts, or lots. PQ is where most revalidation triggers get defined, since it establishes the baseline the process must continue to meet.

If you are validating a sterilization or bonding process for the first time → build your IQ/OQ/PQ protocol before ordering test units. Retrofitting an IQ after OQ testing has already started is a common finding, and it undermines the traceability an assessor is looking for.

If your process hasn’t changed but your equipment or facility has → IQ typically needs to be repeated even when OQ and PQ parameters stay the same, since IQ is tied to the specific installation, not the process design.

Skipping straight to PQ — running production and calling the passing output “validation” — is one of the most common shortcuts auditors flag, because it skips the evidence that the equipment itself is capable of consistently meeting the operating range the process depends on.

If you are outsourcing sterilization or bonding processes → your supplier controls documentation needs to show that you’ve verified the supplier’s process validation, not just received a certificate of conformance.


Software Validation Requirements

Software validation shows up in two places under ISO 13485, and conflating them is a recurring audit finding: software that is part of the device (or used in its production) versus software used for quality management purposes, such as electronic QMS platforms or CAPA tracking tools. Both require validation appropriate to their use, application, and risk — but the depth and method differ substantially, and design-control software validation should be traceable back to the same input/output structure as hardware verification.


What the FDA QMSR Changed for U.S. Manufacturers

The FDA’s Quality Management System Regulation replaced the legacy Quality System Regulation under 21 CFR Part 820, effective February 2, 2026, incorporating ISO 13485:2016 by reference rather than maintaining a separately worded U.S. regulation. For manufacturers who were already ISO 13485 certified, the operational impact on verification and validation practices is smaller than the documentation-mapping impact: DHF, DMR, and DHR content doesn’t necessarily need renaming, but it does need a clear mapping showing where ISO 13485 Clause 7.3 requirements are satisfied within existing U.S. records.

If you were operating under legacy QSR language only → this is the trigger to formally adopt ISO 13485 Clause 7.3 verification/validation terminology and structure, since FDA inspectors are now trained against the ISO clause structure, not the old Part 820 subparts.


Common V&V Documentation Failures

The same handful of gaps show up repeatedly in ISO 13485 QMS audits:

  • No traceability matrix linking design inputs to verification methods and results
  • Validation performed on prototypes rather than production-equivalent units
  • Missing revalidation criteria for processes that later change equipment, materials, or parameters
  • Software validation treated as one-size-fits-all instead of scaled to risk and application
  • Verification and validation dates, methods, and personnel not fully recorded, leaving conclusions without traceable support

👉 Before Your Next Notified Body Assessment

If you’re not confident your traceability matrix would hold up under document review, that’s the exact gap the ISO 13485 Gap Assessment Checklist was built to catch — in under 45 minutes. →


Building a Verification & Validation Plan That Holds Up

A defensible V&V plan starts with the traceability matrix, not the test protocols. Build it in this order:

  1. List every design input and requirement
  2. Map each input to a specific verification method and acceptance criterion
  3. Identify which requirements also require validation evidence, and under what conditions
  4. Define production-equivalent unit criteria before validation begins
  5. Build revalidation triggers into the plan up front — not as an afterthought after a process change

This structure is what turns a stack of individual test reports into a Design History File that answers an assessor’s questions instead of prompting more of them.

Workflow infographic illustrating how verification and validation fit into the ISO 13485 design control process, from user needs and design inputs through production-equivalent units, validation, and Design History File documentation.
This workflow shows how verification and validation integrate into ISO 13485 design controls to produce a complete, traceable Design History File for regulatory compliance.

Quick Audit Checklist

  • ✅ Every design input has a documented verification method and result
  • ✅ Validation was performed on production or production-equivalent units
  • ✅ Risk analysis is referenced in the validation rationale
  • ✅ Process validation records include revalidation criteria
  • ✅ Software validation is scaled to intended use and risk
  • ✅ Verification and validation records include dates, methods, and personnel
  • ⚠️ Watch for validation evidence copied from an earlier device without device-specific justification

FAQ

What is the difference between verification and validation in ISO 13485?

Verification confirms design outputs meet design inputs — did we build it correctly. Validation confirms the finished device meets user needs and intended use — did we build the correct thing. They require separate evidence and cannot substitute for each other.

Does ISO 13485 require validation on production units?

Yes. Clause 7.3.7 requires design validation on production or production-equivalent units under defined operating conditions, not on early prototypes or bench models that don’t reflect final manufacturing.

What processes require process validation under Clause 7.5.6?

Any process where output cannot be fully verified by later inspection or testing — common examples include sterilization, certain welding and bonding processes, injection molding, and adhesive curing.

How did the FDA QMSR affect verification and validation requirements?

The QMSR, effective February 2, 2026, incorporates ISO 13485:2016 into 21 CFR Part 820 by reference. Manufacturers now need documentation that maps clearly to ISO 13485 Clause 7.3, even if internal DHF/DMR/DHR naming stays the same.

Do low-risk devices still need design validation?

Yes, though the depth can scale with risk. A shorter, risk-justified validation plan is acceptable; skipping validation entirely is not.

Does software need separate validation from the device it’s part of?

Software validation is required both for software that’s part of or used in producing the device, and for software used for quality management purposes — but the required depth and method differ by application and risk.

What’s the most common finding auditors cite for validation?

Validation conducted on non-representative units — prototypes or early builds that don’t match production configuration or manufacturing conditions.

Where does risk management fit into verification and validation?

ISO 14971 risk management activities feed directly into what needs validation and how rigorously, particularly for design validation rationale and process revalidation triggers.


📥 Free Resources

  • ISO 13485 Gap Assessment Checklist — free checklist for medical device manufacturers assessing their QMS against ISO 13485 requirements, including design control and V&V documentation gaps
  • ISO 9001 Roadmap — step-by-step implementation guide for manufacturers building or improving a quality management system
  • Manufacturing Compliance Checklist — practical compliance reference covering key ISO, OSHA, and quality requirements for production environments
  • Supplier Quality Checklist — evaluation tool for assessing supplier quality controls and flow-down compliance before audits or new contracts
  • AS9100 Rev D Gap Assessment Checklist — 74-item clause-by-clause checklist for aerospace suppliers assessing their QMS before certification

Not Sure What to Do Next?

🔹 Still researching your V&V documentation gaps? Start with the ISO 13485 Gap Assessment Checklist — it maps directly to Clause 7.3 verification and validation requirements.

🔹 Ready to build a compliant V&V process? BSI Group’s ISO 13485 training covers Clause 7.3 requirements in the depth a design control rebuild needs.

🔹 Need the standard itself to build your traceability matrix against? Get ISO 13485:2016 from ANSI Webstore — code CC2026 takes 5% off, and international formats are available.


Verification proves your engineers met the specification. Validation proves your customers can safely use the product. Auditors expect both. Regulators require both. A complete Design History File demonstrates both through traceable evidence — not one comprehensive-sounding report that tries to do both jobs at once.


Stay Ahead of the Next V&V Finding

Design History File gaps rarely surface during routine work — they surface during an audit or inspection, when there’s no time left to fix them. Manufacturers who catch the verification/validation split early walk into assessments with a traceability matrix that answers questions before they’re asked. Manufacturers who don’t spend the assessment explaining why validation was performed on a prototype.

The Standards Navigator tracks ISO 13485, QMSR, and medical device compliance requirements as they develop — including changes that affect how verification and validation get documented.

👉 Get updates on ISO 13485 and QMSR compliance changes
👉 Be first to access new medical device gap assessment tools and checklists

Subscribe below to stay ahead.

Subscribe

* indicates required

The Standards Navigator — Industrial Compliance. Clearly Explained.